PROTECTION OF CONTROL SIGNALING IN A WIRELESS BACKHAUL NETWORK

    公开(公告)号:WO2021071632A1

    公开(公告)日:2021-04-15

    申请号:PCT/US2020/050698

    申请日:2020-09-14

    Abstract: Methods, systems, and devices for wireless communications are described. A first parent node of a wireless backhaul network may receive, from a donor node of the wireless backhaul network, a token for a child node of the wireless backhaul network, the token being unique to a first wireless link between the first parent node and the child node. The first parent node may determine that a triggering event has occurred for a second wireless link between the first parent node and a second parent node. The first parent node may transmit, in response to determining that the triggering event has occurred, the token to the child node over the first wireless link to indicate for the child node to select a third parent node of the wireless backhaul network.

    IDENTITY BASED SIGNATURE IN SYSTEM INFORMATION PROTECTION

    公开(公告)号:WO2020092826A1

    公开(公告)日:2020-05-07

    申请号:PCT/US2019/059242

    申请日:2019-10-31

    Abstract: A network entity may provision a UE and a base station with parameters for securing network communications. The network entity may send a system parameter to a UE and a private security key to a base station. Additionally, the UE and the base station may each receive synchronization information from the network which may be used to create a randomness parameter. The base station may create a signature based on the private security key, a cell identifier, and the randomness parameter and include the signature in a system information message that is to be broadcasted to one or more UEs. A UE connecting to the base station may receive the system information message from the base station, determine the cell identifier, and verify the system information message based on one or more of the cell identifier, the system parameter, or the randomness parameter.

    SESSION MANAGEMENT AUTHORIZATION TOKEN
    24.
    发明申请

    公开(公告)号:WO2018144200A1

    公开(公告)日:2018-08-09

    申请号:PCT/US2018/013170

    申请日:2018-01-10

    Abstract: Techniques are described that provide a session management authorization token by receiving a session request message to establish a protocol data unit (PDU) session for a logical data network associated with a user equipment (UE), the session request message may include one or more session parameters; verifying that the UE is authorized to establish the PDU session for the logical data network; receiving a key associated with the PDU session; generating an authorization token based on the received key and the session parameters; and transmitting a session response message including the generated authorization token to the UE.

    SECURE SIGNALING BEFORE PERFORMING AN AUTHENTICATION AND KEY AGREEMENT
    25.
    发明申请
    SECURE SIGNALING BEFORE PERFORMING AN AUTHENTICATION AND KEY AGREEMENT 审中-公开
    在执行认证和密钥协议之前安全地进行信号传输

    公开(公告)号:WO2017192393A1

    公开(公告)日:2017-11-09

    申请号:PCT/US2017/030193

    申请日:2017-04-28

    Abstract: Techniques are described for wireless communication. A method of wireless communication at a wireless communication device includes generating a secured query message based at least in part on a security credential of the wireless communication device, where the secured query message is generated prior to performing an authentication and key agreement (AKA) with a network; transmitting the secured query message to the network; receiving a response to the secured query message; and determining whether to perform the AKA with the network based at least in part on the received response.

    Abstract translation: 描述了用于无线通信的技术。 一种在无线通信设备处进行无线通信的方法包括至少部分地基于无线通信设备的安全凭证来生成安全查询消息,其中安全查询消息是在执行认证和密钥协商(AKA)之前生成的,其中 一个网络; 将安全查询消息传输到网络; 接收对安全查询消息的响应; 以及至少部分地基于所接收的响应来确定是否与网络执行AKA。

    SYSTEM ARCHITECTURE FOR MEDICAL IMPLANT
    26.
    发明申请
    SYSTEM ARCHITECTURE FOR MEDICAL IMPLANT 审中-公开
    系统体系结构的医疗植入

    公开(公告)号:WO2017160627A2

    公开(公告)日:2017-09-21

    申请号:PCT/US2017/021778

    申请日:2017-03-10

    Abstract: Aspects of the subject matter described in this disclosure can be implemented in an implant device capable of being configured by an external hospital interrogator device when the external hospital interrogator device is authenticated, and capable of communicating data regarding a patient when paired with an external home interrogator device. The implant device includes RF communications circuitry, one or more sensors configured to measure and/or collect data regarding the patient, and a control system. The control system is configured to receive instructions from the external hospital interrogator device for configuring the implant device when the external hospital interrogator device is authenticated, and receive identification data from the external hospital interrogator device for pairing the implant device with the external home interrogator device.

    Abstract translation: 在本公开中描述的主题的各方面可以在外部医院询问器设备被认证时能够由外部医院询问器设备配置的植入设备中实现,并且能够传送关于 患者与外部家庭询问器设备配对时。 植入装置包括RF通信电路,配置成测量和/或收集关于患者的数据的一个或多个传感器,以及控制系统。 控制系统被配置成当外部医院询问器设备被认证时从外部医院询问器设备接收用于配置植入设备的指令,并从外部医院询问器设备接收标识数据以将植入设备与外部家庭询问器设备配对。

    NETWORK ARCHITECTURE AND SECURITY WITH SIMPLIFIED MOBILITY PROCEDURE
    27.
    发明申请
    NETWORK ARCHITECTURE AND SECURITY WITH SIMPLIFIED MOBILITY PROCEDURE 审中-公开
    网络架构和安全性与简化的机动性程序

    公开(公告)号:WO2017011113A1

    公开(公告)日:2017-01-19

    申请号:PCT/US2016/037066

    申请日:2016-06-10

    Abstract: In an aspect, a network supporting a number of client devices includes a network device that generates a context for a client device. The client device context may include network state information for the client device that enables the network to communicate with the client device. The client device may obtain, from a network device that serves a first service area of the network, information that includes a first client device context. The client device may enter a second service area of the network served by a second network device. Instead of performing a service area update procedure with the network, the client device may transmit a packet in the different service area with the information that includes the client device context. The client device may receive a service relocation message including information associated with the different network device in response to the transmission.

    Abstract translation: 在一方面,支持多个客户端设备的网络包括生成客户端设备的上下文的网络设备。 客户端设备上下文可以包括使得网络能够与客户端设备通信的客户端设备的网络状态信息。 客户端设备可以从服务于网络的第一服务区域的网络设备获得包括第一客户端设备上下文的信息。 客户端设备可以进入由第二网络设备服务的网络的第二服务区域。 客户端设备可以不使用网络执行服务区域更新过程,而是可以在不同的服务区域中发送包含客户端设备上下文的信息。 客户端设备可以响应于传输而接收包括与不同网络设备相关联的信息的服务重定位消息。

    AUTHENTICATION AND KEY AGREEMENT WITH PERFECT FORWARD SECRECY
    28.
    发明申请
    AUTHENTICATION AND KEY AGREEMENT WITH PERFECT FORWARD SECRECY 审中-公开
    认证和关键协议与完美的前瞻性分析

    公开(公告)号:WO2016160256A1

    公开(公告)日:2016-10-06

    申请号:PCT/US2016/020545

    申请日:2016-03-03

    Abstract: Systems and methods for providing authentication key agreement (AKA) with perfect forward secrecy (PFS) are disclosed. In one embodiment, a network according to the disclosure may receive an attach request from a UE, provide an authentication request including a network support indicator to a network resource, receive an authentication token from the network resource, such that the authentication token includes an indication that a network supports PFS, provide the authentication token to the UE, receive an authentication response including a UE public key value, obtain a network public key value and a network private key value, determine a shared key value based on the network private key value and the UE public key value, bind the shared key value with a session key value to create a bound shared key value, and use the bound shared key value to protect subsequent network traffic.

    Abstract translation: 公开了提供具有完美前向保密(PFS)的认证密钥协商(AKA)的系统和方法。 在一个实施例中,根据本公开的网络可以从UE接收附加请求,向网络资源提供包括网络支持指示符的认证请求,从网络资源接收认证令牌,使得认证令牌包括指示 网络支持PFS,向UE提供认证令牌,接收包括UE公钥值的认证响应,获取网络公钥值和网络私钥值,基于网络私钥值确定共享密钥值 和UE公钥值,将共享密钥值与会话密钥值绑定以创建绑定的共享密钥值,并使用绑定的共享密钥值来保护后续网络流量。

    APPARATUS AND METHOD FOR SPONSORED CONNECTIVITY TO WIRELESS NETWORKS USING APPLICATION-SPECIFIC NETWORK ACCESS CREDENTIALS
    29.
    发明申请
    APPARATUS AND METHOD FOR SPONSORED CONNECTIVITY TO WIRELESS NETWORKS USING APPLICATION-SPECIFIC NETWORK ACCESS CREDENTIALS 审中-公开
    使用应用特定网络访问证书为无线网络提供连接的设备和方法

    公开(公告)号:WO2016148902A1

    公开(公告)日:2016-09-22

    申请号:PCT/US2016/020224

    申请日:2016-03-01

    Abstract: At least one feature pertains to a method operational at a user device. The method includes receiving and storing a shared key from an application service provider, and determining that a wireless communication network provides application- specific access to an application service provided by the application service provider. The method further includes transmitting a registration request that includes a device identifier and an application identifier associated with the application service to the wireless communication network. The registration request is transmitted to the application service provider using a data connection through a packet data network. The method further includes receiving authentication information derived at the application service provider that is based on the shared key, and performing authentication and key agreement with the network based on the authentication information and the stored shared key. The user device may then communicate with the application service after authentication and key agreement is successfully performed.

    Abstract translation: 至少一个特征涉及在用户设备上操作的方法。 该方法包括从应用服务提供商接收和存储共享密钥,以及确定无线通信网络向由应用服务提供商提供的应用服务提供针对特定应用的访问。 该方法还包括向无线通信网络发送包括设备标识符和与应用服务相关联的应用标识符的注册请求。 使用通过分组数据网络的数据连接将注册请求发送到应用服务提供商。 该方法还包括接收基于所述共享密钥在所述应用服务提供商处导出的认证信息,并且基于所述认证信息和所存储的共享密钥来执行与所述网络的认证和密钥协商。 然后,用户设备可以在认证和密钥协商成功执行之后与应用服务通信。

    AUTHENTICATION OF BROWSER-BASED SERVICES VIA OPERATOR NETWORK
    30.
    发明申请
    AUTHENTICATION OF BROWSER-BASED SERVICES VIA OPERATOR NETWORK 审中-公开
    通过操作员网络验证基于浏览器的服务

    公开(公告)号:WO2016064520A1

    公开(公告)日:2016-04-28

    申请号:PCT/US2015/051763

    申请日:2015-09-23

    Abstract: An example method of determining a level of service to allocate for a browser-based session includes receiving, at an operator core network, a request to establish a browser-based session for a web service. The request is from a browser executing on a user equipment (UE). The method also includes identifying an attribute value of an attribute assigned to the UE and determining, based on the attribute value assigned to the UE, whether the UE is currently registered with the operator core network. The method further includes determining, based on whether the UE is currently registered with the operator core network, a level of service to allocate for the browser-based session.

    Abstract translation: 确定为基于浏览器的会话分配的服务等级的示例性方法包括在运营商核心网络处接收为web服务建立基于浏览器的会话的请求。 该请求来自在用户设备(UE)上执行的浏览器。 该方法还包括识别分配给UE的属性的属性值,并且基于分配给UE的属性值来确定UE是否当前已经向运营商核心网注册。 该方法还包括基于UE当前是否向运营商核心网络注册确定为基于浏览器的会话分配的服务级别。

Patent Agency Ranking