US2003235305A1PendingUtilityA1

Key generation in a communication system

Priority: Jun 20, 2002Filed: Jun 20, 2002Published: Dec 25, 2003
Est. expiryJun 20, 2022(expired)· nominal 20-yr term from priority
Inventors:Raymond Hsu
H04W 74/00H04L 2463/061H04L 2209/80H04L 2209/805H04L 63/062H04L 9/0844H04L 63/0892H04L 63/08H04W 84/12H04W 48/08H04L 12/28H04L 9/32H04W 12/041H04W 12/062H04W 12/043H04W 12/069
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A communication system generates a Master Session Key (MSK) for accesses to a system entity that does not provide encryption to traffic. Both the home server and the user generate the same MSK. The MSK is used to generate encryption keys for traffic. In one embodiment the MSK is generated using a hashing function and information specific to the requestor. The home server determines the need to generate the MSK based on information contained in an access request message. Once generated, the MSK is provided to the system entity to enable the entity to encrypt communications.

Claims

exact text as granted — not AI-modified
What is claimed is:  
     
         1 . A method for key generation in a communication system, comprising: 
 authenticating an access to a Wireless Local Area Network (WLAN);    generating a Master Session Key (MSK) for the access; and    sending an access accept message including the MSK.    
     
     
         2 . The method as in  claim 1 , wherein authenticating comprises: 
 receiving a user identification;    determining a challenge value; and    determining the shared secret,    and wherein generating an MSK comprises:    hashing the user identification, the challenge value and the shared secret.    
     
     
         3 . The apparatus as in  claim 2 , wherein the user identification is a Network Access Identifier (NAI).  
     
     
         4 . The method as in  claim 1 , wherein authenticating comprises: 
 receiving a user identification;    determining a challenge value; and    determining a random value,    and wherein generating an MSK comprises:    hashing the user identification, the challenge value and the random value.    
     
     
         5 . The apparatus as in  claim 4 , wherein the apparatus identifier is a Network Access Identifier (NAI).  
     
     
         6 . A method for key generation in a communication system, comprising: 
 requesting authentication of an access to a Wireless Local Area Network (WLAN);    receiving an access accept message including a Master Session Key (MSK) for the access; and    generating at least one encryption key as a function of the MSK, wherein the at least one encryption key is used to encrypt traffic for the access.    
     
     
         7 . An apparatus for key generation in a communication system, comprising: 
 means for authenticating an access to a Wireless Local Area Network (WLAN);    means for generating a Master Session Key (MSK) for the access; and    means for determining an encryption key from the MSK.    
     
     
         8 . An apparatus for key generation in a communication system, comprising: 
 means for requesting authentication of an access to a Wireless Local Area Network (WLAN);    means for receiving an access accept message including a Master Session Key (MSK) for the access; and    means for generating at least one encryption key as a function of the MSK, wherein the at least one encryption key is used to encrypt traffic for the access.    
     
     
         9 . An apparatus, comprising: 
 a processing unit;    an authentication procedure unit coupled to the processing unit, adapted to request authentication of an access to a system, and adapted to compute a response to a challenge for the authentication; and    a Master Session Key (MSK) generation unit coupled to the processing unit, adapted to generate an MSK, wherein the MSK is for generating at least one encryption key to encrypt traffic for the access.    
     
     
         10 . The apparatus as in  claim 9 , wherein the MSK is generated using an apparatus identifier, a shared secret, and the challenge.  
     
     
         11 . The apparatus as in  claim 10 , wherein the apparatus identifier is a Network Access Identifier (NAI).  
     
     
         12 . The apparatus as in  claim 9 , wherein the MSK is generated using an apparatus identifier, a shared secret, and a random number.  
     
     
         13 . The apparatus as in  claim 12 , wherein the apparatus identifier is a Network Access Identifier (NAI).  
     
     
         14 . A method in a communication system, comprising: 
 receiving an access request message for an access to the communication system, the access request message having a first field;    determining the state of the first field; and    if the state is a first value, generating a Master Session Key (MSK) for the access.    
     
     
         15 . The method as in  claim 14 , further comprising: 
 sending an access accept message, wherein:    if the state is the first value the access accept message includes the MSK.    
     
     
         16 . The method as in  claim 15 , further comprising: 
 authenticating the access.    
     
     
         17 . The method as in  claim 14 , wherein the first field corresponds to an attribute indicating an access to an entity of the communication system that does not support encryption.  
     
     
         18 . The method as in  claim 17 , wherein the entity is a Wireless Local Area Network (WLAN).  
     
     
         19 . The method as in  claim 14 , wherein the first field corresponds to an attribute indicating origination of the access request message  
     
     
         20 . The method as in  claim 14 , further comprising: 
 authenticating the access by: 
 receiving a user identification;  
 determining a challenge value; and  
 determining the shared secret,  
 and wherein generating the MSK comprises:  
   hashing the user identification, the challenge value and the shared secret.    
     
     
         21 . The method as in  claim 14 , further comprising: 
 authenticating the access by: 
 receiving a user identification;  
 determining a challenge value; and  
 determining a random value,  
 and wherein generating the MSK comprises:  
   hashing the user identification, the challenge value and the random value.    
     
     
         22 . An infrastructure element in a communication system, comprising: 
 means for receiving an access request message for an access to the communication system, the access request message having a first field;    means for determining the state of the first field; and    means for generating a Master Session Key (MSK) for the access if the state is a first value.    
     
     
         23 . An access request message format for a communication system, comprising: 
 a type field identifying a type of attribute information for an access to the communication system; and    a value field for the attribute information, the value field comprising: 
 a second type field identifying a type of sub-attribute information for the access; and  
 a second value field for the sub-attribute information.  
   
     
     
         24 . The access request message format as in  claim 23 , wherein the sub-attribute information is a Master Session Key (MSK) generation instruction.

Join the waitlist — get patent alerts

Track US2003235305A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.