PL2139175T6

Method, system and apparatus for negotiating the security ability when a terminal is moving

Abstract

A communication method includes receiving by a SGSN a context request message from a mobility management entity (MME), obtaining by the SGSN an authentication vector-related key, and calculating by the SGSN a root key according to the authentication vector-related key. In addition, the method further includes sending by the SGSN a context response message including the root key to the MME, wherein the MME derives a NAS protection key according to the root key.

PL2139175T6, drawing sheet 1
Sheet 1 of 4

Term

1.9 yearsto projected expiry

Projected expiry 27 August 2028, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

12 claims: 7 independent, 5 dependent

  1. 1
    Patent claims Zastrzeżenia patentowe 1. The method of negotiating security capability when a user equipment, UE, moves, while, when the UE is idle, it moves from the second / third generation network, 2G / 3G, to the data transmission standard, LTE network, this method includes:1. Sposób negocjacji zdolności bezpieczeństwa, gdy sprzęt użytkownika, UE, przemieszcza się, przy czym, gdy UE jest w stanie bezczynności, przechodzi z sieci drugiej/trzeciej generacji, 2G/3G, do sieci standardu przesyłu danych, LTE, sposób ten obejmuje: odbieranie, za pomocą jednostki zarządzania mobilnością, MME, aktualizacji strefy śledzenia, TAU, komunikatu żądania wysłanego (100) z UE;receiving, using the mobility management unit, MME, tracking zone update, TAU, request message sent (100) from the UE;obtaining (101), using MME, a NAS accessless layer, a security algorithm supported by the UE;uzyskiwanie (101), za pomocą MME, warstwy bezdostępowej NAS, algorytmu bezpieczeństwa obsługiwanego przez UE;obtaining (102), by MME, a vector authentication key from a mobility management context response message sent from a node serving packet data services, SGSN;uzyskiwanie (102), przez MME, wektorowego klucza uwierzytelnienia z komunikatu odpowiedzi kontekstu zarządzania mobilnością, wysłanego z węzła obsługującego usługi pakietowego przesyłania danych, SGSN;selecting (103), by MME, a NAS security algorithm according to a UE-supported NAS security algorithm, deriving a master key according to a vector authentication key, and then deriving a NAS protection key according to a derived master key, and sending (104) a message containing the selected NAS security algorithm to the UE and receiving (104), by the UE, a message including the selected NAS security algorithm sent by the MME;wybieranie (103), przez MME, algorytmu bezpieczeństwa NAS według algorytmu bezpieczeństwa NAS obsługiwanego przez UE, wyprowadzanie klucza głównego według wektorowego klucza uwierzytelnienia, a następnie wyprowadzanie klucza ochrony NAS według wyprowadzonego klucza głównego oraz wysyłanie (104) komunikatu zawierającego wybrany algorytm bezpieczeństwa NAS do UE oraz odbieranie (104), przez UE, komunikatu zawierającego wybrany algorytm bezpieczeństwa NAS wysłany przez MME;output (105), by the EU, master key according to the current vector authentication key and then deriving the NAS security key, according to the derived master key, where when the SGSN node is the SGSN node of the 2G network, the vector authentication key contains at least the Kc encryption key or the value obtained after one-way conversion to the Kc encryption key, or when the SGSN node is a SGSN node of the 3G network, the vector authentication key contains at least the IK integrity key and the CK encryption key or values ​​obtained after performing a one-way conversion to IK and the CK encryption key. wyprowadzanie (105), przez UE, klucza głównego, według aktualnego wektorowego klucza uwierzytelnienia oraz następnie wyprowadzanie klucza bezpieczeństwa NAS, zgodnie z wyprowadzonym kluczem głównym, gdzie gdy węzeł SGSN jest węzłem SGSN sieci 2G, wektorowy klucz uwierzytelnienia zawiera co najmniej klucz szyfrowania Kc lub wartość uzyskaną po przeprowadzeniu jednokierunkowej konwersji na klucz szyfrowania Kc, lub gdy węzeł SGSN jest węzłem SGSN sieci 3G, wektorowy klucz uwierzytelnienia zawiera co najmniej klucz integralności IK i klucz szyfrowania CK lub wartości uzyskane po wykonaniu jednokierunkowej konwersji na IK oraz klucz szyfrowania CK.
  2. 2
    The method according to claim Wherein the MME obtaining a NAS security algorithm supported by the UE includes:2. Sposób według zastrz. 1, w którym uzyskanie, przez MME, algorytmu bezpieczeństwa NAS obsługiwanego przez UE, obejmuje: obtaining, by the MME, security capability information supported by the UE from a TAU request message sent from the UE, where the TAU request message includes a NAS security algorithm supported by the UE. uzyskiwanie, przez MME, informacji zdolności bezpieczeństwa, obsługiwanych przez UE, z komunikatu żądania TAU wysłanego z UE, gdzie komunikat żądania TAU zawiera algorytm bezpieczeństwa NAS obsługiwany przez UE.
  3. 3
    The method according to claim Wherein the MME obtaining a NAS security algorithm supported by the UE includes:3. Sposób według zastrz. 1, w którym uzyskanie przez MME algorytmu bezpieczeństwa NAS, obsługiwanego przez UE, obejmuje: - 14 uzyskiwanie przez MME informacji zdolności bezpieczeństwa, obsługiwanych przez UE, z komunikatu odpowiedzi kontekstu wysłanego z węzła SGSN, gdzie komunikat odpowiedzi kontekstu zawiera algorytm bezpieczeństwa NAS, obsługiwany przez UE. - MME obtaining security capability information, supported by the UE, from the context response message sent from the SGSN, where the context response message includes a NAS security algorithm supported by the UE.
  4. 6
    A system for negotiating security capability when a user equipment, UE, moves, in which, when the UE is idle, it passes from the second / third generation network, 2G / 3G, to the data transmission standard network, LTE, the system includes UE and a mobility management unit, MME, where 6. System do negocjacji zdolności bezpieczeństwa, gdy sprzęt użytkownika, UE, przemieszcza się, w którym, gdy UE jest w stanie bezczynności, przechodzi z sieci drugiej/trzeciej generacji, 2G/3G, do sieci standardu przesyłu danych, LTE, przy czym system obejmuje UE oraz jednostkę zarządzania mobilnością, MME, gdzie The UE is adapted to send the tracking zone update, TAU, request message to the MME, receive the message containing the selected accessless layer, NAS, the security algorithm sent from the MME and output the NAS protection key according to the master key, which is output according to the current vector authentication key, and UE jest przystosowany do wysyłania aktualizacji strefy śledzenia, TAU, komunikatu żądania do MME, odbierania komunikatu zawierającego wybraną warstwę bezdostępową, NAS, algorytmu bezpieczeństwa wysłanego z MME i wyprowadzania klucza ochrony NAS według klucza głównego, który jest wyprowadzany według aktualnego wektorowego klucza uwierzytelnienia oraz MME jest przystosowana do:odbierania komunikatu żądania TAU wysłanego z UE;The MME is adapted to: receive a TAU request message sent from the UE;obtaining a vector authentication key from a mobility management context response message sent from a node serving packet data services, SGSN, and a NAS security algorithm supported by the EU;selecting a NAS security algorithm according to a NAS security algorithm supported by the UE, and generating and sending a message containing the selected NAS security algorithm to the UE;as well as deriving the NAS protection key according to the master key, which is derived according to the obtained vector authentication key, where when the SGSN node is the SGSN node of the 2G network, the vector authentication key contains at least the Kc encryption key or the value obtained after one-way conversion to the Kc encryption key, or uzyskiwania wektorowego klucza uwierzytelnienia z komunikatu odpowiedzi kontekstu zarządzania mobilnością wysłanego z węzła obsługującego usługi pakietowego przesyłania danych, SGSN, oraz algorytmu bezpieczeństwa NAS obsługiwanego przez UE;wybierania algorytmu bezpieczeństwa NAS według algorytmu bezpieczeństwa NAS obsługiwanego przez UE oraz generowania i wysłania komunikatu zawierającego wybrany algorytm bezpieczeństwa NAS do UE;jak również wyprowadzania klucza ochrony NAS według klucza głównego, który jest wyprowadzany według uzyskanego wektorowego klucza uwierzytelnienia, gdzie gdy węzeł SGSN jest węzłem SGSN sieci 2G, wektorowy klucz uwierzytelnienia zawiera co najmniej klucz szyfrowania Kc lub wartość uzyskaną po przeprowadzeniu jednokierunkowej konwersji na klucz szyfrowania Kc, lub - 15 gdy węzeł SGSN jest węzłem SGSN sieci 3G, wektorowy klucz uwierzytelnienia zawiera co najmniej klucz integralności IK oraz klucz szyfrowania CK lub wartości uzyskane po wykonaniu konwersji jednokierunkowej na klucz IK oraz klucz szyfrowania CK. - when the SGSN is the SGSN of the 3G network, the vector authentication key shall contain at least the IK integrity key and the CK encryption key or values ​​obtained after the one-way conversion into the IK key and the CK encryption key.
  5. 8
    Mobility management unit, MME containing the acquisition module, selection module and key output module, where the takeover module is adapted to receive a TAU request message, tracking zone update, sent from user's equipment, EU obtaining the vector authentication key from the response of the mobility management context sent from the node serving the packet data transfer services, SGSN and NAS security algorithm, accessless layer, the UE supported TAU request in the message;8. Jednostka zarządzania mobilnością, MME, zawierająca moduł przejęcia, moduł wyboru oraz moduł wyprowadzania klucza, gdzie moduł przejęcia jest przystosowany do odbierania komunikatu żądania TAU, aktualizacji strefy śledzenia, wysyłanego ze sprzętu użytkownika, UE, uzyskiwania wektorowego klucza uwierzytelnienia z komunikatu odpowiedzi kontekstu zarządzania mobilnością wysyłanego z węzła obsługującego usługi pakietowego przesyłania danych, SGSN oraz algorytmu bezpieczeństwa NAS, warstwy bezdostępowej, obsługiwanego przez UE uwzględnionego w komunikacie żądania TAU;moduł wyboru jest przystosowany do wyboru algorytmu bezpieczeństwa NAS według algorytmu bezpieczeństwa NAS, obsługiwanego przez UE i uzyskiwanego przez moduł przejęcia, generowania i wysyłania komunikatu zawierającego wybrany algorytm bezpieczeństwa NAS do UE oraz moduł wyprowadzania klucza jest przystosowany do wyprowadzania klucza ochrony NAS według klucza głównego, który jest wyprowadzany według wektorowego klucza uwierzytelnienia uzyskanego poprzez moduł przejęcia oraz algorytmu bezpieczeństwa NAS wybranego przez moduł wyboru, gdzie gdy węzeł SGSN jest węzłem SGSN sieci 2G, wektorowy klucz uwierzytelnienia zawiera co najmniej klucz szyfrowania Kc lub wartość uzyskaną po wykonaniu konwersji jednokierunkowej na klucz Kc;lub gdy węzeł SGSN jest węzłem SGSN sieci 3G, wektorowy klucz uwierzytelnienia zawiera co najmniej klucz integralności IK oraz klucz szyfrowania CK lub wartości uzyskane po wykonaniu konwersji jednokierunkowej na klucz szyfrowania CK oraz IK. the selection module is adapted to select the NAS security algorithm according to the NAS security algorithm, operated by the UE and obtained by the takeover module, generating and sending a message containing the selected NAS security algorithm to the UE and the key output module is adapted to output the NAS protection key according to the master key, which is derived according to the vector authentication key obtained through the takeover module and the NAS security algorithm chosen by the selection module, where when the SGSN node is the SGSN node of the 2G network, the vector authentication key contains at least the Kc encryption key or the value obtained after performing a one-way conversion into the Kc key;or when the SGSN node is a SGSN node of the 3G network, the vector authentication key contains at least the IK integrity key and the CK encryption key or values ​​obtained after performing a one-way conversion into the CK and IK encryption key.
  6. 10
    User equipment, UE, where, when the UE is idle, it passes from the second / third generation network, 2G / 3G, to the data transmission standard, LTE network, the UE 10. Sprzęt użytkownika, UE, w którym, gdy UE jest w stanie bezczynności, przechodzi z sieci drugiej/trzeciej generacji, 2G/3G, do sieci standardu przesyłu danych, LTE, przy czym UE - 16 includes the update module, key output module, memory module and detection module, where the update module is adapted to send tracking zone updates, TAU, request message containing security capability information, supported by the UE and stored in the memory module of the mobility management unit, MME, and receiving a message containing the selected accessless layer, NAS, a security algorithm sent from the MME;- 16 zawiera moduł aktualizacji, moduł wyprowadzania klucza, moduł pamięci oraz moduł detekcji, gdzie moduł aktualizacji jest przystosowany do wysyłania aktualizacji strefy śledzenia, TAU, komunikatu żądania zawierającego informacje zdolności bezpieczeństwa, obsługiwane przez UE i przechowywane w module pamięci jednostki zarządzania mobilnością, MME, oraz odbierania komunikatu zawierającego wybraną warstwę bezdostępową, NAS, algorytmu bezpieczeństwa wysyłanego z MME;moduł wyprowadzania klucza jest przystosowany do wyprowadzania klucza ochrony NAS według klucza głównego, który jest wyprowadzony według aktualnego wektorowego klucza uwierzytelnienia oraz algorytmu bezpieczeństwa NAS odebranego przez moduł aktualizacji;the key output module is adapted to output the NAS protection key according to the master key, which is derived according to the current vector authentication key and the NAS security algorithm received by the update module;moduł pamięci jest przystosowany do przechowywania informacji zdolności bezpieczeństwa, obsługiwanych przez UE;the memory module is adapted to store information of security capabilities supported by the UE;a moduł detekcji jest przystosowany do określania, czy ma miejsce atak degradujący podczas wykrycia, że informacje zdolności bezpieczeństwa, obsługiwane przez UE, i odebrane z MME są niezgodne z informacjami zdolności bezpieczeństwa, obsługiwanymi przez UE i przechowywanymi w module pamięci. and the detection module is adapted to determine if a degrading attack takes place when it is detected that the security capability information, supported by the UE, and received from the MME is inconsistent with the security capability information, supported by the UE and stored in the memory module.
  7. 12
    A method of negotiating security capability when a user equipment, UE, moves, in which, when the UE is idle, moves from the second / third generation network, 2G / 3G, to the data standard, LTE network, this method includes :12. Sposób negocjacji zdolności bezpieczeństwa, gdy sprzęt użytkownika, UE, przemieszcza się, w którym, gdy UE jest w stanie bezczynności, przemieszcza się z sieci drugiej/trzeciej generacji, 2G/3G, do sieci standardu przesyłu danych, LTE, przy czym sposób ten obejmuje: odbieranie (300), przez jednostkę zarządzania mobilnością MME, aktualizacji strefy śledzenia, TAU, komunikatu żądania wysyłanego z UE;receiving (300), by the MME mobility management entity, tracking zone update, TAU, request message sent from the UE;obtaining (301, 302) an MME accessless NAS security layer algorithm supported by the UE;uzyskiwanie (301, 302) przez MME warstwy bezdostępowej NAS algorytmu bezpieczeństwa obsługiwanego przez UE;obtaining (303), by MME, the master key, Kasme, derived according to the subscriber's home authentication vector key, HSS, through the authentication and key reconciliation procedure, AKA;uzyskiwanie (303), przez MME, klucza głównego, Kasme, wyprowadzonego według wektorowego klucza uwierzytelnienia domowego serwera abonenta, HSS, poprzez procedurę uzgodnienia uwierzytelnienia i klucza, AKA;selecting (304), by MME, a NAS security algorithm according to a UE-supported NAS security algorithm and a NAS security algorithm supported by a MME, and outputting (304), by a MME, a NAS security key by master key;wybieranie (304), przez MME, algorytmu bezpieczeństwa NAS według algorytmu bezpieczeństwa NAS obsługiwanego przez UE oraz algorytmu bezpieczeństwa NAS obsługiwanego przez MME oraz wyprowadzanie (304), przez MME, klucza ochrony NAS według klucza głównego;generating (305) and sending, by MME, NAS, SMC security mode commands, a request message containing the selected NAS security algorithm to the UE;generowanie (305) i wysyłanie, przez MME, komendy trybu bezpieczeństwa NAS, SMC, komunikatu żądania zawierającego wybrany algorytm bezpieczeństwa NAS do UE;- 17 odbieranie (306), przez UE, komunikatu żądania SMC, zawierającego algorytm bezpieczeństwa NAS wybrany przez MME, pozyskiwanie algorytmu bezpieczeństwa NAS obsługiwanego przez UE i wybranego przez MME, a następnie wyprowadzanie (306) klucza głównego według aktualnego wektorowego klucza uwierzytelnienia uzyskanego w procedurze AKA oraz wyprowadzanie (306) klucza ochrony NAS według klucza głównego. - receiving (306), by the UE, an SMC request message containing the NAS security algorithm selected by the MME, acquiring the NAS security algorithm supported by the UE and selected by the MME, and then deriving (306) the master key according to the current vector authentication key obtained in the procedure AKA and output (306) of the NAS protection key by master key.