Ensuring secure attachment in size constrained authentication protocols
A method to attach a mobile device to a server, using a protocol having data size encoding constraints which prevents using traditional ciphering, includes an initialization phase using a range of ephemeral IMSIs stored in a batch of credential containers of mobile devices and an associated group master key shared by the server and credential containers having the same range of ephemeral IMSIs to initiate a session using a server random value. The initialization phase uses limited payload in a mobile device-to-server message to send a randomly chosen rIMSI among the range of IMSIs to enable the server to generate keys to initiate a secured communication phase, then using individual keys stored in the mobile device and retrieved by the server with an identifier of the credential container sent in a mobile device-to-server message and with an individualization master key owned by the server.
1 . A method to securely attach a mobile device having a credential container to a server,
said method comprising:
an initialization phase using:
a same range of ephemeral IMSIs stored in a batch of credential containers of mobile devices, and
an associated group master key shared by the server and the batch of credential containers of mobile devices having the same range of ephemeral IMSIs,
to initiate a secured session using a server random value, said initialization phase using payload in a first message sent from one of said mobile devices to said server, said first message comprising a randomly chosen IMSI among said range of ephemeral IMSIs by said mobile device, to enable said server to generate keys to initiate a secured communication phase,
said secured communication phase using individual keys stored in the credential container of said mobile device and at said server, an identifier of said credential container being also sent from said mobile device to said server with an individualization master key stored at said server, said method comprising a provisioning phase previous to said initialization phase, wherein said provisioning phase comprises the steps of, at each mobile device side:
receiving and storing said range of ephemeral IMSIs at its credential container,
receiving and storing, at said credential container, said group master key shared by said credential container and said server, identical for every credential container having the same range of ephemeral IMSIs and two individual keys derived using an identifier of said credential and an individualization master key owned by said server, named individual cipher key and individual integrity key,
said initialization phase comprising the steps of, for the initiation of said secured session using a server random value, at said mobile device side, when an attachment is required:
sending, in a first message, at least an attachment request to said server carrying an IMSI value randomly taken out of said range of ephemeral IMSIs,
receiving, in a second message signed by a derived integrity key obtained at the server side, using said group master key and the received randomly chosen IMSI value, an authentication request originating from said server, said authentication request comprising parameters allowing to establish a unique session using said randomly chosen IMSI value and a server random value,
sending, in a third message signed by an integrity key derived at said credential container, using said group master key and said randomly chosen IMSI value, a credential container identifier encrypted using a cipher key derived using said group master key and said randomly chosen IMSI value,
receiving, in a fourth message signed by said integrity key, command and parameters which are to be personalized to enable a temporary subscription encrypted using said cipher key,
subsequent messages in the secured communication phase being ciphered with said cipher key and signed with said integrity key.