WO9727716A1

Management of authentication keys in a mobile communication system

Abstract

A mobile communication system comprising at least one authentication center (102) comprising authentication keys, base stations and mobile stations which communicate with the base stations and to which subscriber identity modules (101, SIM) may be coupled. The mobile communication system comprises an identifier generating means for generating identifiers which correspond to the authentication keys required in the authentication and on the basis of which the authentication keys may be found in the authentication center (102) when authentication is being carried out.

WO9727716A1, drawing sheet 1
Sheet 1 of 2

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

12 claims: 3 independent, 9 dependent

  1. 1
    CLAIMS 1. A method for managing authentication keys in a mobile commu¬ nication system comprising at least one authentication center (102, AUC), base stations (BS) and mobile stations (301 , 500) to which subscriber identity modules (101 , 509, SIM) may be coupled and which communicate with said base stations, c h a r a c t e r i z e d in that the method comprises the follow¬ ing steps:generating (601) authentication keys and identifiers (202) corre¬ sponding thereto by means of which authentication keys corresponding to the identifiers may be found in said authentication center (102, AUC), storing said authentication keys in said authentication center (102, AUC) so that said authentication keys may be found in said authentication center on the basis of said identifiers (202), and storing said authentication keys and said identifiers corresponding to the authentication keys to said subscriber identity modules (101 , 509, SIM).
  2. 3
    A method for managing authentication keys in a mobile commu¬ nication system comprising at least one authentication center (102, AUC), base stations (BS), and mobile stations (301, 500) which are provided with identifiers and which communicate with said base stations and to which sub¬ scriber identity modules (101 , 509, SIM) may be connected, as well as at least one subscriber database (DB) which stores each subscriber's subscriber data, c h a r a c t e r i z e d by comprising the following steps:generating (601) authentication keys and identifiers (202) which cor¬ respond to each of them and by means of which an authentication key corre¬ sponding to the identifier (202) in question may be found in said authentication center (102, AUC), storing in each subscriber identity module (101, 509, SIM) an authentication key to which a specific identifier (202) corresponds, storing said authentication keys in the authentication center (102, AUC) of the mobile communication system so that said authentication keys may be found in said authentication center (102, AUC) on the basis of said identifiers (202), and storing said identifier (202) in said at least one subscriber database (DB) in association with the subscriber data of said subscriber.
  3. 7
    A method for managing authentication keys in a mobile commu- nication system comprising at least one authentication center (102, AUC), mo¬ bile stations (301, 500) to which subscriber identity modules (509, SIM) may be coupled, at least one subscriber database (DB) for storing subscriber data of a mobile station, and base stations (BS) communicating with the mobile stations (301 , 500), the method being characterized by comprising the following steps:generating (601), in a centralized manner in one location ofthe mo¬ bile communication system, authentication keys required in the authentication, and identifiers (202) corresponding to the authentication keys, storing said authentication keys in said authentication center (102, AUC) so that said authentication keys may be found in said authentication center (102, AUC) on the basis of said identifiers (202), storing the authentication key in a subscriber identity module (101, 509, SIM), storing the mobile subscriber identity in said subscriber identity module (101, 509, SIM) following the generating and storing of said authenti- cation keys and said identifiers (202).