Attestation process and system for wireless security
The method and system enhance 5G wireless network security by provisioning mobile equipment with a shared secret key and using a secure enclave for verification, effectively addressing vulnerabilities at the edge of the wireless network and reducing attack risks.
Patent Information
- Application Number
- PCT/US2024/055894
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-17
- Filing Date
- 2024-11-14
- Publication Date
- 2025-05-22
AI Technical Summary
Current 5G wireless network security protocols are vulnerable to attacks, particularly at the edge of the wireless network, where the connection between mobile equipment and network nodes is less secure and requires enhanced authentication techniques.
A method and system for providing a secured challenge and response for wireless network security, which involves provisioning mobile equipment with a shared secret operator-assigned symmetric equipment key, generating an asymmetric key pair, and using a secure enclave to encrypt and verify the key, thereby enhancing the security of the wireless connection.
The proposed solution provides an additional layer of security to reliably verify mobile equipment, reducing or eliminating attacks on wireless networks by ensuring that only authentic and securely provisioned devices can communicate with network nodes.
Smart Images

Figure US2024055894_22052025_PF_FP_ABST
Abstract
Description
Docket No.: 005811.00002ATTESTATION PROCESS AND SYSTEM FOR WIRELESS SECURITYFIELD OF THE INVENTION
[0001] Embodiments of the invention relate to a secured challenge and response or attestationfor wireless network security.BACKGROUND OF THE INVENTION
[0002] Even with enhanced 5G Network security, the wireless interface at the edge of thewireless network remains vulnerable to attack. Current security protocols for 5G include anAuthentication Key Exchange (AKA) that provides a method to verify the connection at the edgeof the network. There remain vulnerabilities in the security in the wireless connection betweena mobile equipment and a network node. Current security protocols utilize the cryptographiccapabilities of a universal subscriber identity module (USIM) associated with the mobileequipment to provide, for example, symmetrical encryption. The USIM stores 1) a unique andpermanent subscriber identity, referred to as a Subscription Permanent Identifier (SUPI), 2) apublic asymmetric key corresponding to the operator network, 3) a shared secret symmetricroot key (i.e., also known as K, a shared secret between the subscriber and the correspondingoperator network), and 4) a counter (i.e., Sequence Number (SQN)). The operator stores thesame information within the operator network. The shared secret symmetric root key (SSSRK orK) provides a long term shared secret that provides an ability for the operator to verify theidentity of the subscriber and SQN provides replay protection for the subscriber. The networknode is securely connected to the operator network, but the connection between the mobileequipment and the network node at the edge of the network is less secure and requires specificauthentication techniques.
[0003] The network node and the mobile equipment, perform the AKA to provide theauthentication. In the typical, known, 5G protocol, to authenticate a mobile equipment, themobile equipment wirelessly requests authentication from the network node. In response to themobile equipment requesting authentication, the operator network, upon receiving the requestfrom the network node, computes an authentication challenge that includes a nonce andAuthentication Token (AUTN). Upon receipt of the nonce and AUTN, the USIM corresponding tothe mobile equipment verifies the freshness of the authentication challenge and verifies theDocket No.: 005811.00002AUTN. If the AUTN is determined to be authentic, USIM computes a response. Specifically, themobile equipment, using the USIM, sends an authentication response including a Subscriberconcealed identifier (SUCI) that is calculated from SUPI using the public asymmetric keycorresponding to the operator network. The network node receives the SUCI, and the operatornetwork decrypts the SUCI using the private asymmetric key that corresponds to the public keycorresponding the operator network and verifies that the SUPI matches the SUPI of thesubscriber. If the decrypted SUCI yields a matching SUPI, the home network furthercommunicates with the mobile equipment through the network node.
[0004] The wireless connection between the mobile equipment and the network node issubject to attack by passive or active attackers. For example, passive attackers may eavesdropon the information exchanged between the mobile equipment and network node. Activeattackers may perform manipulation, interception and / or injection of malicious code intotransmitted information. That is, passive attackers listen to signaling messages between themobile equipment and the network node and can eavesdrop on all information exchanged.Active attackers may, for example, may send and receive signaling messages, for example, toimpersonate network nodes. Passive or active attacks may include, for example, denial ofservice (DDoS) attacks, false cell phone tower or stingray attacks, and / or man in the middle(MiTM) attacks.
[0005] A DDoS attack is an attack by an active attacker where network resources arepurposefully made unavailable to users. In one of these types of attacks, malicious mobileequipment may cause a signaling storm by flooding the network with requests that render thenetwork unavailable to subscribers. Such an attack reduces the ability of the network to providelegitimate data exchange to legitimate user mobile equipment.
[0006] Additional examples of attacks include a false cell tower attack and a stingray attack.False cell tower attacks are a type of attack that utilize a device that can alter the mobileequipment registration process, thus spoofing the identity of a legitimate network node tochange or divert data traffic flows or provide other disruptive activities. For example, the falsecell tower can force mobile equipment in a particular area to connect to the false cell tower, sothat the mobile equipment location and / or data may be obtained by the attacker. These typesof attacks are typically designed to steal user identity and / or steal user credentials. A stingrayattack includes aspects of a false tower attack and may include the injection of malicious code(virus, Trojans, etc.) onto the mobile equipment or at the network node, which may result inDocket No.: 005811.00002compromised information integrity and asset destruction. For example, subscriber data, systemintegrity information, user financial data, and geo location can be stolen and or manipulated.
[0007] In an eavesdropping or MiTM attack, a device intercepts wireless data being transmittedbetween the mobile equipment and the network node. The data that may be intercepted mayinclude data packages, short message service (SMS) data, voice data or other data being sentfrom the mobile equipment or from the network node. This type of attack is commonly utilizedby threat actors attempting to access sensitive information, such as for the purposes ofespionage.
[0008] The current authentication methods for verifying the connection between the mobileequipment and the network node utilize primarily the USIM corresponding to the mobileequipment to complete the Authentication Key Exchange (AKA). However, the AKA is notsufficient to provide security and utilization of the current AKA provides a vulnerability to thewireless network.
[0009] What is needed is a method and system that provides an additional layer or security toreliably verify mobile equipment during the secured challenge and response with the networksnodes to reduce or eliminate attacks on the wireless networks. Other features and advantageswill be made apparent from the present specification. The teachings disclosed extend to thoseembodiments that fall within the scope of the claims, regardless of whether they accomplishone or more of the aforementioned needs.SUMMARY OF THE INVENTION
[0010] The present disclosure includes a method and system for providing a secured challengeand response for wireless / mobile / IOT network security that provides a secure provisioning ofmobile equipment, a challenging of the mobile equipment and the verification of the mobileequipment by a network node to verify that mobile equipment is an authentic and secure deviceprovisioned by the operator.
[0011] An embodiment of the present disclosure includes a non transitory machine readablestorage medium storing one or more sequences of instructions a secured challenge andresponse for wireless network security, which when executed by one or more processors, causeprovisioning of mobile equipment with an operator. A shared secret operator assignedsymmetric equipment key is requested with a subscriber identity module associated with themobile equipment. The shared secret operator assigned symmetric equipment key is providedDocket No.: 005811.00002from the operator and is stored within the subscriber identity module. The subscriber identitymodule then challenges the mobile equipment. The challenging includes generating anasymmetric key pair including an asymmetric encryption key and an asymmetric decryption key.The shared secret operator assigned symmetric equipment key and asymmetric encryption keyare provided to a secure enclave. The shared secret operator assigned symmetric equipmentkey and the asymmetric encryption key are sealed into the secure enclave. A nonce isgenerated with the subscriber identity module and is transmitted to the secure enclave. Theshared secret operator assigned symmetric equipment key and the nonce are encrypted withthe asymmetric encryption key in the secure enclave to form a verification encryption package.The verification encryption package is transmitted to the subscriber identity module. Theverification encryption package is decrypted with the asymmetric decryption key to release theshared secret operator assigned symmetric equipment key. The shared secret operator assignedsymmetric equipment key is stored in the subscriber identity module. A cipher key and anintegrity key are generated with the subscriber identity module from the shared secret operatorassigned symmetric equipment key. The cipher key and an integrity key are stored in thesubscriber identity module.
[0012] Another embodiment of the present disclosure includes a computer system configuredto provide a secured challenge and response for wireless network security. The computersystem includes a mobile equipment having one or more processors. The mobile equipmentincludes one or more computer readable storage mediums storing one or more sequences ofinstructions, which when executed, cause a mobile equipment to provision the mobileequipment with an operator. The provisioning includes requesting, with a subscriber identitymodule associated with the mobile equipment, a shared secret operator assigned symmetricequipment key. The shared secret operator assigned symmetric equipment key is provided fromthe operator and stored within the subscriber identity module. The one or more sequences ofinstructions cause the subscriber identity module to challenge the mobile equipment. Thechallenging includes generating an asymmetric key pair including an asymmetric encryption keyand an asymmetric decryption key. The shared secret operator assigned symmetric equipmentkey and the asymmetric encryption key is provided to a secure enclave. The shared secretoperator assigned symmetric equipment key and the asymmetric encryption key are sealed intothe secure enclave. A nonce is generated with the subscriber identity module and is transmittedto the secure enclave. The shared secret operator assigned symmetric equipment key and theDocket No.: 005811.00002nonce are encrypted with the asymmetric encryption key in the secure enclave to form averification encryption package. The verification encryption package is transmitted to thesubscriber identity module. The verification encryption package is decrypted with theasymmetric decryption key to release the shared secret operator assigned symmetricequipment key. The shared secret operator assigned symmetric equipment key is stored in thesubscriber identity module. A cipher key and an integrity key are generated with the subscriberidentity module from the shared secret operator assigned symmetric equipment key and isstored in the subscriber identity module.
[0013] Another embodiment of the present disclosure includes a method for providing asecured challenge and response for wireless / mobile / IOT network security. The method includesprovisioning a mobile equipment with an operator. The provisioning includes requesting, with asubscriber identity module associated with the mobile equipment, a shared secret operatorassigned symmetric equipment key and providing, from the operator, the shared secretoperator assigned symmetric equipment key, and storing the shared secret operator assignedsymmetric equipment key within the subscriber identity module. The mobile equipment ischallenged with the subscriber identity module. The challenging includes generating anasymmetric key pair including an asymmetric encryption key and an asymmetric decryption key.The shared secret operator assigned symmetric equipment key and the asymmetric encryptionkey are provided to a secure enclave. The shared secret operator assigned symmetricequipment key and the asymmetric encryption key are sealed into the secure enclave. A nonceis generated with the subscriber identity module and is transmitted to the secure enclave. Theshared secret operator assigned symmetric equipment key and the nonce are encrypted withthe asymmetric encryption key in the secure enclave to form a verification encryption package.The verification encryption package is transmitted to the subscriber identity module. Theverification encryption package is decrypted with the asymmetric decryption key to release theshared secret operator assigned symmetric equipment key. The shared secret operatorassigned symmetric equipment key is stored in the subscriber identity module. A cipher key andan integrity key are generated with the subscriber identity module from the shared secretoperator assigned symmetric equipment key and are stored in the subscriber identity module.
[0014] Other features and advantages of the present invention will be apparent from thefollowing more detailed description of the preferred embodiment, taken in conjunction with theaccompanying drawings which illustrate, by way of example, the principles of the invention.Docket No.: 005811.00002BRIEF DESCRIPTION OF DRAWINGS
[0015] Embodiments of the invention are illustrated by way of example, and not by way oflimitation, in the figures of the accompanying drawings and in which like reference numeralsrefer to similar elements and in which:
[0016] FIG. 1 is a block diagram of the functional components of an illustrative mobileequipment according to an embodiment of the disclosure.
[0017] FIG. 2 is a block diagram of the operating components of an illustrative mobileequipment according to an embodiment of the disclosure.
[0018] FIG. 3 is a block diagram of the operating components of an illustrative computersystem according to an embodiment of the disclosure.
[0019] FIG. 4 is a flowchart describing the high level steps of authenticating mobile equipmentaccording to embodiments of the disclosure.
[0020] FIG. 5 is a flowchart describing the steps of provisioning the mobile equipmentaccording to embodiments of the disclosure.
[0021] FIG. 6 is a flowchart describing the steps of challenging the mobile equipment accordingto embodiments of the disclosure.
[0022] FIG. 7 is a flowchart describing the steps of verifying the mobile equipment according toembodiments of the disclosure.
[0023] FIG. 8 is a schematic diagram of the provisioning process utilizing the operatingcomponents of an illustrative mobile equipment according to an embodiment of the disclosure.
[0024] FIG. 9 is a schematic diagram of a portion of the challenging process of an illustrativemobile equipment according to an embodiment of the disclosure.
[0025] FIG. 10 is a schematic diagram of another portion of the challenging process of anillustrative mobile equipment according to an embodiment of the disclosure.
[0026] FIG. 11 is a schematic diagram of another portion of the challenging process of anillustrative mobile equipment according to an embodiment of the disclosure.
[0027] FIG. 12 is a schematic diagram of another portion of the challenging process of anillustrative mobile equipment according to an embodiment of the disclosure.
[0028] FIG. 13 is a schematic diagram of a verification process between the mobile equipmentand the network node according to an embodiment of the disclosure.
[0029] Wherever possible, the same reference numbers will be used throughout the drawingsto represent the same parts.Docket No.: 005811.00002DETAILED DESCRIPTION OF THE INVENTION
[0030] The present disclosure includes a secured challenge and response wireless networksecurity or attestation to authenticate mobile equipment for secure communication to networknodes. In the following description, for the purposes of explanation, numerous specific detailsare set forth in order to provide a thorough understanding of the embodiments of the inventiondescribed herein. It will be apparent, however, that the embodiments of the invention describedherein may be practiced without these specific details. In other instances, well known structuresand devices are shown in block diagram form or discussed at a high level in order to avoidunnecessarily obscuring teachings of embodiments of the invention.
[0031] The method and system according to the present disclosure addresses common attacksby introducing a novel attestation method that verifies mobile equipment as being associatedwith the user / subscriber for secure communication. Embodiments of the present disclosureinclude a method and system wherein mobile equipment (ME) and a network node (e.g., gNb(5G RAN)) perform a certificate authority (CA) public certificate exchange utilizing a cipher keyand integrity key that have been generated and stored in the subscriber identity module of themobile equipment. The method and system according to the present disclosure is OEM agnosticon both the mobile equipment and the network, thus allowing deployment in domestic androaming scenarios. The method and system according to the present disclosure secures theedge of the wireless network due to the additional utilization of a shared secret operatorassigned symmetric equipment key in the cryptographic exchange. In addition, the method andsystem according to the present disclosure provides enhanced security during inter and intranetwork handovers supporting mobility. Further, the enhanced security provided by theutilization of a shared secret operator assigned symmetric equipment key reduces or eliminatesthe ability for firmware of mobile equipment to be compromised. Security is enhanced overprior art systems by the securing of the shared secret operator assigned symmetric equipmentkey from sharing or manipulation, where a nonce is required to release the shared secretoperator assigned symmetric equipment key to the SIM for storage and / or use in verification.
[0032] Certain embodiments of the invention advantageously provide the user of a mobileequipment with the peace of mind knowing that the mobile equipment cannot execute anoperating system if the mobile equipment has been compromised in some fashion. As shall beexplained in detail below, embodiments of the invention may employ a secure enclave, locallyresiding on a mobile equipment, which may be used to attest the resources of a mobileDocket No.: 005811.00002equipment. If the secure enclave judges the mobile equipment to not be associated with theuser / subscriber or having been compromised (as might be the case if malicious code is installedon the mobile equipment), then the mobile equipment may be prevented from communicatingwith a network node, providing network security.
[0033] FIG. 1 shows a block diagram of the functional components of an illustrative mobileequipment 100 according to an embodiment of the disclosure. Mobile equipment 101 may beany mobile device capable of connecting to a network in accordance with some embodimentsdescribed herein. Although mobile equipment 100 may be a handset, as illustrated herein, it willbe understood that other devices can be any mobile device, and that the mobile equipment 100is merely illustrated to provide context for the embodiments of the various embodimentsdescribed herein. For example, the mobile equipment 100 can be a device such as a cellulartelephone, a PDA with mobile communications capabilities, a vehicle, a laptop, a tablet, smartwatch, internet of things (IOT) devices, other smart devices and other mobile devices havingwireless communication abilities. The following discussion is intended to provide a brief, generaldescription of an example of a suitable environment in which the various embodiments can beimplemented. While the description comprises a general context of computer executableinstructions embodied on a machine readable storage medium, those skilled in the art willrecognize that the innovation also can be implemented in combination with other programmodules and / or as a combination of hardware and software.
[0034] The mobile equipment 100 may utilize any suitable applications (e.g., programmodules / clients), which may include routines, programs, components, data structures, etc., thatperform particular tasks or implement particular abstract data types. Moreover, those skilled inthe art will appreciate that the methods described herein can be practiced with other systemconfigurations, comprising single processor or multiprocessor systems, microprocessor based orprogrammable consumer electronics, and the like, each of which can be operatively coupled toone or more associated devices.
[0035] The mobile equipment 100 may include any suitable machine readable media. Machinereadable media can be any available media that can be accessed by the computer and comprisesboth volatile and non volatile media, removable and non removable media. By way of exampleand not limitation, computer readable media can comprise computer storage media andcommunication media. Computer storage media can include volatile and / or non volatile media,removable and / or non removable media implemented in any method or technology for storageDocket No.: 005811.00002of information, such as computer readable instructions, data structures, program modules orother data. Computer storage media can include, but is not limited to, RAM, ROM, EEPROM,flash memory or other memory technology, CD ROM, digital video disk (DVD) or other opticaldisk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magneticstorage devices, or any other medium which can be used to store the desired information, andwhich can be accessed by the computer.
[0036] The mobile equipment 100 may communicate utilizing communication media that istransmitted via wired or wireless connections. Suitable communication media may includecomputer readable instructions, data structures, program modules or other data in a modulateddata signal such as a carrier wave or other transport mechanism and comprises any informationdelivery media. The term “modulated data signal” means a signal that has one or more of itscharacteristics set or changed in such a manner as to encode information in the signal. By way ofexample, and not limitation, communication media comprises wired media such as a wirednetwork or direct wired connection, and wireless media such as acoustic, RF, infrared and otherwireless media. Combinations of the any of the above should also be included within the scopeof computer readable media.
[0037] As shown in FIG. 1, mobile equipment 100 comprises a processor 102 for controlling andprocessing all onboard operations and functions. A memory 104 and firmware 108 are machinereadable media and interfaces to the processor 102 for storage of data and one or moreapplications 106. The applications 106 can be stored in the memory 104 and / or in a firmware108 and executed by the processor 102 from either or both the memory 104 or / and thefirmware 108. The firmware 108 can also store startup code for execution in initializing themobile equipment 100. A communications component 110 for transmitting communicationmedia interfaces to the processor 102 to facilitate wired / wireless communication with externalsystems, e.g., cellular networks, VoIP networks, and so on. Here, the communicationscomponent 110 can also include a suitable cellular transceiver 111 (e.g., a GSM transceiver)and / or an unlicensed transceiver 913 (e.g., Wi Fi, WiMax) for corresponding signalcommunications. Wi Fi, or Wireless Fidelity, allows connection to the Internet from a couch athome, a bed in a hotel room, or a conference room at work, without wires. Wi Fi is a wirelesstechnology similar to that used in a cell phone that enables such devices, e.g., computers, tosend and receive data indoors and out; anywhere within the range of a base station. Wi Finetworks use radio technologies called IEEE802.11 (a, b, g, n, etc.) to provide secure, reliable,Docket No.: 005811.00002fast wireless connectivity. A Wi Fi network can be used to connect computers to each other, tothe Internet, and to wired networks (which use IEEE802.3 or Ethernet). Wi Fi networks operatein the unlicensed 2.4 and 5 GHz radio bands, at an 11 Mbps (802.11b) or 54 Mbps (802.11a) datarate, for example, or with products that contain both bands (dual band), so the networks canprovide real world performance similar to the basic “10BaseT” wired Ethernet networks used inmany offices. The communications component 110 may also facilitate communications fromterrestrial radio networks (e.g., broadcast), digital satellite radio networks, and Internet basedradio services networks.
[0038] The mobile equipment 100 comprises a display 112 for displaying text, images, video,telephony functions, setup functions, and for user input. For example, the display 112 can alsobe referred to as a “screen” that can accommodate the presentation of multimedia content(e.g., music metadata, messages, wallpaper, graphics, etc.). The display 112 can also displayvideos and can facilitate the generation, editing and sharing of video quotes. A serial I / Ointerface 114 is provided in communication with the processor 102 to facilitate wired and / orwireless serial communications (e.g., USB, and / or IEEE 1394) through a hardwire connection,and other serial input devices (e.g., a keyboard, keypad, and mouse). This supports updating andtroubleshooting the mobile equipment 100, for example. Audio capabilities are provided with anaudio I / O component 116, which can include a speaker for the output of audio signals relatedto, for example, indication that the user pressed the proper key or key combination to initiatethe user feedback signal. The audio I / O component 116 also facilitates the input of audio signalsthrough a microphone to record data and / or telephony voice data, and for inputting voicesignals for telephone conversations. Mobile equipment 100 may also include a camera 117 thatinterfaces with processor 102 and provides image or video data. While these components areshown in FIG. 1 one or more of these components may be optionally omitted in mobileequipment 100.
[0039] The mobile equipment 100 may include an interface or other physical subscriberidentity module 118 interfacing with processor 102. The subscriber identify module 118 mayinclude a slot interface for accommodating a SIC (Subscriber Identity Component) in the form,for example, of a card Subscriber Identity Module (SIM) or universal SIM 118, or interfaceproviding a virtual or remote subscriber identity module 118 to interface with the processor102. However, it is to be appreciated that subscriber identity module 118 can be manufacturedinto the mobile equipment 100 and updated by downloading data and software. SIM 118Docket No.: 005811.00002includes a hardware or software device that contains code, such as an applet, that implements asecurity module that support the cryptographic security steps according to methods accordingto the present disclosure. In one embodiment, SIM 118 has a pre installed security applet forAuthentication messaging. In addition, SIM 118 is capable of utilizing application protocol dataunit (APDU) commands along with subscriber identity module application toolkit (SAT) forcommunication with the mobile equipment OS. In addition, SIM 118 may include or may beprovided with a shared secret symmetric root key (K) from the operator, which corresponds tonetwork specific information used to authenticate and identify subscribers on the network. Kmay be stored in SIM 118 and may be utilized to provide cryptographic security that identifiesand authenticates subscribers on mobile networks. K may be provided to SIM 118, such as overthe air (OTA) from the operator, or may be programmed and / or stored in SIM 118 atmanufacture or creation of SIM 118. The shared secret symmetric root key (K) includes the “K”or “Ki” currently known for use in network security for mobile devices, which may include 128bit values used for authenticating SIMs on mobile networks.
[0040] The mobile equipment 100 can process communication media including IP data trafficthrough the communication component 110 to accommodate IP traffic from an IP network suchas, for example, the Internet, a corporate intranet, a home network, a person area network,etc., through an ISP or broadband cable provider. Thus, VoIP traffic can be utilized by the mobileequipment 100 and IP based multimedia content can be received in either an encoded ordecoded format.
[0041] The mobile equipment 100 also comprises a power source 124 in the form of batteriesand / or an AC power subsystem, which power source 124 can interface to an external powersystem or charging equipment (not shown) by a power I / O component 126.
[0042] The mobile equipment 100 can also include a video component 122 for processing videocontent received and, for recording and transmitting video content. For example, the videocomponent 122 can facilitate the generation, editing and sharing of video quotes. A locationtracking component 132 facilitates geographically locating the mobile equipment 100. Asdescribed hereinabove, this can occur when the user initiates the feedback signal automaticallyor manually. A user input component 126 facilitates a mechanism to permit the user to interactwith the mobile equipment 100. The user input component 126 can include such conventionalinput device technologies such as a keypad, keyboard, mouse, stylus pen, and / or touch screen,for example.Docket No.: 005811.00002
[0043] The mobile equipment 100, as indicated above relates to the communicationscomponent 110, comprises an indoor network radio transceiver 113 (e.g., Wi Fi transceiver).This function supports the indoor radio link, such as IEEE 802.11, for the dual mode GSM mobileequipment 100. The mobile equipment 100 can accommodate at least satellite radio servicesthrough a mobile equipment that can combine wireless voice and digital radio chipsets into asingle handheld device.
[0044] Referring again to FIG. 1, firmware 108 includes basic input / output system BIOS 128,secure enclave 130 and storage 132. BIOS 128, as broadly used herein, refers to any basicinput / output system (BIOS) that is designed to be the boot firmware for mobile equipment 100when mobile equipment 100 is powered on. BIOS code may execute prior to the initialization ofan operating system (OS) of the information handling system. In an embodiment, BIOS 128includes or corresponds to Unified Extensible Firmware Interface (UEFI) Platform Firmware. AUnified Extensible Firmware Interface (UEFI) standard has been developed by the Unified EFIForum industry group to enhance the booting process of modern computer systems.
[0045] Secure enclave 130, as broadly used herein, refers to any hardware mechanism whichprovides an environment allowing code executing therein to have full access to resources of thecomputer system in which the secure enclave resides, and yet resources of the computer systemexternal to the secure enclave have no ability to read or write to resources maintained insidethe secure enclave. Non limiting, illustrative examples of secure enclave 130 include theInnovation Engine (IE) available from Intel Corporation of Santa Clara, Calif., and the ARM basedPlatform Security Processor (PSP) available from AMD Inc. of Santa Clara, Calif. Secure enclave130 may enable messages to be exchanged between processes executing outside of secureenclave 132 with processes executing inside of secure enclave 130. In addition, the secureenclave 130 according to the present disclosure may include software, such as x86 SMM andArm TrustZone. Another example of a suitable secure enclave 130 may include a TrustedPlatform Module (TPM).
[0046] Storage 132, as broadly used herein, refers to any machine readable media for storingdigital data. Non limiting, illustrative examples of storage 132 include a hard disk drive (HDD)and solid state memory, such as a flash drive.
[0047] Applications 106 may include a number of program modules that may be stored in thememory 104 or firmware 108 of the mobile equipment. Applications may include one or moreDocket No.: 005811.00002clients 134 which may include an operating system, one or more application programs, otherprogram modules and / or program data.
[0048] FIG. 2 shows a block diagram of the operating elements of an illustrative mobileequipment 100 according to an embodiment of the disclosure. FIG. 2 shows a simplifieddiagram of the elements that provide the operation of the mobile equipment 100 to performthe method according to the present disclosure. As shown in FIG. 2, the mobile equipment 100includes a wireless module 201 and a firmware module 203. Firmware module 203 includeselements of firmware 108 from FIG. 1, including secure enclave 130 and BIOS 128. In addition,firmware module includes a firmware operating system 205, which includes a firmwareoperating system driver 207. Firmware operating system driver 207 is a client 134 that providescontrol and communication within firmware 108. In particular, firmware operating system driver207 includes the ability to provide information, including cryptographic keys to the secureenclave 130 through BIOS 128. Module OS 209 through instructions or code provided by moduleOS driver 211 provide control and communication within components of the mobile equipment100. Both the firmware operating system 205 and the module operating system 211 togetherare included in mobile equipment operating system 219. The firmware operating system driver207 and the module operating system driver 209 function to provide control andcommunication to mobile equipment 100, while maintaining separate elements, such ashardware and accessibility.
[0049] Wireless module 201 includes communication component 110 and subscriberidentification module 118 or SIM, as well as 5G Baseband 205. 5G Baseband, as utilized herein,includes equipment which handles radio communications and radio control processingfunctions. The function of 5G Baseband includes processing 5G protocol messages between themobile equipment 100 and network nodes and / or their corresponding networks using airinterfaces, such as radio frequency (RF) links.
[0050] The subscriber identity module 118 includes code or instructions that providecommunication to the various components of the mobile equipment 100, to componentsexternal to the mobile equipment 100 and is capable of generating cryptographic features forprovisioning, challenging and verifying mobile equipment 100. While not so limited, subscriberidentity module 118, as shown in FIG. 2, includes a number of cryptographic feature generatingcomponents, including an asymmetric key generator 213, a nonce generator 215 and a cipherkey (CK) and integrity key (IK) generator 217. The asymmetric key generator 213 is code orDocket No.: 005811.00002instructions that, when executed by processor 102, generates an asymmetric key pair, includingan asymmetric decryption key and an asymmetric encryption key. The nonce generator 215 iscode or instructions, when executed by processor 102, generates a nonce. “Nonce” as utilizedherein is intended to be interpreted according to its understood meaning in the art and includesan arbitrary number that is used only once in a cryptographic operation. The CK and IKgenerator 217 is code or instructions, when executed by processor 102, generates a cipher keyand an integrity key. “Cipher key” and “integrity key”, as utilized herein, is intended to beinterpreted according to its understood meaning in the art and includes a cipher key (CK) andintegrity key (IK) that are derived keys based on agreed upon Key Derivation Function (KDF) bythe network provider. The cipher key (CK) and integrity key (IK) generated according to thepresent disclosure may be 128bit values and are derived from a shared secret symmetric rootkey (K) and a shared secret operator assigned symmetric equipment key (K2). The cipher key(CK) and integrity key (IK) indicate the type of encryption used for messaging and validity of themessage. Each of the asymmetric key generator 213, the nonce generator 215 and the cipherkey (CK) and integrity key (IK) generator 217 utilize known security algorithms to generate,encrypt or decrypt the cryptographic keys. For example, security algorithms, such as SNOW orAdvance Encryption Standard (AES) algorithm standards may be utilized to generate thecryptographic keys. One particularly suitable example for an encryption for use with the methodand system according to the present disclosure includes Secure Hash Algorithm 256 (SHA 256).Subscriber identity module 118 may include one or more applets stored in read only memory(ROM) within the subscriber identity module 118 that provide the ability to generate, saveand / or communicate information. For example, the applet may provide the ability to receive acryptographic key and transmit the cryptographic key elsewhere in the mobile equipment 100.In addition, the applet may provide the ability to generate cryptographic keys, such as cipherkeys and integrity keys. In addition, the cipher key (CK) and integrity key (IK) generator 217,which may be, for example, an applet in SIM 118, may include code or instructions tocryptographically derive the cipher key (CK) and integrity key (IK) with shared secret symmetricroot key (K) and the shared secret operator assigned symmetric equipment key (K2) and storethe cipher key (CK) and integrity key (IK) in SIM 118.
[0051] FIG. 3 is a block diagram that illustrates a computer system 300 upon which anembodiment of the invention may be implemented. Specifically, computer system 300 may beutilized in one or more network nodes 1302. For example, a network node (e.g., network nodeDocket No.: 005811.000021302 (see for example, FIGs. 8, 10, 11 and 12)) can contain components as described in FIG. 3.The computer 300 can provide networking and communication capabilities between a wired orwireless communication network and a server and / or communication device. In order toprovide additional context for various aspects thereof, FIG. 3 and the following discussion areintended to provide a brief, general description of a suitable computing environment in whichthe various aspects of the innovation can be implemented to facilitate the establishment of atransaction between an entity and a third party. While the description above is in the generalcontext of computer executable instructions that can run on one or more computers, thoseskilled in the art will recognize that the innovation also can be implemented in combination withother program modules and / or as a combination of hardware and software.
[0052] Computer system 300 may include the same suitable applications, machine readablemedia and communication media as described above for mobile equipment 100.
[0053] In one embodiment, as shown in FIG.3, computer system 300 includes processor 302,main memory 304, ROM 306, storage device 308, and communication interface 310. Thesecomponents may be the same or different than the components described above with respectto mobile equipment 100.
[0054] Computer system 300 includes at least one processor 302 for processing information.Computer system 300 includes a main memory 304, such as a random access memory (RAM) orother dynamic storage device, for storing information and instructions to be executed byprocessor 302. Main memory 304 also may be used for storing temporary variables or otherintermediate information during execution of instructions to be executed by processor 302.Computer system 300 further includes a read only memory (ROM) 306 or other static storagedevice for storing static information and instructions for processor 302. A storage device 308,such as a magnetic disk or optical disk, is provided for storing information and instructions.
[0055] Computer system 300 may be coupled to a display 312, such as, but not limited to, alight emitting diode (LED) monitor, organic light emitting diode (OLED) monitor, an LCD monitor,a cathode ray tube (CRT), or other monitor or screen known for displaying information to a user.An input device 314, such as a keyboard, mouse, touch screen or other known input device iscoupled to computer system 300 for communicating information and command selections toprocessor 302. Other non limiting, illustrative examples of input device 314 include any devicefor communicating direction information and command selections to processor 302 and forcontrolling cursor movement on display 312. While only one input device 314 is depicted in FIG.Docket No.: 005811.000023, embodiments of the invention may include any number of input devices 314 coupled tocomputer system 300.
[0056] Embodiments of the invention are related to the use of computer system 300 forimplementing the techniques described herein. According to one embodiment of the invention,those techniques are performed by computer system 300 in response to processor 302executing one or more sequences of one or more instructions contained in main memory 304.Such instructions may be read into main memory 304 from another machine readable medium,such as storage device 308. Execution of the sequences of instructions contained in mainmemory 304 causes processor 302 to perform the process steps described herein. In alternativeembodiments, hard wired circuitry may be used in place of or in combination with softwareinstructions to implement embodiments of the invention. Thus, embodiments of the inventionare not limited to any specific combination of hardware circuitry and software.
[0057] The term “machine readable storage medium” as used herein refers to any mediumthat participates in storing instructions which may be provided to processor 302 for execution.Such a medium may take many forms, including but not limited to, non volatile media andvolatile media. Non volatile media includes, for example, optical or magnetic disks, such asstorage device 308. Volatile media includes dynamic memory, such as main memory 304.
[0058] Non limiting, illustrative examples of machine readable media include, for example, afloppy disk, a flexible disk, hard disk, magnetic tape, or any other magnetic medium, a CD ROM,any other optical medium, a RAM, a PROM, and EPROM, a FLASH EPROM, any other memorychip or cartridge, or any other medium from which a computer can read.
[0059] Various forms of machine readable media may be involved in carrying one or moresequences of one or more instructions to processor 302 for execution. For example, theinstructions may initially be carried on a magnetic disk of a remote computer. The remotecomputer can load the instructions into its dynamic memory and send the instructions over anetwork link 316 to computer system 300.
[0060] Communication interface 310 provides a two way data communication ofcommunication media by coupling to a network link 318 that is connected to a local network.For example, communication interface 316 may be an integrated services digital network (ISDN)card or a modem to provide a data communication connection to a corresponding type ofcommunication line. As another example, communication interface 310 may be a local areanetwork (LAN) card to provide a data communication connection to a compatible LAN. WirelessDocket No.: 005811.00002links, such as but not limited to a Bluetooth and / or 3G / 4G connection, may also beimplemented. In any such implementation, communication interface 310 sends and receiveselectrical, electromagnetic or optical signals that carry digital data streams representing varioustypes of information. Network link 316 typically provides data communication through one ormore networks to other data devices. For example, network link 316 may provide a connectionthrough a local network to a host computer or to data equipment operated by an InternetService Provider (ISP).
[0061] Computer system 300 can send messages and receive data, including program code,through the network(s), network link 316 and communication interface 310. For example, aserver might transmit a requested code for an application program through the Internet, a localISP, a local network, subsequently to communication interface 310. The received code may beexecuted by processor 302 as it is received, and / or stored in storage device 308, or other nonvolatile storage for later execution.
[0062] As shown in FIG. 4, method 400 according to the present disclosure includes a processfor wireless / mobile / IOT network security, where method 400 includes provisioning mobileequipment 100 (step 402), challenging mobile equipment 100 (step 404) and verifying mobileequipment 100 (step 406).
[0063] FIG. 5 shows details of step 402 of method 400, where method 500 includesprovisioning mobile equipment 100. A shared secret operator assigned symmetric equipmentkey (SSOASK) is requested by subscriber identity module 118 of the mobile equipment 100 froman operator (step 502). In response, the operator provides the SSOASK to challenge and verifythe mobile equipment 100 (step 504). The remote providing of the SSOASK may beaccomplished from a request from SIM 118, using pilot data from the operator, for the SSOASKor K2 specific to the mobile equipment 100. In response to the request, operator sends a silentshort message service (over the air) (SMS(OTA)) to mobile equipment 100, which, via baseband,is sent to SIM 118 for initial storage. Operator, as utilized herein are any public or privatewireless service providers, such as 5G service providers. Once received from the operator, themobile equipment 100 stores the SSOASK within the subscriber identity module 118 (step 506).Additionally, the subscriber identity module 118 may further acknowledge receipt of theSSOASK and may authenticate that the subscriber identity module 118 is the subscriber identitymodule 118 that sent the request for the SSOASK to the operator.Docket No.: 005811.00002
[0064] FIG. 6 shows details of step 404 of method 400, wherein method 600 includeschallenging the mobile equipment 100 after the mobile equipment 100 is provisioned accordingto method 500. The challenging includes generating an asymmetric key pair including anasymmetric encryption key and an asymmetric decryption key (step 602). The asymmetric keypair includes an asymmetric encryption key and an asymmetric decryption key, the asymmetrickey pair may also be an asymmetric public / private key pair. The shared secret operator assignedsymmetric equipment key and the asymmetric encryption key are provided to a secure enclave(step 604). In one embodiment, the shared secret operator assigned symmetric equipment keyis removed from the memory of the subscriber identity module 118 after the shared secretoperator assigned symmetric equipment key is transmitted to the secured enclave. The sharedsecret operator assigned symmetric equipment key and the asymmetric encryption key aresealed into the secure enclave (step 606). By “sealing”, as utilized herein, the information, suchas the SSOASK and the symmetric encryption key, is saved in a manner that only softwareexecuting within secure enclave 130 may access the information, thereby providing the privacyand integrity of the information from processes outside of the secure enclave. This "secret", forexample the shared secret operator assigned symmetric equipment key, is sealed against aspecific state of the system, as measured during the firmware boot process. The secret can onlybe unsealed if the system is in the same specific state that the secret was sealed against. In thisway, if the state of the firmware has changed, which could indicate corruption or injection ofmalware into the firmware, the state of the system will be different and therefore the secretcannot be unsealed and will remain sealed with the secure enclave. In another embodiment, theinformation may be stored in another secure location that provides the same privacy andintegrity of the SSOASK and the symmetric encryption key, such as a Trusted Platform Module(TPM). This portion of the challenging method 600 may take place while the mobile equipment100 is performing a measured boot. That is, during the measured boot phase of the startup ofthe mobile equipment 100, the SSOASK is provided to secured enclave and is sealed. A“measured boot” is a known process within computer systems, wherein the system typicallyexecutes firmware that performs a boot process to initialize various system components andinterfaces, load an operating system, and perform various other actions to configure the systeminto a known and initial state. Basic input / output system (BIOS) or unified extensible firmwareinterface (UEFI) specifications may be utilized to oversee these processes. For example, a UEFIcompliant boot process may measure each portion of the code to obtain a signature specific toDocket No.: 005811.00002that code throughout the boot process. Each signature is cryptographically combined togenerate a final signature that represents the specific boot code for the system. Each signatureis cryptographically combined to generate a final signature that represents the specific bootcode for the system. The SSOASK is cryptographically sealed against the final signature toprevent access if the system did not boot the same code. A difference in measurements acrossboots could indicate corruption or injection of malware into the firmware. A nonce is generatedwith the subscriber identity module (step 608) and is transmitted to the secure enclave (step610). The generation of the nonce and the transmittal to the secure enclave may take placeafter the completion of the measured boot. The shared secret operator assigned symmetricequipment key and the nonce are encrypted with the asymmetric encryption key in the secureenclave to form a verification encryption package (step 612). The verification encryptionpackage is transmitted to the subscriber identity module. In one embodiment, the verificationencryption package is only transmitted upon completion of the measured boot by the mobileequipment OS 219. If the measured boot does not measure the same boot code that wasexecuted when sealing the secret, the SSOASK remains sealed in the secure enclave. After theverification encryption package is transmitted to the subscriber identity module 118, theverification encryption package is decrypted with the asymmetric decryption key to release theshared secret operator assigned symmetric equipment key (step 614). The shared secretoperator assigned symmetric equipment key is stored in the subscriber identity module (step616). A cipher key and an integrity key are generated with the subscriber identity module fromthe shared secret operator assigned symmetric equipment key (step 618) and are stored in thesubscriber identity module (step 620). The cipher key and the integrity key are stored such thatthey are available for transmitting in response to a verification request, such as by a networknode 1302. The cipher key and integrity key may be stored in any suitable form and may or maynot be further encrypted. In addition, other cryptographic keys may likewise be saved in thesubscriber identity module 118 to provide verification responses in combination with the cipherkey and the integrity key.
[0065] FIG. 7 shows details of step 406 of method 400, wherein method 700 includes verifyingmobile equipment 100 after the authentication response is received by the network node 1302(see, for example, FIG. 13). Method 700 includes receiving, with the wireless module, a requestfor verification from a network node (step 702). In response to the request for verification,providing the cipher key and the integrity key from the subscriber identity module to theDocket No.: 005811.00002network node (step 704). In one embodiment, the cipher key and integrity key provided to thenetwork node are encrypted. In one embodiment, when the cipher key and the integrity key aresent for Authentication, the message contains AUTH(token) & RAND(cryptographic numbergenerated as response). In one embodiment, the method 700 includes permitting access by themobile equipment 100 to a wireless network associated with the network node 1302 uponverification of the cipher key and the integrity key from the subscriber identity module to thenetwork node by the network node. In one embodiment, the access to the wireless networkutilizes a 5G protocol. Likewise, method 700 includes restricting access to the wireless networkby the mobile equipment 100 to a wireless network associated with the network node 1302 ifverification of the cipher key and the integrity key from the subscriber identity module to thenetwork node is not verified by the network node. Alternatively, the network node 1302 mayrestrict access to the wireless network, for example access utilizing a non 5G protocol if theauthentication response is determined by the network node to not correspond to the uniquechallenge code and the public certificate of the authentication request. Restricting access to thenetwork may vary depending upon specific operators. For example, operators may choose totear down the network connectivity, meaning no network access to the device or may proceedwith the understanding that extra 5G security is not present and cannot be used.
[0066] FIGs. 8 13 show a schematic illustration of the components and the operation of moduleequipment 100 during the method, according to the present disclosure. FIGs. 8 illustrates aprovisioning method 500 for mobile equipment 100. As shown in FIG. 8, upon request from thesubscriber identity module (SIM) 118 of mobile equipment 100, operator 800 remotelygenerates and communicates, shared secret operator assigned symmetric equipment key tomobile equipment 100. Once the shared secret operator assigned symmetric equipment key hasbeen received the shared secret operator assigned symmetric key is saved in the subscriberidentity module (SIM) 118.
[0067] FIG. 9 shows a portion of the challenging method 600, where the shared secret operatorassigned symmetric equipment key and an asymmetric key pair generated by the subscriberidentity module 118 are provided to the secure enclave 130, wherein the shared secret operatorassigned symmetric equipment key and the asymmetric encryption key are sealed into thesecure enclave. As noted above, in one embodiment, this portion of the challenging method600 may be during a measured boot phase of the startup of mobile equipment 100.Docket No.: 005811.00002
[0068] FIG. 10 shows another portion of the challenging method 600, where a nonce isgenerated by the subscriber identity module 118 and provided to the secure enclave 130,wherein the nonce is encrypted with the shared secure operator assigned symmetric equipmentkey and asymmetric encryption key to form a verification encryption package. As noted above,in one embodiment, the verification encryption package is only released and transmitted fromthe secure enclave 130 if the measured boot phase does not identify any problems or anomalieswith the software of the mobile equipment 100.
[0069] FIG. 11 shows another portion of the challenging method 600, where the verificationencryption package is transmitted to the subscriber identity module 118 (such as after themeasured boot) and is decrypted with the asymmetric decryption key. to provide verificationresponses in combination with the cipher key and the integrity key.
[0070] FIG. 12 shows another portion of the challenging method 600, where the subscriberidentity module 118 generated a cipher key (CK) and an integrity (IK), which are saved into thesubscriber identity module 118 for later use in verifying the mobile equipment with a networknode 1302. The cipher key and the integrity key are stored such that they are available fortransmitting in response to a verification request, such as by a network node 1302. The cipherkey and integrity key may be stored in any suitable form and may or may not be furtherencrypted. In addition, other cryptographic keys may likewise be saved in the subscriberidentity module 118
[0071] FIG. 13 shows a verification method 700 for verifying mobile equipment 100 withnetwork node 1302. As shown in FIG. 13, the method includes, upon receiving a request fromnetwork node 1302, transmitting the cipher key (CK) and the integrity key (IK) is provided to thenetwork node 1302. While FIG. 13 show transmitting of the CK and IK, the process according tothe present disclosure is not so limited. For example, the CK and IK may be encrypted or may becombined with other security certificates or cryptographic keys in order to provide furtherverification of identity of the mobile device 100. In one embodiment, the subscriber identitymodule generates and / or stores the security certificates or cryptographic keys to provide theverification response.
[0072] As used in this application, the terms “system,” “component,” “interface,” and the likeare generally intended to refer to a computer related entity or an entity related to anoperational machine with one or more specific functionalities. The entities disclosed herein canbe either hardware, a combination of hardware and software, software, or software inDocket No.: 005811.00002execution. For example, a component can be, but is not limited to being, a process running on aprocessor, a processor, an object, an executable, a thread of execution, a program, and / or acomputer. By way of illustration, both an application running on a server and the server can be acomponent. One or more components can reside within a process and / or thread of executionand a component can be localized on one computer and / or distributed between two or morecomputers. These components also can execute from various computer readable storage mediacomprising various data structures stored thereon. The components can communicate via localand / or remote processes such as in accordance with a signal comprising one or more datapackets (e.g., data from one component interacting with another component in a local system,distributed system, and / or across a network such as the Internet with other systems via thesignal). As another example, a component can be an apparatus with specific functionalityprovided by mechanical parts operated by electric or electronic circuitry that is operated bysoftware or firmware application(s) executed by a processor, wherein the processor can beinternal or external to the apparatus and executes at least a part of the software or firmwareapplication. As yet another example, a component can be an apparatus that provides specificfunctionality through electronic components without mechanical parts, the electroniccomponents can comprise a processor therein to execute software or firmware that confers atleast in part the functionality of the electronic components. An interface can compriseinput / output (I / O) components as well as associated processor, application, and / or APIcomponents.
[0073] Furthermore, the disclosed subject matter can be implemented as a method, apparatus,or article of manufacture using standard programming and / or engineering techniques toproduce software, firmware, hardware, or any combination thereof to control a computer toimplement the disclosed subject matter. The term “article of manufacture” as used herein isintended to encompass a computer program accessible from any computer readable device,computer readable carrier, or computer readable media. For example, computer readablemedia can include, but are not limited to, a magnetic storage device, e.g., hard disk; floppy disk;magnetic strip(s); an optical disk (e.g., compact disk (CD), a digital video disc (DVD), a Blu rayDisc™ (BD)); a smart card; a flash memory device (e.g., card, stick, key drive); and / or a virtualdevice that emulates a storage device and / or any of the above computer readable media.
[0074] As it employed in the subject specification, the term “processor” can refer tosubstantially any computing processing unit or device comprising single core processors; singleDocket No.: 005811.00002processors with software multithread execution capability; multi core processors; multi coreprocessors with software multithread execution capability; multi core processors with hardwaremultithread technology; parallel platforms; and parallel platforms with distributed sharedmemory. Additionally, a processor can refer to an integrated circuit, an application specificintegrated circuit (ASIC), a digital signal processor (DSP), a field programmable gate array(FPGA), a programmable logic controller (PLC), a complex programmable logic device (CPLD), adiscrete gate or transistor logic, discrete hardware components, or any combination thereofdesigned to perform the functions described herein. Processors can exploit nano scalearchitectures such as, but not limited to, molecular and quantum dot based transistors, switchesand gates, in order to optimize space usage or enhance performance of UE. A processor also canbe implemented as a combination of computing processing units.
[0075] Further, terms like “mobile equipment”, “user equipment,” “user device,” “mobiledevice,” “mobile,” station, “access terminal,” “terminal,” “handset,” and similar terminology,generally refer to a wireless device utilized by a subscriber or user of a wireless communicationnetwork or service to receive or convey data, control, voice, video, sound, gaming, orsubstantially any data stream or signaling stream. The foregoing terms are utilizedinterchangeably in the subject specification and related drawings. Likewise, the terms “accesspoint,” “node B,” “base station,” “evolved Node B,” “cell,” “cell site,” and the like, can beutilized interchangeably in the subject application, and refer to a wireless network componentor appliance that serves and receives data, control, voice, video, sound, gaming, or substantiallyany data stream or signaling stream from a set of subscriber stations. Data and signalingstreams can be packetized or frame based flows. It is noted that in the subject specification anddrawings, context or explicit distinction provides differentiation with respect to access points orbase stations that serve and receive data from a mobile device in an outdoor environment, andaccess points or base stations that operate in a confined, primarily indoor environment overlaidin an outdoor coverage area. Data and signaling streams can be packetized or frame basedflows.
[0076] Furthermore, the terms “user,” “subscriber,” “customer,” “consumer,” and the like areemployed interchangeably throughout the subject specification, unless context warrantsparticular distinction(s) among the terms. It should be appreciated that such terms can refer tohuman entities, associated devices, or automated components supported through artificialintelligence (e.g., a capacity to make inference based on complex mathematical formalisms)Docket No.: 005811.00002which can provide simulated vision, sound recognition and so forth. In addition, the terms“wireless network” and “network” are used interchangeable in the subject application, whencontext wherein the term is utilized warrants distinction for clarity purposes such distinction ismade explicit.
[0077] Moreover, the word “exemplary,” where used, is used herein to mean serving as anexample, instance, or illustration. Any aspect or design described herein as “exemplary” is notnecessarily to be construed as preferred or advantageous over other aspects or designs. Rather,use of the word exemplary is intended to present concepts in a concrete fashion. As used in thisapplication, the term “or” is intended to mean an inclusive “or” rather than an exclusive “or”.That is, unless specified otherwise, or clear from context, “X employs A or B” is intended tomean any of the natural inclusive permutations. That is, if X employs A; X employs B; or Xemploys both A and B, then “X employs A or B” is satisfied under any of the foregoing instances.In addition, the articles “a” and “an” as used in this application and the appended claims shouldgenerally be construed to mean “one or more” unless specified otherwise or clear from contextto be directed to a singular form.
[0078] In addition, while a particular feature may have been disclosed with respect to only oneof several implementations, such feature can be combined with one or more other features ofthe other implementations as may be desired and advantageous for any given or particularapplication. Furthermore, to the extent that the terms “have”, “having”, “includes” and“including” and variants thereof are used in either the detailed description or the claims, theseterms are intended to be inclusive in a manner similar to the term “comprising.”
[0079] While the exemplary embodiments illustrated in the figures and described herein arepresently preferred, it should be understood that these embodiments are offered by way ofexample only. Accordingly, the present application is not limited to a particular embodiment butextends to various modifications that nevertheless fall within the scope of the appended claims.The order or sequence of any processes or method steps may be varied or re sequencedaccording to alternative embodiments.
Claims
Docket No.: 005811.00002Claims 1. A non transitory machine readable storage medium storing one or more sequences ofinstructions for a secured challenge and response for wireless network security, which whenexecuted by one or more processors, cause:a mobile equipment to provision the mobile equipment with an operator, theprovisioning comprising:requesting, with a subscriber identity module associated with the mobileequipment, a shared secret operator assigned symmetric equipment key; andproviding, from the operator, the shared secret operator assigned symmetricequipment key, and storing the shared secret operator assigned symmetricequipment key within the subscriber identity module;the subscriber identity module to challenge the mobile equipment, the challengingcomprising: generating an asymmetric key pair, the asymmetric key pair including anasymmetric encryption key and an asymmetric decryption key;providing the shared secret operator assigned symmetric equipment key andthe asymmetric encryption key to a secure enclave;sealing the shared secret operator assigned symmetric equipment key and theasymmetric encryption key into the secure enclave;generating a nonce with the subscriber identity module and transmitting thenonce to the secure enclave;encrypting the shared secret operator assigned symmetric equipment key andthe nonce with the asymmetric encryption key in the secure enclave to form averification encryption package;transmitting the verification encryption package to the subscriber identitymodule;Docket No.: 005811.00002decrypting the verification encryption package with the asymmetric decryptionkey to release the shared secret operator assigned symmetric equipment key;storing the shared secret operator assigned symmetric equipment key in thesubscriber identity module;generating, with the subscriber identity module, a cipher key and an integritykey from the shared secret operator assigned symmetric equipment key; andstoring the cipher key and an integrity key in the subscriber identity module.
2. The non transitory machine readable storage medium of claim 1, wherein the generating anasymmetric key pair is generating with the subscriber identity module.
3. The non transitory machine readable storage medium of claim 2, further comprising one ormore sequences of instructions for a secured challenge and response for wireless networksecurity, which when executed by one or more processors, cause:verification of the mobile equipment, the verification comprising:receiving, with the wireless module, a request for verification from a networknode; andin response to the request for verification, providing the cipher key and theintegrity key from the subscriber identity module to the network node.
4. The non transitory machine readable storage medium of claim 3, wherein the cipher key andintegrity key provided to the network node are encrypted.
5. The non transitory machine readable storage medium of claim 3, further comprising, permittingaccess by the mobile equipment to a wireless network associated with the network node uponverification of the cipher key and the integrity key from the subscriber identity module to thenetwork node by the network node.
6. The non transitory machine readable storage medium of claim 5, wherein the access to thewireless network utilizes a 5G protocol.
7. The non transitory machine readable storage medium of claim 3, further comprising, restrictingaccess to the wireless network by the mobile equipment to a wireless network associated withthe network node if verification of the cipher key and the integrity key from the subscriberidentity module to the network node is not verified by the network node.Docket No.: 005811.000028. The non transitory machine readable storage medium of claim 3, wherein the mobileequipment radio module includes a 5G radio access network driver.
9. A computer system configured to provide a secured challenge and response for wirelessnetwork security, comprising:a mobile equipment comprising one or more processors, the mobile equipmentcomprising one or more computer readable storage mediums storing one or moresequences of instructions, which when executed, cause:a mobile equipment to provision the mobile equipment with an operator, theprovisioning comprising:requesting, with a subscriber identity module associated with the mobileequipment, a shared secret operator assigned symmetric equipment key; andproviding, from the operator, the shared secret operator assigned symmetricequipment key, and storing the shared secret operator assigned symmetricequipment key within the subscriber identity module;the subscriber identity module to challenge the mobile equipment, the challengingcomprising: generating an asymmetric key pair, the asymmetric key pair including anasymmetric encryption key and an asymmetric decryption key;providing the shared secret operator assigned symmetric equipment key andthe asymmetric encryption key to a secure enclave;sealing the shared secret operator assigned symmetric equipment key and theasymmetric encryption key into the secure enclave;generating a nonce with the subscriber identity module and transmitting thenonce to the secure enclave;encrypting the shared secret operator assigned symmetric equipment key andthe nonce with the asymmetric encryption key in the secure enclave to form averification encryption package;Docket No.: 005811.00002transmitting the verification encryption package to the subscriber identitymodule; decrypting the verification encryption package with the asymmetric decryptionkey to release the shared secret operator assigned symmetric equipment key;storing the shared secret operator assigned symmetric equipment key in thesubscriber identity module;generating, with the subscriber identity module, a cipher key and an integritykey from the shared secret operator assigned symmetric equipment key; andstoring the cipher key and an integrity key in the subscriber identity module.
10. The computer system of claim 9, wherein the generating an asymmetric key pair is generatingwith the subscriber identity module.
11. The computer system of claim 9, further comprising one or more sequences of instructions for asecured challenge and response for wireless network security, which when executed, cause:verification of the mobile equipment, the verification comprising:receiving, with the wireless module, a request for verification from a networknode; andin response to the request for verification, providing the cipher key and theintegrity key from the subscriber identity module to the network node.
12. The computer system of claim 11, wherein the cipher key and integrity key provided to thenetwork node are encrypted.
13. The computer system of claim 11, further comprising, permitting access by the mobileequipment to a wireless network associated with the network node upon verification of thecipher key and the integrity key from the subscriber identity module to the network node by thenetwork node.
14. The computer system of claim 13, wherein the access to the wireless network utilizes a 5Gprotocol.
15. The computer system of claim 12, further comprising, restricting access to the wireless networkby the mobile equipment to a wireless network associated with the network node if verificationDocket No.: 005811.00002of the cipher key and the integrity key from the subscriber identity module to the network nodeis not verified by the network node.
16. The computer system of claim 11, wherein the mobile equipment radio module includes a 5Gradio access network driver.
17. A method for providing a secured challenge and response for wireless / mobile / IOT networksecurity, comprising:provisioning a mobile equipment with an operator, the provisioning comprising:requesting, with a subscriber identity module associated with the mobileequipment, a shared secret operator assigned symmetric equipment key; andproviding, from the operator, the shared secret operator assigned symmetricequipment key, and storing the shared secret operator assigned symmetricequipment key within the subscriber identity module;challenging the mobile equipment with the subscriber identity module, the challengingcomprising: generating an asymmetric key pair, the asymmetric key pair including anasymmetric encryption key and an asymmetric decryption key;providing the shared secret operator assigned symmetric equipment key andthe asymmetric encryption key to a secure enclave;sealing the shared secret operator assigned symmetric equipment key and theasymmetric encryption key into the secure enclave;generating a nonce with the subscriber identity module and transmitting thenonce to the secure enclave;encrypting the shared secret operator assigned symmetric equipment key andthe nonce with the asymmetric encryption key in the secure enclave to form averification encryption package;transmitting the verification encryption package to the subscriber identitymodule;Docket No.: 005811.00002decrypting the verification encryption package with the asymmetric decryptionkey to release the shared secret operator assigned symmetric equipment key;storing the shared secret operator assigned symmetric equipment key in thesubscriber identity module;generating, with the subscriber identity module, a cipher key and an integritykey from the shared secret operator assigned symmetric equipment key; andstoring the cipher key and an integrity key in the subscriber identity module.
18. The method of claim 17, wherein the generating an asymmetric key pair is generating with thesubscriber identity module.
19. The method of claim 17, wherein the provisioning further comprises:verifying the mobile equipment, the verifying comprising:receiving, with the wireless module, a request for verification from a networknode; andin response to the request for verification, providing the cipher key and theintegrity key from the subscriber identity module to the network node.
20. The method of claim 19, wherein the cipher key and integrity key provided to the network nodeare encrypted.
21. The method of claim 19, further comprising, permitting access by the mobile equipment to awireless network associated with the network node upon verification of the cipher key and theintegrity key from the subscriber identity module to the network node by the network node.
22. The method of claim 21, wherein the access to the wireless network utilizes a 5G protocol.
23. The method of claim 21, further comprising, restricting access to the wireless network by themobile equipment to a wireless network associated with the network node if verification of thecipher key and the integrity key from the subscriber identity module to the network node is notverified by the network node.
24. The method of claim 21, wherein the mobile equipment radio module includes a 5G radio accessnetwork driver.
Citation Information
Patent Citations
Electronic subscriber identity module provisioning
US20150341791A1
Pre-personalization of electronic subscriber identity modules
US20170093565A1
Systems And Methods For Encrypted Content Management
US20220231840A1
Electronic subscriber identity module transfer credential wrapping
US20220399993A1
Integrated universal integrated circuit card on mobile computing environments
WO2017082966A1