IP Library Granted Patent US 12,659,742
Granted Patent B2
US 12,659,742 · App. 17/298,213 · Granted Jun 16, 2026

Ensuring secure attachment in size constrained authentication protocols

Inventors: Marc Lamberton (Meudon, FR); Eric Bretagne (Meudon, FR); Aline Gouget (Meudon, FR); Sylvain Morandi (Meudon, FR); Arnaud Schwartz (Meudon, FR)
Assignee: THALES DIS FRANCE SAS
H04W12/068H04W12/02H04W12/03H04W12/041H04W12/106
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,742
App. No.
17/298,213
Granted
Jun 16, 2026
Kind
B2
Abstract

A method to attach a mobile device to a server, using a protocol having data size encoding constraints which prevents using traditional ciphering, includes an initialization phase using a range of ephemeral IMSIs stored in a batch of credential containers of mobile devices and an associated group master key shared by the server and credential containers having the same range of ephemeral IMSIs to initiate a session using a server random value. The initialization phase uses limited payload in a mobile device-to-server message to send a randomly chosen rIMSI among the range of IMSIs to enable the server to generate keys to initiate a secured communication phase, then using individual keys stored in the mobile device and retrieved by the server with an identifier of the credential container sent in a mobile device-to-server message and with an individualization master key owned by the server.

Claims (15)

1 . A method to securely attach a mobile device having a credential container to a server,

said method comprising:

an initialization phase using:

a same range of ephemeral IMSIs stored in a batch of credential containers of mobile devices, and

an associated group master key shared by the server and the batch of credential containers of mobile devices having the same range of ephemeral IMSIs,

to initiate a secured session using a server random value, said initialization phase using payload in a first message sent from one of said mobile devices to said server, said first message comprising a randomly chosen IMSI among said range of ephemeral IMSIs by said mobile device, to enable said server to generate keys to initiate a secured communication phase,

said secured communication phase using individual keys stored in the credential container of said mobile device and at said server, an identifier of said credential container being also sent from said mobile device to said server with an individualization master key stored at said server, said method comprising a provisioning phase previous to said initialization phase, wherein said provisioning phase comprises the steps of, at each mobile device side:

receiving and storing said range of ephemeral IMSIs at its credential container,

receiving and storing, at said credential container, said group master key shared by said credential container and said server, identical for every credential container having the same range of ephemeral IMSIs and two individual keys derived using an identifier of said credential and an individualization master key owned by said server, named individual cipher key and individual integrity key,

said initialization phase comprising the steps of, for the initiation of said secured session using a server random value, at said mobile device side, when an attachment is required:

sending, in a first message, at least an attachment request to said server carrying an IMSI value randomly taken out of said range of ephemeral IMSIs,

receiving, in a second message signed by a derived integrity key obtained at the server side, using said group master key and the received randomly chosen IMSI value, an authentication request originating from said server, said authentication request comprising parameters allowing to establish a unique session using said randomly chosen IMSI value and a server random value,

sending, in a third message signed by an integrity key derived at said credential container, using said group master key and said randomly chosen IMSI value, a credential container identifier encrypted using a cipher key derived using said group master key and said randomly chosen IMSI value,

receiving, in a fourth message signed by said integrity key, command and parameters which are to be personalized to enable a temporary subscription encrypted using said cipher key,

subsequent messages in the secured communication phase being ciphered with said cipher key and signed with said integrity key.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2022
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 059072/0509 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2021
From: LAMBERTON, MARC; BRETAGNE, ERIC; GOUGET, ALINE; MORANDI, SYLVAIN; SCHWARTZ, ARNAUD
To: THALES DIS FRANCE SA
Reel/Frame 056935/0777 →
Priority Claims (1)
EP 18306602 · Dec 3, 2018 · regional
Continuity (1)
Related Publication 20220104013A1 · Mar 31, 2022
References Cited (29)
US 8532637B2 · Abolrous · 2013 [cited by examiner]
US 9037112B2 · Rajadurai · 2015 [cited by examiner]
US 20050090256A1 · Dutta · 2005 [cited by examiner]
US 20050113070A1 · Okabe · 2005 [cited by examiner]
US 20080281912A1 · Dillenberger · 2008 [cited by examiner]
US 20090129359A1 · Lee · 2009 [cited by examiner]
US 20110191826A1 · Ballal · 2011 [cited by examiner]
US 20120322410A1 · Lodeweyckx · 2012 [cited by examiner]
US 20130080774A1 · Combet · 2013 [cited by examiner]
US 20140185586A1 · Wu · 2014 [cited by examiner]
US 20140287757A1 · Borg · 2014 [cited by examiner]
US 20150222554A1 · Xu · 2015 [cited by examiner]
US 20150223104A1 · Xu · 2015 [cited by examiner]
US 20170026830A1 · Singh · 2017 [cited by examiner]
US 20170041733A1 · Babbage · 2017 [cited by examiner]
US 20170332217A1 · Youtz · 2017 [cited by examiner]
US 20180077152A1 · Lipovkov · 2018 [cited by examiner]
US 20180331829A1 · Wang · 2018 [cited by examiner]
US 20200236529A1 · Anslot · 2020 [cited by examiner]
EP 3358871A1 · 2018 [cited by examiner]
EP 3506668A1 · 2019 [cited by examiner]
EP 3329706B1 · 2020 [cited by examiner]
EP 3522580B1 · 2021 [cited by examiner]
WO WO2016177674A1 · 2016 [cited by examiner]
WO WO2019034282A1 · 2019 [cited by examiner]
Digital cellular telecommunications system (Phase 2+); Universal Mobile Telecommunications System (UMTS); 3G security; Security architecture (3GPP TS 33.102 version 11.5.1 Release 11) Jul. 2013. (Year: 2013). [cited by examiner]
Negar Sabour, Static Verification of n Implementation of 5G-AKA, 2023, The University of Waterloo, pp. 1-138. (Year: 2023). [cited by examiner]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on the security aspects of the next generation system (Release 14), 3GPP TR 33.899 V1.3.0 (Aug. 27, 2017) (605 pages). [cited by applicant]
International Search Report (PCT/ISA/210) and Written Opinion (PCT/ISA/237) mailed on Feb. 12, 2020, by the European Patent Office as the International Searching Authority for International Application No. PCT/EP2019/08… [cited by applicant]