WO2014161300A1 - 一种用于机器类通信小数据传输的密钥建立方法和系统 - Google Patents

一种用于机器类通信小数据传输的密钥建立方法和系统 Download PDF

Info

Publication number
WO2014161300A1
WO2014161300A1 PCT/CN2013/086244 CN2013086244W WO2014161300A1 WO 2014161300 A1 WO2014161300 A1 WO 2014161300A1 CN 2013086244 W CN2013086244 W CN 2013086244W WO 2014161300 A1 WO2014161300 A1 WO 2014161300A1
Authority
WO
WIPO (PCT)
Prior art keywords
mtc
iwf
mtc device
information
key
Prior art date
Application number
PCT/CN2013/086244
Other languages
English (en)
French (fr)
Inventor
余万涛
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2014161300A1 publication Critical patent/WO2014161300A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/70Services for machine-to-machine communication [M2M] or machine type communication [MTC]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup

Definitions

  • the present invention relates to the field of communications, and in particular, to a key establishment method and system for small data transmission of Machine Type Communication (MTC). Background technique
  • MTC refers to a series of technologies and combinations of technologies that use wireless communication technology to realize data communication and communication between machines and machines, machines and people.
  • MTC has two meanings: the first layer is the machine itself, which is called smart device in the embedded field; the second layer is the connection between the machine and the machine, connecting the machines together through the network.
  • MTC's wide range of applications such as smart measurement, remote monitoring, tracking, medical, etc., make human life more intelligent. Compared with traditional human-to-human communication, MTC devices have a large number of applications and a wide range of applications.
  • the MTC device passes the 3rd Generation Partnership Project (3GPP) network and the MTC Interworking Function (MTC-IWF), and the Service Capability Server (SCS) ), such as the MTC server to communicate.
  • 3GPP 3rd Generation Partnership Project
  • MTC-IWF MTC Interworking Function
  • SCS Service Capability Server
  • SDT Small Data Transmission
  • MTC device and MTC-IWF Each SDT protocol data unit specifies the sender and receiver identity.
  • MME Mobile Management Entity
  • NAS general network access service
  • SDT-Transfer-PDU Small Data Transmission-Transfer-Protocol Data Unit
  • the main purpose of the embodiments of the present invention is to provide a key establishment method and system for MTC small data transmission, and to deploy multiple MTC-IWFs in an MTC system, and can be used in an MTC device and an MTC-IWF. Establish a shared key between.
  • the embodiment of the invention provides a key establishment method for machine type communication MTC small data transmission, and the method includes:
  • the home subscriber server HSS that receives the authentication data request information specifies an MTC interworking function entity MTC-IWF for performing small data transmission for the MTC device that issues the attach request information; the HSS generates a shared secret between the MTC device and the MTC-IWF. Key K iwf ;
  • the HSS sends the MTC-IWF information to the MTC device via the mobility management entity MME or the general packet radio service support node SGSN;
  • the HSS sends the MTC device information and the generated shared key K iwf to the designated MTC-IWF;
  • the MTC-IWF stores the received MTC device information and the shared key K iwf ; the MTC device generates a shared key K iwf .
  • the method further includes:
  • the HSS generates a next-level key by using the shared key K iwf ;
  • the method further includes:
  • the MTC device generates the next-level key through the shared key K iwf .
  • the method further includes:
  • the MTC device sends security association request information to the MTC-IWF via the MME or the SGSN;
  • the MTC-IWF After receiving the security association request information, the MTC-IWF performs authentication according to the stored shared key K iw ⁇ MTC device, and generates a next-level key by using the shared key K iwf ;
  • the MTC-IWF sends a security association response message to the MTC device
  • the MTC device authenticates the MTC-IWF according to the stored shared key ⁇ , and generates the next-level key through the shared key K iwf .
  • the next level key comprises an encryption key and an integrity protection key.
  • the authentication data request information includes identity information of the MTC device, MTC device MTC capability information, and transmit/receive small data capability information;
  • the MTC device that issues the attachment request information specifies an MTC-IWF for small data transmission:
  • the HSS specifies an MTC-IWF for small data transmission for the MTC device that issues the attach request information according to the MTC capability information of the MTC device, the transmit/receive small data capability information, and the information of each MTC-IWF stored by itself.
  • the embodiment of the present invention provides a key establishment system for machine type communication MTC small data transmission, where the system includes: a home subscriber server HSS, an MTC device, and a plurality of MTC interworking function entities MTC-IWF, where The HSS is configured to: after receiving the authentication data request information, specify an MTC-IWF for performing small data transmission for the MTC device that issues the attachment request information; and generate a shared key K iwf between the MTC device and the MTC-IWF; Transmitting the MTC-IWF information to the MTC device via the mobility management entity MME or the general packet radio service support node SGSN; transmitting the MTC device information and the generated shared key K iwf to the designated MTC-IWF;
  • the MTC-IWF is configured to store the received MTC device information and the shared key K iwf ; the MTC device is configured to generate a shared key K iwf .
  • the HSS is further configured to generate a next-level key by using the shared key K iwf ; the MTC device is further configured to generate a next-level key by using the shared key K iwf .
  • the MTC device is further configured to send security association request information to the MTC-IWF via the MME or the SGSN; after receiving the security association response information sent by the MTC-IWF, according to the stored shared key K iw ⁇
  • the MTC-IWF performs authentication, and generates a next-level key by using the shared key K iwf ;
  • the MTC-IWF is further configured to: after receiving the security association request information, perform authentication according to the stored shared key K iw ⁇ MTC device, and generate a next-level key by using the shared key K iwf ; to the MTC The device sends a security association response message.
  • the next level key comprises an encryption key and an integrity protection key.
  • the authentication data request information includes identity information of the MTC device, MTC device MTC capability information, and transmit/receive small data capability information;
  • the HSS is configured to specify, according to the MTC device MTC capability information, the sending/receiving small data capability information, and the information of each MTC-IWF stored by the MTC device, a small data transmission for the MTC device that sends the attach request information. MTC-IWF.
  • the technical solution of the embodiment of the present invention includes: a home subscriber server HSS that receives the authentication data request information, and specifies an MTC interworking function entity MTC-IWF for performing small data transmission for the MTC device that sends the attach request information; HSS generates MTC devices and a shared key K iwf between the MTC-IWFs; the HSS sends the MTC-IWF information to the MTC device via the mobility management entity MME or the general packet radio service support node SGSN; the HSS shares the MTC device information with the generated The key K iwf is sent to the designated MTC-IWF; the MTC-IWF stores the received MTC device information and the shared key K iwf ; the MTC device generates the shared key K iwf . Therefore, in the case of deploying multiple MTC-IWFs in the MTC system, the embodiment of the present invention can establish a shared key between the MTC device and the MTC-IWF.
  • FIG. 1 is a schematic flow chart of an embodiment of a method for establishing a key for MTC small data transmission provided by the present invention
  • Embodiment 1 is a schematic flowchart of Embodiment 1 of a method for establishing a key for MTC small data transmission provided by the present invention
  • Embodiment 3 is a schematic flowchart of Embodiment 2 of a method for establishing a key for MTC small data transmission provided by the present invention
  • Embodiment 4 is a schematic flowchart of Embodiment 3 of a method for establishing a key for MTC small data transmission provided by the present invention
  • FIG. 5 is a schematic structural diagram of an embodiment of a key establishment system for MTC small data transmission provided by the present invention.
  • FIG. 6 is a schematic structural diagram of another embodiment of a key establishment system for MTC small data transmission provided by the present invention.
  • FIG. 7 is a schematic structural diagram of an apparatus for a key establishment system for MTC small data transmission provided by the present invention. detailed description
  • An embodiment of a method for establishing a key for MTC small data transmission is provided by the present invention. As shown in FIG. 1, the method includes:
  • Step 101 A Home Subscriber Server (HSS) that receives the authentication data request information, and specifies an MTC-IWF for performing small data transmission for the MTC device that issues the attach request information.
  • HSS Home Subscriber Server
  • Step 102 The HSS generates a shared key K iwf between the MTC device and the MTC-IWF.
  • Step 103 The HSS sends the MTC-IWF information to the MTC via the mobility management entity MME or the general packet radio service support node SGSN. device;
  • Step 104 The HSS sends the MTC device information and the generated shared key K iwf to the designated MTC-IWF;
  • Step 105 The MTC-IWF stores the received MTC device information and the shared key K iwf .
  • the method further includes:
  • the HSS generates a next-level key by using the shared key K iwf ;
  • the method further includes:
  • the MTC device generates the next-level key through the shared key K iwf .
  • the method further includes:
  • the MTC device sends security association request information to the MTC-IWF via the MME or the SGSN;
  • the MTC-IWF After receiving the security association request information, the MTC-IWF performs authentication according to the stored shared key K iw ⁇ MTC device, and generates a next-level key by using the shared key K iwf ;
  • the MTC-IWF sends a security association response message to the MTC device
  • the MTC device authenticates the MTC-IWF according to the stored shared key ⁇ , and generates the next-level key through the shared key K iwf .
  • the next level key comprises an encryption key and an integrity protection key.
  • the authentication data request information includes identity information of the MTC device, MTC device MTC capability information, and transmit/receive small data capability information;
  • the MTC device that issues the attachment request information specifies an MTC-IWF for small data transmission:
  • the HSS specifies an MTC-IWF for small data transmission for the MTC device that issues the attach request information according to the MTC capability information of the MTC device, the transmit/receive small data capability information, and the information of each MTC-IWF stored by itself.
  • the shared key K iwf is generated by the MTC-IWF. Specifically, as shown in FIG. 2, the following steps are included:
  • Step 201 The MTC device sends the attach request information to the MME.
  • the attach request information includes identity information of the MTC device, such as an International Mobile Subscriber Identification Number (IMSI), an International Mobile Equipment Identity (IMEI), or the like.
  • IMSI International Mobile Subscriber Identification Number
  • IMEI International Mobile Equipment Identity
  • the identity information of the MTC device is further included, and the MTC device MTC capability information and the sending/receiving d and the data capability information are also included.
  • Step 202 The MME sends the authentication data request information to the HSS.
  • the authentication data request information includes identity information of the MTC device, such as IMSI, IMEI, or other identity information that can be used to identify the MTC device, and also includes MTC device MTC capability information and transmit/receive small data capability information.
  • identity information of the MTC device such as IMSI, IMEI, or other identity information that can be used to identify the MTC device, and also includes MTC device MTC capability information and transmit/receive small data capability information.
  • Step 203 The HSS generates an authentication response data according to the subscription information of the MTC device, and specifies an MTC-IWF for performing small data transmission for the MTC device, and generates a shared key K iwf between the MTC device and the MTC-IWF;
  • the shared key K iwf may be generated according to a key generation algorithm, and specifically, may be classified by an Access Security Management Entity (ASME).
  • ASME Access Security Management Entity
  • the HSS may determine the MTC-IWF for small data transmission for the attached MTC device according to the attached MTC device MTC capability information, the transmit/receive small data capability information, and the information of each MTC-IWF stored by itself.
  • Step 204 The HSS sends the MTC-IWF information to the MME together with the authentication response data.
  • the MTC-IWF information may be any information used to identify the MTC-IWF identity.
  • Step 205 the HSS sends the MTC device information and the generated shared key K iwf to the designated MTC-IWF;
  • the MTC device information may be identity information of the MTC device, such as IMSI, IMEI or other identity information that can be used to identify the MTC device.
  • Step 206 The MTC-IWF receives and stores the shared key K iwf and the MTC device information, and maintains and manages the saved shared key and the MTC device information.
  • Step 207 Perform mutual authentication further between the MME and the MTC device.
  • Step 208 The MME sends the MTC-IWF information to the MTC device.
  • Step 209 The MTC device stores the MTC-IWF information, and maintains and manages the stored MTC-IWF information.
  • Step 210 The MTC device generates a shared key K iwf according to a key generation algorithm and saves it.
  • the MTC device needs to indicate that small data needs to be sent to the designated MTC-IWF to implement small data transmission according to the association information between the MTC device and the MTC-IWF stored thereon.
  • the MTC-IWF receives small data from a small data source, such as an MTC server, a network server, another network entity, or another MTC device, the MTC-IWF needs to associate information between the MTC device and the MTC-IWF stored on the MTC-IWF. Determining whether the small data can be forwarded to the MTC device.
  • the small data can be forwarded to the MTC device, the small data is forwarded to the designated MTC device to implement small data transmission; otherwise, the MTC-IWF does not perform small data forwarding. And can further feed small data to small data sources according to system needs. Forward failed information.
  • the MTC device and the MTC-IWF further generate a small data encryption key and a small data integrity protection key based on the shared key K iwf according to system requirements or according to small data transmission security protection requirements.
  • the second embodiment is different from the first embodiment in that the shared key generation step further includes a method for generating a next-level key for small data transmission security protection. Specifically, as shown in FIG. 3, the following steps are included:
  • Step 301 The MTC device sends the attach request information to the MME.
  • the attach request information includes identity information of the MTC device, such as IMSI, and also includes MTC device MTC capability information and transmit/receive small data capability information.
  • Step 302 The MME sends the authentication data request information to the HSS.
  • Step 303 The HSS generates an authentication response data according to the subscription information of the MTC device, and specifies an MTC-IWF for performing small data transmission for the MTC device, and generates a shared key K iwf between the MTC device and the MTC-IWF, and shares the same.
  • the key K iwf generates a next-level key for protecting the secure transmission of small data, such as an encryption key and an integrity protection key;
  • the shared key K iwf may be generated according to a key generation algorithm, and specifically, may be generated by Keym according to a key generation algorithm.
  • Step 304 The HSS sends the MTC-IWF information to the MME together with the authentication response data.
  • the MTC-IWF information may be any information used to identify the MTC-IWF identity.
  • Step 305 The HSS sends the MTC device information and the generated shared key K iwf , the encryption key, and the integrity protection key to the designated MTC-IWF.
  • Step 306 The MTC-IWF receives and stores the MTC device information and the generated shared key K iwf , the encryption key and the integrity protection key, and the saved MTC device information and the generated shared key K iwf and the encryption key. And integrity protection keys for maintenance and management. Step 307, the mutual authentication is further completed between the MME and the MTC device.
  • Step 308 The MME sends the MTC-IWF information to the MTC device.
  • Step 309 The MTC device stores the MTC-IWF information, and maintains and manages the stored MTC-IWF information.
  • Step 310 The MTC device generates a shared key K iwf according to the key generation algorithm, and generates a next-level key, such as an encryption key and an integrity protection key, for protecting the secure transmission of small data through the shared key K iwf . And save the shared key K iwf , encryption key and integrity protection key.
  • the MTC device when the MTC device is attached, the MTC device generates a shared key K iwf with the MTC-IWF, and according to the system requirement or according to the small data transmission security protection requirement, after the shared key is attached and generated, the MTC device initiates generation and The process of generating the next-level key for the small data transmission security protection between the MTC-IWF, as shown in FIG. 4, the method may include the following steps: Step 401, after generating the shared key K iwf , The MTC device sends security association request information to the MTC-IWF via the MME;
  • the security association request information may include security algorithm information, MTC device information, and other information used for authentication and key generation;
  • the security association request information may be sent by using NAS signaling.
  • Step 402 After receiving the security association request information, the MTC-IWF authenticates the MTC device according to the stored shared key, and generates a next-level key for protecting the secure transmission of the small data by using the shared key K iwf , such as Encryption key and integrity protection key.
  • K iwf such as Encryption key and integrity protection key.
  • Step 403 The MTC-IWF sends the security association response information to the MTC device.
  • the security association response information may include security algorithm information, MTC-IWF information, and other information for authentication and key generation.
  • Step 404 The MTC device authenticates the MTC-IWF according to the stored shared key K iwf , and generates a next-level key for protecting the secure transmission of small data through the shared key K iwf , such as encryption. Key and integrity protection keys.
  • Step 405 The MTC device and the MTC-IWF perform small data secure transmission by using the generated encryption key and the integrity protection key.
  • the SGSN may be used instead of the MME.
  • the present invention provides an embodiment of a key establishment system for MTC small data transmission.
  • the system includes: HSS 501.
  • MTC device 502 and a plurality of MTC-IWF 503, wherein
  • the HSS 501 is configured to: after receiving the authentication data request information, specify an MTC-IWF 503 for performing small data transmission for the MTC device 502 that issues the attach request information, and establish and store between the MTC device 502 and the MTC-IWF 503. Correlation relationship; generating a shared key K iwf between the MTC device 502 and the MTC-IWF 503 ; transmitting the MTC-IWF information to the MTC device 502 via the mobility management entity MME or the general packet radio service support node SGSN; And the generated shared key K iwf is sent to the designated MTC-IWF 503;
  • the MTC-IWF 503 is configured to store the received MTC device information and the shared key K iwf ; the MTC device 502 is configured to store the received MTC-IWF information and generate a shared key K iwf .
  • the HSS 501 is further configured to generate a next-level key by using the shared key K iwf ; the MTC device 502 is further configured to generate a next-level key by using the shared key K iwf .
  • the MTC device 502 is further configured to be directed to the MME or the SGSN.
  • the MTC-IWF 503 sends the security association request information; after receiving the security association response information sent by the MTC-IWF 503, the MTC-IWF 503 is authenticated according to the stored shared key K iwf , and is generated by the shared key K iwf Primary key
  • the MTC-IWF 503 is further configured to: after receiving the security association request information, perform authentication according to the stored shared key K iw ⁇ MTC device 502, and generate a next-level key by using the shared key K iwf ;
  • the MTC device 502 transmits security association response information.
  • the next level key comprises an encryption key and an integrity protection key.
  • the authentication data request information includes identity information of the MTC device 502 and MTC device MTC capability information and transmit/receive small data capability information;
  • the HSS 501 is configured to specify, according to the MTC capability information of the MTC device, the sending/receiving small data capability information, and the information of each MTC-IWF 503 stored by itself, for the MTC device 502 that issues the attach request information.
  • the MTC-IWF 503 of data transmission establishes, stores and maintains an association relationship between the MTC device 502 and the MTC-IWF 503.
  • the embodiment of the present invention provides a key establishment system for MTC small data transmission, as shown in FIG. 6, including: an MTC device 502 configured to store MTC-IWF information and a small data transmission shared key.
  • the MME 504 is configured as a NAS signaling process;
  • the HSS 501 is configured to manage and maintain the MTC-IWF information, and can also be used to manage and maintain the MTC device information, and can also be used to establish, store, and maintain the MTC device 502 and the MTC-IWF 503.
  • FIG. 7 is a schematic diagram of a device structure of a key establishment system for MTC small data transmission according to an embodiment of the present invention.
  • the device of the system may include: an MTC device 502, an MME 504, an MTC-IWF 503, and an HSS 501.
  • the device of the system specifically includes:
  • the first storage management unit 5021 is configured to store management MTC device information and key information;
  • the second storage management unit 5031 is configured to store and manage MTC-IWF information and key information;
  • the third storage management unit 5011 is configured to be stored and managed.
  • MTC-IWF information and MTC device information storing and managing association information between the MTC-IWF and the MTC device;
  • the allocating unit 5012 is configured to allocate the specified association according to the MTC device attachment information MTC-IWF;
  • the first transmitting/receiving unit 5022, the second transmitting/receiving unit 5032, and the third transmitting/receiving unit 5013 are configured to transmit and receive signaling information, key information, device information, and small data; the determining unit 5033 is configured to Determining whether the MTC-IWF can forward small data information; the first key negotiating unit 5023 and the second key negotiating unit 5034 are configured to negotiate a shared key, such as an encryption key and an integrity key.
  • each of the above units may be a central processing unit (CPU), a digital signal processor (DSP), or a programmable logic array (FPGA, Field-Programmable Gate Array) in the device to which it belongs. ) Implementation.
  • CPU central processing unit
  • DSP digital signal processor
  • FPGA Field-Programmable Gate Array
  • the SGSN may also be used instead of the MME.
  • modules or steps of the present invention can be implemented by a general-purpose computing device, which can be concentrated on a single computing device or distributed over a network composed of multiple computing devices. Alternatively, they may be implemented by program code executable by the computing device, such that they may be stored in the storage device by the computing device and, in some cases, may be different from the order herein.
  • the steps shown or described are performed, or they are separately fabricated into individual integrated circuit modules, or a plurality of modules or steps are fabricated as a single integrated circuit module.
  • the invention is not limited to any specific combination of hardware and software.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明公开了一种用于机器类通信MTC小数据传输的密钥建立方法和系统,其中,所述方法包括:收到认证数据请求信息的归属用户服务器HSS,为发出附着请求信息的MTC设备指定一个进行小数据传输的MTC互通功能实体MTC-IWF;所述HSS生成MTC设备与MTC-IWF之间的共享密钥Kiwf ;所述HSS将MTC-IWF信息经由移动管理实体MME或通用分组无线业务服务支持节点SGSN发给MTC设备;所述HSS将MTC设备信息和生成的共享密钥Kiwf发送给指定的MTC-IWF;所述MTC-IWF存储收到的MTC设备信息和共享密钥Kiwf;所述MTC设备生成共享密钥Kiwf 。本发明针对MTC系统中部署多个MTC-IWF的情况,能够在MTC设备与MTC-IWF之间建立共享密钥。

Description

一种用于机器类通信小数据传输的密钥建立方法和系统 技术领域
本发明涉及通信领域, 尤其涉及一种用于机器类通信(Machine Type Communication, MTC ) 小数据传输的密钥建立方法及系统。 背景技术
MTC是指应用无线通信技术, 实现机器与机器、 机器与人之间的数据 通信和交流的一系列技术及其组合的总称。 MTC包括两层含义: 第一层是 机器本身, 在嵌入式领域称为智能设备; 第二层意思是机器和机器之间的 连接, 通过网络把机器连接在一起。 MTC的应用范围非常广泛, 例如智能 测量、 远程监控、 跟踪、 医疗等, 使人类生活更加智能化。 与传统的人与 人之间的通信相比, MTC设备( MTC Device )数量巨大, 应用领域广泛。
在现有 MTC 系统中, MTC 设备通过第三代合作伙伴计划 (3rd Generation Partnership Project, 3GPP ) 网络和 MTC互通功能实体 ( MTC InterWorking Function, MTC-IWF ), 与业务能力服务器( Services Capability Server, SCS ), 如 MTC服务器进行通信。
在移动通信系统中, 引入 MTC设备后, 由于 MTC设备数量众多, 并 且这些 MTC设备可能经常接收和发送小数据,从而导致移动通信系统资源 使用效率降低。 为了高效使用网络资源, 通常通过信令在 MTC 设备与 MTC-IWF之间传输小数据。
目前, 在 MTC 设备和 MTC-IWF 部署小数据传输 ( Small Data Transmission, SDT )协议, MTC设备和 SCS之间的任何数据交换都需要 经过 MTC-IWF。每一个 SDT协议数据单元都指明发送和接受方标识。 MTC 设备与移动管理实体( Mobile Management Entity, MME )或通用分组无线 业务( General Packet Radio Service, GPRS )服务支持节点 ( Serving GPRS Support Node, SGSN )之间小数据服务数据单元封装在一个通用的网络接 入服务(Network Access Service, NAS )协议数据单元中传输, 在 NAS协 议数据单元中, 协议类型需要设置成 SDT。 MME/SGSN与 MTC-IWF之间 传输数据时, 小数据封装在小数据传输转移协议数据单元 (Small Data Transmission-Transfer-Protocol Data Unit, SDT-Transfer-PDU)中传输。
在上述方法中, 要保证 MTC设备和 MTC-IWF之间的安全性, 需要在 MTC设备与 MTC-IWF之间建立共享密钥。 但是, 目前在 MTC设备与 MTC-IWF之间建立共享密钥的技术方案仅适用于 MTC系统中仅部署一个 MTC-IWF的情况。 对 MTC系统中部署多个 MTC-IWF的情况, 还无法在 MTC设备与 MTC-IWF之间建立共享密钥。 发明内容
有鉴于此,本发明实施例的主要目的在于提供一种用于 MTC小数据传 输的密钥建立方法和系统, 对 MTC系统中部署多个 MTC-IWF的情况, 能 够在 MTC设备与 MTC-IWF之间建立共享密钥。
为达到上述目的, 本发明实施例的技术方案是这样实现的:
本发明实施例提供了一种用于机器类通信 MTC 小数据传输的密钥建 立方法, 所述方法包括:
收到认证数据请求信息的归属用户服务器 HSS, 为发出附着请求信息 的 MTC设备指定一个进行小数据传输的 MTC互通功能实体 MTC-IWF; 所述 HSS生成 MTC设备与 MTC-IWF之间的共享密钥 Kiwf;
所述 HSS将 MTC-IWF信息经由移动管理实体 MME或通用分组无线 业务服务支持节点 SGSN发给 MTC设备;
所述 HSS 将 MTC 设备信息和生成的共享密钥 Kiwf发送给指定的 MTC-IWF; 所述 MTC-IWF存储收到的 MTC设备信息和共享密钥 Kiwf; 所述 MTC设备生成共享密钥 Kiwf
较佳地,在所述 HSS生成 MTC设备与 MTC-IWF之间的共享密钥 Kiwf 之后, 所述方法还包括:
所述 HSS通过共享密钥 Kiwf生成下一级密钥;
相应的, 在 MTC设备生成共享密钥 Kiwf之后, 所述方法还包括:
MTC设备通过共享密钥 Kiwf生成下一级密钥。
较佳地, 在 MTC设备生成共享密钥 Kiwf之后, 所述方法还包括:
MTC设备经由 MME或 SGSN向 MTC-IWF发送安全关联请求信息;
MTC-IWF收到安全关联请求信息后,根据存储的共享密钥 Kiw † MTC 设备进行认证, 并通过所述共享密钥 Kiwf生成下一级密钥;
MTC-IWF向 MTC设备发送安全关联响应信息;
MTC设备根据存储的共享密钥 ^对 MTC-IWF进行认证, 并通过所 述共享密钥 Kiwf生成下一级密钥。
较佳地, 所述下一级密钥包括加密密钥和完整性保护密钥。
较佳地, 所述认证数据请求信息包括 MTC设备的身份信息和 MTC设 备 MTC能力信息和发送 /接收小数据能力信息;
相应的,所述为发出附着请求信息的 MTC设备指定一个进行小数据传 输的 MTC-IWF为:
HSS根据所述 MTC设备 MTC能力信息、发送 /接收小数据能力信息以 及自身存储的各 MTC-IWF的信息, 为发出附着请求信息的 MTC设备指定 一个进行小数据传输的 MTC-IWF。
本发明实施例提供了一种用于机器类通信 MTC 小数据传输的密钥建 立系统, 所述系统包括: 归属用户服务器 HSS、 MTC设备和多个 MTC互 通功能实体 MTC-IWF, 其中, 所述 HSS, 配置为在收到认证数据请求信息后, 为发出附着请求信息 的 MTC设备指定一个进行小数据传输的 MTC-IWF; 生成 MTC设备与 MTC-IWF之间的共享密钥 Kiwf;将 MTC-IWF信息经由移动管理实体 MME 或通用分组无线业务服务支持节点 SGSN发给 MTC设备; 将 MTC设备信 息和生成的共享密钥 Kiwf发送给指定的 MTC-IWF;
所述 MTC-IWF, 配置为存储收到的 MTC设备信息和共享密钥 Kiwf; 所述 MTC设备, 配置为生成共享密钥 Kiwf
较佳地, 所述 HSS, 还配置为通过共享密钥 Kiwf生成下一级密钥; 所述 MTC设备, 还配置为通过共享密钥 Kiwf生成下一级密钥。
较佳地, 所述 MTC设备, 还配置为经由 MME或 SGSN向 MTC-IWF 发送安全关联请求信息; 在收到 MTC-IWF发来的安全关联响应信息后,根 据存储的共享密钥 Kiw † MTC-IWF进行认证, 并通过所述共享密钥 Kiwf 生成下一级密钥;
所述 MTC-IWF, 还配置为在收到安全关联请求信息后, 根据存储的共 享密钥 Kiw †MTC设备进行认证,并通过所述共享密钥 Kiwf生成下一级密 钥; 向 MTC设备发送安全关联响应信息。
较佳地, 所述下一级密钥包括加密密钥和完整性保护密钥。
较佳地, 所述认证数据请求信息包括 MTC设备的身份信息和 MTC设 备 MTC能力信息和发送 /接收小数据能力信息;
相应的, 所述 HSS, 配置为根据所述 MTC设备 MTC能力信息、 发送 /接收小数据能力信息以及自身存储的各 MTC-IWF的信息, 为发出附着请 求信息的 MTC设备指定一个进行小数据传输的 MTC-IWF。
由上可知, 本发明实施例的技术方案包括: 收到认证数据请求信息的 归属用户服务器 HSS,为发出附着请求信息的 MTC设备指定一个进行小数 据传输的 MTC 互通功能实体 MTC-IWF; 所述 HSS 生成 MTC设备与 MTC-IWF之间的共享密钥 Kiwf; 所述 HSS将 MTC-IWF信息经由移动管理 实体 MME或通用分组无线业务服务支持节点 SGSN发给 MTC设备; 所述 HSS将 MTC设备信息和生成的共享密钥 Kiwf发送给指定的 MTC-IWF; 所 述 MTC-IWF存储收到的 MTC设备信息和共享密钥 Kiwf; 所述 MTC设备 生成共享密钥 Kiwf。 由此, 针对 MTC系统中部署多个 MTC-IWF的情况, 本发明实施例能够在 MTC设备与 MTC-IWF之间建立共享密钥。 附图说明
图 1是本发明提供的一种用于 MTC小数据传输的密钥建立方法的实施 例的流程示意图;
图 2是本发明提供的一种用于 MTC小数据传输的密钥建立方法的实施 例一的流程示意图;
图 3是本发明提供的一种用于 MTC小数据传输的密钥建立方法的实施 例二的流程示意图;
图 4是本发明提供的一种用于 MTC小数据传输的密钥建立方法的实施 例三的流程示意图;
图 5是本发明提供的一种用于 MTC小数据传输的密钥建立系统的实施 例的结构示意图;
图 6是本发明提供的一种用于 MTC小数据传输的密钥建立系统的另一 实施例的结构示意图;
图 7是本发明提供的一种用于 MTC小数据传输的密钥建立系统的设备 结构示意图。 具体实施方式
下文中将参考附图并结合实施例来详细说明本发明。 需要说明的是, 在不冲突的情况下, 本申请中的实施例及实施例中的特征可以相互组合。 本发明提供的一种用于 MTC小数据传输的密钥建立方法的实施例,如 图 1所示, 所述方法包括:
步骤 101、 收到认证数据请求信息的归属用户服务器( Home Subscriber Server, HSS ), 为发出附着请求信息的 MTC设备指定一个进行小数据传输 的 MTC-IWF;
步骤 102、所述 HSS生成 MTC设备与 MTC-IWF之间的共享密钥 Kiwf; 步骤 103、所述 HSS将 MTC-IWF信息经由移动管理实体 MME或通用 分组无线业务服务支持节点 SGSN发给 MTC设备;
步骤 104、所述 HSS将 MTC设备信息和生成的共享密钥 Kiwf发送给指 定的 MTC-IWF;
步骤 105、 所述 MTC-IWF存储收到的 MTC设备信息和共享密钥 Kiwf; 步骤 106、 所述 MTC设备生成共享密钥 Kiwf
较佳地,在所述 HSS生成 MTC设备与 MTC-IWF之间的共享密钥 Kiwf 之后, 所述方法还包括:
所述 HSS通过共享密钥 Kiwf生成下一级密钥;
相应的, 在 MTC设备生成共享密钥 Kiwf之后, 所述方法还包括:
MTC设备通过共享密钥 Kiwf生成下一级密钥。
较佳地, 在 MTC设备生成共享密钥 Kiwf之后, 所述方法还包括:
MTC设备经由 MME或 SGSN向 MTC-IWF发送安全关联请求信息;
MTC-IWF收到安全关联请求信息后,根据存储的共享密钥 Kiw † MTC 设备进行认证, 并通过所述共享密钥 Kiwf生成下一级密钥;
MTC-IWF向 MTC设备发送安全关联响应信息;
MTC设备根据存储的共享密钥 ^对 MTC-IWF进行认证, 并通过所 述共享密钥 Kiwf生成下一级密钥。
较佳地, 所述下一级密钥包括加密密钥和完整性保护密钥。 较佳地, 所述认证数据请求信息包括 MTC设备的身份信息和 MTC设 备 MTC能力信息和发送 /接收小数据能力信息;
相应的,所述为发出附着请求信息的 MTC设备指定一个进行小数据传 输的 MTC-IWF为:
HSS根据所述 MTC设备 MTC能力信息、发送 /接收小数据能力信息以 及自身存储的各 MTC-IWF的信息, 为发出附着请求信息的 MTC设备指定 一个进行小数据传输的 MTC-IWF。
实施例一
该实施例一中, MTC设备附着时与 MTC-IWF生成共享密钥 Kiwf, 具 体地, 如图 2所示, 包括以下步骤:
步骤 201, MTC设备向 MME发送附着请求信息;
这里, 所述附着请求信息中包含 MTC设备的身份信息, 如国际移动用 户识别码 ( International Mobile Subscriber Identification Number, IMSI )、 国 际移动设备身份码 ( International Mobile Equipment Identity, IMEI )、 或者 其他可以用以标识 MTC设备的身份信息, 还包含 MTC设备 MTC能力信 息和发送 /接收 d、数据能力信息。
步骤 202, MME向 HSS发送认证数据请求信息;
这里, 所述认证数据请求信息包括 MTC设备的身份信息, 如 IMSI、 IMEI、 或者其他可以用以标识 MTC设备的身份信息, 还包含 MTC设备 MTC能力信息和发送 /接收小数据能力信息。
步骤 203, HSS根据 MTC设备的签约信息生成认证响应数据, 同时为 MTC 设备指定一个进行小数据传输的 MTC-IWF, 并生成 MTC 设备与 MTC-IWF之间的共享密钥 Kiwf;
这里, 所述共享密钥 Kiwf可以才艮据密钥生成算法生成, 具体的, 可以 由接入安全管理实体( Access Security Management Entity, ASME )根据密 钥生成算法生成;
这里, HSS可以根据附着的 MTC设备 MTC能力信息、发送 /接收小数 据能力信息以及自身存储的各 MTC-IWF的信息, 为附着的 MTC设备确定 进行小数据传输的 MTC-IWF。
步骤 204, HSS将 MTC-IWF信息与认证响应数据一起发送给 MME; 这里,所述 MTC-IWF信息可以是任何用以标识 MTC-IWF身份的信息。 步骤 205, HSS将 MTC设备信息和生成的共享密钥 Kiwf发送给指定的 MTC-IWF;
这里,所述 MTC设备信息可以是 MTC设备的身份信息,如 IMSI、 IMEI 或其他可以用以标识 MTC设备的身份信息。
步骤 206, MTC-IWF接收、 保存共享密钥 Kiwf和 MTC设备信息, 并 对保存的共享密钥 ^和 MTC设备信息进行维护和管理。
步骤 207, MME与 MTC设备间进一步完成互认证。
步骤 208、 MME将 MTC-IWF信息发给 MTC设备。
步骤 209、 MTC设备存储所述 MTC-IWF信息, 并对存储的 MTC-IWF 信息进行维护和管理。
步骤 210、 MTC设备根据密钥生成算法生成共享密钥 Kiwf并保存。 当 MTC设备进行小数据传输时, MTC设备需要根据其上存储的 MTC 设备与 MTC-IWF 之间的关联信息, 指明小数据需要发送到指定的 MTC-IWF以实现小数据的传输。 当 MTC-IWF从小数据源, 如 MTC服务 器、网络服务器、其他网络实体或其他 MTC设备,收到小数据时, MTC-IWF 需要根据其上存储的 MTC设备与 MTC-IWF之间的关联信息, 判断是否可 以向 MTC设备转发小数据, 如果可以向 MTC设备转发小数据, 则将小数 据转发到指定的 MTC设备, 以实现小数据的传输; 否则, 该 MTC-IWF不 进行小数据的转发, 并可以进一步根据系统需要, 向小数据源反馈小数据 转发失败的信息。
实施例二
该实施例二中, 根据系统需要或根据小数据传输安全保护需要, MTC 设备与 MTC-IWF在共享密钥 Kiwf基础上进一步生成小数据加密密钥和小数 据完整性保护密钥, 该过程可以在附着过程中完成, 与实施例一相比, 该 实施例二的不同之处在于, 共享密钥生成步骤中进一步包括了用于小数据 传输安全保护的下一级密钥的生成方式, 具体地, 如图 3 所示, 包括如下 步骤:
步骤 301, MTC设备向 MME发送附着请求信息;
这里, 所述附着请求信息中包含 MTC设备的身份信息, 如 IMSI, 还 包含 MTC设备 MTC能力信息和发送 /接收小数据能力信息。
步骤 302, MME向 HSS发送认证数据请求信息。
步骤 303: HSS根据 MTC设备的签约信息生成认证响应数据, 同时为 MTC 设备指定一个进行小数据传输的 MTC-IWF, 并生成 MTC 设备与 MTC-IWF之间的共享密钥 Kiwf, 并通过共享密钥 Kiwf生成用于保护小数据 安全传输的下一级密钥, 如加密密钥和完整性保护密钥;
这里, 所述共享密钥 Kiwf可以才艮据密钥生成算法生成, 具体的, 可以 由 Kasme根据密钥生成算法生成。
步骤 304, HSS将 MTC-IWF信息与认证响应数据一起发送给 MME; 这里,所述 MTC-IWF信息可以是任何用以标识 MTC-IWF身份的信息。 步骤 305, HSS将 MTC设备信息和生成的共享密钥 Kiwf、 加密密钥和 完整性保护密钥发送给指定的 MTC-IWF。
步骤 306, MTC-IWF接收、保存 MTC设备信息和生成的共享密钥 Kiwf、 加密密钥和完整性保护密钥,并对保存的 MTC设备信息和生成的共享密钥 Kiwf、 加密密钥和完整性保护密钥进行维护和管理。 步骤 307, MME与 MTC设备间进一步完成互认证。
步骤 308、 MME将 MTC-IWF信息发给 MTC设备。
步骤 309、 MTC设备存储所述 MTC-IWF信息, 并对存储的 MTC-IWF 信息进行维护和管理。
步骤 310、 MTC设备根据密钥生成算法生成共享密钥 Kiwf, 并通过共 享密钥 Kiwf生成用于保护小数据安全传输的下一级密钥, 如加密密钥和完 整性保护密钥, 并保存所述共享密钥 Kiwf、 加密密钥和完整性保护密钥。
实施例三
该实施例中, MTC设备附着时, MTC设备与 MTC-IWF生成共享密钥 Kiwf, 根据系统需要或根据小数据传输安全保护需要, 在附着并生成共享密 钥 ^后, MTC设备发起生成与 MTC-IWF之间的用于小数据传输安全保 护的下一级密钥的生成过程, 如图 4所示, 该方法可以包括以下几个步骤: 步骤 401,在生成共享密钥 Kiwf之后, MTC设备经由 MME向 MTC-IWF 发送安全关联请求信息;
这里, 所述安全关联请求信息中可以包括安全算法信息、 MTC设备信 息、 及其他用于认证和密钥生成的信息;
具体的, 所述安全关联请求信息可以通过 NAS信令进行发送。
步骤 402, MTC-IWF收到安全关联请求信息后,根据存储的共享密钥 ^对 MTC设备进行认证, 并通过共享密钥 Kiwf生成用于保护小数据安全 传输的下一级密钥, 如加密密钥和完整性保护密钥。
步骤 403, MTC-IWF向 MTC设备发送安全关联响应信息;
这里,所述安全关联响应信息可以包括安全算法信息、 MTC-IWF信息、 及其他用于认证和密钥生成的信息。
步骤 404, MTC设备根据存储的共享密钥 Kiwf对 MTC-IWF进行认证, 并通过共享密钥 Kiwf生成用于保护小数据安全传输的下一级密钥, 如加密 密钥和完整性保护密钥。
步骤 405, MTC设备与 MTC-IWF之间通过生成的加密密钥和完整性 保护密钥进行小数据安全传输。
在上述实施例一、 二、 三中, 也可以使用 SGSN代替 MME。
对应于上述用于 MTC小数据传输的密钥建立方法,本发明提供的一种 用于 MTC小数据传输的密钥建立系统的实施例, 如图 5所示, 所述系统包 括: HSS 501、 MTC设备 502和多个 MTC-IWF503, 其中,
所述 HSS 501 , 配置为在收到认证数据请求信息后, 为发出附着请求信 息的 MTC设备 502指定一个进行小数据传输的 MTC-IWF 503, 建立并存 储 MTC设备 502与 MTC-IWF 503之间的关联关系; 生成 MTC设备 502 与 MTC-IWF503之间的共享密钥 Kiwf; 将 MTC-IWF信息经由移动管理实 体 MME或通用分组无线业务服务支持节点 SGSN发给 MTC设备 502; 将 MTC设备信息和生成的共享密钥 Kiwf发送给指定的 MTC-IWF 503;
所述 MTC-IWF 503,配置为存储收到的 MTC设备信息和共享密钥 Kiwf; 所述 MTC设备 502, 配置为存储收到的 MTC-IWF信息和生成共享密 钥 Kiwf
较佳地, 所述 HSS 501 , 还配置为通过共享密钥 Kiwf生成下一级密钥; 所述 MTC设备 502, 还配置为通过共享密钥 Kiwf生成下一级密钥。 较佳地, 所述 MTC 设备 502, 还配置为经由 MME 或 SGSN 向
MTC-IWF503发送安全关联请求信息; 在收到 MTC-IWF503发来的安全关 联响应信息后, 根据存储的共享密钥 Kiwf对 MTC-IWF503进行认证, 并通 过所述共享密钥 Kiwf生成下一级密钥;
所述 MTC-IWF503 , 还配置为在收到安全关联请求信息后, 根据存储 的共享密钥 Kiw † MTC设备 502进行认证,并通过所述共享密钥 Kiwf生成 下一级密钥; 向 MTC设备 502发送安全关联响应信息。 较佳地, 所述下一级密钥包括加密密钥和完整性保护密钥。 较佳地,所述认证数据请求信息包括 MTC设备 502的身份信息和 MTC 设备 MTC能力信息和发送 /接收小数据能力信息;
相应的, 所述 HSS 501, 配置为根据所述 MTC设备 MTC能力信息、 发送 /接收小数据能力信息以及自身存储的各 MTC-IWF503的信息, 为发出 附着请求信息的 MTC设备 502指定一个进行小数据传输的 MTC-IWF503 , 建立、 存储并维护 MTC设备 502与 MTC-IWF503之间的关联关系。
在实际应用中,本发明提供的用于 MTC小数据传输的密钥建立系统的 实施例, 图如 6所示, 包括: MTC设备 502, 配置为存储 MTC-IWF信息 和小数据传输共享密钥信息; MME504, 配置为 NAS信令过程; HSS501 , 配置为管理维护 MTC-IWF信息, 也可以用于管理和维护 MTC设备信息, 也可以用于建立、 存储并维护 MTC设备 502与 MTC-IWF503之间的关联 关系, 为 MTC设备 502指定一个进行小数据传输的 MTC-IWF503 , 生成 MTC设备 502与 MTC-IWF503之间的共享密钥; 各 MTC-IWF, 本例中为 MTC-IWF 1503和 MTC-IWF2 503, 用于存储 MTC设备信息和小数据传输 共享密钥信息。
图 7是本发明实施例用于 MTC小数据传输的密钥建立系统的设备结构 示意图, 如图 7所示, 该系统的设备可以包括: MTC设备 502、 MME504、 MTC-IWF503和 HSS501。
具体地, 如图 7所示, 所述系统的设备具体包括:
第一存储管理单元 5021, 配置为存储管理 MTC设备信息和密钥信息; 第二存储管理单元 5031, 配置为存储管理 MTC-IWF信息和密钥信息; 第三存储管理单元 5011,配置为存储管理 MTC-IWF信息和 MTC设备 信息, 存储管理 MTC-IWF与 MTC设备的关联信息;
分配单元 5012, 配置为根据 MTC 设备附着信息分配指定关联的 MTC-IWF;
第一发送 /接收单元 5022、 第二发送 /接收单元 5032、 第三发送 /接收单 元 5013, 配置为信令信息、 密钥信息、 设备信息和小数据的发送和接收; 判断单元 5033, 配置为判断所述 MTC-IWF是否可以转发小数据信息; 第一密钥协商单元 5023、 第二密钥协商单元 5034, 配置为协商共享密 钥, 如加密密钥和完整性密钥。
在实际应用中, 上述各单元可以由其所属装置中的中央处理器(CPU, Central Processing Unit )、 数字信号处理器(DSP, Digital Signal Processor ) 或可编程逻辑阵列 (FPGA, Field - Programmable Gate Array ) 实现。
在上述实施例中, 也可以使用 SGSN代替 MME。
显然, 本领域的技术人员应该明白, 上述的本发明的各模块或各步骤 可以用通用的计算装置来实现, 它们可以集中在单个的计算装置上, 或者 分布在多个计算装置所组成的网络上, 可选地, 它们可以用计算装置可执 行的程序代码来实现, 从而, 可以将它们存储在存储装置中由计算装置来 执行, 并且在某些情况下, 可以以不同于此处的顺序执行所示出或描述的 步骤, 或者将它们分别制作成各个集成电路模块, 或者将它们中的多个模 块或步骤制作成单个集成电路模块来实现。 这样, 本发明不限制于任何特 定的硬件和软件结合。
以上所述仅为本发明的优选实施例而已, 并不用于限制本发明, 对于 本领域的技术人员来说, 本发明可以有各种更改和变化。 凡在本发明的精 神和原则之内, 所作的任何修改、 等同替换、 改进等, 均应包含在本发明 的保护范围之内。

Claims

权利要求书
1、 一种用于机器类通信 MTC小数据传输的密钥建立方法, 所述方法 包括:
收到认证数据请求信息的归属用户服务器 HSS, 为发出附着请求信息 的 MTC设备指定一个进行小数据传输的 MTC互通功能实体 MTC-IWF;
所述 HSS生成 MTC设备与 MTC-IWF之间的共享密钥 Kiwf;
所述 HSS将 MTC-IWF信息经由移动管理实体 MME或通用分组无线 业务服务支持节点 SGSN发给 MTC设备;
所述 HSS 将 MTC 设备信息和生成的共享密钥 Kiwf发送给指定的 MTC-IWF;
所述 MTC-IWF存储收到的 MTC设备信息和共享密钥 Kiwf;
所述 MTC设备生成共享密钥 Kiwf
2、 根据权利要求 1所述的方法, 其中, 在所述 HSS生成 MTC设备与 MTC-IWF之间的共享密钥 Kiwf之后, 所述方法还包括:
所述 HSS通过共享密钥 Kiwf生成下一级密钥;
相应的, 在 MTC设备生成共享密钥 Kiwf之后, 所述方法还包括:
MTC设备通过共享密钥 Kiwf生成下一级密钥。
3、根据权利要求 1所述的方法, 其中,在 MTC设备生成共享密钥 Kiwf 之后, 所述方法还包括:
MTC设备经由 MME或 SGSN向 MTC-IWF发送安全关联请求信息; MTC-IWF收到安全关联请求信息后,根据存储的共享密钥 Kiw † MTC 设备进行认证, 并通过所述共享密钥 Kiwf生成下一级密钥;
MTC-IWF向 MTC设备发送安全关联响应信息;
MTC设备根据存储的共享密钥 ^对 MTC-IWF进行认证, 并通过所 述共享密钥 Kiwf生成下一级密钥。
4、 根据权利要求 2或 3所述的方法, 其中, 所述下一级密钥包括加密 密钥和完整性保护密钥。
5、 根据权利要求 1 所述的方法, 其中, 所述认证数据请求信息包括 MTC设备的身份信息和 MTC设备 MTC能力信息和发送 /接收小数据能力 信息;
相应的,所述为发出附着请求信息的 MTC设备指定一个进行小数据传 输的 MTC-IWF为:
HSS根据所述 MTC设备 MTC能力信息、发送 /接收小数据能力信息以 及自身存储的各 MTC-IWF的信息, 为发出附着请求信息的 MTC设备指定 一个进行小数据传输的 MTC-IWF。
6、 一种用于机器类通信 MTC小数据传输的密钥建立系统, 所述系统 包括: 归属用户服务器 HSS、 MTC 设备和多个 MTC 互通功能实体 MTC-IWF, 其中,
所述 HSS, 配置为在收到认证数据请求信息后, 为发出附着请求信息 的 MTC设备指定一个进行小数据传输的 MTC-IWF; 生成 MTC设备与 MTC-IWF之间的共享密钥 Kiwf;将 MTC-IWF信息经由移动管理实体 MME 或通用分组无线业务服务支持节点 SGSN发给 MTC设备; 将 MTC设备信 息和生成的共享密钥 Kiwf发送给指定的 MTC-IWF;
所述 MTC-IWF, 配置为存储收到的 MTC设备信息和共享密钥 Kiwf; 所述 MTC设备, 配置为生成共享密钥 Kiwf
7、 根据权利要求 6所述的系统, 其中,
所述 HSS, 还配置为通过共享密钥 Kiwf生成下一级密钥;
所述 MTC设备, 还配置为通过共享密钥 Kiwf生成下一级密钥。
8、 根据权利要求 6所述的系统, 其中, 所述 MTC设备, 还配置为经 由 MME或 SGSN向 MTC-IWF发送安全关联请求信息; 在收到 MTC-IWF 发来的安全关联响应信息后,根据存储的共享密钥 Kiw † MTC-IWF进行认 证, 并通过所述共享密钥 Kiwf生成下一级密钥;
所述 MTC-IWF, 还配置为在收到安全关联请求信息后, 根据存储的共 享密钥 Kiw †MTC设备进行认证,并通过所述共享密钥 Kiwf生成下一级密 钥; 向 MTC设备发送安全关联响应信息。
9、 根据权利要求 7或 8所述的系统, 其中, 所述下一级密钥包括加密 密钥和完整性保护密钥。
10、 根据权利要求 6所述的系统, 其中, 所述认证数据请求信息包括 MTC设备的身份信息和 MTC设备 MTC能力信息和发送 /接收小数据能力 信息;
相应的, 所述 HSS, 配置为根据所述 MTC设备 MTC能力信息、 发送 /接收小数据能力信息以及自身存储的各 MTC-IWF的信息, 为发出附着请 求信息的 MTC设备指定一个进行小数据传输的 MTC-IWF。
PCT/CN2013/086244 2013-08-02 2013-10-30 一种用于机器类通信小数据传输的密钥建立方法和系统 WO2014161300A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201310334433.6 2013-08-02
CN201310334433.6A CN104349311A (zh) 2013-08-02 2013-08-02 一种用于机器类通信小数据传输的密钥建立方法和系统

Publications (1)

Publication Number Publication Date
WO2014161300A1 true WO2014161300A1 (zh) 2014-10-09

Family

ID=51657490

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/086244 WO2014161300A1 (zh) 2013-08-02 2013-10-30 一种用于机器类通信小数据传输的密钥建立方法和系统

Country Status (2)

Country Link
CN (1) CN104349311A (zh)
WO (1) WO2014161300A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2531861A (en) * 2014-08-12 2016-05-04 Vodafone Ip Licensing Ltd Machine-to-machine cellular communication security
US20160269907A1 (en) * 2013-10-31 2016-09-15 Nec Corporation Apparatus, system and method for mtc

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20190047143A (ko) * 2013-07-31 2019-05-07 닛본 덴끼 가부시끼가이샤 Mtc 그룹 키 관리를 위한 디바이스들 및 방법
CN106487776B (zh) * 2015-09-02 2020-10-27 中兴通讯股份有限公司 一种保护机器类通信设备的方法、网络实体及系统
CN108616354B (zh) * 2018-04-27 2021-10-26 北京信息科技大学 一种移动通信中密钥协商方法和设备

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102355743A (zh) * 2011-09-23 2012-02-15 电信科学技术研究院 一种ue上下文信息的管理方法和设备
WO2013091383A1 (zh) * 2011-12-22 2013-06-27 电信科学技术研究院 一种确定mtc-iwf实体的方法及装置

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9313747B2 (en) * 2011-07-01 2016-04-12 Intel Corporation Structured codebook for uniform circular array (UCA)

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102355743A (zh) * 2011-09-23 2012-02-15 电信科学技术研究院 一种ue上下文信息的管理方法和设备
WO2013091383A1 (zh) * 2011-12-22 2013-06-27 电信科学技术研究院 一种确定mtc-iwf实体的方法及装置

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
"3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security Aspects of Machine-Type and Other Mobile Data Applications Communications Enhancements; (Release 12", 3GPP TR 33.868, V0.13.0, 30 April 2013 (2013-04-30), pages 73 - 77 *

Cited By (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20160269907A1 (en) * 2013-10-31 2016-09-15 Nec Corporation Apparatus, system and method for mtc
US9848334B2 (en) * 2013-10-31 2017-12-19 Nec Corporation Apparatus, system and method for MTC
US20180070240A1 (en) 2013-10-31 2018-03-08 Nec Corporation Apparatus, system and method for mobile communication
US10299134B2 (en) 2013-10-31 2019-05-21 Nec Corporation Apparatus, system and method for mobile communication
US10306475B2 (en) 2013-10-31 2019-05-28 Nec Corporation Apparatus, system and method for mobile communication
US20190200231A1 (en) * 2013-10-31 2019-06-27 Nec Corporation Apparatus, system, and method for mobile communication
US10681553B2 (en) 2013-10-31 2020-06-09 Nec Corporation Apparatus, system, and method for mobile communication
US11601790B2 (en) 2013-10-31 2023-03-07 Nec Corporation Apparatus, system and method for mobile communication
GB2531861A (en) * 2014-08-12 2016-05-04 Vodafone Ip Licensing Ltd Machine-to-machine cellular communication security

Also Published As

Publication number Publication date
CN104349311A (zh) 2015-02-11

Similar Documents

Publication Publication Date Title
US11627515B2 (en) Method for supporting lawful interception of remote ProSe UE in network
US10601594B2 (en) End-to-end service layer authentication
KR101877733B1 (ko) 기기간 통신 환경에서 그룹 통신을 보안하는 방법 및 시스템
US10142769B2 (en) Method and system for establishing a secure communication between remote UE and relay UE in a device to device communication network
EP3836577B1 (en) Session management method and device for user groups
EP2903322B1 (en) Security management method and apparatus for group communication in mobile communication system
WO2017091959A1 (zh) 一种数据传输方法、用户设备和网络侧设备
AU2018340618B2 (en) Parameter protection method and device, and system
CN104661171B (zh) 一种用于mtc设备组的小数据安全传输方法和系统
KR20160129327A (ko) Mtc에서의 네트워크와의 상호 인증 방법 및 시스템
KR20160078426A (ko) 무선 직접통신 네트워크에서 비대칭 키를 사용하여 아이덴티티를 검증하기 위한 방법 및 장치
JP2018525939A (ja) セキュリティ認証方法、構成方法、および関連デバイス
KR20150051568A (ko) 이동 통신 시스템 환경에서 프락시미티 기반 서비스 단말 간 발견 및 통신을 지원하기 위한 보안 방안 및 시스템
WO2012094879A1 (zh) 一种mtc服务器共享密钥的方法及系统
WO2014161300A1 (zh) 一种用于机器类通信小数据传输的密钥建立方法和系统
JP2024507208A (ja) セルラネットワークを動作させるための方法
WO2012075814A1 (zh) 一种mtc组设备的应用密钥管理方法及系统
CN110943835A (zh) 一种发送无线局域网信息的配网加密方法及系统
KR100892616B1 (ko) 무선 센서 네트워크에서의 새로운 장치 참여 방법
WO2015139370A1 (zh) Mtc设备组小数据安全传输连接建立方法、hss与系统
CN103200191A (zh) 通信装置和无线通信方法
Singh et al. Lightweight multilevel key management scheme for large scale wireless sensor network
US20230308864A1 (en) Wireless communication method, apparatus, and system
WO2022237671A1 (zh) 组寻呼的方法和装置
WO2022032525A1 (zh) 一种组密钥分发方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13880906

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 13880906

Country of ref document: EP

Kind code of ref document: A1