Method of ciphering data transmission in a radio system
Abstract
(57) [Summary] The present invention relates to a method of encrypting data transmission in a wireless system, a user apparatus using the method, and a wireless network subsystem using the method. The method includes (602) a step of generating an encryption key, (604A) a step of generating an encryption mask in the encryption algorithm using the encryption key as an input parameter, and (604B) the step of generating the encryption algorithm. It includes a step of using a logical channel identification parameter or a transfer channel identification parameter as an additional input parameter of (606) and a step of generating encrypted data by applying the encryption mask to plain data.
Term
Term ended
Projected expiry passed 8 March 2020, 6.5 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
1 claim: 1 independent, 0 dependent
- 1【特許請求の範囲】 【請求項1】 無線システムのデータ伝送を暗号化する方法であって、 (602)暗号化キーを生成するステップと、 (604A)前記暗号化キーを入力パラメータとして用いて暗号化アルゴリズムに暗号化マスクを生成するステップと、 (606)前記暗号化マスクをプレーンデータに適用することによって暗号化データを生成するステップと、 を含む方法において、 (604B)論理チャネル特定パラメータまたは転送チャネル特定パラメータを前記暗号化アルゴリズムへの付加入力パラメータとして用いることを特徴とする、無線システムのデータ伝送を暗号化する方法。 【請求項2】 前記暗号化アルゴリズムへの付加入力パラメータとして伝送方向を用いることを特徴とする請求項1に記載の方法。 【請求項3】 前記論理チャネル特定パラメータが、無線アクセスベアラ識別子、論理チャネル識別子、信号リンク識別子の1つであることを特徴とする請求項1に記載の方法。 【請求項4】 前記転送チャネル特定パラメータが専用チャネル識別子であることを特徴とする請求項1に記載の方法。 【請求項5】 前記暗号化アルゴリズムへの付加入力パラメータとして無線フレーム特定パラメータを用いることを特徴とする請求項1に記載の方法。 【請求項6】 前記無線フレーム特定パラメータがユーザ装置フレーム番号であることを特徴とする請求項5に記載の方法。 【請求項7】 前記プレーンデータが、少なくとも2つの並列論理チャネルからの無線リンク制御レイヤプロトコルデータユニットを含み、また各論理チャネルのために個々の暗号化マスクが生成されることを特徴とする請求項1に記載の方法。 【請求項8】 少なくとも1つの論理チャネルの無線リンク制御レイヤプロトコルデータユニットがすでに暗号化され、また暗号化データを生成する前記ステップが、前記すでに暗号化された無線リンク制御レイヤプロトコルデータユニットのために繰り返されないことを特徴とする請求項7に記載の方法。 【請求項9】 前記プレーンデータが、1つの論理チャネルからの1つの無線リンク制御レイヤプロトコルデータユニットを含み、また前記論理チャネルのために個々の暗号化マスクが生成されることを特徴とする請求項1に記載の方法。 【請求項10】 前記プレーンデータが、1つの論理チャネルの少なくとも2つの連続した無線リンク制御レイヤプロトコルデータユニットを含み、また各無線リンク制御レイヤプロトコルデータユニットのために前記暗号化マスクの異なる部分が、前記暗号化データの生成に用いられることを特徴とする請求項1に記載の方法。 【請求項11】 前記プレーンデータが、少なくとも2つの異なる論理チャネルのメディアアクセス制御レイヤプロトコルデータユニットを含む1つの転送ブロックセットを含み、また各転送ブロックセットのために1つの暗号化マスクが、前記暗号化データの生成に用いられることを特徴とする請求項1に記載の方法。 【請求項12】 前記プレーンデータが、1つの論理チャネルのメディアアクセス制御レイヤプロトコルデータユニットを含む1つの転送ブロックセットを含み、また各転送ブロックセットのために1つの暗号化マスクが、前記暗号化データの生成に用いられることを特徴とする請求項1に記載の方法。 【請求項13】 前記暗号化が、プロトコルスタックのメディアアクセス制御レイヤで実施されることを特徴とする請求項1に記載の方法。 【請求項14】 新しい暗号化マスクが、前記プロトコルスタックの物理レイヤの各無線フレームのために生成されることを特徴とする請求項1に記載の方法。 【請求項15】 新しい暗号化マスクが、前記プロトコルスタックの物理レイヤの各インタリーブ期間のために生成されることを特徴とする請求項1に記載の方法。 【請求項16】 暗号化キー(410)を生成するための生成手段(408)と、 暗号化キー(410)を入力パラメータとして用いて暗号化マスク(412A、412B、412C)を生成するための生成手段(408)と接続された暗号化アルゴリズム(400)と、 暗号化マスク(412A、412B、412C)をプレーンデータ(414A、414B、414C)に適用することによって暗号化データ(418A、418B、418C)を生成するための暗号化アルゴリズム(400)と接続された暗号化手段(416A、416B、416C)と、 を具備するユーザ装置(UE)において、 前記暗号化アルゴリズム(400)が、論理チャネル特定パラメータ(402A)または転送チャネル特定パラメータ(402B)を付加入力パラメータとして用いることを特徴とするユーザ装置。 【請求項17】 前記暗号化アルゴリズム(400)が、付加入力パラメータとして伝送方向を用いることを特徴とする請求項16に記載のユーザ装置。 【請求項18】 前記論理チャネル特定パラメータ(402A)が、無線アクセスベアラ識別子、論理チャネル識別子、信号リンク識別子の1つであることを特徴とする請求項16に記載のユーザ装置。 【請求項19】 前記転送チャネル特定パラメータ(402B)が専用チャネル識別子であることを特徴とする請求項16に記載のユーザ装置。 【請求項20】 前記暗号化アルゴリズム(400)が、無線フレーム特定パラメータ(404)を付加入力パラメータとして用いることを特徴とする請求項16に記載のユーザ装置。 【請求項21】 前記無線フレーム特定パラメータ(404)がユーザ装置フレーム番号であることを特徴とする請求項20に記載のユーザ装置。 【請求項22】 前記暗号化手段(416A、416B、416C)が、少なくとも2つの並列論理チャネルからの無線リンク制御レイヤプロトコルデータユニットを含むプレーンデータ(414A、414B、414C)を受け入れ、また暗号化アルゴリズム(400)が、各論理チャネルのために個々の暗号化マスク(412A、412B、412C)を生成し、暗号化手段(416A、416B、416C)が、各論理チャネルのために前記チャネルの暗号化マスク(412A、412B、412C)を用いることを特徴とする請求項16に記載のユーザ装置。 【請求項23】 少なくとも1つの論理チャネルの無線リンク制御レイヤプロトコルデータユニット(414C)がすでに暗号化され、また暗号化手段(416C)が、前記すでに暗号化された無線リンク制御レイヤプロトコルデータユニット(414C)を暗号化しないことを特徴とする請求項22に記載のユーザ装置。 【請求項24】 前記暗号化手段(416A)が、1つの論理チャネルからの無線リンク制御レイヤプロトコルデータユニットを含むプレーンデータ(414A)を受け入れ、また暗号化アルゴリズム(400)が、前記論理チャネルのために個々の暗号化マスク(412A)を生成し、暗号化手段(416A)が、前記論理チャネルのために前記チャネルの暗号化マスク(412A)を用いることを特徴とする請求項16に記載のユーザ装置。 【請求項25】 前記暗号化手段(426)が、1つの論理チャネルの少なくとも2つの連続した無線リンク制御レイヤプロトコルデータユニットを含むプレーンデータを受け入れ、また暗号化アルゴリズム(400)が、前記論理チャネルのために個々の暗号化マスク(412A)を生成し、暗号化手段(426)が、各無線リンク制御レイヤプロトコルデータユニットのために暗号化マスク(412A)の異なる部分を用いることを特徴とする請求項16に記載のユーザ装置。 【請求項26】 前記暗号化手段(434)が、少なくとも2つの異なる論理チャネルのメディアアクセス制御レイヤプロトコルデータユニットを含む1つの転送ブロックセットを含むプレーンデータを受け入れ、また暗号化アルゴリズム(400)が、各転送ブロックセットのために個々の暗号化マスク(412)を生成し、暗号化手段(434)が、各転送ブロックセットのために1つの暗号化マスク(412)を用いることを特徴とする請求項16に記載のユーザ装置。 【請求項27】 前記暗号化手段(434)が、1つの論理チャネルのメディアアクセス制御レイヤプロトコルデータユニットを含む1つの転送ブロックセットを含むプレーンデータ受け入れ、また暗号化アルゴリズム(400)が、各転送ブロックセットのために個々の暗号化マスク(412)を生成し、暗号化手段(434)が、各転送ブロックセットのために1つの暗号化マスク(412)を用いることを特徴とする請求項16に記載のユーザ装置。 【請求項28】 前記生成手段(408)、暗号化アルゴリズム(400)および暗号化手段(416A、416B、416C)が、プロトコルスタックのメディアアクセス制御レイヤに存在することを特徴とする請求項16に記載のユーザ装置。 【請求項29】 前記暗号化アルゴリズム(400)が、前記プロトコルスタックの物理レイヤの各無線フレームのための新しい暗号化マスク(412A、412B、412C)を生成することを特徴とする請求項16に記載のユーザ装置。 【請求項30】 前記暗号化アルゴリズム(400)が、前記プロトコルスタックの物理レイヤの各インタリーブ期間のための新しい暗号化マスク(412A、412B、412C)を生成することを特徴とする請求項16に記載のユーザ装置。 【請求項31】 暗号化キー(410)を生成するための生成手段(408)と、 暗号化キー(410)を入力パラメータとして用いて暗号化マスク(412A、412B、412C)を生成するための生成手段(408)と接続された暗号化アルゴリズム(400)と、 暗号化マスク(412A、412B、412C)をプレーンデータ(414A、414B、414C)に適用することによって暗号化データ(418A、418B、418C)を生成するための暗号化アルゴリズム(400)と接続された暗号化手段(416A、416B、416C)と、 を具備する無線ネットワークサブシステム(RNS)において、 前記暗号化アルゴリズム(400)が、論理チャネル特定パラメータ(402A)または転送チャネル特定パラメータ(402B)を付加入力パラメータとして用いることを特徴とする無線ネットワークサブシステム。 【請求項32】 前記暗号化アルゴリズム(400)が、伝送方向を付加入力パラメータとして用いることを特徴とする請求項31に記載の無線ネットワークサブシステム。 【請求項33】 前記論理チャネル特定パラメータ(402A)が、無線アクセスベアラ識別子、論理チャネル識別子、信号リンク識別子の1つであることを特徴とする請求項31に記載の無線ネットワークサブシステム。 【請求項34】 前記転送チャネル特定パラメータ(402B)が専用チャネル識別子であることを特徴とする請求項31に記載の無線ネットワークサブシステム。 【請求項35】 前記暗号化アルゴリズム(400)が、無線フレーム特定パラメータ(404)を付加入力パラメータとして用いることを特徴とする請求項31に記載の無線ネットワークサブシステム。 【請求項36】 前記無線フレーム特定パラメータ(404)がユーザ装置フレーム番号であることを特徴とする請求項35に記載の無線ネットワークサブシステム。 【請求項37】 前記暗号化手段(416A、416B、416C)が、少なくとも2つの並列論理チャネルからの無線リンク制御レイヤプロトコルデータユニットを含むプレーンデータ(414A、414B、414C)を受け入れ、また暗号化アルゴリズム(400)が、各論理チャネルのために個々の暗号化マスク(412A、412B、412C)を生成し、暗号化手段(416A、416B、416C)が、各論理チャネルのために前記チャネルの暗号化マスク(412A、412B、412C)を用いることを特徴とする請求項31に記載の無線ネットワークサブシステム。 【請求項38】 少なくとも1つの論理チャネルの無線リンク制御レイヤプロトコルデータユニット(414C)がすでに暗号化され、また暗号化手段(416C)が、前記すでに暗号化された無線リンク制御レイヤプロトコルデータユニット(414C)を暗号化しないことを特徴とする請求項37に記載の無線ネットワークサブシステム。 【請求項39】 前記暗号化手段(416A)が、1つの論理チャネルからの無線リンク制御レイヤプロトコルデータユニットを含むプレーンデータ(414A)を受け入れ、また暗号化アルゴリズム(400)が、前記論理チャネルのために個々の暗号化マスク(412A)を生成し、暗号化手段(416A)が、前記論理チャネルのために前記チャネルの暗号化マスク(412A)を用いることを特徴とする請求項31に記載の無線ネットワークサブシステム。 【請求項40】 前記暗号化手段(426)が、1つの論理チャネルの少なくとも2つの連続した無線リンク制御レイヤプロトコルデータユニットを含むプレーンデータを受け入れ、また暗号化アルゴリズム(400)が、前記論理チャネルのために個々の暗号化マスク(412A)を生成し、暗号化手段(426)が、各無線リンク制御レイヤプロトコルデータユニットのために暗号化マスク(412A)の異なる部分を用いることを特徴とする請求項31に記載の無線ネットワークサブシステム。 【請求項41】 前記暗号化手段(434)が、少なくとも2つの異なる論理チャネルのメディアアクセス制御レイヤプロトコルデータユニットを含む1つの転送ブロックセットを含むプレーンデータを受け入れ、また暗号化アルゴリズム(400)が、各転送ブロックセットのために個々の暗号化マスク(412)を生成し、暗号化手段(434)が、各転送ブロックセットのために1つの暗号化マスク(412)を用いることを特徴とする請求項31に記載の無線ネットワークサブシステム。 【請求項42】 前記暗号化手段(434)が、1つの論理チャネルのメディアアクセス制御レイヤプロトコルデータユニットを含む1つの転送ブロックセットを含むプレーンデータを受け入れ、また暗号化アルゴリズム(400)が、各転送ブロックセットのために個々の暗号化マスク(412)を生成し、暗号化手段(434)が、各転送ブロックセットのために1つの暗号化マスク(412)を用いることを特徴とする請求項31に記載の無線ネットワークサブシステム。 【請求項43】 前記生成手段(408)、暗号化アルゴリズム(400)および暗号化手段(416A、416B、416C)が、プロトコルスタックのメディアアクセス制御レイヤに存在することを特徴とする請求項31に記載の無線ネットワークサブシステム。 【請求項44】 前記暗号化アルゴリズム(400)が、前記プロトコルスタックの物理レイヤの各無線フレームのための新しい暗号化マスク(412A、412B、412C)を生成することを特徴とする請求項31に記載の無線ネットワークサブシステム。 【請求項45】 前記暗号化アルゴリズム(400)が、前記プロトコルスタックの物理レイヤの各インタリーブ期間のための新しい暗号化マスク(412A、412B、412C)を生成することを特徴とする請求項31に記載の無線ネットワークサブシステム。
98 paragraphs, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
Field of invention The present invention relates to a method of encrypting data transmission in a wireless system. [0002]
Background of the invention Today, encryption is used in many data transmission systems to prevent the data being transmitted from being available to unqualified users. Cryptography has made considerable progress in the last few years, especially as wireless communications have become more commonplace. [0003]
Encryption can be performed, for example, by encrypting the information transmitted by the transmitter and by deciphering the information in the receiver. In cryptographic means, the information transmitted, eg, a bitstream, is multiplied by a certain number of cryptographic bit patterns, in which case what was the original bitstream if the cryptographic bit pattern used was unknown. Is difficult to find. [0004]
For example, in a digital GSM system, encryption is performed on the radio path, that is, the encryption bitstream to be transmitted on the radio path is formed by taking an XOR of the data bit and the encryption bit, and the encryption bit is , Formed by an algorithm known per se (A5 algorithm) using the encryption key Kc. The A5 algorithm encrypts the information transmitted on the traffic channel and the DCCH control channel. [0005]
The encryption key Kc is set when the network authenticates the terminal but the traffic on the channel is not yet encrypted. In the GSM system, terminals are identified based on TMSI, a temporary mobile subscriber identity formed on the basis of the international mobile subscriber identity, IMSI, or subscriber identifier stored in the terminal. The subscriber identification key Ki is also stored in the terminal. The terminal identification key is also recognized by the system. [0006]
The information in the encryption key Kc must be kept confidential so that the encryption is reliable. Therefore, the encryption key is indirectly transmitted from the network to the terminal. A random access number, RAND, is formed in the network and then the number is transmitted to the terminal via the base station system. The encryption key Kc is formed by a known algorithm (A5 algorithm) from a random access number, RAND, and a subscriber identification key Ki. The encryption key Kc is calculated in the same way on both the terminal and the network portion of the system. [0007]
Therefore, initially, the data transmission in the connection between the terminal and the base station is not encrypted. Encryption does not begin until the base station system sends an encryption mode command to the terminal. When the terminal receives the instruction, the terminal encrypts the data to be transmitted and begins decrypting the received data. Therefore, the base station system initiates decryption of the received data after transmitting the encryption mode instruction, and also encrypts the transmitted data after receiving the first encrypted message from the terminal and correctly decrypting it. Start to convert. In GSM systems, encryption mode instructions include an encryption start instruction and information about the algorithm used. [0008]
The problem with known methods is that they are designed for current systems, so they are capable of multiple parallel services for one mobile station. Encryption of data transmission in new systems. It is inflexible and unsuitable for. If the same cryptographic mask is used for two or more parallel protocol data units transmitted using the same air interface frame, an eavesdropper can extract a lot of information from the data stream. The amount of information that can be retrieved depends on the structure of the data stream. Humans cannot obtain information from random data that has no structure, but usually there is a structure in the data, especially in the signal data. [0009]
Abstract of the invention An object of the present invention is to provide a method for solving the above problems, and a user device and a wireless network subsystem that implement the method. The above objectives are to generate an encryption key, to generate an encryption mask in an encryption algorithm using the encryption key as an input parameter, and to apply the encryption mask to plain data to encrypt data. Is achieved by using a logical channel specific parameter or a transfer channel specific parameter as an additional input parameter to the encryption algorithm in a method of encrypting data transmission of a wireless system, including the step of generating the above. [0010]
The present invention also uses a plain encryption mask and an encryption algorithm connected to a generation means for generating an encryption key and a generation means for generating an encryption mask using the encryption key as an input parameter. The present invention relates to a user apparatus including an encryption algorithm for generating encrypted data by applying to the data and an encryption means connected to the data. The encryption algorithm uses a logical channel specific parameter or a transfer channel specific parameter as additional input parameters. [0011]
Further, the present invention provides an encryption algorithm connected to a generation means for generating an encryption key, a generation means for generating an encryption mask using the encryption key as an input parameter, and an encryption mask. It relates to a wireless network subsystem comprising an encryption algorithm for generating encrypted data by applying it to plain data and connected encryption means. The encryption algorithm uses a logical channel specific parameter or a transfer channel specific parameter as additional input parameters. [0012]
A preferred embodiment of the present invention is set forth in the dependent claims. [0013]
A plurality of advantages are achieved by the present invention. In the solution of the present invention, encryption and its characteristics can be flexibly controlled. The present invention enhances user security in new wireless systems. This solution is also superior to known techniques that use a sufficiently long encryption mask only once per air interface frame, as it allows for a decentralized implementation of the required functionality of the protocol stack. .. [0014]
Detailed description of the invention The present invention can be used in various mobile telephone systems. In the following examples, the use of the present invention describes a general purpose mobile phone system without limiting the invention to the general purpose mobile phone system (UMTS). This embodiment shows the FDD (frequency division double) operation of UMTS, but the present invention is not limited thereto. [0015]
A typical mobile telephone system configuration will be described with reference to FIGS. 1A and 1B. FIG. 1B comprises only the essential blocks for the purposes of the present invention, but it is clear to those skilled in the art that general mobile telephone systems also have other functions and configurations, which are described in more detail here. There is no need to explain to. The main parts of the mobile phone system are the core network CN, the earth radio access network UTRAN and the user equipment UE. The interface between CN and UTRAN is called the lu interface, and the interface between UTRAN and UE is called the Uu interface. [0016]
UTRAN consists of the wireless network subsystem RNS. The interface between the two RNSs is called the lur interface. The RNS consists of a wireless network controller RNC and one or more nodes BsB. The interface between the RNC and node B is called the lub interface, and the receiving area of node B, the cell, is shown in Figure 1A at C. [0017]
The display in Figure 1A is so abstract that it is clearly shown in Figure 1B by describing the part of the GSM system that corresponds to the part of the UMTS. Since the mission and function of the UMTS part is still under planning, it is clear that the mapping presented is by no means binding, but speculative. [0018]
FIG. 1B shows packet-switched transmission from the computer 100 connected to the mobile telephone system to the portable computer 122 connected to the user equipment UE via the Internet 102. The user equipment UE can be, for example, a fixed wireless local loop terminal, a vehicle equipped terminal or a handheld portable terminal. [0019]
The infrastructure of the wireless network UTRAN consists of the wireless network subsystem RNS, or base station subsystem. The wireless network subsystem RNS is composed of a wireless network controller RNC, that is, a base station controller, and at least one node B, that is, a base station under RNC control. [0020]
Node B includes a multiplexer 114, a transceiver 116, and a control unit 118 that controls the operation of the transceiver 116 and the multiplexer 114. The multiplexer 114 arranges the traffic and control channels used by the plurality of transceivers 116 in a single transmission connection lub. [0021] [0021]
Node B transceiver 116 has a connection with an antenna unit 120 used to provide a bidirectional (or sometimes unidirectional) wireless connection Uu to the user equipment UE. The structure of the frame transmitted to the wireless connection Uu is determined in detail and the connection is called the air interface. [0022]
The wireless network controller RNC includes a group relay exchange field 110 and a control unit 112. The group relay exchange field 110 is used to switch between speech and data and to connect signal circuits. Node B and the wireless network controller RNC form a base station subsystem, which further comprises a speech codec, or transcoder, also known as TRAU (Transcoder / Rate Adapter Unit) 108. [0023]
The division of functions and physical structures of the wireless network controller RNC and node B can vary according to the actual implementation of the wireless network subsystem. Typically, node B makes a wireless connection. The wireless network controller RNC typically manages wireless resource management, cell-to-cell handover control, power control, timing and synchronization, and paging for the user equipment. [0024]
The transcoder 108 is usually placed as close as possible to the mobile exchange 106, because it transmits speech between the transcoder 108 and the wireless network controller RNC in the form of a cellular wireless network. This is because it enables and saves the transmission capacity. [0025]
The transcoder 108 converts the different digital speech coding modes used between the public switched telephone network and the cellular wireless network, eg, from a fixed network form of 64 kbit / s to other forms of the cellular wireless network (13 kbit). It provides compatibility between the public switched telephone network and the cellular radio network between (such as / s) and vice versa. Of course, transcoding is done for speech only. Control unit 112 performs call control, mobility management, statistical data collection and signaling. [0026]
The core network CN consists of infrastructure that belongs to the mobile telephone system that is not part of UTRAN. FIG. 1B shows the core network CN, a portion of the mobile exchange 106, and two devices that are the gateway mobile exchange 104 that handles the mobile telephone system interface towards the outside world, in this embodiment towards the Internet 102. .. [0027]
FIG. 5 shows an exemplary structure of the user equipment UE. The essential parts of the user equipment UE are the antenna 502 of the user equipment UE, the transceiver 506, the interface 504 with the control unit 510 of the user equipment UE, the interface 512 with the battery 514, and the display 500, the keyboard 508, the microphone 516, and the speaker. It is a user interface including 518. [0028]
Figure 2A shows the functionality of the wireless transmitter / wireless receiver pair. The radio transmitter may be located at node B or a user device. Therefore, the radio receiver may be located on the user device or node B. [0029]
The upper part of Figure 2A shows the essential functionality of the wireless transmitter. The different services placed on the physical channel are, for example, the control channel of the system processed by the control unit 214 of the speech, data, video or still image and radio transmitter. The control unit 214 is involved in the control of the device itself and the control of the connection. Figure 2A shows the operation of two different transfer channels 200A, 200B. Different services require different source coding devices, and speech requires, for example, a speech codec. However, for clarity, the source encoder is not shown in Figure 2A. [0030]
First, the logical channel is encrypted with blocks 216A, 216B. In encryption, the data to be encrypted is generated by applying an encryption mask to plain data. Next, the encrypted data is placed on the transfer channels of blocks 200A and 200B. Encryption can be performed on logical channels or on forwarding channels, as will be described later with reference to FIGS. 4A, 4C, and 7B. The different channels are then channel encoded in blocks 202A and 202B. One form of channel coding is a different block code, one example of which is patrol redundancy inspection, or CRC. Other typical methods of performing channel coding are convolutional coding and other forms such as punctured convolutional coding and turbocoding. [0031]
When channel-encoded, the channel is interleaved with interleavers 204A, 204B. The purpose of interleaving is to make error correction easier. In interleaving, the bits are mixed together in a predetermined way, so that temporary fading of the radio path does not necessarily make the transmitted information indistinguishable. [0032]
Different signals are multiplexed in block 208 so that different signals can be transmitted using the same transmitter. [0033]
The interleaved encryption bits are spread with a spreading code, scrambled with a scrambling code, and modulated at block 206, the operation of which is detailed in FIG. 2B. [0034]
Finally, the combined signal is carried to the radio frequency portion 210, which may include a power amplifier and a band limiting filter. Next, the analog radio signal is transmitted to the radio path Uu via the antenna 212. [0035]
The lower part of Figure 2A shows the typical functionality of a wireless receiver. Radio receivers are typically Rake receivers. The analog radio signal is received by antenna 234 from the radio path Uu. The received signal is carried to the radio frequency portion 232 with a filter that blocks frequencies outside the desired frequency band. The signal is then converted to intermediate frequency or direct baseband by demodulator 228, in which form the signal is sampled and quantized. [0036]
Since the signal is a multipath-propagated signal, efforts are made to combine the different multipath-propagated signal components of block 228 with multiple Rake fingers. [0037]
In so-called columnar lake fingers, delays for different multipath propagation signal components are searched for. After the delay is confirmed, different lake fingers receive each of the multipath propagation signals by correlating the received signal with the used spread code delayed by the confirmed delay for that particular multipath. Assigned to. The demodulated, non-spreading, identical signal multipaths are then combined to obtain a stronger signal. [0038]
The received physical channel is then demultiplexed by the demultiplexer 224 into a data stream on a different channel. Next, each of the channels is guided to the deinterleavers 226A and 226B, where the received physical channel is deinterleaved. The physical channel is then processed by specific channel decoders 222A, 222B, where the channel coding used for transmission is decoded. The convolutional code is preferably decoded by a Viterbi decoder. After this, the transfer channel is mapped to a logical channel at blocks 200A, 200B, or, otherwise, decoding is performed for the transfer channel. The channel decrypted channel (logical or transfer) is decrypted in blocks 220A, 220B by applying an encryption mask to the received data. Each received logical channel can be further processed, for example, by transferring data to a computer 122 connected to the user equipment UE. The control channel of the system is transported to the control unit 236 of the wireless receiver. [0039]
Figure 2B shows how the transfer channel is encoded and multiplexed. In principle, Figure 2B is partially the same as Figure 2A, but is shown from other perspectives. In blocks 240A and 240B, a cyclic redundancy check is added to each transfer block. Interleaving is performed in two stages on blocks 242A, 242B and 246. Service specific rate matching 244 is used when two or more services with different quality service requests are multiplexed within one or more physical channels. In rate matching, the channel symbol rate is adjusted to the optimum level, where the lowest quality of service requirements for each service is achieved by the same channel symbol energy. Mapping of the transfer channel to the physical channel is performed in block 248. [0040]
Since encryption is a key issue in the present invention, its principle will be described in more detail below. In Table 1, the first column represents the plain data bits that must be transmitted to the recipient. The bits in the second column make up the encryption mask. Cryptographic masks are usually applied to plain data by using the exclusive OR operation, i.e. XOR. The resulting encrypted data is in the third column. This encrypted data is sent to the recipient through the air interface. The recipient then performs the decryption by applying the same encryption mask used by the transmitter to the received data. The fourth column is the cryptographic mask that is summed with the third column by using the XOR operation. The restored data obtained is shown in the fifth column. As you can see, the restored data is the same as the plain data. [table 1]
<img file="JP2002539490A_D0001.tif" /> 【0041】
Figure 3 shows an example of a frame structure used in a physical channel. Frames 340A, 340B, 340C, 340D are given serial numbers from 1 to 72, which form a superframe with a length of 720 ms. The length of one frame 340C is 10 milliseconds. The frame 340C is divided into 16 slots 330A, 330B, 330C and 330D. The length of slot 330C is 0.625 ms. Slot 330C typically corresponds to one power control period in which the power is adjusted, for example, up or down by one decibel. [0042]
Physical channels are divided into different types, including common physical channels and dedicated physical channels. [0043]
Common physical channels are used to carry PCH, BCH, RACH and FACH transfer channels. [0044]
The dedicated physical channel is composed of a dedicated physical data channel (DPDCH) 310 and a dedicated physical control channel (DPCCH) 312. The DPDCH310 is used to carry the data 306 generated in Layer 2 of the OSI (Open Systems Interconnection) model and the layers above it, namely the Dedicated Control Channel (DCH). DPCCH312 carries the control information generated in layer 1 of the OSI model. The control information includes pilot bits 300 used in channel estimation, feedback information (FBI) 308 transmit power control instruction (TPC) 302, and selectively transfer format coupling indicator (TFCI) 304. TFCI304 informs the receiver about the transfer formats of the different transfer channels used in the current frame, i.e. the transfer format combination. [0045]
As can be seen from FIG. 3, the downlink DPDCH310 and DPCCH312 are time-multiplexed to the same slot 330C. On the uplink, the channels are sent in parallel so that the channels are IQ / code (I = common mode, Q = quadrature) that are multiplexed to each frame 340C. [0046]
The channels of the wireless interface Uu follow the OSI (Open Systems Interconnection) model of ISO (International Organization for Standardization), and have three protocol layers, a physical layer (= layer 1), a data link layer (= layer 2), and a network layer. It is processed according to the protocol architecture including (= Layer 3). The protocol stack is located in both the wireless network subsystem RNS and the user equipment UE. Each unit (eg, user equipment or wireless network subsystem) has a layer that logically communicates with layers of other units. Only the lowest physical layers communicate directly with each other. The other layers always use the services provided for the next lower layer. Thus, the message must physically pass vertically between the layers, and only at the lowest layer the message will pass horizontally between the layers. Figure 7A shows the layers of the protocol architecture. The ellipse between the different sublayers indicates the Service Access Point (SAP). [0047]
The physical layer L1 provides different transport channels for the sublayer MAC and higher layers of the MAC. The physical layer transfer service will be described as to how and by what characteristics data is transferred by a wireless interface. Transfer channels include paging channel PCH, broadcast channel BCH, synchronous channel SCH, random access channel RACH, forward access channel FACH, downlink shared channel DSCH, high-speed uplink signal channel FAUSCH and dedicated channel DCH. The physical layer L1 maps the forwarding channel by the physical channel. In FDD (Frequency Division Duplex) mode, physical channels are characterized by code, frequency, and in uplink, by relative phase (I / Q). In TDD (Time Division Duplex) mode, physical channels are also characterized by time slots. [0048]
The forwarding channels are the common channel (when the UE needs to be in-band identified when a particular UE is addressed) and the dedicated channel (when the UE is a physical channel: code and frequency for FDD and code, time for TDD). Can be divided into (if identified by slot and frequency). [0049]
The types of common transfer channels are as follows. RACH is a competition-based uplink channel used, for example, to carry a fairly small amount of initial access or non-real-time dedicated control or traffic data. FACH is a common downlink channel without closed-loop power control used to carry fairly small amounts of data. DSCH is a downlink channel shared with multiple UEs that carry dedicated control or traffic data. BCH is a downlink channel used to broadcast system information throughout the cell. SCH is a downlink channel used to broadcast synchronization information throughout the cell in TDD mode. PCH is a downlink channel used to broadcast control information throughout the cell, enabling efficient UE sleep mode procedures. [0050]
Next, the model of the dedicated transfer channel is as follows. A DCH is a single UE-only channel used for uplinks or downlinks. FAUSCH is an uplink channel used to allocate a dedicated channel in connection with FACH. The data link layer is divided into two sublayers, namely the MAC sublayer (media access control) and the RLC sublayer (wireless link control). The MAC sublayer L2 / MAC provides different logical channels for the RLC sublayer L2 / RLC. Logical channels are characterized by the type of information transferred. Logical channels include paging control channel PCCH, broadcast control channel BCCH, synchronous control channel SCCH, common control channel, dedicated control channel DCCH and dedicated traffic channel DTCH. [0051]
The control channel is used for the transfer of control plane information only. SCCH is a downlink channel for broadcasting synchronization information in the case of TDD (Time Division Duplex) operation. BCCH is a downlink channel for broadcasting system control information. PCCH is a downlink channel that transfers paging information. CCCH is a bidirectional channel for transmitting control information between the network and the UE. This channel is commonly used by UEs that do not have an RRC connection to the network. DCCH is a point bidirectional channel in that it transmits dedicated control information between the UE and the network. This channel is established through the RRC connection setup procedure. [0052]
Traffic channels are used for the transfer of user plane information only. DTCH is a point-to-point channel dedicated to one UE for the transfer of user information. DTCH can exist on both uplink and downlink. [0053]
The MAC layer maps logical channels by forwarding channel. One of the functions of the MAC sublayer is to select the appropriate transfer format for each transfer channel that depends on the instantaneous source bit rate. [0054]
Figure 7C shows the mapping between the logical channel and the forwarding channel. SCCH is connected to SCH. BCCH is connected to BCH. PCCH is connected to PCH. CCCH is connected to RACH and FACH. The DTCH can be connected to RACH and FACH, to RACH and DSCH, to DCH and DSCH, or to DCH. The DCCH can be connected to RACH and FACH, to RACH and DSCH, to DCH and DSCH, to DCH, or to FAUSCH. [0055]
The third layer L3 has an RRC sublayer (radio resource control) that processes the layer 3 control plane signal between the user equipment and the network. Functions performed by the RRC sublayer include allocation, reconfiguration and release of radio resources for RRC connections. Therefore, the RRC sublayer handles the allocation of radio resources required for RRC connections, including both control and user plane requirements. The RRC layer may reconstruct radio resources while establishing an RRC connection. [0056]
In the present invention, we are interested in encrypting the data flow of different services of one user. According to known techniques, all data flows are encrypted using the same encryption mask. [0057]
The method according to the invention for encrypting the data transmission of a wireless system is shown in FIG. Execution of this method begins at block 600. [0058] [0058]
In block 602, the encryption key is generated according to a known technique, for example as described in the background portion of the present invention. [0059]
In block 604A, the encryption mask is generated in the encryption algorithm using the encryption key as an input parameter. Logical channel specific parameters or transfer channel specific parameters are also used as additional input parameters to the encryption algorithm. The logical channel identification parameter can be one of a radio access bearer identifier, a logical channel identifier, a signal link identifier, or some other parameter that identifies the channel used. A particular parameter of the transfer channel can be, for example, a dedicated channel call identifier, or some other parameter that identifies the transfer channel used. [0060]
The term "bearer" is a high-level name for transmitting information used in connection with network services. Depending on the service, UMTS information can normally be transmitted using one or more bearers. For example, services include speech transmission, data services and video services. The radio bearer, on the other hand, represents that portion of the bearer that extends across the air interface. One logical channel usually carries one radio bearer. Logical channels define the services provided by the MAC layer. Logical channels can be mapped to different types of forwarding channels (to dedicated forwarding channels or common forwarding channels), depending on the existing service mode. The forwarding channel defines the services provided by the physical layer. It is also possible to multiplex multiple logical channels to one transport channel at the MAC layer. In addition, the transfer channel is mapped to the physical channel of the physical layer. Layer 1 allows multiple transport channels to be multiplexed into a single physical channel. After multiplex of the transfer channel, it is possible to split the data stream among multiple physical channels. [0061]
Thus, the present invention can be applied to a wireless system in which one or more parallel wireless bearers can be used to radio the terminal with other transceivers. Typically, when a call is established between the terminal and the network, a physical channel is first established for the signaling radio bearer SRB between the terminal and the wireless network subsystem, and this channel is established once. And one or more actual traffic bearers can be established. SRB can also be called a signal link. [0062]
The direction of transmission (uplink / downlink) can be used as an additional input parameter to the encryption algorithm. [0063]
Yet another parameter exists, i.e. the radio frame specific parameter can be used as an additional input parameter to the encryption algorithm. The radio frame specific parameter can be, for example, a user equipment frame number (UEFN), or some other parameter that identifies the radio frame used. The radio frame specific parameters depend on the protocol layer in which the encryption function is performed. If the cryptographic function is implemented at the protocol layer terminating at UE and CN, a mechanism for transporting the used frame number to the receiver must be specified. If the cryptographic function is located at the MAC layer or layer 1 (or some other layer terminating at the UE and node B or RNC), then a frame number consisting of at least a physical frame number can be used. This means that it is not necessary to signal the used frame number as data. [0064]
In block 606, the encrypted data is generated by applying an encryption mask to the plain data, for example using an XOR operation as shown in Table 1. [0065]
Next, detailed examples showing the implementation of the encryption method in the transmitter and the receiver will be described in relation to FIGS. 4A, 4B, and 4C. It will be apparent to those skilled in the art that, for example, encryption can be performed in various states with different numbers of PDUs, although only relevant points will be shown. [0066]
FIG. 4A shows a block diagram defining the basic cryptographic environment specified in the present invention. The generation means 408 is used to generate the encryption key 410 according to a known technique. An encryption algorithm 400 for generating encryption masks 412A, 412B, and 412C is connected to the generation means 408. The encryption algorithm uses the generated encryption key 410 as an input parameter. The encryption algorithm 400 uses the logical channel identification parameter 402A as an additional input parameter. [0067]
At the receiver terminal, the logical channel identification parameter required for decryption can be read from the unencrypted MAC header, for example, from the C / T field of the MAC header. The structure of the MAC PDU is shown in Figure 8. A MAC PDU consists of an optional MAC header 800 and a MAC Service Data Unit (MAC SDU) 802. Both the MAC header and MAC SDU are variable in size. The content and size of the MAC header 800 depends on the type of logical channel, and in some cases no parameters are required for the MAC header 800. The size of the MAC-SDU802 depends on the size of the RLC PDU specified during the setup procedure. MAC header 800 includes C / T field 804. This choice allows for efficient MAC multiplexing of different logical channels (or different instances of the same logical channel type) into a single forwarding channel, both dedicated and common forwarding channels. When using this method, the MAC header is not encrypted, which allows the receiver terminal to have a different MAC. PDU isolation is possible, and common channel mode allows reading of the RNTI (Radio Network Temporary Identifier) field required to routineize a message to the correct entity of UTRAN. [0068]
The encryption algorithm 400 includes encryption means 416A, 416B, 416C for generating encrypted data 418A, 418B, 418C by applying the encryption masks 412A, 412B, 412C to the plain data 414A, 414B, 414C. Is connected. As can be seen in Figure 4A, plain data contains wireless link control layer protocol data units from at least two parallel logical channels, and individual encryption masks are generated for each logical channel. Therefore, in FIG. 4A, therefore, the encryption masks 412A, 412B and 412C are all different from each other. [0069]
At block 420, the encrypted RLC-PDU is processed through the MAC layer and mapped to one forwarding block set, the MAC PDU set. [0070]
Another possible solution is one in which plain data contains one wireless link control layer protocol data unit 414A from only one logical channel, and individual encryption masks 412A for said logical channel. Is generated. Therefore, the present invention also works for individual logical channels. [0071]
A new cryptographic mask is typically generated for each radio frame in the physical layer of the protocol stack. If interleaving is used, a new cryptographic mask can be generated for each interleaving period in the physical layer of the protocol stack. Typically, one interleave period consists of multiple radio frames. [0072]
The left side of FIG. 4A shows the operation performed by the transmitter. As shown on the right side of Figure 4A, the corresponding operation is also performed on the receiver. The only difference is that block 422 is used to derive the RLC-PDU from the received transfer blockset, and decoding means 424A, 424B, 424C are used to decode the received data. is there. [0073]
In one embodiment of the invention, the wireless link control layer protocol data unit of at least one logical channel is already encrypted, and the step of generating the encrypted data is the already encrypted wireless link control. Not repeated due to layer protocol data units. Thus, it is possible to avoid encrypting the data twice. Of course, for example, if such terminal-to-terminal encryption is used, the data can be encrypted twice, first by service application and then by the MAC layer according to the invention. This causes no loss of transmit capacity because the XOR operation does not add extra bits, even if the encryption is performed twice. [0074]
Figure 4B shows a solution for a situation where plain data contains at least two consecutive wireless link control layer protocol data units on a logical channel. For example, assuming that the first RLC PDU414A and the second RLC PDU414B are from one logical channel, the problem is to generate only one encryption mask 412A for these PDU414A, 414B. Can be solved in any way. The different parts of this encryption mask 412A are then used to encrypt the first PDU414A and the second PDU414B. The length of the encryption mask 412A required in this case is, of course, the sum of the lengths of the first and second PDU414A and 414B. Since PDU414A, 414B are from the same logical channel (same radio access bearer), the maximum length required can be calculated to be twice the maximum RLC PDU size for that bearer. [0075]
Figure 4C shows the plain data having one transfer block set (TBS) containing media access control layer protocol data units for at least two different logical channels, with encrypted data for each transfer block set. One encryption mask 412 is used when generating. In this selection, the basic unit to be encrypted is the transfer block set. This specifies the required length of the encryption mask 412 manufactured by Algorithm 400. Layer 1 still adds a transfer block-specific CRC (Cyclic Redundancy Check), but since the XOR operation does not change the length of the data, the entire TBS must be able to be encrypted as a unit. The length of each transfer block on TBS must be communicated to L1 anyway. This choice has the disadvantage that the MAC header is also encrypted and therefore the MAC PDU cannot be routed anywhere on the network side before decrypting the TBS. This is a problem if a common channel on the lur is possible. The length of the required encryption mask 412 is equal to the maximum transfer blockset size for the transfer channel in question. [0076]
Another possible solution is one in which plain data contains a media access control layer protocol data unit for one logical channel, and for each transfer blockset, one encryption in generating the encrypted data. Chemical mask 412 is used. [0077]
The solution of the present invention is preferably implemented in a wireless system by software, in which case the present invention is protocol processing software located in transmitters and receivers, in particular blocks 204A, 204B and 226A, 226B of FIG. Needs a certain function. Thus, the generation means 408, the encryption algorithm 400 and the encryption means 416A, 416B, 416C can be software modules of the protocol stack present in the user equipment UE and the wireless network subsystem RNS. The solution can also be implemented in hardware, for example using an ASIC (application specific integrated circuit) or a separate component. [0078]
The method of the present invention can be implemented, for example, in the media access control layer of the protocol stack. This is shown in Figure 7B, which provides a high-level overview of the MAC layer shown in Figure 7A for the cryptographic features involved. C1 () and C2 () are two choices of encryption location. C1 (0), C1 (1), C1 (2) and C1 (3) show the use of logical channel specific encryption parameters as described above with reference to Figures 4A and 4B, whereas , C2 (00), C2 (01) and C2 (02) indicate the use of transport channel specific encryption parameters. Some MAC features may be needed under the C2 (00), C2 (01) and C2 (02) blocks, but for clarity, they are not shown here. Basically, RLC PDUs come from each logical channel to the MAC layer. At the MAC layer, RLC-PDUs are then mapped to MAC PDUs in functional blocks 700, 702, 704, which include PCH, BCH, SCH, dedicated channel and common channel operations. Usually one RLC PDU is one MAC Mapped to PDU (= forwarding block). This mapping provides a logical-to-forward-channel mapping. The mapping rules are described above in relation to Figure 7C. If encryption is used for CCCH, the encryption block, eg C1 (4), must be in the line between "CCCH" and functional block 704 in Figure 7B. [0079]
Although the present invention has been described above with reference to the examples shown in the accompanying drawings, the present invention is not limited to the examples and can be used in many ways within the creative concept disclosed in the appended claims. It is clear that it can be changed.
[Simple explanation of drawings]
[Fig. 1A]
This is an example of a mobile telephone system (No. 1). [Fig. 1B]
This is an example of a mobile telephone system (No. 2). [Fig. 2A]
Shows transmitter and receiver. [Fig. 2B]
It shows the coding and multiplexing of the transfer channel. [Fig. 3]
Shows the frame structure. [Fig. 4A]
It is a block diagram (No. 1) of the encryption environment by this invention. [Fig. 4B]
It is a block diagram (2) of the encryption environment by this invention. [Fig. 4C]
It is a block diagram (3) of the encryption environment by this invention. [Fig. 5]
Indicates a mobile station. [Fig. 6]
It is a flowchart which showed the method by this invention. [Fig. 7A]
An example of the protocol stack is shown. [Fig. 7B]
An example of the protocol stack according to the present invention is shown. [Fig. 7C]
The mapping between the logical channel and the forwarding channel is shown. [Fig. 8]
The structure of the media access control layer protocol data unit is shown.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2014156620A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| USRE45333E1 | Cited by | United States of America | Applicant |
| JP2006279217A | Cited by | Japan | Examiner |
| US7606226B2 | Cited by | United States of America | Applicant |
| US7623887B2 | Cited by | United States of America | Applicant |
| US7869758B2 | Cited by | United States of America | Applicant |
| US7606226B2 | Cited by | United States of America | Applicant |
| USRE45333E | Cited by | United States of America | Applicant |
| US8380232B2 | Cited by | United States of America | Applicant |
| US8010039B2 | Cited by | United States of America | Applicant |
| US8077716B2 | Cited by | United States of America | Applicant |
| JPH10502507A | Cites | Japan | Examiner |
19 members in 10 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 990500 | Finland | A | |
| 990500 | Finland | A | |
| 990500 | Finland | – | |
| 0000177 | Finland | W | |
| 0000177 | Finland | W | |
| 1999990500 | – | – | – |
| 200000177 | – | – | – |
| FI19990000500 | – | – | – |
| WO2000FI00177 | – | – | – |
Members19
| Document | Office | Kind | |
|---|---|---|---|
| FI990500A0 | Finland | A0 | |
| FI990500A | Finland | A | |
| WO0054456A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU3168900A | Australia | A | |
| FI107487B | Finland | B | |
| KR20010102541A | Republic of Korea | A | |
| EP1159800A1 | European Patent Office (EPO) | A1 | |
| BR0008800A | Brazil | A | |
| CN1349695A | China | A | |
| JP2002539490AThis record | Japan | A | |
| US6882727B1 | United States of America | B1 | |
| US2006120530A1 | United States of America | A1 | |
| EP1159800B1 | European Patent Office (EPO) | B1 | |
| DE60037576D1 | Germany | D1 | |
| KR100816897B1 | Republic of Korea | B1 | |
| DE60037576T2 | Germany | T2 | |
| US7602917B2 | United States of America | B2 | |
| BR0008800B1 | Brazil | B1 | |
| CN1349695B | China | B |
7 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 | |
| Notification of change in applicantJAPANESE INTERMEDIATE CODE: A712A711 | A711 |
Numbers
- Publication
- 2002-539490
- Publication, DOCDB
- 2002539490
- Publication, EPODOC
- JP2002539490
- Application
- 604569
- Application, DOCDB
- 2000604569
- Application, EPODOC
- JP20000604569
Titles2
- Japanese
- 【発明の名称】無線システムのデータ伝送を暗号化する方法
- English
- PROBLEM TO BE SOLVED: To encrypt data transmission of a wireless system.
Classification
- CPC, 6
- H04L9/065
- H04W12/02
- H04L2209/046
- H04L2209/34
- H04L2209/80
- H04W12/033
- IPC, 3
- G09C1 00
- H04L9 18
- H04W12 02