IP Library › Granted Patent US 12,206,680
Granted Patent B2
US 12,206,680 · App. 18/499,713 · Granted Jan 21, 2025

Incorporating network policies in key generation

Inventors: Soo Bum Lee (San Diego, CA); Adrian Edward Escott (Reading, GB); Anand Palanigounder (San Diego, CA)
Assignee: QUALCOMM Incorporated
H04L63/123H04L63/062H04L63/20H04W12/04H04W12/10H04W76/10H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,206,680
App. No.
18/499,713
Granted
Jan 21, 2025
Kind
B2
Abstract

The present disclosure provides techniques that may be applied, for example, for providing network policy information in a secure manner. In some cases, a UE may receive a first message for establishing a secure connection with a network, wherein the first message comprises network policy information, generate a first key based in part on the network policy information, and use the first key to verify the network policy information.

Claims (46)

1. A method for wireless communication by a user equipment (UE), comprising:

receiving network policy information from a network, wherein the network policy information comprises security features of the network;

generating an access and mobility management function (AMF) key by a key derivation function (KDF), wherein a security anchor function (SEAF) key and the network policy information are inputs into the KDF;

generating an integrity protection key based at least in part on the AMF key; and

verifying an integrity of the network policy information using the integrity protection key.

2. The method of claim 1 , wherein receiving network policy information comprises receiving a non-access stratum (NAS) message comprising the network policy information.

3. The method of claim 2 , wherein verifying the integrity of the network policy information comprises verifying an integrity of the NAS message using the integrity protection key.

4. The method of claim 3 , further comprising establishing a secure connection with the network if the integrity of the NAS message is verified.

5. The method of claim 1 , further comprising performing at least one of an authentication or registration procedure with the SEAF, prior to receiving the network policy information, wherein the SEAF key is established based on at least one of the authentication or registration procedure.

6. The method of claim 1 , wherein:

the network policy information is received from an access and mobility management function (AMF) in the network; and

the method further comprises establishing a secure connection with the network by sending a message to the AMF.

7. The method of claim 6 , wherein the message is a SMC complete message.

8. The method of claim 1 , further comprising sending UE policy information to the network, wherein the UE policy information comprises at least one of UE capability information or UE security information.

9. The method of claim 8 , wherein generating the AMF key is based on the UE policy information sent to the network.

10. A method for wireless communication by a security anchor function (SEAF), comprising:

generating an access and mobility management function (AMF) key for an AMF node in a network by inputting a SEAF key and network policy information into a key derivation function (KDF), wherein the network policy information comprises security features of the network; and

sending the AMF key to the AMF node.

11. The method of claim 10 , further comprising participating in at least one of an authentication procedure or registration procedure with a UE prior to generating the AMF key, wherein the SEAF is established based on at least one of the authentication procedure or the registration procedure.

12. The method of claim 10 , further comprising sending the network policy information to the AMF node.

13. The method of claim 10 , further comprising receiving user equipment (UE) policy information of a UE, wherein the UE policy information comprises at least one of UE capability information or UE security information.

14. The method of claim 13 , wherein the AMF key is generated further based on the UE policy information.

15. An apparatus for wireless communication by a user equipment (UE), comprising:

one or more processors individually or collectively configured to execute instructions stored on one or more processors and to cause the UE to:

receive network policy information from a network, wherein the network policy information comprises security features of the network;

generate an access and mobility management function (AMF) key by a key derivation function (KDF), wherein a security anchor function (SEAF) key and the network policy information are inputs into the KDF;

generate an integrity protection key based at least in part on the AMF key; and

verify an integrity of the network policy information using the integrity protection key.

16. The apparatus of claim 15 , wherein the one or more processors are further configured to cause the UE to receive the network policy information in a non-access stratum (NAS) message.

17. The apparatus of claim 16 , wherein, in order to verify the integrity of the network policy information, the one or more processors are further configured to cause the UE to verify an integrity of the NAS message using the integrity protection key.

18. The apparatus of claim 17 , wherein the one or more processors are further configured to cause the UE to establish a secure connection with the network if the integrity of the NAS message is verified.

19. The apparatus of claim 15 , wherein the one or more processors are further configured to cause the UE to perform at least one of an authentication or registration procedure with the SEAF, prior to receiving the network policy information, wherein the SEAF key is established based on at least one of the authentication or registration procedure.

20. The apparatus of claim 15 , wherein the one or more processors are further configured to cause the UE to:

receive the network policy information from an access and mobility management function (AMF) in the network; and

establish a secure connection with the network by sending a message to the AMF.

21. The apparatus of claim 20 , wherein the message is a SMC complete message.

22. The apparatus of claim 15 , wherein the one or more processors are further configured to cause the UE to send UE policy information to the network, wherein the UE policy information comprises at least one of UE capability information or UE security information.

23. The apparatus of claim 22 , wherein the one or more processors are further configured to cause the UE to generate the AMF key based on the UE policy information sent to the network.

24. An apparatus for wireless communication by a security anchor function (SEAF), comprising:

one or more processors individually or collectively configured to execute instructions stored on one or more processors and to cause the SEAF to:

generate an access and mobility management function (AMF) key for an AMF node in a network by inputting a SEAF key and network policy information into a key derivation function (KDF), wherein the network policy information comprises security features of the network; and

send the AMF key to the AMF node.

25. The apparatus of claim 24 , wherein the one or more processors are further configured to cause the SEAF to participate in at least one of an authentication procedure or registration procedure with a UE prior to generating the AMF key, wherein the SEAF is established based on at least one of the authentication procedure or the registration procedure.

26. The apparatus of claim 24 , wherein the one or more processors are further configured to cause the SEAF to send the network policy information to the AMF node.

27. The apparatus of claim 24 , wherein the one or more processors are further configured to cause the SEAF to receive user equipment (UE) policy information of a UE, wherein the UE policy information comprises at least one of UE capability information or UE security information.

28. The apparatus of claim 27 , wherein the AMF key is generated further based on the UE policy information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2023
From: LEE, SOO BUM; ESCOTT, ADRIAN EDWARD; PALANIGOUNDER, ANAND
To: QUALCOMM INCORPORATED
Reel/Frame 065423/0980 →
Continuity (3)
Continuation 16146709 · Sep 28, 2018
Provisional Application 62567086 · Oct 2, 2017
Related Publication 20240064154A1 · Feb 22, 2024
References Cited (50)
US 10057053B2 · Campagna · 2018 [cited by examiner]
US 10219292B2 · Damnjanovic et al. · 2019 [cited by applicant]
US 10984128B1 · Hoffer · 2021 [cited by applicant]
US 20100306076A1 · Taveau et al. · 2010 [cited by applicant]
US 20110255691A1 · Escott et al. · 2011 [cited by applicant]
US 20150104017A1 · Halford · 2015 [cited by examiner]
US 20150312819A1 · Yang et al. · 2015 [cited by applicant]
US 20170079059A1 · Li et al. · 2017 [cited by applicant]
US 20170324652A1 · Lee et al. · 2017 [cited by applicant]
US 20180013568A1 · Muhanna · 2018 [cited by examiner]
US 20180062847A1 · Mildh · 2018 [cited by examiner]
US 20180109538A1 · Kumar · 2018 [cited by examiner]
US 20180367303A1 · Velev et al. · 2018 [cited by applicant]
US 20190104134A1 · Lee et al. · 2019 [cited by applicant]
US 20210153010A1 · Torvinen et al. · 2021 [cited by applicant]
AU 2017216479A1 · 2017 [cited by applicant]
CO 5680123A1 · 2006 [cited by applicant]
TW 201404191A · 2014 [cited by applicant]
WO 2011130684A1 · 2011 [cited by applicant]
WO 2014109283A1 · 2014 [cited by applicant]
WO 2016064544A1 · 2016 [cited by applicant]
WO 2017142362A1 · 2017 [cited by applicant]
Chen, Fatang; Yuan, Jinlong. Enhanced Key Derivation Function of HMAC-SHA-256 Algorithm in LTE Network. 2012 Fourth International Conference on Multimedia Information Networking and Security. https://ieeexplore.ieee.org… [cited by examiner]
Chen, Yi-Ruei; Tzeng, Wen-Guey. Efficient and Provably-Secure Group Key Management Scheme Using Key Derivation. 12 IEEE 11th International Conference on Trust, Security and Privacy in Computing and Communications. https… [cited by examiner]
Kukreja, Deepika et al. Security enhancement by detection and penalization of malicious nodes in wireless networks. 2014 International Conference on Signal Processing and Integrated Networks (SPIN). https://ieeexplore.i… [cited by examiner]
Barskar, Raju et al. Secure key management in vehicular ad-hoc network: A review. 2016 International Conference on Signal Processing, Communication, Power and Embedded System (SCOPES). https://ieeexplore.ieee.org/stamp/… [cited by examiner]
Fu, Anmin et al. EKMP: An enhanced key management protocol for IEEE 802.16m. 2011 IEEE Wireless Communications and Networking Conference. https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=5779291 (Year: 2011). [cited by examiner]
3GPP TR 33.899: “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on the Security Aspects of the Next Generation System (Release 14)”, 3GPP Standard; S3-172095, Techni… [cited by applicant]
3GPP TS 33.401: “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3GPP System Architecture Evolution (SAE); Security architecture (Release 9)”, 3GPP standard; 3rd Generation… [cited by applicant]
3GPP TS 33.501: “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security Architecture and Procedures for 5G System (Release 15)”, 3GPP Draft; S31170316 33501, 3GPP TS 33.5… [cited by applicant]
802.15.6-2012—IEEE Standard for Local and Metropolitan Area Networks—Part 15.6: Wireless Body Area Networks. https://ieeexplore.ieee.org/starnp/starnp.jsp?tp=arnurnber=6161600 (Year: 2012). [cited by applicant]
Badra M., et al., “Key-Exchange Authentication using Shared Secrets”, Computer, vol. 39, Issue. 3, 2006, pp. 58-66. [cited by applicant]
Dohndorf O., et al., “Lightweight Policy-Based Management of Quality-Assured, Device-Based Service Systems”, 2010 IEEE 24th International Conference on Advanced Information Networking and Applications Workshops, 2010, p… [cited by applicant]
Huawei, et al., “Solution for IMSI Privacy While Meeting LI Requirements”, 3GPP TSG SA WG3 #87, S3-171510, Ljubljana, Slovenia, May 19, 2017, 4 Pages, May 15, 2017-May 19, 2017, searched on [Aug. 16, 2022]. [cited by applicant]
International Preliminary Report on Patentability—PCT/US2018/053661, The International Bureau of WIPO—Geneva, Switzerland, Apr. 16, 2020. [cited by applicant]
International Search Report and Written Opinion—PCT/US2018/053661—ISA/EPO—Jan. 16, 2019. [cited by applicant]
Law Y.W., et al., “Secure k-Connectivity Properties of Wireless Sensor Networks”, 2007 IEEE International Conference on Mobile Adhoc and Sensor Systems, 2007, 6 Pages. [cited by applicant]
Ma Z., et al., “Provably Secure Trusted Access Protocol for WLAN Mesh Networks”, 2008 IEEE/IFIP International Conference on Embedded and Ubiquitous Computing, 2008, pp. 43-48. [cited by applicant]
NCSC (CESG): “[MCSEC] Temporary Group Call Security Solution—add Group Call User”, S3-170316, 3GPP TSG SA WG3 (Security) Meeting #86, Feb. 6-10, 2017, Sophia Antipolis, France, 4 Pages. [cited by applicant]
Nec et al., “Improve and Clarify Texts under Note”, 3GPP TSG-SA WG3 Meeting #89, S3-17xyza, CR CRNum, V14.4.0, Reno, Nevada USA, Nov. 27-Dec. 1, 2017, 3 Pages. [cited by applicant]
Nec et al., “pCR to TR 33.899: Update of Solution #1.32”, 3GPP TSG SA WG3 (Security) Meeting #87, S3-171177, May 15-19, 2017, Ljubljana, 4 Pages. [cited by applicant]
Oberoi, et al., “Wearable security: Key Derivation for Body Area Sensor Networks Based on Host Movement”, 2016 IEEE 25th International Symposium on Industrial Electronics (ISIE), https://ieeexplore.ieee.org/starnp/starn… [cited by applicant]
Qualcomm Incorporated: “pCR to Provide a Normative Text for the AMF Key Derivation/Refresh”, 3GPP TSG SA WG3 (Security) Meeting #88, Dali, China, S3-172010, Aug. 11, 2017, 2 Pages, Aug. 7, 2017-Aug. 11, 2017, searched o… [cited by applicant]
Qualcomm Incorporated: “pCR to Provide a Normative Text for the AMF Key Derivation/Refresh”, 3GPP TSG SA WG3 (Security) Meeting #88Bis Adhoc, S3-172387, Singapore, Oct. 9, 2017-Oct. 13, 2017, 3 Pages, Oct. 2, 2017, sear… [cited by applicant]
Qualcomm Incorporated: “Some Corrections and Clarification to the Authentication Text”, 3GPP TSG SA WG3 (Security) Meeting #88, S3-172145, Dali, China, Aug. 11, 2017, 6 Pages, Aug. 7, 2017-Aug. 11, 2017, searched on [Au… [cited by applicant]
Taiwan Search Report—TW107134619—TIPO—Jan. 4, 2022. [cited by applicant]
Thatmann D., et al., “A Secure DHT-Based Key Distribution System for Attribute-Based Encryption and Decryption”, 2015 9th International Conference on Signal Processing and Communication Systems (ICSPCS), 2015, 9 pages. [cited by applicant]
Wang H-M., et al., “Physical Layer Security in Heterogeneous Cellular Networks”, IEEE Transactions on Communications, vol. 64, Issue. 3, 2016, pp. 1-16. [cited by applicant]
Zte, et al., “Key Hierarchy for 5G”, 3GPP Draft; S3-171605, 3GPP TSG SA WG3 (Security) Meeting #87, Key Hierarchy for 5G, 3rd Generation Partnership Project (3GPP), Mobile Competence Centre; 650, Route Des Lucioles; F-0… [cited by applicant]
ZTE: “Update of Solution 8.5”, 3GPP Draft; S3-171053, 3GPP TSG SA WG3 (Security) Meeting #87, Update of Solution 8.5, 3rd Generation Partnership Project (3GPP), Mobile Competence Centre; 650, Route Des Lucioles; F-06921… [cited by applicant]