Abstract:
UPenc MUPenc SeNBUPenc MUPenc MUPenc SUPenc SUPenc SIn order for supporting separate ciphering at an MeNB (20) and an SeNB (30) the MeNB (20) derives separate first and second keys (K K) from a third key (K). The first key (K) is used for confidentially protecting first traffic transmitted over U Plane between the MeNB (20) and a UE (10). The first key (K) may be the same as current KUPenc or a new key. The second key (K) is used for confidentially protecting second traffic transmitted over the U Plane between the UE (10) and the SeNB (30). The MeNB (20) sends the second key (K) to the SeNB (30). The UE (10) negotiates with the MeNB (20) and derives the second key (K) based on a result of the negotiation.
Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence
c/o NEC Corporation 7 1 Shiba 5 chome Minato ku Tokyo
1088001
2. PRASAD Anand Raghawa
c/o NEC Corporation 7 1 Shiba 5 chome Minato ku Tokyo
1088001
Specification
Description
Title of Invention: APPARATUS, SYSTEM AND METHOD FOR
SCE
Technical Field
[0001] The present invention relates to an apparatus, a system and a method for SCE (Small
Cell Enhancement) or also called "dual connectivity", and particularly to a technique to
manage keys for SCE.
Background Art
[0002] The protocol architecture for SCE has been studied by 3GPP (3rd Generation
Partnership Project) as disclosed in NPLs 1 and 2.
[0003] Further, for example, NPL 3 discloses that U-Plane (User-Plane) traffic is transmitted
through an MeNB (Master evolved Node B) and an SeNB (Second eNB) in parallel for
the purpose of offloading the MeNB.
[0004] Furthermore, NPL 4 discloses that for U-Plane protocol architecture disclosed in
NPL 3, support of separate ciphering at the MeNB and the SeNB is required.
[0005] Note that LTE (Long Term Evolution) security specification is disclosed in NPL 5,
for example.
Citation List
Non Patent Literature
[0006] NPL 1: 3GPP TR 36.842, "Evolved Universal Terrestrial Radio Access (E-UTRA);
Study on Small Cell Enhancements for E-UTRA and E-UTRAN - Higher layer aspects
(Release 12)", Vl.0.0, 2013-11, Clause 8.1.1, pp. 32-47
NPL 2: 3GPP TR 36.932, "Scenarios and requirements for small cell enhancements
for E-UTRA and E-UTRAN (Release 12)", V12.1.0, 2013-03
NPL 3: R2- 133650, 3GPP TSG RAN WG2 Meeting #83bis, "Reply LS on security
aspects of protocol architectures for small cell enhancements"
NPL 4: RP- 132069, 3GPP TSG-RAN Meeting #62, "New Work Item Description;
Dual Connectivity for LTE - Core Part", Clause 8
NPL 5: 3GPP TS 33.401, "3GPP System Architecture Evolution (SAE); Security ar
chitecture (Release 12)", V12.9.0, 2013-09
Summary of Invention
Technical Problem
[0007] However, the inventors of this application have found that there is a problem that the
existing solutions do not fulfill the requirements disclosed in NPL 4.
[0008] Accordingly, an exemplary object of the present invention is to provide a solution for
supporting separate ciphering at an MeNB and an SeNB.
Solution to Problem
[0009] In order to achieve the above-mentioned object, a radio base station according to first
exemplary aspect of the present invention includes: derivation means for deriving a
first key from a second key, the first key being used for confidentially protecting traffic
transmitted over U-Plane between a different radio base station and a UE (User
Equipment) that is wirelessly connected to the radio base station, the traffic being
transmitted in parallel with traffic over the U-Plane between the radio base station and
the UE, the second key being shared between the radio base station and the UE; and
send means for sending the first key to the different radio base station.
[0010] Further, a radio base station according to second exemplary aspect of the present
invention includes: reception means for receiving a first key from a core network; and
send means for sending the first key to a different radio base station in order for the
different radio base station to derive a second key used for confidentially protecting
traffic transmitted over U-Plane between the different radio base station and a UE
wirelessly connected to the radio base station, the traffic being transmitted in parallel
with traffic over the U-Plane between the radio base station and the UE.
[001 1] Further, a radio base station according to third exemplary aspect of the present
invention includes: derivation means for deriving a first key from a second key in a
similar manner to a handover procedure, the first key being used for a different radio
base station to derive a third key that is used for confidentially protecting traffic
transmitted over U-Plane between the different radio base station and a UE wirelessly
connected to the radio base station, the traffic being transmitted in parallel with traffic
over the U-Plane between the radio base station and the UE, the second key being
shared between the radio base station and the UE; and send means for sending the first
key to the different radio base station.
[0012] Further, a radio base station according to fourth exemplary aspect of the present
invention includes: send means for sending a random value to a different radio base
station in order for the different radio base station to derive a key that is used for confi
dentially protecting traffic transmitted over U-Plane between the different radio base
station and a UE wirelessly connected to the radio base station, the traffic being
transmitted in parallel with traffic over the U-Plane between the radio base station and
the UE.
[0013] Further, a radio base station according to fifth exemplary aspect of the present
invention includes: derivation means for deriving a first key from a second key, the
first key being used for a different radio base station to derive a third key that is used
for confidentially protecting traffic transmitted over U-Plane between the different
radio base station and a UE wirelessly connected to the radio base station, the traffic
being transmitted in parallel with traffic over the U-Plane between the radio base
station and the UE, the second key being shared between the radio base station and the
UE; and send means for sending the first key to the different radio base station.
[0014] Further, a radio base station according to sixth exemplary aspect of the present
invention includes: reception means for receiving, from a different radio base station to
which a UE is wirelessly connected, a key used for confidentially protecting first
traffic transmitted over U-Plane between the UE and the radio base station, the first
traffic being transmitted in parallel with second traffic over the U-Plane between the
different radio base station and the UE, the key differing from a key used for confi
dentially protecting the second traffic.
[0015] Further, a radio base station according to seventh exemplary aspect of the present
invention includes: reception means for receiving a first key from a different radio base
station to which a UE is wirelessly connected; and derivation means for deriving, from
the first key, a second key used for confidentially protecting first traffic transmitted
over U-Plane between the UE and the radio base station, the first traffic being
transmitted in parallel with second traffic over the U-Plane between the different radio
base station and the UE, the second key differing from a key used for confidentially
protecting the second traffic.
[0016] Further, a radio base station according to eighth exemplary aspect of the present
invention includes: reception means for receiving a random value from a different
radio base station to which a UE is wirelessly connected; and derivation means for
deriving, by use of the random value, a key used for confidentially protecting first
traffic transmitted over U-Plane between the UE and the radio base station, the first
traffic being transmitted in parallel with second traffic over the U-Plane between the
different radio base station and the UE, the key differing from a key used for confi
dentially protecting the second traffic.
[0017] Further, a node according to ninth exemplary aspect of the present invention is
placed within a core network. This node includes: derivation means for deriving a key;
and send means for sending the key to a radio base station to which a UE is wirelessly
connected. The key is used for a different base station to derive a key that is used for
confidentially protecting traffic transmitted over U-Plane between the different radio
base station and a UE wirelessly connected to the radio base station, the traffic being
transmitted in parallel with traffic over the U-Plane between the radio base station and
the UE.
[0018] Further, a UE according to tenth exemplary aspect of the present invention includes:
negotiation means for negotiating with a radio base station to which the UE is
wirelessly connected; and derivation means for deriving, based on a result of the negotiation,
a key used for confidentially protecting traffic transmitted over U-Plane
between a different radio base station and the UE, the traffic being transmitted in
parallel with traffic over the U-Plane between the radio base station and the UE.
[0019] Further, a communication system according to eleventh exemplary aspect of the
present invention includes: a UE; a first radio base station to which the UE is
wirelessly connected; and a second radio base station. The first radio base station is
configured to: derive a first key from a second key, the first key being used for confi
dentially protecting traffic transmitted over U-Plane between the second radio base
station and the UE, the traffic being transmitted in parallel with traffic over the UPlane
between the first radio base station and the UE, the second key being shared
between the first radio base station and the UE; and send the first key to the second
radio base station. The second radio base station is configured to receive the first key
from the first radio base station. The UE is configured to: negotiate with the first radio
base station; and derive the first key based on a result of the negotiation.
[0020] Further, a communication system according to twelfth exemplary aspect of the
present invention includes: a UE; a first radio base station to which the UE is
wirelessly connected; a second radio base station; and a node placed within a core
network. The node is configured to: derive a first key; and send the first key to the first
radio base station. The first radio base station is configured to: receive the first key
from the node; and send the first key to the second radio base station. The second radio
base station is configured to: receive the first key from the first radio base station; and
derive, from the first key, a second key used for confidentially protecting traffic
transmitted over U-Plane between the UE and the second radio base station, the traffic
being transmitted in parallel with traffic over the U-Plane between the UE and the first
radio base station. The UE is configured to: negotiate with the first radio base station;
and derive the second key based on a result of the negotiation.
[0021] Further, a communication system according to thirteenth exemplary aspect of the
present invention includes: a UE; a first radio base station to which the UE is
wirelessly connected; and a second radio base station. The first radio base station is
configured to: derive a first key from a second key, the first key being used for the
second different radio base station to derive a third key that is used for confidentially
protecting traffic transmitted over U-Plane between the UE and the second radio base
station, the traffic being transmitted in parallel with traffic over the U-Plane between
the UE and the first radio base station, the second key being shared between the first
radio base station and the UE; and send the first key to the second radio base station.
The second radio base station is configured to: receive the first key from the first radio
base station; and derive the third key by use of the first key. The UE is configured to:
negotiate with the first radio base station; and derive the third key based on a result of
the negotiation.
[0022] Further, a communication system according to fourteenth exemplary aspect of the
present invention includes: a UE; a first radio base station to which the UE is
wirelessly connected; and a second radio base station. The first radio base station is
configured to send a random value to the second radio base station. The second radio
base station is configured to: receive the random value from the first radio base station;
and derive, by use of the random value, a key used for confidentially protecting traffic
transmitted over U-Plane between the UE and the second radio base station, the traffic
being transmitted in parallel with traffic over the U-Plane between the UE and the first
radio base station. The UE is configured to: negotiate with the first radio base station;
and derive the key based on a result of the negotiation.
[0023] Further, a method according to fifteenth exemplary aspect of the present invention
provides a method of controlling operations in a radio base station. This method
includes: deriving a first key from a second key, the first key being used for confi
dentially protecting traffic transmitted over U-Plane between a different radio base
station and a UE that is wirelessly connected to the radio base station, the traffic being
transmitted in parallel with traffic over the U-Plane between the radio base station and
the UE, the second key being shared between the radio base station and the UE; and
sending the first key to the different radio base station.
[0024] Further, a method according to sixteenth exemplary aspect of the present invention
provides a method of controlling operations in a radio base station. This method
includes: receiving a first key from a core network; and sending the first key to a
different radio base station in order for the different radio base station to derive a
second key used for confidentially protecting traffic transmitted over U-Plane between
the different radio base station and a UE wirelessly connected to the radio base station,
the traffic being transmitted in parallel with traffic over the U-Plane between the radio
base station and the UE.
[0025] Further, a method according to seventeenth exemplary aspect of the present invention
provides a method of controlling operations in a radio base station. This method
includes: deriving a first key from a second key in a similar manner to a handover
procedure, the first key being used for a different radio base station to derive a third
key that is used for confidentially protecting traffic transmitted over U-Plane between
the different radio base station and a UE wirelessly connected to the radio base station,
the traffic being transmitted in parallel with traffic over the U-Plane between the radio
base station and the UE, the second key being shared between the radio base station
and the UE; and sending the first key to the different radio base station.
[0026] Further, a method according to eighteenth exemplary aspect of the present invention
provides a method of controlling operations in a radio base station. This method
includes: sending a random value to a different radio base station in order for the
different radio base station to derive a key that is used for confidentially protecting
traffic transmitted over U-Plane between the different radio base station and a UE
wirelessly connected to the radio base station, the traffic being transmitted in parallel
with traffic over the U-Plane between the radio base station and the UE.
[0027] Further, a method according to nineteenth exemplary aspect of the present invention
provides a method of controlling operations in a radio base station. This method
includes: deriving a first key from a second key, the first key being used for a different
radio base station to derive a third key that is used for confidentially protecting traffic
transmitted over U-Plane between the different radio base station and a UE wirelessly
connected to the radio base station, the traffic being transmitted in parallel with traffic
over the U-Plane between the radio base station and the UE, the second key being
shared between the radio base station and the UE; and sending the first key to the
different radio base station.
[0028] Further, a method according to twentieth exemplary aspect of the present invention
provides a method of controlling operations in a radio base station. This method
includes: receiving, from a different radio base station to which a UE is wirelessly
connected, a key used for confidentially protecting first traffic transmitted over UPlane
between the UE and the radio base station, the first traffic being transmitted in
parallel with second traffic over the U-Plane between the different radio base station
and the UE, the key differing from a key used for confidentially protecting the second
traffic.
[0029] Further, a method according to twenty-first exemplary aspect of the present invention
provides a method of controlling operations in a radio base station. This method
includes: receiving a first key from a different radio base station to which a UE is
wirelessly connected; and deriving, from the first key, a second key used for confi
dentially protecting first traffic transmitted over U-Plane between the UE and the radio
base station, the first traffic being transmitted in parallel with second traffic over the
U-Plane between the different radio base station and the UE, the second key differing
from a key used for confidentially protecting the second traffic.
[0030] Further, a method according to twenty- second exemplary aspect of the present
invention provides a method of controlling operations in a radio base station. This
method includes: receiving a random value from a different radio base station to which
a UE is wirelessly connected; and deriving, by use of the random value, a key used for
confidentially protecting first traffic transmitted over U-Plane between the UE and the
radio base station, the first traffic being transmitted in parallel with second traffic over
the U-Plane between the different radio base station and the UE, the key differing from
a key used for confidentially protecting the second traffic.
[0031] Further, a method according to twenty-third exemplary aspect of the present
invention provides a method of controlling operations in a node placed within a core
network. This method includes: deriving a key; and sending the key to a radio base
station to which a UE is wirelessly connected. The key is used for a different base
station to derive a key that is used for confidentially protecting traffic transmitted over
U-Plane between the different radio base station and a UE wirelessly connected to the
radio base station, the traffic being transmitted in parallel with traffic over the U-Plane
between the radio base station and the UE.
[0032] Further, a method according to twenty-fourth exemplary aspect of the present
invention provides a method of controlling operations in a UE. This method includes:
negotiating with a radio base station to which the UE is wirelessly connected; and
deriving, based on a result of the negotiation, a key used for confidentially protecting
traffic transmitted over U-Plane between a different radio base station and the UE, the
traffic being transmitted in parallel with traffic over the U-Plane between the radio
base station and the UE.
[0033] Further, a method according to twenty-fifth exemplary aspect of the present
invention provides a method of protecting communication in a mobile communication
system including a plurality of base stations, and a UE (User Equipment) connectable
to the plurality of base stations for dual connectivity. This method includes: deriving,
by a first base station, a second key from a first key; sending, by the first base station,
the second key to a second base station; deriving, by the second base station, a third
key from the second key; sending, by the first base station, information or parameter
relating to a fourth key to the UE; and deriving, by the UE, the fourth key for ciphering
of user plane. The third key and the fourth key are the same, and the same key is used
for encrypting communication between the second base station and the UE.
[0034] Further, a mobile communication system according to twenty-sixth exemplary aspect
of the present invention includes: a first base station; a second base station; and a UE
(User Equipment) connectable to the first base station and the second base station for
dual connectivity. The first base station derives a second key from a first key and sends
the second key to the second base station. The second base station derives a third key
from the second key. The first base station sends information or parameter relating to a
fourth key to the UE. The UE derives the fourth key for ciphering of user plane. The
third key and the fourth key are the same, and the same key is used for encrypting
communication between the second base station and the UE.
[0035] Further, a base station according to twenty-seventh exemplary aspect of the present
invention performs dual connectivity in a mobile communication system. This base
station includes: a first unit that connects a UE (User Equipment); and a second unit
that derives a key from a different key received from a different base station. The
derived key is the same as a key derived by the UE and is used for encrypting commu
nication with the UE.
[0036] Furthermore, a UE (User Equipment) according to twenty-eighth exemplary aspect of
the present invention is used in a mobile communication system. This UE includes: a
first unit that connects to a first base station and a second base station for dual con
nectivity; and a second unit that derives a key. The first unit receives information or
parameter relating to a ciphering key from the first base station. The second unit
derives the ciphering key. The ciphering key is the same as a key derived by the
second base station and is used for encrypting communication with the second base
station.
Advantageous Effects of Invention
[0037] According to the present invention, it is possible to solve the above-mentioned
problem, and thus to provide a solution for supporting separate ciphering at an MeNB
and an SeNB.
Brief Description of Drawings
[0038] [fig.l]Fig. 1 is a block diagram showing an example of C-Plane protocol architecture
in a communication system common to first to fourth exemplary embodiments of the
present invention.
[fig.2]Fig. 2 is a block diagram showing an example of U-Plane protocol architecture
in the communication system common to the first to fourth exemplary embodiments.
[fig.3]Fig. 3 is a block diagram showing one example of key hierarchy in the commu
nication system according to the first exemplary embodiment.
[fig.4]Fig. 4 is a sequence diagram showing an example of operations in the commu
nication system according to the first exemplary embodiment.
[fig.5]Fig. 5 is a block diagram showing another example of key hierarchy in the com
munication system according to the first exemplary embodiment
[fig.6]Fig. 6 is a block diagram showing one example of key hierarchy in the commu
nication system according to the second exemplary embodiment.
[fig.7]Fig. 7 is a sequence diagram showing one example of operations in the commu
nication system according to the second exemplary embodiment.
[fig.8]Fig. 8 is a block diagram showing another example of key hierarchy in the com
munication system according to the second exemplary embodiment.
[fig.9]Fig. 9 is a sequence diagram showing another example of operations in the com
munication system according to the second exemplary embodiment
[fig. 10] Fig. 10 is a block diagram showing an example of operations in the commu
nication system according to the third exemplary embodiment.
[fig. 1l]Fig. 11 is a block diagram showing an example of key hierarchy in the communication
system according to the fourth exemplary embodiment.
[fig. 12] Fig. 12 is a block diagram showing a configuration example of a first radio
base station common to the first to fourth exemplary embodiments.
[fig.l3]Fig. 13 is a block diagram showing a configuration example of a second radio
base station common to the first to fourth exemplary embodiments.
[fig. 14] Fig. 14 is a block diagram showing a configuration example of a node
according to the second exemplary embodiment.
[fig.l5]Fig. 15 is a block diagram showing a configuration example of a UE common
to the first to fourth exemplary embodiments.
[fig.l6]Fig. 16 is a block diagram showing U-Plane architecture 1A disclosed in NPL
1.
Description of Embodiments
[0039] Hereinafter, first to fourth exemplary embodiments of radio base stations, a node and
a UE according to the present invention, and a communication system to which these
radio base stations, node and UE are applied, will be described with the accompany
drawings.
[0040] Fig. 1 shows an example of C-Plane (Control-Plane) protocol architecture in a com
munication system common to the first to fourth exemplary embodiments.
[0041] For C-Plane, the communication system includes a UE 10, an MeNB 20, an SeNB 30
and an MME (Mobility Management Entity) 40. The UE 10 communicates with the
MeNB 20 through a Uu interface. The MeNB 20 communicates with the SeNB 30
through an X2-C interface, and communicates with the MME 40 through an Sl-MME
interface. Keying related signalling is conducted over the C-Plane.
[0042] Fig. 2 shows an example of U-Plane protocol architecture in the communication
system.
[0043] For U-Plane, the communication system further includes an SGW (Serving Gateway)
50. Each of the MeNB 20 and the SeNB 30 communicates with the SGW 50 through
an Sl-U interface. In this architecture, U-Plane traffic is transmitted through the MeNB
20 and the SeNB 30 in parallel for the purpose of offloading the MeNB 20 (in other
words, for the purpose of offloading the backhaul Sl-U interface between the MeNB
20 and the SGW 50).
[0044] Next, details of first to fourth exemplary embodiments will be described with
reference to Figs. 3 to 11. Note that configuration examples of the UE 10, the MeNB
20, the SeNB 30 and the MME 40 will be described later with reference to Figs. 12 to
15.
[0045]
In this exemplary embodiment, new keys for confidentially protecting the U-Plane
traffic between the UE 10, and the MeNB 20 and the SeNB 30 (hereinafter, sometimes
referred to as "UP keys") are derived from the same KeNB. The MeNB 20 derives the
UP key for the SeNB 30, and sends it to the SeNB 30.
[0046] There are two options as to how to derive the UP keys as follows.
[0047] (Option 1)
Fig. 3 shows key hierarchy in this option. The illustrated key hierarchy includes KeNB ,
C K t t , K P c, and K c
_s-
[0048] Among them, the KeNB is a key shared upon communication between the UE 10 and
the MeNB 20, and can be derived by the UE 10 and the MME 40 from KASME- The K
C n is a key which can be derived from the KeNB and used for protecting RRC (Radio
Resource Control) traffic with a particular encryption algorithm. The K i t is a key
which can be derived from the KeNB and used for protecting the RRC traffic with a
particular integrity algorithm. The K P t is a key which can be derived from the KeNB
and used for protecting U-Plane traffic between an RN (Relay Node) and a DeNB
(Donner eNB) with a particular integrity algorithm. The K P e nc is a key which can be
derived from the KeNB and used for protecting U-Plane traffic between a UE and an
eNB with a particular encryption algorithm.
[0049] On the other hand, the K P e nc s is a new UP key specific to this exemplary em
bodiment. Kupenc-M described later in the following option 2 is also a new UP key
specific to this exemplary embodiment.
[0050] In operations, as shown in Fig. 4, the MME 40 firstly derives the KENB from the KASME
(step SI 1), and then sends the derived KeNB to the MeNB 20 (step S12).
[0051] The SeNB 30 informs the MeNB 20 about algorithm information, if necessary (step
S13). For example, the algorithm information indicates algorithms for encryption
which can be supported by the SeNB 30, or the like.
[0052] The MeNB 20 derives, from the received KeNB, the K P c and KUP c_s so as to differ
from each other (step SI4).
[0053] Then, the MeNB 20 sends the derived K c S to the SeNB 30 (step S15). The MeNB
20 may send to the SeNB 30 other parameters necessary for encryption at the SeNB
30.
[0054] In parallel with the above steps S14 and S15, the MeNB 20 negotiates with the UE
10 such that the UE 10 can derive the same K P c and KUP c_s (step S16). Specifically,
the MeNB 20 sends to the UE 10 information necessary for deriving the K P c and K
u s such as some parameters, indicators indicating encryption algorithms, and the
like.
[0055] The UE 10 derives the K P e nc M and K P e nc s based on the information obtained by the
negotiation (step S17).
[0056] Note that although the illustration is omitted, the MeNB 20 performs management on
the UP keys (particular on the UP key for the SeNB 30) such as update and/or removal
of the UP keys, and control for separate PDCP (Packet Data Convergence Protocol)
COUNT. The UE 10 also performs management on the UP keys in a similar manner to
the MeNB 20. These explanations can be similarly applied to the following option 2 as
well as second and third exemplary embodiments.
[0057] Thus, as shown by dotted lines in Fig. 4, it is possible to protect U-Plane traffic
between the UE 10, and the MeNB 20 and the SeNB 30 with the separate K P c and K
UPenc-S-
[0058] In this option, the K c may be the existing one which can be derived by a typical
eNB from the KeNB . In other words, the impact on the existing eNB upon applying this
option is only to derive the K C S, so that it is possible to effectively derive the UP
keys.
[0059] (Option 2)
Fig. 5 shows key hierarchy in this option. The illustrated key hierarchy is different
from that shown in Fig. 3, in that separate K P e nc-M and K P enc-s r derived from the K
UPenc-
[0060] In operations, as a substitute for the above step S14 shown in Fig. 4, the MeNB 20
firstly derives the Kupen from the received KeNB, and then derives the Kupe n M and K
UPenc-S from the Kupe n
[0061] In this option, both of Kupe n M and Kupe n s are newly derived, so that it is possible to
make the U-Plane protection more ensure compared with the option 1.
[0062]
In this exemplary embodiment, UP keys are derived from different KeNB . There are
two options as to how to derive the UP keys as follows.
[0063] (Option 1)
Fig. 6 shows key hierarchy in this option. The illustrated key hierarchy includes
separate KeNB M and KeNB S. The KeNB Mis a key used for the MeNB 20 to derive the K
C n the K i t , the K P t and the K c. On the other hand, the KeNB S is a key used for
the SeNB 30 to derive the K c. The K c derived by the MeNB 20 differs from that
derived by the SeNB 30, because the KeNB Mand KeNB S differ from each other.
[0064] In operations, as shown in Fig. 7, the MME 40 firstly derives the separate KENB Mand
eN B s from the KASME (step S21), and then sends the derived KENB Mand KENB S to the
MeNB 20 (step S22).
[0065] The SeNB 30 informs the MeNB 20 about the algorithm information, if necessary
(step S23).
[0066] The MeNB 20 derives its own K P e nc from the received KENB M(step S24), and send
the received KeNB S to the SeNB 30 (step S25).
[0067] The SeNB 30 derives its own K P e nc from the received KENB S (step S26).
[0068] In parallel with the above steps S24 to S26, the MeNB 20 negotiates with the UE 10
such that the UE 10 can derive both K P c for the MeNB 20 and the SeNB 30 (step
S27). Specifically, the MeNB 20 sends to the UE 10 information necessary for
deriving both K c for the MeNB 20 and the SeNB 30, such as some parameters, in
dicators indicating encryption algorithms, and the like.
[0069] The UE 10 derives both K c for the MeNB 20 and the SeNB 30 based on the in
formation obtained by the negotiation (step S28).
[0070] Thus, as shown by dotted lines in Fig. 7, it is possible to protect U-Plane traffic
between the UE 10, and the MeNB 20 and the SeNB 30 with the separate UP keys.
[0071] (Option 2)
Fig. 8 shows key hierarchy in this option. The illustrated key hierarchy is different
from that shown in Fig. 6, in that KeNB" is derived from the KeNB M n a similar manner
to a typical handover procedure, and that the KeNB
** is used as the KeNB s . The KeNB
** is
sent from the MeNB 20 to the SeNB 30.
[0072] In operations, as shown in Fig. 9, the MME 40 firstly derives the KeNB Mfrom the K
ASME (step S31), and then sends the derived K B Mto the MeNB 20 (step S32).
[0073] The MeNB 20 derives the Kupenc, and derives the K eNB " from the received K eNB M as in
handover (step S33).
[0074] Moreover, the MeNB 20 sends the derived KeNB" to the SeNB 30 (step S34).
[0075] The SeNB 30 uses the K eNB ** as K eNB S (step S35), and then derives its own Kup en
from the KeNB S (step S36).
[0076] In parallel with the above steps S33 to S36, the MeNB 20 negotiates with the UE 10
such that the UE 10 can derive both K P c for the MeNB 20 and the SeNB 30 (step
S37). Specifically, the MeNB 20 sends to the UE 10 information necessary for
deriving both K c for the MeNB 20 and the SeNB 30, such as some parameters, in
dicators indicating encryption algorithms, and the like.
[0077] The UE 10 derives both K c for the MeNB 20 and the SeNB 30 based on the in
formation obtained by the negotiation (step S38).
[0078] Thus, as shown by dotted lines in Fig. 9, it is possible to protect U-Plane traffic
between the UE 10, and the MeNB 20 and the SeNB 30 with the separate UP keys as
with the option 1.
[0079] Moreover, in this option, the KeNB Mmay be the existing KeNB. Therefore, it is possible
to minimize the impact on the existing MME upon applying this option.
[0080]
In this exemplary embodiment, UP keys are derived based on different parameters.
[0081] Specifically, as show in Fig. 10, the MeNB 20 sends a random value (random
number) to the SeNB 30. The SeNB 30 derives its own UP key by using the random
value received from the MeNB 20. Parameters for deriving the UP key for the SeNB
30, or the like can be send from the MeNB 20 to the UE 10 upon the negotiation.
[0082] Thus, in this exemplary embodiment, it is possible to protect U-Plane traffic between
the UE 10, and the MeNB 20 and the SeNB 30 with the separate UP keys as with the
above-mentioned first and second exemplary embodiments.
[0083] Moreover, in this exemplary, the UP key itself is not sent from the MeNB 20 to the
SeNB 30. Therefore, it is possible to prevent the UP key from being maliciously in
tercepted.
[0084]