EP1695480A1 - Method and apparatus for authenticating subscriber and network in wireless internet system - Google Patents

Method and apparatus for authenticating subscriber and network in wireless internet system

Info

Publication number
EP1695480A1
EP1695480A1 EP04774379A EP04774379A EP1695480A1 EP 1695480 A1 EP1695480 A1 EP 1695480A1 EP 04774379 A EP04774379 A EP 04774379A EP 04774379 A EP04774379 A EP 04774379A EP 1695480 A1 EP1695480 A1 EP 1695480A1
Authority
EP
European Patent Office
Prior art keywords
nurber
encryption key
network
random
private key
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Withdrawn
Application number
EP04774379A
Other languages
German (de)
French (fr)
Other versions
EP1695480A4 (en
Inventor
Mun-Kyu Lee
Do-Woo Kim
Sung-Ik Jun
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Electronics and Telecommunications Research Institute ETRI
Original Assignee
Electronics and Telecommunications Research Institute ETRI
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Electronics and Telecommunications Research Institute ETRI filed Critical Electronics and Telecommunications Research Institute ETRI
Publication of EP1695480A1 publication Critical patent/EP1695480A1/en
Publication of EP1695480A4 publication Critical patent/EP1695480A4/en
Withdrawn legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0869Network architectures or network communication protocols for network security for authentication of entities for achieving mutual authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • H04L9/0869Generation of secret information including derivation or calculation of cryptographic keys or passwords involving random numbers or seeds
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/14Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/321Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3271Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
    • H04L9/3273Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response for mutual authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/80Wireless
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/061Network architectures or network communication protocols for network security for supporting key management in a packet data network for key exchange, e.g. in peer-to-peer networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0853Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/69Identity-dependent
    • H04W12/72Subscriber identity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/08Access restriction or access information delivery, e.g. discovery data delivery
    • H04W48/10Access restriction or access information delivery, e.g. discovery data delivery using broadcasted information
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W80/00Wireless network protocols or protocol adaptations to wireless operation
    • H04W80/04Network layer protocols, e.g. mobile IP [Internet Protocol]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/16Gateway arrangements

Definitions

  • the present invention relates to a method and an apparatus for authenticating a subscriber and a network, by which the subscriber and the network are provided with mutual authentication and share a key in a wireless Internet system.
  • Subscriber authentication is usually performed using an ID and a password in wireless Internet.
  • This method has two problems. Firstly, since a password is transmitted without being coded, the method is fatally vulnerable in terms of security. Secondly, the method just allows a network to authenticate a subscriber but does not provide a function that allows the subscriber to authenticate the network. That is, the method does not provide mutual authentication. Accordingly, a subscriber is always exposed to the danger of malicious use of an ID/password and the danger of revealing personal information to fake servers. Disclosure of Invention Technical Problem
  • the present invention provides a method and an apparatus for enabling mutual authentication between a network and a user under an existing subscriber identity module (SIM) structure in a wireless Internet system with a minimuri nutrber of messages between the subscriber and the network.
  • SIM subscriber identity module
  • a method of authenticating a subscriber and a network in a wireless Internet system includes a wireless Internet gateway broadcasting an agent advertisement to its subnetwork; a mobile station transmitting a network access identifier containing a first random nutrber and a mobile subscriber identity to the gateway, when entering the sub-network of the gateway ; the gateway transmitting the mobile subscriber identity and the first random n rber to an authentication server; the authentication server extracting a private key using the mobile subscriber identity, generating RES1 using the private key and the first random number, and generating XRES2 using the private key and a second random nurber; the authentication server transmitting the RES1, the second random nurber, and the XRES2 to the gateway; the gateway storing the XRES2 and transmitting the RES 1 and the second random nurber to the mobile station; the mobile station generating XRES1 using the private key and the first random number that are stored therein and comparing the X
  • an apparatus for authenticating a subscriber and a network in a wireless Internet system includes a mobile station which transmits a network access identifier containing a first random nurber and a mobile subscriber identity to a gateway when entering a sub- network of the gateway, generates XRES1 using a private key and the first random number that are stored therein, compares the XRES1 with RES1 received from the gateway to authenticate the network, generates RES2 using the private key and a second random nurber received from the gateway, and transmits the RES2 to the gateway; the gateway which broadcasts an agent advertisement to the sub-network, extracts the mobile subscriber identity and the first random nurber from the network access identifier received from the mobile station entering the sub-network, transmits the mobile subscriber identity and the first random nurber to an authentication server, stores XRES2 received from the authentication server, transmits the RES 1 and the second random nurber to the mobile station, and compares the
  • a n authentication server including a private key extractor which fetches a private key from a DB using a received mobile subscriber identity; a first signal generator which generates a first encryption key and RES1, which is used by a mobile station for network authentication, using the private key and a received first random nurber; a random number generator which generates a second random nutrber; a second signal generator which generates a second encryption key and XRES2, which is used for subscriber authentication, using the private key and the second random nurber; and an encryption key generator which generates a third encryption key by combining the first encryption key and the second encryption key.
  • an apparatus for authenticating a network in a mobile station receives RES 1 and a second random number and includes a random number generator which generates a first random number; a first signal generator which generates a first encryption key and network authentication information XRES 1 using a private key stored therein and the first random nurber; a comparator which compares the XRES 1 with the received RES 1 to authenticate the network; a second signal generator which generates a second encryption key and subscriber authentication information XRES2 using the private key and the received second random number; and an encryption key generator which generates a third encryption key by combining the first encryption key and the second encryption key.
  • a subscriber and a network can mutually authenticate each other using only two pairs of request and reply messages. Also, the subscriber and the network can share a 128-bit encryption key for secure communication using an authentication algorithm used in a conventional SIM-type mobile communication network without any change. Accordingly, security of a wireless Internet network is enhanced at a rninii im cost, and mobile c ⁇ rmunication network and wireless Internet network co-work effectively.
  • FIG. 1 illustrates an entire system including a mobile ccxrmunication network and a wireless Internet network , according to an errbodiment of the present invention
  • FIG. 2 illustrates a protocol for mutual authentication between a mobile station and a wireless Internet network
  • FIG. 3 illustrates a data format of a temporary network access identifier (TNAI);
  • FIG. 4 is a block diagram of an authentication, authorization & accounting server in home side (AAAH).
  • FIG. 5 is a block diagram of an apparatus for authenticating a network in a mobile station. Best Mode [15]
  • errbodiments of the present invention will be described in detail with reference to the accompanying drawings.
  • FIG. 1 illustrates an entire system including a mobile c ⁇ rmunication network and a wireless Internet network , according to an errbodiment of the present invention.
  • a subscriber identity module (SIM) 11 shown in FIG. 1 is inserted into a mobile station (MS) 10.
  • MS mobile station
  • the MS 10 When using the mobile c ⁇ rmunication network, the MS 10 is authenticated by a home location register (HLR) 14 via a base station (BS) 12 and a mobile switching center (MSC) 13.
  • HLR home location register
  • MSC mobile switching center
  • the MS 10 is authenticated by an authentication, authorization & accounting server in home side (AAAH) 18 connected to an access point (AP) 15 via a home agent (HA) 17 and a foreign agent (FA) 16.
  • AAAH authentication, authorization & accounting server in home side
  • AP access point
  • HA home agent
  • FA foreign agent
  • the HLR 14 and the AAAH 18 should be able to access a database (DB) storing a private key corresponding to the SIM 11.
  • DB database
  • a wireless c ⁇ rmunication system e.g., a 3G packet network supporting a mobile Internet protocol (IP)
  • IP mobile Internet protocol
  • two types of Internet access gateways are present as network devices that can allocate an IP address to the MS 10.
  • One is a packet data service node (PDSN) referred to as an FA
  • the other is an HA.
  • the FA allocates an IP address to an MS requesting a simple IP service
  • the HA allocates an IP address to an MS requesting a mobile IP service.
  • the IP address allocated by the FA is discarded after the service ends while the IP address allocated by the HA is valid as far as the MS does not move to an area of another HA.
  • Packet c ⁇ rmunication systems supporting a dynamic IP service are configured based on a domain and are connected to each other through the Internet.
  • Each domain includes a mobile c ⁇ rmunication system and network devices for a packet call service.
  • the mobile c ⁇ rmunication system includes a base transceiver system (BTS) and a base station controller (BSC), which are used in a digital cellular network, a personal c ⁇ rmunications service (PCS) network, and a next generation of a mobile communication network, International Mobile Teleccmnunications (IMT)-2000 (e.g., CDMA2000 or UMTS).
  • the network devices for a packet call service include an HA supporting a dynamic IP service, a PDSN, an authentication, authorization & accounting (AAA) server, a domain name system (DNS) server, and a dynamic host configuration protocol (DHCP) server.
  • AAA authentication, authorization & accounting
  • DNS domain name system
  • DHCP dynamic host configuration
  • An MS accesses a PDSN through a wireless channel.
  • the PDSN or an HA allocates an IP address to the MS requesting a packet call.
  • the IP address allocated by the PDSN is changed when the MS moves to an area of another PDSN, but the IP address allocated by the HA is fixed within a current domain.
  • An AAA server performs authentication, authorization, and accounting with respect to wireless c ⁇ rmunications network subscribers.
  • a security channel is formed between AAA servers.
  • An AAA server identifies a subscriber using a network access identifier (NAI), associates the NAI with a DNS server, and updates a DNS server through the security channel when an IP address is allocated dynamically.
  • NAI network access identifier
  • a host wanting c ⁇ rmunication with a mobile host cannot know a dynamically allocated IP address of the mobile host, and therefore, the DNS server needs to be updated dynamically.
  • a DNS server is a distributed naming system that maps a domain name to an IP address.
  • the DNS server dynamically updates domain names at the requests of network devices so that a fixed domain name is mapped to a changing IP address.
  • a domain name is an address expressed in text to identify a host accessing the Internet and is easier to memorize and more intuitive than an IP address configured with numerals.
  • FIG. 2 illustrates a protocol for mutual authentication between an MS 10 and a wireless Internet network.
  • An FA 16 connected to the wireless Internet network continuously broadcasts an agent advertisement (AA) 20 to its sub-network according to a mobile IP protocol. If the MS 10 enters the sub-network of the FA 16, the MS 10 recognizes the AA 20. Then, the MS 10 generates a first random nurber (RAND1) in step 211 and transmits a registration request (R_Req) 21 to the FA 16.
  • the R_Req 21 contains a care-of-address (Co A) received from the FA 16 and an NAI corresponding to a subscriber's ID.
  • the FA 16 transmits the R_Req 21 as an R_Req 22 to an HA 17.
  • a new type of NAI i.e., a temporary NAI (TNAI)
  • TNAI temporary NAI
  • FIG. 3 illustrates a data format of a TNAI contained in an R_Req message that is generated by the MS 10 and then transmitted sequentially to the FA 16 and HA 17.
  • the TNAI includes an international mobile subscriber identity (IMSI) 31, a first random number (RAND1) that has a length of 128 bits and is generated by an SIM 11 for network authentication, and a Realm 34 indicating a domain to which a subscriber belongs.
  • IMSI international mobile subscriber identity
  • RAND1 first random number
  • Realm 34 indicating a domain to which a subscriber belongs.
  • a tag 30 indicates the authentication method which is intended to be used, and a separator 33 is a mark that separates the IMSI 31 from the Realm 34.
  • the tag 30 and the separator 33 are encoded into, for example, 1-byte ASCII codes corresponding to 9 and @, respectively.
  • the IMSI 31 is encoded into a 15-byte text string where each byte is composed of one of ASCII codes 0x30-0x39 corresponding to 0-9.
  • the RAND1 32 is set by encoding a 128-bit random number to a length of 22 bytes using BASE-64 encoding.
  • the Realm 34 is encoded into a text string corresponding to the domain name.
  • the HA 17 having received the R_Req 22 from the FA 16 extracts the IMSI 31 and the RAND1 32 from the TNAI, generates and transmits an authentication request (A_Req) 23 to an AAAH 18.
  • the AAAH 18 extracts subscriber information and a private key Ki from a DB using the IMSI 31, generates RESl, RAND2, XRES2, and Kc in step 231, and transmits them as an authentication reply (A_Reply) 24 to the HA 17.
  • the HA 17 transmits the A_Reply 24, received from the AAAH 18 as a registration reply (R_Reply) 25 to the FA 16.
  • RESl indicates information used by the MS 10 to authenticate the network
  • XRES2 indicates information used by the FA 16 to authenticate the subscriber.
  • RAND2 is a second random number randomly generated to have 128 bits in length by the AAAH 18.
  • Kc is a 128-bit encryption key generated by combining a 64-bit encryption key Kcl generated using Ki and RAND1 and a 64-bit encryption key Kc2 generated using Ki and RAND2.
  • FIG. 4 is a block diagram illustrating operations of the AAAH 18 while the above- described authentication protocol is performed.
  • Subscriber information and a private key Ki are extracted from a DB 41 using an IMSI received from the HA 17.
  • a first signal generator 42 generates a 64-bit encryption key Kcl in a block 421 and RESl in a block 422 based on the private key Ki and RAND1.
  • a second signal generator 43 generates a 64-bit encryption key Kc2 in a block 431 and XRES2 in a block 432 based on the private key Ki and RAND2.
  • the A8 algorithm used in the blocks 421 and 431 and the A3 algorithm used in the blocks 422 and 432 are predefined authentication/ encryption algorithms in a mobile c ⁇ rmunication network.
  • the RAND2 is a random number generated by a random nurber generator 45.
  • FIG. 5 is a block diagram of an apparatus for authenticating a network in the MS 10 while the authentication protocol is performed.
  • the SIM 11 shown in FIG. 1 included within the MS 10 receives the RESl and the RAND2 from the FA 16. Then, a first signal generator 52 generates authentication information XRES 1 in a block 522 using the private key Ki and the RAND1 that have been stored in the MS 10 in step 213.
  • a comparator 54 compares the XRES1 with the RESl received from the FA 16 in step 215 to authenticate the network.
  • the RAND1 is a random nurber that have been generated by a random number generator 51.
  • the first signal generator 52 generates a 64-bit encryption key Kcl in a block 521.
  • a second signal generator 53 generates subscriber authentication information RES2 in a block 532 and a 64-bit encryption key Kc2 in a block 531 using the RAND2 received from the FA 16 and the private key Ki. Then, in step 217, the RES2 is transmitted to the FA 16, and the encryption keys Kcl and Kc2 are combined to generate a 128-bit encryption key Kc.
  • the RES2 generated by the SIM 11 of the MS 10 is errbedded into an A_Req 27 and transmitted to the FA 16.
  • the FA 16 compares the RES2 received from the MS 10 with the XRES2 stored therein in step 221 to authenticate the subscriber. If authentication succeeds, a SUCCESS message is embedded into an A_Reply 28 and transmitted to the MS 10.
  • an MS 10
  • the MS transmits an NAI containing a first random nurber and an IMSI to the gateway, generates XRES1 using a private key and the first random number that are stored therein, compares the XRES 1 with RES 1 received from the gateway to authenticate a network, generates RES2 using the private key and a second random nurber received from the gateway, and transmits the RES2 to the gateway.
  • a gateway (16, 17) broadcasts an AA to its sub-network, extracts an IMSI and a first random number from an NAI received from an MS entering the sub-network, transmits the IMSI and the first random number to an AAAH (or an authentication server), stores XRES2 received from the AAAH, transmits RESl and a second random number to the MS, and compares RES2 received from the MS with XRES2 stored therein to authenticate a subscriber.
  • AAAH or an authentication server
  • the AAAH ( 18) fetches a private key from a DB using IMSI, generates RES 1 using the private key and a first random nutrber, generates XRES2 using the private key and a second rand n nurber, and transmits the RESl, the second randan number, and the XRES2 to a gateway.
  • the AAAH (18) generates a first encryption key using the private key and the first randan nurber, generates a second encryption key using the private key and the second random nurber, generates a third encryption key by combining the first and second encryption keys, and transmits the third encryption key to the gateway.
  • the gateway stores the third encryption key
  • the MS generates a fourth encryption key using the private key and the first random nurber stored therein, generates a fifth encryption key using the private key and the second random nurber, and generates a sixth encryption key by combining the fourth and fifth encryption keys.
  • the third encryption key generated by the AAAH (18) and the sixth encryption key generated by the MS (10) share the same value.
  • messages transferred between the MS 10 and the FA 16 for mutual authentication between a subscriber and a network include the A A 20 periodically broadcasted by the FA 16 and two pairs of request and reply messages, i.e., R_Req 21, R_Reply 26, A_Req 27, and A_Reply 28.
  • the MS 10 and the FA 16 share the 128-bit encryption key Kc.
  • the mutual authentication between the subscriber and the network can be accomplished using only two pairs of request and reply messages transferred between the MS 10 and the FA 16 in addition to the A A periodically broadcasted by the FA 16 in a wireless Internet network.
  • an algorithm of generating an encryption key is repeated two times in the SIM 11, an effective encryption key is lengthened.
  • the invention can also be embodied as computer readable codes on a computer readable recording medium.
  • the computer readable recording medium is any data storage device that can store data which can be thereafter read by a computer system. Examples of the computer readable recording medium include read-only memory (ROM), random-access memory (RAM), CD-ROMs, magnetic tapes, floppy disks, optical data storage devices, and carrier waves (such as data transmission through the Internet).
  • ROM read-only memory
  • RAM random-access memory
  • CD-ROMs compact discs
  • magnetic tapes magnetic tapes
  • floppy disks optical data storage devices
  • carrier waves such as data transmission through the Internet
  • a subscriber and a network can mutually authenticate each other using only two pairs of request and reply messages. Also, the subscriber and the network can share a 128-bit encryption key for secure c ⁇ rmunication using an authentication algorithm used in a conventional SIM- type mobile c ⁇ rmunication network without any change. Accordingly, security of a wireless Internet network is enhanced at a minimun cost, and mobile communication network and wireless Internet network co-work effectively.
  • the present invention provides mutual authentication between a subscriber and a network using an SIM and a means for allowing a key to be shared by the subscriber and the network.
  • the subscriber and the network in a wireless Internet system exchange miniinum nurber of request and reply messages and can use an authentication algorithm used in a conventional SIM-type mobile c ⁇ rmunication network.
  • the present invention modifies a subscriber authentication method based on an SIM in a second generation mobile communication network, thereby enabling network authentication, and enhances security by increasing the nurber of effective bits of an encryption key shared by a subscriber and a network after authentication. According to the present invention, an unauthorized user is prevented fr ⁇ n using a network through subscriber authentication, and a subscriber's personal information is protected from being revealed to a fake server through authentication of a network and a server.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

Provided are a method and an apparatus for authenticating a subscriber and a network, by which the subscriber and the network are provided with mutual authentication and share a key in a wireless Internet system. An authentication server generates information RES1, which is used by a mobile station for network authentication, using a private key and a first random number; and generates information XRES2, which is used for subscriber authentication, using the private key and a second random number. The mobile station generates network authentication information XRES1 using the private key and the first random number; and generates subscriber authentication information RES2 using the private key and the second random number. The mobile station compares the XRES1 with the RES1 to authenticate the network, and a gateway connected to the authentication server compares the XRES2 with the RES2 to authenticate the subscriber. Accordingly, an unauthorized user is prevented from using a network, and a subscriber's personal information is protected from being revealed to a fake server.

Description

Description METHOD AND APPARATUS FOR AUTHENTICATING SUBSCRIBER AND NETWORK IN WIRELESS INTERNET SYSTEM Technical Field
[1] The present invention relates to a method and an apparatus for authenticating a subscriber and a network, by which the subscriber and the network are provided with mutual authentication and share a key in a wireless Internet system. Background Art
[2] Subscriber authentication is usually performed using an ID and a password in wireless Internet. This method has two problems. Firstly, since a password is transmitted without being coded, the method is fatally vulnerable in terms of security. Secondly, the method just allows a network to authenticate a subscriber but does not provide a function that allows the subscriber to authenticate the network. That is, the method does not provide mutual authentication. Accordingly, a subscriber is always exposed to the danger of malicious use of an ID/password and the danger of revealing personal information to fake servers. Disclosure of Invention Technical Problem
[3] The present invention provides a method and an apparatus for enabling mutual authentication between a network and a user under an existing subscriber identity module (SIM) structure in a wireless Internet system with a minimuri nutrber of messages between the subscriber and the network. Technical Solution
[4] According to an aspect of the present invention, there is provided a method of authenticating a subscriber and a network in a wireless Internet system. The method includes a wireless Internet gateway broadcasting an agent advertisement to its subnetwork; a mobile station transmitting a network access identifier containing a first random nutrber and a mobile subscriber identity to the gateway, when entering the sub-network of the gateway ; the gateway transmitting the mobile subscriber identity and the first random n rber to an authentication server; the authentication server extracting a private key using the mobile subscriber identity, generating RES1 using the private key and the first random number, and generating XRES2 using the private key and a second random nurber; the authentication server transmitting the RES1, the second random nurber, and the XRES2 to the gateway; the gateway storing the XRES2 and transmitting the RES 1 and the second random nurber to the mobile station; the mobile station generating XRES1 using the private key and the first random number that are stored therein and comparing the XRES1 with the RES1 received from the gateway to authenticate the network; the mobile station generating RES2 using the private key and the second random nurber and transmitting the RES2 to the gateway; and the gateway comparing the RES2 received from the mobile station with the XRES2 stored therein to authenticate the subscriber.
[5] According to another aspect of the present invention, there is provided an apparatus for authenticating a subscriber and a network in a wireless Internet system. The apparatus includes a mobile station which transmits a network access identifier containing a first random nurber and a mobile subscriber identity to a gateway when entering a sub- network of the gateway, generates XRES1 using a private key and the first random number that are stored therein, compares the XRES1 with RES1 received from the gateway to authenticate the network, generates RES2 using the private key and a second random nurber received from the gateway, and transmits the RES2 to the gateway; the gateway which broadcasts an agent advertisement to the sub-network, extracts the mobile subscriber identity and the first random nurber from the network access identifier received from the mobile station entering the sub-network, transmits the mobile subscriber identity and the first random nurber to an authentication server, stores XRES2 received from the authentication server, transmits the RES 1 and the second random nurber to the mobile station, and compares the RES2 received from the mobile station with the XRES2 stored therein to authenticate the subscriber; and the authentication server which fetches the private key from a DB using the mobile subscriber identity , generates the RES1 using the private key and the first random number, generates the XRES2 using the private key and the second random nurber, and transmits the RES1, the second random nutrber, and the XRES2 to the gateway.
[6] According to still another aspect of the present invention, there is provided a n authentication server including a private key extractor which fetches a private key from a DB using a received mobile subscriber identity; a first signal generator which generates a first encryption key and RES1, which is used by a mobile station for network authentication, using the private key and a received first random nurber; a random number generator which generates a second random nutrber; a second signal generator which generates a second encryption key and XRES2, which is used for subscriber authentication, using the private key and the second random nurber; and an encryption key generator which generates a third encryption key by combining the first encryption key and the second encryption key.
[7] According to yet another aspect of the present invention, there is provided an apparatus for authenticating a network in a mobile station. The apparatus receives RES 1 and a second random number and includes a random number generator which generates a first random number; a first signal generator which generates a first encryption key and network authentication information XRES 1 using a private key stored therein and the first random nurber; a comparator which compares the XRES 1 with the received RES 1 to authenticate the network; a second signal generator which generates a second encryption key and subscriber authentication information XRES2 using the private key and the received second random number; and an encryption key generator which generates a third encryption key by combining the first encryption key and the second encryption key. Advantageous Effects
[8] According to the present invention, a subscriber and a network can mutually authenticate each other using only two pairs of request and reply messages. Also, the subscriber and the network can share a 128-bit encryption key for secure communication using an authentication algorithm used in a conventional SIM-type mobile communication network without any change. Accordingly, security of a wireless Internet network is enhanced at a rninii im cost, and mobile cαrmunication network and wireless Internet network co-work effectively. Description of Drawings
[9] The above and other features and advantages of the present invention will become more apparent by describing in detail preferred errbodiments thereof with reference to the attached drawings in which:
[10] FIG. 1 illustrates an entire system including a mobile ccxrmunication network and a wireless Internet network , according to an errbodiment of the present invention;
[11] FIG. 2 illustrates a protocol for mutual authentication between a mobile station and a wireless Internet network;
[12] FIG. 3 illustrates a data format of a temporary network access identifier (TNAI);
[13] FIG. 4 is a block diagram of an authentication, authorization & accounting server in home side (AAAH); and
[14] FIG. 5 is a block diagram of an apparatus for authenticating a network in a mobile station. Best Mode [15] Hereinafter, errbodiments of the present invention will be described in detail with reference to the accompanying drawings.
[16] FIG. 1 illustrates an entire system including a mobile cαrmunication network and a wireless Internet network , according to an errbodiment of the present invention. A subscriber identity module (SIM) 11 shown in FIG. 1 is inserted into a mobile station (MS) 10.
[17] When using the mobile cαrmunication network, the MS 10 is authenticated by a home location register (HLR) 14 via a base station (BS) 12 and a mobile switching center (MSC) 13. When using the wireless Internet network, the MS 10 is authenticated by an authentication, authorization & accounting server in home side (AAAH) 18 connected to an access point (AP) 15 via a home agent (HA) 17 and a foreign agent (FA) 16. In order to use the same SIM 11 in two types of networks, the HLR 14 and the AAAH 18 should be able to access a database (DB) storing a private key corresponding to the SIM 11.
[18] In a wireless cαrmunication system (e.g., a 3G packet network) supporting a mobile Internet protocol (IP), two types of Internet access gateways are present as network devices that can allocate an IP address to the MS 10. One is a packet data service node (PDSN) referred to as an FA, and the other is an HA. The FA allocates an IP address to an MS requesting a simple IP service, and the HA allocates an IP address to an MS requesting a mobile IP service. The IP address allocated by the FA is discarded after the service ends while the IP address allocated by the HA is valid as far as the MS does not move to an area of another HA.
[19] Packet cαrmunication systems supporting a dynamic IP service are configured based on a domain and are connected to each other through the Internet. Each domain includes a mobile cαrmunication system and network devices for a packet call service. Here, the mobile cαrmunication system includes a base transceiver system (BTS) and a base station controller (BSC), which are used in a digital cellular network, a personal cαrmunications service (PCS) network, and a next generation of a mobile communication network, International Mobile Teleccmnunications (IMT)-2000 (e.g., CDMA2000 or UMTS). The network devices for a packet call service include an HA supporting a dynamic IP service, a PDSN, an authentication, authorization & accounting (AAA) server, a domain name system (DNS) server, and a dynamic host configuration protocol (DHCP) server.
[20] An MS accesses a PDSN through a wireless channel. The PDSN or an HA allocates an IP address to the MS requesting a packet call. The IP address allocated by the PDSN is changed when the MS moves to an area of another PDSN, but the IP address allocated by the HA is fixed within a current domain.
[21] An AAA server performs authentication, authorization, and accounting with respect to wireless cαrmunications network subscribers. A security channel is formed between AAA servers. An AAA server identifies a subscriber using a network access identifier (NAI), associates the NAI with a DNS server, and updates a DNS server through the security channel when an IP address is allocated dynamically. In other words, a host wanting cαrmunication with a mobile host cannot know a dynamically allocated IP address of the mobile host, and therefore, the DNS server needs to be updated dynamically.
[22] A DNS server is a distributed naming system that maps a domain name to an IP address. The DNS server dynamically updates domain names at the requests of network devices so that a fixed domain name is mapped to a changing IP address. A domain name is an address expressed in text to identify a host accessing the Internet and is easier to memorize and more intuitive than an IP address configured with numerals.
[23] FIG. 2 illustrates a protocol for mutual authentication between an MS 10 and a wireless Internet network. An FA 16 connected to the wireless Internet network continuously broadcasts an agent advertisement (AA) 20 to its sub-network according to a mobile IP protocol. If the MS 10 enters the sub-network of the FA 16, the MS 10 recognizes the AA 20. Then, the MS 10 generates a first random nurber (RAND1) in step 211 and transmits a registration request (R_Req) 21 to the FA 16. The R_Req 21 contains a care-of-address (Co A) received from the FA 16 and an NAI corresponding to a subscriber's ID. The FA 16 transmits the R_Req 21 as an R_Req 22 to an HA 17.
[24] In an embodiment of the present invention, to reduce the nurber of message exchanges for authentication, a new type of NAI, i.e., a temporary NAI (TNAI), is used.
[25] FIG. 3 illustrates a data format of a TNAI contained in an R_Req message that is generated by the MS 10 and then transmitted sequentially to the FA 16 and HA 17. The TNAI includes an international mobile subscriber identity (IMSI) 31, a first random number (RAND1) that has a length of 128 bits and is generated by an SIM 11 for network authentication, and a Realm 34 indicating a domain to which a subscriber belongs. A tag 30 indicates the authentication method which is intended to be used, and a separator 33 is a mark that separates the IMSI 31 from the Realm 34.
[26] In encoding each field of the TNAI, the tag 30 and the separator 33 are encoded into, for example, 1-byte ASCII codes corresponding to 9 and @, respectively. The IMSI 31 is encoded into a 15-byte text string where each byte is composed of one of ASCII codes 0x30-0x39 corresponding to 0-9. The RAND1 32 is set by encoding a 128-bit random number to a length of 22 bytes using BASE-64 encoding. The Realm 34 is encoded into a text string corresponding to the domain name.
[27] Referring to FIG. 2, the HA 17 having received the R_Req 22 from the FA 16 extracts the IMSI 31 and the RAND1 32 from the TNAI, generates and transmits an authentication request (A_Req) 23 to an AAAH 18. The AAAH 18 extracts subscriber information and a private key Ki from a DB using the IMSI 31, generates RESl, RAND2, XRES2, and Kc in step 231, and transmits them as an authentication reply (A_Reply) 24 to the HA 17. The HA 17 transmits the A_Reply 24, received from the AAAH 18 as a registration reply (R_Reply) 25 to the FA 16. Here, RESl indicates information used by the MS 10 to authenticate the network, and XRES2 indicates information used by the FA 16 to authenticate the subscriber. RAND2 is a second random number randomly generated to have 128 bits in length by the AAAH 18. Kc is a 128-bit encryption key generated by combining a 64-bit encryption key Kcl generated using Ki and RAND1 and a 64-bit encryption key Kc2 generated using Ki and RAND2.
[28] FIG. 4 is a block diagram illustrating operations of the AAAH 18 while the above- described authentication protocol is performed. Subscriber information and a private key Ki are extracted from a DB 41 using an IMSI received from the HA 17. A first signal generator 42 generates a 64-bit encryption key Kcl in a block 421 and RESl in a block 422 based on the private key Ki and RAND1. A second signal generator 43 generates a 64-bit encryption key Kc2 in a block 431 and XRES2 in a block 432 based on the private key Ki and RAND2. The A8 algorithm used in the blocks 421 and 431 and the A3 algorithm used in the blocks 422 and 432 are predefined authentication/ encryption algorithms in a mobile cαrmunication network. The RAND2 is a random number generated by a random nurber generator 45.
[29] Refer to FIG. 2. Upon receiving the RES 1 , the RAND2, the XRES2, and the Kc from the HA 17, the FA 16 stores the XRES2 and the Kc and transmits an R_Reply 26 including the RESl and the RAND2 to the MS 10.
[30] FIG. 5 is a block diagram of an apparatus for authenticating a network in the MS 10 while the authentication protocol is performed. The SIM 11 (shown in FIG. 1) included within the MS 10 receives the RESl and the RAND2 from the FA 16. Then, a first signal generator 52 generates authentication information XRES 1 in a block 522 using the private key Ki and the RAND1 that have been stored in the MS 10 in step 213. A comparator 54 compares the XRES1 with the RESl received from the FA 16 in step 215 to authenticate the network. The RAND1 is a random nurber that have been generated by a random number generator 51. In addition, the first signal generator 52 generates a 64-bit encryption key Kcl in a block 521. A second signal generator 53 generates subscriber authentication information RES2 in a block 532 and a 64-bit encryption key Kc2 in a block 531 using the RAND2 received from the FA 16 and the private key Ki. Then, in step 217, the RES2 is transmitted to the FA 16, and the encryption keys Kcl and Kc2 are combined to generate a 128-bit encryption key Kc.
[31] If individual members participating in the authentication protocol normally comply with the authentication protocol, the Kc generated by the AAAH 18 as shown in FIG. 4 and the Kc generated by the SIM 11 of the MS 10 as shown in FIG. 5 share the same value. As a result, the MS 10 and the FA 16 share the encryption key Kc to realize secure cαrmunication.
[32] The RES2 generated by the SIM 11 of the MS 10 is errbedded into an A_Req 27 and transmitted to the FA 16. The FA 16 compares the RES2 received from the MS 10 with the XRES2 stored therein in step 221 to authenticate the subscriber. If authentication succeeds, a SUCCESS message is embedded into an A_Reply 28 and transmitted to the MS 10.
[33] The following description surmarizes functions of individual units associated with the protocol illustrated in FIG. 2.
[34] Where an MS (10) enters a sub-network of a gateway, the MS transmits an NAI containing a first random nurber and an IMSI to the gateway, generates XRES1 using a private key and the first random number that are stored therein, compares the XRES 1 with RES 1 received from the gateway to authenticate a network, generates RES2 using the private key and a second random nurber received from the gateway, and transmits the RES2 to the gateway.
[35] A gateway (16, 17) broadcasts an AA to its sub-network, extracts an IMSI and a first random number from an NAI received from an MS entering the sub-network, transmits the IMSI and the first random number to an AAAH (or an authentication server), stores XRES2 received from the AAAH, transmits RESl and a second random number to the MS, and compares RES2 received from the MS with XRES2 stored therein to authenticate a subscriber.
[36] The AAAH ( 18) fetches a private key from a DB using IMSI, generates RES 1 using the private key and a first random nutrber, generates XRES2 using the private key and a second rand n nurber, and transmits the RESl, the second randan number, and the XRES2 to a gateway.
[37] In addition, the AAAH (18) generates a first encryption key using the private key and the first randan nurber, generates a second encryption key using the private key and the second random nurber, generates a third encryption key by combining the first and second encryption keys, and transmits the third encryption key to the gateway. Then, the gateway stores the third encryption key, and the MS generates a fourth encryption key using the private key and the first random nurber stored therein, generates a fifth encryption key using the private key and the second random nurber, and generates a sixth encryption key by combining the fourth and fifth encryption keys. As a result, the third encryption key generated by the AAAH (18) and the sixth encryption key generated by the MS (10) share the same value.
[38] In the embodiment shown in FIG. 2, messages transferred between the MS 10 and the FA 16 for mutual authentication between a subscriber and a network include the A A 20 periodically broadcasted by the FA 16 and two pairs of request and reply messages, i.e., R_Req 21, R_Reply 26, A_Req 27, and A_Reply 28. After authentication, the MS 10 and the FA 16 share the 128-bit encryption key Kc. Accordingly, in the errbodiment of the present invention, the mutual authentication between the subscriber and the network can be accomplished using only two pairs of request and reply messages transferred between the MS 10 and the FA 16 in addition to the A A periodically broadcasted by the FA 16 in a wireless Internet network. Moreover, since an algorithm of generating an encryption key is repeated two times in the SIM 11, an effective encryption key is lengthened.
[39] The invention can also be embodied as computer readable codes on a computer readable recording medium. The computer readable recording medium is any data storage device that can store data which can be thereafter read by a computer system. Examples of the computer readable recording medium include read-only memory (ROM), random-access memory (RAM), CD-ROMs, magnetic tapes, floppy disks, optical data storage devices, and carrier waves (such as data transmission through the Internet). The computer readable recording medium can also be distributed over network coupled computer systems so that the computer readable code is stored and executed in a distributed fashion.
[40] While the present invention has been particularly shown and described with reference to exemplary errbodiments thereof, it will be understood by those of ordinary skill in the art that various changes in form and details may be made therein without departing from the spirit and scope of the present invention as defined by the following claims. Industrial Applicability
[41] As described above, according to the present invention, a subscriber and a network can mutually authenticate each other using only two pairs of request and reply messages. Also, the subscriber and the network can share a 128-bit encryption key for secure cαrmunication using an authentication algorithm used in a conventional SIM- type mobile cαrmunication network without any change. Accordingly, security of a wireless Internet network is enhanced at a minimun cost, and mobile communication network and wireless Internet network co-work effectively.
[42] The present invention provides mutual authentication between a subscriber and a network using an SIM and a means for allowing a key to be shared by the subscriber and the network. In the present invention, the subscriber and the network in a wireless Internet system exchange miniinum nurber of request and reply messages and can use an authentication algorithm used in a conventional SIM-type mobile cαrmunication network.
[43] The present invention modifies a subscriber authentication method based on an SIM in a second generation mobile communication network, thereby enabling network authentication, and enhances security by increasing the nurber of effective bits of an encryption key shared by a subscriber and a network after authentication. According to the present invention, an unauthorized user is prevented frαn using a network through subscriber authentication, and a subscriber's personal information is protected from being revealed to a fake server through authentication of a network and a server.

Claims

Claims
[1] A method of authenticating a subscriber and a network in a wireless Internet system, the method comprising: a gateway broadcasting an agent advertisement to its sub-network, the gateway being connected to a wireless Internet network; a mobile station transmitting a network access identifier containing a first random nurber and a mobile subscriber identity to the gateway, when entering the sub-network of the gateway ; the gateway transmitting the mobile subscriber identity and the first random nurber to an authentication server; the authentication server extracting a private key using the mobile subscriber identity, generating RESl using the private key and the first randan nurber, and generating XRES2 using the private key and a second random number; the authentication server transmitting the RESl, the second random nurber, and the XRES2 to the gateway; the gateway storing the XRES2 and transmitting the RESl and the second random nurber to the mobile station; the mobile station generating XRES 1 using the private key and the first random nurber that are stored therein and comparing the XRES1 with the RESl received frαn the gateway to authenticate the network; the mobile station generating RES2 using the private key and the second randan nurber and transmitting the RES2 to the gateway; and the gateway comparing the RES2 received frαn the mobile station with the XRES2 stored therein to authenticate the subscriber.
[2] The method of claim 1, further comprising: the authentication server generating a first encryption key using the private key and the first randan nurber, generating a second encryption key using the private key and the second random nurber, generating a third encryption key by combining the first and second encryption keys, and transmitting the third encryption key to the gateway; the gateway storing the third encryption key; and the mobile station generating a fourth encryption key using the private key and the first random nurber that are stored therein, generating a fifth encryption key using the private key and the second random nurber, and generating a sixth encryption key by combining the fourth and fifth encryption keys, wherein the third encryption key generated by the authentication server and the sixth encryption key generated by the mobile station share a same value.
[3] The method of claim 1, wherein the network access identifier that is generated by the mobile station and then transmitted to the gateway comprises the mobile subscriber identity, the first random nurber generated for network authentication, and information about a domain to which the subscriber belongs.
[4] An apparatus for authenticating a subscriber and a network in a wireless Internet system, the apparatus comprising: a mobile station which transmits a network access identifier containing a first random nurber and a mobile subscriber identity to a gateway when entering a sub- network of the gateway, generates XRES1 using a private key and the first random nurber that are stored therein, compares the XRES1 with RESl received frαn the gateway to authenticate the network, generates RES2 using the private key and a second random nutrber received frαn the gateway, and transmits the RES2 to the gateway; the gateway which broadcasts an agent advertisement to the sub-network, extracts the mobile subscriber identity and the first random nurber frαn the network access identifier received from the mobile station entering the subnetwork, transmits the mobile subscriber identity and the first random nurber to an authentication server, stores XRES2 received frαn the authentication server, transmits the RES 1 and the second randan nurber to the mobile station, and compares the RES2 received from the mobile station with the XRES2 stored therein to authenticate the subscriber; and the authentication server which extracts the private key using the mobile subscriber identity , generates the RESl using the private key and the first random nurber, generates the XRES2 using the private key and the second random nurber, and transmits the RESl, the second random number, and the XRES2 to the gateway.
[5] The apparatus of claim 4, wherein the authentication server generates a first encryption key using the private key and the first random nutrber, generates a second encryption key using the private key and the second random nurber, generates a third encryption key by combining the first and second encryption keys, and transmits the third encryption key to the gateway; the gateway stores the third encryption key; and the mobile station generates a fourth encryption key using the private key and the first random nurber stored therein, generates a fifth encryption key using the private key and the second random nurber, and generates a sixth encryption key by combining the fourth and fifth encryption keys; wherein the third encryption key generated by the authentication server and the sixth encryption key generated by the mobile station share a same value.
[6] An authentication server comprising: a private key extractor which fetches a private key from a DB using a received mobile subscriber identity; a first signal generator which generates a first encryption key and RESl, which is used by a mobile station for network authentication, using the private key and a received first random nurber; a randan nurber generator which generates a second random nurber; a second signal generator which generates a second encryption key and XRES2, which is used for subscriber authentication, using the private key and the second random nurber; and an encryption key generator which generates a third encryption key by combining the first encryption key and the second encryption key.
[7] An apparatus for authenticating a network in a mobile station, the apparatus receiving RESl and a second random nurber and cαnprising: a randan nurber generator which generates a first randan nurber; a first signal generator which generates a first encryption key and network authentication information XRES 1 using a private key stored therein and the first random nurber; a cαnparator which cαnpares the XRES 1 with the received RES 1 to authenticate the network; a second signal generator which generates a second encryption key and subscriber authentication information RES2 using the private key and the received second randan nurber; and an encryption key generator which generates a third encryption key by combining the first encryption key and the second encryption key.
[8] A method of authenticating a subscriber and a network in a wireless Internet system, the method cαnprising: a foreign agent (FA) continuously broadcasting an agent advertisement (AA) to its sub-network according to mobile Internet protocol (IP), the FA being connected to a wireless Internet network; a mohle station recognizing the AA and transmitting a network access identifier containing a first randan nurber and a mohle subscriber identity to the FA and a home agent (HA), when entering the sub-network of the FA ; the HA extracting the first randan nurber and the mohle subscriber identity from the network access identifier and transmitting the mohle subscriber identity and the first random nurber to an authentication, authorization & accounting server in home side (AAAH) ; the AAAH extracting a private key using the mohle subscriber identity, generating a first encryption key and RES 1 using the private key and the first random nurber, generating a second encryption key and XRES2 using the private key and a second random nutrber, and generating a third encryption key by combining the first encryption key and the second encryption key; the AAAH transmitting the RESl, the second random number, the XRES2, and the third encryption key to the HA and the FA; the FA storing the XRES2 and the third encryption key and transmitting the RESl and the second random number to the mohle station; the mohle station generating XRES 1 and a fourth encryption key using the private key and the first randan nurber that are stored therein and comparing the XRES 1 with the RES 1 received frαn the FA to authenticate the network; the mohle station generating RES2 and a fifth encryption key using the private key and the second randan nurber received from the FA, transmitting the RES2 to the FA, and generating a sixth encryption key using the fourth and fifth encryption keys; and the FA comparing the RES2 received from the mohle station with the XRES2 stored therein to authenticate the subscriber. [9] The method of claim 8 wherein the third encryption key generated by the authentication, authorization & accounting server in home side (AAAH) and the sixth encryption key generated by the mohle station share a same value.
EP04774379A 2003-12-17 2004-08-23 METHOD AND DEVICE FOR AUTHENTICATING A SUBSCRIBER AND NETWORK IN A WIRELESS INTERNET SYSTEM Withdrawn EP1695480A4 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
KR1020030092564A KR100546778B1 (en) 2003-12-17 2003-12-17 Wireless internet subscriber authentication method and device
PCT/KR2004/002118 WO2005060150A1 (en) 2003-12-17 2004-08-23 Method and apparatus for authenticating subscriber and network in wireless internet system

Publications (2)

Publication Number Publication Date
EP1695480A1 true EP1695480A1 (en) 2006-08-30
EP1695480A4 EP1695480A4 (en) 2012-08-29

Family

ID=36693406

Family Applications (1)

Application Number Title Priority Date Filing Date
EP04774379A Withdrawn EP1695480A4 (en) 2003-12-17 2004-08-23 METHOD AND DEVICE FOR AUTHENTICATING A SUBSCRIBER AND NETWORK IN A WIRELESS INTERNET SYSTEM

Country Status (4)

Country Link
EP (1) EP1695480A4 (en)
KR (1) KR100546778B1 (en)
CN (1) CN1918843B (en)
WO (1) WO2005060150A1 (en)

Families Citing this family (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR100759168B1 (en) * 2005-11-16 2007-09-14 엘지노텔 주식회사 Mobile communication system with safety key generation function and control method
KR100790495B1 (en) * 2006-03-07 2008-01-02 와이즈와이어즈(주) Authentication method, system, server and recording medium for controlling mobile communication terminal using encryption algorithm
KR100745617B1 (en) * 2006-11-17 2007-08-03 주식회사 유비닉스 Subscriber Authentication System and Subscriber Authentication Method Using the Same
EP2168068B1 (en) * 2007-06-11 2015-08-26 Telefonaktiebolaget L M Ericsson (publ) Method and arrangement for certificate handling
KR100934309B1 (en) * 2007-12-05 2009-12-29 유비벨록스(주) Integrated Subscriber Authentication System and Subscriber Authentication Method Using the Same
CN101483525A (en) * 2009-01-22 2009-07-15 中兴通讯股份有限公司 Implementing method for authentication center
CN101635710B (en) 2009-08-25 2011-08-17 西安西电捷通无线网络通信股份有限公司 Pre-shared-key-based method for controlling secure access to networks and system thereof
WO2016018028A1 (en) 2014-07-31 2016-02-04 Samsung Electronics Co., Ltd. Device and method of setting or removing security on content
CN107294712B (en) * 2017-07-24 2020-01-31 北京中测安华科技有限公司 key negotiation method and device
KR102553166B1 (en) * 2018-10-19 2023-07-06 주식회사 케이티 Proxyless multi-path transmission system, and authentication method thereof

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE19630920C1 (en) * 1996-07-31 1997-10-16 Siemens Ag Subscriber authentication and/or data encryption method
DE19756587C2 (en) * 1997-12-18 2003-10-30 Siemens Ag Method and communication system for encrypting information for radio transmission and for authenticating subscribers
DE19820422A1 (en) * 1998-05-07 1999-11-11 Giesecke & Devrient Gmbh Method for authenticating a chip card within a message transmission network
FR2790177B1 (en) * 1999-02-22 2001-05-18 Gemplus Card Int AUTHENTICATION IN A RADIOTELEPHONY NETWORK
WO2000067446A1 (en) * 1999-05-03 2000-11-09 Nokia Corporation SIM BASED AUTHENTICATION MECHANISM FOR DHCRv4/v6 MESSAGES
FI20000760A0 (en) * 2000-03-31 2000-03-31 Nokia Corp Authentication in a packet data network
FI111208B (en) * 2000-06-30 2003-06-13 Nokia Corp Arrangement of data encryption in a wireless telecommunication system
US20020169958A1 (en) * 2001-05-14 2002-11-14 Kai Nyman Authentication in data communication
US7900242B2 (en) * 2001-07-12 2011-03-01 Nokia Corporation Modular authentication and authorization scheme for internet protocol

Also Published As

Publication number Publication date
CN1918843A (en) 2007-02-21
EP1695480A4 (en) 2012-08-29
WO2005060150A1 (en) 2005-06-30
KR20050060839A (en) 2005-06-22
KR100546778B1 (en) 2006-01-25
CN1918843B (en) 2011-02-09

Similar Documents

Publication Publication Date Title
EP1095533B1 (en) Authentication method and corresponding system for a telecommunications network
CN101810018B (en) Secure wireless communication
US10425808B2 (en) Managing user access in a communications network
US7065067B2 (en) Authentication method between mobile node and home agent in a wireless communication system
JP4965671B2 (en) Distribution of user profiles, policies and PMIP keys in wireless communication networks
US8230212B2 (en) Method of indexing security keys for mobile internet protocol authentication
US8112065B2 (en) Mobile authentication through strengthened mutual authentication and handover security
JP5119242B2 (en) Method and system for providing a mobile IP key
ES2349292T3 (en) PROCEDURE AND SERVER TO PROVIDE A MOBILITY KEY.
EA013147B1 (en) Method and system for providing an access specific key
EP1563668A2 (en) Methods and apparatus for dynamic session key generation and rekeying in mobile ip
CN101300815A (en) Method and server for providing a mobile key
US8630420B2 (en) Method for auto-configuration of a network terminal address
US20020169958A1 (en) Authentication in data communication
KR100546778B1 (en) Wireless internet subscriber authentication method and device
KR100968522B1 (en) Mobile authentication method with enhanced mutual authentication and handover security
Hamandi et al. W-AKA: Privacy-enhanced LTE-AKA using secured channel over Wi-Fi
KR20010076763A (en) Authentication Method in Mobile Communication Environment
KR20060117812A (en) Security device and method in wireless network supporting mobile IP

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 20060703

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): FR GB

DAX Request for extension of the european patent (deleted)
RBV Designated contracting states (corrected)

Designated state(s): FR GB

RIC1 Information provided on ipc code assigned before grant

Ipc: H04L 29/06 20060101AFI20120717BHEP

A4 Supplementary search report drawn up and despatched

Effective date: 20120726

17Q First examination report despatched

Effective date: 20121106

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN

18D Application deemed to be withdrawn

Effective date: 20130319