US2014365777A1PendingUtilityA1

Systems and methods for securing network communications

Assignee: INTERDIGITAL PATENT HOLDINGSPriority: Mar 23, 2011Filed: Aug 21, 2014Published: Dec 11, 2014
Est. expiryMar 23, 2031(~4.6 yrs left)· nominal 20-yr term from priority
H04L 9/0819H04L 63/168H04L 67/42H04L 2209/24H04L 63/062H04L 63/08G06F 21/53H04W 12/02G06F 21/575G06F 2221/2107H04W 12/0431H04L 9/3271G06F 2221/2149G06F 21/335G06F 21/42H04L 67/02H04L 63/0869H04W 12/06H04L 63/0272
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Secure communications may be established amongst network entities for performing authentication and/or verification of the network entities. For example, a user equipment (UE) may establish a secure channel with an identity provider, capable of issuing user identities for authentication of the user/UE. The UE may also establish a secure channel with a service provider, capable of providing services to the UE via a network. The identity provider may even establish a secure channel with the service provider for performing secure communications. The establishment of each of these secure channels may enable each network entity to authenticate to the other network entities. The secure channels may also enable the UE to verify that the service provider with which it has established the secure channel is an intended service provider for accessing services.

Claims

exact text as granted — not AI-modified
What is claimed: 
     
         1 . In a system comprising a user equipment (UE), a network application function (NAF), and a bootstrapping server function (BSF), a method performed at the BSF, the method comprising:
 sending a challenge to the UE over a TLS tunnel established between the UE and the BSF, the TLS tunnel having a TLS master key associated therewith;   in response to the challenge, receiving an authentication response;   verifying that the received authentication response matches an expected value to authenticate the UE;   after authenticating the UE, generating a second key; and   deriving a third key for use in subsequently securing communications between the UE and the NAF, the derivation of the third key being at least partially dependent on both the second key and the TLS master key.   
     
     
         2 . The method of  claim 1 , further comprising calculating the expected value using one or more session initiation protocol digest (SIP-digest) credentials. 
     
     
         3 . The method of  claim 1 , wherein the second key is a generic bootstrapping architecture (GBA) session key (Ks), and the step of deriving the third key comprises:
 deriving the third key from the Ks using a GBA protocol, wherein the third key is an application specific key (Ks_NAF).   
     
     
         4 . The method of  claim 3 , wherein the Ks comprises at least one of an integrity key or a confidentiality key. 
     
     
         5 . The method of  claim 1 , the method further comprising sending the second key and a bootstrapping identity associated with the second key to the UE such that the UE can derive the third key. 
     
     
         6 . A bootstrapping server function (BSF) configured to communicate with a network application function (NAF) and a user equipment, the BSF comprising a memory having computer-executable instructions stored thereon and a processor configured to execute the computer-executable instructions to perform one or more operations comprising:
 sending a challenge to the UE over a TLS tunnel established between the UE and the BSF, the TLS tunnel having a TLS master key associated therewith;   in response to the challenge, receiving an authentication response;   verifying that the received authentication response matches an expected value to authenticate the UE;   after authenticating the UE, generating a second key; and   deriving a third key for use in subsequently securing communications between the UE and the NAF, the derivation of the third key being at least partially dependent on both the second key and the TLS master key.   
     
     
         7 . The BSF of  claim 6 , the operations further comprising calculating the expected value using one or more session initiation protocol digest (SIP-digest) credentials. 
     
     
         8 . The BSF of  claim 6 , wherein the second key is a generic bootstrapping architecture (GBA) session key (Ks), and the step of deriving the third key comprises:
 deriving the third key from the Ks using a GBA protocol, wherein the third key is an application specific key (Ks_NAF).   
     
     
         9 . The BSF of  claim 8 , wherein the Ks comprises at least one of an integrity key or a confidentiality key. 
     
     
         10 . The BSF of  claim 6 , the operations further comprising sending the second key and a bootstrapping identity associated with the second key to the UE such that the UE can derive the third key.

Join the waitlist — get patent alerts

Track US2014365777A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.