EP4074087A1 - Method for authenticating a secure element at the level of an authentication server, corresponding secure element and authentication server - Google Patents
Method for authenticating a secure element at the level of an authentication server, corresponding secure element and authentication serverInfo
- Publication number
- EP4074087A1 EP4074087A1 EP20803563.4A EP20803563A EP4074087A1 EP 4074087 A1 EP4074087 A1 EP 4074087A1 EP 20803563 A EP20803563 A EP 20803563A EP 4074087 A1 EP4074087 A1 EP 4074087A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- msin
- secure element
- imsi
- decrypted
- candidate
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
- 238000000034 method Methods 0.000 title claims abstract description 33
- 238000004590 computer program Methods 0.000 claims description 6
- 238000005516 engineering process Methods 0.000 description 3
- 208000014674 injury Diseases 0.000 description 2
- 238000012795 verification Methods 0.000 description 2
- 230000001427 coherent effect Effects 0.000 description 1
- 238000004891 communication Methods 0.000 description 1
- 230000001010 compromised effect Effects 0.000 description 1
- 238000010276 construction Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/02—Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/69—Identity-dependent
- H04W12/72—Subscriber identity
Definitions
- the invention concerns telecommunications and in particular a symmetric key based method and system intended to protect identity privacy of loT (Internet of Things) devices.
- loT Internet of Things
- loT devices with low computation capability need to cipher their identity to comply with GDPR (General Data Protection Regulation).
- loT devices are communicating with secure elements like UICCs, iUICCs (integrated UICCs), eUICCs (embedded UICCs) or soft Sims.
- GDPR requires protection of user identity privacy. This includes identities of loT devices.
- initial authentication to the network requires the device to which the secure element is cooperating, to send its permanent subscription identity (e.g. IMSI - International Mobile Subscriber Identity) in clear over the air interface to the serving access network.
- identity encryption mechanism e.g. in GSM, UMTS or LTE.
- Identity encryption exists for initial authentication in 5G, however this requires the operator to deploy secure elements (UICC) and authentication network functions supporting asymmetric key algorithms. It is known that secure elements running such asymmetric key algorithms are more complex and require more battery power that are incompatible with low power and low cost loT devices.
- Another solution could be to use one or multiple symmetric keys stored in the USIM specifically used for the encryption of the device SUPI/IMSI.
- these keys for practicability reasons need to be shared among groups of devices. The weakness of these system is that if one of device is penetrated and the group key is revealed then the whole group is compromised.
- Symmetric key based authentication requires both end of the mutual authentication process to know the identity of the other end user. This is the reason why identity protection cannot be ensured in earlier technology without introduction of public key mechanism:
- the device In symmetric key system the device needs to provide the network with its identity in clear in the initial authentication, for the network to be able to retrieve the pre-shared secret key based on the sent in clear identity (IMSI).
- IMSI sent in clear identity
- the invention proposes a solution to this problem.
- the present invention proposes a method for authenticating a secure element at the level of an authentication server, the secure element being able to cooperate with a telecommunication terminal, the method comprising:
- a first message comprising a partial IMSI of the secure element or a partial IMSI of an IMSI based user identity that is in the form of a NAI of the secure element, called MSIN_part1, the first message also comprising the MCC and MNC codes of the IMSI or of the IMSI based user identity that is in the form of a NAI of the secure element , the MSIN_part1 comprising some of the most significant digits of the MSIN;
- the invention also concerns a secure element being able to cooperate with a telecommunication terminal, the secure element comprising a computer program comprising instructions for:
- a first message comprising a partial IMSI or a partial IMSI based user identity that is in the form of a NAI, called MSIN_part1, the first message comprising: o the MCC and MNC codes of the IMSI or of the IMSI based user identity that is in the form of a NAI of the secure element and o the MSIN_part1 the MSIN_part1 comprising some of the most significant digits of the MSIN;
- MSIN_part2 a second part, called MSIN_part2 of the MSIN of the secure element and the current sequence number, the second message being encrypted by the key Ki of the secure element in order to provide a token X, the MSIN_part2 comprising some of the less significant digits of the MSIN;
- the invention also concerns an authentication server able to authenticate a secure element , the secure element being able to cooperate with a telecommunication terminal, the authentication server comprising a computer program comprising instructions for:
- a first message comprising a partial IMSI or a partial IMSI based user identity that is in the form of a NAI, called MSIN_part1, the first message comprising the MCC and MNC codes of the IMSI or of the IMSI based user identity that is in the form of a NAI of the secure element , the MSIN_part1 comprising some of the most significant digits of the MSIN; o a second message containing a second part, called MSIN_part2, of the MSIN of the secure element and the current sequence number, the second message being encrypted by the key Ki of the secure element in order to provide a token X, the MSIN_part2 comprising some of the less significant digits of the MSIN;
- the first MSIN_part1 and second part MSIN_part2 do or not fully comprise the MSIN.
- Figure 1 represents a flow of the exchanged signals between a secure element and a home AUSF (H-AUSF (Authentication Server Function));
- H-AUSF Authentication Server Function
- Figure 2 represents the generation of a partial IMSI and of a token at the level of the secure element
- Figure 3 represents how the partial IMSI and the token are exploited at the level of the home AUSF (H-AUSF) for generating an authentication vector.
- Figure 1 represents a flow of the exchanged signals between a secure element 10 and a home AUSF (referenced H-AUSF 12).
- the secure element 10 is able to cooperate with a telecommunication terminal.
- the purpose is to authenticate the secure element 10 at the level of the authentication server H-AUSF 12.
- Figure 1 is described in parallel with figure 2 that shows what happens at the level of the secure element 10.
- the process comprises:
- the token X 23 comprises four fields: A first field that is a header “MSIN_part2:” announcing the content of the second field containing MSIN_part2, a third field that is a header “SQN:” announcing the last field containing SQN.
- a generation at the secure element 10 of another message, called later on first message 20, comprising a partial IMSI (PartiaIJMSI) of the secure element 10, called MSIN_part1 , this first message 20 also comprising the MCC and MNC codes of the IMSI of the secure element 10, the MSIN_part1 comprising some of the most significant digits of the MSIN.
- the MSIN_part1 that constitutes a partial IMSI may contain one or several of the most significant digits of the MSIN part of the IMSI.
- the PartiaIJMSI 20 comprises a concatenation of the MCC, MNC and MSIN_part1.
- the partial IMSI 20 (MCC II MNC II MSIN_part1) and the token X 23 are transmitted to the authentication server 12 through an AMF 11 (Access and Mobility Management Function, see 3GPP TS 23.501).
- AMF 11 Access and Mobility Management Function, see 3GPP TS 23.501.
- a database 30 associates each partial IMSI 20 to a complete IMSI with the corresponding key Ki 22.
- This database permits to constitute a list 31 of the candidate secure elements for which the MSIN_part1 corresponds (step 15).
- the token X 23 is decrypted (step 33) with the key Ki of each of the candidate secure elements of the list, in order to generate decrypted IMSIs (list 34).
- This list 34 thus contains all decrypted IMSIs and the corresponding decrypted sequence number SQN.
- the authentication server 12 checks, for each candidate secure elements of the list, which decrypted IMSI: a - corresponds to the IMSI of the candidate secure element of the list 31 ; and b - which candidate secure element of the list 31 has a sequence number in a valid range of the decrypted sequence number from token X 23.
- the authentication server 12 generates an authentication vector (step 36 in figure 3) by using the key Ki corresponding to the IMSI which has the decrypted MSIN_part2 and has a valid sequence number in order to launch a challenge response process (step 16 in figure 1) between the secure element 10 and the authentication server 12.
- the method according to the invention can be used in 2 ways: a- the first MSIN_part1 and second part MSIN_part2 do not fully comprise the MSIN; b- the first MSIN_part1 and second part MSIN_part2 do fully comprise the MSIN.
- the first MSIN_part1 and second part MSIN_part2 do not fully comprise the MSIN (digits 567 are not sent).
- MSIN_part1 being 123456 (or 12345) and second part MSIN_part2 being 78910 (or 678910 respectively)
- the first MSIN_part1 and second part MSIN_part2 do fully comprise the MSIN (all the digits of the MSIN are sent).
- the H-AUSF 12 can then (at step 36) generate an authentication vector by using the Ki of the candidate IMSI which has the correct MSIN_part2 and a valid sequence number SQN in order to launch a challenge response process between the secure element 10 and the authentication server 12.
- IMSI is used as an example.
- a group identity or other types of identities could be used as long as it does not identify the device/subscription uniquely and provides a certain level of identity uncertainty that complies with the GDPR regulations.
- a NAI Network Access Identifier
- IMSIs are used in before 5G networks (2, 3, 3 and 4G networks). In 5G networks, NAIs are used.
- NAI typically would be in the form of “Special_Group ID. Unique ID”.
- Special_Group ID is an identifier common to a group of secure elements in the field (comprising MCC and MNC codes) and Unique ID is the unique ID of each secure element (diversified per unique secure element) of the group.
- the different IMSIs/NAIs are known by the H-AUSF 12.
- the token X 13 is thus the result of the encryption, with the subscription secret key Ki, of the concatenation of a multiplicity of information pieces that include at least a part (least significant digits) of the identity of the subscription (IMSI) or the Unique ID part of the NAI when a NAI is used.
- the token X also contains the sequence number (SQN) that is used in the mutual authentication mechanism with the network (3GPP AKA). The sequence number was increased in previous authentication process (per 3GPP AKA also), so that the token X 13 is unique following an authentication process with the network.
- a registration counter or a random number generated by the USIM may be part of the concatenation to provide higher entropy.
- one or more well-known labels may be part of the concatenated data to increase the level of certainty during the identification process by the home network.
- the length of the IMSI is generally sufficient.
- the serving network uses the information (MCC and MNC) in the partial identity (PartiaIJMSI) to route the registration request to the home network (H-AUSF 12)
- the home network upon reception of the request (step 15) that contains the PartiaIJMSI and the token X:
- o uses the corresponding secret key (Ki) of the candidate device to decipher the received token X; o Tries to extract data fields of the decipher data. Retrieves in the deciphered data the text labels when present as shown in figure 2 (i.e.
- the H-AUSF 12 When the registering device is identified (only one matched candidate device), the H-AUSF 12 performs the standard process of generating the authentication vector based on the IMSI/Ki and sequence number SQN of the matched device and sends the Authentication Vector to the AMF 11 (step 16 of figure 1).
- the computation intensive task is only performed by the H-AUSF 12, for instance using an HSM.
- the AMF 11 performs then the standard authentication of the registering device and reports the success to the Home Network.
- one or multiple group keys G_key could be deployed by the home network operators for the specific tasks of encrypting the token X (i.e. subscription IMSI/SQN).
- the partial identity of the subscription is replaced by a group key identity GKJd.
- Each group key identity GKJd is associated to a group of devices which have different MSIN_part2 within that group.
- the USIM/device 10 is configured with not only the IMSI/Ki pair but also with a GKJd/G_key; generates the token X using its configured G_key; the token X 23 being the encryption of the concatenation of the partial subscription IMSI (MSIN_part2) and SQN as in the first description; sends the registration containing the GKJd and the generated Token X 23.
- the remaining process is similar to the first detailed process, whereas the PartiaIJMSI and the Ki for the encryption of the token X 23 are replaced respectively by the GKJd and G_key configured in the USIM/Device.
- one or more labels in the encrypted data is not necessary in this case as the deciphered data provide directly the correct MSIN_part2 and SQN that is in the group of devices associated to the GKJd, as by construction of the group, the MSIN_part2 of the devices are unique within this group of devices.
- the GKJd could be added in the concatenation for verification after deciphering. However, this would lengthen the token X 23, which could be challenging for devices with low communication bandwidth.
- the invention uses symmetric key based algorithm to protect the device identity in the initial authentication (registration) process.
- the invention uses a differentiated key per device and does not use a group key.
- the invention could be implemented so that only the end points (i.e. USIM 10 and H-AUSF 13) are modified and the intermediate nodes are unchanged by 3GPP standards.
- the invention also concerns a secure element 10 being able to cooperate with a telecommunication terminal, this secure element 10 comprising a computer program comprising instructions for:
- the invention also concerns an authentication server 12 able to authenticate a secure element 10, the secure element 10 being able to cooperate with a telecommunication terminal, the authentication server 12 comprising a computer program comprising instructions for:
- a first message comprising a partial IMSI or a partial IMSI based user identity that is in the form of a NAI, called MSIN_part1, the first message comprising the MCC and MNC codes of the IMSI or of the IMSI based user identity that is in the form of a NAI of the secure element 10, the MSIN_part1 comprising some of the most significant digits of the MSIN; o a second message containing a second part, called MSIN_part2, of the MSIN of the secure element 10 and the current sequence number, the second message being encrypted by the key Ki of the secure element 10 in order to provide a token X 23, the MSIN_part2 comprising some of the less significant digits of the MSIN; Retrieving a list of the candidate secure elements for which the MSIN_part1 corresponds and, for each of the candidate secure elements of the list, decrypting the token X with the key Ki of each of the candidate secure elements of the list in order to generate
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP19306651.1A EP3836589A1 (en) | 2019-12-13 | 2019-12-13 | Method for authenticating a secure element at the level of an authentication server, corresponding secure element and authentication server |
| PCT/EP2020/081566 WO2021115699A1 (en) | 2019-12-13 | 2020-11-10 | Method for authenticating a secure element at the level of an authentication server, corresponding secure element and authentication server |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4074087A1 true EP4074087A1 (en) | 2022-10-19 |
Family
ID=69650516
Family Applications (2)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP19306651.1A Withdrawn EP3836589A1 (en) | 2019-12-13 | 2019-12-13 | Method for authenticating a secure element at the level of an authentication server, corresponding secure element and authentication server |
| EP20803563.4A Pending EP4074087A1 (en) | 2019-12-13 | 2020-11-10 | Method for authenticating a secure element at the level of an authentication server, corresponding secure element and authentication server |
Family Applications Before (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP19306651.1A Withdrawn EP3836589A1 (en) | 2019-12-13 | 2019-12-13 | Method for authenticating a secure element at the level of an authentication server, corresponding secure element and authentication server |
Country Status (2)
| Country | Link |
|---|---|
| EP (2) | EP3836589A1 (en) |
| WO (1) | WO2021115699A1 (en) |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP2259545A1 (en) * | 2009-06-05 | 2010-12-08 | Gemalto SA | Method for calculating a first identifier of a secured element of a mobile terminal from a second identifier of this secured element |
-
2019
- 2019-12-13 EP EP19306651.1A patent/EP3836589A1/en not_active Withdrawn
-
2020
- 2020-11-10 EP EP20803563.4A patent/EP4074087A1/en active Pending
- 2020-11-10 WO PCT/EP2020/081566 patent/WO2021115699A1/en not_active Ceased
Also Published As
| Publication number | Publication date |
|---|---|
| EP3836589A1 (en) | 2021-06-16 |
| WO2021115699A1 (en) | 2021-06-17 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12089041B2 (en) | Method for authentication a secure element cooperating with a mobile equipment within a terminal in a telecommunication network | |
| EP1123603B1 (en) | Subscription portability for wireless systems | |
| KR102448747B1 (en) | A method for transmitting an encrypted subscription identifier stored in a secure element to a physical or virtual element of a telecommunications network, a corresponding secure element, a physical or virtual element and a terminal cooperating with the secure element | |
| CN111865603B (en) | Authentication method, authentication device and authentication system | |
| US20060291660A1 (en) | SIM UICC based broadcast protection | |
| KR20190139203A (en) | Method for managing communication between server and user equipment | |
| CA3033619C (en) | Authentication server of a cellular telecommunication network and corresponding uicc | |
| KR102425273B1 (en) | Methods and apparatuses for ensuring secure connection in size constrained authentication protocols | |
| KR20210035925A (en) | Operation related to user equipment using secret identifier | |
| JP2021193793A (en) | Cryptographic processing event for encrypting or decrypting data | |
| EP3836589A1 (en) | Method for authenticating a secure element at the level of an authentication server, corresponding secure element and authentication server | |
| KR100330418B1 (en) | Authentication Method in Mobile Communication Environment | |
| US12074972B2 (en) | Method for updating a secret data in a credential container | |
| ES3041788T3 (en) | Method to prevent hidden communication on a channel during device authentication, corresponding vplmn and hplmn | |
| US20230246809A1 (en) | Processing module for authenticating a communication device in a 3g capable network | |
| Wang et al. | Research on an improved proposal of 3G security | |
| WO2006136280A1 (en) | Sim/uicc based broadcast protection | |
| KR20150135715A (en) | Apparatus and method for protecting privacy of user in mobile communication network |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20220713 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20250409 |