Method, Network Element, User Equipment and System for Securing Device-to-Device Communication in a Wireless Network
Claim Score by NHIP
Abstract
Method, network element, user equipment (UE) and system are disclosed for securing device-to-device (D2D) communication in a wireless network. The wireless network has a first UE in an idle mode, a second UE in a connected mode, and a network element. The method comprises: encrypting the second UE's identification (ID) by using a first key which is known to the network element and the first UE and which is unknown to the second UE; sending the encrypted second UE's ID from the network element to the first UE via the second UE; and verifying the second UE's ID by using the encrypted second UE's ID. According to some embodiments, the method further comprises: deriving a D2D key for D2D communication between the first and second UEs, based on a random number and a second key which is known to the network element and the first UE; encrypting the D2D key based at least in part on a third key which is shared between the network element and the second UE and which is unknown to any other UE in the wireless network; and sending the encrypted D2D key from the network element to the second UE.

Term
8 yearsto projected expiry
Projected expiry 3 October 2034, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
20 claims: 3 independent, 17 dependent
- 49Broadest claimClaim Score 68, broad(NHIP)A method for securing device-to-device (D2D) communication in a wireless network having a first user equipment (UE) in an idle mode, a second UE in a connected mode, and a network element, the method comprising:encrypting the second UE's identification (ID) by using a first key which is known to the network element and the first UE and which is unknown to the second UE;andsending the encrypted second UE's ID from the network element to the first UE via the second UE to enable the first UE to verify the second UE's ID by using the encrypted second UE's ID.
- 60A user equipment (UE) suitable to work in an idle mode in a wireless network having a second UE in a connected mode and a network element, the UE comprising:at least one processor;andat least one memory including computer-executable instructions,wherein the at least one memory and the computer-executable instructions are configured to, with the at least one processor, cause the UE to:receive an encrypted second UE's identification (ID) from the second UE, wherein the second UE's ID is encrypted by the network element by using a first key which is known to the network element and the UE and which is unknown to the second UE;andverify the second UE's ID by using the encrypted second UE's ID.
- 64A user equipment (UE) suitable to work in a connected mode in a wireless network having a second UE in an idle mode and a network element, the UE comprising:at least one processor;andat least one memory including computer-executable instructions,wherein the at least one memory and the computer-executable instructions are configured to, with the at least one processor, cause the UE to:receive an encrypted UE's identification (ID) from the network element, wherein the UE's ID is encrypted by using a first key which is known to the network element and the second UE and which is unknown to the UE;andtransmit the encrypted UE's ID to the second UE to enable the second UE to verify the UE's ID by using the encrypted UE's ID.
Independent claims3
76 paragraphs in 5 sections, as filed
FIELD OF THE INVENTION
Embodiments of the disclosure generally relate to wireless communications, and, more particularly, to securing device-to-device (D2D) communication in a wireless network.
BACKGROUND
With the development of the future service, next generation wireless communication systems, such as 3GPP (third Generation Partnership Project) LTE (long term evolution) and beyond system, IMT-A (International Mobile Telecommunications—Advanced) system etc., are introduced to satisfy high speed, large capacity, and a high QoS (Quality of Service) for billions of subscribers. In this regard, efforts have been made to realize network-controlled D2D communications for reducing the load on the cellular communication network. Examples of such D2D communications include direct communications among a cluster of proximity devices, and autonomous D2D communications in a cellular network. In such network-controlled D2D communications, devices such as user equipments (UEs) or mobile terminals directly communicate with each other, instead of conveying data from one device to the other via the cellular network (in particular via an access node or base station thereof), where primary control and configurations, such as channel/bearer configurations, are carried out by the cellular network. Security protection may be an issue for the network-controlled D2D communications, for example, because malicious users may be able to eavesdrop on the D2D communication if no strong security protection between peer UEs conducting a direct D2D communication is used. However, currently the security related procedures have not been fully specified for network-controlled D2D communications, especially for a scenario that one of the peer UEs in the D2D communication stays in an idle mode.
In view of this, it would be advantageous to provide a way to allow for efficiently securing D2D communications, especially when one of the D2D UEs is in an idle mode.
SUMMARY
This summary is provided to introduce a selection of concepts in a simplified form that are further described below in the detailed description. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
According to one aspect of the disclosure, it is provided a method for securing device-to-device (D2D) communication in a wireless network having a first user equipment (UE) in an idle mode, a second UE in a connected mode, and a network element, the method comprising: encrypting the second UE's identification (ID) by using a first key which is known to the network element and the first UE and which is unknown to the second UE; and sending the encrypted second UE's ID from the network element to the first UE via the second UE to enable the first UE to verify the second UE's ID by using the encrypted second UE's ID.
According to another aspect of the disclosure, it is provided a user equipment (UE) suitable to work in an idle mode in a wireless network having a second UE in a connected mode and a network element, the UE comprising: receiving means configured to receive an encrypted second UE's identification (ID) from the second UE, wherein the second UE's ID is encrypted by the network element by using a first key which is known to the network element and the UE and which is unknown to the second UE; and verifying means configured to verify the second UE's ID by using the encrypted second UE's ID.
According to another aspect of the disclosure, it is provided a user equipment (UE) suitable to work in an idle mode in a wireless network having a second UE in a connected mode and a network element, the UE comprising: at least one processor; and at least one memory including computer-executable instructions, wherein the at least one memory and the computer-executable instructions are configured to, with the at least one processor, cause the UE to: receive an encrypted second UE's identification (ID) from the second UE, wherein the second UE's ID is encrypted by the network element by using a first key which is known to the network element and the UE and which is unknown to the second UE; and verify the second UE's ID by using the encrypted second UE's ID.
According to another aspect of the disclosure, it is provided a user equipment (UE) suitable to work in a connected mode in a wireless network having a second UE in an idle mode and a network element, the UE comprising: receiving means configured to receive an encrypted UE's ID from the network element, wherein the UE's ID is encrypted by using a first key which is known to the network element and the second UE and which is unknown to the UE; and transmitting means configured to transmit the encrypted UE's ID to the second UE to enable the second UE to verify the UE's ID by using the encrypted UE's ID.
According to another aspect of the disclosure, it is provided a user equipment (UE) suitable to work in a connected mode in a wireless network having a second UE in an idle mode and a network element, the UE comprising: at least one processor; and at least one memory including computer-executable instructions, wherein the at least one memory and the computer-executable instructions are configured to, with the at least one processor, cause the UE to: receive an encrypted UE's ID from the network element, wherein the UE's ID is encrypted by using a first key which is known to the network element and the second UE and which is unknown to the UE; and transmit the encrypted UE's ID to the second UE to enable the second UE to verify the UE's ID by using the encrypted UE's ID.
According to another aspect of the disclosure, it is provided a network element suitable to work in a wireless network having a first user equipment (UE) in an idle mode and a second UE in a connected mode, the network element comprising: encrypting means configured to encrypt the second UE's identification (ID) by using a first key which is known to the network element and the first UE and which is unknown to the second UE; and transmitting means configured to transmit the encrypted second UE's ID to the second UE to enable the first UE to verify the second UE's ID by using the encrypted second UE's ID.
According to another aspect of the disclosure, it is provided a network element suitable to work in a wireless network having a first user equipment (UE) in an idle mode and a second UE in a connected mode, the network element comprising: at least one processor; and at least one memory including computer-executable instructions, wherein the at least one memory and the computer-executable instructions are configured to, with the at least one processor, cause the network element to: encrypt the second UE's identification (ID) by using a first key which is known to the network element and the first UE and which is unknown to the second UE; and transmit the encrypted second UE's ID to the second UE to enable the first UE to verify the second UE's ID by using the encrypted second UE's ID.
According to another aspect of the disclosure, it is provided a system for securing device-to-device (D2D) communication in a wireless network, comprising: an above-described network element, at least one above-described user equipment (UE) in an idle mode, and at least one above-described UE in a connected mode.
According to another aspect of the disclosure, it is provided a computer program product comprising at least one non-transitory computer-readable storage medium having computer-executable program instructions stored therein, the computer-executable instructions being configured to, when being executed, cause a user equipment to operate in an idle mode as described above.
According to another aspect of the disclosure, it is provided a computer program product comprising at least one non-transitory computer-readable storage medium having computer-executable program instructions stored therein, the computer-executable instructions being configured to, when being executed, cause a user equipment to operate in a connected mode as described above.
According to another aspect of the disclosure, it is provided a computer program product comprising at least one non-transitory computer-readable storage medium having computer-executable program instructions stored therein, the computer-executable instructions being configured to, when being executed, cause a network element to operate as described above.
These and other objects, features and advantages of the disclosure will become apparent from the following detailed description of illustrative embodiments thereof, which are to be read in connection with the accompanying drawings.
BRIEF DESCRIPTION OF THE DRAWINGS
<figref idref="DRAWINGS">FIG. 1</figref> shows a wireless communication system in which at least one embodiment of the present disclosure may be implemented;
<figref idref="DRAWINGS">FIG. 2</figref> depicts an example timing diagram illustrating the process of security key derivation between D2D UEs according to an embodiment of the present disclosure;
<figref idref="DRAWINGS">FIG. 3</figref> depicts another example timing diagram illustrating the process of security key derivation between D2D UEs according to an embodiment of the present disclosure;
<figref idref="DRAWINGS">FIG. 4A</figref> and <figref idref="DRAWINGS">FIG. 4B</figref> are flowcharts showing the process of security key derivations for a network-controlled D2D communication according to an embodiment;
<figref idref="DRAWINGS">FIG. 5</figref> is a flowchart showing the process of security key derivations for a network-controlled D2D communication according to an embodiment;
<figref idref="DRAWINGS">FIG. 6A</figref> and <figref idref="DRAWINGS">FIG. 6B</figref> are flowcharts showing the process of security key derivations for a network-controlled D2D communication according to one embodiment; and
<figref idref="DRAWINGS">FIG. 7</figref> is a simplified block diagram showing some devices that are suitable for use in practicing some exemplary embodiments of the present disclosure.
DETAILED DESCRIPTION
For the purpose of explanation, details are set forth in the following description in order to provide a thorough understanding of the embodiments disclosed. It is apparent, however, to those skilled in the art that the embodiments may be implemented without these specific details or with an equivalent arrangement.
<figref idref="DRAWINGS">FIG. 1</figref> shows a wireless communication system in which at least one embodiment of the present disclosure may be implemented. As shown in <figref idref="DRAWINGS">FIG. 1</figref>, the wireless communication system <b>100</b> includes a base station <b>120</b> supporting a corresponding service in a coverage area <b>122</b> (also referred to as a cell). The base station <b>120</b> is also capable of communicating with wireless devices, such as user equipments (UEs) <b>110</b>A, <b>110</b>B, within the coverage area. Although <figref idref="DRAWINGS">FIG. 1</figref> depicts one base station <b>120</b> and two UEs <b>110</b>A, <b>110</b>B, other quantities of base stations and UEs may be implemented as well.
While this and other embodiments below are primarily discussed in the context of a fourth generation UMTS LTE network, it will be recognized by those of ordinary skill that the disclosure is not so limited. In fact, the various aspects of this disclosure are useful in any wireless network that can benefit from the method as is described herein, such as CDMA, TDMA, FDMA, OFDMA, SC-FDMA and other networks. The terms “network” and “system” are often used interchangeably. A CDMA network may implement a radio technology such as Universal Terrestrial Radio Access (UTRA), cdma2000, etc. UTRA includes Wideband CDMA (WCDMA) and other variants of CDMA. Cdma2000 covers IS-2000, IS-95 and IS-856 standards. A TDMA network may implement a radio technology such as Global System for Mobile Communications (GSM). An OFDMA network may implement a radio technology such as Evolved UTRA (E-UTRA), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash-OFDMA, etc. Further, the term “wireless” means any wireless signal, data, communication, or other interface including without limitation Wi-Fi, Bluetooth, 3G (e.g., 3GPP, 3GPP2, and UMTS), HSDPA/HSUPA, TDMA, CDMA (e.g., IS-95A, WCDMA, etc.), FHSS, DSSS, GSM, PAN/802.15, WiMAX (802.16), 802.20, narrowband/FDMA, OFDM, PCS/DCS, analog cellular, CDPD, satellite systems, millimeter wave or microwave systems, acoustic, and infrared (i.e., IrDA).
In some implementations, the base station <b>120</b> may be implemented as an evolved Node B (eNB) type base station consistent with standards, including the Long Term Evolution (LTE) standards. The UEs <b>110</b>A, <b>110</b>B may be mobile and/or stationary. Moreover, the UEs <b>110</b>A, <b>110</b>B may be referred to as, for example, devices, mobile stations, mobile units, subscriber stations, wireless terminals, terminals, or the like. The UE may be implemented as, for example, a wireless handheld device, a wireless plug-in accessory, or the like. For example, the UE may take the form of a wireless phone, a computer with a wireless connection to a network, or the like. In some cases, the UE may include one or more of the following: at least one processor, at least one computer-readable storage medium (e.g., memory, storage, and the like), a radio access mechanism, and a user interface. The wireless communication system <b>100</b> may include a core network <b>130</b>. The core network <b>130</b> comprises the conventional network elements and function of a cellular communication network, such as MME <b>132</b> (Mobility Management Entity), HSS (Home Subscriber Server) <b>134</b>, etc. Network elements in the core network may be organized in a basic structure and operate in a basic way well known to one skilled in the art.
In embodiments of the present disclosure, the wireless communication system <b>100</b> may be configured to further support network-controlled D2D communications. In this regard, a D2D feature is integrated into the public land mobile systems, such as the 3rd Generation Partnership Project (3GPP) as well as subsequent generations of cellular communication systems. Details of D2D communication are described in, inter alia, 3GPP TS 23.303 entitled “Technical Specification Group Services and System Aspects; Proximity-based services (ProSe); Stage 2(Release 12)” and 3GPP TR 33.833 entitled “Technical Specification Group Services and System Aspects; Study on security issues to support Proximity Services (Release 12)”, which are incorporated here by reference in their entirety. The cellular communication systems, such as the eNB <b>120</b>, the MME <b>132</b> or other network elements, may be used to aid in the establishment and ongoing control of the D2D communications, e.g., radio resources allocation of the D2D communications, switch control, etc. In other words, the UEs can communicate with each other either via the cellular communication system (in particular via eNB <b>120</b>), or via a direct D2D communication.
In addition, the security protection of the direct D2D communications can be also provided by virtue of the sophisticate security mechanism of the cellular communication system. For example, key derivations for securing the direct D2D communications between UE<b>1</b><b>110</b>A and UE<b>2</b><b>110</b>B may be controlled by the MME <b>132</b> and the HSS <b>134</b>. This idea can be easily realized when the UE<b>1</b> and the UE<b>2</b> are both in a connection with the radio access network of the cellular communication system, e.g. stay in a RRC (Radio Resource Control) connected mode. However, when one peer or both peers in the D2D communication are not in a connection with the radio access network, e.g. stay in a RRC idle mode, it will be complex as a D2D peer UE in an idle mode is required to change to a RRC connected mode just for key derivations for D2D communication. Furthermore, it is indeed unpractical to keep both D2D UEs always in a RRC connected mode, because this will increase the power consumption which is a bottle-neck for D2D UEs.
Accordingly, in a scenario that one peer UE or two peer UEs in a D2D communication is in an idle mode, the security provision for a D2D communication becomes an issue. <figref idref="DRAWINGS">FIG. 1</figref> illustrates an example of such scenario, in which one D2D peer (the UE<b>2</b>) is in a RRC connected mode, while the other D2D peer (the UE<b>1</b>) is in a RRC idle mode. It is appreciated that although there is no RRC connection between the UE<b>1</b> and the eNB <b>120</b>, there exists a valid security context (e.g. NAS (Non Access Stratum) security context) for the UE<b>1</b> in the core network <b>130</b>. In this regard, there may exist common keys shared between the UE<b>1</b> and the core network <b>130</b>. For example, MME <b>132</b> may maintain a valid Access Security Management Entity key (denoted as K<sub>ASME</sub>) for the UE<b>1</b>. This valid K<sub>ASME </sub>may be generated through an AKA (Authentication and Key Agreement) procedure when the UE<b>1</b> is registered to the cellular communication system. By virtue of the valid security context maintained in the cellular communication system, a consistence of security keys can be achieved between the UE<b>1</b> and the UE<b>2</b> for D2D communications, without pushing the idle mode UE<b>1</b> into a RRC connected mode. In various embodiments, a new approach is provided to efficiently share a common security key for D2D communications between the UE<b>1</b> and the UE<b>2</b>, by virtue of the valid security context. Some exemplary embodiments will be illustrated with reference to <figref idref="DRAWINGS">FIG. 2</figref>.
<figref idref="DRAWINGS">FIG. 2</figref> depicts an example timing diagram illustrating a procedure of security key derivation between D2D UEs according to an embodiment of the present disclosure. Referring to <figref idref="DRAWINGS">FIG. 2</figref>, the UE<b>1</b><b>110</b>A and the UE<b>2</b><b>110</b>B choose a suitable cell of a cellular communication system to perform a network-controlled D2D communication. The UE<b>1</b> and the UE<b>2</b> may camp on the cell <b>122</b> of the eNB <b>120</b>.
Then at <b>200</b>A, the UE<b>1</b> stays in an idle mode, for example for the lowest energy consumption. In other words, there is no RRC connection established between the UE<b>1</b> and the eNB <b>120</b>. For example, the UE<b>1</b> may stay in a RRC idle mode as specified in LTE protocols. Meanwhile, at <b>200</b>B, the UE<b>2</b> has an activated RRC connection to the eNB <b>120</b>.
As a device capable of D2D communication, the UE<b>1</b> may broadcast notifications for D2D service even if it stays in a RRC idle mode. For example at <b>215</b>, while staying in an idle mode, the UE<b>1</b> broadcasts a notification for D2D service in a physical layer beacon, which comprises its ID (ID), e.g. an IMEI (International Mobile Equipment Identity), an IMSI (International Mobile Subscriber Identity), or a S-TMSI (Short-Temporary Mobile Subscriber Identity). The S-TMSI may be allocated to the UE<b>1</b> when the UE<b>1</b> camps on the cell <b>122</b> of the eNB <b>120</b>. Furthermore, the UE<b>1</b> may also broadcast its current mode in the beacon, for example with an indication that it is staying in a RRC idle mode. In an alternative embodiment, the UE<b>1</b> may further broadcast its supported security algorithms (for example, confidentiality and integrity protection algorithms) in the beacon.
Then, one or more peer D2D UEs (e.g. the UE<b>2</b><b>110</b>B) may detect the broadcasted notification of D2D service from the UE<b>1</b> and decide to establish a D2D connection with the UE<b>1</b>, at <b>220</b>.
In an alternative embodiment, instead of the above procedure in which the UE<b>1</b> broadcasts notification and then the UE<b>2</b> decides to establish connection, the UE<b>2</b> may first broadcast a notification of D2D service in a physical layer beacon, which comprises its ID (e.g. an IMEI, an IMSI, or a S-TMSI) and optionally its supported confidentiality and integrity protection algorithms, at <b>205</b> shown in <figref idref="DRAWINGS">FIG. 3</figref>. Then, at <b>210</b>, in response to the notification broadcasted from the UE<b>2</b>, the UE<b>1</b> may send a connection request to the UE<b>2</b>. Likewise, the connection request comprises the UE<b>1</b>'s ID (e.g. an IMEI, an IMSI, or a S-TMSI) and optionally the UE<b>1</b>'s supported confidentiality and integrity protection algorithms. Then, at <b>220</b>, the UE<b>2</b> may detect the connection request from the UE<b>1</b> and decide to establish a D2D connection with the UE<b>1</b>.
From the information in the detected beacon (see <figref idref="DRAWINGS">FIG. 2</figref>) or connection request (see <figref idref="DRAWINGS">FIG. 3</figref>), the UE<b>2</b> may learn that the UE<b>1</b> is staying in a RRC idle mode, and then initiate a procedure of key derivation for the D2D connection according to some embodiments of the present disclosure. Specifically in these embodiments, at <b>225</b>, the UE<b>2</b> may send a request of key derivation for the D2D connection to the core network (e.g. MME <b>132</b>) by utilizing the activated RRC connection between the UE<b>2</b> and the eNB <b>120</b>. The request comprises the UEI's ID (e.g. S-TMSI of the UE<b>1</b>) and optionally the UE<b>1</b>'s supported confidentiality and integrity protection algorithms, which may be obtained from the detected beacon or connection request. In some exemplary embodiments, the request may be transmitted to the eNB <b>120</b> through an uplink RRC message, and in turn be forwarded from the eNB <b>120</b> to the MME <b>132</b> through a S1-AP (Application Protocol) message. In some other exemplary embodiments, the request may be delivered to MME <b>132</b> as a NAS message which is transparent to the eNB <b>120</b>.
In response to receiving the request of key derivation, the MME <b>132</b> may generate a key for the D2D connection (called as D2D key) at <b>235</b>. In some exemplary embodiments, the MME <b>132</b> may generate a random number (denoted as RAND), and then derive the D2D key (denoted as K<sub>D2D</sub>) from the RAND and a second key which is known to the core network and the UE<b>1</b>. For example, the second key may be provided or generated according to the UE<b>1</b>'s ID. For example, when the UE<b>1</b> first camped on the cell of the eNB <b>120</b> after power on, the core network (i.e. non-access stratum) may register the UE<b>1</b> and achieve a consistence of NAS security (e.g. sharing a common NAS key) between the UE<b>1</b> and the core network. In this regard, there will be a valid NAS security context for the UE<b>1</b> comprising the common NAS key maintained in the core network, for example in the MME <b>132</b> or the HSS <b>134</b>. For example, the second key shared between the UE<b>1</b> and the MME <b>132</b> may be a K<sub>ASME </sub>of the UE<b>1</b>, which may be retrieved based on the UEI's ID and may be used to derive NAS keys. In addition to the K<sub>ASME</sub>, the second key may be another key pre-shared between the UE<b>1</b> and the MME <b>132</b>, e.g., a specific key which is derived from the K<sub>ASME </sub>during the AKA procedure and is dedicated for D2D communication.
In an alternative embodiment, at <b>235</b>, the MME <b>132</b> may further encrypt the K<sub>D2D </sub>based at least in part on a third key (denoted as K<sub>UE2</sub>) which is shared between the core network and the UE<b>2</b> and which is unknown to any other UE in the wireless communication system <b>100</b>. In an exemplary embodiment, the K<sub>UE2 </sub>may be the UE<b>2</b>'s evolved Node B key (K<sub>eNB</sub>) or a key derived from the K<sub>eNB</sub>, wherein the K<sub>eNB </sub>is a key which is derived by the MME <b>132</b> and the UE<b>2</b> from the UE<b>2</b>'s K<sub>ASME </sub>and is used to derive AS (Access Stratum) keys. In addition to the K<sub>eNB</sub>, the K<sub>UE2 </sub>may be another key pre-shared between the UE<b>2</b> and the MME <b>132</b>, e.g., a specific key which is derived from the K<sub>ASME </sub>during the AKA procedure and is dedicated for D2D communication. In an embodiment, the MME <b>132</b> may encrypt the K<sub>D2D </sub>by computing XOR between the K<sub>D2D </sub>and K<sub>UE2</sub>, i.e. K<sub>D2D</sub>⊕K<sub>UE2</sub>.
In another alternative embodiment, at <b>235</b>, the MME <b>132</b> may further encrypt the UE<b>2</b>'s ID by using a first key which is known to the core network and the UE<b>1</b> and which is unknown to the UE<b>2</b>. For example, the first key may be a key derived from the UE<b>1</b>'s K<sub>ASME</sub>, e.g. a key derived from the K<sub>ASME </sub>and the UE<b>1</b>'s ID. Alternatively, the first key may be another key pre-shared between the UE<b>1</b> and the MME <b>132</b>, e.g., a specific key which is derived from the K<sub>ASME </sub>during the AKA procedure and is dedicated for D2D communication. For example, the first key may be derived from K<sub>ASME </sub>through the KDF defined in the Annex A of 3GPP TS33.401 with introducing a new FC (Function Code) and new input parameter(s).
In another alternative embodiment, the MME <b>132</b> may further receive the UE<b>1</b>'s supported confidentiality and integrity protection algorithms from the UE<b>2</b> in the request of key derivation. In this case, the MME <b>132</b> may select a confidentiality and integrity protection algorithm according to the UE<b>1</b>'s supported confidentiality and integrity protection algorithms and the UE<b>2</b>'s security capability, wherein the UE<b>2</b>'s security capability has been known to the MME <b>132</b> during the initial EPS (Evolved Packet System) attach procedure after power-on of the UE<b>2</b>, and the selected confidentiality and integrity protection algorithm may be used for securing D2D communications between the UE<b>1</b> and the UE<b>2</b>.
Then, the MME <b>132</b> may send the RAND and the K<sub>D2D </sub>to the UE<b>2</b> via the eNB <b>120</b>. In an alternative embodiment, the MME <b>132</b> may send the RAND and the encrypted K<sub>D2D </sub>to the UE<b>2</b> via the eNB <b>120</b>, as shown in <b>240</b> and <b>245</b>. In another embodiment, the MME <b>132</b> may send K<sub>D2D</sub>⊕K<sub>UE2 </sub>as the encrypted K<sub>D2D</sub>. In still another embodiment, the MME <b>132</b> may further send the encrypted UE<b>2</b>'s ID to the UE<b>2</b>. In still another embodiment, the MME <b>132</b> may further send an ID of the selected confidentiality and integrity protection algorithm to the UE<b>2</b>.
The RAND and K<sub>D2D </sub>(or the encrypted K<sub>D2D</sub>) and optionally the encrypted UE<b>2</b>'s ID and the ID of the selected confidentiality and integrity protection algorithm may be ciphered and integrity protected by a NAS key of the UE<b>2</b>. Similarly as the NAS key of the UE<b>1</b>, the NAS key of the UE<b>2</b> is a key that is shared between the core network and the UE<b>2</b>.
At <b>250</b>, the UE<b>2</b> receives the RAND and K<sub>D2D </sub>from the MME <b>132</b> via the eNB <b>120</b>, and then stores the K<sub>D2D </sub>for securing D2D communications between the UE<b>1</b> and the UE<b>2</b>. In an alternative embodiment, at <b>250</b>, the UE<b>2</b> receives the RAND and the encrypted K<sub>D2D </sub>from the MME <b>132</b> via the eNB <b>120</b>, decrypts the encrypted K<sub>D2D </sub>based at least in part on the K<sub>UE2</sub>, and stores the decrypted K<sub>D2D</sub>. In another embodiment, the UE<b>2</b> decrypts the encrypted K<sub>D2D </sub>by computing XOR between (K<sub>D2D</sub>⊕K<sub>UE2</sub>) and K<sub>UE2</sub>, i.e. (K<sub>D2D</sub>⊕K<sub>UE2</sub>)⊕K<sub>UE2</sub>. In another alternative embodiment, at <b>250</b>, the UE<b>2</b> may further receive the encrypted UE<b>2</b>'s ID. In another alternative embodiment, at <b>250</b>, the UE<b>2</b> may further receive the ID of the selected confidentiality and integrity protection algorithm.
Then, at <b>255</b>, the UE<b>2</b> may forward the RAND to the UE<b>1</b>. In an alternative embodiment, at <b>255</b>, the UE<b>2</b> may forward the RAND, the UE<b>2</b>'s ID and the encrypted UE<b>2</b>'s ID to the UE<b>1</b>. In another alternative embodiment, the UE<b>2</b> may further forward the ID of the selected confidentiality and integrity protection algorithm to the UE<b>1</b>.
Then, at <b>260</b>, with the received RAND from the UE<b>2</b>, the UE<b>1</b> may derive a K<sub>D2D </sub>from the received RAND and the second key (e.g., K<sub>ASME</sub>). As such, a common D2D key, K<sub>D2D </sub>may be shared between the UE<b>1</b> and the UE<b>2</b> without pushing the UE<b>1</b> from a RRC idle mode into a RRC connected state. The D2D key, K<sub>D2D </sub>may be used directly for securing the D2D communication between the UE<b>1</b> and the UE<b>2</b>. Alternatively or additionally, K<sub>D2D </sub>may be utilized for deriving other keys which are used for securing the D2D communication between the UE<b>1</b> and the UE<b>2</b>.
In an embodiment, the UE<b>1</b> may further receive the UE<b>2</b>'s ID and the encrypted UE<b>2</b>'s ID from the UE<b>2</b>. In this case, at <b>260</b>, the UE<b>1</b> may further decrypt the encrypted UE<b>2</b>'s ID by using a first key (e.g., a key derived from the UE<b>1</b>'s K<sub>ASME</sub>), and verify the UE<b>2</b>'s ID by comparing the decrypted UE<b>2</b>'s ID and the received UE<b>2</b>'s ID. In another alternative embodiment, the UE<b>1</b> may further receive the ID of the selected confidentiality and integrity protection algorithm. In this case, the D2D communications between the UE<b>1</b> and the UE<b>2</b> may be secured through the selected confidentiality and integrity protection algorithm.
<figref idref="DRAWINGS">FIGS. 4A-4B, 5 and 6A-6B</figref> are flowcharts illustrating the process, and results of executions of computer program instructions, in accordance with some example embodiments of this disclosure for security key derivations for a network-controlled D2D communication. More specifically, <figref idref="DRAWINGS">FIGS. 4A-4B, 5 and 6A-6B</figref> show a process flow between a D2D peer UE, such as the UE<b>1</b> or UE<b>2</b>, and a network element of the core network, such as the MME <b>132</b>. In these embodiments, the processes may be implemented in, for instance, a chip set including a processor and a memory as shown in <figref idref="DRAWINGS">FIG. 7</figref>. As such, a UE may provide means for accomplishing various parts of the process <b>400</b>A, <b>400</b>B and/or <b>600</b>A, <b>600</b>B as well as means for accomplishing other processes in conjunction with other components, and a network element of the core network may provide means for accomplishing various parts of the process <b>500</b> as well as means for accomplishing other processes in conjunction with other components.
Referring to <figref idref="DRAWINGS">FIG. 4A</figref>, in step <b>410</b>, a UE (such as the UE<b>2</b><b>110</b>B) sends a notification of D2D service to a peer UE (such as the UE<b>1</b><b>110</b>A) in an idle mode. The notification of D2D service may be sent by broadcasting physical layer beacons. The notification comprises the UE<b>2</b>'s ID and optionally the UE<b>2</b>'s supported confidentiality and integrity protection algorithms.
Next in step <b>420</b>, the UE<b>2</b> receives a connection request from the UE<b>1</b>. The connection request comprises the UE<b>1</b>'s ID and optionally the UE<b>1</b>'s supported confidentiality and integrity protection algorithms. From the connection request, the UE<b>2</b> may determine that the UE<b>1</b> stays in an idle mode.
Next in step <b>440</b>, the UE<b>2</b> sends a request for derivation of D2D key to a network element of a core network (such as the MME <b>132</b>). The request comprises the UE<b>1</b>'s ID and optionally the UE<b>1</b>'s supported confidentiality and integrity protection algorithms.
Next in step <b>450</b>, in response to the request, the UE<b>2</b> receives an encrypted K<sub>D2D</sub>, a random number, an encrypted UE<b>2</b>'s ID and optionally an ID of the selected confidentiality and integrity protection algorithm. The encrypted K<sub>D2D </sub>is generated by the MME <b>132</b> by encrypting a K<sub>D2D </sub>based at least in part on a third key (e.g., the UE<b>2</b>'s K<sub>eNB</sub>), and the K<sub>D2D </sub>is derived by the MME <b>132</b> based on the random number and a second key (e.g., the UE<b>1</b>'s K<sub>ASME</sub>).
Next in step <b>460</b>, the UE<b>2</b> decrypts the encrypted K<sub>D2D </sub>based at least in part on the third key (e.g., the UE<b>2</b>'s K<sub>eNB</sub>). In an embodiment, the UE<b>2</b> decrypts the encrypted K<sub>D2D </sub>by computing XOR between the encrypted K<sub>D2D </sub>and the third key.
Next in step <b>470</b>, the UE<b>2</b> forwards the random number, the UE<b>2</b>'s ID, the encrypted UE<b>2</b>'s ID and optionally the ID of the selected confidentiality and integrity protection algorithm to the UE<b>1</b>, so that the UE<b>1</b> may derive a common D2D key from the random number and the second key (e.g., the UE<b>1</b>'s K<sub>ASME</sub>), and verify the UE<b>2</b>'s ID by using the encrypted UE<b>2</b>'s ID. Then, a D2D connection may be established between the UE<b>1</b> and the UE<b>2</b> and the D2D communications between the UE<b>1</b> and the UE<b>2</b> may be secured based on the common D2D key and through the selected confidentiality and integrity protection algorithm.
<figref idref="DRAWINGS">FIG. 4B</figref> is same as <figref idref="DRAWINGS">FIG. 4A</figref> except that steps <b>410</b> and <b>420</b> are replaced with step <b>430</b>. In step <b>430</b>, the UE<b>2</b> receives a notification of D2D service from the UE<b>1</b> in an idle mode. The notification of D2D service may be received by detecting physical layer beacons broadcasted from the UE<b>1</b>. From the notification, the UE<b>2</b> may determine that the UE<b>1</b> stays in an idle mode.
Referring to <figref idref="DRAWINGS">FIG. 5</figref>, in step <b>510</b>, a network element (such as the MME <b>132</b>) of a core network receives a request for derivation of D2D key from a UE (such as the UE<b>2</b>), the request comprising an ID of a peer UE (such as the UE<b>1</b>) and optionally the UE<b>1</b>'s supported confidentiality and integrity protection algorithms.
Next in step <b>520</b>, in response to the request, the MME <b>132</b> may generate a random number, and derive a D2D key based on the random number and the second key (e.g. the UE<b>1</b>'s K<sub>ASME</sub>). The MME <b>132</b> may further encrypt the D2D key based at least in part on a third key (e.g. the UE<b>2</b>'s K<sub>eNB</sub>).
Next in step <b>530</b>, the MME <b>132</b> encrypts the UE<b>2</b>'s ID by using a first key (for example, a key derived from the K<sub>ASME </sub>and the UE<b>1</b>'s ID). As described in the above embodiments, the first key is known between the UE<b>1</b> and the MME <b>132</b>, but is unknown to the UE<b>2</b>. In an alternative embodiment, the MME <b>132</b> may further select a confidentiality and integrity protection algorithm according to the UE<b>1</b>'s supported confidentiality and integrity protection algorithms and the UE<b>2</b>'s security capability. Next in step <b>540</b>, the MME <b>132</b> sends the random number, the encrypted D2D key, the encrypted UE<b>2</b>'s ID and optionally the ID of the selected confidentiality and integrity protection algorithm to the UE<b>2</b>.
Now reference is made to <figref idref="DRAWINGS">FIG. 6A</figref> which is corresponding to <figref idref="DRAWINGS">FIG. 4A</figref>. In step <b>610</b>, a UE (such as the UE<b>1</b>) in an idle mode receives a notification of D2D service from the UE<b>2</b> in a connected mode. The notification of D2D service may be received by detecting physical layer beacons broadcasted from the UE<b>2</b>.
In step <b>620</b>, in response to receiving the notification, the UE<b>1</b> sends a connection request to the UE<b>2</b>. The connection request comprises the UE<b>1</b>'s ID and optionally the UE<b>1</b>'s supported confidentiality and integrity protection algorithms.
Next in step <b>640</b>, the UE<b>1</b> receives a random number, the UE<b>2</b>'s ID, an encrypted UE<b>2</b>'s ID and optionally an ID of the selected confidentiality and integrity protection algorithm from the UE<b>2</b>.
Next in step <b>650</b>, the UE<b>1</b> derives the first key which is used to encrypt the UE<b>2</b>'s ID (e.g., from the UE<b>1</b>'s K<sub>ASME</sub>), decrypts the encrypted UE<b>2</b>'s ID by using the first key, and verifies the UE<b>2</b>'s ID by comparing the decrypted UE<b>2</b>'s ID and the received UE<b>2</b>'s ID.
Next in step <b>660</b>, the UE<b>1</b> derives a D2D key based on the random number and a second key (such as K<sub>ASME</sub>). Based on the D2D key and optionally the ID of the selected confidentiality and integrity protection algorithm, a D2D connection between the UE<b>1</b> and the UE<b>2</b> may be established.
<figref idref="DRAWINGS">FIG. 6B</figref> corresponds to <figref idref="DRAWINGS">FIG. 4B</figref> and is same as <figref idref="DRAWINGS">FIG. 6A</figref> except that the steps <b>610</b> and <b>620</b> are replaced with step <b>630</b>. In step <b>630</b>, the UE<b>1</b> sends a notification of D2D service to the UE<b>2</b> in a connected mode. The notification of D2D service may be sent by broadcasting physical layer beacons. The notification of D2D service comprises the UE<b>1</b>'s ID and optionally the UE<b>1</b>'s supported confidentiality and integrity protection algorithms.
Based on the above configurations, the following advantageous technical effects can be achieved: <ul id="ul0001" list-style="none"><li id="ul0001-0001" num="0065">(1) Because the UE<b>1</b> in an idle mode need not to be pushed into a connected mode, the power consumption can be reduced.</li><li id="ul0001-0002" num="0066">(2) Because the UE<b>2</b>'s ID is encrypted by the MME <b>132</b> using the first key which is known to the UE<b>1</b> and the MME <b>132</b> and which is unknown to any other UE in the wireless network, the UE<b>1</b> can reliably verify the UE<b>2</b>'s ID such that masquerading behavior can be prevented.</li><li id="ul0001-0003" num="0067">(3) Because the K<sub>D2D </sub>is encrypted based at least in part on a third key which is shared between the MME <b>132</b> and the UE<b>2</b> and which is unknown to any other UE in the wireless network, and the encrypted K<sub>D2D </sub>instead of the K<sub>D2D </sub>is sent to the UE<b>2</b>, only the UE<b>2</b> itself can decrypt the encrypted K<sub>D2D </sub>such that masquerading behavior can be prevented.</li></ul>
Now reference is made to FIG.<b>7</b> illustrating a simplified block diagram of various electronic devices that are suitable for use in practicing the exemplary embodiments of the present disclosure. In <figref idref="DRAWINGS">FIG. 7</figref>, a wireless communication network <b>700</b> may be adapted for communication with UEs (such as UEs <b>110</b>A and <b>110</b>B), via a base station (such as the eNB <b>120</b>). The network <b>700</b> may further include a network element (such as the MME <b>132</b>) for providing a NAS security for the UEs. The UEs <b>110</b>A and <b>110</b>B may perform a cellular communication under the control of the MME <b>132</b>, via the eNB <b>120</b>. Furthermore, the UE<b>1</b><b>110</b>A and the UE<b>2</b><b>110</b>B may perform a D2D communication directly between each other. The security of the D2D communication may be provided for UEs in an idle mode according to the exemplary embodiments of the present disclosure as discussed above.
The UE<b>1</b><b>110</b>A includes a data processor (DP) <b>710</b>A, a memory (MEM) <b>710</b>B that stores a program (PROG) <b>710</b>C, and a suitable radio frequency (RF) transceiver <b>710</b>D for wireless communications with the eNB <b>120</b> via one or more antennas. In an exemplary embodiment, the transceiver <b>710</b>D in the UE <b>110</b>A may be used for D2D communications in both licensed band (e.g. cellular band) and unlicensed band (e.g. WLAN band). Alternatively, the transceiver <b>710</b>D may comprise separate components to support D2D communications in licensed band (e.g. cellular band) and unlicensed band (e.g. WLAN band) respectively.
The UE<b>2</b><b>110</b>B also includes a DP <b>720</b>A, a MEM <b>720</b>B that stores a PROG <b>720</b>C, and a suitable RF transceiver <b>720</b>D. In an exemplary embodiment, the transceiver <b>720</b>D in the UE<b>2</b><b>110</b>B may be used for D2D communications in both licensed band (e.g. cellular band) and unlicensed band (e.g. WLAN band). Alternatively, the transceiver <b>720</b>D may comprise separate components to support D2D communications in licensed band (e.g. cellular band) and unlicensed band (e.g. WLAN band) respectively.
The MME <b>132</b> also includes a DP <b>740</b>A, a MEM <b>740</b>B that stores a PROG <b>740</b>C, and a suitable communication interface <b>740</b>E. The communication interface <b>740</b>E may be able to communicate with the UE<b>1</b> and the UE<b>2</b> via the eNB <b>120</b>. In some examples, the communication interface <b>740</b>E may be used to transmit and receive information using protocols and methods associated with the network-controlled D2D communication.
Some functions of the eNB <b>120</b> may be implemented with a digital signal processor, memory, and computer programs for executing computer processes. The basic structure and operation of the eNB <b>120</b> are known to one skilled in the art, and thus it is shown as a block in order to avoid unnecessarily obscuring the disclosure.
At least one of the PROGs <b>710</b>C, <b>720</b>C, <b>740</b>C is assumed to include program instructions that, when executed by the associated DP, enable the electronic device to operate in accordance with the exemplary embodiments of this disclosure, as discussed above. That is, the exemplary embodiments of this disclosure may be implemented at least in part by computer software executable by the DP <b>710</b>A of the UE<b>1</b><b>110</b>A, by the DP <b>720</b>A of the UE<b>2</b><b>110</b>B, and by the DP <b>740</b>A of the MME <b>132</b>, or by hardware, or by a combination of software and hardware. The basic structure and operation of the UE<b>1</b><b>110</b>A, UE <b>110</b>B, and the MME <b>132</b> are known to one skilled in the art.
In general, the various embodiments of the UE <b>110</b>A and the UE<b>2</b><b>110</b>B may include, but are not limited to, cellular telephones, personal digital assistants (PDAs) having cellular wireless communication capabilities, portable computers having cellular wireless communication capabilities, image capture devices such as digital cameras having wireless communication capabilities, gaming devices having cellular wireless communication capabilities, music storage and playback appliances having cellular wireless communication capabilities, Internet appliances permitting cellular wireless Internet access and browsing, as well as portable units or terminals that incorporate combinations of such functions.
The MEMs <b>710</b>B, <b>720</b>B, <b>740</b>B may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, flash memory, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The DPs <b>720</b>A, <b>720</b>A, <b>740</b>A may be of any type suitable to the local technical environment, and may include one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multi-core processor architectures, as non-limiting examples.
In general, the various exemplary embodiments may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. For example, some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the exemplary embodiments of this disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
As such, it should be appreciated that at least some aspects of the exemplary embodiments of the disclosure may be practiced in various components such as integrated circuit chips and modules. It should thus be appreciated that the exemplary embodiments of this disclosure may be realized in an apparatus that is embodied as an integrated circuit, where the integrated circuit may comprise circuitry (as well as possibly firmware) for embodying at least one or more of a data processor, a digital signal processor, baseband circuitry and radio frequency circuitry that are configurable so as to operate in accordance with the exemplary embodiments of this disclosure.
It should be appreciated that at least some aspects of the exemplary embodiments of the disclosure may be embodied in computer-executable instructions, such as in one or more program modules, executed by one or more computers or other devices. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types when executed by a processor in a computer or other device. The computer executable instructions may be stored on a computer readable medium such as a hard disk, optical disk, removable storage media, solid state memory, RAM, etc. As will be appreciated by one of skill in the art, the function of the program modules may be combined or distributed as desired in various embodiments. In addition, the function may be embodied in whole or in part in firmware or hardware equivalents such as integrated circuits, field programmable gate arrays (FPGA), and the like.
The present disclosure includes any novel feature or combination of features disclosed herein either explicitly or any generalization thereof. Various modifications and adaptations to the foregoing exemplary embodiments of this disclosure may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings. However, any and all modifications will still fall within the scope of the non-Limiting and exemplary embodiments of this disclosure.
Contents5
11 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11
Every citation, both waysCites: the store holds 0 of 1
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10172044B2 | Cited by | United States of America | Search report |
| US10893410B2 | Cited by | United States of America | Applicant |
| US9986431B2 | Cited by | United States of America | Search report |
| US10897707B2 | Cited by | United States of America | Search report |
| US2017280360A1 | Cited by | United States of America | Pre-grant |
| US11070546B2 | Cited by | United States of America | Search report |
| US10728748B2 | Cited by | United States of America | Applicant |
| US2018270653A1 | Cited by | United States of America | Search report |
| US2017055149A1 | Cited by | United States of America | Pre-grant |
8 members in 4 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 2014077271 | China | W | |
| 2014077271 | China | W | |
| PCTCN2014077271 | – | – | – |
| WO2014CN77271 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| WO2015172288A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN106465102A | China | A | |
| US2017055152A1 | United States of America | A1 | |
| EP3143785A1 | European Patent Office (EPO) | A1 | |
| EP3143785A4 | European Patent Office (EPO) | A4 | |
| EP3143785B1 | European Patent Office (EPO) | B1 | |
| US10462660B2 | United States of America | B2 | |
| CN106465102B | China | B |
37 transactions on the USPTO file
1 non-final rejection on record.
- Non-final rejections
- 1
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Email NotificationEML_NTR | EML_NTR | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Is Now CompleteCOMP | COMP | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Email NotificationEML_NTR | EML_NTR | |
| Email NotificationEML_NTR | EML_NTR | |
| Notice of DO/EO Acceptance MailedM903 | M903 | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Sent to Classification ContractorPGPC | PGPC | |
| FITF set to YES - revise initial settingFTFS | FTFS | |
| Preliminary AmendmentA.PE | A.PE | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| 371 Completion Date371COMP | 371COMP | |
| Patent Term Adjustment - Ready for ExaminationPTA.RFE | PTA.RFE | |
| PTO/SB/69-Authorize EPO Access to Search ResultsSREXR141 | SREXR141 | |
| Applicants have given acceptable permission for participating foreignAPPERMS | APPERMS | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Cleared by OIPE CSRL194 | L194 | |
| Entity status set to undiscounted (initial default setting or status change)BIG. | BIG. | |
| Initial Exam Team nnIEXX | IEXX |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| Information on status: patent application and granting procedure in generalPUBLICATIONS -- ISSUE FEE PAYMENT VERIFIEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONSSTPP | STPP | |
| Information on status: patent application and granting procedure in generalDOCKETED NEW CASE - READY FOR EXAMINATIONSTPP | STPP | |
| Information on status: application discontinuationFINAL REJECTION MAILEDSTCB | STCB | |
| Information on status: patent application and granting procedure in generalFINAL REJECTION MAILEDSTPP | STPP | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication
- 20170055152
- Publication, DOCDB
- 2017055152
- Publication, EPODOC
- US2017055152
- Application
- 15306816
- Application, DOCDB
- 201415306816
- Application, EPODOC
- US201415306816
Titles
- English
- Method, Network Element, User Equipment and System for Securing Device-to-Device Communication in a Wireless Network
Patent term adjustment
- A delay
- +157 daysthe office missed an examination deadline
- Applicant delay
- −13 days
- Net adjustment
- 144 days
Classification
- CPC, 16
- H04W12/06
- H04W76/14
- H04L2463/061
- H04W76/023
- H04W12/00512
- H04L63/0876
- H04W12/04031
- H04W12/71
- H04W12/04
- H04W12/0431
- H04L63/06
- H04L9/14
- H04L63/0428
- H04L63/0853
- H04W88/04
- H04L2209/80
- IPC, 7
- H04W12 06
- H04L9 14
- H04W12 04
- H04W76 02
- H04L29 06
- H04W12 041
- H04W12 0431
- USPC, 1
- 001001000