Method for authenticating access layer on basis of public key infrastructure in consideration of handover in next-generation wireless communication system
The present disclosure relates to a 5G or 6G communication system for supporting higher data transmission rates than 4G communication systems such as LTE. In a wireless communication system according to an embodiment of the present invention, an operation method of a serving base station for mutual authentication in an access stratum (AS) section during handover comprises the steps of: receiving a measurement report from a terminal; confirming whether the terminal meets handover conditions on the basis of the measurement report; if the terminal meets the handover conditions, confirming whether a target base station, to which the terminal is to be connected during handover, belongs to the same authentication area (AA) as the serving base station; and transmitting, to the terminal, a handover command that is configured differently according to whether the target base station and the serving base station belong to the same AA.
1 . A method of operating a serving base station (BS) for mutual authentication of an access stratum (AS) section in case that handover is performed in a wireless communication system, the method comprising:
receiving a measurement report from a user equipment (UE);
identifying whether the UE satisfies a handover condition, based on the measurement report;
in case that the UE satisfies the handover condition, identifying whether a target BS connected for handover of the UE belongs to a same authentication area (AA) as that of the serving BS;
transmitting, to the UE, a handover command including inter-AA handover information or intra-AA handover information depending on whether the target BS and the serving BS belong to the same AA, wherein the inter-AA handover information is transmitted in case that the target BS and the serving BS do not belong to the same AA, and wherein the intra-AA handover information is transmitted in case that the target BS and the serving BS belong to the same AA; and
transmitting, to the target BS, a public key infrastructure (PKI)-based authentication packet in case that a PKI-based mutual authentication between the UE and the target BS is completed based on the inter-AA handover information.
2 . The method of claim 1 , wherein the PKI-based mutual authentication between the UE and the target BS is not performed and a key update procedure for the target BS is performed by the UE in case that the intra-AA handover information is transmitted.
3 . The method of claim 1 , wherein the AA is a set of cells served by a physically or logically same computing node.
4 . The method of claim 3 , wherein the same computing node is a logically or physically equal computing node,
the logically same computing node is implemented as software of a same operator, software having an same right, or software performing an same process, and
the physically same computing node is implemented as hardware of a same operator, hardware having an same right, or an same hardware component.
5 . The method of claim 2 , wherein, in case that the inter-AA handover information is received, the UE and the serving BS detach from each other and then the PKI-based mutual authentication between the UE and the target BS is performed.
6 . The method of claim 2 , wherein
the serving BS transmits a PKI-based authentication packet to a network entity, and
the PKI-based authentication packet is transferred to the target BS by the network entity.
7 . A method of operating a user equipment (UE) for mutual authentication of an access stratum (AS) section in case that handover is performed in a wireless communication system, the method comprising:
receiving, from a serving BS for the UE, a handover command including inter-authentication area (AA) handover information or intra-AA handover information depending on whether a target BS for the UE and the serving BS belong to a same AA, wherein the inter-AA handover information is received in case that the target BS and the serving BS do not belong to the same AA, and the intra-AA handover information is received in case that the target BS and the serving BS belong to the same AA; and
performing public key infrastructure (PKI)-based mutual authentication with the target BS based on the inter-AA handover information.
8 . The method of claim 7 , wherein the PKI-based mutual authentication between the UE and the target BS is not performed and a key update procedure for the target BS is performed by the UE in case that the intra-AA handover information is received.
9 . The method of claim 7 , wherein the AA is a set of cells served by a physically or logically same computing node.
10 . The method of claim 8 , wherein, in case that the inter-AA handover information is received, the UE detaches from the serving BS and then performs the PKI-based mutual authentication with the target BS.
11 . A serving base station (BS) supporting mutual authentication of an access stratum (AS) section in case that handover is performed in a wireless communication system, the BS comprising:
a transceiver; and
a controller connected to the transceiver and configured to control the transceiver and perform control to:
receive a measurement report from a user equipment (UE),
identify whether the UE satisfies the handover condition, based on the measurement report, in case that the UE satisfies the handover condition,
identify whether a target BS connected for handover of the UE belongs to a same authentication area (AA) as that of the serving BS,
transmit, to the UE, a handover command including inter-AA handover information or intra-AA handover information depending on whether the target BS and the serving BS belong to the same AA, wherein the inter-AA handover information is transmitted in case that the target BS and the serving BS do not belong to the same AA, and wherein the intra-AA handover information is transmitted in case that the target BS and the serving BS belong to the same AA, and
transmit, to the target BS, a public key infrastructure (PKI)-based authentication packet in case that a PKI-based mutual authentication between the UE and the target BS is completed based oin the inter-AA handover information.
12 . A user equipment (UE) for mutual authentication of an access stratum (AS) section in case that handover is performed in a wireless communication system, the UE comprising:
a transceiver; and
a controller connected to the transceiver and configured to control the transceiver and perform control to:
receive, from a serving BS, a handover command including inter-authentication area (AA) handover information or intra-AA handover information depending on whether a target BS for the UE and the serving BS belong to a same AA, wherein the inter-AA handover information is received in case that the target BS and the serving BS do not belong to the same AA, and wherein the intra-AA handover information is received in case that the target BS and the serving BS belong to the same AA, and
perform public key infrastructure (PKI)-based mutual authentication with the target BS, based on the inter-AA handover information.