Method and device for use in telecommunications system
Abstract
FIELD: information technologies.SUBSTANCE: used in an object (13) of mobility control, MME, a deployed package system, EPS, establishment of a safety protection key, K-eNB, for protection of RRC/UP traffic between user equipment (11), UE, and a node (12) eNodeB, servicing a TJE, the method including stages, where: - a service request (32, 52) NAS is received from UE, a request indicating a sequence number of upperlink to NAS, NAS-U-SEQ; - a security protection key (33, 53) is received, K-eNB, at least from the specified received NAS-U-SEQ and from the stored key-object of access safety control, K-ASME, used jointly with the specified UE; - the specified received K-eNB (34) is sent to the unit (12) eNodeB, servicing the specified UE.EFFECT: reduction of load at data transfer in a network.23 cl, 7 dwg

Term
1.7 yearsleft in the term
Expires 20 May 2028.
- Priority
- Filed
- Granted
- Today
- Expires
23 claims: 6 independent, 17 dependent
- 1The method used in the mobility management entity (MME) of the deployed packet system, EPS, security key establishment, K_eNB, to protect the RRC / UP traffic between the user equipment (11), the UE, and the (12) eNodeB, serving the UE, a method comprising:1. Способ, применяемый в объекте (13) управления подвижностью, ММЕ, развернутой пакетной системы, EPS, установления ключа защиты безопасности, K_eNB, для защиты трафика RRC/UP между оборудованием (11) пользователя, UE, и узлом (12) eNodeB, обслуживающим UE, способ, содержащий этапы, на которых: - accept (32, 52) a NAS service request from the UE, a request indicating the sequence number of the uplink to the NAS, NAS_U_SEQ;- принимают (32, 52) запрос обслуживания NAS от UE, запрос, указывающий порядковый номер восходящей линии связи к NAS, NAS_U_SEQ;- receive (33, 53) security key, K_eNB, at least from the said received NAS_U_SEQ and from the stored key object of the security access control, K_ASME, used in conjunction with the said UE;- получают (33, 53) ключ защиты безопасности, K_eNB, по меньшей мере, из упомянутого принятого NAS_U_SEQ и из хранящегося ключа-объекта управления безопасностью доступа, K_ASME, используемого совместно с упомянутым UE;- direct (34) said received K_eNB to an eNodeB node (12) serving said UE. - направляют (34) упомянутый полученный K_eNB к узлу (12) eNodeB, обслуживающему упомянутый UE.
- 7The method used in the user equipment (11) of the UE of the EPS system to establish the security protection key, K_eNB, to protect the RRC / UP traffic exchanged with the service node (12) of the eNodeB, a method comprising the steps of:7. Способ, используемый в оборудовании (11) пользователя, UE системы EPS, для установления ключа защиты безопасности, K_eNB, для защиты трафика RRC/UP, которым обмениваются с сервисным узлом (12) eNodeB, способ, содержащий этапы на которых: - send (31, 51) a NAS service request to the MME, a request indicating the uplink sequence number to the NAS, NAS_U_SEQ;- посылают (31, 51) запрос обслуживания NAS объекту ММЕ, запрос, указывающий порядковый номер восходящей линии связи к NAS, NAS_U_SEQ;- receive (35, 56) K_eNB, at least from the aforementioned NAS_U_SEQ and from the saved key object control access restriction, K_ASME, used in conjunction with the said MME. - получают (35, 56) K_eNB, по меньшей мере, из упомянутого NAS_U_SEQ и из сохраненного ключа-объекта управления ограничением доступа, K_ASME, используемого совместно с упомянутым ММЕ.
- 9The method corresponding to any one of claims 7, 8 used in the UE, containing an additional integrity check step protecting the NAS service request sent to the MME. 9. Способ, соответствующий любому из пп.7, 8, используемый в UE, содержащий дополнительный этап проверки целостности, защищающий запрос обслуживания NAS, посланный к ММЕ.
- 13The mobility management entity (13), the MME, configured to operate in the EPS system, in which the MME is configured to establish a security protection key, K_eNB, to protect the RRC / UP traffic between the UE (11) and the (12) eNodeB, serving UE, MME, differing:13. Объект управления подвижностью (13), ММЕ, выполненный с возможностью работы в системе EPS, в котором ММЕ выполнен с возможностью установления ключа защиты безопасности, K_eNB, для защиты трафика RRC/UP между UE (11) и узлом (12) eNodeB, обслуживающим UE, ММЕ, отличающийся: - means (62) receiving a NAS service request from the UE, a request indicating the sequence number of the uplink to the NAS, NAS_U_SEQ;- средством (62) приема запроса обслуживания NAS от UE, запроса, указывающего порядковый номер восходящей линии связи к NAS, NAS_U_SEQ;- средство (63) для получения K_eNB, по меньшей мере, из упомянутого принятого NAS_U_SEQ и из хранящегося ключа-объекта управления ограничением доступа, K_ASME, используемого совместно с упомянутым UE;means (63) for obtaining K_eNB, at least from said received NAS_U_SEQ and from the stored key of the access restriction control object, K_ASME, used in conjunction with said UE;- средство (64) посылки упомянутого полученного K_eNB узлу eNodeB, обслуживающему упомянутый UE. means (64) of sending said received K_eNB to the eNodeB serving the said UE.
- 15MME according to item 13 or 14, configured to restore the full sequence number of the uplink to the NAS, NAS_U_SEQ, from the received bits of the lower bits. 15. ММЕ по п.13 или 14, выполненный с возможностью восстановления полного порядкового номер восходящей линии связи к NAS, NAS_U_SEQ, из принятых битов младших разрядов.
- 18User equipment (11), a UE, configured to work in the EPS system, and the UE is configured to establish a security protection key, K_eNB, to protect the RRC / UP traffic exchanged with the service node (12) of the eNodeB, UE, characterized by :18. Оборудование (11) пользователя, UE, выполненное с возможностью работы в системе EPS, причем UE выполнено с возможностью установления ключа защиты безопасности, K_eNB, для защиты трафика RRC/UP, которым обмениваются с сервисным узлом (12) eNodeB, UE, отличающееся: - means (66) of sending the NAS service request to the MME (13), a request indicating the sequence number of the uplink to the NAS, NAS_U_SEQ;- средством (66) посылки запроса обслуживания NAS к ММЕ (13), запроса, указывающего порядковый номер восходящей линии связи к NAS, NAS_U_SEQ;- средством (67) получения K_eNB, по меньшей мере, из упомянутого NAS_U_SEQ и из хранящегося кода-объекта управления ограничением доступа, K_ASME, используемого совместно с упомянутым ММЕ (13). means (67) for obtaining K_eNB from at least said NAS_U_SEQ and from the stored access control object code, K_ASME, used in conjunction with said MME (13).
Independent claims6
58 paragraphs, as filed
<b>The technical field to which the invention relates.</b>
The present invention relates to methods and devices in a communication system and, in particular, to solving a security problem in an EPS system (deployed packet system, Evolved Packet System), that is, in an E-UTRAN system (deployed terrestrial radio access network of a universal mobile communication system, Evolved UMTS Terrestrial Radio Access Network) and in the EPC system (evolved main packet network, Evolved Packet Core network network) for user-switched service requests. More specifically, the present invention relates to a method and apparatus used in the MME (mobility management entity) and in the UE (user equipment) to set a security security key to protect EPS RRC / UP traffic (Evolved Packet System).
<b>The level of technology</b>
In the EPS architecture, subscriber authentication is performed between the UE and the MME, and the MME controls, for example, mobility, UE identities and security parameters. The basis for defining a security procedure in EPS is the security key, K_ASME, which is shared between the MME and the UE and is set during the authentication of the UE. An EPS architecture functional entity called ASME (Access Security Management Entity) may, for example, be combined with the MME, and the ASME accepts and stores the security protection key K_ASME obtained from CK / IK keys restricted to the home network. From the security key K_ASME, ASME derives the NAS security context used to protect the NAS signaling, that is, the signaling of the Non Access Stratum between the EPC's MME and the UE. The NAS security context contains parameters for encoding and protecting the integrity of NAS signaling, such as K_NAS_enc, K_NAS_int, ascending and descending sequence numbers, NAS_U_SEQ and NAS_D_SEQ, and sequence numbers are used to prevent hacking protection by using old messages instead of the original, as well as to enter the encoding and integrity protection procedures. The ASME object provides the NAS security object to the MME object, and one NAS security context is stored in the MME object, and the corresponding NAS security context is stored in the UE, and the burglary protection by replacing the original, integrity protection and encoding are based on the sequential numbers of the NAS security contexts for MME and UE are not reused. K_NAS_int, as well as the sequence numbers of the uplink and downlink, NAS_U_SEQ and NAS_D_SEQ, and sequence numbers are used to prevent security tampering by using old messages instead of the original, as well as to enter coding and integrity protection procedures. The ASME object provides the NAS security object to the MME object, and one NAS security context is stored in the MME object, and the corresponding NAS security context is stored in the UE, and the burglary protection by replacing the original, integrity protection and encoding are based on the sequential numbers of the NAS security contexts for MME and UE are not reused. K_NAS_int, as well as the sequence numbers of the uplink and downlink, NAS_U_SEQ and NAS_D_SEQ, and sequence numbers are used to prevent security tampering by using old messages instead of the original, as well as to enter coding and integrity protection procedures. The ASME object provides the NAS security object to the MME object, and one NAS security context is stored in the MME object, and the corresponding NAS security context is stored in the UE, and the burglary protection by replacing the original, integrity protection and encoding are based on the sequential numbers of the NAS security contexts for MME and UE are not reused. and sequence numbers are used to prevent hacking protection by using old messages instead of the original, as well as to enter coding and integrity protection procedures. The ASME object provides the NAS security object to the MME object, and one NAS security context is stored in the MME object, and the corresponding NAS security context is stored in the UE, and the burglary protection by replacing the original, integrity protection and encoding are based on the sequential numbers of the NAS security contexts for MME and UE are not reused. and sequence numbers are used to prevent hacking protection by using old messages instead of the original, as well as to enter coding and integrity protection procedures. The ASME object provides the NAS security object to the MME object, and one NAS security context is stored in the MME object, and the corresponding NAS security context is stored in the UE, and the burglary protection by replacing the original, integrity protection and encoding are based on the sequential numbers of the NAS security contexts for MME and UE are not reused.
Preferably, the security context to protect the UP / RRC traffic between the UE and the eNodeB service node (i.e., the base station in the EPS architecture) is also based on the security key K_ASME. The UP / RRC security context establishment procedure involves obtaining a key, called K_eNB, from which the K_eNB_UP_enc encryption key is obtained to protect the UP (user plane), that is, the end-user data transmitted through the EPC and E-UTRAN, as well as the K_eNB_RRC_enc encryption key and protection key integrity K_eNB_RRC_int to protect the RRC (radio resource control, Radio Resource Control).
Figure 1 shows a typical example of the passage of a signal for a user-initiated (UE) initiated transition from the IDLE state (idle state) to the ACTIVE state (active) in the EPS architecture. An inactive UE is known only to the EPS system's EPC network, and there is no UP / RRC security context between the eNodeB and the UE. When the UE is ACTIVE, it is known to both the EPC network and the EUTRAN network, and the UP / RRC security context is established to protect the UP / RRC traffic between the UE and the eNobeB that serves it.
Figure 1 shows the UE 11, eNodeB 12, MME 13, service GW (gateway) 14, gateway 15 PDN and HSS (home subscriber server) 16. Service gateway 14 is the EPC node that terminates the interface in the direction of the EUTRAN network, and the gateway The PDN is an EPC network node that terminates the interface in the direction of the PDN (Packet Data Network). If a UE gains access to multiple PDN networks, multiple PDN gateways may exist for this UE. In the S1 signal and the S2 signal, the NAS service request is explicitly sent from the UE to the MME, and the integrity of the NAS service request is protected based on the NAS_U_SEQ. In the optional S3 signal, the UE is authenticated by the MME, and K_ASME is established using the subscriber data stored in the HSS, and the MME object sends a context initial setup request to the eNodeB in the S4 signal. In signals S5 and S6, the eNodeB establishes a unidirectional radio channel from the UE and sends data on the uplink, and returns a message about the completion of the initial context setting to the MME object in the S7 signal. In the S8 signal, the MME sends a unidirectional channel update request to the service GW, and the service GW responds in signal S9.
In previous decisions, obtaining K_eNB using the UE and MME for the RRC / UP security context is based, for example, on a NAS SERVICE ACCEPT (NAS Service Acceptance) message or other explicit information sent from the MME to the UE. However, as shown by the example of traditional EPS signal passing in FIG. 1, the MME will not normally send any NAS SERVICE ACCEPT message after receiving a NAS SERVICE REQUEST service request from the UE in the EPS system. Therefore, it will not be possible to get K_eNB from the information contained in the NAS SERVICE ACCEPT message.
In accordance with the example of the known solution, K_eNB is obtained using MME from K_ASME and NAS_D_SEQ used by MME in a NAS SERVICE ACCEPT message, and the UE receives the same K_eNB by restoring the NAS_D_SEQ sequence number from the NAS SERVICE ACCEPT message and performing this receiving K_eNB as MME . The MME sends K_eNB to the eNodeB when it establishes an S1 connection to the eNodeB. However, the disadvantage of this known solution is that if no explicit NAS SERVICE ACCEPT message is sent from the MME to the UE, as in the example of the traditional signal flow in the EPS system shown in FIG. 1, then for the UE it is impossible to get the same K_eNB as u mme. Even though it is technically possible for the UE to estimate the current downlink sequence number to the NAS, NAS_D_SEQ, this estimate may be erroneous, since the MME may send NAS messages that were lost and never taken to the UE. In such a case, the MME should update its NAS_D_SEQ without letting the UE know about the update, which results in an erroneous NAS_D_SEQ on the UE.
In accordance with another example of a known solution, obtaining K_eNB is based on a separate sequence number stored specifically for receiving K_eNB, and this sequence number is explicitly synchronized during the NAS service request procedure either by sending it from the UE to the MME or by sending it from the MME to the UE . However, the disadvantage of this solution is the added complexity of having a separate sequence number, since it must be stored both in the UE and in the MME in order to prevent the protection from being cracked by replacing the original.
<b>Summary of Invention</b>
The object of the present invention is to solve the problem indicated above, and this and other tasks are solved by the method and apparatus according to the independent claims and the embodiments according to the dependent claims.
The basic idea of the present invention is that K_eNB is obtained from K_ASME and from the NAS_U_SEQ NAS SERVICE REQUEST message sent from the UE to the MME, thereby triggering the establishment of the UP / RRC security context in the eNodeB.
An advantage of the present invention is that no explicit NAS SERVICE ACCEPT message on the downlink or sequence number from the MME to the UE is required, and that the protection functionality against the retransmission of intercepted messages of the NAS security context is reused in the RRC and UP security contexts.
In accordance with one aspect, the invention provides a method for establishing a security key K_eNB in an MME object of an EPS system for protecting RRC / UP traffic between a user equipment UE and an eNodeB serving the UE. The method comprises the steps of receiving a NAS service request from a UE, a request indicating an uplink sequence number to the NAS in the NAS_U_SEQ; obtain the security key K_eNB from at least said received NAS_U_SEQ and from the stored key security access control object K_ASME used in conjunction with said UE; and sending said received K_eNB to an eNodeB serving the said UE.
In accordance with the second aspect, the invention provides an MME object for an EPS system. The MME is configured to establish a security key K_eNB to protect the RRC / UP traffic between the UE and the eNodeB serving the UE. The MME comprises means for receiving a NAS service request from a UE, a request indicating an uplink sequence number to the NAS, NAS_U_SEQ; means for obtaining K_eNB, at least from said received NAS_U_SEQ and from the stored object security management object K_ASME used in conjunction with said UE, as well as means for sending said received K_eNB to the eNodeB serving the said UE.
The first and second aspects additionally provide methods, as well as corresponding means, according to which the MME can obtain K_eNB from NAS_U_SEQ and K_ASME using the pseudo-random PRF function. The MME may additionally recover the full uplink sequence number of the NAS in NAS_U_SEQ from the low-order bits received and the result of checking the integrity of the NAS service request received from the UE. Additionally, the MME may send back an indication of a received NAS_U_SEQ to the UE, and the NAS_U_SEQ may be contained in the setup message directing K_eNB to the eNodeB. Thus, the UE does not need to remember the NAS_U_SEQ sent to the MME.
In accordance with the third aspect, the invention provides a method in the UE user equipment of the EPS system for establishing the security key K_eNB to protect the RRC / UP traffic exchanged with the eNodeB serving it. The method comprises the steps of sending a NAS service request to the MME object, the request indicating the uplink sequence number to the NAS, NAS_U_SEQ; and obtaining the K_eNB from at least said NAS_U_SEQ and from the stored object security management object key K_ASME used in conjunction with said MME.
In accordance with the fourth aspect, the invention provides a user equipment UE, configured to work in the EPS system. The UE is configured to establish a security key K_eNB to protect the RRC / UP traffic exchanged with the serving eNodeB. The UE comprises means for sending a NAS service request to the MME object, the request indicating the uplink sequence number of the NAS, NAS_U_SEQ, as well as the means for obtaining the K_eNB from at least said NAS_U_SEQ and from the stored K_ASME security management object key shared with mentioned mme.
The third and fourth aspects further provide methods, as well as corresponding means, according to which the UE can obtain K_eNB from NAS_U_SEQ and K_ASME using the pseudo-random PRF function, and integrity protection sends a NAS service request to the MME object. Additionally, the UE may store the NAS_U_SEQ from the NAS service request sent to the MME, or, alternatively, receive the NAS_U_SEQ indication sent to the MME NAS service request from the MME via the eNodeB. This alternative embodiment has the advantage that the UE does not need to remember the NAS_U_SEQ sent to the MME. The UE may additionally receive K_eNB from NAS_U_SEQ and K_ASME after receiving the security configuration message from the eNodeB.
<b>Brief Description of the Drawings</b>
The present invention will be further described in more detail and with reference to the accompanying drawings, in which:
FIG. 1 is a signal flow diagram showing a traditional, UE-launched service request in the EPS system; FIG.
2 is a signal flow diagram showing the first embodiment of the present invention, in accordance with which the UE remembers the NAS_U_SEQ message sent to the MME in the NAS service request message;
FIG. 3 is a flow chart of operations for obtaining a K_eNB by the UE and the MME; FIG.
4 is a signal flow diagram showing a second embodiment of the present invention, in which the MME returns the received NAS_U_SEQ to the UE;
5 is a block diagram of the sequence of operations of the second variant of the implementation shown in figure 4; and
figa is a schematic representation of the object MME, and fig.6b is a schematic representation of the UE, with both drawings showing means for obtaining the security key K_eNB.
<b>Detailed description</b>
In the following description, specific details are set forth, such as a specific architecture and sequence of steps to provide a thorough understanding of the present invention. However, it will be apparent to those skilled in the art that the present invention may be practiced in other embodiments that may differ from these specific details.
In addition, it is obvious that the described functions can be implemented using software that operates in conjunction with a programmed microprocessor or a universal computer, and / or using a special-purpose integrated circuit. When the invention is described in the form of a method, the invention may also be implemented in a computer software product, as well as in a system comprising a computer processor and memory in which the memory device is encoded using one or more programs that can perform the functions described.
The concept or invention is that the security key K_eNB is obtained from the K_ASME access control security object key and from the uplink sequence counter, NAS_U_SEQ, NAS SERVICE REQUEST message sent from the UE to the MME, thus starting the UP security context / RRC in the eNodeB node.
When the UE is in IDLE mode (idle), the NAS security context exists and contains, for example, the K_NAS_enc, K_NAS_int, NAS_U_SEQ messages described above, and the NAS_D_SEQ message, and the NAS messages are protected for integrity and, possibly, privacy. The security protection context of the NAS, therefore, also contains security features for the UE, in particular, integrity and coding algorithms.
NAS message protection is based on NAS security keys, K_NAS_enc, K_NAS_int, and upstream and downlink sequence counters, NAS_U_SEQ or NAS_D_SEQ, for sending a message. The complete sequence counter is usually not transmitted in the NAS message, only some of the low-order bits are transmitted, and the full sequence number will be restored at the receiving end from the local estimate of the high-order bits and the received low-order bits.
The concept of the invention can be explained in the context of the signal flow pattern for the service requests to be switched by the UE, as shown in FIG. 1 above:
In the steps of the signals S1 and S2 of the conventional signal flow pattern shown in FIG. 1, the NAS SERVICE REQUEST containing the uplink sequence counter, NAS_U_SEQ, is sent from the UE to the MME, and the NAS SERVICE REQUEST message is integrity protected based on NAS_U_SEQ. The MME object verifies the integrity of the message and accepts it if it is not hacking protection by replacing the original, and this ensures that the NAS_U_SEQ message is new and not used before.
Thereafter, in accordance with the present invention, the MME obtains K_eNB based at least on the received data of the uplink sequence counter NAS_U_SEQ and on K_ASME using the conventional key acquisition function, and this is not shown in the traditional signal flow diagram shown in figure 1. Consequently, the sequence counter can be reset only with authentication. The MME will send the received K_eNB down to the eNodeB node in a message or in tiers in an S4 signal message, a request for an initial context setting (S1-AP).
In the S5 signal, the eNodeB sends a radio bearer establishment message and a security protection configuration message to the UE. These messages can be sent as two separate messages or merged into one message, as shown in FIG. 1, and the receipt of these messages by the UE will be an implicit acknowledgment of the transmitted NAS UE SERVICE REQUEST in the S1 signal. The security mode command will determine, for example, when protection should start and which algorithm to use.
In accordance with the present invention, the UE obtains K_eNB based at least on NAS_U_SEQ and K_ASME using the traditional key acquisition function after receiving the message in the S5 signal, if such acquisition did not occur earlier. Thereafter, the eNodeB and the UE will establish UP / RRC security contexts, and this is not shown in the conventional signal flow diagram in FIG.
In accordance with the first embodiment of the present invention, the UE stores the uplink sequence counter data NAS_U_SEQ contained in the initial NAS SERVICE REQUEST in the signal S1, and uses the stored NAS_U_SEQ to obtain K_eNB.
However, in accordance with the second embodiment, the MME contains upstream sequence counter data NAS_U_SEQ, or only the low order bits indicating NAS_U_SEQ, in the S1-AP setting message, in the S4 signal sent to the eNodeB, and in this case this information also sent to the UE from the eNodeB node during the establishment of the RRC / UP context. In this case, the UE will be able to recover the NAS_U_SEQ indication from the eNodeB to receive K_eNB and should not save the NAS_U_SEQ to the NAS of the NAS service request message sent to the MME in S1 and S2 signals.
FIG. 2 shows a first embodiment of this invention in which the UE stores the NAS_U_SEQ of the initial NAS service request message in the signal S21 for obtaining K_eNB in the signal S24. The MME will receive the NAS_U_SEQ from the UE in the S21 signal or only the low-order bits indicating NAS_U_SEQ and will receive K_eNB based on the NAS_U_SEQ and K_ASME in S22. The MME routes the received K_eNB to the eNodeB in signal S23.
Thereafter, but not shown in FIG. 2, the eNodeB and the UE will establish a UP / RRC security protection context using K_eNB, and the UP / RRC security protection contexts contain the K_eNB_UP_enc encryption key to protect the UP traffic, as well as the encryption key and protection key integrity K_eNB_RRC_enc and K_eNB_RRC_int, respectively, to protect the RRC traffic, thus providing secure UP / RRC traffic in signal S25.
Obtaining K_eNB is performed by the traditional key acquisition function, for example, using a pseudo-random function (PRF); K_eNB = PRF (K_ASME, NAS_U_SEQ, ...).
Additionally, as shown by the dots in the PRF function described above, the function for obtaining K_eNB may have additional ordinary input values, such as, for example, eNodeB identity.
3 is a flow chart illustrating the flow of operations according to the present invention, and at step 31, UE 11 sends an initial NAS service request message to the MME 13 object, indicating upstream sequence counter data to the NAS, NAS_U_SEQ, usually only by sending bits low-order counter. In step 32, the MME receives the NAS service request message from the UE receiving the NAS_U_SEQ, and recovers the complete sequence of the low order bits received. In step 33, the MME obtains the security key K_eNB from at least the received NAS_U_SEQ and K_ASME from the ASME object using a suitable key acquisition function, for example, a pseudo-random function.
After that, at step 34, the MME sends to the eNodeB 12 the received K_eNB, which should be used by the eNodeB to establish the full UP / RRC security context with the UE. In step 35, the UE must receive the same K_eNB from at least the stored K_ASME and the NAS_U_SEQ initial NAS service request message transmitted from the UE to the MME in step 31, and establish the UP / RRC security context from the received K_eNB.
In the first embodiment of the present invention, the UE stores the NAS_U_SEQ transmitted by the MME in the initial NAS request of the NAS service request, and uses the stored sequence number to obtain the K_eNB.
4 is a signal flow diagram showing a second embodiment of the present invention in which the UE does not need to store the NAS_U_SEQ. Instead, the MME will send a NAS_U_SEQ reception indication back to the UE via the eNodeB. In the signal S41 corresponding to the signal S21 in FIG. 2, the UE 11 transmits an initial NAS service request to the MME 13 indicating the uplink sequence number NAS_U_SEQ, and the MME will receive NAS_U_SEQ and will receive K_eNB based at least on NAS_U_SEQ and K_ASME on S42. However, in accordance with this second embodiment, the MME will contain the indication of said received NAS_U_SEQ in the S43 signal transmitted to the eNodeB 12 along with the received K_ENB, and the eNodeB will send the NAS_U_SEQ to the UE in the S44 signal. After that, the UE will receive K_eNB, at least from K_ASME and from NAS_U_SEQ, returned from MME, in signal S45. From the received security key K_eNB, the eNodeB and the UE will establish a UP / RRC security context, thereby providing secure UP / RRC traffic in the S46 signal.
FIG. 5 is a flow chart illustrating the method described above, in accordance with the second embodiment of the present invention, in which the reception indication NAS_U_SEQ returns to the UE from the MME. In step 41, the UE 11 sends an initial NAS service request message to the MME 13, the message indicating data of the uplink NAS sequence counter, NAS_U_SEQ, usually the low-order bits. At step 52, the MME receives the NAS SERVICE REQUEST message from the UE, thereby obtaining the NAS_U_SEQ and, if necessary, recovering the full NAS_U_SEQ from the low-order bits received. In step 53, the MME obtains the security key K_eNB from at least the received NAS_U_SEQ and K_ASME using the appropriate key acquisition function.
Thereafter, the MME contains an upstream sequence counter indication to the NAS, NAS_U_SEQ, in a message directing the received K_eNB to the eNodeB 12, in step 54, and the eNodeB uses the received security key K_eNB to establish the UP / RRC security context. The received NAS_U_SEQ is sent to the UE 11 by the eNodeB at step 55, and at step 5 6 the UE receives the security key K_eNB from at least K_ASME and from the received received NAS_U_SEQ to establish the security context UP / RRC shared with the eNodeB.
Obtaining K_eNB by the MME at step 53 and the UE at step 56 is performed using a suitable traditional key acquisition function, for example a pseudo-random function; K_eNB = PRF (K_ASME, NAS_U_SEQ,, ...). Typically, the key acquisition function will have additional traditional input values, for example, eNodeB identity.
FIG. 6a shows an MME 13 object for an EPS system in accordance with the present invention, further configured to establish a security key K_eNB for a security context to protect UP / RRC traffic between the UE and the service node eNodeB. MME is provided by a traditional communication tool, not shown in the drawing, for communicating with EPS nodes, for example, with eNodeB nodes, via the S1-MME interface. Additionally, in the MME object shown in FIG. 1, the ASME 61 object is shown in dotted lines, since this functional object of the EPS system can be combined with the MME object.
The facility MME 13 shown in Fig. 6a for establishing the security key K_eNB comprises means 62 for receiving a NAS service request message, including NAS_U-SEQ from the UE through its service node eNodeB; key acquisition means 63 for obtaining the security key K_eNB based at least on the received NAS_U-SEQ and stored K_ASME using the conventional key acquisition function; and sending means 64 for sending the received K_eNB to the eNodeB serving the UE.
6b shows a UE 11 (user equipment) corresponding to the present invention, a UE adapted for operation in the EPS system and further configured to establish the security key K_eNB for the security context to protect the UP / RRC traffic exchanged with the serving eNodeB. The UE is provided with a traditional communication tool, not shown in the drawing, to communicate with the nodes in the EPS system via the LTE-Uu interface to its serving eNodeB.
The UE 11 shown in FIG. 6b for establishing the security key K_eNB comprises sending parcel 66 to send the NAS SERVICE REQUEST message to the MME through the serving eNodeB, a request indicating the uplink serial number NAS_U-SEQ, and the security security key establishing means K_eNB contains key acquisition means 67 for obtaining the security key K_eNB based on at least NAS_U-SEQ and stored K_ASME using the usual key acquisition function.
The MME and UE facilities described above, as shown in FIGS. 6a and 6b, perform the functions described using a suitable combination of software and hardware, for example, programmed microprocessors or specialized integrated circuits, as well as conventional radio transmitters and receivers.
Although the invention has been described with reference to certain examples of embodiments, the description as a whole is intended only to clarify the concept of the invention and should not be construed as limiting the scope of the invention.
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both waysCites: the store holds 6 of 7
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2004044744A1 | Cites | United States of America | Search report |
| US2007171857A1 | Cites | United States of America | Search report |
| US7152238B1 | Cites | United States of America | Search report |
| RU97119182A | Cites | Russian Federation | Search report |
| US20040044744A1 | Cites | United States of America | – |
| US20070171857A1 | Cites | United States of America | – |
55 members in 17 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 60972955 | United States of America | – | |
| 97295507 | United States of America | P | |
| 97295507 | United States of America | P | |
| 2008050591 | Sweden | W | |
| 2008050591 | Sweden | W | |
| 60972955 | – | – | – |
| SE2008050591 | – | – | – |
| US20070972955P | – | – | – |
| WO2008SE50591 | – | – | – |
Members55
| Document | Office | Kind | |
|---|---|---|---|
| AU2008301284A1 | Australia | A1 | |
| CA2699846A1 | Canada | A1 | |
| WO2009038522A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AR068031A1 | Argentina | A1 | |
| EP2191608A1 | European Patent Office (EPO) | A1 | |
| CN101803271A | China | A | |
| JP2010539786A | Japan | A | |
| US2010316223A1 | United States of America | A1 | |
| CO6251350A2 | Colombia | A2 | |
| EP2191608A4 | European Patent Office (EPO) | A4 | |
| EP2191608B1 | European Patent Office (EPO) | B1 | |
| AT523980T | Austria | T | |
| ATE523980T1 | Austria | T1 | |
| RU2010115362A | Russian Federation | A | |
| ES2368875T3 | Spain | T3 | |
| PT2191608E | Portugal | E | |
| DK2191608T3 | Denmark | T3 | |
| EP2403180A1 | European Patent Office (EPO) | A1 | |
| PL2191608T3 | Poland | T3 | |
| RU2466503C2 | Russian Federation | C2 | |
| CN101803271B | China | B | |
| JP2013013125A | Japan | A | |
| CN102916808A | China | A | |
| AU2008301284B2 | Australia | B2 | |
| EP2629451A1 | European Patent Office (EPO) | A1 | |
| US8660270B2 | United States of America | B2 | |
| JP5425281B2 | Japan | B2 | |
| US2014185809A1 | United States of America | A1 | |
| US8938076B2 | United States of America | B2 | |
| US2015146870A1 | United States of America | A1 | |
| DE202008018538U1 | Germany | U1 | |
| CN102916808B | China | B | |
| CA2699846C | Canada | C | |
| US9615249B2 | United States of America | B2 | |
| US2017170954A1 | United States of America | A1 | |
| US10057055B2 | United States of America | B2 | |
| US2018332470A1 | United States of America | A1 | |
| RU2466503C9This record | Russian Federation | C9 | |
| EP2629451B1 | European Patent Office (EPO) | B1 | |
| PT2629451T | Portugal | T | |
| DK2629451T3 | Denmark | T3 | |
| US10455417B2 | United States of America | B2 | |
| PL2629451T3 | Poland | T3 | |
| US2020008053A1 | United States of America | A1 | |
| EP3598690A1 | European Patent Office (EPO) | A1 | |
| ES2750051T3 | Spain | T3 | |
| US11075749B2 | United States of America | B2 | |
| US2021328775A1 | United States of America | A1 | |
| EP3598690B1 | European Patent Office (EPO) | B1 | |
| PT3598690T | Portugal | T | |
| DK3598690T3 | Denmark | T3 | |
| ES2906127T3 | Spain | T3 | |
| PL3598690T3 | Poland | T3 | |
| HUE058067T2 | Hungary | T2 | |
| US11917055B2 | United States of America | B2 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Reissue of patent specificationTH4A | TH4A | |
| Reissue of patent specificationTH4A | TH4A |
Numbers
- Publication
- 0002466503
- Publication, DOCDB
- 2466503
- Publication, EPODOC
- RU2466503
- Application
- 2010115362
- Application, DOCDB
- 2010115362
- Application, EPODOC
- RU20100115362
Titles2
- Russian
- СПОСОБ И УСТРОЙСТВО ДЛЯ ИСПОЛЬЗОВАНИЯ В СИСТЕМЕ СВЯЗИ
- English
- METHOD AND DEVICE FOR USE IN TELECOMMUNICATIONS SYSTEM
Classification
- CPC, 11
- H04L9/083
- H04L63/062
- H04L2463/061
- H04W8/20
- H04W92/10
- H04L2209/80
- H04W12/041
- H04W12/0471
- H04L9/0816
- H04L2209/24
- H04L9/0869
- IPC, 1
- H04L9 08