Security capability negotiation methods and devices
12 claims: 5 independent, 7 dependent
- 1A method during a handover of a user equipment, UE, from a first network to a second network, comprising:receiving (205), by an access network entity of the second network, from a core network, CN, entity of the second network, various security capability sets supported by the UE, wherein various security capability sets supported by the UE include at least one radio resource control, RRC/user plane, UP, algorithm supported by the UE;selecting (207), by the access network entity of the second network, an RRC/UP algorithm supported by both the UE and the access network entity of the second network, wherein the selected RRC/UP algorithm is selected according to the at least one RRC/UP algorithm supported by the UE, and at least one RRC/UP algorithm supported by the access network entity of the second network;and sending (208, 209), by the access network entity of the second network, the selected RRC/UP algorithm via the CN entity of the second network to the first network.
- 4An access network entity of a second network comprising:a first means configured to receive, from a core network, CN, entity of the second network during a handover of a user equipment, UE, from a first network to a second network, various security capability sets supported by the UE, wherein various security capability sets supported by the UE include at least one radio resource control, RRC/UP algorithm supported by the UE;a second means configured to select, an RRC/UP algorithm supported by both the UE and the access network entity of the second network, wherein the selected RRC/UP algorithm are selected according to the at least one RRC/UP algorithm supported by the UE and at least one RRC/UP algorithm supported by the access network entity of the second network;and a third means configured to send the selected RRC/UP algorithm via the CN entity of the second network to the first network.
- 7A method during a handover of a user equipment, UE, from a first network to a second network, comprising:receiving(203), by a core network, CN, entity of a second network, various security capability sets supported by the UE from a CN entity of the first network, wherein various security capability sets supported by the UE include at least one radio resource control, RRC/user plane, UP, algorithm supported by the UE;sending(205), by the CN entity of a second network, the at least one RRC/UP algorithm supported by the UE to an access network entity of the second network;receiving(208), by the CN entity of a second network, from the access network entity of the second network, a selected RRC/UP algorithm supported by both the UE and the access network entity of the second network;and sending(209), by the CN entity of a second network, the selected RRC/UP algorithm to the CN entity of the first network.
- 8A core network, CN, entity of a second network:a first means configured to receive various security capability sets supported by a user equipment, UE, from a CN entity of the first network during a handover of the UE from a first network to a second network, wherein various security capability sets supported by the UE include at least one radio resource control, RRC/user plane, UP, algorithm supported by the UE;a second means configured to send the at least one RRC/UP algorithm supported by the UE to an access network entity of the second network;a third means configured to receive from the access network entity of the second network, a selected RRC/UP algorithm supported by both the UE and the access network entity of the second network;and a fourth means configured to send the selected RRC/ UP algorithm to the CN entity of the first network.
Independent claims5
66 paragraphs in 5 sections, as filed
FIELD
0001The present invention relates to the field of communications, and more particularly to a security capability negotiation method, system, and equipment.
BACKGROUND
0002Referring to <figref idref="f0001">FIG. 1</figref>, an existing 3<sup>rd</sup> Generation Partnership Project (3GPP) radio network is divided into a 3GPP radio access network (RAN) and a core network (CN).
0003The 3GPP RAN is further classified into three types as follows.
0004GSM edge radio access network (GERAN): 2G/2.5G access network, collectively referred to as 2G access network below, and including a base transceiver station (BTS) and a base station controller (BSC).
0005Universal terrestrial radio access network (UTRAN): 3G access network, including a node B (NodeB) and a radio network controller (RNC).
0006Evolved UMTS terrestrial radio access network (EUTRAN): also known as future long term evolution (LTE) access network, including an evolved node B (eNodeB, and eNB for short below).
0007The above three RANs are all configured to implement functions related to radio services, and meanwhile realize security capability negotiation with terminals.
0008A 2G/3G core network is further divided into a circuit-switched (CS) domain and a packet-switched (PS) domain. For ease of illustration, CS-related entities are omitted, and only the PS domain is remained. The PS domain performs data service exchange and routing with external packet-based networks beforehand, and includes a serving GPRS support node (SGSN) and a gateway GPRS support node (GGSN). The SGSN is mainly configured to realize route-forwarding, mobility management, session management, and user authentication, and the GGSN is mainly configured to realize the connection with the external packet-based networks, and also implement data transmission on the user plane.
0009A future evolved core network is also referred to as a system architecture evolution (SAE), including entities such as a mobility management entity (MME) and SAE gateway (SAE GW)/packet data network gateway (PDN GW)/home subscriber server (HSS). Similar to the SGSN, the MME is mainly configured to realize mobility management and user authentication. The SAE GW/PDN GW serves as anchor points on the user plane between different access systems. The HSS is mainly configured to store user subscription data.
0010In the 2G network, the SGSN performs the security capability algorithm negotiation between the signaling plane and the user plane. In the 3G network, the RNC performs the security capability algorithm negotiation between the signaling plane and the user plane. In the evolved network LTE/SAE, as the RNC/SGSN does not exist, the MME performs the non-access signaling (NAS) algorithm negotiation, and the eNB performs the radio resource control (RRC)/user plane (UP) algorithm negotiation.
0011When a user is handed over from a 2G/3G network (2G/3G) to an LTE network, or from an LTE to a 2G/3G network, as the entities responsible for the security capability negotiation change and the security capabilities thereof may be different, the security capability negotiation needs to be re-performed. Here, the security capability negotiation means encryption algorithm for the 2G network, means integrity protection algorithm and encryption algorithm for the 3G network, and means NAS algorithm (encryption algorithm and integrity protection algorithm), RRC algorithm (encryption algorithm and integrity protection algorithm), and UP algorithm (encryption algorithm) for the LTE network.
0012Particularly, during the handover from the LTE network to the 2G/3G network, a user equipment (UE) sends its own GERAN (encryption algorithm)/UTRAN security capability (encryption algorithm and integrity protection algorithm) carried in an initial Layer 3 message to the MME. The MME then sends the capabilities of the UE to the SGSN. The SGSN selects and sends the corresponding GERAN/UTRAN security capability algorithm to the UE through the MME During the handover from the LTE to 2G, the SGSN selects the security capability algorithm. However, during the handover from the LTE to 3G, according to the above description about the 3G network, the RNC, instead of the SGSN, selects the security capability algorithm; otherwise, the SGSN has to introduce a new requirement of selecting the security capability algorithm. Meanwhile, the SGSN must know the security capability of the RNC in a certain manner, and then sends the selected algorithm to the RNC, so that additional interaction between the SGSN and the RNC needs to be constructed.
0013During the handover from the 2G/3G to the LTE, the SGSN queries the UE for the NAS (encryption algorithm and integrity protection algorithm)/UP (encryption algorithm)/RRC (encryption algorithm and integrity protection algorithm) security capability. During the handover from the 2G/3G to the LTE, the SGSN sends the capabilities of the UE to the MME Then, the MME selects and sends all the NAS/RRC/UP security capability algorithms to the UE through the SGSN.
0014In the implementation of the present invention, it is found in the prior art that, as the MME selects all the NAS/RRC/UP security capability algorithms, the MME must know the security capability of the corresponding eNB in a certain manner (for example, by configuring or extending interactive messages with the eNB), thus resulting in an inflexible configuration and a complicated process flow.
0015D1 (3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Rationale and track of security decisions in Long Term Evolved (LTE) RAN / 3GPP System Architecture Evolution (SAE) (Release 8); XP050376898) provides a method that during handover from 2G/3G to LTE, MME shall select the algorithms to use and acknowledge its choice to UE in the handover command sent to UE over SGSN.
SUMMARY
0016The claimed invention relates to a method, an apparatus, a method and an apparatus as defined in independent claims 1, 4, 7 and 8, respectively.
BRIEF DESCRIPTION OF THE DRAWINGS
0017<ul id="ul0001" list-style="none" compact="compact"><li><figref idref="f0001">FIG. 1</figref> is a structural view of a conventional 3GPP radio network.</li><li><figref idref="f0002">FIG. 2</figref> is a flow chart illustrating a security capability negotiation method during the handover from a 2G/3G network to an LTE network according to a first embodiment of the present invention.</li><li><figref idref="f0003">FIG. 3</figref> is a flow chart illustrating a security capability negotiation method during the handover from an LTE network to a 3G network according to a second embodiment the present invention.</li><li><figref idref="f0003">FIG. 4</figref> is a schematic structural view illustrating a security capability negotiation system according to a third embodiment of the present invention.</li></ul>
DETAILED DESCRIPTION OF THE EMBODIMENTS
0018Embodiments of the present invention are illustrated in detail below with reference to the accompanying drawings.
0019Referring to <figref idref="f0002">FIG. 2</figref>, the security capability negotiation method according to the first embodiment includes the following processes.
0020In this embodiment, the UE is handed over from 2G/3G to the LTE. First, it is assumed that a UE accesses services via a 2G/3G access network (2G/3G Access).
0021In process 201, the 2G/3G access network determines to initiate a handover.
0022In process 202, the 2G/3G access network initiates a handover request message to the SGSN.
0023In process 203, the SGSN initiates a handover preparation request message to the MME. The handover preparation request message carries various security capability sets supported by the UE, including NAS algorithm (encryption algorithm and integrity protection algorithm), RRC algorithm (encryption algorithm and integrity protection algorithm), and UP algorithm (encryption algorithm).
0024Here, the SGSN may obtain the security capability sets supported by the UE in the following methods.
0025The SGSN directly requests the UE to send the security capability sets supported thereby.
0026A 2G/3G access network entity (BSS or RNC) first determines to initiate a handover, then requests the UE for the security capability sets supported thereby, and sends the capability sets to the SGSN in process 202.
0027In process 204, the MME selects a NAS algorithm (encryption algorithm and integrity protection algorithm) according to the UE supported NAS algorithm (encryption algorithm and integrity protection algorithm), the system allowable NAS algorithm (encryption algorithm and integrity protection algorithm), together with the NAS algorithm (encryption algorithm and integrity protection algorithm) supported by the MME itself.
0028It should be noted that, as the UE supported NAS algorithm (encryption algorithm and integrity protection algorithm), the system allowable NAS algorithm (encryption algorithm and integrity protection algorithm), and the NAS algorithm (encryption algorithm and integrity protection algorithm) supported by the MME itself are all various, the selected NAS algorithm (encryption algorithm and integrity protection algorithm ) is a NAS algorithm (encryption algorithm and integrity protection algorithm) supported by all the UE, the system and the MME.
0029In process 205, the MME sends a handover preparation request message to the eNB. The handover preparation request message carries the UE supported RRC algorithm (encryption algorithm and integrity protection algorithm) and UP algorithm (encryption algorithm), and may also carry the system allowable RRC algorithm (encryption algorithm and integrity protection algorithm) and UP algorithm (encryption algorithm).
0030In process 206, a bearer resource between the eNB and the MME is established, including the establishment of a radio resource.
0031In process 207, the eNB selects the RRC algorithm (encryption algorithm and integrity protection algorithm) and UP algorithm (encryption algorithm) according to the UE supported RRC algorithm (encryption algorithm and integrity protection algorithm) and UP algorithm (encryption algorithm), together with the RRC security capability sets (encryption algorithm and integrity protection algorithm) and UP security capability sets (encryption algorithm) supported by the eNB itself.
0032It should be noted that, as the UE supported RRC algorithm (encryption algorithm and integrity protection algorithm) and UP algorithm (encryption algorithm), the system allowable RRC algorithm (encryption algorithm and integrity protection algorithm) and UP algorithm (encryption algorithm), and the RRC algorithm (encryption algorithm and integrity protection algorithm) and UP algorithm (encryption algorithm) supported by the eNB itself are various, the selection here means selecting the RRC algorithm (encryption algorithm and integrity protection algorithm) and UP algorithm (encryption algorithm) which are both supported by the UE and the MME.
0033In process 205, if the handover preparation request message sent by the MME to the eNB also carries the system allowable RRC algorithm (encryption algorithm and integrity protection algorithm) and UP algorithm (encryption algorithm), the eNB may further combine the system allowable RRC algorithm (encryption algorithm and integrity protection algorithm) and UP algorithm (encryption algorithm) to select the RRC algorithm (encryption algorithm and integrity protection algorithm) and UP algorithm (encryption algorithm) which are supported by all the UE, the MME and the system.
0034In process 208, the eNB sends a handover preparation acknowledgement message to the MME. The handover preparation acknowledgement message carries the selected RRC algorithm (encryption algorithm and integrity protection algorithm) and UP algorithm (encryption algorithm).
0035In process 209, the MME sends a handover preparation acknowledgement message to the SGSN. The handover preparation acknowledgement message carries the selected NAS algorithm (encryption algorithm and integrity protection algorithm), RRC algorithm (encryption algorithm and integrity protection algorithm), and UP algorithm (encryption algorithm).
0036In processes 210 to 211, the SGSN sends a handover command message to the UE via the 2G/3G access network, for indicating the UE to hand over to a destination network. The handover command message carries the selected NAS algorithm (encryption algorithm and integrity protection algorithm), RRC algorithm (encryption algorithm and integrity protection algorithm), and UP algorithm (encryption algorithm).
0037In process 212, the subsequent handover process is implemented.
0038Thereby, the security capability negotiation between the UE and the network equipment (eNB/MME) is completed.
0039Process 204 may also be performed between processes 205 and 209. Process 207 may also be performed before process 206.
0040In this embodiment, during the handover from the 2G/3G to the LTE network, the NAS algorithm protection is implemented between the UE and the MME, the RRC/UP algorithm protection is implemented between the UE and the eNB, and the MME and the eNB are respectively configured to realize the negotiation of the NAS security algorithm and the RRC/UP security algorithm, so that it is unnecessary for the MME to know the security capability of the corresponding eNB in a certain manner (for example, by configuring or extending interactive messages with the eNB) as in the prior art.
0041Referring to <figref idref="f0003">FIG. 3</figref>, in a second embodiment of the present invention, a security capability negotiation method includes the following processes.
0042In this embodiment, a UE hands over from an LTE to 3G. First, it is assumed that a UE accesses services via an LTE access network (eNB).
0043In process 301, the eNB determines to initiate a handover.
0044In process 302, the eNB initiates a handover request message to the MME.
0045In process 303, the MME initiates a handover preparation request message to the SGSN. The handover preparation request message carries 3G security capability sets supported by the UE, including encryption algorithm and integrity protection algorithm.
0046Here, the MME may obtain the 3G security capability sets supported by the UE in the following methods.
0047Before the handover, an initial Layer 3 message already carries the 3G security capability sets supported by the UE, and the UE sends the capability sets to the MME.
0048The MME directly requests the UE to send the 3G security capability sets supported by the UE.
0049The eNB first determines to initiate a handover, then requests the UE for the 3G security capability sets supported by the UE, and sends the capability sets to the MME in process 302.
0050In process 304, the SGSN sends a handover preparation request message to the 3G access network (RNC). The handover preparation request message carries the 3G security capability sets supported by the UE. The 3G security capability sets supported by the UE includes encryption algorithm and integrity protection algorithm, and the handover preparation request may also carry the system allowable 3G security capability sets.
0051In process 305, a bearer resource between the 3G access network (RNC) and the SGSN is established, including the establishment of a radio resource.
0052In process 306, the 3G access network (RNC) selects the 3G security capability sets according to the 3G security capability sets supported by the UE together with the 3G security capability sets supported by the 3G access network itself.
0053It should be noted that, as the 3G security capability sets supported by the UE and the 3G security capability sets supported by the 3G access network (RNC) itself are various, the selection here means selecting the 3G security capability sets supported by the UE and the 3G access network (encryption algorithm and integrity protection algorithm) from the above two categories of 3G security capability sets.
0054In process 304, if the handover preparation request message sent by the SGSN to the 3G access network (RNC) also carries the system allowable 3G security capability sets, the 3G access network (RNC) may further combine the system allowable 3G security capability sets to select the 3G security capability sets.
0055In process 307, the 3G access network (RNC) sends a handover preparation acknowledgement message to the SGSN. The handover preparation acknowledgement message carries the selected 3G security capability sets.
0056In process 308, the SGSN sends a handover preparation acknowledgement message to the MME. The handover preparation acknowledgement message carries the selected 3G security capability sets.
0057In processes 309 to 310, the MME sends a handover command message to the UE via the eNB, indicating the UE to hand over to a destination network. The message carries the selected 3G security capability sets.
0058In process 311, the subsequent handover process is implemented.
0059Thereby, the security capability negotiation between the UE and the network equipment (RNC) is completed.
0060Process 306 may also be performed before process 305.
0061In this embodiment, the SGSN does not need to introduce new requirements during the handover from the LTE to the 3G network.
0062Referring to <figref idref="f0003">FIG. 4</figref>, in a third embodiment of the present invention, a security capability negotiation system is provided, which is applicable to perform security capability negotiation during a mobile network handover. The system includes an access network entity 401 and a core network entity 402 of a first network, and an access network entity 403 and a core network entity 404 of a second network. The access network entity 403 of the second network is configured to select a corresponding security capability when the first network requests to be handed over to the second network. The core network entity 404 of the second network is configured to select a corresponding security capability together with the access network entity 403 of the second network when the first network requests to be handed over to the second network. The core network entity 402 and the access network entity 401 of the first network are configured to send the security capabilities selected by the second network to a UE 405.
0063In this embodiment, a network including an access network entity and a CN entity is further provided. The access network entity is configured to receive a handover request sent by a peer-end network. The CN entity is configured to select and send a corresponding security capability to the UE via the peer-end network together with the access network entity of the network when the peer-end network requests to be handed over to the current network.
0064When the UE hands over from the 2G/3G network to the LTE network, the first network is a 2G network or a 3G network, the access network entity of the 2G network includes a BTS and a BSC. The access network entity of the 3G network includes a node (NodeB) and an RNC. The core network entity of the 2G/3G network includes an SGSN. The second network is an LTE RAN, the access network entity thereof is an evolved node (eNodeB), and the core network entity thereof is an MME. The security capability includes NAS integrity protection and encryption algorithm, RRC integrity protection and encryption algorithm, and UP encryption algorithm. The MME is configured to select the NAS integrity protection and encryption algorithm, and the eNodeB is configured to select the RRC integrity protection, encryption algorithm, and UP encryption algorithm. The working principle and process are shown in <figref idref="f0002">FIG. 2</figref>, and the details will not be repeated herein. The MME and the eNB are adopted to realize the negotiation of the NAS security algorithm and the RRC/UP security algorithm respectively, so that it is unnecessary for the MME to know the security capability of the corresponding eNB in a certain manner (for example, by configuring or extending interactive messages with the eNB) as in the prior art.
0065When the UE hands over from the LTE network to the 3G network, the access network entity of the first network is eNodeB, the core network entity of the first network is MME, the access network entity of the second network is RNC, and the core network entity of the second network is SGSN. The security capability includes 3G security capability sets, and the 3G security capability sets further include encryption algorithm and integrity protection algorithm. The working principle and process are shown in <figref idref="f0002">FIG. 2</figref>, and the details will not be repeated herein. The RNC is configured to select the 3G security capability sets, so that the SGSN does not need to introduce new requirements during the handover from the LTE to the 3G network, and the interaction between the SGSN and the RNC is also unnecessary.
0066Through the above description of the embodiments, it is apparent to those skilled in the art that the embodiments may be accomplished by software on a necessary universal hardware platform, and definitely may also be accomplished by hardware. Therefore, the technical solutions of the present invention can be substantially embodied in the form of a software product. The software product may be stored in a non-volatile storage medium such as a CD-ROM, USB disk, or removable hard disk, and contains several instructions to indicate a communication equipment (for example, a personal computer, server, or network equipment) to perform the method as described in the embodiments of the present invention.
Contents5
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| US2006026671A1 | Cites | United States of America |
| "3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Rationale and track of security decisions in Long Term Evolved (LTE) RAN / 3GPP System Architecture Evolution (SAE) (Release 8)", 3GPP STANDARD; 3GPP TR 33.821, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, no. V0.2.0, 1 April 2007 (2007-04-01), pages 1-82, XP050376898, | Non-patent | – |
21 members in 6 offices
Members21
| Document | Office | Kind | |
|---|---|---|---|
| CN101304600A | China | A | |
| WO2008134986A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2009275309A1 | United States of America | A1 | |
| EP2117248A1 | European Patent Office (EPO) | A1 | |
| JP2010521905A | Japan | A | |
| EP2117248A4 | European Patent Office (EPO) | A4 | |
| CN101304600B | China | B | |
| JP5010690B2 | Japan | B2 | |
| US8774759B2 | United States of America | B2 | |
| EP2117248B1 | European Patent Office (EPO) | B1 | |
| ES2554808T3 | Spain | T3 | |
| EP2966889A1 | European Patent Office (EPO) | A1 | |
| US2016150449A1 | United States of America | A1 | |
| US9668182B2 | United States of America | B2 | |
| US2018070275A1 | United States of America | A1 | |
| EP2966889B1 | European Patent Office (EPO) | B1 | |
| US10383017B2 | United States of America | B2 | |
| EP3554112A1 | European Patent Office (EPO) | A1 | |
| US2020068467A1 | United States of America | A1 | |
| US10958692B2 | United States of America | B2 | |
| EP3554112B1This record | European Patent Office (EPO) | B1 |
80 legal events, as 9 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | BE | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Deletion acc. to par. 5 (withdrawal of the translation of the ep patent)MK05 | MK05 | AT | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Invalidation of extension of european patentsMG9D | MG9D | LT | |
| Translation for ep filed (entry of ep into country)FP | FP | NL | |
| European patents granted designating irelandGrantedFG4D | FG4D | IE | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Reference to at number (ep patent validated in austria)REF | REF | AT | |
| Divisional application: reference to earlier applicationAC | AC | EP | |
| Divisional application: reference to earlier applicationAC | AC | EP | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE PATENT HAS BEEN GRANTEDSTAA | STAA | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: GRANT OF PATENT IS INTENDEDSTAA | STAA | EP | |
| Information related to disapproval of communication of intention to grant by the applicant or resumption of examination proceedings by the epo deletedORIGINAL CODE: EPIDOSDIGR1GRAJ | GRAJ | EP | |
| Information related to payment of fee for publishing/printing deletedORIGINAL CODE: EPIDOSDIGR3GRAL | GRAL | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: REQUEST FOR EXAMINATION WAS MADESTAA | STAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: GRANT OF PATENT IS INTENDEDSTAA | STAA | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: REQUEST FOR EXAMINATION WAS MADESTAA | STAA | EP | |
| Divisional application: reference to earlier applicationAC | AC | EP | |
| Divisional application: reference to earlier applicationAC | AC | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION HAS BEEN PUBLISHEDSTAA | STAA | EP |
Numbers
- Publication
- 3554112
- Application
- 191551803
Titles3
- German
- VERFAHREN UND APPARATE ZUR SICHERHEITSFÄHIGKEITSVERHANDLUNG
- English
- SECURITY CAPABILITY NEGOTIATION METHODS AND DEVICES
- French
- PROCÉDÉS ET ÉQUIPEMENTS DE NÉGOCIATION DE CAPACITÉ DE SÉCURITÉ
Classification
- CPC, 5
- H04L63/205
- H04W36/0038
- H04W12/10
- H04W12/037
- H04W36/1443
- IPC, 7
- H04W12 02
- H04L29 06
- H04W36 00
- H04W12 10
- H04W36 14
- H04W12 037
- H04W12 30
Designated states34
- Contracting states, 34
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
- Monaco
and 10 moreShow fewer
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye
