Encryption in a wireless telecommunications.
Abstract
An example of the present invention is a method of transmitting encrypted user data to a mobile terminal in a wireless telecommunications network. The method comprises sending to the mobile terminal a data packet. The data packet comprises both an identifier of encryption information to used in recovering encrypted user data, and user data encrypted using said encryption information.

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
10 claims: 10 independent, 0 dependent
- 1CLAIMS REIVINDICACIONES Habiéndose descrito la invención como antecede, se reclama como propiedad lo contenido en las siguientes reivindicaciones:Having described the invention as above, the content of the following claims is claimed as property: 1.- A method for transmitting cryptographically encoded user data to a mobile terminal in a wireless telecommunications network, characterized in that it comprises sending to the mobile terminal a data packet, the data packet comprising both a cryptographic encoding information identifier to be used when retrieving cryptographically encoded user data, and cryptographically encoded user data using the cryptographic encoding information where the network comprises a UMTS or LTE network, the data packet comprises the Security Mode Command, the Security Mode Command comprising the identifier of the information cryptographic encoding, and 1.- Un método para transmitir datos de usuario codificados criptográficamente a una terminal móvil en una red de telecomunicaciones inalámbricas, caracterizado porque comprende enviar a la terminal móvil un paquete de datos, el paquete de datos que comprende tanto un identificador de información de codificación criptográfica para utilizarse al recuperar datos de usuario codificados criptográficamente, y datos de usuario codificados criptográficamente que utilizan la información de codificación criptográfica en donde la red comprende una red de UMTS o de LTE, el paquete de datos comprende Comando de Modo de Seguridad, el Comando de Modo de Seguridad que comprende el identificador de la información de codificación criptográfica, y la información de codificación criptográfica comprende un algoritmo de codificación criptográfica. the cryptographic encoding information comprises a cryptographic encoding algorithm.
- 23. A method according to either of claims 1 or 2, characterized in that the user data comprises user signaling data. 3.- Un método de conformidad con cualquiera de las reivindicaciones 1 ó 2, caracterizado porque los datos de usuario comprenden datos de señalización de usuario.
- 34. - Un método de conformidad con la reivindicación Four. - A method according to claim 3, caracterizado porque los datos de señalización de usuario comprenden un mensaje de ÑAS o mensaje de RRC. 3, characterized in that the user signaling data comprises a ÑAS message or RRC message.
- 56. - A method according to any of the preceding claims, characterized in that it further comprises the passage of the mobile terminal that receives the data packet and that uses the identified cryptographic encoding information to retrieve the user data. 6. - Un método de conformidad con cualquiera de las reivindicaciones precedentes, caracterizado porque además comprende el paso de la terminal móvil que recibe el paquete de datos y que utiliza la información de codificación criptográfica identificada para recuperar los datos de usuario.
- 67. - A method according to claim 7. - Un método de conformidad con la reivindicación 6, caracterizado porque además comprende la terminal móvil que almacena la información de codificación criptográfica identificada para uso al recuperar datos de usuario codificados criptográficamente en un paquete de datos subsecuentemente recibido. 6, characterized in that it further comprises the mobile terminal that stores the identified cryptographic encoding information for use in retrieving cryptographically encoded user data in a subsequently received data packet.
- 78. - A UMTS or LTE wireless telecommunications data packet characterized in that it comprises a Security Mode Command comprising both a cryptographic encoding information identifier for use when retrieving cryptographically encoded user data, and cryptographically encoded user data using the cryptographic encryption information, the cryptographic encoding information comprising a cryptographic encryption algorithm. 8. - Un paquete de datos de telecomunicaciones inalámbricas de UMTS o LTE caracterizado porque comprende un Comando de Modo de Seguridad que comprende tanto un identificador de información de codificación criptográfica para utilizarse al recuperar datos de usuario codificados criptográficamente, y datos de usuario codificados criptográficamente que utilizan la información de codificación criptográfica, la información de codificación criptográfica que comprende un algoritmo de codificación criptográfica.
- 89. - A UMTS or LTE wireless telecommunications base station operational to transmit cryptographically encoded user data in a data packet, characterized in that the data packet comprises a Security Mode Command comprising both a cryptographic encoding information identifier to be used when retrieving cryptographically encoded user data, and cryptographically encoded user data using the cryptographic encoding information, the cryptographic information comprising a cryptographic encoding algorithm. 9. - Una estación base de telecomunicaciones inalámbricas de UMTS o LTE operativa para transmitir datos de usuario codificados criptográficamente en un paquete de datos, caracterizada porque el paquete de datos comprende un Comando de Modo de Seguridad que comprende tanto un identificador de información de codificación criptográfica para utilizarse al recuperar datos de usuario codificados criptográficamente, y datos de usuario codificados criptográficamente que utilizan la información de codificación criptográfica, la información criptográfica que comprende un algoritmo de codificación criptográfica.
- 910. - A UMTS or LTE wireless telecommunications terminal characterized in that it comprises a receiver and a processor, the receiver that is operative to receive a data packet, the data packet that comprises a Security Mode Command that includes both an information identifier cryptographic encoding to be used when retrieving cryptographically encoded user data, and cryptographically encoded user data using the cryptographic encoding information, the cryptographic encoding information comprising a cryptographic encoding algorithm;10. - Una terminal de telecomunicaciones inalámbricas de UMTS o LTE caracterizada porque comprende un receptor y un procesador, el receptor que es operativo para recibir un paquete de datos, el paquete de datos que comprende un Comando de Modo de Seguridad que comprende tanto un identificador de información de codificación criptográfica para utilizarse al recuperar datos de usuario codificados criptográficamente, y datos de usuario codificados criptográficamente que utilizan la información de codificación criptográfica, la información de codificación criptográfica que comprende un algoritmo de codificación criptográfica;el procesador que es operativo para utilizar la información de codificación criptográfica para recuperar los datos de usuario codificados criptográficamente que utilizan la información de codificación criptográfica y la terminal móvil que es operativa para almacenar la información de codificación criptográfica para uso subsecuente. the processor that is operative to use the cryptographic encoding information to retrieve the cryptographically encoded user data that uses the cryptographic encoding information and the mobile terminal that is operative to store the cryptographic encoding information for subsequent use.
- 1011, - A method of a mobile terminal in a wireless telecommunications network that receives cryptographically encoded user data, characterized in that it comprises:11,- Un método de una terminal móvil en una red de telecomunicaciones inalámbricas que recibe datos de usuario codificados criptográficamente, caracterizado porque comprende: la terminal móvil que recibe un primer paquete de datos, el primer paquete de datos que comprende datos de usuario codificados criptográficamente que utilizan primera información de codificación criptográfica;the mobile terminal receiving a first data packet, the first data packet comprising cryptographically encoded user data using first cryptographic encoding information;recuperar los datos de usuario en la terminal móvil que utiliza primera información de codificación criptográfica almacenada en la terminal móvil;retrieving user data in the mobile terminal using the first cryptographic encryption information stored in the mobile terminal;la terminal móvil que recibe un siguiente paquete de datos, el paquete de datos que comprende un Comando de Modo de the mobile terminal receiving a next data packet, the data packet comprising a Mode Command Security comprising both an updated cryptographic encoding information identifier for use in retrieving cryptographically encoded user data, and cryptographically encoded user data using the updated cryptographic encryption information, the cryptographic encryption information comprising a cryptographic encryption algorithm;Seguridad que comprende tanto un identificador de información de codificación criptográfica actualizada para utilizarse al recuperar datos de usuario codificados criptográficamente, y datos de usuario codificados criptográficamente que utilizan la información de codificación criptográfica actualizada, la información de codificación criptográfica que comprende un algoritmo de codificación criptográfica;la terminal móvil que utiliza la información de 5 codificación criptográfica para recuperar los datos de usuario codificados criptográficamente que utilizan la información de codificación criptográfica actualizada y almacenan la información de codificación criptográfica actualizada para uso subsecuente al decodificar criptográficamente paquetes the mobile terminal that uses the cryptographic encoding information to retrieve the cryptographically encoded user data that uses the updated cryptographic encoding information and stores the updated cryptographic encoding information for subsequent use when cryptographically decoding packets 10 subsequent 10 subsecuentes.
Independent claims10
96 paragraphs in 1 section, as filed
(54) Title: CRYPTOGRAPHIC CODING IN WIRELESS TELECOMMUNICATIONS. (54) Tltle: ENCRYPTION IN A WIRELESS TELECOMMUNICATIONS.
(57) Summary
An example of the present invention is a method of transmitting cryptographically encoded user data to a mobile terminal in a wireless telecommunications network. The method comprises sending a data packet to the mobile terminal. The data packet comprises both a cryptographic encoding information identifier for use in retrieving cryptographically encoded user data, and cryptographically encoded user data using cryptographic encoding information.
(57) Abstract
An example of the present invention is a method of transmitting encrypted user data to a mobile terminal in a wireless telecommunications network. The method comprises sending to the mobile terminal a data packet. The data packet comprises both an identifier of encryption Information to used in recovering encrypted user data, and user data encrypted using said encryption Information.
i
CRYPTOGRAPHIC CODING IN WIRELESS TELECOMMUNICATIONS
Field of the Invention
The present invention relates to telecommunications, in particular wireless telecommunications.
Background of the Invention
In Universal System systems
Mobile Telecommunications (UMTS), some messages are encrypted cryptographically. Cryptographic encryption was initiated by a security mode command that was sent from the core network through the UMTS terrestrial radio access network (UTRAN) to be received by the mobile terminal. This continues with a security mode response that is sent from the mobile terminal and received by the core network.
For example, as shown in Figure 1, upon receiving a session establishment request, or bearer 1, the core network (CN) 2 sends a security mode 4 command to UTRAN 6 This causes UTRAN 6 to direct security mode command 4 to the mobile terminal (User Equipment, UE) 8). Mobile terminal 8 reacts by initiating its cryptographic encoding algorithms that use specific parameter values, sometimes referred to as a security context, and then recognizes by sending a mode response
Ref .: 201098 security 10 to UTRAN 6 which passes response 10 on the core network 2. After that a message from Stratum of No
Access (ÑAS), such as a session establishment response 12, is sent from core network 2 to mobile terminal 8 through UTRAN 6.
In this known approach, security mode messages are not cryptographically encrypted as they provide the cryptographic encoding information necessary to cryptographically encode the messages that follow.
Another background area is Evolution networks to
Long-term, LTE. From UMTS networks, so-called
Long Term Evolution, LTE. For background in networks
Long Term Evolution, reader is referred to Specification
3GPP Third Generation Association Project Technique
TS 23,882.
Summary of the invention
The reader is referred to the appended independent claims. Some preferred features are presented in the dependent claims.
An example of the present invention is a method of transmitting cryptographically encoded user data to a mobile terminal in a wireless telecommunications network. The method comprises sending a data packet to the mobile terminal. The data packet comprises both a cryptographic encoding information identifier for use in retrieving cryptographically encoded user data, and cryptographically encoded user data using cryptographic encoding information.
The inventors noted that in the known approach security mode command and response signaling causes delay in session establishment procedures. For example, when the mobile terminal moves to the coverage area of another base station, there may be a change in the cryptographic encryption key used. This requires security mode command and response signaling to inform the mobile terminal of the new key before cryptographically encoded data using the new key is sent. This additional signaling may give rise to additional delay. Such a delay can be annoying to the subscriber, and can cause problems with applications that are sensitive to call setup delay, such as push to talk.
In some embodiments of the invention such delays can be reduced.
Brief description of the figures
The embodiments of the present invention will now be described by way of example and with reference to the figures, where:
Figure 1 is a diagram illustrating the known approach to instigating cryptographic encryption as part of session establishment (PREVIOUS TECHNIQUE), Figure 2 is a diagram illustrating a network of
Long-term evolution, LTE, in accordance with a first embodiment of the present invention,
<td>the</td><td>Figure 3</td><td>is</td><td>a diagram</td><td>illustrating</td><td>a</td>
<td>close up</td><td colspan="2">to instigate</td><td>coding</td><td colspan="2">cryptographic like</td>
<td colspan="2">establishment part</td><td>of</td><td>session in the</td><td>network shown in</td><td>the</td>
Figure 2, Figure 4 is a diagram illustrating the structure of a NAS message sent in session establishment, Figure 5 is a diagram illustrating how NAS signaling messages are cryptographically encoded, Figure 6 is a diagram illustrating handover between CN core network nodes in the LTE network, Figure 7 is a diagram illustrating instigating cryptographic encoding as part of Radio resource control connection establishment, RRC, in the LTE network, Figure 8 is a universal diagram illustrating a Universal Mobile Telecommunications System (UMTS) network in accordance with a second embodiment of the present invention, and Figure 9 is a diagram illustrating an approach to instigate cryptographic encryption as part of session establishment in the network shown in the
Figure 8.
Detailed description of the invention
An illustrative LTE network will first be described, followed by explanations of how session establishment cryptographic encryption using combined message is initiated. This continues with an explanation of how cryptographic encryption is handled with the handover of a mobile terminal connecting one core network node to another.
Then an alternative combined message is described.
An alternative network is then described, which is a UMTS network, followed by an explanation of how cryptographic encryption was initiated on that network.
Long-term evolution network
The LTE 14 network, which is based on a System network
Universal Mobile Telecommunications (UMTS), basically shown in Figure 2. The core network includes Mobile Management Entities (MME). Each MME 16 includes a cryptographic coding stage of the message of ÑAS 26. In Figure 2, only one Mobile Management Entity (MME) of the core network 18 and a base station 20 of the network of
LTE 14 were shown for simplicity. The LTE network includes multiple base stations. In the Figure, the base station was also designated eNode B in accordance with LTE terminology. A cell, also called a sector, is the radio coverage area served by a corresponding antenna of a base station. Each base station 20 typically has three cells 22, each covered by one of the three directional antennas 24 angled 120 degrees to each other in azimuth.
In use, a mobile user terminal 28 (often referred to as User Equipment (UE) in LTE / UMTS terminology) communicates with a mobile management entity 16 through at least one cell 22 of at least one base station 20 In this way, the mobile user terminal communicates with the UTRAN 2 network.
Instill cryptographic encryption in session establishment
The inventors noted that it is possible to combine the Security mode command and Stratum No Access (ÑAS) message (such as session establishment response) into a single combined message. The first part of the message is the security mode command and this part is not cryptographically encrypted. The second part of the message is a message from ÑAS and this part is cryptographically encrypted.
As shown in Figure 3, upon receiving a session establishment request 30, the mobile handling entity 16 sends the combined message 32 consisting of the cryptographically encoded unprotected security mode command and cryptographically encoded ÑAS signaling message to the base station 20. This causes base station 20 to route the combined message 32 to the mobile terminal.
User, EU 28). Mobile terminal 28 initiates its security context and then acknowledges by sending a security mode response 34 to base station 20 from where response 34 was directed to mobile handling entity 16. Thereafter a message from Stratum Cryptographically encoded No Access (ÑAS), such as a session establishment response 36 was sent from the MME 16 to the mobile terminal 28 through the base station 20.
The combined message 32 named above as shown in Figure 4, and consists of a cryptographically unencoded security command 38 and a message of
Cryptographically encoded ÑAS 40. The security command consists of information elements that define security context information such as an identifier of the cryptographic encoding key to be used, and for example, a start time identifier for cryptographic encoding. The message of ÑAS 40 consists of information elements that constitute a response from
Session Establishment.
Production of the combined message
In the LTE network 14 cryptographic encoding of ÑAS messages is performed by cryptographic encoding steps 26 at the respective nodes of the core network
18. The cryptographic encoding of ÑAS messages is independent of the cryptographic encoding of user data.
As shown in Figure 5, the ÑAS message for cryptographic encoding together with information to perform cryptographic encoding such as cryptographic encryption keys are entered into cryptographic encoding step 26 from which the cryptographically encoded ÑAS message is provided 40 The cryptographically encoded ÑAS message 40 is concatenated with cryptographically uncoded header information 38. This is possible because MME 16 generally allows cryptographic encoding of at least part of a ÑAS message before concatenation with another non-cryptographically encoded message portion.
Handle cryptographic encryption with handover
Handover is the process of transferring mobile terminal 28 from the connection with a base station 20 and therefore core network node 18 to another base station (not shown) and therefore another core network node (not shown ). Handover is sometimes called a handover.
An example of handover procedure was shown in Figure 6. Initially the connection is to base station 20 and involves using a first cryptographic encryption key. The core network node 18 sends a handover command 42 through the base station 20 to the mobile terminal 28, after which handover 44 of the call connection is performed to an additional base station 20 'and therefore 20 'core network node. A handover complete message 46 is then sent from mobile terminal 28 to new base station 18 'and hence core network node 18'. Therefore the core network node sends a combined message 48, consisting of a cryptographically unencoded security mode command 50 including cryptographic encoding key identifiers as previously discussed, followed by a cryptographically encoded portion 52 of data user, such as signaling messages from ÑAS. Thus, for example, when the core network node that does cryptographic encryption changes, the first combined message 50 of the new core network node
18 'indicates in the security mode command the new security parameter values to be used, and includes, in cryptographic form, new signaling messages from ÑAS.
In an otherwise similar manner, if the cryptographic encryption and cryptographic encryption settings are in turn done on the user plane, the combined package on the user plane consists of the cryptographically uncoded security mode command concatenated with data from user.
Of course, in some modalities, switching to a new cryptographic encryption key, by sending a combined message consisting of a cryptographically non-encrypted security mode command that includes cryptographic encryption key identifiers followed by a cryptographically encoded portion of data from Cryptographically encrypted user using that cryptographic encryption key, can be done at different times than handover between cells. For example, in all modes, the old cell and the new cell can be the same cell.
In this example, the cell initially communicates with the mobile terminal using the old cryptographic encryption parameters. Partially through the session the cell sends a packet containing the new cryptographic encoding parameters and additional user data. The mobile terminal receives the new cryptographic encoding parameters. The mobile terminal uses the new cryptographic encoding parameters to cryptographically decode the cryptographically encoded part of the packet. The mobile terminal also stores the new cryptographic encoding parameters for subsequent use in cryptographic decoding of subsequent packets that are cryptographically encoded using the new cryptographic encoding parameters.
Radio resource control
As shown in Figure 7, a combined message can be sent similarly consisting of a cryptographically encoded non-encrypted security mode command and a cryptographically encoded user data portion, where the user data portion consists of a Control Control message. Radio Resource (RRC). As shown in Figure 7, a
RRC connection request 54 was sent to a base station and the combined message 56, which more specifically comprises the cryptographically encoded RRC Connection Mode command followed by the cryptographically encoded RRC Connection Response (with the new key), was sent by the base station to the mobile terminal 28 'in response. A security mode response is then sent from user terminal 28 '.
Another illustrative system: UMTS
The network is a System terrestrial access network
Universal Mobile Telecommunications (UMTS) (UTRAN), which is a type of broadband code division multiple access (CDMA) network for mobile telecommunications. The network of
UTRAN is basically as shown in Figure 8. Only the radio network controller and two network network base stations
UTRAN 62 were shown for simplicity. As shown in this
Figure, UTRAN 62 network includes base stations 64. In the Figure, each of base stations 64 was also designated Node B in accordance with UMTS terminology. A cell, also called a sector, is the radio coverage area served by a corresponding antenna of a base station. Each base station typically has three cells 66, each covered by one of three directional antennas 67 angled 120 degrees to each other in azimuth. Each radio network controller (RNC) 68 typically controls multiple base stations 64 and thus a number of cells 66. A base station 64 connects to its radio network controller (RNC) 68 from control through a respective interface 69 known as an IuB interface. In use, a mobile user terminal 70 (often referred to as User Equipment (UE) in UMS terminology) communicates with a serving radio network controller (RCN) 68 through at least one cell 66 of the minus one base station
64. In this way, the mobile user terminal communicates with the UTRAN 62 network.
The RNC connects to a Service Access Support Node, SGSN, 72 of core network 74. SGSN 72 includes a cryptographic message encoding step of ÑAS 76 as described in more detail later.
Instigate Cryptographic Encryption in Session Establishment: UMTS Example
The inventors noted that it is possible to combine the Security mode command and Non Access Stratum (ÑAS) message (such as a session establishment response) into a single combined message. The first part of the message is the security mode command and this part is not cryptographically encrypted. The second part of the message is a message from ÑAS and this part is cryptographically encrypted.
As shown in Figure 9, upon receiving a session establishment request 78, SGSN 72 sends the combined message 80 consisting of the cryptographically encoded security mode command and cryptographically encoded ÑAS signaling message to RNC 68 and by hence base station 64. This causes base station 64 to route the combined message 80 to the mobile terminal (User Equipment, UE 70).
Combined message 80 consists of a cryptographically unencoded security command and a cryptographically encoded ÑAS message. The security command consists of information elements that define security context information such as an identifier of the cryptographic encryption key to be used, and for example, a start time identifier for cryptographic encryption. The cryptographically encoded NAS message portion of message 80 consists of information elements constituting a Session Establishment response.
Mobile terminal 70 initiates its security context and then acknowledges by sending a security mode response 82 to base station 64 and therefore RNC 68 from where response 82 was routed to SGSN 72.
general
The present invention can be represented in other specific forms without departing from its essential characteristics. The modalities described are to be considered in all respects only as illustrative and not restrictive. The scope of the invention, therefore, was indicated by the appended claims rather than by the foregoing description. All changes that come within the meaning and scale of equivalency of the claims are to be encompassed within their scope.
Some abbreviations
CN: Core Network
UMTS: Universal Telecommunications System
Mobiles
EU: User Equipment
ÑAS: No Access Stratum (also known as the Core network protocol)
MME: Mobility Management Entity
LTE: Long Term Evolution, a term used in 3GPP for system that is standardized after UMTS
IE: Information Element
RRC: Radio Resource Control (The Radio part of the control protocol otherwise called part of
Access layer of the control protocol)
SGSN: Signaling Access Support Node.
<td>I know</td><td>states that</td><td>in relation to this date,</td><td>the</td>
<td>best method</td><td>known for the</td><td>applicant to carry</td><td>the</td>
<td>practice the</td><td>cited invention,</td><td>is the one that is clear from</td><td>the</td>
present description of the invention.
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
33 members in 13 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 0619499 | United Kingdom | A | |
| 2007006995 | European Patent Office (EPO) | W |
Members33
| Document | Office | Kind | |
|---|---|---|---|
| AU2007304555A1 | Australia | A1 | |
| WO2008040412A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW200830817A | Taiwan Province of China | A | |
| MX2009003314AThis record | Mexico | A | |
| EP2070290A1 | European Patent Office (EPO) | A1 | |
| KR20090063274A | Republic of Korea | A | |
| CN101518032A | China | A | |
| IL197829A0 | Israel | A0 | |
| JP2010506469A | Japan | A | |
| US2010067697A1 | United States of America | A1 | |
| RU2009116675A | Russian Federation | A | |
| AU2007304555B2 | Australia | B2 | |
| KR101078615B1 | Republic of Korea | B1 | |
| RU2458476C2 | Russian Federation | C2 | |
| JP2013081252A | Japan | A | |
| US8494163B2 | United States of America | B2 | |
| US2013216042A1 | United States of America | A1 | |
| CN103327483A | China | A | |
| BRPI0717324A2 | Brazil | A2 | |
| TWI442743B | Taiwan Province of China | B | |
| IL197829A | Israel | A | |
| CN101518032B | China | B | |
| CN104394527A | China | A | |
| US9107066B2 | United States of America | B2 | |
| US2015237501A1 | United States of America | A1 | |
| JP2016021746A | Japan | A | |
| EP2070290B1 | European Patent Office (EPO) | B1 | |
| ES2581354T3 | Spain | T3 | |
| JP6016643B2 | Japan | B2 | |
| US9503901B2 | United States of America | B2 | |
| CN103327483B | China | B | |
| CN104394527B | China | B | |
| BRPI0717324B1 | Brazil | B1 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Grant or registrationFG | FG |
Numbers
- Application
- 2009003314
Titles2
- English
- ENCRYPTION IN A WIRELESS TELECOMMUNICATIONS.
- Spanish
- CODIFICACION CRIPTOGRAFICA EN TELECOMUNICACIONES INALAMBRICAS.
Classification
- CPC, 9
- H04L63/0428
- H04W12/02
- H04W12/08
- H04L63/068
- H04W12/04
- H04W12/033
- H04L9/065
- H04L63/0407
- H04L63/0442
- IPC, 3
- H04L29 06
- H04W12 02
- H04W12 04