Method of transmitting uplink data and buffer status reports in a wireless communications system, wireless device for implementing such method
12 claims: 10 independent, 2 dependent
- 1無線機器(10)と通信するためのそれぞれのセルをサービスする複数の基地局(20)を含む無線通信システム のための ハンドオーバー方法であって、 少なくとも一つのターゲットセルに対して、ソース基地局(20S)から前記ターゲットセルをサービスするターゲット基地局(20T)に、前記ソース基地局と通信リンクを有する無線機器(10)の識別子及び前記無線機器に対する認証データを獲得するための情報を含む第1メッセージを送信 することであって 、前記認証データは、前記無線機器と前記ソース基地局で利用可能な秘密キー及び前記ターゲットセルのアイデンティティ(identity)に依存し、 前記認証データは、MAC-I(message authentication code for integrity)として生成される、ことと、 前記通信リンクに障害(failure)が生じた場合、前記無線機器によりセルを選択し、前記無線機器から、前記選択されたセルをサービスする基地局の一つに、前記無線機器の識別子と、前記秘密キー及び前記選択されたセルのアイデンティティに依存する認証データとを含む再設定要請メッセージを、送信 することと 、 前記選択されたセルが、前記第1メッセージを受信した前記ターゲット基地局によってサービスされるターゲットセルである場合、前記再設定要請メッセージに含まれた前記認証データと、前記第1メッセージから獲得した認証データとの一致を検証 することと 、 前記一致が検証された場合、前記選択されたセルに通信リンクを移す(transferring)こと と 、を含む、ハンドオーバー方法。
- 2前記認証データは、秘密キー及びターゲットセルアイデンティティを含む入力パラメータに基づく暗号化アルゴリズムを用いて計算される、請求項 1 に記載のハンドオーバー方法。
- 3前記入力パラメータは、前記ソース基地局(20S)によってサービスされるソースセルのアイデンティティと、通信リンク上で前記ソース基地局との通信のために前記無線機器(10)に割り当てられる臨時識別子のうち少なくとも一つをさらに含む、請求項 2 に記載のハンドオーバー方法。
- 4前記入力パラメータは、前記無線機器(10)と各ターゲット基地局(20T)間の共通(common)時間レファレンスをさらに含み、 前記認証データは、前記無線機器から前記再設定要請メッセージを受信すると、前記選択されたセルをサービスする基地局で計算される、請求項 2 に記載のハンドオーバー方法。
- 5前記認証データは、前記ソース基地局(20S)から受信した第1メッセージ の 内容の少なくとも一部に基づいてターゲット基地局(20T)で計算され、前記再設定要請メッセージに含まれている認証データと比較される、請求項1に記載のハンドオーバー方法。
- 6前記認証データは、 前記 ソース基地局(20S)で計算され、前記再設定要請メッセージに含まれている認証データとの比較のために 前記 ターゲット基地局 (20T) に送信される、請求項1に記載のハンドオーバー方法。
- 7それぞれのセルをサービスする複数の基地局(20)を有するネットワークとの通信のための無線機器(10)であって、 前記無線機器とソース基地局(20S)との間に提供される通信リンクにおける障害(failure)を感知する感知器と、 前記通信リンク の 障害を感知した場合、前記ネットワークとの追加的通信のためにセルを選択する選択器と、 前記無線機器の識別子(identifier)と、前記無線機器と前記ソース基地局で利用可能な秘密キー及び前記選択されたセルのアイデンティティ(identity)に依存する認証データとを含む再設定要請メッセージを生成する要請生成器 であって、前記認証データは、MAC-I(message authentication code for integrity)である、要請生成器 と、 前記再設定要請メッセージを、前記選択されたセルをサービスする基地局(20T)の一つに送信するように構成された送信器と、を含む、無線機器。
- 8前記認証データは、前記秘密キー、前記選択されたセルのアイデンティティ、及び前記無線機器(10)と少なくとも一つの前記基地局(20)間の共通(common)時間レファレンスを含む入力パラメータに基づく暗号化アルゴリズムを用いて計算される、請求項 7 に記載の無線機器。
- 9無線通信システムで無線機器(10)と通信するために少なくとも一つのセルをサービスする基地局(20T)であって、 前記無線通信システムのソース基地局 (20S) から、該ソース基地局と通信リンクを有する無線機器(10)の識別子と、前記無線機器と前記ソース基地局で利用可能な秘密キー及び前記基地局(20T)によってサービスされるターゲットセルのアイデンティティに依存する前記無線機器の認証データ の 獲得のための情報とを含む第1メッセージを受信するように構成されたネットワークインターフェース であって、前記認証データは、MAC-I(message authentication code for integrity)である、ネットワークインターフェース と、 前記ターゲットセルに位置している無線機器から、前記無線機器の識別子及び認証データを含む再設定要請メッセージを受信するように構成された無線インターフェースと、 前記再設定要請メッセージに含まれた前記無線機器識別子及び前記認証データが、前記第1メッセージに含まれた無線機器識別子及び前記第1メッセージから獲得された認証データとマッチング する 場合、通信リンクを前記ターゲットセルに移す(transferring)ハンドオーバーコントローラと、を含む、基地局。
- 10前記認証データは、前記第1メッセージから受信した秘密キー及び前記ターゲットセルアイデンティティを含む入力パラメータに基づく暗号化アルゴリズムを用いて地域的に(locally)計算され、前記再設定要請メッセージに含まれた認証データと比較される、請求項 9 に記載の基地局。
- 11前記入力パラメータは、前記第1メッセージから受信された、前記ソース基地局(20S)によってサービスされるソースセルのアイデンティティと、通信リンク上で前記ソース基地局と通信のために前記無線機器(10)に割り当てられる臨時識別子のうち少なくとも一つをさらに含む、請求項 10 に記載の基地局。
- 12前記入力パラメータは、前記無線機器(10)からの再設定要請メッセージの受信に対応する時間レファレンスをさらに含む、請求項 10 または 11 に記載の基地局。
Independent claims12
61 paragraphs, as filed
The present invention relates to mobility management of wireless devices in a cellular communication network, and more particularly to controlling the handover of wireless devices from one cell of the network to another. In the following, for convenience of explanation, LTE (long term evolution) type cellular networks will be mainly described, but those skilled in the art of communication can apply the inventions disclosed below to various forms of cellular networks. You can see that.
UMTS (Universal mobile telecommunications system) is a third-generation (3G) asynchronous mobile communication that operates on European system-based WCDMA (wide band code division multiple access), GSM (global system for mobile communications) and GPRS (general packet radio services). It is a system. LTE (long term evolution) of UMTS is 3GPP (3) that standardizes UMTS.<sup>rd</sup> Under discussion under generation partnership project).
3GPP LTE is a technology that enables high-speed packet communication. Many approaches have been proposed for LTE goals, including reducing user and provider costs, improving quality of service, and improving coverage and system capacity. 3G LTE demands reduced cost per bit, increased service availability, flexible use of frequency bands, simple construction, open interfaces and adaptive power consumption of terminals to meet higher level requirements.
FIG. 1 is a block diagram showing a network structure of E-UMTS (evolved universal mobile telecommunication system). E-UMTS is also called an LTE system. Communication networks are widely deployed to provide a variety of communication services such as voice and packet data.
As shown in FIG. 1, the E-UMTS network includes an E-UTRAN (evolved UMTS terrestrial radio access network), an EPC (Evolved Packet Core), and one or more user devices. E-UTRAN includes one or more eNodeB (evolved NodeB or eNB) 20 and a plurality of UEs (user equipment) located in one cell. One or more E-UTRAN MME (mobility management entity) / SAE (system architecture evolution) gateways 30 are located at the end of the network and are connected to the external network.
In the following, the downlink is the communication from eNodeB 20 to UE 10, and the uplink is the communication from UE to eNode. UE 10 is a communication device carried by a user, which is also called an MS (mobile station), UT (user terminal), SS (subscriber station) or wireless device.
eNodeB 20 provides UE 10 with endpoints for the user and control planes. The MME / SAE gateway 30 provides session endpoints and mobility management capabilities for UE 10. The eNodeB and MME / SAE gateway are connected via the S1 interface.
The eNodeB 20 is a fixed facility that typically communicates with the UE 10 and is called a BS (base station) or access point. One eNodeB 20 is arranged for each cell. An interface is used between the eNodeB 20s to carry user and control traffic.
MME provides eNodeB 20 with a variety of features including paging message distribution, security control, standby mobility control, SAE bearer control and NAS (non-access stratum) signaling encryption and integrity checking. SAE gateway hosts offer a variety of features, including U-plane packet removal for paging and U-plane switching to assist UE mobility. For a clearer explanation, the MME / SAE gateway 30 is simply referred to below as the gateway, but it can be understood that such entities include both MME and SAE gates.
Many nodes are connected between eNodeB 20 and gateway 30 via the S1 interface. Each of the eNodeB 20s is connected to each other via an X2 interface, and adjacent eNodeBs can have a meshed network structure containing the X2 interface.
FIG. 2 (a) is a block diagram showing the structure of a general E-UTRAN and EPC. As shown in the figure, eNodeB 20 selects gateway 30, routes to gateway during RRC (Radio Resource Control) active period, schedules and sends paging messages, and to UE 10 in both uplink and downlink. Dynamic allocation of resources, setting and provision of eNodeB measurement, radio bearer control, RAC (radio admission control), and connection mobility control in the LTE_ACTIVE state. In EPC, as mentioned above, the gateway 30 has paging infrastructure functions, LTE-IDLE state management, user plane encryption, SAE (System Architecture Evolution) bearer control, and NAS (Non-Access Stratum) signaling encryption. Perform an integrity test.
2 (b) and 2 (c) are diagrams showing the user plane protocol stack and the control plane protocol stack in E-UMTS. As shown, the protocol hierarchy is the first layer (L1), the second layer (L2), and the third layer (L1), which are based on the lower three layers of the OSI (open system interconnection) standard model widely known in the communication system field. It is classified into L3).
The physical layer, that is, the first layer (L1) provides an information transmission service to the upper layer using a physical channel. The physical layer is connected to a MAC (medium access control) layer located at a higher level via a transmission channel, and data between the MAC layer and the physical layer is transmitted through the transmission channel. Data is transmitted through physical channels between different physical layers, that is, between the transmitting physical layer and the receiving physical layer.
The MAC layer, which is the second layer (L2), provides services to the higher layer, the RLC (radio link control) layer, through a logical channel. The second layer (L2), the RLC layer, supports reliable data transmission. It should be noted that the RLC layer shown in FIGS. 2 (b) and 2 (c) does not require the RLC layer itself when the RLC function is embodied by the MAC layer. The second layer (L2), the PDCP (packet data convergence protocol) layer, performs a header compression function that reduces unnecessary control information, and data transmitted using IP (Internet protocol) packets such as IPv4 or IPv6. Can be effectively transmitted through a radio interface with a relatively small bandwidth.
The RRC (radio resource control) layer, which is located at the bottom of the third layer (L3), is defined only in the control plane, and the logical channel and transmission are related to the setting, resetting and canceling of the radio bearer (RB). Control channels and physical channels. Here, RB means a service provided by the second layer (L2) for data transmission between the device (UE) and E-UTRAN.
As shown in Fig. 2 (b), the RLC and MAC layers (ending at eNodeB 20 on the network side) perform functions such as scheduling, ARQ (Automatic Repeat Request), and HARQ (hybrid automatic repeat request). The PDCP layer (ending at eNodeB 20 on the network side) performs user plane functions such as header compression, integrity checking and encryption.
As shown in Figure 2 (c), the RLC and MAC layers (ending at eNodeB 20 on the network side) perform the same function on the control plane. As shown, the RRC layer (ending at eNodeB 20 on the network side) performs functions such as broadcasting, paging, RRC connection management, RB (Radio Bearer) control, mobility function, UE measurement reporting and control. The NAS control protocol (ending at MME gateway 30 on the network side) is for SAE bearer management, authentication, LTE_IDLE mobility handling, paging initiation at LTE_IDLE and security control for signaling between the gateway and UE 10. It fulfills such a function.
The NAS control protocol utilizes three different states. First, it is the LTE_DETACHED state when there is no RRC entity, second, it is the LTE_IDLE state state where it stores the minimum UE information, but there is no RRC connection, and third, it is the LTE_ACTIVE where the RRC connection is formed. It is in a state. Also, RRC states are divided into two different states, such as RRC_IDLE and RRC_CONNECTED.
In the RRC_IDLE state, UE 10 receives a broadcast about system information and paging information while identifying the DRX (Discontinuous Reception) set by the NAS. In addition, the UE is assigned an ID (identification) that uniquely identifies the UE in the tracking area. Also, in the RRC-IDLE state, RRC information is not saved in eNodeB.
In the RRC_CONNECTED state, UE 10 is RRC-connected to E-UTRAN, but E-UTRAN contains UE information, which allows data to be transmitted and / or received to or from the network (eNodeB). .. UE 10 also reports channel quality information and feedback information to eNodeB.
In the RRC_CONNECTED state, E-UTRAN recognizes the cell to which UE 10 belongs. Thus, the network can transmit and / or receive data to or from UE 10, the network can control the mobility (handover) of the UE, and the network can make cell measurements for adjacent cells. Can be done.
In the RRC_IDLE state, UE 10 identifies the paging DRX (Discontinuous Reception) cycle. In particular, UE 10 monitors the paging signal at specific paging opportunities at every UE specific paging DRX cycle cycle.
FIG. 3 is a diagram showing a general handover procedure in an LTE system. The handover procedure is for transmitting or handing off the moored communication from the source cell serviced by the source eNodeB (20S) to the target cell serviced by the target eNodeB (20T). Here, consider the case where the source cell and the target cell are not served by the same eNodeB.
The source eNodeB (20S) sets the UE measurement procedure forming a part of the RRC protocol shown in FIG. 2 (a) by the area restriction information provided by each eNodeB. This is done by sending one or more MEASUREMENT CONTROL messages to UE 10 in the RRC_CONNECTED state, as shown in stage S1 in Figure 3. The measurements requested by the source eNodeB (20S) aid in the ability to control the connection mobility of the UE. From then on, UE 10 provokes to send a MEASUREMENT REPORT message, broadcast by the source eNodeB and / or by a rule specified by a MEASUREMENT CONTROL message or additional downlink signaling, eg, set by system information. Is done (stage S2).
For each UE in the RRC_CONNECTED state, the source eNodeB (20S) receives one or more handover control algorithms that receive the measurements reported by UE 10 and possibly other measurements made by the source eNodeB (20S). ,Execute. Through such measurements, the source eNodeB (20S) determines whether the target eNodeB (20T) should hand off UE 10. When attempting to hand off, the source eNodeB (20S) sends a HANDOVER REQUEST message to the target eNodeB (20T), delivering the information needed to prepare for a handover to the target side (step). S4). Such information includes the UE X2 signaling environment reference, UE S1 EPC signaling environment reference, target cell directive, RRC environment and SAE bearer environment in the source eNodeB. UE X2 and UE The S1 signaling environment reference allows the target eNodeB to address the source eNodeB and EPC. The SAE bearer environment contains the required RNL (radio network layer) and TNL (transport network layer) addressing information.
The admission control function is performed by the target eNodeB (20T) using the received SAE bearer quality of service (QoS) information for the purpose of increasing the possibility of successful handover (step S5 in Figure 3). ). If the handover is allowed, the target eNodeB (20T) sets the resource based on the received SAE bearer QoS information and issues a new C-RNTI (cell-radio network temporary identifier) to recognize UE 10 in the target cell. Secure. The target eNodeB (20T) prepares the handover in the first and second layers and sends a HANDOVER REQUEST ACKNOWLEDGE message to the source eNodeB (20S) (step S6). The HANDOVER REQUEST ACKNOWLEDGE message is a transparent container that is transmitted to UE 10. container) is included. This container contains the new CRNTI assigned by the target eNodeB and, in some cases, other parameters such as access parameters, SIB (system information block), etc. The HANDOVER REQUEST ACKNOWLEDGE message can also include RNL / TNL information about the forwarding tunnel, if desired.
In response, the source eNodeB (20S) generates a HANDOVER COMMAND message for the RRC protocol and sends it to UE 10 (step S7). At the same time, the source eNodeB (20S) is buffered to send to the UE, as well as information related to the acquisition state of the packet by the UE, and some or all of the packets currently being sent to the UE. , Send to target eNodeB (20T) (S8).
Source eNodeB applies integrity checking and encryption capabilities to the message. The HANDOVER COMMAND message contains a transparent container received from the target eNodeB (20T). The UE receives the HANDOVER COMMAND with the required parameters (new CRNTI, possible start time, target eNodeB SIB, etc.), thereby being directed by the source eNodeB (20S) to perform the handover. UE 10 follows the handover instruction, is separated from the source cell, acquires synchronization, and connects to the target cell (step S9).
When UE 10 successfully connects to the target cell, it sends a HANDOVER CONFIRM message to the target eNodeB (20T) using the newly assigned C-RNTI to inform the UE that the handover procedure has been completed. (Step S10 in Figure 3). The target eNodeB (20T) validates the C-RNTI sent in the HANDOVER CONFIRM message. If the validation passes, the EPC recognizes that the UE has changed the cell with a HANDOVER COMPLETE message from the target eNodeB (20T) (step S11). In stage S12, the EPC switches the downlink data path to the target side and releases the U-plane / TNL resource set in the source eNodeB (20S). The EPC confirms at stage S13 by returning a HANDOVER COMPLETE ACK message.
The target eNodeB (20T) subsequently informs the source eNodeB (20S) that the handover has been successful by sending a RELEASE RESOURCE message that triggers the release of the source resource (step S14), and this The message causes the source eNodeB to release the resource, that is, the wireless / C-plane related resource associated with the UE environment, at stage S15.
UE 10 communicating with constant eNodeB (20) in the RRC_CONNECTED state suffers a wireless link failure. UE 10 can perform the RRC connection reconfiguration procedure to resume bearer operation with the same eNodeB or other eNodeB, or, if possible, switch to the RRC_IDLE state to request a new RRC connection. In particular, the wireless link failure occurs between stages S6 and S7 in the handover procedure shown in FIG. 3 (deterioration of the wireless link prior to the wireless link failure may be the reason for the handover decision). In such cases, UE 10 can often fail to select the correct target cell, especially if the target is selected by the source eNodeB (20S) based on the channel state. Even though the target eNodeB (20T) has already obtained all the necessary information about UE 10 from the source eNodeB (20S), UE 10 still has to enter the RRC_IDLE state, which is the EPC. It is not preferable because it requires a relatively complicated procedure including.
<p> To address this situation, the source eNodeB (20S) is used by the UE when approaching a new cell after the cell selection process, the UE identity used in the RRC connection request in the event of a wireless link failure. Send the identity to the target eNodeB (20T) with a HANDOVER REQUEST message (R2-071717 at the 58th 3GPP TSG-RAN WG2 Conference held in Kobe, Japan, May 7-11, 2007. , Handover Failure Recovery) was proposed. If a radio link failure occurs during the handover preparation stage before the UE 10 has an opportunity to receive a HANDOVER COMMAND message, and the UE finishes selecting the target cell by the handover procedure, the target eNodeB (20T) will , Identifies the UE and informs the UE of the possibility of reusing an existing RRC connection instead of setting up a new connection and contact with the EPC. In other words, the system behaves as if the handover was successful.</p><p> Therefore, instead of sending a HANDOVER CONFIRM message to the target eNodeB (20T), the UE 10 suffering from a radio link failure will have the target eNodeB (20T) identify the UE and the UE and the source eNodeB (20S). Sends an RRC CONNECTION REESTABLISHMENT REQUEST message indicating the UE identifier used to concatenate with the UE environment (context) received from. If the validation passes, the target eNodeB (20T) informs UE 10 that the connection has been resumed by sending an RRC CONNECTION REESTABLISHMENT message (no need to switch to the RRC_IDLE state).</p><p> The UE identifier, directed by the UE and used by the target eNodeB to resolve contention, consists of C-RNTI associated with MAC-I (message authentication code for integrity). Please refer to R2-071717, Handover Failure Recovery of the 58th 3GPP TSG-RAN WG2 Conference held in Kobe, Japan from May 7 to 11, 2007. The use of MAC-I provides a degree of security against intruders attempting to use the existing connections of legitimate users. However, this security is not perfect, and in particular, intruders respond to UE identifiers sent by legitimate UEs in an attempt to abuse RRC connections.</p><p> An object of the present invention is to improve security in the event of a wireless link failure during the handover procedure.</p>
<p> In the following, a handover method in a wireless communication system is proposed. The system includes multiple base stations servicing each cell for communicating with wireless devices. Further, the handover method is For at least one target cell, the source base station obtains the identifier of the wireless device having a communication link with the source base station and the authentication data for the wireless device from the target base station serving the target cell. A first message containing the information is transmitted, where the authentication data depends on the private key available at the radio device and the source base station and the identity of the target cell. When the communication link is impaired, the wireless device selects a cell, and one of the base stations servicing the selected cell from the wireless device includes the wireless device identifier, the secret key, and the above. Send a reconfiguration request message, including authentication data that depends on the identity of the selected cell, When the selected cell is a target cell serviced by the target base station that has received the first message, the authentication data included in the reset request message and the authentication data acquired from the first message. Verify the match with If the match is verified, transfer the communication link to the selected cell. including.</p><p> The transmission of the first message, which is a HANDOVER REQUEST, is triggered by a handover decision based on the measurements reported by the radio device to the source base station. However, handover in other cases is also possible.</p><p> Link failure can occur during the handover procedure, reducing the likelihood that the wireless device will switch to the IDLE state and generate more complex signaling to regain connectivity with the network. Therefore, it is preferable that the network prepares one or more target base stations at the same time. If different target base stations use the same authentication data, there are security weaknesses. That is, an intruder who receives a reset request message including the wireless device identifier and authentication data transmitted from the wireless device to the target base station A is another target base station whose (handover procedure) is prepared in advance. The same message can be sent to "B". In particular, if the message is not received by the base station "A", an intruder can unfairly use the user connection. This security weakness can be avoided, for example, by generating authentication data that depends on the private key, such as MAC-I, and the identity of each target cell.</p><p> The diversification of authentication data can be further improved by utilizing the calculation of the common time reference between the wireless device and each target base station. After that, the authentication data is calculated by the base station that services the selected cell when the reset request message is received from the wireless device. If a certain amount of time elapses between the time reference used to generate the authentication data in the wireless device and the current time, the reconnection will be rejected. This reduces the risk associated with the same reset request message response by an intruder intercepting a message from a legitimate radio device.</p><p> Another aspect of the present invention relates to a wireless device for communication with a network having a plurality of base stations servicing each cell, and is configured to embody the above-mentioned handover method. This wireless device A sensor that detects a failure of the communication link provided between the wireless device and the source base station, A selector that selects a cell for additional communication with the network when it senses a communication link failure. Generates a reconfiguration request message that includes the identifier of the wireless device, a private key available at the wireless device and the source base station, and authentication data that depends on the identity of the selected cell. Request generator and A transmitter configured to send the reset request message to one of the base stations servicing the selected cell, and including.</p><p> Another aspect of the present invention relates to a base station that services at least one cell to communicate with a wireless device in a wireless communication system and is configured to embody the above handover method. This base station From the source base station of the wireless communication system, the identifier of the wireless device having a communication link with the source base station, the private key available to the wireless device and the source base station, and the target cell serviced by the base station. A network interface configured to receive a first message that includes information for acquiring authentication data for the wireless device, which depends on the identity of the wireless device. A wireless interface configured to receive a reset request message containing the identifier and authentication data of the wireless device from the wireless device located in the target cell. When the wireless device identifier and the authentication data included in the reset request message are matched with the wireless device identifier included in the first message and the authentication data acquired from the first message, a communication link is provided. With the transfer ring handover controller, including.<u style="single">The present invention provides, for example,:</u><u style="single">(Item 1)</u><u style="single"> A handover method in a wireless communication system that includes a plurality of base stations (20) servicing each cell for communicating with a wireless device (10).</u><u style="single"> For at least one target cell, the source base station (20S) to the target base station (20T) that services the target cell, the identifier of the wireless device (10) having a communication link with the source base station, and the wireless device. A first message containing information for acquiring authentication data for the radio device is transmitted, where the authentication data is sent to the secret key available in the radio device and the source base station and the identity of the target cell. Depends on</u><u style="single"> When a failure occurs in the communication link, a cell is selected by the wireless device, and the wireless device performs the identifier of the wireless device and the identifier of the wireless device to one of the base stations that service the selected cell from the wireless device. Send a reconfiguration request message containing the private key and authentication data that depends on the identity of the selected cell.</u><u style="single"> When the selected cell is a target cell serviced by the target base station that has received the first message, the authentication data included in the reset request message and the authentication acquired from the first message. Verify the match with the data and</u><u style="single"> If the match is verified, transfer the communication link to the selected cell.</u><u style="single">Handover methods, including.</u><u style="single">(Item 2)</u><u style="single"> The handover method according to item 1, wherein the authentication data is generated as MAC-I (message authentication code for integrity).</u><u style="single">(Item 3)</u><u style="single"> The handover method according to item 2, wherein the authentication data is calculated using an encryption algorithm based on input parameters including a private key and a target cell identity.</u><u style="single">(Item 4)</u><u style="single"> The input parameter is at least one of the identity of the source cell serviced by the source base station (20S) and the temporary identifier assigned to the wireless device (10) for communication with the source base station on the communication link. The handover method according to item 3, further comprising one.</u><u style="single">(Item 5)</u><u style="single"> The input parameters further include a common time reference between the radio device (10) and each target base station (20T).</u><u style="single"> The handover method according to item 3, wherein the authentication data is calculated by the base station servicing the selected cell when the reset request message is received from the wireless device.</u><u style="single">(Item 6)</u><u style="single"> The authentication data is calculated by the target base station (20T) based on at least a part of the content of the first message received from the source base station (20S), and is compared with the authentication data included in the reset request message. The handover method according to item 1.</u><u style="single">(Item 7)</u><u style="single"> The handover method according to item 1, wherein the authentication data is calculated by the source base station (20S) and transmitted to the target base station for comparison with the authentication data included in the reset request message.</u><u style="single">(Item 8)</u><u style="single"> A wireless device (10) for communication with a network having multiple base stations (20) servicing each cell.</u><u style="single"> A sensor that detects a failure in the communication link provided between the wireless device and the source base station (20S), and</u><u style="single"> A selector that selects a cell for additional communication with the network when it senses a communication link failure.</u><u style="single"> Generates a reconfiguration request message that includes the identifier of the wireless device, a private key available at the wireless device and the source base station, and authentication data that depends on the identity of the selected cell. Request generator and</u><u style="single"> A transmitter configured to send the reset request message to one of the base stations (20T) servicing the selected cell, and</u><u style="single">Including wireless equipment.</u><u style="single">(Item 9)</u><u style="single"> Item 8. The wireless device according to item 8, wherein the authentication data is MAC-I (message authentication code for integrity).</u><u style="single">(Item 10)</u><u style="single"> The authentication data is encrypted based on input parameters including the private key, the identity of the selected cell, and a common time reference between the radio device (10) and at least one of the base stations (20). The wireless device according to item 8 or 9, which is calculated using an algorithm.</u><u style="single">(Item 11)</u><u style="single"> A base station (20T) that serves at least one cell to communicate with a wireless device (10) in a wireless communication system.</u><u style="single"> From the source base station of the wireless communication system, by the identifier of the wireless device (10) having a communication link with the source base station, the secret key available in the wireless device and the source base station, and the base station (20T). A network interface configured to receive a first message that includes information for acquiring authentication data for the wireless device that depends on the identity of the target cell being serviced.</u><u style="single"> A wireless interface configured to receive a reset request message including the identifier and authentication data of the wireless device from the wireless device located in the target cell.</u><u style="single"> When the wireless device identifier and the authentication data included in the reset request message are matched with the wireless device identifier included in the first message and the authentication data acquired from the first message, a communication link is provided. With the transfer ring handover controller,</u><u style="single">Including base stations.</u><u style="single">(Item 12)</u><u style="single"> The base station according to item 11, wherein the authentication data is MAC-I (message authentication code for integrity).</u><u style="single">(Item 13)</u><u style="single"> The authentication data is locally calculated using an encryption algorithm based on input parameters including the private key received from the first message and the target cell identity, and is included in the reset request message. The base station according to item 12, which is compared with the data.</u><u style="single">(Item 14)</u><u style="single"> The input parameters are the identity of the source cell serviced by the source base station (20S) received from the first message and the wireless device (10) for communication with the source base station on a communication link. 13. The base station according to item 13, further comprising at least one of the accidental identifiers assigned to.</u><u style="single">(Item 15)</u><u style="single"> The base station according to item 13 or 14, wherein the input parameter further includes a time reference corresponding to the reception of the reset request message from the wireless device (10).</u></p>
<p> The present invention can provide an effective handover method. The present invention can also provide an effective handover method for recovering from a link failure.</p>
Other objects, features and advantages of the present invention will be described in detail below with reference to the accompanying drawings, but the present invention is not limited to the exemplary examples below.<figref num="1">It is a block diagram which shows the network structure of an E-UMTS (or LTE) system.</figref><figref num="2(a)">It is a block diagram which shows the logical structure of the general network entity of an LTE system.</figref><figref num="2(b)">It is a block diagram which shows the logical structure of the general network entity of a user plane (U-plane) protocol stack.</figref><figref num="2(c)">It is a block diagram which shows the logical structure of the general network entity of the control plane (C-plane) protocol stack (Fig. 2 (c)).</figref><figref num="3">It is a figure which shows the general handover procedure in an LTE system.</figref><figref num="4">Handover procedure in LTE system It is a figure which shows the handover procedure when the failure of the wireless link occurs in the real thing.</figref><figref num="5">It is a figure which shows the other possible method of generating the authentication vector by the Example of this invention.</figref><figref num="6">It is a figure which shows the other possible method of generating the authentication vector by the Example of this invention.</figref>
FIG. 4 shows the handover procedure in the event of a wireless link failure, but this is not limited to the LTE system.
The procedure from the start of the procedure to the step S6 is substantially the same as the procedure described above with reference to FIG. 3, and the description thereof will be omitted. However, when the HANDOVER REQUEST message is sent from the source eNodeB (20S) to the target eNodeB (20T), the handover procedure S4 is to the HANDOVER REQUEST message (or to another message sent with the HANDOVER REQUEST message). Transformed to include information that allows the acquisition of authentication data in the form of an authentication vector, along with the UE 10 identifier to begin with (step S4'). The HANDOVER REQUEST message is received by each target eNodeB (20T) via the network X2 interface.
It is important that HANDOVER REQUEST messages are sent to many target eNodeBs selected in stage S3 to deal with the unpredictability of which eNodeB the UE has selected in the event of a wireless link failure. ..
How many target cells are considered in a given environment is a matter of the handover deterministic algorithm executed by the source eNodeB (20S). Given that the radio measurements reported by the UE reveal that many eNodeBs are good candidates for handing off communications, there is considerable potential for these eNodeBs to be selected by the UE in the event of a wireless link failure. Being of nature, these eNodeBs can make all the preparations for the handover (by setting the handover deterministic algorithm). In other cases, only one eNodeB can exist as a good candidate for handover, in which case the HANDOVER REQUEST message will only be sent to the target eNodeB (20T). However, in the latter case, the HANDOVER REQUEST message is preferably transformed into one containing information for acquiring authentication data, as described above.
In some cases, the initiation of the handover by sending one or more HANDOVER REQUEST messages to one or more target eNodeBs is done without considering any measurements reported by the UE. For example, in a cell located inside a tunnel and serviced by eNodeB using a degraded cable antenna, a UE on a moving vehicle can perform a handover procedure before the network goes out of range of the degraded cable antenna. Network technicians experience a wireless link failure before the UE receives the HANDOVER COMMAND, as it fails so often that it fails to measure from a target cell located outside the tunnel, fast enough to complete. We generally expect that we are quite likely to do so. Also, in such a situation, the network technician will be aware of all possible target cells located at the tunnel exit. Therefore, HANDOVER By sending a REQUEST message to each of the eNodeBs servicing the target cell, the network structure anticipates and systematically initiates a handover procedure to all such possible target cells (step S4'is. , Run simultaneously on such an eNodeB).
The source eNodeB (20S) cannot guarantee that a radio link failure will not occur before the handover is complete, so modification of the HANDOVER REQUEST message containing information for calculating the authentication vector is preferably for any handover scenario. It turns out that it is done in. If the handover is successful, the authentication vector should not be easily used. Therefore, in the case of FIG. 3 (even if there is no wireless link failure), the stage S4 can be changed to the stage S4'.
In the case of Figure 4, the HANDOVER COMMAND message cannot be received by UE 10 due to the radio link failure detected in stage S7'. For example, the radio link failure can be detected by using the user plane RLC / MAC procedure shown in Fig. 2 (b). Both the UE RLC / MAC entity and the eNodeB RLC / MAC entity expect to receive the signal at a known time, and if the signal does not arrive, it can be determined to be a radio link failure.
The source eNodeB (20S) may detect a wireless link failure before or after sending a HANDOVER COMMAND message over the wireless interface. When a HANDOVER COMMAND message is sent, the source eNodeB (20S) is buffered to be sent to the UE, as well as information related to the acknowledgement state of the packet by the UE, and is currently being sent to the UE. Send some or all of a packet to each target eNodeB (20T) selected in step S3 (same as step S8 described with reference to FIG. 3). As shown in Figure 4, if the source eNodeB (20S) detects a radio link failure before sending a HANDOVER COMMAND message, the same step S8 is performed to prepare each selected target cell. be able to.
If UE 10 detects a wireless link failure, it remains in the RRC_CONNECTED state for some time (unless the timer expires), attempts to reselect the cell, and is reselected using the general physical layer connection procedure. Approach the cell. If no cell is connected or reselected before the timer expires, the UE switches to the RRC_IDLE state. If the same (source) eNodeB is selected, the original link is restored and the handover procedure can be resumed, as shown in FIG. If another cell is selected, the UE sends a message to the eNodeB servicing that cell to request that the RRC connection be maintained (step S9'). This message is an RRC CONNECTION REESTABLISHMENT REQUEST message generated by the UE's RRC entity on the C-plane (see Figure 2 (c)) and is transmitted over the wireless interface using the underlying RLC, MAC and PHY protocol layers. Can be done. The message is at least --UE identifier and --- Authentication vector by secret key shared with source eNodeB (20S) and identity of selected cell including.
These items form part of the UE-identity IE (information element) contained in the RRC CONNECTION REESTABLISHMENT REQUEST message. For example, the UE-identity IE includes a C-RNTI used in the source cell as a UE identifier and a MAC-I (message authentication code for integrity) calculated as an authentication vector as shown in FIG. 5 or FIG.
In FIGS. 5 and 6, MAC-I is one of the encryption algorithms available between UE and eNodeB and has complete input parameters including a private key shared between UE 10 and source eNodeB (20S). Calculated using the sex algorithm (100). For example, this private key is used by the integrity algorithm 100 to protect RRC traffic.<sub>RRCint</sub>Can be the key. K<sub>RRCint</sub>The key is a higher level secret key K that can be used for both source eNodeB (20S) and UE 10.<sub>eNB</sub>It is one of the keys derived from.
MAC-I is calculated for the additional input parameters of the integrity algorithm 100, including at least the selected cell ID. Such a cell ID can be the physical layer identity of the selected cell. In particular, in the example of Figure 5, the input parameters of the integrity algorithm 100 are assigned to the UE located in the source cell to communicate with the source eNodeB (20S) over the (faulty) wireless link. It additionally includes the RNTI and the source cell ID, eg, the physical layer identity of the source cell.
In such an embodiment, from the perspective of calculating the authentication vector, the information sent from the source eNodeB (20S) to the respective target eNodeB (20T) in the HANDOVER REQUEST message at stage S4'is UE 10 and source eNodeB ( 20S) Includes a private key shared between (K in this example)<sub>RRCint</sub>Key). If the UE source C-RNTI and / or source cell ID is not provided anywhere in the HANDOVER REQUEST message, the UE source C-RNTI and / or source cell ID will provide some of the information for obtaining the authentication vector. Can be formed.
In Figure 5, it can be seen that the source eNodeB can pre-calculate the MAC-I using the physical layer identity of the target cell, such as the Selected Cell-ID input parameter. In such cases, the information for acquisition of the authentication vector (MAC-I) sent with the HANDOVER REQUEST message is reduced to the MAC-I itself, and of course this information is for multiple target eNodeB (20T). Are staying in the handover decision stage S3, they are distinguished from each other among the target eNodeBs.
In another embodiment of FIG. 6, the input parameters of the integrity algorithm 100 are additionally common between UE 10 and eNodeB 20 (or at least eNodeB (20T) that are candidates for handover). ) Includes time reference. The value of this time reference is the value of the local clock in which a certain synchronization is made between the UE and the network when the algorithm 100 is operated together with the truncation that occurs in the specific validity period of MAC-I.
At stage S9', the RRC CONNECTION REESTABLISHMENT REQUEST message sent by UE 10 is not ready for handover, i.e. not being contacted by the source eNodeB (20S), or approach is denied at stage S5. Received by eNodeB. In such a case, the rejection of the reset request is transmitted to UE 10, which retransmits by selecting another cell and resending another RRC CONNECTION REESTABLISHMENT REQUEST message to the selected other cell. Retry the setting request. If UE 10 does not receive any response to the RRC CONNECTION REESTABLISHMENT REQUEST message at a given time, UE 10 switches to the RRC_IDLE state.
Figure 4 shows the RRC CONNECTION REESTABLISHMENT REQUEST message sent by UE 10 at stage S9'through the wireless interface and the C-plane protocol layer (RRC / RLC / MAC / PHY) shown in Figure 2 (c). The case where the handover is received by the target eNodeB (20T) for which the handover is prepared is shown. The target eNodeB (20T) subsequently verifies in stage S10'whether the authentication vector containing the RRC CONNECTION REESTABLISHMENT REQUEST message matches the authentication vector obtained from the HANDOVER REQUEST message in stage S4'.
If this authentication vector was not received directly from the source eNodeB (20S) through the X2 interface, then on the target eNodeB (20T), the information received from the HANDOVER REQUEST message and the cell where the UE was close, as shown in Figure 5 or Figure 6. It is calculated using the ID of.
As shown in Figure 6, if the input parameter contains a common time reference, the above calculation is performed locally on the target eNodeB (20T) when receiving the RRC CONNECTION REESTABLISHMENT REQUEST message. , The time reference is the same as that commonly used on the UE side. Therefore, if the RRC CONNECTION REESTABLISHMENT REQUEST message received by the target eNodeB (20T) is a message improperly reproduced by an intruder, the MAC-I's own generation in the legitimate UE and the MAC in the target eNodeB (20T) -I Updating the common time reference between calculations causes a mismatch, which rejects the reset request.
Also, if the RRC CONNECTION REESTABLISHMENT REQUEST message is first sent to another cell selected by a legitimate user, then depending on the selected cell ID for MAC-I, the target eNodeB (without any time limit) It is possible to prevent a successful unauthorized response to 20T).
If the authentication vector match is verified in step S10', the handover control function of the target eNodeB (20T) transfers the UE's communication link to the selected target cell as follows.
-Similar to the handover procedure using the same reference signal in Fig. 3, the handover procedure in steps S11 to S15 shown in Fig. 4 should be continued. -After receiving the HANDOVER COMPLETE ACK message from the EPC (step S13), complete the RRC connection reconfiguration by sending an RRC CONNECTION REESTABLISHMENT message to UE 10 in step S16'. UE 10 also responds by returning an RRC CONNECTION REESTABLISHMENT COMPLETE message at stage S17'.
In the embodiment shown in FIG. 4, as soon as the source eNodeB (20S) receives the HANDOVER REQUEST ACKNOWLEDGE message in step S6, it is buffered and the source eNodeB (20S) sends to the target eNodeB (20T) through the X2 interface. Performs packet transmission (step S8) at. Alternatively, if a radio link failure is detected in stage S7', the source eNodeB (20S) waits for an indication that UE 10 has successfully approached the target eNodeB (20T) and has been authenticated. You can also do it. In this example, the target eNodeB (20T), whose authentication vector match was verified in step S10'above, receives a HANDOVER COMPLETE ACK message from the EPC in order to recover the buffered and transmitted data. You can contact the source eNodeB (20S) before or after.
In the above, the embodiment of the present invention has been described by taking up the 3GPP LTE system. Those skilled in the art of wireless communication understand that various modifications can be made without departing from the claims of the present invention and the attachment. Therefore, those skilled in the art will appreciate that the present invention is applicable to other communication systems in addition to the 3GPP LTE system.
As mentioned above, the present invention is applicable to mobile communication systems, broadband communication systems and multiple carrier systems.
The above-mentioned examples of the present invention are merely for explaining the present invention, and those skilled in the art to which the present invention belongs can be provided with the technical idea of the present invention disclosed in the appended claims. It can be understood that various modifications, additions, and deletions can be made within the limits that do not deviate.
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both waysCites: the store holds 2 of 3
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2007060127A1 | Cites | United States of America | Examiner |
| US20070060127A1 | Cites | United States of America | – |
| LG Electronics Inc.,Authentication vector at handover failure,3GPP TSG-RAN WG2 #59, R2-073047,2007年 8月19日,全文、全図 | Non-patent | – | – |
| QUALCOMM Europe,"Shared Secret" for Radio Link Failure Procedure,3GPP TSG-RAN WG2 #59, R2-073299,2007年 8月20日,全文、全図 | Non-patent | – | – |
55 members in 11 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 60955382 | United States of America | – | |
| 95538207 | United States of America | P | |
| 95538207 | United States of America | P | |
| 2008004188 | Republic of Korea | W | |
| 2008004188 | Republic of Korea | W | |
| 2007955382 | – | – | – |
| 2008004188 | – | – | – |
| US20070955382P | – | – | – |
| WO2008KR04188 | – | – | – |
Members55
| Document | Office | Kind | |
|---|---|---|---|
| EP2026617A1 | European Patent Office (EPO) | A1 | |
| WO2009022795A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2009022796A2 | World Intellectual Property Organization (WIPO) | A2 | |
| EP2028890A1 | European Patent Office (EPO) | A1 | |
| US2009052420A1 | United States of America | A1 | |
| US2009061878A1 | United States of America | A1 | |
| TW200913748A | Taiwan Province of China | A | |
| WO2009022795A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2009022796A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW200926851A | Taiwan Province of China | A | |
| EP2026617B1 | European Patent Office (EPO) | B1 | |
| AT438274T | Austria | T | |
| ATE438274T1 | Austria | T1 | |
| EP2091281A1 | European Patent Office (EPO) | A1 | |
| DE602008000062D1 | Germany | D1 | |
| US2009296637A1 | United States of America | A1 | |
| ES2330276T3 | Spain | T3 | |
| EP2091281B1 | European Patent Office (EPO) | B1 | |
| AT458370T | Austria | T | |
| ATE458370T1 | Austria | T1 | |
| DE602008000672D1 | Germany | D1 | |
| ES2337633T3 | Spain | T3 | |
| CN101779391A | China | A | |
| JP2010524329A | Japan | A | |
| CN101785214A | China | A | |
| US7792130B2 | United States of America | B2 | |
| JP2011511480A | Japan | A | |
| RU2427105C1 | Russian Federation | C1 | |
| US2011299476A1 | United States of America | A1 | |
| JP4863530B2This record | Japan | B2 | |
| TWI363571B | Taiwan Province of China | B | |
| JP2012095305A | Japan | A | |
| TW201223301A | Taiwan Province of China | A | |
| JP5063781B2 | Japan | B2 | |
| TWI377818B | Taiwan Province of China | B | |
| CN101779391B | China | B | |
| JP5142417B2 | Japan | B2 | |
| CN101785214B | China | B | |
| US8681694B2 | United States of America | B2 | |
| TWI448171B | Taiwan Province of China | B | |
| US8913608B2 | United States of America | B2 | |
| US2015043514A1 | United States of America | A1 | |
| US9319935B2 | United States of America | B2 | |
| US2016192253A1 | United States of America | A1 | |
| BRPI0815152A2 | Brazil | A2 | |
| US2016366611A1 | United States of America | A1 | |
| US9549353B2 | United States of America | B2 | |
| US9992716B2 | United States of America | B2 | |
| EP2028890B1 | European Patent Office (EPO) | B1 | |
| US10440609B2 | United States of America | B2 | |
| US2019394677A1 | United States of America | A1 | |
| BRPI0815152B1 | Brazil | B1 | |
| US11089509B2 | United States of America | B2 | |
| US2021337429A1 | United States of America | A1 | |
| US11653265B2 | United States of America | B2 |
28 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Written request for registration of change of domicileJAPANESE INTERMEDIATE CODE: R313531S531 | S531 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 |
Numbers
- Publication
- 4863530
- Publication, DOCDB
- 4863530
- Publication, EPODOC
- JP4863530B
- Application
- 2010502037
- Application, DOCDB
- 2010502037
- Application, EPODOC
- JP20100502037
Titles2
- Japanese
- リンク障害復旧のためのハンドオーバー方法とこの方法を具現するための無線機器及び基地局
- English
- Handover method for link failure recovery and wireless devices and base stations to embody this method
Classification
- CPC, 20
- H04L69/04
- H04W28/0252
- H04L47/38
- H04W28/0278
- H04W36/0094
- H04W72/52
- H04W72/21
- G08C17/02
- G08C2201/32
- H04W8/04
- H04W72/23
- H04L47/10
- H04L47/263
- H04L47/30
- H04L47/33
- H04W28/12
- H04W28/06
- H04W88/02
- H04W28/065
- H04W88/08
- IPC, 3
- H04W36 08
- H04L47 30
- H04W12 06
