Invention Grant
- Patent Title: Method to authenticate a user at a service provider
-
Application No.: US17603590Application Date: 2020-04-07
-
Publication No.: US12081654B2Publication Date: 2024-09-03
- Inventor: Mireille Pauliac , Ly Thanh Phan
- Applicant: THALES DIS FRANCE SAS
- Applicant Address: FR Meudon
- Assignee: THALES DIS FRANCE SAS
- Current Assignee: THALES DIS FRANCE SAS
- Current Assignee Address: FR Meudon
- Priority: EP 305509 2019.04.18
- International Application: PCT/EP2020/059920 2020.04.07
- International Announcement: WO2020/212207A 2020.10.22
- Date entered country: 2021-10-14
- Main IPC: H04L9/08
- IPC: H04L9/08 ; H04L9/30 ; H04W12/069

Abstract:
Provided is a method to authenticate a user equipment (UE) at a service provider (SP), when the UE is compliant with either Generic Bootstrap Architecture (GBA) or Authentication and Key Agreement for Applications (AKMA). The user authentication is performed by way of the GBA or AKMA protocol The method relies on the Mobile Network Operator's (MNO) GBA or AKMA authentication framework. It can employ a Diffie-Hellman exchange between the user equipment (UE) and the service provider (SP), leading to a Diffie-Hellman session key (gxy), while establishing the GBA or AKMA protocol. The method calculates a final Network Application Function (NAF) or AKMA Application Function key (iNAF_key or iAApF_key) to maintain confidentiality of the communication between the user equipment (UE) and the service provider (SP). It derives this key from the Diffie-Hellman session key (gxy) and from the respective protocol's service provider key (Ks_ext/int_NAF or KAF).
Public/Granted literature
- US20220200795A1 Method to Authenticate a User at a Service Provider Public/Granted day:2022-06-23
Information query