IP Library Granted Patent US 9,722,789
Granted Patent B2
US 9,722,789 · App. 14/265,330 · Granted Aug 1, 2017

Method and system for providing enhanced data encryption protocols in a mobile satellite communications system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,722,789
App. No.
14/265,330
Granted
Aug 1, 2017
Kind
B2
Abstract

An approach for improved security protocols in a mobile satellite system is provided. A remote terminal performs a key establishment function, including determination of a first encryption key for encrypting data for transmission over the satellite communications channels, and determination of an authentication key for authenticating entities communicating over the communications channels. The remote terminal receives a security mode command including a key indicator, and determines a second encryption key for enhanced session data security over communications channels. The second encryption key is determined based on the key indicator and a key generation algorithm. The remote terminal further determines a key indicator response and transmits a security mode complete command including the key indicator response to a satellite base station subsystem (SBSS). The key indicator response is constructed for the SBSS to determine the second encryption key based on the key indicator response and a key generation algorithm.

Claims (48)

1. A method comprising:

performing, by a communications terminal of a mobile communications network, an authentication function with a remote gateway node of the mobile communication network, including generating a first data encryption key configured for a first level of encryption for session data of a communications session of the communications terminal and an authentication key configured for authentication security protection for control layer messaging, wherein the session data and the control layer messaging are to be transmitted between the communications terminal and the remote gateway node over one or more channels of the communications network;

receiving, by the communications terminal, a security mode command from the remote gateway node, wherein the security mode command includes a key indicator;

generating, by the communications terminal, a second data encryption key based on the key indicator and a first key algorithm secured for the communications terminal, wherein the second data encryption key is generated for a second level of encryption for the session data, wherein the second level of encryption is at a higher security level as compared to the first level of encryption; and

generating, by the communications terminal, a key indicator response based on the key indicator, and transmitting a security mode complete command including the key indicator response to the remote gateway node, wherein the key indicator response is configured to enable the remote gateway node to generate the second data encryption key based on the key indicator response and a second key algorithm secured for the remote gateway node.

2. The method of claim 1 , further comprising:

performing one or more packet data protocol (PDP) context activation processes over at least one of the channels of the communications network, wherein messaging for the PDP context activation processes is encrypted at the second level of encryption based on the second data encryption key.

3. The method of claim 1 , further comprising:

encrypting the session data at the second level of encryption based on the second data encryption key; and

transmitting the encrypted session data to the remote gateway node as part of the communications session of the communications terminal.

4. The method of claim 1 , wherein the one of more channels of the mobile communications network consist of wireless communications channels and the communications terminal is a wireless mobile user terminal, and wherein the remote gateway node comprises a base station of the mobile communications network.

5. The method of claim 4 , wherein the mobile communications network is a mobile satellite communications network and the wireless communications channels are satellite communications channels, the communications terminal is a mobile satellite user terminal, and the base station is a satellite base station subsystem that serves as an interface between the satellite communications channels and a core network of a terrestrial communications system.

6. The method of claim 5 , further comprising:

encrypting the session data at the second level of encryption based on the second data encryption key; and

transmitting the encrypted session data to the remote gateway node as part of the communications session of the communications terminal.

7. The method of claim 1 , wherein the generation of the second data encryption key and of the key indicator response are performed at a radio resource control layer of the communications terminal.

8. The method of claim 1 , wherein the generation of the second data encryption key and of the key indicator response are performed at an applications layer of the communications terminal.

9. The method of claim 8 , wherein the key indicator is received by the applications layer directly from a radio resource control layer of the communications terminal, and wherein the key indicator response is transmitted directly to the radio resource control layer.

10. A communications terminal apparatus of a mobile communications network, comprising:

a processing circuit; and

a memory including program code, wherein the program code is configured to be executed by the processing circuit, and

wherein, as a result of the execution of the program code, the processing circuit is configured to cause the communications terminal apparatus to perform at least the following,

performing an authentication function with a remote gateway node of the mobile communication network, including generating a first data encryption key configured for a first level of encryption for session data of a communications session of the communications terminal and an authentication key configured for authentication security protection for control layer messaging, wherein the session data and the control layer messaging are to be transmitted between the communications terminal and the remote gateway node over one or more channels of the communications network;

receiving a security mode command from the remote gateway node, wherein the security mode command includes a key indicator,

generating a second data encryption key based on the key indicator and a first key algorithm secured for the communications terminal, wherein the second data encryption key is generated for a second level of encryption for the session data, wherein the second level of encryption is at a higher security level as compared to the first level of encryption, and

generating a key indicator response based on the key indicator, and transmitting a security mode complete command including the key indicator response to the remote gateway node, wherein the key indicator response is configured to enable the remote gateway node to generate the second data encryption key based on the key indicator response and a second key algorithm secured for the remote gateway node.

11. The communications terminal apparatus of claim 10 , wherein the apparatus is further caused to perform at least the following:

performing one or more packet data protocol (PDP) context activation processes over at least one of the channels of the communications network, wherein messaging for the PDP context activation processes is encrypted at the second level of encryption based on the second data encryption key.

12. The communications terminal apparatus of claim 10 , wherein the apparatus is further caused to perform at least the following:

encrypting the session data at the second level of encryption based on the second data encryption key; and

transmitting the encrypted session data to the remote gateway node as part of the communications session of the communications terminal.

13. The communications terminal apparatus of claim 10 , wherein the one of more channels of the mobile communications network consist of wireless communications channels and the communications terminal apparatus is a wireless mobile user terminal, and wherein the remote gateway node comprises a base station of the mobile communications network.

14. The communications terminal apparatus of claim 13 , wherein the mobile communications network is a mobile satellite communications network and the wireless communications channels are satellite communications channels, the communications terminal apparatus is a mobile satellite user terminal, and the base station is a satellite base station subsystem that serves as an interface between the satellite communications channels and a core network of a terrestrial communications system.

15. The communications terminal apparatus of claim 14 , wherein the apparatus is further caused to perform at least the following:

encrypting the session data at the second level of encryption based on the second data encryption key; and

transmitting the encrypted session data to the remote gateway node as part of the communications session of the communications terminal.

16. The communications terminal apparatus of claim 10 , wherein the generation of the second data encryption key and of the key indicator response are performed at a radio resource control layer of the apparatus.

17. The communications terminal apparatus of claim 10 , wherein the generation of the second data encryption key and of the key indicator response are performed at an applications layer of the apparatus.

18. The communications terminal apparatus of claim 17 , wherein the key indicator is received by the applications layer directly from a radio resource control layer of the communications terminal apparatus, and wherein the key indicator response is transmitted directly to the radio resource control layer.

19. The communications terminal apparatus of claim 10 , further comprising:

an applications processor circuit at an applications layer of the apparatus, wherein the generation of the second data encryption key and of the key indicator response are performed by the applications processor circuit.

20. The communications terminal apparatus of claim 10 , further comprising:

an applications processor circuit at an applications layer of the apparatus; and

a key exchange protocol circuit separate from the applications processor circuit, wherein the generation of the second data encryption key and of the key indicator response are performed by the key exchange protocol circuit.

21. The communications terminal apparatus of claim 10 , further comprising:

an applications processor circuit at an applications layer of the apparatus; and

an encryption circuit separate from the applications processor circuit, wherein the encryption circuit performs the generation of the second data encryption key and of the key indicator response; and

wherein the encryption circuit further performs encryption of the session data at the second level of encryption based on the second data encryption key.

Assignments (6)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION NUMBER 15649418 PREVIOUSLY RECORDED ON REEL 050600 FRAME 0314. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT OF PATENT SECURITY AGREEMENTS. Recorded Sep 3, 2020
From: WELLS FARGO, NATIONAL BANK ASSOCIATION
To: U.S. BANK NATIONAL ASSOCIATION
Reel/Frame 053703/0367 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION NUMBER 15649418 PREVIOUSLY RECORDED AT REEL: 044376 FRAME: 0139. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT. Recorded Sep 3, 2020
From: HUGHES NETWORK SYSTEMS, LLC
To: WELLS FARGO BANK, NATIONAL ASSOCIATION - AS COLLATERAL AGENT
Reel/Frame 053723/0726 →
ASSIGNMENT OF PATENT SECURITY AGREEMENTS Recorded Oct 1, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: U.S. BANK NATIONAL ASSOCIATION
Reel/Frame 050600/0314 →
SECURITY INTEREST Recorded Nov 6, 2017
From: HUGHES NETWORK SYSTEMS, LLC
To: WELLS FARGO BANK, NATIONAL ASSOCIATION - AS COLLATERAL AGENT
Reel/Frame 044376/0139 →
SECURITY INTEREST Recorded Feb 18, 2016
From: HUGHES NETWORK SYSTEMS LLC
To: WELLS FARGO BANK, NATIONAL ASSOCIATION - AS COLLATERAL AGENT
Reel/Frame 037847/0440 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2014
From: CHANNASANDRA RAVISHANKAR; GAGUK ZAKARIA; NASSIR BENAMMAR; JOHN CORRIGAN
To: HUGHES NETWORK SYSTEMS, LLC
Reel/Frame 032974/0243 →