Configure information security
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2026-08-14
Smart Images

Figure CN122580910A_ABST
Abstract
Description
Technical Field
[0001] The examples disclosed herein relate to configuration information security. Some relate to configuration information security in wireless networks. Background Technology
[0002] A wireless network consists of multiple network nodes, including terminal nodes and access nodes. Communication between terminal nodes and access nodes is wireless.
[0003] Configuration information can be used to configure the behavior of one or more nodes in a network. In some cases, it may be desirable to improve or enhance the security of using configuration information in a wireless network. Summary of the Invention
[0004] According to various, but not necessarily all, embodiments, an apparatus is provided comprising components for: Receive configuration information and at least the password encoding of the configuration information from the first access node; The received configuration information is stored in a received configuration information data structure in at least one secure storage environment, and at least the password encoding of the configuration information is stored in at least one secure storage environment; and At least in part, based on the transition from radio connectionless mode to radio connected mode, the contents of the received configuration information data structure and at least the stored cryptographic encoding of the configuration information are transmitted to the second access node so that the stored configuration information can be verified.
[0005] In some examples, the password encoding of the configuration information is generated at least in part based on the configuration information and at least one identifier configured to uniquely identify the first access node.
[0006] In some examples, at least the cryptographic encoding of the configuration information is generated using the configuration information and at least one identifier configured to uniquely identify the first access node as input to at least one cryptographic algorithm.
[0007] In some examples, the password encoding of the configuration information is at least partially generated based on the configuration information and at least one random value.
[0008] In some examples, the configuration information and at least the password encoding of the configuration information are received during radio connection mode.
[0009] In some examples, the configuration information includes configuration information for collecting experience quality measurements.
[0010] According to various, but not necessarily all, embodiments, a method is provided, including: Receive configuration information and at least the password encoding of the configuration information from the first access node; The received configuration information is stored in a received configuration information data structure in at least one secure storage environment, and at least the password encoding of the configuration information is stored in at least one secure storage environment; and At least in part, based on the transition from radio connectionless mode to radio connected mode, the contents of the received configuration information data structure and at least the stored cryptographic encoding of the configuration information are transmitted to the second access node so that the stored configuration information can be verified.
[0011] In some examples, the password encoding of the configuration information is generated at least in part based on the configuration information and at least one identifier configured to uniquely identify the first access node.
[0012] According to various, but not necessarily all, embodiments, a computer program is provided, including instructions that, when executed by a device, cause the device to perform at least the following: Receive configuration information and at least the password encoding of the configuration information from the first access node; The received configuration information is stored in a received configuration information data structure in at least one secure storage environment, and at least the password encoding of the configuration information is stored in at least one secure storage environment; and At least in part, based on the transition from radio connectionless mode to radio connected mode, the contents of the received configuration information data structure and at least the stored cryptographic encoding of the configuration information are transmitted to the second access node so that the stored configuration information can be verified.
[0013] According to various, but not necessarily all, embodiments, an apparatus is provided comprising components for: Receive configuration information from at least one core node; Generate a password encoding that includes at least the configuration information; This causes at least the configuration information and its cryptographic encoding to be transmitted to the terminal node; Receive authentication configuration information and at least the password encoding of the configuration information from the terminal node; and The received verification configuration information is verified at least in part based on the password encoding of the received minimum configuration information.
[0014] In some examples, generating the password encoding for at least the configuration information includes generating the password encoding based at least in part on the received configuration information and at least one identifier configured to uniquely identify the access node.
[0015] In some examples, generating cryptographic encoding of at least configuration information involves using the received configuration information and at least one identifier configured to uniquely identify the access node as input to at least one cryptographic algorithm.
[0016] In some examples, the configuration information includes configuration information for collecting experience quality measurements.
[0017] In some examples, the component is configured to cause at least one of the following to be transmitted to at least one core node: At least the password encoding of the configuration information; or At least one identifier configured to uniquely identify the access node is used when generating the password encoding for at least the configuration information.
[0018] In some examples, verifying the received verification configuration information includes generating a password encoding for at least the verification configuration information and comparing the password encoding for at least the verification configuration information with the password encoding for the received at least the configuration information.
[0019] In some examples, the component is configured to receive at least one identifier configured to uniquely identify the access node for use in generating a password encoding that at least verifies configuration information.
[0020] In some examples, verifying the received verification configuration information includes receiving the expected password encoding of at least the configuration information and comparing the password encoding of the received at least the configuration information with the expected password encoding of the received at least the configuration information.
[0021] In some examples, verifying the received verification configuration information includes transmitting the received verification configuration information and the password encoding of the received at least configuration information for verification.
[0022] According to various, but not necessarily all, embodiments, a computer program is provided, including instructions that, when executed by a device, cause the device to perform at least the following: Receive configuration information from at least one core node; Generate a password encoding that includes at least the configuration information; This causes at least the configuration information and its cryptographic encoding to be transmitted to the terminal node; Receive authentication configuration information and at least the password encoding of the configuration information from the terminal node; and The received verification configuration information is verified at least in part based on the password encoding of the received minimum configuration information.
[0023] According to various, but not necessarily all, embodiments, an apparatus is provided comprising components for: This causes configuration information to be transmitted to at least one access node; Receive a request from the requesting access node for assistance in verifying the authentication configuration information; and This triggers the transmission of information to the requesting access node, enabling the verification of the configuration information.
[0024] In some examples, the configuration information includes configuration information for collecting experience quality measurements.
[0025] In some examples, causing information transmission includes causing transmission of at least one of the following: At least the expected password encoding of the configuration information; or At least one identifier configured to uniquely identify the access node.
[0026] In some examples, the component is configured to receive at least one of the following: At least the password encoding of the configuration information; or At least one identifier configured to uniquely identify the access node is used when generating the password encoding for at least the configuration information.
[0027] According to various, but not necessarily all, embodiments, a method is provided, including: This causes configuration information to be transmitted to at least one access node; Receive a request from the requesting access node for assistance in verifying the authentication configuration information; and This triggers the transmission of information to the requesting access node, enabling the verification of the configuration information.
[0028] According to various, but not necessarily all, embodiments, a computer program is provided, including instructions that, when executed by a device, cause the device to perform at least the following: This causes configuration information to be transmitted to at least one access node; Receive a request from the requesting access node for assistance in verifying the authentication configuration information; and This triggers the transmission of information to the requesting access node, enabling the verification of the configuration information.
[0029] According to various, but not necessarily all, embodiments, an apparatus is provided, comprising: At least one processor; and At least one memory including computer program code; At least one memory stores instructions that, when executed by at least one processor, cause the device to perform at least a portion of one or more methods described herein.
[0030] According to various, but not necessarily all, embodiments, an apparatus is provided that includes components for performing at least a portion of one or more methods described herein.
[0031] The description of functions and / or actions should also be considered as disclosing any components suitable for performing those functions and / or actions. The functions and / or actions described herein can be performed using any suitable method and in any suitable manner.
[0032] Examples as claimed in the appended claims are provided according to various, but not necessarily all, embodiments.
[0033] While the examples and optional features of this disclosure have been described separately, it should be understood that this disclosure covers all possible combinations and permutations thereof. It should be understood that various examples of this disclosure may include any or all of the features described with respect to other examples of this disclosure, and vice versa. Furthermore, it should be understood that one or more or all of the features in any combination may be implemented, included therein, and / or performed as needed and appropriately by means of, means of, and / or computer program instructions. The description of the function should also be considered as disclosing any components suitable for performing that function. Attached Figure Description
[0034] Some examples will now be described with reference to the accompanying drawings, in which: Figure 1 Examples of the topics described in this article are shown; Figure 2 This article presents another example of the topic described in it; Figure 3 This article presents another example of the topic described in it; Figure 4 Another example of the topic described in this article is shown; Figure 5 This article presents another example of the topic described in it; Figure 6 Another example of the topic described in this article is shown; Figure 7 Another example of the topic described in this article is shown; Figure 8 Another example of the topic described in this article is shown; Figure 9 This article presents another example of the topic described in it; Figure 10 Another example of the topic described in this article is shown; Figure 11 Another example of the topic described in this article is shown; Figure 12 Another example of the topic described in this article is shown; Figure 13 This article presents another example of the topic described in it; Figure 14 Another example of the topic described in this article is shown; Figure 15A This article presents another example of the topic described in it; Figure 15B This article presents another example of the topic described in it; The accompanying drawings are not necessarily drawn to scale. For clarity and brevity, some features and views in the drawings may be shown schematically or enlarged to scale. For example, the dimensions of some elements in the drawings may be enlarged relative to other elements to aid illustration. Similar reference numerals are used in the accompanying drawings to indicate similar features. For clarity, not all reference numerals are necessarily shown in all drawings. Detailed Implementation
[0035] Figure 1 An example of network 100 is shown, which includes multiple network nodes, including terminal node 110, access node 120, and one or more core nodes 129. Terminal node 110 communicates with access node 120. One or more core nodes 129 communicate with access node 120.
[0036] In this example, network 100 is a radio telecommunications network in which at least some of the terminal nodes 110 and access nodes 120 communicate with each other by transmitting / receiving radio waves / signals.
[0037] In some examples, one or more core nodes 129 can communicate with each other. In some examples, one or more access nodes 120 can communicate with each other.
[0038] Network 100 may be a cellular network comprising multiple cells 122, each served by an access node 120. In this example, the interface between terminal node 110 and the access node 120 defining cell 122 is a wireless interface 124.
[0039] Access node 120 is a cellular radio transceiver. Terminal node 110 is a cellular radio transceiver.
[0040] In the example shown, cellular network 100 is a 3GPP (3rd Generation Partnership Project) network, where terminal node 110 is a user equipment (UE) (see, for example, see...). Figure 2 ), and access node 120 is a base station.
[0041] In the example, network 100 is the Evolved Universal Terrestrial Radio Access Network (E-UTRAN). The E-UTRAN consists of E-UTRAN Node Bs (eNBs) 120, which provide E-UTRA user plane and control plane (RRC) protocol termination to the UE. The eNBs 120 interconnect with each other via X2 interface 126. The eNBs are also connected to the Mobility Management Entity (MME) 129 via S1 interface 128.
[0042] In other examples, network 100 is a next-generation (or new air, NR) radio access network (NG-RAN). NG-RAN consists of gNodeBs (gNBs) 120 that provide user plane and control plane (RRC) protocol termination to UE 110. gNBs 120 interconnect with each other via Xn interface 126. gNBs are also connected to the Access and Mobility Management Function (AMF) via N2 interface 128.
[0043] In some examples, access node 120 may include at least one wireless edge computing server.
[0044] User equipment 130 (UE) may include mobile devices. When referring to a user equipment, the reference shall include and cover references to mobile devices where possible.
[0045] In the example, network 100 may include a combination of E-UTRAN and NG-RAN.
[0046] In the example, network 100 may include a 6GRAN network.
[0047] The configuration information can be used in the network to control functions such as at least one terminal node 110 or access node 120.
[0048] In the example, the configuration information can be securely stored, for example, in the terminal node, so that the service access node 120 of the terminal node 110 can access the configuration information when the terminal node 110 returns to the radio connection state.
[0049] In the example, you can verify that the configuration information is as expected and has not been tampered with during storage to ensure that the configuration is valid.
[0050] Examples of this disclosure relate to at least one of the following: means, methods, or computer programs for or relating to securely storing configuration information when terminal node 110 is in a radio-disconnected state.
[0051] Additionally or alternatively, examples of this disclosure relate to at least one of the following: an apparatus, method, or computer program for verifying configuration information stored or involving the verification of configuration information stored.
[0052] Figure 2 An example of signaling between entities is shown. Figure 2 An example of method 200 is also shown.
[0053] Figure 2 The method is shown to be performed by a system that includes interactions between different system entities. Figure 2 It also shows a collection of individual methods executed separately by different system entities.
[0054] about Figure 2 One or more features under discussion may be present in one or more other figures.
[0055] exist Figure 2 In this example, multiple devices transmit and / or receive one or more signals and / or messages via and / or using a network. In this example, any suitable form of communication on any suitable network can be used. For example, it can be used... Figure 1 At least a portion of the network 100.
[0056] exist Figure 2 In the example, terminal node 110, access node 120A or access nodes 120A and 120B and core node 129 transmit and / or receive one or more signals and / or one or more messages.
[0057] exist Figure 2 In the example, terminal node 110 is UE 170, access nodes 120A and 120B are gNB 173A and 173B, and core node 129 is Access Management Function (AMF) 175.
[0058] In the example, Figure 2 The transfer between the entities shown can be carried out via any number of intermediate entities, including without any intermediate entities.
[0059] Despite Figure 2 The example shows a single terminal node 110, but in this example, any suitable number of terminal nodes 110 can be included. Similarly, any suitable number of access nodes 120 can be used, and any suitable number of core nodes 129 can be used.
[0060] As used herein, a description of a function / action should also be considered as disclosing at least one of the following: enabling, causing, or controlling the function / action. For example, a description of transmitting information should also be considered as disclosing at least one of the following: enabling information transmission, causing information transmission, or controlling information transmission.
[0061] For example, a description of a device (such as UE 170) transmitting information should also be regarded as disclosing that at least one controller of the device performs at least one of the following: enabling the device to transmit information, enabling the device to transmit information, or controlling the device to transmit information.
[0062] In the example, at least a portion of method 200 can be considered as a method for securely storing configuration information.
[0063] In the example, at least a portion of method 200 can be considered as a method for securely storing configuration information when the terminal node is in radio-connected mode.
[0064] In the example, at least a portion of method 200 can be considered as a method for verifying configuration information.
[0065] In the examples shown, the positions of the boxes indicate one or more entities performing the corresponding functions / actions. For example, box 202 is performed by core node 129 (transmit) and access node 120A (receive). For example, box 204 is performed by access node 120A.
[0066] As used herein, the term "box" is intended to refer to one or more actions shown in the accompanying drawings. For example, the term "box" may refer to... Figure 2 The transmission / reception action indicated by reference numeral 202 in the accompanying drawings can also refer to the generation action indicated by reference numeral 204, and so on.
[0067] At box 202, method 200 includes transmitting configuration information 172 to at least one access node 120A.
[0068] because Figure 2 It shows one or more functions / actions of the transmission, therefore Figure 2 The corresponding reception and the functions / actions for initiating / enabling / controlling reception are also illustrated. For example, from the perspective of access node 120A, at block 202, method 200 includes receiving configuration 172 from at least one core node 129.
[0069] Configuration information 172 may include any suitable configuration information 172. For example, configuration information 172 may include information for use in wireless networks (such as...) Figure 1 Any suitable configuration information used in the example wireless network 100).
[0070] In some examples, configuration information 172 includes configuration information to be stored such that when terminal node 110 transitions from radio non-connected mode 180 to radio connected mode 182, configuration information 172 is available to the serving access node 120 of terminal node 110.
[0071] In some examples, configuration information 172 includes radio configuration information.
[0072] In some examples, configuration information 172 includes measurement configuration information.
[0073] In some examples, configuration information 172 includes, for example, private, sensitive, or confidential information related to user privacy. For instance, configuration information 172 may include at least one of the following: IP address, slice details, or application layer details.
[0074] In some examples, configuration information 172 includes configuration information to be stored to ensure the continuity of at least one service provided to terminal node 110 across radio connection states, such as radio resource control (RRC) states.
[0075] In some examples, configuration information 172 includes Quality of Experience Measurement Collection (QMC) configuration information 172. For example, configuration information 172 may include Multicast / Broadcast Service (MBS) QMC configuration information 172.
[0076] In some examples, method 200 includes determining configuration information 172 by core node 129. For example, configuration information 172 may be received or generated by core node 129.
[0077] In the example, box 202 includes the transmission of an initial context establishment request / UE context modification request.
[0078] At box 204, method 200 includes generating a password encoding 174 for at least configuration information 172.
[0079] In the example, password encoding 174 is an encrypted, encoded, or hashed version of at least configuration information 172. Therefore, in some examples, generating password encoding 174 of at least configuration information 172 includes at least one of encrypting, encoding, or hashing the configuration information.
[0080] In some examples, the cryptographic encoding 174 is the result of applying at least one cryptographic algorithm 188 to the configuration information 172. The at least one cryptographic algorithm may include at least one of the following: at least one encryption algorithm, at least one encoding algorithm, or at least one hash algorithm, etc. For example, a 128-bit algorithm, a 256-bit algorithm, or an AEAD combination algorithm may be used.
[0081] In the example, cryptographic algorithm 188 can be considered a cryptographic function.
[0082] In some examples, generating a password encoding 174 for at least configuration information 172 includes generating the password encoding 174 based at least in part on the received configuration information 172 and at least one identifier 186, which is configured to uniquely identify access node 120, such as access node 120A that is generating the password encoding 174 for at least configuration information 172, which may be considered as the first access node 120A.
[0083] Therefore, in the example, at least the password encoding 174 of the configuration information 172 is generated at least in part based on the configuration information 172 and at least one identifier 186 configured to uniquely identify the first access node 120A.
[0084] At least one identifier 186 can be any suitable identifier configured to uniquely identify access node 120 (such as access node 120A). That is, in the example, identifier 186 is an identifier associated with a single access node 120 (such as access node 120A).
[0085] For example, at least one identifier 186 may include at least one of the following: Physical Cell Identifier (PCI) and E-UTRA Absolute Radio Channel Number (EARFCN).
[0086] In some examples, generating the cryptographic encoding 174 of at least configuration information 172 includes using the received configuration information 172 and at least one identifier 186 configured to uniquely identify access node 120 as input to at least one cryptographic algorithm 188.
[0087] Any suitable cryptographic algorithm can be used. For example, any suitable encryption, encoding, or hashing algorithm can be used. For example, any suitable hash function can be used.
[0088] In some examples, generating a password encoding 174 based on at least configuration information 172 includes generating the password encoding 174 based at least in part on the received configuration information 172 and at least one random value 190.
[0089] For example, generating a cryptographic code 174 that includes at least configuration information 172 may include using the received configuration information 172 and at least one random value 190 as input to at least one cryptographic algorithm 188.
[0090] At box 206, method 200 includes transmitting configuration information 172 and at least a cryptographic encoding of the configuration information 172 to terminal node 110.
[0091] From the perspective of terminal node 110, box 206 includes receiving configuration information 172 from the first access node 120A and at least the password encoding of the configuration information 172 174.
[0092] In some examples, box 206 includes the transmission of an RRC Reconfiguration message.
[0093] At block 208, method 200 includes storing the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment, and storing at least a password encoding 174 of the configuration information 172 in at least one secure storage environment.
[0094] The received configuration information 172 and at least the password encoding 174 of the configuration information 172 can be stored in the same or different secure storage environments. For example, the received configuration information 172 and at least the password encoding 174 of the configuration information 172 can be stored in an individually addressable data structure.
[0095] Any suitable secure storage environment, one or more, can be used. In the example, a secure storage environment can be considered a tamper-proof storage device.
[0096] In the example, a secure storage environment may include a Trusted Execution Environment (TEE) or a Universal Integrated Circuit Card (UICC).
[0097] In the example, the configuration information receiving data structure 177 may include any suitable data structure configured to store information of the received configuration information 172. For example, the configuration information receiving data structure 177 may be any suitable data structure in which the configuration information 172 can be stored for later retrieval.
[0098] At block 210, method 200 includes transmitting from access node 120A to at least one of the following: a cryptographic encoding 174 of at least configuration information 172, or at least one identifier 186 configured to uniquely identify access node 120A when generating the cryptographic encoding 174 of at least configuration information 172.
[0099] Therefore, at block 210, access node 120A may transmit at least one of the following to at least core node 129 for storage, so that it can be retrieved later from core node 129 as needed: at least the password encoding 174 of configuration information 172, or at least one identifier 186 configured to uniquely identify access node 120A when generating the password encoding 174 of configuration information 172. See, for example. Figure 2 Box 218B.
[0100] From the perspective of core node 129, box 210 includes receiving at least one of the following: a password encoding 174 of at least configuration information 172, or at least one identifier 186 configured to uniquely identify access node 120A when generating the password encoding of at least configuration information 172.
[0101] In the example, at box 206, terminal node 110 is in radio connection mode 182. Therefore, in the example, at box 206, configuration information 172 and at least the cipher encoding 174 of configuration information 172 are received during radio connection mode 182.
[0102] In the example, the mode can be considered as a state, so configuration information 172 and at least the cipher encoding 174 of configuration information 172 can be received during the radio connection state.
[0103] In the example, radio connection mode 182 is a state in which terminal node 110 actively connects to access node 120 and terminal node 110 is known to access node 120.
[0104] In the example, terminal node 110 maintains synchronization with the network in radio connection mode.
[0105] Radio connection mode 182 may include RRC connection mode.
[0106] At box 212, method 200 includes switching from radio connected mode 182 to radio disconnected mode 180.
[0107] In the example, radio disconnection mode 180 is when terminal node 110 does not actively connect to access node 120 and access node 120 is unaware of the state of terminal node 100.
[0108] In the example, terminal node 110 does not maintain synchronization with the network in radio-connected mode.
[0109] Radio disconnect mode 180 may include RRC idle or RRC inactive mode.
[0110] Therefore, in some examples, at box 212, terminal node 110 switches from RRC connection to RRC idle or RRC inactive mode.
[0111] Box 212 may include one or more actions of at least one of the access node 120A or the core node 129.
[0112] At block 214, method 200 includes switching from radio non-connected mode 180 to radio connected mode 182. For example, block 214 may include switching from RRC idle or RRC inactive to RRC connected.
[0113] Box 214 can occur at some time after box 212, such as Figure 2 As shown in the example of '…'. For example, terminal node 110 may remain in radio non-connected mode 180 for a period of time before switching to radio connected mode 182.
[0114] At box 214, terminal node 110 can switch to radio connection mode 182 with first access node 120A or a different access node 120B. Therefore, in Figure 2 In the example, Figure 2The vertical solid line in the center at the bottom can indicate the action at the first access node 120A or different access nodes 120B.
[0115] It also shows Figure 2 The vertical dashed line in the lower part indicates the action at the first access node 120A in an example where the terminal node 110 has switched to radio connection mode 182 with a different access node 120B.
[0116] Therefore, at frames 218A, 218A1, 218A2, 218B, 218B1, and 218B2, Figure 2 It shows that it can be used Figure 2 Method 200 includes several options for execution.
[0117] Box 214 may include one or more actions of at least one of access node 120A, access node 120B, or core node 129.
[0118] At block 216, method 200 includes transmitting, at least in part, the contents 184 of the receive configuration information data structure 177 and the stored cryptographic encoding 174 of the configuration information 172 to the second access nodes 120A, 120B based on the transition from radio non-connected mode 180 to radio connected mode 182, so as to enable verification of the stored configuration information.
[0119] therefore, Figure 2 Method 200 is shown, including: Receive configuration information 172 and at least the password encoding 174 of configuration information 172 from the first access node 120A; The received configuration information 172 is stored in a received configuration information data structure 177 in at least one secure storage environment, and the password encoding 174 of the configuration information 172 is stored in at least one secure storage environment; and At least in part, based on the transition from radio disconnected mode 180 to radio connected mode 182, the contents 184 of the received configuration information data structure 177 and the stored cryptographic encoding 174 of the configuration information 172 are transmitted to the second access nodes 120A and 120B so that the stored configuration information can be verified.
[0120] The first access node 120A and the second access nodes 120A and 120B can be the same or different access nodes.
[0121] In other words, in the example, when the second access node is the same as the first access node 120A, the second access node can be referred to by reference numeral 120A, or when the second access node is a different access node from the first access node 120A, the second access node can be referred to by reference numeral 120B.
[0122] In the example, when box 216 is executed, the content 184 of the configuration information data structure 177 is the stored configuration information.
[0123] Therefore, in the example, if the content of the received configuration information data structure 177 changes between boxes 208 and 216, the stored configuration information transmitted at box 216 will be different from the received configuration information 172.
[0124] For example, if the configuration information 172 stored at terminal node 110 is tampered with, the content of the received configuration information data structure 177 changes between boxes 208 and 216, and the stored configuration information transmitted at box 216 is different from the configuration information 172 received at box 206.
[0125] However, in some examples, the content 184 of the received configuration information data structure 177 does not change between boxes 208 and 216, so the stored configuration information transmitted at box 216 is the same as the configuration information 172 received at box 206 in some examples.
[0126] As used herein, the descriptions of receiving configuration information and transmitting configuration information are intended to include cases where the transmitted configuration information is unchanged compared to the received configuration information and cases where the transmitted configuration information has changed compared to the received configuration information.
[0127] In the example, when execution box 216 is executed, the content 184 of the configuration information data structure 177 is received, and the stored configuration information can be considered as the verification configuration information 192.
[0128] From the perspective of access nodes 120A and 120B, method 200 includes receiving authentication configuration information 192 and at least configuration information 172 of password encoding 174 from terminal node 110.
[0129] In some examples, box 216 includes transmitting an RRC setup complete message.
[0130] At box 218, method 200 includes verifying received verification configuration information 192 based at least in part on password encoding 174 of received configuration information.
[0131] therefore, Figure 2 Method 200 is shown, including: Receive configuration information 172 from at least one core node 129; Generate a password encoding 174 with at least configuration information 172; This causes configuration information 172 and at least the password encoding 174 of configuration information 172 to be transmitted to terminal node 110; Receive authentication configuration information 192 and at least configuration information 172's password encoding 174 from terminal node 120; and The received verification configuration information 192 is verified at least in part based on the password encoding 174 of the received configuration information 172.
[0132] In the example, verifying the received verification configuration information 192 includes determining whether the configuration information 172 has changed when it was stored at the terminal node 110.
[0133] In some examples, verifying the received verification configuration information 192 includes performing a comparison using the password encoding 174 of the received at least configuration information 172.
[0134] In some examples, verifying the received verification configuration information 192 includes generating a password encoding 194 that at least verifies the configuration information 192.
[0135] In some examples, verifying the received verification configuration information 192 includes transmission and reception information.
[0136] For example, in an example where the second access node 120A and the first access node 120A are the same node, verifying the received verification configuration information 192 may include transmitting information to and receiving information from the core node 129. This is in Figure 2 The example is shown as box 218B.
[0137] For example, in an example where the second access node 120B and the first access node 120A are different nodes, verifying the received verification configuration information 192 may include transmitting information to and receiving information from the core node 129. This is in Figure 2 The example is shown as box 218B.
[0138] Additionally or alternatively, in examples where the second access node 120B and the first access node 120A are different nodes, verifying the received verification configuration information 192 may include transmitting information to and receiving information from the first access node 120A. This is in Figure 2 The example is shown as box 218A.
[0139] In some examples, verifying the received verification configuration information 192 includes generating a password encoding 194 for at least the verification configuration information 192 and comparing the password encoding 194 for at least the verification configuration information 192 with the password encoding 174 for the received configuration information 172.
[0140] Generating a password encoding 194 that verifies at least configuration information 192 can be performed as described in box 204 regarding configuration information 172.
[0141] Therefore, in the example, the password encoding 174 of the original configuration information 172 generated at box 204 can be compared with the password encoding 194 of the verification configuration information 192 received from the terminal node at box 216 to verify whether the configuration information 172 has changed when it was stored at the terminal node 110.
[0142] This is because, in the example, password codes 174 and 194 are generated in the same way, so if the input configuration information remains unchanged, password codes 174 and 194 will also match.
[0143] In the example, information about at least one cryptographic algorithm 188 used to generate the cryptographic code 174 may be transmitted together with or separately from the configuration information 172.
[0144] For example, information about at least one cryptographic algorithm 188 used to generate cryptographic code 174 can be transmitted / received at box 206, stored at one or more locations in boxes 208 and 210, and transmitted / received at box 218 to enable the generation of cryptographic code 194 for verifying configuration information 192.
[0145] In some examples, information about at least one cryptographic algorithm 18 used to generate the cryptographic code 174 is pre-configured at the access node 120.
[0146] In some examples, at least the password encoding 174 of the configuration information 172 is generated at least in part based on the configuration information 172 and at least one identifier 186 configured to uniquely identify the first access node 120A.
[0147] In an example where the first access node 120A and the second access node 120A are the same node, the second access node 120A can access at least one identifier 186 used.
[0148] However, this may not be the case in an example where the first access node 120A and the second access node 120B are different access nodes.
[0149] In some examples, method 200 includes receiving at least one identifier 186 configured to uniquely identify access node 120A for generating a password encoding 194 that verifies at least configuration information 192.
[0150] At least one identifier 186 can be received from the first access node 120A (box 218A) or the core node 129 (box 218B) or both.
[0151] In some examples, the second access node 120B requests at least one identifier 186 from the first access node 120A or the core node 129 or both.
[0152] In some examples, verifying the received verification configuration information 192 includes receiving the expected password encoding 196 of at least the configuration information, and comparing the password encoding 174 of the received at least the configuration information 172 with the expected password encoding 196 of the received at least the configuration information.
[0153] In some examples, the expected password encoding 196, which can receive at least configuration information from the first access node 120A, can still use the password encoding generated at box 204 as the expected password encoding 196 (box 218A).
[0154] In some examples, the expected password encoding 196 (box 218B) of at least configuration information can be received from core node 129. In one example, core node 129 receives password encoding 174 of at least configuration information 172 at box 210. The password encoding 174 of at least configuration information 172 received at box 210 can be used as the expected password encoding 196 of the at least configuration information.
[0155] The second access node 120B can request the expected password code 196 from the first access node 120A or the core node 129 or both.
[0156] In some examples, verifying the received verification configuration information 192 includes transmitting the received verification configuration information 192 and the password encoding 174 of the received at least configuration information for verification.
[0157] The received authentication configuration information 192 and the password encoding 174 of the received at least configuration information can be transmitted to the first access node 120A (frame 218A), the core node (frame 218B), or both for authentication.
[0158] In some examples, at box 218A1, the first access node 120A generates a password encoding 194 for at least verifying configuration information 192 and compares the password encoding 194 for at least verifying configuration information 192 with the password encoding 174 of the received configuration information 172 to verify configuration information 192.
[0159] At frame 218A2, the first access node transmits the verification result 197 to the second access node 120B.
[0160] In the example, if the password codes 174 and 194 match, the verification result 197 is positive, and it indicates that the received verification configuration information 192 is valid.
[0161] In the example, if the password encodings 174 and 194 do not match, the verification result 197 is negative, and it indicates that the received verification configuration information 192 is invalid.
[0162] In some examples, at box 218B1, core node 129 generates a password encoding 194 for at least verifying configuration information 192 and compares the password encoding 194 for at least verifying configuration information 192 with the password encoding 174 of the received configuration information 172 to verify configuration information 192.
[0163] At frame 218B2, core node 129 transmits verification result 197 to second access node 120B.
[0164] In the example, if the password codes 174 and 194 match, the verification result 197 is positive, and it indicates that the received verification configuration information 192 is valid.
[0165] In the example, if the password encodings 174 and 194 do not match, the verification result 197 is negative, and it indicates that the received verification configuration information 192 is invalid.
[0166] In the example, from the perspective of core node 129, method 200 includes receiving a request 199 from the requesting access node for assistance in verifying the verification configuration information 192.
[0167] The requesting access node can be either the first access node 120A or the second access node 120B.
[0168] In the example, a request for assistance 199 may include at least one of the following: a request for a expected password encoding 196 for at least configuration information, or a request for at least one identifier 186 configured to uniquely identify access node 120.
[0169] In the example, from the perspective of core node 129, method 200 includes transmitting information 198 to the requesting access node to enable verification of verification configuration information 192.
[0170] therefore, Figure 2 Method 200 is shown, including: This causes configuration information 172 to be transmitted to at least one access node 120; Receive a request 199 from the requesting access node for assistance in verifying the authentication configuration information 192; and Information 198 is transmitted to the requesting access node so that the verification configuration information 192 can be verified.
[0171] In some examples, the transmission information 198 includes transmitting at least one of the following: a pre-defined cryptographic encoding 196 for at least configuration information, or at least one identifier configured to uniquely identify the access node 120.
[0172] The examples disclosed herein have advantages and / or provide technical benefits.
[0173] For example, the examples in this disclosure provide secure storage of configuration information at an end node when the end node is in a radio-disconnected state.
[0174] For example, the examples in this disclosure enable the reuse of configuration information when an end node transitions from a radio-unconnected state to a radio-connected state.
[0175] For example, the examples in this disclosure provide verification of configuration information to ensure that the configuration information has not been tampered with, for example, stored at an end node or during transmission.
[0176] For example, examples of this disclosure enable configuration information to be stored to ensure the continuity of at least one service provided to the terminal node across radio connection states, such as Radio Resource Control (RRC) states.
[0177] Figure 3 An example of signaling between entities is shown. Figure 3 An example of method 300 is also shown.
[0178] Figure 3 The method is shown to be performed by a system that includes interactions between different system entities. Figure 3 It also shows a collection of individual methods executed separately by different system entities.
[0179] about Figure 3 One or more features under discussion may be present in one or more other figures.
[0180] exist Figure 3In this example, multiple devices transmit and / or receive one or more signals and / or messages via and / or using a network. In this example, any suitable form of communication on any suitable network can be used. For example, it can be used... Figure 1 At least a portion of the network 100.
[0181] exist Figure 3 In the example, terminal node 110, access node 120A or access nodes 120A and 120B and core node 129 transmit and / or receive one or more signals and / or one or more messages.
[0182] exist Figure 3 In the example, terminal node 110 is UE 170, access nodes 120A and 120B are gNB 173A and 173B, and core node 129 is Access Management Function (AMF) 175.
[0183] In the example, Figure 3 The transfer between the entities shown can be carried out via any number of intermediate entities, including without any intermediate entities.
[0184] Despite Figure 3 The example shows a single terminal node 110, but in this example, any suitable number of terminal nodes 110 can be included. Similarly, any suitable number of access nodes 120 can be used, and any suitable number of core nodes 129 can be used.
[0185] In the example, at least a portion of method 300 can be considered as a method for securely storing configuration information.
[0186] In the example, at least a portion of method 300 can be considered as a method for securely storing configuration information when the terminal node is in radio-connected mode.
[0187] In the example, at least a portion of method 300 can be considered as a method for verifying configuration information.
[0188] At box 302, method 300 includes generating a password encoding 174 based at least in part on configuration information 172 and at least one random value 190.
[0189] Configuration information 172 may include any suitable configuration information 172. For example, configuration information 172 may include information for use in wireless networks (such as...) Figure 1 Any suitable configuration information used in the example wireless network 100).
[0190] In some examples, configuration information 172 includes configuration information to be stored such that when terminal node 110 transitions from radio non-connected mode 180 to radio connected mode 182, configuration information 172 is available to the serving access node 120 of terminal node 110.
[0191] In some examples, configuration information 172 includes radio configuration information.
[0192] In some examples, configuration information 172 includes measurement configuration information.
[0193] In some examples, configuration information 172 includes, for example, private, sensitive, or confidential information related to user privacy. For instance, configuration information 172 may include at least one of the following: IP address, slice details, or application layer details.
[0194] In some examples, configuration information 172 includes configuration information to be stored to ensure the continuity of at least one service provided to terminal node 110 across radio connection states, such as radio resource control (RRC) states.
[0195] In some examples, configuration information 172 includes Quality of Experience Measurement Collection (QMC) configuration information 172. For example, configuration information 172 may include Multicast / Broadcast Service (MBS) QMC configuration information 172.
[0196] In some examples, method 200 includes determining configuration information 172 by core node 129. For example, configuration information 172 may be received or generated by core node 129.
[0197] In the example, password encoding 174 is an encrypted, encoded, or hashed version of at least configuration information 172. Therefore, in some examples, generating password encoding 174 of at least configuration information 172 includes at least one of encrypting, encoding, or hashing the configuration information.
[0198] In some examples, the cryptographic encoding 174 is the result of applying at least one cryptographic algorithm 188 to the configuration information 172. The at least one cryptographic algorithm may include at least one of the following: at least one encryption algorithm, at least one encoding algorithm, or at least one hash algorithm, etc. For example, a 128-bit algorithm, a 256-bit algorithm, or an AEAD combination algorithm may be used.
[0199] In some examples, generating a cryptographic encoding 174 that includes at least configuration information 172 includes using configuration information 172 and at least one random value 190 as input to at least one cryptographic algorithm 188.
[0200] In the example, cryptographic algorithm 188 can be considered a cryptographic function.
[0201] Any suitable cryptographic algorithm can be used. For example, any suitable encryption, encoding, or hashing algorithm can be used. For example, any suitable hash function can be used.
[0202] The generated password encoding 174 of at least configuration information 172 can be stored at core node 129.
[0203] At block 304, method 300 includes transmitting configuration information 172 and at least one random value 190 to at least one access node 120A. Access node 120A may be considered as a first access node 120A.
[0204] because Figure 3 It shows one or more functions / actions of the transmission, therefore Figure 3 The corresponding reception and the functions / actions for initiating / enabling / controlling reception are also illustrated. For example, from the perspective of access node 120A, at block 304, method 300 includes receiving configuration 172 and at least one random value 190 from at least one core node 129.
[0205] In some examples, box 304 includes a transmission initial context establishment request / UE context modification request.
[0206] At box 306, method 300 includes transmitting configuration information 172 and at least one random value 190 to terminal node 110.
[0207] From the perspective of terminal node 110, box 306 includes receiving configuration information 172 and at least one random value 190 from the first access node 120A.
[0208] In some examples, box 306 includes the transmission of RRC reconfiguration messages.
[0209] At block 308, method 300 includes storing the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment.
[0210] Any suitable secure storage environment, one or more, can be used. In the example, a secure storage environment can be considered a tamper-proof storage device.
[0211] In the example, a secure storage environment may include a Trusted Execution Environment (TEE) or a Universal Integrated Circuit Card (UICC).
[0212] In the example, the configuration information receiving data structure 177 may include any suitable data structure configured to store information of the received configuration information 172. For example, the configuration information receiving data structure 177 may be any suitable data structure in which the configuration information 172 can be stored for later retrieval.
[0213] At box 310, method 300 includes generating a cryptographic encoding 174 of at least the configuration information 172 based at least in part on the received configuration information 172 and at least one received random value 190.
[0214] As described with respect to box 304, generating a password encoding 174 for at least configuration information 172 can be performed. Therefore, in the example, when the configuration information 172 and at least one random value remain unchanged between boxes 302 and 310, the password encoding 174 at the core node 192 will match the password encoding 174 at the terminal node.
[0215] In the example, generating a password encoding 174 based on at least configuration information 172 includes generating the password encoding 174 based at least in part on the received configuration information 172 and at least one received random value 190.
[0216] In some examples, generating the cryptographic encoding 174, which includes at least configuration information, involves using configuration information 172 and at least one random value 190 as input to at least one cryptographic algorithm 188.
[0217] Information about at least one cryptographic algorithm 188 used to generate cryptographic code 174 can be transmitted together with or separately from configuration information 172.
[0218] For example, information about at least one cryptographic algorithm 188 used to generate cryptographic code 174 can be transmitted / received at boxes 304 and 306, and stored at box 308.
[0219] In some examples, information about at least one cryptographic algorithm 18 used to generate the cryptographic code 174 is pre-configured at the terminal node 110.
[0220] In the example, at box 306, terminal node 110 is in radio connection mode 182. Therefore, in the example, at box 306, configuration information 172 and at least one random value 190 are received during radio connection mode 182.
[0221] At box 312, method 300 includes switching from radio connected mode 182 to radio disconnected mode 180. In some examples, at box 312, terminal node 110 switches from RRC connected to RRC idle or RRC inactive mode.
[0222] Box 312 may include one or more actions of at least one of the access node 120A or the core node 129.
[0223] At block 314, method 300 includes switching from radio non-connected mode 180 to radio connected mode 182. For example, block 314 may include switching from RRC idle or RRC inactive to RRC connected.
[0224] Box 314 can occur at some time after box 312, such as Figure 3 As shown in the example of '…'. For example, terminal node 110 may remain in radio non-connected mode 180 for a period of time before switching to radio connected mode 182.
[0225] At box 314, terminal node 110 can switch to radio connection mode 182 with first access node 120A or a different access node 120B. Therefore, in Figure 2 In the example, Figure 2 The vertical solid line in the center at the bottom can indicate the action at the first access node 120A or different access nodes 120B.
[0226] Box 314 may include one or more actions of at least one of access node 120A, access node 120B, or core node 129.
[0227] At block 316, method 300 includes transmitting, at least in part, the contents 184 of the receive configuration information data structure 177 and the cryptographic encoding 174 of the configuration information 172 to the second access nodes 120A, 120B based on the transition from radio non-connected mode 180 to radio connected mode 182, so as to enable verification of the stored configuration information.
[0228] therefore, Figure 3 Method 300 is shown, including: Receive configuration information 172 and at least one random value 190 from the first access node 120A; The received configuration information 172 is stored in a received configuration information data structure 177 in at least one secure storage environment; At least in part based on the received configuration information 172 and at least one received random value 190, a cryptographic encoding 174 of at least the configuration information 172 is generated; and At least in part, based on the transition from radio disconnected mode 180 to radio connected mode 182, the contents 184 of the received configuration information data structure 177 and the cryptographic encoding 174 of the configuration information 172 are transmitted to the second access nodes 120A and 120B so that the stored configuration information can be verified.
[0229] The first access node 120A and the second access nodes 120A and 120B can be the same or different access nodes.
[0230] In other words, in the example, when the second access node is the same as the first access node 120A, the second access node can be referred to by reference numeral 120A, or when the second access node is a different access node from the first access node 120A, the second access node can be referred to by reference numeral 120B.
[0231] In the example, when box 216 is executed, the content 184 of the configuration information data structure 177 is the stored configuration information.
[0232] Therefore, in the example, if the content of the received configuration information data structure 177 changes between boxes 308 and 316, the stored configuration information transmitted at box 216 will be different from the received configuration information 172.
[0233] For example, if the configuration information 172 stored at terminal node 110 is tampered with, the content of the received configuration information data structure 177 changes between boxes 308 and 316, and the stored configuration information transmitted at box 316 is different from the configuration information 172 received at box 306.
[0234] However, in some examples, the content 184 of the received configuration information data structure 177 does not change between boxes 308 and 316, so the stored configuration information transmitted at box 316 is the same as the configuration information 172 received at box 306 in some examples.
[0235] In the example, when execution box 216 is executed, the content 184 of the configuration information data structure 177 is received, and the stored configuration information can be considered as the verification configuration information 192.
[0236] From the perspective of access nodes 120A and 120B, method 300 includes receiving authentication configuration information 192 and at least configuration information 172 of password encoding 174 from terminal node 110.
[0237] In some examples, box 316 includes transmitting an RRC setup complete message.
[0238] At block 318, method 300 includes transmitting to core node 129 the received verification configuration information 192 and the cryptographic encoding 174 of the received at least configuration information 172, so that the received verification configuration information 192 can be verified.
[0239] therefore, Figure 3 Method 300 is shown, including: Receive configuration information 172 and at least one random value 190 from at least one core node 129; This causes configuration information 172 and at least one random value 190 to be transmitted to terminal node 110; Receive authentication configuration information 192 and at least configuration information 172's password encoding 174 from terminal node 110; and The received verification configuration information 192 and the received at least configuration information 172 are transmitted to the core node 129 via a cryptographic encoding 174 to enable the verification of the received verification configuration information 192.
[0240] In some examples, box 318 includes transmitting a “send UE information” message.
[0241] From the perspective of the core node 129, method 300 includes receiving authentication configuration information 192 and at least the password encoding of configuration information 172 from access nodes 120A and 120B.
[0242] At box 320, method 300 includes generating a password encoding 194 that verifies at least the configuration information 192, based at least in part on the verification configuration information 192 and at least one random value 190.
[0243] Generating a password encoding 194 that verifies at least configuration information 192 can be performed as described in box 204 regarding configuration information 172.
[0244] Therefore, in some examples, generating a cryptographic encoding 194 that verifies at least the configuration information 192 includes using the configuration information 192 and at least one random value 190 as input to at least one cryptographic algorithm.
[0245] At box 322, method 300 includes comparing a password encoding 194 of at least verification configuration information 192 with a password encoding 174 of generated at least configuration information 172 and a password encoding 174 of received at least configuration information 172 to verify the received verification configuration information 192.
[0246] therefore, Figure 3 Method 300 is shown, including: A password encoding 174 based at least partially on configuration information 172 and at least one random value 190 is generated based on configuration information 172. This causes configuration information 172 and at least one random value 190 to be transmitted to at least one access node 120A; Receive authentication configuration information 192 and password encoding 174 of at least configuration information 174 from access nodes 120A and 120B; and A password encoding 194 is generated based at least in part on the verification configuration information 192 and at least one random value 190; The password encoding 194 of at least the verification configuration information 192 is compared with the password encoding 174 of the generated at least the configuration information 172 and the password encoding 174 of the received at least the configuration information 172 to verify the received verification configuration information 192.
[0247] In the example, the generated password encoding of at least the configuration information can be labeled as 172A, and the received password encoding of at least the configuration information can be labeled as 172B.
[0248] Therefore, in the example, the password encoding 194 of at least the configuration information 192 is compared with the password encoding 174 of at least the configuration information 172 generated at box 302 and the password encoding 174 of at least the configuration information 172 received at box 318 to verify whether the configuration information 172 has changed after being transmitted from the core node 129, for example, whether it has changed during transmission or while stored at the terminal node 110.
[0249] This is because, in the example, password codes 174 and 194 are generated in the same way, so if the input configuration information remains unchanged, password codes 174 and 194 will also match.
[0250] At block 324, method 300 includes transmitting verification result 197 to access nodes 120A and 120B involved in block 318, at least in part, based on a comparison.
[0251] In the example, method 300 includes transmitting a positive verification result in response to determining that at least the password encoding 194 of the verification configuration information 192 matches the password encoding 174 of the generated at least configuration information 172 and the received password encoding 174 of the at least configuration information 172. Otherwise, in the example, the verification result is negative.
[0252] In the example, the verification result indicates that the received verification configuration information 192 is valid.
[0253] In the example, a negative verification result indicates that the received verification configuration information 192 is invalid.
[0254] The examples disclosed herein have advantages and / or provide technical benefits.
[0255] For example, the examples in this disclosure provide secure storage of configuration information at an end node when the end node is in a radio-disconnected state.
[0256] For example, the examples in this disclosure enable the reuse of configuration information when an end node transitions from a radio-unconnected state to a radio-connected state.
[0257] For example, the examples in this disclosure provide verification of configuration information to ensure that the configuration information has not been tampered with, for example, stored at an end node or during transmission.
[0258] For example, examples of this disclosure enable configuration information to be stored to ensure the continuity of at least one service provided to the terminal node across radio connection states, such as Radio Resource Control (RRC) states.
[0259] Figure 4 An example of method 400 is shown.
[0260] Method 400 can be performed by any suitable means including any suitable components for performing method 400, for example, regarding Figure 15A and / or Figure 15B The aforementioned device.
[0261] In the example, method 400 may be performed by terminal node 110 (such as UE 170) or by at least one control device configured to control its functions.
[0262] At box 402, method 400 includes receiving configuration information 172 and at least one random value 190 from the first access node 120A.
[0263] At box 404, method 400 includes storing the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment.
[0264] At box 406, method 400 includes generating a cryptographic encoding 174 of at least the configuration information 172 based at least in part on the received configuration information 172 and at least one received random value 190.
[0265] At block 408, method 400 includes, at least in part, based on the transition from radio disconnected mode 180 to radio connected mode 182, causing the contents 184 of received configuration information data structure 177 and the cryptographic encoding 174 of configuration information 172 to be transmitted to second access nodes 120A, 120B so that the stored configuration information can be verified.
[0266] therefore, Figure 4 Method 400 is shown, including: Receive configuration information 172 and at least one random value 190 from the first access node 120A; The received configuration information 172 is stored in a received configuration information data structure 177 in at least one secure storage environment; At least in part based on the received configuration information 172 and at least one received random value 190, a cryptographic encoding 174 of at least the configuration information 172 is generated; and At least in part, based on the transition from radio disconnected mode 180 to radio connected mode 182, the contents 184 of the received configuration information data structure 177 and the cryptographic encoding 174 of the configuration information 172 are transmitted to the second access nodes 120A and 120B so that the stored configuration information can be verified.
[0267] Figure 5 An example of method 500 is shown.
[0268] Method 500 can be performed by any suitable means including any suitable components for performing method 500, for example, regarding Figure 15A and / or Figure 15B The aforementioned device.
[0269] In the example, method 500 may be performed by at least one access node 120 (such as gNB 173) or by at least one control device configured to control its functions.
[0270] At box 502, method 500 includes receiving configuration information 172 and at least one random value 190 from at least one core node 129.
[0271] At box 504, method 500 includes causing configuration information 172 and at least one random value 190 to be transmitted to terminal node 110.
[0272] At box 506, method 500 includes receiving authentication configuration information 192 and at least password encoding of configuration information 172 from terminal node 110.
[0273] At block 508, method 500 includes causing the received verification configuration information 192 and the received at least configuration information 172 to be transmitted to core node 129 via cryptographic encoding 174, so that the received verification configuration information 192 can be verified.
[0274] therefore, Figure 5 Method 500 is shown, including: Receive configuration information 172 and at least one random value 190 from at least one core node 129; This causes configuration information 172 and at least one random value 190 to be transmitted to terminal node 110; Receive authentication configuration information 192 and at least configuration information 172's password encoding 174 from terminal node 110; and The received verification configuration information 192 and the received at least configuration information 172 are transmitted to the core node 129 via a cryptographic encoding 174 to enable the verification of the received verification configuration information 192.
[0275] Figure 6 An example of method 600 is shown.
[0276] Method 600 can be performed by any suitable means including any suitable components for performing method 600, for example, regarding Figure 15A and / or Figure 15B The aforementioned device.
[0277] In the example, method 600 may be executed by core node 129 (such as AMF 175) or by at least one control device configured to control its functions.
[0278] At box 602, method 600 includes generating a password encoding 174 based at least in part on configuration information 172 and at least one random value 190.
[0279] At box 604, method 600 includes causing configuration information 172 and at least one random value 190 to be transmitted to at least one access node 120A.
[0280] At box 606, method 600 includes receiving authentication configuration information 192 and password encoding 174 of at least configuration information 174 from access nodes 120A and 120B.
[0281] At box 608, method 600 includes generating a password encoding 194 that verifies at least the configuration information 192, based at least in part on the verification configuration information 192 and at least one random value 190.
[0282] At box 610, method 600 includes comparing a password encoding 194 of at least verification configuration information 192 with a password encoding 174 of generated at least configuration information 172 and a password encoding 174 of received at least configuration information 172 to verify the received verification configuration information 192.
[0283] therefore, Figure 6 Method 600 is shown, including: A password encoding 174 based at least partially on configuration information 172 and at least one random value 190 is generated based on configuration information 172. This causes configuration information 172 and at least one random value 190 to be transmitted to at least one access node 120A; Receive authentication configuration information 192 and password encoding 174 of at least configuration information 174 from access nodes 120A and 120B; and A password encoding 194 is generated based at least in part on the verification configuration information 192 and at least one random value 190; The password encoding 194 of at least the verification configuration information 192 is compared with the password encoding 174 of the generated at least the configuration information 172 and the password encoding 174 of the received at least the configuration information 172 to verify the received verification configuration information 192.
[0284] Figure 7 An example of method 700 is shown.
[0285] Method 700 can be performed by any suitable means including any suitable components for performing method 400, for example, regarding Figure 15A and / or Figure 15B The aforementioned device.
[0286] In the example, method 700 may be performed by terminal node 110 (such as UE 170) or by at least one control device configured to control its functions.
[0287] At box 702, method 700 includes receiving configuration information 172 from a first access node 120A and at least a password encoding 174 of the configuration information 172.
[0288] At block 704, method 700 includes storing the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment, and storing the password encoding 174 of the configuration information 172 in at least one secure storage environment.
[0289] At block 706, method 700 includes, at least in part, based on the transition from radio disconnected mode 180 to radio connected mode 182, causing the contents 184 of received configuration information data structure 177 and the stored cryptographic encoding 174 of configuration information 172 to be transmitted to second access nodes 120A, 120B so that the stored configuration information can be verified.
[0290] therefore, Figure 7 Method 700 is shown, including: Receive configuration information 172 and at least the password encoding 174 of configuration information 172 from the first access node 120A; The received configuration information 172 is stored in a received configuration information data structure 177 in at least one secure storage environment, and the password encoding 174 of the configuration information 172 is stored in at least one secure storage environment; and At least in part, based on the transition from radio disconnected mode 180 to radio connected mode 182, the contents 184 of the received configuration information data structure 177 and the stored cryptographic encoding 174 of the configuration information 172 are transmitted to the second access nodes 120A and 120B so that the stored configuration information can be verified.
[0291] Figure 8 An example of method 800 is shown.
[0292] Method 800 can be performed by any suitable means including any suitable components for performing method 800, for example, regarding Figure 15A and / or Figure 15B The aforementioned device.
[0293] In the example, method 800 may be performed by at least one access node 120 (such as gNB 173) or by at least one control device configured to control its functions.
[0294] At box 802, method 800 includes receiving configuration information 172 from at least one core node 129.
[0295] At box 804, method 800 includes generating a password encoding 174 for at least configuration information 172.
[0296] At box 806, method 800 includes transmitting configuration information 172 and at least the cryptographic encoding of configuration information 172 to terminal node 110.
[0297] At box 808, method 800 includes receiving authentication configuration information 192 and at least configuration information 172 of password encoding 174 from terminal node 120.
[0298] At box 810, method 800 includes verifying received verification configuration information 192 based at least in part on password encoding 174 of received configuration information 172.
[0299] therefore, Figure 8 Method 800 is shown, including: Receive configuration information 172 from at least one core node 129; Generate a password encoding 174 with at least configuration information 172; This causes configuration information 172 and at least the password encoding 174 of configuration information 172 to be transmitted to terminal node 110; Receive authentication configuration information 192 and at least configuration information 172's password encoding 174 from terminal node 120; and The received verification configuration information 192 is verified at least in part based on the password encoding 174 of the received configuration information 172.
[0300] Figure 9 An example of method 900 is shown.
[0301] Method 900 can be performed by any suitable means including any suitable components for performing method 900, for example, regarding Figure 15A and / or Figure 15B The aforementioned device.
[0302] In the example, method 900 can be executed by core node 129 (such as AMF 175) or by at least one control device configured to control its functions.
[0303] At box 902, method 900 includes causing configuration information 172 to be transmitted to at least one access node 120.
[0304] At box 904, method 900 includes receiving from the requesting access node a request 199 for assistance in verifying authentication configuration information 192.
[0305] At box 906, method 900 includes transmitting initiation information 198 to the requesting access node to enable verification of verification configuration information 192.
[0306] therefore, Figure 9 Method 900 is shown, including: This causes configuration information 172 to be transmitted to at least one access node 120; Receive a request 199 from the requesting access node for assistance in verifying the authentication configuration information 192; and Information 198 is transmitted to the requesting access node so that the verification configuration information 192 can be verified.
[0307] In the example, to ensure the continuity of signaling-based and management-based QoE measurements for the MBS across RRC states, the QoE measurement configuration information should be made available to the gNB serving the UE when the UE transitions from the RRC_IDLE state to the RRC_CONNECTED state.
[0308] In the example, when the UE is in the RRC_IDLE state, the QoE measurement configuration information should be stored at the UE or AMF. After the UE transitions from the RRC_IDLE state to the RRC_CONNECTED state, this information should be provided to the serving gNB.
[0309] In the example, when QoE measurement configuration information is stored in the UE while the UE is in the RRC_IDLE state, this information should be stored in a manner that ensures user privacy is protected.
[0310] Some examples in this disclosure focus on security and privacy aspects when QoE measurement configuration is stored in the UE. In the examples, parts of the configuration (such as IP addresses, slice details, and application layer details) may be sensitive information and could potentially reveal user privacy and confidential information about the network and network slices. If such information is stored in the UE, it should be stored in a secure storage location and its tampering should be ensured.
[0311] Examples of methods and apparatus for the following are provided in this disclosure: The QMC is securely stored in the UE's tamper-proof memory. It is stored in a TEE-class environment to ensure that even access to this information is controlled, and that the information is only available to UE services that require it, and not to any applications.
[0312] When the QMC is stored in the TEE, the examples in this disclosure also propose a lightweight application that is also stored in the TEE to provide access to the stored QMC information.
[0313] The examples disclosed herein ensure the integrity of the QMC is verified when it is sent from the UE to the RAN.
[0314] In the example, if the QMC is stored in the UE when the UE is in idle or inactive mode, the UE can send the stored QMC to the RAN when the UE moves to connected mode. This can be ensured through several methods described herein.
[0315] The examples described herein assume that a UE may move from one cell to another in idle or inactive mode. In the examples, if the QMC is stored when the UE connects to a cell and the UE subsequently moves to a connection mode with another cell, the new serving cell should be able to verify the integrity of the QMC.
[0316] In all the options given below, the RAN can be considered as one or more access nodes, where the access node can be a gNodeB and / or a wireless edge computing server. Furthermore, the storage in the UE should be located in a secure location, such as a TEE or UICC. QMC-related data stored in the UE may be tampered with at the UE itself or by a man-in-the-middle attack (such as a fake BTS); this document considers various options for detecting any tampering and the possible locations of such tampering (at the UE or outside the UE).
[0317] Algorithms used for hashing or encryption can be pre-configured in the UE using existing technology processes such as SoR, UPU, or OTA configuration updates.
[0318] Figure 10 , 11 Figures 12 and 13 show examples of signaling between entities. Figure 10 , 11 Examples of methods 1000, 1100, 1200, and 1300 are also shown in 12 and 13.
[0319] Figure 10 , 11 Figures 12 and 13 illustrate methods performed by a system that includes interactions between different system entities. Figure 10 , 11 Figures 12 and 13 also show a collection of individual methods executed separately by different system entities.
[0320] about Figure 10 In this variant, the AMF will use the RAND value and QMC information to generate a hash value for the MBS QMC configuration. The hash value of the MBS QMC configuration and the algorithm used to generate it are sent to the UE via a secure NAS connection and stored in the UE's TEE / secure memory location when the UE is in connected mode, while access restrictions are implemented.
[0321] The next time the UE moves from idle mode to connected mode, the hash value HMBS_QMC and the MBS QMC configuration are sent from the UE to the RAN. The RAN can verify the integrity of the MBS QMC with the assistance of the AMF.
[0322] In some examples, the hash value can be calculated by applying a hash algorithm such as MD5SUM or SHA256 to only the QMC information. However, using RAND can further ensure that authentication of the UE that provides the QMC information can also be verified.
[0323] exist Figure 10 In box 1, the AMF stores the MBS QMC configuration. The AMF will generate a RAND and use a cryptographic hash function to generate and store the hash value HMBS_QMC.
[0324] exist Figure 10 At box 2, the AMF will send an Initial Context Establishment Request or a UE Context Modification Request to the RAN, carrying the MBS QMC configuration and hash value HMBS_QMC.
[0325] exist Figure 10 At box 3, the RAN will send an RRC reconfiguration to the UE with the MBS QMC reconfiguration and the hash value HMBS_QMC. The UE will store this hash value for future use.
[0326] exist Figure 10 At box 4, the UE is in RRC connected mode; after the MBS session terminates, the UE moves to RRC idle mode. The RAN will delete the MBS QMC configuration.
[0327] exist Figure 10 In box 5, when the UE moves to the RRC connection state, the UE will send the MBS QMC configuration and the hash value HMBS_QMC stored in box 3 to the RAN in the RRC establishment completion message. The RAN will obtain RAND from the AMF, thereby enabling the RAN to generate the expected HMBS_QMC using the received MBS_QMC, and compare the generated hash value with the received HMBS_QMC to verify integrity. If the verification is successful, the RAN will use the MBS QMC configuration.
[0328] In some examples, the RAN can send the received MBS_QMC and HMBS_QMC to the AMF and request verification. Upon successful verification, the AMF can respond with an affirmative ACK, making the MBS_QMC available for use.
[0329] about Figure 11 In this variant, the AMF sends the MBS QMC configuration to the RAN. The RAN generates an HMBS_QMC hash value using PCI and EARFCN. The generated HMBS_QMC is then sent to the UE. When the UE moves from idle mode to connected mode, the HMBS_AMC and MBS QMC configurations are sent to the RAN. The RAN generates the expected HMBS_QMC and verifies it using the HMBS_QMC.
[0330] exist Figure 11 In box 1, AMF storage MBS QMC configuration.
[0331] exist Figure 11 In box 2, the AMF sends the MBS QMC configuration to the RAN in the Initial Context Establishment Request or UE Context Modification Request message. The RAN will store the MBS QMC configuration and will use MBS_QMC, the PCI value, and EARFCN-DL as inputs to the cryptographic hash function to generate the hash value HMBS_QMC.
[0332] exist Figure 11 At box 3, the RAN will send an RRC reconfiguration message to the UE carrying the MBS QMC configuration and hash value HMBS_QMC. The UW will store the QMC configuration and hash value. Furthermore, at box 3c, the value required for later hash value verification is stored in the AMF.
[0333] exist Figure 11 At box 4, the UE is in RRC connected mode and moves to RRC idle mode. The MBS session is also terminated. The RAN will delete the MBS QMC configuration.
[0334] exist Figure 11At box 5, when the UE moves to RRC connected mode, it sends an RRC establishment complete message to the RAN, carrying the MBS QMC configuration and the hash value HMBS_QMC. The RAN will generate the expected HMBS_QMC and compare it with the received HMBS_QMC for verification. If the verification is successful, the RAN adopts the configuration.
[0335] In some examples, it is expected that HMBS_QMC can be obtained from the AMF and compared with the value obtained from the UE to ensure that the QMC and / or hash value has not been tampered with in the UE.
[0336] In some examples, the serving RAN can obtain the PCI and EARFCN_DL stored in box 3c from the AMF, calculate the expected HMBS_QMC, and then compare them to verify the integrity of the QMC.
[0337] In some examples, this can also be accomplished through communication between the serving RAN and the previous serving RAN. This communication may include, for example: The new RAN will send the HMBS_QMC and MBS_QMC received from the UE to the old RAN and request verification.
[0338] Alternatively, the new RAN obtains the PCI and EARFCN_DL from the old RAN and calculates the hash value itself for verification.
[0339] about Figure 12 In this variant, a hash value is generated, and only the RAND and algorithm information are sent to the UE; therefore, the UE also generates its own hash value. Later, when the UE moves from an idle state to a connected state, the RAN forwards this to the AMF, allowing the RAN to verify the actual configuration with the AMF's assistance. In this option, the QMC_ID can also be used instead of the RAND value. Figure 13 ).
[0340] exist Figure 13 In the example, with Figure 10The main difference in the example is that the hash value is never sent to the UE or via the over-the-air (OTA) interface; instead, it is calculated at both ends. Only the RAND value used to generate the hash value is sent to the UE, so the UE can also generate the hash value. Later, when the UE moves from idle mode to connected mode, the hash value HMBS_QMC is sent from the UE to the RAN, and after the AMF performs hash verification using the previously stored hash value (from Box 1), the RAN can obtain the MBSQMC configuration from the AMF. In Box 5, when the UE sends the QMC and hash value, the AMF recalculates the hash value using the received QMC configuration and compares it with both the hash value received from the UE and the hash value stored in the AMF. If either comparison fails, the verification fails. If both succeed, the QMC received from the UE is correct and usable.
[0341] about Figure 14 In this variant, the QMC ID is used as a reference for the QMC value configuration. Only the QMC ID is shared with the UE; later, when the configuration is needed, the QMC ID is provided, and the MBS QMC configuration is obtained from the AMF using the associated QMC_ID.
[0342] about Figure 14 In this variant, the AMF generates AN_PUB and AN_PRIV keys. The AMF uses the AN_PRIV key to encrypt the MBS_QMC. The encrypted MBS_QMC can then be sent to the UE. When the UE moves from idle mode to connected mode, the UE sends the encrypted MBS_QMC to the RAN; if the RAN has already received the AN_PUB key from the AMF, the RAN decrypts the MBS_QMC itself; otherwise, the RAN requests the AMF to decrypt it in order to subsequently receive the unencrypted MBS_QMC.
[0343] exist Figure 14 In box 1, the AMF will store the MBS QMC configuration. The AMF will generate AN_PUB and AN_PRIV, which are the private and public key pairs. This key pair is the same for all RANs under this particular AMF. The AMF will use AN_PRIV to encrypt the MBS_QMC.
[0344] exist Figure 14 At box 2, the AMF sends the encrypted MBS_QMC value to the RAN, and optionally includes the AN_PUB key in the Initial Context Establishment Request message or UE Context Modification Request sent to the RAN. The RAN will store the MBS QMC configuration and the AN_PUB key.
[0345] exist Figure 14At box 3, the RAN sends an RRC reconfiguration message carrying the encrypted MBS QMC to the UE, and the encrypted MBS QMC is securely stored in the UE.
[0346] exist Figure 14 At box 4, due to the termination of the MBS session, the UE moves from the connected state to the idle state. Therefore, the MBS QMC configuration in the RAN is also deleted.
[0347] exist Figure 14 At box 5, the UE moves to the RRC connection state. The UE will send an RRC establishment completion message to the RAN, carrying the encrypted MBS QMC securely stored in the UE.
[0348] In some examples, if all RANs are configured with the AN_PUB key during box 2, the encrypted MBS_QMC is decrypted and retrieved at the access node.
[0349] In some examples, if the RAN node is not configured with the AN_PUB key, the encrypted MBC_QMC received from the UE can be sent to the AMF for decryption.
[0350] Figure 15A An example block diagram of device 130 is shown. Device 130 may be a controller of a device or equipment, such as terminal node 110, for example UE 46, access node 120, or core node 129. Device 130 may be considered as a controller or controller device.
[0351] The controller 130 can be implemented as a controller circuit. The controller 130 can be implemented in hardware only, some aspects of it can be implemented in software (including firmware) only, or it can be implemented by a combination of hardware and software (including firmware).
[0352] like Figure 15A As shown, the controller 130 can be implemented using instructions that implement hardware functions, such as executable instructions 136 in a general-purpose or special-purpose processor 132, which can be stored on a machine-readable storage medium (disk, memory, etc.) for execution by the processor 132.
[0353] Processor 132 is configured to read from and write to memory 134. Processor 132 may also include an output interface and an input interface, via which processor 132 outputs data and / or commands and via the input interface to processor 132.
[0354] Memory 134 stores instructions, programs, or code 136 that control the operation of device 130 when loaded into processor 132. The computer program instructions, programs, or code 136 provide logic and routines that enable device 130 to perform the methods illustrated in the figures. Processor 132 is configured to load and execute the instructions, programs, or code 136 by reading memory 134.
[0355] Device 130 includes: At least one processor 132; and At least one memory 134 stores instructions that, when executed by at least one processor 132, cause the device to perform at least the following operations: Receive configuration information 172 and at least one random value 190 from the first access node 120A; The received configuration information 172 is stored in a received configuration information data structure 177 in at least one secure storage environment; At least in part based on the received configuration information 172 and at least one received random value 190, a cryptographic encoding 174 of at least the configuration information 172 is generated; and At least in part, based on the transition from radio disconnected mode 180 to radio connected mode 182, the contents 184 of the received configuration information data structure 177 and the cryptographic encoding 174 of the configuration information 172 are transmitted to the second access nodes 120A and 120B so that the stored configuration information can be verified.
[0356] Device 130 includes: At least one processor 132; and At least one memory 134 stores instructions that, when executed by at least one processor 132, cause the device to perform at least the following operations: Receive configuration information 172 and at least one random value 190 from at least one core node 129; This causes configuration information 172 and at least one random value 190 to be transmitted to terminal node 110; Receive authentication configuration information 192 and at least configuration information 172's password encoding 174 from terminal node 110; and The received verification configuration information 192 and the received at least configuration information 172 are transmitted to the core node 129 via a cryptographic encoding 174 to enable the verification of the received verification configuration information 192.
[0357] Device 130 includes: At least one processor 132; and At least one memory 134 stores instructions that, when executed by at least one processor 132, cause the device to perform at least the following operations: A password encoding 174 based at least partially on configuration information 172 and at least one random value 190 is generated based on configuration information 172. This causes configuration information 172 and at least one random value 190 to be transmitted to at least one access node 120A; Receive authentication configuration information 192 and password encoding 174 of at least configuration information 174 from access nodes 120A and 120B; and A password encoding 194 is generated based at least in part on the verification configuration information 192 and at least one random value 190; The password encoding 194 of at least the verification configuration information 192 is compared with the password encoding 174 of the generated at least the configuration information 172 and the password encoding 174 of the received at least the configuration information 172 to verify the received verification configuration information 192.
[0358] Device 130 includes: At least one processor 132; and At least one memory 134 stores instructions that, when executed by at least one processor 132, cause the device to perform at least the following operations: Receive configuration information 172 and at least the password encoding 174 of configuration information 172 from the first access node 120A; The received configuration information 172 is stored in a received configuration information data structure 177 in at least one secure storage environment, and the password encoding 174 of the configuration information 172 is stored in at least one secure storage environment; and At least in part, based on the transition from radio disconnected mode 180 to radio connected mode 182, the contents 184 of the received configuration information data structure 177 and the stored cryptographic encoding 174 of the configuration information 172 are transmitted to the second access nodes 120A and 120B so that the stored configuration information can be verified.
[0359] Device 130 includes: At least one processor 132; and At least one memory 134 stores instructions that, when executed by at least one processor 132, cause the device to perform at least the following operations: Receive configuration information 172 from at least one core node 129; Generate a password encoding 174 with at least configuration information 172; This causes configuration information 172 and at least the password encoding 174 of configuration information 172 to be transmitted to terminal node 110; Receive authentication configuration information 192 and at least configuration information 172's password encoding 174 from terminal node 120; and The received verification configuration information 192 is verified at least in part based on the password encoding 174 of the received configuration information 172.
[0360] Device 130 includes: At least one processor 132; and At least one memory 134 stores instructions that, when executed by at least one processor 132, cause the device to perform at least the following operations: This causes configuration information 172 to be transmitted to at least one access node 120; Receive a request 199 from the requesting access node for assistance in verifying the authentication configuration information 192; and Information 198 is transmitted to the requesting access node so that the verification configuration information 192 can be verified.
[0361] like Figure 15A As shown, instructions, programs, or code 136 can reach device 130 via any suitable delivery mechanism 162. Delivery mechanism 162 can be, for example, a machine-readable medium, a computer-readable medium, a non-transitory computer-readable storage medium, a computer program product, a memory device, a recording medium such as an optical disc read-only memory (CD-ROM), a digital versatile optical disc (DVD), or a solid-state storage device, or an article of manufacture that includes or tangibly embodies the computer program 136. The delivery mechanism can be a signal configured to reliably transmit the computer program 136. Device 130 can propagate or transmit the computer program 136 as a computer data signal.
[0362] The term “non-transient” as used in this article refers to the limitation on the medium itself (i.e., tangible medium rather than signals), rather than the limitation on the persistence of data storage (e.g., RAM and ROM).
[0363] Computer program instructions for causing the device to perform at least the following operations or for performing at least the following operations: Receive configuration information 172 and at least one random value 190 from the first access node 120A; The received configuration information 172 is stored in a received configuration information data structure 177 in at least one secure storage environment; At least in part based on the received configuration information 172 and at least one received random value 190, a cryptographic encoding 174 of at least the configuration information 172 is generated; and At least in part, based on the transition from radio disconnected mode 180 to radio connected mode 182, the contents 184 of the received configuration information data structure 177 and the cryptographic encoding 174 of the configuration information 172 are transmitted to the second access nodes 120A and 120B so that the stored configuration information can be verified.
[0364] Computer program instructions for causing the device to perform at least the following operations or for performing at least the following operations: Receive configuration information 172 and at least one random value 190 from at least one core node 129; This causes configuration information 172 and at least one random value 190 to be transmitted to terminal node 110; Receive authentication configuration information 192 and at least configuration information 172's password encoding 174 from terminal node 110; and The received verification configuration information 192 and the received at least configuration information 172 are transmitted to the core node 129 via a cryptographic encoding 174 to enable the verification of the received verification configuration information 192.
[0365] Computer program instructions for causing the device to perform at least the following operations or for performing at least the following operations: A password encoding 174 based at least partially on configuration information 172 and at least one random value 190 is generated based on configuration information 172. This causes configuration information 172 and at least one random value 190 to be transmitted to at least one access node 120A; Receive authentication configuration information 192 and password encoding 174 of at least configuration information 174 from access nodes 120A and 120B; At least partially based on the verification configuration information 192 and at least one random value 190, a password encoding 194 is generated that verifies at least the configuration information 192; and The password encoding 194 of at least the verification configuration information 192 is compared with the password encoding 174 of the generated at least the configuration information 172 and the password encoding 174 of the received at least the configuration information 172 to verify the received verification configuration information 192.
[0366] Computer program instructions for causing the device to perform at least the following operations or for performing at least the following operations: Receive configuration information 172 and at least the password encoding 174 of configuration information 172 from the first access node 120A; The received configuration information 172 is stored in a received configuration information data structure 177 in at least one secure storage environment, and the password encoding 174 of the configuration information 172 is stored in at least one secure storage environment; and At least in part, based on the transition from radio disconnected mode 180 to radio connected mode 182, the contents 184 of the received configuration information data structure 177 and the stored cryptographic encoding 174 of the configuration information 172 are transmitted to the second access nodes 120A and 120B so that the stored configuration information can be verified.
[0367] Computer program instructions for causing the device to perform at least the following operations or for performing at least the following operations: Receive configuration information 172 from at least one core node 129; Generate a password encoding 174 with at least configuration information 172; This causes configuration information 172 and at least the password encoding 174 of configuration information 172 to be transmitted to terminal node 110; Receive authentication configuration information 192 and at least configuration information 172's password encoding 174 from terminal node 120; and The received verification configuration information 192 is verified at least in part based on the password encoding 174 of the received configuration information 172.
[0368] Computer program instructions for causing the device to perform at least the following operations or for performing at least the following operations: This causes configuration information 172 to be transmitted to at least one access node 120; Receive a request 199 from the requesting access node for assistance in verifying the authentication configuration information 192; and Information 198 is transmitted to the requesting access node so that the verification configuration information 192 can be verified.
[0369] Computer program instructions may be included in a computer program, a non-transitory computer-readable medium, a computer program product, or a machine-readable medium. In some, but not all, examples, computer program instructions may be distributed across more than one computer program.
[0370] Although memory 134 is shown as a single component / circuit, it can be implemented as one or more separate components / circuits, some or all of which may be integrated / removable and / or provide permanent / semi-permanent / dynamic / cached storage.
[0371] In the example, memory 134 includes random access memory 158 and read-only memory 160. In the example, computer program 136 may be stored in read-only memory 158. See, for example, [link to example]. Figure 15B .
[0372] Although processor 132 is shown as a single component / circuit, it can be implemented as one or more separate components / circuits, some or all of which may be integrated / removable. Processor 132 may be a single-core or multi-core processor.
[0373] References to “computer-readable storage medium,” “computer program product,” “tangible computer program,” or “controller,” “computer,” “processor,” etc., should be understood to encompass not only computers with different architectures (such as single-processor / multi-processor architectures and sequential (von Neumann) / parallel architectures) but also special-purpose circuits such as field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), signal processing devices, and other processing circuitry systems. References to computer programs, instructions, code, etc., should be understood to encompass software or firmware used with programmable processors, such as the programmable content of hardware devices, whether that content is for processor instructions or for configuration settings of fixed-function devices, gate arrays, or programmable logic devices, etc.
[0374] As used in this application, the term "circuit" may refer to one or more of the following: (a) Hardware circuit implementation only (e.g., implemented with purely analog and / or digital circuits) and (b) A combination of hardware circuitry and software, such as (if applicable): i. A combination of (multiple) analog and / or digital hardware circuits with software / firmware, and ii. Any part of a hardware processor having software (including (multiple) digital signal processors), software, and (multiple) memories, which work together to enable a device (such as a mobile phone or server) to perform various functions, and (c) (Multiple) hardware circuits and / or (multiple) processors, such as (multiple) microprocessors or a portion thereof, which require software (e.g., firmware) to operate, but may be absent when the software is not required to operate.
[0375] This definition of "circuit" applies to all uses of the term in this application (including in any claim). As another example, as used in this application, the term "circuit" also covers only the implementation of hardware circuitry or processors and their accompanying software and / or firmware. For example, and if applicable to claim elements, the term "circuit" also covers baseband integrated circuits for mobile devices or similar integrated circuits in servers, cellular network devices, or other computing or networking devices.
[0376] The boxes shown in the accompanying drawings may represent steps in the method and / or code segments in computer program 136. The description of a specific order of boxes does not necessarily imply a required or preferred order, and the order and arrangement of boxes can vary. Furthermore, some boxes may be omitted.
[0377] When a structural feature is described, it may be replaced by a component that performs one or more functions to perform that structural feature, whether or not those functions are explicitly or implicitly described.
[0378] When a structural feature is described, it may be replaced by a component that performs one or more functions to perform that structural feature, whether or not those functions are explicitly or implicitly described.
[0379] In the example, device 130 may include components for performing one or more methods or at least a portion thereof as disclosed herein.
[0380] In the example, device 130 may be configured to perform one or more methods, or at least a portion thereof, as disclosed herein.
[0381] The above example can be used as an enabling component for the following: Automotive systems; telecommunications systems; electronic systems including consumer electronics; distributed computing systems; media systems for generating or presenting media content, including audio content, visual content, and audiovisual content, as well as mixed reality, mediated reality, virtual reality, and / or augmented reality; personal systems including personal health systems or personal fitness systems; navigation systems; user interfaces, also known as human-machine interfaces; networks including cellular networks, non-cellular networks, and optical networks; ad hoc networks; the Internet of Things; the Internet of Things; virtualized networks; and related software and services.
[0382] According to the examples of this disclosure, the device can be located in an electronic device (e.g., a mobile terminal). However, it should be understood that the mobile terminal is merely an illustrative example of an electronic device that will benefit from the implementation examples of this disclosure and should not be construed as limiting the scope of this disclosure to mobile terminals. While the device can be located in a mobile terminal in some implementation examples, other types of electronic devices can readily adopt the examples of this disclosure, including but not limited to mobile communication devices, handheld portable electronic devices, wearable computing devices, portable digital assistants (PDAs), pagers, mobile computers, desktop computers, televisions, gaming devices, laptop computers, cameras, video recorders, GPS devices, and other types of electronic systems. Furthermore, the examples of this disclosure can be readily adopted by devices regardless of whether they are intended to provide mobility.
[0383] The term "includes" is used in this document in an inclusive rather than exclusive sense. That is, any reference to X including Y indicates that X may include only one Y or may include more than one Y. If "includes" is intended to be used in an exclusive sense, it will be explicitly stated in the context by referring to "includes only one..." or using "consisting of...".
[0384] In this specification, the terms “connection,” “coupling,” and “communication,” and their derivatives, mean operatively connected / coupled / communicating. It should be understood that any number or combination of intermediate components (including no intermediate components) may be present to provide direct or indirect connection / coupling / communication. Any such intermediate component may include hardware and / or software components.
[0385] As used herein, the term "determine / perform determination" (and its grammatical variations) can include at least calculation, operation, processing, derivation, measurement, investigation, identification, lookup (e.g., searching in a table, database, or other data structure), ascertainment, etc. Furthermore, "determine" can include receiving (e.g., receiving information), accessing (e.g., accessing data in memory), obtaining, etc. Additionally, "determine" can include parsing, selecting, picking, establishing, etc.
[0386] Various examples have been referenced in this specification. Descriptions of features or functions of an example indicate which features or functions exist in that example. The use of the terms "example," "for example," "able," or "may" in the text indicates that, whether explicitly stated or not, these features or functions exist at least in the described example, and may, but not necessarily, exist in some or all other examples. Thus, "example," "for example," "able," or "may" refers to a specific instance of a class of examples. An instance's property can be a property of only that instance, or a property of the class, or a property of a subclass of a class that includes some, but not all, instances of that class. Therefore, it is implicitly disclosed that features described with reference to one example, and not another, may be used as part of a working composition in that other example where possible, but are not necessarily required to be used in that other example.
[0387] As used herein, “at least one of the following” and “at least one of the following” and similar wording, where a list of two or more elements is connected by “and” or “or”, means at least any one element, or at least any two or more elements, or at least all elements.
[0388] Although examples have been described with reference to various examples in the preceding paragraphs, it should be understood that modifications may be made to the given examples without departing from the scope of the claims.
[0389] The features described above can be used in combinations other than those explicitly described above.
[0390] Although some features have been described with reference to certain characteristics, these functions can be performed by other features, whether or not they are described.
[0391] A description of a feature (such as a device or a component of a device) configured to perform a function or for performing a function should also be considered as disclosing a method for performing that function. For example, a description of a device configured to perform one or more actions or for performing one or more actions should also be considered as disclosing a method for performing those one or more actions with or without the device.
[0392] Although features have been described with reference to some examples, these features may also exist in other examples, whether or not they are described.
[0393] The terms “a,” “an,” or “the” are used in this document with an inclusive rather than exclusive meaning. That is, any reference to X including a / an / the Y indicates that X may include only one Y or may include more than one Y, unless the context clearly indicates the opposite. If “a,” “an,” or “the” is intended to be used with an exclusive meaning, it will be clearly stated in the context. In some cases, “at least one” or “one or more” may be used to emphasize an inclusive meaning, but no exclusive meaning should be inferred from the absence of these terms.
[0394] The presence of a feature (or combination of features) in a claim is a reference to that feature or combination of features itself, as well as to features that achieve substantially the same technical effect (equivalent features). Equivalent features include, for example, features that are variations and achieve substantially the same result in substantially the same manner. Equivalent features include, for example, features that perform substantially the same function in substantially the same manner to achieve substantially the same result.
[0395] In this specification, various examples have been referenced to describe the characteristics of the examples using adjectives or adjective phrases. Such descriptions of the characteristics associated with the examples indicate that the characteristics exist exactly as described in some examples, and substantially as described in others.
[0396] The foregoing description illustrates some examples of this disclosure; however, those skilled in the art will recognize possible alternative structures and methodological features that provide equivalent functionality to the specific examples of such structures and features described above, and for the sake of brevity and clarity, have been omitted from the foregoing description. Nevertheless, the foregoing description should be understood to implicitly include references to such alternative structures and methodological features that provide equivalent functionality, unless such alternative structures or methodological features are explicitly excluded in the foregoing description of the examples of this disclosure.
[0397] Despite efforts made in the foregoing specification to draw attention to those features deemed important, an applicant may seek protection by means of the claims for any patentable feature or combination of features mentioned above and / or shown in the figures, whether or not they have been emphasized.
Claims
1. An apparatus comprising components for: Receive configuration information and at least the password encoding of the configuration information from the first access node; The received configuration information is stored in a received configuration information data structure in at least one secure storage environment, and the password encoding of at least the configuration information is stored in at least one secure storage environment; as well as At least in part, based on the transition from radio disconnected mode to radio connected mode, the contents of the received configuration information data structure and at least the stored cryptographic encoding of the configuration information are transmitted to the second access node so that the stored configuration information can be verified.
2. The apparatus according to claim 1, wherein, The password encoding of the configuration information is generated at least in part based on the configuration information and at least one identifier configured to uniquely identify the first access node.
3. The apparatus according to claim 2, wherein, At least the cryptographic encoding of the configuration information is generated using the configuration information and at least one identifier configured to uniquely identify the first access node as input to at least one cryptographic algorithm.
4. The apparatus according to claim 1, wherein, The password encoding of the configuration information is at least partially generated based on the configuration information and at least one random value.
5. The apparatus according to any one of the preceding claims, wherein, The configuration information and at least the cryptographic encoding of the configuration information are received during radio connection mode.
6. The apparatus according to any one of the preceding claims, wherein, The configuration information includes configuration information for collecting experience quality measurements.
7. A method comprising: Receive configuration information and at least the password encoding of the configuration information from the first access node; The received configuration information is stored in a received configuration information data structure in at least one secure storage environment, and the password encoding of at least the configuration information is stored in at least one secure storage environment; as well as At least in part, based on the transition from radio disconnected mode to radio connected mode, the contents of the received configuration information data structure and at least the stored cryptographic encoding of the configuration information are transmitted to the second access node so that the stored configuration information can be verified.
8. The method according to claim 7, wherein, The password encoding of the configuration information is generated at least in part based on the configuration information and at least one identifier configured to uniquely identify the first access node.
9. A computer program comprising instructions that, when executed by a device, cause the device to perform at least the following: Receive configuration information and at least the password encoding of the configuration information from the first access node; The received configuration information is stored in a received configuration information data structure in at least one secure storage environment, and the password encoding of at least the configuration information is stored in at least one secure storage environment; as well as At least in part, based on the transition from radio disconnected mode to radio connected mode, the contents of the received configuration information data structure and at least the stored cryptographic encoding of the configuration information are transmitted to the second access node so that the stored configuration information can be verified.
10. An apparatus comprising components for: Receive configuration information from at least one core node; Generate a password encoding for at least the aforementioned configuration information; This causes at least the configuration information and the cryptographic encoding of the configuration information to be transmitted to the terminal node; Receive authentication configuration information and at least the password encoding of the configuration information from the terminal node; as well as The received verification configuration information is verified at least in part based on the cryptographic encoding of the received configuration information.
11. The apparatus according to claim 10, wherein, The cryptographic encoding that generates at least the configuration information includes generating the cryptographic encoding based at least in part on the received configuration information and at least one identifier configured to uniquely identify the access node.
12. The apparatus according to claim 11, wherein, The cryptographic encoding that generates at least the configuration information includes using the received configuration information and at least one identifier configured to uniquely identify the access node as input to at least one cryptographic algorithm.
13. The apparatus according to any of the preceding claims, wherein, The configuration information includes configuration information for collecting experience quality measurements.
14. The apparatus according to any of the preceding claims, wherein, The component is configured to cause at least one of the following to be transmitted to at least one core node: At least the password encoding of the configuration information; or At least one identifier configured to uniquely identify the access node is used when generating the cryptographic encoding of at least the configuration information.
15. The apparatus according to any of the preceding claims, wherein, Verifying the received verification configuration information includes: generating a password encoding for at least the verification configuration information, and comparing the password encoding for at least the verification configuration information with the password encoding for the received configuration information.
16. The apparatus according to claim 15, wherein, The component is configured to receive at least one identifier configured to uniquely identify the access node for use in generating the cryptographic encoding of at least the verification configuration information.
17. The apparatus according to any of the preceding claims, wherein, Verifying the received verification configuration information includes: receiving an expected password encoding of at least configuration information, and comparing the received password encoding of at least configuration information with the expected password encoding of the received at least configuration information.
18. The apparatus according to any of the preceding claims, wherein, Verifying the received verification configuration information includes: inducing the transmission of the received verification configuration information and the password encoding of the received at least configuration information for verification.
19. A computer program comprising instructions that, when executed by a device, cause the device to perform at least the following: Receive configuration information from at least one core node; Generate a password encoding for at least the aforementioned configuration information; This causes at least the configuration information and the cryptographic encoding of the configuration information to be transmitted to the terminal node; Receive authentication configuration information and at least the password encoding of the configuration information from the terminal node; as well as The received verification configuration information is verified at least in part based on the cryptographic encoding of the received configuration information.
20. An apparatus comprising components for: This causes configuration information to be transmitted to at least one access node; Receive a request from the requesting access node for assistance in verifying the authentication configuration information; and The information is transmitted to the requesting access node to enable the verification configuration information to be verified.
21. The apparatus according to claim 20, wherein, The configuration information includes configuration information for collecting experience quality measurements.
22. The apparatus according to claim 20 or 21, wherein, Inducing information transmission includes inducing the transmission of at least one of the following: At least the expected password encoding of the configuration information; or At least one identifier configured to uniquely identify the access node.
23. The apparatus according to any one of claims 20 to 22, wherein, The component is configured to receive at least one of the following: At least the password encoding of the configuration information; or At least one identifier configured to uniquely identify the access node is used when generating the password encoding for at least the configuration information.
24. A method comprising: This causes configuration information to be transmitted to at least one access node; Receive a request from the requesting access node for assistance in verifying the authentication configuration information; as well as The information is transmitted to the requesting access node to enable the verification configuration information to be verified.
25. A computer program comprising instructions that, when executed by a device, cause the device to perform at least the following: This causes configuration information to be transmitted to at least one access node; Receive a request from the requesting access node for assistance in verifying the authentication configuration information; and The information is transmitted to the requesting access node to enable the verification configuration information to be verified.