IP Library Granted Patent US 7,904,715
Granted Patent B2
US 7,904,715 · App. 10/822,220 · Granted Mar 8, 2011

Method for authenticating dual-mode access terminals

Assignee: Alcatel-Lucent USA Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,904,715
App. No.
10/822,220
Filed
Apr 9, 2004
Granted
Mar 8, 2011
Kind
B2
Art Unit
2436
USPC
713/168
Abstract

A method is provided for operating a dual-mode access terminal such that a CAVE based authentication process may be used in both an IS-2000 and an HRPD mode of operation. Generally, the access terminal receives a CHAP challenge from an access network, and then derives a RAND challenge based on at least a portion of the CHAP challenge. The CAVE based authentication process is then performed using the RAND challenge to produce a SMEKEY and a PLCM. Thereafter a secret CHAP key is derived from the SMEKEY and PLCM and provided to the access network for purposes of authenticating the access terminal in the HRPD mode of operation.

Claims (26)

1. A method of authenticating a user identity module implemented in an access terminal, comprising:

receiving, at the access terminal and over an air interface, a first Challenge Handshake Authentication Protocol (CHAP) challenge associated with a first authentication process;

deriving, at the access terminal, a second challenge associated with a second authentication process based on at least a portion of the first CHAP challenge;

performing, at the user identity module, the second authentication process using the derived second challenge and producing at least one authentication parameter therefrom;

deriving, at the access terminal, a key associated with the first authentication process based on the at least one authentication parameter; and

re-authenticating the access terminal using the key in response to receiving a second CHAP challenge for re-authentication of the first authentication process.

2. A method, as set forth in claim 1 , wherein deriving the second challenge associated with the second authentication process based on at least a portion of the first challenge further comprises deriving a random number (RAND) challenge based on at least a portion of the first CHAP challenge.

3. A method, as set forth in claim 2 , wherein deriving the RAND challenge based on at least a portion of the first CHAP challenge further comprises deriving the RAND challenge from a selected number of least significant bits in the first CHAP challenge.

4. A method, as set forth in claim 3 , wherein performing the second authentication process using the derived second challenge and producing at least one authentication parameter therefrom further comprises performing a cellular authentication and voice encryption (CAVE) based authentication process on the RAND challenge to produce a short message encryption key (SMEKEY).

5. A method, as set forth in claim 4 wherein performing the CAVE based authentication process on the RAND challenge to produce SMEKEY further comprises performing the CAVE based authentication process on the RAND challenge to produce the SMEKEY and a public long code mask (PLCM).

6. A method, as set forth in claim 5 , wherein deriving the key associated with the first authentication process based on the at least one authentication parameter further comprises deriving the key associated with the first authentication process based on SMEKEY and PLCM.

7. A method, as set forth in claim 1 , further comprising:

generating, at the access terminal, an authentication response to the first CHAP challenge based on the key; and

delivering the authentication response over the air interface to a network to request access to the network.

8. A method, as set forth in claim 7 , wherein re-authenticating the access terminal comprises:

determining that the second CHAP challenge associated with the first authentication process is a re-authentication challenge;

bypassing the derivation of the second challenge associated with the second authentication process based on at least a portion of the second CHAP challenge in response to the determining that the second CHAP challenge is the re-authentication challenge;

bypassing the performance of the second authentication process using the derived second challenge and producing at least one authentication parameter therefrom in response to the determining that the second CHAP challenge is the re-authentication challenge; and wherein

deriving the key associated with the first authentication process based on the at least one authentication parameter further comprises using a previously derived key in response to the determining that the second CHAP first challenge is the re-authentication challenge.

9. A method, as set forth in claim 8 , further comprising:

determining that the second CHAP challenge associated with the first authentication process is a re-authentication challenge; and wherein

delivering the key to a network to request access to the network further comprises delivering the previously derived key in response to the determining that the second CHAP challenge is the re-authentication challenge.

10. A method, comprising:

determining, at an access terminal, whether a Challenge Handshake Authentication Protocol (CHAP) challenge is an authentication challenge or a re-authentication challenge;

providing, from the access terminal, a response formed from a secret CHAP key derived using information retrieved from a subscriber identity module in the access terminal when the CHAP challenge is an authentication challenge; and

providing, from the access terminal, a response formed from a previously derived secret CHAP key when the CHAP challenge is a re-authentication challenge.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Oct 9, 2014
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT USA INC.
Reel/Frame 033950/0261 →
SECURITY INTEREST Recorded Mar 7, 2013
From: ALCATEL-LUCENT USA INC.
To: CREDIT SUISSE AG
Reel/Frame 030510/0627 →
MERGER Recorded Jan 19, 2011
From: LUCENT TECHNOLOGIES INC.
To: ALCATEL-LUCENT USA INC.
Reel/Frame 025660/0670 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2004
From: MIZIKOVSKY, SEMYON B.
To: LUCENT TECHNOLOGIES INC.
Reel/Frame 015933/0042 →
Continuity (1)
Related Publication 20050228992A1 · Oct 13, 2005