Concealing temporary user equipment identifiers
Abstract
FIELD: information technology. ^ SUBSTANCE: methods for concealing temporary identifiers (ID) assigned to user equipment (UE) by a wireless communication system are described. At a network entity, a first ID assigned to UE and possibly a salt value are transformed, for example, based on a hash function, in order to obtain a second ID for the UE. An output message directed to the UE is generated based on an input message, the second ID, and the salt value (if present). The output message is sent via a common channel shared by the UE and other UE. At the UE, a message is received via the common channel, and a salt value (if sent) is obtained from the received message. The first ID and the salt value are transformed to obtain the second ID, which is used to determine whether the received message is intended for the UE. ^ EFFECT: protection from intrusion into a message while using very low computational power. ^ 36 cl, 11 dwg
Term
Projected expiry 9 February 2027.
- Priority
- Filed
- Granted
- Today
- Projected expiry
36 claims: 9 independent, 27 dependent
- 1An apparatus for transmitting a message concealed temporary identifier to the user equipment, comprising:a processor configured to transform a first identifier (ID), assigned to the user equipment (UE), to obtain a second ID for the UE, generating an output messages directed to the UE, on Based on input messages and a second ID, and sending the output message via a common channel shared by said UE and other UE, wherein the processor is configured to mask at least a portion of the input message by the second ID, to generate an output message;ipamyat coupled to the processor. 1. Устройство для передачи сообщения со скрытым временным идентификатором к пользовательской аппаратуре, содержащее:процессор, сконфигурированный для преобразования первого идентификатора (ID), назначенного пользовательской аппаратуре (UE), чтобы получить второй ID для UE, формирования выходного сообщения, направляемого в UE, на основании входного сообщения и второго ID, и посылки выходного сообщения через общий канал, совместно используемый упомянутым UE и другими UE, при этом процессор сконфигурирован для маскирования, по меньшей мере, части входного сообщения с помощью второго ID, чтобы сгенерировать выходное сообщение;ипамять, соединенную с процессором. 1. Устройство для передачи сообщения со скрытым временным идентификатором к пользовательской аппаратуре, содержащее:процессор, сконфигурированный для преобразования первого идентификатора (ID), назначенного пользовательской аппаратуре (UE), чтобы получить второй ID для UE, формирования выходного сообщения, направляемого в UE, на основании входного сообщения и второго ID, и посылки выходного сообщения через общий канал, совместно используемый упомянутым UE и другими UE, при этом процессор сконфигурирован для маскирования, по меньшей мере, части входного сообщения с помощью второго ID, чтобы сгенерировать выходное сообщение;ипамять, соединенную с процессором.
- 13A method for transmitting a message concealed temporary identifier to the user equipment, comprising the steps of:transform a first identifier (ID), assigned to the user equipment (UE), to obtain a second ID for the UE;generating output messages directed to the UE on Based on input messages and a second ID, wherein the mask at least a portion of the input message by the second ID, to generate an output message;iposylayut output message via a common channel shared by said UE and other UE. 13. Способ для передачи сообщения со скрытым временным идентификатором к пользовательской аппаратуре, содержащий этапы, на которых:преобразуют первый идентификатор (ID), назначенный пользовательской аппаратуре (UE), чтобы получить второй ID для UE;формируют выходное сообщение, направляемое в UE, на основании входного сообщения и второго ID, при этом маскируют, по меньшей мере, часть входного сообщения с помощью второго ID, чтобы сгенерировать выходное сообщение;ипосылают выходное сообщение через общий канал, совместно используемый упомянутым UE и другими UE. 13. Способ для передачи сообщения со скрытым временным идентификатором к пользовательской аппаратуре, содержащий этапы, на которых:преобразуют первый идентификатор (ID), назначенный пользовательской аппаратуре (UE), чтобы получить второй ID для UE;формируют выходное сообщение, направляемое в UE, на основании входного сообщения и второго ID, при этом маскируют, по меньшей мере, часть входного сообщения с помощью второго ID, чтобы сгенерировать выходное сообщение;ипосылают выходное сообщение через общий канал, совместно используемый упомянутым UE и другими UE.
- 15The method of claim. 13 wherein the step of generating an output message comprises generating an output message to include the second input message ID and unencrypted. 15. Способ по п. 13, в котором этап, на котором формируют выходное сообщение, содержит формирование выходного сообщения, чтобы включить в него входное сообщение и второй ID в незашифрованном виде. 15. Способ по п. 13, в котором этап, на котором формируют выходное сообщение, содержит формирование выходного сообщения, чтобы включить в него входное сообщение и второй ID в незашифрованном виде.
- 17An apparatus for transmitting a message concealed temporary identifier to the user equipment, comprising:means for transforming a first identifier (ID), assigned to the user equipment (UE), to obtain a second ID for the UE;means for generating output messages directed to the UE, on Based on input messages and a second ID, wherein said forming includes masking at least a portion of the input message by the second ID, to generate an output message;and means for sending outgoing message via a common channel shared by said UE and other UE. 17. Устройство для передачи сообщения со скрытым временным идентификатором к пользовательской аппаратуре, содержащее:средство для преобразования первого идентификатора (ID), назначенного пользовательской аппаратуре (UE), чтобы получить второй ID для UE;средство для формирования выходного сообщения, направляемого в UE, на основании входного сообщения и второго ID, причем упомянутое формирование включает в себя маскирование, по меньшей мере, части входного сообщения с помощью второго ID, чтобы сгенерировать выходное сообщение;исредство для посылки выходного сообщения через общий канал, совместно используемый упомянутым UE и другими UE. 17. Устройство для передачи сообщения со скрытым временным идентификатором к пользовательской аппаратуре, содержащее:средство для преобразования первого идентификатора (ID), назначенного пользовательской аппаратуре (UE), чтобы получить второй ID для UE;средство для формирования выходного сообщения, направляемого в UE, на основании входного сообщения и второго ID, причем упомянутое формирование включает в себя маскирование, по меньшей мере, части входного сообщения с помощью второго ID, чтобы сгенерировать выходное сообщение;исредство для посылки выходного сообщения через общий канал, совместно используемый упомянутым UE и другими UE.
- 21A computer readable medium comprising stored thereon instructions, comprising:a first instruction set for transforming a first identifier (ID), assigned to the user equipment (UE), to obtain a second ID for the UE, the second set of instructions for generating output messages directed to UE, on the basis of the input message and the second ID, including masking at least a portion of the input message by the second ID, to generate an output message, and a third instruction set for sending the output message via a common channel shared by said UE and other UE. 21. Машиночитаемый носитель, включающий в себя хранящиеся на нем команды, содержащий:первый набор команд для преобразования первого идентификатора (ID), назначенного пользовательской аппаратуре (UE), чтобы получить второй ID для UЕ;второй набор команд для формирования выходного сообщения, направляемого в UE, на основании входного сообщения и второго ID, включая маскирование, по меньшей мере, части входного сообщения с помощью второго ID, чтобы сформировать выходное сообщение, итретий набор команд для посылки выходного сообщения через общий канал, совместно используемый упомянутым UE и другими UE. 21. Машиночитаемый носитель, включающий в себя хранящиеся на нем команды, содержащий:первый набор команд для преобразования первого идентификатора (ID), назначенного пользовательской аппаратуре (UE), чтобы получить второй ID для UЕ;второй набор команд для формирования выходного сообщения, направляемого в UE, на основании входного сообщения и второго ID, включая маскирование, по меньшей мере, части входного сообщения с помощью второго ID, чтобы сформировать выходное сообщение, итретий набор команд для посылки выходного сообщения через общий канал, совместно используемый упомянутым UE и другими UE.
- 22An apparatus for receiving a message concealed temporary identity in a user equipment, comprising:a processor configured to receive a message via a common channel shared by a plurality of user equipment (UE), transforming a first identifier (ID), designated UE, to obtain a second ID for UE, and determining whether the received message is intended for the UE, based on the second ID, wherein in said message received via a common channel, at least part of the message masked by the second ID;ipamyat coupled to the processor. 22. Устройство для приема сообщения со скрытым временным идентификатором в пользовательской аппаратуре, содержащее:процессор, сконфигурированный для приема сообщения через общий канал, совместно используемый множеством пользовательской аппаратуры (UE), преобразования первого идентификатора (ID), назначенного UE, чтобы получить второй ID для UE, и определения, предназначено ли принятое сообщение для UE, на основании второго ID, при этом в упомянутом сообщении, принимаемом через общий канал, по меньшей мере часть сообщения маскирована с помощью второго ID;ипамять, соединенную с процессором. 22. Устройство для приема сообщения со скрытым временным идентификатором в пользовательской аппаратуре, содержащее:процессор, сконфигурированный для приема сообщения через общий канал, совместно используемый множеством пользовательской аппаратуры (UE), преобразования первого идентификатора (ID), назначенного UE, чтобы получить второй ID для UE, и определения, предназначено ли принятое сообщение для UE, на основании второго ID, при этом в упомянутом сообщении, принимаемом через общий канал, по меньшей мере часть сообщения маскирована с помощью второго ID;ипамять, соединенную с процессором.
- 28A method for receiving a message concealed temporary identity in a user equipment, comprising:receiving a message via a common channel shared by a plurality of user equipment (UE);transform a first identifier (ID), designated UE, to obtain a second ID for UE, wherein in said message received via a common channel, at least part of the message masked by the second ID;and determining, whether the received message is intended for the UE, based on the second ID. 28. Способ для приема сообщения со скрытым временным идентификатором в пользовательской аппаратуре, содержащий этапы, на которых:принимают сообщение через общий канал, совместно используемый множеством пользовательской аппаратуры (UE);преобразуют первый идентификатор (ID), назначенный UE, чтобы получить второй ID для UE, при этом в упомянутом сообщении, принимаемом через общий канал, по меньшей мере часть сообщения маскирована с помощью второго ID;иопределяют, предназначено ли принятое сообщение для UE, на основании второго ID. 28. Способ для приема сообщения со скрытым временным идентификатором в пользовательской аппаратуре, содержащий этапы, на которых:принимают сообщение через общий канал, совместно используемый множеством пользовательской аппаратуры (UE);преобразуют первый идентификатор (ID), назначенный UE, чтобы получить второй ID для UE, при этом в упомянутом сообщении, принимаемом через общий канал, по меньшей мере часть сообщения маскирована с помощью второго ID;иопределяют, предназначено ли принятое сообщение для UE, на основании второго ID.
- 32An apparatus for receiving messages concealed temporary identity in a user equipment, comprising:means for receiving a message via a common channel shared by a plurality of user equipment (UE);means for transforming a first identifier (ID), designated UE, to obtain a second ID for UE, wherein in said message received via a common channel, at least part of the message masked by the second ID;and means for determining whether the received message is intended for the UE, based on the second ID. 32. Устройство для приема сообщения со скрытым временным идентификатором в пользовательской аппаратуре, содержащее:средство для приема сообщения через общий канал, совместно используемый множеством пользовательской аппаратуры (UE);средство для преобразования первого идентификатора (ID), назначенного UE, чтобы получить второй ID для UE, при этом в упомянутом сообщении, принимаемом через общий канал, по меньшей мере часть сообщения маскирована с помощью второго ID;исредство для определения, предназначено ли принятое сообщение для UE, на основании второго ID. 32. Устройство для приема сообщения со скрытым временным идентификатором в пользовательской аппаратуре, содержащее:средство для приема сообщения через общий канал, совместно используемый множеством пользовательской аппаратуры (UE);средство для преобразования первого идентификатора (ID), назначенного UE, чтобы получить второй ID для UE, при этом в упомянутом сообщении, принимаемом через общий канал, по меньшей мере часть сообщения маскирована с помощью второго ID;исредство для определения, предназначено ли принятое сообщение для UE, на основании второго ID.
- 36A computer readable medium comprising stored thereon instructions, comprising:a first instruction set for receiving a message via a common channel shared by a plurality of user equipment (UE);a second instruction set for transforming a first identifier (ID), designated UE, to obtain a second ID for the UE, wherein in said message received via a common channel, at least part of the message masked by the second ID;and a third instruction set for determining whether the received message is intended for the UE, based on the second ID. 36. Машиночитаемый носитель, включающий в себя хранящиеся на нем команды, содержащий:первый набор команд для приема сообщения через общий канал, совместно используемый множеством пользовательской аппаратуры (UE);второй набор команд для преобразования первого идентификатора (ID), назначенного UE, чтобы получить второй ID для UE, при этом в упомянутом сообщении, принимаемом через общий канал, по меньшей мере часть сообщения маскирована с помощью второго ID;итретий набор команд для определения, предназначено ли принятое сообщение для UE, на основании второго ID. 36. Машиночитаемый носитель, включающий в себя хранящиеся на нем команды, содержащий:первый набор команд для приема сообщения через общий канал, совместно используемый множеством пользовательской аппаратуры (UE);второй набор команд для преобразования первого идентификатора (ID), назначенного UE, чтобы получить второй ID для UE, при этом в упомянутом сообщении, принимаемом через общий канал, по меньшей мере часть сообщения маскирована с помощью второго ID;итретий набор команд для определения, предназначено ли принятое сообщение для UE, на основании второго ID.
Independent claims9
78 paragraphs in 4 sections, as filed
This application claims priority to US Provisional Application under № 60/771974, filed February 10, 2006 under the heading "Obscuring temporary user equipment identities", and US Provisional Application under № 60/786463, filed March 27, 2006 under the heading "Downlink data scheduling with opaque UE identities in E-UTRAN ", the right to both of which the assignee of the present invention and incorporated herein by reference.
TECHNICAL FIELD OF THE INVENTION
The present disclosure relates generally to communication, and more specifically to techniques for hiding the identities in a wireless communication system.
BACKGROUND
Wireless communication networks are widely deployed to provide various communication services such as voice, video, packet data, messaging, broadcast, etc. The wireless communication network may include a plurality of user equipment (UE). UE may be assigned various identifiers or identities (ID), used to uniquely identify the UE for a variety of purposes. In certain cases, the UE ID may be sent over the air in the clear without any encryption. This may make it possible for the interceptor intruder or an invasion to be connected via the monitoring channel for messages and determining which messages are directed to the same UE over time. Invasion connectable may be able to link messages to specific UE, but may not be able to determine the correct identities UE. Invasion connectable may be used to keep track of the location UE, and can also be the basis for other more serious of attacks. For example, an attacker may be able to determine which UE ID to nominate a particular UE, by initiating a call to that UE and observing which UE ID is used at about the same time.
Thus, there is a need in the art for a way to deal with invasions connectable without imposing excessive computational overhead of the UE and the network elements.
Disclosure of invention
The present application describes techniques for masking temporary ID, assigned to the UE wireless communication network. These methods may be used for different types of messages addressed to a specific UE and sent in plaintext without encryption via common channels. These methods may be used to improve security, for example to reflect invasion connectable.
In one aspect, in a network element (e.g. node B), the first ID, the designated UE, may be transformed to obtain a second ID for the UE. The first ID may be a radio network temporary identity (RNTI), assigned to the UE in Universal Mobile Telecommunication System (UMTS) or some other type of ID to some other communication system. Origin ID, and possibly a salt value (which is not a static value) can be converted on the basis of a hash function to obtain the second ID. Output message directed to the UE, may be generated based on the input message on the second ID and the salt value (if present). The input message may be a paging message, a scheduling message carrying scheduling information, communication resource assignment, etc. The output message may be sent via a common channel shared by the UE and other UE.
In another aspect, the UE message may be received via a common channel, and the salt value (if sent) can be obtained from the received message. The first ID and the salt value (if sent) can be transformed to obtain the second ID, which may be used to determine whether the received message is intended for the UE.
Various aspects and features of the disclosure are described in further detail below.
BRIEF DESCRIPTION OF DRAWINGS
1 shows a UMTS network.
2 shows the transmission for high-speed access to packet downlink (HSDPA).
3A and 3B show two schemes for converting RNTI.
4A illustrates the processor which sends the converted RNTI unencrypted.
4B illustrates a processor that puts the transformed RNTI in message.
5 shows a process for sending signaling messages to the UE.
6 shows an apparatus for sending signaling messages to the UE.
7 shows a process for receiving signaling messages to the UE.
8 shows an apparatus for receiving signaling messages to the UE.
9 shows a block diagram of UE, Node B and RNC.
EMBODIMENTS
The techniques described herein may be used in various wireless communication networks such as networks of code division multiple access (CDMA), multiple-access network with time division (TDMA), multiple-access network with frequency division (FDMA), network orthogonal FDMA (OFDMA), a network with a single carrier FDMA (SC-FDMA), etc. The terms "network" and "system" are often used interchangeably. A CDMA network may implement a radio technology such as Universal Terrestrial Radio Access (UTRA), enhanced UTRA (E-UTRA), cdma2000, etc. UTRA and E-UTRA are part of UMTS. UTRA includes Wideband-CDMA (W-CDMA) and low chip rate (LCR). cdma2000 covers IS-2000, IS-95 and IS-856 standards. A TDMA network may implement a radio technology such as Global System for Mobile Communications (GSM). An OFDMA network may implement a radio technology such as Long Term Evolution (LTE), IEEE 802.20, Flash-OFDM® etc. UTRA, E-UTRA, UMTS, LTE and GSM are described in documents from an organization named "Partnership Project 3rd Generation" (3GPP). cdma2000 is described in documents from an organization named "Partnership Project 2 3rd Generation" (3GPP2). These various radio technologies and standards are known in the art. For clarity, certain aspects of the techniques are described below for UMTS, and much of the description below, 3GPP terminology is used.
1 depicts a UMTS network 100 that includes a Universal Terrestrial Radio Access Network (UTRAN) and a core network 140. UTRAN includes multiple Node Bs 110 and Radio Network Controller (RNC) 130. Node B is generally a fixed station that communicates with UE, and can also be referred to as an evolved Node B, base station, access point, etc. Each Node B 110 provides communication coverage for a particular geographic area and supports communication for the UE, within the service area. The term "cell" can refer to a Node B and / or its coverage area depending on the context in which the term is used. RNC 130 couples to Node Bs 110 and provides coordination and control for these Node Bs and RNC 130 initiates and terminates the messages for certain protocols and applications. Core network 140 may include various network elements that support various functions such as packet routing, user registration, mobility management, etc.
UE 120 may be distributed throughout the UMTS network, and each UE may be stationary or mobile. The UE may also be referred to as a mobile station, a terminal, an access terminal, a subscriber unit, a station, etc. The UE may be a cellular phone, a personal digital assistant (PDA), a wireless device, a handheld device, a wireless modem, a compact laptop computer, etc. A UE may communicate with one or more Node Bs on the downlink Node B-UE and / or UE-Node B at any given moment. The communication link, the Node B-UE (or forward link) refers to the communication link from the Node B to the UE, and the UE-link node B (or reverse link) refers to the communication link from the UE to the nodes B.
In UMTS, data and signaling for the UE is handled as logical channels at a Radio Link Control (RLC). Logical channels include a dedicated traffic channel (DTCH), shared forward link channel (DSCH), a dedicated control channel (DCCH), a common control channel (CCCH), etc. Logical channels are converted into transport channels at a Medium Access (MAC). Transport channels carry data for different services such as voice, video, packet data, etc. Physical channels are formed using different channelization codes, and they are orthogonal to one another in code domain.
UE in UMTS may be assigned to the set ID, used to identify a UE for different purposes. These ID UE may have different contexts and scale (eg, cell, an area paging, etc.) and / or the existence of different periods of time (such as temporary or permanent). For example, UE may be assigned different RNTI, which may be used as the temporary ID. Table lists some of RNTI, which can be assigned to UE, and gives a brief description of where each RNTI may be used. C-RNTI and a U-RNTI may be assigned to the UE by the serving RNC and can be limited to the particular compound RRC cell. C-RNTI can be used for messages sent on the DSCH and DTCH. U-RNTI can be used for paging messages sent on the paging channel (PCH), and messages sent on the DCCH. DSCH-RNTI, H-RNTI and E-RNTI may be limited to a particular cell and used for signaling messages sent on the DSCH, a high speed shared forward link channel (HS-DSCH) and the channel of the absolute access E-DCH (E-AGCH) respectively. These different RNTI may be jointly referred to as "X-RNTI" and can be used as a temporary ID to the local context in order to address the UE for the signaling messages that are sent via radio resource control protocol (RRC) and MAC. X-RNTI may be assigned with different network elements in UTRAN (or a UTRAN). Each X-RNTI may be used for signaling messages exchanged between a network element UE and a destination receiver.
SimvolNazvanieDlinaIspolzovanieC-RNTIRNTI yacheyki16 bitIspolzuetsya for messages sent on the DTCH and DSCH.U-RNTIUTRAN-RNTI32 bitaIspolzuetsya for paging messages sent on the PCH, and messages sent by DCCHDSCH-RNTIIdentifikator radio DSCH16 bitIspolzuetsya for signaling messages sent over the radio DSCHH-RNTIIdentifikator HS-DSCH16 bitIspolzuetsya for signaling messages sent on the HS-DSCHE-RNTIIdentifikator radio E-DCH16 bitIspolzuetsya for signaling messages sent on the E-AGCH
X-RNTI may be assigned to the UE in different time points via UTRAN. Appointments can take place via an unencrypted signaling due to lack of pre-existing Depending protection between UTRAN and the UE at the time of appointment. However, the appointment of X-RNTI UTRAN typically addresses the UE by temporary identification to the mobile subscriber (TMSI) or packet TMSI (P-TMSI), which is prescribed UE in an encrypted signal level (NAS) layer of the lack of access. Thus, an attacker can observe some X-RNTI has been appointed to the posts using the forward link, but in the absence of additional information about the TMSI or P-TMSI, would not be able to determine which UE receives the assignment.
If the X-RNTI assigned UE, X-RNTI can be sent unencrypted when the encryption without signaling downlink and / or uplink. For example, messages for a particular UE may be sent on the CCCH and the UE addressed recipients via their U-RNTI. These messages can be sent via radio carrier signal 0 (SRB0) and would be unencrypted as SRB0 may transfer messages to UE, which has no dependence protection UTRAN. For messages that are sent unencrypted over the common channel, an attacker may be able to determine that the message was directed at a specific X-RNTI or UE. Despite the fact that the attacker does not know the identity of may of the UE outside the context of a radio, the available information may make it possible to combine information about the messages sent to the same UE in the so-called "invasion to be connected." An attacker can monitor unencrypted scheduling information sent on the control channel and may be able to determine the data addressed to the same UE. Then, an attacker can potentially monitor individual UE mobility between cells during a data session. In any case, the sending of messages in unencrypted form on a common channel may be a result of a vulnerability that can lead to more serious security threat.
The present application describes methods designed to reduce security vulnerabilities due to send messages in plain text on a common channel. These methods may be used for various signaling messages sent at different levels. The techniques may also be used for the downlink and uplink. For explanation the following describes methods for transmitting scheduling information messages, and paging messages on a forward link.
3GPP Release 5 and later supports HSDPA, which is a set of channels and procedures that enable high-speed packet data transmission on the forward link. For HSDPA, a Node B sends data on HS-DSCH, which is a transport channel for the forward link, which is jointly used by all UE in both time and code. HS-DSCH may carry data for one or more UE for each transmission time interval (TTI). For HSDPA, a frame of 10 milliseconds (ms) is divided into five 2-ms subframes, each subframe includes three slots, and each time slot has a duration of 0.667 ms. For HSDPA TTI is equal to one subframe and is the smallest unit of time in which a UE may be scheduled and served. Sharing the HS-DSCH is dynamic and may change from TTI to TTI. The data for the HS-DSCH is sent on the high speed physical shared downlink channel (HS-PDSCH), and signaling for the HS-PDSCH is sent on the shared control channel for HS-DSCH (HS-SCCH).
For HSDPA, the Node B may use up to fifteen channelization codes of 16 chips with a partition coefficient equal to 16 for the HS-PDSCH. The Node B may also use any number of channelization codes from the 128 chips with the distribution ratio equal to 128 for the HS-SCCH. The number of channelization codes of 16 chips for the HS-PDSCH and the number of channelization codes of 128 chips for HS-SCCH are configurable. Channelization codes for the HS-PDSCH and HS-SCCH codes are orthogonal variable distribution ratio (OVSF), that can be generated in a structured manner. The distribution coefficient (SF) is the length of a channelization code. Symbol partitioned by a channelization code of length SF, to generate SF chips for the symbol.
In the following description, HSDPA is considered as having (a) up to fifteen HS-PDSCH, with each HS-PDSCH corresponding to a different code channelization of 16 chips, and (b) any number of HS-SCCH, each HS-SCCH corresponds different channelization code of 128 chips. UE may be assigned up to four HS-SCCH during call setup, and the UE may be assigned to monitor the HS-SCCH during a call. UE may be assigned up to fifteen HS-PDSCH in the TTI. HS-PDSCH may be dynamically assigned and transmitted to the UE via signaling sent on one of the HS-SCCH, the designated UE.
2 illustrates exemplary transmission on the HS-SCCH and HS-PDSCH for HSDPA. The Node B may serve one or more of the UE in each TTI. The Node B sends signaling for each scheduled UE on the HS-SCCH and sends the data to the UE on the HS-PDSCH by two time intervals later. Signaling messages, sent over the HS-SCCH, address the particular UE based on the H-RNTI, this designated UE. Each UE, that could receive the data by HS-PDSCH, it processes the assigned HS-SCCH at each TTI, to determine whether to send a signaling message for this UE. Each UE may compare the signaling messages received on HS-SCCH, with its H-RNTI, to determine whether the signaling message is intended for that UE. Each UE, which is scheduled in the TTI, can process HS-PDSCH, to recover data sent to that UE.
In the example shown in Figure 2, UE, of interest (UE # 1) monitors four HS-SCCH # 1 to # 4 assigned to that UE. UE # 1 is not scheduled in TTI n, and no signaling message is not sent to any UE on HS-SCCH. UE # 1 is scheduled in TTI n + 1, and the signaling message sent to the UE on HS-SCCH # 1. The signaling message can transmit various parameters for the transmission sent in this TTI. UE # 1 is not scheduled in TTI n + 2, is scheduled in TTI n + 3 and receives a signaling message on HS-SCCH # 2, and is not scheduled in TTI n + 4.
Other RNTI may be used for other signaling messages sent by the UE on a specific common channel. For example, the assignment message sent on the E-AGCH, in particular address the UE based on the E-RNTI, this designated UE. Paging messages addressed to a certain UE based on the U-RNTI, this designated UE.
Generally, X-RNTI can be sent in a signaling message transmitted over the forward link, and can be used in each UE, to compare with its own X-RNTI, to determine whether the signaling message is intended for that UE, i.e. to find out "the message for me?". All information in the X-RNTI may not be necessary for this process of comparison, since the possibility of the value space X-RNTI may be incomplete. X-RNTI may be equal in length to 16 bits (or 32 bits), and identities may provide for a significantly larger number UE, what may be able to address the Node B at any one time. For example, the Node B may assign only recognizer 1024 in the range from 0 to 1023. In this case, only the 10 least significant bits (LSB) X-RNTI may be used to uniquely identify a given UE. Then, the Node B may send a random value for the upper bits and the enable each UE to recognize the message sent to the UE, by viewing only the least significant bits, which contain the "real" part of the recognizer. Sending random values for the high order bits may result in a number of different values of X-RNTI, sent for any given UE, which can reduce intrusion connectable. However, this scheme "truncation" is substantially transparent. An attacker who knows this scheme can trivially penetrate it and examine the low order bits to determine which messages are addressed to the same UE.
In one aspect, the X-RNTI can be converted based on the function, and the transformed RNTI (instead of the original X-RNTI) may be sent in a signaling message. UE, which already knows the X-RNTI, may be able to determine whether the signaling message is intended for the UE, based on the converted RNTI. However, an attacker without knowledge of X-RNTI may be able to determine the original X-RNTI based on the converted RNTI, sent in the message. The conversion can be performed in various ways.
3A shows a circuit for converting X-RNTI. The device 310 receives the X-RNTI, converts the X-RNTI based on the conversion function h, and provides the converted RNTI, which is denoted as H (X-RNTI). The conversion function can be irreversible function, which makes it difficult to determine the original X-RNTI of the transformed RNTI. For example, the conversion function can be a cryptographic / secure hash function, which converts the message (for example, X-RNTI) to digest (eg, transformed RNTI), and has the cryptographic properties such that (i) the function between the message and its digest is irreversible and (ii) the likelihood of two messages to convert the same digest is very small. Yield hash function may be referred to as a digest, a signature, hashed value, etc.
Transformed RNTI can be sent in a signaling message and may include a comparison message using UE. Each UE may apply the same transformation function to its X-RNTI, to receive the converted RNTI. Then each UE may compare the transformed RNTI in the received message with the locally generated transformed RNTI, to determine whether the message is intended for that UE.
The transformed RNTI may prevent an attacker to perform a logical conclusion of the original X-RNTI. However, if the same transformed RNTI included in each signaling message sent in a UE, then an attacker may attempt to perform a correlation disorders. To prevent this, the transformed RNTI may be changed with each message.
3B shows a circuit for converting X-RNTI, to receive the different transformed RNTI. The device 320 receives the X-RNTI and the salt value σ, converts the X-RNTI and the salt value from the function Nσ conversion and provides a transformed RNTI, which is designated as Nσ (X-RNTI). The conversion function can be irreversible function, a cryptographic hash function, etc. The salt value is not a static value that can be selected in any manner. Different salt values may be used for different signaling messages so that one X-RNTI may lead to different transformed RNTI for different messages.
Transformed X-RNTI and the salt value σ can be sent in a signaling message, and may include comparison of messages via UE. The salt value σ may be sent in an unencrypted form, together with the transformed RNTI. Salt σ value and / or converted RNTI can also be inserted in the signaling message. In any case, each UE may compare their X-RNTI with transformed RNTI in the signaling message. Each UE may apply a transform function Nσ its X-RNTI and the salt value from the selected message and then may compare the locally generated with the converted RNTI received transformed RNTI in the signaling message.
4A shows a block diagram of the processor design messages 410, which sends the converted RNTI unencrypted in the signaling message. Processor 410 receives input messages and message X-RNTI for a recipient UE and generates an output message directed to the UE.
The processor 410 communications device 420 receives the X-RNTI and possibly a salt value σ, applies a transform function to the X-RNTI and possibly a salt value and provides the converted σ RNTI. A multiplexer (Mux) 422 multiplexes transformed RNTI, the salt value σ (if present) and the input message. The encoder 424 encodes the output of the multiplexer 422 and provides an output message. Processor 410 messages can be used for paging messages sent on the PCH. In this case, the UE ID, or X-RNTI 4A may correspond to U-RNTI.
4B is a block diagram of a design communications processor 450 which inserts the converted RNTI in the signaling message. Processor 450 receives input messages and message X-RNTI for a recipient UE and generates an output message directed to the UE. The input message may comprise various pieces of information.
The processor 450 communications device 460 receives X-RNTI and possibly a salt value σ, applies a transform function to the X-RNTI and possibly a salt value and provides the converted σ RNTI. Multiplexer 462 receives and multiplexes the signaling information and Xa and Xb salt value σ (if present) and provides the multiplexed information X1. The encoder 464 encodes the multiplexed information X1, and provides the coded information. Apparatus 466 masks the encoded information based on the converted RNTI information and provides the masked Sj. Multiplexer 472 receives and multiplexes signaling information with Xc and Xf by providing multiplexed information X2. The device 474 generates a cyclic redundancy check (CRC) on the basis of information X1 and X2, then masks the CRC using the transformed RNTI, to receive the CRC, for a specific UE, and adds a CRC, for a specific UE, information X2. The encoder 476 encodes the output device 474, and provides coded information R2. Multiplexer 478 receives and multiplexes the masked information S1 and R2 encoded information and provides the multiplexed information S1 and R2 as output messages.
Processor 450 messages can be used for signaling messages sent on the HS-SCCH. In this case, Xa may comprise setting information channelization code, Xb may include information about a modulation scheme, Xc may contain information about the size of the transport block, Xd may contain information about the processing HARQ, Xe may contain information on the redundancy version and the aggregate, Xf may comprise information about the new index data and X-RNTI can correspond to H-RNTI. The information S1 can be sent in a first time interval TTI, R2 and the information may be sent in the last two time intervals TTI. In this case, the salt value σ can be multiplexed with the data Xa and Xb, sent in the first time interval TTI, as shown in Figure 4B. This may provide early detection of signaling messages via a UE without waiting that was made all the Post.
4A is a diagram in which the transformed RNTI sent in an unencrypted form in a signaling message. Transformed RNTI may also be sent in an unencrypted form in other ways. 4B shows a scheme in which the transformed RNTI is inserted into the signaling message. Inserting transformed RNTI may also be made in other ways. For example, a signaling message sent by E-AGCH, may include a CRC, for a specific UE, which may be generated based on the transformed E-RNTI. In general, transformed RNTI may be sent in various ways (e.g., unencrypted or inserted) in the signaling message so that the UE can identify a message recipient, as aimed in the UE.
As shown in Figure 2, UE can receive a plurality (e.g., up to four) of signaling messages in each TTI and may examine each received message to determine whether the message is for the UE. The conversion function should be computationally simple such that the UE may apply a transform function for each received message, without adversely affecting the efficiency. Ideally, the comparison with transformed RNTI messages would only require a few additional commands, besides the commands that are typically performed to compare the X-RNTI.
For the circuit shown in Figure 3B, UE may store a lookup table converted RNTI, obtained by hashing its X-RNTI with all possible salt value. Thus, the transformed RNTI may be pre-computed once and stored for later use instead of being calculated every time when receiving the signaling message. For each received message, the UE can extract the salt value from the received message, to select transformed RNTI for this salt value from a lookup table and check the received message by the selected transformed RNTI.
UTRAN may assign new X-RNTI UE via encrypted signaling the beginning of the call and possibly during a call. The converted version of the new X-RNTI may be sent over the air in the clear, as only the UE has not hashed version. The attacker may not have sufficient information to perform a comparison of the signaling messages sent from the transformed RNTI. An attacker could monitor all the signaling messages in the cell for a period of time and establish a correlation of signaling messages by maintaining a database of all possible X-RNTI and comparing each of the received message with all the X-RNTI. With this type of a certain interception can be countered by periodic appointment of new X-RNTI UE.
In order to generate the converted X-RNTI, may be used various conversion functions. In general, the transformation function must have the following qualities:
easy and fast calculation (or accessibility to the lookup table in the UE);
transformed RNTI and the salt value should be small;
difficulty or impossibility of treatment; and
UTRAN easy to protect against conflicts.
For this application between the qualities listed above, it can be made a compromise. For different applications can be used with different transformation functions different characteristics. For example, alarm level 2 may give preference to high bit-efficient and fast decoding and as a result may be able to take a lower level of protection. Alarm level 3 may give preference to a stronger protection because of the large overhead.
The importance of a highly irreversible function may depend on the definition of acceptable on the side of the attacker. The conversion function may simply mask changing a few bits in the positions of X-RNTI and can use the salt value to select masked bits. This conversion function can be sensitive to the gross invasion, in which an attacker collects signaling messages, checks all the possible values for the remote bits and watching to see which of the resulting values are repeated. An attacker could assume that duplicate values are valid X-RNTI different UE, and can remember to check these values with future signaling messages. However, it can be much more time-consuming invasion than accidental interception, usually associated with the invasion to be connected.
Even if the conversion function is somewhat weak in terms of cryptography, UTRAN may assign new X-RNTI via encrypted signaling. In this case, an attacker can not automatically have a pool of well-known X-RNTI, which compare the received messages. In the light of the ability to appoint the new X-RNTI strength cryptographic transformation functions can be considered less important than a simple calculation and storage of bits over the air.
The transformation function can be determined based on various schemes. For example, the conversion function may include the design principles used in a cryptographic / secure hash function such as SHA-1 (algorithm protective hash), SHA-2 (which includes SHA-224, SHA-256, SHA-384 and SHA-512), 4-MD (message digest), MD-5 or other secure hash algorithm known in the art. In one design, a conversion function used and known a priori by both UTRAN, and UE. In another design, a plurality of conversion functions supported, and a transformation function may be selected from a plurality of, for example, at the beginning of the call and transmitted to the UE.
Length salt value σ can be chosen based on a compromise between overhead and reliability. Longer salt value may result in a transformed RNTI for the X-RNTI, which could improve the protection due to large overhead costs and possibly greater likelihood of conflicts. Treatment can be valid for a shorter salt value.
In one design, the transformed RNTI has the same or approximately the same length as the original X-RNTI. For this scheme, the salt value σ can be sent using the additional bits. In another design, the transformed RNTI and the salt value σ have the same or approximately the same length as the original X-RNTI, in order to maintain the same or approximately the same overhead. For this scheme, some of the bits may be "returned" by forming a transformed RNTI shorter than the original X-RNTI. For example, X-RNTI may be 16 bits is converted RNTI may be 10 bits and the salt value may be equal to 6 bits. X-RNTI, and the salt converted RNTI value may also have different lengths. The transformation function may be constructed so as to achieve the desired cryptographic performance using shorter transformed RNTI.
A conflict occurs when two X two-RNTI for UE is converted into the same transformed RNTI. For example, Hσ (x) = Hσ (y), where x and y - two X-RNTI. UE may have no way to resolve the conflict between their transformed RNTI. Transformed RNTI may be used to send scheduling information in one or more of the UE, e.g., as shown in Figure 2. UE-receiver can correctly detect how scheduling information intended for that UE and may decode the data sent to the UE. UE-receiver can not correctly detect scheduling information decoded data for UE-receiver and have a meaningless result after decryption (assuming that the data sent on the HS-DSCH, has been encrypted). In this case conflicts may adversely affect or may not affect the efficiency depending on the application's behavior.
In general, the influence due to conflict X-RNTI may depend on the type of signaling being sent with the help of these X-RNTI. UTRAN may try to prevent conflicts, in order to avoid possible adverse effects.
In one scheme to avoid conflicts UTRAN selects the X-RNTI and the salt value, which are known that they have no conflicts. UTRAN may maintain a set of X-RNTI, appointed or nominated by UE. For each possible salt value σ UTRAN may generate a plurality of transformed RNTI based on the set X-RNTI and that salt value. UTRAN may scan a transformed set of duplicates and may reject the salt value if duplicates are found. In general, a salt value that causes a conflict for a particular X-RNTI, may still be used for other X-RNTI. However, in order to simplify implementation, UTRAN may maintain a list of salt values that result in no duplicates allowed throughout the set X-RNTI. Salt values in this list may be selected for use. Conflicts can also be removed by other means.
5 shows a process 500 performed by a network element in a wireless communication network to send signaling messages to the UE. The network element may be a Node B, RNC, etc. depending on the sent signaling message.
Origin ID, designated UE, may be transformed to obtain a second ID for the UE (block 512). The first ID may be RNTI, designated UE in UMTS or some other type of ID to some other communication system. The first ID may be transformed on the basis of the irreversible function, the hash function or some other function to obtain the second ID. Output message directed to the UE, may be generated based on the input message and the second ID (block 514). The input message may be a paging message, a scheduling message carrying scheduling information, communication resource assignment, etc. The output message may be sent via a common channel shared by the UE and other UE (block 516).
In one design, the first ID and the salt value is hashed to obtain the second ID. The salt value may be sent in unencrypted form in the output message. The salt value may be changed each time the first ID is converted, and can be selected so as to avoid conflicts between the first ID, designated UE. The first ID may have a length which may be equal to the combined length of the second ID and the salt value.
In one design, an output message may include a message input and a second ID in an unencrypted form, for example, as shown in Figure 4A. In another design, a second ID can be inserted into the output message, e.g., as shown in Figure 4B. For example, all or part of the incoming message may be masked by the second ID, to generate an output message. Alternatively CRC, specific for the UE, may be generated on the basis of the input message and the second ID, and the output message may be generated based on the input message and CRC, specific to the UE.
Figure 6 shows an apparatus 600 for sending signaling messages to the UE. Apparatus 600 includes means for transforming a first ID, the designated UE, to obtain a second ID for the UE (module 612), means for generating output messages directed to the UE, on the basis of the input message and the second ID (module 614) and means for sending outgoing message via a common channel shared by the UE and other UE (module 616). Modules 612 and 616 may comprise processors, electronics devices, hardware devices, electronics components, logical circuits, memories, etc. or any combination thereof.
7 shows a process 700 performed by a UE, to receive signaling messages from the wireless communications network. The message may be received via a common channel shared by a plurality of UE (block 712). Origin ID, designated UE, may be transformed to obtain a second ID for the UE (block 714). The conversion can be accomplished via a lookup table, hardware, software, firmware, etc. In one design, the salt value can be obtained from the received message and the first ID and the salt value may be a hash to obtain the second ID. Whether the received message is intended for the UE, it may be determined based on the second ID (block 716). In one design of block 716, a third ID may be obtained from the received message, and it can be compared with the second ID, to determine whether the received message is intended for the UE. In another design of block 716, CRC can be generated based on the received message and the generated CRC may be compared with the CRC, for a specific UE, to determine whether the received message is intended for the UE. The received message may be a paging message, a scheduling message, communication resource assignment, etc. If the received message is a scheduling message, then scheduling information may be obtained from the received message and used to process the data transmission sent to the UE.
8 depicts an apparatus 800 for receiving signaling messages. Apparatus 800 includes means for receiving a message via a common channel shared by a plurality of UE (module 812), means for transforming a first ID, the designated UE, to obtain a second ID for the UE (module 814), and means to determine whether the received message is intended for the UE, based on the second ID (module 816). Modules 812 at 816 may comprise processors, electronics devices, hardware devices, electronics components, logical circuits, memories, etc. or any combination thereof.
9 shows a block diagram of a design of UE 120, Node B 110 and RNC 130 in Figure 1. The reverse link data and signaling sent by UE 120 is processed (e.g., formatted, encoded, and interleaved) by an encoder 922 and further processed (e.g., modulated, form channels and encoded) by a modulator (MOD) 924 to generate output chips. A transmitter (TMTR) 932 then leads to the proper state (e.g., converts to analog, filters, amplifies, and frequency upconverts) the output chips and generates an uplink signal, which is transmitted via an antenna 934. The downlink antenna 934 receives downlink signal transmitted by Node B 110. A receiver (RCVR) 936 drives the appropriate state (e.g., filters, amplifies, downconverts, and digitizes) the received signal from antenna 934 and provides samples. A demodulator (DEMOD) 926 processes (e.g., descrambles, demodulates, and forms channels) the samples and provides symbol estimates. A decoder 928 further processes (e.g., deinterleaves and decodes cancels) the symbol estimates and provides decoded data. Encoder 922, modulator 924, demodulator 926 and decoder 928 may be implemented by a modem processor 920. These units may perform processing in accordance with the radio technology (e.g., UMTS), implemented by a wireless communication network.
Controller / processor 940 controls the operation of UE 120. Controller / processor 940 may perform process 700, shown in Figure 7, and / or other processes for the techniques described herein. Memory 942 stores program codes and data for UE 120 and may also store temporary ID, assigned to UE 120 or UE ID.
9 also shows a design of Node B 110 and RNC 130. Node B 110 includes a controller / processor 950 that performs various functions for communication with the UE, memory 952 that stores program codes and data for Node B 110, and a transceiver 954 that supports radio communication with the UE. Controller / processor 950 may perform process 500, shown in Figure 5, and / or other processes for the techniques described herein. Memory 952 may store temporary ID, assigned to the UE by Node B 110, or NB UE ID. RNC 130 includes a controller / processor 960 that performs various functions to support communication for UE, and a memory 962 that stores program codes and data for RNC 130. Controller / processor 960 may perform process 500, shown in Figure 5, and / or other processes for the techniques described herein. Memory 962 can store time ID, the designated UE, served by the RNC 130, or ID UE RNC.
The techniques described herein may be used for signaling messages sent on the downlink and uplink. The techniques may also be used for messages sent over the control plane and user plane. The control plane is a mechanism designed for carrying signaling for an upper application, and is typically performed using protocols specific to the network interface and signaling messages. The user plane is a mechanism designed for carrying signaling for an upper application, and is typically performed using open protocols such as User Datagram Protocol (UDP), Transmission Control Protocol (TCP) and Internet Protocol (IP). Messages can be transferred as part of signaling in a control plane or as part of data (from a network perspective) in a user plane.
The methods described herein may be implemented by various means. For example, these techniques may be implemented in hardware, firmware, hardware, software, or a combination thereof. For a hardware implementation, the processing units used to perform the methods of this element (e.g., UE, Node B, RNC, etc.) may be implemented within one or more application specific integrated circuits (ASIC), digital signal processors ( DSP), digital signal processing devices (DSPD), programmable logic devices (PLD), field-programmable gate array (FPQA), processors, controllers, electronic devices, other electronic units designed to perform the functions described in this application in a computer or a combination of these devices.
To perform a firmware and / or software techniques may be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. Codes firmware and / or software may be stored in memory (e.g., memory 942, 952 or 962 shown in Figure 9) and executed by a processor (e.g., processor 940, 950 or 960). The memory may be implemented within the processor or external to the processor.
The previous description of the disclosure is provided to enable any person skilled in the art to make or use the disclosure. Various modifications to the disclosure will be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to other embodiments without departing from the spirit and scope of the disclosure. Thus, it is not intended that the present disclosure is limited to the examples described herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Contents4
44 members in 13 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 60771974 | United States of America | – | |
| 77197406 | United States of America | P | |
| 77197406 | United States of America | P | |
| 60786463 | United States of America | – | |
| 78646306 | United States of America | P | |
| 78646306 | United States of America | P | |
| 60771974 | – | – | – |
| 60786463 | – | – | – |
| US20060771974P | – | – | – |
| US20060786463P | – | – | – |
Members44
| Document | Office | Kind | |
|---|---|---|---|
| CA2636270A1 | Canada | A1 | |
| CA2636309A1 | Canada | A1 | |
| WO2007095471A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2007095473A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2007218901A1 | United States of America | A1 | |
| US2007226502A1 | United States of America | A1 | |
| TW200746774A | Taiwan Province of China | A | |
| TW200803394A | Taiwan Province of China | A | |
| WO2007095471A3 | World Intellectual Property Organization (WIPO) | A3 | |
| AR059568A1 | Argentina | A1 | |
| KR20080092469A | Republic of Korea | A | |
| EP1992188A2 | European Patent Office (EPO) | A2 | |
| EP1992189A1 | European Patent Office (EPO) | A1 | |
| KR20080102177A | Republic of Korea | A | |
| CN101379861A | China | A | |
| CN101379863A | China | A | |
| JP2009526334A | Japan | A | |
| JP2009526449A | Japan | A | |
| RU2008136410A | Russian Federation | A | |
| RU2008136412A | Russian Federation | A | |
| RU2404540C2 | Russian Federation | C2 | |
| TWI340582B | Taiwan Province of China | B | |
| BRPI0707581A2 | Brazil | A2 | |
| BRPI0707583A2 | Brazil | A2 | |
| KR101038158B1 | Republic of Korea | B1 | |
| KR101041241B1 | Republic of Korea | B1 | |
| RU2427103C2This record | Russian Federation | C2 | |
| TWI357270B | Taiwan Province of China | B | |
| EP1992189B1 | European Patent Office (EPO) | B1 | |
| ATE543318T1 | Austria | T1 | |
| EP2437460A1 | European Patent Office (EPO) | A1 | |
| JP4927877B2 | Japan | B2 | |
| US8195943B2 | United States of America | B2 | |
| JP4960389B2 | Japan | B2 | |
| EP1992188B1 | European Patent Office (EPO) | B1 | |
| ES2392854T3 | Spain | T3 | |
| CA2636270C | Canada | C | |
| CA2636309C | Canada | C | |
| EP2437460B1 | European Patent Office (EPO) | B1 | |
| CN104768145A | China | A | |
| CN101379861B | China | B | |
| US9154464B2 | United States of America | B2 | |
| BRPI0707583A8 | Brazil | A8 | |
| BRPI0707583B1 | Brazil | B1 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| The patent is invalid due to non-payment of feesMM4A | MM4A |
Numbers
- Publication
- 2427103
- Publication, DOCDB
- 2427103
- Publication, EPODOC
- RU2427103
- Application
- 200813641208
- Application, DOCDB
- 2008136412
- Application, EPODOC
- RU20080136412
Titles2
- Russian
- СКРЫТИЕ ВРЕМЕННЫХ ОПОЗНАВАТЕЛЕЙ ПОЛЬЗОВАТЕЛЬСКОЙ АППАРАТУРЫ
- English
- CONCEALING TEMPORARY USER EQUIPMENT IDENTIFIERS
Classification
- CPC, 17
- H04L63/0407
- H04L9/0891
- H04L9/0838
- H04L2209/80
- H04L63/1441
- H04L63/126
- H04L63/1466
- H04L63/0414
- H04L63/061
- H04W12/02
- H04W12/04
- H04W8/26
- H04W12/10
- H04W12/12
- H04W88/02
- H04L61/5038
- H04W12/75
- IPC, 5
- H04W4 00
- H04L9 32
- H04W8 26
- H04W12 02
- H04W12 10