IP Library Granted Patent US 9,438,594
Granted Patent B2
US 9,438,594 · App. 14/173,073 · Granted Sep 6, 2016

Method and apparatus for establishing tunnel data security channel

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,438,594
App. No.
14/173,073
Granted
Sep 6, 2016
Kind
B2
Abstract

Sending an authentication request message to an authentication device, receiving an authentication response message sent by the authentication device, where the authentication response message includes a trust relationship information element which is used for indicating a trust relationship of a current access, and establishing an S2c tunnel security association according to the trust relationship of the current access. The trust relationship when the non- 3 GPP access side accesses the EPS network may be obtained, thereby ensuring establishment of a correct S2c tunnel security data channel.

Claims (21)

1. A method for establishing a child security association (Child SA) between a user equipment (UE) and a packet data network (PDN) gateway, comprising:

sending, by the PDN gateway, an authentication request message to an authentication device;

receiving, by the PDN gateway, an authentication response message from the authentication device so that the PDN gateway is able to determine whether the UE accesses an Evolved Packet Core (EPC) network via a trusted non-3GPP access network from a trust relationship information element comprised in the authentication response message; and

establishing, by the PDN gateway, the Child SA with the UE according to an indication of the trust relationship information element that the UE accesses the EPC network via the trusted non-3GPP access network.

2. The method according to claim 1 , wherein the establishing the Child SA with the UE comprises:

initiating, by the PDN gateway, a Child SA establishing process.

3. The method according to claim 1 , wherein the establishing the Child SA with the UE comprises:

receiving, by the PDN gateway, a Child SA establishing request from the UE; and

accepting, by the PDN gateway, the Child SA establishing request.

4. The method according to claim 1 , wherein the indication of the trust relationship information element has a value of “trusted” which indicates that the UE accesses the EPC network via a trusted non-3GPP access network.

5. The method according to claim 1 , wherein the authentication device is an authentication authorization accounting (AAA) server or a Home Subscriber Server (HSS).

6. A packet data network (PDN) gateway, comprising:

a transmitter configured to send an authentication request message to an authentication device;

a receiver configured to receive an authentication request response message from the authentication device, so that the PDN gateway is able to determine whether the UE accesses an Evolved Packet Core (EPC) network via a trusted non-3GPP access network from a trust relationship information element comprised in the authentication response message; and

a processor coupled to the transmitter and the receiver and configured to:

establish a child security association (Child SA) with the UE according to an indication of the trust relationship information element that the UE accesses the EPC network via a trusted non-3GPP access network.

7. The PDN gateway according to claim 6 , wherein the processor is configured to initiate a Child SA establishing process with the UE.

8. The PDN gateway according to claim 6 , wherein

the receiver is further configured to receive a Child SA establishing request from the UE; and

the processor is further configured to accept the Child SA establishing request.

9. The PDN gateway according to claim 6 , wherein the indication of the trust relationship information element has a value of “trusted” which indicates that the UE accesses the EPC network via a trusted non-3GPP access network.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2018
From: HUAWEI TECHNOLOGIES CO., LTD.
To: NOKIA TECHNOLOGIES OY
Reel/Frame 045337/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2016
From: LI, HUAN; HERRERO VERON, CHRISTIAN; SHU, LIN
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 039349/0059 →