Method for Dynamically Providing a Key for Authentication in a Relay Device
By dynamically generating layer security keys and PSKs in IAB relay devices, the cost and delay problems caused by preconfigured security credentials are solved, and a more efficient and flexible authentication process is achieved, supporting the rapid deployment of IAB relay devices.
Patent Information
- Application Number
- CN202010546592.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-06-14
- Filing Date
- 2020-06-15
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2040-07-30
AI Technical Summary
During the authentication process of IAB relay devices in existing 5G communication systems, pre-configured security credentials lead to increased manufacturing costs, complex management work and delays, and cannot support the rapid deployment of ad-hoc and temporary IAB relay devices.
The layer security key is dynamically generated at the IAB relay device, and a pre-shared key (PSK) is generated based on the key, which is used for IKEv2 authentication, skipping the pre-configured security credential process, and implementing AS and NAS security establishment through MT functions, and optimizing the authentication process.
It reduces the workload of certification management, reduces certification delay, supports plug-and-play of IAB relay devices, simplifies security credential management, and improves system flexibility and efficiency.
Smart Images

Figure CN112087754B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an electronic device, and more particularly, to a method for dynamically providing a key for Internet Key Exchange (IKE) v2 pre-shared key (PSK) authentication and an integrated access and backhaul (IAB) relay device. Background Art
[0002] In order to meet the increasing demand for wireless data services since the self-deployment of 4G communication systems, efforts have been made to develop improved 5G or pre-5G communication systems. Therefore, 5G or pre-5G communication systems are also referred to as "ultra 4G networks" or "post-LTE systems". The 5G communication system is considered to be implemented in a higher frequency (mmWave) band (e.g., 60 GHz band) to achieve higher data rates. In order to reduce the propagation loss of radio waves and increase the transmission distance, beamforming, massive multiple-input multiple-output (MIMO), full-dimension MIMO (FD-MIMO), array antennas, analog beamforming, and massive antenna technology have been discussed in the 5G communication system. In addition, in the 5G communication system, system network improvements are being developed based on advanced small cells, cloud radio access network (RAN), ultra-dense networks, device-to-device (D2D) communication, wireless backhaul, mobile networks, cooperative communication, coordinated multi-point (CoMP), receiver interference cancellation, etc. In the 5G system, hybrid FSK and QAM modulation (FQAM) and sliding window superimposed coding (SWSC) as advanced coding modulation (ACM), and filter bank multi-carrier (FBMC), non-orthogonal multiple access (NOMA), and sparse code multiple access (SCMA) as advanced access technologies have been developed.
[0003] The Internet is a human-centered connection network in which humans generate and consume information. Now the Internet is evolving towards the Internet of Things (IoT), in which distributed entities (such as things) exchange and process information without human intervention. The Internet of Everything (IoE) has emerged, which is a combination of IoT technology and big data processing technology through connection with a cloud server. Since the implementation of IoT requires technical elements such as "sensing technology", "wired / wireless communication and network infrastructure", "service interface technology", and "security technology", research has recently been conducted on sensor networks, machine-to-machine (M2M) communication, machine type communication (MTC), etc. Such an IoT environment can provide intelligent Internet technology services that create new value for human life by collecting and analyzing data generated between connected things. By the fusion and combination between existing information technology (IT) and various industrial applications, IoT can be applied to various fields, including smart homes, smart buildings, smart cities, smart cars or connected cars, smart grids, healthcare, smart appliances, and advanced medical services.
[0004] In line with this, various attempts have been made to apply 5G communication systems to IoT networks. For example, technologies such as sensor networks, machine type communication (MTC), and machine-to-machine (M2M) communication can be implemented through beamforming, MIMO, and array antennas. Cloud radio access network (RAN), as an application of the above big data processing technology, can also be regarded as an example of the convergence between 5G technology and IoT technology.
[0005] Deploying a faster 5G network requires wireless backhaul and relay links. Wireless backhaul and relay links can flexibly and densely deploy NR cells and radio extensions without the densification of the transmission network. Integrated access backhaul (IAB) devices are used to implement wireless backhaul and relay links. Figure 1A-1B The network architecture of IAB according to the prior art is shown. The IAB donor device is connected to components of the core network such as gNB through the Xn interface, access and mobility management function (AMF), or user plane function (UPF) through the NG interface. The IAB donor (i.e., the IAB donor device) is a next-generation radio access network (NG-RAN) node that supports IAB features and provides a connection to the core network for IAB nodes.
[0006] The IAB donor supports the control unit (CU) function of the control unit / distribution unit (CU / DU) architecture of IAB defined in TS 38.401. The IAB node (i.e., the IAB relay device) is a relay node that supports wireless in-band and out-of-band relaying of NR access services through the NR Uu backhaul link. The IAB relay device supports the user equipment (UE) function and distribution unit (DU) function of the CU / DU architecture of IAB defined in TS 38.401. The CU function of the IAB donor device allows the IAB donor device to operate as a typical gNB. The DU function of the IAB donor device allows the IAB donor to provide an NR backhaul link to the IAB relay device through the F1 interface. The NR backhaul link operates as a typical NR link for backhaul between the IAB donor device and the IAB relay device and, in the case of a multi-hop network, between IAB relay devices.
[0007] The part of the IAB relay device that supports the Uu interface to the IAB donor device or another parent IAB relay device is called the IAB-UE (or IAB-MT). The backhaul connection between the IAB relay device or the IAB donor device or another parent IAB relay device and the public land mobile network (PLMN) is managed through the Uu interface. The DU (or gNB-DU) function in the IAB relay device is responsible for providing NR Uu access to the UE and the sub-IAB nodes. The corresponding gNB-CU function resides on the IAB donor gNB, which controls the IAB node gNB-DU through the F1 interface. The IAB relay device is a normal gNB to the UE and other IAB nodes and allows them to connect to the 5GC. The UE or mobile terminal (MT) function of the IAB relay device allows the IAB relay device to operate as a radio access network (RAN) node. The DU function of the IAB relay device allows the UE (UE) to connect to the IAB relay device. The DU function of the IAB relay device, together with the CU function on the IAB donor device, provides access to the core network for the sub-IAB relay device and the UE in the southbound direction. The IAB relay device uses the MT function to connect to the IAB donor device or the parent IAB relay device through the NR Uu interface. The IAB relay device receives data from the core network through the DU function of the IAB device via the NR backhaul link. The Uu backhaul link can exist between the IAB relay device and the gNB called the IAB donor device or another IAB node relay device.
[0008] The IAB relay device accesses the core network by operating in the new radio stand-alone (NR-SA) mode or the new radio non-stand-alone (NR-NSA) mode (i.e., the E-UTRAN new radio-dual connectivity (EN-DC) mode). Figure 2 The SA-based integration of the new IAB relay device to the core network according to the prior art is shown. The SA-based integration of the new IAB relay device to the core network includes three phases, namely Phase 1, Phase 2, and Phase 3.
[0009] Phase 1: Through the execution of the RRC connection establishment process with the CU function of the IAB donor device, authentication with the core network, context management related to the new IAB relay device, radio bearer configuration related to the access service of the new IAB relay device at the RAN, and optional operation, administration, and maintenance (OAM) connection establishment, the UE / MT function of the new IAB relay device connects to the core network as a normal UE.
[0010] Phase 2: As part of Phase 2, two steps are performed, 1) Backhaul Radio Link Control (RLC) channel establishment and 2) Routing update. In Phase 2-1: Backhaul RLC channel establishment, a backhaul RLC channel is established for CP traffic in Phase 2-1. For example, F1-C messages (i.e., messages sent over the F1 interface) are established to and from the IAB relay device in Phase 2-1. In Phase 2-2: Routing update, the Backhaul Adaptation Protocol (BAP) layer is updated in Phase 2-2 to support routing between the new IAB relay device and the DU function of the IAB donor device. Updating the BAP layer includes configuring a BAP routing identifier for routing in the downlink direction on the DU function of the IAB donor, and configuring a BAP routing identifier for the uplink direction on the MT function of the IAB relay device. In addition, the routing table is updated for all parent IAB relay devices and the DU function of the IAB donor device with routing entries for the new BAP routing identifier. In addition, the DU function of the new IAB relay device is configured with an IP address to establish an IP connection to the core network.
[0011] Phase 3: In Phase 3, i.e., the IAB-DU part establishment, the DU (gNB-DU) function of the IAB relay device is configured. The DU function of the IAB relay device initiates the establishment of an F1-C connection (i.e., a link over the F1 interface) with the CU function of the IAB donor device. After the link is established over the F1 interface, the IAB relay device starts serving the UE.
[0012] An independent authentication mechanism using Internet Key Exchange values (e.g., IKEv2) is performed in Phase 3 for the establishment of a secure F1 interface using Internet Protocol Security (IPsec). Since the MT function and the DU function of the IAB node are independent, both functions perform independent authentication between the IAB relay device and the core network to establish independent security contexts. Since independent authentication is to be performed through each function, multiple credentials are required at the core network and the IAB relay device (e.g., AKA credentials for the UE function (Uu interface) and private keys and certificates for the DU function (F1 interface)), which results in an increase in manufacturing costs and administrative work. In addition, performing independent authentication results in overhead during the execution of multiple redundant authentication executions without security benefits.
[0013] In addition, performing independent identity authentication increases the latency in establishing a secure F1 interface. Additionally, security credentials (e.g., pre-configured certificates, pre-shared keys (PSKs)) are manually configured and re-used for the authentication process for a long time until the credentials are updated. Therefore, an operation, administration, and maintenance (OAM) architecture is also required to configure refreshed credentials to avoid possible re-use of the same key. Moreover, pre-configuration has limitations in scenarios such as mission-critical (e.g., disaster) scenarios and locations or in scenarios of temporary events such as movement, because the IAB donor device at that location requires a security configuration to establish an F1 secure interface, but it is crucial to support ad-hoc and temporary IAB relay devices without any OAM pre-configuration. Therefore, it is desirable to address the above drawbacks or at least provide a useful alternative. Summary of the Invention
[0014] Object of the Invention
[0015] The main object of the embodiments herein is to provide a method for authentication and an IAB relay device, and dynamically generate a PSK for IKEv2 PSK authentication to avoid pre-configuration of relatively weak security credentials.
[0016] Another object of the embodiments herein is to generate a layer security key at an IAB relay device in a wireless network by authenticating using the UE function of the IAB relay device with an IAB donor device or an AMF of a wireless network.
[0017] Another object of the embodiments herein is to generate a layer security key for secure establishment with an IAB donor device.
[0018] Another object of the embodiments herein is to generate a pre-shared key (PSK) based on the layer security key.
[0019] Another object of the embodiments herein is to use the PSK to generate IKEv2 values for establishing the security of the F1 interface with an IAB donor device.
[0020] Another object of the embodiments herein is to establish the security of the F1 interface with an IAB donor device by skipping the authentication process that uses pre-configured security credentials.
[0021] Abstract
[0022] Accordingly, embodiments of the present disclosure provide a method for authentication at an IAB relay device in a wireless network. The method includes generating, by the IAB relay device, a layer security key for one of access stratum (AS) security establishment and non-access stratum (NAS) security establishment with an IAB donor device in the wireless network. Additionally, the method includes generating, by the IAB relay device, a PSK based on the layer security key. Additionally, the method includes generating IKEv2 values using the PSK to establish F1 interface security with the IAB donor device.
[0023] In one embodiment, when the IAB relay device connects to the IAB donor device through a handover from a base station, where the base station in the wireless network provides a security key of the MT function of the IAB relay device to the IAB donor device for generating the layer security key.
[0024] In one embodiment, when the IAB relay device connects to the IAB donor device after power-on or for a registration / attachment process, the IAB relay device uses the MT function of the IAB relay device to perform authentication with the IAB donor device to generate the layer security key.
[0025] In one embodiment, the MT function of the IAB relay device provides the PSK to the DU function of the IAB relay device in response to generating the PSK.
[0026] In one embodiment, in the case of establishing F1 interface security with the IAB donor device, it includes generating, by the IAB donor device, a layer security key for AS security establishment, generating, by the IAB donor device, a PSK based on the layer security key for AS security establishment, and generating, by the IAB donor device, IKE values using the PSK to establish F1 interface security with the IAB relay device.
[0027] In one embodiment, establishing F1 interface security with the IAB donor device includes: generating, by the AMF of the wireless network, a layer security key for NAS security establishment; generating, by the AMF, a PSK based on the layer security key for NAS security establishment; sending, by the AMF, the PSK to the IAB donor device; and in response to receiving the PSK, generating, by the IAB donor device, IKE values using the PSK to establish F1 interface security with the IAB relay device.
[0028] In one embodiment, the layer security key is an AS security key and a NAS security key respectively for AS establishment and NAS security establishment.
[0029] In one embodiment, the PSK is generated using at least one of the following: K SN 、K gNB 、S-K gNB 、K AMF, IAB count, Physical Cell Identifier (PCI), Absolute Radio Frequency Channel Number - Downlink (ARFCN-DL), gNB identifier of the IAB donor device, address of the control unit (CU) of the IAB donor device, address of the IAB relay device, identifier of the IAB relay device, cell identifier, key (K UPenc ) for user plane encryption, key (K UPenc ) for user plane integrity, access type discriminator, uplink NAS count, and other possible parameters.
[0030] In one embodiment, the IAB relay device establishes the F1 interface security with the IAB donor device by skipping the authentication process using pre-configured security credentials.
[0031] Accordingly, the embodiments herein provide an IAB relay device for authentication. The IAB relay device includes a memory, a processor, and an authentication controller, where the processor is coupled to the memory. The authentication controller is coupled to the processor. The authentication controller is configured to generate a layer security key for one of the AS security establishment and NAS security establishment with the IAB donor device in a wireless network. The authentication controller is configured to generate a PSK based on the layer security key. The authentication controller is configured to use the PSK to generate an IKE value to establish the F1 interface security with the IAB donor device.
[0032] These and other aspects of the embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. However, it should be understood that the following description, although indicating the preferred embodiments and many of their specific details, is given by way of illustration and not limitation. Many changes and modifications may be made within the scope of the embodiments of the present invention without departing from the spirit of the invention, and the embodiments of the present invention include all such modifications. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] The method and apparatus are illustrated in the accompanying drawings, in which like reference numerals denote corresponding parts in different drawings. The embodiments herein will be better understood by reference to the following description of the drawings, in which:
[0034] Figure 1A-1B shows the network architecture of an IAB device according to the prior art;
[0035] Figure 2 shows the stand-alone based integration of a new IAB relay device to the core network according to the prior art;
[0036] Figure 3A block diagram of an IAB relay device in a wireless network for generating and using a dynamic PSK without using pre-configured security credentials for establishing a secure F1 interface;
[0037] Figure 4 A flowchart showing a method for generating and using a dynamic PSK for authentication at an IAB relay device according to embodiments disclosed herein;
[0038] Figure 5 A sequence diagram showing signaling between components in a wireless network for establishing F1 interface security by skipping the authentication process using pre-configured security credentials according to embodiments disclosed herein;
[0039] Figure 6 A sequence diagram showing signaling between components in a wireless network for establishing F1 interface security when the layer security key is an AS security key according to embodiments disclosed herein;
[0040] Figure 7 A sequence diagram showing signaling between components in a wireless network for establishing F1 interface security when the layer security key is a NAS security key according to embodiments disclosed herein; and
[0041] Figure 8 Shows an example scenario of generating a PSK using various parameters according to embodiments disclosed herein. Detailed Description
[0042] The embodiments herein and their various features and advantageous details will be more fully explained with reference to the non-limiting embodiments shown in the accompanying drawings and described in detail below. Descriptions of well-known components and processing techniques are omitted so as not to unnecessarily obscure the embodiments herein. Further, the various embodiments described herein are not necessarily mutually exclusive, as some embodiments can be combined with one or more other embodiments to form new embodiments.
[0043] Unless otherwise specified, the term "or" used herein refers to a non-exclusive or. The examples used herein are merely for facilitating an understanding of the manner in which the embodiments herein can be implemented and further enabling those skilled in the art to implement the embodiments herein. Therefore, these examples should not be construed as limiting the scope of the embodiments herein. When considering a dual-connectivity architecture, the term "K gNB " also refers to "S-K gNB " or "K SN", and are used interchangeably in this document. In addition, when an IAB node is connected to a 5GC or a gNB or an eBN, the term "base station" may also be an "IAB donor device". The terms "IAB donor device" or "IAB donor" or "IAB donor gNB" have the same meaning and are used interchangeably throughout the document. The terms "IAB relay device" or "IAB node" have the same meaning and are used interchangeably throughout the document. In addition, in an IAB relay device, the terms "MT function" and "IAB-UE function" are the same and are used interchangeably throughout the document.
[0044] As is conventional in the art, embodiments may be described and illustrated in terms of blocks that perform one or more of the described functions. These blocks may herein be referred to as managers, units, modules, hardware components, etc., which are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits, etc., and may optionally be driven by firmware and software. For example, the circuits may be implemented in one or more semiconductor chips or on a substrate support such as a printed circuit board. The circuits constituting the blocks may be implemented by dedicated hardware, or by a processor (e.g., one or more programmed microprocessors and associated circuits), or by a combination of dedicated hardware performing some of the functions of the block and a processor performing other functions of the block. Without departing from the scope of the present disclosure, each block of an embodiment may be physically divided into two or more interacting discrete blocks. Similarly, without departing from the scope of the present disclosure, the blocks of an embodiment may be physically combined into more complex blocks.
[0045] Embodiments herein provide a method for authentication by dynamically generating a security credential (i.e., a pre-shared key (PSK)) in a plug-and-play scenario at an integrated access and backhaul (IAB) relay device (100) in a wireless network without pre-configuring an F1 security credential. The benefit of the dynamically generated PSK is future-proofing, where each installation will have an independently cryptographically generated key that is automatically calculated and does not require a program to supply or configure the PSK. The key will be new for each deployment or restart of the IAB node. The IAB node only needs network access credentials to complete the IAB integration process, while pre-configured credentials require additional credentials. The present disclosure addresses the mechanism for dynamic key derivation and provisioning, while pre-configuration of security credentials (e.g., certificates) requires additional entities and processes in the IAB node and the IAB donor. Each IKEv2 authentication derives an independent unique PSK, while pre-configuration uses the same credentials for each IKEv2 authentication.
[0046] The method includes generating, by an IAB relay device, a layer security key for one of an access stratum (AS) security establishment and a non-access stratum (NAS) security establishment with an IAB donor device in a wireless network. Further, the method includes generating, by the IAB relay device, a PSK based on the layer security key. Further, the method includes generating, using the PSK, an Internet Key Exchange (IKE) version 2 AUTH value for performing mutual authentication and establishing F1 interface security with the IAB donor device.
[0047] Traditionally, an IAB relay device uses an IAB-UE function and a DU (i.e., gNB-DU in an IAB node) function to perform independent authentication. Different from traditional methods and systems, the proposed method allows the IAB relay device to use an MT function to perform independent authentication and derive NAS and AS security keys. The NAS / AS layer security keys are used to derive a PSK, where the PSK is further used to directly calculate an AUTH value (i.e., an IKEv2 value). Thus, an authentication process such as EAP-TLS, EAP-AKA, or authentication using pre-configured credentials such as certificates, (static) pre-configured PSKs, etc. is skipped / replaced for establishing F1 interface security. Thus, the authentication and establishment of RRC security and IPsec are optimized without compromising the security level. Thus, the management effort of authentication can be reduced by only having a single credential using the MT function. Further, by implementing the proposed method, the overhead of performing multiple redundant authentications at the IAB relay device is reduced. Further, the latency is reduced when establishing a secure F1 interface. In one embodiment, during a UE capability exchange process, the IAB relay device indicates support for a dynamic PSK capability.
[0048] In one embodiment, the network enforces the use of a dynamic PSK through a pre-configured policy to perform IKEv2 authentication using the dynamic PSK in the IAB donor device and the IAB relay device, e.g., using an OAM process or using manual configuration, etc. In another embodiment, the IAB relay device indicates that it uses the dynamic PSK to generate an AUTH value in a vendor ID payload. In another embodiment, when IKEv2 performs PSK authentication using the dynamic PSK, in an IKE_AUTH request message, the IAB node may set the ID type to ID_KEY_ID and set its value to a reserved value that is known to the IAB donor device and the IAB relay device.
[0049] Now referring to the drawings, and more particularly to Figures 3 to 8 , a preferred embodiment is shown.
[0050] Figure 3Block diagram of an IAB relay device (100) in a wireless network (1000) that is pre-configured to generate and use a dynamic PSK without using security credentials for establishing a secure F1 interface, according to embodiments disclosed herein. In one embodiment, the wireless network (1000) includes an IAB relay device (100), an IAB donor device (200), a base station (300), and an access and mobility management function (AMF) (400). The base station (300) and the AMF (400) are components of a core network (not shown in the figure) of the wireless network (1000). In one embodiment, the base station (300) can be an IAB donor device (200) or a gNB or an eNB. In one embodiment, the IAB donor device (200) includes a central unit (CU) function (210) and a distribution unit (DU) function (220). In the present disclosure, the terms "CU function (210)" and "CU (210)" have the same meaning and are used interchangeably. In the present disclosure, the terms "DU function (220)" and "DU (220)" are used interchangeably and have the same meaning. The IAB donor device (200) is connected to at least one of the base station (300) and the AMF (400).
[0051] In one embodiment, the IAB relay device (100) includes an authentication controller (110), a memory (120), a processor (130), a mobile terminal (MT) function (140), a DU function (150), and a communicator (160). In the present disclosure, the terms "MT function (140)", "UE function (140)", "UE (140)", and "MT (140)" are used interchangeably and have the same meaning. Throughout the present disclosure, the terms "DU function (150)", "gNB-DU (150)", and "DU (150)" are used interchangeably. In one embodiment, the authentication controller 110 includes a layer security key generator (111), a PSK generator (112), and an IKE value generator (113). In one embodiment, the layer security key generator (111) and the PSK generator (112) use a key derivation function (KDF), while the IKE value generator (113) uses a pseudorandom function (PRF). Examples of KDF are HMAC-SHA-256. Examples of PRF are AES-XCBC-PRF-128, AES-CMAC-PRF-128, PRF_HMAC_MD5, PRF_HMAC_SHA1, PRF_HMAC_TIGER, and so on.
[0052] The authentication controller (110) is configured to generate a layer security key for access stratum (AS) security establishment or non-access stratum (NAS) security establishment with the IAB donor device (200). In one embodiment, the layer security key is an AS security key (KSN or K gNB or S-K gNB ) and NAS security key (K AMF ). In one embodiment, the layer security key generator (111) generates layer security keys for AS security establishment and NAS security establishment with the IAB donor device (200). In one embodiment, the layer security key generator (111) configures the MT (140) to derive the layer security key.
[0053] In one embodiment, the authentication controller (110) is configured to perform authentication with the core network when the IAB relay device (100) connects to the IAB donor device (200) after power-on or for an initial registration / attachment process, to establish a secure RRC connection with the core network. In response to successful authentication, a secure RRC connection is established between the IAB relay device (100) and the core network for secure exchange of RRC messages. In addition, the authentication controller (110) is configured to generate a layer security key in response to establishing the secure RRC connection. In one embodiment, the MT function (140) performs authentication with the core network when the IAB relay device (100) connects to the IAB donor device (200) after power-on or for an initial registration / attachment process, to establish a secure RRC connection with the core network. In addition, the layer security key generator (111) generates a layer security key in response to establishing the secure RRC connection.
[0054] In another embodiment, when the IAB relay device (100) connects to the IAB donor device (200) by handover or as part of a dual connectivity process from the base station (300), the base station (300) provides the security key of the MT function (140) of the IAB relay device (100) to the IAB donor device (200). In addition, the authentication controller (110) is configured to generate a layer security key in response to receiving the security key of the MT function (140). In one embodiment, in response to receiving the security key of the MT function (140), the layer security key generator (111) generates a layer security key.
[0055] The authentication controller (110) is configured to generate a pre-shared key (PSK) based on the layer security key. In the present disclosure, the terms "PSK", "pre-shared key", and "K IAB” can be used interchangeably. In one embodiment, the PSK generator (112) generates the PSK based on the layer security key. In one embodiment, the PSK generator (112) configures the MT (140) to derive the PSK. In one embodiment, the MT function (140) provides the PSK to the DU function (150) in response to generating the PSK. In one embodiment, depending on the deployment scenario, the MT function (140) and the DU function (150) have an internal / proprietary interface, that is, the MT function (140) and the DU function (150) are logically separated or can be physically separated. Similarly, the CU (210) and the DU (220) are also separated. In this case, the MT function (140) generates the PSK and provides it to the DU function (150) using the internal / proprietary interface or through a standardized interface, which can be provided together with other parameters provided by the MT function (140) to the DU function (150) (for example, the DU configuration received by the IAB-node-UE from the core network (via RRC) is provided to the IAB-node-DU).
[0056] In another embodiment, the DU function (150) sends a key request including necessary information (such as the address of the CU (210)) to the MT function (140). When the PSK is not available to the MT function (140), the MT function (140) derives the PSK and provides the derived secret PSK to the DU function (150). In one embodiment, the PSK is generated using at least one parameter. The parameter includes K SN , K gNB , S-K gNB , K AMF , IAB count, physical cell identifier (PCI), absolute radio frequency channel number - downlink (ARFCN-DL), gNB identifier of the IAB donor device (200), address of the CU (210) of the IAB donor device (200), address of the IAB relay device (100), identifier of the IAB relay device (100), cell identifier, key for user plane encryption (K UPenc ), key for user plane integrity (K UPint ), access type discriminator, uplink NAS count, and other possible parameters.
[0057] The authentication controller (110) is configured to generate an Internet Key Exchange (IKE) authentication (AUTH) value using the generated PSK to establish the F1 interface security with the IAB donor device (200). In one embodiment, the IKE value generator (113) generates the IKE value using the PSK. In one embodiment, the IKE value generator (113) configures the DU (150) to derive the IKE value based on the PSK. In the present disclosure, the terms "IKE value", "IKEv2 value", "IKEv2 AUTH value", and "AUTH value" have the same meaning and are used interchangeably. Additionally, the DU (150) establishes the F1 interface security with the IAB donor device (200) to support the flexible plug-and-play of the IAB node (100) and the IAB donor (200) by skipping the reweighted EAP authentication processes such as EAP-TLS, EAP-AKA, etc., or using the authentication processes with preconfigured security credentials such as certificates, (static) preconfigured PSKs, etc., for optimizing the authentication at the IAB relay device (100).
[0058] In one embodiment, the DU (150) establishes the F1 interface security with the IAB donor device (200) by sending a first request to the IAB donor device (200). In one embodiment, the first request includes the AUTH value (generated using the PSK) or / and the Globally Unique Temporary Identifier (GUTI). In response to receiving the first request from the IAB relay device (100), the IAB donor device (200) generates the PSK based on the layer security key of the UE generated for the AS security establishment. Additionally, the IAB donor device (200) verifies the received AUTH (as part of the specified IKEv2 process), and if the verification is successful, uses the PSK to generate the IKE value to establish the F1 interface security with the IAB relay device (100). In one embodiment, the IAB donor device (200) uses the PSK as the shared secret / master session key (MSK).
[0059] The IAB donor device (200) establishes the F1 interface security with the IAB relay device (100) by sending a second request to the IAB relay device (100), where the second request includes the AUTH value and other parameters for the IPsec security association (SA) establishment.
[0060] In another embodiment, in response to receiving a first request from the IAB relay device (100), the IAB donor device (200) sends a third request to the AMF (400) for NAS security establishment. In one embodiment, the third request includes a GUTI. The AMF (400) identifies the layer security key derived for NAS security establishment based on the GUTI. In addition, the AMF (400) generates a PSK based on the layer security key for NAS security establishment. In addition, the AMF (400) sends the PSK to the IAB donor device (200). In response to receiving the PSK, the IAB donor device (200) uses the PSK to generate an IKE value to establish the F1 interface security with the IAB relay device (100). The IAB donor device (200) establishes the F1 interface security with the IAB relay device (100) by sending a second request to the IAB relay device (100).
[0061] In another embodiment, the IAB relay device (100) and the IAB donor device (200) generate a dynamic PSK to perform flexible plug-and-play of the IAB relay device (100) and the IAB donor device (200). Parameters including a function code (FC) (e.g., FC = 0x7F), the IP address of the CU function (210), the length of the IP address of the DU function (210), the IP address of the DU function (150) of the IAB relay device (100), and the length of the IP address of the DU function (150) are used to generate the dynamic PSK. In one embodiment, the dynamic PSK generated at the output of the PSK generator (112) is 256-bit data.
[0062] In one embodiment, the MT function (140) provides a layer security key (e.g., K gNB ) to the DU function (150) using an internal / proprietary interface or through a standardized interface. In addition, the DU function (150) generates a PSK based on the layer security key. In one embodiment, the MT function (140) provides RRC-related information (e.g., K gNB , PCI) to the DU function (150) using an internal / proprietary interface to generate a PSK at the DU function (150).
[0063] In one embodiment, the DU function (150) sends a parameter request to the MT function (140) to trigger IPsec authentication / re-authentication. The MT function (140) uses the parameter request to derive a PSK and provides the requested parameters to the DU function (150) using an internal / proprietary interface or through a standardized interface.
[0064] In one embodiment, the IAB donor device (200) and the IAB relay device (100) store K IAB。The IAB donor device (200) uses K IAB as a shared secret to perform the IKEv2 procedure between the IAB donor device (200) and the IAB relay device (100). K IAB and the IPsec security association (SA) encryption key are used to establish an IPsec SA between the IAB donor device (200) and the IAB relay device (100). As long as the IAB relay device (100) is connected to the IAB donor device (200), or until the IAB relay device (100) is re-authenticated, K IAB remains valid. In one embodiment, the CU function (210) uses a security gateway (SEG) to terminate the IPsec tunnel. In this case, the CU function (210) generates a PSK and provides it to the SEG using an internal / proprietary interface or a standardized interface.
[0065] The memory (120) may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard disks, optical disks, floppy disks, flash memory, or in the form of electrically programmable memory (EPROM) or electrically erasable programmable memory (EEPROM).
[0066] In addition, in some examples, the memory (120) may be considered a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not implemented as a carrier wave or a propagated signal. However, the term "non-transitory" should not be construed to mean that the memory (120) is immovable. In some examples, the memory (120) may be configured to store more information than the memory (120). In certain examples, the non-transitory storage medium may store data that changes over time (e.g., in random access memory (RAM) or a cache).
[0067] The processor (130) is configured to execute instructions stored in the memory (120). The communicator (160) is configured to perform internal communication between hardware components in the IAB relay device (100). In addition, the communicator (160) is configured to facilitate communication between the IAB relay device (100) and other devices (i.e., a parent IAB relay device, the IAB donor device (200), at least one user equipment (UE)) in the wireless network (1000).
[0068] Although Figure 3FIG. shows the hardware components of the IAB relay device (100), but it should be understood that other embodiments are not limited thereto. In other embodiments, the IAB relay device (100) may include fewer or more components. Additionally, the labels or names of the components are for illustrative purposes only and do not limit the scope of the present invention. One or more components may be combined together to perform the same or substantially similar authentication functions at the IAB relay device (100).
[0069] Figure 4 FIG. S400 is a flowchart showing a method for generating and using a dynamic PSK for authentication at an IAB relay device (100) according to embodiments disclosed herein. At step S401, the method includes generating a layer security key for one of the AS security establishment and NAS security establishment with an IAB donor device (200) in a wireless network (1000). In one embodiment, the method allows a layer security key generator (111) to generate a layer security key for one of the AS security establishment and NAS security establishment with an IAB donor device (200) in a wireless network (1000). At step S402, the method includes generating a PSK based on the layer security key. In one embodiment, the method allows a PSK generator (112) to generate a PSK based on the layer security key. At step S403, the method includes generating an IKE value using the PSK. In one embodiment, the method allows an IKE value generator (113) to use the PSK (as a shared secret) to generate an IKE value. At step S404, the method includes establishing the F1 interface security with the IAB donor device (200). In one embodiment, the method allows the DU (150) to establish the F1 interface security with the IAB donor device (200).
[0070] The various activities, actions, blocks, steps, etc. in flowchart S400 may be performed in the presented order, a different order, or simultaneously. Additionally, in some embodiments, some activities, actions, blocks, steps, etc. may be omitted, added, modified, skipped, etc. without departing from the scope of the present invention.
[0071] Figure 5It is a sequence diagram showing signaling between components in a wireless network (1000) for establishing F1 interface security by skipping the authentication process using pre-configured security credentials. In step S501, the MT (140) of the IAB relay device (100) attaches to the gNB (300) as a typical UE by performing an RRC connection establishment process. In response to successful completion of the RRC connection establishment process, the MT (140) performs authentication and generates an AS security key together with the gNB (300). In step S502, the MT (140) retrieves the IAB device operation, administration, and maintenance (OAM) configuration from the IAB device operation, administration, and maintenance (OAM) (500). The IAB device OAM configuration includes the transport network layer (TNL) address to the CU (210) and a list of cells supporting IAB device access. In step S503, the MT (140) detaches from the gNB (300) during handover for connection to the CU (210) of the IAB donor device (200).
[0072] In step S504, the MT (140) function creates or establishes an AS security context as part of the handover process without performing an authentication process. In step S505, the MT (140) attaches to the CU (210) using the information in the IAB device OAM configuration and performs AS security establishment. In step S504, there is no authentication process performed by the MT (140) function, but an AS security context is created / established as part of the handover process. In step S506, the MT (140) and the CU (210) use the K obtained in step S504 gNB to derive the PSK (i.e., K IAB ). Additionally, in step S506, the MT (140) provides the PSK to the DU (150). In step S507, the DU (150) performs a transport network layer association (TNLA) establishment with the CU (210). In step S508, the DU (150) uses the PSK (obtained in step S506) specified in the Internet Key Exchange Protocol Version 2 (IKEv2) IETF RFC to generate an IKEv2 AUTH payload and skips the authentication process using pre-configured security credentials such as certificates, etc., for establishing an SA (i.e., an IPsec SA) for the F1 interface.
[0073] Similarly, in step S508, the CU (210) uses the PSK (obtained in step S506) specified in the Internet Key Exchange Protocol Version 2 (IKEv2) IETF RFC to generate an IKEv2 AUTH payload. In one embodiment, when the IAB relay device (100) connects to the IAB donor device (200) immediately after powering on in step S505, since for example a handover process is not possible (i.e., step S504 is not possible), then the MT (140) function initiates an initial registration process, performs authentication with the core network via the IAB donor device (200), establishes an AS security context in step S505, and performs other subsequent steps. In step S506, the MT (140) and CU (210) use the K gNB derived PSK (i.e., K IAB ).
[0074] Figure 6 FIG. is a sequence diagram showing signaling between components in a wireless network (1000) for establishing F1 interface security when the layer security key is an AS security key, according to an embodiment disclosed herein. Consider that the IAB relay device (100) is connected to the AMF (400) via the IAB donor device (200). In phase 1, the MT (140) of the IAB relay device (100) connects to the AMF (400) (i.e., the core network) like a typical UE by performing an RRC connection establishment process with the CU (220) of the IAB donor device (200). Additionally, the MT (140) performs authentication with the AMF (400) (i.e., the core network), context management related to the IAB relay device (100), and configures radio bearers related to access services for the IAB relay device (100) in the RAN.
[0075] Additionally, the MT (140) optionally performs OAM connection establishment. In step S601, when the IAB relay device (100) registers with the AMF (400) in a new radio stand-alone (NR-SA) mode via the IAB donor device (200), the MT (140) and CU (220) derive K gNB as the AS security key for AS security establishment. In one embodiment, the MT (140) and CU (220) use S-K gNB as the AS security key for AS security establishment between the IAB relay device (100) and the IAB donor device (200) in a new radio non-stand-alone (NR-NSA) mode (i.e., evolved universal terrestrial radio access (E-UTRA)-NR dual connectivity (EN-DC)), where the MT (140) generates S-K gNB , and the CU (220) obtains S-K gNB from the base station (300).
[0076] In Phase 2, where Phase 2-1: Backhaul RLC channel establishment, a backhaul RLC channel is established for the CP service in Phase 2. For example, in Phase 2-1, an F1-C message (i.e., a message sent through the F1 interface) is established to and from the IAB relay device (100). Phase 2-2: Routing update, in Phase 2, the backhaul adaptive protocol (BAP) layer is updated to support routing between the IAB relay device (100) and the DU (220) of the IAB donor device (200). Updating the BAP layer includes configuring a BAP routing identifier for downlink routing on the DU (210) of the IAB donor device (200), and a BAP routing identifier for uplink direction on the MT (140) of the IAB relay device (100). In addition, the routing table is updated for all parent IAB relay devices and the DU (220) of the IAB donor device (200) with routing entries of the new BAP routing identifier. In addition, the DU (150) of the intelligent IAB relay device (100) configures an IP address to establish an IP connection to the gNB (300).
[0077] In step S602 of Phase 3, the IAB relay device (100) initiates an IKEv2 process with the CU (201) to establish an IPsec SA. In step S603, the MT 140 uses the AS security key (e.g., K gNB or S-K gNB ) to derive K IAB . In step S604, the MT (140) sends K IAB to the DU (150). In step S605, the DU (150) uses the AUTH value generation mechanism specified in the IKEv2 IETF RFC, and uses K IAB as the MSK / PSK / shared secret to calculate the IKEV2 value. In step S605, the DU (150) sends an IKE-AUTH request including the AUTH value (i.e., the IKEv2 value) to the CU (210). In step S607, in response to receiving the request, the CU (210) uses the AS security key (e.g., K gNB ) to derive K IAB . In step S608, the CU (210) uses the K IAB corresponding to the UE as the MSK / PSK / shared secret to calculate the IKEV2 value, and verifies the AUTH value received from the IAB relay device (100).
[0078] In step S609, the CU (210) sends an IKE-AUTH response including the AUTH value (i.e., the AUTH value calculated by the CU (210) using K gNBThe generated IKEv2 value, specified in the IKEv2 IETF RFC for AUTH value generation) and IKE-AUTH requests for other parameters used in IPsec SA establishment. Thus, the DU (150) initiates the establishment of an F1-C connection (i.e., a link over the F1 interface) with the CU (201) of the IAB donor device (200), and establishes a security context to protect the F1 interface (i.e., the F1-C interface and / or the F1-U interface) by skipping the authentication process (e.g., EAP-TLS, EAP-AKA) or using an authentication process with pre-configured credentials (e.g., certificates, (static) pre-configured PSKs, etc.). In addition, the IAB relay device (100) allows the UE to connect after the F1 interface security is established.
[0079] Figure 7 is a sequence diagram showing the signaling between components in a wireless network (1000) for establishing F1 interface security when the layer security key is the NAS security key, according to an embodiment disclosed herein. Consider that the IAB relay device (100) is connected to the AMF (400) via the IAB donor device (200). In phase 1, by performing an RRC connection establishment process with the CU (220) of the IAB donor device (200), the MT (140) of the IAB relay device (100) is connected to the AMF (400) (i.e., the core network) like a typical UE. In addition, the MT (140) performs authentication with the AMF (400) (i.e., the core network), context management related to the IAB relay device (100), and configures radio bearers related to access services for the IAB relay device (100) in the RAN. In addition, the MT (140) optionally performs OAM connection establishment. In step S601, the MT (140) and the AMF (500) derive K AMF as the NAS security key for NAS security establishment.
[0080] In Phase 2, where Phase 2-1: Backhaul RLC channel establishment, a backhaul RLC channel is established for CP services in Phase 2. For example, in Phase 2-1, an F1-C message (i.e., a message sent through the F1 interface) is established to and from the IAB relay device (100). Phase 2-2: Routing update, in Phase 2-2, the BAP layer is updated to support routing between the IAB relay device (100) and the DU (220) of the IAB donor device (200). Updating the BAP layer includes configuring the BAP routing identifier for routing in the downlink direction on the DU (210) of the IAB donor device (200) and configuring the BAP routing identifier for routing in the uplink direction on the MT (140) of the IAB relay device (100). In addition, the routing table is updated for all parent IAB relay devices and the DU (220) of the IAB donor device (200) with routing entries of the new BAP routing identifier. In addition, the DU (150) of the IAB relay device (100) configures an IP address to establish an IP connection to the base station (300). The IAB relay device (100) and the IAB donor device (200) perform TLNA establishment in Phase 2.
[0081] In step S702 of Phase 3, the IAB relay device (100) initiates an IKEv2 process with the CU (201) to establish an IPsec SA. In step S703, the MT140 uses the NAS security key (e.g., K AMF ) to derive K IAB . In step S704, the MT (140) sends K IAB to the DU (150). In step S705, the DU (150) uses K IAB as the MSK / PSK / shared secret specified in the IKEv2 IETF RFC to calculate the IKEV2 value. In step S706, the DU (150) sends an IKE-AUTH request including the GUTI and AUTH value (i.e., the IKEV2 value) as an optional parameter to the CU (210). In step S707, the CU (210) sends a key request including the GUTI to the AMF (400). In step S708, in response to receiving the request, the AMF (400) uses the NAS security key (e.g., K AMF ) to derive K IAB . In step S708, the AMF (400) sends K IAB to the CU (210) through the N2 interface. In step S710, the CU (210) uses K IAB as the MSK / PSK / shared secret specified in the IKEv2 IETF RFC to calculate the IKEv2 value and verify the AUTH value received from the IAB relay device (100).
[0082] In step S711, the CU (210) sends an IKE-AUTH request to the DU (150) that includes the AUTH value (i.e., the IKEv2 value generated by the CU (210)) and other parameters for IPsec SA establishment. Accordingly, the DU (150) initiates the establishment of an F1-C connection (i.e., a link over the F1 interface) with the CU (201) of the IAB donor device (200), and establishes a security context to protect the F1 interface (i.e., the F1-C interface and / or the F1-U interface) by skipping the authentication process (e.g., EAP-TLS, EAP-AKA), or using an authentication process with at least one pre-configured credential (e.g., a certificate, a (static) pre-configured PSK, etc.). Additionally, the IAB relay device (100) allows the UE to connect after the F1 interface security is established.
[0083] Figure 8 An example scenario for generating a PSK using various parameters according to embodiments disclosed herein is shown. In one example, K SN / K gNB , a parameter discriminator (e.g., 0x00 or 0x07 or 0xEF or other possible values), and a parameter identifier (e.g., 0100 or 1111 or other possible values, as shown by symbol (a) of Figure 8 ) are used to generate the PSK (i.e., K IAB ). In another example, the PSK (i.e., K IAB ) is generated using K SN / K gNB and at least one of the following: the IAB count, the PCI, the ARFCN-DL, the gNB identifier of the IAB donor device (200), the address of the CU (210) of the IAB donor device (200), the address of the DU (150) of the IAB relay device (100), the identifier of the IAB relay device (100), and other possible parameters (e.g., the length of the parameter), as shown by symbol (b) of Figure 8 .
[0084] In another example, as shown by symbol (c) of Figure 8 , the PSK (i.e., K IAB ) is generated using K AMF , an access type discriminator, and an uplink NAS count. In another example, as shown by symbol (d) of Figure 8 , the PSK (i.e., K IAB ) is generated using the key for user plane integrity (K UPint ). In another example, as shown by symbol (e) of Figure 8 , the PSK (i.e., K IAB ) is generated using the key for user plane encryption (K UPenc ).
[0085] The embodiments disclosed herein can be implemented using at least one software program that runs on at least one hardware device and performs network management functions to control components.
[0086] The foregoing description of specific embodiments will so fully disclose the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and / or adapt various applications of such specific embodiments without departing from the general concept, and, therefore, such adaptations and modifications should and are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Accordingly, although the embodiments herein have been described in terms of preferred embodiments, those skilled in the art will recognize that the embodiments herein can be practiced with modification within the scope of the embodiments described herein.
Claims
1. A method performed by an integrated access and backhaul IAB relay device (100) in a wireless network (1000), comprising: generating, by the IAB relay device (100), a layer security key for access stratum AS security establishment with an IAB donor device (200); generating, by the IAB relay device (100), a pre-shared key PSK based on the layer security key; and establishing, by the IAB relay device (100), F1 interface security with the IAB donor device using the PSK based on Internet Key Exchange IKE.
2. The method according to claim 1, wherein The PSK is generated based on at least one of an address of a control unit CU of the IAB donor device, an address of a distribution unit DU of the IAB relay device, a length of the address of the CU of the IAB donor device, or a length of the address of the DU of the IAB relay device.
3. The method according to claim 1, wherein The PSK is 256 bits.
4. The method according to claim 1, wherein, It further includes storing the PSK.
5. The method according to claim 1, wherein, The PSK remains valid as long as the IAB relay device is connected to the IAB donor device or until the IAB relay device is re-authenticated.
6. The method according to claim 1, wherein The layer security key for AS security establishment is K gNB or S-K gNB .
7. An integrated access and backhaul IAB relay device (100) for authentication, comprising: a memory (120); a processor (130) coupled to the memory (120); and an authentication controller (110), coupled to the processor, configured to: generate a layer security key for access stratum AS security establishment with an IAB donor device (200); generate a pre-shared key PSK based on the layer security key; and establish F1 interface security with the IAB donor device using the PSK based on Internet Key Exchange IKE.
8. The IAB relay device (100) according to claim 7, wherein, The PSK is generated based on at least one of an address of a control unit CU of the IAB donor device, an address of a distribution unit DU of the IAB relay device, a length of the address of the CU of the IAB donor device, or a length of the address of the DU of the IAB relay device.
9. The IAB relay device (100) according to claim 7, wherein, The PSK is 256-bit data.
10. The IAB relay device (100) according to claim 7, wherein, The controller is further configured to store the PSK.
11. The IAB relay device (100) according to claim 7, wherein, The PSK remains valid as long as the IAB relay device is connected to the IAB donor device or until the IAB relay device is re-authenticated.
12. The IAB relay device (100) according to claim 7, wherein, The layer security key for AS security establishment is K gNB or S-K gNB .