Authentication method based on GBA, and device thereof

    公开(公告)号:US11751051B2

    公开(公告)日:2023-09-05

    申请号:US17289968

    申请日:2019-08-07

    CPC classification number: H04W12/06 G06F21/575 H04W12/72 G06F2221/034

    Abstract: proviced is an authentication method based on a GBA, and the method includes: a BSF receives an initialization request message sent by a UE, wherein the initialization request message carries a first identifier of the UE, and the first identifier comprises at least one of the following: a SUCI, an identifier converted from the SUCI, and a TMPI associated with the subscriber identity; the BSF acquires an AV of the UE according to the first ID; the BSF completes GBA authentication with the UE according to the acquired AV. In this way, the privacy of the SUPI is protected for the UE, and the SUCI or the identifier converted from the SUCI is used to perform the bootstrapping process of the GBA, thereby improving the security of the GBA authentication process.

    Network device and authentication therof and key management method
    5.
    发明申请
    Network device and authentication therof and key management method 有权
    网络设备认证和密钥管理方法

    公开(公告)号:US20150172047A1

    公开(公告)日:2015-06-18

    申请号:US14407525

    申请日:2013-05-28

    Abstract: Provided is a network equipment and an authentication and key management method for the same. The network equipment generates a Network Key (NK); the network equipment performs authentication protocol interaction with opposite communication equipment, and calculates a Basic Session Key (BSK) according to parameters for the authentication protocol interaction and the NK; and the network equipment calculates link Encryption Keys (EKs) used respectively for Media Access Control (MAC) and Physical (PHY) layers using various access technologies according to the BSK, and provides the EKs for respective MAC and PHY layer function modules. With the disclosure, the legality of the equipment is verified by performing an authentication process on the heterogeneous network equipments in one pass, and keys in various MAC layer technologies are managed in a unified way.

    Abstract translation: 提供了一种网络设备及其认证和密钥管理方法。 网络设备产生网络密钥(NK); 网络设备与相对的通信设备进行认证协议交互,并根据认证协议交互和NK的参数计算基本会话密钥(BSK); 并且网络设备根据BSK使用各种接入技术来计算分别用于媒体接入控制(MAC)和物理(PHY)层的链路加密密钥(EK),并为相应的MAC和PHY层功能模块提供EK。 通过本公开,通过一次性对异构网络设备进行认证处理来验证设备的合法性,并且以统一的方式管理各种MAC层技术中的密钥。

Patent Agency Ranking