Biometric authenticated biometric enrollment
US-2024187223-A1 · Jun 6, 2024 · US
US9071962B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9071962-B2 |
| Application number | US-201313901756-A |
| Country | US |
| Kind code | B2 |
| Filing date | May 24, 2013 |
| Priority date | Dec 21, 2010 |
| Publication date | Jun 30, 2015 |
| Grant date | Jun 30, 2015 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A monitoring system is coupled to interfaces in an LTE network and passively captures packets from the network interfaces. First data packets associated with an authentication and key agreement procedure are captured on a first interface. Second data packets associated with the authentication and key agreement procedure are captured on a second interface. Individual ones of the first data packets are correlated to individual ones of the second data packets based upon a same parameter. An authentication vector table is created comprising information from the correlated first data packets and second data packets, wherein entries in the table comprise authentication data for a plurality of security contexts. A cipher key is identified to decipher additional packets for the user. The cipher key can also be identified in case of Inter Radio Access Technology Handover by the user equipment.
Opening claim text (preview).
What is claimed is: 1. A method for deciphering data in an LTE network, comprising: capturing, by a microprocessor, authentication response messages at a monitoring system coupled to an S6a interface; identifying security keys (K ASME ) within the authentication info response messages; generating a calculated eNodeB key (K alg eNB ) from each of the security keys; storing each calculated eNodeB key and a related security key in a memory at the monitoring system; capturing a context request message from an S1-MME interface, the context request message related to a particular user equipment context; identifying an assigned eNodeB key (K eNB-assign ) within the context request message; comparing the assigned eNodeB key to the calculated eNodeB keys that are stored in the memory; identifying a matching calculated eNodeB key that corresponds to the assigned eNodeB key; and using a security key associated with the matching calculated eNodeB to decipher message traffic from the context. 2. The method of claim 1 , further comprising: capturing CK and IK subkeys and KSI from an S3 interface. 3. The method of claim 1 , further comprising: extracting an algorithm type and a security key index from an S1AP HO Request or an S1AP TAU Request. 4. The method of claim 1 , further comprising: deriving a K′ ASME value from CK and IK subkeys and one or two nonces as inputs; creating an authentication vector table; and appending an algorithm type and a security key index to the authentication vector table. 5. The method of 1 , further comprising: deriving an NAS deciphering key (L NASenc ) from the security key associated with the matching calculated eNodeB. 6. The method of 1 , wherein the context request message is an S1AP Initial Context Setup Request message. 7. The method of 1 , wherein the context request message is an S1AP UE Context Modification Request message. 8. The method of 1 , further comprising: capturing security mode complete messages from an S1-MME interface; identifying an uplink count parameter within each of the security mode complete messages; and generating the calculated eNodeB keys (K alg eNB ) from the security keys and corresponding uplink count parameters.
for supporting key management in a packet data network (cryptographic mechanisms or cryptographic arrangements for key management H04L9/08) · CPC title
of security context information · CPC title
Processing captured monitoring data, e.g. for logfile generation · CPC title
by filtering · CPC title
Testing, {supervising or monitoring} using real traffic · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.