Systems, methods, and apparatuses for ciphering error detection and recovery
17 claims: 3 independent, 14 dependent
- 1Patent claims Zastrzeżenia patentowe 1. A method including:1. Sposób obejmujący: using (310) a first set of one or more cipher input parameters to decrypt encrypted data in a received protocol data unit, the encrypted data being generated using a second set of one or more cipher input parameters;wykorzystanie (310) pierwszego zestawu jednego lub większej liczby parametrów wejściowych szyfru dla deszyfrowania danych zaszyfrowanych w odebranej jednostce danych protokołu, przy czym dane zaszyfrowane były generowane przy użyciu drugiego zestawu jednego lub większej liczby parametrów wejściowych szyfru;comparing (320) the value of at least a portion of the decrypted data with the expected value;porównywanie (320) wartości co najmniej części deszyfrowanych danych z wartością oczekiwaną;determining (330), using the decryption control circuits, an encryption error occurring when the value of at least a portion of the decrypted data is not equal to the expected value;and initiating (340) an encryption resynchronization procedure in response to determining that an encryption error has occurred, so as to synchronize at least one of the first set of encryption input parameters with at least one of the second set of encryption input parameters;wherein the encryption resynchronization procedure includes: określanie (330), za pomocą obwodów sterowniczych deszyfrowania, wystąpienia błędu szyfrowania, gdy wartość co najmniej części deszyfrowanych danych nie jest równa oczekiwanej wartości;i inicjowanie (340) procedury ponownej synchronizacji szyfrowania w reakcji na określenie, że wystąpił błąd szyfrowania, tak aby zsynchronizować co najmniej jeden z pierwszego zestawu parametrów wejściowych szyfrowania z co najmniej jednym z drugiego zestawu parametrów wejściowych szyfrowania;przy czym procedura ponownej synchronizacji szyfrowania obejmuje: selecting the most likely alternative value for at least one of the first set of encryption input parameters, said most likely alternative having an incremental encryption input parameter value when the encryption input parameter includes a parameter that increases with each received protocol data unit;wybieranie najbardziej prawdopodobnej alternatywnej wartości dla co najmniej jednego z pierwszego zestawu parametrów wejściowych szyfrowania, przy czym wymieniona najbardziej prawdopodobna alternatywa zawiera przyrostową wartość parametru wejściowego szyfrowania, gdy parametr wejściowy szyfrowania zawiera parametr, który wzrasta z każdą odebraną jednostką danych protokołu;decrypting the encrypted data in the received protocol data unit for which an encryption error occurred or the subsequently received protocol data unit, using the selected most likely alternative value;deszyfrowanie zaszyfrowanych danych w odebranej jednostce danych protokołu, dla której wystąpił błąd szyfrowania lub odebranej później jednostce danych protokołu, z użyciem wybranej najbardziej prawdopodobnej alternatywnej wartości;powtarzanie najbardziej prawdopodobnego wyboru alternatywnego parametru szyfrowania i deszyfrowanie, dopóki liczba powtarzanych prób nie przekroczy wcześniej zdefiniowanej liczby nieudanych prób ponownej synchronizacji;i określanie, że procedura ponownej synchronizacji szyfrowania nie powiodła się w reakcji na liczbę ponownych prób przekraczającą wcześniej zdefiniowaną liczbę nieudanych prób ponownej synchronizacji. repeating the most likely selection of the alternative encryption parameter and decrypting until the number of repeated attempts exceeds the predefined number of unsuccessful attempts to resync;and determining that the encryption resynchronization procedure failed in response to the number of retry attempts exceeding the predefined number of unsuccessful retry attempts.
- 7A device comprising at least one processor and at least one memory storing a computer program code, wherein the at least one memory and the code of the stored computer program are configured to, together with at least one processor, cause the device to be at least:7. Urządzenie zawierające co najmniej jeden procesor i co najmniej jedną pamięć przechowującą kod programu komputerowego, przy czym co najmniej jedna pamięć i kod przechowywanego programu komputerowego są skonfigurowane tak, aby wraz z co najmniej jednym procesorem powodować, że urządzenie będzie co najmniej: use (310) from the first set of one or more cipher input parameters to decrypt encrypted data in the received protocol data unit, the encrypted data being generated using the second set of one or more cipher input parameters;wykorzystywać (310) z pierwszego zestawu jednego lub większej liczby parametrów wejściowych szyfru dla deszyfrowania danych zaszyfrowanych w odebranej jednostce danych protokołu, przy czym dane zaszyfrowane były generowane przy użyciu drugiego zestawu jednego lub większej liczby parametrów wejściowych szyfru;compare (320) the values of at least a portion of the decrypted data with the expected value;porównywać (320) wartości co najmniej części deszyfrowanych danych z wartością oczekiwaną;determine (330) the occurrence of an encryption error when the value of at least part of the data being decrypted is not equal to the expected value;and initiating (340) an encryption resynchronization procedure in response to determining that an encryption error has occurred, so as to synchronize at least one of the first set of encryption input parameters with at least one of the second set of encryption input parameters;wherein the encryption resynchronization procedure includes: określać (330) występowanie błędu szyfrowania, gdy wartość co najmniej części deszyfrowanych danych nie jest równa wartości oczekiwanej;i inicjować (340) procedurę ponownej synchronizacji szyfrowania w reakcji na określanie, że wystąpił błąd szyfrowania, tak aby zsynchronizować co najmniej jeden z pierwszego zestawu parametrów wejściowych szyfrowania z co najmniej jednym z drugiego zestawu parametrów wejściowych szyfrowania;przy czym procedura ponownej synchronizacji szyfrowania obejmuje: selecting the most likely alternative value for at least one of the first set of encryption input parameters, said most likely alternative having an incremental encryption input parameter value when the encryption input parameter includes a parameter that increases with each received protocol data unit;wybieranie najbardziej prawdopodobnej alternatywnej wartości dla co najmniej jednego z pierwszego zestawu parametrów wejściowych szyfrowania, przy czym wspomniana najbardziej prawdopodobna alternatywa zawiera przyrostową wartość parametru wejściowego szyfrowania, gdy parametr wejściowy szyfrowania zawiera parametr, który wzrasta z każdą odebraną jednostką danych protokołu;decrypting the encrypted data in the received protocol data unit for which an encryption error occurred or the subsequently received protocol data unit, using the selected most likely alternative value;deszyfrowanie zaszyfrowanych danych w odebranej jednostce danych protokołu, dla której wystąpił błąd szyfrowania lub odebranej później jednostce danych protokołu, z użyciem wybranej najbardziej prawdopodobnej alternatywnej wartości;- repeating the most likely selection of the alternative encryption and decryption parameter until the number of repeated attempts exceeds the previously defined number of unsuccessful attempts to resync;and determining that the encryption resynchronization procedure failed in response to the number of retry attempts exceeding the predefined number of unsuccessful retry attempts. -24powtarzanie najbardziej prawdopodobnego wyboru alternatywnego parametru szyfrowania i deszyfrowania, dopóki liczba powtarzanych prób nie przekroczy wcześniej zdefiniowanej liczby nieudanych prób ponownej synchronizacji;i określenie, że procedura ponownej synchronizacji szyfrowania nie powiodła się w reakcji na liczbę ponownych prób przekraczającą wcześniej zdefiniowaną liczbę nieudanych prób ponownej synchronizacji.
- 14A computer program product containing at least one computer-readable storage medium containing program instructions read by the computer, wherein the program instructions read by the computer include:14. Produkt w postaci programu komputerowego zawierający co najmniej jeden odczytywany przez komputer nośnik pamięci zawierający przechowywane w nim instrukcje programowe odczytywane przez komputer, przy czym instrukcje programowe odczytywane przez komputer zawierają: a program instruction configured to use (310) the first set of one or more encryption input parameters to decrypt the encrypted data in the received protocol data unit, the encrypted data being encrypted using the second set of one or more encryption input parameters;instrukcję programową skonfigurowaną do wykorzystywania (310) pierwszego zestawu jednego lub większej liczby parametrów wejściowych szyfrowania, aby deszyfrować zaszyfrowane dane w odebranej jednostce danych protokołu, przy czym zaszyfrowane dane zostały zaszyfrowane przy użyciu drugiego zestawu jednego lub większej liczby parametrów wejściowych szyfrowania;a program instruction configured to compare (320) the value of at least a portion of the decrypted data with the expected value;instrukcję programową skonfigurowaną do porównywania (320) wartości co najmniej części deszyfrowanych danych z wartością oczekiwaną;a program instruction configured to determine (330) an encryption error occurring when the value of at least a portion of the data being decrypted is not equal to the expected value;and a program instruction configured to initiate (340) an encryption resynchronization procedure in response to determining that an encryption error has occurred, so as to synchronize at least one of the first set of encryption input parameters with at least one of the second set of encryption input parameters;the encryption resynchronization procedure includes program instructions configured to execute: instrukcję programową skonfigurowaną do określania (330) wystąpienia błędu szyfrowania, gdy wartość co najmniej części deszyfrowanych danych nie jest równa wartości oczekiwanej;i instrukcję programową skonfigurowaną do inicjowania (340) procedury resynchronizacji szyfrowania w reakcji na ustalenie, że wystąpił błąd szyfrowania, tak aby zsynchronizować co najmniej jeden z pierwszego zestawu parametrów wejściowych szyfrowania z co najmniej jednym z drugiego zestawu parametrów wejściowych szyfrowania;przy czym procedura resynchronizacji szyfrowania obejmuje instrukcje programowe skonfigurowane tak, aby wykonywały: selecting the most likely alternative value for at least one of the first set of encryption input parameters, said most likely alternative having an incremental encryption input parameter value when the encryption input parameter includes a parameter that increases with each received protocol data unit;wybieranie najbardziej prawdopodobnej alternatywnej wartości dla co najmniej jednego z pierwszego zestawu parametrów wejściowych szyfrowania, przy czym wspomniana najbardziej prawdopodobna alternatywa zawiera przyrostową wartość parametru wejściowego szyfrowania, gdy parametr wejściowy szyfrowania zawiera parametr, który wzrasta z każdą odebraną jednostką danych protokołu;decrypting the encrypted data in the received protocol data unit for which an encryption error occurred or the subsequently received protocol data unit, using the selected most likely alternative value;deszyfrowanie zaszyfrowanych danych w odebranej jednostce danych protokołu, dla której wystąpił błąd szyfrowania lub odebranej później jednostce danych protokołu, z użyciem wybranej najbardziej prawdopodobnej alternatywnej wartości;powtarzanie najbardziej prawdopodobnego wyboru alternatywnego parametru szyfrowania i deszyfrowania, dopóki liczba powtarzanych prób nie przekroczy wcześniej zdefiniowanej liczby nieudanych prób ponownej synchronizacji;i ustalanie, że procedura ponownej synchronizacji szyfrowania nie powiodła się w reakcji na liczbę ponownych prób przekraczającą wcześniej zdefiniowaną liczbę nieudanych prób resynchronizacji. repeating the most likely selection of the alternative encryption and decryption parameter until the number of repeated attempts exceeds the previously defined number of unsuccessful attempts to resynchronize;and determining that the encryption resynchronization procedure failed in response to the number of retry attempts exceeding the predefined number of failed resynchronization attempts.
Independent claims3
81 paragraphs in 1 section, as filed
Description
TECHNICAL FIELD [0001] Embodiments of this invention relate generally to communication technology and more particularly to systems, methods and devices for detecting and correcting errors.
BACKGROUND [0002] The modern era of telecommunications has led to a huge expansion of wired and wireless networks. Computer, television and telephone networks are experiencing an unprecedented technological development fueled by consumer demand. Wireless and mobile network technologies meet the related needs of consumers, while providing greater flexibility and timeliness of information transfer and convenience for users. In parallel with the expansion of the network, portable computer devices have been developed that use the features offered by wireless networks to facilitate mobile computing. Therefore, mobile communication devices and wireless networks are widely used by consumers to support the use of mobile processing in a wide range of communications.
US 2003/0091048 A1 discloses the detection of the lack of synchronization of the encryption parameters in the RLC entity. The transmitter fills in the unused data fields of the data packet before sending, and the receiver checks the content of the data fields and individual patterns of unused data fields of the received data packet for discrepancies. If the accumulated number of receiver errors exceeds the pre-set threshold value, the receiver will re-synchronize this communication link between the transmitter and the receiver.
US 4,654,480 A discloses that the error detection code is calculated from an encrypted data block and a unique sequence number. The error correction code is sent with an encrypted data block. When the encrypted data is received, the receiving device attaches to the received data blocks a sequence number derived from the local meter, which is synchronized with the meter in the transmitting device and the new error detection code is calculated for comparison with the error detection code received with the encrypted data. A mismatch between the error detection codes indicates a transmission or synchronization error for this block. In any case, the data block can be sent again.
[0003] To prevent a third party from violating data privacy in network communications, at least some of the data can be encrypted. Using encrypted communication may require the receiving unit to use the first set of one or more encryption input parameters to decrypt received encrypted data. The first set of cipher input parameters may require synchronization with the second set of one or more cipher input parameters used by the sending unit to encrypt the data so as to ensure accurate decryption by the receiving unit of the encrypted data. When the first and second set of encryption input parameters are out of sync, an encryption error may occur, so the receiving unit may not be able to accurately decrypt the encrypted data.
BRIEF SUMMARY OF EXAMPLES OF THE IMPLEMENTATION OF THE INVENTION
[0004] Systems, methods, devices and products in the form of computer programs according to the appended claims are therefore provided for detecting and correcting encryption errors. Accordingly, computer methods, devices and programs are provided that can provide a number of benefits to computer devices, computer device users, and network operators. Embodiments of the invention show a receiving device configured to determine the occurrence of an encryption error. In this regard, embodiments of the invention show a receiving device configured to determine the occurrence of an encryption error by comparing the value of the decrypted data with the expected value to determine whether the value of the decrypted data is equal to the expected value. This comparison allows some embodiments of the invention to determine the occurrence of an encryption error regardless of the type of service to which the encrypted protocol data unit is associated. Embodiments of the invention further disclose a receiving device configured to initiate an encryption error correction procedure so as to resynchronize a local set of one or more cipher input parameters used to decrypt received encrypted data using a set of one or more encryption input parameters used by the sending device for decryption. data encrypted before sending to the terminal. Some embodiments of the invention show a receiving device configured to initiate resynchronization of the radio link control with the sending device for resynchronizing one or more encryption input parameters. Embodiments of the invention also show a receiving device configured to autonomously resynchronize one or more cipher input parameters by selecting the most likely alternative value for at least one encryption input parameter.
[0005] In a first embodiment, a method is provided that includes using the first set of one or more encryption input parameters to decrypt encrypted data in a received protocol data unit. In the method of this embodiment, the encrypted data is encrypted using a second set of one or more encryption input parameters. The method of this embodiment further includes comparing the value of at least a portion of the decrypted data with the expected value. The method of this embodiment also includes determining the occurrence of an encryption error when the value of at least a portion of the decrypted data is not equal to the expected value. The method of this embodiment further includes initiating an encryption resynchronization procedure in response to determining that an encryption error has occurred so as to synchronize at least one of the first sets of encryption input parameters with at least one of the second set of encryption input parameters.
[0006] In another embodiment, the device is illustrated. The apparatus of this embodiment comprises at least one processor and at least one computer program code stored in memory, wherein at least one memory and the stored computer program code are configured so that, together with at least one processor, the device will use at least the first set of one or more encryption input parameters to decrypt data in the received protocol data unit. In the device according to this embodiment
- the encrypted data was encrypted using a second set of one or more encryption input parameters. The at least one memory and code of the stored computer program are configured to cause, with at least one processor, that the device according to this embodiment compares the value of at least a portion of the decrypted data with the expected value. The at least one memory and code of the stored computer program are configured to additionally cause the device according to this embodiment to determine the occurrence of an encryption error when the value of at least part of the decrypted data is not equal to the expected value. At least one memory and code of the stored computer program are configured so that, together with at least one processor, also cause that the device according to this embodiment initiates the procedure of resync encryption in response to determining that an encryption error has occurred, so as to resynchronize at least one of the first set of encryption input parameters with at least one of the second set of encryption input parameters.
[0007] In another embodiment, a computer program product is provided. A computer program product includes at least one computer-readable storage medium that includes computer-readable program instructions stored therein. Computer-readable program instructions may include a plurality of program instructions. Although the programming instructions are ordered in this summary, it should be understood that the summary is given for illustrative purposes only, and the ordering is only intended to facilitate a brief presentation of the computer program. The example in no way limits the implementation of related computer program instructions. The first program instruction according to this embodiment is configured to use the first set of one or more encryption input parameters to decrypt encrypted data in a received protocol data unit. The encrypted data of this embodiment is encrypted using a second set of one or more encryption input parameters. The second program instruction according to this embodiment is configured to compare the values of at least part of the decrypted data with the expected value. The third program instruction of this embodiment is configured to determine the occurrence of an encryption error when the value of at least a portion of the decrypted data is not equal to the expected value. The fourth program instruction of this embodiment is configured to initiate an encryption resynchronization procedure in response to determining that an encryption error has occurred, so as to resynchronize at least one of the first set of encryption input parameters with at least one of the second set of encryption input parameters.
[0008] In a further embodiment, a device is provided that comprises means for using the first set of one or more cipher input parameters for decrypting data encrypted in a received protocol data unit. The encrypted data of this embodiment is encrypted using a second set of one or more encryption input parameters. The device according to this embodiment further comprises means for comparing the value of at least part of the decrypted data with the expected value. The apparatus of this embodiment further includes means for determining the occurrence of an encryption error when the value of at least a portion of the decrypted data is not equal to the expected value. Device according to
This embodiment also includes means for initiating the resync encryption procedure in response to determining that an encryption error has occurred, so as to synchronize at least one of the first set of encryption input parameters with at least one of the second set of encryption input parameters.
[0009] The above summary is only provided to summarize some embodiments of the invention so as to provide a basic understanding of some aspects of the invention. In this connection, it should be understood that the above-described embodiments are only examples and should not be construed as limiting the scope of the invention in any way. It is to be understood that the scope of the invention includes many potential embodiments, some of which will be further described below, in addition to the examples summarized herein.
BRIEF DESCRIPTION OF THE FIGURES [0010] After a general description of the embodiments of the invention, reference should now be made to the accompanying drawings, which were not necessarily to scale, and in which:
Fig. 1 illustrates an encryption error detection and correction system according to an embodiment of the invention;
Fig. 2 is a block diagram of a mobile terminal according to an embodiment of the present invention;
Fig. 3 illustrates a flow diagram according to an exemplary method of detecting and correcting errors according to an embodiment of the invention;
Fig. 4 illustrates a flowchart according to an exemplary method of detecting and correcting errors according to an embodiment of the invention;
Fig. 5 illustrates a flowchart according to an exemplary method of detecting and correcting encryption errors according to an embodiment of the invention; and
Fig. 6 illustrates a flow diagram according to an exemplary method of detecting and correcting errors according to an embodiment of the invention.
DETAILED DESCRIPTION [0011] Some embodiments of this invention will now be more fully described with reference to the accompanying drawings, in which some but not all embodiments of the invention are shown. The invention may in fact be made in a variety of forms and should not be construed as being limited to the embodiments set forth in this description; these embodiments are provided to meet applicable legal requirements for disclosing the invention. Similar reference numbers refer to similar elements throughout the description.
[0012] The term "circuits" as used herein refers to (a) implementation of a hardware-only circuit (e.g. implementation of analog circuits and / or digital circuits); (b) a combination of circuits and computer program (s) containing program instructions and / or firmware stored in one or more computer-read memories that work together to cause the device to perform one or more functions described here; and (c) circuits, such as for example
-5 microprocessor (s) or part of the microprocessor (s) that requires software or firmware to operate. This definition of "circuits" applies to all uses of the term in this specification, including each of the claims. In addition, the term "circuits" as used herein also includes an implementation comprising one or more processors and / or parts thereof, and associated software and / or firmware. In another example, the term "circuits" in this application also includes, for example, a baseband integrated circuit or an application processor integrated circuit for a mobile phone or a similar integrated circuit in a server, a cellular network device, another network device and / or another computer device.
[0013] Fig. 1 illustrates a block diagram of a system 100 for detecting and correcting encryption errors according to an embodiment of the invention. The term "exemplary" as used herein is merely an example and as such means one embodiment of the invention and should not be construed as limiting the scope or purpose of the invention in any way. It is to be understood that the scope of the invention includes many potential embodiments in addition to the examples illustrated and described herein. In this regard, although FIG. 1 illustrates one example of a system configuration for detecting and correcting encryption errors; numerous other configurations can also be used to implement embodiments of this invention.
[0014] In at least some embodiments, the system 100 includes a receiving device 102 communicating with the transmitting device 104 via a network 108. The network 108 may include a wireless network, wireless network, or a combination thereof. In one embodiment, the network 108 includes a cellular network or a public terrestrial mobile network, such as that which can be configured to operate in accordance with the standards of the Third Generation Partnership Project (3GPP). The network 108 may include the Internet.
[0015] The receiving device 102 may be made as one or more computer devices. For example, the receiving device 102 may be implemented as a desktop computer, laptop, mobile terminal, portable computer, mobile phone, mobile communication device, gaming device, digital camera / camcorder, audio / video player, television device, radio receiver, digital video recorder. , positioning device, any combination thereof and / or the like configured to receive data over network 108, which have been encrypted and / or transmitted by the transmitting device 104. In another example, the receiving device 102 may include a network node (e.g., radio network controller (RNC), mobility management unit (MME) or the like) configured to decrypt data transmitted via transmitting device 104, access point (e.g. base station, node B, expanded node B and / or other network access point) configured to provide access to network 108, receive encrypted data from transmitting device 104, any other network node configured to perform at least some of the functionality assigned here the transmitting device 104, their connection, etc.
[0016] The transmitting device 104 may be similarly constructed as one or more computer devices. For example, the transmitting device 104 may be configured as a desktop computer, laptop, mobile terminal, portable computer, mobile phone, mobile communication device, gaming device, digital camera / camcorder, audio / video player, television device, radio receiver, digital video recorder. , positioning device, any combination thereof and / or the like configured for encryption and / or
Transmitting data encrypted by the network 108 to the receiving device 102. In another example, the sending device 104 may include a network node (e.g., radio network controller (RNC), network management point (MME) or the like) configured to encrypt data for transmission to the device receiving point 102, access point (e.g. base station, node B, expanded node B and / or other network access point) configured to provide access to network 108 and send encrypted data to the receiving device 102, any other network node configured to perform at least some assigned function here, the sending device 104, some combination thereof, or the like.
In one embodiment, the receiving device 102 and / or the transmitting device 104 is depicted as a mobile terminal as shown in FIG. 2. In this regard, FIG. 2 illustrates a block diagram of a mobile terminal 10 showing one embodiment of a receiving device 102 and / or a transmitting device 104 according to embodiments of the invention. However, it should be understood that the mobile terminal 10 illustrated and described below is merely an illustration of one type of receiving device 102 and / or transmitting device 104 that can implement and / or use embodiments of the invention and therefore does not limit the scope of the invention. Although several embodiments of electronic devices have been illustrated and will be described by way of example, other types of electronic devices such as cell phones, laptops, portable digital assistants (PDAs), pagers, laptops, desktops, gaming devices, televisions and other types of systems electronic devices may use embodiments of the invention.
[0017] As shown, the mobile terminal 10 may include an antenna 12 (or multiple antennas 12) communicating with the transmitter 14 and the receiver 16. The mobile terminal 10 may also include a processor 20 configured to provide signals for and receive signals from the transmitter and receiver respectively. For example, the processor 20 may be implemented as various means including circuits, one or more microprocessors with associated digital signal processor (s), one or more processors without an associated digital signal processor, one or more coprocessors, one or more multi-core processors, one or more controllers, processing circuits, one or more computers, various other processing elements including integrated circuits, such as, for example, ASIC (application-specific integrated circuit) or FPGA (programmable logic gate matrix), or a combination thereof. Although in FIG. 2 shows a single processor, in some embodiments, processor 20 includes multiple processors. These signals sent and received by processor 20 may include signaling information in accordance with the wireless interface standard of a given cellular system and / or any number of different wired or wireless network techniques, including but not limited to Wireless-Fidelity (WiFi), Wireless Local Access (WLAN) , such as the standard Institute of Electrical and Electronics Engineers (IEEE) 802.11, 802.16 and / or the like. In addition, these signals may include speech data, user generated data, user requested data and / or the like. In this regard, the mobile terminal may be capable of operating with one or more wireless interface standards, communication protocols, modulation types, access types and / or the like. More specifically, the mobile terminal may be capable of operating in accordance with various communication protocols of the first
- 7th generation (1G), second generation (2G), 2.5G, third generation (3G), fourth generation (4G), Internet Protocol Multimedia Subsystem (IMS) communication protocols, communication protocols (e.g. session initiation protocol (SIP)) and / or the like. For example, a mobile terminal may be capable of operating in accordance with 2G IZ-136 (Time Division Multiple Access (TDMA)), Global System for Mobile communications (GSM), IS-95 (Code Division Multiple Access (CDMA)) communication protocols and / or the like. Furthermore, for example, the mobile terminal may be capable of operating in accordance with 2.5G General Packet Radio Service (GPRS), Enhanced Data GSM Environment (EDGE) wireless communication protocols and / or the like. In addition, for example, a mobile terminal may be capable of operating in accordance with 3G wireless communication protocols such as Universal Mobile Telecommunications System (UMTS), Code Division Multiple Access 2000 (CDMA2000), Wideband Code Division Multiple Access (WCDMA), Time Division-Synchronous Code Division Multiple Access (TD-SCDMA) and / or the like. For example, the mobile terminal may be configured to transmit and / or receive data transmitted in accordance with the high speed packet access (HSDPA) receiving protocol, the high speed packet access (HSUPA) transmission protocol and / or the like. The mobile terminal may also be capable of operating in accordance with 3.9G wireless communication protocols such as Long Term Evolution (LTE) or Evolved Universal Terrestrial Radio Access Network (EUTRAN) and / or the like. In addition, for example, the mobile terminal may be capable of operating in accordance with fourth generation (4G) wireless communication protocols and / or the like, as well as similar wireless communication protocols that may be developed in the future.
[0018] Some terminals of the narrowband advanced mobile telephony system (NAMPS) as well as the Total Access Communication System (TAC) may also use embodiments of the invention, as may telephones supporting two or more modes (e.g. digital / analog telephones or TDMA / CDMA / analog). In addition, the mobile terminal 10 may be capable of operating in accordance with the Wireless Fidelity (WiFi) or Worldwide Interoperability for Microwave Access (WiMAX) protocols.
[0019] It should be understood that the processor 20 may include circuits for implementing the audio / video and logic functions of the mobile terminal 10. For example, the processor 20 may include a digital signal processing device, microprocessor device, an analog-to-digital converter, a digital-to-analog converter and / or the like. The control and signal processing functions of the mobile terminal can be allocated between these devices according to their respective functionalities. The processor may further include an internal voice encoder (VC) 20a, an internal data modem (DM) 20b and / or the like. In addition, the processor 20 may include functionality to support one or more programs that may be stored in memory. For example, the processor 20 may be capable of operating a communication program such as a web browser. The communication program may allow the mobile terminal 10 to transmit and receive internet content, such as location based content, according to a protocol such as Wireless Application Protocol (WAP), hypertext transfer protocol (HTTP) and / or the like. The mobile terminal 10 may be able to use a transmission control / internet protocol (TCP / IP) to transmit and receive internet content over the internet or other networks.
[0020] The mobile terminal 10 may also include a user interface comprising, for example, telephone or loudspeaker 24, bell 22, microphone 26, display 28, user input interface and / or the like which can be operatively coupled to the processor
twenty. In this regard, the processor 20 may include user interface circuits configured to control at least some of the functions of one or more user interface elements, such as, for example, speaker 24, bell 22, microphone 26, display 28 and / or the like. The processor 20 and / or user interface circuits comprising the processor 20 may be configured to control one or more functions of one or more user interface elements by means of computer program instructions (e.g., software and / or firmware) stored in the memory available to the processor 20 (e.g., non-volatile memory 40, non-volatile memory 42 and / or the like). Although not shown, the mobile terminal may include a battery for powering various circuits associated with the mobile terminal, e.g. a circuit for generating mechanical vibration in the form of a detectable output. The user input interface may include devices allowing the mobile terminal to receive data, such as a keyboard 30, touch display (not shown), joystick (not shown) and / or other input device. In embodiments involving the keyboard, the keyboard may include numeric keys (0-9) and associated keys (#, *) and / or other keys for operating the mobile terminal.
[0021] As shown in Fig. 2, the mobile terminal 10 may also include one or more means for sharing and / or obtaining data. For example, the mobile terminal may include a short range radio frequency (RF) transceiver and / or a calling device 64 so that the data can be shared with and / or obtained from electronic devices using RF techniques. The mobile terminal may contain other short-range transceivers, such as, for example, infrared (IR) 66 transceiver, Bluetooth ™ transceiver (BT) 68 operating using Bluetooth ™ wireless technology developed by Bluetooth ™ Special Interest Group, transceiver 70 wireless universal serial bus (USB) and / or the like. The Bluetooth ™ 68 transceiver may be capable of operating in accordance with very low power Bluetooth ™ technology radio standards (eg Wibree ™). In this regard, the mobile terminal 10 and in particular the short-range transceiver may be able to transmit data to and / or receive data from electronic devices near the mobile terminal, e.g. within 10 meters. Although not shown, the mobile terminal may be capable of transmitting and / or receiving data from electronic devices according to various wireless network techniques, including Wireless Fidelity (Wi-Fi), WLAN techniques such as IEEE 802.11 techniques, IEEE 802.16 techniques and / or the like.
[0022] The mobile terminal 10 may include a memory, such as a subscriber identification module (SIM) 38, a replaceable user identification module (R-UIM), a universal subscriber identification module (USIM) and / or the like that may store information elements related mobile subscriber. In addition to the SIM, the mobile terminal may contain other removable and / or permanent memory. The mobile terminal 10 may include a non-volatile memory 40 and / or a non-volatile memory 42. For example, non-volatile memory 40 may include working memory (RAM) including dynamic and / or static RAM, cache on or off chip, and / or the like. Persistent memory 42, which can be embedded and / or removable, can include, for example, memory
-9 read-only, flash memory, magnetic mass storage (e.g., hard disks, floppy disks, magnetic tapes, etc.), optical disks and / or media, permanent random access memory (NVRAM) and / or the like. Like non-persistent memory 40, persistent memory 42 may include a cache area for temporarily storing data. The memories may store one or more programs, instructions, information items, data and / or the like that can be used by the mobile terminal to perform the functions of the mobile terminal. For example, the memories may contain an identifier, such as an international mobile device identification code (IMEI), capable of uniquely identifying the mobile terminal 10.
[0023] Returning now to FIG. 1, in one embodiment, the receiving device 102 includes various means such as a processor 110, memory 112, communication interface 114 and decryption control circuits 118 for performing the various functions described herein. These means of the receiving device 102 as described herein may be exemplary as e.g. circuits, hardware components (e.g. appropriately programmed processor, combination logic and / or the like), a product in the form of a computer program containing computer-readable program instructions (e.g. software or firmware) stored on a computer-readable medium (e.g. memory 112) which is executed by properly configured processing device (e.g. processor 110) or any combination thereof.
[0024] Processor 110 may, for example, be implemented as various means comprising one or more microprocessors with associated digital signal processor (s), one or more processors without associated digital signal processor (s) , one or more coprocessors, one or more multi-core processors, one or more controllers, processing circuits, one or more computers, various other processing elements including integrated circuits, such as, for example, ASIC (application-specific integrated circuit) or FPGA (programmable logic gate matrix), or a combination thereof. Although in FIG. 1 is a single processor, in some embodiments, processor 110 includes multiple processors. A plurality of processors may be in operational communication with each other and may be collectively configured to perform one or more functions of the receiving device 102 as described herein. Multiple processors may be made in a single computer device or arranged in multiple computer devices collectively configured to perform one or more functions of the receiving device 102 as described herein. In embodiments in which the receiving device 102 is made as a mobile terminal 10, the processor 110 may be made as a processor 20 or may include it. In one embodiment, the processor 110 is configured to execute instructions stored in memory 112 or otherwise available to processor 110. These instructions, carried out by the processor 110, may cause the receiving device 102 to perform one or more functions of the receiving device 102 as described herein. The processor 110, configured by means of hardware or software methods, or by means of a combination thereof, may include a unit capable of performing operations according to embodiments of the invention, when properly configured. Thus, for example, when the embodiment of the processor 110 is ASIC, FPGA or the like, the processor 110 may include specially configured equipment for carrying out one or more
-10 numbers of operations described here. Alternatively, as another example, when the processor 110 is implemented as an instruction executing module, such as those that can be stored in memory 112, the instructions may specifically configure the processor 110 to perform one or more of the algorithms and operations described herein.
[0025] Memory 112 may include, for example, persistent and / or unstable memory. Although in FIG. 1 is a single memory, the memory 112 may contain multiple memories. The memory 112 may contain a non-volatile memory, a non-volatile memory or a combination thereof. In this regard, memory 112 may include, for example, a hard disk, random access memory, cache, flash memory, read-only compact disk (CD-ROM), digital read-only memory (DVD-ROM), optical disk, circuits configured to store information or a reliable connection. In embodiments where the receiving device 102 is made as a mobile terminal 10, the memory 112 may include a non-volatile memory 40 and / or a non-volatile memory 42. Memory 112 may be configured to store information, data, applications, instructions or the like to allow the receiving device 102 to perform various functions according to embodiments of the present invention. For example, in at least some embodiments, the memory 112 is configured to buffer input for processing by the processor 110. Additionally or alternatively in at least some embodiments, memory 112 is configured to store program instructions to be executed by processor 110. Memory 112 may store information in the form of static and / or dynamic information. This stored information may be stored and / or used by the decryption control circuits 118 during the course of performing its function.
[0026] The communication interface 114 may be implemented as any device or means contained in circuits, hardware, a computer program containing computer-readable program instructions stored on a computer-readable medium (e.g., memory 112) and executed by a processing device (e.g. processor 110) or a combination thereof that is configured to receive and / or transmit data from / to a system unit 100, such as, for example, the transmitting device 104. In at least one embodiment, the communication interface 114 is at least partially implemented as the processor 110 or is otherwise controlled by it. In this regard, the communication interface 114 may be in communication with the processor 110, e.g. via a bus. The communication interface 114 may include, for example, an antenna, transmitter, receiver, transceiver and / or assistive hardware or software to enable communication with one or more system 100 units. The communication interface 114 may be configured to receive and / or transmit data using any protocol that can be used for communication between system 100 units. The communication interface 114 may additionally be in communication with the memory 112 and / or the decryption control circuits 118, e.g. via a bus.
[0027] The decryption control circuits 118 can be made as various means, such as circuits, computer hardware, a computer program product containing computer-readable program instructions stored on a computer-readable medium (e.g., memory 112) and executed by a processing device ( e.g. processor 110) or some combination thereof, and in one embodiment they are made as - or otherwise controlled by processor 110. In embodiments where the circuits
Control decryption 118 is separate from processor 110, decryption control circuits 118 may be in communication with processor 110. Decryption control circuits 118 may include and / or be configured to perform at least some functionality of the radio link control unit (RLC), protocol unit data packet convergence (PDCP) and / or the like. The decryption control circuits 118 may further be in communication with one or more memories 112 or communication interface 114, e.g. via a bus.
[0028] Referring now to the transmitting device 104, in the exemplary embodiment, the transmitting device 104 includes various means such as processor 120, memory 122, communication interface 124 and encryption control circuits 126 for performing the various functions described herein. These means of the transmitting device 104 as described herein may be exemplary as e.g. circuits, hardware components (e.g. properly programmed processor, combinational logic and / or the like), a computer program product containing computer-readable program instructions (e.g. software or firmware) stored on a computer-readable medium (e.g. memory 122) that is executed by properly configured processing device (e.g. processor 120) or any combination thereof.
[0029] Processor 120 may, for example, be implemented as various means including one or more microprocessors with associated digital signal processor (s), one or more processors without associated digital signal processor (s) , one or more coprocessors, one or more multi-core processors, one or more controllers, processing circuits, one or more computers, various other processing elements including integrated circuits, such as, for example, ASIC (application-specific integrated circuit) or FPGA (programmable logic gate matrix), or a combination thereof. Although in FIG. 1 is a single processor, in some embodiments, the processor 120 includes multiple processors. A plurality of processors may be in working communication with each other and may be collectively configured to perform one or more functions of the transmitting device 104, as described herein. Multiple processors may be made in a single computer device or disposed in multiple computer devices collectively configured to perform one or more functions of the transmitting device 104, as described herein. In embodiments where the transmitting device 104 is made as a mobile terminal 10, the processor 120 may be made as a processor 20 or may include it. In one embodiment, the processor 120 is configured to execute instructions stored in memory 122 or otherwise available to processor 120. This instruction, executed by the processor 120, may cause the sending device 104 to perform one or more functions of the sending device 104, as described herein. The processor 120, configured by means of hardware or software methods, or by means of a combination thereof, may include a unit capable of performing operations according to embodiments of the invention when properly configured. Thus, for example, when the embodiment of the processor 120 is ASIC, FPGA or the like, the processor 120 may include specially configured equipment for performing one or more of the operations described herein. Alternatively, as another example, when the processor 120 is implemented as a module that executes instructions, such as those that can be stored in memory 122,
- the instructions may specifically configure the processor 120 to perform one or more of the algorithms and operations described herein.
[0030] Memory 122 may include, for example, persistent and / or unstable memory. Although in FIG. 1 illustrates a single memory, then memory 122 may include multiple memories. Numerous memories can be made in a single computer device or arranged in many computer devices. Memory 122 may contain a non-volatile memory, a permanent memory, or some combination thereof. In this regard, memory 122 may include, for example, a hard disk, random access memory, cache, flash memory, read-only compact disk (CD-ROM), digital read-only memory (DVD-ROM), optical disk, circuits configured to store information or a reliable connection. In embodiments where the transmitting device 104 is made as a mobile terminal 10, the memory 122 may include a non-volatile memory 40 and / or a non-volatile memory 42. Memory 122 may be configured to store information, data, applications, instructions or the like to allow the receiving device 104 to perform various functions according to embodiments of the present invention. For example, in at least some embodiments, memory 122 is configured to buffer input for processing by processor 120. Additionally or alternatively in at least some embodiments, memory 122 is configured to store program instructions to be executed by processor 120. Memory 122 may store information in the form of static and / or dynamic information. This stored information may be stored and / or used by the encryption control circuits 126 during the course of performing their function.
[0031] The communication interface 124 may be implemented as any device or means contained in circuits, hardware, a computer program containing computer-readable program instructions stored on a computer-readable medium (e.g. memory 122) and executed by a processing device (e.g. processor 120) or a combination thereof that is configured to receive and / or transmit data from / to a system unit 100, such as, for example, a transmitting device 102. In at least one embodiment, the communication interface 124 is at least partially implemented as a processor 120 or is otherwise controlled by it. In this regard, the communication interface 124 may be in communication with the processor 120, e.g., via a bus. The communication interface 124 may include, for example, an antenna, transmitter, receiver, transceiver and / or assistive hardware or software for enabling communication with one or more system 100 units. The communication interface 124 may be configured to receive and / or transmit data using any protocol that can be used for communication between system 100 units. The communication interface 124 may additionally be in communication with the memory 122 and / or the encryption control circuits 126, e.g. via a bus.
[0032] The encryption control circuits 126 may be made as various means, such as circuits, computer hardware, a computer program product comprising computer read program instructions stored on a computer readable medium (e.g., memory 122) and executed by a processing device ( e.g. processor 120) or some combination thereof, and in one embodiment they are made as - or otherwise controlled by processor 120. In embodiments where the circuits
Encryption controls 126 are included separately from the processor 120, the encryption control circuits 126 may communicate with the processor 120. The encryption control circuits 126 may include and / or be configured to perform at least some functionality of the RLC entity, PDCP entity and / or the like. The encryption-controlled circuits 126 may further communicate with one or more memories 122 or the communication interface 124, e.g. via a bus.
[0033] It should be understood that in some embodiments, the receiving device 102 is configured to perform at least some of the functions of the transmitting device 104 described herein. In this regard, the receiving device 102 may include encryption control circuits 126, which may be made in the form of a processor 110 or be controlled by him. Similarly, in some embodiments, the transmitting device 104 is configured to perform at least some of the functions of the receiving device 102 described herein. In this regard, the transmitting device 104 may include decryption control circuits 118 that can be made as a processor 120 or otherwise controlled by this processor. Embodiments of the invention may facilitate detection and correction of encryption errors on both the sending and the receiving links of networks.
[0034] The encryption control circuits 126 are configured in some embodiments to encrypt data in the protocol data unit (PDU) to be sent to the receiving device 102. The PDU may include RLC PDU, PDCP PDU or the like. The PDU may include PDU in unacknowledged mode (UM) - in this case it is not required that the receiving device 102 acknowledge receipt of the UM PDU. The PDU may include PDU in confirmed mode (AM) - in this case confirmation of the PDU receipt by the receiving device 102 is required. The PDU may be associated with any of various types of communication services transmitted between the receiving device 102 and the transmitting device 104 or other device via the network 108. The type of service includes an upper layer communication application that is served by a unit or PDUs sent to the receiving device 102. For example, the type of service may include voice switched circuit (CS) communication transmitted via the HSPA (High Speed Packet Access) protocol. In another example, the type of service may include VoIP (Voice over Internet Protocol), a streaming service, or other real-time service. The encryption control circuits 126 may be configured to encrypt data using a set of one or more encryption input parameters. A set of one or more encryption input parameters may include, for example, one or more encryption keys (CK), COUNT-C, BEARER (e.g. radio channel identification), LENGTH (e.g. data length), DATA (e.g. data parameter for encryption) or the like. The C-COUNT value may contain and / or be defined at least in part based on the Hyper Frame Number (HFN) value and the sequence number (e.g., RLC sequence number (RLC SN)). The HFN may include an initialized field to an initial value exchanged between the sending device 104 and the receiving device 102 when setting the base channel. The RLC SN may contain the sequence number contained in the PDU header and may be incremented by 1 for each PDU transmission. The encryption control circuits 126 can use a set of encryption input parameters to encrypt data using any codec,
Such as, for example, the Adaptive Multi-Rate (AMR), AMR-Wideband (AMR-WM) codec and / or the like.
[0035] The encryption control circuits 126 can be preconfigured to include an encrypted "expected value" in the PDU to be sent to the receiving device 102. The expected value may include a padding field value, a length indicator, a PDU header, a field currently defined as an R field (e.g. in PDU according to PDCP) and / or another value. For example, the padding field may contain one or more bits having the expected value by the receiving device 102, which are contained in the PDU to ensure data octet alignment in the PDU. In another example, the length indicator may indicate the last octet of each RLC service data unit contained in the PDU (e.g., '1111101' for CS voice transmission over HSPA). Thus, the expected value may indicate the PDU size or other expected value by the receiving device 102. In yet another example, the PDU header may include a value indicating the PDCP type to which the PDCP PDU binds (e.g., '010' - AMR PDCP PDU data for CS voice communication via HSPA, '000' PDU PDU PDU data for VoIP and / or the like).
[0036] In some embodiments, the "expected value" is predefined based on the configuration of the system 100. Additionally or alternatively, the encryption control circuits 126 and the decryption control circuits 118 may be configured to independently determine the expected value at least in part based on the type a communication service for which data is exchanged between the receiving device 102 and the transmitting device 104 (e.g., the expected value of the PDU header). In another example, the encryption control circuits 126 may be configured to define the expected value and provide the expected value to the receiving device 102 during the communication configuration phase (e.g., when setting the radio channel, during RLC resynchronization and / or the like).
[0037] After encrypting the PDU containing the expected value by the receiving device 102, the communication interface 124 can transmit the PDU to the receiving device 102, where it can be received by the communication interface 114. The decryption control circuits 118 are configured in some embodiments of the invention to use a set of one or more encryption input parameters maintained by the decryption control circuits 118 to decrypt the encrypted data in the received PDU. A set of one or more encryption input parameters may include, for example, one or more encryption keys (CK), COUNT-C, BEARER (e.g. radio channel identification), LENGTH (e.g. data length), DATA (e.g. data parameter to be decrypted) or the like. The decryption control circuits 118 may be configured to use a set of encryption input parameters to decrypt data using any codec used by the encryption control circuits 126 to generate data.
[0038] After data decryption by the decryption control circuits 118, the decryption control circuits 118 are configured in some embodiments of the invention to compare the value of at least a portion of the decrypted data with the expected value. As described above, the expected value expected by the decryption control circuits 118 can be pre-configured, selected by the control circuits
Encryption 126 and determined by decryption control circuits 118 based at least partly on network signaling received by terminal 102, determined by decryption control circuits 118 at least partly based on the type of service to which the received PDU and / or the like is associated. At least a portion of the decrypted data may comprise a portion (e.g., header, field and / or the like) of the PDU in which the expected value is located. When the value of at least a portion of the data from the encryption is not equal to the expected value, the decryption control circuits 118 are configured in some embodiments to determine the occurrence of an encryption error. Therefore, if the set of encryption input parameters used by the decryption control circuits 118 to decrypt data is synchronized with the set of encryption input parameters used by the encryption control circuits 126 to encrypt data, at least a portion of the decrypted data should be equal to the expected value.
[0039] The decryption control circuits 118 are configured in some embodiments to initiate an encryption resynchronization procedure in response to determining that an encryption error has occurred such that to resynchronize at least one set of encryption input parameters used by the decryption control circuits 118 to decrypt encrypted data in the received PDU ("first set of encryption input parameters") with at least one set of encryption input parameters used by the encryption control circuits 126 to encrypt data in PDU sent to receiving device 102 ("second set of encryption input parameters"). Therefore, the re-synchronization of at least one of the first set of encryption input parameters with at least one of the second set of encryption input parameters may include, for example, decryption control circuit 118 autonomously updating one or more of the encryption input parameters of the first set, control circuit decrypting 118, updating one or more of the encryption input parameters from the first set based on the signaling exchanged with the transmitting device 104, the decryption control circuit 118 and the encryption control circuit 126 of the same transmitting device 104 setting one or more synchronized encryption input parameters for the first and second set at the configuration stage ( for example. radio channel configuration and / or security mode command procedure) and / or decryption control circuit 118 and encryption control circuit 126 of another transmitting device 104 setting one or more synchronized encryption inputs for the first and second set in the configuration phase (e.g. radio channel configuration and / or security mode command procedure).
[0040] In some embodiments, the decryption control circuits 118 are configured to initiate the encryption resynchronization procedure by initiating the RLC resynchronization procedure (e.g. RLC re-establishment procedures in UM or AM mode, RLC reset procedures in AM mode and / or the like) to initiate at least one encryption input parameter so that the first set of encryption input parameters are re-synchronized with the second set of encryption input parameters. In this regard, the receiving device 102 and the transmitting device 104 may participate in the cell update procedure, and the decryption control circuits 118 and the encryption control circuits 126 may initiate RLC re-establishment or other RLC re-synchronization procedure as part of the procedure
Updating the cells so that the decryption control circuits 118 and the encryption control circuits 126 can initialize at least one synchronized encryption input parameter (e.g., COUNT-C value, UM RLC SN and / or the like).
[0041] additionally or alternatively, in some embodiments, the decryption control circuits 118 are configured to initiate an autonomous encryption resynchronization procedure. In this regard, the decryption control circuits 118 may be configured to select the most likely alternative value for at least one of the first set of encryption input parameters. For example, the most likely alternative value may include an increased value of the cipher input parameter when the cipher input parameter contains a parameter that is incremented with each received PDU. For example, the decryption control circuits may be configured to increase the HFN value of the COUNT-C counter to the current HFN value of the COUNT-C + 1 counter as the most likely alternative value. The decryption control circuits 118 may then use the selected most likely alternative value for at least one of the first encryption input parameters to decrypt the data in the received PDU for which an encryption error occurred or to decrypt the data in the subsequently received PDU. If the selected at least one most likely alternative value of the input encryption parameter (s) is the correct synchronized value (s), then at least some of the decrypted data will be equal to the expected value. If at least some of the decrypted data is not equal to the expected value, then the first and second set of cipher input parameters are still not synchronized and the decryption control circuits 118 may be configured to reselect the most likely alternative value for one or more of the cipher input parameters and attempt to decrypt again the received PDU. The decryption control circuits 118 can be configured to repeat the selection process of the most likely alternative to one or more encryption input parameters until the decryption control circuits 118 re-synchronize again and autonomously at least one parameter from the first set of encryption input parameters with at least one parameter from the other set of encryption input parameters. Additionally or alternatively, the decryption control circuits 118 may be configured to repeat the process of selecting the most likely alternative to one or more encryption input parameters until the decryption control circuits 118 perform a predetermined number of failed attempts to select the most likely alternative to one or more encryption input values, at which point the decryption control circuits 118 may be configured to initiate resynchronization of the RLC as described above to initiate at least one encryption input parameter with the transmitting device 104. A predetermined number of unsuccessful attempts of autonomous resynchronization may for example be signaled to receiving device 102 via network signaling (e.g. from the sending device 104) or decryption control circuits 118 may be pre-configured to perform a predetermined number of failed attempts before RLC resynchronization begins.
[0042] In some embodiments, the decryption control circuits 118 are not configured to initiate the resynchronization encryption procedure in response to each determination that an encryption error has occurred, but rather are configured to initiate the resynchronization encryption procedure after a predetermined number of consecutive encryption errors have occurred. (e.g. for a predetermined number of consecutive PDUs received). A pre-defined number may include a natural number greater than zero. The decryption control circuits 118 can be pre-configured to a predefined number. In another example, the decryption control circuits 118 may be configured to determine a predefined number based at least in part on the type of service with which the PDUs are associated (e.g. the predetermined number may be 3 for CS voice communication transmitted by HSPA and 10 for the stream transmission service). Additionally or alternatively, the decryption control circuits 118 may be configured to determine a predetermined number based at least in part on a received network signaling message forwarded by the sending device 104. Therefore, the encryption control circuits 126 may be configured to determine a predetermined number of consecutive encryption errors which the decryption control circuits 118 are to detect before starting the encryption resynchronization procedure. The encryption control circuits 126 may then generate a network signaling message to be sent to the receiving device 102 via a communication interface 124 that specifies a predetermined number. In embodiments where the decryption control circuits 118 are configured to initiate the encryption resynchronization procedure after a predetermined number of consecutive encryption errors, the decryption control circuits 118 may be configured to change the counter value at least partly based on the number of consecutive encryption errors. which occurred after determining the occurrence of an encryption error and initiating the procedure of resynchronization of encryption based at least partly on the previously defined relationship between the value of the counter and the previously set number. For example, the decryption control circuits 118 may be configured to increase or decrease the value of the counter when the decryption control circuits 118 determine the occurrence of an encryption error and initiate an encryption resynchronization procedure when the value of the counter is equal to threshold values, such as a predetermined number (e.g. if it increases from the initial counter value of zero) or zero (e.g. if it is reduced from the initial value of the counter equal to the previously specified number). However, it should be understood that increasing and decreasing the value of the counter are provided solely by way of examples of how the decryption control circuits 118 are configured to adjust the value of the counter in some embodiments of the invention. In addition, exemplary initial values and thresholds are provided only as examples, and the decryption control circuits 118 may be configured to use different initial values and thresholds.
[0043] In some embodiments, the decryption control circuits 118 are configured to allow detection of encryption errors and checking for the presence of an encryption error only when one or more conditions are met. For example, the decryption control circuits 118 may be configured to allow detection of encryption errors only when configured for this by the sending device 104, e.g., by network signaling passed to the device
Receiving 102 by the transmitting device 104. In this regard, the encryption control circuits 126 may be configured to enable and / or disable the encryption error detection by the decryption control circuits 118 by initiating network signaling on and / or off the encryption error detection for sending to the receiving device. 102 through the transmitting device 104. Network signaling may additionally include an indication of a predetermined number of consecutive encryption errors that the decryption control circuits 118 must detect before starting the encryption resynchronization procedure. Additionally or alternatively, the decryption control circuits 118 may be configured to allow detection of encryption errors based at least in part on the type of service to which the received PDU is associated.
[0044] Fig. 3 illustrates a flow diagram according to an exemplary method of detecting and correcting errors according to an embodiment of the invention. In this regard, FIG. 3 illustrates operations that can be performed by decryption control circuits 118. The method may include initiating by the decryption control circuits 118 the value of at least one encryption input parameter from the first set of one or more encryption input parameters in the transmitting device 104 during operation 300. Operation 310 may include using the decryption control circuits 118 of the first set of encryption input parameters to encrypting data contained in the received PDU. The decryption control circuits 118 may then during the operation 320 compare the value of at least a portion of the decrypted data with the value expected during. Operation 330 may include determining by the decryption control circuits 118 the occurrence of an encryption error when the value of at least a portion of the decrypted data is not equal to the expected value. The decryption control circuits 118 may then initiate the resync encryption procedure in response to this determination during operation 340.
[0045] Fig. 4 illustrates a flow diagram according to an exemplary method of detecting and correcting errors according to an embodiment of the invention. In this regard, FIG. 4 illustrates operations that can be performed by decryption control circuits 118. The method may include initiating by the decryption control circuits 118 values of at least one encryption input parameter from the first set of one or more encryption input parameters by the transmitting device 104 during operation 400. Operation 410 may include determining by the decryption control circuits 118 a predetermined number of consecutive encryption errors that must occur before the start of the resync encryption procedure during operation 410. The decryption control circuits 118 may determine the implementation of operation 410 at least partly based on network signaling transmitted by the device sender 104 and / or type of service with which the received PDU is associated. Operation 420 may include determining by the decryption control circuits 118 the occurrence of a predetermined number of consecutive encryption errors when decrypting the sequentially received PDUs. The decryption control circuits 118 may then initiate the resync encryption procedure in response to the determining operation 420 during operation 430.
[0046] Fig. 5 illustrates a flow diagram according to an exemplary method of detecting and correcting errors according to an embodiment of the invention. In this regard, FIG. 5 illustrates operations that may be performed by the encryption control unit 126. Operation 500 may include the initiation by the encryption control circuits 126 of at least
One encryption input parameter from the second set of one or more encryption input parameters for use in the encryption data in the receiving device 102. The encryption control circuits 126 may then use the second set of encryption input parameters for the encryption data in the PDU to be sent to the receiving device 102 during the operation 510. Operation 520 may optionally include the encryption control circuits performing the resync encryption procedure with the receiving device 102 when the receiving device detects an encryption error. Operation 520 can be performed in embodiments in which the decryption control circuits 118 are configured to initiate RLC resynchronization.
[0047] Fig. 6 illustrates a flow diagram according to an exemplary method of detecting and correcting errors according to an embodiment of the invention. In this regard, FIG. 6 illustrates operations that can be performed by the encryption control unit 126. Operation 600 may include the encryption control circuits 126 initiating values of at least one encryption input parameter from the second set of one or more encryption input parameters for use in the encryption data at the receiving device 102. The encryption control circuits 126 may then cause transmission of a network signaling message configuring the detection encryption errors to the receiving device 102. The network signaling message may include instructions for detecting encryption errors by the receiving device 102, instructions specifying a predetermined number of consecutive encryption errors to be determined by the receiving device 102, occurring before the initiation of the resynchronization encryption procedure and / or a predetermined number of unsuccessful attempts of autonomous resynchronization by the receiving apparatus 102 to perform before initiating the RLC resynchronization procedure. The encryption control circuits 126 may then use the second set of encryption input parameters for the encryption data in the PDU to be sent to the receiving device 102 during operation 620. Operation 630 may optionally include the participation of the encryption control circuits in the resync encryption procedure with the receiving device 102 when the receiving device detects an encryption error (e.g., a predetermined number of consecutive encryption errors). Operation 630 can be performed in embodiments in which the decryption control circuits 118 are configured to initiate RLC resynchronization.
[0048] In FIG. 3-6 are process diagrams showing the system, method and product in the form of a computer program according to embodiments of the invention. It should be understood that each block or stage of flowcharts and block connections in flowcharts can be implemented by various means, such as devices and / or a computer program product, containing one or more computer readable media with program instructions stored thereon for computer reading. For example, one or more of the procedures described herein can be performed using the product instructions in the form of a computer program. In this regard, the computer program product (s) which includes the procedures described herein may be stored by one or more memory devices of the receiving device 102, transmitting device 104, cellular terminal, server or other computer device and executed by the processor in the device computer (e.g. processor 110 and / or processor 120). In some embodiments, computer program instructions
Constituting the computer program product (s), being an embodiment of the procedures described above, may be stored by memory devices in many computer devices. It should be appreciated that any such product in the form of a computer program can be loaded into a computer or other programmable device to create a device in such a way that the product in the form of a computer program including instructions that are executed on a computer or other programmable device creates a means to perform the function specified in the technological block (s) or stage (s). In addition, the computer program product may include one or more computer readable memories on which the computer program instructions may be stored such that one or more computer readable memories may direct the computer or other programmable device to operate in a particular manner in in such a way that the product in the form of a computer program is the product being manufactured, which performs the function specified in the block (s) or stage (s) of the technological scheme. Computer program instructions of one or more computer program products may also be loaded into a computer or other programmable device to cause a series of operational steps to be performed on a computer or other programmable device to produce a computer-implemented process in such a way that the instructions, which operate on a computer or other programmable device provide stages of the implementation of the functions specified in the block (s) or stage (s) of the technological scheme.
[0049] Accordingly, the blocks or steps of the flowchart support the implementation of a combination of means for performing specific functions and a combination of steps for performing specific functions. It is also understood that one or more blocks or stages of the flowchart and the combination of blocks or stages of the flowchart can be implemented using special hardware-based computer systems that perform specific functions or stages, or a combination of specialized equipment and product (s) in the form of computer program.
[0050] The functions described above can be performed in a variety of ways. For example, any suitable means for carrying out each of the functions described above can be used to implement the embodiments of the invention. In one embodiment, a suitably configured processor may form all or part of the elements of the invention. In another embodiment, all or part of the elements of the invention may be configured and run under the control of the product in the form of a computer program. The computer program product for carrying out the methods of embodiments of the invention includes a computer readable storage medium, such as non-volatile storage medium and computer readable program code parts, such as a series of computer instructions contained in a computer readable storage medium.
[0051] Thus, as such, some embodiments of the invention provide several advantages to computer devices, computer device users, and network operators. Embodiments of the invention show a receiving device configured to determine the occurrence of an encryption error. In this regard, embodiments of the invention show a receiving device configured to determine the occurrence of an encryption error by comparing the values of the decrypted data with the expected value to determine whether
-21 the value of decrypted data is equal to the expected value. This comparison allows some embodiments of the invention to determine the occurrence of an encryption error regardless of the type of service to which the encrypted protocol data unit is associated. Embodiments of the invention provide a receiving device 102 configured to determine the occurrence of an encryption error in situations where a cyclic redundancy code (CRC) for CRC protected data may show an error.
[0052] Embodiments of the invention further show a receiving device configured to initiate an encryption error correction procedure such that to resynchronize the local set of one or more cipher input parameters used to decrypt received encrypted data using the set of one or more encryption input parameters used by the sending device to decrypt encrypted data before sending to the terminal. Some embodiments of the invention show a receiving device configured to initiate resynchronization of the radio link control with the sending device for resynchronizing one or more encryption input parameters. Embodiments of the invention also show a receiving device configured to autonomously resynchronize one or more cipher input parameters by selecting the most likely alternative value for at least one encryption input parameter. Embodiments of the invention providing a network signaling configuration of encryption error detection procedures and / or correction of encryption errors eliminate interoperability problems that may occur when a receiving device configured to determine the occurrence of an encryption error and / or initiate an encryption error correction procedure communicates over a non-configured network to support the procedure correction of encryption errors.
[0053] Many modifications and other embodiments of the inventions set forth herein will be understood by those skilled in the art to which the inventions relate, who use the information set forth in the above descriptions and the accompanying drawings. Therefore, it should be understood that the embodiments of the invention are not limited to the specific embodiments disclosed and that the modifications and other embodiments are intended to be within the scope of the appended claims. In addition, although the above descriptions and related drawings describe embodiments in the context of certain example combinations of elements and / or functions, it should be understood that various combinations of elements and / or functions may be implemented by alternative embodiments without departing from the scope of the appended claims. In this regard, for example, other combinations of elements and / or functions than those clearly described above are also contemplated, which may also be set out in some of the appended claims. Although certain terms are used herein, they are used only in a general and descriptive sense and not for the purpose of limitation.
13 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13
33 members in 20 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 49495709 | United States of America | A | |
| 49495709 | United States of America | A | |
| 10793665 | European Patent Office (EPO) | A | |
| 2010050509 | Finland | W | |
| 2010050509 | Finland | W | |
| 107936650 | – | – | – |
| 494957 | – | – | – |
| EP20100793665 | – | – | – |
| US20090494957 | – | – | – |
| WO2010FI50509 | – | – | – |
Members33
| Document | Office | Kind | |
|---|---|---|---|
| US2010332933A1 | United States of America | A1 | |
| CA2766198A1 | Canada | A1 | |
| WO2011001022A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW201129127A | Taiwan Province of China | A | |
| AR077291A1 | Argentina | A1 | |
| MX2011013938A | Mexico | A | |
| SG177392A1 | Singapore | A1 | |
| CL2011003230A1 | Chile | A1 | |
| KR20120042875A | Republic of Korea | A | |
| EP2449748A1 | European Patent Office (EPO) | A1 | |
| CN102804729A | China | A | |
| JP2012531778A | Japan | A | |
| UA100829C2 | Ukraine | C2 | |
| ZA201200651B | South Africa | B | |
| RU2012101495A | Russian Federation | A | |
| JP5347067B2 | Japan | B2 | |
| RU2501173C2 | Russian Federation | C2 | |
| KR101464416B1 | Republic of Korea | B1 | |
| CA2766198C | Canada | C | |
| CN102804729B | China | B | |
| US9124425B2 | United States of America | B2 | |
| TWI510107B | Taiwan Province of China | B | |
| US2015372815A1 | United States of America | A1 | |
| BRPI1014586A2 | Brazil | A2 | |
| AP3720A | African Regional Intellectual Property Organization (ARIPO) | A | |
| MY158762A | Malaysia | A | |
| US9608815B2 | United States of America | B2 | |
| EP2449748A4 | European Patent Office (EPO) | A4 | |
| EP2449748B1 | European Patent Office (EPO) | B1 | |
| DK2449748T3 | Denmark | T3 | |
| PL2449748T3This record | Poland | T3 | |
| BRPI1014586B1 | Brazil | B1 | |
| BRPI1014586B8 | Brazil | B8 |
Numbers
- Publication
- 2449748
- Publication, DOCDB
- 2449748
- Publication, EPODOC
- PL2449748T
- Application
- 10793665
- Application, DOCDB
- 10793665
- Application, EPODOC
- PL20100793665T
Titles2
- English
- SYSTEMS, METHODS, AND APPARATUSES FOR CIPHERING ERROR DETECTION AND RECOVERY
- Polish
- SYSTEMY, SPOSOBY I URZĄDZENIA DO WYKRYWANIA I KOREKTY BŁĘDÓW SZYFROWANIA
Classification
- CPC, 7
- H04L9/12
- H04L2209/80
- H04W12/04
- H04W12/037
- H04L7/00
- H04L9/40
- H04W12/02
- IPC, 4
- H04L67 01
- H04L9 12
- H04W12 02
- H04W12 04
