Nova Patents
IL197829A

Encryption in wireless telecommunications

Abstract

This record has no abstract on file.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

2 claims: 2 independent, 0 dependent

  1. 1
    197829/2 - 1 - ENCRYPTION IN A WIRELESS TELECOMMUNICATIONS Field of the Invention The present invention relates to telecommunications, in particular to wireless telecommunications. Description of the Related Art 5 In known Universal Mobile Telecommunications System (UMTS) systems, some messages are encrypted. Encryption is initiated by a security mode command being sent from the core network via the UMTS terrestrial radio access network (UTRAN) to be received by the mobile terminal. This is followed by a security mode response being sent from the mobile terminal and received by the core network. 10 For example, as shown in Figure 1, upon receiving a session, or bearer, establishment request 1, the core network (CN) 2 sends a security mode command 4 to the UTRAN 6. This causes the UTRAN 6 to forward the security mode command 4 to the mobile terminal (User Equipment, UE 8). The mobile terminal 8 reacts by initialising its encryption algorithms using specific parameter values, sometimes 15 referred to as a security context, and then acknowledges by sending a security mode response 10 to the UTRAN 6 which passes the response 10 on to the core network 2. Thereafter an encrypted Non Access Stratum (NAS) message, such as a session establishment response 12 is sent from the core network 2 to the mobile terminal 8 via the UTRAN 6. 20 In this known approach, the security mode messages are unencrypted since they provide the encryption information needed to encrypt the messages that follow. Another area of background is Long Term Evolution, LTE, networks. From UMTS networks, so-called Long Term Evolution, LTE, networks are now being developed. For background on Long Term Evolution networks, the reader is referred to 25 Third Generation Partnership Project Technical Specification 3GPP TS23.882. References considered to be relevant as background to the presently disclosed subject matter are listed below:WO0245453 discloses a fraudulent intruder can eavesdrop on a call by removing information about an encryption algorithm when a multimode mobile station sends an 30 unprotected initial signaling message containing this information over the radio 01919349\115-01 197829/2 - 2 - interface to the mobile telecommunications system. The attempt can be prevented in a universal mobile telecommunications system (UMTS) comprising at least two radio access networks providing mobile stations with access to at least one core network, a multimode mobile station, and at least one core network. During connection setup with 5 a first radio access network, the multimode mobile station sends an unprotected initial signaling message that includes information about those encryption algorithms that the multimode mobile station supports when it communicates in a second radio access network. The first radio access network saves some or all the information of it. Then it composes and sends an integrity-protected message that includes information about the 10 encryption algorithms supported by the multimode mobile station in the second radio access network. WO03047154 protects the security of a communication between a mobile radio and a radio access network (RAN). A connection is established through the RAN to support a communication with the mobile radio. The connection is configured with a 15 first security configuration. One or more messages are sent over the connection using the first security connection, each message having a message sequence number. When the connection needs to be configured to a second security configuration, an activation message sequence number associated with the reconfiguration is set. When the reconfiguration process is complete and the second security configuration is to be 20 activated, the next message is sent over the connection with the activation message sequence number. Until that time and during the reconfiguration, when the mobile radio transmits a message with a message sequence number lower than the activation message sequence number to the RAN, it uses the first security configuration. An example of such a message is a cell update message or an area update message. 25 Acknowledgement of the above references herein is not to be inferred as meaning that these are in any way relevant to the patentability of the presently disclosed subject matter. Summary of the Invention The reader is referred to the appended independent claims. Some preferred 30 features are laid out in the dependent claims. An example of the present invention is a method of transmitting encrypted user data to a mobile terminal in a wireless telecommunications network. The method 01919349\115-01 197829/2 - 3 - comprises sending to the mobile terminal a data packet. The data packet comprises both an identifier of encryption information to be used in recovering encrypted user data, and user data encrypted using said encryption information. The inventors realised that in the known approach security mode command and response signalling causes delay in session establishment procedures. For example, when the mobile terminal moves to the coverage area of another base station, there can be a change in the encryption key used. This requires security mode command and response signalling so as to inform the mobile terminal of the new key before data encrypted using the new key is sent. This additional signalling can give rise to additional delay. Such a delay may be irksome to the subscriber, and can cause problems with applications that are call setup delay sensitive, such as Push-to-talk. In some embodiments of the invention such delays may be reduced. Brief Description of the Drawings Embodiments of the present invention will now be described by way of example and with reference to the drawings, in which: Figure 1 is a diagram illustrating the known approach to instigating encryption as part of session establishment (PRIOR ART), Figure 2 is a diagram illustrating a Long Term Evolution, LTE, network according to a first embodiment of the present invention, Figure 3 is a diagram illustrating an approach to instigating encryption as part of session establishment in the network shown in Figure 2, Figure 4 is a diagram illustrating the structure of a NAS message sent in session establishment, Figure 5 is a diagram illustrating how NAS signalling messages are encrypted, Figure 6 is a diagram illustrating handover between core network CN nodes in the LTE network, Figure 7 is a diagram illustrating instigating encryption as part of Radio resource control, RRC, connection establishment in the LTE network, Figure 8 is a diagram illustrating a Universal Mobile Telecommunications System (UMTS) network according to a second embodiment of the present invention, and 01919349\115-01 197829/2 - 4 - Figure 9 is a diagram illustrating an approach to instigating encryption as part of session establishment in the network shown in Figure 8. Detailed Description An example LTE network will first be described, followed by explanations of how encryption is initiated in session establishment using a combined message. This is followed by an explanation of how encryption is handled upon handover of a mobile terminal from connection with one core network node to another. An alternative combined message is then described. An alternative network is then described, that being a UMTS network, followed by an explanation of how encryption is initiated in that network. Long Term Evolution Network The LTE network 14, which is based on a Universal Mobile Telecommunications System (UMTS) network, is basically as shown in Figure 2. The core network includes Mobile Management Entities (MME). Each MME 16 includes a NAS message encryption stage 26. In Figure 2, only one Mobile Management Entity (MME) 16 of the core network 18 and one base station 20 of the LTE network 14 are shown for simplicity. The LTE network includes multiple base stations. In the Figure, the base station is also designated “eNode B” in accordance with LTE terminology. A cell, also referred to as a sector, is the radio-coverage area served by a corresponding antenna of a base station. Each base station 20 typically has three cells 22, each covered by one of three directional antennas 24 angled at 120 degrees to each other in azimuth. In use, a mobile user terminal 28 (often referred to as User Equipment (UE) in LTE/UMTS terminology) communicates with a mobile management entity 16 via at least one cell 22 of at least one base station 20. In that way, the mobile user terminal communicates with the UTRAN network 2. Instigating encryption in session establishment The inventors realised that it is possible to combine the Security mode command and Non Access Stratum (NAS) message (such as a session establishment response) into a single combined message. The first part of the message is the security mode command and this part is unencrypted. The second part of the message is a NAS message and this part is encrypted. 01919349\115-01 197829/2 - 5 - As shown in Figure 3, upon receiving a session establishment request 30, the mobile management entity 16 sends the combined message 32 consisting of the unencrypted security mode command and encrypted NAS signalling message to the base station 20. This causes the base station 20 to forward the combined message 32 to 5 the mobile terminal (User Equipment, UE 28). The mobile terminal 28 effects initialisation of its security context and then acknowledges by sending a security mode response 34 to the base station 20 from where the response 34 is forwarded on to the mobile management entity 16. Thereafter an encrypted Non Access Stratum (NAS) message, such as a session establishment response 36 is sent from the MME 16 to the 10 mobile terminal 28 via the base station 20. The combined message 32 referred to above is as shown in Figure 4, and consists of an unencrypted security command 38 and an encrypted NAS message 40. The security command 38 consists of information elements defining security context information such as an identifier of the encryption key to be used, and for example, an 15 identifier of start time for the encryption. The NAS message 40 consists of information elements constituting a Session Establishment response. Production of the combined message In the LTE network 14 encryption of NAS messages is performed by encryption stages 26 in the respective nodes of the core network 18. Encryption of NAS messages 20 is independent of encryption of user data. As shown in Figure 5, the NAS message for encryption together with information to effect the encryption such as encryption keys are input to the encryption stage 26 from which the encrypted NAS message 40 is provided. The encrypted NAS message 40 is concatenated with unencrypted header information 38. This is possible 25 because the MME 16 generally allows encryption of at least part of an NAS message before concatenation with another unencrypted message portion. Handling encryption upon handover Handover is the process of transferring the mobile terminal 28 from connection with one base station 20 and hence core network node 18 to another base station (not 30 shown) and hence another core network node (not shown). Handover is sometimes known as handoff. An example of handover procedure is shown in Figure 6. Initially the connection is to the base station 20 and involves using a first encryption key. The core 01919349\115-01 197829/2 - 6 - network node 18 sends a handover command 42 via the base station 20 to the mobile terminal 28, after which handover 44 of the call connection to a further base station 20' and hence core network node 20' is effected. A “handover complete” message 46 is then sent from the mobile terminal 28 to the new base station 18' and hence core 5 network node 18'. Thereafter the core network node sends a combined message 48, consisting of an unencrypted security mode command 50 including encryption key identifiers as previously discussed, followed by an encrypted portion 52 of user data such as NAS signalling messages. So, for example, when the core network node doing encryption changes, the first combined message 50 from the new core network node 18' 10 indicates in the security mode command the new security parameter values to be used, and includes in encrypted form, new NAS signalling messages. In an otherwise similar embodiment, if encryption and encryption configuration is instead done in the user plane, the combined packet in the user plane consists of the unencrypted security mode command concatenated with user data. 15 Of course, in some embodiments, switching to a new encryption key, by sending a combined message consisting of an unencrypted security mode command including encryption key identifiers followed by an encrypted portion of user data encrypted using that encryption key, can be done at other times than handover between cells. For example, in another embodiment, the old cell and new cell can be the same cell. 20 In this example, initially the cell communicates with the mobile terminal using the old encryption parameters. Part-way through the session the cell sends a packet containing the new encryption parameters and additional user data. The mobile terminal receives the new encryption parameters. The mobile terminal uses the new encryption parameters to decrypt the encrypted part of the packet. The mobile terminal also stores 25 the new encryption parameters for subsequent use in decryption of subsequent packets that are encrypted using the new encryption parameters. Radio Resource Control As shown in Figure 7, a combined message can similarly be sent consisting of an unencrypted security mode command and an encrypted user data portion, where the 30 user data portion consists of a Radio Resource Control (RRC) message. As shown in Figure 7, a RRC Connection Request 54 is sent to a base station 20” and the combined message 56, which more specifically comprises the unencrypted Security Mode command followed by the encrypted (with the new key) RRC Connection Response, is 01919349\115-01 197829/2 - 7 - sent by the base station to the mobile terminal 28' in reply. A security mode response is then sent from the user terminal 28'. Another example system: UMTS The network is a Universal Mobile Telecommunications System (UMTS) 5 terrestrial access network (UTRAN), which is a type of wideband code division multiple access (CDMA) network for mobile telecommunications. The UTRAN network is basically as shown in Figure 8. Only one radio network controller and two base stations of the UTRAN network 62 are shown for simplicity. As shown in this Figure, the UTRAN network 62 includes base stations 64. In the Figure, each of the 10 base stations 64 is also designated “Node B” in accordance with UMTS terminology. A cell, also referred to as a sector, is the radio-coverage area served by a corresponding antenna of a base station. Each base station typically has three cells 66, each covered by one of three directional antennas 67 angled at 120 degrees to each other in azimuth. Each radio network controller (RNC) 68 typically controls several base stations 64 and 15 hence a number of cells 66. A base station 64 is connected to its controlling radio network controller (RNC) 68 via a respective interface 69 known as an IuB interface. In use, a mobile user terminal 70 (often referred to as User Equipment (UE) in UMTS terminology) communicates with a serving radio network controller (RCN) 68 via at least one cell 66 of at least one base station 64. In that way, the mobile user terminal 20 communicates with the UTRAN network 62. The RNC is connected to a Serving Gateway Support Node, SGSN, 72 of the core network 74. The SGSN 72 includes a NAS message encryption stage 76 as described in more detail below. Instigating encryption in session establishment: UMTS Example 25 The inventors realised that it is possible to combine the Security mode command and Non Access Stratum (NAS) message (such as a session establishment response) into a single combined message. The first part of the message is the security mode command and this part is unencrypted. The second part of the message is a NAS message and this part is encrypted. 30 As shown in Figure 9, upon receiving a session establishment request 78, the SGSN 72 sends the combined message 80 consisting of the unencrypted security mode command and encrypted NAS signalling message to the RNC 68 and hence base station 01919349\115-01 197829/2 - 8 -
  2. 2
    64. This causes the base station 64 to forward the combined message 80 to the mobile terminal (User Equipment, UE 70). The combined message 80 consists of an unencrypted security command and an encrypted NAS message. The security commend consists of information elements 5 defining security context information such as an identifier of the encryption key to be used, and for example, an identifier of start time for the encryption. The encrypted NAS message portion of message 80 consists of information elements constituting a Session Establishment response. The mobile terminal 70 effects initialisation of its security context and then 10 acknowledges by sending a security mode response 82 to the base station 64 and hence RNC 68 from where the response 82 is forwarded on to the SGSN 72. General The present invention may be embodied in other specific forms without departing from its essential characteristics. The described embodiments are to be 15 considered in all respects only as illustrative and not restrictive. The scope of the invention is, therefore, indicated by the appended claims rather than by the foregoing description. All changes that come within the meaning and range of equivalency of the claims are to be embraced within their scope. Some Abbreviations 20 CN:Core Network UMTS: Universal Mobile Telecommunications System UE: User equipment NAS: Non Access Stratum (also known as the Core network protocol) MME: Mobility Management Entity 25 LTE: Long Term Evolution, a term used in 3GPP for system that is being standardised after UMTS IE: Information Element RRC: Radio Resource Control (The Radio part of the control protocol otherwise called Access Stratum part of the control protocol) 30 SGSN: Signalling Gateway Support Node. 01919349\115-01