IP Library Granted Patent US 9,166,799
Granted Patent B2
US 9,166,799 · App. 11/968,088 · Granted Oct 20, 2015

IMS security for femtocells

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,166,799
App. No.
11/968,088
Granted
Oct 20, 2015
Kind
B2
Abstract

A mobile station can be authenticated by, for example, sending a challenge to a mobile station, and receiving a first authentication response from the mobile station through a wireless link, the first authentication response being generated based on the challenge and an authentication key stored at the mobile station. A second authentication response is generated based on the first authentication response. The second authentication response is provided to an IMS network for authenticating the mobile station to enable the mobile station to access the IMS network. In some examples, an authentication response of the mobile station is carried in an SIP message sent from the femtocell to a server that can authenticate the mobile station or forward the authentication response to another server that can authenticate the mobile station. Authentication of the mobile station can be performed as an integrated part of or separate from a registration process.

Claims (40)

1. A method comprising:

sending a challenge from a first device to a mobile station, the first device operating as a bridge between the mobile station and an IP multimedia subsystem (IMS) network that includes a home subscriber server, in which the IMS network is configured to use an authentication protocol to establish security associations with mobile stations, and the mobile station is not compatible with the authentication protocol used by the IMS network;

at the first device, receiving a first authentication response from the mobile station through a wireless link, generating a secret key based on the first authentication response, and generating a second authentication response based on the secret key, in which the first authentication response is generated based on the challenge and an authentication key stored at the mobile station; and

providing the second authentication response to the IMS network for authenticating the mobile station to enable the mobile station to access the IMS network, in which the second authentication response is generated by the first device based on the secret key that is generated by the first device based on the first authentication response provided by the mobile station.

2. The method of claim 1 wherein the network comprises at least one of 3GPP IP multimedia subsystem (IMS) network and 3GPP2 IMS network.

3. The method of claim 1 wherein the secret key comprises an AKA (authentication and key agreement) key.

4. The method of claim 1 wherein generating a secret key comprises generating the secret key based on the first authentication response and a random number.

5. The method of claim 1 , comprising generating a cipher key (CK) and an integrity key (IK) from the secret key.

6. The method of claim 1 wherein generating the second authentication response comprises generating the second authentication response according to hypertext transfer protocol (HTTP) digest authentication using authentication and key agreement (AKA).

7. The method of claim 1 wherein the mobile station is compatible with an authentication process based on CAVE (cellular authentication and voice encryption) algorithm.

8. The method of claim 1 wherein the mobile station generates a signaling message encryption key (SMEKEY) and a private long code mask (PLCM) internally but does not transmit the SMEKEY and PLCM wirelessly.

9. The method of claim 1 wherein the mobile station is not compatible with an authentication process based on AKA (authentication and key agreement) protocol.

10. The method of claim 1 wherein sending a challenge from a first device to a mobile station comprises sending, from a femtocell, the challenge to the mobile station.

11. The method of claim 1 wherein the challenge is derived from a random challenge provided by the network.

12. The method of claim 1 wherein the network uses session initiation protocol (SIP) authentication.

13. The method of claim 1 wherein the mobile station comprises at least one of a 1xRTT, UMTS, and GSM mobile phone.

14. The method of claim 1 in which the IMS network uses authentication and key agreement (AKA) protocol to authenticate mobile stations, and the mobile station is not compatible with the authentication and key agreement protocol.

15. A method comprising:

registering a femtocell with a network using a session initiation protocol (SIP) authentication process;

sending a challenge from the femtocell to the mobile station;

at the femtocell, receiving a first authentication response to the challenge wirelessly from the mobile station;

at the femtocell, generating a secret key based on the first authentication response, and generating a second authentication response based on the secret key; and

authenticating the mobile station by sending the second authentication response in an SIP message from the femtocell to a server, in which the server is capable of authenticating the mobile station based on the authentication response or forwards the authentication response to another server that is capable of authenticating the mobile station.

16. The method of claim 15 , comprising assigning a femtocell identifier to the mobile station.

17. The method of claim 16 , comprising associating the femtocell identifier with a mobile identifier of the mobile station.

18. The method of claim 15 wherein registering a femtocell with a network comprises registering the femtocell with an IP multimedia subsystem (IMS) network.

19. The method of claim 18 wherein registering the femtocell with the IMS network comprises authenticating the femtocell using one of a plurality of generic IMS credentials associated with the femtocell, and each of the generic IMS credentials can be used to authenticate an IMS/SIP session initiated from the femtocell.

20. The method of claim 15 , comprising using at least one of a home subscriber server (HSS) and a home location register/authentication center (HLR/AC) to authenticate the mobile station.

21. The method of claim 15 wherein the mobile station sends the authentication response to the femtocell in a 1xRTT session.

22. The method of claim 21 , comprising tying information sent from the mobile station in the 1xRTT session with an SIP session initiated by the femtocell during the SIP authentication process.

23. The method of claim 15 , comprising connecting the femtocell to multiple mobile stations and assigning different femtocell identifiers to different mobile stations.

24. The method of claim 23 , comprising associating the femtocell identifiers with corresponding mobile identifiers of the mobile stations.

25. The method of claim 24 , comprising establishing communication links between multiple femtocells and an IMS network, each femtocell communicating with one or more mobile stations, and routing calls addressed to particular mobile stations identified by the mobile identifiers to corresponding femtocells using the femtocell identifiers associated with the mobile identifiers.

26. The method of claim 25 wherein the mobile identifiers comprise at least one of mobile identification numbers and mobile directory numbers.

27. A method of re-authenticating a mobile station, the method comprising:

after a mobile station has already registered with an IP multimedia subsystem (IMS) network, receiving, at a femtocell, a first authentication response wirelessly from the mobile station without re-registering the mobile station with the IMS network, in which the mobile station is not configured to send session initiation protocol (SIP) registration messages;

sending, from the femtocell, a first SIP message to a server, the first SIP message including a second authentication response that is derived from the first authentication response, in which the second authentication response is generated at the femtocell, and the server is capable of authenticating the mobile station based on the second authentication response or forwards the second authentication response to another server that is capable of authenticating the mobile station; and

receiving a second SIP message from the server indicating that the mobile station has been authenticated.

28. The method of claim 27 wherein the first SIP message comprises at least one of an SIP INVITE request, an SIP MESSAGE request, an SIP INFO request, and an SIP 18x response.

29. The method of claim 27 wherein sending an SIP message comprises sending an SIP message having at least one of (a) a multipurpose internet mail extensions (MIME) payload that includes the authentication response and (b) an SIP header that includes the authentication response.

Assignments (14)
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
PARTIAL TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded May 23, 2022
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 060163/0662 →
PARTIAL RELEASE OF TERM LOAN SECURITY INTEREST Recorded May 16, 2022
From: JPMORGAN CHASE BANK, N.A.
To: COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC
Reel/Frame 060073/0399 →
PARTIAL RELEASE OF ABL SECURITY INTEREST Recorded May 16, 2022
From: JPMORGAN CHASE BANK, N.A.
To: COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC
Reel/Frame 060073/0483 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2022
From: COMMSCOPE TECHNOLOGIES LLC
To: STRONG FORCE IOT PORTFOLIO 2016, LLC
Reel/Frame 059559/0172 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049892/0051 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
RELEASE OF SECURITY INTEREST Recorded Apr 9, 2019
From: JPMORGAN CHASE BANK, N.A.
To: REDWOOD SYSTEMS, INC.; ALLEN TELECOM LLC; ANDREW LLC; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 048840/0001 →
RELEASE OF SECURITY INTEREST Recorded Apr 9, 2019
From: JPMORGAN CHASE BANK, N.A.
To: REDWOOD SYSTEMS, INC.; ALLEN TELECOM LLC; ANDREW LLC; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 049260/0001 →
PATENT SECURITY AGREEMENT (TERM) Recorded Dec 10, 2015
From: COMMSCOPE TECHNOLOGIES LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 037268/0488 →
PATENT SECURITY AGREEMENT (ABL) Recorded Dec 10, 2015
From: COMMSCOPE TECHNOLOGIES LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 037268/0524 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 22, 2015
From: AIRVANA LP
To: COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 036927/0544 →