IP Library Granted Patent US 10,116,685
Granted Patent B2
US 10,116,685 · App. 15/121,357 · Granted Oct 30, 2018

Security key derivation in dual connectivity

Inventors: Prateek Basu Mallick (Langen, DE); Joachim Loehr (Wiesbaden, DE)
Assignee: Sun Patent Trust
H04L63/1441H04L63/06H04L63/068H04L63/1416H04W12/04H04W76/19H04L2463/061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,116,685
App. No.
15/121,357
Granted
Oct 30, 2018
Kind
B2
Abstract

The invention relates to methods for establishing a secure communication link between a mobile station and a secondary base station in a mobile communication system. The invention is also providing mobile communication system for performing these methods, and computer readable media the instructions of which cause the mobile communication system to perform the methods described herein. Specifically, the invention suggests that in response to the detected or signaled potential security breach, the master base station increments a freshness counter for re-initializing the communication between the mobile station and the secondary base station; and the mobile station and the secondary base station re-initialize the communication there between. The re-initialization is performed under the control of the master base station and further includes deriving a same security key based on said incremented freshness counter, and establishing the secure communication link utilizing the same, derived security key.

Claims (16)

1. A secondary base station apparatus, comprising:

a transmitter, which, in operation, transmits a change request of a secondary security key to a master base station when a value of a COUNT exceeds a threshold value, wherein the secondary security key is a security key for the secondary base station apparatus;

a receiver, which, in operation, receives from the master base station an updated secondary security key, the updated secondary security key being derived at the master base station using an incremented freshness counter and a currently active security key of the master base station, without refreshing the current active security key of the master base station; and

control circuitry, which, in operation, computes a new encryption key for communication with a mobile terminal using the updated secondary security key.

2. The secondary base station apparatus according to claim 1 , wherein the COUNT is composed of a packet data convergence protocol (PDCP) sequence number and a hyper frame number (HFN) that is shared between the base station and the mobile terminal.

3. The secondary base station apparatus according to claim 1 , wherein the control circuitry, in operation, re-establishes a communication link with the mobile terminal using the updated secondary security key.

4. The secondary base station apparatus according to claim 1 , wherein a RRCConnectionReconfiguration message is transmitted from the base station or the master base station to the mobile terminal after the master base station transmits the updated secondary security key.

5. The secondary base station apparatus according to claim 1 , wherein the freshness counter is a counter value for refresh of the secondary security key.

6. A communication method for a secondary base station apparatus, the communication method comprising:

transmitting a change request of a secondary security key to a master base station when a value of a COUNT exceeds a threshold value, wherein the secondary security key is a security key for the secondary base station apparatus;

receiving from the master base station an updated secondary security key, the updated secondary security key being derived at the master base station using an incremented freshness counter and a currently active security key of the master base station, without refreshing the currently active security key of the master base station; and

computing a new encryption key for communication with a mobile terminal using the updated secondary security key.

7. The communication method according to claim 6 , wherein the COUNT is composed of a packet data convergence protocol (PDCP) sequence number and a hyper frame number (HFN) that is shared between the secondary base station and the mobile terminal.

8. The communication method according to claim 6 , comprising re-establishing a communication link with the mobile terminal using the updated secondary security key.

9. The communication method according to claim 6 , wherein a RRCConnectionReconfiguration message is transmitted from the secondary base station or the master base station to the mobile terminal after the master station transmits the updated secondary security key.

10. The communication method according to claim 6 , wherein the freshness counter is a counter value for refresh of the secondary security key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2016
From: BASU MALLICK, PRATEEK; LOEHR, JOACHIM
To: SUN PATENT TRUST
Reel/Frame 039606/0950 →
Priority Claims (1)
EP 14001067 · Mar 21, 2014 · regional
Continuity (1)
Related Publication 20160366175A1 · Dec 15, 2016
Cited By (1)
US 12,470,918