IP Library › Granted Patent US 11,882,451
Granted Patent B2
US 11,882,451 · App. 17/911,830 · Granted Jan 23, 2024

Method and device for protecting sensitive user plane traffic

Inventors: Rajavelsamy Rajadurai (Bangalore, IN); Kundan Tiwari (Bangalore, IN); Varini Gupta (Bangalore, IN); Anikethan Ramakrishna Vijaya Kumar (Bangalore, IN)
Assignee: Samsung Electronics Co., Ltd.
H04W12/106H04W12/033H04W12/069
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,882,451
App. No.
17/911,830
Granted
Jan 23, 2024
Kind
B2
Abstract

Disclosed herein are a communication technique for merging, with an IoT technology, a 5G communication system for supporting a data transmission rate higher than that of a 4G system; and a system therefor. Embodiments herein disclose a method of protecting sensitive user plane traffic in an User Equipment (UE) ( 100 ), the method comprising: transmitting, to a network ( 200 ), by the UE ( 100 ) a first NAS message comprising an indicator indicating that the UE ( 200 ) supports of a secure channel for domain name system (DNS); receiving, from the network ( 200 ), by the UE ( 100 ) a second NAS message including DNS server security information in response to transmitting the first NAS message; and transmitting, to the network ( 200 ), by the UE ( 100 ) the DNS over the secure channel based on the DNS server security information.

Claims (21)

1. A method of a user equipment (UE), the method comprising:

transmitting, to a network, a first non-access stratum (NAS) message including an indicator indicating that the UE supports of domain name system (DNS) over transport layer security (TLS) or DNS over datagram TLS (DTLS);

receiving, from the network, a second NAS message including DNS server security information in response to transmitting the first NAS message; and

transmitting, to the network, a message based on the DNS server security information,

wherein the DNS server security information comprises information on a security mechanism, information on a service port, and information on an authentication domain name.

2. The method of claim 1 , wherein the first NAS message comprises one of a protocol data unit (PDU) session establishment request message, a registration request message, or a service request message.

3. The method of claim 2 , wherein the indicator is included in protocol configuration options in the first NAS message.

4. The method of claim 1 , wherein the second NAS message comprises one of a PDU session establishment accept message, a registration accept message, or a service accept message.

5. The method of claim 4 , wherein the DNS server security information is included in protocol configuration options in the second NAS message.

6. The method of claim 1 , wherein the DNS server security information comprises at least one of information on subject public key (SPKI), information on root certificate, and information on a raw public key.

7. A method of a network, the method comprising:

receiving, from a user equipment (UE), a first non-access stratum (NAS) message including an indicator indicating that the UE supports of domain name system (DNS) over transport layer security (TLS) or DNS over datagram TLS (DTLS);

transmitting, to the UE, a second NAS message including DNS server security information in response to transmitting the first NAS message; and

receiving, from the UE, a message based on the DNS server security information,

wherein the DNS server security information comprises information on a security mechanism, information on a service port, and information on an authentication domain name.

8. The method of claim 7 ,

wherein the first NAS message comprises one of a protocol data unit (PDU) session establishment request message, a registration request message, or a service request message, and

wherein the second NAS message comprises one of a PDU session establishment accept message, a registration accept message, or a service accept message.

9. The method of claim 8 , wherein the indicator is included in protocol configuration options in the first NAS message.

10. The method of claim 8 , wherein the DNS server security information is included in protocol configuration options in the second NAS message.

11. The method of claim 7 , wherein the DNS server security information comprises at least one of information on subject public key (SPKI), information on root certificate, information on a raw public key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2022
From: RAJADURAI, RAJAVELSAMY; TIWARI, KUNDAN; GUPTA, VARINI; KUMAR, ANIKETHAN RAMAKRISHNA VIJAYA
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 061107/0824 →
Priority Claims (2)
IN 202041018540 · Apr 30, 2020 · national
IN 2020 41018540 · Apr 28, 2021 · national
Continuity (1)
Related Publication 20230138033A1 · May 4, 2023