IP Library Granted Patent US 9,264,957
Granted Patent B2
US 9,264,957 · App. 13/696,983 · Granted Feb 16, 2016

Key derivation during inter-network handover

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,264,957
App. No.
13/696,983
Granted
Feb 16, 2016
Kind
B2
Abstract

A method for deriving a key during an inter-network handover is provided. The method comprises: obtaining first key information from a first relocation request message, in response to receipt of said first relocation request message which reaches a target network entity first; deriving a key for handover based at least in part on said first key information; and generating an indicator for indicating that the key is derived based at least in part on said first key information.

Claims (53)

1. A method, comprising:

obtaining, by a network entity, first key information from a first relocation request message, in response to receipt of said first relocation request message which reaches a target network entity first, when compared to a second relocation request message arriving after the first relocation request message, wherein the first relocation request message is associated with a first type of bearer and the second relocation request message is associated with a second type of bearer;

deriving, by the network entity, a key for handover based at least in part on said first key information; and

generating, by the network entity, an indicator for indicating that the key is derived based at least in part on said first key information.

2. The method according to claim 1 , further comprising:

transmitting the indicator to a source network entity initiating relocation via a first path.

3. The method according to claim 2 , wherein said transmitting the indicator to the source network entity via said first path comprises:

sending a first handover request message comprising the indicator to a target network node; and

forwarding a first transparent container containing the indicator to the source network entity, wherein said first transparent container is received from the target network node in a first handover acknowledge message which is a response to said first handover request message.

4. The method according to claim 2 , wherein the source network entity sends the indicator received via said first path to a user equipment in a first handover command.

5. The method according to claim 1 , further comprising:

retrieving the indicator, in response to receipt of the second relocation request message comprising second key information; and

transmitting the indicator to a source network entity initiating relocation via a second path.

6. The method according to claim 5 , wherein said transmitting the indicator to the source network entity via said second path comprises:

sending a second handover request message comprising the indicator to a target network node; and

forwarding a second transparent container containing the indicator to the source network entity, wherein said second transparent container is received from the target network node in a second handover acknowledge message which is a response to said second handover request message.

7. The method according to claim 5 , wherein the source network entity sends the indicator received via said second path to the user equipment in a second handover command.

8. The method according to claim 5 , wherein said first key information comprises a cipher key for the first type of bearer comprising a circuit switched bearer and an integrity key for circuit switched bearer, and said second key information comprises a cipher key for the second type of bearer comprising a packet switched bearer and an integrity key for packet switched bearer; and wherein said first path comprises a path for circuit switched relocation, and said second path comprises a path for packet switched relocation.

9. The method according to claim 5 , wherein said first key information comprises a cipher key for the first type of bearer comprising a packet switched bearer and an integrity key for packet switched bearer, and said second key information comprises a cipher key for the second type of bearer comprising a circuit switched bearer and an integrity key for circuit switched bearer; and wherein said first path comprises a path for packet switched relocation, and said second path comprises a path for circuit switched relocation.

10. The method of claim 1 , wherein the network entity comprises the target network entity.

11. The method of claim 1 , wherein the comparison includes the second relocation request message and/or a handover message.

12. The method of claim 1 further comprising:

receiving the first relocation request message, and subsequently receiving the second relocation request message.

13. An apparatus, comprising:

at least one processor; and

at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to perform at least the following:

obtain first key information from a first relocation request message, in response to receipt of said first relocation request message which reaches the apparatus first, when compared to a second relocation request message arriving after the first request relocation message, wherein the first relocation request message is associated with a first type of bearer and the second relocation request message is associated with a second type of bearer;

derive a key for handover based at least in part on said first key information; and

generate an indicator for indicating that the key is derived based at least in part on said first key information, wherein the apparatus comprises a network entity.

14. The apparatus according to claim 13 , wherein the apparatus is further configured to at least transmit the indicator to a source network entity initiating relocation via a first path.

15. The apparatus according to claim 14 , wherein the apparatus is further configured to at least:

send a first handover request message comprising the indicator to a target network node; and

forward a first transparent container containing the indicator to the source network entity, wherein said first transparent container is received from the target network node in a first handover acknowledge message which is a response to said first handover request message.

16. The apparatus according to claim 14 , wherein the source network entity sends the indicator received via said first path to a user equipment in a first handover command.

17. The apparatus according to claim 13 , wherein the apparatus is further configured to at least:

retrieve the indicator, in response to receipt of the second relocation request message comprising second key information; and

transmit the indicator to a source network entity initiating relocation via a second path.

18. The apparatus according to claim 17 , wherein the apparatus is further configured to at least:

send a second handover request message comprising the indicator to a target network node; and

forward a second transparent container containing the indicator to the source network entity, wherein said second transparent container is received from the target network node in a second handover acknowledge message which is a response to said second handover request message.

19. The apparatus according to claim 17 , wherein the source network entity sends the indicator received via said second path to the user equipment in a second handover command.

20. The apparatus according to claim 17 , wherein said first key information comprises a cipher key for the first type of bearer comprising a circuit switched bearer and an integrity key for circuit switched bearer, and said second key information comprises a cipher key for the second type of bearer comprising a packet switched bearer and an integrity key for packet switched bearer; and wherein said first path comprises a path for circuit switched relocation, and said second path comprises a path for packet switched relocation.

21. The apparatus according to claim 17 , wherein said first key information comprises a cipher key for the first type of bearer comprising a packet switched bearer and an integrity key for packet switched bearer, and said second key information comprises a cipher key for the second type of bearer comprising a circuit switched bearer and an integrity key for circuit switched bearer; and wherein said first path comprises a path for packet switched relocation, and said second path comprises a path for circuit switched relocation.

22. An apparatus, comprising:

at least one processor; and

at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to perform at least the following:

obtain an indicator from a first handover command message, in response to receipt of said first handover command message which reaches the apparatus first, when compared to a second handover command message arriving after the first handover command message, wherein the first handover command message is associated with a first type of bearer and the second handover command message is associated with a second type of bearer;

derive a key for handover based at least in part on key information indicated by the indicator; and

perform a first handover procedure with the key.

23. The apparatus according to claim 22 , wherein the apparatus is further configured to perform a second handover procedure with the key, in response to receipt of a second handover command message.

24. The apparatus according to claim 22 , wherein the key information comprises one of the following:

a cipher key for packet switched bearer and an integrity key for packet switched bearer; and

a cipher key for circuit switched bearer and an integrity key for circuit switched bearer.

Assignments (2)
SECURITY INTEREST Recorded Jun 1, 2021
From: WSOU INVESTMENTS, LLC
To: OT WSOU TERRIER HOLDINGS, LLC
Reel/Frame 056990/0081 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2018
From: NOKIA TECHNOLOGIES OY
To: WSOU INVESTMENTS, LLC
Reel/Frame 045084/0282 →