首页> 外国专利> METHOD FOR AUTHENTICATING A SECURE ELEMENT AT THE LEVEL OF AN AUTHENTICATION SERVER, CORRESPONDING SECURE ELEMENT AND AUTHENTICATION SERVER

METHOD FOR AUTHENTICATING A SECURE ELEMENT AT THE LEVEL OF AN AUTHENTICATION SERVER, CORRESPONDING SECURE ELEMENT AND AUTHENTICATION SERVER

机译:用于在身份验证服务器的级别,对应的安全元件和认证服务器的级别进行身份验证安全元件的方法

摘要

The invention concerns a method for authenticating a secure element (10) at the level of an authentication server (12), the secure element (10) being able to cooperate with a telecommunication terminal, the method comprising: Generating at the secure element (10) a first message comprising a partial IMSI of the secure element (10) or a partial IMSI of an IMSI based user identity that is in the form of a NAI of the secure element, called MSI N_part1, the first message also comprising the MCC and MNC codes of the IMSI or of the IMSI based user identity that is in the form of a NAI of the secure element 10, the MSIN_part1 comprising some of the most significant digits of the MSIN; Generating at the secure element (10) a second message containing a second part, called MSIN_part2, of the MSIN of the secure element (10) and the current sequence number, the second message being encrypted by the key Ki of the secure element (10) in order to provide a token X, the MSIN_part2 comprising some of the less significant digits of the MSIN; Transmitting the first message and the token X to the authentication server (12); At the authentication server (12), creating a list of the candidate secure elements for which the MSIN_part1 corresponds and, for each of the candidate secure elements of the list, decrypting the token X with the key Ki of each of the candidate secure elements of the list, in order to generate a decrypted IMSI comprising the MCC, MNC and MSIN_part1 of the first message and decrypted MSIN_part2 of the token X or a decrypted IMSI based user identity that is in the form of a NAI comprising the MCC, MNC and MSIN_part1 of the first message and the decrypted MSIN_part2 of the token X; Checking at the authentication server (12), for each candidate secure element of the list, which candidate IMSI or candidate IMSI based user identity that is in the form of a NAI : a corresponds to the decrypted IMSI of the decrypted token X; and b has an associated sequence number in a valid range of the decrypted sequence number; At the authentication server (12), generating an authentication vector by using the key Ki of the candidate secure element associated to the IMSI or IMSI based user identity that is in the form of a NAI that matches the decrypted MSIN_part2 of the decrypted token X and the candidate secure element has sequence number in a valid range of the decrypted sequence number in order to launch a challenge response process between the secure element (10) and the authentication server (12).
机译:本发明涉及一种用于在认证服务器(12)的级别的安全元件(10)的方法,所述安全元件(10)能够与电信终端配合,该方法包括:在所述安全元件处产生(10 )第一消息包括安全元件(10)的部分IMSI或基于IMSI的基于IMSI的局部IMSI,其是由安全元件的NAI的NAI的形式,称为MSI N_PART1,第一消息还包括MCC和MNC代码的IMSI或基于IMSI的用户身份,其呈安全元件10的NAI的形式,MSIN_PART1包括MSIN的一些最有效数字;在安全元件(10)处生成包含安全元件(10)和当前序列号的MSIN的第二部分的第二消息,以及由安全元件的密钥ki加密的第二消息(10 )为了提供令牌X,MSIN_PART2包括MSIN的一些较小数字的一些较小数字;将第一条消息和令牌X发送到认证服务器(12);在认证服务器(12)中,创建MSIN_PART1对应的候选安全元件的列表,并且对于列表的每个候选安全元件,以及用每个候选安全元件的密钥Ki解密令牌X.该列表,以便生成包括MCC,MNC和MSIN_PART1的解密的IMSI,并将令牌X的MSIN_PART2解密或基于解密的IMSI的MSIN_PART2以包含MCC,MNC和MSIN_PART1的NAI的形式的解密的基于IMSI的用户身份。第一个消息和令牌x的解密的msin_part2;检查身份验证服务器(12),用于列表的每个候选安全元素,其候选IMSI或基于候选IMSI的候选IMSI以NAI的形式对应于解密的令牌x的解密的IMSI; B在解密的序列号的有效范围内具有相关的序列号;在认证服务器(12)中,通过使用与IMSI或IMSI的基于IMSI的密钥Ki的密钥Ki的密钥ki以与解密的令牌x的解密的MSIN_PART2匹配的NAI的形式,生成认证向量候选安全元件在解密的序列号的有效范围内具有序列号,以便在安全元件(10)和认证服务器(12)之间启动挑战响应过程。

著录项

  • 公开/公告号WO2021115699A1

    专利类型

  • 公开/公告日2021-06-17

    原文格式PDF

  • 申请/专利权人 THALES DIS FRANCE SA;

    申请/专利号WO2020EP81566

  • 发明设计人 PHAN LY THANH;

    申请日2020-11-10

  • 分类号H04W12/02;H04W12/03;H04W12/06;H04W12/72;

  • 国家 EP

  • 入库时间 2022-08-24 19:27:30

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号