IP Library › Granted Patent US 12,549,365
Granted Patent B2
US 12,549,365 · App. 18/447,098 · Granted Feb 10, 2026

Apparatus, method, and computer program

Inventors: Markus Staufer (Munich, DE); Peter Schneider (Munich, DE); Ranganathan Mavureddi Dhanasekaran (Munich, DE)
Assignee: Nokia Technologies Oy
H04L9/321H04L9/0819
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,365
App. No.
18/447,098
Granted
Feb 10, 2026
Kind
B2
Abstract

There is provided an apparatus, method and computer program for causing a first apparatus to: obtain an identifier of a cryptographic key according to a first security communication protocol; signal, to a second apparatus, a first authentication request according to a second security communication protocol, the first authentication request comprising the identifier of the cryptographic key and a first verifying information according to a second security communication protocol, wherein the first verifying information comprises a first value calculated using the cryptographic key; receive, from the second apparatus, an authentication response according to the second security communication protocol, the authentication response comprising a second verifying information according to the second security communication protocol, wherein the second verifying information comprises a second value; and verify the second apparatus for the second security communication protocol using the second value and the cryptographic key.

Claims (50)

1 . A method, performed by a first apparatus, comprising:

obtaining an identifier of a cryptographic key according to a first security communication protocol;

receiving a first authentication request from a second apparatus, wherein the first apparatus is a Personal Internet of Things network element with gateway capability (PEGC) and the second apparatus is a Personal Internet of Things network element (PINE);

signaling, in response to the first authentication request, a second authentication request according to a second security communication protocol to a third apparatus, the second authentication request comprising the identifier of the cryptographic key and a first verifying information according to the second security communication protocol, wherein the first verifying information comprises a first value calculated using the cryptographic key, wherein the third apparatus is an Authentication, Authorization, and Accounting (AAA) server, wherein the first security communication protocol is an Authentication and Key Management for Applications (AKMA) protocol and the second security communication protocol is an Internet Protocol (IP)-based security communication protocol, and wherein the IP-based security communication protocol is at least one of a Remote Authentication Dial-In User Service (RADIUS) protocol, an Internet Key Exchange (IKE) protocol, and an IP Security (IPSec) protocol;

receiving, from the third apparatus, a first authentication response according to the second security communication protocol, the first authentication response comprising a second verifying information according to the second security communication protocol, wherein the second verifying information comprises a second value;

verifying the first authentication response using the second value and the cryptographic key; and

signaling, in response to the received first authentication response, a second authentication response to the second apparatus.

2 . The method of claim 1 , further comprising, prior to the step of signaling the second authentication request to the third apparatus:

signaling, to the third apparatus using signaling according to the second security communication protocol, a request to use signaling according to the second security communication protocol to exchange verifying information associated with the first security communication protocol; and

receiving, from the third apparatus using signaling according to the second security communication protocol, an acceptance of the request to use the signaling according to the second security communication protocol to exchange verifying information associated with the first security communication protocol.

3 . A method for exchanging authentication and authorization messages in a Personal Internet of Things Network (PIN), the method performed by a third apparatus, the method comprising:

receiving, from a first apparatus, a second authentication request according to a second security communication protocol in response to the first apparatus receiving a first authentication request from a second apparatus, the second authentication request comprising an identifier of a cryptographic key according to a first security communication protocol and a first verifying information according to the second security communication protocol, wherein the first verifying information comprises a first value, wherein the first apparatus is a Personal Internet of Things network element with gateway capability (PEGC), the second apparatus is a Personal Internet of Things network element (PINE), and the third apparatus is an Authentication, Authorization, and Accounting (AAA) server;

obtaining the cryptographic key using the identifier of the cryptographic key;

verifying the first value using the cryptographic key identified by the identifier of the cryptographic key;

deriving a second verifying information according to the second security communication protocol, wherein the second verifying information comprises a second value calculated using the cryptographic key identified by the identifier of the cryptographic key, wherein the first security communication protocol is an Authentication and Key Management for Applications (AKMA) protocol and the second security communication protocol is an Internet Protocol (IP)-based security communication protocol, and wherein the IP-based security communication protocol is at least one of a Remote Authentication Dial-In User Service (RADIUS) protocol, an Internet Key Exchange (IKE) protocol, and an IP Security (IPSec) protocol; and

signaling, to the first apparatus, an authentication response that comprises at least the second verification information.

4 . The method of claim 3 , wherein the step of obtaining the cryptographic key comprises:

providing the identifier of the cryptographic key with a request for the cryptographic key to a key storage server configured to operate according to the first security communication protocol; and

receiving, from the key storage server, the cryptographic key corresponding to the identifier of the cryptographic key.

5 . The method of claim 4 , further comprising using the cryptographic key to verify the first value prior to using the received cryptographic key to derive the second verifying information.

6 . The method of claim 3 , further comprising, prior to the step of receiving the second authentication request:

receiving, from the first apparatus using signaling according to the second security communication protocol, a request to use signaling according to the second security communication protocol to exchange verifying information according to the first security communication protocol; and

signaling, to the first apparatus using signaling according to the second security communication protocol, an acceptance of the request to use the signaling according to the second security communication protocol to exchange verifying information associated with the first security communication protocol.

7 . A first apparatus comprising:

at least one processor; and

at least one memory storing instructions that, when executed by the at least one processor, causes the first apparatus to perform:

obtaining an identifier of a cryptographic key according to a first security communication protocol;

receiving a first authentication request from a second apparatus, wherein the first apparatus is a Personal Internet of Things network element with gateway capability PEGC) and the second apparatus is a Personal Internet of Things network element PINE);

signaling, in response to the first authentication request, a second authentication request according to a second security communication protocol to a third apparatus, the second authentication request comprising the identifier of the cryptographic key and a first verifying information according to the second security communication protocol, wherein the first verifying information comprises a first value calculated using the cryptographic key, wherein the third apparatus is an Authentication, Authorization, and Accounting (AAA) server, wherein the first security communication protocol is an Authentication and Key Management for Applications (AKMA) protocol and the second security communication protocol is an Internet Protocol (IP)-based security communication protocol, and wherein the IP-based security communication protocol is at least one of a Remote Authentication Dial-In User Service (RADIUS) protocol, an Internet Key Exchange (IKE) protocol, and an IP Security (IPSec) protocol;

receiving, from the third apparatus, a first authentication response according to the second security communication protocol, the first authentication response comprising a second verifying information according to the second security communication protocol, wherein the second verifying information comprises a second value;

verifying the first authentication response using the second value and the cryptographic key; and

signaling, in response to the received first authentication response, a second authentication response to the second apparatus.

8 . The first apparatus of claim 7 , further caused to perform, prior to the step of signaling the second authentication request to the third apparatus:

signaling, to the third apparatus using signaling according to the second security communication protocol, a request to use signaling according to the second security communication protocol to exchange verifying information associated with the first security communication protocol; and

receiving, from the third apparatus using signaling according to the second security communication protocol, an acceptance of the request to use the signaling according to the second security communication protocol to exchange verifying information associated with the first security communication protocol.

9 . A third apparatus comprising:

at least one processor; and

at least one memory storing instructions that, when executed by the at least one processor, causes the third apparatus to perform:

receiving, from a first apparatus in a Personal Internet of Things Network (PIN), a second authentication request according to a second security communication protocol in response to the first apparatus receiving a first authentication request from a second apparatus, the second authentication request comprising an identifier of a cryptographic key according to a first security communication protocol and a first verifying information according to the second security communication protocol, wherein the first verifying information comprises a first value, wherein the first apparatus is a Personal Internet of Things network element with gateway capability (PEGC), the second apparatus is a Personal Internet of Things network element (PINE), and the third apparatus is an Authentication, Authorization, and Accounting (AAA) server;

obtaining the cryptographic key using the identifier of the cryptographic key;

verifying the first value using the cryptographic key identified by the identifier of the cryptographic key;

deriving a second verifying information according to the second security communication protocol, wherein the second verifying information comprises a second value calculated using the cryptographic key identified by the identifier of the cryptographic key, wherein the first security communication protocol is an Authentication and Key Management for Applications (AKMA) protocol and the second security communication protocol is an Internet Protocol (IP)-based security communication protocol, and wherein the IP-based security communication protocol is at least one of a Remote Authentication Dial-In User Service (RADIUS) protocol, an Internet Key Exchange (IKE) protocol, and an IP Security (IPSec) protocol; and

signaling to the first apparatus an authentication response that comprises at least the second verification information.

10 . The third apparatus of claim 9 , wherein obtaining the cryptographic key comprises:

providing the identifier of the cryptographic key with a request for the cryptographic key to a key storage server configured to operate according to the first security communication protocol; and

receiving, from the key storage server, the cryptographic key corresponding to the identifier of the cryptographic key.

11 . The third apparatus of claim 10 , further caused to perform using the cryptographic key to verify the first value prior to using the received cryptographic key to derive the second verifying information.

12 . The third apparatus of claim 9 , further caused to perform, prior to receiving the second authentication request:

receiving, from the first apparatus using signaling according to the second security communication protocol, a request to use signaling according to the second security communication protocol to exchange verifying information according to the first security communication protocol; and

signaling, to the first apparatus using signaling according to the second security communication protocol, an acceptance of the request to use the signaling according to the second security communication protocol to exchange verifying information associated with the first security communication protocol.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2023
From: STAUFER, MARKUS; SCHNEIDER, PETER; MAVUREDDI DHANASEKARAN, RANGANATHAN
To: NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
Reel/Frame 065673/0748 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2023
From: NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
To: NOKIA TECHNOLOGIES OY
Reel/Frame 065673/0751 →
Continuity (2)
Provisional Application 63371305 · Aug 12, 2022
Related Publication 20240056302A1 · Feb 15, 2024
References Cited (27)
US 12267676B2 · Rajadurai · 2025 [cited by examiner]
US 20220116774A1 · Rajadurai · 2022 [cited by examiner]
US 20220150696A1 · Rajadurai · 2022 [cited by examiner]
US 20230397007A1 · Wifvesson · 2023 [cited by examiner]
US 20240314534A1 · Shi · 2024 [cited by examiner]
US 20250168635A1 · Stojanovski · 2025 [cited by examiner]
WO WO2023175461A1 · 2023 [cited by examiner]
ETSI TS 133 535 v17.6.0 pp. 1-26 (Jul. 2022) (Year: 2022). [cited by examiner]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on personal IoT networks security aspects (Release 18)”, 3GPP TR 33.882, V0.1.0, Jun. 2022, pp. 1-8. [cited by applicant]
PCT Application No. PCT/EP2022/072735, “Methods and Devices for Uplink Transmission”, filed on Aug. 12, 2022, pp. 1-43. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Generic Authentication Architecture (GAA); Access to network application functions using Hypertext Transfer Protocol over T… [cited by applicant]
Rigney et al., “Remote Authentication Dial In User Service (RADIUS)”, RFC 2865, Network Working Group, Jun. 2000, pp. 1-76. [cited by applicant]
Aboba et al., “RADIUS (Remote Authentication Dial In User Service) Support For Extensible Authentication Protocol (EAP)”, RFC 3579, Network Working Group, Sep. 2003, pp. 1-46. [cited by applicant]
Zorn, “Microsoft Vendor-specific RADIUS Attributes”, RFC 2548, Network Working Group, Mar. 1999, pp. 1-41. [cited by applicant]
Kaufman et al., “Internet Key Exchange Protocol Version 2 (IKEv2)”, RFC 7296, Internet Engineering Task Force (IETF), Oct. 2014, pp. 1-42. [cited by applicant]
Fairhurst, “Datagram Congestion Control Protocol (DCCP) Simultaneous Open Technique to Facilitate NAT/Middlebox Traversal”, RFC 5596, Network Working Group, Sep. 2009, pp. 1-25. [cited by applicant]
Aboba et al., “Extensible Authentication Protocol (EAP)”, RFC 3748, Network Working Group, Jun. 2004, pp. 1-67. [cited by applicant]
Aboba et al., “Extensible Authentication Protocol (EAP) Key Management Framework”, RFC 5247, Network Working Group, Aug. 2008, pp. 1-79. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Authentication and Key Management for Applications (AKMA) based on 3GPP credentials in the 5G System (5GS) (Release 17)”, 3… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17)”, 3GPP TS 33.501, V17.6.0, Jun. 2022, pp. 1-292. [cited by applicant]
“New solution to KI#1: EAP based PIN deviceauthentication using AKMA”, 3GPP TSG-SA3 Meeting #108Adhoc-e, S3-222571, Agenda: 5.10, Nokia, Oct. 10-14, 2022, 2 pages. [cited by applicant]
“New solution using AKMA”, 3GPP TSG-SA3 Meeting #109, S3-223309, Agenda: 5.10, Nokia, Nov. 14-18, 2022, 4 pages. [cited by applicant]
Extended European Search Report received for corresponding European Patent Application No. 23190075.4, dated Dec. 13, 2023, 7 pages. [cited by applicant]
Huang et al., “Authentication Mechanisms in the 5G System”, Journal of ICT Standardization, vol. 9, No. 2, 2021, pp. 61-78. [cited by applicant]
“pCR to TS 33.535: Update of the AKMA procedures”, 3GPP TSG-SA3 Meeting #98e, S3-200296, Agenda: 3.9, Ericsson, Mar. 2-6, 2020, 4 pages. [cited by applicant]
Extended European Search Report received for corresponding European Patent Application No. 23190439.2, dated Dec. 20, 2023, 14 pages. [cited by applicant]
Yang et al., “Formal Analysis of 5G AKMA”, International Symposium on Dependable Software Engineering: Theories, Tools, and Applications, Nov. 18, 2021, pp. 102-121. [cited by applicant]