Authenticating system information blocks using digital signatures

By using digital signature to protect system information blocks (SIBs) in wireless communication networks, the challenge of system information integrity protection is solved, and the credibility and security of system information are achieved.

CN120167121APending Publication Date: 2025-06-17APPLE INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280101678.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-11-07
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

In wireless communication networks, there are challenges in protecting the integrity of system information, especially in the signal transmission between user equipment (UE) and access node (base station). How to ensure the integrity and credibility of system information blocks (SIBs) is an important issue.

Method used

By using a digital signature to protect the system information block (SIB), the integrity of the SIB is authenticated by verifying the validity of the digital signature when the UE receives the SIB. The method includes including an indication in the message sent by the base station that the digital signature is associated with the SIB, and waiting and verifying the corresponding digital signature after the UE receives the SIB.

Benefits of technology

This method effectively protects the integrity of system information in the wireless network, ensures the credibility and security of system information received by the UE, and prevents intermediate attacks or tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120167121A_ABST
    Figure CN120167121A_ABST
Patent Text Reader

Abstract

Methods, systems, and computer-readable media are disclosed for performing operations including: receiving a message including system information (SI) corresponding to at least one system information block (SIB); determining whether the SI includes an indication indicating that the digital signature is associated with at least one SIB; and in response to determining that the SI includes an indication indicating that the digital signature is associated with the at least one SIB, verifying whether the at least one SIB is valid by authenticating the digital signature associated with the at least one SIB.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] Wireless communication networks provide an integrated communication platform and telecommunication services to wireless user equipment. Example telecommunication services include telephony, data (e.g., voice, audio, and / or video data), messaging, Internet access, and / or other services. Wireless communication networks have wireless access nodes that exchange wireless signals with wireless user equipment using wireless network protocols (such as those described in various telecommunication standards). Example wireless communication networks include Code Division Multiple Access (CDMA) networks, Time Division Multiple Access (TDMA) networks, Frequency Division Multiple Access (FDMA) networks, Orthogonal Frequency Division Multiple Access (OFDMA) networks, Long Term Evolution (LTE), Fifth Generation New Radio (5G NR), and networks beyond 5G.

[0002] Access nodes (e.g., base stations) in a wireless network send system information to user equipment (UE) so that the UE can establish a connection with the network. System information messages may include a Master Information Block (MIB) and System Information Blocks (SIBs) to send different types of control information and / or data. Summary of the Invention

[0003] Systems, methods, devices, and non-transitory computer-readable media for authenticating system information by using digital signatures are disclosed. In some embodiments, one or more SIBs (and / or MIBs) are integrity protected using digital signatures. In some embodiments, a UE receives one or more SIBs from an access node (e.g., a base station), and the one or more SIBs include an indication indicating that digital signatures are used to protect the same SIB or other SIBs. The digital signature is received by the UE in a message from the base station, which is separate from the message carrying the protected SIB. Upon receiving the digital signature, the UE authenticates the SIB received in other messages by verifying the validity of the digital signature.

[0004] According to one aspect of the present disclosure, a method is performed by a user equipment (UE). The method includes: receiving a message from a base station (BS), the message including system information (SI) corresponding to at least one System Information Block (SIB); determining whether the SI includes an indication indicating that a digital signature is associated with the at least one SIB; and in response to determining that the SI includes an indication indicating that a digital signature is associated with the at least one SIB, verifying the validity of the at least one SIB by authenticating the digital signature associated with the at least one SIB.

[0005] According to one aspect of the present disclosure, a method is performed by a base station (BS). The method includes: sending a first message to a UE, the first message including system information (SI), the system information (SI) including an indication indicating that a digital signature is associated with at least one system information block (SIB); and sending a second message to the UE, the second message including a digital signature associated with the at least one SIB.

[0006] Details of one or more embodiments of these systems and methods are set forth in the following figures and description. Other features, objects, and advantages of these systems and methods will be apparent from the specification, drawings, and claims. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] Figure 1 A wireless network is illustrated in accordance with some embodiments.

[0008] Figure 2 A flowchart of an example method is illustrated in accordance with some embodiments.

[0009] Figure 3 A flowchart of an example method is illustrated in accordance with some embodiments.

[0010] Figure 4 A user equipment (UE) is illustrated in accordance with some embodiments.

[0011] Figure 5 An access node is illustrated in accordance with some embodiments. DETAILED DESCRIPTION

[0012] The present disclosure describes methods and systems for protecting the integrity of system information in a wireless network. In the disclosed embodiments, system information blocks (SIBs) sent from a base station to a user equipment (UE) are protected with digital signatures. The signature used to protect the SIB may be included in a separate SIB (e.g., a signature SIB) that the UE can receive before, after, or together with the protected SIB. For example, the signature of the SIB may be received at a different time and in a different message than the SIB. When the UE receives a master information block (MIB) or an SIB, the UE may determine whether the SIB includes an indication indicating that a digital signature is associated with the SIB or with one or more other SIBs indicated by the SIB. If the SIB is protected, the UE may wait to receive the corresponding digital signature. After receiving the digital signature, the UE may verify whether the SIB is valid by authenticating the digital signature.

[0013] Figure 1Illustrates a wireless network 100 according to some specific implementations. The wireless network 100 includes a UE 102 and a base station 104 connected via one or more channels 106A, 106B across an air interface 108. The UE 102 and the base station 104 communicate using a system that supports control for managing access of the UE 102 to the network via the base station 104.

[0014] In some specific implementations, the wireless network 100 may be a non-standalone (NSA) network that combines Long-Term Evolution (LTE) and Fifth-Generation (5G) New Radio (NR) communication standards as defined by the technical specifications of the 3rd Generation Partnership Project (3GPP). For example, the wireless network 100 may be an E-UTRA (Evolved Universal Terrestrial Radio Access)-NR Dual Connectivity (EN-DC) network or an NR-EUTRA Dual Connectivity (NE-DC) network. However, the wireless network 100 may also be a standalone (SA) network that combines only 5G NR. Additionally, other types of communication standards are possible, including future 3GPP systems (e.g., Sixth-Generation (6G) systems), Institute of Electrical and Electronics Engineers (IEEE) 802.11 technologies (e.g., IEEE 802.11a; IEEE 802.11b; IEEE 802.11g; IEEE 802.11-2007; IEEE 802.11n; IEEE 802.11-2012; IEEE 802.11ac; or other currently or future-developed IEEE 802.11 technologies), IEEE 802.16 protocols (e.g., WMAN, WiMAX, etc.). Although terms commonly associated with 5G NR may be used herein to describe aspects, aspects of the present disclosure may be applied to other systems, such as 3G, 4G, and / or systems after 5G (e.g., 6G).

[0015] In wireless network 100, UE 102 and any other UE in the system can be, for example, a laptop computer, a smart phone, a tablet computer, a machine type device such as a smart meter for healthcare or a dedicated device, a smart transportation system, or any other wireless device with or without a user interface. In network 100, base station 104 provides a network connection for UE 102 to a wider network (not shown). This UE connection is provided via air interface 108 within the base station service area provided by base station 104. In some specific implementations, such a wider network can be a wide area network operated by a cellular network provider, or can be the Internet. Each base station service area associated with base station 104 is supported by an antenna integrated with base station 104. The service area is divided into multiple sectors associated with certain antennas. Such sectors can be physically associated with fixed antennas, or can be assigned to physical areas with tunable antennas or antenna settings that can be adjusted during the beamforming process for directing signals to specific sectors.

[0016] UE 102 includes control circuit 110 coupled to transmit circuit 112 and receive circuit 114. Transmit circuit 112 and receive circuit 114 can each be coupled to one or more antennas. Control circuit 110 can include various combinations of dedicated circuits and baseband circuits (e.g., Figure 4 baseband processor circuit 422A). In some specific implementations, the baseband processor circuit can include circuits and / or control logic configured to perform various radio / network protocols and radio control functions enabling communication via the RF circuit with one or more channels 106A, 106B. Radio control functions can include, but are not limited to, signal modulation / demodulation, encoding / decoding, radio frequency shifting, etc. In some embodiments, the modulation / demodulation circuit of the baseband circuit can include fast Fourier transform (FFT), precoding, or constellation mapping / demapping functions. In some embodiments, the encoding / decoding circuit of the baseband circuit can include convolutional, tail-biting convolutional, turbo, Viterbi, or low density parity check (LDPC) encoder / decoder functions. Embodiments of the modulation / demodulation and encoder / decoder functions are not limited to these examples and can include other suitable functions in other embodiments. The baseband circuit is configured to process baseband signals received from the receive signal path of the RF circuit and generate baseband signals for the transmit signal path of the RF circuit. The baseband circuit can handle various radio control functions. Transmit circuit 112 and receive circuit 114 can be respectively adapted to transmit and receive data and can include radio frequency (RF) circuits or front-end module (FEM) circuits.

[0017] In various specific implementations, aspects of the transmit circuit 112, receive circuit 114, and control circuit 110 may be integrated in various ways to implement the operations described herein. The control circuit 110 may be adapted or configured to perform various operations, such as operations related to the UE described elsewhere in this disclosure. For example, the control circuit 110 may receive a system information (SI) message including SIBs from the receive circuit 114. In some examples, the minimum SI message includes a master information block (MIB) and a type 1 SIB (SIB1). In some examples, the SI message may include other SIBs (e.g., SIB2, SIB3). In some examples, the SI message may include essential SIBs (e.g., MIB, SIB1, NTN SIB19). The MIB and SIBs may be defined according to TS 38.331. The MIB includes system information transmitted on the broadcast channel (BCH) and has the direction: network to UE. SIB1 includes information relevant when evaluating whether to allow the UE to access the cell and defines the scheduling of other system information. It also includes radio resource configuration information common to all UEs and prohibition information applied to unified access control, and has the direction: network to UE.

[0018] The SI may correspond to the SI described in TS 38.331. The SI is divided into the MIB and a plurality of SIBs and posSIBs, where:

[0019] - The MIB may be transmitted on the BCH with a period of 80 ms and repeated within 80 ms (TS 38.212

[17] , Article 7.1), and it includes parameters required to obtain SIB1 from the cell. The first transmission of the MIB is scheduled in a subframe defined in Article 4.1 of TS 38.213

[13] , and the repetition is scheduled according to the period of the SSB;

[0020] - SIB1 is transmitted on the DL-SCH with a period of 160 ms and a variable transmission repetition period within 160 ms as specified in Article 13 of TS 38.213

[13] . The default transmission repetition period of SIB1 is 20 ms, but the actual transmission repetition period depends on the network implementation. For the SSB and CORESET multiplexing mode 1, the SIB1 repetition transmission period is 20 ms. For the SSB and CORESET multiplexing modes 2 / 3, the SIB1 transmission repetition period is the same as the SSB period (TS 38.213

[13] , Article 13). SIB1 includes information about the availability and scheduling of other SIBs (e.g., the mapping of SIBs to SI messages, periodicity, SI window size), and an indication of whether one or more SIBs are provided only on demand, and in this case includes the configuration required for the UE to perform an SI request. SIB1 is a cell-specific SIB;

[0021] - SIBs other than SIB1 and posSIBs are carried in System Information (SI) messages, which are transmitted on the DL-SCH. Only SIBs or posSIBs with the same periodicity can be mapped to the same SI message. SIBs and posSIBs are mapped to different SI messages. Each SI message is transmitted within a time-domain window that appears periodically (referred to as an SI window of the same length for all SI messages). Each SI message is associated with an SI window, and the SI windows of different SI messages do not overlap. That is, within an SI window, only the corresponding SI message is transmitted. An SI message can be transmitted multiple times within the SI window. Using the indication in SIB1, any SIB or posSIB other than SIB1 can be configured to be cell-specific or area-specific. A cell-specific SIB only applies within the cell that provides the SIB, while an area-specific SIB applies within an area called an SI area, which consists of one or more cells and is identified by the systemInformationAreaID;

[0022] - The mapping of SIBs to SI messages is configured in schedulingInfoList and schedulingInfoList2, while the mapping of posSIBs to SI messages is configured in posSchedulingInfoList and schedulingInfoList2. Even when configured using a common schedulingInfoList2, SIBs and posSIBs are mapped to separate SI messages. Each SIB is included in only a single SI message. In the case of posSIBs, posSIBs carrying GNSS common assistance data for different GNSS / SBAS

[49] are included in different SI messages. Each SIB and posSIB (including posSIBs carrying GNSS common assistance data for one GNSS / SBAS) is included at most once in the SI message;

[0023] - For a UE in RRC_CONNECTED, the network can provide system information via dedicated signaling using the RRCReconfiguration message, for example, if the UE has an active BWP that is not configured to monitor system information, the common search space for paging, or upon request from the UE.

[0024] - For the PSCell and SCell, the network provides the required SI via dedicated signaling (e.g., within the RRCReconfiguration message). However, the UE shall acquire the MIB of the PSCell to obtain the SFN timing of the SCG (which may be different from the MCG). When the relevant SI of the SCell changes, the network releases and adds the relevant SCell. For the PSCell, the required SI can only be changed via a synchronous reconfiguration.

[0025] Note: The physical layer may impose a limit on the maximum size that an SIB can adopt. The maximum SIB1 or SI message size is 2976 bits.

[0026] The SI framework may support flexible scheduling periodicities for SI messages (e.g., 80 / 160 / 320 / 640 / 1280 / 2560 / 5120 ms). In some specific implementations, new SIBS may be defined to be available on demand. The new SIB may carry up to 2976 bits. The enhancements will not apply to legacy UEs. Introducing / adding security information to existing SIBS may make it difficult to introduce / deploy new features in the future. The existing SI framework schedules SIBS by mapping SIBS to SI messages. The new SIB may be mapped to a separate SI message or may be mapped together with other SIBS in an SI message. The specific periodicity of the SI message used to carry the new SIB can be selected via network configuration. Additionally, the network can decide, via implementation, when to start / stop the broadcast of an SIB.

[0027] In some specific implementations, the control circuit 110 may determine whether an SIB is protected based on whether the SI includes an indication that the SIB is associated with a digital signature.

[0028] In some specific implementations, the MIB and each SIB may carry an indication of whether the SIB or MIB has a signature. A new information element (IE) is introduced to carry this indication. The indication may have a value of true or false. When the indication is true, the control circuit 110 may wait to receive the signature. When the indication is false, the control circuit 110 may continue to process the Sib. For example, the SIB1 message as described in TS 38.331 may be modified to introduce a new information element (IE) to carry the indication as follows:

[0029]

[0030]

[0031] The control circuit 110 may modify its actions when receiving the MIB, as described in 5.2.2.4.1 of TS 38.331. As modified, the control circuit 110 may perform the following operations:

[0032] When receiving the MIB, the UE shall:

[0033] 1> Store the obtained MIB;

[0034] 1> Pending and waiting for signature.

[0035] 1> When the signature arrives, the UE verifies the signature

[0036] 1> If the signature verification is successful, and

[0037] 1> If the UE is in RRC_IDLE or RRC_INACTIVE, or if the UE is in RRC_CONNECTED when T311 is running:

[0038] 2> If cellBarred in the obtained MIB is set to barred:

[0039] 3> Then consider the cell as barred according to TS 38.304

[20] ; 3> If intraFreqReselection is set to notAllowed:

[0040] 4> Then consider cell reselection to other cells on the same frequency as the barred cell as not allowed, as specified in TS 38.304

[20] .

[0041] 3> Otherwise:

[0042] 4> Consider cell reselection to other cells on the same frequency as the barred cell as allowed, as specified in TS38.304

[20] .

[0043] 2> Otherwise:

[0044] 3> Apply the received systemFrameNumber, pdcch-ConfigSIB1, subCarrierSpacingCommon, ssb-SubcarrierOffset and dmrs-TypeA-

[0045] Position.

[0046] 1> If the signature verification fails, the UE will bar the cell.

[0047] In some specific implementations, the SIB may carry an indication indicating whether to use a signature to protect one or more other SIBs. For example, the SI-schedulinginfo IE in SIB1 may be used to indicate whether each other SIB indicated by the IE has a corresponding signature. The IE may be modified to include an indication of the other SIB. For example, the SI-SchedulingInfo IE from TS 38.331 may be modified to introduce a new IE to carry the indication as follows:

[0048]

[0049]

[0050] In the above example, each element in the enumeration list of "Signatureindication" indicates whether each SIB enumerated in "Type" is protected by a digital signature. For example, as shown above, the first element with the value "true" indicates that sibType2 (SIB2) has a digital signature, and the second element with the value "false" indicates that sibType3 (SIB3) does not have a digital signature. The enumeration list of "Signatureindication" may include values for each SIB enumerated in "Type".

[0051] In some specific implementations, SIB1 may carry an indication of each SIB other than the MIB and SIB1. The MIB and / or SIB1 may be modified to carry an indication indicating whether the MIB and / or SIB1 has a signature. For example, the SIB1 message may be modified as described above to include an indication indicating whether SIB1 is protected by a digital signature.

[0052] In some specific implementations, the SIB may include a representation of information, which is a hash of the content of the SIB. The hash may be signed using one of the following: (i) a symmetric key shared between the base station 104 and the UE 102, and (ii) the private key in the public key / private key pair of the base station 104. The private key may be known only to the base station 104, while the public key may be known to the UE 102. The UE 102 may use the public key of the base station 104 to verify the hash.

[0053] In some specific implementations, the control circuit 110 may determine whether the signature indication is true. When the signature indication is true, the UE 102 may use fine-grainedness to determine subsequent behavior. In some specific implementations, when the UE 102 receives the MIB and SIB1, since the MIB and SIB1 carry basic network access information, the UE 102 may start to continue with the MIB and SIB1 as specified in TS 38.331. When the signature arrives, the UE 102 verifies the signature. If the verification fails, the UE 102 will prohibit the cell. In some specific implementations, when the UE 102 receives the MIB and SIB1, the UE 102 may store the MIB and SIB. In such specific implementations, the UE 102 only starts to continue after the signature verification is successful. For example, when security is prioritized over network access, the UE 102 may store the MIB and SIB.

[0054] In some specific implementations, when the UE 102 receives an SIB (e.g., a feature-specific SIB), the UE 102 may only store the SIB and not apply the SIB until the signature arrives. After the signature verification is successful, the UE 102 may resume applying the SIB.

[0055] The UE 102 may perform different actions in response to a signature verification failure. In some specific implementations, the UE 102 prohibits the cell from searching for necessary SIBs (e.g., MIB, SIB1, NTN SIB19, etc.) in response to a signature verification failure. In some specific implementations, for non-necessary SIBs (e.g., V2X SIB, MBS SIB, etc.), the UE 102 disables the features associated with the SIB without prohibiting the cell. For example, the UE will not apply the system information in the SIB whose signature cannot be verified, while applying the system information of other SIBs (e.g., those SIBs whose signatures are verified and / or those SIBs that are not integrity-protected).

[0056] The transmitting circuit 112 may perform various operations described in this specification. Additionally, the transmitting circuit 112 may transmit multiple multiplexed uplink physical channels. The multiple uplink physical channels may be multiplexed according to time-division multiplexing (TDM) or frequency-division multiplexing (FDM) and carrier aggregation. The transmitting circuit 112 may be configured to receive block data from the control circuit 110 for transmission across the air interface 108.

[0057] The receiving circuit 114 may perform various operations described in this specification. For example, the receiving circuit 114 may use channels 106A, 106B to receive SI messages. The receiving circuit 114 may send the SI messages to the control circuit 110. Additionally, the receiving circuit 114 may receive multiple multiplexed downlink physical channels from the air interface 108 and relay these physical channels to the control circuit 110. The multiple downlink physical channels may be multiplexed according to TDM or FDM and carrier aggregation. The transmitting circuit 112 and the receiving circuit 114 may send and receive both control data and content data (e.g., messages, images, videos, etc.) structured within data blocks carried by the physical channels.

[0058] Figure 1 The base station 104 is also illustrated. In a particular implementation, the base station 104 may be an NG radio access network (RAN) or 5G RAN, E-UTRAN, non-terrestrial cell, or a traditional RAN such as UTRAN or GERAN. As used herein, the term "NG RAN" etc. may refer to the base station 104 operating in the NR or 5G wireless network 100, and the term "E-UTRAN" etc. may refer to the base station 104 operating in the LTE or 4G wireless network 100. The UE 102 utilizes connections (or channels) 106A, 106B, each connection including a physical communication interface or layer.

[0059] The base station 104 circuitry may include a control circuit 116 coupled to a transmitting circuit 118 and a receiving circuit 120. The transmitting circuit 118 and the receiving circuit 120 may each be coupled to one or more antennas, which may be used to enable communication via the air interface 108. The transmitting circuit 118 and the receiving circuit 120 may be adapted to send and receive data to and from any UE connected to the base station 104, respectively. The transmitting circuit 118 may send downlink physical channels including multiple downlink subframes. The receiving circuit 120 may receive multiple uplink physical channels from various UEs including the UE 102. The base station 104 may include a gNodeB (gNB) base station that supports SIB signatures. Some specific SIBs (e.g., SIB 30, 31, etc.) may carry all signatures.

[0060] In Figure 1In [the figure], one or more channels 106A, 106B are illustrated as implementing an air interface for communication coupling and may conform to a cellular communication protocol, such as a GSM protocol, a CDMA network protocol, a UMTS protocol, a 3GPP LTE protocol, an advanced long term evolution (LTE-A) protocol, LTE-based unlicensed spectrum access (LTE-U), a 5G protocol, an NR protocol, an NR-based unlicensed spectrum access (NR-U) protocol, and / or any other communication protocol discussed herein. In a particular implementation, the UE 102 may directly exchange communication data via the ProSe interface. The ProSe interface may alternatively be referred to as a sidelink (SL) interface and may include one or more logical channels, including but not limited to a physical sidelink control channel (PSCCH), a physical sidelink control channel (PSCCH), a physical sidelink discovery channel (PSDCH), and a physical sidelink broadcast channel (PSBCH). In some particular implementations, the base station 104 uses the channels 106A, 106B to send system information (SI) to the UE 102.

[0061] Figure 2 A flowchart of an example method 200 according to some particular implementations is illustrated. For clarity of presentation, the following description generally describes the method 200 in the context of the other figures in this specification. For example, the method 200 may be performed by Figure 1 the UE 102. It should be understood that the method 200 may be performed, for example, by any suitable system, environment, software, hardware, or a combination of system, environment, software, and hardware, as appropriate. In some particular implementations, the various steps of the method 200 may be run in parallel, combined, looped, or run in any order.

[0062] At 202, the method 200 includes receiving a message from a base station (BS), the message including system information (SI) corresponding to at least one system information block (SIB). For example, the UE 102 may receive a message including the MIB or SIB1 from the base station 104.

[0063] At 204, the method 200 includes determining whether the SI includes an indication that a digital signature is associated with at least one SIB. For example, the UE 102 may determine whether the signature indication element in the message received from the base station 104 includes a value of true or false. In such examples, a value of true indicates that a digital signature is associated with at least one SIB, and a value of false indicates that a digital signature is not associated with at least one SIB.

[0064] At 206, method 200 includes, in response to determining that the SI includes an indication that a digital signature is associated with at least one SIB, verifying whether at least one SIB is valid by authenticating the digital signature associated with at least one SIB. For example, UE 102 may verify the digital signature and determine an action to perform (e.g., apply the SIB, bar the cell) based on whether the signature verification is successful.

[0065] Figure 2 The example method 200 shown may be modified or reconfigured to include additional, fewer, or different steps ( Figure 2 not shown herein), and these steps may be performed in the order shown or in a different order.

[0066] Figure 3 FIG. illustrates a flowchart of an example method 300 according to some specific implementations. For clarity of presentation, the following description generally describes method 300 in the context of other figures in this specification. For example, method 300 may be performed by Figure 1 base station (BS) 104. It should be understood that method 300 may be performed by any suitable system, environment, software, hardware, or combination of system, environment, software, and hardware, as appropriate. In some specific implementations, the various steps of method 300 may be run in parallel, combined, looped, or run in any order.

[0067] At 302, method 300 includes sending a first message to the UE that includes system information (SI) that includes an indication that a digital signature is associated with at least one system information block (SIB). For example, BS 104 sends a message to UE 102 that includes the MIB or SIB1.

[0068] At 304, method 300 includes sending a second message to the UE that includes a digital signature associated with at least one SIB. For example, BS 104 sends a message to UE 102 that includes the digital signature. In such examples, the digital signature may be included in a specific SIB (e.g., SIB 30, 31).

[0069] Figure 3 The example method 300 shown may be modified or reconfigured to include additional, fewer, or different steps ( Figure 3 not shown herein), and these steps may be performed in the order shown or in a different order.

[0070] [[Inventors: Please note that the following paragraph (in red font) is a template, so you can skip to the embodiment section on page 21]]

[0071] Figure 4 Illustrates a UE 400 according to some specific implementations. UE 400 may be similar toFigure 1 UE 102, and is substantially interchangeable therewith.

[0072] UE 400 can be any mobile or non-mobile computing device, such as a mobile phone, computer, tablet, industrial wireless sensor (e.g., microphone, pressure sensor, thermometer, motion sensor, accelerometer, inventory sensor, voltage / current meter, etc.), video device (e.g., camera, video camera, etc.), wearable device (e.g., smart watch), loose IoT device.

[0073] UE 400 may include a processor 402, an RF interface circuit 404, a memory / storage 406, a user interface 408, sensors 410, a driver circuit 412, a power management integrated circuit (PMIC) 414, an antenna structure 416, and a battery 418. The components of UE 400 may be implemented as integrated circuits (ICs), parts of integrated circuits, discrete electronic devices, or other modules, logic, hardware, software, firmware, or combinations thereof. Figure 4 The block diagram is intended to show a high-level view of some of the components of UE 400. However, some of the components shown may be omitted, additional components may be present, and different arrangements of the shown components may occur in other specific implementations.

[0074] The components of UE 400 may be coupled to various other components via one or more interconnects 420, which may represent any type of interface, input / output, bus (local, system, or expansion), transmission line, trace, optical connection, etc., that allows various circuit components (on common or different chips or chip sets) to interact with each other.

[0075] Processor 402 may include processor circuitry, such as, for example, a baseband processor circuit (BB) 422A, a central processing unit circuit (CPU) 422B, and a graphics processing unit circuit (GPU) 422C. Processor 402 may include any type of circuit or processor circuitry that executes or otherwise operates computer-executable instructions (such as program code, software modules, or functional procedures from memory / storage 406) to cause UE 400 to perform the operations described herein.

[0076] In some specific implementations, the baseband processor circuit 422A may access the communication protocol stack 424 in the memory / storage device 406 to communicate via a 3GPP - compatible network. Generally speaking, the baseband processor circuit 422A may access the communication protocol stack to: perform user - plane functions at the physical (PHY) layer, media access control (MAC) layer, radio link control (RLC) layer, packet data convergence protocol (PDCP) layer, service data adaptation protocol (SDAP) layer, and PDU layer; and perform control - plane functions at the PHY layer, MAC layer, RLC layer, PDCP layer, RRC layer, and non - access stratum. In some specific implementations, the PHY - layer operations may additionally / alternatively be performed by components of the RF interface circuit 404. The baseband processor circuit 422A may generate or process baseband signals or waveforms that carry information in a 3GPP - compatible network. In some specific implementations, the waveforms for NR may be based on cyclic - prefix orthogonal frequency - division multiplexing (OFDM) “CP - OFDM” in the uplink or downlink, and discrete Fourier transform - spread OFDM “DFT - S - OFDM” in the uplink.

[0077] The memory / storage device 406 may include one or more non - transient computer - readable media that include instructions (e.g., the communication protocol stack 424), which may be executed by one or more processors in the processor 402 to cause the UE 400 to perform the various operations described herein. The memory / storage device 406 includes any type of volatile or non - volatile memory that may be distributed throughout the UE 400. In some specific implementations, some of the memory / storage device 406 may be located on the processor 402 itself (e.g., L1 cache and L2 cache), while other memory / storage device 406 is located external to the processor 402 but is accessible to it via a memory interface. The memory / storage device 406 may include any suitable volatile or non - volatile memory, such as but not limited to dynamic random - access memory (DRAM), static random - access memory (SRAM), erasable programmable read - only memory (EPROM), electrically erasable programmable read - only memory (EEPROM), flash memory, solid - state memory, or any other type of memory device technology.

[0078] The RF interface circuit 404 may include transceiver circuitry and a radio - frequency front - end module (RFEM), which allows the UE 400 to communicate with other devices via a radio access network. The RF interface circuit 404 may include various elements arranged in a transmit path or a receive path. These elements may include, for example, switches, mixers, amplifiers, filters, synthesizer circuits, control circuits, etc.

[0079] In the receive path, the RFEM can receive a radiated signal from the air interface via the antenna structure 416 and then filter and amplify the signal (using a low-noise amplifier). The signal can be provided to the receiver of the transceiver, which down-converts the RF signal into a baseband signal provided to the baseband processor of the processor 402.

[0080] In the transmit path, the transmitter of the transceiver up-converts the baseband signal received from the baseband processor and provides the RF signal to the RFEM. The RFEM can amplify the signal through a power amplifier before the RF signal is radiated across the air interface via the antenna 416. In various embodiments, the RF interface circuit 404 can be configured to transmit / receive signals in a manner compatible with the NR access technology.

[0081] The antenna 416 can include antenna elements to convert an electrical signal into radio waves to travel through the air and convert the received radio waves into electrical signals. These antenna elements can be arranged into one or more antenna panels. The antenna 416 can have antenna panels with omnidirectional, directional, or a combination thereof to enable beamforming and multiple-input multiple-output communication. The antenna 416 can include a microstrip antenna, a printed antenna fabricated on the surface of one or more printed circuit boards, a patch antenna, a phased array antenna, etc. The antenna 416 can have one or more panels designed for a specific frequency band included in FR1 or FR2.

[0082] The user interface 408 includes various input / output (I / O) devices designed to enable a user to interact with the UE 400. The user interface 408 includes input device circuitry and output device circuitry. The input device circuitry includes any physical or virtual components for accepting input, particularly including one or more physical or virtual buttons (e.g., a reset button), a physical keyboard, a keypad, a mouse, a touchpad, a touch screen, a microphone, a scanner, or a headset, etc. The output device circuitry includes any physical or virtual components for displaying information or otherwise conveying information (such as sensor readings, actuator positions, or other similar information). The output device circuitry can include any number or combination of audio or visual displays, particularly including one or more simple visual outputs / indicators (e.g., binary state indicators (such as light-emitting diodes "LEDs") and multi-character visual outputs) or more complex outputs (such as a display device or a touch screen (e.g., a liquid crystal display "LCD", an LED display, a quantum dot display, a projector, etc.)), where the output of characters, graphics, multimedia objects, etc. is generated or produced by the operation of the UE 400.

[0083] The sensor 410 may include a device, module, or subsystem that is designed to detect events or changes in its environment and transmit information (sensor data) about the detected events to some other device, module, subsystem, etc. Examples of such sensors particularly include: inertial measurement units including accelerometers, gyroscopes, or magnetometers; microelectromechanical systems or nanoelectromechanical systems including three-axis accelerometers, three-axis gyroscopes, or magnetometers; level sensors; temperature sensors (e.g., thermistors); pressure sensors; image capture devices (e.g., cameras or lensless apertures); light detection and ranging sensors; proximity sensors (e.g., infrared radiation detectors, etc.); depth sensors; ambient light sensors; ultrasonic transceivers; microphones, or other similar audio capture devices; and so on.

[0084] The drive circuit 412 may include software elements and hardware elements for controlling specific devices embedded in, attached to, or otherwise communicatively coupled to the UE 400. The drive circuit 412 may include individual drivers, thereby allowing other components to interact with or control various input / output (I / O) devices that may be present within or connected to the UE 400. For example, the drive circuit 412 may include: a display driver for controlling and allowing access to a display device, a touchscreen driver for controlling and allowing access to a touchscreen interface, a sensor driver for obtaining sensor readings from the sensor circuit 410 and controlling and allowing access to the sensor circuit 410, a driver for obtaining the actuator position of an electromechanical component or controlling and allowing access to an electromechanical component, a camera driver for controlling and allowing access to an embedded image capture device, and an audio driver for controlling and allowing access to one or more audio devices.

[0085] The PMIC 414 may manage the power supplied to various components of the UE 400. Specifically, with respect to the processor 402, the PMIC 414 may control power selection, voltage scaling, battery charging, or DC-DC conversion.

[0086] In some specific implementations, the PMIC 414 may control or otherwise be part of various power-saving mechanisms of the UE 400. The battery 418 may power the UE 400, but in some examples, the UE 400 may be installed and deployed in a fixed location and may have a power source coupled to the power grid. The battery 418 may be a lithium-ion battery, a metal-air battery (such as a zinc-air battery, an aluminum-air battery, a lithium-air battery, etc.). In some specific implementations, such as in vehicle-based applications, the battery 418 may be a typical lead-acid automotive battery.

[0087] Figure 5An access node 500 (e.g., a base station or gNB) is illustrated according to some implementations. The access node 500 may be similar to the base station 104 and may be substantially interchangeable therewith. The access node 500 may include a processor 502, an RF interface circuit 504, a core network (CN) interface circuit 506, a memory / storage device circuit 508, and an antenna structure 510.

[0088] The components of access node 500 may be coupled to various other components via one or more interconnects 512. Processor 502, RF interface circuitry 504, memory / storage circuitry 508 (including communication protocol stack 514), antenna structures 510, and interconnects 512 may be similar to those described with respect to FIG. Figure 4 Like-named elements are shown and described.For example, processor 502 may include processor circuits such as baseband processor circuit (BB) 516A, central processor unit circuit (CPU) 516B, and graphics processor unit circuit (GPU) 516C.

[0089] The CN interface circuit 506 may provide connectivity to a core network (e.g., a 5GC using a 5th Generation Core Network (5GC) compatible network interface protocol such as a Carrier Ethernet protocol or some other suitable protocol). Network connectivity may be provided to / from the access node 500 via optical fiber or wireless backhaul. The CN interface circuit 506 may include one or more dedicated processors or FPGAs for communicating using one or more of the aforementioned protocols. In some implementations, the CN interface circuit 506 may include multiple controllers for providing connectivity to other networks using the same or different protocols.

[0090] As used herein, the terms "access node", "access point", etc. may be described as equipment that provides radio baseband functionality for data and / or voice connections between a network and one or more users. These access nodes may be referred to as BS, gNB, RAN node, eNB, NodeB, RSU, TRxP or TRP, etc., and may include ground stations (e.g., terrestrial access points) or satellite stations that provide coverage within a geographic area (e.g., a cell). As used herein, the terms "NG RAN node", etc. may refer to an access node 500 (e.g., a gNB) operating in an NR or 5G system, and the terms "E-UTRAN node", etc. may refer to an access node 500 (e.g., an eNB) operating in an LTE or 4G system. According to various specific implementations, the access node 500 may be implemented as one or more of a dedicated physical device such as a macrocell base station and / or a low power (LP) base station for providing a femtocell, picocell or other similar cell with a smaller coverage area, smaller user capacity or higher bandwidth than a macrocell.

[0091] In some specific implementations, all or part of the access node 500 can be implemented as one or more software entities running on a server computer and as part of a virtual network that can be referred to as a Centralized RAN (CRAN) and / or a virtual baseband unit pool (vBBUP). In a V2X scenario, the access node 500 can be or act as a "road side unit". The term "road side unit" or "RSU" can refer to any traffic infrastructure entity for V2X communication. The RSU can be implemented in or by a suitable RAN node or a stationary (or relatively stationary) UE, where the RSU implemented in or by a UE can be referred to as a "UE-type RSU", the RSU implemented in or by an eNB can be referred to as an "eNB-type RSU", the RSU implemented in or by a gNB can be referred to as a "gNB-type RSU", and so on.

[0092] For ease of description, various components may be described as performing one or more tasks. Such descriptions should be interpreted as including the phrase "configured to". A component described as configured to perform one or more tasks is expressly intended not to invoke an interpretation under 35 U.S.C. § 112(f) for that component.

[0093] For one or more embodiments, at least one of the components shown in one or more of the foregoing figures can be configured to perform one or more of the operations, techniques, processes, or methods described in the following example section. For example, the baseband circuitry described above in connection with one or more of the foregoing figures can be configured to operate according to one or more of the examples described below. As another example, the circuitry associated with a UE, base station, network element, etc., described above in connection with one or more of the foregoing figures can be configured to operate according to one or more of the examples set forth in the following example section.

[0094] Examples

[0095] In the following sections, additional exemplary embodiments are provided.

[0096] Example 1 includes a method performed by a UE, the method including: receiving a message from a base station (BS), the message including system information (SI) corresponding to at least one system information block (SIB); determining whether the SI includes an indication indicating that a digital signature is associated with the at least one SIB; and in response to determining that the SI includes an indication indicating that a digital signature is associated with the at least one SIB, verifying whether the at least one SIB is valid by authenticating the digital signature associated with the at least one SIB.

[0097] Example 2 includes the method according to Example 1, wherein verifying whether the at least one SIB is valid includes: receiving a second message from the BS, the second message including the digital signature associated with the at least one SIB; in response to receiving the second message from the BS, authenticating the at least one SIB by verifying the validity of the digital signature.

[0098] Example 3 includes the method according to Example 2, the method further including: determining that the at least one SIB is trustworthy by verifying that the digital signature is valid; and in response to determining that the at least one SIB is trustworthy, applying the system information included in the at least one SIB.

[0099] Example 4 includes the method according to Example 2, wherein the at least one SIB includes an essential SIB, the method further including: determining that the digital signature is invalid; in response to determining that the digital signature is invalid, prohibiting the cell corresponding to the BS.

[0100] Example 5 includes the method according to Example 2, the method further including: determining that the digital signature is invalid; and in response to determining that the digital signature is invalid, disabling the network feature specified by the information included in the SIB.

[0101] Example 6 includes the method according to Example 1, wherein receiving the message including SI from the BS includes: receiving a System Information Block type 1 (SIB1) message, and wherein the indication indicating that the digital signature is associated with the at least one SIB is included in an information element (IE) added to the SIB1.

[0102] Example 7 includes the method according to Example 6, wherein the at least one SIB is SIB1, and wherein the indication indicating that the digital signature is associated with the at least one SIB includes an indication indicating that the digital signature is associated with SIB1.

[0103] Example 8 includes the method according to Example 1, wherein receiving the message including SI from the BS includes: receiving a System Information Block type 1 (SIB1) message, and wherein the indication indicating that the digital signature is associated with the at least one SIB is included in an information element (IE) added to the SI-schedulinginfo IE.

[0104] Example 9 includes the method according to Example 8, wherein the at least one SIB includes an enumeration of one or more SIBs, and wherein the IE added to the SI-schedulinginfo IE includes an indication indicating whether a digital signature is associated with each of the enumerated one or more SIBs.

[0105] Example 10 includes the method according to Example 9, wherein the one or more enumerated SIBs include one or more of the following: System Information Block type 2 (SIB2), System Information Block type 3 (SIB3), System Information Block type 4 (SIB4), System Information Block type 5 (SIB5), System Information Block type 6 (SIB6), System Information Block type 7 (SIB7), System Information Block type 8 (SIB8), System Information Block type 9 (SIB9).

[0106] Example 11 includes the method according to Example 1, wherein receiving the message including SI from the BS includes: receiving one or more of a Master Information Block (MIB) or a System Information Block type 1 (SIB1) message, and wherein the indication indicating that the digital signature is associated with the at least one SIB includes an indication indicating that the digital signature is associated with the MIB or the SIB1. The method further includes: when receiving the message from the BS, storing the SIB1 without applying the system information included in the MIB or the SIB1; receiving a second message from the BS, the second message including the digital signature associated with the MIB or the SIB1; in response to receiving the second message from the BS, verifying the validity of the digital signature; determining that the MIB or the SIB1 is trustworthy by verifying that the digital signature is valid; and in response to determining that the MIB or the SIB1 is trustworthy, applying the system information included in the MIB or the SIB1.

[0107] Example 12 includes the method according to Example 1, wherein receiving the message including SI from the BS includes: receiving one of a Master Information Block (MIB) or a System Information Block type 1 (SIB1) message, and wherein the indication indicating that the digital signature is associated with the at least one SIB includes an indication indicating that the digital signature is associated with the MIB or the SIB1. The method further includes: when receiving the message from the BS, applying the system information included in the MIB or the SIB1; receiving a second message from the BS, the second message including the digital signature associated with the MIB or the SIB1; in response to receiving the second message from the BS, verifying the validity of the digital signature; in response to verifying that the digital signature is valid, determining that the digital signature is invalid; and in response to determining that the digital signature is invalid, barring the cell corresponding to the BS.

[0108] Embodiment 13 includes a method performed by a base station (BS), the method comprising: sending a first message to a UE, the first message including system information (SI), the system information (SI) including an indication indicating that a digital signature is associated with at least one system information block (SIB); and sending a second message to the UE, the second message including the digital signature associated with the at least one SIB.

[0109] Embodiment 14 includes the method according to Embodiment 13, wherein sending the second message including the digital signature includes: sending a second SIB including the digital signature associated with the at least one SIB.

[0110] Embodiment 15 includes the method according to Embodiment 13, wherein sending the first message including SI includes: sending a System Information Block type 1 (SIB1) message, and wherein the indication indicating that the digital signature is associated with the at least one SIB is included in an information element (IE) added to SIB1.

[0111] Embodiment 16 includes the method according to Embodiment 15, wherein the at least one SIB is SIB1, and wherein the indication indicating that the digital signature is associated with the at least one SIB includes an indication indicating that the digital signature is associated with SIB1.

[0112] Embodiment 17 includes the method according to Embodiment 13, wherein sending the message including SI includes: sending a System Information Block type 1 (SIB1) message, and wherein the indication indicating that the digital signature is associated with the at least one SIB is included in an information element (IE) added to the SI-schedulinginfo IE.

[0113] Embodiment 18 includes the method according to Embodiment 17, wherein the at least one SIB includes an enumeration of one or more SIBs, and wherein the IE added to the SI-schedulinginfo IE includes an indication indicating whether the digital signature is associated with each of the enumerated one or more SIBs.

[0114] Embodiment 19 includes the method according to Embodiment 18, wherein the enumerated one or more SIBs include one or more of the following: System Information Block type 2 (SIB2), System Information Block type 3 (SIB3), System Information Block type 4 (SIB4), System Information Block type 5 (SIB5), System Information Block type 6 (SIB6), System Information Block type 7 (SIB7), System Information Block type 8 (SIB8), System Information Block type 9 (SIB9).

[0115] Example 20 may include one or more non-transitory computer-readable media including instructions that, when executed by one or more processors of an electronic device, cause the electronic device to perform one or more elements of the method according to any one of Examples 1 to 19 or related thereto, or any other method or process described herein.

[0116] Example 21 may include an apparatus including logic, modules, or circuitry for performing one or more elements of the method according to any one of Examples 1 to 19 or related thereto, or any other method or process described herein.

[0117] Example 22 may include the method, technique, or process according to any one of Examples 1 to 19 or related thereto, or a part or portion thereof.

[0118] Example 22 may include an apparatus including: one or more processors and one or more computer-readable media including instructions that, when executed by the one or more processors, cause the one or more processors to perform the method, technique, or process according to any one of Examples 1 to 19 or related thereto, or a part thereof.

[0119] Example 23 may include a signal according to any one of Examples 1 to 19 or related thereto, or a part or portion thereof.

[0120] Example 24 may include a datagram, information element, packet, frame, segment, PDU, or message according to any one of Examples 1 to 19 or related thereto or otherwise described in the present disclosure, or a part or portion thereof.

[0121] Example 25 may include a signal encoded with data according to any one of Examples 1 to 19 or related thereto or otherwise described in the present disclosure, or a part or portion thereof.

[0122] Example 26 may include a signal encoded with a datagram, IE, packet, frame, segment, PDU, or message according to any one of Examples 1 to 19 or related thereto or otherwise described in the present disclosure, or a part or portion thereof.

[0123] Example 27 may include an electromagnetic signal carrying computer-readable instructions, wherein execution of the computer-readable instructions by one or more processors will cause the one or more processors to perform the method, technique, or process according to any one of Examples 1 to 19 or related thereto, or a part thereof.

[0124] Embodiment 28 may include a computer program that includes instructions, where execution of the program by a processing element will cause the processing element to perform a method, technique, or process, or a portion thereof, as described in or related to any one of Embodiments 1 to 19. The operations or actions performed by the instructions executed by the processing element may include the method according to any one of Embodiments 1 to 19.

[0125] Embodiment 29 may include a signal in a wireless network as shown and described herein.

[0126] Embodiment 30 may include a method of communicating in a wireless network as shown and described herein.

[0127] Embodiment 31 may include a system for providing wireless communication as shown and described herein. The operations or actions performed by the system may include the method according to any one of Embodiments 1 to 19.

[0128] Embodiment 32 may include a device for providing wireless communication as shown and described herein. The operations or actions performed by the device may include the method according to any one of Embodiments 1 to 19.

[0129] The previously described Embodiments 1 to 19 can be implemented using: a computer-implemented method; a non-transitory computer-readable medium that stores computer-readable instructions to execute the computer-implemented method; and a computer system that includes a computer memory interoperably coupled with a hardware processor, the hardware processor being configured to execute the computer-implemented method or the instructions stored on the non-transitory computer-readable medium.

[0130] A system (e.g., a base station, a device including one or more baseband processors, etc.) may be configured to perform a particular operation or the action by virtue of software, firmware, hardware, or a combination thereof installed on the system that causes the system to perform the action in operation. The operations or actions performed by the system may include the method according to any one of Embodiments 1 to 19.

[0131] Unless otherwise expressly stated, any one of the above embodiments may be combined with any other embodiment (or combination of embodiments). The foregoing description of one or more specific embodiments provides illustration and description, but is not intended to be exhaustive or to limit the scope of the embodiments to the precise forms disclosed. Modifications and variations are possible in light of the above teachings, or may be acquired from practice of various embodiments.

[0132] While the above embodiments have been described in considerable detail, many variations and modifications will become apparent to those skilled in the art once the above disclosure is fully understood. It is intended that the following claims be interpreted to cover all such variations and modifications.

[0133] It is well known that the use of personally identifiable information should follow privacy policies and practices that are generally recognized as meeting or exceeding industry or government requirements for maintaining user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of inadvertent or unauthorized access or use, and the nature of authorized use should be clearly explained to users.

Claims

1. A method performed by a User Equipment (UE), the method comprising: Receive a message from a base station (BS), the message including system information (SI) corresponding to at least one system information block (SIB); Determine whether the SI includes an indication indicating that a digital signature is associated with the at least one SIB; and In response to determining that the SI includes an indication indicating that a digital signature is associated with the at least one SIB, determine whether the at least one SIB is valid by authenticating the digital signature associated with the at least one SIB.

2. The method according to claim 1, wherein determining whether the at least one SIB is valid comprises: Receive a second message from the BS, the second message including the digital signature associated with the at least one SIB; And In response to receiving the second message from the BS, authenticate the at least one SIB by verifying the validity of the digital signature.

3. The method according to claim 2, wherein verifying the validity of the digital signature comprises: Verify the representation of the information included in the at least one SIB, the representation of the information being digitally signed using one or more cryptographic keys.

4. The method according to claim 2, the method further comprising: Determine that the at least one SIB is trustworthy by verifying that the digital signature is valid; And In response to determining that the at least one SIB is trustworthy, apply the system information included in the at least one SIB.

5. The method according to claim 2, the method further comprising: Determine that the digital signature is invalid; And In response to determining that the digital signature is invalid, prohibit the cell corresponding to the BS.

6. The method according to claim 2, the method further comprising: Determine that the digital signature is invalid; And In response to determining that the digital signature is invalid, disable the network feature specified by the information included in the SIB.

7. The method according to claim 1, wherein receiving the message comprising SI from the BS comprises: Receive a SIB type 1 (SIB1) message, and wherein the indication indicating that the digital signature is associated with the at least one SIB is included in an information element (IE) added to the SIB1.

8. The method according to claim 7, wherein the at least one SIB is SIB1, and wherein the indication indicating that the digital signature is associated with the at least one SIB comprises an indication indicating that the digital signature is associated with SIB1.

9. The method according to claim 1, wherein receiving the message comprising SI from the BS comprises: Receive a SIB type 1 (SIB1) message, and wherein the indication indicating that the digital signature is associated with the at least one SIB is included in an information element (IE) added to the SI-schedulinginfo IE.

10. The method according to claim 9, wherein the at least one SIB comprises an enumeration of one or more SIBs, and wherein the IE added to the SI-schedulinginfo IE comprises an indication indicating whether the digital signature is associated with each of the enumerated one or more SIBs.

11. The method according to claim 10, wherein the one or more SIBs enumerated include one or more of the following: System Information Block type 2 (SIB2), System Information Block type 3 (SIB3), System Information Block type 4 (SIB4), System Information Block type 5 (SIB5), System Information Block type 6 (SIB6), System Information Block type 7 (SIB7), System Information Block type 8 (SIB8), or System Information Block type 9 (SIB9).

12. The method according to claim 1, wherein receiving the message including the SI from the BS includes: Receive one or more of a master information block (MIB) or a SIB type 1 (SIB1) message, and wherein the indication indicating that the digital signature is associated with the at least one SIB includes an indication indicating that the digital signature is associated with the MIB or the SIB1, the method further comprising: When receiving the message from the BS, store the SIB1 without applying the system information included in the MIB or the SIB1; Receive a second message from the BS, the second message including the digital signature associated with the MIB or the SIB1; In response to receiving the second message from the BS, verify the validity of the digital signature; Determine that the MIB or the SIB1 is trustworthy by verifying that the digital signature is valid; and In response to determining that the MIB or the SIB1 is trustworthy, apply the system information included in the MIB or the SIB1.

13. The method according to claim 1, wherein receiving the message including the SI from the BS includes: Receiving one of a master information block (MIB) or a system information block type 1 (SIB1) message, and wherein the indication indicating that the digital signature is associated with the at least one SIB includes an indication indicating that the digital signature is associated with the MIB or the SIB1, the method further comprising: When receiving the message from the BS, applying the system information included in the MIB or the SIB1; Receiving a second message from the BS, the second message including the digital signature associated with the MIB or the SIB1; In response to receiving the second message from the BS, verifying the validity of the digital signature; In response to verifying the validity of the digital signature, determining that the digital signature is invalid; and In response to determining that the digital signature is invalid, prohibiting the cell corresponding to the BS.

14. A method performed by a base station (BS), the method comprising: Sending a first message including system information (SI) to a user equipment (UE), the system information (SI) including an indication indicating that a digital signature is associated with at least one system information block (SIB); and Sending a second message including the digital signature associated with the at least one SIB to the UE.

15. The method according to claim 14, wherein transmitting the second message including the digital signature includes: Sending a second SIB including the digital signature associated with the at least one SIB.

16. The method according to claim 14, wherein transmitting the first message including the SI includes: Sending a system information block type 1 (SIB1) message, and wherein the indication indicating that the digital signature is associated with the at least one SIB is included in an information element (IE) added to the SIB1.

17. The method according to claim 16, wherein the at least one SIB is SIB1, and wherein the indication indicating that the digital signature is associated with the at least one SIB includes an indication indicating that the digital signature is associated with SIB1.

18. The method according to claim 14, wherein transmitting the first message including the SI includes: Sending a system information block type 1 (SIB1) message, and wherein the indication indicating that the digital signature is associated with the at least one SIB is included in an information element (IE) added to the SI-schedulinginfo IE.

19. The method according to claim 18, wherein the at least one SIB includes an enumeration of one or more SIBs, and wherein the IE added to the SI-schedulinginfo IE includes an indication indicating whether a digital signature is associated with each of the enumerated one or more SIBs.

20. The method according to claim 19, wherein the enumerated one or more SIBs include one or more of the following: System Information Block type 2 (SIB2), System Information Block type 3 (SIB3), System Information Block type 4 (SIB4), System Information Block type 5 (SIB5), System Information Block type 6 (SIB6), System Information Block type 7 (SIB7), System Information Block type 8 (SIB8), System Information Block type 9 (SIB9).

21. A non-transitory computer storage medium encoded with instructions that, when executed by one or more processors, cause the one or more processors to perform the method according to any one of the preceding claims.

22. A system that includes one or more computers and one or more storage devices having stored thereon operative instructions that, when executed by the one or more computers, cause the one or more computers to perform the method according to any one of claims 1 to 20.

23. An apparatus that includes one or more baseband processors configured to perform operations including: decoding a message from a base station (BS), the message including system information (SI) corresponding to at least one system information block (SIB); determining whether the SI includes an indication indicating that a digital signature is associated with the at least one SIB; and responsive to determining that the SI includes an indication indicating that a digital signature is associated with the at least one SIB, determining whether the at least one SIB is valid by authenticating the digital signature associated with the at least one SIB.

24. A base station that includes one or more processors configured to perform operations including: sending a first message to a user equipment (UE), the first message including system information (SI) that includes an indication indicating that a digital signature is associated with at least one system information block (SIB); and sending a second message to the UE, the second message including the digital signature associated with the at least one SIB.

25. An apparatus that includes one or more baseband processors configured to perform the method according to any one of claims 1 to 20.

26. A base station, the base station comprising one or more processors configured to perform the method according to any one of claims 1 to 20.