Cellular Network Authentication Algorithm Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cellular network authentication methods face vulnerabilities due to increasing computational power and the need for enhanced security in long-term evolution and machine-type communication systems, where traditional encryption techniques are becoming less effective against advanced attacks.
Innovation Solution
A method and apparatus for a cellular terminal that employs a security entity with a secure element and subscriber identity application, using cryptographic algorithms like MILENAGE and TUAK, which can select and adapt cryptographic algorithms dynamically for authentication requests and responses, including extended authentication messages with 256-bit authentication tokens and parameters, to enhance security and compatibility with legacy systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional encryption techniques are used for cellular network authentication, then compatibility with legacy systems is maintained, but security resilience against advanced attacks deteriorates
Solution Approach 1:
The authentication system dynamically adapts between different cryptographic algorithms (MILENAGE for legacy systems, TUAK for enhanced security) based on the capabilities of the terminal and network configuration. This allows the system to optimize security resilience while maintaining backward compatibility with legacy authentication infrastructure.
Solution Approach 2:
The patent changes the cryptographic parameters used in authentication by supporting multiple algorithm types (MILENAGE, TUAK-128, TUAK-256) with different key lengths and computational characteristics. This enables the system to adjust security parameters according to threat models and terminal capabilities, resolving the contradiction between enhanced security and legacy compatibility.
2Reliability
If cryptographic algorithms are dynamically selected for authentication, then security is enhanced, but device complexity increases
Solution Approach 1:
The authentication entity is designed with multi-functionality to support multiple cryptographic algorithms (MILENAGE, TUAK-128, TUAK-256) within a single unified framework. This universal design allows the system to enhance security through algorithm selection without proportionally increasing device complexity, as the same authentication infrastructure handles multiple algorithm types.
3Reliability
If extended authentication messages with 256-bit tokens are used, then authentication security is improved, but message length and processing overhead increase
Solution Approach 1:
The authentication message structure dynamically adapts its length based on the selected cryptographic algorithm. When TUAK-256 is selected for enhanced security, extended messages with 256-bit tokens are used. When legacy algorithms are used, standard message lengths are maintained. This dynamic adjustment optimizes security while minimizing unnecessary processing overhead.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
A method, apparatus and computer program in which a cellular terminal: transmits a request that requires authentication procedure triggering to a cellular network and responsively receiving from the cellular network an authentication request message with an indication of a selected cryptographic algorithm from a group of a plurality of cryptographic algorithms; decodes the authentication request message to a decoded authentication request according to the selected cryptographic algorithm and based on a shared secret known by the cellular terminal and a network operator of the cellular terminal; based on the decoded authentication request, the shared secret and the selected cryptographic algorithm, produces and encrypts an authentication response message; and transmits the authentication response message to the cellular network.