WO2009105981A1 - A group traffic encryption key updating method and a system thereof - Google Patents

A group traffic encryption key updating method and a system thereof Download PDF

Info

Publication number
WO2009105981A1
WO2009105981A1 PCT/CN2009/070468 CN2009070468W WO2009105981A1 WO 2009105981 A1 WO2009105981 A1 WO 2009105981A1 CN 2009070468 W CN2009070468 W CN 2009070468W WO 2009105981 A1 WO2009105981 A1 WO 2009105981A1
Authority
WO
WIPO (PCT)
Prior art keywords
encryption key
group
multicast broadcast
broadcast service
key update
Prior art date
Application number
PCT/CN2009/070468
Other languages
French (fr)
Chinese (zh)
Inventor
徐宏亮
莫君贤
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2009105981A1 publication Critical patent/WO2009105981A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/104Grouping of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload

Abstract

The present invention provides a group traffic encryption key updating method, the network side entity transmits a MBS_MAP message which carries GTEK updating information; after receiving the MBS_MAP message, a MS obtains the GTEK updating information, and updates the GTEK of the corresponding MBS. The present invention also provides a group traffic encryption key updating system, and the system includes a network side entity and a mobile station. The group traffic encryption key updating method and system of the present invention can avoid that the GTEK updating information is transmitted for many times, and can notify all the MSs that share the same MBS at the same time; and the MBS_MAP can be transmitted in manner of SFN, which improves the reliability of the indication message.

Description

组业务加密密钥更新方法及系统 本申请要求于 2008 年 2 月 26 日提交中国专利局, 申请号为 200810008354.5 , 发明名称为 "组业务加密密钥更新方法及系统" 的 中国专利申请的优先权, 其全部内容通过引用结合在本申请中。 技术领域  Method and system for updating group business encryption key This application claims priority to Chinese patent application filed on February 26, 2008, Chinese Patent Office, application number 200810008354.5, titled "Group Service Encryption Key Update Method and System" The entire contents of which are incorporated herein by reference. Technical field
本发明涉及移动通信技术领域,特别涉及一种组业务加密密钥更 新方法及系统。 背景技术  The present invention relates to the field of mobile communication technologies, and in particular, to a group service encryption key update method and system. Background technique
WiMAX 的全名 是微波互操作全球互通 (Worldwide Interoperability for Microwave Access) , 又称为 802.16无线城 i或网 , 是一种为企业和家庭用户提供 "最后一英里" 的宽带无线连接方案, 在数据通信领域可实现高覆盖范围, 可以覆盖 25 ~ 30英里的范围。 WiMAX IEEE ( Institute of Electrical and Electronics Engineers , 美 国电气及电子工程师学会) 802.16 的系列宽频无线标准为基础, 作 为它的空口协议。 IEEE 802.16 标准系列到目前为止包括 802.16、 802.16a, 802.16c, 802.16d、 802.16e、 802.16f和 802.16g共七个标准。 其中, 802.16、 16a、 16d属于固定无线接入空中接口标准, 802.16e 属于移动宽带无线接入空中标准。 WiMAX更在 802.16e的基础上, 提出了新的增强技术 802.16m, 802.16m要与 802.16e兼容。  WiMAX's full name is Worldwide Interoperability for Microwave Access, also known as 802.16 Wireless City i or Network, which is a "last mile" broadband wireless connectivity solution for businesses and home users. The communications area offers high coverage and can cover a range of 25 to 30 miles. The WiMAX IEEE (Institute of Electrical and Electronics Engineers) is based on the 802.16 family of broadband wireless standards as its air interface protocol. The IEEE 802.16 family of standards has so far included seven standards including 802.16, 802.16a, 802.16c, 802.16d, 802.16e, 802.16f, and 802.16g. Among them, 802.16, 16a, 16d belong to the fixed wireless access air interface standard, and 802.16e belongs to the mobile broadband wireless access air standard. WiMAX is based on 802.16e and proposes a new enhancement technology, 802.16m. 802.16m is compatible with 802.16e.
下面对移动台 (Mobile Station, 以下筒称: MS ) 的空闲模式与 寻呼原理加以介绍, 由于系统的空闲模式与寻呼原理都是类似的, 因 此以 IEEE 802.16e的空闲模式与寻呼作为示例, 描述如下:  The following describes the idle mode and paging principle of the mobile station (Mobile Station, the following cylinder: MS). Since the idle mode and the paging principle of the system are similar, the idle mode and paging of IEEE 802.16e are used. As an example, the description is as follows:
当 MS处于空闲模式(Idle Mode)时, MS可以在 4艮大的一个区域 内移动, 每隔一定的周期将接收下行广播的业务消息。 MS在这个区 域内漫游过程中不必在漫游的小区向这个小区的基站 ( Base Station, 以下筒称: BS )进行注册。 空闲模式下, MS漫游到不同小区时, 不 必进行切换等正常操作流程, 从而有利于节省 MS 的功率和空口资 源。 处于空闲模式的移动设备, 会周期性的向 BS发送信号进行位置 更新的过程; 或者当其所在寻呼区域发生改变时, 也会向 BS发送信 号进行位置更新的过程。 空闲模式为 BS提供了一种筒单、 及时的方 法通知 MS是否有下行广播的业务消息发送, 及寻呼方式。 When the MS is in the idle mode (Idle Mode), the MS can move in an area of 4 inches, and receive the downlink broadcast service message every certain period. The MS does not have to register with the base station (Base Station, BS) of the cell in the roaming cell during roaming in this area. In idle mode, when the MS roams to a different cell, it does not It is necessary to perform normal operation procedures such as switching, which is beneficial to save MS power and air interface resources. The mobile device in idle mode periodically sends a signal to the BS for location update; or when the paging area is changed, it also sends a signal to the BS for location update. The idle mode provides the BS with a simple, timely method to notify the MS whether there is a downlink broadcast service message transmission, and a paging mode.
寻呼(Paging) : 当网络侧实体, 一般为 BS, 检测到处于空闲模 式的 MS有消息来到时, 就会发起寻呼 MS的过程。 在 IEEE802.16e 中,寻呼消息由 BS广播给 MS。当 MS解析得到的消息中的 MS MAC 地址的哈希值与自己本身 MAC地址的哈希值匹配时, 就认为 BS是 在寻呼自己; 然后 MS就根据消息中的动作码 (Action Code)来执行相 应的动作。  Paging: When the network side entity, generally BS, detects that the MS in the idle mode has a message, it will initiate the process of paging the MS. In IEEE 802.16e, paging messages are broadcast by the BS to the MS. When the hash value of the MS MAC address in the message parsed by the MS matches the hash value of its own MAC address, the BS is considered to be paging itself; then the MS is based on the Action Code in the message. Perform the appropriate action.
现有的 802.16e标准中, 当 MS进入空闲模式后, 会周期的在寻 呼侦听间隔 ( paging listening interval ) 醒过来并接收寻呼消息 ( MOB_PAG_ADV )。 此时, 如果 MS 还加入了某一多播广播业务 ( Multicast Broadcast Service, 以下筒称: MBS ), 即一种在下行链路 上点到多点的数据传输服务, MS还会在每一次多播广播业务指配消 息 (以下筒称: MBS_MAP Message )指定的到达时刻醒过来, 在相 应的广播连接上接收数据。 其中, MBS_MAP消息为一链式指配方式 消息,即在当前的 MBS_MAP消息中会指出下一次发送的 MBS_MAP 消息的到达时刻。 因此 MS可以一环接一环的解出 MBS_MAP消息 的到达时刻。 也就是说, 当 MS 进入空闲模式, 并且已经加入某一 MBS业务后, 会在寻呼侦听间隔和 MBS_MAP消息的到达时刻醒过 来。  In the existing 802.16e standard, when the MS enters the idle mode, it periodically wakes up at the paging listening interval and receives a paging message (MOB_PAG_ADV). At this time, if the MS also joins a multicast broadcast service (hereinafter referred to as MBS), that is, a point-to-multipoint data transmission service on the downlink, the MS will also be more than once. The broadcast service assignment message (hereinafter referred to as MBS_MAP Message) wakes up at the arrival time specified and receives data on the corresponding broadcast connection. The MBS_MAP message is a chained assignment message, that is, the arrival time of the next transmitted MBS_MAP message is indicated in the current MBS_MAP message. Therefore, the MS can solve the arrival time of the MBS_MAP message one by one. That is to say, when the MS enters the idle mode and has joined a certain MBS service, it wakes up at the paging listening interval and the arrival time of the MBS_MAP message.
MBS业务可以采用单频网( Single Frequency Network,以下筒称: SFN )方式发送, 即多个 BS可以利用相同的时频资源发送相同的数 据, 以使得 MS可以从多个基站接收信号, 达到更好的接收效果。  The MBS service can be transmitted in a Single Frequency Network (SFN) mode, that is, multiple BSs can use the same time-frequency resource to transmit the same data, so that the MS can receive signals from multiple base stations to achieve more. Good reception.
MS接收的 MBS的多播数据是进行密钥管理的, 组业务加密密 钥(Group Traffic Encryption Key , 以下筒称: GTEK)的作用是生成多 播数据的加密密钥; 组密钥加密密钥(Group Key Encryption Key, 以 下筒称: GKEK)的作用是加密 GTEK。 一个 GKEK负责多个 GTEK 的更新, 通过 MS的主要管理连接, BS单播 GKEK给 MS的; 多个 GTEK是用 GKEK加密然后广播给 MS的。 如果处于空闲模式的 MS 需要更新 GTEK, BS需要在处于空闲模式的 MS的寻呼侦听间隔, 广播 GTEK给不同的 MS。 如果享用同一个 MBS业务的不同 MS有 不同的寻呼侦听间隔, 那么 BS要广播多次更新 GTEK的通知消息。 The multicast data of the MBS received by the MS is used for key management, and the group traffic encryption key (hereinafter referred to as GTEK) is used to generate an encryption key of the multicast data; the group key encryption key (Group Key Encryption Key, to The lower cylinder is called: GKEK) is used to encrypt GTEK. A GKEK is responsible for the update of multiple GTEKs, through the MS's main management connection, BS unicast GKEK to the MS; multiple GTEKs are encrypted with GKEK and then broadcast to the MS. If the MS in idle mode needs to update the GTEK, the BS needs to broadcast the GTEK to a different MS in the paging listening interval of the MS in idle mode. If different MSs enjoying the same MBS service have different paging listening intervals, the BS broadcasts a notification message that the GTEK is updated multiple times.
综上所述, 在现有的多播业务的密钥更新流程中, 存在如下的技 术缺陷: 享用该 MBS业务的 MS的寻呼侦听间隔可能是不一样的, 因此要多 次广播发送 GTEK 更新通知消息, 即 PKMv2 Group-Key-Update-Command (GTEKx+1)消息, 造成了空口资源的浪 费, 并导致所有使用此 MBS业务的 MS的 GKEK的全部更新完成是 一个非常漫长的过程,无法做到同步更新;由于 GTEK是广播发送的, 因此, 所有不相关的 MS都要解 GTEK更新通知消息; 由于 GTEK 更新通知消息是广播发送的, 因此, 不能采用 SFN方式。 发明内容  In summary, in the key update process of the existing multicast service, the following technical defects exist: The paging listening interval of the MS enjoying the MBS service may be different, so the GTEK is to be broadcast multiple times. The update notification message, that is, the PKMv2 Group-Key-Update-Command (GTEKx+1) message, causes waste of air interface resources, and causes all the updates of the GKEK of all MSs using this MBS service to be completed. This is a very long process and cannot be completed. Synchronous update; since GTEK is broadcasted, all unrelated MSs must resolve the GTEK update notification message; since the GTEK update notification message is broadcast, the SFN mode cannot be used. Summary of the invention
本发明实施例提供一种组业务加密密钥更新方法及系统, 将 Embodiments of the present invention provide a method and system for updating a group service encryption key, which
GTEK更新信息置于 MBS_MAP消息中发送移动台进行组业务加密 密钥更新, 以同步更新 GTEK, 并可获得更好的 SFN增益效果。 The GTEK update information is placed in the MBS_MAP message to send the mobile station to perform group service encryption key update to update the GTEK synchronously and obtain a better SFN gain effect.
本发明实施例提供了一种组业务加密密钥更新方法, 包括: 网络侧实体发送携带组业务加密密钥更新信息的多播广播业务 指配消息;  An embodiment of the present invention provides a method for updating a group service encryption key, including: a network side entity sending a multicast broadcast service assignment message carrying group service encryption key update information;
移动台接收到所述多播广播业务指配消息后,得到所述组业务加 密密钥更新信息, 并更新对应的多播广播业务的组业务加密密钥。  After receiving the multicast broadcast service assignment message, the mobile station obtains the group service encryption key update information, and updates the group service encryption key of the corresponding multicast broadcast service.
本发明实施例还提供了一种组业务加密密钥更新系统, 包括: 网络侧实体,用于发送携带组业务加密密钥更新信息的多播广播 业务指配消息;  The embodiment of the present invention further provides a group service encryption key update system, including: a network side entity, configured to send a multicast broadcast service assignment message carrying group service encryption key update information;
移动台, 用于接收到所述多播广播业务指配消息后, 得到所述组 业务加密密钥更新信息,并更新对应的多播广播业务的组业务加密密 钥。 a mobile station, configured to receive the multicast broadcast service assignment message, obtain the group The service encrypts the key update information and updates the group service encryption key of the corresponding multicast broadcast service.
由以上技术方案可知,本发明实施例的组业务加密密钥更新方法 及系统, 可以克服上述技术缺陷, 并带来如下技术效果:  It can be seen from the above technical solutions that the method and system for updating a group service encryption key in the embodiment of the present invention can overcome the above technical defects and bring the following technical effects:
1)避免了由于享用该 MBS业务的多个 MS的寻呼侦听间隔的不 一样,按每个 MS的寻呼侦听间隔多次发送 GTEK更新通知消息, 并 可以避免空口资源浪费;  1) avoiding the difference in paging listening interval of multiple MSs enjoying the MBS service, sending the GTEK update notification message multiple times according to the paging listening interval of each MS, and avoiding waste of air interface resources;
2) BS在 MBS_MAP消息中,通过一次携带 GTEK更新信息就可 以通知所有享有同一 MBS业务的 MS , 即对应的 GTEK更新信息的 发送对所有的 MS来说是同步的;  2) In the MBS_MAP message, the BS can notify all MSs that have the same MBS service by carrying the GTEK update information at a time, that is, the transmission of the corresponding GTEK update information is synchronized for all MSs;
3) MBS_MAP消息属于多播发送方式, 可以使用 SFN方式进行 发送, 因此, 由它携带 GTEK更新信息会带来 SFN增益, 提高指示 消息的可靠性。 附图说明  3) The MBS_MAP message belongs to the multicast transmission mode and can be sent in the SFN mode. Therefore, carrying the GTEK update information will bring the SFN gain and improve the reliability of the indication message. DRAWINGS
图 1为本发明组业务加密密钥更新方法实施例一的流程示意图; 图 2为本发明组业务加密密钥更新方法实施例二的流程示意图; 图 3为本发明组业务加密密钥更新方法实施例三的流程示意图; 图 4为本发明组业务加密密钥更新方法实施例四的流程示意图; 图 5为本发明组业务加密密钥更新方法实施例五的流程示意图; 图 6为本发明组业务加密密钥更新系统实施例的结构示意图。 具体实施方式  1 is a schematic flowchart of Embodiment 1 of a method for updating a group service encryption key according to the present invention; FIG. 2 is a schematic flowchart of Embodiment 2 of a method for updating a service encryption key of a group according to the present invention; FIG. 4 is a schematic flowchart of Embodiment 4 of a method for updating a service encryption key of a group according to the present invention; FIG. 5 is a schematic flowchart of Embodiment 5 of a method for updating a service encryption key of a group according to the present invention; Schematic diagram of an embodiment of a group service encryption key update system. detailed description
本发明实施例的方案是通过将 GTEK更新信息置于 MBS_MAP 消息中发送移动台进行组业务加密密钥更新, 以获得更好的 SFN增 益效果。 本发明实施例中的网络侧实体包括但不限于 BS。  The solution of the embodiment of the present invention is to send the mobile station to perform group service encryption key update by placing the GTEK update information in the MBS_MAP message to obtain a better SFN gain effect. The network side entity in the embodiment of the present invention includes but is not limited to a BS.
如图 1所示,为本发明组业务加密密钥更新方法实施例一的流程 示意图, 具体步骤如下: 步骤 101、 网络侧实体发送携带组业务加密密钥更新信息的多播 广播业务指配消息; FIG. 1 is a schematic flowchart of Embodiment 1 of a method for updating a service encryption key of a group according to the present invention, and the specific steps are as follows: Step 101: The network side entity sends a multicast broadcast service assignment message that carries the group service encryption key update information.
将现有技术中, 当 MS处于空闲状态时, 在 MS的寻呼有效间隔 发送 GTEK 更新通知消息更改为: 通过在 MBS_MAP 消息中携带 GTEK更新信息, 这样可以做到同一 MBS业务下的所有 MS可以一 次性的同时收到 GTEK更新信息;  In the prior art, when the MS is in an idle state, the GTEK update notification message is sent at the paging effective interval of the MS, and the message is changed to: By carrying the GTEK update information in the MBS_MAP message, all the MSs under the same MBS service can be implemented. Receive GTEK update information at the same time;
步骤 102、 移动台接收到多播广播业务指配消息后, 得到组业务 加密密钥更新信息, 并更新对应的多播广播业务的组业务加密密钥。  Step 102: After receiving the multicast broadcast service assignment message, the mobile station obtains the group service encryption key update information, and updates the group service encryption key of the corresponding multicast broadcast service.
MS接收到 MBS_MAP消息后, 可以解密得到 GTEK, 并更新其 对应的多播广播业务的 GTEK。  After receiving the MBS_MAP message, the MS can decrypt the GTEK and update the GTEK of its corresponding multicast broadcast service.
本实施例提供的组业务加密密钥更新方法,通过将 GTEK更新信 息置于 MBS_MAP消息中发送给 MS,使得 MS可以进行 GTEK的更 浪费及更新过程漫长的缺陷, 可以做到同时对所有 MBS业务对应的 MS进行 GTEK的更新, 及获得更好的 SFN增益效果等。  The group service encryption key update method provided in this embodiment is sent to the MS by placing the GTEK update information in the MBS_MAP message, so that the MS can perform the waste of the GTEK and the long process of the update process, and can simultaneously implement all the MBS services. The corresponding MS performs GTEK update, and obtains a better SFN gain effect.
如图 2所示,为本发明组业务加密密钥更新方法实施例二的流程 示意图, 具体步骤如下:  FIG. 2 is a schematic flowchart of Embodiment 2 of a method for updating a service encryption key of a group according to the present invention, and the specific steps are as follows:
步骤 201、 网络侧实体在多播广播业务指配消息中的可扩展编码 元中携带组业务加密密钥更新信息, 并发送;  Step 201: The network side entity carries the group service encryption key update information in the scalable coding element in the multicast broadcast service assignment message, and sends the group service encryption key update information;
其中,可扩展的编码元, 即类型、长度、值编码元( TLV encoding element );  Wherein, an extensible coding element, that is, a type, a length, and a value encoding element (TLV encoding element);
步骤 202、 移动台接收到多播广播业务指配消息后, 得到可扩展 编码元中携带的组业务加密密钥更新信息,并更新对应的多播广播业 务的组业务加密密钥。  Step 202: After receiving the multicast broadcast service assignment message, the mobile station obtains the group service encryption key update information carried in the scalable code element, and updates the group service encryption key of the corresponding multicast broadcast service.
MS接收到 MBS_MAP消息后,可以从扩展的编码元(TLV encoding element )中解密得到 GTEK,并更新其对应的多播广播业务的 GTEK。 其中, 扩展的 TLV encoding element内容可以为如下表一所示: 表一 After receiving the MBS_MAP message, the MS can decrypt the GTEK from the extended TLV encoding element and update the GTEK of its corresponding multicast broadcast service. The extended TLV encoding element content can be as shown in the following Table 1: Table 1
Figure imgf000007_0001
Type 为现有标准中可以使用 根据内容而 GTEK 更新信息 (见表 而不冲突的任意值 定 二) 表一中的 Value值, 即 GTEK更新的信息内容如下表二所示:
Figure imgf000007_0001
Type is the existing standard can use the GTEK update information according to the content (see table for any value that does not conflict). The Value value in Table 1 is the information content of the GTEK update as shown in Table 2 below:
Figure imgf000008_0001
Figure imgf000008_0001
Figure imgf000008_0002
在该实施例的实现中,如果现有标准协议已经有相应的 TLV, 那 么可以利用此 TLV进行 7 载, 比如在 802.16e标准中, 已经存在类似 的 TLV: SA-TEK-Update, 此 TLV包括了上面新增 TLV的内容, 但 是标准中此 TLV不能在 MBS_MAP消息中携带, 因此需要对此 TLV 的定义进行修改, 使得它可以在 MBS_MAP 消息中携带。 通过此方 法可以非常容易的在一些标准中实现在 MBS_MAP 消息中携带 GTEK更新信息。 本实施例具体说明了将 GTEK更新信息置于 MBS_MAP消息中的可 扩展编码元中发送给 MS, 避免了现有技术进行 GTEK更新造成的空 口资源浪费及更新过程漫长的缺陷, 可以做到同时对所有 MBS业务 对应的 MS进行 GTEK的更新, 及获得更好的 SFN增益效果等。
Figure imgf000008_0002
In the implementation of this embodiment, if the existing standard protocol already has a corresponding TLV, the TLV can be used for 7 loading. For example, in the 802.16e standard, a similar TLV exists: SA-TEK-Update, and the TLV includes The content of the TLV is added above, but the standard TLV cannot be carried in the MBS_MAP message, so the definition of the TLV needs to be modified so that it can be carried in the MBS_MAP message. This method makes it very easy to implement GTEK update information in MBS_MAP messages in some standards. This embodiment specifically describes that the GTEK update information is sent to the MS in the scalable coding element in the MBS_MAP message, which avoids the shortcoming of the air interface resource waste and the update process caused by the GTEK update in the prior art, and can be simultaneously implemented. The MS corresponding to all MBS services performs GTEK update and obtains better SFN gain effects.
如图 3所示,为本发明组业务加密密钥更新方法实施例三的流程 示意图, 具体步骤如下:  As shown in FIG. 3, it is a schematic flowchart of Embodiment 3 of a method for updating a service encryption key of a group according to the present invention, and the specific steps are as follows:
步骤 301、 网络侧实体在多播广播业务指配消息中的信息元中携 带组业务加密密钥更新信息, 并发送;  Step 301: The network side entity carries the group service encryption key update information in the information element in the multicast broadcast service assignment message, and sends the information;
其中 , 信息元包括: 有多播广播业务数据信息元 ( MBS_DATA_IE ) 、 多 播广 播业 务数据 时 分信 息 元 ( MBS_DATA_Time_Diversity_IE )、 扩展多播广播业务数据信息元 ( Extended MBS_DATA _IE )三种类型的 IE之一或者某两个或者三 个都有; GTEK更新信息可以携带在 MBS_MAP消息包括的三种 IE 的一个或者多个中;  The information element includes: one of three types of IEs: a multicast broadcast service data information element (MBS_DATA_IE), a multicast broadcast service data time division information element (MBS_DATA_Time_Diversity_IE), and an extended multicast broadcast service data information element (Extended MBS_DATA_IE). Or two or three; GTEK update information can be carried in one or more of the three IEs included in the MBS_MAP message;
步骤 302、 移动台接收到多播广播业务指配消息后, 得到信息元 中携带的组业务加密密钥更新信息,并更新对应的多播广播业务的组 业务加密密钥。  Step 302: After receiving the multicast broadcast service assignment message, the mobile station obtains the group service encryption key update information carried in the information element, and updates the group service encryption key of the corresponding multicast broadcast service.
MS接收到 MBS_MAP消息后,可以从信息元中解密得到 GTEK, 并更新其对应的多播广播业务的 GTEK。 GTEK更新的信息内容如上 表二所示。  After receiving the MBS_MAP message, the MS can decrypt the GTEK from the information element and update the GTEK of its corresponding multicast broadcast service. The information content of the GTEK update is shown in Table 2 above.
本实施例具体说明了将 GTEK更新信息置于 MBS_MAP消息中 的信息元中发送给 MS , 避免了现有技术进行 GTEK更新造成的空口 资源浪费及更新过程漫长的缺陷, 可以做到同时对所有 MBS业务对 应的 MS进行 GTEK的更新, 及获得更好的 SFN增益效果等。  This embodiment specifically describes that the GTEK update information is sent to the MS in the information element in the MBS_MAP message, which avoids the shortcoming of the air interface resource waste and the update process caused by the GTEK update in the prior art, and can be implemented for all MBS at the same time. The MS corresponding to the service performs GTEK update, and obtains a better SFN gain effect.
如图 4所示,为本发明组业务加密密钥更新方法实施例四的流程 示意图, 具体步骤如下:  As shown in FIG. 4, it is a schematic flowchart of Embodiment 4 of a method for updating a service encryption key of a group according to the present invention, and the specific steps are as follows:
步骤 401、 网络侧实体在多播广播业务数据包中携带组业务加密 密钥更新信息, 并发送;  Step 401: The network side entity carries the group service encryption key update information in the multicast broadcast service data packet, and sends the information;
即在 MBS数据包的 MAC头携带 GTEK更新信息的方法有两种: 通过 MAC子头来携带 GTEK更新信息; 增加一种 MAC扩展子头来 携带 GTEK更新信息; That is, there are two methods for carrying GTEK update information in the MAC header of the MBS packet: Carrying GTEK update information through a MAC subheader; adding a MAC extension subheader to carry GTEK update information;
步骤 402、 移动台接收到多播广播业务数据包后, 得到该数据包 中携带的组业务加密密钥更新信息,并更新对应的多播广播业务的组 业务加密密钥。  Step 402: After receiving the multicast broadcast service data packet, the mobile station obtains the group service encryption key update information carried in the data packet, and updates the group service encryption key of the corresponding multicast broadcast service.
MS接收到 MBS_MAP消息后,可以从数据包中解密得到 GTEK, 并更新其对应的多播广播业务的 GTEK。 GTEK更新的信息内容如上 表二所示。  After receiving the MBS_MAP message, the MS can decrypt the GTEK from the data packet and update the GTEK of its corresponding multicast broadcast service. The information content of the GTEK update is shown in Table 2 above.
本实施例具体说明了将 GTEK更新信息置于 MBS_MAP消息指 配的数据包中发送给 MS, 避免了现有技术进行 GTEK更新造成的空 口资源浪费及更新过程漫长的缺陷, 可以做到同时对所有 MBS业务 对应的 MS进行 GTEK的更新, 及获得更好的 SFN增益效果等。  This embodiment specifically describes that the GTEK update information is sent to the MS in the data packet assigned by the MBS_MAP message, which avoids the waste of the air interface resource caused by the GTEK update in the prior art and the long process of the update process. The MS corresponding to the MBS service performs GTEK update, and obtains a better SFN gain effect.
如图 5所示,为本发明组业务加密密钥更新方法实施例五的流程 示意图, 具体步骤如下:  As shown in FIG. 5, it is a schematic flowchart of Embodiment 5 of a method for updating a service encryption key of a group according to the present invention, and the specific steps are as follows:
步骤 501、 通过移动台的主要管理连接, 网络侧实体单播组密钥 加密密钥更新信息至移动台;  Step 501: The network side entity unicast group key encrypts the key update information to the mobile station by using a primary management connection of the mobile station;
网络侧实体, 一般为 BS, 单播(即 BS分别单独对不同的 MS ) 发送某一 MBS业务对应的 GKEK更新信息给已经加入此 MBS业务 的 MS , 此 GKEK 是为后面加密的多个多播广播业务数据对应的 GTEK1至 GTEKn的 n个 GTEK传输而使用的;  The network side entity, generally a BS, unicast (that is, the BS separately sends different GSKK update information corresponding to different MBS services) to the MS that has joined the MBS service, and the GKEK is a plurality of multicasts that are encrypted later. Used for n GTEK transmissions of GTEK1 to GTEKn corresponding to broadcast service data;
步骤 502、 当组业务加密密钥更新期到达时, 发送携带组业务加 密密钥更新信息的多播广播业务指配消息;  Step 502: When the group service encryption key update period arrives, send a multicast broadcast service assignment message that carries the group service encryption key update information.
当某一多播广播业务对应的 GTEK, 例如 GTEK1的更新期到达 的时候, BS可以在对应的 MBS_MAP消息中携带 GTEK1更新通知 信息;  When the GTEK corresponding to a multicast broadcast service, for example, the update period of the GTEK1 arrives, the BS may carry the GTEK1 update notification information in the corresponding MBS_MAP message;
步骤 503、 移动台根据组密钥加密密钥更新信息中的组密钥加密 密钥, 解密组业务加密密钥更新信息中的组业务加密密钥;  Step 503: The mobile station encrypts the group key encryption key in the key update information according to the group key, and decrypts the group service encryption key in the group service encryption key update information.
利用步骤 501单播发送至 MS的 GKEK解密对应的 GTEK1更新 信息, 并得到其中的 GTEK1 ; 步骤 504、 移动台根据得到的组业务加密密钥更新对应的多播广 播业务的组业务加密密钥。 The GKEK unicasting to the MS is unicast by using step 501 to decrypt the corresponding GTEK1 update information, and obtain GTEK1 therein; Step 504: The mobile station updates the group service encryption key of the corresponding multicast broadcast service according to the obtained group service encryption key.
MS根据得到的 GTEK1更新原来多播广播业务对应的 GTEK, 完成某一多播广播业务对应的 GTEK更新。  The MS updates the GTEK corresponding to the original multicast broadcast service according to the obtained GTEK1, and completes the GTEK update corresponding to a certain multicast broadcast service.
在步骤 501中提到, GKEK是为后面加密的多个多播广播业务数 据对应的 GTEK1至 GTEKn的 n个 GTEK传输而使用的, 那么对应 于其他多播广播业务的 GTEK2至 GTEKn也是采用上述的步骤, 在 不同的对应的 MBS_MAP消息中携带 GTEK更新信息, 发送至 MS , 可以对对应的多播广播业务的 GTEK进行更新。 GTEK更新的信息内 容如上表二所示。  It is mentioned in step 501 that GKEK is used for n GTEK transmissions of GTEK1 to GTEKn corresponding to a plurality of multicast broadcast service data encrypted later, and then GTEK2 to GTEKn corresponding to other multicast broadcast services are also used. Steps: Carrying GTEK update information in different corresponding MBS_MAP messages, and sending the information to the MS, may update the GTEK of the corresponding multicast broadcast service. The information of the GTEK update is shown in Table 2 above.
在上述步骤 502中, 具体的可以在 MBS_MAP消息的可以扩展 的编码元, 即类型、 长度、 值编码元( TLV encoding element )中携带 GTEK更新信息。 标准中的 MBS_MAP消息格式如下表三所示。 In the above step 502, specifically, the GTEK update information may be carried in the extensible coding element of the MBS_MAP message, that is, the type, length, and value encoding element (TLV encoding element). The format of the MBS_MAP message in the standard is shown in Table 3 below.
Figure imgf000011_0001
Figure imgf000011_0001
Syntax语句 Size (bit) 字节 Notes 注解  Syntax Statement Size (bit) Byte Notes Notes
MBS—MAP Message format (){ 一 一  MBS—MAP Message format () { one
Management Message Type = 62 8 62  Management Message Type = 62 8 62
MBS_DIUC_Change_Count 8 一  MBS_DIUC_Change_Count 8 one
#MBS_DATA_IE 4 消息中包括 MBS DATA  #MBS_DATA_IE 4 MBS DATA included in the message
IE的个数 for (i=0; i<n; i++){ 一 n = #MBS DATA IEs The number of IEs for (i=0; i<n; i++){ one n = #MBS DATA IEs
MBS—DATA—IE variable 一 MBS—DATA—IE variable one
} 一 一  } one
#Extended_MBS_DATA_IE 4 消息中包括 Extended  #Extended_MBS_DATA_IE 4 Messages include Extended
MBS DATA IE的个数 for(i=0; i<k; i++) { 一 k = #Extended MBS  The number of MBS DATA IEs for(i=0; i<k; i++) { a k = #Extended MBS
DATA IEs  DATA IEs
Extended_MBS_DATA_IE() variable 一 } Extended_MBS_DATA_IE() variable one }
#MBS_DATA_Time_Diversity 4 消息中包括 MBS DATA #MBS_DATA_Time_Diversity 4 MBS DATA included in the message
—IE Time Diversity IE的个数 for(i=0; i<m; i++){ 一 m = #MBS DATA Time - the number of IE Time Diversity IEs for(i=0; i<m; i++){ one m = #MBS DATA Time
Diversity IEs Diversity IEs
MBS_DATA_Time_Diversity_I variable 一 MBS_DATA_Time_Diversity_I variable one
E()  E()
} 一 一  } one
if(!byte boundary)! 一 一  If(!byte boundary)!
Padding Nibble 4 一  Padding Nibble 4
} }
TLV encoding element 一 一  TLV encoding element
} 可以看出在 MBS_MAP消息中, 后面带了一个可以扩展的 TLV encoding element,这个 TLV encoding element可以用来携带 GTEK更 新信息, 新增的 TLV内容如上表一、 表二所示。 } It can be seen that in the MBS_MAP message, there is an extended TLV encoding element. This TLV encoding element can be used to carry GTEK update information. The newly added TLV content is shown in Table 1 and Table 2 above.
其中, 在本实施例的具体实现中, 如果现有标准协议已经有相应 的 TLV, 那么可以利用此 TLV进行承载, 比如在 802.16e标准中, 已 经存在类似的 TLV: SA-TEK-Update, 此 TLV包括了上面新增 TLV 的内容, 但是标准中此 TLV不能在 MBS_MAP消息携带, 因此需要 对此 TLV的定义进行修改, 使得它可以在 MBS_MAP消息中携带。 通过此方法可以非常容易的在一些标准中实现在 MBS_MAP 消息中 携带 GTEK更新信息。  In the specific implementation of the embodiment, if the existing standard protocol already has a corresponding TLV, the TLV can be used for bearer. For example, in the 802.16e standard, a similar TLV: SA-TEK-Update exists. The TLV includes the content of the above new TLV, but this TLV cannot be carried in the MBS_MAP message in the standard, so the definition of this TLV needs to be modified so that it can be carried in the MBS_MAP message. This method makes it easy to carry GTEK update information in MBS_MAP messages in some standards.
在上述步骤 502中, 具体的还可以在 MBS_MAP消息的信息元 ( information element, 以下筒称: IE ) 中携带 GTEK 更新信息。 MBS_MAP消息包括有多播广播业务数据信息元( MBS_DATA_IE )、 多播广播业务数据时分信息元( MBS_DATA _Time_Diversity_IE )、扩 展多播广播业务数据信息元( Extended MBS_DATA _IE )三种类型的 IE之一或者某两个或者三个都有,如表二所示。 GTEK更新信息可以 携带在 MBS_MAP消息包括的三种 IE的一个或者多个中。 In the above step 502, the GTEK update information may also be carried in the information element (hereinafter referred to as IE) of the MBS_MAP message. The MBS_MAP message includes a multicast broadcast service data information element (MBS_DATA_IE), a multicast broadcast service data time division information element (MBS_DATA_Time_Diversity_IE), and an extension. One of the three types of IEs, or two or three, of the Multicast Broadcast Service Data Information Element (Extended MBS_DATA _IE), as shown in Table 2. The GTEK update information may be carried in one or more of the three IEs included in the MBS_MAP message.
MBS_DATA_IE中携带 GTEK更新信息示例如下表四所示: 表四  An example of carrying GTEK update information in MBS_DATA_IE is shown in Table 4 below: Table 4
Figure imgf000013_0001
Obll: 重复编码因子为 6
Figure imgf000013_0001
Obll: The repetition coding factor is 6
Next MBS Frame Offset 8 下一次多播广播业务的帧偏移Next MBS Frame Offset 8 Frame offset of the next multicast broadcast service
Next MBS OFDMA 8 下一次多播广播业务的正交频 Symbol Offset 分多址接入符号偏移Next MBS OFDMA 8 Orthogonal Frequency of Next Multicast Broadcast Service Symbol Offset Division Multiple Access Symbol Shift
If (Next MBS MAP change 如果下一次多播广播指配是否 indication = 1){ 改变标识 If (Next MBS MAP change if the next multicast broadcast assignment is indicated = 1) { Change the logo
Next MBS No. OFDMA 2 下一次多播广播业务指配消息 Symbols 所占的正交频分多址接入符号 数目  Next MBS No. OFDMA 2 Next Multicast Broadcast Service Assignment Message Number of Orthogonal Frequency Division Multiple Access Symbols occupied by Symbols
Next MBS No. OFDMA 6 下一次多播广播业务指配消息 Subchannels 所占的子信道数目 .  Next MBS No. OFDMA 6 The number of subchannels occupied by the next multicast broadcast service assignment message Subchannels.
}  }
GTEK更新信息 Variable 更新的 GTEK信息 (见表二) GTEK update information Variable updated GTEK information (see Table 2)
Padding variable 填充 Padding variable
} 其中, 多播广播业务指配类型, 在原有标准中此处的值为 0, 本 实施例中在该 MBS_DATA_IE中增加携带 GTEK更新信息后, 可以 采用新值, 以跟原来的 MBS_DATA_IE进行区分。 当然, 可以仍然使 用原来的值。  } The multicast broadcast service assignment type, where the value is 0 in the original standard, in this embodiment, after adding the GTEK update information in the MBS_DATA_IE, a new value may be adopted to distinguish it from the original MBS_DATA_IE. Of course, you can still use the original value.
Extended MBS_DATA_IE中携带 GTEK更新信息示例如下表五 所示:  An example of carrying GTEK update information in Extended MBS_DATA_IE is shown in Table 5 below:
表五  Table 5
Figure imgf000014_0001
Figure imgf000014_0001
shift
Next MBS MAP change indication 1 下一次多播广播指配是 否改变标识 Next MBS MAP change indication 1 Next time the multicast broadcast assignment changes the identity
No. of Multicast CID 3 多播连接标识的数目No. of Multicast CID 3 Number of Multicast Connection Identifiers
For(i = 0; i < No. of Multicast CID; For(i = 0; i < No. of Multicast CID;
i++){  i++){
Multicast CID 12 多播连接标识的低 12位 Multicast CID 12 lower 12 bits of the multicast connection identifier
No. of Logical Channel ID 4 逻辑链路标识的数目No. of Logical Channel ID 4 Number of logical link identifiers
For(j = 0; j < No. of Logical Channel For(j = 0; j < No. of Logical Channel
ID; j++){  ID; j++){
Logical Channel ID 8 逻辑链路标识  Logical Channel ID 8 Logical Link Identifier
}  }
}  }
MBS DIUC 多播广播业务下行链路 间隔使用码 MBS DIUC Multicast Broadcast Service Downlink Interval Usage Code
OFDMA Symbol Offset 8 正交频分多址接入符号 偏移 OFDMA Symbol Offset 8 Orthogonal Frequency Division Multiple Access Symbol Offset
Subchannel Offset 6 子信道偏移  Subchannel Offset 6 Subchannel Offset
Boosting 3 同表 1中的 boosting Boosting 3 with boosting in Table 1
No. OFDMA Symbols 7 多播广播业务指配消息 所占的正交频分多址接 入符号数目No. OFDMA Symbols 7 Number of orthogonal frequency division multiple access symbols occupied by multicast broadcast service assignment messages
No. Subchannels 6 多播广播业务指配消息 所占的子信道数目No. Subchannels 6 Number of subchannels occupied by multicast broadcast service assignment messages
Repetition Coding Indication 2 0b00: 没有重复编码 Repetition Coding Indication 2 0b00: No repetition coding
ObOl: 重复编码因子为 2 OblO: 重复编码因子为 4 Obll: 重复编码因子为 6 Next MBS Frame Offset 8 下一次多播广播业务的 帧偏移 ObOl: The repetition coding factor is 2 OblO: The repetition coding factor is 4 Obll: The repetition coding factor is 6 Next MBS Frame Offset 8 Frame offset of the next multicast broadcast service
Next MBS OFDMA Symbol Offset 8 下一次多播广播业务的 正交频分多址接入符号 偏移  Next MBS OFDMA Symbol Offset 8 Orthogonal Frequency Division Multiple Access (OFDM) Symbol Offset for Next Multicast Broadcast Service
If (Next MBS MAP change indication 如果下一次多播广播指  If (Next MBS MAP change indication if the next multicast broadcast refers to
= 1){ 配是否改变标识 = 1){ Matching whether to change the logo
Next MBS No. OFDMA Symbols 2 下一次多播广播业务指 配消息所占的正交频分 多址接入符号数目Next MBS No. OFDMA Symbols 2 The number of orthogonal frequency division multiple access symbols occupied by the next multicast broadcast service assignment message
Next MBS No. OFDMA Subchannels 6 下一次多播广播业务指 配消息所占的子信道数 Next MBS No. OFDMA Subchannels 6 The number of subchannels occupied by the next multicast broadcast service assignment message
U .  U.
}  }
GTEK更新信息 Variable 更新的 GTEK信息(见表 二)  GTEK update information Variable updated GTEK information (see Table 2)
Padding Variable 填充  Padding Variable fill
} 同上所述, 在这里多播广播业务指配类型, 在原有标准中此处的 值为 2, 本实施例中在该 Extended MBS_DATA_IE中增加携带 GTEK 更新信息后, 可以采用新值, 以跟原来的 Extended MBS_DATA_IE 进行区分。 当然, 可以仍然使用原来的值。  As described above, the multicast broadcast service assignment type is here. In the original standard, the value here is 2. In this embodiment, after the GTEK update information is added in the Extended MBS_DATA_IE, the new value can be adopted. The distinction is made by the Extended MBS_DATA_IE. Of course, you can still use the original value.
MBS_DATA_Time_Diversity_IE中携带 GTEK更新信息示例如下 表六所示: An example of carrying GTEK update information in MBS_DATA_Time_Diversity_IE is shown in Table 6 below:
Figure imgf000016_0001
Figure imgf000016_0002
{ 元
Figure imgf000016_0001
Figure imgf000016_0002
{ yuan
MBS_MAP Type = 1 2 多播广播业务指配类型为 1 MBS_MAP Type = 1 2 Multicast broadcast service assignment type is 1
MBS Burst Frame Offset 2 多播广播业务数据突发帧偏移MBS Burst Frame Offset 2 Multicast Broadcast Service Data Burst Frame Offset
Multicast CID 12 多播连接标识的低 12位Multicast CID 12 lower 12 bits of the multicast connection identifier
OFDMA symbol offset 8 正交频分多址接入符号偏移OFDMA symbol offset 8 Orthogonal Frequency Division Multiple Access (OFDM) symbol offset
N—EP code 4 编码包比特码 (Code of encoder packet bits) N-EP code 4 Code of encoder packet bits
N—SCH code 4 分配的子信道码 (Code of allocated subchannels) N-SCH code 4 Assigned subchannels (Code of allocated subchannels)
AI—SN 1 自动重传请求标识序列号 AI-SN 1 automatic retransmission request identification serial number
(ARQ Identifier Sequence Number)  (ARQ Identifier Sequence Number)
SPID 2 子包标识 (subpacket identifier) SPID 2 subpacket identifier
ACID 自动重传请求信道标识 (ARQ ACID automatic retransmission request channel identification (ARQ
Channel Identifier) Channel Identifier)
Next MBS MAP change indication 1 下一次多播广播指配是否改变 标识 Next MBS MAP change indication 1 Is the next multicast broadcast assignment changed?
Next MBS frame offset 8 下一次多播广播业务的帧偏移 Next MBS frame offset 8 Frame offset of the next multicast broadcast service
Next MBS OFDMA Symbol offset 8 下一次多播广播业务的正交频 分多址接入符号偏移Next MBS OFDMA Symbol offset 8 Orthogonal Frequency Division Multiple Access Symbol Shift for Next Multicast Broadcast Service
If (Next MBS MAP change 如果下一次多播广播指配是否 indication =1) { 改变标识 If (Next MBS MAP change if the next multicast broadcast assignment is indication = 1) { Change the logo
Next MBS No. OFDMA symbols 下一次多播广播业务指配消息 所占的正交频分多址接入符号 数目  Next MBS No. OFDMA symbols The number of orthogonal frequency division multiple access symbols occupied by the next multicast broadcast service assignment message
Next MBS No. OFDMA 下一次多播广播业务指配消息 subchannels 所占的子信道数目 .  Next MBS No. OFDMA The number of subchannels occupied by the next multicast broadcast service assignment message subchannels.
} GTEK更新信息 Variable 更新的 GTEK信息 (见表二)} GTEK update information Variable updated GTEK information (see Table 2)
Padding Variable 填充 Padding Variable fill
} 同上所述, 在这里多播广播业务指配类型, 在原有标准中此处的 值为 1 , 本实施例中在该 MBS_DATA_Time_Diversity_IE中增加携带 GTEK 更新信 息 后 , 可 以 采用 新值 , 以 跟原 来 的 MBS_DATA_Time_Diversity_IE进行区分。 当然, 可以仍然使用原来 的值。  As described above, the multicast broadcast service assignment type is here. In the original standard, the value here is 1. In this embodiment, after adding the GTEK update information in the MBS_DATA_Time_Diversity_IE, the new value may be adopted to follow the original value. The distinction is made by MBS_DATA_Time_Diversity_IE. Of course, you can still use the original value.
在上述步骤 502中, 具体的还可以在 MBS_MAP消息指配的数 据包中携带 GTEK更新信息。  In the above step 502, specifically, the GTEK update information may be carried in the data packet assigned by the MBS_MAP message.
通过 MS的主要管理连接, 由网络侧实体发送 GKEK来更新 MS 的某个多播业务的 GKEK; 当某个 GTEK的更新期到达的时候, BS 可以在对应的 MBS数据包中携带 GTEK更新信息; MS收到更新的 GTEK之后就更新相应的 GTEK; 当下一个 GTEK的更新期到达的时 候, BS可以在对应的另一个 MBS数据包中携带 GTEK更新信息; MS收到 GTEK更新信息之后就更新相应的 GTEK。  The GKEK is sent by the network side entity to update the GKEK of a certain multicast service of the MS through the primary management connection of the MS; when the update period of a GTEK arrives, the BS may carry the GTEK update information in the corresponding MBS data packet; After receiving the updated GTEK, the MS updates the corresponding GTEK; when the next GTEK update period arrives, the BS may carry the GTEK update information in the corresponding another MBS data packet; after receiving the GTEK update information, the MS updates the corresponding GTEK.
下面给出在 MBS数据包中携带 GTEK信息的方法。 在 MBS数 据包的 MAC头携带 GTEK更新信息的方法有两种: 通过 MAC子头 来携带 GTEK更新信息;增加一种 MAC扩展子头来携带 GTEK更新 信息。本实施例中所述的信息格式及内容均基于 IEEE 802.16e, MAC 子头不能进行扩展。 所以这里只是给出通过 MAC 扩展子头来携带 GTEK的方法。但并不限于如果 IEEE 802.16m或是其他标准的 MAC 子头可以扩展的话就可以用 MAC子头来携带 GTEK。  The method of carrying GTEK information in an MBS packet is given below. There are two ways to carry GTEK update information in the MAC header of the MBS packet: Carry the GTEK update information through the MAC subheader; add a MAC extension subheader to carry the GTEK update information. The information format and content described in this embodiment are all based on IEEE 802.16e, and the MAC subheader cannot be extended. So here is just a way to carry GTEK through the MAC extension subheader. However, it is not limited to use the MAC subheader to carry GTEK if the IEEE 802.16m or other standard MAC subheaders can be extended.
新增一种 MAC扩展子头用来携带 GTEK更新信息,下面给出携带 上述信息的扩展子头的具体形式, 如表七所示。  A new MAC extension subheader is added to carry the GTEK update information. The specific form of the extended subheader carrying the above information is shown below, as shown in Table 7.
表七  Table 7
Syntax Size(bits) Notes Key Update Extended - 组密钥加密密钥更新扩展子头 Subheader(){ Syntax Size(bits) Notes Key Update Extended - Group Key Encryption Key Update Extension Subheader Subheader(){
Extended Subheader Type=5 7 扩展子头的类型值为 5 Extended Subheader Type=5 7 The extended subheader has a type value of 5
GTEK更新信息 Variable 更新的 GTEK信息 (见表二)GTEK update information Variable updated GTEK information (see Table 2)
} 其中, 扩展子头的类型值并不一定就是 5 , 只要与现有标准不沖 突即可。 如上表所示, 当 MS解析到 MAC扩展子头的 GTEK时, 就 知道其对应的 MBS业务对应的 GTEK需要更新。 } where the type value of the extended subheader is not necessarily 5, as long as it does not conflict with the existing standard. As shown in the above table, when the MS resolves to the GTEK of the MAC extension subheader, it knows that the GTEK corresponding to its corresponding MBS service needs to be updated.
本实施例中所述的信息格式及内容均基于 IEEE 802.16e,但不限 于 IEEE 802.16e,并且在将来还可能会用在兼容 IEEE 802.16e的 IEEE 802.16m上。  The information format and content described in this embodiment are based on IEEE 802.16e, but are not limited to IEEE 802.16e, and may be used in IEEE 802.16e compatible IEEE 802.16m in the future.
本实施例提供的组业务加密密钥更新方法, 通过单播 GKEK更 新信息至 MS , 并当 GTEK更新期到达时, 发送携带 GTEK更新信息 的 MBS_MAP消息; MS再解密得到 GTEK并更新对应多播广播业务 的 GTEK, 可以实现同时对所有 MBS业务对应的 MS进行 GTEK的 更新, 节省空口资源, 及获得更好的 SFN增益效果等。  The group service encryption key update method provided by this embodiment updates the information to the MS by unicast GKEK, and sends an MBS_MAP message carrying the GTEK update information when the GTEK update period arrives; the MS decrypts the GTEK and updates the corresponding multicast broadcast. The GTEK of the service can implement GTEK update for all MSs corresponding to all MBS services at the same time, save air interface resources, and obtain better SFN gain effects.
如图 6所示,为本发明组业务加密密钥更新系统实施例的结构示 意图, 该组业务加密密钥更新系统包括:  As shown in FIG. 6 , it is a structural schematic diagram of an embodiment of a group service encryption key update system according to the present invention. The group service encryption key update system includes:
网络侧实体 1 , 用于发送携带组业务加密密钥更新信息的多播广 播业务指配消息。  The network side entity 1 is configured to send a multicast broadcast service assignment message carrying the group service encryption key update information.
移动台 2, 用于接收到多播广播业务指配消息后, 得到组业务加 密密钥更新信息, 并更新对应的多播广播业务的组业务加密密钥。  The mobile station 2, after receiving the multicast broadcast service assignment message, obtains the group service encryption key update information, and updates the group service encryption key of the corresponding multicast broadcast service.
所述网络侧实体 1具体还包括有单播模块 11 ,用于通过移动台 2 的主要管理连接, 由单播模块 11单播组密钥加密密钥更新通知消息 至移动台 2。  The network side entity 1 further includes a unicast module 11 for unicasting the group key encryption key update notification message to the mobile station 2 through the primary management connection of the mobile station 2.
所述移动台 2具体包括有解密模块 21 , 用于根据组密钥加密密 钥更新信息中的组密钥加密密钥,解密组业务加密密钥更新信息中的 组业务加密密钥; 更新模块 22, 用于根据得到的组业务加密密钥更 新对应的多播广播业务的组业务加密密钥。 The mobile station 2 specifically includes a decryption module 21, configured to encrypt a group key encryption key in the key update information according to the group key, and decrypt the group service encryption key update information. a group service encryption key; an update module 22, configured to update a group service encryption key of the corresponding multicast broadcast service according to the obtained group service encryption key.
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解 到本发明可以通过硬件实现,也可以可借助软件加必要的通用硬件平 台的方式来实现基于这样的理解,本发明的技术方案可以以软件产品 的形式体现出来, 该软件产品可以存储在一个非易失性存储介质(可 以是 CD-ROM, U盘, 移动硬盘等) 中, 包括若干指令用以使得一 台计算机设备(可以是个人计算机, 服务器, 或者网络设备等)执行 本发明各个实施例所述的方法。  Through the description of the above embodiments, those skilled in the art can clearly understand that the present invention can be implemented by hardware, or can be implemented by means of software plus necessary general hardware platform, and the technical solution of the present invention. It can be embodied in the form of a software product that can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.), including a number of instructions for making a computer device (may It is a personal computer, a server, or a network device, etc.) that performs the methods described in various embodiments of the present invention.
总之, 以上所述仅为本发明的较佳实施例而已, 并非用于限定本 发明的保护范围。 凡在本发明的精神和原则之内, 所作的任何修改、 等同替换、 改进等, 均应包含在本发明的保护范围之内。  In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the scope of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and scope of the present invention are intended to be included within the scope of the present invention.

Claims

权利要求 Rights request
1、 一种组业务加密密钥更新方法, 其特征在于, 包括: 网络侧实体发送携带组业务加密密钥更新信息的多播广播业务 指配消息; A method for updating a group service encryption key, comprising: a network side entity transmitting a multicast broadcast service assignment message carrying a group service encryption key update information;
移动台接收到所述多播广播业务指配消息后,得到所述组业务加 密密钥更新信息, 并更新对应的多播广播业务的组业务加密密钥。  After receiving the multicast broadcast service assignment message, the mobile station obtains the group service encryption key update information, and updates the group service encryption key of the corresponding multicast broadcast service.
2、 根据权利要求 1所述的组业务加密密钥更新方法, 其特征在 于,在所述发送携带所述组业务加密密钥更新信息的多播广播业务指 配消息之前包括: 通过所述移动台的主要管理连接, 所述网络侧实体 单播组密钥加密密钥更新信息至所述移动台。  2. The group service encryption key update method according to claim 1, wherein before the transmitting the multicast broadcast service assignment message carrying the group service encryption key update information, the method comprises: The primary management connection of the station, the network side entity unicast group key encryption key update information to the mobile station.
3、 根据权利要求 2所述的组业务加密密钥更新方法, 其特征在 于, 所述移动台接收到所述多播广播业务指配消息后, 得到所述组业 务加密密钥更新信息,并更新对应的多播广播业务的组业务加密密钥 具体为:  The group service encryption key update method according to claim 2, wherein the mobile station obtains the group service encryption key update information after receiving the multicast broadcast service assignment message, and The group service encryption key for updating the corresponding multicast broadcast service is specifically:
所述移动台根据所述组密钥加密密钥更新信息中的组密钥加密 密钥, 解密所述组业务加密密钥更新信息中的组业务加密密钥; 所述移动台根据得到的组业务加密密钥更新对应的多播广播业 务的组业务加密密钥。  The mobile station decrypts the group service encryption key in the group service encryption key update information according to the group key encryption key in the group key encryption key update information; the mobile station according to the obtained group The service encryption key updates the group service encryption key of the corresponding multicast broadcast service.
4、 根据权利要求 1-3任一项所述的组业务加密密钥更新方法, 其特征在于,所述发送携带所述组业务加密密钥更新信息的多播广播 业务指配消息具体为:  The group service encryption key update method according to any one of claims 1 to 3, wherein the multicast broadcast service assignment message carrying the group service encryption key update information is specifically:
在所述多播广播业务指配消息中的可扩展编码元中携带所述组 业务加密密钥更新信息, 并发送。  And transmitting the group service encryption key update information in the scalable coding element in the multicast broadcast service assignment message.
5、 根据权利要求 1-3任一项所述的组业务加密密钥更新方法, 其特征在于,所述发送携带所述组业务加密密钥更新信息的多播广播 业务指配消息具体为:在所述多播广播业务指配消息中的信息元中携 带所述组业务加密密钥更新信息, 并发送。  The group service encryption key update method according to any one of claims 1 to 3, wherein the multicast broadcast service assignment message carrying the group service encryption key update information is specifically: And carrying the group service encryption key update information in the information element in the multicast broadcast service assignment message, and sending the information.
6、 根据权利要求 5所述的组业务加密密钥更新方法, 其特征在 于,所述在所述多播广播业务指配消息中的信息元中携带所述组业务 加密密钥更新信息, 并发送具体包括: 6. The group service encryption key update method according to claim 5, characterized in that And the carrying the group service encryption key update information in the information element in the multicast broadcast service assignment message, and the sending specifically includes:
在所述多播广播业务指配消息中的多播广播业务数据信息元中 携带所述组业务加密密钥更新信息, 并发送; 或  Transmitting and sending the group service encryption key update information in the multicast broadcast service data information element in the multicast broadcast service assignment message; or
在所述多播广播业务指配消息中的多播广播业务数据时分信息 元中携带所述组业务加密密钥更新信息, 并发送; 或  And transmitting the group service encryption key update information in the multicast broadcast service data time division information element in the multicast broadcast service assignment message, and sending; or
在所述多播广播业务指配消息中的扩展多播广播业务数据信息 元中携带所述组业务加密密钥更新信息, 并发送。  And transmitting the group service encryption key update information in the extended multicast broadcast service data information element in the multicast broadcast service assignment message.
7、 根据权利要求 1-3任一项所述的组业务加密密钥更新方法, 其特征在于,所述发送携带所述组业务加密密钥更新信息的多播广播 业务指配消息具体为:在所述多播广播业务数据包中携带所述组业务 加密密钥更新信息, 并发送。  The group service encryption key update method according to any one of claims 1 to 3, wherein the multicast broadcast service assignment message carrying the group service encryption key update information is specifically: The group service encryption key update information is carried in the multicast broadcast service data packet, and is sent.
8、 根据权利要求 7所述的组业务加密密钥更新方法, 其特征在 于,所述在所述多播广播业务指配消息中的多播广播业务数据包中携 带所述组业务加密密钥更新信息, 并发送具体包括:  The group service encryption key update method according to claim 7, wherein the group service encryption key is carried in the multicast broadcast service data packet in the multicast broadcast service assignment message. Update the information, and send the specifics including:
在所述多播广播业务指配消息中的多播广播业务数据包的媒体 接入控制子头中携带对应的所述组业务加密密钥更新信息, 并发送; 或  Transmitting and transmitting the corresponding group service encryption key update information in a media access control sub-head of the multicast broadcast service data packet in the multicast broadcast service assignment message; or
在所述多播广播业务指配消息中的多播广播业务数据包增加的 媒体访问控制扩展子头中携带对应的所述组业务加密密钥更新信息, 并发送。  The media access control extension subheader added to the multicast broadcast service data packet in the multicast broadcast service assignment message carries the corresponding group service encryption key update information, and is sent.
9、 一种组业务加密密钥更新系统, 其特征在于, 包括: 网络侧实体,用于发送携带组业务加密密钥更新信息的多播广播 业务指配消息;  A group service encryption key update system, comprising: a network side entity, configured to send a multicast broadcast service assignment message carrying a group service encryption key update information;
移动台, 用于接收到所述多播广播业务指配消息后, 得到所述组 业务加密密钥更新信息,并更新对应的多播广播业务的组业务加密密 钥。  The mobile station, after receiving the multicast broadcast service assignment message, obtains the group service encryption key update information, and updates the group service encryption key of the corresponding multicast broadcast service.
10、 根据权利要求 9所述的组业务加密密钥更新系统, 其特征在 于, 所述移动台包括: 解密模块,用于根据所述组密钥加密密钥更新信息中的组密钥加 密密钥, 解密所述组业务加密密钥更新信息中的组业务加密密钥; 更新模块,用于根据得到的组业务加密密钥更新对应的多播广播 业务的组业务加密密钥。 The group service encryption key update system according to claim 9, wherein the mobile station comprises: a decryption module, configured to decrypt a group service encryption key in the group service encryption key update information according to the group key encryption key in the group key encryption key update information; and an update module, configured to obtain The group service encryption key updates the group service encryption key corresponding to the multicast broadcast service.
11、 根据权利要求 9所述的组业务加密密钥更新系统, 其特征在 于, 所述网络侧实体还包括: 单播模块, 用于通过所述移动台的主要 管理连接,所述单播模块单播组密钥加密密钥更新通知消息至所述移 动台。  The group service encryption key update system according to claim 9, wherein the network side entity further comprises: a unicast module, configured to connect, by the mobile station, a primary management connection, the unicast module The unicast group key encrypts the key update notification message to the mobile station.
PCT/CN2009/070468 2008-02-26 2009-02-19 A group traffic encryption key updating method and a system thereof WO2009105981A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN 200810008354 CN101521656B (en) 2008-02-26 2008-02-26 Method and system for updating cryptographic-key used for encrypting group service
CN200810008354.5 2008-02-26

Publications (1)

Publication Number Publication Date
WO2009105981A1 true WO2009105981A1 (en) 2009-09-03

Family

ID=41015525

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/070468 WO2009105981A1 (en) 2008-02-26 2009-02-19 A group traffic encryption key updating method and a system thereof

Country Status (2)

Country Link
CN (1) CN101521656B (en)
WO (1) WO2009105981A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10326803B1 (en) 2014-07-30 2019-06-18 The University Of Tulsa System, method and apparatus for network security monitoring, information sharing, and collective intelligence

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101715188B (en) * 2010-01-14 2015-11-25 中兴通讯股份有限公司 A kind of update method of air interface key and system
US11323979B2 (en) * 2016-08-09 2022-05-03 Nokia Technologies Oy Broadcasting or multicasting to user equipment that use extended idle mode discontinuous reception

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1450751A (en) * 2002-04-09 2003-10-22 华为技术有限公司 Method for distributing key of multi-casting business
CN1510940A (en) * 2002-11-06 2004-07-07 ���ǵ�����ʽ���� Method for transmitting and receiving controlling information in mobile communication system
CN1863047A (en) * 2005-05-11 2006-11-15 中兴通讯股份有限公司 Group communication encryption key managing method of multicast service
WO2006132512A1 (en) * 2005-06-10 2006-12-14 Samsung Electronics Co., Ltd. Method for managing group traffic encryption key in wireless portable internet system

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101102552B (en) * 2007-08-16 2012-12-19 中兴通讯股份有限公司 Update method and system for service secret key

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1450751A (en) * 2002-04-09 2003-10-22 华为技术有限公司 Method for distributing key of multi-casting business
CN1510940A (en) * 2002-11-06 2004-07-07 ���ǵ�����ʽ���� Method for transmitting and receiving controlling information in mobile communication system
CN1863047A (en) * 2005-05-11 2006-11-15 中兴通讯股份有限公司 Group communication encryption key managing method of multicast service
WO2006132512A1 (en) * 2005-06-10 2006-12-14 Samsung Electronics Co., Ltd. Method for managing group traffic encryption key in wireless portable internet system

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10326803B1 (en) 2014-07-30 2019-06-18 The University Of Tulsa System, method and apparatus for network security monitoring, information sharing, and collective intelligence

Also Published As

Publication number Publication date
CN101521656A (en) 2009-09-02
CN101521656B (en) 2012-12-19

Similar Documents

Publication Publication Date Title
JP4559486B2 (en) Method, system and apparatus for realizing resource indication of multicast broadcast service
US7697465B2 (en) Method, system and apparatus for receiving multicast and broadcast service
TWI411327B (en) Method of handling mobility in multimedia broadcast multicast service single frequency network in a wireless communication system and related communication device
TW202015434A (en) Transmission with indication of geographic area
US20100103854A1 (en) Method for receiving system information in multimedia broadcast/multicast service
WO2006047941A1 (en) Method for providing modulation and encoding mode used in multicast service macro-diversity
WO2008113262A1 (en) Scheduling method directed to mbms, scheduling device and base station including scheduling device
WO2011018037A1 (en) Method, apparatus and system for configuring multimedia broadcast multicast service (mbms) control information
WO2010121524A1 (en) Method, base station and user equipment for transmitting and acquiring control information in broadcast multicast system
WO2015114905A1 (en) Apparatus
WO2009052733A1 (en) User equipment paging method and device
WO2011011956A1 (en) Method, system and network side device for transmitting control information of multimedia broadcast multicast service
WO2014067144A1 (en) Trunking paging method, base station and user equipment
WO2011038644A1 (en) Method and system for transmitting subframe identifier information
WO2008043298A1 (en) Method and base station for terminal moving in multicast broadcast system
WO2021134298A1 (en) Resource indication method and device, and communication apparatus
WO2011147246A1 (en) Method and system for uplink resources allocation and feedback of multimedia broadcast multicast
WO2013131438A1 (en) Cluster transmission notification and processing method and device
WO2010118659A1 (en) Method and device for carrying and receiving control information of multimedia broadcast multicast service control channel (mcch) and mcch update indication information
WO2009009986A1 (en) Method of multicast/broadcast service load statistic and related device
WO2014019228A1 (en) Information transmission method, terminal, and base station
WO2008049369A1 (en) A method for sending multicast broadcast service on downlink, and the system and basestation thereof
WO2011035681A1 (en) Method and apparatus for configuring subframes for positioning service
WO2011038668A1 (en) Method and device for processing subframe
WO2008046355A1 (en) Method for receiving multicast broadcast service, system, base station and management equipment thereof

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09714391

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 4662/CHENP/2010

Country of ref document: IN

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09714391

Country of ref document: EP

Kind code of ref document: A1