Method of ciphering data transmission and a cellular radio system employing the method
Abstract
Method of encryption of a data transmission in a radiocommunication system comprising at least one transceiver (102) that communicates with other transceivers (108) over a radiocommunication connection, characterized in that the connection includes two parallel radiocommunication carriers (116 ), and the method comprises performing the encryption on said carriers using parameters selected from the encryption method, in which different parameters of the encryption method are used on each parallel radio bearer (116).

Term
Term ended
Projected expiry passed 28 January 2019, 7.7 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
22 claims: 3 independent, 19 dependent
- 1ES 2 272 046 T3 ES 2 272 046 T3 CLAIMS REIVINDICACIONES 1. Encryption method of a data transmission in a radiocommunication system comprising at least one transceiver (102) that communicates with other transceivers (108) over a radiocommunication connection, characterized in that the connection includes two parallel radiocommunication bearers (116 ), and the method comprises performing encryption on said carriers using selected parameters of the encryption method, wherein different parameters of the encryption method are used on each parallel radio bearer (116). 1. Método de cifrado de una transmisión de datos en un sistema de radiocomunicaciones que comprende por lo menos un transceptor (102) que se comunica con otros transceptores (108) sobre una conexión de radiocomunicaciones, caracterizado porque la conexión incluye dos portadores de radiocomunicaciones paralelos (116), y el método comprende la realización del cifrado sobre dichos portadores usando parámetros seleccionados del método de cifrado, en el que sobre cada portador de radiocomunicaciones paralelo (116) se usan parámetros diferentes del método de cifrado.
- 18Cellular radiocommunication system that comprises, in each cell, at least one base station (104) that communicates with terminals (102) located in its coverage area, the system comprising a base station controller (106) that controls the operation of one or more base stations, said base station controller and the base stations controlled by it forming a base station system (132), characterized in that at least some of the terminals of the system are arranged to communicate simultaneously on two radio bearers (116), and said terminals are arranged to use encryption on the radio bearers, in which the base station system and the Terminals are arranged to use different parameters of the encryption method on each radio bearer used simultaneously. 18. Sistema celular de radiocomunicaciones que comprende, en cada célula, por lo menos una estación base (104) que se comunica con terminales (102) ubicados en su área de cobertura, comprendiendo el sistema un controlador de estaciones base (106) que controla el funcionamiento de una o más estaciones base, formando dicho controlador de estaciones base y las estaciones base controladas por el mismo un sistema de estaciones base (132), caracterizado porque por lo menos algunos de los terminales del sistema están dispuestos para comunicarse simultáneamente sobre dos portadores de radiocomunicaciones (116), y dichos terminales están dispuestos para usar el cifrado sobre los portadores de radiocomunicaciones, en el que el sistema de estaciones base y los terminales están dispuestos para usar parámetros diferentes del método de cifrado sobre cada portador de radiocomunicaciones usado simultáneamente.
- 22Transceiver (102) in a radio communication system, characterized in that the transceiver is arranged to communicate with other transceivers (108) in the system over a connection that includes two parallel radio bearers (116), and in that the transceiver (102) is arranged to perform an encryption on said carriers using selected parameters of the encryption method, such that different parameters of the encryption method are used on each parallel radio bearer (116). 22. Transceptor (102) en un sistema de radiocomunicaciones, caracterizado porque el transceptor está dispuesto para comunicarse con otros transceptores (108) del sistema sobre una conexión que incluye dos portadores de radiocomunicaciones paralelos (116), y porque el transceptor (102) está dispuesto para realizar un cifrado sobre dichos portadores usando parámetros seleccionados del método de cifrado, de tal manera que sobre cada portador de radiocomunicaciones paralelo (116) se usan parámetros diferentes del método de cifrado.
Independent claims3
95 paragraphs in 5 sections, as filed
ES 2 272 046 T3
DESCRIPTION
Encryption method of a data transmission and cellular radiocommunication system using said method.
Field of the invention
The present invention relates to a method of encrypting a data transmission in a radiocommunication system comprising at least one transceiver that communicates with other transceivers over a radiocommunication connection that includes one or more radiocommunication bearers or parallel logical channels . Background of the invention
Today, encryption is used in many data transmission systems to prevent transmitted data from falling into the hands of an unauthorized user. The importance of encryption has grown in recent years, particularly as wireless telecommunications have become more and more widespread.
Encryption can be performed, for example, by encrypting the information to be transmitted at a transmitter, and decrypting the information at a receiver. The term encryption means that the information to be transmitted, for example a bit stream, is multiplied by a certain number of encryption bit patterns, making it difficult to find out what the original bit stream was if the encryption used is unknown.
The prior art discloses many different encryption methods. Such methods are described, for example, in FI 962 352 and WO 95/01684.
In a digital GSM system, for example, the encryption is performed on the radio communication path: an encrypted bit stream is formed to be transmitted on the radio communication path by applying the XOR operator to the data bits with encryption bits, the bits being formed encryption by an algorithm known per se (algorithm A5), using an encryption key Kc. Algorithm A5 encrypts the information transmitted on the traffic channel and the control channel DCCH.
The encryption key Kc is set when the network has authenticated the terminal even though the traffic on the channel has not yet been encrypted. In the GSM system, the terminal is identified based on the International Mobile Subscriber Identity IMSI, which is stored in the terminal, or on the Temporary Mobile Subscriber Identity TMSI, which is formed based on the identity of the subscriber. A subscriber identification key Ki is also stored in the terminal. The system is also aware of a terminal identification key.
For the encryption to be reliable, the information about the encryption key Kc must be kept secret. For this reason, the encryption key is transmitted from the network to the terminal indirectly. In the network a Random Access Number RAND is formed, and then the number is transmitted to the terminal through the base station system. The encryption key Kc is formed by means of a known algorithm (algorithm A5) from the random access number RAND and the subscriber identification key Ki. The encryption key Kc is calculated in the same way both in the terminal and in the network part of the system.
Therefore, at first, the data transmission over a connection between the terminal and the base station is not encrypted. Encryption is not started until the base station system sends an encryption mode command to the terminal. When the terminal has received the order, it begins to encrypt the data to be sent and to decrypt the received data. Correspondingly, the base station system begins to decrypt the received data after sending the encryption mode command and to encrypt the sent data after the successful reception and decoding of the first encrypted message from the terminal. In the GSM system, the encryption mode command comprises a command to initiate encryption, and information about the algorithm to be used.
Document WO97 / 12461 discloses a method of encrypting an information stream which is to be transmitted in a mobile radio communication system. The method involves modifying parameters used in the encryption process depending on the ordinal number of time slots in a frame.
The problem with known methods is that they have been designed for current systems, so they are rigid and not suitable for encrypting data transmission in new systems, in which several parallel services are possible for one mobile station. For example, in GSM the encryption of both signaling and a real traffic channel is interrelated, and the properties of the encryption cannot be adjusted separately.
Brief description of the invention
It is an object of the invention to provide a method and a system implementing the method, which solve the above problems. This objective is achieved with a method of encrypting a data transmission in a radiocommunication system comprising at least one transceiver that communicates with other transceivers over a radiocommunication connection that includes one or more parallel radiocommunication bearers, the encryption being performed on said carriers by using selected parameters of the encryption method. According to the method of the invention, on each parallel radio bearer, different parameters of the method of
ES 2 272 046 T3 encrypted. At least one of the radio bearers is bidirectional and different parameters of the encryption method are used in different transmission directions.
The invention also relates to a cellular radiocommunication system that comprises, in each cell, at least one base station that communicates with terminals located in its coverage area, the system comprising a base station controller that controls the operation of a or more base stations, a base station system forming said base station controller and the base stations controlled by it, and at least some of the terminals of the system being arranged to communicate simultaneously on one or more radio bearers, and said terminals being arranged to use encryption on the radio bearer. In the system of the invention, the base station system and the terminals are arranged to use different parameters of the encryption method on each radio bearer used simultaneously, and the base station system and the terminals are arranged to have a transmission connection. bidirectional data and to use different parameters of the encryption method in different directions of transmission.
Preferred embodiments of the invention are claimed in the dependent claims.
Several advantages are obtained with the method and system of the invention. In the solution of the present invention, the encryption and its properties can be flexibly controlled even if several parallel bearers are used, either simultaneously (multiplexed in an L1 frame) or based on the principle of time division. When several blocks of data are encrypted in parallel with the XOR method (such as in GSM / GPRS), it is important that the different blocks of data (for example, data from different carriers) are encrypted using different input parameters for the algorithm. encryption. If this is not done, a hacker who is eavesdropping on the transmission and who knows the structure of the sent data (for example, signaling data) may obtain an XOR from the original data and determine the information in the data. , including the original data itself, applying an XOR operator of the encrypted data blocks with the same encryption parameters. Another advantage of the invention is that it can be flexibly applied to radiocommunication systems using a GSM / GPRS core network. No changes are necessary in the A GSM interface, but only in the software of the terminals and the base station system. The present invention improves user safety in new radio systems.
Brief description of the figures
The invention will now be described in more detail by means of preferred embodiments and with reference to the accompanying drawings, in which Fig. 1 shows an example of the structure of a cellular radiocommunication network according to the invention, Fig. 2 shows an example of the structure of a transceiver in a base station, Fig. 3 shows an example of the structure of a subscriber terminal, Fig. 4 illustrates the protocol stacks of a cellular radiocommunication network, Fig. 5 shows an example of a message sequence scheme describing the setting of the encryption mode according to the invention, Fig. 6 shows another example of a scheme of a sequence of messages describing the setting of the encryption mode according to the invention, Fig. 7 shows a third example of a scheme of a message sequence describing the setting of the encryption mode according to the invention, Fig. 8 shows a block diagram of an encryption environment according to the invention, and Fig. 9 shows an example of the calculation of carrier-specific encryption keys (Kc (i)).
Detailed description of the invention
First, note the structure of a typical cellular radiocommunication network of the invention with reference to Fig. 1. Fig. 1 shows only the blocks that are essential to the invention, although it will be apparent to those skilled in the art that A conventional cellular radio network also comprises other functions and structures that are not described in more detail herein. Some of the examples describe a cellular radio network using a TDMA (Time Division Multiple Access) method, although the invention should not be considered limited thereto. The invention can also be used in GSM-based cellular radio networks, which are systems that are at least partially based on GSM specifications. The invention can also be used in the UMTS system (Universal Mobile Telephone System) regardless of the radio transmission technology used.
ES 2 272 046 T3
Typically, the cellular radio communication network comprises an infrastructure of a fixed network, that is, a network part 100, and terminals 102, which can be fixed or mounted on a vehicle, or they can be portable terminals. The network part 100 comprises base stations 104. A varied number of base stations 104 are controlled in a centralized manner by a base station controller 106 connected thereto. Base station 104 comprises transceivers 108. For example, in a TDMA radio system, a transceiver 108 provides radio capability for a TDMA frame, which in the GSM system comprises, for example, eight time slots.
Base station 104 comprises a control unit 110, which controls the operation of transceivers 108 and a multiplexer 112. Multiplexer 112 is used to combine the traffic and control channels used by transceivers 108 on a carrier 114.
The transceivers 108 of the base station 104 are connected to an antenna unit 118, by means of which a two-way radio connection 116 is established with the terminal 102. The structure of the frames to be transmitted on the two-way radio connection 116 is defined specifically for each system, and the connection is called an air interface.
Fig. 2 shows in more detail an example of the structure of a transceiver 108 in a base station. In the receiving direction, the transceiver comprises a receiver 200, in which a signal received from an antenna unit 118 is converted to an intermediate frequency or directly to baseband, and then the converted signal is sampled and quantized in a converter. A / D 202. From the converter, the signal is supplied to an equalizer 204, which compensates for interference, eg, interference caused by multipath propagation. A demodulator 206 takes a bit stream from the equalized signal, and the stream is then forwarded to a demultiplexer 208. The demultiplexer 208 separates the bit stream from different time slots into specific logical channels. From the demultiplexer, the signal is supplied to a deinterleaving and decryption module 209. A channel codec 216 then decodes the bit streams of different logical channels, that is, decides whether the bit stream consists of signaling information, which is forwarded to a control unit 214, or if the bit stream consists of speech, which is forwarded 240 to a transcoder 124 of the base station controller 106. Channel codec 216 also performs error correction. Control unit 214 performs internal control functions by controlling different units.
In the transmission direction, the data coming from the channel codec 216 is subjected to the interleaving and encryption module 227. The encryption can also be located in higher protocol layers (as described in the present invention), in which case Block 227 contains only the interleaving function. The signal is then supplied to a burst former 228, which assembles a burst to be transmitted, for example, by adding a training sequence and a tail sequence. A multiplexer 226 allocates a time slot for each burst. A modulator 224 modulates digital signals into a radio frequency carrier wave. The modulated signal is supplied to a transmitter unit 220, in which the signal is filtered before its transmission, that is, the bandwidth of the signal is limited to a desired range, and after filtering the signal is transmitted by a antenna unit 118. Additionally, transmitter 220 controls the output power of the transmission. A synthesizer 212 arranges the necessary frequencies for different units. A clock included in the synthesizer 212 can be controlled locally or can be centrally controlled from elsewhere, for example, from the base station controller 106. The synthesizer produces the necessary frequencies, for example, by means of an oscillator. voltage controlled.
Next, note the structure of a base station system and a base station controller with reference to Fig. 1. The base station controller 106 comprises a switch matrix 120 and a control unit 122. The switch matrix 120 is used to switch voice and data and to connect signaling circuits. A BSS Base Station System 132 made up of one or more base stations 104 and the base station controller 106 further comprises a transcoder 124. The transcoder 124 is usually located as close as possible to a mobile services switching center 128, since in that case the voice can be transferred in a cellular radio network format between the transcoder 124 and the base station controller 106 , and at the same time saving transmission capacity. In UMTS, the base station controller 106 may be referred to as the Radio Network Controller RNC and the base station 104 may be referred to as the "NodeB".
The transcoder 124 converts the different digital coding methods used between the public switched telephone network and the mobile network so that they are compatible, performing conversions, for example, from the 64 kbit / s format of the fixed network to some other format ( eg 13 kbit / s) of the cellular radio network, and vice versa. The functions of the control unit 122 are call control, mobility management, collection of statistical information, and signaling.
In UMTS, an IWU Interworking Unit 130 is used to adapt the base station system 132 to a second generation GSM mobile services switching center 128 or to a support node 134 of a second generation packet network. In Fig. 1, a circuit-switched connection may be established from terminal 102 to a PSTN Public Switched Telephone Network 136 through mobile services switching center 128. In a cellular radio network, it is also possible to use a packet switched connection, such as a General Packet Radio Service GPRS. The connection between the network by
ES 2 272 046 T3 packets 138 and the IWU 130 is established by a GPRS Service Support Node SGSN 134. The function of the support node 134 is to transfer packets from the base station system to the packet network 138 and keep a record of the location of the subscriber terminal 102 in the node area.
The IWU interworking unit 130 can be implemented as a physically independent unit, such as in Fig. 1, or it can be integrated into the base station controller 106 or the mobile services switching center 128. As shown shown in Fig. 1, when packet transmission is used, data is not necessarily transferred between the IWU 130 and the matrix switcher 120 through the transcoder 124 when the transferred data is not to be transcoded.
Here is an example of the structure of the subscriber terminal 102 with reference to Fig. 3. The structure of the terminal is largely similar to the structure of the transceiver 108 of Fig. 2. In the receiving direction, a signal received from an antenna 300 is supplied to a duplex filter 302, which separates the frequencies used in transmission and reception. From the Duplex filter 302 the signal is supplied to the radio frequency parts 304, in which the signal is converted to an intermediate frequency or directly to baseband, and then the converted signal is sampled and quantized in an AID converter 306. From the In the converter, the signal is supplied to an equalizer 308, which compensates for interference, eg, interference caused by multipath propagation. A demodulator 310 takes a bit stream from the equalized signal, and the stream is then forwarded to a demultiplexer 312. The demultiplexer 312 separates the bit stream from different time slots into specific logical channels. From the demultiplexer, the signal is supplied to a deinterlacing and decryption module 313. The encryption may also be located in higher protocol layers, in which case the block
313 contains only interlacing function. Next, a channel codec 314 decodes the bitstreams of different logical channels, that is, it decides whether the bitstream consists of signaling information, which is forwarded to a control unit 316, or whether the bitstream it consists of speech, which is forwarded to a speech codec 318, which then decodes the speech. From the voice codec, the signal is supplied to a speaker 320. The channel codec
314 it also performs error correction. Control unit 316 performs internal control functions by controlling different units. The term "logical channel" used above refers to the TDMA (GSM) system and has a different meaning in the UMTS system.
In the transmission direction, the signal is supplied from a microphone 322 to a speech codec 318, which encodes the speech. From the speech codec, the signal is supplied to a channel codec 314, in which channel coding is performed. The data obtained from the channel codec 314 is submitted to the interleaving and encryption module 323 (in the case that encryption is performed at layer 1). The signal is then supplied to a burst former 324, which assembles a burst to be transmitted, for example, by adding a training sequence and a tail sequence to the data obtained from the channel codec 314. A multiplexer 326 assigns a time interval for each burst. A modulator 328 modulates digital signals on a radio frequency carrier wave. The modulated signal is supplied to a radio frequency transmitter unit 330, in which the signal is filtered before its transmission, that is, the bandwidth of the signal is limited to a desired range, and after filtering the signal is transmitted through duplex filter 302 through antenna 300. Transmitter 330 also controls the output power of the transmission. A synthesizer 332 arranges the necessary frequencies for different units.
In a mobile system of the invention, for example in the UMTS system, the terminals can communicate with the base station (s) using one or more parallel radio bearers. The term "carrier" will be studied in more detail below. The term "bearer" is a high-level designation for the transmission of information, used in connection with a network service. Depending on the services, the information in the UMTS can usually be transmitted using one or more carriers. The services include, for example, voice transmission, data services and video service. On the other hand, a radio bearer represents that part of the bearer that extends over the air interface. Typically, a logical channel carries a radio bearer. A logical channel defines the service offered by a MAC layer. A logical channel can be mapped to different types of transport channels depending on the existing mode of service (either with a dedicated DCH transport channel or with common RACH / FACH transport channels). Transport channels define the services offered by the physical layer. It is also possible to multiplex several logical channels into one transport channel on the MAC layer. In addition, the transport channels are mapped to physical channels on the physical layer. Several transport channels can be multiplexed into one physical channel by means of layer 1. It is also possible that after multiplexing the transport channels, the data stream is divided into several physical channels.
As the implementation of the present invention refers to the functions and processing of the protocols used in a cellular radio communication network, an example of how the necessary protocol stacks can be implemented will be studied below, referring to Fig. 4 In Fig. 4, protocol stack 400, furthest to the left, is located at terminal 102. The next protocol stack 402 is located at base station system 132. The third protocol stack 404 is located in the IWU 130. The protocol stack 406, furthest to the right, is located in the mobile services switching center 128. To the air interface 116 implemented on the radio bearer between the subscriber terminal 102 and the base station system may also be referred to as the Um interface. The interface 140 between the base station system 132 and the mobile services switching center 128 is called the A interface. The interface 408 between the base station system 132 and the IWU is a lu interface 408.
ES 2 272 046 T3
The protocol stacks are provided according to the ISO (International Organization for Standardization) OSI (Open Systems Interconnection) model. In the OSI model, protocol stacks are divided into layers. In total there can be seven layers. Each unit 102, 132, 130, 128 has a layer which is in logical communication with a layer of another unit. Only the lower physical layers communicate with each other directly. The other layers always use the services offered by the next lower layer. Thus, the message must physically pass in the vertical direction between the layers, and only in the lowest layer does the message pass horizontally between the layers.
The first and second layers of Fig. 4 are partially combined at level 410. The third layer of Fig. 4 is level 412. The functions of the different layers are divided between different sub-layers. Depending on the unit, the number and denominations of the sub-layers vary.
The actual data transmission at the bit level takes place in the lowest (first) physical layer, Layer 1. In the physical layer, mechanical, electrical and functional properties are defined to allow connection to a physical path. At the air interface 116, the physical layer is implemented using, for example, TDMA technology in GSM or WCDMA technology in UMTS.
The next layer (the second), that is, the radio link layer, uses the services of the physical layer to carry out a reliable data transmission, dealing, for example, with the correction of errors of the transmission by means of mechanisms Suitable ARQs.
At the air interface 116, the radio link layer is divided into an RLC / MAC sublayer and a LAC sublayer. In the RLC / MAC (Radio Link Control / Medium Access Control) sublayer the function of the RLC part is to segment and assemble the transmitted data. Additionally, the RLC part hides from the upper layers any variation in the quality of the radio bearer 116 of the physical layer. The lAc (Link Access Control) sublayer controls the flow of data at the interface between the second and third layers. The LAC layer transfers the received data stream along the radio bearer 116, using the levels of error detection and correction required by the level of quality of service offered. Another possible embodiment is one in which a sublayer of the radiocommunication network, which will be presented later, communicates directly with the RLC / MAC sublayer. In this last embodiment, between the mobile station and the central network, the LAC sublayer, transparent for the radio access network, can continue to exist.
The third layer, that is, the network layer, constitutes the upper layers that do not depend on data transmission and provides switching techniques by which the connection between the terminals is handled. For example, the network layer establishes, maintains, and releases a connection. In GSM, the network layer is also called the signaling layer. It has two main functions: it routes messages, and it allows several simultaneous connections between two entities.
First, look at the GSM network layer. In a common GSM system, the network layer comprises a CM connection management sublayer, a MM Mobility Management sublayer, and a Radio Resource Management sublayer.
The radio resource management sub-layer is dependent on the radio technology used in GSM and manages the frequency spectrum and system reactions to any change in radio conditions. Additionally, it maintains a high quality channel, for example taking care of channel selection, channel release, all frequency hopping sequences, power control, time tuning, reception of measurement reports from the subscriber terminal , setting a timing advance, setting the encryption mode, and handover between cells. The messages are transferred in the sublayer between the subscriber terminal 102 and the base station controller 106. In the downlink direction, some of the radio resource management messages can be transferred from the base station to the subscriber terminal 102 .
The mobility management sublayer MM deals with any of those consequences resulting from the mobility of the terminal user that are not directly associated with the operation of the radio resource management sublayer. In a fixed network, the sublayer would check the authorization of the user and control the initiation of a session on the network. Thus, in a cellular radiocommunication network, the sublayer supports the mobility of the user, his registration, and the management of the data resulting from the mobility. Additionally, the sublayer checks the identity of the subscriber terminal and the identities of the services that the terminal is authorized to use. In this sublayer, messages are transferred between the subscriber terminal 102 and the mobile services switching center 128.
The CM connection management sublayer manages all the functions related to the management of a circuit switched call. The functions are handled by a call management entity; the other services, such as an SMS (Short Message Service), have their own entities. The connection management sublayer does not detect user mobility. In GSM, the functions of the connection management sub-layer are therefore obtained almost directly from the ISDN (Integrated Services Digital Network) of the fixed network. The call management entity establishes, maintains and releases calls. Different procedures are available for calls initiated by
ES 2 272 046 T3 the subscriber terminal 102 and for the corresponding ones destined to the latter. Messages are also transferred in this sublayer between subscriber terminal 102 and mobile services switching center 128.
Fig. 4 illustrates a protocol stack of the UMTS system. In a normal physical layer in GSM, TDMA technology is used. In UMTS, the latter is replaced by broadband CDMA (Code Division Multiple Access) technology or by a combination of broadband TDMA and CDMA technologies. In that case, in UMTS, the aforementioned GSM radio resource management sub-layer cannot be used again; instead, it is replaced by an RNL Radiocommunication Network sublayer that provides the same services in the upstream direction. The radio network sub-layer can be divided into RBC (Radio Bearer Control) and RRC (Radio Resource Control) sub-layers, although it can also be maintained without dividing it. If it is kept undivided, it can be called the RRC sublayer. If divided into sub-layers, the RRC sub-layer, for example, handles cellular information broadcasting, paging, processing of measurement results from subscriber terminal 102, and handovers. On the other hand, the RBC sublayer deals with the establishment of a logical connection, thus defining, for example, the bit rate and other parameters of the physical layer necessary for the radio bearer, the bit error rate, and defining also if it is a type of reservation of physical resources by packet switching or by circuit switching.
For dual mode terminals (UMTS + GSM), a UAL (UMTS Adaptation Layer) sublayer is required between the mobility management and radio network sublayers in the subscriber terminal 102. In the UAL sublayer, the primitives of the mobility management sublayer become the primitives of the radio network lower sublayer. The UAL layer allows the adaptation of several mobility management sub-layers of 2<sup>to</sup> generation (eg GPRS and GSM mobility management sub-layers) to a single radio network sub-layer.
The only radio network sublayer processed in base station system 132 is the radio network sublayer; the messages of the connection management and mobility management sub-layers are processed transparently, for example, they can be carried as payload in RRC messages. A RANAP (Radio Access Network Application Part) sublayer provides procedures for the negotiation and management of both circuit-switched and packet-switched connections. It corresponds to the BSSAP (Base Station System Application Part) of the GSM, which consists of a BSSMAP (Base Station System Management Part) and a DTAP (Direct Transfer Application Part).
The lower layers of the lu 408 interface can be implemented, for example, using the ATM (Asynchronous Transfer Mode) protocols SAAUSS7 (ATM Adaptation Layer for Signaling / Signaling System Number 7) and AAL (ATM Adaptation Layer) .
The IWU 130 has the corresponding RANAP, SAA / SS7 and AAL sub-layers and the physical layer as base station system 132. The lower layers between the IWU and the BSS can be implemented with other protocols as well.
Additionally, the IWU 130 and the mobile services switching center 128 comprise a BSSMAP layer, which is used to transfer information about a specified subscriber terminal 102 and control information about the base station system 132 between the IWU 130 and the mobile services switching center 128.
At interface A, the first and second layers can be implemented using MTP and SCCP (Message Transfer Part; Signaling Connection Control Part) sub-layers. Its structure is simpler than in the air interface 116, since, for example, no mobility management is necessary.
Thus, the invention can be applied to a radiocommunication system whose terminals can communicate with other transceivers using one or more parallel radio bearers. Typically, when a call is established between a terminal and a network, a physical channel for a Signaling Radio Bearer Srb is first established between the terminal and the base station subsystem, and once this channel has been established, the actual traffic bearer (s) can be established. SRB can also be called a signaling link.
Next we study an example corresponding to a procedure for setting the encryption mode on a signaling radiocommunication bearer by means of a message sequence scheme shown in Fig. 5. The figure shows a radiocommunication network layer (RNL) and a logical link access control (LAC) layer of the terminal, the corresponding layers of the base station system, and the interworking unit IWU. However, it should be understood that Fig. 5 illustrates only one example of a possible signaling. In the solution of the invention, the decisions associated with encryption can also be made in other protocol layers than those described in relation to Fig. 5.
The setting procedure is carried out after the signaling radio bearer SRB has been established and user authentication with the core network has been performed.
ES 2 272 046 T3
In step 500, the RNL BSS receives an encryption key Kc from a message (ENCRYPTION_MODE_ORDER) sent by the IWU or by the CN node. The message comprises an encryption key and information about the allowed encryption algorithms. The BSS may store the allowed encryption algorithms for this mobile station for future use. The BSS also decides which algorithm or algorithms are used for the signaling radio bearer. The decision is made based on the properties of the terminal. Properties are described, for example, by means of so-called class mark data in GSM. In UMTS, this data can be called "user equipment capabilities". The data describe the technical properties of the terminal, such as the transmission power and encryption capacity of the terminal, and the frequencies supported by the terminal. The terminal sends its class mark data to the network at the beginning of each new connection.
In this specific figure, it is considered, by way of example, that the encryption of the traffic channel is done at the LAC layer. However, the protocol level at which the encryption is performed is not essential to the invention. (The protocol layer used mainly influences the frame number that can be used as an input parameter for the encryption algorithm, see Fig. 8). When the RNL BSS has made a decision on the encryption parameters to use, it sends a request to the LAC BSS layer in step 502 that decryption of the received information should start. The message comprises information on the key Kc to be used and on the algorithm to be used in the uplink direction.
In step 504, the RNL BSS receives an acknowledgment from the LAC BSS layer.
In step 506, the RNL BSS sends an encryption mode message (ENCRYPTION_MODE_ORDER) to the terminal's RNL layer. The message is transmitted in an unencrypted format. In the solution of the invention, the algorithms used in the different transmission directions are contained in the message parameters. If the same algorithm is used in both transmission directions, the message comprises only one algorithm.
In step 508, the RNL MS, after receiving the encryption mode command, requests that the LAC MS layer should start encrypting the transmitted signal and decrypting the received signal using the desired algorithms.
In step 510, the LAC MS sends an acknowledgment to the RNL layer MS.
In step 512, the RNL MS sends an acknowledgment of the encryption mode command (ENCRYPTION_MODE_FULL) to the RNL_BSS. The message is transmitted in encrypted format.
In step 514, the RNL BSS requests the LAC BSS layer to start encryption in the downlink direction. The message or primitive includes information on the algorithm to be used, in case it is different from the algorithm used on the uplink.
In step 516, the LAC BSS sends an acknowledgment to the RNL BSS.
In step 518, the RNL BSS sends a notification to the network indicating that encryption has started.
Considering the above method, neither the terminal nor the base station will send a scrambled signal before the receiving party is able to perform decoding.
The procedure described in Fig. 5 can also be used during connection to change encryption mode parameters of one or more radio bearers.
The system of the invention also makes it possible to change the encryption parameters when the traffic bearers are being established or they are being reconfigured. The encryption parameters, such as the encryption key Kc or the encryption algorithm, may be different on different radio bearers, for example on a traffic bearer and on the signaling radio bearer or between two traffic bearers.
Next we will study an example of a method of setting the encryption mode on a real traffic bearer by means of a message sequence scheme shown in Fig. 6. The figure shows a radiocommunication network layer (RNL) of the terminal and a radio network layer of the base station system. It should be understood that Fig. 6, like Fig. 5, only illustrates one example of a possible signaling. Fig. 6 it does not illustrate all the details of communication, that is, how messages travel in the lower carrier layers and the physical layers. Communication is described as so-called peer-to-peer communication, that is, communication between corresponding layers.
The procedure of setting the encryption mode on a real traffic bearer is performed in connection with the establishment of the radio bearer. The network makes a decision about the encryption parameters of the connection. In step 600, a new traffic bearer is requested from the network.
In step 602, the RNL BSS sends a bearer message to the RNL MS layer. The message comprises a Bearer Identifier BID and a Quality of Service of the bearer in question QOS CARRIER. The message further comprises an encryption algorithm for both transmission directions as parameters. In this way, it is possible
ES 2 272 046 T3 define by means of a single message the use of a different algorithm in different transmission directions. If the same algorithm is used in both transmission directions, then the message comprises only one algorithm. The message further comprises a notification (CHANGEKEYCODE, RECOVERYITERATIONS) indicating whether the encryption key used on the SRB signaling radio bearer should be changed. If the encryption key is changed, the preferred way to calculate the key occurs, for example, using the same algorithm as the one corresponding when the original key Kc was calculated, and using the original RAND random access number and the encryption key Previous Ki as parameters of the algorithm. Often times, an algorithm can be iterated several times in succession, and the number of iterations is determined by the IITERATIONS parameter.
In step 604, the RNL MS sends an acknowledgment to the RNL BSS layer. In step 606, the entities of the second layer (Layer 2) are provided for a new radio bearer, and in step 608, a confirmation of the new bearer is sent to the network. Since the second layer is not provided for the new bearer until a decision has been made on the connection parameters (via messages 602 and 604), setting the encryption mode does not require separate signaling.
The system according to the invention also allows a change in the parameters of the encryption method used on the radio bearer during the connection.
Next, an example of a procedure for setting the encryption mode on a real traffic bearer will be studied by means of a message sequence scheme shown in Fig. 7. The figure shows a radiocommunication network layer (RNL) of the terminal and a radio network layer of the base station system. It should be understood that Fig. 7, such as Fig. 6, illustrates only one example of a possible signaling. Furthermore, Fig. 7 it does not show all the details of the communication, that is, how messages travel in the lower carrier layers and the physical layers.
In step 700, the network sends a bearer reconfiguration request to the RNL BSS layer.
In step 702, the RNL BSS sends the bearer reconfiguration request B_RECNF to the corresponding RNL MS layer located at the subscriber terminal. The reconfiguration request B_RECNF comprises one or more bearer identifiers BID and the corresponding QOS CARRIER qualities of service for the RNL layer of the terminal. The message further comprises an encryption algorithm for both transmission directions as parameters. In this way it is possible to define by means of a single message the use of different algorithms in different transmission directions. If the same algorithm is used in both transmission directions, the message comprises only one algorithm. Another parameter of the message is an indication (CHANGE ENCRYPTION KEY, IITERATION COUNT) on whether the encryption key should be changed. The change of the encryption key can preferably be carried out in the manner described in connection with Fig. 6.
In step 704, the radio network sublayer RNL MS of the subscriber terminal triggers the reconfiguration. After a successful reconfiguration, the subscriber terminal sends an acknowledgment B_COMP comprising a single parameter: the identity of the bearer BID. If the encryption change refers to the bearer used to transfer the B_RECNF and B_COMP messages, then the B_COMP message will be transmitted using the new encryption.
In step 708, the RNL BSS performs the reconfiguration, and in step 710 it sends a confirmation of the configuration to the network.
The reconfiguration according to Fig. 7 can be performed both on signaling radio bearers and on traffic bearers.
Fig. 8 depicts a block diagram defining the basic encryption environment defined in the present invention. In contrast to existing systems (GSM-GPRS), a carrier-specific Kc (i) is used for each parallel radio bearer and therefore the encryption mask (the bit string) produced by the algorithm is carrier-specific . The procedure is performed in a separate computing unit 800 for each carrier. The encryption masks 802 to 806 of the computing unit 800 are combined by XOR operators with the data blocks 808 to 812 of the bearers to obtain the encrypted data. The Frame Number used as an input parameter of the calculation unit depends on the protocol layer in which the encryption function is implemented. If implemented on the LLC layer (such as in GPRS), an LLC frame number must be used and some mechanisms must be defined to convey the used frame number to the receiving entity. If the encryption function is located in the mAc layer or layer 1, a frame number that consists at least partially of the physical frame number (used to transmit the data blocks on layer 1) can be used.
The encrypted data is transmitted over the radio path and decryption is performed at the receiver.
Fig. 9 shows an example of how the bearer-specific encryption key Kc (i) is calculated using the encryption algorithm and the Kc of the signaling radio bearer (in the example, bearer 0) as a starting point. The Kc and algorithm used in this case could also be those for some other bearer than the signaling bearer. Other required input parameters 900, 902 can be calculated for the encryption algorithm according to predefined rules, or they can be included in the signaling messages sent9
ES 2 272 046 T3 two from the BSS to the terminal each time it is necessary to calculate a new Kc (i) (parameters for bearer establishment or reconfiguration or encryption mode command messages).
In GSM, the network can request user authentication at any time during the existence of a radio bearer. In this case, the encryption parameters can be changed. This type of option is also likely in future mobile systems, such as the UMTS system. In the system of the invention, the terminal can have several parallel radio bearers, and on each radio bearer, different encryption parameters can be used. Since the actual encryption is preferably performed over a connection between the terminal and the base station system, the RNL BSS layer can decide how the network-requested authentication and encryption mode setting can be performed. The alternatives include:
- the new RAND number is stored for future use, although the encryption mode setting is ignored,
- the encryption key is changed on the signaling radio bearer,
- the encryption key is changed on all active bearers.
In the solution of the invention, the base station controller can have information about the encryption keys used. This situation must be taken into account when the terminal performs a handover, switching to a base station that is controlled by a different base station controller than the old base station. The necessary information is transferred in the invention from the old base station controller to the new base station controller in connection with the handover.
The solution of the invention is implemented in the radio communication system preferably by means of software, whereby the invention requires certain functions of the protocol processing software located in the control unit 122 of the base station controller 106, and of the protocols located in the processor 316 of the transceiver of the subscriber terminal 102. Part of the solution can be partially implemented with hardware (for example, using ASICs, discrete components, or via DSP) to meet time requirements, in the event that data from multiple parallel carriers needs to be encrypted simultaneously so that they are can multiplex into a radio frame. This situation mainly refers to the encryption unit presented in Fig. 9.
Although the invention has been described above with reference to the example illustrated in the accompanying drawings, it should be understood that said invention is not limited thereto, but can be varied in many ways within the scope of the inventive idea disclosed in the appended claims.
Contents5
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
24 members in 13 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 19980000209 | Finland | – | |
| 980209 | Finland | A | |
| 980209 | Finland | A | |
| 99900905980209 | – | – | – |
| FI19980000209 | – | – | – |
Members24
| Document | Office | Kind | |
|---|---|---|---|
| FI980209A | Finland | A | |
| WO9939525A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2057099A | Australia | A | |
| BR9907196A | Brazil | A | |
| EP1064799A1 | European Patent Office (EPO) | A1 | |
| CN1289512A | China | A | |
| KR20010034458A | Republic of Korea | A | |
| JP2002502205A | Japan | A | |
| AU750597B2 | Australia | B2 | |
| US6535979B1 | United States of America | B1 | |
| FI111433B | Finland | B | |
| KR100431638B1 | Republic of Korea | B1 | |
| EP1064799B1 | European Patent Office (EPO) | B1 | |
| AT336865T | Austria | T | |
| ATE336865T1 | Austria | T1 | |
| DE69932814D1 | Germany | D1 | |
| JP2006271010A | Japan | A | |
| DE69932814T2 | Germany | T2 | |
| ES2272046T3This record | Spain | T3 | |
| DE69932814T8 | Germany | T8 | |
| CN101692731A | China | A | |
| JP4555261B2 | Japan | B2 | |
| HK1143018A1 | Hong Kong, China | A1 | |
| CN101692731B | China | B |
Numbers
- Publication
- 2272046
- Publication, DOCDB
- 2272046
- Publication, EPODOC
- ES2272046T
- Application
- 99900905
- Application, DOCDB
- 99900905
- Application, EPODOC
- ES19990900905T
Titles2
- English
- METHOD OF ENCRYPTION OF A DATA TRANSMISSION AND RADIOCOMMUNICATION CELL SYSTEMS USING THIS METHOD.
- Spanish
- METODO DE CIFRADO DE UNA TRANSMISION DE DATOS Y SISTEMAS CELULAR DE RADIOCOMUNICACIONES QUE UTILIZA DICHO METODO.
Classification
- CPC, 3
- H04W12/02
- H04K1/00
- H04W12/037
- IPC, 2
- H04L9 14
- H04W12 00