EP2007160A1

Method and device for performing a handover and communication system comprising such device

Abstract

A method and a device are provided for performing a handover of a first instance from a first network to a second network, the method comprising the steps of (a) a security transfer message is sent to a second instance (HSS, AAA Server); (b) the second instance processes security parameters; and (c) the second instance initiates an authentication based on the security parameters processed.

EP2007160A1, drawing sheet 1
Sheet 1 of 7

Term

Projected expiry 19 June 2027.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

16 claims: 14 independent, 2 dependent

  1. 1
    A method for performing a handover of a first instance from a first network to a second network comprising the following steps:(a) a security transfer message is sent to a second instance (HSS, AAA Server);(b) the second instance processes security parameters;(c) the second instance initiates an authentication based on the security parameters processed.
  2. 3
    The method according to any of the preceding claims, wherein the step (b) comprises:- evaluating parameters in order to determine and/or obtain said security parameters;- mapping of security parameters;- derivation of security parameters;- calculation of security parameters.
  3. 4
    The method according to any of the preceding claims, wherein the initiation of the authentication comprises at least a transfer of a security context, in particular an EAP success information.
  4. 5
    The method according to any of the preceding claims, wherein the first instance is of the following type:- a user equipment;- a mobile terminal;- a mobile computer;- a mobile network element.
  5. 6
    The method according to any of the preceding claims, wherein the first network and/or the second network is of the following type:- a WiMAX network;- an I-WLAN network;- a 3GPP access network;- in general a trusted non-3GPP access network;- in general a non-trusted non-3GPP access network.
  6. 7
    The method according to any of the preceding claims, wherein the security transfer message is sent from the first instance.
  7. 8
    The method according to any of the preceding claims, wherein the security transfer message is sent from a 3GPP access node.
  8. 9
    The method according to any of the preceding claims, wherein the security transfer message is a security context transfer message, in particular a security context transfer request.
  9. 10
    The method according to any of the preceding claims, wherein the second instance is of the following type:- an authentication, authorization and accounting server;- a home subscriber server.
  10. 11
    The method according to any of the preceding claims, wherein the first network and the second network are of different type.
  11. 12
    A device for data processing comprising a processor unit that is arranged such that the method according of any of the preceding claims is executable on said processor unit.
  12. 14
    A device for initiating a handover of a first instance from a first network to a second network comprising:- a first unit for receiving a security transfer message;- a second unit for processing security parameters;- a third unit for initiating an authentication based on the security parameters processed.
  13. 15
    The device according to any of claims 12 to 14, said device is - an authentication, authorization and accounting server and/or- a home subscriber server.
  14. 16
    Communication system comprising the device according to any of claims 12 to 15.