MTC KEY MANAGEMENT FOR SENDING KEY FROM NETWORK TO UE

    公开(公告)号:EP3589001A1

    公开(公告)日:2020-01-01

    申请号:EP19193175.7

    申请日:2013-12-03

    申请人: NEC Corporation

    摘要: A root key (K_iwf) is derived at a network and sent to MTC UE. The K_iwf is used for deriving subkeys for protecting communication between MTC UE and MTC-IWF. In a case where HSS (30) derives the K_iwf, HSS send to MTC-IWF the K_iwf in a new message (Update Subscriber Information). In a case where MME derives the K_iwf, MME sends the K_iwf through HSS or directly to MTC-IWF. MTC-IWF can derive the K_iwf itself. The K_iwf is sent through MME to MTC UE by use of a NAS SMC or Attach Accept message, or sent from MTC-IWF directly to MTC UE. In a case where the K_iwf is sent from MME, MME receives the K_iwf from HSS in an Authentication Data Response message, or from MTC-IWF directly.

    APPARATUS, SYSTEM AND METHOD FOR SMALL CELL ENHANCEMENT / DUAL CONNECTIVITY
    4.
    发明公开
    APPARATUS, SYSTEM AND METHOD FOR SMALL CELL ENHANCEMENT / DUAL CONNECTIVITY 审中-公开
    VORRICHTUNG,SYSTEM UND VERFAHREN ZUR KLEINZELLENVERBESSERUNG /DUALKONNEKTIVITÄT

    公开(公告)号:EP3114880A1

    公开(公告)日:2017-01-11

    申请号:EP15712436.3

    申请日:2015-03-05

    申请人: NEC Corporation

    IPC分类号: H04W36/28

    摘要: An SeNB informs an MeNB that it can configure bearers for the given UE. At this time, the MeNB manages the DRB status, and then sends a key S-KeNB to the SeNB. The MeNB also sends a KSI for the S-KeNB to both of the UE and the SeNB. After this procedure, the MeNB informs an EPC (MME and S-GW) about the new bearer configured at the SeNB, such that the S-GW 50 can start offloading the bearer(s) to the SeNB 30. Prior to the offloading, the EPC network entity (MME or S-GW) performs verification that: 1) whether the request is coming from authenticated source (MeNB); and 2) whether the SeNB is a valid eNB to which the traffic can be offload.

    摘要翻译: SeNB通知MeNB可以配置给定UE的承载。 此时,MeNB管理DRB状态,然后向SeNB发送密钥S-KeNB。 MeNB还向UE和SeNB两者发送S-KeNB的KSI。 在该过程之后,MeNB通知EPC(MME和S-GW)关于在SeNB配置的新承载,使得S-GW50可以开始将承载卸载到SeNB 30.在卸载之前, EPC网络实体(MME或S-GW)执行以下验证:1)请求是否来自认证源(MeNB); 和2)SeNB是否是可以卸载流量的有效eNB。

    DEVICES AND METHOD FOR MTC GROUP KEY MANAGEMENT
    7.
    发明公开
    DEVICES AND METHOD FOR MTC GROUP KEY MANAGEMENT 审中-公开
    VORRICHTUNGEN UND VERFAHRENFÜRMTC-GRUPPENSCHLÜSSELMANAGEMENT

    公开(公告)号:EP3028431A1

    公开(公告)日:2016-06-08

    申请号:EP14748300.2

    申请日:2014-07-07

    申请人: NEC Corporation

    摘要: In order to improve security upon distributing a group key, there is provided a gateway (20) to a core network for a group of MTC devices (10_1-10_n) communicating with the core network. The gateway (20) protects confidentiality and integrity of a group key, and distributes the protected group key to each of the MTC devices (10_1-10_n). The protection is performed by using: a key (Kgr) that is preliminarily shared between the gateway (20) and each of the MTC devices (10_1-10_n), and that is used for the gateway (20) to authenticate each of the MTC devices (10_1-10_n) as a member of the group; or a key (K_iwf) that is shared between an MTC-IWF (50) and each of the MTC devices (10_1-10_n), and that is used to derive temporary keys for securely conducting individual communication between the MTC-IWF (50) and each of the MTC devices (10_1-10_n).

    摘要翻译: 为了在分配组密钥时提高安全性,向与核心网络通信的一组MTC设备(10_1-10_n)提供到核心网络的网关(20)。 网关(20)保护组密钥的机密性和完整性,并将保护组密钥分发给每个MTC设备(10_1-10_n)。 通过使用在网关(20)和每个MTC设备(10_1-10_n)之间预先共享的密钥(Kgr)来执行保护,并且用于网关(20)认证每个MTC 设备(10_1-10_n)作为组的成员; 或者在MTC-IWF(50)和每个MTC设备(10_1-10_n)之间共享的密钥(K_iwf),并且用于导出临时密钥以用于安全地执行MTC-IWF(50) 和每个MTC设备(10_1-10_n)。

    SECURE GROUP CREATION IN PROXIMITY BASED SERVICE COMMUNICATION
    8.
    发明公开
    SECURE GROUP CREATION IN PROXIMITY BASED SERVICE COMMUNICATION 审中-公开
    Safe组创作近基于服务通信

    公开(公告)号:EP3014916A1

    公开(公告)日:2016-05-04

    申请号:EP14737017.5

    申请日:2014-06-13

    申请人: NEC Corporation

    IPC分类号: H04W12/08 H04W8/00 H04W4/00

    摘要: A method of forming a secure group in ProSe communication includes requesting a service request to a ProSe server from a requesting device (21), the service request indicating a request to communicate with a receiving device (22) from the requesting device (21), performing verification on the requesting and receiving devices (21) and (22) by the ProSe server 24, sending a ProSe Service Result to the requesting and receiving devices (21) and (22) to inform to be allowed a group member, and starting a group security establishment of the group including the requesting and receiving devices (21) and (22).

    OPTIMIZATION OF MTC DEVICE TRIGGER DELIVERY
    9.
    发明公开
    OPTIMIZATION OF MTC DEVICE TRIGGER DELIVERY 审中-公开
    OPTIMIERUNG DER AUSGABE EINES MTC-VORRICHTUNGS-TRIGGERS

    公开(公告)号:EP2868121A1

    公开(公告)日:2015-05-06

    申请号:EP13725215.1

    申请日:2013-04-23

    申请人: NEC Corporation

    IPC分类号: H04W4/00

    摘要: A network node (21), which is placed within a core network, stores a list of network elements (24) capable of forwarding a trigger message to a MTC device (10). The network node (21) receives the trigger message from a transmission source (30, 40) placed outside the core network, and then selects, based on the list, one of the network elements to forward the trigger message to the MTC device (10). The MTC device (10) validates the received trigger message, and then transmits, when the trigger message is not validated, to the network node (21) a reject message indicating that the trigger message is not accepted by the MTC device (10). Upon receiving the reject message, the network node (21) forwards the trigger message through a different one of the network elements, or forwards the reject message to transmission source (30, 40) to send the trigger message through user plane.

    摘要翻译: 放置在核心网络内的网络节点(21)存储能够将触发消息转发到MTC设备(10)的网元(24)的列表。 网络节点(21)从放置在核心网络外部的发送源(30,40)接收触发消息,然后根据列表选择一个网络元件将触发消息转发到MTC设备(10 )。 MTC设备(10)验证接收到的触发消息,然后当触发消息未被验证时向网络节点(21)发送指示触发消息不被MTC设备(10)接受的拒绝消息。 在接收到拒绝消息时,网络节点(21)通过不同的网络单元转发触发消息,或者将拒绝消息转发到发送源(30,40),以通过用户平面发送触发消息。

    APPARATUS, SYSTEM AND METHOD FOR SECURE DIRECT COMMUNICATION IN PROXIMITY BASED SERVICES

    公开(公告)号:EP3761690A1

    公开(公告)日:2021-01-06

    申请号:EP20191217.7

    申请日:2014-08-27

    申请人: NEC Corporation

    IPC分类号: H04W12/04

    摘要: In order for effectively ensuring security for direct communication in ProSe, a ProSe Function (20) acquires from a 3rd party root keys for each of UEs (10_1-10_m) to derive a pair of session keys for securely conducting direct communication with different UEs, and distributes the acquired root keys to each of the UEs (10_1-10_m). Each of the UEs (10_1-10_m) derives the session keys by using one of the distributed root keys. Moreover, a plurality of UEs, which form a communication system, and are allowed to conduct direct communication with each other when the UEs are in proximity to each other, share public keys of the UEs therebetween through a node which supports the direct communication upon successfully registering the UEs with the node. Each of the UEs verifies at least a request for the direct communication by using one of the public keys.