Sign In to Follow Application
View All Documents & Correspondence

Communication System, Network Apparatus, Authentication Method, Communication Terminal, And Security Apparatus

Abstract: The purpose of the present invention is to provide a communication system that executes security procedures necessary for applying an Attach Procedure to a NextGen System. This communication system comprises: a communication terminal (10) which transmits an Attach Request message that includes Network Slice Selection Assistance Information (NSSAI) and User Equipment (UE) Security Capabilities; and a network device (20) which is located within a mobile network (30) and which receives the Attach Request message. The network device (20) uses the NSSAI and UE Security Capabilities to determine whether to allow the communication terminal (10) to connect to a core network indicated by NSSAI, from among a plurality of core networks divided up by network slicing.

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
24 May 2019
Publication Number
34/2019
Publication Type
INA
Invention Field
COMMUNICATION
Status
Email
archana@anandandanand.com
Parent Application

Applicants

NEC CORPORATION
7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001

Inventors

1. PRASAD Anand Raghawa
c/o NEC Corporation, 7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001
2. LAKSHMINARAYANAN Sivakamy
c/o NEC India Pvt Ltd., SP Infocity, Block-A, 9th Floor, Module-2A, 40, MGR Salai, Kandanchavadi, Perungudi, Chennai 600096
3. ARUMUGAM Sivabalan
c/o NEC India Pvt Ltd., SP Infocity, Block-A, 9th Floor, Module-2A, 40, MGR Salai, Kandanchavadi, Perungudi, Chennai 600096
4. ITO Hironori
c/o NEC Corporation, 7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001
5. KUNZ Andreas
c/o NEC Europe Ltd., Kurfursten-Anlage 36, Heidelberg 69115

Specification

The present disclosure is a communication system, a network device, authentication method, a communication terminal, and a security device.
BACKGROUND
[0002]
 Currently, as a radio communication scheme used between the communication terminal and the base station, LTE (Long Term Evolution) has become widespread it is stipulated specifications in 3GPP (3rd Generation Partnership Project). LTE is a wireless communication system used to implement the wireless communication of the high-speed and large capacity. Further, as the core network that accommodates a wireless network using LTE, the 3GPP, SAE (System Architecture Evolution) or EPC (Evolved Packet Core) or the like called a packet network it is defined.
[0003]
 Communication terminal, in order to utilize the communication service using LTE, are required to register with the core network. As a procedure for registering the communication terminal to the core network, Attach Procedure is defined in 3GPP. MME disposed within a core network (Mobility Management Entity) executes authentication processing of the communication terminal using the identification information of the communication terminal in Attach Procedure. The MME, in cooperation with the HSS (Home Subscriber Server) or the like which manages subscriber information and performs authentication processing of the communication terminal. As the identification information of the communication terminal, for example, IMEISV (International Mobile Equipment Identity) or IMSI (International Mobile Subscriber Identity) or the like is used.
[0004]
 In recent years, in 3GPP, IoT is Study (Internet of Things) service has been promoted. The IoT services, without user terminal to perform autonomously communication (hereinafter referred to as IoT terminal) is used numerous. Therefore, the service provider is to provide the IoT services using a number of IoT terminal, the mobile network operators, etc. are managed, it is desirable to efficiently accommodate many IoT terminal. Mobile network is a network that includes a wireless network and a core network.
[0005]
 In Annex B of Non-Patent Document 1, the configuration of the core network to which the network slicing is described. Network slicing, in order to accommodate more IoT terminal efficiently, a technique for dividing the core network for each service provided. Further, in Section 5.1, the divided each network (network slice system), it is described that customization and optimization is required.
[0006]
 System to which the network slicing, for example, also called NextGen (Next Generation) System. The radio network used in NextGen System may also be referred to as NG (Next Generation) RAN (Radio Access Network).
CITATION
Non-patent literature
[0007]
Non-Patent Document 1: 3GPP TR23.799 V1.0.2 (2016-9)
Non-Patent Document 2: 3GPP TR33.899 V0.5.0 (2016-10)
Summary of the Invention
Problems that the Invention is to Solve
[0008]
 Also in NextGen System, using Attach Procedure similar procedure for registering the core communication terminal to the network being defined as SAE, it is necessary to register the communication terminal comprising IoT terminal or the like to NextGen System. However, in the NextGen System, various functions related to security processing is introduced, an Attach procedure defined currently in 3GPP, there is a problem that can not be directly applied to NextGen System. Specifically, in Non-Patent Document 2, ARPF (Authentication Credential Repository and Processing Function), AUSF (Authentication Server Function), SEAF (Security Anchor Function), and SCMF introducing (Security Context Management Function), etc. NextGen System There has been studied.
[0009]
 The purpose of the present disclosure is to provide a communication system that performs security procedures required to apply the Attach Procedure to NextGen System, network device, authentication method, a communication terminal, and the security device.
Means for Solving the Problems
[0010]
 Communication system according to a first aspect of the present disclosure, a communication terminal which sends the Attach Request message containing NSSAI (Network Slice Selection Assistance Information) and UE (User Equipment) Security Capabilities, disposed in a mobile network, the Attach comprising a network device for receiving the Request message, wherein the network device uses the NSSAI and the UE Security Capabilities, among the plurality of core network divided by the network slicing, the relative core network shown in the NSSAI It determines whether or not to permit the connection of the communication terminal.
[0011]
 Network device according to a second aspect of the present disclosure, configured to receive the Attach Request message from the communication terminal that transmits Attach Request message containing NSSAI (Network Slice Selection Assistance Information) and UE (User Equipment) Security Capabilities It is, with the NSSAI and the UE Security Capabilities, among the plurality of core network divided by the network slicing, so as to determine whether or not to permit the connection of the communication terminal to the core network shown in the NSSAI constructed.
[0012]
 Authentication method according to the third aspect of the present disclosure receives the Attach Request message from the communication terminal that transmits Attach Request message containing NSSAI (Network Slice Selection Assistance Information) and UE (User Equipment) Security Capabilities, the NSSAI and using said UE Security Capabilities, among the plurality of core network divided by the network slicing determines whether or not to permit the connection of the communication terminal to the core network shown in the NSSAI.
Effect of the invention
[0013]
 The present disclosure can provide a communication system that performs security procedures required to apply the Attach Procedure to NextGen System, network device, authentication method, a communication terminal, and the security device.
BRIEF DESCRIPTION OF THE DRAWINGS
[0014]
FIG. 1 is a configuration diagram of a communication system in the first embodiment.
FIG. 2 is a configuration diagram of a communication system according to the second embodiment.
3 is a diagram showing an Attach Procedure in NextGen System according to the second embodiment.
4 is a diagram showing an Attach Procedure in NextGen System according to the third embodiment.
5 is a diagram showing an Attach Procedure in NextGen System according to the fourth embodiment.
6 is a diagram showing an Attach Procedure in NextGen System according to the fifth embodiment.
7 is a diagram showing an Attach Procedure in NextGen System according to the fifth embodiment.
8 is a diagram showing an Attach Procedure in NextGen System according to the fifth embodiment.
9 is a configuration diagram of a communication system in the sixth embodiment.
FIG. 10 is a configuration diagram of a communication system according to the seventh embodiment.
11 is a diagram showing the hierarchical structure of the security keys to the seventh embodiment.
12 is a diagram showing a NAS Security Procedure in NextGen System according to the seventh embodiment.
13 is a diagram showing a NAS Security Procedure in NextGen System according to the seventh embodiment.
14 is a diagram showing a NAS Security Procedure in NextGen System according to the seventh embodiment.
15 is a diagram showing an UP Security Procedure in NextGen System according to the eighth embodiment.
16 is a diagram showing an UP Security Procedure in NextGen System according to the eighth embodiment.
17 is a diagram showing an UP Security Procedure in NextGen System according to the eighth embodiment.
18 is a diagram showing an UP Security Procedure in NextGen System according to the eighth embodiment.
19 is a diagram showing an UP Security Procedure in NextGen System according to the eighth embodiment.
FIG. 20 is a diagram showing an UP Security Procedure in NextGen System according to the eighth embodiment.
21 is a diagram showing an AS Security Procedure in NextGen System according to the ninth embodiment.
FIG. 22 is a configuration diagram of a communication system according to the tenth embodiment.
23 is a diagram for explaining AKA algorithm according to the tenth embodiment.
FIG. 24 is a diagram for explaining AKA algorithm according to the tenth embodiment.
[25] is a diagram showing a modification of the hierarchical structure of security keys according to the tenth embodiment.
FIG. 26 is a diagram showing a flow of the derivation of the security keys according to the tenth embodiment.
FIG. 27 is a view showing a modified example of the hierarchical structure of security keys according to the tenth embodiment.
[FIG. 28] is a diagram showing a flow of the derivation of the security keys according to the tenth embodiment.
FIG. 29 is a view showing a modified example of the hierarchical structure of security keys according to the tenth embodiment.
[FIG. 30] is a diagram showing a flow of the derivation of the security keys according to the tenth embodiment.
[FIG. 31] is a diagram showing a modification of the hierarchical structure of security keys according to the tenth embodiment.
[FIG. 32] is a diagram showing a flow of the derivation of such a security key to the tenth embodiment.
[33] is a diagram showing a modification of the hierarchical structure of security keys according to the tenth embodiment.
FIG. 34 is a diagram showing the flow of the derivation of such a security key to the tenth embodiment.
[FIG. 35] is a view showing a modified example of the hierarchical structure of the security keys to the tenth embodiment.
[FIG. 36] is a diagram showing a flow of the derivation of such a security key to the tenth embodiment.
[FIG. 37] is a diagram showing a modification of the hierarchical structure of security keys according to the tenth embodiment.
[FIG. 38] is a diagram showing a flow of the derivation of such a security key to the tenth embodiment.
[39] is a diagram showing a modification of the hierarchical structure of security keys according to the tenth embodiment.
[FIG. 40] is a diagram showing a flow of the derivation of the security keys according to the tenth embodiment.
DESCRIPTION OF THE INVENTION
[0015]
 (Embodiment 1)
 Hereinafter, with reference to the drawings will be described embodiments of the present disclosure. A configuration example of a communication system according to the first embodiment will be described with reference to FIG. Communication system of FIG. 1 includes a communication terminal 10 and the network device 20. Network device 20 is arranged in the mobile network 30. Communication terminal 10 and network device 20, the processor may be a computer system that operates by executing a program stored in the memory. The processor may, for example, a microprocessor may be a MPU (Micro Processing Unit), or CPU (Central Processing Unit). The memory may be a volatile memory or nonvolatile memory, it may be configured by a combination of volatile and nonvolatile memory. Processor executes one or more programs including instructions for performing the algorithm described with reference to subsequent figures the computer.
[0016]
 Communication terminal 10, a mobile phone terminal, a smartphone terminal, may be the IoT terminal and the like.
[0017]
 Mobile network 30 includes a radio access network and a core network for the communication terminal 10 and radio communication. Network device 20 may be, for example, a node device or entity operating in 3GPP is defined.
[0018]
 The communication terminal 10 transmits an Attach Request message containing NSSAI (Network Slice Selection Assistance Information) and UE (User Equipment) Security Capabilities (or UE Security Capability) to the network device 20. NSSAI is, for example, information for identifying the core network providing the services the communication terminal 10 is utilized. Here, the core network included in the mobile network 30, the network slicing is applied, is divided for each service provided. Divided network may be referred to as a network slice.
[0019]
 UE Security Capabilities may be a set of identification information corresponding to algorithm information used encryption is performed at the UE is a communication terminal and integrity protection processing. (The set of identifiers corresponding to the ciphering and integrity algorithms implemented in the UE).
[0020]
 Communication terminal 10 is, for example, when the power is shifted from the OFF state to the ON state sends the Attach Request message to the network device 20.
[0021]
 Network device 20 receives the Attach Request message transmitted from the communication terminal 10. Further, the network device 20 uses the NSSAI and UE Security Capabilities contained in Attach Request message, among the plurality of core network divided by the network slicing, permits the connection of the communication terminal 10 to the core network shown in NSSAI determines whether or not the.
[0022]
 As described above, the communication system of FIG. 1, determines whether the core network by the network slicing even if it is divided, to connect the communication terminal 10 to the core network the communication terminal 10 requests a connection can do. Than this, the communication system of FIG. 1, in NextGen System Network slicing is applied, it is possible to perform the security procedures required to apply Attach Procedure.
[0023]
 (Second Embodiment)
 Subsequently, a configuration example of a communication system according to the second embodiment will be described with reference to FIG. Communication system of FIG. 2 shows a NextGen System. Communication system of FIG. 2, ARPF entities 41 (hereinafter referred to as ARPF41), AUSF entities 42 (hereinafter referred to as AUSF42), SEAF entities 43 (hereinafter referred to as SEAF43), SCMF entities 44 (hereinafter referred to as SCMF44) , SCMF45, CP-CN (C -Plane Core Network) entity 46 (hereinafter referred to as CP-CN46), CP-CN47 , NG-RAN entities 48 (hereinafter referred to as NG-RAN48), and have a NG-RAN49 doing. CP-CN 46 includes a MM entity performing Mobility Management, and SM entity that performs Session Management.
[0024]
 Specifically, MM is, registers the user to manage the UE or UE to a mobile network (registration) to be, mobile terminated Communication enables to reachability (reachability) to support, unreachable UE Detection , C (Control) -plane and U (User) assigning a network function relating -plane, and to limit the mobility, or the like.
[0025]
 Also, SM is possible to set the IP connectivity or non-IP connectivity for UE. In other words, SM may be to manage or control the connectivity of the U-Plane.
[0026]
 ARPF41, AUSF42, SEAF43, SCMF44, SCMF45, CP-CN46, and CP-CN47 constitute a core network. Each entity is located in the core network may also be referred to as core network device or security device. NG-RAN48 and NG-RAN49 constitute a radio access network. NG-RAN48, for example, may be a base station used in NextGen System.
[0027]
 Each entity 2 may comprise a plurality of functions. For example, in FIG. 2, ARPF41 is a different entity from the AUSF42, may be one of the entities are used to perform ARPF and Ausf.
[0028]
 ARPF entity is a node apparatus for executing ARPF. Ausf entity is a node apparatus for executing Ausf. ARPF and AUSF, for example, UE (User Equipment) which corresponds to the communication terminal 10 is a function of executing an authentication process as to whether it is possible to connect to the NextGen System. ARPF41 and AUSF42 generates a security key used for the authentication process, holds the generated security key.
[0029]
 SEAF and SCMF is a function that performs an authentication process as to whether it is possible to connect to the UE Core Network Network slicing is applied. SCMF44 and SEAF43 may be referred to as a security device. SEAF43, the security key K received from AUSF42 SEAF security key K from SCMF to derive. SEAF43, the security key K SCMF to send to SCMF44 and SCMF45. SCMF44, the security key K received from SEAF43 SCMF security key K from CP-CN to derive. SCMF44, the security key K CP-CN to send to the CP-CN46 and CP-CN47.
[0030]
 NG-RAN48 and NG-RAN49, the security key K derived in SCMF44 or SEAF43 AN receive.
[0031]
 Each entity constituting the NextGen System uses the security key K received, executes the security processing such as integrity assurance processing of the authentication processing and the message of the UE. In addition, the security key K, may be referred to as a security context.
[0032]
 Subsequently, Attach Procedure is described in NextGen System with reference to FIG. First, UE sends a RRC Connection Request message to the NG-RAN48 (S11). Attach Request message is multiplexed to the RRC Connection Request message (The Attach Request is piggy-backed within the RRC Connection Request). Attach Request message, GUTI as a parameter (Globally Unique Temporary UE Identity), including Network Capabilities, KSI (Key Set Identifier), NSSAI and UE Security Capabilities. GUTI is temporarily allocated identifier to the UE. Network Capabilities is, for example, a security algorithm of the NAS and AS are supported in UE. KSI is the identifier of the key that UE has.
[0033]
 Then, NG-RAN48 confirms the UE Security Capabilities and subscriber information about the UE (Subscription) (S12) (The NG-RAN48 checks the UE Security Capabilities and Subscription for the UE). The confirmation UE Security Capabilities, the algorithm information to be used in the the encryption and integrity protection processing executed in the UE, the encryption and integrity are performed in the core network or NG-RAN48 UE requests a connection assurance processing it may be to determine whether the algorithm information matches used to. Moreover, the confirmation of the subscriber information, the UE may be whether a confirmation whether or not it is allowed to connect for NextGen System, or UE is authorized to connect to the core network. The core network is a core network the UE requests a connection, or may be composed of one or more networks slices. Core network the UE requests a connection may be determined based on NSSAI.
[0034]
 Here, NG-RAN48, the security key K AN and holding the (Retain) (It Is Assumed That The NG-RAN48 Retains The Security Key K AN ). Also in UE, NG-RAN48 security key K holds AN and holds the same key and. In this case, NG-RAN48, the security key K AN can is used to perform the integrity (integrity) assurance processing of Attach Request message in the RRC Connection Request message. NG-RAN48 by executing integrity assurance processing, it is possible to ensure that the Attach Request message has not been tampered with.
[0035]
 Next, NG-RAN48 transmits the RRC Connection Setup message to the UE as a RRC Connection Request message against the response (S13). Then, UE, in order to notify the reception of the RRC Connection Setup message to the NG-RAN48, transmits an RRC Connection Complete message to the NG-RAN48 (S14).
[0036]
 Next, NG-RAN48 transmits an Attach Request message to SEAF43 (S15). The Attach Request message, GUTI, Network Capabilities, KSI, include NSSAI and UE Security Capabilities. SEAF43 sends the Initial Context Setup Request / Attach Accept message to the NG-RAN48.
[0037]
 Next, NG-RAN48 transmits an RRC Connection Reconfig (RRC Connection Reconfiguration) message to the UE (S17). Attach Accept message has been multiplexed in the RRC Connection Reconfig message.
[0038]
 Then, UE, in response to the RRC Connection Refoncig message, transmits a RRC Connection Reconfig Complete message to NG-RAN48 (S18). Next, NG-RAN48, in response to Initial Context Setup Request message and sends the Initial Context Setup Response message to the SEAF43 (S19). Then, UE via the NG-RAN48 to SEAF43, transmits an Attach Complete message (S20).
[0039]
 In step S12, NG-RAN48, the algorithm information used for encryption is performed and integrity protection process does not match the UE and NG-RAN48, and, UE is not allowed to connect for NextGen System or the core network, If it is determined that corresponds to at least one of, without executing the step S13 and subsequent steps, it may send a Reject message to the UE.
[0040]
 Or, in step S12, NG-RAN48, the algorithm information used for encryption is performed and integrity protection process does not match the UE and NG-RAN48, and, UE is allowed to connect for NextGen System or core network there is not, even if it is determined to correspond to at least one of the, step S13 may be continued after the process. In this case, for example, SEAF43 is the UE, rather than the core network the UE requests a connection, it may be continued Attach Procedure to connect to a predetermined core network (default core network).
[0041]
 In step S12, NG-RAN48, the algorithm information coincides used encryption is performed and the integrity protection processing in the UE and NG-RAN48, and, UE is allowed connection to the NextGen System or core network when it is determined to correspond to both the UE, so as to be connected to a core network the UE requesting a connection, to continue the Attach Procedure.
[0042]
 As described above, NG-RAN48 found by checking the UE Security Capabilities and subscriber information (Subscription) (check) relating UE, the Attach Procedure to the core network by the network slicing considering NextGen System which is divided it can be introduced.
[0043]
 Furthermore, NG-RAN48 may transmit Attach Request message to the SEAF43 through the MM entity may transmit the Attach Request message to the SEAF43 through SCMF44.
[0044]
 (Third Embodiment)
 Subsequently, Attach Procedure is described in NextGen System according to the third embodiment with reference to FIG. In FIG. 4, NG-RAN48, the security key K AN and does not hold the (Retain) (It Is Assumed That The NG-RAN48 Does Not Retain The Security Key K AN ).
[0045]
 Step S31 is a detailed description thereof will be omitted because it is similar to step S11 of FIG. Next, NG-RAN48 is confirmed UE Security Capabilities and subscriber information about UE (Subscription) to (check) (S32). Here, NG-RAN48, the security key K AN does not hold. Therefore, NG-RAN48 does not perform the integrity (integrity) assurance processing of Attach Request message in the RRC Connection Request message and forwards the message to SEAF43.
[0046]
 Step S33 ~ S35 is a detailed description thereof will be omitted because it is similar to that of steps S13 ~ S15 of FIG.
[0047]
 Then, SEAF43 is, to make sure the integrity of the Attach Request message (verify or check). SEAF43 is assumed to hold the security key K for the UE. Security key K SEAF43 is held, security key K AN or security key K SEAF may be. Also in UE, the security key K SEAF43 holds AN or the security key K SEAF and holds the same key and. SEAF43 using the security key K that holds, perform integrity assurance process Attach Request message.
[0048]
 Then, SEAF43, if it was possible to verify the integrity of the Attach Request message, to the NG-RAN48, sends the Attach Request Integrity Verified message (S37). Step S37 and subsequent, similarly to step S16 ~ S20 of FIG. 3 is executed.
[0049]
 In step S35, NG-RAN48 may transmit Attach Request message to the SEAF43 through the MM entity may transmit the Attach Request message to the SEAF43 through SCMF44. In addition, confirmation of integrity in the step S36 (verify) may be executed in SCMF44, which may be executed in the ARPF41 (The verification of the integrity of the Attach Request message can be done at the SCMF44 or ARPF41).
[0050]
 As described above, even if the NG-RAN48 does not hold the security key K, the entity being arranged on the core network side, it is possible to check the integrity of the Attach Request message.
[0051]
 (Embodiment 4)
 Subsequently, Attach Procedure is described in NextGen System according to the fourth embodiment with reference to FIG. In FIG. 5, UE, NG-RAN48, and SEAF43 is, the does not hold the security key K.
[0052]
 First, UE sends a RRC Connection Request message to the NG-RAN48 (S41). Attach Request message is multiplexed into RRC Connection Request message. Attach Request message includes a Network capability, NSSAI and UE Security Capabilities as a parameter. However, the Attach Request message, GUTI be temporarily assigned to UE (Globally Unique Temporary UEIdentity) and a KSI does not include.
[0053]
 Next, NG-RAN48 transmits the RRC Connection Setup message to the UE as a RRC Connection Request message against the response (S42). Then, UE, in order to notify the reception of the RRC Connection Setup message to the NG-RAN48, transmits an RRC Connection Complete message to the NG-RAN48 (S43).
[0054]
 Next, NG-RAN48 transmits an Attach Request message to SEAF43 (S44). The Attach Request message, Network capability data, include NSSAI and UE Security Capabilities. However, the Attach Request message, and does not include GUTI and KSI is temporarily assigned to the UE.
[0055]
 Then, SEAF43, in order to obtain the identity of the UE, to the UE, and transmits the Identity Request message (S45). Then, UE transmits the Identity Response message containing the IMSI is identification information of the own device to SEAF43 (S46).
[0056]
 Then, SEAF43 is confirmed UE Security Capabilities and subscriber information about UE (Subscription) to (check) (S47). Then, between the UE and SEAF43, to establish a security context, AKA (Authentication and Key Agreement) and NAS (Non-Access Stratum) SMC (Security Mode Command) is executed (S48). In UE and SEAF43, by AKA and NAS SMC is executed, the security key K is derived in UE and SEAF43.
[0057]
 The AKA and NAS SMC, for example, KDF (Key Derivation Function) may be performed in the UE and SEAF43. In KDF, for example, it used NSSAI as input parameters. Results KDF is executed in UE, derived security key K and RES (Response) is a result of KDF is executed in SEAF43, security key K and XRES (Expected Response) is derived. Here, if the RES and XRES match, UE would have to derive the same security key K and the security key K derived in SEAF43.
[0058]
 Step S48 and subsequent, similarly to step S16 ~ S20 of FIG. 3 is executed.
[0059]
 In step S44, NG-RAN48 may transmit Attach Request message to the SEAF43 through the MM entity may transmit the Attach Request message to the SEAF43 through SCMF44. Further, confirmation of the UE Security Capabilities and subscriber information about the UE in step S47 (Subscription) may be executed in SCMF44, it may be performed in ARPF41.
[0060]
 As described above, UE, each entity being arranged to NG-RAN48 and core network, even when not holding the security key K, by deriving the security key K at the UE and SEAF43, it is possible to confirm the integrity of the Attach Request message.
[0061]
 (Embodiment 5)
 Subsequently, with reference to FIGS. 6-8, the core network entity, a description is given of the flow of the processing to check the UE Security Capabilities and Subscription.
[0062]
 In FIG. 6, UE transmits to SEAF43, the Attach Request message, in addition to NSSAI and UE Security Capabilities, IMSI is included (S51). SEAF43 is, IMSI, Network Capabilities, KSI, upon receiving the Attach Request message containing NSSAI and UE Security Capabilities, check the UE Security Capabilities and subscriber information about UE (Subscription) to (check) (S52). Step S52 and subsequent, similarly to step S16 ~ S20 of FIG. 3 is executed. In FIG. 5, SEAF43 is, after receiving the Attach Request message, transmits an Identity Request message to the UE, receives a Identity Response message the UE IMSI is set. On the other hand, in FIG. 6, the Attach Request message that the UE sends, because it contains IMSI, SEAF43 is, in that it does not transmit the Identity Request message to the UE, different from the process in FIG.
[0063]
 Subsequently, FIG. 7 shows that a confirmation of the UE Security Capabilities, and confirmation of the subscriber information (Subscription) is executed in a different entity. Specifically, SEAF43 receives the same message as the Attach Request message sent in step S51 in FIG. 6, confirms the UE Security Capabilities (S62). Then, SEAF43 is to ARPF41, to request confirmation of the Subscription, the ARPF41 via AUSF42, transmits the UE Subscription the Check Request message. The UE Subscription the Check Request message includes the same information as the Attach Request message sent in step S61.
[0064]
 ARPF41 receives the UE Subscription the Check Request message, to check the subscriber information (S64). Then, ARPF41 completes the confirmation of the subscriber information, transmits the UE Subscription the Check Response message to the SEAF43 via AUSF42 (S65). SEAF43 after receiving the UE Subscription the Check Response message, similarly to step S16 ~ S20 of FIG. 3 is executed.
[0065]
 Subsequently, FIG. 8, confirm the UE Security Capabilities and subscriber information indicates that executed in ARPF41. More specifically, first, SEAF43 receives the same message as the Attach Request message sent in step S51 in FIG. 6. SEAF43 receives the Attach Request message, for requesting confirmation of the UE Security Capabilities and subscriber information, to ARPF41 via AUSF42, sends a UE Security Capabilities and Subscription Check Response message (S74).
[0066]
 Then, ARPF41 is confirmed UE Security Capabilities and subscriber information about UE (Subscription) to (check) (S73). Then, ARPF41 completes the confirmation UE Security Capabilities and subscriber information, transmits the UE Security Capabilities and Subscription Check Response message to the SEAF43 via AUSF42 (S74). SEAF43 after receiving the UE Subscription the Check Response message, similarly to step S16 ~ S20 of FIG. 3 is executed.
[0067]
 As described above, confirmation of the UE Security Capabilities and subscriber information may be executed in one entity located within the core network, it may be performed by distributed across multiple entities.
[0068]
 (Embodiment 6)
 Subsequently, a configuration example of a communication system according to the sixth embodiment will be described with reference to FIG. Communication system of FIG. 9 includes a communication terminal 10_1 and the core network system 20_1.
[0069]
 Node constituting the communication terminal 10_1 and the core network system 20_1 device (may be referred to as a core network device or security device) may be a computer device processor operates by executing a program stored in the memory good. The processor may, for example, a microprocessor may be a MPU (Micro Processing Unit), or CPU (Central Processing Unit). The memory may be a volatile memory or nonvolatile memory, it may be configured by a combination of volatile and nonvolatile memory. Processor executes one or more programs including instructions for performing the algorithm described with reference to subsequent figures the computer.
[0070]
 Communication terminal 10_1, the mobile phone terminal, a smartphone terminal, may be the IoT terminal and the like.
[0071]
 Core network system 20_1 is a communication system that is included in the mobile network. Core network system 20_1, for example, performs session management and mobility management of the communication terminal 10_1. Furthermore, the core network system 20_1, NAS relates to a communication terminal 10_1 (Non Access Stratum) Security Procedure and UP (U-Plane) executes Security Procedure.
[0072]
 Core network system 20_1, the NAS Security Procedure (NAS SMC (Security Mode Command) may be referred to as a procedure), NSSAI (Network Slice Selection Assistance Information) and UE (User Equipment) security using Security Capabilities key (Key ) to generate.
[0073]
 NSSAI is, for example, information for identifying the core network system for providing a service communication terminal 10_1 utilized. Here, the core network system included in the mobile network 30, the network slicing is applied, and is divided for each service provided. Segmented core network system may be referred to as a network slice.
[0074]
 UE Security Capabilities may be a set of identification information corresponding to algorithm information used encryption is performed at the UE is a communication terminal and integrity protection processing. (The set of identifiers corresponding to the ciphering and integrity algorithms implemented in the UE).
[0075]
 Furthermore, the core network system 20_1 transmits information related to NSSAI and UE Security Capabilities used for generating the security key to the communication terminal 10_1.
[0076]
 Communication terminal 10_1, using information related to NSSAI and UE Security Capabilities transmitted from the core network system 20 1, to generate a security key related NAS Security. Security key communication terminal 10_1 generates is the same as the security key generated in the core network system 20_1.
[0077]
 As described above, by using the communication system of FIG. 9, the communication terminal 10_1 may generate the security key using the NSSAI. Than this, the communication terminal 10_1 network slicing is applied, among the divided core network system, it is possible to generate a security key used to connect to a core network system that provides the desired service.
[0078]
 (Embodiment 7)
 Subsequently, a configuration example of a communication system according to the seventh embodiment will be described with reference to FIG. 10. Communication system of FIG. 10 shows a NextGen System. Communication system of FIG. 10, ARPF entities 41 (hereinafter referred to as ARPF41), AUSF entities 42 (hereinafter referred to as AUSF42), SEAF entities 43 (hereinafter referred to as SEAF43), SCMF entities 44 (hereinafter referred to as SCMF44) , SCMF45, CP-CN (C -Plane Core Network) entity 46 (hereinafter referred to as CP-CN46), CP-CN47 , NG-RAN entities 48 (hereinafter referred to as NG-RAN48), NG-RAN49 , UP ( and a U-Plane) -GW (Gateway) 50, and UP-GW51. CP-CN 46 and CP-CN47 includes a MM entity performing Mobility Management, and SM entity that performs Session Management.
[0079]
 Specifically, MM is, registers the user to manage the UE or UE to a mobile network (registration) to be, mobile terminated Communication enables to reachability (reachability) to support, unreachable UE Detection , C (Control) -plane and U (User) assigning a network function relating -plane, or to limit the mobility, or the like.
[0080]
 Also, SM is possible to set the IP connectivity or non-IP connectivity for UE. In other words, SM may be to manage or control the connectivity of the U-Plane.
[0081]
 ARPF41, AUSF42, SEAF43, SCMF44, SCMF45, CP-CN46, CP-CN47, UP-GW50, and UP-GW51 constitute a core network. Each entity is located in the core network may also be referred to as core network device or security device. NG-RAN48 and NG-RAN49 constitute a radio access network. NG-RAN48, for example, may be a base station used in NextGen System.
[0082]
 Each entity shown in FIG. 10 may include a plurality of functions. For example, in FIG. 10, ARPF41 is a different entity from the AUSF42, it may be one of the entities are used to perform ARPF and Ausf.
[0083]
 ARPF entity is a node apparatus for executing ARPF. Ausf entity is a node apparatus for executing Ausf. ARPF and AUSF, for example, UE (User Equipment) which corresponds to the communication terminal 10 is a function of executing an authentication process as to whether it is possible to connect to the NextGen System. ARPF41 and AUSF42 generates a security key used for the authentication process, holds the generated security key.
[0084]
 SEAF and SCMF is a function that performs an authentication process regarding whether the UE can connect to the network slicing cores network. SEAF entity and SCMF entity may be referred to as a security device.
[0085]
 Subsequently, with reference to FIG. 11, described hierarchical structure of security keys. SEAF43, the security key K received from ARPF41 through the AUSF42 SEAF security key K from SCMF to derive. And deriving, for example, may be paraphrased as equal to acquire or generate. SEAF43, the security key K SCMF to send to SCMF44. SCMF44, the security key K received from SEAF43 SCMF security key K from CP-CN and security key K UP to derive. SCMF44, the security key K UP to send to the UP-GW50.
[0086]
 Furthermore, SCMF44 the security key K CP-CN from the key K used to encrypt the NAS message NASenc key K used in the integrity protection processing and NAS message NASint to generate.
[0087]
 UP-GW 50, the security key K UP from the key K used to encrypt the U-Plane data Sess1enc key K used in the integrity protection processing and NAS message Sess1int to generate. Sess1enc shows encryption U-Plane data transmitted in a session that is identified as a session 1. Sess1int shows the the U-Plane data integrity assurance processing transmitted in session identified as a session 1. Security key K UP security keys used in the security key and a plurality of integrity assurance process used multiple encryption may be generated from. In Figure 3, as the security key used for U-Plane data transmitted in any session N, security key K SessNenc and security key K SessNint is shown.
[0088]
 NG-RAN48, the security key K has been derived in SCMF44 or SEAF43 AN receives a. NG-RAN48, the security key K AN from the security key K used in the encryption and integrity protection processing RRC message RRCenc and security key K RRCint to generate. Furthermore, NG-RAN48, the security key K AN from the security key K used in the encryption and integrity protection processing U-Plane data UPenc and security key K UPint to generate.
[0089]
 Each entity constituting the NextGen System uses the security key K received, executes the security processing such as integrity assurance processing of the authentication processing and the message of the UE. In addition, the security key K, may be referred to as a security context.
[0090]
 Next, a description will be given NAS Security Procedure in NextGen System with reference to FIG. First, SEAF43, the security key K holds SEAF security key K from SCMF to derive a (S111). Security key K SCMF is, which may be referred to as the Anchor Key Slice (The SEAF Derives The K SCMF , The Slice Anchor Key.). Then, SEAF43 the security key K SCMF and to derive the (S112), and sends the NAS SMC (Security Mode Command) message to SCMF44 (S113). NAS SMC message, the security key K SCMF including, NSSAI, UE Security Capabilities, the Network Capabilities.
[0091]
 Then, SCMF44 the security key K has received SCMF security key K from CP-CN to derive a (S114, S115). Then, SCMF44, select the algorithm for integrity assurance and encryption, security key K CP-CN to derive the NAS key from (S116) (The SCMF selects the algorithm for integrity protection and encryption and derives the NAS keys) . NAS key, specifically, security key K used in the integrity protection processing NASint security key K used and encryption NASenc may be a (S117).
[0092]
 Then, SCMF44 may forward the NAS SMC message received in step S13 to the UE to (forward) (S118). NAS SMC message includes as parameters, KSI (Key Set Identifier), NSSAI, UE Security Capabilities, Network Capabilities, NAS enc Algo, NAS int Algo, and NAS-MAC the (Message Authentication Code). NAS SMC message, in the sixth embodiment, which is information related to NSSAI and UE Security Capabilities. NAS enc Algo is an algorithm for encryption, NAS int Algo is an algorithm for integrity assurance.
[0093]
 Then, UE, the security key K SCMF and security key K CP-CN to derive a (S119, S120). Then, UE, in order to use the algorithm for integrity protection and encryption received in step S118, the security key K CP-CN derives the NAS key from (S121). NAS key, specifically, security key K used in the integrity protection processing NASint security key K used and encryption NASenc may be a (S122).
[0094]
 Then, UE sends to SCMF44 a NAS SM (Security Mode) Complete message containing the NAS-MAC (S123). SCMF44 transfers NAS SM Complete message received to SEAF43 (S124).
[0095]
 Subsequently, with reference to FIG. 13, a description will be given different NAS Security Procedure and FIG. Step S131 ~ S135 is omitted because it is similar to the steps S 111 ~ S115 in FIG. 12.
[0096]
 SCMF44 the security key K in step S135 CP-CN was derived, and transmits the NAS SMC message MM entity (hereinafter, referred to as MM) to (S136). MM is equivalent to the CP-CN46. NAS SMC message, the security key K CP-CN including, NSSAI, UE Security Capabilities, the Network Capabilities. Step S137 and S138 are identical to those at steps S116 and S117 in FIG. 12. However, steps S137 and S138 is performed by the MM, steps S116 and S117 in FIG. 12 is performed by SCMF44.
[0097]
 Further, steps S139 ~ S143 is omitted because it is similar to steps S118 ~ S122 in FIG. 12. The UE security key K in step S143 NASint and security key K NASenc Deriving transmits a NAS SM Complete message including the NAS-MAC to MM (S144). Furthermore, MM is, forwards the NAS SM Complete message to SCMF44, SCMF44 transfers the NAS SM Complete message to SEAF43 (S145).
[0098]
 Subsequently, with reference to FIG. 14, a description will be given different NAS Security Procedure and FIGS. Step S151 ~ S157 is omitted because it is similar to the steps S 111 ~ S117 in FIG. 12.
[0099]
 Then, SCMF44 in step S157, the security key K NASint and security key K NASenc after deriving, transmits a NAS SMC message to MM (S158). NAS SMC message, KSI, security key K NASint , security key K NASenc including, NSSAI, UE Security Capabilities, Network Capabilities, NAS enc Algo, NAS int Algo, and NAS-MAC.
[0100]
 Step S159 ~ S165 is omitted because it is similar to steps S139 ~ S145 in FIG. 13.
[0101]
 As described above, by carrying out the NAS Security Procedure shown in FIGS. 12 to 14, the security key K used in the encryption and integrity protection processing of the NAS message NASint security key K used and encryption NASenc the , can be shared in between the UE, the apparatus being arranged in the core network.
[0102]
 (Embodiment 8)
 Subsequently, with reference to FIG. 15, described UP Security Procedure according to the eighth embodiment. UP Security Procedure relates security processing upon transmission of U-Plane data.
[0103]
 First, SCMF44 is carried subscriber information check and (Subscription check) Assigning network slices (NS (Network Slice) allocation) relates UE (S171). Subscriber information check, for example, may be to determine whether it is possible to allow connection to the network slices UE is requested. Map Network slices may be to assign network slices to allow connection to UE.
[0104]
 Then, SCMF44 sends a Slice Initiation Request message to the UP-GW50 (S172). Slice Initiation Request message, the security key K SCMF including and NSSAI. UP-GW 50 is, for example, be a UP-GW, which is located on a network slice SCMF44 assigned.
[0105]
 Then, UP-GW50, the security key K has received SCMF security key K from UP to derive a (S173, S174). Then, UP-GW 50 is, SM entity (hereinafter, referred to as SM) to transmit the Slice Session Request message (S175). SM is, for example, corresponds to the CP-CN46. Slice Session Request message, the security key K UP , including the.
[0106]
 Then, SM, select the algorithm for integrity assurance and encryption, security key K UP to derive the session key from (S176). Sessyon key, for example, the security key K used in integrity protection SessNint security key K used and encryption SessNenc may be.
[0107]
 Then, SM sends a Slice Session Response message to the UP-GW50 (S177). Slice Session Response message, the security key K SessNint and security key K SessNenc including.
[0108]
 Then, UP-GW 50 transmits an UP SMC message to UE (S178). UP SMC message includes KSI, SV (), Algorithms, and NS-MAC. SV is an abbreviation of the Security Vector. Algorithms are algorithms for integrity protection and encryption.
[0109]
 Then, UE, the security key K holds SCMF security key K from UP to derive. Furthermore, UE, in order to use the Algorithms received in step S78, the security key K UP security key K from SessNint and security key K SessNenc deriving a (S179).
[0110]
 Then, UE is the UP SM (Security Mode) Complete message containing NS-MAC transmits to the UP-GW50 (S180). UP-GW50 is, check the value of the NS-MAC, to authenticate the UP SM Complete message. Then, UP-GW 50 transmits a Slice Initiation Response message to the SCMF44 (S181).
[0111]
 Subsequently, with reference to FIG. 16, a description will be given different UP Security Procedure and FIG. Step S191 ~ S196 is omitted because it is similar to the steps S171 ~ S176 in FIG. 15.
[0112]
 SM the security key K in step S196 UP from after deriving the session key, and transmits the UP SMC message to UE (S197). UP SMC message includes KSI, SV (), Algorithms, and NS-MAC.
[0113]
 Step S198 is omitted because it is similar to step S179 of FIG. 15. The UE, in step S198, the security key K SessNint and security key K SessNenc after deriving, transmits the UP SM Complete message containing NS-MAC (S199).
[0114]
 Then, SM is, check the value of the NS-MAC, to authenticate the UP SM Complete message. Then, SM sends a Slice Session Response message to the UP-GW50 (S200). Then, UP-GW 50 transmits a Slice Initiation Response message to the SCMF44 (S201).
[0115]
 Subsequently, with reference to FIG. 17, a description will be given different UP Security Procedure with FIGS. 15 and 16. Step S211 ~ S215 is omitted because it is similar to the steps S171 ~ S175 in FIG. 15.
[0116]
 SM the security key K in step S215 UP receives, and selects the algorithm for integrity protection and encryption. Furthermore, SM sends a Slice Session Response message including information about the selected algorithm as a parameter to the UP-GW50 (S216).
[0117]
 Then, UP-GW 50, based on the selected algorithm in the SM, to derive the session key. Sessyon key, for example, the security key K used in integrity protection SessNint security key K used and encryption SessNenc may be.
[0118]
 Step S218 ~ S221, the detailed description thereof is omitted because it is similar to that of steps S178 ~ S181 in FIG. 15.
[0119]
 Subsequently, with reference to FIG. 18, a description will be given different UP Security Procedure and 15 to 17. Step S231 is omitted because it is similar to step S171 of FIG. 15. Then, SCMF44 the security key K holds SCMF security key K from UP to derive a (S232, S233).
[0120]
 Then, SCMF44 sends a Slice Initiation Request message to the UP-GW50 (S234). Slice Initiation Request message, the security key K UP including and NSSAI. Step S235 ~ S241 is omitted because it is similar to steps S175 ~ S181 in FIG. 15.
[0121]
 Subsequently, with reference to FIG. 19, a description will be given different UP Security Procedure and 15 to 18. Step S251 ~ S256 is omitted because it is similar to steps S231 ~ S236 in FIG. 18. Further, steps S257 ~ S261 is omitted because it is similar to steps S197 ~ S201 in FIG. 16.
[0122]
 Subsequently, with reference to FIG. 20, a description will be given different UP Security Procedure and 15 to 19. Step S271 ~ 275 are identical to those at steps S231 ~ S235 in FIG. 18. Further, steps S276 ~ S281 is omitted because it is similar to steps S216 ~ S221 in FIG. 17.
[0123]
 As described above, by performing the UP Security Procedure shown in FIGS. 15 to 20, the security key used for encryption and integrity protection processing U-Plane data K Sessint and encryption security keys used in the K Sessenc and can be shared in between the UE, the apparatus being arranged in the core network.
[0124]
 (Embodiment 9)
 Subsequently, with reference to FIG. 21 will be described AS Security Procedure according to the ninth embodiment. AS Security Procedure relates security processing between the UE and the NG-RAN48. AS Security Procedure of Figure 21 is executed in the Attach process related UE.
[0125]
 First, SCMF44, the security key K holds SCMF security key K from the AN to derive a (S291, S292). Then, SCMF44 is to SM, and transmits the Attach Accept message (S293). Attach Accept message, the security key K AN including. Next, NG-RAN48, the security key K AN derives the security keys related RRC messages and U-Plane data from (S294). Security keys related RRC messages and U-Plane data includes, for example, security keys K RRCint , security key K RRCenc , security key K UPint , and security key K UPenc may be a (S295).
[0126]
 Next, NG-RAN48 sends AS SMC message containing algorithms for algorithms (Int Algo) and encryption related RRC messages and U-Plane data integrity assurance (Enc Algo) to UE (S296).
[0127]
 Then, UE, the security key K holds SCMF security key K from AN deriving a (S297). Furthermore, UE, the security key K AN from the security key K RRCint , security key K RRCenc , security key K UPint , and security key K UPenc deriving a (S298).
[0128]
 Then, UE sends the UP SM Complete message to NG-RAN48 (S299).
[0129]
 As described above, by performing the AS Security Procedure shown in FIG. 21, the security key K used in the encryption and integrity protection processing of data to be transmitted between the UE and the NG-RAN AN security key from K RRCint , security key K RRCenc , security key K UPint , and security key K UPenc and can be shared in between the UE, the apparatus being arranged in the core network.
[0130]
 (Embodiment 10)
 Subsequently, a configuration example of a communication system according to a tenth embodiment will be described with reference to FIG. 22. Communication system of FIG. 22, UE (User Equipment) 101, (R) AN ((Radio) Access Network) 102, UPF (User Plane Function) entity 103 (hereinafter referred to as UPF103), AMF (Access and Mobility Management Function ) entity 104 (hereinafter referred to as AMF104), SMF (Session Management Function ) entity 105 (hereinafter referred to as SMF105), PCF (Policy Control Function ) entity 106 (hereinafter referred to as PFC106), AUSF (Authentication Server Function ) entity 107 (hereinafter referred to as AUSF107), UDM (Unified Data Management ) 108, DN (Data Network) 109, and AF (Application Function) entity 110 has a (hereinafter, the AF110 be).
[0131]
 (R) AN 102 corresponds to NG-RAN48 and NG-RAN49 in FIG. UPF103 corresponds to UP-GW 50 and UP-GW51 in FIG. AMF104 and SMF105 correspond to CP-CN 46 and CP-CN47 of Figure 10. AUSF107 corresponds to AUSF42 in FIG. Further, as shown in FIG. 22, the communication system of FIG. 22, between the devices or between the function, NG1 ~ NG15 interface is set.
[0132]
 UDM108 manages subscriber data (UE Subscription or Subscription information). Further, for example, UDM108 may be a node apparatus for performing ARPF.
[0133]
 Subsequently, with reference to FIG. 23, described AKA algorithm executed in a node apparatus for performing ARPF. Node apparatus for executing ARPF may be, for example, UDM108. K as a parameter to be input to the AKA algorithm, RAND, SQN (Sequence Number) , SNID, and NSSAI is used. Furthermore, K in AKA algorithm, RAND, SQN (Sequence Number) , SNID, and when NSSAI is input, AUTN_ARPF, XRES, and K SEAF is generated. Further, in FIG. 24 has been shown AKA algorithm executed in UE 101. Also in UE 101, as with ARPF, K as parameters, RAND, SQN (Sequence Number) , SNID, and NSSAI is used. In the UE 101, when executing the AKA algorithms, AUTN_UE, RES and K SEAF is generated. Further, as input parameters 23 and 24, network slice ID, tenant ID , SST (Slice / Service Type), may be used SD (Slice Differentiator).
[0134]
 Subsequently, with reference to FIG. 25, a description will be given of a variation of the hierarchical structure of security keys shown in FIG. 11. In the hierarchical structure of Figure 25, NG-RAN48 is, the security key K SEAF K using AN in terms of deriving different from the hierarchical structure of FIG. 11. The other points in the hierarchical structure of Figure 25, and detailed description thereof will be omitted because it is similar to that of FIG 11.
[0135]
 Subsequently, the flow of the derivation of the security keys in the hierarchical structure of the security key 25 will be described with reference to FIG. 26. The derivation of the security key, KDF (Key Deriviation Function) is used. Security key K SCMF , the security key K to the KDF SEAF is derived by, SST (Slice / Service Type) , that and SD (Slice Differentiator) is input. Security key K CP-CN , the security key K to KDF SCMF is derived by and COUNT is inputted. Also, for all the KDF shown in FIG. 26, SST, SD, NSSAI, network slice ID, the value of the tenant ID, or may be used derived value using these values as input values.
[0136]
 Security key K NAS_MMint is, the KDF, NAS-int-algo and security key K CP-CN is derived by that is input. Security key K NASenc is the KDF, NASenc-algo and security key K CP-CN is derived by are input.
[0137]
 Security key K UP is, the KDF, security key K SCMF , Counter, Time Limit, and Data volume is derived by being input. Security key K Sessint is, the KDF, security key K UP is derived by, UP-int-algo, and Counter is input. Security key K Sessenc is, the KDF, security key K UP is derived by, UP-enc-algo, and Counter is input.
[0138]
 Security key K AN , the security key K to KDF SEAF is derived by, NAS Uplink Count, and RAN slice parameters are input. Security key K RRCint the security key K AN is derived by and RRCint-algo is input. Security key K RRCenc the security key K AN is derived by and RRCenc-algo is input. Security key K UPint the security key K AN is derived by and AN-UPint-algo is input. Security key K UPenc the security key K AN is derived by and AN-UPenc-algo is input.
[0139]
 Subsequently, with reference to FIG. 27, a description will be given of a variation of the hierarchical structure of security keys shown in FIG. 11. In the hierarchical structure of Figure 27, AMF104 is, the security key K received from UDM108 SEAF security keys from K CP-CN_MM , security key K AN_other , security key K 3GPP_AN , and security key K non-3GPP_AN generates, the. In addition, AMF104, the security key K CP-CN_MM from, security key K NAS-MM_enc and security key K NAS-MM_int to generate. Security key K NAS-MM_enc and security key K NAS-MM_int is used integrity protection and ciphering of NAS messages related to Mobility Management.
[0140]
 AMF104 the security key K SEAF transmits the SMF105, UPF103, and the (R) AN 102.
[0141]
 SMF105, the security key K SEAF security key K from CP-CN_SM to derive. In addition, SMF105, the security key K CP-CN_SM from, security key K NAS-SM_enc and security key K NAS-SM_int to generate. Security key K NAS-SM_enc and security key K NAS-SM_int is used integrity protection and ciphering of NAS messages related to Session Management.
[0142]
 UPF103, the security key K SEAF security key K from UP to derive. Furthermore, SMF105 the security key K UP from the security key K Sess1enc security key K used in the integrity protection processing and NAS message Sess1int to generate. Furthermore, UPF103 as security keys used in any session N, security key K SessNenc and security key K SessNint to generate.
[0143]
 (R) AN102, the security key K SEAF security key K from the AN / NH to derive. Further (R) AN 102, the security key K AN / NH from the security key K RRCenc , security key K RRCint , security key K UPenc and security key K UPint to generate.
[0144]
 Subsequently, the flow of the derivation of the security keys in the hierarchical structure of the security key 27 will be described with reference to FIG. 28. Security key K CP-CN_MM , in AMF104, security key K to KDF SEAF is derived by and COUNT is inputted. Security key K NAS_MMint is the KDF, NAS_MMint-algo and security key K CP-CN_MM is derived by are input. Security key K NAS_MMenc is the KDF, NAS_MMenc-algo and security key K CP-CN_MM is derived by are input.
[0145]
 Security key K CP-CN_SM is, in SMF105, security key K to the KDF SEAF is derived by, the SST and SD is input. Security key K NAS_SMint is the KDF, NAS_SMint-algo and security key K CP-CN_SM is derived by are input. Security key K NAS_SMenc is the KDF, NAS_SMenc-algo and security key K CP-CN_SM is derived by are input.
[0146]
 Security key K UP , in SMF105, the KDF, the security key K SEAF , Counter, Time limit, and Data volume is derived by input. Security key K Sessint and security key K Sessenc is a detailed description thereof is omitted because it is derived in the same manner as FIG. 26.
[0147]
 Security key K AN , security key K RRCint , security key K RRCenc , security key K UPint , and security key K UPenc is a detailed description thereof is omitted because it is derived in the same manner as FIG. 26. The security key K AN , security key K RRCint , security key K RRCenc , security key K UPint , and security key K UPenc is derived in NG-RAN48 corresponding to (R) AN 102.
[0148]
 Subsequently, with reference to FIG. 29, a description will be given of a variation of the hierarchical structure of security keys shown in FIG. 11. In the hierarchical structure of Figure 29, AMF104 is, the security key K received from UDM108 SEAF security keys from K NAS-MMenc , security key K NAS-MMint , security key K AN_other , security key K 3GPP_AN , and security key K Non- 3GPP_AN , to generate.
[0149]
 AMF104 the security key K SEAF transmits the to SMF105 and (R) AN 102.
[0150]
 SMF105, the security key K SEAF security key K from NAS_SM to generate. Furthermore, SMF105 the security key K NAS_SM from the security key K UP, security key K NAS-SM_enc and security key K NAS-SM_int to generate. In addition, SMF105, the security key K UP from, security key K Sess1enc and security key K Sess1int to generate. Furthermore, SMF105 as security keys used in any session N, security key K SessNenc and security key K SessNint to generate.
[0151]
 (R) AN 102, the security key K SEAF security key K from AN / NH generates a. Furthermore, (R) AN 102, the security key K AN / NH from the security key K RRCenc , security key K RRCint , security key K UPenc and security key K UPint to generate.
[0152]
 Subsequently, the flow of the derivation of the security keys in the hierarchical structure of the security key 29 will be described with reference to FIG. 30. Security key K NAS_MMint , in AMF104, the KDF, NAS_MMint-algo and security key K SEAF is derived by are input. Security key K NAS_MMenc is the KDF, NAS_MMenc-algo and security key K SEAF is derived by are input.
[0153]
 Security key K NAS_SM , in SMF105, security key K to KDF SEAF is derived by, the SST and SD are inputted. Security key K NAS_SMint is the KDF, NAS_SMint-algo and security key K NAS_SM is derived by are input. Security key K NAS_SMenc is the KDF, NAS_SMenc-algo and security key K NAS_SM is derived by are input.
[0154]
 Security key K UP , in SMF105, the KDF, the security key K NAS_SM , Counter, Time limit, and Data volume is derived by input. Security key K Sessint and security key K Sessenc is a detailed description thereof is omitted because it is derived in the same manner as FIG. 26.
[0155]
 Security key K AN , security key K RRCint , security key K RRCenc , security key K UPint , and security key K UPenc is a detailed description thereof is omitted because it is derived in the same manner as FIG. 26. The security key K AN , security key K RRCint , security key K RRCenc , security key K UPint , and security key K UPenc is derived in NG-RAN48 corresponding to (R) AN 102.
[0156]
 Subsequently, with reference to FIG. 31, a description will be given of a variation of the hierarchical structure of security keys shown in FIG. 11. In the hierarchical structure of Figure 31, UDM108 is, from the security key K, to derive a CK (Cipher Key), and IK (Integrity Key). In addition, UDM108, the security key K from CK and IE SEAF to derive. Further, in the hierarchical structure of FIG. 31, AMF104 is, the security key K received from UDM108 SEAF security key K from NAS-MM derives further security key K NAS-MM security key K from NAS-MMint and security keys K NAS-MMenc in that to produce a different from the hierarchical structure of Figure 29. Other hierarchical structure of FIG. 31, a detailed description thereof will be omitted because it is similar to that of FIG 29.
[0157]
 Subsequently, the flow of the derivation of the security keys in the hierarchical structure of the security key 31 will be described with reference to FIG. 32. Security key K NAS_MM , in AMF104, the KDF, COUNT and security key K SEAF is derived by input. Security key K NAS_MMint , in AMF104, the KDF, NAS_MMint-algo and security key K NAS_MM is derived by are input. Security key K NAS_MMenc is the KDF, NAS_MMenc-algo and security key K NAS_MM is derived by are input.
[0158]
 Derivation of the security keys to be executed in SMF105 and NG-RAN48 is a detailed description thereof will be omitted because it is similar to that of FIG 30.
[0159]
 Subsequently, with reference to FIG. 33, a description will be given of a variation of the hierarchical structure of security keys shown in FIG. 11. SMF105 in the hierarchical structure of Figure 33, the security key K received from AMF104 SEAF security key K from UP to generate. Hierarchy of other security keys, and detailed description thereof will be omitted because it is similar to that of FIG 29.
[0160]
 Subsequently, the flow of the derivation of the security keys in the hierarchical structure of the security key 33 will be described with reference to FIG. 34. Security key K UP , in SMF105, the KDF, Counter, Time limit, Data volume and security key K SEAF is derived by input.
[0161]
 Derivation of other security keys to be executed in SMF105, further derivation of the security keys to be executed in AMF104 and NG-RAN48 is a detailed description thereof will be omitted because it is similar to that of FIG 30.
[0162]
 Subsequently, with reference to FIG. 35, a description will be given of a variation of the hierarchical structure of security keys shown in FIG. 11. SMF105 in the hierarchical structure of Figure 35, the security key K received from AMF104 SEAF security key K from UP to generate. In addition, SMF105 the security key K NAS-SM does not perform the derivation of. Hierarchy of other security keys, and detailed description thereof will be omitted because it is similar to that of FIG 31.
[0163]
 Subsequently, the flow of the derivation of the security keys in the hierarchical structure of the security key 35 will be described with reference to FIG. 36. Security key K UP , in SMF105, the KDF, Counter, Time limit, Data volume and security key K SEAF is derived by input. In addition, the security key K NAS-SM is not derived in SMF105.
[0164]
 Derivation of the security keys to be executed in AMF104 and NG-RAN48 is a detailed description thereof will be omitted because it is similar to that of FIG 32.
[0165]
 Subsequently, with reference to FIG. 37, a description will be given of a variation of the hierarchical structure of security keys shown in FIG. 11. AMF104 in the hierarchical structure of Figure 37, the derived security key K NAS-MM sends a to the (R) AN 102. Furthermore, (R) AN 102, the security key K received from AMF104 NAS-MM security key K from AN / NH generates a. Hierarchy of other security keys, and detailed description thereof will be omitted because it is similar to that of FIG 35.
[0166]
 Subsequently, the flow of the derivation of the security keys in the hierarchical structure of the security key 37 will be described with reference to FIG. 38. Security key K AN / NH , in NG-RAN48 corresponding to (R) AN 102, the KDF, the security key K NAS-MM is derived by, NAS Uplink Count, and RAN slice parameters are input.
[0167]
 Derivation of other security keys to be executed in the NG-RAN48, further derivation of the security keys to be executed in AMF104 and SMF105 is a detailed description thereof will be omitted because it is similar to that of FIG 36.
[0168]
 Subsequently, with reference to FIG. 39, a description will be given of a variation of the hierarchical structure of security keys shown in FIG. 11. Hierarchical structure of FIG. 39, SMF105 is security key K NAS-SM in that it does not perform the derivation of, different from the hierarchical structure of Figure 33. Other hierarchical structure of FIG. 39, a detailed description thereof will be omitted because it is similar to that of FIG 33.
[0169]
 Subsequently, the flow of the derivation of the security keys in the hierarchical structure of the security key 39 will be described with reference to FIG. 40. In FIG. 40, in SMF105, security key K NAS-SM in that is not derived differs from the flow of the derivation of the security keys in Figure 34. Other flow derivation of the security keys in FIG. 40, a detailed description thereof will be omitted because it is similar to that of FIG 34.
[0170]
 Derived in the above description, AMF104, SMF105, UPF103, and although such NG-RAN48 has been described to derive the security keys, the same security key security key to derive at each entity (node ​​apparatus), even in the UE101 It is.
[0171]
 By using the flow of the derivation of the hierarchical structure and the security key of the security keys described in FIGS. 23 to 40, for example, the security key K NAS-SM and security key K NAS-MM to each derive a Network slices it can be used specific parameters (Count) associated with mobility and.
[0172]
 The above embodiment has been described as an example composed of hardware, but is not limited thereto. The present disclosure, the processing in the UE and each device can also be implemented by executing a computer program to CPU (Central Processing Unit).
[0173]
 In the above example, the program may be stored using a non-transitory computer readable media of various types (non-transitory computer readable medium), it can be supplied to the computer. Non-transitory computer readable media include with various types of entities (tangible storage medium). Examples of non-transitory computer readable media include magnetic storage media (such as floppy disks, magnetic tape, hard disk drive), magneto-optical recording medium (e.g. optical disk), CD-ROM (Read Only Memory), CD-R, CD-R / W, a semiconductor memory (e.g., a mask ROM, PROM (Programmable ROM), EPROM (Erasable PROM), flash ROM, RAM (Random Access memory)) includes a. The program may be provided to a computer using a temporary computer readable media of various types (transitory computer readable medium). Examples of transitory computer readable media include electric signals, optical signals, and electromagnetic waves. Transitory computer readable media, wired communication path such as electrical wires and optical fibers, or via a wireless communication path can provide the program to a computer.
[0174]
 The present disclosure is not limited to the above embodiments, but can be appropriately changed without departing from the spirit. The present disclosure may be implemented in combination in the form of respective embodiments as appropriate.
[0175]
 Although the present invention has been described with reference to the embodiments, the present invention is not limited by the foregoing. Configuration and details of the present invention, it is possible to make various modifications that those skilled in the art can understand within the scope of the invention.
[0176]
 This application claims priority based on Indian Application 201711003071, filed in 2016, India filed filed October 26 201611036774 and 201611036775, and January 27, 2017, the disclosures of which are herein take in to.
DESCRIPTION OF SYMBOLS
[0177]
 10 communication terminal
 10_1 communication terminal
 20 network device
 20_1 core network system
 30 mobile network
 41 ARPF
 42 Ausf
 43 SEAF
 44 SCMF
 45 SCMF
 46
 CP-CN
 47
 CP-CN 48
 NG-RAN 49 NG-RAN
 50 UP-GW 51 UP-GW
 UE 101
 102
 (R)
 AN 103
 UPF 104
 AMF 105
 SMF 106
 PCF 107
 Ausf 108 UDM
 109 DN 110 AF

WE claims

A communication terminal that transmits NSSAI (Network Slice Selection Assistance Information) and UE (User Equipment) Attach Request message including the Security Capabilities,
 disposed in a mobile network, and a network device for receiving the Attach Request message,
 the network device,
 using the NSSAI and the UE Security Capabilities, among the plurality of core network divided by the network slicing determines whether or not to permit the connection of the communication terminal to the core network shown in the NSSAI ,Communications system.
[Requested item 2]
 The network device is
 a wireless device for performing the communication terminal and the wireless communication,
 performs an authentication process related to the communication terminal, further comprising a security device disposed within the mobile network,
 the wireless device,
 the Attach Request message was transmitted to the security device,
 said security device,
 check the integrity of the Attach Request message (integrity), it transmits the confirmation result to the wireless device, a communication system according to claim 1.
[Requested item 3]
 The network device is
 the a core network apparatus which is disposed in the core network included in the mobile network, by performing the AKA (Authentication and Key Agreement) process between said communication terminal derives the security key , by using the security key to verify the integrity of the Attach Request message, the communication system according to claim 1.
[Requested item 4]
 The network device is
 the a core network apparatus which is disposed in the core network included in the mobile network,
 in a plurality of the network devices, using the NSSAI and the UE Security Capabilities, a plurality of divided by the network Slicing of the core network, wherein the distributing processing to determine whether or not to permit the connection of the communication terminal to the core network shown in NSSAI, the communication system according to claim 1.
[Requested item 5]
 And a communication terminal for transmitting NSSAI (Network Slice Selection Assistance Information) and UE (User Equipment) Attach Request message including the Security Capabilities to receive the Attach Request message,
 using the NSSAI and the UE Security Capabilities, among a plurality of core network divided by the network slicing, configured to determine whether or not to permit the connection of the communication terminal to the core network shown in the NSSAI, network device.
[Requested item 6]
 Receives NSSAI (Network Slice Selection Assistance Information) and UE (User Equipment) from said communication terminal to transmit the Attach Request message that contains the Security Capabilities Attach Request message,
 using the NSSAI and the UE Security Capabilities, divided by the network Slicing It has been among the plurality of core network, determining whether or not the authentication method permits the connection of the communication terminal to the core network shown in the NSSAI.
[Requested item 7]
 A communication terminal that transmits Attach Request message containing NSSAI (Network Slice Selection Assistance Information) ,
 disposed in a mobile network, and a network device for receiving the Attach Request message,
 the communication terminal and said network device , using as input at least said NSSAI, by performing the AKA (Authentication and key Agreement) process, and the communication terminal and the network device to derive the same security key, communication system.
[Requested item 8]
 NSSAI (Network Slice Selection Assistance Information) and transmits the Attach Request message containing and a communication terminal to receive the Attach Request message,
 using as inputs at least the NSSAI, AKA with the communication terminal (Authentication by executing and key Canada Agreement) process, configured to derive the same security key security key by the communication terminal derives the network device.
[Requested item 9]
 NSSAI the Attach Request message including (Network Slice Selection Assistance Information), is configured to transmit to a network device disposed in the mobile network,
 using as input at least said NSSAI, AKA between said network device ( by running the Authentication and key Agreement) process, configured to derive the same security key security keys which the network device derives the communication terminal.
[Requested item 10]
 A communication terminal,
 a communication system and a core network system that performs a NAS Security Procedure for said communication terminal,
 the core network system
 in the NAS Security Procedure, NSSAI (Network Slice Selection Assistance Information) and UE ( get the security key using the User Equipment) security Capabilities, and transmits the information related to the NSSAI and the UE security Capabilities to said communication terminal,
 said communication terminal,
 information related to the NSSAI and the UE security Capabilities obtaining the security key by using the communication system.
[Requested item 11]
 The core network system,
 the acquired from the security key encryption keys and integrity protection keys, the encryption algorithm and integrity protection algorithm executed by using the encryption key and the integrity protection key and transmitted to the communication terminal ,
 the communication terminal,
 in order to use the cryptographic algorithm and the integrity protection algorithm, and obtains the encryption key and integrity protection key used in NAS protocol, the communication system according to claim 10.
[Requested item 12]
 A communication terminal,
 a communication system and a core network system to perform UP Security Procedure for said communication terminal,
 the core network system,
 in the UP Security Procedure, using NSSAI (Network Slice Selection Assistance Information) get the security key, using said security key to obtain a user plane encryption key and for user plane integrity protection key used in the session for transferring user data, for the user plane encryption key and said user plane an algorithm executed by using the integrity protection key and transmitted to the communication terminal,
 the communication terminal,
 in order to use the algorithm, the acquiring security keys relating the acquired UP security Procedure in the core network system ,Communications system.
[Requested item 13]
 In NAS Security Procedure, a key generating unit for acquiring security key using NSSAI (Network Slice Selection Assistance Information) and UE (User Equipment) Security Capabilities,
 transmits the information related to the NSSAI and the UE Security Capabilities to the communication terminal security device comprising a communication unit which, a.
[Requested item 14]
 In UP Security Procedure, acquires the security key using NSSAI (Network Slice Selection Assistance Information) , using said security key, integrity-guarantee-use encryption key and the user plane for the user plane used in the session for transferring user data a key generating unit for acquiring key,
 the security device comprising a communication unit for transmitting an algorithm executed by using the encryption key and integrity protection keys for the user plane for the user plane to the communication terminal.
[Requested item 15]
 A communication unit from the core network system receives the information related to NSSAI (Network Slice Selection Assistance Information) and UE (User Equipment) Security Capabilities,
 the NAS Security Procedure, using information related to the NSSAI and the UE Security Capabilities communication terminal comprising a key generating unit for acquiring security keys, a.
[Requested item 16]
 From the core network system, the UP Security Procedure, a communication unit that receives an algorithm executed by using the integrity-guarantee-key encryption key and the user plane for the user plane,
 get to use the algorithm, in the core network system communication terminal comprising: a key generation unit, a for acquiring the encryption key for the user plane and the integrity-guarantee-key the user plane is.
[Requested item 17]
 In NAS Security Procedure, acquires security keys, using NSSAI (Network Slice Selection Assistance Information) and UE (User Equipment) Security Capabilities
 transmits the NSSAI and information related to the UE Security Capabilities to the communication terminal, the core network communication method in a system.
[Requested item 18]
 And from the security device to NSSAI (Network Slice Selection Assistance Information) receives information related to UE (User Equipment) Security Capabilities,
 the NAS Security Procedure, the security key using the information associated with the NSSAI and the UE Security Capabilities acquiring a communication method in a communication terminal.
[Requested item 19]
 In UP Security Procedure, acquires the security key using NSSAI (Network Slice Selection Assistance Information) ,
 using said security key, integrity-guarantee-use encryption key and the user plane for the user plane used in the session for transferring user data get the key,
 sends an algorithm executed by using the encryption key and integrity protection keys for the user plane for the user plane to the communication terminal, the method communication in the core network system.
[Requested item 20]
 From the core network system, the UP Security Procedure, receives an algorithm executed by using the integrity-guarantee-key encryption key and the user plane for the user plane,
 in order to use the algorithm, acquired in the core network system wherein obtaining an encryption key and integrity protection keys for the user plane for the user plane communication method in a communication terminal.
[Requested item 21]
 The NSSAI and information related to the UE Security Capabilities are NAS Security Mode Command message, the communication system according to claim 10.
[Requested item 22]
 Information relating to the NSSAI and the UE Security Capabilities are NAS Security Mode Command message, the security device according to claim 13.
[Requested item 23]
 Information relating to the NSSAI and the UE Security Capabilities are NAS Security Mode Command message, the communication terminal according to claim 15.

Documents

Application Documents

# Name Date
1 201917020703.pdf 2019-05-24
2 201917020703-TRANSLATIOIN OF PRIOIRTY DOCUMENTS ETC. [24-05-2019(online)].pdf 2019-05-24
3 201917020703-STATEMENT OF UNDERTAKING (FORM 3) [24-05-2019(online)].pdf 2019-05-24
4 201917020703-REQUEST FOR EXAMINATION (FORM-18) [24-05-2019(online)].pdf 2019-05-24
5 201917020703-PRIORITY DOCUMENTS [24-05-2019(online)].pdf 2019-05-24
6 201917020703-POWER OF AUTHORITY [24-05-2019(online)].pdf 2019-05-24
7 201917020703-FORM 18 [24-05-2019(online)].pdf 2019-05-24
8 201917020703-FORM 1 [24-05-2019(online)].pdf 2019-05-24
9 201917020703-DRAWINGS [24-05-2019(online)].pdf 2019-05-24
10 201917020703-DECLARATION OF INVENTORSHIP (FORM 5) [24-05-2019(online)].pdf 2019-05-24
11 201917020703-COMPLETE SPECIFICATION [24-05-2019(online)].pdf 2019-05-24
12 201917020703-Power of Attorney-280519.pdf 2019-05-30
13 201917020703-OTHERS-280519.pdf 2019-05-30
14 201917020703-Correspondence-280519.pdf 2019-05-30
15 201917020703-RELEVANT DOCUMENTS [03-06-2019(online)].pdf 2019-06-03
16 201917020703-MARKED COPIES OF AMENDEMENTS [03-06-2019(online)].pdf 2019-06-03
17 201917020703-FORM 13 [03-06-2019(online)].pdf 2019-06-03
18 201917020703-AMMENDED DOCUMENTS [03-06-2019(online)].pdf 2019-06-03
19 abstract.jpg 2019-07-08
20 201917020703-Proof of Right (MANDATORY) [04-11-2019(online)].pdf 2019-11-04
21 201917020703-certified copy of translation (MANDATORY) [06-11-2019(online)].pdf 2019-11-06
22 201917020703-Proof of Right (MANDATORY) [07-11-2019(online)].pdf 2019-11-07
23 201917020703-OTHERS-061119.pdf 2019-11-11
24 201917020703-Correspondence-061119.pdf 2019-11-11
25 201917020703-OTHERS-081119.pdf 2019-11-14
26 201917020703-Correspondence-081119.pdf 2019-11-14
27 201917020703-OTHERS-131119.pdf 2019-11-18
28 201917020703-Correspondence-131119.pdf 2019-11-18
29 201917020703-FORM 3 [20-11-2019(online)].pdf 2019-11-20
30 201917020703-OTHERS [20-05-2021(online)].pdf 2021-05-20
31 201917020703-Information under section 8(2) [20-05-2021(online)].pdf 2021-05-20
32 201917020703-FORM-26 [20-05-2021(online)].pdf 2021-05-20
33 201917020703-FORM 3 [20-05-2021(online)].pdf 2021-05-20
34 201917020703-FER_SER_REPLY [20-05-2021(online)].pdf 2021-05-20
35 201917020703-DRAWING [20-05-2021(online)].pdf 2021-05-20
36 201917020703-CLAIMS [20-05-2021(online)].pdf 2021-05-20
37 201917020703-FER.pdf 2021-10-18
38 201917020703-US(14)-HearingNotice-(HearingDate-18-10-2023).pdf 2023-09-23
39 201917020703-REQUEST FOR ADJOURNMENT OF HEARING UNDER RULE 129A [13-10-2023(online)].pdf 2023-10-13
40 201917020703-US(14)-ExtendedHearingNotice-(HearingDate-20-11-2023).pdf 2023-10-16
41 201917020703-REQUEST FOR ADJOURNMENT OF HEARING UNDER RULE 129A [15-11-2023(online)].pdf 2023-11-15
42 201917020703-US(14)-ExtendedHearingNotice-(HearingDate-20-12-2023).pdf 2023-11-20
43 201917020703-FORM-26 [19-12-2023(online)].pdf 2023-12-19
44 201917020703-Correspondence to notify the Controller [19-12-2023(online)].pdf 2023-12-19
45 201917020703-Correspondence to notify the Controller [20-12-2023(online)].pdf 2023-12-20
46 201917020703-GPA-211223.pdf 2024-01-05
47 201917020703-Correspondence-211223.pdf 2024-01-05

Search Strategy

1 SearchStrategy201917020703E_11-11-2020.pdf