EP2139175A1

Method, system and apparatus for negotiating the security ability when a terminal is moving

Abstract

A method for negotiating a security capability when a terminal moves is provided. When a user equipment (UE) moves from a second/third generation (2G/3G) network to a long term evolution (LTE) network, the method includes the following steps. A mobility management entity (MME) acquires a non-access signaling (NAS) security algorithm supported by the UE, and an authentication vector-related key or a root key derived according to the authentication vector-related key, selects an NAS security algorithm, derives an NAS protection key according to the authentication vector-related key or the root key, and sends a message carrying the selected NAS security algorithm to the UE. The UE derives an NAS protection key according to an authentication vector-related key thereof. A system for negotiating a security capability when a terminal moves, a UE, and an MME are further provided. Thereby, when the UE moves from the 2G/3G network to the LTE network, the security capability negotiation between the UE and the MME is achieved

EP2139175A1, drawing sheet 1
Sheet 1 of 5

Term

1.9 yearsto projected expiry

Projected expiry 27 August 2028, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

16 claims: 4 independent, 12 dependent

  1. 1
    A method for negotiating a security capability when a terminal moves, wherein when a user equipment (UE) moves from a second/third generation (2G/3G) network to a long term evolution (LTE) network, the method comprises:receiving, by a mobility management entity (MME), a tracking area update (TAU) request message sent from the UE, and acquiring a non-access signaling (NAS) security algorithm supported by the UE, and an authentication vector-related key or a root key derived according to the authentication vector-related key;selecting, by the MME, an NAS security algorithm according to the NAS security algorithm supported by the UE, deriving an NAS protection key according to the authentication vector-related key or the root key, and sending a message carrying the selected NAS security algorithm to the UE;and deriving, by the UE, an NAS protection key according to an authentication vector-related key thereof.
  2. 11
    A system for negotiating a security capability when a terminal moves, comprising a user equipment (UE) and a mobility management entity (MME), wherein the UE is adapted to send a tracking area update (TAU) request message to the MME;receive a message carrying a selected non-access signaling (NAS) security algorithm sent from the MME, and derive an NAS protection key according to an authentication vector-related key;and the MME is adapted to receive the TAU request message sent from the UE;acquire an authentication vector-related key or a root key derived according to the authentication vector-related key, and an NAS security algorithm supported by the UE;select an NAS security algorithm according to the NAS security algorithm supported by the UE, and generate and send a message carrying the selected NAS security algorithm to the UE;and derive an NAS protection key according to the acquired authentication vector-related key or the root key.
  3. 13
    A mobility management entity (MME), comprising an acquisition module, a selection module, and a key derivation module, wherein the acquisition module is adapted to receive a tracking area update (TAU) request message sent from a user equipment (UE), acquire an authentication vector-related key or a root key derived according to the authentication vector-related key, and a non-access signaling (NAS) security algorithm supported by the UE;the selection module is adapted to select an NAS security algorithm according to the NAS security algorithm supported by the UE and acquired by the acquisition module, generate and send a message carrying the selected NAS security algorithm to the UE;and the key derivation module is adapted to derive an NAS protection key according to the authentication vector-related key or the root key derived according to the authentication vector-related key acquired by the acquisition module, and the NAS security algorithm selected by the selection module.
  4. 15
    A user equipment (UE), comprising an updating module, a key derivation module, a storage module, and a detection module, wherein the updating module is adapted to send a tracking area update (TAU) request message carrying security capability information supported by the UE and stored in the storage module to a mobility management entity (MME), and receive a message carrying a selected non-access signaling (NAS) security algorithm sent from the MME;the key derivation module is adapted to derive an NAS protection key according to an authentication vector-related key and the NAS security algorithm received by the updating module;the storage module is adapted to store the security capability information supported by the UE;and the detection module is adapted to determine that a degradation attack occurs when detecting that security capability information supported by the UE and received from the MME is inconsistent with the security capability information supported by the UE and stored in the storage module.