Claims
- 1. A method for protecting the security of a communication between a mobile radio and a radio access network (RAN), comprising:
establishing a connection through the RAN to support a communication with the mobile radio; configuring the connection with a first security configuration; sending one or more messages over the connection using the first security connection, each message having a message sequence number; determining a need to reconfigure the connection to a second security configuration; setting an activation message sequence number associated with the reconfiguration; and when the second security configuration is to be activated, sending a next message with the activation message sequence number.
- 2. The method in claim 1, wherein when the second security configuration is activated, subsequent messages are sent using the second security configuration.
- 3. The method in claim 2, wherein the next message is sent using the second security configuration.
- 4. The method in claim 1, wherein during the reconfiguration, the mobile radio transmits a message with a message sequence number lower than the activation message sequence number to the RAN using the first security configuration.
- 5. The method in claim 4, wherein the message transmitted by the mobile radio is a cell update message or an area update message.
- 6. The method in claim 1, wherein the first security configuration corresponds to a first connection associated with a session involving the mobile radio and the second security configuration corresponds to a second connection associated with the session.
- 7. The method in claim 6, wherein the session is a multimedia session, and the first connection relates to one type of media and the second connection relates to another type of media.
- 8. The method in claim 1, wherein the security configuration relates to integrity protection of the message.
- 9. The method in claim 8, wherein the message includes a control message related to the connection.
- 10. The method in claim 9, wherein the first security configuration includes a first integrity protection key used to authenticate the control signal, and the second security configuration includes a second integrity protection key used to authenticate the control signal.
- 11. The method in claim 1, wherein the security configuration relates to confidentiality protection of the communication, and the communication includes data traffic related to the connection.
- 12. The method in claim 11, wherein the first security configuration includes a first encryption key used to encrypt the data traffic, and the second security configuration includes a second encryption key used to encrypt the data traffic.
- 13. The method in claim 1, further comprising:
setting the activation message sequence number using a maximum number of retransmissions of a message.
- 14. The method in claim 13, wherein the message is a cell update message or an area update message transmitted by the mobile radio to the RAN.
- 15. The method in claim 1, wherein the activation message sequence number corresponds to a future message sequence number greater than a next message sequence number.
- 16. The method in claim 1, wherein the sending step is performed to apply the second security configuration even when the activation message sequence number of messages has not been transmitted at the time that the security reconfiguration is completed.
- 17. A mobile radio configured to communicate with an entity via a connection established through a radio access network (RAN), comprising:
radio transceiving circuitry, and data processing circuitry configured to perform the following tasks:
establish a first security configuration for the connection; send one or more messages over the connection using the first security connection, each message having a message sequence number; determine if the connection is to be reconfigured to a second security configuration; determine an activation message sequence number associated with the reconfiguration; and when the second security configuration is to be activated, send a next message with the activation message sequence number.
- 18. The mobile radio in claim 17, wherein when the second security configuration is activated, subsequent messages sent and received by the mobile radio use the second security configuration.
- 19. The mobile radio in claim 18, wherein the data processing circuitry is configured to transmit the next message using the second security configuration.
- 20. The mobile radio in claim 20, wherein during the reconfiguration, the data processing circuitry is configured to transmit a message with a message sequence number lower than the activation message sequence number to the RAN using the first security configuration.
- 21. The mobile radio in claim 20, wherein the message transmitted by the mobile radio is a cell update message or an area update message.
- 22. The mobile radio in claim 17, wherein the first security configuration corresponds to a first connection associated with a session involving the mobile radio and the second security configuration corresponds to a second connection associated with the session.
- 23. The mobile radio in claim 22, wherein the session is a multimedia session, and the first connection relates to one type of media and the second connection relates to another type of media.
- 24. The mobile radio in claim 17, wherein the security configuration relates to integrity protection of the message, and the message includes a control message related to the connection.
- 25. The mobile radio in claim 24, wherein the first security configuration includes a first integrity protection key used to authenticate the control signal, and the second security configuration includes a second integrity protection key used to authenticate the control signal.
- 26. The mobile radio in claim 17, wherein the security configuration relates to confidentiality protection of the communication, and the communication includes data traffic related to the connection.
- 27. The mobile radio in claim 26, wherein the first security configuration includes a first encryption key used to encrypt the data traffic, and the second security configuration includes a second encryption key used to encrypt the data traffic.
- 28. The mobile radio in claim 17, further comprising:
setting the activation message sequence number using a maximum number of retransmissions of a message.
- 29. The mobile radio in claim 28, wherein the message is a cell update message or an area update message transmitted by the mobile radio to the RAN.
- 30. The mobile radio in claim 17, wherein the activation message sequence number corresponds to a future message sequence number greater than a next message sequence number.
- 31. The mobile radio in claim 17, wherein the data processing circuitry is configured to apply the second security configuration even when the activation number of messages has not been transmitted when the security reconfiguration is completed.
- 32. A radio access network (RAN) node for establishing a mobile radio connection through the RAN to support communications involving the mobile radio, comprising:
data processing circuitry configured to perform the following functions:
establish a first security configuration parameters for the connection; send or receive one or more messages over the connection using the first security connection, each message having a message sequence number; determine if the connection is to be reconfigured to a second security configuration; send a security configuration change message to the mobile radio; detect a next message from the mobile radio with the activation message sequence number; and upon detecting the next message, activate the second security configuration for the connection.
- 33. The RAN node in claim 32, wherein when the second security configuration is activated, subsequent messages are sent using the second security configuration.
- 34. The RAN node in claim 33, wherein the next message is sent using the second security configuration.
- 35. The RAN node in claim 32, wherein the data processing circuitry is configured to transmit a security mode command to the mobile radio when the connection is to be reconfigured to the second security configuration.
- 36. The RAN node in claim 35, wherein the data processing circuitry is configured to detect a security mode complete message from the mobile radio, in response to the security mode command, that includes the activation message sequence number.
- 37. The RAN node in claim 36, wherein the data processing circuitry is configured to transmit a security mode complete acknowledge message to the mobile radio to signal to the mobile radio that the security reconfiguration is complete.
- 38. The RAN node in claim 32, wherein the data processing circuitry is configured to detect during the reconfiguration, a message from the mobile radio having a message sequence number lower than the activation message sequence number to the RAN using the first security configuration.
- 39. The RAN node in claim 38, wherein the message transmitted by the mobile radio is a cell update message or an area update message.
- 40. The RAN node in claim 32, wherein the security configuration relates to integrity protection of the message, and the message includes a control message related to the connection.
- 41. The RAN node in claim 40, wherein the first security configuration includes a first integrity protection key used to authenticate the control signal, and the second security configuration includes a second integrity protection key used to authenticate the control signal.
- 42. The RAN node in claim 32, wherein the security configuration relates to confidentiality protection of the communication, and the communication includes data traffic related to the connection.
- 43. The RAN node in claim 42, wherein the first security configuration includes a first encryption key used to encrypt the data traffic, and the second security configuration includes a second encryption key used to encrypt the data traffic.
- 44. The RAN node in claim 32, wherein the activation message sequence number corresponds to a future message sequence number greater than a next message sequence number.
PRIORITY APPLICATION
[0001] This application claims priority from U.S. provisional patent application No. 60/333,485, filed on Nov. 28, 2001, the disclosure of which is incorporated herein by reference.
Provisional Applications (1)
|
Number |
Date |
Country |
|
60333485 |
Nov 2001 |
US |