EP2051433A1

A method, device and system for generating and distributing the key based on the diameter server

Abstract

A method for generating and distributing keys based on the Diameter server in the mobile communication field is disclosed herein. The MN sends the NAR identifier to the PAR; after receiving the identifier, the PAR sends the NAR identifier and the MN identifier to the Diameter server; after receiving the identifiers, the Diameter server generates a random number first, then generates a shared key according to the random key, and then sends the shared key to the NAR and sends the random number to the MN; after receiving the random number, the MN generates a shared key. An apparatus and system for generating and distributing keys based on the Diameter server are also disclosed herein. The technical solution under the present invention avoids the domino effect and enhances security of the shared key.

EP2051433A1, drawing sheet 1
Sheet 1 of 7

Term

Projected expiry 28 November 2027.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

17 claims: 4 independent, 13 dependent

  1. 1
    A method for generating and distributing keys based on a Diameter server, comprising:receiving, by the Diameter server, a message sent by a Previous Access Router ,PAR, before handover of a Mobile Node ,MN, wherein the message carries a New Access Router , NAR, identifier, abbreviated as NAR_ID, after the handover of the MN, and an MN identifier, MN_ID;generating a random number, and generating a key shared between the MN and the NAR according to the random number;sending the key shared between the MN and the NAR to the NAR;and sending the random number to the MN as a parameter for calculating the key shared between the MN and the NAR.
  2. 11
    A system for generating and distributing keys based on a Diameter server, comprising:a Mobile Node, MN, a Previous Access Router , PAR, a New Access Router, NAR, and a Diameter server;wherein, the Diameter server comprises: a Diameter key generating module, adapted to generate a random number and generate a key shared between the MN and the NAR according to the random number;and a sending module, adapted to send the shared key to the NAR, and send the random number to the MN as a parameter for calculating the key shared between the MN and the NAR.
  3. 15
    The system for generating and distributing keys based on the Diameter server according to any of claims 11-14, wherein the Diameter server further comprises:a key calculating unit, adapted for the Diameter server to calculate the key shared between the MN and the NAR according to this formula: shared key = PRF (key shared between the server and the MN, random number | NAR_ID | Diameter server identifier | MN_ID | validity period of the key);and the MN further comprises a key calculating unit, adapted for the MN to calculate the key shared between the MN and the NAR according to this formula: shared key = PRF (key shared between the server and the MN, random number | NAR_ID | Diameter server identifier | MN_ID | validity period of the key).
  4. 16
    A Diameter server, comprising:a Diameter key generating module, adapted to generate a random number, and generate a key shared between a Mobile Node, MN, and a New Access Router, NAR, according to the random number;and a sending module, adapted to send the shared key to the NAR, and send the random number to the MN as a parameter for calculating the key shared between the MN and the NAR.