IP Library › Granted Patent US 12,231,894
Granted Patent B2
US 12,231,894 · App. 18/540,242 · Granted Feb 18, 2025

Method and device for protecting sensitive user plane traffic

Inventors: Rajavelsamy Rajadurai (Bangalore, IN); Kundan Tiwari (Bangalore, IN); Varini Gupta (Bangalore, IN); Anikethan Ramakrishna Vijaya Kumar (Bangalore, IN)
Assignee: Samsung Electronics Co., Ltd.
H04W12/106H04W12/033H04W12/069
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,894
App. No.
18/540,242
Granted
Feb 18, 2025
Kind
B2
Abstract

Disclosed herein are a communication technique for merging, with an IoT technology, a 5G communication system for supporting a data transmission rate higher than that of a 4G system; and a system therefor. Embodiments herein disclose a method of protecting sensitive user plane traffic in an User Equipment (UE) ( 100 ), the method comprising: transmitting, to a network ( 200 ), by the UE ( 100 ) a first NAS message comprising an indicator indicating that the UE ( 200 ) supports of a secure channel for domain name system (DNS); receiving, from the network ( 200 ), by the UE ( 100 ) a second NAS message including DNS server security information in response to transmitting the first NAS message; and transmitting, to the network ( 200 ), by the UE ( 100 ) the DNS over the secure channel based on the DNS server security information.

Claims (32)

1. A method of a user equipment (UE), the method comprising:

transmitting, to a network entity, a protocol data unit (PDU) session establishment request message including an indicator indicating that the UE supports of domain name system (DNS) over transport layer security (TLS) or DNS over datagram TLS (DTLS); and

receiving, from the network entity, a PDU session establishment accept message including DNS server security information in response to transmitting the PDU session establishment request message,

wherein the DNS server security information comprises information on a security mechanism.

2. The method of claim 1 , wherein the indicator is included in protocol configuration options in the PDU session establishment request message.

3. The method of claim 1 , wherein the DNS server security information is included in protocol configuration options in the PDU session establishment accept message.

4. The method of claim 1 , wherein the DNS server security information comprises at least one of information on a service port, information on an authentication domain name, information on subject public key (SPKI), information on root certificate, and information on a raw public key.

5. A method of a network entity, the method comprising:

receiving, from a user equipment (UE), a protocol data unit (PDU) session establishment request message including an indicator indicating that the UE supports of domain name system (DNS) over transport layer security (TLS) or DNS over datagram TLS (DTLS); and

transmitting, to the UE, a PDU session establishment accept message including DNS server security information in response to receiving the PDU session establishment request message,

wherein the DNS server security information comprises information on a security mechanism.

6. The method of claim 5 , wherein the indicator is included in protocol configuration options in the PDU session establishment request message.

7. The method of claim 5 , wherein the DNS server security information is included in protocol configuration options in the PDU session establishment accept message.

8. The method of claim 5 , wherein the DNS server security information comprises at least one of information on a service port, information on an authentication domain name, information on subject public key (SPKI), information on root certificate, and information on a raw public key.

9. A user equipment (UE), the UE comprising:

a transceiver; and

a controller coupled with the transceiver and configured to control to:

transmit, to a network entity, a protocol data unit (PDU) session establishment request message including an indicator indicating that the UE supports of domain name system (DNS) over transport layer security (TLS) or DNS over datagram TLS (DTLS), and

receive, from the network entity, a PDU session establishment accept message including DNS server security information in response to transmitting the PDU session establishment request message,

wherein the DNS server security information comprises information on a security mechanism.

10. The UE of claim 9 , wherein the indicator is included in protocol configuration options in the PDU session establishment request message.

11. The UE of claim 9 , wherein the DNS server security information is included in protocol configuration options in the PDU session establishment accept message.

12. The UE of claim 9 , wherein the DNS server security information comprises at least one of information on a service port, information on an authentication domain name, information on subject public key (SPKI), information on root certificate, and information on a raw public key.

13. A network entity, the network entity comprising:

a transceiver; and

a controller coupled with the transceiver and configured to control to:

receive, from a user equipment (UE), a protocol data unit (PDU) session establishment request message including an indicator indicating that the UE supports of domain name system (DNS) over transport layer security (TLS) or DNS over datagram TLS (DTLS), and

transmit, to the UE, a PDU session establishment accept message including DNS server security information in response to receiving the PDU session establishment request message,

wherein the DNS server security information comprises information on a security mechanism.

14. The network entity of claim 13 , wherein the indicator is included in protocol configuration options in the PDU session establishment request message.

15. The network entity of claim 13 , wherein the DNS server security information is included in protocol configuration options in the PDU session establishment accept message.

16. The network entity of claim 13 , wherein the DNS server security information comprises at least one of information on a service port, information on an authentication domain name, information on subject public key (SPKI), information on root certificate, and information on a raw public key.

Priority Claims (2)
IN 202041018540 · Apr 30, 2020 · national
IN 2020 41018540 · Apr 28, 2021 · national
Continuity (2)
Continuation 17911830
Related Publication 20240129738A1 · Apr 18, 2024
References Cited (17)
US 10681072B2 · Alfano · 2020 [cited by examiner]
US 11832122B2 · Jung · 2023 [cited by examiner]
US 20050182957A1 · Della-Libera · 2005 [cited by examiner]
US 20090049526A1 · Zhang · 2009 [cited by examiner]
US 20170318463A1 · Lee et al. · 2017 [cited by applicant]
US 20200037165A1 · Kunz · 2020 [cited by examiner]
US 20200068587A1 · Garcia Azorero · 2020 [cited by examiner]
US 20200259853A1 · Alfano et al. · 2020 [cited by applicant]
US 20210168584A1 · Li · 2021 [cited by examiner]
KR 1020200043459A · 2020 [cited by applicant]
WO 2020027632A1 · 2020 [cited by applicant]
Korean Decision on Grant dated Mar. 5, 2024, issued in Korean Application No. 10-2022-7041878. [cited by applicant]
European Search Report dated Sep. 20, 2023, issued in European Application No. 21795914.7. [cited by applicant]
Indian Examination report dated Feb. 24, 2023, issued in Indian Application No. 202041018540. [cited by applicant]
Qualcomm Incorporated et al., ‘Proposed solution for UP IP issues in GSMA LS’, S3-200767, 3GPP TSG-SA3 Meeting #98Bis-e, Apr. 3, 2020, section 3. [cited by applicant]
‘3GPP; TSG SA; Technical report on key issues and potential solutions for Integrity protection of the User Plane; (Release 16)’, 3GPP TR 33.853 V0.7.0, Jan. 2, 2020, sections 5.5-5.5.4, 6.1-6.1.4, 6.5-6.5.4, 6.7-6.7.4; … [cited by applicant]
Vodafone, ‘Corrections to Key Issue 5’, S3-200639, 3GPP TSG-SA3 Meeting #98Bis-e, Apr. 3, 2020, sections 5.5-5.5.4. [cited by applicant]
Cited By (1)
US 12,621,631