IP Library › Granted Patent US 10,708,772
Granted Patent B2
US 10,708,772 · App. 16/111,979 · Granted Jul 7, 2020

Method and apparatus for security key generation for dual connectivity

Inventors: Stefan Wager (Espoo, FI); Niklas Johansson (Sollentuna, SE); Karl Norrman (Stockholm, SE); Oumer Teyeb (Solna, SE); Vesa Virkki (Espoo, FI)
Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
H04W12/04H04L9/14H04L63/061H04L2209/24H04L2209/80H04W36/0069
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,708,772
App. No.
16/111,979
Granted
Jul 7, 2020
Kind
B2
Abstract

Techniques for the secure generation of a set of encryption keys to be used for communication between a wireless terminal and an assisting base station in a dual-connectivity scenario. An example method includes generating an assisting security key for the assisting base station, based on an anchor base station key. The generated assisting security key is sent to the assisting base station, for use by the assisting base station in encrypting data traffic sent to the wireless terminal or in generating one or more additional assisting security keys for encrypting data traffic sent to the wireless terminal while the wireless terminal is dually connected to the anchor base station and the assisting base station. The anchor base station key, or a key derived from the anchor base station key, is used for encrypting data sent to the wireless terminal by the anchor base station.

Claims (13)

1. A method in a wireless terminal, for security key generation for secured communications between the wireless terminal and an assisting base station, wherein the wireless terminal is dually connected to an anchor base station and the assisting base station, wherein a primary security key is known to the anchor base station and the wireless terminal, the method comprising:

generating an assisting security key, based on the primary security key and a freshness parameter, wherein the freshness parameter has been received in a Radio Resource Control message from the anchor base station; and

using the assisting security key in generating one or more additional assisting security keys for encrypting data traffic, wherein the data traffic is sent from the wireless terminal to the assisting base station while the wireless terminal is dually connected to the anchor base station and the assisting base station.

2. The method of claim 1 , wherein the generated assisting security key comprises a base assisting security key for use in generating one or more additional assisting security keys for encrypting data traffic sent to the wireless terminal by the assisting base station.

3. The method of claim 1 , wherein generating the assisting security key comprises deriving the assisting security key from the primary security key using a one-way function.

4. The method of claim 3 , wherein the one-way function is an HMAC-SHA-256 cryptographic function.

5. A wireless terminal, for security key generation for secured communications between the wireless terminal and an assisting base station, the wireless terminal comprising interface circuitry and processing circuitry, wherein the wireless terminal is configured to be dually connected to an anchor base station and the assisting base station, and wherein the processing circuitry is configured to:

generate an assisting security key, based on a primary security key which is known to the anchor base station and the wireless terminal and a freshness parameter received from the anchor base station in a Radio Resource Control message; and

use the assisting security key in generating one or more additional assisting security keys for encrypting data traffic, wherein the data traffic is sent from the wireless terminal to the assisting base station while the wireless terminal is dually connected to the anchor base station and the assisting base station.

6. The wireless terminal of claim 5 , wherein the processing circuitry is further configured to generate the assisting security key by deriving the assisting security key from the primary security key using a one-way function.

7. The wireless terminal of claim 6 , wherein the one-way function is an HMAC-SHA-256 cryptographic function.

8. The wireless terminal of claim 5 , further configured to store the freshness parameter in a memory of the wireless terminal.

9. The wireless terminal of claim 5 , further configured to store the primary security key and/or the assisting security key in a memory of the wireless terminal.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2018
From: VIRKKI, VESA; WAGER, STEFAN
To: OY L M ERICSSON AB
Reel/Frame 046733/0087 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2018
From: OY L M ERICSSON AB
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 046733/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2018
From: JOHANSSON, NIKLAS; NORRMAN, KARL; TEYEB, OUMER
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 046733/0232 →
Continuity (4)
Continuation 15052514 · Feb 24, 2016
Continuation 14372920
Provisional Application 61758373 · Jan 30, 2013
Related Publication 20180367991A1 · Dec 20, 2018
Cited By (3)
US 12,316,757 US 12,328,305 US 12,598,067