EP2583480A2

Apparatus and method for transitioning an enhanced security context from a utran/geran-based serving network to an e-utran-based serving network

Abstract

This record has no abstract on file.

Term

4.7 yearsto projected expiry

Projected expiry 16 June 2031, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

13 claims: 13 independent, 0 dependent

  1. 1
    Claims of equivalent WO 2011159948 A2 CLAIMS 1. A method for transitioning a security context from a first-type serving network to a second-type serving network, comprising:the remote station generating first and second session keys, in accordance with the security context, using a first information element and a first root key associated with the first-type serving network;the remote station receiving a first message from the second-type serving network, wherein the first message signals to the remote station to generate a second root key for use with the second-type serving network;the remote station generating, in response to the first message, the second root key using the first root key and the first and second session keys as inputs;and the remote station protecting wireless communications, on the second-type serving network, based on the second root key.
  2. 2
    A method for transitioning as defined in claim 1, wherein the security context comprises an enhanced security context, the first-type security serving network comprises a UTRAN/GERAN-based serving network, the second-type serving network comprises an E-UTRAN-based serving network, the first root key comprises a first enhanced security context root key, and the second root key comprises a second enhanced security context root key.
  3. 3
    A method for transitioning as defined in claim 1, wherein the first information element comprises a count.
  4. 4
    4 A method for transitioning as defined in claim 1, wherein the remote station comprises a mobile user equipment.
  5. 5
    A remote station, comprising:means for generating first and second session keys, in accordance with a security context, using a first information element and a first root key associated with a the first- type serving network;means for receiving a first message from a second-type serving network, wherein the first message signals to the remote station to generate a root key for use with the second-type serving network;means for generating, in response to the first message, the second root key from the first root key using the first and second session keys as inputs;and means for protecting wireless communications, on the second-type serving network, based on the second root key.
  6. 6
    A remote station as defined in claim 5, wherein the security context comprises an enhanced security context, the first-type security serving network comprises a UTRAN/GERAN-based serving network, the second-type serving network comprises an E-UTRAN-based serving network, the first root key comprises a first enhanced security context root key, and the second root key comprises a second enhanced security context root key.
  7. 7
    A remote station as defined in claim 5, wherein the first information element comprises a count.
  8. 8
    A remote station, comprising:a processor configured to: generate first and second session keys, in accordance with a security context, using a first information element and a first root key associated with a first-type serving network;receive a first message from a second-type serving network, wherein the first message signals to the remote station to generate a second root key for use with the second-type serving network;generate, in response to the first message, the second root key using the first root key and the first and second session keys as inputs;and protect wireless communications, on the second-type serving network, based on the second root key.
  9. 9
    A remote station as defined in claim 8, wherein the security context comprises an enhanced security context, the first-type security serving network comprises a UTRAN/GERAN-based serving network, the second-type serving network comprises an E-UTRAN-based serving network, the first root key comprises a first enhanced security context root key, and the second root key comprises a second enhanced security context root key.
  10. 10
    A remote station as defined in claim 8, wherein the information element comprises a count.
  11. 11
    A computer program product, comprising:computer-readable storage medium, comprising: code for causing a computer to generate first and second session keys, in accordance with a security context, using a first information element and a first root key associated with a first-type serving network;code for causing a computer to receive a first message from a second- type serving network, wherein the first message signals to the remote station to generate a second root key for use with the second-type serving network;code for causing a computer to generate, in response to the first message, the second root key using the first root key and the first and second session keys as inputs;and code for causing a computer to protect wireless communications, on the second-type serving network, based on the second root key.
  12. 12
    A computer program product as defined in claim 11, wherein the security context comprises an enhanced security context, the first-type security serving network comprises a UTRAN/GERAN-based serving network, the second-type serving network comprises an E-UTRAN-based serving network, the first root key comprises a first enhanced security context root key, and the second root key comprises a second enhanced security context root key.
  13. 13
    A computer program product as defined in claim 11, wherein the first information element comprises a count.