IL222384A

Apparatus and method for signaling enhanced security context for session encryption and integrity keys

Abstract

This record has no abstract on file.

IL222384A, drawing sheet 1
Sheet 1 of 6

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

31 claims: 4 independent, 27 dependent

  1. 1
    What is claimed is:1. A method for establishing a first security context between a remote station and a serving network, the first security context having a security property that is not supported by a second security context, the method comprising: forwarding, by the remote station, a first message to the serving network, wherein the remote station supports secure wireless communications using either the first security context or the second security context, the first message includes an information element signaling that the remote station supports the first security context, and the second security context provides secure wireless communications without supporting use of the information element;generating, by the remote station, a session integrity key and a session cipher key, in accordance with the first security context, using the information element;receiving, by the remote station in response to the first message, a second message having a message authentication code that indicates the serving network supports the first security context for secure wireless communications with the remote station, which first security context includes use of the information element not supported by the second security context;checking, by the remote station, the message authentication code using the session integrity key;and in response to successfully checking the message authentication code, having, by the remote station, wireless communications protected by the session cipher key.
  2. 8
    A remote station, comprising:means for forwarding a first message to a serving network, wherein the remote station supports secure wireless communications using either a first security context or a second security context, the first message includes an information element signaling that the remote station supports the first security context, and the second security context provides secure wireless communications without supporting use of the information element;means for generating a session integrity key and a session cipher key, in accordance with the first security context, using the information element;means for receiving, in response to the first message, a second message having a message authentication code that indicates the serving network supports the first security context for secure wireless communications with the remote station, which first security context includes use of the information element not supported by the second security context;means for checking the message authentication code using the session integrity key;and means for having wireless communications, in response to successfully checking the message authentication code, protected by the session cipher key.
  3. 15
    A remote station, comprising:a processor configured to: forward a first message to a serving network, wherein the remote station supports secure wireless communications using either a first security context or a second security context, the first message includes an information element signaling that the remote station supports the first security context, and the second security context provides secure wireless communications without supporting use of the information element;generate a session integrity key and a session cipher key, in accordance with the first security context, using the information element;receive, in response to the first message, a second message having a message authentication code that indicates the serving network supports the first security context for secure wireless communications with the remote station, which first security context includes use of the information element not supported by the second security context;check the message authentication code using the session integrity key;and have wireless communications, in response to a successful check of the message authentication code, protected by the session cipher key.
  4. 22
    A computer program product, comprising:non-transitory computer-readable medium, comprising: code for causing a computer to forward a first message to a serving network, wherein the computer supports secure wireless communications using either a first security context or a second security context, the first message includes an information element signaling that the computer supports the first security context, and the second security context provides secure wireless communications without supporting use of the information element;code for causing a computer to generate a session integrity key and a session cipher key, in accordance with the first security context, using the information element;code for causing a computer to receive, in response to the first message, a second message having a message authentication code that indicates the serving network supports the first security context for secure wireless communications with the remote station, which first security context includes use of the information element not supported by the second security context;code for causing a computer to check the message authentication code using the session integrity key;and code for causing a computer to have wireless communications, in response to a successful check of the message authentication code, protected by the session cipher key.