Access hierarchy security anchor for wireless network service security architecture
By using the Access Layer (AS) security mechanism to generate and transmit AS keys, the complexity of NAS security context in wireless communication systems is solved, enabling efficient and secure access and mobility management for wireless devices.
Patent Information
- Application Number
- CN202480050680.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-08-09
- Filing Date
- 2024-08-01
- Publication Date
- 2026-03-06
AI Technical Summary
When existing wireless communication systems build additional security layers on top of the NAS security context of security functions, they struggle to support additional security features, leading to increased complexity of security functions and difficulties in service access.
By leveraging the Access Layer (AS) security mechanism, security services are used to generate and transmit AS keys, establishing a security context between wireless devices and wireless nodes, and supporting secure access and mobility management for devices in wireless networks.
It simplifies the secure access process to wireless networks, improves the efficiency of secure connections between devices and wireless nodes, and supports smooth movement of devices between different wireless nodes and security context reconstruction.
Smart Images

Figure CN121620947A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to wireless communications in general. For example, aspects of this disclosure relate to access layer security for wireless network service security architectures. Background Technology
[0002] Wireless communication systems are deployed to provide a variety of telecommunications and data services, including telephone, video, data, messaging, and broadcasting. Broadband wireless communication systems have evolved through several generations, including first-generation analog wireless telephone service (1G), second-generation (2G) digital wireless telephone service (including the transitional 2.5G networks), third-generation (3G) high-speed data wireless devices with internet capabilities, and fourth-generation (4G) services (e.g., LTE, WiMax). Examples of wireless communication systems include Code Division Multiple Access (CDMA) systems, Time Division Multiple Access (TDMA) systems, Frequency Division Multiple Access (FDMA) systems, Orthogonal Frequency Division Multiple Access (OFDMA) systems, and the Global System for Mobile Communications (GSM) system. Other wireless communication technologies include 802.11 Wi-Fi, Bluetooth, etc.
[0003] The fifth-generation (5G) mobile standard demands higher data speeds, a greater number of connections, better coverage, and other improvements. According to the Next Generation Mobile Networks Alliance (NGC), the 5G standard (also known as “New Radio” or “NR”) is designed to provide tens of megabits per second of data rate to each of tens of thousands of users, and 1 gigabits per second to dozens of employees on an office floor. To support large-scale sensor deployments, it should support hundreds of thousands of simultaneous connections. The sixth-generation (6G) mobile standard can be built on top of 5G to provide further increased data speeds, better coverage, improved security, and other enhancements. Summary of the Invention
[0004] The following is a simplified summary of the invention relating to one or more aspects disclosed herein. Therefore, this summary should not be considered an exhaustive overview relating to all conceived aspects, nor should it be considered to identify key or decisive elements relating to all conceived aspects or to depict the scope associated with any particular aspect. Accordingly, the following summary presents certain concepts in a simplified form relating to one or more aspects of the mechanisms disclosed herein, preceding the detailed description presented below.
[0005] Systems, methods, apparatuses, and computer-readable media for performing wireless communications are disclosed. In one exemplary example, a method for protecting access to a wireless network is provided. The method includes: receiving from a service a first request for a service key for accessing the service by a security service, the first request for the service key including an identifier of a first wireless node and a service security policy, wherein the service security policy indicates the use of access layer (AS) security, and wherein the first wireless node is wirelessly coupled to a wireless device attempting to access the service; transmitting the service key for accessing the service from the security service in response to the first request for the service key; generating a first AS key based on the identifier of the first wireless node; and transmitting the generated first AS key to the first wireless node based on the identifier of the first wireless node.
[0006] As another example, a method for securing access to a wireless network is provided. The method includes: receiving a service access request for a service of the wireless network from a wireless device wirelessly coupled to the wireless node; sending the service access request to the service; sending Access Layer (AS) security activation state information and an identifier of the wireless node to the service, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; receiving an AS key generated based on the identifier of the wireless node from the security service; and establishing an AS security context with the wireless device based on the AS key.
[0007] In another example, a method for securing access to a wireless network is provided. The method includes: receiving a service access request for the service from a wireless device wirelessly coupled to a wireless node by a service of the wireless network; receiving access layer (AS) security activation state information and an identifier of the wireless node, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; determining whether AS security is active based on a service security policy and the AS security activation state information, wherein the service security policy indicates the use of access layer (AS) security; sending a request for a service key for accessing the service to a security service of the wireless network, the request for the service key including the identifier of the wireless node and the service security policy; receiving service key information for accessing the service in response to the request for the service key; establishing a security context with the wireless device based on the service key information; and registering with a mobility service of the wireless network.
[0008] As another example, an apparatus for protecting access to a wireless network is provided. The apparatus includes: a memory system including instructions; and a processor system coupled to the memory system. The processor system is configured to: receive from a service a first request for a service key for accessing the service, the first request for the service key including an identifier of a first wireless node and a service security policy, wherein the service security policy indicates the use of Access Layer (AS) security, and wherein the first wireless node is wirelessly coupled to a wireless device attempting to access the service; transmit the service key for accessing the service in response to the first request for the service key; generate a first AS key based on the identifier of the first wireless node; and transmit the generated first AS key to the first wireless node based on the identifier of the first wireless node.
[0009] In another example, an apparatus for protecting access to a wireless network is provided. The apparatus includes: a memory system including instructions; and a processor system coupled to the memory system. The processor system is configured to: receive a service access request for a service of the wireless network from a wireless device wirelessly coupled to a wireless node; send the service access request to the service; send Access Layer (AS) security activation state information and an identifier of the wireless node to the service, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; receive an AS key generated based on the identifier of the wireless node from the security service; and establish an AS security context with the wireless device based on the AS key.
[0010] As another example, an apparatus for protecting access to a wireless network is provided. The apparatus includes: a memory system including instructions; and a processor system coupled to the memory system. The processor system is configured to: receive a service access request for a service of the wireless network from a wireless device wirelessly coupled to a wireless node; receive access layer (AS) security activation state information and an identifier of the wireless node, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; determine whether AS security is active based on a service security policy and the AS security activation state information, wherein the service security policy indicates the use of access layer (AS) security; send a request for a service key for accessing the service to a security service of the wireless network, the request for the service key including the identifier of the wireless node and the service security policy; receive service key information for accessing the service in response to the request for the service key; establish a security context with the wireless device based on the service key information; and register with a mobility service of the wireless network.
[0011] In another example, a non-transitory computer-readable medium having instructions stored thereon is provided. These instructions, when executed by a processor system, cause the processor system to: receive from a service a first request for a service key for accessing the service, the first request for the service key including an identifier of a first wireless node and a service security policy, wherein the service security policy instructs the use of Access Layer (AS) security, and wherein the first wireless node is wirelessly coupled to a wireless device attempting to access the service; transmit the service key for accessing the service in response to the first request for the service key; generate a first AS key based on the identifier of the first wireless node; and transmit the generated first AS key to the first wireless node based on the identifier of the first wireless node.
[0012] As another example, a non-transitory computer-readable medium is provided on which instructions are stored. These instructions, when executed by a processor system, cause the processor system to: receive a service access request for a service of a wireless network from a wireless device wirelessly coupled to a wireless node; send the service access request to the service; send access layer (AS) security activation state information and the identifier of the wireless node to the service, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; receive an AS key generated based on the identifier of the wireless node from the security service; and establish an AS security context with the wireless device based on the AS key.
[0013] In another example, a non-transitory computer-readable medium is provided having instructions stored thereon. These instructions, when executed by a processor system, cause the processor system to: receive a service access request for a service of a wireless network from a wireless device wirelessly coupled to a wireless node; receive access layer (AS) security activation state information and an identifier of the wireless node, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; determine whether AS security is active based on a service security policy and the AS security activation state information, wherein the service security policy indicates the use of access layer (AS) security; send a request for a service key for accessing the service to the security service of the wireless network, the request for the service key including the identifier of the wireless node and the service security policy; receive service key information for accessing the service in response to the request for the service key; establish a security context with the wireless device based on the service key information; and register with the mobility service of the wireless network.
[0014] As another example, an apparatus for protecting access to a wireless network is provided. The apparatus includes: components for receiving a service access request for a service of the wireless network from a wireless device wirelessly coupled to the wireless node; components for sending the service access request to the service; components for sending Access Layer (AS) security activation state information and an identifier of the wireless node to the service, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; components for receiving an AS key generated based on the identifier of the wireless node from the security service; and components for establishing an AS security context with the wireless device based on the AS key.
[0015] In another example, an apparatus for protecting access to a wireless network is provided. The apparatus includes: components for receiving a service access request for a service of the wireless network from a wireless device wirelessly coupled to the wireless node; components for sending the service access request to the service; components for sending Access Layer (AS) security activation state information and an identifier of the wireless node to the service, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; components for receiving an AS key generated based on the identifier of the wireless node from the security service; and components for establishing an AS security context with the wireless device based on the AS key.
[0016] As another example, an apparatus for protecting access to a wireless network is provided. The apparatus includes: components for receiving a service access request for a service from a wireless device wirelessly coupled to a wireless node by a service of the wireless network; receiving access layer (AS) security activation state information and an identifier of the wireless node, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; components for determining whether to activate AS security based on a service security policy and the AS security activation state information, wherein the service security policy indicates the use of access layer (AS) security; components for sending a request for a service key for accessing the service to a security service of the wireless network, the request for the service key including the identifier of the wireless node and the service security policy; components for receiving service key information for accessing the service in response to the request for the service key; components for establishing a security context with the wireless device based on the service key information; and components for registering with a mobility service of the wireless network.
[0017] The aspects generally include methods, apparatus, systems, computer program products, non-transitory computer-readable media, user equipment, base stations, wireless communication devices and / or processing systems, as fully described herein with reference to the accompanying drawings and description, and as illustrated in the accompanying drawings and description.
[0018] The features and technical advantages of the examples according to this disclosure have been summarized rather extensively above in order to better understand the detailed description below. Additional features and advantages will be described below. The disclosed concepts and specific examples can be readily used as the basis for modifying or designing other structures for achieving the same purpose of this disclosure. Such equivalent constructions do not depart from the scope of the appended claims. The characteristics of the concepts disclosed herein, in both their organization and manner of operation, and the associated advantages, will be better understood by considering the following description in conjunction with the accompanying drawings. Each of the drawings provided is for illustrative and descriptive purposes and not as a limitation of the definitions in the claims.
[0019] While aspects are described herein by way of example, those skilled in the art will understand that such aspects can be implemented in many different arrangements and scenarios. The techniques described herein can be implemented using different platform types, devices, systems, shapes, sizes, and / or package arrangements. For example, some aspects can be implemented via integrated chip implementations or other devices based on non-modular components (e.g., end-user equipment, vehicles, communication equipment, computing devices, industrial equipment, retail / shopping devices, medical devices, and / or artificial intelligence devices). Aspects can be implemented in chip-level components, modular components, non-modular components, non-chip-level components, device-level components, and / or system-level components. Devices incorporating the described aspects and features may include additional components and features for implementing and practicing the claimed and described aspects. For example, the transmission and reception of wireless signals may include one or more components for analog and digital purposes (e.g., hardware components including antennas, radio frequency (RF) chains, power amplifiers, modulators, buffers, processors, interleavers, adders, and / or summers). The aspects described herein are intended to be practiced in a wide variety of devices, components, systems, distributed arrangements, and / or end-user equipment of various sizes, shapes, and configurations.
[0020] Based on the accompanying drawings and detailed description, other objects and advantages associated with the aspects disclosed herein will be apparent to those skilled in the art. Attached Figure Description
[0021] Examples of specific implementations are described in detail below with reference to the accompanying figures: Figure 1 This is a block diagram illustrating an example of a wireless communication network based on some examples; Figure 2 These are illustrations of base station and user equipment (UE) designs based on some examples, which enable the transmission and processing of signals exchanged between the UE and the base station; Figure 3 This is a diagram illustrating an example of a decomposed base station based on some examples; Figure 4 This is a block diagram illustrating the components of a user device based on some examples; Figure 5 This is a diagram illustrating the security architecture of a wireless system based on various aspects of this disclosure; Figure 6 This is a tree diagram illustrating the hierarchical structure of encryption keys for services such as wireless systems, according to various aspects of this disclosure; Figure 7 This is a call flow diagram illustrating techniques for secure access to services on a wireless system according to various aspects of this disclosure; Figure 8 This is a call flow diagram illustrating various aspects of secure access techniques for roaming according to this disclosure; Figure 9 This is an example of a call flow diagram illustrating a technology 900 for establishing user plane service security according to various aspects of this disclosure; Figure 10 This is an example of a call flow diagram illustrating alternative technology 1000 for establishing user plane service security according to various aspects of this disclosure; Figure 11 This is an example of a call flow diagram illustrating various aspects of this disclosure for establishing a service security call, including AS security. Figure 12 This is an example call flow diagram illustrating various aspects of this disclosure for maintaining AS security for mobility. Figure 13 This is a flowchart illustrating a process for protecting access to a wireless system according to various aspects of this disclosure; Figure 14 This is a flowchart illustrating a process for protecting access to a wireless system according to various aspects of this disclosure; Figure 15 This is a flowchart illustrating various aspects of the process for protecting access to a wireless system according to this disclosure; and Figure 16 This is a diagram illustrating an example of a system used to implement certain aspects of this technology. Detailed Implementation
[0022] Certain aspects and embodiments of this disclosure are provided below. Some of these aspects and embodiments may be applied independently, and some may be combined, as will be apparent to those skilled in the art. Specific details are set forth in the following description for purposes of explanation in order to provide a thorough understanding of the various embodiments of this application. However, it will be apparent, however, that the various embodiments may be practiced without these specific details. The accompanying drawings and descriptions are not intended to be limiting.
[0023] The following description provides only exemplary embodiments and is not intended to limit the scope, applicability, or configuration of this disclosure. Rather, the subsequent description of exemplary embodiments will provide those skilled in the art with enabling descriptions for implementing the exemplary embodiments. It should be understood that various changes may be made to the function and arrangement of the elements without departing from the spirit and scope of this application as set forth in the appended claims.
[0024] Wireless networks are deployed to provide various communication services, such as voice, video, packet data, message sending and receiving, and broadcasting. Wireless networks can support two types of access links for communication between wireless devices. An access link can refer to any communication link between components of a client device (e.g., a User Equipment (UE), Station (STA), or other client device) and a base station (e.g., a 3GPP gNodeB (gNB) for 5G / NR, a 3GPP eNodeB (eNB) for LTE, a Wi-Fi access point (AP), or other base station) or a distributed base station (e.g., a central unit, distributed units, and / or radio units). In one example, the access link between a UE and a 3GPP gNB can be via the Uu interface. In some cases, the access link can support uplink signaling, downlink signaling, connection procedures, etc.
[0025] Various systems and technologies are available for wireless technologies (e.g., 3GPP 5G / New Radio (NR) standards, 6G, etc.) to provide improvements to wireless communication. Devices (e.g., UEs, wireless devices, mobile devices, etc.) can be configured to access wireless networks (e.g., wireless systems) to communicate with other devices. As part of accessing the wireless network, devices can be configured to authenticate with the wireless network. Based on authentication, devices can establish one or more security contexts to allow private communication between the device and the services of the wireless network. In some wireless networks, devices connected to the wireless network will establish a security context with the core network's security functions (e.g., Non-Access Layer (NAS) security). Based on this security context, additional application layer security can be built on top of it. However, because an additional security layer is built on top of the NAS security context of the security function, the security function may need to support the additional security layer, making it difficult to add services that may use security features not supported by the security function.
[0026] This document describes systems, apparatuses, processes (also referred to as methods), and computer-readable media (collectively, "systems and technologies") that allow different services to establish their own security. In some cases, a device may request access to a service by contacting a security service. Services may include mobility services, transport services, voice services, location services, internet services, and so on. The security service may provide cryptographic keys for authenticating and / or securely accessing other services, such as by providing cryptographic keys that can be used by other services to protect communications with the device. In the case of a device initially accessing a security service, the security service may perform an authentication and key negotiation process with the device to generate a session root key and establish a security context with the security service based on the session root key. The session root key may be a cryptographic key from which other cryptographic keys, such as service keys, can be derived. The security service may then transmit service key information of the service that the device is trying to access to the device. The device may use this service key information to derive a service key for accessing the service. The device may then directly transmit a service request to the service based on the service key encoding. The service may then contact the security service to obtain the service key. Once the service obtains the service key from the security service, it can decode service access requests from the device and establish a security context between the service and the device based on the service key. Then, any additional security layer can be built on top of the security context between the service and the device.
[0027] In some cases, Access Layer (AS) security can be used to protect the connection between a device and a wireless node in a wireless system connected to it. AS security applies a security layer to the radio interface of the wireless node that connects the device to the wireless system. Whether AS security is applied can be determined by the services of the wireless system the device is accessing. For example, the device may access a service that can enable AS security between the device and the wireless node based on a service security policy, rather than user plane security. As another example, another service may enable both AS security and user plane security based on a different service security policy. If a service determines that AS security should be enabled, it may send a service key request to a security service. The security service may respond with the service key to allow the service to establish a service security context with the device. The service may also register the service and the device with the mobility service of the wireless system. The security service may derive an AS key and transmit it to the wireless node. The wireless node can then use the AS key to establish an AS security context between the wireless node and the device.
[0028] Because an AS security context is established between the device and the wireless node, if the device moves to another wireless node, the AS security context may need to be rebuilt. Devices can move between wireless nodes during a mobility event. The device can indicate such a mobility event to the mobility service. The mobility service can determine the set of wireless nodes the device can move to and can transmit this set of wireless nodes to the security service in a service key request. The security service can then generate an AS key for the wireless nodes in the set of wireless nodes. The security service can then send the generated AS key to one or more wireless nodes in the set of wireless nodes to help establish the AS security context. Using the AS security context, a wireless node can immediately establish a secure connection with the device without communicating with the security service to obtain the security key.
[0029] In some cases, the wireless node can also generate an AS security context cookie and send it to the device. The AS security context cookie can include information used to reconstruct the AS security context between the wireless node and the device. If the wireless node removes the AS security context (e.g., if the device enters an inactive or idle state) and the device reconnects to the wireless node (e.g., if the device subsequently enters an inactive or idle state), the wireless node can reconstruct the AS security context with the device based on the information in the AS security context cookie.
[0030] When a service (such as a device) receives a service access request, it can request a service key from the security service. As part of this service key request, the service can also transmit a service security policy to the security service. After (or simultaneously with) establishing a service security context between the service and the device, a configuration request is sent to the transport service to establish a UPSA for the service. The configuration request can be sent by either the service or the security service, and can include the service security policy. Based on the service, the device, and the service security policy, the transport service can determine the UPSA to be used and can send a response to the configuration request, which includes an indication of the UPSA to be used (e.g., the identifier of the UPSA). The response to the configuration request can be transmitted to either the service or the security service, depending on which one transmitted the configuration request. If the service transmitted the configuration request, the service can transmit a request to the security service to determine the UPSA key. If the security service transmitted the configuration request, the security service can determine whether a UPSA key is needed. The security service can then determine the UPSA key. In some cases, the UPSA key can be determined based on the service's identifier, using the session root key associated with the wireless device. The security service can then send the UPSA key to the UPSA. Then, UPSA can use the UPSA key to establish a user plane security context with the wireless device.
[0031] Additional aspects of this disclosure are described in more detail below.
[0032] As used herein, the terms “User Equipment” (UE) and “Network Entity” are not intended to be specific to or otherwise limited to any particular Radio Access Technology (RAT) unless otherwise specified. In general, a UE can be any wireless communication device (e.g., mobile phone, router, tablet computer, laptop computer, and / or tracking device, etc.), wearable device (e.g., smartwatch, smart glasses, wearable ring, and / or extended reality (XR) device (such as virtual reality (VR) headset, augmented reality (AR) headset or glasses, or mixed reality (MR) headset)), vehicle (e.g., car, motorcycle, bicycle, etc.), and / or Internet of Things (IoT) device, etc., for a user to communicate over a wireless communication network. A UE can be mobile or can (e.g., at certain times) be stationary and can communicate with a Radio Access Network (RAN). As used herein, the term "UE" can be interchangeably referred to as "access terminal" or "AT," "client device," "wireless device," "subscriber device," "subscriber terminal," "subscriber station," "user terminal," or "UT," "mobile device," "mobile terminal," "mobile station," or variations thereof. Generally, a UE can communicate with the core network via the RAN, and through the core network, the UE can connect to external networks such as the Internet and other UEs. Of course, other mechanisms for connecting to the core network and / or the Internet are also possible for the UE, such as through wired access networks, wireless local area network (WLAN) networks (e.g., based on the IEEE 802.11 communication standard), etc.
[0033] Network entities can be implemented in a converged or monolithic base station architecture, or alternatively, in a decomposed base station architecture, and may include one or more of a central unit (CU), a distributed unit (DU), a radio unit (RU), a near real-time (near RT) RAN intelligent controller (RIC), or a non-real-time (non-RT) RIC. A base station (e.g., with a converged / monolithic or decomposed base station architecture) may operate according to one of several RATs communicating with the UE (depending on the network in which it is deployed), and may alternatively be referred to as an access point (AP), network node, NodeB (NB), evolved NodeB (eNB), next-generation eNB (ng-eNB), new radio (NR) NodeB (also known as gNB or gNodeB), etc. The base station may primarily be used to support the UE's radio access, including supporting data, voice, and / or signaling connections for the supported UE. In some systems, the base station may provide edge node signaling functions, while in others, it may provide additional control and / or network management functions. The communication link through which a UE transmits signals to a base station is called an uplink (UL) channel (e.g., reverse traffic channel, reverse control channel, access channel, etc.). The communication link through which a base station transmits signals to a UE is called a downlink (DL) or forward link channel (e.g., paging channel, control channel, broadcast channel, or forward traffic channel, etc.). As used herein, the term traffic channel (TCH) can refer to uplink, reverse or downlink, and / or forward traffic channel.
[0034] The terms "network entity" or "base station" (e.g., having a converged / monolithic base station architecture or a decomposed base station architecture) can refer to a single physical transmit / receive point (TRP) or multiple physical TRPs that may be co-located or non-co-located. For example, when the term "network entity" or "base station" refers to a single physical TRP, the physical TRP may be a base station antenna corresponding to a cell (or several cell sectors) of the base station. When the term "network entity" or "base station" refers to multiple co-located physical TRPs, these physical TRPs may be an antenna array of the base station (e.g., as in a multiple-input multiple-output (MIMO) system or where the base station employs beamforming). When the term "base station" refers to multiple non-co-located physical TRPs, the physical TRPs may be a distributed antenna system (DAS) (a network of spatially separated antennas connected via a transmission medium to a common source) or a remote radio headend (RRH) (a remote base station connected to a serving base station). Alternatively, a non-co-located physical TRP may be a serving base station receiving measurement reports from a UE and a neighboring base station where the UE is measuring its reference radio frequency (RF) signal (or simply "reference signal"). As used in this article, a TRP is the point by which a base station transmits and receives wireless signals, so any mention of transmitting from or receiving at a base station should be understood as referring to a specific TRP of the base station.
[0035] In some specific implementations supporting UE positioning, network entities or base stations may not support the UE's radio access (e.g., may not support data, voice, and / or signaling connections regarding the UE), but instead may transmit reference signals to the UE for measurement, and / or receive and measure signals transmitted by the UE. Such a base station may be referred to as a positioning beacon (e.g., in the case of transmitting signals to the UE) and / or as a location measurement unit (e.g., in the case of receiving and measuring signals from the UE).
[0036] RF signals comprise electromagnetic waves of a given frequency that transmit information across the space between a transmitter and a receiver. As used herein, a transmitter may send a single “RF signal” or multiple “RF signals” to a receiver. However, due to the propagation characteristics of RF signals through multipath channels, a receiver may receive multiple “RF signals” corresponding to each transmitted RF signal. The same transmitted RF signal on different paths between the transmitter and receiver may be referred to as a “multipath” RF signal. As used herein, where the context clearly indicates that the term “signal” refers to a wireless signal or RF signal, an RF signal may also be referred to as a “wireless signal” or simply a “signal.”
[0037] Various aspects of the systems and technologies described herein will be discussed below with reference to the accompanying drawings. According to these aspects, Figure 1 An example of a wireless communication system 100 is illustrated. The wireless communication system 100 (which may also be referred to as a wireless wide area network (WWAN)) may include various base stations 102 and various UEs 104. In some aspects, base station 102 may also be referred to as a “network entity” or a “network node.” One or more base stations in base station 102 may be implemented in an aggregated or monolithic base station architecture. Additionally or alternatively, one or more base stations in base station 102 may be implemented in a decomposed base station architecture and may include one or more of a central unit (CU), a distributed unit (DU), a radio unit (RU), a near real-time (near RT) RAN intelligent controller (RIC), or a non-real-time (non-RT) RIC. Base station 102 may include macro cell base stations (high-power cellular base stations) and / or small cell base stations (low-power cellular base stations). In one aspect, macro cell base stations may include eNBs and / or ng-eNBs (where wireless communication system 100 corresponds to a Long Term Evolution (LTE) network), or gNBs (where wireless communication system 100 corresponds to an NR network), or a combination of both, and small cell base stations may include femtocells, picocells, microcells, etc.
[0038] Base station 102 can collectively form a RAN and interface with core network 170 (e.g., evolved packet core (EPC) or 5G core (5GC)) via backhaul link 122, and interface with one or more location servers 172 (which may be part of core network 170 or external to core network 170) via core network 170. Among other functions, base station 102 can perform functions related to one or more of the following: delivering user data, radio channel encryption and decryption, integrity protection, header compression, mobility control functions (e.g., handover, dual connectivity), inter-cell interference coordination, connection establishment and release, load balancing, distribution of non-access stratum (NAS) messages, NAS node selection, synchronization, RAN sharing, multimedia broadcast multicast service (MBMS), subscriber and equipment tracking, RAN information management (RIM), paging, location, and delivery of warning messages. Base station 102 can communicate with each other directly or indirectly (e.g., via EPC or 5GC) via backhaul link 134 (which may be wired and / or wireless).
[0039] Base station 102 can wirelessly communicate with UE 104. Each base station in base station 102 can provide communication coverage for a corresponding geographical coverage area 110. In one aspect, base station 102 in each coverage area 110 can support one or more cells. A “cell” is a logical communication entity used to communicate with a base station (e.g., on a frequency resource, referred to as a carrier frequency, component carrier, carrier, frequency band, etc.) and can be associated with an identifier (e.g., Physical Cell Identifier (PCI), Virtual Cell Identifier (VCI), Cell Global Identifier (CGI)) to distinguish cells operating via the same or different carrier frequencies. In some cases, different cells can be configured according to different protocol types that can provide access for different types of UEs (e.g., Machine Type Communication (MTC), Narrowband IoT (NB-IoT), Enhanced Mobile Broadband (eMBB), or other protocol types). Because a cell is supported by a specific base station, the term “cell” can refer to either or both of the logical communication entity and the base station supporting the logical communication entity, depending on the context. Furthermore, since the TRP is typically the physical transmission point of the cell, the terms “cell” and “TRP” can be used interchangeably. In some cases, the term "cell" may also refer to the geographic coverage area (e.g., sector) of a base station, provided that a carrier frequency can be detected within a portion of the geographic coverage area 110 and that carrier frequency is used for communication within that portion.
[0040] While the geographic coverage areas 110 of adjacent macro cell base stations 102 may partially overlap (e.g., in handover areas), some areas within geographic coverage areas 110 may substantially overlap with larger geographic coverage areas 110. For example, a small cell base station 102' may have a coverage area 110' that substantially overlaps with the coverage areas 110 of one or more macro cell base stations 102. A network that includes both small cell base stations and macro cell base stations may be referred to as a heterogeneous network. A heterogeneous network may also include a home eNB (HeNB) that can provide service to a restricted group referred to as a Closed Subscriber Group (CSG).
[0041] The communication link 120 between base station 102 and UE 104 may include uplink (also known as reverse link) transmission from UE 104 to base station 102 and / or downlink (also known as forward link) transmission from base station 102 to UE 104. Communication link 120 may use MIMO antenna techniques, including spatial multiplexing, beamforming, and / or transmit diversity. Communication link 120 may use one or more carrier frequencies. Carrier allocation may be asymmetric for downlink and uplink (e.g., more or fewer carriers may be allocated to the downlink compared to the uplink).
[0042] The wireless communication system 100 may also include a WLAN AP 150 communicating with a WLAN station (STA) 152 via a communication link 154 in unlicensed spectrum (e.g., 5 GHz). When communicating in unlicensed spectrum, the WLAN STA 152 and / or WLAN AP 150 may perform a Free Channel Assessment (CCA) or Listen-After-Talk (LBT) process before communication to determine if the channel is available. In some examples, the wireless communication system 100 may include devices (e.g., UEs, etc.) that communicate with one or more UEs 104, base stations 102, APs 150, etc., using ultra-wideband (UWB) spectrum. The UWB spectrum may range from 3.1 GHz to 10.5 GHz.
[0043] Small cell base station 102' can operate in licensed and / or unlicensed spectrum. When operating in unlicensed spectrum, small cell base station 102' can employ LTE or NR technology and use the same 5 GHz unlicensed spectrum as WLAN AP 150. Small cell base station 102' employing LTE and / or 5G in unlicensed spectrum can enhance coverage of the access network and / or increase the capacity of the access network. NR in unlicensed spectrum can be referred to as NR-U. LTE in unlicensed spectrum can be referred to as LTE-U, Licensed Assisted Access (LAA), or MulteFire.
[0044] The wireless communication system 100 may also include a millimeter-wave (mmW) base station 180, which can operate at mmW and / or near-mmW frequencies to communicate with the UE 182. The mmW base station 180 may be implemented in a converged or monolithic base station architecture, or alternatively, in a decomposed base station architecture (e.g., including one or more of a CU, DU, RU, near-RT RIC, or non-RT RIC). Extremely high frequency (EHF) is a portion of the electromagnetic spectrum that contains radio frequency (RF). EHF has a range of 30 GHz to 300 GHz, with wavelengths between 1 mm and 10 mm. Radio waves in this band are referred to as millimeter waves. Near-mmW extends down to frequencies of 3 GHz with wavelengths of 100 mm. Ultra-high frequency (SHF) bands extend between 3 GHz and 30 GHz, and are also referred to as centimeter waves. Communication using mmW and / or near-mmW radio bands has high path loss and relatively short range. mmW base station 180 and UE 182 can utilize beamforming (transmit and / or receive) on mmW communication link 184 to compensate for extremely high path loss and short range. Furthermore, it should be understood that in alternative configurations, one or more base stations 102 may also use mmW or near-mmW and beamforming for transmission. Therefore, it should be understood that the foregoing illustrations are merely examples and should not be construed as limiting the various aspects disclosed herein.
[0045] In some aspects related to 5G, the spectrum operated by wireless network nodes or entities (e.g., base station 102 / 180, UE 104 / 182) is divided into multiple frequency ranges: FR1 (from 450 MHz to 6000 MHz), FR2 (from 24250 MHz to 52600 MHz), FR3 (above 52600 MHz), and FR4 (between FR1 and FR2). In multi-carrier systems such as 5G, one of the carrier frequencies is referred to as the "primary carrier," "anchor carrier," "primary serving cell," or "PCell," and the remaining carrier frequencies are referred to as "secondary carriers," "secondary serving cells," or "SCell." In carrier aggregation, the anchor carrier is the carrier operating on the primary frequency (e.g., FR1) utilized by UE 104 / 182 and the cell, where UE 104 / 182 performs an initial radio resource control (RRC) connection establishment procedure or initiates an RRC connection re-establishment procedure in that cell. The primary carrier carries all common control channels as well as UE-specific control channels and can be a carrier on a licensed frequency (however, this is not always the case). The secondary carrier is a carrier operating on a second frequency (e.g., FR2) that can be configured and used to provide additional radio resources once an RRC connection is established between UE 104 and the anchor carrier. In some cases, the secondary carrier can be a carrier on an unlicensed frequency. The secondary carrier may contain only the necessary signaling information and signals; for example, since the primary uplink and primary downlink carriers are typically UE-specific, those UE-specific signaling information and signals may not be present on the secondary carrier. This means that different UEs 104 / 182 within a cell can have different downlink primary carriers. The same applies to the uplink primary carrier. The network can change the primary carrier of any UE 104 / 182 at any time. This is done, for example, to balance the load on different carriers. Because a “serving cell” (whether PCell or SCell) corresponds to the carrier frequency and / or component carriers through which some base stations are communicating, the terms “cell,” “serving cell,” “component carrier,” “carrier frequency,” etc., can be used interchangeably.
[0046] For example, still refer to Figure 1One of the frequencies used by macro cell base station 102 can be an anchor carrier (or "PCell"), and the other frequencies used by macro cell base station 102 and / or mmW base station 180 can be secondary carriers ("SCell"). In carrier aggregation, each carrier of base station 102 and / or UE 104 can use a spectrum with a bandwidth of up to Y MHz (e.g., 5 MHz, 10 MHz, 15 MHz, 20 MHz, 100 MHz), with up to a total of Yx MHz (x component carriers) for transmission in each direction. Component carriers may or may not be adjacent to each other in the spectrum. Carrier allocation may be asymmetrical with respect to downlink and uplink (e.g., more or fewer carriers may be allocated to downlink compared to uplink). Simultaneous transmission and / or reception on multiple carriers allows UE 104 / 182 to significantly increase its data transmission rate and / or data reception rate. For example, two aggregated 20 MHz carriers in a multi-carrier system would theoretically result in a doubling of the data rate (i.e., 40 MHz) compared to the data rate obtained by a single 20 MHz carrier.
[0047] To operate on multiple carrier frequencies, base station 102 and / or UE 104 may be equipped with multiple receivers and / or transmitters. For example, UE 104 may have two receivers, namely "Receiver 1" and "Receiver 2", where "Receiver 1" is a multi-band receiver that can be tuned to band (i.e., carrier frequency) 'X' or band 'Y', and "Receiver 2" is a single-band receiver that can be tuned to only band 'Z'. In this example, if UE 104 is being served in band 'X', then band 'X' will be referred to as PCell or active carrier frequency, and "Receiver 1" will need to tune from band 'X' to band 'Y' (SCell) to measure band 'Y' (and vice versa). In contrast, regardless of whether UE 104 is being served in band 'X' or band 'Y', due to the separate "Receiver 2", UE 104 can measure band 'Z' without interrupting service on band 'X' or band 'Y'.
[0048] The wireless communication system 100 may also include a UE 164, which can communicate with the macro cell base station 102 on the communication link 120 and / or with the mmW base station 180 on the mmW communication link 184. For example, the macro cell base station 102 may support PCells and one or more SCells for the UE 164, and the mmW base station 180 may support one or more SCells for the UE 164.
[0049] The wireless communication system 100 may also include one or more UEs, such as UE 190, which are indirectly connected to one or more communication networks via one or more device-to-device (D2D) peer-to-peer (P2P) links (referred to as "side links"). Figure 1 In one example, UE 190 has a D2D P2P link 192 with one of UEs 104 connected to one of the base stations 102 (e.g., UE 190 can indirectly obtain cellular connectivity through this D2D P2P link), and has a D2D P2P link 194 with a WLAN STA 152 connected to a WLAN AP 150 (UE 190 can indirectly obtain WLAN-based Internet connectivity through this D2D P2P link). In one example, D2D P2P links 192 and 194 can use any known D2D RAT (such as LTE Direct (LTE-D), Wi-Fi Direct (Wi-Fi-D), Bluetooth). ® (etc.) to support.
[0050] Figure 2 A block diagram of a base station 102 and a UE 104 designed according to some aspects of this disclosure is shown, which enables the transmission and processing of signals exchanged between the UE and the base station. Design 200 includes components of base station 102 and UE 104, which may be... Figure 1 The base station 102 is a base station and the UE 104 is a UE. The base station 102 may be equipped with T antennas 234a to 234t, and the UE 104 may be equipped with R antennas 252a to 252r, wherein typically T≥1 and R≥1.
[0051] At base station 102, transmitting processor 220 can receive data for one or more UEs from data source 212, select one or more modulation and decoding schemes (MCS) for each UE based at least in part on channel quality indicators (CQI) received from the UE, process (e.g., encode and modulate) the data for each UE based at least in part on the MCS selected for the UE, and provide data symbols for all UEs. Transmitting processor 220 can also process system information (e.g., semi-static resource allocation information (SRPI), etc.) and control information (e.g., CQI requests, grants, upper-layer signaling, channel state information, channel state feedback, etc.), and provide overhead symbols and control symbols. Transmitting processor 220 can also generate reference symbols for reference signals (e.g., cell-specific reference signals (CRS)) and synchronization signals (e.g., primary synchronization signal (PSS) and secondary synchronization signal (SSS)). The transmit (TX) multiple-input multiple-output (MIMO) processor 230 can perform spatial processing (e.g., pre-decoding) on data symbols, control symbols, overhead symbols, and / or reference symbols, where applicable, and can provide T output symbol streams to T modulators (MODs) 232a to 232t. The modulators 232a to 232t are shown as combined modulator-demodulators (MOD-DEMODs). In some cases, the modulator and demodulator can be separate components. Each modulator in the modulators 232a to 232t can process a corresponding output symbol stream (e.g., for an orthogonal frequency division multiplexing (OFDM) scheme, etc.) to obtain an output sample stream. Each modulator in the modulators 232a to 232t can further process (e.g., convert to analog, amplify, filter, and up-convert) the output sample stream to obtain a downlink signal. The T downlink signals can be transmitted from the modulators 232a to 232t via T antennas 234a to 234t, respectively. Based on some aspects described in more detail below, position coding can be used to generate synchronization signals to transmit additional information.
[0052] At UE 104, antennas 252a to 252r can receive downlink signals from base station 102 and / or other base stations and can provide the received signals to demodulators (DEMODs) 254a to 254r respectively. Demodulators 254a to 254r are shown as combined modulator-demodulators (MOD-DEMODs). In some cases, the modulator and demodulator can be separate components. Each demodulator in demodulators 254a to 254r can condition (e.g., filter, amplify, down-convert, and digitize) the received signal to obtain an input sample. Each demodulator in demodulators 254a to 254r can further process the input sample (e.g., for OFDM, etc.) to obtain the received symbols. MIMO detector 256 can obtain the received symbols from all R demodulators 254a to 254r, perform MIMO detection on these received symbols where applicable, and provide the detected symbols. The receiver processor 258 can process (e.g., demodulate and decode) the detected symbols, provide the decoded data for UE 104 to the data sink 260, and provide the decoded control information and system information to the controller / processor 280. The channel processor can determine the Reference Signal Received Power (RSRP), Received Signal Strength Indicator (RSSI), Reference Signal Received Quality (RSRQ), and / or Channel Quality Indicator (CQI), etc.
[0053] On the uplink, at UE 104, the transmit processor 264 can receive and process data from data source 262 and control information from controller / processor 280 (e.g., reports including RSRP, RSSI, RSRQ, CQI, channel state information, and / or channel state feedback, etc.). The transmit processor 264 can also generate reference symbols for one or more reference signals (e.g., based at least in part on β values or sets of β values associated with the one or more reference signals). Symbols from the transmit processor 264 can be pre-decoded by the TX MIMO processor 266, further processed by modulators 254a to 254r (e.g., for DFT-s-OFDM and / or CP-OFDM, etc.), and transmitted to base station 102. At base station 102, uplink signals from UE 104 and other UEs can be received by antennas 234a to 234t, processed by demodulators 232a to 232t, detected by MIMO detector 236 where applicable, and further processed by receiver processor 238 to obtain decoded data and control information transmitted by UE 104. Receiver processor 238 can provide the decoded data to data sink 239 and the decoded control information to controller (processor) 240. Base station 102 may include communication unit 244 and communicates with network controller 231 via communication unit 244. Network controller 231 may include communication unit 294, controller / processor 290, and memory 292.
[0054] In some respects, one or more components of UE 104 may be included in the housing. These include the controller 240 of base station 102, the controller / processor 280 of UE 104, and / or... Figure 2 Any other component may perform one or more techniques associated with determining the implicit uplink control information (UCI) beta value for NR.
[0055] Memory 242 and 282 may store data and program code for base station 102 and UE 104, respectively. Scheduler 246 may schedule UE for data transmission on downlink, uplink and / or sidelink.
[0056] In some respects, the deployment of communication systems (such as 5G New Radio (NR) systems) can involve a variety of components or constituent parts. In a 5G NR system or network, network nodes, network entities, network mobility elements, radio access network (RAN) nodes, core network nodes, network elements or network equipment (such as base stations (BS)), or one or more units (or components) performing base station functionality can be implemented in aggregated or decomposed architectures. For example, BSs (such as Node B (NB), evolved NB (eNB), NR BS, 5G NB, access point (AP), transmit / receive point (TRP), or cell, etc.) can be implemented as aggregated base stations (also known as standalone BS or monolithic BS) or decomposed base stations.
[0057] Aggregated base stations can be configured to utilize a radio protocol stack that is physically or logically integrated within a single RAN node. Decentralized base stations can be configured to utilize a protocol stack that is physically or logically distributed across two or more units, such as one or more central or centralized units (CUs), one or more distributed units (DUs), or one or more radio units (RUs). In some aspects, the CU can be implemented within a RAN node, and one or more DUs can be co-located with the CU, or alternatively, can be geographically or virtually distributed across one or more other RAN nodes. DUs can be implemented to communicate with one or more RUs. Each of the CU, DU, and RU can also be implemented as a virtual unit, namely a virtual central unit (VCU), a virtual distributed unit (VDU), or a virtual radio unit (VRU).
[0058] Base station type operation or network design can take into account the aggregation characteristics of base station functionality. For example, decomposed base stations can be utilized in Integrated Access Backhaul (IAB) networks, Open Radio Access Networks (O-RAN (such as network configurations advocated by the O-RAN Alliance)), or Virtualized Radio Access Networks (vRAN, also known as Cloud Radio Access Networks (C-RAN)). Decomposition can include distributing functionality across two or more units in various physical locations, as well as virtually distributing the functionality of at least one unit, which enables flexibility in network design. Individual units in a decomposed base station or decomposed RAN architecture can be configured to communicate wirelessly with at least one other unit.
[0059] Figure 3A diagram illustrating an example of a decomposed base station 300 architecture is shown. The decomposed base station 300 architecture may include one or more central units (CUs) 310, which may communicate directly with the core network 320 via a backhaul link, or indirectly with the core network 320 via one or more decomposed base station units, such as a near real-time (near-RT) RAN Intelligent Controller (RIC) 325 via an E2 link, or a non-real-time (non-RT) RIC 315 associated with a Service Management and Orchestration (SMO) framework 305, or both. CUs 310 may communicate with one or more distributed units (DUs) 330 via corresponding midhaul links (such as F1 interfaces). DUs 330 may communicate with one or more radio units (RUs) 340 via corresponding fronthaul links. RUs 340 may communicate with a corresponding UE 104 via one or more radio frequency (RF) access links. In some implementations, UE 104 may be served simultaneously by multiple RUs 340.
[0060] Each unit in the array (e.g., CU 310, DU 330, RU 340, and near-RT RIC 325, non-RT RIC 315, and SMO frame 305) may include or be coupled to one or more interfaces configured to receive or transmit signals, data, or information (collectively, signals) via wired or wireless transmission media. Each of these units, or an associated processor or controller providing instructions to the communication interfaces of these units, may be configured to communicate with one or more other units via transmission media. For example, these units may include wired interfaces configured to receive signals or transmit signals to one or more other units via wired transmission media. Additionally, these units may include wireless interfaces that may include receivers, transmitters, or transceivers (such as radio frequency (RF) transceivers) configured to receive signals via wireless transmission media or transmit signals to one or more other units, or both.
[0061] In some aspects, the CU 310 can host one or more higher-level control functions. Such control functions may include Radio Resource Control (RRC), Packet Data Convergence Protocol (PDCP), or Service Data Adaptation Protocol (SDAP), etc. Each control function can be implemented using an interface configured to signal to other control functions hosted by the CU 310. The CU 310 can be configured to handle user plane functionality (i.e., Central Unit-User Plane (CU-UP)), control plane functionality (i.e., Central Unit-Control Plane (CU-CP)), or a combination thereof. In some specific implementations, the CU 310 can be logically divided into one or more CU-UP units and one or more CU-CP units. When implemented in an O-RAN configuration, the CU-UP units can communicate bidirectionally with the CU-CP units via an interface such as an E1 interface. The CU 310 can be implemented to communicate with the DU 330 for network control and signaling purposes, as needed.
[0062] DU 330 may correspond to a logical unit that includes one or more base station functions for controlling the operation of one or more RU 340s. In some aspects, DU 330 may at least partially host one or more of the Radio Link Control (RLC) layer, Medium Access Control (MAC) layer, and one or more high physical (PHY) layers (such as modules for forward error correction (FEC) encoding and decoding, scrambling, modulation and demodulation, etc.) according to functional splits (such as those defined by the 3rd Generation Partnership Project (3GPP). In some aspects, DU 330 may further host one or more low PHY layers. Each layer (or module) may be implemented using an interface configured to communicate signals with other layers (and modules) hosted by DU 330 or with control functions hosted by CU 310.
[0063] Lower-layer functionality can be implemented by one or more RU 340s. In some deployments, an RU340 controlled by a DU 330 may correspond to a logical node that hosts RF processing functions or low-PHY layer functions (such as performing Fast Fourier Transform (FFT), Inverse FFT (iFFT), digital beamforming, or Physical Random Access Channel (PRACH) extraction and filtering, or both, at least in part based on functional decomposition (such as lower-layer functional decomposition). In such architectures, the RU 340 may be implemented to handle over-the-air (OTA) communications with one or more UEs 104. In some specific implementations, the real-time and non-real-time aspects of control plane and user plane communications with the RU 340 may be controlled by the corresponding DU 330. In some scenarios, this configuration enables the implementation of the DU 330 and CU 310 in cloud-based RAN architectures such as vRAN architectures.
[0064] The SMO framework 305 can be configured to support RAN deployment and provisioning of both non-virtualized and virtualized network elements. For non-virtualized network elements, the SMO framework 305 can be configured to support the deployment of dedicated physical resources for RAN coverage requirements, which can be managed via operation and maintenance interfaces such as the O1 interface. For virtualized network elements, the SMO framework 305 can be configured to interact with a cloud computing platform such as the Open Cloud (O-Cloud) 390 to perform network element lifecycle management (such as instantiating virtualized network elements) via a cloud computing platform interface such as the O2 interface. Such virtualized network elements may include, but are not limited to, CU 310, DU 330, RU 340, and near-RT RIC 325. In some implementations, the SMO framework 305 can communicate with hardware aspects of the 4G RAN, such as the Open eNB (O-eNB) 311, via the O1 interface. Additionally, in some implementations, the SMO framework 305 can communicate directly with one or more RUs 340 via the O1 interface. SMO framework 305 may also include a non-RT RIC 315 configured to support the functionality of SMO framework 305.
[0065] The non-RT RIC 315 can be configured to include logical functions that enable non-real-time control and optimization of RAN elements and resources, including artificial intelligence / machine learning (AI / ML) workflows for model training and updates, or policy-based guidance for applications / features in the near-RT RIC 325. The non-RT RIC 315 can be coupled to or communicate with the near-RT RIC 325, such as via an A1 interface. The near-RT RIC 325 can be configured to include logical functions that enable near real-time control and optimization of RAN elements and resources via an interface, such as an E2 interface, through data collection and actions, connecting one or more CU 310s, one or more DU 330s, or both, and O-eNBs to the near-RT RIC 325.
[0066] In some implementations, to generate AI / ML models to be deployed in the near-RT RIC 325, the non-RT RIC 315 may receive parameters or external enrichment information from an external server. This information can be utilized by the near-RT RIC 325 and may be received from non-network data sources or network functions at the SMO framework 305 or the non-RT RIC 315. In some examples, the non-RT RIC 315 or near-RT RIC 325 may be configured to tune RAN behavior or performance. For example, the non-RT RIC 315 may monitor long-term trends and patterns in performance and use AI / ML models to perform corrective actions via the SMO framework 305 (such as reconfiguration via O1) or by creating RAN management policies (such as A1 policies).
[0067] Figure 4 An example of a computing system 470 for a wireless device 407 is illustrated. The wireless device 407 may include client devices such as UEs (e.g., UE 104, UE 152, UE 190) or other types of devices usable by an end user (e.g., a station (STA) configured to communicate using a Wi-Fi interface). For example, the wireless device 407 may include a mobile phone, router, tablet computer, laptop computer, tracking device, wearable device (e.g., smartwatch, glasses, extended reality (XR) device (such as virtual reality (VR), augmented reality (AR), or mixed reality (MR) device)), Internet of Things (IoT) device, access point, and / or another device configured to communicate via a wireless communication network. The computing system 470 includes software and hardware components that may be electrically coupled or communicatively coupled (or otherwise communicated, as applicable) via a bus 489. For example, the computing system 470 includes one or more processors 484. One or more processors 484 may include one or more CPUs, ASICs, FPGAs, APs, GPUs, VPUs, NSPs, microcontrollers, special-purpose hardware, any combination thereof, and / or other processing devices or systems. One or more processors 484 may use bus 489 to communicate between cores and / or with one or more memory devices 486.
[0068] The computing system 470 may also include one or more memory devices 486, one or more digital signal processors (DSPs) 482, one or more subscriber identity modules (SIMs) 474, one or more modems 476, one or more wireless transceivers 478, one or more antennas 487, one or more input devices 472 (e.g., camera, mouse, keyboard, touchscreen, touchpad, keypad, microphone and / or the like) and one or more output devices 480 (e.g., display, speaker, printer and / or the like).
[0069] In some aspects, computing system 470 may include one or more RF interfaces configured to transmit and / or receive radio frequency (RF) signals. In some examples, the RF interface may include components such as modem 476, wireless transceiver 478, and / or antenna 487. One or more wireless transceivers 478 may transmit and receive wireless signals (e.g., signal 488) from one or more other devices via antenna 487, such as other wireless devices, network devices (e.g., base stations such as eNBs and / or gNBs, Wi-Fi access points (APs) such as routers or range extenders, etc.), and / or cloud networks, etc. In some examples, computing system 470 may include multiple antennas or antenna arrays that facilitate simultaneous transmission and reception functionality. Antenna 487 may be an omnidirectional antenna, such that radio frequency (RF) signals can be received from and transmitted in all directions. Wireless signal 488 may be transmitted via a wireless network. The wireless network may be any wireless network, such as cellular or telecommunications networks (e.g., 3G, 4G, 5G, etc.), wireless local area networks (e.g., WiFi networks), Bluetooth™ networks, and / or other networks.
[0070] In some examples, wireless signal 488 can be transmitted directly to other wireless devices using sidelink communication (e.g., using a PC5 interface, using a DSRC interface, etc.). Wireless transceiver 478 can be configured to transmit RF signals via antenna 487 for performing sidelink communication according to one or more transmit power parameters that can be associated with one or more regulated modes. Wireless transceiver 478 can also be configured to receive sidelink communication signals with different signal parameters from other wireless devices.
[0071] In some examples, one or more wireless transceivers 478 may include an RF front end, which includes one or more components such as amplifiers, a mixer for down-converting signals (also called a signal multiplier), a frequency synthesizer (also called an oscillator) that supplies signals to the mixer, a baseband filter, an analog-to-digital converter (ADC), one or more power amplifiers, and other components. The RF front end typically handles the selection of wireless signals 488 and the conversion of wireless signals to baseband frequencies or intermediate frequencies, and can convert RF signals to the digital domain.
[0072] In some cases, computing system 470 may include a decoder-decoder device (or codec) configured to encode and / or decode data transmitted and / or received using one or more wireless transceivers 478. In some cases, computing system 470 may include an encryption-decryption device or component configured (e.g., according to AES and / or DES standards) to encrypt and / or decrypt data transmitted and / or received by one or more wireless transceivers 478.
[0073] One or more SIMs 474 may each securely store an International Mobile Subscriber Identity (IMSI) number and associated key assigned to a user of a wireless device 407. The IMSI and key can be used to identify and authenticate the subscriber when accessing a network provided by a network service provider or operator associated with one or more SIMs 474. One or more modems 476 may modulate one or more signals to encode information to be transmitted using one or more wireless transceivers 478. One or more modems 476 may also demodulate signals received by one or more wireless transceivers 478 to decode the transmitted information. In some examples, one or more modems 476 may include a Wi-Fi modem, a 4G (or LTE) modem, a 5G (or NR) modem, and / or other types of modems. One or more modems 476 and one or more wireless transceivers 478 may be used to transmit data from one or more SIMs 474.
[0074] The computing system 470 may also include one or more non-transitory machine-readable storage media or storage devices (e.g., one or more memory devices 486) (and / or communicate with them), which may include, but are not limited to, local and / or network-accessible storage devices, disk drives, drive arrays, optical storage devices, solid-state storage devices (such as RAM and / or ROM), which may be programmable and / or flash-updatable, etc. Such storage devices may be configured to implement any suitable data storage, including but not limited to various file systems and / or database structures, etc.
[0075] In various embodiments, functionality may be stored as one or more computer program products (e.g., instructions or code) in memory device 486 and executed by one or more processors 484 and / or one or more DSPs 482. Computing system 470 may also include software elements (e.g., residing within one or more memory devices 486) including, for example, operating systems, device drivers, executable libraries, and / or other code, such as one or more application programs, which may include computer programs implementing the functionality provided by the various embodiments and / or may be designed to implement methods and / or configure systems as described herein.
[0076] In some previous wireless systems, multiple security contexts existed on a layer-by-layer basis, and multiple services could coexist with a single security context. For example, a security context (e.g., a Non-Access Layer (NAS) security context between the mobile device (such as the UE) and the core network could be established, which is the result of an authentication process used to establish cryptographically secure communication between the two elements. This NAS security context can anchor other security contexts, as other security contexts can be established on top of the NAS security context. Another security context (e.g., an Access Layer (AS) security context) can also be established via the AMF based on the NAS security context. Additional application-specific security contexts can then be established via a connection through the AS security context. In some cases, separating the security context from the NAS security context can be useful, so that additional security contexts on the NAS are not entirely dependent on the connection between the mobile device and the AMF. Additionally, having a separate security context for services can simplify the implementation of additional services without having to ensure that the AMF supports any security features of the additional services.
[0077] Figure 5 This is a diagram illustrating the security architecture of a wireless system 500 according to various aspects of this disclosure. In some cases, defining a per-service security context may be useful, for example, allowing services to customize security between mobile devices and services without explicit support from the wireless system 500. The wireless system 500 includes a device 502, which may be a UE. The device 502 may be coupled to the wireless system 500 via a DU 504. In some cases, the connection between the device 502 and the DU 504 may be protected based on physical layer and / or media access control layer security 508. Although in Figure 5 The diagram shows a disassembled base station 506, but it is understood that any base station / access node design can be used, such as eNodeB, gNodeB, aggregated / monolithic base station, Wi-Fi access point, etc.
[0078] In some cases, per-service security contexts allow device 502 to establish security contexts with specific services being used by device 502, including services previously classified as core network services, such as mobility service 512, transport service 510, etc. In some cases, the services of wireless system 500 can be divided into different types of services. For example, basic and frequently used services of wireless system 500 (e.g., services similar to those traditionally provided by the core network of the wireless system, such as routing device 502 from and handing it over to the base station) may be referred to as horizontal services 520, as described here... Figure 5The lower part is shown. For example, transport service 510, mobility service 512, security service 514, policy service 516, security context storage service 518, paging service (not shown), etc., can be considered horizontal services 520. More user-oriented (e.g., user-plane applications) and more user-specific higher-level services can be referred to as vertical services 524. Examples of vertical services 524 include location service 528, voice service 530, edge service 532, XR service 534, Internet service 536, etc.
[0079] In some cases, the User Plane Security Anchor (UPSA) 526 service can provide general transport security between device 502 and vertical service 524. For example, UPSA 526 can extend the functionality provided by the Packet Data Convergence Protocol Layer (PDCP) of the 5G NR radio system and can be used to anchor (e.g., terminate) user plane security and / or access layer security for vertical service 524 for radio system 500. In some cases, UPSA 526 can support multiple services. In some cases, the location of UPSA 526 in the network (e.g., near the edge of the network or closer to the core network) can be flexible and can vary based on, for example, what services radio system 500 and the device can support or provide. For example, UPSA 526 can be co-located at DU 504, located within cloud services (e.g., user plane functions), or positioned closer to the supported vertical service 524 (e.g., co-located with vertical service 524), etc. As an example, if UPSA 526 is co-located at DU 504 and terminates user plane security at DU 504, then if device 502 is mobile and moves to another DU / gNodeB / eNodeB, UPSA 526 can be modified (and the associated service security key can be modified). This may not be an issue for services with fewer mobile devices (such as IoT devices), but it may be an issue for more mobile devices. In some cases, for example, depending on the capabilities and / or requirements of the supported services, the network security requirements and / or policies, and / or the location of the termination point of transport service 510, multiple UPSA 526s may be used. In some cases, transport service 510 can control UPSA 526 and can update transport service 510 with the location of UPSA 526. Transport service 510 can then derive certain service security keys and / or provide certain service security keys to certain UPSA 526s based on, for example, the relative location of UPSA 526 with respect to the services being accessed. In some cases, UPSA 526 can be implemented as a service, and a service security context can be established between device 502 and UPSA 526 for user plane service security.
[0080] In some cases, device 502 may include multiple security contexts 522, each established using a specific service in use. For example, device 502 may have a first security context 540 with security service 514, and device 502 may also have a second security context 538 with location service 528. In some cases, security service 514 may provide security services and other network functions to device 502. For example, security service 514 may help establish security contexts between other services and device 502 (e.g., establish authentication keys). In some cases, these security contexts may then be stored in a security context storage service 518. Other services can then access the security context storage service 518 to retrieve the stored security contexts. Thus, security service 514 may anchor the secure establishment between device 502 and the services of wireless system 500. As an example, a service (such as mobility service 512) may request a security context from security service 514. Security service 514 may respond with a security key to mobility service 512, and the security key may be stored in security context storage service 518 for later use by mobility service 512 as needed.
[0081] In some cases, some services previously associated with radio nodes (e.g., gNodeB, DU, CU, RU, etc.) can also be implemented as one or more horizontal services. For example, radio resource management previously performed by the CU / gNodeB can be implemented as a service in the cloud (e.g., horizontal service 520).
[0082] Figure 6 This is a tree diagram illustrating a key hierarchy structure 600 for services used in a wireless system (such as wireless system 500) according to various aspects of this disclosure. In some cases, as part of establishing a connection with the wireless system, devices (such as...) Figure 5 Device 502) can perform master authentication and work with security services (such as...) Figure 5 Security Service 514) Agree on the cryptographic key K SECSVC 602 (e.g., root key). For example, a device may perform an authentication and key management (AKA) process with a security service and generate a root key. In some cases, additional cryptographic keys for other services provided by the wireless system can be derived based on the root key. For example, a security service may use the root key K... SECSVC 602 is used to derive the service key (e.g., K) for vertical services. V-SVC1 -K V-SVCn 604. Security services can also be based on the root key K. SECSVC 602 is used to derive service keys (e.g., K) for some horizontal services. H-SVC1 -K H-SVCk604. Then, communication between the device and vertical services and / or certain horizontal services can be based on service keys (e.g., without going through a security service unless a new service key is required), and security can be established directly between the device and the corresponding service without continuous reliance on the security service or other services. In some cases, multiple root keys can be established based on a successful authentication and key negotiation process. Each root key can correspond to a different network, and the network can be any type of network, such as a home network, a visited network, a logical network, a physical network, any combination thereof, etc. A network-specific root key can be derived from the root key established between the device and the home network.
[0083] In some cases, it can also be based on the root key K SECSVC 602 is used to export the DU service key K for use between the DU 620 and the device. DU 608. In some cases, the DU 620 can be considered another service of the wireless system. In some cases, the DU 620 can host other services, such as MAC security and / or PHY security. The DU 620 can establish a DU-specific key hierarchy for services hosted by the DU 620 to protect communications with the device. MAC security, PHY security, or both can be configured by the DU 620 and can be obtained from the DU service key K. DU 608 Export the key K used for MAC encryption MACEnc 610 and the key K for MAC integrity MACInt 612. In some cases, the PHY security key can be exported in a manner similar to that used for exporting MAC security keys.
[0084] Figure 7 This is a call flowchart illustrating a technique 700 for secure access to services on a wireless system according to various aspects of this disclosure. Figure 7 The wireless system illustrated includes device 702, DU 704, service 706, security service 708, and security context store 710. Device 702 can be substantially similar to... Figure 5 The equipment 502, DU 704 can be basically similar to Figure 5 DU 504, Service 706 can be any horizontal or vertical service other than Security Service 708 and Security Context Storage Service 710, and Security Service 708 can be substantially similar to Figure 5 Security service 514, and security context storage 710 can be essentially similar to Figure 5 Security context storage service 518.
[0085] In some cases, when device 702 attempts to establish a connection with a service of the wireless system, device 702 may send an initial service access request 722 to security service 708. In some cases, the initial service access request 722 may not be protected because a security context has not yet been established between device 702 and security service 708. If device 702 has previously established a security context with security service 708 and wants to re-authenticate (e.g., after exiting idle mode, re-registering, etc.), device 702 may send a protected service access request 724 to establish a security context with one or more services of the wireless system. The protected service access request 724 can be transmitted using the security context previously established between device 702 and security service 708, and is therefore protected. In some cases, because the protected service access request 724 is protected, it may include additional parameters and / or data compared to the initial service access request 722. For example, the protected service access request 724 may include an indication of the requested service, a subscription identifier, etc.
[0086] Upon receiving an initial service access request 722 from device 702, device 702 and security service 708 may use, for example, an authentication and key negotiation protocol to perform an authentication and key negotiation process 726 to generate a session root key between device 702 and security service 708. Upon receiving the initial service access request 722 or a protected service access request 724, security service 708 may perform the authentication and key negotiation process 726. In some cases, the authentication and key negotiation process 726 may use a long-term credential type authentication and key negotiation protocol, such as 6G AKA, Extensible Authentication Protocol Method for Third Generation Authentication and Key Negotiation (EAP-AKA), etc. The session root key may be stored 728 in a security context store 710. As indicated above, the security context store 710 may be implemented as a service and separate from security service 708. The security context store 710 may not be exposed to other services and / or device 702 (e.g., it may not be visible to other services and / or device 702). In some cases, the security context store 710 can be accessed through the security service 708, for example, by requesting the stored service key.
[0087] In some cases, the session root key can be used to establish a primary security context 730 between device 702 and security service 708 (e.g., to perform a security context establishment procedure). The establishment of the primary security context 730 can be performed using a service establishment protocol such as the NAS security mode command procedure, the Transport Layer Security (TLS) service establishment protocol, etc. Once the primary security context 730 is established, further communication between device 702 and the wireless service can be based on the primary security context. In the case where device 702 sends an initial service access request 722, device 702 can, after establishing the primary security context 730, send a service access request 732 requesting access to one or more services of the wireless system in a manner substantially similar to the protected service access request 724.
[0088] In some cases, security service 708 may perform an authorization check 734 to determine, based on subscription and / or policy information 712, what access device 702 may have to service 706 of the wireless system. If device 702 is authorized to access the requested service, security service 708 may send service key information 736 to device 702. In some cases, the service key information may include information for deriving a service key for the service. In some cases, security service 708 may derive the service key based on a received service access request. In other cases, for example, if device 702 has previously accessed service 706, security service 708 may retrieve the service key from storage (such as security context storage 710). Security service 708 may transmit service key information for deriving a service key for the service because the service key can be derived based on information possessed by device 702 (such as a session root key) and parameters (such as a service identifier). Since device 702 possesses a session root key, security service 708 may provide parameters to device 702. The device can then derive the service key. In some cases, service key information may include a service access token. The service access token may be transmitted along with information used to derive the service key, or it may be transmitted in place of that information. As an example, security service 708 may generate a service access token based on the session root key and send the service access token 736 to device 702. Device 702 can obtain the service access token by decoding sender 736 using the session root key stored on device 702. In cases where a service access request requests access to multiple services, service key information for multiple services may be provided to device 702. In some cases, each service access token may correspond to a specific service of the wireless system, such as service 706.
[0089] Device 702 may send a 738 Service Access Request to the service 706 that it is attempting to access. In some cases, the service access request may be protected (e.g., encoded) based on a derived service access key. In some cases, the service access request may include a temporary identifier of device 702, such as a Globally Unique Temporary Identifier (GUTI). This temporary identifier may be insecure. In some cases, the service access request may include a service access token for service 706. Service 706 may then send a 740 Service Key Request and provide any service-specific service security policies to security service 708. In some cases, the service key request may include the service identifier and / or a temporary identifier of device 702. Security service 708 may then respond by sending a 742 Service Key Response to service 706. In some cases, security service 708 may also send a 742 UE Security Capability Information to service 706. Service 706 may use the service key from security service 708 to decrypt the 738 service access request sent from device 702. If the service access request includes a service access token, then service 706 can obtain the service access token.
[0090] In some cases, a service access token can be defined such that the service of the wireless system can determine that the service access token originates from security service 708. Service 706 can verify that the service access token was created by security service 708. The service access token can indicate that device 702 is authorized to access service 706, and based on the verification that the service access token was created by the security service, service 706 may not need to utilize subscription and / or policy information 712 to perform another authorization check. The service access token can be bound to the device's identifier, which can be a subscription identifier, service-specific identifier, etc. Additionally, since service 706 can determine that device 702 is authorized based on the service access token, service 706 may not need to obtain information from device 702 (such as the device 702's permanent identifier) to perform authorization checks. Service 706 can then establish a service-specific security context 744 with device 702 based on the service key.
[0091] Figure 8 This is a call flow diagram illustrating a technology 800 for secure access for roaming according to various aspects of this disclosure. Figure 8 This includes device 802, a second security service 804 for the roaming wireless system, a first security service 806 for the home wireless system, and a security context store 808. Device 802 can be substantially similar to... Figure 5 Equipment 502 and Figure 7 Device 702, first security service 806 and second security service 804 can be substantially similar to Figure 5 Security Service 514 and Figure 7Security service 708, and security context store 808 can be basically similar to Figure 5 Security context storage service 518 and Figure 7 Security context storage service 710.
[0092] In some cases, device 802 can be configured to typically connect to a home wireless system, but it can also roam to other wireless systems, such as roaming wireless systems. Figure 8 In this process, device 802 can perform authentication and key negotiation procedures 812, store the session root key 814, and perform a security context establishment procedure 816 in accordance with the above description. Figure 7 The discussed method establishes a home security context 818 with the first security service 806 of the home wireless system (e.g., with the security context of the home wireless system).
[0093] In some cases, device 802 may roam to another wireless system, such as a roaming wireless system. In some cases, the security services of the home wireless system and the roaming wireless system may be separate, and the UE may interact with these wireless systems independently to establish security contexts with different wireless systems. In some cases, when roaming, it may be useful to establish a security context with the roaming wireless system based on the security context from the home wireless system (e.g., based on the session root key), rather than establishing a completely new security context with the roaming wireless system. Establishing a security context for the roaming wireless system based on the security context of the home wireless system helps allow device 802 to maintain a secure connection to the home security context 818 and allows security service transactions 828 of the home wireless system to be performed while roaming on the roaming wireless system. This also helps to provide secure access to services on the home network that may not be available on the roaming network. Additionally, device 802 will be able to securely access services on the home network without having to rely on the security services of the roaming network. In some cases, the roaming network can be handled in a manner similar to that of services, and the establishment of a security context with the roaming network can be performed in a manner similar to that of establishing a security context with a service.
[0094] In some cases, the second security service 804 of a roaming wireless system can be regarded as another service by the first security service 806 of a home wireless system. For example, if device 802 roams to a roaming wireless system and attempts to establish a security context with the second security service 804 (e.g., via an initial service access request or a protected service access request (not shown)), device 802 can similarly send... Figure 7The service access request 732 is transmitted to the first security service 806 to request roaming services (not shown). The first security service 806 can provide service key information for accessing security services (such as the second security service 804). For example, the first security service 806 can provide service key information (which may include a service access token) for use in a similar manner. Figure 7 The device 802 accesses the second security service 804 by sending service key information (736). Alternatively, the first security service 806 may provide additional information for accessing the second wireless system. Based on this additional information and / or service access tokens, the device 802 may, similarly... Figure 7 The system sends a 738 service access request to attempt to access the second security service 804 of the second wireless system.
[0095] In response to a service access request, the second security service 804 may be similar to Figure 7 The system requests a service key from the first security service 806 of the home wireless system by sending a 740 service key request. In some cases, authentication can be network-initiated, and the security service at the home wireless system or roaming wireless system can trigger the authentication process. The first security service 806 of the home wireless system can generate a service key and, in a manner similar to... Figure 7 The service key is sent to the second security service 804 via the method of sending the service key response 742.
[0096] The second security service 804 can receive and use the service key as if it were the root key used by the second security service 804. The second security service 804 and device 802 can then proceed as described above regarding... Figure 7 The discussed method performs a security context establishment process 822 to establish a roaming (e.g., access) security context 824 (e.g., a security context with a roaming (e.g., access) wireless system) with a second security service 804. Device 802 can then perform a roaming security service transaction 826 with the second security service 804 of the roaming wireless system via the roaming security context 824, and separately perform a home security service transaction with the first security service 806 of the home wireless system via the home security context 818. Therefore, independent protection can be provided for security service transactions of the home wireless system and the roaming wireless system.
[0097] In some cases, because a device can utilize multiple services with per-service security contexts, it can be associated with multiple service security contexts. To help distinguish service security contexts and to help locate them at the service, each service security context can be associated with a security context identifier (ID). In some cases, the security context ID can be a globally unique temporary identifier (GUTI). This security context ID can be included in service requests to the service. The service can then use the security context ID to retrieve the corresponding security context for the device. In some cases, similar to GUTI reassignment, for privacy reasons, the security context ID can be refreshed periodically / semi-periodically / on demand.
[0098] In some cases, a service (e.g., a security service and / or other services) may generate a security context cookie during the service security context establishment process. This security context cookie may be represented as a binary block that can be interpreted by the service but not by other services or the UE. Additionally, the UE or other services may not be able to change the context of the security context cookie without rendering it unavailable / invalid (e.g., via signature, hash, etc.). In some cases, the security context cookie may include any information that can be used by the service / (e.g., retrieved from security context storage) when the device is using the service (e.g., information about the security context, security context ID, security key, subscription / policy information, etc.). As part of the service security context establishment process, the service may provide the security context cookie to the device. The device may store the security context cookie and then provide it the next time the device attempts to access the service. The service can use the information from the security context cookie to restore the service security context with the device. Providing the security context cookie to the device helps minimize the amount of context storage and / or security context management performed by the service.
[0099] Figure 9 This is an example call flow diagram illustrating the technology 900 for establishing user plane service security according to various aspects of this disclosure. Figure 9 This includes device 902, transmission service 904, UPSA 906, user plane service 908, security service 910, and security context storage 912. Device 902 can be substantially similar to... Figure 5 Equipment 502 Figure 7 Equipment 702 and Figure 8 Device 802. Transmission service 904 can be essentially similar to... Figure 5 The transport service 510. Service 908 can be a user plane service, such as... Figure 5Services 528-536. Security service 910 is basically similar to... Figure 5 Security Service 514 and Figure 7 Security service 708. Security context storage 912 can be basically similar to Figure 5 Security context storage service 518 Figure 7 Security context storage service 710 and Figure 8 Security context storage service 808.
[0100] In some cases, when device 902 attempts to establish a connection with the user plane service of a wireless system, device 902 may send a service access request 916 to the wireless network service 908. In some cases, the service access request 916 may include a service access token (e.g., if device 902 previously established a security context with security service 910 and obtained a service access token). In other cases, the service access request may include a temporary identifier of device 902, such as the globally unique temporary identifier (GUTI) of device 902 attempting to access service 908. In some cases, the service access request 916 may be similar to... Figure 7 The service access request 938 sent by the service provider. Based on the received service access request 916, the service can send a service key request 918 and provide any service-specific service security policy to the security service 910. The service key request can be substantially similar to... Figure 7 Send a service key request for 740.
[0101] Service security policies can indicate which security measures can be used, such as whether UPSA security should be used. Service security policies can also indicate where UPSA 906 for Service 908 should be located. When Service 908 is associated with relatively highly mobile devices, UPSA 906 may be located deeper within the radio system (e.g., near the core network / user plane service, etc.) rather than near the edge of the radio system (e.g., near gNodeB / eNodeB / DU / CU / RU, etc.) to help avoid frequent key changes due to mobility. When Service 908 is associated with relatively low-mobility devices, or if latency is particularly important for the service, UPSA 906 may be located closer to the edge of the radio system rather than deeper within it.
[0102] If device 902 has not previously established a security context with service 908 or is performing a re-authentication process, device 902 and security service 910 may use, for example, authentication and key negotiation protocols to perform authentication and key negotiation process 920, in accordance with the provisions above. Figure 7The session root key between device 902 and security service 910 is generated in a similar manner to that described above. In some cases, the authentication and key negotiation process 920 may use long-term credential type authentication and key negotiation protocols, such as 6G AKA, Extensible Authentication Protocol Method for Third Generation Authentication and Key Negotiation (EAP-AKA), etc. The session root key may be stored 922 in security context storage 912. Device 902 and security service 910 can then establish 924 a security context. In some cases, security service 910 may provide device 902 with one or more service access tokens, as described above. Figure 7 The discussion focuses on the following: In some cases, if a security context has been previously established with the security service 910 (e.g., where a valid access token is provided along with the service access request 916), the authentication and key negotiation process 920, the storage of the session root key 922, and the establishment of the security context 924 with the security service 910 can be skipped.
[0103] After establishing a security context with security service 910, in response to a service key request (918) sent from service 908, security service 910 may send a service key response (926) to service 908, which includes a service key derived from the session root key. Service 908 can then establish a service-specific security context (928) with device 902 based on the service key. In some cases, such as as part of establishing the service-specific security context (928), service 908 may send a service security policy to device 902. In some cases, the service security policy may indicate that UPSA security is available for service 908.
[0104] In some cases, service 908 can also establish a user plane security context based on a service security policy. To establish a user plane security context, service 908 can send a 930 UPSA configuration request to transport service 904. In some cases, the UPSA configuration request may include the identifier of device 902 (e.g., GUTI, other public identifiers, temporary identifiers of device 902 used by service 908, etc.), a service identifier (e.g., an identifier associated with the service), and a service security policy. The security policy may indicate where UPSA 906 can be located. The UPSA configuration request may instruct transport service 904 to assist in establishing a user plane security-protected channel with UPSA 906. Transport service 904 may select UPSA 906 based on the service security policy. Transport service 904 may respond to the UPSA configuration request by sending a 932 UPSA configuration response back to service 908. The UPSA configuration response may include the identifier of the selected UPSA 906 (e.g., a UPSA termination point identifier) and UPSA activation status information. UPSA activation status information can indicate whether user plane security has been established (e.g., activated) between service 908 and device 902 (e.g., through another service, such as UPSA 906 for sharing among multiple services). The service can then send a 934 UPSA security configuration request to security service 910 to obtain a UPSA key to configure user plane security. The UPSA security configuration request may include a device identifier, a UPSA identifier, UPSA activation status information, and a user plane security policy. In some cases, the user plane security policy may include information about user plane encryption, user plane integrity protection, or any combination thereof. In some cases, the user plane security policy may be obtained based on the service security policy. In other cases, the user plane security policy may be obtained by security service 910 from a subscription and / or policy service 914 accessible to security service 910. In some cases, security service 910 may determine (e.g., based on the user plane security policy and UPSA activation status information) whether user plane security should be activated, or if it has been activated, whether a new key for user plane security should be issued. If security service 910 determines that a new key does not need to be issued, the security service may allow the user plane security context between device 902 and UPSA 906 to continue using the existing key. If security service 910 determines that a new key should be issued, the security service may derive a new UPSA key.
[0105] Based on the received UPSA security configuration request (e.g., UPSA ID), security service 910 can derive 936 UPSA key K that can be used to establish (or refresh) the user plane security context. UPSA In some cases, it is possible to obtain the session root key (e.g., K). SECSVC602) and the UPSA identifier derive the UPSA key K UPSA (For example, Figure 6 K UPSA 614), as mentioned above regarding Figure 6 As described. In some cases, key derivation functions and session root keys (e.g., K) can be used. SECSVC 602) Derive the UPSA key K from the UPSA identifier, service identifier, and freshness parameter. UPSA The UPSA identifier can be any identifier from UPSA 906, such as an identifier number, IP address, etc. Similarly, the service identifier can be any identifier from service 908. In some cases, the freshness parameter can be a random number. The freshness parameter can be selected, for example, by security service 910, and the freshness parameter can be indicated to device 902 by UPSA 906 during UPSA user plane security establishment 940.
[0106] Then, Security Service 910 can transmit the device identifier and UPSA key K. UPSA The user plane security policy and service identifier are sent to UPSA 938 906. In some cases, such as if user plane security has already been established, the UPSA key K can be omitted. UPSA Because UPSA 906 and device 902 already have UPSA key K UPSA In some cases, user-plane security policies may be included because UPSA 906 can support different types of security (e.g., privacy, integrity protection, etc.), and different services can use different types of security. In other cases, user-plane security policies can be omitted; for example, if a service uses the default type of security, then UPSA 906 only supports a single type of security. This is based on the device identifier and the UPSA key K. UPSA With service identifiers, UPSA 906 and device 902 can establish a user plane security context (940) according to a service security policy. In some cases, the security context between UPSA 906 and device 902 can be established in a manner similar to establishing a security context between device 902 and service 908 (928). Access to service 908 via UPSA 906 and transport service 904 (942) can then be performed. In some cases, during service security establishment (928), device 902 can receive a service security policy from service 908. The service security policy may include UPSA configuration information indicating whether the device can establish user plane security with UPSA.
[0107] Figure 10 This is an example of a call flow diagram illustrating alternative technology 900 for establishing user plane service security according to various aspects of this disclosure. Figure 10 Including with Figure 9 Similar components include device 1002, transport service 1004, UPSA 1006, user plane service 1008, security service 1010, and security context storage 1012. Components with similar names can be substantially similar to those described above. Figure 9 The components discussed. Figure 10 In this process, device 1002 can send service access request 1016 to service 1008, and in response, the service will communicate with the relevant parties regarding... Figure 9 The method discussed is essentially the same as sending a 1018 service key request to security service 1010. If needed, this can be compared with the above discussion. Figure 9 The authentication and key negotiation process 1020, storage of the obtained session root key 1022, establishment of a security context with the security service 1010 1024, sending a service key response 926, and establishment of a service security context 1028 are all performed in the same manner.
[0108] After (or concurrently with) establishing a service-specific security context 1028 between device 1002 and service 1008, security service 1010 can prepare the UPSA key K for establishing the user plane security context. UPSA In this example, security service 1010 can send a 1030 UPSA configuration request to transport service 1004. In some cases, a UPSA configuration request can be substantially similar to the above description. Figure 9 The UPSA configuration request discussed above. In response, Transport Service 1004 can be found in the above section regarding... Figure 9 The method discussed is essentially the same as sending the UPSA configuration response 1032 back to Security Service 1008.
[0109] In some cases, the UPSA configuration response may indicate that a user plane security context has not yet been established between UPSA 1006 and device 1002, and therefore a UPSA key is required. Based on the UPSA security configuration response (e.g., UPSA ID) received from transport service 1004, security service 1010 can derive 1034 a UPSA key K that can be used to establish the user plane security context. UPSA In some cases, the UPSA key K can be derived from the session root key. UPSA As mentioned above Figure 6 As described. Then, security service 1010 can transmit the device identifier, UPSA key K UPSAThe user plane security policy and service identifier are sent to UPSA 1006 via 1036. In some cases, the user plane security policy can be obtained based on the service security policy. In other cases, the user plane security policy can be obtained by security service 1010 from subscription and / or policy service 1014 accessible to security service 1010. As discussed above, in some cases, the UPSA key K can be omitted. UPSA and / or user plane security policies. Based on device identifier, UPSA key K UPSA With service identifiers, UPSA 1006 and device 1002 can establish a user plane security context (1038) according to user plane security policies. In some cases, the security context between UPSA 1006 and device 1002 can be established in a manner similar to establishing a security context (1028) between device 1002 and service 1008. Access to service 1008 via UPSA 1006 and transport service 1004 can then be performed (1040). Therefore, in Figure 10 In this context, the establishment of the user plane security context is primarily guided by security service 1010, while... Figure 9 In this process, Service 908 guides the establishment of the user-plane security context.
[0110] In some cases, Access Layer (AS) security can be used to protect the connection between a device and a wireless node (such as DU / CU / RU / eNodeB / gNodeB / etc.) of the wireless system connected to it. AS can refer to the functional layer of the wireless system, which includes the radio interface that connects the device to the wireless system. AS security can refer to the protocol at the AS layer, which is used to encrypt / decrypt messages between the device and the wireless system via the radio interface. In some cases, AS security can be applied in addition to other over-the-air security measures that can be applied (e.g., at other protocol layers). In some cases, whether AS security is applied can be determined by the service the device is accessing. For example, the device may access a service that can enable AS security between the device and the wireless node based on a service security policy, rather than user plane security. As another example, another service may enable both AS security and user plane security based on a different service security policy.
[0111] Figure 11 This is an example call flowchart illustrating various aspects of this disclosure for establishing a service security call 1100, including AS security. Figure 11 This includes device 1102, DU 1104, mobility service 1106, service 1108, security service 1110, and security context storage 1112. Device 1102 can be substantially similar to... Figure 5 Equipment 502 Figure 7 Equipment 702 Figure 8Equipment 802 Figure 9 Equipment 902 and Figure 10 Device 1002. DU 1104 can be a disassembled base station (such as...) Figure 1 and Figure 2 BS102 and Figure 3 This is part of DU 330, but it is understood that DU can be any wireless node of a wireless system to which device 1102 can connect, such as CU / DU / RU / gNodeB / etc. Service 1108 can be any horizontal or vertical service other than mobility service 1106 or security service 1110. Security service 1110 can be substantially similar to Figure 5 Security Service 514 Figure 7 Security Service 708 Figure 9 Security Service 910 and Figure 10 Security service 1010. Security context storage 1112 can be basically similar to Figure 5 Security context storage service 518 Figure 7 Security context storage service 710 Figure 8 Security Context Storage Service 808 Figure 9 Security context storage service 912 and Figure 10 Security context storage service 1012.
[0112] exist Figure 11 In this context, device 1102 can be used in a manner substantially similar to... Figure 9 The device 1102 attempts to access service 1108 by sending service access request 1114 to service 1108 via service access request 916. Device 1102 can forward service access request 1114 to DU 1104, and DU 1104 can forward service access request 1114 to service 1108. In some cases, DU 1104 can also send service 1108 an indication of the current AS security activation state 1116 and an identifier of DU 1104. The indication of the current AS security activation state 1116 can indicate whether AS security is currently activated between DU 1104 and device 1102 (e.g., activated by another service). Service 1108 can determine that AS security should be used for service 1108 (assuming AS security is not already enabled). Based on the determination that AS security should be used, service 1108 can send service key request 1118 along with service-specific service security policies, AS security activation state information, and DU identifier to security service 1110.
[0113] If device 1102 has not previously established a security context with service 1108 or is performing a re-authentication process, device 1102 and security service 1110 can use, for example, an authentication and key negotiation protocol to perform an authentication and key negotiation process 1120 to generate a session root key between device 1102 and security service 1110. This session root key can be stored 1122 in security context storage 1112, and device 1102 and security service 1110 can communicate with the above-mentioned... Figure 7 and Figure 9 The security context 1124 is established in a similar manner to that described above. In some cases, security service 1110 may provide device 1102 with one or more service access tokens, as described above. Figure 7 The above discussion. In some cases, if a security context has been previously established with security service 1110 (e.g., where a valid access token is provided along with service access request 1114), the authentication and key negotiation process 1120, the storage of the session root key 1122, and the establishment of the security context 1124 with security service 1110 can be skipped. Figure 7 The manner in which the 742 service key response is sent and the 744 service security context is established is substantially similar to the manner in which the 1126 service key response is sent and the 1128 service security context is established.
[0114] When using AS security, service 1108 can transmit mobility service registration 1130 to the mobility service to register device 1102 with mobility service 1106 based on the service security policy. Mobility service registration 1130 may include the identifier of device 1102 and the identifier of service 1108. Mobility service 1106 can trigger an additional key export when a mobility event occurs while device 1102 is moving, as described below. Figure 12 The subject of discussion.
[0115] In some cases, based on the service security policy and AS security activation status information received from service 1108 in service key request 1118, security service 1110 can determine whether a new key should be issued for existing AS security. If security service 1110 determines that a new key does not need to be issued, the security service can allow the AS security context between device 1102 and DU 1104 to continue using the existing key. If security service 1110 determines that a new key should be issued, security service 1110 can derive a new AS key.
[0116] In some cases, security service 1110 can derive AS key K 1132 based on the service security policy and AS security activation status information received from service 1108 in service key request 1118. DUThe AS key K DU This can be used to establish (or refresh) the AS security context between device 1102 and DU 1104. In some cases, this is related to the above regarding... Figure 6 Similar methods to those described can be based at least on the session root key (e.g., K). SECSVC 602), DU identifier, service identifier, another parameter, or any combination thereof to derive AS key K DU (For example, Figure 6 K DU 608). In some cases, key derivation functions and session root keys (e.g., K) can be used. SECSVC 602), DU identifier, service identifier, freshness parameter, additional parameters, or any combination thereof to derive AS key K DU The DU identifier can be any identifier of DU 1104, such as an identifier number, IP address, etc. Similarly, the service identifier can be any identifier of service 1108. In some cases, the freshness parameter can be a random number. The freshness parameter can be selected, for example, by security service 1110, and the freshness parameter can be indicated to device 902 by DU 906 during AS security context establishment 1136. In some cases, DU 1104 and UE 1102 can use AS key K. DU The horizontal key export refreshes the AS key locally without requiring a key refresh from security service 1110. This is used to refresh the AS key K. DU Vertical key export can be performed by security service 1110.
[0117] In some cases, security service 1110 can export the AS key K of 1132. DU Send 1134 along with the AS security policy to DU 1104. In some cases, the AS security policy can be obtained based on the service security policy. In other cases, the AS security policy can be obtained by security service 1110 from subscription and / or policy service 1150 accessible to security service 1110. DU 1104 can then send the AS security policy and AS key K together. DUAn AS security context 1136 is established between device 1102 and DU 1104. As an example, DU 1104 can configure a new bearer for service 1108 based on an AS security policy. The AS security policy can indicate whether the service requires encryption, integrity protection, or both. In some cases, because the AS security context can extend to the Radio Link Control (RLC) protocol stack, any MAC layer security protocol can be used to establish the AS security context. In some cases, MAC layer security terminates at the DU, and the DU can expose service-based interfaces to other services, such as vertical services. In some cases, MAC layer security can be indicated / configured / activated based on configuration messages, such as or similar to Radio Resource Control (RRC) messages. In some cases, MAC layer security can protect Media Access Control Protocol Data Units (MAC PDUs). In some cases, MAC layer security can protect the entire MAC PDU. In some cases, MAC layer security can protect individual MAC sub-PDUs of the MAC PDU. In some cases, MAC layer security can protect only MAC Control Elements (MAC CEs). In some cases, MAC layer security implements encryption, integrity protection, or both based on the AS security policy.
[0118] Figure 12 This is an example call flowchart for maintaining AS security for mobility according to various aspects of this disclosure. Figure 12 This includes device 1202, DU collection 1204, mobility service 1206, and security service 1208. Device 1102 can be substantially similar to... Figure 5 Equipment 502 Figure 7 Equipment 702 Figure 8 Equipment 802 Figure 9 Equipment 902 Figure 10 Equipment 1002 and Figure 11 Device 1102. DU set 1104 can be multiple DUs, where each DU in DU set 1104 is substantially similar to... Figure 11 DU 1104. Mobility service 1206 can be basically similar to Figure 11 Mobility service 1106. Security service 1108 can be basically similar to... Figure 5 Security Service 514 Figure 7 Security Service 708 Figure 9 Security Service 910 Figure 10 Security Service 1010 and Figure 11 Security service 1110.
[0119] exist Figure 12In this context, device 1202 may be a mobile device and may have a security context 1210 established between device 1202 and security service 1208. Additionally, device 1202 has established a security context with a set of services including mobility service 1206, and services (excluding mobility service 1206) have been registered with the mobility service (e.g., ...). Figure 11 (Registration 1130). Device 1202 has also established an AS security context with service DUs (not shown) that are not included in the set of DUs 1204. In some cases, when device 1202 approaches the edge of the service DU's range, device 1202 can notify mobility service 1206 of mobility event 1212 to change the service DU. Mobility service 1206 can determine that DUs that can be prepared to serve device 1202 (e.g., the set of DUs 1204), and mobility service 1206 can transmit the list of DUs along with the service security policy 1214 to security service 1208. Security service 1208 can derive a new AS key (K) for the DUs in the set of DUs 1204. DU As mentioned above Figure 11 The security service 1208 then allows the new AS key (K) to be released. DU The AS security policy, along with the DU security policy, is provided to the DUs in the DU 1204 set. The DUs can then be configured based on the AS security policy and the AS key (K) used for the DU. DU Configure AS security using . In some cases, a new AS key (K) can be prepared for the DU 1204 set. DU ), and transfers 1224 to multiple DUs before moving device 1202 to the set of DUs 1204. In some cases, a new AS key (K) can be prepared for the set of DUs 1204. DU Then, based on which DU device 1202 might move to, the new AS key (K) will be sent. DU The device 1202 transmits 1216 to a single DU in the set of DUs 1204. The DUs in the set of devices 1202 and DUs 1204 can then establish a security context 1218 AS 1220. In some cases, DU 1204 may transmit freshness parameters and / or additional parameters received from the security service to device 1202.
[0120] In some cases, the DU can prepare an AS security context cookie and transmit it to device 1202. The AS security context cookie may include information for reconstructing the AS security context between the DU and device 1202. The AS security context cookie can help optimize reconnection from the device to the DU by allowing the reconstruction of a temporary AS security context without having to obtain a new AS security key from security service 1208. In some cases, the AS security context cookie may be interpreted by the DU that created it and used when device 1202 connects to the DU. For example, device 1202 may enter an inactive state 1226, and the DU may remove the AS security context 1228 after determining that device 1202 has entered an inactive state 1226a. If device 1202 re-enters an active state and device 1202 transmits data with the AS security context cookie 1230, then DU 1204 can establish an AS security context 1232 based on the information in the AS security context cookie used to reconstruct the AS security context. For example, an AS security context cookie may include an AS key (K) encoded in a manner that only DU 1204 can decode. DU (or a key derived from the AS key). Device 1202 can encode data using the AS key (or a derived key) (e.g., based on the AS security context) and transmit data 1230 with an AS security context cookie. DU can then decode the AS security context cookie to obtain the AS key, and then decode the data from device 1202 (e.g., establish a temporary AS security context 1232). DU and / or device 1202 can then notify mobility service 1206 of mobility event 1234, for example, to obtain a new AS key (K). DU To establish a new AS security context (compared to the temporary AS security context 1232).
[0121] Figure 13 This is a flowchart illustrating a process 1300 for protecting access to a wireless system according to various aspects of this disclosure. Process 1300 may be provided by a wireless network (e.g., BS 102, mmW BS 180, ...). Figure 1 Core network 170, core network 320, SMO framework 305, O0eNB 311, RIC 325, O-Cloud 390, CU 310, Figure 5 Security Service 514 Figure 7 Security Service 708 Figure 8 Security Service 1 806 Figure 9Security Service 910 Figure 10 Security Service 1008 Figure 11 Security Service 1110 Figure 12 Security Service 1208 and Figure 16 The wireless device is a component or system (e.g., chipset, server, device, etc.) of a computing system 1600. The wireless device may be a mobile device (e.g., a mobile phone), a networked wearable device (such as a watch), an extended reality (XR) device (such as a virtual reality (VR) device or an augmented reality (AR) device), a vehicle or a component or system of a vehicle, or other types of computing devices (e.g., respectively). Figure 1 and Figure 2 UE 104 Figure 4 Wireless devices 407 Figure 5 Equipment 502 Figure 7 Equipment 702 Figure 8 Equipment 802 Figure 9 Equipment 902 Figure 10 Equipment 1002 Figure 11 Equipment 1102 Figure 12 Equipment 1202 and Figure 16 The operation of process 1300 can be implemented on one or more processors (e.g., computing system 1600, etc.). Figure 16 Software components that execute and run on the processor 1610 or other processor. Furthermore, the transmission and reception of signals by the wireless network (or components of the wireless network, such as security services) in process 1300 may be, for example, by one or more antennas (e.g., antenna 234 in the figure) and / or one or more transceivers (e.g., ...). Figure 2 This is achieved through modulator / demodulator 232, TX MIMO processor 230, MIMO detector 236, transmitter processor 220, receiver processor 238, etc.
[0122] At box 1302, the computing device (or a component thereof) can obtain services (e.g., Figure 11 Service 1108) receives a first request for a service key used to access the service (e.g., Figure 11 Service key request 1118), the first request for the service key includes the first wireless node (e.g., Figure 11 The identifier and service security policy of DU 1104, wherein the service security policy indicates the use of access layer (AS) security, and wherein the first wireless node is wirelessly coupled to a wireless device attempting to access the service (e.g., Figure 11 Equipment 1102 Figure 12Device 1202). In some cases, the first request for the service key includes AS security activation status information. AS security activation information can indicate whether AS security is currently activated. In some cases, the first radio node includes a base station (e.g., BS 102, mmW BS 180, ...). Figure 1 Core network 170 Figure 3 Distributed units (e.g., base station 300) Figure 3 DU 330, Figure 11 (DU 1104).
[0123] At box 1304, the computing device (or a component thereof) may send (e.g., in response to a first request for a service key) Figure 11 Sending 1126) is the service key used to access the service.
[0124] At box 1306, the computing device (or a component thereof) may generate (e.g., based on the identifier of the first wireless node) Figure 11 The first AS key (derived from 1132). In some cases, it can be based at least on the session root key (e.g., K). SECSVC 602), DU identifier, service identifier, another parameter, or any combination thereof to derive AS key K DU (For example, Figure 6 K DU 608). In some cases, the computing device (or a component thereof) may determine the generation of the first AS key based on AS security activation state information and service security policies. In some cases, the generation of the first AS key is further based on the session root key associated with the wireless device (e.g., Figure 6 K SECSVC (602). In some cases, the computing device (or a component thereof) may obtain the AS security policy and send the AS security policy to the first wireless node. In some cases, the AS security policy may be obtained based on the service security policy. In other cases, the AS security policy may be obtained by the security service from the subscription and / or policy service.
[0125] At box 1308, the computing device (or a component thereof) may send the generated first AS key based on the identifier of the first wireless node (e.g., Figure 11 The data is transmitted (1143) to the first wireless node. In some cases, the computing device (or its components) can receive mobility services from the wireless network (e.g., Figure 12 Mobility service 1206) receives (for example, Figure 12 The second request for the service key (sent 1214) includes a set of wireless nodes ( Figure 12The identifier (DU1204) is used, the set of wireless nodes does not include the first wireless node, and an AS key is generated for the wireless nodes in the set. In some cases, the computing device (or a component thereof) can send a second AS key (e.g., Figure 12 Sending 1216) to the second wireless node in the set of wireless nodes. In some cases, the computing device (or a component thereof) may send each AS key in the AS key to the corresponding wireless node in the set of wireless nodes (e.g., sending 1224).
[0126] Figure 14 This is a flowchart illustrating a process 1400 for protecting access to a wireless system according to various aspects of this disclosure. Process 1400 may be provided by a wireless network (e.g., BS 102, mmW BS 180, ...). Figure 1 Core network 170, core network 320, SMO framework 305, O0eNB 311, RIC 325, O-Cloud 390, CU 310, Figure 11 DU 1104, Figure 12 DU1204 and Figure 16 The wireless device is a component or system (e.g., chipset, server, device, etc.) of a computing system 1600. The wireless device may be a mobile device (e.g., a mobile phone), a networked wearable device (such as a watch), an extended reality (XR) device (such as a virtual reality (VR) device or an augmented reality (AR) device), a vehicle or a component or system of a vehicle, or other types of computing devices (e.g., respectively). Figure 1 and Figure 2 UE 104 Figure 4 Wireless devices 407 Figure 5 Equipment 502 Figure 7 Equipment 702 Figure 8 Equipment 802 Figure 9 Equipment 902 Figure 10 Equipment 1002 Figure 11 Equipment 1102 Figure 12 Equipment 1202 and Figure 16 The operation of process 1400 can be implemented on one or more processors (e.g., computing system 1600, etc.). Figure 16 Software components that execute and run on the processor 1610 or other processor. Furthermore, the transmission and reception of signals by the wireless network (or components of the wireless network, such as security services) in process 1400 may be, for example, by one or more antennas (e.g., antenna 234 in the figure) and / or one or more transceivers (e.g., ...). Figure 2This is achieved through modulator / demodulator 232, TX MIMO processor 230, MIMO detector 236, transmitter processor 220, receiver processor 238, etc.
[0127] At box 1402, a computing device (or a component thereof) can be wirelessly coupled to a wireless node (e.g., Figure 11 DU1104, Figure 12 Wireless devices of DU 1204 (e.g., Figure 11 Equipment 1102 Figure 12 Device 1202) receives a service access request (e.g., service 1108) for a wireless network service (e.g., service 1108). Figure 11 (Service access request 1114). For example, a wireless device can send a service access request to a DU, and the DU can forward the service access request to the service.
[0128] At box 1404, a computing device (or a component thereof) may send a service access request to the service.
[0129] At box 1406, the computing device (or a component thereof) may send Access Layer (AS) security activation status information and the identifier of the wireless node (e.g., Figure 11 The AS security activation status (1116) indicates whether AS security between the wireless node and the wireless device is active. In some cases, the AS security activation status indicates that AS security between the wireless node and the wireless device is not active.
[0130] At box 1408, the computing device (or a component thereof) may receive (e.g., security services) Figure 11 Send 1134, Figure 12 The AS key (1216) is generated based on the identifier of the wireless node. In some cases, the computing device (or its components) can receive AS security policies from the security service (e.g., in...). Figure 11 Send 1134, Figure 12 (In the transmission of 1216); and where AS security is further established based on AS security policies. In some cases, the computing device (or its components) may generate an AS security context cookie, which includes information for reconstructing the AS security context; and send the AS security context cookie to the wireless device.
[0131] At box 1410, the computing device (or a component thereof) may establish an AS security context with the wireless device based on an AS key (e.g., AS security context 1136). In some cases, the computing device (or a component thereof) may generate an AS security context cookie that includes information for reconstructing the AS security context; and send the AS security context cookie (e.g., Figure 12 The computer sends a 1222 signal to the wireless device. In some cases, the computing device (or a component thereof) can determine that the wireless device has entered an inactive state; and remove it based on the determination that the wireless device has entered an inactive state (e.g., Figure 12 The removal of 1228) AS security context. In some cases, a computing device (or a component thereof) can receive data sent from a wireless device (e.g., Figure 12 The data transmission (1230) includes an AS security context cookie; establishing a temporary AS security context with the wireless device based on information used to reconstruct the AS security context (e.g., AS security context 1232); and notifying the mobility service of the wireless network (e.g., ...). Figure 12 Notification 1232) Mobility events.
[0132] Figure 15 This is a flowchart illustrating a process 1500 for protecting access to a wireless system according to various aspects of this disclosure. Process 1500 may be provided by a wireless network (e.g., BS 102, mmW BS 180, ...). Figure 1 Core network 170, core network 320, SMO framework 305, O0eNB 311, RIC 325, O-Cloud 390, CU 310, Figure 5 Vertical services 524 Figure 5 Horizontal service 520 Figure 11 Service 1108 and Figure 16 The wireless device may be a component or system (e.g., a chipset server, device, etc.) of a computing system 1600. The wireless device may be a mobile device (e.g., a mobile phone), a networked wearable device (such as a watch), an extended reality (XR) device (such as a virtual reality (VR) device or an augmented reality (AR) device), a vehicle or a component or system of a vehicle, or other types of computing devices (e.g., respectively). Figure 1 and Figure 2 UE 104 Figure 4 Wireless devices 407 Figure 5 Equipment 502 Figure 7 Equipment 702 Figure 8 Equipment 802 Figure 9 Equipment 902 Figure 10 Equipment 1002 Figure 11 Equipment 1102 Figure 12 Equipment 1202 and Figure 16 The operation of process 1500 can be implemented on one or more processors (e.g., computing system 1600, etc.). Figure 16 Software components that execute and run on the processor 1610 or other processor. Furthermore, the transmission and reception of signals in process 1500 by the wireless network (or components of the wireless network, such as security services) may be, for example, by one or more antennas (e.g., antenna 234 in the figure) and / or one or more transceivers (e.g., Figure 2 This is achieved through modulator / demodulator 232, TX MIMO processor 230, MIMO detector 236, transmitter processor 220, receiver processor 238, etc.
[0133] At box 1502, a computing device (or a component thereof) can be wirelessly coupled to a wireless node (e.g., Figure 11 DU1104, Figure 12 Wireless devices of DU 1204 (e.g., Figure 11 Equipment 1102 Figure 12 Device 1202) receives a service access request (e.g., service 1108) for a wireless network service (e.g., service 1108). Figure 11 The service access request (1114) may include, in some cases, a temporary identifier for the wireless device, and wherein, in order to register with the mobility service, the processor system is configured to send the temporary identifier of the wireless device and the identifier of the service to the mobility service. In some cases, the request for the service key may also include AS security activation status information.
[0134] At box 1504, the computing device (or a component thereof) may receive access layer (AS) security activation status information (e.g., Figure 11 The AS security activation status (1116) and the identifier of the wireless node indicate whether AS security between the wireless node and the wireless device is active.
[0135] At box 1506, the computing device (or a component thereof) may determine the activation of AS security based on a service security policy and AS security activation status information, wherein the service security policy indicates the use of access layer (AS) security. In some cases, the AS security activation status information indicates that AS security between the wireless node and the wireless device is not active.
[0136] At box 1508, the computing device (or a component thereof) may send (e.g., ...) to the security service of the wireless network. Figure 11The request for the service key (1118) is for accessing the service, and the request for the service key includes the identifier of the wireless node and the service security policy.
[0137] At box 1510, the computing device (or a component thereof) may receive (e.g., in response to a request for a service key) Figure 11 Sending 1126) is the service key information used to access the service.
[0138] At box 1512, the computing device (or a component thereof) may establish a connection with the wireless device based on service key information (e.g., Figure 11 Establishment of 1128) security context.
[0139] At box 1514, the computing device (or a component thereof) may register with the mobility service of the wireless network (e.g., Figure 11 (Registration 1130).
[0140] Figure 16 This is a diagram illustrating an example of a system used to implement certain aspects of this technology. Specifically, Figure 16 An example of computing system 1600 is illustrated. This computing system can be any computing device, such as constituting an internal computing system, a remote computing system, a camera, or any component thereof, wherein the components of the system communicate with each other using connection 1605. Connection 1605 can be a physical connection using a bus, or a direct connection to processor 1610, such as in a chipset architecture. Connection 1605 can also be a virtual connection, a networking connection, or a logical connection.
[0141] In some embodiments, computing system 1600 is a distributed system, wherein the functions described herein can be distributed across a data center, multiple data centers, a peer-to-peer network, etc. In some embodiments, one or more system components described represent a plurality of such components that each perform some or all of the functions described for which the component is used. In some embodiments, components can be physical devices or virtual devices.
[0142] Example system 1600 includes at least one processing unit (CPU or processor) 1610 and a connection 1605 that communicatively couples various system components, including system memories 1615 such as read-only memory (ROM) 1620 and random access memory (RAM) 1625, to processor 1610. Computing system 1600 may include a cache 1612 of high-speed memory that is directly connected to, closely proximates, or integrated into processor 1610.
[0143] Processor 1610 may include any general-purpose processor and hardware or software services, such as services 1632, 1634, and 1636 stored in storage device 1630, which are configured to control processor 1610 and dedicated processors in which software instructions are incorporated into the actual processor design. Processor 1610 may essentially be a completely independent computing system containing multiple cores or processors, buses, memory controllers, caches, etc. Multi-core processors may be symmetric or asymmetric.
[0144] To enable user interaction, the computing system 1600 includes an input device 1645 that can represent any number of input mechanisms, such as a microphone for voice, a touch-sensitive screen for gesture or graphic input, a keyboard, a mouse, motion input, and voice input. The computing system 1600 may also include an output device 1635 that can be one or more of a plurality of output mechanisms. In some cases, a multimodal system allows the user to provide multiple types of input / output to communicate with the computing system 1600.
[0145] The computing system 1600 may include a communication interface 1640, which typically controls and manages user input and system output. The communication interface may perform or facilitate the receipt and / or transmission of wired or wireless communications using wired and / or wireless transceivers, including utilizing audio jacks / plugs, microphone jacks / plugs, Universal Serial Bus (USB) ports / plugs, Apple... ™ Lightning ™ Ports / plugs, Ethernet ports / plugs, fiber optic ports / plugs, dedicated wired ports / plugs, 3G, 4G, 5G and / or other cellular data network wireless signal transmission, Bluetooth ™ Wireless signal transmission, Bluetooth ™ Low-power (BLE) wireless signal transmission, IBEACON ™Wireless signal transmission, including radio frequency identification (RFID) wireless signal transmission, near field communication (NFC) wireless signal transmission, dedicated short range communication (DSRC) wireless signal transmission, 802.11 Wi-Fi wireless signal transmission, wireless local area network (WLAN) signal transmission, visible light communication (VLC), global microwave access interoperability (WiMAX), infrared (IR) wireless signal transmission, public switched telephone network (PSTN) signal transmission, integrated services digital network (ISDN) signal transmission, ad hoc network signal transmission, radio wave signal transmission, microwave signal transmission, infrared signal transmission, visible light signal transmission, ultraviolet light signal transmission, wireless signal transmission along the electromagnetic spectrum, or some combination thereof. The communication interface 1640 may also include one or more Global Navigation Satellite System (GNSS) receivers or transceivers for determining the location of the computing system 1600 based on one or more signals received from one or more satellites associated with one or more GNSS systems. GNSS systems include, but are not limited to, the U.S. Global Positioning System (GPS), Russia's Global Navigation Satellite System (GLONASS), China's BeiDou Navigation Satellite System (BDS), and Europe's Galileo GNSS. There are no limitations on operation on any particular hardware configuration, and therefore the underlying features here can be easily replaced to obtain improved hardware or firmware configurations as they are developed.
[0146] Storage device 1630 may be a non-volatile and / or non-transitory and / or computer-readable storage device, and may be a hard disk or other type of computer-readable medium capable of storing data accessible by a computer, such as magnetic tape, flash memory cards, solid-state storage devices, digital versatile discs, cartridges, floppy disks, hard disks, magnetic tapes, magnetic stripes, any other magnetic storage media, flash memory, memristor memory, any other solid-state storage, CD-ROM, rewritable CD, digital video disc (DVD), Blu-ray disc (BDD), holographic disc, another optical medium, secure digital card (SD card), micro secure digital card (microSD card), Memory Stick. ®Cards, smart card chips, EMV chips, Subscriber Identity Module (SIM) cards, mini / micro / nano / micro SIM cards, another integrated circuit (IC) chip / card, random access memory (RAM), static RAM (SRAM), dynamic RAM (DRAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash EPROM, cache memory (e.g., level 1 (L1) cache, level 2 (L2) cache, level 3 (L3) cache, level 4 (L4) cache, level 5 (L5) cache or other (L#) cache), resistive random access memory (RRAM / ReRAM), phase change memory (PCM), spin-transfer torque RAM (STT-RAM), another memory chip or cassette and / or combinations thereof.
[0147] Storage device 1630 may include software services, servers, services, etc., which enable the system to perform functions when the code defining such software is executed by processor 1610. In some embodiments, hardware services performing specific functions may include software components for performing functions stored in a computer-readable medium connected to necessary hardware components such as processor 1610, connection 1605, output device 1635, etc. The term "computer-readable medium" includes, but is not limited to, portable or non-portable storage devices, optical storage devices, and various other media capable of storing, containing, or carrying instructions and / or data. Computer-readable media may include non-transitory media in which data can be stored and which does not include carrier waves and / or transient electronic signals propagated wirelessly or via a wired connection. Examples of non-transitory media may include, but are not limited to, magnetic disks or magnetic tapes, optical storage media such as compact discs (CDs) or digital versatile discs (DVDs), flash memory, memory, or memory devices. Computer-readable media may store code and / or machine-executable instructions thereon, which may represent procedures, functions, subroutines, programs, routines, subroutines, modules, software packages, classes, or any combination of instructions, data structures, or program statements. Code segments may be coupled to other code segments or hardware circuitry by passing and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc., may be passed, forwarded, or transmitted via any suitable means, including memory sharing, message passing, token passing, network transmission, etc.
[0148] Specific details have been provided in the foregoing description to offer a thorough understanding of the various embodiments and examples presented herein, but those skilled in the art will recognize that this application is not limited thereto. Therefore, although exemplary embodiments of this application have been described in detail herein, it is to be understood that the inventive concept can be embodied and adopted in a variety of other ways, and the appended claims are intended to be construed as including such variations, unless limited by prior art. Various features and aspects of the applications described above may be used individually or in combination. Furthermore, without departing from the broader scope of this specification, the embodiments can be used in any number of environments and applications beyond those described herein. Therefore, the specification and drawings should be considered illustrative rather than restrictive. For illustrative purposes, the methods are described in a particular order. It should be understood that in alternative embodiments, the methods may be performed in a different order than described.
[0149] For clarity, in some cases, this technology may be presented as comprising individual functional blocks, which include devices, device components, steps, or routines embodied in a method, either in software or a combination of hardware and software. Additional components may be used in addition to those shown in the figures and / or described herein. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form to avoid obscuring these embodiments with unnecessary detail. In other cases, well-known circuits, processes, algorithms, structures, and techniques may be shown without necessary detail to avoid obscuring the embodiments.
[0150] Furthermore, those skilled in the art will understand that the various exemplary logic blocks, modules, circuits, and algorithm steps described in connection with the aspects disclosed herein can be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability between hardware and software, various exemplary components, blocks, modules, circuits, and steps have been described above in general terms of their functionality. Whether such functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the overall system. Those skilled in the art can implement the described functionality in different ways for each specific application; however, such implementation decisions should not be construed as departing from the scope of this disclosure.
[0151] Individual implementations may be described above as processes or methods depicted as flowcharts, flow diagrams, data flow diagrams, structure diagrams, or block diagrams. Although flowcharts may describe operations as sequential processes, many operations within an operation may be executed in parallel or concurrently. Furthermore, the order of operations may be rearranged. A process terminates when its operations are completed, but a process may have additional steps not included in the accompanying drawings. A process may correspond to a method, function, procedure, subroutine, subroutine, etc. When a process corresponds to a function, the termination of the process may correspond to the function returning to the calling function or the main function.
[0152] The processes and methods described in the examples above can be implemented using stored computer-executable instructions or computer-executable instructions otherwise available from a computer-readable medium. Such instructions may include, for example, instructions and data that configure, or otherwise configure, a general-purpose computer, special-purpose computer, or processing device to perform a function or group of functions. The portion may be accessible via a network of the computer resources used. The computer-executable instructions may be, for example, binary, intermediate format instructions such as assembly language, firmware, or source code. Examples of computer-readable media that can be used to store the instructions, the information used, and / or information created during the methods according to the described examples include disks or optical discs, flash memory, USB devices with non-volatile memory, networked storage devices, etc.
[0153] In some implementations, computer-readable storage devices, media, and memories may include cables or wireless signals containing bit streams, etc. However, when referred to, non-transitory computer-readable storage media explicitly excludes media such as power consumption, carrier signals, electromagnetic waves, and the signals themselves.
[0154] Those skilled in the art will understand that information and signals can be represented using any of a variety of different techniques and arts. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referred to throughout the above description may, in some cases, be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, light fields or light particles, or any combination thereof, depending in part on the specific application, in part on the desired design, in part on the corresponding technology, etc.
[0155] The various exemplary logic blocks, modules, and circuits described in conjunction with the aspects disclosed herein can be implemented or executed using hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof, and can take any form factor of various form factors. When implemented in software, firmware, middleware, or microcode, program code or code segments (e.g., computer program products) for performing necessary tasks can be stored in a computer-readable or machine-readable medium. A processor can perform the necessary tasks. Examples of form factors include: laptop computers, smartphones, mobile phones, tablet devices, or other small form factor personal computers, personal digital assistants, rack-mount devices, self-contained devices, etc. The functionality described herein can also be embodied in peripheral devices or intercalation cards. By further example, such functionality can also be implemented on circuit boards in different chips or different processes running on a single device.
[0156] Instructions, media for delivering such instructions, computing resources for executing them, and other structures for supporting such computing resources are example components for providing the functionality described in this disclosure.
[0157] The techniques described herein can also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques can be implemented in any of a variety of devices, such as general-purpose computers, wireless communication devices (mobile phones), or integrated circuit devices with multiple uses, including applications in wireless communication devices (mobile phones) and other devices. Any feature described as a module or component can be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques can be implemented at least in part by a computer-readable data storage medium comprising program code including instructions that, when executed, perform one or more of the methods, algorithms, and / or operations described above. The computer-readable data storage medium can form part of a computer program product, which may include packaging material. The computer-readable medium may include memory or data storage media, such as random access memory (RAM) (such as synchronous dynamic random access memory (SDRAM)), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), flash memory, magnetic or optical data storage media, etc. Additionally or alternatively, the technology may be implemented at least in part by a computer-readable communication medium that carries or conveys program code in the form of instructions or data structures that can be accessed, read and / or executed by a computer, such as propagated signals or waves.
[0158] The program code can be executed by a processor, which may include one or more processors, such as one or more digital signal processors (DSPs), general-purpose microprocessors, application-specific integrated circuits (ASICs), field-programmable arrays (FPGAs), or other equivalent integrated or discrete logic circuits. Such processors can be configured to perform any of the techniques described in this disclosure. A general-purpose processor may be a microprocessor; however, in alternatives, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration. Therefore, as used herein, the term "processor" may refer to any of the foregoing structures, any combination of the foregoing structures, or any other structure or means suitable for implementing the techniques described herein.
[0159] Those skilled in the art will understand that, without departing from the scope of this description, the less than (“<”) and greater than (“>”) symbols or terms used herein may be represented by less than or equal to (“>”) respectively. The sign "") and greater than or equal to (" The symbol ) is used instead.
[0160] When a component is described as being “configured” to perform certain operations, such configuration can be achieved, for example, by designing electronic circuits or other hardware to perform the operations, by programming programmable electronic circuits (e.g., microprocessors or other suitable electronic circuits) to perform the operations, or any combination thereof.
[0161] The phrase “coupled to” or “communicatively coupled to” means that any component is physically connected directly or indirectly to another component, and / or that any component is in communication with another component directly or indirectly (e.g., connected to that other component via a wired or wireless connection and / or other suitable communication interface).
[0162] Claim language or other languages that state "at least one of" and / or "one or more of" in a set indicate that one member of the set or multiple members of the set (in any combination) satisfy the claim. For example, claim language stating "at least one of A and B" or "at least one of A or B" means A, B, or A and B. In another example, claim language stating "at least one of A, B, and C" or "at least one of A, B, or C" means A, B, C, or A and B, or A and C, or B and C, A and B and C, or any repetition is information or data (e.g., A and A, B and B, C and C, A and A and B, etc.), or any other ordering, repetition, or combination of A, B, and C. The language "at least one of" and / or "one or more of" in a set does not limit the set to the items listed in the set. For example, the language of a claim that expresses “at least one of A and B” or “at least one of A or B” may mean A, B or A and B, and may additionally include items not listed in the set of A and B.
[0163] Claims using phrases such as "at least one processor, the at least one processor being configured to," or other languages indicate that one or more processors (in any combination) are capable of performing associated operations. For example, a claim stating "at least one processor, the at least one processor being configured to: X, Y, and Z" means that a single processor can be used to perform operations X, Y, and Z; or that multiple processors are each assigned a specific subset of tasks involving operations X, Y, and Z, such that the multiple processors together perform X, Y, and Z; or that a group of multiple processors work together to perform operations X, Y, and Z. In another example, a claim stating "at least one processor, the at least one processor being configured to: X, Y, and Z" could mean that any single processor can perform only a subset of operations X, Y, and Z.
[0164] The exemplary aspects of this disclosure include: Aspect 1. A method for protecting access to a wireless network, the method comprising: receiving from a service a first request for a service key for accessing the service by a security service, the first request for the service key including an identifier of a first wireless node and a service security policy, wherein the service security policy indicates the use of access layer (AS) security, and wherein the first wireless node is wirelessly coupled to a wireless device attempting to access the service; sending the service key for accessing the service from the security service in response to the first request for the service key; generating a first AS key based on the identifier of the first wireless node; and sending the generated first AS key to the first wireless node based on the identifier of the first wireless node.
[0165] Aspect 2. The method according to aspect 1, wherein the first request for the service key includes AS security activation status information.
[0166] Aspect 3. The method according to aspect 2, the method further comprising determining the generation of the first AS key based on the AS security activation status information and service security policy.
[0167] Aspect 4. The method according to any one of Aspects 2 to 3, wherein the generation of the first AS key is further based on a session root key associated with the wireless device.
[0168] Aspect 5. The method according to any one of Aspects 1 to 4, the method further comprising: obtaining an AS security policy; and sending the AS security policy to the first wireless node.
[0169] Aspect 6. The method according to any one of Aspects 1 to 4, the method further comprising: receiving a second request for a service key from a mobility service of the wireless network, the second request for the service key including an identifier of a set of wireless nodes, the set of wireless nodes excluding the first wireless node; and generating an AS key for wireless nodes in the set of wireless nodes.
[0170] Aspect 7. The method according to aspect 6, the method further comprising sending a second AS key to a second wireless node in the set of wireless nodes.
[0171] Aspect 8. The method according to any one of Aspects 6 to 7, the method further comprising sending each of the AS keys to a corresponding wireless node in the set of wireless nodes.
[0172] Aspect 9. The method according to any one of Aspects 1 to 8, wherein the first wireless node comprises a distributed unit of a base station.
[0173] Aspect 10. A method for protecting access to a wireless network, the method comprising: receiving a service access request for a service of the wireless network from a wireless device wirelessly coupled to the wireless node; sending the service access request to the service; sending access layer (AS) security activation state information and an identifier of the wireless node to the service, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; receiving an AS key generated based on the identifier of the wireless node from a security service; and establishing an AS security context with the wireless device based on the AS key.
[0174] Aspect 11. The method according to aspect 10, the method further comprising receiving an AS security policy from the security service; and wherein the AS security is further established based on the AS security policy.
[0175] Aspect 12. The method according to any one of Aspects 10 to 11, the method further comprising: generating an AS security context cookie, the AS security context cookie including information for reconstructing the AS security context; and sending the AS security context cookie to the wireless device.
[0176] Aspect 13. The method according to aspect 12, the method further comprising: determining that the wireless device has entered an inactive state; and removing the AS security context based on determining that the wireless device has entered the inactive state.
[0177] Aspect 14. The method according to aspect 13, the method further comprising: receiving data transmission from the wireless device, the data transmission including the AS security context cookie; establishing a temporary AS security context with the wireless device based on the information for reconstructing the AS security context; and notifying the mobility service of the wireless network of a mobility event.
[0178] Aspect 15. The method according to any one of Aspects 13 to 14, wherein the AS security activation status information indicates that the AS security between the wireless node and the wireless device is not active.
[0179] Aspect 16. A method for protecting access to a wireless network, the method comprising: receiving a service access request for the service from a wireless device wirelessly coupled to a wireless node by a service of the wireless network; receiving access layer (AS) security activation state information and an identifier of the wireless node, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; determining whether to activate AS security based on a service security policy and the AS security activation state information, wherein the service security policy indicates the use of access layer (AS) security; sending a request to a security service of the wireless network for a service key for accessing the service, the request for the service key including the identifier of the wireless node and the service security policy; receiving service key information for accessing the service in response to the request for the service key; establishing a security context with the wireless device based on the service key information; and registering with a mobility service of the wireless network.
[0180] Aspect 17. The method according to aspect 16, wherein the service access request includes a temporary identifier of the wireless device, and wherein registering with the mobility service includes sending the temporary identifier of the wireless device and the identifier of the service to the mobility service.
[0181] Aspect 18. The method according to any one of Aspects 16 to 17, wherein the AS security activation status information indicates that the AS security between the wireless node and the wireless device is not active.
[0182] Aspect 19. The method according to any one of Aspects 16 to 18, wherein the request for the service key further includes the AS security activation status information.
[0183] Aspect 20. An apparatus for protecting access to a wireless network, the apparatus comprising: a memory system including instructions; and a processor system coupled to the memory system, wherein the processor system is configured to: receive from a service a first request for a service key for accessing the service, the first request for the service key including an identifier of a first wireless node and a service security policy, wherein the service security policy instructs the use of access layer (AS) security, and wherein the first wireless node is wirelessly coupled to a wireless device attempting to access the service; transmit the service key for accessing the service in response to the first request for the service key; generate a first AS key based on the identifier of the first wireless node; and transmit the generated first AS key to the first wireless node based on the identifier of the first wireless node.
[0184] Aspect 21. The apparatus according to aspect 20, wherein the first request for the service key includes AS security activation status information.
[0185] Aspect 22. The apparatus according to aspect 21, wherein the processor system is further configured to determine the generation of the first AS key based on the AS security activation state information and service security policy.
[0186] Aspect 23. The apparatus according to any one of Aspects 21 to 22, wherein the generation of the first AS key is further based on a session root key associated with the wireless device.
[0187] Aspect 24. The apparatus according to any one of Aspects 20 to 23, wherein the processor system is further configured to: obtain an AS security policy; and send the AS security policy to the first wireless node.
[0188] Aspect 25. The apparatus according to any one of Aspects 20 to 23, wherein the processor system is further configured to: receive a second request for a service key from a mobility service of the wireless network, the second request for the service key including an identifier of a set of wireless nodes, the set of wireless nodes excluding the first wireless node; and generate an AS key for the wireless nodes in the set of wireless nodes.
[0189] Aspect 26. The apparatus according to aspect 25, wherein the processor system is further configured to send the second AS key to a second wireless node in the set of wireless nodes.
[0190] Aspect 27. The apparatus according to any one of Aspects 25 to 26, wherein the processor system is further configured to send each of the AS keys to a corresponding wireless node in the set of wireless nodes.
[0191] Aspect 28. The apparatus according to any one of Aspects 20 to 27, wherein the first wireless node comprises a distributed unit of a base station.
[0192] Aspect 29. An apparatus for protecting access to a wireless network, the apparatus comprising: a memory system including instructions; and a processor system coupled to the memory system, wherein the processor system is configured to: receive a service access request for a service of the wireless network from a wireless device wirelessly coupled to a wireless node; send the service access request to the service; send access layer (AS) security activation state information and an identifier of the wireless node to the service, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; receive an AS key generated based on the identifier of the wireless node from a security service; and establish an AS security context with the wireless device based on the AS key.
[0193] Aspect 30. The apparatus according to aspect 29, wherein the processor system is further configured to receive an AS security policy from the security service; and wherein the AS security is further established based on the AS security policy.
[0194] Aspect 31. The apparatus according to any one of Aspects 29 to 30, wherein the processor system is further configured to: generate an AS security context cookie, the AS security context cookie including information for reconstructing the AS security context; and send the AS security context cookie to the wireless device.
[0195] Aspect 32. The apparatus according to aspect 31, wherein the processor system is further configured to: determine that the wireless device has entered an inactive state; and remove the AS security context based on determining that the wireless device has entered the inactive state.
[0196] Aspect 33. The apparatus according to aspect 32, wherein the processor system is further configured to: receive data transmission from the wireless device, the data transmission including the AS security context cookie; establish a temporary AS security context with the wireless device based on the information for reconstructing the AS security context; and notify the mobility service of the wireless network of a mobility event.
[0197] Aspect 34. The apparatus according to any one of Aspects 32 to 33, wherein the AS security activation status information indicates that the AS security between the wireless node and the wireless device is not active.
[0198] Aspect 35. An apparatus for protecting access to a wireless network, the apparatus comprising: a memory system including instructions; and a processor system coupled to the memory system, wherein the processor system is configured to: receive a service access request for a service of the wireless network from a wireless device wirelessly coupled to a wireless node; receive access layer (AS) security activation state information and an identifier of the wireless node, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; determine whether to activate AS security based on a service security policy and the AS security activation state information, wherein the service security policy indicates the use of access layer (AS) security; send a request to a security service of the wireless network for a service key for accessing the service, the request for the service key including the identifier of the wireless node and the service security policy; receive service key information for accessing the service in response to the request for the service key; establish a security context with the wireless device based on the service key information; and register with a mobility service of the wireless network.
[0199] Aspect 36. The apparatus according to aspect 35, wherein the service access request includes a temporary identifier of the wireless device, and wherein, in order to register with the mobility service, the processor system is configured to send the temporary identifier of the wireless device and the identifier of the service to the mobility service.
[0200] Aspect 37. The apparatus according to any one of Aspects 35 to 36, wherein the AS security activation status information indicates that AS security between the wireless node and the wireless device is not active.
[0201] Aspect 38. The apparatus according to any one of Aspects 35 to 37, wherein the request for the service key further includes the AS security activation status information.
[0202] Aspect 39. A non-transitory computer-readable medium having instructions stored thereon, the instructions, when executed by a processor system, causing the processor system to: receive from a service a first request for a service key for accessing the service, the first request for the service key including an identifier of a first wireless node and a service security policy, wherein the service security policy indicates the use of access layer (AS) security, and wherein the first wireless node is wirelessly coupled to a wireless device attempting to access the service; transmit the service key for accessing the service in response to the first request for the service key; generate a first AS key based on the identifier of the first wireless node; and transmit the generated first AS key to the first wireless node based on the identifier of the first wireless node.
[0203] Aspect 40. The non-transitory computer-readable medium according to aspect 39, wherein the first request for the service key includes AS security activation status information.
[0204] Aspect 41. The non-transitory computer-readable medium according to aspect 40, wherein the instructions further cause the processor system to generate the first AS key based on the AS security activation state information and service security policy.
[0205] Aspect 42. The non-transitory computer-readable medium according to any one of aspects 40 to 41, wherein the generation of the first AS key is further based on a session root key associated with the wireless device.
[0206] Aspect 43. A non-transitory computer-readable medium according to any one of aspects 39 to 42, wherein the instructions further cause the processor system to: obtain an AS security policy; and send the AS security policy to the first wireless node.
[0207] Aspect 44. A non-transitory computer-readable medium according to any one of aspects 39 to 42, wherein the instructions further cause the processor system to: receive a second request for a service key from a mobility service of a wireless network, the second request for the service key including an identifier of a set of wireless nodes, the set of wireless nodes excluding the first wireless node; and generate an AS key for the wireless nodes in the set of wireless nodes.
[0208] Aspect 45. The non-transitory computer-readable medium according to aspect 44, wherein the instructions further cause the processor system to send a second AS key to a second wireless node in the set of wireless nodes.
[0209] Aspect 46. The non-transitory computer-readable medium according to any one of Aspects 44 to 45, wherein the instructions further cause the processor system to send each of the AS keys to a corresponding wireless node in the set of wireless nodes.
[0210] Aspect 47. The non-transitory computer-readable medium according to any one of aspects 39 to 46, wherein the first wireless node comprises a distributed unit of a base station.
[0211] Aspect 48. A non-transitory computer-readable medium having instructions stored thereon, the instructions, when executed by a processor system, causing the processor system to: receive a service access request for a service of a wireless network from a wireless device wirelessly coupled to a wireless node; send the service access request to the service; send access layer (AS) security activation state information and an identifier of the wireless node to the service, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; receive an AS key generated based on the identifier of the wireless node from a security service; and establish an AS security context with the wireless device based on the AS key.
[0212] Aspect 49. The non-transitory computer-readable medium according to aspect 48, wherein the instructions further cause the processor system to receive an AS security policy from the security service; and wherein the AS security is further established based on the AS security policy.
[0213] Aspect 50. A non-transitory computer-readable medium according to any one of aspects 48 to 49, wherein the instructions further cause the processor system to: generate an AS security context cookie, the AS security context cookie including information for reconstructing the AS security context; and send the AS security context cookie to the wireless device.
[0214] Aspect 51. The non-transitory computer-readable medium according to aspect 50, wherein the instructions further cause the processor system to: determine that the wireless device has entered an inactive state; and remove the AS security context based on the determination that the wireless device has entered the inactive state.
[0215] Aspect 52. The non-transitory computer-readable medium according to aspect 51, wherein the instructions further cause the processor system to: receive data transmission from the wireless device, the data transmission including the AS security context cookie; establish a temporary AS security context with the wireless device based on the information for reconstructing the AS security context; and notify the mobility service of the wireless network of a mobility event.
[0216] Aspect 53. The non-transitory computer-readable medium according to any one of Aspects 51 to 52, wherein the AS security activation status information indicates that the AS security between the wireless node and the wireless device is not active.
[0217] Aspect 54. A non-transitory computer-readable medium having instructions stored thereon, the instructions, when executed by a processor system, causing the processor system to: receive a service access request for a service of a wireless network from a wireless device wirelessly coupled to a wireless node; receive access layer (AS) security activation state information and an identifier of the wireless node, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; determine whether to activate AS security based on a service security policy and the AS security activation state information, wherein the service security policy indicates the use of access layer (AS) security; send a request to a security service of the wireless network for a service key for accessing the service, the request for the service key including the identifier of the wireless node and the service security policy; receive service key information for accessing the service in response to the request for the service key; establish a security context with the wireless device based on the service key information; and register with a mobility service of the wireless network.
[0218] Aspect 55. The non-transitory computer-readable medium according to aspect 54, wherein the service access request includes a temporary identifier of the wireless device, and wherein, in order to register with the mobility service, the processor system is configured to send the temporary identifier of the wireless device and the identifier of the service to the mobility service.
[0219] Aspect 56. The non-transitory computer-readable medium according to any one of Aspects 54 to 55, wherein the AS security activation status information indicates that AS security between the wireless node and the wireless device is not active.
[0220] Aspect 57. The non-transitory computer-readable medium according to any one of Aspects 54 to 56, wherein the request for the service key further includes the AS security activation status information.
[0221] Aspect 66. An apparatus for wireless communication, the apparatus comprising one or more components for performing operations according to any one of aspects 1 to 57.
Claims
1. An apparatus for securing access to a wireless network, the apparatus comprising: a memory system comprising instructions; and a processor system coupled to the memory system, wherein the processor system is configured to: receive, from a service, a first request for a service key for accessing the service, the first request for the service key comprising an identifier of a first wireless node and a service security policy, wherein the service security policy indicates use of access stratum (AS) security, and wherein the first wireless node is wirelessly coupled to a wireless device attempting to access the service; send, in response to the first request for a service key, the service key for accessing the service; generate a first AS key based on the identifier of the first wireless node; and send the generated first AS key to the first wireless node based on the identifier of the first wireless node.
2. The apparatus of claim 1, wherein the first request for the service key comprises AS security activation status information.
3. The apparatus of claim 2, wherein the processor system is further configured to determine to generate the first AS key based on the AS security activation status information and a service security policy.
4. The apparatus of claim 2, wherein generating the first AS key is further based on a session root key associated with the wireless device.
5. The apparatus of claim 1, wherein the processor system is further configured to: obtain an AS security policy; and send the AS security policy to the first wireless node.
6. The apparatus of claim 1, wherein the processor system is further configured to: receive, from a mobility service of the wireless network, a second request for a service key, the second request for a service key comprising an identifier of a set of wireless nodes that does not include the first wireless node; and generate AS keys for wireless nodes in the set of wireless nodes.
7. The apparatus of claim 6, wherein the processor system is further configured to send a second AS key to a second wireless node in the set of wireless nodes.
8. The apparatus of claim 6, wherein the processor system is further configured to send each of the AS keys to a respective wireless node in the set of wireless nodes.
9. An apparatus for securing access to a wireless network, the apparatus comprising: a memory system comprising instructions; and a processor system coupled to the memory system, wherein the processor system is configured to: receive, from a wireless device wirelessly coupled to a wireless node, a service access request for a service of the wireless network; send the service access request to the service; send access stratum (AS) security activation status information and an identifier of the wireless node to the service, the AS security activation status information indicating whether AS security between the wireless node and the wireless device is active; receive, from a security service, an AS key generated based on the identifier of the wireless node; and establish an AS security context with the wireless device based on the AS key.
10. The apparatus of claim 9, wherein the processor system is further configured to receive, from the security service, an AS security policy; and wherein the AS security is further established based on the AS security policy.
11. The apparatus of claim 9, wherein the processor system is further configured to: generate an AS security context cookie, the AS security context cookie including information for reestablishing the AS security context; and send the AS security context cookie to the wireless device.
12. The apparatus of claim 11, wherein the processor system is further configured to: determine that the wireless device has entered an inactive state; and remove the AS security context based on determining that the wireless device has entered the inactive state.
13. The apparatus of claim 12, wherein the processor system is further configured to: receive a data transmission from the wireless device, the data transmission including the AS security context cookie; establish a temporary AS security context with the wireless device based on the information for reestablishing the AS security context; and notify a mobility service of the wireless network of a mobility event.
14. The apparatus of claim 12, wherein the AS security activation state information indicates that the AS security between the wireless node and the wireless device is not active.
15. An apparatus for protecting access to a wireless network, the apparatus comprising: a memory system including instructions; and a processor system coupled to the memory system, wherein the processor system is configured to: receive, from a wireless device wirelessly coupled to a wireless node, a service access request for a service of the wireless network; receive access stratum (AS) security activation state information and an identifier of the wireless node, the AS security activation state information indicating whether AS security between the wireless node and the wireless device is active; determine to activate AS security based on a service security policy and the AS security activation state information, wherein the service security policy indicates use of access stratum (AS) security; send, to a security service of the wireless network, a request for a service key for accessing the service, the request for the service key including the identifier of the wireless node and the service security policy; receive, in response to the request for the service key, service key information for accessing the service; establish a security context with the wireless device based on the service key information; and register with a mobility service of the wireless network.
16. The apparatus of claim 15, wherein the service access request comprises a temporary identifier of the wireless device, and wherein to register with the mobility service, the processor system is configured to send the temporary identifier of the wireless device and an identifier of the service to the mobility service.
17. The apparatus of claim 15, wherein the AS security activation status information indicates that AS security between the wireless node and the wireless device is not active.
18. The apparatus of claim 15, wherein the request for a service key further comprises the AS security activation status information.
19. A method for securing access to a wireless network, the method comprising: receiving, by a security service from a service, a first request for a service key for accessing the service, the first request for a service key comprising an identifier of a first wireless node and a service security policy, wherein the service security policy indicates use of access stratum (AS) security, and wherein the first wireless node is wirelessly coupled to a wireless device attempting to access the service; sending, from the security service, the service key for accessing the service in response to the first request for a service key; generating a first AS key based on the identifier of the first wireless node; and sending the generated first AS key to the first wireless node based on the identifier of the first wireless node.
20. The method of claim 19, wherein the first request for a service key comprises AS security activation status information.
21. The method of claim 20, the method further comprising determining to generate the first AS key based on the AS security activation status information and a service security policy.
22. The method of claim 20, wherein generating the first AS key is further based on a session root key associated with the wireless device.
23. The method of claim 19, the method further comprising: obtaining an AS security policy; and sending the AS security policy to the first wireless node.
24. The method of claim 19, the method further comprising: receiving, from a mobility service of the wireless network, a second request for a service key, the second request for a service key comprising an identifier of a set of wireless nodes that does not include the first wireless node; and generating AS keys for wireless nodes in the set of wireless nodes.
25. The method of claim 24, the method further comprising sending a second AS key to a second wireless node in the set of wireless nodes.
26. The method of claim 24, the method further comprising sending each of the AS keys to a respective wireless node in the set of wireless nodes.
27. A method for securing access to a wireless network, the method comprising: receiving, by a wireless node from a wireless device wirelessly coupled to the wireless node, a service access request for a service of the wireless network; sending the service access request to the service; sending access stratum (AS) security activation status information and an identifier of the wireless node to the service, the AS security activation status information indicating whether AS security between the wireless node and the wireless device is active; receiving, from a security service, an AS key generated based on the identifier of the wireless node; and establishing an AS security context with the wireless device based on the AS key.
28. The method of claim 27, further comprising receiving, from the security service, an AS security policy; and wherein the AS security is further established based on the AS security policy.
29. A method for securing access to a wireless network, the method comprising: receiving, by a service of the wireless network, a service access request for the service from a wireless device wirelessly coupled to a wireless node; receiving access stratum (AS) security activation status information and an identifier of the wireless node, the AS security activation status information indicating whether AS security between the wireless node and the wireless device is active; determining to activate AS security based on a service security policy and the AS security activation status information, wherein the service security policy indicates use of access stratum (AS) security; sending, to a security service of the wireless network, a request for a service key for accessing the service, the request for the service key including the identifier of the wireless node and the service security policy; receiving, in response to the request for the service key, service key information for accessing the service; establishing a security context with the wireless device based on the service key information; and registering with a mobility service of the wireless network.
30. The method of claim 29, wherein the service access request includes a temporary identifier of the wireless device, and wherein registering with the mobility service includes sending the temporary identifier of the wireless device and an identifier of the service to the mobility service.