Authenticating a Device in a Network

US2016183091A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016183091-A1
Application numberUS-201615057809-A
CountryUS
Kind codeA1
Filing dateMar 1, 2016
Priority dateApr 27, 2011
Publication dateJun 23, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A mobile device and an authentication server are configured to re-establish a security context that was previously established using an Authentication Key Agreement (AKA) procedure. The re-establishment advantageously uses re-use information saved from the preceding AKA procedure, including using synchronization information for each such re-establishment that occurs between AKA procedures. The synchronization information particularly identifies each instance of re-establishment and depends on a sequence number assigned to the preceding AKA procedure and on any previous instances of re-establishing the security context.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method at a mobile device configured for operation in a communication network comprising: establishing Authentication and Key Agreement (AKA) based security contexts with the communication network from time to time, based on performing corresponding AKA procedures with the communication network, each AKA procedure involving the derivation of corresponding session keys at the mobile device and at the communication network according to a shared secret known a priori at the mobile device and at the communication network, said corresponding session keys used for securing data exchanged during the established security context; and at one or more instances after the performance of a preceding AKA procedure and before the performance of a next, succeeding AKA procedure, re-establishing the security context from the preceding AKA procedure using re-use information saved from the preceding AKA procedure, wherein the re-use information depends on a sequence number assigned by the communication network to identify the preceding AKA procedure, and wherein re-establishing the security context from the preceding AKA procedure comprises, for each instance of re-establishment: forming a context regeneration request that includes synchronization information particularly identifying each instance of re-establishment and dependent on the sequence number assigned to the preceding AKA procedure and on any previous instances of re-establishing the security context; sending the context regeneration request to the communication network; receiving a nonce or other authentication value from the communication network in response to the context regeneration request; and generating a new session key to use at the mobile device for securing data exchanged during the re-established security context, based on the received authentication value and the shared secret. 2 . The method of claim 1 , wherein at least the first instance of re-establishing the security context from the preceding AKA procedure using the re-use information saved from the preceding AKA procedure comprises determining that the security context requires refreshing, based on expiration of a timer or based upon signaling received from the communication network. 3 . The method of claim 1 , further comprising generating the synchronization information such that, for each instance of re-establishing the security context from the preceding AKA procedure, the synchronization information reflects how many times the security context has been re-established, or otherwise uniquely identifies each re-use of the re-use information to the communication network. 4 . The method of claim 1 , wherein the re-use information comprises a random value received from the communication network for use in establishing the security context during the preceding AKA procedure, along with the session key generated by the mobile device for the security context, and wherein the context regeneration request comprises a message authentication code that depends on the session key. 5 . A mobile device configured for operation in a communication network comprising: a communication transceiver configured for sending signaling to and receiving signaling from the communication network; and processing circuitry configured to: establish Authentication and Key Agreement (AKA) based security contexts with the communication network from time to time, based on performing corresponding AKA procedures with the communication network, each AKA procedure involving the derivation of corresponding session keys at the mobile device and at the communication network according to a shared secret known a priori at the mobile device and at the communication network, said corresponding session keys used for securing data exchanged during the established security context; and at one or more instances after the performance of a preceding AKA procedure and before the performance of a next, succeeding AKA procedure, re-establish the security context from the preceding AKA procedure using re-use information saved from the preceding AKA procedure, wherein the re-use information depends on a sequence number assigned by the communication network to identify the preceding AKA procedure, and wherein the processing circuitry re-establishes the security context from the preceding AKA procedure for each instance of re-establishment, based on being configured to: form a context regeneration request that includes synchronization information particularly identifying each instance of re-establishment and dependent on the sequence number assigned to the preceding AKA procedure and on any previous instances of re-establishing the security context; send the context regeneration request to the communication network; receive a nonce or other authentication value from the communication network in response to the context regeneration request; and generate a new session key to use at the mobile device for securing data exchanged during the re-established security context, based on the received authentication value and the shared secret. 6 . The mobile device of claim 5 , wherein, for at least the first instance of re-establishing the security context from the preceding AKA procedure using re-use information saved from the preceding AKA procedure, the processing circuitry is configured to determine that the security context requires refreshing, based on expiration of a timer or based upon signaling received from the communication network. 7 . The mobile device of claim 5 , wherein the processing circuitry is configured to generate the synchronization information such that, for each instance of re-establishing the security context from the preceding AKA procedure, the synchronization information reflects how many times the security context has been re-established, or otherwise uniquely identifies each re-use of the re-use information to the communication network. 8 . The mobile device of claim 5 , wherein the re-use information comprises a random value received from the communication network for use in establishing the security context during the preceding AKA procedure, along with the session key generated by the mobile device for the security context, and wherein the context regeneration request comprises a message authentication code that depends on the session key. 9 . A method at an authentication server configured for operation in a communication network comprising: establishing a security context with a mobile device, based on performing an Authentication and Key Agreement (AKA) procedure in dependence on a shared secret known a priori to the authentication server and the mobile device, including providing a session key generated by the authentication server to another network entity operative to secure communications between the mobile device and the communication network; saving a sequence number assigned to and identifying this particular performance of the AKA procedure with respect to the mobile device; and after establishing the security context and before performing another AKA procedure with the mobile device, re-establishing the security context for the mobile device at each of one or more instances, based on: receiving from the other network entity a request to reestablish the security context, wherein the request includes synchronization information from the mobile device; evaluate the synchronization information to determine whether or not the synchronization information includes or correctly derives from the sequence number assigned to the AKA procedure and correctly indicates this particular instance of re-establishment; and responsive to verification of the synchronization information, generating a new session ke

Assignees

Inventors

Classifications

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • for key distribution, e.g. centrally by trusted party (cryptographic mechanisms or cryptographic arrangements for key distribution involving a central third party H04L9/0819) · CPC title

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

  • H04L63/08Primary

    for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016183091A1 cover?
A mobile device and an authentication server are configured to re-establish a security context that was previously established using an Authentication Key Agreement (AKA) procedure. The re-establishment advantageously uses re-use information saved from the preceding AKA procedure, including using synchronization information for each such re-establishment that occurs between AKA procedures. The …
Who is the assignee on this patent?
Ericsson Telefon Ab L M
What technology area does this patent fall under?
Primary CPC classification H04L63/08. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jun 23 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).