Sign In to Follow Application
View All Documents & Correspondence

Source Core Network Node, Communication Terminal And Corresponding Communication Methods

Abstract: The purpose of the present invention is to provide a communication system that executes necessary security procedures when a handover process is executed in a NextGen System. This communication system comprises: a base station (10) which forms a communication area in which a communication terminal (20) is located; and a base station (12) which forms a handover destination communication area for the communication terminal (20). The base station (10) receives from the communication terminal (20) a first message relating to a handover which includes User Equipment (UE) Security Capabilities. The base station (12) receives a second message which includes the UE Security Capabilities, confirms handover execution by the communication terminal (20) on the basis of the UE Security Capabilities, and transmits a third message corresponding to the second message, on the basis of the results of the handover execution confirmation.

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
24 May 2019
Publication Number
34/2019
Publication Type
INA
Invention Field
COMMUNICATION
Status
Email
archana@anandandanand.com
Parent Application
Patent Number
Legal Status
Grant Date
2024-05-10
Renewal Date

Applicants

NEC CORPORATION
7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001

Inventors

1. PRASAD Anand Raghawa
c/o NEC Corporation, 7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001
2. LAKSHMINARAYANAN Sivakamy
c/o NEC India Pvt Ltd., SP Infocity, Block-A, 9th Floor, Module-2A, 40, MGR Salai, Kandanchavadi, Perungudi, Chennai 600096
3. ARUMUGAM Sivabalan
c/o NEC India Pvt Ltd., SP Infocity, Block-A, 9th Floor, Module-2A, 40, MGR Salai, Kandanchavadi, Perungudi, Chennai 600096
4. BASKARAN Sheeba Backia Mary
c/o NEC India Pvt Ltd., SP Infocity, Block-A, 9th Floor, Module-2A, 40, MGR Salai, Kandanchavadi, Perungudi, Chennai 600096
5. ITO Hironori
c/o NEC Corporation, 7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001
6. KUNZ Andreas
c/o NEC Europe Ltd., Kurfursten-Anlage 36, Heidelberg 69115

Specification

The present invention is a communication system, the security device, a communication terminal and a communication method.
BACKGROUND
[0002]
 Currently, as a radio communication scheme used between the communication terminal and the base station, LTE (Long Term Evolution) has become widespread it is stipulated specifications in 3GPP (3rd Generation Partnership Project). LTE is a wireless communication system used to implement the wireless communication of the high-speed and large capacity. Further, as the core network that accommodates a wireless network using LTE, the 3GPP, SAE (System Architecture Evolution) or EPC (Evolved Packet Core) or the like called a packet network it is defined.
[0003]
 Communication terminal, in order to utilize the communication service using LTE, are required to register with the core network. As a procedure for registering the communication terminal to the core network, Attach Procedure is defined in 3GPP. MME disposed within a core network (Mobility Management Entity) executes authentication processing of the communication terminal using the identification information of the communication terminal in Attach Procedure. The MME, in cooperation with the HSS (Home Subscriber Server) or the like which manages subscriber information and performs authentication processing of the communication terminal. As the identification information of the communication terminal, for example, IMEISV (International Mobile Equipment Identity) or IMSI (International Mobile Subscriber Identity) or the like is used.
[0004]
 In recent years, in 3GPP, IoT is Study (Internet of Things) service has been promoted. The IoT services, without user terminal to perform autonomously communication (hereinafter referred to as IoT terminal) is used numerous. Therefore, the service provider is to provide the IoT services using a number of IoT terminal, the mobile network operators, etc. are managed, it is desirable to efficiently accommodate many IoT terminal. Mobile network is a network that includes a wireless network and a core network.
[0005]
 In Annex B of Non-Patent Document 1, the configuration of the core network to which the network slicing is described. Network slicing, in order to accommodate more IoT terminal efficiently, a technique for dividing the core network for each service provided. Further, in Section 5.1, the divided each network (network slice system), it is described that customization and optimization is required.
[0006]
 System to which the network slicing, for example, also called NextGen (Next Generation) System. The radio network used in NextGen System may also be referred to as NG (Next Generation) RAN (Radio Access Network).
CITATION
Non-patent literature
[0007]
Non-Patent Document 1: 3GPP TR23.799 V1.0.2 (2016-9)
Non-Patent Document 2: 3GPP TR33.899 V0.5.0 (2016-10)
Summary of the Invention
Problems that the Invention is to Solve
[0008]
 When the communication terminal moves during communication, NextGen System, like the mobile network having a LTE and EPC, executes the handover process, it is necessary to continue the communication in the communication terminal. However, in the NextGen System, has been introduced various functions related to security processing, a handover processing using the security procedure defined currently in 3GPP, there is a problem that can not be directly applied to NextGen System . Specifically, in Non-Patent Document 2, ARPF (Authentication Credential Repository and Processing Function), AUSF (Authentication Server Function), SEAF (Security Anchor Function), and SCMF introducing (Security Context Management Function), etc. NextGen System There has been studied.
[0009]
 An object of the present invention is to provide a communication system that performs the security procedures required when the handover process is performed in NextGen System, security device, a communication terminal, and a communication method.
Means for Solving the Problems
[0010]
 Communication system according to a first aspect of the present invention includes a first base station that forms a communication area where the communication terminal is present, and a second base station forming a communication area of ​​the handover destination of the communication terminal the first base station may receive a first message relating to the handover including UE Security Capabilities from the communication terminal, the second base station receives the second message including the UE Security Capabilities , on the basis of the UE Security Capabilities perform a handover execution confirmation of the communication terminal, transmitting a third message corresponding to the second message based on the handover execution confirmation results.
[0011]
 The base station according to the second aspect of the present invention is a base station forming a communication area where the communication terminal is present, receives the first message relating to the handover of the communication terminal includes a UE Security Capabilities, the communication be another base station forming a communication area of ​​the handover destination terminal, wherein the performing the handover execution confirmation of the communication terminal based on the UE Security Capabilities to another base station, first comprises the UE Security Capabilities 2 a communication unit for transmitting the message.
[0012]
 Control method according to a third aspect of the present invention is a control method in a base station forming a communication area where the communication terminal is present, receives the first message relating to the handover of the communication terminal includes a UE Security Capabilities , a other base station forming a communication area of ​​the handover destination of the communication terminal, to the other base station to perform the handover execution confirmation of the communication terminal based on the UE Security Capabilities, the UE Security Capabilities transmitting a second message including.
[0013]
 Communication terminal according to the fourth aspect of the present invention is a communication terminal performing handover, a transmission unit for transmitting a first message relating to the handover including UE Security Capabilities to the first base station, the handover a second base station forming a previous communication area of, said after the handover execution confirmation of the communication terminal based on the UE Security Capabilities, receiving section for receiving a second message from the first base station , comprising a.
Effect of the invention
[0014]
 The present invention can provide a communication system that performs the security procedures required when the handover process is performed in NextGen System, security device, a communication terminal, and a communication method.
BRIEF DESCRIPTION OF THE DRAWINGS
[0015]
FIG. 1 is a configuration diagram of a communication system in the first embodiment.
FIG. 2 is a configuration diagram of a communication system according to the second embodiment.
3 is a diagram showing a flow of the handover process according to the second embodiment.
4 is a diagram showing a flow of the handover process according to the second embodiment.
5 is a diagram showing a flow of the handover process according to the second embodiment.
6 is a diagram showing a flow of the handover processing according to the third embodiment.
7 is a diagram showing a flow of the handover processing according to the third embodiment.
8 is a diagram showing a flow of the handover processing according to the fourth embodiment.
9 is a diagram showing a flow of the handover processing according to the fourth embodiment.
10 is a diagram showing a flow of the handover processing according to the fourth embodiment.
11 is a diagram showing a flow of the handover processing according to the fourth embodiment.
12 is a diagram showing a flow of the handover processing according to the fourth embodiment.
13 is a diagram showing a flow of the handover process according to the fifth embodiment.
14 is a diagram showing a flow of the handover process according to the fifth embodiment.
15 is a configuration diagram of a communication system in the sixth embodiment.
16 is a diagram showing a flow of the handover processing according to the sixth embodiment.
17 is a diagram showing a flow of the handover processing according to the sixth embodiment.
18 is a diagram showing a flow of the handover processing according to the sixth embodiment.
19 is a diagram showing a flow of the handover processing according to the sixth embodiment.
FIG. 20 is a diagram showing a flow of the handover processing according to the sixth embodiment.
21 is a diagram showing a flow of the handover processing according to the sixth embodiment.
22 is a diagram showing a flow of the handover processing according to the sixth embodiment.
23 is a diagram showing a flow of the handover processing according to the sixth embodiment.
FIG. 24 is a configuration diagram of a communication system according to the seventh embodiment.
[FIG 25 is a configuration diagram of a communication system according to the seventh embodiment.
DESCRIPTION OF THE INVENTION
[0016]
 (Embodiment 1)
 Hereinafter, with reference to the drawings will be described embodiments of the present invention. A configuration example of a communication system according to the first embodiment will be described with reference to FIG. Communication system of FIG. 1 includes a base station 10, base station 12, and the communication terminal 20.
[0017]
 The base station 10, base station 12, and the communication terminal 20 may be a computer system that operates by the processor executing the program stored in the memory. The processor may, for example, a microprocessor may be a MPU (Micro Processing Unit), or CPU (Central Processing Unit). The memory may be a volatile memory or nonvolatile memory, it may be configured by a combination of volatile and nonvolatile memory. Processor executes one or more programs including instructions for performing the algorithm described with reference to subsequent figures the computer.
[0018]
 Communication terminal 20, a mobile phone terminal, a smartphone terminal, may be the IoT terminal and the like.
[0019]
 The base station 10 and base station 12 forms a communication area, respectively. Communication terminal 20 in the communication area formed by the base station 10 performs the base station 10 and the wireless communication in the communication area formed by the base station 12 performs the base station 12 and wireless communication. In Figure 1, the communication terminal 20 from the communication area formed by the base station 10, how the movement is indicated to the communication area formed by the base station 12. That is, FIG. 1, the communication terminal 20 from the communication area formed by the base station 10 indicates that a handover to a communication area formed by the base station 12.
[0020]
 When the communication terminal 20 performs a handover, the base station 10 receives a message containing a UE Security Capabilities from the communication terminal 20. The base station 10 may transmit a message containing a UE Security Capabilities received to the base station 12. The base station 10 via the set interface or reference point between the base station 10 and base station 12 may transmit the UE Security Capabilities. Or, the base station 10 via a higher-level device which controls the base station to the base station 12 may transmit the UE Security Capabilities.
[0021]
 UE Security Capabilities may be a set of identification information corresponding to the algorithm information to be used by the encryption and integrity protection processing executed in the UE is a communication terminal 20.
[0022]
 The base station 12 receives a message regarding handover including UE Security Capabilities, performing a handover execution confirmation of the communication terminal 20 based on the UE Security Capabilities. Confirmation handover execution may be referred to as a check processing (check). Handover execution confirmation using UE Security Capabilities, for example, the UE Security Capabilities, the method comprising: determining whether the base station 12 contains algorithm information used for encryption and integrity protection process run it may be. Message about the handover base station 12 receives may include further NSSAI. In this case, the base station 12 executes the confirmation handover performed on the basis of NSSAI.
[0023]
 Base station 12, based on the handover execution confirmation result, transmits a message corresponding to the message containing the UE Security Capabilities received. Specifically, the base station 12, the handover execution confirmation of results using the UE Security Capabilities, if the communication terminal 20 is allowed to communicate with the base station 12, to the base station 10 executes the handover of the communication terminal 20 sending a message requesting that.
[0024]
 As described above, the base station 12, when the handover process is executed, to perform the handover execution confirmation using UE Security Capabilities. The UE Security Capabilities, for example, includes information on a plurality of algorithms used in the different encryption and integrity protection processing. Base station 12, by executing a handover execution confirmation using UE Security Capabilities, after the communication terminal 20 performs handover to the own device, it is possible to determine whether it is possible to continue communication.
[0025]
 Than this, for example, when the base station 12 are connected to different networks slice (or network slice system), the base station 12, communication terminal 20 has moved by handover, continue to communicate via the own device it is possible to determine whether it is possible.
[0026]
 (Second Embodiment)
 Subsequently, a configuration example of a communication system according to the second embodiment will be described with reference to FIG. Communication system of FIG. 2, ARPF entity (hereinafter referred to as ARPF) 41, SEAF entity (hereinafter referred to as SEAF) 43, SCMF entity (hereinafter referred to as SCMF) 44 and 45, CP (C-Plane) -CN (Core Network) has a 46 ~ 50, NG-RAN51 ~ 58.
[0027]
 ARPF41, SEAF43, SCMF44 and 45, CP-CN46 ~ 50 constitute a core network. NG-RAN51 ~ 58 constitute a radio access network. NG-RAN, for example, a base station used in NextGen System: it may be a (gNB Next Generation NodeB).
[0028]
 Each entity 2 may comprise a plurality of functions. For example, in FIG. 2, ARPF41 is a different entity from the SEAF43, it may be one of the entities are used to perform ARPF and SEAF.
[0029]
 ARPF entity is a node apparatus for executing ARPF. ARPF, for example, UE (User Equipment) which corresponds to the communication terminal 20 is a function of executing an authentication process as to whether it is possible to connect to the NextGen System. ARPF41 generates a security key used for the authentication process, holds the generated security key.
[0030]
 SEAF entity is a node apparatus for executing SEAF, SCMF entity is a node device for performing the SCMF. SEAF and SCMF is a function that performs an authentication process regarding whether the UE can connect to the network slicing cores network.
[0031]
 CP-CN 46 ~ 48 includes a MM entity performing Mobility Management (MM), and SM entity performing Session Management (SM).
[0032]
 Specifically, MM is, registers the user to manage the UE or UE to a mobile network (registration) to be, mobile terminated Communication enables to reachability (reachability) to support, unreachable UE Detection , C (Control) -plane and U (User) assigning a network function relating -plane, and to limit the mobility, or the like.
[0033]
 Also, SM is possible to set the IP connectivity or non-IP connectivity for UE. In other words, SM may be to manage or control the connectivity of the U-Plane.
[0034]
 2, the dotted line between dotted lines and CP-CN between NG-RAN shows that can communicate directly between between NG-RAN and CP-CN. In other words, between the inter and CP-CN NG-RAN, interface or reference point is set.
[0035]
 Subsequently, with reference to FIG. 3, described handover processing in the NG-RAN53 (INTRA NG RAN HANDOVER). NG-RAN53, the one cell, and is divided into a plurality of sectors. INTRA NG RAN HANDOVER may be, for example, a handover due to movement between the UE sectors. Further, in FIG. 3, instead of the CP-CN, with the MM and SM, described handover process. Also, UP-GW is a gateway that is used to transmit user plane data. The same applies to the subsequent figures.
[0036]
 First, AKA (Authentication and Key Agreement) is performed between the UE and ARPF41. By AKA is performed between the UE and ARPF41, it can be the UE and ARPF41 is, share a security key K.
[0037]
 Then, ARPF41 the security key K was derived from the security key K SEAF to send to SEAF43 (S12). Then, SEAF43 the security key K SEAF security key K was derived from SCMF to send to SCMF44 (S13).
[0038]
 Next, NAS (Non-Access Stratum) Security process between the UE and SCMF44 is executed. NAS Security process, for example, between the UE and SCMF44, may be able Ru establish a secure communication path can be encrypted, such as the C-Plane data.
[0039]
 Then, between the UE and the UP-GW, UP SMC (Security Mode Command) processing is executed. UP SMC process, for example, between the UE and the UP-GW, may be to establish a secure communication path can be encrypted, such as the U-Plane data.
[0040]
 Then, SCMF44 the security key K SCMF security key K was derived from the AN to send to the NG-RAN53 (S16). Then, between the UE and the NG-RAN53, AS Security processing is executed (S17). AS Security process, for example, between the UE and NG-RAN53, it may be to establish a secure communication path can perform encryption of data.
[0041]
 Then, NG-RAN53 performs the Handover Decision (make the handover decision) (S18). Then, NG-RAN53, the security key K holds AN to refresh (S19). In other words, NG-RAN53, the security key K AN security key K from the AN to derive the *. For example, NG-RAN53, the security key K AN update the security key K AN deriving a *. NG-RAN53 further security key K AN derives the security key used from * the integrity protection and encryption related RRC messages and user plane data.
[0042]
 Next, NG-RAN53 sends a Handover Command message to the UE (S20). Handover Command message, for example, security keys K AN include parameters used in deriving *,
[0043]
 Then, UE, using the parameters and the like included in the Handover Command message, the security key K AN deriving a * (S21). UE further security key K AN derives the security key used from * the integrity protection and encryption related RRC messages and user plane data.
[0044]
 Then, between the UE and the NG-RAN53, AS Security processing is executed (S22). When AS Security process is completed in step S22, UE sends a Handover Complete message to NG-RAN53 (S23).
[0045]
 Next, the handover processing between the NG-RAN54 and NG-RAN55 for (INTER NG RAN HANDOVER) will be described with reference to FIGS. Handover process of FIG. 4 and FIG. 5 shows a handover process in the same CP-CN (INTRA CP-CN HANDOVER). Further, FIGS. 4 and 5, the NG-RAN54, the NG-RAN55 is assumes that communicate directly via an interface corresponding to the X2 interface is defined between the 3GPP eNB.
[0046]
 Further, FIGS. 4 and 5, UE have shown a handover processing performed when moving from NG-RAN54 to NG-RAN55. Are assigned to the NG-RAN54 (S) indicates the Source, indicating that a handover source NG-RAN of the UE. Are assigned to the NG-RAN55 (T) indicates the Target, indicating that a handover destination of NG-RAN of the UE.
[0047]
 Step S31-S37 in FIG. 4, a detailed description thereof is omitted because it is similar to that of Step S11-S17 in FIG. Then, UE is the NG-RAN54, sends a Measurement Report message including the UE Security Capabilities (S38). The Measurement Report message, for example, may include information about the result of measuring the radio field intensity of the message or the like transmitted from the NG-RAN55.
[0048]
 Then, NG-RAN54 evaluates the Measurement Report (evaluate), perform the Handover Decision (S39). Then, NG-RAN53, the security key K holds AN to refresh (S40). In other words, NG-RAN54, the security key K AN security key K from the AN to derive the *. For example, NG-RAN54, the security key K AN update the security key K AN deriving a *. NG-RAN54 further security key K AN derives the security key used from * the integrity protection and encryption related RRC messages and user plane data.
[0049]
 Next, NG-RAN54 is a Handover Request message to the NG-RAN55 via an interface corresponding to the X2 interface (S41). Handover Request message, UE Security Capabilities on the UE, and security key K AN including the *.
[0050]
 Next, NG-RAN55 checks (check) the UE Security Capabilities (USC) and UE subscriber information (Subscription) (S42). In other words, NG-RAN55 performs the confirmation handover execution using a UE Security Capabilities and Subscription. That, NG-RAN55 determines whether the UE can access the network slices through the NG-RAN55.
[0051]
 Turning now to FIG. 5, NG-RAN55 is, UE If the entitled to access the network slices through the NG-RAN55 (the UE qualifies for accessing the slice via the new NG RAN), the NG-RAN54 sending a Handover Request Ack message (S43).
[0052]
 Next, NG-RAN54 is to UE, and sends a Handover Command message (S44). Handover Command message, for example, security keys K AN *, used for integrity protection and encryption parameters used in deriving the security key may include an algorithm information.
[0053]
 Then, UE, using the parameters and the like included in the Handover Command message, the security key K AN deriving a * (S45). Further the UE security key K AN derives the security key used from * the integrity protection and encryption related RRC messages and user plane data.
[0054]
 Then, UE is the NG-RAN55, sends a Handover Complete message (S46). Next, NG-RAN55 sends a Path Switch Request message to the MM (S47).
[0055]
 Next, MM is, sends a Modify Bearer Request message to the UP-GW (S48). Then, UP-GW is to MM, sends a Modify Bearer Response message (S49). By the process of step S48 and S49 are executed, the bearer is updated about U-Plane data. Next, MM is, the NG-RAN55, transmits a Path swithc Response message (S50).
[0056]
 Then, between the UE and the NG-RAN55, AS Security processing is executed (S51).
[0057]
 As described above, in the second embodiment, between the NG-RAN55 the UE and the handover destination, in a state where secure communication path has been established, the handover process is executed.
[0058]
 (Embodiment 3)
 Next, the handover processing between the NG-RAN54 and NG-RAN55 for (INTER NG RAN HANDOVER) will be described with reference to FIGS. Handover process of FIG. 6 and FIG. 7 shows a handover process in the same CP-CN (INTRA CP-CN HANDOVER). Further, FIGS. 6 and 7, the NG-RAN54, the NG-RAN55 is assumed to communicate via a CP-CN48. 6 and 7 will be described with reference to MM and SM as CP-CN48.
[0059]
 Step S61 ~ S69 of FIG. 6, a detailed description thereof will be omitted because it is similar to that of steps S31 ~ S39 of FIG.
[0060]
 Next, NG-RAN54 transmits the Hanover Required message to the MM (S70). Handover Required message includes a UE Security Capabilities. Furthermore, MM is, sends a Handover Request message to the NG-RAN55 (S71). Handover Request message includes a UE Security Capabilities.
[0061]
 Then, NG-RAN55 checks (check) the UE Security Capabilities (USC) and the UE subscriber information of (Subscription) (S72). Next, NG-RAN55 is, UE If the entitled to access the network slices through the NG-RAN55, security key K holds AN to refresh (S73). In other words, NG-RAN55, the security key K AN security key K from the AN to derive the *. For example, NG-RAN55, the security key K AN update the security key K AN deriving a *. NG-RAN55 further security key K AN derives the security key used from * the integrity protection and encryption related RRC messages and user plane data.
[0062]
 NG-RAN55 is, for example, pre-security key K for the AN may not receive the. For example, SCMF44, at step S66, the security key K also to NG-RAN55 with NG-RAN54 AN may send a. Or, the message transmitted in step S70 and S71, the security key K AN may contain.
[0063]
 Next, NG-RAN55 via the MM to NG-RAN54, sends the Handover Request ACK message (S74, S75). Step S76 ~ S78 is a detailed description thereof will be omitted because it is similar to that of steps S44 ~ S46 of FIG. 5.
[0064]
 Next, MM is, sends a UE Security Capability Check Request message to SCMF44 (S79). Then, SCMF44 is, to the UP-GW, to send the Modify Bearer Request message (S80). Then, UP-GW is to SCMF44, sends a Modify Bearer Response message (S81). Then, SCMF44 is to MM, sends a UE Security Capability Check Response message (S82). Step S83 is a detailed description thereof will be omitted because it is similar to step S51 of FIG. 5.
[0065]
 As described above, similarly as in the second embodiment in the third embodiment, between the NG-RAN55 the UE and the handover destination, in a state where secure communication path has been established, the handover process is performed .
[0066]
 (Embodiment 4)
 Subsequently, the handover processing between the NG-RAN53 and NG-RAN54 (INTER NG RAN, INTER CP-CN, INTRA SCMF HANDOVER) will be described with reference to FIGS. Handover process of FIG. 8 and FIG. 9 shows a handover process involving a change from CP-CN47 to CP-CN48. Further, FIGS. 8 and 9, the CP-CN47 and MM (S) and SM (S), describes a CP-CN48 as MM (T) and SM (T).
[0067]
 Step S91 ~ S100 is omitted the detailed description is the same as the steps S61 ~ S70 of FIG. 6. Then, MM (S), the security key K CP = CN to derive a * (S101). For example, MM (S) in advance in the security key K for the CP-CN or security key K SCMF and has been received. For example, MM (S) may be applied to any timing, from SCMF44, security keys K derived in SCMF44 CP-CN may receive.
[0068]
 Next, MM (S) transmits a Forward Relocation Request message to the MM (T) (S102). Forward Relocation Request message, UE Security Capabilities and security key K CP = CN , including the *. Next, MM (T) sends a Handover Request message to the NG-RAN54 (S103). Handover Request message includes a UE Security Capabilities. Step S104 and S105 are omitted detailed description is the same as the steps S72 and S73 in FIG. 6.
[0069]
 Next, NG-RAN54 is to MM (T), transmits the Handover Request ACK message. Handover Request ACK message, UE Security Capabilities and security key K AN including the *.
[0070]
 Next, MM (T) is to SM (T), transmits a Session Refresh Request message (S107). Next, SM (T) derives new session keys (S108). session keys may be, for example, a security key used for integrity protection and ciphering about U-Plane data.
[0071]
 Next, SM (T) is the MM (T), transmits a Session Refresh Response message (S109). Next, MM (T) is the MM (S), sends the Forward Relocation Response message (S110). Steps S111 and S112, the detailed description thereof is omitted because it is similar to that of steps S75 and S76 in FIG. 7.
[0072]
 Then, UE, the security key K CP-CN *, security key K AN *, NAS keys, security key used for integrity protection and encryption related RRC messages and user plane data, derives the session keys (S113).
[0073]
 Then, UE, in between the SCMF44, executes the NAS Security processing (S114). Furthermore, UE, in between the UP-GW, executes the UP SMC process (S115). Then, UE is the NG-RAN54, sends a Handover Complete message (S116). Then, UE, in between the NG-RAN54, executes the AS Security processing (S117).
[0074]
 Subsequently, with reference to FIGS. 10 to 12 differs from that of FIG. 8 and FIG. 9, the handover processing between the NG-RAN53 and NG-RAN54 (INTER NG RAN, INTER CP-CN, INTRA SCMF HANDOVER) description to.
[0075]
 10 to 12, it describes the processing of the case of not using the interface between the CP-CN47 and CP-CN48.
[0076]
 Step S121 ~ S130 is omitted steps S91 ~ S100 and hence detailed similar description of FIG. Next, MM (S) transmits a Forward Relocation Request message to the SCMF44 (S131). Forward Relocation Request message includes a UE Security Capabilities. Then, SCMF44 via the MM (T) to the NG-RAN54 sends a Handover Request message (S132, S133). Handover Request message includes a UE Security Capabilities. Step S134 ~ S136 is omitted the detailed description is the same as the steps S104 ~ S106 in FIG.
[0077]
 Then, MM (T), the security key K CP-CN to derive a * (S137). Step S138 ~ S140 is omitted steps S107 ~ S109 and hence detailed similar description of FIG. Next, MM (T) is to SCMF44, sends the Handover Request ACK message (S141). Then, SCMF44 is to MM (S), sends the Forward Relocation Response message (S142).
[0078]
 Step S143 ~ S150 is omitted the detailed description is the same as steps S 111 ~ S117 in FIG. In FIG. 12, UE is after the UP SMC process, security K AN deriving a.
[0079]
 As described above, as well as Embodiments 2 and 3 in the fourth embodiment, between the NG-RAN54 the UE and the handover destination, in a state where secure communication path has been established, the handover processing is performed It is.
[0080]
 (Embodiment 5)
 Subsequently, the handover processing between the NG-RAN55 and NG-RAN56 (INTER NG RAN, INTER CP-CN, INTER SCMF HANDOVER) will be described with reference to FIGS. 13 and 14. Handover process of FIG. 13 and FIG. 14 shows a handover process involving a change from SCMF44 to SCMF45. Further, FIGS. 13 and 14, the CP-CN48 and MM (S) and SM (S), describes a CP-CN49 as MM (T) and SM (T).
[0081]
 First, between the UE and ARPF41, Initial Attach Procedure is executed (S161). Initial Attach Procedure, for example, corresponding to steps S31 ~ S37 of FIG. Further, steps S162 ~ S165 is omitted detailed to those at steps S128 ~ S131 in FIG. 10.
[0082]
 Then, SCMF44 the security key K SCMF to derive the * (S166). In addition, SCMF44, the security key K SCMF using a *, security key K CP-CN to derive a * (S167). Then, SCMF44 via SCMF45 and MM (T), and transmits a Handover Request message to the NG-RAN56 (S168, S169) . Handover Request message includes a UE Security Capabilities.
[0083]
 Step S170 ~ S172, the detailed description thereof is omitted because it is similar to that of steps S134 ~ S136 in FIG. 10 and FIG. 11. Further, steps S173 ~ S175 is omitted detailed to those at steps S138 ~ S140 in FIG. 11.
[0084]
 Next, MM (T) sends a Handover Request ACK message to the SCMF44 via SCMF45 (S176, S177). Step S178 ~ S182, the detailed description thereof is omitted because it is similar to the processing of steps S142 ~ S150 in FIG. 11 and FIG. 12.
[0085]
 As described above, as well as Embodiments 2 to 4 in the fifth embodiment, between the NG-RAN56 the UE and the handover destination, in a state where secure communication path has been established, the handover processing is performed It is.
[0086]
 (Embodiment 6)
 Subsequently, a configuration example of a communication system according to the sixth embodiment will be described with reference to FIG. 15. Communication system of FIG. 15, UE (User Equipment) 101, NG (R) AN ((Radio) Access Network) 102, UPF (User Plane Function) entity 103 (hereinafter referred to as UPF103), AMF (Access and Mobility Management Function) entity 104 (hereinafter referred to as AMF104), SMF (Session Management Function ) entity 105 (hereinafter referred to as SMF105), PCF (Policy Control Function ) entity 106 (hereinafter referred to as PFC106), AUSF (Authentication Server Function ) entity 107 (hereinafter referred to as AUSF107), UDM (Unified Data Management ) 108, DN (Data Network) 109, and AF (Application Function) entity 110 has a (hereinafter, the AF110 be).
[0087]
 UPF103, AMF104, SMF105, PCF106, AUSF107, and UDM108 constitute 5GC (5G Core). 5GC is a core network in NextGen System.
[0088]
 NG (R) AN 102 corresponds to NG-RAN51 ~ NG-RAN58 in FIG. AMF104 and SMF105 correspond to CP-CN46 ~ CP-CN50 of Figure 2. Further, as shown in FIG. 15, the communication system of FIG. 15, between the devices or between the function, NG1 ~ NG15 interface is set.
[0089]
 AUSF107, for example, UE 101 is a function of executing an authentication process as to whether it is possible to connect to 5GC. AUSF107 generates a security key used for the authentication process, holds the generated security key. UDM108 manages subscriber data (UE Subscription or Subscription information). Further, for example, UDM108 may be a node apparatus for performing ARPF. UPF103 is a node device for transmitting U-Plane data.
[0090]
 Subsequently, with reference to FIG. 16, the handover process in the NG (R) in AN102 (INTRA NG RAN HANDOVER) will be described. 16, in the communication system shown in FIG. 15 shows a handover process in NG (R) AN102. Further, FIG. 16 illustrates a handover process executed between the UE101 and the NG (R) AN102. Therefore, in step S201, UE 101 steps S202 ~ S206 is performed after transmitting the Measurement Report message to NG (R) AN 102 may omit a detailed explanation is the same as the steps S18 ~ 21 and step S23 in FIG. 3 to.
[0091]
 Subsequently, the NG handover process between the (R) AN102_1 and NG (R) AN102_2 (Inter NG RAN handover with Xn interface) will be described with reference to FIG. 17. NG (R) AN102_1 is NG (R) AN before UE101 moves (Source NG (R) AN) (may be referred to as Source gNB.), NG (R) AN102_2 is moved UE101 a after the NG (R) aN (Target (R) aN) (may be referred to as Target gNB.). Xn in interface is an interface that is set between the NG (R) AN102_1 and NG (R) AN102_2.
[0092]
 First, if the handover is required, UE is the NG (R) AN102_1, NSSAI (Network Slice Selection Assistance Information), UE Security Capabilities, and transmits the Measurement Report message including the UE Mobility Restirctions (S211) (If handover is required, the UE sends the Measurement Report to the NG (R) AN.). NSSAI is, for example, information for identifying the core network providing the services UE101 uses. Here, 5GC the network slicing is applied, is divided for each service provided. Divided network may be referred to as a network slice.
[0093]
 Then, NG (R) AN102_1 evaluates the Measurement Report (evaluate), Handover perform the Decision (make the handover dicision) ( S212). Next, NG (R) AN102_1 the security key K holds AN to refresh (S213). In other words, NG (R) AN102_1, the security key K AN security key K from the AN to derive the *. For example, NG (R) AN102_1, the security key K AN update the security key K AN deriving a *.
[0094]
 Next, NG (R) AN102_1 is a Handover Request message, transmits through Xn in interface to NG (R) AN102_2 (S214) . Handover Request message, UE Security Capabilities on the UE, Handover Restriction List, NSSAI and security key K AN including the *.
[0095]
 Next, NG (R) AN102_2 determines whether the check (check) NSSAI is supported (S215). In other words, NG (R) AN102_2 performs the confirmation handover execution using a UE Security Capabilities and NSSAI. That, NG (R) AN102_1 determines whether the UE can access the network slices through the NG (R) AN102_2. In other words, Source GNb is, Target GNb is by checking whether the support services required by the UE, and uses the information including NSSAI received from the UE for Handover Decision.
[0096]
 Step S216 ~ S221 is omitted the detailed description is the same as the steps S43 ~ S47 and S50 in FIG.
[0097]
 Next, the handover processing between the NG (R) AN102_1 and NG (R) AN102_2 (Intra vAMF, Intra vSMF, Inter NG (R) AN handover without Xn interface) will be described with reference to FIG. 18.
[0098]
 Step S231 and S232 are omitted detailed to those at steps S211 and S212 in FIG. 17.
[0099]
 Next, NG (R) AN102_1 sends Hanover Required message to AMF104 (S233). Handover Required message contains UE Security Capabilities, Handover Restriction List, NSSAI, and {NH, NCC} a. Furthermore, AMF104 sends a Handover Request message NG (R) to AN102_2 (S234). Handover Request message contains UE Security Capabilities, Handover Restriction List, NSSAI, and {NH, NCC} a.
[0100]
 Next, NG (R) AN102_2 determines whether the check (check) NSSAI is supported (S235). Next, NG (R) AN102_2 is, UE If the entitled to access the network slices through the NG (R) AN102_2, security key K holds AN to refresh (S236). In other words, NG (R) AN102_2, the security key K AN security key K from the AN to derive the *. Furthermore, NG (R) AN102_2 the security key K AN derives the security key used from * the integrity protection and encryption related RRC messages and user plane data.
[0101]
 Next, NG (R) AN102_2 is to AMF104, sends the Handover Request Ack message (S237). Then, AMF104 sends NG to (R) AN102_1 to Handover Command message (S238). Step S239 ~ S241 is omitted steps S217 ~ S219 and hence detailed similar description of Figure 17.
[0102]
 Subsequently, NG handover process between the (R) AN102_1 and NG (R) AN102_2 (Intra vAMF, Inter vSMF, Inter NG (R) AN handover without Xn interface) will be described with reference to FIGS. 19 and 20. SMF105_1 and UPF103_1 are SMF for executing processing relating to UE101 before movement (Source SMF) and UPF (Source UPF), SMF105_2 and UPF103_2 is SMF to perform processing related to UE101 after movement (Target SMF) and UPF ( a Target UPF).
[0103]
 Step S251 ~ S253, the detailed description thereof is omitted because it is similar to that of steps S231 ~ S233 in FIG. 18.
[0104]
 Then, AMF104 selects the SMF based on the NSSAI (The AMF selects the SMF based on NSSAI) (S254). That, AMF104 selects the SMF that is located on a network slices associated with NSSAI received in step S253. Here, AMF104 is, and selects the SMF105_2.
[0105]
 Then, AMF104 is to SMF105_2, it sends a the Create Session Request message (S255). Crease Session Request message includes a UE Security Capabilities and NSSAI.
[0106]
 Then, SMF105_2 is, for NAS signaling protection between the UE101 and SMF105_2, security key K NAS-SM to derive the * (The SMF Derives K NAS-SM * For NAS signaling protection Between The UE And SMF) ( S256).
[0107]
 Then, SMF105_2 selects the UPF for the Slice associated with the NSSAI (The SMF selects the UPF for the slice) (S257). Then, SMF105_2 the security key K for the Slice associated with the NSSAI UP to derive and session key (S258). The session key may be, for example, a Ksessenc used in Ksessint and encryption used in integrity protection. Then, SMF105_2 is to AMF104, sends the Crease Session response message (S259).
[0108]
 Step S260 ~ S263, the detailed description thereof is omitted because it is similar to that of steps S234 ~ S237 in FIG. 18.
[0109]
 Then, AMF104 is to SMF105_1, transmits the Create Data forwarding tunnel request message (S264). Then, SMF105_1 is, against SMF105_2, to create a tunnel for the data transfer (The SMF creates the tunnel for data transfer to the target SMF.) (S265). Then, SMF105_1 is to AMF104, transmits the Create Data forwarding tunnel response message (S266).
[0110]
 Then, AMF104 is, NG (R) to AN102_1, sends the Handover Command message (S 267). Next, NG (R) AN102_1 is to UE 101, sends a Handover Command message (S268).
[0111]
 Then, UE101, using the parameters and the like that is included in the Handover Command message, the security key K NAS-SM to derive the * (Using The Parameter Sent In The Handover Command, The UE Derives The K NAS-SM *) (S269 ). Then, the security key K NAS-SM security key K from * UP to derive and session key (session key) (S270). Next, UE 101, the security key K AN derives *, further derives the security key used for integrity protection and encryption related RRC messages and user plane data (S271).
[0112]
 Next, UE 101 is to NG (R) AN102_2, sends a Handover Complete message NG (R) to AN102_2 (S272).
[0113]
 As described above, while the handover process is being performed, the UE101 and SMF105_2, new security key K NAS-SM can be derived *. In other words, UE101 and SMF105_2, the security key K NAS-SM can be refreshed *. Thus, during the UE101 and SMF105_2, it is possible to establish a NAS-SM security.
[0114]
 Furthermore, NG (R) AN102_2, using NSSAI transmitted from UE 101, by checking whether or not the own device support service UE 101 requests, determines whether to handover the UE 101 be able to.
[0115]
 Then, the handover processing between the NG (R) AN102_1 and NG (R) AN102_2 (Inter vAMF, Intra SMF, Inter NG (R) AN node without Xn interface) will be described with reference to FIG. 21. AMF104_1 is AMF (Source AMF) to execute the process related to UE101 before movement, AMF104_2 is AMF (Target AMF) to execute the process related to UE101 after movement.
[0116]
 Step S281 ~ S283, the detailed description thereof is omitted because it is similar to that of steps S231 ~ S233 in FIG. 18.
[0117]
 Then, AMF104_1 is to AMF104_2, sends the Forward Relocation Request message (S284). Forward Relocation Request message includes a UE Security Capabilities, Handover Restriction List and NSSAI.
[0118]
 Step S285 ~ S288, the detailed description thereof is omitted because it is similar to that of steps S234 ~ S237 in FIG. 18.
[0119]
 Then, AMF104_2 the security key K NAS-MM to derive the * (S289). Then, AMF104_2 is to AMF104_1, sends the Forward Relocation response message (S290).
[0120]
 Step S291 ~ S294, the detailed description thereof is omitted because it is similar to that of steps S238 ~ S241 in FIG. 18. However, UE101 is, in step S293, the security key K AN security key K with * NAS-MM to derive the *.
[0121]
 As described above, while the handover process is being performed, the UE101 and AMF104_2, new security key K NAS-MM can be derived *. In other words, UE 101 and AMF104_2 the security key K NAS-MM can be refreshed *. Thus, during the UE101 and AMF104_2, it is possible to establish a NAS-MM security.
[0122]
 Subsequently, NG handover process between the (R) AN102_1 and NG (R) AN102_2 (Inter vAMF, Inter vSMF, Inter NG (R) AN node without Xn interface) will be described with reference to FIGS. 22 and 23.
[0123]
 Step S301 ~ S304, the detailed description thereof is omitted because it is similar to that of steps S281 ~ S284 in FIG. 21. Further, steps S305 ~ S310 is omitted detailed to those at steps S254 ~ S259 in FIG. 19.
[0124]
 Then, AMF104_2 the security key K NAS-MM to derive the * (S311).
[0125]
 Step S312 ~ S315, the detailed description thereof is omitted because it is similar to that of steps S285 ~ S288 in FIG. 21.
[0126]
 Then, AMF104_2 is to AMF104_1, sends the Forward Relocation response message (S316).
[0127]
 Step S317 ~ S325, the detailed description thereof is omitted because it is similar to that of steps S264 ~ S272 in FIG. 20.
[0128]
 As described above, while the handover process is being performed, the UE101 and SMF105_2, new security key K NAS-SM can be derived *. In other words, UE101 and SMF105_2, the security key K NAS-SM can be refreshed *. Thus, during the UE101 and SMF105_2, it is possible to establish a NAS-SM security. In addition, UE101 and AMF104_2, the new security key K NAS-MM can be derived *. In other words, UE 101 and AMF104_2 the security key K NAS-MM can be refreshed *. Thus, during the UE101 and AMF104_2, it is possible to establish a NAS-MM security.
[0129]
 Furthermore, NG (R) AN102_2, using NSSAI transmitted from UE 101, by checking whether or not the own device support service UE 101 requests, determines whether to handover the UE 101 be able to. In other words, NG (R) AN102_2 (Target gNB) is indicated by NSSAI received, the network slice or service UE101 requests, it is possible to check whether the information device supports.
[0130]
 (Embodiment 7)
 Subsequently, the communication system for realizing roaming UE201 be described with reference to FIG. 24. Communication system of FIG. 24, UE 201, and a (R) AN202, UPF203, AMF204 , V-SMF205, vPCF206, UPF213, H-SMF215, H-PCF216, AUSF217, UDM218, and AF219.
[0131]
 (R) AN202, UPF203, AMF204, V-SMF205, and vPCF206 are node devices are arranged in VPLMN (Visited Public Land Mobile Network). UPF213, H-SMF215, H-PCF216, AUSF217, UDM218, and AF219 are node devices are arranged in HPLMN (Home PLMN).
[0132]
 Figure 24, UE 201 may indicate a state of roaming VPLMN. It will now be described registration when the UE201 has roamed (Registration) procedures and security establishment (security establishment).
[0133]
 First, UE 201 is disposed in VPLMN to (R) AN202, and transmits the RRC Connection request message. UE201, if it has information on RAT restrictions, in the attach request message to include the RAT restrictions, further multiplexes the attach request message to the RRC Connection request message.
[0134]
 Then, (R) AN202 is to AMF204 disposed in VPLMN, to forward the attach request message (forward). AMF204 checks the RAT restrictions of the UE201. Here, AMF204, in order to check the RAT restrictions of UE 201, to UDM218, may request to send information about RAT restrictions of UE 201. In other words, AMF204 from UDM218, may download the UE201 subscriber information of (Subscription information).
[0135]
 In AMF204, if it is determined that the RAT used between the UE 201 is (R) AN202 is limited, (R) AN202 is the UE 201, you must establish other (R) AN and RRC Connection to notify. Further, AMF204, when judging that RAT is not limited to use between the UE 201 is (R) AN202, the area to be visited in the UE 201, checks whether the prohibition zone (forbidden zone).
[0136]
 AMF204, when UE201 determines that the area to be visited is a restricted zone, which sends a message indicating that the (R) to the AN202, reject connections (rejecting the connection). AMF204, if UE 201 determines that the area to be visited not restricted zone, in order to perform authentication related to UE 201, queries the (contact) performed to AUSF217 disposed in HPLMN.
[0137]
 In the authentication process relating to UE 201, if there are security context relates UE 201, UE 201 is to AMF204, transmits a eKSI (evolved Key Set Identifier) ​​seaf. AMF204 checks the validity of the security context. If the security context is not present about the UE201, AKA (Authentication Key Agreement) it is executed. By validation process for UE201 is executed, NAS-MM Security between AMF204 disposed in UE201 and VPLMN is established. Furthermore, the security between the UE201 and (R) AN202 is established. AMF204 is, to H-PCF216 through the vPCF206, make an inquiry about the security algorithms.
[0138]
 UE201, when located in the area where the communication is not permitted (Non-allowd area), it is impossible to start the service requests The. Further, UE 201, when located in the area (allowd Area) that communication is permitted, it is possible to start the service requests The.
[0139]
 The following describes the security establishment in service request processing (security establishment). First, UE 201 is to AMF204, transmits a service request (or service the attach request) message including the S-NSSAI. Then, AMF204 selects the SMF on the basis of the subscriber information of the S-NSSAI and UE 201. Here, AMF204 shall be selected the V-SMF205. Thus, it is in between the UE201 and the V-SMF205, NAS-SM Security is established.
[0140]
 Between the V-SMF205 and H-SMF215, there security is established tunnel (secure tunnel) is. V-SMF205 is, to H-PCF216 through the vPCF206, make an inquiry about the security algorithms.
[0141]
 Next, V-SMF205 selects the appropriate UPF for network slice UE201 wishes to connect. Here, V-SMF205 it is assumed that the select UPF203.
[0142]
 In addition, V-SMF205 is, for UPF203, security key K UP to derive. Further, V-SMF205 is to H-PCF216 via VPCF206, to request security algorithms. In addition, V-SMF205 is, to derive the session key. In addition, V-SMF205 starts the UP (User Plane) SMC (Security Mode Command) processing.
[0143]
 In the communication system of FIG. 24, UE 201 may be served via a PDN (Packed Data Network) in HPLMN.
[0144]
 Subsequently, with reference to FIG. 25 differs from FIG. 24, a description will be given of a communication system for realizing a roaming UE 201. Communication system of FIG. 25, UE 301, and a (R) AN302, UPF303, AMF304, SMF305, vPCF306, AF309, H-PCF316, AUSF317, and UDM318. (R) AN302, UPF303, AMF304, SMF305, vPCF306, and AF309 are nodes device disposed VPLMN. H-PCF316, AUSF317, and UDM318 are nodes device disposed HPLMN.
[0145]
 Figure 25, UE 201 may indicate a state of roaming VPLMN. In the communication system of FIG. 25, UE 301 may be served via a PDN (Packed Data Network) in VPLMN.
[0146]
 The above embodiment has been described as an example composed of hardware, but is not limited thereto. The present disclosure, the processing in the UE and each device can also be implemented by executing a computer program to CPU (Central Processing Unit).
[0147]
 In the above example, the program may be stored using a non-transitory computer readable media of various types (non-transitory computer readable medium), it can be supplied to the computer. Non-transitory computer readable media include with various types of entities (tangible storage medium). Examples of non-transitory computer readable media include magnetic storage media (such as floppy disks, magnetic tape, hard disk drive), magneto-optical recording medium (e.g. optical disk), CD-ROM (Read Only Memory), CD-R, CD-R / W, a semiconductor memory (e.g., a mask ROM, PROM (Programmable ROM), EPROM (Erasable PROM), flash ROM, RAM (Random Access memory)) includes a. The program may be provided to a computer using a temporary computer readable media of various types (transitory computer readable medium). Examples of transitory computer readable media include electric signals, optical signals, and electromagnetic waves. Transitory computer readable media, wired communication path such as electrical wires and optical fibers, or via a wireless communication path can provide the program to a computer.
[0148]
 The present invention is not limited to the above embodiments, but can be appropriately changed without departing from the spirit. The present disclosure may be implemented in combination in the form of respective embodiments as appropriate.
[0149]
 Although the present invention has been described with reference to the embodiments, the present invention is not limited by the foregoing. Configuration and details of the present invention, it is possible to make various modifications that those skilled in the art can understand within the scope of the invention.
[0150]
 This application claims priority based on Indian Application 201711009359, filed on Indian application 201611036777 and March 17, 2017, filed October 26, 2016, the entire disclosure of which is incorporated herein.
DESCRIPTION OF SYMBOLS
[0151]
 10 base stations
 12 base stations
 20 communicates with the terminal ends
 41 is ARPF
 43 is SEAF
 44 is SCMF
 45 SCMF
 46 is the
 CP-the CN
 47 the CP-the
 CN
 48 the
 CP-the CN 49 the
 CP-the CN 50 the CP-the CN 51 is the
 NG-the RAN 52 is the NG-the RAN 53 is the
 NG-the RAN 54 is
 the RAN-the NG
 55
 the RAN the NG-
 56 is the
 NG-the RAN
 57 is the
 NG-the RAN
 58 the
 NG-the RAN 101 the UE 102
 the NG (R & lt) the AN 103
 the UPF 104 the AMF 105 the SMF
 106 the PCF 107 Ausf
 108 the UDM 109 the DN
 110 AF
 201 UE
 202 (R)AN
 203 UPF
 204 AMF
 205 V-SMF
 206 vPCF
 213 UPF
 215 H-SMF
 216 H-PCF
 217 AUSF
 218 UDM
 219 AF
 301 UE
 302 (R)AN
 303 UPF
 304 AMF
 305 SMF
 306 vPCF
 309 AF
 316 H-PCF
 317 AUSF
 318 UDM

WE claims

A first base station that forms a communication area where the communication terminal is present,
 and a second base station forming a communication area of the handover destination of the communication terminal,
 the first base station,
 from said communication terminal receiving a first message relating to the handover including UE Security Capabilities,
 the second base station
 receives the second message including the UE Security Capabilities, handover of the communication terminal based on the UE Security Capabilities run the execution confirmation, it transmits a third message corresponding to the second message based on the handover execution confirmation result, communication system.
[Requested item 2]
 The first base station,
 wherein in response to the first message derives the security key to be applied to data transmitted between said communication terminal,
 said second base station,
 said UE Security Capabilities receiving the second message including said security key, the communication system according to claim 1.
[Requested item 3]
 The second base station,
 based on said UE Security Capabilities the handover execution confirmation of the execution result based on and derives the security key to be applied to data transmitted between said communication terminal, claim the communication system according to 1.
[Requested item 4]
 The first base station receives the first message including the NSSAI (Network Slice Selection Assistance Information) from the communication terminal,
 the second base station receives the second message including the NSSAI the NSSAI performing handover execution confirmation of the communication terminal based on the communication system according to claim 1.
[Requested item 5]
 Further comprising a core network apparatus constituting the core network,
 the core network device
 receives a fourth message from the first base station including the UE Security Capabilities, the second message including the UE Security Capabilities and it transmits the to the second base station, a communication system according to any one of claims 1 to 4.
[Requested item 6]
 A base station forming a communication area where the communication terminal is present,
 receives a first message relating to a handover from the communication terminal includes a UE Security Capabilities, other base station forming a communication area of the handover destination of the communication terminal a is, the UE to Security Capabilities to the other base station to perform the handover execution confirmation of the communication terminal based, a communication unit for transmitting a second message including the UE Security Capabilities, the base station.
[Requested item 7]
 It said second message including a NSSAI (Network Slice Selection Assistance Information), a base station according to claim 6.
[Requested item 8]
 A base station forming a communication area of the handover destination communication terminals existing communication area other base stations form,
 the other receiving the first message relating to the handover from the communication terminal includes a UE Security Capabilities of transmitted from the base station, a second communication unit that receives a message including the UE Security Capabilities,
 and a control unit for executing a handover execution confirmation of the communication terminal based on the UE Security Capabilities,
 the communication parts are
 transmits a third message corresponding to the second message based on the handover execution confirmation result, the base station.
[Requested item 9]
 The second message includes a NSSAI (Network Slice Selection Assistance Information) ,
 wherein the control unit performs the handover execution confirmation of the communication terminal based on the NSSAI, base station according to claim 8.
[Requested item 10]
 A control method in a base station forming a communication area where the communication terminal is present,
 receives a first message relating to a handover from the communication terminal includes a UE Security Capabilities,
 to form a communication area of the handover destination of the communication terminal other a base station, based on said UE Security Capabilities to the other base station to perform the handover execution confirmation of the communication terminal, transmitting a second message including the UE Security Capabilities, the control method.
[Requested item 11]
 It said second message including a NSSAI (Network Slice Selection Assistance Information), the control method according to claim 10.
[Requested item 12]
 A control method in a base station forming a communication area of the handover destination communication terminals existing communication area other base stations to form,
 receiving a first message relating to the handover from the communication terminal includes a UE Security Capabilities It transmitted from the said other base station, receiving said second message comprising UE Security Capabilities,
 on the basis of the UE Security Capabilities perform a handover execution confirmation of the communication terminal,
 the handover execution confirmation results transmitting a third message corresponding to the second message based control method.
[Requested item 13]
 Receiving the second message containing NSSAI (Network Slice Selection Assistance Information) ,
 to perform the handover execution confirmation of the communication terminal based on the NSSAI, control method according to claim 12.
[Requested item 14]
 A communication terminal for performing a handover,
 a transmission unit for transmitting a first message relating to the handover including UE Security Capabilities to the first base station,
 a second base station forming a communication area of the handover destination the after the handover execution confirmation of the communication terminal based on the UE Security Capabilities, and a receiving unit for receiving a second message from the first base station, a communication terminal.
[Requested item 15]
 Said first message includes NSSAI (Network Slice Selection Assistance Information) ,
 the receiving unit, the second base station, after the confirmation the handover execution on the basis of the NSSAI, said first base communication terminal according to claim 14 for receiving the second message from the station.
[Requested item 16]
 A method of controlling a communication terminal to perform the handover,
 transmits a first message relating to the handover including UE Security Capabilities to the first base station,
 a second base station forming a communication area of the handover destination the after the handover execution confirmation of the communication terminal based on the UE Security Capabilities, receiving a second message from the first base station, control method.
[Requested item 17]
 Send NSSAI the first message comprising (Network Slice Selection Assistance Information) to the first base station,
 the second base station, after the confirmation the handover execution on the basis of the NSSAI, the first receiving the second message from the first base station, control method according to claim 16.

Documents

Application Documents

# Name Date
1 201917020702.pdf 2019-05-24
2 201917020702-TRANSLATIOIN OF PRIOIRTY DOCUMENTS ETC. [24-05-2019(online)].pdf 2019-05-24
3 201917020702-STATEMENT OF UNDERTAKING (FORM 3) [24-05-2019(online)].pdf 2019-05-24
4 201917020702-REQUEST FOR EXAMINATION (FORM-18) [24-05-2019(online)].pdf 2019-05-24
5 201917020702-PRIORITY DOCUMENTS [24-05-2019(online)].pdf 2019-05-24
6 201917020702-POWER OF AUTHORITY [24-05-2019(online)].pdf 2019-05-24
7 201917020702-FORM 18 [24-05-2019(online)].pdf 2019-05-24
8 201917020702-FORM 1 [24-05-2019(online)].pdf 2019-05-24
9 201917020702-DRAWINGS [24-05-2019(online)].pdf 2019-05-24
10 201917020702-DECLARATION OF INVENTORSHIP (FORM 5) [24-05-2019(online)].pdf 2019-05-24
11 201917020702-COMPLETE SPECIFICATION [24-05-2019(online)].pdf 2019-05-24
12 201917020702-Power of Attorney-280519.pdf 2019-05-30
13 201917020702-OTHERS-280519.pdf 2019-05-30
14 201917020702-Correspondence-280519.pdf 2019-05-30
15 201917020702-RELEVANT DOCUMENTS [03-06-2019(online)].pdf 2019-06-03
16 201917020702-MARKED COPIES OF AMENDEMENTS [03-06-2019(online)].pdf 2019-06-03
17 201917020702-FORM 13 [03-06-2019(online)].pdf 2019-06-03
18 201917020702-AMMENDED DOCUMENTS [03-06-2019(online)].pdf 2019-06-03
19 abstract.jpg 2019-07-08
20 201917020702-Proof of Right (MANDATORY) [04-11-2019(online)].pdf 2019-11-04
21 201917020702-Proof of Right (MANDATORY) [07-11-2019(online)].pdf 2019-11-07
22 201917020702-OTHERS-061119.pdf 2019-11-11
23 201917020702-Correspondence-061119.pdf 2019-11-11
24 201917020702-OTHERS-131119.pdf 2019-11-18
25 201917020702-Correspondence-131119.pdf 2019-11-18
26 201917020702-FORM 3 [21-11-2019(online)].pdf 2019-11-21
27 201917020702-Proof of Right (MANDATORY) [11-01-2020(online)].pdf 2020-01-11
28 201917020702-PETITION UNDER RULE 137 [16-01-2020(online)].pdf 2020-01-16
29 201917020702-OTHERS-140120.pdf 2020-01-20
30 201917020702-Correspondence-140120.pdf 2020-01-20
31 201917020702-Information under section 8(2) [06-07-2021(online)].pdf 2021-07-06
32 201917020702-FORM-26 [06-07-2021(online)].pdf 2021-07-06
33 201917020702-FORM 3 [06-07-2021(online)].pdf 2021-07-06
34 201917020702-PETITION UNDER RULE 137 [07-07-2021(online)].pdf 2021-07-07
35 201917020702-OTHERS [07-07-2021(online)].pdf 2021-07-07
36 201917020702-MARKED COPIES OF AMENDEMENTS [07-07-2021(online)].pdf 2021-07-07
37 201917020702-FORM 13 [07-07-2021(online)].pdf 2021-07-07
38 201917020702-FER_SER_REPLY [07-07-2021(online)].pdf 2021-07-07
39 201917020702-COMPLETE SPECIFICATION [07-07-2021(online)].pdf 2021-07-07
40 201917020702-CLAIMS [07-07-2021(online)].pdf 2021-07-07
41 201917020702-AMMENDED DOCUMENTS [07-07-2021(online)].pdf 2021-07-07
42 201917020702-ABSTRACT [07-07-2021(online)].pdf 2021-07-07
43 201917020702-FER.pdf 2021-10-18
44 201917020702-US(14)-HearingNotice-(HearingDate-21-02-2024).pdf 2024-02-06
45 201917020702-REQUEST FOR ADJOURNMENT OF HEARING UNDER RULE 129A [16-02-2024(online)].pdf 2024-02-16
46 201917020702-US(14)-ExtendedHearingNotice-(HearingDate-22-03-2024).pdf 2024-02-20
47 201917020702-REQUEST FOR ADJOURNMENT OF HEARING UNDER RULE 129A [19-03-2024(online)].pdf 2024-03-19
48 201917020702-US(14)-ExtendedHearingNotice-(HearingDate-19-04-2024).pdf 2024-03-22
49 201917020702-Correspondence to notify the Controller [17-04-2024(online)].pdf 2024-04-17
50 201917020702-FORM 3 [03-05-2024(online)].pdf 2024-05-03
51 201917020702-Written submissions and relevant documents [04-05-2024(online)].pdf 2024-05-04
52 201917020702-RELEVANT DOCUMENTS [04-05-2024(online)].pdf 2024-05-04
53 201917020702-MARKED COPIES OF AMENDEMENTS [04-05-2024(online)].pdf 2024-05-04
54 201917020702-FORM 13 [04-05-2024(online)].pdf 2024-05-04
55 201917020702-AMMENDED DOCUMENTS [04-05-2024(online)].pdf 2024-05-04
56 201917020702-PatentCertificate10-05-2024.pdf 2024-05-10
57 201917020702-IntimationOfGrant10-05-2024.pdf 2024-05-10

Search Strategy

1 SearchstrategyE_03-12-2020.pdf

ERegister / Renewals

3rd: 01 Aug 2024

From 26/10/2019 - To 26/10/2020

4th: 01 Aug 2024

From 26/10/2020 - To 26/10/2021

5th: 01 Aug 2024

From 26/10/2021 - To 26/10/2022

6th: 01 Aug 2024

From 26/10/2022 - To 26/10/2023

7th: 01 Aug 2024

From 26/10/2023 - To 26/10/2024

8th: 01 Aug 2024

From 26/10/2024 - To 26/10/2025

9th: 23 Oct 2025

From 26/10/2025 - To 26/10/2026