Security management at media access layer using random
By employing random interleaving block size encryption technology in the 5G network's media access control layer, the security protection problem of the media access control layer is solved, achieving both security and stability in data transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NOKIA TECHNOLOGIES OY
- Filing Date
- 2025-10-20
- Publication Date
- 2026-04-21
AI Technical Summary
In 5G networks, the control information of the medium access control layer lacks security protection and is vulnerable to attacks, which can affect network operation and data reception.
In the media access control layer, random interleaving block sizes are used to encrypt data. The data block size is calculated by generating random numbers independently at the user equipment and access node, and the interleaving block size generated by randomness is used for encryption during transmission.
It effectively protects data transmission at the media access control layer, prevents eavesdropping and attacks, reduces latency, and ensures network security and stability.
Smart Images

Figure CN121908259A_ABST
Abstract
Description
Technical Field
[0001] This field generally relates to communication networks, and more specifically, but not exclusively, to security management within such communication networks. Background Technology
[0002] This section introduces aspects that will help in a better understanding of the invention. Therefore, the statements in this section should be read in this light and should not be construed as an admission of what is prior art or what is not prior art.
[0003] Fourth-generation (4G) wireless mobile telecommunications technology (also known as Long Term Evolution (LTE) technology) is designed to provide high-capacity mobile multimedia with high data rates, particularly for human interaction. Next-generation or fifth-generation (5G) technology is designed not only for human interaction but also for machine-type communication in so-called Internet of Things (IoT) networks.
[0004] While 5G networks are designed to enable large-scale IoT services (e.g., a very large number of limited-capacity devices) and mission-critical IoT services (e.g., requiring high reliability), they also support improvements to traditional mobile communication services in the form of enhanced mobile broadband (eMBB) services, thereby providing improved wireless internet access for mobile devices.
[0005] In the example communication system, user equipment such as a mobile terminal (subscriber) (5G UE in a 5G network or more broadly, UE) communicates via an air interface with a base station or access point of an access network in the 5G network, referred to as 5G AN. The access point (e.g., gNB) is, for example, part of the access network of the communication system.
[0006] For example, in 5G networks, the 5G Technical Specification (TS) 23.501, entitled "Technical Specification Group Services and Systems Aspects; System Architecture for 5G Systems," and TS 23.502, entitled "Technical Specification Group Services and Systems Aspects; Processes for 5G Systems (5GS)," describe an access network known as the 5G AN, the contents of which are incorporated herein by reference in their entirety. Typically, an access point (e.g., a gNB) provides the UE with access to the core network (CN or 5GC), which in turn provides the UE with access to other UEs and / or data networks (such as packet data networks, e.g., the Internet).
[0007] TS 23.501 further defines the 5G Service-Based Architecture (SBA), which models services as network functions (NFs) that communicate with each other using a representative state transition application programming interface (Restful API).
[0008] In addition, TS 33.501, entitled “Technical Specification Group Services and Systems Aspects; Security Architecture and Processes for 5G Systems,” further describes the security management details associated with 5G networks. The entire contents of TS 33.501 are incorporated herein by reference.
[0009] Security management is a critical consideration in any communications network environment. However, as efforts continue to improve the architecture and protocols associated with 5G and / or other networks to enhance network efficiency and / or user convenience, security management issues related to one or more access control protocol layers in the communications network environment can present significant technical challenges. Summary of the Invention
[0010] The illustrative embodiments provide security management techniques associated with one or more access control protocol layers in a communication network environment. Although the illustrative embodiments are described herein in the context of the Media Access Control (MAC) layer, it should be understood that one or more security management techniques described herein can be applied to other access control protocol layers in a communication network environment.
[0011] As an example, in one or more other illustrative embodiments, a method includes: generating a first random number based on a first cryptographic value at a user equipment associated with a communication network. The method includes: calculating a first data block size at the user equipment based on the first random number. The method includes: transmitting first data from the user equipment to an access node associated with the communication network, the first data being associated with the access control layer of the communication network and consistent with the first data block size.
[0012] As a further example, in one or more illustrative embodiments, a method includes: generating a first random number based on a first cryptographic value at an access node associated with a communication network. The method includes: calculating a first data block size at the access node based on the first random number. The method includes: transmitting first data from the access node to a user equipment associated with the communication network, the first data being associated with the access control layer of the communication network and consistent with the first data block size.
[0013] Advantageously, illustrative embodiments provide encryption of data at the MAC layer using random interleaving block sizes to protect communication at the MAC layer.
[0014] Further illustrative embodiments are provided in the form of a non-transitory computer-readable medium in which executable program code is embodied, which, when executed by a processor, causes the processor to perform the above-described and / or other steps, operations, etc. Further illustrative embodiments include means having a processor and memory configured to perform the above-described and / or other steps, operations, etc. Some illustrative embodiments include systems configured to perform the above-described and / or other steps, operations, etc. Furthermore, some illustrative embodiments include an apparatus or system comprising components for performing the above-described and / or other steps, operations, etc.
[0015] These and other features and advantages of the embodiments described herein will become more apparent from the accompanying drawings and the following detailed description. Attached Figure Description
[0016] Figure 1 A communication network environment in which one or more illustrative embodiments can be implemented is shown.
[0017] Figure 2 User equipment and entities that can implement one or more illustrative embodiments are shown.
[0018] Figure 3 The key derivation chain in a communication network environment is shown.
[0019] Figure 4 This illustrates the packet / service data unit correspondence between network protocol layers in a communication network environment.
[0020] Figure 5 An example of encrypting data using a random interleaving block size in the media access control layer of a communication network environment, according to an illustrative embodiment, is shown.
[0021] Figure 6 The corresponding interleaving functions in the user equipment and access node are illustrated according to an illustrative embodiment.
[0022] Figure 7 The diagram illustrates the corresponding Media Access Control Packet Data Unit (MAP) structure for LTE and 5G NR communication network environments according to an illustrative embodiment.
[0023] Figure 8 The diagram illustrates the corresponding Media Access Control Packet Data Unit (MAP) structures for downlink and uplink in a communication network environment according to an illustrative embodiment.
[0024] Figure 9 The main field in the 5G NR Media Access Control subheader according to an illustrative embodiment is shown.
[0025] Figure 10An example of block size and duration generated using a random number generator in the interleaving function, according to an illustrative embodiment, is shown.
[0026] Figure 11 The process flow for encrypting data using a random interleaving block size in a media access control layer in a communication network environment is illustrated according to an illustrative embodiment. Detailed Implementation
[0027] This document will illustrate embodiments in conjunction with example communication systems and associated techniques used for security management in communication systems. However, it should be understood that the scope of the claims is not limited to the specific type of communication system and / or process disclosed. Embodiments can be implemented in a variety of other types of communication systems using alternative processes and operations. For example, although illustrated in the context of wireless cellular systems utilizing 3GPP system elements (such as 3GPP Next Generation Systems (5G)), the disclosed embodiments can be directly adapted to a variety of other types of communication systems, such as 6G communication systems.
[0028] According to illustrative embodiments implemented in a 5G communication system environment, one or more 3GPP Technical Specifications (TS) and Technical Reports (TRs) can provide further explanations of network elements / functions and / or operations that can interact with various parts of the present invention's solution (e.g., 3GPP TS23.501, TS 23.502, and TS 33.501 cited above). Other 3GPP TS / TR documents can provide additional details that will be recognized by those skilled in the art, such as TS 38.300 entitled "Technical Specification Group Radio Access Network; NR; Overall Description of NR and NG-RAN; Phase 2" and TS 38.212 entitled "Technical Specification Group Radio Access Network; NR; Multiplexing and Channel Decoding," the disclosures of which are incorporated herein by reference in their entirety. Note that 3GPP TS / TR documents are non-limiting examples of communication network standards (e.g., specifications, processes, reports, requirements, recommendations, etc.). However, while highly suitable for 5G-related 3GPP standards, the embodiments are not necessarily intended to be limited to any particular standard.
[0029] It should be understood that in some illustrative embodiments, the term "5G network" and the like (e.g., 5G system, 5G communication system, 5G environment, 5G communication environment, etc.) can be understood to include all or part of the access network and all or part of the core network. However, the term "5G network" and the like may sometimes be used interchangeably with the term "5GC network" and the like without loss of generality, as any distinction will be understood by those skilled in the art.
[0030] Before describing the illustrative embodiments, the following will be... Figure 1 and Figure 2 A general description of some of the key components of a 5G network within the context of [the context].
[0031] Figure 1 A communication system 100 in which an illustrative embodiment is implemented is shown. It should be understood that the elements shown in the communication system 100 are intended to represent some of the main functions provided within the system, such as control plane functions, user plane functions, etc. Therefore, Figure 1 The boxes shown refer to specific elements in a 5G network that provide some of these key functions. However, some or all of the indicated key functions can be implemented using other network elements. Furthermore, it should be understood that not all functions of a 5G network are provided in the boxes. Figure 1 The figures below depict only a few features. Instead, at least some functions of the illustrative embodiments are shown for ease of explanation. Subsequent figures may depict additional elements / functions (i.e., network entities).
[0032] Therefore, as shown in the figure, the communication system 100 includes a user equipment (UE) 102 communicating with an access point 104 via an air interface 103. It should be understood that the UE 102 can use one or more other types of access points (e.g., access functions, networks, etc.) to communicate with 5GC networks other than gNBs. By way of example only, the access point 104 can be any 5G access network (gNB), an untrusted non-3GPP access network using non-3GPP interoperability functions (N3IWF), a trusted non-3GPP network using trusted non-3GPP gateway functions (TNGF), or a wired access using wired access gateway functions (W-AGF), or it can correspond to a traditional access point (e.g., an eNB). Furthermore, the access point 104 can be a wireless local area network (WLAN) access point, as will be further explained in the illustrative embodiments described herein.
[0033] UE 102 may be a mobile station, and such a mobile station may include, for example, a mobile phone, a computer, an IoT device, or any other type of communication device. Therefore, the term "user equipment" as used herein is intended to be interpreted broadly to encompass a wide variety of different types of mobile stations, subscriber stations, or more generally, communication devices, including examples such as combinations of data cards inserted into laptops or other equipment such as smartphones. Such communication devices are also intended to encompass devices commonly referred to as access terminals.
[0034] In one illustrative embodiment, UE 102 includes a Universal Integrated Circuit Card (UICC) portion and a Mobile Equipment (ME) portion. The UICC is the user-related portion of the UE and includes at least one Universal Subscriber Identity Module (USIM) and appropriate application software. The USIM securely stores a persistent subscription identifier and its associated key, which is used to uniquely identify and authenticate subscribers on the access network. The ME is the user-independent portion of the UE and includes Terminal Equipment (TE) functionality and various Mobile Terminal (MT) functions. Alternative illustrative embodiments may not use UICC-based authentication, such as a Non-Public (NPN) network.
[0035] Note that in one example, the permanent subscription identifier is the International Mobile Subscriber Identity (IMSI) unique to the UE. In one embodiment, the IMSI is a fixed 15-bit length and consists of a 3-bit Mobile Country Code (MCC), a 3-bit Mobile Network Code (MNC), and a 9-bit Mobile Station Identifier (MSIN). In 5G communication systems, the IMSI is referred to as the Subscription Permanent Identifier (SUPI). When the IMSI is used as the SUPI, the MSIN provides the subscriber identity. Therefore, only the MSIN portion of the IMSI typically needs to be encrypted. The MNC and MCC portions of the IMSI provide routing information used by the serving network to route to the correct home network. When the MSIN of the SUPI is encrypted, it is called the Subscription Hidden Identifier (SUCI). Another example of the SUPI uses the Network Access Identifier (NAI). NAIs are commonly used in IoT communications.
[0036] Access point 104 is illustratively part of the radio access network or RAN of communication system 100. Such a radio access network may include, for example, a 5G system with multiple base stations. Components of the radio access network may be more generally considered as “radio access entities”.
[0037] Furthermore, the access point 104 in this illustrative embodiment is operatively coupled to the Access and Mobility Management Function (AMF) 106. In 5G networks, the AMF 106 particularly supports Mobility Management (MM) and Security Anchor (SEAF) functions.
[0038] In this illustrative embodiment, AMF 106 is operatively coupled to other network functions 108 (e.g., using their services). Other network functions 108 may include network functions that can act as service producers (NFp) and / or service consumers (NFc). Note that any network function can be a service producer for one service and a service consumer for another. Furthermore, when the service being provided includes data, the data-providing NFp is referred to as a data producer, and the data-requesting NFc is referred to as a data consumer. A data producer can also be an NF that generates data by modifying or otherwise processing data produced by another NF. Note that more generally, an NF can be considered a "network entity," thereby a network entity that consumes one or more of the data and services can be considered a "consumer network entity," and a network entity that generates one or more of the data and services can be considered a "producer network entity."
[0039] Note that a UE (e.g., UE 102) typically subscribes to a so-called Home Public Land Mobile Network (HPLMN), where some or all of functions 106 and 108 reside. Alternatively, a UE (e.g., UE 102) may receive services from an NPN on which these functions can reside. The HPLMN is also known as the Home Environment (HE). If the UE is roaming (not in the HPLMMN), it typically connects to a Visited Public Land Mobile Network (VPLMN) (also known as the Visited Network), and the network currently serving the UE is also called the Serving Network. In roaming situations, some of functions 106 and 108 may reside in the VPLMN, in which case the functions in the VPLMN communicate with the functions in the HPLMMN as needed. However, in non-roaming scenarios, access and mobility management function 106 and other network functions 108 reside in the same communication network (i.e., the HPLMMN). Unless otherwise stated, the embodiments described herein are not necessarily limited to which functions reside in which PLMN (i.e., the HPLMMN or the VPLMN).
[0040] Access point 104 is also operatively coupled (via one or more of functions 106 and / or 108) to a Session Management Function (SMF) 110, which is operatively coupled to a User Plane Function (UPF) 112. UPF 112 is operatively coupled to a packet data network, such as the Internet 114. Note that the thicker solid line in this figure represents the User Plane (UP) of the communication network, compared to the thinner solid line representing the Control Plane (CP). It should be understood that... Figure 1The Internet 114 in the diagram may additionally or alternatively represent other network infrastructure, including but not limited to cloud computing infrastructure and / or edge computing infrastructure. Further typical operation and functionality of such network elements are not described herein, as they are not the focus of this illustrative embodiment and can be found in the appropriate 3GPP 5G documentation. Note that the functions shown in 106, 108, 110, and 112 are examples of network functions (NFs).
[0041] It should be understood that this particular arrangement of system components is merely an example, and in other embodiments, additional or alternative components of other types and arrangements may be used to implement the communication system. For example, in other embodiments, the communication system 100 may include other components / functions not explicitly shown herein.
[0042] therefore, Figure 1 The arrangement shown is merely one example configuration for a wireless cellular system, and many alternative configurations of system components can be used. For example, although in Figure 1 The embodiments shown depict only a single element / function, but this is merely for the sake of simplicity and clarity. The given alternative embodiments may, of course, include many more such system elements, as well as additional or alternative elements of the type typically associated with conventional system implementations.
[0043] It should also be noted that, although Figure 1 System components are shown as single functional blocks, but the various subnetworks that make up a 5G network are divided into so-called network slices. A network slice (network partition) is a logical network that provides specific network capabilities and characteristics, which may optionally use Network Function Virtualization (NFV) over a common physical infrastructure to support the corresponding service type. Using NFV, network slices are instantiated according to the needs of a given service (e.g., eMBB service, large-scale IoT service, and mission-critical IoT service). Therefore, when an instance of a network slice or function is created, that network slice or function is instantiated. In some embodiments, this involves installing or otherwise running the network slice or function on one or more host devices in the underlying physical infrastructure. UE 102 is configured to access one or more of these services via access point 104.
[0044] Figure 2 This is a block diagram illustrating the computational architecture for various participants in a method according to an illustrative embodiment. More specifically, system 200 is shown as including user equipment (UE) 202 and multiple entities 204-1, ..., 204-N. For example, in the illustrative embodiment and referring back to reference Figure 1UE 202 may represent UE 102, while entities 204-1, ..., 204-N may represent functions 106 and 108 (i.e., network entities, such as but not limited to AMF) and access point 104 (i.e., radio access entities, such as but not limited to RAN nodes or gNBs). It is understood that UE 202 and entities 204-1, ..., 204-N are configured to interact to provide security management and other technologies described herein.
[0045] User equipment 202 includes a processor 212 coupled to memory 216 and interface circuitry 210. The processor 212 of user equipment 202 includes a security management processing module 214, which may be implemented at least partially as software executed by the processor. The security management processing module 214 performs security management as described in conjunction with the following figures and other methods herein. The memory 216 of user equipment 202 includes a security management storage module 218, which stores data generated or otherwise used during security management operations.
[0046] Each of the entities (referred to herein individually or collectively as 204) includes a processor 222 (222-1, ..., 222-N) coupled to memories 226 (226-1, ..., 226-N) and interface circuitry 220 (220-1, ..., 220-N). Each processor 222 of each entity 204 includes a security management processing module 224 (224-1, ..., 224-N), which may be implemented at least in part as software executed by the processor 222. The security management processing module 224 performs security management operations in conjunction with the following figures and otherwise described herein. Each memory 226 of each entity 204 includes a security management storage module 228 (228-1, ..., 228-N) storing data generated or otherwise used during security management operations.
[0047] Processors 212 and 222 may include, for example, microprocessors, such as central processing units (CPUs), application-specific integrated circuits (ASICs), digital signal processors (DSPs), or other types of processing devices, as well as portions or combinations of these elements.
[0048] Memory 216 and 226 may be used to store one or more software programs executed by the respective processors 212 and 222 to implement at least a portion of the functions described herein. For example, security management operations and other functions, as described in conjunction with the following figures and otherwise described herein, may be implemented directly using software code executed by processors 212 and 222.
[0049] Therefore, a given memory in memories 216 and 226 can be considered as an example of a computer program product more generally referred to herein, or more generally as an example of a computer or processor-readable (non-transitory or storage) medium in which executable program code is embodied. Other examples of computer or processor-readable media may include, in any combination, magnetic disks or other types of magnetic or optical media. Illustrative embodiments may include articles of manufacture comprising such computer program products or other computer or processor-readable media.
[0050] Furthermore, memories 216 and 226 may more specifically include, for example, electronic random access memory (RAM) (such as static RAM (SRAM), dynamic RAM (DRAM)) or other types of volatile or non-volatile electronic memory. The latter may include, for example, non-volatile memory such as flash memory, magnetic RAM (MRAM), phase-change RAM (PC-RAM), or ferroelectric RAM (FRAM). As used herein, the term "memory" is intended to be interpreted broadly and may additionally or alternatively encompass, for example, read-only memory (ROM), disk-based memory, or other types of storage devices, as well as portions or combinations of such devices.
[0051] Interface circuits 210 and 220 illustratively include transceivers or other communication hardware or firmware that allow associated system elements to communicate with each other in the manner described herein.
[0052] from Figure 2 It is evident that user equipment 202 and multiple entities 204 are configured to communicate with each other as security management participants via their respective interface circuits 210 and 220. This communication involves each participant sending data to one or more other participants and / or receiving data from one or more other participants. As used herein, the term "data" is intended to be interpreted broadly to encompass any type of information that can be sent between participants, including but not limited to identity data, key pairs, key indicators, tokens, secrets, security management messages, registration request / response messages and data, request / response messages, authorization and / or authentication request / response messages and data, metadata, control data, audio, video, multimedia, consent data, other messages, etc.
[0053] It should be understood that Figure 2 The specific arrangement of the components shown is merely an example, and many alternative configurations can be used in other embodiments. For example, any given network element / function and / or access point can be configured to incorporate additional or replacement components and support other communication protocols.
[0054] Other system components, such as access point 104, SMF 110, and UPF 112, can each be configured to include components such as processors, memory, and network interfaces. Furthermore, entities such as third-party applications and network operators can participate in the methods described herein via computing devices configured to include components such as processors, memory, and network interfaces. These components and devices do not need to be implemented on separate, independent processing platforms, but can instead represent, for example, different functional portions of a single, common processing platform.
[0055] More generally, Figure 2 This can be considered as representing a processing device configured to provide corresponding security management functions and operatively coupled to each other in a communication system. By way of example only, all or part of each of the UE 202 and the plurality of entities 204 (e.g., processor and memory) can be considered as examples of components for performing one or more operations, one or more steps, one or more functions, one or more processes, etc., as described herein.
[0056] Given the illustrative communication network environment described above, some implementations of communication network architectures (such as 5G New Radio (NR) architecture) that can be implemented in it are now described.
[0057] The 5G NR Radio Access Network (RAN) protocol architecture includes a Media (or sometimes called Media) Access Control (MAC) layer that logically resides above the Physical layer. The MAC layer has various functions, one of which is sending and receiving data and control information in the form of MAC Control Elements (MAC-CEs). 5G NR defines a list of MAC-CEs because these facilitate faster signaling and thus reduce latency in beam switching, Bandwidth Partial (BWP) activation, secondary cell (SCell) activation / deactivation, etc. Currently, MAC-CEs are unprotected and therefore vulnerable to security attacks such as eavesdropping, for example, reading unprotected MAC-CEs and learning the identity and mobility patterns of active SCells, injecting fake MAC-CEs using fake base stations, etc.
[0058] Integrity protection and encryption algorithms are used to protect higher-level data in the RAN protocol stack, such as Radio Resource Control (RRC) and Packet Data Convergence Protocol (PDCP) data.
[0059] 5G NR in RAN has features such as K gNB Exported K RRCint K RRCenc K UPint and K UPenc The master authentication implements mutual authentication between the UE and the network, and provides a key called K. SEAF The anchor key. According to K SEAFCreate K during events such as master authentication or non-access stratum (NAS) key update and key refresh events. AMF Then, when the successful NAS Security Mode Command (SMC) procedure is executed, based on K... AMF Derivation of K NASint and K NASenc Whenever an initial access stratum (AS) security context needs to be established between the UE and gNB, the AMF and UE derive K. gNB and the next-hop parameter (NH). K gNB and NH according to K AMF Derived. For example, Figure 3 A key derivation chain 300 consistent with the above-mentioned TS 38.300 is shown.
[0060] Channel interleaving is a technique used at the physical layer to reduce bit error rate and improve transmission efficiency over fading channels. Channel interleavers distribute the transmitted bit stream to minimize the impact of burst errors. Interleavers are used on the transmitting side, and deinterleavers are used on the receiving side. Various interleaving methods exist (e.g., see TS 38.212 above), including but not limited to: (i) sub-block interleavers, where a row-wise bit sequence is input and a column-wise bit sequence is output; and (ii) bit interleavers, where bit sequences are interleaved to create a specified bit sequence.
[0061] After the Transport Block (TB) interleaving process is performed, the MAC layer multiplexes data from multiple UEs for transmission in each Transmission Time Interval (TTI). The process of multiplexing TBs from the gNB and the decoding process at the UE are briefly explained below.
[0062] In 5G networks, the UE identifies and decodes its TB based on the downlink (DL) data sent by the gNB based on the following mechanisms and processes: (i) Physical Downlink Control Channel (PDCCH): The gNB uses the PDCCH to transmit DL control information (DCI). The UE uses a blind decoding process to monitor the PDCCH to look for possible DCI transmissions. The DCI contains scheduling information, including resource allocation for DL data transmission on the PDCCH and the modulation and coding scheme (MCS).
[0063] DCI also includes a Transport Block Size (TBS) parameter, which provides the size of the TB being transmitted and information related to the Hybrid Automatic Repeat Request (HARQ) process identifier used for error correction and retransmission to improve decoding success.
[0064] This information is crucial for the UE to correctly decode the transport block. The DCI is masked using a unique Radio Network Temporary Identifier (RNTI) for each UE. It is this identifier that allows the UE to identify whether the DCI is intended for it during the blind decoding process.
[0065] (ii) C-RNTI (Cell Radio Network Temporary Identifier): In 5G, various temporary identifiers are used to identify UEs serving specific purposes. The C-RNTI is used to uniquely identify a UE within a cell when it is in the RRC_CONNECTED state and is primarily used during scheduling. Identifying the UE is important in DL and UL communications. The UE assigns a surveillance PDCCH to the DL that addresses its C-RNTI.
[0066] (iii) Physical Downlink Shared Channel (PDSCH): The actual DL data is transmitted on the PDSCH. The UE uses information from the DCI to locate and decode the PDSCH. The PDSCH carries the TB, which the UE decodes using parameters specified in the DCI.
[0067] For example only, Figure 4 This illustrates the correspondence between Packet Data Units (PDUs) and Service Data Units (SDUs) between the aforementioned network protocol layers. An SDU is data received by a layer from the layer above, which is typically modified and subsequently transmitted. For example, the receiving layer converts an SDU into a PDU by adding a header to encapsulate it; the SDU is, for instance, the payload of the PDU. A PDU is the basic data unit transmitted between entities in a communication network environment using a protocol.
[0068] In 5G RAN, encryption and integrity protection for control plane (CP) and user plane (UP) data are performed at the PDCP. However, UP control information, especially MAC-CE, is not currently protected during transmission. This vulnerability could lead to attacks that could impair UE or network operation, affect UE data reception (e.g., transmission configuration indicators or TCI status), track UE location (e.g., SCell activation, selected beam, timing advance, or TA command), or launch denial-of-service (DoS) attacks (e.g., by spoofing beam failure discovery or BFR indications from the UE).
[0069] The illustrative embodiments overcome the above and other technical challenges associated with unprotected control information (especially MAC-CE) by providing improved security management techniques.
[0070] For example, some illustrative embodiments use interleaving techniques to encrypt data with random interleaving block sizes in the MAC layer for security purposes. In co-location deployments, security keys, such as K, have already been generated for the RAN (traditionally). UPenc K RRCenc It can be used as a seed for generating random interleaver block sizes. In some implementations, when deploying a separate gNB, new keys can be derived for the purpose of interleaving-based encryption at the MAC layer. Since these keys are generated independently at the UE and at the gNB, there is no signaling exchange of these keys, thus protecting the keys from detection / access by intruders.
[0071] Advantageously, the interleaving solution is not computationally intensive, thus ensuring that the goal of using low-level signaling in the form of MAC-CE in the RAN to reduce latency is still achieved.
[0072] Using randomness to generate the interleaver size ensures that an intruder cannot establish / predict a pattern of interleaver size after observing UE and RAN signaling exchanges over a long period. Since each MAC layer can be uniquely managed for a given UE and base station, a random interleaving method can be used to protect the MAC layers of all DL and UL channels without any limitations.
[0073] The type of security technology used to encrypt MAC packets can be configured in the UE by the gNB or by the AMF of the serving network using security signaling at the NAS or AS layer. In some illustrative embodiments, the configuration may include the following: (i) The size of the interleaving block to use. For example, 0, 2, 4, 8, and 16 can be interleaving block sizes. Depending on the block size, the implementation will add padding bits as needed to ensure full bit interleaving functionality. Figure 5 Example 500 of encrypting data at the MAC layer using a random interleaving block size according to an illustrative embodiment is shown. Input 502 and output 504 for example 500 are shown. Note that a size of zero would mean no interleaving, and this can be an option for specific scenarios such as testing, if needed.
[0074] (ii) The starting block size to be used to send the first packet at the MAC layer.
[0075] (iii) Periodicity / strategy for changing block size. For example, if the periodicity is 13 MAC packets, the block size can be changed after every 13 packets transmitted at the MAC layer. If the strategy is random, both the UE and the base station (BS) can generate random numbers with a seed value derived from one of the generated RRC layer keys. In some illustrative embodiments, new / different keys can also be generated for random interleaving at the MAC layer. In some embodiments, the probability distribution function to be used by the random number generator can also be part of the strategy configuration. Moreover, which key should be used as the seed can be part of the security strategy configuration. Using these random numbers, both the UE and the BS can independently decide when to change the interleaving block size (e.g., after how many MAC layer transmissions should a new block size be used). With padding, the TB size matches the corresponding interleaving block size.
[0076] As mentioned, Figure 5 Example 500 illustrates interleaving with a block size of 4, including padding bits, as needed. Note that padding is only required if the separability of the block size does not give a remainder of zero. Furthermore, in Example 500, the input bit size is 13 (bits 0 to 12). To match the block size of 4, three padding bits are added to the end as "pad 1, padding 2, padding 3". The input bits, including the padding bits, are arranged in a matrix (502) of column size 4, and then the columns are read to determine the output bit sequence, i.e., the interleaved output bit sequence (504).
[0077] Now for reference Figure 6 Example 600 of a random interleaving function that can be implemented in UE 602 and base station (BS) 604 according to an illustrative embodiment is shown. More specifically, the random interleaving block size determination function in UE 602 can use, for example, K macenc1 As a seed for the random number generator, it can generate the block size for bit interleaving at the MAC layer. Similarly, BS 604 also uses the same key K. macenc1 This serves as the seed for their random number generators. Since both entities use the same seed and the same random number generator with the same probability distribution function (according to the strategy), they will both generate the same block size.
[0078] The function to determine the duration of random interleaving block size change in UE 602 can use, for example, K. macenc2 This serves as the seed for the random number generator. The number generated by this function determines how many MAC packets will be followed by a new block size (again generated using the previously defined random number generator). A similar function in BS 604 uses the same key and is therefore synchronized with UE 602.
[0079] Figure 7Example 700 of a corresponding MAC PDU structure for LTE and 5G NR communication network environments, according to an illustrative embodiment, is shown. Figure 8 Example 800 of a corresponding MAC PDU structure for DL and UL according to an illustrative embodiment is shown. Figure 6 The implementation can differ in the key used for the random interleaving function or in the use of one or two random number generators. For example, some illustrative embodiments may use only sequential block sizes such as 0, 2, 4, 8, 16… but maintain the change in block size after a random number of MAC TB transmissions. A new MAC encryption key (K…) macenc1 and K macenc2 K can be used by UE602 and BS 604 gNB The keys are derived using a unique parameter. This unique parameter can be, for example, the Logical Channel Identifier (LCID) of the first / second MAC sub-PDU. The two keys can be derived using different LCIDs. Which LCID UE 602 needs to use can be determined by BS 604 and provided along with the random MAC interleaving configuration message, which will be described below. Note that it is important that these keys are generated independently by UE 602 and BS 604, without over-the-air transmission. In the case of a separate gNB, these keys can be generated at the same entity that generates other RAN keys. This could be the gNB-CU. In this case, UE 602 does not need to know the separate or non-separate gNB architecture. The UE can independently generate these keys using the same Key Derivation Function (KDF) as the RAN.
[0080] The policy configuration received from the core network can determine which keys to use, the block size of the first MAC TB, etc., as described above. Note that a MAC TB (i.e., MAC PDU) consists of multiple MAC sub-PDUs and / or MAC CEs. This can be obtained from... Figure 8 As can be seen, in transparent MACs (e.g., BCCH on BCH, PCH, DL-SCH, SL-BCH), there is no MAC sub-header. A MAC SDU is aligned to the TB size. The illustrative embodiment provides the interleaving of all bits of the MAC PDU (TB). In some illustrative embodiments, a more complex scheme for random interleaving of MAC sub-PDUs may be used.
[0081] Furthermore, according to the illustrative embodiment, the use of randomness in interleaving can be used for encryption in any man-in-the-middle scenario, and ensures that MAC-CE vulnerabilities can be mitigated, since even the MAC-CE bits will now be interleaved. For shared channels, there is no MAC sub-header, and the receiver can first deinterleave the MAC PDU (or MAC sub-PDU) and then detect the header / sub-header, LCID, and MAC-CE bits. This ensures that the proposed random interleaving method does not affect any conventional methods used for shared or dedicated channels.
[0082] like Figure 7 and Figure 8 Further demonstrating, multiple MAC SDUs and MAC-CEs (sent along with their own sub-headers) can be part of a single MAC PDU. The MAC PDU is encapsulated in a TB and sent to the PHY layer over the transport channel for transmission. MAC sub-PDUs typically begin with a sub-header. Following the sub-header are the MAC SDU, MAC CE, or padding. When a set of MAC sub-PDUs does not completely pad the TB, a MAC sub-PDU with padding is included. A MAC sub-PDU with only a sub-header implies zero-length padding. Only one MAC PDU is allowed within a TB. The MAC SDU, CE, and sub-header are all byte-aligned and multiples of 8 bits. The leftmost bit is the most significant bit. The order of sub-PDUs within a MAC PDU is defined. In sidelinks and uplinks, the concatenated order is MAC SDU, CE, and padding. In downlinks, the order is MAC-CE, SDU, and padding. In all cases, padding is typically the last sub-PDU. MAC SDUs have variable sizes, except for SDUs carrying the UL CCCH. Some MAC-CEs have a fixed size, while others have a variable size.
[0083] Figure 9 Example 900 according to an illustrative embodiment is depicted, illustrating LCID (Logical Channel ID) and eLCID (Extended Logical Channel ID). LCID values and meanings differ for downlink, uplink, and sidelink. In DL-SCH, LCID=0 indicates CCCH. In UL-SCH, LCID values 0 or 52 indicate CCCH. In both DL and UL, values 1-32 indicate the identifier of the logical channel, as the MAC layer multiplexes / demultiplexes RLC PDUs arriving via the logical channel. Many other values indicate that the MAC sub-PDU contains a MAC-CE. LCID=63 is used for padding. Values 33 or 34 suggest that the eLCID field is present in the sub-header.
[0084] Figure 10Example 1000 of numbers generated from the two random generators described above, according to an illustrative embodiment, is shown. Interleaving is performed for each MAC TB to be transmitted to the UE. The gNB (BS) MAC multiplexes multiple UE TBs for transmission in the TTI. As described above, the UE decodes the TB intended for its use based on the DCI information received via the PDCCH.
[0085] Now for reference Figure 11 This illustrates a process flow 1100 for encrypting data using a random interleaving block size in a media access control layer within a communication network environment, according to an illustrative embodiment. Process flow 1100 relates to UE 1100 and gNB 1104. Steps 1-11 of process flow 1100 will now be described.
[0086] Step 1: UE authentication, NAS and AS security context establishment completed.
[0087] Step 2: Based on the gNB architecture, two options are proposed: Option 1: gNB CU-DU Separation: In a gNB-separated architecture, the DU is the most frequently deployed NF in the less secure environment, and transferring encryption keys from the CU to the DU is insecure. Therefore, in one illustrative embodiment, a new key is generated at the gNB DU to seed a random MAC interleaver. Alternatively, it can be recognized that F1AP is a secure signaling service / interface with Internet Protocol Security (IPSec) and other protection mechanisms such as Transport Layer Security (TLS). Critical information can be securely sent from the CU to the DU via the F1AP interface in 5G. Therefore, in another illustrative embodiment, the key is generated at the CU and passed to the DU via a secure interface such as F1AP.
[0088] Option 2: gNB CU-DU co-location: If CU and DU are co-located, the encryption key used for encryption and integrity protection can be used to seed a random MAC interleaver.
[0089] Steps 3 and 4: Perform random MAC interleaving configuration / response between gNB 1104 and UE 1102. This may include configuration for generating keys for MAC interleaving.
[0090] Step 5: For Option 1, i.e., the gNB CU-DU separate architecture, UE 1102 generates a key for seeding the random MAC interleaver after receiving the configuration from the gNB. Similarly, gNB 1104 generates a key for seeding the random MAC interleaver after receiving an acknowledgment from UE 1102.
[0091] Data transmission process: The following steps apply to each packet scheduled for transmission: Step 6: UE 1102 and gNB 1104 each deduce the random interleaving block size according to their configuration.
[0092] Step 7: UE 1102 and gNB 114 each apply block interleaving for the packets scheduled for transmission.
[0093] Interleaving can be applied to the entire group or a specific part of the group, such as MAC-CE.
[0094] Steps 8 and 10: Data transmission of the interleaved MAC TB occurs in UL and DL.
[0095] Steps 9 and 11: The receiving entity (i.e., gNB 1104 or UE 1102) will deinterleave the received packets according to the expected interleaving block size.
[0096] Therefore, one or more illustrative embodiments may include an apparatus comprising at least one processor and at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the apparatus to at least: generate a first random number based on a first cryptographic value; calculate a first data block size based on the first random number; and transmit first data associated with an access control layer of a communication network and consistent with the first data block size.
[0097] In some illustrative embodiments, the apparatus may also be configured to: generate a second random number based on a second cryptographic value; calculate a second data block size based on the second random number; change the data block size to be applied to the second data to be transmitted from a first data block size to a second data block size, the second data being associated with the access control layer of the communication network; and transmit second data consistent with the second data block size.
[0098] In some illustrative embodiments, the apparatus is further configured to: interleave input data bits to generate data blocks of first data based on a first data block size. Similarly, interleaving can be performed on input data bits to generate data blocks of second data based on a second data block size.
[0099] In some illustrative embodiments, the apparatus is further configured to: add one or more padding bits to one or more data blocks within a data block, such that each data block is equal to a first data block size. Similarly, to add one or more padding bits to one or more data blocks within a data block, such that each data block is equal to a second data block size.
[0100] In some illustrative embodiments, the change in data block size is based on a randomly calculated duration and / or a data block size duration strategy.
[0101] In some illustrative embodiments, the first cryptographic value may include a first cryptographic key. The first cryptographic key may include a generated cryptographic key used for calculating the data block size and / or for one or more functions in the communication network other than calculating the data block size.
[0102] In some illustrative embodiments, at least one processor and at least one memory are part of a user equipment's access to a communication network via an access node.
[0103] In some illustrative embodiments, the apparatus may also be configured to: receive security configuration data from the access node for calculating the size of a first data block.
[0104] In some illustrative embodiments, the apparatus may also be configured to receive security configuration data for calculating the size of a first data block from a network function associated with the communication network.
[0105] In some illustrative embodiments, at least one processor and at least one memory are part of an access node of a communication network.
[0106] In one or more other illustrative embodiments, a method may include: generating a first random number based on a first password value at a user equipment associated with a communication network; calculating a first data block size at the user equipment based on the first random number; and transmitting first data from the user equipment to an access node associated with the communication network, the first data being associated with the access control layer of the communication network and having the same first data block size.
[0107] In one or more other illustrative embodiments, a method may include: generating a first random number based on a first cryptographic value at an access node associated with a communication network; calculating a first data block size based on the first random number at the access node; and transmitting first data from the access node to a user equipment associated with the communication network, the first data being associated with the access control layer of the communication network and having the same size as the first data block.
[0108] It should be understood that the specific processing operations and other system functions described in conjunction with the figures herein are presented by way of illustrative example only and should not be construed as limiting the scope of this disclosure in any way. Alternative embodiments may use other types of processing operations and messaging protocols. For example, the ordering of steps may vary in other embodiments, or certain steps may be performed at least partially simultaneously rather than sequentially. Furthermore, one or more steps may be repeated periodically, or multiple instances of the method may be performed in parallel with each other.
[0109] It should be emphasized again that the various embodiments described herein are presented by way of illustrative example only and should not be construed as limiting the scope of the claims. For example, alternative embodiments may utilize different communication system configurations, user equipment configurations, base station configurations, authorization processes, messaging protocols, and message formats than those described above in the context of the illustrative embodiments. These and many other alternative embodiments within the scope of the appended claims will be apparent to those skilled in the art.
Claims
1. A device for safety management, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the device to at least: Generate a first random number based on the first password value; The size of the first data block is calculated based on the first random number; as well as Transmit first data, which is associated with the access control layer of the communication network and has the same size as the first data block.
2. The apparatus of claim 1, wherein the at least one memory stores instructions, the instructions, when executed by the at least one processor, further cause the apparatus to at least: A second random number is generated based on the second password value; The size of the second data block is calculated based on the second random number; The size of the data block to be applied to the second data being transmitted is changed from the size of the first data block to the size of the second data block, and the second data is associated with the access control layer of the communication network; as well as Transmit the second data, which is the same size as the second data block.
3. The apparatus of claim 2, wherein the at least one memory stores instructions, the instructions, when executed by the at least one processor, further cause the apparatus to perform at least one of the following: Interleave input data bits to generate data blocks of the first data based on the first data block size; and The input data bits are interleaved to generate data blocks of the second data based on the size of the second data block.
4. The apparatus of claim 3, wherein the at least one memory stores instructions, the instructions, when executed by the at least one processor, further cause the apparatus to perform at least one of the following: Add one or more padding bits to one or more data blocks in the data block, such that each data block is equal to the size of the first data block; and One or more padding bits are added to one or more data blocks in the data block such that each data block is equal to the size of the second data block.
5. The apparatus of claim 2, wherein the change in the data block size is based on a randomly calculated duration.
6. The apparatus of claim 2, wherein the change in data block size is based on a data block size duration strategy.
7. The apparatus of claim 1, wherein the first cryptographic value includes a first cryptographic key.
8. The apparatus of claim 7, wherein the first cryptographic key comprises a cryptographic key generated for calculating the data block size.
9. The apparatus of claim 7, wherein the first cryptographic key comprises a cryptographic key generated for one or more functions in the communication network other than calculating the data block size.
10. The apparatus of claim 1, wherein the at least one processor and the at least one memory are part of a user equipment accessing the communication network via an access node.
11. The apparatus of claim 10, wherein the at least one memory stores instructions, the instructions, when executed by the at least one processor, further cause the apparatus to at least: Receive security configuration data from the access node for calculating the size of the first data block.
12. The apparatus of claim 10, wherein the at least one memory stores instructions, the instructions, when executed by the at least one processor, further cause the apparatus to at least: Security configuration data for calculating the size of the first data block is received from a network function associated with the communication network.
13. The apparatus of claim 1, wherein the at least one processor and the at least one memory are part of an access node of the communication network.
14. A method for security management, comprising: At the user equipment associated with the communication network, a first random number is generated based on the first password value; At the user equipment, the size of the first data block is calculated based on the first random number; as well as First data is transmitted from the user equipment to an access node associated with the communication network, the first data being associated with the access control layer of the communication network and having the same size as the first data block.
15. The method of claim 14, further comprising: At the user equipment, a second random number is generated based on the second password value; At the user equipment, the second data block size is calculated based on the second random number; At the user equipment, the size of the data block to be applied to the second data being transmitted is changed from the first data block size to the second data block size, and the second data is associated with the access control layer of the communication network; as well as The second data, which is the same size as the second data block, is transmitted from the user equipment to the access node.
16. The method of claim 15, further comprising at least one of the following: At the user equipment, input data bits are interleaved to generate data blocks of the first data based on the first data block size; and At the user equipment, input data bits are interleaved to generate data blocks of the second data based on the second data block size.
17. The method of claim 16, further comprising at least one of the following: At the user equipment, one or more padding bits are added to one or more data blocks within the data block, such that each data block is equal to the size of the first data block; and At the user equipment, one or more padding bits are added to one or more data blocks in the data block such that each data block is equal to the size of the second data block.
18. The method of claim 15, wherein the change in the data block size is based on a randomly calculated duration.
19. The method of claim 15, wherein the change in data block size is based on a data block size duration strategy.
20. The method of claim 14, wherein the first cryptographic value includes a first cryptographic key.
21. The method of claim 20, wherein the first cryptographic key comprises a cryptographic key generated for calculating the data block size.
22. The method of claim 20, wherein the first cryptographic key comprises a cryptographic key generated for one or more functions in the communication network other than calculating the data block size.
23. The method of claim 14, further comprising: The access node receives security configuration data for calculating the size of the first data block at the user equipment.
24. The method of claim 14, further comprising: Security configuration data for calculating the size of the first data block at the user equipment is received from a network function associated with the communication network.
25. A method for security management, comprising: At the access node associated with the communication network, a first random number is generated based on the first cryptographic value; At the access node, the size of the first data block is calculated based on the first random number; as well as First data is transmitted from the access node to a user equipment associated with the communication network. The first data is associated with the access control layer of the communication network and has the same size as the first data block.
26. The method of claim 25, further comprising: At the access node, a second random number is generated based on the second password value; At the access node, the size of the second data block is calculated based on the second random number; At the access node, the size of the data block to be applied to the second data to be transmitted is changed from the first data block size to the second data block size, and the second data is associated with the access control layer of the communication network; as well as The second data, which is the same size as the second data block, is transmitted from the access node to the user equipment.
27. The method of claim 26, further comprising at least one of the following: At the access node, input data bits are interleaved to generate data blocks of the first data based on the first data block size; and At the access node, input data bits are interleaved to generate data blocks of the second data based on the second data block size.
28. The method of claim 27, further comprising at least one of the following: At the access node, one or more padding bits are added to one or more data blocks within the data block, such that each data block is equal to the size of the first data block; and At the access node, one or more padding bits are added to one or more data blocks in the data block such that each data block is equal to the size of the second data block.
29. The method of claim 26, wherein the change in the data block size is based on a randomly calculated duration.
30. The method of claim 26, wherein the change in data block size is based on a data block size duration strategy.
31. The method of claim 25, wherein the first cryptographic value comprises a first cryptographic key.
32. The method of claim 31, wherein the first cryptographic key comprises a cryptographic key generated for calculating the data block size.
33. The method of claim 31, wherein the first cryptographic key comprises a cryptographic key generated for one or more functions in the communication network other than calculating the data block size.