Encryption in wireless telecommunications
Abstract
An example of the present invention is a method of transmitting encrypted user data to a mobile terminal in a wireless telecommunications network. The method includes a step of transmitting a data packet to a mobile terminal. The data packet includes both an identifier of the encrypted information to be used when recovering the encrypted user data and the user data encrypted using the encrypted information. [Selection diagram] Fig. 3

Term
6.3 yearsto projected expiry
Projected expiry 7 January 2033, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
10 claims: 4 independent, 6 dependent
- 1無線電気通信ネットワークにおいて、暗号化されたユーザデータをモバイル端末に伝送する方法であって、暗号化されたユーザデータを復元する際に使用されるべき暗号化情報の識別子と、前記暗号化情報を使用して暗号化されたユーザデータとの両方を備えるデータパケットを前記モバイル端末に送信するステップを備え、 前記デ-タパケットの受信に応じて、前記モバイル端末が前記識別された暗号化情報を使用してセキュリティ・コンテキストを初期化し、 前記ネットワークがUMTSまたはLTEネットワークを備え、 前記モバイル端末が前記識別された暗号化情報を使用して前記ユーザデータを復元するステップと、 前記モバイル端末が後で受信されるデータパケット内の暗号化されたユーザデータを復元する際の使用のために前記識別された暗号化情報を記憶するステップをさらに備える、方法。
- 2前記暗号化情報が暗号化アルゴリズムを備える、請求項1に記載の方法。
- 3前記暗号化情報が暗号化鍵を備える、請求項1または2に記載の方法。
- 4前記ユーザデータがユーザ・シグナリング・データを備える、請求項1~3のいずれか1項に記載の方法。
- 5前記ユーザ・シグナリング・データがNASメッセージまたはRRCメッセージを備える、請求項4に記載の方法。
- 6前記ユーザデータがユーザ・トラフィック・データを備える、請求項1~3のいずれか1項に記載の方法。
- 7前記データパケットがセキュリティ・モード・コマンドを備え、前記セキュリティ・モード・コマンドが前記暗号化情報の前記識別子を備える請求項1に記載の方法。
- 8暗号化されたユーザデータを復元する受信機において使用されるために適合され、第1の時間間隔で伝送される暗号化情報の識別子と、前記暗号化情報を使用して暗号化されたユーザデータとの両方を備える、データパケット内の暗号化されたユーザデータを伝送するように動作可能なUMTSまたはLTE無線電気通信基地局であって、 前記受信器が前記識別された暗号化情報を使用して前記ユーザデータを復元し、 前記受信器が後で受信されるデータパケット内の暗号化されたユーザデータを復元する際の使用のために前記識別された暗号化情報を記憶する、UMTSまたはLTE無線電気通信基地局。
- 9受信機およびプロセッサを備える無線電気通信端末であって、 前記受信機が、暗号化されたユーザデータを復元する際に使用されるべき暗号化情報の識別子と、前記暗号化情報を使用して暗号化されたユーザデータとの両方を備えるデータパケットを受信するように動作可能であり、 デ-タパケットの受信に応じて、前記モバイル端末が前記識別された暗号化情報を使用してセキュリティ・コンテキストを初期化し、 前記プロセッサが、前記暗号化情報を使用して、前記暗号化情報を使用して暗号化された前記ユーザデータを復元するように動作可能であり、前記モバイル端末が、後での使用のために前記暗号化情報を記憶するように動作可能であり、 前記端末がUMTSまたはLTE無線電気通信端末である無線電気通信端末。
- 10モバイル端末が、無線電気通信ネットワークにおいて、暗号化されたユーザデータを受信する方法であって、 前記モバイル端末が、第1の暗号化情報を使用して暗号化されたユーザデータを備える第1のデータパケットを受信するステップと、 前記モバイル端末に記憶されている第1の暗号化情報を使用して前記モバイル端末において前記ユーザデータを復元するステップと、 前記モバイル端末が、暗号化されたユーザデータを復元する際に使用されるべき更新された暗号化情報の識別子と、前記更新された暗号化情報を使用して暗号化されたユーザデータとの両方を備える次のデータパケットを受信するステップとを備え、 デ-タパケットの受信に応じて、前記モバイル端末が前記識別された暗号化情報を使用してセキュリティ・コンテキストを初期化し、 前記モバイル端末が、前記更新された暗号化情報を使用して暗号化された前記ユーザデータを復元するための前記暗号化情報を使用し、後でのパケットを復号するときの後での使用のために前記更新された暗号化情報を記憶する方法。
Independent claims10
31 paragraphs, as filed
The present invention relates to telecommunications, and more specifically to wireless telecommunications.
In the known system (Universal Mobile Telecommunications System) (UMTS), some messages are encrypted. Encryption is initiated by a security mode command sent from the core network via UTRAN (UMTS terrestrial radio access network) and received by the mobile terminal. Following this, the security mode response is sent from the mobile terminal and received by the core network.
For example, as shown in Figure 1, core network (CN) 2 sends security mode command 4 to UTRAN6 when it receives a session or bearer establishment request 1. This causes UTRAN6 to transfer security mode command 4 to the mobile terminal (user device, UE8). The mobile device 8 responds by initializing its encryption algorithm with a specific parameter value, sometimes referred to as the security context, and then acknowledges by sending a security mode response 10 to UTRAN6. UTRAN6 then forwards response 10 to core network 2. After that, an encrypted NAS (Non Access Stratum) message such as session establishment response 12 is transmitted from the core network 2 to the mobile terminal 8 via UTRAN6.
In this known technique, security mode messages are not encrypted because they provide the encryption information needed to encrypt subsequent messages.
Another area of background technology is LTE (Long Term Evolution) networks. The so-called LTE (Long Term Evolution) network is currently being developed from the UMTS network. For background technology of Long Term Evolution networks, readers should refer to 3GPP TS (Third Generation Partnership Project Technical Specification) 23.882.
<p> Readers should refer to the attached independent claims. Some preferred features are described in the dependent claims.</p><p> An example of the present invention is a method of transmitting encrypted user data to a mobile terminal in a wireless telecommunications network. The method comprises sending a data packet to a mobile terminal. The data packet includes both an identifier of the encrypted information to be used when recovering the encrypted user data and the user data encrypted using the encrypted information.</p><p> We have found that in known techniques, security mode commands and response signaling cause delays in the session establishment procedure. For example, if the mobile terminal moves to the coverage area of another base station, there may be a change in the encryption key used. This requires security mode commands and response signaling to notify the mobile device of the new key before the data encrypted with the new key is sent. This additional signaling can cause additional delays. Such delays can be annoying to subscribers and can cause problems for applications that are sensitive to call setup delays, such as push-to-talk.</p><p> In some embodiments of the invention, such delays can be reduced.</p><p> Next, embodiments of the present invention will be described, for example, with reference to the accompanying drawings.</p>
<figref num="1">FIG. 5 shows a known technique for invoking encryption as part of session establishment (previous technique).</figref><figref num="2">It is a figure which shows the LTE (Long Term Evolution) network by 1st Embodiment of this invention.</figref><figref num="3">It is a figure which shows the method of invoking encryption as a part of session establishment in the network shown in FIG.</figref><figref num="4">It is a figure which shows the structure of the NAS message transmitted at the time of session establishment.</figref><figref num="5">It is a figure which shows how the NAS signaling message is encrypted.</figref><figref num="6">It is a figure which shows the handover between the core network CN nodes in the LTE network.</figref><figref num="7">It is a figure which shows that encryption is activated as a part of RRC (Radio resource control) connection establishment in an LTE network.</figref><figref num="8">It is a figure which shows the UMTS (Universal Mobile Telecommunications System) network according to the 2nd Embodiment of this invention.</figref><figref num="9">It is a figure which shows the method of invoking encryption as a part of session establishment in the network shown in FIG.</figref>
An exemplary LTE network is first described, and then a join message is used to describe how encryption is initiated when a session is established. Next, how encryption is processed during the handover of the mobile terminal from the connection with one network node to the connection with another network node will be described.
An alternative join message is then described.
An alternative network, which is a UMTS network, is then described, and then how encryption is initiated in that network.
Long Term Evolution Network The LTE network 14 based on the UMTS (Universal Mobile Telecommunications System) network is basically as shown in Fig. 2. The core network includes MME (Mobile Management Entities). Each MME 16 includes NAS message encryption stage 26. In Figure 2, for simplicity, only one mobile management entity (MME) 16 in core network 18 and one base station 20 in LTE network 14 are shown. The LTE network includes multiple base stations. In the figure, the base station is also shown as "e-node B" in LTE jargon. A cell, also called a sector, is a radio coverage area served by the corresponding antenna of the base station. Base station 20 typically has three cells 22, each cell covered by one of three directional antennas 24 arranged at an azimuth of 120 degrees to each other.
In use, the mobile user terminal 28 (often referred to in LTE / UMTS terminology as user equipment (UE)) communicates with the mobile management entity 16 via at least one cell 22 of at least one base station 20. In that way, the mobile user terminal communicates with UTRAN network 2.
Invoking encryption when session is established We have found that it is possible to combine security mode commands and NAS (Non Access Stratum) messages (such as session establishment responses) into a single combined message. The first part of the message is the security mode command, which is unencrypted. The second part of the message is the NAS message, which is encrypted.
Upon receiving the session establishment request 30, mobile management entity 16 bases a combined message 32 consisting of an unencrypted security mode command and an encrypted NAS signaling message, as shown in Figure 3. Send to station 20. This causes the base station 20 to forward the combined message 32 to the mobile terminal (user device, UE28). The mobile terminal 28 performs an initialization of its security context and then acknowledges by sending a security mode response 34 to base station 20, which is forwarded from base station 20 to mobile management entity 16. To. After that, an encrypted NAS (Non Access Stratum) message such as the session establishment response 36 is transmitted from the MME 16 to the mobile terminal 28 via the base station 20.
The combined message 32 mentioned above is as shown in FIG. 4 and consists of an unencrypted security command 38 and an encrypted NAS message 40. The security command 38 consists of an information element that defines security context information, such as an identifier of the encryption key to be used and an identifier of the start time of encryption. The NAS message 40 consists of information elements that make up the session establishment response.
Generate combined message In LTE network 14, NAS message encryption is performed by encryption step 26 at each node of core network 18. NAS message encryption is independent of user data encryption.
As shown in FIG. 5, the NAS message for encryption is input to the encryption stage 26 together with the information for performing encryption such as the encryption key, and the encrypted NAS message 40 is provided from there. Will be done. The encrypted NAS message 40 is concatenated with the unencrypted header information 38. This is possible because MME16 generally allows encryption of at least a portion of the NAS message prior to concatenation with another unencrypted message portion.
Processing encryption at the time of handover Handover takes the mobile terminal 28 from a connection with one base station 20, and thus the core network node 18, to another base station (not shown) and thus another core network node (not shown). The process of transferring. Handovers are sometimes known as handovers.
An example of the handover procedure is shown in FIG. Initially, the connection is to base station 20, which requires the use of a first encryption key. The core network node 18 sends a handover command 42 to the mobile terminal 28 via the base station 20, and then a handover 44 of a call connection to another base station 20', and thus to the core network node 20', is performed. Ru. A "handover complete" message 46 is then transmitted from the mobile terminal 28 to the new base station 18'and thus the core network node 18'. The core network node was then encrypted with the unencrypted security mode command 50 containing the encryption key identifier, followed by user data such as NAS signaling messages, as discussed above. Send a combined message 48 consisting of part 52. So, for example, if the core network node makes an encryption change, the first join message 50 from the new core network node 18'indicates the new security parameter value to be used in the security mode command. Includes NAS signaling messages in encrypted form.
In other similar embodiments, if the encryption and encryption configuration is done in the user plane, then the combined packet in the user plane is in an unencrypted security mode bound to the user data. -Consists of commands.
Of course, in some embodiments, an unencrypted security mode command that includes an encryption key identifier, followed by an encrypted portion of user data that is encrypted using a new encryption key. The exchange for the new encryption key by transmitting the merged message consisting of the above can also be performed at a time other than the handover between cells. For example, in other embodiments, the old cell and the new cell may be the same cell.
In this example, the cell initially communicates with the mobile device using the old encryption parameters. The cell sends a packet containing new encryption parameters and additional user data in the middle of the session. The mobile device receives the new encryption parameters. The mobile device uses the new encryption parameters to decrypt the encrypted portion of the packet. The mobile device also stores the new encryption parameters for later use in encrypting subsequent packets that are encrypted using the new encryption parameters.
Wireless resource control Similarly, as shown in Figure 7, a combined message consisting of an unencrypted security mode command and an encrypted user data portion may be sent, in which case the user data portion is wireless. Consists of resource control (RRC) messages. As shown in Figure 7, an RRC connection request 54 is sent to base station 20 in response to a combined message 56, more specifically an unencrypted security mode command, by the base station. A combined message 56 with an encrypted RRC connection response (using a new key) followed by the base station is sent by the base station to the mobile terminal 28', followed by a security mode response from the user terminal 28'. Is sent.
Another exemplary system: UMTS The network is UTRAN (UMTS (Universal Mobile Telecommunications System) terrestrial access network), which is a type of wideband CDMA (code division multiple access) network for mobile telecommunications. The UTRAN network is basically as shown in Figure 8. For simplicity, only one wireless network controller and two base stations in UTRAN network 62 are shown. As shown in this figure, the UTRAN network 62 includes base station 64. In the figure, each base station 64 is also referred to as "node B" by UMTS terminology. A cell, also called a sector, is a radio coverage area served by the corresponding antenna of the base station. Each base station typically has three cells 66, each cell covered by one of three directional antennas 67 arranged at an azimuth of 120 degrees to each other. Each RNC (radio network) controller) 68 typically controls some base stations 64, and thus some cells 66. The base station 64 is connected to an RNC (radio network controller) 68 that controls the base station via each interface 69 known as an IuB interface. In use, the mobile user terminal 70 (often referred to in UMTS terminology as a user device (UE)) communicates with a serving RNC (radio network controller) 68 via at least one cell 66 of at least one base station 64. .. In that way, the mobile user terminal communicates with the UTRAN network 62.
The RNC is connected to the SGSN (Serving Gateway Support Node) 72 of the core network 74. SGSN72 includes NAS message encryption stage 76, as described in more detail below.
Invoking encryption when session is established: UMTS example We have found that it is possible to combine security mode commands and NAS (Non Access Stratum) messages (such as session establishment responses) into a single combined message. The first part of the message is the security mode command, which is unencrypted. The second part of the message is the NAS message, which is encrypted.
Upon receiving the session establishment request 78, SGSN72 sends a combined message 80 consisting of an unencrypted security mode command and an encrypted NAS signaling message to the RNC68, and thus the base, as shown in Figure 9. Send to station 64. This causes the base station 64 to forward the combined message 80 to the mobile terminal (user device, UE70).
Combined message 80 consists of an unencrypted security command and an encrypted NAS message. A security command consists of an information element that defines an identifier for the encryption key to be used and security context information, such as an identifier for the start time for encryption. The encrypted NAS message portion of message 80 consists of the information elements that make up the session establishment response.
The mobile terminal 70 performs an initialization of its security context and then acknowledges by sending a security mode response 82 to base station 64, and thus to RNC68, which is forwarded from RNC68 to SGSN72.
General The present invention can be practiced in other particular embodiments without departing from the essential features of the invention. The embodiments described are, in all respects, merely exemplary and should be considered non-restrictive. Therefore, the scope of the present invention is shown not by the above description but by the appended claims. The meaning of the equivalent of the claims and all modifications contained in the scope shall be included in the claims.
Some abbreviations CN: Core network UMTS: Universal Mobile Telecommunications System UE: User device NAS: Non Access Stratum (also known as Core Network Protocol) MME: Mobility Management Entity LTE: Long Term Evolution, a term used in 3GPP for systems standardized after UMTS IE: Information element RRC: Radio Resource Control (also known as the Radio part of the control protocol, or the Access Stratum part of the control protocol) SGSN: Signalling Gateway Support Node
10 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO02076011A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| JPH0637750A | Cites | Japan | Examiner |
| JPH0646052A | Cites | Japan | Search report |
34 members in 14 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 0619499 | United Kingdom | A | |
| 0619499 | United Kingdom | A | |
| 06194997 | United Kingdom | – | |
| 2006200619499 | – | – | – |
| GB20060019499 | – | – | – |
Members34
| Document | Office | Kind | |
|---|---|---|---|
| GB0619499D0 | United Kingdom | D0 | |
| AU2007304555A1 | Australia | A1 | |
| WO2008040412A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW200830817A | Taiwan Province of China | A | |
| MX2009003314A | Mexico | A | |
| EP2070290A1 | European Patent Office (EPO) | A1 | |
| KR20090063274A | Republic of Korea | A | |
| CN101518032A | China | A | |
| IL197829A0 | Israel | A0 | |
| JP2010506469A | Japan | A | |
| US2010067697A1 | United States of America | A1 | |
| RU2009116675A | Russian Federation | A | |
| AU2007304555B2 | Australia | B2 | |
| KR101078615B1 | Republic of Korea | B1 | |
| RU2458476C2 | Russian Federation | C2 | |
| JP2013081252AThis record | Japan | A | |
| US8494163B2 | United States of America | B2 | |
| US2013216042A1 | United States of America | A1 | |
| CN103327483A | China | A | |
| BRPI0717324A2 | Brazil | A2 | |
| TWI442743B | Taiwan Province of China | B | |
| IL197829A | Israel | A | |
| CN101518032B | China | B | |
| CN104394527A | China | A | |
| US9107066B2 | United States of America | B2 | |
| US2015237501A1 | United States of America | A1 | |
| JP2016021746A | Japan | A | |
| EP2070290B1 | European Patent Office (EPO) | B1 | |
| ES2581354T3 | Spain | T3 | |
| JP6016643B2 | Japan | B2 | |
| US9503901B2 | United States of America | B2 | |
| CN103327483B | China | B | |
| CN104394527B | China | B | |
| BRPI0717324B1 | Brazil | B1 |
22 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2013081252
- Publication, DOCDB
- 2013081252
- Publication, EPODOC
- JP2013081252
- Application
- 495
- Application, DOCDB
- 2013000495
- Application, EPODOC
- JP20130000495
Titles2
- Japanese
- 無線電気通信における暗号化
- English
- Encryption in wireless telecommunications
Classification
- CPC, 9
- H04L63/0428
- H04W12/02
- H04W12/08
- H04L63/068
- H04W12/04
- H04W12/033
- H04L9/065
- H04L63/0407
- H04L63/0442
- IPC, 3
- H04L9 08
- H04W12 04
- H04W12 02