Generic key-decision mechanism for GAA

US8990897B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-8990897-B2
Application numberUS-201113239246-A
CountryUS
Kind codeB2
Filing dateSep 21, 2011
Priority dateApr 11, 2005
Publication dateMar 24, 2015
Grant dateMar 24, 2015

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method and apparatus provide generic mechanism for a network application server. A receiver receives a request from a user equipment to provide authentication information to a network application function. A determining unit determines a key of a generic authentication architecture to integrate additional network application servers by extending an existing standard for user security settings. A providing unit provides the authentication information to the network application function.

First claim

Opening claim text (preview).

What is claimed: 1. An apparatus comprising: a receiver unit configured to receive a request from a user equipment to provide authentication information to a network application function; a determiner unit configured to determine a key of a generic authentication architecture to integrate additional network application servers by extending an existing standard for user security settings, wherein determining the key includes determining from provided data a key type the network application function is required to use, the provided data being based, at least in part, on data indicating the key type included in the extended user security settings provided by a home subscriber server; and a provider unit configured to provide the authentication information to the network application function. 2. The apparatus as recited in claim 1 , further comprising: a second provider unit configured to provide a type of secure environment in the user equipment in the user security settings. 3. The apparatus as recited in claim 1 , further comprising: a second provider unit configured to provide first and second flag fields in the user security settings that are transported in an authorization header of a specification, wherein in the first flag field, a first derived key in integrated circuit based enhancements is used, and in the second flag field, a second derived key or a third derived key are used. 4. The apparatus as recited in claim 1 , further comprising: a second provider unit configured to provide a flag field indicative of whether a generic bootstrapping architecture with integrated circuit based enhancements enables a universal subscriber identity module, subscriber identity module, secure environment, or a subscriber identity module card. 5. A method comprising: sending, by a user equipment, a request to provide authentication information to a network application function, wherein the request initiates a determination of a key of a generic authentication architecture to integrate additional network application servers by extending an existing standard for user security settings, wherein the request further initiates the determination of, based on at least in part data indicating the key type included in the extended user security settings provided by a home subscriber server, a key type for use by the network application function. 6. An apparatus comprising: at least one processor; at least one memory including computer program code which when executed by the at least one processor is configured to at least send a request to provide authentication information to a network application function, wherein the request initiates a determination of a key of a generic authentication architecture to integrate additional network application servers by extending an existing standard for user security settings, wherein the request further initiates the determination of, based on at least in part data indicating the key type included in the extended user security settings provided by a home subscriber server, a key type for use by the network application function. 7. A non-transitory computer-readable medium including code, which when executed by a processor, provides operations comprising: sending, by a user equipment, a request to provide authentication information to a network application function, wherein the request initiates a determination of a key of a generic authentication architecture to integrate additional network application servers by extending an existing standard for user security settings, wherein the request further initiates the determination of, based on at least in part data indicating the key type included in the extended user security settings provided by a home subscriber server, a key type for use by the network application function.

Assignees

Inventors

Classifications

  • H04L63/062Primary

    for key distribution, e.g. centrally by trusted party (cryptographic mechanisms or cryptographic arrangements for key distribution involving a central third party H04L9/0819) · CPC title

  • Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title

  • Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity · CPC title

  • H04L9/32Primary

    including means for verifying the identity or authority of a user of the system {or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials} · CPC title

  • Counter-measures against attacks; Protection against rogue devices · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US8990897B2 cover?
A method and apparatus provide generic mechanism for a network application server. A receiver receives a request from a user equipment to provide authentication information to a network application function. A determining unit determines a key of a generic authentication architecture to integrate additional network application servers by extending an existing standard for user security settings…
Who is the assignee on this patent?
Holtmanns Silke, Laitinen Pekka, Nokia Corp
What technology area does this patent fall under?
Primary CPC classification H04L63/062. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 24 2015 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).