Methods for handling security of early mobile-terminated data transmissions
There is provided a method in a target network node for performing early data transmission (EDT) when a wireless device has suspended a connection from a source network node. The method comprises: receiving ciphered data from a first network node; sending a message to the wireless device, the message comprising the ciphered data; and in response to the sent message, receiving a message from the wireless device, the message allowing the target network node to retrieve a User Equipment (UE) context of the wireless device from the source network node.
1 . A method in a target network node for performing early data transmission (EDT), the method comprising:
when a wireless device has suspended a connection from a source network node receiving ciphered data from a first network node;
sending a message to the wireless device, the message comprising the ciphered data together with control information, the control information comprising a time advance and an uplink (UL) grant;
in response to the sent message, receiving a message from the wireless device, wherein the message received from the wireless device comprises a resume Identifier (ID), and wherein the message from the wireless device allows the target network node to retrieve a User Equipment (UE) context of the wireless device from the source network node based at least on the resume ID; and
upon reception of the message from the wireless device, performing by a target evolved node B (eNB) and a source eNB, legacy context fetch based on the resumeID.
2 . The method of claim 1 , wherein the first network node is the source network node.
3 . The method of claim 1 , further comprising receiving a message from a second network node, the message from the second network node including an identity (ID) of the wireless device and an identity of the first network node.
4 . The method of claim 3 , further comprising sending, to the first network node, a request to obtain data directed to the wireless device, the request including the ID of the wireless device and wherein receiving the ciphered data is in response to the request to obtain the data directed to the wireless device.
5 . The method of claim 4 , wherein the request to obtain the data comprises an indication of a request to re-activate a UE context of the wireless device at the first network node.
6 . The method of claim 1 , wherein the first network node is a Mobility Management Entity (MME).
7 . The method of claim 6 , further comprising sending a notification to the MME for indicating that the ciphered data have been successfully transmitted to the wireless device.
8 . The method of claim 1 , further comprising sending a paging message to the wireless device, the paging message including a random preamble.
9 . The method of claim 1 , wherein the ciphered data are ciphered using one of a current security key and a new security key based on a re-activated UE context.
10 . A target network node, comprising a communication interface and processing circuitry connected thereto and configured to perform:
when a wireless device has suspended a connection from a source network node, receiving ciphered data from a first network node;
sending a message to a wireless device, the message comprising the ciphered data together with control information, the control information comprising a time advance and an uplink (UL) grant;
in response to the sent message, receiving a message from the wireless device, wherein the message received from the wireless device comprises a resume Identifier (ID), and wherein the message from the wireless device allows the target network node to retrieve a User Equipment (UE) context of the wireless device from a source network node based at least on the resume ID; and
upon reception of the message from the wireless device, performing by a target evolved node B (eNB) and a source eNB, legacy context fetch based on the resumeID.
11 . A method in a source network node for performing early data transmission (EDT), the method comprising:
when a wireless device has suspended a connection from a source network node, re-activating a User Equipment (UE) context of the wireless device for ciphering data received from a serving gateway, the data comprising an ID of the UE allocated by the source network node to the wireless device, wherein the source network node allows a target evolved node B (eNB) to know which source network node, the wireless device was suspended from, whereas the ID of the UE allows the network node to know for which wireless device it needs to locate the context;
receiving a request to retrieve the UE context from a target network node, wherein retrieving the UE context of the wireless device is based at least on a resume identifier that is comprised in a message received by the target network node from the wireless device; and
upon reception of the message from the wireless device, performing by the target eNB and a source eNB, legacy context fetch based on the resumeID.
12 . The method of claim 11 , further comprising ciphering the data based on the re-activated UE context and sending the ciphered data to a first network node.
13 . The method of claim 12 , wherein the first network node is the target network node.
14 . The method of claim 12 , further comprising receiving a request for data for early data transmission from the target network node.
15 . The method of claim 14 , further comprising, in response to the received request, sending a new request to re-activate the UE context to a second network node, wherein the new request to re-activate the UE context comprises a UE context resume request, and wherein the second network node is a Mobility Management Entity (MME).
16 . The method of claim 12 , wherein the first network node is a MME, which forwards the ciphered data to the target network node.
17 . The method of claim 16 , further comprising receiving a paging message that includes an indication of the EDT and sending a request to re-active the UE context in response to receipt of the paging message.
18 . The method of claim 12 , wherein ciphering the received data based on the re-activated UE context comprises ciphering the received data using one of a current security key and a new security key associated with the re-activated UE context.
19 . The method of claim 12 , further comprising initiating a UE context fetch procedure with the target network node in response to receiving the request to retrieve the UE context.