Method and apparatus for network controlled repeater in mobile network

EP4744334A1Pending Publication Date: 2026-05-20SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
SAMSUNG ELECTRONICS CO LTD
Filing Date
2024-07-15
Publication Date
2026-05-20

AI Technical Summary

Technical Problem

Current technologies face challenges in securing the configuration and operation of Network Controlled Repeaters (NCRs) from malicious attacks, particularly due to the risk of wireless interference caused by improper or malicious configuration.

Method used

Implementing access stratum (AS) security and mutual authentication between the NCR and the network, ensuring that the NCR-Fwd configuration is only activated after AS security is established, and restricting unauthorized configurations to prevent interference.

Benefits of technology

Enhances the security of NCR configurations and operations, preventing malicious attacks that could cause wireless interference and ensuring the reliability and efficiency of wireless communication systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024010084_13022025_PF_FP_ABST
    Figure KR2024010084_13022025_PF_FP_ABST
Patent Text Reader

Abstract

The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. A method for communication by a network controlled repeater (NCR) in a wireless communication system is provided. The method comprises activating access stratum (AS) security associated with the NCR; and receiving a radio resource control (RRC) reconfiguration message for configuring an NCR-forward(Fwd) of the NCR based on the AS security being activated.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD AND APPARATUS FOR NETWORK CONTROLLED REPEATER IN MOBILE NETWORK

[0001] The technical field relates generally to a method and apparatus for network-controlled repeater (NCR) in a mobile network. In particular, example implementations include a method and apparatus to make it more difficult to attack a configuration of NCRs.

[0002] 5G mobile communication technologies define broad frequency bands such that high transmission rates and new services are possible, and can be implemented not only in "Sub 6GHz" bands such as 3.5GHz, but also in "Above 6GHz" bands referred to as mmWave including 28GHz and 39GHz. In addition, it has been considered to implement 6G mobile communication technologies (referred to as Beyond 5G systems) in terahertz bands (for example, 95GHz to 3THz bands) in order to accomplish transmission rates fifty times faster than 5G mobile communication technologies and ultra-low latencies one-tenth of 5G mobile communication technologies.

[0003] At the beginning of the development of 5G mobile communication technologies, in order to support services and to satisfy performance requirements in connection with enhanced Mobile BroadBand (eMBB), Ultra Reliable Low Latency Communications (URLLC), and massive Machine-Type Communications (mMTC), there has been ongoing standardization regarding beamforming and massive MIMO for mitigating radio-wave path loss and increasing radio-wave transmission distances in mmWave, supporting numerologies (for example, operating multiple subcarrier spacings) for efficiently utilizing mmWave resources and dynamic operation of slot formats, initial access technologies for supporting multi-beam transmission and broadbands, definition and operation of BWP (BandWidth Part), new channel coding methods such as a LDPC (Low Density Parity Check) code for large amount of data transmission and a polar code for highly reliable transmission of control information, L2 pre-processing, and network slicing for providing a dedicated network specialized to a specific service.

[0004] Currently, there are ongoing discussions regarding improvement and performance enhancement of initial 5G mobile communication technologies in view of services to be supported by 5G mobile communication technologies, and there has been physical layer standardization regarding technologies such as V2X (Vehicle-to-everything) for aiding driving determination by autonomous vehicles based on information regarding positions and states of vehicles transmitted by the vehicles and for enhancing user convenience, NR-U (New Radio Unlicensed) aimed at system operations conforming to various regulation-related requirements in unlicensed bands, NR UE Power Saving, Non-Terrestrial Network (NTN) which is UE-satellite direct communication for providing coverage in an area in which communication with terrestrial networks is unavailable, and positioning.

[0005] Moreover, there has been ongoing standardization in air interface architecture / protocol regarding technologies such as Industrial Internet of Things (IIoT) for supporting new services through interworking and convergence with other industries, IAB (Integrated Access and Backhaul) for providing a node for network service area expansion by supporting a wireless backhaul link and an access link in an integrated manner, mobility enhancement including conditional handover and DAPS (Dual Active Protocol Stack) handover, and two-step random access for simplifying random access procedures (2-step RACH for NR). There also has been ongoing standardization in system architecture / service regarding a 5G baseline architecture (for example, service based architecture or service based interface) for combining Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) for receiving services based on UE positions.

[0006] As 5G mobile communication systems are commercialized, connected devices that have been exponentially increasing will be connected to communication networks, and it is accordingly expected that enhanced functions and performances of 5G mobile communication systems and integrated operations of connected devices will be necessary. To this end, new research is scheduled in connection with eXtended Reality (XR) for efficiently supporting AR (Augmented Reality), VR (Virtual Reality), MR (Mixed Reality) and the like, 5G performance improvement and complexity reduction by utilizing Artificial Intelligence (AI) and Machine Learning (ML), AI service support, metaverse service support, and drone communication.

[0007] Furthermore, such development of 5G mobile communication systems will serve as a basis for developing not only new waveforms for providing coverage in terahertz bands of 6G mobile communication technologies, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), array antennas and large-scale antennas, metamaterial-based lenses and antennas for improving coverage of terahertz band signals, high-dimensional space multiplexing technology using OAM (Orbital Angular Momentum), and RIS (Reconfigurable Intelligent Surface), but also full-duplex technology for increasing frequency efficiency of 6G mobile communication technologies and improving system networks, AI-based communication technology for implementing system optimization by utilizing satellites and AI (Artificial Intelligence) from the design stage and internalizing end-to-end AI support functions, and next-generation distributed computing technology for implementing services at levels of complexity exceeding the limit of UE operation capability by utilizing ultra-high-performance communication and computing resources.

[0008] In recent years, there has been a rapid development in communications technologies that are compliant with third generation partnership project (3GPPTMstandards. A 4thgeneration (4G) wireless communication standard (sometimes referred to as long term evolution (LTETMwas designed to support mobile internet and higher speeds for activities, such as video streaming and gaming. The 3GPPTMstandards then developed a fifth generation (5G) of mobile wireless communications, which provides a step change in the delivery of better and faster communications, for example powering businesses, improving communications within homes and spearheading advances such as driverless cars. These 5G networks have also brought about a wide range of new services, each with its own unique set of requirements categorized under three main categories: Ultra-Reliable Low-Latency Communication (URLLC), massive Machine-Type Communication (mMTC), and Enhanced Mobile Broadband (eMBB). However, as the industry looks toward the future, it is clear that 5G networks are just the beginning.

[0009] A sixth generation (6G) wireless communication standard is currently under development, as the planned successor to 5G, and will likely be significantly faster. Like its predecessors, 6G networks will likely be broadband cellular networks, in which the service area is divided into small geographical areas called cells.6G networks are expected to be even more diverse than their predecessors and are likely to support applications beyond current mobile use scenarios, such as virtual and augmented reality (VR / AR), ubiquitous instant communications, pervasive intelligence and the Internet of Things (IoT). It is expected that mobile network operators will adopt flexible decentralized business models for 6G, with local spectrum licensing, spectrum sharing, infrastructure sharing, and intelligent automated management underpinned by mobile edge computing, artificial intelligence (AI), short-packet communication and blockchain technologies.

[0010] The concept of a Network Control Repeater (NCR) is a Release 18 Study item / Work item to introduce a repeater for coverage purposes that is controlled by the network [RP-213700]. Referring now to FIG. 1, an example block diagram of a known network architecture 100 of NCR communication is illustrated, with communication links between a gNodeB (gNB) 104, a NCR 108 and a user equipment (UE) 102. One of the keys to allow for easy deployments of NCR 108 is that it shall be transparent to a UE 102, irrespective of whether (or not) it is communicating through an NCR 108.

[0011] The NCR 108 may be considered to consist of two logical entities or respective circuits; the NCR-Mobile Termination (MT) 140 and the NCR-Forward (Fwd) 142. The NCR-MT 140 part of the NCR 108 is the entity that terminates the Control Link 130 with a control link circuit 126 in the gNB 104. The main purpose of the NCR-MT 140 is to receive Control Link 130 information for the NCR-Fwd 142, such as general configurations and short-term control link information. The NCR-MT 140 is expected to function almost like a normal UE, meaning that the NCR configurations are signaled similar to a normal UE. This means that the NCR-MT 140 will contain a full protocol stack, but some functionality that is normally used by a UE 102 may not be applicable and will not be implemented by the NCR-MT 140 and / or configured by the network.

[0012] The NCR-Fwd 142 is the forwarding entity that has a backhaul link 132 with a backhaul processing circuit 128 in the gNB 104 and an Access Link 124 to an access link processing circuit 122 in the UE 102. There are three types of forwarding configurations:

[0013] Periodic forwarding: This is configured and activated via the radio resource control (RRC) layer.

[0014] Aperiodic forwarding: This is partly configured via RRC, but activated via downlink control information (DCI), i.e., DCI format 2_8. The DCI format 2_8 indicates the time resource as well as the beam index to be used for forwarding whilst the beam width is configured via the RRC layer.

[0015] Semi-Persistent forwarding: This is partly configured via the RRC layer and activated via medium access control (MAC) control element (CE) (using the NCR Access Link Beam Indication MAC CE). The MAC CE includes the resource set identifier (ID) that is used to select one of forwarding semi-persistent resource lists signalled via RRC and the beam index ID of the spatial resources to be used for forwarding.

[0016] In addition to controlling the forwarding part of the NCR-Fwd, the backhauling of the NCR-Fwd can also be configured. The backhauling part is configured via RRC on the control link as a normal UE. New for NCR is new MAC CEs introduced that control the downlink and uplink backhauling. These are called the NCR Downlink Backhaul Link Beam Indication MAC CE and NCR Uplink Backhaul Link Beam Indication MAC CE. These MAC CEs either contain the TCI state or the SRS Resource ID

[0017] The forwarding operation has the following characteristics: Forwarding can be performed in either RRC connected mode and RRC inactive mode. When an NCR-MT 140 is in RRC inactive mode, only the periodic forwarding is applicable, as the network cannot control the aperiodic forwarding. However, if a Beam Failure occurs and a Beam Failure Recovery (BFR) procedure is triggered, the NCR-Fwd 142 will cease to forward and then continue forwarding once the beam failure has been recovered.

[0018] Referring now to FIG. 2, a message sequence chart 200 of a known mechanism for NCR integration is illustrated. Here, an NCR 108 will be authorized by an Access and Mobility Management Function (AMF) 202 when establishing a connection to a gNB 104 and a core network. The mechanism commences with the NCR 108 and gNB 104 sending and receiving messages at 210, with the NCR 108 then sending an RRCSetupRequest message to the gNB 104 at 220. The gNB 104 responds with RRCSetup information at 230. When an NCR-MT in the NCR 108 connects to a network, the NCR-MT will send an ncr-NodeIndication information element in an RRCSetupComplete message at 240, which indicates to the gNB 104 that a UE is in fact an NCR-MT. At 250, the gNB 104 sends an Initial Context Setup message to the AMF 202. At 260, the AMF 202 will authorize the NCR and if authorized, the AMF indicates to the gNB that the NCR is authorized at 270.

[0019] In communication systems, an operations, administration, and management or operations, administration, and maintenance (OA&M or OAM) is located within the network and configured to handle the processes, activities, tools, and standards involved with operating, administering, managing and maintaining any system. Within the 3GPPTM5G standard, the OAM is expected to play a part of managing the NCR 108. OAM is expected to handle capabilities, output power, allowed / not-allowed cells and directly interact with the NCR 108 for these issues. Similarly, the OAM may also indirectly control the configuration of an NCR 108 through a donor gNB 104 (since the donor gNB 104 configures the NCR 108).

[0020] A known problem with current technologies is Radio Link Failure, whereby procedures are introduced to allow a UE to regain its radio link to another base station, in case the radio link fails. After having been triggered, the UE performs radio resource control (RRC) re-establishment, which means that the UE performs cell selection to potentially find a new cell (the same cell is a possible outcome) and connects to the cell.

[0021] Referring now to FIG. 3, some known examples of Radio Link Failure 300, 350 between a UE 102 and a gNB 104 are illustrated: a) RLF triggered 330 after T310 has been triggered 320 from receiving out-of-sync indications 310; and b) recovering after T310 being triggered. The Radio Link Failure can be declared in a number of cases, where some examples are provided below.

[0022] In the first known example of RLF 300, following a UE out of sync, the UE 102 measures the cell strength through Radio Link Monitoring. If the cell strength is below a certain threshold for a configurable amount of times (N310), the UE triggers a timer (T310) at 320 for the UE 102 to recover. If the UE 102 does not recover, the UE 102 declares a RLF 330. The recover condition is that the UE 102 receives an in-sync indication 360 a configurable amount of times (N311) during the T310 timer duration, as illustrated in RLF 370.

[0023] A second example of RLF is when RLC PDUs are re-transmitted a number of times. Here, the network configures a number of times (maxRetxThreshold) that an RLC protocol data unit (PDU) may be attempted to be re-transmitted.

[0024] A third example of RLF is when there are random access problems. This can occur, for example, when the UE 102 is in connected mode and the UE 102 is trying to re-synchronize, for instance after losing uplink synchronization.

[0025] A fourth example of RLF occurs following a failure of backhaul links, which leads to backhaul (BH) RLF (IAB related).

[0026] A fifth example of RLF occurs following an Uplink Listen Before Talk (LBT) failure, which occurs when the UE 102 fails LBT when, say, operating on an unlicensed band.

[0027] As part of performing RLF, the UE 102 can be configured to gather an RLF-Report, which contains information regarding the RLF, which then can be reported to the gNB 104 where it occurred, or indeed any other gNB.

[0028] In some circumstances, such as when RRC re-establishment fails, or if the UE 102 has not yet activated access stratum (AS) security, the UE 102 may have to leave connected mode under the release cause 'RRC Connection Failure'. The release cause is relayed to upper layers of the UE 102 - non-access stratum (NAS) in this case. The action in NAS, upon entering RRC idle mode with this release cause, is to trigger a Tracking Area Update (TAU) to any cell according to idle mode procedures.

[0029] Referring now to FIG. 4, a known example illustrates RRC Re-establishment procedure 400 is performed after RLF in most cases; and can also be performed when a UE fails a handover, as well as in cases of configuration failure. The RRC Re-establishment procedure 400 comprises communications between a UE 402, an old gNB 404 and a new gNB 406. The RRC Re-establishment procedure 400 includes a RLF being declared between the UE 402 and the old gNB 404 at 410, which in some instances can also be a Handover failure. At 420, an Idle mode cell selection is performed by the UE 402. At 430, after first performing random access, the UE 402 sends a RRC Re-establishment request to the new gNB 406. At 440, the new gNB 406 retrieves UE context from old gNB 404 (if the new gNB is not the same as the old gNB). At 450, the old gNB 404 returns the UE context to the new gNB 406. At 460, the new gNB 406 replies with RRC Re-establishment and potentially reconfigures UE 402 if needed, or continues using the same RRC configuration as previous. If reconfiguring the UE 402, the new gNB 406 replies with RRCSetup. At 470, the UE 402 returns to the new gNB 406 with a message that the RRC re-establishment is complete.

[0030] To indicate to an old gNB 404 that a UE 402 previously associated / connected to it, has failed, the new gNB 406 can signal a so-called RLF indication to the old gNB 404 via the Xn interface, as illustrated in the failure indication procedure 500 of FIG. 5. The RLF indication can for instance contain the RLF-Report compiled by the UE 402.

[0031] Referring now to FIG. 5, a known example illustrates a failure indication procedure 500 with accompanying RLF and RRC re-establishment procedure, as well as RLF Report transmission. The failure indication procedure 500 comprises communications between a UE 402, an old gNB 404 and a new gNB 406. The failure indication procedure 500 includes a RLF being declared between the UE 402 and the old gNB 404 at 510, which in some instances can also be a Handover failure. At 520, an Idle mode cell selection is performed by the UE 402. At 530, after first performing random access, a RRC Re-establishment procedure is performed between the UE 402 and the new gNB 406. At 540, the UE 402 sends a UE information response (in a form of a RLF report) to the new gNB 406. At 550, the new gNB 406 sends the old gNB 404 the failure indication (in the form of the RLF report).

[0032] In 3GPPTM5G, non-access stratum (NAS) and mobility management (MM) are two protocols that operate at the upper layer of the 5G system architecture, above the access stratum (AS) that deals with the radio interface. NAS is responsible for establishing, maintaining, and releasing sessions between the user equipment (UE) and the core network (CN). To activate 5G NAS security, the AMF and the UE first need to perform mutual authentication, which establishes the 5G NAS security context.

[0033] Referring now to FIG. 6, a message sequence chart 600 of a known example of an AS security establishment procedure, from a perspective of the AS layer, is illustrated. When an RRC connection is being established via RRC setup procedures, the procedures will first establish a radio bearer that can be used for further configurations. This first radio bearer is a signalling radio bearer (termed 'SRB1'), which is used for RRC messages (that may include a piggybacked NAS message) as well as for NAS messages prior to an establishment of SRB2, all using a dedicated Control (logical) Channel (DCCH) that is used within the uplink and downlink to carry dedicated control information between the UE or mobile and the network; where SRB2 is for NAS messages, again using DCCH logical channel.

[0034] The mechanism commences with the UE 102 and gNB 104 sending and receiving messages at 610, with the UE 102 then sending an RRCSetupRequest message to the gNB 104 at 620. The gNB 104 responds with RRCSetup information at 630 and the UE confirms that an RRC connection has been established by sending an RRCSetupComplete message to the gNB 104 at 640. Establishing SRB1 (without AS security) at 650 allows for continued configurations of the UE and the establishment of AS security. Configurations that can for instance be configured without AS security include measurement reporting configurations, medium access control (MAC) and physical (PHY) layer configurations, etc.

[0035] Then after this is established, secure NAS signaling can be configured by the gNB 104 sending the Security Mode Command at 660 to the UE 102, which establishes the ciphering and integrity protection algorithms. The UE 102 confirms that AS security has been established at 680 by sending a SecurityCommandComplete message to the gNB 104 at 670.

[0036] Thus, the AS security is established via the Initial AS security activation procedures. This is done through the messageSecurityModeCommandandSecurityModeComplete. TheSecurityModeCommandconfigures the specific security algorithms to be used and theSecurityModeCompleteacknowledges the successful establishment. When a UE 102 receives theSecurityModeCommand, the UE 102 verifies the integrity protection of the message using derived keys, and if the integrity protection passes, then new keys are generated using the signaled ciphering algorithm. These keys are maintained for the SRB after the completion of the Initial AS security activation. AS security supports both ciphering (that provides signaling data confidentiality) and integrity protection (that provides user or data integrity). It is supported for both signaling via SRBs or user data via DRBs. The keys used for ciphering and integrity protection are different for SRBs and DRBs, where all SRBs (SRB1, SRB2, SRB3 and SRB4) share keys (KRRCintand KRRCenc) and DRBs have another set of keys (KUPintand KUPenc). The keys may be updated, but this can only be performed by using RRC Reconfiguration with sync, which causes the UE to perform random access before replying with the RRCReconfigurationComplete message.

[0037] Mutual authentication is performed over NAS by initiating the Authentication Request / Response. There are two methods for performing the mutual authentication; Extensible Authentication Protocol (EAP)-based primary authentication, which is an authentication framework that allows for the use of different authentication methods for secure network access technologies, and 5G EAP with Authentication and Key Agreement (AKA), which uses a more advanced primary authentication algorithm than EAP to generate and exchange encryption keys. The mutual authentication can be initiated when a UE 102 sends a Registration Request and the AMF 202 and the UE 102 have not authenticated themselves. The keys generated during the NAS / 5GC procedures are used when generating AS keys. To start using NAS signaling security, the security mode control procedures are used.

[0038] In the Release 18 work item of the Network Controlled Repeater 108 a simplified repeater was introduced that can be configured and controlled by the network. NCR 108 is a potentially very powerful tool in securing good coverage in a cost-effective manner. However, a number of significant features were not concluded for NCR Release 18.

[0039] The inventors have recognized and appreciated that whilst a repeater is a powerful device, it can also cause significant interference in a wireless communication system if it is mis-configured. In particular, it would be problematic if there was a malicious configuration of the NCR with the intent of producing wireless interference. This risk is particularly prevalent with an NCR because the forwarding operation of the NCR can be configured by a gNB via standardized RRC configurations, which could result in repeating all signals across the bandwidth of a cell. This is different from, for instance, capturing an IAB node, because the IAB node acts as its own base stations and will transmit according to a scheduler based on serving UEs. Furthermore, the NCR-MT will in most cases not have any uplink user data to send by itself. The privacy requirements of an NCR 108 may be less, since there is no personal user data to request. However, there is still a need to ensure secure communication and configuration of an NCR 108 device, as without such security, there is a risk of attack of the NCR configuration with implications to the efficiency and operational state of the wireless system as a whole.

[0040] Thus, the inventors have recognized and appreciated that a need exists for devices, circuits and methods to make the NCR configuration and operation more secure.

[0041] According to an embodiment of the present disclosure, a method for communication by a network controlled repeater (NCR) in a wireless communication system is provided. The method may comprise activating access stratum (AS) security associated with the NCR; and receiving a radio resource control (RRC) reconfiguration message for configuring an NCR-forward(Fwd) of the NCR based on the AS security being activated.

[0042] According to an embodiment of the present disclosure, an apparatus for a network control repeater (NCR) in a wireless communication system is provided. The apparatus may comprise a transceiver; and at least one processor coupled to the transceiver. The at least one processor may be configured to activate access stratum (AS) security associated with the NCR; and receive a radio resource control (RRC) reconfiguration message for configuring an NCR-forward(Fwd) of the NCR based on the AS security being activated.

[0043] According to an embodiment of the present disclosure, a non-transitory computer readable storage medium storing instructions which, when executed by an apparatus for a network controlled repeater (NCR) in a wireless communication system, cause the apparatus to perform operations. The operations may comprise activating access stratum (AS) security associated with the NCR; and receiving a radio resource control (RRC) reconfiguration message for configuring an NCR-forward(Fwd) of the NCR based on the AS security being activated.

[0044] Further details, aspects and embodiments will be described, by way of example only, with reference to the drawings. In the drawings, similar reference numbers are used to identify like or functionally similar elements. Elements in the figures are illustrated for simplicity and clarity and have not necessarily been drawn to scale.

[0045] FIG. 1 illustrates a block diagram of a known network architecture of NCR communication.

[0046] FIG. 2 illustrates a message sequence chart of a known mechanism for NCR integration.

[0047] FIG. 3 illustrates a known example of a simplified message sequence chart of Radio Link Failure.

[0048] FIG. 4 illustrates a known example of a simplified message sequence chart of a RRC Re-establishment procedure.

[0049] FIG. 5 illustrates a known example of a simplified message sequence chart of a failure indication procedure.

[0050] FIG. 6 illustrates a known example of an AS security establishment procedure example from the perspective of the AS layer.

[0051] FIG. 7 illustrates one example of a simplified message sequence chart (with schematic), perceived as a potential NCR problem by the inventors, of an attacker acting as a donor gNB in an attempt to get an NCR-Fwd to create interference.

[0052] FIG. 8 illustrates a block diagram of a base station, such as a gNB, communicating with a NCR, adapted in accordance with some examples.

[0053] FIG. 9 illustrates a simplified message sequence chart of one example of establishing AS security or performing mutual authentication before configuring the NCR-Fwd, adapted in accordance with some examples.

[0054] FIG. 10 illustrates a simplified message sequence chart of one example of configuring NCR-Fwd after NCR is authorized by the core network, adapted in accordance with some examples.

[0055] FIG. 11 illustrates a simplified message sequence chart of one example of general outline of NCR procedures, adapted in accordance with some examples.

[0056] FIG. 12 illustrates an exemplary block diagram of an apparatus for a network entity.

[0057] Skilled artisans will appreciate that elements in the figures are illustrated for simplicity and clarity and have not necessarily been drawn to scale. For example, the dimensions and / or relative positioning of some of the elements in the figures may be exaggerated relative to other elements to help to improve understanding of various examples. Also, common but well-understood elements that are useful or necessary in a commercially feasible embodiment are often not depicted in order to facilitate a less obstructed view of these various examples. It will be further appreciated that certain actions and / or steps may be described or depicted in a particular order of occurrence while those skilled in the art will understand that such specificity with respect to sequence is not actually required. It will also be understood that the terms and expressions used herein have the ordinary technical meaning as is accorded to such terms and expressions by persons skilled in the technical field as set forth above except where different specific meanings have otherwise been set forth herein.

[0058] Examples herein described are related to an NCR and methods for securely configuring and operating an NCR.

[0059] Referring first to FIG. 7, one example of a simplified message sequence chart 700 (with schematic) is illustrated, perceived as a potential NCR problem by the inventors, of an attacker 710 acting as a donor gNB in an attempt to get an NCR-Fwd circuit 142 of an NCR 108 to create interference. In this attack, there is a failure between donor gNB 104 and the NCR 108 that causes an establishment with the attacker 710 acting as the donor gNB. Here, the NCR-MT 140 of the NCR 108 detects the attacker 710 acting as the donor gNB as the strongest gNB at 720. During a normal establishment at 730, the AS security may not be activated for a while as NAS security is established. The attacker 710 acting as the donor gNB is also the entity that sends the command to establish AS security, making it possible to delay any AS security establishment. In this attack, the attacker 710 acting as the donor gNB of an NCR 108, and the attacker configures the NCR 108 to repeat the messages on all signals (e.g., all slots and beams), at 740, thereby causing interference 750 using the operations of the NCR-Fwd circuit 142.

[0060] A yet further envisaged problem of an attack uses the unprotected lower layer signaling in an attempt to get the NCR 108 to forward on resources, thereby causing interference to the network. This is because downlink control information (DCI) and MAC CE can control what resources that an NCR-Fwd 142 forwards on, which is neither integrity protected nor ciphered. It should be noted that similar weaknesses exist for a UE, where an attacker could potentially get the UE to transmit in the uplink using DCIs, thereby also causing interference. However, the difference in this scenario is that a UE has a significantly lower maximum output power compared to an NCR 108, which is a network node.

[0061] In Release 18 Network Controlled Repeaters, it is always considered that the NCR-Fwd will forward, i.e., repeat, the signals of the full bandwidth of a specific cell that the NCR-MT is connected / camping on. Thus, when defining how the forwarding part of an NCR node is configured "from another frequency", the frequency band that the NCR-Fwd is forwarding on may be defined as "forwarding on a carrier", "forwarding a cell", and other similar phraseology. Similarly, it may be considered that there are multiple "NCR-Fwd" entities, existing for each band / carrier, or it may be considered to be a single NCR-Fwd entity that forwards across multiple potentially discontinuous frequency bands. The above scenarios give rise to following possibilities that may perform similar functionality required in existing single carrier NCRs, but function over multiple carriers, in accordance with example embodiments herein described.

[0062] In some examples herein described, the wording "NCR-Fwd ON" / "NCR forwarding" is used to indicate that NCR forwarding is operational, whereas "NCR-Fwd OFF" or "NCR ceasing forwarding" or similar wording is used to indicate that NCR-Fwd is not operating, i.e., not forwarding. "NCR-Fwd ON" may also mean that NCR-Fwd is not "OFF", meaning that it can forward if the NCR has been configured to forward. As a concrete example, the NCR may be configured with aperiodic or semi-persistent forwarding and then NCR-Fwd may be turned "ON". In this case the NCR-Fwd will not perform any forwarding before a DCI or MAC CE command has been received from the donor gNB ordering the NCR-Fwd to forward. This has been defined in NCR 3GPP Rel-18. It is also envisaged that the concepts herein described may be referred to differently when applied to other communication systems, both currently and in the future, for example in 6G. For instance, it is envisaged that "NCR-Fwd ON", "NCR-Fwd partial ON" or "NCR-Fwd OFF", may indicate intermediate steps where the NCR is not forwarding fully but may also be employed to implement the concepts described herein. It is envisaged that this may be, for instance, implemented only using a set of beams to forward, or only using a part of a configuration to forward, or only using a set of the time-resources to forward, or only using a part of the bandwidth to forward, or using less than full power to forward, etc.

[0063] In some of the examples herein described, the term "network" may encompass the core network or a base station (such as a 5G gNB), as both may be employed in the authentication and security provisions herein described. Therefore, in and across some examples, the terms "network" and "base station" or "gNB" may be used interchangeably.

[0064] Referring now to FIG. 8, block diagrams of a wireless base station, in a form of a gNB 804, communicating 821 with a NCR 808 are illustrated, where the respective wireless communications units have been adapted in accordance with some examples.

[0065] The gNB 804 contains a beam forming antenna array 802, coupled to a transceiver via an antenna switch or duplexer 803 that provides isolation between receive and transmit chains within the gNB 804. As regards the receive chain, this includes one or more receiver circuits that include receiver front-end circuitry 806 (effectively providing reception, filtering and intermediate or base-band frequency conversion). The receiver front-end circuitry 806 is coupled to a signal processor 809 (generally realized by a digital signal processor (DSP)). A skilled artisan will appreciate that the level of integration of receiver circuits or components may be, in some instances, implementation-dependent.

[0066] A controller 814 maintains overall operational control of the gNB 804. The controller 814 is also coupled to the receiver front-end circuitry 806 and the signal processor 809. In some examples, the controller 814 is also coupled to a frequency generation circuit 817 and a memory device 816 that selectively stores operating regimes, such as decoding / encoding functions, synchronization patterns, code sequences, and the like. A timer 818 is operably coupled to the controller 814 to control the timing of operations (e.g., transmission or reception of time-dependent signals) within the gNB 804.

[0067] As regards the transmit chain, this includes a transmitter / modulation circuitry 822 and a power amplifier 824 coupled to the beam forming antenna array 802. The transmitter / modulation circuitry 822 and the power amplifier 824 are operationally responsive to the controller 814. The signal processor 809 in the transmit chain may be implemented as distinct from the signal processor in the receive chain. Alternatively, a single processor may be used to implement a processing of both transmit and receive signals, as shown in FIG. 8. Clearly, the various components within the gNB 804 can be realized in discrete or integrated component form, with an ultimate structure therefore being an application-specific or design selection.

[0068] The signal processor 809 comprises a control link processing circuit 826 operably communicates via Control link information 830 to an NCR 808 and comprises a backhaul processing circuit 828 operably coupled to the NCR 808 via a backhaul link 832. The signal processor 809 and / or controller 814 together with the transceiver (e.g., transmitter / modulation circuitry 822 and receiver front-end circuitry 806) of the gNB 804 are configured to transmit Control Link 830 information to a NCR-Fwd circuit 842 in the NCR 808, such as general configurations and short-term control link information. In some examples (not shown), the gNB 804 may be configured to provide configuration messages and details to an NCR 808, in order to configure an NCR-Fwd circuit 842, as described later.

[0069] FIG. 8 also shows a high-level block diagram of a NCR 808. In this example, the NCR 808 may be considered to consist of two or more logical entities performed by software in the signal processor 859 (or by logic in, say, a FPGA, or by other devices or circuits), referred to hereafter as a NCR-Mobile Termination (MT) circuit 840 and an NCR-Forward (Fwd) circuit, 842. In this example, the NCR-MT circuit 840 is the entity that terminates the Control Link 830 with a control link circuit 826 in the gNB 804. The main purpose of the NCR-MT circuit 840 is to receive Control Link 830 information for the NCR-Fwd circuit 842, such as general configurations and short-term control link information. In this example, the NCR-MT circuit 840 is expected to function almost like a normal UE, meaning that the NCR configurations are signaled similar to a normal UE. This means that the NCR-MT circuit 840 will contain a full protocol stack. However, in this example, some functionality that is normally used by a UE may not be applicable and will not be implemented by the NCR-MT circuit 840 and / or configured by the network. In accordance with examples, the NCR-Fwd circuit 842 is the forwarding entity, that has a backhaul link 832 with the backhaul processing circuit 828 in the gNB 804.

[0070] NCR 808 contains a beam forming antenna array 852, for transmitting and receiving transmissions, coupled to a transceiver via an antenna switch or duplexer 853 that provides isolation between receive and transmit chains within the NCR 808. One or more receiver chains, as known in the art, include receiver front-end circuitry 856 (effectively providing reception, filtering and intermediate or base-band frequency conversion). The receiver front-end circuitry 856 is coupled to a signal processor 859 (generally realized by a digital signal processor (DSP)). A skilled artisan will appreciate that the level of integration of receiver circuits or components may be, in some instances, implementation-dependent.

[0071] In some examples (not shown), the NCR-Fwd circuit 842 is operably coupled to the NCR-MT circuit 840 of the NCR 808, and configured or prevented from being configured in accordance with the approaches described later.

[0072] The controller 864 maintains overall operational control of the NCR 808. The controller 864 is also coupled to the receiver front-end circuitry 856 and the signal processor 859. In some examples, the controller 864 is also coupled to a frequency generation circuit 867 and a memory device 866 that selectively stores operating regimes, such as decoding / encoding functions, synchronization patterns, code sequences, and the like. A timer 868 is operably coupled to the controller 864 to control the timing of operations (e.g., transmission or reception of time-dependent signals) within the NCR 808.

[0073] As regards the transmit chain, this includes the signal processor 859 forwarding (repeating) received messages, through transmitter / modulation circuitry 872 and a power amplifier 874 to the beam forming antenna array 852. The transmitter / modulation circuitry 872 and the power amplifier 874 are operationally responsive to the controller 864.

[0074] The signal processor 859 in the transmit chain may be implemented as distinct from the signal processor in the receive chain. Alternatively, a single processor may be used to implement a processing of both transmit and receive signals, as shown in FIG. 8. Clearly, the various components within the NCR 808 can be realized in discrete or integrated component form, with an ultimate structure therefore being an application-specific or design selection.

[0075] In some examples, the signal processor 859 and / or controller 864 and transceiver (e.g., transmitter / modulation circuitry 872 and receiver front-end circuitry 856) of the NCR 808 are configured to communicate with the wireless base station, e.g., gNB 804 to avoid the NCR 808 being falsely configured. In some examples, it is envisaged that there may need to be limitations or new, expected behaviour applied to the donor gNB 804 and the NCR 808, in order to prevent or at least mitigate any attempt at malicious configuration of the NCR 808.

[0076] Therefore, in accordance with examples herein described, one of the most important operations, before the NCR 808 starts operating, is to ensure that security measures have been taken. In some examples, these security measures may encompass at least one, a number, or all of the following configurations:

[0077] Before the NCR-Fwd circuit 842 starts operating, the NCR 808 and either the donor gNB and / or a core network (CN) (e.g CN 905 from FIG. 9) shall have mutually authenticated one another.

[0078] AS security shall have been established between donor gNB 804 and NCR 808.

[0079] NAS security has been established between NCR 808 and core network 905 (e.g., more specifically an AMF in this case).

[0080] In examples of the invention, and only after one or more of these security measures have been taken, the donor gNB 804 may be allowed to configure the NCR 808, or the NCR-Fwd circuit 842 may begin forwarding. In some examples, the NCR 808 may also be considered to be allowed to "accept" configurations after the above one or more security measures have been taken.

[0081] An example of these security measures may, for instance, be that donor gNB 804 shall not configure the NCR 808 with any forwarding resources before AS security has been established, in other words the donor gNB 804 only configures the NCR-Fwd circuit 842 after the AS security has been established. An example of this is illustrated in FIG. 9.

[0082] Referring now to FIG. 9, a message sequence chart 900 illustrates one example of establishing AS security or performing mutual authentication before configuring the NCR-Fwd in accordance with some examples. The message sequence chart 900 illustrates communications between an NCR 808 and a donor gNB 804 and a core network 905. In this example, the NCR 808 includes NCR-MT 840 operably coupled to NCR-Fwd circuit 842.

[0083] At 910, RRC setup procedures are adopted with communications between NCR-MT 840 of the NCR 808 and the donor gNB 804. At 920, a SRB1 without AS security is established between the NCR-MT 840 of the NCR 808 and the donor gNB 804. In accordance with some examples, security measures 925 are then employed between NCR-MT 840 of the NCR 808 and the donor gNB 804. In this example, the security measures 925 comprise establishing a new NAS security link being established between the donor gNB 804 and respectively at 930 the NCR-MT 840 of the NCR 808 and at 932 the CN 905. At 940, the donor gNB 804 sends a SecurityModeCommand to the NCR-MT 840 of the NCR 808. At 950, the NCR-MT 840 of the NCR 808 sends a SecurityModeComplete to the donor gNB 804. At 960, an AS security is, according to examples herein described, now established between the NCR-MT 840 of the NCR 808 and the donor gNB 804 following mutual authentication. At this point, the security measures 925 have been completed. At 970, the donor gNB 804 sends a RRCReconfiguration sent using integrity protection and ciphering (to configure the NCR-Fwd circuit 842 of the NCR 808) to the NCR-MT 840. At this moment, at 975, the NCR-Fwd circuit 842 is turned 'ON'.

[0084] In another example, it is envisaged that the NCR 808 may be configured to not perform any forwarding before AS security has been established. This implicitly means that resources may be configured, but no forwarding is allowed before AS security has been established. As a refinement of this example, it is envisaged that the NCR may be configured to wait until AS security has been confirmed, before starting to forward, thus no additional signaling would be needed.

[0085] In some examples, the establishment of the AS security may be performed via a SecurityModeCommand, or any other methods to establish AS security. If, for instance, a handover is performed, then AS security will be (re-)established with the new gNB. If for instance a dual connectivity connection is established, the AS security of the new cell group will be established via the RRC reconfiguration with sync procedures. If an NCR-MT resumes an RRC connection from the RRC inactive state, the AS security will be resumed after successful RRC Resume procedures.

[0086] As another example, any proprietary algorithm may be used to establish AS security that is suitable for the aforementioned NCR scenario, for example a manual establishment may be used.

[0087] In another example, it is envisaged that a yet further network-based condition may be that the gNB 804 is configured to refrain from configuring the NCR 808 before the NCR 808 has been authorized by an AMF to act as an NCR. In this example, the gNB 804 waits for the authorization in a UE Context setup received by AMF before performing any type of configuration of the NCR-Fwd circuit 842. This is because it may be possible that NCR has setup AS security while the NCR has yet to be authorized in some cases. If for instance it is not safe for the NCR to operate (due to a possible attacker, such as an attacker base station being identified in the vicinity of the NCR), it may be able to establish AS security, but it may not be authorized by the AMF to operate. This scenario is illustrated in FIG. 10.

[0088] Referring now to FIG. 10, a message sequence chart 1000 illustrates communications between an NCR 808 and a donor gNB 804 and a core network 905, in accordance with some examples. In this example, the NCR 808 includes NCR-MT 840, NCR-Fwd circuit 842.

[0089] At 1010, RRC setup procedures are adopted with communications between NCR-MT 840 of the NCR 808 and the donor gNB 804. At 1020, a SRB1 without AS security is established between the NCR-MT 840 of the NCR 808 and the donor gNB 804. In accordance with some examples, security measures 1025 are then employed between NCR-MT 840 of the NCR 808 and the donor gNB 804. In this example, the security measures 1025 comprise a new NAS security link being established between the donor gNB 804 and respectively at 1030 the NCR-MT 840 of the NCR 808 and at 1032 the CN 905. At 1040, the donor gNB 804 sends a SecurityModeCommand to the NCR-MT 840 of the NCR 808. At 1050, the NCR-MT 840 of the NCR 808 sends a SecurityModeComplete message to the donor gNB 804. At 1060, an AS security is, according to examples herein described, now established between the NCR-MT 840 of the NCR 808 and the donor gNB 804 following mutual authentication. At this point, the security measures 1025 have been completed. In this example, at 1070, the CN 905 confirms to the donor gNB 804 that the NCR 808 is authorized and at 1080, the donor gNB 804 sends a RRCReconfiguration message (to configure the NCR-Fwd circuit 842 of the NCR 808) to the NCR-MT 840, where the RRCReconfiguration message is ciphered and integrity-protected. At this moment, at 1090, the NCR-Fwd circuit 842 is turned 'ON'.

[0090] In one example, the donor gNB 804 may be configured to refrain from configuring anything related to backhauling before the security measures have been taken. These configurations can for instance be TCI state or SRS resource configurations of the downlink or uplink. In some examples, it is envisaged that this approach may be important as an attacker may be able to get information on backhaul configuration in order to try to interrupt the NCR-Fwd backhaul operation through MAC CEs (as explained previously).

[0091] Thus, in this scenario, it is envisaged that a network may wait before the above security measures have been taken before authorizing the NCR 808 so that it can be configured by the donor gNB 804 to forward. Similarly, an NCR 808 may be configured to be aware that it should not be configured to forward before the above measures are taken into account.

[0092] Thus, the example message sequence charts 900 and 1000 of FIG. 9 and FIG. 10 respectively illustrate mechanisms to enable protection from two different attacks: a first attack may be a 'man-in-the-middle' attack, where a malicious attacker base station pretends to be a legitimate gNB and configures the gNB to forward using RRC; and a second attack may be a malicious attacker using knowledge of the NCR RRC configuration to obtain the NCR-Fwd circuit 842 to forward using downlink control information (DCI) or MAC CE.

[0093] In some examples, it is envisaged that the donor gNB 804 may be required to use ciphering of the RRC signalling when configuring an NCR-Fwd circuit 842. In some instances, this may be important as in some example implementations it may not be mandatory to use ciphering when sending RRC signalling. If ciphering is not used, the NCR 808 may be configured to refuse or consider the RRC signaling to be invalid.

[0094] In some examples, if a signal processor, e.g., signal processor 859 of the NCR 808, determines that any of the above actions occur, i.e., a network attempts to configure the NCR 808 to forward before security provisions are in place, it is envisaged that one of the following may be employed. For example, the NCR-MT 840 may be configured to perform a re-establishment procedure and the NCR-MT 840 will not consider the attacking gNB as part of a cell selection if the attack gNB communications are performed during a RRC re-establishment procedure. A further example is that the NCR-MT 840 is configured to move into an RRC idle mode, whereby the NCR-MT 840 will then not consider the attacker gNB as part of the cell selection / re-selection. Furthermore, in this example, the attacker gNB may be reported to the network upon re-connecting to a gNB 804 that can be verified. A yet further envisaged example is when the NCR-MT 840 does not perform re-establishment and does not change its RRC state, but it does not pass on the forwarding parameters to the Fwd entity or does not configure or activate forwarding operations. It is envisaged that in this scenario, this may be achieved if the NCR-Fwd circuit 842 has been configured but no forwarding is allowed.

[0095] In one example, the donor gNB 804 will not configure thencr-RNTIbefore AS security has been configured. This is important as thencr-RNTImay not be configured together with the other forwarding configurations. If thencr-RNTIis configured in cleartext, there is a risk that some of the attacks may be attempted. In another example, the donor gNB 804 may be required to re-configure ncr-RNTI regularly, for instance at every 'X' seconds or minutes, every time the NCR 808 resumes from RRC inactive, or every time the NCR-Fwd circuit 842 or NCR 808 is re-configured.

[0096] In another example, if the NCR 808 configuration is sent before security is in place, the NCR 808 will not start forwarding before the security is in place. This is not as secure as the other options, but still protects the NCR 808 from some attacks.

[0097] In one example, the NCR 808 will release itself from the network if AS security is not established within a certain time period of being connected to a donor gNB 804. This has a potential downside that it may enable a different kind of attack, whereby a rogue gNB could withhold or delay the establishment of AS security, leading to the NCR 808 releasing and attaching to this same rogue gNB and disrupting service. Therefore, in a refinement of this scenario, it is envisaged that the NCR-MT 840 may be configured to not consider this rogue gNB as part of the cell selection / re-selection after, say, 'N' such failed attempts at establishing AS security.

[0098] In one example, the configuration of the NCR 808 may be configured to not start until both: 1) security is in place, and 2) an OAM connection has been established and OAM has indicated that forwarding may be started. In one example, it is envisaged that the OAM may also perform authentication check on the base station (e.g., gNB 804) that the NCR 808 is connected to. An example of how this may be specified can be seen in Specification Example #2, where when these two conditions are fulfilled, the NCR 808 is considered to be "authorized".

[0099] In one example, if the gNB 804 is allowed to initially configure NCR-Fwd circuit 842 without AS security (ciphering and integrity protection), then it is envisaged that the AS security must be used when NCR-Fwd is de-configured, i.e., when NCR-Fwd circuit 842 is turned 'OFF'. In this scenario, it is envisaged that this helps to protect against any attacker that is trying to disrupt the NCR 808 from forwarding. Otherwise, an attacker gNB could potentially easily de-configure and turn 'OFF' the NCR-Fwd circuit 842.

[0100] In one example, the OAM will indicate to the NCR 808 if the NCR-MT 840 has connected to an unauthorized / un-authenticated gNB. This can for instance cause the NCR-MT 840 to disconnect to the gNB 804.

[0101] NCR signalling.

[0102] In an NCR 808, DCI and MAC CE may be used to indicate to the NCR-Fwd circuit 842 to forward on certain antenna beams or in certain time slots. The inventors have recognized and appreciated that DCI and MAC CE are neither integrity protected nor ciphered. DCI is used for aperiodic forwarding and MAC CE is used for Semi-Persistent forwarding. Therefore, the inventors have recognized and appreciated that a malicious attacker may thus use the DCI or MAC CE to manipulate the NCR 808 to forward in order to create interference. Thus, in some examples, it is envisaged that certain restrictions may need to be put in place in order to either: (i) reduce the chance of malicious attacker; or (ii) at least reduce the chance to create a lot of interference.

[0103] Similarly, it is known that in order to control the backhauling, MAC CE is used. The inventors have recognized and appreciated that an attacker could control (or partly control) the backhauling in order to either produce interference in the network or to disrupt and / or render any forwarding useless. For instance, if the downlink backhauling is functioning correctly, but an attacker uses MAC CE to change the uplink backhauling, then the operation of the NCR 808 can be rendered useless.

[0104] Therefore, in some examples and in order to detect a possible malicious attacker, the NCR 808 may be configured to detect one or more of the following:

[0105] receiving a DCI or MAC CE indicating resources that have not been configured. For instance, one example for Semi-Persistent Forwarding using MAC CE, detecting if a resource set ID or a beam index is used that has not been configured in the RRC configuration (NCR-SemiPersistentFwdResourceSet), then the NCR 808 may suspect that a malicious attacker is attempting to get the NCR 808 to forward. For instance, one example for aperiodic forwarding using DCI format 2_8, detecting if beam index or time resource index signaled in the DCI is outside of the range as signaled by RRC (in NCR-AperiodicFwdResourceSet), the NCR may suspect that a malicious attacker is attempting to get the NCR 808 to forward. For instance, one example for backhauling MAC CE, detecting if the NCR-MT 840 receiving MAC CE indicates a specific TCI or SRS resource that has not been configured by RRC;

[0106] DCI (with format 2_8) if aperiodic forwarding has not been configured;

[0107] MAC CE if semi-persistent forwarding has not been configured;

[0108] a large amount of DCI / MAC CE signaling that is irregular. For instance, one example may be to detect if more than 'X' commands are received within 'Y' time period, it may be assumed that the UE may have detected a malicious attacker;

[0109] conflicting forwarding requests in DCI and MAC CE. For instance, the NCR 808 may receive requests to forward in the same beam or same time instance from DCI and MAC CE. This can detect a malicious attacker that is attempting to use one type of forwarding, while the other forwarding resources are being used. It is envisaged that this may happen if the attacker does not know the full RRC configuration, but attempts to get the NCR 808 to forward.

[0110] If, in some examples, any of the above is detected, the NCR-MT 840 may be configured to perform one or more of the following actions:

[0111] Ignore the DCI or MAC CE; if for instance a lot of attempts using DCI is made, the NCR can be configured to ignore any DCI (with format 2_8).

[0112] Report the received signaling; this may allow a donor gNB 804 to de-configure any Semi-Persistent or Aperiodic forwarding to reduce risk of excessive forwarding.

[0113] Perform Radio Link Failure / re-establishment; this can for instance be done if the NCR-MT detects a lot of attempts to forward that the donor gNB 804 does not deal with. The NCR-MT 840 may then signal the reason for performing RLF to indicate why the radio link failure was triggered.

[0114] Referring now to FIG. 11, illustrates a simplified message sequence chart 1100 of one example of general outline of NCR procedures, adapted in accordance with some examples. The message sequence chart 1100 illustrates communications between an NCR 808 and a donor gNB 804 together with potential interference caused by an attacker donor gNB 710. In this example, the NCR 808 includes NCR-MT 840 operably coupled to NCR-Fwd circuit 842. At 1110, setup procedures are adopted with communications from donor gNB 804 to NCR-MT 840 of the NCR 808 to configure NCR-Fwd circuit 842. However, at 1120, attacker donor gNB 710 sends DCI or MAC CE to the NCR 808 to initiate forwarding operations. In response, at 1130, the NCR-MT 840 of the NCR 808 is configured to detect signalling that is inconsistent with a donor gNB's configuration and in response at 1140, perform an action based on the detected signalling inconsistencies, such as report the received signalling that may indicate an attacker donor gNB 710 being at large.

[0115] It is envisaged that in some examples, the above scenario may, for instance, protect against cases where the malicious attacker has knowledge or no knowledge of the RRC configuration (by applying or not applying ciphering of the NCR-Fwd configuration as described previously) for the NCR-Fwd circuit 842. With knowledge of the RRC configuration of the NCR-Fwd circuit 842, the attacker donor gNB 710 knows the specific resources where forwarding may occur if signaled via a MAC CE or DCI. Without knowledge, the attacker donor gNB 710 may obtain knowledge on what type of forwarding has been configured (periodic, semi-persistent and aperiodic forwarding) based on monitoring for DCIs and MAC CEs and the NCR 808 forwarding pattern.

[0116] NCR-Fwd circuit 842 'ON' / 'OFF' operation.

[0117] As previously explained in the background section, the AS security keys used for ciphering and integrity protection may be updated using the RRC reconfiguration with sync. One potential issue with this approach is that the reconfiguration with sync procedures requires a random access procedure being employed. Therefore, in one example, if an AS security update occurs, the NCR-Fwd circuit 842 may be configured to not perform any forwarding during the key update and the random access procedure. Alternatively, in another example, if the AS security key update is triggered and fails, the NCR-Fwd circuit 842 will be turned 'OFF'.

[0118] In accordance with some examples, proposed changes to the 3GPP standard are as highlighted {emphasis added} and as illustrated below:

[0119] ---------------------- Example based on 38.331 V17.5.0 ----------------------5.3.5.2InitiationThe Network may initiate the RRC reconfiguration procedure to a UE in RRC_CONNECTED. The Network applies the procedure as follows:the establishment of RBs (other than SRB1, that is established during RRC connection establishment) is performed only when AS security has been activated;the establishment of BH RLC Channels for IAB is performed only when AS security has been activated;the configuration of NCR-Fwd is performed only when AS security has been activated;the establishment of Uu Relay RLC channels and PC5 Relay RLC channels (other than SL-RLC0 and SL-RLC1) for L2 U2N Relay UE is performed only when AS security has been activated, and the establishment of PC5 Relay RLC channels for L2 U2N Remote UE (other than SL-RLC0 and SL-RLC1) is performed only when AS security has been activated;the addition of Secondary Cell Group and SCells is performed only when AS security has been activated;thereconfigurationWithSyncis included insecondaryCellGrouponly when at least one RLC bearer or BH RLC channel is setup in SCG;thereconfigurationWithSyncis included inmasterCellGrouponly when AS security has been activated, and SRB2 with at least one DRB or multicast MRB or, for IAB, SRB2, are setup and not suspended;theconditionalReconfigurationfor CPC is included only when at least one RLC bearer is setup in SCG;theconditionalReconfigurationfor CHO or CPA is included only when AS security has been activated, and SRB2 with at least one DRB or multicast MRB or, for IAB, SRB2, are setup and not suspended.

[0120] ---------------- Example based on running RRC CRR2-2306609----------------5.3.5.5.XNCR-Fwd configurationThe NCR-MT shall:ifNCR-FwdConfigis set tosetup:ifNCR-FwdConfigincludes periodic forwarding resource configuration:indicate to NCR-Fwd to forward in accordance with the configured periodic forwarding resource set(s)once NCR-Fwd is authorized to forward;NOTE:NCR-Fwd is considered authorized when AS security is established andAMF has authorized the NCR.else (NCR-FwdConfigis set torelease):release NCR-Fwd configuration;indicate to NCR-Fwd to cease forwarding.

[0121] -------------- Example based on running MAC CRR2-2306602--------------5.18.tAccess Link Beam Indication for NCRNCR Access Link Beam Indication MAC CE is used by a gNB to indicate to an NCR-node the forwarding resources to be used for the semi-persistent access link transmission between the NCR-node and the UE(s) served by this device.Upon reception of an NCR Access Link Beam Indication MAC CE, the NCR-node shall:apply the configuration signalled in the MAC CE as received by NCR-MT to the forwarding resource lists indicated via RRC, and use it to operate the NCR-Fwd.If the NCR has been configured with Aperiodic forwarding and the resources indicated the Access Link Beam Indication is colliding with transmissions for aperiodic forwarding or if the resources indicated by lower layers collide with that indicated by the Access Link Beam Indication, the NCR reports the anomalous forwarding behaviour to the upper layer

[0122] FIG. 12 illustrates an exemplary block diagram of an apparatus for a network entity.

[0123] The network entity may be implemented by the apparatus 1200 or in the apparatus 1200. The network entity may be any one of a plurality of network entities described in the present disclosure. For example the network entity may be an NCR or a base station (e.g. a gNB).

[0124] The apparatus 1200 may comprise at least one processor 1230, a transceiver 1220, and a memory 1210.

[0125] The at least one processor 1230 may control operations of other elements of the apparatus 500. The at least one processor 1230 may control operations of the apparatus 1200. The operations of the apparatus 1200 for the network entity may be understood as being performed substantially by the at least one processor 1230. The at least one processor 1230 may perform operations of the network entity described in the present disclosure by executing instructions stored in a storage medium.

[0126] The transceiver 1220 may be used for communications of the apparatus 1200. The apparatus 1200 may transmit and / or receive information through the transceiver 1220. The transceiver 1220 may comprise at least one receiver and at least one transmitter. The transceiver 1220 may support communications based on any known radio access technologies (RATs).

[0127] The memory 1210 may store temporary information and / or permanent information for operations of the apparatus 1200 and / or the at least one processor 1230. The memory 1210 may comprise a non-transitory computer-readable storage medium storing instructions. When the instructions are executed by the at least one processor 1230, the instructions may cause the at least one processor 1230 or the apparatus 1200 to executed operations of the network entity described in the present disclosure.

[0128] In particular, it is envisaged that the aforementioned inventive concept can be applied by a semiconductor manufacturer to any integrated circuit comprising a signal processor configured to perform any of the aforementioned operations. Furthermore, the inventive concept can be applied to any circuit that is able to configure, process, encode and / or decode signals for wireless distribution. It is further envisaged that, for example, a semiconductor manufacturer may employ the inventive concept in a design of a stand-alone device, such as a digital signal processor, or application-specific integrated circuit (ASIC) and / or any other sub-system element.

[0129] It will be appreciated that, for clarity purposes, the above description has described example embodiments with reference to different functional units and processors. However, it will be apparent that any suitable distribution of functionality between different functional units or processors, for example with respect to the signal processor may be used without detracting from the concepts described herein. For example, functionality illustrated to be performed by separate processors or controllers may be performed by the same processor or controller. Hence, references to specific functional units are only to be seen as references to suitable means for providing the described functionality, rather than indicative of a strict logical or physical structure or organization.

[0130] Aspects may be implemented in any suitable form including hardware, software, firmware or any combination of these. Examples may optionally be implemented, at least partly, as computer software running on one or more data processors and / or digital signal processors or configurable circuit components such as FPGA devices. Thus, the elements and components of an example may be physically, functionally and logically implemented in any suitable way. Indeed, the functionality may be implemented in a single unit, in a plurality of units or as part of other functional units.

[0131] Although the concepts have been described in connection with some examples, it is not intended to be limited to the specific form set forth herein. Rather, the scope is limited only by the accompanying claims. Additionally, although a feature may appear to be described in connection with particular embodiments, one skilled in the art would recognize that various features of the described examples may be combined in other examples. In the claims, the term 'comprising' does not exclude the presence of other elements or steps.

[0132] Furthermore, although individually listed, a plurality of means, elements or method steps may be implemented by, for example, a single unit or processor. Additionally, although individual features may be included in different claims, these may possibly be advantageously combined, and the inclusion in different claims does not imply that a combination of features is not feasible and / or advantageous. Also, the inclusion of a feature in one category of claims does not imply a limitation to this category, but rather indicates that the feature is equally applicable to other claim categories, as appropriate.

[0133] In accordance with examples herein described, a system and a number of methods and devices are provided to make the NCR configuration and operation more secure, by for instance preventing or making it more difficult to perform attacks, wherein the aforementioned disadvantages with prior art arrangements have been substantially alleviated.

[0134] Abbreviations / Definitions

[0135] In the present disclosure, the following acronyms / definitions are used.

[0136] 3GPP3rdGeneration Partnership Project

[0137] 5G5thGeneration

[0138] 5GC5G Core

[0139] 5QI5G QoS Identifier

[0140] 5GS5G System

[0141] 5GSM5G System Session Management

[0142] 5GMM5G System Mobility Management

[0143] AFApplication Function

[0144] AIArtificial Intelligence

[0145] AMAcknowledged Mode

[0146] AMFAccess and Mobility Management Function

[0147] ASApplication Server

[0148] ASPApplication Service Provider

[0149] AUSFAuthentication Server Function

[0150] CDNContent Delivery Network

[0151] CNCore Network

[0152] DCAFData Collection Application Function

[0153] DNAIData Network Access Identifier

[0154] DNNData Network Name

[0155] DNSDomain Name Server

[0156] DRBData Radio Bearer

[0157] gNBEvolved Node B

[0158] EPCEvolved Packet Core

[0159] FECForward Error Correction

[0160] FQDNFully Qualified Domain Name

[0161] GBRGuaranteed Bit Rate

[0162] gNBNext generation Node B

[0163] GPSIGeneric Public Subscription Identifier

[0164] HSSHome Subscriber Service

[0165] IABIntegrated Access and Backhaul

[0166] IDIdentity / Identifier

[0167] IIoTIndustrial Internet of Things

[0168] IMEIInternational Mobile Equipment Identities

[0169] IPInternet Protocol

[0170] I-SMFIntermediate SMF

[0171] LADNLocal Area Data Network

[0172] LL SSMLower Layer SSM

[0173] MBMSMultimedia Broadcast / Multicast Service

[0174] MBSMulticast / Broadcast Service

[0175] MBSFMulticast / Broadcast Service Function

[0176] MBSTFMulticast / Broadcast Service Transport Function

[0177] MB-SMFMulticast / Broadcast Session Management Function

[0178] MB-UPFMulticast / Broadcast User Plane Function

[0179] MLMachine Learning

[0180] MMEMobility Management Entity

[0181] MNMaster Node

[0182] MNFMonitoring Network Function

[0183] MNOMobile Network Operator

[0184] MTMobile Termination

[0185] NASNon-Access Stratum

[0186] NEFNetwork Exposure Function

[0187] NRFNetwork Repository Function

[0188] NG-RANNext Generation Radio Access Network

[0189] NG-gNBNext Generation gNB

[0190] NSANon-Standalone

[0191] NSSFNetwork Slice Selection Function

[0192] NTNNon-Terrestrial Networks

[0193] NWNetwork

[0194] NWDAFNetwork Data Analytics Function

[0195] OSOperating System

[0196] OSAPPOS Application

[0197] PCFPolicy Control Function

[0198] PCOProtocol Configuration Options

[0199] PDRPacket Detection Rule

[0200] PDUProtocol Data Unit

[0201] PTMPoint To Multipoint

[0202] PTPPoint to Point

[0203] QFIQoS Flow Identifier (ID)

[0204] QoSQuality of Service

[0205] RACHRandom Access Channel

[0206] RANRadio Access Network

[0207] RRCRadio Resource Control

[0208] RSDRoute Selection Descriptor

[0209] RSRPReference Signal Received Power

[0210] RSRQReference Signal Received Quality

[0211] RSS Reference Signal Strength

[0212] RSSI Received Signal Strength Indicator.

[0213] SAStandalone

[0214] SDAPService Data Adaptation Protocol

[0215] SDUService Data Unit

[0216] SGWServing Gateway

[0217] SIMSubscriber Identity Module

[0218] SLAService Level Agreement

[0219] SMSession Management

[0220] SMFSession Management Function

[0221] SNSecondary Node

[0222] S-NSSAISingle Network Slice Selection Assistance Information

[0223] SSBSynchronization Signal Block

[0224] SSMSource Specific IP Multicast address

[0225] SSCSession and Service Continuity

[0226] SRBSignaling Radio Bearer

[0227] SUPISubscription Permanent Identifier

[0228] TATracking Area

[0229] TAITracking Area Identity

[0230] TETerminal Equipment

[0231] TMTransparent Mode

[0232] TMGITemporary Mobile Group Identity

[0233] TSTechnical Specification

[0234] UDMUnified Data Manager

[0235] UDRUnified Data Repository

[0236] UEUser Equipment

[0237] ULUplink

[0238] UMUnacknowledged Mode

[0239] UPUser Plane

[0240] UPFUser Plane Function

[0241] URLLCUltra-Reliable and Low-Latency Communication

[0242] URSPUE Route Selection Policy

Claims

1.A method for communication by a network controlled repeater (NCR) in a wireless communication system, the method comprising:activating access stratum (AS) security associated with the NCR; andreceiving a radio resource control (RRC) reconfiguration message for configuring an NCR-forward(Fwd) of the NCR based on the AS security being activated.2.The method of claim 1, wherein the NCR-Fwd is not configured in case that the AS security is not activated.3.The method of claim 1, wherein activating the AS security comprises:receiving, by a NCR-mobile termination(MT) of the NCR, a security mode command for activating the AS security from a base station; andtransmitting, by the NCR-MT, a security mode complete to the base station, in response to the security mode command.4.The method of claim 3, wherein the NCR-MT communicates with the base station thorough a control link.5.The method of claim 1, wherein the NCR-Fwd communicates with a base station through a backhaul link, and the NCR-Fwd communicates with a user equipment (UE) through an access link.6.The method of claim 1, wherein the NCR-Fwd does not perform forwarding operation in case that the AS security is not activated.7.The method of claim 1, further comprising:indicating, by an NCR-MT of the NCR, to the NCR-Fwd to perform forwarding based on the AS security being activated.8.An apparatus for a network control repeater (NCR) in a wireless communication system, the apparatus comprising:a transceiver; andat least one processor coupled to the transceiver, wherein the at least one processor is configured to:activate access stratum (AS) security associated with the NCR; andreceive a radio resource control (RRC) reconfiguration message for configuring an NCR-forward(Fwd) of the NCR based on the AS security being activated.9.The apparatus of claim 8, wherein the NCR-Fwd is not configured in case that the AS security is not activated.10.The apparatus of claim 8, wherein the at least one processor is configured to:receive, by a NCR-mobile termination(MT) of the NCR, a security mode command for activating the AS security from a base station; andtransmit, by the NCR-MT, a security mode complete to the base station, in response to the security mode command.11.The apparatus of claim 10, wherein the NCR-MT communicates with the base station thorough a control link.12.The apparatus of claim 8, wherein the NCR-Fwd communicates with a base station through a backhaul link, and the NCR-Fwd communicates with a user equipment (UE) through an access link.13.The apparatus of claim 8, wherein the NCR-Fwd does not perform forwarding operation in case that the AS security is not activated.14.The apparatus of claim 8, wherein the at least one processor is further configured to:indicate, by an NCR-MT of the NCR, to the NCR-Fwd to perform forwarding based on the AS security being activated.15.A non-transitory computer readable storage medium storing instructions which, when executed by an apparatus for a network controlled repeater (NCR) in a wireless communication system, cause the apparatus to perform operations according to a method in one of claims 1 to 7.