IP Library Granted Patent US 10,085,148
Granted Patent B2
US 10,085,148 · App. 15/672,636 · Granted Sep 25, 2018

Method and apparatus for new key derivation upon handoff in wireless networks

Inventor: Michaela Vanderveen (Tracy, CA)
Assignee: QUALCOMM Incorporate
H04W12/04H04L9/083H04L9/0841H04L2209/80H04L2463/061H04W8/26H04W36/08H04W74/004H04W76/10H04W88/08H04W92/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,085,148
App. No.
15/672,636
Granted
Sep 25, 2018
Kind
B2
Abstract

A novel key management approach is provided for securing communication handoffs between an access terminal and two access points. An access terminal establishes a secure communication session with a first access point based on a first master session key based on a master transient key. The access terminal obtains a second access point identifier associated with a second access point and sends a message associated with a handoff to either the first access point or the second access point. The access terminal generates a second master session key based on at least the master transient key and the second access point identifier. The second master session key is used for secure communications with the second access point in connection with an intra-authenticator handoff from the first access point to the second access point. The access terminal then moves the secure communication session to the second access point.

Claims (66)

1. A method of wireless communication at an access terminal, comprising:

deriving a master transient key based on a master key and an identifier;

establishing a secure communication session with a first access point based on a first master session key that is based on the master transient key;

obtaining a second access point identifier associated with a second access point;

sending a message to at least one of the first access point or the second access point, the message being associated with a handoff of the secure communication session to the second access point;

generating a second master session key based on at least the master transient key and the second access point identifier, wherein the second master session key is different than the first master session key, wherein the second master session key is used for secure communications with the second access point in connection with an intra-authenticator handoff from the first access point to the second access point associated with a same authenticator in a cellular network; and

moving, in a handoff, the secure communication session to the second access point, wherein the second master session key is used in the secure communication session with the second access point.

2. The method of claim 1 , wherein the same authenticator comprises a same mobility management entity (MME) in the cellular network.

3. The method of claim 1 , further comprising:

generating the first master session key based on the master transient key,

wherein the secure communication session with the first access point is established using the first master session key.

4. The method of claim 1 , wherein the master transient key is generated based on a top-level master key associated with the access terminal.

5. The method of claim 1 , wherein the master transient key is based on an access terminal identifier.

6. The method of claim 1 , wherein the second master session key corresponds to a third master session key at the second access point generated independently from the second master session key at the access terminal.

7. The method of claim 1 , wherein the message is sent prior to generating the second master session key.

8. The method of claim 1 , wherein the access terminal first communicates with the second access point using the second master session key after the second access point receives the second master session key from a separate source.

9. An apparatus for wireless communication at a wireless terminal, comprising:

means for deriving a master transient key based on a master key and an identifier;

means for establishing a secure communication session with a first access point based on a first master session key that is based on the master transient key;

means for obtaining a second access point identifier associated with a second access point;

means for sending a message to at least one of the first access point or the second access point, the message being associated with a handoff of the secure communication session to the second access point;

means for generating a second master session key based on at least the master transient key and the second access point identifier, wherein the second master session key is different than the first master session key, wherein the second master session key is used for secure communications with the second access point in connection with an intra-authenticator handoff from the first access point to the second access point associated with a same authenticator in a cellular network; and

means for moving, in a handoff, the secure communication session to the second access point, wherein the second master session key is used in the secure communication session with the second access point.

10. The apparatus of claim 9 , wherein the same authenticator comprises a same mobility management entity (MME) in the cellular network.

11. The apparatus of claim 9 , further comprising:

means for generating the first master session key based on the master transient key,

wherein the secure communication session with the first access point is established using the first master session key.

12. The apparatus of claim 9 , wherein the master transient key is generated based on a top-level master key associated with the access terminal.

13. The apparatus of claim 9 , wherein the master transient key is based on an access terminal identifier.

14. The apparatus of claim 9 , wherein the second master session key corresponds to a third master session key at the second access point generated independently from the second master session key at the access terminal.

15. The apparatus of claim 9 , wherein the message is sent prior to generating the second master session key.

16. The apparatus of claim 9 , wherein the access terminal first communicates with the second access point using the second master session key after the second access point receives the second master session key from a separate source.

17. An apparatus for wireless communication at a wireless terminal, comprising:

a memory; and

at least one processor coupled to the memory and configured to cause the apparatus to:

derive a master transient key based on a master key and an identifier;

establish a secure communication session with a first access point based on a first master session key that is based on the master transient key;

obtain a second access point identifier associated with a second access point;

send a message to at least one of the first access point or the second access point, the message being associated with a handoff of the secure communication session to the second access point;

generate a second master session key based on at least the master transient key and the second access point identifier, wherein the second master session key is different than the first master session key, wherein the second master session key is used for secure communications with the second access point in connection with an intra-authenticator handoff from the first access point to the second access point associated with a same authenticator in a cellular network; and

move, in a handoff, the secure communication session to the second access point, wherein the second master session key is used in the secure communication session with the second access point.

18. The apparatus of claim 17 , wherein the same authenticator comprises a same mobility management entity (MME) in the cellular network.

19. The apparatus of claim 17 , wherein the at least one processor is further configured to cause the apparatus to:

generate the first master session key based on the master transient key,

wherein the secure communication session with the first access point is established using the first master session key.

20. The apparatus of claim 17 , wherein the master transient key is generated based on a top-level master key associated with the access terminal.

21. The apparatus of claim 17 , wherein the master transient key is based on an access terminal identifier.

22. The apparatus of claim 17 , wherein the second master session key corresponds to a third master session key at the second access point generated independently from the second master session key at the access terminal.

23. The apparatus of claim 17 , wherein the message is sent prior to generating the second master session key.

24. The apparatus of claim 17 , wherein the access terminal first communicates with the second access point using the second master session key after the second access point receives the second master session key from a separate source.

25. A non-transitory computer-readable medium storing computer executable code for wireless communication at a wireless terminal, comprising code to:

derive a master transient key based on a master key and an identifier;

establish a secure communication session with a first access point based on a first master session key that is based on the master transient key;

obtain a second access point identifier associated with a second access point;

send a message to at least one of the first access point or the second access point, the message being associated with a handoff of the secure communication session to the second access point;

generate a second master session key based on at least the master transient key and the second access point identifier, wherein the second master session key is different than the first master session key, wherein the second master session key is used for secure communications with the second access point in connection with an intra-authenticator hand off from the first access point to the second access point associated with a same authenticator in a cellular network; and

move, in a handoff, the secure communication session to the second access point, wherein the second master session key is used in the secure communication session with the second access point.

26. The computer-readable medium of claim 25 , wherein the same authenticator comprises a same mobility management entity (MME) in the cellular network.

27. The computer-readable medium of claim 25 , further comprising code to:

generate the first master session key based on the master transient key,

wherein the secure communication session with the first access point is established using the first master session key.

28. The computer-readable medium of claim 25 , wherein the master transient key is generated based on a top-level master key associated with the access terminal.

29. The computer-readable medium of claim 25 , wherein the master transient key is based on an access terminal identifier.

30. The computer-readable medium of claim 25 , wherein the second master session key corresponds to a third master session key at the second access point generated independently from the second master session key at the access terminal.

31. The computer-readable medium of claim 25 , wherein the message is sent prior to generating the second master session key.

32. The computer-readable medium of claim 25 , wherein the access terminal first communicates with the second access point using the second master session key after the second access point receives the second master session key from a separate source.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 9, 2017
From: VANDERVEEN, MICHAELA
To: QUALCOMM INCORPORATED
Reel/Frame 043249/0140 →
Continuity (3)
Continuation 12109082 · Apr 24, 2008
Provisional Application 60914033 · Apr 26, 2007
Related Publication 20170339558A1 · Nov 23, 2017