IP Library Granted Patent US 12,477,342
Granted Patent B2
US 12,477,342 · App. 18/232,227 · Granted Nov 18, 2025

Method for configuring evolved packet system non-access stratum security algorithm and related apparatus

Inventors: Xiange Hu (Shanghai, CN); Linping Yang (Shanghai, CN); Wen Hu (Shanghai, CN); Li Qiang (Beijing, CN)
Assignee: Huawei Technologies Co., Ltd.
H04W12/37H04L63/20H04W12/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,477,342
App. No.
18/232,227
Granted
Nov 18, 2025
Kind
B2
Abstract

This application discloses methods and related apparatuses for configuring an EPS NAS security algorithm in the field of communication technologies. In an example technical solution provided in this application, an access and mobility management function entity determines whether a selected EPS NAS security algorithm has been successfully provided to a terminal device, and after determining that the selected EPS NAS security algorithm has not been successfully provided to the terminal device, the access and mobility management function entity provides the selected EPS NAS security algorithm to the terminal device again.

Claims (56)

1 . A method for configuring an evolved packet system (EPS) non-access stratum (NAS) security algorithm, wherein the method comprises:

receiving, by an access and mobility management function entity, a first registration request message from a terminal device;

determining, in response to the first registration request message by the access and mobility management function entity, whether a selected EPS NAS security algorithm has been successfully provided to the terminal device when a valid 5th generation mobile communication (5G) NAS security context indicated by the terminal device exists on the access and mobility management function entity; and

providing, by the access and mobility management function entity, the selected EPS NAS security algorithm to the terminal device when the access and mobility management function entity determines that the selected EPS NAS security algorithm has not been successfully provided to the terminal device.

2 . The method according to claim 1 , wherein before the determining, by the access and mobility management function entity, whether a selected EPS NAS security algorithm has been successfully provided to the terminal device, the method further comprises:

sending, by the access and mobility management function entity, a first message to the terminal device, wherein the first message comprises an information element of the selected EPS NAS security algorithm; and

the determining, by an access and mobility management function entity, that a selected EPS NAS security algorithm has not been successfully provided to a terminal device comprises: determining, by the access and mobility management function entity, that a first completion message has not been received, wherein the first completion message indicates that the terminal device has received the first message.

3 . The method according to claim 2 , wherein the determining, by the access and mobility management function entity, that a first completion message has not been received comprises:

determining, by the access and mobility management function entity, that the first completion message has not been received within a preset time.

4 . The method according to claim 2 , wherein the first message is a security mode command (SMC) message, and the first completion message is an SMC completion message.

5 . The method according to claim 2 , wherein before the sending, by the access and mobility management function entity, a first message to the terminal device, the method further comprises:

receiving, by the access and mobility management function entity, a second registration request message from the terminal device, wherein the second registration request message comprises a first key set identifier for next generation radio access network (ngKSI), and the first ngKSI indicates that no 5G NAS security context exists on the terminal device.

6 . The method according to claim 1 , wherein the providing, by the access and mobility management function entity, the selected EPS NAS security algorithm for the terminal device comprises:

sending, by the access and mobility management function entity, a first message to the terminal device, wherein the first message comprises an information element of the selected EPS NAS security algorithm, and the first message is an SMC message.

7 . The method according to claim 1 , wherein the method further comprises:

marking, by the access and mobility management function entity, the selected EPS NAS security algorithm as invalid in response to determining that the selected EPS NAS security algorithm has not been successfully provided to the terminal device.

8 . The method according to claim 1 , wherein the method further comprises:

determining, by the access and mobility management function entity, to update the selected EPS NAS security algorithm; and

providing, by the access and mobility management function entity, an updated selected EPS NAS security algorithm for the terminal device.

9 . The method according to claim 8 , wherein the method further comprises:

determining, by the access and mobility management function entity, that the updated selected EPS NAS security algorithm has not been successfully provided to the terminal device; and

providing, by the access and mobility management function entity, the updated selected EPS NAS security algorithm for the terminal device.

10 . The method according to claim 1 , wherein the access and mobility management function entity supports an N26 interface, and the terminal device supports an S1 mode.

11 . A method for configuring an evolved packet system (EPS) non-access stratum (NAS) security algorithm, wherein the method comprises:

determining, by a terminal device, that a selected EPS NAS security algorithm corresponding to a 5th generation mobile communication (5G) NAS security context does not exist;

deleting, by the terminal device, the 5G NAS security context;

sending, by the terminal device, a second message to an access and mobility management function entity, wherein the second message is used to request the 5G NAS security context; and

receiving, by the terminal device, an information element of the selected EPS NAS security algorithm from the access and mobility management function entity.

12 . The method according to claim 11 , wherein before the determining, by a terminal device, that a selected EPS NAS security algorithm corresponding to a 5G NAS security context does not exist, the method further comprises:

receiving, by the terminal device, a third message sent by the access and mobility management function entity, wherein the third message comprises the 5G NAS security context; and

sending, by the terminal device, a third completion message to the access and mobility management function entity, wherein the third completion message indicates that the terminal device has received the third message.

13 . The method according to claim 11 , wherein the determining, by a terminal device, that a selected EPS NAS security algorithm corresponding to a 5G NAS security context does not exist comprises:

determining that a next generation radio access network key set identifier (ngKSI) does not correspond to the selected EPS NAS security algorithm.

14 . The method according to claim 11 , wherein the access and mobility management function entity supports an N26 interface, and the terminal device supports an S1 mode.

15 . An apparatus comprising:

at least one processor, and

at least one memory storing instructions, when executed by the at least one processor, to cause the apparatus to:

receive a first registration request message from a terminal device;

determine, in response to the first registration request message, whether a selected evolved packet system (EPS) non- access stratum (NAS) security algorithm has been successfully provided to the terminal device when a valid 5 th generation mobile communication ( 5 G) NAS security context indicated by the terminal device exists on the apparatus; and

provide the selected EPS NAS security algorithm to the terminal device when the apparatus determines that the selected EPS NAS security algorithm has not been successfully provided to the terminal device.

16 . The apparatus according to claim 15 , wherein the determining that the selected EPS NAS security algorithm has not been successfully provided to a terminal device comprises:

sending a first message to the terminal device, wherein the first message comprises an information element of the selected EPS NAS security algorithm; and

determining that a first completion message has not been received, wherein the first completion message indicates that the terminal device has received the first message.

17 . The apparatus according to claim 16 , wherein the determining that the first completion message has not been received comprises determining that the first completion message has not been received within a preset time.

18 . The apparatus according to claim 16 , wherein the first message is a security mode command (SMC) message, and the first completion message is an SMC completion message.

19 . The apparatus according to claim 15 , wherein the instructions further cause the apparatus to:

mark the selected EPS NAS security algorithm as invalid in response to determining that the selected EPS NAS security algorithm has not been successfully provided to the terminal device.

20 . The apparatus according to claim 15 , wherein the providing the selected EPS NAS security algorithm for the terminal device comprises sending a first message to the terminal device, wherein the first message comprises an information element of the selected EPS NAS security algorithm, and the first message is an SMC message.

21 . The apparatus according to claim 15 , wherein the apparatus supports an N 26 interface, and the terminal device supports an S 1 mode.

22 . An apparatus comprising:

at least one processor and

at least one memory storing instructions, when executed by the at least one processor, to cause the apparatus to:

determine that a selected evolved packet system (EPS) non-access stratum (NAS) security algorithm corresponding to a 5 th generation mobile communication ( 5 G) NAS security context does not exist;

delete the 5 G NAS security context;

send a second message to an access and mobility management function entity, wherein the second message is used to request the 5 G NAS security context; and

receive an information element of the selected EPS NAS security algorithm from the access and mobility management function entity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2023
From: HU, XIANGE; YANG, LINPING; HU, WEN; QIANG, LI
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 065409/0199 →
Priority Claims (1)
CN 202110183922.0 · Feb 10, 2021 · national
Continuity (2)
Continuation PCTCN2022075767 · Feb 10, 2022
Related Publication 20230388802A1 · Nov 30, 2023
References Cited (42)
US 10750366B1 · Gundavelli · 2020 [cited by examiner]
US 10771978B2 · Ben Henda · 2020 [cited by examiner]
US 20160094988A1 · Lee · 2016 [cited by examiner]
US 20170318463A1 · Lee · 2017 [cited by examiner]
US 20180167915A1 · Lee · 2018 [cited by examiner]
US 20180242147A1 · Fransen · 2018 [cited by examiner]
US 20190174449A1 · Shan · 2019 [cited by examiner]
US 20200178076A1 · Ben Henda · 2020 [cited by examiner]
US 20200221281A1 · Rajadurai · 2020 [cited by examiner]
US 20200228987A1 · Ben Henda · 2020 [cited by examiner]
US 20200236544A1 · Kunz · 2020 [cited by examiner]
US 20200236554A1 · Lee · 2020 [cited by examiner]
US 20200323017A1 · Niemi et al. · 2020 [cited by applicant]
US 20200359202A1 · Pan · 2020 [cited by examiner]
US 20200396673A1 · Tiwari · 2020 [cited by examiner]
US 20210160691A1 · Liu · 2021 [cited by examiner]
US 20210258316A1 · Liu · 2021 [cited by examiner]
US 20210314776A1 · Ben Henda · 2021 [cited by examiner]
CN 101835156A · 2010 [cited by applicant]
CN 102595369A · 2012 [cited by applicant]
CN 107786511A · 2018 [cited by applicant]
CN 109644339A · 2019 [cited by applicant]
CN 109819439A · 2019 [cited by applicant]
TW 202027454A · 2020 [cited by applicant]
WO 2020065132A1 · 2020 [cited by applicant]
Yu, Da; Wen, Wushao. Non-access-stratum request attack in E-UTRAN. 2012 Computing, Communication and Applications Conference, https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=6154001 (Year: 2012). [cited by examiner]
Hu, Xinxin et al. A Systematic Analysis Method for 5G Non-Access Stratum Signalling Security. IEEE Access, vol. 7. https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=8817957 (Year: 2019). [cited by examiner]
Ahmad, Ijaz et al. Security for 5G and Beyond. IEEE Communications Surveys & Tutorials, vol. 21, Issue 4. https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=8712553 (Year: 2019). [cited by examiner]
Lescuyer, Pierre; Lucidarme, Thierry. Life in EPS Networks. Evolved Packet System (EPS): The LTE and SAE Evolution of 3G UMTS, pp. 229-280. https://ieeexplore.ieee.org/xpl/ebooks/bookPdfWithBanner.jsp?fileName=8041593.p… [cited by examiner]
Forsberg, Dan et al. Interworking Security between EPS and Other Systems. LTE Security, pp. 183-214. https://ieeexplore.ieee.org/xpl/ebooks/bookPdfWithBanner.jsp?fileName=8043900.pdf&bkn=8040448&pdfType=chapter (Year: 2… [cited by examiner]
Forsberg, Dan et al. EPS Security Architecture, pp. 83-107. https://ieeexplore.ieee.org/xpl/ebooks/bookPdfWithBanner.jsp?fileName=8043541.pdf&bkn=8040448&pdfType=chapter (Year: 2013). [cited by examiner]
3GPP TS 33.501 V17.0.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17),” Dec. 2020, 253 pages. [cited by applicant]
3GPP TS 33.401 V15.11.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3GPP System Architecture Evolution (SAE); Security architecture (Release 15),” Mar. 2020, 163 page… [cited by applicant]
3GPP TS 24.301 V17.1.0, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS); Stage 3 (Release 17),” Dec. 2020,… [cited by applicant]
International Search Report and Written Opinion in International AppIn. No. PCT/CN2022/075767, mailed on May 6, 2022, 18 pages (with English translation). [cited by applicant]
Office Action in Taiwanese Appln. No. 111104243, mailed on Sep. 26, 2022, 14 pages (with English translation). [cited by applicant]
Media Tek Inc., “Recovery from NASC verification failure,” 3GPP TSG-SA3 Meeting #98e, S3-200320, e-meeting, Feb. 2-6, 2020, 3 pages. [cited by applicant]
Huawei et al., “Initiate SMC to provide Selected EPS NAS security algorithms,” 3GPP TSG-CT WG1 Meeting #128-e, C1-210980, Electronic meeting, Feb. 25-Mar. 5, 2021, 5 pages. [cited by applicant]
Huawei et al., “Initiate SMC to provide Selected EPS NAS security algorithms,” 3GPP TSG-CT Meeting #128-e, C1-211265, Electronic meeting, Feb. 25-Mar. 5, 2021, 5 pages. [cited by applicant]
Extended European Search Report in European Appln No. 22752316.4, dated Jun. 4, 2024, 10 pages. [cited by applicant]
3GPP TS 24.501 V17.1.0, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Non-Access-Stratum (NAS) protocol for 5G System (5GS); Stage 3; (Release 17),” Dec. 2020, 74 pages. [cited by applicant]
Office Action in Japanese Appln. No. 2023-548586, mailed on Aug. 27, 2024, 12 pages (with English Translation). [cited by applicant]