Cipher key updating method and device under active state
Abstract
The invention discloses a secret key updating method under active state comprising following steps: user terminal under active state or network side starts a secret key updating when satisfying preset condition; the network side and user terminal update secret key and consult start time of new secret key. The invention also discloses a secret key updating device under active state. The user terminal and network side actively starts secret key updating procedure, and solves problem of secret key updating of session under active state.

Term
1 yearleft in the term
Expires 28 September 2027.
- Priority and filed
- Granted
- Today
- Expires
12 claims: 3 independent, 9 dependent
- 1A key update method in an active state is characterized by including the following steps:a user terminal in an active state or a network side initiates a key update process when a preset condition is met;a network side mobility management entity MME Notify the network-side evolved base station eNB of the new key K generated in the key update procedureeNBThen, the network-side eNB according to the new key KeNBThe air interface key is updated, and the network-side eNB and the user terminal negotiate the activation time of the air interface key. 1. 一种激活active状态下的密钥更新方法,其特征在于,包括以下步骤: 处于active状态下的用户终端或网络侧在满足预设条件时,发起密钥更新流程; 网络侧移动性管理实体MME通知网络侧演进基站eNB所述密钥更新流程中所产生的新 密钥KeNB后, 所述网络侧eNB根据所述新密钥KeNB更新空口密钥,并且所述网络侧eNB和用户终端 协商所述空口密钥的启动时间。
- 10A user terminal, which is used for key update in an active state, is characterized by comprising:a terminal key update detection unit, which is used to determine whether a key update process needs to be initiated according to a preset condition;a terminal key update unit, When the terminal key update detection unit determines that a key update is required, send a key update request message to the network side, and then the network side mobility management entity MME notifies the network side evolution base station eNB of the key update process After the new key «"B generated in the eNB, negotiate with the eNB that the eNB uses the new key KeNBStart time of the updated air interface key. 10. 一种用户终端,用于在active状态下进行密钥更新,其特征在于,包括: 终端密钥更新检测单元,用于根据预设条件判断是否需要发起密钥更新流程; 终端密钥更新单元,用于在所述终端密钥更新检测单元判断为需要进行密钥更新时, 向网络侧发送密钥更新请求消息,进而在网络侧移动管理实体MME通知网络侧演进基站 eNB所述密钥更新流程中所产生的新密钥《“Β后,与所述eNB协商所述eNB根据所述新密钥 KeNB更新的空口密钥的启动时间。
- 12A network-side mobility management entity MME, which is used to update keys in an active state, is characterized by comprising:a key update initiation unit, which is used to perform system switching or discover K at a user terminalAIf sme has not been updated for a long time, the key update process is initiated;the key update unit is used to update the new key K generated in the key update processeNBThe context modification information is sent to the evolved base station eNB, so that the eNB according to the new key KeNBUpdating the air interface key and negotiating the activation time of the air interface key with the user terminal. 12. 一种网络侧移动管理实体MME,用于在active状态下进行密钥更新,其特征在于, 包括: 密钥更新发起单元,用于在用户终端进行系统切换或者发现KAsme长时间没有更新,则 发起密钥更新流程; 密钥更新单元,用于将所述密钥更新流程中产生的新密钥KeNB通过上下文修改信息发 送给演进基站eNB,以使得所述eNB根据所述新密钥KeNB更新空口密钥并和所述用户终端协 商所述空口密钥的启动时间。
Independent claims3
140 paragraphs, as filed
-A kind of key update method and equipment technical field in act i ve state
[0001] The present invention relates to the field of communication technology, and in particular to a method and device for updating a key in an active state.
Background technique
[0002] In order to ensure the future 3GPP (3<sup>rd</sup> Generation Partnership Project, the third generation) system competitiveness, an access technology evolution work is being carried out within the 3GPP organization. Especially in order to strengthen the 3GPP system's ability to handle the rapidly growing IP data services, the use of packet technology in the 3GPP system requires further enhancement. The most important parts of this type of technological evolution include: reduced delay and response time, higher user data rates, enhanced system capacity and coverage, and reduction in overall operator costs. In addition, the evolved network structure is also an important indicator for the backward compatibility of the existing network. In terms of security, the user security process in the evolved network must ensure that it provides at least the same level of security mechanisms as the current 2G and 3G systems.
[0003] As shown in FIG. 1, the core network of the wireless evolution network mainly includes logical function bodies such as MME (Mobility Management Entity) and SAE Gateway (System Architecture Evolution Gateway), where the MME is responsible for the control plane. Mobility management includes user context and mobility status management, assigning user temporary identities, security functions, etc.; SAEGateway is responsible for initiating paging for downlink data in idle state, managing and saving IP bearer parameters and routing information in the network, etc., acting as a different interface Enter the user plane anchor point between systems. In the wireless evolution network, the security of the user plane is terminated in the access network. The access network BS (Base Station, base station) is called eNB (evolved NodeB), and the security of the signaling plane is divided into the access layer information. Let RRC (RadioResource Control) signaling and non-access stratum signaling NAS (Non AccessStratum, non-access stratum) signaling be terminated in the access network and core network respectively. The key required for signaling protection and data protection is the key CK generated by the AKA (Authentication and Key Agreement) process, IK is derived from various types, and the derivation relationship is shown in Figure 2.
[0004] where K<sub>eNB</sub>_<sub>EEC</sub>_<sub>INI</sub>Is the RRC signaling integrity protection key, K<sub>eNB</sub>_<sub>EEC</sub>_<sub>ENC</sub>Is the RRC signaling encryption protection key, K<sub>eNB</sub>-<sub>EEC</sub>_<sub>UP</sub>It is the user plane data encryption protection key. And K<sub>NAS</sub>_<sub>ENC</sub>Is the NAS signaling encryption protection key, K<sub>NAS</sub>_<sub>INI</sub>It is the NAS signaling integrity protection key.
[0005] At present, in the SAE/LTE system, there have been related discussions about how to apply the method to the active session immediately after key negotiation. All of the methods are based on the premise that the key has been successfully updated to a new key, but they do not involve the process of how to obtain the new key. Therefore, it is necessary to propose a method to solve how to negotiate a new key in the active state. In addition, the active state key update requires the network side to have the ability to initiate key negotiation. In the prior art, the network side does not actively initiate the key update process during communication, but only when the user transitions from the non-active state to the active state and initiates the initial NAS message to the network side, such as attach request, paging (Paging) response, location update request, etc., will determine whether a certain key needs to be updated.
[0006] Summary of the Invention
[0007] The embodiments of the present invention provide a key update method and device in an active state, which are used to implement key update in an active state.
[0008] To achieve the foregoing objective, an embodiment of the present invention provides a key update method in an active state, which includes
CN 101400059 Β
The following steps:
[0009] The user terminal or the network side in the active state initiates a key update process when the preset conditions are met; [0010] the network side mobility management entity MME notifies the network side evolved base station eNB of the key update process After the new key is generated,
[0011] The network-side eNB updates the air interface key according to the new key, and the network-side eNB and the user terminal negotiate the activation time of the air interface key.
[0012] The embodiment of the present invention also provides a user terminal for performing key update in an active state, including:
[0013] The terminal key update detection unit is configured to determine whether it is necessary to initiate a key update process according to preset conditions;
[0014] The terminal key update initiation unit is configured to send a key update request message to the network side when the terminal key update detection unit determines that a key update is required, and then move the management entity MME on the network side Notify the network-side evolved base station eNB of the new key K generated in the key update procedure<sub>eNB</sub>After that, it negotiates with the eNB that the eNB according to the new key K<sub>eNB</sub>Start time of the updated air interface key.
[0015] The embodiment of the present invention also provides a network-side mobility management entity, which is used to update the key in the active state, including:
[0016] The key update initiation unit is used to initiate a key update process when the user terminal performs system switching or finds that the key has not been updated for a long time;
[0017] The key update unit is used to update the new key K generated by the key update process<sub>eNB</sub>The context modification information is sent to the evolved base station eNB, so that the eNB according to the new key K<sub>eNB</sub>Updating the air interface key and negotiating the activation time of the air interface key with the user terminal.
[0018] Compared with the prior art, the embodiments of the present invention have the following advantages:
[0019] In different situations, the user terminal in the active state and the network side actively initiate the key update process, which solves the problem of key update in the session in the active state.
[0020] Brief Description of the Drawings
[0021] FIG. 1 is a schematic diagram of the structure of a wireless evolution network in the prior art;
[0022] FIG. 2 is a schematic diagram of the key derivation relationship in the prior art;
[0023] FIG. 3 is a flowchart of a key update method in the active state in the first embodiment of the present invention;
[0024] FIG. 4 is a flowchart of the key update in the active state initiated by the UE in the second embodiment of the present invention; [0025] FIG. 5 is the active state in the active state initiated by the network-side eNB in the third embodiment of the present invention Key update flowchart;
[0026] FIG. 6 is a flowchart of the key update in the active state initiated by the network-side eNB in the fifth embodiment of the present invention;
[0027] FIG. 7 is a flowchart of key update in the active state initiated by the network-side MME in the sixth embodiment of the present invention;
[0028] FIG. 8 is a flowchart of the eNB notifying the UE of the new key through the air interface key update process in the seventh embodiment of the present invention; [0029] FIG. 9 is the eNB through the air interface key update process in the eighth embodiment of the present invention The flowchart of notifying the UE of the new key; [0030] FIG. 10 is a schematic diagram of the key update system in the active state in the ninth embodiment of the present invention.
[0031] Specific embodiments
[0032] The following describes the implementation of the present invention with reference to the accompanying drawings and examples.
[0033] In the first embodiment of the present invention, a key update method in the active state is: the UE decides whether it needs to
The key is updated in the active state. The method for updating the key in the active state is shown in FIG. 3 and includes the following steps: [0034] Step s301, the user terminal or the network side in the active state determines that it needs to be performed according to the preset settings. Key update and initiate key update.
[0035] The pre-settings may include: (1) the user terminal discovers that the sequence number corresponding to UP (User Plane, user plane) or RRC is about to reach the upper limit; (2) the user terminal has performed an evolved base station eNB handover or self handover Or system switching; (3) User terminal or network side finds K<sub>A</sub>sme has not been updated for a long time.
[0036] Step s302, the network side executes a key update process.
[0037] The key update includes: updating all keys through the AKA authentication process; or there is no need to update K<sub>ASME</sub>, Only update its derived key.
[0038] Step S303, the user terminal and the network side obtain the updated key.
[0039] Step S304: After obtaining the new key, the user terminal and the network side negotiate the start time of the new key.
[0040] The embodiments of the present invention will be further described below in combination with different application scenarios.
[0041] In the second embodiment of the present invention, a key update method in the active state is shown in FIG. 4, which is a key update process in the active state initiated by the UE, which includes the following steps:
[0042] Step s401, when the UE finds that the key needs to be updated for some reason in the active state, it actively sends to the network side
The MME triggers the key update procedure.
[0043] The possible reasons why the key needs to be updated include: (1) UP (or the sequence number corresponding to RRC is about to reach the upper limit; (2) the UE has just switched to a new eNB; (3) K<sub>asme</sub>It has not been updated for a long time. The UE can trigger the key update procedure by sending a TAU/RAU request, or a special attachment request, or a special service request, or a key update request message to the MME.
[0044] If the TAU/RAU message is sent as the key update request to trigger the key update, even if the UE does not have a location/routing area update, the TAU/RAU request is also sent, but the TAU/RAU request is The old routing area identifier is consistent with the new routing area identifier. In order to identify the key update request, a special value can be set for the Update type (update type) value in the TAU/RAU request, which means that the key needs to be updated. This special value can use only one special value without distinguishing which reasons, or it can be subdivided into different reasons (RRC/UP counter value overflow, or handover, or K<sub>ASME</sub>Expired) use a different value; or the UE does not give any instructions and uses several existing values (for example, the value representing route/location area replacement). In addition, because periodic location registration does not require updating the key, it should be distinguished from it. In order to distinguish it from periodic location/route registration, it is best not to use a value representing Periodic updating, such as 000, for Update type.
[0045] Note: Several values of Update type in the existing UMTS are shown in Table 1:
[0046] Table 1:
[0047]
<td>0000010100Π</td><td>RA updatingcombined RA/LA updatingcombined RA/LA updating with IMSI attachPeriodic updating</td>
[0048] Step s402: After receiving the request for triggering the key update (which may be one of the several requests described in step 401), the MME executes the relevant key update according to the request type.
[0049] If K<sub>ASME</sub>Need to be updated, such as cross-system handover from GSM/UMTS to SAE/LTE, or K<sub>ASME</sub>Expired
Initiate the AKA authentication process;
[0050] If Krsme does not need to be updated, only its derived key needs to be updated. If a handover occurs in the LTE system, or the key needs to be updated due to the overflow of the RRC/UP counter value, then the new derived key is calculated based on K^με. key. Can only update K<sub>eNB</sub>, Can also be combined with K<sub>NA</sub> S-int<sup>?</sup> K<sub>N</sub>AS-enc is updated together.
[0051] Step s403. If it is determined in step s402 that the K^με update needs to be performed, then the AKA process is performed to update the key. This step is optional.
[0052] Step s404: According to the decision of step s402, each key is updated. If you only need to update K<sub>ASME</sub>Each derived key of, then use the existing K<sub>ASME</sub>The key calculates the corresponding key.
[0053] Step s405, the MME sends the new key to the eNB.
[0054] In step s406, the eNB and the UE negotiate a new key start time.
[0055] The method for the eNB to notify the activation time of the new key can be one of the following methods, or one other than these methods:
[0056] (1) The eNB notifies the UE of the activation time of the new key through a simplified security mode command, and the UE confirms the received security mode command. The UE and the network side activate the new key according to the time when the new key is activated. If the NAS key needs to be updated, in step s405, it may be necessary to initiate a NAS security mode command to negotiate a new NAS key activation time.
[0057] (2) The eNB initiates a self-handover command to request the UE to switch to the eNB itself, so that the UE can use its own key. The specific implementation belongs to the existing technology.
[0058] (3) The eNB adds KSI in front of each data packet to indicate which decryption the UE uses.
[0059] In addition to the above method, you can also refer to the description of the seventh embodiment or the eighth embodiment below.
[0060] Step s407: The network side sends a response message to the user to end all processes.
[0061] It should be pointed out that the new NAS key activation time can also be carried in this response.
[0062] In the third embodiment of the present invention, a key update method in the active state is shown in FIG. 5, which is a process of key update in the active state actively initiated by the network-side eNB.
[0063] This embodiment is a key update process initiated by the eNB. When the UP or RRC encryption/integrity protection sequence number is about to reach the maximum value (about to wrap around), in order to prevent repetition of the key stream, the corresponding key may need to be updated; or even if the sequence number does not reach the maximum value, the UE is in LTE_ACTIVE The status is very long, and it may be necessary to update the user plane protection key Kup-enc or KeNB. In these two cases, there is no need to update K^με and K^, only the Kup'Krrc key needs to be updated. Of course you can also update Zhang Pan at the same time
[0064] The key update process in the third embodiment is described as follows:
[0065] Step s501: When the eNB finds that the key needs to be updated according to the above-mentioned security requirements, it sends a key update request message to the MME to request the MME to generate a new K<sub>eNB</sub> ; MME will start from K<sub>ASME</sub>Export new K<sub>eNB</sub> ;
[0066] The key update request message may be: (1) A request message specifically for the eNB to request the MME to update the key, and the request message requires a response from the MME. A notification type message. The MME is notified that the key needs to be updated, and the notification message does not require a response from the MME.
[0067] Step s502: The MME updates the key core according to the situation. Its center can be MME through the existing
K<sub>ASME</sub>Derived, it may also be that the MME updates K through the AKA process<sub>ASME</sub>It will be calculated later.
[0068] Step s503, the MME changes the new K<sub>eNB</sub>Sent to eNB. The MME can send the key to the eNB in the following ways:
[0069] (1) A key update response message corresponding to the key update request sent by the eNB in step s501
CN 101400059 Β
interest.
[0070] (2) A context modification message initiated by the MME, in which the new key is sent to the eNBo in the modification message
[0071] (3) A security context modification message initiated by the MME, in which the new key is sent to the eNB.
[0072] It is worth noting that in addition to the new Ke® MME, it may be necessary to calculate K<sub>eNB</sub>Other required parameters are sent to the eNB in the above manner. For example, when MME uses the existing K<sub>A</sub>When sme calculates a new key, it may need to introduce a variable parameter (such as a counter, a random number), then this variable parameter may also need to be sent to the eNB, and sent to the UE through the eNB to ensure that the UE can use the same parameter calculation This new K<sub>eNBO</sub>
[0073] The eNB will use this new K<sub>eNB</sub>Derive a new K<sub>UP</sub>And K<sub>EECO</sub>This derivation process may need to use C-RNTI or a random number as an input parameter; if C-RNTI is used, either the original C-RNTI may be used, or a new C-RNTI parameter may be generated for the UE.
[0074] Step s504, the air interface new key initiation process, that is, the method of how to negotiate a new key replacement time, except that the PDCP (Packet Data Convergence Protocol) SN is used in the existing scheme, and the data carries KSI or mandatory For the manner in which the UE performs IDLE state transition, please refer to the description of Embodiment 7 or Embodiment 8 below.
[0075] If in step s503, the MME uses method (2) to send K<sub>eNB</sub>, Then the eNB may need to respond to the MME with a (security) context modification response message after the new key is activated.
[0076] In the fourth embodiment of the present invention, a key update method in the active state is shown in FIG. 5, which is a key update process in the active state initiated by the eNB on the network side.
[0077] This embodiment is a key update process initiated by the eNB. When the UP or RRC encryption/integrity protection sequence number is about to reach the maximum value (about to wrap around), in order to prevent repetition of the key stream, the corresponding key may need to be updated; or even if the sequence number does not reach the maximum value, the UE is in LTE_ACTIVE The state takes a long time, and it may be necessary to update the user plane protection key K<sub>UP</sub>_<sub>enc</sub>Or K<sub>eNBO</sub>There is no need to update K in these two cases<sub>ASME</sub>And, only need to update the heart eight Krrc key.
[0078] The difference from the third embodiment is: in the third embodiment K<sub>eNB</sub>Is newer, and in this example K<sub>eNB</sub>Do not update.
The key update process in the fourth embodiment is described as follows:
[0079] (1) When the eNB finds that the key needs to be updated (the eNB finds that the key needs to be updated according to the aforementioned security requirements), it generates a random number or a new C-RNTI, and then uses K<sub>eNB</sub>And other parameters to generate a new RRC/UP key.
[0080] (2) The eNB notifies the UE of the new key parameters through the air interface key update process. For the adopted air interface key update process, refer to the description of the following embodiment.
[0081] In the fifth embodiment of the present invention, a key update method in the active state is shown in FIG. 6, which is a key update process in the active state initiated by the network-side eNB, which includes the following steps:
[0082] Step s601: In a non-handover situation, if the network side, such as the eNB, wants to update the key. Then, a self-handover command is sent to the UE, that is, the UE is required to switch to the source cell (the target cell is the same as the source cell).
[0083] Step s602: After receiving the handover command, the UE re-accesses the eNB.
[0084] For the description of step s603 to step s609 in the following process, please refer to step s401 to step s407 in the second embodiment, which will not be repeated here.
[0085] In the sixth embodiment of the present invention, a key update method in the active state is shown in FIG. 7, which is a process in which a network-side MME actively initiates a key update, and includes the following steps:
[0086] Step s701, the network-side MME finds that the Krsme has been used for too long, and then decides to initiate an AKA process. The network side needs to provide for each K<sub>Aa(</sub>E set an effective time, when the effective time reaches the maximum value, the corresponding process will be triggered immediately
CN 101400059 Β
[0087] In step s702, the MME actively initiates a special paging message to the UE. This step is optional.
[0088] The Paging cause of this special paging request may be NULL, or a special value indicating that the key update is performed.
[0089] Step s703: After receiving the paging message, the UE sends a paging response to the network.
[0090] Steps 702 and 703 are optional steps.
[0091] Step s704: When the MME directly sends an authentication request message to the UE to initiate the execution of AKA, or after receiving the paging response, it will decide to execute AKA according to the paging message received in the prior art, and initiate to the UE AKA process.
[0092] Step s705, the MME calculates each derived key.
[0093] Step s706, MME sets K<sub>eNB</sub>To the eNB, the specific method of sending can be carried in a NAS message and instruct the UE to activate the new NAS key. This step is optional.
[0094] The MME can send the key to the eNB in one of the following ways:
[0095] (1) A context modification message that is actively sent to the eNB is carried. This context modification message can use a special S1 initial context establishment message, or it can be a newly defined S1 interface signaling.
[0096] (2) A security context modification message that is actively sent to the eNB is carried.
[0097] Of course, other similar messages are not ruled out.
[0098] In step s707, the eNB and the UE negotiate a new key start time. The optional start time of the NAS key can also be negotiated in this process.
[0099] Step s708, the user and the network side communicate with the new key.
[0100] For the newly generated key, the eNB needs to notify the UE of the new key through an air interface key update process. In the key update process, the main purpose of the air interface key update process is: (1) Send the parameters related to the derived key to the UE, such as a new C-RNTI or random number; (2) Tell the UE the key Start Time.
[0101] In the seventh embodiment of the present invention, an SMC (Safe Mode Control, safe mode control) process is taken as an example to describe
The T eNB notifies the UE of the new key through the air interface key update process, as shown in FIG. 8, including the following steps: [0102] Step s801, the eNB determines that a special SMC message needs to be sent to the UE according to the trigger condition.
[0103] The parameters in the SMC message include one or more of the following parameters: (1) Parameters required for key derivation, such as C-RNTL·random number, etc.; (2) Downlink activation time of the NAS key; ( 3) Downlink activation time of the RRC key; (4) Uplink and downlink activation time of the user plane key; (5) Other possible parameters, such as determining the new password of the uplink data packet (including user plane and control plane data packets) Key start time.
[0104] In addition, when the eNB sends a downlink message, it may: (1) stop sending downlink data, so that the downlink start time can start from the next data packet; (2) continue to send, but in order to avoid sending packets too fast. The key start error, the started PDCP SN can be set backward;
[0105] Of course, in addition to the SMC message, a new command such as a security context modification command/security reconfiguration command may also be newly defined, requiring the UE to change the key used according to the parameters carried in the command and the time.
[0106] Step s802: After receiving the relevant message, the UE returns the corresponding message to the eNB.
[0107] Specifically, after the UE receives the SMC message, it derives a new key according to related parameters; optionally, it may also need to determine the start time of uplink data packets (including user plane and control plane data packets); and then give it to the eNB The corresponding message is returned. Each PDCP SN started by the new key is carried in the message. The UE may not stop sending the data packet, but calculate the new key and the new key start time in the background, and then send the new start time to the eNB. If this method is used, then
CN 101400059 Β
It is necessary to set the key start time of the upstream data packet to a later point.
[0108] Step s803, the air interface communicates under the protection of the new key.
[0109] In the eighth embodiment of the present invention, using the self-handover process as an example, describes the process in which the eNB notifies the UE of the new key through the air interface key update process. As shown in Figure 9, it includes the following steps:
[0110] Step s901: The eNB determines that it needs to send a HO Command message to the UE according to the trigger condition.
[0111] Under normal circumstances, since the HO Command message is sent to the UE to tell the UE to switch to another Cell, the HO Command message will carry the air resources and C-RNTI allocated by another Cell; but in the embodiment The HO Command message in the middle does not instruct the UE to switch to other Cells, but only tells the UE to start the key update, so the parameters need to be changed: (1) The transparent container for Target eNB to UE in the original HOCommand message should be removed; (2) ) The C-RNTI allocated by the target eNB to the UE in the original message needs to be modified to be allocated by the Source eNB itself; (3) Increase the NAS key activation time that may be required; (4) Increase the RRC key Downlink activation time; (5) Increase the downlink activation time of the user plane key; (6) Increase the reason value and tell the UE that this HO Command message instructs the UE to update the key, not for handover.
[0112] In addition, in accordance with the general requirements of the HO Command, the eNB will no longer send any data packets after sending the HO Command message.
[0113] Step s902, after the UE receives the HO Command message: (1) According to the cause value, it is judged that this handover is only to update the key; therefore, there is no need to synchronize to the new cell; (2) stop sending uplink data packets; (3) derived New key; (4) Determine the start time of the uplink data packet; (5) Send a message to the eNB to inform the start time of the uplink data packet.
[0114] In step s903, the UE and the eNB communicate under the protection of the new key.
[0115] By using the method provided by the embodiment of the present invention, it is realized that the user terminal in the active state and the network side actively initiate the key update process under different circumstances, which solves the problem of key update in the session in the active state. In addition, the implementation process is simple and easy to implement.
[0116] The ninth embodiment of the present invention also discloses a key update system in an active state. As shown in FIG. 10, it includes at least one user terminal 10 and a network-side entity 20. The user terminal in the active state and When the network side entity meets the preset conditions, it initiates a key update and updates the key.
[0117] Specifically, the user terminal 10 further includes:
[0118] The terminal key update detection unit 11 is configured to determine whether a key update needs to be initiated according to a preset condition.
[0119] The terminal key update initiation unit 12 is configured to send a key update request message to the network-side entity 20 when the terminal key update detection unit 11 determines that a key update is required.
[0120] The terminal key update setting unit 13 is used to pre-set conditions for initiating a key update and provide it to the terminal key update detection unit 11.
[0121] Specifically, the network-side entity 20 specifically includes:
[0122] The key update detection unit 21 is configured to determine whether a key update needs to be initiated according to preset conditions.
[0123] The key update initiation unit 22 is configured to send a request message to the user terminal 10 when the key update detection unit 21 determines that a key update is needed, for instructing the key update.
[0124] The key update unit 23 is configured to update the key when the user terminal 10 or the network entity 20 initiates a key update.
[0125] The key update setting unit 24 is used to pre-set conditions for initiating a key update and provide it to the key update detection unit 21.
[0126] The key activation negotiation unit 25 is configured to negotiate the activation time of the new key with the user terminal.
[0127] Among them, the functions of the above-mentioned units can be implemented by the MME and eNB on the network side.
[0128] By using the system and equipment provided by the embodiments of the present invention, it is realized that the user terminal in the active state and the network side actively initiate the key update process under different conditions, which solves the problem of the key update process in the active state session. problem. In addition, the implementation process is simple and easy to implement.
[0129] Through the description of the above implementation manners, those skilled in the art can clearly understand that the present invention can be implemented by means of software plus a necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is better. The best way to implement it. Based on this understanding, the technical solution of the present invention can be embodied in the form of a software product in essence or a part that contributes to the existing technology. The computer software product is stored in a storage medium and includes a number of instructions to make a A network device or user terminal executes the method described in each embodiment of the present invention.
[0130] The above disclosures are only a few specific embodiments of the present invention, but the present invention is not limited thereto, and any changes that can be thought of by those skilled in the art should fall into the protection scope of the present invention.
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US9031240B2 | Cited by | United States of America | Applicant |
| US8144877B2 | Cited by | United States of America | Applicant |
| US8023658B2 | Cited by | United States of America | Applicant |
| US8300827B2 | Cited by | United States of America | Applicant |
| CN1835633A | Cites | China | – |
| CN1878058A | Cites | China | – |
| CN1937489A | Cites | China | – |
| CN1953369A | Cites | China | – |
| US20040071293A1 | Cites | United States of America | – |
22 members in 6 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 200710151885 | China | A | |
| CN20071151885 | – | – | – |
Members22
| Document | Office | Kind | |
|---|---|---|---|
| CN101400059A | China | A | |
| WO2009043294A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2197147A1 | European Patent Office (EPO) | A1 | |
| US2010202618A1 | United States of America | A1 | |
| CN101400059BThis record | China | B | |
| US2011080875A1 | United States of America | A1 | |
| US8023658B2 | United States of America | B2 | |
| US2011310849A1 | United States of America | A1 | |
| US8144877B2 | United States of America | B2 | |
| EP2197147A4 | European Patent Office (EPO) | A4 | |
| US8300827B2 | United States of America | B2 | |
| US2012307803A1 | United States of America | A1 | |
| US9031240B2 | United States of America | B2 | |
| US2015208240A1 | United States of America | A1 | |
| US10057769B2 | United States of America | B2 | |
| US2019007832A1 | United States of America | A1 | |
| EP2197147B1 | European Patent Office (EPO) | B1 | |
| TR201906527T4 | Türkiye | T4 | |
| PT2197147T | Portugal | T | |
| EP3591891A1 | European Patent Office (EPO) | A1 | |
| US10999065B2 | United States of America | B2 | |
| EP3591891B1 | European Patent Office (EPO) | B1 |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Enforcement, change and cancellation of record of contracts on the licence for exploitation of a patent or utility modelLICC | LICC | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 101400059
- Publication, DOCDB
- 101400059
- Publication, EPODOC
- CN101400059B
- Application
- 101518855
- Application, DOCDB
- 200710151885
- Application, EPODOC
- CN200710151885
Titles2
- Chinese
- 一种active状态下的密钥更新方法和设备
- English
- Method and equipment for key update in active state
Classification
- CPC, 9
- H04L9/0844
- H04L63/068
- H04L2209/80
- H04L9/0891
- H04W12/08
- H04W12/06
- H04W12/0431
- H04W12/041
- H04L63/08
- IPC, 4
- H04W12 04
- H04L29 06
- H04W12 0431
- H04W12 0433