Security reconfiguration in a universal mobile telecommunications system
Abstract
The invention protects the security of a communication between a mobile radio and a radio access network (RAN). A connection is established through the RAN to support a communication with the mobile radio. The connection is configured with a first security configuration. One or more messages are sent over the connection using the first security configuration, each message having a message sequence number. When the connection needs to be configured to a second security configuration, an activation message sequence number associated with the reconfiguration is set. When the reconfiguration process is complete and the second security configuration is to be activated, the next message is sent over the connection with the activation message sequence number. Until that time and during the reconfiguration, when the mobile radio transmits a message with a message sequence number lower than the activation message sequence number to the RAN, it uses the first security configuration. An example of such a message is a cell update message or an area update message.

Term
Term ended
Expired 8 November 2022, 3.9 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
44 claims: 44 independent, 0 dependent
- 1A method for protecting the security of a communication between a mobile radio and a radio access network (RAN) including establishing a connection through the RAN to support a communication with the mobile radio, characterized by:configuring the connection with a first security configuration;sending one or more messages over the connection using the first security connection, each message having a message sequence number;determining a need to reconfigure the connection to a second security configuration;setting an activation message sequence number associated with the reconfiguration;andwhen the second security configuration is to be activated, sending a next message with the activation message sequence number. Procédé pour protéger la sécurité d'une communication entre une radio mobile et un réseau d'accès radio (RAN) incluant l'établissement d'une connexion par l'intermédiaire du RAN afin de supporter une communication avec la radio mobile, caractérisé par : la configuration de la connexion à l'aide d'une première configuration de sécurité ;l'envoi d'un ou de plusieurs messages sur la connexion en utilisant la première connexion de sécurité, chaque message présentant un numéro de séquence de message ;la détermination de la nécessité de reconfigurer la connexion selon une seconde configuration de sécurité ;l'établissement d'un numéro de séquence de message d'activation associé à la reconfiguration ;etlorsque la seconde configuration de sécurité doit être activée, l'envoi d'un prochain message avec le numéro de séquence de message d'activation. Verfahren zum Schutz der Sicherheit einer Kommunikation zwischen einem Mobilfunkgerät und einem Funkzugangsnetzwerk (RAN) einschließlich der Einrichtung einer Verbindung über das RAN, um eine Kommunikation mit dem Mobilfunkgerät zu unterstützen, gekennzeichnet durch die folgenden Schritte: Konfigurieren der Verbindung mit einer ersten Sicherheitskonfiguration;Senden einer oder mehrerer Nachrichten über die Verbindung unter Verwendung der ersten Sicherheitsverbindung, wobei jede Nachricht eine Nachrichtenfolgenummer hat;Bestimmen eines Bedarfs, die Verbindung zu einer zweiten Sicherheitskonfiguration zu rekonfigurieren;Festlegen einer Aktivierungs-Nachrichtenfolgenummer, die der Rekonfiguration zugeordnet ist;undwenn eine zweite Sicherheitskonfiguration aktiviert werden soll, Senden einer nächsten Nachricht mit der Aktivierungs-Nachrichtenfolgenummer.
- 2Procédé selon la revendication 1, dans lequel, lorsque la seconde configuration de sécurité est activée, des messages suivants sont envoyés en utilisant la seconde configuration de sécurité. The method in claim 1, wherein when the second security configuration is activated, subsequent messages are sent using the second security configuration. Verfahren nach Anspruch 1, wobei, wenn die zweite Sicherheitskonfiguration aktiviert wird, nachfolgende Nachrichten unter Verwendung der zweiten Sicherheitskonfiguration gesendet werden.
- 3Procédé selon la revendication 2, dans lequel le prochain message est envoyé en utilisant la seconde configuration de sécurité. The method in claim 2, wherein the next message is sent using the second security configuration. Verfahren nach Anspruch 2, wobei die nächste Nachricht unter Verwendung der zweiten Sicherheitskonfiguration gesendet wird.
- 4Procédé selon la revendication 1, dans lequel, pendant la reconfiguration, la radio mobile transmet un message présentant un numéro de séquence de message qui est inférieur au numéro de séquence de message d'activation au RAN en utilisant la première configuration de sécurité. The method in claim 1, wherein during the reconfiguration, the mobile radio transmits a message with a message sequence number lower than the activation message sequence number to the RAN using the first security configuration. Verfahren nach Anspruch 1, wobei das Mobilfunkgerät während der Rekonfiguration unter Verwendung der ersten Sicherheitskonfiguration eine Nachricht mit einer Nachrichtenfolgenummer an das RAN sendet, die niedriger als die Aktivierungs-Nachrichtenfolgenummer ist.
- 5Procédé selon la revendication 4, dans lequel le message qui est transmis par la radio mobile est un message de mise à jour de cellule ou un message de mise à jour de zone. The method in claim 4, wherein the message transmitted by the mobile radio is a cell update message or an area update message. Verfahren nach Anspruch 4, wobei die durch das Mobilfunkgerät übertragene Nachricht eine Zellenaktualisierungsnachricht oder eine Bereichsaktualisierungsnachricht ist.
- 6Procédé selon la revendication 1, dans lequel la première configuration de sécurité correspond à une première connexion qui est associée à une session qui met en jeu la radio mobile et la seconde configuration de sécurité correspond à une seconde connexion qui est associée à la session. The method in claim 1, wherein the first security configuration corresponds to a first connection associated with a session involving the mobile radio and the second security configuration corresponds to a second connection associated with the session. Verfahren nach Anspruch 1, wobei die erste Sicherheitskonfiguration einer ersten Verbindung entspricht, die einer das Mobilfunkgerät miteinbeziehenden Sitzung zugeordnet ist, und die zweite Sicherheitskonfiguration einer zweiten Verbindung entspricht, die der Sitzung zugeordnet ist.
- 7Procédé selon la revendication 6, dans lequel la session est une session multimédia et la première connexion se rapporte à un type de média et la seconde connexion se rapporte à un autre type de média. The method in claim 6, wherein the session is a multimedia session, and the first connection relates to one type of media and the second connection relates to another type of media. Verfahren nach Anspruch 6, wobei die Sitzung eine Multimedia-Sitzung ist und die erste Verbindung sich auf einen Medientyp bezieht und die zweite Verbindung sich auf einen anderen Medientyp bezieht.
- 8Procédé selon la revendication 1, dans lequel la configuration de sécurité se rapporte à une protection d'intégrité du message. The method in claim 1, wherein the security configuration relates to integrity protection of the message. Verfahren nach Anspruch 1, wobei die Sicherheitskonfiguration sich auf den Integritätsschutz der Nachricht bezieht.
- 9Procédé selon la revendication 8, dans lequel le message inclut un message de commande qui est rapporté à la connexion. The method in claim 8, wherein the message includes a control message related to the connection. Verfahren nach Anspruch 8, wobei die Nachricht eine Steuerungsnachricht aufweist, die sich auf die Verbindung bezieht.
- 10Procédé selon la revendication 9, dans lequel la première configuration de sécurité inclut une première clé de protection d'intégrité qui est utilisée pour authentifier le signal de commande et la seconde configuration de sécurité inclut une seconde clé de protection d'intégrité qui est utilisée pour authentifier le signal de commande. The method in claim 9, wherein the first security configuration includes a first integrity protection key used to authenticate the control signal, and the second security configuration includes a second integrity protection key used to authenticate the control signal. Verfahren nach Anspruch 9, wobei die erste Sicherheitskonfiguration einen ersten Integritätsschutzschlüssel aufweist, der verwendet wird, um das Steuerungssignal zu authentifizieren, und die zweite Sicherheitskonfiguration einen zweiten Integritätsschutzschlüssel aufweist, der verwendet wird, um das Steuerungssignal zu authentifizieren.
- 11Procédé selon la revendication 1, dans lequel la configuration de sécurité se rapporte à une protection de confidentialité de la communication et la communication inclut un trafic de données rapporté à la connexion. The method in claim 1, wherein the security configuration relates to confidentiality protection of the communication, and the communication includes data traffic related to the connection. Verfahren nach Anspruch 1, wobei die Sicherheitskonfiguration sich auf den Vertraulichkeitsschutz der Kommunikation bezieht und die Kommunikation Datenverkehr aufweist, der sich auf die Verbindung bezieht.
- 12Procédé selon la revendication 11, dans lequel la première configuration de sécurité inclut une première clé de cryptage qui est utilisée pour crypter le trafic de données et la seconde configuration de sécurité inclut une seconde clé de cryptage qui est utilisée pour crypter le trafic de données. The method in claim 11, wherein the first security configuration includes a first encryption key used to encrypt the data traffic, and the second security configuration includes a second encryption key used to encrypt the data traffic. Verfahren nach Anspruch 11, wobei die erste Sicherheitskonfiguration einen ersten Verschlüsselungsschlüssel aufweist, der verwendet wird, um den Datenverkehr zu verschlüsseln, und die zweite Sicherheitskonfiguration einen zweiten Verschlüsselungsschlüssel aufweist, der verwendet wird, um den Datenverkehr zu verschlüsseln.
- 13Procédé selon la revendication 1, comprenant en outre :la fixation du numéro de séquence de message d'activation en utilisant un nombre maximum de réémissions d'un message. The method in claim 1, further comprising: setting the activation message sequence number using a maximum number of retransmissions of a message. Verfahren nach Anspruch 1, ferner mit dem Schritt: Festlegen der Aktivierungs-Nachrichtenfolgenummer unter Verwendung einer Höchstzahl von Übertragungswiederholungen einer Nachricht.
- 14Procédé selon la revendication 13, dans lequel le message est un message de mise à jour de cellule ou un message de mise à jour de zone qui est transmis par la radio mobile au RAN. The method in claim 13, wherein the message is a cell update message or an area update message transmitted by the mobile radio to the RAN. Verfahren nach Anspruch 13, wobei die Nachricht eine Zellenaktualisierungsnachricht oder eine Bereichsaktualisierungsnachricht ist, die durch das Mobilfunkgerät an das RAN übertragen wird.
- 15Procédé selon la revendication 1, dans lequel le numéro de séquence de message d'activation correspond à un numéro de séquence de message futur qui est supérieur à un prochain numéro de séquence de message. The method in claim 1, wherein the activation message sequence number corresponds to a future message sequence number greater than a next message sequence number. Verfahren nach Anspruch 1, wobei die Aktivierungs-Nachrichtenfolgenummer einer künftigen Nachrichtenfolgenummer entspricht, die größer als eine nächste Nachrichtenfolgenummer ist.
- 16Procédé selon la revendication 1, dans lequel l'étape d'envoi est réalisée pour appliquer la seconde configuration de sécurité même lorsque le numéro de séquence de message d'activation de messages n'a pas été transmis à l'instant où la configuration de sécurité est achevée. The method in claim 1, wherein the sending step is performed to apply the second security configuration even when the activation message sequence number of messages has not been transmitted at the time that the security reconfiguration is completed. Verfahren nach Anspruch 1, wobei der Sendeschritt durchgeführt wird, um die zweite Sicherheitskonfiguration auch dann anzuwenden, wenn die Aktivierungs-Nachrichtenfolgenummer von Nachrichten zu dem Zeitpunkt, wo die Sicherheits-Rekonfiguration abgeschlossen ist, nicht übertragen worden ist.
- 17A mobile radio (12) configured to communicate with an entity via a connection established through a radio access network (RAN) (14), comprising radio transceiving circuitry (32) and data processing circuitry (30) characterized in that the data processing circuitry (30) is configured to perform the following tasks:establish a first security configuration for the connection;send one or more messages over the connection using the first security connection, each message having a message sequence number;determine if the connection is to be reconfigured to a second security configuration;determine an activation message sequence number associated with the reconfiguration;andwhen the second security configuration is to be activated, send a next message with the activation message sequence number. Mobilfunkgerät (12), das dafür konfiguriert ist, mit einer Instanz über eine durch ein Funkzugangsnetzwerk (RAN) (14) eingerichtete Verbindung zu kommunizieren, mit einer Funk-Sende/Empfangsschaltungsanordnung (32) und einer Datenverarbeitungsschaltungsanordnung (30), dadurch gekennzeichnet, daß die Datenverarbeitungsschaltungsanordnung (30) dafür konfiguriert ist, die folgenden Aufgaben durchzuführen: Einrichten einer ersten Sicherheitskonfiguration für die Verbindung;Senden einer oder mehrerer Nachrichten über die Verbindung unter Verwendung der ersten Sicherheitsverbindung, wobei jede Nachricht eine Nachrichtenfolgenummer hat;Bestimmen, ob die Verbindung zu einer zweiten Sicherheitskonfiguration rekonfiguriert werden soll;Bestimmen einer Aktivierungs-Nachrichtenfolgenummer, die der Rekonfiguration zugeordnet ist;undwenn eine zweite Sicherheitskonfiguration aktiviert werden soll, Senden einer nächsten Nachricht mit der Aktivierungs-Nachrichtenfolgenummer. Radio mobile (12) qui est configurée pour communiquer avec une entité via une connexion qui est établie par l'intermédiaire d'un réseau d'accès radio (RAN) (14), comprenant un circuit d'émetteur-récepteur radio (32) et un circuit de traitement de données (30), caractérisée en ce que le circuit de traitement de données (30) est configuré pour réaliser les tâches qui suivent : établissement d'une première configuration de sécurité pour la connexion ;envoi d'un ou de plusieurs messages sur la connexion en utilisant la première configuration de sécurité, chaque message présentant un numéro de séquence de message ;détermination si la connexion doit être reconfigurée selon une seconde configuration de sécurité ;détermination d'un numéro de séquence de message d'activation associé à la reconfiguration ;etlorsque la seconde configuration de sécurité doit être activée, envoi d'un prochain message avec le numéro de séquence de message d'activation.
- 18Mobilfunkgerät nach Anspruch 17, wobei, wenn die zweite Sicherheitskonfiguration aktiviert ist, die durch das Mobilfunkgerät gesendete und empfangene nachfolgende Nachrichten die zweite Sicherheitskonfiguration verwenden. Radio mobile selon la revendication 17, dans laquelle, lorsque la seconde configuration de sécurité est activée, des messages suivants qui sont envoyés et reçus par la radio mobile utilisent la seconde configuration de sécurité. The mobile radio in claim 17, wherein when the second security configuration is activated, subsequent messages sent and received by the mobile radio use the second security configuration.
- 19Mobilfunkgerät nach Anspruch 18, wobei die Datenverarbeitungsschaltungsanordnung (30) dafür konfiguriert ist, die nächste Nachricht unter Verwendung der zweiten Sicherheitskonfiguration zu senden. Radio mobile selon la revendication 18, dans laquelle le circuit de traitement de données (30) est configuré pour transmettre le prochain message en utilisant la seconde configuration de sécurité. The mobile radio in claim 18, wherein the data processing circuitry (30) is configured to transmit the next message using the second security configuration.
- 20Mobilfunkgerät nach Anspruch 19, wobei die Datenverarbeitungsschaltungsanordnung (30) dafür konfiguriert ist, während der Rekonfiguration unter Verwendung der ersten Sicherheitskonfiguration eine Nachricht mit einer Nachrichtenfolgenummer an das RAN zu senden, die niedriger als die Aktivierungs-Nachrichtenfolgenummer ist. Radio mobile selon la revendication 19, dans laquelle, pendant la reconfiguration, le circuit de traitement de données (30) est configuré pour transmettre un message avec un numéro de séquence de message qui est inférieur au numéro de séquence de message d'activation au RAN en utilisant la première configuration de sécurité. The mobile radio in claim 19, wherein during the reconfiguration, the data processing circuitry (30) is configured to transmit a message with a message sequence number lower than the activation message sequence number to the RAN using the first security configuration.
- 21Mobilfunkgerät nach Anspruch 20, wobei die durch das Mobilfunkgerät übertragene Nachricht eine Zellenaktualisierungsnachricht oder eine Bereichsaktualisierungsnachricht ist. Radio mobile selon la revendication 20, dans laquelle le message qui est transmis par la radio mobile est un message de mise à jour de cellule ou un message de mise à jour de zone. The mobile radio in claim 20, wherein the message transmitted by the mobile radio is a cell update message or an area update message.
- 22Mobilfunkgerät nach Anspruch 17, wobei die erste Sicherheitskonfiguration einer ersten Verbindung entspricht, die einer das Mobilfunkgerät miteinbeziehenden Sitzung zugeordnet ist, und die zweite Sicherheitskonfiguration einer zweiten Verbindung entspricht, die der Sitzung zugeordnet ist. Radio mobile selon la revendication 17, dans laquelle la première configuration de sécurité correspond à une première connexion qui est associée à une session qui met en jeu la radio mobile et la seconde configuration de sécurité correspond à une seconde connexion qui est associée à la session. The mobile radio in claim 17, wherein the first security configuration corresponds to a first connection associated with a session involving the mobile radio and the second security configuration corresponds to a second connection associated with the session.
- 23Mobilfunkgerät nach Anspruch 22, wobei die Sitzung eine Multimedia-Sitzung ist und die erste Verbindung sich auf einen Medientyp bezieht und die zweite Verbindung sich auf einen anderen Medientyp bezieht. Radio mobile selon la revendication 22, dans laquelle la session est une session multimédia et la première connexion se rapporte à un type de média et la seconde connexion se rapporte à un autre type de média. The mobile radio in claim 22, wherein the session is a multimedia session, and the first connection relates to one type of media and the second connection relates to another type of media.
- 24Mobilfunkgerät nach Anspruch 17, wobei die Sicherheitskonfiguration sich auf den Integritätsschutz der Nachricht bezieht und die Nachricht eine Steuerungsnachricht aufweist, die sich auf die Verbindung bezieht. Radio mobile selon la revendication 17, dans laquelle la configuration de sécurité se rapporte à une protection d'intégrité du message et le message inclut un message de commande rapporté à la connexion. The mobile radio in claim 17, wherein the security configuration relates to integrity protection of the message, and the message includes a control message related to the connection.
- 25Mobilfunkgerät nach Anspruch 24, wobei die erste Sicherheitskonfiguration einen ersten Integritätsschutzschlüssel aufweist, der verwendet wird, um das Steuerungssignal zu authentifizieren, und die zweite Sicherheitskonfiguration einen zweiten Integritätsschutzschlüssel aufweist, der verwendet wird, um das Steuerungssignal zu authentifizieren. Radio mobile selon la revendication 24, dans laquelle la première configuration de sécurité inclut une première clé de protection d'intégrité utilisée pour authentifier le signal de commande et la seconde configuration de sécurité inclut une seconde clé de protection d'intégrité utilisée pour authentifier le signal de commande. The mobile radio in claim 24, wherein the first security configuration includes a first integrity protection key used to authenticate the control signal, and the second security configuration includes a second integrity protection key used to authenticate the control signal.
- 26Mobilfunkgerät nach Anspruch 17, wobei die Sicherheitskonfiguration sich auf den Vertraulichkeitsschutz der Kommunikation bezieht und die Kommunikation Datenverkehr aufweist, der sich auf die Verbindung bezieht. Radio mobile selon la revendication 17, dans laquelle la configuration de sécurité se rapporte à une protection de confidentialité de la communication et la communication inclut un trafic de données rapporté à la connexion. The mobile radio in claim 17, wherein the security configuration relates to confidentiality protection of the communication, and the communication includes data traffic related to the connection.
- 27Mobilfunkgerät nach Anspruch 26, wobei die erste Sicherheitskonfiguration einen ersten Verschlüsselungsschlüssel aufweist, der verwendet wird, um den Datenverkehr zu verschlüsseln, und die zweite Sicherheitskonfiguration einen zweiten Verschlüsselungsschlüssel aufweist, der verwendet wird, um den Datenverkehr zu verschlüsseln. Radio mobile selon la revendication 26, dans laquelle la première configuration de sécurité inclut une première clé de cryptage qui est utilisée pour crypter le trafic de données et la seconde configuration de sécurité inclut une seconde clé de cryptage qui est utilisée pour crypter le trafic de données. The mobile radio in claim 26, wherein the first security configuration includes a first encryption key used to encrypt the data traffic, and the second security configuration includes a second encryption key used to encrypt the data traffic.
- 28Mobilfunkgerät nach Anspruch 17, wobei die Datenverarbeitungsschaltungsanordnung (30) dafür konfiguriert ist, die Aktivierungs-Nachrichtenfolgenummer unter Verwendung einer Höchstzahl von Übertragungswiederholungen einer Nachricht festzulegen. Radio mobile selon la revendication 17, dans laquelle le circuit de traitement de données (30) est configuré pour établir le numéro de séquence de message d'activation en utilisant un nombre maximum de réémissions d'un message. The mobile radio in claim 17, wherein the data processing circuitry (30) is configured to set the activation message sequence number using a maximum number of retransmissions of a message.
- 29Mobilfunkgerät nach Anspruch 28, wobei die Nachricht eine Zellenaktualisierungsnachricht oder eine Bereichsaktualisierungsnachricht ist, die durch das Mobilfunkgerät an das RAN übertragen wird. Radio mobile selon la revendication 28, dans laquelle le message est un message de mise à jour de cellule ou un message de mise à jour de zone qui est transmis par la radio mobile au RAN. The mobile radio in claim 28, wherein the message is a cell update message or an area update message transmitted by the mobile radio to the RAN.
- 30Mobilfunkgerät nach Anspruch 17, wobei die Aktivierungs-Nachrichtenfolgenummer einer künftigen Nachrichtenfolgenummer entspricht, die größer als eine nächste Nachrichtenfolgenummer ist. Radio mobile selon la revendication 17, dans laquelle le numéro de séquence de message d'activation correspond à un numéro de séquence de message futur qui est supérieur à un prochain numéro de séquence de message. The mobile radio in claim 17, wherein the activation message sequence number corresponds to a future message sequence number greater than a next message sequence number.
- 31Mobilfunkgerät nach Anspruch 17, wobei die Datenverarbeitungsschaltungsanordnung (30) dafür konfiguriert ist, die zweite Sicherheitskonfiguration auch dann anzuwenden, wenn die Aktivierungsnummer von Nachrichten zu dem Zeitpunkt, wo die Sicherheits-Rekonfiguration abgeschlossen ist, nicht übertragen worden ist. Radio mobile selon la revendication 17, dans laquelle le circuit de traitement de données (30) est configuré pour appliquer la seconde configuration de sécurité même lorsque le numéro d'activation de messages n'a pas été transmis lorsque la reconfiguration de sécurité est achevée. The mobile radio in claim 17, wherein the data processing circuitry (30) is configured to apply the second security configuration even when the activation number of messages has not been transmitted when the security reconfiguration is completed.
- 32A radio access network (RAN) node (26) for establishing a mobile radio (12) connection through the RAN (14) to support communications involving the mobile radio, characterized by data processing circuitry (40) configured to perform the following functions:establish a first security configuration parameters for the connection;send or receive one or more messages over the connection using the first security connection, each message having a message sequence number;determine if the connection is to be reconfigured to a second security configuration;send a security configuration change message to the mobile radio;detect a next message from the mobile radio with an activation message sequence number;andupon detecting the next message, activate the second security configuration for the connection. Funkzugangsnetzwerk-(RAN-)Knoten (26) zur Herstellung einer Verbindung eines Mobilfunkgeräts (12) durch das RAN (14), um Kommunikationen zu unterstützen, die das Mobilfunkgerät miteinbeziehen, gekennzeichnet durch eine Datenverarbeitungsschaltungsanordnung (40), die dafür konfiguriert ist, die folgenden Funktionen auszuführen: Einrichten von Parametern einer ersten Sicherheitskonfiguration für die Verbindung;Senden oder Empfangen einer oder mehrerer Nachrichten über die Verbindung unter Verwendung der ersten Sicherheitsverbindung, wobei jede Nachricht eine Nachrichtenfolgenummer hat;Bestimmen, ob die Verbindung zu einer zweiten Sicherheitskonfiguration rekonfiguriert werden soll;Senden einer Sicherheitskonfigurations-Änderungsnachricht an das Mobilfunkgerät;Detektieren einer nächsten Nachricht vom Mobilfunkgerät mit einer Aktivierungs-Nachrichtenfolgenummer;undnach Detektion der nächsten Nachricht, Aktivieren der zweiten Sicherheitskonfiguration für die Verbindung. Noeud de réseau d'accès radio (RAN) (26) pour établir une connexion de radio mobile (12) par l'intermédiaire du RAN (14) afin de supporter des communications qui mettent en jeu la radio mobile, caractérisé par un circuit de traitement de données (40) qui est configuré pour réaliser les fonctions qui suivent : établissement de paramètres d'une première configuration de sécurité pour la connexion ;envoi ou réception d'un ou de plusieurs messages à travers la connexion en utilisant la première connexion de sécurité, chaque message présentant un numéro de séquence de message ;détermination si la connexion doit être reconfigurée selon une seconde configuration de sécurité ;envoi d'un message de changement de configuration de sécurité sur la radio mobile ;détection d'un prochain message à partir de la radio mobile avec un numéro de séquence de message d'activation ;etsuite à la détection du prochain message, activation de la seconde configuration de sécurité pour la connexion.
- 33Noeud de RAN selon la revendication 32, dans lequel, lorsque la seconde configuration de sécurité est activée, des messages suivants sont envoyés en utilisant la seconde configuration de sécurité. RAN-Knoten nach Anspruch 32, wobei, wenn die zweite Sicherheitskonfiguration aktiviert ist, nachfolgende Nachrichten unter Verwendung der zweiten Sicherheitskonfiguration gesendet werden. The RAN node in claim 32, wherein when the second security configuration is activated, subsequent messages are sent using the second security configuration.
- 34Noeud de RAN selon la revendication 33, dans lequel le message suivant est envoyé en utilisant la seconde configuration de sécurité. RAN-Knoten nach Anspruch 33, wobei die nächste Nachricht unter Verwendung der zweiten Sicherheitskonfiguration gesendet wird. The RAN node in claim 33, wherein the next message is sent using the second security configuration.
- 35Noeud de RAN selon la revendication 32, dans lequel le circuit de traitement de données (40) est configuré pour transmettre une commande de noeud de sécurité à la radio mobile (12) lorsque la connexion doit être reconfigurée selon la seconde configuration de sécurité. RAN-Knoten nach Anspruch 32, wobei die Datenverarbeitungsschaltungsanordnung (40) dafür konfiguriert ist, einen Sicherheitsmodus-Befehl an das Mobilfunkgerät (12) zu senden, wenn die Verbindung zur zweiten Sicherheitskonfiguration rekonfiguriert werden soll. The RAN node in claim 32, wherein the data processing circuitry (40) is configured to transmit a security mode command to the mobile radio (12) when the connection is to be reconfigured to the second security configuration.
- 36Noeud de RAN selon la revendication 35, dans lequel le circuit de traitement de données (40) est configuré pour détecter un message d'achèvement de mode de sécurité en provenance de la radio mobile (12) en réponse à la commande de mode de sécurité, lequel message inclut le numéro de séquence de message d'activation. RAN-Knoten nach Anspruch 35, wobei die Datenverarbeitungsschaltungsanordnung (40) dafür konfiguriert ist, als Antwort auf den Sicherheitsmodus-Befehl eine Sicherheitsmodus-Abschlussnachricht vom Mobilfunkgerät (12) zu detektieren, die die Aktivierungs-Nachrichtenfolgenummer aufweist. The RAN node in claim 35, wherein the data processing circuitry (40) is configured to detect a security mode complete message from the mobile radio (12), in response to the security mode command, that includes the activation message sequence number.
- 37Noeud de RAN selon la revendication 36, dans lequel le circuit de traitement de données (40) est configuré pour transmettre un message d'accusé de réception d'achèvement de mode de sécurité à la radio mobile (12) pour signaler à la radio mobile (12) que la reconfiguration de sécurité est achevée. RAN-Knoten nach Anspruch 36, wobei die Datenverarbeitungsschaltungsanordnung (40) dafür konfiguriert ist, eine Sicherheitsmodus-Abschlussbestätigungsnachricht an das Mobilfunkgerät (12) zu übertragen, um dem Mobilfunkgerät (12) zu signalisieren, daß die Sicherheits-Rekonfiguration abgeschlossen ist. The RAN node in claim 36, wherein the data processing circuitry (40) is configured to transmit a security mode complete acknowledge message to the mobile radio (12) to signal to the mobile radio (12) that the security reconfiguration is complete.
- 38Noeud de RAN selon la revendication 32, dans lequel le circuit de traitement de données (40) est configuré pour détecter, pendant la reconfiguration, un message en provenance de la radio mobile (12) présentant un numéro de séquence de message qui est inférieur au numéro de séquence de message d'activation sur le RAN en utilisant la première configuration de sécurité. RAN-Knoten nach Anspruch 32, wobei die Datenverarbeitungsschaltungsanordnung (40) dafür konfiguriert ist, während der Rekonfiguration eine Nachricht vom Mobilfunkgerät (12) an das RAN mit einer Nachrichtenfolgenummer, die niedriger als die Aktivierungs-Nachrichtenfolgenummer ist, unter Verwendung der ersten Sicherheitskonfiguration zu detektieren. The RAN node in claim 32, wherein the data processing circuitry (40) is configured to detect during the reconfiguration, a message from the mobile radio (40) having a message sequence number lower than the activation message sequence number to the RAN using the first security configuration.
- 39Noeud de RAN selon la revendication 38, dans lequel le message qui est transmis par la radio mobile (12) est un message de mise à jour de cellule ou un message de mise à jour de zone. RAN-Knoten nach Anspruch 38, wobei die durch das Mobilfunkgerät (12) übertragene Nachricht eine Zellenaktualisierungsnachricht oder eine Bereichsaktualisierungsnachricht ist. The RAN node in claim 38, wherein the message transmitted by the mobile radio (12) is a cell update message or an area update message.
- 40Noeud de RAN selon la revendication 32, dans lequel la configuration de sécurité se rapporte à une protection d'intégrité du message, et le message inclut un message de commande qui est rapporté à la connexion. RAN-Knoten nach Anspruch 32, wobei die Sicherheitskonfiguration sich auf den Integritätsschutz der Nachricht bezieht und die Nachricht eine Steuerungsnachricht aufweist, die sich auf die Verbindung bezieht. The RAN node in claim 32, wherein the security configuration relates to integrity protection of the message, and the message includes a control message related to the connection.
- 41Noeud de RAN selon la revendication 40, dans lequel la première configuration de sécurité inclut une première clé de protection d'intégrité qui est utilisée pour authentifier le signal de commande et la seconde configuration de sécurité inclut une seconde clé de protection d'intégrité qui est utilisée pour authentifier le signal de commande. RAN-Knoten nach Anspruch 40, wobei die erste Sicherheitskonfiguration einen ersten Integritätsschutzschlüssel aufweist, der verwendet wird, um das Steuerungssignal zu authentifizieren, und die zweite Sicherheitskonfiguration einen zweiten Integritätsschutzschlüssel aufweist, der verwendet wird, um das Steuerungssignal zu authentifizieren. The RAN node in claim 40, wherein the first security configuration includes a first integrity protection key used to authenticate the control signal, and the second security configuration includes a second integrity protection key used to authenticate the control signal.
- 42Noeud de RAN selon la revendication 32, dans lequel la configuration de sécurité se rapporte à une protection de confidentialité de la communication et la communication inclut un trafic de données rapporté à la connexion. RAN-Knoten nach Anspruch 32, wobei die Sicherheitskonfiguration sich auf den Vertraulichkeitsschutz der Kommunikation bezieht und die Kommunikation Datenverkehr aufweist, der sich auf die Verbindung bezieht. The RAN node in claim 32, wherein the security configuration relates to confidentiality protection of the communication, and the communication includes data traffic related to the connection.
- 43Noeud de RAN selon la revendication 42, dans lequel la première configuration de sécurité inclut une première clé de cryptage qui est utilisée pour crypter le trafic de données et la seconde configuration de sécurité inclut une seconde clé de cryptage qui est utilisée pour crypter le trafic de données. RAN-Knoten nach Anspruch 42, wobei die erste Sicherheitskonfiguration einen ersten Verschlüsselungsschlüssel aufweist, der verwendet wird, um den Datenverkehr zu verschlüsseln, und die zweite Sicherheitskonfiguration einen zweiten Verschlüsselungsschlüssel aufweist, der verwendet wird, um den Datenverkehr zu verschlüsseln. The RAN node in claim 42, wherein the first security configuration includes a first encryption key used to encrypt the data traffic, and the second security configuration includes a second encryption key used to encrypt the data traffic.
- 44Noeud de RAN selon la revendication 32, dans lequel le numéro de séquence de message d'activation correspond à un numéro de séquence de message futur qui est supérieur à un prochain numéro de séquence de message. RAN-Knoten nach Anspruch 32, wobei die Aktivierungs-Nachrichtenfolgenummer einer künftigen Nachrichtenfolgenummer entspricht, die größer als eine nächste Nachrichtenfolgenummer ist. The RAN node in claim 32, wherein the activation message sequence number corresponds to a future message sequence number greater than a next message sequence number.
Independent claims44
33 paragraphs in 5 sections, as filed
PRIORITY APPLICATION
This application claims priority from U.S. provisional patent application number 60/333,485, filed on November 28, 2001.
FIELD OF THE INVENTION
The present invention relates to Universal Mobile Telecommunications System (UMTS) communications, and more particularly, to security functions in a UMTS.
BACKGROUND AND SUMMARY OF THE INVENTION
An example communication system is the Universal Mobile Telecommunications System (UMTS) described in the 3GPP specification as well as other communications systems. A simplified, example architecture for a UMTS system is illustrated in Fig. 1 and includes a user equipment (UE) 12 which communicates over an air/radio interface <i>U</i><sub><i>u</i></sub> with a radio access network (RAN) 14 sometimes referred to as a UMTS Terrestrial Radio Access Network (UTRAN). The RAN 14 communicates with one or more core networks 16. In Fig. 1, a circuit-switched core network 18 and a packet-switched core network 20 both communicate with the RAN 14 over respective <i>I</i><sub><i>u</i></sub> - <i>PS</i> interfaces.
A more detailed illustration of a UTRAN 22 is shown in Fig. 2. The UTRAN 22 includes one or more radio network systems (RNS) 24. Each RNS 24 includes one or more radio network controllers (RNC) 26. RNCs communicate over an <i>I</i><sub><i>ur</i></sub> interface. Each RNC is coupled to one or more base stations, each of which is referred to in the UTRAN as a node B 28. The RNC and each node B communicate over an interface <i>I</i><sub><i>ub</i></sub>. Each node B conducts radio communications via one or more cells with various UEs. In Fig. 2, each node B 28 is shown with three cells C1-C3.
Fig. 3 shows the UTRAN radio protocol architecture with more detailed information regarding the same available in the 3GPP TS25.301. The protocol architecture is divided into five layers including an application layer, a transport layer, a radio resource control (RRC) layer, a link layer, and a physical layer. The left side of the protocol stack from the RRC layer and below represents the control plane where control signaling is conducted. The right side of the protocol stack represents the user plane where user traffic is communicated. Information is communicated through the UTRAN using logical channels referred to as radio bearers. On the control plane, the radio bearers are called signal radio bearers and may include, for example, signaling radio bearers 0-4. In the user plane, other radio bearers such as radio bearers 5-31 are used to carry user traffic. These bearers are then transported on physical transport channels over the physical layer/radio interface. More details regarding the radio access bearer service provided by the UTRAN may be found in 3GPP TS 23.107.
While details are provided regarding the UTRAN, other radio access networks exist. One example is the GSM/EDGE radio access network (GERAN) that evolved from GSM to the enhanced data rates for GSM evolution (EDGE). Although the present invention is particularly applicable to the UTRAN, it may be applied in any RAN.
Security functions in a communication system provide some sort of confidentiality and/or authentication for a communication. In UMTS, an example confidentiality security function is ciphering or encryption of user data, and an example authentication security function is integrity protection of control signaling. Control signaling sent between a UE/mobile radio station and the radio network is considered sensitive information whose integrity must be protected. In regard to control signaling integrity protection, reference is made to the 3GPP specification TS 33.102, and in particular, to section 6.5 that relates to access link integrity.
Ciphering/encrypting may be performed for user traffic. Ciphering is performed in the user plane either at the radio link control (RLC) sublayer of the link layer, i.e., if the RLC mode is acknowledged or unacknowledged, or in the media access control (MAC) sublayer, i.e., if the mode is RLC transparent mode. Integrity protection/authentication of control signaling is performed in the control plane at the RRC layer. When a connection (which can be viewed as a sort of logical channel) is to be established with a user equipment through the UTRAN, a security mode setup procedure is performed to protect the integrity of control signaling messages sent between the UE and the UTRAN. Examples of control signaling messages include paging messages, handover messages, RRC connection request, setup, and release messages, system broadcast information messages, etc.
Different algorithms may be used to cipher/encrypt user data and to protect the integrity of control signaling. A ciphering algorithm may generate a ciphering key (CK). One example of such a ciphering algorithm is an "f8" algorithm described in 3GPP TS 33.102. Similarly, an integrity/authentication protection algorithm may generate an integrity protection key (IK). One example of such an integrity protection algorithm is an "f9" algorithm described in 3GPP TS 33.102. The pair of "keys" generated by ciphering and integrity protection algorithms is sometimes referred to as a "key set." Recall from Fig. 1 that the UTRAN may be coupled to different core networks such as a circuit-switched network and a packet-switched network. A key pair for a circuit-switched domain may be denoted, (<i>CK</i><sub><i>cs</i></sub>, <i>IK</i><sub><i>cs</i></sub>), and for the packet-switched domain, (<i>CK</i><sub><i>ps</i></sub>, <i>IK</i><sub><i>ps</i></sub>).
When a UE initiates a session (e.g., a multimedia session), a Radio Resource Control (RRC) layer 3 connection is established within the UTRAN. Part of that connection setup includes an authentication procedure where a security configuration is established for a specific core network domain. The security configuration for a core network domain may be broken down into two parts. A first part of the security configuration is from the core network to the UTRAN using an RANAP Security Mode Command message, (see 3GPP TS 25.413). A second part is from the UTRAN to the UE using an RRC Security Mode Command (see 3GPP TS 25.331).
An example procedure for establishing a security configuration between the UTRAN and UE is illustrated in Fig. 4. Initially, the mobile station/user equipment establishes an RRC connection with a serving-RNC (SRNC) in the UTRAN. This connection is initiated for a particular core network domain. For example, the connection might support a web browser application running on the UE, and therefore, the connection would be a packet-switched core network. During the RRC connection establishment, parameter values necessary to establish an initial security configuration for the connection are transferred between the UE and the SRNC along with the UE's security capabilities. The SRNC stores the security configuration values and the UE security capabilities.
The UE sends an initial protocol layer 3 (L3) message including its user identity, (e.g., IMSI), to initiate a connection set-up using a visiting location register (VLR) for a circuit-switched connection or a serving GPRS support node (SGSN) for a packet-switched domain-type connection. Authentication and key generation procedures are performed between the VLR/SGSN and the UE where an integrity and ciphering key pair is generated for the connection and stored by the UE. The VLR/SGSN also decides which integrity and ciphering algorithms may be employed: UIA stands for UMTS integrity algorithm and UEA stands for UMTS encryption algorithm. The VLR/SGSN sends a Security Mode Command to the SRNC to provide the allowed integrity and encryption algorithms (UIAs and UEAs) as well as the integrity key (IK) and ciphering key (CK).
The SRNC selects an appropriate integrity algorithm and encryption algorithm and generates parameters needed for the selected algorithms. An example of such a parameter is a random value generated at the network (referred to as FRESH in the 3GPP spec). The SRNC sends a Security Mode Command to the UE which includes the core network domain, the selected integrity algorithm, and parameters like the random value. The selected integrity algorithm output/result is also sent. That output/result is denoted MAC-I, for Message Authorization Code-Integrity, and is generated as a function of the integrity key (IK), the message whose integrity is to be protected, the random number, a direction of signaling (i.e., uplink or downlink), and a count value corresponding to a message sequence number (MSN) of the current RRC message. The UE verifies this information including generating for itself the MAC-I using the same parameters, and acknowledges that the security mode is complete in messages 9, 10, and 11. Thereafter, ciphering and deciphering as well as authentication of messages for this connection are performed using the configured security parameters.
The current message sequence number (MSN) for integrity protection is referred to in the 3GPP specification as count-I. For each signaling radio bearers 0-4, there is one count-I value per uplink signaling radio bearer and one count-I per downlink signaling radio bearer. Count-I is composed of two parts. A short sequence number forming the least significant bits of the count is a four bit RRC sequence number (RRC SN) and is available in each RRC packet data unit (PDU). The long sequence number is an RRC hyper-frame number (RRC HFN) which is incremented each RRC sequence number cycle. The RRC HFN is initialized in message 1 (START values) as one of the security configuration parameter values.
Accordingly, the signaling radio bearers used to transfer signaling messages from core network service domains are integrity protected by the integrity key of the core network service domain for which the most recent security mode negotiation took place. If additional services are requested, if services are requested from another core network, from the same core network, or if an additional connection is requested, it may be necessary to change the integrity configuration of an already integrity protected, ongoing signaling connection.
An example of such security reconfiguration over the air interface is an RRC security mode control procedure described in 3GPP TS 25.331, section 8.1.12, and illustrated in Fig. 5. The purpose of this procedure is to start/restart ciphering with a new ciphering configuration for data traffic radio bearers, and to start or modify the integrity protection configuration for all control signaling radio bearers. To start or modify the integrity protection configuration, the UTRAN sends a Security Mode Command to the UE. Upon reception of the Security Mode Command, the UE sets an activation value in the uplink direction, and an activation value by the UTRAN is set in the downlink direction for all signaling radio bearers. An activation value is specified for each affected radio bearer. This activation value effectively indicates when the new security/integrity configuration with new integrity and ciphering keys should be used.
In one approach, the UE may set the uplink activation value for a corresponding radio access bearer as the current RRC message sequence number (RRC SN<sub>current</sub>) plus a constant k. Recall that the RRC message sequence number is the four bit value used to stamp each RRC message with a number. The constant, for example, might be determined based on a maximum number of retransmissions of a Cell Update or a routing area Update message transmitted by the UE to the UTRAN. Any such update message is sent in the uplink direction by the UE to the UTRAN on a signaling radio bearer, e.g., RB0. This setting of the activation value until some message is transmitted in the future means that the UE will send update messages using the old security configuration, including the old ciphering and integrity keys starting from the current sequence number message (RRC SN<sub>current</sub>). The old configuration is used until a future message is transmitted having the activation message sequence number (RRC SN<sub>current</sub> + <i>k</i>). Only when the message sequence number reaches (RRC SN<sub>current</sub> + <i>k</i>) will the new security configuration be applied. By setting the activation number to some future message sequence number, the UE can send cell updates and other messages to the UTRAN using the old security configuration even though security reconfiguration is taking place. Cell update messages are particularly important, especially for a fast-moving user equipment, to ensure that the current location of the mobile is known by the UTRAN.
Thus, the benefit of this security configuration procedure is that the cell update and other important messages can be sent with the old security configuration so that the UTRAN can receive such messages while the security reconfiguration process transpires. Unfortunately, a disadvantage with this approach is that the mechanism for indicating use of the new security configuration is flawed.
The problem is the UE needs to send a certain number of CELL UPDATE messages before the new security configuration will be used and the old security configuration will be released. In the example above that time is when the current message received at the UTRAN from the UE has a message sequence number equal to RRC SN<sub>current</sub> + k. This approach assumes that the UE is moving between enough cells so that k CELL UPDATEs will occur in a relatively short period of time. For a non-moving or slow-moving UE, it is likely that such an activation number of cell update messages will not be sent in a reasonable period of time (if ever). As a result, the new security configuration, e.g., for a new UE to core network connection, will not be implemented and the requested new service or connection will not be delivered.
The present invention provides a solution to the problem identified above in an improved method for protecting the security of a communication between a mobile radio and a radio access network (RAN). A connection is established through the RAN to support a communication with the mobile radio. The connection is configured with a first security configuration. One or more messages are sent over the connection using the first security connection, each message having a message sequence number. When it is determined that there is a need to configure the connection to a second security configuration, an activation message sequence number associated with the reconfiguration is set. When the reconfiguration process is complete and the second security configuration is to be activated, the next message is sent over the connection with the activation message sequence number. Until that time and during the reconfiguration, when the mobile radio transmits a message with a message sequence number lower than the activation message sequence number to the RAN, it uses the first security configuration. An example of such a message is a cell update message or an area update message.
The first security configuration corresponds, for example, to a first connection associated with the session involving the mobile radio, and the second security configuration may correspond, for example, to a second connection associated with the session. In a multimedia session, the first connection could relate to one type of media, and the second connection to another type.
The security configuration may relate to integrity protection of a message, where the message includes control signaling related to the connection. The first security configuration may include a first integrity protection key used to authenticate the control signaling. The second security configuration includes a second integrity protection key. The security configuration may also relate to confidentiality protection of the connection. For example, the first security configuration includes a first encryption key used to encrypt data traffic associated with the connection, and the second security configuration includes a second encryption key used to encrypt the data traffic.
The activation message sequence number corresponds to a future message sequence number that is greater than the next message number in the message sequence. In one example, non-limiting embodiment, the activation message sequence number is set using the maximum number of retransmissions of a message. The activation message sequence number is sent with the next message upon completion of the reconfiguration operation, even when the activation number of messages has not yet been transmitted at the time the security reconfiguration is complete. In this way, unnecessary or indefinite delays associated with the security reconfiguration are avoided.
BRIEF DESCRIPTION OF THE DRAWINGS
The foregoing and other objects, features, and advantages of the present invention may be more readily understood with reference to the following description taken in conjunction with the accompanying drawings. <ul id="ul0001" list-style="none"><li>Fig. 1 illustrates a simplified block diagram of an example UMTS communications system in which the present invention may be employed;</li><li>Fig. 2 illustrates additional details of a UTRAN-type of radio access network;</li><li>Fig. 3 illustrates various protocols used in the UTRAN for setting up a connection with a mobile radio;</li><li>Fig. 4 illustrates an authentication and connection set-up signaling diagram;</li><li>Fig. 5 illustrates a security reconfiguration signaling diagram;</li><li>Fig. 6 illustrates example procedures in flowchart form for implementing an example embodiment of the present invention;</li><li>Figs. 7A and 7B illustrate simplified function block diagrams of a user equipment in a radio network controller; and</li><li>Fig. 8 illustrates a signaling diagram for implementing a security reconfiguration in accordance with one detailed, example, and non-limiting embodiment of the present invention.</li></ul>
DETAILED DESCRIPTION
In the following description, for purposes of explanation and not limitation, specific details are set forth, such as particular embodiments, procedures, techniques, etc. in order to provide a thorough understanding of the present invention. However, it will be apparent to one skilled in the art that the present invention may be practiced in other embodiments that depart from these specific details. For example, while the present invention is described in an example application to UMTS systems, the present invention may be employed in any cellular radio system.
In some instances, detailed descriptions of well-known methods, interfaces, devices, and signaling techniques are omitted so as not to obscure the description of the present invention with unnecessary detail. Moreover, individual function blocks are shown in some of the figures. Those skilled in the art will appreciate that the functions may be implemented using individual hardware circuits, using software functioning in conjunction with a suitably programmed digital microprocessor or general purpose computer, using an application specific integrated circuit (ASIC), and/or using one or more digital signal processors (DSPs).
The present invention may be implemented in any radio communications system that includes a radio access network. In this regard, reference is now made to the flowchart diagram illustrated in Fig. 6 which shows one set of non-limiting, example procedures for implementing the present invention. Initially, a connection is established through the radio access network to support a communication with a user equipment (step S1). The connection is configured using a first security configuration (step S2). One or more messages is sent over the connection using the first security configuration. Each message has its own message sequence number (MSN), i.e., MSN = 1, 2, 3, ... (step S3). It is determined that there is a need to reconfigure the connection (or an additional connection for a multimedia session involving the user equipment) to a second security configuration (step S4). An activation message sequence number is set for purposes of the security reconfiguration (step S5). When the second security configuration is ready to be applied, a next message is sent using the activation message sequence number (step S6).
In other words, whenever the second security configuration is ready for activation, the normal in-sequence message number is not used for the next message. Instead, the activation message sequence number is used to indicate that the UE and the RAN should now send messages using the second security configuration. Up until the sending of that message that includes the activation message sequence number, messages are sent between the UE and the RAN using the first security configuration. In this way, important messages, such as cell update messages or area update messages can be sent, for example, from the UE to the RAN to update the UE's position during the time that the security reconfiguration process is occurring. On the other hand, the present invention avoids undue delays in activating the second security configuration by sending the activation message sequence number with the next message sent after the reconfiguration process is complete.
A more detailed, but still example of the present invention is now described in the context of a UMTS system in which the radio access network corresponds to a UTRAN as illustrated in Figs. 2 and 3. In the simplified block diagram of Fig. 7A, the user equipment 12 includes data processing circuitry 30 coupled to radio transceiving circuitry 32, which in turn is coupled to an antenna 34. The data processing circuitry 30 performs functions to implement the security configuration and reconfiguration various operations associated with the present invention. Fig. 7B illustrates a simplified radio network controller 26 from the UTRAN. The RNC 26 includes data processing circuitry 40 coupled to various interfaces including an interface 42 to the core networks, an interface 44 to the node Bs, and an interface 46 to other RNCs in the UTRAN. The data processing circuitry 40 performs functions to implement various security configuration and reconfiguration operations associated with the present invention.
Attention is directed to the example signaling diagram shown in Fig. 8 for reconfiguring a security configuration for a connection established between the UE and the UTRAN. It is assumed in the diagram that a connection involving the UE is set up and that an initial security configuration is in place for the connection. In the first function block shown for the UE, the UE sets the uplink radio resource control message sequence number to zero for various radio bearers including RB0, 1, 2, 3, and 4. The UE and the UTRAN count the number of messages sent from this initialized value for each radio bearer using a MSN count-I value for each bearer. The initial MSN value is zero. The UE also sets a constant, labeled here as N302, equal to some value shown as 3. In this example, that constant is equal to a number of allowed retransmissions of the cell update/UTRAN routing area (URA) update message.
When a security reconfiguration operation is necessary, the UTRAN sends a Security Mode Command to the UE, which is acknowledged by the UE in a layer 2 Security Mode Command acknowledgement. After that acknowledgment, the UE sets an activation message sequence number for each uplink bearer with the example shown in the figure for RB0 = 0 + N302 + 1 = 4. The UE sends a Security Mode Complete message to the UTRAN. While waiting for the UTRAN to acknowledge the Security Mode Complete message which signals that the reconfiguration process is completed, the UE sends the UTRAN a cell update message using the initial security configuration. After sending the cell update message, the uplink MSN count for RB0 is incremented to 1. Another cell update message is sent by the UE before the UTRAN acknowledges the Security Mode Complete message using the initial security configuration.
When the UE receives the acknowledgement of the Security Mode Complete message from the UTRAN, the UE knows that the UTRAN received the Security Mode Complete message indicating that the security reconfiguration is complete. At this point the UE and UTRAN are free to use the new security configuration. The UE therefore sets the MSN count, which is currently at 2, to the activate message sequence number, which is 4. It sends the next message, a cell update message, using the new security configuration. Because that message includes the RRC MSN count set at the activation MSN, the UTRAN also knows to use the new security configuration.
While the present invention has been described with respect to particular embodiments, those skilled in the art will recognize that the present invention is not limited to these specific exemplary embodiments. Different formats, embodiments, and adaptations besides those shown and described as well as many variations, modifications, and equivalent arrangements may also be used to implement the invention. Therefore, while the present invention has been described in relation to its preferred embodiments, it is to be understood that this disclosure is only illustrative and exemplary of the present invention.
Contents5
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US9930530B2 | Cited by | United States of America | Applicant |
| CN102948208A | Cited by | China | Search report |
| EP1063776A | Cites | European Patent Office (EPO) | – |
| EP1063806A | Cites | European Patent Office (EPO) | – |
| WO0049760A | Cites | World Intellectual Property Organization (WIPO) | – |
| WO0129825A | Cites | World Intellectual Property Organization (WIPO) | – |
| WO0137506A | Cites | World Intellectual Property Organization (WIPO) | – |
| US2002036992A1 | Cites | United States of America | – |
15 members in 9 offices
Priority claims14
| Document | Office | Kind | Date |
|---|---|---|---|
| 333485P | United States of America | – | |
| 33348501 | United States of America | P | |
| 33348501 | United States of America | P | |
| 259435 | United States of America | – | |
| 25943502 | United States of America | A | |
| 25943502 | United States of America | A | |
| 0202043 | Sweden | W | |
| 0202043 | Sweden | W | |
| 259435 | – | – | – |
| 333485P | – | – | – |
| SE2002002043 | – | – | – |
| US20010333485P | – | – | – |
| US20020259435 | – | – | – |
| WO2002SE02043 | – | – | – |
Members15
| Document | Office | Kind | |
|---|---|---|---|
| US2003100291A1 | United States of America | A1 | |
| WO03047154A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2002351559A1 | Australia | A1 | |
| WO03047154A9 | World Intellectual Property Organization (WIPO) | A9 | |
| EP1451963A1 | European Patent Office (EPO) | A1 | |
| JP2005510949A | Japan | A | |
| PL369638A1 | Poland | A1 | |
| US7020455B2 | United States of America | B2 | |
| EP1451963B1This record | European Patent Office (EPO) | B1 | |
| AT333730T | Austria | T | |
| ATE333730T1 | Austria | T1 | |
| DE60213280D1 | Germany | D1 | |
| ES2268121T3 | Spain | T3 | |
| DE60213280T2 | Germany | T2 | |
| JP4066371B2 | Japan | B2 |
63 legal events, as 7 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Expiry of rightR071 | R071 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Amendments to the register in respect of changes of name or changes affecting rights (sect. 32/1977)REGISTERED BETWEEN 20161020 AND 20161026732E | 732E | GB | |
| Fee paymentPLFP | PLFP | FR | |
| Transmission of propertyTP | TP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Fr: translation filedET | ET | EP | |
| Nl: lapsed or annulled due to failure to fulfill the requirements of art. 29p and 29m of the patents actLapsedNLV1 | NLV1 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| European patents granted designating irelandGrantedFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1451963
- Publication, DOCDB
- 1451963
- Publication, EPODOC
- EP1451963
- Application
- 2786310
- Application, DOCDB
- 02786310
- Application, EPODOC
- EP20020786310
Titles3
- German
- SICHERHEITSUMKONFIGURATION IN EINEM UNIVERSELLEN MOBILTELEKOMMUNIKATIONSSYSTEM
- English
- SECURITY RECONFIGURATION IN A UNIVERSAL MOBILE TELECOMMUNICATIONS SYSTEM
- French
- RECONFIGURATION DE SECURITE DANS UN SYSTEME DE TELECOMMUNICATIONS MOBILE UNIVERSEL
Classification
- CPC, 11
- H04L63/20
- H04L12/2856
- H04L63/0428
- H04L63/08
- H04L63/123
- H04W12/0013
- H04W28/18
- H04W12/1006
- H04W76/10
- H04W12/033
- H04W12/106
- IPC, 5
- H04L1 00
- H04L12 56
- G09C1 00
- H04L12 28
- H04L29 06
Designated states24
- Contracting states, 24
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden
- Slovakia
- Türkiye