PROTECTION OF STRATUM COMMUNICATION WITHOUT ACCESS IN A WIRELESS COMMUNICATION NETWORK

MX430973BActive Publication Date: 2026-02-25TELEFONAKTIEBOLAGET LM ERICSSON (PUBL) +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
MX2021001534
Authority / Receiving Office
MX · MX
Patent Type
Patents
Current Assignee / Owner
Priority Date
2018-08-13
Filing Date
2021-02-05
Publication Date
2026-02-25
Estimated Expiration
2039-08-12

AI Technical Summary

Technical Problem

Existing wireless communication networks face challenges in efficiently updating Non-Access Stratum (NAS) keys while maintaining low signaling overhead and ensuring backward security, particularly during transitions between different generations of networks like 5G and 6G, without requiring primary authentication procedures.

Method used

Implementing horizontal key derivation to update NAS keys by deriving a new base key from the current base key, using conditions such as NAS message counts or time thresholds, and activating the new keys through a NAS Security Mode Command procedure, thereby avoiding the need for primary authentication and reducing signaling overhead.

Benefits of technology

This method efficiently updates NAS keys with minimal signaling overhead, ensuring secure transitions between different wireless communication network generations and maintaining backward security without the need for primary authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure MX430973B0
    Figure MX430973B0
Patent Text Reader

Abstract

Network equipment (16A) is configured for use in a wireless communication network. Network equipment (16A) is configured to detect one or more conditions under which the non-accessible stratum (NAS) keys (26A) that protect NAS communication between network equipment (16A) and a wireless device (12) must be updated. In response to the detection of one or more conditions, network equipment (16A) is configured to derive, from a base key (24A) from which the NAS keys (26A) were derived, a new base key (24B) from which new NAS keys (26B) will be derived. Network equipment (16A) is also configured to activate the new base key (24B).
Need to check novelty before this filing date? Find Prior Art

Description

PROTECTION OF UNSECTIONED LAYER COMMUNICATION IN A WIRELESS COMMUNICATION NETWORK TECHNICAL FIELD This application relates generally to a wireless communication network, and more specifically to the protection of non-access stratum (NAS) communication in that network. BACKGROUND OF THE INVENTION The non-accessible layer (NAS) is the highest layer of the control plane between a wireless device and a core network in a wireless communication system. The NAS supports, for example, mobility management and session management for a wireless device. Protecting NAS communication between the wireless device and the core network involves safeguarding the integrity and / or encryption of the communication. The wireless device and the core network must agree on the NAS keys to be used for this protection. However, the NAS keys must be updated or changed occasionally to prevent unauthorized key reuse. Maintaining agreement between the wireless device and the core network on the NAS keys, even when the NAS keys are to be changed, presents a significant challenge. This must be done in a way that robustly supports future generations of wireless communication networks and keeps signaling overhead low. BRIEF DESCRIPTION OF THE INVENTION Some of the methods described herein leverage horizontal key derivation to update the non-access stratum (NAS) keys that protect NAS communication in a wireless network. Since currently active NAS keys are derived from a currently active base key (e.g., the currently active Kamf), horizontal key derivation can involve deriving a new base key (e.g., a new Kamf) from the currently active base key and then deriving new NAS keys from the new base key. NAS keys can be updated in this way, for example, in anticipation of an NAS count for a NAS connection between a wireless device and network equipment, by resetting the count from a maximum value to an initial value.This, in turn, can protect the transfer of the wireless device's security context between different wireless communication networks, even networks of different generations (for example, a transfer between 5G and 6G networks). Furthermore, horizontal key derivation is more efficient in terms of control signaling than having to execute hrc Lnn / Lznz / E / YiAi primary authentication procedures or active native security contexts to update NAS keys. More specifically, the modalities herein include a method carried out by network equipment configured for use in a wireless communication network. The method comprises detecting one or more conditions under which the non-access stratum (NAS) keys protecting NAS communication between the network equipment and a wireless device must be updated. The method may also comprise, in response to the detection of one or more conditions, deriving, from a base key from which the NAS keys were derived, a new base key from which new NAS keys will be derived. The method in some modalities may also include activating the new base key. In some configurations, one or more conditions include a NAS count value for a NAS connection between the network equipment and the wireless device that falls within a certain threshold relative to a maximum NAS count value. In this case, the NAS count represents the number of NAS messages sent in a given direction over the NAS connection. Alternatively or in addition, the one or more conditions include one or more conditions that are detected before a NAS count value for a NAS connection between the hrc Lnn / Lznz / E / YiAi network equipment and the wireless device changes from a maximum value to an initial value. The NAS count tallies the number of NAS messages sent in a given direction across the NAS connection. In other modalities, one or more conditions include alternatively or additionally that the ÑAS keys have been used for at least a threshold period of time or a threshold number of times. In some modes, deriving the new base key involves deriving the new base key from the base key and a value from an NAS count that counts a number of NAS messages sent in a given direction through an NAS connection between the network equipment and the wireless device. In some modes, deriving the new base key involves calculating the new base key as the output of a key derivation function that takes a string and a key as inputs. In this case, the base key is passed to the key derivation function as the key, and a set of concatenated parameters is passed to the key derivation function as the string. The parameter set includes a NAS count value that tallies the number of NAS messages sent in a given direction over a NAS connection between the network equipment and the wireless device. In one mode, for example, the key derivation function is a Hash-Based Message Authentication Code (HMAC) function that uses a Secure Hash Algorithm (SHA) to hash the HMAC inputs into a string and a key. In some modes, activating the new base key involves performing a NAS Security Mode Command (SMC) procedure between the network equipment and the wireless device to establish a new NAS security context between the network equipment and the wireless device, which includes the new base key. In one mode, for example, performing the NAS SMC procedure involves transmitting a NAS SMC message to the wireless device that indicates a NAS count value, which tallies the number of NAS messages sent in a particular direction across a NAS connection between the network equipment and the wireless device. In some methods, the new base key is included in a new security context established between the network equipment and the wireless device. In this case, the method may also involve transferring the new security context to another network device. In some modalities, the method also involves transmitting or receiving NAS communication that is protected with new NAS keys. In some modes, the ÑAS count described above hrc Lnn / Lznz / E / YiAi is an uplink ÑAS count that counts the number of ÑAS messages sent in an uplink direction through the ÑAS connection, or the ÑAS count is a downlink ÑAS count that counts the number of ÑAS messages sent in a downlink direction through the ÑAS connection. In any of the above scenarios, the network equipment can implement an Access and Mobility (AME) function. In this case, the base key is a Kamf key, and the new base key is a new Kamf key. In some modes, deriving the new base key may involve deriving the new base key without running a primary authentication procedure or activating a native security context. In some versions, the method also involves incrementing a NAS count for a NAS connection between the network equipment and the wireless device before transferring a NAS security context for the wireless device to another network equipment. In this case, the detection, bypass, and activation described above are performed after this increment but before the transfer. The modalities in this document also include the corresponding devices, software, and media. For example, the modalities include hrc Lnn / Lznz / E / YiAi network equipment configured for use in a wireless communication network. The network equipment is configured (for example, via communication circuitry and processing circuitry) to detect one or more conditions under which the non-accessible stratum (NAS) keys protecting NAS communication between the network equipment and a wireless device must be updated; in response to the detection of one or more conditions, derive from a base key from which the NAS keys were derived; a new base key from which new NAS keys will be derived; and activate the new base key. The methods described herein also include a method implemented by a network team configured to implement an access and mobility function (AMF). This method may involve activating new non-access stratum keys (NAS) from horizontal Kamf derivation before an uplink or downlink NAS count is wrapped with a current security context. Here, horizontal Kamf derivation creates a new Kamf key from a currently active Kamf key. The modalities also include network equipment configured to implement an Access and Mobility Function (AMF). The network equipment is configured (for example, via communication and processing circuits) to activate new hrc Lnn / Lznz / E / YiAi non-access stratum (NAS) keys from horizontal Kamf derivation before an uplink or downlink NAS count is wrapped with a current security context. Horizontal Kamf derivation creates a new Kamf key from a currently active Kamf key. hrc Lnn / Lznz / E / YiAi BRIEF DESCRIPTION OF THE DRAWINGS Figure 1 is a block diagram of a wireless communication system 10 according to some modalities. Figure 2 is a logical flow diagram of a method carried out by a network team according to some modalities. Figure 3 is a logical flow diagram of a method carried out by a network team in accordance with other modalities. Figure 4A is a block diagram of a network equipment according to some modalities. Figure 4B is a block diagram of a network equipment according to other modalities. Figure 5 is a block diagram of a 5G (5GS) system according to some modalities. Figure 6 is a block diagram of a non-roaming architecture for interoperability between the 5G system (5GS) and the Evolved Packet Core (EPC) / Evolved Universal Mobile Telecommunications System (UMTS) (EUTRAN) terrestrial radio access according to some modalities. Figure 7 is a flowchart of horizontal key derivation calls for ÑAS key update according to some modalities. hrc Lnn / Lznz / E / YiAi DETAILED DESCRIPTION OF THE INVENTION Figure 1 shows a wireless communication system 10 according to some modalities. According to Figure 1, a wireless device 12 (for example, a user device) communicates with a radio access network (RAN) 14 through a radio interface 13 to access a core network (CN) 16 of the system 10. The CN 16, in turn, can connect the wireless device 12 to one or more data networks, such as the Internet. CN 16 includes network equipment 16A in a CN 16 control plane. In the control plane, network equipment 16A participates in non-access stratum (NAS) communication 18 with wireless device 12, for example, as part of supporting mobility management for wireless device 12. In these and other modes, NAS communication 18 can be used for system information transmission, location, NAS information transfer, access stratum (AS) security configuration, radio access capacity transfer, measurement and reporting configuration, and / or mobility control. Such NAS communication 18 can be carried out as NAS messages transferred over a NAS connection between wireless device 12 and network equipment 16A. In modalities where CN 16 is a 5G core network, the 16A network equipment can implement an access and mobility function (AME). Separately, wireless device 12 and network equipment 16A apply protection 20 to NAS communication 18, for example, in the form of integrity protection and / or encryption. Figure 1 shows that wireless device 12 and network equipment 16A maintain a security context 22A (for example, a 5G NAS security context) for wireless device 12. The security context 22A includes, among other things, a base key 24A. The base key 24A can be, for example, a Kamf key derived from a Kseaf anchor key in modes where network equipment 16A implements an AME. However, no matter the particular nature of the 24A base key, the wireless device 12 and the network equipment 16A derive NAS keys 26A from the 24A base key, for example, by deriving the 28A vertical key.The wireless device 12 and the network equipment 16A base the protection of ÑAS communication 18 on these ÑAS 26A keys. The hrc Lnn / Lznz / E / YiAi ÑAS 26A keys may include, for example, a ÑAS KNAsint key for integrity protection and a ÑAS KNAsenc key for encryption. The 16A network equipment, according to some modes, can detect one or more conditions under which the 26A ÑAS keys must be updated. Consider, for example, modes in which the 22A security context includes a 30A ÑAS count for a ÑAS connection between the 12 wireless device and the 16A network equipment. The 30A ÑAS count tallies the number of ÑAS messages sent in a specific direction (e.g., uplink or downlink) across a ÑAS connection. In this case, the one or more conditions in some modes include a 30A ÑAS count value that is close to wrapping around a maximum value around an initial value. The one or more conditions can be defined, for example, as a 30A ÑAS count value that falls within a certain threshold (X) of the maximum value.Alternatively or in addition, the one or more conditions may include one or more conditions that are detected before the ÑAS 30A count value is reached. In other forms, the one or more conditions may include that the ÑAS 2 6A keys have been used for at least a threshold period of time or a threshold number of times. Regardless of the specific hrc Lnn / Lznz / E / YiAi conditions that trigger the update of the ÑAS 26A keys, network equipment 16A, in response to the detection of these conditions, derives a new base key 24B from the base key 24A upon which the ÑAS 26A keys were derived. This new base key 24B, as shown in Figure 1, can be included in a new security context 22B for wireless device 12. Alternatively, network equipment 16A can derive the new base key 24B from the (old) base key 24A using horizontal key derivation 32. Specifically, network equipment 16A (horizontally) derives the new base key 24B from the (old) base key 24A without executing a primary authentication procedure or activating a native security context.This key derivation is appropriate from a control signaling overload perspective, since horizontal key derivation requires less control signaling than, for example, primary authentication. More specifically, deriving the new 24B base key can involve deriving the new 24B base key from the (old) 24A base key and a value from the 30A ÑAS count (e.g., an uplink ÑAS count value). As an example, the new 24B base key can be calculated as the output of a key derivation function (KDF) that takes a string and a key as inputs. The (old) 24A base key can be entered into the KDF as the hrc key Lnn / Lznz / E / YiAi input. A set of parameters can be concatenated together and entered into the KDF as the input string. The parameter set can include a value from the 30A ÑAS count. Consider an example where the (old) base key 24A is a Kamf key, the new base key 24B is a Kamf' key, and the KDF is a Hash-Based Message Authentication Code (HMAC) function that uses a Secure Hash Algorithm (SHA) to hash the HMAC function's string and key inputs. In this case, the new base key Kamf' can be calculated as Kamf' = HMACSHA-256(Key, S), where Key = Kamf and S is the input string constructed from a set of parameters that includes the ÑAS count value 30A. Regardless of the specific way in which network equipment 16A derives the new base key 24B from the (old) base key 24A, the new NAS keys 26B must be derived from this new base key 24B, for example, by vertical key derivation 28B. And wireless device 12 and network equipment 16A must change to base the protection 20 of NAS communication 18 on these new NAS keys 26B. Network equipment 16A is further configured to activate the new base key 24B, for example, so that the new base key 24B (and the new NAS keys 26B) can be used for protection. As shown in Figure 1, hrc Lnn / Lznz / E / YiAi, for example, the new base key 24B can be included in a new security context 22B. Network equipment 16A can activate the new base key 24B by establishing the new security context 22B between network equipment 16A and wireless device 12, which includes the new base key 24B. Network equipment 16A can establish the new security context 22B by performing a Security-AS Mode Command (SMC) procedure between network equipment 16A and wireless device 12.This ÑAS SMC procedure may involve network equipment 16A transmitting an ÑAS SMC message to wireless device 12 indicating the value of ÑAS count 30A, for example, on which to base a ÑAS count 30B for the new security context 22B. However, it should be noted that in some modes, network equipment 16A performs the processing described above in conjunction with and / or in anticipation of transferring a security context for wireless device 12 to another network equipment (for example, as part of an AME change resulting from idle mode mobility or a handover from connected mode). In these and other modes, before transferring a security context for wireless device 12, network equipment 16A may increment the value of a NAS count for a NAS connection between network equipment 16A and wireless device 12, for example, to protect the hrc Lnn / Lznz / E / YiAi security context transfer and / or to ensure backward security.In this case, network equipment 16A can detect one or more conditions for horizontal key derivation of the new base key 24B after, such as as part of, or in anticipation of, increasing the NAS count 30A. After increasing the NAS count 30A, network equipment 16A can therefore perform horizontal key derivation to derive the new base key 24B, activate the new base key 24B, and then transfer the new security context 22B for wireless device 12. In particular, some modes protect this transfer of the new security context 22B between different wireless communication networks, even networks of different generations (for example, a transfer between 5G and 6G networks). In view of the variations and modifications described above, Figure 2 represents a method implemented by network equipment 16A (e.g., configured to implement an AME) for use in a wireless communication network according to particular modalities. The method includes detecting one or more conditions under which the NAS keys 26A (which protect the NAS communication between network equipment 16A and wireless device 12) must be updated (Block 110). The condition(s) may include, for example, a NAS count value of 30A for a NAS connection between network equipment 16A and wireless device 12 within a certain threshold from a maximum NAS count value of 30A.Separately, the method also includes, in response to the detection of one or more conditions, deriving, from a 24A base key from which the 26A ÑAS keys were derived, a new 24B base key from which new 26B ÑAS keys will be derived (Block 120). The method shown may also include the activation of the new 24B base key (Block 130). In some modes, the method may also include transferring a new 22B security context, which includes the new 24B base key (Block 140), to another network device (for example, one configured to implement a new AME). In fact, in some modes, the method may be performed in anticipation of such a transfer. For example, in some modes, the security context transfer requires incrementing the NAS count 30A, for example, to protect the transfer and / or provide backward security. In such a case, the method shown may also include incrementing the NAS count 30A (Block 105). However, in some modes, one or more conditions include a value of a 30A ÑAS count for an ÑAS connection between the network equipment 16A and the wireless device 12 within a certain threshold from a maximum hrc Lnn / Lznz / E / YiAi value of the 30A ÑAS count, where the 30A ÑAS count counts a number of ÑAS messages sent in a certain direction through the ÑAS connection. Alternatively or in addition, the one or more conditions may include one or more conditions that are detected before a value of an ÑAS count 30A for an ÑAS connection between network equipment 16A and wireless device 12 passes from a maximum value to an initial value, wherein ÑAS count 30Ά counts a number of ÑAS messages sent in a certain direction through the ÑAS connection. In some modalities, one or more conditions include that the ÑAS 2 6A keys have been used for at least a threshold time period or a threshold number of times. In some modes, deriving the new 24B base key involves deriving the new 24B base key from the 24A base key and a value of an NAS count 30A that counts a number of NAS messages sent in a certain direction through a NAS connection between network equipment 16A and wireless device 12. In some methods, deriving the new base-24 key involves calculating the new base-24 key as the output of a key derivation function that takes a string and a key as inputs. In this case, the base-24 key is input into the key derivation function as the key. hrc Lnn / Lznz / E / YiAi A set of concatenated parameters is entered into the key derivation function as the string. This parameter set includes a NAS count value (30A) that tallies the number of NAS messages sent in a specific direction over a NAS connection between network equipment 16A and wireless device 12. In such a configuration, for example, the key derivation function is a Hash-Based Message Authentication Code (HMAC) function that uses a Secure Hash Algorithm (SHA) to hash the HMAC function inputs in the form of a string and a key. In some modes, activating the new 24B base key involves performing a NAS Security Mode Command (SMC) procedure between network equipment 16A and wireless device 12 to establish a new NAS security context between network equipment 16A and wireless device 12 that includes the new 24B base key. In one mode, for example, performing the NAS SMC procedure involves transmitting a NAS SMC message to wireless device 12 that indicates a value for a NAS counter 30A, which counts the number of NAS messages sent in a particular direction across a NAS connection between network equipment 16A and wireless device 12. In some modalities, the method may also include transmitting or receiving NAS communication that is protected with new NAS 26B keys. hrc Lnn / Lznz / E / YiAi In some modes, the 30A ÑAS count is an uplink ÑAS count that counts a number of ÑAS messages sent in an uplink direction through the ÑAS connection, or the 30A ÑAS count is a downlink ÑAS count that counts a number of ÑAS messages sent in a downlink direction through the ÑAS connection. In some configurations, the 16A network equipment implements an Access and Mobility (AME) function. In this case, the base key 24A is a Kamf key, and the new base key 24B is a new Kamf key. In some modes, deriving the new 24B base key involves deriving the new 24B base key without executing a primary authentication procedure or activating a native security context. In some versions, the method also involves incrementing a NAS count value 30A for a NAS connection between network equipment 16A and wireless device 12 before transferring a NAS security context for wireless device 12 to another network device. In this case, detection, bypass, and activation occur after the increment but before the transfer. Alternatively, or in addition, Figure 3 depicts a method implemented by network equipment 16A configured to implement an Access and Mobility Function (AME) according to hrc Lnn / Lznz / E / YiAi with other specific modalities. This method involves activating new NAS keys 26B derived from horizontal Kamf before a NAS COUNT uplink or downlink 30A is wrapped with a current security context 22A (Block 210). Similarly, in some modalities, the method may also involve transferring a new security context 22B, including the horizontally derived Kamf (Block 220), to another network equipment (e.g., implementing a new AMF). In fact, in some modalities, the method may be implemented in anticipation of such a transfer.For example, in some modes, the transfer of the security context requires incrementing the uplink or downlink NAS count, for example, to protect the transfer and / or provide backward security. In such a case, the method shown may also include incrementing the uplink or downlink NAS count (Block 205). Note that the 16A network equipment described above can perform the methods herein and any other processing by implementing any means, module, unit, or functional circuit. In one embodiment, for example, the 16A network equipment comprises respective circuits configured to perform the steps shown in the method figures. The circuits or circuits in this respect may comprise circuits dedicated to performing certain functional processing and / or one or more microprocessors along with memory. For example, the circuit may include one or more microprocessors or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), special-purpose digital logic, and the like.Processing circuits can be configured to execute program code stored in memory, which may include one or more types of memory, such as read-only memory (ROM), random-access memory, cache memory, flash memory devices, optical storage devices, etc. The program code stored in memory may include program instructions for executing one or more telecommunications and / or data communication protocols, as well as instructions for carrying out one or more of the techniques described in this document, in various modes. In memory-based modes, the memory stores program code that, when executed by one or more processors, performs the techniques described in this document. Figure 4A, for example, illustrates network equipment 16A implemented according to one or more modes. As shown, network equipment 16A includes a processing circuit 310 and a communication circuit 320. The communication circuit 320 is configured to transmit and / or receive information to and / or from one or more nodes or devices, for example, via any communication technology. The processing circuit 310 is configured to perform the processing described above (for example, in Figures 2 and / or 3), such as executing instructions stored in memory 330. The processing circuit 310 may, in this respect, implement certain functional media, units, or modules. Figure 4B illustrates a schematic block diagram of network equipment 16A according to several other modalities. As shown, network equipment 16A implements various functional means, units, or modules, for example, through the processing circuit 310 in Figure 4A and / or by means of software code. These functional means, units, or modules, for example, to implement the method in Figure 2, include a detection unit or module 410 to detect one or more conditions under which the ÑAS 26A keys (which protect the ÑAS 18 communication between network equipment 16A and wireless device 12) must be updated. A derivation unit or module 420 can also be included to, in response to the detection of one or more conditions, derive, from a 24A base key in which the 26A ÑAS keys were derived, a new 24B base key in which new 26B ÑAS keys will be derived.You can also include a 430 activation unit or module in hrc Lnn / Lznz / E / YiAi to activate the new 24B base key. Those skilled in the technology will also appreciate that the modalities presented herein also include the corresponding software programs. A computer program comprises instructions that, when executed on at least one processor of the 16A network equipment, cause the 16A network equipment to perform any of the respective processes described above. A computer program in this respect may comprise one or more code modules corresponding to the media or units described above. The formats also include a carrier that contains the computer program. This carrier may comprise an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium. In this sense, the modalities in this document also include a computer program product stored on a non-transient computer-readable medium (storage or recording) and comprising instructions that, when executed by a processor of the 16A network equipment, cause the 16A network equipment to function as described above. The modes further include a software product comprising program code portions hrc Lnn / Lznz / E / YiAi to carry out the steps of any of the modes herein when the software product is executed by a computing device. This software product may be stored on a computer-readable recording medium. Although some modes in this document are described as applying to NAS communication, other modes in this document extend to any control plane communication between the wireless device 12 and the network equipment 16A. Additional modes will now be described. At least some of these modes may be described as applicable in certain contexts and / or types of wireless networks for illustrative purposes, but the modes are equally applicable in other contexts and / or types of wireless networks not explicitly described. Currently, 3GPP is developing standards for 5th generation (5G) wireless communication systems, also known as next-generation (NG) systems. 5G is expected to support many new scenarios and use cases and be an enabler for the Internet of Things (IoT). NG systems are expected to provide connectivity to a wide range of new devices such as sensors, smart wearables, vehicles, machines, and more. Flexibility would then be a key property in NG systems. This is reflected in the security requirement for network access, which demands support for alternative authentication methods and different types of credentials than the usual Authentication and Key Agreement (AKA) credentials previously provisioned by the operator and securely stored on the Universal Integrated Circuit Card (UICC).This allows factory or business owners to leverage their own identity and credential management systems for authentication and access network security. The architecture working group of the 3G Partnership Project (3GPP) has finalized the architecture of the 5G systems illustrated in Figure 5, which is from TS 23.501. This is the architecture of the non-roaming 5G system in reference point representation. To ensure a smooth rollout of 5G systems, the 3GPP architecture group is currently working on supporting interoperability between 4G (legacy) and 5G systems. This will enable not only seamless mobility between systems but also seamless handovers. Interworking involves network entities and data objects belonging to different generation systems. The final non-roaming architecture for interworking between the 5G system (5GS) and the Evolved Packet Core (EPC) / Evolved Mobile Telecommunications System (UMTS) terrestrial radio (E-UTRAN) hrc Lnn / Lznz / E / YiAi access is shown in Figure 6 of TS 23.501. The general principle has been to adapt to the previous generation to minimize the impact on legacy infrastructure and ensure a smooth deployment of the new one. Consequently, the security mechanisms for interworking must minimize or avoid the impact on 4G systems. Consequently, the new generation must adapt to the previous generation. However, this should not impose restrictions or limitations on 5G security mechanisms beyond interoperability. More precisely, interoperability with 4G should not impede the independent evolution of 5G security, for example, by introducing new cryptographic algorithms, increasing the size of Media Access Control (MAC) fields, and so on. In other words, security mechanisms for interoperability should not prevent the independent evolution of 5G security. Currently, certain challenges exist. Security mechanisms for interoperability should provide the means to protect the transfer of the user equipment (UE) context from the source system to the target systems. How this transfer is triggered depends on whether the UE is idle or active. In idle-mode mobility, the transfer is triggered by a No Access Stratum (NAS) message from the UE to the serving core network (CN) entity in the target system. In active-mode mobility (handovers), the transfer is triggered by an internal message (handover required) from the radio access network (RAN) to the serving CN entity within the source system. Essentially, the source system initiates the transfer. The security mechanism must also provide the means to obtain new, fresh keys for the target system. For this problem, one principle observed during the development of 5G is backward security. Backward security, as defined in TS 33.501, is the property that, for an entity with knowledge of a key Kn, it is computationally infeasible to compute any previous Kn-m(m>0) from which Kn is derived. To achieve backward security in 5GS during an Access and Mobility Role (AME) change, the source AME can derive a new Kamf key for the target AME using the current key and one of the ÑAS counts. More precisely, during idle-mode mobility, the uplink ÑAS count is used, and for handovers involving an AMF change, the downlink ÑAS count is used. To mitigate the reuse of hrc Lnn / Lznz / E / YiAi keys in case of a handover failure, the source AMF always increments the downlink ÑAS count before transferring the UE context to the target AMF. In the event of a handover failure where the UE ends up back at the originating AMF, this mechanism ensures that the available ÑAS downlink COUNT value is recent and can be safely used to derive another Kamf. In the evolved packet system (EPS), the situation is different because, as described in TS 33.401, the source Mobility Management (MME) always transfers the ÑAS COUNTS without any changes. However, the source MME always generates a new next hop (NH) and increments the associated next hop chaining counter (NCC) before the transfer during a handover involving an MME change. Therefore, during interworking with 5GS, there is a risk that the received ÑAS downlink COUNT will not change during a handover failure followed by a new EPS-to-5GS handover procedure. This is why, for legacy EPS-to-5GS interworking, the NH parameter can be used to derive the Kasme Kamf key instead of the ÑAS downlink COUNT, as described in TS 33.501. Since the NH parameter is always up-to-date, it prevents key reuse. In 5GS, increasing the downlink count hrc Lnn / Lznz / E / YiAi of NAS before context transfer between AMFs during handovers will facilitate the introduction of a clean and simple solution for interoperability with future systems. In such a future scenario, a source AME is expected to behave as if it were interacting with a target AME, even though it might be a completely different function. However, this target function will always have the means to derive a new key from the received Kamf key. One problem relates to how to handle ÑAS count wrappers. AMEs are required to activate new ÑAS keys from a primary authentication run or activate the native security context, which has sufficiently low ÑAS COUNT values, before the uplink or downlink ÑAS COUNT is wrapped with the current security context. Problematically, then, the only way an AME can currently remedy this is by running a primary authentication, thereby establishing a new Kamf. Certain aspects of the present invention and its embodiments may provide solutions to these or other challenges. Some embodiments propose that a source AME can trigger a horizontal key derivation Kamf to update the keys whenever necessary, such as when the ÑAS counts are about to be reset. hrc Lnn / Lznz / E / YiAi Certain modes may provide one or more of the following technical advantages. Some modes have one or more of the following advantages: (1) they avoid the need for a primary authentication run, thus avoiding the signaling overhead that would have been incurred; (2) they allow updating the Kamf key and all subsequently derived ÑAS and AS keys. Some approaches propose using the horizontal key derivation function introduced for the Kamf key to update ÑAS keys or reset ÑAS counts when they are about to be reset. To activate a new key of this type, it may be necessary to run a ÑAS security mode procedure so that the UE and AME synchronize and begin using the security context based on the newly derived key. Figure 7 illustrates some approaches in this regard with respect to horizontal Kamf key derivation for ÑAS key updates. In step 0, it is assumed that the UE is registered and that the UE and the AME have already established and activated a NAS security context. At one point, in step 1, the UE determines that it must initiate some NAS signaling, for example, to access a service (service request) or follow a handover that involves a change of AME to register at the new destination hrc Lnn / Lznz / E / YiAi AME (registration request). In step 2, the UE sends an initial ÑAS message to re-establish the ÑAS connection with the network. At one point, in step 3, the AME determines that the ÑAS key needs updating, for example, because the ÑAS counts are about to be reset or because of a local operator policy to update ÑAS keys after a certain time or amount of use. The AMF derives a new Kamf key using horizontal Kamf derivation as described for the idle-mode mobility case in TS 33.501, that is, using the current ÑAS uplink COUNT value. The difference here is that this newly derived Kamf key must be used by the same AMF, whereas in the mobility case, it is delivered to the destination AMF. In step 4, to activate the newly derived Kamf key, the AMF triggers a ÑAS SMC execution that includes the current ÑAS uplink COUNT value as described for the idle-mode mobility case in TS 33.501. The UE obtains a new Kamf key in the same way as the AMF using the ÑAS uplink COUNT value included in the ÑAS SMC. As a result of the successful completion of step 4, the UE and AMF will share a new ÑAS security context with new keys and reset ÑAS COUNTS. hrc Lnn / Lznz / E / YiAi In the case of multiple ÑAS connections established through 3GPP access and non-3GPP access on the same AMF, the AMF can: (1) use the newly derived Kamf on a second ÑAS connection by running a ÑAS SMC executed on the second ÑAS connection including the ngKSI of the newly derived Kamf key or (2) the AMF and UE can use the newly derived Kamf on all ÑAS connections immediately at the same time. In some modes, the ÑAS COUNT is either the 24-bit ÑAS UL COUNT value or the 24-bit ÑAS DL COUNT value, depending on the address, which is associated with the current ÑAS connection identified by the value used to form the CARRIER input. A ÑAS COUNT can be constructed as: ÑAS COUNT = ÑAS OVERFLOW | ÑAS SQN. Here, ÑAS OVERFLOW is a 16-bit value that increments each time the ÑAS SQN increments from its maximum value. And ÑAS SQN is the 8-bit sequence number included in each ÑAS message. A wireless communication system in this document may comprise and / or interact with any type of communication, telecommunications, data, cellular, and / or radio network, or other similar system. In some modalities, the wireless communication system may be configured to operate according to specific standards or other types of predefined rules or procedures. Therefore, particular modalities of the wireless communication system may implement communication standards, such as the Global System for Mobile Communications (GSM), the Universal System for Mobile Telecommunications (UMTS), Long Term Evolution (LTE), Narrowband Internet of Things (NB-IoT), and / or other suitable 2G, 3G, 4G, or 5G standards; wireless local area network (WLAN) standards, such as the IEEE 802 standards.11; and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability Standards for Microwave Access (WiMax), Bluetooth, Z-Wave and / or ZigBee. The wireless communication system may comprise one or more backhaul networks, core networks, IP networks, public switched telephone networks (PSTNs), packet data networks, optical networks, wide area networks (WANs), local area networks (LANs), wireless local area networks, area networks (WLANs), wired networks, wireless networks, metropolitan area networks, and other networks to enable communication between devices. As used in this document, 16A network equipment refers to equipment capable, configured, arranged, and / or operable to communicate directly or indirectly with a wireless device and / or other network nodes or equipment in the wireless communication system to enable and / or provide wireless access to the hrc Lnn / Lznz / E / YiAi wireless device and / or to perform other functions (e.g., management) in the wireless communication system. Examples of network equipment include, but are not limited to, equipment in a core network of the wireless communication system to implement a Mobility Management Entity (MME) or an Access and Mobility (AME) function.However, more generally, network equipment can represent any suitable device (or group of devices) capable, configured, arranged and / or operable to enable and / or provide a wireless device with access to the wireless communication system or to provide some service to a wireless device that has accessed the wireless communication system. As used in this document, a wireless device (WD) refers to a device capable, configured, arranged, and / or operable to communicate wirelessly with network equipment and / or other wireless devices. Wireless communication may involve the transmission and / or reception of wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for transmitting information through the air. In some configurations, a WD may be configured to transmit and / or receive information without direct human interaction. For example, a WD may be designed to transmit information to a network on a predetermined schedule (hrc Lnn / Lznz / E / YiAi), when triggered by an internal or external event, or in response to network requests.Examples of a wireless device include, but are not limited to, a smartphone, a mobile phone, a user equipment (UE), a cell phone, a voice over IP (VoIP) phone, a wireless local loop phone, a desktop computer, a personal digital assistant (PDA), a wireless camera, a gaming console or device, a music storage device, a playback device, a handheld terminal device, a wireless endpoint, a mobile station, a tablet, a laptop computer, laptop embedded equipment (LEE), laptop mounted equipment (LME), a smart device, customer premises wireless equipment (CPE), a vehicle mounted wireless terminal device, etc.A Device Warehouse (WD) can support device-to-device (D2D) communication, for example, by implementing a 3GPP standard for sidelink communication, vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2X), and in this case, it can be called a D2D communication device. As another specific example, in an Internet of Things (IoT) scenario, a WD can represent a machine or other device that performs monitoring and / or measurements and transmits the results of such monitoring and / or measurements to another WD and / or a network node. In this case, the WD can be a machine-to-machine (M2M) device, which in a 3GPP context can be called an MTC device. As a particular example, the WD can be a UE that implements the 3GPP Narrowband Internet of Things (NB-IoT) standard.Specific examples of such machines or devices include sensors, measuring devices such as power meters, industrial machinery, or household or personal appliances (e.g., refrigerators, televisions, etc.), and personal wearable devices (e.g., watches, fitness trackers, etc.). In other scenarios, a WD may represent a vehicle or other equipment capable of monitoring and / or reporting its operational status or other functions associated with its operation. A WD as described above may represent the endpoint of a wireless connection, in which case the device may be called a wireless terminal. Furthermore, a WD as described above may be mobile, in which case it may also be called a mobile device or mobile terminal. Any appropriate step, method, feature, function, or benefit described herein may be carried out through one or more functional units or modules of one or more virtual appliances. Each virtual appliance may comprise several of these functional units. These functional units may be implemented by processing circuits, which may include one or more hrc Lnn / Lznz / E / YiAi microprocessors or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), special-purpose digital logic, and the like. The processing circuits may be configured to execute program code stored in memory, which may include one or more types of memory, such as read-only memory (ROM), random-access memory (RAM), cache memory, flash memory devices, optical storage devices, and so on.The program code stored in memory includes program instructions for executing one or more telecommunications and / or data communication protocols, as well as instructions for carrying out one or more of the techniques described herein. In some implementations, processing circuits may be used to enable the respective functional unit to perform the corresponding functions in accordance with one or more embodiments of the present invention. Generally, all terms used in this document should be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or implied by the context in which they are used. All references to an element, apparatus, component, means, step, etc., should be clearly interpreted as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any of the methods described in this document do not have to be carried out in the exact order stated, unless a step is explicitly described as following or preceding another step and / or it is implied that one step must follow or precede another. Any feature of any of the modalities described herein may be applied to any other modality, where appropriate.Furthermore, any advantage of any of the modalities may apply to any other modalities and vice versa. Other objectives, characteristics, and advantages of the attached modalities will become clear from the description. The term unit may have a conventional meaning in the field of electronics, electrical devices and / or electronic devices and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, solid-state logic and / or discrete devices, computer programs or instructions to carry out the respective tasks, procedures, calculations, outputs and / or visual presentation functions, etc., such as those described in this document. Some of the modalities covered in this document are described more fully with reference to the accompanying drawings. However, other modalities are included within the scope of the subject matter described herein. The subject matter described should not be interpreted as being limited solely to the modalities set forth in this document; rather, these modalities are provided by way of example to convey the scope of the subject matter to those skilled in the art. hrc Lnn / Lznz / E / YiAi

Claims

1. A method carried out by a network equipment (16A) configured for use in a wireless communication network, the method comprising: detecting (110) one or more conditions under which the non-access stratum (NAS) keys (26A) protecting NAS communication between the network equipment (16A) and a wireless device (12) should be updated; in response to the detection of the one or more conditions, deriving (120), from a base key (24A) from which the NAS keys (26A) were derived, a new base key (24B) from which new NAS keys (26B) are to be derived; and activating (130) the new base key (24B).

2. The method according to any of claims 1-2, wherein the one or more conditions include one or more conditions that are detected before a value of an NAS count for an NAS connection between the network equipment (16A) and the wireless device (12) passes from a maximum value to an initial value, wherein the NAS count counts a number of NAS messages sent in a certain direction through the NAS connection.

3. The method according to any of claims 1-2, wherein said derivation comprises deriving the new base key (24B) from the base key (24A) and a value of an NAS count that counts a number of NAS messages sent in a certain direction through an NAS connection between the network equipment (16A) and the wireless device (12).

4. The method according to any of claims 1-3, wherein said derivation comprises calculating the new base key (24B) as an output of a key derivation function taking a string and a key as inputs, wherein the base key (24A) is entered into the key derivation function as said key, wherein a set of parameters concatenated together is entered into the key derivation function as said string, wherein the set of parameters includes a value of an NAS count that counts a number of NAS messages sent in a certain direction through an NAS connection between the network equipment (16A) and the wireless device (12).

5. The method according to claim 4, wherein the key derivation function is a hash-based message authentication code (HMAC) function that uses a secure hash algorithm (SHA) to hash inputs to the HMAC function in the form of a string and a key.

6. The method according to any of claims 1-5, wherein said activation comprises carrying out a NAS hrc Lnn / Lznz / E / YiAi (SMC) security mode command procedure between the network equipment (16A) and the wireless device (12) to establish between the network equipment (16A) and the wireless device (12) a new NAS security context that includes the new base key (24B).

7. The method according to claim 6, wherein carrying out the NAS SMC procedure comprises transmitting an NAS SMC message to the wireless device (12) indicating a value of an NAS count that counts a number of NAS messages sent in a certain direction through an NAS connection between the network equipment (16A) and the wireless device (12).

8. The method according to any of claims 1-7, wherein the new base key (24B) is included in a new security context established between the network equipment (16A) and the wireless device (12), and wherein the method further comprises transferring the new security context to other network equipment.

9. The method according to any of claims 1-8, further comprising transmitting or receiving NAS communication that is protected with new NAS keys (26B).

10. The method according to any of claims 1-9, wherein the network equipment (16A) implements an access and mobility function (AMF), wherein the base key (24A) is a Kamf key, and wherein the new hrc Lnn / Lznz / E / YiAi base key (24B) is a new Kamf key.

11. The method according to any of claims 1-10, wherein deriving the new base key (24B) comprises deriving the new base key (24B) without executing a primary authentication procedure or activating a native security context.

12. The method according to any of claims 1-11, further comprising incrementing a value of an NAS count for an NAS connection between the network equipment (16A) and the wireless device (12) before transferring an NAS security context for the wireless device (12) to another network equipment, and wherein said detection, derivation, and activation are carried out after said increment but before said transfer.

13. Network equipment (16A) configured for use in a wireless communication network, the network equipment (16A) configured to: detect one or more conditions under which the non-access stratum (NAS) keys (26A) protecting NAS communication between the network equipment (16A) and a wireless device (12) should be updated; in response to the detection of the one or more conditions, derive, from a base key (24A) from which the NAS keys (26A) were derived, a new base key (24B) from which new NAS keys (26B) will be derived; and hrc Lnn / Lznz / E / YiAi activate the new base key (24B).

14. The network equipment according to claim 13, configured to carry out the method according to any of claims 2-12.

15. Network equipment (16A) configured for use in a wireless communication network, wherein the network equipment (16A) comprises: communication circuit (320); and processing circuit (310) configured to: detect one or more conditions under which the non-access stratum (NAS) keys (26A) protecting NAS communication between the network equipment (16A) and a wireless device (12) should be updated; in response to the detection of the one or more conditions, derive, from a base key (24A) from which the NAS keys (26A) were derived, a new base key (24B) from which new NAS keys (26B) will be derived; and activate the new base key (24B).

16. The network equipment according to claim 15, wherein the network equipment (16A) is configured to carry out the method according to any of claims 2-12.

17. A computer program comprising instructions that, when executed by at least one network equipment processor (16A), cause the hrc Lnn / Lznz / E / YiAi network equipment (16A) to carry out the method in accordance with any of claims 1-12.

18. A carrier containing the computer program according to claim 17, wherein the carrier is an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium.

19. A method carried out by a network equipment (16A) configured to implement an access and mobility function (AMF), the method comprising: activating (210) new non-access stratum (NAS) keys (26B) from horizontal Kamf derivation before a NAS uplink or downlink is wrapped with a current security context, wherein the horizontal Kamf derivation derives a new Kamf key from a currently active Kamf key.

20. Network equipment (16A) configured to implement an access and mobility function (AMF), the network equipment (16A) configured to: activate new non-access stratum (NAS) keys (26B) from horizontal Kamf derivation before an uplink or downlink COUNT of NAS is wrapped with a current security context, wherein horizontal Kamf derivation derives a new Kamf key from a currently active Kamf key.

21. Network equipment (16A) configured to implement hrc Lnn / Lznz / E / YiAi an access and mobility function (AMF), wherein the network equipment (16A) comprises: communication circuits (320); and processing circuits (310) configured to activate new non-access stratum (NAS) keys (26B) from horizontal Kamf derivation before an uplink or downlink COUNT of NAS is wrapped with a current security context, wherein the horizontal Kamf derivation derives a new Kamf key from a currently active Kamf key.

22. A computer program comprising instructions that, when executed by at least one network equipment processor (16A), cause the network equipment (16A) to carry out the method according to claim 19.

23. A carrier containing the computer program according to claim 22, wherein the carrier is an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium.