Sign In to Follow Application
View All Documents & Correspondence

Key Management In Machine Type Communication System

Abstract: A MTC device (10) and a MTC interworking function MTC IWF (20) form a communication system and conduct communication with each other. In this communication system a root key (K iwf) is securely shared between the MTC device (10) and the MTC IWF (20). The MTC device (10) and the MTC IWF (20) use the root key (K iwf) to respectively derive temporary keys (K di (K di conf K di int)) for protecting the communication. The temporary keys provide integrity protection and confidentiality. The root key can be derived by the HSS or MME/SGSN/MSC and provided to the MTC IWF. The root key can also be derived by the MTC IWF based on received key derivation material. The described system is useful for the security of small data transmission in MTC system.

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
11 February 2015
Publication Number
26/2015
Publication Type
INA
Invention Field
COMMUNICATION
Status
Email
Parent Application

Applicants

NEC CORPORATION
7-1 Shiba 5 chome Minato ku Tokyo 1088001

Inventors

1. ZHANG Xiaowei
c/o NEC Corporation 7-1 Shiba 5 chome Minato ku Tokyo 1088001
2. PRASAD Anand Raghawa
c/o NEC Corporation 7-1 Shiba 5 chome Minato ku Tokyo 1088001

Specification

1
WO 2014/041806 PCT/JP2013/005398
Description
Title of Invention: KEY MANAGEMENT IN MACHINE TYPE
COMMUNICATION SYSTEM
Technical Field
[0001] The present invention relates to key management in MTC (Machine-Type Communication)
system.
Background Art
[0002] As described in NPL 1, the security over the interface between MTC device and
MTC-IWF (MTC Inter-Working Function) should be studied. However, the study has
not been fulfilled. Currently, there is no security solution over the interface between
MTC device and MTC-IWF in 3GPP (3rd Generation Partnership Project) SA3.
Citation List
Non Patent Literature
[0003] NPL 1: 3GPP TR 33.868, "Security aspects of Machine-Type Communications;
(Release 11)", vO.9.0, 2012-07, Clause 4
Summary of Invention
Technical Problem
[0004] As discussed above, secure communication is required between MTC device and
MTC-IWF.
[0005] MTC-rWF supports to authorize SCS (Service Capability Server) and to authorize
control plane requests from SCS including trigger. MTC-IWF also delivers the
messages (e.g. trigger message) from SCS to MTC devices. Man-in-the-middle and
replay attack may happen on the interface between MTC device and MTC-IWF. Also,
MME (Mobility Management Entity) does not need to have knowledge about SCS and
the message content that it forwards. Therefore it is reasonable to have end-to-end
security between MTC device and MTC-rWF.
Solution to Problem
[0006] In order to solve the above-mentioned problems, a communication system according
to first exemplary aspect of the present invention includes a MTC device; and a MTCIWF
that conducts communication with the MTC device. In this system, a root key is
securely shared between the MTC device and the MTC-rWF. The MTC device and the
MTC-IWF use the root key to respectively derive temporary keys for protecting the
communication.
[0007] Further, a MTC-IWF according to second exemplary aspect of the present invention
includes a communication means for conducting communication with a MTC device; a
2
WO 2014/041806 PCT/JP2013/005398
sharing means for securely sharing a root key with the MTC device; and a derivation
means for deriving temporary keys by use of the root key for protecting the communication.
[0008] Further, a MTC device according to third exemplary aspect of the present invention
includes a communication means for conducting communication with a MTC-IWF; a
sharing means for securely sharing a root key with the MTC-IWF; and a derivation
means for deriving temporary keys by use of the root key for protecting the communication.
[0009] Further, a network entity according to fourth exemplary aspect of the present
invention is placed within a core network to which a MTC device attached. This
network entity includes a derivation means for deriving a root key; and a send means
for sending the root key to a MTC-IWF that conducts communication with the MTC
device.
[0010] Further, a network entity according to fifth exemplary aspect of the present invention
is placed within a core network to which a MTC device attached. This network entity
includes a send means for sending, to a MTC-IWF that conducts communication with
the MTC device, materials for the MTC-IWF to derive a root key.
[001 1] Further, a method according to sixth exemplary aspect of the present invention
provides a method of controlling operations in a MTC-IWF. This method includes
conducting communication with a MTC device; securely sharing a root key with the
MTC device; and deriving temporary keys by use of the root key for protecting the
communication.
[0012] Further, a method according to seventh exemplary aspect of the present invention
provides a method of controlling operations in a MTC device. This method includes
conducting communication with a MTC-IWF; securely sharing a root key with the
MTC-IWF; and deriving temporary keys by use of the root key for protecting the communication.
[0013] Further, a method according to eighth exemplary aspect of the present invention
provides a method of controlling operations in a network entity placed within a core
network to which a MTC device attached. This method includes deriving a root key;
and sending the root key to a MTC-IWF that conducts communication with the MTC
device.
[0014] Furthermore, a method according to ninth exemplary aspect of the present invention
provides a method of controlling operations in a network entity placed within a core
network to which a MTC device attached. This method includes sending, to a MTCIWF
that conducts communication with the MTC device, materials for the MTC-IWF
to derive a root key.
3
WO 2014/041806 PCT/JP2013/005398
Advantageous Effects of Invention
[0015] According to the present invention, it is possible to solve the above-mentioned
problems, so that for example, the following effects (1) to (3) can be achieved.
[0016] (1) End-to-end security can be provided by protecting the messages between MTCIWF
and UE (User Equipment) with the proposed keys.
[0017] (2) UE can perform MTC-IWF authorization by integrity check of the messages sent
from MTC-IWF, with using the proposed keys.
[0018] (3) The message can be serving node (MME/SGSN/MSC) independent. Messages
sent from MTC-IWF can be delivered to UE, even the serving node is changed due to
UE mobility, or network failure. UE doesn't need to perform source authentication and
authorization again.
Brief Description of Drawings
[0019] [fig. 1] Fig. 1 is a block diagram showing a configuration example of a communication
system according to an exemplary embodiment of the present invention.
[fig.2]Fig. 2 is a block diagram showing a key hierarchy in the communication system
according to the exemplary embodiment.
[fig.3]Fig. 3 is a sequence diagram showing a first operation example of the communication
system according to the exemplary embodiment.
[fig.4]Fig. 4 is a sequence diagram showing a second operation example of the communication
system according to the exemplary embodiment.
[fig.5]Fig. 5 is a sequence diagram showing a third operation example of the communication
system according to the exemplary embodiment.
[fig. 6]Fig. 6 is a block diagram showing a configuration example of a MTC-IWF
according to the exemplary embodiment.
[fig.7]Fig. 7 is a block diagram showing a configuration example ofaMTC device
according to the exemplary embodiment.
[fig.8]Fig. 8 is a block diagram showing a configuration example of a network entity
according to the exemplary embodiment.
Description of Embodiments
[0020] Hereinafter, an exemplary embodiment of the present invention will be described
with reference to Figs. 1 to 8.
[0021] As shown in Fig. 1, a communication system according to this exemplary embodiment
includes a core network (3GPP network), and one or more MTC devices 10
which connect to the core network through a RAN (Radio Access Network). Note that,
in this exemplary embodiment, the definition of MTC device follows that in NPL 1
that "A MTC Device is a UE equipped for Machine Type Communication". While the
illustration is omitted, the RAN is formed by a plurality of base stations (i.e., eNBs
4
WO 2014/041806 PCT/JP2013/005398
(evolved Node Bs)).
[0022] The MTC device 10 attaches to the core network. The MTC device 10 can host one
or multiple MTC Applications. The corresponding MTC Applications in the external
network are hosted on one or multiple ASs (Application Servers).
[0023] Further, the core network includes aMTC-IWF 20. The MTC-IWF 20 serves as a
network entity relaying messages between the MTC device 10 and SCS 50 which
connects to the core network to communicate with the MTC device 10. The core
network includes, as other network entities, an HSS (Home Subscriber Server) 30, an
MME, an SGSN (Serving GPRS (General Packet Radio Service) Support Node), an
MSC (Mobile Switching Centre) and the like. In the following description, the MME,
SGSN and MSC are sometimes referred to as "MME/SGSN/MSC" and collectively
denoted by the symbol 40. Communication between the MTC device 10 and the MTCIWF
20 is conducted through the MME/SGSN/MSC 40.
[0024] Furthermore, a few assumptions are made for this exemplary embodiment as follows:
- The UE (MTC device 10) and core network (HSS 30, MME/SGSN/MSC 40) have
mutual authenticated.
- The security association is established between HSS 30, MME/SGSN/MSC 40 and
MTC-IWF 20.
[0025] This exemplary embodiment proposes to derive and allocate keys that MTC-IWF 20
and UE (MTC device 10) share with each other. The keys are for confidentiality and
integrity protection of the communication between MTC-IWF 20 and UE (MTC
device 10).
[0026] Specifically, as shown in Fig. 2, this exemplary embodiment proposes to have a key
hierarchy with root key and temporary key. The root key K_iwf is used to derive a pair
of temporary keys K_di (K_di_conf, K_di_int). K_di_conf is a confidentiality key for
encrypting and decrypting messages transferred between the MTC device 10 and the
MTC-IWF 20. K_di_int is an integrity key for protecting and checking the integrity of
messages transferred between the MTC device 10 and the MTC-IWF 20.
[0027] The use of temporary keys is because that any attack on temporary keys will not lead
to compromise of root key which is at a higher level in the hierarchy, such that the root
key can be used to re-derive new keys that in turn mitigates issues created by compromised
lower layer keys.
[0028] Further, the MTC device 10 may authorize the MTC-IWF 20 in accordance with a
result of the integrity check. Specifically, the MTC device 10 authorizes the MTC-IWF
20 as a true one when succeeding in the integrity check. In this case, it is possible to
prevent the MTC device 10 from communicating with a MTC-IWF masquerading as
the true one, even when the MTC device 10 connects to a false network. It is preferable
that these integrity check and authorization are applied to a roaming UE/MTC device.
5
WO 2014/041806 PCT/JP2013/005398
[0029] Next, operation examples of this exemplary embodiment will be described in detail.
[0030] [1]. Derivation and allocation of the root key K_iwf
K_iwf can be derived by HSS 30, MME/SGSN/MSC 40 or MTC-IWF 20. The 3
scenarios are shown in Figs. 3, 4 and 5.
[0031] Key distribution can be done in two ways as given below.
[0032] (1) Distributed
(A) Given network entity (HSS 30 or MME/SGSN/MSC 40) sends the key to MTCIWF,
in case that the root key is not derived by MTC-IWF 20 itself, and
(B) UE.
[0033] Note that the key being sent to UE should be after the security is established between
MTC device 10 and network (HSS 30 and MME/SGSN/MSC 40), and it should be
protected with valid security context.
[0034] (2) Synchronized
(A) Given network entity (HSS 30 or MME/SGSN/MSC 40) sends the key to MTCIWF
20 or MTC-IWF 20 derives the root key by itself.
(B) UE derives the same key.
[0035] [2]. Temporary keys
After the root key is derived, UE (MTC device 10) and MTC-IWF 20 will derive the
pair of temporary keys that are used to protect the communication between MTC-IWF
20 and UE (MTC device 10).
[0036] Temporary key derivation at network side is done by the serving MTC-IWF 20.
When MTC-IWF 20 first time needs to communicate with a given UE, it derives a pair
or a few pair of temporary keys from the root key. UE derives the same temporary
keys in the same way that MTC-IWF 20 does. In the case where there is more than one
pair of temporary keys, MTC-IWF 20 will indicate UE which one to use for the communication.
And UE will choose the one that MTC-IWF 20 indicated.
[0037] [3]. Input parameters for key derivation
K_iwf can be derived as follows.
(1) K_iwf can be derived from CK (Cipher Key), IK (Integrity Key). In this case, it
can re-use part of the existing key hierarchy.
(2) K_iwf can be derived from Kasme (Key Access Security Management Entity). It
can re-use part of the existing key hierarchy.
(3) K_iwf can be derived separately from the 3GPP key hierarchy.
Other values will be also used as input parameters for K_iwf derivation.
[0038] K_di can be derived using K_iwf and other input parameters.
[0039] [4]. Key storage
Both root key (K_iwf) and temporary keys (K_di_conf, K_di_int) can be stored in
USIM (Universal Subscriber Identity Module) or non- volatile memory of ME (Mobile
6
WO 2014/041806 PCT/JP2013/005398
Equipment).
[0040] The 3 scenarios of root key derivation are subsequently described with reference to
Figs. 3, 4 and 5.
[0041] Fig. 3 shows the key derivation and allocation, when HSS 30 derives the root key.
[0042] (S 11) HSS 30 derives the root key K_iwf with CK, IK as the input keys.
(512) HSS 30 sends the root key K_iwf to MTC-IWF 20.
(513) MTC device 10 derives the same root key K_iwf (S13a) or alternatively, HSS
30 sends the root key K_iwf to MTC device 10 (SI 3b), this should be after the NAS
and/or AS security is established.
(514) MTC-IWF 20 derives the temporary keys from K_iwf.
(515) MTC device 10 derives the same temporary keys from the K_iwf it has, in the
same way that MTC-IWF 20 does.
(516) MTC-IWF 20 indicates MTC device 10 which pair of temporary keys it should
use, if more than one pair of temporary keys are derived.
(517) Messages transferred between MTC device and MTC-IWF are protected by the
pair of temporary keys.
[0043] Fig. 4 shows the key derivation and allocation, when MME/SGSN/MSC 40 derives
the root key.
[0044] (S2 1) MME/SGSN/MSC 40 derives the root key K_iwf with Kasme as the input key.
(522) MME/SGSN/MSC 40 sends the root key K_iwf to MTC-IWF 20.
(523) MTC device 10 derives the same root key K_iwf (S23a) or alternatively,
MME/SGSN/MSC 40 sends the root key K_iwf to MTC device 10 (S23b), this should
be after the NAS and/or AS security is established.
(524) MTC-IWF 20 derives the temporary keys from K_iwf.
(525) MTC device 10 derives the same temporary keys from the K_iwf it has, in the
same way that MTC-IWF 20 does.
(526) MTC-IWF 20 indicates MTC device 10 which pair of temporary keys it should
use, if more than one pair of temporary keys are derived.
(527) Messages transferred between MTC device 10 and MTC-IWF 20 are protected
by the pair of temporary keys.
[0045] Fig. 5 shows the key derivation and allocation, when MTC-IWF 20 derives the root
key.
[0046] (S3 1) MME/SGSN/MSC 40 or HSS 30 sends the material for root key K_iwf
derivation to MTC-IWF 20 (S3la), or alternatively, MTC device 10 and MTC-IWF 20
have a common value for K_iwf derivation (S3 lb).
(532) MTC-IWF 20 derives the root key K_iwf.
(533) MTC device 10 derives the same root key K_iwf.
(534) MTC-IWF 20 derives the temporary keys from K_iwf.
7
WO 2014/041806 PCT/JP2013/005398
(535) MTC device 10 derives the same temporary keys from the K_iwf it has, in the
same way that MTC-IWF 20 does.
(536) MTC-IWF 20 indicates MTC device 10 which pair of temporary keys it should
use, if more than one pair of temporary keys are derived.
(537) Messages transferred between MTC device 10 and MTC-IWF 20 are protected
by the pair of temporary keys.
[0047] Next, configuration examples of the MTC-IWF 20, the MTC device 10 and the
network entity (HSS 30 or MME/SGSN/MSC 40) according to this exemplary embodiment
will be subsequently described with reference to Figs. 6 to 8.
[0048] As shown in Fig. 6, the MTC-IWF 20 includes at least a communication unit 21, a
sharing unit 22, and a derivation unit 23. The communication unit 2 1 conducts communication
with the MTC device 10. The sharing unit 22 securely shares the root key
K_iwf with the MTC device 10 in a manner shown any one of Figs. 3 to 5. The
derivation unit 23 derives the temporary keys K_di by use of the root key K_iwf for
protecting the communication. As a result, the temporary keys K_di can be also shared
between the MTC-IWF 20 and the MTC device 10. Note that these units 2 1 to 23 are
mutually connected with each other thorough a bus or the like. These units 2 1 to 2 3
can be configured by, for example, transceivers which respectively conduct communication
with the HSS 30, the MME/SGSN/MSC 40 and the SCS 50, and a controller
which controls these transceivers to execute the processes shown at Steps S12, S14,
S16 and S17 to S10 in Fig. 3, the processes shown at Steps S22, S24, S26 and S27 in
Fig. 4, the processes shown at Steps S31, S32, S34, S36 and S37 in Fig. 5, or processes
equivalent thereto.
[0049] Further, as shown in Fig. 7, the MTC device 10 includes at least a communication
unit 11, a sharing unit 12, and a derivation unit 13. It is preferable that The MTC 10
further includes an authorization unit 14. The communication unit 11 conducts communication
with the MTC-IWF 20. The sharing unit 12 securely shares the root key
K_iwf with the MTC device 10 in a manner shown any one of Figs. 3 to 5. The
derivation unit 13 derives the temporary keys K_di by use of the root key K_iwf for
protecting the communication. As a result, the temporary keys K_di can be also shared
between the MTC device 10 and the MTC-IWF 20. The authorization unit 14 performs
the integrity check by use of the integrity key K_di_int, and authorizes the MTC-IWF
20 in accordance with a result of the integrity check. Note that these units 11 to 14 are
mutually connected with each other thorough a bus or the like. These units 11 to 14
can be configured by, for example, a transceiver which wirelessly conducts communication
with the core network through the RAN, and a controller which controls this
transceiver to execute the processes shown at Steps S13 and S15 to 17 in Fig. 3, the
processes shown at Steps S23 and S25 to S27 in Fig. 4, the processes shown at Steps
8
WO 2014/041806 PCT/JP2013/005398
S31, S33 and S35 to S37 in Fig. 5, or processes equivalent thereto.
[0050] Furthermore, as shown in Fig. 8, each of the HSS 30 and the MME/SGSN/MSC 40
includes at least a derivation unit 31 and a send unit 32. The derivation unit 31 derives
the root key K_iwf. The send unit 32 sends the root key K_iwf to the MTC-IWF 20.
The send unit 32 may also send the root key K_iwf to the MTC device 10 after the
NAS and/or AS security context is established between the MTC device 10 and each of
the HSS 30 and the MME/SGSN/MSC 40. Alternatively, the send unit 32 sends
materials for the root key K_iwf derivation to the MTC-IWF 20. Note that these units
31 and 32 are mutually connected with each other thorough a bus or the like. These
units 31 and 32 can be configured by, for example, a transceiver which conducts communication
with the MTC-IWF 20, a transceiver which conducts communication with
the RAN in the case of the MME/SGSN/MSC 40, and a controller which controls these
transceivers to execute the processes shown at Steps SI 1 to S13 in Fig. 3, the processes
shown at Steps S21 to S23 in Fig. 4, the processes shown at Step S31 in Fig. 5, or
processes equivalent thereto.
[0051] Note that the present invention is not limited to the above-mentioned exemplary embodiment,
and it is obvious that various modifications can be made by those of
ordinary skill in the art based on the recitation of the claims.
[0052] The whole or part of the exemplary embodiment disclosed above can be described as,
but not limited to, the following supplementary notes.
[0053] (Supplementary note 1)
New key hierarchy is proposed for secure communication between MTC-IWF and
UE/MTC device. It includes the following.
(A) A root key which is used to derive a pair of temporary keys.
(B) A pair of temporary keys including confidentiality and integrity keys for
protecting the communication between MTC-IWF and UE/MTC device.
[0054] (Supplementary note 2)
New messages or new parameters in existing message for key management in 3GPP
MTC architecture.
[0055] (Supplementary note 3)
Secure communication between MTC-IWF and UE/MTC device is provided, on top
of the established NAS and/or AS security context.
[0056] (Supplementary note 4)
MTC-IWF authorization can be realized by UE/MTC device performing integrity
check of the message received from MTC-IWF. This also applies to a roaming UE/
MTC device.
[0057] This application is based upon and claims the benefit of priority from Japanese patent
application No. 2012-201693, filed on September 13, 2012, the disclosures of which
9
WO 2014/041806 PCT/JP2013/005398
are incorporated herein in their entirety by reference.
Reference Signs List
158] 10 MTC DEVICE
11, 2 1 COMMUNICATION UNIT
12, 22 SHARING UNIT
13, 23, 3 1 DERIVATION UNIT
14 AUTHORIZATION UNIT
20 MTC-IWF
30 HSS
32 SEND UNIT
40 MME/SGSN/MSC
WO 2014/041806
10
PCT/JP2013/005398
Claims
[Claim 1] A communication system comprising:
a MTC (Machine-Type-Communication) device; and
a MTC-IWF (MTC Inter-Working Function) that conducts communication
with the MTC device,
wherein a root key is securely shared between the MTC device and the
MTC-IWF, and
wherein the MTC device and the MTC-IWF use the root key to respectively
derive temporary keys for protecting the communication
between the MTC device and the MTC-IWF.
[Claim 2] The communication system according to Claim 1, wherein the
temporary keys include an integrity key for at least one of integrity
protection and integrity check of a message transferred between the
MTC device and the MTC-IWF.
[Claim 3] The communication system according to Claim 2, wherein the MTC
device performs at least one of integrity protection and integrity check
of the message by use of the integrity key, and performs MTC-IWF authorization
in accordance with a result of the integrity check.
[Claim 4] The communication system according to any one of Claims 1 to 3,
wherein the temporary keys include a confidentiality key for encrypting
and decrypting a message transferred between the MTC device and the
MTC-IWF.
[Claim 5] The communication system according to any one of Claims 1 to 4,
wherein the communication is conducted through a different network
entity placed within a core network to which the MTC device attached.
[Claim 6] The communication system according to any one of Claims 1 to 5,
wherein the sharing of root key is performed in such a manner that:
the MTC-IWF receives a root key derived by a different network entity
placed within a core network to which the MTC device attached; and
the MTC device derives a root key by the MTC device itself, or
receives the derived root key from the different network entity after
NAS and/or AS security context is established between the MTC
device and the different network entity.
[Claim 7] The communication system according to any one of Claims 1 to 5,
wherein the sharing of root key is performed in such a manner that:
the MTC-IWF receives materials from a different network entity placed
within a core network to which the MTC device attached, and derives a
WO 2014/041806
11
PCT/JP2013/005398
root key by use of the materials; and
the MTC device derives a root key by the MTC device itself.
[Claim 8] The communication system according to Claim 6 or 7, wherein the
different network entity comprises an HSS (Home Subscriber Server).
[Claim 9] The communication system according to Claim 6 or 7, wherein the
different network entity comprises an MME (Mobility Management
Entity), an SGSN (Serving GPRS (General Packet Radio Service)
Support Node), or an MSC (Mobile Switching Center).
[Claim 10] The communication system according to any one of Claims 1 to 5,
wherein the sharing of root key is performed in such a manner that the
MTC-IWF and the MTC device share a common value, and derive a
root key by use of the common value independently.
[Claim 11] A MTC-IWF (MTC-Interworking Function) comprising:
a communication means for conducting communication with a MTC
(Machine-Type-Communication) device;
a sharing means for securely sharing a root key with the MTC device;
and
a derivation means for deriving temporary keys, by use of the root key,
for protecting the communication between the MTC device and the
MTC-IWF.
[Claim 12] The MTC-IWF according to Claim 11, wherein the derivation means is
configured to derive, as one of the temporary keys, an integrity key for
at least one of integrity protection and integrity check of a message
received from the MTC device.
[Claim 13] The MTC-IWF according to Claim 11 or 12, wherein the derivation
means is configured to derive, as one of the temporary keys, a confidentiality
key for encrypting a message to be transmitted to the MTC
device and for decrypting a message received from the MTC device.
[Claim 14] The MTC-IWF according to any one of Claims 11 to 13, wherein the
communication means is configured to conduct the communication
through a different network entity placed within a core network to
which the MTC device attached.
[Claim 15] The MTC-IWF according to any one of Claims 11 to 14, wherein the
sharing means is configured to receive a root key derived by a different
network entity placed within a core network to which the MTC device
attached.
[Claim 16] The MTC-IWF according to any one of Claims 11 to 14, wherein the
sharing means is configured to:
WO 2014/041806
12
PCT/JP2013/005398
receive materials from a different network entity placed within a core
network to which the MTC device attached; and
derive a root key by use of the materials.
[Claim 17] The MTC-IWF according to any one of Claims 11 to 14, wherein the
sharing means is configured to:
share a common value with the MTC device; and
derive a root key by use of the common value.
[Claim 18] A MTC (Machine-Type-Communication) device comprising:
a communication means for conducting communication with a MTCIWF
(MTC Inter-Working Function);
a sharing means for securely sharing a root key with the MTC-IWF;
and
a derivation means for deriving temporary keys, by use of the root key,
for protecting the communication between the MTC device and the
MTC-IWF.
[Claim 19] The MTC device according to Claim 18, wherein the derivation means
is configured to derive, one of the temporary keys, an integrity key for
at least one of integrity protection and integrity check of a message
received from the MTC-IWF.
[Claim 20] The MTC device according to Claim 19, further comprising:
an authorization means of at least one of integrity protection and
integrity check of the message by use of the integrity key, and for authorizing
the MTC-IWF in accordance with a result of the check.
[Claim 21] The MTC device according to any one of Claims 18 to 20, wherein the
derivation means is configured to derive, one of the temporary keys, a
confidentiality key for encrypting a message to be transmitted to the
MTC-IWF and for decrypting a message received from the MTC-IWF.
[Claim 22] The MTC device according to any one of Claims 18 to 21, wherein the
communication means is configured to conduct the communication
through a different network entity placed within a core network to
which the MTC device attached.
[Claim 23] The MTC device according to any one of Claims 18 to 22, wherein the
sharing means is configured to receive a root key by a different
network entity placed within a core network to which the MTC device
attached, after NAS and/or AS security context is established between
the MTC device and the different network entity.
[Claim 24] The MTC device according to any one of Claims 18 to 22, wherein the
sharing means is configured to:
WO 2014/041806
13
PCT/JP2013/005398
share a common value with the MTC-IWF; and
derive a root key by use of the common value.
[Claim 25] A network entity placed within a core network to which a MTC
(Machine-Type-Communication) device attached, the network entity
comprising:
a derivation means for deriving a root key; and
a send means for sending the root key to a MTC-IWF (MTC Inter-
Working Function) that conducts communication with the MTC device.
[Claim 26] The network entity according to Claim 25, wherein the send means is
configured to further send the root key to the MTC device after NAS
(Non-Access Stratum) and/or AS (Access Stratum) security context is
established between the MTC device and the network entity.
[Claim 27] A network entity placed within a core network to which a MTC
(Machine-Type-Communication) device attached, the network entity
comprising:
a send means for sending, to a MTC-IWF (MTC Inter-Working
Function) that conducts communication with the MTC device,
materials for the MTC-IWF to derive a root key.
[Claim 28] The network entity according to any one of Claims 25 to 27,
comprising an HSS (Home Subscriber Server).
[Claim 29] The network entity according to any one of Claims 25 to 27,
comprising an MME (Mobility Management Entity), an SGSN
(Serving GPRS (General Packet Radio Service) Support Node), or an
MSC (Mobile Switching Center).
[Claim 30] A method of controlling operations in a MTC-IWF (MTC Inter-
Working Function), the method comprising:
conducting communication with a MTC
(Machine-Type-Communication) device;
securely sharing a root key with the MTC device; and
deriving temporary keys, by use of the root key, for protecting the communication
between the MTC device and the MTC-IWF.
[Claim 31] A method of controlling operations in a MTC
(Machine-Type-Communication) device, the method comprising:
conducting communication with a MTC-IWF (MTC Inter-Working
Function);
securely sharing a root key with the MTC-IWF; and
deriving temporary keys, by use of the root key, for protecting the communication
between the MTC device and the MTC-IWF.
14
WO 2014/041806 PCT/JP2013/005398
1144
WO 2014/041806 PCT/JP2013/005398
[Claim 32] A method of controlling operations in a network entity placed within a
core network to which a MTC (Machine-Type-Communication) device
attached, the method comprising:
deriving a root key; and
sending the root key to a MTC-IWF (MTC Inter-Working Function)
that conducts communication with the MTC device.
[Claim 33] The method according to Claim 32, further comprising:
sending the root key to the MTC device after NAS (Non-Access
Stratum) and/or AS (Access Stratum) security context is established
between the MTC device and the network entity.
[Claim 34] A method of controlling operations in a network entity placed within a
core network to which a MTC (Machine-Type-Communication) device
attached, the method comprising:
sending, to a MTC-IWF (MTC Inter-Working Function) that conducts
communication with the MTC device, materials for the MTC-IWF to
derive a root key.

Documents