Integrity check in a communication system
Abstract
Method for carrying out an integrity check in a system comprising a first node and a second node (6, 20), a plurality of communication channels being arranged between said first node and said second node, each communication channel having a different identity (RB ID), said method comprising the steps of calculating an authentication code (MAC-I) using a plurality of values, some of said values being the same for said different communication channels, and for transmitting information related to the authentication code (MAC-I) from one of said nodes to the other, said method being characterized in that at least one of said values is arranged to include information regarding the identity of a communication channel (RB ID) of said plurality of communication channels.

Term
Term ended
Projected expiry passed 23 January 2021, 5.7 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
20 claims: 9 independent, 11 dependent
- 1ES 2 249 455 T3 ES 2 249 455 T3 CLAIMS REIVINDICACIONES 1. Method for carrying out an integrity check in a system comprising a first node and a second node (6, 20), a plurality of communication channels being arranged between said first node and said second node, each communication channel having a different identity (RB ID), said method comprising the steps of calculating an authentication code (MAC-I) using a plurality of values, some of said values being the same for said different communication channels, and transmission of information related to the authentication code (MAC-I) from one of said nodes to the other, said method being characterized in that at least one of said values is arranged to include information regarding the identity of a communication channel (RB ID) of said plurality of communication channels. 1. Método para llevar a cabo una comprobación de integridad en un sistema que comprende un primer nodo y un segundo nodo (6, 20), estando dispuesta una pluralidad de canales de comunicación entre dicho primer nodo y dicho segundo nodo, teniendo cada canal de comunicación una identidad diferente (RB ID), comprendiendo dicho método las etapas de cálculo de un código de autentificación (MAC-I) utilizando una pluralidad de valores, siendo algunos de dichos valores los mismos para dichos canales de comunicación diferentes, y de transmisión de información relativa al código de autentificación (MAC-I) desde uno de dichos nodos al otro, estando caracterizado dicho método porque al menos uno de dichos valores está dispuesto para incluir información relativa a la identidad de un canal de comunicación (RB ID) de dicha pluralidad de canales de comunicación.
- 6Method according to any of the preceding claims, wherein said values for calculating the authentication code (MAC-I) comprise one or more of the following values:an integrity key (IK);an address value (DIRECTION), a refresh value (FRESH), a message value (MESSAGE), and a count value (COUNT-I). 6. Método de acuerdo con cualquiera de las reivindicaciones precedentes, en el que dichos valores para calcular el código de autentificación (MAC-I) comprende uno o más de los valores siguientes: una clave de integridad (IK);un valor de dirección (DIRECTION), un valor de refresco (FRESH), un valor de mensaje (MESSAGE) y un valor de recuento (COUNT-I).
- 7Method according to claims 3 or 5 or 6, in which said information related to the identity of the communication channel (RB ID) of said plurality of communication channels is combined with one or more of the following:said refresh value ;7. Método de acuerdo con las reivindicaciones 3 ó 5 ó 6, en el que dicha información relativa a la identidad del canal de comunicación (RB ID) de dicha pluralidad de canales de comunicación se combina con uno o más de cuanto sigue: dicho valor de refresco;dicho valor de recuento;dicha clave de integridad;dicho valor de dirección y dicho valor de mensaje. said count value;said integrity key;said address value and said message value.
- 9Method according to any of the preceding claims, in which the authentication code (MAC-I) is sent from one node to another. 9. Método de acuerdo con cualquiera de las reivindicaciones precedentes, en el que el código de autentificación (MAC-I) se envía desde uno a otro nodo.
- 10Method according to any of the preceding claims, in which said first and second nodes (6, 20) communicate through a wireless connection. 10. Método de acuerdo con cualquiera de las reivindicaciones precedentes, en el que dichos primer y segundo nodos (6, 20) se comunican a través de una conexión inalámbrica.
- 15Método de acuerdo con cualquiera de las reivindicaciones precedentes, en el que dicha pluralidad de canales de comunicación incluye un soporte radio. fifteen. Method according to any of the preceding claims, wherein said plurality of communication channels includes a radio support.
- 17Method according to any of the preceding claims, in which said values are entered in an algorithm (UIA) to calculate said authentication code. 17. Método de acuerdo con cualquiera de las reivindicaciones precedentes, en el que dichos valores se introducen en un algoritmo (UIA) para calcular dicho código de autentificación.
- 19Node for use in a system that includes said node (6, 20) and an additional node (20, 6), providing a plurality of different communication channels between said nodes, each of the communication channels having a different identity, and said node comprising means for calculating an authentication code (MAC-I) from a plurality of values, some of said values being the same for said different communication channels, and to transmit information related to the authentication code (MAC-I) from said node (6. 20) to said additional node (20. 6), characterized in that at least one of said values is arranged to include information related to the identity of a communication channel (RB ID) of said plurality of communication channels. 19. Nodo para utilizar en un sistema que incluye dicho nodo (6, 20) y un nodo adicional (20, 6), proporcionándose una pluralidad de diferentes canales de comunicación entre dichos nodos, teniendo cada uno de los canales de comunicación una identidad diferente, y comprendiendo dicho nodo medios para calcular un código de autentificación (MAC-I) a partir de una pluralidad de valores, siendo algunos de dichos valores los mismos para dichos canales de comunicación diferentes, y para transmitir información relativa al código de autentificación (MAC-I) desde dicho nodo (6. 20) a dicho nodo adicional (20. 6), caracterizado porque al menos uno de dichos valores está dispuesto para incluir información relativa a la identidad de un canal de comunicación (RB ID) de dicha pluralidad de canales de comunicación.
Independent claims9
138 paragraphs in 3 sections, as filed
ES 2 249 455 T3
DESCRIPTION
Integrity check in a communication system.
Scope of the invention
The present invention relates to a method for verifying the integrity of communications between a first node and a second node. Particularly, but not exclusively, the invention relates to a method for verifying the integrity of communications between a mobile station and a cellular network. Background of the invention
Several different telecommunication networks are known. A telecommunication network is a cellular telecommunication network, in which the area covered by the network is divided into a plurality of cells. Each cell has a base station, which provides service to the mobile stations located in the cell associated with the base station. In this way, the user equipment, such as mobile stations, receives the signals from the base station and transmits them to it, and can therefore communicate through the base stations. Similarly, the cellular system typically includes a base station controller, which controls the operation of one or more base stations. At least a part of the user equipment found in the system can communicate simultaneously through one or more communication channels.
Telecommunications faces the problem of ensuring that the information received has been sent by an authorized sender, and not by an unauthorized party who is trying to impersonate the sender. This problem is especially important in the case of cellular telecommunication systems, whose air interface offers a possible opportunity for an unauthorized party to eavesdrop on a transmission and replace its contents. US 4,393,269 presents a method and a device that incorporates a one-way sequence to verify transactions and identity.
One solution to this problem is the authentication of the communicating parties. An authentication process tries to discover and verify the identity of the parties that establish the communication, so that each of the parties receives information regarding the identity of the other party and can trust that identity. Authentication is typically carried out by a specific procedure at the beginning of a connection. However, this procedure can allow unauthorized manipulation, insertion, and deletion of subsequent messages. Separate authentication is required for each message transmitted. This operation can be carried out by attaching to the message a message authentication code (MAC-I) at the transmitting end, and checking the value of the message authentication code MAC-I at the receiving end.
Typically, a MAC-I message authentication code consists of a relatively short string of bits, depending on the message it is protecting, and a secret key known to both the sender and receiver of the message. The secret key is generated and agreed upon during the authentication procedure that takes place at the beginning of the connection. In some cases, the algorithm (which is used to calculate the message authentication MAC-I code based on the secret key and the message) is also secret, but this is usually not the case.
The process of authenticating simple messages is often referred to as integrity protection. To protect the integrity of a message, the transmitting party calculates an authentication value of a message based on the message to be sent and the secret key using the specified algorithm, and sends the message with the value of the MAC code -I of message authentication. The receiving party calculates again the value of the message authentication MACI code based on the message and the secret key according to the specified algorithm, and compares the MAC-I authentication code of the received message and the MAC code -I calculated message authentication. If the two values of the MAC-I authentication code of the message match, the receiver can trust that the message is intact and has been sent by the supposed sender.
Integrity protection schemes can be subject to attack. There are two methods that can be used by an unauthorized party to forge a message authentication MAC-I code value for a new or changed message. The first method involves obtaining the secret key and the second method involves using a new or modified message, without having knowledge of the secret key.
A third party can obtain the secret key in two different ways:
- calculating all the possible keys until finding a key that matches the data of the observed MAC-I message authentication code pairs, or otherwise forcing the algorithm for generating MAC-I values of the message authentication codes; or
- directly capturing a stored or transmitted secret key.
The parties that have originally established communication can prevent a third party from obtaining the secret key, using an algorithm that is cryptographically robust, using a secret key long enough to prevent exhaustive search of all keys, and using a secure method for the transmission and storage of the secret keys.
A third party can try to disrupt the exchange of messages between the parties without having a secret key, guessing the correct MAC-I value of the message authentication code, or re-executing some previous message transmitted between the two parties. In the latter case, the correct MAC-I message authentication code corresponding to the message is known from the original transmission. This type of attack can be very useful to an unauthorized third party. For example, you can multiply the number of additional actions that are favorable to the intruder. In this way, even monetary transactions can be repeated.
The correct value of the MAC-I message authentication code can be prevented from being guessed by using long values for the auten2 code
ES 2 249 455 T3 MAC-I message qualification. The value of the MAC-I message authentication code should be long enough to reduce the probability of a successful hit to a low enough level, compared to the advantage of a successful spoof. For example, using a 32-bit message authentication code MAC-I value reduces the probability of hitting the correct code to 1/4294967296. This probability is low enough for most applications.
Obtaining a correct MACI value of the message authentication code can be prevented by a replay attack, that is, by replaying a previous message, by introducing a variable parameter as a function of time during the calculation of the message authentication MAC-I values. . For example, a timestamp or sequence number can be used as additional information entered into the MAC-I algorithm of the message authentication code, in addition to the integrity secret key and the message.
In the case of using a number sequence as a variable parameter in function of time, a mechanism is used that prevents the possibility of using the same number sequence more than once with the same secret key. Normally, the two parties that establish communication keep track of the sequence numbers used.
If several communication channels are in use that all use the same secret key, the following problem arises: a message on a communication channel associated with a certain sequence number, for example n, can be repeated on another channel that is establishing a communication at an appropriate time, that is, when the sequence number n is acceptable on the other channel.
The application of encryption and integrity protection methods in the UMTS system has been proposed for the third generation standard. However, the method that has been proposed allows the sending of an identical message on two different signaling radio carriers at different times. This makes the system vulnerable to MITM (Man-in-the-Middle) attacks. In particular, these systems can be vulnerable to the "replay attack" described above.
Typically, a single repeated signaling message does not confer a significant advantage on the unauthorized third party, but the unauthorized third party may try to repeat a longer dialogue in order, for example, to set up an additional call and thus take over. portions of a connection.
A technical specification made by the 3rd Generation Partnership Project; Group Services and System Aspects; 3G Security; Security Architecture (3G TS 22.102, version 3.3.1, release 1999) presents a security architecture in which the above problems can occur.
Summary of the invention
One of the purposes of embodiments of the present invention is to address one or more of the problems discussed above.
According to one aspect of the present invention, there is provided a method for carrying out an integrity check in a system that includes a first node and a second node, a plurality of channels being arranged between said first node and said second node, each of the communication channels having a different identity, and said method comprising the step of calculating an authentication code using a plurality of values, some of said values being the same for said different communication channels, as well as the stage of transmitting information related to the authentication code from one of the nodes to the other, configuring at least one of said values so that it includes information related to identity of a communication channel belonging to said plurality of communication channels.
A separate entry may be available for such information regarding the identity of the communication channel. Said information regarding the identity of the communication channel can be combined with at least one other input value. Such values can include one or more of the following values: an integrity key; an address value; a soft drink value; a message value and a count value. The output of the integrity algorithm can be sent from one node to the other. Said communication channels can include a radio support. Said input values can be entered into an algorithm to calculate said output.
According to another aspect of the present invention, a node is provided for use in a system that includes said node and an additional node, a plurality of different communication channels being arranged between said nodes, and each communication channel having a different identity. , said node including means for calculating an authentication code, said authentication code being calculated from a plurality of values, some of said values being the same for said different communication channels, and for transmitting information related to the authentication code from said node to said additional node, in which at least one of said values is arranged to include information relating to the identity of a communication channel (RB ID) of said plurality of communication channels.
Various advantages can be achieved by embodiments of the invention. In the solution offered by the present invention, the attack by reproduction can also be prevented in case of using several parallel communication channels. An advantage is that the embodiments can be flexibly applied to any system that uses parallel communication channels in one connection. Carrying out the present invention can increase user security in communication systems, especially wireless communication systems. Embodiments can ensure that parallel communication channels in a connection never use the same set of input parameters to calculate the message authentication code MAC-I.
Brief description of the drawings
In order to better understand the present invention, and how it can be carried out, reference will now be made, by way of example, to the accompanying illustrations, in which:
Figure 1 shows elements of a cellular network with which embodiments of the present invention can be used.
Figure 2 shows the architecture of the Uu protocol of the radio interface between the UE user equipment.
ES 2 249 455 T3 and Node B, and between the user equipment UE and the radio network controller rNc of figure 1.
Figure 3 schematically shows the integrity protection function.
Figure 4 shows the modified integrity protection function in accordance with embodiments of the present invention.
Fig. 5 shows the modified integrity protection function according to a further embodiment of the present invention.
Figure 6 shows a further embodiment of the present invention.
Figure 7 shows a key and authentication agreement procedure.
Figure 8 shows the generation of authentication vectors.
Figure 9 shows an example of a user authentication function in the USIM, according to an embodiment of the present invention.
Detailed description of embodiments of the invention
With reference to Figure 1, a typical structure of a mobile telephone system will be described. The main components of the mobile telephone system are: a central network CN 2, a UMTS radio network UTRAN 4 and a user equipment 6. The central network CN 2 can be connected to external networks 8, which can be either circuit-switched networks (CS) 81 (eg PLMN, PSTN, ISDN) or packet switched networks (PS) 82 (eg Internet). The interface between the core network CN 2 and the UMTS radio network UTRAN 4 is called the Iu interface, and the interface between the UMTS radio network UTRAN 4 and the user equipment UE 6 is called the Uu interface. As shown in Figure 1, the RNC is connected to two CN nodes (MSC / VLR and SGSN). In some network topologies it may be possible for an RNC to be connected to one CN node or to more than two CN nodes.
The core network is made up of a subscriber location register HLR 10, a mobile services switching center / visitor location register MSC / VLR 12, an MSC GMSC gateway 14, a GPRS Support Node (General Packet Radio SGSN 16 service service) and a GGSN 18 gateway GPRS support node.
The UTRAN 4 is made up of RNS radio network subsystems 20 and 22. The interface between both RNS radio network subsystems is called the Iur interface. The radio network subsystems RNS 20 and 22 are composed of a radio network controller RNC 24 and one or more nodes Bs 26. The interface between the radio network controller RNC 24 and node B 26 is called the interface Iub.
The radio network controller RNC 24 is the network element responsible for controlling the radio resources of the UTRAN 4. The RNC 24 interacts with the core network CN 2 (typically, with an MSC 12 and a SGSN 16) and It is also the term of the RRC radio resource control protocol that defines the messages and procedures exchanged between the UE 6 user equipments and the UTRAN 4 network. The RNC 24 logically corresponds to the base station controller of the GSM standard (global system for mobile communications).
The main function of Node B 26 is to perform L1 air interface processing (channel and interleaving coding, rate adaptation, distribution, etc.). It also performs some basic radio resource management operations, such as inner loop power control. From a logical point of view it corresponds to the transmitter-receiver base station of the GSM standard.
The user equipment UE 6 consists of two components: the mobile equipment ME 30 and the subscriber identification module UMTS USIM 32. The mobile equipment ME is the radio terminal used for radio communications through the Uu interface between the equipment of user UE 6 and the network UTRAN 4. The USIM 32 is a smart card that stores the identity of the subscriber, executes the authentication algorithms and stores the authentication and encryption keys, as well as certain information related to the subscription and required by the terminal.
Referring to Figure 2, the architecture of the radio interface protocol will be described in accordance with the 3GPP specifications. The described protocol entities operate between:
- the user equipment UE 6 and the Node B 26, and / or
- the user equipment UE 6 and the RNC 24.
The division of the protocol layers between Node B and RNC 24 will not be described in this document.
The radio interface protocols can be divided into a control plane 50 and a user plane 52. Control plane 50 is used for all signaling between UE 6 and RNC 24, as well as between UE 6 and the core network. CN 2. The user plane carries the actual user data. Some of the radio interface protocols operate only in one plane, while some protocols operate in both planes.
Radio interface protocols can be divided into layers, such as layer 1 L1 54 (also called the physical layer), layer 2 L ”56 (also called the data link layer) and layer 3 L3 58 (also called the network layer). Some layers contain only one protocol, while other layers contain several different protocols.
The L1 physical layer 54 offers services to the medium access control (MAC) layer 60, through transport channels characterized by the form and characteristics with which the data is transferred.
In turn, the medium access control (MAC) layer 60 offers services to the radio link control layer 62 through logical channels. Logical channels are characterized by the type of data transmitted. In the MAC medium access control layer 60, the logical channels are mapped to the transport channels.
The RLC radio link control layer 62 offers services to the upper layers through SAP service access points, which describe how the RLC radio link control layer 62 handles data packets and whether, for example, an automatic repeat request (ARQ) function is used. In the control plane 50, the RLC radio link control services are used by the RRC radio resource control layer 64 for transport signaling. Typically, a minimum of three RLC radio link control entities 62 are dedicated to transport signaling - one transparent entity, one unrecognized mode, and one recognized mode. In user plane 52, RLC services are used either by the service-specific protocol layers - PDCP 66 packet data convergence protocol or BMC 68 multicast emission control - or by
ES 2 249 455 T3 any other higher layer user plane functions (eg speech codecs). RLC services are called control plane signaling radio bearers and user plane radio bearers for those services that do not use the PDCP or BMC protocols.
The packet data convergence protocol (PDCP) exists only for PS packet-switched domain services (services routed through the SGSN) and its main function is header compression, which means compression of the redundant protocol control (eg TCP / IP and RTP / UDP / IP headers) at the transmitting entity, and its decompression at the receiving entity. The services offered by PDCP are called radio beacons.
The Multicast Broadcast Control Protocol (BMC) exists only for the SMS Cell Broadcast Service short message service, which is derived from GSM. The service offered by the BMC protocol is also called a radio bearer.
The RRC layer 64 offers services to the upper layers (the no-access stratum) through service access points. All the higher layer signaling between the user equipment UE 6 and the core network CN 2 (mobility management, call control, session management, etc.) is encapsulated in RRC messages for transmission over the radio interface.
The control interfaces between the RRC layer 64 and all lower layer protocols are used by the RRC layer 64 to configure the characteristics of the lower layer protocol entities, including parameters for the physical, logical and transport channels. These same control interfaces are used by the RRC layer 64, for example, to instruct the lower layers to perform various types of measurements, and by the lower layers to inform the RRC layer of the measurement results and errors.
The embodiment of the invention is described in the context of a UMTS (Universal Mobile Telecommunications System) system. The present invention is applicable to all types of communication, for example, signaling, real-time services, and non-real-time services. However, it should be appreciated that the embodiments of the present invention are applicable to any other system.
In the proposal of the UMTS standard corresponding to the third generation, the SGSN 16 and the user equipment UE 6, for example, a mobile station, have an upper layer L3 that supports the mobility management MM (sometimes called GMM) and SM session management. This upper layer also supports the SMS short message service. These upper layer L3 protocols are derived from the second generation GPRS system. The SMS service supports the mobile-originated and mobile-terminated message service described in the third-generation specification 3GPP TS 23.040. The mobility management function manages the location of the mobile station, that is, the connection of the mobile station to the network and its authentication. In this way, the MM manages mobility management functions, such as connect, disconnect, security (ie, authentication), and routing updates. According to one embodiment, the integrity keys can be calculated during the authentication procedure of the MM. An embodiment of this aspect of the present invention will now be explained in greater detail, by way of example.
The SGSN 16 and RNS 20 have a Radio Access Network Application Protocol (RANAP) layer. This protocol is used to control the Iu interface bearers, but it also encapsulates and carries the signaling from the upper layers. The RANAP layer manages the signaling between the SGSN 16 and the RNS 20. The RANAP protocol is described in the specification corresponding to the third generation 3GPP TS 25.413. The mobile station 6 and the RNS 20 both have a radio resource control protocol RRC that provides control of the radio bearer via the radio interface, for example, for the transmission of higher layer signaling messages and SMS messages. . This layer handles most of the communications between the mobile station 6 and the RNC 24. An RRC is specified, for example, in the specification for the third generation 3GPP TS 25.331.
MM, SM and SMS messages are sent from SGSN 16 to RNS 20 encapsulated in a RANAP protocol message (the message is called a direct transfer in the 3GPP specifications). The packet is sent by the RANAP layer of RNC 24 to the RRC layer of RNC 24. The transmission function in the RNS 20 effectively separates the RANAP headers and transmits the useful data in the RRC protocol, using a suitable primitive, so that the RRC layer knows that it is a higher layer message that must be sent to mobile station 6. The RNC 24 inserts a message integrity checksum (RRC) that carries the higher-level message in the payload (the RRC message is called a direct transfer in the 3GPP specifications). The RNC 24 can also encrypt the message. This operation will be described in more detail later. The RNS 20 sends the packet through the air interface to the mobile station 6.
In the mobile originating direction, the RRC layer of mobile station 6 receives the message from the higher layer, encapsulates it in an RRC direct transfer message and adds a message authentication code to it before sending it to RNS 20. The message is transmitted from the RRC layer to the RANAP layer of RNS 20. The RNS 20 verifies the information associated with the message to check if the integrity of the packet has been verified.
Next, the integrity check procedure will be described. Most of the information elements of RRC radio resource control, MM mobility management, and SM session management (as well as other higher layer protocols) are considered sensitive and their integrity should be protected. Because of this, an integrity function can be applied in most of the RRC signaling messages transmitted between the mobile station and the RNS 20. However, these RRC messages that are sent before the integrity key is known can be ignored. The integrity function uses an integrity algorithm with the integrity key IK to calculate a message authentication code for a given message. This operation is carried out in the mobile station and in the RNS, since both have the integrity key IK and the integrity algorithm.
Reference should be made to figure 3, which shows
ES 2 249 455 T3 the use of the integrity algorithm to calculate the MAC-I message authentication code.
The algorithm input parameters are the integrity key IK, a message number or time dependent COUNT-I input, a random value by the FRESH network, the DIRECTION address bit, and the MESSAGE signaling data. This last entry is the message or data packet. Based on these input parameters, the UIA integrity algorithm calculates a message authentication code corresponding to data integrity (MAC-I). This MACI code is then attached to the message before it is sent through the air interface, either to or from the mobile station.
The receiver of said code and message also calculates a message authentication code corresponding to the XMAC-I data integrity in the received message using the same UIA algorithm. The UIA algorithm has the same inputs as the sending end of the message. The codes calculated by the algorithm at the sending end (MACI) and at the receiving end (XMAC-I) should be the same, in case the integrity of the message needs to be verified.
The input parameter COUNT-I is a value that is increased by one for each message whose integrity is protected. COUNT-I consists of two parts: the hyperframe number (HFN), as the most significant part, and a message sequence number, as the least significant part. The initial value of the hyperframe number is sent by the mobile station to the network during the establishment of a connection. When the connection is released, the mobile station stores the largest hyperframe number used since the connection, and increases its value by one. This value is then used as the initial HFN value for the next connection. This ensures that the user (the network) does not reuse any COUNT-I values with the same integrity key for different connections. After a (re) authentication procedure, when a new IK is generated and put into use, the HFN value can be reset to zero again.
The FRESH input parameter protects the network against the reproduction of signaling messages by the mobile station. During connection establishment, the network generates a random FRESH value and sends it to the user. Subsequently, the FRESH value is used by both the network and the mobile station throughout the duration of a single connection. This mechanism ensures to the network that the mobile station is not replaying any old MAC-I message authentication code from a previous connection.
The IK integrity key configuration is done as described in this document. The password can be changed as often as the network operator wants. The configuration of the key can be done as soon as the identity of the mobile subscriber is known. The IK key is stored in the visitor location register and transferred to the RNC when required. The IK key is also stored in the mobile station until it is updated in the next authentication.
A KSI key string identifier is a number that is associated with the encryption and integrity keys obtained during the authentication procedure. It is stored together with the encryption and integrity keys on the MS and on the network. The key series identifier is used to allow reuse of the key during subsequent connection establishment. The KSI is used to verify if the MS and the network will use the same encryption and integrity keys.
A mechanism is provided to ensure that a specific integrity key is not used for an unlimited period of time, in order to prevent attacks that use compromised keys.
The authentication process that generates integrity keys is not mandatory at the time of connection establishment.
The mobile station is configured to start the generation of a new encryption key and a new integrity key, in the event that the counter reaches a maximum value set by the operator and stored in the mobile station the next time it is sent. the RRC connection request message. This mechanism will ensure that an integrity key and an encryption key cannot be reused more times than the limit set by the operator.
It should be noted that there may be more than one integrity algorithm, information is exchanged between the mobile station and the radio network controllers defining the algorithm. It should be noted that the sender and receiver of the messages should use the same algorithm.
When a mobile station wishes to establish a connection to the network, the mobile station will indicate to the network which version or versions of the algorithm the MS supports. The integrity of the message itself, which is transmitted to the RNC after the authentication procedure has been completed, must be protected.
The network will compare its integrity protection capabilities and preferences, as well as any special subscription requirements of the mobile station with those indicated by the mobile station, and will act in accordance with the following rules:
1) If the mobile station and the network do not have common versions of the algorithm, the connection should be released.
2) If the mobile station and the network have at least one version of the algorithm in common, the network will then select one of the mutually acceptable versions of the algorithm for use in said connection.
Integrity protection is carried out by attaching the MACI message authentication code to the message whose integrity is to be protected. The mobile station can attach the MAC-I to the messages as soon as it has received a connection-specific FRESH value from the RNC.
If the value of the hyperframe number HFN is greater than or equal to the largest value stored in the mobile station, the mobile station indicates to the network during the establishment of the RRC connection that it is necessary to initialize a new agreement on authentication and keys.
The RNC can be configured to detect that new security parameters are needed. This procedure can be initiated due to (repeated) failure of the integrity checks (eg COUNT-I has lost its synchronization) or if the handover to a new RNC does not support an algorithm selected by the old RNC, etc.
ES 2 249 455 T3
A new encryption key CK is established each time an authentication procedure is executed between the mobile station and the SGSN.
The integrity key IK can be changed if the mobile station passes from one base station to a different base station.
It should be noted that, in embodiments of the invention, the integrity check can only start at any point after the connection is established, as well as be attached.
It should also be noted that, in the case of data connections, the connection may remain open for relatively long periods of time, and may even remain permanently open.
It has been agreed that more than one signaling radio bearer, that is, a radio bearer in the control plane, which is a service offered by RLC, can be established between a mobile station or other user equipment 6 and the RNS 20. The Current 3GPP specification proposes that up to four signaling radio bearers can be provided.
In the current 3GPP specification, two or more of the SRB signaling radio bearers may have the same input parameters for the integrity algorithm shown in Figure 3. If all the input parameters of the integrity algorithm are the same, the output will be the same.
The current proposal, as mentioned above, leaves open the possibility that an intruder or "ambush" repeats a signaling message from a radio signaling medium or other radio signaling medium. The COUNT-I value is specific to each signaling radio bearer, and may be different on different signaling bearers. Consider the following scenario: a message has been sent on a first signaling radio bearer SRB1 with a COUNT value of 77. When the count value corresponding to a second signaling radio bearer SRB2 reaches the value 77, the unauthorized party you can just repeat the message previously sent through SRB1 using SRB2.
Typically, a single signaling message from one signaling radio bearer repeated on the second signaling radio bearer does not confer a significant advantage to "ambushing", but the unauthorized party may also repeat a longer dialogue to, for example, For example, establish an additional call that can use "ambush", and thus, hijack components of the connection. A simpler example of a “repeat attack” would be that the unauthorized party could, for example, repeat a dialogue held via SMS, said dialogue being, for example, a monetary transaction.
With current third generation proposals, this problem can only arise in a limited number of circumstances. This is due to the fact that the use of the four Signaling Radio Beacons (SRB) is limited. Only certain RRCs can be sent on certain signaling radio carriers. The “repeat attack” scenario would be possible for a message corresponding to a non-access stratum (NAS) (CM / MM / SMS messages carried in an RRC direct transfer) or to a NAS message dialogue between the UE and the SGSN / MSC . The RRC download is an RRC message that carries in payload all NAS messages across the air interface. However, this problem could harm a mobile user as, for example, SMS messages could be adversely affected.
There are two basic solutions to the "repeat attack" problem. First, the different communication channels using the same secret key can coordinate the use of COUNT-I sequence numbers in such a way that each sequence number is used at most only once on any of the channels. This coordination can be very uncomfortable, and even impossible in certain situations. It should be noted that when the implementations are applied to the radio interface of the 3-cell network<sup>to </sup>UMTS generation, the communication channels can be called radio bearers.
As will be discussed in greater detail, embodiments of the present invention use a solution in which an additional parameter is used as input to calculate the MAC-I authentication code of the message. The value of this parameter is unique at least for each communication channel that uses the same secret key. The value can also be unique for all communication channels of a connection between the user equipment UE 6 and the RNS 20.
In a further embodiment of the present invention, the problem is avoided by ensuring that the same integrity key is never used for different parallel communication channels.
With reference to FIG. 4, the modifications made to the known integrity protection function that are incorporated into the present invention are described. These modifications do not cause any changes to the actual UIA integration algorithm.
A communication channel specific parameter is added as input to the integrity protection algorithm. In the 3GPP specifications, this communication channel specific parameter is the radio bearer identification (RB ID). In an example of an application of the present invention, the identification of the radio bearer represents the identity of the signaling radio bearer in the proposed third generation WCDMA system, and can be a variable number between 0 and 3. It should be noted that the The specific parameter of the communication channel used depends on the protocol layer in which the message authentication code is calculated. Still using the 3GPP specification as an example, if the message authentication code were added to the RLC protocol, the parameter would be the identity of a logical channel (see Figure 2). As another possible example, if integrity protection were carried out in the PDCP protocol layer or in the RRC protocol layer, the additional parameter would be a radio bearer identity (see Figure 2). It should be noted that when discussing the control plane of the protocol stack, the terms identity of the signaling radio bearer and identity of the radio bearer are equivalent.
Since the identity of the signaling radio bearer is known to the sender and the receiver, ie the user equipment UE 6 and the RNS 20, it is not necessary to explicitly send the identity information through the radio interface.
Figure 4 shows the possible places where the new parameter can be included without modifying the
ES 2 249 455 T3 UIA integrity algorithm. Since the sender and receiver are similar, when viewed from the input parameter point of view (see figure 3), only one of the parts is shown in the figure
Four. It is necessary to indicate that the receiver and the sender will execute the same algorithm. As can be seen in Figure 4, preferred embodiments include the new parameter by appending it (as a string) to one or more of the existing algorithm input parameters.
In one embodiment, the identification of the RB IB signaling radio bearer is part of the FRESH or COUNT-I input parameters. This is shown by the numbers "1" and "2" in Figure 4, respectively. In practice, the FRESH and COUNT-I parameters would incorporate the FRESH or COUNT-I information and the identification information. For example, if the FRESH value has n bits, the FRESH information would be represented by "a" bits, and the identification information by "b" bits, where a + b = n. In practice, this would mean shortening the FRESH parameter. The same modification can be carried out in the COUNT-I parameter. In a modification, part of the identification of the signaling radio bearer may be provided by the COUNT-I parameter, and part, by the FRESH parameter. However, if COUNTI is shortened, it may take less time to “roll over,” that is, to reach the maximum value and return to zero. If the FRESH parameter is abbreviated, it could be the case that the probability of accidentally repeating the value increases (it is selected randomly).
In a further embodiment, the ID of the signaling radio bearer is part of the integrity key IK. This is illustrated by the number "4" in Figure 4. Since both the sender and the receiver, ie the mobile station and the RNS 20, know the identity of the signaling radio bearer, it is not necessary to send the information of identity through the radio interface with the real MESSAGE. For example, if the MESSAGE has n bits and the RB identity ID has i bits, the actual “MESSAGE” that would be included in the integrity algorithm would have n + i bits. Thus, instead of just the MESSAGE being included in the integrity algorithm, the string of bits included in the integrity algorithm would become the identity of the signaling radio bearer and the MESSAGE. This solution has no impact on security issues (for example, counter lengths) related to the integrity algorithm. This means that no parameters included in the algorithm are shortened.
In some embodiments, it is possible to divide the identification information among more than one entry.
Figure 5 illustrates a further embodiment of the invention, said embodiment having effect on the actual integrity algorithm UIA. In this embodiment, the integrity algorithm is provided with an additional parameter, as shown in figure 5. In this example, when the integrity protection is executed in the RRC protocol layer, the additional parameter is a bearer identification. radio (signaling) RB ID, which is unique to the radio (signaling) support. This parameter is included separately and is used in the calculation performed by the UIA integrity algorithm. In this embodiment, the new media ID (RB ID) of the new parameter is combined with the DIRECTION parameter. This embodiment would effectively make the existing, ie, "old" parameter "DIRECTION" longer, and thus influence the actual integrity algorithm UIA.
In an alternative embodiment, a unique integrity key IK is generated for each radio bearer. This can be achieved by modifying the authentication procedure of an upper layer L3 that supports MM mobility management and SM session management in the proposed UMTS specifications. As briefly explained above, the mobility management function manages the location of the mobile station, that is, the connection of the mobile station to the network and its authentication. The integrity algorithm executed on each of the signaling radio carriers during a modified authentication procedure can yield unique results, preventing the type of attack explained above.
Reference will now be made to Figures 7 to 9, which show some possible authentication and key agreement procedures. The mechanisms described achieve mutual authentication by the user and the network, showing the knowledge of a secret key K that is shared between, and available only for the user services identification module USIM and the authentication center AuC of the home environment of user HE. In addition, the USIM and the HE keep track of the SeQ counters.<sub>ms</sub> AND SEQ<sub>i have</sub>, respectively, to support network authentication.
The method can be designed in a way that is compatible with, for example, the current GSM security architecture and facilitates the migration from GSM to UMTS. The method consists of a challenge / response protocol identical to the GSM subscriber authentication and key establishment protocols, combined with a number-based sequence pass protocol for network authentication, derived from the ISO ISO / IEC standard. 97984. Before explaining the generation of integrity keys, an authentication mechanism and agreement on keys will be discussed. Figure 7 shows a summary of a possible authentication and key agreement mechanism. Figure 8 shows a possible procedure for the generation of authentication vectors.
Upon receiving a request from the VLR / SGSN, the HE / AuC sends an ordered matrix of n authentication vectors (the equivalent of a GSM "triplet") to the VLR / SGSN. Each authentication vector consists of the following components: a random number RAND, an expected response XRES, an encryption key CK, an integrity key IK, and an authentication token AUTN. Each authentication vector is valid for an authentication and key agreement between the VLR / SGSN and the USIM.
When the VLR / SGSN initiates an authentication and key agreement, it selects the next authentication vector in the array and sends the RAND and AUTN parameters to the user. The USIM checks if AUTCN can be accepted, and if so, generates a RES response which is returned to the VLR / SGSN. The USIM also calculates CK and IK. The VLR / SGSN compares the received RES response with XRES. If they match, the VLR / SGSN considers that the authentication and exchange of agreements on
ES 2 249 455 T3 keys have been successfully completed. The established keys CK and IK will then be transferred by the USIM and the VLR / SGSN to the entities that carry out the encryption and integrity functions. In the proposed UMTS system, these entities could preferably be some of the radio interface protocols described in figure 2. The entities are preferably located in the user equipment UE and in the radio network controller RNC.
The VLR / SGSN can offer secure services even when HE / AuC links are not available by allowing them to use encryption and integration keys previously obtained for a user, so that a secure connection can still be established without the need for authentication and agreement on keys. In this case, the authentication will be based on a shared integrity key, by protecting the data integrity of the signaling messages.
The elements of the authentication will be the AuC of the user's HE (HE / AuC) and the USIM in the user's mobile station. The mechanism may consist of the following procedures:
- distribution of the authentication information from the HE / AuC to the VLR / SGSN. The user's HE is supposed to trust the VLR / SGSN to securely manage the authentication information. The intra-system links between the VLR / SGSN and the HE / AuC are also assumed to be adequately secure. Likewise, it is assumed that the user trusts the HE.
- Mutual authentication and establishment of new encryption and integrity keys between the VLR / SGSN and the MS.
- Distribution of authentication data from a previously visited VLR to the visited VLR. Links between VLRs / SGSNs are assumed to be adequately secure.
The purpose of distributing authentication data from the HE to the SN is to provide the VLR / SGSN with an array of new authentication vectors from the user's HE to perform a series of user authentications. The VLR / SGSN invokes the procedures requesting authentication vectors from the HE / AuC. The authentication data request will include a user identity. If the user is known to the VLR / SGSN through the IMUI, the authentication data request will include the IMUI. If the user is identified by an encrypted permanent identity, the HLR message may instead be included through which the HE can obtain the IMUI. In this case, this procedure and the "user identity request to the HLR" procedure are preferably integrated.
Upon receiving the authentication data request from the VLR / SGSN, the HE may have previously calculated the required number of authentication vectors and retrieved them from the HLR database, or calculated them when requested. The HE / AuC again sends an authentication response to the VLR / SGSN containing an ordered array of n AV authentication vectors (1 ... n). The HE / AuC generates a new sequence number SQN and a non-predictable random value RAND. For each user, the HE / AuC also tracks a counter, which is <sup>SQN</sup>HE.
The USIM sequence number checking mechanism for newness will to some extent allow mis-ordered sequence numbers to be used. The purpose of this operation is to ensure that the rate of authentication failures caused by synchronization failures is low enough. This requires that the USIM be able to store information about previous authentication events that have completed successfully (for example, sequence numbers or important elements thereof). The mechanism will ensure that a sequence number can still be accepted if it is among the last x = 50 sequence numbers generated. This does not prevent a sequence number from being rejected for other reasons, such as an age limit in the case of time-based sequence numbers.
It is not necessary to use the same minimum number x in the systems to guarantee that the rate of synchronization failures is low enough in different usage scenarios, and especially, the simultaneous registration in the service domains CS- and PS-, movements of user between VLR / SGSNs that do not exchange authentication information, or overloaded networks.
The use of SEQHE may be specific to the sequence number generation method. An AMF key and authentication management field may be included in the authentication token of each authentication vector.
Subsequently, the following values can be calculated:
- a message authentication code MAC = F1k (SQN || RAND || AMF), where f1 is a message authentication function;
- an expected response XRES = F2<sub>K </sub>(RAND), where f2 is a message authentication function (possibly truncated);
- an encryption key CK = F3K (RAND), where f3 is a key generation function;
- an encryption key IK = F4K (RAND), where f4 is a key generation function;
- an anonymity key AK = F5K (RAND), where f5 is a key generation function or f5 = 0.
In accordance with embodiments of the present invention, more than one IK is generated. This can be achieved, for example, by modifying the function f4 so that the desired number of Iks is obtained, for example, 4; see figure 9). One possibility is to specify that the f4 function should be started multiple times during the generation of an authentication vector. This can be done, for example, by supplying in the second stage the first IK [1] generated as input to the function f4, instead of a new RAND value. In the third “stage”, the IK [2] generated in the second stage would be included in the function
ES 2 249 455 T3 f4 to obtain the third integrity key IK [3]. One possibility is also to introduce a desired number of RAND values in the function f4. In this way, it is possible to generate as many Iks as necessary for the system in question. For example, in the UMTS system according to the 3GPP delivery 99 specifications, four integrity keys would be required.
The authentication symbol AUTN = SQN + AK || AMF || MAC can be built below. AK is the anonymity key used to conceal the sequence number, as the sequence number can reveal the identity and location of the user. Sequence number concealment is done to protect against passive attacks only. If concealment is not necessary, f5 = 0.
The purpose of the authentication and key agreements procedure is to authenticate the user and establish a new encryption and integrity key pair between the VLR / SGSN and the MS. During the authentication process, the user verifies the novelty of the authentication vector used. The VLR / SGSN invokes the procedure by selecting the next unused authentication vector from the ordered array of authentication vectors from the VLR database. The VLR / SGSN sends the user the RAND challenge random value and an authentication token for AUTN network authentication from the selected authentication vector. When received, the user proceeds as shown in Figure 9.
When receiving RAND and AUTN, the user first calculates the anonymity key AK = F5<sub>K </sub>(RAND) and retrieves the sequence number SQN = (SQN + AK) + AK. The user then calculates XMAC = F1k (SQNIIRANDIIAMF), and compares it to the MAC value included in AUTN. If they are different, the user sends a “user authentication reject” message to the VLR / sGsn with an indication of the cause, and the user exits the procedure. The USIM then checks if the received SQN sequence number is in the correct range.
According to one embodiment of the present invention, the USIM generates more than one IK instead of generating just one IK, as explained above. This can be achieved, for example, by modifying function f4, specifying that function f4 should be started several times during generation of an authentication vector or by entering a desired number of RAND values in function f4. This may require that the network (SN / VLR) send the required number of RANds and AUTNs to the UE and that the UE may need to also generate a RES for each rAnd and return all generated RESs values to the network, as described above. in the case of a RAND-AUTN value.
Embodiments of the present invention can be used in any system that allows unencrypted signaling and uses integrity checksums on at least two parallel radio bearers.
Embodiments of the present invention have been described in the context of a cellular wireless telecommunication network. However, alternative embodiments of the present invention can be used with any other type of communication network, both wireless and otherwise. Embodiments of the present invention can be used for any form of communication in which integrity checks or the like are provided with a plurality of radio carriers or the like in parallel.
Contents3
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
41 members in 15 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 0004178 | United Kingdom | A | |
| 20000004178 | United Kingdom | – |
Members41
| Document | Office | Kind | |
|---|---|---|---|
| GB0004178D0 | United Kingdom | D0 | |
| CA2368530A1 | Canada | A1 | |
| WO0163954A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2848501A | Australia | A | |
| EP1169880A1 | European Patent Office (EPO) | A1 | |
| US2002044552A1 | United States of America | A1 | |
| IL145606D0 | Israel | D0 | |
| CN1363195A | China | A | |
| JP2003524353A | Japan | A | |
| AU772195B2 | Australia | B2 | |
| EP1432271A2 | European Patent Office (EPO) | A2 | |
| CN1156196C | China | C | |
| EP1432271A3 | European Patent Office (EPO) | A3 | |
| AU772195C | Australia | C | |
| EP1169880B1 | European Patent Office (EPO) | B1 | |
| AT306798T | Austria | T | |
| ATE306798T1 | Austria | T1 | |
| JP3742772B2 | Japan | B2 | |
| DE60113925D1 | Germany | D1 | |
| US7009940B2 | United States of America | B2 | |
| ES2249455T3This record | Spain | T3 | |
| DE60113925T2 | Germany | T2 | |
| US2006159031A1 | United States of America | A1 | |
| IL145606A | Israel | A | |
| IL175752D0 | Israel | D0 | |
| CA2368530C | Canada | C | |
| EP1432271B1 | European Patent Office (EPO) | B1 | |
| AT472909T | Austria | T | |
| ATE472909T1 | Austria | T1 | |
| DE60142494D1 | Germany | D1 | |
| PT1432271E | Portugal | E | |
| ES2346435T3 | Spain | T3 | |
| DK1432271T3 | Denmark | T3 | |
| DK1432271T5 | Denmark | T5 | |
| IL175752A | Israel | A | |
| US8014307B2 | United States of America | B2 | |
| US2012051225A1 | United States of America | A1 | |
| US8774032B2 | United States of America | B2 | |
| US2014323091A1 | United States of America | A1 | |
| CY1111052T1 | Cyprus | T1 | |
| US10187794B2 | United States of America | B2 |
Numbers
- Publication
- 2249455
- Application
- 1953645
Titles2
- Spanish
- COMPROBACION DE INTEGRIDAD EN UN SISTEMA DE COMUNICACIONES.
- English
- INTEGRITY CHECK IN A COMMUNICATIONS SYSTEM.
Classification
- CPC, 7
- H04W12/06
- H04L63/0869
- H04L63/123
- H04W12/10
- H04W76/11
- H04W12/037
- H04W12/02
- IPC, 4
- H04M3 42
- H04L9 16
- H04L9 18
- H04W12 00