Method for negotiating security capability when terminal moves
17 claims: 4 independent, 13 dependent
- 1端末が移動するときにセキュリティ機能を折衝するための方法であって、移動局(UE)が、第2/第3世代(2G/3G)ネットワークからロングタームエボリューション(LTE)ネットワークに移動するとき、 移動性管理エンティティ(MME)が、前記UEから送られたトラッキングエリアアップデート(TAU)要求メッセージを受け取り、かつ前記UEによりサポートされる非アクセスシグナリング(NAS)セキュリティアルゴリズムと、認証ベクトル関連鍵、もしくは前記認証ベクトル関連鍵により導出されるルート鍵とを取得するステップと、 前記MMEが、前記UEによりサポートされる前記NASセキュリティアルゴリズムに従ってNASセキュリティアルゴリズムを選択し、前記認証ベクトル関連鍵または前記ルート鍵によりNAS保護鍵を導出し、かつ前記選択されたNASセキュリティアルゴリズムを運ぶメッセージを前記UEに送るステップと、 前記UEが、その認証ベクトル関連鍵によりNAS保護鍵を導出するステップとを含む方法。
- 2前記MMEが前記UEによりサポートされる前記NASセキュリティアルゴリズムを取得する前記ステップが、 前記MMEが、前記UEから送られた前記TAU要求メッセージから、前記UEによりサポートされるセキュリティ機能情報を取得するステップを含み、前記TAU要求メッセージが、前記UEによりサポートされる前記NASセキュリティアルゴリズムを含む、請求項1に記載の方法。
- 3前記MMEが前記UEによりサポートされる前記NASセキュリティアルゴリズムを取得する前記ステップが、 前記MMEが、サービス汎用パケット無線サービス(GPRS)サポートノード(SGSN)から送られた移動性管理コンテキスト応答メッセージから、前記UEによりサポートされるセキュリティ機能情報を取得するステップを含み、前記移動性管理コンテキスト応答メッセージが、前記UEによりサポートされる前記NASセキュリティアルゴリズムを含む、請求項1に記載の方法。
- 4前記MMEが前記認証ベクトル関連鍵を取得する前記ステップが、 前記MMEが、SGSNから送られた移動性管理コンテキスト応答メッセージから、前記認証ベクトル関連鍵を取得するステップを含み、また 前記MMEが、前記認証ベクトル関連鍵により導出される前記ルート鍵を取得する前記ステップが、 前記MMEが、前記SGSNから送られた前記移動性管理コンテキスト応答メッセージから、前記認証ベクトル関連鍵により導出される前記ルート鍵を取得するステップを含む、請求項1に記載の方法。
- 5前記SGSNが、前記2GネットワークのSGSNであるとき、前記認証ベクトル関連鍵は少なくとも、暗号化鍵Kc、または前記暗号化鍵Kcに対して一方向変換が行われた後に得られた値を含み、あるいは 前記SGSNが、前記3GネットワークのSGSNであるとき、前記認証ベクトル関連鍵は少なくとも、完全性鍵IKおよび暗号化鍵CKを、または前記IKおよび前記暗号化鍵CKに対して一方向変換が行われた後に得られた値を含む、請求項4に記載の方法。
- 6前記SGSNが、前記2GネットワークのSGSNであるとき、前記認証ベクトル関連鍵により導出される前記ルート鍵が、暗号化鍵Kc、または前記暗号化鍵Kcに基づいて一方向に変換された値により前記SGSNによって導出されて、次いで、前記MMEに送られ、あるいは 前記SGSNが、前記3GネットワークのSGSNであるとき、前記認証ベクトル関連鍵により導出される前記ルート鍵が、完全性鍵IKおよび暗号化鍵CK、または前記完全性鍵IKおよび前記暗号化鍵CKに対して一方向変換が行われた後に得られた値により前記SGSNによって導出されて、次いで、前記MMEに送られる、請求項4に記載の方法。
- 7前記MMEが前記認証ベクトル関連鍵により導出される前記ルート鍵を取得する前記ステップが、 前記MMEが、認証および鍵共有(AKA)手順を介して、前記認証ベクトル関連鍵により導出される前記ルート鍵を直接取得するステップを含む、請求項1に記載の方法。
- 8前記MMEおよび前記UEがそれぞれ、前記認証ベクトル関連鍵により前記NAS保護鍵を導出する前記ステップが、 前記MMEおよび前記UEが、前記認証ベクトル関連鍵により前記ルート鍵を導出し、次いで、前記導出されたルート鍵により前記NAS保護鍵を導出するステップを含む、請求項1に記載の方法。
- 9前記MMEが前記選択されたNASセキュリティアルゴリズムを運ぶメッセージを前記UEに送る前記ステップの前に、 前記MMEが前記選択されたNASセキュリティアルゴリズムを運ぶ前記メッセージに対して完全性保護を実施するステップと、 前記UEが、前記選択されたNASセキュリティアルゴリズムを運ぶ前記メッセージを受け取った後に、前記選択されたNASセキュリティアルゴリズムを運ぶ前記メッセージに対して実施された前記完全性保護が、前記導出されたNAS保護鍵に従って正しいかどうかを検出するステップとをさらに含む、請求項1に記載の方法。
- 10前記選択されたNASセキュリティアルゴリズムを運ぶ前記メッセージが、前記UEによりサポートされる前記セキュリティ機能情報をさらに運び、また 前記UEが、前記受け取った前記UEによりサポートされるセキュリティ機能情報が、前記UEにサポートされたセキュリティ機能情報と矛盾していないかどうかを判定することにより、劣化攻撃が行われたかどうかを判定するステップをさらに含む、請求項2に記載の方法。
- 11前記選択されたNASセキュリティアルゴリズムを運ぶ前記メッセージが、前記UEによりサポートされる前記セキュリティ機能情報をさらに運び、また 前記UEが、前記受け取った前記UEによりサポートされるセキュリティ機能情報が、前記UEによりサポートされるセキュリティ機能情報と矛盾していないかどうかを判定することにより、劣化攻撃が行われたかどうかを判定するステップをさらに含む、請求項3に記載の方法。
- 12端末が移動するときにセキュリティ機能を折衝するためのシステムであって、移動局(UE)と移動性管理エンティティ(MME)とを備え、 前記UEが、トラッキングエリアアップデート(TAU)要求メッセージを前記MMEに送り、前記MMEから送られた、選択された非アクセスシグナリング(NAS)セキュリティアルゴリズムを運ぶメッセージを受け取り、認証ベクトル関連鍵によりNAS保護鍵を導出するように適合されており、 前記MMEが、前記UEから送られた前記TAU要求メッセージを受け取り、認証ベクトル関連鍵、もしくは前記認証ベクトル関連鍵により導出されるルート鍵と、前記UEによりサポートされるNASセキュリティアルゴリズムとを取得し、前記UEによりサポートされる前記NASセキュリティアルゴリズムに従ってNASセキュリティアルゴリズムを選択して、前記選択されたNASセキュリティアルゴリズムを運ぶメッセージを生成して前記UEに送信し、前記取得された認証ベクトル関連鍵もしくは前記ルート鍵によりNAS保護鍵を導出するように適合される、システム。
- 13前記MMEがさらに、前記UEによりサポートされるセキュリティ機能情報を取得し、前記UEに送られる前記選択されたNASセキュリティアルゴリズムを運ぶメッセージ中で、前記UEによりサポートされる前記セキュリティ機能情報を搬送し、 前記UEがさらに、前記MMEから送られた前記UEによりサポートされる前記セキュリティ機能情報が、前記UEによりサポートされるセキュリティ機能と矛盾していないかどうかを判定することにより、劣化攻撃が行われたかどうかを判定する、請求項12に記載のシステム。
- 14取得モジュール、選択モジュール、および鍵導出モジュールを備え、 前記取得モジュールが、移動局(UE)から送られたトラッキングエリアアップデート(TAU)要求メッセージを受け取り、認証ベクトル関連鍵、もしくは前記認証ベクトル関連鍵により導出されるルート鍵と、前記UEによりサポートされる非アクセスシグナリング(NAS)セキュリティアルゴリズムとを取得するように適合され、 前記選択モジュールが、前記UEによりサポートされ、かつ前記取得モジュールにより取得された前記NASセキュリティアルゴリズムに従ってNASセキュリティアルゴリズムを選択し、前記選択されたNASセキュリティアルゴリズムを運ぶメッセージを生成して前記UEに送信するように適合され、 前記鍵導出モジュールが、前記取得モジュールにより取得された、前記認証ベクトル関連鍵、もしくは前記認証ベクトル関連鍵により導出される前記ルート鍵と、前記選択モジュールにより選択された前記NASセキュリティアルゴリズムとにより、NAS保護鍵を導出するように適合される移動性管理エンティティ(MME)。
- 15前記取得モジュールが、前記UEによりサポートされるセキュリティ機能情報をさらに取得し、また前記選択モジュールが、前記選択されたNASセキュリティアルゴリズムを運ぶ前記メッセージ中で、前記UEによりサポートされ、かつ前記取得モジュールにより取得された前記セキュリティ機能情報をさらに搬送する、請求項14に記載のMME。
- 16更新モジュール、鍵導出モジュール、ストレージモジュール、および検出モジュールを備え、 前記更新モジュールが、前記UEによりサポートされ、かつ前記ストレージモジュール中に記憶されたセキュリティ機能情報を運ぶトラッキングエリアアップデート(TAU)要求メッセージを移動性管理エンティティ(MME)に送り、また前記MMEから送られた、選択された非アクセスシグナリング(NAS)セキュリティアルゴリズムを運ぶメッセージを受け取るように適合され、 前記鍵導出モジュールが、認証ベクトル関連鍵、および前記更新モジュールにより受信された前記NASセキュリティアルゴリズムによりNAS保護鍵を導出するように適合され、 前記ストレージモジュールが、前記UEによりサポートされる前記セキュリティ機能情報を記憶するように適合され、 前記検出モジュールが、前記UEによりサポートされかつ前記MMEから受け取ったセキュリティ機能情報が、前記UEによりサポートされかつ前記ストレージモジュールに記憶された前記セキュリティ機能情報と矛盾していることを検出した場合、劣化攻撃が行われたと判定するように適合される移動局(UE)。
- 17前記MMEから送られた、前記選択されたNASセキュリティアルゴリズムを運ぶ前記メッセージが、前記UEによりサポートされるセキュリティ機能情報をさらに運ぶ、請求項16に記載のUE。
Independent claims17
78 paragraphs, as filed
Cross-reference of related applications This application claims priority to Chinese Patent Application No. 200710145703.3 filed on August 31, 2007 and Chinese Patent Application No. 200710151700.0 filed on September 26, 2007. It is a continuation of International Application No. PCT / CN 2008/072165 filed in, all of which are incorporated herein by reference in their entirety.
The present invention relates to the field of wireless communication technology, and more specifically, methods and systems for negotiating security functions when a terminal moves, MME (mobility management entity), and UE (user equipment). : Mobile station).
Radio networks include radio access networks and core networks. The core network of LTE (long term evolution) wireless networks includes MME. MME has similar functions to those of SGSN (service GPRS (general packet radio service) support node) of 2nd and 3rd generation (2G / 3G) networks, and mainly handles mobility management and user authentication. Handle. In a 2G / 3G or LTE wireless network, when the UE is idle, the UE will be with SGSN or MME, respectively, and NAS (non-access). signaling: Non-access signaling) Security features need to be negotiated. Security features include a NAS signaling encryption algorithm, a corresponding NAS integrity protection key Knas-int, a NAS integrity protection algorithm, and a corresponding NAS confidentiality protection key Knas-enc, which are between the UE and the system. It is used for signaling transmission, which can ensure the normal reception of UE signaling and the security of the communication system.
When a UE accessing 2G GERAN (global system for mobile communications) edge radio access network (GSM) or 3G UTRAN (UMTS (universal mobile telecommunications system) terrestrial radio access network) goes idle, the UE becomes , The LTE radio access network can be moved to the tracking area, so the UE can access the network again via LTE. At this point, TAU (tracking area) update: Tracking area update) The procedure is performed, that is, the TAU procedure is performed between heterogeneous networks. During the procedure, the entity that negotiates security features for the UE will change, for example, from SGSN to MME, and the entity may have different security features, so the security of subsequent interactions between the UE and the network. To ensure, it is necessary to repeat the security function negotiation procedure. For LTE networks, security feature negotiations include NAS integrity protection algorithms and NAS integrity protection algorithms, RRC (radio resource control) confidentiality protection algorithms and RRC integrity protection algorithms, and UP (user plane) confidentiality. Note that it involves negotiation of protection algorithms.
For TAU procedures initiated by an idle UE, NAS confidentiality protection algorithms, NAS integrity protection algorithms, and corresponding NAS protection key negotiations need to be resolved.
During the implementation of the present invention, the present inventor has not found in the prior art a method for negotiating security features during the TAU procedure between heterogeneous networks, thus allowing the UE to move from a 2G / 3G network to an LTE network. When moving to, we found that we could not negotiate security features and could not guarantee the security of subsequent interactions between the UE and the network.
<p> Therefore, the present invention targets a method for negotiating security functions when a terminal moves, and allows an idle UE to negotiate security functions when moving from a 2G / 3G network to an LTE network. ..</p><p> The present invention further targets a system for negotiating security functions when a terminal moves, allowing an idle UE to negotiate security functions when moving from a 2G / 3G network to an LTE network.</p><p> The present invention further targets MMEs, allowing idle UEs to negotiate security features when moving from a 2G / 3G network to an LTE network.</p><p> The present invention further targets UE devices, allowing idle UEs to negotiate security features when moving from a 2G / 3G network to an LTE network.</p>
<p> In order to achieve the objects, the technical solution of the present invention is implemented as follows.</p><p> A method for negotiating security features as the terminal moves is provided, which method involves the following steps:</p><p> The MME receives the TAU request message sent from the UE and obtains the NAS security algorithm supported by the UE and the authentication vector-related key or the root key derived from the authentication vector-related key.</p><p> The MME selects the NAS security algorithm according to the NAS security algorithm supported by the UE, derives the NAS protection key by the authentication vector related key or the root key, and sends a message to the UE carrying the selected NAS security algorithm.</p><p> The UE derives the NAS protection key from the authentication vector related key.</p><p> A system is provided for negotiating security features as the terminal moves, including UE and MME.</p><p> The UE sends a TAU request message to the MME, receives a message from the MME carrying the selected NAS security algorithm, and is adapted to derive the NAS protection key with the authentication vector associated key.</p><p> The MME receives the TAU request message sent from the UE, obtains the authentication vector related key or the root key derived by the authentication vector related key, and the NAS security algorithm supported by the UE, and is supported by the UE. Adapts to select a NAS security algorithm according to the NAS security algorithm, generate a message carrying the selected NAS security algorithm, send it to the UE, and derive the NAS protection key with the obtained authentication vector related key or root key. Will be done.</p><p> An MME is provided that includes an acquisition module, a selection module, and a key derivation module.</p><p> The acquisition module receives the TAU request message sent from the UE and is adapted to acquire the authentication vector-related key, or the root key derived from the authentication vector-related key, and the NAS security algorithm supported by the UE. ..</p><p> The selection module is supported by the UE and is adapted to select the NAS security algorithm according to the NAS security algorithm acquired by the acquisition module, generate a message carrying the selected NAS security algorithm, and send the message to the UE. The algorithm.</p><p> The key derivation module is adapted to derive the NAS protection key by the authentication vector related key acquired by the acquisition module or the root key derived by the authentication vector related key and the NAS security algorithm selected by the selection module. Will be done.</p><p> A UE is provided that includes an update module, a key derivation module, a storage module, and a discovery module.</p><p> The update module now sends a TAU request message to the MME that carries the security feature information supported by the UE and stored in the storage module, and also receives a message from the MME carrying the selected NAS security algorithm. It is adapted.</p><p> The key derivation module is adapted to derive the NAS protection key by the authentication vector associated key and the NAS security algorithm received by the update module.</p><p> The storage module is adapted to store security feature information supported by the UE.</p><p> If the detection module detects that the security feature information supported by the UE and received from the MME is inconsistent with the security feature information supported by the UE and stored in the storage module, a degradation attack is launched. It is adapted to determine that it has been done.<u style="single"> The present invention is also a method for negotiating security functions when a terminal moves, in which a mobile station (UE; user equipment) is a long-term evolution from a 2nd / 3rd generation (2G / 3G) network. (LTE; long term evolution) When moving to a network</u><u style="single"> A mobility management entity (MME) receives a tracking area update (TAU) request message sent by the UE and is non-access signaling (NAS) supported by the UE. signaling) The step of acquiring the security algorithm and the authentication vector-related key or the root key derived from the authentication vector-related key, and</u><u style="single"> A message in which the MME selects a NAS security algorithm according to the NAS security algorithm supported by the UE, derives a NAS protection key by the authentication vector related key or the root key, and carries the selected NAS security algorithm. Is a method including a step of sending the message to the UE.</u></p><p> In the technical solution of the present invention, the MME receives the TAU request message sent from the UE, the authentication vector related key, or the root key derived by the authentication vector related key, and the NAS security algorithm supported by the UE. And then select the NAS security algorithm according to the NAS security algorithm supported by the UE, generate a message carrying the selected NAS security algorithm, and send the message to the UE, thereby the UE and Allows MMEs to share NAS security algorithms. In addition, the MME derives the NAS protection key with the authentication vector-related key, or the root key derived with the authentication vector-related key, and the UE derives the NAS protection key with the authentication vector-related key, thereby the MME and. Allows UEs to share NAS protection keys. In this way, when moving from a 2G / 3G network to an LTE network, the UE can negotiate the NAS security algorithm and NAS protection key with the MME, and thus the security function negotiation process in the TAU procedure between heterogeneous networks. Is achieved, thereby ensuring the security of subsequent dialogue between the UE and the network.</p><p> Furthermore, the present invention can also be applied to security function negotiation procedures when a UE moves within an LTE network.</p>
<figref num="1">It is a flow chart of the method by 1st Embodiment of this invention for negotiating a security function when a terminal moves.</figref><figref num="2">It is a flow chart of the method by the 2nd Embodiment of this invention for negotiating a security function when a terminal moves.</figref><figref num="3">It is a flow chart of the method by the 3rd Embodiment of this invention for negotiating a security function when a terminal moves.</figref><figref num="4">FIG. 5 is a structural diagram of a system according to an embodiment of the present invention for negotiating a security function when a terminal moves.</figref>
In the method provided in the embodiments of the present invention for negotiating security functions when the terminal moves, when the UE moves from the 2G / 3G network to the LTE network, the MME is sent from the UE. Receive the TAU request message and get the NAS security algorithm supported by the UE and the authentication vector related key or the root key derived by the authentication vector related key. The MME then selects the NAS security algorithm according to the NAS security algorithm supported by the UE, derives the NAS protection key by the authentication vector related key or the root key derived by the authentication vector related key, and selects the NAS. Send a message to the UE carrying the security algorithm. The UE derives the NAS protection key from the authentication vector related key.
Embodiments of the present invention will be described in detail below with reference to the specific embodiments and the accompanying drawings.
Suppose the UE goes idle after accessing UTRAN / GERAN. In this case, when moving to the LTE network tracking area, the UE initiates the TAU procedure.
FIG. 1 is a flow chart of a method according to the first embodiment of the present invention for negotiating a security function when a terminal moves. With reference to FIG. 1, the method includes the following steps.
At step 100, the UE sends a TAU request to the MME.
In this step, the UE sends a TAU request to the new MME via the LTE radio access network eNB (evolved Node B). For convenience of explanation, the communication between the UE and the MME via the eNB is simplified to the communication between the UE and the MME in the following description.
In this step, the TAU request sent from the UE to the MME not only carries some parameters such as TMSI (temporary mobile subscriber identity) known to those skilled in the art, but is also supported by the UE. Security function information can also be carried. Security feature information includes NAS security algorithms (NAS integrity protection algorithms and / or NAS confidentiality protection algorithms) and RRC security algorithms (RRC integrity protection algorithms and / or RRC confidentiality protection algorithms), or UP security algorithms. (Confidentiality protection algorithm) can also be included.
In steps 101-102, the MME acquires the NAS security algorithm supported by the UE and sends a mobility management context request message to the SGSN. After receiving the message, the SGSN sends a mobility management context response message to the MME carrying the authentication vector associated key.
In step 100, if the UE does not convey the NAS security algorithm supported by the UE in the TAU request sent to the MME, the SGSN will be supported by the UE after receiving the mobility management context request message. Queries the NAS security algorithm and carries the NAS security algorithm supported by the queried UE in the mobility management context response message sent to the MME. NAS security algorithms are NAS integrity protection algorithms and / or NAS confidentiality protection algorithms.
When the UE moves from the 2G network to the tracking area of the LTE network, the SGSN in the above process is the SGSN of the 2G network, and the authentication vector related key is at least a one-way conversion to the encryption key Kc, or Kc. Includes the value Kc'obtained after When the UE moves from the 3G network to the tracking area of the LTE network, the SGSN of the above process is the SGSN of the 3G network, and the authentication vector related keys are at least the integrity key IK and the encryption key CK, or IK and Includes the values IK'and CK' after a one-way conversion to CK.
One-way conversion refers to a conversion procedure in which the original parameters are converted by using a specific algorithm in order to obtain the target parameters, but the original parameters cannot be obtained due to the target parameters. For example, for Kc, Kc'is obtained by using the algorithm f (Kc), but if Kc cannot be derived from Kc' using any inverse transformation algorithm, the transformation is a one-way transformation.
In step 103, the MME selects the new NAS security algorithm according to the NAS security algorithm supported by the UE, the NAS security algorithm supported by the MME, and the NAS security algorithm allowed by the system, and by the authentication vector associated key. The root key Kasme is derived, and then the NAS protection key is derived by Kasme. NAS protection keys include the NAS integrity protection key Knas-int and / or the NAS confidentiality protection key Knas-enc.
At step 104, the MME generates a TAU acceptance message carrying the selected NAS security algorithm.
At this step, MME can also implement NAS integrity protection for TAU acceptance messages. For example, the MME follows the NAS integrity protection key Knas-int obtained in step 103, the information in TAU acceptance, and the NAS integrity protection algorithm in the selected NAS security algorithm, and the NAS integrity protection message authentication code ( The value of NAS-MAC) is derived, then the value is carried by the TAU acceptance message, and the TAU acceptance message is sent to the UE.
The TAU acceptance message in this step can also carry security feature information supported by the UE.
In step 105, the UE receives a TAU acceptance message carrying the NAS security algorithm selected by the MME, obtains the negotiated NAS security algorithm, and then its current authentication vector associated key (eg, the original network is 3G). If, then IK and CK, or IK'and CK' derived by IK and CK, or if the original network is 2G, then Kc or Kc' derived by Kc) to derive the root key Kasme. Then, the NAS protection key is derived from the root key. NAS protection keys include the NAS integrity protection key Knas-int and / or the NAS confidentiality protection key Knas-enc.
At this step, the UE can also detect if the integrity protection provided for the TAU acceptance message is correct. If it is incorrect, the current security function negotiation can be determined to have failed and the security function negotiation procedure can be restarted. For example, the UE derives the NAS-MAC by the derived NAS confidentiality protection key Knas-enc, the information in TAU acceptance, and the NAS integrity protection algorithm carried in the TAU acceptance message, and then the derived NAS. -Compare whether the MAC is the same as the NAS-MAC carried in the TAU acceptance message. If they are the same, it indicates that the message has not changed during transmission, but if they are not the same, it is considered that the message has been changed during transmission, and therefore the current security function negotiation has failed. Will be done.
In step 104, if the TAU acceptance message further carries security feature information supported by the UE, then in this step the UE further carries security feature information supported by the UE and carried in the TAU acceptance message. It can be compared with the security function information stored in. If the two do not contradict each other, it is determined that no degradation attack has been performed, otherwise it has been determined that a degradation attack has occurred and the current security function negotiation has failed. The security function negotiation procedure can be restarted, thereby preventing degradation attacks.
Against degradation attacks, the UE has two security algorithms: the high strength algorithm A1 and the low strength algorithm. strength) Algorithm A2 is supported at the same time, and MME is also assumed to support algorithm 2. In this method, the high intensity algorithm A1 should be negotiated between the UE and MME. However, if the UE changes the security function information of the UE in the path of sending the security function information supported by the UE to the MME, for example, only the low-strength algorithm A2 is maintained, or When the MME chooses the NAS security algorithm, if the security feature information supported by the UE is modified by the attacker and only the low-strength algorithm A2 is maintained, the MME chooses the low-strength algorithm A2 and chooses it. It can only be sent to the UE. That is, through negotiations between the UE and MME, a low-intensity algorithm A2, rather than a high-intensity algorithm A1, is obtained, thus allowing an attacker to make an attack more easily, which is the so-called degradation attack. Is. In the embodiment of the present invention, the MME sends the security function information supported by the UE to the UE, and the UE sends the security function information supported by the UE inconsistent with the security function information supported by the UE. Detects if not, thereby detecting and further stopping degradation attacks.
The procedure by which the MME finally derives the NAS protection key with the authentication vector-related key in step 103 is not limited to any temporal order with respect to step 104 and step 105, and the procedure is prior to step 104. Can be performed in, or can be performed between steps 104 and 105, or after step 105.
In the above process, MME and UE can also derive the NAS protection key directly by the authentication vector related key without having to derive the root key and then derive the NAS protection key by the root key. ..
In the above process, the derivation method used by the UE to derive the NAS protection key with the authentication vector-related key is the same as the method used on the network side to derive the NAS protection key with the authentication vector-related key. If you are a trader, please understand that you have to. Derivation methods include arbitrary one-way transformations, such as Kasme = f (IK, CK, other parameters), Knas-enc = f (Kasme, NAS confidentiality algorithm, other parameters), and Knas-int = f. (Kasme, NAS integrity protection algorithm, other parameters) can be used.
Further, to highlight this embodiment of the invention, non-security related procedures have been excluded between steps 102 and 104 in the above process.
Through the above process, UE and MME can share NAS security algorithm and NAS protection key, thereby negotiating NAS security functions.
FIG. 2 is a flow chart of a method according to a second embodiment of the present invention for negotiating a security function when a terminal moves. With reference to FIG. 2, the method includes the following steps.
Step 200 is the same as step 100 and therefore its description is excluded here.
In steps 201-203, the MME acquires the NAS security algorithm supported by the UE and sends a context request message to the SGSN. After receiving the context request message, the SGSN derives the root key with its authentication vector associated key and then sends a context response message carrying the root key to the MME.
In another embodiment of the invention, in step 200, if the UE does not convey the NAS security algorithm supported by the UE in the TAU request sent to the MME, after receiving the mobility management context request message. , SGSN queries the NAS security algorithms supported by the UE and carries the NAS security algorithms supported by the queried UE in the mobility management context response message sent to the MME. NAS security algorithms are NAS integrity protection algorithms and / or NAS confidentiality protection algorithms.
When the UE moves from the 2G network to the tracking area of the LTE network, the SGSN in the above process is the SGSN of the 2G network, and the root key is either by Kc or after a one-way conversion to Kc. It is the root key Kasme derived by SGSN by the acquired Kc'. When the UE moves from the 3G network to the tracking area of the LTE network, the SGSN of the above process is the SGSN of the 3G network, and the root key is unidirectionally converted to IK and CK, or IK and CK. Kasme derived by SGSN by the subsequent IK'and CK'.
In step 204, the MME selects the new NAS security algorithm according to the NAS security algorithm supported by the UE, the NAS security algorithm supported by the MME, and the NAS security algorithm allowed by the system, and then by the root key. Derive the NAS protection key. NAS protection keys include the NAS integrity protection key Knas-int and / or the NAS confidentiality protection key Knas-enc.
At step 205, the MME generates a TAU acceptance message carrying the selected NAS security algorithm.
At this step, MME can also implement NAS integrity protection for TAU acceptance messages. The TAU acceptance message in this step can also carry security feature information supported by the UE.
At step 206, the UE receives a TAU acceptance message carrying the NAS security algorithm selected by the MME, obtains the negotiated NAS security algorithm, and then its current authentication vector associated key (eg, the original network is 3G). If, then IK and CK, or IK'and CK' derived by IK and CK, or if the original network is 2G, then Kc or Kc' derived by Kc) to derive the root key Kasme. Then, the NAS protection key is derived from the root key. NAS protection keys include the NAS integrity protection key Knas-int and / or the NAS confidentiality protection key Knas-enc.
At this step, the UE can also detect if the integrity protection provided for the TAU acceptance message is correct. If it is incorrect, the current security function negotiation can be determined to have failed and the security function negotiation procedure can be restarted.
In another embodiment of the invention, if in step 205 the TAU acceptance message further carries security feature information supported by the UE, then in this step the UE is further carried in the TAU acceptance message, supported by the UE. The security function information provided can be compared with the security function information supported by the UE. If the two do not contradict each other, it is determined that no degradation attack has been performed, otherwise it has been determined that a degradation attack has occurred and the current security function negotiation has failed. The security function negotiation procedure can be restarted, thereby preventing degradation attacks.
In another embodiment of the invention, the procedure by which the MME derives the NAS protection key by the root key in step 204 is not limited to any temporal order with respect to steps 205 and 206. It can be performed before step 205, or between step 205 and step 206, or after step 206.
In the above process, the derivation method used by the UE to derive the NAS protection key with the authentication vector-related key is the method used on the network side to derive the NAS protection key with the authentication vector-related key. Those in the industry should understand that they must be the same.
Through the above process, UE and MME can share NAS security algorithm and NAS protection key, thereby negotiating NAS security functions.
FIG. 3 is a flow chart of a method according to a third embodiment of the present invention for negotiating a security function when a terminal moves. With reference to FIG. 3, the method includes the following steps.
Step 300 is the same as step 100 and therefore its description is excluded here.
In steps 301-302, the MME obtains the NAS security algorithm supported by the UE from the SGSN via the mobility management context request and response message.
In another embodiment of the invention, in step 300, if the UE does not convey the NAS security algorithm supported by the UE in the TAU request sent to the MME, after receiving the mobility management context request message. , SGSN queries the NAS security algorithms supported by the UE and carries the NAS security algorithms supported by the queried UE in the mobility management context response message sent to the MME. NAS security algorithms are NAS integrity protection algorithms and / or NAS confidentiality protection algorithms.
In step 303, the MME obtains the root key Kasme derived from the HSS (home subscriber server) by the authentication vector related key via the AKA (authentication and key agreement) procedure. ..
In step 304, the MME selects the new NAS security algorithm according to the NAS security algorithm supported by the UE, the NAS security algorithm supported by the MME, and the NAS security algorithm allowed by the system, and then by Kasme and others. To derive the NAS protection key of. NAS protection keys include the integrity protection key Knas-int and the NAS confidentiality protection key Knas-enc.
In step 305, the MME generates a NAS SMC (security mode command) request message carrying the selected NAS security algorithm and sends it to the UE. SMC request messages can be carried in TAU acceptance messages.
At this step, the MME can also implement NAS integrity protection for SMC acceptance messages. For example, the MME uses the NAS integrity protection key Knas-int obtained in step 304, the information in the SMC request message, and the NAS integrity protection algorithm in the selected NAS security algorithm to authenticate the NAS integrity protection message. It derives the value of the code (NAS-MAC), then carries that value in the SMC request message and sends the SMC request message to the UE.
The SMC request message in this step can also carry security feature information supported by the UE.
At step 306, the UE receives an SMC request message carrying the NAS security algorithm selected by the MME, obtains the NAS security algorithm supported by the UE and selected by the MME, and then obtains the current obtained in that AKA procedure. The root key is derived by the authentication vector related key of, and the NAS protection key is derived by the root key. NAS protection keys include the NAS integrity protection key Knas-int and the NAS confidentiality protection key Knas-enc.
In this embodiment, in this step the UE can further detect whether the integrity protection provided for the TAU acceptance message is correct. If it is incorrect, the current security function negotiation can be determined to have failed and the security function negotiation procedure can be restarted. For example, the UE derives the NAS-MAC with the derived NAS confidentiality protection key Knas-enc, the information in the TAU acceptance message, and the NAS integrity protection algorithm carried in the TAU acceptance message, and then derives. Compare whether the NAS-MAC is the same as the NAS-MAC carried in the TAU acceptance message. If they are the same, it indicates that the message has not changed during transmission, but if they are not the same, it is considered that the message has been changed during transmission, and therefore the current security function negotiation has failed. Will be done.
In another embodiment of the invention, if in step 305 the SMC request message further carries security feature information supported by the UE, then in this step the UE is further supported by the UE and in the SMC request message. The security function information carried can be compared with the security function information supported by the UE. If the two are consistent with each other, it is determined that no degradation attack has been performed, and if they are not, a degradation attack has been conducted and the current security function negotiation has been determined to have failed and security. The functional negotiation procedure can be restarted, thereby preventing a degradation attack.
At step 307, the UE sends an SMC completion response message to the MME. The SMC completion response message can also be carried in the TAU completion message.
At step 308, the MME returns a TAU acceptance message.
In another embodiment of the invention, step 308 is combined with step 305 when in step 305 the SMC request message is sent to the UE by carrying it in a TAU acceptance message.
At step 309, the UE returns a TAU completion message.
In another embodiment of the invention, in step 307, step 309 is combined with step 307 when the SMC completion response message is carried in the TAU completion message.
Through the above process, NAS security functions are negotiated.
All or part of the steps in the method according to embodiments of the invention can be performed by a program instructing the relevant hardware, which is ROM (read-only memory) / RAM (random access memory). It should be understood by those skilled in the art that it can be stored in computer-readable storage media such as), magnetic disks, or optical disks.
FIG. 4 is a structural diagram of a system according to an embodiment of the present invention for negotiating security functions when a terminal moves. With reference to Figure 4, the system includes UE and MME.
The UE is adapted to send a TAU request message to the MME, receive a message from the MME carrying the selected NAS security algorithm, and derive the NAS protection key with the authentication vector associated key.
The MME receives the TAU request message sent from the UE, obtains the authentication vector-related key, or the root key derived from the authentication vector-related key, and the NAS security algorithm supported by the UE, and the NAS supported by the UE. The NAS security algorithm is selected according to the security algorithm, a message carrying the selected NAS security algorithm is generated and sent to the UE, and the NAS is protected by the acquired authentication vector-related key or the root key derived from the authentication vector-related key. Adapted to derive the key.
In the system, the MME also gets the security feature information supported by the UE, and also carries the security feature information supported by the UE in the message carrying the selected NAS security algorithm sent to the UE. The UE also determines if a degradation attack has taken place by determining if the security feature information supported by the UE and sent by the MME is consistent with the security feature information supported by the UE. ..
Specifically, the MME includes an acquisition module, a selection module, and a key derivation module.
The acquisition module receives the TAU request message sent from the UE and is adapted to acquire the authentication vector-related key, or the root key derived from the authentication vector-related key, and the NAS security algorithm supported by the UE. .. The selection module is supported by the UE and is adapted to select the NAS security algorithm according to the NAS security algorithm acquired by the acquisition module, generate a message carrying the selected NAS security algorithm, and send it to the UE. The key derivation module is adapted to derive the NAS protection key by the authentication vector-related key acquired by the acquisition module, or the root key derived by the authentication vector-related key, and the selected NAS security algorithm.
The acquisition module also acquires the security function information supported by the UE, and the selection module further acquires the security function information supported by the UE and acquired by the acquisition module in the message carrying the selected NAS security algorithm. Transport.
The UE includes an update module, a key derivation module, a storage module, and a discovery module.
The update module is supported by the UE and is adapted to send a TAU request message to the MME carrying the security feature information stored in the storage module and to receive a message sent by the MME carrying the selected NAS security algorithm. Ru. The key derivation module is adapted to derive the NAS protection key by the authentication vector associated key and the selected NAS security algorithm received by the update module. The storage module is adapted to store security feature information supported by the UE. The detection module determines that a degradation attack has taken place when it detects that the security feature information received from the UE is supported by the UE and is inconsistent with the security feature information supported by the UE and stored in the storage module. Is adapted as The message sent by the MME carrying the selected NAS security algorithm also carries the security feature information supported by the UE.
In the technical solution provided in the embodiments of the present invention, the MME receives the TAU request message sent from the UE, and the NAS security algorithm supported by the UE and the authentication vector related key or authentication vector. It gets the root key derived from the associated key, then selects the NAS security algorithm according to the NAS security algorithm supported by the UE, generates a message carrying the selected NAS security algorithm and sends it to the UE, thereby. It is understood from the above description that the UE and MME will be able to share NAS security algorithms. Furthermore, the UE and MME derive the NAS protection key by the authentication vector-related key or the root key derived by the authentication vector-related key, which enables the MME and the UE to share the NAS protection key. When moving from a 2G / 3G network to an LTE network in this way, the UE can negotiate with the MME about NAS security algorithms and NAS protection keys, and therefore security function negotiation in TAU procedures between heterogeneous networks. The process is accomplished, which guarantees the security of subsequent interactions between the UE and the network.
According to the present invention, deterioration attacks can be further prevented. The MME also returns the security feature information supported by the UE via the TAU acceptance message, which allows the UE to ensure that the security feature information supported by the UE is consistent with the current security feature information supported by the UE. Detect if. If there is no contradiction, the current security function negotiation is successful, and the NAS security algorithm and NAS protection key obtained through the negotiation can be used. If there is a contradiction, a deterioration attack is performed, the current security function negotiation fails, and it is determined that the security function negotiation needs to be performed again. According to the above solution, it is possible to detect whether the security function information supported by the UE was attacked before the MME obtained the security function information supported by the UE, thereby causing a deterioration attack. It can be blocked and the security of subsequent dialogue between the UE and the network can be guaranteed.
The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any changes, equal replacements, and improvements made without departing from the spirit and principles of the invention are within the scope of the invention.
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP2010528559A | Cites | Japan |
| JP2010521905A | Cites | Japan |
| JP2009540721A | Cites | Japan |
| JP2009531952A | Cites | Japan |
| EP2214444A1 | Cites | European Patent Office (EPO) |
| 3GPP TR 33.821 V0.2.0,2007年 4月 | Non-patent | – |
31 members in 8 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 2007101457033 | China | – | |
| 200710145703 | China | A | |
| 2007101517000 | China | – | |
| 200710151700 | China | A | |
| 2008072165 | China | W |
Members31
| Document | Office | Kind | |
|---|---|---|---|
| CN101378591A | China | A | |
| WO2009030155A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2139175A1 | European Patent Office (EPO) | A1 | |
| US2010095123A1 | United States of America | A1 | |
| EP2139175A4 | European Patent Office (EPO) | A4 | |
| JP2010533390A | Japan | A | |
| CN101378591B | China | B | |
| RU2009146555A | Russian Federation | A | |
| RU2435319C2 | Russian Federation | C2 | |
| JP4976548B2This record | Japan | B2 | |
| EP2139175B1 | European Patent Office (EPO) | B1 | |
| EP2549701A1 | European Patent Office (EPO) | A1 | |
| ES2401039T3 | Spain | T3 | |
| PL2139175T3 | Poland | T3 | |
| US8656169B2 | United States of America | B2 | |
| EP2549701B1 | European Patent Office (EPO) | B1 | |
| US2014120879A1 | United States of America | A1 | |
| US8812848B2 | United States of America | B2 | |
| US2014295800A1 | United States of America | A1 | |
| US9241261B2 | United States of America | B2 | |
| US2016028703A1 | United States of America | A1 | |
| US2016088472A1 | United States of America | A1 | |
| US9497625B2 | United States of America | B2 | |
| US9538373B2 | United States of America | B2 | |
| US2017094506A1 | United States of America | A1 | |
| EP2139175B3 | European Patent Office (EPO) | B3 | |
| ES2401039T7 | Spain | T7 | |
| PL2139175T6 | Poland | T6 | |
| US10015669B2 | United States of America | B2 | |
| US2018310170A1 | United States of America | A1 | |
| US10595198B2 | United States of America | B2 |
22 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Report on accelerated examinationJAPANESE INTERMEDIATE CODE: A971005A975 | A975 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Explanation of circumstances concerning accelerated examinationJAPANESE INTERMEDIATE CODE: A871A871 | A871 |
Numbers
- Publication
- 4976548
- Application
- 2010513633
Titles2
- Japanese
- 端末が移動するときにセキュリティ機能を折衝するための方法、システム、および装置
- English
- Methods, systems, and devices for negotiating security features as the device moves
Classification
- CPC, 16
- H04L9/0844
- H04L63/1441
- H04L63/20
- H04L63/205
- H04L2463/061
- H04L9/088
- H04L69/24
- H04W12/0431
- H04W12/041
- H04W12/106
- H04W12/122
- H04W36/0038
- H04L63/0492
- H04L63/062
- H04L63/0876
- H04W8/02
- IPC, 6
- H04L9 32
- H04L9 08
- H04W12 041
- H04W12 0431
- H04W12 06
- H04W12 08
