US 12,108,250 B2
Method and device for authenticating access stratum in next generation wireless communication system
Donghyun Je, Suwon-si (KR); and Jungsoo Jung, Suwon-si (KR)
Assigned to Samsung Electronics Co., Ltd., Suwon-si (KR)
Filed by Samsung Electronics Co., Ltd., Suwon-si (KR)
Filed on Nov. 24, 2021, as Appl. No. 17/535,209.
Claims priority of application No. 10-2020-0160985 (KR), filed on Nov. 26, 2020.
Prior Publication US 2022/0167166 A1, May 26, 2022
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01); H04W 12/033 (2021.01); H04W 12/069 (2021.01)
CPC H04W 12/069 (2021.01) [H04L 63/0869 (2013.01); H04W 12/033 (2021.01)] 13 Claims
OG exemplary drawing
 
1. A method of a user equipment (UE) for a mutual authentication operation in an access stratum (AS) section in a wireless communication system, the method comprising:
transmitting, to a base station, a first message including a first random value;
receiving, from the base station, a second message including a second random value and a base station certificate for the base station in response to transmitting the first message;
transmitting, to the base station, a certificate revocation information request message to receive revocation information for the base station certificate from a certificate verification server;
receiving, from the base station, a certificate revocation information response message including the revocation information for the base station certificate;
determining whether the base station certificate is valid based on the revocation information for the base station certificate;
transmitting, to the base station, a third message including a UE certificate and a temporary session key based on a determination that the base station certificate is valid; and
receiving, from the base station, a fourth message indicating that the mutual authentication operation between the UE and the base station is completed in case that an authentication operation of the UE certificate is completed,
wherein a session key for the base station is generated based on the first random value, the second random value, and the temporary session key, and
wherein the revocation information for the base station certificate comprises a credential revocation list (CRL) indicating a certificate revocation list, and the revocation information for the base station certificate is identified per registration area (RA) or per tracking area (TA) based on location information for at least one base station and movement information for at least one UE.