System and method for wireless network access protection and security architecture
By introducing wireless network-specific keys (WN-specific keys) into the wireless network, the problem of frequent transmission of UE-specific keys in intensive deployment environments in traditional technology is solved, and more efficient mobile device authentication and access protection is achieved.
Patent Information
- Application Number
- CN202010813750.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2014-07-03
- Filing Date
- 2015-07-02
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2035-07-02
AI Technical Summary
In dense deployment environments, UE-specific keys are repeatedly transmitted between wireless networks in traditional wireless networks, resulting in increased latency and overhead, making it difficult to quickly and effectively authenticate mobile devices.
A wireless network-specific key (WN-specific key) is adopted, which is assigned to the wireless network and is used when establishing a wireless connection between the base station and the user equipment, reducing the key exchange frequency and does not need to transmit a WN-specific key during handover.
Through WN-specific keys, the frequency of key exchange is reduced, mobile device authentication efficiency is improved in intensive deployment environments, and latency and overhead are reduced.
Smart Images

Figure CN112105016B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a system and method for wireless communication, and in a specific embodiment, to a system and method for wireless network access protection and security architecture. Background Art
[0002] Wireless networks often use access keys to ensure that only valid users are allowed to access the wireless network. In traditional 3G / 4G wireless networks, after UE authentication / authorization, the mobility management entity (MME) distributes user equipment (UE)-specific key material to the packet data network (PDN) gateway (PGW) and user equipment (UE) in the evolved packet core (EPC), and the user equipment-specific key material is used to encrypt data communications on the bearer channel extending between the UE and the PGW. In particular, UE-specific key material, or UE-specific key (abbreviated), is transmitted between wireless networks during switching. Transmitting UE-specific keys in dense deployment environments where switching is more frequent may be problematic because repeatedly transmitting key material between wireless networks significantly increases the delay and overhead associated with UE mobility. Therefore, a technology that can quickly and effectively authenticate UEs in dense deployment environments is needed. Summary of the invention
[0003] Technical advantages are generally achieved by the present disclosure describing embodiments of a "wireless network access protection and security architecture."
[0004] According to one embodiment, a method for wireless network access protection is provided. In this example, the method includes a base station obtaining a wireless network (WN)-specific key, and the wireless network (WN)-specific key is assigned to the wireless network. The base station belongs to the wireless network. The method further includes: establishing a wireless connection between the base station and a user equipment (UE), and receiving encrypted data from the UE on the wireless connection. The encrypted data has a first layer of encryption and a second layer of encryption. The method further includes: decrypting the first layer of encryption using a WN-specific key to obtain partially decrypted data; and forwarding the partially decrypted data to a gateway in the WN. A device for performing the method is also provided.
[0005] According to another embodiment, a method for distributing keys in a wireless network is provided. In this example, the method includes generating a wireless network (WN) specific key at a WN key controller. The WN specific key is assigned to a first wireless network. The method further includes: distributing the WN specific key to a base station in the first wireless network for providing access protection on a wireless access interface established between the base station and a user equipment (UE) accessing the wireless network. A device for performing the method is also provided.
[0006] According to yet another embodiment, a key management architecture is provided. In this example, the key management architecture includes: a wireless network (WN) protection controller, adapted to obtain a user equipment (UE) specific key, the user equipment (UE) specific key being assigned to a UE accessing the wireless network, and adapted to distribute the UE specific key to a serving gateway (SGW) in the wireless network. The UE specific key is adapted to provide access protection on a bearer channel extending between the UE and the SGW.
[0007] According to yet another embodiment, a method for authenticating a mobile device is provided. In this example, the method includes: receiving a UE-specific key at a WN protection controller, the WN protection controller being assigned to distribute the key throughout the wireless network. The method further includes: identifying a wireless network domain corresponding to a UE identifier specified by the UE-specific key; and distributing the UE-specific key to a serving gateway (SGW) in the wireless network domain. The UE-specific key is suitable for providing access protection on a bearer channel extending between the UE and the SGW. A device for performing the method is also provided.
[0008] According to yet another embodiment, a method for providing service-specific access protection is provided. In this example, the method includes: identifying a machine-to-machine (M2M) service associated with an M2M client; receiving a service-specific key assigned to the M2M service at an SGW; and receiving a packet from a network device. The packet is associated with the M2M service. The method further includes: attempting to decrypt the packet using the service-specific key; and when the attempt to decrypt the packet is unsuccessful, discarding the packet. A device for performing the method is also provided.
[0009] According to yet another embodiment, a method for group-specific access protection is provided. In this example, the method includes: identifying a private network, receiving a group-specific key assigned to the private network at an SGW, receiving a packet addressed to a network device belonging to the private network; and attempting to decrypt the packet using the group-specific key. The method further includes: when the attempt to decrypt the packet is unsuccessful, discarding the packet. A device for performing the method is also provided. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] For a more complete understanding of the present disclosure and its advantages, reference is now made to the following description taken in conjunction with the accompanying drawings, in which:
[0011] Figure 1 A schematic diagram showing an embodiment of a wireless network is shown;
[0012] Figure 2 A schematic diagram of a traditional wireless network security architecture is shown;
[0013] Figure 3 A schematic diagram showing an embodiment of a wireless network security architecture;
[0014] Figure 4 A schematic diagram showing an embodiment of a wireless network architecture for providing multi-level access protection is shown;
[0015] Figure 5 A schematic diagram illustrating an embodiment of a wireless network security architecture for managing network access keys;
[0016] Figure 6 A schematic diagram showing another embodiment of a wireless network security architecture for managing network access keys;
[0017] Figure 7 A schematic diagram showing an embodiment of a wireless network architecture for managing UE-specific key material;
[0018] Figure 8 A schematic diagram showing an embodiment of a network architecture for providing access protection for M2M services;
[0019] Fig. 9 A schematic diagram showing an embodiment of a wireless network architecture for managing service-specific key material;
[0020] Fig.10 A schematic diagram showing an embodiment of a network architecture for providing access protection for communications between members of a public group;
[0021] Fig.11 A schematic diagram showing an embodiment of a wireless network architecture for managing group-specific keying material;
[0022] Fig.12 A schematic diagram illustrating an embodiment of a computing platform; and
[0023] Fig.13 A schematic diagram of an embodiment of a communication device is shown.
[0024] Corresponding numerals and symbols in the different figures generally indicate corresponding parts unless otherwise indicated.The figures are drawn to clearly illustrate the relevant aspects of the embodiments and are not necessarily drawn to scale. DETAILED DESCRIPTION
[0025] The implementation and use of the embodiments of the present disclosure will be discussed in more detail below. However, it should be understood that the concepts disclosed herein can be embodied in a variety of specific contexts, and the specific embodiments discussed are merely illustrative and are not intended to limit the scope of the claims. It should be further understood that various changes, substitutions and modifications can be made without departing from the spirit and scope of the present disclosure as defined by the appended claims.
[0026] 3G / 4G wireless networks provide access protection to bearer channels extending from the UE to the Packet Data Network (PDN) Gateway (PGW) of the Evolved Packet Core (EPC) network using UE-specific keys. However, a separate level of access protection is not provided for the wireless connection extending between the UE and the RAN. In future network architectures, a radio access network may have an infrastructure provided by a first entity and telecommunication services provided by another entity on top of the infrastructure. In order to accommodate the growing demand for bandwidth, it is likely that future network deployments will include dense and ultra-dense network segments as part of the overall network. Therefore, a multi-level access network security framework suitable for densely deployed wireless networks is needed.
[0027] Various aspects of the present disclosure provide techniques for utilizing wireless network-specific (WN-specific) key material, or WN-specific keys (for short), to provide access protection on wireless access links. More specifically, WN-specific keys are associated (or assigned) to wireless networks and distributed to access points of the wireless network, as well as UEs after UE authentication. The WN-specific keys are then used to encrypt / decrypt data transmitted on the wireless access link. The WN-specific keys can be used in conjunction with UE-specific keys to provide multi-level access protection. In some embodiments, WN-specific keys are shared between adjacent wireless networks to reduce the frequency of key exchanges during handover. For example, public WN-specific keys can be pre-distributed to access points in adjacent wireless networks so that handovers occur between these adjacent wireless networks without exchanging WN-specific keys during handover. Aspects of the present disclosure also provide service-specific keys for providing access protection to machine-to-machine (M2M) services, and group-specific keys for providing access protection to service flows communicating between members of a public group, such as a private social network. A network security architecture for distributing UE-specific, WN-specific, service-specific, and group-specific keys is also provided. These and other details will be described in more detail below.
[0028] Figure 1A network 100 for communicating data is shown. The network 100 includes an access point (AP) 110 having a coverage area 101, a plurality of mobile devices 120, and a backhaul network 130. The AP 110 may include any component capable of providing wireless access, particularly by establishing an uplink (dashed line) and / or downlink (dash-dot line) connection with the mobile device 120, such as a base station, an enhanced base station (eNB), a femtocell, and other wirelessly enabled devices. The mobile device 120 may include any component capable of establishing a wireless connection with the AP 110, such as a user equipment (UE), a mobile station (STA), or other wirelessly enabled device. The backhaul network 130 may be any component or collection of components that enables data to be exchanged between the AP 110 and a remote end (not shown). In some embodiments, the network 100 may include various other wireless devices, such as relays, low-power nodes, etc.
[0029] Traditional 3G / 4G wireless networks use UE-specific keys to provide access protection to the bearer channels extending from the UE to the PGW of the EPC network, but do not provide a separate level of access protection for the wireless connection extending between the UE and the RAN. Figure 2 A conventional wireless network security architecture 200 providing single-layer access protection is shown. As shown, the conventional wireless network security architecture 200 includes a wireless network domain 210 providing wireless access to a UE 205. The wireless network domain 210 includes a base station 212, an SGW 214, a PGW 216, a mobility management entity (MME) 218, and a home security server (HHS) 220. A bearer channel is established between the UE 205 and the PGW 216 through the BS 212 and the SGW 214. The PGW 216 acts as a gateway between the wireless network domain 210 and the Internet 240.
[0030] When the bearer channel is established, the MME 218 authenticates the UE 205. Specifically, the authentication center 230 generates a shared key (e.g., a public private key access security management entity (KASME)) using a cipher key (CK) and an integrity key (IK) during UE authentication. Next, the authentication center 230 generates a set of keys and checksums using the shared key and a random number, and sends the generated keys, checksums, and random numbers to the MME 218. The MME 218 distributes the generated checksums and random numbers to the UE 205. The universal user identity module (USIM) in the UE 205 independently calculates a set of identical keys using the random number and shared key provided by the MME 218. Bidirectional authentication is performed by verifying the checksums calculated in the UE 205 and the EPC 218. Thereafter, the MME 218 distributes UE-specific keys to both the UE 205 and the PGW 216. The UE-specific keys are used to encrypt / decrypt data communicated on the bearer channel. For example, UE 205 may use a UE-specific key to encrypt data carried in an uplink transmission on a bearer channel, and PGW 216 may use the UE-specific key to attempt to decrypt the data received on the bearer channel. Once the data is decrypted, PGW 216 may forward the data to a remote destination via Internet 240. In some embodiments, MME 218 may send a public-private key pair to UE 205 and PGW 216. UE 205 and PGW 216 may use the public-private key pair to generate a UE-specific key. For example, UE 205 may unilaterally generate a UE-specific key, encrypt the UE-specific key using the public-private key pair, and then communicate the encrypted UE-specific key to PGW 216. As another example, PGW 216 may unilaterally generate a UE-specific key, encrypt the UE-specific key using the public-private key pair, and then communicate the encrypted UE-specific key to UE 205. As yet another example, the PGW 216 and the UE 205 may bilaterally generate UE-specific keys, such as through a key exchange protocol, and may encrypt messages exchanged during the key exchange protocol using a public-private key.
[0031] However, UE-specific keys can provide access protection to the bearer channel extending between the UE and the PGW, but do not provide protection for the wireless connection extending between the UE and the BS.Therefore, a multi-level access network security framework suitable for densely deployed wireless networks is needed.
[0032] Various aspects of the present disclosure provide a multi-layer access protection scheme that provides access protection to wireless access links using WN-specific keys in addition to providing access protection to bearer channels using UE-specific keys. Figure 3An embodiment of a wireless network security architecture 300 for providing multi-level access protection is shown. As shown, the wireless network security architecture 300 of the embodiment includes a wireless network domain 310 that provides wireless access to a UE 305. The wireless network domain 310 includes a base station 312 (also referred to as an access point 312), a serving gateway 314, a packet gateway 316, a WN key controller 322, a WN protection controller 324, and a key management entity 326.
[0033] UE-specific keys are used to encrypt / decrypt data communicated on a bearer channel extending between UE 305 and service gateway 314. Service gateway 314 may be a virtual service gateway, such as a virtual user-specific service gateway or a virtual service-specific service gateway. UE-specific keys may be distributed to service gateway 314 via WN protection controller 324, which may obtain UE-specific keys from key management entity 326. In one embodiment, key management entity 326 is a third-party management entity operated by a third-party administrator that is independent and distinct from the operator of the wireless network. Key management entity 326 may derive UE-specific keys using information provided by authentication center 330. WN protection controller 324 may have multiple responsibilities. For example, WN protection controller 324 may maintain key materials such as UE-specific keys, service-specific keys, group-specific keys, backhaul (BH) keys, etc. WN protection controller 324 may also manage network-node / device authentication and coordinate key synchronization with other controllers in other wireless network domains.
[0034] The WN-specific key is used to encrypt / decrypt data communicated over the wireless connection extending between the UE 305 and the access point 312. The WN-specific key may be distributed to the access point 312 before the UE 305 establishes a wireless link connection. The WN-specific key may be sent to the UE 305 after the UE is authenticated. The WN-specific key may be exclusively assigned to the wireless network domain 310. Alternatively, the WN-specific key may be assigned to a group or cluster of wireless network domains to which the wireless network domain 310 belongs.
[0035] Figure 4 An embodiment of a wireless network architecture 400 for providing multi-level access protection is shown. As shown, the wireless network architecture 400 of the embodiment includes a radio access network 410, an evolved packet core (EPC) 420, and a virtual network 430. The RAN 410 includes an access point 412 adapted to provide wireless access to a UE 405. The EPC 420 specifically includes a gateway adapted to act as a gateway between the EPC 420 and the RAN 410, such as a serving gateway (SGW) 414, and a packet data network (PDN) gateway (PGW) 416 adapted to act as a gateway between the EPC 420 and the Internet 450. The EPC 420 may include other components ( Figure 4 The EPC 420 may include a plurality of distributed EPCs, in which case some components (eg, SGW) may be placed in the distributed EPCs.
[0036] In particular, the RAN 410 and the EPC 420 together form a wireless network that provides a bearer path 451 between the UE 405 and the Internet 450. The bearer path 451 can carry a traffic flow communicated between the UE 405 and the remote end 490, and can include multiple interfaces and / or segments. In this example, the bearer path 451 includes a wireless connection 415 extending between the UE 405 and the access point 412 (e.g., a "UU interface"), a bearer channel 424 extending between the access point 412 and the SGW 414 (e.g., an "S1-U interface"), and a bearer channel 426 extending between the SGW 414 and the PGW 416 (e.g., an "S5 interface"). In some embodiments, the physical topology of the wireless network formed by the RAN 410 and the EPC 420 can be mapped to a virtual topology using the virtual network 430. In these embodiments, the bearer path 451 can correspond to a virtual path 452 extending through the virtual network 430.
[0037] As shown, the wireless network architecture 400 of the embodiment provides multi-level access protection along the bearer path 451. Specifically, the WN-specific key is suitable for providing access protection on the wireless connection 415, and the UE-specific key is suitable for providing access protection on the bearer channel 424 and / or the bearer channel 426. In some embodiments, end-to-end protection can also be provided using customer privacy information. In addition, virtual network protection can be provided using virtual network-specific (VN-specific) key material or VN-specific keys (abbreviated). Although the wireless network architecture 400 is described as providing multi-level access protection, aspects of the present disclosure are not limited to this. For example, the wireless network 400 may be suitable for providing a single-level access protection, such as by using WN-specific keys to encrypt / decrypt data communicated on the wireless connection 415 without using UE-specific key information. This provides a more efficient handover because the handover can occur without exchanging any keys.
[0038] Figure 5An embodiment of a wireless network security architecture 500 for managing network access keys in a wireless network domain 510 is shown. As shown, the wireless network domain 510 includes a plurality of wireless nodes 515 and a wireless network access link protection key controller 509 or WN key controller 509 (for short). The WN key controller 509 sends WN-specific keys to local wireless nodes 515. The wireless node 515 distributes the WN-specific keys to the UE 505 after UE authentication, and thereafter, the WN-specific keys are used to encrypt / decrypt data communicated on the wireless access link. In one embodiment, the WN-specific keys are synchronized on the plurality of wireless nodes 515 so that the UE 505 can be switched between the plurality of wireless nodes 515 without transmitting the WN-specific keys during the switching. The plurality of wireless nodes 515 can be managed by the same network operator.
[0039] Figure 6 An embodiment of a wireless network security architecture 600 for managing network access keys across multiple wireless network domains 610, 620 is shown. The wireless network domains 610, 620 may be managed by the same or different operators and may include wireless nodes 615, 625 adapted to provide wireless access to UEs 605, 606. Prior to wireless connection establishment, a key controller 609 distributes WN-specific keys to the wireless nodes 615, 625. After UE authentication, the wireless nodes 615, 625 distribute WN-specific keys to the UEs 605, 606. The WN-specific keys are shared between the wireless network domains 610, 620 so that inter-domain handovers can be performed without transmitting the WN-specific keys during handover.
[0040] Various aspects of the present disclosure provide a secure architecture for managing UE-specific keys. Figure 7 An embodiment of a wireless network architecture 700 for managing UE-specific key material between wireless network domains 710, 720 is shown. As shown, the network architecture 700 includes UE-specific SGWs 714, 724 located in respective wireless network domains 710, 720, WN protection controllers 718, 728 associated with respective wireless network domains 710, 720, a key management entity 736, and an authentication center 740.
[0041] The management of UE-specific key material in the wireless network architecture 700 is described in a sequence of eight steps that can be triggered when the UE 705 initiates the link establishment process. In the first step (1), the UE 705 is authorized and authenticated by the authentication center 740. In some embodiments, the authentication center 740 includes a global entity responsible for various UE-specific tasks such as UE-specific naming, authentication, authorization and / or billing centers. In other embodiments, the authentication center 740 includes a control center of the home network of the UE 705.
[0042] During the second step (2), the authentication center 740 provides the UE-specific key or material for deriving the UE-specific key to the key management entity 736. Next, the key management entity provides the UE-specific key to the WN protection controller 718 during the third step (3). The WN protection controller 718 distributes the UE-specific key to the UE-specific SGW 714 during the fourth step (4) and distributes the UE-specific key to the UE 705 during the fifth step (5).
[0043] During the sixth step, UE 705 moves from wireless network domain 710 to wireless network domain 720, thereby triggering a handover. As a result of the handover, during a seventh step (7), a UE-specific key is transferred from WN protection controller 718 to WN protection controller 728. WN protection controller 728 is responsible for key distribution in the second wireless domain 720 and distributes the UE-specific key to the UE-specific SGW during an eighth step (8).
[0044] Various aspects of the present disclosure provide service-specific keys suitable for providing access protection for traffic flows related to machine-to-machine (M2M) traffic. Figure 8 An embodiment of a network architecture 800 for providing access protection for M2M service-related traffic flows transmitted over multiple network domains 801, 802, 803 is shown. In this example, a first M2M service is registered to an M2M client 810, and a second M2M service is registered to an M2M client 820. The M2M-related traffic flows may be encrypted / decrypted using traffic-specific key information. For example, before communicating the traffic flow to the M2M service client 810, machines 811, 812 may encrypt data using a first traffic-specific key, and before communicating the traffic flow to the M2M service client 820, machines 821, 822 may encrypt data using a second traffic-specific key.
[0045] M2M service-related traffic flows may be filtered at different network locations. For example, a network with a relatively stable topology (e.g., machines are not frequently added / removed) may perform traffic flow filtering at the edge of the network, such as on respective machines and M2M clients. Other networks may filter M2M service-related traffic flows at one of the gateways 831-833 in the network domains 801-803. For example, filtering may be performed at a service-specific gateway, such as a virtual service-specific SGW. Filtering may also be performed by a PGW or a gateway in a virtual network domain. An entity filtering M2M-related traffic flows may attempt to decrypt packets in the traffic flow using corresponding service-specific keys, and then discard any packets that the entity cannot successfully decrypt.
[0046] Various aspects of the present disclosure provide an architecture for managing business-specific key material. Fig. 9 An embodiment of a wireless network architecture 900 for managing service-specific key materials in a network domain 910 is shown. As shown, the network architecture 900 includes a service-specific SGW 914 located in the network domain 910, a protection controller 918 associated with the network domain 910, a key management entity 936, an authentication center 940, and an M2M client 950.
[0047] The management of service-specific key material in the wireless network architecture 900 is described in a sequence of eight steps, which can be triggered when an M2M client 950 initiates M2M service registration. In the first step (1), the M2M client 950 is authorized and authenticated by the authentication center 940, which can be a global entity responsible for various M2M service-specific tasks or a control center in the home network of the M2M client 950.
[0048] During the second step (2), the authentication center 940 provides the service-specific key or material for deriving the service-specific key to the key management entity 936. Then during the third step (3), the key management entity provides the service-specific key to the protection controller 918, and during the fourth step (4), the protection controller 918 distributes the service-specific key to the service-specific SGW 914. During the fifth step (5), the machine 905 attempts to register as a participant in the M2M service, which may include sending a request specifying the service name to the service-specific SGW 914. The registration attempt may be triggered when the machine 905 is powered on or otherwise configured by the user. During the sixth step (6), the service request is forwarded from the service-specific SGW 914 to the M2M client 950, which may maintain security information for authenticating devices / machines that are allowed to participate in the M2M service. During a seventh step (7), the M2M client 950 notifies the protection controller 918 that the machine 905 has been authenticated, prompting the protection controller 918 to distribute a service-specific key to the machine 905 during an eighth step (8).
[0049] Various aspects of the present disclosure provide access protection to traffic flows communicated between members of a private social network using group-specific keys. Fig.10An embodiment of a network architecture 1000 for providing access protection to traffic flows communicated between members of a public group such as a private social network is shown. As shown, the network architecture 1000 of the embodiment includes wireless network domains 1010, 1020 for providing wireless access to wireless devices 1005, 1006, 1007 registered to a public network or group, such as a private social network / group. As shown, the wireless network domains 1010, 1020 include access points 1012, 1022 suitable for providing wireless access to wireless devices 1005, 1006, 1007, as well as service gateways 1014, 1024, and packet gateways 1016, 1026. In some embodiments, group-related traffic flows are transmitted to a remote end 1036 (e.g., an application server, etc.) via the Internet 1030. Group-related traffic flows can also be communicated between group members 1005, 1006, 1007. Members 1005, 1006, 1007 and remote end 1036 may use group-specific keys to encrypt / decrypt group-related traffic.
[0050] Fig.11 An embodiment of a wireless network architecture 1100 for managing group-specific keying material in a network domain 1110 is shown. As shown, the network architecture 1100 includes a group-specific SGW 1114 located in the network domain 1110, a protection controller 1118 associated with the network domain 1110, a key management entity 1136, and an authentication center 1150. The management of group-specific keying material in the wireless network architecture 1100 is described in a sequence of eight steps, which can be triggered when the group head device 1105 initiates a dedicated group / network registration.
[0051] In a first step (1), the head device 1105 is authorized and authenticated by the authentication center 1150. The authentication center 1150 can be a global entity responsible for various group-specific tasks, or a control center of the home network of the head device 1105. In a second step (2), the key management entity 1136 creates a group-specific key. Then in a third step (3), the key management entity 1136 provides the group-specific key to the WN protection controller 1118, and during a fourth step (4), the WN protection controller 1118 sends the group-specific key to the group-specific SGW 1114. During a fifth step (5), the group member 1106 attempts to register as a participant in the private network by sending a registration request to the authentication center 1150. In a sixth step, the authentication center 1150 forwards the request to the head device 1105 and in a seventh step sends an authentication confirmation to the WN protection controller 1118. In the eighth step (8), the WN protection controller 1118 sends a group-specific key to the group member 1106, after which the group-specific key is used to encrypt / decrypt group-related traffic flows.
[0052] Various aspects of the present disclosure provide several benefits. For example, the techniques of the embodiments may provide flexible protection schemes for wireless network access and reduce the amount of link protection material transmitted during switching. Embodiments may also provide unified security control and provide security control convergence at virtual user-specific SGWs, virtual service-specific SGWs, and / or group-specific SGWs. Various aspects of the present disclosure may provide access protection to wireless backhaul links and prevent malicious nodes from attacking customer service flows. In one embodiment, nodes in a wireless network domain may use backhaul (BH) keys to encrypt / decrypt communications on a wireless backhaul interface. The management of different types of keys may be performed independently of each other.
[0053] Various keys (e.g., UE-specific keys, WN-specific keys, etc.) may be used for encryption / decryption in either direction on the corresponding link, interface, or channel. For example, WN-specific keys may be used to perform encryption / decryption of uplink data communicated on the wireless access link, and to perform encryption / decryption of downlink data communicated on the wireless access link.
[0054] Various aspects of the present disclosure provide a method for wireless network access protection. The method includes: obtaining a wireless network (WN) specific key assigned to a wireless network, establishing a wireless interface between a base station and a user equipment (UE), and receiving encrypted data from the UE on the wireless interface. The encrypted data has at least a first layer of encryption and a second layer of encryption. The method further includes: partially decrypting the encrypted data using a WN specific key so as to remove the first layer of encryption from the encrypted data, thereby obtaining partially decrypted data including the second layer of encryption, and forwarding the partially decrypted data to a gateway in the WN. In some embodiments, the gateway includes a user-specific serving gateway (SGW). In some embodiments, the user-specific SGW is adapted to further decrypt the partially decrypted data using a UE-specific key so as to remove the second layer of encryption from the decrypted data. The UE-specific key may be different from the WN-specific key. In some embodiments, the user-specific SGW and the base station are co-located on the same network-side device. In other embodiments, the user-specific SGW and the base station are located on different network-side devices. In some embodiments, the method further includes: receiving a packet on the wireless interface, attempting to partially decrypt the packet using a WN specific key; and when the attempt to partially decrypt the packet is unsuccessful, discarding the packet. The method may further include: forwarding the packet to a user-specific SGW when the attempt to partially decrypt the packet is successful. The user-specific SGW is adapted to attempt to further decrypt the packet using a UE-specific key, and is adapted to discard the packet when the attempt to further decrypt the packet using the UE-specific key fails. In some embodiments, the first layer of encryption provides access protection for the wireless interface, and the second layer of encryption provides access protection for the bearer channel extending between the UE and the user-specific SGW. In some embodiments, WN-specific keys are distributed to a group of base stations in a wireless network so that switching occurs between base stations in the group of base stations without exchanging WN-specific keys during the switching. WN-specific keys are allocated to a group of wireless networks so that switching occurs between wireless networks in the group of wireless networks without exchanging WN-specific keys during the switching. A device for performing the method is also provided.
[0055] Various aspects of the present disclosure provide a method for distributing keys in a wireless network. In this example, the method includes: generating a wireless network (WN) specific key on a WN key controller. The WN specific key is distributed to a first wireless network. The method further includes: distributing the WN specific key to a base station in the first wireless network to provide access protection on a wireless access interface established between the base station and a user equipment (UE) accessing the wireless network. In some embodiments, the WN specific key is distributed to a group of wireless networks including at least the first wireless network and the second wireless network. In these embodiments, the method further includes: distributing the WN specific key to a base station in the second wireless network. In some embodiments, the method further includes: updating the WN specific key at the end of a first time period, and distributing the updated WN specific key to the base station in the first wireless network at the beginning of a second time period. During the first time period, the WN specific key provides access protection to the wireless access interface, and during the second time period, the updated WN specific key provides access protection to the wireless access interface. A device for performing the method is also provided. The WN specific key can be distributed to an access point to which the UE is not connected, alleviating the need to include key information during a base station to base station handover process. At the same time, if the UE traffic flow to the gateway is encrypted using a different key (eg, a UE-specific key), the UE traffic flow is still protected from intrusion before it is received by the gateway.
[0056] Various aspects of the present disclosure provide a key management architecture. In this example, the key management architecture includes: a wireless network (WN) protection controller, suitable for obtaining a user equipment (UE)-specific key assigned to a UE accessing a wireless network, and distributing the UE-specific key to a service gateway (SGW) in the wireless network. The UE-specific key is suitable for providing access protection for a bearer channel extending between the UE and the SGW. In some embodiments, the WN protection controller obtains the UE-specific key from a third-party key management entity. The third-party key management entity is operated by a third-party administrator who is independent and distinct from the operator of the wireless network. In some embodiments, the key management architecture also includes a WN key controller, suitable for generating WN-specific keys assigned to a wireless network, and distributing WN-specific keys to base stations in the wireless network. The WN-specific key can be independent and distinct from the UE-specific key. The WN-specific key is suitable for providing access protection for a wireless access interface established between a base station and a user equipment (UE) accessing the wireless network.
[0057] Various aspects of the present disclosure provide a method for authenticating a mobile device. In this example, the method includes: receiving a UE-specific key from a third-party key management entity at a WN protection controller, the WN protection controller being assigned to distribute the key throughout the wireless network. The third-party key management entity is operated by a third-party administrator that is different from the operator of the wireless network. The method further includes: identifying a wireless network domain corresponding to a UE identifier specified by the UE-specific key; and distributing the UE-specific key to a serving gateway (SGW) in the wireless network domain. The UE-specific key is suitable for providing access protection for a bearer channel extending between the UE and the SGW. In some embodiments, the SGW is a user-specific SGW. A device for performing the method is also provided.
[0058] Various aspects of the present disclosure provide a method for providing service-specific access protection. In this example, the method includes: identifying a machine-to-machine (M2M) service associated with an M2M client; receiving a service-specific key assigned to the M2M service at an SGW; and receiving a packet from a network device. The packet is related to the M2M service. The method further includes: attempting to decrypt the packet using a service-specific key; and discarding the packet when the attempt to decrypt the packet is unsuccessful. In some embodiments, the SGW is a service-specific SGW. In some embodiments, the method further includes: forwarding the decrypted packet to the M2M client when the attempt to decrypt the packet is successful. In some embodiments, a service-specific key is assigned to the M2M service, and the service-specific key is not specific to the network device. In some embodiments, after the M2M client authenticates the network device, the service-specific key is provided to the network device. A device for performing the method is also provided.
[0059] Various aspects of the present disclosure provide a method for group-specific access protection. In this example, the method includes: identifying a private network, receiving a group-specific key assigned to the private network at an SGW, receiving a packet addressed to a network device belonging to the private network, and attempting to decrypt the packet using the group-specific key. The method further includes: discarding the packet when the attempt to decrypt the packet is unsuccessful. In some embodiments, the SGW is a business-specific SGW. In some embodiments, the public group includes a private social network. In some embodiments, a key is assigned to the private network, and the key is not specific to any one individual network device. A device for performing the method is also provided.
[0060] Fig.12is a block diagram of a processing system that can be used to implement the devices and methods disclosed herein. A particular device may use all of the components shown, or only a subset of the components, and the level of integration may vary from device to device. In addition, a device may contain multiple instances of a component, for example, multiple processing units, processors, memories, transmitters, receivers, etc. A processing system may include a processing unit that is equipped with one or more input / output devices, for example, a speaker, a microphone, a mouse, a touch screen, a keypad, a keyboard, a printer, a display, etc. A processing unit may include a central processing unit (CPU), a memory, a mass storage device, a video adapter, and an I / O interface connected to a bus.
[0061] The bus may be one or more of any type of several bus architectures, including a memory bus or memory controller, a peripheral bus, a video bus, etc. The CPU may include any type of electronic data processor. The memory may include any type of non-transient system memory, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), read-only memory (ROM), or a combination thereof. In one embodiment, the memory may include a ROM used at boot time, and a DRAM used for program and data storage when executing a program.
[0062] The mass storage device may include any type of non-transitory storage device for storing data, programs, and other information and for making the data, programs, and other information accessible via a bus. The mass storage device may include, for example, one or more solid-state drives, hard disk drives, magnetic disk drives, optical disk drives, and the like.
[0063] Video adapter and I / O interface provide the interface that external input and output device is coupled to processing unit.As shown in the figure, the example of input and output device comprises the display that is coupled to video adapter, and the mouse / keyboard / printer that is coupled to I / O interface.Other equipment can be coupled to processing unit, and can use additional or less interface card.For example, can use the serial interface such as universal serial bus (USB) (not shown) to provide interface for printer.
[0064] The processing unit also includes one or more network interfaces, which may include wired connections such as Ethernet cables, and / or wireless connections to access nodes or different networks. The network interface enables the processing unit to communicate with the remote unit via a network. For example, the network interface may provide wireless communication via one or more transmitters / transmit antennas and one or more receivers / receive antennas. In one embodiment, the processing unit is coupled to a local area network or a wide area network for data processing and communication with remote devices, such as other processing units, the Internet, remote storage facilities, etc.
[0065] Fig.13 1 is a block diagram of an embodiment of a communication device 1300, which is equivalent to one or more devices (eg, UE, eNB, controller, etc.) as described above. The communication device 1300 may include a device that may (or may not) be configured in accordance with Fig.13 The arrangement shown is a processor 1304, a memory 1306, and a plurality of interfaces 1310, 1312, 1314. The processor 1304 may be any component capable of performing computations and / or other processing-related tasks, and the memory 1306 may be any component capable of storing programs and / or instructions for the processor 1304. The interfaces 1310, 1312, 1314 may be any component or collection of components that enable the communication device 1300 to communicate with other devices.
[0066] Although the present invention has been described in detail, it should be understood that various changes, substitutions and modifications may be made without departing from the spirit and scope of the present disclosure as defined by the appended claims. In addition, the scope of the present disclosure is not intended to be limited to the specific embodiments described herein, as one of ordinary skill in the art can readily appreciate from the present disclosure that currently existing or later to be developed processes, machines, manufactures, material compositions, means, methods or steps may perform substantially the same functions or achieve substantially the same results as the corresponding embodiments described herein. Therefore, the appended claims are intended to include within their scope such processes, machines, manufactures, material compositions, means, methods or steps.
[0067] Although the present invention has been described in conjunction with exemplary embodiments, the present invention is not intended to be construed as being limited thereto. With reference to these descriptions, it will be apparent to those skilled in the art that various modifications and combinations of the exemplary embodiments and other embodiments of the present invention may be made. Therefore, the appended claims cover any of these modifications or embodiments.
Claims
1. A key management architecture, comprising: A wireless network WN protection controller, adapted to obtain a user equipment UE specific key, the user equipment UE specific key being assigned to the UE accessing the wireless network, and adapted to distribute the UE specific key to a serving gateway SGW in the wireless network, wherein the UE specific key is adapted to provide a first layer of access protection on a bearer channel extending between the UE and the SGW; a WN key controller adapted to generate a WN-specific key assigned to the wireless network and distribute the WN-specific key to base stations in the wireless network, wherein the WN-specific key is independent and distinct from the UE-specific key and the WN-specific key is adapted to provide a second layer of access protection on a wireless access interface established between the base station and the UE accessing the wireless network; a first device adapted to obtain at least two of the UE-specific key, the WN-specific key, and a virtual network VN-specific key, wherein the VN-specific key is adapted to provide layer 3 access protection to a virtual path extending through the VN; as well as Data encrypted using at least two of the UE-specific key, the WN-specific key, and the VN-specific key is transmitted to the base station in the wireless network.
2. The key management architecture of claim 1, wherein the WN protection controller obtains the UE-specific key from a third-party key management entity, wherein the third-party key management entity is operated by a third-party administrator that is independent and distinct from an operator of the wireless network.
3. The key management architecture of claim 2, wherein the first device is authorized and authenticated by the third-party key management entity.
4. The key management architecture according to claim 1, wherein the first device is further configured to: moving from a coverage area of the wireless network to a second coverage area of a second wireless network; in, The UE-specific key is transmitted from the WN protection controller in the wireless network to a second WN protection controller in the second wireless network; The second WN protection controller distributes the UE-specific key to a second serving gateway SGW in the second wireless network.
5. The key management architecture according to claim 3, wherein the first device is a head device in a group, and the first device is further configured to: After the first device is authorized and authenticated by the third-party key management, it receives a group-specific key from the WN protection controller, where the group-specific key is suitable for encrypting group-related traffic flows in a private network.
6. The key management architecture according to claim 5, wherein the first device is further configured to: receiving a registration request from a second device of the group, the registration request forwarded by the third-party key management entity to the first device, for indicating that the second device attempts to register as a participant of the private network; and An authentication confirmation is sent to a WN protection controller in the wireless network, causing the WN protection controller to forward the group-specific key to the second device in response to the authentication confirmation.
7. A method for authenticating a mobile device, the method comprising: A wireless network WN protection controller receives a key specific to a user equipment UE, wherein the WN protection controller is assigned to distribute the key throughout the wireless network; The WN protection controller identifies a wireless network domain corresponding to a UE identifier specified by the UE-specific key; as well as The WN protection controller distributes the UE-specific key to a serving gateway SGW in the wireless network domain, wherein the UE-specific key is suitable for providing a first layer of access protection on a bearer channel extending between the UE and the SGW; A WN key controller generates a WN-specific key assigned to the wireless network domain and distributes the WN-specific key to base stations in the wireless network domain, wherein the WN-specific key is independent and distinct from the UE-specific key and the WN-specific key is suitable for providing a second layer of access protection on a wireless access interface established between the base station and the UE accessing the wireless network domain; The first device obtains at least two of the UE-specific key, the WN-specific key, and the virtual network VN-specific key, wherein the VN-specific key is suitable for providing third-layer access protection for a virtual path extending through the VN; and transmits data encrypted using at least two of the UE-specific key, the WN-specific key, and the VN-specific key to the base station in the wireless network domain.
8. The method of claim 7, wherein the WN protection controller receives the UE-specific key from a third-party key management entity, the third-party key management entity being operated by a third-party administrator distinct from an operator of the wireless network.
9. The method according to claim 7, wherein the SGW is a user-specific SGW.
10. The method of claim 8, wherein the first device is authorized and authenticated by the third party key management entity.
11. The method according to claim 7, further comprising: The first device moves from a coverage area of the wireless network domain to a second coverage area of a second wireless network domain; wherein the UE-specific key is transmitted from the WN protection controller in the wireless network domain to a second WN protection controller in the second wireless network domain; The second WN protection controller distributes the UE-specific key to a second serving gateway SGW in the second wireless network domain.
12. The method according to claim 10, wherein the first device is a head device in a group, the method further comprising: After the first device is authorized and authenticated by the third-party key management, the first device receives a group-specific key from the WN protection controller, where the group-specific key is suitable for encrypting group-related traffic flows in a private network.
13. The method according to claim 12, further comprising: The first device receives a registration request from a second device in the group, the registration request being forwarded by the third-party key management entity to the first device to instruct the second device to attempt to register as a participant in the private network; The first device sends an authentication confirmation to a WN protection controller in the wireless network domain; The WN protection controller forwards the group-specific key to the second device in response to the authentication confirmation.
Citation Information
Patent Citations
Selective security termination in next generation mobile networks
CN101810017A