Method for controlling handover in a cellular radiocommunications network
Abstract
Control procedure of a logical communication channel in circuit mode between a radio terminal (14) and a cellular radio communication infrastructure, the infrastructure comprising at least one central network (30), radio network controllers (60, 61) connected to the central network and comprising first and second controllers and base stations (70, 71) equipped with radio interfaces and each connected to one of the radio network controllers.

Term
Term ended
Projected expiry passed 18 May 2021, 5.3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
17 claims: 7 independent, 10 dependent
- 1ES 2 203 583 T3 REIVINDICACIONES 1. Procedimiento de control de un canal lógico de comunicación en modo circuito entre un terminal de radio (14) y una infraestructura de radiocomunicación celular, comprendiendo la infraestructura al menos una red central (30), unos controladores de red de radio (60, 61) conectados a la red central y comprendiendo unos primer y segundo controladores y unas estaciones de base (70, 71) dotadas de interfaces de radio y conectadas cada una a uno de los controladores de red de radio, comprendiendo el procedimiento las siguientes etapas:- establecer al menos una primera vía de comunicación entre el red central y el terminal, que pasa por una de las estaciones de base (70) que utiliza un primer recurso de acceso de radio, y por el primer controlador (60) que constituye un controlador maestro para dicha primera vía;- transmitir la información relevante del canal lógico según la primera vía de comunicación;- establecer al menos una segunda vía de comunicación entre la red central y el terminal, que pasa por una de la estación de base (71) que utiliza un segundo recurso de acceso de radio, distinto del primer recurso, y por el segundo controlador (61) que constituye un controlador maestro para dicha segunda vía;y - transmitir la información relevante del canal lógico según la segunda vía de comunicación, caracterizado porque la información transmitida según cada vía de comunicación está cifrada durante una parte de dicha vía que va desde el controlador maestro al terminal de radio, efectuándose el cifrado en función de unos parámetros que comprenden una clave secreta (CK) yun número de secuencia de cifrado (CSN) combinado con dicha clave, incrementando el controlador maestro y el terminal conjuntamente el número de secuencia de cifrado al ritmo de tramas de duración determinada, para disponer de los mismos parámetros de cifrado y permitir el descifrado de la información, la segunda vía se establece mediante un procedimiento de transferencia que comprende la transmisión de unos datos de ajuste desde el primer controlador al segundo controlador, una fase de emisión simultánea de señales de radio en los primer y segundo recursos de acceso por las estaciones (70, 71) base respectivas de las primera y segunda vías, y la supresión de la primera vía a continuación, las señales de radio emitidas en los primer y segundo recursos de acceso durante la fase de emisión simultánea transportan la misma información, estando dicha información cifrada por el segundo controlador (61) con un número de secuencia de cifrado desfasado con adelanto con respecto al utilizado por el primer controlador (60) para cifrar la información transmitida a lo largo de la primera vía, y el terminal de radio (14) conmuta del primer recurso de acceso al segundo recurso de acceso durante la fase de emisión simultánea, adelantando el número de secuencia de cifrado con el fin de alinear el número desfasado utilizado por el segundo controlador (61).
- 2Procedimiento según la reivindicación 1, en el que el procedimiento de transferencia comprende, tras la recepción de los datos de ajuste porel segundo controlador (61), la transmisión de un mensaje de control de conmutación desde el segundo controlador al terminal de radio (14) por medio del primer controlador (60).
- 3Procedimiento según la reivindicación 2, en el que el mensaje de control de conmutación indica, con respecto a una referencia de tiempo disponible en el terminal de radio (14) y en el segundo controlador (61), una trama de inicialización a la que corresponde un valor de inicialización del número desfasado de secuencia de cifrado, siendo determinable dicho valor de inicialización por el terminal de radio y por el segundo controlador.
- 4Procedimiento según una cualquiera de las reivindicaciones anteriores, en el que los números (CSN) de secuencia de cifrado se representan sobre M bits, y los datos de ajuste comprenden una cantidad representada por los M-P bits de mayor peso de un valor presente del número de secuencia de cifrado utilizado por el primer controlador, siendo M y P enteros tales que 0 P M.
- 5Procedimiento según las reivindicaciones 2 y 4, en el que los P bits de menor peso de un valor de inicialización del número desfasado de secuencia de cifrado están indicados en el mensaje de control de conmutación.
- 6Procedimiento según la reivindicación 4, en el que el adelanto del número desfasado de secuencia de cifrado utilizado por el segundo controlador (61) con respecto al utilizado por el primer controlador (60), se realiza incrementando dicha cantidad comprendida en los datos de ajuste recibidos por el primer controlador, y atribuyendo los M-P bits de la cantidad así incrementada a los M-P bits de mayor peso de un valor de inicialización del número desfasado.
- 7Procedimiento según las reivindicaciones 2 y 6, en el que dicha cantidad incrementada se indica en el mensaje de control de conmutación.
- 8Procedimiento según la reivindicación 5 ó 6, en el que el valor de inicialización del número desfasado corresponde a al menos una trama de inicialización determinable por el terminal de radio (14) y por el segundo controlador (61).
- 9Procedimiento según una cualquiera de las reivindicaciones anteriores, en el que los datos de ajuste comprenden unos datos representativos de un desfase entre el número de secuencia de cifrado utilizado por el primer controlador (60) y una referencia de tiempo disponible en el segundo controlador.
- 10Procedimiento según la reivindicación 9, en el que dicho desfase es medido por el terminal (14) en base a señales de radio recibidas procedentes de una estación (71) base conectada al segundo controlador (61) y que lleva información relativa a dicha referencia de tiempo.
- 11Procedimiento según la reivindicación 10, en el que dicha referencia de tiempo comprende un contador de tramas para una estación (71) base conectada al segundo controlador (61).
- 12Procedimiento según las reivindicaciones 4 y 10, en el que la información relativa a dicha referencia de tiempo corresponde a un numero de trama representado sobre Q bits, siendo Q un entero tal que P Q M.
- 13Procedimiento según una cualquiera de las reivindicaciones 1 a 12, en el que los datos de ajuste son ES 2 203 583 T3 transmitidos del primer controlador (60) al segundo controlador (61) por medio de la red central (30).
- 14Procedimiento según una cualquiera de las reivindicaciones 1 a 13, en el que los primer y segundo recursos de acceso de radio comprenden frecuencias portadoras distintas.
- 15Procedimiento según una cualquiera de las reivindicaciones 1 a 14, en el que los primer y segundo controladores (60, 61) pertenecen a redes de acceso distintas.
- 16Procedimiento según una cualquiera de las reivindicaciones 1 a 14, en el que los primer y segundo controladores (60, 61) están situados en un mismo nodo de red, y comprenden circuitos distintos respecto a las primeray segunda vías, paraal menos una parte de los protocolos de comunicación que incluyen las funciones de cifrado y descifrado de la información, comunicándose dichos circuitos entre sí de maneraasíncrona.
- 17Red de acceso de un sistema celular de radiocomunicación que comprende al menos un controlador de red de radio que comprende los medios para ejecutar las etapas de un procedimiento según una cualquiera de las reivindicaciones anteriores. NOTA INFORMATIVA:Conforme a la reserva del art. 167.2 del Convenio de Patentes Europeas (CPE) y a la Disposición Transitoria del RD 2424/1986, de 10 de octubre, relativo a la aplicación del Convenio de Patente Europea, las patentes europeas que designen a España y solicitadas antes del 7-10-1992, no producirán ningún efecto en España en la medida en que confieran protección a productos químicos y farmacéuticos como tales. Esta información no prejuzga que la patente esté o no incluida en la mencionada reserva.
Independent claims17
97 paragraphs in 3 sections, as filed
ES 2 203 583 T3
DESCRIPTION
Channel transfer control procedure in a cellular radiocommunication network.
The present invention relates to the field of radiocommunications, and in particular to the encryption techniques used in cellular networks.
The invention is particularly applicable to third-generation cellular networks of the UMTS type ("Universal Mobile Telecommunication System") that use code division multiple access techniques (CDMA, "Code Division Multiple Access").
Next, the invention is described in its application to a UMTS network, where Figure 1 shows the architecture.
On the one hand, the mobile service switches 10, which belong to a central network (CN, "Core Network"), are related to one or more fixed networks 11, and on the other hand, by means of an interface called Iu, with control equipment 12, or RNC ("Radio Network Controller"). Each RNC 12 is related to one or more base stations 13 via an interface called Iub. The base stations 13, distributed over the coverage territory of the network, are capable of communicating by radio with the mobile terminals 14, 14a, 14b, called UE ("User Equipment"). Base stations can be regrouped to form nodes, called "Node Bs". Furthermore, several RNCs 12 can communicate with each other via an interface called Iur. The RNCs and the base stations form an access network called UTRAN ("UMTS Terrestrial Radio Access Network").
The UTRAN comprises elements of layers 1 and 2 of the ISO model to supply the required links over the radio interface (called Uu), and a stage 15A for the control of radio resources (RRC, "Radio Resource Control") belonging to to layer 3, as described in the technical specification 3G TS 25.301, “Radio Interface Protocol”, version 3.4.0, published in March 2000 by the 3GPP (3<sup>rd</sup> Generation Partnership Project). Viewed from the upper layers, the UTRAN simply acts as a relay between the UE and the CN.
Figure 2 shows the RRC stages 15A, 15B and the lower layer stages belonging to the UTRAN and a UE. On each side, layer 2 is subdivided into a radio link control (RLC, "Radio Link Control") stage 16A, 16B and a medium access control (MAC, "Medium Access Control" stage 17A, 17B). ”). Layer 1 comprises a coding and multiplexing stage 18A, 18B. A radio stage 19A, 19B guarantees the emission of the radio signals from the symbol trains supplied by the stage 18A, 18B, and the reception of the signals in the other direction.
There are different ways of adapting the protocol architecture according to figure 2 to the material architecture of the UTRAN according to figure 1, and in general different organizations can be adopted according to the types of channels (see section 11.2 of the technical specification 3G TS 25.401, "UTRAN Overall Description", version 3.1.0, published in January 2000 by 3GPP). The RRC, RLC and MAC stages are located at RNC 12. Layer 1 is located, for example, at node B. However, a part of this layer can be found in RNC 12.
When several RNCs are involved in a communication with a UE, there is generally a service RNC called SRNC (“Serving RNC”), where the relevant Layer 2 modules (RLC and MAC) are located, and at least one relay RNC. , called DRNC ("Drift RNC"), to which a base station with which the UE is in radio link is connected. The appropriate protocols guarantee exchanges between these RNCs over the Iur interface, for example ATM (“Asynchronous Transfer Mode”) and AAL2 (“ATM Adaptation Layer No. 2”). Also, these same protocols can be used by the Iub interface for exchanges between a Node B and its RNC.
Layers 1 and 2 are each controlled by the RRC sublayer, whose characteristics are described in the technical specification 3G TS 25.331, "RRC Protocol Specification", version 3.1.0, published in October 1999 by the 3GPP. The RRC stage 15A, 15B monitors the radio interface. Furthermore, it handles flows to be transmitted to the remote station according to a "control plan", as opposed to the "user plan" which corresponds to the processing of user data emitted by layer 3.
The RLC sublayer is described in the 3G TS 25.322 technical specification, "RLC Protocol Specification", version 3.2.0, published in March 2000 by 3GPP. In the broadcast direction, the RLC stage 16A, 16B receives, according to the respective logical channels, data streams composed of service data units (RLC-SDU) broadcast from layer 3. An RLC module of step 16A, 16B is associated with each logical channel to carry out in particular a segmentation of the RLC-SDU units of the stream into protocol data units (RLC-PDU) addressed to the MAC sublayer and comprising a header RLC optional. In the reception direction, an RLC module inversely performs a readjustment of the RLC-SDUs of the logical channel from the data units received from the MAC sublayer.
The RLC stage 16A, 16B can have several modes of operation, particularly depending on the type of logical channel. In the course of the present description, the transparent mode of the RLC sublayer will be considered, which is suitable for a logical channel relative to circuit mode communication. In this transparent mode, the RLC module performs segmentation and reset operations when necessary, and does not introduce any headers to the RLC-PDUs.
The MAC sublayer is described in the 3G technical specification TS 25.321, "MAC Protocol Specification", version 3.3.0, published in March 2000 by 3GPP. It transposes one or more logical channels into one or more TrCH transport channels (“Transport CHannel”). In the broadcast sense, the MAC stage 17A, 17B can multiplex one or more logical channels in the same transport channel. In such a transport channel, the MAC step 17A, 17B supplies successive transport blocks TrBk ("Transport Block") each consisting of an optional MAC header and an RLCPDU emitted from an associated logical channel.
For each TrCH, the RRC sublayer supplies the MAC sublayer with a set of transport formats (TFS, "Transport Format Set"). A transport format comprises a transmission time interval TTI (“Transmission Time Interval”) equal to 10, 20, 40 or 80 ms, a transport block size2
ES 2 203 583 T3 te, a transport block set size and parameters that define the protection scheme to be applied by layer 1 in the TrCH to detect and correct transmission errors. Depending on the throughput running on the logical channel (s) associated with the TrCH, the MAC step 17A, 17B selects a transport format in the TFS assigned by the RRC sublayer, and supplies in each TTI a set of transport blocks according to the format selected, indicating that format to layer 1.
Layer 1 can multiplex multiple TrCHs on a given physical channel. In that case, the RRC sublayer assigns a set of Transport Format Combination Set (TFCS) to the physical channel, and the MAC sublayer dynamically selects a transport format combination in that TFCS set, defining the transport formats to be used in the different multiplexed TrCHs.
UMTS uses the CDMA spectrum spreading technique, that is, the transmitted symbols are multiplied by spreading codes made up of samples, called “chips”, whose frequency (3.84 Mchip / s in the case of UMTS) is higher than that of transmitted symbols. The spreading codes distinguish between different physical channels PhCH ("Physical CHannel") that are superimposed on the same transmission resource constituted by a carrier frequency. The auto and cross-correlation properties of the spreading codes allow the receiver to separate the PhCHs and extract the symbols that are intended for it. For UMTS in FDD (“Frequency Division Duplex”) mode in the downlink, a scrambling code is assigned to each base station, and different physical channels used by this base station are distinguished by channel codes ("Channelisation codes") orthogonal to each other. The base station can also use multiple scrambling codes orthogonal to each other. In the uplink, the base station uses the scrambling code to separate the sending UEs, and eventually the channel code to separate the physical channels broadcast from the same UE. For each PhCH, the global spreading code is the product of the channel code and the scrambling code. The expansion factor (equal to the ratio between the frequency of segments and the frequency of symbols) is a power of 2 between 4 and 512. This factor is chosen as a function of the throughput of symbols to be transmitted over the PhCH.
The different physical channels are organized in 10 ms frames that follow one another on the carrier frequency used by the base station. Each frame is subdivided into 15 666 μδ timeslots. Each slot can carry the superimposed contributions of one or more physical channels, comprising common channels and dedicated channels DPCH ("Dedicated Physical CHannel"). Each DPCH carries with the data a transport format combination indication TFCI ("Transport Format Combination Indicator") emitted from the MAC sublayer, which allows the recipient MAC module to recognize the structure of the TrBk.
For the same communication, it is possible to establish several DPCHs corresponding to different channel codes, whose expansion factors can be the same or different. Specifically, this situation occurs when a DPCH cannot supply the throughput required by the application. On the other hand, this same communication can use one or more transport channels. The coding and multiplexing of the information symbol streams emitted from the TRCs by the PhCHs are described in detail in the technical specification 3G TS 25.212, “Multiplexing and channel coding (FDD)” version 3.0.0, published in October 1999 by 3GPP.
With regard to each logical channel, for which the RLC sublayer processing module operates in transparent mode, the MAC stage 17A, 17B also guarantees an encryption of the transmitted information and a decryption of the received information. In the corresponding transport channel, the TrBk related to that logical channel each consist of an encrypted RLC-PDU unit according to a mechanism described in chapter 8 of the aforementioned 3G TS 25.301 specification.
Figure 3 illustrates the encryption module 20 of the MAC stage 17A, 17B of the RNC or the UE, used for a logical channel. An encryption algorithm 21 is executed to generate a binary mask that is combined with the information bits of the RLCPDU received in transparent mode from the RLC, by means of an exclusive OU operation (port 22). An identical module is usable for decryption. Algorithm 21 calculates the mask based on the following parameters:
- CK: secret encryption key of M = 32 bits, defined in a previous authentication phase between the core network and the UE;
- CSN: ciphering sequence number (“Ciphering Sequence Number”) made up of M = 32 bits;
- BEARER: logical channel identifier, used to generate different masks for the different logical channels;
- DIRECTION: bit that indicates the direction of transmission (ascending or descending) that is used to generate different masks in the two directions;
- LENGTH: mask length in number of bits, provided by the RRC stage depending on the transport format.
Algorithm 21 combines the CSN number of M bits in the CK key in order to avoid using the same mask to encrypt different blocks. This CSN number increases at the rate of the 10 ms radio frames. Thus, Figure 3 shows the 32-bit counter 23 that supplies the CSN parameter. This counter increments the CSN number by an amount N to each new block of the logical channel, where N is the number of frames per TTI in the transport channel that carries that logical channel (N = 1, 2, 4 or 8). Therefore, the counter is incremented by 1 every 10 ms, by 2 every 20 ms, by 4 every 40 ms, or by 8 every 80 ms. At the beginning of the encrypted communication, the RRC stage supplies an initial value CSN0 of the CSN number and a start command of the counter 23 (START). These operations are carried out both at the RNC, where the MAC task is executed, and at the UE.
A problem considered in the present invention is that of the transfer of the CSN counters during a movement of the MAC module that guarantees the encryption function in the network infrastructure.
ES 2 203 583 T3
Such a shift takes place within the framework of a handover procedure involving a radio access resource change (handover). Thus, the handover procedure can lead to a change in SRNC, which requires that the CSN counter of the new SRNC be synchronized with that of the previous SRNC (and the UE), although the Iu and / or Iur interfaces they have the RNCs to communicate with each other are asynchronous. Likewise, the case can be considered in which the MAC module displacement takes place within the same RNC, if it uses different circuits to manage the access resources used before and after the transfer.
In the 3G technical specification TR 25.832, “Manifestations of Handover and SRNS Relocation”, version 3.0.0, published in October 1999 by the 3GPP, different possible scenarios for the transfer procedure are described. On the one hand, we distinguish between soft handover, or SHO ("soft handover"), which uses a macrodiversity mode and which may eventually be followed by a change in SRNC called "relocation" and, on the other hand, sudden handover, or HHO ("hard handover"), corresponding, for example, to a change in carrier frequency (with or without a change in RNC) and / or a transfer between two RNCs (of the same access network or of different access networks) that cannot communicate with each other through an Iur interface . An HHO can take place within a UTRAN if several carrier frequencies are assigned to its operator or if Iur interfaces are not provided for all RNCs in this UTRAN. Likewise, an HHO can take place between two different access networks, for example, between two UTRANs or between a UTRAN and a system of a different nature based on a similar functional architecture that, in particular, allows the same encryption procedures to be used, such as as a GERAN type system ("GSM / EDGE Radio Access Network").
UMTS in FDD mode supports a macrodiversity technique, which consists in providing that a UE can communicate simultaneously with different base stations in such a way that, in the downstream direction, the UE receives the same information several times and that, in the upstream direction , the radio signal emitted by the UE is picked up by the base stations to form separate estimates combined later in the UTRAN.
Macrodiversity provides a reception gain that improves the qualities of the system thanks to the combination of different observations of the same information. It also allows for smooth intercellular transfers (SHO), when the UE is moving.
In macrodiversity, the switching of the transport channels for multiple transmission after the UTRAN or the UE, and the combination of these transport channels in reception, are operations that correspond to a selection and combination module that belongs to layer 1. This module is in the interface with the MAC sublayer and is in the RNC that manages the UE. If the base stations involved depend on different RNCs communicating through the Iur interface, one of these RNCs plays the role of SRNC and the other that of DRNC.
When an SHO is completed, the radio link between the UE and the home base station is broken. Then, it may be that no base station, at a distance from which the UE is located, is dependent on the SRNC.
The UTRAN may well continue to support communication in this way. However, this is not optimal since it is possible to provide exchanges that intervene on the Iur interface and release the old SRNC, realizing it so that the DRNC becomes the new SRNC for ongoing communication. This is the object of the relocation procedure (“SRNS Relocation”, see section 7.2.3.2 of the aforementioned 3G TS 25.401 specification), activated at the initiative of the former SRNC.
This relocation procedure comprises the transfer of RLC and MAC instances (as well as the layer 1 selection and recombination module if macrodiversity is maintained) from the previous SRNC to the previous DRNC.
One problem this raises is the transfer of the CSN counter used by the encryption algorithm in transparent RLC mode. Indeed, this counter must remain in sync with the one located in the MAC layer on the UE side, while the links between the RNCs (through the Iu interface and the core network or through the Iur interface) are in principle asynchronous.
The 32-bit CSN number can be decomposed into a connection frame CFN number (“Connection Frame Number”) corresponding to the P least significant bits of the CSN and into a hyperframe HFN number (“HyperFrame Number”) corresponding to the 32 bits of greater weight (P = 8 according to chapter 8 of the aforementioned 3G TS 25.301 specification).
The RNC that supervises each cell handled by a base station 13 updates for this cell a system frame number SFN ("System Frame Number"), encoded in Q = 12 bits, which is incremented in each new radio frame of 10 ms. This SFN number is broadcast by the base station on its common control channels.
A UE measures the time lag between the signals it detects from cells close to its current cell and its own clock. Before the activation of an SHO to a target cell, the UE supplies its SRNC with the offset that it has measured for this target cell, which corresponds to the offset obtained in the common channel, in a zone of 2<sup>P</sup> x 10 ms (where 2.56 s), between the destination cell's SFN counter and its own CFN counter. This phase shift is determined, based on a detection of synchronization patterns, with a temporal precision that is clearly finer than 10 ms, for example of the order of the symbol time. It serves to temporarily establish the emission of the new base station, to which it is directed through the Iur interface, so that, in macrodiversity mode, the information received by the UE from the different stations is not too out of phase between yes, which would require an excessive amount of memory to be able to operate the combination of observations.
Due to the provision of this offset, the DRNC knows a priori the P least significant bits of the counter CSN to be used for encryption and decryption. But the heavier bits (HFN) are not supplied. The current 3GPP specifications foresee that the relocation procedure includes the sending by the SRNC of a “Relocation_Required” message through the Iu interface, in which it is
ES 2 203 583 T3 inserted the HFN number so that the DRNC can synchronize its encryption sequence counter. Upon receiving this message, the core network activates the task that will lead to the switching of the communication towards the DRNC, and transparently retransmits the HFN to the latter.
These provisions do not solve the aforementioned problem because between the moment the SRNC transmits the HFN value and the moment the DRNC receives it, the HFN in force on the UE side has been able to increase. This occurs every time the HFN takes more than 2.56 s to be received by the DRNC, which is difficult to avoid with certainty, considering the queues that messages can encounter in the asynchronous core network and the timing of handling of the message "Relocation_Required" by switches 10. Errors can also arise if the HFN takes less time to reach the DRNC: if it is issued at a time when the CFN is worth for example 255, it is very likely that it will be received by the DRNC once the HFN value has increased up to the EU level.
The above problem reappears, even more severely, on HHOs running without using macrodiversity mode.
In an HHO, there is generally a double broadcast phase during which the same downstream information is transmitted simultaneously on both access resources. This allows the UE to receive without interruption the information that is destined for it as soon as it passes through the second access resource. Therefore, it is necessary for the RNC in charge of the destination cell to quickly become aware of the cipher sequence counter CSN relative to the UE when an HHO is to be executed. On the other hand, the RNC of the destination cell, if different from the previous SRNC, generally has no prior knowledge of the CFN counter since there is no macrodiversity. Therefore, the value sent by the previous SRNC must cover even the least significant bits of the CSN so that, most likely, it will be obsolete when it is received by the RNC of the destination cell, taking into account the progression delays in the network. asynchronous. This drawback is difficult to eliminate in the absence of a synchronization of the base stations, which is not necessary for the operation of a UMTS network and is not exploited by the standard.
It should be noted that the problem considered above does not arise in the non-transparent modes of the RLC sublayer. These non-transparent modes are intended for packet transmissions, for which it is generally not inconvenient to momentarily interrupt the transmission during a transfer or relocation procedure, in order to ensure, for example, for an acknowledgment mechanism, that the correct counter value has been received. On the other hand, it is the RLC sublayer that guarantees the encryption / decryption function in non-transparent mode, using a header sequence number of each RLC-PDU unit to encrypt the data contained in this RLC-PDU unit. This sequence number is clearly transmitted, so that the encryption counters do not need to be synchronized at the two ends.
In second-generation GSM systems (“Global System for Mobile communication”) using time division multiple access (TDMA) techniques, encryption is performed only on the air interface. The increase in the encryption key is based on the synchronization relative to the TDMA hyperframes, which is obtained unambiguously on both parts of the radio link within the framework of the time multiplexing scheme. Consequently, the above problem no longer arises.
Document WO98 / 09458 describes a radio access system derived from GSM, in which the encryption of communications is guaranteed only on the air interface. This system is bound by the need for a synchronization of the base stations at the TDMA superframe scale. Furthermore, the synchronization of the encryption counters fails when the expected exchanges between the base stations take longer than the relatively short duration of a super frame (120 ms).
An object of the present invention is to provide a solution to the problem of synchronization of encryption counters, in particular, in the case of HHO.
Therefore, the invention proposes a method of controlling a logical channel of communication in circuit mode between a radio terminal and a cellular radiocommunication infrastructure. The infrastructure comprises at least one central network, radio network controllers connected to the central network and comprising first and second controllers, and base stations provided with radio interfaces and each connected to one of the network controllers of radio. The procedure comprises the following stages:
- establishing at least a first communication path between the central network and the terminal, which passes through one of the base stations that uses a first radio access resource and through the first controller that constitutes a master controller for said first path;
- transmit the relevant information of the logical channel according to the first communication path;
- establish at least a second communication path between the central network and the terminal, which passes through one of the base stations that uses a second radio access resource, different from the first resource, and through the second controller that constitutes a master controller for said second way; Y
- transmit the relevant information of the logical channel according to the second communication path.
The information transmitted according to each communication path is encrypted in a part of said path that goes from the master controller to the radio terminal. Encryption is carried out based on parameters that comprise a secret key and an encryption sequence number combined with said key. The master controller and the terminal jointly increase the encryption sequence number at the rate of time frames to provide the same encryption parameters to allow decryption of the information. The second channel is established by a transfer procedure that comprises the transmission of adjustment data from the first controller to the second controller, a phase of simultaneous emission of radio signals by the first and second access resources for the respective base stations of the first and second tracks, after the elimination of the first track. The radio signals emitted by the first and second access resources during the simulcast phase, carry
ES 2 203 583 T3 the same information, said information being encrypted by the second controller by means of an encryption sequence number out of phase with respect to that used by the first controller to encrypt the information transmitted along the first path. The radio terminal switches from the first access resource to the second access resource, during the encryption broadcast phase, to align the out-of-phase number used by the second controller.
The handover method preferably comprises, upon receipt of setting data by the second controller, the transmission of a switch control message from the second controller to the radio terminal by means of the first controller. This message may indicate, with respect to a time reference available to the radio terminal and the second controller, an initialization frame to which corresponds an initialization value of the out of date cipher sequence number, said initialization value being determinable by the radio terminal and by the second controller.
In one embodiment of the method, the encryption sequence numbers are represented in M bits, and the adjustment data comprises an amount represented by the MP bits with the highest weight of a present value of the encryption sequence number used by the first controller, where M and P are integers such that 0 <P <M. The switching control message can then indicate the P least significant bits of an initialization value of the cipher sequence number out of phase and / or its MP bits of greatest weight corresponding to said quantity, increased in order to guarantee the advance of the out-of-date cipher sequence number. This initialization value of the offset number corresponds to an initialization frame that can be determined by the terminal and by the second controller.
The adjustment data finally comprises data representative of an offset between the scrambling sequence number used by the first controller and a time reference available to the second controller.
Another aspect of the present invention refers to an access network of a cellular radiocommunication system comprising at least one radio network controller arranged to implement a method as defined above.
Other particularities and advantages of the present invention will be apparent from the following description of non-limiting embodiments, with reference to the attached drawings, in which:
figure 1, previously exposed, is a diagram of a UMTS network;
Figure 2, previously discussed, is a diagram showing the layered organization of some communication protocols used in the UMTS network radio interface;
Figure 3, previously commented, is a synoptic diagram of an encryption module used in the MAC layer of a UMTS network;
figure 4 is a simplified diagram of a UMTS network to which the invention can be applied;
Figures 5 to 7 are diagrams of the network of Figure 4 showing the active links at different times of a communication;
The infrastructure designed in figure 4 has a simplified configuration on a voluntary basis to make the explanation of the invention clearer. The core network comprises a mobile service switching center 30 (MSC, "Mobile Service Switching Center") for circuit mode, connected by Iu interfaces to two radio network subsystems (SRNS) each having an RNC 60, 61. The two RNCs 60, 61 respectively control the base stations 70, 71 (node B) through Iub interfaces. In the example shown, there is no Iur interface between the two RNCs 60, 61 involved. It should be noted that there could be an Iur interface of this type, but that it is not suitable for handover, for example, because it is between two different carrier frequencies. In another embodiment, the RNCs 60, 61 belong to different access networks (a UTRAN and a GERAN, for example).
Figures 5 to 7 show active communication paths between the core network and a UE 14 as it moves, in a typical HHO scenario in the network configuration of Figure 4. At the beginning (Figure 5), a via conventionally between the MSC 30 of the core network and the UE 14 through the originating RNC 60 and the base station 70 that depends on it. The SRNC 60 and the UE each have a MAC instance that, for each logical channel dedicated in circuit mode and each direction of communication, guarantees the encryption and decryption functions of the information transmitted by this first channel, in the manner indicated with reference to figure
3. The static parameters (CK, BEARER, DIRECTION, LENGTH) of the module 20 and the initialization parameters of the counter 23 have been supplied by the RRC stage.
The UE performs the prescribed measurements on the common channels of the cells close to its own, in particular those of the base station 71 connected to the RNC 61 in the situation illustrated by figure 5. When the analysis of these measurements shows that a HHO to base station 71, SRNC 60 directs to its MSC 30 an HHO request message ("Handover_Prepare") designating the destination RNC 61. In particular, for the practice of the invention, it is advantageous that the UE 14 measures the time offset Δ between its own cipher sequence number CSN and the frame number SFN broadcast by the base station 71 on its common downstream channels. This phase shift Δ is measured with a finer resolution than that of the 10 ms frames. It is observed that A<sub>k</sub> = (CSN SFN) mod 2<sup>k</sup> is the number represented by the k least significant bits of the integer part of the phase shift Δ, expressed in units of 10 ms (1 <k <Q). Being the CSN on M = 32 bits and the SFN on Q = 12 bits, the UE measures Δ<sub>Q</sub> = Δ<sub>12</sub>. In the framework of macrodiversity procedures, it accounts for the UTRAN of Δ<sub>ρ</sub> = Δ8.
When handover is activated, a second path is established starting from the downstream direction (Figure 6). The same relevant logical channel information is transmitted twice from the MSC 30 (or multiple MSCs), once through the RNC 60 and the base station 70 and once through the RNC 61 and the base station 71. In the upstream direction, the terminal 14 saves the parameters of the physical channel of the first channel until the latter receives a "Handover_Command" message requesting it to switch to the other base station 71. Upon receiving this message, the UE 14 executes the command once the synchronized network completes the establishment of the second path. Then the first way is deleted (figure 7).
In the situation illustrated by figure 6, the infor6
ES 2 203 583 T3 downstream is encrypted in the two ways between the RNC and the UE. For example, the following process is applied to the RRC layer to start the counter 23 used to encrypt and decrypt in the MAC layer of the destination RNC 61
- in the "Handover_Prepare" message, the originating RNC 60 includes the current HFNE value of the HFN hyperframe number made up of the MP bits with the highest weight of the CSN counter it uses, this HFNE value being transmitted by the central network to the RNC 61 of destination;
- after having received this information, if it accepts the transfer, the destination RNC 61 determines an initialization frame number SFNI of the counter 23 with respect to the SFN frame counter of the destination base station 71, as well as an initialization CSNI value corresponding to the encryption sequence number, such that this sequence number is ahead of that used in the first path between the RNC 60 and the UE;
- when the MAC instance begins to encrypt the information received from the MSC in the downstream path, for a frame with number SFN0 in the destination cell, the RRC layer of RNC 61 initializes the counter 23 of this MAC instance to the value CSN0 = ( CSNI - SFNI + SFN0) mod 2<sup>M</sup> , and instructs base station 71 to broadcast to UE 14.
In parallel, in the switch command message that directs the UE through the core network and the originating RNC 60 ("Handover_Command"), the destination RNC 61 indicates the CSNI and SFNI parameters. Thus, at the time the UE switches over, it can reset its counter 23 to align with that of the RNC 61, which will allow encryption and decryption on the second path.
Indeed, the UE knows the Δ<sub>Q</sub> and its CSN of the previous path at the time of the switch, so that it can deduce the corresponding SFN in the destination cell: SFN = (CSN - A<sub>Q</sub>) mod 2<sup>Q</sup>, and therefore immediately reset its counter 23 to the correct value for the second way:
CSN0 = (CSNI - SFNI + SFN) mod2<sup>M</sup>
Since switching to base station 71, the UE has its CSN number synchronized. Then you can immediately receive the downstream information and broadcast the upstream information with the correct encryption. Once the base station 61 has acquired synchronization, the second path is complete.
This synchronization of the CSN counters is adequate since the execution time of the HHO, between the emission by the originating RNC of the message “Handover_Prepare” and the switching of the UE, does not exceed 2<sup>Q</sup> x 10 ms = 40 s. which in practice is always the case.
The advance of the new CSN with respect to the one used in the cell of origin serves to obtain the double transmission that serves to minimize the interruption due to the HHO, always avoiding that the same encryption mask is produced to encrypt different blocks transmitted by the radio, which is necessary for security reasons.
It is observed that these results are obtained without the need for the destination RNC to receive the information through the originating CFN, which is problematic considering the asynchronous transmission through the core network, even in the Δ phase shift observed by the UE .
To avoid producing the same encryption mask to encrypt different blocks, the initialization CSNI value must be determined based on information supplied from the source RNC, ie the HFNE parameter. The RNC 61 adds an offset θ> 0 to this parameter to form the MP bits with the highest weight of the initialization CSNI value, and assigns a predefined CFNI value to the P bits with the least weight, for example CFNI = 0. In this way, take CSNI = ((HFNE + θ) x 2<sup>P</sup> + CFNI) mod 2<sup>M</sup>.
The lag θ considers the probable execution times of the HHO. In the case where P = 8, we can take, for example, θ = 8, which provides a sufficient margin, of the order of 20 s, for the execution of the HHO. This phase shift θ can also be programmable.
It should be noted that the controllers 60 and 61, operating in the manner described above with reference to Figures 4 to 7, could, according to a variant of the invention, be two different parts of a piece of equipment located at a given node of the network. This equipment can be of the RNC type in the UMTS architecture, and the two different parts can be circuits that independently manage the two paths, at least as regards the MAC layer, these circuits communicating with each other asynchronously. These circuits, for example, are supported by two different cards or contained in two different compartments of the RNC.
It will further be noted that the above HHO process can take various equivalent forms. Thus, instead of explicitly containing CSNI and SFNI, the control message returned from the destination RNC to the UE could only be the difference (CSNI - SFN) mod 2<sup>M</sup> that is enough for the synchronization, or any combination that allows to find this difference.
Furthermore, the CSNI, SFNI data indicated by the destination RNC in the control message returned to the originating RNC and the UE may, totally or partially, be implicit:
- if the offset θ is fixed or known by the originating RNC, it may already have MP bits of greater weight (HFNE + θ) of the CSNI parameter, so it is not essential that it receives them again if it transmits them itself to the EU;
- if the CFNI value is fixed (for example 0), it is not necessary to transmit it to the UE. The same is the case if this value is defined with respect to the SFN of the destination cell since the UE can determine this SFN with the help of its CFN and the offset Δ<sub>Q</sub> that you have measured;
- if the SFNI is a value that the UE can know, for example because it is fixed, it is not necessary to report it. This observation is also valid only for a lower weight part of the SFNI.
In cases where the UE has sent an offset value A to the originating RNC 60<sub>k</sub> between the CSN used jointly by the UE and the source RNC and the SFN of the destination cell (for example k = P
ES 2 203 583 T3 ok = Q), this RNC 60 can communicate it to the destination RNC, in particular, with the message "Handover_Prepare". In this way, it can be considered that the time reference available in the UE, with respect to which the initialization frame of the new counter CSN is defined, is constituted by the least significant k bits of the previous CSN. In particular, it may have had a macro-diversity phase between the source and destination RNCs on a first carrier frequency before performing a carrier change HHO to the destination RNC. In such a case, the destination RNC already has the phase shift Δ<sub>Q</sub> or Δ<sub>Ρ</sub>, so it is not mandatory to repeat it at the time of HHO. Also, another UE may have had a macro-diversity phase between the source (SRNC) and destination (DRNC) RNCs. When the HHO procedure starts at UE 14, the originating RNC 60 can then determine the relevant value of the offset Δι<sub>;</sub> without necessarily being received by the UE 14: it deduces it from the CFN of the two UEs and from the lag measured and indicated by the other UE.
Other time references can be used if they are available at the same time in the destination RNC 61 and the UE or in the originating RNC, to express the initialization frame number SFNI or any quantity related to this number, for example:
- the SFN of another base station related to the destination RNC, whose common control channel has been detected by the UE (or by another UE supervised by the originating RNC);
- the SFN of any base station, in particular that of the originating cell, if the RNCs are aware of the differences in SFN between the different cells, which is perhaps used between subscriber location services;
- a time reference, common to the RNCs, obtained for example by means of GPS or similar type receivers that detect synchronization signals emitted by a constellation of satellites.
Contents3
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
17 members in 11 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 0006562 | France | A | |
| 20000006562 | France | – |
Members17
| Document | Office | Kind | |
|---|---|---|---|
| EP1158827A1 | European Patent Office (EPO) | A1 | |
| WO0191500A1 | World Intellectual Property Organization (WIPO) | A1 | |
| FR2809579A1 | France | A1 | |
| AU6246201A | Australia | A | |
| US2002013147A1 | United States of America | A1 | |
| EP1158827B1 | European Patent Office (EPO) | B1 | |
| FR2809579B1 | France | B1 | |
| AT244493T | Austria | T | |
| ATE244493T1 | Austria | T1 | |
| DE60100414D1 | Germany | D1 | |
| CN1443428A | China | A | |
| PT1158827E | Portugal | E | |
| ES2203583T3This record | Spain | T3 | |
| DE60100414T2 | Germany | T2 | |
| HK1058452A1 | Hong Kong, China | A1 | |
| US6768903B2 | United States of America | B2 | |
| CN1222191C | China | C |
Numbers
- Publication
- 2203583
- Application
- 1401300
Titles2
- Spanish
- PROCEDIMIENTO DE CONTROL DE TRANSFERENCIA DE UN CANAL EN UNA RED DE RADIOCOMUNICACION CELULAR.
- English
- TRANSFER CONTROL PROCEDURE OF A CHANNEL IN A CELLULAR RADIOCOMMUNICATION NETWORK.
Classification
- CPC, 3
- H04L63/0457
- H04W80/02
- H04W12/037
- IPC, 2
- H04W12 00
- H04W36 12