System and method for optimizing authentication procedure during inter access system handovers
Abstract
The present invention provides a method and system for deriving a new key for accessing a new system. The present invention enables an optimized authentication procedure using an existing system access key during handover from an existing system to a new system. Allowing the user terminal to perform fast re-authentication During the handover preparation, the user terminal accessing the new system receives the temporary ID. The above method uses an existing system access key to generate a system access key for the new network.

Term
Projected expiry 2 April 2027.
- Priority
- Filed
- Published
- Today
- Projected expiry
24 claims: 5 independent, 19 dependent
- 1異種ネットワークにおけるアクセスシステム間のハンドオーバー時に認証手順を最適化する方法であって、 新たなシステムにアクセスするための新たなキーを派生するステップと、 既存システムから新たなシステムへのハンドオーバー時に既存システムアクセスキーを用いて認証手順を最適化するステップと、 ハンドオーバー準備時に新たなシステムにアクセスし、UEが前記新たなシステムで速い再認証を遂行可能にするための臨時ID(Identification)を前記UEによって受信するステップと、 を有することを特徴とする方法。
- 2認証手順の最適化は、 I-WLAN(Integrated Wireless Local Area Network access system)からSAE(System Architecture Evolution access system)への順方向ハンドオーバー及びSAEからI-WLANへの逆方向ハンドオーバーと、 UMTS(Universal Mobile Telecommunication System)からSAEへの順方向ハンドオーバー及びSAEからUMTSへの逆方向ハンドオーバーと、 I-WLANからUMTSへの順方向ハンドオーバー及びUMTSからI-WLANへの逆方向ハンドオーバーのうち、少なくとも一つからのUEハンドオーバーに関連していることを特徴とする請求項1に記載の方法。
- 3SAEアクセスシステムからI-WLANへの前記逆方向ハンドオーバーは、 前記UEによって、周期的又はイベントベースの測定値をEUTRAN(Enhanced UMTS Terrestrial Radio Access Network)に伝送するステップと、 ENB(Evolving Node B)/MME(Mobility Management Entity)によって、伝送されたUE測定値がしきい値以下であると判断し、あるいはMMEによってEUTRANが持続できないと判断するステップと、 前記ENB/MMEによって、他のRAT(Radio Access Technology)又はUEのサービス領域内で利用可能なRATをスキャンするようにUEに要求し、あるいはUEによってEUTRANが持続できないと決定して他のRATをスキャニングするステップと、 前記UEによって、I-WLAN IDとNAI(Network Access Identifier)を含むI-WLAN測定レポートを他のパラメータと共にSAEシステムに伝送し、ENB/MME又はENB/MMEと論理インターワーキングユニットによって、UEをI-WLANネットワークにハンドオーバーするように決定するステップと、 前記MMEによって、I-WLANのAAA(Authentication,Authorization,and Accounting)サーバIPアドレスを分析するためにNAIを利用し、論理インターワーキングユニットを通じてAAAサーバに接続し、前記論理インターワーキングユニットはMME、AAAサーバ、又はSAEシステム又はI-WLANシステムのネットワークエンティティのうちの一つに配置されたステップと、 前記MMEによって、前記インターワーキングユニットを通じてハンドオーバー要求をAAAサーバに伝送し、前記ハンドオーバー要求はNAI、I-WLAN ID、非使用AV(Authentication Vector)、最新CK(Cypher Key)及びIK(Integrity Key)とその他パラメータを含むステップと、前記AAAサーバによって、他のAAAが登録されたか否かを判定するようにHSS(Home Subscription Server)を確認し、そうでない場合には、AAAサーバによってソフト登録を遂行し、AAAは、NAI、CK及びIKを用いてMSK、TEK、及びEMSKキーを生成し、匿名(pseudonym)ID及び速い再認証IDを含む臨時IDを生成し、前記TEKを用いて臨時IDを保護してUEに伝送するステップと、 前記AAAサーバによって、インターワーキングユニットを通じてハンドオーバー承認メッセージをMMEに伝送し、前記ハンドオーバー承認メッセージは保護された臨時IDと認証が要求されるか否かを示す表示を含むステップと、 前記MMEによって、前記受信されたパラメータを含むハンドオーバー命令メッセージをハンドオーバー承認メッセージを通じてUEに伝送するステップと、 UEによって、I-WLANネットワークへのハンドオーバーのためにSAEシステムからハンドオーバー命令を受信した後に、前記CK及びIKを用いてMSK、TEK及びEMSKキーを生成し、保護された臨時IDを解読するステップと、 UEによって、I-WLANとのL2(Layer2)接続(attachment)を開始するステップと、 を有することを特徴とする請求項2に記載の方法。
- 4I-WLANシステムが認証を要求すると、I-WLANによって認証手順を開始するステップと、 UEがハンドオーバー命令を受信すると、前記UEによって速い再認証臨時IDを伝送するステップと、 前記UEによって、臨時匿名ID、臨時速い再認証ID、及びEAP(Extensible Authentication Protocol)応答識別メッセージのインテグリティの保護のうちの一つと共にEAP応答識別メッセージをI-WLANを通じてAAAサーバに伝送するステップと、 AAAサーバによって、臨時IDと一緒にEAP応答識別メッセージを受信し、インテグリティの保護及び臨時IDを検証することによって、AAAがUEを認証するステップと、 前記AAAサーバによって、保護された成功的な結果表示を利用することを以前に要求した場合、EAP成功メッセージを伝送する前にEAP要求/AKA通知メッセージを伝送し、前記EAP要求/AKA通知メッセージはMAC(Medium Access Control)保護され、前記AAAサーバは新たな臨時IDと前記EAP要求/AKA通知メッセージを生成してUEに伝送するステップと、 I-WLANによって、EAP要求/AKA通知メッセージをUEに伝達し、UEはEAP応答/AKA通知を伝送してEAP応答/AKA通知メッセージをAAAサーバに伝達し、AAAサーバは前記メッセージの内容を考慮しないステップと、 AAAサーバによって、EAP成功メッセージをI-WLANに伝送し、I-WLANに対して付加キーイング要素が生成された場合、I-WLANは認証されたWLAN-UEとの通信に利用されるキーイング要素を格納するステップと、 AAAサーバが保護された成功的な結果表示を利用しないと、新たな臨時IDを生成してEAP成功メッセージと一緒にUEに伝送するステップと、 I-WLANによって、EAP成功メッセージを通じてWLAN-UEに成功的な認証について知らせ、EAP AKA交換が成功的に完了され、WLAN-UE及びI-WLANはEAP AKA交換中に派生されたキーイング要素を共有するステップと、 UEによって、I-WLANネットワークと一緒に速い再認証手順を開始し、UEが速い再認証IDを受信しないと、UEが全体認証手順を開始するために匿名IDを伝送するステップと、 をさらに有することを特徴とする請求項3に記載の方法。
- 5SAEアクセスシステムからI-WLANへの前記逆方向ハンドオーバーは、 前記UEによって、周期的又はイベントベースの測定値をEUTRANに伝送するステップと、 前記ENB/MMEによって、伝送されたUE測定値がしきい値以下であると判断し、あるいはMMEによってEUTRANが持続できないと判断するステップと、 前記ENB/MMEによって、他のRAT又はUEのサービス領域内で利用可能なRATをスキャンするようにUEに要求し、あるいはUEによってEUTRANが持続できないと決定して他のRATをスキャニングするステップと、 前記UEによって、少なくともI-WLAN IDとNAIを含むI-WLAN測定レポートをSAEシステムに伝送し、前記ENB/MMEによってUEをI-WLANネットワークにハンドオーバーするように決定するステップと、 前記MMEによって、I-WLANのAAAサーバIPアドレスを分析するためにNAIを利用し、論理インターワーキングユニットを通じてAAAサーバに接続し、前記論理インターワーキングユニットはMME、AAAサーバ、又はSAEシステム又はI-WLANシステムのネットワークエンティティのうちの一つに配置されたステップと、 前記MMEによって、インターワーキングユニットを通じてハンドオーバー要求をAAAサーバに伝送し、前記ハンドオーバー要求はNAI、I-WLAN ID、非使用AV、最新CK及びIKとその他パラメータを含むステップと、前記AAAサーバによって、他のAAAが登録されたか否かを判定するようにHSSを確認し、そうでない場合には、AAAサーバによってソフト登録を遂行し、AAAは、NAI、CK及びIKを用いてMSK、TEK、及びEMSKキーを生成し、匿名ID及び速い再認証IDを含む臨時IDを生成し、前記TEKを用いて臨時IDを保護してUEに伝送するステップと、 前記AAAサーバによって、インターワーキングユニットを通じてハンドオーバー承認メッセージをMMEに伝送し、前記ハンドオーバー承認メッセージは保護された臨時IDと認証が要求されるか否かを示す表示を含むステップと、 前記MMEによって、前記受信されたパラメータを含むハンドオーバー命令メッセージをハンドオーバー承認メッセージを通じてUEに伝送するステップと、 前記UEによって、I-WLANネットワークへのハンドオーバーのためにSAEシステムからハンドオーバー命令を受信した後に、前記CK及びIKを用いてMSK、TEK及びEMSKキーを生成し、保護された臨時IDを解読するステップと、 前記UEによってI-WLANとのL2接続を開始するステップと、 を有することを特徴とする請求項1に記載の方法。
- 6I-WLANシステムが認証を要求すると、I-WLANによって認証手順を開始するステップと、 前記UEがハンドオーバー命令を受信すると、前記UEによって速い再認証臨時IDを伝送するステップと、 前記UEによって、臨時匿名ID、臨時速い再認証ID、及びEAP(Extensible Authentication Protocol)応答識別メッセージのインテグリティの保護のうちの一つと共にEAP応答識別メッセージを前記I-WLANを通じてAAAサーバに伝送するステップと、 前記AAAサーバによって、臨時IDと一緒にEAP応答識別メッセージを受信し、インテグリティの保護及び臨時IDを検証することによって、前記AAAがUEを認証するステップと、 前記AAAサーバによって、保護された成功的な結果表示を利用することを事前に要求した場合、EAP成功メッセージを伝送する前にメッセージEAP要求/AKA通知メッセージを伝送し、前記EAP要求/AKA通知メッセージはMAC保護され、前記AAAサーバは新たな臨時IDと前記EAP要求/AKA通知メッセージを生成してUEに伝送するステップと、 前記I-WLANによって、EAP要求/AKA通知メッセージをUEに伝達し、UEはEAP応答/AKA通知を伝送してEAP応答/AKA通知メッセージをAAAサーバに伝達し、AAAサーバは前記メッセージの内容を考慮しないステップと、 前記AAAサーバによって、EAP成功メッセージをI-WLANに伝送し、I-WLANに対して付加キーイング要素が生成された場合、I-WLANは認証されたWLAN-UEとの通信に利用されるキーイング要素を格納するステップと、 前記AAAサーバが保護された成功的な結果表示を利用しないと、前記AAAサーバによって新たな臨時IDを生成してEAP成功メッセージと一緒にUEに伝送するステップと、 前記I-WLANによって、EAP成功メッセージを通じてWLAN-UEに成功的な認証について知らせ、EAP AKA交換が成功的に完了され、WLAN-UE及びI-WLANはEAP AKA交換中に派生されたキーイング要素を共有するステップと、 前記UEによって、I-WLANネットワークと一緒に速い再認証手順を開始し、UEが速い再認証IDを受信しないと、UEが全体認証手順を開始するために匿名IDを伝送するステップと、 前記UEによって、成功的な認証手順以後にHO命令にAAAサーバによってリストされた最適化した認証手順を開始し、UEはEMSK(Extended Master Session Key)基盤の最適化手順を用いて前記最適化した認証手順を開始するステップと、をさらに有し、 前記UEは、前記最適化した認証手順のための速い再認証手順を選択的に(alternatively)開始することを特徴とする請求項5に記載の方法。
- 7I-WLANとの成功的な接続後に、前記UEによって、HO命令にAAAサーバによってリストされた最適化認証手順を開始し、前記UEは、EMSK(Extended Master Session Key)基盤の最適化手順を用いて前記最適化した認証手順を開始するするステップをさらに有し、 前記UEは、前記最適化した認証手順のための速い再認証手順を選択的に開始することを特徴とする請求項5に記載の方法。
- 8SAEからI-WLAN ASへの順方向ハンドオーバーは、 認証手順の間に、前記UEが現在以前のアクセスシステムである既存のアクセスシステムの詳細を伝送し、コアネットワークによってセキュリティコンテキストとバッファリングされたコンテキストを以前アクセスシステムから検索し、以前アクセスシステムの詳細はEAPOL ID応答メッセージ内で伝送されるステップと、 認証手順の間に、前記UEとネットワークによってCKとIKを用いて複数のキーを派生させ、コアネットワークは臨時IDを生成して前記UEに伝送し、UEは速い再認証手順を始めるステップと、 前記UEによって、最も最近に成功的に受信されたパケットシーケンス番号をI-WLANネットワークに伝送し、I-WLANネットワークは前記パケットをコアネットワークに伝送し、コアネットワークは前記UEによって最後に成功的に受信されたシーケンス番号以後のパケットを伝送し始めるステップと、 を有することを特徴とする請求項2に記載の方法。
- 9I-WLANからSAEシステムへの逆方向ハンドオーバーは、 前記UEによって、MME、AAAサーバ、及びSAEシステム又はI-WLANシステムのネットワークエンティティのうちの一つに配置されるか、または個別に配置された論理的な決定及びインターワーキングユニットに周期的或いはイベントベースの測定値を伝送するステップと、 前記論理的な決定及びインターワーキングユニットはUE測定値がしきい値以下であり、あるいはI-WLANが持続できないことを知るようになると、前記論理的な決定及びインターワーキングユニットによって、他のRATをスキャニングし始めることをUEに要求し、あるいはENB/MMEによって、UEにそれのサービス領域内で利用可能な特定RATをスキャンすることを要求し、またはUEによってI-WLANが持続できないと判断して他のRATのスキャニングを始めるステップと、 前記UEによって、TAI、選択されたUIA及びUEA、ENB-ID及びSTART値を含むSAE測定レポートをAAAサーバを通じて論理的な決定及びインターワーキングユニットに伝送するステップと、 前記論理的な決定及びインターワーキングユニットは、UEをSAEネットワークにハンドオーバーするように決定し、前記決定をAAAサーバに知らせるステップと、 前記TAIを用いて、AAAサーバがHSSに接続してMMEアドレスを知るようになるステップと、 前記AAAサーバによって、ハンドオーバー要求メッセージをMME/UPE(User Plane Entity)に伝送し、前記ハンドオーバー要求メッセージは少なくとも以前RATタイプ、非使用AV、最も最新のCK及びIK、及びENB-IDを含むステップと、 前記MMEによって、他のAAAが登録されたか否かについてHSSを確認し、そうでない場合には、ソフト登録を遂行してキーを生成するステップと、 前記MMEによって、インタワーキングユニットを通じてAAAサーバにハンドオーバー承認メッセージを伝送し、前記MMEは選択されたUEA及びUIA、FRESHを含み、最後のRAN保護を開始するかを決定するステップと、 前記AAAサーバによって、ハンドオーバー承認メッセージを通じて受信されたパラメータをハンドオーバー命令メッセージを通じてUEに伝送するステップと、 前記SAEネットワークへのハンドオーバーのためにAAAサーバからハンドオーバー命令を受信した後に、UEによって、最も最新のCK及びIKを用いてSAEシステムに固有のキーを派生するステップと、 前記UEが何らの保護なしにENBとのL2接続を始めるステップと、 前記UEによって、初期L3メッセージをMME/UPEに伝送し、前記初期L3メッセージはユーザー識別、START値及びMAC-I NAS を含んでMAC-I NAS は派生したSAE固有のキー、及びFRESH及びSTART値を用いて計算されるステップと、 前記MME/UPEによって派生されたキー、受信されたSTART及びFRESH値を用いてMAC-Iを検証するステップと、 前記MME/UPEによってENB、START、FRESH及びUEA及びUIAに対するキーを含む初期L3メッセージ応答を伝送し、MMEがENB、START、選択的にはFRESH及びUEA及びUIAに対するキーを除いた初期L3メッセージが応答を通じてMAC-I NAS を計算するステップと、 前記MMEによって、初期L3メッセージが応答を受信してSTART、FRESH及びUEA及びUIAに対するキーを格納するステップと、 前記ENBによって、初期L3メッセージが応答をUEに伝送し、RANセキュリティ(MAC-I RAN )を始めるステップと、 前記UEによって、MAC-I NAS とMAC-I RAN を検証するステップと、 を有することを特徴とする請求項2に記載の方法。
- 10I-WLANからSAEシステムへの逆方向ハンドオーバー(代案2)は、 前記UEによって、MME、AAAサーバ、及びSAEシステム又はI-WLANシステムのネットワークエンティティのうちの一つに配置されるか、または個別に配置された論理的な決定及びインターワーキングユニットに周期的或いはイベントベースの測定値を伝送するステップと、 前記論理的な決定及びインターワーキングユニットはUE測定値がしきい値以下であるか、あるいはI-WLANが持続できないことを知るようになると、前記論理的な決定及びインターワーキングユニットによって、UEに他のRATをスキャニングし始めることを要求し、あるいはENB/MMEによって、UEにそれのサービス領域内で利用可能な特定RATをスキャンすることを要求し、またはUEがI-WLANが持続できないと判断して他のRATのスキャニングを始めるステップと、 前記UEによって、TAI、選択されたUIA及びUEA、ENB-ID及びSTART値を含むSAE測定レポートをAAAサーバを通じて論理的な決定及びインターワーキングユニットに伝送するステップと、 前記論理的な決定及びインターワーキングユニットは、UEをSAEネットワークにハンドオーバーするように決定し、前記決定をAAAサーバに知らせるステップと、 前記TAIを用いて、AAAサーバがHSSに接続してMMEアドレスを知るようになるステップと、 前記AAAサーバによって、ハンドオーバー要求メッセージをMME/UPEに伝送し、前記ハンドオーバー要求メッセージは少なくとも以前RATタイプ、非使用AV、最も最新のCK及びIK、及びENB-IDを含むステップと、 前記MMEによって、他のAAAが登録されたか否かについてHSSを確認し、そうでない場合には、ソフト登録を遂行し、AAAサーバによって伝送されたCKとIKを用いてキーを生成するステップと、 前記MMEによって、FRESHを生成し、ENB-IDを用いてENBにセキュリティコンテキストを分配するステップと、 前記MMEによって、インタワーキングユニットを通じてAAAサーバにハンドオーバー承認メッセージを伝送し、前記ハンドオーバー承認メッセージは、前記選択されたUEA及びUIA、FRESHとRAN保護の開始のための表示を含むステップと、 前記AAAサーバがハンドオーバー承認メッセージを通じて受信された前記パラメータをハンドオーバー命令メッセージを通じてUEに伝送するステップと、 前記UEによって、最も最新のCK及びIKを用いてSAEシステムに固有のキーを決定し、UEをSAEネットワークにハンドオーバーするようにAAAサーバからハンドオーバー命令を受信した後、RAN保護を始めるステップと、 前記UEによって、ENBとのL2接続を始め、RRCメッセージを保護し、ENBへの初期メッセージで、UEはSTART値を伝送し、派生されたSAE固有のキー、FRESH及びSTART値を用いてMAC-I RAN を計算し、ENBがMAC-I RAN を検証するステップ、 前記UEが初期L3メッセージをMME/UPEに伝送し、前記初期L3メッセージはユーザー識別、START値及びMAC-I NAS を含み、MAC-I NAS は派生したSAE固有のキー、及びFRESH及びSTART値を用いて計算されるステップと、 前記MME/UPEによって、派生されたキー、受信されたSTART及びFRESH値を用いてMAC-Iを検証するステップと、 前記MME/UPEによって、初期L3メッセージ応答を伝送し、MMEは、前記初期L3メッセージ応答を通じてMAC-I NAS を計算するステップと、 をさらに有することを特徴とする請求項2に記載の方法。
- 11I-WLANからSAEシステムへの順方向ハンドオーバーは、 前記UEが現在以前のアクセスシステムである既存のアクセスシステムの詳細をTAU手順内に伝送し、コアネットワークによってTAU手順又は初期NASメッセージで以前アクセスシステムからセキュリティコンテキスト(CK及びIK)とバッファリングされたパケットを検索するステップをさらに有することを特徴とする請求項2に記載の方法。
- 12UMTSからSAEシステムへの逆方向ハンドオーバーは、 前記UEがSGSN(Serving GPRS Support Node)にレポートを通じて周期的またはイベントベースの測定値を伝送するステップと、 前記測定レポートに基づいて、SGSNがUEに他のRATをスキャニングし始めることを要求し、ENB/MMEがUEに他のRAT、またはUEのサービス領域内で利用可能なRATをスキャンすることを要求し、あるいはUEによってEUTRANが持続できないと決定して他のRATをスキャニングするステップと、 前記UEによって、TAI、選択されたUIA及びUEA、START値及びENB-IDを含む前記SAE測定レポートをSGSNに伝送するステップと、 前記SGSNによって、UEをSAEネットワークにハンドオーバーするように決定し、SGSNはMMEアドレスを決定するためにTAIを利用してS3又はS4インターフェースのうちの少なくとも一つを用いてMMEに接続し、HSSに接続するステップと、 前記SGSNによってMME/UPEにハンドオーバー要求メッセージを伝送し、前記ハンドオーバー要求メッセージは少なくとも、セキュリティコンテキスト、以前RATタイプ、非使用AV、最も最新のCK及びIK、ENB-ID、START値及びKSIを含むステップと、 前記MMEによって、他のMMEがHSSに登録されたか否かについてHSSを確認し、そうでない場合に、MMEはソフト登録を遂行してSGSNにより伝送されたCK及びIKを用いてキーを生成し、MMEがUMTSパラメータをMME、AAAサーバ、又はSAEシステム又はI-WLANシステムのネットワークエンティティの中の一つに配置された論理インターワーキングユニットを用いてSAE固有のパラメータに変換するステップと、 前記MMEによって、少なくてもRAN保護、選択されたUIA及びUEA、FRESH、START及びKSIに対するENBキーを含むセキュリティコンテキストをENBに分配するためにENB-IDを用いてFRESHを生成するステップと、 前記MMEによって、SGSNにハンドオーバー承認メッセージを伝送し、前記ハンドオーバー承認メッセージはUEA、UIA及びFRESHを含むステップと、 前記SGSNによって、HO承認メッセージを通じて受信されたパラメータをUEにハンドオーバー命令メッセージを通じて伝送するステップと、 UEによって、最も最新のCK及びIKを用いてSAEシステムに固有のキーを決定し、UEをSAEネットワークにハンドオーバーするためにSGSNからハンドオーバー命令を受信した後、RAN保護を始めるステップと、 前記UEによって、ENBとのL2接続を始め、RRCメッセージを保護し、ENBへの初期メッセージで、UEはSTART値を伝送し、派生されたSAE固有のキー、FRESH及びSTART値を用いてMAC-I RAN を計算し、ENBがSTART値と共に受信されたセキュリティテキストを用いてMAC-I RAN を検証するステップと、 前記UEによって、初期L3メッセージをMME/UPEに伝送し、前記初期L3メッセージはユーザー識別、START値、KSI及びMAC-I NAS を含み、MAC-I NAS は派生したSAE固有のキー、及びFRESH及びSTART値を用いて計算されるステップと、 前記MME/UPEによって、派生されたキー、受信されたSTART及びFRESH値を用いてMAC-I NAS を検証するステップと、 前記MME/UPEによって、初期L3メッセージ応答を伝送し、MMEは、前記初期L3メッセージ応答を通じてMAC-I NAS を計算するステップと、 をさらに有することを特徴とする請求項2に記載の方法。
- 13UMTSからSAEシステムへの順方向ハンドオーバーは、 TAU手順又は初期NASメッセージの間、UEが現在以前のアクセスシステムである既存のアクセスシステムの詳細を伝送し、コアネットワークは以前アクセスシステムからセキュリティコンテキスト(CK及びIK)とバッファリングされたパケットを検索するステップをさらに有することを特徴とする請求項2に記載の方法。
- 14SAEからUMTSシステムへの逆方向ハンドオーバーは、 前記UEによって、ENB/MMEにレポートを通じて周期的またはイベントベースの測定値を伝送するステップと、 前記ENB/MMEによって、UEに他のRAT又はUEのサービス領域内に利用可能なRATをスキャニングし始めることを要求するために前記レポートを利用し、あるいは前記UEによって、EUTRANが持続できないと決定して他のRATをスキャニングするステップと、 前記UEによって、RAI、支援されるUIA及びUEA、KSI及びSTART値、及びセルIDを含むUMTS測定レポートをENB/MMEに伝送するステップと、 前記SGSNによって、UEをUMTSネットワークにハンドオーバーするように決定し、MMEはRAIを用いてSGSNのアドレスを把握し、S3又はS4インターフェースのうちの一つを利用し、あるいはHSSに接続することによってSGSNに接続するステップと、 前記MMEによって、SGSNにハンドオーバー要求メッセージを伝送し、前記ハンドオーバー要求メッセージはセキュリティコンテキスト、以前RATタイプ、非使用AV、最も最新のCK及びIK、セルID、START値、KSI及び他のパラメータを含み、MMEはMME、SGSN、又はSAEシステム又はUMTSシステムのネットワークエンティティのうちの一つに配置された、または個別に配置された論理インターワーキングユニットを用いてSAEパラメータをUMTS固有のパラメータに変換するステップと、 前記SGSNによって、他のSGSNがHSSに登録されたか否かについてHSSを確認し、そうでない場合に、SGSNはソフト登録を遂行するステップと、 前記SGSNは、FRESHを生成し、少なくとも保護、選択されたUIA及びUEA、FRESH、START及びKSIに対したキーを含むセキュリティコンテキストをセルIDを用いてRNCに分配し、前記RNCは受信されたパラメータを格納するステップと、 前記SGSNによって、ハンドオーバー承認メッセージをMMEに伝送し、前記ハンドオーバー承認メッセージはUEA、UIA及びFRESHを含むステップと、 前記MMEによって、ハンドオーバー承認メッセージを通じて受信されたパラメータをUEにハンドオーバー命令メッセージを通じて伝送するステップと、 UMTSネットワークにハンドオーバーするために、MMEからハンドオーバー命令を受信した後に、UEによってUMTSネットワークに対して最も最新のCK及びIKを利用してRAN保護を始めるステップと、 前記UEによって、RNCとのL2接続を開始し、UEはRRCメッセージを保護し始め、初期メッセージの間にSTART値をRNCに伝達するステップと、 UEによって、ユーザー識別、START値、KSI及びMAC-Iを含む初期L3メッセージをSGSNに伝送するステップと、 RNCによって、MAC-Iを検証してSGSNに伝送するステップと、 をさらに有することを特徴とする請求項2に記載の方法。
- 15SAEからUMTSシステムへの順方向ハンドオーバーは、 RAU手順または1番目のNASメッセージ中に、UEが現在以前のアクセスシステムである既存のアクセスシステムの詳細を伝送し、現在ネットワークが以前アクセスシステムからセキュリティコンテキスト(CK及びIK)とバッファリングされたパケットを検索するステップをさらに有することを特徴とする請求項2に記載の方法。
- 16UMTSからI-WLANアクセスシステムへの前記逆方向ハンドオーバーは、 前記UEによって、周期的又はイベントベースの測定値をEUTRANに伝送するステップと、 前記RNC/SGSNによって、伝送されたUE測定値がしきい値以下であると判断し、あるいはSGSNによってEUTRANが持続できないと判断するステップと、 前記ENB/MMEによって、他のRAT又はUEのサービス領域内で利用可能なRATをスキャンするようにUEに要求し、あるいはUEによってEUTRANが持続できないと決定して他のRATをスキャニングするステップと、 前記UEによって、I-WLAN IDとNAIを含むI-WLAN測定レポートを他のパラメータと共にSGSNシステムに伝送し、SGSNによって、UEをI-WLANネットワークにハンドオーバーするように決定するステップと、 前記SGSNによって、I-WLANのAAAサーバIPアドレスを分析するためにNAIを利用し、論理インターワーキングユニットを通じてAAAサーバに接続し、前記論理インターワーキングユニットはSGSN、AAAサーバ、又はUMTSシステム又はI-WLANシステムのネットワークエンティティのうちの一つに配置されたステップと、 前記SGSNによって、インターワーキングユニットを通じてハンドオーバー要求をAAAサーバに伝送し、前記ハンドオーバー要求はNAI、I-WLAN ID、非使用AV、最新CK及びIKとその他パラメータを含むステップと、前記AAAサーバによって、他のAAAが登録されたか否かを判定するようにHSSを確認し、そうでない場合には、AAAサーバによってソフト登録を遂行し、AAAは、NAI、CK及びIKを用いてMSK、TEK、及びEMSKキーを生成し、匿名ID及び速い再認証IDを含む臨時IDを生成し、前記TEKを用いて臨時IDを保護してUEに伝送するステップと、 前記AAAサーバによって、インターワーキングユニットを通じてハンドオーバー承認メッセージをSGSNに伝送し、前記ハンドオーバー承認メッセージは保護された臨時IDと認証が要求されるか否かを示す表示を含むステップと、 前記SGSNによって前記受信されたパラメータを含むハンドオーバー命令メッセージをハンドオーバー承認メッセージを通じてUEに伝送するステップと、 前記UEによって、I-WLANネットワークへのハンドオーバーのためにUMTSシステムからハンドオーバー命令を受信した後に、前記CK及びIKを用いてMSK、TEK及びEMSKキーを生成し、保護された臨時IDを解読するステップと、 前記UEによってI-WLANとのL2接続を開始するステップと、 を有することを特徴とする請求項2に記載の方法。
- 17I-WLANシステムが認証を要求すると、I-WLANによって認証手順を開始するステップと、 UEがハンドオーバー命令を受信すると、前記UEによって速い再認証臨時IDを伝送するステップと、 前記UEによって、臨時匿名ID、臨時速い再認証ID、及びEAP応答識別メッセージのインテグリティの保護のうちの一つと共にEAP応答IDメッセージをI-WLANを通じてAAAサーバに伝送するステップと、 AAAサーバが臨時識別と一緒にEAP応答識別メッセージを受信すると、AAAサーバによって、インテグリティの保護及び臨時IDを検証するステップと、 前記AAAサーバによってUEを認証するステップと、 前記AAAサーバによって、保護された成功的な結果表示を利用することを以前に要求した場合、EAP成功メッセージを伝送する前にEAP要求/AKA通知メッセージを伝送し、前記EAP要求/AKA通知メッセージはMAC保護されるステップと、 前記AAAサーバによって、新たな臨時IDとEAP要求/AKA通知メッセージを生成してUEに伝送するステップと、 前記I-WLANによって、EAP要求/AKA通知メッセージをUEに伝達し、UEはEAP応答/AKA通知を伝送してEAP応答/AKA通知メッセージをAAAサーバに伝達し、AAAサーバは前記メッセージの内容を考慮しないステップと、 前記AAAサーバによって、EAP成功メッセージをI-WLANに伝送し、I-WLANに対して付加キーイング要素が生成された場合、AAAサーバは基本AAAプロトコルメッセージに前記キーイング要素を含み、I-WLANは認証されたWLAN-UEとの通信に利用されるキーイング要素を格納するステップと、 前記AAAサーバが保護された成功的な結果表示を利用しないと、新たな臨時IDを生成してEAP成功メッセージと一緒にUEに伝送するステップと、 前記I-WLANによって、EAP成功メッセージを通じてWLAN-UEに成功的な認証について知らせ、EAP AKA交換が成功的に完了され、WLAN-UE及びI-WLANはEAP AKA交換中に派生されたキーイング要素を共有するステップと、 前記UEによって、I-WLANネットワークと一緒に速い再認証手順を開始し、UEが速い再認証IDを受信しないと、UEが全体認証手順を開始するために匿名IDを伝送するステップと、 をさらに有することを特徴とする請求項16に記載の方法。
- 18UMTSからI-WLANアクセスシステムへの前記逆方向ハンドオーバーは、 前記UEによって、周期的又はイベントベースの測定値をEUTRANに伝送するステップと、 前記RNC/SGSNによって、伝送されたUE測定値がしきい値以下であると判断し、あるいはSGSNによってEUTRANが持続できないと判断するステップと、 前記ENB/MMEによって、他のRAT又はUEのサービス領域内で利用可能なRATをスキャンするようにUEに要求し、あるいはUEによってEUTRANが持続できないと決定して他のRATをスキャニングするステップと、 前記UEによって、I-WLAN IDとNAIを含むI-WLAN測定レポートを他のパラメータと共にSGSNシステムに伝送し、SGSNによって、UEをI-WLANネットワークにハンドオーバーするように決定するステップと、 前記SGSNによって、I-WLANのAAAサーバIPアドレスを分析するためにNAIを利用し、論理インターワーキングユニットを通じてAAAサーバに接続し、前記論理インターワーキングユニットはSGSN、AAAサーバ、又はUMTSシステム又はI-WLANシステムのネットワークエンティティのうちの一つに配置されたステップと、 前記SGSNによって、インターワーキングユニットを通じてハンドオーバー要求をAAAサーバに伝送し、前記ハンドオーバー要求はNAI、I-WLAN ID、非使用AV、最新CK及びIKとその他パラメータを含むステップと、前記AAAサーバによって、他のAAAが登録されたか否かを判定するようにHSSを確認し、そうでない場合には、AAAサーバによってソフト登録を遂行し、AAAは、NAI、CK及びIKを用いてMSK、TEK、及びEMSKキーを生成し、匿名ID及び速い再認証IDを含む臨時IDを生成し、前記TEKを用いて臨時IDを保護してUEに伝送するステップと、 前記AAAサーバによって、インターワーキングユニットを通じてハンドオーバー承認メッセージをSGSNに伝送し、前記ハンドオーバー承認メッセージは保護された臨時IDと認証が要求されるか否かを示す表示を含み、AAAサーバはハンドオーバー承認メッセージ内にハンドオーバー手順を継続して遂行するUEに対して支援される最適化手順を含むステップと、 前記SGSNによって前記受信されたパラメータを含むハンドオーバー命令メッセージをハンドオーバー承認メッセージを通じてUEに伝送するステップと、 前記UEによって、I-WLANネットワークへのハンドオーバーのためにUMTSシステムからハンドオーバー命令を受信した後に、前記CK及びIKを用いてMSK、TEK及びEMSKキーを生成し、保護された臨時IDを解読するステップと、 前記UEによってI-WLANとのL2接続を開始するステップと、 を有することを特徴とする請求項2に記載の方法。
- 19I-WLANシステムが認証を要求すると、I-WLANによって認証手順を開始するステップと、 前記Temp IDが前記UEによってハンドオーバー命令を受信すると、前記UEによって速い再認証臨時IDを伝送するステップと、 前記UEによって、臨時匿名ID、臨時速い再認証ID、及びEAP応答識別メッセージのインテグリティの保護のうちの一つと共にEAP応答識別メッセージをI-WLANを通じてAAAサーバに伝送するステップと、 AAAサーバが臨時IDと一緒にEAP応答識別メッセージを受信すると、AAAサーバによって、インテグリティの保護及び臨時IDを検証することによって、前記AAAサーバによってUEを認証するステップと、 前記AAAサーバによって、保護された成功的な結果表示を利用することを以前に要求した場合、EAP成功メッセージを伝送する前にメッセージEAP要求/AKA通知メッセージを伝送し、前記EAP要求/AKA通知メッセージはMAC保護されるステップと、 前記AAAサーバによって、新たな臨時IDとEAP要求/AKA通知メッセージを生成してUEに伝送するステップと、 前記I-WLANによって、EAP要求/AKA通知メッセージをUEに伝達し、UEはEAP応答/AKA通知を伝送してEAP応答/AKA通知メッセージをAAAサーバに伝達し、AAAサーバは前記メッセージの内容を考慮しないステップと、 前記AAAサーバによって、EAP成功メッセージをI-WLANに伝送し、I-WLANに対して付加キーイング要素が生成された場合、AAAサーバは基本AAAプロトコルメッセージに前記キーイング要素を含み、I-WLANは認証されたWLAN-UEとの通信に利用されるキーイング要素を格納するステップと、 前記AAAサーバが保護された成功的な結果表示を利用しないと、新たな臨時IDを生成してEAP成功メッセージと一緒にUEに伝送するステップと、 前記I-WLANによって、EAP成功メッセージを通じてWLAN-UEに成功的な認証について知らせ、EAP AKA交換が成功的に完了して、WLAN-UE及びI-WLANはEAP AKA交換中に派生されたキーイング要素を共有するステップと、 前記UEによって、I-WLANネットワークと一緒に速い再認証手順を開始し、UEが速い再認証IDを受信しないと、UEが全体認証手順を開始するために匿名IDを伝送するステップと、 成功的な認証手順以後に、UEがハンドオーバー命令にAAAサーバによってリストされた最適化した認証手順を開始し、前記UEによって、EMSK基盤の最適化手順を用いて前記最適化した認証手順を開始するステップと、 前記UEによって、前記最適化した認証手順に対する速い再認証手順を選択的に開始するステップと、 をさらに有することを特徴とする請求項18に記載の方法。
- 20UMTSからI-WLANアクセスシステムへの前記逆方向ハンドオーバーは、 前記UEによって、周期的又はイベントベースの測定値をEUTRANに伝送するステップと、 前記RNC/SGSNによって、伝送されたUE測定値がしきい値以下であると判断し、あるいはSGSNによってEUTRANが持続できないと判断するステップと、 前記ENB/MMEによって、他のRAT又はUEのサービス領域内で利用可能なRATをスキャンするようにUEに要求し、あるいはUEによってEUTRANが持続できないと決定して他のRATをスキャニングするステップと、 前記UEによって、I-WLAN IDとNAIを含むI-WLAN測定レポートを他のパラメータと共にSGSNシステムに伝送し、SGSNによって、UEをI-WLANネットワークにハンドオーバーするように決定するステップと、 前記SGSNによって、I-WLANのAAAサーバIPアドレスを分析するためにNAIを利用し、論理インターワーキングユニットを通じてAAAサーバに接続し、前記論理インターワーキングユニットはSGSN、AAAサーバ、又はUMTSシステム又はI-WLANシステムのネットワークエンティティのうちの一つに配置されたステップと、 前記SGSNによって、インターワーキングユニットを通じてハンドオーバー要求をAAAサーバに伝送し、前記ハンドオーバー要求はNAI、I-WLAN ID、非使用AV、最新CK及びIKとその他パラメータを含むステップと、前記AAAサーバによって、他のAAAが登録されたか否かを判定するようにHSSを確認し、そうでない場合には、AAAサーバによってソフト登録を遂行し、AAAは、NAI、CK及びIKを用いてMSK、TEK、及びEMSKキーを生成し、匿名ID及び速い再認証IDを含む臨時IDを生成し、前記TEKを用いて臨時IDを保護してUEに伝送するステップと、 前記AAAサーバによって、インターワーキングユニットを通じてハンドオーバー承認メッセージをSGSNに伝送し、前記ハンドオーバー承認メッセージは保護された臨時IDと認証が要求されるか否かを示す表示を含むステップと、 前記SGSNによって前記受信されたパラメータを含むハンドオーバー命令メッセージをハンドオーバー承認メッセージを通じてUEに伝送するステップと、 前記UEによって、I-WLANネットワークへのハンドオーバーのためにUMTSシステムからハンドオーバー命令を受信した後に、前記CK及びIKを用いてMSK、TEK及びEMSKキーを生成し、保護された臨時IDを解読するステップと、 前記UEによってI-WLANとのL2接続を開始するステップと、 前記UEによって、I-WLAN ANと成功的な接続以後に、ハンドオーバーの命令内のAAAサーバによってリストされたシナリオのための最適化した認証手順を開始し、UEによって、EMSKベースの最適化手順を用いて前記最適化した認証手順を開始するステップと、 前記UEによって、前記最適化した認証手順のための速い再認証手順を選択的に開始するステップと、 をさらに有することを特徴とする請求項2に記載の方法。
- 21SAEシステムからI-WLANへの順方向ハンドオーバーは、 認証手順の間に、前記UEが現在以前のアクセスシステムである既存のアクセスシステムの詳細を伝送し、コアネットワークによってセキュリティコンテキストとバッファリングされたコンテキストを以前アクセスシステムから検索し、以前アクセスシステムの詳細はEAPOL ID応答メッセージ内で伝送されるステップと、 前記コアネットワークによって、臨時IDを生成してUEに伝達し、前記UEは、認証手順中に最適化した認証のための速い再認証手順を開始し、UEとネットワークがCK及びIKを用いてキーを派生するステップと、 前記UEによって、最も最近に成功的に受信されたパケットシーケンス番号をI-WLANネットワークに伝送し、I-WLANネットワークは前記パケットをコアネットワークに伝送し、コアネットワークは前記UEによって最後に成功的に受信されたシーケンス番号以後のパケットを伝送し始めるステップと、 を含むことを特徴とする請求項2に記載の方法。
- 22I-WLANからUMTSアクセスシステムへの逆方向ハンドオーバーは、 前記UEとネットワークによって、最も最新のCK及びIKを利用し、UEはAKAA認証無しにRRC接続手順とSMC手順を始めるステップと、 ハンドオーバー準備段階でSMC手順を選択的に遂行するステップと、 ネットワークによって、支援されるアルゴリズムを伝送し、UEがアルゴリズムを選択して初期メッセージの保護を始めるステップをさらに含むことを特徴とする請求項2に記載の方法。
- 23I-WLANからUMTSアクセスシステムへの順方向ハンドオーバーは、 RAU手順中に、UEがRAUメッセージ内に以前アクセスシステムの詳細を伝送し、コアネットワークが既存及び現在の以前アクセスシステムからセキュリティコンテキスト及びバッファリングされたパケットを検索するステップをさらに含むことを特徴とする請求項2に記載の方法。
- 24異種ネットワークにおけるアクセスシステム間のハンドオーバー時に認証手順を最適化するシステムであって、 新たなシステムにアクセスするための新たなキーを派生する手段と、 既存システムから新たなシステムへのハンドオーバー時に、既存システムと共に使用される既存システムアクセスキーを用いて認証手順を最適化する手段と、 ユーザー端末が速い再認証を遂行可能にするハンドオーバー準備時に新たなシステムにアクセスするユーザー端末によって臨時IDを受信する手段と、 を含むことを特徴とするシステム。
Independent claims24
159 paragraphs, as filed
The present invention relates to heterogeneous systems, optimization of authentication procedures during handover between access systems, and key derivation methods for evolved systems, especially previous access. The present invention relates to a method of using a system key to generate a new key for ensuring communication with a new access system after the handover.
The 3GPP (3rd Generation Partnership Project) Radio Access Network (RAN), System Architecture (SA), and Core Terminal (CT) working groups have enhanced next-generation radio systems. ) The goal is to develop a UTRAN (E-UTRAN) structure. E-UTRAN systems are currently required to co-exist with 2nd and 3rd generation (3G) wireless systems, especially with existing systems as specified in the 3GPP TR 23.882, 3GPP TS 23.401, and 3GPP TS 23.402 standards. It is required to support handover with a newly evolved E-UTRAN system as done.
The E-UTRAN system is an evolved system of the 3GPP UTRAN system, and the main entities are UE (User Equipment), ENB (Enhanced Node B), MME (Mobility Management Entity), and UPE (User Plane) as shown in Fig. 1. Entity) and IASA (Inter Access System Anchor). The ENB of the E-UTRAN system must have the characteristics of Node B and the Radio Network Controller (RNC) of the legacy UTRAN system. The System Architecture Evolution (SAE) MME manages and stores UE contexts (UE / User Identity, UE Movement State, User Security Parameters when idle). In addition, MME generates temporary identities to be assigned to UE, and UE is TA or PLMN (Public Land Mobile). Check the authentication to see if it stays on the Network) and perform the user authentication. The SAE UPE terminates the downlink data path for the idle UE and triggers and initiates a paging when the downlink data arrives at the UE. The UPE also manages and stores UE contexts, such as IP (Internet Protocol) bearer services or network internal routing information, and performs replication of user traffic in the case of interception. The IASA is a user plane anchor for mobility between different access systems. This IASA performs or assists in handover between different access systems.
GERAN (GSM (Global System for Mobile Communication) / EDGE (Enhanced Data rates for Global Evolution) Radio Access Network) consists of a transmission / reception base station (Base Transceiver Station: BTS) and a base station controller (BSC). Will be done. UTRAN consists of Node B and Radio Network Controller (RNC). As shown in Fig. 1, the GPRS (General Packet Radio Service) core network consists of a Serving GPRS Support Node (SGSN) and a Gateway GPRS Support Node (GGSN).
The I-WLAN (Integrated Wireless Local Area Network) system specified in the 3GPP TS 23.234 standard provides a system and method for integrating an old UTRAN system with a WLAN system, as shown in Figure 2. The I-WLAN system allows WLAN users to access the 3GPP packet switching service.
However, currently no efficient mechanism has been presented to provide an authentication procedure during handover between heterogeneous access systems. Furthermore, no method has been presented for generating keys for evolved systems.
<p> Therefore, the present invention at least solves the above-mentioned problems and disadvantages of the prior art, and provides the following advantages. Therefore, an object of the present invention provides a method of optimizing an authentication procedure at the time of handover between access systems in a heterogeneous network. Another object of the present invention is to provide a system that optimizes the authentication procedure at the time of handover between access systems in a heterogeneous network. The present invention also provides a mechanism for generating a key specific to the SAE system.</p>
<p> In order to achieve the above object, the present invention is a method of optimizing the authentication procedure at the time of handover between access systems in a heterogeneous network, and derives a new key for accessing a new system. Steps, steps to optimize the authentication procedure using the existing system access key when handovering from an existing system to a new system, and accessing the new system when preparing for handover, allowing the UE to quickly reauthenticate with the new system. It is characterized by having a step of receiving a temporary ID (Identification) by the UE to enable the execution of the above.</p><p> Further, the present invention is a system that optimizes the authentication procedure at the time of handover between access systems in a heterogeneous network, and is a means for deriving a new key for accessing the new system and a new system from the existing system. A means of optimizing the authentication procedure using the existing system access key used with the existing system at the time of handover to, and a user accessing the new system at the time of handover preparation that enables the user terminal to perform fast re-authentication. It is characterized by including a means for receiving a temporary ID by a terminal.</p><p> The present invention includes a mechanism that provides an optimized authentication procedure at the time of handover by utilizing the active authentication key used in the second access system in the first access system. The present invention also includes a mechanism for performing fast reauthentication during the handover procedure. The present invention includes a mechanism for generating keys for systems that have evolved to ensure communication between UEs and network entities.</p><p> Furthermore, according to another aspect of the present invention, it is as follows. Optimizing network access authentication procedures during handover in heterogeneous network environments. To provide a mechanism for generating a new key for a new access system, instead of performing the access system's dependent authentication procedure, using the latest active key generated by the previous access system. .. To provide a mechanism for deriving new keys for both forward and reverse handovers. For exchanging keys, security contexts, and other messages through a logical interworking unit co-located with the network entity of the SAE system or I-WLAN interworking system or another entity of the SAE system or I-WLAN interworking system. To provide a signaling interface between MME / UPE and AAA (Authentication Authorization and Accounting) servers. Generating a key with an active EUTRAN network access key by UE and AAA servers for I-WLAN access and secure communication.</p><p> Generate keys (EAP-related keys, namely TEK, MSK and EMSK) from the SAE system or UMTS system to the I-WLAN system using the latest CK (Cypher Key) and IK (Integrity Key) at the handover preparation stage. This UE transmits the I-WLAN ID and NAI to the SAE system through the measurement report. The network entity of the SAE system includes the latest CK and IK along with other parameters in the handover (HandOver: hereinafter referred to as "HO") preparation request transferred to the I-WLAN interworking system. The UE and network can generate keys during the handover preparation phase.</p><p> During the I-WLAN attach procedure, when the UE moves from the SAE system to the I-WLAN system, if the UE and AAA server generate a key during the handover preparation stage, the WLAN-AN will send the UE to the AAA server. When requesting authentication, the I-WLAN network entity (AAA server) provides to transmit the MSK to the WLAN-AN without an EAP authentication procedure. In this way, the UE and I-WLAN AS can directly implement the IEEE (Institute of Electrical and Electronic Engineers) 802.11 specific handshake mechanism to initiate L2 (Layer 2) protections.</p><p> In the handover preparation phase, the AAA server transmits the I-WLAN-specific temporary ID, anonymous (pseudonym) and / or fast re-authentication ID (in the HO accept message / HO instruction message) to the UE. The UE may perform a fast reauthentication procedure during the initial handover from the SAE AS to the I-WLAN AS (when the network transmits a fast reauthentication ID and requires the UE to authenticate and refresh the key). it can. According to the present invention, the UE can transmit the sequence number of the last successfully received packet to the I-WLAN AS. The I-WLAN AS propagates the packet to the core network, which can begin transmitting packets after the last successfully received sequence number to the UE.</p><p> According to the present invention, the network is handed over from the SAE system or UMTS system to the I-WLAN system, while the UE lists scenario 2 and scenario 3 authentication procedures and assisted optimization procedures during the HO instruction. Can be instructed to carry out together. In this way, the UE can select and start one of the optimization procedures directly supported by the network, without any enforcement error method.</p><p> According to the present invention, the MME performs soft registration with the HSS at the HO preparation stage, and after the handover, the UE connects to the MME. The SGSN performs software registration with the HSS at the HO preparation stage, and after the handover, the UE connects to the SGSN.</p><p> According to the present invention, the AAA server performs software registration with the HSS in the HO preparation stage, and after the handover, the UE is connected to the AAA server. The security mode instruction procedure is carried out in the HO preparatory phase during the handover to the SAE system or UMTS system.</p><p> According to the present invention, the UE transmits an algorithm selected from the list of network assisted algorithms broadcasted by the network to the SAE system through a measurement report. The HO instruction allows the SAE system to agree / negotiate the UE selection algorithm and allow the UE to begin protecting the initial message during handover.</p><p> According to the present invention, the SGSN transmits the latest CK and IK to the MME or authentication and key management entity of the SAE system, which derives the SAE-specific key and pre-handover. Or distribute to SAE system entities at the time of handover.</p><p> According to the present invention, the MME converts LTE (Lon Term Evolution) related parameters into UMTS-specific parameters when an HO request is made from another AS or an HO request is made to another AS. The MME transmits the latest CK and IK to the SGSN, which distributes this key to the RNC (Radio Network Controller) when a handover preparation request is made from the SAE system.</p><p> According to the present invention, during the forward handover authentication procedure for UMTS AS, the UE transmits the details of the previous access system through the RAU procedure or the initial NAS message, and the core network is the security context (eg, eg) from the previous access system. Packets buffered with CK and IK) can be retrieved. During the forward handover authentication procedure to the I-WLAN AS, the UE previously transmits the details of the access system and the core network can retrieve the security context and buffered packets from the previously access system. Details of this earlier access system are transmitted through the EAPOL ID response message.</p><p> According to the present invention, the UE transmits the sequence number of the last successfully received packet to the access system, which previously transmitted this to the core network and was last successfully received by the UE. Packets after the sequence number can be started to be transmitted.</p><p> According to the present invention, when the UE and the network generate a key using UMTS CK and IK during the scenario 2 authentication procedure in I-WLAN AS, the core network generates a temporary ID and transmits it to the UE. The UE initiates a fast reauthentication procedure for scenario 3 access.</p><p> During the forward handover authentication procedure for the SAE AS, the UE transmits the details of the previous access system through the TAU procedure or the initial NAS message, and the core network is buffered with the security context (eg, CK and IK) from the previous access system. Search for ringed packets.</p>
Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the accompanying drawings. Below, it is clear to those who have ordinary knowledge in the art that various modifications are possible in the embodiments of the present invention without departing from the scope and spirit of the present invention. In addition, when it is determined that a specific description of a known function or configuration related to the present invention makes the gist of the present invention unclear, the detailed description thereof will be omitted.
The present invention provides a system and a method for providing an optimized authentication procedure at the time of handover between heterogeneous networks, and also provides a mechanism for generating a key unique to the SAE system. This method includes a mechanism for generating a new access system-specific key using the old access system key without performing an access system-specific authentication procedure.
FIG. 3 shows a reverse handover (scenario 2 access) from the SAE to the I-WLAN access system according to the present invention. Referring to FIG. 3, the UE transmits periodic or event-based measurements to the EUTRAN network in step 1. If the ENB (Evolving Node B) / MME (Mobility Management Entity) finds that the UE measurement is below the threshold, or if the MME determines that EUTRAN cannot be sustained by any method, then in step 2a, another RAT. You can ask the UE to start scanning (Radio Access Technology), or you can ask the UE to scan for a specific RAT available within the adjacent RAT or its coverage area. Also, by Layer 2 (L2) or other means, the UE determines that EUTRAN is unsustainable and initiates scanning of other RATs.
In step 3, the UE transmits the I-WLAN measurement report, including the I-WLAN ID and NAI, along with other parameters to the SAE system. The ENB / MME then decides to hand over the UE to the I-WLAN network itself or selectively by a logical interworking unit.
Using NAI (Network Address Identifier), MME analyzes the I-WLAN AAA server IP address in step 4 and connects to the AAA server through a logical interworking unit. This logical interworking unit can be located within the MME or AAA server, or simultaneously within the network entity of the SAE system or I-WLAN system. The function of the interworking unit is to convert the RAN and CN container / protocol / parameters of the first access system to the second access system.
In step 5, the MME transmits the HO request to the AAA server through the interworking unit. The HO request includes NAI, I-WLAN ID, unused AV (Authentication Vector), latest CK and IK and other parameters.
The AAA checks the HSS to see if another AAA has been registered with the HSS (Home Subscription Service), and if not, performs a soft registration in step 6. AAA uses NAI, CK and IK to generate / derive keys (MSK, TEK and EMSK). In addition, the AAA server generates a Temp ID (anonymous (pseudonym) ID and fast re-authentication ID), protects (encrypts) the Temp ID using the generated TEK, and transmits it to the UE.
In step 7, the AAA server transmits the HO approval to the MME through the interworking unit. The HO approval message includes a protected Temp ID and an indication of whether Scenario 2 and Scenario 3 authentication was requested. In step 8, the MME transmits the parameters received through the HO approval message to the UE as an HO instruction message.
After receiving the HO instruction from the SAE system for handover to the I-WLAN network, the UE generated and protected keys (MSK, TEK and EMSK) using the latest CK and IK in step 9. Decrypt the Temp ID. At step 10, the UE initiates an L2 attachment with the I-WLAN AS.
When the I-WLAN system requests authentication, the WLAN-AN initiates the authentication procedure in step 11a.1. Then, in step 11a.2, the UE transmits the Temp ID (fast re-authentication ID) when the Temp ID is received through the HO instruction. The UE transmits EAP response identification, including protection of Temp ID (anonymous ID or fast reauthentication ID) and optionally integrity of the EAP response identification message, to the AAA server through I-WLAN AN.
When the AAA server receives the EAP response identification message with the Temp ID, the AAA becomes aware that the UE has performed HO preparation. The AAA server verifies integrity protection and Temp ID in step 11a.3. Therefore, AAA authenticates the UE. Optionally, if the AAA server was previously requested to use a protected success result display, the MAC (Medium Access Control) protected message EAP request / AKA notification (Notification) prior to the EAP success message. ) Can be transmitted. The AAA server generates a new Temp ID and transmits it to the UE along with the EAP request / AKA notification message. The WLAN AN propagates the EAP request / AKA notification message to the UE, which sends the EAP response / AKA notification. The WLAN AN transmits EAP response / AKA notification messages to the AAA server, which ignores the contents of these messages.
The AAA server transmits the EAP success message to the WLAN AN in step 11a.4. When some extra keying material is generated for the protection of WLAN technology-specific confidentiality and / or integrity, the AAA server uses this keying element as an underlying AAA protocol message (ie, EAP). Include in (not level). The I-WLAN AN stores the keying elements used to communicate with the authenticated WLAN-UE. If the AAA server is not using the protected successful result display, the AAA server will generate a new Temp ID and send it to the UE along with the EAP success message.
The I-WLAN AN informs the WLAN-UE through an EAP success message regarding successful authentication in step 11a.5. At this time, the EAP AKA exchange is completed successfully, and the WLAN-UE and I-WLAN AN share the keying elements generated during this exchange. Alternatively, in step 11b, the UE initiates a fast reauthentication procedure with the I-WLAN network. If the UE does not receive a fast reauthentication ID, the UE transmits an anonymous ID to initiate the global authentication procedure.
FIG. 4 shows a reverse handover (scenario 2 and scenario 3 access) from the SAE to the I-WLAN access system according to the present invention. Referring to FIG. 4, the UE transmits periodic or event-based measurements to the EUTRAN network in step 1.
If the ENB / MME finds that the UE reading is below the threshold, or if the MME determines that EUTRAN cannot be sustained in any way, it requires the UE to start scanning other RATs in step 2a. Alternatively, the UE can be requested to scan for a specific RAT available within the adjacent RAT or its service area. Also, by L2 or other means, the UE determines that EUTRAN is unsustainable and initiates scanning of other RATs.
In step 3, the UE transmits the I-WLAN measurement report, including the I-WLAN ID and NAI, along with other parameters to the SAE system. The ENB / MME then decides to hand over the UE to the I-WLAN network.
Using NAI, MME analyzes the I-WLAN AAA server IP address and connects to the AAA server through a logical interworking unit in step 4. This logical interworking unit can be located within the MME or AAA server, or simultaneously within the network entity of the SAE system or I-WLAN system. The function of the interworking unit is to convert the RAN and CN container / protocol / parameters of the first access system to the second access system.
In step 5, the MME transmits the HO request to the AAA server through the interworking unit. The HO request includes NAI, I-WLAN ID, unused AV, latest CK and IK and other parameters.
In step 6, the AAA checks the HSS to see if another AAA has been registered with the HSS, and if not, the AAA performs the soft registration. AAA uses NAI, CK and IK to generate keys (MSK, TEK and EMSK). In addition, the AAA server generates a Temp ID (anonymous ID and fast re-authentication ID), protects (encrypts) the Temp ID using the generated TEK, and transmits it to the UE.
The AAA server transmits the HO approval to the MME through the interworking unit in step 7. The HO approval message includes a protected Temp ID and an indication of whether Scenario 2 and Scenario 3 authentication was requested. The AAA server also includes in the HO approval an optimization procedure that is assisted for UEs that perform Scenario 2 and Scenario 3 in succession.
In step 8, the MME transmits the received parameter as an HO instruction message to the UE through the HO approval message. After receiving the HO instruction from the SAE system for handover to the I-WLAN network, the UE generated and protected keys (MSK, TEK and EMSK) using the latest CK and IK in step 9. Decrypt Temp ID (anonymous ID and fast reauthentication ID). At step 10, the UE initiates an L2 connection with the I-WLAN AS.
When the I-WLAN system requests authentication, the WLAN-AN initiates the authentication procedure in step 11a.1. The UE then transmits the Temp ID (Fast Reauthentication ID) when received through the HO instruction in step 11a.2. The UE transmits EAP response identification, including Temp ID (anonymous ID or fast reauthentication ID) and optionally integrity protection of the EAP response identification message, to the AAA server through the I-WLAN AN.
When the AAA server receives the EAP response identification message with the Temp ID, the AAA becomes aware that the UE has performed HO preparation. The AAA server verifies integrity protection and Temp ID in step 11a.3. Therefore, AAA authenticates the UE. Optionally, if the AAA server is previously requested to use a protected success result display, it can send a MAC-protected message EAP request / AKA notification prior to the EAP success message. The AAA server generates a new Temp ID and transmits it to the UE along with the EAP request / AKA notification message. The WLAN AN propagates the EAP request / AKA notification message to the UE, which transmits the EAP response / AKA notification. The WLAN AN transmits EAP response / AKA notification messages to the AAA server, which ignores the contents of these messages.
The AAA server transmits the EAP success message to the WLAN AN in step 11a.4. When some extra keying elements are generated for the protection of WLAN technology-specific confidentiality and / or integrity, the AAA server includes these keying elements in the base AAA protocol message (ie, not at the EAP level). The I-WLAN AN stores the keying elements used to communicate with the authenticated WLAN-UE. If the AAA server is not using the protected successful result display, the AAA server will generate a new Temp ID and send it to the UE along with the EAP success message.
I-WLAN AN informs WLAN-UE with an EAP success message regarding successful authentication in step 11a.5. At this time, the EAP AKA exchange is completed successfully, and the WLAN-UE and I-WLAN AN share the keying elements generated during this exchange.
Alternatively, the UE initiates a fast reauthentication procedure with the I-WLAN network in step 11b. If the UE does not receive a fast reauthentication ID, the UE transmits an anonymous ID to initiate the global authentication procedure.
After a successful scenario 2 authentication procedure, the UE initiates an optimized authentication procedure for scenario 3 listed by the AAA server in the HO instruction in step 12a. The UE can initiate the Scenario 3 authentication procedure using the EMSK-based optimization procedure. The UE can also initiate a quick re-authentication procedure for the scenario 3 authentication procedure in step 12b.
FIG. 5 shows a reverse handover (direct scenario 3 access) from the SAE to the I-WLAN access system according to the present invention. Referring to FIG. 5, the UE transmits periodic or event-based measurements to the EUTRAN network in step 1.
If the ENB / MME finds that the UE reading is below the threshold, or if the MME determines that EUTRAN cannot be sustained in any way, it requires the UE to start scanning other RATs in step 2. Alternatively, the UE can be requested to scan for a specific RAT available within the adjacent RAT or its service area. Also, by L2 or other means, the UE determines that EUTRAN is unsustainable and initiates scanning of other RATs.
In step 3, the UE transmits the I-WLAN measurement report, including the I-WLAN ID and NAI, along with other parameters to the SAE system. The ENB / MME then decides to hand over the UE to the I-WLAN network.
Using NAI, MME analyzes the I-WLANAAA server IP address and connects to the AAA server through a logical interworking unit in step 4. This logical interworking unit can be located within the MME or AAA server, or simultaneously within the network entity of the SAE system or I-WLAN system. The function of the interworking unit is to convert the RAN and CN container / protocol / parameters of the first access system to the second access system.
In step 5, the MME transmits the HO request to the AAA server through the interworking unit. The HO request includes NAI, I-WLAN ID, unused AV, latest CK and IK and other parameters.
AAA will check the HSS to see if another AAA has been registered with the HSS, otherwise AAA will carry out the soft registration. AAA uses NAI, CK and IK to generate keys (MSK, TEK and EMSK). The AAA server also generates a Temp ID (anonymous ID and fast re-authentication ID) and uses this generated TEK to protect (encrypt) the Temp ID. Then, AAA transmits the above Temp ID to the UE.
The AAA server transmits the HO approval to the MME through the interworking unit in step 7. The HO approval message includes a protected Temp ID and an indication of whether Scenario 2 and Scenario 3 authentication was requested. The AAA server also includes in HO approval an optimization procedure that is assisted for UEs that perform Scenario 2 and Scenario 3 in succession.
In step 8, the MME transmits the received parameter as an HO instruction message to the UE through the HO approval message. After receiving the HO instruction from the SAE system for handover to the I-WLAN network, the UE generated and protected keys (MSK, TEK and EMSK) using the latest CK and IK in step 9. Decrypt the Temp ID. At step 10, the UE initiates an L2 connection with the I-WLAN AS.
After a successful connection with the I-WLAN AN, the UE initiates an optimized authentication procedure for scenario 3 listed by the AAA server on the HO instruction in step 11a. The UE can initiate the Scenario 3 authentication procedure using the EMSK-based optimization procedure. The UE can selectively initiate a fast re-authentication procedure for the Scenario 3 authentication procedure in step 11b.
Forward handover from SAE to I-WLAN AS: During the authentication procedure, the UE can transmit previously access system details, thereby allowing the core network to retrieve packets buffered with the security context from the previous access system. Modern access system details can be transmitted within the EAPOL ID response message.
Scenario 2 During the authentication procedure, when the UE and network generate a key using CK and IK, the core network generates a Temp ID and communicates it to the UE. The UE can begin a fast reauthentication procedure for scenario 3 access.
The UE transmits the sequence number of the last successfully received packet to the I-WLAN network, which can transmit this sequence number to the core network. The core network then begins to propagate packets after the last successfully received sequence number by the UE.
FIG. 6 shows a reverse handover (Alternative 1) from the I-WLAN to the SAE system according to the present invention. Referring to FIG. 6, the UE transmits periodic or event-based measurements to the logical decision and interworking unit in step 1. This logical decision and interworking unit can be located within the MME or AAA server, or as a separate entity, or simultaneously within the network entity of the SAE system or I-WLAN system. The function of the decision and interworking unit is to convert the RAN and CN container / protocol / parameters of the first access system to the second access system and determine whether to perform HO based on the above measurements.
If the logical decision and interworking unit finds that the UE reading is below the threshold and determines that the I-WLAN is unsustainable by other means, the logical decision and interworking unit decides step 2 You can request the UE to start scanning for other RATs, or the ENB / MME can request the UE to scan adjacent RATs, or specific RATs available within its service area. Also, by L2 or some other means, the UE determines that I-WLAN is unsustainable and begins scanning other RATs.
In step 3, the UE transmits a SAE measurement report containing the TAI, selected UIA and UEA, ENB-ID and optionally the START value to the logical decision and interworking unit through the AAA server. Then, in step 4, the logical decision and interworking unit decides to hand over the UE to the SAE network and informs the AAA server of this. Using TAI, the AAA server will know the MME address by connecting to the HSS.
In step 6, the AAA server transmits the HO request message to the MME / UPE. The HO request message includes the previous RAT type, unused AV, latest CK and IK, optionally ENB-ID and other parameters. The MME checks the HSS to see if another MME has been registered with the HSS, and if not, performs the software registration in step 7. MME also generates a key.
In step 8, the MME transmits the HO approval to the AAA server through the interworking unit. This HO approval message contains information and other parameters regarding the selected UEA and UIA, selectively initiating FRESH and RAN protection. The AAA server transmits the parameters received through the HO approval message in step 9 to the UE through the HO instruction message.
After receiving the HO instruction from the AAA server for handover to the SAE network, the UE causes the SAE system to generate a unique key in step 10 using the latest CK and IK. The UE initiates an L2 connection with the ENB in step 11 without any protection.
The UE transmits an initial layer 3 (L3) message to the MME / UPE in step 12. Initial L3 messages include user identification, START value and MAC-I<sub>NAS</sub>including. This MAC-I<sub>NAS</sub>Is calculated using the generated SAE-specific key and optionally the FRESH and START values.
The MME / UPE verifies MAC-I using the generated key, the received START, and selectively the FRESH value in step 13. The MME / UPE transmits an initial L3 message response containing keys for ENB, START, selectively FRESH and agreed UEA and UIA. MME will MAC-I through the initial L3 message response excluding keys to ENB, START, selectively FRESH and agreed UEA and UIA.<sub>NAS</sub>To calculate.
ENB receives the initial L3 message response and stores the keys for START, selectively FRESH and the agreed UEA and UIA. ENB propagates the initial L3 message response to the UE. Optionally, ENB is RAN security (MAC-I)<sub>RAN</sub>) Can be started. UE is MAC-I<sub>NAS</sub>And MAC-I<sub>RAN</sub>To verify.
FIG. 7 shows a reverse handover (Alternative 2) from the I-WLAN to the SAE system according to the present invention. Referring to FIG. 7, the UE transmits periodic or event-based measurements to the logical decision and interworking unit in step 1. This logical decision and interworking unit can be located within the MME or AAA server, or as a separate entity, or simultaneously within the network entity of the SAE system or I-WLAN system. The function of the decision and interworking unit is to convert the RAN and CN container / protocol / parameters of the first access system to the second access system and determine whether to perform HO based on the above measurements.
If the logical decision and interworking unit finds that the UE reading is below the threshold and determines that the I-WLAN is unsustainable by other means, the logical decision and interworking unit decides step 2 You can request the UE to start scanning for other RATs, or the ENB / MME can request the UE to scan adjacent RATs, or specific RATs available within its service area. Also, by L2 or some other means, the UE determines that I-WLAN is unsustainable and begins scanning other RATs.
In step 3, the UE transmits a SAE measurement report containing the TAI, selected UIA and UEA, ENB-ID and optionally the START value to the logical decision and interworking unit through the AAA server. The logical decision and interworking unit then decides to hand over the UE to the SAE network and informs the AAA server of this. Using TAI, the AAA server will know the MME address by connecting to the HSS in step 5.
In step 6, the AAA server transmits the HO request message to the MME / UPE. The HO request message includes the previous RAT type, unused AV, latest CK and IK, optionally ENB-ID and other parameters. In step 7, the MME checks the HSS to see if another MME has been registered with the HSS, and if not, performs the software registration. In addition, MME generates a key using CK and IK by the AAA server.
In step 8, the MME uses the ENB-ID to generate a FRESH and distributes the security context to the ENB. In step 9, the MME transmits the HO approval to the AAA server through the interworking unit. The HO approval message contains information and other parameters regarding the selected UEA and UIA, and whether to selectively initiate FRESH and RAN protection.
In step 10, the AAA server transmits the parameters received through the HO approval message to the UE through the HO instruction message. After receiving the HO instruction from the AAA server for handover to the SAE network, the UE in step 11 generates a key specific to the SAE system using the latest CK and IK and begins RAN protection.
The UE initiates an L2 connection with ENB in step 12. The UE begins protecting RRC messages. During the initial message to ENB, the UE propagates the START value and uses the generated SAE-specific key, optionally FRESH and START value, to MAC-I.<sub>RAN</sub>To calculate. ENB then MAC-I with the START value using the security context received in step 8.<sub>RAN</sub>To verify.
The UE transmits the initial L3 message to the MME / UPE in step 13. Initial L3 messages include user identification, START value and MAC-I<sub>NAS</sub>including. This MAC-I<sub>NAS</sub>Is calculated using the generated SAE-specific key and optionally the FRESH and START values.
MME / UPE in step 14 MAC-I using the generated key, the received START, and optionally the FRESH value.<sub>NAS</sub>To verify. The MME / UPE transmits the initial L3 message response. MME is MAC-I through the initial L3 message response<sub>NAS</sub>To calculate.
Forward handover from I-WLAN to SAE system: During the TAU procedure or initial NAS message, the UE transmits the details of the previously access system within the TAU procedure, and the core network searches the previously access system for packets buffered with the security context (CK and IK). Can be done.
FIG. 8 shows a reverse handover from UMTS to a SAE system according to the present invention. Referring to FIG. 8, the UE transmits periodic or event-based measurements to the SGSN in step 1. Based on the measurement report, the SGSN in step 2 requires the UE to start scanning for other RATs, or the ENB / MME to scan adjacent RATs or specific RATs available in their service area. Can be requested. Alternatively, by L2 or other means, the UE determines that UMTS is unsustainable and begins scanning for other RATs.
In step 3, the UE transmits a SAE measurement report containing the TAI, the selected UIA and UEA, and optionally the START value and / or ENB ID to the SGSN. The SGSN then decides to hand over the UE to the SAE network. Using TAI, SGSN will know the MME address in step 4, use the S3 or S4 interface, connect to HSS, or connect to MME through other methods.
The SGSN transmits the HO request message to the MME / UPE in step 5. The HO request message includes the security context, previously RAT type, unused AV, latest CK and IK, and optionally ENB-ID, START value, KSI and other parameters.
In step 6, the MME checks the HSS to see if the MME has been registered with the HSS, otherwise the MME will register the software. The MME uses the CK and IK transmitted by the SGSN to generate the key. MMEs convert UMTS parameters to SAE-specific parameters using logical interworking units that can be located within the MME or AAA server, or simultaneously within the network entities of the SAE or I-WLAN system. .. The function of the interworking unit translates the RAN and CN containers / protocols / parameters of one access system into another.
In step 7, the MME generates a FRESH and sends the security context with the ENB-ID, including the ENB key for RAN protection, the selected UIA and UEA, FRESH, START, KSI, and other parameters to the ENB. Distribute.
In step 8, the MME transmits the HO approval to the SGSN. The HO approval message contains the selected UEA and UIA, optionally FRESH. In step 9, the SGSN transmits the parameters received through the HO approval message to the UE through the HO instruction message. After receiving the HO instruction from the SGSN for handover to the SAE network, the UE in step 10 generates a key specific to the SAE system using the latest CK and IK and begins RAN protection.
The UE initiates an L2 connection with ENB in step 11. The UE selectively begins protecting RRC messages. During the initial message to ENB, the UE propagates the START value and uses the generated SAE-specific key, optionally FRESH and START value, to MAC-I.<sub>RAN</sub>To calculate. ENB then MAC-I with the START value using the security context received in step 8.<sub>RAN</sub>To verify.
The UE transmits the initial L3 message to the MME / UPE in step 12. Initial L3 messages include user identification, START value and MAC-I<sub>NAS</sub>including. This MAC-I<sub>NAS</sub>Is calculated using the generated SAE-specific key and optionally the FRESH and START values.
The MME / UPE validates MAC-I using the generated key, the received START, and selectively the FRESH value in step 13. The MME / UPE transmits the initial L3 message response in step 14. MME is MAC-I through the initial L3 message response<sub>NAS</sub>To calculate.
Forward Handover from UMTS to SAE System: During the TAU procedure or initial NAS message, the UE transmits the details of the previously access system and the core network can retrieve the packets buffered with the security context (CK and IK) from the previously access system.
FIG. 9 shows a reverse handover from SAE to UMTS system according to the present invention. Referring to FIG. 9, the UE transmits periodic or event-based measurements to the ENB / MME in step 1.
Based on the measurement report, ENB / MME requests the UE to start scanning other RATs in step 2, or ENB / MME scans the adjacent RATs or specific RATs available for their service area. Can be requested from the UE. Alternatively, by L2 or other means, the UE determines that EUTRAN is unsustainable and begins scanning other RATs.
In step 3, the UE transmits a UMTS measurement report containing RAI, supported UIA and UEA, KSI and START value and cell ID to ENB / MME. SGSN then decides to hand over the UE to the UMTS network in step 4. Using RAI, MME becomes aware of the SGSN address and uses the S3 or S4 interface, connects to HSS, or connects to SGSM through known methods.
The MME transmits the HO request message to the SGSN in step 5. The HO request message includes the security context, previously RAT type, unused AV, latest CK and IK, and optionally cell ID, START value, KSI and other parameters. The MME sets the SAE parameters to UMTS using a logical interworking unit that can be placed within the MME or SGSN, or as a separate network entity, or simultaneously within the network entity of the SAE or UMTS system. Convert to unique parameters. The function of the interworking unit converts the RAN and CN container / protocol / parameters of the first access system to the second access system.
This SGSN confirms the HSS in step 6 to see if the SGSN has been registered with the HSS, otherwise it will perform the software registration.
In step 7, the SGSN generates a FRESH and uses the cell ID to transmit a security context to the RNC containing the key for protection, the selected UIA and UEA, FRESH, START, KSI and other parameters. RNC stores the received parameters.
The SGSN transmits the HO approval to the MME in step 8. The HO approval message contains the selected UEA and UIA, and optionally FRESH. In step 9, the MME communicates the parameters received through the HO approval message to the UE through the HO instruction message.
After receiving the HO instruction from the MME for handover to the UMTS network, the UE selectively initiates RAN protection in step 10 utilizing the latest CK and IK for the UMTS network. The UE initiates an L2 connection with the RNC in step 11. The UE selectively begins to protect RRC messages. During the initial message to the RNC, the UE carries the START value.
In step 12, the UE transmits the initial L3 message to the SGSN. The initial L3 message contains user identification, START value, KSI and MAC-I. The RNC verifies the MAC-I in step 13 and transmits it to the SGSN in step 14.
Forward Handover from SAE to UMTS System: During the RAU procedure or the first NAS message, the UE may transmit last / previous access system details and the core network may retrieve packets buffered with the security context (CK and IK) from the previous access system. it can.
FIG. 10 shows a reverse handover (scenario 2 access) from UMTS to an I-WLAN access system according to the present invention. Referring to FIG. 10, the UE transmits periodic or event-based measurements to the UTRAN network in step 1.
If the RNC / SGSN finds that the UE reading is below the threshold, or if the SGSN determines that EUTRAN cannot be sustained in any way, it requires the UE to start scanning other RATs in step 2. Alternatively, the UE can be requested to scan for a specific RAT available within the adjacent RAT or its service area. Also, by L2 or other means, the UE determines that UTRAN is unsustainable and initiates scanning of other RATs.
In step 3, the UE transmits the I-WLAN measurement report, including the I-WLAN ID and NAI, along with the other parameters to the SGSN. The SGSN then decides to hand over the UE to the I-WLAN network.
Using NAI, SGSN analyzes the I-WLAN AAA server IP address and connects to the AAA server through a logical interworking unit in step 4. This logical interworking unit can be located within the SGSN or AAA server, or as a separate network entity. Alternatively, they can be placed simultaneously within a network entity in a UMTS or I-WLAN system. The function of the interworking unit is to convert the RAN and CN container / protocol / parameters of the first access system to the second access system.
The SGSN transmits the HO request to the AAA server through the interworking unit in step 5. The HO request includes NAI, I-WLAN ID, unused AV, latest CK and IK and other parameters.
The AAA checks the HSS to see if another AAA has been registered with the HSS, otherwise the AAA will perform the soft registration in step 6. AAA uses NAI, CK and IK to generate keys (MSK, TEK and EMSK) and Temp IDs (anonymous IDs and fast reauthentication IDs). The AAA server protects (encrypts) the Temp ID using the generated TEK and transmits it to the UE.
In step 7, the AAA server transmits the HO approval to the SGSN through the interworking unit. The HO approval message includes a protected Temp ID and an indication of whether Scenario 2 and Scenario 3 authentication was requested. In step 8, the SGSN transmits the parameters received through the HO approval message to the UE as an HO instruction message.
After receiving the HO instruction from the UMTS system for handover to the I-WLAN network, the UE generated and protected keys (MSK, TEK and EMSK) using the latest CK and IK in step 9. Decrypt Temp ID (anonymous ID or fast reauthentication ID).
The UE initiates an L2 connection with the I-WLAN AS in step 10. When the I-WLAN system requests authentication, the WLAN-AN initiates the authentication procedure in step 11a.1.
The UE then transmits the Temp ID (Fast Reauthentication ID) when received through the HO instruction in step 11a.2. The UE transmits EAP response identification, including protection of Temp ID (anonymous ID or fast reauthentication ID) and integrity of the EAP response identification message, to the AAA server through I-WLAN AN.
When the AAA server receives the EAP response identification message with the Temp ID, the AAA becomes aware that the UE has performed HO preparation. The AAA server verifies integrity protection and Temp ID in step 11a.3. Therefore, AAA authenticates the UE. The AAA server selectively sends a MAC-protected message EAP request / AKA notification prior to the EAP success message if the AAA server was previously requested to use a protected success result display. be able to. The AAA server generates a new Temp ID and transmits it to the UE along with the EAP request / AKA notification message. The WLAN AN propagates the EAP request / AKA notification message to the UE. The UE transmits the EAP response / AKA notification. The WLAN AN transmits EAP response / AKA notification messages to the AAA server, which ignores the contents of these messages.
The AAA server transmits the EAP success message to the WLAN AN in step 11a.4. When some extra keying elements are generated for the protection of WLAN technology-specific confidentiality and / or integrity, the AAA server includes these keying elements in the base AAA protocol message (ie, not at the EAP level). The I-WLAN AN stores the keying elements used to communicate with the authenticated WLAN-UE. If the AAA server is not using the protected successful result display, the AAA server will generate a new Temp ID and send it to the UE along with the EAP success message.
I-WLAN AN informs WLAN-UE with an EAP success message regarding successful authentication in step 11a.5. At this time, the EAP AKA exchange is completed successfully, and the WLAN-UE and I-WLAN AN share the keying elements generated during this exchange.
Alternatively, in step 11b, the UE initiates a fast reauthentication procedure with the I-WLAN network. If the UE does not receive a fast reauthentication ID, the UE transmits an anonymous ID to initiate the global authentication procedure.
FIG. 11 shows a reverse handover (scenario 2 and scenario 3 access) from UMTS to an I-WLAN access system according to the present invention. Referring to FIG. 11, the UE transmits periodic or event-based measurements to the EUTRAN network in step 1.
If the RNC / SGSN finds that the UE reading is below the threshold, or if the SGSN determines that EUTRAN cannot be sustained in any way, it either requires the UE to start scanning other RATs, or an adjacent RAT. Alternatively, the UE can be requested to scan for specific RATs available within its service area. Also, by L2 or other means, the UE determines that UTRAN is unsustainable and initiates scanning of other RATs.
In step 3, the UE transmits the I-WLAN measurement report, including the I-WLAN ID and NAI, along with the other parameters to the SGSN. The SGSN then decides to hand over the UE to the I-WLAN network.
Using NAI, SGSN analyzes the I-WLAN AAA server IP address and connects to the AAA server through a logical interworking unit in step 4. This logical interworking unit can be located within an SGSN or AAA server, in a separate network entity, or simultaneously in a network entity in a UMTS or I-WLAN system. The function of the interworking unit is to convert the RAN and CN container / protocol / parameters of one access system to another access system.
The SGSN transmits the HO request to the AAA server through the interworking unit in step 5. The HO request includes NAI, I-WLAN ID, unused AV, latest CK and IK and other parameters.
AAA will check the HSS to see if another AAA has been registered with the HSS, otherwise AAA will carry out the soft registration. AAA uses NAI, CK and IK to generate keys (MSK, TEK and EMSK). In addition, the AAA server generates a Temp ID (anonymous ID and fast re-authentication ID), protects (encrypts) the Temp ID using the generated TEK, and transmits it to the UE.
The AAA server transmits the HO approval to the SGSN through the interworking unit in step 7. The HO approval message includes a protected Temp ID and an indication of whether Scenario 2 and Scenario 3 authentication was requested. The AAA server also includes in HO approval an optimization procedure that is assisted for UEs that perform Scenario 2 and Scenario 3 in succession.
In step 8, the SGSN transmits the parameters received through the HO approval message to the UE as an HO instruction message. After receiving the HO instruction from the UMTS system for handover to the I-WLAN network, the UE generated and protected keys (MSK, TEK and EMSK) using the latest CK and IK in step 9. Decrypt the Temp ID.
The UE initiates an L2 connection with the I-WLAN AS in step 10. When the I-WLAN system requests authentication, the WLAN-AN initiates the authentication procedure in step 11a.1.
The UE then transmits the Temp ID (Fast Reauthentication ID) when received through the HO instruction in step 11a.2. The UE transmits EAP response identification, including protection of Temp ID (anonymous ID or fast reauthentication ID) and integrity of the EAP response identification message, to the AAA server through I-WLAN AN.
When the AAA server receives the EAP response identification message with the Temp ID, the AAA becomes aware that the UE has performed HO preparation. The AAA server verifies integrity protection and Temp ID in step 11a.3. Therefore, AAA authenticates the UE. Optionally, if the AAA server was previously requested to use a protected success result display, it can send a MAC-protected message EAP request / AKA notification prior to the EAP success message. The AAA server generates a new Temp ID and transmits it to the UE along with the EAP request / AKA notification message. The WLAN AN propagates the EAP request / AKA notification message to the UE. The UE transmits the EAP response / AKA notification. The WLAN AN transmits EAP response / AKA notification messages to the AAA server, which ignores the contents of these messages.
The AAA server transmits the EAP success message to the WLAN AN in step 11a.4. When some extra keying elements are generated for the protection of WLAN technology-specific confidentiality and / or integrity, the AAA server includes these keying elements in the base AAA protocol message (ie, not at the EAP level). The I-WLAN AN stores the keying elements used to communicate with the authenticated WLAN-UE. If the AAA server is not using the protected successful result display, the AAA server will generate a new Temp ID and send it to the UE along with the EAP success message.
I-WLAN AN informs WLAN-UE with an EAP success message regarding successful authentication in step 11a.5. At this time, the EAP AKA exchange is completed successfully, and the WLAN-UE and I-WLAN AN share the keying elements generated during this exchange.
Also, in step 11b, the UE initiates a fast reauthentication procedure with the I-WLAN network. If the UE does not receive a fast reauthentication ID, the UE transmits an anonymous ID to initiate the global authentication procedure.
After a successful scenario 2 authentication procedure, the UE initiates an optimized authentication procedure for scenario 3 listed by the AAA server in the HO instruction in step 12a. The UE can initiate the Scenario 3 authentication procedure using the EMSK-based optimization procedure. The UE can also initiate a quick re-authentication procedure for the scenario 3 authentication procedure in step 12b.
FIG. 12 shows a reverse handover (scenario 3 access) from UMTS to an I-WLAN access system according to the present invention. Referring to FIG. 12, the UE transmits periodic or event-based measurements to the UTRAN network in step 1.
If the RNC / SGSN finds that the UE reading is below the threshold, or if the SGSN determines that EUTRAN cannot be sustained in any way, it requires the UE to start scanning other RATs in step 2. Alternatively, the UE can be requested to scan for a specific RAT available within the adjacent RAT or its service area. Also, by L2 or other means, the UE determines that UTRAN is unsustainable and initiates scanning of other RATs.
In step 3, the UE transmits the I-WLAN measurement report, including the I-WLAN ID and NAI, along with the other parameters to the SGSN. The SGSN then decides to hand over the UE to the I-WLAN network.
Using NAI, SGSN analyzes the I-WLAN AAA server IP address and connects to the AAA server through a logical interworking unit in step 4. This logical interworking unit can be located within an SGSN or AAA server, in a separate network entity, or simultaneously within a network entity in a UMTS or I-WLAN system. The function of the interworking unit is to convert the RAN and CN container / protocol / parameters of one access system to another access system.
The SGSN transmits the HO request to the AAA server through the interworking unit in step 5. The HO request includes NAI, I-WLAN ID, unused AV, latest CK and IK and other parameters.
In step 6, the AAA checks the HSS to see if another AAA has been registered with the HSS, and if not, performs the software registration. AAA uses NAI, CK and IK to generate / derivative keys (MSK, TEK and EMSK). In addition, the AAA server generates a Temp ID (anonymous ID and fast re-authentication ID), protects (encrypts) the Temp ID using the generated TEK, and transmits it to the UE.
The AAA server transmits the HO approval to the SGSN through the interworking unit in step 7. The HO approval message includes a protected Temp ID (anonymous ID and fast reauthentication ID) and an indication of whether Scenario 2 and Scenario 3 authentication was requested. The AAA server also includes in the HO approval an optimization procedure that is assisted for UEs that perform Scenario 2 and Scenario 3 in succession.
In step 8, the SGSN transmits the parameters received through the HO approval message to the UE as an HO instruction message. After receiving the HO instruction from the UMTS system for handover to the I-WLAN network, the UE generated and protected keys (MSK, TEK and EMSK) using the latest CK and IK in step 9. Decrypt Temp (anonymous ID and fast reauthentication ID) ID.
The UE initiates an L2 connection with the I-WLAN AS in step 10. After a successful connection with the I-WLAN AN, the UE initiates an optimized authentication procedure for scenario 3 listed by the AAA server on the HO instruction in step 11a. The UE can initiate the Scenario 3 authentication procedure using the EMSK-based optimization procedure. The UE can selectively initiate a fast re-authentication procedure for the Scenario 3 authentication procedure in step 11b.
Forward handover from SAE system to I-WLAN AS: During the authentication procedure, the UE can transmit previously access system details, thereby allowing the core network to retrieve packets buffered with the security context from the previous access system. Modern access system details can be transmitted within the EAPOL ID response message.
Scenario 2 During the authentication procedure, when the UE and network generate a key using CK and IK, the core network generates a Temp ID and communicates it to the UE. The UE can begin a fast reauthentication procedure for scenario 3 access.
The UE transmits the sequence number of the last successfully received packet to the I-WLAN network. The I-WLAN network can propagate this sequence number to the core network. The core network then begins to propagate packets after the last successfully received sequence number by the UE.
Reverse Handover from I-WLAN to UMTS Access System: UEs and networks can selectively use the latest CK and IK. This UE initiates RRC connection and SMC procedures without AKA certification. Also, the SMC procedure can be carried out during the HO preparatory stage. With the HO instruction, the network transmits the supported algorithm, and the UE selects the algorithm and begins initial message protection.
Forward Handover from I-WLAN to UMTS Access System: During the RAU procedure, the UE transmits previously access system details through RAU messages, allowing the core network to retrieve packets buffered with the security context (CK and IK) from the previously access system.
Key Generation for SAE Systems-Alternative 1: as shown in Figure 13. As shown in Figure 13, 9AV is generated by UE and HSS. The functions f6, f7, f8, f9 are new key derived functions for LTE / SAE systems. When the MME requests n 9AVs, the HSS transmits the above AVs to the MME in order to authenticate and secure LTE / SAE capable UE communication.
Security context transmission from LTE / SAE to other RATs is shown as <Formula 1> or <Formula 2> below.
<maths num="1"><img file="JP2009531952A_D0001.tif" /></maths>
Or
<maths num="2"><img file="JP2009531952A_D0002.tif" /></maths>
Here, CK represents a encryption key (Cypher Key), and IK represents an integrity key or an AV key from HSS. Security context transmission from other RATs to LTE / SAE is shown as <Formula 3>.
<maths num="3"><img file="JP2009531952A_D0003.tif" /></maths>
Here, CK represents an encryption key and IK represents an integrity key. The above keys are derived from UE and MME. When MME and UPE are combined, the functions F8 and F9 are not provided and CK<sub>NAS</sub>And IK<sub>NAS</sub>Is used for NAS signal protection and user plane protection. Security context transmission from LTE / SAE to other RATs is shown as <Formula 4>.
<maths num="4"><img file="JP2009531952A_D0004.tif" /></maths>
Here, CK and IK are pre-identified. Security context transmission from other RATs to LTE / SAE looks like the following <Formula 5>.
<maths num="5"><img file="JP2009531952A_D0005.tif" /></maths>
Here, prf represents a pseudo random function, and CK, IK, and UE are pre-identified.
Key Derivation for SAE Systems-Alternative 2: In this alternative, the LTE / SAE system utilizes UMTS AV as shown in Figure 14 and derives other keys as shown in <Formula 6> below.
<maths num="6"><img file="JP2009531952A_D0006.tif" /></maths>
Common CK for all MMEs<sub>NAS</sub>And IK<sub>NAS</sub>However, CK common to all UPEs (User Plane Entity)<sub>UP</sub>And IK<sub>UP</sub>, And a common CK for all ENBs<sub>RAN</sub>And IK<sub>RAN</sub>There is. Functions F8 and F9 are not provided and CK when MME and UPE are combined<sub>NAS</sub>And IK<sub>NAS</sub>Is used for NAS signal protection and user plane protection.
<maths num="7"><img file="JP2009531952A_D0007.tif" /></maths>
Here, each of these parameters is pre-identified. UE identification is in NAI format when EAP-AKA is used, and IMSI or TMSI when UMTS-AKA infrastructure certification is performed. Also, UE identification can be associated with serving node identification. Common CK for all MMEs in the same operator domain<sub>NAS</sub>And IK<sub>NAS</sub>And CK common to all ENBs<sub>RAN</sub>And IK<sub>RAN</sub>There is.
Key Derivation for SAE Systems-Alternative 3 In this alternative, the LTE / SAE system utilizes UMTS AV as shown in Figure 14 and derives other keys as shown in Equations 8-13.
<maths num="8"><img file="JP2009531952A_D0008.tif" /></maths>
<maths num="9"><img file="JP2009531952A_D0009.tif" /></maths>
<maths num="10"><img file="JP2009531952A_D0010.tif" /></maths>
<maths num="11"><img file="JP2009531952A_D0011.tif" /></maths>
<maths num="12"><img file="JP2009531952A_D0012.tif" /></maths>
<maths num="13"><img file="JP2009531952A_D0013.tif" /></maths>
In the above formula, prf represents a pseudo-random function, UE represents a user terminal (User Equipment), ID represents an identifier (Identifier), and MME represents a mobility management Entity (Mobility Management Entity). The unique key is derived for the network entity.
Other control methods and devices can be derived from the various combinations of methods and devices of the invention as shown in the above description and accompanying drawings, and those skilled in the art are within the scope of the present invention. Is self-evident. It should be noted that hosts for storing applications include, but are not limited to, microchips, microprocessors, handheld communication devices, computers, rendering devices or multifunction devices. is there.
Although the specific embodiments have been described above in the detailed description of the present invention, it is a person having ordinary knowledge in the art that various changes can be made without departing from the scope of claims. Is clear. Therefore, the scope of the present invention is not limited to the above-described embodiment, but should be determined based on the description of the scope of claims and equivalents thereof.
<figref num="1">It is a figure which shows the conventional logical upper hierarchy structure with respect to the evolved system.</figref><figref num="2">It is a figure which shows the conventional I-WLAN system configuration and network element.</figref><figref num="3">It is a figure which shows the message flow for the reverse handover (scenario 2 access) from SAE to the I-WLAN access system by this invention.</figref><figref num="4">It is a figure which shows the message flow for the reverse handover (scenario 2 and scenario 3 access) from SAE to the I-WLAN access system by this invention.</figref><figref num="5">It is a figure which shows the message flow for the reverse handover (scenario 3 access) from SAE to the I-WLAN access system by this invention.</figref><figref num="6">It is a figure which shows the message flow for the reverse handover (alternative 1) from I-WLAN to LTE by this invention.</figref><figref num="7">It is a figure which shows the message flow for the reverse handover (alternative 2) from I-WLAN to LTE by this invention.</figref><figref num="8">It is a figure which shows the message flow for the reverse handover from the UMTS system to the LTE system by this invention.</figref><figref num="9">It is a figure which shows the message flow for the reverse handover from the LTE system to the UMTS system by this invention.</figref><figref num="10">It is a figure which shows the message flow for the reverse handover (scenario 2 access) from the UMTS system to the I-WLAN access system by this invention.</figref><figref num="11">It is a figure which shows the message flow for the reverse handover (scenario 2 and scenario 3 access) from the UMTS system to the I-WLAN access system by this invention.</figref><figref num="12">It is a figure which shows the message flow for the reverse handover (scenario 3 access) from UMTS to the I-WLAN access system by this invention.</figref><figref num="13">It is a figure which shows the key derivation (alternative 1) for the evolved system by this invention.</figref><figref num="14">It is a figure which shows the key derivation (alternative 1) for the evolved system by this invention.</figref>
Code description
1,2a, 2b, 3,4,5,6,7,8,9,10,11,11a.1,11a.2,11a.3,11a.4,11a.5,11b,12,12a, 12b,13,14,15,16,17; Step
28 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US11032747B2 | Cited by | United States of America | Applicant |
| US9538373B2 | Cited by | United States of America | Applicant |
| US9497625B2 | Cited by | United States of America | Applicant |
| US10849191B2 | Cited by | United States of America | Applicant |
| JP2011519235A | Cited by | Japan | Examiner |
| US9572027B2 | Cited by | United States of America | Applicant |
| US9241261B2 | Cited by | United States of America | Applicant |
| US10015669B2 | Cited by | United States of America | Applicant |
| JP2010533390A | Cited by | Japan | Examiner |
| US10548012B2 | Cited by | United States of America | Applicant |
| US10986544B2 | Cited by | United States of America | Applicant |
| US8804962B2 | Cited by | United States of America | Applicant |
| JP2013529419A | Cited by | Japan | Search report |
| WO2014002533A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2011519235A | Cited by | Japan | Search report |
| US11751107B2 | Cited by | United States of America | Applicant |
| JP2019527504A | Cited by | Japan | Search report |
| US8812848B2 | Cited by | United States of America | Applicant |
| US9949197B2 | Cited by | United States of America | Applicant |
| US10595198B2 | Cited by | United States of America | Applicant |
| WO2005027557A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO2005027560A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
16 members in 8 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 597CHE2006 | India | – | |
| 597CH2006 | India | A | |
| 597CH2006 | India | A | |
| 2007001601 | Republic of Korea | W | |
| 2007001601 | Republic of Korea | W | |
| 2006CH20060597 | – | – | – |
| 2007001601 | – | – | – |
| IN2006CHE597 | – | – | – |
| WO2007KR01601 | – | – | – |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| EP1841267A2 | European Patent Office (EPO) | A2 | |
| AU2007232622A1 | Australia | A1 | |
| CA2642822A1 | Canada | A1 | |
| WO2007114623A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2007249352A1 | United States of America | A1 | |
| KR20090004896A | Republic of Korea | A | |
| CN101411115A | China | A | |
| JP2009531952AThis record | Japan | A | |
| AU2007232622B2 | Australia | B2 | |
| CN101411115B | China | B | |
| JP5059096B2 | Japan | B2 | |
| CA2642822C | Canada | C | |
| US8462742B2 | United States of America | B2 | |
| KR101514845B1 | Republic of Korea | B1 | |
| EP1841267A3 | European Patent Office (EPO) | A3 | |
| EP1841267B1 | European Patent Office (EPO) | B1 |
17 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 |
Numbers
- Publication
- 2009531952
- Publication, DOCDB
- 2009531952
- Publication, EPODOC
- JP2009531952
- Application
- 2009502694
- Application, DOCDB
- 2009502694
- Application, EPODOC
- JP20090502694
Titles2
- Japanese
- アクセスシステム間のハンドオーバー時の認証手順を最適化するシステム及び方法
- English
- Systems and methods for optimizing authentication procedures during handover between access systems
Classification
- CPC, 9
- H04W36/0016
- H04L63/08
- H04W12/0433
- H04W12/0431
- H04W12/062
- H04W36/1443
- H04W36/1446
- H04L63/0823
- H04W12/069
- IPC, 4
- H04W12 06
- H04W36 14
- H04L9 32
- H04W8 18
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo