Method and apparatus for supporting security mechanism having different security levels in mobile communication system

By transmitting high-security-level algorithms and encryption key information in wireless communication systems, the problem of sharing key generation between terminals and networks at different security levels is solved, thus achieving the effectiveness and reliability of secure communication.

CN121532988APending Publication Date: 2026-02-13SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480046564.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-07-14
Filing Date
2024-07-10
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

In wireless communication systems, when terminals and networks authenticate each other and generate shared keys, problems may arise due to differences in the security levels of the entities, and existing methods have failed to effectively handle this situation.

Method used

In a wireless communication system, a first network entity receives and sends information related to a user equipment (UE) and a high-security algorithm supported by the first network entity, while a second network entity receives and sends a high-security encryption key, thereby enabling encryption key generation between the terminal and the network.

Benefits of technology

It effectively provides secure communication services between entities with different security levels, improving the security and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121532988A_ABST
    Figure CN121532988A_ABST
Patent Text Reader

Abstract

The present disclosure relates to a method for supporting a higher data transmission rate performed in a 5G or 6G communication system, the method comprising the steps of: receiving, from a user equipment (UE), first information on a designated UE; and transmitting, to a second network entity, second information related to an algorithm supported by the UE and the first network entity based on the first information on the designated UE, the second information including information related to notifying that the algorithm supported by the UE and the first network entity includes an algorithm having a high security level.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a wireless communication system, and more specifically, to a method and apparatus for communicating between entities with different security levels when the entities constituting a terminal and a network have different security levels in the process of mutual authentication and generating a shared key for secure communication. Background Technology

[0002] 5G mobile communication technology defines a wide frequency band to enable fast transmission speeds and new services, and it can be implemented not only in frequency bands of 6 GHz or lower, such as 3.5 GHz (“sub-6 GHz”), but also in ultra-high frequency bands known as millimeter waves, such as 28 GHz and 39 GHz (“above 6 GHz”). Furthermore, 6G mobile communication technology (referred to as super 5G systems) has been considered for implementation in terahertz (THz) bands (e.g., the 95 GHz to 3 THz band) to achieve transmission rates fifty times faster than 5G mobile communication technology and ultra-low latency one-tenth that of 5G mobile communication technology.

[0003] In the early stages of 5G mobile communication technology, in order to meet the service support and performance requirements of enhanced mobile broadband (eMBB), ultra-reliable low-latency communication (URLLC), and massive machine-type communication (mMTC), standardization has been carried out on the following technologies: beamforming and massive multiple-input multiple-output (MIMO) for mitigating radio wave path loss and increasing radio wave transmission distance in millimeter waves; dynamic operation supporting parameter sets (operating multiple subcarrier spacings, etc.) and time slot formats for efficient utilization of millimeter wave resources; initial access technologies supporting multi-beam transmission and broadband; definition and operation of bandwidth portion (BWP); new channel coding methods (such as low-density parity-check (LDPC) codes for large data transmissions and polar codes for highly reliable transmission of control information); L2 preprocessing; and network slicing for providing dedicated networks for specific services.

[0004] Currently, discussions are underway to improve the initial 5G mobile communication technology and enhance its performance, while also considering the services that 5G mobile communication technology is intended to support, and there is already physical layer standardization regarding technologies such as: Vehicle-to-Everything (V2X) for assisting autonomous vehicles in determining driving based on information about the location and status of vehicles transmitted by vehicles and for enhancing user convenience; New Radio Unlicensed (NR-U) designed to make system operation in unlicensed bands comply with various regulatory requirements; NR UE power saving; Non-Terrestrial Networks (NTN) for UE-satellite direct communication to provide coverage in areas where communication with terrestrial networks is unavailable; and positioning.

[0005] Furthermore, standardization is underway in the wireless interface architecture / protocol domain for technologies such as: Industrial Internet of Things (IIoT) to support new services through interoperability and convergence with other industries; Integrated Access and Backhaul (IAB) for nodes to provide network service area extension by supporting wireless backhaul and access links in an integrated manner; mobility enhancements including conditional handover and Dual Active Protocol Stack (DAPS) handover; and 2-step RACH for NR to simplify the random access process. In terms of system architecture / services, standardization is also underway for: 5G baseline architectures (e.g., service-based architectures or service-based interfaces) for combining Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies; and Mobile Edge Computing (MEC) for UE location-based reception services.

[0006] When such 5G mobile communication systems are commercialized, the already exponentially growing number of connected devices will be connected to the communication network, and therefore, enhanced functionality and performance of 5G mobile communication systems, as well as integrated operation of connected devices, are expected to be necessary. To this end, new research is planned related to: Extended Reality (XR) for effectively supporting Augmented Reality (AR), Virtual Reality (VR), Mixed Reality (MR), etc.; improving 5G performance and reducing 5G complexity by leveraging Artificial Intelligence (AI) and Machine Learning (ML); AI service support; Metaverse service support; and drone communication.

[0007] Furthermore, this development of 5G mobile communication systems will serve as a foundation for: not only developing full-duplex technologies to improve the frequency efficiency of 6G mobile communication technologies and enhance system networks; AI-based communication technologies to optimize systems by leveraging satellites and AI (artificial intelligence) from the design phase and internalizing end-to-end AI support capabilities; and next-generation distributed computing technologies to provide services at a complexity level exceeding the operational capabilities of UEs by utilizing ultra-high-performance communication and computing resources; but also developing new waveforms for providing terahertz band coverage for 6G mobile communication technologies, multi-antenna transmission technologies (such as full-dimensional MIMO (FD-MIMO), array antennas, and massive MIMO), metamaterial-based lenses and antennas for improving terahertz band signal coverage, high-dimensional spatial multiplexing technologies using orbital angular momentum (OAM), and reconfigurable smart surfaces (RIS). Summary of the Invention

[0008] Technical issues

[0009] Based on the foregoing discussion, the purpose of this disclosure is to address the following problem. In wireless communication systems, when a terminal and a network perform mutual authentication and generate a shared key for subsequent secure communication, the entities constituting the terminal and the network can have different security levels. Existing methods have been designed in this context without considering the possibility of these entities having different security levels, which can lead to problems. Therefore, this disclosure aims to solve the aforementioned problem.

[0010] Solution to the problem

[0011] According to this disclosure for solving the above-mentioned problems, a method performed by a first network entity in a wireless communication system may include: receiving first information about a specified UE from a user equipment (UE); and, based on the first information about the specified UE, sending second information related to an algorithm supported by the UE and the first network entity to a second network entity, wherein the second information may be related to notifying the UE and the first network entity that the supported algorithm includes an algorithm with a high security level.

[0012] In an embodiment, the first information may be associated with an encryption algorithm supported by the UE.

[0013] In an embodiment, the method may further include receiving third information from a second network entity regarding the derivation of a high-security-level encryption key related to authentication and shared key generation.

[0014] In an embodiment, when the third information is received, the method may further include sending all or part of the third information to the UE, wherein the UE may include a subscriber identification module (SIM) and a mobile device (ME), and all or part of the third information may be sent from the ME to the SIM.

[0015] Furthermore, in another embodiment of this disclosure, the method performed by the second network entity in the wireless communication system may include: receiving, based on first information about a specified UE, second information related to the UE and an algorithm supported by the first network entity from the first network entity, wherein the first information about the specified UE may be sent from the UE to the first network entity, and the second information may be related to notifying the UE and the first network entity that the supported algorithms include algorithms with a high security level.

[0016] Furthermore, in another embodiment of this disclosure, a first network entity in a wireless communication system may include: a transceiver capable of transmitting and receiving at least one signal; and a controller coupled to the transceiver, wherein the controller may be configured to: receive first information about a specified UE from a user equipment (UE), and based on the first information about the specified UE, transmit second information related to an algorithm supported by the UE and the first network entity to a second network entity, wherein the second information may be related to notifying the UE and the first network entity that the supported algorithm includes an algorithm with a high security level.

[0017] Furthermore, in another embodiment of this disclosure, the second network entity in the wireless communication system may include: a transceiver capable of transmitting and receiving at least one signal; and a controller coupled to the transceiver, wherein the controller may be configured to: receive, based on first information about a specified UE, second information relating to the UE and an algorithm supported by the first network entity, wherein the first information about the specified UE may be transmitted from the UE to the first network entity, and the second information may be related to notifying the UE and the first network entity that the supported algorithm includes an algorithm with a high security level.

[0018] Beneficial effects of the invention

[0019] Various embodiments of this disclosure can provide an apparatus and method capable of effectively providing services in a wireless communication system.

[0020] The effects that can be obtained from this disclosure are not limited to those mentioned in the various embodiments, and other effects not mentioned can be clearly understood by those skilled in the art to which this disclosure pertains from the following description. Attached Figure Description

[0021] Figure 1a This is a diagram illustrating a communication network including a core network entity in a wireless communication system according to various embodiments of the present disclosure.

[0022] Figure 1b This is a diagram illustrating a wireless environment including a core network in a wireless communication system according to various embodiments of the present disclosure.

[0023] Figure 2a This is a block diagram illustrating an example of the functional structure of a terminal according to an embodiment of the present disclosure.

[0024] Figure 2b This is a block diagram illustrating an example of the functional structure of a base station according to an embodiment of the present disclosure.

[0025] Figure 2c This is a block diagram illustrating an example of the functional structure of a core network entity according to an embodiment of the present disclosure.

[0026] Figure 3 This is a diagram illustrating a hierarchical structure of encryption keys for secure communication generated by a terminal and a network according to embodiments of the present disclosure.

[0027] Figure 4 This is a message flow diagram illustrating the authentication process of a terminal and a network, and the shared key generation process for secure communication, according to embodiments of the present disclosure.

[0028] Figure 5 This is a message flow diagram illustrating the authentication process of terminals and networks with different security levels, as well as the shared key generation process for secure communication, according to embodiments of this disclosure.

[0029] Figure 6 This is a message flow diagram illustrating an authentication process between terminals and networks with different security levels, and a shared key generation process for secure communication, according to another embodiment of this disclosure. Detailed Implementation

[0030] The terminology used in this disclosure is intended to describe particular embodiments only and may not be intended to limit the scope of other embodiments. Singular expressions may include plural expressions unless the context clearly indicates otherwise. The terminology used herein, including technical or scientific terms, may have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains. Terms used in this disclosure that are defined in a general dictionary may be interpreted as having the same or similar meaning in the context of related art and should not be interpreted in an idealized or overly formal sense unless explicitly defined in this disclosure. In some cases, even terms defined in this disclosure should not be construed as excluding embodiments of this disclosure.

[0031] In the various embodiments of this disclosure described below, hardware-based methods are illustrated by way of example. However, because the various embodiments of this disclosure include techniques utilizing both hardware and software, the various embodiments of this disclosure are not intended to exclude software-based methods.

[0032] The 3rd Generation Partnership Project (3GPP), responsible for standardizing cellular mobile communication systems, is standardizing a new core network architecture called the 5G Core (5GC) to enable the evolution from existing 4G LTE systems to 5G systems. Compared to the Evolved Packet Core (EPC), which serves as the network core for existing 4G systems, the 5GC supports the following differentiated features.

[0033] First, 5GC introduces network slicing functionality. As one of the requirements of 5G, 5GC should support various types of terminals and services (e.g., eMBB, URLLC, or mMTC services). Different types of services have different requirements for the core network. For example, eMBB services require high data rates, while URLLC services require high reliability and low latency. One technology proposed to meet these diverse service requirements is network slicing.

[0034] Network slicing is a method of creating multiple logical networks by virtualizing a single physical network, and each Network Slice Instance (NSI) can have different characteristics. Therefore, each NSI can meet various service requirements by including Network Functions (NFs) tailored to its characteristics. Multiple 5G services can be effectively supported when NSIs with characteristics suitable for the services required by each terminal are allocated.

[0035] Second, 5GC can facilitate support for network virtualization paradigms by separating mobility management and session management functions. In 4G LTE, services are provided through signaling exchange with a single core entity called the Mobility Management Entity (MME), which is responsible for registration, authentication, mobility management, and session management of all terminals. However, in 5G, with the explosive increase in the number of terminals and the greater diversity of mobility and service / session characteristics to be supported based on terminal type, supporting all functions in a single entity such as the MME inevitably leads to limited scalability, as each required function necessitates the addition of an additional entity. Therefore, to improve scalability in terms of the functional / implementation complexity and signaling load of the core entity responsible for the control plane, various functions are being developed based on an architecture that separates mobility management and session management functions.

[0036] In the following, various embodiments will be described in detail with reference to the accompanying drawings. Furthermore, in describing embodiments of this disclosure, detailed descriptions of known functions or constructions will be omitted where it is determined that such detailed descriptions might unnecessarily obscure the subject matter of the embodiments. The terminology described below is defined in consideration of the functions in the embodiments and may vary according to the intent or habits of the user and operator. Therefore, definitions should be based on the entire contents of this specification.

[0037] For the same reason, some components are exaggerated, omitted, or shown schematically in the accompanying drawings. Furthermore, the dimensions of each component do not perfectly reflect the actual dimensions. In all the drawings, the same reference numerals are used to label identical or equivalent components.

[0038] The advantages and features of this disclosure, as well as methods of implementing them, will become apparent from the following detailed description of the embodiments in conjunction with the accompanying drawings. However, this disclosure is not limited to the embodiments disclosed below, but can be implemented in various different forms, and only these embodiments complete this disclosure and are provided to fully inform those skilled in the art of the scope of this disclosure, which is limited only by the scope of the claims. Throughout this specification, the same reference numerals refer to the same components.

[0039] In this context, it should be understood that each block of the message flow diagram and combinations of message flow diagrams can be executed by computer program instructions. Because these computer program instructions can be mounted on the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, the instructions executed by the processor of the computer or other programmable data processing equipment generate means for performing the functions described in the message flow diagram blocks. Because these computer program instructions can be stored in a computer-usable or computer-readable storage device, and can instruct the computer or other programmable data processing equipment to implement functions in a particular manner, the instructions stored in the computer-usable or computer-readable storage device can produce a product containing instruction means for performing the functions described in the message flow diagram blocks. Because the computer program instructions can be mounted on a computer or other programmable data processing equipment, a series of operational steps are performed on the computer or other programmable data processing equipment to generate a computer-executable process; therefore, the instructions for performing the computer or other programmable data processing equipment can provide steps for performing the functions described in one or more message flow diagram blocks.

[0040] Furthermore, each box may represent a portion of a module, segment, or code that includes one or more executable instructions for performing a specified logical function. It should also be noted that in some alternative implementations, the functions described in the boxes may not occur in a sequential order. For example, two boxes shown one after the other may actually execute substantially simultaneously, or these boxes may sometimes execute in reverse order according to their respective functions.

[0041] In this context, the term "-unit" as used in the various embodiments of this disclosure refers to a software or hardware component, such as a field-programmable gate array (FPGA) or application-specific integrated circuit (ASIC), and a "-unit" may perform certain roles. However, a "-unit" is not limited to software or hardware. A "unit" may be configured to reside in an addressable memory medium or may be configured to reproduce one or more processors. Thus, by way of example, a "-unit" may include components such as software components, object-oriented software components, class components, and task components, processes, functions, attributes, procedures, subroutines, program code segments, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functionality provided in components and "-units" may be combined into a smaller number of components and "-units," or may be further separated into additional components and "-units." Furthermore, components and "-units" may be implemented to reproduce one or more CPUs in a device or secure multimedia card.

[0042] In the following text, as the entity performing resource allocation for a terminal, a base station can be at least one of an eNode B (eNB), a Node B, a base station (BS), a radio access network (RAN), an access network (AN), a RAN node, an NR NB, a gNB, a radio access unit, a base station controller, or a node on a network. A terminal can include a user equipment (UE), a mobile station (MS), a cellular phone, a smartphone, a computer, or a multimedia system capable of performing communication functions. In various embodiments of this disclosure, the case where the terminal is a UE is described as an example. Furthermore, although various embodiments of this disclosure are described below using LTE, LTE-A, or NR-based systems as examples, these embodiments can also be applied to other communication systems with similar technical backgrounds or channel types. Moreover, as those skilled in the art will understand, various embodiments of this disclosure can be applied to other communication systems with modifications that do not substantially depart from the scope of this disclosure.

[0043] In the following description, for ease of description, terms for identifying connected nodes, referring to network entities, referring to messages, referring to interfaces between network entities, referring to various types of identification information, etc., are provided only as examples. Therefore, this disclosure is not limited to the terms described below, and other terms that refer to objects with equivalent technical meanings may be used.

[0044] Furthermore, although this disclosure uses terminology used in certain communication standards (e.g., the 3rd Generation Partnership Project (3GPP)) to describe various embodiments, this is merely for illustrative purposes. The various embodiments of this disclosure can be readily modified and applied to other communication systems. Below, some terms used in the core network of this disclosure are predefined.

[0045] AMF Access and Mobility Management Functions

[0046] CN Core Network

[0047] CNF containerized network functionality

[0048] DNN data network name

[0049] PCF strategy control function

[0050] HSS Belongs to Subscriber Server

[0051] SMF Session Management Function

[0052] UDM User Data Management

[0053] UPF User Plane Functions

[0054] CNF containerized network functionality

[0055] VNF Virtual Network Function

[0056] Figure 1a This is a diagram illustrating a communication network including a core network entity in a wireless communication system according to various embodiments of the present disclosure. The 5G mobile communication network may include a 5G user equipment (UE) 110, a 5G radio access network (RAN) 120, and a 5G core network.

[0057] The 5G core network may include network functions such as Access and Mobility Management Function (AMF) 150, which provides mobility management functions for UEs; Session Management Function (SMF) 160, which provides session management functions; User Plane Function (UPF) 170, which performs data transmission roles; Policy Control Function (PCF) 180, which provides policy control functions; Unified Data Management (UDM) 153, which provides data management functions such as subscriber data and policy control data; or Unified Data Repository (UDR), which stores data for various network functions.

[0058] refer to Figure 1aUE 110 can communicate via a wireless channel (i.e., an access network formed with base stations (e.g., eNB, gNB)). In some embodiments, UE 110 can be a device used by a user and configured to provide a user interface (UI). As an example, UE 110 can be a UE equipped in a vehicle for driving. In some other embodiments, UE 110 can be a device performing machine-type communication (MTC) without user intervention, or it can be an autonomous vehicle. UE can also be referred to as a "terminal," "vehicle terminal," "user equipment (UE)," "mobile station," "subscriber station," "remote terminal," "wireless terminal," "user device," or other terms with equivalent technical meanings. As a terminal device, in addition to UE, a customer premises equipment (CPE) or a dongle-type terminal can be used. CPE can be connected to an NG-RAN node like a UE and provide network access to other communication devices (e.g., laptop computers).

[0059] refer to Figure 1a The AMF 150 can provide access and mobility management functions for each UE 110, and each UE 110 can essentially be connected to a single AMF 150. Specifically, the AMF 150 can perform at least one of the following functions: signaling between core network nodes for mobility between 3GPP access networks, an interface (N2 interface) between radio access networks (e.g., 5G RAN) 120, NAS signaling with UE 110, identification of SMF 160, or providing the transmission of session management (SM) messages between UE 110 and SMF 160. Some or all of the functions of the AMF 150 can be supported within a single instance of an AMF 150.

[0060] refer to Figure 1a The SMF 160 can provide session management functions, and in the case of multiple sessions on the UE 110, each session can be managed by a different SMF 160. Specifically, the SMF 160 can perform at least one of the following functions: session management (e.g., session establishment, modification, and release, including maintenance of the tunnel between the UPF 170 and access network nodes), selection and control of user plane (UP) functions, configuration of traffic redirection for routing services to appropriate destinations in the UPF 170, termination of the SM portion of NAS messages, and initiation of downlink data notification (DDN) or AN-specific SM information (e.g., transmitted to the access network via the N2 interface through the AMF 150). Some or all of the functions of the SMF 160 can be supported within a single instance of the SMF 160.

[0061] In 3GPP systems, the conceptual link connecting NFs within a 5G system can be referred to as a reference point. A reference point can also be referred to as an interface. The following illustrates reference points (hereinafter, interchangeably referred to as interfaces) included in the 5G system architectures shown in various embodiments of this disclosure.

[0062] -N1: Reference point between UE 110 and AMF 150

[0063] -N2: (R) Reference point between AN 120 and AMF150

[0064] -N3: (R) Reference point between AN 120 and UPF170

[0065] -N4: Reference point between SMF 160 and UPF 170

[0066] -N5: Reference point between PCF 180 and AF 130

[0067] -N6: Reference point between UPF 170 and DN 140

[0068] -N7: Reference point between SMF 160 and PCF 180

[0069] -N8: Reference point between UDM 153 and AMF 150

[0070] -N9: Reference point between two cores with a UPF of 170

[0071] -N10: Reference point between UDM 153 and SMF 160

[0072] -N11: Reference point between AMF 150 and SMF 160

[0073] -N12: Reference point between AMF 150 and Authentication Server Function (AUSF) 151

[0074] -N13: Reference point between UDM 153 and AUSF 151

[0075] -N14: Reference point between the two AMF 150s

[0076] -N15: The reference point between PCF 180 and AMF 150 in non-roaming scenarios, and the reference point between PCF 180 and AMF 150 within the surveyed network in roaming scenarios.

[0077] Figure 1b This is a diagram illustrating a wireless environment including a core network in a wireless communication system according to an embodiment of the present disclosure. Reference Figure 1b The wireless communication system includes Radio Access Network (RAN) 120 and Core Network (CN).

[0078] RAN 120 is a network directly connected to a user equipment (e.g., UE 110) and serves as the infrastructure for providing radio access to UE 110. RAN 120 includes a group of multiple base stations, including base station 125, and the multiple base stations can communicate with each other through interfaces formed therebetween. At least some of the interfaces between the multiple base stations can be wired or wireless. Base station 125 may have a structure divided into central units (CU) and distributed units (DU). In this case, one CU can control multiple DU. In addition to the term "base station," base station 125 may also be referred to as an "access point (AP)," "next-generation node B (gNB)," "fifth-generation node (5G node)," "radio point," "transmit / receive point (TRP)," or other terms with equivalent technical meanings. UE 110 accesses RAN 120 and communicates with base station 125 via a radio channel. In addition to the term "terminal," UE 110 may be referred to as a "user equipment (UE)," "mobile station," "subscriber station," "remote terminal," "radio terminal," "user device," or other terms with equivalent technical meanings.

[0079] The core network is the network that manages the entire system, controls RAN 120, and processes data and control signals transmitted and received through RAN 120 for UE 110. The core network performs various functions, such as user plane and control plane control, mobility management, subscriber information management, charging, and interoperability with other types of systems (e.g., Long Term Evolution (LTE) systems). To perform these functions, the core network may include multiple functionally separate entities with different network functions (NFs). For example, core network 200 may include Access and Mobility Management Function (AMF) 150, Session Management Function (SMF) 160, User Plane Function (UPF) 170, Policy and Charging Function (PCF) 180, Network Repository Function (NRF) 159, Unified Data Management (UDM) 153, Network Exposure Function (NEF) 155, and Unified Data Repository (UDR) 157.

[0080] UE 110 connects to RAN 120 and accesses AMF 150, which performs mobility management functions for the core network. AMF 150 is the function or entity responsible for both access to RAN 120 and mobility management for UE 110. SMF 160 is the NF that manages the session. AMF 150 connects to SMF 160 and routes session-related messages for UE 110 to SMF 160. SMF 160 connects to UPF 170 to allocate user plane resources to be provided to UE 110 and establishes tunnels for transmitting data between base station 125 and UPF 170. PCF 180 controls policy and charging-related information for the session used by UE 110.

[0081] NRF 159 performs the function of storing information about NFs installed in the mobile communication operator's network and notifying the stored information. NRF 159 can connect to all NFs. When each NF begins operation in the operator's network, it registers with NRF 159 to notify NRF 159 that the corresponding NF is operating within the network. UDM 153 is an NF that performs a similar function to the Home Subscriber Server (HSS) in a 4G network and stores the subscription information of UE 110 or the context in which UE 110 is used within the network.

[0082] NEF 155 is used to connect third-party servers and NFs within the 5G mobile communication system. Furthermore, NEF 155 performs functions of providing data to, updating, or retrieving data from UDR 157. UDR 157 performs functions of storing UE 110's subscription information, policy information, data exposed to external entities, or information required by third-party applications. Additionally, UDR 157 performs functions of providing the stored data to other NFs.

[0083] Figure 2a This is a block diagram illustrating an example of the functional structure of a UE according to an embodiment of the present disclosure. Figure 2a The configuration shown can be understood as the configuration of UE 110. Terms such as “…unit” and “…device” used below refer to a unit that processes at least one function or operation, which can be implemented by hardware, software or a combination of hardware and software.

[0084] refer to Figure 2a The UE includes a communication unit 205, a memory 210, and a controller 215.

[0085] Communication unit 205 performs functions for transmitting and receiving signals via a wireless channel. For example, communication unit 205 performs conversion between baseband signals and bitstreams according to the system's physical layer specifications. For instance, when transmitting data, communication unit 205 generates complex symbols by encoding and modulating the transmitted bitstream. Furthermore, when receiving data, communication unit 205 recovers the received bitstream by demodulating and decoding the baseband signal. Additionally, communication unit 205 up-converts the baseband signal to an RF band signal and transmits it via an antenna, and down-converts the RF band signal received via the antenna back to a baseband signal. For example, communication unit 205 may include a transmit filter, a receive filter, an amplifier, a mixer, an oscillator, a digital-to-analog converter (DAC), an analog-to-digital converter (ADC), etc.

[0086] Furthermore, the communication unit 205 may include multiple transmit and receive paths. Additionally, the communication unit 205 may include at least one antenna array composed of multiple antenna elements. In terms of hardware, the communication unit 205 may be constructed from digital and analog circuits (e.g., radio frequency integrated circuits (RFICs)). Here, the digital and analog circuits can be implemented in a single package. Furthermore, the communication unit 205 may include multiple RF chains. Furthermore, the communication unit 205 may perform beamforming.

[0087] As described above, the communication unit 205 transmits and receives signals. Therefore, all or part of the communication unit 205 may be referred to as a "transmitter," a "receiver," or a "transceiver." Furthermore, in the following description, the term "transmission and reception via a wireless channel" is used to include the processing performed by the communication unit 205 as described above.

[0088] Memory 210 stores data such as basic programs, application programs, and configuration information for the operation of the UE. Memory 210 may be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. Furthermore, memory 210 provides stored data upon request from controller 215.

[0089] Controller 215 controls the overall operation of the UE. For example, controller 215 sends and receives signals via communication unit 205. Furthermore, controller 215 records and retrieves data from memory 210. Additionally, controller 215 can perform the functions of the protocol stack required by the communication standard. For this purpose, controller 215 may include at least a processor or microprocessor, or may be part of a processor. Furthermore, communication unit 205 and a portion of controller 215 may be referred to as a communication processor (CP). According to various embodiments, controller 215 can control synchronization performed using a wireless communication network. For example, controller 215 can control the UE to perform operations according to various embodiments described below.

[0090] According to various embodiments of this disclosure, a terminal may consist of a mobile device (ME) and a Universal Mobile Telecommunications Service (UMTS) Subscriber Identity Module (USIM). The ME may include a mobile terminal (MT) and a terminal device (TE). The MT may be a part of a radio access protocol operating therein, and the TE may be a part of control functions operating therein. For example, in the case of a wireless communication terminal (e.g., a mobile phone), the MT and TE may be integrated, while in the case of a laptop computer, the MT and TE may be separate. In this disclosure, the ME and USIM may be represented as different entities depending on the operation of each component, but this disclosure is not limited thereto, and various embodiments of this disclosure can be described by referring to a terminal (e.g., a UE) that includes both the ME and the USIM, or by referring to the ME as a terminal.

[0091] Figure 2b This is a block diagram illustrating an example of the functional structure of a base station according to an embodiment of the present disclosure. Figure 2b The configuration shown can be understood as the configuration of base station 120. Terms such as “…unit” and “…device” used below refer to a unit that processes at least one function or operation, which can be implemented by hardware, software or a combination of hardware and software.

[0092] Reference Figure 2b The base station includes a wireless communication unit 235, a backhaul communication unit 220, a memory 225, and a controller 230.

[0093] The wireless communication unit 235 performs functions for transmitting and receiving signals via a wireless channel. For example, the wireless communication unit 235 performs conversion functions between baseband signals and bitstreams according to the system's physical layer specifications. For example, when transmitting data, the wireless communication unit 235 encodes and modulates the transmitted bitstream to generate complex symbols. Furthermore, when receiving data, the wireless communication unit 235 recovers the received bitstream by demodulating and decoding the baseband signal.

[0094] Furthermore, the wireless communication unit 235 up-converts the baseband signal into a radio frequency (RF) band signal and transmits it through an antenna, and down-converts the RF band signal received through the antenna back into a baseband signal. For this purpose, the wireless communication unit 235 may include a transmit filter, a receive filter, an amplifier, a mixer, an oscillator, a digital-to-analog converter (DAC), an analog-to-digital converter (ADC), etc. Furthermore, the wireless communication unit 235 may include multiple transmit and receive paths. Additionally, the wireless communication unit 235 may include at least one antenna array composed of multiple antenna elements.

[0095] In terms of hardware, the wireless communication unit 235 can be composed of digital units and analog units, and the analog units can be composed of multiple sub-units according to operating power, operating frequency, etc. The digital units can be implemented by at least one processor (e.g., a digital signal processor (DSP)).

[0096] As described above, the wireless communication unit 235 transmits and receives signals. Therefore, all or part of the wireless communication unit 235 may be referred to as a "transmitter," a "receiver," or a "transceiver." Furthermore, in the following description, the term "transmission and reception performed via a wireless channel" is used to include the processes described above performed by the wireless communication unit 235.

[0097] The backhaul communication unit 220 provides an interface for performing communication with other nodes within the network. That is, the backhaul communication unit 220 converts bit streams sent from the base station to another node (e.g., another access node, another base station, upper-layer node, and core network) into physical signals, and converts physical signals received from another node into bit streams.

[0098] The memory 225 stores data such as basic programs, application programs, and configuration information for operating the base station. The memory 225 may be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. Furthermore, the memory 225 provides stored data upon request from the controller 230.

[0099] Controller 230 controls the overall operation of the base station. For example, controller 230 sends and receives signals via wireless communication unit 235 or backhaul communication unit 220. Furthermore, controller 230 records and retrieves data in memory 225. Additionally, controller 230 can perform the functions of the protocol stack required by the communication standard. According to another implementation example, the protocol stack may be included in wireless communication unit 235. For this purpose, controller 230 may include at least one processor. According to various embodiments, controller 230 can control synchronization performed using a wireless communication network. For example, controller 230 can control the base station to perform operations according to various embodiments described below.

[0100] Figure 2c This is a block diagram illustrating an example of the functional structure of a core network entity according to an embodiment of the present disclosure. Figure 2c The composition of core network entities in a wireless communication system according to various embodiments of the present disclosure is illustrated. Figure 2c The configuration shown can be understood as the configuration of a device having the functionality of at least one of the network entities including the AMF 150 of FIG1. ​​Terms such as “…unit” and “…device” as used herein refer to a unit that processes at least one function or operation, and this can be implemented by hardware, software, or a combination of hardware and software.

[0101] refer to Figure 2c The core network entities include a communication unit 240, a memory 245, and a controller 250.

[0102] Communication unit 240 provides an interface for performing communication with other devices within the network. That is, communication unit 240 converts bit streams sent from the core network entity to another device into physical signals, and converts physical signals received from another device back into bit streams. In other words, communication unit 240 can both send and receive signals. Therefore, communication unit 240 can be referred to as a modem, transmitter, receiver, or transceiver. In this context, communication unit 240 enables the core network entity to communicate with other devices or systems via a backhaul connection (e.g., wired or wireless backhaul) or via the network.

[0103] Memory 245 stores data such as basic programs, application programs, and configuration information for operating core network entities. Memory 245 may consist of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. Furthermore, memory 245 provides stored data upon request from controller 250.

[0104] Controller 250 controls the overall operation of the core network entity. For example, controller 250 sends and receives signals via communication unit 240. Furthermore, controller 250 records and retrieves data from memory 245. For this purpose, controller 250 may include at least one processor. According to various embodiments of this disclosure, controller 250 can control synchronization performed using a wireless communication network. For example, controller 250 can control the core network entity to perform operations according to various embodiments described below.

[0105] In the following description, for ease of description, terms for identifying connected nodes, referring to network entities, referring to messages, referring to interfaces between network entities, referring to various types of identification information, etc., are provided only as examples. Therefore, this disclosure is not limited to the terms described below, and other terms that refer to objects with equivalent technical meanings may be used.

[0106] In the following text, for ease of description, this disclosure uses terms and names defined in 5G System (5GS) and New Radio (NR) standards, which are the most recent standards defined by the 3rd Generation Partnership Project (3GPP) organization among current existing communication standards. However, this disclosure is not limited to the terms and names and can be applied equivalently to wireless communication networks conforming to other standards. In particular, this disclosure can be applied to 3GPP 5G mobile communication standards (e.g., 5GS and NR).

[0107] Figure 3 This is a diagram illustrating the hierarchical structure of encryption keys for secure communication generated by the UE and the network according to embodiments of this disclosure.

[0108] The encryption key that the UE and the network actually use to communicate is an encryption key derived from the root key pre-stored in the two entities through several steps.

[0109] The reason why the root key shared between the UE and the network is not used directly, but instead a new key for communication is derived, is as follows. The root key shared by the UE and the network is security information stored in the SIM card on the UE side and in the UDM / ARF on the network side, and remains unchanged until the SIM card is replaced. In other words, authentication between the UE and the network occurs multiple times while the SIM is in use, and the root key remains unchanged throughout this process. Therefore, if the root key value is used as the encryption key for communication, the key value used for secure communication remains unchanged, thus weakening the security level. To improve the security level, a new encryption key should be generated each time authentication is performed, and this newly generated key should be used for communication. Therefore, the UE and the network do not directly use the pre-stored root key value as the key for encrypted communication, but instead derive a new key from the root key value. This process can be achieved by deriving a new encryption key using the root key value and a random value (hereinafter referred to as RAND) that changes with each authentication. Simply put, the "root key" and "RAND" can be used as the material for deriving the encryption key, which the UE and the network will actually use for secure communication after authentication, and therefore, the encryption key can be different for each authentication.

[0110] However, the above-described derivation process can be performed in multiple stages rather than in a single step. In other words, it can be performed through multiple layers. The reason for such a multi-stage process is as follows: The UE consists of a SIM and an ME, and the network consists of various entities such as UDM, ARPF, AUSF, and SEAF. Each entity has a different security level and role, and their roles in the process of deriving the encryption key are also different. Therefore, since the encryption key should be generated through collaboration among multiple entities, the process of deriving the encryption key is performed in multiple stages, and the resulting key has a hierarchical structure.

[0111] As mentioned above, Figure 3 This is a diagram illustrating the hierarchy of the aforementioned keys. A detailed description is provided below.

[0112] First, let's describe it from the perspective of the user experience (UE).

[0113] -UE can consist of SIM and ME.

[0114] -SIM can have the root key value mentioned above. The root key can be referred to as K.

[0115] -SIM can use the K and RAND values ​​mentioned above to derive encryption key values ​​called CK and IK.

[0116] -SIM can send CK and IK to ME.

[0117] -ME can use the received CK and IK values ​​to generate an encryption key value called K_SEAF.

[0118] Next, we will describe it from the perspective of networks.

[0119] - A network can consist of UDM, ARPF, AUSF, and SEAF.

[0120] -SEAF can be a logical entity or function provided by AMF for security purposes.

[0121] -UDM / ARPF can have the root key value K mentioned above.

[0122] -UDM / ARPF can use the K and RAND values ​​mentioned above to derive encryption key values ​​called CK and IK.

[0123] -UDM / ARPF can send CK and IK values ​​to UDM / ARPF / AUSF.

[0124] -UDM / ARPF / AUSF can use the received CK and IK values ​​to generate an encrypted value called K_SEAF.

[0125] -UDM / ARPF / AUSF can send the generated K_SEAF to SEAF.

[0126] Through the above process, the UE and the network can share the public encryption key K_SEAF.

[0127] The UE and network can use K_SEAF to derive additional encryption keys for lower layers, not shown in the accompanying diagram. The newly derived key can be an encryption key to be used in “UE and AMF” and / or “UE and gNB”. The derived key can be a key for encryption purposes (i.e., encryption / decryption) and / or a key for integrity protection.

[0128] The encryption keys described above can have different security levels. For example, the encryption keys can have two different security levels. For example, the encryption key supporting the higher security level can have a longer key length, and the encryption key supporting the lower security level can have a shorter key length. For example, the encryption key supporting the higher security level can have a key value suitable for a 256-bit encryption algorithm, and the encryption key supporting the lower security level can have a key value suitable for a 128-bit encryption algorithm.

[0129] A SIM that supports high security levels can provide both high-security and low-security encryption keys to the ME simultaneously. A SIM that supports low security levels may be able to provide only the low-security encryption key to the ME.

[0130] A ME that supports high-security levels can simultaneously support both high-security encryption algorithms using high-security encryption keys and low-security encryption algorithms using low-security encryption keys. A ME that supports low-security levels may only support low-security encryption algorithms using low-security encryption keys.

[0131] Networks supporting high security levels can export both high-security and low-security encryption keys simultaneously. Furthermore, they can support both high-security encryption algorithms using the high-security key and low-security encryption algorithms using the low-security key. Networks supporting low security levels can only export low-security encryption keys. Additionally, they may only support low-security encryption algorithms using the low-security key.

[0132] Figure 4 This is a message flow diagram illustrating the authentication process between a UE and a network, and the shared key generation process for secure communication, according to embodiments of this disclosure.

[0133] The above process is called initial authentication, and through this process, the UE and the network can authenticate each other and share encryption keys to be used for secure communication between them. (See also...) Figure 3 Describe a detailed description of the encryption key to be used for secure communication.

[0134] exist Figure 4 The UE 400 shown in the diagram can be composed of SIM 410 and ME 420. Figure 4 The network shown can consist of SEAF430 and AUSF / UDM / ARPF 440.

[0135] This will be described separately below. Figure 4 Each step to be performed in the process.

[0136] In step 401, ME 420 may perform one or more of the following processes.

[0137] -ME 420 can send information that can specify the UE to SEAF 430. The above information can be a Subscription Hidden Identifier (SUCI) or a 5G Globally Unique Temporary Identifier (GUTI).

[0138] -ME 420 can send the encryption algorithms supported by ME to SEAF 430. This information can be referred to as security capabilities.

[0139] In step 402, SEAF 430 may perform one or more of the following procedures.

[0140] SEAF 430 can send information to AUSF / UDM / ARPF 440 that specifies the UE that has requested authentication. This information can be the SUCI or Subscription Permanent Identifier (SUPI) corresponding to the UE.

[0141] In step 403, AUSF / UDM / ARPF 440 may perform one or more of the following procedures.

[0142] -AUSF / UDM / ARPF 440 can specify the SIM that has requested authentication based on information received from the UE.

[0143] -AUSF / UDM / ARPF 440 can identify the cryptographic root key owned by the SIM that has requested authentication. The root key can be a reference... Figure 3 The K described.

[0144] - AUSF / UDM / ARPF 440 can send the information required for authentication and shared key generation to SEAF 430. This information can be referred to as AV. AV may include references... Figure 3 The RAND value described.

[0145] In step 404, SEAF 430 may perform one or more of the following procedures.

[0146] -SEAF 430 can send all or part of the AV value received in step 403 to ME 420.

[0147] The value sent above can include the RAND value.

[0148] In step 405, ME 420 may perform one or more of the following processes.

[0149] -ME 420 can send all or part of the AV value received in step 404 to SIM 410.

[0150] The value sent above can include the RAND value.

[0151] In step 406, SIM 410 may perform one or more of the following processes.

[0152] -SIM 410 can use the received RAND and the key K stored therein to generate a cryptographic key (CK) and an integrity key (IK). (See reference...) Figure 3 Descriptions of CK and IK.

[0153] -SIM 410 can send the generated CK and IK to ME 420.

[0154] In step 407, one or more of the following procedures may be performed.

[0155] -ME 420 can derive K_SEAF using the CK and IK received in step 406. Furthermore, ME 420 can generate encryption and / or integrity protection keys to be used with AMF and / or gNB by using the derived K_SEAF.

[0156] -AUSF / UDM / ARPF 440 can generate K_SEAF and send it to SEAF 430. K_SEAF can be used to generate encryption and / or integrity protection keys for AMF and / or gNB that will be used for secure communication with the UE.

[0157] like Figure 3 As described in the disclosure, each entity constituting the UE and the network can support either a high security level or a low security level. However, when the security levels of entities differ, the primary authentication method shown in the figure (which is the currently used method) may not function correctly. Consider the following scenario as an example.

[0158] -SIM: Supports high security levels

[0159] ME: Supports low security levels

[0160] SEAF / AUSF / UDM / ARPF: Supports high security levels

[0161] In this scenario, in step 403, based on the fact that the SIM supports a high security level, the AUSF / UDM / ARPF 440 of the SIM, using the information received in step 402, specifies that it will send an AV to the SEAF 430 for generating a high security level key. Through steps 404 and 405, the AV is sent to the SIM 410, and in step 406, the SIM 410 can send the high security levels CK and IK to the ME 420. However, since the ME 420 supports a low security level, and as referenced... Figure 3 As stated, the ME 420, which supports low security levels, cannot use high security level encryption keys, and therefore cannot perform the authentication process normally.

[0162] The above example is just one illustration, and various issues may arise when the three entities have different security levels.

[0163] In the following description, several methods for solving these problems will be proposed.

[0164] Figure 5 This is a message flow diagram illustrating the authentication process between UEs and networks with different security levels, and the shared key generation process for secure communication, according to embodiments of this disclosure.

[0165] The above process is an improved form of initial authentication, through which the UE and the network can authenticate each other and share encryption keys to be used for secure communication between them. (See reference...) Figure 3 Describe a detailed description of the encryption key to be used for secure communication.

[0166] exist Figure 5 The UE 500 shown in the diagram can be composed of SIM 510 and ME 520. Figure 5 The network illustrated in the diagram can consist of SEAF 530 and AUSF / UDM / ARPF 540. SIM, ME, and SEAF can all support either high or low security levels. (Refer to...) Figure 3 and Figure 4 Provide a detailed description of the features that support high or low security levels for SIM, ME, and SEAF.

[0167] This will be described separately below. Figure 5 Each step to be performed in the process.

[0168] In step 501, ME 520 may perform one or more of the following processes.

[0169] -ME 520 can send information that can specify the UE to SEAF 530. The above information can be SUCI or 5G-GUTI.

[0170] -ME 520 can send the encryption algorithms supported by the ME to SEAF 530. This information can be referred to as security capabilities. In this case, an ME supporting a high level of security can include algorithms with a high level of security.

[0171] In step 502, SEAF 530 may perform one or more of the following procedures.

[0172] -SEAF 530 can send information to AUSF / UDM / ARPF 540 specifying that the UE has requested authentication. This information can be a SUCI or SUPI corresponding to the UE.

[0173] In this case, if the SEAF 530 supports a high level of security, the following procedure can be performed additionally.

[0174] SEAF 530 can send a notification to AUSF / UDM / ARPF 540 regarding the algorithms supported by ME 520 received in step 501, including information about algorithms with high security levels (indicated as indicator 1 in the figure). This information can be included as a parameter in the message sent by SEAF 530 to AUSF / UDM / ARPF 540 in step 502.

[0175] In step 503, AUSF / UDM / ARPF 540 may perform one or more of the following procedures.

[0176] -AUSF / UDM / ARPF 540 can specify the SIM that has requested authentication based on information received from the UE.

[0177] -AUSF / UDM / ARPF 540 can identify the cryptographic root key owned by the SIM that has requested authentication. The root key can be a reference... Figure 3 The K described.

[0178] The AUSF / UDM / ARPF 540 can send the information required for authentication and shared key generation to the SEAF 530. This information can be referred to as the AV. The AV may include references... Figure 3 The RAND value described.

[0179] If the SIM is identified as supporting a high level of security and indicator 1 is received in step 502, the AUSF / UDM / ARPF 540 can generate an AV that includes the information required to derive the high-security-level encryption key.

[0180] If the AV consists of information required to derive a high-security encryption key, the AUSF / UDM / ARPF 540 may send a message to the SEAF 530 notifying this fact (indicated as indicator 2 in the figures). This information may be included as a parameter of the message sent by the AUSF / UDM / ARPF 540 in step 503.

[0181] In step 504, SEAF 530 may perform one or more of the following procedures.

[0182] -SEAF 530 can send all or part of the AV value received in step 503 to ME 520.

[0183] The value sent above can include the RAND value.

[0184] In this case, if the SEAF 530 supports a high level of security, the following procedure can be performed additionally.

[0185] If SEAF 530 receives indicator 2 in step 503, SEAF 530 may send a message to ME 520 notifying it of this fact (indicated as indicator 3 in the figure). This information may be included as a parameter in the message sent by SEAF 530 in step 504.

[0186] In step 505, ME 520 may perform one or more of the following processes.

[0187] -ME 520 can send all or part of the AV value received in step 504 to SIM 510.

[0188] The value sent above can include the RAND value.

[0189] In this case, if the ME 520 supports a high level of security, the following procedure can be performed separately.

[0190] If ME 520 receives indicator 3 in step 504, ME 520 can send a message to SIM 510 notifying it of this fact (represented as indicator 4 in the figure). This information can be included as a parameter in the message sent by ME 520 in step 505.

[0191] In step 506, SIM 510 may perform one or more of the following processes.

[0192] -SIM 510 can use the received RAND and the key K stored therein to generate CK and IK. (Refer to...) Figure 3 Descriptions of CK and IK.

[0193] -SIM 510 can send the generated CK and IK to ME 520.

[0194] In this case, if the SIM 510 supports a high level of security, the following procedure can be performed additionally.

[0195] If SIM 510 receives indicator 4 in step 505, SIM 510 can send CK and IK with a high security level to ME 520. If SIM 510 does not receive indicator 4 in step 505, SIM 510 can send CK and IK with a low security level to ME 520.

[0196] In step 507, one or more of the following procedures may be performed.

[0197] The ME 520 can derive K_SEAF using the CK and IK received in step 506. Furthermore, the ME 520 can generate encryption and / or integrity protection keys to be used with the AMF and / or gNB by using the derived K_SEAF.

[0198] -AUSF / UDM / ARPF 540 can generate K_SEAF and send it to SEAF 530. K_SEAF can be used to generate encryption and / or integrity protection keys for AMF and / or gNB that will be used for secure communication with the UE.

[0199] Figure 6 This is a message flow diagram illustrating the authentication process between a UE and a network that may have different security levels, and the shared key generation process for secure communication, according to another embodiment of this disclosure.

[0200] The above process is an improved form of initial authentication, through which the UE and the network can authenticate each other and share encryption keys to be used for secure communication between them. (See reference...) Figure 3 Describe a detailed description of the encryption key to be used for secure communication.

[0201] exist Figure 6 The UE 600 shown in the diagram can be composed of SIM 610 and ME 620. Figure 6 The network illustrated can consist of SEAF 630 and AUSF / UDM / ARPF 640. SIM, ME, and SEAF can all support either high or low security levels. (Refer to...) Figure 3 and Figure 4 Provide a detailed description of the features that support high or low security levels for SIM, ME, and SEAF.

[0202] This will be described separately below. Figure 6Each step to be performed in the process.

[0203] In step 601, if the ME 620 supports a high level of security, one or more of the following procedures can be performed.

[0204] The ME 620 can send a message to the SIM 610 (indicated by indicator 1 in the diagram) to inquire whether the SIM supports a high level of security.

[0205] In step 602, if SIM 610 supports a high level of security, one or more of the following procedures can be performed.

[0206] If indicator 1 is received in step 601, SIM 610 can send information to ME 620 that it supports a high level of security (represented as a response in the figure).

[0207] In step 603, ME 620 may perform one or more of the following processes.

[0208] -ME 620 can send information that can specify the UE to SEAF 630. The above information can be SUCI or 5G-GUTI.

[0209] The ME 620 can send the encryption algorithms supported by the ME to the SEAF 630. This information can be referred to as security capabilities.

[0210] In this case, if the SEAF 630 supports a high level of security, the following procedure can be performed separately.

[0211] If indicator 1 is received in step 602, ME 620 may include an algorithm with a high security level and send it to SEAF 630. If indicator 1 is not received in step 602, ME 620 may send only an algorithm with a low security level to SEAF 630.

[0212] In step 604, SEAF 630 may perform one or more of the following procedures.

[0213] -SEAF 630 can send information to AUSF / UDM / ARPF 640 specifying the UE that has requested authentication. This information can be the SUCI or SUPI corresponding to the UE.

[0214] In this case, if the SEAF 630 supports a high level of security, the following procedure can be performed separately.

[0215] If the algorithms supported by ME 620 received in step 603 include those with a high level of security, then SEAF 630 may send a message to AUSF / UDM / ARPF 640 notifying this fact (indicated as indicator 2 in the figure). This information may be included as a parameter in the message sent by SEAF 630 to AUSF / UDM / ARPF 640 in step 604.

[0216] In step 605, AUSF / UDM / ARPF 640 may perform one or more of the following procedures.

[0217] -AUSF / UDM / ARPF 640 can specify the SIM that has requested authentication based on information received from the UE.

[0218] -AUSF / UDM / ARPF 640 can identify the cryptographic root key owned by the SIM that has requested authentication. The root key can be a reference... Figure 3 The K described.

[0219] The AUSF / UDM / ARPF 640 can send the information required for authentication and shared key generation to the SEAF 630. This information can be referred to as an AV. The AV may include references... Figure 3 The RAND value described.

[0220] If indicator 2 is received in step 604, AUSF / UDM / ARPF 640 can generate an AV that includes the information needed to derive a high-security encryption key.

[0221] In step 606, SEAF 630 may perform one or more of the following procedures.

[0222] -SEAF 630 can send all or part of the AV value received in step 605 to ME 620.

[0223] The value sent above can include the RAND value.

[0224] In this case, if the SEAF 630 supports a high level of security, the following procedure can be performed separately.

[0225] If the algorithms supported by the ME received in step 603 include those with a high security level, then SEAF 630 may send a notification that it also supports a high security level (indicated by indicator 3 in the figure). This information may be included as a parameter in the message sent by SEAF 630 in step 606.

[0226] In step 607, ME 620 may perform one or more of the following processes.

[0227] -ME 620 can send all or part of the AV value received in step 606 to SIM 610.

[0228] The value sent above can include the RAND value.

[0229] In this case, if the ME 620 supports a high level of security, the following procedure can be performed separately.

[0230] If ME 620 receives indicator 3 in step 606, ME 620 may send a message to SIM 610 notifying it of this fact (represented as indicator 4 in the figure). This information may be included as a parameter in the message sent by ME 620 in step 607.

[0231] In step 608, SIM 610 may perform one or more of the following processes.

[0232] The SIM 610 can use the received RAND and the key K stored therein to generate CK and IK. (Refer to...) Figure 3 Descriptions of CK and IK.

[0233] -SIM 610 can send the generated CK and IK to ME 620.

[0234] In this case, if the SIM 610 supports a high level of security, the following procedure can be performed additionally.

[0235] If SIM 610 receives indicator 4 in step 607, SIM 610 can send CK and IK with a high security level to ME 620. If SIM 610 does not receive indicator 4 in step 707, SIM 610 can send CK and IK with a low security level to ME 620.

[0236] In step 609, one or more of the following procedures may be performed.

[0237] The ME 620 can derive K_SEAF using the CK and IK received in step 608. Furthermore, the ME 620 can generate encryption and / or integrity protection keys to be used with the AMF and / or gNB by using the derived K_SEAF.

[0238] -AUSF / UDM / ARPF 640 can generate K_SEAF and send it to SEAF 630. K_SEAF can be used to generate encryption and / or integrity protection keys for AMF and / or gNB to be used for secure communication with the UE.

[0239] It should be noted that Figures 1a to 6 The structural diagrams, exemplary diagrams of control / data signal transmission and reception methods, and exemplary diagrams of operation processes shown are not intended to limit the scope of the embodiments of this disclosure. That is, they are not intended to be referenced in any way. Figures 1a to 6 All components, entities, or operational steps described should be interpreted as necessary components for implementing this disclosure, and this disclosure may be implemented without departing from its spirit even if only some of these components are included.

[0240] The operation of the above embodiments can be implemented by providing a memory device storing the corresponding program code in any component within the device. That is, the controller of the device can perform the above operations by reading and executing the program code stored in the memory device through a processor or central processing unit (CPU).

[0241] The various components and modules of the physical or UE devices described in this disclosure can be operated using hardware circuitry (such as complementary metal-oxide-semiconductor (CMOS) based logic circuitry), firmware, software, and / or combinations of hardware, firmware, and software embedded in a machine-readable medium. For example, various electrical structures and methods can be implemented using circuitry such as transistors, logic gates, and application-specific integrated circuits (ASICs).

[0242] The methods described in the claims or specification of this disclosure can be implemented in hardware, software, or a combination of hardware and software.

[0243] In the case of software implementation, a computer-readable storage medium storing one or more programs (software modules) may be provided. The one or more programs stored in the computer-readable storage medium are configured to be executed by one or more processors in an electronic device. The one or more programs include instructions for causing the electronic device to perform a method according to the embodiments described in the claims or specification of this disclosure.

[0244] Such programs (software modules, software) can be stored in random access memory, including non-volatile memory such as flash memory, read-only memory (ROM), electrically erasable programmable ROM (EEPROM), disk storage devices, optical disc ROM (CD-ROM), digital versatile optical disc (DVD), another form of optical storage device, or magnetic tape cassette. Alternatively, the program can be stored in a memory consisting of some or all of these components. Furthermore, each component memory may include multiple components.

[0245] Furthermore, the program can be stored in an attachable storage device that can be accessed via a communication network such as the Internet, intranet, local area network (LAN), wide area network (WAN), or storage area network (SAN), or a combination thereof. Such a storage device can access the device implementing the embodiments of this disclosure via an external port. Additionally, a separate storage device on the communication network can access the device implementing the embodiments of this disclosure.

[0246] In the specific embodiments of this disclosure described above, the elements included in this disclosure are represented in a singular or plural form according to the presented specific embodiments. However, singular or plural expressions are suitably chosen for the purposes of presentation, and this disclosure is not limited to singular or plural components; even if a component is represented in the plural form, it may consist of a singular component, or even if a component is represented in the singular form, it may consist of a plural component.

[0247] In the detailed description of this disclosure, although specific embodiments have been described, various modifications may be made without departing from the scope of this disclosure. Therefore, the scope of this disclosure should not be limited to the described embodiments, but should be defined by the appended claims and their equivalents.

Claims

1. A method performed by a first network entity in a wireless communication system, the method comprising: Receive first information about the specified UE from the user equipment (UE); and Based on the first information about the specified UE, second information related to the algorithm supported by the UE and the first network entity is sent to the second network entity. Among them, the second information and the algorithms supported by the UE and the first network entity include algorithms with high security levels.

2. The method according to claim 1, wherein, The first piece of information is associated with the encryption algorithm supported by the UE.

3. The method according to claim 1, further comprising: Receive third information from the second network entity regarding the export of high-security encryption keys related to authentication and shared key generation.

4. The method according to claim 3, further comprising: If the third information is received, send all or part of the third information to the UE. The UE includes a subscriber identification module (SIM) and a mobile device (ME), as well as In this process, all or part of the third information is sent from the ME to the SIM.

5. A method performed by a second network entity in a wireless communication system, the method comprising: Based on the first information about the specified user equipment (UE), second information related to the UE and the algorithm supported by the first network entity is received from the first network entity. Among them, the first information about the designated UE is sent from the UE to the first network entity, and Among them, the second information and the algorithms supported by the UE and the first network entity include algorithms with high security levels.

6. The method according to claim 5, wherein, The first piece of information is associated with the encryption algorithm supported by the UE.

7. The method according to claim 5, further comprising: Send third information to the first network entity regarding the export of a high-security encryption key related to authentication and shared key generation.

8. The method according to claim 7, wherein, When third information is sent, all or part of the third information is sent from the first network entity to the UE. The UE includes a subscriber identification module (SIM) and a mobile device (ME), as well as In this process, all or part of the third information is sent from the ME to the SIM.

9. A first network entity in a wireless communication system, the first network entity comprising: A transceiver is capable of sending and receiving at least one signal; and The controller is coupled to the transceiver. The controller is configured as follows: Receive first information about the specified UE from the user equipment (UE), and Based on the first information about the specified UE, second information related to the algorithm supported by the UE and the first network entity is sent to the second network entity. Among them, the second information and the algorithms supported by the UE and the first network entity include algorithms with high security levels.

10. The first network entity according to claim 9, wherein, The first piece of information is associated with the encryption algorithm supported by the UE.

11. The first network entity according to claim 9, wherein, The controller is also configured to receive third information from the second network entity regarding the export of high-security encryption keys related to authentication and shared key generation.

12. The first network entity according to claim 11, in, Upon receiving the third information, the controller is also configured to send all or part of the third information to the UE. The UE includes a subscriber identification module (SIM) and a mobile device (ME), as well as In this process, all or part of the third information is sent from the ME to the SIM.

13. A second network entity in a wireless communication system, the second network entity comprising: A transceiver is capable of sending and receiving at least one signal; and The controller is coupled to the transceiver. The controller is configured to receive second information related to the UE and an algorithm supported by the first network entity, based on first information about a specified user equipment (UE). Among them, the first information about the designated UE is sent from the UE to the first network entity, and Among them, the second information and the algorithms supported by the UE and the first network entity include algorithms with high security levels.

14. The second network entity according to claim 13, wherein, The first piece of information is associated with the encryption algorithm supported by the UE.

15. The second network entity according to claim 14, in, The controller is also configured to send third information to the first network entity regarding the export of a high-security encryption key related to authentication and shared key generation. In the case where third information is sent, all or part of the third information is sent from the first network entity to the UE. The UE includes a subscriber identification module (SIM) and a mobile device (ME), as well as In this process, all or part of the third information is sent from the ME to the SIM.