Method and arrangement in a telecommunication system
Abstract
A method in a User Equipment (UE) of an Evolved Packet System (EPS) establishes a security key (K_eNB) for protecting Radio Resource Control/User Plane (RRC/UP) traffic exchanged with a serving eNodeB. The method comprises sending a Non-Access Stratum (NAS) Service Request to a Mobility Management Entity (MME), the request indicating a NAS uplink sequence number (NAS_U_SEQ). The method further comprises receiving an indication of the NAS_U_SEQ of the NAS Service Request sent to the MME, back from the MME via the eNodeB. The method further comprises deriving the K_eNB from at least the received indication of the NAS_U_SEQ and from a stored Access Security Management Entity-key (K_ASME) shared with said MME.

Term
1.7 yearsto projected expiry
Projected expiry 20 May 2028, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
23 claims: 14 independent, 9 dependent
- 1Claims Zastrzeżenia patentowe 1. A method in the MME mobility management unit (13) of the extended EPS system for determining the security key K_eNB for protection of RRC / UP traffic between the UE (11) and eNodeB (12) serving the UE, the method comprising the steps of:1. Sposób w jednostce zarządzania ruchliwością MME (13) rozbudowanego systemu pakietów EPS ustalania klucza zabezpieczeń K_eNB dla ochrony ruchu RRC/UP pomiędzy urządzeniem użytkownika UE (11) a eNodeB (12) obsługującym UE, przy czym sposób obejmuje następujące etapy: - odbiór (32, 52) żądania usługi NAS z UE, żądania wskazują cego liczbę sekwencji połączenia wstępującego NAS, NAS_U_SEQ, - receiving (32, 52) NAS service requests from the UE, the request indicating the number of uplink NAS connection sequence, NAS_U_SEQ, - obtaining (33, 53) the K_eNB security key from at least said received NAS_U_SEQ and from the stored security entity management key K_ASME provided to said UE, - uzyskiwanie (33, 53) klucza zabezpieczeń K_eNB z przynajmniej wspomnianego odebranego NAS_U_SEQ oraz z przechowywanego w pamięci klucza K_ASME jednostki zarządzania zabezpieczeniami, udostępnianych wspomnianemu UE, - przekazywanie (34) wspomnianego uzyskanego K_eNB do eNodeB (12) obsługującego wspomniane UE. - transmitting (34) said obtained K_eNB to an eNodeB (12) serving said UE.
- 4A method in an MME, as claimed in any preceding claim, comprising a further step of checking the integrity of a NAS service request received from the UE (11). 4. Sposób w MME, według dowolnego z poprzednich zastrzeżeń, obejmujący kolejny etap sprawdzania integralności żądania usługi NAS, otrzymanego z UE (11).
- 5A method in an MME, as claimed in any preceding claim, comprising a further step of returning (54, 55) the indication of the received NAS_U_SEQ to the UE (11). 5. Sposób w MME, według dowolnego z poprzednich zastrzeżeń, obejmujący kolejny etap zwracania (54, 55) wskazania odebranego NAS_U_SEQ do UE (11).
- 7A method in a UE (11) of an extensive EPS system for determining a K_eNB security key for protecting RRC / UP traffic exchanged with an eNodeB (12), the method comprising the following steps:7. Sposób w urządzeniu użytkownika UE (11) rozbudowanego systemu pakietów EPS ustalania klucza zabezpieczeń K_eNB dla ochrony ruchu RRC/UP wymienianego z obsł ugują cym eNodeB (12), przy czym sposób obejmuje nastę puj ą ce etapy: - sending (31, 51) a NAS service request to a traffic management MME unit, a request indicating the number of uplink NAS connection sequences, NAS_U_SEQ, - obtaining (35, 56) K_eNB from at least said NAS_U_SEQ and from the stored security management key K_ASME , made available to said MME. - wysyłanie (31, 51) żądania usługi NAS do jednostki MME zarządzania ruchliwoś cią, żądania wskazującego liczbę sekwencji połączenia wstępującego NAS, NAS_U_SEQ, - uzyskiwanie (35, 56) K_eNB z przynajmniej wspomnianego NAS_U_SEQ oraz z przechowywanego w pamięci klucza K_ASME jednostki zarządzania zabezpieczeniami dostępu, udostępnianych wspomnianemu MME.
- 11A method in the EU according to any of the claims 1-11. 7 - 9, comprising the receiving stage (55) of the NAS service request NAS_U_SEQ sent to the MME, back from the MME (13) via the eNodeB (12). 11. Sposób w UE według dowolnego z zastrz. 7 - 9, obejmujący etap odbioru (55) wskazania NAS_U_SEQ żądania usługi NAS, wysłanego do MME, z powrotem z MME (13) poprzez eNodeB (12).
- 12A method in the UE according to any of the claims 1-11. 10 or 11, wherein K_eNB is obtained from NAS_U_SEQ and K_ASME after receiving the security configuration message from the eNodeB. 12. Sposób w UE według dowolnego z zastrz. 10 albo 11, w którym K_eNB jest uzyskiwane z NAS_U_SEQ oraz K_ASME po odbiorze wiadomo ś ci o konfiguracji zabezpieczeń z eNodeB.
- 13An MME (13) mobility management unit adapted to an extended packet system (EPS), wherein the MME is configured to establish a K_eNB security key for RRC / UP traffic protection between UE (11) and eNodeB (12) serving the UE, wherein MME is characterized by:13. Jednostka MME (13) zarządzania ruchliwością, przystosowana do rozbudowanego systemu pakietów (EPS), przy czym MME jest skonfigurowana do ustalania klucza zabezpieczeń K_eNB dla ochrony ruchu RRC/UP pomiędzy UE (11) a eNodeB (12) obsługującym UE, przy czym MME jest znamienna przez: - means (62) for receiving a service request from a UE from the UE, the request indicating the number of uplink NAS connection sequence, NAS_U_SEQ, - ś rodki (62) do odbioru żądania usł ugi NAS z UE, przy czym żądanie wskazuje liczbę sekwencji połączenia wstępującego NAS, NAS_U_SEQ, - means (63) for obtaining K_eNB from at least said received NAS_U_SEQ and from the K_ASME key stored in the access security management entity made available to said UE, - ś rodki (63) do uzyskiwania K_eNB z przynajmniej wspomnianego odebranego NAS_U_SEQ oraz z przechowywanego w pamięci klucza K_ASME jednostki zarządzania zabezpieczeniami dostępu, udostępnianych wspomnianemu UE, - means (64) for sending said obtained K_eNB to an eNodeB serving said UE. - ś rodki (64) do wysył ania wspomnianego uzyskanego K_eNB do eNodeB obsługującego wspomniane UE.
- 17MME według dowolnego z zastrz.13 - 16, skonfigurowana do przekazywania (54) wskazania NAS_U_SEQ do eNodeB (12), dla zwrotu (55) do UE (11) z eNodeB. 17. The MME of any one of claims 13 to 16 configured to forward (54) the indication NAS_U_SEQ to the eNodeB (12) for the return (55) to the UE (11) from the eNodeB.
- 18A UE (11) user device adapted for a sophisticated EPS packet system, wherein the UE is configured to establish a K_eNB security key to protect RRC / UP traffic exchanged with an serving eNodeB (12), the UE being characterized by:18. Urządzenie użytkownika UE (11), przystosowane dla rozbudowanego systemu pakietów EPS, przy czym UE jest skonfigurowane do ustalania klucza zabezpieczeń K_eNB dla ochrony ruchu RRC/UP wymienianego z obsługującym eNodeB (12), przy czym UE jest znamienne przez: - means (66) for sending a NAS service request to the MME (13), a request indicating the number of uplink NAS connection sequence, NAS_U_SEQ, - ś rodki (66) do wysyłania żądania usługi NAS do MME (13), żądania wskazującego liczbę sekwencji połączenia wstępującego NAS, NAS_U_SEQ, - means (67) for obtaining K_eNB from at least said NAS_U_SEQ and from the K_ASME key stored in the management of the access security management device made available to said MME (13). - środki (67) do uzyskiwania K_eNB z przynajmniej wspomnianej NAS_U_SEQ oraz z przechowywanego w pamię ci klucza K_ASME jednostki zarzą dzania zabezpieczeniami dostępu, udostępnianych wspomnianej MME (13).
- 22The UE according to any of the claims 18-20, configured to receive a NAS_U_SEQ indication of a NAS service request sent to the MME (13), back from the MME via the eNodeB (12). 22. UE według dowolnego z zastrz. 18 - 20, skonfigurowane do odbioru wskazania NAS_U_SEQ żądania usługi NAS, wysłanego do MME (13), z powrotem z MME poprzez eNodeB (12).
Independent claims14
64 paragraphs, as filed
Technical field The present invention relates to methods and devices in a telecommunications system, in particular security solutions in an expanded system of Evolved Packet Systems (EPS), i.e. access to the UPLAN (Evolved UMTS Terrestrial Radio Network Access) radio network and EPC backbone network. (Evolved Packet Core network) for service requests invoked by the UE user terminal. More specifically, the present invention relates to a method and an apparatus in a mobility management unit (MME) and a UE (User Equipment) device for an Evolved Packet System (EPS) for determining a security key for RRC / UP traffic protection.
Background [0002] In the EPS architecture, the subscriber's authentication takes place between the UE and the MME (Mobility Management Entity) management unit, and the MME manages e.g. mobility, EU identity and security parameters. The basis for determining the security procedure in the EPS is the security key (K_ASME), which is made available between the MME and the EU, and which has been established during the EU authentication. An EPS architecture functional unit called an Access Security Management Entity (ASME) can, for example, be co-located with the MME, and ASME receives and stores the K_ASME security key from the CK / IK keys enclosed in the home network. From the K_ASME security key, ASME obtains the NAS security context used to protect the NAS signaling, ie NonAccess Stratum signaling between the MME of the Evolved Packet Core (EPC) network and the EU. The NAS security context contains parameters for encryption and protection of NAS signaling integrity, such as K_NAS_enc, K_NAS_int, as well as the number of down-link sequences [link between satellite and earth station] and up-link [NAS-U_SEQ] and NAS_D_SEQ ; and the number of sequences are used to prevent the repetition of old messages, as well as to introduce encryption and integrity protection procedures. ASME provides the NAS security context for MME; and a NAS security context is stored in the MME, and the correct NAS security context is maintained in the UE; and replay protection, integrity protection and encryption are based on
[0003] Preferably, the security context for protecting the UP / RRC traffic between the UE and the serving eNodeB (i.e., the radio base station in the EPS architecture) is also based on said security key (K_ASME). The procedure for determining the context of the UP / RRC security includes obtaining a key named K_eNB, from which it comes
- 2 encryption key K_eNB_UP_enc for protection of the UP user plane (User Plane), ie end user data transmitted by EPC and E-UTRAN, as well as encryption key (K_eNB_RRC_enc) and integrity protection key (K_eNB_RRC_int) to secure RRC radio resource control (Radio Resource control).
[0004] Figure 1 shows a conventional, exemplary flow of signaling for a transition initiated by the UE from a passive IDLE state to an active ACTIVE state in an EPS architecture. The UE IDLE [passive user device] is known only to the EPC (Evolved Packet Core) of the EPS system, and no UP / RRC security context exists between the eNodeB and the UE. The UE in the ACTIVE active mode is known in both the EPC and the EUTRAN network, and the UP / RRC security context has been established to protect the UP / RRC traffic between the UE and its serving eNodeB.
[0005] Figure 1 shows UE-11, eNodeB-12, MME-13, serving gateway GW (Gateway) -14, gate PDN-15 and central database of users HSS (Home Subscriber Server) - 16. Gateway operator 14 is a node from the EPC that ends the interface to the EUTRAN network, and the PDN gateway is a node from the EPC that terminates the interface to the packet data network (PDN). If the UE opens multiple PDNs, there may be multiple PDN gateways for that UE. In the signal S1 and the signal S2, the Request Service (NAS Service Request) is transparently transferred from the UE to the MME, and the NAS Service Request is protected in terms of integrity based on NAS_U_SEQ. In the optional signal S3, the UE is authenticated by the MME, and the K_ASME is determined based on subscriber data stored in memory in the Home Subscriber Server (HSS), and the MME sends the Initial Context Setup Request to eNodeB, in S4. In signals S5 and S6, the eNodeB determines the carrier in the radio interface (radio bearer) from the UE and forwards the uplink data (the transmission of signals from the earth to the satellite) and returns the message of completing the Initial Context Setup to MME in signal S7. In signal S8, the MME sends the media update request in the radio interface to the serving GW, and the serving GW responds in the S9 signal. The eNodeB determines the carrier in the radio bearer from the UE and forwards the uplink data (the transmission of signals from the Earth to the satellite) and returns the message of completing the Initial Context Setup to the MME in the S7 signal. In signal S8, the MME sends the media update request in the radio interface to the serving GW, and the serving GW responds in the S9 signal. The eNodeB determines the carrier in the radio bearer from the UE and forwards the uplink data (the transmission of signals from the Earth to the satellite) and returns the message of completing the Initial Context Setup to the MME in the S7 signal. In signal S8, the MME sends the media update request in the radio interface to the serving GW, and the serving GW responds in the S9 signal.
[0006] In known solutions, obtaining K_eNB using the UE and MME for the RRC / UP security context was based, for example, on the NAS SERVICE ACCEPT message or other explicit information sent from the MME to the UE. However, as shown in the exemplary conventional flow of EPS signaling in FIG. 1, the MME will typically not send any NAS SERVICE ACCEPT after receiving the NAS SERVICE REQUEST from the EU in EPS. Therefore, it will not be possible to obtain K_eNB from the information contained in the message NAS SERVICE ACCEPT.
[0007] According to an exemplary, known solution, K_eNB is obtained by means of MME with K_ASME and NAS_D_SEQ used by MME in a NAS SERVICE ACCEPT message, and the UE obtains the same
- 3 K_eNB by downloading the sequence number (NAS_D_SEQ) from the NAS SERVICE ACCEPT message and by doing the same to obtain K_eNB as MME. The MME forwards the K_eNB to the eNodeB while creating the S1 connection with the eNodeB. However, a disadvantage of this known solution is that if no explicit message is defined for NAS SERVICE ACCEPT from MME to UE, as in the example, conventional flow of EPS signaling in Figure 1, it is impossible for the UE to obtain the same K_eNB as MME . Even if it is technically possible for the UE to estimate the current number of downlink NAS (NAS_D_SEQ) sequences, this evaluation may be wrong because the MME could send NAS messages that were lost and never reached the UE. In this case, the MME would update its NAS_D_SEQ,
[0008] According to another exemplary known solution, obtaining K_eNB is based on a separate sequence number maintained specifically for obtaining K_eNB, and this number of sequences is clearly synchronized during a NAS service request (NAS) request or by sending it by the UE to the MME. or by sending it through the MME to the EU. However, the disadvantage of this solution is the additional complexity of the separate sequence number, since it must be maintained both in the EU and in the MME to prevent attacks by repeating.
Summary The purpose of this invention is to solve the problem described above, and this object and other objects are achieved by means of the method and apparatus according to the independent claims and by means of the dependent claims.
[0010] The basic idea of the present invention is that K_eNB is derived from K_ASME and from NAS_U_SEQ a message US SERVICE REQUEST from the UE to MME, thereby causing the UP / RRC security context to be determined in the eNodeB.
[0011] An advantage of the present invention is that no explicit downlink message US NAS SERVICE ACCEPT or number of sequences from the MME to the UE are necessary and that the protection functionality against repeating the NAS security context is reused in contexts RRC and UP security.
[0012] According to one aspect, the invention provides a method in an MME (Mobility Management Entity) management unit of an Evolved Packet System (EPS) for determining a security key (K_eNB) to protect RRC / UP traffic between a user equipment (UE) and an eNodeB serving the UE. The method includes the steps of: receiving a NAS service request (US Service Request) from the UE, a request indicating the number of uplink NAS connection (NAS_U_SEQ); obtaining a security key (K_eNB) from at least said NAS_U_SEQ and from the key storage management entity K_ASME stored in the key (Access Security Management)
- 4 Entity-key), made available to said UE; and transmitting said obtained K_eNB to an eNodeB serving the UE.
[0013] According to a second aspect, the invention provides a MME (Mobility Management Entity) management unit for an Evolved Packet System (EPS). The MME is configured to determine the security key (K_eNB) to protect the RRC / UP traffic between the UE and the eNodeB serving the UE. The MME includes means for receiving a NAS service request (US Service Request) from the UE, a request indicating the number of uplink NAS (NAS_U_SEQ) sequences; means for obtaining a K_eNB from at least said received NAS_U_SEQ and from a key access management entity K_ASME (Access Security Management Entity-key) shared with said UE; as well as means for sending said obtained K_eNB to the eNodeB serving the UE.
[0014] The first and second aspects further provide methods as well as corresponding means according to which the MME can obtain K_eNB from NAS_U_SEQ and K_ASME using the pseudo-random function PRF (Pseudo-Random Function). The MME may also reconstruct the full number of uplink NAS (NAS_U_SEQ) sequences from the received lesser bits and check the integrity of the NAS service request received from the UE. In addition, the MME may return an indication of the received NAS_U_SEQ to the UE, and the NAS_U_SEQ may be included in the installation message forwarding K_eNB to the eNodeB. Thus, the UE does not have to remember NAS_U_SEQ sent to the MME.
[0015] According to a third aspect, the invention provides a method in a user device (UE) of an Evolved Packet System (EPS) for establishing a security key K_eNB for protection of RRC / UP traffic exchanged with a serving eNodeB. The method comprises the steps of: sending a NAS service request to the MME (Mobility Management Entity) management entity, a request indicating the number of uplink NAS steps; and obtaining a K_eNB from at least said NAS_U_SEQ and stored in the key memory of the access security management entity K_ASME (Access Security Management Entity-key) provided to said MME.
[0016] According to a fourth aspect, the invention provides a user equipment (UE) adapted to an Evolved Packet System (EPS). The UE is configured to set a security key (K_eNB) to protect the RRC / UP traffic exchanged with the serving eNodeB. The UE includes means for sending a NAS Service Request to the MME, a request indicating a number of NAS uplink steps (NAS_U_SEQ), as well as means for obtaining K_eNB from at least said NAS_U_SEQ and from the K_ASME Access Management Entity stored in memory key ( Access Security Management Entity-key), made available to said MME.
[0017] The third and fourth aspects further provide methods as well as corresponding means according to which the UE can obtain K_eNB from NAS_U_SEQ and K_ASME using the Pseudo-Random Function Pseudo-Random Function and to protect integrity
- 5 NAS Service Request requests sent to the MME. In addition, the UE may store NAS_U_SEQ NAS Service Request sent to the MME, or, optionally, receive the NAS_U_SEQ Request for a NAS Service Request sent to the MME, back from the MME by the eNodeB. This alternative embodiment has the advantage that the UE does not have to remember the NAS_U_SEQ sent to the MME. The UE may further obtain K_eNB from AS_U_SEQ and K_ASME upon receipt of security configuration message from the eNodeB.
Brief description of the drawings [0018] The present invention will now be described in more detail with reference to the attached drawings, in which:
- figure 1 is a signaling diagram illustrating a conventional Service Request generated by the UE in EPS;
- figure 2 is a signaling diagram illustrating a first embodiment of the invention according to which the UE remembers NAS_U_SEQ sent to the MME in a NAS SERVICE REQUEST message;
- figure 3 is a flow chart illustrating the acquisition of K_eNB by means of the UE and MME;
- figure 4 is a signaling diagram illustrating a second embodiment of the invention in which the MME returns the received NAS_U_SEQ to the UE;
- figure 5 is a flow chart illustrating the second embodiment shown in figure 4 and
- figure 6a schematically shows the MME (Mobility Management Entity), and figure 6b is a schematic representation of the UE, both provided with means for obtaining the security key K_eNB.
Detailed Description [0019] In the following description, details have been specified, such as for a particular architecture and sequence of steps to provide a thorough understanding of the present invention. However, it is obvious to a person skilled in the art that the invention can be used in other embodiments that may deviate from these details.
[0020] Furthermore, it is evident that the described functions may be implemented by means of software operating in conjunction with a programmed microprocessor or a universal computer, and / or by means of a specialized integrated circuit. In places where the invention is described in the form of a method, the invention may also be incorporated into a computer program product, as well as a system comprising a computer processor and memory, wherein the memory is encrypted by means of one or more programs that can perform the described functions.
[0021] The concept or invention is that the security key (K_eNB) is derived from the key of the Access Security Management Entity-key (K_ASME) and the uplink sequence counter (NAS_U_SEQ)
- 6 messages REQUESTED BY THE NAS SERVICE (US SERVICE REQUEST), sent from the UE to the MME, thus causing the establishment of the UP / RRC security context in the eNodeB.
[0022] When the UE is in the passive IDLE mode, there is a NAS security context and includes, e.g., the aforementioned K_NAS_enc, K_NAS_int, NAS_U_SEQ and NAS_D_SEQ, and the NAS messages are protected in terms of integrity and probably confidentiality. The security context of the NAS therefore also includes EU security functions, in particular encryption and integrity algorithms.
[0023] The protection of NAS messages is based on NAS security keys, K_NAS_enc, K_NAS_int, and uplink and downlink sequence counters, NAS_U_SEQ and NAS_D_SEQ, for the direction of the message. The full sequence counter is usually not transmitted with the NAS message, only some of the lesser bits and the number of the full sequence will be reproduced on the receiving side from the local estimation of the more significant bits and the received lesser bits.
[0024] The idea of the invention may be explained in the context of a signaling scheme for service tasks invoked by the UE, as illustrated in the above-described figure 1:
[0025] In S1 and S2 of the conventional signaling scheme in figure 1, the NAS SERVICE REQUEST request, including the uplink sequence counter (NAS_U_SEQ), is forwarded from the UE to the MME and the REQUEST-message of the NAS SERVICE REQUEST-message. ) is protected in terms of integrity based on the mentioned NAS_U_SEQ. The MME checks the integrity of the message and approves it if it is not a repetition, and this ensures that NAS_U_SEQ is new and has not been used before.
Thus, according to the invention, the MME obtains K_eNB based at least on the received NAS_U_SEQ upcomer sequence counter and on the K_ASME, using a conventional key derivation function, and this is not included in the conventional signaling scheme depicted in figure 1. In connection with the sequence counter can only be reset during authentication. The MME will send the obtained K_eNB down to the eNodeB w, or duplicated to the S4 signal, the initial context configuration request S1-AP (Initial Context Setup Request S1-AP).
[0027] In the S5 signal, the eNodeB sends the UE a carrier determination in the Radio Bearer Establishment and security configuration messages (Security Mode).
Command - security mode command). These messages may be sent as two separate messages or combined into one message as in FIG. 1, and receipt of these messages by the UE will indirectly confirm the NAS SERVICE REQUEST of the user equipment in signal S1. The Security Mode Command will specify, for example, when protection should start and which algorithm to use.
[0028] According to the invention, the UE obtains K_eNB based on at least NAS_U_SEQ and K_ASME, using a conventional key derivation function, after receiving the message into an S5 signal, if not done before. Then, eNodeB and EU
- 7 determine the UP / RRC security contexts, and this is not represented in the conventional signaling scheme in figure 1.
[0029] According to a first embodiment of the invention, the UE stores the uplink sequence counter (NAS_U_SEQ) included in the initial NAS SERVICE REQUEST in the signal S1 and uses stored in the NAS_U_SEQ memory to obtain the K_eNB.
[0030] However, according to a second embodiment, the MME includes an uplink sequence count (NAS_U_SEQ) or only minor bits indicating NAS_U_SEQ, in an installation message S1-AP, in a signal S4 sent to the eNodeB, in which case the information is also transmitted to the UE with eNodeB when creating the RRC / UP context. In this case, the UE will be able to recover the NAS_U_SEQ indication from the eNodeB to obtain K_eNB, and it does not need to retain the NAS_S_SEQ of the NAS SERVICE REQUEST-message sent to the MME in the signals S1 and S2.
[0031] Figure 2 shows a first embodiment of the invention in which the UE maintains NAS_U_SEQ of the initial NAS SERVICE REQUEST message in signal S21 for obtaining K_eNB in signal S24. The MME will receive the NAS_U_SEQ from the UE in the S21 signal, or only the non-significant bits indicating the NAS_U_SEQ, and obtain the K_eNB based on NAS_U_SEQ and K_ASME in S22. The MME forwards the obtained K_eNB to the eNodeB in the S23 signal.
[0032] Next, the eNodeB and UE, not shown in figure 2, will determine the UP / RRC security context using K_eNB, the UP / RRC security contexts comprising the encryption key (K_eNB_UP_enc) for traffic protection UP, as well as the encryption key and the integrity protection key ( respectively, K_eNB_RR__enc and K_eNB_RRC_int) for RRC traffic protection, which enables safe traffic of UP / RRC traffic in the S25 signal.
[0033] Obtaining K_eNB is performed using a conventional key derivation function, e.g. by a pseudo random function (Pseudo-Random Function); K_eNB = PRF (K_ASME, NAS_U_SEQ, ...).
[0034] Furthermore, as represented by the dots in the above-described PRF function, the function of obtaining K_eNB may have additional, conventional input values, such as e.g. the eNodeB identity.
[0035] Figure 3 is a flow chart illustrating the method according to the invention, and in step 31, the UE 11 sends an initial NAS SERVICE REQUEST message to the MME 13, a message indicating a NAS uplink sequence count (NAS_U_SEQ), usually only by sending insignificant bits of the meter. In step 32, the MME receives the NAS SERVICE REQUEST-message from the UE, obtaining NAS_U_SEQ and reconstructing the full sequence of the non-significant bits received. In step 33, the MME obtains a security key (K_eNB) from at least the received NAS_U_SEQ and K_ASME from the ASME (Access Security Mobility Entity) using
- 8 the corresponding key acquisition function, e.g. the pseudo-Random Function.
[0036] Next, the MME forwards the received K_eNB to the eNodeB 12, in step 34, for use by the eNodeB, to determine the complete UP / RRC security context of the shared UE. In step 35, said UE will obtain the same K_eNB from at least the stored in K_ASME memory and from NAS_U_SEQ of the initial NAS SERVICE REQUEST message transmitted from UE to MME in step 31 and will determine the UP / RRC security context from the obtained K_eNB. .
In a first embodiment of this invention, the UE stores in the NAS_U_SEQ memory forwarded to the MME in the initial NAS SERVICE REQUEST-message and uses the stored number of sequences to obtain K_eNB.
[0038] Figure 4 is a signaling diagram illustrating a second embodiment of the present invention wherein the UE does not need to store in the NAS_U_SEQ memory. Instead, the MME will return the indication of the received NAS_U_SEQ back to the UE via the eNodeB. In signal S41, corresponding to signal S21 in figure 2, UE 11 forwards the initial NAS SERVICE REQUEST to MME 13, indicating the number of uplink sequence (NAS_U_SEQ), and the MME will receive NAS_U_SEQ and obtain K_eNB based on at least NAS_U_SEQ and K_ASME in S42. However, according to a second embodiment, the MME will include an indication of said received NAS_U_SEQ in the signal S43 passed to the eNodeB 12 together with the obtained K_eNB, and the eNodeB will forward the NAS_U_SEQ to the UE, in the signal S44. Next, The UE will obtain K_eNB from at least K_ASME and from NAS_U_SEQ returned by the MME in the S45 signal. From the obtained security key (K_eNB), the eNodeB and the UE will determine the UP / RRC security context, thus enabling secure UP / RRC traffic in the S46 signal.
[0039] Figure 5 is a flow chart illustrating the above described method according to a second embodiment of the invention in which the indication NAS_U_SEQ returns to the UE by means of MME. In step 41, the UE 11 sends the initial NAS SERVICE REQUEST-message to the MME 13, a message indicating a NAS uplink sequence count (NAS_U_SEQ), typically non-significant bits. In step 52, the MME receives from the UE a NAS SERVICE REQUEST-message, thus obtaining a NAS_U_SEQ, and, if necessary, rebuilding the full NAS_U_SEQ from the non-significant bits received. In step 53, the MME obtains the security key (K_eNB) from at least the received NAS_U_SEQ and K_ASME, using the corresponding key retrieval function.
[0040] Next, the MME includes a NAS uplink sequence counter number indication (NAS_U_SEQ) in the message forwarded to the obtained K_eNB to eNodeB 12, in step 54, and the eNodeB uses the received security key (K_eNB) to establish the UP / RRC security context. The received NAS_U_SEQ is forwarded to the UE 11 using
- eNodeB, in step 55, and in step 56, the UE obtains a security key (K_eNB), from at least K_ASME and from said received NAS_U_SEQ, to determine the UP / RRC security context of the shared eNodeB.
[0041] The acquisition of K_eNB by MME in step 53 and using UE in step 56 is effected by means of a suitable conventional key derivation function, e.g. a pseudo random function; K_eNB = PRF (K_ASME, NAS_U_SEQ, ...). Typically, the function will have additional, conventional input values, e.g. eNodeB identity.
[0042] Figure 6a illustrates a mobility management unit MME 13 (Mobility Management Entity) for EPS, according to the invention, further configured to establish a security key (K_eNB) for a security context to protect UP / RRC traffic between a UE and an eNodeB. Conventional telecommunication means, not shown in the figure, are provided for the MME for communication with nodes in the EPS, e.g. with eNodeBs via the S1-MME interface. Furthermore, in the MME of FIG. 1, the ASME (Access Security Management Entity) management entity 61 is represented in the form of dashed lines, because this functional unit can be co-located with the MME.
[0043] The MME measures 13, depicted in figure 6a, for establishing the security key (K_eNB) include reception means 62 for peering a NAS SERVICE REQUEST message, including a NAS_U-SEQ from the UE (via its servicer). eNodeB; means for deriving a key 63 for deriving a security key K_eNB, based on at least a received NAS_U-SEQ and stored in the memory K_ASME, using a conventional key derivation function; and means for sending 64 serving a obtained K_eNB to an eNodeB serving the UE.
[0044] Figure 6b shows a UE 11 (User Entity) according to the invention, UE adapted to EPS, and further configured to determine a security key (K_eNB) for a security context to protect UP / RRC traffic exchanged with its servicing eNodeB . The UE is equipped with conventional telecommunications means, not shown in the figure, for communication with nodes in the EPS via the LTE-Uu interface to its serving eNodeB.
[0045] The UE 11, depicted in figure 6b, for establishing the security key (K_eNB) comprise means of sending 66 for sending a NAS SERVICE REQUEST-message to the MME via an eNodeB-serving requester indicating the number of connection sequences ascending (NAS_U-SEK), and means for determining the security key (K_eNB), include means for obtaining a key 67 for deriving the security key (K_eNB) based on at least NAS_U-8EQ and stored in the K_ASME memory using the conventional key derivation function.
[0046] The above-described measures for MME and UE, as shown in Figures 6a and 6b, perform the described functions by means of an appropriate combination of software and hardware, e.g. a programmed microprocessor or a specialized circuit, as well as traditional radio transmitters and receivers.
[0047] Although the invention has been described with reference to specific embodiments, the description essentially has the sole purpose of presenting the idea of the invention and should not be taken as limiting the scope of the invention.
She prepared and verified
Grażyna Palka Patent attorney
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
55 members in 17 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 97295507 | United States of America | P | |
| 97295507 | United States of America | P | |
| 08767152 | European Patent Office (EPO) | A | |
| 2008050591 | Sweden | W | |
| 2008050591 | Sweden | W | |
| EP20080767152 | – | – | – |
| US20070972955P | – | – | – |
| WO2008SE50591 | – | – | – |
Members55
| Document | Office | Kind | |
|---|---|---|---|
| AU2008301284A1 | Australia | A1 | |
| CA2699846A1 | Canada | A1 | |
| WO2009038522A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AR068031A1 | Argentina | A1 | |
| EP2191608A1 | European Patent Office (EPO) | A1 | |
| CN101803271A | China | A | |
| JP2010539786A | Japan | A | |
| US2010316223A1 | United States of America | A1 | |
| CO6251350A2 | Colombia | A2 | |
| EP2191608A4 | European Patent Office (EPO) | A4 | |
| EP2191608B1 | European Patent Office (EPO) | B1 | |
| AT523980T | Austria | T | |
| ATE523980T1 | Austria | T1 | |
| RU2010115362A | Russian Federation | A | |
| ES2368875T3 | Spain | T3 | |
| PT2191608E | Portugal | E | |
| DK2191608T3 | Denmark | T3 | |
| EP2403180A1 | European Patent Office (EPO) | A1 | |
| PL2191608T3This record | Poland | T3 | |
| RU2466503C2 | Russian Federation | C2 | |
| CN101803271B | China | B | |
| JP2013013125A | Japan | A | |
| CN102916808A | China | A | |
| AU2008301284B2 | Australia | B2 | |
| EP2629451A1 | European Patent Office (EPO) | A1 | |
| US8660270B2 | United States of America | B2 | |
| JP5425281B2 | Japan | B2 | |
| US2014185809A1 | United States of America | A1 | |
| US8938076B2 | United States of America | B2 | |
| US2015146870A1 | United States of America | A1 | |
| DE202008018538U1 | Germany | U1 | |
| CN102916808B | China | B | |
| CA2699846C | Canada | C | |
| US9615249B2 | United States of America | B2 | |
| US2017170954A1 | United States of America | A1 | |
| US10057055B2 | United States of America | B2 | |
| US2018332470A1 | United States of America | A1 | |
| RU2466503C9 | Russian Federation | C9 | |
| EP2629451B1 | European Patent Office (EPO) | B1 | |
| PT2629451T | Portugal | T | |
| DK2629451T3 | Denmark | T3 | |
| US10455417B2 | United States of America | B2 | |
| PL2629451T3 | Poland | T3 | |
| US2020008053A1 | United States of America | A1 | |
| EP3598690A1 | European Patent Office (EPO) | A1 | |
| ES2750051T3 | Spain | T3 | |
| US11075749B2 | United States of America | B2 | |
| US2021328775A1 | United States of America | A1 | |
| EP3598690B1 | European Patent Office (EPO) | B1 | |
| PT3598690T | Portugal | T | |
| DK3598690T3 | Denmark | T3 | |
| ES2906127T3 | Spain | T3 | |
| PL3598690T3 | Poland | T3 | |
| HUE058067T2 | Hungary | T2 | |
| US11917055B2 | United States of America | B2 |
Numbers
- Publication, DOCDB
- 2191608
- Publication, EPODOC
- PL2191608T
- Application
- 767152
- Application, DOCDB
- 08767152
- Application, EPODOC
- PL20080767152T
Titles2
- English
- Method and arrangement in a telecommunication system
- Polish
- Sposób i urządzenie w systemie telekomunikacyjnym
Classification
- CPC, 11
- H04L9/083
- H04L63/062
- H04L2463/061
- H04W8/20
- H04W92/10
- H04L2209/80
- H04W12/041
- H04W12/0471
- H04L9/0816
- H04L2209/24
- H04L9/0869
- IPC, 4
- H04L9 08
- H04L9 32
- H04L29 06
- H04W12 04