Method and system for providing security from a radio access network

US9986432B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9986432-B2
Application numberUS-201415105439-A
CountryUS
Kind codeB2
Filing dateDec 23, 2014
Priority dateDec 23, 2013
Publication dateMay 29, 2018
Grant dateMay 29, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The disclosure relates to a security method and system in a telecommunications network comprising a radio access network system and a core network system. The radio access network system is configured to provide a wireless radio interface for at least one user device, wherein a shared secret key is stored in both the user device and the core network system. At least one vector is received from the core network system comprising one or more values derived from the shared secret key. At least one of an authentication procedure and a key agreement procedure is performed in the radio access network system for the user device over the wireless radio interface using the one or more values of the received vector for establishing a connection between the user device and the radio access network system.

First claim

Opening claim text (preview).

The invention claimed is: 1. A security method in a telecommunications network comprising a radio access network (RAN) system and a core network system, wherein the radio access network system is configured to provide a wireless radio interface for at least one user device, wherein a shared secret key is stored in both the user device and the core network system, the method carried out in the radio access network system and comprising: receiving from the core network system, at least one vector comprising one or more values derived from the shared secret key; storing the at least one vector in the radio access network; and after storing the at least one vector, performing at least one of an authentication procedure and a key agreement procedure for the user device over the wireless radio interface using the one or more values of the received vector for establishing a connection between the user device and the radio access network system, wherein the core network system pre-stores a RAN only indication associated with the user device to transmit the vector to the radio access network system, the method further comprising only receiving the at least one vector in the radio access network system from the core network system for a user device for which the RAN only indication has been pre-stored. 2. The method according to claim 1 , further comprising the detecting an inability to handle the at least one of the authentication procedure and the key agreement procedure from the core network system, wherein receiving the vector is performed prior to detecting the inability and performing the authentication procedure and/or key agreement procedure using the one or more values of the received vector is performed after detecting the inability. 3. The method according to claim 1 , further comprising storing at least one communication identifier in the radio access network system, the communication identifier enabling a communication service to be established for the user device. 4. The method according claim 1 , further comprising: periodically receiving the vector from the core network system. 5. The method according to claim 1 , wherein the radio access network system comprises at least a first node and a second node, communicatively connected to the first node, the method further comprising: receiving a request for establishing a connection at the first node in the radio access network system; and performing the at least one of the authentication procedure and the key agreement procedure at the second node in the radio access network system. 6. The method according to claim 5 , further comprising: receiving a location indication at the first node in the request for establishing a connection, the location indication indicating that the vector is available at the second node. 7. The method according to claim 1 , further comprising: receiving the vector in a trusted node in the radio access network system. 8. The method according to claim 1 , further comprising refreshing one or more vectors in the radio access network system for performing the at least one of the authentication procedure and the key agreement procedure. 9. The method according claim 1 , further comprising: transmitting a RAN-only indication to the user device that the radio access network system performs the at least one of the authentication procedure and the key agreement procedure for obtaining one or more services from the radio access network system. 10. The method according to claim 5 , further comprising: recording in a third node of the radio access network system that the vector is available at the second node and informing the first node by the third node that the vector is available at the second node. 11. The method according to claim 5 , further comprising: broadcasting a request from the first node in the radio access network system, the request identifying the user device for which the vector is sought. 12. The method according to claim 5 , further comprising: transmitting a location indication from the second node to the first node and further to the user device, the location indication indicating that the vector is available at the second node. 13. The method according to claim 1 , further comprising: transmitting a signalling message to the user device indicating that one or more values of the vector are non-operable for performing the authentication procedure and/or the key agreement procedure when the core network system is able to perform the authentication procedure and the key agreement procedure. 14. A non-transitory computer readable medium having instructions stored thereon that, when executed by one or more processors of a radio access network system, cause the radio access network system to carry out operations for security in a telecommunications network, wherein the telecommunications network comprises the radio access network system and a core network system, wherein the radio access network system is configured to provide a wireless radio interface for at least one user device, wherein a shared secret key is stored in both the user device and the core network system, and wherein the operations include: receiving from the core network system, at least one vector comprising one or more values derived from the shared secret key; storing the at least one vector in the radio access network; and after storing the at least one vector, performing at least one of an authentication procedure and a key agreement procedure for the user device over the wireless radio interface using the one or more values of the received vector for establishing a connection between the user device and the radio access network system, wherein the core network system pre-stores a RAN only indication associated with the user device to transmit the vector to the radio access network system, the method further comprising only receiving the at least one vector in the radio access network system from the core network system for a user device for which the RAN only indication has been pre-stored. 15. A radio access network system comprising: one or more network nodes providing a wireless radio interface for at least one user device and configured to connect to a core network system, wherein, in operation, a shared secret key is stored in both the user device and the core network system; a receiver configured for receiving from the core network system at least one vector comprising one or more values derived from the shared secret key; a processor configured for performing at least one of an authentication procedure and a key agreement procedure for the user device over the wireless radio interface using the one or more values of the received vector for establishing a connection between the user device and the radio access network system; and one or more processors and memory storing instructions that, when executed by the one or more processors, cause the radio access network system to carry out operations including: receiving from the core network system, at least one vector comprising one or more values derived from the shared secret key; storing the at least one vector in the radio access network; and after storing the at least one vector, performing at least one of an authentication procedure and a key agreement procedure for the user device over the wireless radio interface using the one or more values of the received vector for establishing a connection between the user device and the radio access network system, wherein the core network system pre-stores a RAN only indication associated with the user device to transmit the vector

Assignees

Inventors

Classifications

  • Access point devices · CPC title

  • by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity · CPC title

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • G06F16/22Primary

    Indexing; Data structures therefor; Storage structures · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9986432B2 cover?
The disclosure relates to a security method and system in a telecommunications network comprising a radio access network system and a core network system. The radio access network system is configured to provide a wireless radio interface for at least one user device, wherein a shared secret key is stored in both the user device and the core network system. At least one vector is received from …
Who is the assignee on this patent?
Koninklijke Kpn Nv, TNO, Nederlandse Organisatie Voor Toegepast Natuurwetenschappelijk Onderzgek Tno
What technology area does this patent fall under?
Primary CPC classification G06F16/22. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue May 29 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).