WO2007025484A1

Updating negotiation method for authorization key and device thereof

Abstract

An updating negotiation method for the authorization key and a device thereof is applied in a communication network. In the network side, the control parameter for controlling the authorization key updating is set; the terminal transmits the request message for key updating to the network side, which carries the information corresponding to the control parameter for controlling the authorization key updating; the network side receives the request message for key updating, then determines whether the information corresponding to the control parameter for controlling the authorization key updating is valid, based on the reserved control parameter, if yes, processes the key updating, if no, ends the procedure. According to present invention, it is prevented that the illegal user updates the authorization key by the user card cloned illegally.

WO2007025484A1, drawing sheet 1
Sheet 1 of 4

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

18 claims: 4 independent, 14 dependent

  1. 1
    A method for negotiating a key update, wherein a control parameter for controlling an update of an authentication key is preset on a network side; the method includes:The terminal sends a key update request message and related information of a control parameter for controlling the authentication key update to the network side;After receiving the key update request message, the network side determines whether the related information of the control parameter from the terminal is legal according to the control parameter saved by the network side, and performs authentication when the related information of the control parameter is legal. Key update.
  2. 8
    The method according to any one of claims 1, 2, 4, 5 or 6, wherein the method further comprises:when the terminal sends a key update request message to the network side, carrying the first random number generated by the terminal;After receiving the key update request message sent by the terminal, the network side calculates the second calculation result according to the authentication key of the corresponding terminal user and the first random number, and sends the second calculation result to the terminal;After receiving the second calculation result sent by the network side, the terminal calculates the first calculation result according to the authentication key saved by the terminal and the first random number, and the terminal compares whether the second calculation result and the first calculation result are consistent. If it is inconsistent, it is considered that the network side is illegal, and the key update process is ended;otherwise, the related information of the control parameter for controlling the authentication key update is sent to the network side.
  3. 14
    An apparatus for implementing a key update negotiation, which is used to implement a key update negotiation between a terminal and a network side, and is characterized by:a key update request message generating unit, configured to generate a key update request message requesting to update the authentication key;An authentication key saving unit, configured to save an authentication key of the terminal;a control parameter obtaining unit, configured to acquire a control parameter for controlling the update of the authentication key;and a related information generating unit of the control parameter, configured to generate related information according to the control parameter acquired by the control parameter acquiring unit when requesting the update of the authentication key .
  4. 17
    An apparatus for implementing a key update negotiation, which is used to implement a key update negotiation between a terminal and a network side, and is characterized by:An authentication key saving unit, configured to save an authentication key of the terminal;a control parameter storage unit, configured to store a control parameter for controlling the update of the authentication key;a key update request message receiving unit, configured to receive a key update request message from the terminal requesting to update the authentication key;a related information parsing unit of the control parameter, configured to parse relevant information of the control parameter of the control authentication key update from the terminal;The related information verification unit of the control parameter is configured to determine, according to the control parameter stored by the control parameter storage unit, whether the related information from the terminal is legal after receiving the key update request message.