IP Library › Granted Patent US 12,192,765
Granted Patent B2
US 12,192,765 · App. 17/430,690 · Granted Jan 7, 2025

Management of user equipment security capabilities in communication system

Inventor: Jennifer Liu (Plano, TX)
Assignee: Nokia Technologies Oy
H04W12/106H04L63/205H04L67/303H04W12/03H04W12/37H04W36/0038H04L69/28
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,192,765
App. No.
17/430,690
Granted
Jan 7, 2025
Kind
B2
Abstract

Techniques for security management in communication systems are provided. For example, a method includes receiving, from user equipment, a request indicating one or more security capabilities of the user equipment. The method also includes determining whether the indicated one or more security capabilities meet one or more designated criteria of a communication network, and rejecting the request by the user equipment responsive to determining that the indicated one or more security capabilities do not meet the one or more designated criteria of the communication network. For example, the request is rejected when it is determined that the user equipment does not support any encryption and/or integrity algorithms, or fails to support mandatory encryption and/or integrity algorithms. This serves to prevent malicious user equipment from gaining access to the communication network.

Claims (46)

1. An apparatus comprising:

at least one processor;

at least one memory including computer program code;

the at least one memory and the computer program code being configured to, with the at least one processor, cause the apparatus at least to:

receive, from user equipment, a request indicating one or more security capabilities of the user equipment;

determine whether the indicated one or more security capabilities meet one or more designated criteria of a communication network;

reject the request by the user equipment responsive to determining that the indicated one or more security capabilities do not meet the one or more designated criteria of the communication network; and

send a rejection notification to the user equipment, the rejection notification comprising a failure cause indication based at least in part on the determination that the indicated one or more security capabilities do not meet the one or more designated criteria of the communication network;

wherein the failure cause indication comprises a cause code indicating to the user equipment that an initial access request or a mobility request has failed due to the one or more security capabilities of the user equipment not being acceptable to the communication network.

2. The apparatus of claim 1 , wherein the rejection notification further comprises a back-off timer value.

3. The apparatus of claim 1 , wherein the initial access request comprises an initial registration request or an initial attach request and the mobility request comprises a mobility registration request or a mobility tracking area update request.

4. The apparatus of claim 1 , wherein the indicated one or more security capabilities comprise an indication of one or more encryption algorithms supported by the user equipment, and further wherein the determination that the indicated one or more security capabilities do not meet the one or more designated criteria of the communication network comprises determining that the user equipment (i) does not support any encryption algorithm or (ii) fails to support a mandatory encryption algorithm.

5. The apparatus of claim 1 , wherein the indicated one or more security capabilities comprise an indication of one or more integrity algorithms supported by the user equipment, and further wherein the determination that the indicated one or more security capabilities do not meet the one or more designated criteria of the communication network comprises determining that the user equipment (i) does not support any integrity algorithm or (ii) fails to support a mandatory integrity algorithm.

6. The apparatus of claim 1 , wherein the communication network comprises a 5G network and the apparatus comprises an access and mobility management function (AMF) of the 5G network.

7. The apparatus of claim 1 , wherein the communication network comprises a 4G network and the apparatus comprises mobility management entity (MME) of the 4G network.

8. The apparatus of claim 1 , wherein the failure cause indication comprises a 5G System (5GS) mobility management (5GMM) cause value.

9. The apparatus of claim 1 , wherein the failure cause indication comprises an Evolved Packet System (EPS) mobility management (EMM) cause value.

10. The apparatus of claim 1 , wherein the failure cause indication signals the user equipment to (i) abort a registration procedure with the communication network and (ii) reset a registration attempt counter.

11. A method comprising:

receiving, from user equipment, a request indicating one or more security capabilities of the user equipment;

determining whether the indicated one or more security capabilities meet one or more designated criteria of a communication network;

rejecting the request by the user equipment responsive to determining that the indicated one or more security capabilities do not meet the one or more designated criteria of the communication network; and

sending a rejection notification to the user equipment, the rejection notification comprising a failure cause indication based at least in part on the determination that the indicated one or more security capabilities do not meet the one or more designated criteria of the communication network;

wherein the failure cause indication comprises a cause code indicating to the user equipment that an initial access request or a mobility request has failed due to the one or more security capabilities of the user equipment not being acceptable to the communication network.

12. An article of manufacture comprising a non-transitory computer-readable storage medium having embodied therein executable program code that when executed by a processor causes the processor to perform the steps of claim 11 .

13. An apparatus comprising:

at least one processor;

at least one memory including computer program code;

the at least one memory and the computer program code being configured to, with the at least one processor, cause the apparatus at least to:

send, to a security management node in a communication network, a request indicating one or more security capabilities of the apparatus; and

receive, from the security management node, a rejection notification responsive to the indicated one or more security capabilities not meeting one or more designated criteria of the communication network;

wherein the rejection notification comprises a failure cause indication based at least in part on a determination that the indicated one or more security capabilities do not meet the one or more designated criteria of the communication network; and

wherein the failure cause indication comprises a cause code indicating to the apparatus that an initial access request or a mobility request has failed due to the one or more security capabilities of the apparatus not being acceptable to the communication network.

14. The apparatus of claim 13 , wherein the initial access request comprises an initial registration request or an initial attach request and the mobility request comprises a mobility registration request or a mobility tracking area update request.

15. The apparatus of claim 13 , the indicated one or more security capabilities comprise an indication of one or more encryption algorithms supported by the apparatus, and further wherein the rejection notification is received responsive to a determination that the apparatus (i) does not support any encryption algorithm or (ii) fails to support a mandatory encryption algorithm.

16. The apparatus of claim 13 , the indicated one or more security capabilities comprise an indication of one or more integrity algorithms supported by the apparatus, and further wherein the rejection notification is received responsive to a determination that the apparatus (i) does not support any integrity algorithm or (ii) fails to support a mandatory integrity algorithm.

17. The apparatus of claim 13 , wherein in response to receiving the rejection notification the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus to:

abort an attempt to access the communication network; and

reset an access attempt counter.

18. The apparatus of claim 13 , wherein in response to receiving the rejection notification the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus to refrain from attempting to access the communication network based at least in part on a timer value included in the rejection notification.

19. A method comprising:

sending, to a security management node in a communication network, a request indicating one or more security capabilities of an apparatus; and

receiving, from the security management node, a rejection notification responsive to the indicated one or more security capabilities not meeting one or more designated criteria of the communication network;

wherein the rejection notification comprises a failure cause indication based at least in part on a determination that the indicated one or more security capabilities do not meet the one or more designated criteria of the communication network; and

wherein the failure cause indication comprises a cause code indicating to the apparatus that an initial access request or a mobility request has failed due to the one or more security capabilities of the apparatus not being acceptable to the communication network.

20. An article of manufacture comprising a non-transitory computer-readable storage medium having embodied therein executable program code that when executed by a processor causes the processor to perform the steps of claim 19 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2021
From: LIU, JENNIFER
To: NOKIA TECHNOLOGIES OY
Reel/Frame 057166/0446 →
Continuity (2)
Provisional Application 62806370 · Feb 15, 2019
Related Publication 20220201488A1 · Jun 23, 2022
References Cited (28)
US 20080304434A1 · Giaretta · 2008 [cited by examiner]
US 20150181462A1 · Iwai · 2015 [cited by examiner]
US 20160183156A1 · Chin · 2016 [cited by examiner]
US 20170367031A1 · Kuge et al. · 2017 [cited by applicant]
US 20180376444A1 · Kim · 2018 [cited by examiner]
US 20190230585A1 · Chun · 2019 [cited by examiner]
US 20190349759A1 · Rosenberg · 2019 [cited by examiner]
US 20190394651A1 · Wifvesson · 2019 [cited by examiner]
CN 1571540A · 2005 [cited by applicant]
CN 101686233A · 2010 [cited by applicant]
CN 102960029A · 2013 [cited by applicant]
WO 2011001861A1 · 2011 [cited by applicant]
WO 2019030727A1 · 2019 [cited by applicant]
Office action received for corresponding Vietnam Patent Application No. 1-2021-05285, dated Oct. 15, 2021, 1 page of office action and 1 page of translation available. [cited by applicant]
“Discussion on Handling when the UE Indicated Security Capabilities are Invalid or Unacceptable”, 3GPP TSG CT WG1 Meeting #115, C1-191324, Agenda : 15.2.2.1, Nokia, Feb. 25-Mar. 1, 2019, 2 pages. [cited by applicant]
“Handling when the UE Indicated Security Capabilities are Invalid or Unacceptable”, 3GPP TSG CT WG1 Meeting #115, C1-191702, Nokia, Feb. 25-Mar. 1, 2019, 4 pages. [cited by applicant]
“Handling when the UE Indicated Security Capabilities are Invalid or Unacceptable”, 3GPP TSG CT WG1 Meeting #115, C1-191700, Nokia, Feb. 25-Mar. 1, 2019, 3 pages. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Non-Access-Stratum (NAS) protocol for 5G System (5GS); Stage 3 (Release 15)”, 3GPP Ts 24.501, V15.2.1, Jan. 2019, pp. 1-455. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS); Stage 3 (Release 15)”, 3GPP TS 24.301, V15.5.0, Dec. 2018… [cited by applicant]
International Search Report and Written Opinion received for corresponding Patent Cooperation Treaty Application No. PCT/FI2020/050046, dated Apr. 2, 2020, 13 pages. [cited by applicant]
“Discussion on DoS and Replay Attacks for Rejection Procedure”, RAN WG2 Meeting #101, R2-1803266, Agenda : 10.4.1.7.5, Huawei, Feb. 26-Mar. 2, 2018, 6 pages. [cited by applicant]
Rejection Decision received for corresponding Chinese Patent Application No. 202080013950.1, dated Feb. 28, 2023, 8 pages of Rejection Decision, no page of summary/translation available. [cited by applicant]
Extended European Search Report received for corresponding European Patent Application No. 20755979.0, dated Sep. 29, 2022, 6 pages. [cited by applicant]
Office Action received for corresponding Chinese Patent Application No. 202080013950.1, dated Oct. 8, 2022, 9 pages of Office Action, 4 pages of summary and translation available. [cited by applicant]
Indonesian Patent Application No. P00202106509, Notice of Stage 1 Substantive Examination Result (with English language translation), Oct. 30, 2023, 6 pages. [cited by applicant]
Vietnam Patent Application No. 2101004689 Office Action (with English language translation), Mar. 7, 2024, 6 pages. [cited by applicant]
Office action received for corresponding Vietnam Patent Application No. 1-2021-05285, dated Aug. 14, 2023, 2 pages of office action and 1 page of translation available. [cited by applicant]
European Patent Application No. 20755979.0 Office Action, Mar. 22, 2024, 5 pages. [cited by applicant]