Specification
DESCRIPTION
Title of Invention
GROUP SECURITY IN MACHINE-TYPE COMMUNICATION
Technical Field
This invention provides a security solution for group based
Machine-Type Communication (MTC) which is disclosed in non patent
literature 1 and 2 . The invention intends to reduce the signaling between
MTC devices and network and establish efficient secure communication
between group based MTC devices and the network.
Background Art
MTC communication has been drawing attention in both the
technical/academic and industry. According to the current 3GPP (3rd
Generation Partnership Project) specifications, the MTC devices in the
same area and/or have the same MTC feature attributed and/or belong to
the same MTC user can group together and communicate to network as a
unit.
However, from security point of view it is not yet described that how
the MTC devices that belong to a group establish secure communication
with network, including the authentication to devices and key allocation.
Neither that how a MTC device establishes secure communication with
network when it newly joins a group.
A method to establish such a secure communication between
communication devices is disclosed in patent literature 1. In patent
literature 1, when a distributing server, which distributes data, receives a
distributing request from another server (requesting server), the distributing
server sends a security request to the requesting server. The requesting
server performs setting for its security and sends information on the
security setting. The distributing server confirms the security setting of the
requesting server, and then sends requested data to the requesting server if
there is no problem on the security setting received.
Furthermore, related arts are disclosed in patent literature 2, 3 and
4 as follows.
In patent literature 2, a method by using hush function to generate a
temporary identifier (ID) for a new wireless communication device which
does not conflict with IDs of the other wireless communication devices, is
disclosed.
A communication method between communication devices is
disclosed in patent literature 3 . One-to-one or one-to-multiple
communication is performed between devices which are set as the same
group.
In patent literature 4 , it is disclosed that an integrating entity
integrates messages received from a plurality of entity, and send the
integrated message to its destination .
Patent literature 5 discloses a M2M (Machine to Machine, Mobile to
Machine, Machine to Mobile) module which is connected to a network.
[Citation List]
[Patent Literature]
[Patent Literature 1] Japanese Patent Application Laid-Open No.
2008-257340
[Patent Literature 2] International Patent Publication No.
WO2007/07281 4
[Patent Literature 3] Japanese Patent Application Laid-Open No.
2006- 081 84
[Patent Literature 4] Japanese Patent Application Laid-Open No.
2007- 0891 56
[Patent Literature 5] Japanese Patent Application Laid-Open No.
2008- 5431 37
[Non Patent Literature]
[Non Patent Literature 1] TS 22.368 "Service requirements for
Machine-Type Communications (MTC); Stage 1" (Release 10).
[Non Patent Literature 2] TS 23.888 "System Improvements for
Machine-Type Communications" (Release 10).
[Non Patent Literature 3] TS33.401 "3GPP System Architecture Evolution
(SAE); Security architecture" (Release 9).
Summary of Invention
[Technical Problem]
However, patent literature 1 discloses secure communication
between single communication devices, in other words, one-to-one
communication. Therefore, if the secure communication method disclosed
in patent literature 1 is applied to the system supposed in non patent
literature 1, which includes a plurality of the MTC devices, traffic in a
network would increase in proportion to the number of MTC devices. This is
because that the communication is carried between each single MTC device
and the network.
[Solution to Problem]
There are two main practical situations considered. One is the
group has been created and the group ID (grID) is shared by the MTC
devices that belong to the group and the network before any communication
started. For the devices, the grID is embedded in its USIM (Universal
Subscriber Identity Module) card. This will be presented in Invention .
The other situation is for a MTC device to join an existing group.
The network does not have knowledge about this MTC device in advance.
However the MTC devices who satisfy the network's requirement for a group
can request to join the group. In the opposite of invention I, the network
and the MTC device can not reach an agreement in advanced. The solution
will be proposed in Invention II. It is optional for gateway to have an UICC
(Universal Integrated Circuit Card) . When a MTC device functions as a
gateway, it will have an UICC.
An exemplary object of the invention is to provide a communication
apparatus, a communication system, a communication method and a
storage medium for storing a communication program which can solve the
problem described above.
A communication apparatus to an exemplary aspect of the invention,
which is connected to a network and a plurality of communication terminals,
includes: a group information sending means for sending group information
which is received from the network; an access control means for receiving
a reply from the communication terminal which responded to the group
information and for sending the reply to the network; and a temporary
identifier and group key sending means for sending a temporary identifier
and a group key to the communication terminal which responded to the
group information, when the communication apparatus received the
temporary identifier and the group key from the network.
A communication system to an exemplary aspect of the invention
includes: a plurality of communication terminals; a network; and a
communication apparatus which relays communication between the
plurality of communication terminals and the network; wherein the
communication apparatus receives group information from the network,
sends the group information to the plurality of communication terminals,
and sends a temporary identifier and a group key to the communication
terminal replied to the group information.
A communication method to an exemplary aspect of the invention,
which is performed between a network and a plurality of communication
terminals, the method includes: receiving group information from the
network; sending the group information to the plurality of communication
terminals; receiving a reply to the group information from the
communication terminal; and sending a temporary identifier and a group key
to the communication terminal replied to the group information.
A storage medium for storing a communication program to an
aspect of the invention includes: a group information sending process for
sending group information which is received from the network; an access
control process for receiving a reply from the communication terminal which
responded to the group information and for sending the reply to the
network; and a temporary identifier and group key sending process for
sending a temporary identifier and a group key to the communication
terminal which responded to the group information, when the temporary
identifier and the group key are received from the network.
[Advantageous Effects of Invention]
According to the present invention, traffic between MTC devices
and the network can be decreased and- a secure communication will be
established between the group based MTC devices and the network.
Brief Description of Drawings
[Fig. 1] is a block diagram for the Invention I.
[Fig. ] is a block diagram for the Invention I I .
[Fig. 3] is a message sequence chart between MTC device, gateway
and core network in the Invention I.
[Fig. 4] is a message sequence chart between MTC device, gateway
and core network in the Invention I I .
[Fig. 5] is a block diagram showing a configuration of the
communication apparatus in the first exemplary embodiment.
[Fig. 6] is a flowchart showing an operation in the first exemplary
embodiment.
[Fig. 7] is a block diagram showing a configuration of the
communication system in the second exemplary embodiment.
[Fig. 8] is a block diagram showing a configuration of the gateway
in the second exemplary embodiment.
[Fig. 9] is a block diagram showing a configuration of the MTC
device in the second exemplary embodiment.
[Fig. 10] is a block diagram showing a configuration of the core
network in the second exemplary embodiment.
[Fig. 11] is a flowchart showing an operation in the second
exemplary embodiment.
[Fig. 12] is a flowchart showing an operation in the third exemplary
embodiment.
Description of Embodiments
[Invention I]
The object of the invention is achieved by using a gateway (GW) for
security management to group optimized MTC devices. Main role of the
gateway is to establish security communication between the MTC devices
and the core network, distribute group key (grKey) and unicast temporary
IDs to the MTC devices, and optionally perform access control and generate
temporary IDs.
A few assumptions are made for this invention as below.
1. The gateway and the core network (CN) have established secure
communication.
2. The group is created beforehand on network decision.
3. The unique group D is known by all of the MTC devices within the
group and retrieved by the gateway from the network before any
communication is started.
4 . The authentication between the gateway with UICC and the
network and, between the MTC devices and the network follows 3GPP
standard AKA (Authentication and Key Agreement) .
5 . Each gateway can manage more than one group.
The invention consists of the steps below.
1. The gateway broadcasts the grIDs and sets a timer. A MTC
device will respond to the gateway with a matched grID it holds.
2 . The gateway sends a concatenated Attach Request message to
the network for the MTC devices responded before the timer is expired.
3 . Access control against MTC list for the MTC devices responded
the broadcast is performed by ( 1 ) the gateway only, (2) the network only, (3)
or both the gateway and the network.
4. AKA procedure for the MTC devices is performed in the way that
all the messages from the MTC devices are collected by the gateway and
sent to the network in a concatenated message. In the same way, the
message sent from the network is a concatenated message and the gateway
will distribute to each MTC device.
5. After a successful AKA procedure, a Security Mode Command
(SMC) procedure is performed as that of 3GPP standard [3] . From which,
the integrity and confidential keys are generated and activated for
communication between the MTC devices and the network.
6. The gateway receives grKey from the network after the secure
communication is established between them, and before the gateway
distributes it to the MTC devices. The gateway can optionally generate the
grKey itself.
7. The network creates a unique temporary ID (tempID) for each
MTC devices, by which it can exclusively recognize and communicate with
a MTC device. It sends the templDs to the gateway, and the gateway
unicasts the tempID to each MTC device. The gateway can optionally
create tempID for a MTC device. In this case, it will send the templDs to
the network.
Fig. 3 is a message sequence chart between the MTC device, the
gateway and the core network in the Invention .
At step 10, the gateway and the core network perform mutual
authentication and establish secure channel.
At step 2 , the network sends the grID, the gwlD, the grKey, the
group feature and the MTC list to the gateway. The grKey can be optionally
generated by the gateway.
At step 14, the gateway broadcasts the grID with features of a group,
and starts a timer to wait the MTC device's response.
At step 6, the MTC device which has stored the grID and the feature
matched with those in the broadcast shall respond the broadcast.
At step 18, the gateway will perform access control for the MTC
device which responded its broadcast, by comparing the received grID
against the MTC list. When the timer is expired, any response from the
MTC devices will be discarded. The access control here is optional if the
network will perform access control.
At step 20, the gateway sends a concatenated Attach Request
message including all the Attach Request messages from the MTC devices.
At step 22, the network will perform access control against the MTC
list. This procedure is optional if the gateway performs access control and
the network trusts it.
At step 24, the network performs authentication procedure with the
MTC devices, followed by a Security Mode Command (SMC) procedure in
step 26.
At step 28, the network (or the gateway optionally) generates a
unique temporary ID for each MTC device. If the network generated the
templDs, it will send them to the gateway in the Attach Accept message. If
the gateway generated templDs, it will inform them to the network in step
32.
At step 30, the gateway unicasts the templDs and distributes the
grKey to the MTC devices.
[Invention I I ]
The object of the invention is achieved by a strategy that the
network broadcasts feature requirements of a group, since the network
does not have any previous knowledge about the MTC devices which are to
be in the group. The MTC devices which meet those feature requirements
will (request to join a group) be authenticated individually by the network.
Assumption 1, 4 , 5 of Invention I applies here. And a few other
assumptions are made for this invention as below.
. The network and the MTC devices do not have any knowledge
about each other beforehand.
2. Mutual authentication between the network and the MTC devices,
and identity allocation follow 3GPP standard procedure.
The invention consists of the steps below.
1. The network broadcasts features of a group.
2 . The MTC devices which match the feature may respond, e.g. by
sending an Attach request to join the group.
3 . The network performs authentication and access control for the
MTC devices.
4 . The network generates and sends the tempID to the MTC devices.
5 . The network informs the gateway which MTC device will join the
group by sending the MTC device identity to the gateway.
6 . The generation of tempID can optionally be done by the gateway,
if so, the network will send the IMSIs (International Mobile Subscriber
Identity) of the MTC devices to the gateway. The gateway will send the
network the templDs after the generation.
7. The gateway distributes the grKey to the MTC devices.
Fig. 4 is a message sequence chart between the MTC device, the
gateway and the core network in the Invention l|.
At step 10 , the gateway and the core network perform mutual
authentication and establish secure channel.
At step 12, the network broadcasts the group features and starts a
timer to wait the MTC device to respond.
At step 14, the MTC device which matches the features can respond
by sending a request of joining the group.
At step 6 , the network will perform access control against the MTC
list. When the timer is expired, any response from the MTC devices will be
discarded.
At step 18 , the network will perform authentication with the MTC
device which responded its broadcast, followed with a SMC procedure.
At step 20, the network will generate a tempID which is unique for
each MTC device.
At step 22, the network will send the tempID to the MTC device in the
Attach Accept message.
At step 24, the network will indicate the gateway the succeeded
authenticated MTC devices' tempID.
At step 28, the gateway distributes the grKey to the MTC devices,
and can optionally unicast the templDs to the MTC devices which can be
generated in step 26. If the gateway generates the templDs, it will send
them to the network.
According to the embodiments described above, sending
concatenated messages between the gateway to the network decreases
signaling and provides efficiency especially when the group size grows
large. Using a gateway for the security management of a group, it prevents
further attacks to a network. It provides flexibility for a group to have new
members. Access control tempID generation locally performed by the
gateway can also reduce the network's load.
Hereinafter, the exemplary embodiments of the present invention
are described in detail with reference to accompanying drawings.
Documents
Application Documents
| # |
Name |
Date |
| 1 |
788-CHENP-2013 POWER OF ATTORNEY 31-01-2013.pdf |
2013-01-31 |
| 2 |
788-CHENP-2013 PCT PUBLICATION 31-01-2013.pdf |
2013-01-31 |
| 3 |
788-CHENP-2013 FORM-5 31-01-2013.pdf |
2013-01-31 |
| 4 |
788-CHENP-2013 FORM-3 31-01-2013.pdf |
2013-01-31 |
| 5 |
788-CHENP-2013 FORM-2 FIRST PAGE 31-01-2013.pdf |
2013-01-31 |
| 6 |
788-CHENP-2013 FORM-18 31-01-2013.pdf |
2013-01-31 |
| 7 |
788-CHENP-2013 FORM-1 31-01-2013.pdf |
2013-01-31 |
| 8 |
788-CHENP-2013 DRAWINGS 31-01-2013.pdf |
2013-01-31 |
| 9 |
788-CHENP-2013 DESCRIPTION (COMPLETE) 31-01-2013.pdf |
2013-01-31 |
| 10 |
788-CHENP-2013 CORRESPONDENCE OTHERS 31-01-2013.pdf |
2013-01-31 |
| 11 |
788-CHENP-2013 CLAIMS SIGNATURE LAST PAGE 31-01-2013.pdf |
2013-01-31 |
| 12 |
788-CHENP-2013 CLAIMS 31-01-2013.pdf |
2013-01-31 |
| 13 |
788-CHENP-2013.pdf |
2013-02-03 |
| 14 |
788-CHENP-2013 FORM-3 23-07-2013.pdf |
2013-07-23 |
| 15 |
788-CHENP-2013 CORRESPONDENCE OTHERS 23-07-2013.pdf |
2013-07-23 |
| 16 |
abstract788-CHENP-2013.jpg |
2014-05-12 |
| 17 |
788-CHENP-2013-FER.pdf |
2018-12-12 |
| 18 |
788-CHENP-2013-AbandonedLetter.pdf |
2019-06-14 |
Search Strategy
| 1 |
788_chenp_2013_search_06-12-2018.pdf |