白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Secured authenticated communication between an initiator and a responder

專利號(hào)
US11997078B2
公開日期
2024-05-28
申請(qǐng)人
Telefonaktiebolaget LM Ericsson (publ)(SE Stockholm)
發(fā)明人
Vesa Lehtovirta; Mohit Sethi
IPC分類
H04L9/40
技術(shù)領(lǐng)域
responder,initiator,n3iwf,party,ue,ike_auth,eap,in,message,secure
地域: Stockholm

摘要

Secure, authenticated communication is enabled between an initiator (12) (e.g., a user equipment) and a responder (14) (e.g., an authentication server function, AUSF, or a subscription de-concealing function, SIDF). The initiator (12) transmits a message (20) to the responder (14) over a secure communication channel (16). The message (20) may include information indicating a third party (18) whose signing of data (e.g., bound to the secure communication channel (16)) will authenticate the responder (14) to the initiator (12). The responder (14) correspondingly retrieves from the third party (18) data that is signed by the third party (18) and transmits a response (24) to the initiator (12) that includes the retrieved data. The initiator (12) receives this response (24) and determines whether or not the responder (14) is authenticated by determining whether or not the response (24) includes data that is signed by the third party (18).

說明書

In step 10, the UE 40 completes the authentication (if initiated in step 7) and creates a NAS security context. The UE 40 shall respond to the NAS SMC it received from the AMF 48 based on the selected algorithms and parameters. The UE 40 shall encapsulate the NAS SMC Complete in the EAP-5G Response.

In step 11, the N3IWF 42 shall forward the NAS packet containing NAS SMC Complete to the AMF 48 over the N2 interface.

In step 12, the AMF 48 upon reception of the NAS SMC Complete from the UE 40 or upon success of integrity protection verification, initiates the NGAP procedure to set up the AN context. The AMF 48 shall compute the N3IWF key, KN3IWF, using the uplink NAS COUNT associated with NAS connection identifier “1” for the establishment of the IPsec SA between the UE 40 and the N3IWF 42 and shall include it in the NGAP Initial Context Setup Request sent to the N3IWF 42.

In step 13, the N3IWF 42 sends an EAP-Success/EAP-5G to the UE 40 upon reception of the NGAP Initial Context Setup Request containing the N3IWF key, KN3IWF. This completes the EAP-5G session and no further EAP-5G packets are exchanged. If the N3IWF 42 does not receive the KN3IWF from AMF 48, the N3IWF 42 shall respond with an EAP-Failure.

In step 14, the IPsec SA is established between the UE 40 and N3IWF 42 by using the N3IWF key KN3IWF that was created in the UE 40 using the uplink NAS COUNT associated with NAS connection identifier “1” and was received by N3IWF 42 from the AMF 48 in step 12.

權(quán)利要求

1
微信群二維碼
意見反饋