-
公开(公告)号:US20240056302A1
公开(公告)日:2024-02-15
申请号:US18447098
申请日:2023-08-09
Applicant: Nokia Technologies Oy
Inventor: Markus STAUFER , Peter SCHNEIDER , Ranganathan MAVUREDDI DHANASEKARAN
CPC classification number: H04L9/321 , H04L9/0819
Abstract: There is provided an apparatus, method and computer program for causing a first apparatus to: obtain an identifier of a cryptographic key according to a first security communication protocol; signal, to a second apparatus, a first authentication request according to a second security communication protocol, the first authentication request comprising the identifier of the cryptographic key and a first verifying information according to a second security communication protocol, wherein the first verifying information comprises a first value calculated using the cryptographic key; receive, from the second apparatus, an authentication response according to the second security communication protocol, the authentication response comprising a second verifying information according to the second security communication protocol, wherein the second verifying information comprises a second value; and verify the second apparatus for the second security communication protocol using the second value and the cryptographic key.
-
公开(公告)号:US20230198780A1
公开(公告)日:2023-06-22
申请号:US18065914
申请日:2022-12-14
Applicant: Nokia Technologies Oy
Inventor: Peter SCHNEIDER , Ranganathan Mavureddi Dhanasekaran
CPC classification number: H04L9/3263 , H04W12/06
Abstract: According to an example aspect of the present invention, there is provided a method comprising: generating a certificate comprising an identifier of a base station, a public key of the base station, and a public key of a terminal; signing the certificate by a signature based on a private key belonging to the public key of the base station; sending the signed certificate to the terminal using an established security association; monitoring whether the base station receives a request for local authentication of the terminal, wherein the request comprises an encrypted certificate unit and a base station identifier; checking whether the base station identifier is the identifier of the base station and, if it is, decrypting the encrypted certificate unit using the private key; and using the public key of the terminal for a communication with the terminal if the certificate unit comprises the signed certificate.
-
公开(公告)号:US20240056802A1
公开(公告)日:2024-02-15
申请号:US18446408
申请日:2023-08-08
Applicant: Nokia Technologies Oy
Inventor: Benoist Pierre SEBIRE , Peter SCHNEIDER
CPC classification number: H04W12/03 , H04L9/0618
Abstract: Methods and apparatus are disclosed for security of a wireless communication between a communication device and a counterpart communication device. A method performed at the communication device comprises, ciphering a fixed part of a medium access control (MAC) protocol data unit (PDU) at MAC layer for the wireless communication. The fixed part of the MAC PDU comprises at least one of the following fields: at least one MAC control element, or at least one header of radio protocol in the MAC PDU.
-
公开(公告)号:US20230413046A1
公开(公告)日:2023-12-21
申请号:US18334794
申请日:2023-06-14
Applicant: Nokia Technologies Oy
Inventor: Peter SCHNEIDER , Markus STAUFER , Ranganathan MAVUREDDI DHANASEKARAN
IPC: H04W12/06 , H04W40/22 , H04W12/08 , H04W12/033
CPC classification number: H04W12/06 , H04W12/033 , H04W12/08 , H04W40/22
Abstract: According to an example aspect of the present invention, there is provided an apparatus, such as a user equipment, configured to transmit to a cellular core network a request to open a protocol session to an external network which is external to the cellular core network, the request being configured to cause the cellular core network to transmit to the external network, or to receive from the external network, a code associated with a subscription of the apparatus, forward at least one authentication request originating in the external network to a node connected with the apparatus, via a local connection, and forward at least one authentication response from the node to the external network via the cellular core network, and relay packets comprised in the protocol session between the node and the external network without participating in the protocol session as an endpoint.
-
公开(公告)号:US20230007642A1
公开(公告)日:2023-01-05
申请号:US17851771
申请日:2022-06-28
Applicant: Nokia Technologies OY
Inventor: Guillaume DECARREAU , Samuli Heikki TURTINEN , Peter SCHNEIDER
Abstract: The apparatus includes at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to duplicate base station computation of an identifier value for a user equipment, and search for one or more control channel transmissions incorporating an identifier value matching the identifier value.
-
公开(公告)号:US20200045549A1
公开(公告)日:2020-02-06
申请号:US16340027
申请日:2016-10-07
Applicant: NOKIA TECHNOLOGIES OY
Inventor: Peter SCHNEIDER
Abstract: Internet of Things devices are provisioned with programmable subscriber units by arranging a secure end-to-end connection with an IoT Application Server IoTAS with a temporary connection through a mobile network that has been previously informed of the identities of the IoT devices. Through the secure end-to-end connection, the IoTAS provides an IoT device with provisioning information that enables mutual authentication between the mobile network and the IoT device so that the IoT device can be equipped with a programmable subscription that enables the IoT device to normally attach to the mobile network.
-
7.
公开(公告)号:US20240056805A1
公开(公告)日:2024-02-15
申请号:US18447341
申请日:2023-08-10
Applicant: Nokia Technologies Oy
Inventor: Markus STAUFER , Peter SCHNEIDER , Ranganathan MAVUREDDI DHANASEKARAN , Saurabh KHARE
IPC: H04W12/0431 , H04W12/069 , H04W12/03
CPC classification number: H04W12/0431 , H04W12/069 , H04W12/03
Abstract: A method is disclosed comprising: establishing an encrypted session with an application function based on a certificate; receiving a request for an application key from the application function using the encrypted session, wherein the request comprises a key identifier relating to a user device and an application function identifier; determining at least one response to the request for the application key from a set of possible responses, the set comprising at least a rejection and a message comprising the application key and a user device identifier; and transmitting the at least one response to the request for the application key to the application function. Furthermore, related methods, apparatuses, computer programs and systems are disclosed.
-
公开(公告)号:US20230171747A1
公开(公告)日:2023-06-01
申请号:US17997317
申请日:2021-04-29
Applicant: Nokia Technologies Oy
Inventor: Peter SCHNEIDER , Joerg SCHAEPPERLE
IPC: H04W72/044
CPC classification number: H04W72/044
Abstract: The present subject matter relates to a base station for a wireless communication system. The base station is configured to serve a set of user equipments. The base station comprises means configured for: allocating radio resources of the communication system for data communication between a specific subset of one or more user equipments of the set and the base station, enabling acquisition, by the subset of user equipments, of resource allocation information indicative of the allocated radio resources.
-
公开(公告)号:US20210219256A1
公开(公告)日:2021-07-15
申请号:US17055119
申请日:2018-05-18
Applicant: Nokia Technologies Oy
Inventor: Cinzia SARTORI , Anja JERICHOW , Peter SCHNEIDER
Abstract: Authentication in a public land mobile network, PLMN, having tenant slices is performed by a network element that has: a memory comprising program code; a communication circuitry for communication with entities in the PLMN; and a processing circuitry configured to execute the program code and according to the program code to cause: detecting a registration request from a mobile communication device, MCDt; detecting whether the registration request requests access to a network slice with one-tier authentication with the network slice, and: if yes, causing beginning of authenticating the MCDt with the network slice independently of any authentication between the MCDt and the PLMN.
-
-
-
-
-
-
-
-