EP1124397A2

Simplified security for handoff in wireless communications

Abstract

The defined boundaries in a network are pushed down to the base station level. Doing so necessitates authentication each time a wireless terminal switches communication, or "handoffs" from one base station to another. To achieve such authentication in an efficient manner, security information, i.e., the derived information, is transferred from one base station directly to another. By directly it is meant without accessing any other source of the derived information, although the information may be transferred via other intervening nodes of the network that form an interconnection path for the base stations. A simplified network, i.e., a network with reduced hierarchy from a control point of view, e.g., one that only requires home location register and base station network entities along with interconnection therefore, may be employed with a minimal decrease in performance, e.g., a minimal increase in delay, during the handoff process. In one embodiment of the invention, a first base station which initially receives a service request from a wireless terminal requests authentication information from a central security node and receives in response at least, one, but typically two or more, sets of security information. When it is time for a handoff from the first base station to a second base station, the first base station transmits to the second base station at least one of the sets of security information it received from the central security node. The second base station then uses the information it received from the first base station to authenticate the wireless terminal.

EP1124397A2, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Projected expiry passed 29 January 2021, 5.7 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

22 claims: 22 independent, 0 dependent

  1. 1
    A method for facilitating secure handoff in a network having at least first and second wireless base stations and a least one wireless mobile terminal, the method comprising the steps of:receiving a request from said at least one wireless mobile terminal for a handoff from said first base station to said second base station;and transferring security information from said first base station to said second base station in response to said request.
  2. 2
    The invention as defined in claim 1 further wherein said security information includes a set including at least a random number, an authenticator derivable by said wireless mobile terminal but not said first or second base stations, and a key.
  3. 3
    The invention as defined in claim 1 further wherein at least a portion of said security information is used to validate said at least one mobile wireless terminal to said second base station.
  4. 4
    The invention as defined in claim 1 further wherein said security information transferred from said first base station to said second base station in response to said request is less than all of the security information received by said first base station.
  5. 5
    The invention as defined in claim 4 wherein all of the security information received by said first base station was received from a wireless mobile terminal validation system.
  6. 6
    The invention as defined in claim 4 wherein all of the security information received by said first base station was received from a third base station.
  7. 7
    The invention as defined in claim 1 wherein said transferring security information from said first base station to said second base station in response to said request is performed only when said first base station knows said second base station prior to said receiving step.
  8. 8
    The invention as defined in claim 1 further comprising the step of initiating an encrypted link between said second base station and said wireless terminal when said first base station and said wireless terminal were communicating using an encrypted link, said second base station using said security information transferred from said first base station to said second base station in initiating said encrypted link between said second base station and said wireless terminal.
  9. 9
    A method for performing handoffs in a network for providing wireless communication service having at least first and second wireless base stations and a least one wireless terminal, the method comprising the steps of:transmitting a request, from said wireless terminal for a handoff between said first base station to said second base station;receiving a response at said wireless terminal when said second base station knows said first base station prior to receiving said request indicating that said second base station can engage in facilitated handoffs with said first base station;and connecting said wireless terminal for user traffic to said second base station.
  10. 10
    The invention as defined in claim 9 wherein said facilitated handoff employs information about said wireless terminal transferred from said first base station to second base station.
  11. 11
    The invention as defined in claim 10 wherein said information is security information.
  12. 12
    The invention as defined in claim 10 wherein said information is security information received from a security center.
  13. 13
    The invention as defined in claim 10 wherein said information is security information received from a base station other than said first or second base stations.
  14. 14
    The invention as defined in claim 10 wherein said information is security information and includes at least one from the set consisting of:(i) a password, (ii) a challenge-response pair, and (iii) a challenge-response cipher key tuple.
  15. 15
    The invention as defined in claim 10 wherein said information is security information that is received over a network for inter base station communication.
  16. 16
    The invention as defined in claim 10 wherein said connecting step further includes the step of    initiating an encrypted link between said second base station and said wireless terminal when said first base station and said wireless terminal were communicating using an encrypted link prior to said handoff request, said second base station using security information transferred from said first base station to said second base station as part of said response in initiating said encrypted link between said second base station and said wireless terminal.
  17. 17
    A method for performing handoffs in a network having at least first and second wireless base stations and a least one wireless terminal, the method comprising the steps of:transmitting a request, from said wireless terminal for a handoff between said first base station to said second base station;when said second base station does not know said first base station prior to receiving said request, receiving at said wireless terminal an indication that it must connect to said second base station without benefit of information supplied from said first base station.
  18. 18
    The invention as defined in claim 17 wherein said information is security information.
  19. 19
    The invention as defined in claim 17 wherein said information is security information received from a security center.
  20. 20
    The invention as defined in claim 17 wherein said information is security information received from a base station other than said first or second base stations.
  21. 21
    A method for performing a handoff in a wireless network having at least first and second base stations and a least one wireless terminal, the method comprising the steps of:receiving a request, by said second base station, from said wireless terminal for a handoff between said first base station to said second base station;performing an expedited handoff when second base station knows said first base station prior to receiving said request;and performing a nonexpedited handoff when second base station does not know said first base station prior to receiving said request.
  22. 22
    The invention as defined in claim 21 wherein said step of performing an expedited handoff includes the step of transferring security information from said first base station to said second base station.
Independent claims22