Secure tunnel establishment upon attachment or handover to an access network
DCFirst Claim
1. A method for establishing a secure tunnel to a trusted packet data gateway upon a mobile node initially attaching to or performing a handover to a target access network, the method comprising:
- determining from a reachability list maintained in the mobile node at least one trusted packet data gateway that is reachable through the target access network, wherein the reachability list lists data sets indicating data paths and the reachability status of respective known trusted packet data gateways for each respective data path, andestablishing a secure tunnel to the trusted packet data gateway determined from the reachability list maintained in the mobile node, the secure tunnel is established prior to the attachment to the target access network.
3 Assignments
Litigations
0 Petitions
Accused Products
Abstract
The invention relates to a method, mobile node and computer-readable medium for establishing (or pre-establishing) a secure tunnel to an ePDG to prepare for a mobile node attachment or handover to another access network. To reduce the delay of a handover or upon attachment of a mobile node to an access network implied by mechanisms to discover a ePDG, the mobile node maintains a reachability list that can be consulted to identify an ePDG or ePDGs that are reachable in the target access network, i.e. to which the mobile node may establish a secure tunnel. If the mobile node can identify a reachable ePDG for a given access network from the reachability list, the mobile node (pre-)establishes a secure tunnel to the ePDG upon attaching to the given access network. In alternative solutions DNS, DHCP or other mechanism can be used to provide the mobile node with information on ePDGs in its vicinity.
-
Citations
26 Claims
-
1. A method for establishing a secure tunnel to a trusted packet data gateway upon a mobile node initially attaching to or performing a handover to a target access network, the method comprising:
-
determining from a reachability list maintained in the mobile node at least one trusted packet data gateway that is reachable through the target access network, wherein the reachability list lists data sets indicating data paths and the reachability status of respective known trusted packet data gateways for each respective data path, and establishing a secure tunnel to the trusted packet data gateway determined from the reachability list maintained in the mobile node, the secure tunnel is established prior to the attachment to the target access network. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15)
-
-
16. A method for establishing a secure tunnel to a trusted packet data gateway, the method comprising the steps:
-
establishing a secure tunnel to the trusted packet data gateway through a source access gateway and via a packet data network gateway prior to handover to a target access network, checking prior to attachment to the target access network whether the trusted packet data gateway can be reached through the target access network by checking reachability status of the trusted packet data gateway through the target access network based on a reachability list maintained by the mobile node, wherein the reachability list lists data sets indicating data paths and the reachability status of respective known trusted packet data gateways for each respective data path, and requesting via the source access network the core network node of a core network connected to the source access network to maintain the connection to the trusted packet data gateway via the packet data network gateway upon the mobile node attaching to the target access network. - View Dependent Claims (17, 18, 19, 20, 21, 22, 23, 24)
-
-
25. A mobile node comprising:
-
a processing unit configured to determine from a reachability list maintained in the mobile node at least one trusted packet data gateway that is reachable through the target access network, wherein the reachability list lists data sets indicating data paths and the reachability status of respective known trusted packet data gateways for each respective data path, and a communication unit configured to establish a secure tunnel to the trusted packet data gateway, determined from the reachability list maintained in the mobile node, wherein the secure tunnel is established prior to the attachment to the target access network.
-
-
26. A mobile node comprising:
-
a communication unit configured to establish a secure tunnel to the trusted packet data gateway through a source access gateway and via a packet data network gateway prior to handover to a target access network, and a processing unit configured to check prior to attachment to the target access network whether the trusted packet data gateway can be reached through the target access network by checking reachability status of the trusted packet data gateway through the target access network based on a reachability list maintained by the mobile node, wherein the reachability list lists data sets indicating data paths and the reachability status of respective known trusted packet data gateways for each respective data path, wherein the communication unit is configured to request via the source access network the core network node of a core network connected to the source access network to maintain the connection to the trusted packet data gateway via the packet data network gateway upon the mobile node attaching to the target access network.
-
Specification