User equipment parameter update head protection
By providing UPU header protection indication in the wireless communication system and using the UPU header as input to calculate UPU-MAC, the problem of missing UPU header integrity protection during the UPU process is solved, and the successful execution of the UPU process and the unified exchange of UPU header protection capabilities are realized.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- LENOVO (SINGAPORE) PTE LTD
- Filing Date
- 2024-09-27
- Publication Date
- 2026-04-21
AI Technical Summary
In wireless communication systems, the lack of integrity protection for the UPU header during the UPU process can lead to UPU failure, and existing solutions have failed to effectively address the issue of UPU header protection capability exchange between the UE and the network.
The network (such as UDM, AUSF) provides the UE with instructions on UPU header protection and uses the UPU header as input to calculate UPU-MAC during the UPU process. The UE generates a confirmation of successful verification, ensuring the integrity protection of the UPU header.
It achieves integrity protection of the UPU header, ensures the successful execution of the UPU process, and uniformly applies and verifies the UPU header protection capability between the UE and the network, thus solving the mismatch problem of UPU header protection in traditional UE and network.
Smart Images

Figure CN121909671A_ABST
Abstract
Description
Related applications
[0001] This application claims priority to U.S. Patent Application Serial No. 18 / 898,172, filed September 26, 2024, entitled "User Equipment Parameter Update Header Protection," the entire contents of which are incorporated herein by reference. U.S. Patent Application Serial No. 18 / 898,172 also claims priority to U.S. Provisional Application Serial No. 63 / 587,021, filed September 29, 2023, entitled "User Equipment Parameter Update Header Protection," the entire contents of which are incorporated herein by reference. Technical Field
[0002] This disclosure relates to wireless communications, and more specifically to the User Equipment (UE) Parameter Update (UPU) process. Background Technology
[0003] A wireless communication system may include one or more network communication devices, such as base stations, which can support wireless communication for one or more user communication devices, which may also be referred to as user equipment (UE) or other suitable terms. The wireless communication system can support wireless communication with one or more user communication devices by utilizing the resources of the wireless communication system (e.g., time resources (e.g., symbols, time slots, subframes, frames, etc.) or frequency resources (e.g., subcarriers, carriers, etc.)). Additionally, the wireless communication system can support wireless communication across a variety of wireless access technologies, including third-generation (3G), fourth-generation (4G), and fifth-generation (5G) wireless access technologies, as well as other suitable wireless access technologies beyond 5G (e.g., sixth-generation (6G)).
[0004] In wireless communication systems, the UPU (User Purchase) process is managed by a unified data management system used to update UE parameters, such as routing indicators, default configuration network slice selection assistance information (NSSAI), disaster roaming information, and mobile device (ME) routing indicators; these are collectively referred to as UPU data. During the UPU process, the UDM (User Request Authentication Server) function (AUSF) generates and provides a Message Authentication Code (MAC) (identified as UPU-MAC-I). AUSF , from K AUSF Export from [source], input is UPU data, length of UPU data, Counter. UPU and Counter UPU (length) for use in UPU data protection. Summary of the Invention
[0005] The article “a” preceding an element is unrestricted and is understood to refer to “at least one element” or “one or more elements” among those elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” are used interchangeably. As used herein, including in the claims, the use of “or” in a list of items (e.g., a list of items beginning with phrases such as “at least one of…,” “one or more of…,” or “one or two of…”) indicates an inclusive list such that, for example, a list of at least one of A, B, or C represents A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Furthermore, as used herein, the phrase “based on” should not be construed as a reference to a closed set of conditions. For example, an example step described as “based on condition A” may be based on both condition A and condition B without departing from the scope of this disclosure. In other words, as used herein, the phrase “based on” should be interpreted in the same manner as the phrase “at least partially based on.” Furthermore, as used herein, including in the claims, “set” may include one or more elements.
[0006] Some implementations of the methods and apparatus described herein may also include a UE for wireless communication to receive a non-access stratum (NAS) message including an indication of UPU header protection; calculate a UPU message authentication code (MAC) using the UPU header as at least one input for UPU protection; and send an acknowledgment indicating successful UPU header verification.
[0007] In some implementations of the methods and apparatus described herein, the UE determines to perform UPU header verification; and calculates the UPU MAC based at least in part on the determination to perform UPU header verification. The UE uses the UPU header as at least one input for UPU protection to calculate the UPU MAC as UPU-MAC-I. AUSF The UE confirms successful UPU header authentication. The UE generates a MAC address (UPU-MAC-I) indicating successful UPU header authentication. UE The UE confirms successful verification of UPU header protection and sends a verification indication of successful UPU header protection verification to the UDM via the Access and Mobility Management Function (AMF). The UE receives a capability request regarding whether it supports UPU header protection and sends a capability response indicating that the UE supports UPU header protection. This capability response is sent to the AMF in a NAS message, which is at least one of an Initial Registration Request message or a Registration Update Request message, and is forwarded by the AMF to the UDM to indicate that the UE supports UPU header protection.
[0008] Some implementations of the methods and apparatus described herein may also include a processor for wireless communication to receive a NAS message including an indication of UPU header protection; calculate a UPU MAC using the UPU header as at least one input for UPU protection; and send an acknowledgment indicating successful UPU header verification.
[0009] In some implementations of the methods and apparatus described herein, the processor determines to perform UPU header verification; and calculates the UPU MAC based at least in part on the determination to perform UPU header verification. The processor uses the UPU header as at least one input for UPU protection to calculate the UPU MAC as UPU-MAC-I. AUSF The processor confirms successful UPU header verification. The processor generates a MAC address indicating successful UPU header verification (UPU-MAC-I). UE The processor determines the successful verification of UPU header protection; and sends a verification indication of successful UPU header protection verification to the UDM via the AMF. The processor receives a capability request regarding whether the UE supports UPU header protection; and sends a capability response indicating that the UE supports UPU header protection. This capability response is sent to the AMF in a NAS message, which is at least one of an initial registration request message or a registration update request message, and is forwarded by the AMF to the UDM to indicate that the UE supports UPU header protection.
[0010] Some implementations of the methods and apparatus described herein may also include a method performed by a UE, the method comprising: receiving a NAS message including an indication of UPU header protection; calculating a UPU MAC using the UPU header as at least one input for UPU protection; and sending an acknowledgment indicating successful UPU header verification.
[0011] In some implementations of the methods and apparatus described herein, the method further includes: determining to perform UPU header verification; and calculating the UPU MAC based at least in part on determining to perform UPU header verification. The method further includes: using the UPU header as at least one input for UPU protection, calculating the UPU MAC as UPU-MAC-I. AUSF The method also includes: determining that the UPU header verification was successful. The method further includes: generating a MAC address (UPU-MAC-I) indicating successful UPU header verification. UEThe method further includes: determining successful verification of UPU header protection; and sending a verification indication of successful UPU header protection verification to the UDM via the AMF. The method also includes: receiving a capability request regarding whether the UE supports UPU header protection; and sending a capability response indicating that the UE supports UPU header protection. This capability response is sent to the AMF in a NAS message, which is at least one of an initial registration request message or a registration update request message, and is forwarded by the AMF to the UDM to indicate that the UE supports UPU header protection.
[0012] Some implementations of the methods and apparatus described herein may also include a network device (NE) (e.g., UDM) for wireless communication to send a request to the AUSF for applying UPU header protection; and to send at least one of a UPU transparency container or UPU header information to the UE, the at least one UPU transparency container or UPU header information including an indication that the UPU header is protected.
[0013] In some implementations of the methods and apparatus described herein, the NE (e.g., UDM) sends a capability request regarding whether the UE supports UPU header protection; and receives a capability response indicating whether the UE supports UPU header protection. The NE sends the capability request regarding whether the UE supports UPU header protection; receives a capability response indicating whether the UE supports UPU header protection; and stores information regarding the UE's capability to support UPU header protection. The NE determines to apply UPU header protection. The request for applying UPU header protection via AUSF includes at least one of the following: a first indication requiring UPU header protection; or a second indication requiring UPU header verification and acknowledgment. The NE sets the acknowledgment requirement indication to confirm that the UE has received and successfully verified the UPU data and UPU header information. The NE sends a relevant indication for UPU header protection to the UE, indicating that the UE uses the UPU header as at least one input for UPU protection to calculate the UPU MAC. This relevant indication indicates that the UE uses the UPU header as at least one input for UPU protection to calculate the UPU MAC as UPU-MAC-I. AUSF The NE generates a transparent UPU container with an indication that UPU header protection is set in the UPU header. The NE determines that UPU header protection is applied; and includes one or more of the following: a UPU dataset type specific to the UPU header information, the length of the UPU dataset specific to the UPU header information, and the UPU header information in the UPU data sent to a UE that supports UPU header protection. The UPU header information included in the UPU data provides integrity protection for the UPU header information. The NE determines that UPU header protection is applied; and includes an indication that the UPU header is protected as part of the UPU data in the UPU header sent to the UE.
[0014] Some implementations of the methods and apparatus described herein may also include a method performed by an (NE) (e.g., a UDM) comprising: sending a request to an AUSF to apply UPU header protection; and sending at least one of a UPU transparency container or UPU header information to a UE, the at least one UPU transparency container or UPU header information including an indication that the UPU header is protected.
[0015] In some implementations of the methods and apparatus described herein, the method further includes: sending a capability request regarding whether the UE supports UPU header protection; and receiving a capability response indicating whether the UE supports UPU header protection. The method further includes: sending a capability request regarding whether the UE supports UPU header protection; receiving a capability response indicating whether the UE supports UPU header protection; and storing information regarding the UE's capability to support UPU header protection. The method further includes: determining whether to apply UPU header protection. The request for applying UPU header protection via AUSF includes at least one of the following: a first indication requiring UPU header protection, or a second indication requiring UPU header verification and confirmation. The method further includes: setting a confirmation requirement indication to confirm that the UE has received and successfully verified the UPU data and UPU header information. The method further includes: sending a relevant indication for UPU header protection to the UE, the relevant indication indicating that the UE uses the UPU header as at least one input for UPU protection to calculate the UPU MAC. The relevant indication indicates that the UE uses the UPU header as at least one input for UPU protection to calculate the UPU MAC as UPU-MAC-I. AUSF The method further includes: generating a UPU transparent container with an indication that UPU header protection is set in the UPU header. The method also includes: determining that UPU header protection is applied; and including one or more of the following: a UPU dataset type specific to UPU header information, the length of the UPU dataset specific to UPU header information, and UPU header information in the UPU data sent to a UE that supports UPU header protection. The UPU header information included in the UPU data provides integrity protection for the UPU header information. The method also includes: determining that UPU header protection is applied; and an indication that the UPU header is protected as part of the UPU data in the UPU header sent to the UE.
[0016] Some implementations of the methods and apparatus described herein may also include a NE (e.g., an AMF) for wireless communication to receive at least one of the following from a UDM: a UPU transparent container or UPU header information including a UPU header protection indication for a UE; and to send the UPU transparent container or UPU header information to the UE.
[0017] In some implementations of the methods and apparatus described herein, the NE (e.g., AMF) sends a UPU transparent container or UPU header information to the UE as a NAS message including an indication of UPU header protection. If a transparent container is not received from the UDM but a UPU header protection indication information element is received, the NE generates a UPU transparent container with a UPU header including the UPU header protection indication.
[0018] Some implementations of the methods and apparatus described herein may also include a method performed by the NE (e.g., AMF), comprising: receiving from the UDM at least one of the following: a UPU transparent container or UPU header information including a UPU header protection indication for the UE; and sending the UPU transparent container or UPU header information to the UE.
[0019] In some implementations of the methods and apparatus described herein, the method further includes: sending a UPU transparent container or UPU header information to the UE as a NAS message including an indication of UPU header protection. The method also includes: if a transparent container is not received from the UDM but a UPU header protection indication information element is received, generating a UPU transparent container with a UPU header including the UPU header protection indication. Attached Figure Description
[0020] Figure 1 Examples of wireless communication systems according to various aspects of this disclosure are shown.
[0021] Figure 2 Examples of UPU process enhancements supporting UPU header protection (as a standalone IE) and related network capability indications are shown in accordance with various aspects of this disclosure.
[0022] Figure 3 Examples of UPU process enhancements supporting UPU header protection as part of UPU data and related network capability indications, according to various aspects of this disclosure, are shown.
[0023] Figure 4 Examples of UEs according to various aspects of this disclosure are shown.
[0024] Figure 5 Examples of processors according to various aspects of this disclosure are shown.
[0025] Figure 6 Examples of network devices (NEs) according to various aspects of this disclosure are shown.
[0026] Figure 7 A flowchart of a method performed by a UE according to various aspects of this disclosure is shown.
[0027] Figure 8A flowchart is shown of a method performed by an NE (e.g., a UDM) according to various aspects of this disclosure.
[0028] Figure 9 A flowchart is shown of a method performed by an NE (e.g., an AMF) according to various aspects of this disclosure. Detailed Implementation
[0029] In wireless communication systems, the UPU process is managed by a unified data management system used to update UE parameters, such as routing indicators, default configuration network slice selection assistance information (NSSAI), disaster roaming information, and ME routing indicators; these are collectively referred to as UPU data. During the UPU process, the UDM requests authentication from the AUSF to generate and provide a MAC (identified as UPU-MAC-I). AUSF , from K AUSF Export from [source], input is UPU data, length of UPU data, Counter. UPU and Counter UPU The length of the header (counter) is used for UPU data protection. Additionally, the UDM transmits the UPU header and Counter data via AMF. UPU UPU data and UPU MAC-I AUSF The UPU header sent to the UE is not protected by any MAC integrity protocol. Any intermediary (e.g., AMF) can alter the bit values of the UPU header, causing the UPU process to fail. It is worth noting that the lack of UPU header protection during the UPU process may lead to malicious tampering of the UPU header value, thus causing the UPU process to fail.
[0030] This disclosure aims to provide several enhanced implementations of UPU header protection during the UE parameter update process of a 3GPP 5G system. By utilizing the described techniques, the network (e.g., UDM, AUSF, via AMF) provides the UE with an indication that the network supports UPU header protection (e.g., and / or that UPU header protection is applied). If the network supports UPU header protection and knows that the UE also supports UPU header protection, the network decides to apply UPU header protection and then sends an indication to the UE that the network supports and applies UPU header protection. If the network supports UPU header protection but does not know whether the user equipment also supports UPU header protection (e.g., if the relevant UE capability is not received from the UE in any early step of the registration process), the network decides not to apply UPU header protection. If the UE supports UPU header protection and receives an indication related to UPU header protection from the network, the UE decides to use the UPU header as the MAC calculation (the same UPU-MAC-I as AUSF). AUSF One of the inputs to verify the MAC received from the network (i.e., UPU-MAC-I).AUSF In addition, the UE can also generate a UPU-MAC-I acknowledgment confirming that the UE has successfully received and verified the UPU header and UPU data. UE It can also send relevant instructions to the network.
[0031] The various aspects of this disclosure are described in the context of wireless communication systems.
[0032] Figure 1 Examples of a wireless communication system 100 according to various aspects of this disclosure are shown. The wireless communication system 100 may include one or more NEs 102, one or more UEs 104, and a core network (CN) 106. The wireless communication system 100 may support various wireless access technologies. In some implementations, the wireless communication system 100 may be a 4G network, such as an LTE network or an LTE-A advanced network. In some other implementations, the wireless communication system 100 may be an NR network, such as a 5G network, a 5G advanced network, or a 5G ultra-wideband (5G-UWB) network. In other implementations, the wireless communication system 100 may be a combination of 4G and 5G networks, or other suitable wireless access technologies, including IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20. The wireless communication system 100 may support wireless access technologies other than 5G, such as 6G. In addition, the wireless communication system 100 can support technologies such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA).
[0033] One or more NEs 102 may be distributed across a geographical area to form a wireless communication system 100. One or more NEs in the NEs 102 described herein may be, include, or may be referred to as network nodes, base stations, network elements, network functions, network entities, radio access networks (RANs), NodeBs, NodeBs (eNBs), next-generation NodeBs, or other suitable terms. NEs 102 and UEs 104 may communicate via a communication link, which may be a wireless or wired connection. For example, NEs 102 and UEs 104 may perform wireless communication (e.g., receiving signaling, sending signaling) via a Uu interface.
[0034] NE 102 can provide a geographic coverage area for which it can support services for one or more UE 104s within that geographic coverage area. For example, NE 102 and UE 104 can support wireless communication of signals associated with services (e.g., voice, video, packet data, messaging, broadcasting, etc.) based on one or more radio access technologies. In some implementations, NE 102 can be mobile, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas associated with the same or different radio access technologies may overlap, but different geographic coverage areas can be associated with different NE 102s.
[0035] One or more UEs 104 may be distributed within a geographical area of the wireless communication system 100. UE 104 may include or be referred to as a remote unit, mobile device, wireless device, remote device, subscriber device, transmitting device, receiving device, or other suitable terms. In some implementations, UE 104 may be referred to as a unit, station, terminal, or client, etc. Alternatively or alternatively, UE 104 may be referred to as an Internet of Things (IoT) device, an Internet of Everything (IoE) device, or a Machine Type Communication (MTC) device, etc.
[0036] UE 104 can support direct wireless communication with other UE 104 via a communication link. For example, UE 104 can support direct wireless communication with another UE 104 via a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link may be referred to as a sidelink. For example, UE 104 can support direct wireless communication with another UE 104 via a PC5 interface.
[0037] A NE 102 may support communication with a CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102s or CN 106s via one or more backhaul links (e.g., S1, N2, N6, or other network interfaces). In some implementations, NE 102s may communicate directly with each other. In some other implementations, NE 102s may communicate indirectly with each other (e.g., via CN 106). In some implementations, one or more NE 102s may include sub-components, such as access network entities, which may be an example of an Access Node Controller (ANC). The ANC may communicate with one or more UEs 104s via one or more other access network transport entities, which may be referred to as radio headends, intelligent radio headends, or transmit-receive points (TRPs).
[0038] CN 106 can support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. CN 106 can be an evolved packet core (EPC) or a 5G core (5GC), which may include control plane entities (e.g., Mobility Management Entity (MME), Access and Mobility Management Function (AMF)) that manage access and mobility, and user plane entities (e.g., Serving Gateway (S-GW), Packet Data Network (PDN) Gateway (P-GW), or User Plane Function (UPF)) that route packets or connect to external networks. In some implementations, the control plane entities may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signaling bearers, etc.), for one or more UEs 104 served by one or more NEs 102 associated with CN 106.
[0039] CN 106 can communicate with the packet data network via one or more backhaul links (e.g., via S1, N2, N6, or other network interfaces). The packet data network may include an application server. In some implementations, one or more UEs 104 can communicate with the application server. UE 104 can establish a session with CN 106 via NE 102 (e.g., a Protocol Data Unit (PDU) session, etc.). CN 106 can use the established session (e.g., an established PDU session) to route traffic (e.g., control information, data, etc.) between UE 104 and the application server. A PDU session can be an example of a logical connection between UE 104 and CN 106 (e.g., one or more network functions of CN 106).
[0040] In the wireless communication system 100, NE 102 and UE 104 can use the resources of the wireless communication system 100 (e.g., time resources (e.g., symbols, time slots, subframes, frames, etc.) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communication). In some implementations, NE 102 and UE 104 can support different resource structures. For example, NE 102 and UE 104 can support different frame structures. In some implementations, such as in 4G, NE 102 and UE 104 can support a single frame structure. In some other implementations, such as in 5G and other suitable radio access technologies, NE 102 and UE 104 can support various frame structures (i.e., multiple frame structures). NE 102 and UE 104 can support various frame structures based on one or more digital technologies.
[0041] One or more digital technologies may be supported in the wireless communication system 100, and the digital technologies may include subcarrier spacing and cyclic prefix. The first digital technology (e.g., μ=0) can be associated with the first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first digital technique (e.g., ...) associated with the first subcarrier spacing (e.g., 15 kHz) is... μ =0) can utilize one time slot per subframe. Second digital technologies (e.g., μ =1) can be associated with the second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. The third digital technology (e.g., μ =2) can be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth digital technology (e.g., μ =3) can be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth digital technology (e.g., μ =4) can be associated with the fifth subcarrier spacing (e.g., 240 kHz) and the normal cyclic prefix.
[0042] The time intervals of resources (e.g., communication resources) can be organized according to frames (also called radio frames). Each frame can have a duration, for example, 10 milliseconds (ms). In some implementations, each frame can include multiple subframes. For example, each frame can include 10 subframes, and each subframe can have a duration, for example, 1 ms. In some implementations, each frame can have the same duration. In some implementations, each subframe of a frame can have the same duration.
[0043] Alternatively or concurrently, the time intervals of resources (e.g., communication resources) can be organized according to time slots. For example, a subframe may include a certain number (e.g., quantity) of time slots. The number of time slots in each subframe may also depend on one or more digital technologies supported in the wireless communication system 100. For example, a first digital technology, a second digital technology, a third digital technology, a fourth digital technology, and a fifth digital technology (i.e., ...) associated with corresponding subcarrier intervals of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz. μ =0、 μ =1、 μ =2、 μ =3、 μ=4) One time slot per subframe, two time slots per subframe, four time slots per subframe, eight time slots per subframe, and 16 time slots per subframe can be used, respectively. Each time slot can include a certain number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of time slots in a subframe can depend on the digital technology. For a normal cyclic prefix, a time slot can include 14 symbols. For an extended cyclic prefix (e.g., for a 60 kHz subcarrier spacing), a time slot can include 12 symbols. The relationship between the number of symbols per time slot, the number of time slots per subframe, and the number of time slots per frame for both normal and extended cyclic prefixes can depend on the digital technology. It should be understood that for the first digital technology (e.g., quantity) associated with the first subcarrier spacing (e.g., 15 kHz), μ The reference of =0 can be used interchangeably between subframes and time slots.
[0044] In the wireless communication system 100, the electromagnetic (EM) spectrum can be divided into various categories, frequency bands, frequency channels, etc., based on frequency or wavelength. For example, the wireless communication system 100 can support one or more operating frequency bands, such as frequency range names FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, NE 102 and UE 104 can perform wireless communication on one or more operating frequency bands. In some implementations, FR1 can be used by NE 102 and UE 104, as well as other devices or apparatuses, for cellular communication services (e.g., control information, data). In some implementations, FR2 can be used by NE 102 and UE 104, as well as other devices or apparatuses, for short-range, high data rate capabilities.
[0045] FR1 can be associated with one or more digital technologies (e.g., at least three digital technologies). For example, FR1 can be associated with the following: a first digital technology (e.g., μ =0), which includes a 15 kHz subcarrier spacing; second digital technology (e.g., μ =1), which includes a 30 kHz subcarrier spacing; third digital technology (e.g., μ =2), which includes a subcarrier spacing of 60 kHz. FR2 can be associated with one or more digital technologies (e.g., at least two digital technologies). For example, FR2 can be associated with a third digital technology (e.g., μ=2), which includes a 60 kHz subcarrier spacing; and a fourth digital technology (e.g., μ =3), which includes a subcarrier spacing of 120 kHz.
[0046] Depending on the implementation, one or more of NE 102 and UE 104 are operable to implement various aspects of the technology described with reference to this disclosure. For example, NE 102 (e.g., UDM) transmits (e.g., sends) a request to AUSF for applying UPU header protection, and sends a UPU transparency container and / or UPU header information to UE 104. The UPU transparency container and / or UPU header information includes an indication that the UPU header is protected. UE 104 receives a NAS message including the indication of UPU header protection, calculates the UPU MAC using the UPU header as at least one input for UPU protection, and sends an acknowledgment indicating successful UPU header verification. In another example, NE 102 (e.g., AMF) receives at least one of a UPU transparency container or UPU header information from UDM, which includes an indication of UPU header protection for UE 104, and sends the UPU transparency container or UPU header information to the UE.
[0047] Regarding the UPU process, the UDM (via AMF) sends a UE parameter update transparent container to the UE. This UE parameter update transparent container includes a UPU header to indicate various information, such as an acknowledgment (ACK) value, which indicates whether an acknowledgment from the UE is requested (i.e., acknowledgment of successful reception of the UPU data list); and a re-registration (REG) value, which indicates whether a re-registration from the UE is requested, etc. Acknowledgment (ACK) value (4th byte, 2nd bit) 0: No confirmation requested; 1: Confirmation requested. Re-register (REG) value (4th byte, 3rd bit) 0 No re-registration requested, 1 Request re-registration It should also be noted that if the UDM sends a separate information element (IE) related to the UPU based on the received information (such as in this case), and if the AMF supports it, the UDM can generate and send a "UE parameter update transparent container" to the UE.
[0048] Regarding the "UE Parameter Update Transparent Container," the UPU transparent container (via AMF) is sent from the UDM to the UE. For example, the UE parameter update transparent container information element for a UE parameter update data type with a value of "0": And an example of a UE parameter update header for a UE parameter update data type with a value of "0":
[0049] In another example, the UPU transparent container (via AMF) is sent from the UE to the UDM. For instance, the transparent container information element is updated for a UE parameter with a value of "1" and an update data type. And an example of a UE parameter update header for a UE parameter update data type with a value of "1":
[0050] Regarding the UE parameter update capability check, the previous description is in UPU-MAC-I. AUSF The calculation uses the UPU header as an additional input to provide UPU header protection, but this requires support from both the UE and the network. This may become possible in newer 5G versions (e.g., version 19 and later), but the solution is not complete. For example, limitations of legacy UEs (i.e., older UEs) and legacy networks do not support using the UPU header as UPU-MAC-I on the network side. AUSF The solution does not explain how UE and network capabilities (supported in newer features) regarding UPU header protection are exchanged between the UE and network. Therefore, applying UPU header protection in scenarios involving legacy UEs and / or legacy networks is not feasible. For example, if the network supports UPU header protection, the UDM could send a UPU-MAC-I calculated using the UPU header as one of the inputs. AUSF However, if the receiving UE is a legacy UE that does not support UPU header protection, the UE will generate a UPU-MAC-I that does not use the UPU header as input. AUSF The calculated UPU-MAC-I AUSF Will be connected with the received UPU-MAC-I AUSF Mismatch, therefore UPU-MAC-I AUSF The verification will fail.
[0051] Regarding previous documentation related to UPU header protection, the UE has informed the UDM that it supports UPU header information in UPU data. If the UE supports receiving UPU header information in UPU data, the UDM should further include the UPU header information in the UPU data. Including the UPU header information in the UPU data can provide integrity protection for that information. If the UPU data contains UPU header information, the UE should use that information as the UPU header and operate accordingly.
[0052] However, this solution attempts to avoid the influence of AUSF by placing the "UPU header" inside the "UPU data," thereby enabling AUSF to generate UPU-MAC-I using existing inputs. AUSF This also indirectly protects the UPU header, as it is located within the UPU data and participates in UPU-MAC-I. AUSF The generation of this solution involves the UE informing the network that it supports "UPU header information in UPU data," but the network does not provide the UE with any UPU header protection capabilities. If the UE is connected to a 5G system with legacy AUSF and UDM (i.e., an older system), the network (i.e., AUSF, UDM) cannot protect the UPU header. Even if the UE informs the network that it supports UPU header protection in UPU data, legacy network functions cannot understand the UE's new capabilities. Furthermore, when the UE receives UPU-MAC-I from the network... AUSF At this time, the UE will assume that the UPU header is protected in the UPU data and will calculate the UPU-MAC-I by placing the "UPU header" in the "UPU data". AUSF However, the UPU-MAC-I calculated by the UE AUSF The UPU-MAC-I calculated by the receiving network will be used. AUSF Mismatch, and UPU-MAC-I AUSF The verification will fail.
[0053] In various aspects of this disclosure, the described implementations provide several enhancements for UPU header protection during the UE parameter update process for 3GPP 5G systems: • The network (e.g., UDM, AUSF, via AMF) provides the UE with an indication that the network supports UPU header protection (e.g., and / or UPU header protection is applied). • If the network supports UPU header protection, and if it is aware that the UE also supports UPU header protection, the network determines that UPU header protection should be applied, and then sends an instruction to the UE that the network supports and applies UPU header protection. • If the network supports UPU header protection but is unaware that the UE also supports UPU header protection (e.g., if the relevant UE capability is not received from the UE in any early step of the registration process), the network determines that UPU header protection should not be applied. • If the UE supports UPU header protection, and if it receives a UPU header protection related indication from the network, the UE determines the calculation in MAC (the same UPU-MAC-I as AUSF). AUSF The UPU header is used as one of the inputs to verify the MAC received from the network (i.e., UPU-MAC-I). AUSF ). • In addition, the UE can also generate a UPU-MAC-I acknowledgment that the UE has successfully received and verified the UPU header and UPU data. UE It can also send relevant instructions to the network.
[0054] In various aspects of this disclosure, one implementation informs the network of UPU header protection capabilities and applies UPU header protection (with implications for AUSF). This describes how the network's ability to support UPU header protection is indicated to the UE, and how UPU header protection is uniformly applied and verified between the UE and the network during the UPU process.
[0055] Figure 2 illustrates an example 200 of UPU process enhancements supporting UPU header protection (as a standalone IE) and related network capability indications according to various aspects of this disclosure.
[0056] At step 0, the UE 104, which supports UPU header protection, sends an indication to the access and AMF 202 in any NAS / N1 message regarding the UE's ability to support UPU header protection. The AMF may send or forward the received indication regarding the UE's ability to support UPU header protection to the UDM 206 in any Nudm service operation message or any Namf service operation message.
[0057] At step 1, the UDM determines that a UPU will be performed using a control plane procedure when the UE registers with the 5G system. If the end consumer of any UE parameters to be updated (e.g., updated routing ID data) is the USIM, the UDM protects these parameters using a secure packet mechanism to update the parameters stored on the USIM. The UDM then prepares UE parameter update data (UPU data) by including the parameters (if any) protected by secure packets and any UE parameters whose end consumer is the ME. If the UDM supports UPU header protection, and if the UDM has previously received an indication of UE capability for any UE that it supports UPU header protection (during any authentication or registration process, or during subscription data management), the UDM determines to apply UPU header protection.
[0058] At steps 2 and 3, the UDM can obtain the UPU-MAC-I by invoking the Nausf_UPUProtection service operation message by including the UPU data in the AUSF 204. AUSF and Counter UPU The UDM can choose to hold the latest K of the UE. AUSFThe UDM determines that the UE has successfully verified the security check of the received UPU data. If the UDM includes an ACK indication in the Nausf_UPUProtection service operation message, it signals that the UE also requires the expected UPU-XMAC-I. UE If the UDM determines that the UPU header should be protected by AUSF, the UDM also includes a UPU header protection indication, and may include the UPU header in the Nausf_UPUProtection service operation message to signal AUSF in UPU-MAC-I. AUSF The UPU header is required during generation. (In UPU-MAC-I) AUSF The calculation includes a UE parameter update header, which allows the UE to verify that it has not been tampered with by any intermediary.
[0059] Details of CounterUPU will be referenced below. Figure 3 Describe it. In UPU-MAC-I AUSF The calculation includes UPU data, allowing the UE to verify that it has not been tampered with by any intermediary. Expected UPU-XMAC-I UE Allow UDM to verify that the UE correctly receives UPU data. As described below, AUSF uses the UE-specific home key (K). AUSF The UPU-MAC-I is calculated from the UPU data received from the requested network function and the UPU header (if received or generated automatically based on the UPU header protection indication). AUSF and UPU-MAC-I AUSF and Counter UPU Delivered to NF. If an ACK indication input is present, AUSF also calculates UPU-XMAC-I. UE The response returns the calculated UPU-XMAC-I. UE As an alternative or supplement, the expected UPU-XMAC-I UE The calculation may also include a UPU header verification acknowledgment that “UE successfully verified the UPU header”, which allows the UDM to verify that the UE correctly received the UPU header.
[0060] Regarding the enhanced UPU-MAC-I AUSF Generating functions, when from K AUSF Export UPU-MAC-I AUSFAt this time, the following parameters are used by AUSF to form the input S of the Key Derivation Function (KDF): FC = 0x7B; P0 = UE parameter update data (i.e., the UE parameter update list (starting from the 23rd octet)); L0 = length of the UE parameter update data; P1 = CounterUPU; L1 = length of the CounterUPU; P2 = UPU header; L2 = length of the UPU header; and the input key Key is K. AUSF UPU-MAC-I AUSF The 128 least significant bits of the output identified by KDF.
[0061] Regarding the enhanced UPU-MAC-I UE / UPU-XMAC-I UE Generating functions, when from K AUSF Export UPU-MAC-I UE / UPU-XMAC-I UE At this time, the following parameters are used by AUSF to form the input S of KDF. FC = 0x7C; P0 = 0x01 (UPU confirmation: successful verification of UE parameter update data); L0 = length of UPU confirmation (i.e., 0x00 0x01); P1 = CounterUPU; L1 = length of CounterUPU; P0 = 0x02 (UPU header confirmation: successful verification of UE parameter update header); L0 = length of UPU header confirmation (i.e., 0x00 0x01); The input key Key can be KAUSF. UPU-MAC-I UE / UPU-XMAC-I UE The 128 least significant bits of the output identified by KDF.
[0062] In step 4, the UDM invokes the Nudm_SDM_Notification service operation. If the AMF supports the UPU transparent container, this service operation includes the UPU transparent container; otherwise, it includes separate IEs containing the UPU header protection indication, UPU header, UE parameter update data, and UPU-MAC-I within the access and mobility subscription data. AUSF and Counter UPU If the UDM requests confirmation, its temporary storage will contain the expected UPU-XMAC-I. UE If the UDM includes a transparent UPU container, the UPU header may include UPU header protection (support / enable) related indications as shown below.
[0063] At step 5, based on the received Nudm_SDM_Notification message, the AMF sends a DLNAS transport message to the served UE. The AMF includes a transparent container in the DL NAS transport message (if received from the UDM in step 4). Otherwise, if the UDM provides a separate IE in step 4, the AMF constructs a UPU transparent container by including a UPU header and a UPU header protection indication (if these information elements (IE) are received from the UDM in step 4).
[0064] At step 6, based on the received DL NAS transmission message, the UE updates the received UE parameter data, UPU header (if UPU header protection was indicated and received in step 5), and Counter in the same manner as AUSF (as shown in steps 2-3). UPU Calculate UPU-MAC-I AUSF And verify whether it matches the UPU-MAC-I received within the UPU transparent container in the DL NAS transmission message. AUSF Value match. If UPU-MAC-I AUSF If the verification is successful and the UPU data contains any parameters protected by a secure packet, the ME can forward the secure packet to the USIM using the given procedure. If UPU-MAC-I AUSF If the verification is successful and the UPU data contains any parameters not protected by security groups, then the ME can update its stored parameters to the parameters received in the UDM update data.
[0065] In step 7, if the UDM has requested acknowledgment from the UE, and (i) the UE has successfully verified and updated the UE parameter update data provided by the UDM, and (ii) if the UE has successfully verified the UE parameter update header provided by the UDM, then the UE can send a UL NAS transmission message to the serving AMF. Then, the UE generates a UPU-MAC-I... UE (As described in steps 2-3, the same as AUSF), and generate UPU-MAC-I UE Included in the transparent container for UL NAS transmission messages. The UE can also send an indication or message of successful UPU header verification within the transparent container for UL NAS transmission messages.
[0066] Alternatively, if the UE sends a UPU transparent container, the UE can indicate in the UPU header either "UPU header protection verification successful / UPU header protected by UE" or "UPU header protection verification unsuccessful / UPU header not protected by UE", as shown below. Alternatively, if the UE supports UPU header protection, and if the UE calculates the UPU-MAC-I... UEWith the received UPU-MAC-I AUSF If there is a mismatch, regardless of whether the UE receives the UPU header protection indication from the UDM, the UE sends a message indicating that the UPU header verification failed and sets the relevant bits in the UPU header, as shown below. The response in step 7 includes the message indicating that the UPU header verification failed.
[0067] At step 8, if a UPU-MAC-I message is received in the UL NAS transmission message... UE If a transparent container with a UPU header verification success indication or information is received, the AMF sends a Nudm_SDM_Info request message containing that transparent container to the UDM. Alternatively, if a UPU-MAC-I header is received in the UL NAS transport message... UE If the AMF has a transparent container for indicating or indicating that the UPU header verification failed, the AMF can send a Nudm_SDM_Info request message containing that transparent container to the UDM.
[0068] In step 9, if the UDM instructs the UE to confirm that the security check of the received UE parameter update data was successful, and if the UDM receives an indication or message indicating successful UPU header verification, then the UDM will send the received UPU-MAC-I... UE With the expected UPU-XMAC-I temporarily stored by UDM in step 4 UE The comparison is then performed. Alternatively, if the UDM receives an indication or message that the UPU header verification failed in step 9, the UDM can record the message and retry the UPU process based on its local policy. If the UDM supports home-triggered authentication, it can determine whether to trigger primary authentication to refresh the UPU counter based on the counter value received in step 3, according to its local policy.
[0069] This example illustrates the UE parameter update header (network to UE) for UE parameter update data types with a value of "0": The UE parameter update transparent container information element Option 1: UPU Head Protection Indicator (UPU HPI) value (4th octet, 4th bit) 0 - UPU head is not protected or UPU head protection is not supported / enabled 1- UPU head protection or UPU head protection support / enable Option 2: UPU Head Protection Indicator (UPU HPI) value (4th octet, xth bit) – General definition covering both “network to UE” and “UE to network” cases (shown in the two examples below). 0 - UPU header is protected by network 1 - The UPU header is protected by the UE.
[0070] The alternative example illustrates UPU header enhancement (which will be sent from the network to the UE):
[0071] Another example illustrates UPU header enhancement with a UE parameter update header for a UE parameter update data type with a value of "1" (from UE to network), (UE to network): Option 3: UPU Head Protection Indicator (UPU HPI) value (4th octet, 2nd bit) 0 - The UPU header is not protected by the UE or the UPU header verification at the UE failed. 1 - The UPU header is protected by the UE or the UPU header is successfully verified at the UE.
[0072] In this disclosure, one implementation notifies the network of UPU header protection capabilities and applies UPU header protection (in the absence of AUSF impact). This describes how to indicate to the UE that the network supports UPU header protection capabilities without impacting AUSF, and how to uniformly apply and verify UPU header protection between the network and the UE during the UE parameter update (UPU) process.
[0073] Figure 3 Example 300 is shown, which supports UPU header protection as part of UPU data and related network capability indications according to various aspects of this disclosure.
[0074] At step 0, UE 104 notifies UDM 306 (e.g., during the authentication or registration process) of the UPU header information in its supporting UPU data or the UE's UPU header protection capability indication.
[0075] At step 1, when the UE registers with the 5G system, the UDM determines to perform a UPU using a control plane procedure. If the end consumer of any UE parameters to be updated (e.g., updated routing ID data) is the USIM, the UDM protects these parameters using a secure packet mechanism to update the parameters stored on the USIM. The UDM can then prepare UE parameter update data (UPU data) by including the parameters protected by secure packets (if any) and any UE parameters whose end consumer is the ME. If the UE supports receiving UPU header information in the UPU data, or if the UE supports the capability of UPU header protection, the UDM may also include the UPU header information in the UPU data (as shown below). If the UDM supports UPU header protection, and if the UDM previously (during any authentication or registration process, or during subscription data management) received a UE capability indication for any UE that indicates the UE supports "UPU header protection (as part of UPU data)" or "UPU header information in UPU data," the UDM determines to apply UPU header protection. Including UPU header information in the UPU data provides integrity protection for that information.
[0076] In steps 2 and 3, the UDM invokes the Nausf_UPUProtection service operation message by including the UPU data in an AUSF 304 call to obtain the UPU-MAC-I. AUSF and Counter UPU The UDM can choose to hold the latest K of the UE. AUSF The UDM determines that the UE has successfully verified the security check of the received UPU data. If the UDM determines that the security check was successful, the UDM can include an ACK indication in the Nausf_UPUProtection service operation message to signal that the expected UPU-XMAC-I is still required. UE As described in the specification. Alternatively, if the UDM determines that the UE acknowledges the successful security checks of the received UPU data and UPU header, the UDM may include an ACK indication in the Nausf_UPUProtection service operation message (for cases where both UPU data and UPU header security checks are successful) to signal that it also requires the expected UPU-XMAC-I for this situation. UE Counter UPU The details are as follows. In UPU-MAC-I AUSF The calculation includes UPU data, allowing the UE to verify that it has not been tampered with by any intermediary. Expected UPU-XMAC-I UE Allow UDM to verify that the UE is correctly receiving UPU data.
[0077] Regarding the UE parameter update counter (Counter) UPU AUSF and UE will use a 16-bit counter. UPU With key K AUSF Related. When the newly exported K AUSF When stored, the UE will use Counter UPU Initialize to 0x00 0x00. The UE stores the UPU counter. If the USIM supports both 5G parameter storage and 5G parameter extended storage, then the Counter... UPU It will be stored in the USIM. Otherwise, Counter UPU Stored in the non-volatile memory of the ME. To generate UPU-MAC-I AUSF AUSF uses Counter UPU For UPU-MAC-I AUSF Each new calculation, Counter UPU It can be incremented by AUSF. As mentioned above, Counter UPU Used as UPU-MAC-I AUSF and UPU-MAC-I UE Freshness input in the derivation to mitigate replay attacks. AUSF will (used to generate UPU-MAC-I) AUSF Counter UPU Value along with UPU-MAC-I AUSF Send them together to the UE. The UE only accepts Counters larger than those stored. UPU Value Counter UPU Value. Then, only if the received UPU-MAC-I AUSF Only when the verification is successful will the UE utilize the received Counter. UPU Update the stored Counter UPU The UE exports the UPU-MAC-I used for UE parameter update data confirmation. UE When using the Counter received from UDM UPU .
[0078] AUSF and UE in K AUSF Maintain Counter throughout its lifecycle UPU AUSF supports updating UE parameters using control plane procedures, when the newly exported K... AUSF When stored, Counter UPU Initialized to 0x00 0x01. AUSF can be used in the first calculated UPU-MAC-I. AUSF Then Counter UPUSet to 0x00 0x02, and for each additionally calculated UPU-MAC-I AUSF Counter UPU Monotonically increasing. A UPU counter with a value of 0x00 will not be used to calculate UPU-MAC-I. AUSF and UPU-MAC-I UE If with UE's K AUSF Related Counter UPU The UE is about to wrap around, and AUSF will suspend the UE parameter update protection service for this UE. When a new K is generated for the UE... AUSF At that time, the Counter at AUSF UPU The reset is set to 0x000x01 as defined above, and AUSF resumes the UE parameter update protection service for this UE.
[0079] Regarding the enhanced UPU-MAC-I AUSF Generating functions, when from K AUSF Export UPU-MAC-I AUSF At this time, the following parameters are used by AUSF to form the input S of KDF. FC = 0x7B; P0 = UE parameter update data (i.e., the UE parameter update list, starting from the 23rd octet) and UPU header; L0 = length of UE parameter update data; P1 = CounterUPU; L1 = length of CounterUPU; the input key Key is K. AUSF UPU-MAC-I AUSF The 128 least significant bits of the output identified by KDF.
[0080] Regarding the enhanced UPU-MAC-I UE / UPU-XMAC-I UE Generating functions, when from K AUSF Export UPU-MAC-I UE / UPU-XMAC-I UE At this time, the following parameters are used by AUSF to form the input S of KDF. FC = 0x7C; P0 = 0x02 (UPU confirmation: successful verification of UE parameter update data and successful verification of UE parameter update header); L0 = length of UPU confirmation (i.e., 0x00 0x02); P1 = CounterUPU; L1 = length of CounterUPU; the input key Key is K. AUSF UPU-MAC-I UE / UPU-XMAC-I UE The 128 least significant bits of the output identified by KDF.
[0081] At step 4, the UDM can invoke the Nudm_SDM_Notification service operation. If the AMF supports the UPU transparent container, the service operation includes the UPU transparent container; otherwise, it includes separate IEs containing the UE Parameter Update Header (UPU Header) protection indication, UPU header, UE parameter update data, and UPU-MAC-I within the access and mobility subscription data. AUSF and Counter UPU If the UDM requests confirmation, it should temporarily store the expected UPU-XMAC-I. UE Alternatively, the UE Parameter Update Header (UPU Header) protection indication may be referred to as UPU Data with UPU Header or UPU Header in UPU Data Protection Indication.
[0082] At step 5, based on the received Nudm_SDM_Notification message, AMF 302 can send a DL NAS transport message to the served UE. If AMF received the transparent container from UDM in step 4, it can include the transparent container in the DL NAS transport message. Otherwise, if UDM provides a separate IE in step 4, AMF can construct the UPU transparent container by including the UPU header and UPU header protection indication (if these information elements (IE) are received from UDM in step 4).
[0083] At step 6, based on the received DL NAS transmission message, the UE can update the received UE parameter data, UPU header (if UPU header protection was indicated in the received step 5 and the UE supports the UPU header protection capability described in step 0), and Counter in the same manner as AUSF (as shown in steps 2-3). UPU Calculate UPU-MAC-I AUSF And verify whether it matches the UPU-MAC-I received within the UPU transparent container in the DL NAS transmission message. AUSF Value match. If UPU-MAC-I AUSF If the verification is successful and the UPU data contains any parameters protected by a secure packet, the ME should forward the secure packet to the USIM using the given procedure. If UPU-MAC-I AUSF If the verification is successful and the UPU data contains any parameters not protected by a security packet, the ME should update its stored parameters using the parameters in the received UDM update data. If the UPU data contains UPU header information, the UE should use this information as the UPU header and perform the corresponding operation.
[0084] In step 7, if the UDM has requested acknowledgment from the UE, and (i) the UE has successfully verified and updated the UE parameter update data provided by the UDM, and (ii) the UE has successfully verified the UE parameter update header provided by the UDM, then the UE can send a UL NAS transmission message to the serving AMF. The UE can generate a UPU-MAC-I UE (As shown in steps 2-3, the same as AUSF), and the generated UPU-MAC-I UE This is included in the transparent container of the UL NAS transmission message. The UE can also send an indication or message indicating successful UPU header verification within the transparent container of the UL NAS transmission message. Alternatively, if the UE sends a transparent UPU container, the UE can accordingly indicate in the UPU header "UPU header protection verification successful or UPU header protected by the UE" or "UPU header protection verification unsuccessful or UPU header not protected by the UE," as shown above. Alternatively, if the UE supports UPU header protection, and if the UE calculates the UPU-MAC-I... UE With the received UPU-MAC-I AUSF If there is a mismatch, regardless of whether the UE receives the UPU header protection indication from the UDM, the UE sends a message indicating that the UPU header verification failed and sets the relevant bits in the UPU header as shown above. The response in step 7 includes the message indicating that the UPU header verification failed.
[0085] At step 8, if a UPU-MAC-I message is received in the UL NAS transmission message... UE If a transparent container containing a UPU header verification success indication or information is received, the AMF can send a Nudm_SDM_Info request message with that transparent container to the UDM. Alternatively, if a UPU-MAC-I header is received in the UL NAS transport message... UE If the AMF has a transparent container for indicating or indicating that the UPU header verification failed, the AMF can send a Nudm_SDM_Info request message containing that transparent container to the UDM.
[0086] In step 9, if the UDM instructs the UE to confirm that the security check of the received UE parameter update data was successful, and if the UDM receives an indication or message indicating successful UPU header verification, then the UDM will send the received UPU-MAC-I... UE With the expected UPU-XMAC-I temporarily stored by UDM in step 4 UEThe comparison is then performed. Alternatively, if the UDM receives an indication or message that the UPU header verification failed in step 9, the UDM can record the message and retry the UPU process based on its local policy. If the UDM supports home-triggered authentication, it can determine whether to trigger primary authentication to refresh the UPU counter based on the counter value received in step 3, according to its local policy.
[0087] The example illustrates a UE parameter update list that includes a UPU header with a new data type specific to the UPU header information, as well as length information associated with the UPU header, which is included as part of the UPU data (i.e., the UE parameter update list) as the new UPU data type:
[0088] Figure 4 illustrates an example of a UE 400 according to various aspects of this disclosure. The UE 400 may include a processor 402, a memory 404, a controller 406, and a transceiver 408. The processor 402, memory 404, controller 406, or transceiver 408, or various combinations thereof, or various components thereof, may be examples of parts for performing various aspects of this disclosure described herein. These components may be coupled via one or more interfaces (e.g., operatively, communicatively, functionally, electronically, electrically).
[0089] Processor 402, memory 404, controller 406, or transceiver 408, or various combinations or components thereof, may be implemented in hardware (e.g., a circuit system). This hardware may include a processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof, configured or otherwise supporting components for performing the functions described in this disclosure.
[0090] Processor 402 may include intelligent hardware devices (e.g., a general-purpose processor, DSP, CPU, ASIC, FPGA, or any combination thereof). In some implementations, processor 402 may be configured to operate memory 404. In other implementations, memory 404 may be integrated into processor 402. Processor 402 may be configured to execute computer-readable instructions stored in memory 404 to cause UE 400 to perform various functions of this disclosure.
[0091] Memory 404 may include volatile or non-volatile memory. Memory 404 may store computer-readable, computer-executable code, including instructions that, when executed by processor 402, cause UE 400 to perform the various functions described herein. This code may be stored in a non-transitory computer-readable medium, such as memory 404 or other types of memory. Computer-readable media include non-transitory computer storage media and communication media, including any medium that facilitates the transfer of computer programs from one place to another. Non-transitory storage media may be any available medium that can be accessed by a general-purpose computer or a special-purpose computer.
[0092] In some implementations, processor 402 and memory 404 coupled to processor 402 may be configured to cause UE 400 to perform one or more functions described herein (e.g., execute instructions stored in memory 404 via processor 402). For example, processor 402 may support wireless communication at UE 400 according to the examples disclosed herein. UE 400 may be configured or operable to support components for: receiving a NAS message including an indication of UPU header protection; calculating a UPU MAC using the UPU header as at least one input for PDU protection; and sending an acknowledgment indicating successful UPU header verification.
[0093] Furthermore, UE 400 can be configured to support any one or a combination of the following: the method further includes: determining to perform UPU header verification; and calculating the UPU MAC based on at least a partial determination to perform UPU header verification. The method also includes: using the UPU header as at least one input for UPU protection, calculating the UPU MAC as UPU-MAC-I. AUSF The method also includes: determining that the UPU header verification was successful. The method further includes: generating a MAC address (UPU-MAC-I) indicating successful UPU header verification. UE The method further includes: determining successful verification of UPU header protection; and sending a verification indication of successful verification of UPU header protection to the UDM via the AMF. The method also includes: receiving a capability request regarding whether the UE supports UPU header protection; and sending a capability response indicating that the UE supports UPU header protection. This capability response is sent to the AMF in a NAS message, which is at least one of an initial registration request message or a registration update request message, and is forwarded by the AMF to the UDM to indicate that the UE supports UPU header protection.
[0094] Alternatively or concurrently, UE 400 may support at least one memory and at least one processor coupled to at least one memory and configured such that UE: receives a NAS message including an indication of UPU header protection; calculates a UPU MAC using the UPU header as at least one input for UPU protection; and sends an acknowledgment indicating successful UPU header verification.
[0095] Additionally, UE 400 can be configured to support any one or a combination of the following: at least one processor is configured such that the UE: determines to perform UPU header verification; and calculates UPUMAC based on at least a partial determination to perform UPU header verification. At least one processor is configured such that the UE: uses the UPU header as at least one input for UPU protection to calculate the UPU MAC as UPU-MAC-I. AUSF At least one processor is configured to cause the UE to: determine that the UPU header authentication was successful. At least one processor is configured to cause the UE to: generate a MAC address indicating successful UPU header authentication (UPU-MAC-I). UE At least one processor is configured to cause the UE to: determine successful verification of UPU header protection; and send a verification indication of successful UPU header protection verification to the UDM via the AMF. At least one processor is configured to cause the UE to receive a capability request regarding whether the UE supports UPU header protection; and send a capability response indicating that the UE supports UPU header protection. This capability response is sent to the AMF in a NAS message, which is at least one of an initial registration request message or a registration update request message, and is forwarded by the AMF to the UDM to indicate that the UE supports UPU header protection.
[0096] Controller 406 can manage input and output signals for UE 400. Controller 406 can also manage peripheral devices not integrated into UE 400. In some implementations, controller 406 can utilize an operating system such as iOS®, Android®, Windows®, or other operating systems. In some implementations, controller 406 can be implemented as part of processor 402.
[0097] In some implementations, UE 400 may include at least one transceiver 408. In other implementations, UE 400 may have more than one transceiver 408. The transceiver 408 may represent a wireless transceiver. Transceiver 408 may include one or more receiver chains 410, one or more transmitter chains 412, or a combination thereof.
[0098] Receiver chain 410 can be configured to receive signals (e.g., control information, data, packets) via a wireless medium. For example, receiver chain 410 may include one or more antennas to receive signals transmitted over the air or a wireless medium. Receiver chain 410 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. Receiver chain 410 may include at least one demodulator configured to demodulate the received signal and acquire transmitted data by reversing the modulation technique applied during signal transmission. Receiver chain 410 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.
[0099] Transmitter chain 412 can be configured to generate and transmit signals (e.g., control information, data, packets). Transmitter chain 412 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques, such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes such as phase shift keying (PSK) or quadrature amplitude modulation (QAM). Transmitter chain 412 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over a wireless medium. Transmitter chain 412 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0100] Figure 5 illustrates an example of a processor 500 according to various aspects of this disclosure. The processor 500 may be an example of a processor configured to perform various operations according to the examples described herein. The processor 500 may include a controller 502 configured to perform various operations according to the examples described herein. The processor 500 may optionally include at least one memory 504, which may be, for example, an L1 / L2 / L3 cache. Additionally or alternatively, the processor 500 may optionally include one or more arithmetic logic units (ALUs) 506. One or more of these components may be electronically communicated or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).
[0101] Processor 500 may be a processor chipset and includes a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receive, acquire, retrieve, send, output, forward, store, determine, identify, access, write, read) according to examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory native to or included therein of the processor chipset (e.g., processor 500)) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase-change memory (PCM), etc.).
[0102] Controller 502 can be configured to manage and coordinate various operations of processor 500 (e.g., signaling, receiving, acquiring, retrieving, sending, outputting, forwarding, storing, determining, identifying, accessing, writing, and reading) to enable processor 500 to support various operations according to the examples described herein. For example, controller 502 can operate as a control unit of processor 500, generating control signals that manage the operation of various components of processor 500. These control signals include enabling or disabling functional units, selecting data paths, initiating memory accesses, and coordinating operation timing.
[0103] Controller 502 may be configured to fetch (e.g., fetch, retrieve, receive) instructions from memory 504 and determine subsequent instructions(s) to be executed, enabling processor 500 to support various operations according to the examples described herein. Controller 502 may be configured to track the memory addresses of instructions associated with memory 504. Controller 502 may be configured to decode instructions to determine the operations to be performed and the operands involved. For example, controller 502 may be configured to interpret instructions and determine control signals to be output to other components of processor 500, enabling processor 500 to support various operations according to the examples described herein. Additionally or alternatively, controller 502 may be configured to manage data flow within processor 500. Controller 502 may be configured to control data transfers between registers, ALU 506, and other functional units of processor 500.
[0104] Memory 504 may include one or more caches (e.g., local to processor 500 or included in processor 500) or other memories such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementations, memory 504 may be located within or on the processor chipset (e.g., local to processor 500). In other implementations, memory 504 may be located outside the processor chipset (e.g., remotely from processor 500).
[0105] Memory 504 may store computer-readable, computer-executable code, including instructions that, when executed by processor 500, cause processor 500 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, such as system memory or another type of memory. Controller 502 and / or processor 500 may be configured to execute computer-readable instructions stored in memory 504 to cause processor 500 to perform various functions. For example, processor 500 and / or controller 502 may be coupled to, or coupled to, memory 504, processor 500, and controller 502, and may be configured to perform the various functions described herein. In some examples, processor 500 may include multiple processors, and memory 504 may include multiple memories. One or more of the multiple processors may be coupled to one or more of the multiple memories, and these processors and memories may be configured individually or collectively to perform the various functions described herein.
[0106] One or more ALU 506s can be configured to support various operations according to the examples described herein. In some implementations, one or more ALU 506s may be located within or on the processor chipset (e.g., processor 500). In some other implementations, one or more ALU 506s may be located outside the processor chipset (e.g., processor 500). One or more ALU 506s can perform one or more computations on data, such as addition, subtraction, multiplication, and division. For example, one or more ALU 506s can receive input operands and an opcode, the opcode determining the operation to be performed. One or more ALU 506s can be configured with various logic and arithmetic circuitry, including adders, subtractors, shifters, and logic gates, to process and manipulate data according to the operation. Alternatively or concurrently, one or more ALU 506s may support logical operations such as AND, OR, XOR, NOR, and NAND, enabling one or more ALU 506s to handle conditional operations, comparisons, and bitwise operations.
[0107] Processor 500 may support wireless communication according to the examples disclosed herein. Processor 500 may be configured or operable to support at least one processor coupled to at least one memory, and is configured such that the processor: receives a NAS message including an indication of UPU header protection; calculates a UPU MAC using the UPU header as at least one input for UPU protection; and sends an acknowledgment indicating successful UPU header verification.
[0108] Additionally, the processor 500 may be configured or operable to support any one or a combination of the following: at least one controller is configured such that the processor: determines to perform UPU header verification; and calculates the UPU MAC based at least in part on the determination to perform UPU header verification. At least one controller is configured such that the processor: uses the UPU header as at least one input for UPU protection to calculate the UPU MAC as UPU-MAC-I. AUSF At least one controller is configured to cause the processor to: determine that the UPU header verification was successful. At least one controller is configured to cause the processor to: generate a MAC indicating successful UPU header verification (UPU-MAC-I). UE At least one controller is configured to cause the processor to determine: successful verification of UPU header protection; and to send a verification indication of successful UPU header protection verification to the UDM via the AMF. At least one controller is configured to cause the processor to: receive a capability request regarding whether the UE supports UPU header protection; and send a capability response indicating that the UE supports UPU header protection. This capability response is sent to the AMF in a NAS message, which is at least one of an initial registration request message or a registration update request message, and is forwarded by the AMF to the UDM to indicate that the UE supports UPU header protection.
[0109] Figure 6 An example of an NE 600 according to various aspects of this disclosure is shown. The NE 600 may include a processor 602, a memory 604, a controller 606, and a transceiver 608. The processor 602, memory 604, controller 606, or transceiver 608, or various combinations thereof, or various components thereof, may be examples of parts for performing various aspects of the present disclosure described herein. These components may be coupled via one or more interfaces (e.g., operatively, communicatively, functionally, electronically, electrically).
[0110] Processor 602, memory 604, controller 606, or transceiver 608, or various combinations or components thereof, may be implemented in hardware (e.g., a circuit system). This hardware may include a processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof, configured to or otherwise supporting means for performing the functions described in this disclosure.
[0111] Processor 602 may include intelligent hardware devices (e.g., a general-purpose processor, DSP, CPU, ASIC, FPGA, or any combination thereof). In some implementations, processor 602 may be configured to operate memory 604. In other implementations, memory 604 may be integrated into processor 602. Processor 602 may be configured to execute computer-readable instructions stored in memory 604 to cause NE 600 to perform various functions of this disclosure.
[0112] Memory 604 may include volatile or non-volatile memory. Memory 604 may store computer-readable, computer-executable code, including instructions that, when executed by processor 602, cause NE 600 to perform the various functions described herein. This code may be stored in a non-transitory computer-readable medium, such as memory 604 or other types of memory. Computer-readable media include non-transitory computer storage media and communication media, including any medium that facilitates the transfer of computer programs from one place to another. Non-transitory storage media may be any available medium that can be accessed by a general-purpose computer or a special-purpose computer.
[0113] In some implementations, processor 602 and memory 604 coupled to processor 602 may be configured to cause NE 600 to perform one or more functions described herein (e.g., execute instructions stored in memory 604 via processor 602). For example, processor 602 may support wireless communication at NE 600 according to the examples disclosed herein. NE 600 (e.g., UDM) may be configured or operable to support components for: sending a request to AUSF to apply UPU header protection; and sending at least one of UPU transparency container or UPU header information to UE, wherein at least one UPU transparency container or UPU header information includes an indication that the UPU header is protected.
[0114] Additionally, the NE 600 can be configured or operable to support any one or a combination of the following: The method further includes: sending a capability request regarding whether the UE supports UPU header protection; and receiving a capability response indicating whether the UE supports UPU header protection. The method further includes: sending a capability request regarding whether the UE supports UPU header protection; receiving a capability response indicating whether the UE supports UPU header protection; and storing information regarding the UE's capability to support UPU header protection. The method further includes: determining the application of UPU header protection. The request to AUSF to apply User Plane Update header protection includes at least one of the following: a first indication requiring UPU header protection, or a second indication requiring UPU header verification and acknowledgment. The method further includes: setting an indication requiring acknowledgment that confirms the UE has received and successfully verified the UPU data and UPU header information. The method further includes: sending a relevant indication to the UE regarding UPU header protection, the relevant indication indicating that the UE uses the UPU header as at least one input for UPU protection to calculate the UPU MAC. The relevant indication indicates that the UE uses the UPU header as at least one input for UPU protection to calculate the UPU MAC as UPU-MAC-I. AUSF The method further includes: generating a UPU transparent container with an indication that UPU header protection is set in the UPU header. The method also includes: determining that UPU header protection is applied; and including one or more of the following: a UPU dataset type specific to UPU header information, the length of the UPU dataset specific to UPU header information, and UPU header information in the UPU data sent to a UE that supports UPU header protection. The UPU header information included in the UPU data provides integrity protection for the UPU header information. The method also includes: determining that UPU header protection is applied; and an indication that the UPU header is protected as part of the UPU data in the UPU header sent to the UE.
[0115] Alternatively or concurrently, the NE 600 may support at least one memory and at least one processor, the at least one processor being coupled to at least one memory and configured such that the NE: sends a request to the AUSF to apply UPU header protection; and sends at least one of a UPU transparency container or UPU header information to the UE, the at least one UPU transparency container or UPU header information including an indication that the UPU header is protected.
[0116] Additionally, the NE 600 can be configured to support any one or a combination of the following: at least one processor is configured to cause the NE to: send a capability request regarding whether the UE supports UPU header protection; and receive a capability response indicating that the UE supports UPU header protection. At least one processor is configured to cause the NE to: send a capability request regarding whether the UE supports UPU header protection; receive a capability response indicating whether the UE supports UPU header protection; and store information regarding the UE's capability to support UPU header protection. At least one processor is configured to cause the NE to: determine whether to apply UPU header protection. Sending a request to the AUSF to apply UPU header protection includes at least one of the following: a first indication requiring UPU header protection, or a second indication requiring UPU header verification and acknowledgment. At least one processor is configured to cause the NE to: set an indication required for acknowledgment, which confirms that the UE has received and successfully verified the UPU data and UPU header information. At least one processor is configured to cause the NE to: send a relevant indication for UPU header protection to the UE, which indicates that the UE uses the UPU header as at least one input for UPU protection to calculate the UPU MAC. The relevant instruction specifies that the UE uses the UPU header as at least one input for UPU protection, and calculates the UPU MAC as UPU-MAC-I. AUSF At least one processor is configured to cause the NE to: generate a UPU transparent container with an indication that UPU header protection is set in the UPU header. At least one processor is configured to cause the NE to: determine that UPU header protection is applied; and include one or more of the following: a UPU dataset type specific to UPU header information, the length of the UPU dataset specific to UPU header information, and UPU header information in the UPU data sent to a UE that supports UPU header protection. The UPU header information included in the UPU data provides integrity protection for the UPU header information. At least one processor is configured to cause the UE to: determine that UPU header protection is applied; and include an indication that the UPU header is protected as part of the UPU data in the UPU header sent to the UE.
[0117] In some implementations, processor 602 and memory 604 coupled to processor 602 may be configured such that NE 600 performs one or more functions described herein (e.g., processor 602 executes instructions stored in memory 604). For example, processor 602 may support wireless communication at NE 600 according to the examples disclosed herein. NE 600 (e.g., AMF) may be configured or operable to support components for: receiving at least one of the following from UDM: a UPU transparency container or UPU header information including a UPU header protection indication for the UE; and transmitting the UPU transparency container or UPU header information to the UE.
[0118] Additionally, the NE 600 can be configured or operable to support any one or a combination of the following: The method further includes sending a UPU transparent container or UPU header information to the UE as a NAS message including an indication of UPU header protection. The method further includes: if a transparent container is not received from the UDM and a UPU header protection indication information element is received, the NE generates a UPU transparent container with a UPU header including the UPU header protection indication.
[0119] Alternatively or concurrently, the NE 600 may support at least one memory and at least one processor, the at least one processor being coupled to at least one memory and configured such that the NE: receives from the UDM at least one of the following: a UPU transparent container or UPU header information including a UPU header protection indication for the UE; and sends the UPU transparent container or UPU header information to the UE.
[0120] Additionally, the NE 600 can be configured to support any one or a combination of the following: at least one processor is configured such that the NE sends a UPU transparent container or UPU header information to the UE as a NAS message including an indication of UPU header protection. At least one processor is configured such that the NE generates a UPU transparent container with a UPU header including the UPU header protection indication if it does not receive a transparent container from the UDM but receives a UPU header protection indication information element.
[0121] Controller 606 can manage input and output signals for NE 600. Controller 606 can also manage peripheral devices not integrated into NE 600. In some implementations, controller 606 can utilize an operating system such as iOS®, Android®, Windows®, or other operating systems. In some implementations, controller 606 can be implemented as part of processor 602.
[0122] In some implementations, the NE 600 may include at least one transceiver 608. In other implementations, the NE 600 may have more than one transceiver 608. The transceiver 608 may represent a wireless transceiver. The transceiver 608 may include one or more receiver chains 610, one or more transmitter chains 612, or a combination thereof.
[0123] Receiver chain 610 can be configured to receive signals (e.g., control information, data, packets) via a wireless medium. For example, receiver chain 610 may include one or more antennas to receive signals transmitted over the air or a wireless medium. Receiver chain 610 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. Receiver chain 610 may include at least one demodulator configured to demodulate the received signal and acquire transmitted data by reversing the modulation technique applied during signal transmission. Receiver chain 610 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.
[0124] Transmitter chain 612 can be configured to generate and transmit signals (e.g., control information, data, packets). Transmitter chain 612 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques, such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes such as phase shift keying (PSK) or quadrature amplitude modulation (QAM). Transmitter chain 612 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over a wireless medium. Transmitter chain 612 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0125] Figure 7 shows a flowchart of method 700 according to various aspects of this disclosure. The operation of this method can be implemented by the UE described herein. In some implementations, the UE can execute a set of instructions to control the functional elements of the UE to perform the described function. It should be noted that the method described herein describes one possible implementation, and the operations and steps can be rearranged or otherwise modified, and other implementations are possible.
[0126] At 702, the method may include: receiving a NAS message that includes an indication of UPU header protection. The operation of 702 can be performed according to the examples described herein. In some implementations, aspects of the operation of 702 may be derived from references. Figure 4 The UE described is used for execution.
[0127] At 704, the method may include: calculating the UPU MAC using the UPU header as at least one input for UPU protection. The operation of 704 can be performed according to the examples described herein. In some implementations, aspects of the operation of 704 can be found in the references. Figure 4 The UE described is used for execution.
[0128] At point 706, the method may include sending an acknowledgment indicating successful UPU header verification. The operation at point 706 can be performed according to the examples described herein. In some implementations, aspects of the operation at point 706 can be found in the references. Figure 4 The UE described is used for execution.
[0129] Figure 8 shows a flowchart of method 800 according to various aspects of this disclosure. The operation of this method can be implemented by an NE (e.g., a UDM) as described herein. In some implementations, the NE can execute a set of instructions to control the functional elements of the NE to perform the described function. It should be noted that the method described herein describes one possible implementation, and the operations and steps can be rearranged or otherwise modified, and other implementations are possible.
[0130] At 802, the method may include sending a request to AUSF to apply UPU header protection. The operation of 802 can be performed according to the examples described herein. In some implementations, aspects of the operation of 802 can be found in the references. Figure 6 The described NE is used for execution.
[0131] At 804, the method may include: sending to the UE at least one of a UPU transparency container or UPU header information, wherein at least one UPU transparency container or UPU header information includes an indication that the UPU header is protected. The operation of 804 can be performed according to the examples described herein. In some implementations, aspects of the operation of 804 may be derived from references... Figure 6 The described NE is used for execution.
[0132] Figure 9 A flowchart of method 900 according to various aspects of this disclosure is shown. The operation of this method can be implemented by an NE (e.g., an AMF) as described herein. In some implementations, the NE can execute a set of instructions to control the functional elements of the NE to perform the described function. It should be noted that the method described herein describes one possible implementation, and the operations and steps can be rearranged or otherwise modified, and other implementations are possible.
[0133] At 902, the method may include receiving from the UDM at least one of the following: a UPU transparency container or UPU header information including a UPU header protection indication for the UE. The operation of 902 can be performed according to the examples described herein. In some implementations, aspects of the operation of 902 may be derived from references... Figure 6 The described NE is used for execution.
[0134] At position 904, the method may include sending a UPU transparency container or UPU header information to the UE. The operation at position 904 can be performed according to the examples described herein. In some implementations, aspects of the operation at position 904 may be derived from references. Figure 6 The described NE is used for execution.
[0135] The description herein is provided to enable those skilled in the art to make or use this disclosure. Various modifications to this disclosure will be apparent to those skilled in the art, and the general principles defined herein may be applied to other variations without departing from the scope of this disclosure. Therefore, this disclosure is not limited to the examples and designs described herein, but should be given the broadest scope consistent with the principles and novel features disclosed herein.
Claims
1. A user equipment (UE) for wireless communication, comprising: At least one memory; as well as At least one processor, coupled to the at least one memory, and configured such that the UE: Receive a non-access stratum (NAS) message, the NAS message including an indication of UE parameter update UPU header protection; Use the UPU header as at least one input for UPU protection to calculate the UPU message authentication code (MAC); as well as Send a confirmation indicating that the UPU header verification was successful.
2. The UE of claim 1, wherein the at least one processor is configured such that the UE: Determine to perform the UPU header verification; and The UPU MAC is calculated based at least in part on determining whether to perform the UPU header verification.
3. The UE of claim 1, wherein the at least one processor is configured such that the UE: uses the UPU header as the at least one input for UPU protection, and calculates the UPU MAC as UPU-MAC-I. AUSF .
4. The UE of claim 1, wherein the at least one processor is configured to cause the UE to: determine that the UPU header verification is successful.
5. The UE of claim 1, wherein the at least one processor is configured to cause the UE to: generate a MAC UPU-MAC-I indicating successful UPU header verification. UE .
6. The UE according to claim 1, wherein, The at least one processor is configured such that the UE: Verification of successful protection of the UPU header; and The Access and Mobility Management Function (AMF) sends a successful verification indication of the UPU header protection to the Unified Data Management Function (UDM).
7. The UE of claim 1, wherein the at least one processor is configured such that the UE: Receive a request regarding whether the UE supports the capability of the UPU header protection; and Send a response indicating that the UE supports the capability of the UPU header protection.
8. The UE of claim 7, wherein the capability response is sent to the Access and Mobility Management Function (AMF) in a NAS message, the NAS message being at least one of an Initial Registration Request Message or a Registration Update Request Message, and the NAS message being forwarded by the AMF to the Unified Data Management (UDM) to indicate that the UE supports the UPU header protection.
9. A processor for wireless communication, comprising: At least one controller, coupled to at least one memory, and configured such that the processor: Receive a non-access stratum (NAS) message, the NAS message including an indication of UE parameter update UPU header protection; Use the UPU header as at least one input for UPU protection to calculate the UPU message authentication code (MAC); as well as Send a confirmation indicating that the UPU header verification was successful.
10. The processor of claim 9, wherein the at least one controller is configured such that the processor: Determine to perform the UPU header verification; and The UPU MAC is calculated based at least in part on determining whether to perform the UPU header verification.
11. The processor according to claim 9, wherein, The at least one controller is configured such that the processor: uses the UPU header as the at least one input for UPU protection, to calculate the UPU MAC as UPU-MAC-I. AUSF .
12. The processor of claim 9, wherein the at least one controller is configured to cause the processor to: determine that the UPU header verification is successful.
13. The processor of claim 9, wherein the at least one controller is configured to cause the processor to: generate a MAC UPU-MAC-I indicating successful verification of the UPU header. UE .
14. The processor of claim 9, wherein the at least one controller is configured such that the processor: Verification of successful protection of the UPU header; and The Access and Mobility Management Function (AMF) sends a successful verification indication of the UPU header protection to the Unified Data Management Function (UDM).
15. The processor of claim 9, wherein the at least one controller is configured such that the processor: Receive a request regarding whether the UE supports the capability of the UPU header protection; and Send a response indicating that the UE supports the capability of the UPU header protection.
16. The processor of claim 15, wherein the capability response is sent in a NAS message to the Access and Mobility Management Function (AMF), the NAS message being at least one of an Initial Registration Request message or a Registration Update Request message, the NAS message being forwarded by the AMF to the Unified Data Management (UDM) to indicate that the UE supports the UPU header protection.
17. A method performed by a user equipment (UE), the method comprising: Receive a non-access stratum (NAS) message, the NAS message including an indication of UE parameter update UPU header protection; Use the UPU header as at least one input for UPU protection to calculate the UPU message authentication code (MAC); as well as Send a confirmation indicating that the UPU header verification was successful.
18. The method of claim 17, further comprising: Determine whether to perform the UPU header verification; as well as The UPU MAC is calculated based at least in part on determining whether to perform the UPU header verification.
19. The method of claim 17, further comprising: Using the UPU header as the at least one input for UPU protection, the UPU MAC is calculated as UPU-MAC-I. AUSF .
20. A network device NE for wireless communication, comprising: At least one memory; as well as At least one processor, coupled to the at least one memory, and configured such that the NE: Send a request to the Authentication Server Function (AUSF) to update the UPU header protection using user equipment parameters; and Send at least one of a UPU transparent container or a UPU header information to the user equipment (UE), wherein the at least one UPU transparent container or the UPU header information includes an indication that the UPU header is protected.