IP Library Granted Patent US 12666259
Granted Patent B2
US 12666259 · App. 17/293,093 · Granted Jun 23, 2026

Authentication of a communications device

Inventors: Vesa Lehtovirta (Espoo, FI); Vesa Torvinen (Sauvo, FI); Noamen Ben Henda (Vällingby, SE)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04W12/0433H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12666259
App. No.
17/293,093
Granted
Jun 23, 2026
Kind
B2
Abstract

A method is performed by a communications device. The method may comprise receiving, via a control plane of a serving network of the communications device, a message in an authentication procedure for authentication of the communications device with a home network of the communications device. The message in some embodiments indicates that the authentication is for the purpose of establishing a shared security key between the communications device and an application server.

Claims (41)

1 . A method performed by a communications device, the method comprising:

receiving, via a control plane of a serving network of the communications device, a message in an authentication procedure for authentication of the communications device with a home network of the communications device, wherein the message indicates that the authentication is for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network by refraining from deriving new serving network security keys for the communication device as a result of the authentication;

determining, from the message, that authentication with the home network is to be for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network;

generating a master key shared between the communications device and the home network; and

based on said determining, deriving, from the master key, an application layer security key shared between the communications device and the application server, but preserving the security key hierarchy of the serving network by refraining from further deriving from the master key a serving network security key shared between the communications device and the serving network.

2 . The method of claim 1 , wherein the message is an authentication request message that requests the communications device to authenticate itself with the home network.

3 . The method of claim 1 , wherein the received message is a non-access stratum (NAS) authentication request message or an extensible authentication protocol (EAP) request message or an authentication and key agreement (AKA) challenge message.

4 . The method of claim 1 , further comprising transmitting, to the serving network, a message that indicates the authentication is to be for the purpose of establishing a shared security key between the communications device and an application server while preserving the security key hierarchy of the serving network.

5 . The method of claim 1 , wherein the message indicates that the authentication is for the purpose of establishing an application layer security key between the communications device and an application server for securing application layer communication between the communications device and the application server.

6 . The method of claim 1 , wherein the message indicates that the authentication is for Authentication and Key Management for Applications (AKMA) authentication, rather than primary authentication, wherein the AKMA authentication preserves the security key hierarchy of the serving network.

7 . The method of claim 1 , wherein authentication for the purpose of establishing a shared security key between the communications device and the application server preserves an existing anchor key in the security key hierarchy of the serving network even upon successful authentication of the communications device.

8 . A method performed by a communications device, the method comprising:

transmitting, to a serving network of the communications device, a message that indicates authentication of the communications device with a home network of the communications device is to be for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network by refraining from deriving new serving network security keys for the communication device as a result of the authentication; and

after the communications device authenticates itself to the home network, and based on the purpose of the authentication being for establishing a shared security key between the communications device and an application server, generating a master key shared between the communications device and the home network and deriving, from the master key, an application layer security key shared between the communications device and the application server but preserving the security key hierarchy of the serving network by refraining from deriving from the master key a serving network security key shared between the communications device and the serving network.

9 . The method of claim 8 , further comprising securing communication between the communications device and the application server based on the application layer security key.

10 . The method of claim 8 , further comprising transmitting an application layer message to, and/or receiving an application layer message from, the application server, wherein the transmitted application layer message and/or the received application layer message is protected based on the application layer security key.

11 . The method of claim 8 , wherein:

the master key comprises a key Kausf that is shared between the communications device and an authentication server function (AUSF); or

the master key comprises a key Kbsf that is shared between the communications device and a bootstrapping server function (BSF).

12 . A method performed by network equipment configured for use in a home network of a communications device, the method comprising:

transmitting, via a control plane of a serving network of the communications device, a message in an authentication procedure for authentication of the communications device with the home network, wherein the message indicates the authentication is for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network by refraining from deriving new serving network security keys for the communication device as a result of the authentication;

determining that authentication of the communications device with the home network is to be for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network;

generating a master key shared between the communications device and the home network; and

based on said determining, preserving the security key hierarchy of the serving network by refraining from deriving from the master key a serving network security key shared between the communications device and the serving network.

13 . The method of claim 12 , wherein the message is an authentication request message that requests the communications device to authenticate itself with the home network, or an extensible authentication protocol (EAP) request message, or an authentication and key agreement (AKA) challenge message.

14 . The method of claim 12 , further comprising:

receiving, from the communications device or other network equipment, a message that indicates the authentication of the communications device with the home network is to be for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network; and

based on the message received from the communications device or the other network equipment, generating the message to be transmitted to indicate that the authentication is for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network.

15 . The method of claim 12 , wherein the master key comprises:

a key Kausf that is shared between the communications device and an authentication server function, AUSF; or

a key Kbsf that is shared between the communications device and a bootstrapping server function (BSF).

16 . The method of claim 12 , wherein the network equipment implements an authentication server function (AUSF) or a bootstrapping server function (BSF) or an authentication and key management for applications (AKMA) anchor.

17 . A method performed by network equipment configured for use in a home network of a communications device, the method comprising:

receiving, from a serving network of the communications device, a message in an authentication procedure for authentication of the communications device with the home network, wherein the message indicates the authentication is for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network by refraining from deriving new serving network security keys for the communication device as a result of the authentication; and

based on the purpose of the authentication being for establishing a shared security key between the communications device and an application server, generating a master key shared between the communications device and the home network, but refraining from deriving any serving network security key shared between the communications device and the serving network based on the master key.

18 . The method of claim 17 , wherein the message is an authentication request message that requests the communications device to authenticate itself with the home network.

19 . The method of claim 17 , further comprising, based on the received message, transmitting an authentication get request message that requests information for the authentication and that indicates the authentication is for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network.

20 . The method of claim 17 , wherein:

the master key comprises a key Kausf that is shared between the communications device and an authentication server function, AUSF; or

the master key comprises a key Kbsf that is shared between the communications device and a bootstrapping server function (BSF).

21 . The method of claim 17 , wherein the network equipment implements an authentication server function (AUSF) or a bootstrapping server function (BSF) or an authentication and key management for applications (AKMA) anchor.