Extended Sequence Number for Mutual Authentication in Legacy CDMA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional 2G CDMA security protocols lack mutual authentication, and some hardware devices are not capable of processing more advanced 3G CDMA or IMS security protocols, limiting their ability to establish secure communication channels with IMS networks.

Innovation Solution

The introduction of an extended sequence number that includes a hardware identifier of the mobile equipment, allowing for mutual authentication by comparing message authentication codes and sequence numbers, and reallocating bits to accommodate the additional hardware identifier information in authentication tokens and vectors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional 3G CDMA security protocols with sequence numbers are used, then mutual authentication is achieved, but legacy 2G CDMA hardware devices cannot process these protocols

Engineering Contradiction:
Improvemutual authenticationVSAvoidhardware compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The sequence number is segmented into two parts: a hardware identifier portion and a conventional sequence number portion. This segmentation allows the authentication protocol to include hardware-specific identification while maintaining compatibility with existing authentication mechanisms, enabling both mutual authentication and broader hardware adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The extended sequence number structure serves multiple functions: it provides hardware identification, maintains sequence number functionality for authentication state tracking, and enables mutual authentication. This multi-functionality allows the same authentication mechanism to work across different hardware platforms while achieving the security goals of 3G CDMA protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If sequence number size is increased to include hardware identifiers, then mutual authentication capability is improved, but the size of authentication tokens and vectors increases

Engineering Contradiction:
Improvemutual authentication capabilityVSAvoidauthentication token size
Core Design Contradiction:
ReliabilityVSLength of stationary object

Solution Approach 1:

The authentication token structure is segmented to include the extended sequence number as a distinct component. This segmentation allows the system to manage the increased size by organizing the token into manageable parts: hardware identifier, sequence number, authentication management field, and message authentication code, facilitating efficient processing and transmission.

Inventive Principle:
Principle #1Segmentation

3Reliability

If extended sequence numbers with hardware identifiers are implemented, then security is enhanced through mutual authentication, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication protocol is segmented into distinct processing steps: extracting the extended sequence number from the authentication token, separating the hardware identifier from the sequence number portion, verifying the message authentication code, and updating the stored sequence number. This segmentation simplifies the implementation complexity by providing a clear, step-by-step process despite the enhanced security requirements.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2195997B1Method and system of communication using extended sequence number
Publication Date: 2017.05.03 NOKIA OF AMERICA CORP
  • EP2195997B1 patent drawingFigure 1
  • EP2195997B1 patent drawingFigure 2~3
  • EP2195997B1 patent drawingFigure 4

AI summary

Described is a method by mobile equipment (100) to communicate with a network (20). The method includes receiving a network authentication token (AUTN) having a first message authentication code (MAC), an authentication message field (AMF) and a first extended sequence number (ESQN) that includes a first hardware identifier and first sequence number, and authenticating the network based on the first message authentication code, the first hardware identifier, and the first sequence number.