Integrity check in communication system
Abstract
The present invention discloses a communication method between a first node and a second node, wherein a plurality of different channels are set between the first node and the second node, and the method includes the steps of: calculating an integrity output, so The integrity output is calculated from multiple values, a part of the value is the same for the different channels, and at least one of the values is set to include information related to the identity of the channel Each channel has a different identity, and the information related to the integrity output is transmitted from one of the said nodes to the other; communication is carried out between the said nodes.

Term
Term ended
Expired 23 January 2021, 5.7 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
21 claims: 4 independent, 17 dependent
- 1一种在第一节点和第二节点之间通信的方法,其中多个不同的信道设置在第一和第二节点之间,所述方法包括步骤:计算一个完整性输出,所述的完整性输出是从多个值中计算出来的,所述值的一部分对于所述的不同信道是相同的,所述值中的至少一个被设置成包括与所述信道的身份相关的信息,每个信道具有一个不同的身份,从其中一个所述的节点向另一个传送与该完整性输出相关的信息;在所述节点之间进行通信。
- 2根据权利要求1的方法,其中对于与信道身份相关的所述信息提供一个独立的输入。
- 3根据权利要求1的方法,其中与信道身份相关的所述信息与至少一个其它输入值相组合。
- 4根据权利要求3的方法,其中与信道身份相关的所述信息仅与一个其它输入值相组合。
- 5根据权利要求3的方法,其中所述的组合后输入值包括分配给所述信道身份的第一部分,以及分配给由所述值提供的其他信息的第二部分。
- 6根据权利要求1的方法,其中用以计算所述完整性输出的所述值包括下述值中的一个或者多个:完整性密钥、方向值、刷新值、消息值以及计数值。
- 7根据权利要求1的方法,其中与信道身份相关的所述信息与下述值中的一个或者多个相组合:所述刷新值、所述计数值、所述完整性密钥、所述方向值以及所述消息值。
- 8根据权利要求7的方法,其中所述消息值从一个节点发送到另一个节点,而无需信道标识信息。
- 9根据权利要求1的方法,其中所计算的完整性输出从一个节点发送到另一个节点。
- 10根据权利要求1的方法,其中所述第一节点与所述第二节点之间的通信经过无线连接。
- 11根据权利要求10的方法,其中所述第一和第二节点中的一个是用户设备。
- 12根据权利要求11的方法,其中所述用户设备是一个移动站。
- 13根据权利要求10的方法,其中所述第一和第二节点中的一个是无线电网络控制器。
- 14根据权利要求10的方法,其中所述第一和第二节点中的一个是节点B。
- 15根据权利要求1的方法,其中所述通信信道包括一个无线电承载。
- 16根据权利要求15的方法,其中所述无线电承载是一个信令无线电承载。
- 17根据权利要求1的方法,其中所述值被输入到用以计算所述完整性输出的算法中。
- 18根据权利要求7的方法,其中在不同的信道中使用同一个完整性密钥。
- 19一种在系统中执行完整性检验的方法,该系统包括一个第一节点以及一个第二节点,多个通信信道设置在所述第一节点和第二节点之间,所述的方法包括:利用多个值来计算一个完整性输出,所述值中的一部分对于所述不同信道都是相同的,所述值中的至少一个被设置成包含与信道身份相关的信息,每个信道具有一个不同的身份;从其中一个所述节点向另一个节点传送与所述完整性输出相关的信息。
- 20一种节点,所述节点用于包含所述节点和另一个节点的系统中,多个不同的信道设置在所述节点之间,所述节点包括用于计算一个完整性输出的装置,所述的完整性输出是从多个值中计算出来的,所述值的一部分对于所述的不同信道是相同的,所述值中的至少一个被设置成包括与所述信道的身份相关的信息,每个信道具有一个不同的身份;以及从其中一个所述的节点向另一个传送与该完整性输出相关信息的装置。
- 21一种节点,所述节点用于包含所述节点和另一个节点的系统中,多个不同的信道设置在所述节点之间,所述节点包括用于计算一个完整性输出的装置,所述的完整性输出是从多个值中计算出来的,所述值的一部分对于所述的不同信道是相同的,所述值中的至少一个被设置成包括与所述信道的身份相关的信息,每个信道具有一个不同的身份;以及将由所述节点计算出来的与完整性输出相关的信息与由另一个节点计算出来的值相比较的装置。
Independent claims21
117 paragraphs, as filed
Integrity check in communication system
Technical field
The present invention relates to a method for verifying the integrity of communication between a first node and a second node. In particular, but not exclusively, the present invention relates to a method for verifying the integrity of communication between a mobile station and a cellular network.
Background technique
Many different communication networks are already known. One type of communication network is a cellular communication network in which the area covered by the network is divided into multiple cells. Each cell has a base station, and the base station serves mobile stations in the cell associated with the base station. User equipment, such as a mobile station, receives signals from the base station and transmits signals to the base station so that the user equipment can communicate through the base station. The cellular system generally also includes a base station controller, which is used to control the operation of one or more base stations. At least some user equipment of the system can communicate on one or more communication channels at the same time.
Communication faces the problem of ensuring that the received information is sent by an authorized sender, not by an unauthorized user who is trying to impersonate the sender. This problem is particularly relevant to cellular communication systems, where the air interface provides potential opportunities for unauthorized users to eavesdrop and replace transmitted content.
One solution to this problem is the authentication of communication users. The purpose of an authentication process is to discover and verify the identities of communication users so that each user receives information about the identities of other users. And the identity can be trusted. Authentication is generally performed in a specific process when the connection is started. However, this process leaves room for unauthorized manipulation, insertion, and deletion of subsequent messages. It is necessary to independently authenticate each transmitted message. This can be achieved by attaching a message authentication code (MAC-I) to the message at the sending end, and verifying the message authentication code MAC-I at the receiving end.
The message authentication code MAC-I is generally a relatively small bit string, which depends on the message it protects and the key known to the sender and receiver of the message. The key is generated and agreed during the authentication process at the beginning of the connection. In some cases, the algorithm (used to calculate the authentication code MAC-I based on the key and the message) is also confidential, but this is usually not the case.
The authentication process of a single message is often referred to as integrity protection. In order to protect the integrity of the message, the sending user calculates the message authentication value based on the message to be sent and the key using the specified algorithm, and sends the message with the MAC-I value of the message authentication code. The receiving user recalculates the message authentication code MAC-I based on the message and the key of the specified algorithm, and compares the received message authentication code MAC-I with the calculated message authentication code MAC-I. If the two message authentication codes MAC-I match, the receiver can trust that the message is complete and sent by the presumed user.
The integrity protection scheme can be deciphered. Unauthorized users can forge the value of the message authentication code MAC-I in two ways for modified or new messages. The first method involves obtaining the key, while the second method involves providing a modified or new message without knowing the key.
The key can be obtained by a third party in the following two ways:-by calculating all possible keys until the key matching the observed message authentication code MAC-I pair is found, or by cracking used to generate message authentication Algorithm to code the MAC-I value;-by directly capturing the stored or transmitted key.
The original communication party can prevent a third party from obtaining the secret by using a strong encryption algorithm, using a key long enough to prevent exhaustive searches for all keys, and by using a secure method for transmitting and storing the key. key.
The third party can guess the correct MAC-I value of the message authentication code, or by replaying the previous message transmitted between the two parties, trying to interrupt the message transmission between the two parties without using the key. In the latter case, the correct message authentication code MAC-I for the message has been known since the original transmission. This deciphering is very useful for unauthorized third parties. For example, this can double the number of further actions that are beneficial to the intruder. Even currency transactions can be repeated in this way.
The long message authentication code MAC-I value can be used to prevent the correct guessing of the message authentication code MAC-I. The MAC-I value of the message authentication code should be long enough to reduce the probability of guessing to a sufficiently low level compared with the benefits obtained by successful forgery. Using the 32-bit message authentication code MAC-I value reduces the probability of correct guessing to 1/4294967296. This is small enough for most applications.
Using replay deciphering, that is, replaying the previous message, obtaining the correct MAC-I value of the message authentication code can be prevented by introducing a time-varying parameter into the calculation of the message authentication MAC-I value. For example, in addition to the confidential integrity key and the message, the timestamp value or the serial number is used as a further input to enter the message authentication code MAC-I algorithm.
When a sequence of numbers is used as a time-varying parameter, a mechanism is used to prevent the possibility of using the same key to use the same serial number more than once. Generally speaking, both parties in the communication monitor the serial number used.
If multiple communication channels in use all use the same key, the following problems will occur. The message on the communication channel associated with a given sequence number, for example n, can be repeated on another communication channel when appropriate, that is, the sequence number n can be accepted on other channels.
For the third-generation standard, it has been proposed to apply encryption and integrity protection in the UMTS system. However, the proposed method allows the same message to be sent on different signaling radio bearers at different times. This makes the system vulnerable to "man-in-the-middle" deciphering damage. In particular, such systems may be vulnerable to the aforementioned "reproducing deciphering" damage.
Generally speaking, a repeated signaling message does not give a significant benefit to an unauthorized third party, but the third party can try to repeat a longer conversation in order to establish an additional call, thus stealing part of the connection.
Summary of the invention
The purpose of the present invention is to solve one or more of the above-mentioned problems.
According to one aspect of the present invention, there is provided a method of communication between a first node and a second node, wherein a plurality of different channels are set between the first and second nodes, and the method includes the steps of: calculating a Integrity output, the integrity output is calculated from a plurality of values, a part of the value is the same for the different channels, and at least one of the values is set to include The identity-related information of each channel has a different identity, and the information related to the integrity output is transmitted from one of the said nodes to the other; communication is carried out between the said nodes.
Provides an independent input for information related to the identity of the channel. The information related to the channel identity can be combined with at least one other input value. The input value may include one or more of the following values: integrity key; direction value; latest value; message value and count value. The output of the integrity algorithm can be sent from one node to another. The communication channel may include a radio bearer. The input value can be input into an algorithm to calculate the output.
According to another aspect of the present invention, there is provided a method for performing an integrity check on a system. The system includes a first node and a second node, and a plurality of communication channels are set between the first node and the second node. In the meantime, the method includes: calculating an integrity output using a plurality of values, some of the values are the same for the different channels, and at least one of the values is set to include Identity-related information, each channel has a different identity.
According to another aspect of the present invention, there is provided a method of communication between a first node and a second node, a plurality of communication channels are set between the first node and the second node, and the method includes: Use multiple values to calculate an integrity output, one of the values is an integrity key, and each of the channels has a different integrity key; and transfer from one of the nodes to another Information related to the output of the integrity algorithm.
According to another aspect of the present invention, there is provided a method of communication between a first node and a second node, a plurality of communication channels are set between the first node and the second node, and the method includes: Trigger an authentication process; and through the authentication process, calculate the required number of integrity parameters.
According to another aspect of the present invention, a node is provided, the node is used in a system including the node and another node, a plurality of different channels are set between the nodes, and the node includes A device for calculating an integrity output, the integrity output is calculated from multiple values, a part of the value is the same for the different channels, and at least one of the values is set to include The information related to the identity of the channel, each channel has a different identity; and a device for transmitting the information related to the integrity output from one of the said nodes to the other.
According to another aspect of the present invention, a node is provided, the node is used in a system including the node and another node, a plurality of different channels are set between the nodes, and the node includes A device for calculating an integrity output, the integrity output is calculated from a plurality of values, a part of the value is the same for the different channels, and at least one of the values is set to include The information related to the identity of the channel, each channel has a different identity; and a device that compares the information related to the integrity output calculated by the node with the value calculated by another node.
According to another aspect of the present invention, an algorithm for calculating an integrity output is provided. The integrity output is used in a system including the node and another node, and a plurality of different channels are set between the nodes. Meanwhile, the algorithm includes a device for calculating an integrity output, the integrity output is calculated from a plurality of values, a part of the value is the same for the different channels, and the value At least one of is configured to include information related to the identity of the channel, each channel having a different identity.
The embodiments of the present invention can achieve various advantages. In the technical solution of the present invention, in the case of using multiple parallel communication channels, reproducing deciphering can also be prevented. One advantage is that the embodiments can be flexibly applied to any system that utilizes multiple parallel communication channels within a connection. The embodiments of the present invention can enhance user security in a communication system, especially a wireless communication system. These embodiments can ensure that multiple parallel communication channels in a connection do not use the same set of input parameters to calculate the message authentication code MAC-I.
Description of the drawings
In order to better understand the present invention and how to implement the present invention, the present invention is described below with the help of examples and with reference to the accompanying drawings. Wherein: FIG. 1 shows each unit of a cellular network to which the embodiment of the present invention can be applied;
Figure 2 shows the Uu protocol architecture of the radio interface between the user equipment UE and the Node B, and between the user equipment UE and the radio network controller RNC of Figure 1; Figure 3 schematically depicts the integrity protection function Figure 4 shows an integrity protection function modified according to an embodiment of the present invention; Figure 5 shows an integrity protection function modified according to other embodiments of the present invention; Figure 6 shows other implementation principles of the present invention; Figure 7 Shows the authentication key and the key agreement process; Fig. 8 shows the generation of the authentication vector; Fig. 9 shows an example of the user authentication function in the USIM according to an embodiment of the present invention.
Specific Implementation Now referring to Figure 1, Figure 1 describes a typical mobile phone system structure. The main parts of the mobile phone system are: core network CN 2, UMTS terrestrial radio access network UTRAN 4 and user equipment UE 6. The core network CN 2 may be connected to an external network 8, which may be a circuit switched (CS) network 81 (for example, PLMN, PSTN, ISDN) or a packet switched (PS) network 82 (for example, the Internet). The interface between the core network CN 2 and the UMTS terrestrial radio access network UTRAN 4 is called the Iu interface, and the interface between the UMTS terrestrial radio access network UTRAN 4 and the user equipment UE is called the Uu interface. As shown in Figure 1, the RNC is connected to two CNs (MSC/VLR and SGSN). In some network structures, one RNC can also be connected to one CN node or more than two CN nodes.
The core network CN 2 includes a home location register HLR 10, a mobile switching center/visit location register MSC/VLR 12, a gateway MSC GMSC 14, a serving GPRS (general group radio service) support node SGSN 16 and a gateway GPRS support node GGSN 18.
UTRAN 4 includes radio subsystems 20 and 22. The interface between the two radio subsystems RNS is called the Iur interface. The radio network subsystems RNS 20 and 22 respectively include a radio network controller RNC 24 and one or more Node Bs 26. The interface between the radio network controller RNC 24 and the Node B 26 is called the Iub interface.
The radio network controller RNC 24 is a network unit responsible for controlling the radio resources of UTRAN 4. The RNC 24 interfaces with the core network CN 2 (usually interfaces with an MSV 12 and an SGSN 16), and also terminates the radio resource control RRC protocol, which defines the messages and procedures between the user equipment UE 6 and the UTRAN 4. The RNC 24 logically corresponds to a base station controller of the GSM (Global System for Mobile Communications) standard.
The main function of the Node B 26 is to perform air interface L1 processing (channel coding and interleaving, rate adaptation, spread spectrum, etc.). It also performs some basic radio resource management operations, such as inner loop power control. It logically corresponds to the base transceiver station of the GSM standard.
The user equipment UE 6 includes two parts: the mobile equipment ME 30 and the UMTS user identity module USIM 32. The mobile equipment ME is a radio terminal used to communicate between the user equipment UE6 and the UTRAN 4 via the Uu interface. The USIM 32 is a smart card that maintains user identity, executes authentication algorithms, stores authentication and encryption keys, and certain user information required in the terminal.
Referring now to Figure 2, Figure 2 describes the architecture of the radio interface protocol according to the 3GPP technical specifications. The protocol entity works between the following elements:-between the user equipment UE 2 and the Node B 26; and/or-between the user equipment UE 2 and the RNC 24.
The division of protocol layers between Node B 26 and RNC 24 will not be described here.
The radio interface protocol can be divided into a control plane 50 and a user plane 52. The control plane 50 is used for signaling between the UE 2 and the RNC 24, and between the user equipment UE 2 and the core network CN 2. User plane 2 carries actual user data. Some radio interface protocols only work in one plane, while others can work in two planes.
The radio interface protocol can be divided into multiple layers, namely layer 1 L1 54 (also known as the physical layer), layer 2 L2 56 (also known as the data link layer), and layer 3 L3 58 (also known as the network layer) ). Some layers contain only one protocol, and some layers contain multiple different protocols.
The physical layer L1 54 provides a service to the media access control (MAC) layer 60 via a transport channel, which is characterized by how the data is transmitted and what characteristics it carries.
The medium access control (MAC) layer 60 provides services to the radio link RLC layer 62 by means of logical channels. Logical channels are characterized by the type of data transmitted. In the media access control MAC layer 60, logical channels are mapped to transport channels.
The radio link control RLC 62 provides services to higher layers via the service access point SAP, which describes how the radio link control RLC layer 62 processes data packets and whether to use automatic repeat request (ARQ). In the control plane 50, the radio link control RLC service is used by the radio resource control RRC layer 54 for signaling transmission. Generally, there are at least three radio link control RLC 62 entities involved in signaling transmission-one is a transparent entity, one is an unanswered mode entity, and the other is an answer mode entity. On the user plane 52, the RLC service is either used by the service-specific protocol layer-Packet Data Convergence Protocol PDCP 66 or Broadcast Multicast Control BMC 68, or by other high-level user plane functions (for example, voice codec). For services that do not use PDCP or BMC protocols, RLC services are called signaling radio bearers in the control plane, and radio bearers in the user plane.
The Packet Data Convergence Protocol (PDCP) only exists in the services of the PS domain of packet switching (services routed through the SGSN), and its main function is header compression, which means that redundant protocol control information is compressed in the transmitting entity ( For example, TCP/IP and RTP/IP headers are decompressed in the receiving entity. The services provided by PDCP are called radio bearers.
The Broadcast Multicast Control Protocol (BMC) only exists in the short message service SMS cell broadcast service, which is derived from GSM. The services provided by BMC are also called radio bearers.
The RRC layer 64 provides services to the higher layer (to the non-access layer) through the service access point. All higher-layer signaling between the user equipment UE 6 and the core network CN 2 is encapsulated in RRC messages for transmission over the air interface.
The control interface between the RRC 64 and all lower layer protocols is used by the RRC layer 64 to assign characteristics of the lower layer protocol entities. These characteristics include physical, transport, and logical channel parameters. The RRC layer 64 uses the same control interface, for example, for ordering the lower layer to perform certain types of measurements, and these control interfaces are used by the lower layer to report the measurement structure and errors to the RRC.
The embodiments of the present invention have been described in the UMTS (Universal Mobile Telecommunication System) environment. The present invention is also applicable to all types of communications, such as signaling, real-time services, and non-real-time services. However, it should be understood that the embodiments of the present invention are also applicable to any other systems.
In the proposal for the third-generation UMTS standard, the SGSN 16 and the user equipment UE 6 such as a mobile station have an uppermost layer L3, which supports mobility management MM (sometimes also referred to as GMM) and session management SM. The uppermost layer also supports short message service SMS. The protocol of the top layer L3 is obtained from the second-generation GPRS system. SMS supports the short message service originated by the mobile station and terminated by the mobile station described in the third-generation technical specification 3GPP TS 23.040. The mobility management function manages the positioning of the mobile station, that is, the mobile station attaches to the network and authenticates. Therefore, MM supports mobility management functions, such as attachment, separation, confidentiality (for example, authentication), and routing update. According to an embodiment, the integrity key can be calculated during the authentication process of the MM. An exemplary embodiment of this aspect of the invention will be described in more detail.
SGSN 16 and RNS 20 have a radio access network application protocol (RANAP) layer. This protocol is used to control the Iu interface bearer, but it also encapsulates and transmits higher-level signaling. RANAP is specified in the third generation technical specification 3GPP TS 25.413. Both the user equipment 6 and the RNS 20 have a radio resource control protocol RRC, which provides radio bearer control via a radio interface, for example, used to transmit higher-layer signaling messages and SMS messages. This layer handles the main part of the communication between the user equipment 6 and the RNC 24. For example, RRC is specified in the third generation technical specification 3GPP TS 25.331.
The MM, SM and SMS messages encapsulated in the RANAP protocol message (this message is called direct transmission in the 3GPP technical specifications) are sent from the SGSN 16 to the RNS 20. The packet is forwarded by the RANAP layer of the RNC 24 to the RRC layer of the RNC 24. The relay function in RNS 24 effectively strips the RANAP header by using appropriate primitives and forwards the payload to the RRC protocol so that the RRC layer knows that it is the uppermost layer that must be forwarded to the user equipment 6 news. The RNC 24 inserts an integrity checksum into the message that transfers higher-layer messages in the payload (the RRC message is called direct transfer in the 3GPP technical specifications). The RNC 24 can also encrypt the message. This will be described in detail below. The RNS 20 forwards the packet to the user equipment 6 via the air interface.
In the direction from the mobile station, the RRC layer of the user equipment 6 receives the higher-layer message, encapsulates the message into the RRC direct transmission message, and adds a message authentication code between the message is sent to the RNS 20 To the message. The message is relayed from the RRC layer to the RANAP of the RNS 20. The RNS 20 checks the information related to the message to find out whether the packet has been integrity checked.
The integrity check process will now be described. The integrity of most radio resource control RRC, mobility management MM, and session management SM (and other higher layer 3 protocols) information elements are considered and must be integrity checked. Therefore, the integrity function can be applied to most of the RRC signaling messages transmitted between the mobile station and the RNS 20. However, these RRC messages that are transmitted before the integrity key is known can be ignored. The integrity function uses the integrity algorithm with the integrity key IK to calculate the message authentication code for a given message. This is implemented in the mobile station and RNS that both have the integrity key IK and the integrity algorithm.
Referring now to Figure 3, Figure 3 describes the use of an integrity algorithm to calculate the message authentication code MAC-I.
The parameters input to the algorithm are the integrity key, the input COUNT-I depending on the time or the message number, the random value FRESH generated by the network, the direction bit DIRECTION, and the signaling data MESSAGE. The subsequent input is a message or data packet. Based on these input parameters, the message authentication code for data integrity (MAC-I) is calculated by the integrity algorithm. Then, the message authentication code is attached to the message before being sent over the air interface.
The code is used to calculate the message authentication code used for the data algorithm XMAC-I on the message received using the same algorithm UIA when the message is received. The algorithm UIA has the same input as the sender of the message. If the data integrity of the message is to be verified, the message authentication code (MAC-I, XMAC-I) calculated by the algorithm at the sending end and the receiving end should be the same.
The input parameter COUNT-I is a value that adds 1 to each integrity-protected message. COUNT-I includes two parts: the super frame number (HFN) as the most effective part and the message sequence number as the more effective part. The initial value of the superframe number is sent to the network by the mobile station during the connection establishment. When the connection is released, the mobile station stores the most frequently used superframe number from the connection and adds one. This value is then used as the initial HFN value for the next connection. In this way, the user uses the same integrity key for different connections to ensure that no COUNT-I is reused (network). After the authentication process, when a new IK is generated and used, the HFN value can be reset to zero.
The input parameter FRESH causes the network to prevent the signalling message from being reproduced by the mobile station. When the connection is established, the network generates a random value and sends the value to the user. Subsequently, the value FRESH is used by the network and the mobile station for the entire duration of a connection. This mechanism assures the network that the mobile station has not reproduced any old message authentication code MAC-I from previous connections.
The setting of the integrity key IK is described below. This key can be changed as often as desired by the network operator. Once the identity of the mobile user is known, the key setting can happen. The key IK is stored in the visitor location register and transferred to the RNC 10 when needed. This key is also stored in the mobile station until it is updated during authentication.
The key set identifier KSI is a number that is related to the cipher book and the integrity key obtained during the authentication process. This number is stored in the MS and the network together with the codebook and the integrity key. The key set identifier is used to allow the key to be reused during subsequent connection establishment. KSI is used to verify whether the MS and the network will use the same codebook and integrity key.
Provides a mechanism that does not use a specific integrity key within an unlimited time period to avoid decryption with a compromised key.
The authentication to generate the integrity key is not mandatory when the connection is established.
If the counter reaches the maximum value set by the operator and stored in the mobile station when the next RRC connection request message is sent out, the mobile station is set to trigger the generation of a new codebook and integrity key. This mechanism will ensure that the integrity key and the codebook will not be reused more than the limit set by the operator.
It should be understood that there can be more than one integrity algorithm, and information is exchanged between the mobile station and the radio network controller that defines the algorithm. It should be noted that the sender and receiver of the message should use the same algorithm.
When the mobile station wishes to establish a connection with the network, the mobile station should indicate to the network which version or versions the MS supports. The message itself must be fully protected and transmitted to the RNC after the end of the authentication process.
The network should compare its integrity protection capabilities and priorities, as well as any special requirements reserved by the mobile station, with the requirements indicated by the mobile station and made according to the following rules: 1) If the mobile station and the network do not share If the mobile station and the network have at least one algorithm version in common, the network should use one of the mutually acceptable algorithm versions for the connection.
Integrity protection is achieved by attaching the message authentication code MAC-I to the message to be completely protected. As long as the mobile station receives a connection-specific FRESH value from the RNC, the mobile station can attach MAC-I to the message.
If the number of superframes HFN is greater than or equal to the maximum value stored in the mobile station, the mobile station indicates to the network that a new authentication and key agreement needs to be initiated when the RRC connection is established.
RNC can be set to detect the need for new confidential parameters. This can be penalized by the failure of the integrity check (for example, COUNT-I loses synchronization), or the handover to the new RNC does not support the algorithm selected by the old RNC.
Whenever the authentication process is executed between the mobile station and the SGSN, a new codebook is established.
If the mobile station switches from one base station to a different base station, the integrity key IK can be changed.
It should be understood that, in the embodiment of the present invention, the integrity check can be started at any point after the connection has been established and attached.
It should be understood that for a data connection, the connection can be opened for a considerable period of time, or it can even be opened permanently.
It has been agreed to establish more than one signaling radio bearer between the mobile station or other user equipment 6 and the RNS 20, and the bearer is a radio bearer on the control plane of the service provided by the RLC. The current 3GPP technical specifications suggest that up to 4 signaling radio bearers can be provided.
In the current 3GPP technical specifications, two or more signaling radio bearer SRBs can have the same parameters input into the integrity algorithm shown in FIG. 3. If all the parameters input to the integrity algorithm are the same, the output is the same.
As mentioned earlier, the current proposal leaves the possibility of intruders or "people in the middle" to repeat the signaling message from one signaling radio bearer on another signaling radio bearer. The COUNT-I value is specific to each signaling radio bearer and can be different on different signaling bearers. Consider the following situation. A message with a COUNT value of 77 is sent on the first signaling radio success SRB1. When the count value of the second signaling radio bearer reaches 77, the unauthorized party can simply repeat the message previously sent on SRB1 by using SRB2.
Generally speaking, repeating a signaling message from the signaling radio bearer on the second signaling radio bearer will not give the "person in the middle" obvious benefits, but the unauthorized party can also repeat a long conversation in order to It is possible to establish an additional call that the "person in the middle" can use to steal part of the connection. A simple "repeated deciphering" situation is that an unauthorized party can repeat a conversation passed through SMS, such as a currency transaction.
For the current third-generation proposal, this problem may only arise in a limited number of environments. This is due to the very limited utilization of the four signaling radio bearers (SRB). Only certain RRC messages can be sent on certain signaling radio bearers. The "duplicate deciphering" situation is possible for non-access stratum (NAS) messages (messages such as CM/MM/SMS that are transferred between RRCs), or NAS message dialogue between UE and SGSN/MSC. RRC direct transmission is a kind of RRC message, which transmits all NAS messages passing through the interface in the payload. However, this problem can harm mobile users because SMS messages can be adversely affected.
There are two basic solutions to "duplicate deciphering". First, different communication channels using the same key can coordinate the use of the serial number COUNT-I in this way, that is, each serial number can be used at most once in any channel. This coordination can be very troublesome or even impossible in some cases. It should be understood that when the embodiments are applied to the radio interface of the third-generation cellular network UMTS, these communication channels may be referred to as radio bearers.
As will be discussed in further detail, the embodiment of the present invention uses such a technical solution that an additional parameter is used as an input to be input into the calculation of the message authentication code MAC-I. The value of this parameter is unique at least for each communication channel, and these communication channels use the same key. This value is unique for all communication channels in the connection between the user equipment UE 6 and the RNS 20.
In other embodiments of the present invention, this problem is avoided by ensuring that the same integrity key has never been used for different parallel communication channels.
Referring now to FIG. 4, FIG. 4 illustrates a modification of the known integrity protection function embodying the present invention. For the actual integrity algorithm UIA, these modifications do not cause any changes.
The specific parameters of the communication channel are used as input and input into the integrity protection algorithm. In the 3GPP technical specifications, the specific parameter of the communication channel is the radio bearer identification (RBID). In the application example of the present invention, the radio bearer identity represents the identity of the signaling radio bearer in the proposed WCDMA third-generation system, and the identity can be a number between 0 and 3. It should be noted that the specific parameters of the communication channel used depend on the protocol layer used to calculate the message authentication code. Still taking 3GPP as an example, if the message authentication code is added to the RLC protocol, the parameter will be the identity of the logical channel (see Figure 2). As another example, if integrity protection is implemented in the PDCP protocol layer and the RRC layer, the additional parameter will be the identity of the radio bearer (see FIG. 2). It should be understood that when discussing the control plane part of the protocol stack, the terms "signaling radio bearer identity" and "radio bearer identity" may be equivalent.
Since both the sender and the receiver, that is, the user equipment UE and the RNS 20, know the identity of the signaling radio bearer, there is no need to explicitly send the identity information through the radio interface.
Figure 4 shows possible locations for including new parameters without modifying the algorithm UIA. Since the sender and receiver are similar from the perspective of input parameters, only one side is shown in FIG. 4. It should be understood that the receiving and transmitting parts will execute the same algorithm. It can be seen from FIG. 4 that by appending a new parameter (in the form of a parameter string) to one or more existing algorithm input parameters, the preferred embodiment includes the new parameter.
In one embodiment, the signaling radio bearer identity RB IB is part of the input parameter FRESH or COUNT-I. In Figure 4, the numbers "1" and "2" are used to indicate. In practice, the FRESH and COUNT-I parameters will include FRESH and COUNT-I information and the identification information. For example, if the FRESH value has n bits, the FRESH information will be represented by a bits, and the identification information will be represented by b bits, where a+b=n. This will mean that the FRESH parameter is actually shortened. The COUNT-I parameter can be modified accordingly. In a modification, part of the signaling radio bearer identity may be provided by the COUNT-I parameter, and partly by the FRESH parameter. However, if COUNT-I becomes shorter, it can take a shorter time to "wrap around", that is, reach the maximum value and return a zero value. If the FRESH parameter is shortened, the possibility of repeating the value may increase by chance.
In other embodiments, the signaling radio bearer id is part of the integrity key. It is indicated by the number "4" in FIG. 4. For example, if the IK value has n bits, the IK information will be represented by a bits, and the identification information will be represented by b bits, where a+b=n. However, if the key IK is shorter, the possibility of simply guessing the key increases.
In other embodiments of the present invention, the identity of the signaling radio bearer can be incorporated into the MESSAGE, where the MESSAGE is fed into the integrity algorithm. It is indicated by the number "3" in FIG. 4. Since both the sender and receiver, that is, the mobile station and the RNS 20, know the identity of the signaling radio bearer, there is no need to use the actual MESSAGE to send the identity information through the radio interface. For example, if MESSAGE has n bits and identity RB IB has i bits, the actual'MESSAGE' that will be fed to the integrity algorithm will have n+i bits. Therefore, not only the MESSAGE is input to the integrity algorithm, but the bit string fed into the integrity algorithm will be compiled into the signaling radio bearer identity and the MESSAGE. This solution has no effect on the confidentiality issues related to the integrity algorithm. This means that the parameters fed into the algorithm have not been shortened.
In some embodiments, the identification information can be separated between more than two inputs.
Figure 5 shows other embodiments of the present invention, which can implement the actual integrity algorithm UIA. In this embodiment, an additional parameter is provided to the integrity algorithm, as shown in FIG. 5. In this example, when integrity protection is performed on the RRC protocol layer, the additional parameter is a (signaling) radio bearer identification RB ID, which uniquely corresponds to the (signaling) radio bearer. This parameter is entered independently and used in the calculations performed by the integrity algorithm UIA.
Fig. 6 shows other embodiments of the present invention, which can implement the actual integrity algorithm UIA. In this embodiment, the new parameter bearer id (RB ID) is combined with the parameter DIRECTION. This embodiment will effectively make the existing, that is, "old" DIRECTION parameters longer, so that the actual integrity algorithm UIA can be implemented.
In an alternative embodiment, an integrity key is generated uniquely for each radio bearer. This can be achieved by modifying the authentication process of the uppermost layer. In the proposed UMTS technical specification, the uppermost layer supports mobility management MM and dialogue management SM. As already briefly described above, the mobility management function manages the positioning of the mobile station, that is, the attachment and authentication of the mobile station to the network. During the modified authentication process, the integrity algorithm executed on each signaling radio bearer can provide a unique result, preventing the types of deciphering outlined previously.
Referring now to Figures 7 to 9, Figures 7 to 9 illustrate possible authentication and key agreement processes. The above mechanism realizes the mutual authentication between the user and the network who know the key K. In the user's home environment, the key K is shared between the user and the network, and can only be used by the user service identity module USIM and the authentication center AuC . In addition, USIM and HE monitor counters SEQMS and SEQHE, respectively, to support network authentication.
The process can be designed such that it is compatible with the current GSM security architecture and facilitates the migration from GSM to UMTS. The method includes the same query/response protocol as GSM user authentication, and a key establishment protocol combined with a serial number-based one-pass protocol, where the single-pass protocol is used from the ISO standard ISO/IEC Network authentication obtained in 9798-4. Before explaining the integrity key information, we will discuss authentication and key agreement mechanisms. Figure 7 outlines possible authentication and key agreement mechanisms. Figure 8 shows a possible process for generating an authentication vector.
Upon receiving a request from a VLR/SGSN, HE/AuC sends an ordered array of n authentication vectors (equivalent to "three bytes" of GSM) to the VLR/SGSN. Each authentication vector includes the following elements: a random number RAND, an expected response XRES, a codebook CK, an integrity key IK, and an authentication token AUTN. Each authentication vector is suitable for an authentication and key agreement between VIR/SGSN and USIM.
When the VLR/SSGSN starts authentication and key agreement, it selects the next authentication vector from the array, and sends the parameters RAND and AUTN to the user. The USIM checks whether the AUTN can be repeated, and if so, generates a response RES that is sent back to the VLR/SGSN. USIM also calculates CK and IK. VIR/SGSN compares the received RES with XRES. If they match, VIR/SGSN considers the exchange of authentication and key agreement that will be successfully concluded. The established keys CK and IK will then be transmitted by the USIM and VLR/SGSN to the entity that performs encryption and integrity functions. In the proposed UMTS system, these entities are preferably certain radio interface protocols described in FIG. 2. These entities are preferably located in the user equipment UE and the radio network controller RNC.
Even when HE/AuC cannot be used by allowing the HE/AuC link to use the previously obtained cipherbook and integrity key for the user, so that no authentication and key agreement are required and a secure connection is still established, the VLR/SGSN still Can provide security services.
The authentication party should be the AuC (HE/AuC) of the user HE and the USIM of the user's mobile station. This mechanism may include the following processes:-Allocate authentication from HE/AuC to VLR/SGSN. It is assumed that the VLR/SGSN will be trusted by the user's HE in order to safely process the authentication information. It is also assumed that the intra-system link between VLR/SGSN and HE/AuC is sufficiently secure. It is further assumed that the user trusts the HE.
-Mutual authentication between VLR/SGSN and HE/AuC and establishment of a new cipher and integrity key.
-Allocate authentication data from the previously visited VIR to the newly visited VLR. It is assumed that the link between the VLR/SGSN is sufficiently secure.
The purpose of allocating authentication data from the HE to the SE is to provide a VLR/SGSN with a new authentication vector from the user's HE. The VLR/SGSN invokes these processes by requesting the authentication vector from the HE/AuC. The "authentication data request" should include a user identity. If the user is already known in the VIR/SGSN by means of IMUI, the "Authentication Data Request" should include IMUI. If the user is identified with the help of an encrypted permanent user, the HLR message can be included, and the HE obtains the IMUI from the HLR message. In this case, this process is preferably combined with the process of "requesting user identity from HLR".
Once the "authentication data request" is received from the VLR/SGSN, the HE can pre-calculate the required number of authentication vectors and restore these vectors from the HLR database, or can calculate them as required. The HE/AuC sends an authentication response back to the VLR/SGSN, which contains an ordered array AV(1...n) of n authentication vectors. HE/AuC generates a letter's serial number SQN and an unexpected inquiry RAND. For each user, HE/AuC also monitors the counter SQNHE.
The mechanism used to verify the refresh of the serial number in the USIM should allow the serial number to be used out of order to some extent. This is to ensure that the authentication failure rate due to synchronization failure is sufficiently low. This requires the ability of the USIM to store information about past successful events (such as the serial number or related parts of it). This mechanism will ensure that if the serial number is among the last generated x=50 serial numbers, the serial number can still be accepted. This should not prevent a serial number from being rejected for other reasons, such as restrictions on the aging of time-based serial numbers.
It is necessary to use the same minimum number of X in the entire system to ensure that the synchronization failure rate is sufficiently low in various use cases, especially when logging in at the same time in the CS service and PS service domains, and in parallel between the VLR/SGSN Users who do not exchange authentication information move to supercharge the network.
The use of SEGHE can be specific to the method of generating the serial number. The authentication and key management field AMF can be included in the authentication plate of each authentication vector.
The following values can then be calculated:-message authentication code MAC = f1K (SQNRANDAMF), where f1 is the message authentication function;-expected response XRES = f2K(RAND), where f2 is a (may be truncated) ) Message authentication function;-cipher book CK = f3K (RAND), where f3 is a key generation function;-integrity key IK = f4K (RAND), where f4 is a key generation function;
-Anonymous key AK=f5K(RAND), where f5 is a key generation function or f50.
According to the embodiment of the present invention, more than one IK is generated. For example, this can be achieved by modifying the f4 function so that it generates the required number of IK (for example, 4, see Figure 4). One possibility is to specify that the f4 function must be triggered multiple times during the generation of the authentication vector. This can be achieved by inputting the first generated IK[1] in the second round (round) instead of the new RAND as input and inputting it into the f4 function. In the third round, IK[2] generated in the second round will be input into the second f4 function to obtain the third integrity key IK[3]. One possibility is to input the required number of RANDs to the function f4. Thus, as many IK:S as possible can be generated for the system in question. For example, in the UMTS system according to the 3GPP Release '99 technical specification, 4 integrity keys will be required.
Then the authentication card AUTN=SQNAKAMFMAC can be constructed. AK is an anonymous key used to hide the serial number, because the serial number pit reveals the user's identity and location. The concealment of the serial number is only used to protect passive deciphering. If there is no need to hide, then f50.
The purpose of the authentication and key agreement process is to authenticate users and establish a new pair of cipher books and integrity keys between the VLR/SGSN and the MS. During the authentication period, the user verifies the refresh of the authentication vector used. The VLR/SGSN invokes the process by selecting the next unused authentication vector from the ordered array of authentication vectors in the VLR database. The VLR/SGSN sends a random inquiry RAND and an authentication plate from the selected authentication vector to the user for network authentication. Once received, the user goes to the process shown in Figure 9.
Once RAND and AUTN are received, the user first calculates the anonymous key AK=f5K(RAND), and restores the serial number SQN=(SQNAK)AK. Next, the user calculates XMAC=f1K(SQNRANDAMF) and compares it with the MAC contained in AUTN. If they are different, the user uses a suspension instruction to send "user authentication rejection" back to the VLR/SGSN, and the user abandons the process. Then the USIM verifies that the received serial number SQN is in the correct range.
According to the embodiment of the present invention, the USIM generates more than one IK instead of generating only one IK. As explained above. This can be achieved by modifying the f4 function, that is, by stipulating that the f4 function must be triggered multiple times during the authentication vector generation period, or by inputting the required number of RAND to the f4 function. This may require the network (SN/VLR) to send the required number of RANDs and AUTNs to the UE, and the UE may need to generate an RES for each RAND, and return all generated RES to the network, as described above for the case of a RAND+AUTN .
The embodiments of the present invention can be used in any system that implements non-encrypted signaling in at least two parallel radio bearers and utilizes integrity checksums.
The embodiments of the present invention have been described in a wireless cellular communication network. However, alternative embodiments of the present invention can be used in other types of wireless communication networks. The embodiments of the present invention can also be used in any form of communication in which multiple parallel radio bearers are provided for integrity checking and the like.
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN102714794A | Cited by | China | Search report |
41 members in 15 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 0004178 | United Kingdom | A | |
| 0004178 | United Kingdom | A | |
| 00041780 | United Kingdom | – | |
| 00041780 | – | – | – |
| GB20000004178 | – | – | – |
Members41
| Document | Office | Kind | |
|---|---|---|---|
| GB0004178D0 | United Kingdom | D0 | |
| CA2368530A1 | Canada | A1 | |
| WO0163954A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2848501A | Australia | A | |
| EP1169880A1 | European Patent Office (EPO) | A1 | |
| US2002044552A1 | United States of America | A1 | |
| IL145606D0 | Israel | D0 | |
| CN1363195A | China | A | |
| JP2003524353A | Japan | A | |
| AU772195B2 | Australia | B2 | |
| EP1432271A2 | European Patent Office (EPO) | A2 | |
| CN1156196CThis record | China | C | |
| EP1432271A3 | European Patent Office (EPO) | A3 | |
| AU772195C | Australia | C | |
| EP1169880B1 | European Patent Office (EPO) | B1 | |
| AT306798T | Austria | T | |
| ATE306798T1 | Austria | T1 | |
| JP3742772B2 | Japan | B2 | |
| DE60113925D1 | Germany | D1 | |
| US7009940B2 | United States of America | B2 | |
| ES2249455T3 | Spain | T3 | |
| DE60113925T2 | Germany | T2 | |
| US2006159031A1 | United States of America | A1 | |
| IL145606A | Israel | A | |
| IL175752D0 | Israel | D0 | |
| CA2368530C | Canada | C | |
| EP1432271B1 | European Patent Office (EPO) | B1 | |
| AT472909T | Austria | T | |
| ATE472909T1 | Austria | T1 | |
| DE60142494D1 | Germany | D1 | |
| PT1432271E | Portugal | E | |
| ES2346435T3 | Spain | T3 | |
| DK1432271T3 | Denmark | T3 | |
| DK1432271T5 | Denmark | T5 | |
| IL175752A | Israel | A | |
| US8014307B2 | United States of America | B2 | |
| US2012051225A1 | United States of America | A1 | |
| US8774032B2 | United States of America | B2 | |
| US2014323091A1 | United States of America | A1 | |
| CY1111052T1 | Cyprus | T1 | |
| US10187794B2 | United States of America | B2 |
7 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Expiry of patent termCX01 | CX01 | |
| Transfer of patent application or patent right or utility modelC41 | C41 | |
| Succession or assignment of patent rightASS | ASS | |
| Transfer of patent application or patent right or utility modelC41 | C41 | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| PublicationC06 | C06 | |
| Entry into substantive examinationC10 | C10 |
Numbers
- Publication
- 1156196
- Publication, DOCDB
- 1156196
- Publication, EPODOC
- CN1156196C
- Application
- 18002870
- Application, DOCDB
- 01800287
- Application, EPODOC
- CN2001800287
Titles2
- Chinese
- 通信系统中的完整性检验
- English
- Integrity check in communication system
Classification
- CPC, 7
- H04W12/06
- H04L63/0869
- H04L63/123
- H04W12/10
- H04W76/11
- H04W12/037
- H04W12/02
- IPC, 4
- H04M3 42
- H04L9 16
- H04L9 18
- H04W12 00