Method and apparatus for dynamically changing security algorithms in a randomised pattern
Patent Information
- Application Number
- CN202610224842.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2025-02-27
- Filing Date
- 2026-02-25
- Publication Date
- 2026-09-04
AI Technical Summary
例如,安全级别较高的安全算法需要更长的密钥长度和/或更复杂的计算,因此,在通信期间可导致某些延迟和/或相对较大的能耗
[0053] According to embodiments of this disclosure, exemplary embodiments of this disclosure propose a mechanism that provides specific means and/or procedures for dynamically changing a security algorithm in a randomized mode.
Smart Images

Figure CN122698232A_ABST
Abstract
Description
Technical Field
[0001] Various exemplary embodiments of this disclosure generally relate to communication technologies, and more specifically, to methods and apparatus for dynamically changing security algorithms in a randomized mode. Background Technology
[0002] In communication networks, communication content needs to be encrypted to improve security. Various security algorithms have been developed to meet the ever-increasing security demands.
[0003] Typically, each security algorithm has its own advantages and disadvantages. For example, higher-security algorithms require longer key lengths and / or more complex computations, which can lead to some latency and / or relatively high energy consumption during communication. Conversely, lower-security algorithms have shorter key lengths and / or simpler computations, and therefore lower security levels. Summary of the Invention
[0004] This invention is intended to present some aspects in a simplified form, which will be further described in the following detailed description. This invention is not intended to identify key or essential features of the claimed subject matter, nor is it intended to limit the scope of the claimed subject matter.
[0005] Certain aspects of this disclosure and its embodiments can provide solutions to these or other challenges. Various embodiments are presented herein to address one or more problems disclosed herein. Specific methods and apparatus are provided for dynamically changing security algorithms in randomized modes.
[0006] A first aspect of this disclosure provides an apparatus operating as a terminal device, comprising: at least one processor; and at least one memory containing computer program code. The at least one memory and the computer program code are configured, together with the at least one processor, to cause the apparatus operating as the terminal device to at least: receive a first message from a network entity for configuring a security mode. The first message indicates: a list of security algorithms, and a change mode for the security algorithms. The change mode includes a randomization mode. When the randomization mode is enabled, the apparatus operating as the terminal device changes the security algorithms based on at least one random number generated by the apparatus operating as the terminal device.
[0007] In an exemplary embodiment of this disclosure, the at least one memory and the computer program code are further configured, together with the at least one processor, to cause the apparatus operating as the terminal device to at least: receive a seed from the network entity; and generate a configured number of random numbers based on the seed.
[0008] In an exemplary embodiment of this disclosure, the at least one memory and the computer program code are further configured, together with the at least one processor, to cause the apparatus operating as the terminal device to at least: obtain parameters for generating a seed; generate the seed based on the parameters; and generate a configured number of random numbers based on the seed.
[0009] In an exemplary embodiment of this disclosure, the parameters for generating the seed include a key exported locally by the terminal device.
[0010] In an exemplary embodiment of this disclosure, the change mode indicates at least one of the following: a condition that triggers a change in the security algorithm, and / or a method of selecting a security algorithm from the list of security algorithms to be used after the change in the security algorithm is triggered. When the randomization mode is enabled, at least one of the conditions that trigger the change and / or the method of selecting the security algorithm is based on the at least one random number.
[0011] In an exemplary embodiment of this disclosure, the condition triggering the change includes at least one of the following: a time-based condition or a load-based condition. The time-based condition is met after a period of time has passed since the security algorithm was used. When the randomization mode is enabled, the period of time is determined based on a random number from the at least one random number set. The load-based condition is met after a load has been applied to the security algorithm. When the randomization mode is enabled, the load is determined based on a random number from the at least one random number set. The load is indicated by at least one of the following: the length of the plaintext, or the number of messages.
[0012] In an exemplary embodiment of this disclosure, the at least one random number includes a first set of random numbers for determining a set of time periods; and / or the at least one random number includes a second set of random numbers for determining a set of loads.
[0013] In an exemplary embodiment of this disclosure, when the randomization mode is enabled, the sequence number of the security algorithm to be used is determined based on a random number from the at least one set of random numbers. The at least one set of random numbers includes a third set of random numbers used to determine a set of sequence numbers for the security algorithm.
[0014] In an exemplary embodiment of this disclosure, the change mode indicates that the sequence number of the security algorithm to be used is determined based on a set of bits in a key. The set of bits used to determine the security algorithm to be used has a first position in the key, and the set of bits used to determine a previously used security algorithm has a second position in the key. The first position is shifted relative to the second position. The shift is pre-configured or determined based on a random number from the at least one random number.
[0015] In an exemplary embodiment of this disclosure, the at least one memory and the computer program code are further configured, together with the at least one processor, to cause the apparatus operating as the terminal device to at least: send an acceptance message to the network entity when the apparatus operating as the terminal device supports the security algorithm list and the security algorithm change mode; or send a rejection message to the network entity when the apparatus operating as the terminal device does not support at least one of the security algorithm list or the security algorithm change mode; or wait for a period of time after receiving the first message when the apparatus operating as the terminal device does not support at least one of the security algorithm list or the security algorithm change mode.
[0016] In an exemplary embodiment of this disclosure, the rejection message includes at least one of the following: a list of supported security algorithms or a changed mode of the supported security algorithms of the device operating as the terminal device. The at least one memory and the computer program code are further configured, together with the at least one processor, to cause the device operating as the terminal device to at least perform: receiving a second message from the network entity for configuring a security mode. The second message indicates at least one of the following: at least a portion of the list of supported security algorithms, and / or a changed mode of the supported security algorithms.
[0017] In an exemplary embodiment of this disclosure, the entries for security algorithms in the security algorithm list include the type of the security algorithm and / or the key length of the security algorithm. The security algorithm list includes a subset of encryption algorithms and / or a subset of integrity protection algorithms. The security algorithm list is used for Non-Access Stratum (NAS) communication and / or Access Stratum (AS) communication. The network entity includes: a Radio Access Network (RAN) entity, or a core network entity including at least one of: Access and Mobility Management Function (AMF), User Plane Function (UPF), or Network Data Analysis Function (NWDAF). The terminal device includes: User Equipment (UE).
[0018] In an exemplary embodiment of this disclosure, the network entity includes a core network entity.
[0019] In an exemplary embodiment of this disclosure, the first message includes a Non-Access Stratum (NAS) security mode command. The network entity includes an Access and Mobility Management Function (AMF). The security algorithm list includes a subset of encryption algorithms for NAS and / or a subset of integrity protection algorithms for NAS. The key of the network entity includes: K AMF .
[0020] In an exemplary embodiment of this disclosure, the network entity includes a radio access network (RAN) entity.
[0021] In an exemplary embodiment of this disclosure, the network entity includes a base station (BS). The key of the network entity includes K. gNB .
[0022] In an exemplary embodiment of this disclosure, the first message includes an Access Layer (AS) security mode command. The security algorithm list includes a subset of encryption algorithms for Radio Resource Control (RRC) and / or User Plane (UP), and / or a subset of integrity protection algorithms for RRC and / or UP.
[0023] In an exemplary embodiment of this disclosure, the at least one memory and the computer program code are further configured, together with the at least one processor, to cause the apparatus operating as the terminal device to at least: receive an RRC connection reconfiguration message from the network entity. The RRC connection reconfiguration message indicates at least one of the following: enabling the change mode indicated by the first message for at least one data radio bearer (DRB); disabling the change mode indicated by the first message for at least one DRB; and / or, a change mode for a list of security algorithms and / or security algorithms for at least one DRB.
[0024] A second aspect of this disclosure provides an apparatus operating as a network entity, comprising: at least one processor; and at least one memory containing computer program code. The at least one memory and the computer program code are configured, together with the at least one processor, to cause the apparatus operating as the network entity to at least: send a first message to a terminal device for configuring a security mode. The first message indicates: a list of security algorithms, and a change mode for the security algorithms. The change mode includes a randomization mode. When the randomization mode is enabled, the apparatus operating as the network entity changes the security algorithms based on at least one random number generated by the apparatus operating as the network entity.
[0025] In an exemplary embodiment of this disclosure, the at least one memory and the computer program code are further configured, together with the at least one processor, to cause the means operating as the network entity to at least: send a seed to the terminal device; and generate a configured number of random numbers based on the seed.
[0026] In an exemplary embodiment of this disclosure, the at least one memory and the computer program code are further configured, together with the at least one processor, to cause the means operating as the network entity to at least: obtain parameters for generating a seed; generate the seed based on the parameters; and generate a configured number of random numbers based on the seed.
[0027] In an exemplary embodiment of this disclosure, the parameters used to generate the seed include a key exported locally by the network entity.
[0028] In an exemplary embodiment of this disclosure, the change mode indicates at least one of the following: a condition that triggers a change in the security algorithm, and / or a method of selecting a security algorithm from the list of security algorithms to be used after the change in the security algorithm is triggered. When the randomization mode is enabled, at least one of the conditions that trigger the change and / or the method of selecting the security algorithm is based on the at least one random number.
[0029] In an exemplary embodiment of this disclosure, the condition triggering the change includes at least one of the following: a time-based condition or a load-based condition. The time-based condition is met after a period of time has passed since the security algorithm was used. When the randomization mode is enabled, the period of time is determined based on a random number from the at least one random number set. The load-based condition is met after a load has been applied to the security algorithm. When the randomization mode is enabled, the load is determined based on a random number from the at least one random number set. The load is indicated by at least one of the following: the length of the plaintext, or the number of messages.
[0030] In an exemplary embodiment of this disclosure, the at least one random number includes a first set of random numbers for determining a set of time periods. The at least one random number includes a second set of random numbers for determining a set of load values.
[0031] In an exemplary embodiment of this disclosure, when the randomization mode is enabled, the sequence number of the security algorithm to be used is determined based on a random number from the at least one set of random numbers. The at least one set of random numbers includes a third set of random numbers used to determine a set of sequence numbers for the security algorithm.
[0032] In an exemplary embodiment of this disclosure, the change mode indicates that the sequence number of the security algorithm to be used is determined based on a set of bits in a key. The set of bits used to determine the security algorithm to be used has a first position in the key, and the set of bits used to determine a previously used security algorithm has a second position in the key. The first position is shifted relative to the second position. The shift is pre-configured or determined based on a random number from the at least one random number.
[0033] In an exemplary embodiment of this disclosure, the at least one memory and the computer program code are further configured, together with the at least one processor, to cause the apparatus operating as the network entity to at least: receive an accept message from the terminal device when the terminal device supports the security algorithm list and the security algorithm change mode; or receive a reject message from the terminal device when the terminal device does not support at least one of the security algorithm list or the security algorithm change mode; or determine that the terminal device does not support at least one of the security algorithm list or the security algorithm change mode when no response is received within a period of time after sending the first message.
[0034] In an exemplary embodiment of this disclosure, the rejection message includes at least one of the following: a list of security algorithms supported by the terminal device, or a change mode of the supported security algorithms. The at least one memory and the computer program code are further configured, together with the at least one processor, to cause the apparatus operating as the network entity to at least: store at least one of the following: a list of security algorithms supported by the terminal device or a change mode of the supported security algorithms; and / or send a second message to the terminal device for configuring a security mode. The second message includes at least one of the following: at least a portion of the list of supported security algorithms, and / or an indication of a change mode of the supported security algorithms.
[0035] In an exemplary embodiment of this disclosure, the at least one memory and the computer program code are further configured, together with the at least one processor, to cause the apparatus operating as the network entity to at least perform: sending a report to the operation management network entity regarding the capabilities of the terminal device. At least one of the security algorithm list or the change mode of the security algorithms is received from the operation management network entity or determined by the network entity.
[0036] In an exemplary embodiment of this disclosure, an entry for a security algorithm in the security algorithm list includes the type of the security algorithm and / or the key length of the security algorithm. The security algorithm list includes a subset of encryption algorithms and / or a subset of integrity protection algorithms. The security algorithm list is used for Non-Access Stratum (NAS) communication and / or Access Stratum (AS) communication. The network entity includes: a Radio Access Network (RAN) entity, and a core network entity including at least one of: Access and Mobility Management Function (AMF), User Plane Function (UPF), or Network Data Analysis Function (NWDAF). The terminal device includes: User Equipment (UE).
[0037] In an exemplary embodiment of this disclosure, the network entity includes a core network entity.
[0038] In an exemplary embodiment of this disclosure, the first message includes a Non-Access Stratum (NAS) security mode command. The network entity includes an Access and Mobility Management Function (AMF). The security algorithm list includes a subset of encryption algorithms for NAS and / or a subset of integrity protection algorithms for NAS. The key of the network entity includes: K AMF .
[0039] In an exemplary embodiment of this disclosure, the network entity includes a radio access network (RAN) entity.
[0040] In an exemplary embodiment of this disclosure, the network entity includes a base station (BS). The key of the network entity includes K. gNB .
[0041] In an exemplary embodiment of this disclosure, the first message includes an Access Layer (AS) security mode command. The security algorithm list includes a subset of encryption algorithms for Radio Resource Control (RRC) and / or User Plane (UP); and / or, a subset of integrity protection algorithms for RRC and / or UP.
[0042] In an exemplary embodiment of this disclosure, the at least one memory and the computer program code are further configured, together with the at least one processor, to cause the means operating as the network entity to at least: send an RRC connection reconfiguration message to the terminal device. The RRC connection reconfiguration message indicates at least one of the following: enabling the change mode indicated by the first message for at least one data radio bearer (DRB); disabling the change mode indicated by the first message for at least one DRB; and / or, a change mode for a list of security algorithms and / or security algorithms for at least one DRB.
[0043] In an exemplary embodiment of this disclosure, at least one of the security algorithm list or the change mode of the security algorithm is received by the network entity from the core network entity.
[0044] A third aspect of this disclosure provides a method performed by an apparatus operating as a terminal device, comprising: receiving a first message from a network entity for configuring a security mode. The first message indicates: a list of security algorithms, and a change mode for the security algorithms. The change mode includes a randomization mode. When the randomization mode is enabled, the apparatus operating as the terminal device changes the security algorithms based on at least one random number generated by the apparatus operating as the terminal device.
[0045] In exemplary embodiments of this disclosure, the method is performed by an apparatus according to any embodiment of the first aspect.
[0046] In an exemplary embodiment of this disclosure, the network entity includes a core network entity.
[0047] In an exemplary embodiment of this disclosure, the network entity includes a radio access network (RAN) entity.
[0048] A fourth aspect of this disclosure provides a method performed by an apparatus operating as a network entity, comprising: sending a first message to a terminal device for configuring a security mode. The first message indicates: a list of security algorithms, and an indication of a change mode for the security algorithms. The change mode includes a randomization mode. When the randomization mode is enabled, the apparatus operating as the network entity changes the security algorithms based on at least one random number generated by the apparatus operating as the network entity.
[0049] In exemplary embodiments of this disclosure, the method is performed by an apparatus according to any embodiment of the second aspect.
[0050] In an exemplary embodiment of this disclosure, the network entity includes a core network entity.
[0051] In an exemplary embodiment of this disclosure, the network entity includes a radio access network (RAN) entity.
[0052] A fifth aspect of this disclosure provides a computer-readable storage medium that stores instructions, when executed by at least one processor of a device, causing the at least one processor of the device to perform at least the method according to any of the above embodiments.
[0053] According to embodiments of this disclosure, exemplary embodiments of this disclosure propose a mechanism that provides specific means and / or procedures for dynamically changing a security algorithm in a randomized mode.
[0054] Performance can be improved, energy consumption reduced, latency shortened, and computational load decreased by switching to a less secure algorithm and a shorter key during specific time periods. A method can be provided to balance security and efficiency.
[0055] By dynamically changing the algorithm and key, the number of permutations and combinations can be increased, thereby further improving the security level.
[0056] In particular, a stronger level of security can be achieved when one or more randomization parameters are used. Attached Figure Description
[0057] For example, the above and other aspects, features, and advantages of various embodiments of the present disclosure will become more apparent from the following detailed description with reference to the accompanying drawings, in which similar reference numerals or letters are used to designate similar or equivalent elements. The drawings shown are for facilitating a better understanding of the embodiments of the present disclosure and are not necessarily drawn to scale, wherein:
[0058] Figure 1 This is a schematic diagram illustrating an example of the 3GPP 5G initial attach call procedure.
[0059] Figure 2 This is a block diagram illustrating an exemplary structure of an apparatus operating as a terminal device according to an exemplary embodiment of the present disclosure.
[0060] Figure 3A This is a flowchart illustrating a method performed by an apparatus operating as a terminal device according to an embodiment of the present disclosure.
[0061] Figure 3B This illustrates exemplary embodiments according to this disclosure. Figure 3A A flowchart of the other steps of the method shown.
[0062] Figure 3C This illustrates exemplary embodiments according to this disclosure. Figure 3A A flowchart of the other steps of the method shown.
[0063] Figure 3D This illustrates exemplary embodiments according to this disclosure. Figure 3A A flowchart of the other steps of the method shown.
[0064] Figure 3E This illustrates exemplary embodiments according to this disclosure. Figure 3A A flowchart of the other steps of the method shown.
[0065] Figure 3F This illustrates exemplary embodiments according to this disclosure. Figure 3A A flowchart of the other steps of the method shown.
[0066] Figure 4 This is a block diagram illustrating an exemplary structure of an apparatus operating as a network entity according to an exemplary embodiment of the present disclosure.
[0067] Figure 5A This is a flowchart illustrating a method performed by an apparatus operating as a network entity according to an embodiment of the present disclosure.
[0068] Figure 5B This illustrates exemplary embodiments according to this disclosure. Figure 5A A flowchart of the other steps of the method shown.
[0069] Figure 5C This illustrates exemplary embodiments according to this disclosure. Figure 5A A flowchart of the other steps of the method shown.
[0070] Figure 5D This illustrates exemplary embodiments according to this disclosure. Figure 5A A flowchart of the other steps of the method shown.
[0071] Figure 5E This illustrates exemplary embodiments according to this disclosure. Figure 5A A flowchart of the other steps of the method shown.
[0072] Figure 5F This illustrates exemplary embodiments according to this disclosure. Figure 5A A flowchart of the other steps of the method shown.
[0073] Figure 5G This illustrates exemplary embodiments according to this disclosure. Figure 5A A flowchart of the other steps of the method shown.
[0074] Figure 6 This is a block diagram illustrating an apparatus / computer-readable storage medium according to embodiments of the present disclosure.
[0075] Figure 7 This is a block diagram illustrating exemplary device units of a terminal device suitable for performing methods according to embodiments of the present disclosure.
[0076] Figure 8 This is a block diagram illustrating exemplary device units of a network entity suitable for performing methods according to embodiments of the present disclosure.
[0077] Figure 9 This is a diagram illustrating an exemplary random algorithm and key selection at the UE and BS according to an embodiment of this disclosure.
[0078] Figure 10 This illustrates the same seed (SEED) on the UE and network side according to embodiments of this disclosure.NAS and SEED AS Export the example graph.
[0079] Figure 11A , 11B This is a diagram illustrating an exemplary end-to-end message sequence of a NAS security procedure according to an embodiment of the present disclosure, including backward compatibility.
[0080] Figure 12A , 12B This is a diagram illustrating an exemplary AS security mode procedure utilizing dynamic security change mode according to an embodiment of the present disclosure.
[0081] Figure 13 This is a diagram illustrating a first exemplary alteration pattern according to an embodiment of the present disclosure.
[0082] Figure 14 This is a diagram illustrating a second exemplary alteration mode according to an embodiment of the present disclosure.
[0083] Figure 15 This is a diagram illustrating a third exemplary alteration mode according to an embodiment of the present disclosure.
[0084] Figure 16 This is a diagram illustrating a fourth exemplary alteration mode according to an embodiment of the present disclosure.
[0085] Figure 17 This illustrates an embodiment based on the present disclosure. Figure 16 The diagram shows the use of different algorithms for the fourth exemplary change mode.
[0086] Figure 18 This is a diagram illustrating a fifth exemplary alteration mode according to an embodiment of the present disclosure.
[0087] Figure 19 This is a diagram illustrating a sixth exemplary alteration mode according to an embodiment of the present disclosure.
[0088] Figure 20 This is a diagram illustrating an exemplary structure of a NAS security change mode information element according to an embodiment of this disclosure. Detailed Implementation
[0089] Embodiments of this disclosure are described in detail with reference to the accompanying drawings. It should be understood that these embodiments are discussed for better understanding only and are not intended to limit the scope of this disclosure. The features, advantages, and characteristics described in this disclosure may be combined in any suitable manner in one or more embodiments.
[0090] Generally, all terms used herein are to be interpreted according to their ordinary meaning in the relevant art, unless clearly assigned and / or implied otherwise in the context of their use. The steps of any method disclosed herein need not be performed in the exact order disclosed unless explicitly indicated and / or implied in the context. Where appropriate, any feature of any embodiment disclosed herein may be applied to any other embodiment.
[0091] As used herein, the term "network" or "communication network" refers to a network that conforms to any suitable communication standard (e.g., for the Internet or any wireless network). For example, wireless communication standards may include WLAN (Wireless Local Area Network), New Radio (NR), Long Term Evolution (LTE), LTE-Advanced, 5G NR, 6G, etc. In the following description, the terms "network" and "system" are used interchangeably.
[0092] The term "entity / network entity" refers to a computing device, computing node, computing function, or any other device (physical or virtual) in a communication network. For example, a node in the network can include a base station (BS), an access point (AP), or any other suitable device in a wireless communication network. For instance, a BS can be a Node B (NodeB or NB), an evolved Node B (eNodeB or eNB), a next-generation Node B (gNodeB or gNB), a remote radio unit (RRU), a radio head (RH), a remote radio head (RRH), a relay, or a low-power node such as a femtocell or picocell. Furthermore, a node can include other core network nodes such as Access and Mobility Management Functions (AMF), Session Management Functions (SMF), User Plane Functions (UPF), Mobility Management Entities (MME), or Serving Gateways (S-GW).
[0093] The term "terminal device" refers to any terminal device that can access a communication network and receive services therefrom. By way of example and not limitation, a terminal device refers to a mobile terminal, user equipment (UE), non-AP device (such as a non-AP station (STA)), or other suitable device. Terminal devices can include, but are not limited to, mobile phones, cellular phones, smartphones, wearable devices, in-vehicle wireless terminal equipment, vehicles, etc.
[0094] As an example, a terminal device can refer to a device configured to communicate according to one or more communication standards promulgated by any standards organization, such as the 3rd Generation Partnership Project (3GPP).
[0095] As yet another example, in the Internet of Things (IoT) scenario, a terminal device can represent a machine or other device that performs monitoring and / or measurement and sends the results of such monitoring and / or measurement to another terminal device and / or network device. Specific examples of such machines or devices are sensors; metering devices such as power meters; industrial machinery; or household or personal appliances such as refrigerators and televisions; personal wearable devices such as watches, etc. In other scenarios, a terminal device can represent a vehicle or other device capable of monitoring and / or reporting its operational status or other functions related to its operation.
[0096] It should be understood that although the terms “first” and “second” may be used herein to describe various elements, these elements should not be limited by these terms. These terms are used only to distinguish one element from another. For example, without departing from the scope of the exemplary embodiments, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed terms.
[0097] As used herein, expressions such as “at least one of the following: a list of two or more elements” and “at least one of the lists of two or more elements” refer to at least any one element, or at least any two or more elements, or at least all elements.
[0098] As mobile communication networks have evolved from second-generation (2G) to fifth-generation (5G) and higher, secure communication, such as from user equipment to the network, has become increasingly important. Secure communication includes the integrity and confidentiality of control and user data. Symmetric secure communication uses keys at both the sender and receiver. 3GPP systems typically support symmetric key systems. 3GPP supports a variety of security algorithms, including Advanced Encryption System (AES), ZUC, and SNOW 5G.
[0099] 5G introduces ultra-low latency communication for latency-sensitive services. Furthermore, networks are increasingly designed to achieve higher performance, particularly better energy efficiency / energy savings and lower latency.
[0100] 3GPP supports a variety of security algorithms, including AES, ZUC, and SNOW 5G. Each has its own advantages and disadvantages. For example, each of these algorithms supports different key lengths.
[0101] Figure 1 This is a diagram illustrating an example of the 3GPP 5G initial attach call process.
[0102] like Figure 1 As shown, the process includes the following main steps:
[0103] 1. The user equipment (UE) receives the synchronization signal block / physical broadcast channel (SSB / PBCH) from the radio access network (RAN).
[0104] 2. The UE receives System Information Blocks (SIBs) from the RAN.
[0105] 3. The UE and RAN perform the Random Access Channel (RACH) procedure.
[0106] 4. The UE and RAN perform Radio Resource Control (RRC) establishment.
[0107] 5. The UE sends a registration request to the Access and Mobility Management Function (AMF) via the RAN.
[0108] 6. UE and AMF perform the authentication process.
[0109] 7. The UE receives the "Security Mode Command" from the AMF via a Non-Access Stratum (NAS) message.
[0110] 8. The UE sends a “Security Mode Command Complete” message to the AMF via the NAS.
[0111] 9. The UE receives the "Security Mode Command" from the RAN via RRC message.
[0112] 10. The UE sends a “Security Mode Command Complete” message to the RAN via an RRC message.
[0113] 11. The UE and AMF perform the procedures related to registration acceptance and completion.
[0114] 12. The UE and RAN perform procedures related to RRC Reconfiguration.
[0115] 13. The UE and session management function execute procedures related to Protocol Data Unit (PDU) sessions.
[0116] Figure 1The bold and underlined text highlights the NAS (Security mode command) sent from the AMF to the UE, and the RRC (Security mode command) sent from the RAN to the UE. These messages specify the integrity protection algorithm and encryption algorithm for use on the NAS and RRC, respectively, between the UE and the AMF / RAN.
[0117] 3GPP Technical Specification (TS) 24.501 V18.6.0 (2024-03) defines the NAS: Security mode command message with a Selected NAS Security algorithms (IE) information element that specifies the integrity protection algorithm and encryption algorithm. 3GPP TS 24.501 defines the Selected NAS Security algorithms IE that specifies the integrity protection algorithm and encryption algorithm.
[0118] 3GPP TS 38.331 V18.0.0 (2023-12) defines the RRC: SecurityModeCommand message for the SecurityAlgorithmConfig IE, which specifies the integrity protection algorithm and the encryption algorithm. The 3GPP TS 38.331 specification defines the SecurityAlgorithmConfig IE that specifies the integrity protection algorithm and the encryption algorithm.
[0119] In the sixth generation (6G), it is necessary to improve overall performance while maintaining, and even enhancing, security. One of the most important performance aspects is energy efficiency. Stronger security can lead to increased computational load, thus negatively impacting energy consumption.
[0120] Generally, security can be improved by employing superior, but often more complex, security algorithms or by increasing key length. However, both of these techniques require greater computing power and increase cost and energy consumption. This also means that security operations take longer and processing latency increases. This presents challenges in meeting UE latency and energy efficiency / saving requirements, as well as network latency and energy efficiency / saving requirements.
[0121] As business volume increases, secure operations require longer times and consume more energy, thus making security a bottleneck. Existing technologies often involve a trade-off between performance and security.
[0122] In 3GPP Services and Systems (SA) 3#117, S3-243400 was proposed for a new Work Item Description (WID). This proposal allows a UE to reject a secure mode command if it deems the proposed algorithm weak. In non-emergency UE registration (attachment) procedures, the current security algorithm decisions made as part of secure mode negotiation are unilateral. Current procedures prevent UEs from rejecting, for example, insecure algorithms or algorithms known to be harmful (infringing on user privacy). Although this proposal has not been approved for (Rel)-19, it may spark offline discussions about allowing the negotiation of secure algorithms between the UE and the network, or may further impact Rel-20.
[0123] Furthermore, 256-bit algorithms were discussed in 3GPP SA3. Moreover, with the inclusion of quantum-safe algorithms under discussion in 3GPP, legacy UEs (devices) will not support the newer quantum-safe algorithms. Including these algorithms in 3GPP Rel-19 / Rel-20 will pose significant challenges to backward compatibility for legacy UEs. Due to the lack of support for quantum-safe or 256-bit algorithms, these UEs are vulnerable to attacks.
[0124] Some embodiments of this disclosure focus on achieving better performance while ensuring strong security. In particular, stronger security can be achieved when using randomization modes.
[0125] Figure 2 This is a block diagram illustrating an exemplary structure of an apparatus operating as a terminal device according to an exemplary embodiment of the present disclosure.
[0126] like Figure 2 As shown, the apparatus 20 for a terminal device includes at least one processor 202 and at least one memory 204 containing computer program code. The at least one memory 204 and the computer program code are configured, together with the at least one processor 202, to cause the apparatus 20, operating as a terminal device, to at least perform the methods described according to any of the following embodiments, such as... Figures 3A-3F , Figure 9-20 As shown.
[0127] Figure 3A This is a flowchart illustrating a method performed by an apparatus operating as a terminal device according to an embodiment of the present disclosure.
[0128] like Figure 3A As shown, method 300 includes: S302, receiving a first message from a network entity for configuring a security mode. The first message indicates: a list of security algorithms, and a change mode for the security algorithms. The change mode includes a randomization mode. When the randomization mode is enabled, a device operating as a terminal device changes the security algorithm based on at least one random number generated by the device operating as a terminal device.
[0129] According to embodiments of this disclosure, exemplary embodiments of this disclosure propose mechanisms that provide specific means / programs for dynamically changing a security algorithm in a randomization mode. Performance can also be improved, energy consumption reduced, latency shortened, and computational load reduced by switching to a less secure security algorithm and a shorter key for a specific time period. A method for balancing security and efficiency can be provided. Dynamic changes can increase the number of permutations and combinations of algorithms and keys. The security level can be further improved. In particular, a stronger security level can be achieved when using one or more randomization parameters.
[0130] Figure 3B This illustrates exemplary embodiments according to this disclosure. Figure 3A A flowchart of the other steps of the method shown.
[0131] like Figure 3B As shown, method 300 further includes: S304, receiving a seed from a network entity; and S306, generating a configured number of random numbers based on the seed.
[0132] According to embodiments of this disclosure, the terminal device can use a seed received from a network entity. Therefore, the terminal device and the network entity can use the same seed to generate the same random numbers. Then, when the security algorithm changes based on the random numbers, they can still use the same security algorithm.
[0133] Figure 3C This illustrates exemplary embodiments according to this disclosure. Figure 3A A flowchart of the other steps of the method shown.
[0134] like Figure 3C As shown, method 300 further includes: S308, obtaining parameters for generating a seed; S310, generating a seed based on the parameters; and S312, generating a configured number of random numbers based on the seed.
[0135] According to embodiments of this disclosure, the terminal device can use a seed it generates itself. Therefore, no information is transmitted over the air between the terminal device and the network. The security level can be further enhanced. As long as the terminal device and the network entity use the same parameters to generate the seed, both the terminal device and the network entity can obtain the same seed and thus use the same random number.
[0136] In an exemplary embodiment of this disclosure, the parameters used to generate the seed include a key exported locally by the terminal device.
[0137] According to embodiments of this disclosure, a key exported locally by the terminal device can be used to generate a seed, thus eliminating the need for any additional information to be transmitted over the air between the terminal device and the network.
[0138] In an exemplary embodiment of this disclosure, the change mode indicates at least one of the following: a condition that triggers a change in the security algorithm, and / or a method for selecting a security algorithm from a list of security algorithms to be used after the change in the security algorithm is triggered. When the randomization mode is enabled, at least one of the conditions that trigger the change and / or the method for selecting the security algorithm is based on at least one random number.
[0139] According to exemplary embodiments of this disclosure, the security algorithm can be randomly changed and / or selected, thereby greatly improving the security level.
[0140] In exemplary embodiments of this disclosure, the conditions triggering the change include at least one of the following: a time-based condition or a load-based condition. A time-based condition is met after a period of time has passed since the security algorithm was used. When randomization mode is enabled, this period is determined based on a random number from at least one random number set. A load-based condition is met after a load has been applied to the security algorithm. When randomization mode is enabled, the load is determined based on a random number from at least one random number set. This load is indicated by at least one of the following: the length of the plaintext or the number of messages.
[0141] According to exemplary embodiments of this disclosure, various triggering conditions are supported, such as triggering conditions based on random time or triggering conditions based on random load.
[0142] In an exemplary embodiment of this disclosure, at least one random number includes a first set of random numbers for determining a set of time periods; and / or at least one random number includes a second set of random numbers for determining a set of loads.
[0143] According to embodiments of this disclosure, each trigger of the change can be based on a different random number, thereby further improving the security level.
[0144] In an exemplary embodiment of this disclosure, when randomization mode is enabled, the sequence number of the security algorithm to be used is determined based on a random number from at least one set of random numbers. The at least one set of random numbers includes a third set of random numbers used to determine a set of sequence numbers for the security algorithm.
[0145] According to exemplary embodiments of this disclosure, the algorithm used after a change is triggered can also be based on random numbers, thereby further enhancing the security level.
[0146] In an exemplary embodiment of this disclosure, the sequence number of the security algorithm to be used, indicating the mode change, is determined based on a set of bits in a key. The set of bits used to determine the security algorithm to be used has a first position in the key, and the set of bits used to determine a previously used security algorithm has a second position in the key. The first position is shifted relative to the second position. This shift is pre-configured or determined based on a random number from at least one random number set.
[0147] According to exemplary embodiments of this disclosure, random numbers can be used in various ways to improve the level of security.
[0148] Figure 3D This illustrates exemplary embodiments according to this disclosure. Figure 3A A flowchart of the other steps of the method shown.
[0149] like Figure 3D As shown, method 300 further includes: S314, sending an accept message to a network entity when the device operating as a terminal device supports the security algorithm list and the security algorithm change mode; or S316, sending a reject message to a network entity when the device operating as a terminal device does not support at least one of the security algorithm list or the security algorithm change mode; or S318, waiting for a period of time after receiving the first message when the device operating as a terminal device does not support at least one of the security algorithm list or the security algorithm change mode.
[0150] According to exemplary embodiments of this disclosure, these embodiments provide mechanisms for enabling a terminal device to provide feedback to a network entity. The terminal device can implicitly or explicitly reject configurations from the network entity. Therefore, it also provides better backward compatibility. For example, alternative terminal devices that cannot understand and utilize the first message are also compatible.
[0151] Figure 3E This illustrates exemplary embodiments according to this disclosure. Figure 3A A flowchart of the other steps of the method shown.
[0152] In an exemplary embodiment of this disclosure, the rejection message includes at least one of the following: a list of security algorithms supported by the device operating as a terminal device, or a change mode of the supported security algorithms.
[0153] like Figure 3E As shown, method 300 further includes: S320, receiving a second message from the network entity for configuring a security mode. The second message indicates at least one of the following: at least a portion of the list of supported security algorithms, and / or a change mode for the supported security algorithms.
[0154] According to exemplary embodiments of this disclosure, a terminal device can provide the required configuration to a network entity; therefore, these embodiments provide a mechanism for enabling the terminal device to negotiate with a network entity.
[0155] In an exemplary embodiment of this disclosure, the entries for security algorithms in the security algorithm list include the type of security algorithm and / or the key length of the security algorithm. The security algorithm list includes a subset of encryption algorithms and / or a subset of integrity protection algorithms. The security algorithm list is used for non-access stratum (NAS) communications and / or access stratum (AS) communications. Network entities include: Radio Access Network (RAN) entities, or core network entities including at least one of the following: Access and Mobility Management Function (AMF), User Plane Function (UPF), or Network Data Analysis Function (NWDAF). Terminal equipment includes: User Equipment (UE).
[0156] According to exemplary embodiments of this disclosure, the provided mechanism can be used to change the security algorithm type and key length. Furthermore, the provided mechanism can be generally and widely applied to different algorithms, different communication types, and different devices / apparatus.
[0157] In exemplary embodiments of this disclosure, network entities include core network entities.
[0158] In an exemplary embodiment of this disclosure, the first message includes a Non-Access Stratum (NAS) security mode command. The network entity includes an Access and Mobility Management Function (AMF). The security algorithm list includes a subset of encryption algorithms for NAS and / or a subset of integrity protection algorithms for NAS. The key of the network entity includes: K AMF .
[0159] According to embodiments of this disclosure, the provided mechanism can be applied, for example, to NAS communication between a UE and an AMF. K exported and stored by the UE AMF It can be used to generate a seed and then generate random numbers. No additional information needs to be sent over the air.
[0160] In an exemplary embodiment of this disclosure, the network entity includes a radio access network (RAN) entity.
[0161] In an exemplary embodiment of this disclosure, the network entity includes a base station (BS). The key of the network entity includes K. gNB .
[0162] In an exemplary embodiment of this disclosure, the first message includes an Access Layer (AS) security mode command. The security algorithm list includes a subset of encryption algorithms for Radio Resource Control (RRC) and / or User Plane (UP); and / or, a subset of integrity protection algorithms for RRC and / or UP.
[0163] According to embodiments of this disclosure, the provided mechanism can be applied, for example, to AS communication between a UE and a base station. K is exported and stored by the UE. gNB It can be used to generate a seed, which can then be used to generate random numbers. No additional information needs to be sent over the air.
[0164] Figure 3F This illustrates exemplary embodiments according to this disclosure. Figure 3A A flowchart of the other steps of the method shown.
[0165] like Figure 3F As shown, method 300 further includes: S322, receiving an RRC connection reconfiguration message from a network entity. The RRC connection reconfiguration message indicates at least one of the following: enabling a change mode indicated by a first message for at least one data radio bearer (DRB); disabling a change mode indicated by a first message for at least one DRB; and / or, a change mode for a list of security algorithms and / or security algorithms for at least one DRB.
[0166] According to embodiments of this disclosure, for each data radio bearer, a change mode can be enabled, disabled, or configured / reconfigured.
[0167] Figure 4 This is a block diagram illustrating an exemplary structure of an apparatus operating as a network entity according to an exemplary embodiment of the present disclosure.
[0168] like Figure 4 As shown, the apparatus 40, operating as a network entity, includes at least one processor 402 and at least one memory 404 containing computer program code. The at least one memory 404 and the computer program code are configured, together with the at least one processor 402, to cause the apparatus 40, operating as a network entity, to perform at least one of the following embodiments, such as... Figures 5A-5G , Figure 9-20 shown.
[0169] Figure 5A This is a flowchart illustrating a method performed by a device operating as a network entity.
[0170] like Figure 5A As shown, method 500 includes: S502, sending a first message to a terminal device for configuring a security mode. The first message indicates: a list of security algorithms, and a change mode for the security algorithms. The change mode includes a randomization mode. When the randomization mode is enabled, the means operating as a network entity changes the security algorithm based on at least one random number generated by the means operating as a network entity.
[0171] Figure 5B This illustrates exemplary embodiments according to this disclosure. Figure 5AA flowchart of the other steps of the method shown.
[0172] like Figure 5B As shown, method 500 further includes: S504, sending a seed to the terminal device; and S506, generating a configured number of random numbers based on the seed.
[0173] Figure 5C This illustrates exemplary embodiments according to this disclosure. Figure 5A A flowchart of the other steps of the method shown.
[0174] like Figure 5C As shown, method 500 further includes: S508, obtaining parameters for generating a seed; S510, generating a seed based on the parameters; and S512, generating a configured number of random numbers based on the seed.
[0175] In an exemplary embodiment of this disclosure, the parameters used to generate the seed include a key exported locally by the network entity.
[0176] In an exemplary embodiment of this disclosure, the change mode indicates at least one of the following: a condition that triggers a change in the security algorithm, and / or a method for selecting a security algorithm from a list of security algorithms to be used after the change in the security algorithm is triggered. When the randomization mode is enabled, at least one of the conditions that trigger the change and / or the method for selecting the security algorithm is based on at least one random number.
[0177] In exemplary embodiments of this disclosure, the conditions triggering the change include at least one of the following: a time-based condition or a load-based condition. A time-based condition is met after a period of time has passed since the security algorithm was used. When randomization mode is enabled, this period is determined based on a random number from at least one random number set. A load-based condition is met after a load has been applied to the security algorithm. When randomization mode is enabled, the load is determined based on a random number from at least one random number set. This load is indicated by at least one of the following: the length of the plaintext, or the number of messages.
[0178] In an exemplary embodiment of this disclosure, at least one random number includes a first set of random numbers for determining a set of time periods. At least one random number includes a second set of random numbers for determining a set of load values.
[0179] In an exemplary embodiment of this disclosure, when randomization mode is enabled, the sequence number of the security algorithm to be used is determined based on a random number from at least one set of random numbers. The at least one set of random numbers includes a third set of random numbers used to determine a set of sequence numbers for the security algorithm.
[0180] In an exemplary embodiment of this disclosure, the sequence number of the security algorithm to be used, indicating the mode change, is determined based on a set of bits in a key. The set of bits used to determine the security algorithm to be used has a first position in the key, and the set of bits used to determine a previously used security algorithm has a second position in the key. The first position is shifted relative to the second position. This shift is pre-configured or determined based on a random number from at least one random number set.
[0181] Figure 5D This illustrates exemplary embodiments according to this disclosure. Figure 5A A flowchart of the other steps of the method shown.
[0182] like Figure 5D As shown, method 500 further includes: S514, receiving an accept message from the terminal device when the terminal device supports the security algorithm list and the security algorithm change mode; or S516, receiving a reject message from the terminal device when the terminal device does not support at least one of the security algorithm list or the security algorithm change mode; or S518, determining that the terminal device does not support at least one of the security algorithm list or the security algorithm change mode when no response is received within a period of time after sending the first message.
[0183] Figure 5E This illustrates exemplary embodiments according to this disclosure. Figure 5A A flowchart of the other steps of the method shown.
[0184] In an exemplary embodiment of this disclosure, the rejection message includes at least one of the following: a list of security algorithms supported by the terminal device or a change mode of the supported security algorithms.
[0185] like Figure 5E As shown, method 500 further includes: S520, storing at least one of the following: a list of security algorithms supported by the terminal device or a change mode of the supported security algorithms; and / or S522, sending a second message to the terminal device for configuring a security mode. The second message includes at least one of the following: at least a portion of the list of supported security algorithms, and / or an indication of a change mode of the supported security algorithms.
[0186] According to embodiments of this disclosure, network entities can store historical data about the capabilities of terminal devices.
[0187] Figure 5F This illustrates exemplary embodiments according to this disclosure. Figure 5A A flowchart of the other steps of the method shown.
[0188] like Figure 5FAs shown, method 500 further includes: S524, sending a report on the capabilities of the terminal device to the operation management network entity. At least one of the security algorithm list or security algorithm change modes is received from or determined by the operation management network entity.
[0189] According to exemplary embodiments of this disclosure, historical data regarding the capabilities of terminal devices may also be provided to the operator's operation management network entity and / or the operation management network entity in the core communication network.
[0190] In an exemplary embodiment of this disclosure, an entry for a security algorithm in the security algorithm list includes the type of the security algorithm and / or the key length of the security algorithm. The security algorithm list includes a subset of encryption algorithms and / or a subset of integrity protection algorithms. The security algorithm list is used for Non-Access Stratum (NAS) communications and / or Access Stratum (AS) communications. Network entities include: Radio Access Network (RAN) entities, or core network entities including at least one of the following: Access and Mobility Management Function (AMF), User Plane Function (UPF), or Network Data Analysis Function (NWDAF). Terminal equipment includes: User Equipment (UE).
[0191] In exemplary embodiments of this disclosure, network entities include core network entities.
[0192] In an exemplary embodiment of this disclosure, the first message includes a Non-Access Stratum (NAS) security mode command. The network entity includes an Access and Mobility Management Function (AMF). The security algorithm list includes a subset of encryption algorithms for NAS and / or a subset of integrity protection algorithms for NAS. The key of the network entity includes: K AMF .
[0193] In an exemplary embodiment of this disclosure, the network entity includes a radio access network (RAN) entity.
[0194] In an exemplary embodiment of this disclosure, the network entity includes a base station (BS). The key of the network entity includes K. gNB .
[0195] In an exemplary embodiment of this disclosure, the first message includes an Access Layer (AS) security mode command. The security algorithm list includes a subset of encryption algorithms for Radio Resource Control (RRC) and / or User Plane (UP); and / or, a subset of integrity protection algorithms for RRC and / or UP.
[0196] Figure 5G This illustrates exemplary embodiments according to this disclosure. Figure 5A A flowchart of the other steps of the method shown.
[0197] like Figure 5GAs shown, method 500 further includes: S526, sending an RRC connection reconfiguration message to the terminal device. The RRC connection reconfiguration message indicates at least one of the following: enabling a change mode indicated by the first message for at least one data radio bearer (DRB); disabling a change mode indicated by the first message for at least one DRB; and / or, a change mode for a list of security algorithms and / or security algorithms for at least one DRB.
[0198] In an exemplary embodiment of this disclosure, at least one of the security algorithm list or security algorithm change modes is received by the network entity from the core network entity.
[0199] According to an exemplary embodiment of this disclosure, a radio access network (RAN) entity can receive information about a terminal device from a core network entity.
[0200] Processors 202 and 402 can be any type of processing component, such as one or more microprocessors or microcontrollers, as well as other digital hardware, including digital signal processors (DSPs), application-specific digital logic, etc. Memory 204 and 404 can be any type of storage component, such as read-only memory (ROM), random access memory, cache memory, flash memory, optical storage device, etc.
[0201] Figure 6 This is a block diagram illustrating an apparatus / computer-readable storage medium according to embodiments of the present disclosure.
[0202] like Figure 6 As shown, the computer-readable storage medium 60 stores instructions 61, which, when executed by at least one processor of a device operating as a network node or terminal device, cause the at least one processor of the device to perform the method according to any of the above embodiments, such as... Figures 3A-3F , Figures 5A-5G , Figure 9-20 As shown.
[0203] Furthermore, this disclosure may also provide a carrier containing the aforementioned computer program / instructions. This carrier may be an electrical signal, an optical signal, a radio signal, or one of the aforementioned computer-readable storage media. Computer-readable storage media may be, for example, high-density optical discs or electrical storage devices such as RAM (Random Access Memory), ROM (Read-Only Memory), flash memory, magnetic tape, CD-ROM, DVD, Blu-ray disc, etc.
[0204] Figure 7 This is a block diagram illustrating exemplary device units of a terminal device suitable for performing methods according to embodiments of the present disclosure.
[0205] like Figure 7As shown, terminal device 70 may include a receiving unit 702 configured to receive a first message from a network entity for configuring a security mode. The first message indicates a list of security algorithms and a change mode for the security algorithms. The change mode includes a randomization mode. When the randomization mode is enabled, the means operating as the terminal device changes the security algorithm based on at least one random number generated by the means operating as the terminal device.
[0206] In exemplary embodiments of this disclosure, terminal device 70 is further configured to perform the method according to any of the above embodiments, such as Figures 3A-3F , Figure 9-20 As shown.
[0207] Figure 8 This is a block diagram illustrating exemplary device units of a network entity suitable for performing methods according to embodiments of the present disclosure.
[0208] like Figure 8 As shown, the network entity may include a sending unit 802 configured to send a first message to a terminal device for configuring a security mode. The first message indicates a list of security algorithms and a change mode for the security algorithms. The change mode includes a randomization mode. When the randomization mode is enabled, the means operating as the network entity changes the security algorithm based on at least one random number generated by the means operating as the network entity.
[0209] In exemplary embodiments of this disclosure, network entity 80 is also configured to perform the methods described according to any of the foregoing embodiments, such as Figures 5A-5G , Figure 9-20 As shown.
[0210] The term "unit" may have the conventional meaning in the field of electronic, electrical and / or electronic equipment, and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logic solid-state and / or discrete devices, computer programs or instructions for performing the corresponding tasks, programs, calculations, outputs and / or display functions described herein.
[0211] As used in this application, the term "circuit" may refer to one or more or all of the following:
[0212] (a) Pure hardware circuit implementation (e.g., implementation using only analog and / or digital circuits), and
[0213] (b) A combination of hardware circuitry and software, such as (if applicable):
[0214] (i) A combination of analog hardware circuitry and / or digital hardware circuitry with software / firmware, and
[0215] (ii) Any part of a hardware processor (including a digital signal processor), software, and memory that works together to enable a device (such as a mobile phone or server) to perform various functions, and
[0216] (c) Hardware circuitry and / or processors, such as microprocessors or a portion thereof, that require software (e.g., firmware) for operation, but may not exist when software is not required to perform the operation.
[0217] This definition of "circuit" applies to the term in this disclosure, including all uses in any claim. As another example, as used in this disclosure, the term "circuit" also covers an implementation of a hardware circuit or processor (or processors) alone, or a portion thereof and its (or their) accompanying software and / or firmware. For example, if applicable to a particular claim element, the term "circuit" also covers a baseband integrated circuit or processor integrated circuit for a mobile device, or a similar integrated circuit in a server, cellular network device, or other computing or network device.
[0218] Using these units, the device does not require a fixed processor or memory; any type of computing and storage resources can be deployed through at least one node / device / entity / device associated with the communication system. Virtualization and network computing technologies (e.g., cloud computing) can be further introduced to improve the efficiency of network resource utilization and network flexibility.
[0219] The techniques described herein can be implemented through various components, such that the means for implementing one or more functions of the corresponding apparatus described in the usage embodiments includes not only prior art components but also components for implementing one or more functions of the corresponding apparatus described in the usage embodiments. This may include separate components for each individual function, or components that can be configured to perform two or more functions. For example, these techniques can be implemented through hardware (one or more devices), firmware (one or more devices), software (one or more modules / units), or combinations thereof. For firmware or software, implementation can be done through modules (e.g., programs, functions, etc.) that perform the functions described herein.
[0220] In some embodiments, some or all of the functions described herein may be provided by processing circuitry that executes instructions stored in memory, which in some embodiments may be a computer program product in the form of a non-transient computer-readable storage medium. In alternative embodiments, some or all of the functions may be provided by processing circuitry that does not execute instructions stored on a separate or discrete device-readable storage medium, such as by hard-wired methods. In any of these particular embodiments, the processing circuitry may be configured to perform the described functions regardless of whether instructions stored on a non-transient computer-readable storage medium are executed. The advantages provided by these functions are not limited to the processing circuitry alone, or to other components of the computing device, but are shared by the computing device as a whole, and / or generally by the end user and wireless network.
[0221] As used herein, the term “non-transient” refers to a limitation on the medium itself (i.e., tangible, not signal), rather than a limitation on the persistence of data storage (e.g., RAM vs. ROM).
[0222] Based on the above embodiments, some other detailed solutions can be provided, as shown below.
[0223] We can assume that the system supports a set of N security algorithms for a given set A:
[0224] A = { A1, …, A i ,…,A N};N >= 1;1 <= i<= N.
[0225] These security algorithms are arranged in ascending order of security, that is, the security of A1 <= … <= A i Security <= ... <= A N Security.
[0226] We can also assume that each security algorithm Ai supports a set of "N" keys Si. i "One key:
[0227] KEYS i = { K i1 , …, K ij ,…,K iNi};N i >= 1; 1 <= j <= N i .
[0228] These keys are arranged in ascending order of key length, i.e., K i1 Length <= … <= K ij Length <= … <= K iNi The length.
[0229] We can also assume that the safe algorithm at index "x" in group "A" (i.e., A) is selected. x ), and select group "KEYS" x "used in Algorithm A" x The key at index "y" (i.e., K) xy x>=1 and y>=1.
[0230] Some embodiments of this disclosure propose that, during operation, a random pattern generated from A1 to A1 is achieved by using a randomized configuration generated based on negotiation or independently derived at the source and target. x Or change the security algorithm in some subsets of it.
[0231] Figure 9 This is a diagram illustrating an exemplary random algorithm and key selection at the UE and BS according to an embodiment of this disclosure.
[0232] Figure 9 A high-level logic diagram of the proposed exemplary embodiment is shown. For the AS security context, both the UE and BS use a SEED to generate random numbers for selecting the algorithm and associated key. Therefore, there will be a random algorithm and key selection function.
[0233] As long as the UE and BS use the SEED AS They are completely identical, and their random number generation functions are the same (e.g., using the same random number generation function in the same programming language). Without sharing any information over the air, the UE and BS can choose the same algorithm and the same key. Similarly, a SEEDN can be generated between the UE and AMF. AS Furthermore, this seed is used in the NAS security context. These objectives can be achieved using the following techniques.
[0234] Figure 10 This illustrates the same seed (SEED) on the UE and network side according to embodiments of this disclosure. NAS and SEED AS Export the example graph.
[0235] By using the same key derivation function (KDF) and the same input, both the UE and AMF can independently generate the same SEED. NAS The value is that no information is exchanged in the air. Figure 10 An example of this export is shown. In this example, both the UE and AMF use K. AMF The same seed value is generated via the same seed derivation function. In some other embodiments, the UE and AMF do not use K. AMF Instead, they use any other value known to both sides (e.g., any other key). In this case, no information is shared in the air. KAMF Derived during UE master authentication according to traditional procedures, this key allows for the non-over-the-air sharing of any information.
[0236] Next, after the NAS security mode procedure is completed, a seed can be generated at both the UE and BS. AS The value is used to dynamically select the encryption and integrity algorithms.
[0237] SEED NAS It can be used to generate random numbers for dynamically selecting encryption and integrity algorithms for NAS security between UE and NAS.
[0238] SEED AS It can be used to generate random numbers for dynamically selecting encryption and integrity algorithms for AS security between UE and BS.
[0239] In a randomized mode / randomized mode generated based on a random configuration negotiated between the source and the target, or independently derived from the source and the target, the key can be modified as follows:
[0240] From K used in security algorithm A1 11 To K 1N1 or a subset thereof,
[0241] From K used in security algorithm A2 21 To K 2N2 or a subset thereof, ......
[0243] From the security algorithm A x K x1 To K xNx or a subset thereof, and / or
[0244] Keys generated randomly based on the same number of different groups.
[0245] Although the source and target derive random configurations independently, using the same SEED value and the same random export function ensures that the exported configurations are exactly the same.
[0246] It is clear that using "less secure" algorithms and shorter keys can improve performance (reduce energy consumption, shorten latency, reduce computation, etc.). However, from an attacker's perspective, these exemplary embodiments make the choice of secure algorithm a variable. Therefore, an attacker must try all algorithms until A... x Moreover, the number of keys scanned by the attackers increased from... Increase to This will double or even multiply the security level.
[0247] Because the algorithm and key switch between random modes, attackers need to change the length of the input ciphertext, thus increasing the difficulty of their work. The risk for attackers is that even if one segment of ciphertext is decrypted, the entire process must be repeated for the next segment, requiring attackers to continuously use resources over a long period, increasing costs (computational and energy resources) and the risk of being caught.
[0248] Through these exemplary embodiments, the increased number of security algorithms and key permutations that an attacker needs to try significantly enhances security, while still maintaining a high-performance window during communication between the two entities. These exemplary embodiments also enhance the security of UEs compatible with Rel-18 or older 3GPP versions (which do not support newer algorithms such as quantum-safe or 256-bit algorithms).
[0249] It is assumed that the security key generation currently implemented independently by the entities involved in secure communication (i.e., the RAN, the core network (CN), and the UE) will continue. Furthermore, modifications to messages identified in the embodiments below can be implemented.
[0250] According to embodiments of this disclosure, networks such as RAN and CN, and UEs, can change security algorithms and keys through a given pattern (which may use random numbers) specified in the embodiments below, thereby achieving better performance and enhanced security.
[0251] The embodiments disclosed herein apply to currently supported 3GPP security algorithms and key lengths. Other alternative embodiments may also include options for any kind of security algorithm (such as 256-bit algorithms and quantum-safe algorithms) to be supported and / or implemented in the future.
[0252] Figure 11A , 11B This is a diagram illustrating an exemplary end-to-end message sequence of a NAS security procedure according to an embodiment of the present disclosure, including backward compatibility.
[0253] Figure 11A , 11B An end-to-end message sequence of an exemplary embodiment of this disclosure is shown. Figure 11A , 11B The underlined messages and message content are provided by embodiments of this disclosure.
[0254] The message sequence mainly includes the following steps.
[0255] Step 0: This step is optional and allows the operator or Operations Management and Maintenance (OAM) to configure security change mode details in the core network. In this example embodiment, the operator may define a security change mode utilizing random configuration (i.e., randomized mode / random mode) in this step.
[0256] Step 1: UE master authentication completed successfully.
[0257] Step 2: After successful UE authentication in Step 1, the core network can determine / derive the security change mode. This determination can be made using historical data on security algorithm compatibility stored in the core network from Steps 5a, 6a, and 9a described below. If the same UE is connected to the same core network, this step helps optimize the selection of security algorithms and their parameters for the specific UE. If historical data indicates that the UE supports a random configuration of the security change mode, the security change mode can be determined in this step.
[0258] (Randomness Option 1) Step 3: The core network sends a NAS security mode command, along with a security change mode (IE) as described in Table 9.11.3.x.1 below. In this option, AMF includes SEED. NAS The value is included with the command. This option is relatively weaker compared to option 2 below, but it can be used in some implementations. For example, it can enhance the security of UEs that do not support updated algorithms (such as 256-bit or quantum-safe algorithms) by allowing dynamic runtime changes in algorithm and key selection that are known only to the terminal entities (UE and core network).
[0259] (Randomness Option 2) Step 3: The core network sends a NAS security mode command, along with the security change mode IE as described in Table 9.11.3.x.1 below. In this option, the AMF does not send a SEED. NAS The value is included with the command.
[0260] (Randomness Option 2) Step 4a: UE and AMF independently derive SEED NAS Value, such as Figure 11A As shown. By using SEED NAS The value generates a random number, and uses the dynamic algorithm ID (NAS-enc-Alg-ID and NAS-int-Alg-ID) derived from the random number generation. Both sides (UE and AMF) can also independently derive the same NAS key (K). NASenc and K NASint ).
[0261] Step 4b: The UE checks the security algorithm and parameters and verifies the possibility of dynamic security change mode.
[0262] Step 5: If the UE can support the security algorithm and parameters, and finds that a security change mode is possible, it responds with a NAS Security Mode Command (SMC) Accept Message.
[0263] Step 5a: The core network updates the information on the supported algorithms and parameters for the UE in its internal database (DB). This allows the core network to export the appropriate IE in step 2 when the next NAS SMC is sent to the same UE.
[0264] Step 6: If the UE does not support all algorithms and parameters, but partially supports some algorithms and parameters from the given list, it will respond with a NAS SMC Reject message, which includes a list of supported algorithms and parameters. For example, a UE that does not support quantum-safe algorithms can provide a list of supported algorithms along with this rejection message.
[0265] Step 6a: The core network updates the information on the algorithms and parameters supported by the UE in its internal database. This allows the core network to derive the appropriate IE in step 2 when the next NASSMC is sent to the same UE.
[0266] Step 7: In this step, the core network can send a NAS SMC message with the updated IE for security mode change. The updated IE can exclude algorithms and parameters that the UE does not support.
[0267] Step 8: For the updated list, the UE responds with a NAS SMC accept message.
[0268] Step 8a: This is an optional step, in which the core network may send information about the supported security algorithms and parameters to the OAM / operator. This can be used for further analysis.
[0269] Steps 9, 9a, 10, and 11: For legacy UEs (which do not implement the SMC Reject message), the core network can implement a timer in step 9. When the timer expires, the core network can update the local history of the supported algorithms for the UE in step 9a and determine that these UEs are still not upgraded. Therefore, in steps 10 and 11, it reverts to the older SMC procedure.
[0270] Step 11a: This is an optional step, in which the core network may send information about supported security algorithms and parameters to the OAM / operator. This can be used for further analysis.
[0271] The call flow described above is a core network-centric example. Clearly, similar call flows can be used for other communication procedures, such as RAN-UE communication. For instance, in RAN-UE communication, the RAN node sends an RRC security mode command message to the UE, thus configuring the UE with a changed security algorithm.
[0272] Figure 12A , 12BThis is a diagram illustrating an exemplary AS security mode procedure with dynamic security change mode according to an embodiment of the present disclosure.
[0273] Figure 12A , 12B The underlined messages and message content are provided by embodiments of this disclosure.
[0274] Step 12: As part of the NGAP (Next Generation Application Protocol) Initial Context Setup Message, the AMF informs the BS about the UE's ability to change security modes: fully supported / partially supported / legacy UE.
[0275] Step 13: The BS sends an AS security mode command to the UE, along with a flag indicating support for dynamic security mode change. This flag can be omitted for legacy UEs.
[0276] Steps 14a and 14b: If security change modes are fully or partially supported at the UE, the UE and BS independently derive the SEED for random security change modes at the AS. AS This will be used for the dynamic selection of encryption and integrity algorithms for the AS security context.
[0277] Additionally, in some implementations, from SEED AS The derived random numbers can already be used to generate the first set of keys using an algorithm ID dynamically selected for UP and RRC. This means that in this step, SEED is used... AS This can generate random numbers to determine the first set of UP-int-alg-ID, UP-enc-alg-ID, RRC-int-alg-ID, and RRC-enc-alg-ID. These IDs can be used to derive K. UPint K UPenc K RRCint and K RRCenc .
[0278] Steps 15 and 16: Following tradition, complete the AS security mode and registration.
[0279] Steps 17-19 refer to 3GPP TS 33.501 V19.1.0 (2025-01). Figure 6 6.2-1: UP security activation mechanism.
[0280] Step 17: Along with the RRC connection reconfiguration for UP security activation, enable / disable dynamic security change mode for each DRB, and / or the BS may send policies to the UE.
[0281] In some implementations, if a different policy is not sent at this step, the dynamic security change mode policy configuration shared during NAS security context establishment can be reused for UP.
[0282] In some implementations, only an enable / disable flag is sent, and this flag can be applied to all DRBs.
[0283] In steps 18a and 18b, in addition to the traditional procedure, if the dynamic security change mode is enabled, both the UE and BTS can pre-generate the random numbers required by the policy in this step.
[0284] Step 19: RRC connection reconfiguration completed and sent from UE to BTS according to tradition.
[0285] Step 20: At runtime, for UP data, dynamically select the algorithm and key according to the policy. Some policy examples are explained below.
[0286] Further explanation will be given regarding the list of security algorithms, the conditions that trigger changes to security algorithms, and some examples of how to select a security algorithm from the list to be used.
[0287] Figure 13 This is a diagram illustrating a first exemplary alteration pattern according to an embodiment of the present disclosure.
[0288] In Example 1, the trigger condition (toggle trigger) is a time-based condition (which can be configured from both time-based and load-based conditions). Specifically, the algorithm can change every 10 seconds.
[0289] The selection of a security algorithm is based on a key. Specifically, it's based on a set of bits in the key. The position of this set of bits is shifted each time to determine the security algorithm that will be used when a change is triggered.
[0290] For example, at time point 0s, the sequence number of the algorithm is determined using the three least significant bits (LSBs) in position A of the key (which can be configured from the derived key and the multiplexed key). In this example, the three LSBs are 110, which can represent the decimal value 6. Therefore, the algorithm NEA-126 with sequence number 6 in the algorithm list is selected and then used for the time period 0s (or 1s) - 10s.
[0291] Then, at time 11s, the algorithm is changed. Three bits in position B (offset by one bit relative to position A) are used to determine the algorithm's sequence number. In this example, the three LSBs are 011, which can represent the decimal value 3. Therefore, algorithm NEA-256 with sequence number 3 from the algorithm list is selected and used for the time period 11s-20s.
[0292] Furthermore, at time 21s, a change in the algorithm is triggered. Three bits at position C will be used.
[0293] Figure 14 This is a diagram illustrating a second exemplary alteration mode according to an embodiment of the present disclosure.
[0294] In Example 2, the condition triggering the change is based on the load size. Specifically, one algorithm is used for every 10Mb of data. The algorithms in the list will be used cyclically (round-robin), so no additional parameters (such as keys) are needed.
[0295] It should be noted that various combinations of conditions and methods can be used. For example, conditions can be time-based, and algorithms can be used iteratively.
[0296] The following examples will explain the new concepts added in these exemplary embodiments. The random numbers indicated in these examples are generated using the same SEED value at both ends (UE and network entity). This ensures consistency between the UE and the network (RAN and / or core).
[0297] Figure 15 This is a diagram illustrating a third exemplary alteration mode according to an embodiment of the present disclosure.
[0298] In Example 3, the condition that triggers the change is based on the randomization time, and the method of selecting the security algorithm is based on the generated key (i.e., switching based on the generated key).
[0299] In some embodiments, the "generated key" can be related to... Figure 10 The figure from K AMF Generated SEED NAS same.
[0300] In some other embodiments, SEED is used. NAS The first random number generated can be used as the "generated key".
[0301] In some other embodiments, the "generated key" can be related to K. AMF same.
[0302] Randomization time # = minimum time + random number * (maximum time – minimum time); 0.00 <= random number <= 1.00.
[0303] The following example illustrates this.
[0304] SEED NAS = 131
[0305] Generate the binary form of the key (with K) AMF (Same) = 101110001011
[0306] SEED NAS The four random numbers generated can be used to calculate the randomization time based on these four random numbers. The randomization time will be 50, 57, 75, 21, which is the same at both the UE and AMF.
[0307] Based on the position A, B, C, etc. of “101110001011” (or any other example position, which may also be randomized), select the algorithm to be used for each change.
[0308]
[0309] The specific implementation of random number generation functions, such as programming languages and calculation methods, is not restricted, as long as they are the same at both the UE and the network entity. The UE and the network entity can generate the same random numbers based on the same seed.
[0310] For example, pseudo-random number generators (such as those based on linear congruence generators or Mersenne rotation algorithms) are very useful because the same sequence of random numbers can be generated from the same random seed. Therefore, they can be used in cryptography, as long as the seed remains secret. The sender and receiver can automatically generate the same set of numbers to use as the key.
[0311] The following is sample code for generating random numbers.
[0312] Code in UE:
[0313] # Import random module
[0314] import random
[0315] r_ue_seed = 173
[0316] random.seed(r_ue_seed)
[0317] print("Numbers generated at UE with Seed value =", r_ue_seed)
[0318] for i in range(5):
[0319] # The generated random number will be between 1 and 1000.
[0320] print(random.randint(1, 1000))
[0321] Codes in BTS (Broadband Transceiver Station):
[0322] #Import random module
[0323] import random
[0324] r_bts_seed = 173
[0325] random.seed(r_bts_seed)
[0326] print("Numbers generated at BTS with Seed value =", r_bts_seed)
[0327] for i in range(5):
[0328] The generated random number will be between 1 and 1000.
[0329] print(random.randint(1, 1000))
[0330] First example of calling code in UE:
[0331] PS C:\Users\rabhat\>python .\Rand_gen_UE.py
[0332] Number generated at UE using seed value = 173 332 499 685 839 797
[0338] First example of calling code in BTS:
[0339] PS C:\Users\rabhat\>python .\Rand_gen_BTS.py
[0340] Numbers generated at BTS using seed value = 173 332 499 685 839 797
[0346] ============================================================
[0347] Second example of calling code in UE:
[0348] PS C:\Users\rabhat\>python .\Rand_gen_UE.py
[0349] Number generated at UE using seed value = 87 150 756 194 897 860
[0355] Second example of calling code in BTS:
[0356] PS C:\Users\rabhat\>python .\Rand_gen_BTS.py
[0357] Numbers generated at BTS using seed value = 87 150 756 194 897 860
[0363] The above example demonstrates that the same random number can be generated at both the UE and the BTS.
[0364] Figure 16 This is a diagram illustrating a fourth exemplary alteration mode according to an embodiment of the present disclosure.
[0365] In Example 4, the condition that triggers the change is based on the randomized payload size. The algorithms in the list will be used cyclically (round-robin), so no additional parameters (such as keys) are needed.
[0366] Randomized load # = minimum load + random number * (maximum load – minimum load); 0.00 <= random number <= 1.00.
[0367] Generate random numbers 0, 0.44, 0.22...0.11, with corresponding loads of 10Mb, 50Mb, 30Mb...20Mb.
[0368] Figure 17 This illustrates an embodiment based on the present disclosure. Figure 16 The diagram shows the use of different algorithms for the fourth exemplary change mode.
[0369] Step 1: The AES-128 encryption algorithm is effective with a payload of 10Mb. Assuming each packet has the same size of 100kb, 100 such packets should be sent before changing the algorithm.
[0370] Step 2: Now, the new encryption algorithm AES-256 is effective at a payload of 60Mb. Assuming each packet has the same size of 100kb, 500 such packets should be sent before changing the algorithm again.
[0371] Step 3: Now, the new encryption algorithm AES-512 is effective at a payload of 90Mb. Assuming each packet has the same size of 100kb, 300 such packets should be sent before changing the algorithm again.
[0372] Figure 18 This is a diagram illustrating a fifth exemplary alteration mode according to an embodiment of the present disclosure.
[0373] In Example 5, the condition triggering the change is a time-based condition. Specifically, an algorithm is used every 10 seconds. The algorithms in the list will be used randomly, i.e., based on generated random numbers.
[0374] Algorithm # = INT(random number * (number of algorithms – 1)); 0.00 <= random number <= 1.00.
[0375] Figure 19 This is a diagram illustrating a third exemplary alteration mode according to an embodiment of the present disclosure.
[0376] In Example 6, the condition that triggers the change is based on the randomized load, and the way the security algorithm is selected is also random, that is, based on the generated random number.
[0377] Algorithm # = INT(random number * (number of algorithms – 1)); 0.00 <= random number <= 1.00.
[0378] Randomized load # = minimum load + random number * (maximum load – minimum load); 0.00 <= random number <= 1.00.
[0379] It should be noted that the above examples are not limiting, and different conditions and methods in different examples can be combined according to different practical needs.
[0380] The table below lists the encryption speed (Mbps) of three exemplary representative encryption algorithms (i.e., AES-128, AES-192, and AES-256) based on certain lab tests, and the gain when changing from a long-key algorithm to a short-key algorithm (e.g., from AES-192 to AES-128).
[0381]
[0382] Therefore, according to embodiments of this disclosure, short key algorithms can be used to improve communication speed, while long key algorithms can be used to enhance security.
[0383] Therefore, flexible changes in security algorithms during communication will provide both enhanced security and better performance.
[0384] According to embodiments of this disclosure, some exemplary proposals can also be made for the TS 24.501 Non-Access Stratum (NAS) protocol for 5G systems (5GS). Modifications to the security mode command message can be proposed as follows (proposals are underlined).
[0385] Table 8.2.25.1.1: Safe Mode Command Message Content
[0386]
[0387]
[0388] It should be noted that the names, values, and / or other attributes of the proposed parameters are merely illustrative examples and not limiting ones.
[0389] Further details of the proposed parameters are illustrated by the following example.
[0390] 9.11.3.x NAS Security Change Mode
[0391] (See Figure 12)
[0392] Figure 9 .11.3.x.1: NAS Security Change Mode Information Elements
[0393] Table 9.11.3.x.1: NAS Security Algorithm Information Elements
[0394]
[0395]
[0396]
[0397] It should be noted that the parameters and messages described above are merely examples and not limitations. For example, some items in the parameters can be deleted, and other items can be added. These items can be sent using one or more parameters and / or one or more messages.
[0398] Alternatively, a similar modification can be made in Clause 1.1.1.1 of the TS 38.331 NR; Radio Resource Control (RRC) protocol specification for RAN-UE communication, for example as an AS security change mode information element.
[0399] In 3GPP SA 3#117, S3-243400 was proposed for the new WID. This proposal allows the UE to reject a secure mode command if it deems the proposed algorithm weak. In non-urgent UE registration (attachment) procedures, the current security algorithm decision, made as part of the security mode negotiation, is unilateral. The current procedure prevents the UE from rejecting, for example, an insecure algorithm or an algorithm known to be a compromise (infringing on user privacy). Although this proposal was not approved for Rel-19, it sparked offline discussions about allowing the negotiation of secure algorithms between the UE and the network. Embodiments disclosed herein will provide further enhancements to the proposal in Rel-20. This is also more likely, as quantum-safe algorithms and 256-bit algorithm support are required in 3GPP.
[0400] In addition, other relevant standards, such as the relevant Open(O)-RAN standards, may also be updated.
[0401] The proposed implementation can also be used in 6G (Rel-20), with a focus on performance, including energy efficiency, latency, and computing requirements, in order to achieve a balance between security and performance.
[0402] These embodiments can be applied to various entities, such as various UEs, core network functions (such as AMF, User Plane Functions (UPF), Network Data Analysis Functions (NWDAF)), RAN products (such as base stations), and operation and maintenance (O&M) products (located within or outside the core network), etc.
[0403] According to the exemplary embodiments described above, the proposed methods, apparatuses, etc., can be used to enhance the security of a UE based on variations between different security algorithms and security key combinations.
[0404] These embodiments propose methods to enhance UE security by increasing the number of permutations and combinations of security algorithms and keys through the use of security change modes. Security change modes enable dynamic runtime changes to the selection of security algorithms and keys.
[0405] The solutions proposed in these embodiments allow at least one of the following:
[0406] Enhance security by increasing the number of algorithm and key combinations that attackers must try;
[0407] By switching to a less secure algorithm and a shorter key during specific time periods, performance can be improved, energy consumption reduced, latency shortened, and computational load decreased.
[0408] A method for balancing security and efficiency; or
[0409] Enhance the security of UEs compatible with Rel-18 or older 3GPP versions.
[0410] It should be understood that the above embodiments are for illustrative purposes only and not for limitation. This disclosure may be carried out in ways other than those specifically set forth herein without departing from its essential characteristics. All changes to these embodiments are intended to be incorporated herein without departing from the meaning and equivalence of the appended claims.
[0411] Explanation of Abbreviations
[0412] AES Advanced Encryption System
[0413] AMF access and mobility management functions
[0414] CN Core Network
[0415] NAS Non-Access Layer
[0416] RAN Radio Access Network
[0417] UE User Equipment
[0418] NEA NR encryption algorithm
[0419] NIA NR Integrity Protection Algorithm
[0420] AF application functions
[0421] UDM Unified Data Management
[0422] UDR Unified Data Repository
[0423] NEF Network Open Functions
[0424] NF Network Functions
[0425] NR New Radio
[0426] 3GPP Third Generation Partnership Project
[0427] TR Technical Report
[0428] NW Network
[0429] 3GPP Third Generation Partnership Project
[0430] 5GC fifth-generation core network
[0431] 5G fifth generation
[0432] 6G sixth generation
[0433] RRC Radio Resource Control
[0434] Rel version
[0435] DL downlink
[0436] UL uplink.
Claims
1. A device (20) operating as a terminal device, comprising: At least one processor (202); as well as At least one memory (204) contains computer program code; The at least one memory (204) and the computer program code are configured, together with the at least one processor (202), to cause the device (20) operating as the terminal device to perform at least the following: Receive the first message from the network entity for configuring the security mode; The first message indicates: a list of security algorithms, and the change mode of the security algorithms; The change mode includes a randomization mode; When the randomization mode is enabled, the device (20) operating as the terminal device changes the security algorithm based on at least one random number generated by the device (20) operating as the terminal device.
2. The apparatus (20) operating as the terminal device according to claim 1, wherein, The at least one memory (204) and the computer program code are also configured, together with the at least one processor (202), to cause the device (20) operating as the terminal device to perform at least the following: Receive seeds from the network entity; and Based on the seed, generate the configured number of random numbers.
3. The apparatus (20) operating as the terminal device according to claim 1, wherein, The at least one memory (204) and the computer program code are also configured, together with the at least one processor (202), to cause the device (20) operating as the terminal device to perform at least the following: Obtain the parameters used to generate the seed; Based on the parameters, the seed is generated; and Based on the seed, generate the configured number of random numbers.
4. The apparatus (20) operating as the terminal device according to claim 3, wherein, The parameters used to generate the seed include a key exported locally by the terminal device.
5. The apparatus (20) operating as the terminal device according to any one of claims 1 to 4. in, The change mode indicates at least one of the following: the conditions that trigger the change of the security algorithm, and / or the method of selecting from the list of security algorithms to use the security algorithm after the change of the security algorithm is triggered; as well as Wherein, when the randomization mode is enabled, at least one of the conditions that trigger the change and / or the manner of selecting the security algorithm is based on the at least one random number.
6. The apparatus (20) operating as the terminal device according to claim 5. in, The conditions that trigger the change include at least one of the following: time-based conditions or load-based conditions; The time-based condition is satisfied after a period of time has elapsed since the security algorithm was used. Wherein, when the randomization mode is enabled, the time period is determined based on a random number among the at least one random number; The load-based condition is satisfied after the security algorithm has been applied to the load amount; Wherein, when the randomization mode is enabled, the load is determined based on a random number from the at least one random number; and The load is indicated by at least one of the following: the length of the plaintext, or the number of messages.
7. The apparatus (20) operating as the terminal device according to claim 6. in, The at least one random number includes a first set of random numbers, used to determine a set of time periods respectively; and / or The at least one random number includes a second set of random numbers, used to determine a set of load values respectively.
8. The apparatus (20) operating as the terminal device according to any one of claims 5 to 7. in, When the randomization mode is enabled, the sequence number of the security algorithm to be used is determined based on a random number from the at least one random number. The at least one random number includes a third set of random numbers, used to determine a set of sequence numbers for the security algorithm.
9. The apparatus (20) operating as the terminal device according to any one of claims 5 to 7. in, The change mode indicates that the sequence number of the security algorithm to be used is determined based on a set of bits in the key; Wherein, the set of bits used to determine the security algorithm to be used has a first position in the key, and the set of bits used to determine the previously used security algorithm has a second position in the key; Wherein, the first position is shifted relative to the second position; The shift is either pre-configured or determined based on a random number from the at least one random number.
10. The apparatus (20) operating as the terminal device according to any one of claims 1 to 9, wherein, The at least one memory (204) and the computer program code are also configured, together with the at least one processor (202), to cause the device (20) operating as the terminal device to perform at least the following: When the device (20) operating as the terminal device supports the list of security algorithms and the change mode of the security algorithms, it sends an acceptance message to the network entity; or When the device (20) operating as the terminal device does not support at least one of the security algorithm list or the change mode of the security algorithm, a rejection message is sent to the network entity; or When the device (20) operating as the terminal device does not support at least one of the security algorithm list or the change mode of the security algorithm, it waits for a period of time after receiving the first message.
11. The apparatus (20) operating as the terminal device according to claim 10. in, The rejection message includes at least one of the following: a list of security algorithms supported by the device (20) operating the terminal device, or a change mode of the supported security algorithms; The at least one memory (204) and the computer program code are further configured, together with the at least one processor (202), to cause the device (20) operating as the terminal device to at least perform: receiving a second message from the network entity for configuring a security mode; The second message indicates at least one of the following: at least a portion of the list of supported security algorithms, and / or a change mode of the supported security algorithms.
12. The apparatus (20) operating as the terminal device according to any one of claims 1 to 11. in, The security algorithm entries in the security algorithm list include the type of the security algorithm and / or the key length of the security algorithm; The security algorithm list includes a subset of encryption algorithms and / or a subset of integrity protection algorithms; The security algorithm list is used for non-access stratum (NAS) communication and / or access stratum (AS) communication. The network entities include: a Radio Access Network (RAN) entity, or a core network entity including at least one of the following: Access and Mobility Management Function (AMF), User Plane Function (UPF), or Network Data Analysis Function (NWDAF); and / or The terminal device includes: User Equipment (UE).
13. An apparatus (40) for operating as a network entity, comprising: At least one processor (402); as well as At least one memory (404) containing computer program code; The at least one memory (404) and the computer program code are configured, together with the at least one processor (402), to cause the device (40) operating as the network entity to perform at least the following: Send the first message to the terminal device to configure the security mode; The first message indicates: a list of security algorithms, and the change mode of the security algorithms; The change mode includes a randomization mode; When the randomization mode is enabled, the device (40) operating the network entity changes the security algorithm based on at least one random number generated by the device (40) operating the network entity.
14. The apparatus (40) operating as the network entity according to claim 13, wherein, The at least one memory (404) and the computer program code are also configured, together with the at least one processor (402), to cause the means (40) operating as the network entity to at least execute: Send the seed to the terminal device; and Based on the seed, generate the configured number of random numbers.
15. The apparatus (40) operating as the network entity according to claim 13, wherein, The at least one memory (404) and the computer program code are also configured, together with the at least one processor (402), to cause the means (40) operating as the network entity to at least execute: Obtain the parameters used to generate the seed; Based on the parameters, the seed is generated; and Based on the seed, generate the configured number of random numbers.
16. The apparatus (40) operating as the network entity according to claim 15, wherein, The parameters used to generate the seed include a key exported locally by the network entity.
17. The apparatus (40) operating as the network entity according to any one of claims 13 to 16. in, The change mode indicates at least one of the following: the conditions that trigger the change of the security algorithm, and / or the method of selecting from the list of security algorithms to use the security algorithm after the change of the security algorithm is triggered; as well as Wherein, when the randomization mode is enabled, at least one of the conditions that trigger the change and / or the manner of selecting the security algorithm is based on the at least one random number.
18. The apparatus (40) operating as the network entity according to claim 17. in, The conditions that trigger the change include at least one of the following: time-based conditions or load-based conditions; The time-based condition is satisfied after a period of time has elapsed since the security algorithm was used. Wherein, when the randomization mode is enabled, the time period is determined based on a random number among the at least one random number; The load-based condition is satisfied after the security algorithm has been applied to the load amount; Wherein, when the randomization mode is enabled, the load is determined based on a random number from the at least one random number; and The load is indicated by at least one of the following: the length of the plaintext, or the number of messages.
19. The apparatus (40) operating as the network entity according to claim 18. in, The at least one random number includes a first set of random numbers, used to determine a set of time periods respectively; and / or The at least one random number includes a second set of random numbers, used to determine a set of load values respectively.
20. The apparatus (40) for operating the network entity according to any one of claims 17 to 19. in, When the randomization mode is enabled, the sequence number of the security algorithm to be used is determined based on a random number from the at least one random number. The at least one random number includes a third set of random numbers, used to determine a set of sequence numbers for the security algorithm.
21. The apparatus (40) for operating the network entity according to any one of claims 17 to 19. in, The change mode indicates that the sequence number of the security algorithm to be used is determined based on a set of bits in the key; Wherein, the set of bits used to determine the security algorithm to be used has a first position in the key, and the set of bits used to determine the previously used security algorithm has a second position in the key; Wherein, the first position is shifted relative to the second position; and The shift is either pre-configured or determined based on a random number from the at least one random number.
22. The apparatus (40) operating as the network entity according to any one of claims 13 to 21, wherein, The at least one memory (404) and the computer program code are also configured, together with the at least one processor (402), to cause the means (40) operating as the network entity to at least execute: When the terminal device supports the security algorithm list and the security algorithm change mode, an acceptance message is received from the terminal device; or When the terminal device does not support at least one of the security algorithm list or the change mode of the security algorithm, a rejection message is received from the terminal device; or If no response is received within a certain period of time after sending the first message, it is determined that the terminal device does not support at least one of the security algorithm list or the change mode of the security algorithm.
23. The apparatus (40) operating as the network entity according to claim 22. in, The rejection message includes at least one of the following: a list of security algorithms supported by the terminal device, or a change mode of the supported security algorithms; The at least one memory (404) and the computer program code are further configured, together with the at least one processor (402), to cause the means (40) operating as the network entity to at least execute: Store at least one of the following: a list of security algorithms supported by the terminal device or a change mode of the supported security algorithms; and / or Send a second message to the terminal device for configuring the security mode; and The second message includes at least one of the following: at least a portion of the list of supported security algorithms, and / or an indication of a change mode for the supported security algorithms.
24. The apparatus (40) operating as the network entity according to any one of claims 13 to 23, wherein, The at least one memory (404) and the computer program code are also configured, together with the at least one processor (402), to cause the means (40) operating as the network entity to at least execute: Send a report on the capabilities of the terminal device to the operations management network entity; Wherein, at least one of the security algorithm list or the security algorithm change mode is received from the operation management network entity or determined by the network entity.
25. The apparatus (40) operating as the network entity according to any one of claims 13 to 24. in, The security algorithm entries in the security algorithm list include the type of the security algorithm and / or the key length of the security algorithm; The security algorithm list includes a subset of encryption algorithms and / or a subset of integrity protection algorithms; The security algorithm list is used for non-access stratum (NAS) communication and / or access stratum (AS) communication. The network entity includes: a Radio Access Network (RAN) entity, comprising at least one of the following core network entities: Access and Mobility Management Function (AMF), User Plane Function (UPF), or Network Data Analysis Function (NWDAF); and The terminal device includes: User Equipment (UE).
26. A method (300) performed by a device (20) operating as a terminal device, comprising: Receive the first message from the network entity for configuring the security mode; The first message indicates: a list of security algorithms, and a change mode for the security algorithms; and The change mode includes a randomization mode; When the randomization mode is enabled, the device (20) operating as the terminal device changes the security algorithm based on at least one random number generated by the device (20) operating as the terminal device.
27. The method (300) according to claim 26, wherein, The method is performed by the apparatus according to any one of claims 1 to 12.
28. A method (500) performed by a means (40) operating as a network entity, comprising: Send the first message to the terminal device to configure the security mode; The first message indicates: a list of security algorithms, and an indication of the change mode of the security algorithms; The change mode includes a randomization mode; When the randomization mode is enabled, the device (40) operating the network entity changes the security algorithm based on at least one random number generated by the device (40) operating the network entity.
29. The method (500) according to claim 28, wherein, The method is performed by the apparatus according to any one of claims 13 to 25.
30. A computer-readable storage medium (60) storing instructions (61) that, when executed by at least one processor of a device, cause the at least one processor of the device to perform at least the method according to any one of claims 26 to 29.