IP Library › Granted Patent US 12,225,377
Granted Patent B2
US 12,225,377 · App. 17/774,896 · Granted Feb 11, 2025

Methods for trust information in communication network and related communication equipment and communication device

Inventors: Vesa Lehtovirta (Espoo, FI); Prajwol Kumar Nakarmi (Sollentuna, SE); Helena Vahidi Mazinani (Lund, SE); Noamen Ben Henda (Vällingby, SE); Markus Hanhisalo (Espoo, FI)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04W12/082H04W8/06H04W12/069H04W12/66H04W60/00H04W84/042
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,225,377
App. No.
17/774,896
Granted
Feb 11, 2025
Kind
B2
Abstract

A method performed by a network equipment of a communication network to dynamically provide trust information to a communication device registered or being registered to the communication network is provided. The method includes determining a trust information for each of one or more access networks. The trust information indicates whether each of the one or more access networks is trusted. The method further includes indicating to the communication device whether the one or more access networks is trusted for a current session or a later session. A method performed by a communication device registered or being registered with a communication network to dynamically receive trust information is also provided. The method includes receiving a message including a protected trust information list from a network equipment. The method further includes verifying the protection of the message. The method further includes storing the protected trust information list.

Claims (38)

1. A method performed by a network equipment of a communication network to dynamically provide trust information to a communication device registered to or being registered the communication network, the method comprising:

determining a trust information for each of one or more access networks, wherein the trust information indicates whether each of the one or more access networks is trusted, wherein the determining a trust information for each of one or more access networks comprises protecting a trust information list with a key shared with the communication device to obtain a protected trust information list; and

indicating to the communication device whether the one or more access networks is trusted for a current session or a later session, wherein the indicating to the communication device whether the one or more access networks is trusted for a current session or a later session comprises sending the protected trust information list toward the communication device.

2. The method of claim 1 , wherein the determining a trust information for each of one or more access networks comprises:

obtaining a list of the one or more access networks; and

associating the trust information to each of the one or more of the access networks in the list of the one or more access networks resulting in the trust information list.

3. The method of claim 1 , wherein the sending the protected trust information list toward the communication device is sent toward the communication device during steering of the communication device in a visited public land mobile network (VPLMN) during registration.

4. The method of claim 1 , wherein the sending the protected trust information list toward the communication device is sent toward the communication device during steering of the communication device in a visited public land mobile network (VPLMN) after registration.

5. The method of claim 4 , further comprising:

sending a message to an authentication server function (AUSF) to obtain security material for protection of the trust information list; and

receiving a response to the first message from the AUSF with the security material.

6. The method of claim 1 , wherein the sending the protected trust information list toward the communication device is sent toward the communication device via a parameters update to the communication device during a unified data management (UDM) control plane security procedure.

7. The method of claim 6 , wherein the parameters update comprises a user equipment parameter update (UPU).

8. The method of claim 6 , further comprising:

sending a message to an authentication server function (AUSF) to obtain security material for protection of the trust information list; and

receiving a response to the first message from the AUSF with the security material.

9. The method of claim 1 , wherein the sending the protected trust information list toward the communication device is sent toward the communication device after a primary authentication.

10. The method of claim 2 , wherein the list is obtained where an authentication of the communication device was performed; and

the sending the protected trust information list toward the communication device is sent toward the communication device using a user equipment parameter update (UPU) procedure.

11. A network equipment comprising:

processing circuitry; and

memory coupled with the processing circuitry, wherein the memory includes instructions that when executed by the processing circuitry causes the network equipment to perform operations comprising:

determining a trust information for each of one or more access networks, wherein the trust information indicates whether each of the one or more access networks is trusted, wherein the determining a trust information for each of one or more access networks comprises protecting a trust information list with a key shared with the communication device to obtain a protected trust information list; and

indicating to a communication device registered or being registered with a communication network whether the one or more access networks is trusted for a current session or a later session, wherein the indicating to the communication device whether the one or more access networks is trusted for a current session or a later session comprises sending the protected trust information list toward the communication device.

12. A method performed by a communication device registered or being registered with a communication network to dynamically receive trust information, the method comprising:

receiving a message including a protected trust information list from a network equipment;

verifying the protection of the message; and

storing the protected trust information list.

13. The method of claim 12 , wherein the receiving a message including a protected trust information list from a network equipment is received during steering of the communication device in a visited public land mobile network (VPLMN) after registration.

14. The method of claim 12 , wherein the receiving a message including a protected trust information list from a network equipment is received via a parameters update to the communication device during a unified data management (UDM) control plane security procedure.

15. The method of claim 14 , wherein the parameters update comprises a user equipment parameter update (UPU).

16. The method of claim 12 , wherein the receiving a message including a protected trust information list from a network equipment is received after a primary authentication.

17. The method of claim 12 , wherein the protected trust information comprises a plurality of trust indications comprising a trust indication from a visited public land mobile network (VPLMN) and a trust indication from a home public land mobile network (HPLMN).

18. The method of claim 17 , wherein the communication device has default behavior that the trust indication from the VPLMN overrides the trust indication of the HPLMN.

19. A communication device registered or being registered with a communication network adapted to perform operations comprising:

receive a message including a protected trust information list from a network equipment;

verify the protection of the message; and

store the protected trust information list.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2022
From: LEHTOVIRTA, VESA; HANHISALO, MARKUS
To: OY L M ERICSSON AB
Reel/Frame 059866/0878 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2022
From: OY L M ERICSSON AB
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 059866/0916 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2022
From: NAKARMI, PRAJWOL KUMAR; VAHIDI MAZINANI, HELENA; BEN HENDA, NOAMEN
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 059866/0978 →
Continuity (1)
Related Publication 20220394473A1 · Dec 8, 2022
References Cited (23)
US 20110025632A1 · Lee · 2011 [cited by applicant]
US 20110225632A1 · Ropolyi et al. · 2011 [cited by applicant]
US 20120322412A1 · Qiang · 2012 [cited by applicant]
US 20140096193A1 · Naeslund et al. · 2014 [cited by applicant]
US 20140149741A1 · Balakrishnan et al. · 2014 [cited by applicant]
US 20170055302A1 · Wang et al. · 2017 [cited by applicant]
US 20190028873A1 · Drevon et al. · 2019 [cited by applicant]
US 20190335333A1 · Sohail et al. · 2019 [cited by applicant]
US 20200280849A1 · Ito et al. · 2020 [cited by applicant]
CN 101730172A · 2010 [cited by examiner]
WO 2009126083A1 · 2009 [cited by applicant]
WO 2017182057A1 · 2017 [cited by applicant]
WO 2019065897A1 · 2019 [cited by applicant]
WO 2020037665A1 · 2020 [cited by applicant]
International Search Report and Written Opinion of the International Searching Authority for PCT International Application No. PCT/SE2020/051081 dated Mar. 10, 2021. [cited by applicant]
3GPP TS 33.501 V16.0.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16),” Sep. 2019, 196 pages. [cited by applicant]
3GPP TS 23.502 V16.2.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 16),” Sep. 2019, 525 pages. [cited by applicant]
3GPP TS 33.402 V15.1.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3GPP System Architecture Evolution (SAE); Security aspects of non-3GPP accesses (Release 15),” Jun.… [cited by applicant]
3GPP TS 23.501 V16.2.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System Architecture for the 5G System (5GS); Stage 2 (Release 16),” Sep. 2019, 391 pages. [cited by applicant]
Office Action mailed Mar. 7, 2024 for Indian Patent Application No. 202247035528, 7 pages. [cited by applicant]
Extended European Search Report mailed Oct. 16, 2023 for European Application No. 20886366.2; 13 pages. [cited by applicant]
Communication pursuant to Rules 70(2) and 70a(2) EPC mailed Nov. 3, 2023 for European Application No. 20886366.2; 1 page. [cited by applicant]
Huawei; “Access Type and RAT Type per Non-3GPP Accesses”; 3GPP TSG-WG SA2 Meeting #136; S2-1911335; Reno, Nevada; Nov. 18-22, 2019; 6 pages. [cited by applicant]
Cited By (1)
US 12,707,271