Systems and methods for securing network communications
Abstract
Secure communications may be established amongst network entities for performing authentication and/or verification of the network entities. For example, a user equipment (UE) may establish a secure channel with an identity provider, capable of issuing user identities for authentication of the user/UE. The UE may also establish a secure channel with a service provider, capable of providing services to the UE via a network. The identity provider may even establish a secure channel with the service provider for performing secure communications. The establishment of each of these secure channels may enable each network entity to authenticate to the other network entities. The secure channels may also enable the UE to verify that the service provider with which it has established the secure channel is an intended service provider for accessing services.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . In a system comprising a user equipment (UE), a network application function (NAF), and a bootstrapping server function (BSF), a method performed at the BSF, the method comprising:
sending a challenge to the UE over a TLS tunnel established between the UE and the BSF, the TLS tunnel having a TLS master key associated therewith; in response to the challenge, receiving an authentication response; verifying that the received authentication response matches an expected value to authenticate the UE; after authenticating the UE, generating a second key; and deriving a third key for use in subsequently securing communications between the UE and the NAF, the derivation of the third key being at least partially dependent on both the second key and the TLS master key.
2 . The method of claim 1 , further comprising calculating the expected value using one or more session initiation protocol digest (SIP-digest) credentials.
3 . The method of claim 1 , wherein the second key is a generic bootstrapping architecture (GBA) session key (Ks), and the step of deriving the third key comprises:
deriving the third key from the Ks using a GBA protocol, wherein the third key is an application specific key (Ks_NAF).
4 . The method of claim 3 , wherein the Ks comprises at least one of an integrity key or a confidentiality key.
5 . The method of claim 1 , the method further comprising sending the second key and a bootstrapping identity associated with the second key to the UE such that the UE can derive the third key.
6 . A bootstrapping server function (BSF) configured to communicate with a network application function (NAF) and a user equipment, the BSF comprising a memory having computer-executable instructions stored thereon and a processor configured to execute the computer-executable instructions to perform one or more operations comprising:
sending a challenge to the UE over a TLS tunnel established between the UE and the BSF, the TLS tunnel having a TLS master key associated therewith; in response to the challenge, receiving an authentication response; verifying that the received authentication response matches an expected value to authenticate the UE; after authenticating the UE, generating a second key; and deriving a third key for use in subsequently securing communications between the UE and the NAF, the derivation of the third key being at least partially dependent on both the second key and the TLS master key.
7 . The BSF of claim 6 , the operations further comprising calculating the expected value using one or more session initiation protocol digest (SIP-digest) credentials.
8 . The BSF of claim 6 , wherein the second key is a generic bootstrapping architecture (GBA) session key (Ks), and the step of deriving the third key comprises:
deriving the third key from the Ks using a GBA protocol, wherein the third key is an application specific key (Ks_NAF).
9 . The BSF of claim 8 , wherein the Ks comprises at least one of an integrity key or a confidentiality key.
10 . The BSF of claim 6 , the operations further comprising sending the second key and a bootstrapping identity associated with the second key to the UE such that the UE can derive the third key.Join the waitlist — get patent alerts
Track US2014365777A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.