EPS Authentication and Key Agreement
Dan Forsberg, Günther Horn, Wolf-Dietrich Moeller, Valtteri Niemi · 2010
This chapter describes how users are identified and authenticated for network access in Evolved Packet System (EPS). It introduces the means to identify subscribers and terminals, and the mechanisms to protect the related identities. The chapter then provides a detailed presentation of EPS AKA, the protocol used in EPS to authenticate subscribers and agree a local master key. Further keys are then derived from this local master key to protect signaling and user traffic over various interfaces between the UE and the network. The complete EPS key hierarchies resulting from the derivation process are described. In addition to keys, other security-related parameters need to be shared between two entities running a security protocol between them. These parameters, together with the keys, form a security context, and the various security contexts used in EPS are described. Controlled Vocabulary Terms communication system security; identification technology; message authentication