UE PRIVACY FOR AKMA
    1.
    发明公开
    UE PRIVACY FOR AKMA 审中-公开

    公开(公告)号:US20240056301A1

    公开(公告)日:2024-02-15

    申请号:US18447374

    申请日:2023-08-10

    CPC classification number: H04L9/32

    Abstract: Method comprising:



    monitoring whether a network receives an authorization request for establishing a session of an AF with a UE, wherein the authorization request comprises a permanent identifier of the AF, a received temporary identifier of the AF, and a temporary identifier of a UE;
    if the authorization request is received:

    forming a key identifier based on the temporary identifier of the UE;
    retrieving, based on the key identifier, a stored key and a first permanent identifier of the UE;
    calculating a calculated temporary identifier of the AF based on the permanent identifier of the AF and the stored key;
    checking whether the calculated temporary identifier of the AF is identical with the received temporary identifier of the AF;
    inhibiting authorizing the AF for the establishing the session with the UE if the calculated temporary identifier of the AF is not identical with the received temporary identifier of the AF.

    Network function service subscription control

    公开(公告)号:US11425636B1

    公开(公告)日:2022-08-23

    申请号:US17232640

    申请日:2021-04-16

    Abstract: According to an example aspect, there is provided a method, comprising: receiving, from a first network function consumer, a subscribe request for a second network function consumer to subscribe to a service, wherein the subscribe request comprises a notification address and identifies the second network function consumer, transmitting, to a network repository function, an access token request, comprising the notification address and identifying the second network function consumer, receiving, from the network repository function, an access token response comprising an access token comprising the notification address verified by the network repository function, transmitting, to the second network function consumer, an authorization request for receiving data authorization and comprising the access token, receiving, from the second network function consumer, an authorization response indicative of authorization of the second network function consumer, and transmitting, on the basis of the authorization response, a notification to the second network function consumer.

    SYSTEM AND METHOD FOR SAVING MOBILE BATTERY AND EMPOWERING USER EQUIPMENT FOR INCOMING COMMUNICATION AND PAGING

    公开(公告)号:US20210410071A1

    公开(公告)日:2021-12-30

    申请号:US17279438

    申请日:2018-09-25

    Abstract: A system and method for saving mobile battery and empowering user equipment for controlling incoming communication and paging are provided. Also provided are a system and method for determining whether a mobile a device is in an idle mode, and in response to receiving an incoming communication from a service, determining whether the service associated with the incoming communication is on a reject list of services or a preferred list of services. The system performs a first action specified by a determination that the service is on the reject list of services or the service is not on the preferred list of services, and performs a second action specified by a determination that the service is on the preferred list of services. The first action differs from the second action.

    POST QUANTUM SECURITY PROFILE FOR JWE AND TLS IN 3GPP NETWORKS

    公开(公告)号:US20250016559A1

    公开(公告)日:2025-01-09

    申请号:US18749970

    申请日:2024-06-21

    Abstract: Method comprising: informing a responding entity of two or more first key exchange schemes each comprising a respective key exchange supported by an initiating entity for a communication between the responding entity and the initiating entity; receiving, from the responding entity, an indication of a selected key exchange scheme in response to the informing the responding entity of the two or more first key exchange schemes; checking whether the selected key exchange scheme is a hybrid key exchange scheme; and, in response to checking that the selected key exchange scheme is not the hybrid key exchange scheme: rejecting the communication between the responding entity and the initiating entity; or performing the communication by exchanging a key according to the selected key exchange scheme and sending an alert indicating that the key exchange scheme different from the hybrid key exchange scheme is used for the communication.

    Security enhancements for cellular communication systems

    公开(公告)号:US12041455B2

    公开(公告)日:2024-07-16

    申请号:US17514120

    申请日:2021-10-29

    CPC classification number: H04W12/122 H04W12/128

    Abstract: According to an example aspect of the present invention, there is provided a method comprising, determining, by an apparatus configured to operate as a network function a cellular communication system, at least two disjoint network paths, wherein the at least two disjoint network paths are different paths, and comprise different physical resources, transmitting, by the apparatus, a subscription request to an analytics function of the cellular communication system, to request notifications about attacks or risks of attacks on at least one network function on at least one of the at least two disjoint network paths, receiving from the analytics function, by the apparatus, information about at least one compromised network entity and/or at least one network entity having a risk of being compromised on said at least one of the at least two disjoint network paths and performing, by the apparatus, attack mitigation based on said information.

    NETWORK SECURITY
    8.
    发明公开
    NETWORK SECURITY 审中-公开

    公开(公告)号:US20230155832A1

    公开(公告)日:2023-05-18

    申请号:US18047434

    申请日:2022-10-18

    CPC classification number: H04L9/3213 H04L63/0884

    Abstract: According to an example aspect of the present invention, there is provided an apparatus configured to process a request for an access token authorizing access for a network function consumer to a service provided by a network function producer, the request being received in the apparatus from a service communication proxy, wherein the processing comprises one or more of the following verification: verification that a credential data element comprised in the request, cryptographically signed by the network function consumer, identifies the request, the service or a type of the service, and verification with reference to a further node, or to a profile of the network function consumer, that the service communication proxy is authorized to act on behalf of the network function consumer, and transmit, responsive to at least one of the verifications being successful, the requested access token, the access token comprising an indication of the service communication proxy.

    Security enhancements for cellular communication systems

    公开(公告)号:US20230136287A1

    公开(公告)日:2023-05-04

    申请号:US17514120

    申请日:2021-10-29

    Abstract: According to an example aspect of the present invention, there is provided a method comprising, determining, by an apparatus configured to operate as a network function a cellular communication system, at least two disjoint network paths, wherein the at least two disjoint network paths are different paths, and comprise different physical resources, transmitting, by the apparatus, a subscription request to an analytics function of the cellular communication system, to request notifications about attacks or risks of attacks on at least one network function on at least one of the at least two disjoint network paths, receiving from the analytics function, by the apparatus, information about at least one compromised network entity and/or at least one network entity having a risk of being compromised on said at least one of the at least two disjoint network paths and performing, by the apparatus, attack mitigation based on said information.

Patent Agency Ranking