TWI708513B - 網路安全架構 - Google Patents

網路安全架構 Download PDF

Info

Publication number
TWI708513B
TWI708513B TW105118428A TW105118428A TWI708513B TW I708513 B TWI708513 B TW I708513B TW 105118428 A TW105118428 A TW 105118428A TW 105118428 A TW105118428 A TW 105118428A TW I708513 B TWI708513 B TW I708513B
Authority
TW
Taiwan
Prior art keywords
network
client device
key
packet
iotf
Prior art date
Application number
TW105118428A
Other languages
English (en)
Chinese (zh)
Other versions
TW201703556A (zh
Inventor
李秀凡
霍恩蓋文伯納德
帕拉尼古德艾納德
Original Assignee
美商高通公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 美商高通公司 filed Critical 美商高通公司
Publication of TW201703556A publication Critical patent/TW201703556A/zh
Application granted granted Critical
Publication of TWI708513B publication Critical patent/TWI708513B/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/062Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/12Applying verification of the received information
    • H04L63/123Applying verification of the received information received data contents, e.g. message integrity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/10Integrity
    • H04W12/106Packet or message integrity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/70Services for machine-to-machine communication [M2M] or machine type communication [MTC]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2463/00Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
    • H04L2463/061Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying further key derivation, e.g. deriving traffic keys from a pair-wise master key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/02Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/10Integrity

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
TW105118428A 2015-07-12 2016-06-13 網路安全架構 TWI708513B (zh)

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
US201562191459P 2015-07-12 2015-07-12
US62/191,459 2015-07-12
US15/160,326 US10362011B2 (en) 2015-07-12 2016-05-20 Network security architecture
US15/160,326 2016-05-20

Publications (2)

Publication Number Publication Date
TW201703556A TW201703556A (zh) 2017-01-16
TWI708513B true TWI708513B (zh) 2020-10-21

Family

ID=57731536

Family Applications (1)

Application Number Title Priority Date Filing Date
TW105118428A TWI708513B (zh) 2015-07-12 2016-06-13 網路安全架構

Country Status (8)

Country Link
US (4) US10362011B2 (enExample)
EP (2) EP3905744B1 (enExample)
JP (2) JP6882255B2 (enExample)
KR (1) KR102447299B1 (enExample)
CN (2) CN113329006B (enExample)
BR (1) BR112018000644A2 (enExample)
TW (1) TWI708513B (enExample)
WO (1) WO2017011114A1 (enExample)

Families Citing this family (52)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10505850B2 (en) 2015-02-24 2019-12-10 Qualcomm Incorporated Efficient policy enforcement using network tokens for services—user-plane approach
US10362011B2 (en) 2015-07-12 2019-07-23 Qualcomm Incorporated Network security architecture
TWI562661B (en) * 2015-08-27 2016-12-11 Ind Tech Res Inst Cell and method and system for bandwidth management of backhaul network of cell
CN106961722B (zh) * 2016-01-12 2018-09-11 展讯通信(上海)有限公司 数据的传输方法及基站
CN107666667B (zh) * 2016-07-29 2019-09-17 电信科学技术研究院 一种数据传输方法、第一设备及第二设备
EP3501234A4 (en) * 2016-08-22 2020-04-01 Nokia Technologies Oy SECURITY PROCEDURE
US20180097807A1 (en) * 2016-09-30 2018-04-05 Lg Electronics Inc. Method and apparatus for performing initial access procedure based on authentication in wireless communication system
CN109891830B (zh) * 2016-11-04 2021-04-09 华为技术有限公司 一种功能调度方法、设备和系统
CN108347416B (zh) 2017-01-24 2021-06-29 华为技术有限公司 一种安全保护协商方法及网元
EP3571807B1 (en) * 2017-01-27 2021-09-22 Samsung Electronics Co., Ltd. Method for providing end-to-end security over signaling plane in mission critical data communication system
RU2761445C2 (ru) 2017-01-30 2021-12-08 Телефонактиеболагет Лм Эрикссон (Пабл) Способы для защиты целостности данных пользовательской плоскости
PL3596953T3 (pl) 2017-03-17 2023-10-09 Telefonaktiebolaget Lm Ericsson (Publ) Rozwiązanie dotyczące bezpieczeństwa włączania i wyłączania zabezpieczeń dla danych up pomiędzy ue a ran w 5g
DE102017208735A1 (de) * 2017-05-23 2018-11-29 Siemens Aktiengesellschaft Verfahren und Vorrichtung zum Schutz einer Kommunikation zwischen mindestens einer ersten Kommunikationseinrichtung und wenigstens einer zweiten Kommunikationseinrichtung insbesondere innerhalb eines Kommunikationsnetzwerkes einer industriellen Fertigung und/oder Automatisierung
CN110896683A (zh) * 2017-06-01 2020-03-20 华为国际有限公司 数据保护方法、装置以及系统
US10470042B2 (en) * 2017-07-27 2019-11-05 Nokia Technologies Oy Secure short message service over non-access stratum
US20190045412A1 (en) * 2017-08-02 2019-02-07 Sears Brands, L.L.C. Automatically switching communication pathways between connected devices
US20190089592A1 (en) * 2017-09-20 2019-03-21 Quanta Computer Inc. Role-based automatic configuration system and method for ethernet switches
CN111183663B (zh) 2017-11-08 2025-10-10 Oppo广东移动通信有限公司 完整性保护的控制方法、网络设备及计算机存储介质
US10771450B2 (en) * 2018-01-12 2020-09-08 Blackberry Limited Method and system for securely provisioning a remote device
AU2019249939B2 (en) 2018-04-06 2021-09-30 Telefonaktiebolaget Lm Ericsson (Publ) UE controlled handling of the security policy for user plane protection in 5G systems
CN108833340A (zh) * 2018-04-26 2018-11-16 浙江麦知网络科技有限公司 一种室内网络通信安全保护系统
EP3565191B1 (en) 2018-04-30 2021-07-07 Hewlett Packard Enterprise Development LP Provisioning and managing internet-of-thing devices over a network
US20220038433A1 (en) * 2018-09-21 2022-02-03 Nokia Technologies Oy Method and apparatus for secure messaging between network functions
CH715441B1 (de) * 2018-10-09 2024-08-15 Legic Identsystems Ag Verfahren und Vorrichtungen zum Kommunizieren zwischen einer Internet-der-Dinge-Vorrichtung und einem entfernten Computersystem.
WO2020099148A1 (en) * 2018-11-12 2020-05-22 Telefonaktiebolaget Lm Ericsson (Publ) Authentication of a communications device
EP3607715B1 (en) 2018-11-14 2021-07-14 Telefonaktiebolaget LM Ericsson (publ) NF SERVICE CONSUMER RESTART DETECTION USING DIRECT SIGNALING BETWEEN NFs
EP3788773B1 (en) 2019-04-08 2021-06-23 Telefonaktiebolaget Lm Ericsson (Publ) Systems and methods for handling telescopic fqdns
US11533613B2 (en) * 2019-08-16 2022-12-20 Qualcomm Incorporated Providing secure communications between computing devices
WO2021060855A1 (ko) * 2019-09-24 2021-04-01 프라이빗테크놀로지 주식회사 제어 데이터 패킷을 보호하기 위한 시스템 및 그에 관한 방법
US12166759B2 (en) 2019-09-24 2024-12-10 Pribit Technology, Inc. System for remote execution code-based node control flow management, and method therefor
US20220255906A1 (en) * 2019-09-24 2022-08-11 Pribit Technology, Inc. System For Protecting Control Data Packet And Method Pertaining To Same
US11271777B2 (en) 2019-09-24 2022-03-08 Pribit Technology, Inc. System for controlling network access of terminal based on tunnel and method thereof
JP7395211B2 (ja) 2019-09-24 2023-12-11 プライビット テクノロジー インク 端末のネットワーク接続を認証及び制御するためのシステム及びそれに関する方法
US11190494B2 (en) 2019-09-24 2021-11-30 Pribit Technology, Inc. Application whitelist using a controlled node flow
US12381890B2 (en) 2019-09-24 2025-08-05 Pribit Technology, Inc. System and method for secure network access of terminal
KR102119257B1 (ko) * 2019-09-24 2020-06-26 프라이빗테크놀로지 주식회사 터널에 기반하여 단말의 네트워크 접속을 제어하기 위한 시스템 및 그에 관한 방법
US11381557B2 (en) 2019-09-24 2022-07-05 Pribit Technology, Inc. Secure data transmission using a controlled node flow
US11652801B2 (en) 2019-09-24 2023-05-16 Pribit Technology, Inc. Network access control system and method therefor
US11082256B2 (en) 2019-09-24 2021-08-03 Pribit Technology, Inc. System for controlling network access of terminal based on tunnel and method thereof
US12348494B2 (en) 2019-09-24 2025-07-01 Pribit Technology, Inc. Network access control system and method therefor
US12126994B2 (en) 2019-10-04 2024-10-22 Qualcomm Incorporated User plane integrity protection (UP IP) capability signaling in 5G/4G systems
TWI754950B (zh) * 2020-06-02 2022-02-11 鴻海精密工業股份有限公司 物聯網設備、伺服器及軟體更新方法
CN112188447B (zh) * 2020-08-26 2021-09-14 江苏龙睿物联网科技有限公司 一种物联网移动基站通信保护系统及保护方法
WO2022172698A1 (ja) * 2021-02-09 2022-08-18 ソニーセミコンダクタソリューションズ株式会社 情報処理装置、移動体装置、および通信システム
US20220353263A1 (en) * 2021-04-28 2022-11-03 Verizon Patent And Licensing Inc. Systems and methods for securing network function subscribe notification process
US11902260B2 (en) * 2021-08-02 2024-02-13 Cisco Technology, Inc. Securing control/user plane traffic
US11570180B1 (en) * 2021-12-23 2023-01-31 Eque Corporation Systems configured for validation with a dynamic cryptographic code and methods thereof
US11928039B1 (en) * 2022-11-01 2024-03-12 Micron Technologies, Inc. Data-transfer test mode
US20240275540A1 (en) * 2023-02-13 2024-08-15 Apple Inc. Signaling-less Data Transfer
TWI884122B (zh) * 2023-12-18 2025-05-11 慧榮科技股份有限公司 寫入和恢復受保護資料的方法及電腦程式產品及裝置
TWI874051B (zh) * 2023-12-18 2025-02-21 慧榮科技股份有限公司 寫入和恢復受保護資料的方法及電腦程式產品及裝置
WO2025192938A1 (en) * 2024-03-14 2025-09-18 Samsung Electronics Co., Ltd. Method and apparatus for radio access network

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2013006219A1 (en) * 2011-07-01 2013-01-10 Intel Corporation Small data communications in a wireless communication network
KR20130037481A (ko) * 2011-10-06 2013-04-16 주식회사 케이티 통신망, 개체 및 트리거링 제어 방법
WO2013065996A1 (ko) * 2011-11-03 2013-05-10 주식회사 케이티 기계 형태 통신 단말의 트리거링을 위한 서버 및 방법

Family Cites Families (32)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2002096151A1 (en) 2001-05-22 2002-11-28 Flarion Technologies, Inc. Authentication system for mobile entities
US8832449B2 (en) * 2006-03-22 2014-09-09 Lg Electronics Inc. Security considerations for the LTE of UMTS
US20080181411A1 (en) 2007-01-26 2008-07-31 Karl Norrman Method and system for protecting signaling information
US8855138B2 (en) * 2008-08-25 2014-10-07 Qualcomm Incorporated Relay architecture framework
CN102090093B (zh) 2009-04-30 2013-04-17 华为技术有限公司 空口链路安全机制建立的方法、设备
CN102036256B (zh) * 2009-09-28 2013-03-20 华为技术有限公司 数据传输方法、装置及系统
US8477724B2 (en) 2010-01-11 2013-07-02 Research In Motion Limited System and method for enabling session context continuity of local service availability in local cellular coverage
US9021072B2 (en) * 2010-01-28 2015-04-28 Verizon Patent And Licensing Inc. Localized media offload
GB201008633D0 (en) * 2010-05-24 2010-07-07 Gigle Networks Iberia Sl Communications apparatus
TW201624961A (zh) 2010-11-15 2016-07-01 內數位專利控股公司 憑症驗證及頻道耦合
WO2012154325A1 (en) * 2011-04-01 2012-11-15 Interdigital Patent Holdings, Inc. Method and apparatus for controlling connectivity to a network
US20120252481A1 (en) * 2011-04-01 2012-10-04 Cisco Technology, Inc. Machine to machine communication in a communication network
US20140126448A1 (en) 2011-06-22 2014-05-08 Nec Europe Ltd. Energy awareness in mobile communication user equipment and networks, including optimizations based on state compression
US20130046821A1 (en) * 2011-08-15 2013-02-21 Renasas Mobile Corporation Advanced Machine-To-Machine Communications
KR101935785B1 (ko) 2011-08-16 2019-04-03 삼성전자 주식회사 무선통신시스템에서 멀티미디어 방송 서비스를 수신하는 방법 및 장치
CN103002428B (zh) * 2011-09-15 2016-08-03 华为技术有限公司 一种物联网终端网络附着的方法及系统
BR112014007959A2 (pt) * 2011-10-03 2017-06-13 Intel Corp mecanismos para comunicação de dispositivo para dispositivo
KR102095405B1 (ko) * 2012-05-10 2020-03-31 삼성전자주식회사 데이터 패킷들의 업링크 및 다운링크 동안 비연결형 전송을 위한 방법 및 시스템
EP2693800A1 (en) * 2012-08-03 2014-02-05 Panasonic Corporation Radio Resource Managment for Dual Priority Access
CN103686708B (zh) 2012-09-13 2018-01-19 电信科学技术研究院 一种密钥隔离方法及设备
JPWO2014084383A1 (ja) 2012-11-30 2017-01-05 シャープ株式会社 基地局装置、端末装置、通信システム、送信方法、受信方法、通信方法および集積回路
EP2944108B1 (en) 2013-01-11 2020-03-04 LG Electronics Inc. Method and apparatus for applying security information in wireless communication system
GB201306350D0 (en) 2013-04-08 2013-05-22 Gen Dynamics Broadband Inc Apparatus and methods for key generation
CN105103606B (zh) * 2013-05-09 2018-12-11 英特尔Ip公司 缓冲器溢出的减少
CN104620660B (zh) * 2013-08-02 2019-04-12 华为技术有限公司 空闲状态随机接入方法及设备
IN2013MU02890A (enExample) * 2013-09-05 2015-07-03 Tata Consultancy Services Ltd
US9497673B2 (en) * 2013-11-01 2016-11-15 Blackberry Limited Method and apparatus to enable multiple wireless connections
JP2016540441A (ja) * 2013-12-06 2016-12-22 アイディーエーシー ホールディングス インコーポレイテッド 無線システムにおける階層化された接続性
CN104540107A (zh) * 2014-12-03 2015-04-22 东莞宇龙通信科技有限公司 Mtc终端群组的管理方法、管理系统和网络侧设备
WO2016162502A1 (en) 2015-04-08 2016-10-13 Telefonaktiebolaget Lm Ericsson (Publ) Method, apparatus, and system for providing encryption or integrity protection in a wireless network
EP3286935B1 (en) * 2015-04-22 2021-03-17 Convida Wireless, LLC Small data usage enablement in 3gpp networks
US10362011B2 (en) 2015-07-12 2019-07-23 Qualcomm Incorporated Network security architecture

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2013006219A1 (en) * 2011-07-01 2013-01-10 Intel Corporation Small data communications in a wireless communication network
KR20130037481A (ko) * 2011-10-06 2013-04-16 주식회사 케이티 통신망, 개체 및 트리거링 제어 방법
WO2013065996A1 (ko) * 2011-11-03 2013-05-10 주식회사 케이티 기계 형태 통신 단말의 트리거링을 위한 서버 및 방법

Also Published As

Publication number Publication date
US20190306140A1 (en) 2019-10-03
EP3905744B1 (en) 2025-11-12
US10362011B2 (en) 2019-07-23
JP6882255B2 (ja) 2021-06-02
WO2017011114A1 (en) 2017-01-19
CN107736047A (zh) 2018-02-23
US20170012956A1 (en) 2017-01-12
US12010107B2 (en) 2024-06-11
EP3320707B1 (en) 2021-11-17
US20220263812A1 (en) 2022-08-18
KR102447299B1 (ko) 2022-09-23
US20190306141A1 (en) 2019-10-03
CN113329006A (zh) 2021-08-31
EP3905744A1 (en) 2021-11-03
JP2018528647A (ja) 2018-09-27
BR112018000644A2 (pt) 2018-09-18
CN113329006B (zh) 2023-05-26
JP2021145342A (ja) 2021-09-24
US11329969B2 (en) 2022-05-10
JP7246430B2 (ja) 2023-03-27
CN107736047B (zh) 2021-06-08
EP3320707A1 (en) 2018-05-16
KR20180030023A (ko) 2018-03-21
TW201703556A (zh) 2017-01-16

Similar Documents

Publication Publication Date Title
US12010107B2 (en) Network security architecture
US11716615B2 (en) Network architecture and security with simplified mobility procedure
US11172357B2 (en) Network architecture and security with encrypted client device contexts
TWI726890B (zh) 具有加密的網路可達性上下文的網路架構和安全

Legal Events

Date Code Title Description
MM4A Annulment or lapse of patent due to non-payment of fees