IP Library Granted Patent US 12707258
Granted Patent B2
US 12707258 · App. 18/197,828 · Granted Aug 11, 2026

Methods supporting authentication in wireless communication networks and related network nodes and wireless terminals

Inventor: Monica Wifvesson (Lund, SE)
Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
H04W12/041H04L63/08H04L63/162H04W8/08H04W12/0433H04W12/06H04W36/0038
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12707258
App. No.
18/197,828
Granted
Aug 11, 2026
Kind
B2
Abstract

Methods in a wireless communication network may include providing a first authentication key, and deriving a second authentication key based on the first authentication key, with the second authentication key being associated with the wireless terminal. Responsive to deriving the second authentication key, a key response message may be transmitted including the second authentication key and/or an EAP-Finish/Re-auth message. Some other methods in a wireless communication network may include receiving a key response message including a core network mobility management authentication key and an EAP-Finish/Re-auth message. Responsive to receiving the key response message, the network may initiate transmission of an EAP-Finish/Re-auth message and/or a freshness parameter used to derive the core network mobility management authentication key from the wireless communication network to the wireless terminal responsive to the key response message. Related wireless terminal methods are also discussed.

Claims (60)

1 . A method in a wireless communication network supporting communications with a wireless terminal, the method comprising:

a security function (SF) receiving, from a core network mobility management node (CN-MMN), a key request message comprising an indication that the wireless terminal supports an Extensible Authentication Protocol (EAP) Re-authentication Protocol (ERP);

the SF obtaining a first authentication key (rMSK);

the SF deriving a second authentication key (new-K-cn-mm) based on the first authentication key, wherein the second authentication key is associated with the wireless terminal;

after deriving the second authentication key, the SF transmitting to the CN-MMN a key response message that is responsive to the key request message, wherein the key response message comprises the second authentication key (new K-cn-mm) and an Extensible Authentication Protocol Finish/Re-authentication (EAP-Finish/Re-auth) message;

the CN-MMN receiving from the SF the key response message comprising the EAP-Finish/Re-auth message; and

after receiving from the SF the key response message comprising the EAP-Finish/Re-auth message, the CN-MMN transmitting to the wireless terminal a security mode command (SMC) message comprising the EAP-Finish/Re-auth message that was included in the key response message received from the SF.

2 . The method of claim 1 , wherein

the method further comprises, after receiving the key request message from the CN-MMN and prior to transmitting the key response message to the CN-MMN:

the SF transmitting to the wireless terminal an ERP trigger message for triggering an ERP exchange; and

after transmitting the ERP trigger message to the wireless terminal, receiving an ERP initiation message transmitted by the wireless terminal, wherein the ERP initiation message initiates the ERP exchange.

3 . The method of claim 1 , wherein

the SMC message is transmitted to the wireless terminal without the second authentication key (new K-cn-mm).

4 . The method of claim 1 , wherein

the key response message includes a freshness parameter used to derive the second authentication key.

5 . The method of claim 4 , wherein

the EAP-Finish/Re-auth message is transmitted to the wireless terminal with the freshness parameter used to derive the second authentication key.

6 . The method of claim 1 , wherein

the method further comprises, before transmitting the key request message, the CN-MMN receives a request message transmitted by the wireless terminal,

the request message transmitted by the wireless terminal comprises information indicating that the wireless terminal supports ERP, and

the method further comprises, after transmitting the SMC message to the wireless terminal, the CN-MMN transmits to the wireless terminal a response message response to the request message transmitted by the wireless terminals.

7 . The method of claim 1 , wherein

the key request message is responsive to a request message from the wireless terminal, wherein the request message includes the indication that the wireless terminal supports the ERP.

8 . The method of claim 7 , wherein

an EAP-Finish/Re-auth message and the indication that the wireless terminal supports the ERP are transmitted to the wireless terminal responsive to the key response message.

9 . The method of claim 7 , wherein

the EAP-Finish/Re-auth message is transmitted to the wireless terminal responsive to the key response message.

10 . The method of claim 7 , wherein

the indication that the wireless terminal supports the ERP is transmitted to the wireless terminal responsive to the key response message.

11 . A node (SEAF) of a wireless communication network, the node comprising:

a network interface adapted to provide communication with other nodes of the wireless communication network; and

a processor coupled to the network interface, wherein the processor is configured to transmit and/or receive communications through the network interface, and wherein the processor is configured to cause the node to perform a method comprising:

receiving, from a core network mobility management node (CN-MMN), a key request message comprising an indication that the wireless terminal supports an Extensible Authentication Protocol (EAP) Re-authentication Protocol (ERP);

obtaining a first authentication key (rMSK);

deriving a second authentication key (new-K-cn-mm) based on the first authentication key, wherein the second authentication key is associated with the wireless terminal; and

after deriving the second authentication key, transmitting to the CN-MMN a key response message that is responsive to the key request message, wherein the key response message comprises the second authentication key (new K-cn-mm) and an Extensible Authentication Protocol Finish/Re-authentication (EAP-Finish/Re-auth) message, wherein the CN-MMN is configured to:

receive from the key response message comprising the EAP-Finish/Re-auth message; and

after receiving the key response message comprising the EAP-Finish/Re-auth message, transmit to the wireless terminal a security mode command (SMC) message comprising the EAP-Finish/Re-auth message that was included in the key response message.

12 . The node of claim 11 , wherein

the method further comprises, after receiving the key request message from the CN-MMN and prior to transmitting the key response message to the CN-MMN:

the SF transmitting to the wireless terminal an ERP trigger message for triggering an ERP exchange; and

after transmitting the ERP trigger message to the wireless terminal, receiving an ERP initiation message transmitted by the wireless terminal, wherein the ERP initiation message initiates the ERP exchange.

13 . The node of claim 11 , wherein

the SMC message is transmitted to the wireless terminal without the second authentication key (new K-cn-mm).

14 . The node of claim 11 , wherein

the key response message includes a freshness parameter used to derive the second authentication key.

15 . The node of claim 14 , wherein

the EAP-Finish/Re-auth message is transmitted to the wireless terminal with the freshness parameter used to derive the second authentication key.

16 . The node of claim 11 , wherein

the method further comprises, before transmitting the key request message, the CN-MMN receives a request message transmitted by the wireless terminal,

the request message transmitted by the wireless terminal comprises information indicating that the wireless terminal supports ERP, and

the method further comprises, after transmitting the SMC message to the wireless terminal, the CN-MMN transmits to the wireless terminal a response message response to the request message transmitted by the wireless terminals.

17 . The node of claim 11 , wherein

the key request message is responsive to a request message from the wireless terminal, wherein the request message includes the indication that the wireless terminal supports the ERP.

18 . The node of claim 17 , wherein

an EAP-Finish/Re-auth message and the indication that the wireless terminal supports the ERP are transmitted to the wireless terminal responsive to the key response message.

19 . The node of claim 17 , wherein

the EAP-Finish/Re-auth message is transmitted to the wireless terminal responsive to the key response message.

20 . The node of claim 17 , wherein

the indication that the wireless terminal supports the ERP is transmitted to the wireless terminal responsive to the key response message.