Tuesday, 12 July 2016

Location Update

Location Update
Once the procedures for authentication and NAS security setup are completed, now the MME has to register the subscriber in the network, and find out what services the subscriber can use. To this end, the MME notifies the HSS the subscriber is registered in the network and located in its TAs, and then downloads information about the subscriber from the HSS. All these are done through the location update procedure, and by using Diameter protocol over the S6a interface between the MME and the HSS. The call flows during this procedure are as in below figure


1) [MME  HSS] Notifying UE Location
The MME sends an Update Location Request (IMSI, MME ID) message to the HSS in order to notify of the UE’s registration and obtain the subscription information of the UE.

2) [HSS] UE Location Update
The HSS registers the MME ID to indicate in which MME the UE is located in.

3) [MME  HSS] Delivering User Subscription Information
The HSS sends the MME subscription information of the subscriber as included in an Update Location Answer message, so that the MME can create an EPS session and a default EPS bearer for the subscriber. The subscription information included in the Update Location Answer message is as follows:
Update Location Answer (IMSI, Subscribed APN, Subscribed P-GW ID, Subscribed QoS Profile)
  Subscribed APN: APN that a user is subscribing to (e.g. Internet service)
  Subscribed P-GW ID: an ID for P-GW through which a user can access the Subscribed APN
 Subscribed QoS Profile5 (UE-AMBR(UL/DL), QCI, ARP, APN-AMBR(UL/DL))
            - UE-AMBR (UL/DL): the aggregate bandwidth of all non-GBR bearers that a UE can have                  Determined by MME and controlled by eNB.
            - QCI, ARP, APN-AMBR (UL/DL): QoS applied to the Subscribed APN

4) [MME] Storing Subscription Information

The MME receives the Update Location Answer message from the HSS, and stores the subscription information from the message.
From the downloaded subscription information, the MME can check what services

LTE Security

LTE Security: Key Concepts

Authentication:
•The LTE Network verifies the UE’s identity by challenging the UT use the keys and report a result.
•The network checks the result against the expected result

Integrity:
•Signaling message receiver verifies that the received message is exactly the message that the transmitter sent
•This is done using an integrity checksum
•Guards against “man in the middle” attacks where the senders messages and intercepted by a hacker and a modified message is relayed to the receiver

Encryption:
•The sender encrypts the data with a secret key that is only known to the receiver
•Only the receiver is able to decode the message
•Guards against hackers listening in on the data

LTE Security Key Hierarchy


Encryption and Integrity Protection in the LTE Control Plan


•LTE supports two levels on security on the control plane
–The NAS traffic between the MME and the UE is protected with NAS level keys
–The RRC connection traffic between the MME and the UE is protected with RRC level keys
•This means that the NAS traffic is being protected with NAS as well as RRC level security



Encryption and Integrity Protection in the LTE User Plane
•User plane data is encrypted with the KUPenc key






LTE NAS Key Derivation at the MME and UE

















LTE RRC Key Derivation at the eNodeB and UE













LTE User Plane Key Derivation at the eNodeB and UE






Key Stream Computation


3GPP Security Specifications:

LTE Security
•33.401: System Architecture Evolution (SAE); Security architecture
•33.402: System Architecture Evolution (SAE); Security aspects of non-3GPP

Lawful Interception
•33.106: Lawful interception requirements
•33.107: Lawful interception architecture and functions
•33.108: Handover interface for Lawful Interception

Key Derivation Function
•33.220: GAA: Generic Bootstrapping Architecture (GBA)

Backhaul Security
•33.310: Network Domain Security (NDS); Authentication Framework (AF)

Relay Node Security
•33.816: Feasibility study on LTE relay node security (also 33.401)

Home (e) Node B Security
•33.320: Home (evolved) Node B Security

























Friday, 8 July 2016

Change of UE mode of operation

Change of UE mode of operation

The UE mode of operation can change as a result of:
-     a change of UE's usage setting for a CS voice capable UE;
-     a change of voice domain preference as defined in  for a CS voice capable UE;
-     a failure of IMS registration; or

-     a change in UE configuration regarding the use of SMS over SGs.



NAS Security Setup


NAS Security Setup
Once user authentication is completed, the MME initiates the NAS security setup procedure so that NAS messages can be securely exchanged between the two entities. Figure 5 shows the call flows in the NAS security setup procedure.





1) [MME] Generating NAS Security Keys
The MME selects ciphering and integrity algorithms to be applied to NAS messages from the Attach Request message received from the UE. Next, it derives a NAS integrity key (KNASint) and a NAS encryption key (KNASenc) from KASME, to be applied to NAS messages.

2) [UE  MME] Helping UE to Generate NAS Security Keys
The MME informs the UE of the selected security algorithms, by including them in a Security Mode Command (KSIASME, Security Algorithm, NAS-MAC) message, helping the UE to generate NAS security keys. The message is sent with its integrity-protected (by including NAS-MAC).

3) [UE] Generating NAS Security Keys
When the UE receives the Security Mode Command message, the UE generates NAS security keys (KNASint and KNASenc) by using the NAS security algorithm that the MME selected, and performs an integrity validation on the Security Mode Command message by using the NAS integrity key (KNASint). If the message passes the integrity check, it can be seen that the NAS security keys are successfully set and properly working between the two entities.

4) [UE  MME] NAS Security Key Generation Complete
The UE informs the MME of the successful generation of NAS security keys by sending a Security Mode Complete (NAS-MAC) message, after having it encrypted and integrity protected using the generated keys.

After completing the above steps, the procedure for NAS security setup between the two entities ends. Then messages between the two thereafter are securely delivered, as encrypted and integrity-protected.







UE mode of operation

A UE attached for EPS services shalloperate in one of the following operation modes:
-     PS mode 1 of operation: the UE registers only to EPS services, and UE's usage setting is "voice centric";
-     PS mode 2 of operation: the UE registers only to EPS services, and UE's usage setting is "data centric" or the UE has no CS voice capability;
-     CS/PS mode 1 of operation: the UE registers to both EPS and non-EPS services, and UE's usage setting is "voice centric"; and

-     CS/PS mode 2 of operation: the UE registers to both EPS and non-EPS services, and UE's usage setting is "data centric" or the UE has no CS voice capability.

NAS Protocol,function

NAS Overview

NAS(non-access stratum) it is a Layer 3 signaling protocol and it is a highest stratum of the control plane between UE and MME at the radio interface Main functions of the protocols that are part of the NAS are:NAS Protocol Functions:
Main functions of the protocols that are part of the NAS are:
-the support of mobility of the user equipment (UE); and
-the support of session management procedures to establish and maintain IP connectivity between the UE and a packet data network gateway (PDN GW).
-NAS security (e.g. integrity protection and ciphering of NAS signalling messages.)

For the support of the above functions, the following procedures are required,
-elementary procedures for EMM(EPS mobility management)
-elementary procedures for ESM(EPS session management)

Linkage between the protocols for EPS mobility management and EPS session management

During the EPS attach procedure, the network activates a default EPS bearer context. Additionally, the network can activate one or several dedicated EPS bearer contexts in parallel. To this purpose the EPS session management messages for the default EPS bearer context activation are transmitted in an information element in the EPS mobility management messages. The UE and the network execute the attach procedure, the default EPS bearer context activation procedure, and the dedicated EPS bearer context activation procedure in parallel. The UE and network shall complete the combined default EPS bearer context activation procedure and the attach procedure before the dedicated EPS bearer context activation procedure is completed. The success of the attach procedure is dependent on the success of the default EPS bearer context activation procedure. If the attach procedure fails, then the ESM procedures also fail.
Except for the attach procedure, during EMM procedures the transmission of ESM messages shall be suspended.

Friday, 1 July 2016

EARFCN Calculation

EARFCN Calculation

LTE EARFCN Equation
Fdownlink = FDL_Low + 0.1 (NDL - NOffset_DL)
Fuplink = FUL_Low + 0.1 (NUL - NOffset_UL)

The channel raster for LTE is 100kHz for all bands, i.e. the carrier centre frequency must be
an integer multiple of 100kHz. This is represented in the equation by the “0.1” value.



Example:
It is possible to utilize the previous equations to calculate the frequency for a given EARFCN.
In addition, it is possible to calculate the EARFCN for a given frequency with a defined uplink and downlink frequency.
The calculation shown in the figure translates a downlink frequency of 2127.4MHz to an EARFCN equal to 174.