IP Library › Granted Patent US 12,250,550
Granted Patent B2
US 12,250,550 · App. 17/710,846 · Granted Mar 11, 2025

Method and apparatus for using NAS message for data protection

Inventor: Kyungjoo Suh (Suwon-si, KR)
Assignee: Samsung Electronics Co., Ltd.
H04W12/37H04W12/10H04W60/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,250,550
App. No.
17/710,846
Granted
Mar 11, 2025
Kind
B2
Abstract

A method, performed by a user equipment (UE), for protecting data includes: transmitting an attach request message including at least one security protection parameter regarding a UE capability to support a security protection for a user plane, to a mobility management entity (MME) via a base station; and in case that a security policy is determined at a policy charging function (PCF) based on the attach request message and information of the security policy is received at the MME, receiving an attach accept message including at least one security protection parameter regarding a network capability for the security policy related with an evolved packet system (EPS) bearer, from the MME via the base station.

Claims (48)

1. A method of a user equipment (UE) for protecting data, the method comprising:

transmitting, to a mobility management entity (MME) via a base station, an attach request message including at least one security protection parameter associated with a UE capability to support a security protection for a user plane; and

when a first security policy is determined at a policy control entity based on the attach request message and information of the first security policy is received at the MME, receiving, from the MME via the base station, an attach accept message including at least one security protection parameter associated with a network capability for the first security policy related with an evolved packet system (EPS) bearer.

2. The method of claim 1 , wherein:

the attach request message further includes maximum data rate information related with the security protection; and

the maximum data rate information includes at least one of information for a maximum data rate corresponding to each UE used for a user plane integrity protection or information for the maximum data rate corresponding to each UE used for the security protection.

3. The method of claim 2 , wherein:

the attach request message piggybacks a packet data network (PDN) connectivity request message; and

the information for the maximum data rate related with the security protection is piggybacked in the PDN connectivity request message.

4. The method of claim 1 , further comprising:

when a second security policy is determined at the policy control entity and information for the second security policy is received at the MME, receiving an activate dedicated EPS bearer context request message including the at least one security protection parameter associated with a network capability for the second security policy related with another EPS bearer.

5. A method of a mobility management entity (MME) for protecting data, the method comprising:

receiving, from a user equipment (UE) via a base station, an attach request message including at least one security protection parameter associated with a UE capability to support a security protection for a user plane; and

when a first security policy is determined at a policy control entity based on the attach request message and information of the first security policy is received at the MME, transmitting, to the UE via the base station, an attach accept message including at least one security protection parameter associated with a network capability for the first security policy related with an evolved packet system (EPS) bearer.

6. The method of claim 5 , wherein:

the attach request message further includes maximum data rate information related with the security protection; and

the maximum data rate information includes at least one of information for a maximum data rate corresponding to each UE used for a user plane integrity protection or information for the maximum data rate corresponding to each UE used for the security protection.

7. The method of claim 6 , wherein:

the attach request message piggybacks a packet data network (PDN) connectivity request message; and

the information for the maximum data rate related with the security protection is piggybacked in the PDN connectivity request message.

8. The method of claim 5 , further comprising:

when a second security policy is determined at the policy control entity and information for the second security policy is received at the MME, transmitting an activate dedicated EPS bearer context request message including the at least one security protection parameter associated with a network capability for the second security policy related with another EPS bearer.

9. A user equipment (UE) for protecting data, the UE comprising:

a transceiver; and

at least one processor coupled with the transceiver and configured to:

transmit, to a mobility management entity (MME) via a base station, an attach request message including at least one security protection parameter associated with a UE capability to support a security protection for a user plane, and

when a first security policy is determined at a policy control entity based on the attach request message and information of the first security policy is received at the MME, receive, from the MME via the base station, an attach accept message including at least one security protection parameter associated with a network capability for the first security policy related with an evolved packet system (EPS) bearer.

10. The UE of claim 9 , wherein:

the attach request message further includes maximum data rate information related with the security protection; and

the maximum data rate information includes at least one of information for a maximum data rate corresponding to each UE used for a user plane integrity protection or information for the maximum data rate corresponding to each UE used for the security protection.

11. The UE of claim 10 , wherein:

the attach request message piggybacks a packet data network (PDN) connectivity request message; and

the information for the maximum data rate related with the security protection is piggybacked in the PDN connectivity request message.

12. The UE of claim 9 , wherein the at least one processor is further configured to

when a second security policy is determined at the policy control entity and information for the second security policy is received at the MME, receive an activate dedicated EPS bearer context request message including the at least one security protection parameter associated with a network capability for the second security policy related with another EPS bearer.

13. A mobility management entity (MME) for protecting data, the MME comprising:

a transceiver; and

at least one processor coupled with the transceiver and configured to:

receive, from a user equipment (UE) via a base station, an attach request message including at least one security protection parameter associated with a UE capability to support a security protection for a user plane, and

when a first security policy is determined at a policy control entity based on the attach request message and information of the first security policy is received at the MME, transmit, to the UE via the base station, an attach accept message including at least one security protection parameter associated with a network capability for the first security policy related with an evolved packet system (EPS) bearer.

14. The MME of claim 13 , wherein:

the attach request message further includes maximum data rate information related with the security protection; and

the maximum data rate information includes at least one of information for a maximum data rate corresponding to each UE used for a user plane integrity protection or information for the maximum data rate corresponding to each UE used for the security protection.

15. The MME of claim 14 , wherein:

the attach request message piggybacks a packet data network (PDN) connectivity request message; and

the information for the maximum data rate related with the security protection is piggybacked in the PDN connectivity request message.

16. The MME of claim 13 , wherein the at least one processor is further configured to:

when a second security policy is determined at the policy control entity and information for the second security policy is received at the MME, transmit an activate dedicated EPS bearer context request message including the at least one security protection parameter associated with a network capability for the second security policy related with another EPS bearer.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2022
From: SUH, KYUNGJOO
To: SAMSUNG ELECTRONICS CO., LTD
Reel/Frame 059568/0583 →
Priority Claims (1)
KR 10-2021-0041929 · Mar 31, 2021 · national
Continuity (1)
Related Publication 20220330028A1 · Oct 13, 2022
References Cited (18)
US 9629028B2 · Meylan et al. · 2017 [cited by applicant]
US 10944786B2 · Chen · 2021 [cited by examiner]
US 20190098597A1 · Basu Mallick · 2019 [cited by examiner]
US 20200084631A1 · Zhang · 2020 [cited by examiner]
US 20210014688A1 · Ito · 2021 [cited by examiner]
US 20220078677A1 · Yin · 2022 [cited by examiner]
US 20220201488A1 · Liu · 2022 [cited by examiner]
US 20220240213A1 · Ly · 2022 [cited by examiner]
US 20240196218A1 · Ito · 2024 [cited by examiner]
CN 108235300B · 2020 [cited by applicant]
EP 3541105A1 · 2019 [cited by applicant]
WO 2020153894A1 · 2020 [cited by applicant]
RAN WG3, “Enforcement of maximum supported data rate for integrity protection”, 3GPP TSG SA WG3 Meeting #94, Jan. 18, 2019, S3-190038, 3 pages. [cited by applicant]
RAN2, “LS on maximum data rate of user plane integrity protected data”, 3GPP TSG SA WG2 Meeting #S2-125, Feb. 1, 2018, S2-181420, 3 pages. [cited by applicant]
Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or the Declaration dated Jun. 17, 2022 in connection with International Patent Application… [cited by applicant]
Supplementary European Search Report dated May 15, 2024, in connection with European Application No. 22781615.4, 10 pages. [cited by applicant]
3GPP TS 23.501 V16.6.0 (Sep. 2020), Technical Specification, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 1… [cited by applicant]
Piggybacking (data transmission), Wikipedia, Jun. 2020, 2 pages. [cited by applicant]