Method and apparatus for improving security level related to transmission of configuration information in wireless communication system
By generating subkeys for encryption and integrity protection, the security threat when the network provides configuration information to roaming UEs in wireless communication systems is resolved, and the security and integrity of information transmission are improved.
Patent Information
- Application Number
- CN202480050890.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-08-09
- Filing Date
- 2024-06-26
- Publication Date
- 2026-03-06
AI Technical Summary
In wireless communication systems, there are security threats when the network provides configuration information to roaming user equipment (UE), especially the possibility of inferring the KAUSF key by visiting the PLMN, which violates security requirements.
Encryption and integrity protection are achieved by generating subkeys, including generating subkeys by the UE and AUSF, using the subkeys to encrypt and protect the integrity of configuration information, and verifying the integrity of the information through a message authentication code (MAC).
It improves the security of configuration information transmission in wireless communication systems, prevents key leakage, and ensures the confidentiality and integrity of information.
Smart Images

Figure CN121620945A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to methods and apparatus for enhancing the security level associated with the transmission of configuration information in a wireless communication system. Specifically, this disclosure relates to methods and apparatus for enhancing the security level when a network provides configuration information to a UE in a wireless communication system. Background Technology
[0002] 5G mobile communication technology defines a wide frequency band to enable high-speed transmission rates and new services. This can be achieved not only in sub-6GHz bands such as 3.5GHz, but also in "above 6GHz" bands, including 28GHz and 39GHz, known as millimeter waves (mmWave). Furthermore, 6G mobile communication technology (referred to as "super 5G systems") is being considered for implementation in terahertz (THz) bands (e.g., the 95GHz to 3THz band), aiming to achieve transmission rates 50 times faster and latency 1 / 10th that of 5G mobile communication technology.
[0003] In the early stages of 5G mobile communication technology development, to support and meet the performance requirements of services related to enhanced mobile broadband (eMBB), ultra-reliable low-latency communication (URLLC), and massive machine-type communication (mMTC), relevant standardization work has been carried out, involving: beamforming and massive MIMO for mitigating path loss and increasing radio wave propagation distance in millimeter-wave bands; support for multiple parameter sets (such as multi-subcarrier spacing) for efficient utilization of millimeter-wave band resources and dynamic operation of time slot formats; initial access technologies for supporting multi-beam transmission and broadband; definition and operation of bandwidth portion (BWP); new channel coding methods (such as low-density parity-check (LDPC) codes for high-capacity data transmission and polar codes for highly reliable transmission of control information); L2 preprocessing; and network slicing for providing dedicated networks for specific services.
[0004] Currently, considering the services that 5G mobile communication technology is intended to support, discussions are underway regarding improvements and enhancements to the initial 5G mobile communication technology, and physical layer standardization work is also progressing. The technologies involved include: vehicle-to-everything (V2X) networks that assist autonomous vehicles in making driving decisions and improve user convenience based on vehicle-transmitted location and status information; NR-U (New Radio Unlicensed) systems designed to meet various regulatory requirements for unlicensed frequency bands; NR UE low-power technology; UE-satellite direct communication technology (non-terrestrial network (NTN)) that provides coverage for areas that cannot communicate with terrestrial networks; and positioning technology.
[0005] In addition, standardization efforts are underway in the air interface architecture / protocol aspect for technologies such as: Industrial Internet of Things (IIoT) to support new services through integration with other industries; Integrated Access and Backhaul (IAB) to provide nodes for network service area extension by supporting wireless backhaul and access links in an integrated manner; Mobility enhancements including conditional handover and dual active protocol stack (DAPS) handover; and NR two-step random access (2-step RACH for NR) to simplify the random access process. Meanwhile, in terms of system architecture / services, ongoing standardization efforts involve: 5G baseline architectures (e.g., service-based architectures or service-based interfaces) for combining Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies; and Mobile Edge Computing (MEC) for UE location-based reception services.
[0006] With the commercialization of 5G mobile communication systems, the number of connected devices will explode, necessitating enhanced functionality and performance of 5G mobile communication systems and integrated operation of interconnected devices. To this end, new research will be conducted in the following areas: Extended Reality (XR) for efficient support of Augmented Reality (AR), Virtual Reality (VR), Mixed Reality (MR), etc.; leveraging Artificial Intelligence (AI) and Machine Learning (ML) to improve 5G performance and reduce complexity; AI service support; Metaverse service support; and drone communication.
[0007] Furthermore, the development of 5G mobile communication systems will not only lay the foundation for the development of technologies such as: novel waveforms for providing coverage in the terahertz band of 6G mobile communication technology; multi-antenna transmission technologies such as full-dimensional MIMO (FD-MIMO), array antennas, and massive MIMO; metamaterial-based lenses and antennas for improving terahertz band signal coverage; high-dimensional spatial multiplexing technologies utilizing orbital angular momentum (OAM) and reconfigurable smart surfaces (RIS); but also lay the foundation for the development of technologies such as: full-duplex technologies for improving the frequency efficiency of 6G mobile communication technology and improving system networks; AI-based communication technologies that utilize satellites and AI from the design stage to achieve system optimization and incorporate end-to-end AI support; and next-generation distributed computing technologies that utilize ultra-high-performance communication and computing resources to achieve service levels with complexity exceeding the limits of terminal operation capabilities.
[0008] As mentioned above, with the development of mobile communication systems capable of providing various services, there is a need for an effective method to provide such services.
[0009] The network can provide configuration information to roaming UEs. Currently, this can be achieved using Roaming Guidance (SoR) or UE Parameter Update (UPU). In these methods, the AUSF of the Home PLMN (HPLMN) sends information to the Visiting PLMN (VPLMN) solely through integrity protection using the KAUSF. Directly using the KAUSF (one of the most securely managed keys) for integrity protection and sending it to the VPLMN can pose security threats. For example, if a sufficient amount of data protected by the KAUSF and its corresponding values accumulates, the VPLMN may be able to deduce the KAUSF. The VPLMN's ability to deduce the KAUSF (which should only be securely managed within the HPLMN) may violate security requirements. Furthermore, when providing configuration information to roaming UEs using SoR and UPU, the types of data transmitted through these two mechanisms are gradually increasing, and such data is likely to contain information that should not be exposed to the VPLMN. Summary of the Invention
[0010] [Technical Issues]
[0011] Based on the above discussion, this disclosure aims to address potential security issues that may arise when a network provides configuration information to a UE.
[0012] [Technical Solution]
[0013] A method performed by a UE according to embodiments of this disclosure may include: sending an indication indicating whether the UE supports a new function; receiving an indication indicating whether the network supports the new function; receiving an indication indicating whether configuration information is encrypted; and from K... AUSF Generate a subkey; and use the generated subkey to perform decryption and integrity protection verification.
[0014] The method performed by the AUSF (or the first network entity) according to embodiments of this disclosure may include: receiving an indication indicating whether the UE supports a new function; sending an indication indicating whether the network supports the new function; receiving an indication from the UDM (or the second network entity) indicating that configuration information needs to be encrypted; and receiving an indication from K... AUSF Generate a subkey; use the generated subkey to encrypt and protect the configuration information; generate an indication that the configuration information has been encrypted and protected; and send the encrypted and protected configuration information to the UDM.
[0015] A method performed by an AUSF entity according to an embodiment of this disclosure includes: receiving configuration information and an instruction indicating encryption or integrity protection of the configuration information from a Unified Data Management (UDM) entity; generating a first subkey for encryption or a second subkey for integrity protection from a stored parent key; encrypting the configuration information using the first subkey or protecting the configuration information for integrity using the second subkey; and sending the encrypted or integrity-protected configuration information to the UDM entity.
[0016] In an embodiment, the method performed by AUSF may further include: sending information to the UDM entity about a first algorithm used for the encryption or information about a second algorithm used for the integrity protection.
[0017] In an embodiment, the method performed by AUSF may further include: generating a message authentication code (MAC) value using at least one of the parent key, the second child key, or a counter value for integrity protection, wherein the MAC value can be used to identify whether the configuration information received by the UE has been tampered with.
[0018] In an embodiment, the method performed by the AUSF may further include: receiving UE capability information, the UE capability information indicating whether the UE can generate the first subkey or the second subkey from the parent key, and sending the UE capability information to the UDM entity. Here, the parent key may be K_AUSF, the first subkey may be K_SoRenc, and the second subkey may be K_SoRint.
[0019] A method performed by a UE in a wireless communication system includes: receiving encrypted or integrity-protected configuration information and an indication indicating that the configuration information has been encrypted or integrity-protected from an Access and Mobility Management Function (AMF) entity; generating a first subkey for decryption or a second subkey for integrity protection verification from a stored parent key; and decrypting the encrypted configuration information using the first subkey or verifying the integrity protection of the integrity-protected configuration information using the second subkey.
[0020] In an embodiment, the method performed by the UE may further include: receiving information from the AMF entity regarding a first algorithm for the encryption or information regarding a second algorithm for the integrity protection.
[0021] In an embodiment, the method performed by the UE may further include: generating a Message Authentication Code (MAC) value using at least one of the parent key, the second child key, or a counter value for integrity protection, and sending the MAC value to the AMF entity, wherein the MAC value can be used to identify whether the configuration information received by the UE has been tampered with.
[0022] In an embodiment, the method performed by the UE may further include: sending UE capability information to the AMF entity, the UE capability information indicating whether the UE can generate the first subkey or the second subkey from the parent key, and receiving network capability information from the AMF entity, the network capability information indicating whether the network entity can generate the first subkey or the second subkey from the parent key.
[0023] [Beneficial effects of the invention]
[0024] Various embodiments of this disclosure may provide an apparatus and method for securely providing services in a wireless communication system.
[0025] The beneficial effects that can be obtained from this disclosure are not limited to those described above, and other unmentioned effects will be clearly understood by those skilled in the art from the following description. Attached Figure Description
[0026] Figure 1A illustrates a communication network including a core network entity in a wireless communication system according to various embodiments of the present disclosure.
[0027] Figure 1B illustrates a wireless environment including a core network in a wireless communication system according to various embodiments of the present disclosure.
[0028] Figure 2A shows an example of the functional structure of a UE according to an embodiment of the present disclosure.
[0029] Figure 2B shows an example of the functional structure of a base station according to an embodiment of the present disclosure.
[0030] Figure 2C illustrates an example of the functional structure of a core network entity according to an embodiment of this disclosure.
[0031] Figure 3 This is a schematic diagram illustrating the process of using SoR to provide configuration information to the UE security during the registration process according to an embodiment of this disclosure.
[0032] Figure 4 This is a schematic diagram illustrating the process of providing configuration information to the UE security using SoR after the registration process, according to an embodiment of this disclosure.
[0033] Figure 5 This is a schematic diagram of a process for providing configuration information to a UE using a UPU according to an embodiment of this disclosure. Detailed Implementation
[0034] The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of other embodiments. Singular expressions may include plural expressions unless the context clearly indicates otherwise. The terms used herein (including technical and scientific terms) may have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains. Terms such as those defined in a general dictionary may be interpreted as having a meaning equivalent to that in the context of the relevant technical field and are not to be construed as having an ideal or overly formal meaning unless explicitly defined in this disclosure. In some cases, even terms defined in this disclosure should not be construed as excluding embodiments of this disclosure.
[0035] The following description of various embodiments of this disclosure will be based on a hardware approach. However, the various embodiments of this disclosure include techniques using both hardware and software, and therefore do not exclude a software perspective.
[0036] 3GPP, responsible for standardizing cellular mobile communications, has introduced a new core network architecture called 5G Core Network (5GC) and is pushing forward with its standardization to drive the evolution from 4G LTE systems to 5G systems. Compared to the Evolved Packet Core Network (EPC), which serves as the network core for legacy 4G, 5GC supports the following distinguishable functions.
[0037] First, network slicing was introduced in 5GC. As a requirement of 5G, 5GC needs to support various types of terminals and services (such as eMBB, URLLC, or mMTC services). Each type of service has different requirements for the core network. For example, eMBB services may require high data rates, while URLLC services may require high stability and low latency. Network slicing has been proposed as one of the technologies to meet these diverse service requirements.
[0038] Network slicing is a method of creating multiple logical networks by virtualizing a physical network, where each Network Slice Instance (NSI) can have different characteristics. Therefore, each NSI has Network Functions (NFs) tailored to its characteristics to meet various service requirements. By assigning an NSI suitable for the required service characteristics to each terminal, various 5G services can be efficiently supported.
[0039] Secondly, 5GC can easily support network virtualization paradigms by separating mobility management and session management functions. In traditional 4G LTE, services are provided through signaling exchange with a single core device called a Mobility Management Entity (MME), which is responsible for registration, authentication, mobility management, and session management functions for all terminals. However, in 5G, with the explosive growth in the number of terminals and the segmentation of mobility and service / session characteristics to be supported based on each terminal type, the scalability of adding entities according to required functions inevitably decreases if a single device such as the MME supports all functions. Therefore, to improve the scalability of the control plane signaling load and the functional / implementation complexity of the core device responsible for the control plane, various functions are being developed based on an architecture that separates mobility management and session management functions.
[0040] The various embodiments of this disclosure will now be described in detail with reference to the accompanying drawings. In describing this disclosure, detailed descriptions of known functions or configurations incorporated herein will be omitted where it is determined that such detailed descriptions would obscure the subject matter of the disclosure. The terminology described below is defined in consideration of the functions in this disclosure and may vary depending on the user, user intent, or habit. Therefore, the definitions of the terminology should be based on the entirety of this specification.
[0041] For the same reason, some elements in the accompanying drawings may be exaggerated, omitted, or shown schematically. Furthermore, the dimensions of each element do not perfectly reflect its actual size. In the various drawings, identical or corresponding elements will be given the same reference numerals.
[0042] The advantages, features, and implementation methods of this disclosure will become apparent from the following detailed description of embodiments in conjunction with the accompanying drawings. However, this disclosure is not limited to the following embodiments and can be implemented in many different forms. The following embodiments are only intended to fully disclose this disclosure and inform those skilled in the art of its scope, which is defined solely by the appended claims. Throughout this specification, the same or similar reference numerals denote the same or similar elements.
[0043] In this document, it should be understood that each block in a flowchart, and combinations of blocks in a flowchart, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute on the processor of the computer or other programmable data processing apparatus, generate means for implementing the functions specified in the flowchart blocks. These computer program instructions can also be stored in a computer-usable or computer-readable storage medium that can direct the computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-usable or computer-readable storage medium generate an article of writing including instruction means for implementing the functions specified in the flowchart blocks. The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in the flowchart blocks.
[0044] Furthermore, each block in a flowchart can represent a code module, code segment, or code section, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in a block may not occur in the order shown. For example, two blocks shown consecutively may actually execute substantially simultaneously, or depending on the functions involved, the blocks may sometimes execute in reverse order.
[0045] As used in the various embodiments of this disclosure, "unit" refers to a software element or hardware element (e.g., a field-programmable gate array (FPGA) or application-specific integrated circuit (ASIC)) that performs a predetermined function. However, "unit" is not limited to software or hardware. A "unit" may be configured to be stored in an addressable storage medium or to execute one or more processors. Thus, a "unit" includes, for example, software elements, object-oriented software elements, class elements or task elements, procedures, functions, attributes, processes, subroutines, program code segments, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and parameters. The elements and functions provided by a "unit" may be combined into fewer elements or "units," or divided into more elements or "units." Furthermore, elements and "units" may be implemented to reproduce one or more CPUs within a device or secure multimedia card.
[0046] In the following description, a base station is an entity that allocates resources to a terminal and may include at least one of an evolved Node B (eNB), a Node B, a base station (BS), a radio access network (RAN), an access network (AN), a RAN node, an NR NB, a gNB, a radio access unit, a base station controller, and nodes on the network. A terminal may include a user equipment (UE), a mobile station (MS), a cellular phone, a smartphone, a computer, or a multimedia system capable of performing communication functions. In various embodiments of this disclosure, the case where the terminal is a UE will be described as an example. Furthermore, in the description of the various embodiments below, systems based on LTE, LTE-A, or NR may be described as examples, but the various embodiments of this disclosure can also be applied to other communication systems with similar technical backgrounds or channel types. Moreover, based on the judgment of those skilled in the art, the various embodiments of this disclosure can be applied to other communication systems with some modifications without significantly departing from the scope of the embodiments of this disclosure.
[0047] In the following description, terms used to identify access nodes, to refer to network entities, to refer to messages, to refer to interfaces between network entities, and to refer to various identifying information are used exemplarily for ease of description. Therefore, this disclosure is not limited to the terminology described below, and other terms referring to objects with equivalent technical meanings may also be used.
[0048] Furthermore, various embodiments of this disclosure will be described using terminology found in certain communication standards (e.g., the 3rd Generation Partnership Project (3GPP)), but these are for illustrative purposes only. The various embodiments of this disclosure can also be readily applied to other communication systems with modifications. Below, before further explanation, some terms used in the core network of this disclosure will be defined.
[0049] AMF: Access and Mobility Management Functions
[0050] CN: Core Network
[0051] CNF: Containerized Networking Functions
[0052] DNN: Data Network Name
[0053] PCF: Policy Control Function
[0054] HSS: Home Subscriber Server
[0055] SMF: Session Management Function
[0056] UDM: User Data Management
[0057] UPF: User-Face Functionality
[0058] CNF: Containerized Networking Functions
[0059] VNF: Virtualized Network Function
[0060] Figure 1A illustrates a communication network including a core network entity in a wireless communication system according to various embodiments of the present disclosure. The 5G mobile communication network may include a 5G user equipment (5G UE) 110, a 5G radio access network (5G RAN) 120, and a 5G core network.
[0061] The 5G core network may include network functions such as Access and Mobility Management Function (AMF) 150, which provides mobility management functions for UEs; Session Management Function (SMF) 160, which provides session management functions; User Plane Function (UPF) 170, which provides data transmission functions; Policy Control Function (PCF) 180, which provides policy control functions; User Data Management (UDM) 153, which manages data such as subscriber data and policy control data; or Unified Data Repository (UDR), which stores data for various network functions.
[0062] Referring to Figure 1A, User Equipment (UE) 110 can communicate via a radio channel (i.e., access network) established between the UE and a base station (e.g., an eNB or gNB). In some embodiments, UE 110 refers to a device used by a user and is configured to provide a user interface (UI). For example, UE 110 may be a UE equipped in a moving vehicle. In other embodiments, UE 110 may be an autonomous vehicle or a device performing machine-type communication (MTC) that operates without user intervention. In addition to the term "electronic device," UE may also be referred to as a "terminal," "vehicle terminal," "user equipment (UE)," "mobile station," "subscriber station," "remote terminal," "wireless terminal," or other terms with equivalent technical meanings. Besides UE, Client Premises Equipment (CPE) or dongle-type UEs can be used as terminals. Client Premises Equipment can connect to NG-RAN nodes like UEs and can provide network access to other communication devices (e.g., laptops).
[0063] Referring to Figure 1A, the AMF 150 provides access and mobility management functions on a UE 110 basis; essentially, one UE 110 can connect to one AMF 150. Specifically, the AMF 150 can perform at least one of the following functions: signaling between core network nodes for mobility between 3GPP access networks, interface (N2 interface) between radio access networks (e.g., 5G RAN) 120s, NAS signaling with UE 110, identification of SMF 160, and transmission of session management (SM) messages between UE 110 and SMF 160. Some or all of the functions of the AMF 150 can be supported within a single instance of an AMF 150.
[0064] Referring to Figure 1A, the SMF 160 provides session management functions, and when the UE 100 has multiple sessions, each session can be managed by a different SMF 160. Specifically, the SMF 160 can perform at least one of the following functions: session management (e.g., session establishment, modification, and release, including tunnel maintenance between the UPF 170 and access network nodes), selection and control of user plane (UP) functions, configuration for service bootstrapping to route services from the UPF 170 to appropriate destinations, termination of the SM portion of NAS messages, downlink data notification (DDN), and delivery of access network-specific (AN) SM information to the access network via the N2 interface through an initiator (e.g., the AMF 150). Some or all of the functions of the SMF 160 can be supported within a single instance of an SMF 160.
[0065] In 3GPP systems, a conceptual link connecting NFs in a 5G system may be referred to as a "reference point". A reference point may also be referred to as an "interface". The following are exemplary examples of reference points (hereinafter used interchangeably with "interface") included in the 5G system architectures represented by various embodiments of this disclosure.
[0066] - N1: Reference point between UE 110 and AMF 150
[0067] - N2: (R) Reference point between AN 120 and AMF 150
[0068] - N3: Reference point between (R)AN 120 and UPF 170
[0069] - N4: Reference point between SMF 160 and UPF 170
[0070] - N5: Reference point between PCF 180 and AF 130
[0071] - N6: Reference point between UPF 170 and DN 140
[0072] - N7: Reference point between SMF 160 and PCF 180
[0073] - N8: Reference point between UDM 153 and AMF 150
[0074] - N9: Reference point between two cores with UPF 170
[0075] - N10: Reference point between UDM 153 and SMF 160
[0076] - N11: Reference point between AMF 150 and SMF 160
[0077] - N12: Reference point between AMF 150 and Authentication Server Function (AUSF) 151
[0078] - N13: Reference point between UDM 153 and AUSF 151
[0079] - N14: Reference point between the two AMF 150s
[0080] - N15: The reference point between PCF 180 and AMF 150 in non-roaming scenarios, and the reference point between AMF 150 and PCF 180 in the visited network in roaming scenarios.
[0081] Figure 1B illustrates a wireless environment including a core network in a wireless communication system according to various embodiments of the present disclosure. Referring to Figure 1B, the wireless communication system may include a radio access network (RAN) 120 and a core network (CN).
[0082] RAN 120 is a network directly connected to a user equipment (e.g., UE 110) and serves as the infrastructure providing radio access to UE 110. RAN 120 comprises a collection of multiple base stations that can communicate through interfaces established between them. At least some of these interfaces can be wired or wireless. Base station 125 may have a structure with separate central unit (CU) and distributed unit (DU). In this case, one CU can control multiple DUs. Besides the term "base station," base station 125 may also be referred to as an "access point (AP)," "next-generation node B (gNB)," "fifth-generation node (5G node)," "wireless point," "transmit / receive point (TRP)," or other terms with equivalent technical meanings. UE 110 can access RAN 120 and communicate with base station 125 via a wireless channel. Besides "terminal," terminal 110 may also be referred to as "user equipment (UE)," "mobile station," "subscriber station," "remote terminal," "wireless terminal," or "user equipment," or other terms with equivalent technical meanings.
[0083] The CN is the network that manages the entire system, controlling the RAN 120 and processing data and control signals sent or received via the RAN 120 for the UE 110. The CN can perform various functions, including user plane and control plane control, mobility processing, subscriber information management, charging, and integration with different types of systems (such as Long Term Evolution (LTE) systems). To perform these functions, the CN may include multiple entities with different network functions (NFs) that are functionally separate from each other. For example, the CN 200 may include Access and Mobility Management Function (AMF) 150, Session Management Function (SMF) 160, User Plane Function (UPF) 170, Policy and Charging Function (PCF) 180, Network Repository Function (NRF) 159, User Data Management (UDM) 153, Network Open Function (NEF) 155, and / or Unified Data Repository (UDR) 157.
[0084] UE 110 can connect to RAN 120 to access AMF 150, which performs mobility management functions for CN. AMF150 is a function or device that serves both access to RAN 120 and mobility management for UE 110. SMF 160 is the NF for managing sessions. AMF 150 can connect to SMF 160 and route session-related messages for UE 110 to SMF160. SMF 160 can connect to UPF 170 to allocate user plane resources to be provided to UE 110 and establish a tunnel for data transmission between base station 125 and UPF170. PCF 180 controls information related to charging and policy for sessions used by UE 110.
[0085] NRF 159 can store information about NFs installed in the mobile service provider network and notify the network of the stored information. NRF 159 can connect to all NFs. Each NF registers itself with NRF 159 when it begins to operate in the service provider network, thereby notifying NRF 159 that the NF is operating in the network. UDM 153 is an NF that performs a role similar to a Home Subscriber Server (HSS) in a 4G network and can store UE 110's subscription information or the context in which UE 110 is used in the network.
[0086] The NEF 155 can connect third-party servers to the NF in a 5G mobile communication system. Furthermore, the NEF 155 can provide data to the UDR 157 and can update or retrieve data. The UDR 157 can store the UE 120's subscription information, policy information, data exposed to external systems, or information required by third-party applications. The UDR 157 can also provide stored data to another NF.
[0087] Figure 2A illustrates an example of the functional structure of a UE according to an embodiment of the present disclosure. The structure shown in Figure 2A can be understood as the structure of UE 110. As used herein, terms such as “…unit” and “…device” refer to a unit configured to process at least one function or operation, and can be implemented by hardware, software, or a combination of hardware and software.
[0088] Referring to Figure 2A, the UE may include a communication unit 205, a memory 210, and a controller 215.
[0089] Communication unit 205 can perform functions for transmitting and receiving signals via a wireless channel. For example, communication unit 205 can perform conversion functions between baseband signals and bit strings according to the system's physical layer specifications. For instance, during data transmission, communication unit 205 can encode and modulate the transmitted bit string to generate complex symbols. Furthermore, during data reception, communication unit 205 can demodulate and decode the baseband signal to recover the received bit string. Additionally, communication unit 205 can up-convert the baseband signal to an RF band signal, then transmit the converted RF band signal through an antenna, and down-convert the RF band signal received through the antenna back to a baseband signal. For example, communication unit 205 may include a transmit filter, a receive filter, an amplifier, a mixer, an oscillator, a DAC, and an ADC.
[0090] Furthermore, the communication unit 205 may include multiple transmit / receive paths. Additionally, the communication unit 205 may include at least one antenna array containing multiple antenna elements. In terms of hardware, the communication unit 205 may include digital and analog circuitry (e.g., radio frequency integrated circuits (RFICs)). The digital and analog circuitry may be implemented in a single package. Furthermore, the communication unit 205 may include multiple RF chains. Additionally, the communication unit 205 may perform beamforming.
[0091] Communication unit 205 can transmit and receive signals as described above. Therefore, all or part of communication unit 205 may be referred to as a "transmitter," a "receiver," or a "transceiver." Furthermore, as used in the following description, the meaning of "transmission and reception performed via a wireless channel" includes the meaning of the above-described processing performed by communication unit 205.
[0092] The memory 210 may store basic programs, application programs, and data such as configuration information for the operation of the main base station. The memory 210 may include volatile memory, non-volatile memory, or a combination of volatile memory and non-volatile memory. In addition, the memory 210 may provide the stored data upon request from the controller 215.
[0093] Controller 215 can control the overall operation of the UE. For example, controller 215 can send and receive signals via communication unit 205. Furthermore, controller 215 records data in and reads data from memory 210. Additionally, controller 215 can perform the functions of the protocol stack required by the communication specifications. For this purpose, controller 215 may include at least one processor or microprocessor, or it may be part of a processor. Furthermore, communication unit 205 and a portion of controller 215 may be referred to as a communication processor (CP). According to various embodiments of this disclosure, controller 215 can control the performance of synchronization using a wireless communication network. For example, controller 215 can control the UE to perform the operations described below according to various embodiments.
[0094] According to various embodiments of this disclosure, the UE can be configured by a mobile device (ME) and a Universal Mobile Telecommunications System (UMTS) Subscriber Identity Module (USIM). The ME may include a mobile terminal (MT) and a terminal device (TE). The MT may be the part running a radio access protocol, and the TE may be the part running control functions. For example, in the case of a wireless communication terminal (e.g., a mobile phone), the MT and TE may be integrated, while in the case of a laptop computer, the MT and TE may be separate. As used herein, the ME and TE may be represented as separate entities depending on the operation of the respective components, but this disclosure is not limited thereto, and in describing various embodiments of this disclosure, the ME and TE may be collectively represented as a terminal (e.g., the UE) or the ME may be represented as a terminal.
[0095] Figure 2B illustrates an example of the functional structure of a base station according to an embodiment of the present disclosure. The structure shown in Figure 2B can be understood as the structure of base station 125. As used herein, terms such as “…unit” and “…device” refer to a unit configured to process at least one function or operation, which can be implemented by hardware, software, or a combination of hardware and software.
[0096] Referring to Figure 2B, the base station may include a wireless communication unit 235, a backhaul communication unit 220, a memory 225, and a controller 230.
[0097] The wireless communication unit 235 performs functions for transmitting or receiving signals via a wireless channel. For example, the wireless communication unit 235 can perform conversion functions between baseband signals and bit strings according to the physical layer specifications of the system. For example, during data transmission, the wireless communication unit 235 can encode and modulate the transmitted bit string to generate complex symbols. Furthermore, during data reception, the wireless communication unit 235 can demodulate and decode the baseband signal to reconstruct the received bit string.
[0098] Furthermore, the wireless communication unit 235 up-converts the baseband signal to an RF band signal, transmits the signal through an antenna, and down-converts the RF band signal received through the antenna back to a baseband signal. For this purpose, the wireless communication unit 235 may include a transmit filter, a receive filter, an amplifier, a mixer, an oscillator, a digital-to-analog converter (DAC), an analog-to-digital converter (ADC), etc. Additionally, the wireless communication unit 235 may include multiple transmit / receive paths. Furthermore, the wireless communication unit 235 may include at least one antenna array containing multiple antenna elements.
[0099] In terms of hardware, the wireless communication unit 235 may include a digital unit and an analog unit. The analog unit may include multiple sub-units depending on the operating power, frequency, etc. The digital unit may be implemented as at least one processor (e.g., a digital signal processor (DSP)).
[0100] The wireless communication unit 235 can transmit and receive signals as described above. Therefore, all or part of the wireless communication unit 235 may be referred to as a "transmitter," a "receiver," or a "transceiver." Furthermore, as used in the following description, the meaning of "transmission and reception performed via a wireless channel" includes the meaning of the above-described processing performed by the wireless communication unit 235.
[0101] The backhaul communication unit 220 provides an interface for communicating with other nodes in the network. That is, the backhaul communication unit 220 can convert bit strings sent from the base station to any other node (e.g., any other access node, any other base station, upper-layer node, or core network) into physical signals, and convert physical signals received from any other node into bit strings.
[0102] The memory 225 may store basic programs, application programs, and data such as configuration information for the operation of the main base station. The memory 225 may include volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. Furthermore, the storage device 225 may provide stored data upon request from the controller 230.
[0103] Controller 230 can control the overall operation of the base station. For example, controller 230 can send and receive signals via wireless communication unit 235 or backhaul communication unit 220. Furthermore, controller 230 records data in and reads data from storage device 225. Additionally, controller 230 can perform the functions of the protocol stack required by the communication specification. According to another embodiment, the protocol stack may be included in wireless communication unit 235. For this purpose, controller 230 may include at least one processor. According to various embodiments of this disclosure, controller 230 can control the use of a wireless communication network to perform synchronization. For example, controller 230 can control the base station to perform the operations described below according to various embodiments.
[0104] Figure 2C illustrates an example of the functional structure of a core network entity according to an embodiment of the present disclosure. The structure of a core network entity in a wireless communication system according to various embodiments of the present disclosure is shown. The structure shown in Figure 2C can be understood as the structure of a device having at least one function of the network entity including the AMF 150 of Figure 1. As used herein, terms such as “…unit” and “…device” refer to a unit configured to process at least one function or operation, which can be implemented by hardware, software, or a combination of hardware and software.
[0105] Referring to Figure 2C, the core network entity may include a communication unit 240, a memory 245, and a controller 250.
[0106] Communication unit 240 provides an interface for communicating with other devices in the network. That is, communication unit 240 converts bit strings sent from the core network entity to any other device into physical signals, and converts physical signals received from any other device into bit strings. Communication unit 240 can send / receive signals. Therefore, communication unit 240 may be referred to as a modem, transmitter, receiver, or transceiver. Communication unit 240 enables the core network entity to communicate with other devices or systems via backhaul connections (e.g., wired or wireless backhaul) or over the network.
[0107] Memory 245 may store basic programs, application programs, and data such as configuration information used for network entity operation. Memory 245 may include volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. Furthermore, memory 245 may provide stored data upon request from controller 250.
[0108] Controller 250 can control the overall operation of core network equipment. For example, controller 250 can send and receive signals via communication unit 240. Furthermore, controller 250 records data in and reads data from memory 245. For this purpose, controller 250 may include at least one processor. According to various embodiments of this disclosure, controller 250 can control synchronization performed using a wireless communication network. For example, controller 250 can control core network entities to perform the operations described below according to various embodiments.
[0109] In the following description, terms used to identify access nodes, to refer to network entities, to refer to messages, to refer to interfaces between network entities, and to refer to various identifying information are used exemplarily for ease of description. Therefore, this disclosure is not limited to the terminology described below, and other terms referring to objects with equivalent technical meanings may also be used.
[0110] In the following description of this disclosure, for ease of description, terms and names defined in the latest standards specified by the 3GPP group in existing communication standards (i.e., 5G Systems (5GS) and New Radio (NR) standards) will be used. However, this disclosure is not limited to these terms and names and can be equally applied to systems conforming to other standards. In particular, this disclosure can be applied to fifth-generation mobile communication standards (e.g., 5GS and NR).
[0111] Figure 3 This is a schematic diagram illustrating the process of providing configuration information to the UE security during the registration process using SoR, according to an embodiment of this disclosure.
[0112] refer to Figure 3 In operation 301, the UE may send an indication of whether it supports a new feature for SoR protection along with a registration request message. This new feature for SoR protection may refer to AUSF or the UE using K... AUSF The obtained subkey (e.g., K) SoRenc or K SoRint The key is used to encrypt / decrypt SoR data or perform integrity protection or integrity protection verification. For example, this instruction could be a new parameter or a remaining portion of previously sent data intended for future use. Here, K... AUSF This can be referred to as the parent key, from K AUSF Exported K SoRenc or K SoRint The key can be called a subkey.
[0113] In Operation 302, the UE and the network (which may refer to network entities such as the AMF of a VPLMN, the AUSF of an HPLMN, or the UDM of an HPLMN, where the VPLMN and HPLMN can be the same) can perform an authentication process. During the authentication process, the UE and the network can share whether the UE and the network support new features for SoR protection. For example, the relevant information can be shared via new parameters or using existing parameters (such as a random number (RAND) value). When the AUSF of an HPLMN receives UE capabilities, it can send the UE capabilities to the UDM of the HPLMN. When the UDM receives UE SoR capabilities, it can send its own capabilities to the AUSF, and when the AUSF has the capability for the new feature, it can send the network SoR capability to the UE. Alternatively, even if the network SoR capability is not sent to the UE, the UE can know that the network has SoR capability when it receives an additional indication or when an indication of encryption capability is present in the SoR header when receiving SoR data. During the authentication process, the VPLMN's AMF can send the UE security capabilities (a list of encryption algorithms and a list of integrity protection algorithms supported by the UE) received from the UE in Operation 1, or the encryption algorithm or integrity protection algorithm selected by the VPLMN's AMF based on the corresponding information, to the HPLMN's ASF.
[0114] In Operation 303, the UE and the network can exchange their capabilities via NAS Secure Mode Command or NAS Secure Mode Complete (NAS SMC) messages.
[0115] In Operation 304, the VPLMN's AMF can request registration from the UDM, which can utilize the Nudm_UECE_Registration message. When the VPLMN's AMF receives UE SoR capability in Operation 3, the VPLMN's AMF can provide the UE SoR capability to the HPLMN's UDM.
[0116] In operation 305, the HPLMN's UDM can send a registration response message to the VPLMN's AMF.
[0117] In Operation 306, the VPLMN's AMF can invoke the Nudm_SDM_Get service to receive access and mobility subscription data about the UE from the UDM.
[0118] In operation 307, the UDM may determine to send SoR data (bootstrapping information) to the UE and may determine whether the information to be sent needs to be encrypted. The SoR data according to embodiments of this disclosure may include information required for UE roaming (e.g., information such as a preferred PLMN list) and may refer to data provided to the UE.
[0119] In operation 308, the UDM may send to the AUSF at least one of the following: SUPI, SoR data, ACK indication, or a protection indication indicating whether the SoR data needs encryption. The indication indicating whether the SoR data needs encryption may be an additional indication, or it may be indicated in the SoR header that encryption is required. The condition for the UDM to send the indication indicating whether the SoR data needs encryption may be that it received UE SoR capability in one of the previous operations.
[0120] HPLMN's AUSF can be obtained from K AUSF Generate K SoRenc and K SoRint Key. To generate K SoRenc and K SoRint The key can contain the encryption algorithm and algorithm ID, or the integrity protection algorithm and algorithm ID, and K. AUSF As input, use HMAC-SHA256 or a pre-agreed function between UE and AUSF. K SoRenc and K SoRint The key can be called K-based AUSF Generated K AUSF The subkey. K SoRenc It can be the key used by AUSF / UE to encrypt / decrypt SoR data, K SoRint It can be a key used by AUSF / UE to perform integrity protection / integrity protection verification on SoR data.
[0121] Although the accompanying diagram shows the corresponding operation after operation 308, AUSF can generate the key in any operation after AUSF has known about the UE's SoR capability.
[0122] In Operation 309, AUSF can send encrypted data and integrity-protected data (e.g., SoR-MAC-I) to UDM. AUSF ), Counter SoR and SoR-XMAC-I UE At least one of the following: SoR-MAC-I AUSF It can be done using K SoRint Key, SoR header, Counter SoR or K AUSF At least one of the following is a value for encrypted SoR data or SoR data with integrity protection. Counter SoR This is a value managed by the UE and AUSF, and can be used for integrity protection. SoR-XMAC-I UE This is the value generated by AUSF when the UDM sends the ACK indication. Subsequently, the UDM can transmit the SoR-XMAC-I received from AUSF. UEThe value is calculated by the UE and sent to the UDM via SoR-MAC-I. UE A comparison is performed to verify whether the UE has successfully received untampered data. AUSF can use K... AUSF K SoRint and Counter SoR To generate SoR-XMAC-I, at least one of the following must be used: UE AUSF can use K SoRenc The SoR data received from the UDM in Operation 8 is encrypted, and the encryption algorithm can be selected from the UE security capabilities received from the AMF in Operation 2, using the same encryption algorithm sent by the VPLMN AMF, or using an encryption algorithm agreed upon with the UE. The AUSF can use K... SoRint Integrity protection is performed on the SoR data received from the UDM in Operation 8. The integrity protection algorithm can be selected from the UE security capabilities received from the AMF in Operation 2, using the same integrity algorithm sent by the VPLMN AMF, or using an integrity algorithm agreed upon with the UE. In integrity protection, the method pre-agreed with the UE can be the HMAC-SHA256 algorithm, using 0x77, the SoR header, the SoR header length, and the Counter. SoR and Counter SoR The length of the key is taken as input, where the input key can be K. SoRint The AUSF can also combine and send algorithms for encryption or integrity protection. These algorithms can be included together in the SoR header or notified via additional instructions. The HPLMN AUSF can autonomously generate the SoR header based on data received from the HPLMN UDM, or generate and send additional instructions.
[0123] In operation 310, the UDM can send Nudm_SDM_Get_Response to the AMF of the VPLMN. Nudm_SDM_Get_Response includes encrypted SoR data, SoR data, integrity-protected data, and a Counter. SoR At least one of the following. UDM may also send the encryption or integrity protection algorithms used by AUSF.
[0124] In operation 311, the VPLMN's AMF can send a Registration Accept message, which includes the value received from the HPLMN UDM in operation 310.
[0125] UE can also be obtained from K in the same way as AUSF. AUSF Generate K SoRenc and K SoRintKey. Although the accompanying diagram shows this operation after operation 311, it can be performed after the UE is aware of the network's SoR capabilities. Alternatively, when the UE learns in operation 311 that the SoR data is encrypted or that the SoR data is protected for integrity with a new key, the UE can obtain the key from the network. AUSF Generate a new key.
[0126] In Operation 312, the UE can verify SoR-MAC-I AUSF To perform integrity protection verification, and when the SoR header or indication is known, SoR-MAC-I is used. AUSF When encrypted, the K generated in the above operations can be used. SoRenc Key decryption is performed. UE authentication SoR-MAC-I AUSF The method may include the following operations: the UE generates a SoR-MAC-I with AUSF in operation 309. AUSF The SoR-MAC-I is calculated in the same way. AUSF (Using K) SoRint Key, SoR header, Counter SoR or K AUSF At least one of the following (values of encrypted SoR data or SoR data after integrity protection) is used to verify whether the value calculated by the UE is the same as the value received from the VPLMN AMF. In verifying SoR-MAC-I... AUSF Previously, the UE could determine the key used for integrity protection verification through the SoR header or indication.
[0127] When the UDM sends an ACK indication and the UE successfully performs authentication in operation 312, the UE can generate a SoR-MAC-I. UE And in operation 313, the SoR-MAC-I is sent via a registration completion message. UE UE can use K AUSF K SoRint and Counter SoR At least one of the following is used to generate SoR-MAC-I UE .
[0128] When the VPLMN's AMF receives SoR-MAC-I from the UE in Operation 313 UE At that time, the AMF can send the value to the UDM of the HPLMN in operation 314.
[0129] In operation 315, the HPLMN's UDM can receive SoR-MAC-I from the VPLMN AMF. UE The value is the same as the SoR-XMAC-I received from AUSF in operation 309. UE The values are compared to identify whether the UE has received the data correctly.
[0130] Figure 4 This is a schematic diagram illustrating the process of providing configuration information to the UE securely using SoR after the registration process, according to an embodiment of this disclosure.
[0131] refer to Figure 4 In Operation 401, the UDM can determine whether to send SoR data to the UE and whether the information to be sent needs to be encrypted. The UDM can determine the UE's SoR capability (whether the UE has the ability to use data from K) through a registration request message, authentication process, or NAS SMC procedure. AUSF The generated subkey performs encryption, decryption, and integrity protection functions. The UE can also learn about the network's SoR capabilities through the same process. The encryption or integrity protection algorithm used for protection with the new key can be the UE security capabilities (a list of encryption algorithms and a list of integrity protection algorithms supported by the UE) sent by the UE via the registration request message, the encryption or integrity protection algorithm selected by the VPLMN's AMF based on this information, or a method pre-agreed between the UE and the AFS. SoR data can be referred to as configuration information.
[0132] In operation 402, the UDM may send to the AUSF at least one of the following: SUPI, SoR data (e.g., a boot list), ACK indication, or an indication indicating whether the SoR data needs to be encrypted. The indication indicating whether the SoR data needs to be encrypted may be an additional indication, or it may be indicated in the SoR header that encryption is required. The condition for the UDM to send the indication indicating whether the SoR data needs to be encrypted may be that it received UE SoR capability in one of the previous operations.
[0133] HPLMN's AUSF can be obtained from K AUSF Generate K SoRenc and K SoRint Key. To generate K SoRenc or K SoRint The key can take the encryption algorithm and algorithm ID, or the integrity protection algorithm and algorithm ID, and K_AUSF as input values, and use HMAC-SHA256 or a function pre-agreed between the UE and AUSF as a function. Although the attached diagram shows the corresponding operation after operation 402, AUSF can generate the key in any operation after AUSF knows the UE's SoR capability.
[0134] In Operation 403, AUSF may send encrypted data and integrity-protected data (e.g., SoR-MAC-I) to UDM. AUSF ), Counter SoR and SoR-XMAC-I UE At least one of them. AUSF may use K SoRencThe SoR data received from the UDM in Operation 402 is encrypted, and the encryption algorithm can be selected from the UE security capabilities received from the AMF in Operation 402, using the same encryption algorithm sent by the VPLMN AMF, or using an encryption algorithm agreed upon with the UE. The AUSF can use K... SoRint Integrity protection is performed on the SoR data received from the UDM in Operation 402. The integrity protection algorithm can be selected from the UE security capabilities received from the AMF in Operation 402, using the same integrity algorithm sent by the VPLMN AMF, or using an integrity algorithm agreed upon with the UE. In integrity protection, the method pre-agreed with the UE can be the HMAC-SHA256 algorithm, using 0x77, the SoR header, the SoR header length, and the Counter. SoR and Counter SoR The length of the key is taken as input, where the input key can be K. SoRint The AUSF can also combine and send algorithms for encryption or integrity protection. These algorithms can be included together in the SoR header or communicated via additional instructions. The HPLMN AUSF can autonomously generate the SoR header based on data received from the HPLMN UDM, or generate and send additional instructions.
[0135] In Operation 404, the UDM can send encrypted SoR data, SoR data, integrity-protected data, and Counter to the AMF of the VPLMN. SoR The Nudm_SDM_Get_Response must contain at least one of the following: The UDM can also send the encryption or integrity protection algorithm used by AUSF.
[0136] In operation 405, the AMF of the VPLMN may send a DLNAS Transport message that includes the value received from the HPLMN UDM in operation 404.
[0137] UE can also be obtained from K in the same way as AUSF. AUSF Generate K SoRenc and K SoRint Key. Although the accompanying diagram shows this operation after Operation 405, it can be performed after the UE is aware of the network's SoR capabilities. Alternatively, when the UE learns in Operation 405 that the SoR data is encrypted or that the SoR data is protected for integrity with a new key, the UE can obtain the key from the network. AUSF Generate a new key.
[0138] In Operation 406, the UE can verify SoR-MAC-I. AUSF To perform integrity protection verification, and when the SoR header or indication is known, SoR-MAC-I is used. AUSFWhen encrypted, the K generated in the above operations can be used. SoRenc Decryption is performed using the key.
[0139] When the UDM sends an ACK indication and the UE successfully performs authentication in operation 406, the UE can generate a SoR-MAC-I. UE And in operation 407, the SoR-MAC-I is sent via a UL NAS Transport message. UE .
[0140] When the VPLMN's AMF receives SoR-MAC-I from the UE in Operation 407 UE At that time, the AMF can send the value to the UDM of the HPLMN in operation 408.
[0141] In operation 409, the HPLMN UDM can transmit the SoR-MAC-I received from the VPLMN AMF. UE The value is the same as the SoR-XMAC-I received from AUSF in operation 403. UE The values are compared to identify whether the UE has received the data correctly.
[0142] Figure 5 This is a schematic diagram illustrating the process of providing configuration information to the UE securely using a UPU according to an embodiment of this disclosure.
[0143] refer to Figure 5 In Operation 501, the UDM can determine whether to send UPU data to the UE and whether the information to be sent needs to be encrypted. The UDM can determine the UE's UPU capability (whether the UE has the ability to use UPU data from K) through a registration request message, authentication process, or NAS SMC procedure. AUSF The generated subkey performs encryption and decryption as well as integrity protection functions. The UE can also learn about the network's UPU capabilities through the same process. According to embodiments of this disclosure, UE parameter update (UPU) refers to a method by which the UDM provides data to the UE security via control, and UPU data refers to data provided using the UPU. This data may indicate information required by the UE, such as routing indicators and default configuration network slice selection assistance information (NSSAI). The encryption or integrity protection algorithm protected using the new key may be the UE security capabilities (a list of encryption algorithms and a list of integrity protection algorithms supported by the UE) sent by the UE via a registration request message, the encryption or integrity protection algorithm selected by the VPLMN's AMF based on this information, or a method pre-agreed between the UE and the AMF. UE UPU capability or network UPU capability may refer to the use of data from the K... AUSF The generated subkey performs encryption / decryption and integrity protection verification on the UPU data. The UPU data can also be referred to as configuration information.
[0144] In operation 502, the UDM may send to the AUSF at least one of the following: SUPI, UPU data, ACK indication, or indication indicating whether the UPU data needs to be encrypted. The indication indicating whether the UPU data needs to be encrypted may be an additional indication, or it may be indicated in the UPU header that encryption is required. The condition for the UDM to send the indication indicating whether the UPU data needs to be encrypted may be that it received UE UPU capability in one of the previous operations.
[0145] HPLMN's AUSF can be obtained from K AUSF Generate K UPUenc and K UPUint Key. K UPUenc It can be the key used by AUSF / UE to encrypt / decrypt UPU data, K UPUint This can be the key used by AUSF / UE to perform integrity protection / integrity protection verification on encrypted UPU data or UPU data. To generate K... UPUenc or K UPUint The key can contain the encryption algorithm and algorithm ID, or the integrity protection algorithm and algorithm ID, and K. AUSF As input, HMAC-SHA256 or a pre-agreed function between the UE and AUSF is used. Although the attached diagram shows the corresponding operation after operation 502, AUSF can generate the key in any operation after AUSF knows the UE's UPU capabilities. Here, K AUSF This can be referred to as the parent key, K UPUenc and K UPUint This can be referred to as a subkey.
[0146] In Operation 503, AUSF can send encrypted data and integrity-protected data (e.g., UPU-MAC-I) to UDM. AUSF ), Counter UPU and UPU-XMAC-I UE At least one of the following: UPU-MAC-I AUSF It can be done using K UPUint Key, UPU header, Counter UPU or K AUSF At least one of the following is a value for encrypted UPU data or UPU data after integrity protection. UPU This is a value managed by the UE and AUSF, and can be used for integrity protection. SoR-XMAC-I UE This is the value generated by AUSF when the UDM sends an ACK indication. Subsequently, the UDM can access this value via the UPU-XMAC-I received from AUSF. UEThe value is calculated by the UE and sent to the UDU-MAC-I of the UDM. UE The comparison verifies whether the UE has successfully received untampered data. AUSF can use K... AUSF K UPUint and Counter UPU To generate UPU-XMAC-I, at least one of the following must be used: UE AUSF can use K UPUenc The UPU data received from the UDM in Operation 502 is encrypted, and the encryption algorithm can be selected from the UE security capabilities received from the AMF in Operation 502, using the same encryption algorithm sent by the VPLMN AMF, or using an encryption algorithm agreed upon with the UE. The AUSF can use K... UPUint Integrity protection is performed on the UPU data received from the UDM in Operation 502. The integrity protection algorithm can be selected from the UE security capabilities received from the AMF in Operation 502, using the same integrity algorithm sent by the VPLMN AMF, or using an integrity algorithm agreed upon with the UE. In integrity protection, the method pre-agreed with the UE can be the HMAC-SHA256 algorithm, using 0x7B, UPU data, the length of the UPU data, and Counter. UPU and Counter UPU The length of the key is taken as input, where the input key can be K. UPUint The AUSF can also combine and send algorithms for encryption or integrity protection. These algorithms can be included in the UPU header or communicated via additional instructions. The HPLMN AUSF can autonomously generate a UPU header or generate and send additional instructions based on data received from the HPLMN UDM.
[0147] In Operation 504, the UDM can send encrypted UPU data, UPU data, integrity-protected data, and Counter to the AMF of the VPLMN. UPU The Nudm_SDM_Get_Response must contain at least one of the following: The UDM can also send the encryption or integrity protection algorithm used by AUSF.
[0148] In operation 505, the VPLMN's AMF may send a DNNAS Transport message that includes the value received from the HPLMN UDM in operation 504.
[0149] UE can also be obtained from K in the same way as AUSF. AUSF Generate K UPUenc and K UPUintKey. Although the accompanying diagram shows this operation after Operation 505, it can be performed after the UE is aware of the network UPU capabilities. Alternatively, the UE can perform this operation from... when it learns in Operation 505 that the UPU data is encrypted or that the UPU data is protected for integrity with a new key. KAUSF Generate a new key (e.g., K) UPUenc and K UPUint ).
[0150] In Operation 506, the UE can verify the UPU-MAC-I. AUSF To perform integrity protection verification, and when the UPU header or indication is known, UPU-MAC-I is used. AUSF When encrypted, the K generated in the above operations can be used. UPUenc Decryption is performed using the key.
[0151] When the UDM sends an ACK indication and the UE successfully performs authentication in operation 506, the UE can generate a UPU-MAC-I. UE And in operation 507, the UPU-MAC-I is sent via the UL NAS Transport message. UE .
[0152] When the VPLMN's AMF receives UPU-MAC-I from the UE in Operation 507 UE At that time, the AMF can send the value to the UDM of the HPLMN in operation 508.
[0153] In Operation 509, the HPLMN's UDM can receive the UPU-MAC-I from the VPLMN AMF. UE The value is the same as the UPU-XMAC-I received from AUSF in Operation 503. UE The values are compared to identify whether the UE has received the data correctly.
[0154] It should be noted that Figures 1A to 1B Figure 5 The configuration diagrams, schematic diagrams of control / data signal transmission methods, schematic diagrams of operation flows, and structural diagrams shown above are not intended to limit the scope of protection of this disclosure. That is, Figures 1A to 1B are not intended to limit the scope of protection of this disclosure. Figure 5 All constituent elements, entities, or operational steps shown and described herein should not be construed as essential elements for implementing this disclosure, and may be implemented without prejudice to the nature of this disclosure even if only some elements are included.
[0155] The operation of the above embodiments can be implemented by providing any unit of the device with a storage device for storing the corresponding program code. That is, the controller in the device can read and execute the program code stored in the storage device through a processor or CPU to perform the above operations.
[0156] The various units or modules of the entities or terminal devices described herein can be operated by hardware circuits such as logic circuits based on complementary metal-oxide-semiconductor (CMOS), firmware, or hardware circuits such as software and / or combinations of hardware and firmware and / or software embedded in a machine-readable medium. For example, various electrical structures and methods can be implemented by electrical circuits such as transistors, logic gates, and application-specific integrated circuits (ASICs).
[0157] The methods disclosed in the claims or the methods of the embodiments described in this disclosure may be implemented by hardware, software, or a combination of hardware and software.
[0158] When the method is implemented in software, a computer-readable storage medium may be provided for storing one or more programs (software modules). The one or more programs stored in the computer-readable storage medium may be configured to be executed by one or more processors within an electronic device. The at least one program includes instructions to cause the electronic device to perform the method according to the appended claims and / or the various embodiments of this disclosure.
[0159] These programs (software modules or software) may be stored in non-volatile memory, including random access memory and flash memory, read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic disk storage devices, optical disc-ROM (CD-ROM), digital versatile optical disc (DVD), or other types of optical storage devices or magnetic tape. Alternatively, any combination of some or all of these may form a memory storing programs. Furthermore, electronic devices may include multiple such memories.
[0160] Furthermore, programs can be stored in attachable storage devices that are accessible to electronic devices via communication networks such as the Internet, intranets, local area networks (LANs), wide area LANs (WLANs), and storage area networks (SANs), or combinations thereof. Such storage devices can be accessed via external ports. Additionally, separate storage devices on communication networks can access portable electronic devices.
[0161] In the detailed embodiments of this disclosure described above, the elements included in this disclosure are represented in singular or plural form according to the presented detailed embodiments. However, the singular or plural form is a form chosen for ease of description and suitability for the presentation scenario, and this disclosure is not limited to elements represented in singular or plural form. Therefore, an element represented in plural form may include a single element, or an element represented in singular form may include multiple elements.
[0162] Although specific embodiments have been described in the detailed description of this disclosure, it will be apparent that various modifications and changes can be made thereto without departing from the scope of this disclosure. Therefore, the scope of this disclosure should not be defined as limited to the embodiments set forth herein, but rather as defined by the appended claims and their equivalents.
Claims
1. A method performed by an authentication server function (AUSF) entity in a wireless communication system, the method comprising: receiving, from a unified data management (UDM) entity, configuration information and an indication indicating encryption or integrity protection of the configuration information; generating, from a stored parent key, a first child key for encryption or a second child key for integrity protection; encrypting the configuration information using the first child key or integrity protecting the configuration information using the second child key; and transmitting, to the UDM entity, the encrypted or integrity protected configuration information. transmitting, to the UDM entity, information about a first algorithm for encryption or information about a second algorithm for integrity protection.
2. The method of claim 1, further comprising: generating a message authentication code (MAC) value using at least one of the parent key, the second child key, or a counter value for integrity protection, 3. The method of claim 1, further comprising: wherein the MAC value is used to identify whether the configuration information received by a user equipment is tampered. 4.The method of claim 1, further comprising: receiving user equipment capability information indicating whether a user equipment is capable of generating the first child key or the second child key from the parent key; and transmitting, to the UDM entity, the user equipment capability information. 5.A method performed by a user equipment (UE) in a wireless communication system, the method comprising: receiving, from an access and mobility management function (AMF) entity, encrypted or integrity protected configuration information and an indication indicating that the configuration information has been encrypted or integrity protected; generating, from a stored parent key, a first child key for decryption or a second child key for integrity protection verification; and decrypting the encrypted configuration information using the first child key or integrity protection verifying the integrity protected configuration information using the second child key. 6.The method of claim 5, further comprising: receiving, from the AMF entity, information about a first algorithm for encryption or information about a second algorithm for integrity protection. 7.The method of claim 5, further comprising: generating a message authentication code (MAC) value using at least one of the parent key, the second child key, or a counter value for integrity protection; and transmitting, to the AMF entity, the MAC value, wherein the MAC value is used to identify whether the configuration information received by the UE is tampered. 8.The method of claim 5, further comprising: transmitting, to the AMF entity, UE capability information indicating whether the UE is capable of generating the first child key or the second child key from the parent key; and receiving, from the AMF entity, network capability information indicating whether a network entity is capable of generating the first child key or the second child key from the parent key. 9.An authentication server function (AUSF) entity in a wireless communication system, the AUSF entity comprising: a transceiver; and a controller connected with the transceiver, wherein the controller is configured to: receive configuration information and an indication indicating encryption or integrity protection of the configuration information from a unified data management, UDM, entity; generate a first sub-key for encryption or a second sub-key for integrity protection from a stored parent key; encrypt the configuration information using the first sub-key or integrity protect the configuration information using the second sub-key; and send the encrypted or integrity protected configuration information to the UDM entity.
10. The AUSF entity of claim 9, wherein, the controller is configured to send information about a first algorithm for encryption or information about a second algorithm for integrity protection to the UDM entity.
11. The AUSF entity of claim 9, wherein, the controller is configured to generate a message authentication code, MAC, value using at least one of the parent key, the second sub-key, or a counter value for the integrity protection, wherein the MAC value is used to identify whether the configuration information received by a user equipment is tampered.
12. The AUSF entity of claim 9, wherein, the controller is configured to: receive user equipment capability information indicating whether a user equipment is capable of generating the first sub-key or the second sub-key from the parent key; and send the user equipment capability information to the UDM entity.
13. A user equipment, UE, in a wireless communication system, the UE comprising: a transceiver; and a controller connected with the transceiver, wherein the controller is configured to: receive encrypted or integrity protected configuration information and an indication indicating that the configuration information has been encrypted or has been integrity protected from an access and mobility management function, AMF, entity; generate a first sub-key for decryption or a second sub-key for integrity protection verification from a stored parent key; and decrypt the encrypted configuration information using the first sub-key or integrity protection verify the integrity protected configuration information using the second sub-key. the controller is configured to receive information about a first algorithm for encryption or information about a second algorithm for integrity protection from the AMF entity.
14. The UE of claim 13, wherein, the controller is configured to:
15. The UE of claim 13, wherein, send UE capability information to the AMF entity, the UE capability information indicating whether the UE is capable of generating the first sub-key or the second sub-key from the parent key; receive network capability information from the AMF entity, the network capability information indicating whether a network entity is capable of generating the first sub-key or the second sub-key from the parent key; generate a message authentication code, MAC, value using at least one of the parent key, the second sub-key, or a counter value for integrity protection; and send the MAC value to the AMF entity, and wherein the MAC value is used to identify whether the configuration information received by the UE is tampered.