Methods, devices, and systems for scg security in wireless networks
By pre-configuring candidate secondary nodes and synchronization security keys in wireless devices, and updating security keys using SW counters and basic keys, the latency and security issues in the process of switching and adding secondary nodes in wireless communication networks are solved, enabling fast and secure switching and adding of secondary nodes.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ZTE CORP
- Filing Date
- 2023-01-06
- Publication Date
- 2026-05-01
AI Technical Summary
In wireless communication networks, existing technologies suffer from service latency and security deficiencies during the handover and addition of dual connectivity (SCG and SN), especially in the selection and handover of secondary nodes, where preparation work leads to delays and potential security risks.
By pre-configuring candidate slave nodes and synchronization security keys in wireless devices, using SW counters and basic keys to derive security keys, and updating keys as needed, preparation work is reduced, and security and handover efficiency are improved.
It enables fast and secure switching and addition of secondary nodes in wireless networks, reducing service latency and enhancing network robustness and security.
Smart Images

Figure CN119586210B_ABST
Abstract
Description
Technical Field
[0001] This disclosure generally relates to wireless communications, and more particularly to methods, apparatus, and systems for ensuring security in connection with secondary carrier groups (SCGs) and / or secondary nodes (SNs) in wireless networks. Background Technology
[0002] With the rapid development of wireless communication technology, dual connectivity has been introduced to meet the demands for higher speed, higher throughput and capacity, higher efficiency, and lower latency. This involves using two base stations to support a primary carrier group (MCG) and a secondary carrier group (SCG). It supports handover between SCGs and the addition of new SCGs, as well as handover between cells within the same SCG, to achieve robust secondary connectivity. Minimizing execution time and improving the performance of these processes is crucial. Summary of the Invention
[0003] This disclosure relates to methods, devices, and systems for ensuring security related to SCG and / or SN in wireless networks.
[0004] In some embodiments, a method performed by a wireless device is disclosed. The method may include: selecting a target primary / secondary cell (PScell) in a radio access network (RAN) in response to satisfying execution conditions, the target PScell being associated with a target secondary node (SN), wherein: the target SN is associated with a SW counter (SN handover counter); the SW counter and a base key specific to the target SN are used to derive a security key; the security key is specific to the target SN and is used to protect data between the wireless device and the target SN; and synchronizing the SW counter and the base key between the wireless device and the target SN; determining whether an update to the SW counter is required; and, upon determining that an update to the SW counter is required: incrementing the SW counter by a predefined value, wherein, starting from the last reset of the SW counter, the incremented SW counter is different from any previous SW counter used by the wireless device to derive the security key; and updating the security key based on the incremented SW counter and the base key.
[0005] The above method may further include: transmitting a first message to the master node or the target SN requesting a switch from the current PScell to the target PScell, wherein: when it is determined that the SW counter needs to be updated, the first message includes at least one of the following: an indicator indicating that the security key in the target SN needs to be updated; or an incrementing value of the SW counter.
[0006] In some embodiments, there is a wireless device or a network element including a processor and memory, wherein the processor is configured to read code from memory and implement any of the methods described in any embodiment.
[0007] In some embodiments, a computer program product includes computer-readable program medium code stored thereon, which, when executed by a processor, causes the processor to perform any of the methods described in any embodiment.
[0008] Other aspects and alternatives to the above embodiments and their implementation are described in more detail in the following drawings, description and claims. Attached Figure Description
[0009] Figure 1 An example wireless communication network is shown.
[0010] Figure 2 An example wireless network node is shown.
[0011] Figure 3 An example user device is shown.
[0012] Figure 4 An exemplary dual-connection configuration is shown, with a gNB acting as the master node (MN) and an eNB acting as the slave node (SN).
[0013] Figure 5 An exemplary SN addition / modification process initiated by the master node (MN) is shown.
[0014] Figure 6 An exemplary SN configuration pre-configured in the UE is shown.
[0015] Figure 7 An example K is shown. SN 'Export process.'
[0016] Figure 8 An exemplary scheme for maintaining and synchronizing the SW counter (SN switching counter) between the UE and the SN is shown.
[0017] Figure 9 An exemplary conditional PScell change (CPC) or conditional PScell addition (CPA) procedure initiated by a UE pre-configured with a candidate SCG (or candidate SN) is shown.
[0018] Figure 10 Another exemplary CPC / CPA procedure is shown, initiated by a UE that has been pre-configured with a candidate SCG (or candidate SN). Detailed Implementation
[0019] Wireless communication network
[0020] Figure 1An exemplary wireless communication network 100 is shown, comprising a core network 110 and a radio access network (RAN) 120. The core network 110 also includes at least one mobility management entity (MME) 112 and / or at least one access and mobility management function (AMF). Figure 1 Other functions that may be included in the core network 110 are not shown. RAN 120 also includes multiple base stations, such as base stations 122 and 124. Base stations may include at least one evolved NodeB (eNB) for 4G LTE, an enhanced LTE eNB (ng-eNB), or a next-generation NodeB (gNB) for 5G New Radio (NR), or any other type of signal transmission / reception equipment, such as a UMTS NodeB. eNB 122 communicates with MME 112 via the S1 interface. Both eNB 122 and gNB 124 can be connected to AMF 114 via the Ng interface. Each base station manages and supports at least one cell. For example, base station gNB 124 can be configured to manage and support cell 1, cell 2, and cell 3.
[0021] The gNB 124 may include a central unit (CU) and at least one distributed unit (DU). The CU and DU may be located in the same location or in separate locations. The CU and DU may be connected via an F1 interface. Alternatively, for an eNB capable of connecting to a 5G network, it may similarly consist of a CU and at least one DU, referred to as ng-eNB-CU and ng-eNB-DU, respectively. The ng-eNB-CU and ng-eNB-DU may be connected via a W1 interface.
[0022] The wireless communication network 100 may include one or more tracking areas. A tracking area may include a set of cells managed by at least one base station. For example, tracking area 1, labeled 140, includes cell 1, cell 2, and cell 3, and may also include cells that can be managed by other base stations. Figure 1 More cells are not shown in the diagram. The wireless communication network 100 may also include at least one UE 160. The UE can select one cell from a plurality of cells supported by the base station to communicate with the base station via an over-the-air (OTA) wireless communication interface and resources, and can reselect a cell for communication as the UE 160 travels within the wireless communication network 100. For example, the UE 160 may initially select cell 1 to communicate with base station 124, and may then reselect cell 2 at a later time. The cell selection or reselection of the UE 160 may be based on wireless signal strength / quality and other factors in various cells.
[0023] The wireless communication network 100 can be implemented as, for example, a 2G, 3G, 4G / LTE, or 5G cellular communication network. Correspondingly, base stations 122 and 124 can be implemented as 2G base stations, 3G NodeBs, LTE eNBs, or 5G NR gNBs. The UE 160 can be implemented as a mobile or fixed communication device capable of accessing the wireless communication network 100. The UE 160 can include, but is not limited to, mobile phones, laptops, tablets, personal digital assistants, wearable devices, Internet of Things (IoT) devices, MTC / eMTC devices, distributed remote sensor devices, roadside assistance devices, XR devices, and desktop computers. The UE 160 may also be commonly referred to as a wireless communication device or a wireless terminal. The UE 160 can support sidelink communication to another UE via a PC5 interface.
[0024] Although the following description focuses on, Figure 1 The cellular wireless communication system shown is based on principles applicable to other types of wireless communication systems used for paging wireless devices. These other wireless systems may include, but are not limited to, Wi-Fi, Bluetooth, ZigBee, and WiMax networks.
[0025] Figure 2 An example of an electronic device 200 for implementing a network base station (e.g., a wireless access network node), core network (CN), and / or operation and maintenance (OAM) is shown. Optionally, in one embodiment, the example electronic device 200 may include wireless transmit / receive (Tx / Rx) circuitry 208 to transmit / receive communications with a UE and / or other base stations. Optionally, in one embodiment, the electronic device 200 may also include network interface circuitry 209 to enable the base station to communicate with other base stations and / or the core network, for example, optical or wired interconnects, Ethernet, and / or other data transmission media / protocols. The electronic device 200 may optionally include an input / output (I / O) interface 206 for communication with operators, etc.
[0026] Electronic device 200 may also include system circuitry 204. System circuitry 204 may include one or more processors 221 and / or memory 222. Memory 222 may include operating system 224, instructions 226, and parameters 228. Instructions 226 may be configured for one or more processors 221 to perform functions of the network node. Parameters 228 may include parameters that support the execution of instructions 226. For example, parameters may include network protocol settings, bandwidth parameters, radio frequency mapping allocation, and / or other parameters.
[0027] Figure 3An example of an electronic device for implementing terminal device 300 (e.g., user equipment (UE)) is shown. UE 300 may be a mobile device, such as a smartphone or mobile communication module installed in a vehicle. UE 300 may include some or all of the following: communication interface 302, system circuitry 304, input / output interface (I / O) 306, display circuitry 308, and memory 309. The display circuitry may include a user interface 310. System circuitry 304 may include any combination of hardware, software, firmware, or other logic / circuit. System circuitry 304 may be implemented, for example, with one or more system-on-chip (SoC), application-specific integrated circuit (ASIC), discrete analog and digital circuitry, and other circuitry. System circuitry 304 may be part of an implementation of any desired functionality in UE 300. In this regard, system logic 304 may include logic that, for example, facilitates decoding and playing music and video, such as MP3, MP4, MPEG, AVI, FLAC, AC3, or WAV decoding and playback; running applications; accepting user input; saving and retrieving application data; establishing, maintaining, and terminating cellular phone calls or data connections, such as internet connections; establishing, maintaining, and terminating wireless network connections, Bluetooth connections, or other connections; and displaying relevant information on user interface 310. User interface 310 and input / output (I / O) interface 306 may include a graphical user interface, a touch-sensitive display, haptic feedback or other haptic outputs, voice or facial recognition inputs, buttons, switches, speakers, and other user interface elements. Additional examples of I / O interface 306 may include a microphone, video and still image cameras, temperature sensors, vibration sensors, rotation and orientation sensors, headphone and microphone input / output jacks, a universal serial bus (USB) connector, a memory card slot, radiation sensors (e.g., IR sensors), and other types of inputs.
[0028] Reference Figure 3The communication interface 302 may include radio frequency (RF) transmitting (Tx) and receiving (Rx) circuitry 316 that processes the transmission and reception of signals via one or more antennas 314. The communication interface 302 may include one or more transceivers. The transceiver may be a wireless transceiver that includes modulation / demodulation circuitry, a digital-to-analog converter (DAC), a shaping table, an analog-to-digital converter (ADC), filters, waveform shapers, filters, preamplifiers, power amplifiers, and / or other logic for transmission and reception via one or more antennas or (for some devices) via a physical (e.g., wired) medium. The transmitted and received signals may follow any of various formats, protocols, modulations (e.g., QPSK, 16-QAM, 64-QAM, or 256-QAM), frequency channels, bit rates, and encodings. As a specific example, the communication interface 302 may include a transceiver supporting transmission and reception under 2G, 3G, BT, WiFi, Universal Mobile Telecommunications System (UMTS), High-Speed Packet Access (HSPA)+, 4G / LTE, and 5G standards. However, the techniques described below are applicable to other wireless communication technologies, whether from the 3rd Generation Partnership Project (3GPP), the GSM Association, 3GPP2, IEEE, or other partners or standards bodies.
[0029] Reference Figure 3 System circuitry 304 may include one or more processors 321 and memory 322. Memory 322 stores, for example, an operating system 324, instructions 326, and parameters 328. Processor 321 is configured to execute instructions 326 to achieve the desired functionality of UE 300. Parameters 328 can provide and specify configuration and operational options for instructions 326. Memory 322 may also store any BT, WiFi, 3G, 4G, 5G, or other data that UE 300 will send or has received via communication interface 302. In various embodiments, system power for UE 300 may be provided by power storage devices such as batteries or transformers.
[0030] Network deployment with dual connectivity
[0031] With the rapid development of wireless communication technology, dual connectivity (DC) functionality has been introduced to meet the demands for higher speed, higher throughput and capacity, higher efficiency, and lower latency. Typically, in a DC deployment, a UE is allowed to connect to two base stations (or two nodes) and send / receive data via both base stations. These two base stations can be of the same type; for example, both base stations could be eNBs, gNBs, ng-eNBs, etc. Alternatively, they can be of different types. The core network supporting DC deployment can include, for example, an LTE Evolution Packet Core (EPC) or a 5G core.
[0032] In a DC deployment, one node acts as the primary node (MN) and the other as the secondary node (SN). In some example implementations, the MN is the node the UE first connects to. Subsequently, the UE can connect to the SN.
[0033] In some example implementations, only the MN is used to provide control plane connectivity between the UE and the core network. The SN, on the other hand, provides additional resources to carry user plane traffic.
[0034] In some example implementations, the SN may also carry signaling messages.
[0035] Example DC configurations include EN-DC (E-UTRA-NR dual connectivity), NE-DC (NR–E-UTRA dual connectivity), NR-DC (New Radio dual connectivity), NGEN-DC (NG-RAN–E-UTRA dual connectivity), etc. Exemplarily, MN can be an eNB (in EN-DC), ng-eNB (in NGEN-DC), or gNB (in both NR-DC and NE-DC). SN can be an en-gNB (in EN-DC), ng-eNB (in NE-DC), or gNB (in both NR-DC and NGEN-DC).
[0036] In some deployments, the DC (Distributed Cell Group) can be configured in conjunction with carrier aggregation (CA), where both the MN (Member Cell Node) and SN (Signal Node) can be associated with multiple cells or carriers. These aggregated carriers are collectively referred to as Primary Cell Groups (MCGs) and Secondary Cell Groups (SCGs). Note that an MCG is associated with an MN, and an SCG is associated with an SN. Furthermore, note that an MCG may implicitly imply the MN it is associated with, and an SCG may implicitly imply the SN it is associated with.
[0037] Reference Figure 4 To obtain an example DC configuration. In this example, MCG 410 is associated with MN as gNB, and SCG 412 is associated with SN as eNB.
[0038] The MCG may include a set of serving cells associated with the MN, including a primary cell (PCcell) and one or more optional secondary cells (Scells). The SCG may include a set of serving cells associated with the SN, including a primary SCG cell (PScell) and one or more optional Scells. Figure 4 In the SCG 410, one PCell and two SCells are configured: Scell 1 and Scell 2. The SCG 412 is configured with one PSCell and two SCells: Scell 1 and Scell 2.
[0039] In some implementations, the UE can be configured with multiple candidate SCGs (or SNs). The UE can be connected to an MN, but can switch from one SCG to another; or the UE can switch PScells within the same SCG.
[0040] In the embodiments and example implementations below, the UE can be configured with a DC configuration.
[0041] SN addition / modification process (initiated by MN)
[0042] In some example implementations, the MN can add to or change (modify) the SN. For example, the UE can switch from one SCG to another (i.e., from one SN to another SN), and a PScell change will occur. Figure 5 An exemplary overall message / signaling flow for adding / modifying SNs is shown.
[0043] Step 1
[0044] The UE establishes a Radio Resource Control (RRC) connection with the MN.
[0045] Step 2
[0046] The MN sends an SN add / modify request to the SN via the Xn-C interface to negotiate available resources, configuration, and algorithms (e.g., security algorithms) at the SN. If a new security key (K) from the SN is required... SN The MN can calculate and deliver this information to the SN. UE security capabilities and user plane (UP) security policies can also be sent to the SN.
[0047] UE security capabilities may include capabilities for Next Generation Radio Access Network (NG-RAN), 5G Non-Access Stratum (NAS), and 5G Access Stratum (AS), and if the UE supports these access types, may also include capabilities for Evolved Packet System (EPS), Universal Terrestrial Radio Access Network (UTRAN), and GSM EDGE Radio Access Network (GERAN). UP security policies can be used to activate UP confidentiality and / or UP integrity for one or more DRBs belonging to a PDU session associated with the UE.
[0048] In the case of PDU separation, the request may also include UP integrity protection and encryption activation decisions from MN.
[0049] Step 3
[0050] The SN allocates necessary resources, such as radio resources and transport network resources. The SN can also select encryption and integrity algorithms with the highest priority from its configured list that are also present in the UE's security capabilities. If a new K is delivered to the SN in step 2...SN Then the SN can calculate the RRC key and the UP key. The SN can then activate the UP security policy based on the UP key.
[0051] Step 4
[0052] The SN sends an SN Add / Modify Confirmation to the MN, indicating the availability of the requested resource and the identifiers of one or more selected algorithms for the UE's requested Data Radio Bearer (DRB) and / or Signaling Radio Bearer (SRB). UP integrity protection and encryption indications may also be sent to the MN.
[0053] Step 5
[0054] The MN sends an RRC connection reconfiguration request to the UE, instructing it to configure a new DRB and / or SRB for the SN. The MN may include SN counter parameters to indicate the need for a new K. SN And the UE needs to calculate the K of the SN. SN The MN forwards the UE configuration parameters (which include one or more algorithm identifiers received from the SN in step 4) and the UP integrity protection and encryption indications (received from the SN in step 4) to the UE.
[0055] Please note that this message can be sent via the RRC connection between the MN and the UE, and uses the MN's K. RRCint Integrity is protected by the (RRC security key). Therefore, the SN counter is tamper-proof.
[0056] Step 6
[0057] After verifying its integrity, the UE accepts the RRC connection reconfiguration request. If the SN counter parameter is included, the UE calculates K of the SN. SN The UE can also calculate the required RRC and UP keys and activate RRC and UP protection based on the received associated SRB and / or DRB instructions. The UE sends an RRC reconfiguration complete message to the MN. At this point, the UE can choose to activate the selected encryption / decryption and integrity protection keys using the SN.
[0058] Step 7
[0059] The MN, for example, sends an SN reconfiguration complete message to the SN via the Xn-C interface to notify the SN of the configuration result. Upon receiving this message, the SN can choose to activate the selected encryption / decryption and integrity protection using the UE. Alternatively, if the SN does not activate encryption / decryption and integrity protection using the UE at this stage, the SN can activate encryption / decryption and integrity protection upon receiving a random access request from the UE.
[0060] During this SN addition / modification process, K SNUsed to protect the connection between the UE and the SN. The UE can calculate K itself. SN SN relies on MN to deliver K SN .
[0061] In some example implementations, K SN It can be derived using a Key Derivation Function (KDF). The KDF can be based on the Hash-based Message Authentication Code Secure Hash Algorithm 256 (HMAC-SHA-256). Equation 1 below shows the derivation of K using a KDF. SN Example:
[0062] K SN = KDF (key, S) (1)
[0063] In Equation 1, the KDF has two inputs: an input key and a string S. For example, using Equation 2 below, the string S can be a concatenation of multiple strings (or multiple input parameters):
[0064] S = FC || P0 || L0 || P1 || L1 || … || Pn || Ln (2)
[0065] In Equation 2, FC is the function code. In the connection, there are multiple parameters (from P0 to Pn, where n is a non-negative integer), and the length value of each parameter (i.e., L0, L1, ..., Ln).
[0066] As an example, in order to derive K SN You can use the following input:
[0067] -FC = 0x79.
[0068] -P0 = the non-negative integer value of the SN counter.
[0069] -L0 = the length of P0 (i.e., the length of the SN counter value, for example, in bits or bytes).
[0070] The input key can be a key used for the MN, and when the MN is an ng-eNB, it can include K. eNB When MN is gNB, it can include K. gNB .
[0071] Selectively add / change SCGs using pre-configuration
[0072] In the SN addition / modification process described in the previous section, the decision to add / modify the SN is made by the MN. Once the MN triggers the process, the SN and UE need to perform preparatory work, including resource allocation, capability negotiation, and algorithm selection. This preparatory work may cause service delays. Therefore, in order to speed up the process and reduce the duration of service interruptions, it is necessary to reduce or even eliminate the preparatory work so that the link between the UE and SN can be established with minimal effort after the SN addition / modification decision is made.
[0073] One solution is to move the preparation work or preparation phase to an earlier stage before making a decision to add / modify the SN.
[0074] The UE can be pre-configured with a pool of candidate SNs, including multiple candidate SNs. For each candidate SN, the UE can be configured with settings related to, for example, resource allocation, capability negotiation, and algorithm selection. The UE can also be configured with execution conditions for evaluating and triggering SN addition or modification. For the same candidate SN, there may be different execution conditions serving different purposes, such as execution conditions for SN addition and execution conditions for SN modification. Furthermore, in some example implementations, candidate SNs can support multiple configurations, for example, configurations serving different Quality of Service (QoS), different security levels, or different throughput. Accordingly, the UE can evaluate multiple execution conditions of candidate SNs and select an SN configuration that matches the satisfied execution conditions.
[0075] The SN configuration can be used for conditional PScell addition (CPA) and / or conditional PScell change (CPC) because PScell addition and PScell change are triggered when the conditions defined in the execution condition are met.
[0076] refer to Figure 6 As an example, the UE is configured with a pool of candidate SNs including three candidate SNs (SN 1 to SN 3). SN configuration and execution conditions 610, 612, and 614 are pre-configured for the UE. Based on these pre-configured settings, the UE can add one of these SNs to add an SCG, or change its SCG from one SN to another. The UE can also change its PScell within the same SCG.
[0077] Similarly, for each candidate SN, pre-configuration can be performed to support the CPA / CPC process. For example, candidate SNs can be configured with UE capabilities and UE security preferences to minimize negotiation effort after selecting a candidate SN for SN addition or modification.
[0078] SN key (K SN ) conversion
[0079] In some embodiments, the link between the UE and the SN (or the PScell in the SN) is provided by K. SN The derived key (SN's security key, which can be derived using equations 1 and 2) is used for protection, denoted as K. SN For example, such as Figure 4 As shown, the link between the UE and the PScell in the SCG412 can be generated by K. SN 'To protect. K' SN Synchronize between UE and SN.
[0080] Figure 7 An exemplary K is shown for each candidate SN in the candidate SN pool. SN 'Derivation process. In this example, there are 3 SNs (SN 1 to SN 3). From the UE side, the UE can pre-configure an SN counter, which is pre-configured by, for example, MN as a non-negative integer (e.g., 0). First, the UE can calculate the security key K for each SN.' SN As shown in Table 1.
[0081] Table 1: K SN Export
[0082]
[0083] The root key can be used for MN (e.g.) Figure 4 The security key of the master node (shown) can include K when MN is an ng-eNB. eNB When MN is gNB, it can include K. gNB Please note that the root key may be the same for all candidate SNs in the candidate SN pool (because all these candidate SNs are associated with the same MN).
[0084] Using the formulas in Table 1, KDF can use the same root key as the input key, but each SN uses a different input string. Therefore, the security key K for each SN is... SN They are different.
[0085] Then, K for each SN SN This will be used to derive K corresponding to SN. SN The basic key. Another counter (SN handover counter) is further introduced and pre-configured on the UE side (in... Figure 7 (This is represented as the SW counter). The SW counter can be pre-configured by, for example, MN to an initial integer value, such as 0. Then, the UE can use KDF to derive K. SN '. As some examples, K SN '1=KDF(K SN 1, "a string based on the SW counter"); or KSN '2=KDF(K SN 2, "String based on SW counter"). Note that for the same base key K... SN K can be refreshed by refreshing the SW counter. SN (For example, by incrementing the SW counter by a predefined integer, such as 1). In the following embodiments, how to determine when the SW counter needs to be refreshed will be described in detail.
[0086] Basic key K SN Synchronize between the UE and the corresponding SN. For example, SN 1 maintains the same K as the UE. SN 1 replica. Synchronization can be coordinated by, for example, an MN via signaling. In some example implementations, the MN can transmit K... SN It is sent to the corresponding SN, and the UE can calculate K itself. SN .
[0087] The SW counter is synchronized between the UE and SN in various forms.
[0088] In some example implementations, the SW counter is synchronized between the UE and each candidate SN. The UE may maintain one SW counter for each candidate SN, while each candidate SN maintains its own SW counter. For example, as... Figure 8 As shown, the UE can maintain three SW counters: SW counter 1, SW counter 2, and SW counter 3, serving SN 1, SN 2, and SN 3 respectively. Each SN can maintain its own SW counter corresponding to the SW counter on the UE side, forming an SW counter pair. Each pair of SW counters can be initialized to the same initial value (e.g., 0). When a candidate SN is selected as the target SN, if it is necessary to refresh the SW counters, the UE can notify the target SN of the refreshed SW counter value or an indicator indicating that the SW counters need to be refreshed, in order to maintain SW counter synchronization.
[0089] In some other example implementations, the SW counter only needs to be synchronized between the UE and the target SN. The target SN is a candidate SN associated with the selected PScell during the CPC / CPA procedure. For example, the target SN could be a candidate SN to which the UE changes its PScell (i.e., to which it switches the link to a new PScell under that target SN). The UE can notify the target SN of the refreshed SW counter value.
[0090] Because the UE and the target SN have a basic key for synchronization (K) SN ) and SW counter, therefore K SN It can be calculated on each side and synchronized between the UE and the target SN.
[0091] K SN 'It can be exported in various ways using KDF with different input strings, as described below.'
[0092] For example, K SN '=KDF(K SN (Input string). For details on how the input parameters are formed into the input string, please refer to Equation 2.
[0093] In some example implementations, the following input parameters may be used:
[0094] -FC = 0x7E.
[0095] -P0 = the non-negative integer value of the SW counter.
[0096] -L0 = the length of the SW counter value (e.g., 1 byte, 2 bytes, etc.).
[0097] In some example implementations, the following input parameters may be used:
[0098] -FC = 0x7E.
[0099] -P0 = SP - the non-negative integer value of the counter.
[0100] -L0 = SP - the length of the counter value.
[0101] -P1 = PSCell id of the target PScell or ARFCN-DL (absolute radio frequency channel number in the downlink direction, e.g., absolute frequency of the SSB (synchronization signal / PBCH block) of the target PScell).
[0102] -L1 = PSCell id or the length of ARFCN-DL.
[0103] In some example implementations, the following input parameters may be used:
[0104] -FC = 0x7E.
[0105] -P0 = SP - the non-negative integer value of the counter.
[0106] -L0 = SP - Length of the counter value (i.e., 0x00 0x02).
[0107] -P1 = PSCell id of the target PScell.
[0108] -L1 = the length of the PSCell id.
[0109] -P2 = ARFCN-DL of the target PScell.
[0110] -L2 = the length of ARFCN-DL (i.e., 0x00 0x03).
[0111] Example 1: Selective SCG Addition / Change with Security Key Refresh
[0112] In this embodiment, the UE is pre-configured with candidate SN / SCG settings to expedite the CPC / CPA process. For each candidate SN in the candidate SN pool, K SN Synchronize between the UE and each candidate SN. Note that K SN This can be derived based on Equation 1 described earlier. As stated in the previous section, K SN The transformation is represented as K. SN ', maintained by the UE and each candidate SN, and used to protect the link between the UE and the corresponding candidate SN.
[0113] During CPA / CPC, the UE can persist with the Pcell in the MCG and add a new PScell, or switch to another PScell in a different or the same SCG (or SN). The UE can maintain the pre-configured SN / SCG configuration and can switch back and forth to the same PScell multiple times. Depending on the different PScell addition / switching scenarios, the K of the SN used to protect the link between the UE and the SN is determined. SN 'It may be reused, or it may need to be refreshed to enhance security.' In this embodiment, K is described in detail. SN Refresh mechanism.
[0114] When a UE is configured with multiple candidate SNs, a security key for the candidate SNs, namely K, is used to protect the link between the UE and the candidate SNs. SN ', as described in the previous section. K SN It can be derived as described in the previous section, for example, K SN '=KDF(K SN ("a string based on the SW counter"). Specifically, the input key can be a security key for the SN, which is also known as the key used to calculate K. SN The "basic key" of '.
[0115] K SN There are several security requirements. First, each candidate SN has its own unique K. SN Secondly, for the same candidate SN, there is a refresh requirement; therefore, in some cases, it is necessary to refresh or update K. SN Further details will be described in later paragraphs.
[0116] Figure 9 An example message flow of a CPC / CPA procedure initiated by a UE is shown, which includes the following steps.
[0117] Step 0
[0118] This step can be used as a pre-configuration phase.
[0119] The UE can be pre-configured with a candidate SN pool (or SCG pool), which includes multiple candidate SNs (or multiple candidate SCGs). Return to reference Figure 6 For each candidate SN, the configuration maintained by the UE includes: Conditional PScell Addition (CPA) configuration; and / or Conditional PScell Change (CPC) configuration. The UE can also be pre-configured with execution conditions corresponding to the CPA and CPC configurations. For example, when the CPA execution conditions are met, subsequent PScell additions can be performed according to the CPA configuration.
[0120] In some example implementations, the UE can be pre-configured with an SN counter for each candidate SN (or candidate SCG). The MN can assign a unique initial value to each SN counter. For example, such as... Figure 6 As shown, the initial values of the three SN counters can be 0, 1, and 2, respectively.
[0121] Alternatively, in some other example implementations, the UE only needs to maintain one SN counter as a base counter and derive the corresponding SN counter value to be applied to each SN. For example, the base value pre-configured for the SN counter can be 0, and the UE can start from the base value and derive / assign a counter value for each SN, for example, by incrementing the SN counter value after each assignment. Exemplarily, the UE can receive the base counter from the MN.
[0122] As mentioned earlier, the UE also maintains one or more SW counters depending on the specific implementation. The basic principle or requirement is that the SW counters are synchronized between the UE and the target SN (for hosting the selected PScell in the case of CPC / CPA). For details on how to maintain and synchronize the SW counters, please refer to "SN Key (K)". SN (Conversion) section.
[0123] On the SN side, each candidate SN can be prepared in advance for subsequent CPC / CPA execution. Each SN can be pre-configured with SN counters and SW counters synchronized with the UE. For example, the initial value of the SP counter can be set to "0". Each SN can also obtain its K from the MN. SN Then its K can be calculated in this step or in a subsequent step before the first CPC / CPA process. SN '.
[0124] Step 1
[0125] The UE evaluates the execution conditions. If a specific PScell under a candidate SN meets the CPA / CPC execution conditions, the UE will select the PScell (and its associated candidate SN, also known as the target SN) and continue the CPA / CPC process. The execution conditions for CPA and CPC may be different.
[0126] As an example, see reference Figure 8 The UE is pre-configured with three SNs: SN 1, SN 2, and SN 3. Each SN has three cells: Cell 1, Cell 2, and Cell 3. The UE has current dual connectivity, and its current PScell is Cell 1 under SN 1. If the CPC execution conditions are met, the UE can select Cell 2 under SN 2 to execute the CPC procedure. In this case, SN 2 is the target SN.
[0127] Step 2
[0128] The UE triggers a CPC / CPA procedure for the selected PSCell by sending a CPC / CPA request message to the MN. The message may include at least one of the following: an SN counter for the target SN (i.e., a candidate SN associated with the selected PSCell); or an identifier, such as the PSCell id of the selected PSCell, to identify the target SN associated with the selected PSCell.
[0129] The SW counter of the target SN associated with the selected PSCell may or may not need to be refreshed (updated) from its current value. If the selected PSCell is associated with an SN different from the SN associated with the current PScell in the dual connection, then the SW counter needs to be refreshed. Accordingly, the K of the candidate SN... SN An update may also be required, and the UE will need to recalculate K based on the refreshed SW counter. SN When it is determined that the SW counter needs to be refreshed, the CPC / CPA request message may also include an SW counter refresh indicator indicating that the SW counter needs to be refreshed, or the refreshed SW counter value.
[0130] As an example, back Figure 8 Assume the current dual connectivity uses cell 1 in SN 1 as the PScell (i.e., SN 1 is the current SN). The UE determines that it needs to change the PScell to cell 2 under SN 2. In this case, since the selected PScell is associated with an SN different from the current SN, the SW counter of SN 2 (i.e., the SN associated with the selected PScell) needs to be refreshed, and the K of SN 2 also needs to be updated. SN '.
[0131] As another example, in Figure 8In this scenario, assume the current dual connectivity uses cell 1 in SN 1 as the PScell (i.e., SN 1 is the current SN). The UE determines it needs to change the PScell to cell 2 within the same SN. In this case, there is no SN change, therefore the SW counter for SN 1 does not need to be refreshed, and the K counter for SN 1... SN It can be reused without updating.
[0132] In some example implementations, the UE maintains a SW counter for each SN. When refreshing the SW counter of a selected candidate SN, the UE can increment the SW counter value by an offset (e.g., a predefined positive integer, such as 1) to obtain the refreshed value of the SW counter for the selected candidate SN (i.e., the target SN). Note that the refreshed value must not have been used to calculate K for the same candidate SN. SN The offset can be configured by MN.
[0133] As an example, suppose the UE maintains 3 SW counters (one for each SN) before the SW counter is refreshed, with the following values:
[0134] SW counter 1: 0; SW counter 2: 1; SW counter 3: 2.
[0135] Assuming the UE needs to refresh SW counter 2 (for SN 2) based on the above-described logic, the UE can increment SW counter 2 by 1. After the refresh, the three SW counters will have the following values (the value of SW counter 2 has been updated):
[0136] SW counter 1: 0; SW counter 2: 2; SW counter 3: 2.
[0137] Because the SW counter has an upper limit, if the SW counter reaches its upper limit, the counter will be reset (this can be called SW counter wrapping). Each reset marks a new cycle for the SW counter. In such a reset event, for example, MN can update all SN counters to different values. This type of SN counter update can be viewed as the reinitialization of SN counters with different initial values. For example, the initial SN counter values {0, 1, 2} might apply to 3 candidate SNs. After reinitialization, the SN counter values could be reset to {3, 4, 5}. The corresponding K needs to be calculated based on the reinitialized SN counters. SN To obtain the updated K SN Used for deriving K SN The basic key. Therefore, when considering SW counter wraparound / reset, it is required that within each cycle of the SW counter, the refreshed SW counter value should not be used to calculate K for the same candidate SN. SN '.
[0138] Step 3
[0139] The MN, for example, sends CPC / CPA request messages (for adding / modifying the SN) to the SN (i.e., the target SN) via the Xn-C interface. Exemplarily, the MN can transparently forward SN add / modify requests to the SN.
[0140] Step 4
[0141] If the SW counter refresh indicator or the refreshed SW counter value is carried in the CPC / CPA request message, the SN determines that the SW counter needs to be refreshed upon receiving the CPC / CPA request message. The SN continues to update its K using the same key derivation method as the UE. SN In other words, K SN 'Based on the SN's basic key (K) SN The string is derived from the SW counter value. Note that the base key and SW counter are synchronized between the SN and UE.
[0142] Step 5
[0143] The SN, for example, sends a CPC / CPA request confirmation message to the MN via the Xn-C interface. The SN can activate the selected encryption / decryption and integrity protection using the UE based on a pre-configured setup. If the SN does not activate encryption / decryption and integrity protection using the UE at this stage, the SN can choose to activate encryption / decryption and integrity protection upon receiving a random access request from the UE. Note that if an update to K is required for the SN in step 2... SN 'Then encryption / decryption and integrity protection are based on the updated K' SN ', otherwise the current K SN It can be used for security protection.
[0144] Step 6
[0145] The MN sends a CPC / CPA request confirmation message to the UE. Upon receiving this message, the UE can then base its decision on K. SN At this point, use the SN to activate the selected encryption / decryption and integrity protection key.
[0146] In this embodiment, the UE maintains a SW counter for each candidate SN in the candidate SN pool (e.g., Figure 8 (SW counters 1 to SW counter 3). When the UE switches to a PScell under a different target SN than the current SN associated with the current PScell, the SW counter of the target SN will be refreshed, and both the UE and the target SN will calculate a new K. SN '. Updated K SN'Will be used to protect the link between the UE and the target SN (e.g., the link between the UE and the target PScell of the target SN).
[0147] Alternatively, a single SW counter implementation can be used, as described above.
[0148] Example 2: Selective SCG Addition / Change with Security Key Refresh
[0149] This embodiment is similar to Embodiment 1. For example, it is used to synchronize the SW counter and K. SN The basic principles and mechanisms remain applicable. One difference relates to the involvement of the MN in the entire CPC / CPA process. Specifically, during the preparation phase (as shown in step 0 of Embodiment 1), various resources, such as radio resources and transport network resources, can be prepared in both the candidate SN and the UE. Therefore, the UE and the candidate SN can communicate directly with each other without the involvement of the MN.
[0150] Figure 10 The example message flow of a UE-initiated CPC / CPA procedure is shown, where the UE and the candidate SN (target SN) communicate / negotiate directly after the preparation phase. The procedure includes the following steps.
[0151] Step 0
[0152] These are the pre-configured preparation steps. See step 0 of Example 1 for details.
[0153] Step 1
[0154] The UE evaluates the execution conditions used to trigger CPC / CPA. See step 1 of Example 1 for details.
[0155] Step 2
[0156] This step is similar to step 2 in Embodiment 1, except that the UE directly sends a CPC / CPA request message to the target SN without the participation of the MN.
[0157] Step 3
[0158] If the SW counter refresh indicator or the refreshed SW counter value is carried in the CPC / CPA request message, the SN determines that the SW counter needs to be refreshed upon receiving the CPC / CPA request message. The SN continues to update its K using the same key derivation method as the UE. SN In other words, K SN 'Based on the SN's basic key (K) SN The string is derived from the SW counter value. Note that the base key and SW counter are synchronized between the SN and UE.
[0159] Step 4
[0160] Step 4 is similar to step 5 in Embodiment 1, except that the SN directly sends a CPC / CPA request confirmation message to the UE without the participation of the MN.
[0161] After receiving the CPC / CPA request confirmation message, the UE can base it on K SN At this point, use the SN to activate the selected encryption / decryption and integrity protection key.
[0162] The above description and accompanying drawings provide specific example embodiments and implementations. However, the described subject matter can be embodied in a variety of different forms, and therefore, the covered or claimed subject matter is intended to be construed as not being limited to any of the example embodiments described herein. The scope of the claimed or covered subject matter is quite broad. Among other things, the subject matter can be embodied as a method, apparatus, component, system, or non-transitory computer-readable medium for storing computer code. Thus, embodiments can take the form of, for example, hardware, software, firmware, storage medium, or any combination thereof. For example, the above-described method embodiments can be implemented by executing computer code stored in memory, by components, apparatus, or a system including memory and a processor.
[0163] Throughout the specification and claims, terms may have meanings that are suggested or implied in the context, beyond their explicitly stated meanings. Similarly, the phrase "in one embodiment / implementation" as used herein does not necessarily refer to the same embodiment, and the phrase "in another embodiment / implementation" as used herein does not necessarily refer to different embodiments. For example, the claimed subject matter includes combinations of all or some exemplary embodiments.
[0164] Generally, terms can be understood, at least in part, from their usage in the context. For example, terms such as “and,” “or,” or “and / or” as used herein can include a variety of meanings, which may depend at least in part on the context in which they are used. Typically, “or,” when used in an associative list, such as A, B, or C, means A, B, and C (in an inclusive sense) and A, B, or C (in an exclusive sense). Furthermore, the term “one or more,” as used herein, can be used, at least in part, to describe any feature, structure, or characteristic in a singular sense, or a combination of features, structures, or characteristics in a plural sense. Similarly, terms such as “a,” “one,” or “the” can be understood to indicate either a singular or plural usage, at least in part, depending on the context. Additionally, the term “based on” can be understood to not necessarily convey an exclusive set of factors; rather, it may allow for the presence of other factors that are not necessarily explicitly described, at least in part, depending on the context.
[0165] References to features, advantages, or similar language in this specification do not imply that all features and advantages achievable through this solution should or are included in any single implementation thereof. Rather, references to features and advantages are to be understood as meaning that a particular feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of this solution. Therefore, the discussion of features and advantages, as well as similar language, throughout this specification may, but not necessarily, refer to the same embodiments.
[0166] Furthermore, the described features, advantages, and characteristics of this solution can be combined in any suitable manner in one or more embodiments. Based on the description herein, those skilled in the art will recognize that this solution can be implemented without one or more specific features or advantages of a particular embodiment. In other instances, additional features and advantages that may not be present in all embodiments of this solution may be recognized in certain embodiments.
Claims
1. A wireless communication method performed by a wireless device in a wireless network, comprising: In response to the fulfillment of the execution conditions, a target primary / secondary PScell is selected in the Radio Access Network (RAN). The target PScell is associated with the target secondary node SN, wherein: The target SN is associated with the SW counter (SN switching counter); The SW counter and the base key specific to the target SN are used to derive the security key; The security key is specific to the target SN and is used to protect data between the wireless device and the target SN; and The SW counter and the basic key are synchronized between the wireless device and the target SN; Determine whether the SW counter needs to be updated; When it is determined that the SW counter needs to be updated: The SW counter is incremented by a predefined value, wherein, starting from the last reset of the SW counter, the incremented SW counter is different from any previous SW counter used by the wireless device to derive the security key; and The security key is updated based on the incrementing SW counter and the basic key; and a first message requesting a switch from the current PScell to the target PScell is sent to the master node or the target SN, wherein: When it is determined that the SW counter needs to be updated, the first message includes at least one of the following: An indicator that requires updating the security key in the target SN; or The incrementing value of the SW counter.
2. The method according to claim 1, wherein, Determining whether the SW counter associated with the target SN needs to be updated includes: In response to the fact that the SN associated with the target PScell is different from the SN associated with the current PScell, it is determined that the SW counter associated with the target SN needs to be updated.
3. The method according to claim 1, wherein, The wireless device has dual connections with the RAN, including a primary connection between the wireless device and the master node, and a secondary connection between the wireless device and the current PScell.
4. The method according to claim 1, wherein, The initial value of the SW counter is pre-configured as an integer value by the master node.
5. The method according to any one of claims 1-4, wherein, The base key is derived using a key derivation function based on at least one of the following inputs: The root key of the master node; or The SN counter is based on the initial SN counter value configured by the master node.
6. The method according to any one of claims 1-4, wherein, The reset of the SW counter is triggered by the surround of the SW counter, and the method also includes resetting the base key.
7. The method according to any one of claims 1-4, wherein, Before selecting the target PScell in response to the fulfillment of the execution conditions, the method further includes: receiving an initial value of the SW counter from the master node.
8. The method according to any one of claims 1-4, wherein, Updating the security key based on the incrementing SW counter and the base key includes: The security key is derived using a key derivation function, the input of which includes at least one of the following: An input key based on the aforementioned basic key; or It must include at least the input parameters of an incrementing SW counter.
9. The method according to claim 8, wherein, The input parameters also include at least one of the following: The identifier of the target PScell; or The absolute radio frequency channel number ARFCN-DL in the downlink direction of the target PScell.
10. The method according to claim 9, wherein, The input parameters also include at least one of the following: The first length of the identifier of the target PScell; or The second length of the ARFCN-DL of the target PScell.
11. The method according to any one of claims 1-4, further comprising: A second message is received from the master node or the target SN, indicating that the target SN is ready to establish a secure connection with the wireless device based on an updated security key.
12. The method of claim 11, further comprising: The security configuration associated with the target PScell is activated based on the updated security key.
13. The method according to any one of claims 1-4, wherein: The wireless device is configured with a candidate SN list; The target SN belongs to the candidate SN list; and Each candidate SN in the candidate SN list is associated with a corresponding SW counter.
14. The method of claim 13, further comprising: Receive the initial value of each SW counter corresponding to each candidate SN in the candidate SN list from the master node.
15. The method according to any one of claims 1-4, wherein, Each of the master node and the target SN includes a base station, which includes one of the following: gNodeB(gNB); eNodeB (eNB); ng-eNodeB (ng-eNB); or NodeB.
16. A wireless communication device comprising a memory for storing computer instructions and a processor for communicating with the memory, wherein, When the processor executes the computer instructions, the processor is configured to implement the method of any one of claims 1-15.
17. A computer program product comprising a non-transitory computer-readable program medium having computer code stored thereon, the computer code, when executed by one or more processors, causing the one or more processors to perform the method of any one of claims 1-15.