Revised Solution for Device Binding Revised from S40-20121003-001 3GPP2 TSG-SX WG4 SX40-20130321-002 Source: Qualcomm Incorporated Contact(s): Anand Palanigounder,

Slides:



Advertisements
Similar presentations
Binding of cdma2000 access subscription with specific device(s) 3GPP2 TSG-S WG4 S Source: Qualcomm Incorporated Contact(s): Anand Palanigounder,
Advertisements

Use cases for Device Binding 3GPP2 TSG-S WG4 S Source: Qualcomm Incorporated Contact(s): Anand Palanigounder,
Mobile IPv4 FA CoA Support in WLAN Interworking Raymond Hsu Qualcomm Inc. Notice: QUALCOMM Incorporated grants a free, irrevocable license.
Mobile IPv4 FA CoA Support in WLAN Interworking Raymond Hsu, Qualcomm Inc., Sanket S. Nesargi, Nortel, Nanying Yin,
Dynamic HA Assignment for MIPv4 in WLAN Interworking Raymond Hsu, Qualcomm Inc., Wing C. Lau, Qualcomm Inc., Notice:
MIP6-HA-Local-Assignment-Capability indication to MS Contributors grant a free, irrevocable license to 3GPP2 and its Organization Partners.
Tunneling Protocol Support for 1x CSFB from E-UTRAN
HUAWEI TECHNOLOGIES CO., LTD. Huawei Technologies Co., Ltd. grant a free, irrevocable license to 3GPP2 and its Organizational Partners to.
HUAWEI TECHNOLOGIES CO., LTD. Huawei Technologies Co., Ltd. grant a free, irrevocable license to 3GPP2 and its Organizational Partners to.
IP Connectivity for E911 in HRPD/PDS Networks Page 1 IP Connectivity for Emergency Calls in HRPD/PDS Networks 3GPP2 Meeting, 1/07 IP Connectivity for Emergency.
XHRPD Example Scenario for MSS Masa Shirota Qualcomm Inc. July 15, GPP2 Dalian Meeting Recommendation: FYI Notice QUALCOMM Incorporated grants a.
Source: Qualcomm Incorporated Contact: Roozbeh Atarius October25th, 2010 Page 1 MEID and IMEI and Instance ID Notice © All.
Summary of 3GPP TR GPP2 TSG-S WG4 S Source: Qualcomm Incorporated Contact(s): Anand Palanigounder,
3GPP2 A r0 3GPP2 C xxxr0 TSG-A WG3 and TSG-C WG2 Title: HRPD Redirect on EPC Unavailable Source: Mike DolanAlcatel-Lucent Dave.
Overview & Definitions for Downloadable Credentials 1 S GPP2 TSG-S WG1 Source: Sprint, US Cellular, Motorola Mobility, Qualcomm Contact(s):
1 IP Service Authorization Support and Mobility Selection for X.S0011-E Source: QUALCOMM Inc.: Masa Shirota, George Cherian, Jun Wang,
Proposed High Level Solution for Device Binding 3GPP2 TSG-SX WG4 SX Source: Qualcomm Incorporated and Alcatel-Lucent Contact(s): Anand Palanigounder,
1 UATI-IP address mapping Peerapol Tinnakornsrisuphap David Ott Qualcomm.
1 May 14, 2007 Zhibi Wang, Simon Mizikovsky – Alcatel-Lucent Vidya Narayanan, Anand Palanigounder – QUALCOMM ABSTRACT: Access authentication architecture.
1 cdma2000® Data Service Transition to NULL Support Jun Wang Ravi Patwardhan June 5, 2003 Recommendation -
© Alcatel-Lucent | M2M Numbering | April 12, GPP2 M2M TITLE Numbering in 3GPP2 for M2MSOURCE Mike Dolan, Alcatel-Lucent, Mike.
3GPP2 X xxx Title: SIP6 access and MIP6 Access Differentiation Sources: ZTE Contact: Rajesh Bhalla
1x Device Binding Framework Overview to TSG-AC 3GPP2 TSG-AC AC Source: TSG-SX WG4 Contact(s): Anand Palanigounder,
Broadcast Area Based Management for BCMCS Quanzhong Gao Weidong Wu 04/05/2005.
Security Framework for (e)HRPD 1 S GPP2 TSG-S WG4 Source: QUALCOMM Incorporated Contact(s): Anand Palanigounder
1 Title:Using group of artificial pilots to identify target femtocell during active hand-in Source:Peerapol Tinnakornsrisuphap, Ravindra Patwardhan QUALCOMM.
Authentication Profile for UICC- less eHRPD Terminals QUALCOMM Incorporated Contact(s): Anand Palanigounder Jun Wang.
Broadcast/Multicast Priority List JUNHYUK SONG SAMSUNG Incorporated grants a free, irrevocable license to 3GPP2 and its Organization Partners to incorporate.
1 A13 Proxy for supporting HRPD Handout from femto AP to macro AN Peerapol Tinnakornsrisuphap David Ott
C August 24, 2004 Page 1 SMS Spam Control Nobuyuki Uchida QUALCOMM Incorporated Notice ©2004 QUALCOMM Incorporated. All rights reserved.
1 SeGW Certificate profile (Revised) 3GPP2 TSG-S WG4 /TSG-X WG5 (PDS) S X xx Source: QUALCOMM Incorporated Contact(s): Anand.
Page 1 January 16, 2008 Source: 3GPP2 TSG-S WG4 (Security) Contacts: Anand Palanigounder, Chair, TSG-S WG4 ( Zhibi Wang,
Proposed 1x Device Binding Solution Based on SX & SX GPP2 TSG-SX WG4 SX Source(s): Qualcomm Incorporated.
80-VXXX-X A July 2008 Page 1 QUALCOMM Confidential and Proprietary PCC Support for cdma2000 QUALCOMM Inc. Jun Wang, George Cherian, Masa Shirota
Proposed Solution for Device Binding 3GPP2 TSG-S WG4 S Source: Qualcomm Incorporated Contact(s): Anand Palanigounder,
May 12, 2008 Alcatel Lucent, Cisco, Motorola, Nortel, Verizon ABSTRACT: Proposed is additional key hierarchy and derivation for EPS access over eHRPD.
1 1xBCMCS – Registration for Paging Ragulan Sinnarajah QUALCOMM Incorporated September 15 Notice.
1/19 BCMCS Support In IS-820-C (Stage 2) Lijun Zhao QUALCOMM July 20th, 2004.
Mobility Management in WLAN IW Inma Carrion, Vijay DevarapalliNokia Raymond HsuQualcomm Inc. Pete McCann, Frank AlfanoLucent Serge ManningSprint Notice:
FMS/TR-069 File Download Security Source: QUALCOMM Incorporated Contact(s): Anand Palanigounder Yinian Mao
1 Authentication and User Profile April 24, 2007 Jun Wang QUALCOMM Inc. Notice Contributors grant a free, irrevocable license to 3GPP2 and its Organization.
X xxx ZTE Discussion on cdma2000 Charging with PCC Title: Discussion on handover indicator transfer in S2a Sources: China Telecom, Huawei, Alcatel-Lucent.
Jun Wang Anand Palanigounder Peerapol Tinnakornsrisuphap
July 21, 2008 Alcatel Lucent ABSTRACT: Proposed is key derivation for eHRPD RAN Handoff. RECOMMENDATION: Review and approve. Notice Contributors grant.
HRPD Network Load Balance ZTE grants a free, irrevocable license to 3GPP2 and its Organizational Partners to incorporate text or other copyrightable material.
Active Call Hand-in in cdma2000 1x Airvana Qualcomm October 27 th, GPP2 Seoul, Korea Notice ©2008. All rights reserved. The contributors grants a.
Supporting Local Breakout in HRPD Femto Peerapol Tinnakornsrisuphap Qualcomm Doug Knisely
August 25, 2008 Alcatel Lucent ABSTRACT: 1x System Reliability is important in the face of major events, such as an earthquake. There are several ways.
Jun Wang Anand Palanigounder Peerapol Tinnakornsrisuphap
Remote access to Local IP network via Femto Peerapol Tinnakornsrisuphap Anand Palanigounder
X xxx ZTE Discussion on cdma2000 Charging with PCC Title: Inter-RAT RAN information management protocol Stack Sources: NSN Contact: Scott Marin,
Page 1 Notice © All rights reserved. Qualcomm Incorporated grants a free, irrevocable license to 3GPP2 and its Organizational Partners to incorporate.
Comment to Limited Idle Mode Nortel Networksgrants a free, irrevocable license to 3GPP2 and its Organizational Partners to incorporate text or other copyrightable.
1 Remote IP Access - Stage 2 Architecture proposal for adoption Peerapol Tinnakornsrisuphap Anand.
Mobile Sensing Measurement Report for supporting 1x Active Hand-in Peerapol Tinnakornsrisuphap Chirag Patel
Jun Wang Anand Palanigounder Peerapol Tinnakornsrisuphap
EHRPD-LTE Inter Technology Spectrum Optimization Source: Qualcomm Incorporated Contact: Jun Wang/George Cherian September 9, 2013 Notice ©2013. All rights.
X xx CT+ZTE PCC for cdma2000 MS Init Call Flows 1 1 Title: PCC for cdma2000 – MS-Init Call Flow Example Sources: CTC, ZTE Contact: CHINA TELECOM.
1 Title: Performance of Default Parameters for 1xEV-DO RTCMAC Source: Christopher Lott, QUALCOMM Incorporated , Date: Februrary.
1 HRPD Fast Handoff Jun Wang and Raymond Hsu Qualcomm Inc Notice: QUALCOMM Incorporated grants a free, irrevocable license to 3GPP2 and its Organization.
TSG-C SWG2.3 BCMCAHG Source: Lucent Technologies Contact: Krishna Balachandran Kenneth Budka Joseph Kang
1 On 3GPP2 Femto Security Anand Palanigounder Qualcomm Inc. Notice: Contributors grant a free, irrevocable license to 3GPP2 and its Organization.
1 OMP for Dual Rx AT in LTE tunneled mode Contributors grants a free, irrevocable license to 3GPP2 and its Organizational Partners to incorporate text.
C August 19, 2003 Page 1 SMS Push Teleservice Nobuyuki Uchida QUALCOMM Incorporated Notice ©2003 QUALCOMM Incorporated. All rights reserved.QUALCOMM.
1 MSI (Multiple Service Instances) Ravindra Patwardhan QUALCOMM Incorporated Review and approve for D Notice QUALCOMM.
WLAN IW Enhancement for Multiple Authentications Support QUALCOMM Inc.: Raymond Hsu, QUALCOMM Inc.: Masa Shirota,
3GPP2 A r0 3GPP2 C xxxr0 TSG-A WG3 and TSG-C WG2 Title: M2M Congestion Control in the RAN Source: Mike Dolan Dave Rossetti Satish.
1 IP Service Authorization Support and Mobility Selection Source: QUALCOMM Inc.: Masa Shirota, George Cherian, Jun Wang,
Source: Qualcomm Incorporated Contact: Jun Wang, George Cherian March 1, 2010 Page 1 3GPP2 Femtocell Phase II Femto Access Control Enhancement Notice ©
E-UTRAN - HRPD rev B Interworking
Presentation transcript:

Revised Solution for Device Binding Revised from S GPP2 TSG-SX WG4 SX Source: Qualcomm Incorporated Contact(s): Anand Palanigounder, Aram Perez, Recommendation: For Discussion & Decision Notice QUALCOMM Incorporated grants a free, irrevocable license to 3GPP2 and its Organizational Partners to incorporate text or other copyrightable material contained in the contribution and any modifications thereof in the creation of 3GPP2 publications; to copyright and sell in Organizational Partner’s name any Organizational Partner’s standards publication even though it may include all or portions of this contribution; and at the Organizational Partner’s sole discretion to permit others to reproduce in whole or in part such contribution or the resulting Organizational Partner’s standards publication. QUALCOMM Incorporated is also willing to grant licenses under such contributor copyrights to third parties on reasonable, non- discriminatory terms and conditions for purpose of practicing an Organizational Partner’s standard which incorporates this contribution. This document has been prepared by QUALCOMM Incorporated to assist the development of specifications by 3GPP2. It is proposed to the Committee as a basis for discussion and is not to be construed as a binding proposal on QUALCOMM Incorporated. QUALCOMM Incorporated specifically reserves the right to amend or modify the material contained herein and nothing herein shall be construed as conferring or offering licenses or rights with respect to any intellectual property of QUALCOMM Incorporated other than provided in the copyright statement above.

Overview Background Terms Solution Principles Device Binding Function Message Flow 2

Background This presentation proposes a high level solution to the Device Binding requirement in document S.R0146-0: – SEC-04: cdma2000 networks shall support a mechanism to restrict the use of a cdma2000 M2M access subscription to a specific cdma2000 M2M Device or a M2M group of devices. This is a revised contribution of S based on received comments 3

Terms BSC – Base Station Controller DBF – Device Binding Function FFS – For Future Study IE – Information Element IMSI – International Mobile Subscription Identifier ME – Mobile Equipment MEID – Mobile Equipment Identifier ME_SIG – signature calculated using the ME’s private key MIN – Mobile Identification Number MSID – Mobile Station Identifier MSC – Mobile Switching Center VLR – Visitor Location Register 4

Solution Principles (1) The solution is proposed for cdma2000 1x networks – Whether a solution is required for (e)HRPD is FFS If required, applicability of this proposed solution to (e)HRPD is FFS Device manufacturer provisions a private key associated with device identity (MEID) – How the device manufacturer issues the private key and certificate is outside the scope of standard The network has access to the certificate of a ME 5

Solution Principles (2) During the 1x registration process, the MSC/VLR queries the DBF (new logical entity) whether the subscription is restricted MSC/VLR sends a Status Request message requesting MEID authentication The BSC transparently forwards the Status Request / Response message from the MSC/VLR (Status Request) or ME (Status Response) 6

Solution Principles (3) MEs support the Device Binding functionality responds with a authentication signature in the Status Response message – NOTE: If the subscription requires Device Binding, but the ME does not respond with a signature, the network should deny service to the ME 7

Device Binding Function The Device Binding Function (DBF) is a new logical function in the network that – Determines whether a particular subscription, identified by the MSID associated with the subscription, is restricted to an ME or a group of ME’s. The ME is identified by its Mobile Equipment Identifier (MEID) – Maintains the mapping between MSIDs (subscription) and MEID bindings – Generates a nonce used to authenticate the ME – Performs authentication of MEID and sends a response to MSC/VLR indicating whether to allow / deny service to the MS DBF could be part of an existing network element or a new network element 8

Message Flow for 1x (1) The figure in the following slide shows the high level message flow for Device Binding in cdma2000 1x networks Color coding: – Items in red means something new being added 9

Message Flow for 1x (2) 10

Message Flow (3) 1.The MS sends 1x Registration request to BSC 2.The BSC, MSC/VLR and HLR perform Location Updating and exchange subscription authentication information 3.The BSC and MS perform the subscription authentication using either CAVE or AKA 4.The BSC and MSC/VLR confirms subscription authentication 11

Message Flow (4) A.The MSC/VLR sends a Device Restriction Query message that contains the MSID to the Device Binding Function (DBF). B.Based on the MSID, the DBF checks if the subscription is restricted to a ME or group of ME’s. – The DBF maintains the binding between the MSID and the ME’s. C.If the MSID is not restricted, the DBF sends a Device Restriction Response to the MSC/VLR with a Status value indicating that restriction is not required. The MSC/VLR continues with step 5 on slide

Message Flow (5) D.If the MSID is restricted, the DBF generates a random 128-bit Nonce value and sends a Device Restriction Response, with a Status value indicating that restriction is required and the Nonce. – The DBF saves the Nonce for the MSID to be used later in step J. E.The MSC/VLR sends a Status Request to the BSC, requesting the ME’s MEID and includes the Nonce that it received from the DBF. – The presence of the Nonce indicates to the ME that Device Authentication is required. 13

Message Flow (6) F.The BSC forwards the Status Request to the ME G.The ME generates a digital signature using the private key associated with the MEID over the Nonce, MSID and MEID, called ME_SIG, and includes it in the Status Response to the BSC along with the MEID. – If the ME does not support this security framework, it sends back a normal Status Response with just the MEID. 14

Message Flow (7) H.The BSC forwards the Status Response to the MSC/VLR. I.The MSC/VLR sends a Validate Device Request message to the DBF. The message includes the MSID, the MEID and the ME_SIG from the MS. 15

Message Flow (8) J.The DBF validates the ME by checking that the MSID and MEID pairing is allowed. If not allowed, validation fails and the message flows continues with step K. If allowed, then the DBF uses the Nonce it saved in step D to verify the ME_SIG. In addition, in order to verify the ME_SIG, the DBF needs to have access to the certificate associated with the MEID. – How the DBF gets access to the certificate is outside the scope of this framework. 16

Message Flow (9) K.Based on the validation result, the DBF sends a Validate Device Response message to the MSC/VLR with the Status set to Allow if the binding is successfully validated by the DBF or Deny otherwise. L.If the Status is Allow, the MSC/VLR accepts the registration (step 5 on slide 18). M.If the Status is Deny, the MSC/VLC sends MS registration rejection. 17

Message Flow (10) 5.The BSC informs the MS that it has been registered 18

Proposal Discuss & Adopt the solution concept 19