Security solution for integrating a WiFi radio interface in LTE access network

US9414223B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9414223-B2
Application numberUS-201213399293-A
CountryUS
Kind codeB2
Filing dateFeb 17, 2012
Priority dateFeb 17, 2012
Publication dateAug 9, 2016
Grant dateAug 9, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for security for inter-RAT carrier aggregation is disclosed. The method includes encrypting a message using an encryption technique for a first RAT. The method also includes sending, to a UE, at least a portion of the encrypted message using a different, second RAT. Sending using the second RAT does not further encrypt the at least a portion of the encrypted message. The method further includes receiving the at least a portion of the message encrypted using the first RAT protocol. Receiving uses the second, different RAT. The method also includes decrypting the at least a portion of the message using the first RAT protocol. Apparatus and computer readable media are also described.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: encrypting a message using an encryption technique for a first radio access technology; sending, to a user equipment, at least a portion of the encrypted message using a different, second radio access technology, where sending using the second radio access technology does not further encrypt the at least a portion of the encrypted message; and filtering incoming transmissions on the second radio access technology using a medium access control address of the second radio access technology; wherein the method further comprises sending, to the user equipment using the first radio access technology, instructions for the user equipment to configure for operation on the second radio access technology, wherein the instructions include an identification of a second radio access technology access point, wherein the encrypted message is also integrity protected, and wherein the message is configured to discard a packet data unit and an integrity verification failure identification is indicated when an integrity verification fails; where the first radio access technology is a Universal Terrestrial Radio Access Network (UTRAN) packet data convergence protocol and the second radio access technology is a wireless local area network, wherein the encryption of the message comprises only a single Long Term Evolution (LTE) encrypted and wherein the sending of the at least a portion of the LTE encrypted message using the wireless local area network does not further encrypt the at least a portion of the LTE encrypted message. 2. The method of claim 1 , where the at least a portion of the encrypted message is a first portion, the method further comprising: splitting the encrypted message into the first portion and a second portion; and sending the second portion of the encrypted message using the first radio access technology. 3. The method of claim 1 , where encrypting the message occurs at a first protocol layer, and sending the at least a portion of the encrypted message occurs at a lower second protocol layer. 4. The method of claim 1 , further comprising: receiving, from the user equipment using the first radio access technology, a medium access control address of the user equipment on the second radio access technology; adding the medium access control address to an access list for the second radio access technology access point; and removing the medium access control address from the access list in response to a lack of activity for the user equipment on the second radio access technology. 5. A method comprising: receiving at least a portion of a message encrypted using a first radio access technology protocol, where receiving uses a second, different radio access technology; decrypting the at least a portion of the message using the first radio access technology protocol; and filtering incoming transmissions on the second radio access technology using a medium access control address of the second radio access technology; wherein the method further comprises receiving, using the first radio access technology protocol, instructions to configure a user equipment for operation on the second radio access technology, wherein the instructions include an identification of a second radio access technology access point, wherein the encrypted message is also integrity protected, and wherein the message is configured to discard a packet data unit and an integrity verification failure identification is indicated when an integrity verification fails; where the first radio access technology is a Universal Terrestrial Radio Access Network (UTRAN) packet data convergence protocol and the second radio access technology is a wireless local area network, wherein the encryption of the message comprises only a single Long Term Evolution (LTE) encryption, and wherein the sending of the at least a portion of the LTE encrypted message using the wireless local area network does not further encrypt the at least a portion of the LTE encrypted message. 6. The method of claim 5 , further comprising: binding medium access control address of the second radio access technology to a first radio access technology identity. 7. The method of claim 5 , where decrypting the message occurs at a first protocol layer, and the method further comprises sending the decrypted message to a higher, second protocol layer, wherein the first protocol layer comprises a packet data convergence protocol (PDCP) layer, wherein the method further comprises determining whether the decrypted message passes a cyclic redundancy check at the second protocol layer, and determining whether the decrypted message passes the integrity verification at the second protocol layer. 8. The method of claim 5 , where the at least a portion of the encrypted message is a first portion, the method further comprising: receiving the second portion of the encrypted message using the first radio access technology; decrypting the second portion of the message using the first radio access technology protocol; and combining the decrypted first portion and the decrypted second portion to generate a decrypted message. 9. An apparatus, comprising at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to perform at least the following: to encrypt a message using an encryption technique for a first radio access technology; to send, to a user equipment, at least a portion of the encrypted message using a different, second radio access technology, where sending using the second radio access technology does not further encrypt the at least a portion of the encrypted message; and to filter incoming transmissions on the second radio access technology using a medium access control address of the second radio access technology; wherein the at least one memory and the computer program code are further configured to cause the apparatus to send, to the user equipment using the first radio access technology, instructions for the user equipment to configure for operation on the second radio access technology, wherein the instructions include an identification of a second radio access technology access point, wherein the encrypted message is also integrity protected, and wherein the message is configured to discard a packet data unit and an integrity verification failure identification is indicated when an integrity verification fails; where the first radio access technology is a Universal Terrestrial Radio Access Network (UTRAN) packet data convergence protocol and the second radio access technology is a wireless local area network, wherein the encryption of the message comprises only a single Long Term Evolution (LTE) encryption, and wherein the sending of the at least a portion of the LTE encrypted message using the wireless local area network does not further encrypt the at least a portion of the LTE encrypted message. 10. The apparatus of claim 9 , where the at least a portion of the encrypted message is a first portion, and the at least one memory and the computer program code are further configured to cause the apparatus: to split the encrypted message into the first portion and a second portion; and to send the second portion of the encrypted message using the first radio access technology. 11. The apparatus of claim 9 , where encrypting the message occurs at a first protocol layer, and sending the at least a portion of the encrypted message occurs at a lower second protocol layer. 12. The apparatus of claim 9 , where the at least one memory and the computer

Assignees

Inventors

Classifications

  • Data link layer protocols · CPC title

  • H04L63/205Primary

    involving negotiation or determination of the one or more network security mechanisms to be used, e.g. by negotiation between the client and the server or between peers or by selection according to the capabilities of the entities involved (negotiation of communication capabilities H04L69/24) · CPC title

  • WLAN [Wireless Local Area Networks] · CPC title

  • H04W12/02Primary

    Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII] · CPC title

  • Protecting confidentiality, e.g. by encryption · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9414223B2 cover?
A method for security for inter-RAT carrier aggregation is disclosed. The method includes encrypting a message using an encryption technique for a first RAT. The method also includes sending, to a UE, at least a portion of the encrypted message using a different, second RAT. Sending using the second RAT does not further encrypt the at least a portion of the encrypted message. The method further…
Who is the assignee on this patent?
Ginzboorg Philip, Malkamaki Esa M, Rantala Enrico, and 3 more
What technology area does this patent fall under?
Primary CPC classification H04L63/205. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 09 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).