IP Library Granted Patent US 10,356,619
Granted Patent B2
US 10,356,619 · App. 15/919,404 · Granted Jul 16, 2019

Access through non-3GPP access networks

Inventors: Mats Näslund (Bromma, SE); Jari Arkko (Kauniainen, FI); Rolf Blom (Järfälla, SE); Vesa Petteri Lehtovirta (Espoo, FI); Karl Norrman (Stockholm, SE); Stefan Rommer (Västra Frölunda, SE); Bengt Sahlin (Espoo, FI)
Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
H04W12/06G06F21/30H04L63/08H04L63/0892H04W60/00H04W72/0493H04L63/0272H04L63/1433H04L63/162H04L63/164H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,356,619
App. No.
15/919,404
Granted
Jul 16, 2019
Kind
B2
Abstract

A user equipment receives an Extensible Authentication Protocol Authentication and Key Agreement Prime (EAP AKA′) message, from an authentication server related to the user equipment, in an authentication procedure being part of setting up a connection from the user equipment through an access network. The user equipment sets up an IP Security tunnel between the user equipment and an evolved Packet Data Gateway responsive to the EAP AKA′ message indicating that the access network is untrusted.

Claims (25)

1. A method performed by a user equipment for communication through an access network, the method comprising:

receiving an Extensible Authentication Protocol Authentication and Key Agreement Prime (EAP AKA′) message, from an authentication server related to the user equipment, in an authentication procedure being part of setting up a connection from the user equipment through the access network; and

setting up an IP Security tunnel between the user equipment and an evolved Packet Data Gateway responsive to the EAP AKA′ message indicating that the access network is untrusted.

2. The method of claim 1 , wherein the authentication server is a Third Generation Partnership Project (3GPP) Authentication, Authorization, Accounting (AAA) server in a home network of the user equipment.

3. The method of claim 1 , wherein the authentication procedure is based on EAP AKA′.

4. The method of claim 1 , further comprising:

obtaining information from the message indicating at least one protocol to be used for communication along the connection to be established; and

using the at least one protocol in establishing the connection through the access network.

5. A user equipment for communication through an access network, the user equipment comprising:

one or more processing circuits configured to:

receive an Extensible Authentication Protocol Authentication and Key Agreement Prime (EAP AKA′) message, from an authentication server related to the user equipment, in an authentication procedure being part of setting up a connection from the user equipment through the access network; and

set up an IP Security tunnel between the user equipment and an evolved Packet Data Gateway responsive to the EAP AKA′ message indicating that the access network is untrusted.

6. The user equipment of claim 5 , wherein the one or more processing circuits are further configured to:

obtain information from the message indicating at least one protocol to be used for communication along the connection to be established; and

use said at least one protocol in establishing the connection through the access network.

7. The user equipment of claim 5 , wherein the authentication server is a Third Generation Partnership Project (3GPP) Authentication, Authorization, Accounting (AAA) server in a home network of the user equipment.

8. The user equipment of claim 5 , wherein the authentication procedure is based on EAP AKA′.

9. An authentication server related to a user equipment, the authentication server comprising:

one or more processing circuits configured to:

participate in an authentication procedure that establishes connectivity from the user equipment through an access network;

generate an Extensible Authentication Protocol Authentication and Key Agreement Prime (EAP AKA′) message indicating whether or not the access network is trusted;

send the EAP AKA′ message to the user equipment, as part of the authentication procedure, before the user equipment has established a connection through the access network.

10. The authentication server of claim 9 , wherein the authentication server is a Third Generation Partnership Project (3GPP) Authentication, Authorization, Accounting (AAA) server in a home network of the user equipment.

11. The authentication server of claim 9 , wherein the authentication procedure is based on EAP AKA′.

12. The authentication server of claim 9 , wherein to generate the EAP AKA′ message, the one or more processing circuits are further configured to include information indicating at least one protocol to be used for communication along the connection to be established.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2018
From: ARKKO, JARI; BLOM, ROLF; LEHTOVIRTA, VESA; NÄSLUND, MATS; NORRMAN, KARL; ROMMER, STEFAN; SAHLIN, BENGT
To: TELEFONAKTIEBOLAGET L M ERICSSON (PUBL)
Reel/Frame 045186/0486 →
CHANGE OF NAME Recorded Mar 13, 2018
From: TELEFONAKTIEBOLAGET L M ERICSSON (PUBL)
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 045573/0628 →
Continuity (5)
Continuation 14820130 · Aug 6, 2015
Continuation 14090828 · Nov 26, 2013
Continuation 12937008
Provisional Application 61044242 · Apr 11, 2008
Related Publication 20180206118A1 · Jul 19, 2018