EP2197147A1

Method and device for updating a key in the active state

Abstract

A method for updating a key in an active state is disclosed according to the embodiments of the present invention. The method includes steps of: initiating a key update by a user equipment in the active state or a network side when a pre-defined condition is met; updating the key by the network side and the user equipment, and negotiating an activation time of the new keys. An apparatus for updating a key in an active state is also disclosed according to the present invention. With the present invention, the user equipment in an active state and the network side may actively initiate the key update procedure in different cases, thereby solving the problem concerning the key update for a session in an active state.

EP2197147A1, drawing sheet 1
Sheet 1 of 7

Term

2 yearsto projected expiry

Projected expiry 25 September 2028, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

21 claims: 5 independent, 16 dependent

  1. 1
    A method for updating a key in an active state, characterized by comprising:initiating a key update by a user equipment in the active state or a network side when a pre-defined condition is met;updating the keys by the network side and the user equipment, and negotiating an activation time of the new keys.
  2. 5
    The method ac cording to claim 1, characterized in that , the step of updating the key by the network side and the user equipment and negotiating the activation time of the new keys when the user equipment initiates the key update specifically comprises:receiving, by a Mobility Management Entity (MME) at the network side, a key update request sent by the user equipment;performing an Authentication and Key Agreement (AKA) procedure to update keys when the MME determines that all of the keys need to be updated, otherwise, updating only derived keys by the network side;informing, by the MME, to the evolved NodeB (eNB) at the network side of the new key K eNB ;and negotiating, by the eNB with the user equipment, the activation time of the new keys.
  3. 12
    A user equipment for updating a key in an active state, characterized by comprising:a terminal key update detecting unit, configured to determine based on a pre-defined condition whether a key update needs to be initiated;and a terminal key update initiating unit, configured to send a key update request message to a network side when the terminal key update detecting unit determines that the key needs to be updated.
  4. 14
    A network side entity for updating a key in an active state, characterized by comprising:a key update detecting unit, configured to determine based on a pre-defined condition whether a key update needs to be initiated;a key update initiating unit, configured to send a request message for indicating the key update when the key update detecting unit determines that the key needs to be updated;and a key updating unit, configured to update the key when the user equipment or the network side entity initiates the key update.
  5. 17
    A method for updat ing a key in an active state, characterized by comprising:initiating, by a network side, a key update when a pre-defined condition is met;and updating the key by the network side, and informing a user equipment of the new key.