Method and device for securing connections in a communication network
A technology for user equipment and equipment, which is applied in wireless communication, security communication devices, security devices, etc., and can solve problems such as undesired, slowing down the authentication process, and time-consuming users.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Publication Date
- 2018-07-10
Smart Images

Figure 1 
Figure 2 
Figure 3
Abstract
Description
technical field
[0001] The invention relates to methods and devices for securing connections in a communication network. More specifically, though not necessarily, the present invention relates to two-factor authentication for use in a generic bootstrap architecture. Background technique
[0002] Today we see the development towards the network society. An increasing percentage of users' daily lives are spent using telecommunication services such as telephone calls, instant messaging, email, or access to Internet services. Even users' personal data such as documents, music, photos, etc. are stored on web services "in the cloud". Social networking provides communication, online presence and document sharing. Public and private sector companies rely on telecom and cloud services to increase their business volumes. Consequently, the importance of security and privacy for users and businesses continues to increase. Particularly important aspects are authentication and data ...
Examples
Embodiment Construction
[0043] The Generic Bootstrapping Architecture (GBA) defined in 3GPP Technical Specification TS 33.220 provides a mechanism whereby a client terminal (UE) can be authenticated to a network application function (NAF) and a secure session key can be derived for communication between the UE and the NAF use. like figure 2 As shown, the GBA provides a mechanism whereby the UE bootstraps with the Bootstrap Server Function (BSF) such that the UE is authenticated to the BSF and a master key Ks and a Bootstrap Transaction Identifier (B-TID) are obtained. The UE then derives the application specific key Ks_NAF through a Key Derivation Function (KDF) defined as KDF(Ks, "gba-me", nonce, IMPI, NAF_id). Ks is the previously defined master key; "gba-me" is a fixed value; nonce is a random number used to generate Ks; IMPI is the Internet Protocol Multimedia Private Identity of the UE; and NAF_id is the NAF identifier of the NAF. The NAF_ID is formed by concatenating the Fully Qualified Doma...