IP Library Granted Patent US 8,295,488
Granted Patent B2
US 8,295,488 · App. 11/186,901 · Granted Oct 23, 2012

Exchange of key material

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,295,488
App. No.
11/186,901
Granted
Oct 23, 2012
Kind
B2
Abstract

A communication network manages key material. A method generates and provides session keys from a security node to an access node for further propagation during handoff procedures, without requiring the security node to take part in the handoff procedures.

Claims (30)

1. A method for arranging security for a communications network, the method comprising:

deriving a first session key at a mobile terminal based upon a root key that is shared by the mobile terminal and a security node;

receiving a handoff initiation command and information relating to derivation of a second session key at the mobile terminal from a first access node;

requesting, via the mobile terminal, session context information from the security node if a second access node does not have the second session key for communication with the mobile terminal;

deriving, via the mobile terminal using a processor, the second session key based at least on the root key, the information relating to derivation of the second session key, and a part of identity information of the second access node;

encrypting at least a first part of a message with the first session key at the mobile terminal for transmission of the message to the second access node; and

encrypting at least a second part of the message with the second session key at the mobile terminal for transmission of the message to the second access node.

2. The method according to claim 1 , further comprising receiving information from the second access node, wherein the derivation of the second session key is based in part on the information received from the second access node.

3. The method of claim 1 , wherein deriving the second session key is based in part on a nonce for the access node.

4. A non-transitory computer-readable medium having computer-readable instructions stored thereon that, if executed by a mobile device, cause the mobile device to:

derive a first session key based upon a root key that is shared by the mobile terminal and a security node;

receive a handoff initiation command and information relating to derivation of a second session key from a first access node;

request session context information from the security node if a second access node does not have the second session key for communication with the mobile terminal;

derive the second session key based on at least the root key, information relating to derivation of the second session key, and a part of identity information of the second access node; and

encrypt at least a first part of a message with the first session key for transmission of the message to the second access node; and

encrypt at least a second part of the message with the second session key for transmission of the message to the second access node.

5. The non-transitory computer-readable medium of claim 4 , further causing the computing device to receive information from the second access node, wherein the derivation of the second session key is based in part on the information received from the second access node.

6. The non-transitory computer-readable medium of claim 4 , wherein deriving the second session key is based in part on a nonce for the access node.

7. A mobile terminal comprising:

an electronic processor configured to:

derive a first session key at a mobile terminal based upon a root key that is shared by the mobile terminal and a security node

a receiver configured to:

receive a handoff initiation command and information relating to derivation of a second session key from a first access node;

a transmitter configured to request session context information from the security node if a second access node does not have the second session key for communication with the mobile terminal;

a derivation component configured to derive the second session key based on at least the root key, the information relating to derivation of the second session key, and a part of identity information of the second access node; and

an encryptor configured to:

encrypt at least a first part of a message with the first session key for transmission of the message to the second access node; and

encrypt at least a second part of the message with the second session key for transmission of the message to the second access node.

8. The mobile terminal of claim 7 , wherein the receiver is configured to receive information from the second access node, and wherein the derivation component is further configured to derive the second session key based at least in part on the information received from the second access node.

9. The mobile terminal of claim 7 , wherein deriving the second session key is based in part on a nonce for the access node.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2023
From: MIND FUSION, LLC
To: THINKLOGIX, LLC
Reel/Frame 064357/0554 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2023
From: INTELLECTUAL VENTURES ASSETS 191 LLC
To: MIND FUSION, LLC
Reel/Frame 064270/0685 →
SECURITY INTEREST Recorded Mar 23, 2023
From: MIND FUSION, LLC
To: INTELLECTUAL VENTURES ASSETS 191 LLC
Reel/Frame 063155/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2023
From: INTELLECTUAL VENTURES I LLC
To: INTELLECTUAL VENTURES ASSETS 191 LLC
Reel/Frame 062705/0781 →
MERGER Recorded Jul 22, 2011
From: SPYDER NAVIGATIONS L.L.C.
To: INTELLECTUAL VENTURES I LLC
Reel/Frame 026637/0611 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2007
From: NOKIA CORPORATION
To: SPYDER NAVIGATIONS L.L.C.
Reel/Frame 019814/0846 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2005
From: FORSBERG, DAN; TARKKALA, LAURI
To: NOKIA CORPORATION
Reel/Frame 016806/0200 →