IP Library › Granted Patent US 11,659,387
Granted Patent B2
US 11,659,387 · App. 16/943,869 · Granted May 23, 2023

User equipment authentication preventing sequence number leakage

Inventors: Suresh Nair (Whippany, NJ); Ranganathan Mavureddi Dhanasekaran (Nuremberg, DE); Anja Jerichow (Grafing, DE)
Assignee: Nokia Technologies Oy
H04W12/06H04L9/3271H04L63/08H04W8/18H04W12/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,659,387
App. No.
16/943,869
Granted
May 23, 2023
Kind
B2
Abstract

Techniques for preventing sequence number leakage during user equipment authentication in a communication network are provided. For example, a method comprises obtaining a permanent identifier and an authentication sequence value that are unique to user equipment, concealing the permanent identifier and the authentication sequence value, and sending the concealed permanent identifier and the authentication sequence value in a registration message from the user equipment to a communication network. Then, advantageously, in response to receipt of an authentication failure message from the communication network, the user equipment can send a response message to the communication network containing a failure cause indication without a re-synchronization token.

Claims (61)

1. An apparatus comprising:

at least one processor;

at least one memory including computer program code;

the at least one memory and the computer program code being configured to, with the at least one processor, cause the apparatus at least to:

obtain a permanent identifier and an authentication sequence value that are unique to the apparatus;

conceal the permanent identifier and the authentication sequence value; and

send the concealed permanent identifier and the authentication sequence value in a registration message to a communication network.

2. The apparatus of claim 1 , wherein the at least one memory and the computer program code being configured to, with the at least one processor, further cause the apparatus to:

combine the permanent identifier and the authentication sequence value prior to concealment.

3. The apparatus of claim 1 , wherein the at least one memory and the computer program code being configured to, with the at least one processor, further cause the apparatus to:

in response to receipt of an authentication request message from the communication network, send a response message to the communication network containing a failure cause indication without a re-synchronization token.

4. The apparatus of claim 1 , wherein the at least one memory and the computer program code being configured to, with the at least one processor, further cause the apparatus to:

in response to receipt of an authentication request message from the communication network, send a response message to the communication network containing a failure cause indication without a re-synchronization token, wherein the failure cause indication indicates that the authentication sequence value had been sent earlier.

5. The apparatus of claim 1 , wherein the apparatus is part of user equipment configured for 5G authentication operations and the communication network is part of a 5G core network.

6. The apparatus of claim 5 , wherein the permanent identifier comprises a subscriber permanent identifier (SUPI) and the authentication sequence value comprises a sequence number (SQN) that are concatenated and encrypted as part of a subscriber concealed identifier (SUCI) and sent in the registration message.

7. The apparatus of claim 1 , wherein concealing the permanent identifier and the authentication sequence value comprises utilizing a combination of the permanent identifier and the authentication sequence value as an input to an encryption algorithm.

8. The apparatus of claim 7 , wherein the encryption algorithm comprises an elliptic curve integrated encryption scheme.

9. The apparatus of claim 7 , wherein the combination of the permanent identifier and the authentication sequence value comprises a concatenation of the permanent identifier and the authentication sequence value.

10. An apparatus comprising:

at least one processor;

at least one memory including computer program code;

the at least one memory and the computer program code being configured to, with the at least one processor, cause the apparatus at least to:

obtain a permanent identifier and an authentication sequence value that are unique to the apparatus;

conceal the permanent identifier and the authentication sequence value;

send the concealed permanent identifier and the authentication sequence value in a registration message to a communication network; and

combine the permanent identifier and the authentication sequence value prior to concealment;

wherein combining the permanent identifier and the authentication sequence value prior to concealment further comprises concatenating the permanent identifier and the authentication sequence value to generate a single plain text block that is concealed and sent in the registration message.

11. A method comprising:

obtaining a permanent identifier and an authentication sequence value that are unique to user equipment;

concealing the permanent identifier and the authentication sequence value; and

sending the concealed permanent identifier and the authentication sequence value in a registration message from the user equipment to a communication network.

12. The method of claim 11 , further comprising combining the permanent identifier and the authentication sequence value prior to concealment.

13. The method of claim 11 , further comprising, in response to receipt of an authentication request message from the communication network, sending a response message to the communication network containing a failure cause indication without a re-synchronization token.

14. The method of claim 11 , further comprising, in response to receipt of an authentication request message from the communication network, sending a response message to the communication network containing a failure cause indication without a re-synchronization token, wherein the failure cause indication indicates that the authentication sequence value had been sent earlier.

15. The method of claim 11 , wherein the user equipment is configured for 5G authentication operations and the communication network is part of a 5G core network.

16. The method of claim 15 , wherein the permanent identifier comprises a subscriber permanent identifier (SUPI) and the authentication sequence value comprises a sequence number (SQN) that are concatenated and encrypted as part of a subscriber concealed identifier (SUCI) and sent in the registration message.

17. The method of claim 11 , wherein concealing the permanent identifier and the authentication sequence value comprises utilizing a combination of the permanent identifier and the authentication sequence value as an input to an encryption algorithm.

18. The method of claim 17 , wherein the encryption algorithm comprises an elliptic curve integrated encryption scheme.

19. The method of claim 17 , wherein the combination of the permanent identifier and the authentication sequence value comprises a concatenation of the permanent identifier and the authentication sequence value.

20. A method comprising:

obtaining a permanent identifier and an authentication sequence value that are unique to user equipment;

concealing the permanent identifier and the authentication sequence value;

sending the concealed permanent identifier and the authentication sequence value in a registration message from the user equipment to a communication network; and

combining the permanent identifier and the authentication sequence value prior to concealment;

wherein combining the permanent identifier and the authentication sequence value prior to concealment further comprises concatenating the permanent identifier and the authentication sequence value to generate a single plain text block that is concealed and sent in the registration message.

21. An article of manufacture comprising a non-transitory computer-readable storage medium having embodied therein executable program code that when executed by a processor causes the processor to perform the steps of:

obtaining a permanent identifier and an authentication sequence value that are unique to user equipment;

concealing the permanent identifier and the authentication sequence value; and

sending the concealed permanent identifier and the authentication sequence value in a registration message from the user equipment to a communication network.

22. The article of claim 21 , further comprising the step of combining the permanent identifier and the authentication sequence value prior to concealment.

23. The article of claim 21 , further comprising the step of, in response to receipt of an authentication request message from the communication network, sending a response message to the communication network containing a failure cause indication without a re-synchronization token.

24. The article of claim 21 , further comprising the step of, in response to receipt of an authentication request message from the communication network, sending a response message to the communication network containing a failure cause indication without a re-synchronization token, wherein the failure cause indication indicates that the authentication sequence value had been sent earlier.

25. The article of claim 21 , wherein concealing the permanent identifier and the authentication sequence value comprises utilizing a combination of the permanent identifier and the authentication sequence value as an input to an encryption algorithm.

26. The article of claim 21 , wherein the encryption algorithm comprises an elliptic curve integrated encryption scheme.

27. The article of claim 21 , wherein the combination of the permanent identifier and the authentication sequence value comprises a concatenation of the permanent identifier and the authentication sequence value.

28. An article of manufacture comprising a non-transitory computer-readable storage medium having embodied therein executable program code that when executed by a processor causes the processor to perform the steps of:

obtaining a permanent identifier and an authentication sequence value that are unique to user equipment;

concealing the permanent identifier and the authentication sequence value;

sending the concealed permanent identifier and the authentication sequence value in a registration message from the user equipment to a communication network; and

combining the permanent identifier and the authentication sequence value prior to concealment;

wherein combining the permanent identifier and the authentication sequence value prior to concealment further comprises concatenating the permanent identifier and the authentication sequence value to generate a single plain text block that is concealed and sent in the registration message.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 20, 2020
From: NAIR, SURESH
To: NOKIA OF AMERICA CORPORATION
Reel/Frame 053555/0307 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNMENT BY REMOVING THE INVENTOR/ASSIGNOR SURESH NAIR AND REMOVING THE ASSIGNEE NOKIA OF AMERICA CORPORATION PREVIOUSLY RECORDED AT REEL: 053445 FRAME: 0565. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Aug 20, 2020
From: DHANASEKARAN, RANGANATHAN MAVUREDDI; JERICHOW, ANJA
To: NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
Reel/Frame 053570/0022 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2020
From: NOKIA OF AMERICA CORPORATION
To: NOKIA TECHNOLOGIES OY
Reel/Frame 053541/0133 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2020
From: NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
To: NOKIA TECHNOLOGIES OY
Reel/Frame 053541/0598 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2020
From: NAIR, SURESH; DHANASEKARAN, RANGANATHAN MAVUREDDI; JERICHOW, ANJA
To: NOKIA OF AMERICA CORPORATION; NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
Reel/Frame 053445/0565 →
Continuity (1)
Related Publication 20220038896A1 · Feb 3, 2022
Cited By (2)
US 12,696,087 US 12,713,236