Method, system and apparatus for negotiating the security ability when a terminal is moving
Abstract
A communication method includes receiving by a SGSN a context request message from a mobility management entity (MME), obtaining by the SGSN an authentication vector-related key, and calculating by the SGSN a root key according to the authentication vector-related key. In addition, the method further includes sending by the SGSN a context response message including the root key to the MME, wherein the MME derives a NAS protection key according to the root key.

Term
1.9 yearsto projected expiry
Projected expiry 27 August 2028, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
12 claims: 7 independent, 5 dependent
- 1Patent claims Zastrzeżenia patentowe 1. The method of negotiating security capability when a user equipment, UE, moves, while, when the UE is idle, it moves from the second / third generation network, 2G / 3G, to the data transmission standard, LTE network, this method includes:1. Sposób negocjacji zdolności bezpieczeństwa, gdy sprzęt użytkownika, UE, przemieszcza się, przy czym, gdy UE jest w stanie bezczynności, przechodzi z sieci drugiej/trzeciej generacji, 2G/3G, do sieci standardu przesyłu danych, LTE, sposób ten obejmuje: odbieranie, za pomocą jednostki zarządzania mobilnością, MME, aktualizacji strefy śledzenia, TAU, komunikatu żądania wysłanego (100) z UE;receiving, using the mobility management unit, MME, tracking zone update, TAU, request message sent (100) from the UE;obtaining (101), using MME, a NAS accessless layer, a security algorithm supported by the UE;uzyskiwanie (101), za pomocą MME, warstwy bezdostępowej NAS, algorytmu bezpieczeństwa obsługiwanego przez UE;obtaining (102), by MME, a vector authentication key from a mobility management context response message sent from a node serving packet data services, SGSN;uzyskiwanie (102), przez MME, wektorowego klucza uwierzytelnienia z komunikatu odpowiedzi kontekstu zarządzania mobilnością, wysłanego z węzła obsługującego usługi pakietowego przesyłania danych, SGSN;selecting (103), by MME, a NAS security algorithm according to a UE-supported NAS security algorithm, deriving a master key according to a vector authentication key, and then deriving a NAS protection key according to a derived master key, and sending (104) a message containing the selected NAS security algorithm to the UE and receiving (104), by the UE, a message including the selected NAS security algorithm sent by the MME;wybieranie (103), przez MME, algorytmu bezpieczeństwa NAS według algorytmu bezpieczeństwa NAS obsługiwanego przez UE, wyprowadzanie klucza głównego według wektorowego klucza uwierzytelnienia, a następnie wyprowadzanie klucza ochrony NAS według wyprowadzonego klucza głównego oraz wysyłanie (104) komunikatu zawierającego wybrany algorytm bezpieczeństwa NAS do UE oraz odbieranie (104), przez UE, komunikatu zawierającego wybrany algorytm bezpieczeństwa NAS wysłany przez MME;output (105), by the EU, master key according to the current vector authentication key and then deriving the NAS security key, according to the derived master key, where when the SGSN node is the SGSN node of the 2G network, the vector authentication key contains at least the Kc encryption key or the value obtained after one-way conversion to the Kc encryption key, or when the SGSN node is a SGSN node of the 3G network, the vector authentication key contains at least the IK integrity key and the CK encryption key or values obtained after performing a one-way conversion to IK and the CK encryption key. wyprowadzanie (105), przez UE, klucza głównego, według aktualnego wektorowego klucza uwierzytelnienia oraz następnie wyprowadzanie klucza bezpieczeństwa NAS, zgodnie z wyprowadzonym kluczem głównym, gdzie gdy węzeł SGSN jest węzłem SGSN sieci 2G, wektorowy klucz uwierzytelnienia zawiera co najmniej klucz szyfrowania Kc lub wartość uzyskaną po przeprowadzeniu jednokierunkowej konwersji na klucz szyfrowania Kc, lub gdy węzeł SGSN jest węzłem SGSN sieci 3G, wektorowy klucz uwierzytelnienia zawiera co najmniej klucz integralności IK i klucz szyfrowania CK lub wartości uzyskane po wykonaniu jednokierunkowej konwersji na IK oraz klucz szyfrowania CK.
- 2The method according to claim Wherein the MME obtaining a NAS security algorithm supported by the UE includes:2. Sposób według zastrz. 1, w którym uzyskanie, przez MME, algorytmu bezpieczeństwa NAS obsługiwanego przez UE, obejmuje: obtaining, by the MME, security capability information supported by the UE from a TAU request message sent from the UE, where the TAU request message includes a NAS security algorithm supported by the UE. uzyskiwanie, przez MME, informacji zdolności bezpieczeństwa, obsługiwanych przez UE, z komunikatu żądania TAU wysłanego z UE, gdzie komunikat żądania TAU zawiera algorytm bezpieczeństwa NAS obsługiwany przez UE.
- 3The method according to claim Wherein the MME obtaining a NAS security algorithm supported by the UE includes:3. Sposób według zastrz. 1, w którym uzyskanie przez MME algorytmu bezpieczeństwa NAS, obsługiwanego przez UE, obejmuje: - 14 uzyskiwanie przez MME informacji zdolności bezpieczeństwa, obsługiwanych przez UE, z komunikatu odpowiedzi kontekstu wysłanego z węzła SGSN, gdzie komunikat odpowiedzi kontekstu zawiera algorytm bezpieczeństwa NAS, obsługiwany przez UE. - MME obtaining security capability information, supported by the UE, from the context response message sent from the SGSN, where the context response message includes a NAS security algorithm supported by the UE.
- 6A system for negotiating security capability when a user equipment, UE, moves, in which, when the UE is idle, it passes from the second / third generation network, 2G / 3G, to the data transmission standard network, LTE, the system includes UE and a mobility management unit, MME, where 6. System do negocjacji zdolności bezpieczeństwa, gdy sprzęt użytkownika, UE, przemieszcza się, w którym, gdy UE jest w stanie bezczynności, przechodzi z sieci drugiej/trzeciej generacji, 2G/3G, do sieci standardu przesyłu danych, LTE, przy czym system obejmuje UE oraz jednostkę zarządzania mobilnością, MME, gdzie The UE is adapted to send the tracking zone update, TAU, request message to the MME, receive the message containing the selected accessless layer, NAS, the security algorithm sent from the MME and output the NAS protection key according to the master key, which is output according to the current vector authentication key, and UE jest przystosowany do wysyłania aktualizacji strefy śledzenia, TAU, komunikatu żądania do MME, odbierania komunikatu zawierającego wybraną warstwę bezdostępową, NAS, algorytmu bezpieczeństwa wysłanego z MME i wyprowadzania klucza ochrony NAS według klucza głównego, który jest wyprowadzany według aktualnego wektorowego klucza uwierzytelnienia oraz MME jest przystosowana do:odbierania komunikatu żądania TAU wysłanego z UE;The MME is adapted to: receive a TAU request message sent from the UE;obtaining a vector authentication key from a mobility management context response message sent from a node serving packet data services, SGSN, and a NAS security algorithm supported by the EU;selecting a NAS security algorithm according to a NAS security algorithm supported by the UE, and generating and sending a message containing the selected NAS security algorithm to the UE;as well as deriving the NAS protection key according to the master key, which is derived according to the obtained vector authentication key, where when the SGSN node is the SGSN node of the 2G network, the vector authentication key contains at least the Kc encryption key or the value obtained after one-way conversion to the Kc encryption key, or uzyskiwania wektorowego klucza uwierzytelnienia z komunikatu odpowiedzi kontekstu zarządzania mobilnością wysłanego z węzła obsługującego usługi pakietowego przesyłania danych, SGSN, oraz algorytmu bezpieczeństwa NAS obsługiwanego przez UE;wybierania algorytmu bezpieczeństwa NAS według algorytmu bezpieczeństwa NAS obsługiwanego przez UE oraz generowania i wysłania komunikatu zawierającego wybrany algorytm bezpieczeństwa NAS do UE;jak również wyprowadzania klucza ochrony NAS według klucza głównego, który jest wyprowadzany według uzyskanego wektorowego klucza uwierzytelnienia, gdzie gdy węzeł SGSN jest węzłem SGSN sieci 2G, wektorowy klucz uwierzytelnienia zawiera co najmniej klucz szyfrowania Kc lub wartość uzyskaną po przeprowadzeniu jednokierunkowej konwersji na klucz szyfrowania Kc, lub - 15 gdy węzeł SGSN jest węzłem SGSN sieci 3G, wektorowy klucz uwierzytelnienia zawiera co najmniej klucz integralności IK oraz klucz szyfrowania CK lub wartości uzyskane po wykonaniu konwersji jednokierunkowej na klucz IK oraz klucz szyfrowania CK. - when the SGSN is the SGSN of the 3G network, the vector authentication key shall contain at least the IK integrity key and the CK encryption key or values obtained after the one-way conversion into the IK key and the CK encryption key.
- 8Mobility management unit, MME containing the acquisition module, selection module and key output module, where the takeover module is adapted to receive a TAU request message, tracking zone update, sent from user's equipment, EU obtaining the vector authentication key from the response of the mobility management context sent from the node serving the packet data transfer services, SGSN and NAS security algorithm, accessless layer, the UE supported TAU request in the message;8. Jednostka zarządzania mobilnością, MME, zawierająca moduł przejęcia, moduł wyboru oraz moduł wyprowadzania klucza, gdzie moduł przejęcia jest przystosowany do odbierania komunikatu żądania TAU, aktualizacji strefy śledzenia, wysyłanego ze sprzętu użytkownika, UE, uzyskiwania wektorowego klucza uwierzytelnienia z komunikatu odpowiedzi kontekstu zarządzania mobilnością wysyłanego z węzła obsługującego usługi pakietowego przesyłania danych, SGSN oraz algorytmu bezpieczeństwa NAS, warstwy bezdostępowej, obsługiwanego przez UE uwzględnionego w komunikacie żądania TAU;moduł wyboru jest przystosowany do wyboru algorytmu bezpieczeństwa NAS według algorytmu bezpieczeństwa NAS, obsługiwanego przez UE i uzyskiwanego przez moduł przejęcia, generowania i wysyłania komunikatu zawierającego wybrany algorytm bezpieczeństwa NAS do UE oraz moduł wyprowadzania klucza jest przystosowany do wyprowadzania klucza ochrony NAS według klucza głównego, który jest wyprowadzany według wektorowego klucza uwierzytelnienia uzyskanego poprzez moduł przejęcia oraz algorytmu bezpieczeństwa NAS wybranego przez moduł wyboru, gdzie gdy węzeł SGSN jest węzłem SGSN sieci 2G, wektorowy klucz uwierzytelnienia zawiera co najmniej klucz szyfrowania Kc lub wartość uzyskaną po wykonaniu konwersji jednokierunkowej na klucz Kc;lub gdy węzeł SGSN jest węzłem SGSN sieci 3G, wektorowy klucz uwierzytelnienia zawiera co najmniej klucz integralności IK oraz klucz szyfrowania CK lub wartości uzyskane po wykonaniu konwersji jednokierunkowej na klucz szyfrowania CK oraz IK. the selection module is adapted to select the NAS security algorithm according to the NAS security algorithm, operated by the UE and obtained by the takeover module, generating and sending a message containing the selected NAS security algorithm to the UE and the key output module is adapted to output the NAS protection key according to the master key, which is derived according to the vector authentication key obtained through the takeover module and the NAS security algorithm chosen by the selection module, where when the SGSN node is the SGSN node of the 2G network, the vector authentication key contains at least the Kc encryption key or the value obtained after performing a one-way conversion into the Kc key;or when the SGSN node is a SGSN node of the 3G network, the vector authentication key contains at least the IK integrity key and the CK encryption key or values obtained after performing a one-way conversion into the CK and IK encryption key.
- 10User equipment, UE, where, when the UE is idle, it passes from the second / third generation network, 2G / 3G, to the data transmission standard, LTE network, the UE 10. Sprzęt użytkownika, UE, w którym, gdy UE jest w stanie bezczynności, przechodzi z sieci drugiej/trzeciej generacji, 2G/3G, do sieci standardu przesyłu danych, LTE, przy czym UE - 16 includes the update module, key output module, memory module and detection module, where the update module is adapted to send tracking zone updates, TAU, request message containing security capability information, supported by the UE and stored in the memory module of the mobility management unit, MME, and receiving a message containing the selected accessless layer, NAS, a security algorithm sent from the MME;- 16 zawiera moduł aktualizacji, moduł wyprowadzania klucza, moduł pamięci oraz moduł detekcji, gdzie moduł aktualizacji jest przystosowany do wysyłania aktualizacji strefy śledzenia, TAU, komunikatu żądania zawierającego informacje zdolności bezpieczeństwa, obsługiwane przez UE i przechowywane w module pamięci jednostki zarządzania mobilnością, MME, oraz odbierania komunikatu zawierającego wybraną warstwę bezdostępową, NAS, algorytmu bezpieczeństwa wysyłanego z MME;moduł wyprowadzania klucza jest przystosowany do wyprowadzania klucza ochrony NAS według klucza głównego, który jest wyprowadzony według aktualnego wektorowego klucza uwierzytelnienia oraz algorytmu bezpieczeństwa NAS odebranego przez moduł aktualizacji;the key output module is adapted to output the NAS protection key according to the master key, which is derived according to the current vector authentication key and the NAS security algorithm received by the update module;moduł pamięci jest przystosowany do przechowywania informacji zdolności bezpieczeństwa, obsługiwanych przez UE;the memory module is adapted to store information of security capabilities supported by the UE;a moduł detekcji jest przystosowany do określania, czy ma miejsce atak degradujący podczas wykrycia, że informacje zdolności bezpieczeństwa, obsługiwane przez UE, i odebrane z MME są niezgodne z informacjami zdolności bezpieczeństwa, obsługiwanymi przez UE i przechowywanymi w module pamięci. and the detection module is adapted to determine if a degrading attack takes place when it is detected that the security capability information, supported by the UE, and received from the MME is inconsistent with the security capability information, supported by the UE and stored in the memory module.
- 12A method of negotiating security capability when a user equipment, UE, moves, in which, when the UE is idle, moves from the second / third generation network, 2G / 3G, to the data standard, LTE network, this method includes :12. Sposób negocjacji zdolności bezpieczeństwa, gdy sprzęt użytkownika, UE, przemieszcza się, w którym, gdy UE jest w stanie bezczynności, przemieszcza się z sieci drugiej/trzeciej generacji, 2G/3G, do sieci standardu przesyłu danych, LTE, przy czym sposób ten obejmuje: odbieranie (300), przez jednostkę zarządzania mobilnością MME, aktualizacji strefy śledzenia, TAU, komunikatu żądania wysyłanego z UE;receiving (300), by the MME mobility management entity, tracking zone update, TAU, request message sent from the UE;obtaining (301, 302) an MME accessless NAS security layer algorithm supported by the UE;uzyskiwanie (301, 302) przez MME warstwy bezdostępowej NAS algorytmu bezpieczeństwa obsługiwanego przez UE;obtaining (303), by MME, the master key, Kasme, derived according to the subscriber's home authentication vector key, HSS, through the authentication and key reconciliation procedure, AKA;uzyskiwanie (303), przez MME, klucza głównego, Kasme, wyprowadzonego według wektorowego klucza uwierzytelnienia domowego serwera abonenta, HSS, poprzez procedurę uzgodnienia uwierzytelnienia i klucza, AKA;selecting (304), by MME, a NAS security algorithm according to a UE-supported NAS security algorithm and a NAS security algorithm supported by a MME, and outputting (304), by a MME, a NAS security key by master key;wybieranie (304), przez MME, algorytmu bezpieczeństwa NAS według algorytmu bezpieczeństwa NAS obsługiwanego przez UE oraz algorytmu bezpieczeństwa NAS obsługiwanego przez MME oraz wyprowadzanie (304), przez MME, klucza ochrony NAS według klucza głównego;generating (305) and sending, by MME, NAS, SMC security mode commands, a request message containing the selected NAS security algorithm to the UE;generowanie (305) i wysyłanie, przez MME, komendy trybu bezpieczeństwa NAS, SMC, komunikatu żądania zawierającego wybrany algorytm bezpieczeństwa NAS do UE;- 17 odbieranie (306), przez UE, komunikatu żądania SMC, zawierającego algorytm bezpieczeństwa NAS wybrany przez MME, pozyskiwanie algorytmu bezpieczeństwa NAS obsługiwanego przez UE i wybranego przez MME, a następnie wyprowadzanie (306) klucza głównego według aktualnego wektorowego klucza uwierzytelnienia uzyskanego w procedurze AKA oraz wyprowadzanie (306) klucza ochrony NAS według klucza głównego. - receiving (306), by the UE, an SMC request message containing the NAS security algorithm selected by the MME, acquiring the NAS security algorithm supported by the UE and selected by the MME, and then deriving (306) the master key according to the current vector authentication key obtained in the procedure AKA and output (306) of the NAS protection key by master key.
Independent claims7
92 paragraphs, as filed
[0001] The invention relates to the field of wireless communications technology, in particular the method and system for negotiating security capabilities during terminal movement, mobility management entity (MME) and user equipment (UE).
BACKGROUND OF THE INVENTION [0002] A wireless network includes a radio access network and a core network. The backbone network of the LTE (Standard Long Term Evolution) contains MME. MME has functions similar to those of the node (SGSN) that supports packet data transmission services in GSM networks (GPRS). General Packet Radio Service) of the second / third generation networks (2G / 3G), and is mainly responsible for mobility management and user authentication. If the UE is idle in a 2G / 3G network or LTE wireless network, the UE must properly negotiate the security capability of the accessless signaling (NAS). non-access signaling) from an SGSN or MME node. The security capability includes the NAS signaling encryption algorithm, the corresponding Knas-int NAS integrity protection key, the NAS integrity protection algorithm and the corresponding Knas-enc confidentiality protection key, which are used to signal transmission between the UE and the system, thus ensuring normal reception of UE signaling and security communication system.
[0003] When the UE enters the global 2G mobile communication system (GSM, global system for mobile communications) an edge wireless access network (GERAN) or a universal 3G mobile communication system (UMTS) universal mobile telecommunications system) of terrestrial radio access network (UTRAN) terrestrial radio access network) goes into idle state, the UE may go to the LTE radio access network tracking zone, and thus the UE may re-access the network using LTE. At this moment, the tracking zone update procedure (TAU) appears tracking area update), i.e. there is a TAU procedure between heterogeneous networks. During the procedure, because the entity performs security capability negotiations for the UE, it changes, for example, from the SGSN node to the MME, and the entities may have different security capabilities, the security capability negotiation procedure must be re-performed to ensure the security of subsequent EU-network interactions. It should be noted that for LTE networks, security capability negotiations include negotiation of NAS confidentiality protection algorithm and NAS integrity protection algorithm, radio resource control confidentiality algorithm (RRC). radio resource control) and the RRC integrity protection algorithm, as well as the user level confidentiality algorithm (UP) user plane).
[0004] In the case of the TAU procedure initiated by the UE in idle state, the negotiation issues of the NAS confidentiality protection algorithm, the NAS integrity protection algorithm and the corresponding NAS protection keys should be resolved.
[0005] During the implementation of the invention, the inventor has found that no way can be found for the negotiation of security capabilities during the TAU procedure between heterogeneous networks in the prior art, so that with the transition of the UE from the 2G / 3G network to the LTE network, the negotiation of security capabilities cannot be carried out. as a result, the security of the next interaction between the EU and the network cannot be guaranteed.
[0006] "A joint project of several standardization organizations aimed at developing third generation 3G mobile telephony systems: Group services of technical specifications and system aspects; GPRS enhancement for E-UTRAN access (Issue 8) "3GPP STANDARD: 3GPP TS 23.401, A joint project of several standardization organizations aimed at developing third generation 3G (3GPP) mobile telephony systems, Mobile competence center; 650, ROUTE DES LUCIOLES, F-06921 SOPHIAANTIPOLIS CEDEX, France, No. V1.1.0, 1 July 2007 (01.07.2007), pages 1-78, XP050363612 defines GPRS improvements for E-UTRAN access.
[0007] SIEMENS NOKIA ET AL NETWORKS: "Pseudo - CR to TR 33.821: Keyboard support for mobility in idle mode" 3GPP VERSION; S3-070529, Joint project of several standardization organizations, aimed at developing third generation 3G (3GPP) mobile telephony systems, 650 Mobile Competence Center, ROUTE DES LUCIOLES, F-06921 SOPHIA-ANTIPOLIS CEDEX, FRANCE, volume SA WG3, Montreal No. 20070703, 3 July 2007 (03.07.2007), XP050279999, discusses keyboard support for idle mobility, when the UE switches from the previous LTE network to the new LTE network.
[0008] 3GPP: "A joint project of several standardization organizations, aimed at developing third generation 3G mobile telephony systems: Group services of technical specifications and system aspects; Rationality and decision path regarding security in the Long Term Evolved (LTE) RAN / 3GPP access system Architecture Evolution (SAE) (8th edition) "3GPP PROJECT, S3-070625-TR33821-V040CL, Joint project of several standardization organizations, aimed at developing third generation 3G (3GPP) mobile telephony systems, Mobile Competence Center, 650, ROUTE DES LUCIOLES, F-06921 SOPHIA-ANTIPOLIS CEDEX, FRANCE, volume SA WG3, Montreal No. 20070714, 14 July 2007 (14.07.2007), XP050280077 discusses the rationality and decision making path for security in the LTE RAN / 3GPP SAE network.
[0009] "A joint project of several standardization organizations aimed at the development of 3G 3G mobile telephony systems: Group services of technical specifications and system aspects; 3GPP System Architecture Evolution: Report on technical options and applications (Edition 7)" 3GPP STANDARD; 3GPP TR 23.882, 3rd GENERATION PARTNERSHIP (3GPP), Mobile Competence Center, 650, ROUTE
- 3 DES LUCIOLES, F-06921 SOPHIA-ANTIPOLIS CEDEX, FRANCE, No. V1.1 1.0, July 1, 2007 (01.07.2007), pp. 147-176, XP050364123 summarizes 3GPP System Architecture Evolution: Report on technical variants and conclusions.
SUMMARY OF THE INVENTION [0010] Thus, the invention is devoted to methods having the features of claims 1 and 12, a system with the features according to claim 6, a mobility management unit with the features according to claim 8 and a user equipment with the features according to claim 10. Preferred embodiments thereof in the relevant dependent claims.
BRIEF DESCRIPTION OF THE DRAWINGS [0011]
Fig. 1 shows a block diagram of a method according to a first embodiment of the invention for negotiating security capabilities during terminal movement;
Fig. 2 is a flowchart of a method, in accordance with a second embodiment of the invention, for negotiating security capabilities during terminal movement;
Fig. 3 is a flowchart of a method, in accordance with a second embodiment of the invention, for negotiating security capabilities during terminal movement;
Fig. 4 is a construction drawing of the system, according to an embodiment of the invention, for negotiating the security capability during terminal movement.
DETAILED DESCRIPTION OF EMBODIMENTS [0012] According to the method for negotiating security capabilities during the movement of the terminal shown in the embodiments of the invention, when UE transfers from 2G / 3G network to LTE network, The MME receives the TAU request message sent from the UE and acquires the NAS security algorithm supported by the UE, included in the TAU request message, and a vector authentication key or master key derived from the vector authentication key. The MME then selects the NAS security algorithm according to the NAS security algorithm supported by the UE, outputs the NAS protection key according to the vector authentication key or the master key derived according to the vector authentication key and sends a message containing the selected NAS security algorithm to the UE. The UE outputs the NAS protection key according to the vector authentication key.
[0013] Embodiments of the invention are set out in detail below with reference to specific embodiments and the accompanying drawings.
[0014] It is assumed that the UE has access to UTRAN / GERAN when idle. In this case, after moving to the LTE tracking zone, the UE will start the TAU procedure.
[0015] FIG. 1 is a block diagram of a method according to the first embodiment of the invention for negotiating security capabilities during terminal movement. Referring to FIG. 1, the method comprises the following steps.
[0016] At step 100, the UE sends a TAU request to the MME.
[0017] At this stage, the UE sends a TAU request to the new MME via the expanded Node B (eNB) LTE radio access network. For convenience of description, communication between UE and MME via eNB is simplified for communication between UE and MME in the description below.
[0018] The TAU request sent from the UE to the MME at this stage not only contains some parameters such as the mobile subscriber's temporal identity (TMSI). temporary mobile subscriber identity), known to experts in the field, but may also contain information on security capabilities supported by the EU. Security capability information includes a NAS security algorithm (NAS integrity protection algorithm and / or NAS confidentiality algorithm), and can also include an RRC security algorithm (RRC integrity protection algorithm and / or RRC confidentiality algorithm) or an UP security algorithm (UP confidentiality algorithm ).
[0019] In steps 101-102, the MME obtains a NAS security algorithm supported by the UE and sends a mobility management context request message to the SGSN. Upon receipt of the message, the SGSN sends a mobility management context response message containing the vector authentication key to the MME.
[0020] If at step 100, the UE does not transfer the UE supported algorithm of the UE in the TAU request sent to the MME, after receiving the mobility management context request message, the SGSN node questions the UE's security algorithm supported by the UE in the mobility management context response message sent to the MME. The NAS security algorithm is an NAS integrity protection algorithm and / or NAS confidentiality protection algorithm.
[0021] If the UE moves from the 2G network to the LTE network tracking zone, the SGSN node in the above process is the SGSN node of the 2G network, and the vector authentication key contains at least the Kc encryption key or Kc 'value obtained after performing a one-way conversion to Kc. When the UE moves from the 3G network to the LTE tracking zone, the SGSN node in the above process is the SGSN node of the 3G network, and the vector key authentication contains at least the IK integrity key and the CK encryption key or IK 'and CK' values after performing a one-way conversion to IK and CK.
[0022] Unidirectional conversion refers to a conversion procedure during which the original parameter is converted using a certain algorithm to obtain a target parameter, but the original parameter cannot be derived according to the target parameter. For example, in the case of Kc, if Kc 'is obtained using the f (KC) algorithm, but KC cannot be derived according to Kc' using any inverse algorithm, then the conversion will be a one-way conversion.
[0023] In step 103, the MME selects a new NAS security algorithm in accordance with the UE supported NAS security algorithm and an MME supported NAS security algorithm, as well as a NAS security algorithm allowed by the system, outputs the Kasme master key according to a vector key
- 5 authentication, and then derives the Kasme NAS security key. The NAS protection key includes the Knas-INT NAS integrity protection key and / or the Knas-enc NAS confidentiality key.
[0024] During step 104, the MME generates a TAU acceptance message containing the selected NAS security algorithm.
[0025] At this stage, the MME may further perform NAS integrity protection on the TAU acceptance message. For example, MME derives the value of the NAS integrity protection message authentication code (NAS-MAC), according to the Knas-int NAS integrity protection key derived during step 103, information in the TAU acceptance message and the NAS integrity protection algorithm in the selected security algorithm, and then transfers the value in TAU acceptance message and sends the TAU acceptance message to the UE.
[0026] The TAU acceptance message at this stage may further include security capability information supported by the UE.
[0027] In step 105, the UE receives the TAU acceptance message including the NAS security algorithm selected by the MME and obtains the negotiated NAS security algorithm; and then outputs the primary key Kasme according to his current vector authentication key (for example, IK and CK or IK 'and CK' derived in accordance with IK and CK when the primary network is 3G or Kc or Kc 'derived according to Kc when the primary network is 2G ) and outputs the security key according to the master key. The NAS protection key includes the Knas-int integrity protection key and / or the Knas-enc NAS confidentiality key.
[0028] At this stage, the UE may further detect if the integrity protection implemented on the TAU acceptance message is correct. If not, it will be determined that the current security capability negotiations fail and the security capability negotiation procedure can be restarted. For example, the UE outputs NAS-MAC according to the derived Knas-enc NAS confidentiality key, TAU acceptance information and NAS integrity protection algorithm carried in the TAU acceptance message, and then compares whether the derived NAS-MAC is the same as NAS-MAC placed in the TAU acceptance message. If so, it means that the message has not been modified during transmission, otherwise it is considered that the message has been modified during transmission and thus it is considered that the current security negotiation has failed.
[0029] If, in step 104, the TAU acceptance message further includes security capability information supported by the UE, during this step the UE may further compare the security capability information supported by the UE and included in the TAU acceptance message with the security capability information, here stored. If both information match, this means that there has been no degrading attack; otherwise, it appears that there has been a performance related attack and that current capacity negotiations
- 6 security fails and the procedure for negotiating security capabilities can be restarted, thus preventing a degrading attack.
[0030] In the case of a degrading attack, it is assumed that the UE supports two security algorithms simultaneously, namely high power algorithm A1 and low power algorithm A2, and MME also supports two algorithms. In this way, the high power algorithm A1 should be negotiated between UE and MME. However, if on the path along which the UE sends security capability information supported by the UE to the MME, the attacker changes UE security capability information, for example, only the A2 low power algorithm is maintained or when MME selects the NAS security algorithm, security capability information, supported by the UE, are changed by the attacker and only the A2 low power algorithm is maintained, the MME can only select and send the A2 low power algorithm to the UE. This means that the A2 low power algorithm rather than the A1 high power algorithm is obtained as a result of negotiations between the UE and MME so that the attacker can perform the attack more easily, which is also a so-called degrading attack. In the embodiment of the present invention, the MME sends the UE's security capability information to the UE, and the UE detects whether the UE's security capability information matches the UE's security capability information, thereby detecting and further preventing a degrading attack .
[0031] The procedure of the MME finally deriving the NAS protection key according to the vector authentication key during step 103 is not limited to any sequence with respect to step 104 and step 105, and the procedure can be performed before step 104 or between step 104 and step 105 or after step 105.
[0032] In the above process, the MME and UE may also directly derive the NAS protection key according to the vector authentication key without deriving the master key and then deriving the NAS protection key according to the master key.
[0033] Those skilled in the art should understand that in the above process, the derivation method used by the UE to derive the NAS protection key according to the vector authentication key must be the same as that used by the network page for deriving the NAS protection key according to the vector authentication key. The output method can take the form of any one-way conversion, for example, Kasme = f (IK, CK, other parameters), Knas-enc = f (Kasme, NAS confidentiality algorithm, other parameters) and Knas-int = f (Kasme, algorithm NAS integrity protection, other parameters).
[0034] Furthermore, in the above method, to isolate this embodiment of the invention, procedures that do not relate to protection are omitted between steps 102 and 104.
[0035] As part of the above process, the UE and MME can share the NAS security algorithm and the NAS protection key, thereby implementing NAS security capability negotiations.
[0036] FIG. 2 is a flowchart of a method, in accordance with a second embodiment of the invention, for negotiating security capabilities during terminal movement; referring to FIG. 2, the method comprises the following steps.
[0037] Step 200 is the same as step 100, therefore its description will be omitted here.
[0038] In steps 201-203, the MME obtains a NAS security algorithm supported by the UE and sends a context request message to the SGSN. Upon receiving the context request message, the SGSN derives the master key according to its vector authentication key, and then sends the context response message containing the master key to the MME.
[0039] In other embodiments of the invention, if in step 200 the UE does not carry the UE-supported NAS security algorithm in the TAU request sent to the MME, after receiving the mobility management context request message, the SGSN node questions the UE-supported NAS security algorithm, and carries the questioned NAS security algorithm supported by the UE in the mobility management context response message sent to the MME. The NAS security algorithm is an NAS integrity protection algorithm and / or NAS confidentiality protection algorithm.
[0040] When the UE moves from the 2G network to the LTE network tracking zone, the SGSN node from the above process is the SGSN node of the 2G network, and the master key is the primary Kasme key derived by the SGSN node according to Kc or Kc 'obtained after performing a one-way conversion to Kc . When the UE moves from the 3G network to the LTE tracking zone, the SGSN node from the above process is the SGSN node of the 3G network, and the primary key is Kasme, which is derived through the SGSN node according to IK and CK, or IK 'and CK' after performing one-way conversion on IK and CK.
[0041] In step 204, the MME selects the new NAS security algorithm according to the UE supported security algorithm and the NAS security algorithm supported by the MME, as well as the NAS security algorithm allowed by the system, and then outputs the NAS protection key according to the master key. The NAS protection key includes the Knas-int NAS integrity protection key and / or the Knas-enc NAS confidentiality key.
[0042] In step 205, the MME generates a TAU acceptance message containing the selected NAS security algorithm.
[0043] At this stage, the MME may further perform NAS integrity protection on the TAU acceptance message. The TAU acceptance message at this stage may further include security capability information supported by the UE.
[0044] At step 206, the UE receives the TAU acceptance message including the NAS security algorithm selected by the MME and obtains the negotiated NAS security algorithm; and then derives the Kasme master key according to its current vector authentication key (e.g. IK and CK or IK 'and CK' derived in accordance with IK and CK when the primary network is 3G or KC or KC 'that was derived
- 8 according to Kc, when the primary network is 2G), and also derives the NAS protection key according to the master key. The NAS protection key includes the Knasint NAS integrity protection key and / or the Knas-enc NAS confidentiality key.
[0045] At this stage, the UE may further detect whether the integrity protection implemented in the scope of the TAU acceptance message is adequate. If not, it will be established that the current security capability negotiations fail and the security capability negotiation procedure can be restarted.
[0046] In other embodiments of the invention, if in step 205 the TAU acceptance message further includes security capability information supported by the UE, in this step the UE may further compare the security capability information supported by the UE being in the TAU acceptance communication with the security capability information , operated by the EU. If both information match, it will be determined that no degrading attack occurs, otherwise it will appear that the degrading attack is taking place and that the current security capability negotiations fail and the security capability negotiation procedure can be restarted, preventing in this way a degrading attack.
[0047] In other embodiments of the invention, the procedure according to which the MME outputs the NAS security key according to the master key, in step 204 is not limited to any time sequence with respect to step 205 and step 206, and the procedure can be performed before step 205 or between step 205 and step 206, or after step 206.
[0048] Those skilled in the art should understand that in the above process, the derivation method used by the UE for deriving the NAS protection key according to the vector authentication key must be the same as used by the network page for deriving the NAS protection key according to the vector authentication key.
[0049] As part of the above process, the UE and MME may share a NAS security algorithm and a NAS security key, thereby negotiating NAS security capabilities.
[0050] FIG. 3 is a flowchart of a method, according to a third embodiment of the invention, to negotiate security capabilities during terminal movement. Referring to FIG. 3, the method comprises the following steps.
[0051] Step 300 is the same as step 100, hence its description is omitted here.
[0052] In steps 301-302, the MME obtains a NAS security algorithm supported by the UE from the SGSN by requesting mobility management context and response messages.
[0053] In other embodiments of the invention, if at step 300 the UE does not carry the UE-supported NAS security algorithm in the TAU request sent to the MME, after receiving the mobility management context request message, the SGSN node questions the UE-supported NAS security algorithm, and carries the questioned
- 9 NAS security algorithm supported by the UE in the mobility management context response message sent to the MME. The NAS security algorithm is an NAS integrity protection algorithm and / or NAS confidentiality protection algorithm.
[0054] In step 303, the MME obtains the Kasme master key derived according to the vector authentication key from the home subscriber server (HSS) through the authentication and key agreement (AKA).
[0055] In step 304, the MME selects the new NAS security algorithm according to the UE supported NAS security algorithm and the security algorithm
NAS supported by MME, as well as NAS security algorithm allowed by the system, and then derives other NAS protection keys according to Kasme. NAS protection keys include the Knas-int NAS integrity protection key and the Knas-enc confidentiality protection key.
[0056] In step 305, the MME generates and sends to the UE a NAS security mode command (SMC) request message containing the selected NAS security algorithm. The SMC request message may be included in the TAU acceptance message.
[0057] At this stage, the MME may further perform NAS integrity protection on the TAU acceptance message. For example, the MME outputs the value of the NAS Integrity Protection Authentication Code (NAS-MAC), according to the Knas-int NAS Integrity Protection Key derived during step 304, the information in the SMC request message and the NAS integrity protection algorithm in the selected NAS security algorithm, and then it transfers the value in the SMC request message and sends the SMC request message to the UE.
[0058] The SMC request message during this step may further include security capability information supported by the UE.
[0059] At step 306, the UE receives the SMC request message containing the NAS security algorithm selected by the MME and obtains the NAS security algorithm supported by the UE and selected by the MME, and then outputs the master key according to the current vector authentication key obtained in its AKA procedure and outputs the key NAS protection by master key. The NAS protection key includes the Knas-int NAS integrity protection key and the Knas-enc confidentiality protection key.
[0060] In this embodiment, at this stage, the UE may further detect if the integrity protection implemented on the TAU acceptance message is correct. If not, it is concluded that the current security capability negotiations fail and the security capability negotiation procedure can be restarted. For example, the UE outputs NASMAC according to the derived Knas-enc confidentiality protection key, information in the TAU acceptance message and the NAS integrity protection algorithm contained in the TAU acceptance message, and then compares whether the derived NAS-MAC is the same as the NAS-MAC contained in TAU acceptance message. If so, it shows us
- that the message has not been modified during transmission; otherwise, the message is deemed to have been modified during transmission and thus it is determined that current security negotiation fails.
[0061] In other embodiments of the invention, if in step 305 the SMC request message further includes security capability information supported by the UE, in this step the UE may further compare the security capability information supported by the UE and included in the SMC request message, with security capability information supported by the EU. If both are compatible, no degradative attack is considered to have occurred; otherwise, it will turn out that a degrading attack has occurred and that the current security capability negotiations fail and the security capability negotiation procedure can be restarted, thus preventing the degrading attack.
[0062] At step 307, the UE sends a complete SMC response message to the MME. The complete SMC reply message may be carried in the complete TAU message.
[0063] In step 308, the MME returns a TAU acceptance message.
[0064] In other embodiments of the invention, when the SMC request message is sent to the UE via the SMC request message in the TAU acceptance message in step 305, step 308 is combined with step 305.
[0065] In step 309, the UE returns a complete TAU message.
[0066] In other embodiments of the invention, in the case where the complete SMC response message is forwarded in the complete TAU message in step 307, step 309 is combined with step 307.
[0067] As part of the above process, NAS security capability negotiations are completed.
[0068] Persons of ordinary skill in the art should understand that all or part of the steps of the method of the invention can be implemented by a program instructing the relevant equipment, and the program can be stored on a computer storage medium such as, for example, memory only ROM reading / RAM direct memory, magnetic disk or optical disk.
[0069] FIG. 4 is a block diagram of the system, in accordance with an embodiment of the invention, for negotiating security capabilities during terminal movement. Referring to FIG. 4, the system includes UE and MME.
[0070] The UE is adapted to send the TAU request message to the MME, receive the message containing the selected NAS security algorithm, sent from the MME, and output the NAS protection key according to the vector authentication key.
[0071] The MME is adapted to: receive a TAU request message sent from the UE; obtaining a vector authentication key or derived key
- 11 according to the vector authentication key and NAS security algorithm supported by the UE; selecting a NAS security algorithm in accordance with a NAS security algorithm supported by the UE, and generating and sending messages containing the selected NAS security algorithm to the UE, as well as outputting a NAS security key according to the obtained vector authentication key or a master key derived according to a vector authentication key.
[0072] In the MME, the system further obtains security capability information, supported by the UE, and also carries security capability information, supported by the UE, in a message containing the selected NAS security algorithm sent to the UE, and furthermore, the UE determines whether a degradative attack is taking place by determining whether the security capability information, supported by the UE and sent from the MME, is consistent with the security capability information supported by the UE.
[0073] In particular, the MME comprises a takeover module, a selection module and a key output module.
[0074] The takeover module is adapted to receive a TAU request message sent from the UE, obtain a vector authentication key or master key derived according to the vector authentication key and a NAS security algorithm supported by the UE. The selection module is adapted to select the NAS security algorithm according to the NAS security algorithm supported by the UE and obtained by the module for taking over, generating and sending a message containing the selected security algorithm to the UE. The key output module is adapted to output the NAS protection key according to the vector authentication key or the master key derived according to the vector authentication key obtained by the takeover module and the selected NAS security algorithm.
[0075] The takeover module further obtains security capability information supported by the UE, and the selection module further includes security capability information supported by the UE and obtained by the takeover module in the message including the selected NAS security algorithm.
[0076] The UE comprises an update module, a key output module, a memory module and a detection module.
[0077] The update module is adapted to send a TAU request message containing security capability information, operated by the UE, and stored in the memory module, to the MME and receive a message containing the selected NAS security algorithm sent from the MME. The key output module is adapted to output the NAS protection key according to the vector authentication key and the selected NAS security algorithm received by the update module. The memory module is adapted to store information of security capabilities supported by UE. The detection module is adapted to determine whether the security capability information, supported by the UE, and received from the MME is
- 12 incompatible with security capability information operated by the UE and stored in the memory module. The message containing the selected NAS security algorithm sent from the MME also contains security capability information supported by the UE.
[0078] From the above description, we can deduce that in the technical solutions provided in the embodiments of the invention, The MME receives the TAU request message sent from the UE and obtains the security algorithm supported by the UE and the vector authentication key or master key derived according to the vector authentication key; and then selects the NAS security algorithm according to the NAS security algorithm supported by the UE and generates and sends a message containing the selected NAS security algorithm to the UE, thereby enabling UE and MME to share the NAS security algorithm. In addition, UE and MME derive the NAS protection key according to the vector authentication key or a master key derived according to the vector authentication key, enabling MME and UE to share the NAS protection key. In this way, when switching from a 2G / 3G network to an LTE network, the UE can negotiate the NAS security algorithm and the NAS security key with MME, thanks to which we obtain that the process of negotiating the security capability in the TAU procedure between heterogeneous networks is achieved, ensuring thus, the security of subsequent interaction between the EU and the network.
[0079] With this invention, it is also possible to prevent a degrading attack. The MME also returns the UE's security capability information using the TAU acceptance message and the UE detects whether the UE's security capability information matches the current UE's security capability information. If so, the current security capability negotiations are effective, and the NAS security algorithm and NAS security key obtained during the negotiations can be used. If not, it is considered that a degrading attack is taking place, current security capability negotiations fail, and security capability negotiations must be re-conducted. The above described solutions can detect whether security capability information, supported by the UE, is attacked before MME obtains the security capability information, supported by the UE, thus preventing a degrading attack and ensuring the security of the next interaction between the UE and the network.
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
31 members in 8 offices
Priority claims14
| Document | Office | Kind | Date |
|---|---|---|---|
| 200710145703 | China | A | |
| 200710145703 | China | A | |
| 200710151700 | China | A | |
| 200710151700 | China | A | |
| 08784154 | European Patent Office (EPO) | A | |
| 2008072165 | China | W | |
| 2008072165 | China | W | |
| 087841540 | – | – | – |
| 200710145703 | – | – | – |
| 200710151700 | – | – | – |
| CN20071145703 | – | – | – |
| CN20071151700 | – | – | – |
| EP20080784154 | – | – | – |
| WO2008CN72165 | – | – | – |
Members31
| Document | Office | Kind | |
|---|---|---|---|
| CN101378591A | China | A | |
| WO2009030155A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2139175A1 | European Patent Office (EPO) | A1 | |
| US2010095123A1 | United States of America | A1 | |
| EP2139175A4 | European Patent Office (EPO) | A4 | |
| JP2010533390A | Japan | A | |
| CN101378591B | China | B | |
| RU2009146555A | Russian Federation | A | |
| RU2435319C2 | Russian Federation | C2 | |
| JP4976548B2 | Japan | B2 | |
| EP2139175B1 | European Patent Office (EPO) | B1 | |
| EP2549701A1 | European Patent Office (EPO) | A1 | |
| ES2401039T3 | Spain | T3 | |
| PL2139175T3 | Poland | T3 | |
| US8656169B2 | United States of America | B2 | |
| EP2549701B1 | European Patent Office (EPO) | B1 | |
| US2014120879A1 | United States of America | A1 | |
| US8812848B2 | United States of America | B2 | |
| US2014295800A1 | United States of America | A1 | |
| US9241261B2 | United States of America | B2 | |
| US2016028703A1 | United States of America | A1 | |
| US2016088472A1 | United States of America | A1 | |
| US9497625B2 | United States of America | B2 | |
| US9538373B2 | United States of America | B2 | |
| US2017094506A1 | United States of America | A1 | |
| EP2139175B3 | European Patent Office (EPO) | B3 | |
| ES2401039T7 | Spain | T7 | |
| PL2139175T6This record | Poland | T6 | |
| US10015669B2 | United States of America | B2 | |
| US2018310170A1 | United States of America | A1 | |
| US10595198B2 | United States of America | B2 |
Numbers
- Publication
- 2139175
- Publication, DOCDB
- 2139175
- Publication, EPODOC
- PL2139175T
- Application
- 8784154
- Application, DOCDB
- 08784154
- Application, EPODOC
- PL20080784154T
Titles2
- English
- METHOD, SYSTEM AND APPARATUS FOR NEGOTIATING THE SECURITY ABILITY WHEN A TERMINAL IS MOVING
- Polish
- Sposób, system i urządzenie do negocjacji zdolności bezpieczeństwa podczas przemieszczania się terminala
Classification
- CPC, 16
- H04L9/0844
- H04L63/1441
- H04L63/20
- H04L63/205
- H04L2463/061
- H04L9/088
- H04L69/24
- H04W12/0431
- H04W12/041
- H04W12/106
- H04W12/122
- H04W36/0038
- H04L63/0492
- H04L63/062
- H04L63/0876
- H04W8/02
- IPC, 7
- H04L29 06
- H04L9 08
- H04L9 32
- H04W12 041
- H04W12 0431
- H04W12 06
- H04W12 08