IP Library Granted Patent US 10,873,464
Granted Patent B2
US 10,873,464 · App. 15/670,964 · Granted Dec 22, 2020

Authentication mechanism for 5G technologies

Inventors: Ahmad Shawky Muhanna (Richardson, TX); Marcus Wong (Green Brook, NJ)
Assignee: Futurewei Technologies, Inc.
H04L9/3242H04L9/0822H04L9/0825H04L9/14H04L63/045H04L63/0428H04W12/06H04L9/006H04L2209/80H04W8/18H04W12/00514H04W12/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,873,464
App. No.
15/670,964
Granted
Dec 22, 2020
Kind
B2
Abstract

Embodiments of this disclosure provide techniques for securely communicating an IMSI over the air from a UE to an SeAN, as well as for securely validating an unencrypted IMSI that the SeAN receives from the home network, during authentication protocols. In particular, the UE may either encrypt the IMSI assigned to the UE using an IMSI encryption key (K IMSIenc ) or compute a hash of the IMSI assigned to the UE using an IMSI integrity key (K IMSIint ), and then send the encrypted IMSI or the hash of the IMSI to the serving network. The encrypted IMSI or hash of the encrypted IMSI may then be used by the SeAN to validate an unencrypted IMSI that was previously received from an HSS in the home network of the UE.

Claims (38)

1. A method for secure authentication, the method comprising:

sending, by a user equipment (UE), an encrypted International Mobile Subscriber Identity (IMSI) or a hash of the IMSI to a base station in a serving network, the encrypted IMSI or the hash of the IMSI having been generated using an IMSI encryption key (K IMSIenc ) or an IMSI integrity key (K IMSIint ) associated with a serving home network, wherein the K IMSIenc or the K IMSIint is derived by the UE based at least in part on a COUNTER received from the base station in the serving network.

2. The method of claim 1 , further comprising:

computing, by the UE, a response parameter (RES) based on a pre-provisioned key (K_key) associated with the UE and a random number (RAND); and

sending the RES to the base station in the serving network.

3. The method of claim 1 , wherein the K IMSIenc or the K IMSIint is a NAS encryption or integrity key.

4. The method of claim 1 , wherein the K IMSIenc or the K IMSIint is further derived based on a shared key.

5. The method of claim 1 , wherein the K IMSIenc or the K IMSIint is an IAS encryption or integrity key (K IMSIenc ).

6. The method of claim 1 , wherein the K IMSIenc or the K IMSIint is further derived based on a shared key computed by the UE using at least a public key of the home network and the COUNTER received from the base station in the serving network.

7. The method of claim 1 , wherein the K IMSIenc or the K IMSIint is a serving network public key (SPuK).

8. The method of claim 1 , wherein the encrypted IMSI or the Hash of the IMSI is sent to the base station in the serving network via an initial authentication-request (IAR) message.

9. The method of claim 1 , wherein the encrypted IMSI or the Hash of the IMSI is sent to the base station in the serving network via a user authentication request message.

10. A user equipment (UE) comprising:

a processor; and

a non-transitory computer readable storage medium storing programming for execution by the processor, the programming including instructions to:

send an encrypted International Mobile Subscriber Identity (IMSI) or a hash of the IMSI to a base station in a serving network, the encrypted IMSI or the hash of the IMSI having been generated using an IMSI encryption key (K IMSIenc ) or an IMSI integrity key (K IMSIint ) associated with a home network, wherein the K IMSIenc or the K IMSIint is derived by the UE based at least in part on a COUNTER received from the base station in the serving network.

11. The UE of claim 10 , wherein the programming further includes instructions to:

compute a response parameter (RES) based on a pre-provisioned key (K_key) associated with the UE and a random number (RAND); and

send the RES to the base station in the serving network.

12. The UE of claim 10 , wherein the K IMSIenc or the K IMSIint is a NAS encryption or integrity key.

13. The UE of claim 10 , wherein the K IMSIenc or the K IMSIint is further derived based on a shared key.

14. The UE of claim 10 , wherein the K IMSIenc or the K IMSIint is an IAS encryption or integrity key (K IASenc ).

15. The UE of claim 10 , wherein the K IMSIenc or the K IMSIint is further derived based on a shared key computed by the UE using at least a public key of the home network and the COUNTER received from the base station in the serving network.

16. The UE of claim 10 , wherein the K IMSIenc or the K IMSIint is a serving network public key (SPuK).

17. The UE of claim 10 , wherein the encrypted IMSI or the Hash of the IMSI is sent to the base station in the serving network via an initial authentication-request (IAR) message.

18. The UE of claim 10 , wherein the encrypted IMSI or the Hash of the IMSI is sent to the base station in the serving network via a user authentication request message.

19. A computer program product comprising a non-transitory computer readable storage medium storing programming, the programming including instructions to:

send an encrypted International Mobile Subscriber Identity (IMSI) or a hash of the IMSI from a user equipment (UE) to a base station in a serving network, the encrypted IMSI or the hash of the IMSI having been generated using an IMSI encryption key (K IMSIenc ) or an IMSI integrity key (K IMSIint ) associated with a home network, wherein the K IMSIenc or the K IMSIint is derived by the UE based at least in part on a COUNTER received from the base station in the serving network.

20. The computer program product of claim 19 , wherein the programming further includes instructions to:

compute a response parameter (RES) based on a pre-provisioned key (K_key) associated with the UE and a random number (RAND); and

send the RES from the UE to the base station in the serving network.

21. The computer program product of claim 19 , wherein the K IMSIenc or the K IMSIint is a NAS encryption or integrity key.

22. The computer program product of claim 19 , wherein the K IMSIenc or the K IMSIint is further derived based on a shared key.

23. The computer program product of claim 19 , wherein the K IMSIenc or the K IMSIint is an IAS encryption or integrity key (K IASenc ).

24. The computer program product of claim 19 , wherein the K IMSIenc or the K IMSIint is further derived based on a shared key computed by the UE using at least a public key of the home network and the COUNTER received from the base station in the serving network.

25. The computer program product of claim 19 , wherein the K IMSIenc or the K IMSIint is a serving network public key (SPuK).

26. The computer program product of claim 19 , wherein the encrypted IMSI or the Hash of the IMSI is sent to the base station in the serving network via an initial authentication request (IAR) message.

27. The computer program product of claim 19 , wherein the encrypted IMSI or the Hash of the IMSI is sent to the base station in the serving network via a user authentication request message.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2017
From: MUHANNA, AHMAD SHAWKY; WONG, MARCUS
To: FUTUREWEI TECHNOLOGIES, INC.
Reel/Frame 043759/0282 →
Continuity (9)
Continuation In Part 15453776 · Mar 8, 2017
Provisional Application 62463521 · Feb 24, 2017
Provisional Application 62414488 · Oct 28, 2016
Provisional Application 62306550 · Mar 10, 2016
Provisional Application 62317295 · Apr 1, 2016
Provisional Application 62383223 · Sep 2, 2016
Provisional Application 62399069 · Sep 23, 2016
Provisional Application 62399055 · Sep 23, 2016
Related Publication 20180013568A1 · Jan 11, 2018
Cited By (5)
US 12,302,093 US 12,445,838 US 12,542,654 US 12,652,533 US 12,666,259