Abstract: In order to improve security upon distributing a group key there is provided a gateway (20) to a core network for a group of MTC devices (10_1 10_n) communicating with the core network. The gateway (20) protects confidentiality and integrity of a group key and distributes the protected group key to each of the MTC devices (10_1 10_n). The protection is performed by using: a key (Kgr) that is preliminarily shared between the gateway (20) and each of the MTC devices (10_1 10_n) and that is used for the gateway (20) to authenticate each of the MTC devices (10_1 10_n) as a member of the group; or a key (K_iwf) that is shared between an MTC IWF (50) and each of the MTC devices (10_1 10_n) and that is used to derive temporary keys for securely conducting individual communication between the MTC IWF (50) and each of the MTC devices (10_1 10_n).
Description
Title of Invention: DEVICES AND METHOD FOR MTC GROUP KEY MANAGEMENT
Technical Field
[0001] The present invention relates to a security solution for group based MTC
(Machine-Type-Communication). In particular, the present invention relates to
techniques to distribute a group key within a core network and to MTC devices, to
derive the group key and/or to manage the group key.
Background Art
[0002] The 3GPP (3rd Generation Partnership Project) architecture of MTC has been studied
in NPL 1. Study of group based MTC has also been initiated in NPL 2.
[0003] Further, PTL 1 discloses that a GW (Gateway) which serves as a gateway to a core
network for a group of MTC devices, and uses a group key to securely conduct com
munication with the group members.
[0004] Note that the MTC device is a UE (User Equipment) equipped for MTC, which will
be sometimes referred to as "MTC UE" or "UE" in the following explanation.
Citation List
Non Patent Literature
[0005] NPL 1: 3GPP TS 23.682, "Architecture enhancements to facilitate communications
with packet data networks and applications (Release 11)", VI 1.2.0, 2012-09
NPL 2: 3GPP TR 23.887, "Machine-Type and other Mobile Data Applications Com
munications Enhancements (Release 12)", V0.5.0, 2012-11, Clause 8, pp. 78-94
NPL 3: 3GPP TR 33.868, "Security aspects of Machine-Type and other Mobile Data
Applications Communications Enhancements; (Release 12)", V0.13.0, 2013-04,
Clause A.6.4.2, pp.87-88
Patent Literature
[0006] PTL 1: International Patent Publication No. WO 20 12/0 18130
Summary of Invention
Technical Problem
[0007] However, the inventors of this application have found that there is a problem in PTL
1 that the group key is distributed to the group members without any protection.
[0008] Note that NPL 3 discloses that an MME (Mobility Management Entity) protects the
group key by using NAS (Non Access Stratum) security context. However, there is a
problem in NPL 3 that the NAS security context merely ensures the confidentiality of
group key.
[0009] Accordingly, an exemplary object of the present invention is to improve security
upon distributing a group key.
Solution to Problem
[0010] In order to achieve the above-mentioned object, a communication system according
to first exemplary aspect of the present invention includes a group of MTC devices that
communicate with a core network, and a gateway to the core network for the group.
The gateway distributes, to each of the MTC devices, a first key for securely
conducting group communication. Upon distributing the first key, the gateway protects
confidentiality and integrity of the first key by using: a second key that is preliminarily
shared between the gateway and each of the MTC devices, and that is used for the
gateway to authenticate each of the MTC devices as a member of the group; or a third
key that is shared between an MTC-IWF (MTC Inter-Working Function) and each of
the MTC devices, and that is used to derive temporary keys for securely conducting in
dividual communication between the MTC-IWF and each of the MTC devices. The
MTC-IWF serves as an entering point to the core network for an SCS (Service Ca
pability Server) that communicates with the group through the core network.
[001 1] Further, a gateway according to second exemplary aspect of the present invention
serves as a gateway to a core network for a group of MTC devices communicating
with the core network. The gateway includes: protection means for protecting confi
dentiality and integrity of a first key for securely conducting group communication;
and distribution means for distributing the protected first key to each of the MTC
devices. The protection means is configured to perform the protection by using: a
second key that is preliminarily shared between the gateway and each of the MTC
devices, and that is used for the gateway to authenticate each of the MTC devices as a
member of the group; or a third key that is shared between an MTC-IWF and each of
the MTC devices, and that is used to derive temporary keys for securely conducting in
dividual communication between the MTC-IWF and each of the MTC devices. The
MTC-IWF serves as an entering point to the core network for an SCS that com
municates with the group through the core network.
[0012] Further, an MTC device according to third exemplary aspect of the present invention
is grouped to communicate with a core network. The MTC device includes: reception
means for receiving, from a gateway to the core network for a group of MTC devices,
a first key for securely conducting group communication. Confidentiality and integrity
of the first key are protected with a second key or a third key. The second key is pre
liminarily shared between the gateway and each of the MTC devices, and used for the
gateway to authenticate each of the MTC devices as a member of the group. The third
key is shared between an MTC-IWF and each of the MTC devices, and used to derive
temporary keys for securely conducting individual communication between the MTCIWF
and each of the MTC devices. The MTC-IWF serves as an entering point to the
core network for an SCS that communicates with the group through the core network.
[0013] Further, a method according to fourth exemplary aspect of the present invention
provides a method of controlling operations in a gateway to a core network for a group
of MTC devices that communicates with the core network. This method includes:
protecting confidentiality and integrity of a first key for securely conducting group
communication; and distributing the protected first key to each of the MTC devices.
The protection is performed by using: a second key that is preliminarily shared
between the gateway and each of the MTC devices, and that is used for the gateway to
authenticate each of the MTC devices as a member of the group; or a third key that is
shared between an MTC-IWF and each of the MTC devices, and that is used to derive
temporary keys for securely conducting individual communication between the MTCIWF
and each of the MTC devices. The MTC-IWF serves as an entering point to the
core network for an SCS that communicates with the group through the core network.
[0014] Furthermore, a method according to fifth exemplary aspect of the present invention
provides a method of controlling operations in an MTC device that is grouped to com
municate with a core network. This method includes: receiving, from a gateway to the
core network for a group of MTC devices, a first key for securely conducting group
communication. Confidentiality and integrity of the first key are protected with a
second key or a third key. The second key is preliminarily shared between the gateway
and each of the MTC devices, and used for the gateway to authenticate each of the
MTC devices as a member of the group. The third key is shared between an MTC-IWF
and each of the MTC devices, and used to derive temporary keys for securely
conducting individual communication between the MTC-IWF and each of the MTC
devices. The MTC-IWF serves as an entering point to the core network for an SCS that
communicates with the group through the core network.
Advantageous Effects of Invention
[0015] According to the present invention, it is possible to solve the above-mentioned
problems, and thus to improve security upon distributing a group key.
Brief Description of Drawings
[0016] [fig. 1]Fig. 1 is a block diagram showing a configuration example of a communication
system according to an exemplary embodiment of the present invention.
[fig.2]Fig. 2 is a sequence diagram showing a first operation example of the commu
nication system according to the exemplary embodiment.
[fig.3]Fig. 3 is a sequence diagram showing a second operation example of the com
munication system according to the exemplary embodiment.
[fig.4]Fig. 4 is a sequence diagram showing a third operation example of the commu
nication system according to the exemplary embodiment.
[fig.5]Fig. 5 is a sequence diagram showing a fourth operation example of the commu
nication system according to the exemplary embodiment.
[fig.6]Fig. 6 is a sequence diagram showing a fifth operation example of the commu
nication system according to the exemplary embodiment.
[fig.7]Fig. 7 is a sequence diagram showing a sixth operation example of the commu
nication system according to the exemplary embodiment.
[fig.8]Fig. 8 is a block diagram showing a configuration example of a MTC UE
according to the exemplary embodiment.
[fig.9]Fig. 9 is a block diagram showing a configuration example of a group GW
according to the exemplary embodiment.
[fig.lO]Fig. 10 is a block diagram showing a configuration example of an HSS
according to the exemplary embodiment.
[fig. 1l]Fig. 11 is a block diagram showing a configuration example of an MTC-IWF
according to the exemplary embodiment.
Description of Embodiments
[0017] Hereinafter, an exemplary embodiment of the present invention will be described
with the accompany drawings.
[0018] In this exemplary embodiment, there will be proposed details for group keys
derivation at a core network, key distribution to proper network nodes and UEs, key
management and how the group keys are used for securing communication. Key
derivation parameters can be either sent from an HSS (Home Subscriber Server) to an
MTC-IWF, or from the MTC-IWF to the HSS. The derivation algorithms are available
in the network node.
[0019] As shown in Fig. 1, a communication system according to this exemplary em
bodiment includes a core network (3GPP network), and one or more MTC UEs 10
which are UEs equipped for MTC and connect to the core network through a RAN
(Radio Access Network). In this exemplary embodiment, the MTC UEs 10 are grouped
to communicate with the core network. Note that while the illustration is omitted, the
RAN is formed by a plurality of base stations (e.g., eNBs (evolved Node Bs)).
[0020] The MTC UE 10 attaches to the core network. The MTC UE 10 can host one or
multiple MTC Applications. The corresponding MTC Applications in the external
network are hosted on an SCS 60. The SCS 60 connects to the core network to com
municate with the MTC UE 10.
[0021] Further, the core network includes an MME 30, an HSS 40 and an MTC-IWF 50 as a
part of its network nodes. The MME 30 relays traffic between the RAN and the MTCIWF
50. The HSS 40 manages subscription information on the MTC UEs 10, and the
like. The MTC-IWF 50 serves as an entering point to the core network for the SCS 60,
and if necessary, acquires the subscription information and the like from the HSS 40.
The core network also includes, as other network nodes, an SGSN (Serving GPRS
(General Packet Radio Service) Support Node), an MSC (Mobile Switching Centre)
and the like. The SGSN and the MSC function as with the MME 30.
[0022] While the illustration is omitted in Fig. 1, the core network includes a gateway to the
core network for the group of MTC UEs 10. Hereinafter, this gateway is referred to as
"group GW" and denoted by the symbol 20. Typically, the group GW 20 distributes to
each of the MTC UEs 10 a group key for securely conducting group communication
between the group GW 20 and the group of MTC UEs 10. The group GW 20 can be
either deployed in a network node or be an independent node.
[0023] Next, operation examples of this exemplary embodiment will be described in detail
with reference to Figs. 2 to 7. Note that configuration examples of the MTC UE 10, the
group GW 20, the HSS 40 and the MTC-IWF 50 will be described later with reference
to Figs. 8 to 11.
[0024] 1. Key distribution
Group communication requires the group GW 20 and group member of MTC UEs 10
share the same group key.
[0025] There are two options that the group GW 20 can obtain the group keys. One of
options is a case where the group GW 20 itself derives the group key. There will be
described later how to derive the group key. Another one of options is a case where the
group GW 20 receives the group key from another network node. This exemplary em
bodiment further considers that whether the group GW 20 is configured at the MTCIWF
50 or not.
[0026] (1) Case where the MTC-rWF 50 is not group GW 20 but shares the group key
In this case, as shown in Fig. 2, the HSS 40 derives the group key and sends it to the
MTC-IWF 50 together with group ID in a Subscriber Information Response message
(Steps Sla to Slc).
[0027] Alternatively, the MTC-IWF 50 derives the group key, when it has received the
group ID and optionally key derivation parameters from the HSS 40 in the Subscriber
Information Response message (Steps S2a to S2c).
[0028] The derived group key is sent, to the group GW 20 through the MME 30, together
with the group ID and a KSI (Key Set Identifier) of the group key (Step S3).
[0029] Then, the group GW 20 distributes the group key to MTC UEs 10_1 to 10_n (n?2)
which are members of MTC group (Steps S4_l to S4_n).
[0030] There are two ways to protect the group key upon the distribution to the MTC UEs
10_1 to 10_n.
[0031] One of ways is to use a pre-configured authentication used group key Kgr. The key
Kgr is preliminarily shared between the group GW 20 and each of the MTC UEs 10_1
to 10_n, and used for the group GW 20 to authenticate each of the MTC UEs 10_1 to
10_n as a member of the MTC group.
[0032] Upon the authentication, each of the MTC UEs 10_1 to 10_n receives an Authen
tication Request message from the group GW 20, and then computes e.g., a RES
(authentication response) with the key Kgr. Each of the MTC UEs 10_1 to 10_n sends
to the group GW 20 an Authentication Response message containing the computed
RES. The group GW 20 checks the received RES with the key Kgr, thereby authen
ticating each of the MTC UEs 10_1 to 10_n.
[0033] Upon the distribution, the group GW 20 encrypts the group key with the key Kgr to
protect the confidentiality of group key, and also ensures the integrity of group key
with the key Kgr. Each of the MTC UEs 10_1 to 10_n decrypts the received group key
with the key Kgr, and also checks the integrity of the received group key with the key
Kgr.
[0034] Another one of ways is to use a root key K_iwf. The root key K_iwf is shared
between the MTC-IWF 50 and each of the MTC UEs 10_1 to 10_n, and used to derive
temporary keys for securely conducting individual communication between the MTCIWF
50 and each of the MTC UEs 10_1 to 10_n.
[0035] One of temporary keys is a confidentiality key for encrypting and decrypting
messages transferred between the MTC-IWF and the MTC UE. Another one of
temporary keys is an integrity key for checking the integrity of message transferred
between the MTC-IWF and the MTC UE.
[0036] Upon the distribution, the group GW 20 encrypts the group key with the key K_iwf
to protect the confidentiality of group key, and also ensures the integrity of group key
with the key K_iwf. Each of the MTC UEs 10_1 to 10_n decrypts the received group
key with the key K_iwf, and also checks the integrity of the received group key with
the key K_iwf.
[0037] According to this exemplary embodiment, both of the confidentiality and integrity of
group key is ensured upon the distribution to the group member, so that it is possible to
greatly improve security compared with the above-mentioned PTL 1 and NPL 3.
[0038] (2) Case where the MTC-IWF 50 is the group GW 20
In this case, as shown in Fig. 3, the HSS 40 or an MTC-IWF 50A (which also serves
as the group GW) derives the group key in a similar manner to Fig. 2 (Steps SI l a to
S12c).
[0039] Then, the MTC-IWF 50A distributes the group key to the MTC UEs 10_1 to 10_n in
a similar manner to Fig. 2 (Steps S14_l to S14_n).
[0040] (3) Case where the MTC-IWF 50 is not group GW 20 and does not need to share the
group key
In this case, as shown in Fig. 4, the HSS 40 derives the group key and sends it to the
MME 30 during UE authentication procedure in e.g., an Authentication Data Response
message (Steps S21 and S22). In the case of including the group key in the Authen
tication Data Response message, it is possible to reduce the impact to communication
protocols. This is because the Authentication Data Response message is the existing
message transferred between typical MME and HSS.
[0041] The MME 30 can send the group key to the group GW 20 in a new message or
include it in the forwarded trigger (Step S23).
[0042] The group key can be only activated after each of the MTC UEs 10_1 to 10_n is au
thenticated to the core network as the group member and individually. Thereafter, the
MME 30 can also send the group key to the group GW 20 after it confirmed that each
of the MTC UEs 10_1 to 10_n is authenticated as the group member and individually.
[0043] Then, the group GW 20 distributes the group key to the MTC UEs 10_1 to 10_n in a
similar manner to Fig. 2 (Steps S24_l to S24_n).
[0044] 2. Key derivation
For deriving the group key, the KDF (Key Derivation Function) defined in 3GPP TS
33.401 can be re-used.
[0045] There are four options of input parameter:
(1) the pre-configured key Kgr (in MTC UE and group GW);
(2) the key K_iwf that shared between MTC-IWF and MTC UE;
(3) Kasme defined in 3GPP TS 33.401; and
(4) random number.
[0046] Other parameters can be: internal group ID, group gateway ID, key derivation
algorithm identifier, counter.
[0047] A lifetime value can be also generated when the new group keys are derived.
[0048] Key derivation parameters can be sent from the HSS 40 to the MTC-IWF 50 (or
50A), or from the MTC-IWF 50 (or 50A) to the HSS 40. The derivation algorithms are
configured in the network node which derives the group key.
[0049] 3. Key management
The group key can be updated when:
the lifetime of the group key is expired;
a group member is deleted from the group;
the derivation parameter (e.g., the root key K_iwf) has been updated; or
derive and store new group keys before transit to inactive state.
[0050] Examples of key update procedure are shown in Figs. 5 to 7.
[005 1] (1) Case where the MTC-IWF 50 is not group GW 20 but shares the group key
In this case, as shown in Fig. 5, the HSS 40 updates the group key and sends it to the
MTC-IWF 50 together with group ID in a Subscriber Information Update message
(Steps S3 l a and S3 lb).
[0052] Alternatively, the MTC-IWF 50 updates the group key, and optionally retrieves key
derivation parameters from the HSS 40 (Steps S32a and S32b).
[0053] The updated group key is sent, to the group GW 20 through the MME 30, together
with the group ID and a KSI of the updated group key (Step S33).
[0054] Then, the group GW 20 re-distributes the updated group key to MTC UEs 10_1 to
10_n (Steps S34_l to S34_n). At this time, the updated group key is protected by using
the key Kgr or K_iwf.
[0055] (2) Case where the MTC-IWF 50 is the group GW 20
In this case, as shown in Fig. 6, the HSS 40 or the MTC-IWF 50A updates the group
key in a similar manner to Fig. 5 (Steps S41a to S42b).
[0056] Then, the MTC-IWF 50A re-distributes the updated group key to the MTC UEs 10_1
to 10_n in a similar manner to Fig. 5 (Steps S44_l to S44_n).
[0057] (3) Case where the MTC-IWF 50 is not group GW 20 and does not need to share the
group key
In this case, as shown in Fig. 7, the HSS 40 updates the group key and sends it to the
MME 30 in e.g., an Insert Subscriber Data message (Steps S51 and S52). In the case of
including the updated group key in the Insert Subscriber Data message, it is possible to
reduce the impact to communication protocols. This is because the Insert Subscriber
Data is the existing message transferred between typical MME and HSS.
[0058] The MME 30 can send the updated group key to the group GW 20 in a new message
(Step S53).
[0059] Then, the group GW 20 re-distributes the updated group key to the MTC UEs 10_1
to 10_n in a similar manner to Fig. 5 (Steps S54_l to S54_n).
[0060] Next, configuration examples of the MTC UE 10, the group GW 20, the HSS 40 and
the MTC-IWF 50 (50A) according to this exemplary embodiment will be described
with reference to Figs. 8 to 11.
[0061] As shown in Fig. 8, the MTC UE 10 includes a reception unit 11 that receives the
protected group key from the group GW 20. The reception unit 11 can be configured
by, for example, a transceiver which wirelessly conducts communication with the core
network through the RAN, and a controller such as a CPU (Central Processing Unit)
which controls this transceiver.
[0062] As show in Fig. 9, the group GW 20 includes at least a protection unit 2 1 and a di s
tribution unit 22. The protection unit 2 1 protects the group key by using the key Kgr or
K_iwf. The distribution unit 22 distributes the protected group key to the MTC UE 10.
In the case where the HSS 40 or the MTC-IWF 50 (not the Group GW 20) derives the
group key, the group GW 20 further includes a reception unit 23 that receives the
group key from the HSS 40 or the MTC-IWF 50. The reception unit 23 also receives
the updated group key. As a substitute for the reception unit 23, the group GW 20 may
include a derivation unit 24 that derives the group key by using, as the key derivation
parameters, the key Kgr, the key K_iwf, the Kasme or the random number. The
derivation unit 24 also updates the group key. In either case, the protection unit 2 1
protects the updated group key by using the key Kgr or K_iwf, and the distribution unit
22 re-distributes the protected and updated group key. Note that these units 2 1 to 24
are mutually connected with each other through a bus or the like. These units 2 1 to 24
can be configured by, for example, transceivers which conduct communication with
other nodes within the core network, and a controller such as a CPU which controls
these transceivers.
[0063] As show in Fig. 10, the HSS 40 can include a derivation unit 4 1 and a send unit 42 in
addition to elements of a typical HSS. The derivation unit 4 1 derives the group key by
using, as the key derivation parameters, the key Kgr, the key K_iwf, the Kasme or the
random number. The send unit 42 sends the group key to the group GW 20 and/or the
MTC-IWF 50. The derivation unit 4 1 may update the group key, and the send unit 42
may send the updated group key to the group GW 20 and/or the MTC-IWF 50. Note
that these units 4 1 and 42 are mutually connected with each other through a bus or the
like. These units 4 1 and 42 can be configured by, for example, transceivers which
conduct communication with other nodes within the core network, and a controller
such as a CPU which controls these transceivers.
[0064] As show in Fig. 11, the MTC-IWF 50 (50A) can include a derivation unit 5 1 and a
send unit 52 in addition to elements of a typical MTC-rWF. The derivation unit 5 1
derives the group key by using, as the key derivation parameters, the key Kgr, the key
K_iwf, the Kasme or the random number. The send unit 52 sends the group key to the
group GW 20 or the MTC UE 10. The derivation unit 5 1 may update the group key,
and the send unit 52 may send the updated group key to the group GW 20 or the MTC
UE 10. Note that these units 5 1 and 52 are mutually connected with each other through
a bus or the like. These units 5 1 and 52 can be configured by, for example, transceivers
which conduct communication with other nodes within the core network, and a
controller such as a CPU which controls these transceivers.
[0065] Note that the present invention is not limited to the above-mentioned exemplary em
bodiment, and it is obvious that various modifications can be made by those of
ordinary skill in the art based on the recitation of the claims.
[0066] This application is based upon and claims the benefit of priority from Japanese patent
application No. 2013-158881, filed on July 31, 2013, the disclosure of which is in
corporated herein in its entirety by reference.
Reference Signs List
[0067] 10, 10_l-10_n MTC UE
, 23 RECEPTION UNIT
Group GW
PROTECTION UNIT
DISTRIBUTION UNIT
41, 5 1 DERIVATION UNIT
MME
HSS
52 SEND UNIT
50A MTC-rWF
SCS
Claims
[Claim 1] A communication system comprising:
a group of MTC (Machine-Type-Communication) devices that com
municate with a core network; and
a gateway to the core network for the group, the gateway distributing to
each of the MTC devices a first key for securely conducting group
communication,
wherein upon distributing the first key, the gateway protects confi
dentiality and integrity of the first key by using:
a second key that is preliminarily shared between the gateway and each
of the MTC devices, and that is used for the gateway to authenticate
each of the MTC devices as a member of the group; or
a third key that is shared between an MTC-IWF (MTC Inter-Working
Function) and each of the MTC devices, and that is used to derive
temporary keys for securely conducting individual communication
between the MTC-IWF and each of the MTC devices, the MTC-IWF
serving as an entering point to the core network for an SCS (Service
Capability Server) that communicates with the group through the core
network.
[Claim 2] The communication system according to Claim 1, further comprising:
an HSS (Home Subscriber Server) that manages subscription in
formation on each of the MTC devices, and that derives the first key to
be distributed from the gateway to each of the MTC devices,
wherein as a parameter for deriving the first key, the HSS uses:
the second key;
the third key;
Kasme (Key Access Security Management Entity); or
a random number.
[Claim 3] The communication system according to Claim 2, wherein the HSS
transfers the first key to the MTC-IWF.
[Claim 4] The communication system according to Claim 2 or 3, wherein the
HSS is configured to:
update the first key when lifetime of the first key expires, a member of
the group is deleted from the group, the parameter is changed, or the
group communication transits to an inactive state; and
cause the gateway to re-distribute the updated first key.
[Claim 5] The communication system according to Claim 4, wherein the HSS
WO 2015/015714 PCT/JP2014/003579
uses an Insert Subscriber Data message upon causing the gateway to re
distribute the updated first key.
[Claim 6] The communication system according to Claim 1,
wherein the MTC-IWF derives the first key to be distributed from the
gateway to each of the MTC devices,
wherein as a parameter for deriving the first key, the MTC-IWF uses:
the second key;
the third key;
Kasme; or
a random number.
[Claim 7] The communication system according to Claim 6, further comprising:
an HSS that manages subscription information on each of the MTC
devices,
wherein the MTC-IWF acquires the parameter from the HSS.
[Claim 8] The communication system according to Claim 6 or 7, wherein the
MTC-IWF is configured to:
update the first key when lifetime of the first key expires, a member of
the group is deleted from the group, the parameter is changed, or the
group communication transits to an inactive state; and
cause the gateway to re-distribute the updated first key.
[Claim 9] The communication system according to Claim 1, wherein the gateway
derives the first key by using as a parameter:
the second key;
the third key;
Kasme; or
a random number.
[Claim 10] The communication system according to Claim 9, wherein the gateway
is configured to:
update the first key when lifetime of the first key expires, a member of
the group is deleted from the group, the parameter is changed, or the
group communication transits to an inactive state;
protect the updated first key by using the second or third key; and
re-distribute the protected and updated first key.
[Claim 11] A gateway to a core network for a group of MTC devices commu
nicating with the core network, the gateway comprising:
protection means for protecting confidentiality and integrity of a first
key for securely conducting group communication; and
distribution means for distributing the protected first key to each of the
WO 2015/015714 PCT/JP2014/003579
MTC devices,
wherein the protection means is configured to perform the protection
by using:
a second key that is preliminarily shared between the gateway and each
of the MTC devices, and that is used for the gateway to authenticate
each of the MTC devices as a member of the group; or
a third key that is shared between an MTC-IWF and each of the MTC
devices, and that is used to derive temporary keys for securely
conducting individual communication between the MTC-IWF and each
of the MTC devices, the MTC-IWF serving as an entering point to the
core network for an SCS that communicates with the group through the
core network.
[Claim 12] The gateway according to Claim 11, further comprising:
reception means for receiving the first key from an HSS that manages
subscription information on each of the MTC devices, or from the
MTC-IWF.
[Claim 13] The gateway according to Claim 12,
wherein when the first key is updated by the HSS or the MTC-IWF, the
reception means is configured to receive the updated first key,
wherein the protection means is configured to protect the updated first
key by using the second or third key,
wherein the distribution means is configured to re-distribute the
protected and updated first key.
[Claim 14] The gateway according to Claim 11, further comprising derivation
means for deriving the first key by using as a parameter:
the second key;
the third key;
Kasme; or
a random number.
[Claim 15] The gateway according to Claim 14,
wherein the derivation means is configured to update the first key when
lifetime of the first key expires, a member of the group is deleted from
the group, the parameter is changed, or the group communication
transits to an inactive state,
wherein the protection means is configured to protect the updated first
key by using the second or third key,
wherein the distribution means is configured to re-distribute the
protected and updated first key.
WO 2015/015714 PCT/JP2014/003579
[Claim 16] An MTC device that is grouped to communicate with a core network,
the MTC device comprising:
reception means for receiving, from a gateway to the core network for a
group of MTC devices, a first key for securely conducting group com
munication, confidentiality and integrity of the first key being protected
with a second key or a third key,
wherein the second key is preliminarily shared between the gateway
and each of the MTC devices, and used for the gateway to authenticate
each of the MTC devices as a member of the group,
wherein the third key is shared between an MTC-IWF and each of the
MTC devices, and used to derive temporary keys for securely
conducting individual communication between the MTC-IWF and each
of the MTC devices, the MTC-IWF serving as an entering point to the
core network for an SCS that communicates with the group through the
core network.
[Claim 17] A method of controlling operations in a gateway to a core network for a
group of MTC devices that communicates with the core network, the
method comprising:
protecting confidentiality and integrity of a first key for securely
conducting group communication; and
distributing the protected first key to each of the MTC devices,
wherein the protection is performed by using:
a second key that is preliminarily shared between the gateway and each
of the MTC devices, and that is used for the gateway to authenticate
each of the MTC devices as a member of the group; or
a third key that is shared between an MTC-IWF and each of the MTC
devices, and that is used to derive temporary keys for securely
conducting individual communication between the MTC-IWF and each
of the MTC devices, the MTC-IWF serving as an entering point to the
core network for an SCS that communicates with the group through the
core network.
[Claim 18] A method of controlling operations in an MTC device that is grouped
to communicate with a core network, the method comprising:
receiving, from a gateway to the core network for a group of MTC
devices, a first key for securely conducting group communication, con
fidentiality and integrity of the first key being protected with a second
key or a third key,
wherein the second key is preliminarily shared between the gateway
PCT/JP2014/003579
and each of the MTC devices, and used for the gateway to authenticate
each of the MTC devices as a member of the group,
wherein the third key is shared between an MTC-IWF and each of the
MTC devices, and used to derive temporary keys for securely
conducting individual communication between the MTC-IWF and each
of the MTC devices, the MTC-IWF serving as an entering point to the
core network for an SCS that communicates with the group through the
core network.
| # | Name | Date |
|---|---|---|
| 1 | Priority Document [30-12-2015(online)].pdf | 2015-12-30 |
| 2 | Form 5 [30-12-2015(online)].pdf | 2015-12-30 |
| 3 | Form 3 [30-12-2015(online)].pdf | 2015-12-30 |
| 4 | Form 18 [30-12-2015(online)].pdf | 2015-12-30 |
| 5 | Drawing [30-12-2015(online)].pdf | 2015-12-30 |
| 6 | Description(Complete) [30-12-2015(online)].pdf | 2015-12-30 |
| 7 | 11929-DELNP-2015.pdf | 2016-01-04 |
| 8 | 11929-delnp-2015-GPA-(27-01-2016).pdf | 2016-01-27 |
| 9 | 11929-delnp-2015-Correspondence Others-(27-01-2016).pdf | 2016-01-27 |
| 10 | Other Patent Document [27-06-2016(online)].pdf | 2016-06-27 |
| 11 | Form 3 [28-06-2016(online)].pdf | 2016-06-28 |
| 12 | 11929-delnp-2015-Form-1-(11-07-2016).pdf | 2016-07-11 |
| 13 | 11929-delnp-2015-Correspondence Others-(11-07-2016).pdf | 2016-07-11 |
| 14 | 11929-DELNP-2015-FER.pdf | 2019-11-19 |
| 1 | Searchstrategy_15-11-2019.pdf |