LEGITIMATE INTERCEPTION OF APPLICATION FUNCTION ACTIVITIES
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- THALES DIS FRANCE SA
- Filing Date
- 2023-03-09
- Publication Date
- 2026-04-29
AI Technical Summary
Existing bootstrapping technologies like GBA and AKMA face challenges in enabling lawful interception of user equipment activities, particularly in roaming scenarios, as they prevent Lawful Interception in the Visited PLMN due to encrypted tunnels and lack a mechanism for verifying the authenticity of shared AF keys.
A method is introduced to enable lawful interception by using an AF key provided by the Home PLMN or a third party, verifying its authenticity through parallel cryptographic operations, such as encrypting and decrypting a parameter like GUTI using the AF key, and comparing it with the original parameter to ensure matching integrity values.
Ensures that the Visited PLMN can verify the authenticity of the AF key, allowing lawful interception to function correctly and preventing false key provisioning, thus securing communication interfaces in roaming scenarios.
Description
FIELD OF THE INVENTION
[0001] The present invention relates to a method to enable lawful interception of activities of a user equipment, UE, with an application function, AF, associated to a bootstrapping technology.
[0002] The invention also pertains to a user equipment UE implementing this method and to a bootstrapping Anchor Function implementing this method.BACKGROUND OF THE INVENTION
[0003] Bootstrapping technologies enable keys to be shared between a user equipment UE and an application function AF. Such bootstrapping technologies are typically the Generic Bootstrapping Architecture GBA or Authentication and Key Management for Applications AKMA based on 3GPP credentials in the 5G System.
[0004] GBA has been defined in 4G, while AKMA has been specified in 5G Rel-17.
[0005] These technologies are gaining new applications with the development, among others, of the Edge Computing and of Proximity Services, known under the ProSe acronym. In particular, V2X applications implicating vehicles are an example of services based on ProSe enabler.
[0006] Also, those usages increase the use case for having the Application Function outside of the currently used Public Land Mobile Network, PLMN, which causes specific situations regarding the access to UE's activities using Application Function.
[0007] In particular, roaming use cases have been excluded from Rel-17 by lawful interception LI group (3GPP SA3-LI) until a solution is warranty that VPLMN, Visited PLMN, is receiving the appropriate material to ensure LI.
[0008] A solution could be to use certificate-based TLS but this solution is not privileged for the applications newly developed. Bootstrapping technologies have real advantages in comparison and there is a need to fulfill Lawful Interception requirements for all deployments scenarios, typically a UE in roaming for those technologies too.
[0009] Bootstrapping technologies, typically GBA and AKMA, enable the establishment of keys shared between a UE and an AF. 3GPP does not preclude the AF to be operated outside a visited Public Land Mobile Network, VPLMN. The AF could be operated by the Home Network, HPLMN, or a visited network, or a third party. During 3GPP Rel-17, 3GPP SA3 LI group in charge of Lawful Interceptions raised the following issue.
[0010] The shared key in most cases can be used for encryption across the VPLMN by creating an encrypted tunnel between the UE and a point outside the VPLMN, e.g. a point in the Home PLMN, HPLMN, or in third party. This prevents Lawful Interception to take place in the VPLMN as required.
[0011] For encryption, which the MNO has been involved in establishing, there is a Lawful Interception requirement to provide either decrypted traffic or the means for law enforcement to decrypt the traffic.
[0012] This requirement applies to mechanism such as AKMA where the MNO (Mobile Network Operator) is involved in establishing and distributing key material for encryption. There are thus lawful interception requirements for AKMA and GBA.
[0013] Furthermore, when roaming, LI needs to be possible to perform independently in each of the involved jurisdiction, including the ones of the roaming country. In particular, activation of LI in the VPLMN needs to be carried out without explicit support from a HPMLN as it would otherwise lead information that the inbound roamer is a LI target in the VPLMN. In particular, the problem to solve applies to AKMA and GBA.
[0014] So far, there is no solution known to address the problem described above. Further alternative and advantageous solutions would, accordingly, be desirable in the art.SUMMARY OF THE INVENTION
[0015] The present invention aims at enabling the lawful interception, also in roaming situation, for any application using a bootstrapping technology.
[0016] The present invention is defined, in its broadest sense, as a method to enable lawful interception of activities of a user equipment UE with an application function AF associated to a bootstrapping technology, the activities using an AF key, while the UE is in a roaming situation with a visited Public Land Mobile Network, VPLMN, using at least one parameter known by both the UE and the VPLMN, the VPLMN having been provided, for lawful interception purposes, with a provided application function key, the method comprising the steps of, respectively, for the UE or for the VPLMN: sending the parameter known by both the UE and the VPLMN encrypted with, respectively, the AF key or the provided AF key, to, respectively, the VPLMN or the UE, and for, respectively, the VPLMN or the UE, which received the encrypted parameter: decrypting the encrypted parameter with, respectively, the provided AF key or the AF key, and comparing the decrypted parameter with the parameter as known by, respectively, the VPLMN or the UE which received the encrypted parameter, authorizing the use of the AF only if the comparison shows that both parameters are the same.
[0017] The Lawful Interception possibility of the invention is based on the provision, by the Home PLMN (HPLMN in the following), or by any third party responsible for a given application function AF, of the shared AF key to the visited PLMN. It is here noted that the AF belongs to HPLMN or to a third party. So far, the provisioning of the shared AF key is under the responsibility of the HPLMN only, as the HPLMN is the owner of an anchor function, typically the AAnF for AKMA Anchor Function, where the AF key is derived. However, the invention also applies to situations where such key is provided by the third party which monitors the application function. The invention applies to both cases.
[0018] The invention further ensures that the HPLMN, or the third party responsible to provide the application function key, cannot lie to the Visited PLMN (VPLMN in the following) on the shared key value. Otherwise, the provision of the AF key cannot be of any value for the lawful interception requirement.
[0019] In bootstrapping technology context, the scenario where the HPLMN could lie to the VPLMN on the value of the shared AF key takes place when the UE is in roaming and that the AF belongs to the HPLMN or to another party.
[0020] The invention includes a way, in the case where the AF key is provided systematically to the VPLMN, to check that a correct AF key was provided to fulfil Lawful Interceptions requirements. In other words, the invention enables the VPLMN to verify the AF key as provided by the HPLMN when the UE is in roaming and when the AF is operated by the HPLMN, or by a third party of the VPLMN.
[0021] The principle of the invention is thus to make parallel cryptographic operations using the AF key to be verified in order to be able that the provided AF key is correct. It is here thus noted that the terms encrypt / decrypt designate any kind of cryptographic operations enabling to check that a correct AF key was provided by the HPLMN. The calculation of an integrity value of a parameter calculated with the AF key is thus to be considered as an encryption in the meaning of the invention.
[0022] Thus, in a specific embodiment, the encrypted parameter is an integrity value of the parameter calculated with, respectively, the AF key or the provided AF key, the decryption step consisting in a calculation with, respectively, the provided AF key or the AF key, of an integrity value of the parameter as known by, respectively, the VPLMN or the UE, which received the encrypted parameter, the comparison step consisting in a comparison of the calculated integrity value with the one as received, the use of the AF being authorized only if the comparison shows that both integrity values are the same.
[0023] In this specific embodiment, typically, a Message Authentication Code, MAC, calculated with the AF key is used.
[0024] The invention prevents a HPLMN or any PLMN hosting an Application Function implementing a bootstrapping technology and thus an AF key to lie to any other PLMN, typically a VPLMN, on shared keys used between a UE and an AF.
[0025] The invention thus relies on the usage of an AF key as provided by the HPLMN, or by another entity associated to the AF, to the VPLMN and of parameter(s) known by the UE and the VPLMN. The invention involves a parameter known by the UE and the VPLMN.
[0026] In a preferred embodiment, this parameter is a Generic Universal Temporary Identifier GUTI.
[0027] This embodiment uses the main parameter used for the connection of the UE to the VPLMN and is thus a simple and thus preferred embodiment.
[0028] The invention enables to check the authenticity of the application function key, in a user equipment roaming context where the user equipment using the application function key is connected to a visited Public Land Mobile Network, VPLMN.
[0029] This invention ensures that GBA and AKMA solutions, which besides generally rely on the presence of an USIM, could be used in any deployment scenario where there is interest in securing interfaces thanks to Pre-share key-TLS PSK-TLS.
[0030] According to an advantageous feature, an application function identifier to identify the concerned AF is included in exchanges between the UE and the vVPLMN.
[0031] Such an AF identifier enables to retrieve the appropriate application function key and to authorize the use of the right verified application function. Such an identifier is a minima associated to the message comprising the encrypted parameter and to the authorization related messages.
[0032] According to a particular feature, the UE having a Home Public Land Mobile Network, HPLMN, the provisioning of the application function key is done by the HPLMN.
[0033] This situation corresponds to the case where the HPLMN owns the AF but also to cases where the HPLMN centralizes the management of bootstrapping scenarios involving third parties. This is the schema that is most of the time currently implemented when a third party, in the meaning of the 3GPP standardization, is involved in the management of the AF. In such a case, the HPLMN receives necessary key information from such third party for the implementation of the bootstrapping, thus including application function keys.
[0034] According to another particular feature of the invention, the bootstrapping technology implementing an Anchor Function in PLMN, the anchor function storing application function keys resulting from bootstrapping technology, the steps as performed by the VPLMN are performed by the Anchor Function of the VPLMN.
[0035] This feature corresponds to the simplest implementation of the invention in a VPLMN. The centralization of the bootstrapping necessary material in the anchor function of the VPLMN and performing the steps of the invention within the anchor function is a simple and efficient way to implement the invention.
[0036] According to an implementation, the roaming situation using an access management function, the step of, for the entity which encrypts the parameter known by both the UE and the VPLMN, sending the encrypted parameter to the other entity, comprises a sub-step of, for the encrypting entity, to send the encrypted parameter to the access management function which forwards it to the other entity.
[0037] This implementation implies the access management function AMF as generally active in roaming situation to be involved in the method of the invention. This is here noted that, when an AF identifier is used, it follows the same way via the AMF.
[0038] The invention also concerns a user equipment UE having roaming features with a visited PLMN using a parameter known by both the UE and the visited PLMN and having a duty to enable lawful interception of its activities with an application function AF associated to a bootstrapping technology, the activities using an AF key stored in the UE, the UE comprising: an encryption / decryption module adapted to encrypt the parameter known by both the UE and the visited PLMN using the stored AF key and / or to decrypt a received encrypted parameter using the stored AF key, a reception / transmission module adapted to send the encrypted parameter to the visited PLMN and / or to receive the encrypted parameter from the visited PLMN, a processing module adapted to compare a decrypted parameter with the parameter as known by the UE in the case where the parameter is decrypted, the reception / transmission module being, in this case, further adapted to send the result of the comparison to an access management function for it to authorize the use of the AF only if the comparison shows that both parameters are the same.
[0039] Such a user equipment is adapted to the implementation of the method of the invention according to both embodiments of the method, i.e. in the direction from the UE to the visited PLMN or from the visited PLMN to the UE. Of course, these two embodiments can be implemented in one direction for a specific AF and in the other direction for another AF. The two embodiments can coexist or one of them can also be exclusively implemented to perform the method of the invention.
[0040] The use of the terms "or" and "and / or" in the claims aims to cover both embodiments together or independently in the definition of the scope of the invention.
[0041] The term "respectively" enables to cover the two embodiments in parallel.
[0042] The invention also relates to a PLMN adapted to attach a user equipment UE in a roaming situation as a visited Public Land Mobile Network, VPLMN, using a parameter known by both the UE and itself as a VPLMN and adapted to enable lawful interception of activities of the UE with an application function AF associated to a bootstrapping technology the AF being owned by a third party of the PLMN, the activities using an AF key, the PLMN being adapted to be provided with an application function key, the PLMN further comprising: an encryption / decryption module adapted to encrypt the parameter using the provided AF key and / or to decrypt a received encrypted parameter using the provided AF key, a reception / transmission module adapted to send the encrypted parameter to the UE and / or to receive the encrypted parameter from the UE, a processing module adapted to compare a decrypted parameter with the parameter as known by the PLMN in the case where the parameter is decrypted by the PLMN, the reception / transmission module being, in this case, further adapted to send the result of the comparison to an access management function for it to authorize the use of the AF only if the comparison shows that both parameters are the same.
[0043] Such a PLMN is adapted to perform both embodiments of the method of the invention.
[0044] Again, the implementation of only one embodiment without the second one is included in the scope as defined in the claims.
[0045] It is here noted that in general and in other parts of the patent application, the terms "third party" designate what it generally designated in 3GPP, i.e. an entity distinct / independent from the operator, this operator being the Home PLMN, HPLMN, or the Visited PLMN, VPLMN. In the above definition of a PLMN of the invention in the last paragraphs, these terms designate, however, all third parties of the PLMN, including, this time, also the HPLMN.
[0046] According to an advantageous implementation, the PLMN has a bootstrapping Anchor Function adapted to perform the steps of the method of the invention.
[0047] As seen above, this implementation is a simple and efficient way to implement the invention.
[0048] To the accomplishment of the foregoing and related ends, one or more embodiments comprise the features hereinafter fully described and particularly pointed out in the claims.BRIEF DESCRIPTION OF THE DRAWINGS
[0049] The following description and the annexed drawings set forth in detail certain illustrative aspects and are indicative of but a few of the various ways in which the principles of the embodiments may be employed. Other advantages and novel features will become apparent from the following detailed description when considered in conjunction with the drawings and the disclosed embodiments are intended to include all such aspects and their equivalents. Figure 1 shows a time flowchart of a first embodiment of the method of the invention, Figure 2 shows a time flowchart of a second embodiment of the method of the invention. DETAILED DESCRIPTION OF EMBODIMENTS OF THE INVENTION
[0050] For a more complete understanding of the invention, the invention will now be described in detail with reference to the accompanying drawing. The detailed description will illustrate and describe what is considered as a preferred embodiment of the invention. It should of course be understood that various modifications and changes in form or detail could readily be made without departing from the scope of the invention. It is therefore intended that the invention may not be limited to the exact form and detail shown and described herein, nor to anything less than the whole of the invention disclosed herein and as claimed hereinafter. The same elements have been designated with the same references in the different drawings. For clarity, only those elements and steps which are useful to the understanding of the present invention have been shown in the drawings and will be described.
[0051] Figure 1 schematically shows a flowchart of a method of the invention. The invention concerns GBA and AKMA as bootstrapping technologies implemented in 5G.
[0052] The following illustrative description is done for an AKMA bootstrapping but similar functional entities exist in GBA or in other bootstrapping technologies and the implementation of the invention would be similar.
[0053] In this exemplary flowchart, a user equipment UE is in roaming situation with a visited Public Land Mobile Network, VPLMN, having a visited AKMA anchor function vAAnF. While attaching to the VPLMN, the UE has been provided by a Generic Universal Temporary Identifier GUTI.
[0054] As a pre-requisite of the invention, the UE was registered and has derived bootstrapping AF keys, in a step S0, for the use of application functions AF using a Bootstrapping technology, typically AKMA-based AF keys for the use of several AF.
[0055] This prerequisite can be done before or during the roaming situation as soon as the UE can enter in relation with the AF. For this registration, the UE is in communication with an Access and Mobility Management Function, AMF, in 5G, and with an Authentication Server Function, AUSF.
[0056] The registration is done for the use of an Application Function AF managed by the HPLMN of the UE or another entity. In such situation, this can be the anchor function hAAnF of the HPLMN which derives the keys relative to the bootstrapping technology, but the AF key can also be managed and thus provided by any other third party habilitated to manage such AF.
[0057] A primary authentication and an establishment of useful keys for the bootstrapping technology is thus performed in the preliminary step S0.
[0058] The useful keys, including at least a master bootstrapping key mKBS from which the application function keys will be derived, are then stored in the Anchor Function hAAnF, which belongs here to the HPLMN. It could also be an anchor function belonging to a third party which manages the application function AF. This step in a pre-requisite of the method of the invention.
[0059] Then, in a step S1, the UE, while in roaming situation, requests an Application session establishment with the AF. This implies the sending of an AKMA Key identifier of UE A-KID in an AKMA infrastructure. The identifier that would be used in a GBA infrastructure is B-TID.
[0060] In a step S2, the AF then sends a request for an application key KAF with A-KID and an AF identifier AF_ID. This request is done to the Anchor Function hAAnF in charge of the management of the AF and with which the UE has previously proceeded to a primary authentication and establishment of a master bootstrapping key mKBS.
[0061] In a step S3, the hAAnF derives an application function key KAF from the master bootstrapping key mKBS as previously stored.
[0062] Then, in a step S4, the hAAnF answers to the AF while sending at least the key KAF and, advantageously, a key expiration time.
[0063] In a step S5, as the hAAnF is informed of the visited PLMN of the UE, the hAAnF also sends the key KAF to the visited Anchor Function vAAnF. The vAAnF is the entity receiving the KAF from the HPLMN of the UE or from the third party which manages the application function. Here it is thus noted that it could be another third party than the hAAnF that would be informed of the visited PLMN of the UE in order to be able to provide the necessary AF key.
[0064] Step S4 triggers an answer, in a step S6, of the AF to the UE informing the UE that an application session is established.
[0065] In a first embodiment of the invention, after the Application Session establishment response, messages are exchanged in the direction from the UE, in roaming situation, to the AMF, which then communicates with the vAAnF.
[0066] In a step S10, the UE encrypts the GUTI with KAF. Alternatively, the UE can also calculate an integrity value of the GUTI with KAF as an encrypted GUTI.
[0067] It then sends, in a step S11, the encrypted GUTle to the AMF together with an identifier enabling to retrieve the appropriate KAF in the targeted VAAnF.
[0068] In a step S12, the AMF, which knows the GUTI, forwards to the vAAnF both the encrypted GUTle and the GUTI in clear text with the identifier enabling to retrieve the appropriate KAF in the targeted VAAnF.
[0069] In a step S13, the vAAnF then deciphers the encrypted GUTle with the KAFp as received from the hAAnF of the HPLMN or from third party that manages the AF. Alternatively, the vAAnF calculates an integrity value GUTId of the GUTI in clear text as received with the KAFp as received from the hAAnF of the HPLMN or from third party that manages the AF.
[0070] The deciphered GUTId is compared with the received GUTI in clear text in a step S14. Alternatively, the calculated integrity value GUTId is compared with the received integrity GUTI value.
[0071] In a step S15, the vAAnF sends a message to the AMF indicating if the GUTI verification was successful or not, with the identifier enabling to retrieve the appropriate KAF in the UE.
[0072] The AMF then sends message to the UE indicating if the GUTI verification was successful or not, as illustrated by a step S16.
[0073] The UE then uses the application function AF only in the case the verification was successful.
[0074] In a second embodiment, shown on figure 2, after the Application Session establishment response of step S6, messages are exchanged from the vAAnF to the AMF, which then forwards them to the UE.
[0075] In a first step S20, the vAAnF contacts the AMF to obtain the GUTI in a step S21.
[0076] Then, in a step S22, the vAAnF encrypts the GUTI with the key KAFp as received from the hAAnF.
[0077] The vAAnF then sends the encrypted GUTle to the AMF in a step S23, together with an identifier enabling to retrieve the appropriate KAF in the UE.
[0078] The AMF forwards the encrypted GUTle to the UE in a step S24, together with an identifier enabling to retrieve the appropriate KAF.
[0079] In a step S25, the UE decrypts the GUTI with the appropriate key KAF.
[0080] The UE then compares the decrypted value GUTId with the GUTI stored in the UE in a step S26.
[0081] The UE sends a message to the AMF indicating if the GUTI verification was successful or not, in a step S27.
[0082] The AMF then forwards the indication to the vAAnF in a step S28.
[0083] The UE uses the application function only if the verification was successful.
[0084] With the invention, as soon as the UE is in roaming, the UE checks whether the GUTI verification has been performed while having requested any use of any application function AF. The applicative steps with the AF then take place only if the GUTI verification took place. The solutions apply to any application using bootstrapping technologies, typically AKMA and GBA.
[0085] In the above detailed description, reference is made to the accompanying drawings that show, by way of illustration, specific embodiments in which the invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the invention. The above detailed description is, therefore, not to be taken in a limiting sense, and the scope of the present invention is defined only by the appended claims, appropriately interpreted.
[0086] Specifically, the use of an integrity value as an encrypted value is under the scope of the invention. In this case, the decryption step is indeed a calculation of the integrity value using the AF key without departing from the principles of the invention, which solves the problem of enabling lawful interception for an application by enabling to check that a correct application key was provided. The scope of protection sought for is defined by the appended claims.
Claims
1. Method to enable lawful interception of activities of a user equipment, UE, with an application function, AF, associated to a bootstrapping technology, said activities using an AF key, while said UE is in a roaming situation with a visited Public Land Mobile Network, PLMN, using at least one parameter known by both said UE and said visited PLMN, said visited PLMN having been provided, for lawful interception purposes, with a said provided application function key, said method comprising the steps of, respectively, for said UE or for said visited PLMN: - sending (S11, S12, S23, S24) said parameter known by both said UE and said visited PLMN encrypted with, respectively, said AF key or said provided AF key, to, respectively, said visited PLMN or said UE, and for, respectively, said visited PLMN or said UE, which received the encrypted parameter: - decrypting (S13, S25) said encrypted parameter with, respectively, said provided AF key or said AF key, and - comparing (S14, S26) said decrypted parameter with the parameter as known by, respectively, said visited PLMN or said UE which received said encrypted parameter, - authorizing (S15, S16, S27, S28) the use of said AF only if the comparison shows that both parameters are the same.
2. Method according to claim 1, wherein said parameter known by both said UE and said visited PLMN is a Generic Universal Temporary Identifier, GUTI.
3. Method according to one of preceding claims, wherein an application function identifier to identify the concerned AF is included in exchanges between said UE and said visited PLMN.
4. Method according to one of preceding claims, wherein said UE having a Home Public Land Mobile Network, HPLMN, the provisioning of the application function key is done by said HPLMN.
5. Method according to one of preceding claims, wherein the bootstrapping technology implementing an Anchor Function in PLMN, said anchor function storing application function keys resulting from bootstrapping technology, the steps as performed by said visited PLMN are performed by the Anchor Function of said visited PLMN.
6. Method according to one of preceding claims, wherein the roaming situation using an access management function, the step of, for the entity which encrypts said parameter known by both said UE and said visited PLMN, sending the encrypted parameter to the other entity comprises a sub-step of, for the encrypting entity, to send said encrypted parameter to the access management function which forwards it to the other entity.
7. User equipment, UE, having roaming features with a visited PLMN using a parameter known by both said UE and said visited PLMN and having a duty to enable lawful interception of its activities with an application function AF associated to a bootstrapping technology, said activities using an AF key stored in said UE, said UE comprising: - an encryption / decryption module adapted to encrypt said parameter known by both said UE and said visited PLMN using the stored AF key and / or to decrypt a received encrypted parameter using said stored AF key, - a reception / transmission module adapted to send (S11, S12) said encrypted parameter to said visited PLMN and / or to receive (S23, S24) said encrypted parameter from said visited PLMN, - a processing module adapted to compare (S26) a decrypted parameter with said parameter as known by said UE in the case where said parameter is decrypted, the reception / transmission module being, in this case, further adapted to send (S27, S28) the result of the comparison to an access management function for it to authorize the use of said application function AF only if said comparison shows that both parameters are the same.
8. PLMN adapted to attach a user equipment, UE, in a roaming situation as a visited Public Land Mobile Network, PLMN, using a parameter known by both said UE and itself as a visited PLMN and adapted to enable lawful interception of activities of said UE with an application function, AF, associated to a bootstrapping technology, said AF being owned by a third party of said PLMN, said activities using an AF key, said PLMN being adapted to be provided with an application function key, said PLMN further comprising: - an encryption / decryption module adapted to encrypt (S22) said parameter using the provided AF key and / or to decrypt a received encrypted parameter using said provided AF key, - a reception / transmission module adapted to send (S23, S24) said encrypted parameter to said UE and / or to receive (S11, S12) said encrypted parameter from said UE, - a processing module adapted to compare (S14) a decrypted parameter with the parameter as known by said PLMN in the case where said encrypted parameter is decrypted by said PLMN, said reception / transmission module being, in this case, further adapted to send (S15, S16) the result of the comparison to an access management function for it to authorize the use of said AF only if said comparison shows that both parameters are the same.
9. PLMN according to claim 8, said PLMN having a bootstrapping Anchor Function adapted to perform the steps of the method of claims 1 to 6.