EP2037652A2

Methods and apparatuses for detecting whether user equipment resides in a trusted or a non-trusted access network

Abstract

The invention provides a method for trust relationship detection between a core and access network for a user equipment. The gist is that a security tunnel establishment procedure is used so one entity, be it part of the core network or be it the user equipment itself, is provided with information to determine whether the access network is trusted or untrusted. The information may comprise a first IP address/prefix, which is initially assigned to the user equipment, upon attaching to the access network. The necessary information may further comprise a second IP address/prefix, which is an address/prefix that is allocated at a trusted entity of the core network. Depending which entity determines the trust relationship of the access network, it might be necessary to transmit either the first IP address/prefix or the second IP address/prefix or the first and the second IP address/prefix using the security tunnel establishment procedure.

EP2037652A2, drawing sheet 1
Sheet 1 of 8

Term

Projected expiry 28 April 2028.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

15 claims: 4 independent, 11 dependent

  1. 1
    A method for determining the trust relationship between a core network and an access network for a user equipment, that attaches to the access network, wherein the core network comprises a first gateway, the method comprising the steps of:upon attaching to the access network, receiving by the user equipment a first IP address/prefix, assigned to the user equipment by the access network, exchanging messages of a security tunnel establishment procedure, performed between the user equipment and the first gateway, the messages including information on the first IP address/prefix and/or a home IP address/prefix of the user equipment, and determining in the first gateway or in the user equipment, whether or not the access network is trusted by the core network, based on the first IP address/prefix and on the home IP address/prefix.
  2. 9
    A method for determining the trust relationship between a core network and an access network for a user equipment, that attaches to the access network, wherein the core network comprises a packet data network gateway, the method comprising the steps of:transmitting an initiation message from the user equipment to the packet data network gateway, and wherein in case no reply or an error message is received from the packet data network gateway in response to the initiation message, the user equipment determines that the access network is not trusted by the core network.
  3. 11
    A user equipment attached to an access network, wherein a trust relationship between a core network, comprising a first gateway, and the access network is determined, the user equipment comprising:a receiver adapted to receive a first IP address/prefix, assigned to the user equipment by the access network, the receiver and a transmitter being adapted to exchange messages of a security tunnel establishment procedure, performed between the user equipment and the first gateway, the messages including information on the first IP address/prefix and/or a home IP address/prefix of the user equipment, a processor adapted to determine whether or not the access network is trusted by the core network, based on the first IP address/prefix and on the home IP address/prefix.
  4. 12
    A gateway in a core network, wherein a trust relationship between the core network and an access network is determined for a user equipment, attached to the access network, the gateway comprising:a receiver and transmitter adapted to exchange messages of a security tunnel establishment procedure, performed between the user equipment and the gateway, the messages including information on a first IP address/prefix, received by the user equipment upon attaching to the access network, and assigned to the user equipment by the access network, wherein the messages further include information on a home IP address/prefix of the user equipment, and a processor adapted to determine whether or not the access network is trusted by the core network, based on the first IP address/prefix and on the home IP address/prefix.
  5. 15
    The gateway according to one of claims 12 to 14, wherein the first gateway is an evolved packet data gateway, and wherein wherein the receiver is adapted to receive a message of the security tunnel establishment procedure, the transmitter is adapted to transmit a mobility message to a packet data network gateway, wherein the mobility message triggers the packet data network gateway to return the home IP address/prefix to the evolved packet data gateway.