EP1073233A2

Method and apparatus for performing a key update using bidirectional validation

Abstract

A key update system uses information in an update message from a communications system to generate a new key and perform a bidirectional validation of the new key. After a unit validates the new key, at least a portion of information from the update message is used by the communications system to validate the new key. As a result, the communications system is not required to generate and transmit a separate authentication challenge to validate the new key. For example, a wireless communications system can send an update message with a sequence RANDSSD to the wireless unit. The wireless unit generates a new SSD using at least a portion of the sequence RANDSSD, and the wireless unit uses at least a portion of the new SSD to generate a signature value AUTHBS to validate the new key and thereby the home authentication center that initiated the update of the SSD. After the wireless unit validates the new key by comparing the AUTHBS generated by the wireless unit with an AUTHBS generated by the wireless communications system, the wireless unit uses at least a portion of the sequence RANDSSD and at least a portion of the new SSD to generate the validation value AUTHSSD. The validation value AUTHSSD can be sent to the wireless communications system along with a confirmation signal indicating the wireless unit has validated the new key. The wireless communications system can validate the new SSD by comparing the validation value AUTHSSD received from the wireless unit with a validation value generated in the same fashion by the wireless communications system.

EP1073233A2, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Projected expiry passed 17 July 2020, 6.2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

21 claims: 4 independent, 17 dependent

  1. 1
    A method of updating a key maintained in a unit for communicating with a communications system, said method comprising:receiving a sequence;generating said key from a secret value stored in said unit at least a portion of said sequence;validating said key;generating a validation value using at least a portion of said sequence and at least a portion of said key;andsending said validation value to said communication system for said communication system to validate said key.
  2. 6
    A method of updating a key maintained for a unit in a communications system, said method comprising:sending an update sequence for said unit;sending a signature value for said unit using at least a portion of a key generated from a secret value stored in said communications system associated with said unit and at least a portion of said update sequence for said unit to validate said key;receiving a first validation value from said unit;andcomparing said first validation value with a said second validation value generated using at least a portion of said update sequence and at least a portion of said key.
  3. 12
    A key update system for enabling a unit to communicate with a communications system, said system comprising:processing circuitry being configured to receive a sequence and to generate a key from a secret value stored in said unit and at least a portion of said sequence, said system being configured to use said key to validate said key and to generate a validation value using at least a portion of said sequence and at least a portion of said key, said processing circuitry being configured to provide said validation value to said system for said system to validate said key.
  4. 17
    A system for updating a key maintained for a unit in a communications system, said system comprising:processing circuitry configured to provide an update sequence for said unit and to provide a signature value for said unit using at least a portion of a key generated from a secret value stored in said communications system associated with said unit, and at least a portion of said update sequence for said unit to validate said communications system, said processing circuitry further configured to receive a first validation value from said unit and to compare said first validation value and a said second validation value generated using at least a portion of said update sequence and at least a portion of said key.