3 ms·
I skimmed through the paper, what isn’t clear to me is how the original Registration Procedure is modified exactly. How is the Authentication Procedure done by
by red0point 5y ago
I skimmed through the paper, what isn’t clear to me is how the original Registration Procedure is modified exactly. How is the Authentication Procedure done by the AUF when it doesn’t know the shared key K between the USIM and the network?
Can you elaborate a bit on that? Is every USIM using the same shared key?
Thanks!
- red0point 5y agoAdditional question for my understanding - this needs an app running in the background to send the signed token at every other time interval, correct?
- barathr 5y agoThat's right. (The token is used for oblivious authentication, so it's not identifying.) The attach procedure works as usual, it's just that the IMSI/SUPI is no longer individually identifying (which then necessitates the oblivious authentication protocol).
- prschmitt 5y agoThe regular attach procedure is unchanged. In the simplest version we give every SIM the identical IMSI and key. However, their use is to only gain IP connectivity - the equivalent of an allow list on the backend db (AUSF) which gives you IP connectivity. At that point you do billing and auth at the PGPP-GW using oblivious auth tokens.
- red0point 5y agoThanks! You mention that this is the simplest version, is there one where you use distinct keys? Also, regarding the IMEI - let‘s assume the UE nullified it, how would you distinguish between a legitimately nullified UE and a stolen UE that had its IMEI nullified?