Device for notifying length of message authentication code

By incorporating MAC length data into messages and using ABBA parameters, the 3GPP specifications address the lack of MAC length negotiation, enabling secure use of longer MAC lengths and enhancing security between terminal devices and networks.

JP2025073480APending Publication Date: 2025-05-13KDDI CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023184322
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-10-26
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

Conventional 3GPP specifications lack a defined method for negotiating the length of message authentication codes (MAC) between terminal devices and networks, leading to compatibility issues when longer MAC lengths are required for enhanced security.

Method used

Incorporating data indicating the supported MAC length into messages exchanged between network devices and terminal devices, using ABBA parameters to specify the MAC length and algorithm, and enabling terminal devices to reject insecure security mode commands.

Benefits of technology

Enables secure negotiation and use of longer MAC lengths between terminal devices and networks, enhancing security against tampering and ensuring compatibility between devices and infrastructure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025073480000001_ABST
    Figure 2025073480000001_ABST
Patent Text Reader

Abstract

To provide a method for confirming that a message authentication code MAC longer than current 32 bits is supported between a terminal device UE and a network NW.SOLUTION: A message transmitted from a SEAF to a base station gNB in step S10 includes an ABBA parameter. Using the ABBA parameter, a terminal device UE is notified that a network NW side supports a 128-bit MAC. For example, using 4 bits in the ABBA parameter, it is achieved such that "0001: RAN is compatible with the 128-bit MAC " and "0010: AMF is compatible with the 128-bit MAC." By setting the ABBA parameter, the terminal device UE is notified that the RAN or AMF is compatible with the 128-bit MAC.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a technique for extending the message authentication code length in the 3GPP (registered trademark) (Third Generation Partnership Project) specifications and sharing support for a longer message authentication code (MAC) between a terminal device UE and a network NW. [Background technology]

[0002] A terminal device UE (User Equipment) is a mobile communication terminal used by a user, such as a smartphone. When terminal devices UE communicate with each other, they communicate via a mobile communication network such as 5G. This mobile communication network is hereinafter referred to as a "network NW."

[0003] When a terminal device UE and a network NW communicate wirelessly, each transmits an encrypted message. The message is then decrypted on the receiving side. The algorithm used to encrypt the message is called an "encryption algorithm." In addition, there is a risk that a third party may tamper with the message during wireless communication. Therefore, the sender creates a code for tamper detection and attaches the code to the message before sending it. The algorithm for creating the code for tamper detection is called the "tamper detection algorithm." Conventionally, in order to prove that a transmitted message has not been tampered with, the sender calculates a message authentication code (MAC) and attaches the calculated message authentication code to the message to be transmitted. [Prior art documents] [Non-patent literature]

[0004] [Non-Patent Document 1] 3GPP (registered trademark) SA3, TS33.401 [Non-Patent Document 2] 3GPP (registered trademark) SA3, TS33.501 Summary of the Invention [Problem to be solved by the invention]

[0005] Conventionally, a 32-bit message authentication code (MAC) has been used. However, in recent years, there has been a movement to increase the length of the message authentication code (hereafter referred to as "MAC length") in order to provide sufficient security against tampering. However, in the conventional specifications, there is no definition of MAC length negotiation between the terminal device UE and the network NW. For example, if the MAC length is extended to 128 bits on the transmitting side, there is a problem that the receiving side cannot determine how many bits of MAC should be calculated.

[0006] An object of the present invention is to realize a method for confirming, between a terminal device UE and a network NW, that a MAC longer than the current 32 bits is supported. [Means for solving the problem]

[0007] The inventors discovered that data indicating how many bits of a message authentication code the network device supports can be included in a message sent from a network device to a terminal device, and thus completed the present invention.

[0008] (1) A network device that includes data indicating how many bits of a message authentication code the network device supports in a message to be sent from the network device to a terminal device, and transmits the message to the terminal device. (2) The network device of (1) above, which includes data indicating how many bits of a message authentication code the network device supports in an ABBA parameter in a message sent from the network device to a terminal device. (3) The network device according to (2) above, which also specifies a message authentication code algorithm using ABBA parameters. (4) A terminal device that receives a message sent from a network device, the message including data indicating how many bits of a message authentication code the network device supports, and notifies the network device of the security function of the terminal device using a tamper detection algorithm different from the tamper detection algorithm selected by the network device. (5) A terminal device that includes data indicating how many bits of a message authentication code the previously connected AMF supported in the GUTI in an initial connection message sent to a network device. (6) A terminal device that includes data indicating how many bits of a message authentication code the terminal device requests to use in network slice selection assistance information (NSSAI) in a message sent to a base station. (7) A network device according to (1) above, which includes data indicating how many bits of a message authentication code the network device supports in a system information block SIB in a message sent from the network device to a terminal device. (8) A terminal device that rejects an access stratum security mode command when the MAC length of the tamper detection algorithm that it supports does not match the MAC length of the tamper detection algorithm presented in the access stratum security mode command (AS Security Mode Command) message received from the base station. (9) A terminal device that, when presenting its security functions to the AMF, presents the tamper detection algorithms it supports and the MAC lengths it supports separately. (10) A terminal device that receives a message transmitted from the network device of (7) above, which ranks multiple received system information blocks SIBs according to whether or not they support 128-bit MAC, and selects a network node to connect to based on received signal strength and tamper detection strength. Effect of the Invention

[0009] According to the present invention, a network device notifies a terminal device of how many bits of a message authentication code the network device supports, so that negotiation can be performed between the network device and the terminal device regarding the length of the message authentication code to be used. [Brief description of the drawings]

[0010] [Figure 1] FIG. 1 illustrates the use of the tamper detection algorithm NIA to detect message tampering. [Diagram 2] This is a diagram (first half) showing the procedures of authentication, key agreement, and NAS SMC between the terminal device UE and the network NW. [Diagram 3] This is the second half of the diagram showing the procedures of authentication, key agreement, and NAS SMC between the terminal device UE and the network NW. [Figure 4] FIG. 1 illustrates an example of a man-in-the-middle attacker tampering with a message. [Diagram 5] A diagram showing the procedure for selecting a network slice instance. [Figure 6] FIG. 13 is a diagram showing a procedure for selecting a cell. [Figure 7] A diagram showing a terminal device collecting SIBs of base stations that it can receive. [Figure 8] FIG. 11 is a diagram showing an example of the result of a terminal device assigning priorities to base stations. [Figure 9] FIG. 1 illustrates a terminal device sending an attach request to the cell with the strongest signal strength. [Figure 10] FIG. 23 is a diagram showing a cell with a priority level of 1 in the sixth embodiment of the present invention. [Figure 11] FIG. 13 is a schematic diagram of priority allocation in a sixth embodiment of the present invention. [Figure 12] FIG. 13 is a diagram showing negotiation of a tamper detection algorithm and a MAC length. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0011] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. Figure 1 shows the calculation of a message authentication code (MAC) on the sending side and the receiving side. The message authentication code (MAC) is defined as MAC-I in the 3GPP (registered trademark) (Third Generation Partnership Project) specifications, and is used to detect tampering of messages in the Packet Data Convergence Protocol (PDCP) layer. On the sending side, NIA calculates the message authentication code (MAC) using the 128-bit key, 32-bit count, 5-bit bearer, 1-bit direction, and message as input. In the current specification, the MAC length is 32 bits. The sending side transmits the generated message authentication code (MAC) together with the message. On the receiving side, the NIA calculates the message authentication code (MAC) using the received message, 128-bit key, 32-bit count, 5-bit bearer, and 1-bit direction as input. On the receiving side, the NIA compares the received message authentication code (MAC) with the message authentication code (MAC) calculated from the received message, etc. If they match, it can be confirmed that the message has not been tampered with on the way.

[0012] 2 and 3 are a series of diagrams showing the procedures of authentication, key agreement, and NAS (Non-Access-Stratum) SMC (Secure Mode Command) between a terminal device UE and a network NW in the prior art and an embodiment of the present invention. When the terminal device UE is powered on, a random access procedure is performed in step S1, and then an RRC connection procedure is performed in step S2, followed by initial connection and authentication.

[0013] In step S3, the terminal device UE transmits an initial connection message to the base station gNB. The initial connection message includes the security function of the terminal device UE and a Globally Unique Temporary UE Identity (GUTI) or a Subscription Concealed Identifier (SUCI). In step S4, the base station gNB transfers the initial connection message to an Access and Mobility Management Function (AMF) / Security Anchor Functionality (SEAF) of the core network. In step S5, if the initial connection message contains a SUCI or SUPI (Subscription Permanent Identifier), i.e., if the terminal device UE has not yet been authenticated, the AMF / SEAF initiates an authentication procedure with the UDM (Unified Data Management) / AUSF (Authentication Server Function) / ARPF (Authentication credentials Repository Function).

[0014] In step S6, the SEAF sends a Nausf_UEAuthentication_Authenticate Request message to the AUSF. This message includes a SUCI or SUPI. In step S7, the AUSF checks whether the SEAF that sent the request message is allowed to use the service network name. In step S7, the AUSF temporarily stores the received service network name and sends a Nudm_UEAuthentication_Get Request message including the SUCI or SUPI and the service network name to the UDM / ARPF / SIDF (Subscription Identifier De-concealing function).

[0015] In step S7, when the UDM receives the Nudm_UEAuthentication_Get Request message, if a SUCI is received, the UDM calls the SIDF to decrypt the SUCI and obtain a SUPI. In step S7, based on the SUPI, the UDM / ARPF selects whether to use EAP-AKA' or 5G-AKA. In step S7, the UDM / ARPF generates an authentication vector (AV) consisting of (RAND, AUTN, XRES, CK', IK') and sends the authentication vector AV to the AUSF together with the Nudm_UEAuthentication_Get Response.

[0016] If the authentication method is set to 5G-AKA, the AUSF sends a message including an AKA Challenge message to the SEAF in step S8. At this time, the AKA-Challenge message also includes the expected response. The SEAF forwards this to the base station gNB in ​​step S10. The message sent to the base station gNB in ​​step S10 includes an Authentication Request message, which is a NAS (Non-Access-Stratum) message. This Authentication Request message sent in steps S10 and S12 includes an ngKSI (5G system key configuration identifier) ​​and an ABBA parameter set to 0x0000 according to TS 33.501.

[0017] In step S12, the base station gNB forwards the received message to the terminal device UE. In step S13, the terminal device UE calculates a response from the received message and checks whether the AUTN (authentication token) is correct. If the AUTN is correct, in step S14, the terminal device UE sends a message as a response, which the base station gNB forwards to the SEAF in step S16.

[0018] If EAP-AKA' is selected as the authentication method, the SEAF transfers the response received in step S16 to the AUSF in step S18. On the other hand, if 5G-AKA is selected as the authentication method, the SEAF compares the response from the terminal device UE with the hash value of the expected response received from the AUSF in step S8 in step S17, and if they match, transfers the expected response to the AUSF in step S18. In step S19, the AUSF compares the response from the terminal device UE with the expected response, and if there is a match, sends the anchor key KSEAF and SUPI to the SEAF in a Nausf_UEAuthentication_Authenticate Response in step S20.

[0019] In step S21, the SEAF verifies that the AUSF has successfully authenticated the terminal UE. If the terminal UE is successfully authenticated, in step S22, the AMF sends an authentication success message to the terminal UE. In step S21, the AMF creates a NAS message called Secure Mode Command, which contains the security capabilities of the UE, the tamper detection and encryption algorithms selected by the AMF, and possibly the ABBA parameters and the ngKSI. The base station gNB receives the message and forwards the NAS message to the UE in step S24.

[0020] In step S25, the terminal device UE verifies the message using its tamper detection function to verify that the security capabilities of the terminal device UE have not been tampered with. If everything is OK, the terminal device UE sends a Secure Mode Complete message to the AMF via the base station gNB (steps S26 and S27). This Secure Mode Complete message includes the security capabilities of the terminal device UE and the requested NSSAI.

[0021] In step S28, the AMF verifies that the received message can be correctly decoded and has not been tampered with, and in step S29, sends a registration accept message, which includes the allowed NSSAI, the new GUTI assigned to the terminal device UE, and the capabilities supported by the network. The authentication, key agreement, and NAS SMC procedures in the prior art and in the embodiments of the present invention have been described above.

[0022] The present invention uses a conventional message to notify the terminal device UE from the network NW side that the network NW side supports the 128-bit tamper detection algorithm. [First embodiment] Notification of 128-bit MAC support using ABBA parameters The message transmitted from the SEAF to the base station gNB in ​​step S10 in Fig. 2 includes an ABBA parameter. The ABBA parameter is used to notify the terminal device UE that the network NW supports the 128-bit tamper detection algorithm. For example, this can be achieved as follows using 4 bits of the ABBA parameter. 0001: RAN is capable of supporting 128-bit MAC 0010:AMF supports 128-bit MAC

[0023] By setting the ABBA parameters, the terminal device UE is notified that the RAN or AMF is capable of supporting 128-bit MAC. Therefore, the terminal device UE can use the ABBA parameters in step S25 of the procedure in FIG. 3 as follows. 1. If the ABBA parameter is set to 0010 and the terminal device UE is capable of supporting 128-bit MAC, the terminal device UE can check whether the network NW has selected a 128-bit tamper detection algorithm. If the 128-bit tamper detection algorithm is selected, the terminal device UE accepts the message and sends a Secure Mode Complete message protected by the selected algorithm. b. If the 128-bit tamper detection algorithm is not selected, the terminal device UE rejects the Secure Mode Command sent in step S24 and sets a bit in the rejection message indicating that it wishes to use the 128-bit tamper detection algorithm.

[0024] However, there are multiple types of "128-bit MAC security algorithms." If the terminal device UE and the network do not support the same type of 128-bit MAC security algorithm, the AMF may select a 32-bit tamper detection algorithm, which the terminal device UE may reject. This is resolved by the following method.

[0025] (Method 1) By adding a new field to the NAS Secure Mode Command to indicate "128-bit MAC compatible algorithm selection error", the terminal device UE is notified that there is no 128-bit tamper detection algorithm supported by both the AMF and the terminal device UE. If this bit is set, the terminal device UE accepts the 32-bit tamper detection algorithm selected by the AMF. (Method 2) A logic based on the UE security capability sent by the terminal device UE in steps S3 and S4 is added to the SEAF. If the terminal device UE indicates that it supports 128-bit MAC, the SEAF checks whether the network supports the same type of algorithm, and if so, sets the ABBA parameter as described above to indicate that the AMF or RAN supports 128-bit MAC. However, if there is no common algorithm, the SEAF does not set the ABBA parameter, thereby indicating that the 128-bit tamper detection algorithm cannot be selected. If the ABBA parameter is not set, the terminal device UE accepts the 32-bit tamper detection algorithm.

[0026] In this embodiment, it is important for the terminal device UE to confirm that the security functions it sent in step S3 match the security functions it received in step S12, thereby preventing attacks by a man-in-the-middle located between the terminal device UE and the network NW (hereinafter referred to as a "man-in-the-middle attack").

[0027] [Second embodiment] How to specify the 128-bit tamper detection algorithm using the ABBA parameter In addition to the first embodiment, it is also conceivable that the SEAF selects the type of algorithm and notifies the terminal device UE using the ABBA parameters. This will be described with reference to Figs. 2 and 3. The SEAF receives the security capabilities of the UE in the message of step S4, and in step S5, the SEAF checks whether the security capabilities of the UE include a 128-bit tamper detection algorithm. If the UE can use a 128-bit tamper detection algorithm, the SEAF selects the highest priority 128-bit tamper detection algorithm supported by the UE (it can also select a RAN security algorithm).

[0028] Once the SEAF selection is complete, it specifies the selected algorithm in the ABBA parameters. For example, the first byte can be used to specify the algorithm as shown in Table 1. [Table 1] The second byte is set as shown in Table 2. [Table 2]

[0029] SEAF operates as follows: Method 3 or Method 4. (Method 3) The SEAF is configured with a prioritized list of algorithms for the AS and NAS, and uses the same logic that the base stations gNB and AMF use to select the appropriate algorithm. In this case, the SEAF needs to inform the base stations gNB and AMF of the algorithm it has selected, which can be explicitly notified by a new message called "algorithm selected by SEAF". Alternatively, it can be configured that the base stations gNB and AMF check the ABBA parameters and set the selected algorithm. (Method 4) The SEAF sends an "algorithm selection request" including the security capabilities of the terminal device UE to the AMF and the base station gNB, and sets the corresponding bits of the ABBA parameters based on the responses of the AMF and the base station gNB.

[0030] The ABBA parameters are independent of the selected algorithm, so they can be used to select a 256-bit algorithm even if a vulnerability is found in the 128-bit algorithm. Also, if the terminal equipment UE does not support the 256-bit algorithm, the ABBA parameters are not set, so it is possible to connect legacy terminal equipment UE to the network.

[0031] If the ABBA parameter is set, the terminal device UE capable of supporting 128-bit MAC verifies in step S25 that the message received in step S24 indicates the same algorithm. If the same algorithm is not indicated, the terminal device UE rejects the SMC (Secure Mode Command) using an SMC reject message due to an algorithm mismatch. This allows the AMF to know the reason why the terminal device UE rejected the NAS Secure Mode Command sent in step S24.

[0032] [Third embodiment] UE Security Function Exchange If an attacker exists between the terminal device UE and the network NW, an attacker can tamper with messages to select a weaker algorithm, even if both the terminal device UE and the network NW support the 128-bit tampering detection algorithm. An example of an attacker tampering with a message will be described with reference to Figure 4. Figure 4 shows the same flow as Figures 2 and 3, but only shows the NAS message between the terminal device UE and the AMF, and shows the procedure in which a Man-in-the-middle (MITM) (short for Att) tampers with the message. "'" is added to the tampered message.

[0033] The terminal device UE is unauthenticated and sends a registration request or an initial NAS message in message M1, which includes UE security capabilities and other elements. The attacker Att deletes all UE security capabilities except those that can be attacked. For example, if the terminal device UE sends in message M1 that it supports tamper detection algorithms 128-NIA1, 128-NIA2, 128-NIA3, 128-NIA4, 128-NIA5, and 128-NIA6, the attacker Att tampers with message M1 as if it supports only the attackable algorithms among them. For example, if 128-NIA2 is attackable, the attacker Att tampers with the message M1 so that it supports only this tamper detection algorithm. The attacker Att then sends the tamped message 1' to the AMF.

[0034] The AMF responds with a normal authentication request message M2, which the attacker forwards to the terminal UE without modification. The terminal UE processes the authentication request message, verifies its validity, and if valid, creates an authentication response message M3. The attacker forwards the authentication response message to the AMF without modification.

[0035] The AMF then selects an algorithm based on the UE security capabilities received in message M1' modified by the attacker and sends a Secure Mode Command message M4 to the terminal device UE protected with the tamper detection algorithm selected by the attacker Att. Since the SMC message includes the UE security capabilities received in message 1', the attacker takes message M4, replaces the UE security capabilities with those of message M1 and verifies that the MAC matches the message. The modified message is sent to the terminal device UE as message M4'.

[0036] When the terminal UE receives message M4', it verifies that the UE security capabilities are correct and the MAC, and if so, uses the selected encryption and tamper detection algorithms. The terminal UE then creates a Secure Mode Complete message M5, encrypts it with the selected algorithm and protects it with the tamper detection algorithm.

[0037] The attacker checks message M5 and checks whether it contains a UE security function. If it does, the attacker changes the UE security function again, encrypts the message, and ensures that the MAC matches the message. The attacker sends message 5´ to the AMF, which considers the NAS SMC to be complete, and the authentication of the terminal device UE is completed.

[0038] The above attack by the attacker Att can be resolved by following the steps below. 1) securely notifying the terminal device UE that a 128-bit tamper detection algorithm is available in the core network; 2) Notify the AMF of security capabilities without using the selected algorithm. This allows the AMF to verify that the message has not been tampered with by a man-in-the-middle attacker (Att).

[0039] Specifically, follow the steps below. Step 1: In the authentication process, the SEAF uses the ABBA parameter to indicate that the core network supports 128-bit MAC or indicates the algorithms that the core network supports. The SEAF includes the ABBA parameter in the message M2 in FIG. Step 2: In Secure Mode Complete, the terminal UE verifies that the message has not been tampered with, and verifies the received UE security capability. In addition to the selected tamper detection algorithm, the terminal UE adds a MAC of the UE security capability using another tamper detection algorithm. Here, the "algorithm different from the selected tamper detection algorithm" must be an algorithm supported by both the terminal device UE and the network, and may be, for example, Key Derivation Function (KDF) or HMAC-SHA-256.

[0040] When the terminal device UE generates a MAC using the KDF, K NASint_256 Using this key, we can calculate the MAC for the Initial NAS message as follows: UE_Capabilities_Hash = KDF(K NASint_256 , Initial NAS message) Similarly, the MAC for the UE Security Capabilities can be calculated as follows: UE_Capabilities_Hash = KDF(K NASint_256 , UE Security Capabilities) The terminal device UE includes this in a Secure Mode Complete message and sends it to the AMF.

[0041] Step 3: The AMF receives the Secure Mode Complete message and calculates the MAC for the UE security function. If the results match, the AMF can determine that the correct algorithm has been selected. If the results do not match, the AMF reconfigures the NAS security protocol using the newly selected algorithm, sends a NAS Secure Mode Command to the terminal device UE again, and repeats the above process from step 1.

[0042] The key used for the MAC calculation may be any key that can be used by the AMF and the terminal device UE, and the following are assumed. - K, the AMF root key AMF -K NASInt and K NASEnc Session keys such as As long as the terminal device UE and the AMF use the same key, any of these keys may be input into the hash function. According to this embodiment, an attack that causes a 32-bit MAC to be selected can be prevented as follows. Since the ABBA parameters are used as inputs for key derivation, if an attacker tampers with the ABBA parameters, the generated K AMF changes. K AMF With input, K gNB , K NASint , K NASenc Therefore, if the ABBA parameters are tampered with, different keys will be generated between the terminal device UE and the AMF, and connection establishment will fail. In addition to the 32-bit MAC provided in the conventional technology, if the terminal UE supports 128-bit MAC, an additional MAC is provided, so the AMF can determine whether the terminal UE supports 128-bit MAC by checking the additional MAC. The AMF verifies the two MACs and only successfully completes the NAS Secure Mode Command if both verifications are successful. If either one fails, the connection can be terminated or the NAS Secure Mode Command can be re-executed. In this way, if a man in the middle tampers with a message, it can be detected and the attack can be thwarted.

[0043] [Fourth embodiment] How to select 128-bit MAC on wake from idle When the authentication of the terminal device UE is completed, the AMF assigns the 5G GUTI to the terminal device UE. In TS23.501, the 5G GUTI is: <guami>It is defined as <5G-TMSI>, and GUAMI (Globally Unique AMF Identifier) ​​is defined as follows: - <guami> := <mcc> <mnc><AMFリージョンID><AMFセットID><AMFポインタ>

[0044] This GUAMI is used when the authenticated terminal device UE reconnects to the network and continues the session using a set of conventional keys. In FIG. 2, the terminal device UE includes a 5G GUTI in the message of step S3. The GAUMI part of the 5G GUTI is used by the base station gNB to identify the set of AMFs. However, if the base station gNB is not connected to the target AMF (for example, if the AMF does not serve the particular area where the terminal device UE is currently located), the base station gNB selects another AMF from which to obtain the security context from the previous AMF.

[0045] Here, the base station gNB cannot determine whether the terminal device UE previously used a 128-bit tamper detection algorithm (and therefore needs to preferentially connect to an AMF compatible with 128-bit MAC) or whether the terminal device UE used a 32-bit tamper detection algorithm (whether it can connect to an AMF that only supports 32-bit MAC).

[0046] In order for the base station gNB to distinguish this, it can be realized by including the 128-bit MAC support function of AMF in the GUAMI part of GUTI. For example, GUAMI is extended by adding a field indicating the 128-bit MAC support function as follows: - <guami> := <mcc> <mnc><AMFリージョンID><AMFセットID><AMFポインタ><128-bit MAC support> The base station gNB checks the GUAMI and is able to select an AMF that supports 128-bit MAC based on whether the previous AMF supports 128-bit MAC.

[0047] or <guami>Without changing the fields,<AMFセットID> Another method is to classify the AMFs into 32-bit MAC compatible AMFs and 128-bit MAC compatible AMFs. The operator places the 128-bit MAC compatible AMFs in a specific set and sets the set ID value in the base station gNB, so that the base station gNB can select the AMF based on the AMF set ID value even if the region ID is different. By applying this to the entire network, once a terminal device UE is connected to an environment that supports 128-bit MAC, it will always be connected to an AMF that supports 128-bit MAC thereafter.

[0048] [Fifth embodiment] Requesting a 128-bit MAC using NSSAI Another possible method is to use network slice selection assistance information (NSSAI) to notify the base station gNB that the 128-bit tamper detection algorithm will be used. The NSSAI is included in the message transmitted in step S3 in Fig. 2, and the NSSAI consists of up to eight S-NSSAIs. Each S-NSSAI is defined as a combination of SST (Slice / Service Type) and SD (Slice Differentiator). The currently defined SST values ​​are shown in Table 3. [Table 3] The first 127 of the SST are defined by 3GPP, and the remaining 128 values ​​can be set independently by operators. The value of SD can also be set independently by operators. Currently defined slices are related to the type of service the network provides, and no information about security or algorithms is defined.

[0049] However, the slice information is used to select the appropriate AMF, which poses a problem when only some AMFs in the network support the 128-bit tamper detection algorithm. For example, if a terminal device UE capable of supporting 128-bit MAC requests SST4, the terminal device UE cannot use the 128-bit tamper detection algorithm if the AMF that processes SST4 does not support 128-bit MAC. This problem can be solved by defining a new slice, as shown in the example below. Table 4 shows a 128-bit MAC as an example, but any MAC other than 128-bit MAC can be supported. [Table 4]

[0050] A terminal device UE capable of supporting 128-bit MAC can notify the network NW that it prioritizes the use of the 128-bit tamper detection algorithm by including this NSSAI in a connection request. This enables the base station gNB to select an appropriate AMF capable of supporting 128-bit MAC based on slice information. Although the connection request may be altered by a man-in-the-middle attacker, by including slice information in Secure Mode Complete together with the security function of the terminal device UE, it becomes possible to detect tampering using MAC, thereby avoiding the problem of alteration by a man-in-the-middle attacker.

[0051] This embodiment also has the advantage that the home network can check the need for a 128-bit MAC. Figure 5 shows the network slice instance selection procedure. This procedure is typically initiated by the first AMF as part of the registration procedure. The terminal device UE sends the requested NSSAI in both the RRC setup complete and the NAS registration request. The base station gNB uses this information for AMF selection and tentative processing before obtaining the allowed NSSAI.

[0052] The AMF obtains the slice permitted by the user's contract and selects the appropriate network slice instance based on the permitted S-NSSAI, PLMN ID (Public Land Mobile Network ID), etc. in cooperation with the NSSF (Network Slice Selection Function). At this time, a change to another AMF may occur if necessary. For example, if the AMF determines that an AMF capable of supporting 128-bit MAC is required, the AMF can initiate a change to another AMF.

[0053] As shown in Figure 5, in order to confirm the slices permitted by the contract, the AMF sends a slice information request to the UDM (S102). The UDM returns a slice information response indicating the slices permitted by the contract (S103). This feature can be used by the home network to control the use of the 128-bit tamper detection algorithm. For example, if the visited network charges extra for the use of the 128-bit tamper detection algorithm, the home network can deny the roaming UE from using the 128-bit MAC slice. Also, if the operator offers the 128-bit MAC for a fee, the operator can direct the UE to a 32-bit MAC slice if the subscriber does not pay.

[0054] Since a registration request from a terminal device UE can only include eight slices, if the terminal device UE wants to obtain a 128-bit MAC slice or a 32-bit MAC slice and obtain access to five or more slices, it cannot transmit a request including that information. To solve this problem, we consider introducing a virtual 128-bit MAC slice. If the terminal device UE wants to use 128-bit MAC security in the slice requested by the NSSAI, it can notify the network side by requesting this virtual slice. In other words, a terminal device UE that requests a 128-bit MAC indicates a "virtual 128-bit MAC slice" in addition to a normal slice. In this case, the slice table will be as shown in Table 5. [Table 5] This allows the base station gNB to determine whether a 128-bit MAC is required by simply checking one slice identifier.

[0055] [Sixth embodiment] How to notify 128-bit MAC support status using SIB We propose two methods to inform the terminal device UE that the RAN supports 128-bit MAC. The first method modifies the system information block (SIB) to add an indicator for each cell indicating whether it supports 128-bit MAC. The second method uses the PLMN ID, which is a value in the SIB, and a list of PLMNs that support 128-bit MAC to find a match. Either method achieves optimal cell selection by checking 128-bit MAC support in addition to other factors evaluated in the conventional method.

[0056] When selecting a cell, the terminal equipment UE acquires a Master Information Block (MIB), SIB1, and SIB2. The MIB is used by the terminal equipment UE to find an associated SIB. The SIB is system information of a cell acquired by the terminal equipment UE when selecting a cell, and 24 types are defined (SIB1 to SIB24 for 5G), and SIB1 and SIB2 are used when selecting a cell. SIB1 is ultimately used for cell selection, cell access, and SI (System Information) scheduling.

[0057] SIB1 includes cell selection information and scheduling information, which are information related to cell access, and this embodiment is applied to this SIB1. The information related to cell access includes a PLMN ID list, a PLMN ID, a TA code, a cell ID, and a cell state. The cell selection information includes a minimum reception level. The scheduling information includes an SI message type & periodicity, SIB mapping information, and an SI window length required for the terminal device UE to identify other SIBs (from 2 to 9 in the case of LTE, or from SIB2-24 in the case of NR). For PLMN selection, it is assumed that "Operator controlled PLMN Selector with Access Technology" is used. This method is defined in TS23.122 and is performed using information stored locally in the ME (Mobile Equipment) and information stored locally in the USIM. Furthermore, the PLMN ID is composed of the Mobile Country Code (MCC) and the Mobile Network Code (MNC), and similarly, the IMSI is composed of the PLMN ID and the subscriber identifier in the PLMN. The PLMN ID in the IMSI is called the Home PLMN ID or HPLMN ID.

[0058] The ME contains a list of "equivalent PLMNs" that are known to be equivalent to other PLMNs. This list is modified after each round of the Location Information Update procedure, the Routing Area Update procedure, the GPRS Attach procedure, the Tracking Area Update procedure, the EPS Attach procedure and the Registration procedure. Therefore, this list may be modified by the mobile operator to which the UE is currently connected. This list allows the ME to identify and connect to equivalent PLMN IDs. It also uses this information to identify cells with stronger reception and to identify the same PLMN in other radio communications such as GSM, UMTS, LTE and NR. In addition, the USIM may contain a list of "equivalent home PLMNs", which are used to identify PLMNs that the ME has access to and which it can treat as equivalent to a home PLMN ID. The ME selects a home PLMN in preference to other PLMN IDs. The ME uses this file whenever it is available, and treats the order of the PLMN IDs listed as the priority.

[0059] The USIM file may also specify combinations of PLMN IDs and radio access technologies, and is used by the operator to specify which PLMN ID and radio access combinations should be prioritized by the ME. TS23.122 defines the automatic network selection mode procedure as shown in Table 6. [Table 6]

[0060] In this embodiment, a new priority is added based on whether the cell or network supports 128-bit MAC. Cell selection is usually divided into two steps, 1) PLMN ID selection, and 2) the cell with the strongest reception strength within that PLMN ID, as shown in Figure 6. 1. In Fig. 7, the terminal device UE collects all SIBs of base stations gNB that can receive signals. It can also collect SIBs for radio accesses that can be received (gNB for NR, eNB for LTE, NodeB for UMTS, etc.) in the same way. After receiving the SIBs, the terminal device UE performs the following comparison for each SIB: ·Whether the PLMN ID corresponds to the PLMN ID of your IMSI. · If not, whether the PLMN ID is an "Equivalent Home PLMN ID". · Whether it is included in the list of allowed PLMN IDs.

[0061] 2. Depending on the PLMN IDs indicated in the SIB, the terminal device UE assigns priorities to these base stations gNBs. The ones corresponding to the LPMNs with a contract or equivalent HLPMNs are given the highest priority, and the terminal device UE compares the signal strengths and assigns priorities depending on the signal strength. The results of the priority assignment are shown in Table 7 and Figure 8. [Table 7] Here, it is assumed that operator 1 is HPLMN. The terminal device UE sorts the received SIBs 1) according to the ordered list of prioritized PLMN IDs obtained from the storage in the terminal device UE, and 2) according to signal strength within the same PLMN ID.

[0062] 3. According to the instructions received from the different base stations gNB, the terminal device UE sends an attach request to the cell with the strongest signal strength. In the example of Table 7, based on the signal strength, as in Figure 9, the terminal device UE selects to attach to cell 2 of operator 1 and sends an attach request.

[0063] In this embodiment, an extended SIB1 is applied, and information provided to the terminal device UE is added to the conventional network selection mode, which enables the terminal device UE to select a network according to whether the base station gNB supports 32-bit MAC or 128-bit MAC. A new item (1-bit flag) is added to SIB1 to indicate whether the base station gNB supports the 128-bit tamper detection algorithm. It is also possible to add an item indicating the maximum length supported by the base station gNB (e.g., 1: 32 bits, 2: 64 bits, 3: 128 bits). Alternatively, each bit can indicate the supported algorithm or algorithm strength, and the base station gNB can indicate the algorithms it supports by setting the corresponding bit to 1. In either case, the supported MAC length can be notified to the terminal device UE by extending SIB1.

[0064] Below, an example will be shown in which the terminal device UE of this embodiment preferentially selects a base station gNB that supports 128-bit MAC. 1. The terminal device UE collects receivable SIBs from the base station gNB. Receivable radio access (gNB for NR, eNB for LTE, NodeB for UMTS, etc.) can also be collected in the same manner. After receiving the SIBs, the terminal device UE performs the following comparison for each SIB: Whether the PLMN ID corresponds to the PLMN ID of your IMSI If not, whether the PLMN ID is an "Equivalent Home PLMN ID" -Whether it is included in the list of allowed PLMN IDs When checking the PLMN ID, it also checks whether the corresponding base station supports 128-bit MAC, which indicates the priority of each base station.

[0065] 2. Based on the support status of 128-bit MAC indicated in the SIB, the terminal device UE removes all cells that do not support 128-bit MAC. It then assigns a priority to the base stations gNBs of the contracted carrier and compares the signal strength for each received SIB. An example of the result is shown in Table 8. [Table 8]

[0066] Although Table 8 shows only a 128-bit MAC, any MAC length can be accommodated. The terminal device UE sorts the received SIBs according to 1) the order of the prioritized PLMN IDs retrieved from the terminal device UE storage, 2) signal strength, and 3) whether they support 128-bit MAC. In Table 8, the priority of cell 1 of operator 1 is set to 1. Then, cells that do not support 128-bit MAC are removed. For cell 2 of operator 2 in row 4, the PLMN ID is from a different operator, so it may be different from the terminal device UE, but it may have the same PLMN ID subset or may not be a forbidden PLMN ID. And since it supports 128-bit MAC, it remains as an available base station and is prioritized over base stations that do not support 128-bit MAC. FIG. 10 is a diagram showing cell 1 of operator 1 with priority level 1.

[0067] This embodiment is effective for operators who gradually update their base stations gNBs. This makes it possible to deploy 128-bit MAC-compatible base stations gNBs throughout the country without the need to upgrade all base stations gNBs, which is more efficient. In addition, the terminal device UE can search for a base station gNB that supports 128-bit MAC and connect to a network that supports the security function supported by the terminal device UE. Since the base station gNB is expected to continue to support the 32-bit tamper detection algorithm, legacy terminal equipment UE or terminal equipment UE that does not support 128-bit MAC can continue to be used and there is no adverse effect due to this embodiment.

[0068] In this embodiment, the terminal device UE is notified that it supports 128-bit MAC by changing the cell selection method, but as an alternative method, this can be achieved by adding a PLMN ID that supports 128-bit MAC independent of other PLMN IDs. This allows the terminal device UE to search only for PLMN IDs that support 128-bit MAC as necessary, and if a receivable PLMN ID is not found, the terminal device UE selects according to the priority criteria defined in TS23.122. The operator configures a list of PLMN IDs that support 128-bit MAC in a file on the subscriber's USIM. Specifically, with the transition to 128-bit MAC, the operator advertises the "128-bit MAC support" status in each base station that supports 128-bit MAC using the PLMN ID list. The terminal device UE uses this list to prioritize the PLMN IDs.

[0069] The list of home PLMN IDs or equivalent home PLMN IDs shall be called "File 1". A new file (hereinafter "File 2") containing a list of PLMN IDs corresponding to 128-bit MACs is created. This File 2 is provisioned on the USIM by the contracted operator and is updated periodically. When performing cell selection, the terminal device UE performs the following steps:

[0070] 1. The terminal device UE reads file 1 and file 2 from the USIM. 2. The terminal device UE receives the SIB broadcast and creates a list of "available PLMN IDs". 3. The terminal UE selects an "available PLMN ID" from the Home PLMN ID or a list of equivalent Home PLMN IDs (file 1) as defined in the prior art. 4. The terminal device UE checks whether each PLMN ID in the available PLMN ID list is included in the 128-bit MAC compatible PLMN ID list (file 2). 5. The terminal device UE prioritizes the PLMN IDs in the "Available PLMN IDs" list depending on whether they support 128-bit MAC support. 6. After creating the prioritized PLMN ID list, the UE selects a cell to connect to based on the highest priority PLMN ID and the cell's signal strength. Figure 11 shows the flow of operations.

[0071] Below is an example showing how the method works. (1) The terminal device UE receives a list of PLMN IDs from the base station gNB and creates a list of available PLMN IDs. It is assumed that the list of available PLMN IDs created is as follows: 1.440 15 2.440 16 3.440 27 4.440 29 5.440 43 6.440 48 7.440 49 8.440 51 9.440 52 10.440 79 In this example, it is assumed that the UE's Home PLMN ID is 440 43 and the equivalent Home PLMN IDs are 440 15, 440 16, 440 43, 440 48, 440 49, 440 51, 440 52. For convenience, this list is written in Mobile Network Code (MNC) order, although this need not be the case in an actual implementation.

[0072] (2) In step 2, the terminal device UE filters the "Available PLMN ID" list according to whether it is a home PLMN ID or not based on the input of file 1. If the home PLMN ID is present in the list, the terminal device UE proceeds to step (2-a). (2-a) The terminal device UE uses file 2, which is a list of PLMN IDs that support 128-bit MAC, and if the found home PLMN ID (440 43) supports 128-bit MAC, assigns this PLMN ID priority 1. File 2 indicating that the home PLMN supports 128-bit MAC looks like this: 1.440 43 2.440 48 3.440 49 4.440 51 PLMN ID 440 43 is assigned priority 1 and written to a file or in-memory list. If the HPLMN is not found in file 2, it is assigned priority 3 to the same list / in-memory file.

[0073] (3) In the next step 3, the terminal device UE goes back to the list of available PLMN IDs and selects PLMN IDs included in the equivalent home PLMN ID list available in file 1. In this example, the selection results are 440 15, 440 16, 440 43, 440 48, 440 49, 440 51, 440 52. For each PLMN ID included in the "available PLMN IDs" and file 1, the terminal device UE performs step (3-a).

[0074] (3-a) The terminal device UE uses file 2 in the same manner as in step 2 to check whether the PLMN ID supports 128-bit MAC. If the PLMN ID supports 128-bit MAC, priority 2 is assigned and the PLMN ID is written to memory together with the priority. As an example, priority 2 is assigned to the following PLMN ID: 440 48 440 49 440 51 If the PLMN ID is not listed in file 2, assign it priority 4. As an example, assign priority 4 to the following PLMN IDs: 440 15 440 16 440 51

[0075] (4) If the terminal device UE does not find the Home PLMN ID or any PLMN ID included in the equivalent Home PLMN ID list, the terminal device UE selects a PLMN ID from the "Available PLMN IDs". In the prior art, the terminal device UE checks whether there is an "Operator Controlled PLMN Selector with Access Technology" file on the SIM card, and checks whether each PLMN ID is included in the file.

[0076] The terminal device UE assigns a priority to each PLMN ID using logic similar to (2-a) and (3-a), that is, assigning a priority of 5 to PLMN IDs included in the 128-bit MAC compatible PLMN ID list and a priority of 6 to PLMN IDs not included in the list. However, this logic is applied only if the terminal device UE finds a PLMN ID included in the "Operator Controlled PLMN Selector with Access Technology" file.

[0077] If no HPLMN ID was found in step 3, the terminal UE may have multiple PLMN IDs with priority 3 or 4. For example, the terminal UE may find four PLMN IDs with priority 3 and three with priority 4. In this case, the terminal UE can use the same logic as a terminal UE that does not support 128-bit MAC to determine which PLMN to connect to. Since the order of the PLMN IDs in the equivalent HPLMN ID list (file 1) indicates the priority, the terminal UE will try to connect to the PLMN in the list with the highest priority of priority 3 in file 1, and if unsuccessful, will move on to the next PLMN.

[0078] A similar logic can be applied in step 4: for a list of PLMN IDs with priority 5, the UE will first try to connect to the PLMN with the highest priority in the "Operator Controlled PLMN Selector with Access Technology" file. If it is not included in the list, the UE will randomly select one and try to connect to it.

[0079] The advantage of this approach is that the operator can provision the USIM with the "Operator Controlled PLMN Selector with Access Technology" and "Equivalent HPLMN" list that are optimal for UEs that do not support 128-bit MAC. By adding PLMN ID files that support 128-bit MAC, the operator can change the priority order in which the UE selects the PLMN ID. For example, assume that the operator configures the equivalent home PLMN ID list as shown in Table 9. [Table 9] Table 10 shows PLMN IDs that support 128-bit MAC, with the order of display indicating the priority. [Table 10]

[0080] In this case, a terminal device UE that does not support 128-bit MAC attempts to connect to PLMN IDs in the order of the equivalent home PLMN ID list, and a terminal device UE that supports 128-bit MAC prioritizes PLMN IDs as shown in Table 11. [Table 11]

[0081] Table 11 shows that PLMN IDs that support 128-bit MAC (43, 48, 49, 51) are assigned priority 3 and are listed in the order of their appearance in the list of equivalent HPLMNs, while PLMN IDs that only support 32-bit MAC are assigned priority 4 and are also listed in the order of their appearance in the list of equivalent HPLMNs (52, 15, 16). A similar logic applies in roaming scenarios, where the "Operator Controlled list with Access Technologies" is used instead of the equivalent HPLMN ID list, with the 128-bit MAC-enabled PLMN ID remaining unchanged.

[0082] Finally, it may be possible that no base station supporting a 128-bit MAC can be found, such as in the case of Table 12. Table 11 lists a 128-bit MAC as an example, but is applicable to any MAC length. [Table 12] In the case of Table 12, fallback occurs and the priority is updated according to the order of prioritized PLMN IDs retrieved from the storage in the terminal device UE, and then according to the signal strength. In addition, if an operator adds a base station that supports 128-bit MAC but does not assign an independent PLMN ID (when a single PLMN ID contains a mixture of base stations gNBs that support 32-bit MAC and 128-bit MAC), it becomes difficult to distinguish them. Even in such cases, it is possible to deal with the problem by extending the SIB (e-SIB) and adding a PLMN ID file that supports 128-bit MAC, and this can be applied according to the operator's deployment plan.

[0083] In case of roaming, the terminal UE has a list of forbidden PLMN IDs, which it records if a connection attempt is rejected. In that case, the PLMN ID in question is added to the "forbidden PLMN ID" list. Similarly, in a roaming scenario, the terminal UE can record which PLMN IDs were 128-bit MAC compatible and records these PLMN IDs in the terminal UE memory as a "128-bit MAC compatible PLMN ID" list. The terminal UE erases this list at the appropriate time, e.g. after a certain time has elapsed, after being switched off or after reconnecting to the home PLMN.

[0084] [Seventh embodiment] Selection by terminal device UE During the security activation process of the terminal device UE, the base station gNB sends an AS Security Mode Command indicating the security algorithm to be used between the terminal device UE and the base station gNB. When the terminal device UE receives the Security Mode Command message, it verifies the MAC-I. If the verification is successful, the terminal device UE decrypts the message.

[0085] The terminal device UE checks whether the algorithm indicated in the Security Mode Command (SMC) is a 128-bit tamper detection algorithm. If the terminal device UE supports the 128-bit tamper detection algorithm but the algorithm indicated in the SMC is a 32-bit MAC, the terminal device UE rejects the AS SMC and restarts the process. The terminal device UE notifies the base station gNB of the reason for the rejection by transmitting an error code indicating "algorithm mismatch" or "128-bit tamper detection algorithm required." If the base station gNB can select the 128-bit tamper detection algorithm after receiving the error code, it transmits a new AS SMC message.

[0086] In the first and second embodiments, the terminal equipment UE may receive a notification indicating that the RAN supports a 128-bit tamper detection algorithm. If the terminal equipment UE receives a notification indicating that the RAN supports a 128-bit tamper detection algorithm but the AS SMC specifies a 32-bit tamper detection algorithm, it is desirable for the terminal equipment UE to reject the AS SMC. In this case, the terminal equipment UE is notified by the ABBA parameter that the network device supports a 128-bit tamper detection algorithm, and a mismatch occurs with the 32-bit tamper detection algorithm selected by the RAN.

[0087] Another case in which the terminal device UE rejects AS SMC is when the NAS SMC specifies a 128-bit tamper detection algorithm, but the base station gNB selects a 32-bit tamper detection algorithm. If there is a difference in the security level of the tamper detection algorithm, the terminal device UE rejects AS SMC with a "128-bit compatible tamper detection algorithm selection error" and then performs AS SMC again.

[0088] As in the first embodiment, the base station gNB can indicate to the terminal device UE that there is a mismatch between the terminal device UE and the base station gNB in ​​support of the 128-bit tamper detection algorithm. The base station gNB executes the following method 5.

[0089] (Method 5) By adding a new field to the AS Secure Mode Command to indicate a "128-bit compatible tamper detection algorithm selection error", the base station gNB notifies the terminal device UE that there is no 128-bit tamper detection algorithm supported by both the base station gNB and the terminal device UE. If the bit in this field is set, the terminal device UE accepts the 32-bit tamper detection algorithm selected by the base station gNB.

[0090] Also, the terminal device UE may resend the attach request and the network NW may re-perform authentication and key agreement, in which case new NAS SMC and AS SMC are generated. It is also possible to send connection requests to specific PLMN IDs to check whether they support the required algorithm, and it is also possible to keep a list of PLMN IDs that do not support the 128-bit tamper detection algorithm as a file and lower the priority of those PLMN IDs.

[0091] [Eighth embodiment] Independent selection of tamper detection algorithm and MAC length In the prior art, the terminal device UE and the network NW negotiate to select the tamper detection algorithm to be used for AS and NAS security. The available algorithm options (i.e., NIA1, NIA2, NIA3) all generate a MAC with a length of 32 bits, so the selection of the tamper detection algorithm also determines the MAC length to be used.

[0092] Figure 12 shows the negotiation of the falsification detection algorithm and the MAC length. If the falsification detection algorithm can generate MACs of different lengths, as shown on the right side of Figure 12, it becomes possible to select the algorithm to be used and the MAC length. In the following, we assume that the falsification detection algorithm can support multiple MAC lengths based on the input parameters.

[0093] The terminal device UE indicates the supported MAC length in addition to the supported tamper detection algorithm. The terminal device UE uses the Initial NAS message to transmit the UE security function to the AMF and notifies the supported encryption algorithm. At this time, as shown in Table 13, a 4-bit MACL (MAC length) parameter is included. By setting the MACL parameter to a value other than 0000, the terminal device UE indicates to the AMF that it supports a MAC longer than 32 bits. [Table 13]

[0094] Table 13 shows the cases where the MAC length is 32 bits, 64 bits, 96 bits, and 128 bits, and other parameters are reserved for expansion. Therefore, it is possible to support MACs longer than 128 bits according to future needs. The AMF determines the NAS SMC according to the received UE security capabilities. If the MACL parameter is not received or the received parameter value is 0000, the NAS SMC procedure is performed as in the prior art. If the AMF receives a MACL value other than 0000, that is, if the terminal device UE supports a MAC longer than 32 bits, the NAS SMC procedure is performed as follows.

[0095] In step S21 of Figure 2, the AMF creates a Secure Mode Command message including the following information: UE security capabilities (including supported algorithms and MAC lengths) - Tamper detection and encryption algorithms selected by AMF for NAS protection The MAC length selected by the AMF (shall be encoded in the same way as the MACL parameter, e.g. use 0001 for a 64-bit MAC) Other (may not be included) ·ABBA parameters ngKSI in NAS messages

[0096] The NAS SMC message is protected according to the selected tamper detection algorithm and MAC length. For example, if both the UE and the AMF support 64-bit MAC, the NAS SMC message is also protected with a 64-bit MAC. The base station gNB receives the message and forwards the NAS message in a message in step S24. In step S25, the terminal device UE verifies the message. In particular, the terminal device UE detects tampering of the message and verifies that the UE security functions have not been tampered with. If the verification is successful, the UE sends a Secure Mode Complete message (steps S26 and S27) to the AMF via the gNB.

[0097] This invention enables the terminal device UE and the network NW to share support for longer message authentication codes, making it possible to contribute to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), which is to "build resilient infrastructure, promote sustainable industrialization and foster innovation." [Explanation of symbols]

[0098] Steps to select 210 PLMN ID 220 Selecting a cell within a selected PLMN ID< / guami> < / mnc> < / mcc> < / guami> < / mnc> < / mcc> < / guami> < / guami>

Claims

1. A network device transmits to a terminal device a message including data indicating how many bits of a message authentication code the network device supports in the message to be transmitted from the network device to the terminal device.

2. 2. The network device according to claim 1, wherein data indicating how many bits of a message authentication code the network device supports is included in an ABBA parameter in a message transmitted from the network device to the terminal device.

3. 3. The network device according to claim 2, wherein the ABBA parameters also specify an algorithm for a message authentication code.

4. A terminal device that receives a message including data indicating how many bits of a message authentication code the network device supports, the message including: A terminal device that notifies a network device of its security capabilities by using a tamper detection algorithm different from a tamper detection algorithm selected by the network device.

5. A terminal device that includes data indicating how many bits of a message authentication code the previously connected AMF supported in the GUTI in an initial connection message sent to a network device.

6. A terminal device that includes data indicating how many bits of a message authentication code the terminal device requests to use in network slice selection assistance information NSSAI in a message sent to a base station.

7. 2. The network device according to claim 1, wherein data indicating how many bits of a message authentication code the network device supports is included in a system information block SIB in a message transmitted from the network device to a terminal device.

8. A terminal device that rejects an access stratum security mode command when the MAC length of a tampering detection algorithm that it supports does not match the MAC length of the tampering detection algorithm presented in an access stratum security mode command (AS Security Mode Command) message received from a base station.

9. A terminal device that, when presenting its security functions to an AMF, separately presents the tamper detection algorithm it supports and the MAC length it supports.

10. A terminal device that receives a message transmitted from the network device described in claim 7, ranks the received multiple system information blocks SIB according to whether they support 128-bit MAC, and selects a network node to connect to based on received signal strength and tamper detection strength.