7.2.3 Mutual Authentication and Establishment of a Shared Key
between the Serving Network and the UE
The purpose of this procedure is the authentication of the user and the establishment of a
new local master key KASME between the MME and the UE, and, furthermore, the verifi-
cation of the freshness of the AV and authentication of its origin (the user’s home network)
by the USIM. KASME is used in subsequent procedures for deriving further keys for the
protection of the user plane (UP), RRC signalling and NAS signalling (see Section 7.3).
Authentication Requests
The MME invokes the procedure by selecting the next unused EPS AV from the ordered
array of EPS AVs in the MME database (if there is more than one). If the MME has
no EPS AV, it requests one from the HSS. The MME then sends the random challenge
RAND and the authentication token for network authentication AUTN from the selected
EPS AV to the ME, which forwards it to the USIM. The MME also generates a key set
identifier in EPS (eKSI) and includes it in the Authentication Request (see Section 7.4).
Verification in the USIM
Upon receipt of RAND and AUTN, the USIM proceeds as shown in Figure 7.3, which
is taken from Figure 9 in [TS33.102].
According to [TS33.102], the USIM first computes the AK = f5K (RAND) and retrieves
the sequence number SQN = (SQN xor AK) xor AK, where K is, as explained, the
permanent secret key shared between USIM and AuC. Remember that if no concealment
is needed, then f5K ≡ 0 (AK = 0).
Next the USIM computes XMAC = f1K (SQN ||RAND || AMF) and verifies that it
equals the MAC included in AUTN.
Then the USIM verifies that the received sequence number SQN is in the correct range.
The mechanism for the SQN verification in the USIM has not been standardized, for the
same reason that the SQN generation in the HSS has not been standardized: both the
USIM and the HSS are under the control of the same stakeholder, the operator. But, for
those who do not want to specify their own mechanism, the informative Annex C.2 of
[TS33.102] provides an example mechanism.
đang được dịch, vui lòng đợi..