Method and system for identity authentication and key agreement

A technology for key negotiation and identity authentication, applied in the field of identity authentication and key negotiation methods and systems, can solve problems such as increased transmission delay, denial of service attacks, and increased message transmission processes, and achieve the effect of ensuring security

CN101741555AInactive Publication Date: 2010-06-16ZTE CORP
0 Cites 29 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Publication Date
2010-06-16
Estimated Expiration
Not applicable · inactive patent

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention discloses a method and a system for identity authentication and key agreement. The method comprises the following steps that: an MS chooses a VLR from a plurality of VLRs according to a key broadcast protocol to acquire a public key of the chosen VLR, and then chooses a first random number; the MS sends the public key, an identifier of the HLR, the first random number and an international mobile subscriber identity, namely an IMSI of the MS which is encrypted by the public key of the chosen VLR to the chosen VLR; the chosen VLR uses a private key thereof to decrypt and acquire the IMSI, a shared key of the chosen VLR and an HLR is used for encrypting the decrypted IMSI, the IMSI is sent to the HLR, a second random number is generated, and then the second random number is sent to the MS; and the MS uses a private key thereof, the first random number and the second random number to construct an intermediate variable, and sends the intermediate variable to the chosen VLR, and then the chosen VLR performs authentication on the MS through the intermediate variable.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The present invention relates to the communication field, and in particular, relates to an identity authentication and key agreement method and system. Background technique

[0002] Authentication and Key Agreement (Authentication.and Key Agreement, referred to as AKA) or Extensible Authentication Protocol-AKA (Extensible Authentication Protocol-Authentication.and Key Agreement, referred to as EAP-AKA) is based on a challenge-response mechanism and a symmetric cipher mechanism, which runs on the user identity module, and the AKA-based authentication and key distribution protocol requires the participation of three parties: the mobile station (MobileStation), the visiting office (VLR), and the home office (HLR). The EAP-AKA protocol is initiated by the VLR, and the VLR first sends an EAP request / identity mark message to the MS, and then begins the process of authentication and key distribution. The relevant protocols are described below:

[0003] (1) ...

Examples

Embodiment Construction

[0064] Functional Overview

[0065] The present invention considers the problem of poor confidentiality of IMSI and key transmission in the related art. The present invention adopts the Public Key Broadcast Protocol (Public Key Broadcast Protocol-PKBP), and introduces a credible Certificate Authority (Certificate Authority, CA) into the network. Generate private keys and issue public keys to VLR and HLR, and use the self-verifying public key identity authentication scheme to effectively improve the confidentiality of IMSI and key transmission.

[0066] method embodiment

[0067] In this embodiment, an identity authentication and key agreement method is provided, which is applied to a system including a CA, an HLR, multiple VLRs, and an MS affiliated to the HLR, where the CA can be the HLR, multiple VLRs, and MS issues public and private keys.

[0068] Such as image 3 As shown, the identity authentication and key agreement method according to this embodiment includes:

[0...