Abstract: A method of handling security mode control wherein when a UE is in a limited state on a cell and does not have any NAS security context. The UE initiates emergency registration procedure. The UE establishes the RRC Connection and sends Registration Request message containing only cleartext IEs in RRC setup complete message. In other words, the Registration Request message doesn"t include non-cleartext IEs even if the UE needs to send non-cleartext IEs in step 4, because there is no NAS security contexts set up between UE and AMF. A person skilled in the art would appreciate that the cleartext IEs are information elements that can be sent without confidentiality protection in initial NAS messages (e.g. Registration request message) and the non-cleartext IEs are information elements that are not cleartext IEs.
1. A method of handling security mode control in a communication session between a User Equipment and a network comprising the steps of: sending, to a base station, an emergency registration request by the UE; establishing and sending, by the UE, a registration request message to the base station; sending, by the UE, the registration complete message; sending, by the base station, the registration request message to the network; performing, by the network, an authentication procedure and a Security Mode Control procedure by sending Security Mode Command message to the UE; sending, by the UE a Security mode reject message upon detection of a mismatch in UE security capability, by the UE; securing subsequent message, by the UE; wherein the network registers the user equipment for the emergency services.
2. The method as claimed in claim 1, wherein the registration request message comprises of cleartext information elements (IEs).
3. The method as claimed in claim 1, wherein the Security Mode Command message is different with the latest values sent by the UE to the network.
4. The method as claimed in claim 1, wherein the network is configured to include selected security information elements.
5. The method as claimed in claim 1, wherein Security mode reject message comprises of information including information elements and the cleartext information elements.
6. The method as claimed in claim 1, wherein the subsequent message is secured by the UE and the network by performing ciphering and integrity procedure.
7. A method of handling security mode control in a communication session between a User Equipment and a network comprising the steps of: sending, to a base station, an emergency registration request by the UE; 25 establishing and sending, by the UE, a registration request message to the base station; sending, by the UE, an encrypted registration complete message; sending, by the base station, the registration request message to the network; performing, by the network, an authentication procedure and a Security Mode Control procedure by sending Security Mode Command message to the UE; sending, by the UE a Security mode reject message upon detection of a mismatch in UE security capability, by the UE; securing subsequent message, by the UE; wherein the network registers the user equipment for the emergency services.
8. The method as claimed in claim 7, wherein the UE is registered to the network for normal services and have a Protocol data unit session for emergency services.
9. The method as claimed in claim 7, wherein the registration request message comprises of cleartext information elements (IEs).
10. The method as claimed in claim 7, wherein the Security Mode Command message is different with the latest values sent by the UE to the network.
11. The method as claimed in claim 7, wherein the network is configured to include selected security information elements.
12. The method as claimed in claim 7, wherein Security mode reject message comprises of information including information elements and the cleartext information elements.
13. The method as claimed in claim 7, wherein the UE and the network is configured to release non-emergency PDU sessions upon detection of mismatch in UE security capability by the UE.
14. The method as claimed in claim 7, wherein the subsequent message is secured by the UE and the network by performing ciphering and integrity procedure. 26
15. A User Equipment for handling security mode control in a communication session with a network comprises of a: a Communication control module; an operating system; a controller; a transceiver circuit; wherein the communication control module is configured to send an emergency registration request to the network; the controller is configured to establish a session with the network; the controller is further configured to perform an authentication with the network; wherein a transceiver control module of the UE is configured to send a security mode reject message upon detection of the mismatch in the UE security capability detected by the Controller; wherein the operating system of the UE is configured to secure the subsequent messages with the network by performing ciphering and integrity procedure stored in a memory of the UE.
16. A network for handling security mode control in a communication session with a UE comprises of : a Communication control module; an operating system; a controller; a transceiver circuit; wherein the communication control module is configured to receive an emergency registration request sent by the UE; the controller is configured to establish a session with the UE; the controller is further configured to perform an authentication with the UE; wherein a transceiver control module of the network is configured to receive a security mode reject message upon detection of the mismatch in the UE security capability; wherein the operating system of the network is configured to secure the subsequent messages with the UE by performing ciphering and integrity procedure stored in a memory of the network.
Background of the Invention
[0001] The 5GS system performs authentication procedure for mutual authentication of the UE and the network and to generate NAS Security keys (e.g. keys KAUSF, KSEAF and KAMF) used for the ciphering and integrity protection. After the successful mutual authentication procedure the network initiates security mode control procedure to take a NAS security context into use, and initializes and starts NAS signaling security between the UE and the network with the corresponding NAS keys and NAS security algorithms. After the successful security mode control procedure the UE and the network will start using the NAS security context. During the security mode control procedure, the UE checks a UE security capability that is received from the network by comparing with the UE security capability that has been sent to the network during the registration procedure if the network has correct UE security capabilities or not.
[0002] According to the specification 3GPP TS 24.501 [4], during the security mode control procedure when the UE receives Security mode command message then the UE detects that the network included the Selected EPS NAS security algorithms IE in the SECURITY MODE COMMAND message without including a Replayed S1 UE security capabilities IE, or that the received replayed UE security capabilities have been altered compared to the latest values that the UE sent to the network, the UE shall set the cause value to #23 "UE security capabilities mismatch". The network will terminate the procedure which triggers the security mode control procedure
[0003] In this case (i.e. mismatch case), if the UE has PDU session for emergency services then this security mode control procedure will release the emergency services. This will create drop in emergency services. This means that the emergency services, as to be treated as the highest priority in 3GPP system, may not be provided and this may cause a significant negative impacts to the social life as the emergency services are considered as the social infrastructure that citizen can rely on.
3
[0004] Similarly, in this case (i.e. mismatch case), if the UE is about to initiate an emergency service then this security mode control procedure will release the emergency service. This will create drop in emergency service.
[0005] When the UE and the 5GC cannot establish the 5G NAS security context and therefore cannot protect a NAS message with integrity or ciphering then the man in the middle can change the value of a sensitive information or delete the sensitive information from the UE and the UE cannot detect this. This will lead to un-deterministic UE behavior or in some cases denial of service.
[0006] Therefore, there is need to overcome the problems existed in order to enable UE and the network for handling of emergency bearer service when the security mode control procedure fails.
SUMMARY OF THE PRESENT INVENTION
[0007] The following presents a simplified summary of the subject matter in order to provide a basic understanding of some aspects of subject matter embodiments. This summary is not an extensive overview of the subject matter. It is not intended to identify key/critical elements of the embodiments or to delineate the scope of the subject matter.
[0008] In order to overcome at least the problems as discussed above, a method of handling security mode control in a communication session between a User Equipment and a network comprises of the steps of sending, to a base station, an emergency registration request by the UE; establishing and sending, by the UE, a registration request message to the base station; sending, by the UE, the registration complete message; sending, by the base station, the registration request message to the network; performing, by the network, an authentication procedure and a Security Mode Control procedure by sending Security Mode Command message to the UE; sending, by the UE a Security mode reject message upon detection of a mismatch in UE security capability, by the UE; securing subsequent message, by the UE; wherein the network registers the user equipment for the emergency services.
[0009] In an embodiment of the present invention, the registration request message comprises of cleartext information elements (IEs) and the Security Mode Command message is different with the latest values sent by the UE to the network.
4
[0010] The network of the present invention is also configured to include selected security information elements. The Security mode reject message comprises of information including information elements and the cleartext information elements.
[0011] In an embodiment of the present invention the subsequent message is secured by the UE and the network by performing ciphering and integrity procedure.
[0012] In an another embodiment of the present invention, a method of handling security mode control in a communication session between a User Equipment and a network is described, wherein the method comprises of sending, to a base station, an emergency registration request by the UE; establishing and sending, by the UE, a registration request message to the base station; sending, by the UE, an encrypted registration complete message; sending, by the base station, the registration request message to the network; performing, by the network, an authentication procedure and a Security Mode Control procedure by sending Security Mode Command message to the UE; sending, by the UE a Security mode reject message upon detection of a mismatch in UE security capability, by the UE; securing subsequent message, by the UE; wherein the network registers the user equipment for the emergency services.
[0013] As per the present invention, the UE is registered to the network for normal services and have a Protocol data unit session for emergency services. Further, the registration request message comprises of cleartext information elements (IEs) and wherein the Security Mode Command message is different with the latest values sent by the UE to the network.
[0014] The network of the present invention is also configured to include selected security information elements and wherein Security mode reject message comprises of information including information elements and the cleartext information elements.
[0015] In an another embodiment of the present invention, the UE and the network is configured to release non-emergency PDU sessions upon detection of mismatch in UE security capability by the UE and wherein the subsequent message is secured by the UE and the network by performing ciphering and integrity procedure.
[0016] In yet another embodiment of the present invention, a User Equipment for handling security mode control in a communication session with a network is disclosed which comprises of a Communication control module; an operating system; a controller; a transceiver circuit; wherein the communication control module is configured to send an
5
emergency registration request to the network; the controller is configured to establish a session with the network; the controller is further configured to perform an authentication with the network; wherein a transceiver control module of the UE is configured to send a security mode reject message upon detection of the mismatch in the UE security capability detected by the Controller; wherein the operating system of the UE is configured to secure the subsequent messages with the network by performing ciphering and integrity procedure stored in a memory of the UE.
[0017] In yet another embodiment of the present invention a network for handling security mode control in a communication session with a UE is disclosed which comprises of a Communication control module; an operating system; a controller; a transceiver circuit; wherein the communication control module is configured to receive an emergency registration request sent by the UE; the controller is configured to establish a session with the UE; the controller is further configured to perform an authentication with the UE; wherein a transceiver control module of the network is configured to receive a security mode reject message upon detection of the mismatch in the UE security capability; wherein the operating system of the network is configured to secure the subsequent messages with the UE by performing ciphering and integrity procedure stored in a memory of the network.
BRIEF DESCRIPTION OF FIGURES
[0018] The foregoing and further objects, features and advantages of the present subject matter will become apparent from the following description of exemplary embodiments with reference to the accompanying drawings, wherein like numerals are used to represent like elements.
[0019] It is to be noted, however, that the appended drawings along with the reference numerals illustrate only typical embodiments of the present subject matter, and are therefore, not to be considered for limiting of its scope, for the subject matter may admit to other equally effective embodiments.
FIGURE 1 illustrates security mode control procedure for emergency services during the Registration procedure.
6
FIGURE 2 illustrates security mode control procedure for emergency services in Service Request procedure
FIGURE 3 illustrates a block diagram of the User Equipment (UE) with the present disclosure
FIGURE 4 illustrates a block diagram of the R(AN) node with the present disclosure
FIGURE 5 illustrates a block diagram of the core network node with the present disclosure
DETAILED DESCRIPTION
[0020] Exemplary embodiments now will be described with reference to the accompanying drawings. The disclosure may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey its scope to those skilled in the art. The terminology used in the detailed description of the particular exemplary embodiments illustrated in the accompanying drawings is not intended to be limiting. In the drawings, like numbers refer to like elements.
[0021] It is to be noted, however, that the reference numerals in claims illustrate only typical embodiments of the present subject matter, and are therefore, not to be considered for limiting of its scope, for the subject matter may admit to other equally effective embodiments.
[0022] The specification may refer to “an”, “one” or “some” embodiment(s) in several locations. This does not necessarily imply that each such reference is to the same embodiment(s), or that the feature only applies to a single embodiment. Single features of different embodiments may also be combined to provide other embodiments.
[0023] As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless expressly stated otherwise. It will be further understood that the terms “includes”, “comprises”, “including” and/or “comprising” when used in this
7
specification, specify the presence of stated features, integers, steps, operations, elements, and/or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and/or groups thereof. It will be understood that when an element is referred to as being “connected” or “coupled” to another element, it can be directly connected or coupled to the other element or intervening elements may be present. Furthermore, “connected” or “coupled” as used herein may include operatively connected or coupled. As used herein, the term “and/or” includes any and all combinations and arrangements of one or more of the associated listed items.
[0024] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of the relevant art and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein.
[0025] The figures depict a simplified structure only showing some elements and functional entities, all being logical units whose implementation may differ from what is shown. The connections shown are logical connections; the actual physical connections may be different. It is apparent to a person skilled in the art that the structure may also comprise other functions and structures.
[0026] Also, all logical units described and depicted in the figures include the software and/or hardware components required for the unit to function. Further, each unit may comprise within itself one or more components which are implicitly understood. These components may be operatively coupled to each other and be configured to communicate with each other to perform the function of the said unit.
[0027] According to the different embodiments of the present invention, it is provided that when a UE is in a limited state on a cell and does not have any NAS security context. The UE initiates emergency registration procedure. The UE establishes the RRC Connection and sends Registration Request message containing only cleartext IEs in RRC setup complete message. In other words, the Registration Request message doesn't include non-cleartext IEs even if the UE needs to send non-cleartext IEs in step 4, because there is no NAS security
8
contexts set up between UE and AMF. A person skilled in the art would appreciate that the cleartext IEs are information elements that can be sent without confidentiality protection in initial NAS messages (e.g. Registration request message) and the non-cleartext IEs are information elements that are not cleartext IEs.
[0028] A person skilled in the art would also appreciate that when the initial NAS message is a Registration Request message, the cleartext IEs may be at least one of:
- Extended protocol discriminator;
- Security header type;
- Spare half octet;
- Registration request message identity;
- 5GS registration type;
- ngKSI;
- 5GS mobile identity;
- UE security capability;
- Additional GUTI;
- UE status; and
- EPS NAS message container.
[0029] Also, when the initial NAS message is a SERVICE REQUEST message, the cleartext IEs may be at least one of:
- Extended protocol discriminator;
- Security header type;
- Spare half octet;
- ngKSI;
- Service request message identity;
- Service type; and
- 5G-S-TMSI.
[0030] The UE is configured to send a Registration request message after sending the RRC setup complete message. Upon receiving the Registration request message, sent by the UE, the gNB forwards the registration request message to the 5GC in an Initial UE message. A person skilled in the art would appreciate that the registration request message can be sent via NG interface.
9
[0030] A person skilled in the art also appreciate that the 5GC maybe an AMF. Further, the 5GC executes authentication procedure and when the authentication procedure is executed successfully the network initiates Security Mode Control procedure by sending Security Mode Command message. The UE receives the Security Mode Command message and the UE detects UE security capability mismatch, for example, the network included the Selected EPS NAS security algorithms IE in the SECURITY MODE COMMAND message without including a Replayed S1 UE security capabilities IE, or the received replayed UE security capabilities have been altered compared to the latest values that the UE sent to the 5GC, the UE shall set the 5GMM cause value to #23 “UE security capabilities mismatch”. If the security mode control procedure fails at the UE for some unspecified reason then the UE shall set the 5GMM cause value to #24 security mode rejected, unspecified.
[0031] The UE is also configured to send the Security Mode Reject message containing the 5GMM cause. The Security Mode Reject message may contain entire Registration Request message containing all IEs included in the cleartext IEs. Furthermore, the Security Mode Reject message may contain non-cleartext IEs if the UE has needed to send non-cleartext IEs.
[0032] In one example the UE may set the other cause value or information element indicating that although the Security Mode setup fails, ongoing process can be proceeded as it is for emergency service.
[0033] In one example, instead of the Security Mode Reject message, the UE may use the other 5GMM message. For example, Security Mode Complete message. The Security Mode Complete message may also contain all IEs included in the cleartext IEs. Furthermore, the Security Mode Complete message may also contain non-cleartext IEs if the UE has needed to send non-cleartext IEs.
[0034] As per the present invention, the UE and the 5GC uses the standardized null ciphering algorithm and null integrity protection algorithm to protect the subsequent NAS message(s). A person skilled in the art would appreciate that the null ciphering and the null integrity protection are intended towards securing the subsequent NAS message and simultaneously the UE and the 5GC are configured to not to release the emergency service even if UE detects the UE security capability mismatch.
10
[0035] In one example the UE and the 5GC may use a dedicated ciphering algorithm and a dedicated integrity protection algorithm that are locally configured in both the UE and the 5GC wherein at least one of the dedicated configurations may be provided by gNB or 5GC. Accordingly, the 5GC sends registration accept message to the UE that is encrypted with null ciphering algorithm (5G-EA0) and integrity protected with null encryption algorithm (5G-IA0).
[0036] In one example the 5GC is configured to send a registration accept message to the UE that is encrypted with the dedicated ciphering algorithm and the dedicated integrity protection algorithm that are locally configured in both the UE and the 5GC. The 5GC may also include the Emergency only information element onto the registration accept message. The Emergency only IE indicates UE that all services, except emergency services, are restricted with this registration. Further, as soon as the Emergency services are completed, the UE may detach from the 5GS.
[0037] In another embodiment of the present invention, when the UE is registered to a PLMN for normal service and has been authenticated successfully, the UE, in that case has a valid 5G NAS security context. Further, the UE is in 5GMM –IDLE mode and has established an emergency PDU session. The UE, therefore, initiates a service request procedure. The UE establishes the RRC connection and sends Service Request message with cleartext IEs and the entire Service Request message (i.e. containing both cleartext IEs and non-cleartext IEs) in the NAS message container IE of the Service Request IE and shall cipher the value part of the NAS message container IE. The network is configured to optionally execute authentication procedure and upon the successful execution of the authentication procedure by the UE and the 5GC. A person skilled in the art would appreciate that the 5GC maybe an AMF.
[0038] The 5GC, upon successful execution of authentication, initiates security mode control procedure by sending Security Mode Command message and when the UE receives the Security Mode Command message and the UE is configured to detect UE security capability mismatch, for example, the network included the Selected EPS NAS security algorithms IE in the SECURITY MODE COMMAND message without including a Replayed S1 UE security capabilities IE, or the received replayed UE security capabilities have been altered compared to the latest values that the UE sent to the 5GC, the UE shall set the 5GMM cause
11
value to #23 "UE security capabilities mismatch". Further, if the security mode control procedure fails at the UE for some unspecified reason then the UE shall set the 5GMM cause value to #24 security mode rejected, unspecified. Also, when the UE sends Security Mode Reject message containing the 5GMM cause. The Security Mode Reject message may contain all IEs included in the cleartext IEs. Furthermore, the Security Mode Reject message may contain non-cleartext IEs if the UE has needed to send non-cleartext IEs.
[0039] In one example the UE may set the other cause value or information element indicating that although the Security Mode setup fails, ongoing process can be proceeded as it is for emergency service.
[0040] In one example, instead of the Security Mode Reject message, the UE may use the other 5GMM message. For example, Security Mode Complete message. In this case, the Security Mode Complete message may contain all IEs included in the cleartext IEs. Furthermore, the Security Mode Complete message may contain non-cleartext IEs if the UE has needed to send non-cleartext IEs.
[0041] The UE is also configured to execute either a process to release the non-emergency PDU sessions or to use null security algorithm and thereafter releases the non-emergency PDU sessions.
[0042] The UE and the 5GC are configured to use the 5G NAS security context to encrypt and integrity protect all the subsequent NAS message(s). The UE and the network releases the non-emergency PDU session(s) either locally or UE or network initiated ESM procedure. Further, the UE and the 5GC are also configured to use the null ciphering algorithm and null integrity algorithm to cipher and integrity protect all the subsequent NAS message(s). The UE and the network releases all non-emergency PDU session(s) either locally or UE or network initiated ESM procedure. In one example the UE and the 5GC uses a dedicated ciphering algorithm and a dedicated integrity protection algorithm that are locally configured in both the UE and the 5GC for emergency PDU session. Upon execution either of the process for which UE and the network are configured for, the PDU session establishment procedure takes place for emergency services and the network/5GC sends the Service Accept message to the UE for the emergency PDU session. The network/5GC may also include the Emergency only information element onto the Service Accept message. The Emergency only IE indicates UE that all services, except emergency services, are restricted and requests UE to
12
release the emergency PDU session right after the end of the Emergency services. The UE may also detach from the 5GS right after the end of the Emergency services.
[0043] In one example the UE is registered to the network for normal services and has a 5G NAS security context. The UE is also configured to initiates Service Request procedure to establish a PDU session for an emergency service.
[0044] In one example, the UE and the network will follow the same steps if the registration procedure is initiated at the UE and the UE has a valid 5G NAS security context. Therefore, the Registration Request message containing a cleartext IE(s) and entire Registration Request message with cleartext and non-cleartext IE(s) in a NAS message container IE and the value part of the NAS message container IE is ciphered with the NAS message container IE.
[0045] In yet another embodiment of the present invention, When a UE is registered to a PLMN without 5G NAS security context then the 5GC does not provide a sensitive information to the UE without integrity protection in a Non-Access Stratum (NAS) message during any NAS procedure. When the UE receives sensitive information in a NAS message without the integrity protection then the UE shall ignore the sensitive information.
[0046] In one example, in the scenario of this embodiment, the UE uses previous latest value of the sensitive information for the PLMN which was sent security protected (Ciphered or Integrity protected) while the UE is registered without 5G NAS security. The UE also subsequently uses the previous latest sensitive information value when the UE is registered and the UE and the 5GC start protecting the NAS messages with ciphering or integrity algorithm other than null ciphering or null integrity algorithm respectively.
[0047] In one example the UE and the 5GC uses the default value (pre-defined) value for the sensitive information.
[0047] In this embodiment the UE is registered to a PLMN without the 5G NAS security context for the case when the UE cannot establish the 5G NAS security context because the UE cannot perform authentication procedure (no UICC in the UE or UE context cannot be fetched) or authentication procedure fails or security mode control procedure fails; and the UE has a PDU session for an emergency service or registering to the 5GC to establish the
13
PDU session for an emergency service. In this scenario the UE and the 5GC uses the null ciphering or null integrity protection algorithm. The sensitive information element can be at least one of the following information element:
1. Equivalent PLMNs
2. TAI list
3. Allowed NSSAI
4. Rejected NSSAI
5. Configured NSSAI
6. 5GS network feature support
7. PDU session status
8. PDU session reactivation result
9. PDU session reactivation result error cause
10. LADN information
11. MICO indication
12. Network slicing indication
13. Service area list
14. T3512 value
15. Non-3GPP de-registration timer value
16. T3502 value
17. SOR transparent container
18. EAP message
19. NSSAI inclusion mode
20. Operator-defined access category definitions
21. Negotiated DRX parameters
[0048] It is also understood to a person skilled in the art that the embodiments disclosed in the present specification are applicable to ng-eNB connected to 5GC or EPC and are also applicable for the EPS and UMTS.
[0049] The User Equipment (or “UE”, “mobile station”, “mobile device” or “wireless device”) in the present disclosure is an entity connected to a network via a wireless interface.
14
[0050] It should be noted that the UE in this specification is not limited to a dedicated communication device, and can be applied to any device, having a communication function as a UE described in this specification, as explained in the following paragraphs.
[0051] The terms "User Equipment" or "UE" (as the term is used by 3GPP), "mobile station", "mobile device", and "wireless device" are generally intended to be synonymous with one another, and include standalone mobile stations, such as terminals, cell phones, smart phones, tablets, cellular IoT devices, IoT devices, and machinery.
[0052] It will be appreciated that the terms “UE” and “wireless device” also encompass devices that remain stationary for a long period of time.
[0053] A UE may, for example, be an item of equipment for production or manufacture and/or an item of energy related machinery (for example equipment or machinery such as: boilers; engines; turbines; solar panels; wind turbines; hydroelectric generators; thermal power generators; nuclear electricity generators; batteries; nuclear systems and/or associated equipment; heavy electrical machinery; pumps including vacuum pumps; compressors; fans; blowers; oil hydraulic equipment; pneumatic equipment; metal working machinery; manipulators; robots and/or their application systems; tools; molds or dies; rolls; conveying equipment; elevating equipment; materials handling equipment; textile machinery; sewing machines; printing and/or related machinery; paper converting machinery; chemical machinery; mining and/or construction machinery and/or related equipment; machinery and/or implements for agriculture, forestry and/or fisheries; safety and/or environment preservation equipment; tractors; precision bearings; chains; gears; power transmission equipment; lubricating equipment; valves; pipe fittings; and/or application systems for any of the previously mentioned equipment or machinery etc.).
[0054] A UE may, for example, be an item of transport equipment (for example transport equipment such as: rolling stocks; motor vehicles; motor cycles; bicycles; trains; buses; carts; rickshaws; ships and other watercraft; aircraft; rockets; satellites; drones; balloons etc.).
[0055] A UE may, for example, be an item of information and communication equipment (for example information and communication equipment such as: electronic computer and related equipment; communication and related equipment; electronic components etc.).
15
[0056] A UE may, for example, be a refrigerating machine, a refrigerating machine applied product, an item of trade and/or service industry equipment, a vending machine, an automatic service machine, an office machine or equipment, a consumer electronic and electronic appliance (for example a consumer electronic appliance such as: audio equipment; video equipment; a loud speaker; a radio; a television; a microwave oven; a rice cooker; a coffee machine; a dishwasher; a washing machine; a dryer; an electronic fan or related appliance; a cleaner etc.).
[0057] A UE may, for example, be an electrical application system or equipment (for example an electrical application system or equipment such as: an x-ray system; a particle accelerator; radio isotope equipment; sonic equipment; electromagnetic application equipment; electronic power application equipment etc.).
[0058] A UE may, for example, be an electronic lamp, a luminaire, a measuring instrument, an analyzer, a tester, or a surveying or sensing instrument (for example a surveying or sensing instrument such as: a smoke alarm; a human alarm sensor; a motion sensor; a wireless tag etc.), a watch or clock, a laboratory instrument, optical apparatus, medical equipment and/or system, a weapon, an item of cutlery, a hand tool, or the like.
[0059] A UE may, for example, be a wireless-equipped personal digital assistant or related equipment (such as a wireless card or module designed for attachment to or for insertion into another electronic device (for example a personal computer, electrical measuring machine)).
[0060] A UE may be a device or a part of a system that provides applications, services, and solutions described below, as to “internet of things (IoT)”, using a variety of wired and/or wireless communication technologies.
[0061] Internet of Things devices (or "things") may be equipped with appropriate electronics, software, sensors, network connectivity, and/or the like, which enable these devices to collect and exchange data with each other and with other communication devices. IoT devices may comprise automated equipment that follow software instructions stored in an internal memory. IoT devices may operate without requiring human supervision or interaction. IoT devices might also remain stationary and/or inactive for a long period of time. IoT devices
16
may be implemented as a part of a (generally) stationary apparatus. IoT devices may also be embedded in non-stationary apparatus (e.g. vehicles) or attached to animals or persons to be monitored/tracked.
[0062] It will be appreciated that IoT technology can be implemented on any communication devices that can connect to a communications network for sending/receiving data, regardless of whether such communication devices are controlled by human input or software instructions stored in memory.
[0063] It will be appreciated that IoT devices are sometimes also referred to as Machine-Type Communication (MTC) devices or Machine-to-Machine (M2M) communication devices or Narrow Band-IoT UE (NB-IoT UE). It will be appreciated that a UE may support one or more IoT or MTC applications. Some examples of MTC applications are listed in the Table 1 (source: 33GPP TS 22.368 [3], Annex B, the contents of which are incorporated herein by reference). This list is not exhaustive and is intended to be indicative of some examples of machine-type communication applications.
Table 1: Some examples of machine-type communication applications.
Service Area
MTC applications
Security
Surveillance systems
Backup for landline
Control of physical access (e.g. to buildings)
Car/driver security
Tracking & Tracing
Fleet Management
Order Management
Pay as you drive
Asset Tracking
Navigation
Traffic information
Road tolling
Road traffic optimisation/steering
Payment
Point of sales
17
Vending machines
Gaming machines
Health
Monitoring vital signs
Supporting the aged or handicapped
Web Access Telemedicine points
Remote diagnostics
Remote Maintenance/Control
Sensors
Lighting
Pumps
Valves
Elevator control
Vending machine control
Vehicle diagnostics
Metering
Power
Gas
Water
Heating
Grid control
Industrial metering
Consumer Devices
Digital photo frame
Digital camera
eBook
[0064] Applications, services, and solutions may be an MVNO (Mobile Virtual Network Operator) service, an emergency radio communication system, a PBX (Private Branch eXchange) system, a PHS/Digital Cordless Telecommunications system, a POS (Point of sale) system, an advertise calling system, an MBMS (Multimedia Broadcast and Multicast Service), a V2X (Vehicle to Everything) system, a train radio system, a location related service, a Disaster/Emergency Wireless Communication Service, a community service, a video streaming service, a femto cell application service, a VoLTE (Voice over LTE) service, a charging service, a radio on demand service, a roaming service, an activity monitoring service, a telecom carrier/communication NW selection service, a functional restriction
18
service, a PoC (Proof of Concept) service, a personal information management service, an ad-hoc network/DTN (Delay Tolerant Networking) service, etc.
[0065] Further, the above-described UE categories are merely examples of applications of the technical ideas and exemplary embodiments described in the present document. Needless to say, these technical ideas and embodiments are not limited to the above-described UE and various modifications can be made thereto.
[0066] Figure 3 is a block diagram illustrating the main components of the UE. As shown, the UE includes a transceiver circuit which is operable to transmit signals to and to receive signals from the connected node(s) via one or more antenna. Although not necessarily shown in Figure 9, the UE will of course have all the usual functionality of a conventional mobile device (such as a user interface) and this may be provided by any one or any combination of hardware, software and firmware, as appropriate. Software may be pre-installed in the memory and/or may be downloaded via the telecommunication network or from a removable data storage device (RMD), for example.
[0067] A controller controls the operation of the UE in accordance with software stored in a memory. For example, the controller may be realized by Central Processing Unit (CPU). The software includes, among other things, an operating system and a communications control module having at least a transceiver control module. The communications control module (using its transceiver control sub-module) is responsible for handling (generating/sending/receiving) signalling and uplink/downlink data packets between the UE and other nodes, such as the base station / (R)AN node, a MME, the AMF (and other core network nodes). Such signalling may include, for example, appropriately formatted signalling messages relating to connection establishment and maintenance (e.g. RRC messages,), NAS messages such as periodic location update related messages (e.g. tracking area update, paging area updates, location area update) etc.
[0068] Figure 4 is a block diagram illustrating the main components of an exemplary (R)AN node, for example a base station ('eNB' in LTE, ‘gNB’ in 5G). As shown, the (R)AN node includes a transceiver circuit which is operable to transmit signals to and to receive signals from connected UE(s) via one or more antenna and to transmit signals to and to receive signals from other network nodes (either directly or indirectly) via a network interface. A
19
controller controls the operation of the (R)AN node in accordance with software stored in a memory. For example, the controller may be realized by Central Processing Unit (CPU). Software may be pre-installed in the memory and/or may be downloaded via the telecommunication network or from a removable data storage device (RMD), for example. The software includes, among other things, an operating system and a communications control module having at least a transceiver control module.
[0069] The communications control module (using its transceiver control sub-module) is responsible for handling (generating/sending/receiving) signalling between the (R)AN node and other nodes, such as the UE, the MME, the AMF(e.g. directly or indirectly). The signalling may include, for example, appropriately formatted signalling messages relating to a radio connection and location procedures (for a particular UE), and in particular, relating to connection establishment and maintenance (e.g. RRC connection establishment and other RRC messages), periodic location update related messages (e.g. tracking area update, paging area updates, location area update), S1 AP messages and NG AP messages (i.e. messages by N2 reference point), etc. Such signalling may also include, for example, broadcast information (e.g. Master Information and System information) in a sending case.
[0070] The controller is also configured (by software or hardware) to handle related tasks such as, when implemented, UE mobility estimate and/or moving trajectory estimation.
[0071] Figure 5 is a block diagram illustrating the main components of the AMF. The AMF is included in the 5GC. As shown, the AMF includes a transceiver circuit which is operable to transmit signals to and to receive signals from other nodes (including the UE) via a network interface. A controller controls the operation of the AMF in accordance with software stored in a memory. For example, the controller may be realized by Central Processing Unit (CPU). Software may be pre-installed in the memory and/or may be downloaded via the telecommunication network or from a removable data storage device (RMD), for example. The software includes, among other things, an operating system and a communications control module having at least a transceiver control module.
[0072] The communications control module (using its transceiver control sub-module) is responsible for handling (generating/sending/ receiving) signalling between the AMF and other nodes, such as the UE, base station/(R)AN node (e.g. "gNB" or "eNB") (directly or
20
indirectly). Such signalling may include, for example, appropriately formatted signalling messages relating to the procedures described herein, for example, NG AP message (i.e. a message by N2 reference point) to convey an NAS message from and to the UE, etc.
[0073] As will be appreciated by one of skill in the art, the present disclosure may be embodied as a method, and system. Accordingly, the present disclosure may take the form of an entirely hardware embodiment, a software embodiment or an embodiment combining software and hardware aspects.
[0074] It will be understood that each block of the block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions/acts specified in the flowchart and/or block diagram block or blocks. A general-purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, e.g., a plurality of microprocessors, one or more microprocessors, or any other such configuration.
[0075] The methods or algorithms described in connection with the examples disclosed herein may be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. A storage medium may be coupled to the processor such that the processor can read information from, and write information to, the storage medium. In the alternative, the storage medium may be integral to the processor. The processor and the storage medium may reside in an ASIC.
[0076] The previous description of the disclosed examples is provided to enable any person skilled in the art to make or use the present invention. Various modifications to these examples will be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to other examples without departing from the spirit or scope of
21
the invention. Thus, the present invention is not intended to be limited to the examples shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0077] For the purposes of the present document, the abbreviations given in 3GPP TR 21.905 [1] and the following apply. An abbreviation defined in the present document takes precedence over the definition of the same abbreviation, if any, in 3GPP TR 21.905 [1].
5GC 5G Core Network
5GS 5G System
5G-AN 5G Access Network
5G-GUTI 5G Globally Unique Temporary Identifier
5G S-TMSI 5G S-Temporary Mobile Subscription Identifier
5QI 5G QoS Identifier
AF Application Function
AMF Access and Mobility Management Function
AN Access Node
AS Access Stratum
AUSF Authentication Server Function
CM Connection Management
CP Control Plane
CSFB Circuit Switched (CS) Fallback
DL Downlink
DN Data Network
DNAI DN Access Identifier
DNN Data Network Name
EDT Early Data Transmission
EPS Evolved Packet System
EPC Evolved Packet Core
FQDN Fully Qualified Domain Name
GFBR Guaranteed Flow Bit Rate
GMLC Gateway Mobile Location Centre
GPSI Generic Public Subscription Identifier
GUAMI Globally Unique AMF Identifier
HR Home Routed (roaming)
22
I-RNTI I-Radio Network Temporary Identifier
LADN Local Area Data Network
LBO Local Break Out (roaming)
LMF Location Management Function
LRF Location Retrieval Function
MAC Medium Access Control
MFBR Maximum Flow Bit Rate
MICO Mobile Initiated Connection Only
MME Mobility Management Entity
N3IWF Non-3GPP Inter Working Function
NAI Network Access Identifier
NAS Non-Access Stratum
NEF Network Exposure Function
NF Network Function
NG-RAN Next Generation Radio Access Network
NR New Radio
NRF Network Repository Function
NSI ID Network Slice Instance Identifier
NSSAI Network Slice Selection Assistance Information
NSSF Network Slice Selection Function
NSSP Network Slice Selection Policy
PCF Policy Control Function
PEI Permanent Equipment Identifier
PER Packet Error Rate
PFD Packet Flow Description
PLMN Public land mobile network
PPD Paging Policy Differentiation
PPI Paging Policy Indicator
PSA PDU Session Anchor
QFI QoS Flow Identifier
QoE Quality of Experience
(R)AN (Radio) Access Network
RLC Radio Link Control
RM Registration Management
23
RQA Reflective QoS Attribute
RQI Reflective QoS Indication
RRC Radio Resource Control
SA NR Standalone New Radio
SBA Service Based Architecture
SBI Service Based Interface
SD Slice Differentiator
SDAP Service Data Adaptation Protocol
SEAF Security Anchor Functionality
SEPP Security Edge Protection Proxy
SMF Session Management Function
S-NSSAI Single Network Slice Selection Assistance Information
SSC Session and Service Continuity
SST Slice/Service Type
SUCI Subscription Concealed Identifier
SUPI Subscription Permanent Identifier
UDSF Unstructured Data Storage Function
UICC Universal Integrated Circuit Card
UL Uplink
UL CL Uplink Classifier
USIM Universal Subscriber Identity Module
UPF User Plane Function
UDR Unified Data Repository
URSP UE Route Selection Policy
SMS Short Message Service
SMSF SMS Function
MT Mobile Terminated
UAC Unified Access Control
ODACD Operator Defined Access Category Definitions
OS Operating System
We Claim:
1. A method of handling security mode control in a communication session between a User Equipment and a network comprising the steps of:
sending, to a base station, an emergency registration request by the UE;
establishing and sending, by the UE, a registration request message to the base station;
sending, by the UE, the registration complete message;
sending, by the base station, the registration request message to the network;
performing, by the network, an authentication procedure and a Security Mode Control procedure by sending Security Mode Command message to the UE;
sending, by the UE a Security mode reject message upon detection of a mismatch in UE security capability, by the UE;
securing subsequent message, by the UE;
wherein the network registers the user equipment for the emergency services.
2. The method as claimed in claim 1, wherein the registration request message comprises of cleartext information elements (IEs).
3. The method as claimed in claim 1, wherein the Security Mode Command message is different with the latest values sent by the UE to the network.
4. The method as claimed in claim 1, wherein the network is configured to include selected security information elements.
5. The method as claimed in claim 1, wherein Security mode reject message comprises of information including information elements and the cleartext information elements.
6. The method as claimed in claim 1, wherein the subsequent message is secured by the UE and the network by performing ciphering and integrity procedure.
7. A method of handling security mode control in a communication session between a User Equipment and a network comprising the steps of:
sending, to a base station, an emergency registration request by the UE;
25
establishing and sending, by the UE, a registration request message to the base station;
sending, by the UE, an encrypted registration complete message;
sending, by the base station, the registration request message to the network;
performing, by the network, an authentication procedure and a Security Mode Control procedure by sending Security Mode Command message to the UE;
sending, by the UE a Security mode reject message upon detection of a mismatch in UE security capability, by the UE;
securing subsequent message, by the UE;
wherein the network registers the user equipment for the emergency services.
8. The method as claimed in claim 7, wherein the UE is registered to the network for normal services and have a Protocol data unit session for emergency services.
9. The method as claimed in claim 7, wherein the registration request message comprises of cleartext information elements (IEs).
10. The method as claimed in claim 7, wherein the Security Mode Command message is different with the latest values sent by the UE to the network.
11. The method as claimed in claim 7, wherein the network is configured to include selected security information elements.
12. The method as claimed in claim 7, wherein Security mode reject message comprises of information including information elements and the cleartext information elements.
13. The method as claimed in claim 7, wherein the UE and the network is configured to release non-emergency PDU sessions upon detection of mismatch in UE security capability by the UE.
14. The method as claimed in claim 7, wherein the subsequent message is secured by the UE and the network by performing ciphering and integrity procedure.
26
15. A User Equipment for handling security mode control in a communication session with a network comprises of a:
a Communication control module;
an operating system;
a controller;
a transceiver circuit;
wherein the communication control module is configured to send an emergency registration request to the network;
the controller is configured to establish a session with the network;
the controller is further configured to perform an authentication with the network; wherein a transceiver control module of the UE is configured to send a security mode reject message upon detection of the mismatch in the UE security capability detected by the Controller; wherein
the operating system of the UE is configured to secure the subsequent messages with the network by performing ciphering and integrity procedure stored in a memory of the UE.
16. A network for handling security mode control in a communication session with a UE comprises of :
a Communication control module;
an operating system;
a controller;
a transceiver circuit;
wherein the communication control module is configured to receive an emergency registration request sent by the UE;
the controller is configured to establish a session with the UE;
the controller is further configured to perform an authentication with the UE; wherein a transceiver control module of the network is configured to receive a security mode reject message upon detection of the mismatch in the UE security capability; wherein the operating system of the network is configured to secure the subsequent messages with the UE by performing ciphering and integrity procedure stored in a memory of the network.
| # | Name | Date |
|---|---|---|
| 1 | 201911006084-STATEMENT OF UNDERTAKING (FORM 3) [15-02-2019(online)].pdf | 2019-02-15 |
| 2 | 201911006084-POWER OF AUTHORITY [15-02-2019(online)].pdf | 2019-02-15 |
| 3 | 201911006084-FORM 1 [15-02-2019(online)].pdf | 2019-02-15 |
| 4 | 201911006084-DRAWINGS [15-02-2019(online)].pdf | 2019-02-15 |
| 5 | 201911006084-DECLARATION OF INVENTORSHIP (FORM 5) [15-02-2019(online)].pdf | 2019-02-15 |
| 6 | 201911006084-COMPLETE SPECIFICATION [15-02-2019(online)].pdf | 2019-02-15 |
| 7 | 201911006084-Power of Attorney-190219.pdf | 2019-02-20 |
| 8 | 201911006084-Correspondence-190219.pdf | 2019-02-20 |
| 9 | abstract.jpg | 2019-03-27 |
| 10 | 201911006084-Proof of Right (MANDATORY) [04-11-2019(online)].pdf | 2019-11-04 |
| 11 | 201911006084-PETITION UNDER RULE 137 [05-11-2019(online)].pdf | 2019-11-05 |
| 12 | 201911006084-Correspondence-061119.pdf | 2019-11-11 |
| 13 | 201911006084-OTHERS-061119.pdf | 2019-11-13 |
| 14 | 201911006084-Proof of Right (MANDATORY) [20-11-2019(online)].pdf | 2019-11-20 |
| 15 | 201911006084-OTHERS-251119.pdf | 2019-11-28 |
| 16 | 201911006084-Correspondence-251119.pdf | 2019-11-28 |