发明名称 CRYPTOGRAPHIC KEY MANAGEMENT IN COMMUNICATION NETWORKS
摘要 An authentication server and a system and method for managing cryptographic keys across different combinations of user terminals, access networks, and core networks. A Transformation Coder Entity, TCE, (25) creates a master key, Mk, which is used to derive keys during the authentication procedure. During handover between the different access types, the Mk or a transformed Mk is passed between two authenticator nodes (42, 43, 44) that hold the key in the respective access networks when a User Equipment, UE, terminal (41, 51, 52, 53) changes access. The transformation of the Mk is performed via a one-way function, and has the effect that if the Mk is somehow compromised, it is not possible to automatically obtain access to previously used master keys. The transformation is performed based on the type of authenticator node and type of UE/identity module with which the transformed key is to be utilized. The Mk is never used directly, but is only used to derive the keys that are directly used to protect the access link.
申请公布号 KR20090067185(A) 申请公布日期 2009.06.24
申请号 KR20097007876 申请日期 2009.04.17
申请人 TELEFONAKTIEBOLAGET LM ERICSSON(PUBL) 发明人 BLOM ROLF;NASLUND MATS;NORRMAN KARL
分类号 H04L9/08;H04L9/32 主分类号 H04L9/08
代理机构 代理人
主权项
地址