欢迎来到天天文库
浏览记录
ID:22795610
大小:185.50 KB
页数:10页
时间:2018-10-31
《鉴权加密流程》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、33102分组域和电路域地鉴权加密流程是互相独立地.目前SGSN实现地时候,可以实现两种处理:1、是否鉴权;2、隔多少次鉴权一次.可以配置间隔地次数.对于加密来说,每次搭建Iu连接,就需要进行加密地重新协商.哪怕是由于进行业务引起地Iu连接建立.但是此时只是重新协商一致性校验地相关参数和加密算法,密钥CK和IK是不会变地(因为密钥地产生是在鉴权流程中根据RAND产生地,所以只有鉴权之后,才会产生新地密钥).3G是不能重用鉴权参数(5元组)地.因为AUTN中有跟时间同步相关地参数,所以无法重用.a.鉴权流程
2、Figure5:AuthenticationandkeyagreementUponreceiptofarequestfromtheVLR/SGSN,theHE/AuCsendsanorderedarrayofnauthenticationvectors(theequivalentofaGSM"triplet")totheVLR/SGSN.Theauthenticationvectorsareorderedbasedonsequencenumber.Eachauthenticationvectorconsi
3、stsofthefollowingcomponents:arandomnumberRAND,anexpectedresponseXRES,acipherkeyCK,anintegritykeyIKandanauthenticationtokenAUTN.EachauthenticationvectorisgoodforoneauthenticationandkeyagreementbetweentheVLR/SGSNandtheUSIM.WhentheVLR/SGSNinitiatesanauthenti
4、cationandkeyagreement,itselectsthenextauthenticationvectorfromtheorderedarrayandsendstheparametersRANDandAUTNtotheuser.Authenticationvectorsinaparticularnodeareusedonafirst-in/first-outbasis.TheUSIMcheckswhetherAUTNcanbeacceptedand,ifso,producesaresponseR
5、ESwhichissentbacktotheVLR/SGSN.TheUSIMalsocomputesCKandIK.TheVLR/SGSNcomparesthereceivedRESwithXRES.IftheymatchtheVLR/SGSNconsiderstheauthenticationandkeyagreementexchangetobesuccessfullycompleted.TheestablishedkeysCKandIKwillthenbetransferredbytheUSIMand
6、theVLR/SGSNtotheentitieswhichperformcipheringandintegrityfunctions.VLR/SGSNscanoffersecureserviceevenwhenHE/AuClinksareunavailablebyallowingthemtousepreviouslyderivedcipherandintegritykeysforausersothatasecureconnectioncanstillbesetupwithouttheneedforanau
7、thenticationandkeyagreement.Authenticationisinthatcasebasedonasharedintegritykey,bymeansofdataintegrityprotectionofsignallingmessages(see6.4).TheauthenticatingpartiesshallbetheAuCoftheuser'sHE(HE/AuC)andtheUSIMintheuser'smobilestation.Themechanismconsists
8、ofthefollowingprocedures:AproceduretodistributeauthenticationinformationfromtheHE/AuCtotheVLR/SGSN.Thisprocedureisdescribedin6.3.2.TheVLR/SGSNisassumedtobetrustedbytheuser'sHEtohandleauthenticationinformationsecurel
此文档下载收益归作者所有