Methods, apparatuses and computer program products enabling to improve handover security in mobile communication networks

US9817720B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9817720-B2
Application numberUS-201214438956-A
CountryUS
Kind codeB2
Filing dateOct 29, 2012
Priority dateOct 29, 2012
Publication dateNov 14, 2017
Grant dateNov 14, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An apparatus comprises a memory unit, and a control unit connected to the memory unit. The apparatus can be configured to interface at least one access node; the control unit is configured to derive at least one local level security key within an established security context for a terminal, forward the derived local security key to at least one access node, and detect failures in a handover for a terminal being served by a first access node towards a second access node. The failures concern the interface between the apparatus and the second access node. In response to a verified trigger condition, the control unit can re-adjust local level security keys with keys maintained at the terminal within the established security context.

First claim

Opening claim text (preview).

What is claimed is: 1. An apparatus comprising: a memory unit; and a processor connected to the memory unit, wherein the apparatus is configured to interface with at least one access node, and wherein the processor and the memory unit are configured at least to: process one or more higher level security keys received from a network entity to derive at least one local level security key within an established security context for a terminal; forward said derived at least one local level security key to the at least one access node; and invoke a context modification procedure to re-adjust the at least one local level security key with at least one local level security key maintained at the terminal within the established security context, wherein a re-keying procedure for the at least one access node is performed in which a network access stratum security mode command procedure is initiated, and an updated network access stratum count parameter of a most recent network access stratum security mode command message is obtained, with the updated network access stratum parameter being used to derive a new key for the at least one access node computed based on an existing higher level security key, the new key being provided to the at least one access node for a radio resource control reconfiguration performed between the at least one access node and a terminal, and the re-keying procedure being performed without performing an Authentication and Key Agreement procedure. 2. The apparatus according to claim 1 , wherein the at least one local level security key is a next hop (NH) key and a next hop chaining counter (NCC) being used as a key. 3. The apparatus according to claim 1 , wherein a trigger condition is verified by the apparatus, and wherein the trigger condition represents a number of past failed handovers concerning the interface between the apparatus and a second access node. 4. The apparatus according to claim 3 , wherein the number of past failed handovers depends on a maximum number of a next hop chaining counter (NCC) as at least one of the local level security keys. 5. The apparatus according to claim 1 , wherein the context modification procedure invoked is a terminal context modification procedure associated with the terminal to be handed over. 6. The apparatus according to claim 5 , wherein the processor and the memory unit are configured at least to: compose a terminal context modification request message comprising a latest one of the at least one local level security key, wherein a next hop chaining counter (NCC) as at least one of the local level security key is included in a distinct information element; and forward the distinct information element to a first access node. 7. The apparatus according to claim 1 , wherein the context modification procedure invoked is a network access stratum security mode procedure associated with the terminal to be handed over. 8. The apparatus according to claim 7 , wherein the control unit and the processor are further configured at least to: initiate a new network access stratum security mode procedure based on an evolved key set identifier (eKSI) and associated algorithms; obtain, based on the new network access stratum security mode procedure, the updated network access stratum parameter for such procedure; process the obtained updated parameter together with an intermediate base key of an access security management entity (K_ASME) to derive a fresh access node base key (K_eNB) as the at least one of the local level security key; and forward the fresh access node base key to the access node. 9. A method comprising: processing one or more higher level security keys received from a network entity to derive at least one local level security key within an established security context for a terminal; forwarding said derived at least one local level security key to at least one access node; and invoking a context modification procedure to re-adjust the at least one local level security key with at least one local level security key maintained at the terminal within the established security context, wherein a re-keying procedure for the at least one access node is performed in which a network access stratum security mode command procedure is initiated, and an updated network access stratum count parameter of a most recent network access stratum security mode command message is obtained, with the updated network access stratum parameter being used to derive a new key for the at least one access node computed based on an existing higher level security key, the new key being provided to the at least one access node for a radio resource control reconfiguration performed between the at least one access node and a terminal, and the re-keying procedure being performed without performing an Authentication and Key Agreement procedure. 10. The method according to claim 9 , wherein the at least one local level security key is a next hop (NH) key and a next hop chaining counter (NCC) being used as a key. 11. The method according to claim 9 , wherein a trigger condition is verified by the another network entity, and wherein the trigger condition represents a number of past failed handovers concerning the interface between another network entity and a second access node. 12. The method according to claim 11 , wherein the number of past failed handovers depends on a maximum number of a next hop chaining counter (NCC) as at least one of the local level security keys. 13. The method according to claim 9 , wherein the context modification procedure invoked is a terminal context modification procedure associated with the terminal to be handed over. 14. The method according to claim 13 further comprising: composing a terminal context modification request message comprising a latest one of the at least one local level security key, wherein a next hop chaining counter (NCC) as at least one of the local level security key is included in a distinct information element; and forwarding the distinct information element to a first access node. 15. The method according to claim 9 , wherein the context modification procedure invoked is a network access stratum security mode procedure associated with the terminal to be handed over. 16. The method according to claim 15 , further comprising: initiating a new network access stratum security mode procedure based on an evolved key set identifier (eKSI) and associated algorithms; obtaining, based on the new network access stratum security mode procedure, the updated network access stratum parameter for such procedure; processing the obtained updated parameter together with an intermediate base key of an access security management entity (K_ASME) to derive a fresh access node base key (K_eNB) as the at least one of the local level security key; and forwarding the fresh access node base key to the access node. 17. A computer program product embodied on a non-transitory computer-readable medium, said product comprising computer-executable components which, when the program is run on a computer, are configured to perform the method steps according to claim 9 . 18. A system comprising an access node, a user equipment, and an apparatus, the apparatus comprising: a memory unit; and a processor connected to the memory unit, wherein the apparatus is configured to interface with at least one access node, and wherein the processor and the memory unit are configured at least to: process one or more higher level security keys received from a network entity to derive at least one local

Assignees

Inventors

Classifications

  • of security context information · CPC title

  • Monitoring of systems including the internet · CPC title

  • Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title

  • Saving, restoring, recovering or retrying · CPC title

  • Reselecting an access point · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9817720B2 cover?
An apparatus comprises a memory unit, and a control unit connected to the memory unit. The apparatus can be configured to interface at least one access node; the control unit is configured to derive at least one local level security key within an established security context for a terminal, forward the derived local security key to at least one access node, and detect failures in a handover for…
Who is the assignee on this patent?
Nokia Solutions & Networks Oy
What technology area does this patent fall under?
Primary CPC classification G06F11/1402. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Nov 14 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).