Performing a group authentication and key agreement procedure
Summary by NHIP
Group Authentication Method
The method initiates a group authentication and key agreement procedure via a master device using a shared group key. Upon failure, the master device instructs specific devices to individually initiate authentication toward an entity instead of retrying the group process.
Claim Score by NHIP
Abstract
Provided are a method, a corresponding apparatus and a computer program product for performing a group authentication and key agreement procedure. A method comprises initiating, by a master device in a group of devices, a group authentication and key agreement procedure towards an authentication entity, wherein a shared group key is defined for use in the group authentication and key agreement procedure; performing mutual authentication between the master device and the authentication entity based upon the shared group key; and performing mutual authentication between the authenticated master device and other devices in the group based upon the shared group key for completion of the group authentication and key agreement procedure. With the claimed invention, the impact of the signaling overhead on a network can be significantly decreased without substantive modification to the existing architecture of the network.

Term
4.7 yearsleft in the term
Expires 26 May 2031.
- Priority and filed
- Granted
- Today
- Expires
18 claims: 3 independent, 15 dependent
- 1Broadest claimClaim Score 50, average(NHIP)A method, comprising:initiating, by a master device in a group of devices, a group authentication and key agreement procedure towards an authentication entity, wherein a shared group key is defined for use in the group authentication and key agreement procedure;performing mutual authentication between the master device and the authentication entity based upon the shared group key;performing mutual authentication between the authenticated master device and other devices in the group based upon the shared group key for completion of the group authentication and key agreement procedure;and in response to failure by one or more devices in the group authentication and key agreement procedure, instructing, by the master device, one or more of the devices that have failed, to initiate an authentication and key agreement procedure towards the authentication entity individually.
- 9An apparatus, comprising:at least one processor, and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to at least perform: initiating, by the apparatus in a group of devices, a group authentication and key agreement procedure towards an authentication entity, wherein a shared group key is defined for use in the group authentication and key agreement procedure;performing mutual authentication between the apparatus and the authentication entity based upon the shared group key;performing mutual authentication between the authenticated apparatus and other devices in the group based upon the shared group key for completion of the group authentication and key agreement procedure;and in response to failure by one or more devices in the group authentication and key agreement procedure, instructing, by the master device, one or more of the devices that have failed, to initiate an authentication and key agreement procedure towards the authentication entity individually.
- 18A non-transitory computer readable medium storing a program of instructions, execution of which by at least one processor configures an apparatus to perform at least:initiating, by a master device in a group of devices, a group authentication and key agreement procedure towards an authentication entity, wherein a shared group key is defined for use in the group authentication and key agreement procedure;performing mutual authentication between the master device and the authentication entity based upon the shared group key;performing mutual authentication between the authenticated master device and other devices in the group based upon the shared group key for completion of the group authentication and key agreement procedure;and in response to failure by one or more devices in the group authentication and key agreement procedure, instructing, by the master device, one or more of the devices that have failed, to initiate an authentication and key agreement procedure towards the authentication entity individually.
Independent claims3
56 paragraphs in 6 sections, as filed
RELATED APPLICATION
This application was originally filed as PCT Application No. PCT/CN2011/074693 filed May 26, 2011.
FIELD OF THE INVENTION
Embodiments of the present invention generally relate to wireless communication. More particularly, embodiments of the present invention relate to a method, an apparatus, and a computer program product for performing a group authentication and key agreement procedure on a group of communication devices, e.g., machine-type-communication devices.
BACKGROUND OF THE INVENTION
Various abbreviations that appear in the specification and/or in the drawing figures are defined as below: <ul id="ul0001" list-style="none"><li id="ul0001-0001" num="0000"><ul id="ul0002" list-style="none"><li id="ul0002-0001" num="0004">3GPP Third Generation Partnership Project</li><li id="ul0002-0002" num="0005">LTE Long Term Evolution</li><li id="ul0002-0003" num="0006">BS Base Station</li><li id="ul0002-0004" num="0007">MS Mobile Station</li><li id="ul0002-0005" num="0008">MME Mobility Management Entity</li><li id="ul0002-0006" num="0009">UE User Equipment</li><li id="ul0002-0007" num="0010">IMSI International Mobile Subscriber Identity</li><li id="ul0002-0008" num="0011">ASME Access Security Management Entity</li><li id="ul0002-0009" num="0012">TMSI Temporary Mobile Subscriber Identity</li><li id="ul0002-0010" num="0013">MTC Machine Type Communication</li><li id="ul0002-0011" num="0014">HSS Home Subscriber Server</li><li id="ul0002-0012" num="0015">IMEI International Mobile Equipment Identity</li><li id="ul0002-0013" num="0016">AV Authentication Vector</li><li id="ul0002-0014" num="0017">USIM Universal Subscriber Identity Module</li><li id="ul0002-0015" num="0018">AUTN Authentication Token</li><li id="ul0002-0016" num="0019">RAND Random Challenge</li><li id="ul0002-0017" num="0020">GPRS General Packet Radio Service</li><li id="ul0002-0018" num="0021">SGSN Serving GPRS Support Node</li><li id="ul0002-0019" num="0022">XRES Expected Response</li><li id="ul0002-0020" num="0023">CK Cipher Key</li><li id="ul0002-0021" num="0024">IK Integrity Key</li><li id="ul0002-0022" num="0025">AK Anonymity Key</li><li id="ul0002-0023" num="0026">XMAC Expected Message Authentication Code</li><li id="ul0002-0024" num="0027">MAC Message Authentication Code</li><li id="ul0002-0025" num="0028">AuC Authentication Center</li><li id="ul0002-0026" num="0029">AKA Authentication and Key Agreement</li></ul></li></ul>
An AKA procedure is a procedure that has been employed by many communication systems of today for the purpose of improving system security and robustness. One such an AKA procedure has been detailed in 3GPP Technical Specifications 33.102 and 33.401, which are incorporated herein by reference in their entirety. The AKA procedure, which may involve a challenge-response authentication procedure as known in the art, will inevitably cause certain amount of signaling overhead. When the number of devices to be authenticated in the AKA procedure is relatively low, it will merely cause small amount of overhead for the network. However, in a situation where devices to be simultaneously authenticated are numerous, it will generate tremendous signaling overhead that may burden the bandwidth and processing capability of the network. This is especially true for machine-type communications in which many MTC devices formed in groups will initiate their own AKA procedures towards the network simultaneously and thereby make negative impact on the network. For more information regarding MTC communications, see 3GPP Technical Report 33.868, which is also incorporated herein by reference in its entirety.
Therefore, what is needed in the prior art is means for performing a group AKA procedure on a group of devices in an efficient and secure manner such that the impact of signaling overhead on the network could be decreased.
SUMMARY OF THE INVENTION
A method, an apparatus, and a computer program product are therefore provided for performing a group AKA procedure on a group of devices. In particular, a method, an apparatus and a computer program product are provided where a master device in a group of devices, upon completion of its own authentication with the network (i.e., authentication entities), may authenticate other devices in the group on behalf of the network. Thus, for example, the impact of the signaling overhead on the network may be decreased without substantive modification to the existing architecture of the network.
One embodiment of the present invention provides a method. The method comprises initiating, by a master device in a group of devices, a group authentication and key agreement procedure towards an authentication entity, wherein a shared group key is defined for use in the group authentication and key agreement procedure. The method also comprises performing mutual authentication between the master device and the authentication entity based upon the shared group key. Additionally, the method comprises performing mutual authentication between the authenticated master device and other devices in the group based upon the shared group key for completion of the group authentication and key agreement procedure.
In one embodiment, the master device is selected by an owner of the group of devices, an owner of the master device or a network operator.
In another embodiment, a plurality of different shared group keys are defined for a plurality of different groups of devices such that the device has a plurality of the shared group keys based upon the groups to which it belongs.
In an additional embodiment, the performing mutual authentication is based upon a challenge-response authentication procedure.
In one embodiment, the method further comprises sending, from the master device, to the authentication entity a message regarding results of the group authentication and key agreement procedure.
In another embodiment, the method further comprises instructing, by the master device, one or more devices that have failed in the group authentication and key agreement procedure to initiate an authentication and key agreement procedure towards the authentication entity individually.
In an additional embodiment, the method further comprises generating, for one or more devices that have been successfully authenticated in the group authentication and key agreement procedure, a respective new shared key based upon one or more device specific parameters and an intermediate group key derived from the shared group key.
In another embodiment, the one or more device specific parameters are one or more of an existing specific key, an international mobile subscriber identity, a temporary mobile subscriber identity, and an international mobile equipment identity of the device.
In one embodiment, the existing specific key is a shared key derived from a shared root key between the device and an authentication center, and the respective new shared key is derived from the existing specific key and the intermediate group key.
An additional embodiment of the present invention provides an apparatus. The apparatus comprises means for initiating, by a master device in a group of devices, a group authentication and key agreement procedure towards an authentication entity, wherein a shared group key is defined for use in the group authentication and key agreement procedure. The apparatus also comprises means for performing mutual authentication between the master device and the authentication entity based upon the shared group key. Additionally, the apparatus comprises means for performing mutual authentication between the authenticated master device and other devices in the group based upon the shared group key for completion of the group authentication and key agreement procedure.
In one embodiment, the master device is selected by an owner of the group of devices, an owner of the master device or a network operator.
In another embodiment, a plurality of different shared group keys are defined for a plurality of different groups of devices such that the device has a plurality of the shared group keys based upon the groups to which it belongs.
In an additional embodiment, the performing mutual authentication is based upon a challenge-response authentication procedure.
In one embodiment, the apparatus further comprises means for sending, from the master device, to the authentication entity a message regarding results of the group authentication and key agreement procedure.
In another embodiment, the apparatus further comprises means for instructing, by the master device, one or more devices that have failed in the group authentication and key agreement procedure to initiate an authentication and key agreement procedure towards the authentication entity individually.
In an additional embodiment, the apparatus comprises means for generating, for one or more devices that have been successfully authenticated in the group authentication and key agreement procedure, a respective new shared key based upon one or more device specific parameters and an intermediate group key derived from the shared group key.
In a further embodiment, the one or more device specific parameters are one or more of an existing specific key, an international mobile subscriber identity, a temporary mobile subscriber identity, and an international mobile equipment identity of the device.
In one embodiment, the existing specific key is a shared key derived from a shared root key between the device and an authentication center, and the respective new shared key is derived from the existing specific key and the intermediate group key.
One embodiment of the present invention provides an apparatus. The apparatus comprises at least one processor and at least one memory including compute program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to at least perform: initiating, by a master device in a group of devices, a group authentication and key agreement procedure towards an authentication entity, wherein a shared group key is defined for use in the group authentication and key agreement procedure; performing mutual authentication between the master device and the authentication entity based upon the shared group key; and performing mutual authentication between the authenticated master device and other devices in the group based upon the shared group key for completion of the group authentication and key agreement procedure.
One embodiment of the present invention provides a computer program product. The computer program product comprises at least one computer readable storage medium having a computer readable program code portion stored thereon. The computer readable program code portion comprises program code instructions for initiating, by a master device in a group of devices, a group authentication and key agreement procedure towards an authentication entity, wherein a shared group key is defined for use in the group authentication and key agreement procedure. The computer readable program code portion also comprises program code instructions for performing mutual authentication between the master device and the authentication entity based upon the shared group key. The computer readable program code portion further comprises program code instructions for performing mutual authentication between the authenticated master device and other devices in the group based upon the shared group key for completion of the group authentication and key agreement procedure.
With certain embodiments of the present invention, the signaling overhead caused by performance of too many AKA procedures on a group of device will be decreased. Additionally, with the shared group key, secure communications between the group of devices and the network may be improved.
Other features and advantages of the embodiments of the present invention will also be understood from the following description of specific embodiments when read in conjunction with the accompanying drawings, which illustrate, by way of example, the principles of embodiments of the invention.
BRIEF DESCRIPTION OF THE DRAWINGS
A more complete understanding of various embodiments of the present invention and the advantages thereof may be acquired by referring to the following description in consideration of the accompanying drawings, in which like reference numbers indicate like features, and wherein:
<figref idref="DRAWINGS">FIG. 1</figref> exemplarily illustrates a simplified 3GPP network that provides an environment and structure for application of the principles of the present invention;
<figref idref="DRAWINGS">FIG. 2</figref> exemplarily illustrates a flow chart of a method for performing a group AKA procedure on a group of devices according to an embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 3</figref> is a flow chart exemplarily illustrating a method for performing a group AKA procedure on a group of devices under a LTE network according to an embodiment of the present invention; and
<figref idref="DRAWINGS">FIG. 4</figref> is a block diagram illustrating an apparatus for performing a group AKA procedure according to an embodiment of the present invention.
DETAILED DESCRIPTION OF EMBODIMENTS
In the following description of the various embodiments, reference is made to the accompanying drawings, which form a part thereof, and in which is shown by way of illustration various embodiments in which the present invention may be practiced. It is to be understood by those skilled in the art that other embodiments may be utilized and structural and functional modifications may be made without departing from the scope and spirit of the present invention.
In one embodiment of the present invention, a master device in a group of devices may initiate a group AKA procedure towards the network, e.g., an authentication entity. For the group AKA procedure, a shared group key is predefined so as to perform mutual authentication between master device and the network. When the master device has been successfully authenticated, it will authenticate other devices in the group in place of the authentication entity. In another embodiment of the present invention, if one or more devices in the group fail in the authentication, then each of them will initiate an individual AKA procedure with the authentication entity. In an additional embodiment of the present invention, the master device will send to the authentication entity a message regarding the results of the group AKA procedure.
<figref idref="DRAWINGS">FIG. 1</figref> exemplarily illustrates a simplified 3GPP network <b>100</b> that provides an environment and structure for application of the principles of the present invention. The network <b>100</b> as illustrated in <figref idref="DRAWINGS">FIG. 1</figref> includes a MTC device <b>102</b><i>a</i>, a MTC device <b>102</b><i>b</i>, and a master MTC device <b>104</b> that are located at an access portion of the network <b>100</b>. Additionally, the network <b>100</b> includes a MME (used in a LTE system) or SGSN (used in a 3G system) <b>106</b> and a HSS/AuC <b>108</b> that are located in the 3GPP bearer as illustrated by a circle, wherein the MME or SGSN <b>106</b> and HSS/AuC <b>108</b> belong to network-side (as compared to the access portion) entities and the MME or SGSN <b>106</b> may also be referred to as an authentication entity. Furthermore, the network <b>100</b> includes a MTC server <b>110</b><i>a </i>and a MTC server <b>110</b><i>b </i>that are connected to the 3GPP bearer and handle various transactions regarding a group of MTC devices, e.g., the group consisting of the MTC device <b>102</b><i>a</i>, <b>102</b><i>b </i>and <b>104</b> as illustrated in <figref idref="DRAWINGS">FIG. 1</figref>. It should be understood that the network <b>100</b> is provided as an example of one embodiment and should not be construed to narrow the scope or spirit of the disclosure in any way.
In a conventional AKA procedure, each device in a group of devices would have to initiate an AKA procedure towards the network individually. As illustrated with dotted lines in <figref idref="DRAWINGS">FIG. 1</figref>, the MTC devices <b>102</b><i>a </i>and <b>102</b><i>b </i>each initiate a AKA procedure towards the MME or SGSN <b>106</b> through their respective shared root key K<sub>i </sub>which has been stored in the USIM. Upon receipt of the AKA procedure requests, the MME or SGSN <b>106</b>, as an intermediate party, may interact with the HSS/AuC <b>108</b> so as to perform respective challenge-response procedures for authenticating the MTC devices <b>102</b><i>a </i>and <b>102</b><i>b</i>. Although only three MTC devices (including the master MTC device) are illustrated herein for exemplary purpose, there may be a group of hundreds of MTC devices in practice. When such a number of MTC devices initiate AKA procedures separately and simultaneously, it is unquestionable that the generated signaling overhead cause tremendous impact on the MME or SGSN <b>106</b> and HSS/AuC <b>108</b>.
An efficient way to alleviate the above impact on the network is to decrease the number of performed AKA procedures at the network side. To this end, embodiments of the present application propose performing a group AKA procedure on a group of devices, e.g., MTC devices. In the group AKA procedure, a master MTC device <b>104</b> may be selected or designated in a group of MTC devices beforehand by a network operator, an owner of the master MTC device, or an owner of the group of MTC devices (e.g., a company, such as a power company). Then the master MTC device <b>104</b> may initiate a group AKA procedure towards the authentication entity through a predefined shared group key K<sub>group </sub>that is similar to the key K<sub>i</sub>.
Upon completion of the AKA procedure between the master MTC device <b>104</b> and network-side entities, i.e., MME or SGSN <b>106</b> and HSS/AuC <b>108</b>, the master MTC device <b>104</b> may authenticate other MTC devices in the group on behalf of the network-side entities. In other words, other MTC devices in the group may perform individual AKA procedures no longer with network-side entities but with the master MTC device <b>104</b>. As such, the signaling overhead at the network side would be significantly decreased because the AKA procedure has been performed only once at the network side.
<figref idref="DRAWINGS">FIG. 2</figref> exemplarily illustrates a flow chart of a method <b>200</b> according to an embodiment of the present invention. The method starts at step S<b>201</b> and proceeds to step S<b>202</b> at which the method <b>200</b> initiates, by a master device in a group of devices, a group AKA procedure towards an authentication entity, wherein a shared group key is defined for use in the group AKA procedure. In one embodiment, the master device is selected by an owner of the group of devices, an owner of the master device or a network operator. In other words, any one of devices in the group may play a role as the master device to initiate the group AKA procedure as needed. In another embodiment, a plurality of different shared group keys are defined for a plurality of different groups of devices such that the device has a plurality of the shared group keys based upon the groups to which it belongs.
Upon initiation of the group AKA procedure, the method <b>200</b> advances to step S<b>203</b>. At step S<b>203</b>, the method <b>200</b> performs mutual authentication between the master device and the authentication entity based upon the shared group key. In one embodiment, the mutual authentication may be performed based upon a challenge-response authentication procedure in which the shared group key is used instead of a conventional key. As is known to those skilled in the art, the challenge-response authentication procedure is successful only when the device has authenticated the network and the network has authenticated the device.
Upon authentication of the master device and the network, the method <b>200</b> proceeds to step S<b>204</b> at which the method <b>200</b> performs mutual authentication between the authenticated master device and other devices in the group based upon the shared group key for completion of the group AKA procedure. Like step S<b>203</b>, the mutual authentication herein also may involve a challenge-response authentication procedure.
Although not shown in <figref idref="DRAWINGS">FIG. 2</figref>, the method <b>200</b> may comprise additional steps in various embodiments. For example, in one embodiment, the method <b>200</b> may instruct, by the master device, one or more devices that have failed in the group AKA procedure to initiate new AKA procedures towards the authentication entity individually. In another embodiment, the method <b>200</b> may send, from the master device, to the authentication entity a message regarding results of the group AKA procedure; thereby, the authentication entity can be aware of which devices in the group have passed through the group AKA procedure. In an additional embodiment, the method <b>200</b> may generate, for one or more devices that have been successfully authenticated in the group AKA procedure, a respective new shared key based upon one or more device specific parameters and an intermediate group key derived from the shared group key, wherein the one or more device specific parameters are one or more of an existing specific key, an international mobile subscriber identity, a temporary mobile subscriber identity, and an international mobile equipment identity of the device. In one embodiment, the existing specific key is a shared key derived from a shared root key between the device and an AuC, and the respective new shared key is derived from the existing specific key and the intermediate group key.
Finally, the method <b>200</b> ends at step S<b>205</b>.
For a better understanding of the embodiments of the present invention, a more complete and detailed example of a group AKA procedure will now be described with reference to <figref idref="DRAWINGS">FIG. 3</figref>, illustrating a method <b>300</b> for performing a group AKA procedure on a group of devices (e.g., embodied as MTC devices) under the LTE system. For proper implementation of the method <b>300</b>, it is assumed that a group of MTC devices has been registered to the network previously and each registered MTC device has a shared key K<sub>ASME </sub>with the network, though <figref idref="DRAWINGS">FIG. 3</figref> only illustrates for brevity one MTC device and one master MTC device that are in a same group. Further, it is assumed that a group key K<sub>group </sub>dedicated for the group AKA procedure has been defined and stored in each device in the group, e.g. on the USIM. Such a group key K<sub>group </sub>can be securely pushed to the device from the network based upon secure communication preestablished under the protection of the unique shared root key K<sub>i </sub>or a shared key derived from K<sub>i</sub>.
Based upon the above assumptions or a scenario established thereby, the method <b>300</b> starts at step S<b>301</b>, wherein the master MTC device, which can be selected from the group by an owner of the group of devices, an owner of the master device, or a network operator, sends a group AKA procedure request to the MME. Upon receipt of the group AKA procedure request, the MME, at step S<b>302</b>, requests an AV from the HSS/AuC. Due to the previous registration of the MTC devices to the network or an indicator indicative of the group AKA procedure in the request, the HSS/AuC determines that this request is in relation to a group AKA procedure. Thus, in order to assist in the group AKA procedure, it will generate an AV that includes, for example, four components, i.e., a RAND, an AUTN, a XRES, and a K<sub>ASME-GROUP</sub>. The component K<sub>ASME-GROUP </sub>is a shared intermediate key derived from the key K<sub>group</sub>. Regarding how to derive such a shared intermediate key, reference may be made to for example Annex of 3GPP TS 33.401. Alternatively, with respect to the components RAND and AUTN, each of them can be substituted by new components RAND<sub>group </sub>and AUTN<sub>group </sub>dedicated for a group AKA procedure, respectively. At step S<b>303</b>, in response to the request from the MME, the HSS/AuC sends the AV including the above four components to the MME.
Upon receiving the AV from the HSS/AuC, the MME, at Step S<b>304</b>, forwards the components RAND and AUTN to the master MTC device. The master MTC device, more particularly, its USIM, upon receipt of the RAND and AUTN, at step S<b>305</b>, first authenticates the MME by computing XMAC and comparing it with MAC included in AUTN. If XMAC equals MAC, then the master MTC device determines the MME is a trusted entity; otherwise, the master MTC device will abandon or abort the group AKA procedure this time and may attempt to reinitiate a group AKA procedure after a certain time interval. In one embodiment, when number of attempts to reinitiate the group AKA procedure exceeds a predefined limit, a new master device should be selected or assigned to initiate the group AKA procedure. Upon successfully authenticating the MME, the master MTC device generates a response RES based upon the shared group key K<sub>group </sub>and RAND. Afterwards, the master MTC device sends the response RES back to the MME.
To authenticate the master MTC device, the MME simply verifies that the response RES received from the master MTC device equals the XRES received in the AV. Once the response RES equals the XRES, authentication of the master MTC device towards the wireless network has been successfully completed. Alternatively, subsequent to the above mutual authentication, the master MTC device may compute a new shared key K<sub>ASME</sub>′ based upon the intermediate key K<sub>ASME-GROUP </sub>derived from K<sub>group </sub>and one or more device specific parameters. The one or more device specific parameters may be one or more of an existing specific key, e.g., K<sub>ASME</sub>, or other identifies, e.g., IMSI, TMSI or IMEI. For example, the key K<sub>ASME</sub>′ can be calculated, e.g., by an equation as below. <br />K<sub>ASME</sub>′=K<sub>ASME</sub>⊕K<sub>ASME-GROUP</sub> (1)
The resulting K<sub>ASME</sub>′ is used for further secure communication with the network. For example, the K<sub>ASME</sub>′ may be used to generate keys for other layers, such as the Non-Access Stratum, Access Stratus, and user plane. It should be noted that the above generation of the key K<sub>ASME</sub>′ is not necessary when the old K<sub>ASME </sub>is still suitable for further secure communication.
Having been successfully authenticated, the master MTC device, at step S<b>306</b>, sends RAND and AUTN to others devices in the group so as to perform the mutual authentication between itself and each of other devices in the group. Similar to the step S<b>305</b>, each of other devices in the group performs authentication operations on the master MTC device to assure such a master MTC device is a trusted master device rather than a masquerader of the master device. Likewise, upon successfully authenticating the master MTC device, the MTC device in the group generates a respective response RES based upon the shared group key K<sub>group </sub>and RAND and then forwards the RES to the master MTC device. Similarly, the master MTC device determines whether the RES equals the XRES. If this is the case, it indicates that the MTC device passes through the authentication; otherwise, optionally, at step S<b>307</b>, the master MTC device informs the MTC device of failure in the authentication. Then, alternatively or additionally, the MTC device that fails in the authentication may initiate an individual AKA procedure towards the network at step S<b>308</b>. Upon successful authentication by the master MTC device, at step S<b>309</b>, the MTC device may alternatively computes its own K<sub>ASME</sub>′ based upon its own existing specific key, e.g., K<sub>ASME</sub>, which may be unusable now, or its own identifies, e.g., IMSI, TMSI or IMEI. Alternatively, the MTC device may apply the equation (<b>1</b>) as discussed above with respect to the master MTC device to compute its own K<sub>ASME</sub>′ for further secure communication with the network.
The master device, at step S<b>310</b>, may send to the MME a message regarding the results of the group AKA procedure so that the MME may know which devices in the group have passed through the group AKA procedure. Similar to the MTC device, the MME may also compute, at step S<b>311</b>, a respective new shared key K<sub>ASME</sub>′ for further secure communication.
Although the foregoing has taken the LTE system and the group of the MTC devices as an example to describe an embodiment of the present invention, the present invention should not be limited thereto. A person skilled in the art can understand that the above method <b>300</b> may also be implemented, for example, in a 3G system and other types of a group of devices by some modifications. For example, when the method <b>300</b> is implemented in the 3G system, the above keys K<sub>ASME </sub>and K<sub>ASME-GROUP </sub>in the LTE system may be replaced by keys IK and CK, and IK<sub>group </sub>and CK<sub>group</sub>, respectively. Similarly, the SGSN in the 3G system will play the same role as the MME in the LTE system. In addition, in view of the fact that a person skilled in the art, based upon the disclosure and teaching of the present application, can implement the embodiments of the present invention without any additional efforts, further details regarding how to derive and use keys of various levels are omitted herein for not obscuring embodiments of the present invention unnecessarily with the prior art.
<figref idref="DRAWINGS">FIG. 4</figref> is a schematic diagram of an apparatus <b>400</b> according to another embodiment of the present invention, which implements relevant steps of methods <b>200</b> and <b>300</b> as illustrated in <figref idref="DRAWINGS">FIGS. 2 and 3</figref>. The apparatus as illustrated in <figref idref="DRAWINGS">FIG. 4</figref> is only an example of the electronic devices in which the present invention is implemented. In certain embodiments, the apparatus as illustrated in <figref idref="DRAWINGS">FIG. 4</figref> may be a personal digital assistant (PDA), a mobile phone, an electronic card reader, a sensor device, etc. As illustrated in <figref idref="DRAWINGS">FIG. 4</figref>, the apparatus <b>400</b> may comprise at least one processor <b>400</b>, a keyboard <b>401</b>, a codec circuitry <b>402</b>, a microphone <b>403</b>, an ear-piece <b>404</b>, a radio interface circuitry <b>405</b>, an antenna <b>406</b>, at least one memory <b>407</b> storing computer program code, an infrared port <b>408</b>, a display <b>409</b>, a smart card <b>410</b> (e.g., an USIM card according to embodiments of the present invention), and a card reader <b>411</b>. Individual circuits and elements are all of a type well known in the art and some of them are omitted herein so as not to obscuring embodiments of the present invention unnecessarily. As illustrated in <figref idref="DRAWINGS">FIG. 4</figref>, the memory <b>407</b> and the computer program code as stored therein are configured to cause the processor <b>400</b> to perform relevant steps in methods <b>200</b> and <b>300</b> as described in connection with <figref idref="DRAWINGS">FIGS. 2 and 3</figref>.
In addition, exemplary embodiments of the present invention have been described above with reference to block diagrams and flowchart illustrations of methods, apparatuses (i.e., systems). It should be understood that each block of the block diagrams and flowchart illustrations, and combinations of blocks in the block diagrams and flowchart illustrations, respectively, can be implemented by various means including computer program instructions. These computer program instructions may be loaded onto a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions which execute on the computer or other programmable data processing apparatus create means for implementing the functions specified in the flowchart block or blocks.
The foregoing computer program instructions can be, for example, sub-routines and/or functions. A computer program product in one embodiment of the invention comprises at least one computer readable storage medium, on which the foregoing computer program instructions are stored. The computer readable storage medium can be, for example, an optical compact disk or an electronic memory device like a RAM (random access memory) or a ROM (read only memory).
Many modifications and other embodiments of the inventions set forth herein will come to mind to one skilled in the art to which these embodiments of the invention pertain having the benefit of the teachings presented in the foregoing descriptions and the associated drawings. Therefore, it is to be understood that the embodiments of the invention are not to be limited to the specific embodiments disclosed and that modifications and other embodiments are intended to be included within the scope of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.
Contents6
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both waysCites: the store holds 22 of 23
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10887295B2 | Cited by | United States of America | Search report |
| US2018115539A1 | Cited by | United States of America | Search report |
| US2018115539A1 | Cited by | United States of America | Search report |
| NL2031140A | Cited by | Netherlands (Kingdom of the) | Applicant |
| US2018115539A1 | Cited by | United States of America | Search report |
| CN101106449A | Cites | China | Applicant |
| CN101399661A | Cites | China | Applicant |
| CN102143491A | Cites | China | Applicant |
| CN102215474A | Cites | China | Applicant |
| US2005187966A1 | Cites | United States of America | Search report |
| JP2009027513A | Cites | Japan | Applicant |
| WO2010117310A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| US2010185850A1 | Cites | United States of America | Search report |
| US2012023564A1 | Cites | United States of America | Search report |
| EP2530963A1 | Cites | European Patent Office (EPO) | Applicant |
| US7620824B2 | Cites | United States of America | Search report |
| US8209532B2 | Cites | United States of America | Search report |
| US20050187966A1 | Cites | United States of America | Search report |
| US20100185850A1 | Cites | United States of America | Search report |
| US20120023564A1 | Cites | United States of America | Search report |
| CN101106449 | Cites | China | Applicant |
| CN101399661 | Cites | China | Applicant |
| CN102143491 | Cites | China | Applicant |
| CN102215474 | Cites | China | Applicant |
| EP2530963A1 | Cites | European Patent Office (EPO) | Applicant |
| JP2009027513 | Cites | Japan | Applicant |
| WO2010117310A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| International Search Report received for corresponding Patent Cooperation Treaty Application No. PCT/CN2011/074693, dated Mar. 8, 2012, 3 pages. | Non-patent | – | Applicant |
| "Solution-MTC group based authentication, Huawei, 3GPP TSG-SA3(Security)", S3-110076, Jan. 2011, 2 pgs. | Non-patent | – | Applicant |
| "MTC group based authentication, Huawei, 3GPP TSG-SA3(Security)", S3-101276, Nov. 2010, 2 pgs. | Non-patent | – | Applicant |
| "3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3GPP System Architecture Evolution (SAE); Security architecture (Release 10)", 3GPP TS 33.401 V10.0.0, Mar. 2011, 113 pgs. | Non-patent | – | Applicant |
| International Search Report received for corresponding Patent Cooperation Treaty Application No. PCT/CN2011/074693, dated Mar. 8, 2012, 3 pages. | Non-patent | – | Applicant |
| “Solution—MTC group based authentication, Huawei, 3GPP TSG-SA3(Security)”, S3-110076, Jan. 2011, 2 pgs. | Non-patent | – | Applicant |
| “MTC group based authentication, Huawei, 3GPP TSG-SA3(Security)”, S3-101276, Nov. 2010, 2 pgs. | Non-patent | – | Applicant |
| “3<sup>rd </sup>Generation Partnership Project; Technical Specification Group Services and System Aspects; 3GPP System Architecture Evolution (SAE); Security architecture (Release 10)”, 3GPP TS 33.401 V10.0.0, Mar. 2011, 113 pgs. | Non-patent | – | Applicant |
6 members in 4 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 2011074693 | China | W | |
| 2011074693 | China | W | |
| PCTCN2011074693 | – | – | – |
| WO2011CN74693 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| WO2012159272A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2014075509A1 | United States of America | A1 | |
| CN103688563A | China | A | |
| EP2716093A1 | European Patent Office (EPO) | A1 | |
| EP2716093A4 | European Patent Office (EPO) | A4 | |
| US9270672B2This record | United States of America | B2 |
61 transactions on the USPTO file
Allowed after 2 non-final rejections.
- Non-final rejections
- 2
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| 7.5 yr surcharge - late pmt w/in 6 mo, Large EntityM1555 | M1555 | |
| Payment of Maintenance Fee, 8th Year, Large EntityM1552 | M1552 | |
| Maintenance Fee Reminder MailedREM. | REM. | |
| Payment of Maintenance Fee, 4th Year, Large EntityM1551 | M1551 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Email NotificationEML_NTR | EML_NTR | |
| Filing Receipt - CorrectedFLRCPT.C | FLRCPT.C | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Reasons for AllowanceEX.R | EX.R | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Response after Non-Final ActionA... | A... | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Email NotificationEML_NTR | EML_NTR | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| FITF set to NO - revise initial settingFTFI | FTFI | |
| Application Is Now CompleteCOMP | COMP | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Email NotificationEML_NTR | EML_NTR | |
| Email NotificationEML_NTR | EML_NTR | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Notice of DO/EO Acceptance MailedM903 | M903 | |
| Sent to Classification ContractorPGPC | PGPC | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Preliminary AmendmentA.PE | A.PE | |
| 371 Completion Date371COMP | 371COMP | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Cleared by OIPE CSRL194 | L194 | |
| Entity status set to undiscounted (initial default setting or status change)BIG. | BIG. | |
| Initial Exam Team nnIEXX | IEXX |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Fee payment procedure7.5 YR SURCHARGE - LATE PMT W/IN 6 MO, LARGE ENTITY (ORIGINAL EVENT CODE: M1555); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Maintenance fee paymentMAFP | MAFP | |
| Fee payment procedureMAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication
- 09270672
- Publication, DOCDB
- 9270672
- Publication, EPODOC
- US9270672
- Application
- 14119665
- Application, DOCDB
- 201114119665
- Application, EPODOC
- US201114119665
Titles
- English
- Performing a group authentication and key agreement procedure
Patent term adjustment
- A delay
- +7 daysthe office missed an examination deadline
- Applicant delay
- −32 days
- Net adjustment
- 0 days
Classification
- CPC, 11
- H04L63/0869
- H04L63/065
- H04L63/104
- H04W12/06
- H04W4/70
- H04W12/0433
- H04W4/005
- H04W12/0431
- H04W12/04
- H04W12/041
- H04W12/069
- IPC, 7
- G06F7 04
- H04L29 06
- H04W4 70
- H04W12 0431
- H04W12 06
- H04W4 00
- H04W12 04
- USPC, 1
- 001001000