Secure cell redirection in wireless networks

By performing an authentication process between the user equipment (UE) and the network in the LTE network and generating cell redirection commands with integrity protection, the problem of the UE being unable to verify the authenticity of the eNodeB is solved, preventing fake eNB attacks and improving the security and reliability of the system.

CN116390179BActive Publication Date: 2026-03-24NOKIA OF AMERICA CORP
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2018-01-29
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

In LTE networks, user equipment (UE) in idle mode cannot verify the authenticity of the attached eNodeB, leading to potential attacks during cell redirection, especially attacks by fake eNBs.

Method used

By performing an authentication process between the user equipment (UE) and the network, a cell redirection command with integrity protection is generated and transmitted, ensuring the authenticity and security of the command.

Benefits of technology

It effectively prevents attacks during cell redirection, ensures secure communication between the UE and the network, and improves the security and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116390179B_ABST
    Figure CN116390179B_ABST
Patent Text Reader

Abstract

A mobility management entity (MME) is configured to perform cell redirection or circuit switched fallback with a security protocol. The MME receives an initial connection message from a user equipment (UE) in idle mode with a service request for a voice call. Before the MME processes the service request, the MME and the UE first perform an authentication procedure with the UE. The MME generates a cell redirection command with integrity protection using an integrity key established during the authentication procedure. The MME transmits the cell redirection command with integrity protection to the UE in a payload of a signaling message. The MME can also transmit its policy for security protected cell redirection to the UE in an initial attach message to the network or with a tracking area update message.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the invention patent application filed on January 29, 2018, with application number 201880023398.7 and invention title "Secure Cell Redirection in Wireless Network".

[0002] Cross-reference to related applications

[0003] This application claims priority to U.S. Provisional Application No. 62 / 454,876, filed February 5, 2017, entitled “System and Method for Secure Cell Redirection in Wireless Networks,” pursuant to 35 USC119(e), which is hereby incorporated by reference. Technical Field

[0004] This application generally relates to wireless networks, and more specifically to cell redirection of user equipment from a first access network to a second access network. Background Technology

[0005] The statements in this section provide a description of the relevant technologies, not an admission of prior art. 3G and LTE can coexist for a period of time as mobile operators migrate their networks from third-generation (3G) systems (such as GSM circuit-switched networks) to Long Term Evolution (LTE) networks. Because 3G circuit-switched (CS) voice mechanisms may be more mature and available than LTE Voice over Internet Protocol (VoIP), operators may consider using 3G circuit-switched (CS) networks to provide voice calls.

[0006] The 3GPP (3rd Generation Partnership Project) standards define certain protocols or procedures for a "fallback" mechanism to 3G circuit-switched (CS) voice services. According to the 3GPP CS fallback procedure, when a mobile user connected to an LTE network has an incoming or outgoing call, the user equipment (UE) can fall back to or switch from the LTE network to the Universal Mobile Telecommunications System (UMTS) or GSM network. For example, when the LTE / WCDMA network is busy or unable to provide service to the UE, the LTE / WCDMA network can redirect service requests for voice calls from the UE to the GSM network. This redirection procedure or command is sometimes referred to as "cell redirection."

[0007] Unfortunately, in current LTE networks, UEs in idle mode lack a mechanism to verify the eNodeB or cell to which they are attached. Since there is no message passing between the UE and the eNB, the UE may be unable to detect whether the eNodeB (eNB) is genuine. Furthermore, the eNB lacks a security context for idle UEs. Thus, attacks during cell redirection to the GSM network are possible, for example, by using a fake eNB.

[0008] Therefore, remedial measures or processes are needed to provide additional security to prevent attacks during cell redirection. Summary of the Invention

[0009] In one embodiment, a method for performing cell redirection includes: receiving an initial attachment request with a service request from a user equipment (UE) via a first network; processing the initial attachment request, wherein processing the initial attachment request includes performing an authentication process; processing the service request from the UE; and generating a cell redirection command with integrity protection and transmitting the cell redirection command with integrity protection to the UE.

[0010] In another embodiment, the user equipment (UE) includes: a radio interface configured to connect to a first access network and a second access network, and processing circuitry configured to transmit a service request for a voice call to the first access network. The processing circuitry is further configured to receive a connection release message from the first access network, wherein the payload of the connection release message includes a cell redirection command with integrity protection, and to perform authentication of the cell redirection command in the payload of the connection release message.

[0011] In another embodiment, a control node includes: a network interface configured to transmit signaling messages with a user equipment (UE) in a first access network; and processing equipment configured to receive an initial connection message from the UE in the first access network, wherein the initial connection message includes a service request for a voice call. The processing equipment is further configured to perform an authentication process with the UE and generate an integrity key; process the service request from the UE; and use the integrity key to generate a cell redirection command with integrity protection. The control node is then configured to transmit the cell redirection command with integrity protection to the UE.

[0012] In one or more of the above embodiments, the cell redirection command includes a NAS signaling message carrying a CS rollback command included in the payload of the NAS signaling message. Integrity protection of the NAS signaling message payload is performed using an integrity key. Attached Figure Description

[0013] Some embodiments of the apparatus and / or methods according to embodiments of the present disclosure will now be described by way of example only and with reference to the accompanying drawings, wherein:

[0014] Figure 1 A schematic block diagram illustrating an embodiment of a network used for cell redirection is shown.

[0015] Figure 2 The diagram illustrates a logic flowchart of an embodiment of a method for cell redirection.

[0016] Figure 3 The illustration shows an embodiment of a logic flowchart for a method for cell redirection with security procedures.

[0017] Figure 4 The illustration shows a logic flowchart of an embodiment of another method for cell redirection with security procedures.

[0018] Figure 5 The illustration shows a logic flowchart of an embodiment of a method for cell redirection with a successfully verified security process.

[0019] Figure 6 The illustration shows a logic flowchart of an embodiment of a method for cell redirection with a security process involving failure verification.

[0020] Figure 7 The illustration shows a logic flowchart of an embodiment of a method for cell redirection with security procedures.

[0021] Figure 8 A more detailed flowchart illustrating the logic of the authentication process is provided.

[0022] Figure 9 A schematic block diagram of an embodiment of an example user equipment is shown.

[0023] Figure 10 A schematic block diagram illustrating an exemplary embodiment of an eNodeB is shown.

[0024] Figure 11 A schematic block diagram illustrating an exemplary embodiment of an MME is shown.

[0025] Figure 12 The diagram illustrates a logic flowchart of an embodiment of a method for notifying a UE of a cell redirection policy. Detailed Implementation

[0026] The specification and accompanying drawings illustrate only the principles of various embodiments. Therefore, it will be understood that those skilled in the art will be able to design various arrangements, although these arrangements are not expressly described or shown herein, but embody the principles of this document and the claims and fall within the spirit and scope of this disclosure. Furthermore, all examples described herein are intended primarily for illustrative purposes only to aid the reader in understanding the principles of the embodiments and the concepts contributed by the inventors to the art, and should be understood as not being limited to such specifically illustrated examples and conditions. Moreover, all statements herein that set forth principles, aspects, and embodiments, as well as specific examples thereof, are intended to cover their equivalents.

[0027] For convenience, some abbreviations used in this article have been expanded below: AKA Authentication and Key Negotiation

[0028] CS circuit switching

[0029] GERAN GSM / EDGE radio access network

[0030] HSS Home User Server

[0031] EPC Evolved Packet Core

[0032] ePDG (evolved packet data gateway)

[0033] EAP Extensible Authentication Protocol

[0034] E-UTRAN (Evolved Universal Terrestrial Radio Access Network)

[0035] GPRS General Packet Radio Service

[0036] GSM Global Mobile Communication System

[0037] MME (Mobility Management Entity)

[0038] MSC Mobile Switching Center

[0039] NAS Non-Access Layer

[0040] RRC Radio Resource Control

[0041] SGSN service GPRS supported nodes

[0042] UE User Equipment

[0043] UTRAN (Universal Terrestrial Radio Access Network)

[0044] Figure 1A schematic block diagram of an embodiment of a network 100 for cell redirection is illustrated. This exemplary network 100 is described in more detail in the technical standard TS 23.272V 13.4.0 (June 2016) entitled “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Circuit Switched (CS) fallback in Evolved Packet System (EPS); Stage 2 (Release 13)”, which is hereby incorporated by reference. While this network 100 is described herein, other networks and architectures may also be implemented in one or more embodiments described herein.

[0045] User equipment (UE) 110 includes an interface configured to access CS domain 122 (such as a GSM or UMTS network) via GERAN access network 104 and / or UTRAN access network 106. GERAN access network 104 includes GSM radio access technology, including its evolution in the form of Enhanced Data Rate Global Evolution (EDGE) and / or General Packet Radio Service (GPRS). UTRAN access network 106 is a UMTS radio access network that can connect services from circuit switching to an IP-based packet-switched core network.

[0046] The UE 110 interface is also configured to support communication with the E-UTRAN access network 102 via the LTE User Air Interface (LTE-Uu). The E-UTRAN access network 102 includes one or more eNodeBs or eNBs 118 for connection from the UE 110 to the Mobility Management Entity (MME) 112 in the Evolved Packet Core (EPC) network 108. The MME 112 provides support for the control plane in the EPC network 108. The MME 112 provides signaling related to mobility and security for access to the EPC network 108 by the UE 110 via E-UTRAN 102. The MME 112 is also configured for tracking and paging of the UE 110 in idle mode. The MME 112 uses a set of Non-Access Stratum (NAS) protocols for control plane signaling with the UE for EPC network access. Radio Resource Control (RRC) protocols are used in UMTS and LTE on the air interface between the UE 110 and E-UTRAN 102.

[0047] The Serving GPRS Support Node (SGSN) 114 is configured for processing packet-switched data within network 100, such as mobility management and authentication of network 100. The MSC server 120 is a GSM node configured to control switching in the CS domain 122. For example, as defined in 3GPP TS 29.118 (SGsAP), the SGs interface can be used between the MME 112 and the MSC server 120 to support cell redirection or CS fallback as described herein.

[0048] Figure 2 A logical flowchart of an embodiment of method 200 for cell redirection is illustrated. Call redirection or circuit-switched (CS) fallback as described herein enables UE 110, accessing E-UTRAN 102 in a 3GPP / LTE network, to access GERAN 104 or UTRAN 106 in CS domain 122 during the call setup process. Reuse of voice services from CS domain 122 has been standardized to support first deployment options for LTE networks or other packet-switched networks. The current process is described in standardized protocols, such as 3GPP TS 36.331 v.14.1.0 (December 2016) entitled “3rd Generation Partnership Project; Technical Specification Group Radio Access Network; Evolved Universal Terrestrial Radio Access (E-UTRA); Radio Resource Control (RRC); Protocol specification (Release 14)”, which is hereby incorporated by reference.

[0049] As an example, the release of an RRC connection with redirection to GERAN / UTRAN can be based on... Figure 2 The following message flow is executed as shown. UE 110 and eNB 118 execute random access procedure 202 for UE 110 to synchronize with E-UTRAN 102. After random access procedure 202, if UE 110 is not already attached to EPC network 108, UE 110 initiates an attachment procedure.

[0050] During the attachment process, UE 110 initiates an RRC connection using a three-way RRC handshake with eNB 118 and MME 112. UE 110 transmits an RRC connection request (SRB0) 204 to eNB 118, which responds with an RRC connection establishment (SRB0) message 206. UE 110 then transmits an RRC connection establishment complete (SRB1) message 208 to eNB 118, which includes a service request. For example, the service request can be formatted according to a Non-Access Stratum (NAS) message. NAS messages can be used as signaling between UE 110 and MME 112. The service request 210 is forwarded to MME 112 for processing.

[0051] When service request 210 includes a request for voice service, MME 112 may initiate a cell redirection procedure. MME 112 transmits a CS backoff message 212 to eNB 118, instructing eNB 118 that UE 110 should be redirected to another access network, such as UTRAN network 106 or GERAN network 104. MME 112 may also initiate a cell redirection procedure if there are pending voice calls to UE 110 that will be terminated. eNB 118 then triggers cell redirection procedure 214 to redirect UE 110 to another access network (UTRAN / GERAN). eNB 118 may also transmit an RRC connection release message 216 to release the RRC connection for UE 110. The RRC connection release message 216 may be transmitted via a signaling channel such as the LTE SRB1 signaling channel.

[0052] During cell redirection 214, a potential attack could occur in two instances. In the first instance, UE 110 performs an initial attachment to the network and makes a service request for the initiation of a voice call. In the second instance, UE 110 is in idle mode and initiates a service request in response to a paging message from the network for a pending voice call that will be terminated on the UE. To protect against such potential attacks, one or more embodiments of the following exemplary security procedures can be implemented.

[0053] When UE 110 initiates the "Initial Attachment" procedure to E_UTRAN 102 using a service request for a voice call, UE 110 has not yet been authenticated by EPC network 108. Conversely, UE 110 may not have authenticated EPC network 108 yet. Therefore, in this embodiment, EPC network 108 processes the Initial Attachment procedure and authenticates UE 110 before processing the service request for the voice call.

[0054] For example, when an RRC connection message from UE 110 includes an "Initial Attachment" indicator with "Service Request (Voice Call)", MME 112 first processes the Initial Attachment request from UE 110 before processing the Service Request. UE 110 must then be authenticated as part of the Initial Attachment process. This authentication verifies the authenticity of the other between UE 110 and MME 112. The Initial Attachment process is described in various standards, including, for example, 3GPP TS 23.401 "General Packet Radio Service (GPRS) enhancements for Evolved Universal Terrestrial Radio Access Network (E-UTRAN) access", version 14, released in June 2016, which is hereby incorporated by reference.

[0055] Specifically, the Authentication and Key Agreement (AKA) procedure between the MME and UE is specified in 3GPP TS 33.401 “3GPP System Architecture Evolution: Security Architecture”, version 14, published on September 30, 2016, which is hereby incorporated by reference. The AKA procedure describes the protocol for mutual authentication between the UE 110 and MME 112. Successful completion of the AKA procedure results in the establishment of a security association (i.e., a set of security data) between the UE 110 and MME 112, which implements a set of security services. For example, the security data established during the AKA procedure may include an integrity key to secure communication using symmetric cryptography between the UE 110 and MME 112.

[0056] One potential threat during cell redirection is a "fake" GERAN 104. For example, UE 110 receives a cell redirection message with a fake GERAN 104 identity. In one embodiment, to address this threat of redirection to a fake GERAN 104, MME 112 processes the "service request (voice call)" from UE 110 only after the AKA procedure is completed and the integrity key with UE 110 is established.

[0057] Figure 3A logic flowchart of an embodiment of a method 300 for cell redirection with a security procedure is illustrated. In step 302, UE 110 transmits a connection request for initial attachment to E_UTRAN 102 using a service request for a voice call. In step 304, before processing the service request, MME 112 first performs the initial attachment procedure. During the initial attachment procedure, the mobile device (ME) identity is obtained from UE 110. MME 112 can then verify the ME identity.

[0058] In step 306, additionally, as part of the initial attachment process or otherwise, an authentication process is performed between UE 110 and E_UTRAN 102. For example, an AKA process or other type of authentication process, authenticating UE 110 to MME 112 and / or MME 112 to UE 110, is performed. Then, in step 308, the service request is processed. After the authentication process is completed, MME 112 then initiates a cell redirection for UE 110 from a first network (e.g., E-UTRAN 102) to a second network (such as UTRAN 106 or GERAN 104). Then, in step 310, the second network can complete the service request for the voice call.

[0059] Figure 4 The illustration shows a logical flowchart of an embodiment of another method 400 for cell redirection with security procedures. In this example, UE 110 is in idle mode. For example, UE 110 may be in RRC_IDLE state, where UE 110 is powered on but does not have an established connection with the access network (such as an RRC connection). Typically, the location of UE 110 without an established connection is unknown to the network at the cell level. eNB 118 does not have any context for UE 110.

[0060] In idle mode, UE 110 must first request an RRC connection. At 402, UE 110 generates and transmits a random access channel request. At 404, eNB 118 responds using a random access channel response / grant. Then, at 406, UE 110 generates and transmits an RRC connection request (e.g., via a signaling channel). The signaling channel may include LTE Signaling Radio Bearer (SRB) channels, such as SRB0. At 408, eNB 118 confirms the RRC connection establishment using the SRB0 channel. The UE is then switched to ECM-CONNECTED mode, as specified in more detail, for example, in 3GPP TS 23.401 “General Packet Radio Service (GPRS) enhancements for Evolved Universal Terrestrial Radio Access Network (E-UTRAN)”, version 14, published in June 2016, which is hereby incorporated by reference.

[0061] UE 110 generates and transmits RRC connection establishment completion 410 and a service request via a signaling channel such as an LTE SRB1 channel. In an embodiment, the service request includes an indication that UE 110 is requesting a voice call. The service request may be included in a Non-Access Stratum (NAS) message format. UE 110 uses an integrity key to protect the integrity of the NAS service request to MME 112, which is established during an authentication process (such as an AKA process) performed during RRC connection establishment. For example, the NASint key determined using the integrity key is used to protect the NAS payload in the NAS service request message 412.

[0062] eNB 118 forwards NAS service request message 412 to MME 112. At 414, MME 112 authenticates UE 110 and the service request message. If authenticated, MME 112 processes the service request for the voice call.

[0063] In this example, at 416, MME 112 determines that a cell redirection to a second network is required in response to the service request. For example, MME 112 determines that a voice call should be terminated to UE 110 using a GERAN / GSM network, or that the LTE network may not support voice calls for loading, maintenance, or other network conditions. If service request 416 includes a request for the initiation of a voice call, MME 112 may also determine that a cell redirection is required.

[0064] Then, MME 112 uses the S1 Application Protocol (AP) interface (S1 AP interface) to generate a CS rollback command 418 and transmits it to UE 110. For additional security, MME 112 includes integrity protection for the CS rollback command to UE 110. In a first embodiment, the CS rollback command 418 may include a NAS command with integrity protection using a NASint key, which is established during the AKA procedure. MME 112 uses the CS rollback command to generate a NAS command in the payload to UE 110. The NASint key protects the payload of the NAS command 418. The CS rollback command can therefore include a NAS payload addressed to the UE, which is protected using the NASint key. In the current procedure, this CS rollback command or message fails to include a NAS payload or payload integrity protection.

[0065] In the second embodiment, integrity protection includes inserting a NAS token into the CS fallback command protection using the NASint key of UE 110. MME 112 uses the NASint key of UE 110 to generate the NAS token. MME 112 includes the NAS token in the CS fallback command to UE 110. Therefore, instead of integrity protection of the NAS payload, MME 112 includes the NAS token in the CS fallback command. Due to space constraints in the RRC redirection message, this second embodiment reduces the bytes used for integrity protection in the CS fallback command message. UE 110 can then use the NAS token and its NASint key to authenticate the CS fallback command.

[0066] The eNB 118 transmits an RRC connection release message 420 to the UE 110, which includes a CS fallback command. The CS fallback command may also include parameters for the second network or cell to which the UE is attached, such as identification parameters for GERAN 104 or UTRAN 106. The eNB 118 transparently includes the NAS payload or NAS token received from the MME 112 via the S1 AP interface. Because the UE 110 and eNB 118 do not share a security context, the RRC connection release message is not integrity protected. However, for integrity protection, the NAS payload included in the RRC connection release message 420 is integrity protected by the MME 112, or the NAS token generated by the MME using the UE's NAS context is included in the CS fallback command. The UE can use the NASint key or NAS token to verify the NAS payload to confirm that the CS fallback command originates from the MME 112 and not from a "fake" MME.

[0067] Figure 5The illustration shows a logic flowchart of an embodiment of a cell redirection method 500 with a successfully verified security process. UE 110 receives an RRC connection release message 502, which includes a CS backoff command with integrity protection. The message may also include an identification parameter for attaching to another network (e.g., GERAN 104 or UTRAN 106).

[0068] In the 504 error, UE 110 attempts to verify a CS fallback command. For example, the CS fallback command could be part of the payload of a NAS message encoded using a NASint key. UE 110 attempts to verify the NAS payload of the NAS message using the NASint key. In another example, the CS fallback command includes a NAS token generated using UE 110's NASint key. UE 110 attempts to verify the NAS token using its NASint key.

[0069] When the authentication at 506 is successful—for example, if the NAS payload or NAS token passes the integrity check or authentication—UE 110 processes the RRC connection release command and attempts to connect to another network. For example, UE 110 may transmit an RRC connection establishment message 508 to the GERAN 104 or UTRAN 106 identified in the CS fallback command. Then, GERAN 104 or UTRAN 106 may transmit an RRC connection establishment complete message 510 to UE 110 to establish an RRC connection for providing voice calls to UE 110.

[0070] Figure 6 The diagram illustrates a logic flowchart of an embodiment of a cell redirection method 600 for a security process with failure verification. UE 110 receives an RRC connection release message 602, which includes a CS fallback command with integrity protection. At 604, UE 110 attempts to verify the CS fallback command. For example, the CS fallback command may be part of the payload of a NAS message encoded using a NASint key (e.g., an integrity key). UE 110 attempts to verify the NAS payload or the NAS token of the NAS message using the NASint key (e.g., the integrity key).

[0071] In this embodiment, at 606, authentication fails. For example, authentication may fail because UE 110 cannot authenticate the NAS payload or NAS token. The NAS payload or NAS token fails the integrity check or authentication, or the RRC connection release message does not include the NAS payload. When authentication fails at 606, at 608, UE 110 abandons or discards the attachment procedure.

[0072] Figure 7 The diagram illustrates a logic flowchart of an embodiment of a cell redirection method 700 with a security procedure. At 702, UE 110 is in idle mode and initiates an attachment procedure with a service request for voice service with a first network. The first network may include E-UTRAN 102, which supports access to an EPC network 108 (such as LTE or other packet-switched network types). At 704, before processing the service request, UE 110 performs an initial attachment procedure with the first network to establish a connection. At 706, UE 110 and the first network perform an authentication procedure to exchange authentication information, such as encryption keys. For example, an AKA procedure or other type of authentication procedure is performed, which authenticates UE 110 to the first network and the first network to UE 110.

[0073] Following the authentication process at 706, at 708, UE 110 receives a cell redirection command with integrity protection. For example, the cell redirection command may include a CS backoff message in the payload of a NAS message. Integrity protection allows UE 110 to verify the source of the message as the first network and / or verify the cell redirection command.

[0074] When UE 110 verifies the source of the command and / or the command as the first network at 710, at 714, the UE initiates a connection to the second network to provide voice service. The second network may include a circuit-switched network or domain 122, which has access networks such as UTRAN 106 or GERAN 104. The second network can then fulfill the service request for the voice call. When UE 110 fails to verify the source of the command and / or the command as the first network at 710, at 712, UE 110 ignores the CS fallback command and abandons or discards the attachment process with the second network.

[0075] Figure 8 A logic flowchart of method 800 for performing the authentication process in more detail is illustrated. When UE 110 is in idle mode, UE 110 must first attach to E-UTRAN 102 by performing an attachment procedure. In the embodiments herein, at 802, the attachment procedure includes an authentication procedure.

[0076] At 804, UE 110 transmits an initial attach request to eNB 118. At 806, eNB 118 forwards the initial attach request to MME 112. When UE 110 supports CS fallback, UE 110 can include the information element "Voice Domain Preferences and UE Usage Settings" in the attach request.

[0077] In this embodiment, prior to a service request for a voice call, UE 110 and MME 112 perform authentication, which includes cell redirection. Authentication may include one or more types of integrity protection procedures. For example, an integrity protection procedure includes an AKA procedure that generates security data, such as integrity key material for RRC and NAS encryption keys and RRC and NAS integrity protection. At 810, MME 112 transmits a user authentication request to UE 110. The user authentication request may include a random challenge RAND for network authentication and an authentication token AUTN from an authentication vector. The authentication request may also include a base key K. ASME The UE and MME share the basic key K. ASME .

[0078] Upon receiving this message, the UE's USIM verifies the authentication vector by checking if the AUTN is acceptable. If so, the USIM calculates the response RES. The USIM calculates keys CK and IK based on a permanent key K, which is stored on the USIM on the UICC and in the Home Location Register (HLR) in the EPC network 108. The keys CK and IK are a key pair obtained in the HLR and on the UE 110's USIM during the AKA procedure. At 812, the UE 110 transmits a user authentication response, which includes the response RES calculated based on the keys CK and IK.

[0079] The MME checks the RES. If verified, authentication is successful. If not, depending on the identity type used by UE 110, the MME 112 can initiate a further identity request or send an authentication rejection message to UE 110. After successful authentication, at step 814, the MME 112 transmits an attach accept message to UE 110.

[0080] Figure 9 A schematic block diagram of an embodiment of example user equipment 110 is illustrated. User equipment (UE) 110 may include a smartphone, smart tablet, laptop, smartwatch, PC, TV, or other device. The UE 110 described herein is for illustrative purposes only. Additional or alternative components and functions may be included in or combined with other components or functions. Additionally, one or more functions and components shown herein may not be present in the UE 110.

[0081] UE 110 includes a processing device 902 and a memory device 904. The memory device 904 stores operable instructions that, when executed by the processing device 902, can perform one or more functions described herein with respect to UE 110. For example, the memory device 904 may include instructions and data that, when used by the processing device 902, handle functions of various protocols and procedures, such as functions of handling various protocols and procedures in a protocol stack including NAS 950, Radio Resource Control (RRC) 952, Packet Data Convergence Control (PDCP) 954, Radio Link Control (RLC) 956, and Media Access Control, as well as physical layer functions 958. Additionally, UE 110 may also include a UICC 934, which includes a USIM 932.

[0082] UE 110 may further include a Bluetooth transceiver 912, a WLAN (IEEE 802.11x compliant) transceiver 914, and a Global Positioning Satellite (GPS) transceiver 918. The WLAN transceiver 914 can operate as a non-3GPP access interface to the EPC network 108. UE 110 also includes an RF transceiver 916 compliant with the following wireless network protocols: Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (UTRAN), Long Term Evolution (LTE) Evolved UTRAN (E-UTRAN), LTE Advanced (LTE-A), or other wireless network protocols. UE 110 includes RX processing circuitry 938 and TX processing circuitry 940.

[0083] UE 110 may further include a user application 932, an AC adapter 922, a USB transceiver 926, and an Ethernet port 928. UE 110 may further include one or more user interfaces 920, such as a touchscreen controller, speaker, microphone, or display. UE 110 may also include a power management unit 930 and a battery module 924. One or more internal communication buses (not shown) may communicatively couple one or more components of UE 110.

[0084] Figure 10 A schematic block diagram illustrating an embodiment of an exemplary eNB 118 is shown. The eNB 118 described herein is for illustrative purposes only. One or more functions or components shown herein may be absent or may be combined with other components or functions. Additional components or functions may also be included. The eNB 118 includes a processing device 1002 and a memory device 1004 that stores instructions, which, when executed by the processing device 1002, can perform one or more functions described herein with respect to the eNB 118.

[0085] The eNB 118 includes multiple RF transceivers 1016, transmit (TX) processing circuitry 1008, and receive (RX) processing circuitry 1010. The eNB 118 also includes a network interface 1006 for communicating with other eNBs 118 and core network nodes such as the MME 112.

[0086] RF transceiver 1016 receives input RF signals, such as signals transmitted by UE 110. RF transceiver 1016 down-converts the input RF signals to generate an IF or baseband signal. The IF or baseband signal is sent to RX processing circuitry 1010, which generates a processed baseband signal by filtering, decoding, and / or digitizing the baseband or IF signal. RX processing circuitry 1010 transmits the processed baseband signal to processing device 1002 for further processing. RX processing circuitry 1010 includes an integrity protection module 1020 configured to perform one or more of the functions described herein with respect to PDCP integrity protection.

[0087] The TX processing circuit 1008 receives analog or digital data from the processing device 1002. The TX processing circuit 1008 encodes, multiplexes, and / or digitizes the output baseband data to generate a processed baseband or IF signal. The RF transceiver 1016 receives the processed baseband or IF signal from the TX processing circuit 1008 and up-converts the baseband or IF signal to an RF signal transmitted via the antenna.

[0088] Figure 11 A schematic block diagram of an exemplary embodiment of MME 112 is illustrated. MME 112 is a control node for E-UTRAN access network 102. MME 112 is responsible for tracking and paging procedures including retransmissions, and for the idle mode of UE 110. MME 112 also relates to RRC bearer activation and deactivation procedures, and cell redirection procedures to the CS switching network or domain 122. MME 112 is the termination point for encryption and integrity protection of NAS signaling, including CS backoff commands or other cell redirection messages.

[0089] The MME 112 described herein is for illustrative purposes only. One or more functions or components shown herein may be absent or may be combined with other components or functions. Additional components or functions may also be included. The MME 112 includes a processing device 1102 and a memory device 1104 storing instructions that, when executed by the processing device 1102, can perform one or more functions described herein with respect to the MME 112. For example, the memory device 1104 may include instructions and data that, when used by the processing device 1102, process the functions of a protocol stack including NAS layer 1120, S1 Application Protocol (S1AP) 1122, IP layer 1124, and Layer 2 / Layer 1 functions 1126. The MME 112 is the endpoint for encryption and integrity protection of NAS signaling, including CS backoff commands or other cell redirection messages.

[0090] The MME 112 includes a network interface 1106, transmit (TX) processing circuitry 1108, and receive (RX) processing circuitry 1110. The network interface 1106 is configured to communicate with one or more eNBs 118 and other core network nodes. The network interface 1106 may include one or more types of transceivers 1114, including RF transceivers 1116, or one or more types of ports, such as Ethernet ports 1118.

[0091] Figure 12 The illustration shows a logic flowchart of an embodiment of a method for notifying a UE of a cell redirection policy. In this embodiment, the MME 112 notifies the UE 110 whether cell redirection with integrity protection is supported. This process can be performed in any network, for example, regardless of whether the network has 2G or 3G coverage by an LTE network. The UE 110 can then perform cell redirection according to the cell redirection policy to avoid security threats.

[0092] At 1202, UE 110 and eNB 118 perform a random access procedure to synchronize UE 110 with E-UTRAN 102. After the random access procedure at 1202, if UE 110 has not yet attached to EPC network 108, UE 110 initiates an attachment procedure.

[0093] During the attach process, UE 110 initiates an RRC connection using a three-way RRC handshake with eNB 118 and MME 112. At 1204, UE 110 transmits an RRC connection request (SRB0) to eNB 118, and at 1206, the eNB responds with an RRC connection establishment (SRB0) message. Then, at 1208, UE 110 transmits an RRC connection establishment complete (SRB1) message to eNB 118. UE 110 may also transmit an initial attach request message to eNB 118, which has the identity of the UE included therein. If UE 110 has already been authenticated and has been moved to the coverage area of ​​a specific tracking area under MME 112 due to mobility in idle mode, UE 110 may also transmit a tracking area update message.

[0094] At 1210, eNB118 forwards the initial attach request message to MME. MME 112 uses the UE identity presented at 1212 to authenticate UE 110. UE 110 authentication may involve multiple messages between UE 110 and MME 112 to derive the authentication vector, mutually verify UE 110 and the network / MME 112, and establish the NAS security context, as described in 3GPP TS 33.401 “3GPP System Architecture Evolution: Security Architecture”, version 14, released on September 30, 2016, which is hereby incorporated by introduction.

[0095] After UE 110 is authenticated, at 1214, MME 112 transmits an Initial Attachment Acceptance / Location Area Update (TAU) Acceptance message. The Initial Attachment Acceptance message is securely protected using a newly established NAS integrity key for eNB 118. The Initial Attachment Acceptance / TAU Acceptance message further includes a cell redirection policy field or parameter. The cell redirection policy field informs UE 110 whether integrity-protected cell redirection is supported. For example, the cell redirection policy field or parameter can indicate "Yes" if the network policy supports integrity-protected cell redirection, or "No" if the network policy does not support integrity-protected cell redirection. At 1216, eNB 118 forwards an Initial Attachment Response / Location Area Update Response message to UE 110.

[0096] Therefore, UE 110 is notified whether the network supports cell redirection with integrity protection. MME 112 notifies UE 110 whether it provides cell redirection with integrity protection. Thus, UE 110 is informed of the network policy and whether UE 110 can expect cell redirection with integrity protection from the network during initial attachment or tracking area update. UE 110 can then perform cell redirection according to the cell redirection policy to avoid security threats. For example, if the network policy supports secure cell redirection, UE 110 can accept only secure cell redirection commands. This method allows operators to progressively implement cell redirection with integrity protection across the network.

[0097] The processing device or application processing device described herein includes at least one processing device, such as a microprocessor, microcontroller, digital signal processor, microcomputer, central processing unit, field-programmable gate array, programmable logic device, state machine, logic circuit, analog circuit, digital circuit, and / or any device that manipulates signals (analog and / or digital) based on circuitry and / or hard-coded operable instructions. The memory device is a non-transient memory device and can be internal or external memory, and the memory can be a single memory device or multiple memory devices. The memory device can be read-only memory, random access memory, volatile memory, non-volatile memory, static memory, dynamic memory, flash memory, cache memory, and / or any non-transient memory device that stores digital information. The term "module" is used in the description of one or more embodiments of the elements herein. A module includes one or more processing devices and / or one or more non-transient memory devices operable to perform one or more functions as may be described herein. A module can operate independently and / or in combination with other modules and can utilize the processing devices and / or memory of other modules and / or operable instructions of other modules. As used in this article, a module can contain one or more submodules, and each submodule can be one or more modules.

[0098] As may be used herein, the terms “operable to” or “configurable to” indicate an element comprising one or more of the following: circuitry, instructions, modules, data, inputs(multiple) and outputs(multiple) for performing one or more of the described or necessary corresponding functions, and may further include elements inferred to be coupled to one or more other items for performing the described or necessary corresponding functions. As may also be used herein, the terms “coupled,” “coupled to,” “connected to,” and / or “connected” or “interconnected” include direct connections between nodes / devices and / or indirect connections between nodes / devices via intermediate items (e.g., items including, but not limited to, components, elements, circuits, modules, nodes, devices, network elements, etc.). As may further be used herein, an inferred connection (i.e., one element being inferred to be connected to another element) includes direct and indirect connections between two items in the same manner as “connected to.”

[0099] Note that aspects of this disclosure can be described herein as processes, depicted as diagrams, flowcharts, block diagrams, or flowcharts. Although a flowchart can describe operations as a sequential process, many operations can be executed in parallel or concurrently. Additionally, the order of operations can be rearranged. A process terminates when its operations are completed. A process can correspond to a method, function, procedure, subroutine, subroutine, etc. When a process corresponds to a function, its termination corresponds to the function returning from the calling function or the main function.

[0100] The various features of this disclosure described herein can be implemented in different systems and devices without departing from this disclosure. It should be noted that the foregoing aspects of this disclosure are merely illustrative and not intended to limit the scope of this disclosure. The descriptions of various aspects of this disclosure are intended to be illustrative and not to limit the scope of the claims. Thus, this teaching can be readily applied to other types of devices, and many substitutions, modifications, and variations will be apparent to those skilled in the art.

[0101] In the foregoing description, certain representative aspects of the invention have been described with reference to specific examples. However, various modifications and variations can be made without departing from the scope of the invention as set forth in the claims. The description and drawings are illustrative rather than restrictive, and the modifications are intended to be included within the scope of the invention. Therefore, the scope of the invention should be determined by the claims and their legal equivalents, and not merely by the described examples. For example, any components and / or elements set forth in the device claims can be assembled in various arrangements or otherwise operatively configured, and are therefore not limited to the specific configurations set forth in the claims.

[0102] Furthermore, the benefits, other advantages, and solutions to problems have been described above with respect to specific embodiments. However, the benefits, advantages, solutions to problems, and any elements that may make any benefit, advantage, or solution occur or become more significant shall not be construed as key, essential, or necessary features of any or all claims.

[0103] As used herein, the terms “comprising,” “including,” “constituting,” “having,” “including,” “comprising,” or any variation thereof are intended to refer to non-exclusive inclusion, such that a process, method, article, composition, or apparatus that includes a list of elements may include not only those elements set forth but also other elements not expressly listed or inherent to such processes, methods, articles, compositions, or apparatuses. Other combinations and / or modifications of the above-described structures, arrangements, applications, proportions, elements, materials, or components used in the practice of this invention, except those specifically set forth, may be varied or otherwise adapted specifically to particular environments, manufacturing specifications, design parameters, or other operational requirements without departing from similar general principles.

[0104] Furthermore, unless otherwise specified, references to elements in the singular form are not intended to mean "one and only one," but rather "one or more." Unless otherwise specified, the term "some" means one or more. All structural and functional equivalents of elements throughout the various aspects described in this disclosure that are known or will be known hereafter by one of ordinary skill in the art are expressly incorporated herein by reference and are intended to be covered by the claims. Furthermore, regardless of whether such disclosure is expressly set forth in the claims, the contents disclosed herein are not intended to be intended for the public. Pursuant to 35 U.SC §112(f), unless the element is expressly set forth by the phrase "means for," or, where required by a method, by the phrase "steps for," the claim elements are not intended to be interpreted as "means plus function" type elements.

Claims

1. A method for communication, comprising: Prior to authentication between the user equipment (UE) and a base station in the first access network, a radio resource control (RRC) connection message is transmitted at the UE and to the base station in the first access network. The RRC connection message includes an initial attachment request indication and a service request for the initiation of a voice call. Receive a Radio Resource Control (RRC) connection release message from the base station. The RRC connection release message is generated by the base station without integrity protection. The RRC connection release message includes a payload, which includes a Non-Access Stratum (NAS) signaling message with a cell redirection command. This cell redirection command has integrity protection. This includes the NAS signaling message of the cell redirection command being received at the base station from the Mobility Management Entity (MME), and includes integrity protection by the MME using an integrity key. The integrity key is generated by the MME through a NAS authentication process performed between the MME and the UE.

2. The method according to claim 1, further comprising: Transmit the mobile device (ME) identity of the UE to be verified by the MME.

3. The method according to claim 1 or 2, further comprising: An authentication process is performed together with the base station to authenticate the UE to the MME and / or to authenticate the MME to the UE.

4. The method according to any one of claims 1 or 2, wherein the RRC connection release message is based on the existence of a pending voice call to the UE that will be terminated.

5. The method according to any one of claims 1 or 2, wherein the RRC connection release message includes a circuit switching (CS) rollback command with integrity protection.

6. The method according to claim 5, further comprising: The NAS integrity key is used to verify the CS rollback command.

7. The method according to claim 6, further comprising: If the verification is successful, an attachment process to the second access network is initiated, and the second access network is identified in the CS fallback command.

8. The method of claim 7, wherein initiating the attachment procedure comprises: Transmit an RRC connection establishment message to the second access network.

9. The method of claim 8, further comprising initiating the attachment procedure: Receive an RRC connection establishment complete message from the second access network; as well as Voice calls are received from the second access network via an RRC connection to the second access network.

10. The method of claim 6, further comprising: In the event of verification failure, the attachment process to the second access network, which is identified in the CS rollback command, is abandoned.

11. An apparatus for communication, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the device to at least: Prior to authentication between the device and a base station in the first access network, a Radio Resource Control (RRC) connection message is transmitted to the base station in the first access network. The RRC connection message includes an initial attachment request indication and a service request for the initiation of a voice call. Receive a Radio Resource Control (RRC) connection release message from the base station. The RRC connection release message is generated by the base station without integrity protection. The RRC connection release message includes a payload, which includes a Non-Access Stratum (NAS) signaling message with a cell redirection command. This cell redirection command has integrity protection. This includes the NAS signaling message of the cell redirection command being received at the base station from the Mobility Management Entity (MME), and includes integrity protection by the MME using an integrity key. The integrity key is generated by the MME through a NAS authentication process performed between the MME and the device.

12. The apparatus of claim 11, wherein the apparatus is further configured to: Transmit the mobile device (ME) identity of the device to be verified by the MME to the MME.

13. The apparatus according to claim 11 or 12, wherein the apparatus is further configured to: An authentication process is performed together with the base station to authenticate the device to the MME and / or to authenticate the MME to the device.

14. The apparatus according to any one of claims 11 or 12, wherein the RRC connection release message is based on the existence of a pending voice call to the apparatus that will be terminated.

15. The apparatus of any one of claims 11 or 12, wherein the RRC connection release message includes a circuit switching (CS) rollback command with integrity protection.

16. The apparatus of claim 15, wherein the apparatus is further configured to: The NAS integrity key is used to verify the CS rollback command.

17. The apparatus of claim 16, wherein the apparatus is further configured to: If the verification is successful, an attachment process to the second access network is initiated, and the second access network is identified in the CS fallback command.

18. The apparatus of claim 17, wherein the apparatus is configured to initiate the attachment process by: Transmit an RRC connection establishment message to the second access network.

19. The apparatus of claim 18, wherein the apparatus is configured to initiate the attachment process by: Receive an RRC connection establishment completion message from the second access network; and Voice calls are received from the second access network via an RRC connection to the second access network.

20. The apparatus of claim 16, wherein the apparatus is further configured to: In the event of verification failure, the attachment process to the second access network, which is identified in the CS rollback command, is abandoned.

21. A non-transitory computer-readable medium comprising program instructions stored thereon, the program instructions, when executed on at least one processor, causing the at least one processor to perform the method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • Method and system for generating an identity identifier of a key

    US20110123029A1

  • Method for transmitting paging and apparatus for supporting the same in wireless communication system

    US20160205661A1