Enhanced mechanisms for secure random access procedures
By masking bit sequences, rearranging beamforming, and encrypting CRI values, the security of random access procedures in wireless communication systems is enhanced, effectively mitigating Sparrow attacks and ensuring secure communication.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- KONINKLIJKE PHILIPS NV
- Filing Date
- 2026-02-16
- Publication Date
- 2026-06-02
AI Technical Summary
Wireless communication systems are vulnerable to Sparrow attacks during random access procedures, which allow malicious UEs to communicate covertly through the RACH procedure, posing security risks, especially in satellite-based communications.
Implement methods and devices that enhance security by masking bit sequences, rearranging beamforming, adapting transmission power, and using encryption techniques to secure random access procedures, including variable masking, beam rearrangement, and encryption of CRI values.
Enhances security in random access procedures by making it difficult for malicious UEs to communicate covertly, reducing the risk of Sparrow attacks and ensuring secure communication.
Smart Images

Figure 2026090426000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to security technologies for secure random access procedures in wireless communication networks such as cellular communication networks, but is not limited thereto.
Background Art
[0002] Many wireless communication systems provide a geographical service area in which a wireless communication device (for example, an end device or terminal device such as a mobile station or user equipment (UE)) communicates with an access device that provides services to a specific geographical service area where the terminal device is located. To provide the geographical service area, an access device (base station, Node B (eNB, eNodeB, gNB, gNodeB, ng-eNB, etc.), access point, etc.) is used. The access device is connected within the network, enabling a communication link to be formed between the wireless communication device and other devices.
[0003] In such a telecommunication system, a wireless communication device can access various types of services including voice services and data services via an access device deployed in the area. The network access device is connected to a core network (CN) that is managed by a network administrator who controls the telecommunication system to regulate service provision. To achieve this purpose, the UE must first connect to the access device via a random access procedure. In a Sparrow attack, the random access (RACH) procedure is used as a hidden communication channel by malicious UEs.
[0004] In the RACH procedure, in Message 1, the UE transmits its random access preamble transmission; in Message 2, the gNB transmits its random access response; in Message 3, the UE transmits its scheduled UL transmission; and in Message 4, the gNB responds with contention resolution.
[0005] The above attack assumes that a malicious sending UE (UE1) is permitted to include a random bit sequence x in message 3 to distinguish itself from other UEs competing for RACH access. If the gNB responds with a conflict resolution message, it must include the bit sequence x received from the malicious sending UE1 in message 4 so that another malicious receiving UE2 can receive the bit sequence. This is possible because the base station broadcasts message 4. In this way, the malicious sending device UE1 can send a message to the malicious receiving device UE2.
[0006] Furthermore, such telecommunications systems are evolving to allow wireless communication devices to access the CN not only through actual base stations (RBS) but also through other access devices. For example, a remote UE (i.e., a UE that cannot directly reach an RBS) uses a relay UE (i.e., a UE that connects to the CN via another UE or an RBS) to connect to the CN. Similarly, other access devices could be mobile base stations such as those mounted on vehicles or satellites. In such communication scenarios, a Sparrow attack can have an even greater impact, for example, in satellite-based communications, because satellites can potentially cover a very wide area. [Overview of the Initiative] [Problems that the invention aims to solve]
[0007] Thus, it remains desirable to enhance the available security features in wireless communication systems to further minimize the risks posed by attacks against random access procedures.
[0008] The objective of this invention is to provide a more secure random access procedure. [Means for solving the problem]
[0009] This objective is achieved by the methods described in claim 1, claim 9, claim 17, claim 19, and claim 23, by the apparatus described in claim 7, claim 8, claim 18, claim 22, and claim 27, by the attack detection system described in claim 14, by the method described in claim 15, and by the computer program product described in claim 29.
[0010] According to a first aspect of the present invention, a method is proposed for securely performing a random access procedure between a user device UE and an access device in a wireless network, the method being: - A step to receive a sequence of L bits s from the UE; - A step of extracting a k-bit value V by masking s with a mask; and - Step to send V; It has. According to a modification of the first aspect of the present invention, the number of bits L in sequence s is less than the number of bits k in value V.
[0011] According to a second modification of the first aspect of the present invention, the number of bits k of the value V is variable and configurable. Furthermore, the number of bits k may depend on at least one of the number of UEs performing the random access procedure, the network load, the desired security level, and the policy.
[0012] According to a third modification of the first aspect of the present invention, which can be combined with the previous modifications, the mask used to mask the sequence s is determined depending on at least one of the number of UEs performing the random access procedure, the network load, the desired security level, and the policy.
[0013] According to a fourth modification of the first aspect of the present invention, which can be combined with the previous modifications, the seed used to determine the mask may be notified together with V.
[0014] According to a second aspect of the present invention, a device for securely executing a random access procedure is proposed, the device being: - A receiver configured to receive a bit sequence s of L bits; - A microcontroller configured to extract a k-bit value V by masking s with a mask; and - A transmitter configured to send V; It has.
[0015] According to a third aspect of the present invention, a device for securely executing a random access procedure is proposed, the device being: - k-bit sequence V' receiver; - Memory for storing L-bit sequences s; and - A microcontroller configured to determine a mask, extract a k-bit value V by masking a sequence s with the mask, and compare V with V'; It has.
[0016] A fourth aspect of the present invention, which can be used in combination with or independently of the first aspect of the present invention, is proposed for securely performing a random access procedure between a user device UE and an access device in a wireless network, the method comprising modifying the beamforming of a reference signal, the modification of which: - The access device rearranges the order in which the directional beams transmitting the reference signal are broadcast; and The process by which the access device renames the corresponding beam index used to identify the beam; It is characterized by being based on at least one of the following.
[0017] In the first modification of the fourth embodiment, the above modification is characterized by a small random angular change in the broadcast direction of the beam.
[0018] In a second modification of the fourth aspect that can be combined with the first modification of the present invention, the method further includes a change characterized by adapting the beam of the random access procedure, the transmission power in message 2 or message 4, based on at least one of the configuration step, the reference signal received power RSRP of message 1 and / or message 3 in the random access procedure, and the quality value reported by the user equipment with channel state information CSI. In this case, the method can further include the step of lowering the priority of the UE or notifying an alarm when at least one pattern of the monitored RSRP measurement value and CSI measurement value deviates from the normal pattern.
[0019] In a third modification of the fourth aspect of the present invention that can be combined with the previous modification, the method further includes a change characterized by invalidating a given beam when the access device detects that the given beam is used excessively frequently.
[0020] In a fourth modification of the fourth aspect of the present invention that can be combined with the previous modification, the method: - Monitoring whether any UE is attempting a random access procedure; and - Executing a change when no UE is executing a random access procedure or when a maximum number M of UEs are executing a random access procedure; may further have.
[0021] In a fifth modification of the fourth aspect that can be combined with the previous modification, the method: - Periodic or cyclic changes; and - On-demand changes; further includes at least one of.
[0022] In a fifth modification of the fourth aspect that can be combined with the previous modification, the method has the change: - Receiving a change schedule from the management entity; - Mutual monitoring of changes in adjacent access devices; and - Execution of changes or receipt of notifications via a communication interface; The method further includes coordinating multiple access devices when performed by at least one of the methods described above.
[0023] According to a fifth aspect of the present invention, a method is proposed for adjusting a random access procedure that is activated by a change in the access device, the method being: - The UE resends message 1 of the random access procedure using a new preferred beam; - Steps for the UE to report its new preferred beam; and - The access device uses a beam that best covers the UE based on the change; It includes at least one of the following.
[0024] According to a sixth aspect of the present invention, a device for securely executing a random access procedure is proposed, the device being: - Beamforming-capable transmitters; and - A control unit that controls the beamforming of the transmitter; The device has: - A process to rearrange the order in which directional beams transmitting a reference signal are broadcast; and - The process of renaming the corresponding beam index used to identify a beam; It is configured to introduce a modification of the beamforming of the reference signal, characterized by at least one of the following:
[0025] According to a seventh aspect of the present invention, which can be used in combination with the first or fourth aspects of the present invention, or independently, a method is proposed for securely performing a random access procedure between a user device UE and an access device in a wireless network, the method being: - A step of determining or receiving an encryption key K linked to the access device and UE; - A step of determining or receiving a sequence of L bits; - The step of encrypting s with K to V; and - Step to send V; It has.
[0026] In the first variation of the seventh embodiment, the method further includes the step of determining an encryption key K that depends on the physical channel characteristics between the user device and the access device. Alternatively, the method may further include the step of receiving a public key associated with the access device.
[0027] According to an eighth aspect of the present invention, a device for securely executing a random access procedure is proposed, the device comprising a transmitter and a control unit, and the device: - Determine or receive the encryption key linked to the access device and UE; - Determine or receive sequences of L bits; - Encrypt s with K to V; and - Send V; It is configured in this way.
[0028] According to a ninth aspect of the present invention, which can be combined with the first, fourth, or seventh aspect of the present invention, a method is proposed for securely performing a random access procedure between a user device UE and an access device in a wireless network, the method being: - A step of monitoring whether a UE performing a random access procedure is within the communication range of the cell; and - A step to restrict access to the UE performing the random access procedure from outside the cell's communication range; It has.
[0029] In the first modification of the ninth embodiment, the monitoring step is performed based on timing advance parameters.
[0030] In a second modification of a ninth embodiment, which can be combined with the first modification, the method is: - A step of configuring the access device with the maximum allowable timing advance value; - A step to calculate the required timing advance value for the PRACH message; - A step to restrict access to PRACH messages that require a timing advance value greater than the maximum allowable timing advance value; and A step to report an alarm when the PRACH message requires a timing advance value greater than the maximum allowable timing advance value; It further includes at least one of the following.
[0031] In a third variation of the ninth aspect of the present invention, which can be combined with the first or second variation, the method further includes the step of monitoring an assigned TA value in a RAR (Random Access Response) message.
[0032] According to a tenth aspect of the present invention, a device for securely executing a random access procedure is proposed, the device being: — A process to monitor whether a UE executing a random access procedure is within the communication range of a cell; and - A process to restrict access to a UE performing a random access procedure from outside the cell's communication range; Includes.
[0033] According to an eleventh aspect of the present invention, a network device for a wireless network is proposed, which includes a device according to one or more of the above aspects.
[0034] It should be noted that the above-mentioned device can be implemented based on individual hardware circuits having the configuration of individual hardware components, integrated chips, or chip modules, or based on signal processing devices or chips controlled by software routines or programs stored in memory, written to computer-readable media, or downloaded from a network such as the Internet.
[0035] The apparatus, network apparatus, and methods detailed above should be understood to have similar and / or identical preferred embodiments, particularly as defined in the dependent claims.
[0036] Furthermore, it should be understood that the above-mentioned devices, network devices, and methods may refer to or be executed on one or more distributed network devices.
[0037] Preferred embodiments of the present invention should be understood to be any combination of the dependent claims or the embodiments described above with the corresponding independent claims.
[0038] The above and other aspects of the present invention will become apparent from the embodiments described below and will be explained with reference to such embodiments. [Brief explanation of the drawing]
[0039] [Figure 1] Figure 1 provides a schematic and illustrative illustration of the communication network. [Figure 2] Figure 2 shows the message flow of a random access procedure. [Figure 3] Figure 3 shows the radiation pattern of a primary station implementing various technologies related to one embodiment of the present invention. [Modes for carrying out the invention]
[0040] Embodiments of the present invention will be described below based on radio resource control (RRC) signal transmission for 5G cellular networks, particularly random access procedures.
[0041] Throughout this disclosure, the abbreviation “gNB” (5G term) is intended to mean an access device such as a cellular base station or WiFi access point. A gNB may consist of a centralized control plane unit (gNB-CU-CP), a plurality of centralized user plane units (gNB-CU-UP), and / or a plurality of distributed units (gNB-DU). A gNB is part of a radio access network (RAN) that provides an interface to functions within the core network (CN). The RAN is part of a radio communication network. It implements radio access technology (RAT). Conceptually, it exists between communication devices such as mobile phones, computers, or any remotely controlled machines, and provides their connection to the CN. The CN is the core part of the communication network and provides numerous services to customers interconnected via the RAN. More specifically, it directs communication streams through the communication network and possibly other networks.
[0042] Figure 1 schematically and illustratively shows a communication network that can implement the embodiments disclosed herein. The illustrated exemplary network is a cellular telecommunications network, such as a 4G or 5G network, and its terminal / end equipment (referred to as user equipment, or UE, in 5G) and access equipment (gNB) implement the equipment according to the disclosed embodiments. In Figure 1, the terminal / end equipment is shown as receivers Rx, but it is understood that they also function as transmitters within the network. Similarly, the access equipment (gNB) is shown as transmitters Tx in Figure 1, but it is understood that they also function as receivers within the network. For example, the terminal / end equipment can access various types of services, including voice and data services, through signal exchange with base stations of the network.
[0043] Each base station provides services and communicates with terminals / end devices located within a designated area, also called a cell. Two adjacent cells are shown by a dotted line in Figure 1. The base stations are connected to the core network CN, which is managed by the network administrator or governing body and controls the provision of services. Each cell is serviced by one base station, which functions as the interface between the terminals / end devices and the core network (CN). Therefore, if multiple terminals / end devices are mobile devices that can move from one network cell to another, as shown in Figure 1, the interface used by a given terminal / end device may change over time.
[0044] Terminals / end devices can communicate with base stations over various radio channels, uplink (from the device to each base station) and downlink (from each base station to the device). Other radio channels may exist, for example, between terminals / end devices (e.g., sidelink channels) and between base stations (e.g., X2 interface), but are not shown in Figure 1 for simplification. Each terminal / end device can perform its own function along any of its own channels.
[0045] Access devices may be stationary devices such as base stations installed in buildings, or mobile devices such as vehicle-mounted base stations, UAVs, or satellites that provide cellular connectivity.
[0046] The key element for implementing the scheduling mechanism is a radio resource control (RRC) protocol that can operate end-to-end with respect to wireless communication devices (UEs in 5G terminology).
[0047] Other elements for implementing the scheduling mechanism may be control elements (CEs) of the Media Access Control (MAC) protocol, which are short elements (or information elements (IEs)) inserted between existing uplink (UL), downlink (DL), or sidelink (SL) transmissions on the MAC layer, used to efficiently notify specific events, measurements, or configurations. Furthermore, MAC CEs may be used by access devices (e.g., gNBs) to control the behavior of communication devices (e.g., UEs) when performing various other 3GPP® mechanisms such as channel status information (CSI) reports, sounding reference signals (SRS), or discontinuous reception (DRX).
[0048] A further element may be the use of Downlink Control Information (DCI), which is a short message transmitted in a special blindly detectable modulation or encoding on a low-bitrate control channel (e.g., a Physical Downlink Control Channel (PDCCH)). This mechanism is implemented at the Physical Protocol Layer (PHY L1) and does not require the use of the MAC PDU header structure. In this case, various DCI formats can be defined with different information content. Communication resources for dynamic scheduling can be indicated in the DCI.
[0049] 3GPP® specification TS33.501 discloses how networks use information transmitted in measurement reports in RRC_CONNECTED mode to perform UE-assisted network-based detection of fake or sham base stations (FBS). Furthermore, the initially mentioned 3GPP® specification TR33.809 discloses research findings on the FBS problem and discusses different solutions for evading / detecting FBS and MitM attackers.
[0050] In the Sparrow attack, which is available online at https: / / arxiv.org / pdf / 2108.12161.pdf and refers to “SPARROW: A Novel Covert Communication Scheme Exploiting Broadcast Signals in LTE, 5G & Beyond” (hereinafter referred to as reference [1]), 3GPP® Tdoc S3-212783 (hereinafter referred to as reference [2]), and 3GPP® Tdoc S3-212452 (hereinafter referred to as reference [3]), a malicious UE uses the Random Access (RACH) procedure as a hidden communication channel. In the RACH procedure, in message 1 the UE sends its Random Access preamble transmission, in message 2 the gNB sends its Random Access response, in message 3 the UE sends its Scheduled UL transmission, and in message 4 the gNB responds with a conflict resolution. The attack assumes that a malicious sending UE (UE1) is permitted to include a random bit sequence x in message 3 to distinguish itself from other UEs simultaneously competing for the RACH access. If the gNB responds with a conflict resolution message, it must include the bit sequence x received from the malicious sending UE1 in message 4, and thus another malicious receiving UE2 can receive it. This is possible because the base station broadcasts message 4. In this way, the malicious sending device UE1 can send a message to the malicious receiving device UE2. It should be noted that reference [1] states that messages 2 and 4 are sent in basic transmission mode (e.g., broadcast SRB). It should be noted that message 2 is addressed to the UE using RA-RNTI derived from the transmission slot selected by the UE to send message 1. In message 2, the gNB assigns the UE a TC-RNTI (16-bit length). The bit sequence x is represented by a 48-bit length conflict resolution ID (CRI) containing a 40-bit length randomly selected value.
[0051] References [1] and [2] describe a method to counter a Sparrow attack by taking the bit sequence x received from the UE and calculating a function H() on x concatenated with a random salt s, i.e., calculating H(x|s), where H() can be a cryptographic hash function and | signifies concatenation. The gNB then sends H(x|s){or some bits of H(x|s), e.g., the least significant bit or some bits random to the UE} along with the salt s in message 4. Here, the salt acts as a hint to the UE on how to check whether message 4 is actually directed at it, because the UE must check whether the calculation of its own value x, sent in message 3, concatenated with the received salt s, is equal to the received H(x|s). The problem with this approach in S3-212783 is that transmitting s requires additional bandwidth, and its length also affects the probability of a collision.
[0052] One possible solution to address this bandwidth problem is to compute a salt s used by the gNB to determine the communication resources (e.g., time slot, SFN, frequency) used to send, for example, message 4, and to implicitly transmit this salt s with message 4. The salt could also be some of the other communication parameters used in the RACH procedure, e.g., the (randomized) resource allocation for message 2 or one of the RNTIs, e.g., the RNTI used to identify message 4. When a UE receives message 4, it determines the value of s from, for example, the communication resources or RNTI used to send message 4. Once the UE has s, it can verify that the message is addressed to it by checking whether the hash of its own bit string x concatenated with the received s is equal to the H(x|s) value received in message 4. This approach to delivering the salt reduces communication overhead.
[0053] References [1] and [2] also describe how the output of H(x|s) can be truncated (e.g., only the k least significant bits are sent), how some bits can be sent (K erasure), or how some errors can be introduced (K errors). For example, in the case of K erasure, it is necessary to indicate which bits have been deleted. This can be done by a mask that is H(x|s) long, for example, L bits long. In this case, the remaining Lk bits must be sent. For example, transmitting a mask in such a K erasure also requires additional bandwidth, i.e., L bits.
[0054] This can be addressed if the mask is derived from several randomly generated parameters, such as RNTI or allocated transmission resources, which are inherently exchanged in message 4 or previous messages. To generate a bit sequence in the form of a mask from smaller random values, the mask can be computed by applying a pseudo-random function based on a specific function, such as a hash function like SHA-256, to generate a bit sequence of L bits with fixed weights K. Since the weights are fixed, they can be specified in the technical specification and do not need to be exchanged. One way to compute such a bit sequence is to randomly generate indices between 0 and L-1 until different indices of K are generated. In this case, the mask is a bit sequence of L bits with 1s at the positions of the generated indices. Another approach is to set up a bit sequence with K 1s and LK 0s and apply a random rearrangement. This can be done by randomly generating L long values (e.g., 128 bits long) (e.g., by applying a pseudo-random function to the seed), setting the least significant bit of the first K values to 1 and the least significant bit of the last LK values to 0. In the next step, L seemingly random values are selected. The mask is constructed by concatenating the least significant bits of L selected values. Another option is to randomly generate L-bit candidate masks from a seed, for example, count the number of 1s, and accept the candidate mask if the number of 1s is greater than a minimum threshold (th_min) and less than or equal to a maximum threshold (th_max). This process is repeated if the candidate mask does not satisfy the required weights. If th_max - th_min > 1, the value of k must be swapped, or instead, how many additional 1s the mask contains compared to th_min, for example.
[0055] It should be noted that the underlying approaches proposed in references [1] or [3] do not completely solve the Sparrow attack, because the malicious UE1 on the sending side can manage / determine the bit sequence x to be sent, and the malicious UE2 on the receiving side can still find that bit sequence using a dictionary. For example, suppose the malicious sender UE1 can send either x0=000...000 or x1=1111...111, and UE2 knows these two values. Suppose the gNB sends LK least significant bits of the Hash(x|s) of the known s. When the malicious receiving UE, UE2, receives these values, it selects x0 and x1 to obtain Hash(x0|s) and Hash(x1|s). UE2 then truncates these outputs to consider only the LK least significant bits. If either of these values matches, UE2 understands that UE1 sent a message to it.
[0056] In another relevant embodiment for addressing a Sparrow attack, the gNB encrypts or scrambles the received bit string x using, for example, a function (e.g., a hash) of the bit string and salt as the key. If a UE receives the result in message 4, the UE can verify that the message is addressed to it by decrypting (or descrambling) the received value using the same key derived from its own transmitted value x and salt. If malicious devices UE1 and UE2 want to use this approach to communicate, UE2 would need to decrypt (or descramble) the received value using all possible keys derived from all possible messages xi and salts s.
[0057] It should be noted that in the above embodiment, it is advantageous to make the salt as long as possible. This is because it increases the effort required of a malicious receiver and hinders the pre-computation of the dictionary. The problem is that sending a long salt may be impossible because the current standard limits the size of the CRI to 48 bits. Thus, it is advantageous to send this salt, or part of it, implicitly in order to make the attack as complex as possible. Alternatively, if both the UE and gNB have access to a common value, such as a counter derived from UTC time, such a counter can also be used as part of the salt. The least significant bit of the UTC time can be swapped to resolve any potential slow time synchronization issues.
[0058] Reference [1] states that the total size of a message is 2L + SK, where L is the length of H(x|s), S is the length of the salt, and K is the number of bits not sent. The presented embodiment explains how the message size can be reduced to LK, since the S bits of the salt can be implicitly sent, and the L bit length mask used to select the K bits to be deleted can also be implicitly sent: that is, the mask is generated by a pseudorandom function from an implicitly sent seed.
[0059] In other embodiments modified according to the solution proposed in the present application from the previous embodiments, when the gNB receives a received CRI field of x-bit length in message 3, in message 4, it can transmit a subset (<x) of these bits. The subset of the bits can be selected according to a mask. Thus, this embodiment is the same as the previous embodiment described above, but it is not necessary to apply a hash function to the received CRI. This can make it easier to communicate with a malicious receiving UE (for example, because the repetition code can enable it to withstand this countermeasure), but this countermeasure reduces the CPU requirement and increases the difficulty of executing an attack by reducing the amount of data that can be transmitted. Thus, a method for securely executing a random access procedure between a UE and an access device in a wireless network is proposed, and the method includes: Receiving an L-bit bit sequence s received from the UE; Determining a mask; Extracting a k-bit value V by masking s with the mask; and Transmitting V; and has.
[0060] In the above embodiment, the number of bits transmitted in message 4 can be context-dependent. For example, if the gNB notices that almost no UE is currently performing RACH, the gNB can respond with a very small number of bits of the received CRI. If the gNB notices that a large number of UEs are performing RACH, the gNB can use more bits in the response of message 4. For example, if the CRI is x-bit long (for example, x is 40 bits), the response in message 4 can include an x-bit field as follows (such as x = x1 + x2 + x3): · x1 bits (for example, x1 = 2) can be used to indicate an identifier indicating the length of the mask or how many bits of the CRI are to be returned. For example, 00 can indicate 5 bits, 01 can indicate 10 bits, 10 can indicate 20 bits, and 11 can indicate 38 bits; The x2 bits are used to encode a seed used to calculate the mask used to select the bits to be selected. As shown in the previous embodiment, this seed may also be sent implicitly, for example, within the allocated resources used for sending message 4. In the above example, if the seed is explicitly sent, the value can be 33, 28, or 18 bits long. This field does not exist if the seed is not explicitly sent; • x3 bits are used to encode the bits to be transmitted. In the example above, this can be 5, 10, 20, or 38 bits long. Thus, in the definition above, x3 = k.
[0061] Note that additional bits (or another field) may be required to indicate whether or not the seed is implicitly sent. If the number of bits returned is less than x, the gNB may send an even shorter message to make the system more efficient.
[0062] In another relevant embodiment for addressing sparrow attacks, the gNB can use highly concentrated beamforming when sending message 4. This reduces the risk of other UEs receiving the message.
[0063] Here, it is necessary to consider that after scanning the SSB broadcast by the gNB, the UE will indicate to the gNB which beam it prefers. The UE can indicate which beam it prefers by selecting a specific preamble to be used in message 1. In this way, the gNB will know which of its beams used to broadcast the SSB was best received by the UE. A malicious transmitting UE who knows the gNB's radiation pattern should note that if the gNB uses a static beam / SSB, i.e., if a beam is always used in the same geographic area to broadcast a given SSB, it may still be possible to circumvent concentrated beamforming. If the gNB uses a static beam / SSB and the malicious transmitting UE knows which beam the gNB uses to cover the area where the malicious receiving UE is located, the malicious transmitting UE may select a preamble linked to the beam / SSB that covers the area where the malicious receiving UE is located and use that preamble in the first message of the RACH procedure so that the gNB responds in message 2 or 4 using that beam. To circumvent this situation, gNB can use highly concentrated beamforming, followed by additional techniques to further complicate the Sparrow attack.
[0064] The first technique involves the gNB rearranging the order in which beams are broadcast and renaming the corresponding SSB indices used to identify them. Such rearrangement and renaming may be performed periodically (e.g., every T seconds), each time the system frame number (SFN) wraps around, or on demand {for example, if the gNB detects that a given beam / SSB is being used more than usual (indicating a possible ongoing Sparrow attack)}. This rearrangement may be performed as defined by a configurable policy by the governing entity (e.g., a network function within the core network). This rearrangement may be configurable by the network operator.
[0065] An example of the above rearrangement / naming is as follows: At time t0, gNB uses four beams / SSBs that are transmitted sequentially and point to, for example, north, east, south, and west, identified as SSB0, SSB1, SSB2, and SSB3; at time t1, gNB uses four beams / SSBs that are transmitted sequentially and point to east, west, north, and south, identified as SSB0, SSB1, SSB2, and SSB3. Each time the beam / SSB arrangement and naming changes, a malicious transmitting UE will not know exactly which beams / indexes are being used to cover a given area, making it more difficult to handle a Sparrow attack. A similar example may be possible in satellite-based access devices. In this case, different beams (SSBs) may point to different areas within an area, for example, different regions within a country. The beam naming may change periodically.
[0066] A second related technique involves slightly altering the direction of each beam after rearrangement / naming, while the base station still maintains coverage of the entire area. This configuration is useful because if the direction remains fixed even when the beam arrangement / naming changes, a malicious transmitting UE could re-identify the beams by their power signature. If the direction or transmit power is slightly altered each time, it will become more difficult for a malicious transmitting UE to re-identify the beams, i.e., to know which areas are covered by which beams in the RACH procedure.
[0067] A third related technique is that the gNB adapts its SSB and transmit power in messages 2 and / or 4 based on, for example, a pre-configuration step (e.g., during deployment), the reference signal received power (RSRP) of message 1 (or 3), and / or the CSI with the UE performing the RACH procedure. The gNB adjusts its transmit power so that it does not reach a UE far from the UE performing the RACH procedure. Note that a malicious transmitting UE may attempt to manipulate the gNB's transmit power by, for example, modifying the measurement directed towards the gNB or transmitting message 1 (or 3) at a low power to make the gNB assume that it is very far away and cause the gNB to transmit at a high power. However, the gNB can monitor the RSRP / CSI measurement of the UE performing the RACH and use these measurements to determine a communication pattern that requires high transmit power for messages 2 and 4, where multiple UEs attempt to participate, for example, with low RSRP. If a pattern is detected that deviates from the gNB's normal history pattern regarding the RACH procedure, the gNB may lower the priority of these UEs or issue an alarm. Figure 3 shows the radiation pattern of a gNB implementing the first, second, and third techniques when transmitting beams / SSBs. Over three time intervals T1, T2, and T3, it can be seen in what direction and at what power the base station transmits four SSBs (SSB0, ..., SSB3). These SSBs are depicted by ellipses around the gNB. The direction of the ellipse indicates the direction of the transmitted beam / SSB, and the length of the ellipse indicates the transmitted power. It can be seen that the gNB transmits SSBs / beams in different timing sequences, in different directions, and / or at slightly different transmitted powers.
[0068] Figure 3 shows two UEs, namely UE-A and UE-B. UE-A could be a malicious transmitting UE, and UE-B could be a malicious receiving UE. At the top of Figure 3, the RSRPs of each beam / SSB of the gNB measured by UE-A are shown for each of the time intervals T1, T2, and T3. It can be seen that at T1, T2, and T3, UE-A observes SSB0, SSB2, and SSB3, respectively, as the strongest beam / SSBs. These are the beams / SSBs that UE-A should use to perform RACH if selection is performed based on measured signal power. In contrast, if UE-A wants to perform a Sparrow attack with UE-B, UE-A should use beams / SSBs SSB3, SSB1, and SSB0. Because this configuration is constantly changing, it is difficult for UE-A to use the appropriate beam / SSB with high reliability, and as a result, UE-A cannot communicate with UE-B with high reliability via a Sparrow attack.
[0069] A fourth related technique is to disable a given beam if the gNB detects that it is frequently used in an area that is being served by other base stations or other DUs of the base station.
[0070] In the embodiments and techniques described above, the gNB / 5G system should adapt the timing to serve an area with different gNBs so that (1) rearranging the SSB / beam, (2) changing the beam direction, (3) changing the transmit power, and / or (4) minimizing communication interruptions during RACH. The gNB can achieve this by (1) monitoring whether any UE is attempting RACH, and (2) performing the above modifications only if no UE is currently performing RACH or up to several million UEs are currently performing RACH. The gNB may also choose to complete ongoing RACH attempts based on the previous SSB / beam configuration. Furthermore, multiple gNBs should coordinate themselves when adapting their radiation patterns. This can be accomplished by (1) having the core network distribute the transmit schedule to the gNB under its own control; (2) having the gNB measure the signals (beam / SSB) received from surrounding cells and use this to adapt the transmit parameters (direction or transmit power); and (3) having the gNB notify them of the corresponding transmit patterns via the Xn interface. Furthermore, if the UE notices a sudden change in the RSRP measured by the gNB while performing the RACH procedure, it can take the following actions: *If the above change is measured after sending message 1, the UE may resend message 1 using the newly selected beam / SSB with the best received RSRP; *If the above changes are measured after sending message 1 or 3, the UE can report its new preferred (preferred) beam; *If the above change is measured after sending message 1 (or 3), the UE may attempt to receive message 2 (or 4) via the previous beam until it notifies the gNB of its new priority; *If the above changes are measured after sending message 1 or 3, the gNB may also choose to respond using the beam expected to best cover the UE. In this case, the UE can also expect to receive the response via one of the beams with the best RSRP.
[0071] While the above measures are feasible, UEs or gNBs should only implement such measures if required or permitted by their policy. This is because this could be exploited by a malicious transmitting UE to determine which beams are being used to cover an area where a malicious receiving UE is located.
[0072] In an additional embodiment, the gNB encrypts the received CRI value, or a subset thereof, and sends it back to the UE. This makes it difficult for a malicious receiving UE to understand the transmitted value. The challenge with using such an "encryption-based" solution is determining how to establish a key between the UE and the gNB without allowing a malicious receiving UE to guess it. The solution to this challenge is to rely on the physical channel characteristics between the UE and the gNB (e.g., the phase of the subcarriers used in the communication) and to use a "key" that is known only to both devices. For example, the gNB transmits some physical information in a randomized manner so that the information is specific to the area where the receiving UE is located. For example, such physical information may relate to the beam / SSB that the gNB is using to cover a given area when transmitting the MIB / SIB1. If the UE measures the received power of the SSB / beam, the UE selects an appropriate preamble (relating to the SSB / beam received at the best RSRP) and transmits it to the gNB. This provides indicative information not only about which beam is the best received beam, but also about which other beams are likely to be well received by the UE (even if the RSRP is low). Note that this information is not exchanged over radio communication, making it even more difficult for a malicious receiving UE to obtain it. This shared physical information can form the basis of an encryption key that can be used to encrypt the CRI value (or a hash of the CRI value or a subset of bits of the hash of the CRI value) in message 4. For example, if the gNB uses 64 SSB / beams, the UE and gNB can use the indices of the k best-received SSB / beams, excluding the best-received one, as the encryption key. For example, k can be 2. This encryption can be performed, for example, by applying a hash function or key derivation function to the SSB index to generate a pseudo-random sequence, and then XORing the transmitted data with the least significant bit of the generated pseudo-random sequence.It should be noted that, instead of encryption, this physical information can also be used as SALT in the above embodiment, particularly when calculating H(x|s). It should also be noted that in message 3, the UE can provide the gNB with measured physical channel characteristics, such as the RSRP levels of different beams / SSBs. The gNB can verify that the above levels are what they should be and use this information in its response in message 4, for example, to encrypt the response.
[0073] Another encryption approach could involve the gNB making a public key available for encryption. This can be done if the gNB sends its encryption public key in the SIB. The gNB or CN can sign this encryption public key, which can be verified by the UE if the UE has a corresponding trust anchor, for example, a certificate containing the public key used to create the digital signature. This trust anchor may be pre-configured. Once the UE receives or retrieves this encryption public key, it can use the public key to encrypt fields that need protection, such as the CRI. To retrieve the public key, the UE first reads / receives the MIB, then reads / receives SIB1, and then uses the information in SIB1 to determine if this public key is available in another SIB. If it is available, the UE can read / receive it.
[0074] In variations of the relevant embodiments, the UE / access device should use an encryption scheme secure against chosen-ciphertext attacks to prevent an attacker from freely altering the ciphertext. For example, such a device must use an encryption scheme that relies on FO transformation, such as a CCA Secure KEM scheme, or a combination of the CCA Secure KEM scheme and a symmetric encryption scheme such as GCM. In such a scheme, if m is a message transferred from the UE to the gNB, the UE creates a ciphertext that includes a public key component generated by the UE and depends on the message m itself. When the gNB receives the message, it will decrypt the CT itself to obtain the message m'. Once the gNB has obtained m', it checks whether the public key component generated from m' is equal to the one received. In this way, the gNB can determine whether the message has been altered. If m is very short, it is better to encapsulate a random symmetric key with CCA Secure KEM and then encrypt m using a symmetric encryption algorithm with that key.
[0075] In the above embodiment, backward compatibility between the legacy UE and the new gNB, and between the new UE and the legacy base station, must be considered. One option is for the new gNB to broadcast its capabilities as part of the system information (e.g., indicating bits in SIB1). The gNB may also notify this information in message 2 or 4 by, for example, setting certain bits to a predefined value. Another option is for the new UE to notify how the bit sequence in the message should be calculated, for example, by simply retransmitting the bit sequence in message 3, or by including a specific conversion to this value as described above. The UE may notify this fact by setting a bit in message 1 or 3 to a specific value. The new gNB uses this to determine how the bit sequence in reply message 4 should be calculated. If the new UE determines that the gNB is a legacy base station by, for example, observing that SIB1 does not indicate that the gNB is a new gNB that supports the feature, then the new UE will know that it only needs to check the received bit sequence in message 4 against the bit sequence it sent in message 3. If a new UE obtains directive information that the gNB is a new base station supporting enhanced defenses against Sparrow attacks, the UE will check the value of the input bit string in message 4 as shown in one of the embodiments above.
[0076] In a Sparrow attack [1][2][3], the Random Access (RACH) procedure is used by a malicious UE as a covert communication channel. In the RACH procedure, in message 1, the UE sends its Random Access ambilude; in message 2, the gNB sends its Random Access response; in message 3, the UE sends its Scheduled UL transmission; and in message 4, the gNB replies with a conflict resolution. This RACH procedure is shown in Figure 2. The attack assumes that a malicious sending UE, UE1, is permitted to include a random bit sequence x in message 3 to distinguish itself from other UEs that are simultaneously competing for the RACH access. When the gNB replies with a conflict resolution message, it must include the bit sequence x received from the malicious sending UE1 in message 4 so that another malicious receiving UE2 can receive the bit sequence. This can be achieved by a base station broadcasting message 4. In this way, the malicious sending device UE1 can send a message to the malicious receiving device UE2.
[0077] Note that messages 2 and 4 are transmitted in basic transmission mode (e.g., broadcast SRB). Note that message 2 is addressed to the UE using the RA-RNTI derived from the transmission slot selected by the UE to send message 1. In message 2, the gNB assigns the UE a TC-RNTI (16 bits long). Bit sequence x is represented as a 48-bit conflict resolution ID (CRI) containing a randomly selected 40-bit value.
[0078] One way to handle the Sparrow attack is to extract the bit sequence x received from the UE and compute a function H() on x concatenated with a random value sort s, i.e., H(x|s) (e.g., H() can be a cryptographic hash function), where | means concatenation. Then, the gNB sends H(x|s) {or some bits of H(x|s), e.g., the least significant bits or some bits random to the UE} together with the sort s in message 4. In this case, the above sort functions as a hint to the UE on how to check whether message 4 is actually intended for itself. This is because the UE has to check that the computation of its own value x sent in message 3 concatenated with the received sort s is equal to the received H(x|s).
[0079] The output of H(x|s) can be truncated (e.g., only the k least significant bits are sent), only some bits can be sent (K erasures), or some errors can be introduced (K errors). For example, in the case of K erasures, it is necessary to notify which bits are deleted. This can be done using a mask of the same length as H(x|s), e.g., L-bit long.
[0080] The first problem in the above solution is that the transmission of the sort s and / or the mask requires additional bandwidth and its length also affects the probability of collision. In particular, the solution detailed in reference [1] requires transmitting 2L + S - K, where L refers to the length of H(x|s) and the mask, S refers to the length of the sort, and K < L is the number of bits not transmitted from H(x|s). However, in the case of the compatible solution, only 40 bits are available (corresponding to the length of the CRI).
[0081] A second problem with the above solutions is that while these solutions address specific covert communication attacks during the RACH procedure, there are further covert communication channel attacks that have not yet been described and therefore remain unresolved. For example, it could be explained that malicious sender and receiver UEs could communicate covertly using only the first two messages of the RACH procedure by utilizing the timing advance command and the RA-RNTI field. This covert communication attack is called a TA-based covert communication attack.
[0082] According to the current definition of this aspect of the present invention, it includes at least one of the following two features:
[0083] A first feature of this aspect of the present invention is to describe how to implicitly transmit the elements (salt and mask) required in some solutions (e.g., in reference [1][2]) so that these elements do not consume any additional bandwidth. This makes it possible to reduce the bandwidth requirement in reference [1][2] from 2L+SK bits to LK bits.
[0084] A second feature of this aspect of the present invention is to describe a solution to address TA-based stealth communication attacks.
[0085] In reference [1], a hidden communication attack is described based on the manipulation of the conflict resolution ID in the third message of the RACH procedure. A similar hidden communication attack can be achieved by manipulating the transmission timing of the first message of the RACH procedure. That is, if the UE transmits slightly earlier or later, the gNB will assign a different timing advance value (encoded in 12 bits), which will be broadcast in message 2 (RAR) of the RACH procedure. A malicious sending UE can do this as follows: In step 1, the malicious sending UE sends a PRACH request (the first message in the RACH procedure) and learns the assigned timing advance (TA) value from the gNB's response (RAR, the second message in the RACH procedure). The malicious sending UE can perform this action once or multiple times to obtain a good estimate of the TA value that the gNB assigns to the UE. In step 2, if a malicious sending UE knows the TA value that gNB assigns to it, it can modify the timing of sending the PRACH message so that gNB assigns it any TA value it likes. This capability allows us to assume that the malicious sending UE and the malicious receiving UE have agreed on the following exemplary protocol for sending data through this hidden channel: In step 1), the sending UE forces gNB to assign a TA value equal to or close to the maximum value for N requests (e.g., N=1) within a given period (e.g., 1 minute). For example, if the TA value can be 12 bits long, the sending UE forces gNB to assign a TA value equal to or greater than 1111 1111 0000 in binary. In step 2), if the transmitting UE has successfully processed the gNB to respond with a TA equal to or close to the maximum value, the transmitting UE sends a PRACH at a time when the gNB responds with a TA value such that the most significant bits (multiple most significant bits) indicate a long distance and the lower bits indicate the data that the transmitting UE wants to send to the receiving UE. For example, possible TA values sent in the TA command field are: 11 AAAA AAAA YY This is possible, where the two most significant bits are set to 1 to indicate that the UE is far from the gNB, the bit indicated by A is used to send the message, and the bit set to Y is ignored (because these can occur due to possible timing inaccuracies at the gNB when receiving the PRACH). In this example, the sending UE requires two PRACH messages to have the gNB broadcast bytes of useful data (AAAA AAAA) within the TA command field of the RAR message that can be understood by the receiving UE.
[0086] The TA-based hidden communication channel described above can be further enhanced, for example, if a malicious sending UE and a malicious receiving UE agree to the use of a specific RA-RNTI. If this is the case, the reliability and capability of the channel are increased. This is because, if a receiving UE observes a RAR message addressed to a specific RA-RNTI with a very large TA value, the receiving UE can more reliably identify the origin of the message. Solutions to such TA-based hidden communication channels may need to differ from the solutions presented in the embodiments described above. The main reason is, While the conflict resolution ID can be randomly selected, the TA value is inherently related to the communication channel between the UE and the gNB, ensuring that uplink frames are properly aligned with downlink frames.
[0087] It should be noted that performing random access procedures with access devices located on satellites, i.e., non-terrestrial networks, may require different parameters and field sizes than those in terrestrial networks. For example, timing advance values may require longer field sizes, e.g., more than 12 bits, due to the large distance between the terminal equipment (UE) and the access device. This may facilitate the use of such fields to enable hidden communication channels.
[0088] A first embodiment for addressing this TA-based hidden communication channel requires the gNB to monitor whether the UE performing RACH is within the expected communication range of the cell. If the cell is deployed to cover an area up to 2 km around its location, requests arriving from UEs located outside this coverage area (and corresponding to high TA values) should be excluded or at least limited. This can be done by: 1) configuring the gNB with a maximum allowable TA value (TA threshold). For example, this can be done during deployment or operation, for example, from the core network or a network management center. During operation, 2) the gNB calculates the required TA value for incoming PRACH messages and excludes, i.e., does not respond to, those requiring a TA value greater than the TA threshold. If this occurs, 3) the gNB can also report an alarm to a management function, for example, a function that performs an analysis of a possible security event. As an extension, the gNB may also accept TA values greater than the TA threshold if it occurs sporadically, but if multiple such TA values are detected in a burst, these should be excluded.
[0089] A second embodiment for addressing this TA-based hidden communication channel can analyze patterns of assigned TA values (and / or related communication parameters such as RA-RNTI used) within RAR messages and compare them to expected ones. To achieve this objective, the gNB can maintain a historical data record of the distribution of TA values (and / or RA-RNTI) over time. This may include, for example, the distribution of TA values (mean, median, maximum, minimum, etc.) as a function of daytime, day of week, and month. This historical data record can be stored in the gNB or supplied to, for example, a data analysis function (DAF) in the core network. The gNB or DAF can analyze the calculated TA values of incoming PRACH messages, for example, by clustering them and identifying clusters that deviate from normal values. This detection may be based on, for example, performing principal component analysis or a chi-squared test to check, for example, whether the distribution of past TA values and new TA values follows the same distribution.
[0090] In a third embodiment for addressing this TA-based hidden channel, the base station calculates a TA value (TA_real) corresponding to the received PRACH message and adds a random variable R to this value so that the TA value sent to the UE in the second message of the RACH procedure is TA_real+R. For example, if the TA value is 12 bits long and the R value is 6 bits long (e.g., a value between -32 and 31), this will reduce the number of valid bits available to send data from the transmitting UE to the receiving UE. The initial inaccuracy resulting from adding R is eliminated in later protocol exchanges because the gNB can update the UE's initially assigned TA value via MAC-CE. The timing advance command is only 6 bits in MAC-CE. In this embodiment, the gNB can avoid receiving errors in message 3 (and subsequent messages) of the RACH procedure by taking the added R value into account by making appropriate scheduling choices that take into account the UE's actual TA value. The reason is that the UE uses an inaccurate TA value due to the addition of R, and therefore this can lead to a situation where two frames from two UEs arrive at the gNB, for example, one of these frames could be message 3 from the UE, while the other frame could be an uplink message from the other UE. Since the gNB is aware of the assigned R value, it can adapt its resource allocation schedule to these two UEs to avoid frame collisions.
[0091] The above embodiment also applies to a two-step RACH when messages 1 and 3 are combined into a single message A from the UE to the gNB, and messages 2 and 4 are combined into a single message B from the gNB to the UE.
[0092] Furthermore, the underlying principles are also applicable to other wireless systems of 3GPP® and other standardization bodies. For example, 3GPP® is studying the use of relay devices such as UEs or base stations in Integrated Access Backhaul (IAB) networks to expand its scope. In such use cases, MitM attackers may be located, for example, between remote UEs and relay UEs. In these situations, MitM attackers can be detected and evaded by the proposed or similar techniques.
[0093] Furthermore, the proposed techniques for secure random access procedures can be implemented in all types of wireless networks where such access processes may be used. For example, the techniques can be applied to devices communicating using cellular wireless communication standards, particularly the 5G or 6G specifications of the Third Generation Partnership Project (3GPP®).
[0094] Thus, the wireless communication device may be various types of devices, including mobile phones, vehicles (for vehicle-to-vehicle (V2V) communication or more generally, vehicle-to-all (V2X) communication), V2X devices, IoT hubs, IoT devices, etc., including low-power medical sensors for health monitoring, medical (emergency) diagnostic and treatment devices for hospitals or emergency responders, and virtual reality (VR) headsets. The access device may be a base station, a base station mounted on a means of transport, etc., and the means of transport may be sea, land or air transport, satellite, UAV, etc.
[0095] Furthermore, the present invention can be applied to medical applications or connected healthcare involving multiple wireless (e.g., 4G / 5G) connected sensor or actuator nodes, medical applications or connected healthcare in which wireless (e.g., 4G / 5G) connected devices consume or generate continuous data streams of a specific average data rate, such as video, in a timely manner, general IoT applications (e.g., smart cities, logistics, agriculture, etc.) including ultrasound, X-ray, computed tomography (CT) imaging devices, real-time patient sensors, audio, voice, or video streaming devices used by medical personnel, wireless, mobile, or fixed sensor or actuator nodes, emergency services and critical communication applications, V2X systems, systems for improved service range for 5G cellular networks using high-frequency (e.g., millimeter wave) RF, and any other application area of 5G communications in which relay is used.
[0096] Other modifications of the disclosed embodiments can be understood and implemented by those skilled in the art by examining the drawings, this disclosure, and the appended claims when carrying out the invention described in the claims. In the claims, the word "having (including)" does not exclude other elements or steps, and the singular form does not exclude plural. A single processor or other unit can perform the functions of several items described in the claims. The mere fact that certain means are described in different dependent claims does not mean that combinations of these means cannot be used advantageously. The above description details certain embodiments of the invention. However, no matter how detailed the above may appear in the text, it will be understood that the invention can be carried out in many forms and is therefore not limited to the disclosed embodiments. It should be noted that the use of certain terms when describing certain features or embodiments of the invention should not be construed as meaning that the terms are redefined herein so as to be limited to any particular feature of the feature or embodiment of the invention to which the terms relate. Furthermore, the expression "at least one of A, B, and C" should be understood as disjunctive, meaning "A and / or B and / or C."
[0097] A single unit or device can perform the functions of several items described in a claim. The mere fact that certain means are described in different dependent claims does not mean that combinations of these means cannot be used advantageously.
[0098] The processes described in Figures 1 to 3, etc., can be implemented as program code means for a computer program and / or as dedicated hardware for related communication or access devices, respectively. Computer programs can be stored and / or distributed not only on appropriate media such as optical storage media or solid-state media supplied together with or as part of other hardware, but also in other forms, such as via the Internet or other wired or wireless communication systems.
Claims
1. A method for securely executing a random access procedure between user equipment and an access device in a wireless network, The steps include receiving a sequence s of L bits received from the user device, The steps include extracting a k-bit value V by masking the sequence s with a mask, The step of transmitting the aforementioned value and A method having
2. The method according to claim 1, wherein the number of bits L of the sequence s is smaller than the number of bits k of the value V.
3. The method according to claim 1, wherein the number of bits k of the value V is variable and configurable.
4. The method according to claim 3, wherein the number of bits k depends on at least one of the number of user devices performing a random access procedure, the load on the network, a desired security level, and a policy.
5. The method according to claim 1, wherein the mask used to mask the sequence s is determined depending on at least one of the number of user devices performing the random access procedure, the network load, a desired security level, and a policy.
6. The method according to any one of claims 1 to 5, wherein a seed used to determine the mask is notified together with the value V.
7. A device for securely executing random access procedures, A receiver that receives a bit sequence of L bits, A microcontroller that extracts a k-bit value V by masking the aforementioned bit sequence s with a mask, A transmitter that transmits the aforementioned value V and A device having.
8. A device for securely executing random access procedures, A receiver that receives a k-bit sequence V', A memory that stores a sequence s of L bits, A microcontroller determines a mask, extracts a k-bit value V by masking the sequence s with the mask, and compares the value V with V'. A device having.
9. A method for securely performing a random access procedure between user equipment and an access device in a wireless network, comprising modifying the beamforming of a reference signal, wherein the modification is The access device performs a process of rearranging the order in which the directional beams transmitting the reference signal are broadcast, The access device performs the process of renaming the corresponding beam index used to identify the beam. A method characterized by comprising at least one of the following.
10. The method according to claim 9, wherein the change is due to a small random angular change in the broadcast direction of the beam.
11. The method according to claim 9 or 10, further comprising a setup step, a reference signal received power RSRP of message 1 and / or message 3 in the random access procedure, and a modification of the directional beam in the random access procedure by adapting the transmit power in message 2 or message 4 based on at least one of the quality values reported by the user equipment in channel state information CSI.
12. The method according to claim 11, further comprising the step of lowering the priority of a user device or issuing an alarm if the pattern of at least one of the monitored RSRP measurement and CSI measurement deviates from a normal pattern.
13. The method according to any one of claims 9 to 12, further comprising a modification characterized in that the access device deactivates a given beam when it detects that the given beam is being used excessively frequently.
14. The said method, A step of monitoring whether any user device is attempting the random access procedure, The step of performing the change when no user device is executing the random access procedure, or when up to several million user devices are executing the random access procedure. The method according to any one of claims 9 to 13, further comprising:
15. The said method, Regular or periodic changes, and On-demand changes The method according to any one of claims 9 to 14, further comprising at least one of the above.
16. The method in question is subject to change. Receipt of change schedule from the managing entity, Mutual monitoring of changes in adjacent access devices, and Execution of changes or receipt of notifications via a communication interface The method according to any one of claims 9 to 15, further comprising the step of coordinating a plurality of access devices when performed by at least one of the following.
17. A method for adjusting a random access procedure initiated by a change in an access device, The user device retransmits message 1 of the random access procedure using a new priority beam, The user device reports its new priority beam, The steps include: the access device using a beam that best covers the user equipment based on the aforementioned modification; A method that includes at least one of the following.
18. A device for securely executing random access procedures, A beamforming-capable transmitter, A control unit that controls the beamforming of the transmitter and The device has, A process to rearrange the order in which directional beams transmitting a reference signal are broadcast, and The process of renaming the corresponding beam index used to identify the aforementioned beam. A device that introduces a change in the beamforming of the reference signal by at least one of the following.
19. A method for securely executing a random access procedure between user equipment and an access device in a wireless network, The steps include determining or receiving an encryption key K linked to the access device and the user equipment, A step of determining or receiving a sequence s of L bits, The steps are: Encrypting sequence s into V with encryption key K, The step of sending V and A method having
20. The method according to claim 19, further comprising the step of determining an encryption key K that depends on the physical channel characteristics between the user device and the access device.
21. The method according to claim 19, further comprising the step of receiving a public key associated with the access device.
22. A device for securely executing random access procedures, comprising a transmitter and a control unit, the device is Determine or receive the encryption key linked to the access device and user equipment. Determine or receive a sequence s of L bits, Encrypt sequence s with encryption key K into V, V transmission, Device.
23. A method for securely executing a random access procedure between user equipment and an access device in a wireless network, A step of monitoring whether the UE executing the random access procedure is within the communication range of the cell, A step of restricting access from outside the communication range of the cell to user equipment that performs the random access procedure. A method having
24. The method according to claim 23, wherein the monitoring step is performed based on timing advance parameters.
25. The said method, The steps include configuring the access device with the maximum allowable timing advance value, The steps include calculating the required timing advance value for the PRACH message, The steps include restricting access to PRACH messages that require a timing advance value greater than the maximum allowable timing advance value, The steps include: reporting an alarm when the PRACH message requires a timing advance value greater than the maximum allowable timing advance value; and The method according to claim 23 or 24, further comprising at least one of the above.
26. The method according to any one of claims 23 to 25, further comprising the step of monitoring the assigned TA value in the RAR message.
27. A device for securely executing random access procedures, wherein the device is A process to monitor whether the user device executing the aforementioned random access procedure is within the communication range of the cell, A process to restrict access from outside the communication range of the cell to user equipment that executes the random access procedure. A device including a device.
28. A network device for a wireless network, comprising the device described in any one of claims 7, 8, 18, 22, and 27.
29. A computer program comprising code that, when loaded onto a wireless device, causes the wireless device to perform steps according to claim 1, 9, 17, 19, or 23.