EP3554112A1

Security capability negotiation method, system, and equipment

Abstract

A security capability negotiation method is applicable to perform security capability negotiation during a mobile network handover. The method includes the following processes: a second network receives a handover request sent by a first network; an access network entity of the second network selects a corresponding security capability, or an access network entity and a core network (CN) entity of the second network respectively select a corresponding security capability; the second network sends the selected security capability to a user equipment (UE) via the first network. Moreover, a security capability negotiation system is also provided. Therefore, in the present invention, it is unnecessary for the MME to know the security capability of the corresponding eNB in a certain manner during a handover from a 2G/3G network to an LTE network. Meanwhile, during the handover from the LTE network to the 3G network, the SGSN does not need to introduce new requirements.

EP3554112A1, drawing sheet 1
Sheet 1 of 4

Term

1.6 yearsto projected expiry

Projected expiry 5 May 2028, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

12 claims: 4 independent, 8 dependent

  1. 1
    A method during a handover of a user equipment, UE, from a first network to a second network, comprising:receiving, by an access network entity of the second network, from a core network, CN, entity of the second network, various security capability sets supported by the UE, wherein various security capability sets supported by the UE includes a radio resource control, RRC, algorithm and a user plane, UP, algorithm supported by the UE;selecting, by the access network entity of the second network, an RRC algorithm and an UP algorithm supported by both the UE and the access network entity of the second network, wherein the selected RRC algorithm and the selected UP algorithm are selected according to the RRC algorithm and the UP algorithm supported by the UE and an RRC algorithm and an UP algorithm supported by the access network entity of the second network;and sending, by the access network entity of the second network, the selected RRC algorithm and the selected UP algorithm to the CN entity of the second network.
  2. 5
    An access network entity of a second network comprising:a first means configured to receive, from a core network, CN, entity of the second network during a handover of a user equipment, UE, from a first network to a second network, various security capability sets supported by the UE, wherein various security capability sets supported by the UE includes a radio resource control, RRC, algorithm and a user plane, UP, algorithm supported by the UE;a second means configured to select, an RRC algorithm and an UP algorithm supported by both the UE and the access network entity of the second network, wherein the selected RRC algorithm and the selected UP algorithm are selected according to the RRC algorithm and the UP algorithm supported by the UE and an RRC algorithm and an UP algorithm supported by the access network entity of the second network;and a third means configured to send the selected RRC algorithm and the selected UP algorithm to the CN entity of the second network.
  3. 9
    A method during a handover of a user equipment, UE, from a first network to a second network, comprising:receiving, by a core network, CN, entity of a second network, various security capability sets supported by the UE from a CN entity of the first network, wherein various security capability sets supported by the UE includes a radio resource control, RRC, algorithm and a user plane, UP, algorithm supported by the UE;sending, by the CN entity of a second network, the RRC algorithm and the UP algorithm supported by the UE to an access network entity of the second network;receiving, by the CN entity of a second network, from the access network entity of the second network, a selected RRC algorithm and a selected UP algorithm supported by both the UE and the access network entity of the second network;and sending, by the CN entity of a second network, the selected RRC algorithm and the selected UP algorithm to the CN entity of the first network.
  4. 11
    A core network, CN, entity of a second network:a first means configured to receive, various security capability sets supported by a user equipment, UE, from a CN entity of the first network during a handover of the UE from a first network to a second network, wherein various security capability sets supported by the UE includes a radio resource control, RRC, algorithm and a user plane, UP, algorithm supported by the UE;a second means configured to send the RRC algorithm and the UP algorithm supported by the UE to an access network entity of the second network;a third means configured to receive from the access network entity of the second network, a selected RRC algorithm and a selected UP algorithm supported by both the UE and the access network entity of the second network;and a forth means configured to send the selected RRC algorithm and the selected UP algorithm to the CN entity of the first network.