US 12,219,055 B2
Method, device, and system for deriving keys
Aiqin Zhang, Shanghai (CN); Jing Chen, Shenzhen (CN); and Xiaoyu Bi, Beijing (CN)
Assigned to HUAWEI TECHNOLOGIES CO., LTD., Shenzhen (CN)
Filed by HUAWEI TECHNOLOGIES CO., LTD., Guangdong (CN)
Filed on Jan. 24, 2022, as Appl. No. 17/583,013.
Application 17/583,013 is a continuation of application No. 13/323,840, filed on Dec. 13, 2011, granted, now 11,240,019.
Application 13/323,840 is a continuation of application No. PCT/CN2010/074559, filed on Jun. 26, 2010.
Claims priority of application No. 200910148423.7 (CN), filed on Jun. 26, 2009.
Prior Publication US 2022/0150062 A1, May 12, 2022
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 9/08 (2006.01); H04L 9/40 (2022.01); H04W 12/041 (2021.01); H04W 36/00 (2009.01); H04W 88/14 (2009.01)
CPC H04L 9/0869 (2013.01) [H04L 63/06 (2013.01); H04W 12/041 (2021.01); H04L 2209/80 (2013.01); H04L 2463/061 (2013.01); H04W 36/0011 (2013.01); H04W 88/14 (2013.01)] 28 Claims
OG exemplary drawing
 
1. A communication system, comprising:
a base station of a source network; and
a mobility management entity of the source network, wherein:
the base station is configured to send, in a first handover process from the source network to a target network, a handover required message to the mobility management entity; and
the mobility management entity is configured to:
receive the handover required message from the base station;
obtain a first non-access stratum (NAS) downlink count value in the first handover process;
derive, according to a key derivation function (KDF), a root key, the first NAS downlink count value, and a first key comprising a ciphering key and an integrity key;
send at least a portion of the first NAS downlink count value to a user equipment in the first handover process;
after deriving the first key, obtain, in the first handover process, a second NAS downlink count value by incrementing a value to the first NAS downlink count value, wherein the second NAS downlink count value is obtained in the absence of the mobility management entity sending a NAS message; and
after the first handover process fails, derive a second key in a second handover process according to the KDF, the root key, and the second NAS downlink count value.