Layer 2 security enhancement

CN116171641BActive Publication Date: 2026-08-14APPLE INC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-24
Publication Date
2026-08-14

Smart Images

  • Figure CN116171641B_ABST
    Figure CN116171641B_ABST
Patent Text Reader

Abstract

A method for a transmitter in a wireless communication system is provided, the method comprising: generating a protocol data unit (PDU) in layer 2 (L2); performing security protection on a control PDU in the PDU in L2 to obtain a protected control PDU for the control PDU, wherein the control PDU is in a sublayer below the Service Data Adaptation Protocol (SDAP); and transmitting the protected control PDU.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates generally to wireless communication systems, and more specifically to security enhancements in Layer 2 (L2). Background Technology

[0002] Wireless mobile communication technologies use various standards and protocols to transmit data between base stations and wireless mobile devices. Wireless communication system standards and protocols may include the 3rd Generation Partnership Project (3GPP) Long Term Evolution (LTE); the 5th Generation (5G) 3GPP New Radio (NR) standard; the Institute of Electrical and Electronics Engineers (IEEE) 802.16 standard, commonly referred to by the industry organization as Global Microwave Access Interoperability (WiMAX); and the IEEE 802.11 standard for Wireless Local Area Networks (WLANs), commonly referred to by the industry organization as Wi-Fi. In the 3GPP Radio Access Network (RAN) of an LTE system, a base station may include RAN nodes such as an Evolved Universal Terrestrial Radio Access Network (E-UTRAN) Node B (also commonly referred to as an Evolved Node B, Enhanced Node B, eNodeB, or eNB) and / or a Radio Network Controller (RNC) in the E-UTRAN, which communicates with wireless communication equipment called User Equipment (UE). In a fifth-generation (5G) wireless RAN, RAN nodes may include 5G nodes, new radio (NR) nodes, or gNodeBs (gNBs), which communicate with wireless communication equipment (also known as user equipment (UE)). Summary of the Invention

[0003] According to an aspect of this disclosure, a method for a transmitter in a wireless communication system is provided, the method comprising generating a Protocol Data Unit (PDU) in a Layer 2 (L2); performing security protection on a control PDU in the PDU in the L2 to obtain a protected control PDU for the control PDU, wherein the control PDU is in a sublayer below the Service Data Adaptation Protocol (SDAP); and transmitting the protected control PDU.

[0004] According to an aspect of this disclosure, a method for a receiver in a wireless communication system is provided, the method including a protected control PDU in a receiver layer 2 (L2), wherein the protected control PDU is obtained by performing security protection on a control PDU in a sublayer below the Service Data Adaptation Protocol (SDAP).

[0005] According to an aspect of this disclosure, a method for a transmitter in a wireless communication system is provided, the method comprising generating a Protocol Data Unit (PDU) in Layer 2 (L2); performing security protection on the header of one of the PDUs in L2 to obtain a protected PDU for that PDU, wherein the PDU is in a sublayer below a Packet Data Convergence Protocol (PDCP); and transmitting the protected PDU.

[0006] According to an aspect of this disclosure, a method for a receiver in a wireless communication system is provided, the method including a protected PDU in a receiving layer 2 (L2), wherein the protected PDU is obtained by performing security protection on at least the header of the PDU in a sublayer below the Packet Data Convergence Protocol (PDCP).

[0007] According to an aspect of this disclosure, an apparatus for a transmitter is provided, the apparatus comprising: one or more processors configured to perform the steps of the methods mentioned above for the transmitter.

[0008] According to an aspect of this disclosure, an apparatus for a receiver includes: one or more processors configured to perform the steps of the methods mentioned above for the receiver.

[0009] According to an aspect of this disclosure, a computer-readable medium having a computer program stored thereon is provided, which, when executed by one or more processors, causes a device to perform the steps of the methods mentioned above.

[0010] According to an aspect of this disclosure, a computer program product includes a computer program that, when executed by one or more processors, causes a device to perform the steps of the methods mentioned above. Attached Figure Description

[0011] The features and advantages of this disclosure will become apparent from the following detailed description taken in conjunction with the accompanying drawings, which illustrate the features of this disclosure by way of example.

[0012] Figure 1 It is a block diagram of a system including base stations and user equipment (UE) according to some implementation schemes.

[0013] Figure 2 A flowchart of an exemplary method of a transmitter according to some implementation schemes is shown.

[0014] Figure 3 A flowchart illustrating an exemplary method of a receiver according to some implementation schemes is shown.

[0015] Figure 4 A flowchart of an exemplary method of a transmitter according to some implementation schemes is shown.

[0016] Figure 5 A flowchart illustrating an exemplary method of a receiver according to some implementation schemes is shown.

[0017] Figure 6 Communication exchange combined with security protection is illustrated according to some embodiments of this disclosure.

[0018] Figure 7 An exemplary block diagram of a transmitter apparatus according to some embodiments is shown.

[0019] Figure 8 An exemplary block diagram of a receiver device according to some embodiments is shown.

[0020] Figure 9 Exemplary components of a device according to some implementation schemes are shown.

[0021] Figure 10 An exemplary interface of a baseband circuit according to some implementation schemes is shown.

[0022] Figure 11 The components are shown according to some implementation schemes.

[0023] Figure 12 The architecture of a wireless network according to some implementation schemes is shown. Detailed Implementation

[0024] In this disclosure, a "base station" may include RAN nodes such as an Evolved Universal Terrestrial Radio Access Network (E-UTRAN) node B (also commonly referred to as an evolved node B, enhanced node B, eNodeB, or eNB) and / or a Radio Network Controller (RNC) and / or a 5G node, a New Radio (NR) node, or a gNodeB (gNB), which communicates with wireless communication equipment also referred to as User Equipment (UE). Although some examples may be described with reference to any of E-UTRAN node B, eNB, RNC, and / or gNB, such equipment can be replaced by any type of base station.

[0025] Carrier aggregation is a technique that allows multiple carrier signals operating at different frequencies to be used to carry communications for a single UE, thereby increasing the bandwidth available to a single device. In some aspects, carrier aggregation can be used when one or more component carriers are operating at unlicensed frequencies.

[0026] To increase bandwidth and thus bit rate, user equipment (UE) can connect to more than one serving cell. In New Radio (NR), one serving cell can be designated as the primary cell (PCell), while other cells can be secondary cells (SCells). In some cases, the PCell and SCell for the UE may correspond to the same base station (supported by the same base station). In other cases, the PCell and SCell may correspond to different base stations (supported by different base stations).

[0027] In wireless communication, each frequency band has a primary component carrier called the primary cell (PCell), and the other component carriers are called secondary cells (SCells). SCells can be activated for data transmission if necessary.

[0028] Figure 1 A wireless network 100 according to some embodiments is shown. The wireless network 100 includes a UE 101 and a base station 150 connected via an air interface 190.

[0029] UE 101 and any other UE in the system can be, for example, a laptop computer, smartphone, tablet computer, printer, machine-type device, such as a smart meter or dedicated device for healthcare monitoring, remote security monitoring, intelligent transportation systems, or any other wireless device with or without a user interface. Base station 150 provides UE 101 with network connectivity to a wider network (not shown) via air interface 190 within the base station service area provided by base station 150. In some embodiments, such a wider network can be a wide area network operated by a cellular network provider, or it can be the Internet. Each base station service area associated with base station 150 is supported by an antenna integrated with base station 150. The service area is divided into multiple sectors associated with certain antennas. Such sectors can be physically associated with fixed antennas, or can be assigned to physical areas with tunable antennas or antenna configurations that can be adjusted during beamforming to direct signals to a particular sector. For example, one implementation of base station 150 includes three sectors, each covering a 120-degree area, wherein the antenna array is pointed at each sector to provide 360-degree coverage around base station 150.

[0030] UE 101 includes control circuitry 105 coupled to transmit circuitry 110 and receive circuitry 115. Transmit circuitry 110 and receive circuitry 115 may each be coupled to one or more antennas. Control circuitry 105 may be adapted to perform operations associated with MTC. In some embodiments, control circuitry 105 of UE 101 may perform calculations or initiate measurements associated with air interface 190 to determine the channel quality of an available connection to base station 150. These calculations may be performed in conjunction with control circuitry 155 of base station 150. Transmit circuitry 110 and receive circuitry 115 may be adapted to transmit and receive data, respectively. Control circuitry 105 may be adapted or configured to perform various operations, such as the various UE-related operations described elsewhere in this disclosure. Transmit circuitry 110 may transmit multiple multiplexed uplink physical channels. These multiple uplink physical channels may be multiplexed according to time division multiplexing (TDM) or frequency division multiplexing (FDM). Transmit circuitry 110 may be configured to receive block data from control circuitry 105 for transmission across air interface 190. Similarly, receiving circuitry 115 can receive multiple multiplexed downlink physical channels from air interface 190 and relay these physical channels to control circuitry 105. Uplink and downlink physical channels can be multiplexed according to TDM or FDM. Transmitting circuitry 110 and receiving circuitry 115 can transmit and receive structured control data and content data (e.g., messages, images, video, etc.) within data blocks carried by the physical channels.

[0031] Figure 1 A base station 150 according to various embodiments is also shown. The base station 150 circuitry may include control circuitry 155 coupled to transmitting circuitry 160 and receiving circuitry 165. Transmitting circuitry 160 and receiving circuitry 165 may each be coupled to one or more antennas, which may be used for communication via air interface 190.

[0032] Control circuitry 155 can be adapted to perform operations associated with the MTC. Transmitting circuitry 160 and receiving circuitry 165 can be adapted to transmit and receive data respectively within a narrow system bandwidth, which is narrower than the standard bandwidth used for personal communications. In some embodiments, for example, the transmission bandwidth can be set to or close to 1.4 MHz. In other embodiments, other bandwidths can be used. Control circuitry 155 can perform various operations, such as those associated with the base station described elsewhere in this disclosure.

[0033] Within a narrow system bandwidth, the transmitter circuit 160 can transmit multiple multiplexed downlink physical channels. These multiple downlink physical channels can be multiplexed according to TDM or FDM. The transmitter circuit 160 can transmit these multiple multiplexed downlink physical channels in a downlink superframe consisting of multiple downlink subframes.

[0034] Within a narrow system bandwidth, receiver circuit 165 can receive multiple multiplexed uplink physical channels. These multiple uplink physical channels can be multiplexed according to TDM or FDM. Receiver circuit 165 can receive these multiple multiplexed uplink physical channels in an uplink superframe composed of multiple uplink subframes.

[0035] As further described below, control circuits 105 and 155 may be involved in measuring the channel quality of air interface 190. Channel quality may be based, for example, on physical barriers between UE 101 and base station 150, electromagnetic interference from other sources, reflections, or indirect paths between UE 101 and base station 150, or other such signal noise sources. Based on channel quality, multiple retransmissions of data blocks can be scheduled, allowing transmitting circuit 110 to transmit multiple copies of the same data, and receiving circuit 115 to receive multiple copies of the same data.

[0036] The UE and various base stations (e.g., base stations supporting all types of serving cells including PCells and SCells, or base stations acting as network devices for communicating with the UE) described in the following embodiments can be provided by Figure 1 The UE 101 and base station 150 described herein are implemented.

[0037] In the current Access Layer (AS) security framework, a unicast transmission is permitted after AS security is activated. The UE can calculate a signature (e.g., MAC-I) and transmit this signature in the RRC Reestablishment Request and RRC Reestablishment Request to help network (NW) devices in the wireless communication system identify the UE. In particular, L2 security configuration can be applied to transmission security and stability.

[0038] Layer 2 may include sublayers, including: Media Access Control (MAC) layer, Radio Link Control (RLC) layer, Packet Data Convergence Protocol (PDCP) layer, and Service Data Adaptation Protocol (SDAP) layer.

[0039] In the current AS security configuration, AS security may include integrity protection and encryption of Radio Resource Control (RRC) signaling (e.g., Signaling Radio Bearer (SRB)) and user data (e.g., Data Radio Bearer (DRB)). The AS Security Mode Command (SMC) procedure is used for RRC and User Plane (UP) security algorithm negotiation and RRC security activation. The current AS security configuration is performed per DRB, and all DRBs belonging to the same Protocol Data Unit (PDU) session use the same security configuration. Integrity protection and encryption algorithms are common to SRB1, SRB2, SRB3 (if configured), and DRBs configured with integrity protection, and have the same keyToUse value.

[0040] Under the current L2 security configuration, for the PDCP layer, the encrypted data units are the MAC-I and the data portion of the PDCP data PDU, excluding the SDAP header and SDAP control PDU (if included in the PDCP service data unit (SDU)). Encryption does not apply to the PDCU control PDU. Furthermore, the data units protected for integrity are the PDU header and the data portion of the PDU before encryption. Integrity protection applies to the PDCP data PDU of the SRB and the PDCP data PDU of the DRB. In other words, the PDCH header and SDAP header can be protected by the current integrity protection mechanism, and the data portion and MAC-I in the PDCP layer can be protected by encryption.

[0041] In summary, current L2 security protection applies to SDAP control PDUs (protected for integrity at the PDCP layer), SDAP headers (protected for integrity at the PDCP layer), PDCP headers (protected for integrity at the PDCP layer), and PDCP data PDUs (protected for encryption at the PDCP layer). However, control PDUs in sublayers below the SDAP layer (i.e., the PDCP, RLC, and MAC layers) are unprotected. Additionally, headers in sublayers below the PDCP layer are unprotected. Since control PDUs can affect RACH procedures, MIMO configuration, activation configuration, or scheduling information, unprotected control PDUs and headers can lead to spoofed control PDUs and spoofed L2 headers in the L2 layer during wireless communication. Specifically, spoofed control PDUs in the L2 layer can cause erroneous UE operation and may disconnect the connection between the UE and the NW. Spoofed L2 headers can cause unnecessary packet dropping in the receiver.

[0042] Table 1 shows the headers of control PDUs or PDUs that are not protected by current security protection mechanisms but can be protected by the implementation scheme of this disclosure.

[0043]

[0044]

[0045]

[0046] Table 1

[0047] Therefore, in order to provide enhancements to L2 security mechanisms, this disclosure provides a method and apparatus for a transmitter and a method and apparatus for a receiver to provide improved protection in L2.

[0048] Figure 2 A flowchart of an exemplary method of a transmitter according to some implementation schemes is shown. Figure 2 The method 200 shown can be derived from... Figure 1 The description is as follows: UE 101, which is a transmitter or base station 150 in a wireless communication system.

[0049] At step S202, the transmitter may generate a PDU in L2. The PDU in L2 may include an SDAP PDU, a PDCP PDU, an RLC PDU, a MAC PDU, or a MAC subPDU.

[0050] At step S204, the transmitter of the wireless communication system can perform security protection on the control PDU in the PDU in L2 to obtain a protected control PDU for that control PDU, wherein the control PDU is in a sublayer below the Serving Data Adaptation Protocol (SDAP). For example, the control PDU to be protected can be a PDCP control PDU, an RLC control PDU, or a MAC control subPDU (MAC control element (MAC-CE)).

[0051] Security protection for the control PDU may include at least one of integrity protection, encryption protection, or hash protection based on the corresponding security protection algorithm.

[0052] In some implementations, within an integrity protection mechanism, a protected control PDU can be determined by applying an integrity protection algorithm to the control PDU to be protected. Based on the output of the integrity protection algorithm, a signature (e.g., MAC-I) can be determined, and the combination of the control PDU and the signature can be identified as the protected control PDU. For example, the signature can be assembled with the original control PDU to obtain the protected control PDU.

[0053] For example, the MAC-I field can be added to the status PDU, as in TS 38.322. Figure 6As shown in .2.2.5-1, this state PDU can be protected by calculating and adding MAC-I to generate a protected state PDU. Other RLC control PDUs, such as the PDCP control PDU shown in TS 38.322, or the MAC control PDU shown in TS 38.321, can also be protected for integrity in a similar manner.

[0054] In some implementations, the integrity protection algorithm may include integrity protection algorithms for 5G systems, such as 128-NIA1, 128-NIA2, or 128-NIA3. In other implementations, the integrity protection algorithm may include integrity protection algorithms for LTE or 3G systems, such as EIA1, EIA2, EIA3, UIA1, or UIA2. Those skilled in the art can apply any other possible integrity protection algorithm to the control PDU as needed. By reusing existing integrity protection algorithms, improved security protection can be achieved at minimal cost.

[0055] The inputs to the integrity protection algorithm used to control the PDU may include: COUNT parameter; DIRECTION parameter; BEARER parameter; and integrity protection key.

[0056] The COUNT and BEARER parameters can be set based on any possible values ​​to differentiate between different control PDUs, or they can be set to be universal for all control PDUs to be protected.

[0057] In some examples, the COUNT parameter of the integrity protection algorithm can be a fixed COUNT value. For example, the COUNT parameter of the integrity protection algorithm can be set to 0 or any other possible value. In some other examples, the COUNT parameter of the integrity protection algorithm can be a sequence number (SN) assigned in the lower layer. For example, for a PDCP control PDU to be protected, the COUNT parameter of the integrity protection algorithm can be determined by the RLC SN. For an RLC control PDU to be protected, the COUNT parameter of the integrity protection algorithm can be determined by the MAC SN. In still other examples, the COUNT parameter of the integrity protection algorithm can be determined as a random value. When the COUNT parameter of the integrity protection algorithm is a random value, the random value can be indicated to the peer entity. The random value can be indicated explicitly or implicitly. In the implicit mode, the random value can be indicated by the index corresponding to the random value.

[0058] In some examples, the BEARER parameter of the integrity protection algorithm can be the BEARER ID of the bearer associated with the control PDU. In another example, the BEARER parameter of the integrity protection algorithm can be a fixed value. For example, the BEARER parameter of the integrity protection algorithm can be set to 0 or any other possible value. In some other examples, the BEARER parameter of the integrity protection algorithm can be a control PDU type indicator. For example, the BEARER parameter of the integrity protection algorithm can be a value in a field of the control PDU that indicates the type of the control PDU to be protected. In still other examples, the BEARER parameter of the integrity protection algorithm can be a value in any other specified field of the control PDU to be protected. For example, the type of the control PDU can be represented by the LCID of the MAC-CE.

[0059] The DIRECTION parameter of the integrity protection algorithm can indicate either the uplink (UL) direction or the downlink (DL) direction. In some examples, the DIRECTION parameter of the integrity protection algorithm can be set to 0 to indicate the UL direction and to 1 to indicate the DL direction. Those skilled in the art can set the DIRECTION parameter of the integrity protection algorithm to any other possible value as appropriate.

[0060] Integrity protection keys may include integrity protection key K RRCint or K UPint (As shown in TS 38.300). K RRCint It can be a key derived from the base station for integrity protection of RRC signaling. K UPint It can be a key derived from the base station for integrity protection of UP communication traffic. Alternatively, those skilled in the art can derive the integrity protection key in any other possible manner depending on the specific circumstances.

[0061] In some other specific implementations, within the encryption mechanism, the protected control PDU can be determined by applying an encryption algorithm to the control PDU to be protected. The output of the encryption algorithm can be used to identify the protected control PDU.

[0062] In some implementations, the encryption algorithm may include encryption algorithms for 5G systems, such as 128-NEA1, 128-NEA2, or 128-NEA3. In other implementations, the encryption algorithm may include encryption algorithms for LTE or 3G systems, such as 128-EEA1, 128-EEA2, 128-EEA3, UEA1, or UEA2. Those skilled in the art may apply any other possible encryption algorithms to the control PDU as appropriate.

[0063] The inputs to the encryption algorithm may include: the COUNT parameter; the DIRECTION parameter; the BEARER parameter; and the encryption key.

[0064] The COUNT and BEARER parameters can be set based on any possible values ​​to differentiate between different control PDUs, or they can be set to be universal for all control PDUs to be protected.

[0065] In some examples, the COUNT parameter of the encryption algorithm can be a fixed COUNT value. For example, the COUNT parameter of the encryption algorithm can be set to 0 or any other possible value. In some other examples, the COUNT parameter of the encryption algorithm can be a sequence number (SN) assigned in the lower layer. For example, for a PDCP control PDU to be protected, the COUNT parameter of the encryption algorithm can be determined by the RLC SN. For an RLC control PDU to be protected, the COUNT parameter of the encryption algorithm can be determined by the MAC SN. In still other examples, the COUNT parameter of the encryption algorithm can be determined as a random value. When the COUNT parameter of the encryption algorithm is a random value, the random value can be indicated to the peer entity. The random value can be indicated explicitly or implicitly. In the implicit mode, the random value can be indicated by an index corresponding to the random value.

[0066] In some examples, the BEARER parameter of the encryption algorithm can be the BEARERID of the bearer associated with the control PDU. In another example, the BEARER parameter of the encryption algorithm can be a fixed value. For example, the BEARER parameter of the encryption algorithm can be set to 0 or any other possible value. In some other examples, the BEARER parameter of the encryption algorithm can be a control PDU type indicator. For example, the BEARER parameter of the encryption algorithm can be a value in a field of the control PDU that indicates the type of the control PDU to be protected. In still other examples, the BEARER parameter of the encryption algorithm can be a value in any other specified field of the control PDU to be protected. For example, the type of the control PDU can be represented by the LCID of the MAC-CE.

[0067] The DIRECTION parameter of an encryption algorithm can indicate either the uplink (UL) direction or the downlink (DL) direction. In some examples, the DIRECTION parameter can be set to 0 to indicate the UL direction and to 1 to indicate the DL direction. Those skilled in the art can set the DIRECTION parameter of the encryption algorithm to any other possible value as appropriate.

[0068] The encryption key may include encryption key K RRCenc or K UPenc (As indicated in TS 38.300). K RRCencIt can be a key derived from the base station for encryption protection of RRC signaling. K UPenc It can be a key derived from the base station for encrypting and protecting UP communication traffic. Alternatively, those skilled in the art can derive the encryption key in any other possible manner depending on the specific circumstances.

[0069] In some other implementations, within a hash protection mechanism, the protected control PDU can be determined by applying a hash algorithm to the control PDU. The output of the hash algorithm can be used to identify the protected control PDU. The hash algorithm can be SHA-256 or any other applicable hash algorithm.

[0070] In some examples, the input to the hash algorithm can be the control PDU itself. In other examples, the input to the hash algorithm can be a combination of the control PDU and an additional random value. The random value for the hash algorithm can be indicated to the peer entity. The random value can be indicated explicitly or implicitly. In the implicit mode, the random value can be indicated by an index corresponding to the random value.

[0071] At step S206, the transmitter may, for example, transmit a protected control PDU to a receiver in a wireless communication system.

[0072] Figure 3 A flowchart illustrating an exemplary method of a receiver according to some implementation schemes is shown. Figure 3 The method 300 shown can be used by... Figure 1 The description is as follows: UE 101, which is a receiver in a wireless communication system, or base station 150.

[0073] At S302, the receiver can receive a protected control PDU in layer 2 (L2), wherein the protected control PDU is obtained by performing security protection on the control PDU in the sublayer below the Service Data Adaptation Protocol (SDAP).

[0074] The protected control PDU can be a PDCP control PDU, an RLC control PDU, or a MAC control PDU (MAC control element (MAC-CE)).

[0075] The protected control PDU can be combined as follows Figure 2 The security protections shown (e.g., integrity protection, encryption protection, or hash protection) are derived from the corresponding control PDUs in sub-layers below SDAP. Security protections can be combined with... Figure 2 The descriptions are the same.

[0076] In some implementations, within an integrity protection mechanism, a protected control PDU can be determined by applying an integrity protection algorithm to the control PDU to be protected. Based on the output of the integrity protection algorithm, a signature (e.g., MAC-I) can be determined, and the combination of the control PDU and the signature can be identified as the protected control PDU. For example, the signature can be assembled with the original control PDU to obtain the protected control PDU.

[0077] When a protected control PDU is obtained based on an integrity protection algorithm, the receiver can also perform integrity verification on the protected control PDU based on its signature. If the signature is incorrect or missing, the protected control PDU may be discarded by the receiver.

[0078] In some implementations, the integrity protection algorithm may include integrity protection algorithms for 5G systems, such as 128-NIA1, 128-NIA2, or 128-NIA3. In other implementations, the integrity protection algorithm may include integrity protection algorithms for LTE or 3G systems, such as EIA1, EIA2, EIA3, UIA1, or UIA2. Those skilled in the art may apply any other possible integrity protection algorithm to the control PDU as appropriate.

[0079] The inputs to the integrity protection algorithm used to control the PDU may include: the COUNT parameter; the DIRECTION parameter; the BEARER parameter; and the integrity protection key.

[0080] The COUNT and BEARER parameters can be set based on any possible values ​​to differentiate between different control PDUs, or they can be set to be universal for all control PDUs to be protected.

[0081] In some examples, the COUNT parameter of the integrity protection algorithm can be a fixed COUNT value. For example, the COUNT parameter of the integrity protection algorithm can be set to 0 or any other possible value. In some other examples, the COUNT parameter of the integrity protection algorithm can be a sequence number (SN) assigned in the lower layer. For example, for a PDCP control PDU to be protected, the COUNT parameter of the integrity protection algorithm can be determined by the RLC SN. For an RLC control PDU to be protected, the COUNT parameter of the integrity protection algorithm can be determined by the MAC SN. In still other examples, the COUNT parameter of the integrity protection algorithm can be determined as a random value. When the COUNT parameter of the integrity protection algorithm is a random value, the random value can be indicated to the peer entity. The random value can be indicated explicitly or implicitly. In the implicit mode, the random value can be indicated by the index corresponding to the random value.

[0082] In some examples, the BEARER parameter of the integrity protection algorithm can be the BEARER ID of the bearer associated with the control PDU. In another example, the BEARER parameter of the integrity protection algorithm can be a fixed value. For example, the BEARER parameter of the integrity protection algorithm can be set to 0 or any other possible value. In some other examples, the BEARER parameter of the integrity protection algorithm can be a control PDU type indicator. For example, the BEARER parameter of the integrity protection algorithm can be a value in a field of the control PDU that indicates the type of the control PDU to be protected. In still other examples, the BEARER parameter of the integrity protection algorithm can be a value in any other specified field of the control PDU to be protected. For example, the type of the control PDU can be represented by the LCID of the MAC-CE.

[0083] The DIRECTION parameter of the integrity protection algorithm can indicate either the uplink (UL) direction or the downlink (DL) direction. In some examples, the DIRECTION parameter of the integrity protection algorithm can be set to 0 to indicate the UL direction and to 1 to indicate the DL direction. Those skilled in the art can set the DIRECTION parameter of the integrity protection algorithm to any other possible value as appropriate.

[0084] Integrity protection keys may include integrity protection key K RRCint or K UPint (As shown in TS 38.300). K RRCint It can be a key derived from the base station for integrity protection of RRC signaling. K UPint It can be a key derived from the base station for integrity protection of UP communication traffic. Alternatively, those skilled in the art can derive the integrity protection key in any other possible manner depending on the specific circumstances.

[0085] In some other specific implementations, within the encryption mechanism, the protected control PDU can be determined by applying an encryption algorithm to the control PDU to be protected. The output of the encryption algorithm can be used to identify the protected control PDU.

[0086] When a protected control PDU is obtained based on an encryption algorithm, the receiver can determine the control PDU by applying the corresponding decryption algorithm to the protected control PDU, thereby obtaining the plaintext of the control PDU.

[0087] In some implementations, the encryption algorithm may include encryption algorithms for 5G systems, such as 128-NEA1, 128-NEA2, or 128-NEA3. In other implementations, the encryption algorithm may include encryption algorithms for LTE or 3G systems, such as 128-EEA1, 128-EEA2, 128-EEA3, UEA1, or UEA2. Those skilled in the art may apply any other possible encryption algorithms to the control PDU as appropriate.

[0088] The inputs to the encryption algorithm may include: the COUNT parameter; the DIRECTION parameter; the BEARER parameter; and the encryption key.

[0089] The COUNT and BEARER parameters can be set based on any possible values ​​to differentiate between different control PDUs, or they can be set to be universal for all control PDUs to be protected.

[0090] In some examples, the COUNT parameter of the encryption algorithm can be a fixed COUNT value. For example, the COUNT parameter of the encryption algorithm can be set to 0 or any other possible value. In some other examples, the COUNT parameter of the encryption algorithm can be a sequence number (SN) assigned in the lower layer. For example, for a PDCP control PDU to be protected, the COUNT parameter of the encryption algorithm can be determined by the RLC SN. For an RLC control PDU to be protected, the COUNT parameter of the encryption algorithm can be determined by the MAC SN. In still other examples, the COUNT parameter of the encryption algorithm can be determined as a random value. When the COUNT parameter of the encryption algorithm is a random value, the random value can be indicated to the peer entity. The random value can be indicated explicitly or implicitly. In the implicit mode, the random value can be indicated by an index corresponding to the random value.

[0091] In some examples, the BEARER parameter of the encryption algorithm can be the BEARERID of the bearer associated with the control PDU. In another example, the BEARER parameter of the encryption algorithm can be a fixed value. For example, the BEARER parameter of the encryption algorithm can be set to 0 or any other possible value. In some other examples, the BEARER parameter of the encryption algorithm can be a control PDU type indicator. For example, the BEARER parameter of the encryption algorithm can be a value in a field of the control PDU that indicates the type of the control PDU to be protected. In still other examples, the BEARER parameter of the encryption algorithm can be a value in any other specified field of the control PDU to be protected. For example, the type of the control PDU can be represented by the LCID of the MAC-CE.

[0092] The DIRECTION parameter of an encryption algorithm can indicate either the uplink (UL) direction or the downlink (DL) direction. In some examples, the DIRECTION parameter can be set to 0 to indicate the UL direction and to 1 to indicate the DL direction. Those skilled in the art can set the DIRECTION parameter of the encryption algorithm to any other possible value as appropriate.

[0093] The encryption key may include encryption key K RRCenc or K UPenc (As indicated in TS 38.300). K RRCenc It can be a key derived from the base station for encryption protection of RRC signaling. K UPenc It can be a key derived from the base station for encrypting and protecting UP communication traffic. Alternatively, those skilled in the art can derive the encryption key in any other possible manner depending on the specific circumstances.

[0094] In some other implementations, within a hash protection mechanism, the protected control PDU can be determined by applying a hash algorithm to the control PDU. The output of the hash algorithm can be used to identify the protected control PDU. The hash algorithm can be SHA-256 or any other applicable hash algorithm.

[0095] When the protected control PDU is obtained based on the HASH algorithm, the receiver can determine the control PDU by applying the reverse HASH algorithm to the protected control PDU in order to obtain the plaintext of the control PDU.

[0096] In some examples, the input to the hash algorithm can be the control PDU itself. In other examples, the input to the hash algorithm can be a combination of the control PDU and an additional random value. The random value for the hash algorithm can be indicated to the peer entity. The random value can be indicated explicitly or implicitly. In the implicit mode, the random value can be indicated by an index corresponding to the random value.

[0097] According to the implementation scheme of this application, by applying a protection algorithm to at least one control PDU in a sublayer below SDAP, improved protection is applied to L2 PDUs, and attacks on L2 control PDUs can be effectively prevented.

[0098] Figure 4 A flowchart of an exemplary method of a transmitter according to some implementation schemes is shown. Figure 4 The method 400 shown can be derived from... Figure 1 The description is as follows: UE 101, which is a transmitter or base station 150 in a wireless communication system.

[0099] At step S402, the transmitter may generate a PDU in L2. The PDU in L2 may include an SDAP PDU, a PDCP PDU, an RLC PDU, a MAC PDU, or a MAC subPDU.

[0100] At step S404, the transmitter may perform security protection on the header of one of the PDUs in L2 to obtain a protected PDU for that PDU, wherein the PDU is in a sublayer below the Packet Data Convergence Protocol (PDCP). For example, the PDU may be an RLC PDU or a MAC PDU (e.g., a MAC subPDU, since the header can be generated at the MAC subPDU level), and the header of the RLC PDU or MAC PDU may be protected by security protection.

[0101] Security protection for the PDU header may include integrity protection or any other security protection mechanism applicable as the specific circumstances warrant.

[0102] In some implementations, within an integrity protection mechanism, a protected PDU can be determined by applying an integrity protection algorithm to at least the header of the PDU to be protected. Based on the output of the integrity protection algorithm, a header signature (e.g., MAC-I) for the PDU's header can be determined, and the combination of the PDU and the header signature can be identified as a protected PDU. For example, the header signature can be assembled with the original PDU to obtain a protected PDU.

[0103] In some implementations, integrity protection algorithms may be applied only to the PDU header. In other implementations, integrity protection algorithms may be applied to the entire PDU. Protecting the entire PDU provides comprehensive protection. However, protecting only the PDU header minimizes the workload of the security protection process.

[0104] For PDUs such as MAC subPDUs or RLC PDUs, MAC-I can be introduced and carried at the MAC subPDU or RLC PDU level. In some examples, MAC-I may be calculated based solely on the header of the MAC subPDU or the header of the RLC header. In another example, MAC-I may be calculated based solely on the entire MAC subPDU including the MAC header or the entire RLC including the RLC header.

[0105] In some specific implementations, if integrity protection is applied to the entire PDU, i.e., MAC-I is calculated based on the entire PDU, then integrity protection in the upper layer will not be needed because the content of the upper-layer PDU is already protected by the integrity of the entire PDU in the lower layer. For example, if MAC-I is calculated based on the entire MAC subPDU, then integrity protection does not need to be applied in the PDCP and RLC layers.

[0106] For example, the MAC-I field can be added to, as in TS 38.321 Figure 6 The DL MAC PDU shown in .1.2-4 can be protected by calculating and adding MAC-I to generate a protected state PDU. Other RLC control PDUs, such as the PDCP control PDU shown in TS 38.322 or the MAC control PDU shown in TS 38.321, can also be protected in a similar manner.

[0107] In some implementations, the integrity protection algorithm may include integrity protection algorithms for 5G systems, such as 128-NIA1, 128-NIA2, or 128-NIA3. In other implementations, the integrity protection algorithm may include integrity protection algorithms for LTE or 3G systems, such as EIA1, EIA2, EIA3, UIA1, or UIA2. Those skilled in the art may apply any other possible integrity protection algorithm to the PDU header as appropriate.

[0108] The inputs to the integrity protection algorithm for the PDU header may include: the COUNT parameter; the DIRECTION parameter; the BEARER parameter; and the integrity protection key.

[0109] The COUNT and BEARER parameters can be set based on any possible values ​​to distinguish different PDUs, or they can be set to be universal for all PDUs to be protected.

[0110] In some examples, the COUNT parameter of the integrity protection algorithm can be a fixed COUNT value. For example, the COUNT parameter of the integrity protection algorithm can be set to 0 or any other possible value. In some other examples, the COUNT parameter of the integrity protection algorithm can be a sequence number (SN) assigned in the lower layer. In still other examples, the COUNT parameter of the integrity protection algorithm can be determined as a random value. When the COUNT parameter of the integrity protection algorithm is a random value, the random value can be indicated to the peer entity. The random value can be indicated explicitly or implicitly. In the implicit way, the random value can be indicated by the index corresponding to the random value.

[0111] In some examples, the BEARER parameter of the integrity protection algorithm can be a fixed value. For example, the BEARER parameter of the integrity protection algorithm can be set to 0 or any other possible value. In some other examples, the BEARER parameter of the integrity protection algorithm can be a PDU type indicator. For example, the BEARER parameter of the integrity protection algorithm can be a value in a field of the PDU that indicates the type of the PDU to be protected. In still other examples, the BEARER parameter of the integrity protection algorithm can be a value in any other specified field of the PDU to be protected.

[0112] The DIRECTION parameter of the integrity protection algorithm can indicate either the uplink (UL) direction or the downlink (DL) direction. In some examples, the DIRECTION parameter of the integrity protection algorithm can be set to 0 to indicate the UL direction and to 1 to indicate the DL direction. Those skilled in the art can set the DIRECTION parameter of the integrity protection algorithm to any other possible value as appropriate.

[0113] Integrity protection keys may include integrity protection key K RRCint or K UPint (As shown in TS 38.300). K RRCint It can be a key derived from the base station for integrity protection of RRC signaling. K UPint It can be a key derived from the base station for integrity protection of UP communication traffic. Alternatively, those skilled in the art can derive the integrity protection key in any other possible manner depending on the specific circumstances.

[0114] In step S406, the transmitter may transmit a protected PDU to the receiver in the wireless communication system.

[0115] Figure 5 A flowchart illustrating an exemplary method of a receiver according to some implementation schemes is shown. Figure 5 The method 500 shown can be used by... Figure 1 The description is as follows: UE 101, which is a receiver in a wireless communication system, or base station 150.

[0116] At step S502, the receiver may receive a protected PDU in layer 2 (L2), wherein the protected PDU is obtained by performing security protection on at least the header of the PDU in a sublayer below the Packet Data Convergence Protocol (PDCP).

[0117] The protected PDU can be an RLC PDU or a MAC PDU, and the header of the RLC PDU or MAC PDU can be protected by security protection.

[0118] Security protection for PDU headers may include, for example, combining Figure 3 The integrity protection described or any other security protection mechanism applicable as appropriate.

[0119] In some implementations, within the integrity protection mechanism, a protected PDU can be determined by applying an integrity protection algorithm to at least the header of the PDU to be protected. Based on the output of the integrity protection algorithm, a header signature (e.g., MAC-I) for the PDU's header can be determined, and the combination of the PDU and the header signature can be identified as the protected PDU.

[0120] When a protected PDU is obtained based on an integrity protection algorithm, the receiver can also perform integrity verification on the protected PDU based on the header signature. If the header signature is incorrect or missing, the protected PDU may be discarded by the receiver.

[0121] In some implementations, integrity protection algorithms may be applied only to the PDU header. In other implementations, integrity protection algorithms may be applied to the entire PDU. Protecting the entire PDU provides comprehensive protection. However, protecting only the PDU header minimizes the workload of the security protection process.

[0122] For PDUs such as MAC subPDUs or RLC PDUs, a MAC-I signature can be introduced and carried at the MAC subPDU or RLC PDU level. In some examples, the MAC-I may be calculated based solely on the header of the MAC subPDU or the header of the RLC. In another example, the MAC-I may be calculated based solely on the entire MAC subPDU including the MAC header or the entire RLC including the RLC header.

[0123] In some specific implementations, if integrity protection is applied to the entire PDU, i.e., MAC-I is calculated based on the entire PDU, then integrity protection in the upper layer will not be needed because the content of the upper-layer PDU is already protected by the integrity of the entire PDU in the lower layer. For example, if MAC-I is calculated based on the entire MAC subPDU, then integrity protection does not need to be applied in the PDCP and RLC layers.

[0124] In some implementations, the integrity protection algorithm may include integrity protection algorithms for 5G systems, such as 128-NIA1, 128-NIA2, or 128-NIA3. In other implementations, the integrity protection algorithm may include integrity protection algorithms for LTE or 3G systems, such as EIA1, EIA2, EIA3, UIA1, or UIA2. Those skilled in the art may apply any other possible integrity protection algorithm to the PDU header as appropriate.

[0125] The inputs to the integrity protection algorithm for the PDU header may include: the COUNT parameter; the DIRECTION parameter; the BEARER parameter; and the integrity protection key.

[0126] In some examples, the COUNT parameter of the integrity protection algorithm can be a fixed COUNT value. For example, the COUNT parameter of the integrity protection algorithm can be set to 0 or any other possible value. In some other examples, the COUNT parameter of the integrity protection algorithm can be a sequence number (SN) assigned in the lower layer. In still other examples, the COUNT parameter of the integrity protection algorithm can be determined as a random value. When the COUNT parameter of the integrity protection algorithm is a random value, the random value can be indicated to the peer entity. The random value can be indicated explicitly or implicitly. In the implicit way, the random value can be indicated by the index corresponding to the random value.

[0127] In some examples, the BEARER parameter of the integrity protection algorithm can be a fixed value. For example, the BEARER parameter of the integrity protection algorithm can be set to 0 or any other possible value. In some other examples, the BEARER parameter of the integrity protection algorithm can be a PDU type indicator. For example, the BEARER parameter of the integrity protection algorithm can be a value in a field of the PDU that indicates the type of the PDU to be protected. In still other examples, the BEARER parameter of the integrity protection algorithm can be a value in any other specified field of the PDU to be protected.

[0128] The DIRECTION parameter of the integrity protection algorithm can indicate either the uplink (UL) direction or the downlink (DL) direction. In some examples, the DIRECTION parameter of the integrity protection algorithm can be set to 0 to indicate the UL direction and to 1 to indicate the DL direction. Those skilled in the art can set the DIRECTION parameter of the integrity protection algorithm to any other possible value as appropriate.

[0129] Integrity protection keys may include integrity protection key K RRCint or K UPint (As shown in TS 38.300). K RRCint It can be a key derived from the base station for integrity protection of RRC signaling. K UPint It can be a key derived from the base station for integrity protection of UP communication traffic. Alternatively, those skilled in the art can derive the integrity protection key in any other possible manner depending on the specific circumstances.

[0130] According to the implementation of this application, by applying a protection algorithm to at least one PDU header in a sublayer below PDCP, improved protection is applied to the L2 PDU, and attacks on the L2 header can be effectively prevented.

[0131] In some implementation schemes, it can be based on the combination Figure 2 and Figure 3 The security protection mechanism shown is used to protect all control PDUs in sub-layers below SDAP. In some other implementations, it may not be necessary to apply security protection to all control PDUs.

[0132] Similarly, in some implementations, it can be based on the combination Figure 4 and Figure 5 The security protection mechanism shown is used to protect the headers of all PDUs in sublayers below PDCP. In some other implementations, it may not be necessary to apply security protection to the headers of all PDUs.

[0133] For example, in integrity protection mechanisms, signatures may not be carried in each packet.

[0134] At least one rule can be used to select the packet to be protected, control the PDU or either the header of the PDU.

[0135] In some implementations, the rules can be configured by network devices in the wireless communication system, and the UE in the wireless communication system can follow the rules configured by the NW to generate protected packets.

[0136] In some examples, the rules may include determining the packets to be protected based on a protection frequency during PDU transmission. For example, the protection frequency may be determined to be one every 10 packets. Therefore, one protected packet can be generated every 10 packets during transmission. Those skilled in the art can set the protection frequency to any other value as needed.

[0137] In some other examples, the rule may include generating a protected packet in a single transmission within the Uu interface, assuming that multiple packets will be delivered in the Uu interface at transmission time intervals (TTIs).

[0138] In other examples, the rules may include determining which packets to be protected is based on a protection period for protected packet transmissions. For example, protected packets may be generated every 10 seconds. Those skilled in the art can set the protection period for protected packet transmissions to any other value as appropriate.

[0139] In some other implementations, the NW of the wireless communication system can dynamically trigger protected packet transmission.

[0140] In some other implementations, the rules may include determining the packets to be protected in response to dynamic triggering. For example, a UE in a wireless communication system may receive a trigger indicating that security protection should be activated for the headers of control PDUs and / or PDUs in L2, so the UE may apply, in combination with, the headers of control PDUs and / or PDUs in L2. Figure 2 and Figure 4 The security protections described.

[0141] In some other implementations, the NW of the wireless communication system can be configured to enable security protection for at least one specified PDU type. For example, rules may include determining packets to be protected based on a specified PDU type. Based on the NW configuration, the transmitter of the wireless communication system can perform actions such as combining... Figure 2 and Figure 4 The security protections described.

[0142] At least one rule can be configured by the NW device of the wireless communication system.

[0143] When security protection is dynamically applied to an L2 PDU, an explicit indication of whether a packet is protected can be included in the packet. Therefore, peer entities can identify whether a received packet is protected. In some examples, a protected packet may include at least one bit indicating that the packet is protected. When integrity protection is applied to a packet, the protected packet may explicitly indicate the presence of MAC-I.

[0144] In some implementations, the UE in wireless communication can detect security risks. When the connection between the UE and the NW (Network Controller) is abnormal, the UE can detect the occurrence of a security problem. For example, if the UE detects a security problem in the connection between the UE and the NW in the communication system, the UE can report the security problem to the NW. The UE can also indicate to the NW the type of packet to be protected. Furthermore, if the UE detects a security problem in the connection between the UE and the NW in the communication system, the UE can trigger a UE connection re-establishment or trigger a Primary Cell Group (MCG) / Secondary Cell Group (SCG) fault procedure. Further security protections can be applied to the re-established connection.

[0145] Figure 6 Communication exchange combined with security protection is illustrated according to some embodiments of this disclosure.

[0146] At operation 603, base station 602 can transmit security protection activation to UE 601. Security protection activation enables security protection in L2 for the following transmissions between the UE and the base station.

[0147] Security protection activation can be transmitted via RRC messages or any other possible means for transmitting control information.

[0148] Then, security protection activation may also include configuration of parameters that may be necessary for security protection. For example, security protection activation may indicate the frequency of occurrence of protected packets, the type of protected packets, and the parameters required by the security protection algorithm.

[0149] At operation 604, the UE can perform transmissions using protected packets. The UE can generate protected packets (e.g., protected control PDUs or PDUs with protected headers). This can be based on, for example, combining... Figure 2 and Figure 4 The described method generates protected packets.

[0150] Figure 7 An exemplary block diagram of a transmitter apparatus according to some embodiments is shown. Figure 7 The device 700 shown can be used to achieve, for example, a combination Figure 2 Method 200 shown and combined as Figure 4 Method 400 is shown.

[0151] like Figure 7 As shown, the device 700 includes a generation unit 710, a security protection unit 720, and a transmission unit 730.

[0152] Regarding security protection of control PDUs, generation unit 710 can be configured to generate Protocol Data Units (PDUs) in Layer 2 (L2). Security protection unit 720 can be configured to perform security protection on control PDUs among the PDUs in L2 to obtain protected control PDUs for those control PDUs, wherein the control PDUs are in a sublayer below the Service Data Adaptation Protocol (SDAP). Transmission unit 730 can be configured to transmit the protected control PDUs.

[0153] Regarding security protection of the PDU header, generation unit 710 can be configured to generate Protocol Data Units (PDUs) in Layer 2 (L2). Security protection unit 720 can be configured to perform security protection on the header of one of the PDUs in L2 to obtain a protected PDU for that PDU, wherein the PDU is in a sublayer below the Packet Data Convergence Protocol (PDCP). Transmission unit 730 can be configured to transmit the protected PDU.

[0154] Figure 8 An exemplary block diagram of a receiver device according to some embodiments is shown. Figure 8 The device 800 shown can be used to achieve, for example, a combination Figure 3 The method 300 shown and how it is combined Figure 5 Method 500 is shown.

[0155] like Figure 8As shown, the device 800 includes a receiving unit 810.

[0156] Regarding security protection for control PDUs, receiving unit 810 can be configured as a protected control PDU in receiving layer 2 (L2), wherein the protected control PDU is obtained by performing security protection on control PDUs in a sublayer below the Service Data Adaptation Protocol (SDAP).

[0157] Regarding security protection of the PDU header, the receiving unit 810 can be configured to receive a protected PDU in Layer 2 (L2), wherein the protected PDU is obtained by performing security protection on at least the header of the PDU in a sublayer below the Packet Data Convergence Protocol (PDCP).

[0158] Figure 9 Example components of a device 900 according to some embodiments are shown. In some embodiments, device 900 may include at least application circuitry 902, baseband circuitry 904, radio frequency (RF) circuitry (shown as RF circuitry 920), front-end module (FEM) circuitry (shown as FEM circuitry 930), one or more antennas 932, and power management circuitry (PMC) (shown as PMC 934) coupled together as shown. Components of the illustrated device 900 may be included in a UE or RAN node. In some embodiments, device 900 may include fewer components (e.g., the RAN node may not utilize application circuitry 902, but instead include a processor / controller to process IP data received from the EPC). In some embodiments, device 900 may include additional components such as, for example, memory / storage devices, displays, cameras, sensors, or input / output (I / O) interfaces. In other embodiments, the components described below may be included in more than one device (e.g., the circuitry may be individually included in more than one device for a cloud-RAN (C-RAN) specific implementation).

[0159] Application circuitry 902 may include one or more application processors. For example, application circuitry 902 may include circuitry such as, but not limited to, one or more single-core or multi-core processors. The processor may include any combination of general-purpose processors and special-purpose processors (e.g., graphics processors, application processors, etc.). The processor may be coupled to or may include a memory / storage device and may be configured to execute instructions stored in the memory / storage device to enable various applications or operating systems to run on device 900. In some embodiments, the processor of application circuitry 902 may process IP data packets received from the EPC.

[0160] Baseband circuitry 904 may include circuitry such as, but not limited to, one or more single-core or multi-core processors. Baseband circuitry 904 may include one or more baseband processors or control logic components to process baseband signals received from the receive signal path of RF circuitry 920 and generate baseband signals for the transmit signal path of RF circuitry 920. Baseband circuitry 904 may interact with application circuitry 902 to generate and process baseband signals and control the operation of RF circuitry 920. For example, in some embodiments, baseband circuitry 904 may include a third-generation (3G) baseband processor (3G baseband processor 906), a fourth-generation (4G) baseband processor (4G baseband processor 908), a fifth-generation (5G) baseband processor (5G baseband processor 910), or other existing, under development, or future generations of baseband processors 912 (e.g., second-generation (2G), sixth-generation (6G), etc.). Baseband circuitry 904 (e.g., one or more baseband processors) can handle various radio control functions that enable communication with one or more radio networks via RF circuitry 920. In other embodiments, some or all of the functions of the illustrated baseband processor may be included in modules stored in memory 918 and executed via a central processing unit ETnit (CPET 914). Radio control functions may include, but are not limited to, signal modulation / demodulation, encoding / decoding, RF shifting, etc. In some embodiments, the modulation / demodulation circuitry of baseband circuitry 904 may include Fast Fourier Transform (FFT), precoding, or constellation mapping / demapping functions. In some embodiments, the encoding / decoding circuitry of baseband circuitry 904 may include convolution, tail-biting convolution, turbo, Viterbi, or low-density parity-check (LDPC) encoder / decoder functions. Implementations of modulation / demodulation and encoder / decoder functions are not limited to these examples, and other suitable functions may be included in other embodiments.

[0161] In some embodiments, the baseband circuitry 904 may include a digital signal processor (DSP), such as one or more audio DSPs 916. The one or more audio DSPs 916 may include elements for compression / decompression and echo cancellation, and in other embodiments may include other suitable processing elements. In some embodiments, components of the baseband circuitry may be suitably combined in a single chip, a single chipset, or disposed on the same circuit board. In some embodiments, some or all of the components of the baseband circuitry 904 and the application circuitry 902 may be implemented together, for example, on a system-on-a-chip (SoC).

[0162] In some implementations, baseband circuit 904 can provide communication compatible with one or more radio technologies. For example, in some implementations, baseband circuit 904 can support communication with the Evolved Universal Terrestrial Radio Access Network (EUTRAN) or other Wireless Metropolitan Area Networks (WMAN), Wireless Local Area Networks (WLAN), or Wireless Personal Area Networks (WPAN). Implementations in which baseband circuit 904 is configured to support radio communication with more than one radio protocol are referred to as multi-mode baseband circuits.

[0163] RF circuit 920 enables communication with a wireless network via a non-solid medium using modulated electromagnetic radiation. In various embodiments, RF circuit 920 may include switches, filters, amplifiers, etc., to facilitate communication with the wireless network. RF circuit 920 may include a receive signal path that includes circuitry for down-converting the RF signal received from FEM circuit 930 and providing a baseband signal to baseband circuit 904. RF circuit 920 may also include a transmit signal path that includes circuitry for up-converting the baseband signal provided by baseband circuit 904 and providing an RF output signal for transmission to FEM circuit 930.

[0164] In some embodiments, the receive signal path of RF circuit 920 may include mixer circuit 922, amplifier circuit 924, and filter circuit 926. In some embodiments, the transmit signal path of RF circuit 920 may include filter circuit 926 and mixer circuit 922. RF circuit 920 may also include synthesizer circuit 928 for synthesizing frequencies used by mixer circuit 922 for both the receive and transmit signal paths. In some embodiments, mixer circuit 922 for the receive signal path may be configured to down-convert the RF signal received from FEM circuit 930 based on the synthesized frequency provided by synthesizer circuit 928. Amplifier circuit 924 may be configured to amplify the down-converted signal, and filter circuit 926 may be a low-pass filter (LPF) or band-pass filter (BPF) configured to remove unwanted signals from the down-converted signal to generate an output baseband signal. The output baseband signal may be provided to baseband circuit 904 for further processing. In some embodiments, although not required, the output baseband signal may be a zero-frequency baseband signal. In some implementations, the mixer circuit 922 for receiving the signal path may include a passive mixer, but the scope of the implementation is not limited in this respect.

[0165] In some implementations, the mixer circuit 922 of the transmit signal path may be configured to up-convert the input baseband signal based on the synthesized frequency provided by the synthesizer circuit 928 to generate an RF output signal for the FEM circuit 930. The baseband signal may be provided by the baseband circuit 904 and may be filtered by the filter circuit 926.

[0166] In some embodiments, the mixer circuit 922 for the receive signal path and the mixer circuit 922 for the transmit signal path may include two or more mixers and may be arranged for quadrature downconversion and upconversion, respectively. In some embodiments, the mixer circuit 922 for the receive signal path and the mixer circuit 922 for the transmit signal path may include two or more mixers and may be arranged for image rejection (e.g., Hartley image rejection). In some embodiments, the mixer circuit 922 for the receive signal path and the mixer circuit 922 may be arranged for direct downconversion and direct upconversion, respectively. In some embodiments, the mixer circuit 922 for the receive signal path and the mixer circuit 922 for the transmit signal path may be configured for superheterodyne operation.

[0167] In some embodiments, the output baseband signal and the input baseband signal may be analog baseband signals, although the scope of the embodiments is not limited in this respect. In some alternative embodiments, the output baseband signal and the input baseband signal may be digital baseband signals. In these alternative embodiments, the RF circuit 920 may include analog-to-digital converter (ADC) and digital-to-analog converter (DAC) circuitry, and the baseband circuit 904 may include a digital baseband interface for communicating with the RF circuit 920.

[0168] In some dual-mode implementations, separate radio IC circuits can be provided to process signals for each spectrum, but the scope of the implementation is not limited in this respect.

[0169] In some implementations, synthesizer circuit 928 may be a fractional N synthesizer or a fractional N / N+1 synthesizer, but the scope of implementations is not limited in this respect, as other types of frequency synthesizers may also be suitable. For example, synthesizer circuit 928 may be a Δ-Σ synthesizer, a frequency multiplier, or a synthesizer including a phase-locked loop with a frequency divider.

[0170] Synthesizer circuit 928 can be configured to synthesize an output frequency based on the frequency input and the divider control input for use by mixer circuit 922 of RF circuit 920. In some embodiments, synthesizer circuit 928 may be a fractional N / N+1 synthesizer.

[0171] In some implementations, the frequency input may be provided by a voltage-controlled oscillator (VCO), although this is not mandatory. The divider control input may be provided by baseband circuitry 904 or application circuitry 902 (such as an application processor) according to the desired output frequency. In some implementations, the divider control input (e.g., N) may be determined from a lookup table based on the channel indicated by application circuitry 902.

[0172] The synthesizer circuit 928 of the RF circuit 920 may include a frequency divider, a delay-locked loop (DLL), a multiplexer, and a phase accumulator. In some embodiments, the frequency divider may be a dual-mode divider (DMD), and the phase accumulator may be a digital phase accumulator (DPA). In some embodiments, the DMD may be configured to divide the input signal by N or N+1 (e.g., based on carry) to provide a fractional division ratio. In some example embodiments, the DLL may include a cascaded, tunable delay element, a phase detector, a charge pump, and a set of D-type flip-flops. In these embodiments, the delay elements may be configured to divide the VCO cycle into Nd equal phase groups, where Nd is the number of delay elements in the delay line. Thus, the DLL provides negative feedback to help ensure that the total delay through the delay line is one VCO cycle.

[0173] In some embodiments, synthesizer circuitry 928 may be configured to generate a carrier frequency as the output frequency, while in other embodiments, the output frequency may be a multiple of the carrier frequency (e.g., twice the carrier frequency, four times the carrier frequency) and used in conjunction with quadrature generator and frequency divider circuitry to generate multiple signals having multiple different phases relative to each other at the carrier frequency. In some embodiments, the output frequency may be the LO frequency (fLO). In some embodiments, RF circuitry 920 may include an IQ / polarity converter.

[0174] FEM circuit 930 may include a receive signal path, which may include circuitry configured to operate on RF signals received from one or more antennas 932, amplify the received signals, and provide an amplified version of the received signals to RF circuit 920 for further processing. FEM circuit 930 may also include a transmit signal path, which may include circuitry configured to amplify transmit signals provided by RF circuit 920 for transmission by one or more of the one or more antennas 932. In various embodiments, amplification via the transmit or receive signal path may be performed only in RF circuit 920, only in FEM circuit 930, or in both RF circuit 920 and FEM circuit 930.

[0175] In some embodiments, FEM circuit 930 may include a TX / RX switch to switch between transmit and receive mode operation. FEM circuit 930 may include a receive signal path and a transmit signal path. The receive signal path of FEM circuit 930 may include an LNA to amplify the received RF signal and provide the amplified received RF signal as an output (e.g., to RF circuit 920). The transmit signal path of FEM circuit 930 may include a power amplifier (PA) to amplify the input RF signal (e.g., provided by RF circuit 920), and one or more filters to generate an RF signal for subsequent transmission (e.g., through one or more antennas in one or more antennas 932).

[0176] In some implementations, the PMC 934 manages the power supplied to the baseband circuitry 904. Specifically, the PMC 934 can control power selection, voltage scaling, battery charging, or DC-DC conversion. The PMC 934 is typically included when the device 900 is capable of being battery powered, for example, when the device 900 is included in an EGE. The PMC 934 can improve power conversion efficiency while providing the desired implementation size and thermal characteristics.

[0177] Figure 9 The PMC 934 is shown coupled only to the baseband circuit 904. However, in other embodiments, the PMC 934 may additionally or alternatively be coupled to other components (such as, but not limited to, the application circuit 902, the RF circuit 920, or the FEM circuit 930) and perform similar power management operations for those components.

[0178] In some implementations, the PMC 934 can control or otherwise become part of various power-saving mechanisms of the device 900. For example, if the device 900 is in an RRC connected state, where it remains connected to the RAN node because it expects to receive communication soon, the device can enter a state called Discontinuous Receive Mode (DRX) after an inactive period. During this state, the device 900 can be powered down for short intervals, thereby saving power.

[0179] If there is no data service activity during the extended period, device 900 can transition to RRC Idle state. In RRC Idle state, the device is disconnected from the network and does not perform operations such as channel quality feedback or handover. Device 900 enters a very low power state and performs paging. In this very low power state, the device periodically wakes up again to listen to the network and then powers off again. Device 900 cannot receive data in this state, and in order to receive data, the device transitions back to RRC Connected state.

[0180] An additional power-saving mode allows the device to be unavailable from the network for periods exceeding the paging interval (ranging from seconds to hours). During this time, the device is completely unconnected to the network and can be completely powered off. Any data sent during this period will incur significant latency, which is assumed to be acceptable.

[0181] The processors of application circuitry 902 and baseband circuitry 904 are elements that can be used to execute one or more instances of the protocol stack. For example, the processor of baseband circuitry 904 can be used alone or in combination to execute layer 3, layer 2, or layer 1 functions, while the processor of application circuitry 902 can utilize data received from these layers (e.g., packet data) and further execute layer 4 functions (e.g., Transport Communication Protocol (TCP) and User Datagram Protocol (UDP) layers). As mentioned herein, layer 3 may include the Radio Resource Control (RRC) layer, which will be described in further detail below. As mentioned herein, layer 2 may include the Media Access Control (MAC) layer, Radio Link Control (RLC) layer, and Packet Data Convergence Protocol (PDCP) layer, which will be described in further detail below. As mentioned herein, layer 1 may include the physical (PHY) layer of the UE / RAN node, which will be described in further detail below.

[0182] Figure 10 An exemplary interface 1000 of a baseband circuit according to some embodiments is shown. As discussed above, Figure 9 The baseband circuitry 904 may include a 3G baseband processor 906, a 4G baseband processor 908, a 5G baseband processor 910, other baseband processors 912, a CPU 914, and a memory 918 utilized by the processors. As shown, each of these processors may include a corresponding memory interface 1002 to send data to / receive data from the memory 918.

[0183] The baseband circuit 904 may also include one or more interfaces for communicatively coupling to other circuits / devices, such as a memory interface 1004 (e.g., an interface for sending / receiving data to / from a memory external to the baseband circuit 904) or an application circuit interface 1006 (e.g., an interface for sending / receiving data to / from a memory external to the baseband circuit 904). Figure 9 Application circuit 902 (interface for sending / receiving data), RF circuit interface 1008 (e.g., for sending / receiving data to / from...). Figure 9 The RF circuit 920 is an interface for transmitting / receiving data, and the wireless hardware connection interface 1010 is used for transmitting / receiving data to / from near field communication (NFC) components. Components (e.g.) (low power consumption) Interfaces for sending / receiving data to / from components and other communication components) and power management interface 1012 (e.g., an interface for sending / receiving power or control signals to / from PMC 934).

[0184] Figure 11 This is a block diagram illustrating a component 1100, according to some exemplary embodiments, capable of reading instructions from a machine-readable or computer-readable medium (e.g., a non-transitory machine-readable storage medium) and capable of executing any one or more of the methods discussed herein. Specifically, Figure 11 A schematic representation of hardware resources 1102 is shown, including one or more processors 1112 (or processor cores), one or more memory / storage devices 1118, and one or more communication resources 1120, each of which is communicatively coupled via bus 1122. For implementations utilizing node virtualization (e.g., NFV), an executable hypervisor 1104 provides an execution environment for one or more network slices / subslices to utilize hardware resources 1102.

[0185] Processor 1112 (e.g., a central processing unit (CPU), a reduced instruction set computing (RISC) processor, a complex instruction set computing (CISC) processor, a graphics processing unit (GPU), a digital signal processor (DSP) (such as a baseband processor), an application-specific integrated circuit (ASIC), a radio frequency integrated circuit (RFIC), another processor, or any suitable combination thereof) may include, for example, processor 1114 and processor 1116.

[0186] The memory / storage device 1118 may include main memory, disk storage, or any suitable combination thereof. The memory / storage device 1118 may include, but is not limited to, any type of volatile or non-volatile memory, such as dynamic random access memory (DRAM), static random access memory (SRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, solid-state storage devices, etc.

[0187] Communication resource 1120 may include interconnect or network interface components or other suitable devices for communicating with one or more peripheral devices 1106 or one or more databases 1108 via network 1110. For example, communication resource 1120 may include wired communication components (e.g., for coupling via Universal Serial Bus (USB), cellular communication components, NFC components, etc. Components (e.g.) (low power consumption) Components and other communication components.

[0188] Instructions 1124 may include software, programs, applications, applets, or other executable code for causing at least one processor in processor 1112 to perform one or more of the methods discussed herein. Instructions 1124 may reside wholly or partially within processor 1112 (e.g., within the processor's cache memory), memory / storage device 1118, or at least one of any suitable combination thereof. Furthermore, any portion of instructions 1124 may be transferred from any combination of peripheral device 1106 or database 1108 to hardware resource 1102. Therefore, the memory of processor 1112, memory / storage device 1118, peripheral device 1106, and database 1108 are examples of computer-readable and machine-readable media.

[0189] For one or more embodiments, at least one of the components shown in one or more of the foregoing figures may be configured to perform one or more operations, techniques, processes, and / or methods as described in the Examples section below. For example, the baseband circuitry described above in conjunction with one or more of the foregoing figures may be configured to operate according to one or more of the examples below. As another example, circuitry associated with the UE, base station, network element, etc., described above in conjunction with one or more of the foregoing figures may be configured to operate according to one or more of the examples shown in the Examples section below.

[0190] Figure 12 The architecture of a system 1200 of a network according to some embodiments is shown. System 1200 includes one or more user equipment (UEs), shown in this example as UE 1202 and UE 1204. UE 1202 and UE 1204 are shown as smartphones (e.g., handheld touchscreen mobile computing devices that can connect to one or more cellular networks), but it may also include any mobile or non-mobile computing device, such as a personal data assistant (PDA), pager, laptop computer, desktop computer, wireless handheld terminal, or any computing device that includes a wireless communication interface.

[0191] In some implementations, either UE 1202 or UE 1204 may include an Internet of Things (IoT) UE, which may include a network access layer designed to utilize low-power IoT applications with short-lived UE connectivity. The IoT UE may exchange data with an MTC server or device via technologies such as machine-to-machine (M2M) or machine-type communication (MTC), through a Public Land Mobile Network (PLMN), Proximity-Based Service (ProSe) or Device-to-Device (D2D) communication, sensor networks, or an IoT network. M2M or MTC data exchange may be machine-initiated data exchange. An IoT network describes interconnected IoT UEs, which may include uniquely identifiable embedded computing devices (within the Internet infrastructure) with short-lived connectivity. The IoT UE may execute background applications (e.g., keeping track of activity messages, status updates, etc.) to facilitate connectivity within the IoT network.

[0192] UE 1202 and UE 1204 can be configured to connect (e.g., communicatively coupled) to a radio access network (RAN) (shown as RAN 1206). RAN 1206 can be, for example, an Evolved Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (E-UTRAN), a Next Generation RAN (NG RAN), or some other type of RAN. UE 1202 and UE 1204 utilize connection 1208 and connection 1210, respectively, where each connection includes a physical communication interface or layer (discussed in further detail below); in this example, connection 1208 and connection 1210 are shown as air interfaces for communicative coupling and can be consistent with cellular communication protocols such as Global System for Mobile Communications (GSM), Code Division Multiple Access (CDMA) network protocols, Push-to-Talk (PTT) protocols, Cellular PTT protocols (POC), Universal Mobile Telecommunications System (UMTS) protocols, 3GPP Long Term Evolution (LTE) protocols, 5G protocols, New Radio (NR) protocols, etc.

[0193] In this implementation, UE 1202 and UE 1204 can also directly exchange communication data via ProSe interface 1212. ProSe interface 1212 may alternatively be referred to as a sidelink interface including one or more logical channels, including but not limited to the Physical Sidelink Control Channel (PSCCH), Physical Sidelink Shared Channel (PSSCH), Physical Sidelink Discovery Channel (PSDCH), and Physical Sidelink Broadcast Channel (PSBCH).

[0194] UE 1204 is shown configured to access an access point (AP) (shown as AP 1214) via connection 1216. Connection 1216 can include local wireless connectivity, such as a connection consistent with any IEEE 802.11 protocol, while AP 1214 will include Wireless Fidelity. Router. In this example, AP 1214 can connect to the Internet without connecting to the core network of the wireless system (described in further detail below).

[0195] RAN 1206 may include one or more access nodes that enable connections 1208 and 1210. These access nodes (ANs) may be referred to as base stations (BS), node Bs, evolved Node Bs (eNBs), next-generation Node Bs (gNBs), RAN nodes, etc., and may include ground stations (e.g., terrestrial access points) or satellite stations that provide coverage within a geographic area (e.g., a cell). RAN 1206 may include one or more RAN nodes for providing macrocells, such as macro RAN node 1218, and one or more RAN nodes for providing femtocells or picocells (e.g., cells with smaller coverage, smaller user capacity, or higher bandwidth compared to macrocells), such as low-power (LP) RAN nodes (e.g., LP RAN node 1220).

[0196] Either macro RAN node 1218 or LP RAN node 1220 can terminate the air interface protocol and can be the first point of contact for UE 1202 and UE 1204. In some implementations, either macro RAN node 1218 or LP RAN node 1220 can fulfill various logical functions of RAN 1206, including but not limited to the functions of a radio network controller (RNC), such as radio bearer management, uplink and downlink dynamic radio resource management, data packet scheduling, and mobility management.

[0197] According to some implementations, UE 1202 and UE 1204 can be configured to communicate with each other or with either macro RAN node 1218 or LP RAN node 1220 on a multi-carrier communication channel using orthogonal frequency division multiplexing (OFDM) communication signals based on various communication technologies, such as, but not limited to, orthogonal frequency division multiple access (OFDMA) communication technology (e.g., for downlink communication) or single-carrier frequency division multiple access (SC-FDMA) communication technology (e.g., for uplink and ProSe or sidelink communication)). However, the scope of the implementation is not limited in this respect. The OFDM signal may include multiple orthogonal subcarriers.

[0198] In some implementations, the downlink resource grid can be used for downlink transmissions from either RAN node 1218 or LP RAN node 1220 to UE 1202 and UE 1204, while uplink transmissions can utilize similar techniques. The grid can be a time-frequency grid, referred to as a resource grid or time-frequency resource grid, which represents the physical resources in the downlink within each time slot. This time-frequency plane representation is common practice for OFDM systems, making radio resource allocation intuitive. Each column and row of the resource grid corresponds to an OFDM symbol and an OFDM subcarrier, respectively. The duration of the resource grid in the time domain corresponds to a time slot in a radio frame. The smallest time-frequency unit in the resource grid is represented as a resource element. Each resource grid comprises multiple resource blocks that describe the mapping of certain physical channels to resource elements. Each resource block comprises a set of resource elements; in the frequency domain, this can represent the minimum amount of resources currently available for allocation. Such resource blocks are used to transmit several different physical downlink channels.

[0199] The Physical Downlink Shared Channel (PDSCH) can carry user data and higher-layer signaling to UE 1202 and UE 1204. The Physical Downlink Control Channel (PDCCH) can carry information such as the transmission format and resource allocation related to the PDSCH channel. The PDCCH can also inform UE 1202 and UE 1204 of the transmission format, resource allocation, and H-ARQ (Hybrid Automatic Repeat Request) information related to the uplink shared channel. Typically, downlink scheduling (allocating control and shared channel resource blocks to UE 1204 within the cell) can be performed at either macro RAN node 1218 or LP RAN node 1220 based on channel quality information fed back from either UE 1202 or UE 1204. Downlink resource allocation information can be transmitted on the PDCCH used for (e.g., allocated to) each of UE 1202 and UE 1204.

[0200] PDCCH can use Control Channel Elements (CCEs) to transmit control information. Before being mapped to resource elements, the complex-valued symbols of the PDCCH are first organized into quadruplets, which are then arranged using a sub-block interleaver for rate matching. One or more of these CCEs can be used to transmit each PDCCH, where each CCE can correspond to a set of four physical resource elements (REGs) of nine. Four Quadrature Phase Shift Keying (QPSK) symbols can be mapped to each REG. Depending on the size of the Downlink Control Information (DCI) and channel conditions, one or more CCEs can be used to transmit the PDCCH. In LTE, four or more different PDCCH formats with different numbers of CCEs (e.g., aggregation levels, L = 1, 2, 4, or 8) can exist.

[0201] Some implementations may use the concept of resource allocation for control channel information, which is an extension of the above concept. For example, some implementations may utilize an enhanced physical downlink control channel (EPDCCH) that uses PDSCH resources for control information transmission. EPDCCH may be transmitted using one or more enhanced control channel elements (ECCEs). Similarly, each ECCE may correspond to a set of nine physical resource elements, referred to as an enhanced resource element group (EREG). In some cases, an ECCE may have a different number of EREGs.

[0202] RAN 1206 is communicatively coupled to the core network (CN) (shown as CN 1228) via S1 interface 1222. In this implementation, CN 1228 may be an evolved packet core (EPC) network, a next-generation packet core (NPC) network, or some other type of CN. In this implementation, S1 interface 1222 is divided into two parts: S1-U interface 1224, which carries service data between macro RAN node 1218 and LP RAN node 1220 and the serving gateway (S-GW) (shown as S-GW 1232); and S1-Mobility Management Entity (MME) interface (shown as S1-MME interface 1226), which is the signaling interface between macro RAN node 1218 and LP RAN node 1220 and MME 1230.

[0203] In this implementation, CN 1228 includes an MME 1230, an S-GW 1232, a Packet Data Network (PDN) Gateway (P-GW) (shown as P-GW 1234), and a Home Subscriber Server (HSS) (shown as HSS 1236). The MME 1230 can functionally resemble the control plane of a legacy General Packet Radio Service (GPRS) Support Node (SGSN). The MME 1230 can manage access-related mobility aspects such as gateway selection and tracking area list management. The HSS 1236 may include a database for network users, containing subscription-related information for supporting the handling of communication sessions for network entities. Depending on the number of mobile subscribers, equipment capacity, network organization, etc., CN 1228 may include one or more HSS 1236s. For example, the HSS 1236 may provide support for routing / roaming, authentication, authorization, naming / addressing resolution, location correlation, etc.

[0204] The S-GW 1232 can terminate the S1 interface 322 toward RAN 1206 and route data packets between RAN 1206 and CN 1228. Additionally, the S-GW 1232 can serve as a local mobility anchor for inter-RAN node handover and can also provide an anchor for inter-3GPP mobility. Other responsibilities may include lawful interception, billing, and enforcement of certain policies.

[0205] P-GW 1234 can terminate the SGi interface toward the PDN. P-GW 1234 can route data packets between CN 1228 (e.g., an EPC network) and external networks (such as a network including application server 1242 (alternatively referred to as application function (AF)) via an Internet Protocol (IP) interface (shown as IP communication interface 1238). Generally, application server 1242 can be an element that provides applications that use IP bearer resources with the core network (e.g., ETMTS Packet Service (PS) domain, LTE PS data service, etc.). In this embodiment, P-GW 1234 is shown communicatively coupled to application server 1242 via IP communication interface 1238. Application server 1242 can also be configured to support one or more communication services (e.g., Voice over Internet Protocol (VoIP) sessions, PTT sessions, group communication sessions, social networking services, etc.) for UE 1202 and UE 1204 via CN 1228.

[0206] P-GW 1234 can also be a node for policy enforcement and charging data collection. The Policy and Charging Enforcement Function (PCRF) (shown as PCRF 1240) is the policy and charging control element of CN 1228. In non-roaming scenarios, a single PCRF may exist in the domestic public land mobile network (HPLMN) associated with the ETE's Internet Protocol Connectivity Access Network (IP-CAN) session. In roaming scenarios with local traffic breaches, two PCRFs may exist associated with the UE's IP-CAN session: the domestic PCRF in the HPLMN (H-PCRF) and the visited PCRF in the visited public land mobile network (VPLMN) (V-PCRF). PCRF 1240 can be communicatively coupled to application server 1242 via P-GW 1234. Application server 1242 can signal PCRF 1240 to indicate new service flows and select appropriate Quality of Service (QoS) and charging parameters. PCRF 1240 can provide this rule to a Policy and Charging Enforcement Function (PCEF) (not shown) with an appropriate Flow Template (TFT) and QoS Category Identifier (QCI), which begins with QoS and charging specified by application server 1242.

[0207] Additional Examples

[0208] For one or more embodiments, at least one of the components shown in one or more of the foregoing figures may be configured to perform one or more operations, techniques, processes, and / or methods as described in the Examples section below. For example, the baseband circuitry described above in conjunction with one or more of the foregoing figures may be configured to operate according to one or more of the examples below. As another example, circuitry associated with the UE, base station, network element, etc., described above in conjunction with one or more of the foregoing figures may be configured to operate according to one or more of the examples shown in the Examples section below.

[0209] The following examples relate to other implementation schemes.

[0210] Example 1 is a method for a transmitter in a wireless communication system, the method comprising: generating a Protocol Data Unit (PDU) in Layer 2 (L2); performing security protection on a control PDU in the PDU in L2 to obtain a protected control PDU for the control PDU, wherein the control PDU is in a sublayer below the Service Data Adaptation Protocol (SDAP); and transmitting the protected control PDU.

[0211] Example 2 is based on the method described in Example 1, wherein a protected control PDU is obtained by the following steps: applying an integrity protection algorithm to the control PDU; determining a signature for the control PDU; and determining a combination of the control PDU and the signature as a protected control PDU.

[0212] Example 3 is based on the method described in Example 2, wherein the inputs to the integrity protection algorithm include: COUNT parameter; DIRECTION parameter; BEARER parameter; and integrity protection key.

[0213] Example 4 is based on the method described in Example 1, wherein a protected control PDU is obtained by the following steps: applying an encryption algorithm to the control PDU; and determining the output of the encryption algorithm as the protected control PDU.

[0214] Example 5 is the method described in Example 4, wherein the inputs to the encryption algorithm include: a COUNT parameter; a DIRECTION parameter; a BEARER parameter; and an encryption key.

[0215] Example 6 is the method according to Example 3 or 5, wherein the COUNT parameter is one of the following: a fixed COUNT value; a sequence number (SN) assigned in the lower layer; or a random value.

[0216] Example 7 is the method according to Example 3 or 5, wherein the BEARER parameter is one of the following: a fixed BEARER value; a control PDU type indicator; or a value in a specified field of the PDU.

[0217] Example 8 is based on the method described in Example 1, wherein the protected control PDU is obtained through the following steps: applying a HASH algorithm to the control PDU; and determining the protected control PDU based on the output of the HASH algorithm.

[0218] Example 9 is the method according to Example 8, wherein the input to the HASH algorithm is a control PDU and an additional random value.

[0219] Example 10 is a method according to any one of Examples 1 to 9, wherein the control PDU is determined based on at least one of the following rules: determining the control PDU to be protected based on the protection frequency in the PDU transmission; determining a protected control PDU in a transmission in the Uu interface; determining the control PDU to be protected based on the protection period; determining the control PDU to be protected in response to dynamic triggering; or determining the control PDU to be protected by a specified PDU type.

[0220] Example 11 is the method according to Example 10, wherein at least one rule is configured by a network device of a wireless communication system.

[0221] Example 12 is the method according to Example 11 or 12, wherein the protected control PDU includes at least one bit indicating that the control PDU is protected.

[0222] Example 13 is a method according to any one of Examples 1 to 12, wherein the user equipment (UE) of the wireless communication system reports a security problem to the network device of the wireless communication system.

[0223] Example 14 is a method according to Example 13, in which the UE transmits recommendation information indicating the type of control PDU to be protected.

[0224] Example 15 describes the process by which the UE triggers a UE connection re-establishment or a primary cell group (MCG) / secondary cell group (SCG) failure, according to the method described in Example 13.

[0225] Example 16 is a method for a receiver in a wireless communication system, the method comprising: a protected control PDU in a receiver layer 2 (L2), wherein the protected control PDU is obtained by performing security protection on a control PDU in a sublayer below the Service Data Adaptation Protocol (SDAP).

[0226] Example 17 is the method according to Example 16, wherein a protected control PDU is obtained by the following steps: applying an integrity protection algorithm to the control PDU; determining a signature for the control PDU; and determining a combination of the control PDU and the signature as a protected control PDU.

[0227] Example 18 is the method according to Example 17, wherein the inputs to the integrity protection algorithm include: COUNT parameter; DIRECTION parameter; BEARER parameter; and integrity protection key.

[0228] Example 19 is the method according to Example 16, wherein a protected control PDU is obtained by the following steps: applying an encryption algorithm to the control PDU; and determining the output of the encryption algorithm as the protected control PDU.

[0229] Example 20 is the method according to Example 19, wherein the inputs to the encryption algorithm include: a COUNT parameter; a DIRECTION parameter; a BEARER parameter; and an encryption key.

[0230] Example 21 is the method according to Example 18 or 20, wherein the COUNT parameter is one of the following: a fixed COUNT value; a sequence number (SN) assigned in the lower layer; or a random value.

[0231] Example 22 is the method according to Example 18 or 20, wherein the BEARER parameter is one of the following: a fixed BEARER value; a control PDU type indicator; or a value in a specified field of the PDU.

[0232] Example 23 is the method according to Example 16, wherein the protected control PDU is obtained by the following steps: applying a HASH algorithm to the control PDU; and determining the protected control PDU based on the output of the HASH algorithm.

[0233] Example 24 is the method according to Example 23, wherein the input to the HASH algorithm is a control PDU and an additional random value.

[0234] Example 25 is the method according to Example 17, further comprising:

[0235] Integrity verification is performed on protected control PDUs based on signatures.

[0236] Example 26 is the method according to Example 19, further comprising: determining the control PDU by applying a corresponding decryption algorithm to the protected control PDU.

[0237] Example 27 is the method according to Example 23, further comprising: determining the control PDU by applying a reverse HASH algorithm to the protected control PDU.

[0238] Example 28 is a method for a transmitter in a wireless communication system, the method comprising: generating a Protocol Data Unit (PDU) in Layer 2 (L2); performing security protection on the header of one of the PDUs in L2 to obtain a protected PDU for that PDU, wherein the PDU is in a sublayer below the Packet Data Convergence Protocol (PDCP); and transmitting the protected PDU.

[0239] Example 29 is the method according to Example 28, wherein a protected PDU is obtained by the following steps: applying an integrity protection algorithm to at least the header of the PDU; determining a header signature for the header of the PDU; and determining a combination of the PDU and the header signature as a protected PDU.

[0240] Example 30 is the method according to Example 29, wherein applying an integrity protection algorithm to at least the header of the PDU includes: applying the integrity protection algorithm to the header only or to the entire PDU.

[0241] Example 31 is a method according to any one of Examples 28 to 30, wherein the PDU is a Radio Link Control (RLC) PDU or a Media Access Control (MAC) subPDU.

[0242] Example 32 is a method according to any one of Examples 28 to 31, wherein the PDU to be protected in L2 is determined based on at least one of the following rules: determining the PDU to be protected based on the protection frequency in PDU transmission; determining a protected PDU in a transmission in the Uu interface; determining the PDU to be protected based on the protection period; determining the PDU to be protected in response to dynamic triggering; or determining the PDU to be protected by a specified PDU type.

[0243] Example 33 is the method according to Example 32, wherein at least one rule is configured by a network device of a wireless communication system.

[0244] Example 34 is the method according to Example 32 or 33, wherein the protected PDU includes at least one bit indicating that the PDU is protected.

[0245] Example 35 is a method according to any one of Examples 28 to 34, wherein the user equipment (UE) of the wireless communication system reports a security problem to the network device of the wireless communication system.

[0246] Example 36 is a method according to Example 35, in which the UE transmits recommendation information indicating the type of PDU to be protected.

[0247] Example 37 describes the process by which the UE triggers a UE connection re-establishment or a primary cell group (MCG) / secondary cell group (SCG) failure, according to the method described in Example 35.

[0248] Example 38 is a method for a receiver in a wireless communication system, the method comprising: a protected PDU in a receiving layer 2 (L2), wherein the protected PDU is obtained by performing security protection on at least the header of the PDU in a sublayer below the Packet Data Convergence Protocol (PDCP).

[0249] Example 39 is the method according to Example 38, wherein a protected PDU is obtained by the following steps: applying an integrity protection algorithm to at least the header of the PDU; determining a header signature for the header of the PDU; and determining a combination of the PDU and the header signature as a protected PDU.

[0250] Example 40 is the method according to Example 39, wherein applying an integrity protection algorithm to at least the header of the PDU includes: applying the integrity protection algorithm to the header only or to the entire PDU.

[0251] Example 41 is the method according to Example 40, further comprising: performing integrity verification on the protected PDU based on the header signature.

[0252] Example 42 is an apparatus for a transmitter, the apparatus comprising: one or more processors configured to perform the steps of the method according to any one of Examples 1 to 15 and 28 to 37.

[0253] Example 43 is an apparatus for a receiver, the apparatus comprising: one or more processors configured to perform the steps of the method according to any one of Examples 16 to 27 and 38 to 41.

[0254] Example 44 is a computer-readable medium having stored thereon computer programs that, when executed by one or more processors of the device, cause the device to perform the steps of the method according to any one of Examples 1 to 41.

[0255] Example 45 is a computer program product comprising a computer program that, when executed by one or more processors of a device, causes the device to perform the steps of the method according to any one of Examples 1-41.

[0256] Unless otherwise expressly stated, any of the above embodiments may be combined with any other embodiment (or combination of embodiments). The foregoing description of one or more specific embodiments provides illustration and description, but is not intended to be exhaustive or to limit the scope of the embodiments to the precise forms disclosed. In view of the teachings above, modifications and variations are possible, or modifications and variations may be obtained from the practice of various embodiments.

[0257] It should be recognized that the systems described herein include descriptions of specific implementations. These implementations may be combined into a single system, partially integrated into other systems, divided into multiple systems, or otherwise partitioned or combined. Furthermore, it is conceivable to use parameters / attributes / aspects, etc., of one implementation in another implementation. For clarity, these parameters / attributes / aspects, etc., are described only in one or more implementations, and it should be recognized that unless specifically stated herein, these parameters / attributes / aspects, etc., may be combined with or replace parameters / attributes, etc., of another implementation.

[0258] As is widely recognized, the use of personally identifiable information should comply with privacy policies and practices that are generally accepted to meet or exceed industry or governmental requirements for protecting user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of unintentional or unauthorized access or use, and the nature of authorized use should be clearly explained to users.

[0259] Although the foregoing has been described in considerable detail for clarity, it will be apparent that certain changes and modifications can be made without departing from the principles of the invention. It should be noted that many alternative ways exist to implement both the processes and apparatus described herein. Therefore, embodiments of the invention should be considered illustrative rather than restrictive, and this specification is not limited to the details given herein, but can be modified within the scope of the appended claims and their equivalents.

Claims

1. A method for wireless communication, the method comprising: Generate Protocol Data Units (PDUs) in Layer 2 (L2); Security protection is performed on the control PDU in L2 to obtain a protected control PDU for the control PDU, wherein the control PDU is in a sublayer below the Service Data Adaptation Protocol (SDAP) layer; as well as Transmit the protected control PDU.

2. The method of claim 1, wherein the protected control PDU is obtained by: An integrity protection algorithm is applied to the control PDU; Determine the signature for the control PDU; and The protected control PDU is assembled into a combination including the control PDU and the signature as the protected control PDU.

3. The method according to claim 2, wherein the inputs to the integrity protection algorithm include: COUNT parameter; DIRECTION parameters; BEARER parameters; as well as Integrity protection key.

4. The method of claim 1, wherein the protected control PDU is obtained by: An encryption algorithm is applied to the control PDU; and The output of the encryption algorithm is determined as the protected control PDU.

5. The method according to claim 4, wherein the input to the encryption algorithm includes: COUNT parameter; DIRECTION parameters; BEARER parameters; as well as Encryption key.

6. The method according to claim 3 or 5, wherein the COUNT parameter is: Fixed COUNT value; The serial number (SN) assigned in the lower layer; or Random value.

7. The method according to claim 3 or 5, wherein the BEARER parameter is: Fixed BEARER value; Control PDU type indication; or The values ​​in the fields of the control PDU.

8. The method of claim 1, wherein the protected control PDU is obtained by: A hash algorithm is applied to the control PDU; and The protected control PDU is determined based on the output of the HASH algorithm.

9. The method of claim 8, wherein the input to the HASH algorithm is the control PDU and an additional random value.

10. The method according to any one of claims 1 to 5, wherein the control PDU is determined based on a rule associated with the following: Protection frequency in PDU transmission; In the Uu interface, a protected control PDU is determined in a transmission; Protection period; Dynamic triggering; or Specify the PDU type.

11. The method of claim 10, wherein the rule is configured by a network device of the wireless communication system.

12. The method according to any one of claims 1 to 5, wherein the protected control PDU includes at least one bit indicating that the control PDU is protected.

13. The method according to any one of claims 1 to 5, further comprising: The security issue is reported to the network equipment of the wireless communication system.

14. The method of claim 13, further comprising: The transmission indicates recommended information on the type of control PDU to be protected.

15. The method of claim 13, further comprising: Triggering a UE connection re-establishment or a primary cell group (MCG) / secondary cell group (SCG) failure process.

16. One or more computer-readable media having instructions that, when executed by one or more processors, cause a device to: The protected control PDU in Receive Layer 2 (L2), wherein the protected control PDU is obtained by performing security protection on the control PDU in a sublayer below the Service Data Adaptation Protocol (SDAP); and Process the protected control PDU.

17. One or more computer-readable media according to claim 16, wherein the protected control PDU is obtained by: An integrity protection algorithm is applied to the control PDU; Determine the signature for the control PDU; and The protected control PDU is assembled into a combination including the control PDU and the signature as the protected control PDU.

18. The one or more computer-readable media of claim 17, wherein the inputs to the integrity protection algorithm include: COUNT parameter; DIRECTION parameters; BEARER parameters; as well as Integrity protection key.

19. One or more computer-readable media according to claim 17, wherein the instructions, when executed, further cause the device to: Integrity verification is performed on the protected control PDU based on the signature.

20. One or more computer-readable media according to claim 16, wherein the protected control PDU is obtained by: An encryption algorithm is applied to the control PDU; and The output of the encryption algorithm is determined as the protected control PDU.

21. The one or more computer-readable media of claim 20, wherein the instructions, when executed, further cause the device to: The control PDU is determined by applying the corresponding decryption algorithm to the protected control PDU.

22. The computer-readable medium of claim 20, wherein the input to the encryption algorithm comprises: COUNT parameter; DIRECTION parameters; BEARER parameters; as well as Encryption key.

23. The computer-readable medium of claim 18 or 22, wherein the COUNT parameter is: Fixed COUNT value; The serial number (SN) assigned in the lower layer; or Random value.

24. The computer-readable medium of claim 18 or 22, wherein the BEARER parameter is: Fixed BEARER value; Control PDU type indication; or The value in the specified field of the control PDU.

25. One or more computer-readable media according to claim 16, wherein the protected control PDU is obtained by: A hash algorithm is applied to the control PDU; and The protected control PDU is determined based on the output of the HASH algorithm.

26. The computer-readable medium of claim 25, wherein the input to the HASH algorithm is the control PDU and an additional random value.

27. The one or more computer-readable media of claim 25, wherein the instructions, when executed, further cause the device to: The control PDU is determined by applying a reverse hash algorithm to the protected control PDU.

28. A method for wireless communication, the method comprising: Generate Protocol Data Units (PDUs) in Layer 2 (L2); Security protection is performed on the header of one of the PDUs in L2 to obtain a protected PDU for that PDU, wherein the PDU is in a sublayer below the Packet Data Convergence Protocol (PDCP); as well as Transmit the protected PDU.

29. The method of claim 28, wherein the protected PDU is obtained by: An integrity protection algorithm is applied to at least the header of the PDU; Determine the header signature for the header of the PDU; and The protected control PDU is assembled into a combination including the PDU and the header signature as the protected PDU.

30. The method of claim 29, wherein applying an integrity protection algorithm to at least the header of the PDU comprises: The integrity protection algorithm is applied only to the header or to the entire PDU.

31. The method according to any one of claims 28 to 30, wherein the PDU is a Radio Link Control (RLC) PDU or a Media Access Control (MAC) subPDU.

32. The method according to any one of claims 28 to 30, wherein the PDU to be protected in L2 is determined based on at least one of the following rules: The PDU to be protected is determined based on the protection frequency in PDU transmission; In the Uu interface, a protected PDU is determined in a transmission; The PDU to be protected is determined based on the protection period; The PDU to be protected is determined in response to dynamic triggering; or The PDU to be protected is determined by specifying the PDU type.

33. The method of claim 32, wherein the at least one rule is configured by a network device of the wireless communication system.

34. The method of claim 32, wherein the protected PDU includes at least one bit indicating that the PDU is protected.

35. The method according to any one of claims 28 to 30, wherein the user equipment (UE) of the wireless communication system reports the occurrence of a security problem to the network equipment of the wireless communication system.

36. The method of claim 35, wherein the UE is used to transmit recommendation information indicating the type of PDU to be protected.

37. The method according to claim 35, wherein the UE triggers a UE connection re-establishment or primary cell group (MCG) / secondary cell group (SCG) failure process.

38. A method for wireless communication, the method comprising: The protected control PDU in the receiving layer 2 (L2) is obtained by performing security protection on at least the header of the PDU in the sublayer below the Packet Data Convergence Protocol (PDCP).

39. The method of claim 38, wherein the protected PDU is obtained by: An integrity protection algorithm is applied to at least the header of the PDU; Determine the header signature for the header of the PDU; and The protected control PDU is assembled into a combination including the PDU and the header signature as the protected PDU.

40. The method of claim 39, wherein applying an integrity protection algorithm to at least the header of the PDU comprises: The integrity protection algorithm is applied only to the header or to the entire PDU.

41. The method of claim 40, further comprising: Integrity verification is performed on the protected PDU based on the header signature.

Citation Information

Patent Citations

  • Method and device for identifying security key based on PDCP layer device in next-generation mobile communication system

    EP3879780A1