NETWORK SECURITY ARCHITECTURE
    124.
    发明申请
    NETWORK SECURITY ARCHITECTURE 审中-公开
    网络安全架构

    公开(公告)号:US20170012956A1

    公开(公告)日:2017-01-12

    申请号:US15160326

    申请日:2016-05-20

    Abstract: In an aspect, a network supporting client devices includes one or more network nodes implementing network functions. Such network functions enable a client device to apply a security context to communications with the network when the client device is not in a connected mode. The client device obtains a user plane key shared with a user plane network function implemented at a first network node and/or a control plane key shared with a control plane network function implemented at a second network node. The client device protects a data packet with the user plane key or a control packet with the control plane key. The data packet includes first destination information indicating the first network node and the control packet includes second destination information indicating the second network node. The client device transmits the data packet or control packet.

    Abstract translation: 在一方面,支持客户端设备的网络包括实现网络功能的一个或多个网络节点。 当客户端设备不处于连接模式时,这样的网络功能使得客户端设备能够将安全上下文应用于与网络的通信。 客户端设备获得与在第二网络节点处实现的控制平面网络功能共享的第一网络节点和/或控制平面密钥实现的用户平面网络功能共享的用户平面密钥。 客户机设备利用用户平面密钥或具有控制平面密钥的控制分组来保护数据分组。 数据分组包括指示第一网络节点的第一目的地信息,并且控制分组包括指示第二网络节点的第二目的地信息。 客户端设备发送数据包或控制包。

    APPARATUS AND METHOD FOR SPONSORED CONNECTIVITY TO WIRELESS NETWORKS USING APPLICATION-SPECIFIC NETWORK ACCESS CREDENTIALS
    126.
    发明申请
    APPARATUS AND METHOD FOR SPONSORED CONNECTIVITY TO WIRELESS NETWORKS USING APPLICATION-SPECIFIC NETWORK ACCESS CREDENTIALS 有权
    使用应用程序特定网络访问凭证为无线网络提供连通性的装置和方法

    公开(公告)号:US20160277191A1

    公开(公告)日:2016-09-22

    申请号:US14829459

    申请日:2015-08-18

    Abstract: At least one feature pertains to a method operational at a user device that includes receiving, from an application service provider, an application-specific certificate associated with at least one application service provided by the application service provider. The method also includes determining that a wireless communication network provides application-specific access to the application service provided by the application service provider, and transmitting a registration request including the application-specific certificate to the wireless communication network for authentication of the user device. The application-specific certificate includes a user device public key. The method further includes performing authentication and key agreement with the wireless communication network, and communicating with the application service after authentication and key agreement is successfully performed. In one aspect, authentication and key agreement with the network is performed directly between the user device and the network and independent to the application service provider.

    Abstract translation: 至少一个特征涉及在用户设备处操作的方法,其包括从应用服务提供商接收与应用服务提供商提供的至少一个应用服务相关联的特定于应用的证书。 该方法还包括:确定无线通信网络向由应用服务提供商提供的应用服务提供特定应用的接入,并向用户设备发送包含应用专用证书的注册请求给无线通信网络。 应用程序特定证书包括用户设备公钥。 该方法还包括执行与无线通信网络的认证和密钥协商,并且在认证和密钥协商成功执行之后与应用服务进行通信。 一方面,在用户设备和网络之间直接执行与网络的认证和密钥协商,并且独立于应用服务提供商。

    Network based provisioning of UE credentials for non-operator wireless deployments
    127.
    发明授权
    Network based provisioning of UE credentials for non-operator wireless deployments 有权
    基于网络的非运营商无线部署的UE凭据提供

    公开(公告)号:US09445443B2

    公开(公告)日:2016-09-13

    申请号:US14489234

    申请日:2014-09-17

    CPC classification number: H04W76/11 H04W4/50 H04W8/18 H04W12/04 H04W84/12

    Abstract: Methods, systems, and devices are described for provisioning of devices, such as UEs, for service at a wireless network. One or more device parameters may be identified for use in provisioning the device on the wireless network, which may be provided to a network element. The network element may use the provided parameters to access a subscription server. The subscription server may provide verification and/or subscription parameters of the device that may then be used by the device to verify that the device is authorized to access the wireless network.

    Abstract translation: 描述了用于为无线网络服务的诸如UE之类的设备的供应的方法,系统和设备。 可以识别一个或多个设备参数,以用于在可以提供给网络元件的无线网络上提供设备。 网元可以使用所提供的参数来访问订阅服务器。 订阅服务器可以提供设备的验证和/或订阅参数,然后设备可以使用该参数来验证设备是否被授权接入无线网络。

    WI-FI PRIVACY IN AN ACCESS POINT USING MEDIA ACCESS CONTROL ADDRESS RANDOMIZATION
    128.
    发明申请
    WI-FI PRIVACY IN AN ACCESS POINT USING MEDIA ACCESS CONTROL ADDRESS RANDOMIZATION 审中-公开
    使用媒体访问控制地址随机的接入点中的WI-FI隐私

    公开(公告)号:US20160135053A1

    公开(公告)日:2016-05-12

    申请号:US14934563

    申请日:2015-11-06

    Abstract: Methods, systems, apparatuses, and devices are described for access point privacy using media access control (MAC) address randomization. The access point may identify a MAC address for use with over-the-air (OTA) transmissions and a persistent MAC address for backend communications. The access point may communicate the OTA MAC address and the persistent MAC address to a wireless station. The access point and the wireless station may exchange data frames and perform MAC replacement techniques to map the OTA MAC address to the persistent MAC address. The persistent MAC address may provide for data routing, mobility management, etc., whereas the OTA MAC address may provide for privacy for the wireless transmissions.

    Abstract translation: 使用媒体访问控制(MAC)地址随机化来描述用于接入点隐私的方法,系统,设备和设备。 接入点可以识别用于空中(OTA)传输的MAC地址和用于后端通信的持久MAC地址。 接入点可以将OTA MAC地址和持久MAC地址通信给无线站。 接入点和无线站可以交换数据帧并执行MAC替换技术将OTA MAC地址映射到持久MAC地址。 持久MAC地址可以提供数据路由,移动性管理等,而OTA MAC地址可以为无线传输提供隐私。

    CERTIFICATE PROVISIONING FOR AUTHENTICATION TO A NETWORK
    129.
    发明申请
    CERTIFICATE PROVISIONING FOR AUTHENTICATION TO A NETWORK 审中-公开
    认证证明给网络的证书

    公开(公告)号:US20160134621A1

    公开(公告)日:2016-05-12

    申请号:US14795635

    申请日:2015-07-09

    Abstract: A method for authenticating a device to a network using a device certificate is described. The method includes generating a private-public key pair on a system-on-chip (SoC) of the device. The private key is protected by a hardware-based root of trust of the SoC. The method also includes generating a device certificate that is signed using the private key. The method further includes using the device certificate to gain access to the network.

    Abstract translation: 描述了使用设备证书将设备认证到网络的方法。 该方法包括在该设备的片上系统(SoC)上生成私钥对。 私有密钥受到基于硬件的SoC信任根源的保护。 该方法还包括生成使用私钥签名的设备证书。 该方法还包括使用设备证书来访问网络。

    AUTHENTICATION OF BROWSER-BASED SERVICES VIA OPERATOR NETWORK
    130.
    发明申请
    AUTHENTICATION OF BROWSER-BASED SERVICES VIA OPERATOR NETWORK 审中-公开
    通过操作员网络验证基于浏览器的服务

    公开(公告)号:US20160119788A1

    公开(公告)日:2016-04-28

    申请号:US14521373

    申请日:2014-10-22

    Abstract: An example method of determining a level of service to allocate for a browser-based session includes receiving, at an operator core network, a request to establish a browser-based session for a web service. The request is from a browser executing on a user equipment (UE). The method also includes identifying an attribute value of an attribute assigned to the UE and determining, based on the attribute value assigned to the UE, whether the UE is currently registered with the operator core network. The method further includes determining, based on whether the UE is currently registered with the operator core network, a level of service to allocate for the browser-based session.

    Abstract translation: 确定为基于浏览器的会话分配的服务等级的示例性方法包括在运营商核心网络处接收为web服务建立基于浏览器的会话的请求。 该请求来自在用户设备(UE)上执行的浏览器。 该方法还包括识别分配给UE的属性的属性值,并且基于分配给UE的属性值来确定UE是否当前已经向运营商核心网注册。 该方法还包括基于UE当前是否向运营商核心网络注册确定为基于浏览器的会话分配的服务级别。

Patent Agency Ranking