Nova Patents
EP2291946B2

Cryptographic key generation

Abstract

This record has no abstract on file.

EP2291946B2, drawing sheet 1
Sheet 1 of 28

Term

1.8 yearsleft in the term

Expires 21 July 2028.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

17 claims: 3 independent, 14 dependent

  1. 1
    A method for generating a cryptographic key (120) for protecting mobile communication between two entities (202, 204), wherein the method is carried out by the first entity (202, 302) as part of an Authentication and Key Agreement (AKA) procedure based on an UMTS AKA protocol initiated by the second entity (204, 304), the method being characterized by the steps of:- providing (306) at least two parameters (106, 108), wherein the first parameter (106) comprises or is derived from a set of cryptographic keys (110, 112) having been computed by the first entity (202) by running the AKA procedure and the second parameter comprises or is derived from a token (116) having a different value each time the AKA procedure is initiated by the second entity (204, 304) for the first entity (202, 302);and - applying (308) a key derivation function to generate a cryptographic key (120) based on the provided parameters (106, 108);wherein the token (116) is a concatenation of the exclusive OR of a sequence number and an Anonymity Key , an Authentication and Key Management Field , and a Message Authentication Code , wherein the SQN indicates the number of times the AKA procedure has been initiated by the second entity (204, 304) for the first entity (202, 302), and wherein the AK is a cryptographic key produced by a key generation function f5 using a random challenge pursuant to the UMTS AKA protocol.
  2. 10
    A computer program product characterized by computer program code portions for executing the steps of the method according to any one of the preceding claims when the computer program product is run on a computer system.
  3. 12
    A device (100) adapted to generate a cryptographic key (120) for a mobile communications entity (202, 302) adapted to run an Authentication and Key Agreement procedure based on an UMTS AKA protocol, the device (100) being characterized by :- a first component (102) adapted to provide at least two parameters (106, 108), wherein the first parameter (106) comprises or is derived from a set of cryptographic keys (110, 112) having been computed by the mobile communications entity (202, 302) by running the AKA procedure, and the second parameter (108) comprises or is derived from a token (116), the at least two parameters provided having a different value each time the AKA procedure is initiated for the mobile communications entity (202, 302);and - a second component (104) adapted to run a key derivation function to generate a cryptographic key (120) based on the provided parameters (106, 108);wherein the token (116) is a concatenation of the exclusive OR of a sequence number and an Anonymity Key (AK), an Authentication and Key Management Field , and a Message Authentication Code , wherein the SQN indicates the number of times the AKA procedure has been initiated for the mobile communications entity (202, 302), and wherein the AK is a cryptographic key produced by a key generation function f5 using a random challenge pursuant to the UMTS AKA protcol.
  4. 14
    The device (100) of any one of the claims 12 to 13, further adapted to apply one or more further key derivation functions to generate more cryptographic keys based on the cryptographic key (120) generated.
  5. 15
    A user equipment (202) characterized by the device (100) according to any one of the claims 12 to 14.