Abstract:
A method and apparatus for performing a multiple Pre-Shared Key (PSK) based authentication in a single procedure is described, where the multiple PSK based authentication generates a combined credential in a terminal by using a plurality of credentials including a user identifier and the PSK, and authenticates the terminal in an authentication server by using the combined credential.
Abstract:
Disclosed is an apparatus and method for generating a security key in a mobile communication system that performs security key generation. An Authentication, Authorization and Accounting (AAA) server generates a Master Session Key (MSK) and an Enhanced MSK (EMSK) from a Long Term Credential key, and a Device-MSK (D-MSK), a User-MSK (U-MSK) and a Device and User-MSK (DU-MSK) from the MSK and the EMSK. An Access Gateway (AG) generates a Root-MSK (R-MSK) from the MSK and EMSK received from the AAA server. A Signaling Radio Network Controller (SRNC) generates a Pairwise Master Key (PMK) from the R-MSK received from the AG, and a Traffic Session Key (TSK) from the PMK. A Base Station (BS) sets up a radio connection to a Mobile Station (MS) using the TSK received from the SRNC, and performs radio communication using the set radio connection. The MS generates an MSK and an EMSK, and generates there from a D-MSK, a U-MSK, a DU-MSK, an R-MSK, a PMK, an SRK and a TSK, to perform radio communication with the BS.
Abstract:
A method and apparatus for supporting a Short Message Service (SMS) of a Mobile Station (MS) during an idle mode in a wireless communication system are provided. An MS operation method for supporting an SMS in a wireless communication system includes receiving an SMS message from a Base Station (BS) through a ranging message in an idle mode, upon receiving the SMS message from the BS, starting a timer, while the timer operates, waiting UpLink (UL) resource allocation for transmission of an ACKnowledge (ACK) message about the SMS message, and, upon being allocated a UL resource for the ACK message transmission, transmitting the ACK message using the UL resource.
Abstract:
A method and apparatus for performing device authentication and user authentication in a mobile communication network are provided. A connection is established between an MS and an SRNC that controls communications of the MS through a BS. The SRNC receives a D-MSK for device authentication of the MS from an AAA server that has completed an EAP negotiation with the MS and stores the D-MSK by the SRNC, when the BS triggers an EAP authentication after the connection establishment. The SRNC receives an R-MSK from an AG and stores the R-MSK after the connection establishment. The R-MSK is generated using a U-MSK for user authentication of the MS received from the AAA server by the AG. The SRNC generates a PMK for use during a session using at least one of the D-MSK and the R-MSK, and one of the BS and the SRNC generate a key set using the PMK, for use in at least one of data encryption, data integrity check, and session management during the session.
Abstract:
A method and apparatus providing an emergency communication service in a wireless communication system. A mobile station (MS) transmits a message requesting the emergency communication service to a base station (BS), receives a connection setup request message from the BS, the connection setup request message including a Service Flow Identifier (SFID) indicating that a service flow corresponding to the emergency communication service has been generated, a Flow Identifier (FID) between the BS and the MS for providing the emergency communication service, and an indicator indicating a connection request for the emergency communication service, performs a setup procedure for using the service flow based on the SFID, the FID, and the indicator and, upon completion of the setup procedure, transmits a data packet for the emergency communication service to the BS.
Abstract:
An authentication method and apparatus in a communication system are provided. In a method for authenticating a first node at a second authentication server in a communication system comprising the first node registered to a first authentication server and a second node registered to the second authentication server, an authentication request message requesting authentication of the first node is received from the second node, the authentication request message is transmitted to the first authentication server, and upon receipt of an authentication success message indicating successful authentication of the first node from the first authentication server, the authentication success message is transmitted to the second node.
Abstract:
An apparatus and a method of a mobile communication system is provided. In a method for changing a Quality of Service (QoS) of a base station in a mobile communication system, when a QoS parameter change is detected from a packet received from a terminal, the changed QoS parameter is determined. A Generic Route Encapsulation (GRE) packet to which the changed QoS parameter has been applied is transmitted to an upper node. When a Dynamic Service Change (DSC) performance with the terminal is requested by the upper node, the DSC is performed with the terminal. The changed QoS parameter is applied.
Abstract:
A local Packet Data Network (PDN) access method of a User Equipment (UE) in a wireless communication system is provided. The local Packet Data Network (PDN) access method in a wireless communication system according to the present invention includes transmitting a local PDN connectivity request message from a base station to a Mobility Management Entity (MME); transmitting a bearer request message from the MME received the PDN connectivity request message to a Serving Gateway (SGW) proxy of the base station; forwarding the bearer request message from the SGW proxy to a PDN Gateway (PGW) proxy of the base station; transmitting a bearer response message indicating a local PDN access service of the base station in gateway mode from the PGW proxy to the SGW proxy; forwarding the bearer response message from the SGW to the MME; transmitting a bearer setup message from the MME received the bearer response message to the base station; and connecting a mobile terminal to the local PDN based on information contained in the bearer setup message.
Abstract:
A method and apparatus for network reentry of a Mobile Station (MS) in a wireless communication system are provided. The method includes receiving allocation of a context search identifier from a network while a network entry procedure is performed, and transmitting a ranging request message including the allocated context search identifier to a Base Station (BS) when a network reentry event occurs.
Abstract:
A Master Session Key (MSK) refresh in a wireless communication system is provided. A MSK refreshing method MSK includes when receiving a first Media Access Control (MAC) message including MSK refresh indication information from a Base Station (BS), generating, at a Mobile Station (MS), an Extended Master Session Key (EMSK)_Hash by applying a hash function to an EMSK and sending a second MAC message including the EMSK_Hash, sending, at the BS, a context request message including the EMSK_Hash to an Access Service Network GateWay (ASN-GW), sending, at the ASN-GW, an authentication request message including the EMSK_Hash to an authentication server, when receiving the authentication request message including the EMSK_Hash, confirming, at the authentication server, the same EMSK as the MS based on the EMSK_Hash, determining an MSK1 using the EMSK, and sending an authentication accept message including the MSK1 to the ASN-GW, and sending, at the ASN-GW, a context report message including an Authorization Key (AK) context to the BS.