WO2012137643A1 - 移動通信方法及び移動管理ノード - Google Patents

移動通信方法及び移動管理ノード Download PDF

Info

Publication number
WO2012137643A1
WO2012137643A1 PCT/JP2012/058134 JP2012058134W WO2012137643A1 WO 2012137643 A1 WO2012137643 A1 WO 2012137643A1 JP 2012058134 W JP2012058134 W JP 2012058134W WO 2012137643 A1 WO2012137643 A1 WO 2012137643A1
Authority
WO
WIPO (PCT)
Prior art keywords
relay node
node
attach process
subscriber
identification module
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2012/058134
Other languages
English (en)
French (fr)
Inventor
高橋 秀明
康史 森岡
アルフ ツーゲンマイヤー
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
NTT Docomo Inc
Original Assignee
NTT Docomo Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority to EP12768325.8A priority Critical patent/EP2696616B1/en
Priority to KR1020137028839A priority patent/KR20130137037A/ko
Priority to MX2013011315A priority patent/MX2013011315A/es
Priority to RU2013146040/07A priority patent/RU2573418C2/ru
Priority to KR20147029659A priority patent/KR20140140596A/ko
Priority to CN201280017310.3A priority patent/CN103460743B/zh
Application filed by NTT Docomo Inc filed Critical NTT Docomo Inc
Priority to AU2012239436A priority patent/AU2012239436B2/en
Priority to US14/009,169 priority patent/US9002324B2/en
Priority to ES12768325.8T priority patent/ES2620412T3/es
Publication of WO2012137643A1 publication Critical patent/WO2012137643A1/ja
Anticipated expiration legal-status Critical
Priority to ZA2013/07833A priority patent/ZA201307833B/en
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • H04W12/0431Key distribution or pre-distribution; Key agreement
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W60/00Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0853Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0838Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • H04W12/0433Key management protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/062Pre-authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/17Selecting a data network PoA [Point of Attachment]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/18Selecting a network or a communication service
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/04Large scale networks; Deep hierarchical networks
    • H04W84/042Public Land Mobile systems, e.g. cellular systems
    • H04W84/047Public Land Mobile systems, e.g. cellular systems using dedicated repeater stations
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0838Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
    • H04L9/0841Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols
    • H04L9/0844Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols with user authentication or key authentication, e.g. ElGamal, MTI, MQV-Menezes-Qu-Vanstone protocol or Diffie-Hellman protocols using implicitly-certified keys

Definitions

  • the present invention relates to a mobile communication method and a mobility management node.
  • a relay node RN (Relay Node) that can be connected to the radio base station DeNB (Donor eNB) via the Un interface can be used.
  • the attach process of the relay node RN is defined to perform the attach process (Phase-2) as the relay node RN after performing the attach process (Phase-1) similar to that of the mobile station UE (non-patent document). References 1 and 2).
  • USB-RN Universal Subscriber Identity Module-RN, subscriber identification module for relay node
  • the relay node RN uses the USIM-RN. Activate and restore (or reconfigure) the secure channel with such USIM-RN.
  • the USIM-RN can only be accessed through a secure channel.
  • the relay node RN invalidates “EPS security context” in the USIM-RN.
  • step S2002 the relay node RN transmits “Attach Request (RN) (attach request signal)” requesting the attach process as the relay node RN to the radio base station DeNB.
  • the relay node RN transmits “Attach Request” including IMSI (International Mobile Subscriber Identity) or GUTI (Global Unique Temporary Identifier) related to USIM-RN.
  • IMSI International Mobile Subscriber Identity
  • GUTI Global Unique Temporary Identifier
  • step S2003 the radio base station DeNB transmits “(S1) Initial UE message (initial signal)” to the mobility management node MME (Mobility Management Entity).
  • the mobility management node MME makes an “EPS-AKA (Evolved Packet System-Authentication and Key Agreement, authentication) between the relay node RN and the USIM-RN in step S2004.
  • EPS-AKA Evolved Packet System-Authentication and Key Agreement, authentication
  • NAS Non Access Stratum
  • the relay node RN uses only the key received from the USIM-RN via the secure channel.
  • the mobility management node MME can use the USIM-RN for the attach process as the relay node RN based on the subscriber data (subscription data) acquired from the subscriber management server HSS (Home Subscriber Server). It is determined whether or not.
  • step S2007 the mobility management node MME transmits “(S1) Initial Context Setup Request” including the determination result to the radio base station DeNB.
  • the radio base station DeNB sets AS (Access Stratum) security in step S2009, and in step S2010, Set AS security for relay node RN for S1 / X2 DRB (Data Radio Bearer).
  • AS Access Stratum
  • the radio base station DeNB rejects the attach process of the relay node RN.
  • the present invention has been made in view of the above-described problems, and provides a mobile communication method and a mobility management node that can avoid useless use of resources in attach processing as a relay node RN. Objective.
  • a first feature of the present invention is a mobile communication method, in which a relay node in which a secure channel is established with a relay node subscriber identification module is connected to a radio base station as a relay node.
  • the mobility management node initiates an authentication and key agreement procedure between the relay node and the universal subscriber identity module, and the mobility management node
  • the subscriber identification module for relay node attaches as the relay node
  • a second feature of the present invention is a mobility management node, in a relay node attachment process in which a secure channel is established with a relay node subscriber identification module, from a radio base station as a relay node.
  • An authentication and key agreement procedure between a receiving unit configured to receive an initial signal indicating that it is an attach process and the relay node and the general-purpose subscriber identification module according to the initial signal Whether or not the relay node subscriber identification module can be used for the attach process as the relay node based on the communication unit configured to start the communication and the subscriber data acquired from the subscriber management server.
  • a determination unit configured to determine whether or not the relay node subscriber identification module is configured by the determination unit.
  • the communication unit is configured to set up NAS security with the relay node when it is determined that the network node can be used for the attach process as the relay node.
  • the communication unit is configured to terminate the authentication and key agreement procedure without success. It is a summary.
  • FIG. 1 is an overall configuration diagram of a mobile communication system according to a first embodiment of the present invention.
  • FIG. 2 is a functional block diagram of the mobility management node according to the first embodiment of the present invention.
  • FIG. 3 is a sequence diagram showing operations of the mobile communication system according to the first embodiment of the present invention.
  • FIG. 4 is a sequence diagram showing the operation of the existing mobile communication system.
  • the mobile communication system is an LTE-Advanced mobile communication system, and, as shown in FIG. 1, a subscriber management server HSS, a mobile management node MME, a radio base station DeNB, a relay node RN.
  • the USIM-RN is configured to be able to connect to the relay node RN.
  • the relay node RN is configured to activate the connected USIM-RN and establish a secure channel with the USIM-RN.
  • the mobility management node MME includes a reception unit 11, a transmission unit 12, a communication unit 13, and a determination unit 14.
  • the receiving unit 11 is configured to receive various information from the radio base station DeNB and the subscriber management server HSS.
  • the reception unit 11 is configured to receive “(S1) Initial UE message” from the radio base station DeNB, or to receive subscriber data related to the relay node RN from the subscriber management server HSS. ing.
  • the transmission unit 12 is configured to transmit various information to the radio base station DeNB.
  • the transmission unit 12 is configured to transmit “(S1) Initial Context Setup Request” to the radio base station DeNB.
  • the communication unit 13 is configured to perform “EPA-AKA” with the relay node RN and the USIM-RN and to set NAS security with the relay node RN.
  • the determination unit 14 is configured to determine whether the USIM-RN can be used for the attach process as the relay node RN based on the subscriber data acquired from the subscriber management server HSS.
  • the communication unit 13 is configured to set NAS security with the relay node. Has been.
  • the determination unit 14 determines that the USIM-RN cannot be used for the attach process as the relay node RN, the communication unit 13 ends “EPS-AKA” without success. Has been.
  • the relay node RN activates the USIM-RN and restores a secure channel with the USIM-RN ( Or reset it).
  • the relay node RN invalidates “EPS security context” in the USIM-RN.
  • step S1002 the relay node RN transmits “Attach Request (RN)” requesting the attach process as the relay node RN to the radio base station DeNB.
  • the relay node RN transmits “Attach Request” including IMSI or GUTI related to the USIM-RN.
  • step S1003 the radio base station DeNB transmits “(S1) Initial UE message” indicating that it is an attach process as the relay node RN to the mobility management node MME.
  • step S1004 the mobility management node MME starts “EPS-AKA” between the relay node RN and the USIM-RN in response to the “(S1) Initial UE message”.
  • step S1005 the mobility management node MME determines whether the USIM-RN can be used for the attach process as the relay node RN based on the subscriber data acquired from the subscriber management server HSS.
  • the mobility management node MME transmits “Release UE Context” to the radio base station DeNB in step S1006.
  • NAS security is set with the relay node RN.
  • the relay node RN uses only the key received from the USIM-RN via the secure channel.
  • step S1008 the mobility management node MME transmits “(S1) Initial Context Setup Request” to the radio base station DeNB.
  • the “(S1) Initial Context Setup Request” does not include the determination result in step S1005.
  • the radio base station DeNB sets AS (Access Stratum) security in step S1009, and sets AS security for the relay node RN for S1 / X2 DRB in step S1010.
  • AS Access Stratum
  • the mobility management node MME causes “EPS-AKA” to fail (that is, terminate without success).
  • the attach process as the relay node RN when USIM-RN cannot be used in the attach process as the relay node RN, NAS security is set between the mobility management node MME and the relay node RN. Therefore, the attach process as the relay node RN fails, so that useless resources, for example, useless transmission of “(S1) Initial Context Setup Request” can be avoided.
  • a first feature of the present embodiment is a mobile communication method, in which a relay node RN in which a secure channel is established with USIM-RN (relay node subscriber identification module) is a radio base station DeNB.
  • a relay node RN in which a secure channel is established with USIM-RN (relay node subscriber identification module) is a radio base station DeNB.
  • the radio base station DeNB performs mobility management according to “Attach Request (RN)”.
  • EPA- between the relay node RN and the USIM-RN.
  • KA Authentication and Key Agreement Procedure
  • USIM-RN uses for the attach process as relay node RN based on the subscriber data acquired from the subscriber management server HSS by the mobility management node MME. Determining whether it can be performed, and setting the NAS security between the mobility management node MME and the relay node RN when it is determined that the USIM-RN can be used for the attach process as the relay node RN And a step in which “EPS-AKA” fails when it is determined that the USIM-RN cannot be used for the attach process as the relay node RN.
  • the mobility management node MME is a relay node RN in which a secure channel is established with the USIM-RN
  • the reception unit 11 configured to receive “(S1) Initial UE message” indicating the attach process as the relay node RN from the radio base station DeNB, and “(S1) Initial UE” Based on the subscriber data acquired from the communication management unit 13 configured to start “EPS-AKA” between the relay node RN and the USIM-RN and the subscriber management server HSS according to the “message”.
  • a determination unit 14 configured to determine whether the USIM-RN can be used for the attach process as the relay node RN.
  • the determination unit 14 causes the USIM-RN to When it is determined that it can be used for the attach process as the RN, the communication unit 13 Are configured to set the NAS security between the communication unit 13 and the determination unit 14 determines that the USIM-RN cannot be used for the attach process as the relay node RN, the communication unit 13 The gist is that “EPS-AKA” is configured to end without success.
  • the operations of the mobility management node MME, the radio base station DeNB, the relay node RN, and the subscriber management server HSS described above may be implemented by hardware or may be implemented by a software module that is executed by a processor. However, it may be implemented by a combination of both.
  • the software modules include RAM (Random Access Memory), flash memory, ROM (Read Only Memory), EPROM (Erasable Programmable ROM), EEPROM (Electronically Erasable and Programmable, Removable ROM, Hard Disk, and Removable ROM).
  • RAM Random Access Memory
  • flash memory ROM (Read Only Memory)
  • EPROM Erasable Programmable ROM
  • EEPROM Electrically Erasable and Programmable, Removable ROM, Hard Disk, and Removable ROM.
  • it may be provided in a storage medium of an arbitrary format such as a CD-ROM.
  • the storage medium is connected to the processor so that the processor can read and write information from and to the storage medium. Further, such a storage medium may be integrated in the processor. Such a storage medium and processor may be provided in the ASIC. Such an ASIC may be provided in the mobility management node MME, the radio base station DeNB, the relay node RN, or the subscriber management server HSS. Further, the storage medium and the processor may be provided as a discrete component in the mobility management node MME, the radio base station DeNB, the relay node RN, or the subscriber management server HSS.
  • RN ... relay node HSS ... subscriber management server MME ... mobility management node 11 ... reception unit 12 ... transmission unit 13 ... communication unit 14 ... determination unit

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

リレーノードRNとしてのアタッチ処理において、無駄なリソースの使用を回避する。本発明に係る移動通信方法は、無線基地局DeNBが、USIM-RNとの間でセキュアなチャネルが確立されているリレーノードRNから受信した「Attach Request(RN)」に応じて、移動管理ノードMMEに対して、リレーノードRNとしてのアタッチ処理であることを示す「(S1)Initial UE message」を送信する工程と、移動管理ノードMMEが、「(S1)Initial UE message」に応じて、リレーノードRN及びUSIM-RNとの間で「EPS-AKA」を開始する工程と、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得ないと判定された場合、「EPS-AKA」が失敗する工程とを有する。

Description

移動通信方法及び移動管理ノード
 本発明は、移動通信方法及び移動管理ノードに関する。
 LTE(Long Term Evolution)-Advanced方式では、無線基地局DeNB(Donor eNB)に対して、Unインターフェイスを介して接続可能なリレーノードRN(Relay Node)を用いることができる。
 かかるリレーノードRNのアタッチ処理は、移動局UEと同様のアタッチ処理(Phase-1)を行った後、リレーノードRNとしてのアタッチ処理(Phase-2)を行うように規定されている(非特許文献1及び2)。
 ここで、図4を参照して、かかるリレーノードRNとしてのアタッチ処理について簡単に説明する。
 図4に示すように、ステップS2001において、「USIM-RN(Universal Subscriber Identity Module-RN、リレーノード用加入者識別モジュール)」が、未だアクティブではない場合、リレーノードRNは、かかるUSIM-RNをアクティブにし、かかるUSIM-RNとの間のセキュアなチャネルを復旧させる(或いは、再設定する)。
 なお、USIM-RNに対しては、セキュアなチャネルを介してのみアクセス可能である。
 かかる場合、リレーノードRNは、USIM-RN内の「EPS security context」を無効にする。
 ステップS2002において、リレーノードRNは、無線基地局DeNBに対して、リレーノードRNとしてのアタッチ処理を要求する「Attach Request(RN)(アタッチ要求信号)」を送信する。
 ここで、リレーノードRNは、USIM-RNに係るIMSI(International Mobile Subscriber Identity)又はGUTI(Global Unique Temporary Identifier)を含む「Attach Request」を送信する。
 ステップS2003において、無線基地局DeNBは、移動管理ノードMME(Mobility Management Entity)に対して、「(S1)Initial UE message(初期信号)」を送信する。
 移動管理ノードMMEは、かかる「(S1)Initial UE message」に応じて、ステップS2004において、リレーノードRN及びUSIM-RNとの間で、「EPS-AKA(Evolved Packet System-Authentication and Key Agreement、認証及び鍵同意手順)」を行うと共に、ステップS2005において、リレーノードRNとの間で、NAS(Non Access Stratum)セキュリティを設定する。
 ここで、リレーノードRNは、セキュアなチャネルを介してUSIM-RNから受信した鍵のみを使用する。
 ステップS2006において、移動管理ノードMMEは、加入者管理サーバHSS(Home Subscriber Server)から取得した加入者データ(subscription data)に基づいて、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得るか否かについて判定する。
 ステップS2007において、移動管理ノードMMEは、無線基地局DeNBに対して、かかる判定結果を含む「(S1)Initial Context Setup Request」を送信する。
 かかる判定結果が、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得ることを示す場合、無線基地局DeNBは、ステップS2009において、AS(Access Stratum)セキュリティを設定し、ステップS2010において、S1/X2 DRB(Data Radio Bearer)に対するリレーノードRN用のASセキュリティを設定する。
 一方、かかる判定結果が、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得ないことを示す場合、無線基地局DeNBは、リレーノードRNのアタッチ処理を拒絶する。
3GPP TS33.401 3GPP TS36.300
 しかしながら、既存のLTE-Advanced方式では、上述のように、リレーノードRNとしてのアタッチ処理において、USIM-RNを用いることができない場合(すなわち、リレーノードRNとしてのアタッチ処理が拒絶されてしまう場合)であっても、移動管理ノードMMEとリレーノードRNとの間で、必ずNASセキュリティが設定されてしまうため、無駄な「(S1)Initial Context Setup Request」が送信されてしまうという不具合があった。
 そこで、本発明は、上述の課題に鑑みてなされたものであり、リレーノードRNとしてのアタッチ処理において、無駄なリソースの使用を回避することができる移動通信方法及び移動管理ノードを提供することを目的とする。
 本発明の第1の特徴は、移動通信方法であって、リレーノード用加入者識別モジュールとの間でセキュアなチャネルが確立されているリレーノードが、無線基地局に対して、リレーノードとしてのアタッチ処理を要求するアタッチ要求信号を送信する工程と、前記無線基地局が、前記アタッチ要求信号に応じて、移動管理ノードに対して、リレーノードとしてのアタッチ処理であることを示す初期信号を送信する工程と、前記移動管理ノードが、前記初期信号に応じて、前記リレーノード及び汎用加入者識別モジュールとの間で、認証及び鍵同意手順を開始する工程と、前記移動管理ノードが、加入者管理サーバから取得した加入者データに基づいて、前記リレーノード用加入者識別モジュールが、前記リレーノードとしてのアタッチ処理に用いられ得るか否かについて判定する工程と、前記リレーノード用加入者識別モジュールが、前記リレーノードとしてのアタッチ処理に用いられ得ると判定された場合、前記移動管理ノードと前記リレーノードとの間で、NASセキュリティを設定する工程と、前記リレーノード用加入者識別モジュールが、前記リレーノードとしてのアタッチ処理に用いられ得ないと判定された場合、前記認証及び鍵同意手順が失敗する工程とを有することを要旨とする。
 本発明の第2の特徴は、移動管理ノードであって、リレーノード用加入者識別モジュールとの間でセキュアなチャネルが確立されているリレーノードのアタッチ処理において、無線基地局から、リレーノードとしてのアタッチ処理であることを示す初期信号を受信するように構成されている受信部と、前記初期信号に応じて、前記リレーノード及び前記汎用加入者識別モジュールとの間で、認証及び鍵同意手順を開始するように構成されている通信部と、加入者管理サーバから取得した加入者データに基づいて、前記リレーノード用加入者識別モジュールが、前記リレーノードとしてのアタッチ処理に用いられ得るか否かについて判定するように構成されている判定部とを具備し、前記判定部によって、前記リレーノード用加入者識別モジュールが、前記リレーノードとしてのアタッチ処理に用いられ得ると判定された場合、前記通信部は、前記リレーノードとの間で、NASセキュリティを設定するように構成されており、前記判定部によって、前記リレーノード用加入者識別モジュールが、前記リレーノードとしてのアタッチ処理に用いられ得ないと判定された場合、前記通信部は、前記認証及び鍵同意手順を成功させることなく終了させるように構成されていることを要旨とする。
図1は、本発明の第1の実施形態に係る移動通信システムの全体構成図である。 図2は、本発明の第1の実施形態に係る移動管理ノードの機能ブロック図である。 図3は、本発明の第1の実施形態に係る移動通信システムの動作を示すシーケンス図である。 図4は、既存の移動通信システムの動作を示すシーケンス図である。
(本発明の第1の実施形態に係る移動通信システム)
 図1乃至図3を参照して、本発明の第1の実施形態に係る移動通信システムについて説明する。
 本実施形態に係る移動通信システムは、LTE-Advanced方式の移動通信システムであって、図1に示すように、加入者管理サーバHSSと、移動管理ノードMMEと、無線基地局DeNBと、リレーノードRNとを具備している。
 また、USIM-RNは、リレーノードRNに接続することができるように構成されている。
 リレーノードRNは、接続されているUSIM-RNをアクティブにし、USIM-RNとの間でセキュアなチャネルを確立することができるように構成されている。
 図2に示すように、移動管理ノードMMEは、受信部11と、送信部12と、通信部13と、判定部14とを具備している。
 受信部11は、無線基地局DeNBや加入者管理サーバHSSから、各種情報を受信するように構成されている。
 例えば、受信部11は、無線基地局DeNBから、「(S1)Initial UE message」を受信したり、加入者管理サーバHSSから、リレーノードRNに係る加入者データを受信したりするように構成されている。
 送信部12は、無線基地局DeNBに対して、各種情報を送信するように構成されている。
 例えば、送信部12は、無線基地局DeNBに対して、「(S1)Initial Context Setup Request」を送信するように構成されている。
 通信部13は、リレーノードRN及びUSIM-RNとの間で、「EPA-AKA」を行ったり、リレーノードRNとの間で、NASセキュリティを設定したりするように構成されている。
 判定部14は、加入者管理サーバHSSから取得した加入者データに基づいて、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得るか否かについて判定するように構成されている。
 ここで、判定部14によって、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得ると判定された場合、通信部13は、リレーノードとの間で、NASセキュリティを設定するように構成されている。
 一方、判定部14によって、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得ないと判定された場合、通信部13は、「EPS-AKA」を成功させることなく終了させるように構成されている。
 以下、図3を参照して、本発明の第1の実施形態に係る移動通信システムの動作の一例について説明する。
 図3に示すように、ステップS1001において、USIM-RNが、未だアクティブではない場合、リレーノードRNは、かかるUSIM-RNをアクティブにし、かかるUSIM-RNとの間のセキュアなチャネルを復旧させる(或いは、再設定する)。
 かかる場合、リレーノードRNは、USIM-RN内の「EPS security context」を無効にする。
 ステップS1002において、リレーノードRNは、無線基地局DeNBに対して、リレーノードRNとしてのアタッチ処理を要求する「Attach Request(RN)」を送信する。
 ここで、リレーノードRNは、USIM-RNに係るIMSI又はGUTIを含む「Attach Request」を送信する。
 ステップS1003において、無線基地局DeNBは、移動管理ノードMMEに対して、リレーノードRNとしてのアタッチ処理であることを示す「(S1)Initial UE message」を送信する。
 ステップS1004において、移動管理ノードMMEは、かかる「(S1)Initial UE message」に応じて、リレーノードRN及びUSIM-RNとの間で、「EPS-AKA」を開始する。
 ステップS1005において、移動管理ノードMMEは、加入者管理サーバHSSから取得した加入者データに基づいて、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得るか否かについて判定する。
 USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得ると判定された場合、移動管理ノードMMEは、ステップS1006において、無線基地局DeNBに対して、「Release UE Context」を送信し、ステップS1007において、リレーノードRNとの間で、NASセキュリティを設定する。
 ここで、リレーノードRNは、セキュアなチャネルを介してUSIM-RNから受信した鍵のみを使用する。
 ステップS1008において、移動管理ノードMMEは、無線基地局DeNBに対して、「(S1)Initial Context Setup Request」を送信する。かかる「(S1)Initial Context Setup Request」は、ステップS1005における判定結果を含まない。
 無線基地局DeNBは、ステップS1009において、AS(Access Stratum)セキュリティを設定し、ステップS1010において、S1/X2 DRBに対するリレーノードRN用のASセキュリティを設定する。
 一方、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得ないと判定された場合、移動管理ノードMMEは、「EPS-AKA」を失敗させる(すなわち、成功させることなく終了させる)。
 本実施形態に係る移動通信システムによれば、リレーノードRNとしてのアタッチ処理において、USIM-RNを用いることができない場合には、移動管理ノードMMEとリレーノードRNとの間で、NASセキュリティを設定することなく、かかるリレーノードRNとしてのアタッチ処理を失敗させてしまうため、無駄なリソースの使用、例えば、無駄な「(S1)Initial Context Setup Request」の送信を回避することができる。
 以上に述べた本実施形態の特徴は、以下のように表現されていてもよい。
 本実施形態の第1の特徴は、移動通信方法であって、USIM-RN(リレーノード用加入者識別モジュール)との間でセキュアなチャネルが確立されているリレーノードRNが、無線基地局DeNBに対して、リレーノードRNとしてのアタッチを要求する「Attach Request(RN)(アタッチ要求信号)」を送信する工程と、無線基地局DeNBが、「Attach Request(RN)」に応じて、移動管理ノードMMEに対して、リレーノードRNとしてのアタッチ処理であることを示す「(S1)Initial UE message(初期信号)」を送信する工程と、移動管理ノードMMEが、「(S1)Initial UE message」に応じて、リレーノードRN及びUSIM-RNとの間で、「EPA-AKA(認証及び鍵同意手順)」を開始する工程と、移動管理ノードMMEが、加入者管理サーバHSSから取得した加入者データに基づいて、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得るか否かについて判定する工程と、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得ると判定された場合、移動管理ノードMMEとリレーノードRNとの間で、NASセキュリティを設定する工程と、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得ないと判定された場合、「EPS-AKA」が失敗する工程とを有することを要旨とする
 本実施形態の第2の特徴は、移動管理ノードMMEであって、USIM-RNとの間でセキュアなチャネルが確立されているリレーノードRNのアタッチ処理において、無線基地局DeNBから、リレーノードRNとしてのアタッチ処理であることを示す「(S1)Initial UE message」を受信するように構成されている受信部11と、「(S1)Initial UE message」に応じて、リレーノードRN及びUSIM-RNとの間で、「EPS-AKA」を開始するように構成されている通信部13と、加入者管理サーバHSSから取得した加入者データに基づいて、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得るか否かについて判定するように構成されている判定部14とを具備し、判定部14によって、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得ると判定された場合、通信部13は、リレーノードとの間で、NASセキュリティを設定するように構成されており、判定部14によって、USIM-RNが、リレーノードRNとしてのアタッチ処理に用いられ得ないと判定された場合、通信部13は、「EPS-AKA」を成功させることなく終了させるように構成されていることを要旨とする。
 なお、上述の移動管理ノードMMEや無線基地局DeNBやリレーノードRNやや加入者管理サーバHSSの動作は、ハードウェアによって実施されてもよいし、プロセッサによって実行されるソフトウェアモジュールによって実施されてもよいし、両者の組み合わせによって実施されてもよい。
 ソフトウェアモジュールは、RAM(Random Access Memory)や、フラッシュメモリや、ROM(Read Only Memory)や、EPROM(Erasable Programmable ROM)や、EEPROM(Electronically Erasable and Programmable ROM)や、レジスタや、ハードディスクや、リムーバブルディスクや、CD-ROMといった任意形式の記憶媒体内に設けられていてもよい。
 かかる記憶媒体は、プロセッサが当該記憶媒体に情報を読み書きできるように、当該プロセッサに接続されている。また、かかる記憶媒体は、プロセッサに集積されていてもよい。また、かかる記憶媒体及びプロセッサは、ASIC内に設けられていてもよい。かかるASICは、移動管理ノードMMEや無線基地局DeNBやリレーノードRNやや加入者管理サーバHSS内に設けられていてもよい。また、かかる記憶媒体及びプロセッサは、ディスクリートコンポーネントとして移動管理ノードMMEや無線基地局DeNBやリレーノードRNや加入者管理サーバHSS内に設けられていてもよい。
 以上、上述の実施形態を用いて本発明について詳細に説明したが、当業者にとっては、本発明が本明細書中に説明した実施形態に限定されるものではないということは明らかである。本発明は、請求の範囲の記載により定まる本発明の趣旨及び範囲を逸脱することなく修正及び変更態様として実施することができる。従って、本明細書の記載は、例示説明を目的とするものであり、本発明に対して何ら制限的な意味を有するものではない。
 なお、日本国特許出願第2011-082240号(2011年4月1日出願)の全内容が、参照により、本願明細書に組み込まれている。
 以上説明したように、本発明によれば、リレーノードRNとしてのアタッチ処理において、無駄なリソースの使用を回避することができる移動通信方法及び移動管理ノードを提供することができる。
RN…リレーノード
HSS…加入者管理サーバ
MME…移動管理ノード
11…受信部
12…送信部
13…通信部
14…判定部

Claims (2)

  1.  リレーノード用加入者識別モジュールとの間でセキュアなチャネルが確立されているリレーノードが、無線基地局に対して、リレーノードとしてのアタッチ処理を要求するアタッチ要求信号を送信する工程と、
     前記無線基地局が、前記アタッチ要求信号に応じて、移動管理ノードに対して、リレーノードとしてのアタッチ処理であることを示す初期信号を送信する工程と、
     前記移動管理ノードが、前記初期信号に応じて、前記リレーノード及び汎用加入者識別モジュールとの間で、認証及び鍵同意手順を開始する工程と、
     前記移動管理ノードが、加入者管理サーバから取得した加入者データに基づいて、前記リレーノード用加入者識別モジュールが、前記リレーノードとしてのアタッチ処理に用いられ得るか否かについて判定する工程と、
     前記リレーノード用加入者識別モジュールが、前記リレーノードとしてのアタッチ処理に用いられ得ると判定された場合、前記移動管理ノードと前記リレーノードとの間で、NASセキュリティを設定する工程と、
     前記リレーノード用加入者識別モジュールが、前記リレーノードとしてのアタッチ処理に用いられ得ないと判定された場合、前記認証及び鍵同意手順が失敗する工程とを有することを特徴とする移動通信方法。
  2.  リレーノード用加入者識別モジュールとの間でセキュアなチャネルが確立されているリレーノードのアタッチ処理において、無線基地局から、リレーノードとしてのアタッチ処理であることを示す初期信号を受信するように構成されている受信部と、
     前記初期信号に応じて、前記リレーノード及び前記汎用加入者識別モジュールとの間で、認証及び鍵同意手順を開始するように構成されている通信部と、
     加入者管理サーバから取得した加入者データに基づいて、前記リレーノード用加入者識別モジュールが、前記リレーノードとしてのアタッチ処理に用いられ得るか否かについて判定するように構成されている判定部とを具備し、
     前記判定部によって、前記リレーノード用加入者識別モジュールが、前記リレーノードとしてのアタッチ処理に用いられ得ると判定された場合、前記通信部は、前記リレーノードとの間で、NASセキュリティを設定するように構成されており、
     前記判定部によって、前記リレーノード用加入者識別モジュールが、前記リレーノードとしてのアタッチ処理に用いられ得ないと判定された場合、前記通信部は、前記認証及び鍵同意手順を成功させることなく終了させるように構成されていることを特徴とする移動管理ノード。
PCT/JP2012/058134 2011-04-01 2012-03-28 移動通信方法及び移動管理ノード Ceased WO2012137643A1 (ja)

Priority Applications (10)

Application Number Priority Date Filing Date Title
AU2012239436A AU2012239436B2 (en) 2011-04-01 2012-03-28 Mobile communication method and mobile management node
KR1020137028839A KR20130137037A (ko) 2011-04-01 2012-03-28 이동통신방법 및 이동 관리 노드
MX2013011315A MX2013011315A (es) 2011-04-01 2012-03-28 Metodo de comunicacion movil y nodo de manejo movil.
RU2013146040/07A RU2573418C2 (ru) 2011-04-01 2012-03-28 Способ мобильной связи и узел управления мобильностью
KR20147029659A KR20140140596A (ko) 2011-04-01 2012-03-28 이동통신방법 및 이동 관리 노드
EP12768325.8A EP2696616B1 (en) 2011-04-01 2012-03-28 Mobile communication method and mobile management node
ES12768325.8T ES2620412T3 (es) 2011-04-01 2012-03-28 Método de comunicación móvil y nodo de gestión móvil
CN201280017310.3A CN103460743B (zh) 2011-04-01 2012-03-28 移动通信方法以及移动管理节点
US14/009,169 US9002324B2 (en) 2011-04-01 2012-03-28 Mobile communication method and mobile management node
ZA2013/07833A ZA201307833B (en) 2011-04-01 2013-10-21 Mobile communication method and mobile management node

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2011-082240 2011-04-01
JP2011082240A JP5021820B1 (ja) 2011-04-01 2011-04-01 移動通信方法及び移動管理ノード

Publications (1)

Publication Number Publication Date
WO2012137643A1 true WO2012137643A1 (ja) 2012-10-11

Family

ID=46969044

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2012/058134 Ceased WO2012137643A1 (ja) 2011-04-01 2012-03-28 移動通信方法及び移動管理ノード

Country Status (11)

Country Link
US (1) US9002324B2 (ja)
EP (1) EP2696616B1 (ja)
JP (1) JP5021820B1 (ja)
KR (2) KR20140140596A (ja)
CN (1) CN103460743B (ja)
AU (1) AU2012239436B2 (ja)
ES (1) ES2620412T3 (ja)
MX (1) MX2013011315A (ja)
RU (1) RU2573418C2 (ja)
WO (1) WO2012137643A1 (ja)
ZA (1) ZA201307833B (ja)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2015100974A1 (zh) * 2013-12-31 2015-07-09 华为技术有限公司 一种终端认证的方法、装置及系统

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR102164801B1 (ko) * 2014-03-21 2020-10-13 삼성전자주식회사 액세스 포인트 연결 시스템, 방법 및 장치
US10588019B2 (en) * 2016-05-05 2020-03-10 Qualcomm Incorporated Secure signaling before performing an authentication and key agreement
WO2018126452A1 (zh) * 2017-01-06 2018-07-12 华为技术有限公司 授权验证方法和装置

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2011023873A (ja) * 2009-07-14 2011-02-03 Ntt Docomo Inc 移動通信方法及び無線基地局

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
RU2009102013A (ru) * 2006-06-30 2010-08-10 Нокиа Коропрейшн (FI) Ретранслятор
CN101902835B (zh) * 2009-05-27 2014-09-10 中国移动通信集团公司 中继节点识别方法、基站、中继节点及移动管理实体
US8904167B2 (en) * 2010-01-22 2014-12-02 Qualcomm Incorporated Method and apparatus for securing wireless relay nodes

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2011023873A (ja) * 2009-07-14 2011-02-03 Ntt Docomo Inc 移動通信方法及び無線基地局

Non-Patent Citations (4)

* Cited by examiner, † Cited by third party
Title
"LTE;Evolved Universal Terrestrial Radio Access (E-UTRA) and Evolved Universal Terrestrial Radio Access Network (E-UTRAN);Overall description;Stage 2", 3GPP TS136.300 V10.2.0, December 2010 (2010-12-01), pages 33 - 35, XP055127900 *
3RD GENERATION PARTNERSHIP PROJECT: "3GPP System Architecture Evolution (SAE); Security architecture (3GPP TS33.401)", 2008
3RD GENERATION PARTNERSHIP PROJECT: "Evolved Universal Terrestrial Radio Access (E-UTRA) and Evolved Universal Terrestrial Radio Access Network (E-UTRAN); Overall description; Stage 2", 2006
See also references of EP2696616A4 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2015100974A1 (zh) * 2013-12-31 2015-07-09 华为技术有限公司 一种终端认证的方法、装置及系统
US10588015B2 (en) 2013-12-31 2020-03-10 Huawei Technologies Co., Ltd. Terminal authenticating method, apparatus, and system

Also Published As

Publication number Publication date
ZA201307833B (en) 2015-01-28
CN103460743B (zh) 2014-12-31
RU2013146040A (ru) 2015-05-10
MX2013011315A (es) 2013-12-06
US20140094145A1 (en) 2014-04-03
EP2696616A4 (en) 2015-02-18
AU2012239436B2 (en) 2015-07-02
JP5021820B1 (ja) 2012-09-12
US9002324B2 (en) 2015-04-07
AU2012239436A8 (en) 2013-11-14
AU2012239436A1 (en) 2013-10-31
EP2696616A1 (en) 2014-02-12
EP2696616B1 (en) 2016-12-28
KR20130137037A (ko) 2013-12-13
JP2012217110A (ja) 2012-11-08
CN103460743A (zh) 2013-12-18
KR20140140596A (ko) 2014-12-09
RU2573418C2 (ru) 2016-01-20
ES2620412T3 (es) 2017-06-28

Similar Documents

Publication Publication Date Title
US9807072B2 (en) Fast-accessing method and apparatus
ES2989427T3 (es) Identificador de UE en reanudación de RRC
JP6745346B2 (ja) 無線通信方法、及び装置
US20120178417A1 (en) Mobile communication method and mobile communication system
US9590962B2 (en) Using cookies to identify security contexts for connectionless service
US10904756B2 (en) Authentication for next generation systems
US20130203382A1 (en) Mobile communication method, mobile communication system, and radio base station
JP5508184B2 (ja) 接続方法及び無線基地局
US11172529B2 (en) Multi-connectivity establishment method, communication system, user equipment and access point
JP5021820B1 (ja) 移動通信方法及び移動管理ノード
WO2016061979A1 (zh) 管理设备间d2d通信分组的方法、设备和存储介质
CN106537953A (zh) 用于改善或启用用户设备对移动通信网络的无线电覆盖的方法、适于具有改善的无线电覆盖的用户设备、适于将改善的无线电覆盖提供给用户设备的中继用户设备、用于改善或启用用户设备的无线电覆盖的系统、移动通信网络、程序和计算机程序产品
TW201228314A (en) Mobile communication method and radio base station
JP5285659B2 (ja) 移動通信方法及びリレーノード
WO2017128306A1 (zh) 通信方法及设备
US20210360584A1 (en) Communication Method, Terminal Apparatus, and Access Network Apparatus
CN114374957B (zh) 一种短距离通信方法及装置
CN104685928A (zh) 移动通信方法
CN102781000A (zh) 一种实施业务处理的方法、基站、移动管理实体和系统
JP2012175653A (ja) 移動通信方法及び移動局
JP2012170160A (ja) 移動通信方法、リレーノード及び無線基地局
JP2011029901A (ja) 移動通信方法及び交換局

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12768325

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: MX/A/2013/011315

Country of ref document: MX

NENP Non-entry into the national phase

Ref country code: DE

REEP Request for entry into the european phase

Ref document number: 2012768325

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 2012768325

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 2012239436

Country of ref document: AU

Date of ref document: 20120328

Kind code of ref document: A

Ref document number: 20137028839

Country of ref document: KR

Kind code of ref document: A

ENP Entry into the national phase

Ref document number: 2013146040

Country of ref document: RU

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 14009169

Country of ref document: US