×

ENTITY BIDIRECTIONAL-IDENTIFICATION METHOD FOR SUPPORTING FAST HANDOFF

  • US 20110078438A1
  • Filed: 05/27/2009
  • Published: 03/31/2011
  • Est. Priority Date: 05/29/2008
  • Status: Active Grant
First Claim
Patent Images

1. A mutual entity authentication method supporting rapid handoff, the method involving three security elements comprising two authentication elements A and B and a Trusted third Party TP, wherein the trusted third party TP is a trusted third party of the authentication elements A and B;

  • the authentication element A comprises n authentication entities A1, A2, . . . , An, and the authentication element B comprises m authentication entities B1, B2, . . . , Bm, among which synchronization information is provided; and

    all of the authentication entities in the same authentication element share one public key certificate or possess one public key, and for any pair of authentication entities Ai (i=1, 2, . . . , n) and Bj (j=1, 2, . . . , m), the authentication method comprises the steps of;

    1) transmitting, by the authentication entity Bj, an authentication activation message INIBj to the authentication entity Ai, whereinINIBj=RBj

    IDB

    Text1, wherein RBj denotes a random number generated by the authentication entity Bj, IDB denotes an identifier of the authentication element B, and Text1 denotes a first optional text;

    2) transmitting, by the authentication entity Ai, an access authentication request message AREQAi to the authentication entity Bj upon reception of the authentication activation message INIBj, wherein
    AREQAi=RBj

    R
    Ai

    IDA

    Text2∥

    TokenAB TokenAB=sSA(RBj

    RAi

    IDAText2), wherein RAi denotes a random number generated by the authentication entity Ai, IDA denotes an identifier of the authentication element A, Text2 denotes a second optional text, TokenAB denotes a token transmitted from the authentication entity Ai to the authentication entity Bj, and sSA denotes a signature of the authentication element A;

    3) on receiving the access authentication request message AREQAi, verifying, by the authentication entity Bj, RBj in AREQAi and RBj in INIBj for consistency, and if RBj in AREQAi is consistent with RBj in INIBj, searching, by the authentication entity Bj, for a locally stored authentication result of the authentication element A;

    if there is stored an authentication result of the authentication element A, going to step

         4);

    4) transmitting, by the authentication entity Bj, an access authentication response message ARESBj to the authentication entity Ai, and calculating a shared master key between the authentication entities Ai and Bj, wherein
    ARESBj=IRESTP

    R
    Ai

    Text5∥

    TokenBA TokenBA=sSB(TokenAB∥

    RBj

    Text5), wherein Text5 denotes a fifth optional text, IRESTP denotes an identity authentication response message stored locally at the authentication entity Bj which comprises the authentication result of the authentication element A, TokenBA denotes a token transmitted from the authentication entity Bj to the authentication entity Ai, and sSB denotes a signature of the authentication element B; and

    5) verifying, by the authentication entity Ai, the access authentication response message ARESBj upon reception thereof.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×