CN101400059B

Cipher key updating method and device under active state

Abstract

The invention discloses a secret key updating method under active state comprising following steps: user terminal under active state or network side starts a secret key updating when satisfying preset condition; the network side and user terminal update secret key and consult start time of new secret key. The invention also discloses a secret key updating device under active state. The user terminal and network side actively starts secret key updating procedure, and solves problem of secret key updating of session under active state.

CN101400059B, drawing sheet 1
Sheet 1 of 7

Term

1 yearleft in the term

Expires 28 September 2027.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

12 claims: 3 independent, 9 dependent

  1. 1
    A key update method in an active state is characterized by including the following steps:a user terminal in an active state or a network side initiates a key update process when a preset condition is met;a network side mobility management entity MME Notify the network-side evolved base station eNB of the new key K generated in the key update procedureeNBThen, the network-side eNB according to the new key KeNBThe air interface key is updated, and the network-side eNB and the user terminal negotiate the activation time of the air interface key. 1. 一种激活active状态下的密钥更新方法,其特征在于,包括以下步骤: 处于active状态下的用户终端或网络侧在满足预设条件时,发起密钥更新流程; 网络侧移动性管理实体MME通知网络侧演进基站eNB所述密钥更新流程中所产生的新 密钥KeNB后, 所述网络侧eNB根据所述新密钥KeNB更新空口密钥,并且所述网络侧eNB和用户终端 协商所述空口密钥的启动时间。
  2. 10
    A user terminal, which is used for key update in an active state, is characterized by comprising:a terminal key update detection unit, which is used to determine whether a key update process needs to be initiated according to a preset condition;a terminal key update unit, When the terminal key update detection unit determines that a key update is required, send a key update request message to the network side, and then the network side mobility management entity MME notifies the network side evolution base station eNB of the key update process After the new key «"B generated in the eNB, negotiate with the eNB that the eNB uses the new key KeNBStart time of the updated air interface key. 10. 一种用户终端,用于在active状态下进行密钥更新,其特征在于,包括: 终端密钥更新检测单元,用于根据预设条件判断是否需要发起密钥更新流程; 终端密钥更新单元,用于在所述终端密钥更新检测单元判断为需要进行密钥更新时, 向网络侧发送密钥更新请求消息,进而在网络侧移动管理实体MME通知网络侧演进基站 eNB所述密钥更新流程中所产生的新密钥《“Β后,与所述eNB协商所述eNB根据所述新密钥 KeNB更新的空口密钥的启动时间。
  3. 12
    A network-side mobility management entity MME, which is used to update keys in an active state, is characterized by comprising:a key update initiation unit, which is used to perform system switching or discover K at a user terminalAIf sme has not been updated for a long time, the key update process is initiated;the key update unit is used to update the new key K generated in the key update processeNBThe context modification information is sent to the evolved base station eNB, so that the eNB according to the new key KeNBUpdating the air interface key and negotiating the activation time of the air interface key with the user terminal. 12. 一种网络侧移动管理实体MME,用于在active状态下进行密钥更新,其特征在于, 包括: 密钥更新发起单元,用于在用户终端进行系统切换或者发现KAsme长时间没有更新,则 发起密钥更新流程; 密钥更新单元,用于将所述密钥更新流程中产生的新密钥KeNB通过上下文修改信息发 送给演进基站eNB,以使得所述eNB根据所述新密钥KeNB更新空口密钥并和所述用户终端协 商所述空口密钥的启动时间。