白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Secured authenticated communication between an initiator and a responder

專利號(hào)
US11997078B2
公開日期
2024-05-28
申請(qǐng)人
Telefonaktiebolaget LM Ericsson (publ)(SE Stockholm)
發(fā)明人
Vesa Lehtovirta; Mohit Sethi
IPC分類
H04L9/40
技術(shù)領(lǐng)域
responder,initiator,n3iwf,party,ue,ike_auth,eap,in,message,secure
地域: Stockholm

摘要

Secure, authenticated communication is enabled between an initiator (12) (e.g., a user equipment) and a responder (14) (e.g., an authentication server function, AUSF, or a subscription de-concealing function, SIDF). The initiator (12) transmits a message (20) to the responder (14) over a secure communication channel (16). The message (20) may include information indicating a third party (18) whose signing of data (e.g., bound to the secure communication channel (16)) will authenticate the responder (14) to the initiator (12). The responder (14) correspondingly retrieves from the third party (18) data that is signed by the third party (18) and transmits a response (24) to the initiator (12) that includes the retrieved data. The initiator (12) receives this response (24) and determines whether or not the responder (14) is authenticated by determining whether or not the response (24) includes data that is signed by the third party (18).

說明書

Embodiments herein further include a method for enabling secured, authenticated communication between an initiator and a responder. The method as performed by third party equipment of a third party includes receiving, at the third party equipment and from the responder, a request that includes data (e.g., bound to a secure communication channel established between the initiator and the responder) and that requests the third party to sign the data. The method may further include signing the data at the third party equipment and transmitting the signed data from the third party equipment towards the responder in response to the request.

Note that the data described in any of the methods in some embodiments includes or is a function of at least some data exchanged between the initiator and the responder as part of establishing the secure communication channel. In one embodiment, for instance, the data comprises an authentication payload formed from at least a portion of a message that the responder sent to the initiator as part of establishing the secure communication channel. Alternatively or additionally, the data may include or be a function of one or more of: a shared secret resulting from establishment of the secure communication channel; one or more freshness parameters exchanged as part of establishing the secure communication channel; and an identity of the responder and/or an identity of the initiator.

In still further embodiments, the data described above may comprises a random number signed with a key derived from a shared secret SKEYSEED. The shared secret SKEYSEED may for instance be calculated from one or more nonces exchanged between the initiator and the responder as part of establishing the secure communication channel and from a Diffie-Hellman shared secret or an Elliptic Curve Diffie-Hellman shared secret between the initiator and the responder.

權(quán)利要求

1
微信群二維碼
意見反饋