IP Library › Granted Patent US 11,956,626
Granted Patent B2
US 11,956,626 · App. 17/603,833 · Granted Apr 9, 2024

Cryptographic key generation for mobile communications device

Inventors: Bo Holm Bjerrum (Nibe, DK); Anja Jerichow (Grafing bei München, DE)
Assignee: NOKIA TECHNOLOGIES OY
H04W12/041H04L9/0866H04W12/0431H04W12/068H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,956,626
App. No.
17/603,833
Granted
Apr 9, 2024
Kind
B2
Abstract

According to an example aspect of the present invention, there is provided method, comprising: generating a first key based on a first input specific to a mobile device, wherein the first input comprises measurement of mutable code of the mobile device and a unique device secret, generating a symmetric second key on the basis of the first key and a second input specific to the mobile device, and generating authentication credentials on the basis of the second key for authenticating the mobile device to a mobile communications network.

Claims (34)

1. An apparatus comprising at least one processor; and at least one memory including computer program code, the at least one memory and computer program code being configured to, with the at least one processor, to cause the apparatus to at least perform:

generate a first key based on a first input specific to a mobile device, wherein the first input comprises measurement of mutable code of the mobile device and a unique device secret;

generating a cryptographic hash of the mutable code, wherein the mutable code includes a firmware image;

generate a symmetric second key on the basis of the first key and a second input specific to the mobile device, wherein the second input comprises a device identifier of the mobile device;

generate authentication credentials on the basis of the second key for authenticating the mobile device to a mobile communications network, wherein the authentication credentials are generated as part of an authentication and key agreement based authentication procedure;

generate a cipher key and an integrity key on the basis of the second key; and

use the device identifier as an input for authentication and key agreement based authentication procedure between the mobile device and the mobile communications network.

2. The apparatus of claim 1 , wherein the at least one memory and computer program code are further configured to, with the at least one processor, to cause the apparatus to perform: generate an extended master session key on the basis of the second key.

3. The apparatus of claim 1 , wherein the first input further comprises measurement of hardware state and configuration.

4. The apparatus of claim 1 wherein the at least one memory and computer program code are further configured to, with the at least one processor, to cause the apparatus to perform: apply a secure hash function or a keyed-hash message authentication code function to the first input to generate the first key.

5. The apparatus of claim 1 , wherein the mobile device is a constrained user equipment device, such as an internet-of-things device, and the mobile communications network is a non-public network.

6. The apparatus of claim 1 , wherein the at least one memory and computer program code are further configured to, with the at least one processor, to cause the apparatus to perform: generate the first key by immutable code of the mobile device and the second key by a key derivation function in mutable code of the mobile device.

7. The apparatus of claim 1 , wherein the at least one memory and computer program code are further configured to, with the at least one processor, to cause the apparatus to perform: generate an authentication response on the basis of the second key and an authentication vector received in an authentication request from the mobile communications network, for authenticating the mobile device to the mobile communications network.

8. The apparatus of claim 1 , wherein the apparatus is or comprises the mobile device operating as a user equipment to the mobile communications network.

9. The apparatus of claim 1 , wherein the apparatus comprises a unified data management function, an authentication server function, or an authentication, authorization, and accounting server of the mobile communications network.

10. A method, comprising:

generating a first key based on a first input specific to a mobile device, wherein the first input comprises measurement of mutable code of the mobile device and a unique device secret;

generating a cryptographic hash of the mutable code, wherein the mutable code includes a firmware image;

generating a symmetric second key on the basis of the first key and a second input specific to the mobile device, wherein the second input comprises a device identifier of the mobile device;

generating authentication credentials on the basis of the second key for authenticating the mobile device to a mobile communications network, wherein the authentication credentials are generated as part of an authentication and key agreement based authentication procedure;

generate a cipher key and an integrity key on the basis of the second key; and

use the device identifier as an input for authentication and key agreement based authentication procedure between the mobile device and the mobile communications network.

11. The method of claim 10 , wherein the authentication credentials are generated as part of an authentication and key agreement based authentication procedure.

12. The method of claim 10 , wherein a cipher key and an integrity key is generated on the basis of the second key.

13. The method of claim 10 , wherein an extended master session key is generated on the basis of the second key.

14. The method of claim 10 , wherein the first input further comprises measurement of hardware state and configuration.

15. The method of claim 10 , wherein a secure hash function or a keyed-hash message authentication code function is applied to the first input to generate the first key.

16. A non-transitory computer readable medium having stored thereon a set of computer readable instructions that, when executed by at least one processor, cause an apparatus to at least:

generating a first key based on a first input specific to a mobile device, wherein the first input comprises measurement of mutable code of the mobile device and a unique device secret;

generating a cryptographic hash of the mutable code, wherein the mutable code includes a firmware image;

generating a symmetric second key on the basis of the first key and a second input specific to the mobile device, wherein the second input comprises a device identifier of the mobile device;

generating authentication credentials on the basis of the second key for authenticating the mobile device to a mobile communications network, wherein the authentication credentials are generated as part of an authentication and key agreement based authentication procedure;

generate a cipher key and an integrity key on the basis of the second key; and

use the device identifier as an input for authentication and key agreement based authentication procedure between the mobile device and the mobile communications network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2022
From: BJERRUM, BO HOLM; JERICHOW, ANJA
To: NOKIA TECHNOLOGIES OY
Reel/Frame 058552/0710 →
Continuity (1)
Related Publication 20220182821A1 · Jun 9, 2022
Cited By (1)
US 12,463,821