WO2008151663A1

Method and apparatuses for authentication and reauthentication of a user with first and second authentication procedures

Abstract

A method of authenticating a user to a network, the user being in possession of first and second authentication credentials associated respectively with first and second authentication procedures. The method comprises sending a challenge from the network to the user according to said second authentication procedure, receiving the challenge at the user and computing a response using said first credential or keying material obtained during an earlier running of said first authentication procedure, and said second credential, sending the response from the user to the network, and receiving the response within the network and using the response to authenticate the user according to said second authentication procedure.

WO2008151663A1, drawing sheet 1
Sheet 1 of 7

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

18 claims: 5 independent, 13 dependent

  1. 1
    Claims 1. A method of authenticating a user to a network, the user being in possession of first and second authentication credentials associated respectively with first and second authentication procedures, the method comprising:sending a challenge from the network to the user according to said second authentication procedure;receiving the challenge at the user and computing a response using said first credential or keying material obtained during an earlier running of said first authentication procedure, and said second credential;sending the response from the user to the network;and receiving the response within the network and using the response to authenticate the user according to said second authentication procedure.
  2. 6
    A method according to any one of the preceding claims, wherein said challenge contains a nonce, and said step of computing a response comprises using the nonce to compute the response.
  3. 7
    A method according to any one of the preceding claims and comprising sending said challenge together with an indication that the second procedure is to be linked to the first procedure.
  4. 11
    A user terminal configured to run first and second authentication procedures with a network and to store respective first and second authentication credentials, the terminal being configured to:receive a challenge from the network according to said second authentication procedure;compute a response using said first credential or keying material obtained during an earlier running of said first authentication procedure, and said second credential;and send the response to the network.
  5. 14
    A user terminal according to any one of claims 11 to 13, said second procedure being one of an authentication and key agreement procedure and a public key infrastructure procedure.
  6. 15
    A user terminal according to any one of claims 11 to 14 and comprising a universal Integrated circuit card on which is stored one or both of said first and second authentication credentials.
  7. 17
    A network node configured to authenticate a network user, the network node being configured to:send a challenge to the user according to a second authentication procedure;receive a response to said challenge from the user;and authenticate the response using a second credential associated with said second authentication procedure and a first credential or keying material obtained during an earlier running of a first authentication procedure between the network and the user.