-
公开(公告)号:MY142227A
公开(公告)日:2010-11-15
申请号:MYPI20060464
申请日:2006-02-03
Applicant: QUALCOMM INC
Inventor: GORDON ROSE GREGORY , JAMES SEMPLE , WALLACE NASIELSKI JOHN
Abstract: A MUTUAL AUTHENTICATION METHOD IS PROVIDED FOR SECURELY AGREEING APPLICATION-SECURITY KEYS WITH MOBILE TERMINALS SUPPORTING LEGACY SUBSCRIBER IDENTITY MODULES (E.G., GSM SIM AND CDMA2000 R-UIM, WHICH DO NOT SUPPORT 3G AKA MECHANISMS). A CHALLENGE-RESPONSE KEY EXCHANGE IS IMPLEMENTED BETWEEN A BOOTSTRAPPING SERVER FUNCTION (BSF) AND MOBILE TERMINAL (MT). THE BSF GENERATES AN AUTHENTICATION CHALLENGE AND SENDS IT TO THE MT UNDER A SERVER-AUTHENTICATED PUBLIC KEY MECHANISM. THE MT RECEIVES THE CHALLENGE AND DETERMINES WHETHER IT ORIGINATES FROM THE BSF BASED ON A BOOTSTRAPPING SERVER CERTIFICATE. THE MT FORMULATES A RESPONSE TO THE AUTHENTICATION CHALLENGE BASED ON KEYS DERIVED FROM THE AUTHENTICATION CHALLENGE AND A PRE-SHARED SECRET KEY. THE BSF RECEIVES THE AUTHENTICATION RESPONSE AND VERIFIES WHETHER IT ORIGINATES FROM THE MT. ONCE. VERIFIED, THE BSF AND MT INDEPENDENTLY CALCULATE AN APPLICATION SECURITY KEY THAT THE BSF SENDS TO A REQUESTING NETWORK APPLICATION FUNCTION TO ESTABLISH SECURE COMUNICATIONS WITH THE MT.