Method and system for managing security in mobile communication system
Summary by NHIP
Mobile Security Management
The mobility management entity performs security procedures by comparing a received public land mobile network identity with a cell identity. It transmits an authentication request or security mode command when these identities differ and the tracking area update procedure finishes.
Claim Score by NHIP
Abstract
A method, an apparatus, and a system for solving and managing security problems, which may occur during a handover of a User Equipment (UE) between PLMNs in a mobile communication network, by using a Non-Access Stratum (NAS) protocol are provided. By the method, a UE can perform a security mode command and an authentication with a network. Further, the method can prevent interruption of communication due to authentication or security during a handover of a UE between Public Land Mobile Networks (PLMNs).

Term
4.1 yearsleft in the term
Expires 27 October 2030.
- Priority
- Filed
- Granted
- Today
- Expires
15 claims: 2 independent, 13 dependent
- 1Broadest claimClaim Score 54, average(NHIP)A method for performing a security procedure by a mobility management entity (MME) in a mobile communication system, the method comprising:receiving, from a terminal, a tracking area update (TAU) request message including a public land mobile network identity (PLMN ID) after a handover of the terminal;comparing the PLMN ID included in the TAU request message with a PLMN ID of a cell;transmitting, to the terminal, an authentication request message if the PLMN ID included in the TAU request message is different from the PLMN ID of the cell and a TAU procedure is complete;and receiving, from the terminal, an authentication response message including an authentication response parameter if an authentication is accepted.
- 9A mobility management entity (MME) apparatus for performing a security procedure in a mobile communication system, the MME apparatus comprising:a transceiver configured to transmit and receive messages;and a controller configured to: receive, from a terminal, a tracking area update (TAU) request message including a public land mobile network identity (PLMN ID) after a handover of the terminal, compare the PLMN ID included in the TAU request message with a PLMN ID of a cell, transmit, to the terminal, an authentication request message if the PLMN ID included in the TAU request message is different from the PLMN ID of the cell and a TAU procedure is complete, and receive, from the terminal, an authentication response message including an authentication response parameter if an authentication is accepted.
Independent claims2
87 paragraphs in 5 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATION(S)
0001This application is a continuation application of prior application Ser. No. 14/844,737, filed on Sep. 3, 2015, which is a continuation application of prior application Ser. No. 14/532,421, filed on Nov. 4, 2014, which issued as U.S. Pat. No. 9,131,380 on Sep. 8, 2015, and claimed the benefit under 35 U.S.C §119(a) of a U.S. patent application filed on Apr. 27, 2012, in the U.S. Patent and Trademark Office and assigned Ser. No. 13/504,786, which issued as U.S. Pat. No. 8,881,237 on Nov. 4, 2014, and which was the U.S. National Stage application under 35 U.S.C. §371 of an International Application filed on Oct. 27, 2010, and assigned application number PCT/KR2010/007430, which claimed the benefit under 35 U.S.C. §365(b) of a Korean patent application filed in the Korean Industrial Property Office on Oct. 27, 2009, and assigned Serial number 10-2009-0102501, the entire disclosure of each of which is hereby incorporated by reference.
BACKGROUND OF THE INVENTION
00021. Field of the Invention
0003The present invention relates to a mobile communication system. More particularly, the present invention relates to a method and a system for managing a security and an authentication of a User Equipment (UE) and a network in an environment in which the UE performs a handover.
00042. Description of the Related Art
0005The 3rd Generation Partnership Project (3GPP), which is a representative organization for establishing standards for a mobile communication system, has defined an Evolved Packet System (EPS) for the next generation communication and has employed the Mobility Management Entity (MME) as a mobility management entity of a network. For the mobile communication system as described above, a solution improved from the Non-Access Stratum (NAS) protocol, which has been used in the conventional mobile communication systems, such as a 3GPP communication system, has been presented in order to provide a high speed communication service in the next generation mobile communication. In the improved solution, a security management scheme has been enhanced by employing, in performing a security mode, the concept of a NAS protocol, which provides a security to a NAS, in addition to a security process performed in a wireless access stratum and a conventional authentication process.
0006However, according to the current NAS protocol definition and the current NAS protocol security definition, the security may not be ensured or the communication may be interrupted in supporting a handover between Public Land Mobile Networks (PLMNs). Therefore, a need exists for a method capable of supporting the communication, the security, and the authentication between a UE and a network in an efficient and incessant manner even though the PLMN changes, through an improvement of a NAS security mode command process introduced in order to enhance the NAS protocol and the authentication process.
0007The above information is presented as background information only to assist with an understanding of the present disclosure. No determination has been made, and no assertion is made, as to whether any of the above might be applicable as prior art with regard to the present invention.
SUMMARY OF THE INVENTION
0008Aspects of the present invention are to address at least the above-mentioned problems and/or disadvantages and to provide at least the advantages described below. Accordingly, an aspect of the present invention is to provide a system and a method for security management using a Non-Access Stratum (NAS) protocol during a handover of a UE by a mobility management entity in a mobile communication system.
0009Another aspect of the present invention is to provide a system and a method for security management in a mobile communication system, which enables smooth operations of authentication and security modes even during a handover of a User Equipment (UE) between Public Land Mobile Networks (PLMNs) by using a NAS protocol, thereby achieving an efficient mobility management of the UE.
0010In accordance with an aspect of the present invention, a method of managing a security during a handover of a User Equipment (UE) by a Mobility Management Entity (MME) of a mobile communication system is provided. The method includes comparing a network identity included in a Tracking Area Update (TAU) request message received from the UE with a network identity of the MME, and determining whether to transmit an authentication request message, based on a result of the comparison between the network identities.
0011In accordance with another aspect of the present invention, a method of managing a security during a handover of a UE in a mobile communication system is provided. The method includes transmitting a TAU request message to an MME, and receiving an authentication request message from the MME according to a result of comparison between a network identity included in the TAU request message and a network identity of the MME.
0012In accordance with another aspect of the present invention, a method of managing a security during a handover of a UE by an MME of a mobile communication system is provided. The method includes receiving a TAU request message from the UE, comparing a network identity included in the TAU request message with a network identity of the MME, and determining whether to transmit a Security Mode Command (SMC) message to the UE as a result of the comparison.
0013In accordance with another aspect of the present invention, a method of managing a security during a handover of a UE in a mobile communication system is provided. The method includes transmitting a TAU request message to an MME, and receiving an SMC message from the MME according to a result of comparison between a network identity included in the TAU request message and a network identity of the MME.
0014In accordance with another aspect of the present invention, an apparatus for managing a security during a handover of a UE by an MME of a mobile communication system is provided. The apparatus includes a control unit for comparing a network identity included in a TAU request message received from the UE with a network identity of the MME, and for determining whether to transmit an authentication request message, based on a result of the comparison between the network identities.
0015In accordance with another aspect of the present invention, an apparatus for managing a security during a handover of a UE in a mobile communication system is provided. The apparatus includes a control unit for transmitting a TAU request message to an MME, and for receiving an authentication request message from the MME according to a result of comparison between a network identity included in the TAU request message and a network identity of the MME.
0016In accordance with another aspect of the present invention, an apparatus for managing a security during a handover of a UE in a mobile communication system is provided. The apparatus includes a control unit for transmitting a TAU request message to an MME, and for receiving an SMC message from the MME according to a result of comparison between a network identity included in the TAU request message and a network identity of the MME.
0017Other aspects, advantages, and salient features of the invention will become apparent to those skilled in the art from the following detailed description, which, taken in conjunction with the annexed drawings, discloses exemplary embodiments of the invention.
BRIEF DESCRIPTION OF THE DRAWINGS
0018The above and other aspects, features, and advantages of certain exemplary embodiments of the present invention will be more apparent from the following description taken in conjunction with the accompanying drawings, in which:
0019<figref idref="DRAWINGS">FIG. 1</figref> is a block diagram illustrating a Public Land Mobile Network (PLMN) handover and security environment in a mobile communication system according to an exemplary embodiment of the present invention;
0020<figref idref="DRAWINGS">FIG. 2</figref> is a message flow diagram illustrating a process of authentication during a handover between PLMNs according to an exemplary embodiment of the present invention;
0021<figref idref="DRAWINGS">FIG. 3</figref> is a message flow diagram illustrating a Security Mode Command (SMC) process during a handover between PLMNs according to an exemplary embodiment of the present invention;
0022<figref idref="DRAWINGS">FIG. 4</figref> is a message flow diagram illustrating an authentication process during a handover between PLMNs according to an exemplary embodiment of the present invention;
0023<figref idref="DRAWINGS">FIG. 5</figref> is a message flow diagram illustrating an authentication process during a handover between PLMNs according to another exemplary embodiment of the present invention;
0024<figref idref="DRAWINGS">FIG. 6</figref> is a message flow diagram illustrating a Security Mode Command (SMC) process during a handover between PLMNs according to an exemplary embodiment of the present invention;
0025<figref idref="DRAWINGS">FIG. 7</figref> is a message flow diagram illustrating an SMC process during a handover between PLMNs according to another exemplary embodiment of the present invention;
0026<figref idref="DRAWINGS">FIG. 8</figref> is a flowchart illustrating an operation of a Mobile Management Entity (MME) for supporting an authentication process during a handover between PLMNs according to an exemplary embodiment of the present invention;
0027<figref idref="DRAWINGS">FIG. 9</figref> is a flowchart illustrating an operation of a UE for supporting an authentication process during a handover between PLMNs according to an exemplary embodiment of the present invention;
0028<figref idref="DRAWINGS">FIG. 10</figref> is a flowchart illustrating an operation of an MME for supporting an SMC process during a handover between PLMNs according to an exemplary embodiment of the present invention; and
0029<figref idref="DRAWINGS">FIG. 11</figref> is a flowchart illustrating an operation of a User Equipment (UE) for supporting an SMC process during a handover between PLMNs according to an exemplary embodiment of the present invention.
0030Throughout the drawings, it should be noted that like reference numbers are used to depict the same or similar elements, features, and structures.
DETAILED DESCRIPTION OF EXEMPLARY EMBODIMENTS
0031The following description with reference to the accompanying drawings is provided to assist in a comprehensive understanding of exemplary embodiments of the invention as defined by the claims and their equivalents. It includes various specific details to assist in that understanding but these are to be regarded as merely exemplary. Accordingly, those of ordinary skill in the art will recognize that various changes and modifications of the embodiments described herein can be made without departing from the scope and spirit of the invention. In addition, descriptions of well-known functions and constructions may be omitted for clarity and conciseness.
0032The terms and words used in the following description and claims are not limited to the bibliographical meanings, but, are merely used by the inventor to enable a clear and consistent understanding of the invention. Accordingly, it should be apparent to those skilled in the art that the following description of exemplary embodiments of the present invention is provided for illustration purpose only and not for the purpose of limiting the invention as defined by the appended claims and their equivalents.
0033It is to be understood that the singular forms “a,” “an,” and “the” include plural referents unless the context clearly dictates otherwise. Thus, for example, reference to “a component surface” includes reference to one or more of such surfaces.
0034A main idea of the exemplary embodiments of the present invention is to provide an incessant mobile communication for a mobile communication system during a handover of a User Equipment (UE) between Public Land Mobile Networks (PLMNs) by using a Non-Access Stratum (NAS) protocol which is a protocol between a UE and a Mobility Management Entity (MME). Further, exemplary embodiments of the present invention provide a method of supporting an authentication and the security and management of a NAS protocol, which is a protocol between a UE and an MME for authentication. The following detailed description of exemplary embodiments of the present invention discusses a 3GPP-based Evolved Packet System (EPS) system, Universal Terrestrial Radio Access Network (UTRAN), and GSM EDGE Radio Access Network (GERAN), although exemplary embodiments of the present invention can be used by another mobile communication system using a NAS protocol.
0035Meanwhile, as shown in <figref idref="DRAWINGS">FIG. 1</figref>, the exemplary embodiment of the present invention shown in <figref idref="DRAWINGS">FIG. 1</figref> proposes a method of supporting an authentication and a security for communication between a UE and an MME by using a NAS protocol when a UE moves from an Evolved UTRAN (EUTRAN) or another Radio Access Technology (RAT) to another EUTRAN, and this method can be applied to other mobile communication systems, which have similar technical backgrounds, channel types, network architectures, or protocols, or perform similar operations with different protocols, with small modifications without departing from the scope of the present invention, as apparent to those skilled in the art.
0036<figref idref="DRAWINGS">FIG. 1</figref> is a block diagram illustrating a PLMN handover and security environment in a mobile communication system according to an exemplary embodiment of the present invention. As an example, a 3GPP EPS system structure has been described in <figref idref="DRAWINGS">FIG. 1</figref>. The following description of exemplary embodiments of the present invention mainly discusses potential problems associated with when a UE moves from a EUTRAN or another RAT to another EUTRAN. According to exemplary embodiments of the present invention, the method can be used by another similar mobile communication system.
0037Referring to <figref idref="DRAWINGS">FIG. 1</figref>, an Evolved Node Base Station (E Node B; eNB)/Radio Network Controller (RNC) <b>133</b> establishes a radio access and performs a communication with a UE <b>110</b> located within a service area of itself. The UE <b>110</b> refers to a terminal or UE accessing a packet data network, such as the Internet, through a Serving Gateway (SGW) <b>116</b>. As described herein, a Packet Data Network Gateway (PDN GW) <b>118</b> as an important network entity of a packet data network that serves as a Home Agent (HA).
0038Meanwhile, a Mobility Management Entity (MME)/Serving GPRS Support Node (SGSN) <b>135</b> performs a mobility management, a location management, and a registration of a UE. Further, a Home Subscriber Server (HSS) <b>121</b> for managing authentication information and service information for a user and a UE is connected to the MME/SGSN <b>135</b> through an interface.
0039A data path exists between the eNB/RNC <b>133</b> and the Serving GW <b>116</b>, and a control path or an interface for managing the mobility of a UE exists between the MME/SGSN <b>135</b> and the Serving GW <b>116</b>. According to exemplary embodiments of the present invention, the UE <b>110</b> and the MME/SGSN <b>135</b> communicate with each other using a NAS protocol stack, thereby performing the mobility management and session management.
0040Exemplary embodiments of the present invention address a situation in which a UE <b>110</b> connected to a source network performs a handover. It is assumed that the source network may be one RAT among various types of RATs, such as a EUTRAN, UTRAN, and GERAN, and the PLMN of the source network is different from the PLMN to which the UE <b>110</b> will move. That is, exemplary embodiments of the present invention attempt to resolve problems associated with a handover situation of a UE <b>110</b> in which the PLMN changes from PLMN A to PLMN B during the handoff of the UE <b>110</b> from a source network to a target network and the target network supports the EUTRAN. Therefore, when the UE <b>110</b> performs a handover from a source network to a target network, the UE <b>110</b> is connected to the target eNB <b>112</b>, the target MME <b>114</b>, and the target HSS <b>141</b>, and receives a service from them. <figref idref="DRAWINGS">FIGS. 2 to 11</figref> will be described with reference to the above-mentioned network according to exemplary embodiments of the present invention for an efficient operation and the UE <b>110</b> and the MME <b>114</b> based on a NAS protocol.
0041<figref idref="DRAWINGS">FIG. 2</figref> is a message flow diagram illustrating a process of authentication during a handover between PLMNs according to an exemplary embodiment of the present invention.
0042Step <b>201</b> corresponds to a handover preparation step. That is, step <b>201</b> corresponds to a step of requesting a core network to provide resources, which includes a step of making requests for resource preparation by the target eNB <b>112</b>, the target MME <b>114</b>, and the serving GW <b>116</b>. In this step, a bearer context or mobility management context is transmitted from a source system to a target system for the requesting.
0043The handover preparation step includes the following sub-steps. When the source eNB/RNC <b>133</b> transmits a “relocation required” message to the source MME/SGSN <b>135</b> in step <b>201</b>-<b>1</b>, the source MME/SGSN <b>135</b> forwards a relocation request message to the target MME <b>114</b> in step <b>201</b>-<b>3</b>. Then, in step <b>201</b>-<b>5</b>, the target MME <b>114</b> forwards a relocation response message to the source MME/SGSN <b>135</b>.
0044In step <b>211</b>, the source MME/SGSN <b>135</b> sends a relocation command message to the source eNB/RNC <b>133</b>, thereby notifying the source eNB/RNC <b>133</b> that the handover preparation step has been completed. Then, the source eNB/RNC <b>133</b> transmits a handover command message to the UE <b>110</b> in step <b>213</b>, and the UE <b>110</b> issues a handover command to the target eNB <b>112</b> in step <b>215</b>. When the UE <b>110</b> has performed a handover to the target eNB <b>112</b>, the target eNB <b>112</b> transmits a handover notification message to the target MME <b>114</b> in step <b>217</b>. Thereafter, in step <b>219</b>, if there is a change in the serving GW <b>116</b>, a bearer modification request is made by the target MME <b>114</b>, the serving GW <b>116</b>, or the PDN GW <b>118</b>. In step <b>221</b>, during the handover process, the UE <b>110</b> transmits a Tracking Area Update (TAU) request message to the target MME <b>114</b>. Thereafter, the target MME <b>114</b> inserts a PLMN Identity (ID) in a TAU response message, which is not shown in the drawings, and then sends the TAU response message to the UE <b>110</b>. Then, the UE <b>110</b> can obtain a network ID of the serving network, which provides a service to the UE <b>110</b>. The network ID includes a serving network ID and the PLMN ID. Therefore, even though the authentication thereafter is started in the target MME <b>114</b>, no problem occurs in the authentication because the UE <b>110</b> and the target MME <b>114</b> share the PLMN ID (e.g., the ID of the PLMN B).
0045Referring to <figref idref="DRAWINGS">FIG. 2</figref>, when the target MME <b>114</b> transmits an authentication request message to the UE <b>110</b> as in step <b>241</b> while the target MME <b>114</b> processes the TAU request message received in step <b>221</b>, the UE <b>110</b> verifies an authentication vector in step <b>243</b>. At this time, because the UE <b>110</b> has not received a response (e.g., TAU response message) in response to the TAU request message, the UE <b>110</b> uses the PLMN ID (e.g., PLMN A), which is the currently known ID of the serving network, in calculation for verifying the authentication vector, which results in a failure in the verification of the entire authentication vector. As a result, the Radio Resource Control (RRC) connection between the UE <b>110</b> and the source eNB/RNC <b>133</b> is interrupted in step <b>245</b>, which causes a problem.
0046<figref idref="DRAWINGS">FIG. 3</figref> is a message flow diagram illustrating a Security Mode Command (SMC) process during a handover between PLMNs according to an exemplary embodiment of the present invention.
0047Referring to <figref idref="DRAWINGS">FIG. 3</figref>, the exemplary embodiment of the present invention is described in relation to an example which is hereinafter referred to as SMC case 1.
0048Step <b>301</b> corresponds to a handover preparation step. Step <b>301</b> is identical to the handover preparation step <b>201</b>, so a detailed description thereof will be omitted here.
0049In step <b>311</b>, the source MME/SGSN <b>135</b> sends a relocation command message to the source eNB/RNC <b>133</b>, thereby notifying the source eNB/RNC <b>133</b> that the handover preparation step has been completed. Then, the source eNB/RNC <b>133</b> transmits a handover command message to the UE <b>110</b> in step <b>313</b>, and the UE <b>110</b> issues a handover command to the target eNB <b>112</b>. When the UE <b>110</b> completes the handover process to the target eNB <b>112</b> in step <b>315</b>, the target eNB <b>112</b> transmits a handover notification message to the target MME <b>114</b> in step <b>317</b>. Thereafter, in step <b>319</b>, if there is a change in the serving GW <b>116</b>, etc., a bearer modification request is made by the target MME <b>114</b>, the serving GW <b>116</b>, or the PDN GW <b>118</b>. In step <b>321</b>, during the handover process, the UE <b>110</b> transmits a Tracking Area Update (TAU) request message to the target MME <b>114</b>. Thereafter, the target MME <b>114</b> inserts a PLMN Identity (ID) in a TAU response message, which is not shown in the drawings, and then sends the TAU response message to the UE <b>110</b>. Then, the UE <b>110</b> can obtain a network ID of the serving network, which provides a service to the UE <b>110</b>. Therefore, even though the security mode command process thereafter is started in the target MME <b>114</b>, no problem occurs in executing the security mode command since the UE <b>110</b> and the target MME <b>114</b> share the PLMN ID (e.g., the ID of the PLMN B).
0050However, referring to <figref idref="DRAWINGS">FIG. 3</figref>, the target MME <b>114</b> transmits a security mode command message to the UE <b>110</b> as in step <b>341</b> while it processes the TAU request message received in step <b>321</b>. Then, in step <b>343</b>, the UE <b>110</b> searches for an authentication key through an NAS Key Set Identity (eKSI). At this time, because the UE <b>110</b> has not received a response (e.g., a TAU response message) in response to the TAU request message, the serving network ID currently known to the UE <b>110</b> is the PLMN ID (PLMN A). However, due to the same eKSI in spite of different authentication values KASME, a NAS encryption key, and a NAS integrity key are generated based on the different authentication keys. Thereafter, when the UE <b>110</b> verifies the NAS Message Authentication Code (MAC) value in step <b>345</b>, the UE <b>110</b> fails in deciphering the MAC because the integrity keys are different. As a result, a Radio Resource Control (RRC) protocol connection between the UE <b>110</b> and the source eNB/RNC <b>133</b> may be interrupted, which causes a problem. In step <b>351</b>, the target MME <b>114</b> transmits a TAU accept message to the UE <b>110</b>. In the following description of exemplary embodiments of the present invention (as shown in <figref idref="DRAWINGS">FIGS. 4 to 11</figref>), the operations of the UE are performed by a control unit (not shown) within the UE, and the operations of the MME are performed by a control unit (not shown) within the MME.
0051<figref idref="DRAWINGS">FIG. 4</figref> is a message flow diagram illustrating an authentication process during a handover between PLMNs according to an exemplary embodiment of the present invention.
0052Referring to <figref idref="DRAWINGS">FIG. 4</figref>, the exemplary embodiment of the present invention is described in relation to the example identified as SMC case 1.
0053Step <b>401</b> corresponds to a handover preparation step. Step <b>401</b> is identical to the handover preparation step <b>201</b>, so a detailed description thereof will be omitted here.
0054In step <b>411</b>, the source MME/SGSN <b>135</b> sends a relocation command message to the source eNB/RNC <b>133</b>, thereby notifying the source eNB/RNC <b>133</b> that the handover preparation step has been completed. Then, the source eNB/RNC <b>133</b> transmits a handover command message to the UE <b>110</b> in step <b>413</b>, and the UE <b>110</b> issues a handover command to the target eNB <b>112</b>. When the UE <b>110</b> completes the handover process to the target eNB <b>112</b> in step <b>415</b>, the target eNB <b>112</b> transmits a handover notification message to the target MME <b>114</b> in step <b>417</b>. Thereafter, in step <b>419</b>, if there is a change in the serving GW <b>116</b>, etc., a bearer modification request is made by the target MME <b>114</b>, the serving GW <b>116</b>, the PDN GW <b>118</b>, etc. In step <b>421</b>, during the handover process, the UE <b>110</b> transmits a Tracking Area Update (TAU) request message to the target MME <b>114</b>. Thereafter, in step <b>423</b>, the MME <b>114</b> compares the PLMN ID of the MME <b>114</b> itself and the PLMN ID included in the information transmitted from the UE <b>110</b>. When the two IDs are different, the MME <b>114</b> sends an identity request message to the UE <b>110</b> in step <b>425</b>. In step <b>427</b>, the UE <b>110</b> transmits an identity response message including an International Mobile Station Identity (IMSI) of itself to the target MME <b>114</b>. In step <b>429</b>, the target MME <b>114</b> transmits an authentication data request message to the HSS <b>141</b>. In step <b>431</b>, the HSS <b>141</b> calculates an authentication vector based on a new PLMN identity. Then, the HSS <b>141</b> transmits a random number (RAND), an authentication key (KASME), and an authentication token (AUTN) to the target MME <b>114</b> through an authentication data response step as step <b>433</b>. Thereafter, the target MME <b>114</b> transmits an authentication request message including a serving network identity (i.e. PLMN identity) to the UE <b>110</b> in step <b>441</b>. The authentication request message further includes an AUTN and a random challenge (RAND), which are a part of the authentication vector, in addition to the PLMN identity. In step <b>443</b>, the UE <b>110</b> verifies the authentication vector and calculates the authentication key (K<sub>ASME</sub>) by using the new PLMN identity transmitted from the MME <b>114</b>. Thereafter, in step <b>445</b>, the UE <b>110</b> transmits an authentication response message to the target MME <b>114</b> in step <b>445</b>. At this time, the authentication response message sent from the UE <b>110</b> to the target MME <b>114</b> includes an RES, which is a response parameter calculated by the UE <b>110</b>. The RES may include the calculated authentication key (K<sub>ASME</sub>).
0055In the meantime, the target MME <b>114</b> verifies if a received authentication response message is an authentication response message transmitted from the UE, to which the target MME itself has sent the authentication request, by comparing the RES included in the received authentication response message with an expected response (XRES).
0056Although <figref idref="DRAWINGS">FIG. 4</figref> is based on an assumption that there is no transfer of a PLMN identity by the eNB/RNC <b>133</b> through a handover command in step <b>413</b>, a PLMN identity may be transferred through a handover command by the eNB/RNC <b>133</b> in step <b>413</b> in the case of another embodiment (authentication case 3). Then, even when the TAU request message has been transmitted from the UE <b>110</b> to the target MME <b>114</b> as in step <b>421</b>, the UE <b>110</b> and the MME <b>114</b> can have the same PLMN ID even without performing steps <b>423</b> to <b>441</b>. Therefore, the authentication process, security process, and communication thereafter can be incessantly performed even though the target MME <b>114</b> transmits an authentication request message in step <b>441</b>.
0057<figref idref="DRAWINGS">FIG. 5</figref> is a message flow diagram illustrating an authentication process during a handover between PLMNs according to another exemplary embodiment of the present invention.
0058Referring to <figref idref="DRAWINGS">FIG. 5</figref>, the exemplary embodiment of the present invention is described in relation to an example which is hereafter referred to as SMC case 2.
0059Step <b>501</b> corresponds to a handover preparation step. Step <b>501</b> is identical to the handover preparation step <b>201</b>, so a detailed description thereof will be omitted here.
0060In step <b>511</b>, the source MME/SGSN <b>135</b> sends a relocation command message to the source eNB/RNC <b>133</b>, thereby notifying the source eNB/RNC <b>133</b> that the handover preparation step has been completed. Then, the source eNB/RNC <b>133</b> transmits a handover command message to the UE <b>110</b> in step <b>513</b>, and the UE <b>110</b> issues a handover command to the target eNB <b>112</b>. When the UE <b>110</b> completes the handover process to the target eNB <b>112</b> in step <b>515</b>, the target eNB <b>112</b> transmits a handover notification message to the target MME <b>114</b> in step <b>517</b>. Thereafter, in step <b>519</b>, if there is a change in the serving GW <b>116</b>, etc., a bearer modification request is made by the target MME <b>114</b>, the serving GW <b>116</b>, the PDN GW <b>118</b>, etc. In step <b>521</b>, during the handover process, the UE <b>110</b> transmits a Tracking Area Update (TAU) request message to the target MME <b>114</b>. Thereafter, in step <b>523</b>, the target MME <b>114</b> compares the PLMN ID of the MME <b>114</b> itself with the PLMN ID included in the information transmitted from the UE <b>110</b>. Then, in step <b>541</b>, when the two IDs are different, which implies that the serving network identities (PLMN identities) are different, the MME <b>114</b> does not send an authentication request message to the UE <b>110</b> until the processing of the TAU request message in step <b>521</b> is completed.
0061<figref idref="DRAWINGS">FIG. 6</figref> is a message flow diagram illustrating a Security Mode Command (SMC) process during a handover between PLMNs according to an exemplary embodiment of the present invention.
0062Referring to <figref idref="DRAWINGS">FIG. 6</figref>, the exemplary embodiment of the present invention is described in relation to the example identified as SMC case 1.
0063Step <b>601</b> corresponds to a handover preparation step. Step <b>601</b> is identical to the handover preparation step <b>201</b>, so a detailed description thereof will be omitted here.
0064In step <b>611</b>, the source MME/SGSN <b>135</b> sends a relocation command message to the source eNB/RNC <b>133</b>, thereby notifying the source eNB/RNC <b>133</b> that the handover preparation step has been completed. Then, the source eNB/RNC <b>133</b> transmits a handover command message to the UE <b>110</b> in step <b>613</b>, and the UE <b>110</b> issues a handover command to the target eNB <b>112</b>. When the UE <b>110</b> completes the handover process to the target eNB <b>112</b> in step <b>615</b>, the target eNB <b>112</b> transmits a handover notification message to the target MME <b>116</b> in step <b>617</b>. Thereafter, in step <b>619</b>, if there is a change in the serving GW <b>116</b>, etc., a bearer modification request is made by the target MME <b>116</b>, the serving GW <b>116</b>, the PDN GW <b>118</b>, etc. In step <b>621</b>, during the handover process, the UE <b>110</b> transmits a Tracking Area Update (TAU) request message to the target MME <b>116</b>. Thereafter, in step <b>623</b>, the target MME <b>116</b> compares the PLMN ID of the MME <b>116</b> itself with the PLMN ID included in the information transmitted from the UE <b>110</b>. When the two IDs are different and the target MME <b>114</b> has acquired an authentication key (K<sub>ASME</sub>) for a new PLMN identity, the target MME <b>114</b> generates a NAS integrity key (K<sub>NAS</sub>int) and a NAS encryption key (K<sub>NAS</sub>enc) in step <b>625</b>. Thereafter, in step <b>641</b>, the target MME <b>114</b> inserts a serving network identity (i.e., a PLMN identity) in a Security Mode Command (SMC) message and transmits the SMC message to the UE <b>110</b>. In step <b>643</b>, the UE <b>110</b> acquires an authentication key through a NAS Key Set Identity (eKSI). At this time, the UE <b>110</b> acquires the authentication key through an eKSI corresponding to the corresponding PLMN identity by using the newly received PLMN identity information, and generates a NAS integrity key (K<sub>NAS</sub>int) and a NAS encryption key (K<sub>NAS</sub>enc) from the authentication key. Thereafter, in step <b>645</b>, the UE <b>110</b> verifies a NAS Message Authentication Code (MAC) by using the NAS integrity key (K<sub>NAS</sub>int). When the verification is a success, the UE <b>110</b> transmits a NAS security mode completion message in step <b>647</b>.
0065Although <figref idref="DRAWINGS">FIG. 6</figref> is based on an assumption that there is no transfer of a PLMN identity by the eNB/RNC <b>133</b> through a handover command in step <b>613</b>, a PLMN identity may be transferred through a handover command by the eNB/RNC <b>133</b> in step <b>613</b> in the case of another exemplary embodiment of the present invention described in relation to an example which is hereinafter referred to as SMC case 3. Then, even when the TAU request message has been transmitted from the UE <b>110</b> to the target MME <b>114</b> as in step <b>621</b>, the UE <b>110</b> and the MME <b>114</b> can have the same PLMN ID even without performing steps <b>623</b> to <b>641</b>. Therefore, the authentication process, security process, and communication thereafter can be incessantly performed even though the target MME <b>114</b> transmits an SMC message in step <b>641</b>.
0066<figref idref="DRAWINGS">FIG. 7</figref> is a message flow diagram illustrating an SMC process during a handover between PLMNs according to another exemplary embodiment of the present invention.
0067Referring to <figref idref="DRAWINGS">FIG. 7</figref>, the exemplary embodiment of the present invention is described in relation to the example identified as SMC case 2.
0068Step <b>701</b> corresponds to a handover preparation step. Step <b>701</b> is identical to the handover preparation step <b>201</b>, so a detailed description thereof will be omitted here.
0069In step <b>711</b>, the source MME/SGSN <b>135</b> sends a relocation command message to the source eNB/RNC <b>133</b>, thereby notifying the source eNB/RNC <b>133</b> that the handover preparation step has been completed. Then, the source eNB/RNC <b>133</b> transmits a handover command message to the UE <b>110</b> in step <b>713</b>, and the UE <b>110</b> issues a handover command to the target eNB <b>112</b>. When the UE <b>110</b> completes the handover process to the target eNB <b>112</b> in step <b>715</b>, the target eNB <b>112</b> transmits a handover notification message to the target MME <b>114</b> in step <b>717</b>. Thereafter, in step <b>719</b>, if there is a change in the serving GW <b>116</b>, etc., a bearer modification request is made by the target MME <b>114</b>, the serving GW <b>116</b>, the PDN GW <b>118</b>, etc. In step <b>721</b>, during the handover process, the UE <b>110</b> transmits a Tracking Area Update (TAU) request message to the target MME <b>114</b>. Thereafter, in step <b>723</b>, the target MME <b>114</b> compares the PLMN ID of the MME <b>114</b> itself with the PLMN ID included in the information transmitted from the UE <b>110</b>. Then, in step <b>741</b>, when the two PLMN identities are different and the target MME <b>114</b> has acquired an authentication key (K<sub>ASME</sub>) for a new PLMN identity through an authentication process, the target MME <b>114</b> does not send an SMC message based on the new authentication key to the UE <b>110</b> until the processing of the TAU request message is completed.
0070<figref idref="DRAWINGS">FIG. 8</figref> is a flowchart illustrating an operation of an MME for supporting an authentication process during a handover between PLMNs according to an exemplary embodiment of the present invention.
0071Referring to <figref idref="DRAWINGS">FIG. 8</figref>, in step <b>801</b>, the target MME <b>114</b> performs a handover preparation process. Step <b>801</b> is identical to the handover preparation step <b>201</b>, so a detailed description thereof will be omitted here. In step <b>803</b>, the target MME <b>114</b> performs a process before receiving a TAU request message among the handover process. In step <b>805</b>, the target MME <b>114</b> determines the serving network identity (i.e., PLMN identity) through various comparisons, for example, by comparing the PLMN ID of the target MME <b>114</b> with a PLMN ID within an old GUTI of the TAU message transmitted from the UE <b>110</b> or by comparing the PLMN ID of the target MME <b>114</b> with a PLMN ID of a last-visited TAI within the TAU message transmitted from the UE <b>110</b>. When the PLMN IDs are different, one solution is that the target MME <b>114</b> does not send an authentication request message to the UE <b>110</b> until the processing of the TAU message is completed as in step <b>811</b>. Another solution (e.g., case 1) is that the target MME <b>114</b> sends an identity request message to the UE <b>110</b> and receives an identity response message from the UE <b>110</b> as in step <b>821</b>. Thereafter, as in step <b>823</b>, the target MME <b>114</b> transmits an authentication data request message to the HSS <b>141</b> by using UE identity information and receives a new authentication vector as a response. In step <b>825</b>, the target MME <b>114</b> sends an authentication request message together with a serving network ID (i.e. PLMN ID) to the UE <b>110</b>. Then, in step <b>841</b>, the target MME <b>114</b> receives an authentication response message and verifies the response value.
0072<figref idref="DRAWINGS">FIG. 9</figref> is a flowchart illustrating an operation of a UE for supporting an authentication process during a handover between PLMNs according to an exemplary embodiment of the present invention.
0073Referring to <figref idref="DRAWINGS">FIG. 9</figref>, in step <b>901</b>, the UE <b>110</b> performs a handover preparation process. Step <b>901</b> is identical to the handover preparation step <b>201</b>, so a detailed description thereof will be omitted here. In step <b>903</b>, the UE <b>110</b> performs a process before sending a TAU request message among the handover process. In step <b>921</b>, the UE <b>110</b> receives an identity request message from the target MME <b>114</b> and sends an identity response message to the target MME <b>114</b> as a response to the identity request message in step <b>921</b>. In step <b>925</b>, the UE <b>110</b> receives an authentication request message including a serving network ID (i.e., PLMN ID) from the target MME <b>114</b>. Then, in step <b>931</b>, the UE <b>110</b> verifies an authentication token, calculates a response value (RES), and calculates an authentication key (K<sub>ASME</sub>) by using the serving network ID. Thereafter, in step <b>941</b>, the UE <b>110</b> transmits an authentication response message to the target MME <b>114</b>.
0074<figref idref="DRAWINGS">FIG. 10</figref> is a flowchart illustrating an operation of an MME for supporting an SMC process during a handover between PLMNs according to an exemplary embodiment of the present invention.
0075Referring to <figref idref="DRAWINGS">FIG. 10</figref>, in step <b>1001</b>, the target MME <b>114</b> performs a handover preparation process. Step <b>1001</b> is identical to the handover preparation step <b>201</b>, so a detailed description thereof will be omitted here. In step <b>1003</b>, the target MME <b>114</b> performs a process before receiving a TAU request message among the entire handover process. In step <b>1005</b>, the target MME <b>114</b> determines the serving network identity (i.e., PLMN identity) through various comparisons, for example, by comparing the PLMN ID of the target MME <b>114</b> with a PLMN ID within an old GUTI of the TAU message transmitted from the UE <b>110</b> or by comparing the PLMN ID of the target MME <b>114</b> with a PLMN ID of a last-visited TAI within the TAU message transmitted from the UE <b>110</b>. When the PLMN IDs are different, one solution is that the target MME <b>114</b> does not send an SMC message to the UE <b>110</b> until the processing of the TAU message is completed as in step <b>1011</b>. Another solution (e.g., case 1) is that, when the MME <b>114</b> has acquired a new authentication key (K<sub>ASME</sub>) through a new authentication, the target MME <b>114</b> generates a NAS encryption key and a NAS integrity key as in step <b>1021</b>. Then, in step <b>1025</b>, the target MME <b>114</b> sends a NAS SMC message together with a serving network ID (i.e., PLMN ID) to the UE <b>110</b>. Then, in step <b>1041</b>, the target MME <b>114</b> receives a security mode completion message from the UE <b>110</b>.
0076<figref idref="DRAWINGS">FIG. 11</figref> is a flowchart illustrating an operation of a UE for supporting an SMC process during a handover between PLMNs according to an exemplary embodiment of the present invention.
0077Referring to <figref idref="DRAWINGS">FIG. 11</figref>, in step <b>1101</b>, the UE <b>110</b> performs a handover preparation process. Step <b>1101</b> is identical to the handover preparation step <b>201</b>, so a detailed description thereof will be omitted here. In step <b>1103</b>, the UE <b>110</b> performs a process before sending a TAU request message among the entire handover process. In step <b>1125</b>, the UE <b>110</b> receives an SMC message including a serving network ID (i.e., PLMN ID) from the target MME <b>114</b>. Then, in step <b>1131</b>, the UE <b>110</b> generates a NAS encryption key and a NAS integrity key based on an authentication key indexed by an eKSI, wherein the UE <b>110</b> finds an eKSI corresponding to the newly received PLMN ID. In step <b>1133</b>, the UE <b>110</b> verifies a Message Authentication Code (MAC) by using the NAS integrity key. Thereafter, in step <b>1141</b>, the UE <b>110</b> transmits a security mode completion message to the target MME <b>114</b>.
0078According to exemplary embodiments of the present invention, as described above with reference to <figref idref="DRAWINGS">FIGS. 4 to 11</figref>, it may be necessary to support messages shown in Tables 1 to 3 for operations of the UE and the MME, which will be described hereinafter.
0079Table 1 below shows types of authentication request messages according to exemplary embodiments of the present invention. Although the message types shown in Table 1 are used when the messages are transmitted from the target MME <b>114</b> to the UE <b>110</b> as in step <b>441</b> of <figref idref="DRAWINGS">FIG. 4</figref>, exemplary embodiments of the present invention are not limited to the shown message types. Detailed information on the PLMN IDs of Table 1 can be referred to Table 3.
0080<tables id="TABLE-US-00001" num="00001"><table frame="none" colsep="0" rowsep="0"><tgroup align="left" colsep="0" rowsep="0" cols="6"><colspec colname="1" colwidth="14pt" align="left" /><colspec colname="2" colwidth="56pt" align="left" /><colspec colname="3" colwidth="70pt" align="left" /><colspec colname="4" colwidth="28pt" align="center" /><colspec colname="5" colwidth="28pt" align="center" /><colspec colname="6" colwidth="21pt" align="center" /><thead><row><entry namest="1" nameend="6" rowsep="1">TABLE 1</entry></row><row><entry namest="1" nameend="6" align="center" rowsep="1" /></row><row><entry /><entry>Information</entry><entry /><entry /><entry /><entry /></row><row><entry>IEI</entry><entry>element</entry><entry>Type/Reference</entry><entry>Presence</entry><entry>Format</entry><entry>Length</entry></row><row><entry namest="1" nameend="6" align="center" rowsep="1" /></row></thead><tbody valign="top"><row><entry /><entry>Protocol </entry><entry>Protocol discriminator</entry><entry>M</entry><entry>V</entry><entry>½</entry></row><row><entry /><entry>discriminator</entry><entry>9.2</entry><entry /><entry /><entry /></row><row><entry /><entry>Security header</entry><entry>Security header type</entry><entry>M</entry><entry>V</entry><entry>½</entry></row><row><entry /><entry>type</entry><entry>9.3.1</entry><entry /><entry /><entry /></row><row><entry /><entry>Authentication</entry><entry>Message type</entry><entry>M</entry><entry>V</entry><entry>1</entry></row><row><entry /><entry>request message </entry><entry>9.8</entry><entry /><entry /><entry /></row><row><entry /><entry>type</entry><entry /><entry /><entry /><entry /></row><row><entry /><entry>NAS key set</entry><entry>NAS key set identifier</entry><entry>M</entry><entry>V</entry><entry>½</entry></row><row><entry /><entry>identifier<sub>ASME</sub></entry><entry>9.9.3.21</entry><entry /><entry /><entry /></row><row><entry /><entry>Spare half octet</entry><entry>Spare half octet</entry><entry>M</entry><entry>V</entry><entry>½</entry></row><row><entry /><entry /><entry>9.9.2.9</entry><entry /><entry /><entry /></row><row><entry /><entry>Authentication</entry><entry>Authentication</entry><entry>M</entry><entry>V</entry><entry>16</entry></row><row><entry /><entry>parameter RAND </entry><entry>parameter RAND</entry><entry /><entry /><entry /></row><row><entry /><entry>(EPS challenge)</entry><entry>9.9.3.3</entry><entry /><entry /><entry /></row><row><entry /><entry>Authentication </entry><entry>Authentication</entry><entry>M</entry><entry>LV</entry><entry>17</entry></row><row><entry /><entry>parameter AUTN </entry><entry>parameter AUTN</entry><entry /><entry /><entry /></row><row><entry /><entry>(EPS challenge)</entry><entry>9.9.3.2</entry><entry /><entry /><entry /></row><row><entry /><entry>PLMN Identity</entry><entry>PLMN identity</entry><entry>O</entry><entry>V</entry><entry> 3</entry></row><row><entry /><entry /><entry>x.x.x.x (spec section</entry><entry /><entry /><entry /></row><row><entry /><entry /><entry>number)</entry></row><row><entry namest="1" nameend="6" align="center" rowsep="1" /></row></tbody></tgroup></table></tables>
0081Table 2 below shows types of SMC messages according to exemplary embodiments of the present invention. Although the message types shown in Table 2 are used when the messages are transmitted from the target MME <b>114</b> to the UE <b>110</b> as in step <b>641</b> of <figref idref="DRAWINGS">FIG. 6</figref>, exemplary embodiments of the present invention are not limited to the shown message types. Detailed information on the PLMN IDs of Table 2 can be referred to Table 3.
0082<tables id="TABLE-US-00002" num="00002"><table frame="none" colsep="0" rowsep="0"><tgroup align="left" colsep="0" rowsep="0" cols="6"><colspec colname="1" colwidth="14pt" align="left" /><colspec colname="2" colwidth="56pt" align="left" /><colspec colname="3" colwidth="70pt" align="left" /><colspec colname="4" colwidth="28pt" align="center" /><colspec colname="5" colwidth="28pt" align="center" /><colspec colname="6" colwidth="21pt" align="center" /><thead><row><entry namest="1" nameend="6" rowsep="1">TABLE 2</entry></row><row><entry namest="1" nameend="6" align="center" rowsep="1" /></row><row><entry /><entry>Information</entry><entry /><entry /><entry /><entry /></row><row><entry>IEI</entry><entry>Element</entry><entry>Type/Reference</entry><entry>Presence</entry><entry>Format</entry><entry>Length</entry></row><row><entry namest="1" nameend="6" align="center" rowsep="1" /></row></thead><tbody valign="top"><row><entry /><entry>Protocol </entry><entry>Protocol discriminator</entry><entry>M</entry><entry>V</entry><entry>½</entry></row><row><entry /><entry>discriminator</entry><entry>9.2</entry><entry /><entry /><entry /></row><row><entry /><entry>Security header </entry><entry>Security header type</entry><entry>M</entry><entry>V</entry><entry>½</entry></row><row><entry /><entry>type</entry><entry>9.3.1</entry><entry /><entry /><entry /></row><row><entry /><entry>Security mode </entry><entry>Message type</entry><entry>M</entry><entry>V</entry><entry>1</entry></row><row><entry /><entry>command</entry><entry>9.8</entry><entry /><entry /><entry /></row><row><entry /><entry>message identity</entry><entry /><entry /><entry /><entry /></row><row><entry /><entry>Selected NAS </entry><entry>NAS security</entry><entry>M</entry><entry>V</entry><entry>1</entry></row><row><entry /><entry>security</entry><entry>algorithms</entry><entry /><entry /><entry /></row><row><entry /><entry>algorithms</entry><entry>9.9.3.23</entry><entry /><entry /><entry /></row><row><entry /><entry>NAS key set </entry><entry>NAS key set identifier</entry><entry>M</entry><entry>V</entry><entry>½</entry></row><row><entry /><entry>identifier</entry><entry>9.9.3.21</entry><entry /><entry /><entry /></row><row><entry /><entry>Spare half octet</entry><entry>Spare half octet</entry><entry>M</entry><entry>V</entry><entry>½</entry></row><row><entry /><entry /><entry>9.9.2.9</entry><entry /><entry /><entry /></row><row><entry /><entry>Replayed UE </entry><entry>UE security capability</entry><entry>M</entry><entry>LV</entry><entry>3-6</entry></row><row><entry /><entry>security</entry><entry>9.9.3.36</entry><entry /><entry /><entry /></row><row><entry /><entry>capabilities</entry><entry /><entry /><entry /><entry /></row><row><entry>C-</entry><entry>IMEISV </entry><entry>IMEISV request</entry><entry>O</entry><entry>TV</entry><entry>1</entry></row><row><entry /><entry>request</entry><entry>9.9.3.18</entry><entry /><entry /><entry /></row><row><entry>55</entry><entry>Replayed </entry><entry>Nonce</entry><entry>O</entry><entry>TV</entry><entry>5</entry></row><row><entry /><entry>nonce<sub>UE</sub></entry><entry>9.9.3.25</entry><entry /><entry /><entry /></row><row><entry>56</entry><entry>Nonce<sub>MME</sub></entry><entry>Nonce</entry><entry>O</entry><entry>TV</entry><entry>5</entry></row><row><entry /><entry /><entry>9.9.3.25</entry><entry /><entry /><entry /></row><row><entry /><entry>PLMN </entry><entry>PLMN identity</entry><entry>O</entry><entry>V</entry><entry>3</entry></row><row><entry /><entry>Identity</entry><entry>x.x.x.x</entry></row><row><entry namest="1" nameend="6" align="center" rowsep="1" /></row></tbody></tgroup></table></tables>
0083Table 3 below shows PLMN ID Information Elements (IEs) included in the authentication request message or the SMC message of Tables 1 and 2 according to exemplary embodiments of the present invention, which correspond to IEs for notifying of information to be included in order to send the PLMN identities to the UE <b>110</b>. Further, the PLMN ID IEs are not limited to the message types shown in Table 3. The PLMN ID IEs are IEs of type 3 and have a length of 4 octets. The MCC indicates a Mobile Country Code, in which octet 2 and octet 3 are configured in bits 1 to 4, and the MNC indicates a Mobile Network Code, in which octet 4 and octet 3 are configured in bits 5 to 8.
0084<tables id="TABLE-US-00003" num="00003"><table frame="none" colsep="0" rowsep="0"><tgroup align="left" colsep="0" rowsep="0" cols="9"><colspec colname="1" colwidth="21pt" align="center" /><colspec colname="2" colwidth="21pt" align="center" /><colspec colname="3" colwidth="21pt" align="center" /><colspec colname="4" colwidth="21pt" align="center" /><colspec colname="5" colwidth="21pt" align="center" /><colspec colname="6" colwidth="21pt" align="center" /><colspec colname="7" colwidth="21pt" align="center" /><colspec colname="8" colwidth="21pt" align="center" /><colspec colname="9" colwidth="49pt" align="left" /><thead><row><entry namest="1" nameend="9" rowsep="1">TABLE 3</entry></row><row><entry namest="1" nameend="9" align="center" rowsep="1" /></row></thead><tbody valign="top"><row><entry>8</entry><entry>7</entry><entry>6</entry><entry>5</entry><entry>4</entry><entry>3</entry><entry>2</entry><entry>1</entry><entry /></row></tbody></tgroup><tgroup align="left" colsep="0" rowsep="0" cols="2"><colspec colname="1" colwidth="168pt" align="center" /><colspec colname="2" colwidth="49pt" align="left" /><tbody valign="top"><row><entry>PLMN identity IEI</entry><entry>octet 1</entry></row></tbody></tgroup><tgroup align="left" colsep="0" rowsep="0" cols="3"><colspec colname="1" colwidth="84pt" align="center" /><colspec colname="2" colwidth="84pt" align="center" /><colspec colname="3" colwidth="49pt" align="left" /><tbody valign="top"><row><entry>MCC digit 2</entry><entry>MCC digit 1</entry><entry>octet 2</entry></row><row><entry>MNC digit 3</entry><entry>MCC digit 3</entry><entry>octet 3</entry></row><row><entry>MNC digit 2</entry><entry>MNC digit 1</entry><entry>octet 4</entry></row></tbody></tgroup><tgroup align="left" colsep="0" rowsep="0" cols="2"><colspec colname="1" colwidth="21pt" align="left" /><colspec colname="2" colwidth="196pt" align="left" /><tbody valign="top"><row><entry /><entry>MCC, Mobile country code (octet 3, octet 4 bits 1 to 4)</entry></row><row><entry /><entry>The MCC field is coded as in ITU-T Rec. E212, Annex A.</entry></row><row><entry /><entry>MNC, Mobile network code (octet 5, octet 4 bits 5 to 8).</entry></row><row><entry /><entry>The coding of this field is the responsibility of each</entry></row><row><entry /><entry>administration but BCD coding shall be used. The MNC shall</entry></row><row><entry /><entry>consist of 2 or 3 digits. For PCS 1900 for NA, Federal</entry></row><row><entry /><entry>regulation mandates that a 3-digit MNC shall be used. However</entry></row><row><entry /><entry>a network operator may decide to use only two digits in the</entry></row><row><entry /><entry>MNC over the radio interface. In this case, bits 5 to 8 of octet 4</entry></row><row><entry /><entry>shall be coded as “1111”. Mobile equipment shall accept MNC</entry></row><row><entry /><entry>coded in such a way.</entry></row><row><entry namest="1" nameend="2" align="center" rowsep="1" /></row></tbody></tgroup></table></tables>
0085In a mobile communication network according to exemplary embodiments of the present invention, when a UE performs a handover between PLMNs, especially when a UE performs a handover from a EUTRAN or another RAT (e.g., such as GETRAN or UTRAN) to another EUTRAN, it is possible to resolve problems associated with the authentication and security of the UE, thereby preventing interruption of communication.
0086Further, exemplary embodiments of the present invention propose a method capable of smoothly performing an authentication of a UE and a security mode command for the UE even during a handover of the UE between PLMNs by using a NAS protocol, so as to achieve an efficient mobility management of the UE.
0087While the invention has been shown and described with reference to certain exemplary embodiments thereof, it will be understood by those skilled in the art that various changes in form and details may be made therein without departing from the spirit and scope of the invention as defined by the appended claims and their equivalents.
Contents5
13 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP1860904A1 | Cites | European Patent Office (EPO) | Applicant |
| WO2008054668A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| US2008267407A1 | Cites | United States of America | Applicant |
| US2009061878A1 | Cites | United States of America | Applicant |
| US2009305699A1 | Cites | United States of America | Applicant |
| US2010054472A1 | Cites | United States of America | Applicant |
| US2010081435A1 | Cites | United States of America | Applicant |
| EP2018083A1 | Cites | European Patent Office (EPO) | Applicant |
| US8144877B2 | Cites | United States of America | Applicant |
| US20080267407A1 | Cites | United States of America | Applicant |
| US20090061878A1 | Cites | United States of America | Applicant |
| US20090305699A1 | Cites | United States of America | Applicant |
| US20100054472A1 | Cites | United States of America | Applicant |
| US20100081435A1 | Cites | United States of America | Applicant |
| EP1860904A1 | Cites | European Patent Office (EPO) | Applicant |
| EP2018083A1 | Cites | European Patent Office (EPO) | Applicant |
| WO2008054668A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| Myungseok Song; Jae-Young Choi; Jun-dong Cho; Jongpil Jeong; Byung-Hun Song; Hyungsu Lee; “Reduction of authentication cost based on key caching for inter-MME handover support”; High Performance Computing & Simulation (HPCS), 2014 International Conference on Year: Apr. 2014; pp. 885-892. | Non-patent | – | Search report |
| Mitjana et al., “Background Scan Mechanism whereby PLMN is able to instruct a capable mobile terminal to perform regular attempts”; Siemens AG; IPCOM000125707D; Jul. 2005; pp. 1-2. | Non-patent | – | Applicant |
| Jeong et al., “HIMALIS-C-ITS: Fast and secure mobility management scheme based on HIMALIS for cooperative ITS service in future networks”, Ubiquitous and Future Networks (ICUFN), 2013 Fifth International Conference on year, Jan. 2013, pp. 60-65. | Non-patent | – | Applicant |
| Myungseok Song; Jae-Young Choi; Jun-dong Cho; Jongpil Jeong; Byung-Hun Song; Hyungsu Lee; "Reduction of authentication cost based on key caching for inter-MME handover support"; High Performance Computing & Simulation (HPCS), 2014 International Conference on Year: Apr. 2014; pp. 885-892. | Non-patent | – | Search report |
| Mitjana et al., "Background Scan Mechanism whereby PLMN is able to instruct a capable mobile terminal to perform regular attempts"; Siemens AG; IPCOM000125707D; Jul. 2005; pp. 1-2. | Non-patent | – | Applicant |
| Jeong et al., "HIMALIS-C-ITS: Fast and secure mobility management scheme based on HIMALIS for cooperative ITS service in future networks", Ubiquitous and Future Networks (ICUFN), 2013 Fifth International Conference on year, Jan. 2013, pp. 60-65. | Non-patent | – | Applicant |
26 members in 3 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 1020090102501 | Republic of Korea | – | |
| 20090102501 | Republic of Korea | A | |
| 2010007430 | Republic of Korea | W | |
| 201213504786 | United States of America | A | |
| 201414532421 | United States of America | A | |
| 201514844737 | United States of America | A |
Members26
| Document | Office | Kind | |
|---|---|---|---|
| KR20110045796A | Republic of Korea | A | |
| WO2011052995A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2011052995A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2012210397A1 | United States of America | A1 | |
| US8881237B2 | United States of America | B2 | |
| US2015056959A1 | United States of America | A1 | |
| US9131380B2 | United States of America | B2 | |
| US2015382253A1 | United States of America | A1 | |
| US2016029256A1 | United States of America | A1 | |
| US2016029257A1 | United States of America | A1 | |
| US2016029258A1 | United States of America | A1 | |
| US2016029259A1 | United States of America | A1 | |
| US2016029260A1 | United States of America | A1 | |
| US2016037391A1 | United States of America | A1 | |
| US2016037392A1 | United States of America | A1 | |
| US2016037393A1 | United States of America | A1 | |
| US9264949B1 | United States of America | B1 | |
| US9271200B2 | United States of America | B2 | |
| US9271201B2This record | United States of America | B2 | |
| US9277463B2 | United States of America | B2 | |
| US9282490B2 | United States of America | B2 | |
| US9357443B2 | United States of America | B2 | |
| US9357444B2 | United States of America | B2 | |
| US9392502B2 | United States of America | B2 | |
| US9392503B2 | United States of America | B2 | |
| KR101700448B1 | Republic of Korea | B1 |
47 transactions on the USPTO file
Allowed without a rejection on record.
- Non-final rejections
- 0
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Payment of Maintenance Fee, 8th Year, Large EntityM1552 | M1552 | |
| Payment of Maintenance Fee, 4th Year, Large EntityM1551 | M1551 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Email NotificationEML_NTR | EML_NTR | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Dispatch to FDCD1935 | D1935 | |
| Email NotificationEML_NTR | EML_NTR | |
| Printer Rush- No mailingTCPB | TCPB | |
| Mail Response to 312 Amendment (PTO-271)MN271 | MN271 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Response to Amendment under Rule 312N271 | N271 | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Amendment after Notice of Allowance (Rule 312)AllowedA.NA | A.NA | |
| Mail Post CardPST_CRD | PST_CRD | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Reasons for AllowanceEX.R | EX.R | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Priority document has successfully retrieved via PDX/DASPD.RECVD | PD.RECVD | |
| Request for Foreign Priority (Priority Papers May Be Included)RQPR | RQPR | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Paralegal or electronic terminal disclaimer approvedP574 | P574 | |
| Terminal Disclaimer FiledDIST | DIST | |
| Email NotificationEML_NTR | EML_NTR | |
| Application Is Now CompleteCOMP | COMP | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Sent to Classification ContractorPGPC | PGPC | |
| FITF set to NO - revise initial settingFTFI | FTFI | |
| Cleared by OIPE CSRL194 | L194 | |
| Miscellaneous Incoming LetterLET. | LET. | |
| Reference capture on IDSRCAP | RCAP | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Patent Term Adjustment - Ready for ExaminationPTA.RFE | PTA.RFE | |
| Applicants have given acceptable permission for participating foreignAPPERMS | APPERMS | |
| Request from applicant for the USPTO to retrieve the Priority DocumentPDREQUST | PDREQUST | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Entity Status Set To Undiscounted (Initial Default Setting or Status Change)BIG. | BIG. | |
| Initial Exam Team nnIEXX | IEXX |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Maintenance fee paymentMAFP | MAFP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP |
Numbers
- Publication
- 9271201
- Application
- 14876489
Titles
- English
- Method and system for managing security in mobile communication system
Patent term adjustment
- Applicant delay
- −22 days
- Net adjustment
- 0 days
Classification
- CPC, 11
- H04W36/0038
- H04W12/04
- H04W76/11
- H04W12/06
- H04W36/0005
- H04W76/021
- H04W84/042
- H04W12/062
- H04W60/00
- H04W36/0016
- H04W36/12
- IPC, 7
- G06F21 00
- H04L29 06
- H04W36 00
- H04W12 06
- H04W76 02
- H04W60 00
- H04W84 04