EP1362452A2

Method and apparatus for providing authentication in a communication system

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 18 January 2022, 4.7 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

11 claims: 8 independent, 3 dependent

  1. 1
    Claims of equivalent WO 02067495 A2 What is claimed is:Claims 1. A method comprising the steps of: generating a random number, an expected response, and a derived cipher key;forwarding the random number and a random seed to a base station;, receiving, from the base station, a response to the random number and the random seed;comparing the response and the expected response;when the response matches the expected response, forwarding the derived cipher key to the base station.
  2. 3
    A method performed by any of a base station and comprising the steps of:receiving an authentication request from a mobile station;determining whether to forward the request to an authentication agent;when it is determined to forward the request, forwarding the request to the authentication agent;receiving a random number and a random seed from the authentication agent;forwarding the random number and the random seed to the mobile station;receiving a response to the random number and the random seed from the mobile station and forwarding the response to the authentication agent;when the authentication agent authenticates the mobile station, receiving a derived cipher key from the authentication agent;encrypting messages to the mobile station and decrypting messages from the mobile station with the derived cipher key.
  3. 4
    6. A method performed by a base station and comprising the steps of:receiving a random number from a mobile station;forwarding the random number to an authentication agent;receiving a response to the random number and a random seed from the authentication agent;forwarding the response and the random seed to the mobile station;when the mobile station authenticates the infrastructure, forwarding an authenticated message to the authentication agent;receiving a derived cipher key from the authentication agent;encrypting messages to the mobile station and decrypting messages from the mobile station with a derived cipher key.
  4. 5
    7. A method comprising the steps of:generating session authentication information for each of a plurality of authentication keys for use in a communication system;encrypting the session authentication information;forwarding the encrypted session authentication information to a storage device for access in a non-real-time manner.
  5. 8
    10. A system comprising:.;, a key management facility, arranged and constructed to store an authentication key for each mobile station residing in the system;a user configuration server, operably coupled to the key management facility, arranged and constructed to store and distribute session authentication information for each mobile station residing in the system;a zone manager, operably coupled to the user configuration server, arranged and constructed to store relevant session authentication information for a zone managed by the zone manager and to distribute the relevant session authentication information to a home location register within a zone controller for the zone;wherein the key management facility, user configuration server, and the zone manager are arranged and constructed to provide the session authentication information to each other or to a zone in the even of a fault in the system;wherein the home location register is arranged and constructed to continue to provide authentication and support secure communications in the event of a fault at any of the key management facility, user configuration server, and the zone manager.
  6. 9
    11. A system comprising:a plurality of first- 1 eve I system devices, arranged and constructed to encrypt, store, and forward at least some session authentication information in a non-real-time manner;a plurality of second-level system devices, arranged and constructed to receive at least a part of the session authentication information from at least one of the plurality of first-level system devices in a real-time manner.
  7. 10
    12. A method comprising the steps of:receiving, from a mobile station, a request to communicate in a communication system;determining whether the request is encrypted;when the request is not encrypted, sending a request to authenticate the mobile station to an infrastructure device in the communication system;when the request is encrypted, determining whether the mobile station is powering up;when the mobile station is powering up and the request is encrypted, sending a request to authenticate the mobile station to the infrastructure device in the communication system;when the mobile station is not powering up and the request is encrypted, determining whether the request is encrypted using a valid key;when the mobile station is not powering up and the request is encrypted using a valid key, permitting the mobile station access to the system without requesting authentication.
  8. 11
    13. A method comprising the steps of:receiving, from a mobile station, a request to communicate in a communication system;determining whether the mobile station is powering up;when the mobile station is powering up, sending a request to authenticate the mobile station to an infrastructure device in the communication system;when the mobile station is not powering up, determining whether the request is encrypted;when the request is not encrypted, sending a request to authenticate the mobile station to an infrastructure device in the communication system;when the mobile station is not powering up and the request is encrypted, determining whether the request is encrypted using a valid key;when the mobile station is not powering up and the request is encrypted using a valid key, permitting the mobile station access to the system without requesting authentication.