Sunday, 17 July 2016

Behaviour of the UE in state EMM-DEREGISTERED and state EMM-REGISTERED

Behaviour of the UE in state EMM-DEREGISTERED and state EMM-REGISTERED

General

In this subclause, the detailed behaviour of the UE in the states EMM-DEREGISTERED and EMM-REGISTERED is described.

UE behaviour in state EMM-DEREGISTERED

The state EMM-DEREGISTERED is entered in the UE, when:
-     the detach or combined detach is performed either by the UE or by the MME
-     the attach request is rejected by the MME
-     the tracking area update request is rejected by the MME
-     the service request procedure is rejected by the MME
-     the UE deactivates all EPS bearer contexts locally
-     the UE is switched on; or
-     when an inter-system change from S1 mode to non‑3GPP access is completed and the non‑3GPP access network provides PDN connectivity to the same EPC.
In state EMM-DEREGISTERED, the UE shall behave according to the substate(NORMAL-SERVICE, LIMITED-SERVICE, ATTEMPTING-TO-ATTACH, PLMN-SEARCH, NO-IMSI, ATTACH-NEEDED, NO-CELL-AVAILABLE)

Primary substate selection

Selection of the substate after power on
When the UE is switched on, the substate shall be PLMN-SEARCH if the USIM is available and valid. The substate chosen after PLMN-SEARCH, following power on is:
-     if no cell can be selected, the substate shall be NO-CELL-AVAILABLE;
-     if no USIM is present, the substate shall be NO-IMSI;
-     if a suitable cell has been found and the PLMN or tracking area is not in the forbidden list, then the substate shall be NORMAL-SERVICE;
-     if the selected cell is in a forbidden PLMN or a forbidden tracking area, then the UE shall enter the substate LIMITED-SERVICE;
-     if the UE is in manual network selection mode and no cell of the selected PLMN has been found, the UE shall enter the substate NO-CELL-AVAILABLE; and
-     if the selected cell is a non-3GPP cell, the substate shall be NO-CELL-AVAILABLE.

Detailed description of UE behaviour in state EMM-DEREGISTERED

NORMAL-SERVICE
The UE shall perform an attach or combined attach procedure.
LIMITED-SERVICE
The UE shall perform an attach or combined attach procedure when entering a cell which provides normal service.
The UE may perform attach for emergency bearer services.
ATTEMPTING-TO-ATTACH
The UE shall:
-     perform an attach or combined attach procedure on the expiry of timers T3411 or T3402;
-     perform an attach or combined attach procedure when the UE enters a new cell in a different tracking area, and the tracking area of the new cell is not in the list of forbidden tracking areas; and
-     perform an attach procedure upon request of the upper layers to establish a PDN connection for emergency bearer services.
PLMN-SEARCH
The UE shall perform PLMN selection. If a new PLMN is selected, the UE shall reset the attach attempt counter and perform the attach or combined attach procedure
The UE may perform attach for emergency bearer services when entering a cell which provides limited service.
NO-IMSI
The UE shall perform cell selection
The UE may perform attach for emergency bearer services.
ATTACH-NEEDED
The UE shall start the attach or combined attach procedure, if still needed, as soon as the access is allowed in the selected cell for one of the access classes of the UE.
If the attach procedure was requested by upper layers to establish a PDN connection for emergency bearer services, the UE shall initiate the attach procedure if the "access class 10" bit broadcasted in the cell indicates that access for emergency calls is allowed.
NO-CELL-AVAILABLE
The UE shall perform cell selection according to and choose an appropriate substate when a cell is found. When the lower layers indicate to prepare for an S101 mode to S1 mode handover and the PLMN identity of the target cell provided with this indication is not in one of forbidden PLMN lists, the UE shall enter substate NORMAL-SERVICE.
NOTE:      It is assumed that the UE can determine the PLMN identity of networks supporting cdma2000®HRPD access from the information broadcast over the radio interface. For the purpose of S101 mode to S1 mode handover, the UE can use the PLMN identity of the visited cdma2000® HRPD network also as PLMN identity of the target cell.

Substate when back to state EMM-DEREGISTERED from another EMM state

When returning to state EMM-DEREGISTERED, the UE shall select a cell.
The substate depends on the result of the cell selection procedure, the outcome of the previously performed EMM specific procedures, on the EPS update status of the UE, on the tracking area data stored in the UE and on the presence of the USIM:
-     If no cell has been found, the substate is NO-CELL-AVAILABLE, until a cell is found.
-     If no USIM is present or if the inserted USIM is considered invalid by the UE, the substate shall be NO-IMSI.
-     If the selected cell is in a tracking area where the UE is allowed to roam, the substate shall be NORMAL-SERVICE.
-     If an attach shall be performed (e.g. network requested re-attach), the substate shall be ATTEMPTING-TO-ATTACH.
-     If a PLMN reselection is needed, the substate shall be PLMN-SEARCH.
-     If the selected cell is in a tracking area where the UE is not allowed to roam, the substate shall be LIMITED-SERVICE; and
-     if the selected cell is a non-3GPP cell, the substate shall be NO-CELL-AVAILABLE.

UE behaviour in state EMM-REGISTERED

The state EMM-REGISTERED is entered at the UE, when:
-     the attach or combined attach procedure is performed by the UE.
In state EMM-REGISTERED, the UE shall behave according to the substate .
Editor's note:  A new substate for UEs attached for emergency bearer services served by a cell with limited services may be required, and this is FFS.

Detailed description of UE behaviour in state EMM-REGISTERED

NORMAL-SERVICE
The UE:
-     shall perform normal, periodic and combined tracking area updating and
-     shall respond to paging.
ATTEMPTING-TO-UPDATE
The UE:
-     shall not send any user data;
-     shall perform tracking area updating on the expiry of timers T3411 or T3402;
-     shall perform tracking area updating when the tracking area of the serving cell has changed and this tracking area is not in the list of forbidden tracking areas; and
-     shall perform a tracking area updating procedure upon request of the upper layers to establish a PDN connection for emergency bearer services.
LIMITED-SERVICE
The UE:
-     shall perform cell selection/reselection.
-     may respond to paging (with IMSI); and
-     may perform attach for emergency bearer services.
PLMN-SEARCH
The UE may enter this substate when it is in automatic network selection mode and the maximum allowed number of subsequently unsuccessful tracking area updating have been performed. The UE may also enter this substate as a result of a tracking area update rejected by the network or as a result of a service request rejected by the network . If a new PLMN is selected, the UE shall reset the tracking area updating attempt counter and perform the tracking area updating or combined tracking area updating procedure.
UPDATE-NEEDED
The UE:
-     shall not send any user data;
-     shall not send signalling information unless as a response to paging;
-     shall perform a tracking area updating procedure upon request by the upper layers to establish a PDN connection for emergency bearer services, if the "access class 10" bit broadcasted in the cell indicates that access for emergency calls is allowed;
-     shall perform cell selection/reselection according to and
-     shall enter the appropriate new substate depending on the EPS update status as soon as the access is allowed in the selected cell for one of the access classes of the UE.
NO-CELL-AVAILABLE
The UE shall perform cell selection/reselection.
ATTEMPTING-TO-UPDATE-MM
The UE:
-     shall perform cell selection/reselection.
-     shall be able to receive and transmit user data and signalling information; and
-     shall perform combined tracking area updating procedure indicating "combined TA/LA updating with IMSI attach" on the expiry of timers T3411 or T3402 or when the UE enters a tracking area not in the list of registered tracking areas.


EMM sublayer states

EMM sublayer states

EMM sublayer states in the UE
The following are the possible EMM states of an EMM entity in the UE.

Main states
The EPS capability is disabled in the UE. No EPS mobility management function shall be performed in this state.

 EMM-DEREGISTERED
In the state EMM-DEREGISTERED, no EMM context has been established and the UE location is unknown to an MME and hence it is unreachable by an MME. In order to establish an EMM context, the UE shall start the attach or combined attach procedure .

 EMM-REGISTERED-INITIATED
A UE enters the state EMM-REGISTERED-INITIATED after it has started the attach or the combined attach procedure and is waiting for a response from the MME.

In the state EMM-REGISTERED an EMM context has been established and a default EPS bearer context has been activated in the UE. When the UE is in EMM-IDLE mode, the UE location is known to the MME with an accuracy of a list of tracking areas containing a certain number of tracking areas. When the UE is in EMM-CONNECTED mode, the UE location is known to the MME with an accuracy of a serving eNodeB. The UE may initiate sending and receiving user data and signalling information and reply to paging. Additionally, tracking area updating or combined tracking area updating procedure is performed.

A UE enters the state EMM-DEREGISTERED-INITIATED after it has requested release of the EMM context by starting the detach or combined detach procedure and is waiting for a response from the MME

 EMM-TRACKING-AREA-UPDATING-INITIATED
A UE enters the state EMM-TRACKING-AREA-UPDATING-INITIATED after it has started the tracking area updating or combined tracking area updating procedure and is waiting for a response from the MME.

 EMM-SERVICE-REQUEST-INITIATED
A UE enters the state EMM-SERVICE-REQUEST-INITIATED after it has started the service request procedure and is waiting for a response from the MME.

Substates of state EMM-DEREGISTERED
The state EMM-DEREGISTERED is subdivided into a number of substates as described in this subclause. Valid subscriber data are available for the UE before it enters the substates, except for the substate EMM-DEREGISTERED.NO-IMSI.
EMM-DEREGISTERED.NORMAL-SERVICE
The substate EMM-DEREGISTERED.NORMAL-SERVICE is chosen in the UE, if the EPS update status is EU1 or EU2, in the meantime a cell has been selected and the PLMN or tracking area is not in the forbidden list.
EMM-DEREGISTERED.LIMITED-SERVICE
The substate EMM-DEREGISTERED.LIMITED-SERVICE is chosen in the UE, if the EPS update status is EU3, and it is known that a selected cell is unable to provide normal service (e.g. the selected cell is in a forbidden PLMN, is in a forbidden tracking area or has a CSG ID not included in the UE's Allowed CSG list).
EMM-DEREGISTERED.ATTEMPTING-TO-ATTACH
The substate EMM-DEREGISTERED.ATTEMPTING-TO-ATTACH is chosen in the UE, if the EPS update status is EU2, and a previous attach was rejected.
EMM-DEREGISTERED.PLMN-SEARCH
The substate EMM-DEREGISTERED.PLMN-SEARCH is chosen in the UE, if the UE with a valid USIM is switched on.
EMM-DEREGISTERED.NO-IMSI
The substate EMM-DEREGISTERED.NO-IMSI is chosen in the UE, if the UE is switched on without a valid USIM inserted.
EMM-DEREGISTERED.ATTACH-NEEDED
Valid subscriber data are available for the UE and for some reason an attach must be performed as soon as possible. This substate can be entered if the access class is blocked due to access class control, or if the network rejects the NAS signalling connection establishment.
EMM-DEREGISTERED.NO-CELL-AVAILABLE
No E-UTRAN cell can be selected. This substate is entered after a first intensive search failed when in substate EMM-DEREGISTERED.PLMN-SEARCH. Cells are searched for at a low rhythm. No EPS services are offered.
Substates of state EMM-REGISTERED
EMM-REGISTERED.NORMAL-SERVICE
The substate EMM-REGISTERED.NORMAL-SERVICE is chosen by the UE as the primary substate when the UE enters the state EMM-REGISTERED.
EMM-REGISTERED.ATTEMPTING-TO-UPDATE
The substate EMM-REGISTERED.ATTEMPTING-TO-UPDATE is chosen by the UE if the tracking area updating or combined tracking area updating procedure failed due to a missing response from the network. No EMM procedure except the tracking area updating or combined tracking area updating procedure shall be initiated by the UE in this substate. No data shall be sent or received.
EMM-REGISTERED.LIMITED-SERVICE
The substate EMM-REGISTERED.LIMITED-SERVICE is chosen in the UE, if the cell the UE selected is known not to be able to provide normal service.
EMM-REGISTERED.PLMN-SEARCH
The substate EMM-REGISTERED.PLMN-SEARCH is chosen in the UE, while the UE is searching for PLMNs.
EMM-REGISTERED.UPDATE-NEEDED
The UE has to perform a tracking area updating or combined tracking area updating procedure, but access to the current cell is barred. This state can be entered if the access class is blocked due to access class control, or if the network rejects the NAS signalling connection establishment. No EMM procedure except tracking area updating or combined tracking area updating or service request as a response to paging shall be initiated by the UE in this substate.
EMM-REGISTERED.NO-CELL-AVAILABLE
E-UTRAN coverage has been lost. In this substate, the UE shall not initiate any EMM procedures except for cell and PLMN reselection.
EMM-REGISTERED.ATTEMPTING-TO-UPDATE-MM
A combined attach procedure or a combined tracking area updating procedure was successful for EPS services only. User data and signalling information may be sent and received.
EMM-REGISTERED.IMSI-DETACH-INITIATED
The UE performs a combined detach procedure for non-EPS services only (detach type "IMSI detach"). This substate is entered if the UE is attached for EPS and non-EPS services and wants to detach for non-EPS services only. User data and signalling information may be sent and received.
EPS update status
In order to describe the detailed UE behaviour, the EPS update (EU) status pertaining to a specific subscriber is defined.
The EPS update status is stored in a non-volatile memory in the USIM if the corresponding file is present in the USIM, else in the non-volatile memory in the ME, as described in annex C.
The EPS update status value is changed only after the execution of an attach or combined attach, network initiated detach, authentication, tracking area update or combined tracking area update, service request or paging for EPS services using IMSI procedure.
EU1: UPDATED
      The last attach or tracking area updating attempt was successful.
EU2: NOT UPDATED
      The last attach, service request or tracking area updating attempt failed procedurally, i.e. no response or reject message was received from the MME.
EU3: ROAMING NOT ALLOWED
      The last attach, service request or tracking area updating attempt was correctly performed, but the answer from the MME was negative (because of roaming or subscription restrictions).
EMM sublayer states in the MME
EMM-DEREGISTERED
In the state EMM-DEREGISTERED, the MME has no EMM context or the EMM Context is marked as detached. The UE is detached. The MME may answer to an attach or a combined attach procedure initiated by the UE.
EMM-COMMON-PROCEDURE-INITIATED
The MME enters the state EMM-COMMON-PROCEDURE-INITIATED, after it has started a common EMM procedure and is waiting for a response from the UE.
EMM-REGISTERED
In the state EMM-REGISTERED, an EMM context has been established and a default EPS bearer context has been activated in the MME.
EMM-DEREGISTERED-INITIATED
The MME enters the state EMM-DEREGISTERED-INITIATED after it has started a detach procedure and is waiting for a response from the UE.



Coordination between EMM and GMM

If GMM and EMM are both enabled, a UE capable of S1 mode and A/Gb mode or Iu mode or both shall maintain one common registration for GMM and EMM indicating whether the UE is registered for packet services or not.
A UE that is not registered shall be in state GMM-DEREGISTERED and in state EMM-DEREGISTERED.
If the UE performs a successful attach or combined attach procedure in S1 mode, it shall enter substates GMM-REGISTERED.NO-CELL-AVAILABLE and EMM-REGISTERED.NORMAL-SERVICE.
If the UE performs a successful GPRS attach or combined GPRS attach procedure in A/Gb or Iu mode, it shall enter substates GMM-REGISTERED.NORMAL-SERVICE and EMM-REGISTERED.NO-CELL-AVAILABLE.
After successful completion of routing area updating or combined routing area updating and tracking area updating or combined tracking area updating procedures in both S1 mode and A/Gb or Iu mode, if the network has indicated that ISR is activated, the UE shall maintain registration and related periodic update timers in both GMM and EMM.

Coordination between EMM and MM

UEs that operate in CS/PS mode 1 or CS/PS mode 2 of operation shall use the combined EPS/IMSI attach procedure in order to attach to both EPS and non-EPS services.
UEs that operate in CS/PS mode 1 or CS/PS mode 2 of operation and are already attached to both EPS and non-EPS services shall use the combined tracking area updating and periodic tracking area updating procedures.
UEs that operate in CS/PS mode 1 or CS/PS mode 2 of operation and are already attached to both EPS and non-EPS services shall perform a combined detach procedure in order to detach for non-EPS services.
UEs that operate in CS/PS mode 1 or CS/PS mode 2 of operation should not use any MM timers related to MM specific procedures (e.g. T3210, T3211, T3212, T3213) while camped on E-UTRAN, unless the re-activation of these timers is explicitly described. If the MM timers are already running, the UE should not react on the expiration of the timers.


Wednesday, 13 July 2016

Elementary procedures for EPS mobility management

Elementary procedures for EPS mobility management 

The main function of the mobility management sublayer is to support the mobility of a user equipment, such as informing the network of its present location and providing user identity confidentiality.

A further function of the mobility management sublayer is to provide connection management services to the session management (SM) sublayer and the short message services (SMS) entity of the connection management (CM) sublayer.


Types of EMM procedures
Depending on how they can be initiated, three types of EMM procedures can be distinguished:
1)   EMM common procedures:
      An EMM common procedure can always be initiated whilst a NAS signalling connection exists.               The procedures belonging to this type are:

      Initiated by the network:
-     GUTI reallocation;
-     authentication;
-     security mode control;
-     identification;
-     EMM information.

2)   EMM specific procedures:
      At any time only one UE initiated EMM specific procedure can be running. The procedures 
      belonging to this type are:

      Initiated by the UE and used to attach the IMSI in the network for EPS services and/or non-EPS              services, and to establish an EMM context and a default bearer:
-     attach and combined attach.

      Initiated by the UE and used to attach the IMSI or IMEI for emergency bearer services, and to                 establish an EMM context and a default bearer to a PDN that provides emergency bearer services:
-     attach.

      Initiated by the UE or the network and used to detach the IMSI in the network for EPS services               and/or non-EPS services and to release an EMM context and all bearers:
-     detach andcombined detach.

      Initiated by the UE when an EMM context has been established:
-     normal tracking area updating and combined tracking area updating (S1 mode only);
-     periodic tracking area updating (S1 mode only).

      The tracking area updating procedure can be used to request also the resource reservation for                sending data.

3)   EMM connection management procedures (S1 mode only):

      Initiated by the UE and used to establish a secure connection to the network or to request the               resource reservation for sending data, or both:
-     service request.
      The service request procedure can only be initiated if no UE initiated EMM specific procedure is          ongoing.

      Initiated by the network and used to request the establishment of a NAS signalling connection or         to prompt the UE to re-attach if necessary as a result of a network failure:
-     paging procedure.
      Initiated by the UE or the network and used to transport NAS messages:
-     transport of NAS messages.
      The transport of NAS messages procedure cannot be initiated while an EMM specific procedure         or a service request procedure is ongoing.

NAS security (as per spec:24.301)

          NAS security

4.4.1  General

This clause describes the principles for the handling of EPS security contexts in the UE and in the MME and the procedures used for the security protection of EPS NAS messages between UE and MME. Security protection involves integrity protection and ciphering of the EMM and ESM NAS messages.
The signalling procedures for the control of NAS security are part of the EMM protocol and are described in detail in clause 5.
NOTE:      The use of ciphering in a network is an operator option. In this subclause, for the ease of description, it is assumed that ciphering is used, unless explicitly indicated otherwise. Operation of a network without ciphering is achieved by configuring the MME so that it always selects the "null ciphering algorithm", EEA0.

4.4.2  Handling of EPS security contexts

4.4.2.1            General

The security parameters for authentication, integrity protection and ciphering are tied together in an EPS security context and identified by a key set identifier for E-UTRAN (eKSI). The relationship between the security parameters is defined in 3GPP TS 33.401 [19].
Before security can be activated, the MME and the UE need to establish an EPS security context. Usually, the EPS security context is created as the result of an authentication procedure between MME and UE. Alternatively, during inter-system handover from A/Gb mode to S1 mode or Iu mode to S1 mode, the MME and the UE derive a mapped EPS security context from a UMTS security context that has been established while the UE was in A/Gb mode or Iu mode.
The key set identifier eKSI is assigned by the MME either during the authentication procedure or, for the mapped security context, during the handover procedure. The eKSI consists of a value and a type of security context parameter indicating whether an EPS security context is a native EPS security context or a mapped EPS security context. When the EPS security context is a native EPS security context, the eKSI has the value of KSIASME, and when the current EPS security context is a mapped EPS security context, the eKSI has the value of KSISGSN.
The eKSI can be used to establish the secure exchange of NAS messages at the next establishment of a NAS signalling connection without executing a new authentication procedure (see subclause 4.4.2.3).To this purpose the initial NAS messages (ATTACH REQUEST, TRACKING AREA UPDATE REQUEST, DETACH REQUEST, SERVICE REQUEST and EXTENDED SERVICE REQUEST) and the SECURITY MODE COMMAND message contain an eKSI in the NAS key set identifier IE or the value part of eKSI in the KSI and sequence number IE indicating the current EPS security context used to integrity protect the message.
In the present document, when the UE is required to delete an eKSI, the UE shall set the eKSI to the value "no key is available" and consider also the associated keys KASME or K'ASME , EPS NAS ciphering key and EPS NAS integrity key invalid (i.e. the EPS NAS security context associated with the eKSI as no longer valid).
NOTE:      In some specifications the term ciphering key sequence number might be used instead of the term Key Set Identifier (KSI).
The EPS security context is taken into use, when the MME initiates a security mode control procedure or, if it is a mapped EPS security context, during the inter-system handover procedure. The security context which has been taken into use by the network most recently is called current security context.
The UE and the MME need to be able to maintain two EPS security contexts simultaneously, since:
-     after a re-authentication, the UE and the MME can have both a current EPS security context and a non-current EPS security context which has not yet been taken into use; and
-     after an inter-system handover from A/Gb mode to S1 mode or Iu mode to S1 mode, the UE and the MME can have both a mapped EPS security context which is the current EPS security context and a native EPS security context that was created during a previous access in S1 mode or S101 mode.
The number of EPS security contexts that need to be maintained simultaneously by the UE and the MME is limited by the following requirements:
-     After a successful (re-)authentication, the MME and the UE shall delete any old EPS security context different from the current EPS security context.
-     When a new EPS security context is taken into use through a security mode control procedure, the MME and the UE shall delete the previously current EPS security context.
-     When a new EPS security context is taken into use during the inter-system handover from A/Gb mode to S1 mode or Iu mode to S1 mode, the MME and the UE shall not delete the previously current native EPS security context.
-     When the MME and the UE derive a new mapped EPS security context during inter-system handover from A/Gb mode to S1 mode or Iu mode to S1 mode, the MME and the UE shall delete any existing mapped EPS security context.
-     When a native EPS security context is taken into use, the MME and the UE shall delete any mapped EPS security context.
When the UE moves from EMM-CONNECTED to EMM-IDLE, it shall storethe current EPS security context as specified in annex C.
The UE shall mark the EPS security context (stored according to annex C) as invalid:
-     when the UE moves from EMM-IDLE to EMM-CONNECTED; or
-     when the UE moves from EMM-DEREGISTERED to EMM-REGISTERED.

4.4.2.2            Establishment of a mapped EPS security context during intersystem handover

In order for the UE to derive a mapped EPS security context for an inter-system change from A/Gb mode or Iu mode to S1 mode in EMM-CONNECTED mode, the MME shall generate a KSISGSN, create a nonceMME and generate the K'ASME using the created nonceMME as indicated in 3GPP TS 33.401 [19]. The MME shall include the selected NAS algorithms, nonceMME and generated KSISGSN(associated with the K'ASME) in the NAS security transparent container for handover to E-UTRAN. The MME shall derive the EPS NAS keys from K'ASMEand the MME shall set the uplink and downlink NAS COUNT counters of the mapped EPS security context to zero.

4.4.2.3            Establishment of secure exchange of NAS messages

Secure exchange of NAS messages via a NAS signalling connection is usually established by the MME during the attach procedure by initiating a security mode control procedure. After successful completion of the security mode control procedure, except for the messages specified in subclauses 4.4.4 and 4.4.5, all NAS messages exchanged between the UE and the MME are sent integrity protected and ciphered using the current EPS security algorithm.
During inter-system handover from A/Gb mode to S1 mode or Iu mode to S1 mode, secure exchange of NAS messages is established between the MME and the UE by:
-     the transmission of NAS security related parameters encapsulated in the AS signalling from the MME to the UE triggering the inter-system handover (see 3GPP TS 33.401 [19]). The UE uses these parameters to generate the mapped EPS security context; and,
-     after the handover, the transmission of a TRACKING AREA UPDATE REQUEST message from the UE to the MME. The UE shall send this message integrity protected using the mapped EPS security context, but unciphered. From this time onward, except for the messages specified in subclauses 4.4.4 and 4.4.5, all NAS messages exchanged between the UE and the MME are sent integrity protected and ciphered using the mapped EPS security context.
The secure exchange of NAS messages shall be continued after S1 mode to S1 mode handover. It is terminated after inter-system handover from S1 mode to A/Gb mode or Iu mode or when the NAS signalling connection is released.
When a UE in EMM-IDLE mode establishes a new NAS signalling connection and has a valid current EPS security context, secure exchange of NAS messages can be re-established in the following ways:
1)   Except for the case described in item 3 below, the UE shall transmit the initial NAS message integrity protected with the current EPS security context, but unciphered. The UE shall include the eKSI indicating the current EPS security context value in the initial NAS message. The MME shall check whether the eKSI included in the initial NAS message belongs to an EPS security context available in the MME, and shall verify the MAC of the NAS message. If the verification is successful, the MME may re-establish the secure exchange of NAS messages:
-     by replying with a NAS message that is integrity protected and ciphered using the current EPS security context. From this time onward, except for the messages specified in subclauses 4.4.4 and 4.4.5, all NAS messages exchanged between the UE and the MME are sent integrity protected and ciphered; or
-     by initiating a security mode control procedure. This can be used by the MME to take a non-current EPS security context into use or to modify the current EPS security context by selecting new NAS security algorithms; or
2)   If the initial NAS message was a SERVICE REQUEST message or EXTENDED SERVICE REQUEST message, secure exchange of NAS messages is triggered by the indication from the lower layers that the user plane radio bearers are successfully set up. After successful completion of the procedure, except for the messages specified in subclauses 4.4.4 and 4.4.5, all NAS messages exchanged between the UE and the MME are sent integrity protected and ciphered.
3)   If the UE has no current EPS security context and performs a tracking area updating procedure after an inter-system change in idle mode from A/Gb mode to S1 mode or Iu mode to S1 mode, the UE shall send the TRACKING AREA UPDATE REQUEST message without integrity protection and encryption. The UE shall include a nonce and a GPRS ciphering key sequence number for creation of a mapped security context. The MME creates a fresh mapped EPS security context and takes this context into use by initiating a security mode control procedure. This re-establishes the secure exchange of NAS messages.

4.4.2.4            Change of security keys

When the MME initiates a re-authentication to create a new EPS security context, the messages exchanged during the authentication procedure are integrity protected and ciphered using the current EPS security context, if any.
Both UE and MME shall continue to use the current EPS security context, until the MME initiates a security mode control procedure. The SECURITY MODE COMMAND message sent by the MME includes the eKSI of the new EPS security context to be used. The MME shall send the message integrity protected with the new EPS security context, but unciphered. When the UE responds with a SECURITY MODE COMPLETE, it shall send the message integrity protected and ciphered with the new EPS security context.
The MME can also modify the current EPS security context or take an existing native EPS security context into use, by sending a SECURITY MODE COMMAND message including the eKSI of the EPS security context to be modified and including a new set of selected NAS security algorithms. In this case the MME shall send the SECURITY MODE COMMAND message integrity protected with the modified EPS security context, but unciphered. When the UE replies with a SECURITY MODE COMPLETE message, it shall send the message integrity protected and ciphered with the modified EPS security context.

4.4.3  Handling of NAS COUNT and NAS sequence number

4.4.3.1            General

Each EPS NAS security context shall be associated with two separate counters NAS COUNT: one related to uplink NAS messages and one related to downlink NAS messages. The NAS COUNT counters use 24 bit internal representation and are independently maintained by UE and MME. The NAS COUNT shall be constructed as a NAS sequence number (8 least significant bits) concatenated with a NAS overflow counter (16 most significant bits).
When NAS COUNT is input to NAS ciphering or NAS integrity algorithms it shall be considered to be a 32-bit entity which shall be constructed by padding the 24-bit internal representation with 8 zeros in the most significant bits.
During the handover from UTRAN/GERAN to E-UTRAN, if the mapped EPS security context is taken into use, the NAS COUNT values for this EPS security context shall be initialized to zero in the UE and the network for uplink and downlink NAS messages.
The NAS sequence number part of the NAS COUNT shall be exchanged between the UE and the MME as part of the NAS signalling. After each new or retransmitted outbound security protected NAS message, the sender shall increase the NAS COUNT number by one. Specifically, on the sender side, the NAS sequence number shall be increased by one, and if the result is zero (due to wrap around), the NAS overflow counter shall also be incremented by one (see subclause 4.4.3.5). The receiving side shall estimate the NAS COUNT used by the sending side. Specifically, if the estimated NAS sequence number wraps around, the NAS overflow counter shall be incremented by one.
In some NAS messages only 5 of the 8 NAS sequence number bits are transmitted. When this is the case, the receiver shall estimate the remaining 3 most significant bits of the sequence number.

4.4.3.2            Replay protection

Replay protection shall be supported for received NAS messages both in the MME and the UE. However, since the realization of replay protection does not affect the interoperability between nodes, no specific mechanism is required for implementation.
Replay protection must assure that one and the same NAS message is not accepted twice by the receiver. Specifically, for a given NAS security context, a given NAS COUNT value shall be accepted at most one time and only if message integrity verifies correctly.

4.4.3.3            Integrity protection and verification

The sender shall use its locally stored NAS COUNT as input to the integrity protection algorithm.
The receiver shall use the NAS sequence number included in the received message (or estimated from the 5 bits of the NAS sequence number received in the message) and an estimate for the NAS overflow counter as defined in subclause 4.4.3.1 to form the NAS COUNT input to the integrity verification algorithm.
The algorithm to calculate the integrity protection information is specified in 3GPP TS 33.401 [19], and the integrity protection shall include octet 6 to n of the security protected NAS message, i.e. the sequence number IE and the NAS message IE. In addition to the data that is to be integrity protected, the constant BEARER ID, DIRECTION bit, NAS COUNT and NAS integrity key are input to the integrity protection algorithm. These parameters are described in 3GPP TS 33.401 [19].
After successful integrity protection validation, the receiver shall update its corresponding locally stored NAS COUNT with the value of the estimated NAS COUNT for this NAS message.

4.4.3.4            Ciphering and deciphering

The sender shall use its locally stored NAS COUNT as input to the ciphering algorithm.
The receiver shall use the NAS sequence number included in the received message (or estimated from the 5 bits of the NAS sequence number received in the message) and an estimate for the NAS overflow counter as defined in subclause 4.4.3.1 to form the NAS COUNT input to the deciphering algorithm.
The input parameters to the NAS ciphering algorithm are the constant BEARER ID, DIRECTION bit, NAS COUNT, NAS encryption key and the length of the key stream to be generated by the encryption algorithm.

4.4.3.5            NAS COUNT wrap around

If, when increasing the NAS COUNT as specified above, the MME detects that its NAS COUNT is "close" to wrap around, (close to 224), the MME shall initiate a new AKA procedure with the UE, leading to a new established NAS security context and the NAS COUNT being reset to 0 in both the UE and the MME when the new NAS security context is activated as discussed above.
Similarly, the MME shall initiate an AKA procedure if it detects that the UE's uplink NAS COUNT is close to wrap around. If for some reason a new KASME has not been established using AKA before the NAS COUNT wraps around, the node (MME or UE) in need of sending a NAS message shall instead release the NAS signalling connection. Prior to sending the next uplink NAS message, the UE shall delete the eKSI indicating the current EPS security context.

4.4.4  Integrity protection of NAS signalling messages

4.4.4.1            General

For the UE, integrity protected signalling is mandatory for the NAS messages once a valid EPS security context exists and has been taken into use. For the network, integrity protected signalling is mandatory for the NAS messages once a secure exchange of NAS messages has been established for the NAS signalling connection. Integrity protection of all NAS signalling messages is the responsibility of the NAS. It is the network which activates integrity protection.
Details of the integrity protection and verification of NAS signalling messages are specified in 3GPP TS 33.401 [19].
When both ciphering and integrity protection are activated, the NAS message is first encrypted and then the encrypted NAS message and the NAS sequence number are integrity protected by calculating the MAC.
When only integrity protection is activated, and ciphering is not activated, the unciphered NAS message and the NAS sequence number are integrity protected by calculating the MAC.
When during the EPS attach procedure an ESM message is piggybacked in an EMM message, there is only one sequence number IE and one message authentication code IE, if any, for the combined NAS message.

4.4.4.2            Integrity checking of NAS signalling messages in the UE

Except the messages listed below, no NAS signalling messages shall be processed by the receiving EMM entity in the UE or forwarded to the ESM entity, unless the secure exchange of NAS messages has been established for the NAS signalling connection:
-     EMM messages:
-     IDENTITY REQUEST (if requested identification parameter is IMSI);
-     AUTHENTICATION REQUEST;
-     AUTHENTICATION REJECT;
-     ATTACH REJECT;
-     DETACH REQUEST;
-     DETACH ACCEPT (for non switch off);
-     TRACKING AREA UPDATE REJECT;
-     SERVICE REJECT.
NOTE:      These messages are accepted by the UE without integrity protection, as in certain situations they are sent by the network before security can be activated.
All ESM messages are integrity protected.
Once the secure exchange of NAS messages has been established, the receiving EMM or ESM entity in the UE shall not process any NAS signalling messages unless they have been successfully integrity checked by the NAS. If NAS signalling messages, having not successfully passed the integrity check, are received, then the NAS in the UE shall discard that message. If any NAS signalling message is received as not integrity protected even though the secure exchange of NAS messages has been established by the network, then the NAS shall discard this message.

4.4.4.3            Integrity checking of NAS signalling messages in the MME

Except the messages listed below, no NAS signalling messages shall be processed by the receiving EMM entity in the MME or forwarded to the ESM entity, unless the secure exchange of NAS messages has been established for the NAS signalling connection:
-     EMM messages:
-     ATTACH REQUEST;
-     IDENTITY RESPONSE (if requested identification parameter is IMSI);
-     AUTHENTICATION RESPONSE;
-     AUTHENTICATION FAILURE;
-     SECURITY MODE REJECT;
-     DETACH REQUEST;
-     DETACH ACCEPT;
-     TRACKING AREA UPDATE REQUEST.
NOTE 1:   The TRACKING AREA UPDATE REQUEST message is sent by the UE without integrity protection, if the tracking area updating procedure is initiated due to an inter-system change in idle mode and no current EPS security context is available in the UE. The other messages are accepted by the MME without integrity protection, as in certain situations they are sent by the UE before security can be activated.
All ESM messages are integrity protected except a PDN CONNECTIVITY REQUEST message if it is sent piggybacked in ATTACH REQUEST message and NAS security is not activated.
Once a current EPS security context exists, until the secure exchange of NAS messages has been established for the NAS signalling connection, the receiving EMM entity in the MME shall process the following NAS signalling messages, even if the MAC included in the message fails the integrity check or cannot be verified, as the EPS security context is not available in the network:
-     ATTACH REQUEST;
-     IDENTITY RESPONSE (if requested identification parameter is IMSI);
-     AUTHENTICATION RESPONSE;
-     AUTHENTICATION FAILURE;
-     SECURITY MODE REJECT;
-     DETACH REQUEST (if sent before security has been activated);
-     DETACH ACCEPT;
-     TRACKING AREA UPDATE REQUEST;
-     SERVICE REQUEST;
-     EXTENDED SERVICE REQUEST.
NOTE 2:   These messages are processed by the MME even when the MAC that fails the integrity check or cannot be verified, as in certain situations they can be sent by the UE protected with an EPS security context that is no longer available in the network.
If an ATTACH REQUEST message fails the integrity check, the MME shall authenticate the subscriber before processing the attach request any further.
If a TRACKING AREA UPDATE REQUEST message fails the integrity check, the MME shall initiate a security mode control procedure to take a new mapped EPS security context into use, if the UE provided a nonceUE, GPRS ciphering key sequence number, P-TMSI and RAI in the TRACKING AREA UPDATE REQUEST message; otherwise the MME shall reject the request with EMM cause #9 "UE identity cannot be derived by the network".
If a SERVICE REQUEST or EXTENDED SERVICE REQUEST message fails the integrity check, the MME shall reject the request with EMM cause #9 "UE identity cannot be derived by the network".
Once the secure exchange of NAS messages has been established for the NAS signalling connection, the receiving EMM or ESM entity in the MME shall not process any NAS signalling messages unless they have been successfully integrity checked by the NAS. If any NAS signalling message, having not successfully passed the integrity check, is received, then the NAS in the MME shall discard that message. If any NAS signalling message is received, as not integrity protected even though the secure exchange of NAS messages has been established, then the NAS shall discard this message.

4.4.5  Ciphering of NAS signalling messages

The use of ciphering in a network is an operator option subject to MME configuration. When operation of the network without ciphering is configured, the MME shall indicate the use of "null ciphering algorithm" EEA0 (see subclause 9.9.3.23) in the current security context for all UEs. For setting the security header type in outbound NAS messages, the UE and the MME shall apply the same rules irrespective of whether the "null ciphering algorithm" or any other ciphering algorithm is indicated in the security context.
When the UE establishes a new NAS signalling connection, it shall send the initial NAS message unciphered.
The UE shall start the ciphering and deciphering of NAS messages when the secure exchange of NAS messages has been established for a NAS signalling connection. From this time onward, except for the ATTACH REQUEST message and TRACKING AREA UPDATE REQUEST message, the UE shall send all NAS messages ciphered until the NAS signalling connection is released, or the UE performs intersystem handover to A/Gb mode or Iu mode.
The MME shall start ciphering and deciphering of NAS messages as described in subclause 4.4.2.2. From this time onward, except for the SECURITY MODE COMMAND message, the MME shall send all NAS messages ciphered until the NAS signalling connection is released, or the UE performs intersystem handover to A/Gb mode or Iu mode.
Once the encryption of NAS messages has been started between the MME and the UE, the receiver shall discard the unciphered NAS messages which shall have been ciphered according to the rules described in this specification.
If the "null ciphering algorithm" EEA0 has been selected as a ciphering algorithm, the NAS messages with the security header indicating ciphering are regarded as ciphered.
Details of ciphering and deciphering of NAS signalling messages are specified in 3GPP TS 33.401 [19].

Disabling and re-enabling of UE's E-UTRA capability

When the UE supporting the A/Gb and/or Iu mode together with the S1 mode needs to stay in A/Gb or Iu mode, in order to prevent unwanted handover or cell reselection from UTRAN/GERAN to E-UTRAN, the UE shall disable the E-UTRA capability.
-     The UE shall not set the E-UTRA support bits of the MS Radio Access capability IE (see 3GPP TS 24.008 [13], subclause 10.5.5.12a), the E-UTRA support bits of Mobile Station Classmark 3 IE (see 3GPP TS 24.008 [13], subclause 10.5.1.7) and the ISR support bit of the MS network capability IE (see 3GPP TS 24.008 [13], subclause 10.5.5.12) in the ATTACH REQUEST message and the ROUTING AREA UPDATE REQUEST message after it selects GERAN or UTRAN; and
-     the UE NAS layer shall indicate the access stratum layer(s) of disabling of the E-UTRA capability.
The UE shall enable the E-UTRA capability again in the following cases:
-     the UE mode of operation changes from CS/PS mode 1 of operation to CS/PS mode 2 of operation;
-     the UE mode of operation changes from PS mode 1 of operation to PS mode 2 of operation;
-     the UE powers off and powers on again; or
-     for the PLMN selection purpose.


Tuesday, 12 July 2016

Location Update

Location Update
Once the procedures for authentication and NAS security setup are completed, now the MME has to register the subscriber in the network, and find out what services the subscriber can use. To this end, the MME notifies the HSS the subscriber is registered in the network and located in its TAs, and then downloads information about the subscriber from the HSS. All these are done through the location update procedure, and by using Diameter protocol over the S6a interface between the MME and the HSS. The call flows during this procedure are as in below figure


1) [MME  HSS] Notifying UE Location
The MME sends an Update Location Request (IMSI, MME ID) message to the HSS in order to notify of the UE’s registration and obtain the subscription information of the UE.

2) [HSS] UE Location Update
The HSS registers the MME ID to indicate in which MME the UE is located in.

3) [MME  HSS] Delivering User Subscription Information
The HSS sends the MME subscription information of the subscriber as included in an Update Location Answer message, so that the MME can create an EPS session and a default EPS bearer for the subscriber. The subscription information included in the Update Location Answer message is as follows:
Update Location Answer (IMSI, Subscribed APN, Subscribed P-GW ID, Subscribed QoS Profile)
  Subscribed APN: APN that a user is subscribing to (e.g. Internet service)
  Subscribed P-GW ID: an ID for P-GW through which a user can access the Subscribed APN
 Subscribed QoS Profile5 (UE-AMBR(UL/DL), QCI, ARP, APN-AMBR(UL/DL))
            - UE-AMBR (UL/DL): the aggregate bandwidth of all non-GBR bearers that a UE can have                  Determined by MME and controlled by eNB.
            - QCI, ARP, APN-AMBR (UL/DL): QoS applied to the Subscribed APN

4) [MME] Storing Subscription Information

The MME receives the Update Location Answer message from the HSS, and stores the subscription information from the message.
From the downloaded subscription information, the MME can check what services

LTE Security

LTE Security: Key Concepts

Authentication:
•The LTE Network verifies the UE’s identity by challenging the UT use the keys and report a result.
•The network checks the result against the expected result

Integrity:
•Signaling message receiver verifies that the received message is exactly the message that the transmitter sent
•This is done using an integrity checksum
•Guards against “man in the middle” attacks where the senders messages and intercepted by a hacker and a modified message is relayed to the receiver

Encryption:
•The sender encrypts the data with a secret key that is only known to the receiver
•Only the receiver is able to decode the message
•Guards against hackers listening in on the data

LTE Security Key Hierarchy


Encryption and Integrity Protection in the LTE Control Plan


•LTE supports two levels on security on the control plane
–The NAS traffic between the MME and the UE is protected with NAS level keys
–The RRC connection traffic between the MME and the UE is protected with RRC level keys
•This means that the NAS traffic is being protected with NAS as well as RRC level security



Encryption and Integrity Protection in the LTE User Plane
•User plane data is encrypted with the KUPenc key






LTE NAS Key Derivation at the MME and UE

















LTE RRC Key Derivation at the eNodeB and UE













LTE User Plane Key Derivation at the eNodeB and UE






Key Stream Computation


3GPP Security Specifications:

LTE Security
•33.401: System Architecture Evolution (SAE); Security architecture
•33.402: System Architecture Evolution (SAE); Security aspects of non-3GPP

Lawful Interception
•33.106: Lawful interception requirements
•33.107: Lawful interception architecture and functions
•33.108: Handover interface for Lawful Interception

Key Derivation Function
•33.220: GAA: Generic Bootstrapping Architecture (GBA)

Backhaul Security
•33.310: Network Domain Security (NDS); Authentication Framework (AF)

Relay Node Security
•33.816: Feasibility study on LTE relay node security (also 33.401)

Home (e) Node B Security
•33.320: Home (evolved) Node B Security

























Friday, 8 July 2016

Change of UE mode of operation

Change of UE mode of operation

The UE mode of operation can change as a result of:
-     a change of UE's usage setting for a CS voice capable UE;
-     a change of voice domain preference as defined in  for a CS voice capable UE;
-     a failure of IMS registration; or

-     a change in UE configuration regarding the use of SMS over SGs.