IPC분류정보
국가/구분 |
United States(US) Patent
등록
|
국제특허분류(IPC7판) |
|
출원번호 |
US-0213618
(2008-06-23)
|
등록번호 |
US-8121293
(2012-02-21)
|
우선권정보 |
FI-20002613 (2000-11-28); FI-20010282 (2001-02-14) |
발명자
/ 주소 |
- Vialen, Jukka
- Niemi, Valtteri
|
출원인 / 주소 |
|
대리인 / 주소 |
|
인용정보 |
피인용 횟수 :
6 인용 특허 :
25 |
초록
▼
During connection setup with a first radio access network, a multimode mobile station sends an unprotected initial signaling message that includes information about those encryption algorithms that the multimode mobile station supports when it communications in a second radio access network. The fir
During connection setup with a first radio access network, a multimode mobile station sends an unprotected initial signaling message that includes information about those encryption algorithms that the multimode mobile station supports when it communications in a second radio access network. The first radio access network saves some or all the information. Then it composes and sends an integrity-protected message that includes information about the encryption algorithms supported by the multimode mobile station in the second radio access network.
대표청구항
▼
1. An apparatus, comprising: a processor configured to compose an integrity protected command message for sending from a radio access network to a multimode mobile station, said integrity protected command message including information relating to the encrypting algorithms supported by a multimode m
1. An apparatus, comprising: a processor configured to compose an integrity protected command message for sending from a radio access network to a multimode mobile station, said integrity protected command message including information relating to the encrypting algorithms supported by a multimode mobile station in a further radio access network, and comprising a payload and a message authentication code. 2. The apparatus of claim 1, wherein the processor is further configured to attach information about the encryption algorithms supported by the multimode mobile station in said further radio access network received in an unprotected signaling message from the multimode mobile station to said payload and to apply said payload in an algorithm computing said message authentication code. 3. The apparatus of claim 1, wherein the processor is further configured to save an unprotected signaling message received from the multimode mobile station including information about encryption algorithms supported by the multimode mobile station in the further radio access network and to use the unprotected signaling message in an algorithm computing said message authentication code. 4. The apparatus of claim 1, wherein the processor is further configured to save a payload of an unprotected signaling message received from the multimode mobile station including information about encryption algorithms supported by the multimode mobile station in the further radio access network and to use the payload of the unprotected signaling message in an algorithm computing said message authentication code. 5. The apparatus of claim 1, wherein the processor is further configured to save information about the encryption algorithms supported by the multimode mobile station in said further radio access network and to use information about the encryption algorithms supported by the multimode mobile station in said further radio access network together with information about an encryption algorithm embedded in a command message received from a core network in computing said message authentication code. 6. The apparatus of claim 1, wherein the processor is further configured to omit from the integrity protected command message information about the encryption algorithms supported by the multimode mobile station in said further radio access network and information about the security capability of said multimode mobile station in said radio access network. 7. The apparatus of claim 1, wherein the processor is further configured to include in said integrity protected command message information about the encryption algorithms supported by the multimode mobile station in said further radio access network. 8. The apparatus of claim 1, wherein the processor is further configured to receive said information about the encryption algorithms supported by the multimode mobile station in said further radio access network during connection setup, to save said information about the encryption algorithms, and to use said information about encryption algorithms in composing the integrity protected command message. 9. The apparatus of claim 1, wherein the processor is further configured to send information about the encryption algorithms supported by the multimode mobile station in said further radio access network to a core network. 10. The apparatus of claim 1, wherein the processor is further configured to receive a command message from a core network instructing the multimode mobile station to cipher further communications. 11. The apparatus of claim 10, wherein the processor is further configured to send to said multimode mobile station said integrity protected command message after receiving said command message from the core network. 12. The apparatus of claim 1, wherein said integrity protected command message is configured to instruct the multimode mobile station to cipher further communications. 13. An apparatus, comprising: a transmitter configured to send to a first radio access network an unprotected signaling message including information about encryption algorithms supported by a multimode mobile station in a second radio access network;a receiver configured to receive from the first radio access network an integrity protected command message including information relating to said encryption algorithms supported by the multimode mobile station in the second radio access network, said integrity protected command message comprising a payload and a message authentication code; anda processor configured to conclude whether said information relating to said encryption algorithms in said integrity protected command message corresponds to said information about said encryption algorithms in said unprotected signaling message. 14. The apparatus of claim 13, wherein said payload comprises information about encryption algorithms, said multimode mobile station configured to compare information about the encryption algorithms received in said payload with stored information about said encryption algorithms supported by the multimode mobile station. 15. The apparatus of claim 13, wherein the processor is further configured to save the unprotected signaling message and to use the unprotected signaling message in an algorithm computing an expected message authentication code for the integrity protected command message. 16. The apparatus of claim 13, wherein the processor is further configured to save a payload of the unprotected signaling message and to use the payload of the unprotected signaling message in an algorithm computing an expected message authentication code for the integrity protected command message. 17. The apparatus of claim 13, wherein the processor is further configured to use information about the encryption algorithms supported by the multimode mobile station in said second radio access network together with information about an encryption algorithm for use with said first radio access network in computing an expected message authentication code for the integrity protected command message. 18. The apparatus of claim 13, wherein said integrity protected command message omits information about the encryption algorithms supported by the multimode mobile station in said further radio access network and information about the security capability of said multimode mobile station in said radio access network. 19. The apparatus of claim 13, wherein said integrity protected command message comprises information about the encryption algorithms supported by the multimode mobile station in said further radio access network. 20. The apparatus of claim 13, wherein the processor is further configured to send said information about the encryption algorithms supported by the multimode mobile station in said second radio access network during connection setup. 21. The apparatus of claim 13, wherein said integrity protected command message instructs the multimode mobile station to cipher further communications. 22. A method, comprising: composing an integrity protected command message, said integrity protected command message including information relating to the encrypting algorithms supported by the multimode mobile station in a second radio access network and including a payload and a message authentication code; andsending the composed integrity protected command message from a first radio access network to a multimode mobile station. 23. The method of claim 22, further comprising: sending information about the encryption algorithms supported by the multimode mobile station in said second radio access network to a core network. 24. The method of claim 22, further comprising: receiving a command message from the core network, said command message instructing the multimode mobile station to cipher further communication. 25. The method of claim 22, further comprising: instructing the multimode mobile station to cipher further communications with said integrity protected command message. 26. A method, comprising: sending from a multimode mobile station to a first radio access network an unprotected signaling message including information about encryption algorithms supported by the multimode mobile station in a second radio access network;receiving from the first radio access network an integrity protected command message including information relating to said encryption algorithms supported by the multimode mobile station in the second radio access network, said integrity protected command message comprising a payload and a message authentication code; andconcluding whether said information relating to said encryption algorithms in said integrity protected command message corresponds to said information about said encryption algorithms in said unprotected signaling message. 27. The method of claim 26, wherein said payload comprises information about encryption algorithms, and wherein the method further comprises comparing information about the encryption algorithms received in said payload with stored information about said encryption algorithms supported by the multimode mobile station. 28. The method of claim 26, further comprising: saving the unprotected signaling message; andusing the unprotected signaling message in an algorithm computing an expected message authentication code for the integrity protected command message. 29. The method of claim 26, further comprising: saving a payload of the unprotected signaling message; andusing the payload of the unprotected signaling message in an algorithm computing an expected message authentication code for the integrity protected command message. 30. The method of claim 26, further comprising: using information about the encryption algorithms supported by the multimode mobile station in said second radio access network together with information about an encryption algorithm for use with said first radio access network in computing an expected message authentication code for the integrity protected command message. 31. The method of claim 26, wherein said integrity protected command message omits information about the encryption algorithms supported by the multimode mobile station in said further radio access network and information about the security capability of said multimode mobile station in said radio access network. 32. The method of claim 26, wherein said integrity protected command message comprises information about the encryption algorithms supported by the multimode mobile station in said further radio access network. 33. The method of claim 26, further comprising: sending said information about the encryption algorithms supported by the multimode mobile station in said second radio access network during connection setup. 34. The method of claim 26, wherein said integrity protected command message instructs the multimode mobile station to cipher further communications. 35. An apparatus, comprising: a transmitter configured to send to a first radio access network an unprotected signaling message identifying encryption algorithms supported by a multimode mobile station in a second radio access network;a receiver configured to receive from the first radio access network an integrity protected command message identifying said encryption algorithms supported by the multimode mobile station in the second radio access network, said integrity protected command message comprising a payload and a message authentication code; anda processor configured to conclude whether identification of said encryption algorithms in said integrity protected command message corresponds to identification of said encryption algorithms in said unprotected signaling message. 36. The apparatus of claim 35, wherein said unprotected signaling message identifying encryption algorithms supported by a multimode mobile station in the second radio access network includes GSM classmark information relating to the security capability of the multimode mobile station in the second radio access network; and whereinsaid integrity protected command message identifying said encryption algorithms supported by the multimode mobile station in the second radio access network includes said GSM classmark information relating to the security capability of the multimode mobile station in the second radio access network; and whereinsaid processor is configured to conclude whether said identifications of said encryption algorithms in the sent unprotected and received integrity protected messages, respectively, correspond by determining whether said GSM classmark information in the sent unprotected and received integrity protected messages, respectively, match. 37. The apparatus of claim 36, wherein said first radio access network is a UMTS network and said second radio access network is a GSM network; and wherein said unprotected signaling message identifying encryption algorithms supported by a multimode mobile station in the second radio access network further includes UE security capability information relating to the security capability of the multimode mobile station in the first radio access network; and whereinsaid integrity protected command message identifying said encryption algorithms supported by the multimode mobile station in the second radio access network further includes said UE security capability information relating to the security capability of the multimode mobile station in the first radio access network; and whereinsaid processor is configured to conclude whether said respective identifications of said encryption algorithms correspond by determining whether said GSM classmark information in the sent unprotected and received integrity protected messages, respectively is the same and whether said UE security capability information in the sent unprotected and received integrity protected messages, respectively, match. 38. The apparatus of claim 36, wherein said GSM classmark information is used in calculating said message authentication code.
※ AI-Helper는 부적절한 답변을 할 수 있습니다.