Journal of Zhejiang University SCIENCE C 2011 Vol.12 No.5 P.371-378


A three-level authenticated conference key establishment protocol for UMTS networks

Author(s):  Chung-Fu Lu, Tzong-Chen Wu, Chien-Lung Hsu

Affiliation(s):  Department of Information Management, National Taiwan University of Science and Technology, Taiwan 106, Taipei, Department of Computer and Communication Engineering, Taipei College of Maritime Technology, Taiwan 111, Taipei, Department of Information Management, Chang Gung University, Taiwan 333, Taoyuan

Corresponding email(s):   clhsu@mail.cgu.edu.tw

Key Words:  Universal Mobile Telecommunications System (UMTS), Three-level, Conference key establishment, Secure group communication, Authentication

A conference key establishment protocol allows a group of conferees to agree on a secret key shared among them for secure group communication. This paper proposes a three-level conference key establishment protocol based on the universal Mobile Telecommunications System (UMTS) framework to establish a group-level key, home location register (HLR) level keys, and visitor location register (VLR) level keys simultaneously for a group of conferees. The group-level key is used to secure the communications for all conferees, the HLR-level key is for those within the same HLR domain, and the VLR-level key is for those within the same VLR domain. The group-level key can be used for securing inter-domain group-oriented applications such as commercial remote conferencing systems. The HLR- and VLR-level keys can be used for securing intra-domain subgroup applications (e.g., location-based or context-aware services) and dynamic key updating. Since our proposed protocol exploits existing UMTS security functions and the exclusive-or operation, it is compatible with UMTS architecture. This means that it is fast and easy to implement on the existing UMTS architecture. Furthermore, the proposed protocol has low computational complexities and can provide cost effectiveness, load-amortization, scalability, user authentication, key establishment, key confirmation, key updating, and lawful interception.

