IP Library Granted Patent US 11,166,164
Granted Patent B2
US 11,166,164 · App. 16/721,410 · Granted Nov 2, 2021

Security handling for RRC resume from inactive state

Inventors: Gunnar Mildh (Sollentuna, SE); Icaro L. J. da Silva (Solna, SE)
Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
H04W12/60H04L63/102H04W12/037H04W12/041H04W76/18H04W76/19H04W76/27H04W80/08H04W92/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,166,164
App. No.
16/721,410
Granted
Nov 2, 2021
Kind
B2
Abstract

Methods are provided for a User Equipment, UE, in NR RRC to revert back to an old security context if an RRC Resume procedure from an inactive state fails. In this way, any subsequent Resume attempts by the UE will derive new security keys from the old keys, which means that the keys and security context will be the same for each attempt. In this way, the security context in the UE will remain synchronized with the network security context, regardless of how many attempts the UE has performed (assuming the network does not change the security context when the Resume procedure fails). Alternatively, the UE may store the new security context it derives during the first Resume attempt, and then ensure that it is reused at subsequent Resume attempts.

Claims (17)

1. A method of updating a security context, performed by a wireless device operative in a wireless communication network employing a Radio Resource Control (RRC) protocol, wherein the wireless device in RRC CONNECTED state receives from the network an RRC Suspend message including a security update parameter, and in response to the RRC Suspend message enters an RRC INACTIVE state and stores a first security context, the method comprising, upon attempting to transition to an RRC CONNECTED state:

generating a second security context from the security update parameter received in the RRC Suspend message;

sending to the network an RRC Resume Request message; and

in response to one of:

receiving from the network an RRC Reject message in response to the RRC Resume Request message;

expiration of a timer started upon sending the RRC Resume Request message, without receiving a responsive message from the network; and

performing a cell reselection prior to receiving a message from the network responsive to the RRC Resume Request message,

storing the second security context and utilizing the second security context until confirmed by the network.

2. The method of claim 1 , further comprising, upon again attempting to transition to an RRC CONNECTED state, repeating method steps except for generating the second security context.

3. The method of claim 1 , further comprising, upon receiving an RRC message, other than an RRC Reject message, that is integrity protected using the second security context, discarding the first security context and using the second security context for further communication.

4. The method of claim 1 , further comprising, upon receiving an RRC Setup message indicating the wireless device is to discard a stored Access Stratum message, discarding both first and second security contexts.

5. The method of claim 1 , wherein the security update parameter contained in the RRC Suspend message comprises a chaining counter parameter used for next hop access key derivation.

6. The method of claim 1 , wherein the first and second security contexts comprise one or more cryptographic keys.

7. The method of claim 1 , further comprising, after receiving from the network an RRC Reject message in response to the RRC Resume Request message, obtaining a wait time the wireless device is to wait prior to sending another RRC Resume Request message.

8. The method of claim 7 , wherein the wait time is included in the RRC Reject message.

9. The method of claim 7 , wherein the wait time is a predetermined value.

10. The method of claim 7 , wherein the wait time is obtained from a different message received from the network.

Continuity (3)
Continuation 16386077 · Apr 16, 2019
Provisional Application 62657967 · Apr 16, 2018
Related Publication 20200162897A1 · May 21, 2020