IP Library Granted Patent US 9,202,055
Granted Patent B2
US 9,202,055 · App. 13/447,571 · Granted Dec 1, 2015

Method and apparatus for providing machine-to-machine service

Inventors: Alper Yegin (Sariyer, TR); Youngkyo Baek (Seoul, KR)
Assignee: Samsung Electronics Co., Ltd.
G06F21/57H04L63/0807H04W4/001H04W4/005H04W12/06G06F9/4401G06F2221/2143H04L63/126H04L2463/061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,202,055
App. No.
13/447,571
Granted
Dec 1, 2015
Kind
B2
Abstract

A method and an apparatus for providing Machine-to-Machine (M2M) service are provided. A method of providing service by an M2M device includes transmitting a request for service to a Network Security Capability (NSEC), the request for service comprising a identifier of a Device Service Capability Layer (DSCL) of the M2M device, performing an Extensible Authentication Protocol (EAP) authentication with an M2M Authentication Server (MAS) via the NSEC, and generating, if the EAP authentication is successful, a service key using a Master Session Key (MSK), a first constant string, and the identifier of the DSCL.

Claims (51)

1. A method of providing service for a machine-to-machine (M2M) device, the method comprising:

transmitting, a request for service to a network entity providing a security capability;

performing an authentication with an M2M authentication server (MAS) via the network entity;

generating, if the authentication is successful, a service key based on a master session key (MSK), a first constant string, and an identification associated with the M2M device;

transmitting a message indicating registration result acknowledgement to the network entity, comprising a value for a lifetime requested for the registration; and

generating an application key based on the service key, a second constant string, and an application identification (ID).

2. The method of claim 1 , wherein the performing of the authentication comprises communicating, for the authentication with the network entity, by using a protocol for carrying authentication for network access (PANA).

3. The method of claim 1 , wherein the request for service is a PANA-Client-Initiation (PCI) packet.

4. The method of claim 1 , wherein the request for service comprises information for identifying at least one component of the M2M device.

5. The method of claim 4 , wherein the at least one component comprises a device security capability layer (DSCL).

6. The method of claim 1 , wherein the request for service comprises an identification of a device security capability layer (DSCL).

7. The method of claim 1 , further comprising receiving an identification for service from one of the network entity and the MAS.

8. The method of claim 7 , wherein the service key is generated based on further the identification for service.

9. A machine-to-machine (M2M) device, the M2M device comprising:

a transceiver configured to transmit a request for service to a network entity providing a security capability; and

a controller configured:

to control performing an authentication with an M2M authentication server (MAS) via the network entity,

to generate, if the authentication is successful, a service key based on a master session key (MSK), a first constant string, and an identification associated with the M2M device,

to transmit a message indicating registration result acknowledgement to the network entity, comprising a value for a lifetime requested for the registration, and

to generate an application key based on the service key, a second constant string, and an application identification (ID).

10. The M2M device of claim 9 , wherein the transceiver is further configured to communicate with the network entity, during the authentication with the network entity, by using a protocol for carrying authentication for network access (PANA).

11. The M2M device of claim 9 , wherein the request for service is a PANA-Client-Initiation (PCI) packet.

12. The M2M device of claim 9 , wherein the request for service comprises information for identifying at least one component of the M2M device.

13. The M2M device of claim 12 , wherein the at least one component comprises a device security capability layer (DSCL).

14. The M2M device of claim 9 , wherein the request for service comprises an identification of a device security capability layer (DSCL).

15. The M2M device of claim 9 , further comprising a transceiver configured to receive an identification for service from one of the network entity and the MAS.

16. The M2M device of claim 15 , wherein the service key is generated based on further the identification for service.

17. A method of providing service by a network entity providing a security capability in a network system, the method comprising:

receiving a request for service from a machine-to-machine (M2M) device;

performing an authentication with the M2M device and an M2M authentication server (MAS);

generating, if the authentication is successful, a service key based on a master session key (MSK), a first constant string, and an identification associated with the M2M device;

transmitting a message indicating registration result acknowledgement to the MAS, comprising a value for a lifetime requested for the registration; and

generating an application key based on the service key, a second constant string, and an application identification (ID).

18. The method of claim 17 , wherein the performing of the authentication comprises communicating, for the authentication with the M2M device, by using a protocol for carrying authentication for network access (PANA); and

communicating, for the authentication with the MAS, by using an authentication, authorization and accounting (AAA) protocol.

19. The method of claim 17 , wherein the request for service is a PANA-Client-Initiation (PCI) packet.

20. The method of claim 17 , wherein the request for service comprises information for identifying at least one component of the M2M device.

21. The method of claim 20 , wherein the at least one component comprises a device security capability layer (DSCL).

22. The method of claim 17 , wherein the request for service comprises an identification of a device security capability layer (DSCL).

23. A network entity for providing service in a Machine-to-Machine (M2M) system, the network entity comprising:

a transceiver configured to receive a request for service from a M2M device; and

a controller configured:

to control performing an authentication with the M2M device and an M2M authentication server (MAS),

to generate, if the authentication is successful, a service key based on a master session key (MSK), a first constant string, and an identification associated with the M2M device,

to transmit a message indicating registration result acknowledgement to the MAS, comprising a value for a lifetime requested for the registration, and

to generate an application key based on the service key, a second constant string, and an application identification (ID).

24. The network entity of claim 23 , wherein the transceiver is further configured to communicate during the authentication with the M2M device, by using a protocol for carrying authentication for network access (PANA), and to communicate, during the authentication with the MAS, by using an authentication, authorization and accounting (AAA) protocol.

25. The network entity of claim 23 , wherein the request for service is a PANA-Client-Initiation (PCI) packet.

26. The network entity of claim 23 , wherein the request for service comprises information for identifying at least one component of the M2M device.

27. The network entity of claim 26 , wherein the at least one component comprises a device security capability layer (DSCL).

28. The network entity of claim 23 , wherein the request for service comprises the identification of a device security capability layer (DSCL).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2012
From: YEGIN, ALPER; BAEK, YOUNGKYO
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 028051/0092 →
Continuity (4)
Provisional Application 61475972 · Apr 15, 2011
Provisional Application 61485275 · May 12, 2011
Provisional Application 61544577 · Oct 7, 2011
Related Publication 20120265983A1 · Oct 18, 2012