IP Library Granted Patent US 12,081,972
Granted Patent B2
US 12,081,972 · App. 16/746,495 · Granted Sep 3, 2024

Protection of sequence numbers in authentication and key agreement protocol

Inventors: Adrian Edward Escott (Reading, GB); Soo Bum Lee (San Diego, CA); Anand Palanigounder (San Diego, CA)
Assignee: QUALCOMM Incorporated
H04W12/06H04L9/12H04L9/3242H04W12/0431H04W56/001
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,081,972
App. No.
16/746,495
Granted
Sep 3, 2024
Kind
B2
Abstract

Techniques and apparatus for protecting sequence numbers used in authentication procedures are described. One technique includes receiving, from a network, an authentication request comprising at least a random challenge. After receipt of the authentication request, a synchronization parameter is generated based at least in part on a key shared by the network and the UE, the random challenge, and a first message authentication code (MAC). The synchronization parameter and the first MAC are transmitted to the network in response to the authentication request.

Claims (27)

1. A method for authenticating a network for wireless communications by a user equipment (UE), comprising:

receiving, from the network, an authentication request comprising at least a random challenge;

after receiving the authentication request, generating a synchronization parameter based at least in part on a key shared by the network and the UE, the random challenge, and a first message authentication code (MAC), wherein generating the synchronization parameter comprises:

generating the first MAC using a first function, wherein the key shared by the network and the UE, the random challenge, and a first sequence number are inputs into the first function; and

generating an anonymity key (AK) using a second function, wherein the random challenge, the first MAC, and the key shared by the network and the UE are inputs into the second function;

transmitting, in response to the authentication request, the synchronization parameter to the network;

after transmitting the synchronization parameter, receiving another authentication request comprising a second sequence number from the network, wherein the second sequence number is set based on the first sequence number;

detecting that a value of the second sequence number is within a predetermined range of sequence numbers; and

transmitting an authentication response to the network after the detection.

2. The method of claim 1 , wherein:

the first sequence number is a sequence number associated with the UE that is maintained in the UE; and

the second sequence number is a sequence number associated with the UE that is maintained in the network.

3. The method of claim 1 , further comprising detecting a synchronization failure by determining that a value of a sequence number received with the authentication request is not within a predetermined range of sequence number values.

4. An apparatus for wireless communications, comprising:

a receiver configured to receive, from a network, an authentication request comprising at least a random challenge;

at least one processor configured to generate a synchronization parameter based at least in part on a key shared by the network and the apparatus, the random challenge, and a first message authentication code (MAC), wherein, to generate the synchronization parameter, the at least one processor is configured to:

generate the first MAC using a first function, wherein the key shared by the network and a user equipment (UE), the random challenge, and a first sequence number are inputs into the first function; and

generate an anonymity key (AK) using a second function, wherein the random challenge, the first MAC, and the key shared by the network and the UE are inputs into the second function;

a transmitter configured to transmit, in response to the authentication request, the synchronization parameter to the network; and

a memory coupled to the at least one processor, wherein:

the receiver is further configured to receive, after transmission of the synchronization parameter, another authentication request comprising a second sequence number from the network, wherein the second sequence number is set based on the first sequence number;

the at least one processor is further configured to detect that a value of the second sequence number is within a predetermined range of sequence numbers; and

the transmitter is further configured to transmit an authentication response to the network after the detection.

5. The apparatus of claim 4 , wherein:

the first sequence number is a sequence number associated with the apparatus that is maintained in the UE; and

the second sequence number is a sequence number associated with the apparatus that is maintained in the network.

6. The apparatus of claim 4 , wherein the at least one processor is configured to detect a synchronization failure by determining that a value of a sequence number received with the authentication request is not within a predetermined range of sequence number values.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2020
From: ESCOTT, ADRIAN EDWARD; LEE, SOO BUM; PALANIGOUNDER, ANAND
To: QUALCOMM INCORPORATED
Reel/Frame 053112/0026 →
Continuity (2)
Provisional Application 62794191 · Jan 18, 2019
Related Publication 20200236548A1 · Jul 23, 2020
Cited By (2)
US 12,671,571 US 12,696,087