2. 2¡¢¼øÈ¨¹ý³Ì
2.1 ×ÛÊö
EPS¼øÈ¨ºÍÃÜÔ¿ÐÉÌ£¨AKA£©¹ý³ÌµÄÄ¿µÄÊÇʵÏÖÓû§ºÍÍøÂçÖ®¼äµÄ¹²Í¬¼øÈ¨£¬²¢É̶¨Ò»¸öÃÜÔ¿KASME¡£
EPSµÄAKA¹ý³Ì×ÜÊÇÓÉÍøÂç³õʼ»¯ºÍ¿ØÖÆ¡£µ«ÊÇ£¬UEÄܾܾøÍøÂç²à·¢ÆðµÄEPS¼øÈ¨Ñ¯ÎÊ¡£Ö»ÓÐUSIM´æÔÚµÄÇé¿öÏ£¬UE²Å»á¼ÌÐø½øÐÐEPS¼øÈ¨¡£
µ±EPS ¼øÈ¨³É¹¦£¬EPS °²È«ÉÏÏÂÎľͻáÔÚUE ºÍÍøÂç²à½¨Á¢¡£ÔÚÒ»¸ö³É¹¦µÄ¼øÈ¨¹ý³ÌÆÚ¼ä£¬USIM »á¼ÆËãÃÜÔ¿CK ºÍIK¡£CK ºÍIK Ëæºó»á±»ÓÃ×÷²úÉúKASME µÄÊäÈë¡£KASME ±»´æ´¢ÔÚEPS °²È«ÉÏÏÂÎÄÖУ¬¸ÃEPS °²È«ÉÏÏÂÎÄ´æÓÚÍøÂçºÍME µÄ·ÇÓÀ¾Ã´æ´¢½éÖÊÖС£
2.2 ÍøÂç³õʼ»¯¼øÈ¨
µ±NAS ÐÅÁîÁ¬½Ó´æÔÚ£¬ÍøÂç¾Í¿ÉÒÔÔÙÈÎÒâʱ¿Ì·¢Æð¼øÈ¨¹ý³Ì¡£ÍøÂçͨ¹ý¸øUE ·¢ËÍAUTHENTICATION REQUEST ÏûÏ¢ºÍÆô¶¯¶¨Ê±Æ÷T3460 À´³õʼ»¯¼øÈ¨¹ý³Ì¡£ÈçÏÂͼ£º
AUTHENTICATION REQUEST ÏûÏ¢°üº¬¼ÆËã¼øÈ¨ÏìÓ¦µÄ±ØÒª²ÎÊý¡£
µÚ5Ò³
2.3 UE µÄ¼øÈ¨ÏìÓ¦
³ýÁËÔÚ2.6 ÖÐÃèÊöµÄÇé¿öÍ⣬UE ½«´¦Àí¼øÈ¨Ñ¯ÎÊÊý¾Ý£¬²¢»ØÓ¦Ò»ÌõAUTHENTICATION RESPONSE ÏûÏ¢¸øÍøÂç¡£
¶ÔÓÚÒ»¸ö³É¹¦µÄEPS ¼øÈ¨Ñ¯ÎÊ£¬UE ½«¸ù¾ÝÒÔϹæÔò¾ö¶¨ÓÃÀ´¼ÆËãеÄKASME µÄPLMN Identity£º
a) µ±UE ´ÓEMM-IDLE ×´Ì¬×ªÒÆµ½EMM-CONNECTED ״̬£¬UE ½«Ê¹ÓÃÑ¡ÔñµÄPLMN µÄPLMN Identity Ö±µ½µÚÒ»´ÎÇл»¡£
b) ÔÚÇл»»òÕßÒìϵͳÇл»µ½S1-mode ºó£¬
- Èç¹ûÄ¿±êÐ¡Çø²»Êǹ²ÏíÍøÂçÐ¡Çø£¬UE ½«Ê¹ÓÃÊÕµ½µÄϵͳÐÅÏ¢ÖеÄPLMN Identity£» - Èç¹ûÄ¿±êÐ¡ÇøÊÇÒ»¸ö¹²ÏíÍøÂçÐ¡Çø£¬²¢ÇÒUE ÓÐÒ»¸öÓÐЧµÄGUTI£¬UE ½«Ê¹ÓÃGUTI ÖеıíʾPLMN Identity µÄ²¿·Ö£»
- Èç¹ûÄ¿±êÐ¡ÇøÊÇÒ»¸ö¹²ÏíÍøÂçÐ¡Çø£¬²¢ÇÒUEÓÐÒ»¸öÓÐЧµÄP-TMSI ºÍRAI£¬ µ«ÊÇûÓÐÓÐЧµÄGUTI£¬UE ½«Ê¹ÓÃRAI ÖеıíʾPLMN Identity µÄ²¿·Ö¡£
¶ÔÓÚÒ»¸ö³É¹¦µÄEPS ¼øÈ¨Ñ¯ÎÊ£¬¸ù¾Ý¼øÈ¨Ñ¯ÎÊÊý¾Ý¼ÆËã»ñµÃµÄеÄKASME ½«´æ´¢ÔÚME ·ÇÓÀ¾ÃÐÔ´æ´¢½éÖÊÖеÄÒ»¸öеÄEPS °²È«ÉÏÏÂÎÄÖС£
USIM ½«ÀûÓôÓME ½ÓÊÕÀ´µÄ¼øÈ¨Ñ¯ÎÊÊý¾ÝÀ´¼ÆËã¼øÈ¨ÏìÓ¦£¨RES£©£¬²¢´«µÝRES ¸øME¡£
ΪÁ˱ÜÃâͬ²½´íÎ󣬵±UE ½ÓÊÕµ½Ò»¸öAUTHENTICATION REQUEST ÏûÏ¢£¬UE ½«½ÓÊÕµ½µÄRAND ºÍÉÏÊöµÄRES Ò»Æð´æ´¢µ½ME µÄ·ÇÓÀ¾ÃÐÔ´æ´¢Æ÷¡£µ±UE ÊÕµ½ºóÐøµÄAUTHENTICATION REQUEST£¬Èç¹û´æ´¢µÄRAND ÖµºÍÊÕµ½µÄеÄÖµÏàµÈ£¬ME²»»á½«RAND´«µÝ¸øUSIM£¬µ«ÊǻᷢËͰüº¬´æ´¢µÄRESµÄAUTHENTICATION RESPONSEÏûÏ¢¡£Èç¹ûÔÚMEÖÐûÓÐÓÐЧ´æ´¢µÄRAND»òÕß´æ´¢µÄRANDºÍÊÕµ½µÄÐÂÖµ²»Ò»Ñù£¬ME½«´«µÝRANDÖµ¸øUSIM£¬ÓÃÐÂÖµ¸²¸Ç֮ǰ´æ´¢µÄÈκÎRANDºÍRES£¬²¢Æô¶¯£¬»òÕ߸´Î»²¢ÖØÆô¶¨Ê±Æ÷T3416¡£
´æ´¢ÔÚMEÖеÄRANDºÍRESÖµ½«±»É¾³ý£¬¶¨Ê±Æ÷T3416£¨Èç¹ûÔÚÔËÐУ©½«±»Í£Ö¹£º
- µ±½ÓÊÕµ½Ò»¸ö
- SECURITY MODE COMMAND, - SERVICE REJECT,
µÚ6Ò³
- TRACKING AREA UPDATE ACCEPT, or - AUTHENTICATION REJECT message; - µ±¶¨Ê±Æ÷T3416³¬Ê±£»»òÕß
- Èç¹ûUE½øÈëEMM-DEREGISTERED or EMM-NULL״̬¡£ 2.4 ÍøÂç²àÍê³É¼øÈ¨
µ±½ÓÊÕµ½Ò»¸öAUTHENTICATION RESPONSEÏûÏ¢£¬ÍøÂ罫ֹͣ¶¨Ê±Æ÷T3460²¢¼ì²éRESµÄÕýÈ·ÐÔ¡£
Èç¹û¼øÈ¨¹ý³Ì³É¹¦µÄÍê³É£¬²¢ÇÒÏà¹ØµÄeKSI´æ´¢ÔÚÍøÂçµÄEPS°²È«ÉÏÏÂÎÄÖУ¬µ±³õʼ»¯Ò»¸öеļøÈ¨¹ý³Ì£¬ÍøÂ罫°üº¬Ò»¸ö²»Í¬µÄeKSIµ½AUTHENTICATION REQUESTÏûÏ¢ÖС£
µ±½ÓÊÕµ½Ò»ÌõAUTHENTICATION FAILUREÏûÏ¢£¬ÍøÂ罫ֹͣT3460¶¨Ê±Æ÷¡£EMM causeΪ #21\µÄÇé¿öÏ£¬ºËÐÄÍø¿ÉÄܺÍHSS/AuCÖØÐÂÐÉ̲¢Ìṩ¸øUEеļøÈ¨²ÎÊý¡£
2.5 ÍøÂç¾Ü¾ø¼øÈ¨
Èç¹ûUE·µ»ØµÄ¼øÈ¨ÏìÓ¦ÎÞЧ£¬ÍøÂç¸ù¾ÝUEÔÚ³õʼNASÏûÏ¢ÖÐʹÓõÄtype of identity×÷³öÏìÓ¦£º
- Èç¹ûGUTI±»Ê¹Óã» - Èç¹ûIMSI±»Ê¹Óã»
Èç¹ûGUTI±»Ê¹Óã¬ÍøÂçÓ¦¸Ã³õʼ»¯ÈÏÖ¤¹ý³Ì¡£Èç¹ûÔÚÈÏÖ¤¹ý³ÌÖÐÓÉUE¸ø³öµÄIMSIºÍÍøÂç²àÓµÓеĺÍGUTIÏà¹ØÁªµÄIMSI²»Ò»Ñù£¬½«Ó¦ÓÃÕýÈ·µÄ²ÎÊýÖØÆô¼øÈ¨¹ý³Ì¡£·ñÔò£¬Èç¹ûUEÌṩµÄIMSIºÍÍøÂç´æ´¢µÄIMSIÏàͬ£¬ÍøÂçÓ¦¸Ã°´ÏÂÃæµÄÃèÊö¼ÌÐø¡£
Èç¹û³õʼNASÏûÏ¢ÖеÄIMSI±»ÓÃÀ´ÈÏÖ¤£¬»òÕßÔÚÒ»¸ö²»³É¹¦¼øÈ¨Ö®ºóÍøÂç¾ö¶¨²»·¢ÆðÈÏÖ¤¹ý³Ì£¬ÍøÂçÓ¦¸Ã·¢ËÍAUTHENTICATION REJECTÏûÏ¢¸øUE¡£
µ±½ÓÊÕµ½AUTHENTICATION REJECTÏûÏ¢ºó£¬UEÓ¦¸Ã½«¸üÐÂ״̬ÉèÖÃΪEU3 ROAMING NOT ALLOWED£¬É¾³ý´æ´¢µÄGUTI£¬TAIÁÐ±í£¬×î½ü·ÃÎʵÄTAIºÍKSIASME¡£USIM½«±»ÈÏΪÎÞЧֱµ½UE¹Ø»ú»òÕß°üº¬¸ÃUSIMµÄUICC±»ÒƳý¡£
Èç¹ûÖ§³ÖA/Gb»òÕßIuģʽ¡¡£¨Ê¡ÂÔ£©
Èç¹ûUEÊÕµ½AUTHENTICATION REJECTÏûÏ¢£¬UE½«·ÅÆúÈκÎEMMÐÅÁî¹ý³Ì£¬Í£Ö¹ÈκÎÔËÐеÄT3410£¬T3417»òÕßT3430¶¨Ê±Æ÷£¬²¢½øÈëEMM-DEREGISTERED×´ µÚ7Ò³
̬¡£
2.6 UE¾Ü¾ø¼øÈ¨
ÔÚÒ»¸öEPS¼øÈ¨Ñ¯ÎÊÖУ¬UEÐèҪͨ¹ýAUTHENTICATION REQUESTÏûÏ¢ÖÐµÄ AUTN²ÎÊý¼ì²éºËÐÄÍøµÄÕæÊµÐÔ£¬´Ó¶øÊ¹µÃUEÄܹ»Ì½²âÒ»¸öαÔìµÄÍøÂç¡£
ÔÚEPS¼øÈ¨¹ý³ÌÆÚ¼ä£¬UE¿ÉÄÜÓÉÓÚ´íÎóµÄAUTN²ÎÊý¶ø¾Ü¾øºËÐÄÍø¡£¸Ã²ÎÊý°üº¬Èý¸ö¿ÉÄܵļøÈ¨´íÎó£º
a) MAC´íÎó
Èç¹ûUE·¢ÏÖMAC£¨ÔÚAUTN²ÎÊýÖÐÓɺËÐÄÍøÌṩ£©ÎÞЧ£¬UE½«·¢ËÍ
AUTHENTICATION FAILUREÏûÏ¢¸øÍøÂ磬ÏûÏ¢ÖеÄEMM causeΪ#20¡±MAC failure¡±¡£UEÈ»ºó½«Ö´ÐÐ2.7ÖÐÃèÊöµÄÌõÄ¿c¡£
b) ²»½ÓÊÜNon-EPS¼øÈ¨
Èç¹û·¢ÏÖÓɺËÐÄÍøÌṩµÄAUTNÖеÄAMFÓòµÄ¡± separation bit¡±µÄֵΪ0£¬UE·¢ËÍAUTHENTICATION FAILUREÏûÏ¢¸øÍøÂ磬ÏûÏ¢ÖеÄEMM causeÉèÖÃΪ#26¡± non-EPS authentication unacceptable¡±£¬UEÈ»ºóÖ´ÐÐ2.7ÖÐÃèÊöµÄÌõÄ¿d¡£
TS 33.401ÖеÄÏà¹ØËµÃ÷£º
If the Network Type equals E-UTRAN then the \of AUTN shall be set to 1 to indicate to the UE that the authentication vector is only usable for AKA in an EPS context, if the %usable in a non-EPS context only (e.g. GSM, UMTS).
c) SQN´íÎó
Èç¹ûUE·¢ÏÖSQN£¨Sequence Number£¬ÔÚAUTNÖÐÓɺËÐÄÍøÌṩ£©³¬³ö·¶Î§£¬UE·¢ËÍAUTHENTICATION FAILUREÏûÏ¢¸øÍøÂ磬ÏûÏ¢ÖеÄEMM causeÉèÖÃΪ#21¡±synch failure¡±£¬UEÈ»ºóÖ´ÐÐ2.7ÖÐÃèÊöµÄÌõÄ¿e¡£
Èç¹ûUE·µ»ØAUTHENTICATION FAILUREÏûÏ¢¸øÍøÂ磬UE±ØÐëɾ³ýÈκÎÏÈǰ´æ´¢µÄRANDºÍRES£¬Èç¹ûT3416ÔËÐУ¬½«ÆäÍ£Ö¹¡£
2.7 Òì³£Çé¿ö a) µÍ²ã´íÎó£º
ÔÚ½ÓÊÕµ½AUTHENTICATION RESPONSE֮ǰ̽²âµ½µÍ²ã´íÎó£¬ÍøÂ罫·ÅÆú¸Ã¹ý³Ì¡£ b) T3460³¬Ê±
µÚ8Ò³
Ïà¹ØÍÆ¼ö£º