Method, apparatus, and system for preventing abuse of authentication vector
Abstract
A method for preventing abuse of an Authentication Vector (AV) and a system and apparatus for implementing the method are provided. Access network information of a non-3rd Generation Partnership Project (3GPP) access network where a user resides is bound to an AV of the user, so that when the user accesses an Evolved Packet System (EPS) through the non-3GPP access network, even if an entity in the non-3GPP access network is breached, or an Evolved Packet Data Gateway (ePDG) connected to an untrusted non-3GPP access network is breached, the stolen AV cannot be applied to other non-3GPP access networks by an attacker.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for preventing abuse of an Authentication Vector (AV) when a user accesses an Evolved Packet System (EPS) through a non-3rd Generation Partnership Project (non-3GPP) access network, the method comprising:
sending, by an Authorization, Authentication and Accounting Server (AAA server), access network information of the non-3GPP access network where the user resides to a Home Subscriber Server (HSS); receiving, by the AAA server, a key for binding the access network information to an Authentication Vector (AV) of the user, the key calculated according to a formula: Key=K(CK, IK, access network information), wherein CK and IK are two parameters in the AV of the user and K( ) is an algorithm for calculating the key.
2 . The method according to claim 1 , wherein the access network information comprises a Radio Access Technology (RAT) or a combination of an RAT and a network identity of the non-3GPP network.
3 . The method according to claim 2 , wherein:
the RAT indicates that the non-3GPP access network is a Worldwide Interoperability for Microwave Access (Wimax) network, a Code Division Multiple Access (CDMA) 2000 network, a Wireless Local Area Network (WLAN) network, a trusted non-3GPP access network, or an untrusted non-3GPP access network; and the network identity of the non-3GPP access network comprises a Mobile Network Code (MNC) and a Mobile Country Code (MCC).
4 . The method according to claim 1 , wherein the access network information is carried in an Attribute Value Pair (AVP).
5 . The method according to claim 2 , wherein the access network information is carried in an Attribute Value Pair (AVP).
6 . The method according to claim 3 , wherein the access network information is carried in an Attribute Value Pair (AVP).
7 . A Home Subscriber Server (HSS), comprising:
a receiver configured to receive access network information of a non-3rd Generation Partnership Project (non-3GPP) access network where a user resides, wherein the access network information is sent by an Authorization, Authentication and Accounting Server (AAA server); a processor configured to calculate a key for binding the access network information to an Authentication Vector (AV) of the user according to a formula: Key=K(CK, IK, access network information), wherein CK and IK are two parameters in the AV of the user and K( ) is an algorithm for calculating the key; a transmitter configured to send the key provided by the processor to the AAA server; and wherein the access network information comprises a Radio Access Technology (RAT) or a combination of an RAT and a network identity of the non-3GPP network.
8 . The method according to claim 7 , wherein:
the RAT indicates that the non-3GPP access network is a Worldwide Interoperability for Microwave Access (Wimax) network, a Code Division Multiple Access (CDMA) 2000 network, a Wireless Local Area Network (WLAN) network, a trusted non-3GPP access network, or an untrusted non-3GPP access network; and the network identity of the non-3GPP access network comprises a Mobile Network Code (MNC) and a Mobile Country Code (MCC).
9 . The method according to claim 7 , wherein the access network information is carried in an Attribute Value Pair (AVP).
10 . The method according to claim 8 , wherein the access network information is carried in an Attribute Value Pair (AVP).
11 . An Authorization, Authentication and Accounting Server (AAA server), the AAA server comprising:
a transmitter configured to send access network information of a non-3rd Generation Partnership Project (3GPP) access network where a user resides to a Home Subscriber Server (HSS); a receiver configured to receive a key for binding the access network information to an Authentication Vector (AV) of the user, the key calculated according to a formula: Key=K(CK, IK, access network information), wherein CK and IK are two parameters in the AV of the user and K( ) is an algorithm for calculating the key; and wherein the access network information comprises a Radio Access Technology (RAT) or a combination of an RAT and a network identity of the non-3GPP network.
12 . The method according to claim 11 , wherein:
the RAT indicates that the non-3GPP access network is a Worldwide Interoperability for Microwave Access (Wimax) network, a Code Division Multiple Access (CDMA) 2000 network, a Wireless Local Area Network (WLAN) network, a trusted non-3GPP access network, or an untrusted non-3GPP access network; and the network identity of the non-3GPP access network comprises a Mobile Network Code (MNC) and a Mobile Country Code (MCC).
13 . The method according to claim 11 , wherein the access network information is carried in an Attribute Value Pair (AVP).
14 . The method according to claim 12 , wherein the access network information is carried in an Attribute Value Pair (AVP).Join the waitlist — get patent alerts
Track US2014053249A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.