ANSI-41 Authentication for Legacy 2G CDMA Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy 2G CDMA hardware devices are unable to provide a mutually authenticated communication channel using 3G CDMA AKA security protocols due to outdated hardware, and attempts to use IS-41 authentication procedures are insecure as they allow attackers to replay session keys.
Innovation Solution
Implementing ANSI-41 security protocols by mobile equipment and networks to establish authentication keys through a method involving challenges, responses, and message authentication codes, ensuring secure communication channels without relying on compromised session keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If legacy 2G CDMA hardware devices are used, then device compatibility is maintained, but mutual authentication capability is lost
Solution Approach 1:
The patent changes the authentication parameters by using ANSI-41 protocol instead of traditional 2G CDMA authentication. This allows legacy hardware to perform mutual authentication by modifying the authentication mechanism rather than requiring hardware replacement, thus maintaining compatibility while improving security.
Solution Approach 2:
The patent replaces the mechanical hardware-based authentication system with a protocol-based authentication mechanism. By substituting the authentication process with ANSI-41 protocol that uses challenges and responses, the system achieves mutual authentication without requiring new hardware, resolving the contradiction between hardware compatibility and authentication security.
2Adaptability or versatility
If IS-41 authentication procedures are used, then protocol compatibility is achieved, but security is compromised due to replay attacks
Solution Approach 1:
The patent applies preliminary action by having the network send a challenge before the authentication response is generated. This challenge-response mechanism prevents replay attacks because the challenge changes with each authentication attempt, making it impossible for attackers to reuse previous authentication responses.
Solution Approach 2:
The patent implements feedback through the challenge-response mechanism where the network sends a challenge, the mobile station generates a response based on that challenge, and the network verifies the response. This feedback loop ensures that each authentication is unique and prevents replay attacks, while maintaining protocol compatibility.
3Adaptability or versatility
If traditional authentication keys are used, then backward compatibility is maintained, but communication security is insufficient
Solution Approach 1:
The patent achieves universality by designing an authentication mechanism that works on legacy 2G CDMA hardware while providing 3G-level security. The ANSI-41 protocol is implemented in a way that is compatible with existing hardware, allowing the same device to maintain both backward compatibility and enhanced communication security.
Solution Approach 2:
The patent uses an intermediary approach by introducing a new authentication protocol layer that sits between the legacy hardware and the communication security requirements. This intermediary protocol (ANSI-41) translates the capabilities of legacy hardware into secure authentication mechanisms, bridging the gap between backward compatibility and communication security.
Data Source
AI summary
A method of establishing authentication keys at both a network and mobile equipment are provided. The authentication key generated by the mobile equipment is based on both mobile keys and network keys, which are each calculated by the mobile equipment. The authentication key generated by the network is based on both mobile keys and network keys, which are each calculated by the network. The mobile keys are calculated from a challenge generated by the mobile equipment and the network keys generated by the mobile based on a challenge generated by network.


