Identity privacy in wireless networks

    公开(公告)号:US10237729B2

    公开(公告)日:2019-03-19

    申请号:US14808862

    申请日:2015-07-24

    Abstract: Systems and techniques are disclosed to protect a user equipment's international mobile subscriber identity by providing a privacy mobile subscriber identity instead. In an attach attempt to a serving network, the UE provides the PMSI instead of IMSI, protecting the IMSI from exposure. The PMSI is determined between a home network server and the UE so that intermediate node elements in the serving network do not have knowledge of the relationship between the PMSI and the IMSI. Upon receipt of the PMSI in the attach request, the server generates a next PMSI to be used in a subsequent attach request and sends the next PMSI to the UE for confirmation. The UE confirms the next PMSI to synchronize between the UE and server and sends an acknowledgment token to the server. The UE and the server then each update local copies of the current and next PMSI values.

    Apparatus and method for mobility procedure involving mobility management entity relocation

    公开(公告)号:US09883385B2

    公开(公告)日:2018-01-30

    申请号:US15089396

    申请日:2016-04-01

    CPC classification number: H04W12/04 H04W12/02 H04W36/0038 H04W36/0055

    Abstract: A device that identifies entry into a new service area, transmits a service area update request to a network device associated with a network, receives a control plane message from the network indicating control plane device relocation or a key refresh due to a service area change in response to transmitting the service area update request, and derives a first key based in part on data included in the control plane message and a second key shared between the device and a key management device. Another device that receives a handover command from a network device associated with a network, the handover command indicating a new service area, derives a first key based on data included in the handover command and on a second key shared between the device and a key management device, and sends a handover confirmation message that is secured based on the first key.

    Methods and apparatus for providing network-assisted key agreement for D2D communications
    16.
    发明授权
    Methods and apparatus for providing network-assisted key agreement for D2D communications 有权
    为D2D通信提供网络辅助密钥协议的方法和设备

    公开(公告)号:US08873757B2

    公开(公告)日:2014-10-28

    申请号:US13655884

    申请日:2012-10-19

    CPC classification number: H04W12/04 H04L63/18 H04W76/14

    Abstract: A method, an apparatus, and a computer program product for wireless communication are provided in connection with facilitating secure D2D communications in a LTE based WWAN. In one example, a UE is equipped to send a shared key request using a first non-access stratum (NAS) message to a MME, calculate a first UE key based on a MME-first UE key, an uplink count value, and at least a portion of contextual information, receive a second NAS message from the MME, and calculate a final UE key based at least on the first UE key. In another example, a MME is equipped to receive a NAS message such as the message send by the first UE, calculate a first UE key, receive a message at least indicating successful contact with the second UE, and send a second NAS message to the first UE indicating the successful contact.

    Abstract translation: 提供了一种用于无线通信的方法,装置和计算机程序产品,用于促进基于LTE的WWAN中的安全的D2D通信。 在一个示例中,UE被配备为使用第一非接入层(NAS)消息向MME发送共享密钥请求,基于MME第一UE密钥,上行链路计数值,以及 至少一部分上下文信息,从MME接收第二NAS消息,并且至少基于第一UE密钥来计算最终UE密钥。 在另一示例中,MME被配备为接收诸如由第一UE发送的消息的NAS消息,计算第一UE密钥,接收至少指示与第二UE成功联系的消息,并向第二UE发送第二NAS消息 第一个UE指示成功的联系。

    METHODS AND APPARATUS FOR PROVIDING ADDITIONAL SECURITY FOR COMMUNICATION OF SENSITIVE INFORMATION
    17.
    发明申请
    METHODS AND APPARATUS FOR PROVIDING ADDITIONAL SECURITY FOR COMMUNICATION OF SENSITIVE INFORMATION 有权
    提供敏感信息通信附加安全的方法和装置

    公开(公告)号:US20140112475A1

    公开(公告)日:2014-04-24

    申请号:US13656112

    申请日:2012-10-19

    CPC classification number: H04W12/02 H04L63/0457 H04W12/04 H04W76/14

    Abstract: A method, an apparatus, and a computer program product for wireless communication are provided in connection with providing additional security for communication of sensitive information within a LTE based WWAN. In one example, a communications device is equipped to generate a keystream based on a mobility management entity-user equipment (MME-UE) key, a non-access stratum (NAS) message count value, and a contextual string associated with an informational element, and the contextual information, and cryptographically process the informational element using the generated keystream. In such an example, the communications device may be a UE, a MME, etc.

    Abstract translation: 提供一种用于无线通信的方法,装置和计算机程序产品,用于提供用于在基于LTE的WWAN内的敏感信息的通信的附加安全性。 在一个示例中,通信设备被配备为基于移动性管理实体 - 用户设备(MME-UE)密钥,非接入层(NAS)消息计数值和与信息元素相关联的上下文字符串来生成密钥流 ,以及上下文信息,并使用生成的密钥流密码地处理信息元素。 在这种示例中,通信设备可以是UE,MME等

    Network access privacy
    19.
    发明授权

    公开(公告)号:US12052372B2

    公开(公告)日:2024-07-30

    申请号:US17650813

    申请日:2022-02-11

    Abstract: The present disclosure provides techniques that may be applied, for example, in a multi-slice network for maintaining privacy when attempting to access the network. An exemplary method generally includes transmitting a registration request message to a serving network to register with the serving network; receiving a first confirmation message indicating a secure connection with the serving network has been established; transmitting, after receiving the first confirmation message, a secure message to the serving network comprising an indication of at least one configured network slice that the UE wants to communicate over, wherein the at least one configured network slice is associated with a privacy flag that is set; and receiving a second confirmation message from the serving network indicating that the UE is permitted to communicate over the at least one configured network slice.

Patent Agency Ranking