IP Library Granted Patent US 12,666,259
Granted Patent B2
US 12,666,259 · App. 17/293,093 · Granted Jun 23, 2026

Authentication of a communications device

Inventors: Vesa Lehtovirta (Espoo, FI); Vesa Torvinen (Sauvo, FI); Noamen Ben Henda (Vällingby, SE)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04W12/0433H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,666,259
App. No.
17/293,093
Granted
Jun 23, 2026
Kind
B2
Abstract

A method is performed by a communications device. The method may comprise receiving, via a control plane of a serving network of the communications device, a message in an authentication procedure for authentication of the communications device with a home network of the communications device. The message in some embodiments indicates that the authentication is for the purpose of establishing a shared security key between the communications device and an application server.

Claims (41)

1 . A method performed by a communications device, the method comprising:

receiving, via a control plane of a serving network of the communications device, a message in an authentication procedure for authentication of the communications device with a home network of the communications device, wherein the message indicates that the authentication is for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network by refraining from deriving new serving network security keys for the communication device as a result of the authentication;

determining, from the message, that authentication with the home network is to be for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network;

generating a master key shared between the communications device and the home network; and

based on said determining, deriving, from the master key, an application layer security key shared between the communications device and the application server, but preserving the security key hierarchy of the serving network by refraining from further deriving from the master key a serving network security key shared between the communications device and the serving network.

2 . The method of claim 1 , wherein the message is an authentication request message that requests the communications device to authenticate itself with the home network.

3 . The method of claim 1 , wherein the received message is a non-access stratum (NAS) authentication request message or an extensible authentication protocol (EAP) request message or an authentication and key agreement (AKA) challenge message.

4 . The method of claim 1 , further comprising transmitting, to the serving network, a message that indicates the authentication is to be for the purpose of establishing a shared security key between the communications device and an application server while preserving the security key hierarchy of the serving network.

5 . The method of claim 1 , wherein the message indicates that the authentication is for the purpose of establishing an application layer security key between the communications device and an application server for securing application layer communication between the communications device and the application server.

6 . The method of claim 1 , wherein the message indicates that the authentication is for Authentication and Key Management for Applications (AKMA) authentication, rather than primary authentication, wherein the AKMA authentication preserves the security key hierarchy of the serving network.

7 . The method of claim 1 , wherein authentication for the purpose of establishing a shared security key between the communications device and the application server preserves an existing anchor key in the security key hierarchy of the serving network even upon successful authentication of the communications device.

8 . A method performed by a communications device, the method comprising:

transmitting, to a serving network of the communications device, a message that indicates authentication of the communications device with a home network of the communications device is to be for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network by refraining from deriving new serving network security keys for the communication device as a result of the authentication; and

after the communications device authenticates itself to the home network, and based on the purpose of the authentication being for establishing a shared security key between the communications device and an application server, generating a master key shared between the communications device and the home network and deriving, from the master key, an application layer security key shared between the communications device and the application server but preserving the security key hierarchy of the serving network by refraining from deriving from the master key a serving network security key shared between the communications device and the serving network.

9 . The method of claim 8 , further comprising securing communication between the communications device and the application server based on the application layer security key.

10 . The method of claim 8 , further comprising transmitting an application layer message to, and/or receiving an application layer message from, the application server, wherein the transmitted application layer message and/or the received application layer message is protected based on the application layer security key.

11 . The method of claim 8 , wherein:

the master key comprises a key Kausf that is shared between the communications device and an authentication server function (AUSF); or

the master key comprises a key Kbsf that is shared between the communications device and a bootstrapping server function (BSF).

12 . A method performed by network equipment configured for use in a home network of a communications device, the method comprising:

transmitting, via a control plane of a serving network of the communications device, a message in an authentication procedure for authentication of the communications device with the home network, wherein the message indicates the authentication is for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network by refraining from deriving new serving network security keys for the communication device as a result of the authentication;

determining that authentication of the communications device with the home network is to be for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network;

generating a master key shared between the communications device and the home network; and

based on said determining, preserving the security key hierarchy of the serving network by refraining from deriving from the master key a serving network security key shared between the communications device and the serving network.

13 . The method of claim 12 , wherein the message is an authentication request message that requests the communications device to authenticate itself with the home network, or an extensible authentication protocol (EAP) request message, or an authentication and key agreement (AKA) challenge message.

14 . The method of claim 12 , further comprising:

receiving, from the communications device or other network equipment, a message that indicates the authentication of the communications device with the home network is to be for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network; and

based on the message received from the communications device or the other network equipment, generating the message to be transmitted to indicate that the authentication is for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network.

15 . The method of claim 12 , wherein the master key comprises:

a key Kausf that is shared between the communications device and an authentication server function, AUSF; or

a key Kbsf that is shared between the communications device and a bootstrapping server function (BSF).

16 . The method of claim 12 , wherein the network equipment implements an authentication server function (AUSF) or a bootstrapping server function (BSF) or an authentication and key management for applications (AKMA) anchor.

17 . A method performed by network equipment configured for use in a home network of a communications device, the method comprising:

receiving, from a serving network of the communications device, a message in an authentication procedure for authentication of the communications device with the home network, wherein the message indicates the authentication is for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network by refraining from deriving new serving network security keys for the communication device as a result of the authentication; and

based on the purpose of the authentication being for establishing a shared security key between the communications device and an application server, generating a master key shared between the communications device and the home network, but refraining from deriving any serving network security key shared between the communications device and the serving network based on the master key.

18 . The method of claim 17 , wherein the message is an authentication request message that requests the communications device to authenticate itself with the home network.

19 . The method of claim 17 , further comprising, based on the received message, transmitting an authentication get request message that requests information for the authentication and that indicates the authentication is for the purpose of establishing a shared security key between the communications device and an application server while preserving a security key hierarchy of the serving network.

20 . The method of claim 17 , wherein:

the master key comprises a key Kausf that is shared between the communications device and an authentication server function, AUSF; or

the master key comprises a key Kbsf that is shared between the communications device and a bootstrapping server function (BSF).

21 . The method of claim 17 , wherein the network equipment implements an authentication server function (AUSF) or a bootstrapping server function (BSF) or an authentication and key management for applications (AKMA) anchor.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2021
From: BEN HENDA, NOAMEN
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 057927/0833 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2021
From: OY L M ERICSSON AB
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 057927/0960 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2021
From: LEHTOVIRTA, VESA; TORVINEN, VESA
To: OY L M ERICSSON AB
Reel/Frame 057927/0891 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED AT REEL: 056211 FRAME: 0617. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 14, 2021
From: LEHTOVIRTA, VESA; TORVINEN, VESA
To: OY L M ERICSSON AB
Reel/Frame 056559/0907 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2021
From: BEN HENDA, NOAMEN
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 056211/0578 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2021
From: OY L M ERICSSON AB
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 056211/0662 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2021
From: LEHTOVIRTA, VESA; TORVINEN, VESA
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 056211/0617 →
Priority Claims (1)
SE 1830329-7 · Nov 12, 2018 · national
Continuity (1)
Related Publication 20210400475A1 · Dec 23, 2021
References Cited (48)
US 8881236B2 · Wang · 2014 [cited by examiner]
US 10237787B2 · Sharma · 2019 [cited by examiner]
US 10873464B2 · Muhanna · 2020 [cited by examiner]
US 20020114469A1 · Faccin · 2002 [cited by examiner]
US 20040165726A1 · Yamamichi · 2004 [cited by examiner]
US 20060154645A1 · Valkenburg · 2006 [cited by examiner]
US 20060171541A1 · Horn et al. · 2006 [cited by applicant]
US 20070204160A1 · Chan · 2007 [cited by examiner]
US 20070294186A1 · Yan · 2007 [cited by examiner]
US 20080102795A1 · Johur · 2008 [cited by examiner]
US 20090054036A1 · Chen · 2009 [cited by examiner]
US 20100002883A1 · Sammour · 2010 [cited by examiner]
US 20110004762A1 · Horn · 2011 [cited by examiner]
US 20110167270A1 · Lee · 2011 [cited by examiner]
US 20120030739A1 · Vadapalli · 2012 [cited by examiner]
US 20120106456A1 · Jin · 2012 [cited by examiner]
US 20120110637A1 · Holtmanns · 2012 [cited by examiner]
US 20120204224A1 · Wang · 2012 [cited by examiner]
US 20120204231A1 · Holtmanns et al. · 2012 [cited by applicant]
US 20160094988A1 · Lee · 2016 [cited by examiner]
US 20170012956A1 · Lee · 2017 [cited by examiner]
US 20170064554A1 · Li · 2017 [cited by examiner]
US 20180007557A1 · Lee · 2018 [cited by examiner]
US 20180013568A1 · Muhanna · 2018 [cited by examiner]
US 20180295125A1 · Lee · 2018 [cited by examiner]
US 20180317086A1 · Ben Henda · 2018 [cited by examiner]
US 20220394567A1 · Sharma · 2022 [cited by examiner]
EP 2988538A1 · 2016 [cited by applicant]
R. Arul, G. Raja, A. K. Bashir, J. Chaudry and A. Ali, “A Console GRID Leveraged Authentication and Key Agreement Mechanism for LTE/SAE,” in IEEE Transactions on Industrial Informatics, vol. 14, No. 6, pp. 2677-2689, Ju… [cited by examiner]
Zhiguo Wan, et al. 2008. A secure privacy-preserving roaming protocol based on hierarchical identity-based encryption for mobile networks. In Proceedings of the first ACM conference on Wireless network security (WiSec '… [cited by examiner]
3GPP, “3GPP TR 33.cde V0.2.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on authentication and key management for applications; based on 3GPP credential in 5G (… [cited by applicant]
3GPP, “3GPP TS 24.302 V15.4.0”, 3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Access to the 3GPP Evolved Packet Core (EPC) via non-3GPP access networks; Stage 3 (Release 1… [cited by applicant]
3GPP, “3GPP TS 33.102 V15.0.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3G Security; Security architecture (Release 15), Jun. 2018, 1-77. [cited by applicant]
3GPP, “3GPP TS 33.310 V16.0.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Network Domain Security (NDS); Authentication Framework (AF) (Release 16), Jun. 2018, 1-58. [cited by applicant]
3GPP, “3GPP TS 33.402 V15.1.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3GPP System Architecture Evolution (SAE); Security aspects of non-3GPP accesses (Release 15)… [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Generic Authentication Architecture (GAA); Generic Bootstrapping Architecture (GBA) (Release 15)”, 3GPP TS 33.220 V15… [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System; Stage 2 (Release 15)”, 3GPP TS 23.502 V15.3.0, Sep. 2018, 1-330. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 15)”, 3GPP TS 33.501 V15.2.0 (Sep. 2018), Sep. 2018, 1-17… [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System Architecture for the 5G System; Stage 2 (Release 15)”, 3GPP TS 23.501 V15.3.0, Sep. 2018, 1-226. [cited by applicant]
Aboba, B., et al., “Extensible Authentication Protocol (EAP)”, Network Working Group, RFC 3748, Jun. 2004, 1-67. [cited by applicant]
Arkko, J., et al., “Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA)”, Network Working Group, Request for Comments: 4187, Jan. 2006, 1-79. [cited by applicant]
Arkko, J., et al., “Improved Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA')”, Network Working Group, Request for Comments: 5448, May 2009, 1-29. [cited by applicant]
Dierks, T., et al., “The Transport Layer Security (TLS) Protocol Version 1.2”, Network Working Group, Request for Comments: 5246, Aug. 2008, 1-104. [cited by applicant]
Ericsson, “New solution: Access independent architecture solution for AKMA”, 3GPP TSG SA WG3 (Security) Meeting #93, S3-183562, (revision of S3-18xabc), Spokane(US), Nov. 12-16, 2018, 1-3. [cited by applicant]
Ericsson, “New solution: Stand-alone architecture solution for AKMA”, 3GPP TSG SA WG3 (Security) Meeting #93, S3-183564, (revision of S3-18xabc), Spokane(US), Nov. 12-16, 2018, 1-3. [cited by applicant]
Huawei, et al., “Solution for bootstrapping authentication of AKMA”, 3GPP TSG SA WG3 (Security) Meeting #93, S3-183420, (revision of S3-18xabc), Spokane (USA), Nov. 12-16, 2018, 1-4. [cited by applicant]
Simon, D., “The EAP-TLS Authentication Protocol”, Network Working Group, Request for Comments: 5216, Mar. 2008, 1-34. [cited by applicant]
3GPP, “3GPP TR 33.899 V0.6.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on the security aspects of the next generation system (Release 14), Nov. 2016, 375 page… [cited by applicant]