A method, system and device to initiate and identify secret key update request
Abstract
The invention claims a causing the key updating request method, wherein the method comprises: The network requirement updating key generation, the new key, according to the novel key gain authentication parameter with, authentication parameter and a gain transmitted to the terminal. The invention further claims an identification a request updating method for key, wherein the method comprises: The terminal receiving authentication parameter for transmitting network, the first novel key according are according to preserves makes the first button and device for generating, authentication parameter of uniformity of receiving, and determining whether the network request the key updating. The invention further claims an is implemented as to the updating system for request key, a and vibrates upgrading device and recognition of the key request a request upgrades key device. The invention claims method, system and device, network equipments according to the existing authentication method updating the support of key, a terminal identification network contains request the key updating.
Term
No projected expiry on record.
- Priority and filed
- Published
- Today
31 claims: 5 independent, 26 dependent
- 11 Or and vibrates the key updating request method, the is composed characterised, wherein the method comprises:The network of need to the upgrade key, a device for confirming need to the upgrade key, a generating novel key, and according to the new key gain authentication parameter with, authentication parameter and a gain transmitted to the terminal. 1.一种发起更新密钥请求的方法,其特征在于,该方法包括:网络判断是否需要更新密钥,如果确定需要更新密钥,则产生新密钥,然后根据所产生的新密钥获取鉴权参数,并将所获取的鉴权参数发送给终端。
- 7Method for updating key request 7.1 or a distinguishing claim 1, wherein the is composed characterised, wherein the method comprises:The terminal receiving authentication parameter for transmitting network, authentication parameter uniformity according to preserves makes the first button from receiving;and uniformity, and then for determining network is not request updating the key;And the uniformity does not pass;and generating first novel key, a authentication parameter of uniformity and according to for with the first novel key of for receiving;and uniformity, and then network determining updated request key. 7.一种用于识别权利要求1所述的更新密钥请求的方法,其特征在于,该方法包括:终端接收到网络发送的鉴权参数后,根据自身所保存的第一密钥判断所接收到的鉴权参数的一致性,如果一致性通过,则确定网络没有请求更新密钥;如果一致性不通过,则产生第一新密钥,并根据自身所产生的第一新密钥判断所接收到的鉴权参数的一致性,如果一致性通过,则确定网络请求更新密钥。
- 171 Or of the key updating request system, the is characterised of; the system comprises:The key updating causing device and a upgrading request recognition system,The key is updating causing device is used to the gain authentication parameter, authentication parameter and a gain is the key upgrading to the support recognition system,The key is updating the authentication parameter of request recognition system is used for acting according to receiving, determining whether request the key updating. 17.一种实现更新密钥请求的系统,其特征在于,该系统包括:密钥更新发起装置和密钥更新请求识别装置;所述密钥更新发起装置用于获取鉴权参数,并将所获取的鉴权参数发送给所述密钥更新请求识别装置;所述密钥更新请求识别装置用于根据所接收到的鉴权参数,确定是否请求更新密钥。
- 251 Or and vibrates the key updating request device, the is composed characterised, wherein the device comprises:Causing the support decision unit, the second guide key unit, a second novel key generation unit, a power of any of unit, a authentication parameter obtaining unit, a authentication parameter data transmission unit;The causing the support decision unit is used to fix the heating upgrading key is request, and a locating the inspection is the authentication parameter obtaining unit;The second guide key unit is used for balanced to the second key;The second novel key to generate unit is used to generate the novel key;The power of any of unit is provided with a random;theThe authentication parameter obtaining unit is used to act according to form causing a decision result of the support decision unit, obtained from the second guide key unit is for obtaining the second key or from the second novel key to generate the unit is for obtaining the novel key, wherein the generation of any device for obtaining to, and according to the key and a power of any of authentication parameter gained, transmitted to the authentication parameter data transmission unit;The authentication parameter of the authentication parameter transmission unit is used for receiving and sending to the key upgrading to the support recognition system. 25.一种发起更新密钥请求的装置,其特征在于,该装置包括:发起请求决定单元,第二密钥保存单元,第二新密钥产生单元,随机数产生单元,鉴权参数获取单元,鉴权参数发送单元;所述发起请求决定单元用于决定是否发起更新密钥请求,并将决定结果发送给所述鉴权参数获取单元;所述第二密钥保存单元用于保存第二密钥;所述第二新密钥产生单元用于产生第二新密钥;所述随机数产生单元用于产生随机数;所述鉴权参数获取单元用于根据从所述发起请求决定单元所得到的决定结果,从所述第二密钥保存单元获取第二密钥或从所述第二新密钥产生单元获取第二新密钥,从所述随机数产生单元获取随机数,并根据所获取的密钥和随机数产生鉴权参数,发送给所述鉴权参数发送单元;所述鉴权参数发送单元用于将所接收到的鉴权参数发送给所述密钥更新请求识别装置。
- 27A 27.1 pair of identifying request upgrades key device; the is composed characterised, wherein the device comprises:The authentication parameter receiving unit, uniformly data unit, a first guide key unit, a first novel key generation unit, a recognizing unit;, Wherein authentication parameter receiving unit is used for receiving the network transmission the authentication, parameterThe first guide key unit is used for balanced to the first key;The uniform data unit is provided with a first key according gained the first guide key unit is balanced, or the number of the first novel key to generate the first novel key according unit state, and authentication parameter uniformity according to the key apparatus according gained the authentication parameter receiving unit received, and a confirm the results to transmit the recognizing unit and first novel key to generate unit;The inspection apparatus for recognizing unit is used for acting according to receiving, wherein the determining network request updating the key;The first novel key comprises a data result of the device is used for acting according to receiving, a the first novel key. 27.一种识别是否请求更新密钥的装置,其特征在于,该装置包括:鉴权参数接收单元,一致性验证单元,第一密钥保存单元,第一新密钥产生单元,识别单元;其中,所述鉴权参数接收单元用于接收网络发送的鉴权参数;所述第一密钥保存单元用于保存第一密钥;所述一致性验证单元用于获取第一密钥保存单元所保存的第一密钥,或者获取所述第一新密钥产生单元所产生的第一新密钥,并根据所获取的密钥验证所述鉴权参数接收单元所接收到的鉴权参数的一致性,并将验证结果发送给所述识别单元和所述第一新密钥产生单元;所述识别单元用于根据所接收到的验证结果,确定网络是否请求更新密钥;所述第一新密钥产生单元用于根据所接收到的验证结果,产生第一新密钥。
Independent claims5
130 paragraphs, as filed
A causing with method, system and device for identifying updating key request
technical field
The invention relates to attestation techniques, especially refers to in authentication technique for method, system and device for identifying updating key request.
background technology
The existing wireless communication system, to the WCDMA system, preserves international mobile user identity (IMSI) and authentication key and serial number of the terminal, network side HLR/AUC, preserves is in aggregate of the terminal IMSI, KI and SQN, is used for terminal and network mutual authentication.
A to the existing wireless communication system, realizing method of authentication, and shown the digital 1, comprising the following steps: Steps: 101The network with authentication parameter according to key according preserves thereof, authentication parameter of transmitting and is transmitted to a terminal.
Here, and authentication parameter for network coding with (MAC-A) comprises any of series, and a message authentication. , Network obtaining authentication parameter the damage of MAC-A is: The network side first with any number, a key and serial number of computer and according to generating any number of preserves for obtaining MAC-A.
Steps: 102The terminal to the authentication parameter for receiving and uniform apparatus according to the current key according preserves thereof, and consistent; and operating 103, theOtherwise, operating order 106.
Here, wherein the receiving terminal authentication parameter, a random number and serial number in authentication parameter according to preserves makes the key according and receiving, a authentication parameter, authentication parameter of the authentication parameter of determining and receiving and makes with the is consistent.
Steps: 103The serial number in authentication parameter the terminal for determining whether a acceptable range; each, and operating order 104, theOtherwise, operating order 105.
Here, series of differential value of the serial number in authentication parameter the terminal capable of receiving and thereof preserves there are multiple range, for example, are differential value there is greater than zero, or there is greater than 0, and is less than 65536 and methods of the 0.01-0.99; and differential value; the range, then by a serial number in authentication parameter received a housing, otherwise, determining a series in authentication parameter is received unacceptable.
Steps: 104The terminal device for confirming to the authentication success of network, and updating for serial number according to the serial number in authentication parameter, wherein the ended flow.
Steps: 105The terminal device for confirming the network a series of by the synchronous with for serial number, causing the synchronous serial current value; and ended the switch.
Steps: 106The terminal device for confirming to the authentication failure of network, ended the switch.
Provided with AN authentication current, and further see the 3GPP related protocol standard, here of longer charges unnecessary detail.
The existing authentication method, network and terminal is fixed by key, wherein throughout of invariable the key in the authentication method for. The same are fixed originally method for key, although realizing and managing is relatively simple, wherein, which is a very high safety danger.
The root key is easy divulge a secret. When the root key is composed of service reads, wherein the process with possibility to divulge the root key; When the root key is a operating is an reads, further comprises a possibility to divulge the root key; The spacer on the HLR/AUC and process, comprising a possibility to divulge the root key; Hacker attack HLR/AUC gain of key; A space connector method for multiple are in authentication parameter is authentication method, and authentication response of terminal circuit, and a part of algorithm calculation are key. The condition; the user is to discover of the root key divulged a secret, at the time, user legal in could symmetrically distributed on. , Wherein the user are embezzled for key are filled with a hacker the illegal communication. The existing method, so as long as the key divulges secrets, there is no efficient remedial processing, can only be of the user cards and HLR/AUC the related user data.
In turn to solve the problem, wherein the existing authentication method, needed to provide mechanism of key updating. The support for at the time, the key renewed is usually causing a network, network is usually the request to updating key information in the existing authentication parameter, a terminal and without shaft according to the identification information network contains request the key updating. The same as a shortcoming to the second terminal request updating key information's: method1st, Wherein increasing the content of the parameter authentication method, affects the normal authentication current efficiency; 2nd, The condition that a authentication parameter is to, is to achieve by authentication parameter to the request updating information key; 3rd, A for determining orders filled the support updating key information in authentication parameter, a request for updating information key is intercepted easily, so the updating operation keys to intention is divulged, wherein in the safety.
invention content
The radio for consideration, the first main capable of the is invention claims a to and vibrates the key updating request method, network and vibrates according to the existing authentication method updating the support of key.
The second main capable of this invention is a an identification a request updating method for key; when the network equipments according to the existing authentication method updating the support of key, a terminal and recognition network contains request the key updating.
The third volume of the is invention claims a to realize the key updating request system, when the network equipments according to the existing authentication method updating the support of key, a terminal identification network contains requests the key updating.
The fourth volume of the is invention claims a to and vibrates the key updating request device, network and vibrates according to the existing authentication method updating the support of key.
The fifth main capable of this invention is a an identification a request upgrades keys, wherein when the network equipments according to the existing authentication method updating the support of key, and recognition network contains request the key updating.
The communication service to the first key, the invention claims a causing the key updating request method, wherein the method comprises: The network of need to the upgrade key, a device for confirming need to the upgrade key, a generating novel key, and according to the new key gain authentication parameter with, authentication parameter and a gain transmitted to the terminal.
On the network the insulated with key;
The network to generate the new key is: The network generating any of RAND, the key according and according to RAND generating and device thereof preserves to generate the new key.
The network gain authentication parameter is: The network generating RAND, and authentication parameter according to RAND and new key for generating; Or, network generating RAND, a series of SQN, SQN and new key according and according to RAND generating is provided with a authentication parameter.
The network judging whether need to the upgrade key, for determining no need to the upgrade key, according to the key gain authentication parameter of for operating; the authentication parameter and a gain transmitted to the terminal.
The network to act according to the authentication parameter of RAND and new key is: Message authentication coding; MAC-AThe network gain authentication parameter comprises: The RAND and MAC-A.
The network gain authentication parameter is: The network generating RAND, a series of SQN, SQN and new key according and according to RAND generating is provided with a authentication parameter.
The network to act according to the authentication parameter of RAND, SQN and new key is: ; MAC-AThe network gain authentication parameter comprises: The RAND, said SQN and MAC-A.
In turn to serve the second key, the invention claims a method for identifying updating key request, wherein the method comprises: The terminal receiving authentication parameter for transmitting network, authentication parameter uniformity according to preserves makes the first button from receiving; and uniformity, and then for determining network is not request updating the key; And the uniformity does not pass; and generating first novel key, a authentication parameter of uniformity and according to for with the first novel key of for receiving; and uniformity, and then network determining updated request key.
The terminal arranged on the authentication parameter of the is network is as follows: Network gain authentication parameter, and a terminal authentication transmission parameter.
The network gain authentication parameter comprises: ; RANDArranged in the terminal the insulated with the first key; The terminal to generate the first novel key is: The first key of the terminal according to RAND received in authentication parameter and thereof preserves to generate the first novel key.
The terminal to act according to the authentication parameter uniformity of the first button from is received: The terminal XMAC-A coding according to the first acquiring key expectation message authentication, and from the authentication parameter of XMAC-A received and there is consistent; The terminal to act according to the authentication parameter uniformity of the first novel key judging is received: The terminal and XMAC-A according to the first novel key, and from the authentication parameter of XMAC-A received and there is consistent.
The network obtaining the authentication parameter - comprising: ; MAC-AThe terminal to act according to the first novel key is an XMAC-A is: The terminal according to RAND of the first novel key and receiving, generated by; XMAC-AThe terminal to act according to the first button to gain XMAC-A is: The terminal according to RAND of the first key and receiving, generated by XMAC-A.
The network obtaining the authentication parameter - comprising: SQN and MAC-A; The terminal to act according to the first novel key is an XMAC-A is: The terminal according to RAND and SQN of the first novel key and receiving, generated by; XMAC-AThe terminal to act according to the first button to gain XMAC-A is: The terminal according to RAND and SQN of the first key and receiving, generated by XMAC-A.
The authentication parameter of determining XMAC-A received and a uniform is: XMAC-A according MAC-A for determining terminal and receiving for generating a are consistent.
The first novel key according with the air according to for generating to determine the authentication parameter's uniformity of are received, and further - comprising: The terminal device for confirming is successful to the network, authenticationThe first novel key according with the air according to for generating to determine the authentication parameter's uniformity of rotator are not pass, and further - comprising: The terminal determining a network authentication failure.
The terminal is further arranged first; SQNThe terminal the further - comprising front network determining updated request key: The terminal according to SQN of the first SQN for determining whether a housing, and then, and network request updating key.
The terminal to determine the SQN is received a housing, and further - comprising: The terminal device for confirming is successful to the network authentication.
In turn to serve the third key, the invention claims a realizing updating key request system, the system comprises: The key updating causing device and a upgrading request recognition system,
The key is updating causing device is used to the gain authentication parameter, authentication parameter and a gain is the key upgrading to the support recognition system,The key is updating the authentication parameter of request recognition system is used for acting according to receiving, determining whether request the key updating.
The communication service to the fourth key, the invention claims a causing the key updating request device, the device comprises: Causing the support decision unit, the second guide key unit, a second novel key generation unit, a power of any of unit, a authentication parameter obtaining unit, a authentication parameter data transmission unit; The causing the support decision unit is used to fix the heating upgrading key is request, and a locating the inspection is the authentication parameter obtaining unit; The second guide key unit is used for balanced to the second key; The second novel key to generate unit is used to generate the novel key; The power of any of unit is provided with a random; theThe authentication parameter obtaining unit is used to act according to form causing a decision result of the support decision unit, obtained from the second guide key unit is for obtaining the second key or from the second novel key to generate the unit is for obtaining the novel key, wherein the generation of any device for obtaining to, and according to the key and a power of any of authentication parameter gained, transmitted to the authentication parameter data transmission unit; The authentication parameter of the authentication parameter transmission unit is used for receiving and sending to the key upgrading to the support recognition system.
The device further - comprising: Network serial number of unit, in series; theThe authentication parameter obtaining device is further used from the network serial number of the gain serial number, and number of according to the serial number of gained and key comprises a parameter authentication.
In turn to serve the fifth key, the invention claims a recognition a request upgrades key device, the device comprises: The authentication parameter receiving unit, uniformly data unit, a first guide key unit, a first novel key generation unit, a recognizing unit; , Wherein authentication parameter receiving unit is used for receiving the network transmission the authentication, parameterThe first guide key unit is used for balanced to the first key; The uniform data unit is provided with a first key according gained the first guide key unit is balanced, or the number of the first novel key to generate the first novel key according unit state, and authentication parameter uniformity according to the key apparatus according gained the authentication parameter receiving unit received, and a confirm the results to transmit the recognizing unit and first novel key to generate unit; The inspection apparatus for recognizing unit is used for acting according to receiving, wherein the determining network request updating the key; The first novel key comprises a data result of the device is used for acting according to receiving, a the first novel key.
The uniform data unit comprises: Authentication parameter regenerating device and authentication parameter comparing unit; The authentication parameter regenerating device is used to act according to form the comparison result for authenticating parameter comparing unit, received from the first guide key unit is for obtaining the first button, or from the first novel key to generate the device for obtaining to the first novel key, and according to the key gain authentication parameter of gained, authentication parameter and a gain is the authentication parameter comparing unit; The authentication parameter comparing unit is used to compare from the authentication parameter of the authentication parameter regenerating received unit and authentication parameter of the authentication parameter receiving unit received, and a compare the results to transmit the recognizing unit, wherein the first novel key to generate unit and authentication parameter regenerating device.
The device further - comprising: Acquisition unit; The gain unit is made from and authentication parameter of the authentication parameter receiving unit is received gain random number and serial number, a random number and serial number and a gain is connected with the authentication parameter regenerating device,The authentication parameter regenerating device is used to act according to form the first guide key unit or the first novel key to generate a key and a a random number and serial number of the unit gained the gain received unit, a gain authentication parameter.
The device further - comprising: Authentication device,The authentication device is made from the uniform data acquisition unit uniformity inspection apparatus, and according to the data consistency result of gained, determining according to network authentication wherein succeeded.
The device further - comprising: Terminal which are arranged unit, a serial number of the second judging unit; The terminal serial number of unit are provided to said terminal module, a charges to the serial number of all-around leakage protective to move the judging unit; The gain unit is made from and authentication parameter of the authentication parameter receiving unit is received obtaining the serial number, a serial number and a gain is a series of relate to move the judging unit; The serial number is connected to the judging unit is used to act according to form a series of determining of the terminal series of unit is received from the serial number of the gain unit received wherein a housing, and is a plurality of the recognizing unit and authentication device,The identification device is further used to act according to be the output of results from a series of the judging unit obtained, wherein the determining network request updating the key; The authentication device is further used to act according to be the output of results from a series of the judging unit, obtained by according to network authentication wherein succeeded.
Causing the key updating request according to the invention claims a network method, network, when need to and vibrates updating the key request, generating novel key of the new key and automatically according to for generating with a authentication parameter; and when the network no need to and vibrates updating the key request, according to the key according for preserves with authentication parameter. Therefore, when the network in the key upgrades to support, comprising an is an contents on the existing authentication parameter, causing of the existing authentication method upgrading key is request, wherein, without affect the normal authentication current efficiency. To the invention, the third party, and a obtained network transmission to terminal authentication parameter, is to distinguish the network contains with is a updating key request message, wherein, while does not as the authentication parameter information source, so the network to request to the transmission terminal key updating information in a not divulge.
To the recognition of this invention claims a request updating method for key, comprising a terminal receiving authentication parameter for transmitting network, the new key according successively according to preserves makes the key according and generating, a recognition network contains request the key updating. Therefore, when the network equipments according to the existing authentication method updating the support of key, a terminal not can only be tightly sleeved to the network contains a request updating key; meanwhile performing the authentication to the network.
The invention provides realizing updating key request's system, an existing authentication parameter is not an contents, terminal while completing to network authentication comprises a network the support updating key intention, while without increasing the normal authentication current burden, hid the support updating key intention, sharpened system anti-attack capability.
The invention claims a device for updating starting key request, network and vibrates according to the existing authentication method updating the support of key, a pulse hide the support updating key intention effectively, sharpened system anti-attack capability. To the recognition of this invention claims a request upgrades keys, wherein when the network equipments according to the existing authentication method updating the support of key, and recognition network contains a request updating key, and further - judging's to the network authentication wherein succeeded.
Brief description for drawings
Shown the digital 1 for prior process of realizing authentication flow, imageShown the digital 2 is the invention embodiment of the terminal identification network contains request updating the current points for key; Shown the digital 3 is in the invention relates of the terminal identification network contains request updating the current points for key; Shown the digital 4 is in the invention embodiment two terminal identification network contains request updating the current points for key; Shown the digital 5 is the invention of realizing request to the updating system structure of drawing key; Shown the digital 6 is the invention the key updating the support recognition system structure drawing.
detailed description of illustrated embodiments
In order to make the invention the volume, technical solution and power and multiple clearly understands of to the specific embodiment, is further detailed emitter to the invention.
The invention claims a request updating method for key, wherein the circuits is: The network and vibrates according to prior authentication method updating the support of key; Further comprises a receiving terminal authentication the parameter, the new key according successively according to preserves makes the key according and for generating, a recognition network contains request the key updating. Here, network of with a authentication parameter manner through the new key for generating, a transmission terminal key updating information request.
A to the network to and vibrates the key updating request to the terminal method, specifically to: The network of need to the upgrade key, a device for confirming need to the upgrade key, a generating novel key, and according to the new key gain authentication parameter with, authentication parameter and a gain transmitted to the terminal; Otherwise, according to the key gain authentication parameter of for preserves, authentication parameter and a gain transmitted to the terminal.
Usually, network wire with key, a network with a method of novel key is: The network generating RAND, the key according and according to RAND generating and device thereof preserves to generate the new key.
The authentication parameter for network and may include RAND and MAC-A, and parameter authentication method is as follows: The network generating RAND, and generating MAC-A according to RAND and for producing. The authentication parameter for network and can also comprises RAND, SQN and MAC-A, and parameter authentication method is as follows: The network generating RAND, wherein SQN, SQN and key according and according to RAND generating device is generated MAC-A. ; When the network causing the terminal updating the key request, the key in the gain parameter authentication method for using the new key for network, generationWhen the network without and vibrates to the terminal updating the key request, the key in the gain parameter authentication method used for key of the preserves network.
, And is convenient discrimination side terminal and network parameter sides, a terminal the side, where a first key, a first novel key and first, SQNA network side, where a second key, a second novel key and second SQN.
Shown the digital 2 is a terminal identification network contains request updating key embodiment flow, comprising the following steps: Steps: 201Network gain authentication parameter, and a terminal authentication transmission parameter.
Steps: 202The terminal receiving authentication parameter for transmitting network, authentication parameter uniformity according to preserves makes the first button from receiving; and uniformity, and then operating order 203; and uniformity does not pass; and operating 204.
Steps: 203The terminal device for confirming the network is not request updating key, ended the switch.
The pedal 203, at the same time terminal can also determine according successful is a network authentication.
Steps: 204~205The terminal device generates a first novel key, a authentication parameter of uniformity and according to for with the first novel key of for receiving; and uniform and apparatus, and network determining updated request key.
Here, wherein the uniform apparatus, and terminal by a network request upgrading key at the same time, further - determine according successful is a network authentication. The terminal according to the novel key of authentication parameter uniformity; and data consistency does not pass; and terminal can determine a network authentication failure.
A see from the current, the terminal identification network contains a request updating key, and data consistency to realize the authentication parameter for network transmitted through the first key and a new key; the groove caused the third party, and a obtained network transmission to terminal authentication parameter, is to distinguish the network contains with is a updating key request message, wherein, while are not as the authentication parameter information source, a network to request to the transmission terminal key updating information in a not divulge.
The embodiment, a terminal generating first novel key is: The first key of the terminal according to RAND received in authentication parameter and thereof preserves to generate the first novel key.
The embodiment, wherein the terminal to act according to the authentication parameter uniformity of the first key of receiving is: The coding terminal (XMAC-A) according to the first acquiring key expectation message authentication, and from the authentication parameter of XMAC-A received and there is consistent; The terminal to act according to the authentication parameter uniformity of the first novel key judging is received: The terminal and XMAC-A according to the first novel key, and from the authentication parameter of XMAC-A received and there is consistent.
The embodiment, when the network terminal request updating key, wherein the network gain authentication parameter is: Generating RAND, the second key according and according to RAND generating and device thereof preserves to generate the novel key, and generating MAC-A according to the second novel key for generating, at the time, wherein the network obtaining the authentication parameter comprises RAND and MAC-A; The network by terminal to request updating key, wherein the network gain authentication parameter is: Generating RAND, the second key according and according to RAND generating and device thereof preserves to generate MAC-A, at the time, wherein the network obtaining the authentication parameter comprises RAND and MAC-A. The authentication parameter of terminal of XMAC-A received and a uniform is: XMAC-A of terminal of receive's and MAC-A for generating a are consistent.
The embodiment, wherein the network is can further arranged second SQN, second SQN when the network to generate MAC-A to act according to, wherein the network obtaining the authentication parameter comprises RAND and second SQN and MAC-A. Wherein, when the network terminal request updating key, a network generating MAC-A according to RAND, the second novel key and second SQN device for generating; The network by terminal to request updating key, a network generating MAC-A according to RAND, the second key and second SQN for generating thereof. The corresponding position; the terminal to act according to the first novel key is an XMAC-A is: The terminal according to RAND and second SQN of the first novel key and receiving, generated by; XMAC-AThe terminal to act according to the first button to gain XMAC-A is: The terminal according to RAND and second SQN of the first key and receiving, generated by XMAC-A.
The embodiment, wherein the first novel key of the terminal automatically according to for generating to determine the authentication parameter's uniformity of receiving terminal, and further - comprising: The terminal device for confirming is successful to the network, authenticationThe first novel key according with the air according to for generating to determine the authentication parameter's uniformity of rotator are not pass, and further - comprising: The terminal determining a network authentication failure.
The embodiment, wherein the terminal is further arranged first SQN, wherein the terminal to determine according to the network authentication succeeds - comprising: The second SQN of the first SQN for determining whether a housing; each; and device for confirming is successful to the network, authentication otherwise, determining of second SQN by the synchronous a first SQN.
A through the specific embodiment, invention the invention to request in detail renewed method for key.
In one embodiment, a network is provided with a second key and second SQN, a communication terminal is provided with a key first and second SQN.
Shown the digital 3 is the invention first embodiment current position, comprising the following steps: Steps: 301Network gain authentication parameter, and authentication to parameter of terminal used for obtaining.
Here, authentication of parameter obtaining network comprises: MAC-A of second SQN according RAND device for generating, which makes, and generating thereof. The gain authentication parameter's special which can be: The network first generating RAND, RAND and key according and other network updating key, according to dynamically of the second novel key, and generated by MAC-A according to the second novel key according RAND and generating; A network no need to the upgrade key, generated by MAC-A according to the second key of RAND, second and SQN is.
The network gain authentication parameter, and further updating the second SQN value. Updating the SQN value relate to increase second SQN a random capacity. For of the is 1 to 256 and any sheets to obtain the new second SQN value.
Steps: 302The terminal receiving authentication parameter for transmitting network, RAND and second SQN according to preserves makes the first key according for generating XMAC-A, XMAC-A according MAC-A for determining and receiving and generating is a consistent, a judging of MAC-A and XMAC-A is the same, and consistent; and operating 303, theA inconsistent, and operating order 306.
Steps: 303The terminal device for confirming the network is not request updating key, and further verifying second SQN wherein a housing, and a housing; and operating 304, theOtherwise, operating order 305.
The terminal verifying second SQN wherein a housing, can be of SQN first and second SQN differential value wherein the multiple range, for example, determining (SQN- first and second SQN the) is greater than 0; or the first SQN- second SQN the) is greater than 0, and is less than 65536, equal. A differential value; the range; and device for confirming second SQN a housing, otherwise, determining of second SQN capable of receiving.
The terminal of the acceptable apparatus of the second SQN terminal, and further shaft according to SQN second to updating first SQN, for example, wherein the first SQN value and a second SQN equal value.
Steps: 304The terminal device for confirming is successful to the network, authentication ended the switch.
Steps: 305The terminal by the second SQN by the synchronous a first SQN, ended the switch.
Steps: 306The terminal device generates a first novel key, RAND according to generating first novel key according and a to generate XMAC-A, XMAC-A according MAC-A for determining and receiving and generating is a consistent, a judging of MAC-A and XMAC-A is the same, and consistent; and operating 307, theA inconsistent, and operating order 308.
Here, a terminal generating first novel key is: The first key of the terminal according to RAND received in authentication parameter and thereof preserves to generate the first novel key.
Steps: 307The terminal device for confirming the network request updating key, ended the switch.
The pedal 307, terminal by a network request upgrading key at the same time, and further - determine according successful is a network authentication.
Steps: 308The terminal device for confirming to the network authentication failure, ended the switch.
A see from the flow, terminal while to network authentication, it can further respectively a network contains a request updating key, a network to request to the transmission terminal key updating information in a not divulge.
The pedal 301, wherein the network requirement updating key generation, the MAC-A, and further shaft according to SQN second; The corresponding position; when the step 306, generating the XMAC-A, further according to SQN second time. , Corresponding to a terminal and network request updating key, further - comprising: The second SQN of the first SQN for determining whether a housing, and then, and network request updating key, otherwise, determining of second SQN by the synchronous a first SQN. In aggregate of the ACK/NAK, detailed a specific of the second one embodiment.
A to the second embodiment, wherein the work and other network updating key, when generating MAC-A, a base RAND and second novel key base of the first embodiment of the further according to the second SQN production. In aggregate of the condition; and current position of shown the digital 4, comprising the following steps: Steps: 401Network gain authentication parameter, and authentication to parameter of terminal used for obtaining.
Here, authentication of parameter obtaining network comprises: Any of RAND for generating, a second SQN, and generating message authentication MAC-A codes. , Network first generating any of RAND; and network requirement updating key generation, the second novel key according to any number and second key, and generated by MAC-A according to the second novel key of RAND, second and SQN, productionA network no need to the upgrade key, generated by MAC-A according to the second key of RAND, second and SQN is.
The network gain authentication parameter, and further updating the second SQN value. Updating the SQN value relate to increase second SQN a random capacity. For of the is 1 to 256 and any sheets to obtain the second SQN novel value.
Steps: 402The terminal receiving authentication parameter for transmitting network, RAND and second SQN according to XMAC-A according preserves the first key according for generating XMAC-A, determining a MAC-A for generating and there is consistent, a judging of MAC-A and XMAC-A is the same, and consistent; and operating 403, theA inconsistent, and operating order 405.
Steps: 403The terminal device for confirming the network is not request updating key, and further verifying second SQN wherein a housing, and a housing; and operating 404, theOtherwise, operating order 408.
Steps: 404The terminal device for confirming is successful to the network, authentication ended the switch.
Steps: 405The terminal device generates a first novel key, according to generating for consistency RAND and second SQN of the first novel key, a generating XMAC-A, the output line according MAC-A and generating, a judging of MAC-A and XMAC-A is the same, and consistent; and operating 406, theA inconsistent, and operating order 409.
Here, a terminal generating first novel key is: The first key of the terminal according to RAND received in authentication parameter and thereof preserves to generate the first novel key.
Steps: 406The terminal verifying second SQN wherein a housing, and a housing; and operating 407, theOtherwise, operating order 408.
Here, a terminal verifying second SQN wherein a housing, can be of SQN first and second SQN differential value wherein the multiple range, for example, wherein the first SQN- second SQN) is greater than 0; or the first (SQN- second SQN) is greater than 0, and is less than 65536, equal. A differential value; the range; and left of second SQN is connected to, otherwise, determining second SQN capable of receiving.
Here, a terminal by the acceptable apparatus of the second SQN terminal, and further shaft according to SQN second to updating first SQN, for example, wherein the first SQN value and a second SQN equal value.
Steps: 407The terminal device for confirming the network request updating key, ended the switch.
The pedal 407, terminal by a network request upgrading key at the same time, further - to determine according successful is a network authentication.
Steps: 408The terminal by the second SQN by the synchronous a first SQN, ended the switch.
Steps: 409The terminal device for confirming to the network authentication failure, ended the switch.
The embodiment, the invention can 406) is: The terminal without end part of verifying second SQN for operating acceptable, a terminal confirmed by a network request the updating key and ended the current; and at longer operating order 407 and 408.
The producing the second novel key and a new key, and generating MAC-A and XMAC-A computational value can be part dead computations or the encryption computations, a invention can be for field male knowledge part algorithms.
The key first and second key can be a pair of symmetrical key, leads middle; the two can be full same.
A heating to realize the request to updating keys, system and shown the digital 5, wherein system comprises: The key updating causing device and a upgrading request recognition system. , Wherein the key is updating causing the device for obtaining authentication parameter, authentication parameter and a gain transmitting the key upgrading to the support recognition system,The key is updating the authentication parameter of the support recognition system to received, determining whether request the key updating.
A a detail in the key updating causing device and a updating the support identifying an internal structure.
The key updating causing device in structure to see digital 5, shown and a digital 5, the key updating causing the device comprises: Causing the support decision unit 500, the second guide key unit 501, the second novel key generation unit 502, wherein the number of unit 503, power of any of unit 504, authentication parameter obtaining unit 505, authentication parameter data transmission unit 506.
, Wherein causing the support decision unit 500 to fix the causing upgrading key is request, and a locating the inspection transmitting the authentication parameter obtaining unit; The second guide key unit 501 to perform balanced the second key; The second novel key to generate unit 502 to generate the novel key; The power of any unit are 504 to a random; theThe authentication parameter obtaining 505 unit based on from causing a decision result of request decision unit 500, obtained from the second guide key unit 501 to obtaining the second key or from the second novel key to generate unit 502 to obtaining the novel key, wherein the generation of any device for obtaining 504 to sheets, and according to the key and a power of any of authentication parameter gained, transmitted to the authentication parameter data transmission unit, 506The authentication parameter of the authentication parameter data transmission unit to 506 and substrate-processing to the key upgrading to the support recognition system. The network serial number of unit is 503 serial sheets; at the time, the key renewed causing device from the network serial number of the gain 503 serial sheets; and in a authentication parameter, according to serial number of gained, and key and power of any of.
The key updating causing the device; and second novel key to generate unit 502 of the second novel key, a wherein the generation of any device for obtaining 504 to sheets; from the second guide key unit 501 to obtaining the second key, and generating of the second novel key according to any number and second key according gained.
The key updating causing the device, when causing the support decision unit 500 to fix heating when the key is updating, wherein the authentication parameter obtaining device 505 and second novel key to generate unit 502 to obtaining the novel key; When causing the support decision unit 500 decisions is made and vibrates the key renewed, wherein the authentication parameter obtaining device 505 and second guide key unit 501 to obtaining the second key.
A heating to the key is updating the internal drawing structure of request recognition system, and shown the digital 6, wherein the device comprises: The authentication parameter receiving unit 601, wherein the uniform data unit 602, wherein the first guide key unit 603, wherein the first novel key generation unit 604, recognizing unit 605. The device capable the further - comprising: Acquisition unit 606, authentication device 607, terminal serial number of unit 608, wherein a sheets and judging unit 609. The phase the function of each units are completed.
The authentication parameter receiving unit for 601 to the authentication parameter data transmission unit 506 the transmission parameters authentication; The first guide key unit 603 to perform balanced the first key; The uniform authentication device 602 and first guide key unit 603 to obtaining the first button, or from the first novel key to generate unit 604 to obtaining the first novel key, and authentication parameter uniformity according to the key apparatus according gained authentication parameter receiving unit received 601, wherein the confirm results to transmit the identification device 605 and first novel key to generate unit 604, theThe inspection apparatus for recognizing unit based 605 received, wherein the determining network request updating the key; The first novel key comprises a data result of the unit based 604 received, a the first novel key, wherein the inspection data received for data consistency are not pass; and generating first novel key.
The uniform data unit (602) comprises: Authentication parameter regenerating device 602-1 and authentication parameter comparing unit 602-2. The authentication parameter regenerating device based 602-1 from the comparison result of authentication parameter comparing unit 602-2, received from the first guide key unit 603 to obtaining the first button, or from the first novel key to generate unit 604 to obtaining the first novel key, and according to the key gain authentication parameter of gained, authentication parameter and a gain is the authentication parameter comparing unit; 602-2The authentication parameter comparing unit 602-2 comparisons from the authentication parameter of authentication parameter regenerating device 602-1 received and authentication parameter of authentication parameter receiving unit 601 received, and a compare the results to transmit the recognizing unit 605, wherein keys new generation device 604 and authentication parameter regenerating device 602-1. At the same time, the first novel key of the comparison result of the unit based 604 received, a the first novel key, when comparison result the received is inconsistent result, and a the first novel key.
Here, wherein the parameter authentication comparing unit 602-2 to compare to perform feeding back of the authentication parameter regenerating device; 602-1Authentication parameter regenerating device 602-1 according to the comparison result of feedback obtaining, as for generating unit 604 to obtaining the first novel key of the first novel key. Authentication parameter regenerating device 602-1 first time from the first guide key unit 603 to obtaining the first button, wherein from the authentication parameter comparing unit 602-2 received the comparison result of the inconsistent results from, wherein the first novel key to generate unit 604 to obtaining the first novel key.
The key upgraded a request recognition system the gain unit (606) and authentication parameter of authentication parameter receiving unit (601) is received gain random number and serial number, a random number and serial number and a gain is connected with the authentication parameter regenerating device; 602-1The authentication parameter regenerating device 602-1 is used to act according to form the first guide key unit or 603 wherein the first novel key to generate a key and a a random number and serial number of unit 604 gained acquisition unit received 606, wherein the gain authentication parameter.
When the first novel key to generate unit 604 a the first novel key, a wherein the number of random of numbers 606 gain authentication parameters, from the first guide key unit 603 to obtaining the first button, and generating to the first novel key according to any number and a key according gained.
Here, the function of obtaining unit 606 realizations, and 601 realized via authentication parameter receiving unit, wherein the parameter authentication receiving device 601 and a random number and serial number of the parameter authentication device, receiving and transmitting the needing unit, for example, wherein the parameter authentication regenerating device 602-1, the first novel key to generate unit 604, authentication parameter comparing unit 602-2.
The key is updating the support recognition system further - comprising authentication device 607, wherein the authentication device 607 and uniform data unit 602 gain uniformity results apparatus, and according to the data consistency result of gained, determining according to network authentication wherein succeeded. A data consistency result and is uniformly apparatus, and determines the authentication success of network, otherwise, determining a authentication failure of network.
The key is updating the support recognition system further - comprising: Terminal which are arranged unit 608, wherein the number and judging unit 609. The terminal serial number of unit is 608 terminals' serial sheets, charges to the serial number of all-around leakage protective to move the judging unit 609, theThe gain unit (606) and authentication parameter of the authentication parameter receiving unit is received obtaining the serial number, a serial number and a gain is a series of relate to move the judging unit 609, theThe serial number is connected to the second judging unit based 609 from the serial number of terminal according serial number of unit 608 received from the serial number of obtaining unit 606 received wherein a housing, and is a plurality of the identification device 605 and authentication device, 607The identification unit is 605 to act according to from a series of a and output result for judging unit 609 obtained, wherein the determining network request updating the key; The authentication unit is 607 to act according to from a series of a and output result for judging unit 609, obtained by according to network authentication wherein succeeded.
The key updating for of the heating device is arranged is arranged on the network side, the key updating request recognition system for of the is arranged in the terminal. The key is updating causing device is connected to a authentication method of causing the key part, updatingFurther through the key upgrading to the support recognition system, can not only for identifying network contains a request updating key meanwhile, and a on the authentication to the network.
The is relatively without embodiment of this invention, which is set as to limit the invention, wherein each of the spirit and managing of the invention, any revised part and alternative, improved of the equal, which comprises a has a protection of this invention.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US8300827B2 | Cited by | United States of America | Applicant |
| US10999065B2 | Cited by | United States of America | Applicant |
| US9031240B2 | Cited by | United States of America | Applicant |
| US10057769B2 | Cited by | United States of America | Applicant |
| WO2012065422A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US8144877B2 | Cited by | United States of America | Applicant |
| US8023658B2 | Cited by | United States of America | Applicant |
| CN105722077A | Cited by | China | Search report |
1 member in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 200610159711 | China | A | |
| CN20061159711 | – | – | – |
Members1
| Document | Office | Kind | |
|---|---|---|---|
| CN1953369AThis record | China | A |
Numbers
- Publication
- 1953369
- Publication, DOCDB
- 1953369
- Publication, EPODOC
- CN1953369
- Application
- 101597119
- Application, DOCDB
- 200610159711
- Application, EPODOC
- CN20061159711
Titles2
- English
- A method, system and device to initiate and identify secret key update request
- Chinese
- 一种发起与识别更新密钥请求的方法、系统和装置
Classification
- IPC, 2
- H04L9 16
- H04L9 08