US 11,743,718 B2
Security context handling in 5G during connected mode
Noamen Ben Henda, Stockholm (SE); Christine Jost, Lund (SE); Karl Norrman, Stockholm (SE); and Monica Wifvesson, Lund (SE)
Assigned to TELEFONAKTIEBOLAGET LM ERICSSON (PUBL), Stockholm (SE)
Filed by Telefonaktiebolaget LM Ericsson (publ), Stockholm (SE)
Filed on Jul. 22, 2022, as Appl. No. 17/871,357.
Application 17/871,357 is a continuation of application No. 16/713,984, filed on Dec. 13, 2019, granted, now 11,432,141.
Application 16/713,984 is a continuation of application No. 16/235,438, filed on Dec. 28, 2018, granted, now 10,536,849, issued on Jan. 14, 2020.
Application 16/235,438 is a continuation of application No. PCT/EP2018/052153, filed on Jan. 29, 2018.
Claims priority of provisional application 62/452,267, filed on Jan. 30, 2017.
Prior Publication US 2022/0360980 A1, Nov. 10, 2022
This patent is subject to a terminal disclaimer.
Int. Cl. H04W 12/04 (2021.01); H04W 12/041 (2021.01); H04W 60/02 (2009.01); H04W 36/00 (2009.01); H04W 48/20 (2009.01); H04W 12/0433 (2021.01); H04L 9/40 (2022.01); H04W 36/14 (2009.01); H04W 36/38 (2009.01)
CPC H04W 12/041 (2021.01) [H04L 63/062 (2013.01); H04W 12/0433 (2021.01); H04W 36/0038 (2013.01); H04W 36/14 (2013.01); H04W 36/385 (2013.01); H04W 48/20 (2013.01); H04W 60/02 (2013.01); H04L 2463/061 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method for transferring a security context during a handover of a user equipment, the method implemented by one or more core network nodes in a core network of a wireless communication network, wherein the one or more core network nodes provide a source Access and Mobility Management Function (AMF) the method comprising:
receiving, from a source base station in an access network of the wireless communication network, a first handover message indicating that a handover of the user equipment is needed;
deriving a new non-access stratum (NAS) key responsive to deciding that an operator specific security policy is met, wherein the NAS key is used to derive NAS ciphering and integrity protection keys for protection of NAS signaling between the UE and AMF;
sending, responsive to the first handover message, the new NAS key to a target AMF in the core network of the wireless communication network; and
sending, in a second handover message, a key derivation parameter and a key change indication to the user equipment, the key change indication comprising a key change indicator flag set to a value indicating a change of a NAS key.