GENERATION OF MULTIPLE SHARED KEYS BY USER EQUIPMENT AND BASE STATION USING KEY EXPANSION MULTIPLIER
    2.
    发明申请
    GENERATION OF MULTIPLE SHARED KEYS BY USER EQUIPMENT AND BASE STATION USING KEY EXPANSION MULTIPLIER 有权
    使用主要扩展单元的用户设备和基站生成多个共享的KEYS

    公开(公告)号:US20160127893A1

    公开(公告)日:2016-05-05

    申请号:US14527231

    申请日:2014-10-29

    IPC分类号: H04W12/04 H04W72/04 H04W12/02

    摘要: In one embodiment, multiple keys are generated in user equipment of a communication system based at least in part on a designated key expansion multiplier. A key identifier is received in the user equipment from a base station of the communication system. The user equipment selects a particular one of the keys as a function of the received key identifier, and utilizes the selected one of the keys to secure data sent from the user equipment to the base station. For example, the keys may comprise respective portions of a key stream generated by the user equipment responsive to a message received from the base station, with the keys being shared by the user equipment and the base station through independent generation of the key stream in the base station. The base station may illustratively comprise an evolved Node B (eNB) of an Evolved Universal Terrestrial Radio Access Network (E-UTRAN).

    摘要翻译: 在一个实施例中,至少部分地基于指定的密钥扩展乘法器在通信系统的用户设备中生成多个密钥。 从通信系统的基站在用户设备中接收到密钥标识符。 用户设备根据所接收的密钥标识符来选择密钥中的特定密钥,并利用所选择的一个密钥来保护从用户设备发送到基站的数据。 例如,密钥可以包括由用户设备响应于从基站接收到的消息生成的密钥流的相应部分,密钥由用户设备和基站通过独立生成密钥流在 基站。 基站可以示例性地包括演进的通用陆地无线电接入网络(E-UTRAN)的演进节点B(eNB)。

    Verification of cell authenticity in a wireless network through traffic monitoring

    公开(公告)号:US10200862B2

    公开(公告)日:2019-02-05

    申请号:US15383725

    申请日:2016-12-19

    摘要: We disclose various embodiments that enable a mobile terminal to confirm authenticity of a base station before the mobile terminal proceeds to camp on the corresponding cell. In an example embodiment, the authentication processing includes the mobile terminal tuning to a selected control channel of the base station to monitor RF signals transmitted thereon. The base station is deemed to be authentic if the monitored RF signals indicate the presence of live traffic between the base station and one or more other mobile terminals. The control channel can be selected from a fixed set of uplink and/or downlink control channels that are typically used by a legitimate base station. The presence of live traffic on the selected control channel can be detected by detecting certain control messages that are typically transmitted on that control channel between the base station and one or more mobile terminals served by that base station.

    NETWORK-INITIATED DETACH PROCEDURES IN A NEUTRAL HOST NETWORK

    公开(公告)号:US20180199384A1

    公开(公告)日:2018-07-12

    申请号:US15403573

    申请日:2017-01-11

    发明人: Semyon Mizikovsky

    IPC分类号: H04W76/06 H04W16/14

    摘要: A neutral host network is configured to provide services supported by any one or more of multiple Participating Service Providers (PSPs) to user equipment in an unlicensed frequency band. The neutral host network includes a neutral host gateway configured for communication with at least one external network, a mobility management entity (MME), and a local authentication, authorization, and accounting (AAA) server configured to determine that a session involving the user equipment is to be detached from the neutral host network. The local AAA server is also configured to transmit, to the neutral host gateway, a first message to initiate session detach of the session involving the user equipment. The neutral host gateway can be configured to transmit a second message to the MME in response to receiving the first message. The MME is configured to perform session detach for the session in response to receiving the second message.

    Validating cell access mode
    5.
    发明授权

    公开(公告)号:US09986420B2

    公开(公告)日:2018-05-29

    申请号:US14790228

    申请日:2015-07-02

    摘要: An example method includes receiving at a User Equipment (UE) a value for an Access Mode identifier and a value for a Closed Subscriber Group (CSG) identifier in one or more cell advertisements, selecting a cell based on the or more cell advertisements, and reporting in a message the value of the Access Mode identifier and the value CSG identifier for the cell advertisement of the cell selected. A core network element receives a first Access Mode identifier value and a first CSG identifier value, these first values associated with a cell advertisement of a cell selected by a UE; receives a second Access Mode identifier value and a second CSG identifier value, these second values reported by the cell selected by the UE; performs a comparison of first and second Access Mode identifier value and/or first and second CSG identifier values; and takes action based on the comparison.

    VERIFICATION OF CELL AUTHENTICITY IN A WIRELESS NETWORK USING AN EXTENDED TIME STAMP

    公开(公告)号:US20180124697A1

    公开(公告)日:2018-05-03

    申请号:US15383733

    申请日:2016-12-19

    IPC分类号: H04W48/20 H04W12/06

    摘要: We disclose various embodiments that enable a mobile terminal to confirm authenticity of a base station before the mobile terminal proceeds to camp on the corresponding cell, e.g., during an idle mode. In an example embodiment, the authentication processing includes the mobile terminal validating a digital signature included in an information block received from a candidate base station, the digital signature having been generated by the base station using an extended time stamp that indicates the calendar year, month, and/or day in addition to the UTC time-counter value. The information block typically includes a truncated time stamp, which the mobile terminal uses to reconstruct the extended time stamp, the reconstruction being performed using a system time stamp that was previously broadcast by the base station. The reconstructed time stamp is then fed, together with other relevant data, into a security algorithm that can confirm the validity of the digital signature.

    Generation of mobile session identifier for neutral host network

    公开(公告)号:US10187917B2

    公开(公告)日:2019-01-22

    申请号:US15243414

    申请日:2016-08-22

    发明人: Semyon Mizikovsky

    摘要: An identifier of a mobile session is generated for a mobile device accessing a network operating in an unlicensed radio band (e.g., Neutral Host Network). Generation of at least one part of the identifier comprises generating a random binary value, converting the random binary value into a decimal value, and truncating the decimal value to a number of decimal digits consistent with an identifier recognizable by a network operating in a licensed radio band (e.g., 3GPP Evolved Packet Core).

    Generation of multiple shared keys by user equipment and base station using key expansion multiplier
    8.
    发明授权
    Generation of multiple shared keys by user equipment and base station using key expansion multiplier 有权
    用户设备和基站使用密钥扩展倍增器生成多个共享密钥

    公开(公告)号:US09585013B2

    公开(公告)日:2017-02-28

    申请号:US14527231

    申请日:2014-10-29

    摘要: In one embodiment, multiple keys are generated in user equipment of a communication system based at least in part on a designated key expansion multiplier. A key identifier is received in the user equipment from a base station of the communication system. The user equipment selects a particular one of the keys as a function of the received key identifier, and utilizes the selected one of the keys to secure data sent from the user equipment to the base station. For example, the keys may comprise respective portions of a key stream generated by the user equipment responsive to a message received from the base station, with the keys being shared by the user equipment and the base station through independent generation of the key stream in the base station. The base station may illustratively comprise an evolved Node B (eNB) of an Evolved Universal Terrestrial Radio Access Network (E-UTRAN).

    摘要翻译: 在一个实施例中,至少部分地基于指定的密钥扩展乘法器在通信系统的用户设备中生成多个密钥。 从通信系统的基站在用户设备中接收到密钥标识符。 用户设备根据所接收的密钥标识符来选择密钥中的特定密钥,并利用所选择的一个密钥来保护从用户设备发送到基站的数据。 例如,密钥可以包括由用户设备响应于从基站接收到的消息生成的密钥流的相应部分,密钥由用户设备和基站通过独立地生成密钥流中的密钥流来共享 基站。 基站可以示例性地包括演进的通用陆地无线电接入网络(E-UTRAN)的演进节点B(eNB)。

    Verification of cell authenticity in a wireless network using a system query

    公开(公告)号:US10200861B2

    公开(公告)日:2019-02-05

    申请号:US15383715

    申请日:2016-12-19

    摘要: We disclose various embodiments that enable a mobile terminal to authenticate a base station before the mobile terminal proceeds to attach to the corresponding network and/or camp on the corresponding cell, e.g., during the initial network selection and attachment or during an idle mode. In an example embodiment, the authentication processing includes the mobile terminal generating and sending to a candidate base station a system query with a nonce. The candidate base station is deemed to be authentic only if the acknowledgement generated and transmitted in response to the system query includes a copy of the nonce properly signed by a digital signature generated using one or more security keys. In some embodiments, the system query may also include a request for GPS coordinates and/or selected system information signed using a digital signature, which the mobile terminal may beneficially use to further strengthen the protection against a spoofing attack.

    Preventing collision of mobile session identifiers in neutral host network

    公开(公告)号:US10187906B2

    公开(公告)日:2019-01-22

    申请号:US15243466

    申请日:2016-08-22

    发明人: Semyon Mizikovsky

    摘要: A first identifier of a mobile session is generated for a mobile device accessing a network operating in an unlicensed radio band, wherein at least one part of the first mobile session identifier comprises a decimal format consistent with an identifier recognizable by a network operating in a licensed radio band. The first mobile session identifier is compared to one or more previously generated mobile session identifiers currently allocated in the unlicensed radio band network to prevent collision there between.