Security Feature Negotiation Between Network and User Terminal
Abstract
A Mobile Station (MS), a Base Station System (BSS) and a Mobile Switching Centre (MSC) of a cellular network, such as GSM, are disclosed. According to one embodiment, the MS is arranged to carry out one or more security features in its communication with the network. For example, the MS may be arranged to: by means of information received in a signalling message ( 0 ) from the network, discover if the network supports one or more of said security features, exchange information with the network in order to enable the use of one or more of the above-mentioned supported security features in the communication, carry out at least one of the one or more of the supported security features in the communication with the network.
Claims
exact text as granted — not AI-modified1 . A method in a user equipment in a cellular network, the method comprising:
identifying, by the user equipment, a first authentication key based on an authentication process involving the user equipment and a network node in the cellular network; identifying, by the user equipment, a second authentication key based on the first authentication key; sending, by the user equipment, a first message to a network node, the message comprising information on a plurality of security capabilities of the user equipment; receiving, by the user equipment, a second message from the network node, the second message comprising:
an indication of a selected one or more of the plurality of security capabilities to be used in a future communication with the network node;
data based on user equipment security capability information as received by the network node;
using the second authentication key to verify integrity of the second message; performing a comparison based on at least:
the information on the plurality of security capabilities of the user equipment comprised in the first message sent to the network node; and
the data based on user equipment security capability information as received by the network node comprised in the second message received from the network node; and
when the comparing does not indicate a match, transmitting an error message to the network node.
2 . The method according to claim 1 , comprising deriving the second authentication key using a predefined or agreed-upon principle.
3 . The method according to claim 1 , comprising deriving the second authentication key using a one-way cryptographic hash function.
4 . The method according to claim 1 , wherein the first authentication key is known to or agreed upon by the user equipment and the network node.
5 . The method according to claim 1 , wherein said method takes place during setup of a session between the user equipment and the network node.
6 . The method according to claim 1 , wherein the cellular network is a Long Term Evolution, LTE, network.
7 . The method according to claim 1 , wherein when the comparison indicates a match, using the selected one or more of the plurality of security capabilities in a future communication with the network node.
8 . A user equipment configured to:
identify a first authentication key based on an authentication process involving the user equipment and a network node in a cellular network; identify a second authentication key based on the first authentication key; send a first message to a network node, the message comprising information on a plurality of security capabilities of the user equipment; receive a second message from the network node, the second message comprising:
an indication of a selected one or more of the plurality of security capabilities to be used in a future communication with the network node;
data based on user equipment security capability information as received by the network node;
use the second authentication key to verify integrity of the second message; perform a comparison based on at least:
the information on the plurality of security capabilities of the user equipment comprised in the first message sent to the network node; and
the data based on user equipment security capability information as received by the network node comprised in the second message received from the network node; and
when the comparing does not indicate a match, transmitting an error message to the network node.
9 . The user equipment according to claim 8 , the user equipment being configured to derive the second authentication key using a predefined or agreed-upon principle.
10 . The user equipment according to claim 8 , the user equipment being configured to derive the second authentication key using a one-way cryptographic hash function.
11 . The user equipment according to claim 8 , wherein the first authentication key is known to or agreed upon by the user equipment and the network node.
12 . The user equipment according to claim 8 , wherein said method takes place during setup of a session between the user equipment and the network node.
13 . The user equipment according to claim 8 , wherein the cellular network is a Long Term Evolution, LTE, network.
14 . The user equipment according to claim 8 , the user equipment being configured to use the selected one or more of the plurality of security capabilities in a future communication with the network node when the comparison indicates a match.Join the waitlist — get patent alerts
Track US2016095053A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.