Tech-invite3GPPspaceIETFspace
21222324252627282931323334353637384‑5x

Content for  TR 33.859  Word version:  11.1.0

Top   Top   None   None   Next
0…   4…

 

0  Introductionp. 7

Deployments of HSPA UTRAN with part of the RNC functionality, including user plane and signaling protection, moved to HSPA NodeBs present the same threat environment as encountered by E-UTRAN eNBs. To help counter the threats towards the base stations, E UTRAN has introduced a key hierarchy and a key-refresh mechanism, making security breaches of the keys used on the air-interface much less severe. With the current key management in UTRAN it is impossible to achieve the same level of protection as in E-UTRAN.
The introduction of a key hierarchy in UTRAN gives an increased protection level and achieves additional benefits by yielding more secure interworking between UTRAN and E-UTRAN. It also implies a simpler handling in the sense that key management becomes more aligned in the two systems.
Up

1  Scopep. 8

The objective of this work item is to study potential solutions for introducing an "E-UTRAN-like" key hierarchy in UTRAN, to improve the security level in UTRAN in the presence of the new deployment scenarios and to ensure that a security breach in UTRAN will not propagate into E-UTRAN. The study covers the technical feasibility and consequences. The impacts of such potential solution on UTRAN of earlier releases are identified. Interworking with earlier releases of UTRAN, GERAN and E-UTRAN is also studied.
The UTRAN key hierarchy is assumed to be built on top of (R99+) UMTS AKA, without requiring any changes to the authentication protocol or USIM. Therefore, it could in principle be used also in GERAN as long as USIMs are used and the SGSN, MSC/VLR, and ME are updated. However, the benefit of introducing the key hierarchy in GPRS is smaller than for the circuit switched part, as the traffic protection already terminates in the core network. Solution details for GERAN are not discussed further.
The study covers both PS and CS part of UTRAN.
Up

2  Referencesp. 8

The following documents contain provisions which, through reference in this text, constitute provisions of the present document.
  • References are either specific (identified by date of publication, edition number, version number, etc.) or non specific.
  • For a specific reference, subsequent revisions do not apply.
  • For a non-specific reference, the latest version applies. In the case of a reference to a 3GPP document (including a GSM document), a non-specific reference implicitly refers to the latest version of that document in the same Release as the present document.
[1]
TR 21.905: "Vocabulary for 3GPP Specifications".
[2]
SP-070782, "FS on UTRAN key management enhancements".
[3]
TS 33.102: "3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3G Security; Security architecture".
[4]
TS 33.401: "3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3GPP System Architecture Evolution (SAE): Security Architecture".
[5]
TS 24.008: "3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Mobile radio interface Layer 3 specification; Core network protocols; Stage 3".
[6]
TS 24.301: "3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS); Stage 3".
[7]
TS 29.060: "3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; General Packet Radio Service (GPRS); GPRS Tunnelling Protocol (GTP) across the Gn and Gp interface".
[8]
TS 29.274: "3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 3GPP Evolved Packet System (EPS); Evolved General Packet Radio Service (GPRS) Tunnelling Protocol for Control plane (GTPv2-C); Stage 3".
[9]
TS 25.413: "3rd Generation Partnership Project; Technical Specification Group Radio Access Network; UTRAN Iu interface Radio Access Network Application Part (RANAP) signalling".
[10]
TS 25.331: "3rd Generation Partnership Project; Technical Specification Group Radio Access Network; Radio Resource Control (RRC); Protocol Specification".
[11]
TS 23.060: "3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; General Packet Radio Service (GPRS); Service description; Stage 2".
[12]
TS 33.220: "3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Generic Authentication Architecture (GAA); Generic bootstrapping architecture".
[13]
TS 25.423: "3rd Generation Partnership Project; Technical Specification Group Radio Access Network; UTRAN Iur interface RNSAP signalling".
[14]
TS 36.413: "3rd Generation Partnership Project; Technical Specification Group Radio Access Network; Evolved Universal Terrestrial Radio Access Network (E-UTRAN); S1 Application Protocol (S1AP)".
[15]
TS 36.331: "3rd Generation Partnership Project; Technical Specification Group Radio Access Network; Evolved Universal Terrestrial Radio Access (E-UTRA); Radio Resource Control (RRC); Protocol specification".
[16]
TS 29.002: "3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Mobile Application Part (MAP) specification".
[17]
TS 44.018: "3rd Generation Partnership Project; Technical Specification Group GSM/EDGE Radio Access Network; Mobile radio interface layer 3 specification; Radio Resource Control (RRC) protocol".
Up

3  Definitions, symbols and abbreviationsp. 9

3.1  Definitionsp. 9

For the purposes of the present document, the terms and definitions given in TR 21.905 and the following apply. A term defined in the present document takes precedence over the definition of the same term, if any, in TR 21.905.
UTRAN Key Hierarchy:
This refers to the key hierarchy studied in this TR. The root key is KASMEU, see next.
KASMEU:
Root key of the UTRAN key hierarchy. (Relation to KASME is elaborated below)
KRNC:
A key kept in an RNC used to derive keying material for use on the Uu reference point.
ME_U:
A UMTS terminal not aware of the UTRAN key hierarchy
ME_U+:
A UMTS only terminal aware of the UTRAN key hierarchy
SGSN, MSC/VLR, RNC:
Legacy nodes, not upgraded to support the UTRAN key hierarchy
SGSN+, MSC/VLR+, RNC+:
The corresponding nodes upgraded to support the UTRAN key hierarchy
When it is not important for the discussion whether it is an SGSN or an MSC/VLR, the generic term Core Network Node (CNN) will be used to denote the entity. The term CNN+ is used to denote a Core Network Node that is aware of the UTRAN KH.
Up

3.2  Abbreviationsp. 9

For the purposes of the present document, the abbreviations given in TR 21.905 and the following apply. An abbreviation defined in the present document takes precedence over the definition of the same abbreviation, if any, in TR 21.905.
AKA
Authentication and Key Agreement
AV
Authentication Vector
CK
Ciphering Key
CN
Core Network
CNN
Core Network Node
CS
Circuit Switched
DL
Downlink
EPS
Evolved Packet System
E-UTRAN
Evolved UTRAN
GERAN
GSM/EDGE Radio Access Network
HO
Hand over
HSPA
High Speed Packet Access
HSS
Home Subscriber Server
KDF
Key Derivation Function
IE
Information Element
IK
Integrity Key
IRAT
Inter RAT
KSI
Key Set Identifier
LAU
Location Area Update
LSB
Least Significant Bit
LTE
Long Term Evolution
ME
Mobile Entity
MME
Mobility Management Entity
MSC
Mobile services Switching Centre
NAS
Non Access Stratum
NCC
Next-hop Chaining Counter
NH
Next Hop
NW
Network
PLMN
Public Land Mobile Network
PS
Packet Switched
RAN
Radio Access Network
RANAP
RAN Application Part
RAT
Radio Access Technology
RAU
Routing Area Update
RRC
Radio Resource Control
RNC
Radio Network Controller
RNS
Radio Network Subsystem
SGSN
Serving GPRS Support Node
SMC
Security Mode Command
SRNC
Serving RNC
SRNS
Serving RNS
TAU
Tracking Area Update
UE
User Equipment
UEA
UMTS Encryption Algorithm
UIA
UMTS Integrity Algorithm
UICC
Universal Integrated Circuit Card
UL
Uplink
UMTS
Universal Mobile Telecommunications System
UP
User Plane
URA
UTRAN Registration Area
UTRAN
Universal Terrestrial Radio Access Network
UTRAN KH
UTRAN Key Hierarchy
VLR
Visited Location Registry
Up

Up   Top   ToC