Extended Sequence Number for Mutual Authentication in Legacy CDMA
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional 2G CDMA security protocols lack mutual authentication, and some hardware devices are not capable of processing more advanced 3G CDMA or IMS security protocols, limiting their ability to establish secure communication channels with IMS networks.
Innovation Solution
The introduction of an extended sequence number that includes a hardware identifier of the mobile equipment, allowing for mutual authentication by comparing message authentication codes and sequence numbers, and reallocating bits to accommodate the additional hardware identifier information in authentication tokens and vectors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional 3G CDMA security protocols with sequence numbers are used, then mutual authentication is achieved, but legacy 2G CDMA hardware devices cannot process these protocols
Solution Approach 1:
The sequence number is segmented into two parts: a hardware identifier portion and a conventional sequence number portion. This segmentation allows the authentication protocol to include hardware-specific identification while maintaining compatibility with existing authentication mechanisms, enabling both mutual authentication and broader hardware adaptability.
Solution Approach 2:
The extended sequence number structure serves multiple functions: it provides hardware identification, maintains sequence number functionality for authentication state tracking, and enables mutual authentication. This multi-functionality allows the same authentication mechanism to work across different hardware platforms while achieving the security goals of 3G CDMA protocols.
2Reliability
If sequence number size is increased to include hardware identifiers, then mutual authentication capability is improved, but the size of authentication tokens and vectors increases
Solution Approach 1:
The authentication token structure is segmented to include the extended sequence number as a distinct component. This segmentation allows the system to manage the increased size by organizing the token into manageable parts: hardware identifier, sequence number, authentication management field, and message authentication code, facilitating efficient processing and transmission.
3Reliability
If extended sequence numbers with hardware identifiers are implemented, then security is enhanced through mutual authentication, but device complexity increases
Solution Approach 1:
The authentication protocol is segmented into distinct processing steps: extracting the extended sequence number from the authentication token, separating the hardware identifier from the sequence number portion, verifying the message authentication code, and updating the stored sequence number. This segmentation simplifies the implementation complexity by providing a clear, step-by-step process despite the enhanced security requirements.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
Described is a method by mobile equipment (100) to communicate with a network (20). The method includes receiving a network authentication token (AUTN) having a first message authentication code (MAC), an authentication message field (AMF) and a first extended sequence number (ESQN) that includes a first hardware identifier and first sequence number, and authenticating the network based on the first message authentication code, the first hardware identifier, and the first sequence number.