Evolution of Cellular Systems 19
The following security features are associated with the confidentiality of the data on
the network access link:
● Cipher algorithm agreement: the property that ensures that subscriber and serving
network can securely decide on the algorithm that should be subsequently used;
● Cipher key agreement: the property that subscriber and the serving network mutually
decide on the cipher key that should be subsequently used;
● Confidentiality of user data: the property that ensures that user data is protected on
the overhead, such that it cannot be overheard; and
● Confidentiality of signaling data: the property that ensures that signaling data cannot
be overheard on the radio interface.
The features provided to achieve integrity of data on the network access link are:
● Integrity algorithm agreement: the property that the subscriber and the serving network
can securely decide on the integrity algorithm that should be subsequently used;
● Integrity key agreement: the property that the subscriber and the serving network
agree on an integrity key that shall be subsequently used; and
● Data integrity and origin authentication of signaling data: the property that the
subscriber or serving network is able to verify that signaling has not been modified
later after it was sent by the sending entity, and that the origin of the signaling data
received is the valid one.
UMTS AKA is a security mechanism used to accomplish the authentication features
and all of the key agreement features described above. This mechanism is based on a
challenge/response authentication protocol implemented in such a way as to achieve
maximum compatibility with GSM’s subscriber authentication and key establishment
protocol, so that the transition from GSM to UMTS can be made. A challenge/response
protocol is a security measure used by one entity to verify the identity of another entity,
without revealing a secret password shared by the two entities involved [23]. Each entity
must prove to the other that it knows the password without actually revealing the
information that it has knowledge of the password.
The UMTS AKA process is started by a serving network after first registration by a
user, after a service request, after a location update request, after an attach request, and
after a detach request or connection re‐establishment request. The information about
the user must be transferred from the user’s home network to the serving network in
order to complete the process.
Table 1.1 Structure of an authentication vector.
Field
Description
RAND
Random Challenge
Ck
Cipher key
Ik
Integrity Key
AUTN
Authentication Token
XRES
Expected Response
The following security features are associated with the confidentiality of the data on
the network access link:
● Cipher algorithm agreement: the property that ensures that subscriber and serving
network can securely decide on the algorithm that should be subsequently used;
● Cipher key agreement: the property that subscriber and the serving network mutually
decide on the cipher key that should be subsequently used;
● Confidentiality of user data: the property that ensures that user data is protected on
the overhead, such that it cannot be overheard; and
● Confidentiality of signaling data: the property that ensures that signaling data cannot
be overheard on the radio interface.
The features provided to achieve integrity of data on the network access link are:
● Integrity algorithm agreement: the property that the subscriber and the serving network
can securely decide on the integrity algorithm that should be subsequently used;
● Integrity key agreement: the property that the subscriber and the serving network
agree on an integrity key that shall be subsequently used; and
● Data integrity and origin authentication of signaling data: the property that the
subscriber or serving network is able to verify that signaling has not been modified
later after it was sent by the sending entity, and that the origin of the signaling data
received is the valid one.
UMTS AKA is a security mechanism used to accomplish the authentication features
and all of the key agreement features described above. This mechanism is based on a
challenge/response authentication protocol implemented in such a way as to achieve
maximum compatibility with GSM’s subscriber authentication and key establishment
protocol, so that the transition from GSM to UMTS can be made. A challenge/response
protocol is a security measure used by one entity to verify the identity of another entity,
without revealing a secret password shared by the two entities involved [23]. Each entity
must prove to the other that it knows the password without actually revealing the
information that it has knowledge of the password.
The UMTS AKA process is started by a serving network after first registration by a
user, after a service request, after a location update request, after an attach request, and
after a detach request or connection re‐establishment request. The information about
the user must be transferred from the user’s home network to the serving network in
order to complete the process.
Table 1.1 Structure of an authentication vector.
Field
Description
RAND
Random Challenge
Ck
Cipher key
Ik
Integrity Key
AUTN
Authentication Token
XRES
Expected Response
