Method for providing security for multiple NAS connections using separate counts and related network nodes and wireless terminals
By providing a unique identification and serial number for each NAS connection, the problem of orderly delivery of NAS messages under multiple access connections in 5G systems is solved, and the efficiency, secure delivery and flexibility of NAS messages are achieved.
Patent Information
- Application Number
- CN202210948654.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2017-05-08
- Filing Date
- 2018-05-07
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2038-05-07
AI Technical Summary
In 5G systems, orderly delivery of NAS messages may be unreliable in multiple connections accessed via 3GPP and non-3GPP, resulting in traditional security mechanisms that cannot effectively protect the integrity, confidentiality and playback protection of messages.
By providing a unique NAS connection identity for each NAS connection, integrity authentication and encryption keys for NAS messages are generated and different serial number parts are assigned in the NAS counting domain to ensure that the message delivery for each NAS connection has unique authentication and encryption separation.
It realizes the orderly delivery and security of NAS messages in multiple parallel NAS connection scenarios, ensures security services and protection at the same level as traditional systems, and supports parallel execution and flexibility of different access types.
Smart Images

Figure CN115567922B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates generally to the field of communications, and more particularly, to wireless communications and related network nodes and wireless terminals. Background Art
[0002] In a 5G system, a UE can simultaneously register to the same PLMN via 3GPP access (e.g., using an LTE or 5G access node, also referred to as a base station, eNB, gNB, etc.) and non-3GPP access (e.g., using WiFi or satellite nodes). For this purpose, the wireless terminal UE and the network AMF (Access Management Function) are expected to maintain one connection for each access type (i.e., one connection for 3GPP access and one connection for non-3GPP NAS connection). In this case, TS 23.501 (referred to as reference [1]) further describes which elements of the user context in the AMF will be shared between connections and which will not be shared. For example, there can be multiple connection management (CM) and registration management states, one for each access type. On the other hand, a common temporary identifier can be used.
[0003] As described in TS 33.401 [2], the security mechanisms in the legacy system can provide integrity, confidentiality and replay protection for NAS messages. The NAS security context consists of the KASME key, the derived protection keys KNASint and KNASenc, the key set identifier eKSI and a pair of counters NAS COUNT (one for each direction (uplink and downlink)). These security parameters can be provisioned for a NAS connection and can be refreshed when a new KASME is created (e.g. after the authentication process).
[0004] Furthermore, the replay protection mechanism partially implemented by the NAS COUNT may rely on the assumption that the protocol is reliable and that NAS procedures are run in sequence such that a new procedure is started only after the current procedure is terminated. This may provide / guarantee in-order delivery of NAS messages such that both the UE and the MME need only store two values of the NAS COUNT, one for each direction (i.e., one NAS COUNT for uplink and one NAS COUNT for downlink). These will be the next and only expected / accepted values.
[0005] However, for multiple connections via 3GPP and non-3GPP accesses, in-order delivery of NAS messages via different connections may be unreliable. Summary of the invention
[0006] According to some embodiments of the inventive concept, a method at a first communication node may provide communication of a network access stratum (NAS) message with a second communication node. A first NAS connection identifier may be provided for a first NAS connection between the first and second communication nodes, and a second NAS connection identifier may be provided for a second NAS connection between the first and second communication nodes. Moreover, the first and second NAS connection identifiers may be different, and the first and second NAS connections may be different. A first NAS message may be transmitted between the first and second communication nodes over a first NAS connection, and transmitting the first NAS message may include performing at least one of generating a message authentication code for integrity authentication of the first NAS message using the first NAS connection identifier and / or encrypting / decrypting the first NAS message using the first NAS connection identifier. A second NAS message may be transmitted between the first and second communication nodes over a second NAS connection, and transmitting the second NAS message may include performing at least one of generating a message authentication code for integrity authentication of the second NAS message using the second NAS connection identifier and / or encrypting / decrypting the second NAS message using the second NAS connection identifier.
[0007] According to some other embodiments of the inventive concept, a method at a first communication node may provide for communication of a network access stratum (NAS) message with a second communication node. A first NAS connection may be provided between the first and second communication nodes, and a second NAS connection may be provided between the first and second communication nodes. Moreover, the first and second NAS connections may be different. A NAS count field may be allocated such that a first portion of the NAS count field is allocated for NAS messages delivered through the first NAS connection, and such that a second portion of the NAS count field is allocated for NAS messages delivered through the second NAS connection. Moreover, the first and second portions of the NAS count field may be mutually exclusive. The NAS message may be delivered through the first NAS connection using the lowest NAS count value from the first portion of the NAS count field for each NAS message that has not been previously used for delivery through the first NAS connection. The NAS message may be delivered through the second NAS connection using the lowest NAS count value from the second portion of the NAS count field for each NAS message that has not been previously used for delivery through the second NAS connection.
[0008] According to some embodiments of the inventive concepts disclosed herein, management of parallel NAS connections may be improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] The accompanying drawings, which are included to provide a further understanding of the present disclosure and are incorporated in and constitute a part of this application, illustrate certain non-limiting embodiments of the inventive concept. In the drawings:
[0010] Figure 1is a diagram illustrating an example of message organization of a security-protected NAS message;
[0011] Figure 2 It is a graphic Figure 1 A table of security header types for security-protected NAS messages;
[0012] Figure 3A and 3B The diagram illustrates the use of the 128-bit integrity EIA process to authenticate the integrity of a message;
[0013] 4A and 4B illustrate data of a message encrypted using a 128-bit encryption EEA process;
[0014] Figure 5 is a block diagram illustrating multiple NAS connections between a core network node and a wireless terminal according to some embodiments of the inventive concept;
[0015] Figure 6 is a block diagram illustrating elements of a wireless terminal UE according to some embodiments of the inventive concept;
[0016] Figure 7 is a block diagram illustrating elements of a network node according to some embodiments of the inventive concept;
[0017] Figure 8 and 9 are diagrams respectively illustrating some embodiments according to the inventive concept Figure 5 and Figure 7 at the network nodes and at Figure 5 and Figure 6 A block diagram of a NAS security function at a wireless terminal;
[0018] Fig. 10A , 10B , 12A and 12B illustrate the use of integrity procedures to authenticate the integrity of NAS messages according to some embodiments of the inventive concept;
[0019] 11A, 11B, 13A and 13B illustrate the use of an encryption / decryption process to encrypt / decrypt data of a NAS message according to some embodiments of the inventive concept;
[0020] Fig.14 illustrates a process type distinguisher that may be used according to some embodiments of the inventive concept;
[0021] Fig.15 and 16 illustrates key derivation that may be used according to some embodiments of the inventive concept;
[0022] Fig.17A and 18Ais a flow chart illustrating the operation of delivering NAS messages over multiple NAS connections according to some embodiments of the inventive concept; and
[0023] Fig. 17B and 18B are diagrams of some embodiments according to the inventive concept, respectively corresponding to Fig.17A and 18A A block diagram of the operation of the memory module. DETAILED DESCRIPTION
[0024] The inventive concept will now be described more fully below with reference to the accompanying drawings, in which examples of embodiments of the inventive concept are shown. However, the inventive concept can be implemented in many different forms and should not be construed as being limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be exhaustive and complete, and these embodiments will fully convey the scope of the inventive concept to those skilled in the art. It should also be noted that these embodiments are not mutually exclusive. A component from one embodiment may be tacitly assumed to be present in / used in another embodiment.
[0025] The following description presents various embodiments of the disclosed subject matter. These embodiments are presented as teaching examples and are not constructed to limit the scope of the disclosed subject matter. For example, some details of the described embodiments may be modified, omitted or expanded without departing from the scope of the described subject matter.
[0026] Figure 5 is a block diagram illustrating multiple NAS connections between a core network node 501 (providing access management) and a wireless terminal UE 505 according to some embodiments of the inventive concept. As shown, a first NAS connection may be provided by a 3GPP access node (e.g., a base station, eNB, eNodeB, gNB, gNodeB), a second NAS connection may be provided by a first non-3GPP access node (e.g., a WiFi access node), and a third NAS connection may be provided by a second non-3GPP access node (e.g., a satellite node). In the case of different NAS connections provided by different access nodes of different technologies, the likelihood that a receiving node (be it a wireless terminal 505 in a downlink or a core network node 501 in an uplink) receives all NAS messages in sequence may be reduced.
[0027] Figure 65 is a block diagram illustrating elements of a wireless terminal UE 505 (also referred to as a wireless device, wireless communication device, wireless communication terminal, user equipment, user equipment node / terminal / device, etc.) configured to provide wireless communication according to an embodiment of the inventive concept. As shown, the wireless terminal UE may include a transceiver circuit 601 (also referred to as a transceiver), the transceiver circuit 601 including a transmitter and a receiver configured to provide uplink and downlink radio communications with (one or more) base stations of a radio access network. The wireless terminal UE may also include a processor circuit 603 (also referred to as a processor) coupled to the transceiver circuit and a memory circuit 605 (also referred to as a memory) coupled to the processor circuit. The memory circuit 605 may include a computer-readable program code, which, when executed by the processor circuit 603, causes the processor circuit to perform operations according to the embodiments disclosed herein. According to other embodiments, the processor circuit 603 may be defined as including a memory, so that a separate memory circuit is not required. The wireless terminal UE may also include an interface 607 (such as a user interface) coupled to the processor 603, and / or the wireless terminal UE may be incorporated into a vehicle. User interface 607 may include, for example, a display (eg, touch screen) that provides visual output, a speaker that provides audio output, and / or a user input device (eg, touch screen, keypad, button(s), etc.) that accepts user input.
[0028] As discussed herein, the operations of the wireless terminal UE 505 may be performed by the processor 603 and / or the transceiver 601. For example, the processor 603 may control the transceiver 601 to transmit communications to an access node via the transceiver 601 over a radio interface and / or to receive communications from an access node via the transceiver 601 over a radio interface. Moreover, modules may be stored in the memory 605, and these modules may provide instructions such that when the instructions of the modules are executed by the processor 603, the processor 603 performs corresponding operations (e.g., operations discussed below with respect to example embodiments).
[0029] Figure 7 1 is a block diagram illustrating elements of a network node (also referred to as a core network node, base station, eNB, eNodeB, gNB, gNodeB, etc.) of a radio access network (RAN) configured to support wireless communication according to an embodiment of the inventive concept. As shown, the network node may include a network interface circuit 501 (also referred to as a network interface), the network interface circuit 501 including a network interface configured to communicate with the network node, for example, via a communication interface such as Figure 5The access node shown in provides a transmitter and receiver for uplink and downlink radio communications with wireless terminals. The network node may also include a processor circuit 703 (also referred to as a processor) coupled to the network interface circuit and a memory circuit 705 (also referred to as a memory) coupled to the processor circuit. The memory circuit 705 may include a computer-readable program code that, when executed by the processor circuit 703, causes the processor circuit to perform operations according to the embodiments disclosed herein. According to other embodiments, the processor circuit 703 may be defined to include a memory so that a separate memory circuit is not required.
[0030] As discussed herein, the operations of the network node 501 may be performed by the processor 703 and / or the network interface 701. For example, the processor 703 may control the network interface 701 to transmit communications to one or more access nodes via the network interface 701 and / or to receive communications from one or more access nodes via the network interface, as described herein. Figure 5 Moreover, modules may be stored in the memory 705, and these modules may provide instructions so that when the instructions of the modules are executed by the processor 703, the processor 703 performs corresponding operations (e.g., the operations discussed below with respect to the example embodiments). Figure 5 and Figure 7 501, but the operations of the 3GPP access node 503-1 and the network node 501 may be combined by providing a transceiver in the network node 501. In such an embodiment, the transceiver of the network node 501 may provide a 3GPP NAS connection via a direct 3GPP interface with the wireless terminal 505. According to such an embodiment, the processor 703 may control the transceiver to transmit communications to the wireless terminal 505 through the transceiver and / or receive communications from the wireless terminal 505 through the transceiver over the radio interface.
[0031] The general message format and information element encoding for NAS messages in the EPC will now be discussed.
[0032] For the legacy EPC / LTE system, TS 24.301 (also referred to as reference [3]) describes a general message format and information element encoding for NAS messages. If the NAS message is a security-protected NAS message, the message includes the following parts:
[0033] a) protocol discriminator;
[0034] b) security header type;
[0035] c) Message Authentication Code (MAC);
[0036] d) serial number; and
[0037] e) Plaintext NAS message.
[0038] exist Figure 1 The organization of a security-protected NAS message is illustrated in the example shown in FIG. Figure 1 The diagram illustrates the message organization of a security-protected NAS message.
[0039] The first octet of each EPS Mobility Management (EMM) message contains the Security Header Type IE in bits 5 to 8. This IE contains control information related to the security protection of NAS messages. The total size of the Security Header Type IE is 4 bits. The Security Header Type IE can take the form Figure 2 The values shown in the table are Figure 2 Pictured Figure 1 The security header type for secure NAS messages.
[0040] Figure 1 The Message Authentication Code (MAC) information element in the NAS message includes / contains the integrity protection information of the message. If there is a valid EPS security context and the security function is enabled, the MAC IE is included in the security-protected NAS message.
[0041] Figure 1 The Sequence Number IE in includes the NAS message sequence number (SN), which consists of the eight least significant bits of the NAS COUNT of the security-protected NAS message.
[0042] When a NAS message is to be sent both encrypted and integrity protected, the NAS message is first encrypted, and then the encrypted NAS message and the NAS sequence number (NAS COUNT) are integrity protected by calculating a MAC.
[0043] When a NAS message is to be sent integrity-protected only and not encrypted, the unencrypted NAS message and the NAS sequence number are integrity protected by calculating a MAC.
[0044] TS 33.401 (also referred to as reference [2]) and TS 24.301 (also referred to as reference [3]) describe that each individual KASME has a unique pair of NAS COUNTs associated with it, one NAS COUNT for the uplink and one NAS COUNT for the downlink.
[0045] The NAS COUNTs for a specific KASME are not reset to their starting values (that is, NAS COUNTs have their starting values only when a new KASME is created). This reduces / prevents security issues of using the same NAS COUNT with the same NAS key, e.g., keystream reuse.
[0046] TS 24.301 (also referred to as reference [3]) describes that a sender uses its locally stored NAS COUNT as input to an integrity protection / authentication procedure (also referred to as an integrity protection / authentication algorithm) for providing integrity and authentication. The receiver uses the NAS sequence number included in the received message (or estimated from the 5 bits of the NAS sequence number received in the message) and an estimate of the NAS overflow counter to form the NAS COUNT input to the integrity authentication procedure.
[0047] The integrity protection comprises octets 6 to n of the secured NAS message, namely the Sequence Number IE and the NAS Message IE.After a successful integrity protection validation, the receiver updates its corresponding locally stored NAS COUNT with the estimated NAS COUNT value for this NAS message.
[0048] Replay protection SHOULD / MUST ensure that the same NAS message is not accepted twice by a receiver. Specifically, for a given EPS security context, a given NAS COUNT value SHOULD be accepted at most once, and only if the message integrity has been verified correctly.
[0049] A 128-bit integrity procedure can be used in EPC / LTE. According to TS 33.401 (also referred to as reference [2]), the input parameters to the 128-bit integrity procedure are a 128-bit integrity key called KEY, a 32-bit COUNT (i.e., NAS COUNT), a 5-bit bearer identifier called BEARER, a 1-bit transmission direction (i.e., DIRECTION), and the message itself (i.e., MESSAGE). The DIRECTION bit can / should be 0 for the uplink and 1 for the downlink. The bit length of MESSAGE is LENGTH. Figure 3A and 3B The diagram shows the use of the 128-bit integrity process EIA to authenticate the integrity of the message. Figure 3A As shown in , the sender can derive MAC-I / NAS-MAC and Figure 3B As shown in , the receiver can derive XMAC-I / XNAS-MAC.
[0050] Based on these input parameters, the transmitter uses Figure 3AThe integrity process EIA (also called the integrity algorithm EIA) is used to calculate the 32-bit message authentication code (MAC-I / NAS-MAC). Figure 1 As shown in , a message authentication code (MAC) is then appended to the message when it is sent. The receiver computes the message authentication code for the message in the same way as the sender (using Figure 3B The integrity process (also known as the integrity algorithm EIA) calculates the expected message authentication code (XMAC-1 / XNAS-MAC) for the received message and verifies the data integrity of the message by comparing the calculated MAC with the received message authentication code (i.e. MAC-I / NAS-MAC).
[0051] TS 24.301 (also referred to as reference [3]) describes that the sender uses its locally stored NAS COUNT as input to the encryption algorithm. The receiver uses the NAS sequence number included in the received message (or estimated from the 5 bits of the NAS sequence number received in the message) and an estimate of the NAS overflow counter to form the NAS COUNT input to the decryption algorithm.
[0052] A 128-bit encryption algorithm may be used. According to TS 33.401 (also referred to as reference [2]), the input parameters to the encryption process (also referred to as the encryption algorithm) are a 128-bit encryption key named KEY, a 32-bit COUNT (i.e., NAS COUNT), a 5-bit bearer identifier BRARER, a 1-bit transmission direction (i.e., DIRECTION), and the required length of the key stream (i.e., LENGTH). The DIRECTION bit should be 0 for the uplink and 1 for the downlink.
[0053] Figures 4A and 4B illustrate the encryption of data.Based on the input parameters, the EEA process generates an output keystream block KEYSTREAM for encrypting the input plaintext block PLAINTEXT to produce an output ciphertext block CIPHERTEXT.
[0054] Support for multiple NAS connections terminating in the same AMF may raise new issues including future-proofing, concurrency, agnosticism and / or flexibility.
[0055] Regarding future-proofing, the classification of accesses by type into 3GPP and non-3GPP is actually future-proof and can be applied to any new future access technology. Although it may seem that there is no need to support more than two NAS connections, it cannot be ruled out with certainty that there will not be any future features or enhancements that require supporting more than two simultaneous NAS connections, one NAS connection over 3GPP and two NAS connections over non-3GPP accesses (e.g. Wifi and satellite). For this reason, it may be better that the new security mechanism is not limited to two connections, and that it effectively supports any (up to a certain limit) number of simultaneous connections.
[0056] Regarding concurrency, the introduction of multiple NAS connections may cause concurrency issues, because now the system can potentially run multiple NAS procedures in parallel on different NAS legs. It is conceivable that the AMF is forced to execute one NAS procedure at a time regardless of the NAS connection, so that the basic assumptions of the traditional security mechanism are preserved. This would not be expected. For example, a NAS process that fails on one NAS connection may suspend all ongoing operations on another NAS connection, for example, until the failure timer expires. This may be an undesirable design choice. Therefore, it may be better if the new security mechanism supports the execution of NAS procedures in parallel on different connections.
[0057] Regarding agnosticism, it is expected that the new security mechanism will provide the same security services regardless of the access type. Security services may include integrity, confidentiality, and replay protection. According to the general design principle of the access-agnostic 5G architecture, security services should be provided in a transparent manner to the access type.
[0058] Regarding flexibility, the new feature of multiple NAS connections may lead to new scenarios that are not possible in legacy systems. For example, one NAS connection over one access type may be active all the time, while another NAS connection over a different access type flickers (a term of abuse). More precisely, a UE may be registered on one NAS leg while oscillating between two registration states on another leg. Not to mention, a UE may perform several handovers involving AMF changes simultaneously. Therefore, the new security mechanism may be expected to be flexible enough to support such mobility scenarios.
[0059] According to some embodiments of the inventive concept, a method for securing parallel NAS connections may be provided. Such a method may be based on a partially shared security context so that a master key (KASME equivalent in 5G) is shared for different NAS connections with the same wireless terminal, and for each NAS connection with the same wireless terminal, there is a dedicated separate pair of NASCOUNTs, based on the use of a NAS parameter called NAS CONN ID (NAS connection identification) to identify each NAS connection with the same wireless terminal.
[0060] According to some embodiments, the disclosed method / apparatus may address issues related to future-proofing, concurrency, unknowability, and flexibility while providing similar / same levels of security services and protection regarding NAS connections as in conventional systems.
[0061] The following assumptions can be made regarding multiple NAS connections.
[0062] First, there may be an AMF-specific key denoted by KAMF, which is the equivalent of KASME in the 5G system. This key is established via successful authentication and is used to derive NAS protocol protection keys, namely KNASint and KNASenc.
[0063] Second, the system may provide / guarantee in-order delivery of NAS messages on each leg (connection). More specifically, the basic NAS transport assumptions from the legacy system for each NAS connection may still apply, but this does not preclude the execution of NAS procedures in parallel on different connections.
[0064] Third, the choice of encryption procedure (also called encryption algorithm) can be applied indiscriminately to all NAS connections. In other words, it can be assumed that there is no NAS connection specific security negotiation. It is expected that the negotiation will take place once during the establishment and activation of the AMF keys, such as the equivalent of the NAS SMC procedure in 5G. The NAS SMC (Security Mode Command) procedure is described in detail in TS 33.401 (also referred to as reference [2]).
[0065] It can also be assumed that NAS security is an additional function of NAS that provides security services to NAS protocol management entities, as Figure 8 and 9 Although this can be left to the implementation, the Figure 8 and 9 For the reception of uplink NAS messages and the transmission of downlink NAS messages, Figure 8The operations of the NAS protocol entities (including NAS security functions and NAS connection management functions) of the network node 501 may be performed by the processor 703 of the network node 501. For the reception of downlink NAS messages and the transmission of uplink NAS messages, Fig. 9 The operation of the NAS protocol entities (including NAS security functions and NAS connection management functions) can be performed by Figure 6 The processor 603 of the wireless terminal 505 is executed.
[0066] For example, NAS security services may be provided by an independent security function that interacts with other NAS protocol entities or functions. For example, a NAS connection management function may forward a protected message received on the uplink to a security function that performs checking and encryption operations and returns a result (e.g., whether the integrity check failed or passed, and / or whether the message was decrypted, etc.). When a message is to be protected on the downlink, the NAS connection management function provides the payload to the security function, which performs the necessary operations and returns the protected message.
[0067] Figure 8 and 9 The NAS security functions at the core network node and at the wireless terminal are illustrated respectively.
[0068] For 5G, it is expected that the NAS security context may include the AMF key KAMF, the derived protection keys KNASint and KNASenc, and the key set identifier eKSI equivalent in 5G. According to some embodiments of the present disclosure, in this NAS security context, a separate pair of NAS COUNTs may be used for each NAS connection with a wireless terminal.
[0069] As discussed above, for each NAS connection, a separate pair of NAS COUNTs may be used / maintained, one for each direction. Since security keys are shared, and in order to reduce / avoid key stream reuse, a method for cryptographic separation may be used / required. For this purpose, a NAS connection-specific parameter may be introduced, and the NAS connection-specific parameter may be referred to as a NAS connection identifier and is identified by a NAS CONN ID.
[0070] NAS CONN ID is a number that increments whenever a new NAS connection is established for a wireless terminal. In a security context, each NAS COUNT pair is associated with a unique NAS CONN ID value. When interacting with NAS security functions, the new parameter is used as a differentiator to indicate which NAS connection each message belongs to. In order to track unassigned NASCONN ID values, additional parameters may be used / needed. This new parameter, indicated by NEXT NAS CONN ID, may also be part of the security context. The NEXT NAS CONN ID parameter is initially set to 0 and increments whenever a new NAS connection is established for a wireless terminal. Whenever a new NAS connection is created for a wireless terminal, the current NEXT NAS CONN ID value is assigned as an identifier. More specifically, a new NAS COUNT pair is created and associated with the NASCONN ID, and the value of the NAS CONN ID is set to the current NEXT NAS CONN ID value. The NEXT NAS CONNID value is then incremented. The NAS connection identifier NAS CONN ID can thereby be used (directly or indirectly) as input for authentication and / or encryption / decryption processes.
[0071] According to some embodiments of the inventive concept, when a new NAS COUNT pair is created, the value of the counter is set to 0. The NAS CONN ID may be an 8-bit value that is used to pad the NAS COUNT 24-bit internal representation when constructing the input to the NAS encryption / decryption and / or integrity process. In conventional systems, the padding may always be set to 0, as described in TS 24.301 (also referred to as reference [3]). Since each NAS connection is identified by a unique NAS CONN ID, the padding provides / ensures cryptographic separation for messages traveling over different NAS connections.
[0072] Fig. 10A and 10B The diagram illustrates the use of the integrity procedure EIA (also referred to as the integrity algorithm EIA) to authenticate the integrity of the message using the NAS CONN ID on the sender side and the receiver side. By incorporating the NAS connection identifier NASCONN ID in the COUNT input, separation can be provided for the authentication of different NAS connections for the same wireless terminal. For example, the COUNT input can be a 32-bit value generated as a concatenation of an 8-bit NAS CONN ID for the NAS connection and a 24-bit NAS COUNT for the NAS connection (i.e., COUNT (32 bits) = NAS CONN ID (8 bits) || NAS COUNT (24 bits)). Thus, Fig. 10A The diagram shows the use of NAS CONN ID to derive MAC-I / NAS-MAC on the transmitter side, and Fig. 10B Illustrated using NAS CONN ID to derive XMAC-I / XNAS-MAC on the receiver side.
[0073] 11A and 11B illustrate the use of encryption / decryption algorithm EEA to encrypt / decrypt messages using NASCONN ID on the sender side and receiver side. By incorporating the NAS connection identifier NAS CONN ID in the COUNT input, separation can be provided for encrypting / decrypting different NAS connections for the same wireless terminal. For example, the COUNT input can be a 32-bit value generated as a concatenation of an 8-bit NAS CONN ID for the NAS connection and a 24-bit NAS COUNT for the NAS connection (i.e., COUNT (32 bits) = NAS CONN ID (8 bits) || NAS COUNT (24 bits)). Thus, FIG. 11A illustrates the use of NASCONN ID to encrypt plain text on the transmitter side, and Fig. 11B The diagram illustrates decryption of the ciphertext on the receiver side using the NAS CONN ID.
[0074] According to some other embodiments, as discussed below, the NAS CONN ID may be a 5-bit value that is used as a BEARER input for authentication and / or encryption / decryption processes.
[0075] Figures 12A and 12B illustrate the use of the integrity algorithm EIA to authenticate the integrity of the message using the NAS CONN ID on the sender side and the receiver side. By using the NAS CONN ID as the BEARER input, separation can be provided for the authentication of different NAS connections for the same wireless terminal. Thus, Figure 12A illustrates the use of the NAS CONN ID as the BEARER input to derive the MAC-I / NAS-MAC on the transmitter side, and Fig. 12B Illustrated to derive XMAC-I / XNAS-MAC on the receiver side using NAS CONN ID as BEARER input.
[0076] Figures 13A and 13B illustrate the use of encryption / decryption process EEA to encrypt / decrypt messages using NASCONN ID on the sender side and the receiver side. By using the NAS connection identity NAS CONN ID as the BEARER input, separation can be provided for encryption / decryption of different NAS connections for the same wireless terminal. Thus, Figure 13A illustrates the use of NASCONN ID as the BEARER input to encrypt plain text on the transmitter side, and Fig. 13BIllustrate decryption of ciphertext on the receiver side using NAS CONN ID as BEARER input.
[0077] Now it will target Fig.17A Flowchart and Fig. 17B Discussion Fig. 10A -B, 11A-B, 12A-B and / or 13A-B integrity authentication and / or encryption / decryption operations.
[0078] Now refer to Fig.17A Flowchart and Fig. 17B The modules discuss the operation of communication nodes. For example, Fig. 17B The module may be stored in a memory of the communication node (for example, if the communication node is a wireless terminal, it is stored in Figure 6 or if the communication node is a network node, then stored in the wireless terminal memory 605. Figure 7 The modules may be in the network node memory 705 of the communication node), and these modules may provide instructions so that when the instructions of the modules are executed by the communication node processor (for example, if the communication node is a wireless terminal, the wireless terminal processor 603, or if the communication node is a network node, the network node processor 705), the processor executes Fig.17A The corresponding operations of the flowchart.
[0079] As above for Figure 5 As discussed, the first and second NAS connections may be provided between the first and second communication nodes, such as between the wireless terminal 505 and the network node 501 (e.g., a core network node). At block 1711, the communication node processor may provide a first NAS connection identifier for the first NAS connection between the first and second communication nodes (e.g., using the first identification module 1751). At block 1713, the communication node processor may also provide a second NAS connection identifier for the second NAS connection between the first and second communication nodes (e.g., using the second identification module 1753). Moreover, the first and second NAS connection identifiers are different, and the first and second NAS connections are different.
[0080] At block 1717, for communication over the first NAS connection, the communication node processor may communicate a first NAS message between the first and second communication nodes over the first NAS connection (e.g., using the first communication module 1757). More particularly, communicating the first NAS message may include at least one of performing integrity protection on the first NAS message using the first NAS connection identifier and / or performing confidentiality protection on the first NAS message using the first NAS connection identifier.
[0081] At block 1719, for communication over the second NAS connection, the communication node processor may communicate a second NAS message between the first and second communication nodes over the second NAS connection (e.g., using the second communication module 1759). More particularly, communicating the second NAS message may include at least one of performing integrity protection on the second NAS message using the second NAS connection identifier and / or performing confidentiality protection on the second NAS message using the second NAS connection identifier.
[0082] The first and second NAS connections share a master key of the NAS security context. Furthermore, delivering the first NAS message may include at least one of performing integrity protection on the first NAS message using the first NAS connection identifier and the master key and / or performing confidentiality protection on the first NAS message using the first NAS connection identifier and the master key. Similarly, delivering the second NAS message may include at least one of performing integrity protection on the second NAS message using the second NAS connection identifier and the master key and / or performing confidentiality protection on the second NAS message using the second NAS connection identifier and the master key.
[0083] Fig.17A The operation may be performed by a communication node that is transmitting the NAS message (e.g., the wireless terminal 505 in the uplink, or the network node 501 in the downlink). As discussed above, the first and second NAS connections may share a master key for the NAS security context. In box 1717, delivering the first NAS message may include performing integrity protection by generating a first message authentication code based on the first NAS connection identifier, the master key, and the first NAS message, and transmitting the first NAS message together with the first message authentication code to the second communication node through the first NAS connection. In box 1719, delivering the second NAS message may include performing integrity protection on the second NAS message by generating a second message authentication code based on the second NAS connection identifier, the master key, and the second NAS message, and transmitting the second NAS message together with the second message authentication code to the second communication node through the second NAS connection.
[0084] According to some embodiments of the transmitting node, the first NAS connection identifier may be concatenated with a first NAS count for a first NAS message, the concatenation of the first NAS connection identifier and the first NAS count may be provided as an input to generate a first message authentication code, the second NAS connection identifier may be concatenated with a second NAS count for a second NAS message, and the concatenation of the second NAS connection identifier and the second NAS count may be provided as an input to generate a second message authentication code. According to some other embodiments of the transmitting node, the first NAS connection identifier may be provided as an input to generate the first message authentication code, and the second NAS connection identifier may be provided as an input to generate the second message authentication code. According to some other embodiments of the transmitting node, the master key and the first NAS connection identifier may be used to derive a first integrity protection key for generating the first message authentication code, and the master key and the second NAS connection identifier may be used to derive a second integrity protection key for generating the second message authentication code. Moreover, performing integrity protection on the first NAS message may include performing integrity protection on the first NAS message using a 5G-compatible EIA integrity protection interface, and performing integrity protection on the second NAS message may include performing integrity protection on the second NAS message using a 5G-compatible EIA integrity protection interface.
[0085] Fig.17A The operation may be performed by a communication node that is transmitting the NAS message (e.g., the wireless terminal 505 in the uplink, or the network node 501 in the downlink). As discussed above, the first and second NAS connections may share a master key for a NAS security context. At block 1717, delivering the first NAS message may include performing confidentiality protection on the first NAS message by encrypting the first NAS message using the first NAS connection identifier and the master key to provide a first encrypted NAS message, and transmitting the first encrypted NAS message to the second communication node over the first NAS connection. At block 1719, delivering the second NAS message may include performing confidentiality protection on the second NAS message by encrypting the second NAS message using the second NAS connection identifier and the master key to provide a second encrypted NAS message, and transmitting the second encrypted NAS message to the second communication node over the second NAS connection.
[0086] According to some embodiments of the transmitting node, the first NAS connection identifier may be concatenated with a first NAS count for a first NAS message, the concatenation of the first NAS connection identifier and the first NAS count may be provided as an input to generating a first encrypted NAS message, the second NAS connection identifier may be concatenated with a second NAS count for a second NAS message, and the concatenation of the second NAS connection identifier and the second NAS count may be provided as an input to generating a second encrypted NAS message. According to some other embodiments of the transmitting node, the first NAS connection identifier may be provided as an input to generating the first encrypted NAS message, and the second NAS connection identifier may be provided as an input to generating the second encrypted NAS message. According to still other embodiments of the transmitting node, the master key and the first NAS connection identifier may be used to derive a first encryption key for generating the first encrypted NAS message, and the master key and the second NAS connection identifier may be used to derive a second encryption key for generating the second encrypted NAS message. Encrypting the first NAS message may include encrypting the first NAS message using EEA encryption, and encrypting the second NAS message includes encrypting the second NAS message using EEA encryption. Moreover, performing confidentiality protection on the first NAS message may include performing confidentiality protection on the first NAS message using a 5G-compatible EEA encryption interface, and performing confidentiality protection on the second NAS message may include performing confidentiality protection on the second NAS message using a 5G-compatible EEA encryption interface.
[0087] Fig.17A The operation may be performed by a communication node (e.g., a wireless terminal on a downlink or a network node on an uplink) that is receiving the NAS message. As discussed above, the first and second NAS connections may share a master key for a NAS security context. At block 1715, delivering the first NAS message may include receiving a first NAS message and a first message authentication code from a second communication node via a first NAS connection, performing integrity protection of the first NAS message by generating a first derived message authentication code for the first NAS message based on a first NAS connection identifier, a master key, and the first NAS message, and processing the first NAS message in response to the first message authentication code and the first derived message authentication code matching. At block 1719, delivering the second NAS message may include receiving a second NAS message and a second message authentication code from a second communication node via a second NAS connection, performing integrity protection of the second NAS message by generating a second derived message authentication code for the second NAS message based on a second NAS connection identifier, a master key, and the second NAS message, and processing the second NAS message in response to the second message authentication code and the second derived message authentication code matching.
[0088] According to some embodiments of the receiving node, the first NAS connection identifier may be concatenated with a first NAS count for a first NAS message, the concatenation of the first NAS connection identifier and the first NAS count may be provided as an input to generate a first derived message authentication code, the second NAS connection identifier may be concatenated with a second NAS count for a second NAS message, and the concatenation of the second NAS connection identifier and the second NAS count may be provided as an input to generate a second derived message authentication code. According to some other embodiments of the receiving node, the first NAS connection identifier may be provided as an input to generate a first derived message authentication code, and the second NAS connection identifier may be provided as an input to generate a second derived message authentication code. According to some other embodiments of the receiving node, the master key and the first NAS connection identifier may be used to derive a first integrity protection key for generating the first derived message authentication code, and the master key and the second NAS connection identifier may be used to derive a second integrity protection key for generating the second derived message authentication code. Moreover, performing integrity protection on the first NAS message may include performing integrity protection on the first NAS message using a 5G-compatible EIA integrity protection interface, and performing integrity protection on the second NAS message may include performing integrity protection on the second NAS message using a 5G-compatible EIA integrity protection interface.
[0089] Fig.17A The operation may be performed by a communication node (e.g., a wireless terminal on a downlink or a network node on an uplink) that is receiving the NAS message. As discussed above, the first and second NAS connections may share a master key for a NAS security context. In box 1717, delivering the first NAS message may include receiving a first encrypted NAS message from a second communication node via a first NAS connection, performing confidentiality protection on the first NAS message by decrypting the first encrypted NAS message using a first NAS connection identifier and the master key to provide a first decrypted NAS message, and processing the first decrypted NAS message. In box 1719, delivering the second NAS message may include receiving a second encrypted NAS message from a second communication node via a second NAS connection, performing confidentiality protection on the second NAS message by decrypting the second encrypted NAS message using a second NAS connection identifier and the master key to provide a second decrypted NAS message, and processing the second decrypted NAS message.
[0090] According to some embodiments of the receiving node, the first NAS connection identifier may be concatenated with a first NAS count for a first NAS message, the concatenation of the first NAS connection identifier and the first NAS count may be provided as an input to generate a first decrypted NAS message, the second NAS connection identifier may be concatenated with a second NAS count for a second NAS message, and the concatenation of the second NAS connection identifier and the second NAS count may be provided as an input to generate a second encrypted NAS message. According to some other embodiments of the receiving node, the first NAS connection identifier may be provided as an input to generate a first decrypted NAS message, and the second NAS connection identifier may be provided as an input to generate a second decrypted NAS message. According to some other embodiments of the receiving node, the master key and the first NAS connection identifier may be used to derive a first decryption key for generating the first decrypted NAS message, and the master key and the second NAS connection identifier may be used to derive a second decryption key for generating the second decrypted NAS message. Moreover, performing confidentiality protection on the first NAS message may include performing confidentiality protection on the first NAS message using a 5G-compatible EEA decryption interface, and performing confidentiality protection on the second NAS message may include performing confidentiality protection on the second NAS message using a 5G-compatible EEA decryption interface.
[0091] exist Fig.17A In an embodiment of the present invention, the first NAS connection may be provided by a 3GPP access node between the first and second communication nodes, and the second NAS connection may be provided by a non-3GPP access node between the first and second communication nodes; or the first NAS connection may be provided by a non-3GPP access node between the first and second communication nodes, and the second NAS connection may be provided by a 3GPP access node between the first and second communication nodes. For example, the 3GPP access node may include a radio access network base station, and the non-3GPP access node may include at least one of a WiFi access node and / or a satellite access node.
[0092] Furthermore, the first and second communication nodes can simultaneously maintain Fig.17A Furthermore, a packet data unit (PDU) session may be established based on the first and second NAS messages to transfer user plane data between the first and second communication nodes.
[0093] For some embodiments of communication nodes and related methods, Fig.17A Various operations and / or Fig. 17B The module may be optional. Regarding the method of Example 1 (as described below), for example, Fig. 17B The operation of box 1715 may be optional.
[0094] According to some other embodiments, as described below, the NAS COUNT domain may be divided according to the number of running NAS connections.
[0095] Relative to targeting Fig. 10A -B, 11A-B, 12A-B and 13A-B The embodiments discussed above differ in that the NAS CONN ID may not be continuously incremented, and in fact, it is possible to assign the same NAS CONN ID value to different NAS connections during the lifetime of the KAMF key.
[0096] In such an embodiment, a new parameter denoted by NAS CONN NUM can be used to track the number of running NAS connections of the wireless terminal. In addition, a special pair of NAS COUNTs can be used to track the maximum value of COUNTs on the uplink and downlink across all available NAS COUNT pairs. This parameter can be called the MAX NAS COUNT pair. Initially, all parameters are set to 0. When a new NAS connection is established for the wireless terminal, the new NAS connection is assigned the current NASCONN NUM value as the NAS CONN ID. A new pair of NAS COUNTs is created, where their values are set to the current NASCOUNT MAX value plus the connection NAS CONN ID. For all existing connections, the NAS COUNT value is adjusted to the current NASCOUNT MAX value plus the corresponding NAS CONN ID value. Finally, the NAS CONN NUM is incremented.
[0097] In the case of a NAS connection being terminated, then the NAS CONN NUM is decremented, all connections with identifiers beyond the identifier of the connection being torn down are decremented, and all NAS COUNTs are adjusted as in the case of a connection being added. Whenever a NAS message is successfully processed (either for transmission or on reception), then the NAS COUNT value is incremented by the NAS COUNT NUM for that NAS connection. Intuitively, the NAS CONN NUM is used as the increment for all NAS COUNTs. However, to reduce / prevent overlap, the NAS COUNT is readjusted each time a connection is established or torn down, based on the current NAS COUNT MAX value and the corresponding (possibly readjusted) NAS CONN ID.
[0098] This embodiment may not provide / ensure efficient / good usage of the NAS COUNT field. In case one NAS connection is more active (driving the MAX NAS COUNT value) than other NAS connections, then terminating the more active NAS connection may trigger a jump in the NAS COUNT values of the remaining connections and thereby trigger a waste of NAS COUNT values.
[0099] Now refer to Fig.18A Flowchart and Fig.18B The modules discuss the operation of communication nodes. For example, Fig.18B The module may be stored in a memory of the communication node (for example, if the communication node is a wireless terminal, it is stored in Figure 6 or if the communication node is a network node, then stored in the wireless terminal memory 605. Figure 7 The modules may be in the network node memory 705 of the communication node), and these modules may provide instructions so that when the instructions of the modules are executed by the communication node processor (for example, if the communication node is a wireless terminal, the wireless terminal processor 603, or if the communication node is a network node, the network node processor 705), the processor executes Fig.18A The corresponding operations of the flowchart.
[0100] At block 1801, the communication node processor may provide a first NAS connection between the first and second communication nodes (e.g., using the first NAS connection module 1851), and at block 1803, the communication node processor may provide a second NAS connection between the first and second communication nodes (e.g., using the second NAS connection module 1853). Moreover, the first and second NAS connections may be different.
[0101] At block 1805, the communication node processor may allocate the NAS count field (e.g., using allocation module 1855) such that a first portion of the NAS count field is allocated for NAS messages communicated over the first NAS connection and a second portion of the NAS count field is allocated for NAS messages communicated over the second NAS connection. Furthermore, the first and second portions of the NAS count field may be mutually exclusive.
[0102] For NAS communication at block 1807, the communication node processor may determine which connection to use at block 1809. At block 1811, the communication node processor may communicate the NAS message over the first NAS connection using the lowest NAS count value from the first portion of the NAS count field for each NAS message communicated over the first NAS connection (e.g., using the first NAS communication module 1851). At block 1813, the communication node processor may communicate the NAS message over the second NAS connection using the lowest NAS count value from the second portion of the NAS count field for each NAS message communicated over the second NAS connection (e.g., using the second NAS communication module 1853).
[0103] The NAS count values of the first and second parts of the NAS count field may be interleaved. In the case of two NAS connections, the first part of the NAS count field may include even NAS count values and the second part of the NAS count field may include odd NAS count values. With this partitioning of the NAS count field, NAS messages delivered over the first NAS connection may be assigned sequence numbers 0, 2, 4, 6, 8, etc. from the first part of the NAS count field, and NAS messages delivered over the second NAS connection may be assigned sequence numbers 1, 3, 5, 7, etc. from the second part of the NAS count field. Moreover, if one of the NAS connections is more active, more sequence numbers may be assigned from one part of the NAS count field than from another part of the NAS count field. For example, if 8 NAS messages are delivered over the first NAS connection and 3 NAS messages are delivered over the second NAS connection, sequence numbers 0, 2, 4, 6, 8, 10, 12, and 14 may be assigned to the NAS messages delivered over the first NAS connection, sequence numbers 1, 3, and 5 may be assigned to the NAS messages delivered over the second NAS connection, and the maximum NAS count value will be 14.
[0104] The operations of blocks 1807, 1809, 1811, and 1813 may be repeated at block 1815 until a change in connection occurs. For example, at block 1816, the communication node processor may provide a third NAS connection between the first and second communication nodes (e.g., using third NAS connection module 1856). The first and third NAS connections are different, and the second and third NAS connections are different. Also, at block 1817, the communication node processor may reallocate the NAS count field (e.g., using reallocate module 1857). Upon reallocation, a first portion of the NAS count field may be allocated for NAS messages delivered via the first NAS connection, a second portion of the NAS count field may be allocated for NAS messages delivered via the second NAS connection, and a third portion of the NAS count field may be allocated for NAS messages delivered via the third NAS connection, wherein the first, second, and third portions of the NAS count field are mutually exclusive.
[0105] Continuing with the above example, if the NAS count maximum value is 18, a reallocation may occur for NAS count values greater than 14, leaving NAS count values 7, 9, 11, and 13 unused. According to such an example, after the reallocation, a first portion of the NAS count field may include NAS count values greater than 14 that are divisible by 3 (e.g., 15, 18, 21, 24, etc.), a second portion of the NAS count field may include NAS count values greater than 14 that provide a remainder of 1 when divided by 3 (e.g., 16, 19, 22, 25, etc.), and a third portion of the NAS count field may include NAS count values greater than 14 that provide a remainder of 2 when divided by 3 (e.g., 17, 20, 23, 26, etc.).
[0106] For the NAS communication at block 1819, the communication node processor may determine which connection to use at block 1821. At block 1831, the communication node processor may communicate the NAS message over the first NAS connection using the lowest NAS count value from the first portion of the NAS count field for each NAS message that has not been previously used to communicate over the first NAS connection (e.g., using the first NAS communication module 1861). At block 1833, the communication node processor may communicate the NAS message over the second NAS connection using the lowest NAS count value from the second portion of the NAS count field for each NAS message that has not been previously used to communicate over the second NAS connection (e.g., using the second NAS communication module 1863). At block 1835, the communication node processor may communicate the NAS message over the third NAS connection using the lowest NAS count value from the third portion of the NAS count field for each NAS message that has not been previously used to communicate over the third NAS connection (e.g., using the second NAS communication module 1865).
[0107] according to Fig.18A In some embodiments of the present invention, the first communication node may be a network node, the second communication node may be a wireless terminal, and the NAS count field may be an uplink NAS count field. Thus, delivering the NAS message via the first NAS connection may include receiving the NAS message via the first NAS connection, and delivering the NAS message via the second NAS connection may include receiving the NAS message via the second NAS connection.
[0108] according to Fig.18A In some other embodiments, the first communication node may be a network node, the second communication node may be a wireless terminal, and the NAS count field may be a downlink NAS count field. Thus, delivering the NAS message over the first NAS connection may include transmitting the NAS message over the first NAS connection, and delivering the NAS message over the second NAS connection may include transmitting the NAS message over the second NAS connection.
[0109] according to Fig.18A In still other embodiments, the first communication node may be a wireless terminal, the second communication node may be a network node, and the NAS count field is an uplink NAS count field. Thus, delivering the NAS message via the first NAS connection may include transmitting the NAS message via the first NAS connection, and delivering the NAS message via the second NAS connection may include transmitting the NAS message via the second NAS connection.
[0110] according to Fig.18A In some other embodiments, the first communication node may be a wireless terminal, the second communication node may be a network node, and the NAS count field may be a downlink NAS count field. Thus, delivering the NAS message via the first NAS connection may include receiving the NAS message via the first NAS connection, and delivering the NAS message via the second NAS connection may include receiving the NAS message via the second NAS connection.
[0111] exist Fig.18A In an embodiment, the first NAS connection may be provided through a 3GPP access node between the first and second communication nodes, and the second NAS connection may be provided through a non-3GPP access node between the first and second communication nodes, or the first NAS connection may be provided through a non-3GPP access node between the first and second communication nodes, and the second NAS connection may be provided through a 3GPP access node between the first and second communication nodes.
[0112] Furthermore, communicating the NAS message over the first NAS connection may include at least one of performing integrity protection by generating a message authentication code using a corresponding NAS-count value from the first portion of the NAS-count field and / or performing confidentiality protection using a corresponding NAS-count value from the first portion of the NAS-count field. Similarly, communicating the NAS message over the second NAS connection may include at least one of performing integrity protection by generating a message authentication code using a corresponding NAS-count value from the second portion of the NAS-count field and / or performing confidentiality protection using a corresponding NAS-count value from the second portion of the NAS-count field.
[0113] Furthermore, the first and second communication nodes can simultaneously maintain Fig.18A Furthermore, a packet data unit (PDU) session may be established based on the first and second NAS messages to transfer user plane data between the first and second communication nodes.
[0114] For some embodiments of communication nodes and related methods, Fig.18A Various operations and / or Fig.18B The module may be optional. Regarding the method of Example Embodiment 1 (described below), for example, Fig.18A The operations of boxes 1807, 1809, 18015, 1816, 1817, 1819, 1821, 1831, 1833 and 1835 may be optional, and modules 1856, 1857, 1861, 1863 and 1865 may be optional.
[0115] According to some other embodiments of the inventive concept, encryption separation may be provided at the key level.NAS protection keys may be derived in a conventional system as described in TS33.401 (also referred to as reference [2]).
[0116] In general, all key derivations for LTE (including input parameter encoding) can be performed using the key derivation function (KDF) specified in TS 33.220 (also referred to as reference [4]). The KDF accepts as input a secret key and a string S. The derived key is obtained by applying HMAC-SHA-256 (described in RFC 2104, also referred to as reference [5]) to the input secret key and string S. The string S is constructed by concatenating a discriminator parameter called FC and a set of other parameters and their corresponding lengths: S = FC || P0 || L0 || P1 || L1 || P2 || L2 || P3 || L3 || ... || Pn || Ln, where Pi (i from 0 to n) is a parameter and Li is its length in octets.
[0117] According to clause A.7 of TS 33.401 (also referred to as reference [2]), when deriving keys for NAS integrity and NAS encryption processes (also referred to as algorithms) from KASME and the process / algorithm type and ID, the following parameters may / should be used to form the string S.
[0118] -FC = 0x15
[0119] - P0 = procedure type specifier
[0120] - L0 = length of the procedure type specifier (i.e. 0x00 0x01)
[0121] - P1 = Process ID
[0122] - L1 = length of the process identifier (i.e. 0x00 0x01)
[0123] The process type specifier shall be NAS-enc-alg for NAS encryption procedures and NAS-int-alg for NAS integrity protection procedures (see Table A.7-1). Fig.14 is a table illustrating process type specifiers.
[0124] The process identifier (as specified in clause 5 of TS 33.401, also referred to as reference [2]) may / should be placed in the four least significant bits of the octet. The two least significant bits of the four most significant bits may be reserved for future use, and the two most significant bits of the most significant nibble may be reserved for private use. All four most significant bits may / should be set to all zeros.
[0125] For NAS process key derivation, the input key can / should be 256-bit KASME. For a process key of length n bits, where n is less than or equal to 256, the n least significant bits of the 256 bits output by the KDF can / should be used as the process key (also called the algorithm key).
[0126] As mentioned above Fig. 10A As discussed in Figures 1-B, 11A-B, 12A-B and 13A-B, the NAS connection identifier NAS CONN ID can be used in the authentication and / or encryption / decryption process to provide separation for different NAS connections used by the same wireless terminal.
[0127] According to some embodiments, the NAS CONN ID may be used in deriving the NAS protection keys KNASenc and KNASint. The resulting protection keys may thus be NAS connection specific to provide separation for different NAS connections used by the same wireless terminal.
[0128] For example, a new parameter P2 may be introduced in order to construct the input S string. This parameter P2 will be the NAS CONN ID, and its length L2 will be whatever length (in octets) the NAS CONN ID has. For example, if the NAS CONN ID is 8 bits long, then L2 is 1 (for one octet). If the NAS CONN ID is specified as a 32-bit long value, then L2 will be set to a constant 4 (for four octets). All other parameters (P0, P1) may remain unchanged, or may be based on the 5G equivalents.
[0129] Fig.15 The diagram illustrates a key derivation based on an S string, where the NAS CONN ID is used in deriving the S string. Here, the master key KAMF and S are provided as inputs to a key derivation function KDF to generate a key K for EIA authentication and / or EEA encryption / decryption. Fig.15 middle:
[0130] ● KAMF is the 5G equivalent of KASME;
[0131] ● S is constructed as a cascade of FC||P0||L0||P1||L1||P2||L2, where:
[0132] o FC is potentially a new discriminator for deriving NAS protection keys,
[0133] ○ P0, P1, L0, and L1 are based on potentially new parameters and values that are equivalent to those used in LTE. In fact, the algorithms in 5G may potentially have other names and other type specifier values, etc.
[0134] ○ P2 and L2 are new parameters based on NAS CONN ID.
[0135] The same process is used to derive NAS integrity protection keys or NAS encryption keys, depending on the FC value. Since the NAS CONN ID is used in the derivation function, those keys will be NAS connection specific.
[0136] According to some other embodiments, the NAS CONN ID may be used to derive a new level of key KNAS from the KAMF key, which is then used to derive other lower level protection keys. KNAS and the derived protection keys may thus be NAS connection specific.
[0137] For example, Fig.16As shown in , a new key called KNAS can be derived from KAMF, where S is set to FC||P0||L0, where FC has a new value and P0, L0 correspond to the NAS CONN ID. In fact, P0 and L0 are defined similarly as above for Fig.15 P2 and L2 discussed. Because the NAS CONN ID is used in the derivation of this new intermediate key, it is NAS connection specific. All things subsequently derived from the KNAS key will also be NAS connection specific. Therefore, it is recommended to derive the NAS protection keys KNASint and KNASenc from KNAS similar to what is done in conventional systems when deriving NAS protection keys KNASint and KNASenc from KASME.
[0138] Thus, if Fig.16 As shown in FIG. 1 , an overall key derivation scheme for generating NAS protection keys can be provided. In an embodiment where key derivation is provided based on NAS CONN ID, the same as above for Fig. 10A -B, 11A-B, 12A-B and 13A-B, a greater number of connection-specific parameters may be used / required.
[0139] Example embodiments are discussed below.
[0140] 1. A method of providing, at a first communication node, communication of a network access stratum (NAS) message with a second communication node, the method comprising: providing (1711) a first NAS connection identifier for a first NAS connection between the first and second communication nodes; providing (1713) a second NAS connection identifier for a second NAS connection between the first and second communication nodes, wherein the first and second NAS connection identifiers are different, and wherein the first and second NAS connections are different; communicating (1717) a first NAS message between the first and second communication nodes over the first NAS connection, wherein communicating the first NAS message comprises at least one of performing integrity protection on the first NAS message using the first NAS connection identifier and / or performing confidentiality protection on the first NAS message using the first NAS connection identifier; and communicating (1719) a second NAS message between the first and second communication nodes over the second NAS connection, wherein communicating the second NAS message comprises at least one of performing integrity protection on the second NAS message using the second NAS connection identifier and / or performing confidentiality protection on the second NAS message using the second NAS connection identifier for confidentiality protection.
[0141] 2. The method of embodiment 1, wherein the first and second NAS connections share a master key of a NAS security context, wherein delivering the first NAS message comprises at least one of performing integrity protection on the first NAS message using the first NAS connection identifier and the master key and / or performing confidentiality protection on the first NAS message using the first NAS connection identifier and the master key, and wherein delivering the second NAS message comprises at least one of performing integrity protection on the second NAS message using the second NAS connection identifier and the master key and / or performing confidentiality protection on the second NAS message using the second NAS connection identifier and the master key.
[0142] 3. The method of embodiment 1, wherein the first and second NAS connections share a master key of a NAS security context, wherein delivering the first NAS message includes performing integrity protection on the first NAS message by generating a first message authentication code based on the first NAS connection identifier, the master key, and the first NAS message, and transmitting the first NAS message together with the first message authentication code to the second communication node through the first NAS connection, and wherein delivering the second NAS message includes performing integrity protection on the second NAS message by generating a second message authentication code based on the second NAS connection identifier, the master key, and the second NAS message, and transmitting the second NAS message together with the second message authentication code to the second communication node through the second NAS connection.
[0143] 4. The method of embodiment 3, wherein the first NAS connection identifier is concatenated with a first NAS count for the first NAS message, wherein the concatenation of the first NAS connection identifier and the first NAS count is provided as an input to generating a first message authentication code, wherein the second NAS connection identifier is concatenated with a second NAS count for the second NAS message, and wherein the concatenation of the second NAS connection identifier and the second NAS count is provided as an input to generating a second message authentication code.
[0144] 5. The method of embodiment 3, wherein the first NAS connection identifier is provided as an input to generate the first message authentication code, and wherein the second NAS connection identifier is provided as an input to generate the second message authentication code.
[0145] 6. The method of embodiment 3, wherein the master key and the first NAS connection identifier are used to derive a first integrity protection key for generating a first message authentication code, and wherein the master key and the second NAS connection identifier are used to derive a second integrity protection key for generating a second message authentication code.
[0146] 7. The method of any one of embodiments 3-6, wherein performing integrity protection on the first NAS message includes performing integrity protection on the first NAS message using a 5G-compatible EIA integrity protection interface, and wherein performing integrity protection on the second NAS message includes performing integrity protection on the second NAS message using a 5G-compatible EIA integrity protection interface.
[0147] 8. The method of embodiment 1, wherein the first and second NAS connections share a master key of a NAS security context, wherein delivering a first NAS message comprises performing confidentiality protection on the first NAS message by encrypting the first NAS message using a first NAS connection identifier and the master key to provide a first encrypted NAS message, and delivering the first encrypted NAS message to the second communication node through the first NAS connection; and wherein delivering a second NAS message comprises performing confidentiality protection on the second NAS message by encrypting the second NAS message using a second NAS connection identifier and the master key to provide a second encrypted NAS message, and delivering the second encrypted NAS message to the second communication node through the second NAS connection.
[0148] 9. The method of embodiment 8, wherein the first NAS connection identifier is concatenated with a first NAS count for a first NAS message, wherein the concatenation of the first NAS connection identifier and the first NAS count is provided as an input to generating a first encrypted NAS message, wherein the second NAS connection identifier is concatenated with a second NAS count for a second NAS message, and wherein the concatenation of the second NAS connection identifier and the second NAS count is provided as an input to generating a second encrypted NAS message.
[0149] 10. The method of embodiment 8, wherein the first NAS connection identifier is provided as an input to generating the first encrypted NAS message, and wherein the second NAS connection identifier is provided as an input to generating the second encrypted NAS message.
[0150] 11. The method of embodiment 8, wherein the master key and the first NAS connection identifier are used to derive a first encryption key for generating a first encrypted NAS message, and wherein the master key and the second NAS connection identifier are used to derive a second encryption key for generating a second encrypted NAS message.
[0151] 12. The method of any one of embodiments 8-11, wherein performing confidentiality protection on the first NAS message includes performing confidentiality protection on the first NAS message using a 5G-compatible EEA encryption interface, and wherein performing confidentiality protection on the second NAS message includes performing confidentiality protection on the second NAS message using a 5G-compatible EEA encryption interface.
[0152] 13. The method of embodiment 1, wherein the first and second NAS connections share a master key of a NAS security context, wherein delivering a first NAS message comprises receiving a first NAS message and a first message authentication code from a second communication node via the first NAS connection, performing integrity protection on the first NAS message by generating a first derived message authentication code of the first NAS message based on the first NAS connection identifier, the master key, and the first NAS message, and processing the first NAS message in response to the first message authentication code and the first derived message authentication code matching, and wherein delivering a second NAS message comprises receiving a second NAS message and a second message authentication code from a second communication node via the second NAS connection, performing integrity protection on the second NAS message by generating a second derived message authentication code of the second NAS message based on the second NAS connection identifier, the master key, and the second NAS message, and processing the second NAS message in response to the second message authentication code and the second derived message authentication code matching.
[0153] 14. The method of embodiment 13, wherein the first NAS connection identifier is concatenated with a first NAS count for a first NAS message, wherein the concatenation of the first NAS connection identifier and the first NAS count is provided as an input to generating a first derived message authentication code, wherein the second NAS connection identifier is concatenated with a second NAS count for a second NAS message, and wherein the concatenation of the second NAS connection identifier and the second NAS count is provided as an input to generating a second derived message authentication code.
[0154] 15. The method of embodiment 13, wherein the first NAS connection identifier is provided as an input to generate the first derived message authentication code, and wherein the second NAS connection identifier is provided as an input to generate the second derived message authentication code.
[0155] 16. The method of embodiment 13, wherein the master key and the first NAS connection identifier are used to derive a first integrity protection key for generating a first derived message authentication code, and wherein the master key and the second NAS connection identifier are used to derive a second integrity protection key for generating a second derived message authentication code.
[0156] 17. The method of any one of embodiments 13-16, wherein performing integrity protection on the first NAS message includes performing integrity protection on the first NAS message using a 5G-compatible EIA integrity protection interface, and wherein performing integrity protection on the second NAS message includes performing integrity protection on the second NAS message using a 5G-compatible EIA integrity protection interface.
[0157] 18. The method of embodiment 1, wherein the first and second NAS connections share a master key of a NAS security context, wherein communicating the first NAS message comprises receiving a first encrypted NAS message from the second communication node via the first NAS connection, performing confidentiality protection on the first NAS message by decrypting the first encrypted NAS message using the first NAS connection identifier and the master key to provide a first decrypted NAS message, and processing the first decrypted NAS message. wherein communicating the second NAS message comprises receiving a second encrypted NAS message from the second communication node via the second NAS connection, performing confidentiality protection on the second NAS message by decrypting the second encrypted NAS message using the second NAS connection identifier and the master key to provide a second decrypted NAS message, and processing the second decrypted NAS message.
[0158] 19. The method of embodiment 18, wherein the first NAS connection identifier is concatenated with a first NAS count for a first NAS message, wherein the concatenation of the first NAS connection identifier and the first NAS count is provided as an input to generating a first decrypted NAS message, wherein the second NAS connection identifier is concatenated with a second NAS count for a second NAS message, and wherein the concatenation of the second NAS connection identifier and the second NAS count is provided as an input to generating a second encrypted NAS message.
[0159] 20. The method of embodiment 18, wherein the first NAS connection identifier is provided as an input to generating the first decrypted NAS message, and wherein the second NAS connection identifier is provided as an input to generating the second decrypted NAS message.
[0160] 21. The method of embodiment 18, wherein the master key and the first NAS connection identifier are used to derive a first decryption key for generating a first decrypted NAS message, and wherein the master key and the second NAS connection identifier are used to derive a second decryption key for generating a second decrypted NAS message.
[0161] 22. The method of any of embodiments 18-21, wherein performing confidentiality protection on the first NAS message includes performing confidentiality protection on the first NAS message using a 5G-compatible EEA decryption interface, and wherein performing confidentiality protection on the second NAS message includes performing confidentiality protection on the second NAS message using a 5G-compatible EEA decryption interface.
[0162] 23. The method of any of embodiments 1-22, wherein the first NAS connection is provided via a 3GPP access node between the first and second communication nodes, and the second NAS connection is provided via a non-3GPP access node between the first and second communication nodes, or wherein the first NAS connection is provided via a non-3GPP access node between the first and second communication nodes, and the second NAS connection is provided via a 3GPP access node between the first and second communication nodes.
[0163] 24. The method of embodiment 23, wherein the 3GPP access node comprises a radio access network base station, and wherein the non-3GPP access node comprises at least one of a WiFi access node and / or a satellite access node.
[0164] 25. The method of any one of embodiments 1-24, wherein the first and second NAS connections are simultaneously maintained between the first and second communications nodes.
[0165] 26. The method of any one of embodiments 1-25, wherein the first communication node comprises a network node of a wireless communication network and the second communication node comprises a wireless terminal, or wherein the first communication node comprises a wireless terminal and the second communication node comprises a network node of a wireless communication network.
[0166] 27. The method of any one of embodiments 1-26, further comprising: establishing a packet data unit (PDU) session based on the first and second NAS messages to transfer user plane data between the first and second communication nodes.
[0167] 28. A method of providing, at a first communication node, communication of network access stratum (NAS) messages with a second communication node, the method comprising: providing (1801) a first NAS connection between the first and second communication nodes; providing (1803) a second NAS connection between the first and second communication nodes, wherein the first and second NAS connections are different; allocating (1805) a NAS count field such that a first portion of the NAS count field is allocated for NAS messages communicated over the first NAS connection and such that a second portion of the NAS count field is allocated for NAS messages communicated over the second NAS connection, wherein the first portion and the second portion of the NAS count field are mutually exclusive; communicating (1811, 1831) a NAS message over the first NAS connection using a lowest NAS count value from the first portion of the NAS count field for each NAS message communicated over the first NAS connection; and communicating (1813, 1833) a NAS message over the second NAS connection using a lowest NAS count value from the second portion of the NAS count field for each NAS message communicated over the second NAS connection.
[0168] 29. The method of embodiment 28, wherein the NAS count values of the first part and the second part of the NAS count field are interleaved.
[0169] 30. The method of embodiment 29, wherein the first portion of the NAS count field includes even NAS count values, and wherein the second portion of the NAS count field includes odd NAS count values.
[0170] 31. The method of any of embodiments 28-29, the method further comprising: providing (1816) a third NAS connection between the first and second communication nodes, wherein the first and third NAS connections are different, and the second and third NAS connections are different, wherein a third portion of the NAS connection count field is allocated for NAS messages delivered over the third NAS connection, wherein the first, second, and third portions of the NAS count field are mutually exclusive; and delivering (1835) the NAS message over the third NAS connection using a lowest NAS count value from the third portion of the NAS count field that has not been previously used for the third NAS connection.
[0171] 32. The method of embodiment 31, wherein the first portion of the NAS count field includes a NAS count value that is divisible by 3, wherein the second portion of the NAS count field includes a NAS count value that provides a remainder of 1 when divided by 3, and wherein the third portion of the NAS count field includes a NAS count value that provides a remainder of 2 when divided by 3.
[0172] 33. The method of any of embodiments 28-32, wherein the first communication node comprises a network node and the second communication node comprises a wireless terminal, wherein the NAS count field is an uplink NAS count field, wherein delivering the NAS message via the first NAS connection comprises receiving the NAS message via the first NAS connection, and wherein delivering the NAS message via the second NAS connection comprises receiving the NAS message via the second NAS connection.
[0173] 34. The method of any of embodiments 28-32, wherein the first communication node comprises a network node and the second communication node comprises a wireless terminal, wherein the NAS count field is a downlink NAS count field, wherein delivering the NAS message via the first NAS connection comprises transmitting the NAS message via the first NAS connection, and wherein delivering the NAS message via the second NAS connection comprises transmitting the NAS message via the second NAS connection.
[0174] 35. The method of any of embodiments 28-32, wherein the first communication node comprises a wireless terminal and the second communication node comprises a network node, wherein the NAS count field is an uplink NAS count field, wherein delivering the NAS message via the first NAS connection comprises transmitting the NAS message via the first NAS connection, and wherein delivering the NAS message via the second NAS connection comprises transmitting the NAS message via the second NAS connection.
[0175] 36. The method of any of embodiments 28-32, wherein the first communication node comprises a wireless terminal and the second communication node comprises a network node, wherein the NAS count field is a downlink NAS count field, wherein delivering the NAS message via the first NAS connection comprises receiving the NAS message via the first NAS connection, and wherein delivering the NAS message via the second NAS connection comprises receiving the NAS message via the second NAS connection.
[0176] 37. The method of any of embodiments 28-36, wherein the first NAS connection is provided via a 3GPP access node between the first and second communication nodes, and the second NAS connection is provided via a non-3GPP access node between the first and second communication nodes, or wherein the first NAS connection is provided via a non-3GPP access node between the first and second communication nodes, and the second NAS connection is provided via a 3GPP access node between the first and second communication nodes.
[0177] 38. The method of embodiment 37, wherein the 3GPP access node comprises a radio access network base station, and wherein the non-3GPP access node comprises at least one of a WiFi access node and / or a satellite access node.
[0178] 39. The method of any of embodiments 28-38, wherein delivering the NAS message over the first NAS connection includes at least one of performing integrity protection by generating a message authentication code using a corresponding NAS count value from a first portion of the NAS count field and / or performing confidentiality protection using a corresponding NAS count value from the first portion of the NAS count field, and wherein delivering the NAS message over the second NAS connection includes at least one of performing integrity protection by generating a message authentication code using a corresponding NAS count value from a second portion of the NAS count field and / or performing confidentiality protection using a corresponding NAS count value from a second portion of the NAS count field.
[0179] 40. A communication node, wherein the communication node is adapted to perform operations according to any one of embodiments 1-39.
[0180] 41. A communication node, wherein the communication node comprises a module configured to perform operations according to any one of embodiments 1-39.
[0181] 42. A first communication node, comprising: a communication interface (601, 701), wherein the communication interface (601, 701) is configured to provide communication with a second communication node; and a processor (603, 703), wherein the processor (603, 703) is coupled to the communication interface, wherein the processor is configured to transmit communications to the second communication node and / or receive communications from the second communication node via the communication interface, wherein the processor is configured to perform operations according to any one of embodiments 1-39.
[0182] Further definitions and embodiments are discussed below.
[0183] In the above description of various embodiments of the inventive concept, it is to be understood that the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit the inventive concept. Unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as those of ordinary skill in the art to which the inventive concept belongs. It will be further understood that terms (such as those defined in commonly used dictionaries) should be interpreted as having a meaning consistent with their meaning in the context of the relevant field and this specification, and will not be interpreted in an idealized or overly formal sense unless explicitly defined herein.
[0184] When an element is referred to as being "connected" to another element, "coupled" to another element, "responsive" to another element or their variants, it can be directly connected to, coupled to or responsive to another element, or there may be an intervening element. On the contrary, when an element is referred to as being "directly connected" to another element, "directly coupled" to another element, "directly responsive" to another element or their variants, there is no intervening element. Similar numbers refer to similar elements throughout. Furthermore, "coupling", "connection", "response" or their variants as used herein may include wireless coupling, connection or response. As used herein, the singular forms "a, an" and "the" are intended to also include plural forms, unless the context clearly indicates otherwise. For the sake of brevity and / or clarity, well-known functions or structures may not be described in detail. The term "and / or" includes any and all combinations of one or more of the associated listed items.
[0185] It will be understood that although the terms first, second, third, etc. may be used herein to describe various elements / operations, these elements / operations should not be limited by these terms. These terms are only used to distinguish one element / operation from another element / operation. Thus, the first element / operation in some embodiments may be referred to as the second element / operation in other embodiments without departing from the teaching of the inventive concept. The same reference numerals or the same reference signs indicate the same or similar elements throughout the specification.
[0186] As used herein, the terms "comprise, comprising, comprises," "include, including, includes," "have, has, having," or variations thereof are open ended and include one or more stated features, integers, elements, steps, components, or functions, but do not preclude the presence or addition of one or more other features, integers, elements, steps, components, functions, or combinations thereof. In addition, as used herein, the common abbreviation "eg," which is derived from the Latin phrase "exempli gratia," may be used to introduce or specify one or more general examples of previously mentioned items, and is not intended to limit such items. The common abbreviation "ie," which is derived from the Latin phrase "id est," may be used to specify a specific item from a more general statement.
[0187] Example embodiments are described herein with reference to block diagrams and / or flowchart illustrations of computer-implemented methods, devices (systems and / or apparatuses), and / or computer program products. It is to be understood that the blocks of the block diagrams and / or flowchart illustrations and the combination of blocks in the block diagrams and / or flowchart illustrations can be implemented by computer program instructions executed by one or more computer circuits. These computer program instructions can be provided to a processor circuit of a general-purpose computer circuit, a special-purpose computer circuit, and / or other programmable data processing circuit to produce a machine, so that instructions executed via a processor of a computer and / or other programmable data processing device transform and control transistors, values stored in memory locations, and other hardware components within such circuits to implement the functions / actions specified in the block diagrams and / or one or more flowchart boxes, and thereby create components (functionality) and / or structures for implementing the functions / actions specified in the block diagrams and / or (one or more) flowchart boxes.
[0188] These computer program instructions may also be stored in a tangible computer-readable medium that can direct a computer or other programmable data processing device to function in a specific manner, so that the instructions stored in the computer-readable medium produce an article of manufacture, the article of manufacture including instructions for implementing the functions / actions specified in the block diagram and / or one or more flowchart blocks. Therefore, the embodiments of the present inventive concept may be implemented in hardware and / or in software (including firmware, resident software, microcode, etc.) running on a processor such as a digital signal processor, which may be collectively referred to as a "circuit", "module" or a variant thereof.
[0189] It should also be noted that in some alternative implementations, the function / action annotated in the frame may not occur in the order annotated in the flow chart. For example, depending on the functionality / action involved, the two frames shown continuously may actually be executed substantially simultaneously, or the frames may sometimes be executed in reverse order. Moreover, the functionality of a given frame of a flow chart and / or block diagram may be divided into a plurality of frames, and / or the functionality of two or more frames of a flow chart and / or block diagram may be integrated at least in part. Finally, without departing from the scope of the inventive concept, other frames may be added / inserted between the illustrated frames, and / or frames / operations may be omitted. Moreover, although some diagrams include arrows on the communication path to illustrate the main direction of communication, it is to be understood that communication may occur in the direction opposite to the arrows depicted.
[0190] Many variations and modifications can be made to the embodiments without substantially departing from the principles of the inventive concept. All such variations and modifications are intended to be included in the scope of the inventive concept herein. Thus, the subject matter disclosed above is to be considered illustrative, rather than restrictive, and the examples of the embodiments are intended to cover all such modifications, enhancements, and other embodiments that fall within the spirit and scope of the inventive concept. Thus, to the maximum extent permitted by law, the scope of the inventive concept will be determined by the broadest permissible interpretation of the present disclosure, including the following claims and their equivalents, and should not be constrained or limited by the foregoing detailed description.
[0191] The above mentioned abbreviations are discussed below.
[0192] Abbreviation
[0193] AMF Access Management Function
[0194] CM Connection Management
[0195] CONN ID Connection ID
[0196] EEA EPS encryption algorithm
[0197] EIA EPS Integrity Algorithm
[0198] eKSI E-UTRAN Key Set Identifier
[0199] EMM EPS Mobility Management
[0200] EPC Evolved Packet Core
[0201] EPS Evolved Packet System
[0202] IE Information Elements
[0203] KAMF AMS specific key
[0204] KASME Access Security Management Item Key
[0205] KDF Key Derivation Function
[0206] KNAS NAS Protection Key
[0207] KNASenc KNAS Encryption
[0208] KNASint KNAS Integrity
[0209] LTE Long Term Evolution
[0210] MAC Message Authentication Code
[0211] NAS Network Access Layer
[0212] PDU Packet Data Unit
[0213] SMC Safe Mode Commands
[0214] SN Serial Number
[0215] UE User Equipment
[0216] 3GPP Third Generation Partnership Project
[0217] 5G Fifth Generation
[0218] The references mentioned above are identified as follows.
[0219] Ref. [1] 3GPP TS 23.501 V0.4.0 (2017-04), Technical SpecificationGroup Services andSystem Aspects; System Architecture for the 5G System;Stage 2 (Release 15)
[0220] Ref. [2] 3GPP TS 33.401 V14.2.0 (2017-03), Technical SpecificationGroup Services and System Aspects; 3GPP System Architecture Evolution (SAE);Security architecture(Release 14)
[0221] Ref. [3] 3GPP TS 24.301 V14.3.0 (2017-03), Technical SpecificationGroup Core Network and Terminals; Non-Access-Stratum (NAS) protocol forEvolved Packet System (EPS); Stage 3(Release 14)
[0222] Ref. [4] 3GPP TS 33.220 V14.0.0 (2016-12), Technical SpecificationGroup Services and System Aspects; Generic Authentication Architecture (GAA);Generic Bootstrapping Architecture (GBA)(Release 14)
[0223] Ref. [5] Krawczyk, et al., “HMAC: Keyed-Hashing for MessageAuthentication,” RFC 2104, February 1997
Claims
1. A method for providing, at a first communication node, communication of a network access stratum NAS message with a second communication node of a wireless communication network, the method comprising: A first NAS message is communicated (1717) between the first communication node and the second communication node via a first NAS connection, wherein communicating the first NAS message comprises: performing integrity protection on the first NAS message using a first NAS connection identifier, and performing the integrity protection on the first NAS message by generating a first message authentication code based on the first NAS connection identifier, a master key of a NAS security context, and the first NAS message, and transmitting the first NAS message together with the first message authentication code to the second communication node via the first NAS connection; A second NAS message is communicated (1719) between the first communication node and the second communication node via a second NAS connection, wherein communicating the second NAS message comprises: performing integrity protection on the second NAS message using a second NAS connection identifier, wherein the first and second NAS connections are different and share the master key, and performing the integrity protection on the second NAS message by generating a second message authentication code based on the second NAS connection identifier, the master key, and the second NAS message, and transmitting the second NAS message together with the second message authentication code to the second communication node via the second NAS connection.
2. The method of claim 1, wherein the first NAS connection identifier is provided as an input to generating the first message authentication code, and wherein the second NAS connection identifier is provided as an input to generating the second message authentication code.
3. The method of any one of claims 1-2, wherein performing integrity protection on the first NAS message comprises performing integrity protection on the first NAS message using a 5G-compatible EIA integrity protection interface, and wherein performing integrity protection on the second NAS message comprises performing integrity protection on the second NAS message using the 5G-compatible EIA integrity protection interface.
4. The method of any one of claims 1 to 3, wherein the first NAS connection is provided through a 3GPP access node between the first communication node and the second communication node, and the second NAS connection is provided through a non-3GPP access node between the first communication node and the second communication node, or wherein the first NAS connection is provided through a non-3GPP access node between the first communication node and the second communication node, and the second NAS connection is provided through a 3GPP access node between the first communication node and the second communication node.
5. The method of claim 4, wherein the 3GPP access node comprises a radio access network base station, and wherein the non-3GPP access node comprises at least one of the following: a WiFi access node and / or a satellite access node.
6. The method of any one of claims 1-5, wherein the first and second NAS connections are simultaneously maintained between the first communication node and the second communication node.
7. The method according to any one of claims 1 to 6, further comprising: A packet data unit (PDU) session is established based on the first and second NAS messages to transfer user plane data between the first communication node and the second communication node.
8. A first communication node adapted to provide communication of network access stratum NAS messages with a second communication node of a wireless communication network, wherein first and second NAS connections between the first communication node and the second communication node share a master key for a NAS security context, and wherein the first communication node is adapted to: The step of transmitting a first NAS message between the first communication node and the second communication node through the first NAS connection, wherein the transmitting the first NAS message comprises: performing integrity protection on the first NAS message using the first NAS connection identifier, performing the integrity protection on the first NAS message by generating a first message authentication code based on the first NAS connection identifier, the master key and the first NAS message, and transmitting the first NAS message together with the first message authentication code to the second communication node through the first NAS connection; A second NAS message is communicated between the first communication node and the second communication node through the second NAS connection, wherein the communicating the second NAS message comprises: performing integrity protection on the second NAS message using a second NAS connection identifier, performing integrity protection on the second NAS message by generating a second message authentication code based on the second NAS connection identifier, the master key and the second NAS message, and transmitting the second NAS message together with the second message authentication code to the second communication node through the second NAS connection.
9. The first communications node of claim 8, wherein the first NAS connection identifier is provided as an input to generating the first message authentication code, and wherein the second NAS connection identifier is provided as an input to generating the second message authentication code.
10. A first communication node as described in any one of claims 8-9, wherein performing integrity protection on the first NAS message includes performing integrity protection on the first NAS message using a 5G-compatible EIA integrity protection interface, and wherein performing integrity protection on the second NAS message includes performing integrity protection on the second NAS message using the 5G-compatible EIA integrity protection interface.
11. A first communication node as described in any one of claims 8 to 10, wherein the first NAS connection is provided through a 3GPP access node between the first communication node and the second communication node, and the second NAS connection is provided through a non-3GPP access node between the first communication node and the second communication node, or wherein the first NAS connection is provided through a non-3GPP access node between the first communication node and the second communication node, and the second NAS connection is provided through a 3GPP access node between the first communication node and the second communication node.
12. The first communications node of claim 11, wherein the 3GPP access node comprises a radio access network base station, and wherein the non-3GPP access node comprises at least one of: a WiFi access node and / or a satellite access node.
13. The first communication node according to any one of claims 8 to 12, wherein the first and second NAS connections are simultaneously maintained between the first communication node and the second communication node.
14. The first communication node according to any one of claims 8 to 13, wherein the first communication node is further adapted to: A packet data unit (PDU) session is established based on the first and second NAS messages to transfer user plane data between the first communication node and the second communication node.
Citation Information
Patent Citations
Mobile communications network, infrastructure equipment and method for managing reduced mobility of and sending downlink data to machine type communciations (mtc) devices
CN103843428A
Multiple concurrent contexts virtual evolved session management (virtual ESM)
US20160286600A1