Secure random access procedure

CN115735398BActive Publication Date: 2026-08-18APPLE INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202180007886.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-01
Publication Date
2026-08-18
Estimated Expiration
2041-07-01

Smart Images

  • Figure CN115735398B_ABST
    Figure CN115735398B_ABST
Patent Text Reader

Abstract

The present application relates to apparatuses and components including devices, systems, and methods for secure random access in a wireless communication system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to a secure random access procedure. Background Technology

[0002] The 3GPP fifth-generation (5G) new radio (NR) network uses a two-step or four-step random access (RA) process to allow user devices (such as mobile phones) to negotiate access to the network. Summary of the Invention

[0003] A method includes: generating a random access preamble for transmission to a base station; generating a first message including a contention resolution identifier for transmission to the base station; identifying a second message received from the base station including a first value; generating a second value based at least in part on a plurality of parameters, wherein the plurality of parameters includes the contention resolution identifier, a random access radio network temporary identifier (RA-RNTI), and a current value, the RA-RNTI being at least in part based on the timing of the random access preamble; and comparing the first value with the second value to determine whether a random access procedure was successful. Attached Figure Description

[0004] Figure 1 A network environment according to some implementation schemes is shown.

[0005] Figure 2 The signaling diagram for the four-step random access (RA) process is shown.

[0006] Figure 3 The signaling diagram of the attack during the four-step RA process is shown.

[0007] Figure 4 The signaling diagram for the two-step RA process is shown.

[0008] Figure 5 The signaling diagram of the attack during the two-step RA process is shown.

[0009] Figure 6A The operational flow / algorithm structure according to some implementation schemes is shown.

[0010] Figure 6B The operational flow / algorithm structure according to some implementation schemes is shown.

[0011] Figure 7A A one-way hash is shown according to some implementation schemes.

[0012] Figure 7B This illustrates a one-way hash with an added current value, based on some implementation schemes.

[0013] Figure 7CA one-way hash with a temporary radio network identifier added is shown according to some implementation schemes.

[0014] Figure 8A The operational flow / algorithm structure according to some implementation schemes is shown.

[0015] Figure 8B The operational flow / algorithm structure according to some implementation schemes is shown.

[0016] Figure 9A The operational flow / algorithm structure according to some implementation schemes is shown.

[0017] Figure 9B The operational flow / algorithm structure according to some implementation schemes is shown.

[0018] Figure 10 Signaling diagrams for asymmetric key technology according to some implementation schemes are shown.

[0019] Figure 11 The operational flow / algorithm structure according to some implementation schemes is shown.

[0020] Figure 12 The operational flow / algorithm structure according to some implementation schemes is shown.

[0021] Figure 13 A signaling diagram of a user equipment identifier-based technology according to some implementation schemes is shown.

[0022] Figure 14A The operational flow / algorithm structure according to some implementation schemes is shown.

[0023] Figure 14B The operational flow / algorithm structure according to some implementation schemes is shown.

[0024] Figure 15A The operational flow / algorithm structure according to some implementation schemes is shown.

[0025] Figure 15B The operational flow / algorithm structure according to some implementation schemes is shown.

[0026] Figure 16 User equipment according to some implementation schemes is shown.

[0027] Figure 17 A base station according to some implementation schemes is shown. Detailed Implementation

[0028] The following detailed description relates to the accompanying drawings. The same reference numerals may be used in different drawings to identify the same or similar elements. In the following description, specific details, such as particular structures, architectures, interfaces, technologies, etc., are set forth for illustrative and non-limiting purposes to provide a thorough understanding of various aspects of the various embodiments. However, it will be apparent to those skilled in the art that various aspects of the various embodiments may be practiced in other examples departing from these specific details. In some cases, descriptions of well-known apparatus, circuits, and methods have been omitted so as not to obscure the description of the various embodiments with unnecessary detail. For the purposes of this document, the phrase "A or B" refers to (A), (B), or (A and B).

[0029] The following is a glossary of terms that may be used in this disclosure.

[0030] As used herein, the term "circuit" refers to, is part of, or includes the following: hardware components such as electronic circuits, logic circuits, processors (shared, dedicated, or grouped) or memories (shared, dedicated, or grouped), application-specific integrated circuits (ASICs), field-programmable devices (FPDs) (e.g., field-programmable gate arrays (FPGAs), programmable logic devices (PLDs), complex PLDs (CPLDs), high-capacity PLDs (HCPLDs), structured ASICs, or programmable system-on-chips (SoCs)), digital signal processors (DSPs), etc. In some embodiments, a circuit may execute one or more software or firmware programs to provide at least some of the said functions. The term "circuit" may also refer to a combination of one or more hardware elements and program code for performing the functions (or a combination of circuits used in an electrical or electronic system). In these embodiments, the combination of hardware elements and program code may be referred to as a particular type of circuit.

[0031] As used herein, the term "processor circuit" means, is part of, or includes the following: a circuit capable of sequentially and automatically performing a series of arithmetic or logical operations or recording, storing, or transmitting digital data. The term "processor circuit" may also refer to an application processor, baseband processor, central processing unit (CPU), graphics processing unit, single-core processor, dual-core processor, triple-core processor, quad-core processor, or any other apparatus capable of executing or otherwise operating computer-executable instructions (such as program code, software modules, and / or functional procedures).

[0032] As used herein, the term "interface circuit" refers to, is part of, or includes a circuit that enables the exchange of information between two or more components or devices. The term "interface circuit" can refer to one or more hardware interfaces, such as buses, I / O interfaces, peripheral component interfaces, network interface cards, etc.

[0033] As used herein, the term "user equipment" or "UE" refers to equipment of a remote user that has radio communication capabilities and can describe network resources in a communication network. Furthermore, the term "user equipment" or "UE" can be considered synonymous and can be referred to as a client, mobile phone, mobile device, mobile terminal, user terminal, mobile unit, mobile station, mobile user, subscriber, user, remote station, access agent, user agent, receiver, radio equipment, reconfigurable radio equipment, reconfigurable mobile equipment, etc. Additionally, the term "user equipment" or "UE" can include any type of wireless / wired equipment or any computing equipment that includes a wireless communication interface.

[0034] As used herein, the term "computer system" means any type of interconnected electronic equipment, computer equipment, or components thereof. Additionally, the term "computer system" or "system" may refer to the various components of a computer that are communicatively coupled to each other. Furthermore, the term "computer system" or "system" may refer to multiple computer equipment or multiple computing systems that are communicatively coupled to each other and configured to share computing resources or network resources.

[0035] As used herein, the term "resource" refers to physical or virtual equipment, physical or virtual components within a computing environment, or physical or virtual components within a particular piece of equipment, such as computer equipment, mechanical equipment, memory space, processor / CPU time, processor / CPU utilization, processor and accelerator load, hardware time or utilization, power supply, input / output operations, port or network sockets, channel / link allocation, throughput, memory utilization, storage, network, databases and applications, units of workload, etc. "Hardware resource" can refer to computing, storage, or networking resources provided by physical hardware components. "Virtualized resource" can refer to computing, storage, or networking resources provided by virtualization infrastructure to applications, equipment, systems, etc. The terms "network resource" or "communication resource" can refer to resources that computer equipment / systems can access via a communication network. The term "system resource" can refer to any kind of shared entity providing services and can include computing or network resources. System resources can be considered as a coherent set of functions, network data objects, or services accessible through a server, wherein such system resources reside on a single host or multiple hosts and are clearly identifiable.

[0036] As used herein, the term "channel" refers to any tangible or intangible transmission medium used to transmit data or data streams. The term "channel" may be synonymous or equivalent with "communication channel," "data communication channel," "transmission channel," "data transmission channel," "access channel," "data access channel," "link," "data link," "carrier," "radio frequency carrier," or any other similar term indicating a path or medium through which data is transmitted. Additionally, as used herein, the term "link" refers to a connection between two pieces of equipment used for transmitting and receiving information.

[0037] As used in this article, the terms "instantiate" and "instantiate" refer to the creation of an instance. "Instance" also refers to the concrete occurrence of an object, which may occur, for example, during the execution of program code.

[0038] The term "connection" can mean that two or more elements at a common communication protocol layer have an established signaling relationship with each other through a communication channel, link, interface, or reference point.

[0039] As used herein, the term "network element" refers to physical or virtualized equipment or infrastructure used to provide wired or wireless communication network services. The term "network element" may be considered synonymous with or referred to as networked computers, network hardware, network devices, network nodes, virtualized network functions, etc.

[0040] The term "information element" refers to a structural element that contains one or more fields. The term "field" refers to the individual content of an information element, or the data element that contains that content. An information element may include one or more additional information elements.

[0041] This paper describes techniques for preventing piracy broadcast attacks during two-step and four-step random access (RA) processes. Figure 1 A network environment 100 according to some embodiments is illustrated. Network environment 100 may include user equipment (UE) 102, 104, 106 and access node 108. Access node 108 may be a base station providing one or more radio access cells (e.g., 3GPP New Radio (NR) cells), through which one or more of UE 102 / 104 / 106 can communicate with access node 108 (e.g., via an NR-Uu interface). In some aspects, access node 108 is a next-generation node B (gNB) providing one or more 3GPP NR cells.

[0042] Access node 108 can transmit information (e.g., data and control signaling) in the downlink direction by mapping logical channels onto transport channels and transport channels onto physical channels. Logical channels can transmit data between the Radio Link Control (RLC) layer and the Media Access Control (MAC) layer; transport channels can transmit data between the MAC and PHY layers; and physical channels can transmit information across the air interface. Physical channels may include the Physical Broadcast Channel (PBCH); the Physical Downlink Shared Channel (PDSCH); and the Physical Downlink Control Channel (PDCCH).

[0043] The PBCH can be used to broadcast system information that UE 102 / 104 / 106 can use for initial access to the serving cell. The PBCH can be transmitted together with the Physical Synchronization Signal (PSS) and the Secondary Synchronization Signal (SSS) in the Synchronization Signal (SS) / PBCH block. During the cell search process and for beam selection, UE 102 / 104 / 106 can use the SS / PBCH block (SSB).

[0044] PDSCH can be used to transmit end-user application data, signaling radio bearer (SRB) messages, system information messages (except for, for example, master information block (MIB)), and paging messages.

[0045] Access node 108 can use PDCCH to transmit downlink control information (DCI) to UEs 102 / 104 / 106. DCI can provide uplink resource allocation on the Physical Uplink Shared Channel (PUSCH), downlink resource allocation on the PDSCH, and various other control information. DCI can also be used to provide uplink power control commands, configure time slot formats, or indicate that preemption has occurred.

[0046] Access node (e.g., base station or gNB) 108 may also transmit various reference signals to UE 102 / 104 / 106. Reference signals (RS) are special signals that exist only at the PHY layer and are not used to deliver any specific information (e.g., data), but their purpose is to provide a reference point for transmit power. Reference signals may include demodulation reference signals (DMRS) for PBCH, PDCCH, and PDSCH. UE 104 may compare the received version of the DMRS with a known sequence of transmitted DMRS to estimate the effects of the propagation channel. UE 102 / 104 / 106 may subsequently apply the inversion of the propagation channel during the demodulation process of the corresponding physical channel transmission.

[0047] Reference signals may also include Channel State Information Reference Signals (CSI-RS). CSI-RS can be a multi-purpose downlink transmission that can be used for CSI reporting, beam management, connection mode mobility, radio link failure detection, beam failure detection and recovery, and fine-tuning of time and frequency synchronization. For example, UEs 102 / 104 / 106 can measure the SSB and CSI-RS to determine the desired downlink beam pairs for transmit / receive PDCCH and Physical Downlink Shared Channel (PDSCH) transmissions. The UE can use the Physical Uplink Control Channel (PUCCH) to transmit uplink control information (UCI) to access node 108, including, for example, Hybrid Automatic Repeat Request (HARQ) acknowledgments, scheduling requests, and periodic and semi-persistent Channel State Information (CSI) reports.

[0048] In NR, the Random Access (RA) procedure is the initial step for a UE to establish a connection to the cell service. During this RA procedure, the UE and the network have not yet authenticated each other. Figure 2 The signaling diagram for a four-step RA procedure between UE 102 and gNB 108 (as described, for example, in Section 9.2.6 of 3GPP Technical Specification (TS) 38.300 v16.5.0 (2021-04)) is shown. UE 102 transmits a random access preamble (Msg1) (e.g., on the Physical Random Access Channel (PRACH). In response to receiving such a random access preamble, gNB 108 transmits either Msg2 or a random access response (RAR) (e.g., on the Physical Downlink Shared Channel (PDSCH)). The downlink resources used for the RAR can be indicated in a first downlink control message (DCI), which gNB 108 can transmit on the Physical Downlink Control Channel (PDCCH). The first DCI may include cyclic redundancy check (CRC) bits scrambled by a random access (RA) radio network temporary identifier (RNTI) (RA-RNTI), where the RA-RNTI is based on the timing of the random access preamble and is therefore known to both UE 102 and gNB 108. The RAR may include uplink grants for transmission on the Physical Uplink Shared Channel (PUSCH) and Temporary Cell RNTI (TC-RNTI), and may also include timing advance commands.

[0049] In response to the RAR, UE 102 sends a message (Msg3) that may include a contention resolution identifier. For example, UE 102 may send Msg3 on the PUSCH and in accordance with uplink grant. In response to receiving such a Msg3, gNB 108 sends a message (Msg4) (e.g., on the PDSCH). The downlink resources used for the RAR may be indicated by a second DCI, which gNB 108 may send on the PDCCH. The second DCI may include CRC bits that can be scrambled by the TC-RNTI included in the RAR.

[0050] Multiple UEs can choose the same preamble (in Msg1) and simultaneously respond to a single downlink RA response (Msg2 or RAR) by sending concurrent RRC connection requests (e.g., in Msg3). Each RRC connection request includes a 40-bit UE identifier for the corresponding UE (e.g., a random value or an S-Temporary Mobile Subscriber Identity (S-TMSI)). Only one of these requests will ultimately be accepted by the network, and this request will be signaled back by responding to the accepted 40-bit UE identifier (e.g., in Msg4). If the received contention-resolved identifier matches the transmitted identifier, the UE declares contention resolved, and the RA procedure is successful.

[0051] The above four-step RA process may be vulnerable to security threats from piracy attacks.

[0052] Figure 3The signaling diagram illustrates an example of such an attack in a four-step RA process, where gNB 108 unknowingly acts as a relay for a covert channel between UE 104 and UE 106 without authorization or authentication. Malicious UE 104 sends a (not random) forty-bit message (e.g., as its contention resolution ID) to gNB 108, which then rebroadcasts the message to all UEs within the cell coverage area (e.g., within Msg4). UE 104's partners (e.g., UE 106) can passively scan downlink signals within the coverage area, thereby receiving the rebroadcast message without being tracked. This type of "piracy broadcast attack" can constitute illicit communication by unauthorized exploitation of resources of commercial wireless infrastructure. The Global System for Mobile Communications Association (GSMA) has issued a liaison letter (LS) R2-2106454 entitled “Stealth Pirating Attack by RACHRebroadcast Overwriting (SPARROW)” (Fraud and Security Group (FSAG) Doc. 93_009) to the 3GPP Technical Specification Group (TSG) Services and Systems Working Group (SA3) 3 and Technical Specification Group Radio Access Network (RAN) WG2 (RAN2) (submitted to 3GPP TSG RAN WG2#114-e e-meeting, May 19-27, 2021), requesting consideration and possible mitigation of this risk.

[0053] 5G networks can support a two-step RA process (as described, for example, in Section 9.2.6 of 3GPP TS 38.300 v16.5.0 (2021-04)), and Figure 4 The signaling diagram for this two-step RA procedure between UE 102 and gNB 108 is shown. UE 102 transmits MsgA, which includes 1) a random access preamble (Msg1) (e.g., on PRACH) and 2) a message (Msg3) (e.g., on PUSCH), where Msg3 includes a contention resolution identifier. For example, Msg3 may include a Common Control Channel (CCCH) Service Data Unit (SDU) containing a contention resolution identifier.

[0054] In response to receiving such a MsgA, gNB 108 transmits MsgB (e.g., on the Physical Downlink Shared Channel (PDSCH)). MsgB may include a Random Access Response (RAR) and a contention resolution identifier for MsgA. The RAR in a two-step RA process may differ from the RAR in the four-step process described above (e.g., the RAR in a two-step RA process may lack a TC-RNTI). The downlink resources used for MsgB may be indicated by a DCI, which gNB 108 may transmit on the Physical Downlink Control Channel (PDCCH). The DCI may include CRC bits that can be scrambled by the msgB RNTI (msgB-RNTI), where the msgB-RNTI is based on the timing of the random access preamble and is therefore known to both UE 102 and gNB 108.

[0055] The two-step RA process may have similar security issues as described above, such as... Figure 5 As shown. In the two-step RA process, if the CCCH SDU (msg3) is included in MsgA, contention resolution can be based on the contention resolution ID included in MsgB. In this case, the contention resolution ID can be the first forty-eight bits of the uplink CCCH SDU. Partner UE 106 may need to know the msgB-RNTI and wait for the window msgB_responseTime as configured in System Information Block 1 (SIB1). Partner UE 106 uses the msgB-RNTI to monitor the PDCCH to identify the DCI that allocates downlink resources for MsgB, and to obtain the contents of MsgB and retrieve the 48-bit contention resolution ID, which can be a secret message transmitted by UE 104.

[0056] The attack described above could be effective against UE 106 located within the target area of ​​Msg4 (or MsgB in a 2-step RA). To mitigate such attacks, gNB 108 could transmit Msg4 with limited transmit power and / or in limited transmit beam directions based on information and measurements from msg3. For 4G LTE and 5G sub-6GHz bands, it is assumed that the eNB / gNB uses omnidirectional antennas. Therefore, a large coverage area of ​​the gNB is expected, allowing relays performed by the eNB / gNB to reach potentially many malicious UEs 106. For the source malicious UE 104 located near the cell edge, the msg4 transmission via gNB 108 can cover the entire cell since the gNB intends to reach UE 104. For 5G directional beam transmission, the retransmission area can be significantly reduced. However, for non-terrestrial network (NTN) communications, even narrow beams can cover vast areas of the Earth's surface (e.g., points with diameters of 10 km to 100 km).

[0057] Certain limitations on such piracy broadcast attacks can be derived. For example, performing such an attack might require modifying the modem of a malicious UE 104, 106 (e.g., in software and / or firmware). Depending on the specific implementation of gNB 106, the amount of information transmitted in each such attack could have a maximum limit of forty-eight bits (or thirty-nine or forty bits). In the worst case, for example, gNB 108 could be implemented as blindly replaying the first forty-eight bits of the UL CCCH MAC PDU received in Msg3 (e.g., typically including an eight-bit setup reason + a spare bit + a thirty-nine-bit random string).

[0058] The detectability of the attack may increase with use: while a single message transmission (i.e., limited to forty bits) may be undetectable, if the attacking UE 104 attempts to use more covert channel bandwidth, it may leave detectable Media Access Control (MAC) layer traffic patterns. However, if the attack is initiated by a large number of fraudulent UEs, the detectability of the traffic patterns may be indeterminate. Information disclosed in the existing RA process cannot be used to identify the attacker because the attacking UE 104 will not include a genuine 5G-S-TMSI in Msg3. The attacking UE 104 can also function as normal equipment in subsequent access processes, thus there is no genuine "abnormal behavior" that network operators need to detect.

[0059] Due to the competition for access with legitimate UEs in Contention-Based Random Access (CBRA), there is a risk that UE performance may be degraded due to such attacks. At a minimum, the wasted processing of msg1 / msg3 from malicious UEs and the transmission of corresponding msg2 and msg4 by the gNB 108 could represent lost revenue for the operator, and in any case, such attacks could constitute unauthorized use of licensed radio resources. Due to the poor scalability of the attack, the overall risk level can be considered low to moderate.

[0060] Techniques that can be implemented to mitigate such attacks have been proposed. Figure 6A An operational flow / algorithm structure 600 according to some implementation schemes is shown. The operational flow / algorithm structure 600 may be executed or implemented by a base station such as, for example, base station 108 or 2200 or its components such as baseband processor 1704A.

[0061] The operation flow / algorithm structure 600 may include receiving a first message including a contention resolution identifier at 604. For example, the first message may be msg3 or msgA as described herein.

[0062] The operation process / algorithm structure 600 may include generating a code value based on the race resolution identifier at 608.

[0063] The operation flow / algorithm structure 600 may include sending a second message, including a code value, at 612. For example, the second message may be msg4 or msgB as described herein.

[0064] Figure 6B An operational flow / algorithm structure 640 according to some implementation schemes is shown. The operational flow / algorithm structure 640 may be executed or implemented by a UE such as, for example, UE 102 or UE 1600 or its components such as baseband processor 1604A.

[0065] The operation flow / algorithm structure 640 may include sending a first message including a race-resolved identifier at 644. For example, the first message may be msg3 or msgA as described herein.

[0066] The operation flow / algorithm structure 640 may include receiving a second message, including a first code value, at 648. For example, the second message may be msg4 or msgB as described herein.

[0067] The operation process / algorithm structure 640 may include generating a second code value based on the race-resolved identifier at 652.

[0068] The operation process / algorithm structure 640 may include comparing the first code value with the second code value at 656.

[0069] In one example, a hash function is used to generate a code value at 608 (and correspondingly, a second code value at 652). Instead of simply replaying the forty-bit "random" number sent by the malicious UE 104, gNB 108 performs a one-way hash on the input (X) of Msg3 (e.g., as...). Figure 7A (As shown) and include the hash output h(X) in Msg4. In one example (non-restrictive), the hash function is a specific implementation of Secure Hash Algorithm 2 (SHA-2), such as, for example, SHA-256. Partner UE 106 is no longer able to receive the 40-bit secret message transmitted by malicious UE 104 because it cannot reverse the one-way hash, while UE 102 easily generates the hash output because it knows the race-resolved identifier it sent. Mathematically, a hash collision may occur, but the probability is extremely low because the number of UEs that might send the same random access preamble in Msg1 is limited.

[0070] Even in cases where malicious UEs 104 and 106 attempt to pre-calculate the relationship between X and h(X), the number of bits that can be secretly transmitted can be significantly reduced. For example, if UE 104 prepares M different "X→h(X)" in its dictionary, the information entropy decreases to log2(M) in each attack, which can significantly reduce the efficiency of the attack.

[0071] The method, which includes generating a code value at position 608 (and a second code value at position 652) using a hash function, can be enhanced by allowing gNB 108 to add additional input to the one-way hash function. For example... Figure 7B As shown, for example, a random current value (e.g., a 16-bit or 32-bit random value) can be added as input to the hash function: hash(X, current) = h(X). In this method, gNB 108 includes the current value in Msg4, such that a non-malicious UE 102 can still match h(X) with X (e.g., a contention resolution identifier) ​​by adding the current value as input to the hash function.

[0072] This enhancement increases the computational cost for a malicious UE 106 to participate in the attack. Malicious UEs 104 and 106 are no longer able to prepare the X→h(X) dictionary and perform simple lookups. Instead, UE 106 must utilize the instantaneous current value to compute the hash of all M hypotheses. To implement this enhancement, a new information element for the current value can be included in Msg4. To avoid the need for such modifications, the Random Access (RA) Radio Network Temporary Identifier (RNTI) (RA-RNTI) can be used instead of the current value as an additional input to the hash function (e.g., as shown in the image). Figure 7C (As shown). Because RA-RNTI is based on the timing of the random access preamble (e.g., the PRACH timing in which the preamble is transmitted), it is known to both gNB 108 and UE 102 before Msg3 is transmitted. However, this method may be less efficient than using the current value because RA-RNTI may be known in advance by UE 106 as a result of coordination between malicious UEs 104 and 106 (e.g., preamble transmission by UE 104 during the PRACH timing known to UE 106).

[0073] The second method involves transforming the content of Msg4 by scrambling it with an RNTI. In one such example, the network (e.g., gNB 108) uses a RA-RNTI to scramble the Msg3 content (e.g., contention resolution identifier) ​​in Msg4. Note that the RA-RNTI has already been used by the network to scramble the PDCCH in Msg2 (e.g., scrambling the CRC bits of the DCI indicating downlink resource allocation for Msg2). For malicious UEs 104 and 106 launching the attack, UE 106 needs to know the timing of the Msg1 transmission (i.e., the preamble) used to determine the RA-RNTI. The non-malicious UE 102 will know precisely when it transmits the preamble in time and will be unaffected by this method, as it can easily use the same RA-RNTI to descramble the Msg3 content (e.g., contention resolution identifier) ​​in Msg4.

[0074] For the hash function modification including RA-RNTI as described above, malicious UEs 104 and 106 can pre-negotiate to bypass this method: in this case, by synchronizing their timing during the attack, the RA-RNTI becomes known to UE 106. Furthermore, the RA-RNTI value is restricted to a short time period, depending on the PRACH configuration, allowing malicious UE 106 to perform a brute-force descrambling attack on Msg4 by trying a limited list of RA-RNTI candidates.

[0075] In another example of this second method, gNB 108 uses the Temporary Cell RNTI (TC-RNTI) included in Msg2 (e.g., RAR in a four-step RA procedure) to scramble the content of Msg3 in Msg4 (e.g., contention resolution identifier). In this case, although a malicious UE 106 can know the TC-RNTI when receiving Msg2, its value cannot be predetermined like the RA-RNTI. Similarly, a non-malicious UE 102 can easily use the same TC-RNTI included in Msg2 to descramble the content of Msg3 in Msg4 (e.g., contention resolution identifier).

[0076] Figure 8A A specific implementation 800 of the operation flow / algorithm structure 600 according to some implementation schemes is shown. The operation flow / algorithm structure 800 may be executed or implemented by a base station such as, for example, base station 108 or 1700 or its components such as baseband processor 1704A.

[0077] The operation flow / algorithm structure 800 may include instances 804 and 812 of 604 and 612, respectively, as described herein. The operation flow / algorithm structure 800 may also include generating a code value based on a contention-resolved identifier using a hash function at a specific implementation 810 of 608. In another example, the second message may include a current value, and the code value may be generated based on the contention-resolved identifier and the current value. Alternatively, the code value may be generated based on the contention-resolved identifier and at least a RA-RNTI based on the timing of the random access preamble.

[0078] Figure 8B A specific implementation 840 of the operation flow / algorithm structure 640 according to some implementation schemes is shown. The operation flow / algorithm structure 840 may be executed or implemented by a UE such as, for example, UE 102 or UE 1600 or its components such as baseband processor 1604A.

[0079] Operational flow / algorithm structure 840 may include instances 844, 848, and 856 of 644, 648, and 656, respectively, as described herein. Operational flow / algorithm structure 840 may also include, at a specific implementation 854 of 652, using a hash function to generate a second code value based on a contention-resolved identifier. In another example, the second message may include a current value, and the second code value may be generated based on the contention-resolved identifier and the current value. Alternatively, the second code value may be generated based on the contention-resolved identifier and at least a RA-RNTI based on the timing of the random access preamble.

[0080] Figure 9A A specific implementation 900 of the operation flow / algorithm structure 600 according to some implementation schemes is shown. The operation flow / algorithm structure 900 may be executed or implemented by a base station such as, for example, base station 108 or 1700 or its components such as baseband processor 1704A.

[0081] The operation flow / algorithm structure 900 may include instances 904 and 912 of 604 and 612, respectively, as described herein. The operation flow / algorithm structure 900 may also include, at a specific implementation 910 of 608, the use of a scrambling function to generate code values ​​based on a contention resolution identifier. For example, code values ​​may be generated based on a contention resolution identifier and at least a timing-based RA-RNTI of a random access preamble (e.g., by scrambling the contention resolution identifier using RA-RNTI). Alternatively, code values ​​may be generated based on a contention resolution identifier and a TC-RNTI (e.g., by scrambling the contention resolution identifier using TC-RNTI).

[0082] Figure 9B An operational flow / algorithm structure 940 according to some implementation schemes is shown. The operational flow / algorithm structure 940 may be executed or implemented by a UE such as, for example, UE 104 or UE 1600 or its components such as baseband processor 1604A.

[0083] The operation flow / algorithm structure 940 may include instances 944 and 948 of 644 and 648, respectively, as described herein. The operation flow / algorithm structure 940 may also include descrambling the first code value at 954 to obtain the second code value. For example, the first code value may be descrambled based on a RA-RNTI based at least on the timing of the random access preamble. Alternatively, the first code value may be descrambled based on a TC-RNTI (which may be received, for example, in the random access response).

[0084] like Figure 9B As shown, the operation flow / algorithm structure 940 may also include comparing the second code value with the race resolution identifier at 958.

[0085] In the third approach, asymmetric key technology is used to protect Msg3 and Msg4 during the four-step RA process. Signatures are being considered for CCCH protection, primarily to attempt to authenticate messages from the base station to the UE for fake base station detection. However, for UE piracy attacks as described in this paper, a solution is desired that ensures messages from the UE to the gNB can be authenticated by the gNB.

[0086] This technology assumes that UE 102 has its own public / private key pair (KUE_private, KUE_public) and gNB 108 also has its own public / private key pair (KgNB_private, KgNB_public). Figure 10 The signaling diagram for this solution is shown in the following four-step RA process: 1) The public key of gNB 108 can be broadcast (e.g., in a System Information Block (SIB)) or it can be included in Msg2. 2) After obtaining the key KgNB_public, UE 102 performs an ECDH (Elliptic Curve Diffie-Hellman) algorithm to generate a shared session key Ksess, which is based on the keys KUE_public and KgNB_public. 3) UE 102 creates a signature with Ksess and includes both the signature and the key KUE_public in Msg3. 4) gNB 108 obtains the key KUE_public from Msg3, performs ECDH to generate the shared session key Ksess, and then uses the key Ksess to verify the signature. If the signature is verified, gNB 108 sends msg4 protected with Ksess.

[0087] It is worth noting that, using, for example Figure 10 The described technique eliminates the need for the gNB 108 to repeat the content presented in Msg3 within Msg4, thus preventing piracy attacks. A normal UE 102 will be able to decrypt Msg4 using Ksess. For another UE sending the same RA preamble in Msg1 and also sending Msg3 containing its public key, Msg4 from the gNB 108 will not be decrypted by that other UE because the gNB does not select its KUE_public to generate the session key.

[0088] like Figure 10 The technique described avoids the gNB 108 rebroadcasting the UE identifier in Msg4. The public key overhead may be relatively large (e.g., 512 bits or 1024 bits, but shorter key lengths are also possible).

[0089] Figure 11An operational flow / algorithm structure 1100 according to some implementation schemes is shown. The operational flow / algorithm structure 1100 may be executed or implemented by a base station such as, for example, base station 108 or 1700 or its components such as baseband processor 1704A.

[0090] The operation flow / algorithm structure 1100 may include receiving a first message at 1104, which includes the user equipment public key and a signature. For example, the first message may be msg3 as described herein.

[0091] The operation process / algorithm structure 1100 may include generating a session key at 1108, wherein the session key is based on the user equipment public key and a second public key (e.g., the base station's public key).

[0092] The operation process / algorithm structure 1100 may include using the generated session key at 1112 to determine whether the signature is valid.

[0093] The operation flow / algorithm structure 1100 may include sending a second message at 1116, wherein the second message is based on the generated session key and signature. For example, the second message may be msg4 as described herein.

[0094] Figure 12 An operational flow / algorithm structure 1200 according to some implementation schemes is shown. The operational flow / algorithm structure 1200 may be executed or implemented by a UE such as, for example, UE 102 or UE 1600 or its components such as baseband processor 1604A.

[0095] The operation procedure / algorithm structure 1200 may include sending a random access preamble at 1204. For example, sending the random access preamble may be performed on PRACH.

[0096] The operational procedure / algorithm structure 1200 may include receiving a random access response (RAR) at 1208. For example, the random access response may be received on the PDSCH.

[0097] The operation procedure / algorithm structure 1200 may include generating a session key at 1212, where the session key is based on the user equipment public key and the network public key (e.g., the base station's public key). For example, the network public key may be received in the RAR or in the SIB. For example, the session key may be created by performing the ECDH algorithm.

[0098] The operation flow / algorithm structure 1200 may include creating a signature based on the generated session key at 1216. The signature may also be based on, for example, a contention resolution identifier.

[0099] The operation flow / algorithm structure 1200 may include sending a first message at 1220, which includes the user equipment public key and the generated signature. For example, the first message may be msg3 as described herein.

[0100] The techniques described above include sending encoded (e.g., hashed or scrambled) values ​​in Msg4 (in a four-step RA process) or MsgB (in a two-step RA process). Public key-based techniques are also described, which can be computationally intensive and add overhead to all UEs performing the RA process.

[0101] Another technique is described that imposes additional requirements in Msg3 (during a four-step RA process) or MsgA (during a two-step RA process) such that 1) attacks from malicious UE 104 can be detected in real time, and rebroadcasts from Msg4 (or MsgB) can be prevented; or 2) attacks from malicious UE 104 are not detected in real time, but UE 104 provides signatures that can be logged, for example, to support future checks to detect whether an attack has occurred. The network can later check the UE ID to ensure that the Non-Access Stratum (NAS) process matches the UE identifier that is being protected in the Msg3 (MsgA) signature.

[0102] Figure 13The signaling diagram used for this method in a four-step RA process is shown. Before the RA process begins, UE 102 and the network share a “long-term identifier” (e.g., a “long-term key”) that identifies UE 102. UE 102 uses the long-term identifier and RNTI (e.g., RA_RNTI or TC-RNTI) to generate a hash signature (e.g., using the hash function described above), and sends the hash signature (e.g., as a contention resolution identifier) ​​in Msg3 (or in MsgA in a two-step RA process). The hash signature may have a length of, for example, forty bits. On the network side, gNB 108 and / or core network (CN) functions (e.g., Access and Mobility Management Functions (AMF)) can verify the signature and determine whether the Msg3 (MsgA) is valid if the processing delay for such verification is feasible. If Msg3 (MsgA) is determined to be invalid, gNB 108 may choose to ignore Msg3 (MsgA) and record it for future inspection. If such processing delays are not feasible, gNB 108 may transmit Msg4 (or MsgB in a two-step RA process) anyway, but record the signature for future verification. In the latter case, the attack may not be prevented because a malicious UE 104 could ignore the rules or impersonate someone else, but the recording at least makes the attack detectable. For example, a failure of a UE to present a valid signature with a valid long-term identifier or long-term key (in Msg3) can be recorded, and the detection of such a failure may also trigger other actions (e.g., referral to law enforcement).

[0103] In another example of this method, the signature can be a separate information element in Msg3 (MsgA) (e.g., in addition to a 40-bit RNTI or a 40-bit random number (e.g., a race-to-solve identifier)). In this case, the signature is not rebroadcast in Msg4 (MsgB).

[0104] Figure 14A An operational flow / algorithm structure 1400 according to some implementation schemes is shown. The operational flow / algorithm structure 1400 may be executed or implemented by a base station such as, for example, base station 108 or 1700 or its components such as baseband processor 1704A.

[0105] The operation flow / algorithm structure 1400 may include receiving a first message including a signature at 1412. For example, the first message may be msg3 as described herein (e.g., in a four-step RA process) or msgA (e.g., in a two-step RA process).

[0106] Operational flow / algorithm structure 1400 may include verifying the signature at 1416 using the UE identifier and Radio Network Temporary Identifier (RNTI). Such verification may include, for example (e.g., using a hash function), generating a code value based on the UE identifier and RNTI and comparing that code value with the received signature. The RNTI may be, for example, an RA-RNTI (e.g., based on the timing of the random access preamble). In a four-step RA process, the RNTI may be a TC-RNTI (which may be included in the RAR).

[0107] Figure 14B A specific implementation 1440 of the operation flow / algorithm structure 1400 according to some implementation schemes is shown. The operation flow / algorithm structure 1440 may be executed or implemented by a base station such as, for example, base station 108 or 1700 or its components such as baseband processor 1704A.

[0108] The operation procedure / algorithm structure 1440 may also include receiving a random access preamble at 1404. For example, the random access preamble may be received on PRACH.

[0109] The operation procedure / algorithm structure 1440 may also include sending a random access response (RAR) at 1408. For example, sending a random access response can be performed on the PDSCH.

[0110] Figure 15A An operational flow / algorithm structure 1500 according to some implementation schemes is shown. The operational flow / algorithm structure 1500 may be executed or implemented by a UE such as, for example, UE 102 or UE 1600 or its components such as baseband processor 1604A.

[0111] The operation flow / algorithm structure 1500 may include generating a signature at 1512, where the signature is based on the user equipment identifier and the RNTI. Signature generation may be performed, for example, using a hash function. The RNTI may be, for example, an RA-RNTI (e.g., based on timing of the random access preamble). In a four-step RA process, the RNTI may be a TC-RNTI (which may be included in the RAR).

[0112] The operation flow / algorithm structure 1500 may include sending a first message including the generated signature at 1516. For example, the first message may be msg3 as described herein (e.g., in a four-step RA process) or msgA (e.g., in a two-step RA process).

[0113] Figure 15B An operational flow / algorithm structure 1500 according to some implementation schemes is shown. The operational flow / algorithm structure 1500 may be executed or implemented by a UE such as, for example, UE 102 or UE 1600 or its components such as baseband processor 1604A.

[0114] The operation procedure / algorithm structure 1500 may include sending a random access preamble at 1504. For example, sending the random access preamble may be performed on PRACH.

[0115] The operational procedure / algorithm structure 1500 may include receiving a random access response (RAR) at 1508. For example, the random access response may be received on the PDSCH.

[0116] Figure 16 A UE 1600 according to some implementation schemes is shown. UE 1600 may be similar to Figure 1 The UE 102 is essentially interchangeable with it.

[0117] The UE 1600 can be any mobile or non-mobile computing device, such as mobile phones, computers, tablets, industrial wireless sensors (e.g., microphones, carbon dioxide sensors, pressure sensors, humidity sensors, thermometers, motion sensors, accelerometers, laser scanners, fluid level sensors, inventory sensors, voltmeters / ammeters, actuators, etc.), video surveillance / monitoring equipment (e.g., cameras, camcorders, etc.), wearable devices (e.g., smartwatches), and loosely coupled IoT devices.

[0118] UE 1600 may include a processor 1604, RF interface circuitry 1608, memory / storage device 1612, user interface 1616, sensor 1620, drive circuitry 1622, power management integrated circuit (PMIC) 1624, antenna structure 1626, and battery 1628. Components of UE 1600 may be implemented as integrated circuits (ICs), portions of integrated circuits, discrete electronic devices or other modules, logic components, hardware, software, firmware, or combinations thereof. Figure 16 The block diagram is intended to show a high-level view of some of the components of the UE 1600. However, some of the components shown may be omitted, additional components may be present, and different arrangements of the components shown may occur in other specific implementations.

[0119] Components of UE 1600 can be coupled to various other components via one or more interconnects 1632, which can represent any type of interface, input / output, bus (local, system, or extended), transmission line, trace, optical connector, etc., that allows various circuit components (on common or different chips or chipsets) to interact with each other.

[0120] Processor 1604 may include processor circuitry, such as, for example, baseband processor circuitry (BB) 1604A, central processing unit circuitry (CPU) 1604B, and graphics processing unit circuitry (GPU) 1604C. Processor 1604 may include any type of circuitry or processor circuitry that executes or otherwise operates computer-executable instructions, such as program code, software modules, or functional processes from memory / storage device 1612, to cause UE 1600 to perform the operations described herein.

[0121] In some implementations, the baseband processor circuit 1604A can access the communication protocol stack 1636 in the memory / storage device 1612 to communicate over a 3GPP-compliant network. Generally, the baseband processor circuit 1604A can access the communication protocol stack to perform the following operations: user plane functions at the PHY, MAC, RLC, PDCP, SDAP, and PDU layers; and control plane functions at the PHY, MAC, RLC, PDCP, RRC, and non-access layers. In some implementations, PHY layer operations may additionally / optionally be performed by components of the RF interface circuit 1608.

[0122] The baseband processor circuit 1604A can generate or process baseband signals or waveforms carrying information in a 3GPP-compliant network. In some implementations, the waveforms used for NR can be based on cyclic prefix OFDM (“CP-OFDM”) in the uplink or downlink, and Discrete Fourier Transform Extended OFDM (“DFT-S-OFDM”) in the uplink.

[0123] Memory / storage device 1612 may include one or more non-transitory computer-readable media, including instructions (e.g., communication protocol stack 1636) that can be executed by one or more processors in processor 1604 to cause UE 1600 to perform the various operations described herein. Memory / storage device 1612 includes any type of volatile or non-volatile memory that can be distributed throughout UE 1600. In some embodiments, some memory / storage devices in memory / storage device 1612 may be located on processor 1604 itself (e.g., L1 cache and L2 cache), while other memory / storage devices 1612 may be located external to processor 1604 but accessible via a memory interface. Memory / storage device 1612 may include any suitable volatile or non-volatile memory, such as, but not limited to, dynamic random access memory (DRAM), static random access memory (SRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, solid-state memory, or any other type of memory equipment technology.

[0124] The RF interface circuitry 1608 may include transceiver circuitry and a radio frequency front-end module (RFEM), which allows the UE 1600 to communicate with other equipment via a radio access network. The RF interface circuitry 1608 may include various components arranged in the transmit or receive path. These components may include, for example, switches, mixers, amplifiers, filters, synthesizer circuitry, control circuitry, etc.

[0125] In the receiving path, the RFEM can receive the radiated signal from the air interface via antenna structure 1626 and continue to filter and amplify the signal (using a low-noise amplifier). This signal can be provided to the receiver of the transceiver, which downconverts the RF signal into a baseband signal that is provided to the baseband processor of processor 1604.

[0126] In the transmission path, the transceiver's transmitter upconverts the baseband signal received from the baseband processor and provides the RF signal to the RFEM. The RFEM amplifies the RF signal using a power amplifier before it is radiated across the air interface via antenna 1626.

[0127] In various implementations, the RF interface circuit 1608 can be configured to transmit / receive signals in a manner compatible with NR access technology.

[0128] Antenna 1626 may include antenna elements to convert electrical signals into radio waves for propagation through the air and to convert received radio waves back into electrical signals. These antenna elements may be arranged in one or more antenna panels. Antenna 1626 may have omnidirectional, directional, or combinations thereof antenna panels to enable beamforming and multiple-input / multiple-output communication. Antenna 1626 may include microstrip antennas, printed antennas fabricated on the surface of one or more printed circuit boards, patch antennas, phased array antennas, etc. Antenna 1626 may have one or more panels designed for a specific frequency band included in FR1 or FR2.

[0129] User interface circuitry 1616 includes various input / output (I / O) devices designed to enable users to interact with UE 1600. User interface circuitry 1616 includes input device circuitry and output device circuitry. Input device circuitry includes any physical or virtual device for accepting input, particularly including one or more physical or virtual buttons (e.g., a reset button), a physical keyboard, a keypad, a mouse, a touchpad, a touchscreen, a microphone, a scanner, a headset, etc. Output device circuitry includes any physical or virtual device for displaying information or otherwise conveying information, such as sensor readings, actuator positions, or other similar information. Output device circuitry may include any number or combination of audio or visual displays, particularly including one or more simple visual outputs / indicators (e.g., binary status indicators such as light-emitting diodes "LEDs") and multi-character visual outputs), or more complex outputs such as display devices or touchscreens (e.g., liquid crystal displays "LCDs", LED displays, quantum dot displays, projectors, etc.), wherein the output of characters, graphics, multimedia objects, etc., is generated or produced by the operation of UE 1600.

[0130] Sensor 1620 may include equipment, modules, or subsystems intended to detect events or changes in their environment and transmit information about the detected events (sensor data) to other equipment, modules, subsystems, etc. Examples of such sensors include, in particular: inertial measurement units including accelerometers, gyroscopes, or magnetometers; microelectromechanical systems (MEMS) or nanoelectromechanical systems (NEMS) including triaxial accelerometers, triaxial gyroscopes, or magnetometers; level sensors; flow sensors; temperature sensors (e.g., thermistors); pressure sensors; barometric pressure sensors; gravimeters; altimeters; image capture equipment (e.g., cameras or lensless aperture sensors); light detection and ranging sensors; proximity sensors (e.g., infrared radiation detectors, etc.); depth sensors; ambient light sensors; ultrasonic transceivers; microphones or other similar audio capture equipment; etc.

[0131] The driving circuitry 1622 may include software and hardware elements for controlling specific devices embedded in, attached to, or otherwise communicatively coupled to the UE 1600. The driving circuitry 1622 may include various drivers that allow other components to interact with or control various input / output (I / O) devices that may exist within or be connected to the UE 1600. For example, the driving circuitry 1622 may include: a display driver for controlling and allowing access to a display device; a touchscreen driver for controlling and allowing access to a touchscreen interface; a sensor driver for acquiring sensor readings of sensor circuitry 1620 and controlling and allowing access to sensor circuitry 1620; a driver for acquiring actuator positions of electromechanical components or controlling and allowing access to electromechanical components; a camera driver for controlling and allowing access to an embedded image capture device; and an audio driver for controlling and allowing access to one or more audio devices.

[0132] The PMIC 1624 manages the power supplied to various components of the UE 1600. Specifically, relative to the processor 1604, the PMIC 1624 controls power selection, voltage scaling, battery charging, or DC-DC conversion.

[0133] In some implementations, the PMIC 1624 may control or otherwise become part of various power-saving mechanisms of the UE 1600, including DRX, as discussed herein.

[0134] Battery 1628 can power UE 1600, but in some examples, UE 1600 may be mounted in a fixed location and may have a power source coupled to the mains. Battery 1628 may be a lithium-ion battery, a metal-air battery such as a zinc-air battery, an aluminum-air battery, a lithium-air battery, etc. In some specific implementations, such as in vehicle-based applications, battery 1628 may be a typical lead-acid automotive battery.

[0135] Figure 17 An access node 1700 (e.g., a gNB) according to some implementations is shown. Access node 1700 may be similar to access node 108 and is substantially interchangeable with it.

[0136] Access node 1700 may include processor 1704, RF interface circuit 1708, core network (CN) interface circuit 1712, memory / storage circuit 1716 and antenna structure 1726.

[0137] The components of access node 1700 can be coupled to various other components via one or more interconnectors 1728.

[0138] The processor 1704, RF interface circuit 1708, memory / storage device circuit 1716 (including communication protocol stack 1710), antenna structure 1726, and interconnector 1728 are similar to those in the reference. Figure 16 Similar named elements are shown and described.

[0139] The CN interface circuit 1712 can provide connectivity to a core network (e.g., a 5GC using a 5G core network (5GC) compatible network interface protocol, such as Carrier Ethernet, or some other suitable protocol). Network connectivity can be provided to / from access node 1700 via fiber optic or wireless backhaul. The CN interface circuit 1712 may include one or more dedicated processors or FPGAs for communicating using one or more of the aforementioned protocols. In some implementations, the CN interface circuit 1712 may include multiple controllers for providing connectivity to other networks using the same or different protocols.

[0140] As is widely recognized, the use of personally identifiable information should comply with privacy policies and practices that are generally accepted to meet or exceed industry or governmental requirements for protecting user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of unintentional or unauthorized access or use, and the nature of authorized use should be clearly explained to users.

[0141] For one or more embodiments, at least one of the components shown in one or more of the foregoing figures may be configured to perform one or more operations, techniques, processes, or methods as described in the Examples section below. For example, the baseband circuitry described above in conjunction with one or more of the foregoing figures may be configured to operate according to one or more of the examples below. Similarly, circuitry associated with the UE, base station, network element, etc., described above in conjunction with one or more of the foregoing figures may be configured to operate according to one or more of the examples shown in the Examples section below.

[0142] Example

[0143] Further exemplary implementations are provided in the following sections.

[0144] Example 1 includes a method for operating a base station, the method comprising: receiving a first message including a contention resolution identifier; generating a code value based on the contention resolution identifier; and sending a second message including the code value.

[0145] Example 2 includes the method according to Example 1 or some other embodiments herein, wherein the method further includes sending a RAR including uplink grant, and wherein receiving the first message includes receiving the first message according to the uplink grant.

[0146] Example 3 includes the method according to Example 1 or some other embodiments herein, wherein the method further includes sending a RAR including a TC-RNTI, and wherein a code value is generated based on a contention resolution identifier and a TC-RNTI.

[0147] Example 4 includes the method according to Example 2 or 3 or some other embodiments herein, wherein sending RAR includes sending RAR on PDSCH.

[0148] Example 5 includes the method according to Example 1 or some other embodiments herein, wherein the method further includes receiving a random access preamble, and wherein a code value is generated based on a contention resolution identifier and a random access radio network temporary identifier (RA-RNTI) based at least on the timing of the random access preamble.

[0149] Example 6 includes the method described according to Example 3 or 5 or some other embodiments herein, wherein generating code values ​​is performed using a scrambling function.

[0150] Example 7 includes the method according to Example 1 or some other embodiments herein, wherein the first message includes a CCCH SDU containing a contention resolution identifier.

[0151] Example 8 includes the method according to Example 1 or some other embodiments herein, wherein the method includes sending downlink control information (DCI) indicating downlink resource allocation for a second message and including cyclic redundancy (CRC) bits, and wherein the CRC bits of the DCI are scrambled by a radio network temporary identifier.

[0152] Example 9 includes the method according to Example 8 or some other embodiments herein, wherein the method further includes receiving a random access preamble, and the RNTI is based at least on the timing of the random access preamble.

[0153] Example 10 includes the method according to Example 5 or 9 or some other embodiments herein, wherein receiving a random access preamble includes receiving a random access preamble on a PRACH.

[0154] Example 11 includes the method according to Example 1 or some other embodiments herein, wherein the second message includes a current value, and wherein a code value is generated based on a race-resolved identifier and the current value.

[0155] Example 12 includes the method described according to Examples 1 to 3, 5, 7 to 9 or 11 or some other embodiments herein, wherein generating the code value is performed using a hash function.

[0156] Example 13 includes the method according to Examples 1 to 3, 5, 7 to 9 and 11 or some other embodiments herein, wherein receiving the first message occurs on the PUSCH.

[0157] Example 14 includes the method according to Examples 1 to 3, 5, 7 to 9 and 11 or some other embodiments herein, wherein the transmission of the second message occurs on the PDSCH.

[0158] Example 15 includes a method of operating a user equipment, the method comprising: sending a first message including a contention resolution identifier; receiving a second message including a first code value; generating a second code value based on the contention resolution identifier; and comparing the first code value with the second code value.

[0159] Example 16 includes the method according to Example 15 or 28 or some other embodiments herein, wherein the method further includes receiving a RAR including uplink grant, and wherein the first message includes sending a first message according to the uplink grant.

[0160] Example 17 includes the method according to Example 15 or some other embodiments herein, wherein the method further includes receiving a RAR including a TC-RNTI, and wherein a second code value is generated based on a contention resolution identifier and the TC-RNTI.

[0161] Example 18 includes the method according to Example 16 or 17 or some other embodiments herein, wherein receiving RAR includes receiving RAR on PDSCH.

[0162] Example 19 includes the method according to Example 15 or 28 or some other embodiments herein, wherein the method further includes transmitting a random access preamble, and wherein a second code value is generated based on a contention resolution identifier and at least based on a RA-RNTI of timing of the random access preamble.

[0163] Example 20 includes the method described according to Example 15 or 28 or some other embodiments herein, wherein the first message includes a CCCH SDU containing a contention resolution identifier.

[0164] Example 21 includes the method according to Example 15 or 28 or some other embodiments herein, wherein the method includes receiving a DCI indicating a downlink resource allocation for a second message and including CRC bits, and wherein the CRC bits of the DCI are scrambled by RNTI.

[0165] Example 22 includes the method according to Example 21 or 28 or some other embodiments herein, wherein the method further includes transmitting a random access preamble, and the RNTI is based at least on the timing of the random access preamble.

[0166] Example 23 includes the method according to Example 19, 22, or 28 or some other embodiments herein, wherein sending a random access preamble includes sending a random access preamble on PRACH.

[0167] Example 24 includes the method according to Example 15 or some other embodiments herein, wherein the second message includes a current value, and wherein a second code value is generated based on a race-resolved identifier and the current value.

[0168] Example 25 includes the method described according to Examples 15 to 17, 19 to 22 or 24 or some other embodiments herein, wherein generating the second code value is performed using a hash function.

[0169] Example 26 includes the method described according to Examples 15 to 17, 19 to 22, 24 or 28 or some other embodiments herein, wherein the transmission of the first message occurs on the PUSCH.

[0170] Example 27 includes the method according to Examples 15 to 17, 19 to 22, 24 or 28 or some other embodiments herein, wherein receiving the second message occurs on the PDSCH.

[0171] Example 28 includes a method of operating a user equipment, the method comprising: sending a first message including a contention resolution identifier; receiving a second message including a first code value; descrambling the first code value to obtain a second code value; and comparing the second code value with the contention resolution identifier.

[0172] Example 29 includes a base station comprising: a processing circuit for: receiving a first message including a user equipment public key and a signature; generating a session key, wherein the session key is based on a user equipment public key and a second public key; using the generated session key to determine that the signature is valid; and sending a second message, wherein the second message is based on the generated session key and the signature; and a memory coupled to the processing circuit for storing the user equipment public key and the second public key.

[0173] Example 30 includes a base station according to Example 29 or some other embodiments herein, wherein the processing circuitry is further configured to encrypt a second message using the generated session key.

[0174] Example 31 includes a base station according to Example 29 or some other embodiments herein, wherein the processing circuitry is further configured to broadcast a second public key in the SIB.

[0175] Example 32 includes a base station according to Example 29 or some other embodiments herein, wherein the processing circuitry is further configured to receive a random access preamble; and in response to receiving the random access preamble, to send a random access response including a second public key.

[0176] Example 33 includes a base station according to Example 29 or some other embodiments herein, wherein the processing circuitry is further configured to transmit a DCI indicating downlink resource allocation for a second message and including CRC bits, wherein the CRC bits of the DCI are scrambled by RA-RNTI based at least on a timing of a random access preamble.

[0177] Example 34 includes a base station according to Example 29 or some other embodiments herein, wherein the processing circuitry is further configured to transmit a RAR including uplink grant, and wherein the processing circuitry is configured to receive a first message based on the uplink grant.

[0178] Example 35 includes a base station according to any one of Examples 29 to 34 or some other embodiments herein, wherein processing circuitry is used to generate a session key by performing an elliptic curve Diffie-Hellman (ECDH) algorithm.

[0179] Example 36 includes a base station according to any one of Examples 29 to 34 or some other embodiments herein, wherein processing circuitry is configured to receive a first message on the PUSCH.

[0180] Example 37 includes a base station according to any one of Examples 29 to 34 or some other embodiments herein, wherein processing circuitry is used to transmit a second message on the PDSCH.

[0181] Example 38 includes a user equipment, comprising: a processing circuit for: sending a random access preamble; receiving a first RAR; generating a session key, wherein the session key is based on a user equipment public key and a network public key; creating a signature based on the session key; and sending a first message including the user equipment public key and the signature; and a memory coupled to the processing circuit for storing the user equipment public key and the network public key.

[0182] Example 39 includes a user equipment according to Example 38 or some other embodiments herein, wherein the processing circuitry is further configured to receive a second message and use the generated session key to decrypt the received second message.

[0183] Example 40 includes a user equipment according to Example 39 or some other embodiments herein, wherein processing circuitry is configured to receive a second message on the PDSCH.

[0184] Example 41 includes a user equipment according to Example 38 or some other embodiments herein, wherein the processing circuitry is further configured to receive a network public key in the SIB.

[0185] Example 42 includes a user equipment according to Example 38 or some other embodiments herein, wherein the processing circuitry is further configured to receive a network public key in the RAR.

[0186] Example 43 includes a user equipment according to Example 38 or some other embodiments herein, wherein the RAR includes an uplink grant, and wherein processing circuitry is configured to send a first message based on the uplink grant.

[0187] Example 44 includes a user equipment according to Example 38 or some other embodiments herein, wherein the processing circuitry is further configured to receive a DCI indicating downlink resource allocation for a second message and including CRC bits, and wherein the CRC bits of the DCI are scrambled by RA-RNTI based at least on a timing of a random access preamble.

[0188] Example 45 includes a user equipment according to any one of Examples 38 to 44 or some other embodiments herein, wherein processing circuitry is used to generate a session key by performing the ECDH algorithm.

[0189] Example 46 includes a user equipment according to any one of Examples 38 to 44 or some other embodiments herein, wherein processing circuitry is configured to send a first message on the PUSCH.

[0190] Example 47 includes one or more computer-readable media having instructions that, when executed by one or more processors, cause a user equipment to: generate a signature, wherein the signature is based on a user equipment identifier and an RNTI; and send a first message including the generated signature.

[0191] Example 48 includes one or more computer-readable media according to Example 47 or some other embodiments herein, wherein instructions, when executed by one or more processors, cause a user equipment to send a random access preamble, wherein the RNTI is based on the timing of the random access preamble.

[0192] Example 49 includes one or more computer-readable media according to Example 47 or some other embodiments herein, wherein instructions, when executed by one or more processors, cause a user equipment to receive a RAR, wherein the RAR includes an RNTI.

[0193] Example 50 includes one or more computer-readable media according to Example 49 or some other embodiments herein, wherein the RAR includes uplink grants for scheduling transmissions on the PUSCH, and wherein instructions, when executed by one or more processors, cause a user equipment to send a first message on the PUSCH according to the uplink grants.

[0194] Example 51 includes one or more computer-readable media according to Example 47 or some other embodiments herein, wherein the first message further includes a race-solving identifier, and wherein a signature is included in the information element of the first message.

[0195] Example 52 includes one or more computer-readable media according to any one of Examples 47 to 51 or some other embodiments herein, wherein instructions, when executed by one or more processors, cause a user equipment to receive a second message including a signature.

[0196] Example 53 includes one or more computer-readable media having instructions that, when executed by one or more processors, cause a base station to receive a first message including a signature, and to verify the signature using the identifier of the user equipment and the RNTI.

[0197] Example 54 includes one or more computer-readable media according to Example 53 or some other embodiments herein, wherein instructions, when executed by one or more processors, cause a base station to receive a random access preamble, wherein the RNTI is based on the timing of the random access preamble.

[0198] Example 55 includes one or more computer-readable media according to Example 53 or some other embodiments herein, wherein instructions, when executed by one or more processors, cause a base station to transmit a received RAR, wherein the RAR includes an RNTI.

[0199] Example 56 includes one or more computer-readable media according to Example 55 or some other embodiments herein, wherein the RAR includes uplink grants for scheduling transmissions on the PUSCH, and wherein instructions, when executed by one or more processors, cause a base station to receive a first message on the PUSCH according to the uplink grants.

[0200] Example 57 includes one or more computer-readable media according to Example 53 or some other embodiments herein, wherein the first message further includes a race-solving identifier, and wherein a signature is included in the information element of the first message.

[0201] Example 58 includes one or more computer-readable media according to any one of Examples 53 to 57 or some other embodiments herein, wherein the instructions, when executed by one or more processors, cause a base station to send a second message including a signature.

[0202] Example 59 may include an apparatus comprising means for performing one or more elements of a method or process described or associated with any of Examples 1 to 58 or any other method or process described herein.

[0203] Embodiment 60 may include one or more non-transitory computer-readable media, the one or more non-transitory computer-readable media including instructions that, when executed by one or more processors of an electronic device, cause the electronic device to perform one or more elements of the method or any other method or process described herein according to any one of Embodiments 1 to 58.

[0204] Example 61 may include an apparatus comprising logic components, modules, or circuitry for performing one or more elements of the method described or associated with any of Examples 1 to 58 or any other method or process described herein.

[0205] Example 62 may include any of the methods, techniques, or processes described or associated with any of Examples 1 to 58, or a portion or component thereof.

[0206] Example 63 may include an apparatus comprising one or more processors and one or more computer-readable media, the one or more computer-readable media including instructions that, when executed by the one or more processors, cause the one or more processors to perform a method, technique, or process or part thereof as described or associated with any of Examples 1 to 58.

[0207] Example 64 may include a signal, or a portion thereof, as described or associated with any of Examples 1 to 58.

[0208] Example 65 may include a datagram, information element, packet, frame, segment, PDU, or message, or a portion or component thereof, as described or associated with any of Examples 1 to 58 or otherwise described in this disclosure.

[0209] Example 66 may include a signal, or a portion thereof, encoded with data according to any one of Examples 1 to 58 or otherwise described in this disclosure.

[0210] Example 67 may include a signal, or a portion thereof, encoded as a datagram, IE, packet, frame, segment, PDU, or message, as described or associated with any of Examples 1 to 58 or otherwise described in this disclosure.

[0211] Example 68 may include an electromagnetic signal carrying computer-readable instructions, wherein execution of the computer-readable instructions by one or more processors causes one or more processors to perform a method, technique, or process, or a portion thereof, as described or associated with any of Examples 1 to 58.

[0212] Example 69 may include a computer program comprising instructions, wherein execution of the program by a processing element causes the processing element to perform a method, technique, or process, or a portion thereof, as described or associated with any one of Examples 1 to 58.

[0213] Example 70 may include signals in a wireless network as shown and described herein.

[0214] Example 71 may include methods for communicating in a wireless network as shown and described herein.

[0215] Example 72 may include a system for providing wireless communication as shown and described herein.

[0216] Example 73 may include apparatus for providing wireless communication as shown and described herein.

[0217] Unless otherwise expressly stated, any of the examples above may be combined with any other example (or combination of examples). The foregoing description of one or more specific embodiments provides illustration and description, but is not intended to be exhaustive or to limit the scope of the embodiments to the precise form disclosed. In light of the teachings above, modifications and variations are possible, or modifications and variations may be derived from practice of various embodiments.

[0218] Although the above embodiments have been described in considerable detail, many variations and modifications will become apparent to those skilled in the art once the disclosure is fully understood. This disclosure is intended to render the following claims as encompassing all such variations and modifications.

Claims

1. A method for wireless communication, comprising: Generate a random access preamble for transmission to the base station; Generate a first message, including a contention resolution identifier, for transmission to the base station; Identify a second message received from the base station, including a first value; Generate a second value based at least in part on a plurality of parameters, wherein the second message includes a current value and the plurality of parameters include the contention resolution identifier and the current value; or, wherein the plurality of parameters include the contention resolution identifier and a random access radio network temporary identifier (RA-RNTI), the RA-RNTI being based at least in part on the timing of the random access preamble; as well as The first value is compared with the second value to determine whether the random access procedure was successful.

2. The method of claim 1, wherein the method further comprises identifying a Random Access Response (RAR) including uplink grant received from the base station, and The first message will be sent based on the uplink authorization.

3. The method of claim 1, wherein the method further comprises identifying a Random Access Response (RAR) received from the base station including a Temporary Cell Radio Network Temporary Identifier (TC-RNTI), and The parameters mentioned above also include the TC-RNTI.

4. The method according to any one of claims 1 to 3, wherein the first message includes a Common Control Channel (CCCH) Service Data Unit (SDU), the Common Control Channel Service Data Unit including the contention resolution identifier.

5. The method according to any one of claims 1 to 3, wherein the method includes identifying downlink control information (DCI) received from the base station, the downlink control information (DCI) indicating downlink resource allocation for the second message and including cyclic redundancy check (CRC) bits, and The CRC bit of the DCI is scrambled by a radio network temporary identifier (RNTI) based at least in part on the timing of the random access preamble.

6. The method according to any one of claims 1 to 3, wherein generating the second value is performed using a hash function.

7. The method according to any one of claims 1 to 3, further comprising: The first public key for identifying the base station; A shared session key is generated based on the first public key and the second public key of the user equipment (UE); as well as A signature is generated at least in part based on the shared session key, wherein the first message includes the signature.

8. The method according to any one of claims 1 to 3, further comprising: A signature is generated at least in part based on the user equipment identifier and the RA-RNTI, wherein the first message includes the signature.

9. A user equipment comprising processing circuitry and a memory coupled to the processing circuitry, the processing circuitry being configured to perform the method according to any one of claims 1-8.

10. One or more computer-readable media having instructions that, when executed by one or more processors, cause a user equipment to perform the method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Contention resolution in random access procedure

    WO2020168532A1

  • Method and apparatus for receiving random access message, or method and apparatus for sending random access message

    WO2021068237A1