Patents by Inventor Ahmad Shawky Muhanna
Ahmad Shawky Muhanna has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12047781Abstract: A method and apparatus are provided for delivering user equipment (UE) new radio (NR) security capabilities and mobility management entity interworking. In the embodiments, adding the UE NR security capabilities in a new information element over a non-access stratum (NAS) is compatible with a legacy mobility management entity and eliminate any potential of bidding-down attack and is more advantageous and serves the security solution better. As long as the UE is connected to the long term evolution (LTE) and all UE security capabilities including LTE security capabilities have been replayed correctly and successfully in the NAS security mode command (SMC) message, the UE may not consider the absence of the UE NR security capabilities in the NAS SMC as a security vulnerability.Type: GrantFiled: February 28, 2022Date of Patent: July 23, 2024Assignee: HUAWEI TECHNOLOGIES CO., LTD.Inventors: Ahmad Shawky Muhanna, He Li, Mazin Ali Al-Shalash
-
Patent number: 11895498Abstract: Embodiments of this disclosure provide techniques for communicating in a wireless communication system. In particular, a user equipment (UE) may receiving a security command message from a base station comprising an indication of an integrity protection algorithm and an indication of an encryption algorithm. The first security command message may trigger a radio resource control (RRC) traffic signaling protection procedure between the UE and the base station. The UE transmits a security command complete message to the base station. The security command complete message may trigger a packet data unit (PDU) session establishment procedure to establish a PDU session between the UE and the base station.Type: GrantFiled: April 4, 2022Date of Patent: February 6, 2024Inventors: Ahmad Shawky Muhanna, Xin Zeng
-
Publication number: 20230353379Abstract: This disclosure provides techniques for securely communicating user equipment (UE) specific information from a UE to a network-side device. In particular, the UE may either encrypt the UE specific information using an encryption key to form an encrypted portion, where the UE specific information includes subscriber identity information and the encryption key is calculated in accordance with a public key of a home network of the UE. The UE generates a message authentication code (MAC) signature based on the encrypted portion and a first integrity key, where the first integrity key is calculated in accordance with the public key of the home network. The UE sends, to a network-side device, a request message including the encrypted portion, the MAC signature and a network identifier of the home network.Type: ApplicationFiled: July 7, 2023Publication date: November 2, 2023Applicant: Futurewei Technologies, Inc.Inventors: Ahmad Shawky Muhanna, Marcus Wong
-
Patent number: 11700131Abstract: Embodiments of this disclosure provide techniques for securely communicating an IMSI over the air from a UE to an SeAN, as well as for securely validating an unencrypted IMSI that the SeAN receives from the home network, during authentication protocols. In particular, the UE may either encrypt the IMSI assigned to the UE using an IMSI encryption key (KIMSIenc) or compute a hash of the IMSI assigned to the UE using an IMSI integrity key (KIMSIint), and then send the encrypted IMSI or the hash of the IMSI to the serving network. The encrypted IMSI or hash of the encrypted IMSI may then be used by the SeAN to validate an unencrypted IMSI that was previously received from an HSS in the home network of the UE.Type: GrantFiled: December 17, 2020Date of Patent: July 11, 2023Assignee: Futurewei Technologies, Inc.Inventors: Ahmad Shawky Muhanna, Marcus Wong
-
Patent number: 11418962Abstract: A method and apparatus are provided for delivering user equipment (UE) new radio (NR) security capabilities and mobility management entity interworking. In the embodiments, adding the UE NR security capabilities in a new information element over a non-access stratum (NAS) is compatible with a legacy mobility management entity and eliminate any potential of bidding-down attack and is more advantageous and serves the security solution better. As long as the UE is connected to the long term evolution (LTE) and all UE security capabilities including LTE security capabilities have been replayed correctly and successfully in the NAS security mode command (SMC) message, the UE may not consider the absence of the UE NR security capabilities in the NAS SMC as a security vulnerability.Type: GrantFiled: February 6, 2020Date of Patent: August 16, 2022Assignee: HUAWEI TECHNOLOGIES CO., LTD.Inventors: Ahmad Shawky Muhanna, He Li, Mazin Ali Al-Shalash
-
Publication number: 20220232384Abstract: Embodiments of this disclosure provide techniques for communicating in a wireless communication system. In particular, a user equipment (UE) may receiving a security command message from a base station comprising an indication of an integrity protection algorithm and an indication of an encryption algorithm. The first security command message may trigger a radio resource control (RRC) traffic signaling protection procedure between the UE and the base station. The UE transmits a security command complete message to the base station. The security command complete message may trigger a packet data unit (PDU) session establishment procedure to establish a PDU session between the UE and the base station.Type: ApplicationFiled: April 4, 2022Publication date: July 21, 2022Applicant: Futurewei Technologies, Inc.Inventors: Ahmad Shawky Muhanna, Xin Zeng
-
Publication number: 20220225100Abstract: Embodiments of this disclosure provide techniques for communicating in a wireless communication system. In particular, a user equipment (UE) may receiving a security command message from a base station comprising an indication of an integrity protection algorithm and an indication of an encryption algorithm. The first security command message may trigger a radio resource control (RRC) traffic signaling protection procedure between the UE and the base station. The UE transmits a security command complete message to the base station. The security command complete message may trigger a packet data unit (PDU) session establishment procedure to establish a PDU session between the UE and the base station.Type: ApplicationFiled: April 4, 2022Publication date: July 14, 2022Inventors: Ahmad Shawky Muhanna, Xin Zeng
-
Publication number: 20220191701Abstract: A method and apparatus are provided for delivering user equipment (UE) new radio (NR) security capabilities and mobility management entity interworking. In the embodiments, adding the UE NR security capabilities in a new information element over a non-access stratum (NAS) is compatible with a legacy mobility management entity and eliminate any potential of bidding-down attack and is more advantageous and serves the security solution better. As long as the UE is connected to the long term evolution (LTE) and all UE security capabilities including LTE security capabilities have been replayed correctly and successfully in the NAS security mode command (SMC) message, the UE may not consider the absence of the UE NR security capabilities in the NAS SMC as a security vulnerability.Type: ApplicationFiled: February 28, 2022Publication date: June 16, 2022Inventors: Ahmad Shawky Muhanna, He Li, Mazin Ali Al-Shalash
-
Patent number: 11297502Abstract: Embodiments of this disclosure provide techniques for communicating in a wireless communication system. In particular, a user equipment (UE) may receiving a security command message from a base station comprising an indication of an integrity protection algorithm and an indication of an encryption algorithm. The first security command message may trigger a radio resource control (RRC) traffic signaling protection procedure between the UE and the base station. The UE transmits a security command complete message to the base station. The security command complete message may trigger a packet data unit (PDU) session establishment procedure to establish a PDU session between the UE and the base station.Type: GrantFiled: September 4, 2018Date of Patent: April 5, 2022Assignee: FUTUREWEI TECHNOLOGIES, INC.Inventors: Ahmad Shawky Muhanna, Xin Zeng
-
Patent number: 11265723Abstract: A method and apparatus are provided for delivering user equipment (UE) new radio (NR) security capabilities and mobility management entity interworking. In the embodiments, adding the UE NR security capabilities in a new information element over a non-access stratum (NAS) is compatible with a legacy mobility management entity and eliminate any potential of bidding-down attack and is more advantageous and serves the security solution better. As long as the UE is connected to the long term evolution (LTE) and all UE security capabilities including LTE security capabilities have been replayed correctly and successfully in the NAS security mode command (SMC) message, the UE may not consider the absence of the UE NR security capabilities in the NAS SMC as a security vulnerability.Type: GrantFiled: February 6, 2020Date of Patent: March 1, 2022Assignee: Huawei Technologies Co., Ltd.Inventors: Ahmad Shawky Muhanna, He Li, Mazin Ali Al-Shalash
-
Publication number: 20210211296Abstract: Embodiments of this disclosure provide techniques for securely communicating an IMSI over the air from a UE to an SeAN, as well as for securely validating an unencrypted IMSI that the SeAN receives from the home network, during authentication protocols. In particular, the UE may either encrypt the IMSI assigned to the UE using an IMSI encryption key (KIMSIenc) or compute a hash of the IMSI assigned to the UE using an IMSI integrity key (KIMSIint), and then send the encrypted IMSI or the hash of the IMSI to the serving network. The encrypted IMSI or hash of the encrypted IMSI may then be used by the SeAN to validate an unencrypted IMSI that was previously received from an HSS in the home network of the UE.Type: ApplicationFiled: December 17, 2020Publication date: July 8, 2021Inventors: Ahmad Shawky Muhanna, Marcus Wong
-
Publication number: 20210135878Abstract: Embodiment mutual authentication and security agreement (MASA) protocols may use independently generated integrity and/or encryption keys to securely communicate private information exchanged between UEs and various network-side devices (e.g., base stations, MMEs, HSSs, etc.). In particular, embodiment MASA protocols may use an initial authentication request (IAR) encryption key (KIARENC) to encrypt UE specific information (e.g., an IMSI, etc.) in an IAR message and/or an initial authentication response (IAS) encryption key (KIASENC) to encrypt private information in an IAS message. Additionally, embodiment MASA protocols may use an IAR integrity protection key (KIARINT) to verify the integrity of information in an IAR message and/or an IAS integrity protection key (KIASINT) to verify the integrity of information in an IAS message. The KIARENC, KIARINT, KIASENC, and/or KIASINT may be independently computed by the UE and a home subscriber server (HSS).Type: ApplicationFiled: January 11, 2021Publication date: May 6, 2021Inventors: Ahmad Shawky Muhanna, Marcus Wong
-
Patent number: 10887295Abstract: It is possible to reduce singling overhead in a radio access network by coordinating authentication of a group of UEs (e.g., IoT devices, etc.) via a master device. In particular, the master device may aggregate UE identifiers (UE_IDs) for UEs in the group, and send an identity message carrying the UE_IDs and a master device identifier (MD_ID) to a base station, which may then relay the identity message to a Security Anchor Node (SeAN). The SeAN may send an authentication data request carrying the UE_IDs and MD_ID to a Home Subscriber Server (HSS), which may return an authentication data response that includes a group authentication information. The group authentication information may then be used to achieve mutual authentication between the SeAN and each of the master device, group of UEs, and individual UEs.Type: GrantFiled: September 29, 2017Date of Patent: January 5, 2021Assignee: Futurewei Technologies, Inc.Inventors: Ahmad Shawky Muhanna, Xiang Xie
-
Patent number: 10873464Abstract: Embodiments of this disclosure provide techniques for securely communicating an IMSI over the air from a UE to an SeAN, as well as for securely validating an unencrypted IMSI that the SeAN receives from the home network, during authentication protocols. In particular, the UE may either encrypt the IMSI assigned to the UE using an IMSI encryption key (KIMSIenc) or compute a hash of the IMSI assigned to the UE using an IMSI integrity key (KIMSIint), and then send the encrypted IMSI or the hash of the IMSI to the serving network. The encrypted IMSI or hash of the encrypted IMSI may then be used by the SeAN to validate an unencrypted IMSI that was previously received from an HSS in the home network of the UE.Type: GrantFiled: August 7, 2017Date of Patent: December 22, 2020Assignee: Futurewei Technologies, Inc.Inventors: Ahmad Shawky Muhanna, Marcus Wong
-
Publication number: 20200178068Abstract: A method and apparatus are provided for delivering user equipment (UE) new radio (NR) security capabilities and mobility management entity interworking. In the embodiments, adding the UE NR security capabilities in a new information element over a non-access stratum (NAS) is compatible with a legacy mobility management entity and eliminate any potential of bidding-down attack and is more advantageous and serves the security solution better. As long as the UE is connected to the long term evolution (LTE) and all UE security capabilities including LTE security capabilities have been replayed correctly and successfully in the NAS security mode command (SMC) message, the UE may not consider the absence of the UE NR security capabilities in the NAS SMC as a security vulnerability.Type: ApplicationFiled: February 6, 2020Publication date: June 4, 2020Inventors: Ahmad Shawky Muhanna, He Li, Mazin Ali Al-Shalash
-
Publication number: 20190288851Abstract: Embodiment mutual authentication and security agreement (MASA) protocols may use independently generated integrity and/or encryption keys to securely communicate private information exchanged between UEs and various network-side devices (e.g., base stations, MMEs, HSSs, etc.). In particular, embodiment MASA protocols may use an initial authentication request (IAR) encryption key (KIARENC) to encrypt UE specific information (e.g., an IMSI, etc.) in an IAR message and/or an initial authentication response (IAS) encryption key (KIASENC) to encrypt private information in an IAS message. Additionally, embodiment MASA protocols may use an IAR integrity protection key (KIARINT) to verify the integrity of information in an IAR message and/or an IAS integrity protection key (KIASINT) to verify the integrity of information in an IAS message. The KIARENC, KIARINT, KIASENC, and/or KIASINT may be independently computed by the UE and a home subscriber server (HSS).Type: ApplicationFiled: June 6, 2019Publication date: September 19, 2019Inventors: Ahmad Shawky Muhanna, Marcus Wong
-
Patent number: 10412056Abstract: A method for establishing a trust relationship in an ultra dense network is provided. The method comprises receiving, by a user equipment (UE), a reconfiguration request from a macrocell; deriving, by the UE, a user plane encryption key according to information in the reconfiguration request; transmitting, by the UE, a first user plane signaling message to a first microcell in a group of microcells when the UE is attached to the first microcell; and transmitting, by the UE, a second user plane signaling message to a second microcell in the group of microcells when the UE is attached to the second microcell, wherein the first user plane signaling message and the second user plane signaling message are both encrypted according to the user plane encryption key.Type: GrantFiled: July 18, 2016Date of Patent: September 10, 2019Assignee: Futurewei Technologies, Inc.Inventors: Ahmad Shawky Muhanna, Zhibi Wang, Jiangsheng Wang
-
Patent number: 10382206Abstract: Embodiment mutual authentication and security agreement (MASA) protocols may use independently generated integrity and/or encryption keys to securely communicate private information exchanged between UEs and various network-side devices (e.g., base stations, MMEs, HSSs, etc.). In particular, embodiment MASA protocols may use an initial authentication request (IAR) encryption key (KIARENC) to encrypt UE specific information (e.g., an IMSI, etc.) in an IAR message and/or an initial authentication response (IAS) encryption key (KIASENC) to encrypt private information in an IAS message. Additionally, embodiment MASA protocols may use an IAR integrity protection key (KIARINT) to verify the integrity of information in an IAR message and/or an IAS integrity protection key (KIASINT) to verify the integrity of information in an IAS message. The KIARENC, KIARINT, KIASENC, and/or KIASINT may be independently computed by the UE and a home subscriber server (HSS).Type: GrantFiled: March 8, 2017Date of Patent: August 13, 2019Assignee: Futurewei Technologies, Inc.Inventors: Ahmad Shawky Muhanna, Marcus Wong
-
Patent number: 10375031Abstract: A method for establishing a trust relationship in an ultra dense network is provided. The method comprises receiving, by a user equipment (UE), a reconfiguration request from a macrocell; deriving, by the UE, a user plane encryption key according to information in the reconfiguration request; transmitting, by the UE, a first user plane signaling message to a first microcell in a group of microcells when the UE is attached to the first microcell; and transmitting, by the UE, a second user plane signaling message to a second microcell in the group of microcells when the UE is attached to the second microcell, wherein the first user plane signaling message and the second user plane signaling message are both encrypted according to the user plane encryption key.Type: GrantFiled: July 18, 2016Date of Patent: August 6, 2019Assignee: Futurewei Technologies, Inc.Inventors: Ahmad Shawky Muhanna, Zhibi Wang, Jiangsheng Wang
-
Publication number: 20190082325Abstract: Embodiments of this disclosure provide techniques for communicating in a wireless communication system. In particular, a user equipment (UE) may receiving a security command message from a base station comprising an indication of an integrity protection algorithm and an indication of an encryption algorithm. The first security command message may trigger a radio resource control (RRC) traffic signaling protection procedure between the UE and the base station. The UE transmits a security command complete message to the base station. The security command complete message may trigger a packet data unit (PDU) session establishment procedure to establish a PDU session between the UE and the base station.Type: ApplicationFiled: September 4, 2018Publication date: March 14, 2019Inventors: Ahmad Shawky Muhanna, Xin Zeng