EP0955783A2

Method and apparatus for performing authentication for roaming between different mobile communication systems

Abstract

A method and apparatus for permitting global roaming between two communication networks which utilize different authentication schemes. The authentication interoperability function (AIF) and method translate between the authentication schemes of each network, for example, a triplet-based network and a shared secret data (SSD) network. When a user from a network that natively uses SSD authentication roams into a triplet-based network, the authentication interoperability function produces triplets from the current SSD. When a triplet user roams into an SSD network, the AIF produces SSD from the triplet.

EP0955783A2, drawing sheet 1
Sheet 1 of 11

Term

Term ended

Projected expiry passed 27 April 2019, 7.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

58 claims: 12 independent, 46 dependent

  1. 1
    An authentication interoperability function for facilitating authentication of a user from a first network when the user is in a second network, having a different authentication scheme from the first network, said authentication interoperability function receiving a challenge/response pair from an authentication data base in the first network, creating a secondary key from the challenge/response pair, and sending the secondary key to an intermediary in the second network to authenticate the user from the first network.
  2. 8
    An authentication interoperability function for facilitating authentication of a user from a first network when the user is in the second network, having a different authentication scheme from the first network, said authentication interoperability function receiving a secondary key from an authentication data base from the first network, creating a challenge/response pair from the secondary key, and sending the challenge/response pair to an intermediary in the second network to authenticate the user from the first network.
  3. 15
    A method of authenticating a user from a first network when the user is in a second network, having a different authentication scheme from the first network, said method comprising the steps of:receiving a challenge/response pair from an authentication data base in the first network;generating a key from the challenge/response pair;and authenticating the user based on the key.
  4. 20
    A method for authenticating a user from a first network when the user is in a second network, having a different authentication scheme from the first network, said method comprising the steps of:generating a challenge/response pair from a key;transmitting the challenge/response pair to an intermediary in the first network;authenticating the user based on the challenge/response pair.
  5. 25
    An interface for authenticating a user from a first network when the user is in a second network, having a different authentication scheme from the first network, said interface comprising:a message containing a challenge/response pair from an authentication data base in the first network to an intermediary in the second network.
  6. 31
    An interface for authenticating a user from a first network when the user is in a second network, having a different authentication scheme from the first network, said interface comprising:a message containing a challenge from an intermediary in the first network to the user and a response from the user to the intermediary in the first network.
  7. 39
    An intermediary for authenticating a user from a first network when the user is in a second network, having a different authentication scheme from the first network, said intermediary comprising:a receiving element for receiving a challenge/ response pair from an authentication data base in the first network;a generating element for generating a key from the challenge/response pair;an authenticating element for authenticating the user based on the key.
  8. 44
    An authentication data base from facilitating authentication of a user from a first network when the user is in a second network, having a different authentication scheme from the first network, said location register comprising:a generating element for generating a challenge/ response pair from a key;a transmitting element for transmitting the challenge/response pair to an intermediary in the first network which authenticates the user based on the challenge/response pair.
  9. 45
    The authentication data base on claim 44, wherein the key is a secondary key generated from a primary key.
  10. 47
    The authentication data base of claim, 44, wherein the first network is a Global System for Mobiles (GSM) network, the second network is an IS-41 network, the intermediary in the first network is a visiting location register in the GSM network, and the authentication data base is a home location register in the IS-41 network.
  11. 49
    An intermediary for authenticating a user from a first network when the user is in a second network, having a different authentication scheme from the first network, said intermediary comprising:a receiving element for receiving a challenge/ response pair from a an authentication data base in the second network, which generated the challenge/response pair from a key;and an authenticating element for authenticating the user based on the challenge/response pair.
  12. 54
    An authentication data base for facilitating authentication of a user from a first network when the user is in a second network, having a different authentication scheme from the first network, said location register comprising:a generating element for generating a key from a challenge/response pair;a transmitting element for transmitting the key to an intermediary in the second network which authenticates the user based on the key.