EP2139175B1

Method, system and apparatus for negotiating the security ability when a terminal is moving

Abstract

This record has no abstract on file.

EP2139175B1, drawing sheet 1
Sheet 1 of 4

Term

1.9 yearsleft in the term

Expires 27 August 2028.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

12 claims: 5 independent, 7 dependent

  1. 1
    A method for negotiating a security capability when a user equipment, UE, moves, wherein when the UE in idle state, moves from a second/third generation, 2G/3G, network to a long term evolution, LTE, network, the method comprises:receiving, by a mobility management entity, MME, a tracking area update, TAU, request message sent (100) from the UE;acquiring (101), by the MME, a non-access stratum, NAS, security algorithm supported by the UE;acquiring (102), by the MME, an authentication vector-related key from a mobility management context response message sent from a service general packet radio service support node, SGSN;selecting (103), by the MME, a NAS security algorithm according to the NAS security algorithm supported by the UE, deriving, a root key according to the authentication vector-related key, and then deriving a NAS protection key according to the derived root key, and sending (104) a message carrying the selected NAS security algorithm to the UE;and receiving (104), by the UE, the message carrying the selected NAS security algorithm sent by the MME;deriving (105), by the UE, a root key according to a current authentication vector-related key, and then deriving a NAS protection key according to the derived root key, wherein when the SGSN is an SGSN of the 2G network, the authentication vector-related key at least comprises an encryption key Kc or a value obtained after a unidirectional conversion is performed on the encryption key Kc;or when the SGSN is an SGSN of the 3G network, the authentication vector-related key at least comprises an integrity key IK and an encryption key CK, or values obtained after a unidirectional conversion is performed on the IK and the encryption key CK.
  2. 6
    A system for negotiating a security capability when a user equipment, UE, moves, wherein when the UE in idle state, moves from a second/third generation, 2G/3G, network to a long term evolution, LTE, network, the system comprises the UE and a mobility management entity, MME, wherein the UE is adapted to send a tracking area update, TAU, request message to the MME, receive a message carrying a selected non-access stratum, NAS, security algorithm sent from the MME, and derive a NAS protection key according to a root key which is derived according to a current authentication vector-related key; and the MME is adapted to:receive the TAU request message sent from the UE;acquire an authentication vector-related key from a mobility management context response message sent from a service general packet radio service support node, SGSN, and a NAS security algorithm supported by the UE;select a NAS security algorithm according to the NAS security algorithm supported by the UE, and generate and send a message carrying the selected NAS security algorithm to the UE;and derive a NAS protection key according to a root key which is derived according to the acquired authentication vector-related key, wherein when the SGSN is an SGSN of the 2G network, the authentication vector-related key at least comprises an encryption key Kc or a value obtained after a unidirectional conversion is performed on the encryption key Kc;or when the SGSN is an SGSN of the 3G network, the authentication vector-related key at least comprises an integrity key IK and an encryption key CK, or values obtained after a unidirectional conversion is performed on the IK and the encryption key CK.
  3. 8
    A mobility management entity, MME, comprising an acquisition module, a selection module, and a key derivation module, wherein the acquisition module is adapted to receive a tracking area update, TAU, request message sent from a user equipment, UE, acquire an authentication vector-related key from a mobility management context response message sent from a service general packet radio service support node, SGSN, and a non-access stratum, NAS, security algorithm supported by the UE;the selection module is adapted to select a NAS security algorithm according to the NAS security algorithm supported by the UE and acquired by the acquisition module, generate and send a message carrying the selected NAS security algorithm to the UE;and the key derivation module is adapted to derive a NAS protection key according to a root key which is derived according to the authentication vector-related key acquired by the acquisition module, and the NAS security algorithm selected by the selection module, wherein when the SGSN is an SGSN of the 2G network, the authentication vector-related key at least comprises an encryption key Kc or a value obtained after a unidirectional conversion is performed on the encryption key Kc;or when the SGSN is an SGSN of the 3G network, the authentication vector-related key at least comprises an integrity key IK and an encryption key CK, or values obtained after a unidirectional conversion is performed on the IK and the encryption key CK.
  4. 10
    A user equipment, UE, wherein when the UE in idle state, moves from a second/third generation, 2G/3G, network to a long term evolution, LTE, network, the UE comprises an updating module, a key derivation module, a storage module, and a detection module, wherein the updating module is adapted to send a tracking area update, TAU, request message carrying security capability information supported by the UE and stored in the storage module to a mobility management entity, MME, and receive a message carrying a selected non-access stratum, NAS, security algorithm sent from the MME;the key derivation module is adapted to derive a NAS protection key according to a root key which is derived according to a current authentication vector-related key and the NAS security algorithm received by the updating module;the storage module is adapted to store the security capability information supported by the UE;and the detection module is adapted to determine that a degradation attack occurs when detecting that security capability information supported by the UE and received from the MME is inconsistent with the security capability information supported by the UE and stored in the storage module.
  5. 12
    A method for negotiating a security capability when a user equipment, UE, moves, wherein when the UE in idle state, moves from a second/third generation, 2G/3G, network to a long term evolution, LTE, network, the method comprises:receiving (300), by a mobility management entity, MME, a tracking area update, TAU, request message sent from the UE;acquiring (301, 302), by the MME, a non-access stratum, NAS, security algorithm supported by the UE;acquiring (303), by the MME, a root key, Kasme, derived according to an authentication vector-related key from a home subscriber server, HSS, through an authentication and key agreement, AKA, procedure;selecting (304), by the MME, a NAS security algorithm according to the NAS security algorithm supported by the UE and an NAS security algorithm supported by the MME;and deriving (304), by the MME, a NAS protection key according to the root key;generating (305) and sending, by the MME, a NAS security mode command, SMC, request message carrying the selected NAS security algorithm to the UE;receiving (306), by the UE, the SMC request message carrying the NAS security algorithm selected by the MME, acquiring the NAS security algorithm supported by the UE and selected by the MME;and then deriving (306) a root key according to a current authentication vector-related key obtained in an AKA procedure, and deriving (306) an NAS protection key according to the root key.