×

Method, system and authentication centre for authenticating in end-to-end communications based on a mobile network

  • US 7,984,298 B2
  • Filed: 08/30/2007
  • Issued: 07/19/2011
  • Est. Priority Date: 01/24/2006
  • Status: Active Grant
First Claim
Patent Images

1. A method for authenticating in end-to-end communications based on a mobile network, applied to a system including a first service entity requesting a service, a second service entity providing the service and an Entity Authentication Centre, EAC, the method comprising:

  • negotiating an authentication mode between the first service entity and the EAC, wherein the negotiated authentication mode comprises;

    an authentication mechanism between the first service entity and the EAC, an authentication mechanism between the second service entity and the EAC, a mechanism of authentication inquiring, a mechanism for generating a derived key, and an authentication mechanism between the first service entity and the second service entity;

    performing a mutual authentication between the EAC and the first service entity according to the authentication mechanism between the first service entity and the EAC comprised in the negotiated authentication mode, and performing a mutual authentication between the EAC and the second service entity according to the authentication mechanism between the second service entity and the EAC comprised in the negotiated authentication mode;

    if the first service entity requests the second service entity to provide the service, the EAC providing authentication inquiring for the first service entity and the second service entity according to the mechanism of authentication inquiring comprised in the negotiated authentication mode, and generating a shared derived key for protecting the communication between the first service entity and the second service entity according to the mechanism for generating a derived key comprised in the negotiated authentication mode; and

    the first service entity and the second service entity authenticating each other according to the shared derived key and the authentication mechanism between the first service entity and the second service entity comprised in the negotiated authentication mode, and generating a session key for protecting the service.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×