IP Library Granted Patent US 12,556,989
Granted Patent B2
US 12,556,989 · App. 18/633,137 · Granted Feb 17, 2026

Systems and methods for preventing handover caused by an insecure message from a network node

Inventors: Icaro L. J. Da Silva (Stockholm, SE); Patrik Rugeland (Stockholm, SE)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04W36/0094H04W12/10H04W76/10H04W76/27
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,989
App. No.
18/633,137
Granted
Feb 17, 2026
Kind
B2
Abstract

Systems, methods, and apparatus for handling messages from network nodes of a wireless communications system are disclosed. An example method performed by a terminal includes receiving a message from a network node. The terminal determines that the message contains a reconfigurationWithSync field and that security is not activated when the message is received. Responsive to the determining, the terminal prevents triggering of a handover operation.

Claims (37)

1 . A method for handling messages in a wireless communications system, the method comprising:

receiving a reconfiguration message from a network node;

determining that the reconfiguration message contains a handover command and that security is not activated; and

responsive to the determining, performing a recovery procedure that includes preventing triggering of a handover operation.

2 . The method of claim 1 , wherein the reconfiguration message comprises an RRCSetup message.

3 . The method of claim 1 , wherein preventing triggering of the handover operation comprises transitioning to an RRC_IDLE state.

4 . The method of claim 1 , wherein the handover operation comprises a reconfiguration with sync.

5 . The method of claim 1 , wherein the reconfiguration message is received on SRB0, and wherein the security not being activated includes the reconfiguration message not being cipher or integrity protected.

6 . The method of claim 1 , further comprising:

indicating a failure to upper layers.

7 . The method of claim 6 , wherein the failure indicated to the upper layers comprises an RRC connection failure indication.

8 . The method of claim 1 , further comprising:

logging information based on content of the reconfiguration message that was received without security protection; and

reporting the logged information.

9 . The method of claim 1 , wherein preventing triggering of a handover operation includes preventing use of any content of the reconfiguration message for a cell reconfiguration operation.

10 . The method of claim 1 , wherein performing the recovery procedure includes performing a NAS recovery.

11 . A user equipment for handling messages in a wireless communications system, the user equipment comprising:

a processor; and

a memory coupled to the processor, wherein the memory stores instructions that when executed by the processor causes the processor to perform operations comprising:

receiving a reconfiguration message from a network node;

determining that the reconfiguration message contains a handover command and that security is not activated; and

responsive to the determining, performing a recovery procedure that includes preventing triggering of a handover operation.

12 . The user equipment of claim 11 , wherein the reconfiguration message comprises an RRCSetup message.

13 . The user equipment of claim 11 , wherein preventing triggering of the handover operation comprises transitioning to an RRC_IDLE state.

14 . The user equipment of claim 11 , wherein the handover operation comprises a reconfiguration with sync.

15 . The user equipment of claim 11 , wherein the reconfiguration message is received on SRB0, and wherein the security not being activated includes the reconfiguration message not being cipher or integrity protected.

16 . The user equipment of claim 11 , the operations further comprising:

indicating a failure to upper layers.

17 . The user equipment of claim 16 , wherein the failure indicated to the upper layers comprises an RRC connection failure indication.

18 . The user equipment of claim 11 , the operations further comprising:

logging information based on content of the reconfiguration message that was received without security protection; and

reporting the logged information.

19 . The user equipment of claim 11 , wherein performing the recovery procedure includes performing a NAS recovery.

20 . A non-transitory computer readable storage medium comprising computer readable program code that when executed by a processor causes the processor to perform operations comprising:

receiving a reconfiguration message from a network node;

determining that the reconfiguration message contains a handover command and that security is not activated; and

responsive to the determining, performing a recovery procedure that includes preventing triggering of a handover operation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2026
From: DA SILVA, ICARO L. J.; RUGELAND, PATRIK
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 073474/0283 →
Continuity (3)
Continuation 17281494
Provisional Application 62754214 · Nov 1, 2018
Related Publication 20240259900A1 · Aug 1, 2024
References Cited (35)
US 10750562B2 · Park et al. · 2020 [cited by applicant]
US 20070265875A1 · Jiang · 2007 [cited by examiner]
US 20080318546A1 · Kitazoe · 2008 [cited by examiner]
US 20140269613A1 · Tiwari · 2014 [cited by examiner]
US 20170332399A1 · Yi et al. · 2017 [cited by applicant]
US 20180092156A1 · Kim et al. · 2018 [cited by applicant]
US 20180317264A1 · Agiwal et al. · 2018 [cited by applicant]
US 20190394691A1 · Shih et al. · 2019 [cited by applicant]
US 20200045674A1 · Tseng et al. · 2020 [cited by applicant]
US 20200059395A1 · Chen · 2020 [cited by applicant]
US 20200100311A1 · Cirik et al. · 2020 [cited by applicant]
US 20200337108A1 · Wu et al. · 2020 [cited by applicant]
US 20210153012A1 · Sharma · 2021 [cited by examiner]
US 20210195675A1 · Park et al. · 2021 [cited by applicant]
US 20210321277A1 · Murray et al. · 2021 [cited by applicant]
US 20220007255A1 · Rugeland · 2022 [cited by examiner]
CN 104272793A · 2015 [cited by applicant]
CN 108293236A · 2018 [cited by applicant]
CN 110431873A · 2019 [cited by applicant]
EP 2381719A1 · 2011 [cited by applicant]
EP 2943008A1 · 2015 [cited by applicant]
WO 2017092813A1 · 2017 [cited by applicant]
WO 2018030866A1 · 2018 [cited by applicant]
WO 2018082817A1 · 2018 [cited by applicant]
WO 2018143703A1 · 2018 [cited by applicant]
WO 2018174627A1 · 2018 [cited by applicant]
WO 2018199822A1 · 2018 [cited by applicant]
WO 2018203815A1 · 2018 [cited by applicant]
WO 2019032023A1 · 2019 [cited by applicant]
CATT, “As security for RRC Re-establishment procedure”, 3GPP TSG-WG2 Meeting #103, Gothenburg, Sweden, Aug. 20-24, 2018, pp. 1-11, R2-1811233, 3GPP. [cited by applicant]
Ericsson, “Introduction of SA”, 3GPP TSG-WG2 Meeting #103, Gothenburg, Sweden, Aug. 20-24, 2018, Change Request R2-1813492, pp. 1-431, 3GPP. [cited by applicant]
Ericsson, “Summary of agreements on connection control”, 3GPP TSG-RAN WG2 #101Bis, R2-1805352, Sanya, P. R. of China, April 16-20, pp. 1-9, 3GPP. [cited by applicant]
Intel Corporation, Change Request “Security protection for RRC messages”, 3GPP TSG-RAN WG2 NR AH Meeting 1807, Montreal, Canada, Jul. 2-6, 2018, pp. 1-4, R2-1809797, 3GPP. [cited by applicant]
Qualcomm Europe, “Handling of integrity protection check failure”, 3GPP TSG-RAN WG2 meeting #62-bis, Warsaw, Poland, Jun. 30-Jul. 4, 2008, pp. 1-4, R2-083572, 3GPP. [cited by applicant]
Samsung, “Remaining issues of RRC connection control from Inactive”, 3GPP TSG-RAN WG2 #99bis, Prague, Czech Republic, Oct. 9-13, 2017, pp. 1-7, R2-1711664, 3GPP. [cited by applicant]