IP Library Granted Patent US 10,187,202
Granted Patent B2
US 10,187,202 · App. 15/789,399 · Granted Jan 22, 2019

Key agreement for wireless communication

Inventors: Matthew John Campagna (Ridgefield, CT); Daniel Richard L. Brown (Mississauga, CA); Nevine Maurice Nassif Ebeid (Kitchener, CA)
Assignee: Certicom Corp.
H04L9/0819H04L9/0866H04L9/14H04L9/3271H04W12/04H04L63/123H04L2209/24H04L2209/80H04L2463/061H04W12/02H04W12/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,187,202
App. No.
15/789,399
Granted
Jan 22, 2019
Kind
B2
Abstract

Methods, systems, and computer programs for performing key agreement operations in a communication system are described. In some aspects, a wireless network operator receives a mobile device identifier and accesses a secret key associated with the mobile device. A message authentication code function is evaluated based on the secret key to produce an output value. A session key and a challenge value are obtained based on the output value. In some aspects, a mobile device accesses a secret key in response to receiving the challenge value from the wireless network operator. A message authentication code function is evaluated based on the secret key to produce an output value. A response value and a session key are obtained based on the output value. The response value is transmitted to the wireless network operator.

Claims (65)

1. A wireless network operator system comprising:

a communication interface operable to receive an identifier of a mobile device, and a response from the mobile device;

data processing apparatus operable to:

receive an identifier of a universal integrated circuit card (UICC);

access, based on the identifier, a secret key held by the computer system, wherein the secret key is associated with the identifier;

evaluate a key derivation function (KDF) at least in part on the secret key, wherein the KDF is a hash function, to produce a first output value;

obtain a session key based on the first output value;

produce a second output value by evaluating the KDF at least in part on a sequence value; and

obtain a message authentication code (MAC) based on the second output value;

wherein the KDF is evaluated on a plurality of input values including:

a challenge value; and

an output length variable that indicates a bit-length of a KDF output.

2. The wireless network operator system of claim 1 , wherein the output length variable is the sum of bit-lengths of keying material needed.

3. The wireless network operator system of claim 1 , wherein the first output value is used to compute a cipher key.

4. The wireless network operator system of claim 1 , wherein one or more of the evaluations result from one iteration of the hash function.

5. The wireless network operator system of claim 1 , wherein the data processing apparatus is further configured to:

obtain the challenge value before evaluating the KDF, the challenge value being a random challenge value;

obtain an expected response value based on the first output value; and

generate a message that includes the random challenge value and the expected response value.

6. The wireless network operator system of claim 5 , wherein evaluating the KDF to produce the first output value comprises evaluating the KDF based at least in part on the secret key and the random challenge value.

7. The wireless network operator system of claim 1 , wherein the data processing apparatus is further configured to generate an authentication token based on the second output value.

8. The wireless network operator system of claim 1 , wherein said producing the second output value by evaluating the KDF at least in part on the sequence value comprises producing the second output value by evaluating the KDF at least in part on the sequence value and the secret key.

9. The wireless network operator system of claim 1 , wherein the first output value is produced by evaluating the KDF at least in part on the secret key and the challenge value, the challenge value being a random value, and wherein the second output value is produced by evaluating the KDF at least in part on the secret key, the random value, and the sequence value.

10. The wireless network operator system of claim 9 , wherein the data processing apparatus is further configured to further comprising generating a message that includes the random value, an expected response value obtained from the first output value, and the session key.

11. A non-transitory computer readable medium having stored thereon computer readable code executable by a processor to perform a method of:

receiving an identifier of a universal integrated circuit card (UICC);

accessing, based on the identifier, a secret key held by the computer system, wherein the secret key is associated with the identifier;

evaluating a key derivation function (KDF) at least in part on the secret key, wherein the KDF is a hash function, to produce a first output value;

obtaining a session key based on the first output value;

producing a second output value by evaluating the KDF at least in part on a sequence value; and

obtaining a message authentication code (MAC) based on the second output value;

wherein the KDF is evaluated on a plurality of input values including:

a challenge value; and

an output length variable that indicates a bit-length of a KDF output.

12. The non-transitory computer readable medium of claim 11 , wherein the output length variable is the sum of bit-lengths of keying material needed.

13. The non-transitory computer readable medium of claim 11 , wherein the first output value is used to compute a cipher key.

14. The non-transitory computer readable medium of claim 11 , wherein one or more of the evaluations result from one iteration of the hash function.

15. The non-transitory computer readable medium of claim 11 , the method further comprising:

obtaining the challenge value before evaluating the KDF, the challenge value being a random challenge value;

obtaining an expected response value based on the first output value; and

generating a message that includes the random challenge value and the expected response value.

16. The non-transitory computer readable medium of claim 15 , wherein evaluating the KDF to produce the first output value comprises evaluating the KDF based at least in part on the secret key and the random challenge value.

17. The non-transitory computer readable medium of claim 11 , the method further comprising:

generating an authentication token based on the second output value.

18. The non-transitory computer readable medium of claim 11 , wherein said producing the second output value by evaluating the KDF at least in part on the sequence value comprises producing the second output value by evaluating the KDF at least in part on the sequence value and the secret key.

19. The non-transitory computer readable medium of claim 11 , wherein the first output value is produced by evaluating the KDF at least in part on the secret key and the challenge value, the challenge value being a random value, and wherein the second output value is produced by evaluating the KDF at least in part on the secret key, the random value, and the sequence value.

20. The non-transitory computer readable medium of claim 19 , the method further comprising generating a message that includes the random value, an expected response value obtained from the first output value, and the session key.

21. A non-transitory computer readable medium having stored thereon computer readable code executable by a processor to perform a method of:

accessing a secret key;

evaluating a key derivation function (KDF) based on the secret key to produce a first output value;

obtaining a session key based on the first output value;

obtaining a response value based on the first output value;

producing a second output value by evaluating the KDF at least in part on a sequence value;

obtaining a message authentication code based on the second output value; and

transmitting the response value to a wireless network operator system;

wherein the KDF is a hash function; and

wherein the KDF is evaluated on a plurality of input values including

a challenge value; and

an output length variable that indicates a bit-length of a KDF output.

22. The non-transitory computer readable medium of claim 21 , wherein one or more of the evaluations result from one iteration of the hash function.

23. The non-transitory computer readable medium of claim 21 , the method further comprising generating an authentication token based on the second output value.

24. The non-transitory computer readable medium of claim 21 the method further comprising receiving the challenge value from the wireless network operator system, the challenge value being a random challenge value, and wherein the random challenge value is used with the secret key to produce the first output value.

25. The non-transitory computer readable medium of claim 21 , wherein said producing the second output value by evaluating the KDF at least in part on the sequence value comprises producing the second output value by evaluating the KDF at least in part on the sequence value and the secret key.

26. The non-transitory computer readable medium of claim 21 , wherein the first output value is produced by evaluating the KDF at least in part on the secret key and at least in part on the challenge value, the challenge value being a random challenge value received from the wireless network operator system, and wherein the second output value is produced by evaluating the KDF at least in part on the secret key, the random challenge value, and the sequence value.

27. The non-transitory computer readable medium of claim 26 , the method further comprising comparing the message authentication code to a value received from the wireless network operator system.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2018
From: CERTICOM (US) LIMITED
To: CERTICOM CORP.
Reel/Frame 045453/0454 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2018
From: CAMPAGNA, MATTHEW JOHN
To: CERTICOM (U.S.) LIMITED
Reel/Frame 044669/0182 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2018
From: BROWN, DANIEL RICHARD L.; EBEID, NEVINE MAURICE NASSIF
To: CERTICOM CORP.
Reel/Frame 044668/0876 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2018
From: CERTICOM (U.S.) LIMITED
To: CERTICOM CORP.
Reel/Frame 045096/0952 →
Continuity (3)
Continuation 14603637 · Jan 23, 2015
Continuation 13536747 · Jun 28, 2012
Related Publication 20180109374A1 · Apr 19, 2018