Base station with two priority lists of algorithms having different strengths
By employing multiple priority lists for cryptographic algorithms at base stations, the solution addresses the challenge of maintaining encryption security during handovers between 5G network base stations with varying encryption capabilities, ensuring consistent and strong cryptographic standards.
Patent Information
- Application Number
- JP2023184319
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-26
- Publication Date
- 2025-05-13
AI Technical Summary
In 5G mobile communication networks, when a terminal device moves from a base station supporting 256-bit encryption algorithms to one that does not, the security level of encryption changes, necessitating the determination of an appropriate cryptographic algorithm for secure communication.
Implementing multiple priority lists of different strengths for cryptographic and tamper detection algorithms at base stations, allowing them to select the appropriate algorithm based on received security policies, terminal device security functions, and algorithms selected by source base stations.
Ensures the use of appropriately strong cryptographic algorithms at base stations, maintaining security levels during handovers between base stations with different encryption capabilities, thereby enhancing overall network security.
Smart Images

Figure 2025073477000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a method for selecting an encryption algorithm in a mobile communication network. [Background technology]
[0002] A terminal device UE (User Equipment) is a mobile communication terminal used by a user, such as a smartphone. When terminal devices UE communicate with each other, they communicate via a mobile communication network such as 5G. This mobile communication network is hereinafter referred to as a "network NW."
[0003] When a terminal device UE and a network NW communicate wirelessly, each transmits an encrypted message. The message is then decrypted on the receiving side. The algorithm used to encrypt the message is called an "encryption algorithm." In addition, there is a risk that a third party may tamper with the message during wireless communication. Therefore, the sender creates a code for tamper detection and attaches the code to the message before sending it. The algorithm for creating the code for tamper detection is called the "tamper detection algorithm."
[0004] Current mobile communication networks (including 5G) use 128-bit encryption algorithms for the air interface between base stations and terminal equipment UE, and for communication between the core network and terminal equipment UE. However, the introduction of 256-bit algorithms is being considered by 3GPP (Third Generation Partnership Project) SA3. The introduction of 256-bit algorithms is possible by adding the algorithms to the specification (TS33.501), 1) listing the algorithms as mandatory or optional, and 2) introducing supporting software and hardware. This does not change the way the network and UE communicate with each other or decide which algorithm to use. [Prior art documents] [Non-patent literature]
[0005] [Non-Patent Document 1] 3GPP (registered trademark) SA3, TS33.501 [Non-Patent Document 2] 3GPP (registered trademark) SA3, TS37.340 [Non-Patent Document 3] 3GPP (registered trademark) SA3, TS38.413 Summary of the Invention [Problem to be solved by the invention]
[0006] In this way, the terminal equipment UE will be connected to a radio access network that has a mixture of base stations that only support 128-bit algorithms and base stations that also support 256-bit algorithms. Therefore, the 5G network and the terminal equipment UE will need to support 128-bit and 256-bit encryption algorithms in parallel. If the terminal equipment UE moves from a base station that supports 256-bit to another base station that does not support 256-bit encryption algorithms, the encryption security level will change and the expected behavior must be determined.
[0007] The present invention aims to enable a terminal device UE to use an encryption algorithm of appropriate strength in a base station that does not support a 256-bit encryption algorithm when the terminal device UE moves from a base station that supports 256 bits to another base station that does not support a 256-bit encryption algorithm. [Means for solving the problem]
[0008] The present inventors discovered that a base station can be provided with a plurality of priority lists with different strengths for encryption algorithms and / or tamper detection algorithms, and have completed the present invention.
[0009] (1) The first base station of the present invention is a base station having a plurality of priority lists with different strengths for encryption algorithms and / or tamper detection algorithms, and has a function of determining which of the plurality of priority lists to use to select an encryption algorithm and / or tamper detection algorithm when it receives a security function of a terminal device from a terminal device or a source base station as a target base station during handover.
[0010] (2) The first base station may select, from among the plurality of priority lists, a priority list having a higher strength.
[0011] (3) The first base station may determine, based on a security policy received from an SMF, which priority list of the multiple priority lists to use to select an encryption algorithm and / or a tamper detection algorithm.
[0012] (4) The first base station may determine which of the multiple priority lists to use to select an encryption algorithm and / or a tamper detection algorithm based on the algorithm selected by the source base station and the security capabilities of the terminal device.
[0013] (5) The first base station may determine which of the multiple priority lists to use to select an encryption algorithm and / or a tamper detection algorithm, based on the algorithm selected by the source base station and a security policy received from the SMF.
[0014] (6) A second base station according to the present invention is a base station having a plurality of priority lists with different strengths for encryption algorithms and / or tamper detection algorithms, and as a secondary node in a dual connection, has a function of determining which of the plurality of priority lists to use to select an encryption algorithm and / or tamper detection algorithm based on the algorithm or priority list selected by the master node.
[0015] (7) A first terminal device according to the present invention is a terminal device in which a base station having multiple priority lists with different strengths for encryption algorithms and / or tamper detection algorithms serves as a master node and secondary node during dual connection, and rejects the addition of the secondary node if the priority list in which the algorithm used in the master node is selected is not the same as the priority list in which the algorithm selected in the secondary node is selected.
[0016] (8) A third base station according to the present invention is a base station having multiple priority lists with different strengths for encryption algorithms and / or tamper detection algorithms, and as a source base station during handover, manages the handover of a terminal device to an adjacent base station corresponding to the encryption algorithm and / or tamper detection algorithm with the highest strength.
[0017] (9) A fourth base station according to the present invention is a base station having multiple priority lists with different strengths for encryption algorithms and / or tamper detection algorithms, and as a master node of a dual connection, adds only the base station compatible with the encryption algorithm and / or tamper detection algorithm with the highest strength as a secondary node. Effect of the Invention
[0018] According to the present invention, a base station is provided with multiple priority lists of encryption algorithms and / or tamper detection algorithms with different strengths, so that when a terminal device UE moves from a base station that supports 256 bits to another base station that does not support a 256-bit encryption algorithm, an encryption algorithm and / or tamper detection algorithm of appropriate strength can be used in the other base station. [Brief description of the drawings]
[0019] [Figure 1]A diagram showing a handover from a source gNB that supports a 256-bit encryption algorithm to a target gNB that does not support a 256-bit encryption algorithm in the prior art. [Diagram 2] FIG. 1 illustrates four different dual connections according to the prior art. [Diagram 3] FIG. 1 illustrates a process flow for adding a secondary node according to the prior art. [Figure 4] FIG. 11 is a diagram showing a processing flow of handover according to an embodiment of the present invention. [Diagram 5] FIG. 4 is a diagram showing a processing flow of handover in the first embodiment of the present invention. [Figure 6] FIG. 1 is a diagram showing a process flow of the conventional technology and an embodiment of the present invention. [Figure 7] 11 is a diagram illustrating the operation of logic L2 when the algorithms do not match in the embodiment of the present invention. FIG. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0020] First, before describing the embodiments of the present invention with reference to the drawings, problems with the prior art will be described. Figure 1 is a diagram for explaining a problem that occurs in a handover in the related art when the source base station gNB is a base station that supports a 256-bit algorithm, but the target base station gNB is a base station that does not support a 256-bit algorithm. In this case, the following scenarios may occur.
[0021] 1. The terminal device UE is connected to a first base station gNB (source gNB). Since both the terminal device UE and this base station gNB (source gNB) support 256 bits, a 256-bit algorithm is selected.
[0022] 2. Depending on the radio conditions, congestion situation, etc. between the terminal device UE and the source gNB, the source gNB decides to hand over the terminal device UE and sends an RRC (Radio Resource Control) connection reconfiguration message to the terminal device UE to connect to the target gNB.
[0023] 3. The terminal device UE disconnects from the source gNB and then connects to the target gNB. When the target gNB sends a handover notification message to the AMF, the handover connection is completed. However, during this process, the encryption algorithm is switched to a 128-bit algorithm because the target gNB does not support the 256-bit algorithm.
[0024] In this operation, the strength of the algorithm is not taken into consideration during handover, so the encryption algorithm between the target gNB and the terminal device UE has a lower security level than the algorithm with the source gNB. The above are the problems when performing handover in the conventional technology.
[0025] Although this problem can be avoided by standardizing the settings of base stations gNBs, this solution lacks flexibility and does not provide a way to preferentially select the 128-bit algorithm when, for example, one wants to select the 128-bit algorithm for reasons such as battery consumption, computational load, or lack of additional radio resources required for the 256-bit tamper detection algorithm.
[0026] A similar problem can occur in dual connectivity where a terminal device UE is connected to both a master node (MN) or primary RAN and a secondary node (SN) or secondary RAN, resulting in mixed security levels when one uses 128-bit and the other 256-bit algorithms.
[0027] FIG. 2 is a diagram showing four aspects of dual connectivity in the prior art. In FIG. 2(a), a UPF (User Plane Function) is connected to a master node MN. In FIG. 2(b), a UPF is connected to a secondary node SN. In FIG. 2(c), two different UPFs are connected to a master node MN and a secondary node SN, respectively. In FIG. 2(d), a terminal device UE is connected to one CU (central unit) via two different DUs (distributed units), respectively.
[0028] Secondary nodes can be added following the procedures for adding secondary nodes described in TS 37.340 and TS 33.501, which defines the associated security procedures.
[0029] FIG. 3 is a diagram showing a procedure for adding a secondary node in accordance with the prior art TS37.340 and TS33.501. In step S1 of Fig. 3, the master node MN decides to add a secondary node SN and transmits an SN addition request message to the target secondary node SN. The SN addition request includes QoS parameters at the QoS (Quality of Service) flow level, TNL (Transport Network Layer) addresses at the PDU (Protocol Data Unit) session level, and network slide information at the PDU session level. In step S1, the master node MN also provides the security capabilities and UP (User Plane) security policy of the terminal device UE, and the keys required for the security context between the secondary node SN and the terminal device UE.
[0030] In step S2, the secondary node SN decides to accept or reject the SN addition request based on whether it has the necessary radio resources. If it has the necessary resources, the secondary node SN compares the received security capabilities of the terminal device UE with its own list of prioritized security algorithms and selects the highest priority algorithm supported by the terminal device UE.
[0031] This operation is performed for both encryption and tamper detection algorithms. Finally, if UP (User Plane) tamper detection is enabled in the master node MN, it provides an indication of whether UP tamper detection can also be enabled in the secondary node SN.
[0032] In step S3, the secondary node SN sends an SN Addition Request Confirmation message, which includes an SN RRC configuration message including the selected security algorithm and whether UP tamper detection is enabled in the secondary node SN.
[0033] In step S4, the master node MN checks whether the received message is an acknowledgement message, and in step S5, forwards the RRC container to the terminal device UE.
[0034] In step S6, the terminal device UE receives the container, checks whether it can accommodate the new configuration, derives the necessary RRC and UP keys, activates security algorithms with the secondary node SN, creates an SN response message and includes it in the MN RRC reconfiguration complete message of step S7.
[0035] In step S8, the master node MN extracts an SN RRC reconfiguration complete message and forwards it to the secondary node SN as a message in step S9.
[0036] In step S10, the secondary node SN enables security according to a previously selected algorithm, and in step S11, the terminal device UE initiates a random access procedure to establish a connection with the secondary node SN.
[0037] In this way, the selection of the security algorithm is performed by the secondary node SN independently of the master node MN. Therefore, if the security algorithms supported by the secondary node SN and the master node MN are different, the secondary node SN and the master node MN may select algorithms with different strengths.
[0038] For example, if the master node MN selects a 256-bit algorithm, and the secondary node SN selects a 128-bit algorithm, the secondary node SN may unintentionally weaken security. On the other hand, if 128-bit security is sufficient, selecting 256 bits may result in unnecessary use of computational resources. These are the problems with dual connections in the prior art.
[0039] Two solutions (hereinafter referred to as the "first solution" and the "second solution") can be proposed to the problems described above regarding the conventional technology.
[0040] The “first solution” involves adding a second list including 256-bit algorithms to the base station gNB, since under the current specifications the base station gNB does not have a list of encryption algorithms that support 256-bit encryption algorithms, and also including in the base station gNB a function to determine whether to select a 128-bit or 256-bit encryption algorithm list.
[0041] In the "First Solution", Base stations gNBs that support 256-bit algorithms use two priority lists instead of one algorithm priority list, and The two priority lists are divided according to the strength of the encryption algorithm. The base station gNB is to be provided with a function for determining whether to use the first priority list or the second priority list to select an algorithm when receiving the terminal equipment UE capabilities from the terminal equipment UE or from the source gNB. This prevents a 128-bit algorithm from being selected in an environment where a 256-bit algorithm is available, thereby achieving greater security.
[0042] In this specification, an example in which the first solution is applied to handover will be described as a "first embodiment." In this specification, an example in which the first solution is applied to a dual connection will be described as a "second embodiment."
[0043] [Second solution] The “second solution” is a method to preferentially select the 256-bit algorithm when only some base stations gNBs do not support 256 bits.
[0044] In the "Second Solution", Check if the target gNB supports 256-bit and In case of handover, instruct the terminal device UE to handover only if the target gNB supports 256 bits; In case of dual connectivity, a secondary node shall be added only if the secondary node SN is 256-bit compatible, and bearers terminating only at 256-bit compatible nodes shall be used.
[0045] In this specification, an example in which the second solution is applied to handover will be described as a "third embodiment." In this specification, an example in which the second solution is applied to a dual connection will be described as a "fourth embodiment."
[0046] [First embodiment] An example in which the first solution is applied to handover will be referred to as a first embodiment. It is assumed that all nodes in the RAN support both 128-bit and 256-bit encryption on the air interface. In this case, the terminal device UE and the network NW need to manage the handover in such a way that the initially selected security level is correctly maintained.
[0047] FIG. 5 shows a handover procedure assuming that two priority lists (hereinafter, the "priority list" may be simply referred to as the "list") are prepared in the base station gNB. Consider the case where the connection with the source NG-RAN (or base station gNB) is completed and the already authenticated terminal device UE moves (see step S21 in FIG. 5, where the core network is denoted as CN). The terminal device UE is connected to a first base station gNB (source gNB) and transmits measurement reports (denoted MR). These measurement reports MR include the signal strengths of other gNBs that the terminal device UE can detect. Depending on the radio conditions, the first base station gNB (source gNB) may decide to hand over the terminal device UE to a second base station gNB (target gNB) (step S24 in FIG. 5).
[0048] When it is decided to perform handover, the first base station gNB (source gNB) sends a handover request message to the second base station gNB (target gNB) (step S25 in FIG. 5). The handover request message includes the following information: (1) Source gNB Identifier (2) Cause of handover (3) Target cell ID from UE measurement report (4) GUAMI (Globally Unique AMF Identifier) of the terminal device UE (5) The security capabilities of the terminal device UE stored in the first base station gNB and the currently used security algorithms
[0049] In step S26, if the target gNB accepts the handover, it sends a handover confirm message (step S27 in FIG. 5). This message includes the following information: (1) Source gNB Identifier (2) Target gNB identifier (3) PDU Session Admit List (4) An RRC container including the selected security algorithm (the RRC container is sent to the terminal device UE)
[0050] In this embodiment, the target gNB selects a security algorithm from the security capabilities of the terminal device UE received from the source gNB in step S25 of Fig. 5 (step S26). The target gNB selects the algorithm with the highest priority from the list of algorithms stored locally.
[0051] If the 256-bit algorithm is added to the existing list, the priority of the 128-bit algorithm and the 256-bit algorithm cannot be distinguished, and the base station gNB cannot support prioritization by key length. Therefore, in addition to the existing list, a separate list that describes the priority of the 256-bit algorithm is introduced.
[0052] The first embodiment differs from the prior art in that the target gNB in step S26 has two priority lists: a priority list listing the priorities of 128-bit algorithms, and a priority list listing the priorities of 256-bit algorithms. In step S26, the target gNB first determines which of the two priority lists to use. The logic for determining which of the two priority lists to use is referred to as "logic L2."
[0053] The logic that determines which algorithm to use using the priority list determined by logic L2 is called "logic L1." The difference between the use of logic in the conventional technology and in the first embodiment will be explained later with reference to FIG.
[0054] There are four possible configuration methods for the logic L2. Here, only the names of the four configuration methods are listed, and the details of each configuration method will be described later. (1) Realization of L2 through configuration within the target gNB (2) Realization of L2 through security policies (3) L2 implementation based on algorithms selected by the source gNB and security functions of the terminal device UE (4) L2 is realized by the algorithm selected by the source gNB and the policy of the SMF (session management function).
[0055] In this embodiment, if the algorithm selected at the target gNB is different from the algorithm selected at the source gNB, in step S27 the target NG-RAN sends a handover command message to the source NG-RAN indicating the selected algorithm from the 256-bit security capability list. This message is included in the RRC container and is omitted if the algorithm selected at the target gNB is the same as the algorithm selected at the source gNB. This message is forwarded by the source gNB to the terminal device UE in step S28, which derives a new key in step S29. In step S30, the handover is completed and the terminal device UE is connected to the target gNB.
[0056] FIG. 6 shows the difference between a base station gNB configured by the conventional technology (FIG. 6(a)) and a base station gNB equipped with two lists of the first embodiment (FIG. 6(b)). 601 is a priority list held by the base station gNB of the conventional technology. 602 and 603 are priority lists held by the base station gNB of the first embodiment. In the conventional technology of FIG. 6(a), the base station gNB has one list of algorithms. When the base station gNB receives the security function of the terminal device UE (hereinafter, abbreviated as "UE function"), it executes logic L1 to confirm the UE security function with the highest priority (256-NEA1 in FIG. 6(a)) from the algorithms listed in the list. Next, the base station gNB selects the algorithm as the algorithm to be used in the session with the terminal device UE (L1 in FIG. 6(a)). In the current specification, logic L1 may be executed twice for the tamper detection algorithm and the encryption algorithm.
[0057] Figure 6(b) shows a base station gNB configured with two lists of security algorithms. In this example, the first list 602 is a list of 128-bit encryption algorithms and the second list 603 is a list of 256-bit encryption algorithms. However, other implementation methods are possible, for example the first list could be a list of symmetric key encryption algorithms and the second list a list of public key encryption algorithms. Alternatively, the first list could be a list of authentication encryption algorithms and the second list a list of only encryption algorithms (not authentication encryption). The operation of the logic L1 in FIG. 6(b) is the same as the operation of the logic L1 in FIG. 6(a).
[0058] More than two lists may be needed if future base stations gNBs support 128, 256 and 512 symmetric cryptographic algorithms, in which case steps L2 and L1 may be repeated for each set of cryptographic and tamper detection algorithms, as is common in mobile networks today.
[0059] In Fig. 6(b), there are several possibilities how the base station gNB can execute logic L2 and L1. The purpose of logic L2 is to decide which list the base station gNB should select based on some information it receives. In FIG. 5, after it is decided to perform handover in step S24, the following methods (1) to (4) are possible as a method of implementing logic L2, as described above.
[0060] (1) Realization of L2 through configuration within the target gNB: The target gNB is configured to always prioritize 256 bits (second list) over 128 bits (first list) by a static policy set in the base station gNB. This method is easy to implement and easy to deduce how it works. However, in handovers involving legacy gNBs that only support 128-bit algorithms, the encryption strength may change before and after the handover.
[0061] (2) L2 implementation via security policy: The base station gNB enables security functions according to a security policy from the SMF (session management function), but extends the security policy to include a flag indicating whether the 128-bit algorithm or the 256-bit algorithm is to be prioritized. The base station gNB selects the 128-bit or 256-bit algorithm based on the received security policy. In this method, the carrier can set a policy for each subscriber, so that the 256-bit algorithm can be set to be used when higher security is required, and the 128-bit algorithm can be set to be used for devices with limited processing performance such as IoT devices. In a handover involving a gNB that only supports the 128-bit algorithm, the encryption strength may change before and after the handover.
[0062] (3) L2 implementation based on the algorithm selected by the source gNB and the security functions of the terminal device UE: The target gNB can also implement the L2 logic by selecting the list using both criteria (the algorithm selected by the source gNB and the security capabilities of the terminal device UE). In Figure 5, it works as follows: (A) Select to match the strength of the algorithm of the source gNB. If the source gNB selects an algorithm with a strength corresponding to the first list (128-bit algorithm), the target gNB also selects an algorithm from the first list. However, the algorithms may be different. For example, if the source gNB supports only 128-bit algorithms 128-NEA1 and the target gNB supports only algorithms 128-NEA2, the first lists of both gNBs will be different, but the target gNB will select an algorithm from the first list.
[0063] (a) Select according to UE functions. The base station gNB can only select algorithms that fit the UE capabilities. It is expected that all terminal equipment UEs support all 128-bit and 256-bit algorithms, but the base station gNB must also check whether the algorithm selected in the previous step is supported. Corresponding to the above example, if the terminal equipment UE supports 128-NEA1, 256-NEA4, and 256-NEA6, the target gNB cannot select 128-NEA2 even if the source gNB selected 128-NEA1. In this case, the target gNB must select the second list.
[0064] (4) L2 implementation based on the algorithm selected by the source gNB and the policy of the SMF (session management function): In case of handover from a source gNB that only supports 128 bits, the above approach provides a lower level of security than it could provide. To avoid this, the SMF needs to send a 256-bit indication to the target gNB. Alternatively, the AMF may send a 256-bit indication. This works as follows:
[0065] (a) The target gNB receives a handover request from the source gNB, including the security functions of the terminal device UE. (i) The target gNB requests the AMF to provide security functionality for the terminal device UE. (c) The AMF includes a flag indicating whether or not 256-bit is used in the UE security function and sets this flag to “Yes” to indicate to the target gNB that this terminal device UE uses 256-bit security. (E) The target gNB selects the second list and compares it with the security capabilities of the terminal device UE to select an algorithm with a high priority from the list.
[0066] [Second embodiment] The second embodiment is an example in which the first solution is applied to dual connectivity. In the second embodiment, it is assumed that most nodes in the RAN support both 128-bit and 256-bit encryption over the air interface. When the base station gNB to which the terminal device UE is connected decides to add a secondary node SN, the master node MN needs to select a secondary node SN that provides the same functions as the base station gNB to which the terminal device UE is currently connected. To do this, it is necessary to modify the procedure for adding a secondary node shown in Figure 3. The modification will be described with reference to Figure 3.
[0067] It is assumed that the terminal device UE is connected to a base station gNB(MN) that supports both 256-bit and 128-bit algorithms. The base station gNB (MN and SN) stores a first list and a second list, and has two logics for determining which algorithm to select. An example will be described in which the base station gNB(MN) first selects the 256-bit algorithm. Fig. 3 is an operation flow diagram of dual connection of the conventional technology, but can also be used as an operation flow diagram of the second embodiment. However, while the master node MN and the secondary node SN in the conventional technology have only one priority list, the master node MN and the secondary node SN in the second embodiment each have two priority lists. Therefore, the information contained in each message transmitted is different between the conventional technology and the second embodiment. In addition, the contents of the processing in the master node MN and the secondary node SN are also different between the conventional technology and the second embodiment.
[0068] For example, in the second embodiment, the message transmitted by the master node MN in step S1 can include information on which of the two priority lists the master node MN selected the algorithm from. However, in the conventional technology, such information is not included in the message transmitted in step S1. Also, in the second embodiment, in step S2, the secondary node SN executes the logic L2 described above to decide which of the two priority lists to use, whereas in the prior art, this is not done.
[0069] Furthermore, in the second embodiment, the message transmitted by the secondary node SN in step S3 can include information on whether the priority list used by the master node MN when selecting an algorithm is the same as the priority list used by the secondary node SN when selecting an algorithm, but this is not done in the conventional technology. As described above, the operation flow diagram is the same in FIG. 3 for both the conventional technology and the second embodiment, but the information contained in each message and the processing content at each step are different between the conventional technology and the second embodiment.
[0070] In step S1, the master node MN decides to add a secondary node SN and transmits an SN addition request message. The master node MN includes the selected algorithm in the message. The master node MN may also indicate which list the algorithm was selected from. It may also indicate the strength and function of the algorithm. For example, if there are three lists of 128-bit algorithms, 256-bit algorithms, and AEAD algorithms, the base station gNB(MN) may instruct which list (e.g., list 1, list 2, or list 3) should be selected, or may give instructions such as "encryption: 256-bit, tamper detection: 256-bit" and "AEAD: yes."
[0071] In step S2, the secondary node SN approves or rejects the request. In addition, the secondary node SN executes logic L2 to check which algorithm or which list the master node MN selected and selects the appropriate list. The secondary node SN then selects the algorithm from the list that has the highest priority and is supported by the terminal device UE. If no corresponding algorithm is found, the secondary node SN · Select an algorithm from the other list. Deny the request. Either of the above may be performed.
[0072] The secondary node SN then sends a message in step S3 which, in addition to the above, includes an indicator of whether the secondary node SN selected an algorithm from the same list. Alternatively, the secondary node SN may omit the indicator. In that case, the master node MN checks the RRC container in the next step S4.
[0073] In step S4, the master node MN checks whether the received message is a confirmation message, and checks the contents of the message as well as whether an algorithm of the same strength has been selected by one of the following methods. Check if the indicator is set. Check the selected algorithm and ensure that it is also in the masternode MN’s selected list. Check the strength of the algorithm through the list of configured algorithms and strengths.
[0074] If the master node MN determines that the correct algorithm has been selected, it forwards the RRC container unchanged to the terminal device UE and transmits it as an MN RRC reconfiguration message in step S5. If the algorithm selection is incorrect, the procedure ends, unless there is a security policy allowing mixed strength connections or the master node MN terminates the traffic, in which case the procedure may continue.
[0075] In step S6, when the terminal device UE receives the RRC container, it checks whether it can support reconfiguration, derives the necessary RRC key and UP key, and enables the security algorithm of the secondary node SN. The terminal device UE can also execute additional logic to use the two lists to determine whether the selected algorithms match in strength. For example, the terminal device UE executes the following algorithms (A) to (C) to determine whether the selected algorithms match in strength. (A) The algorithm used in MN is logic L11 that determines the selected list (a) Logic L12 that determines the list selected by the algorithm selected by SN (c) Logic L13 that determines whether the two lists determined in (a) and (b) above are the same.
[0076] Similarly, logic L11 and L12 can be used to determine the strength of the algorithms from a preconfigured list. Logic L13 determines if the strengths are the same. The advantage of this approach is that it allows the comparison of the strengths of a mix of AEAD and cryptographic-only algorithms.
[0077] Alternatively, the logic L13 can take a security policy into account. If the security policy set in the terminal device UE allows different algorithm strengths, the logic L13 allows the secondary node SN and the master node MN to select different algorithms. By setting the security policy such that the secondary node SN selects a security level equal to or higher than that of the master node MN, it is possible for the secondary node SN to select a 256-bit algorithm even if the master node MN selects a 128-bit algorithm.
[0078] If the result of logic L13 is NG, the terminal device UE can reject the addition of the secondary node SN. If the addition of the secondary node SN is rejected, an SN response message is created in step S6 and inserted into the MN RRC reconfiguration complete message, which is the message to be transmitted in step S7. If the terminal device UE rejects the addition of the SN, it indicates rejection due to a mismatch in security algorithms.
[0079] In step S8, if the terminal device UE does not reject the SN addition, the master node MN develops an SN RRC reconfiguration complete message and forwards it to the secondary node SN as a message in step S9. If the terminal device UE rejects the SN addition, the master node MN ends the procedure.
[0080] In step S10, the secondary node SN enables security according to a previously selected algorithm, and in step S11, the terminal device UE initiates a random access procedure to establish a connection with the secondary node SN.
[0081] [Third embodiment] An example in which the second solution is applied to handover is referred to as a third embodiment. The key point of this solution is to perform handover only to a base station gNB that supports 256 bits, i.e. to manage the terminal device UE so that it is handed over only to a base station gNB that supports 256 bits.
[0082] This solution is based on the premise that there exists a mixture of base stations gNBs that are compatible only with 128-bit encryption algorithms and base stations gNBs that are compatible with both 128-bit and 256-bit encryption algorithms. It is assumed that some base stations gNBs have only the first list (or two, if encryption algorithms and tamper detection algorithms are counted separately), and other base stations gNBs have a mixture of the first list and the second list (or four, if encryption algorithms and tamper detection algorithms are counted separately). In this case, the base station gNB manages handover so that the terminal device UE is handed over only to base stations gNBs compatible with 256 bits, thereby connecting the terminal device UE to a base station gNB compatible with both 128 bits and 256 bits.
[0083] 1) Static configuration at the base station gNB One way to achieve this would be to use a list like the one shown in Table 1. [Table 1] In TS38.413, the cell ID is specified and it is defined that a single base station gNB may contain multiple cell IDs, therefore the list of base stations gNBs can be compressed by including only the neighboring base stations gNBs instead of the complete cell IDs listed in the table above.
[0084] A base station gNB that holds such a list operates according to the following procedure. (1) The base station gNB receives a measurement report from the terminal device UE. (2) When the base station gNB determines that a handover is necessary, it checks whether the base station gNB is connected using a 256-bit security algorithm or whether the 256-bit security presence / absence flag in the policy received from the SMF (session management function) is set to “Yes”. (3) If support for the 256-bit algorithm is confirmed, the base station gNB examines the measurement report, selects the best base station gNB included in the neighboring base stations gNBs that support 256 bits, and attempts handover to the base station gNB that supports 256 bits. (4) If confirmation is not possible in (2) above, the base station gNB will follow normal logic and perform a handover to the base station gNB with the best signal.
[0085] 2) Changes to the handover process Here, we propose a handover procedure that allows the base station gNB to check the support of the handover destination base station gNB. The procedure is explained using Figure 5. In step S25, the source gNB queries one or more base stations gNBs (target gNBs) to confirm whether handover is possible. Next, when the message of step S27 is returned, the source gNB checks the RRC container of the message and checks the security algorithm. Based on the selected security algorithm, the source gNB decides whether to continue or abort the handover. If the source gNB aborts the handover, it attempts a handover to another base station gNB. Thus, when the source gNB receives the message of step S27, the source gNB operates to handover only to a target base station gNB that supports 256 bits, which is different from the conventional technology. The decision to continue the handover will be based on the following:
[0086] If the terminal device UE is connecting using a 256-bit algorithm and the target gNB selects the 256-bit algorithm, or If the terminal device UE is connecting using a 128-bit algorithm, if the target gNB selects the 128-bit algorithm, Continue the handover.
[0087] [Fourth embodiment] The fourth embodiment is an example in which the second solution is applied to dual connectivity. In the fourth embodiment, a secondary node is added only if the secondary node SN is 256-bit compatible. In the fourth embodiment, similarly to the third embodiment, two types of realization methods are possible. In the first implementation method, the master node MN holds in advance a table indicating whether each adjacent node is compatible with 256 bits or not, and attempts dual connection only to nodes that are compatible with 256 bits.
[0088] The second realization method is, for example, to execute the following steps (A) to (D). (a) The master node MN sends a message to an adjacent node requesting that it add a secondary node SN. (a) The node that receives the message (1) above selects a security algorithm. (c) The node that receives the message (1) above includes information indicating the selected security algorithm in a message and transmits it to the master node MN. (d) The master node MN checks the security algorithm selected by the node receiving the message in (1) above, and if it is a 256-bit algorithm, it continues processing. If it is not a 256-bit algorithm, it stops processing.
[0089] In the first and second embodiments in which the "first solution" is applied, the base station gNB is provided with two priority lists with different strengths. In response to this, it is also possible to adopt a variant of the "first solution" (i.e., a variant of the first embodiment and a variant of the second embodiment) in which one table of attributes for multiple algorithms is prepared, and a table for use by logic L1 is created based on the execution result of logic L2.
[0090] As implementation forms of the modified example, two implementation examples (hereinafter, a "first implementation example" and a "second implementation example") can be given. First, the first implementation example will be described. The first implementation example is a table of security algorithms, with the following (a) to (c) provided as attributes. (A) Whether the algorithm is supported (a) The "list" to which the algorithm belongs (List 1 and List 2 have different strengths) (c) Priority of algorithms in each list
[0091] Table 2 shows the first implementation example. [Table 2]
[0092] The first implementation example of Table 2 shows algorithms A1 to A6, with priority given to each list. In this implementation, logic L2 first selects which rows in the table are relevant based on the execution result. For example, if the execution result of logic L2 is to use list 1, it selects rows A1 and A5. It then passes the selected rows to logic L1. From the received rows, logic L1 selects an algorithm that matches the security capabilities of the terminal device UE.
[0093] Next, a second implementation example will be described below. In the second implementation example, the following (A) to (D) are provided as attributes. (A) Whether the algorithm is supported (a) Type (classification of encryption algorithm, tamper detection algorithm, and AEAD algorithm) (c) Bit strength (D) Priority by type and bit strength
[0094] Table 3 shows a second implementation example. [Table 3]
[0095] First, the type is determined. Then, depending on the result of the execution of logic L2, the bit strength is determined. Then, it is selected which rows in the table are relevant. For example, if the type is encryption and the bit strength is 256 bits, then the rows A2 and A4 are selected. Then, the selected rows are passed to logic L1 to select an algorithm that matches the security capabilities of the terminal device UE.
[0096] Furthermore, it is obvious that when there is a list of 128-bit encryption algorithms and a list of 128-bit tamper detection algorithms, it is also possible to realize the priority list by adding a string of 256-bit encryption algorithms and a string of 256-bit tamper detection algorithms, respectively. For example, it is expanded as shown below.
[0097] Suppose the list of encryption algorithms is shown in Table 4 and the list of tamper detection algorithms is shown in Table 5. [Table 4] [Table 5]
[0098] Here, E represents the encryption, A represents the algorithm, and 1 to 3 are the identifiers of each algorithm. If EA1 to EA3 and IA1 to IA3 are all 128-bit algorithms, then by adding EA4 to EA6 as 256-bit encryption algorithms and IA4 to IA6 as 256-bit tamper detection algorithms, the list can be expanded as shown in Tables 6 and 7 below. [Table 6] [Table 7]
[0099] Logic L2 decides which column to select, and logic L1 decides which algorithm to select.
[0100] This invention enables the target base station and secondary node to select the appropriate encryption algorithm, making it possible to contribute to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), which is to "build resilient infrastructure, promote sustainable industrialization and foster innovation." [Explanation of symbols]
[0101] 601~603 Priority List
Claims
1. A base station having a plurality of priority lists with different strengths for encryption algorithms and / or tamper detection algorithms, A base station having a function of determining which of the multiple priority lists to use to select an encryption algorithm and / or a tamper detection algorithm when receiving a security function of a terminal device from a terminal device or a source base station as a target base station during handover.
2. The base station according to claim 1 , wherein the target base station selects a priority list having a stronger strength from among the plurality of priority lists.
3. The base station according to claim 1, wherein the target base station determines which of the multiple priority lists to use to select an encryption algorithm and / or a tamper detection algorithm based on a security policy received from the SMF.
4. The base station of claim 1, wherein the target base station determines which of the multiple priority lists to use to select an encryption algorithm and / or a tamper detection algorithm based on the algorithm selected by the source base station and the security capabilities of the terminal device.
5. The base station according to claim 1, wherein the target base station determines which of the multiple priority lists to use to select an encryption algorithm and / or a tamper detection algorithm based on the algorithm selected by the source base station and a security policy received from the SMF.
6. A base station having a plurality of priority lists with different strengths for encryption algorithms and / or tamper detection algorithms, A base station having a function of determining, as a secondary node of a dual connection, which of the multiple priority lists to use to select an encryption algorithm and / or a tamper detection algorithm based on the algorithm or priority list selected by the master node.
7. A terminal device that uses a base station having a plurality of priority lists with different strengths for encryption algorithms and / or tamper detection algorithms as a master node and a secondary node during dual connection, A terminal device that rejects the addition of a secondary node when the priority list in which the algorithm used in the master node is selected is not the same as the priority list in which the algorithm selected in the secondary node is selected.
8. A base station having a plurality of priority lists with different strengths for encryption algorithms and / or tamper detection algorithms, A base station that, as a source base station during handover, manages handover of a terminal device to an adjacent base station compatible with the strongest encryption algorithm and / or tamper detection algorithm.
9. A base station having a plurality of priority lists with different strengths for encryption algorithms and / or tamper detection algorithms, A base station that adds only a base station compatible with the strongest encryption algorithm and / or tamper detection algorithm as a secondary node as a dual-connection master node.