Invention Grant
- Patent Title: Initial network authorization for a communications device
-
Application No.: US16982140Application Date: 2018-03-20
-
Publication No.: US11863663B2Publication Date: 2024-01-02
- Inventor: Per Ståhl
- Applicant: Telefonaktiebolaget LM Ericsson (publ)
- Applicant Address: SE Stockholm
- Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
- Current Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
- Current Assignee Address: SE Stockholm
- Agency: Rothwell, Figg, Ernst & Manbeck, P.C.
- International Application: PCT/EP2018/057047 2018.03.20
- International Announcement: WO2019/179608A 2019.09.26
- Date entered country: 2020-09-18
- Main IPC: H04L9/08
- IPC: H04L9/08 ; H04L9/32 ; H04L67/306

Abstract:
There is provided mechanisms for initial network authentication between a communications device and a network. A method is performed by the communications device. The communications device comprises an identity module supporting remote subscription profile download. The identity module comprises credentials for remote subscription profile download. The method comprises performing a first message exchange with an authentication server. The first message exchange comprises an identity module challenge obtained from the identity module being transmitted to the authentication server from the communications device. The method comprises receiving a second message from the authentication server. The second message comprises an ephemeral public key of the authentication server, an authentication server challenge and an authentication server signature. The authentication server signature is based on the ephemeral public key of the authentication server, the authentication server challenge, and the identity module challenge and follows a format used for handling remote subscription profile download to the identity module. The method comprises transmitting a third message towards the authentication server. The third message comprises an ephemeral public key of the communications device and an identity module signature. The identity module signature is based on the identity module credentials used for remote subscription profile download and is based on the ephemeral public key of the communications device and the authentication server challenge and follows the format used for remote subscription profile download to the identity module. The method comprises generating a master session key (MSK) from a shared secret established using the ephemeral public key of the authentication server and a private key corresponding to the ephemeral public key of the communications device. The MSK is for use when establishing secure communication between the communications device and the network.
Public/Granted literature
- US20210203488A1 INITIAL NETWORK AUTHORIZATION FOR A COMMUNICATIONS DEVICE Public/Granted day:2021-07-01
Information query