Method and device for use in telecommunications system
Abstract
FIELD: information technologies. ^ SUBSTANCE: used in an object (13) of mobility control, MME, a deployed package system, EPS, establishment of a safety protection key, K-eNB, for protection of RRC/UP traffic between user equipment (11), UE, and a node (12) eNodeB, servicing a TJE, the method including stages, where: - a service request (32, 52) NAS is received from UE, a request indicating a sequence number of upperlink to NAS, NAS-U-SEQ; - a security protection key (33, 53) is received, K-eNB, at least from the specified received NAS-U-SEQ and from the stored key-object of access safety control, K-ASME, used jointly with the specified UE; - the specified received K-eNB (34) is sent to the unit (12) eNodeB, servicing the specified UE. ^ EFFECT: reduction of load at data transfer in a network. ^ 23 cl, 7 dwg
Term
1.7 yearsleft in the term
Expires 20 May 2028.
- Priority
- Filed
- Granted
- Today
- Expires
23 claims: 7 independent, 16 dependent
- 1A method used in an object (13) mobility management, the MME deployed batch system, EPS, of establishing a security key safety, K-eNB, to protect the graphics RRC / UP between the equipment (11) user, UE and a node (12) eNodeB serving the UE, the method comprising the steps of:- receiving (32, 52) the service request NAS from the UE, the request indicating the sequence number of the uplink to the NAS, NAS-U-SEQ;- receive (33, 53) the switch safety protection, K-eNB, at least, of said received NAS-U-SEQ from the stored key-management object security access, K-ASME, used together with said UE;- directing (34) said resultant K-eNB to node (12) eNodeB, serving said UE. 1. Способ, применяемый в объекте (13) управления подвижностью, ММЕ, развернутой пакетной системы, EPS, установления ключа защиты безопасности, K-eNB, для защиты графика RRC/UP между оборудованием (11) пользователя, UE и узлом (12) eNodeB, обслуживающим UE, способ, содержащий этапы, на которых:- принимают (32, 52) запрос обслуживания NAS от UE, запрос, указывающий порядковый номер восходящей линии связи к NAS, NAS-U-SEQ;- получают (33, 53) ключ защиты безопасности, K-eNB, по меньшей мере, из упомянутого принятого NAS-U-SEQ и из хранящегося ключа-объекта управления безопасностью доступа, K-ASME, используемого совместно с упомянутым UE;- направляют (34) упомянутый полученный K-eNB к узлу (12) eNodeB, обслуживающему упомянутый UE. 1. Способ, применяемый в объекте (13) управления подвижностью, ММЕ, развернутой пакетной системы, EPS, установления ключа защиты безопасности, K-eNB, для защиты графика RRC/UP между оборудованием (11) пользователя, UE и узлом (12) eNodeB, обслуживающим UE, способ, содержащий этапы, на которых:- принимают (32, 52) запрос обслуживания NAS от UE, запрос, указывающий порядковый номер восходящей линии связи к NAS, NAS-U-SEQ;- получают (33, 53) ключ защиты безопасности, K-eNB, по меньшей мере, из упомянутого принятого NAS-U-SEQ и из хранящегося ключа-объекта управления безопасностью доступа, K-ASME, используемого совместно с упомянутым UE;- направляют (34) упомянутый полученный K-eNB к узлу (12) eNodeB, обслуживающему упомянутый UE.
- 7A method used in equipment (11) user, UE system EPS, of establishing a security key for security, K-eNB, to protect the graphics RRC / UP, which communicates with the service node (12), eNodeB, comprising the steps of:- sending (31, 51) the service request NAS entity MME, the request indicating the sequence number of the uplink to the NAS, NAS-U-SEQ;- receive (35, 56) K-eNB, at least from said NAS-U-SEQ and from the stored key-control object access restriction, K-ASME, used in conjunction with said MME. 7. Способ, используемый в оборудовании (11) пользователя, UE системы EPS, для установления ключа защиты безопасности, K-eNB, для защиты графика RRC/UP, которым обмениваются с сервисным узлом (12) eNodeB, содержащий этапы на которых:- посылают (31, 51) запрос обслуживания NAS объекту ММЕ, запрос, указывающий порядковый номер восходящей линии связи к NAS, NAS-U-SEQ;- получают (35, 56) K-eNB, по меньшей мере, из упомянутого NAS-U-SEQ и из сохраненного ключа-объекта управления ограничением доступа, K-ASME, используемого совместно с упомянутым ММЕ. 7. Способ, используемый в оборудовании (11) пользователя, UE системы EPS, для установления ключа защиты безопасности, K-eNB, для защиты графика RRC/UP, которым обмениваются с сервисным узлом (12) eNodeB, содержащий этапы на которых:- посылают (31, 51) запрос обслуживания NAS объекту ММЕ, запрос, указывающий порядковый номер восходящей линии связи к NAS, NAS-U-SEQ;- получают (35, 56) K-eNB, по меньшей мере, из упомянутого NAS-U-SEQ и из сохраненного ключа-объекта управления ограничением доступа, K-ASME, используемого совместно с упомянутым ММЕ.
- 13The mobility management entity (13), MME, adapted to work in the EPS system, wherein the MME is arranged to establish a security key safety, K-eNB, to protect traffic RRC / UP between the UE (11) and a node (12) eNodeB, serving the UE, the MME characterized by:- means (62) receiving the service request NAS from the UE, the request indicating the sequence number of the uplink to the NAS, NAS-U-SEQ;- means (63) for K-eNB, by at least from said received NAS-U-SEQ and a stored key from the object control access restriction, K-ASME, used together with said UE;- means (64) sending said resultant K-eNB node eNodeB, serving said UE. 13. Объект управления подвижностью (13), ММЕ, выполненный с возможностью работы в системе EPS, в котором ММЕ выполнен с возможностью установления ключа защиты безопасности, K-eNB, для защиты трафика RRC/UP между UE (11) и узлом (12) eNodeB, обслуживающим UE, ММЕ, отличающийся:- средством (62) приема запроса обслуживания NAS от UE, запроса, указывающего порядковый номер восходящей линии связи к NAS, NAS-U-SEQ;- средство (63) для получения K-eNB, по меньшей мере, из упомянутого принятого NAS-U-SEQ и из хранящегося ключа-объекта управления ограничением доступа, K-ASME, используемого совместно с упомянутым UE;- средство (64) посылки упомянутого полученного K-eNB узлу eNodeB, обслуживающему упомянутый UE. 13. Объект управления подвижностью (13), ММЕ, выполненный с возможностью работы в системе EPS, в котором ММЕ выполнен с возможностью установления ключа защиты безопасности, K-eNB, для защиты трафика RRC/UP между UE (11) и узлом (12) eNodeB, обслуживающим UE, ММЕ, отличающийся:- средством (62) приема запроса обслуживания NAS от UE, запроса, указывающего порядковый номер восходящей линии связи к NAS, NAS-U-SEQ;- средство (63) для получения K-eNB, по меньшей мере, из упомянутого принятого NAS-U-SEQ и из хранящегося ключа-объекта управления ограничением доступа, K-ASME, используемого совместно с упомянутым UE;- средство (64) посылки упомянутого полученного K-eNB узлу eNodeB, обслуживающему упомянутый UE.
- 18Equipment (11) of the user, UE, operable in the system of EPS, wherein the UE is arranged to establish a security key safety, K-eNB, to protect the graphics RRC / UP, which communicates with the service node (12), eNodeB, UE , wherein:- means (66) sending a service request NAS to the MME (13), the request indicating the sequence number of the uplink to the NAS, NAS-U-SEQ;- means (67) providing K-eNB, at least from said NAS-U-SEQ and a stored code of the object access control constraint, K-ASME, used together with said MME (13). 18. Оборудование (11) пользователя, UE, выполненное с возможностью работы в системе EPS, причем UE выполнено с возможностью установления ключа защиты безопасности, K-eNB, для защиты графика RRC/UP, которым обмениваются с сервисным узлом (12) eNodeB, UE, отличающееся:- средством (66) посылки запроса обслуживания NAS к ММЕ (13), запроса, указывающего порядковый номер восходящей линии связи к NAS, NAS-U-SEQ;- средством (67) получения K-eNB, по меньшей мере, из упомянутого NAS-U-SEQ и из хранящегося кода-объекта управления ограничением доступа, K-ASME, используемого совместно с упомянутым ММЕ (13). 18. Оборудование (11) пользователя, UE, выполненное с возможностью работы в системе EPS, причем UE выполнено с возможностью установления ключа защиты безопасности, K-eNB, для защиты графика RRC/UP, которым обмениваются с сервисным узлом (12) eNodeB, UE, отличающееся:- средством (66) посылки запроса обслуживания NAS к ММЕ (13), запроса, указывающего порядковый номер восходящей линии связи к NAS, NAS-U-SEQ;- средством (67) получения K-eNB, по меньшей мере, из упомянутого NAS-U-SEQ и из хранящегося кода-объекта управления ограничением доступа, K-ASME, используемого совместно с упомянутым ММЕ (13).
- 21UE no claim 18, arranged to store NAS-U of SEQ NAS service request, sent to the MME (13). 21. UE no п.18, выполненное с возможностью хранения NAS U-SEQ из запроса обслуживания NAS, посланного к ММЕ (13). 21. UE no п.18, выполненное с возможностью хранения NAS U-SEQ из запроса обслуживания NAS, посланного к ММЕ (13).
- 22UE no claim 18, adapted to receive indication NAS-U-SEQ NAS service request, sent to the MME (13), back from the MME via the node (12) eNodeB. 22. UE no п.18, выполненное с возможностью приема индикации NAS-U-SEQ запроса обслуживания NAS, посланной к ММЕ, (13) обратно от ММЕ через узел (12) eNodeB. 22. UE no п.18, выполненное с возможностью приема индикации NAS-U-SEQ запроса обслуживания NAS, посланной к ММЕ, (13) обратно от ММЕ через узел (12) eNodeB.
- 23UE no claim 21 or 22, adapted to obtain the K-eNB after receiving a message from the security configuration from the node (12) eNodeB. 23. UE no п.21 или 22, выполненное с возможностью получения K-eNB после приема сообщения с конфигурацией безопасности от узла (12) eNodeB. 23. UE no п.21 или 22, выполненное с возможностью получения K-eNB после приема сообщения с конфигурацией безопасности от узла (12) eNodeB.
Independent claims7
54 paragraphs in 4 sections, as filed
TECHNICAL FIELD OF THE INVENTION
The present invention relates to methods and devices in the communication system, and in particular to a security solution in the EPS (unfolded packaging system, Evolved Packet System), that is, in E-UTRAN (unfolded terrestrial radio access network of universal mobile telecommunications system, Evolved UMTS Terrestrial Radio Access Network) and in the EPC (detailed basic packet network, Evolved Packet Core network) for the switching equipment user service requests. More particularly, the present invention relates to a method and apparatus used in the MME (mobility management entity) and a UE (user equipment) for the installation of safety protection key to protect traffic RRC / UP system EPS (Evolved Packet System).
BACKGROUND
The architecture EPS subscriber authentication is performed between the UE and the MME, and the MME manages, for example, mobility, UE identification and security parameters. The basis for determination of safety procedures to EPS is a security key, K_ASME, which is shared by the MME and the UE, and is set to authenticate UE. Functional object architecture EPS, called the ASME (control object security access, Access Security Management Entity), can be, for example, is aligned with the MME, and the object ASME receives and stores the key K_ASME safety protection obtained from keys CK / IK, limited home network. From a security key K_ASME ASME brings security context NAS, used to protect signaling NAS, ie lack of access layer signaling (Non Access Stratum) between MME EPC network and a UE. Context NAS security contains parameters for encoding and protect the integrity of signaling NAS, such as K_NAS_enc, K_NAS_int, and sequence numbers uplink and downlink, NAS_U_SEQ and NAS_D_SEQ, and the sequence numbers are used to prevent tampering protection by use of old messages in place of the original, and to enter the coding procedure and integrity protection. Object ASME provides the MME security context NAS, and the same context as the NAS security is stored in the object MME, and a corresponding security context NAS stored by the UE, and the protection against burglary by substituting the original integrity protection and encryption are based on that the sequence numbers of SAs NAS for MME and UE are not reused.
Preferably, the security context for the protection of traffic UP / RRC between the UE and the service node eNodeB (i.e. a radio base station in the EPS architecture) is also based on said security key K_ASME. The procedure to establish a security context UP / RRC comprises receiving a key called K_eNB, from which the encryption key K_eNB_UP_enc to protect the UP (User Plane), i.e. end-user data transmitted over EPC and E-UTRAN, as well as the encryption key K_eNB_RRC_enc protection key to protect the integrity of K_eNB_RRC_int RRC (Radio Resource Control, Radio Resource Control).
Figure 1 shows a typical example of the signal for the initiated user equipment (UE) transition from the state IDLE (inaction) of a state ACTIVE (acting) in the architecture of EPS. Dormant UE is only known EPC network of EPS, and no security context of the UP / RRC between the eNodeB and the UE does not exist. When the UE is in ACTIVE state, it is known as EPC network, or EUTRAN network, and the security context of the UP / RRC traffic protection established for UP / RRC between the UE and its serving Node eNobeB.
1 shows a UE 11, eNodeB 12, MME 13, the service GW (Gateway) 14, 15 PDN gateway and HSS (Home Subscriber Server) 16. The service gateway 14 is a node EPC, which terminates the interface towards EUTRAN network, and a gateway PDN is a network node EPC, which terminates the interface towards the PDN (packet data network). If a UE accesses multiple PDN networks, for that UE can exist multiple PDN gateways. The signal S1 and signal S2 is clearly NAS service request sent from the UE to the MME, and the NAS Service Request integrity protected based on NAS_U_SEQ. Optionally, the signal S3 is authenticated UE via MME, and K_ASME is established, using subscriber data stored in the HSS, and the MME sends the initial request to set the context in the eNodeB signal S4. The signals S5 and S6 of the eNodeB establishes the radio bearer with the UE and forwards uplink data communication, and returns a completion message to the initial installation MME context to an object in the signal S7. In signal S8 MME sends a bearer update request to the service GW, GW and the service responds in signal S9.
In previous solutions receipt K_eNB by the UE and MME for the security context of RRC / UP based, e.g., on a message NAS SERVICE ACCEPT (NAS service agreement) or other explicit information sent from the MME to the UE. However, as shown in the conventional example of the signals on the EPS 1, MME will normally not send any NAS SERVICE ACCEPT message after receiving the service request NAS SERVICE REQUEST from a UE in an EPS system. Therefore, it would be impossible to get K_eNB of the information contained in the message NAS SERVICE ACCEPT.
According to an exemplary known solution K_eNB prepared by MME from the K_ASME and the NAS_D_SEQ, used MME reported NAS SERVICE ACCEPT, and the UE derives the same K_eNB, restoring sequence number NAS_D_SEQ post NAS SERVICE ACCEPT and performing a reception K_eNB, as MME . K_eNB MME transmits to node eNodeB, when it establishes a connection with the node eNodeB S1. However, a disadvantage of this known solution is that if no explicit NAS SERVICE ACCEPT message is not supplied from the MME to the UE, as in the example of the signals in the conventional EPS system, shown in Figure 1, it is impossible for the UE to receive the same K_eNB, both at the MME. Even though it is technically possible for the UE to estimate a current sequence number of the downlink to the NAS, NAS_D_SEQ, this estimation could be erroneous, since the MME may send a NAS message, that were lost and never received the UE. In this case, MME should update its NAS_D_SEQ, without letting know the UE updating, leading to an erroneous NAS_D_SEQ the UE.
In accordance with another example of the known solutions receipt K_eNB is based on a separate sequence number, stored specifically for K_eNB, and this sequence number explicitly synchronized during the procedure service request NAS or by sending it from the UE to the MME, or by sending it from the MME to the UE . However, a disadvantage of this solution is the additional complexity of a separate sequence number, since it must be stored in the UE, and the MME, to prevent burglary protection by substituting the original.
SUMMARY OF THE INVENTION
The present invention aims at solving the problems outlined above, and this and other objects are achieved by the method and apparatus according to independent claims and embodiments according to the dependent claims.
The basic idea of the present invention is that the K_eNB is derived from K_ASME and from the NAS_U_SEQ posts NAS SERVICE REQUEST, transmitted from the UE to the MME, thereby triggering the establishment of the security context of UP / RRC node eNodeB.
An advantage of the present invention is that no explicit message NAS SERVICE ACCEPT downlink or sequence number from the MME to the UE is not required, and that the functionality of the protection retransmission intercepted communications context NAS security reused in security contexts RRC and UP.
In accordance with one aspect, the invention provides a method of establishing in the MME of the EPS system security key K_eNB for traffic protection RRC / UP between the user equipment UE and node eNodeB, serving the UE. The method comprises the steps of receiving a service request from the NAS UE, the request indicating the sequence number of the uplink to the NAS in the NAS_U_SEQ; obtaining the security key K_eNB, at least from said received NAS_U_SEQ and from a stored key object security access control K_ASME, used together with said UE; and sending said received K_eNB node eNodeB, serving said UE.
According to a second aspect of the invention provides the MME for the EPS system. MME is arranged to establish a security key K_eNB for traffic protection RRC / UP between the UE and the node eNodeB, serving the UE. MME comprises means for receiving an NAS Service Request from the UE, the request indicating the sequence number of the uplink to the NAS, NAS_U_SEQ; K_eNB obtaining means, at least from said received NAS_U_SEQ and from a stored key object security access control K_ASME, used together with said UE, as well as means for sending said derived K_eNB to the node eNodeB, serving said UE.
The first and second aspects further provide methods, as well as corresponding means, according to which the MME may receive the K_eNB from the NAS_U_SEQ and the K_ASME, using a pseudo-random function PRF. The MME may further reconstruct the full sequence number of the uplink NAS in NAS_U_SEQ from received low-order bits and integrity check result NAS service request, received from the UE. Additionally, MME may send back an indication of the adopted NAS_U_SEQ to the UE, and NAS_U_SEQ may be contained in the message setup guide K_eNB to node eNodeB. Thus, UE should remember NAS_U_SEQ, sent to the MME.
According to a third aspect, the invention provides a method in the user equipment UE EPS system for establishing the security key K_eNB, to protect traffic RRC / UP, which is exchanged with its serving eNodeB node. The method comprises sending a service request NAS entity MME, where the request indicates the sequence number of the uplink to the NAS, NAS_U_SEQ; and receiving K_eNB, at least from said NAS_U_SEQ and from a stored key object security access control K_ASME, used together with said MME.
According to a fourth aspect of the invention provides a user equipment UE, operable in the EPS. UE is arranged to establish a security key K_eNB for traffic protection RRC / UP, which communicates with the serving node eNodeB. UE comprises means for sending a service request NAS to the object MME, where the request indicates the sequence number of the uplink NAS, NAS_U_SEQ, as well as means of obtaining K_eNB, at least from said NAS_U_SEQ and from a stored key-management object security access K_ASME, used in conjunction with said MME.
The third and fourth aspects further provide methods, as well as corresponding means, according to which the UE can receive the K_eNB from the NAS_U_SEQ and the K_ASME, using a pseudo-random function PRF, and integrity protection of NAS sends a service request to the entity MME. Additionally, UE may store the NAS_U_SEQ of the NAS Service Request, sent to the MME, or, alternatively, take the indication NAS_U_SEQ sent to the MME NAS service request from the MME via the eNodeB node. This alternative embodiment has the advantage that the UE does not have to remember the NAS_U_SEQ, sent to the MME. The UE may obtain an additional K_eNB of NAS_U_SEQ and K_ASME after receiving the message from the security configuration on the node eNodeB.
BRIEF DESCRIPTION OF DRAWINGS
The present invention will be described in more detail with reference to the accompanying drawings, in which:
1 - signal flow chart showing the traditional, triggered by UE service request in the EPS;
Figure 2 - a signal flow chart showing a first embodiment of the present invention, according to which the UE remembers the NAS_U_SEQ message, sent to the MME in the NAS Service Request message;
Figure 3 - a block flowchart obtain K_eNB by the UE and the target MME;
4 - a signal flow chart showing a second embodiment of the present invention in which the MME returns the received NAS_U_SEQ to the UE;
5 - a block flowchart of the second embodiment shown in Figure 4; and
6a - schematic object MME, and 6b - schematic UE, both figures show means for obtaining the security key K_eNB.
Detailed description
In the following description specific details are set forth such as the particular architecture and sequences of steps to provide a thorough understanding of the present invention. However, those skilled in the art will appreciate that the present invention may be practiced in other embodiments that differ from these specific details.
Furthermore, it is obvious that the described functions may be implemented using software functioning in conjunction with a programmed microprocessor or general purpose computer, and / or using special-purpose integrated circuit. When the invention is described in the form of a method, the invention can also be implemented in a computer program product and a system comprising a computer processor and a memory, wherein the memory is encoded with one or more programs that may perform the described functions.
Concept or the invention is that the security key security K_eNB obtained from the key-management object security access K_ASME and from the sequence counter uplink, NAS_U_SEQ, messages NAS SERVICE REQUEST, sent from the UE to the MME, launching, thus establishing a security context UP / RRC node eNodeB.
When the UE is in IDLE mode (inactivity), the NAS security context exists and comprises, for example, the above-described messages K_NAS_enc, K_NAS_int, NAS_U_SEQ and NAS_D_SEQ message, and the NAS messages are integrity protected against and possibly confidentiality. Safety NAS security context, thereby also includes security features to UE, in particular the integrity and encryption algorithms.
Protecting NAS messages is based on the security keys NAS, K_NAS_enc, K_NAS_int, counters and sequences in the uplink and downlink, NAS_U_SEQ or NAS_D_SEQ, for sending messages. Full counter sequences are usually not sent by NAS, passed only a few low-order bits, and a complete serial number will be recovered at the receiving end of the local assessment of bits MSBs and LSBs received bits.
The inventive concept can be explained in the context of a signal flow chart for switching UE service requests, as shown in Figure 1 above.
In steps S1 and S2 signals the traditional scheme of the signals shown in Figure 1, NAS SERVICE REQUEST, comprising a counter sequences for uplink, NAS_U_SEQ, is sent from the UE to the MME, and the NAS SERVICE REQUEST message is integrity protected against based on said NAS_U_SEQ. The MME checks the integrity of the message and accept it, if it's not hacking protection by replacing the original, and it ensures that the message NAS_U_SEQ is new and has not been used before.
Thereafter, in accordance with the present invention, MME receives K_eNB, based at least on the received data sequence counter uplink NAS_U_SEQ and on the K_ASME, using a conventional function of receiving the key, and not shown in the traditional scheme of the signals shown in 1. Consequently, the counter can be reset condition only when the authentication. MME will send the derived K_eNB down at the eNodeB in the message or tiers in the message signal S4, the initial setup of context request (S1-AP).
In signal S5 the eNodeB sends a radio bearer setup message and a configuration message security protection to the UE. These messages can be sent as two separate messages or combine them into one message, as shown in Figure 1, and reception of these messages to the UE will implicitly transmitted confirms UE NAS SERVICE REQUEST in signal S1. The team will determine the security regime, for example, when the protection should start and which algorithm to use.
In accordance with the present invention, the UE derives the K_eNB, based at least on the NAS_U_SEQ and the K_ASME, using a conventional key derivation function, upon receiving the message in signal S5, if such access has not occurred earlier. Thereafter, the eNodeB and the UE will establish SAs UP / RRC, and this is not shown in the conventional signal flow chart in Figure 1.
In accordance with a first embodiment of the present invention, the UE stores data sequence counter NAS_U_SEQ uplink, contained in the initial NAS SERVICE REQUEST in signal S1, and uses the stored NAS_U_SEQ for K_eNB.
However, according to the second embodiment, MME contains data sequence counter uplink NAS_U_SEQ, or only low-order bits indicating the NAS_U_SEQ, in the setup message S1-AP, in signal S4, sent to the node eNodeB, in which case this information It is also sent to the UE from the eNodeB during the RRC context establishment / UP. In this case, the UE will be able to restore the display NAS_U_SEQ from the eNodeB for K_eNB and must not retain NAS_U_SEQ for NAS NAS service request messages, sent to the MME in the signals S1 and S2.
2 shows a first embodiment of this invention wherein the UE stores the NAS_U_SEQ of the initial NAS message in the service request signal S21 for receiving K_eNB in the signal S24. MME will NAS_U_SEQ from the UE in the signal S21, or only low-order bits indicating NAS_U_SEQ, and get K_eNB, based on NAS_U_SEQ and K_ASME in S22. MME sends the resulting K_eNB to node eNodeB in the signal S23.
Thereafter, in Figure 2 but not illustrated, eNodeB and the UE will establish the context of safety protection UP / RRC, using the K_eNB, and security contexts security UP / RRC contain encryption key for protecting K_eNB_UP_enc UP-traffic, as well as the encryption key and the protection key K_eNB_RRC_enc K_eNB_RRC_int integrity and, respectively, for the protection of RRC traffic, thus providing, safe traffic UP / RRC in the signal S25.
Getting K_eNB performed the traditional function of obtaining a key, for example, by using a pseudo-random function (PRF); K_eNB = PRF (K_ASME, NAS_U_SEQ, ...).
Further, as shown in the above-described points PRF-function K_eNB receiving function may have additional conventional input values, such as, for example, eNodeB-identity.
3 is a block diagram showing a sequence of operations according to the present invention, and in step 31, UE 11 sends the initial NAS Service Request message to the MME 13, indicating meter data sequences to the uplink NAS, NAS_U_SEQ, normally only by sending the bits LSB counter. In step MME 32 receives the service request from the NAS UE, receiving NAS_U_SEQ, and restores the full sequence from the received low-order bits. In step 33, the MME acquires the security key K_eNB from at least the received NAS_U_SEQ and the K_ASME from the ASME object, using a suitable key derivation function, e.g. pseudorandom function.
Thereafter, in step 34, it sends to the MME node eNodeB 12 derived K_eNB, to be used by the eNodeB to complete the installation of the security context UP / RRC together with the UE. In step 35, said UE will receive the same K_eNB, at least the stored K_ASME and from the NAS_U_SEQ of the initial NAS service request message, transmitted from the UE to the MME in step 31, and establish a security context UP / RRC obtained from K_eNB.
In the first embodiment of the present invention, the UE stores the NAS_U_SEQ, transmitted MME in the initial NAS message NAS service request, and uses the stored sequence number for K_eNB.
Figure 4 is a signal flow chart showing a second embodiment of the present invention in which the UE should store the NAS_U_SEQ. Instead, the MME will send the indication reception NAS_U_SEQ back to the UE through the eNodeB. In signal S41, corresponding to the signal S21 in Figure 2, UE 11 transmits an initial NAS service request to the MME 13, indicating the sequence number of the uplink NAS_U_SEQ, and MME will receive and accept NAS_U_SEQ K_eNB, based at least on the NAS_U_SEQ and the K_ASME at S42. However, according to this second embodiment, MME will include an indication of said received NAS_U_SEQ in signal S43, the transmitting node eNodeB 12 together with the derived K_eNB, and the eNodeB will send NAS_U_SEQ to the UE in the signal S44. Thereafter, the UE receives K_eNB, at least from the K_ASME and from the NAS_U_SEQ, returned from the MME, in signal S45. From this key security protection K_eNB, eNodeB and the UE will establish the security context of the UP / RRC, thus ensuring safe traffic UP / RRC in the signal S46.
5 is a block diagram showing the above described method according to the second embodiment of the present invention wherein the indication receiving NAS_U_SEQ back to the UE from the MME. At step 41, UE 11 sends the initial NAS service request message to the MME 13, the message indicates that the data sequence counter uplink NAS, NAS_U_SEQ, normally low-order bits. In step MME 52 receives the NAS SERVICE REQUEST message from the UE, thereby obtaining NAS_U_SEQ, and, if necessary, reconstructing the full NAS_U_SEQ from the received low-order bits. In step 53, the MME acquires the security key K_eNB, at least from the received NAS_U_SEQ and the K_ASME, using a suitable key derivation function.
After the MME includes an indication of the sequence counter in the uplink to the NAS, NAS_U_SEQ, in the message directing prepared K_eNB to node eNodeB 12, in step 54, and the eNodeB uses the received security key K_eNB for establishing security context UP / RRC. The received NAS_U_SEQ sent to the UE 11 by the eNodeB in step 55 and at step 56 the UE derives the security key K_eNB, at least from the K_ASME and from said received NAS_U_SEQ, to establish a security context UP / RRC, used in conjunction with the eNodeB.
Preparation K_eNB the MME in step 53, and the UE in step 56 is performed by a suitable conventional key derivation function, e.g., a pseudo-random function; K_eNB = PRF (K_ASME, NAS_U_SEQ,, ...). Typically, the function key will be getting additional conventional input values, for example eNodeB-identity.
6a shows the MME 13 for EPS system, the present invention is further adapted to establish a security key K_eNB for a security context for the protection of traffic UP / RRC between the UE and the service node eNodeB. MME provides conventional communication means not shown, for connection with EPS nodes, such as nodes eNodeB, through interface S1-MME. Further, in the object MME, shown in Figure 1, ASME object 61 shown as a dotted line, since this functional entity of the EPS system can be combined with target MME.
Means the MME 13 shown in Figure 6a for establishing the security key K_eNB comprises means 62 receiving the message NAS service request, including NAS_U-SEQ from a UE through its service node eNodeB; means 63 for receiving the key security key K_eNB, based at least on the received NAS_U-SEQ and stored K_ASME, using a conventional key derivation function; and sending means 64 for sending the resulting K_eNB per node eNodeB, serving the UE.
Figure 6b shows UE 11 (UE) according to the present invention, UE, adapted for use in the EPS, and further arranged to establish a security key K_eNB for a security context for the protection of traffic UP / RRC, which communicates with the serving node eNodeB. UE provides conventional communication means not shown, to communicate with nodes in the EPS via an LTE-Uu to its serving node eNodeB.
Means UE 11 shown in figure 6b for establishing the security key K_eNB comprises sending means 66 for sending messages NAS SERVICE REQUEST entity MME via the serving node eNodeB, the request indicating the sequence number of the uplink NAS_U-SEQ, and the means for establishing a security key security K_eNB comprises means 67 for receiving the key security key K_eNB, based at least on NAS_U-SEQ and stored K_ASME, using a conventional key derivation function.
Described above means the MME and the UE, as shown in Figures 6a and 6b, implement the described functions using a suitable combination of software and hardware equipment, such as a programmed microprocessor or ASICs, as well as conventional radio transmitters and receivers.
Although the invention has been described with reference to certain exemplary embodiments, a description in general only intended to illustrate the inventive concept and should not be construed as limiting the scope of the invention.
Contents4
Every citation, both waysCites: the store holds 4 of 5
| Document | Relation | Office | Cited during |
|---|---|---|---|
| RU2741509C1 | Cited by | Russian Federation | Search report |
| US11838754B2 | Cited by | United States of America | Applicant |
| US11039313B1 | Cited by | United States of America | Applicant |
| US10939334B2 | Cited by | United States of America | Applicant |
| RU2735089C1 | Cited by | Russian Federation | Search report |
| US11184812B2 | Cited by | United States of America | Applicant |
| RU97119182A | Cites | Russian Federation | – |
| US20040044744A1 | Cites | United States of America | – |
| US20070171857A1 | Cites | United States of America | – |
| US7152238B1 | Cites | United States of America | – |
55 members in 17 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 60972955 | United States of America | – | |
| 97295507 | United States of America | P | |
| 97295507 | United States of America | P | |
| 2008050591 | Sweden | W | |
| 2008050591 | Sweden | W | |
| 60972955 | – | – | – |
| US20070972955P | – | – | – |
| WO2008SE50591 | – | – | – |
Members55
| Document | Office | Kind | |
|---|---|---|---|
| AU2008301284A1 | Australia | A1 | |
| CA2699846A1 | Canada | A1 | |
| WO2009038522A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AR068031A1 | Argentina | A1 | |
| EP2191608A1 | European Patent Office (EPO) | A1 | |
| CN101803271A | China | A | |
| JP2010539786A | Japan | A | |
| US2010316223A1 | United States of America | A1 | |
| CO6251350A2 | Colombia | A2 | |
| EP2191608A4 | European Patent Office (EPO) | A4 | |
| EP2191608B1 | European Patent Office (EPO) | B1 | |
| AT523980T | Austria | T | |
| ATE523980T1 | Austria | T1 | |
| RU2010115362A | Russian Federation | A | |
| ES2368875T3 | Spain | T3 | |
| PT2191608E | Portugal | E | |
| DK2191608T3 | Denmark | T3 | |
| EP2403180A1 | European Patent Office (EPO) | A1 | |
| PL2191608T3 | Poland | T3 | |
| RU2466503C2This record | Russian Federation | C2 | |
| CN101803271B | China | B | |
| JP2013013125A | Japan | A | |
| CN102916808A | China | A | |
| AU2008301284B2 | Australia | B2 | |
| EP2629451A1 | European Patent Office (EPO) | A1 | |
| US8660270B2 | United States of America | B2 | |
| JP5425281B2 | Japan | B2 | |
| US2014185809A1 | United States of America | A1 | |
| US8938076B2 | United States of America | B2 | |
| US2015146870A1 | United States of America | A1 | |
| DE202008018538U1 | Germany | U1 | |
| CN102916808B | China | B | |
| CA2699846C | Canada | C | |
| US9615249B2 | United States of America | B2 | |
| US2017170954A1 | United States of America | A1 | |
| US10057055B2 | United States of America | B2 | |
| US2018332470A1 | United States of America | A1 | |
| RU2466503C9 | Russian Federation | C9 | |
| EP2629451B1 | European Patent Office (EPO) | B1 | |
| PT2629451T | Portugal | T | |
| DK2629451T3 | Denmark | T3 | |
| US10455417B2 | United States of America | B2 | |
| PL2629451T3 | Poland | T3 | |
| US2020008053A1 | United States of America | A1 | |
| EP3598690A1 | European Patent Office (EPO) | A1 | |
| ES2750051T3 | Spain | T3 | |
| US11075749B2 | United States of America | B2 | |
| US2021328775A1 | United States of America | A1 | |
| EP3598690B1 | European Patent Office (EPO) | B1 | |
| PT3598690T | Portugal | T | |
| DK3598690T3 | Denmark | T3 | |
| ES2906127T3 | Spain | T3 | |
| PL3598690T3 | Poland | T3 | |
| HUE058067T2 | Hungary | T2 | |
| US11917055B2 | United States of America | B2 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Reissue of patent specificationTH4A | TH4A | |
| Reissue of patent specificationTH4A | TH4A |
Numbers
- Publication
- 2466503
- Publication, DOCDB
- 2466503
- Publication, EPODOC
- RU2466503
- Application
- 201011536208
- Application, DOCDB
- 2010115362
- Application, EPODOC
- RU20100115362
Titles2
- Russian
- СПОСОБ И УСТРОЙСТВО ДЛЯ ИСПОЛЬЗОВАНИЯ В СИСТЕМЕ СВЯЗИ
- English
- METHOD AND DEVICE FOR USE IN TELECOMMUNICATIONS SYSTEM
Classification
- CPC, 11
- H04L9/083
- H04L63/062
- H04L2463/061
- H04W8/20
- H04W92/10
- H04L2209/80
- H04W12/041
- H04W12/0471
- H04L9/0816
- H04L2209/24
- H04L9/0869
- IPC, 1
- H04L9 08