Method and apparatus for supporting security establishment in device-to-device relay communication
Patent Information
- Application Number
- PCT/KR2024/000184
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-02-10
- Filing Date
- 2024-01-04
- Publication Date
- 2025-05-22
AI Technical Summary
In 5G wireless communication systems, establishing secure relay connections between terminals is challenging due to the need for both hop-to-hop and end-to-end security, which can be inefficient and prone to malicious attacks like Man-in-the-Middle (MITM) when security policies and methods are inconsistent, leading to difficulties in establishing smooth connections and ensuring data integrity and confidentiality.
A method and device that enable terminals to negotiate and establish inter-hop and end-point security methods, allowing for efficient relay communication by obtaining and relaying security information between terminals, thereby providing hop-to-hop and end-to-end security, reducing unnecessary security measures and preventing malicious attacks.
This approach enhances the efficiency of relay communication by safely protecting data from malicious users while ensuring secure data transmission through consistent security policies, reducing the load and time required for establishing connections.
Smart Images

Figure KR2024000184_22052025_PF_FP_ABST
Abstract
Description
Method and device for supporting security establishment in terminal-to-terminal relay communication
[0001] The present disclosure relates to a method and device for supporting security establishment in terminal-to-terminal relay communication of a wireless communication system.
[0002] Specifically, the present disclosure relates to a method and device for establishing hop-to-hop security and end-to-end security by allowing terminals establishing a terminal-to-terminal relay connection to negotiate a method for hop-to-hop security with a relay terminal and a method for end-to-end security between two terminals constituting an end point.
[0003] To meet the growing demand for wireless data traffic following the commercialization of 4G (4th generation) communication systems, efforts are being made to develop improved 5G (5th generation) communication systems, or pre-5G communication systems. For this reason, 5G communication systems, or pre-5G communication systems, are also referred to as "Beyond 4G Network" communication systems or "Post-LTE" systems.
[0004] To achieve high data rates, 5G communication systems are being considered for implementation in ultra-high frequency (mmWave) bands (e.g., the 60 GHz band). To mitigate radio path loss and increase the transmission range of radio waves in ultra-high frequency bands, beamforming, massive MIMO (massive MIMO), full-dimensional MIMO (FD-MIMO), array antennas, analog beamforming, and large-scale antenna technologies are being discussed in 5G communication systems.
[0005] Additionally, to improve the network of the system, technologies such as evolved small cells, advanced small cells, cloud radio access networks (cloud RAN), ultra-dense networks, device-to-device communication (D2D), wireless backhaul, moving networks, cooperative communication, CoMP (Coordinated Multi-Points), and interference cancellation are being developed in 5G communication systems.
[0006] In addition, advanced coding modulation (ACM) methods such as FQAM (Hybrid FSK and QAM Modulation) and SWSC (Sliding Window Superposition Coding), as well as advanced access technologies such as FBMC (Filter Bank Multi Carrier), NOMA (non-orthogonal multiple access), and SCMA (sparse code multiple access) are being developed in 5G systems.
[0007] As described above, with the advancement of wireless communication systems, 5G systems can support terminal-to-terminal relay connection services, enabling two terminals to communicate via a relay terminal. Meanwhile, the two terminals constituting the end point and the relay terminal that relays their data require various methods for hop-by-hop security (HbH security) and end-to-end security (E2E security), and thus establish hop-by-hop and end-to-end security.
[0008] Based on the discussion described above, the present disclosure seeks to provide a method and device capable of providing smooth efficiency of service in a wireless communication system.
[0009] In a 5G system, a terminal-to-terminal relay connection service can be supported, allowing two terminals to communicate via a relay terminal. Terminals establishing a terminal-to-terminal relay connection (e.g., an end terminal and a relay terminal) may require hop-to-hop and end-to-end security to protect data. However, considering the size and amount of data transmitted and received between the terminals, applying both hop-to-hop and end-to-end security may be unnecessary to reduce significant time and load based on the related processes. Meanwhile, if terminals establishing a terminal-to-terminal relay connection (e.g., an end terminal and a relay terminal) do not agree on a common hop-to-hop and end-to-end security method, smooth connection establishment may be difficult. Furthermore, data integrity and / or confidentiality protection may be invalidated during a terminal-to-terminal relay connection due to reasons such as inconsistencies in the security policies and methods required by the terminals. In such cases, a malicious relay terminal may launch a man-in-the-middle (MITM) attack between the end terminals.
[0010] Accordingly, the present disclosure provides a method for terminals to discuss hop-by-hop security and end-to-end security methods so as to safely protect data transmitted during relay between terminals, and thereby establish hop-by-hop security and end-to-end security.
[0011] The technical problems to be achieved in the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned will be clearly understood by a person having ordinary skill in the technical field to which the present invention pertains from the description below.
[0012] According to various embodiments of the present disclosure, in a wireless communication system, a method performed by a first terminal may include the steps of obtaining information about the first terminal related to hop-to-hop security and end-to-end security, receiving information about establishment of the hop-to-hop security and end-to-end security from a relay terminal based on the information about the first terminal, and performing a relay connection procedure with the relay terminal and a second terminal based on the information about establishment of the hop-to-hop security and end-to-end security.
[0013] According to various embodiments of the present disclosure, in a wireless communication system, a first terminal includes at least one transceiver and a controller coupled to the at least one transceiver, wherein the controller is configured to obtain information about the first terminal related to hop-to-hop security and end-to-end security, receive information about establishment of the hop-to-hop security and end-to-end security from a relay terminal based on the information about the first terminal, and perform a relay connection procedure with the relay terminal and a second terminal based on the information about establishment of the hop-to-hop security and end-to-end security.
[0014] Various embodiments of the present disclosure can provide a device and method capable of effectively providing a service in a wireless communication system.
[0015] Various embodiments of the present disclosure provide methods for terminals establishing terminal-to-terminal relay connections to receive terminal-to-terminal relay security policies and parameters and negotiate hop-to-hop and end-to-end security methods. Furthermore, embodiments of the present disclosure provide methods for establishing hop-to-hop and end-to-end security, thereby increasing the efficiency of terminal-to-terminal relay communication and safely protecting data from malicious users.
[0016] The effects that can be obtained from the present disclosure are not limited to the effects mentioned above, and other effects that are not mentioned can be clearly understood by a person having ordinary skill in the art to which the present disclosure belongs from the description below.
[0017] FIG. 1 illustrates a communication network including core network entities in a wireless communication system according to various embodiments of the present disclosure.
[0018] FIG. 2 illustrates the flow of signals for digital signatures according to various embodiments of the present disclosure.
[0019] FIG. 3 illustrates a flow of signals for a terminal to verify an electronic signature according to various embodiments of the present disclosure.
[0020] FIG. 4 illustrates a signal flow for a terminal to receive information necessary for establishing security according to various embodiments of the present disclosure.
[0021] FIG. 5 illustrates another signal flow for a terminal to receive information necessary for establishing security, according to various embodiments of the present disclosure.
[0022] FIG. 6 illustrates a signal flow for a terminal to set a security policy according to various embodiments of the present disclosure.
[0023] FIG. 7 illustrates the flow of signals for establishing hop-by-hop security in terminal-to-terminal relay according to various embodiments of the present disclosure.
[0024] FIG. 8 illustrates a signal flow for establishing end-to-end security in terminal-to-terminal relay according to various embodiments of the present disclosure.
[0025] FIG. 9 illustrates the flow of signals for terminals to negotiate and establish hop-by-hop security and end-to-end security methods during terminal-to-terminal relay according to various embodiments of the present disclosure.
[0026] FIG. 10 illustrates a flow of signals for terminals to discover terminals with which they can negotiate a hop-by-hop security method in a discovery procedure during terminal-to-terminal relay according to various embodiments of the present disclosure.
[0027] FIG. 11 illustrates a signal flow for terminals to discover terminals with which they can negotiate hop-by-hop security and end-to-end security methods in a discovery procedure during terminal-to-terminal relay according to various embodiments of the present disclosure.
[0028] FIG. 12 illustrates another signal flow for terminals to negotiate and establish hop-by-hop security and end-to-end security methods during terminal-to-terminal relay according to various embodiments of the present disclosure.
[0029] FIG. 13 illustrates a functional configuration of a terminal according to various embodiments of the present disclosure.
[0030] FIG. 14 illustrates a functional configuration of a network entity according to various embodiments of the present disclosure.
[0031] The terms used in this disclosure are used only to describe specific embodiments and may not be intended to limit the scope of other embodiments. The singular expression may include plural expressions unless the context clearly indicates otherwise. Terms used herein, including technical or scientific terms, may have the same meaning as commonly understood by those of ordinary skill in the art described in this disclosure. Terms defined in general dictionaries among the terms used in this disclosure may be interpreted as having the same or similar meaning in the context of the relevant technology, and shall not be interpreted in an idealized or overly formal sense unless explicitly defined in this disclosure. In some cases, even if a term is defined in this disclosure, it cannot be interpreted to exclude embodiments of the present disclosure.
[0032] The various embodiments of the present disclosure described below illustrate a hardware-based approach as an example. However, since the various embodiments of the present disclosure include techniques utilizing both hardware and software, the various embodiments of the present disclosure do not exclude a software-based approach.
[0033] The operating principles of the present disclosure are described in detail below with reference to the attached drawings. When describing the present disclosure, detailed descriptions of related known functions or configurations will be omitted if they are deemed to unnecessarily obscure the gist of the present disclosure. Furthermore, the terms described below are defined based on the functions of the present disclosure and may vary depending on the intent or custom of the user or operator. Therefore, their definitions should be based on the overall content of this specification.
[0034] For the same reason, some components in the attached drawings are omitted or schematically depicted. Furthermore, the dimensions of each component do not entirely reflect the actual size. Identical or corresponding components in each drawing are assigned the same reference numbers.
[0035] The advantages and features of the present disclosure, and methods for achieving them, will become clearer with reference to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided only to ensure that the present disclosure is complete and to fully inform those skilled in the art of the scope of the present disclosure, and the present disclosure is defined only by the scope of the claims. Like reference numerals refer to like elements throughout the specification.
[0036] At this time, it will be understood that each block of the processing flowchart drawings and combinations of the flowchart drawings can be performed by computer program instructions. Since the computer program instructions can be installed in a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, the instructions executed by the processor of the computer or other programmable data processing equipment can create a means for performing the functions described in the flowchart block(s). Since the computer program instructions can also be stored in a computer-available or computer-readable memory that can direct a computer or other programmable data processing equipment to implement a function in a specific manner, the instructions stored in the computer-available or computer-readable memory can also produce a manufactured item that includes an instruction means for performing the functions described in the flowchart block(s). Since the computer program instructions may be installed on a computer or other programmable data processing device, a series of operational steps may be performed on the computer or other programmable data processing device to create a computer-executable process, and the instructions that cause the computer or other programmable data processing device to perform the steps for performing the functions described in the flowchart block(s) may also provide steps for performing the functions described in the flowchart block(s).
[0037] Additionally, each block may represent a module, segment, or portion of code that contains one or more executable instructions for performing a specific logical function(s). In some alternative implementation examples, the functions mentioned in the blocks may occur out of order. For example, two blocks shown in succession may actually be executed substantially concurrently, or the blocks may sometimes be executed in reverse order, depending on their respective functions.
[0038] The term '~part' used in this embodiment means a software or hardware component, and the '~part' performs certain roles. However, the '~part' is not limited to software or hardware. The '~part' may be configured to reside on an addressable storage medium and may be configured to regenerate one or more processors. Thus, as an example, the '~part' includes components such as software components, object-oriented software components, class components, and task components, processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functionality provided within the components and '~parts' may be combined into a smaller number of components and '~parts' or further separated into additional components and '~parts'. In addition, the components and '~parts' may be implemented to regenerate one or more CPUs within a device or a secure multimedia card. Additionally, in the embodiment, '~bu' may include one or more processors.
[0039] The embodiments of the present disclosure described below may also be applied to other communication systems with similar technical backgrounds or channel types. Furthermore, the embodiments of the present disclosure may be applied to other communication systems with some modifications, as determined by a person skilled in the art, without significantly departing from the scope of the present disclosure.
[0040] In specifically describing the embodiments of the present disclosure, the communication system may utilize various wired or wireless communication systems, and for example, the 3GPP, a wireless communication standard standardization organization, may utilize the New RAN (NR), which is a wireless access network in the 5G communication standard, and the Packet Core (5G System, or 5G Core Network, or NG Core (Next Generation Core)), which is a core network. In addition, it may be applied to other communication systems with similar technical backgrounds with slight modifications within a range that does not significantly deviate from the scope of the present disclosure, and this will be possible at the discretion of a person skilled in the art of the present disclosure.
[0041] The following terms used in the description of the present disclosure to identify connection nodes, terms referring to network entities (e.g., network functions), terms referring to messages, terms referring to interfaces between network functions (NFs), terms referring to various identification information, etc. are provided as examples for convenience of explanation. Therefore, the present disclosure is not limited to the terms described below, and other terms referring to objects having equivalent technical meanings may be used.
[0042] Additionally, while this disclosure describes various embodiments using terminology used in certain communication standards (e.g., 3rd Generation Partnership Project (3GPP)), these are merely illustrative examples. The various embodiments of this disclosure can be easily modified and applied to other communication systems.
[0043] 5G systems are considering supporting a wider range of services compared to existing 4G systems. For example, representative services include enhanced mobile broadband (eMBB), ultra-reliable and low latency communication (URLLC), massive machine type communication (mMTC), and evolved multimedia broadcast / multicast service (eMBMS). Systems that provide URLLC services can be referred to as URLLC systems, and systems that provide eMBB services as eMBB systems. Furthermore, the terms "service" and "system" can be used interchangeably.
[0044] Among these, URLLC service is a new service being considered for 5G systems, unlike existing 4G systems. Compared to other services, it requires ultra-high reliability (e.g., a packet error rate of approximately 10-5) and low latency (e.g., approximately 0.5 msec). To meet these stringent requirements, URLLC service may require a shorter transmission time interval (TTI) than eMBB service, and various operation methods utilizing this are being considered.
[0045] Meanwhile, the Internet is evolving from a human-centric network where humans create and consume information to an Internet of Things (IoT) network where information is exchanged and processed between distributed components such as objects. The Internet of Everything (IoE) technology, which combines IoT technology with big data processing technology through connections to cloud servers, is also emerging. To implement the IoT, technological elements such as sensing technology, wireless and wired communication and network infrastructure, service interface technology, and security technology are required. Recently, technologies such as sensor networks for connecting objects, machine-to-machine (M2M), and machine-type communication (MTC) are being researched.
[0046] In an IoT environment, intelligent IT (Internet Technology) services can be provided that collect and analyze data generated from connected objects, creating new value in human life. IoT can be applied to areas such as smart homes, smart buildings, smart cities, smart or connected cars, smart grids, healthcare, smart appliances, and advanced medical services through the convergence and integration of existing IT (information technology) technologies with various industries.
[0047] Accordingly, various attempts are being made to apply 5G communication systems to IoT networks. For example, technologies such as sensor networks, machine-to-machine (M2M), and machine-type communication (MTC) are being implemented using 5G communication techniques such as beamforming, MIMO, and array antennas. The application of cloud radio access networks (cloud RAN), a big data processing technology described above, can also be considered an example of the convergence of 5G and IoT technologies.
[0048] Meanwhile, 3GPP, which is in charge of cellular mobile communication standards, is naming a new core network structure 5G core (5GC) and proceeding with standardization to promote evolution from the existing 4G LTE system to a 5G system.
[0049] 5GC supports the following differentiated features compared to the evolved packet core (EPC), the network core for existing 4G.
[0050] First, 5GC introduces network slicing. As a requirement of 5G, 5GC must support a variety of terminal types and services. Examples include enhanced mobile broadband (eMBB), ultra-reliable low-latency communications (URLLC), and massive machine-type communications (mMTC). These terminals and services each have different requirements for the core network. For example, eMBB services require high data rates, while URLLC services demand high reliability and low latency. Network slicing is a proposed technology to meet these diverse service requirements.
[0051] Network slicing virtualizes a single physical network to create multiple logical networks. Each network slice instance (NSI) can have different characteristics. Therefore, each NSI can have a network function (NF) tailored to its characteristics, enabling it to satisfy diverse service requirements. By assigning an NSI tailored to the service requirements of each terminal, various 5G services can be efficiently supported.
[0052] Second, 5GC can facilitate support for the network virtualization paradigm by separating mobility management and session management functions. In existing 4G LTE, all terminals could receive network services through signaling exchanges with a single core device called the mobility management entity (MME), which was responsible for registration, authentication, mobility management, and session management. However, in 5G, the number of terminals will explode, and the mobility and traffic / session characteristics that must be supported will become more specialized depending on the terminal type. Therefore, supporting all functions with a single device like the MME will inevitably reduce scalability by adding entities for each required function. Therefore, various functions are being developed based on a structure that separates mobility management and session management functions to improve scalability in terms of functional / implementation complexity and signaling load of the core device responsible for the control plane.
[0053] Existing D2D (Device-to-Device) systems provide a method for multiple terminals outside the coverage of a base station to communicate with each other using a relay terminal. When multiple terminals communicate with each other through a relay terminal, a method is required to provide hop-by-hop protection for data between the two terminals communicating via the relay terminal, a method to provide end-to-end protection (E2E protection) for data between the two terminals constituting the end, and a method for the two terminals constituting the end and the relay terminal to agree on whether to establish hop-by-hop protection or end-to-end protection.
[0054] Additionally, when multiple terminals communicate with a relay terminal in between, a method is needed for the two terminals constituting the terminal and the relay terminal to negotiate hop-by-hop and end-to-end security methods, and a method is needed to establish hop-by-hop and end-to-end security accordingly. The security methods mentioned above may include integrity protection to ensure message integrity and encryption / decryption to ensure message confidentiality.
[0055] According to various embodiments of the present disclosure, a base station, which performs resource allocation of a terminal, may be at least one of an eNode B (eNB), a Node B, a BS (Base Station), a RAN (Radio Access Network), an AN (Access Network), a RAN node, a NR NB, a gNB, a wireless access unit, a base station controller, or a node on a network. The terminal may include a UE (User Equipment), an MS (Mobile Station), a cellular phone, a smartphone, a computer, or a multimedia system capable of performing a communication function. In the present invention, a downlink (DL) refers to a wireless transmission path of a signal transmitted from a base station to a terminal, and an uplink (UL) refers to a wireless transmission path of a signal transmitted from a terminal to a base station. In addition, although an embodiment of the present invention is described below using an LTE or LTE-A system as an example, an embodiment of the present invention may also be applied to other communication systems having a similar technical background or channel type. In addition, embodiments of the present invention may be applied to other communication systems through some modifications within a scope that does not significantly deviate from the scope of the present invention, as judged by a person having skilled technical knowledge.
[0056] FIG. 1 illustrates a communication network including core network entities in a wireless communication system according to various embodiments of the present disclosure.
[0057] In the present disclosure, network technology may refer to standard specifications defined by the International Telecommunication Union (ITU) or 3GPP (e.g., TS 23.501, TS 23.502, TS 23.503, etc.). Components included in the network structure of Fig. 1 may each mean a physical entity, or may mean software performing an individual function or hardware combined with software. Referring to Fig. 1, reference symbols shown as Nx (N1, N2, N3, etc.) represent known interfaces between network functions (NFs) in a 5G core network (CN), and related descriptions may refer to standard specifications (TS 23.501).
[0058] The units that perform each function provided by a 5G network system can be defined as network functions (NFs). The structure of a 5G mobile communications network is illustrated in Figure 1. Referring to FIG. 1, a 5G network system may include at least one of a New Radio (NR) base station (NG-RAN (radio access node)) (112) for wireless connection of a user equipment (UE) (111), an access and mobility management function (AMF) (180) for managing network connection and mobility, a session management function (SMF) (190) for performing functions related to sessions for the UE, a user plane function (UPF) (113) in charge of transmitting user data and controlled by the SMF, an application function (AF) (160), a network exposure function (NEF) (120) for supporting communication between the 5GC and the AF (160), a unified data management (UDM) (150) for storing and managing data, a policy and control function (PCF) (140) for managing policies, or a data network (DN) (121) such as the Internet through which user data is transmitted. Additionally, the network system may further include an authentication server function (AUSF) (170) that provides user authorization authentication and authorization services with UDM (150) / AMF (180). In addition to the NF, an operation, administration, and management (OAM) system (not shown) for managing terminals and 5G mobile communication networks may also be included. Session information may include QoS information, billing information, packet processing information, and the like.And the 5G network system may further include at least one of a network slice selection function (NSSF) (110) or a network repository function (NRF) (130).
[0059] FIG. 2 illustrates signal flow for digital signatures according to various embodiments of the present disclosure. Specifically, referring to FIG. 2 , a pre-processing process for digital signatures is illustrated.
[0060] The UE (201) disclosed in FIG. 2 may include some or all of the configuration of the terminal (111) illustrated in FIG. 1. According to various embodiments of the present disclosure, a Key Management Server (KMS) (200) may be included in one or more of the network functions (NFs) illustrated in FIG. 1. For example, the KMS may include the AUSF illustrated in FIG. 1 or a logical network function implemented within the AUSF. According to one embodiment of the present disclosure, the KMS may be a new entity introduced for preliminary work for a digital signature, rather than one of the network functions illustrated in FIG. 1. The new entity may collaborate with the network function illustrated in FIG. 1. According to one embodiment, the digital signature may include an identity-based digital signature method.
[0061] Referring to FIG. 2, in step (210), KMS may perform at least one of the following processes.
[0062] Step 1: According to one embodiment of the present disclosure, the KMS (200) may have its own pair of asymmetric keys (e.g., including a public key). According to one embodiment of the present disclosure, the asymmetric key pair may include a KMS Secret Authentication Key (KSAK) and a KMS Public Authentication Key (KPAK). According to one embodiment of the present disclosure, the KSAK may be a private key of the KMS (200). According to one embodiment of the present disclosure, the KPAK may be a public key of the KMS (200). According to one embodiment of the present disclosure, the KPAK and the KSAK may include a pair of an asymmetric key and a secret key generated using any asymmetric key system. According to one embodiment of the present disclosure, any asymmetric key system may include RSA or an elliptic curve cryptosystem. According to one embodiment, RSA may include an asymmetric key system based on number theory, particularly the difficulty of factorization. In one embodiment, an elliptic curve cryptosystem may include an asymmetric key system based on the difficulty of algebraic geometry or elliptic geometry, particularly the discrete logarithm problem of elliptic curves.
[0063] Step 2: According to one embodiment of the present disclosure, the KMS (200) can generate a Secret Signing Key (SSK) and a Public Validation Token (PVT). According to one embodiment of the present disclosure, the SSK can be used for electronic signatures, and the PVT can be used for electronic signature verification. According to one embodiment, the SSK and the PVT can be provided to the UE (201) and can include different values for each UE. According to one embodiment of the present disclosure, the UE (201) can generate an electronic signature of the UE (201) using the SSK of the UE (201), and the generated signature can be verified using the PVT.
[0064] The process by which the KMS (200) generates the SSK and PVT may vary. For example, the KMS (200) may generate an asymmetric key pair (PVT, v). According to one embodiment of the present disclosure, v may correspond to a secret key of a public key system, and the PVT may be a public key corresponding to v. According to one embodiment of the present disclosure, the KMS (200) may generate the SSK using at least one of the KPAK, KSAK, v, PVT, or ID values of the UE. According to various embodiments of the present disclosure, the KMS (200) may generate the SSK by adding necessary values in addition to the KPAK, KSAK, v, PVT, or ID values of the UE.
[0065] In step (220), KMS (200) can transmit to UE (210) at least one of SSK, a secret key for signing of UE (201), PVT for signature verification, or KPAK of KMS (200).
[0066] FIG. 3 illustrates the flow of signals for a terminal to verify an electronic signature according to various embodiments of the present disclosure. Referring to FIG. 3, UE 1 (301) and UE 2 (302) may include some or all of the configuration of terminal (111) of FIG. 1.
[0067] UE 1 (301) illustrated in FIG. 3 may have the following values through the process described in FIG. 2.
[0068] - KPAK of KMS
[0069] - UE's "Secret Key for Signature SSK" and "Token for Signature Verification PVT" (hereinafter, for convenience, described as UE1.SSK and UE1.PVT)
[0070] UE 2 (302) illustrated in FIG. 3 may have the following values.
[0071] - KPAK of KMS
[0072] Referring to FIG. 3, in step (310), UE 1 (301) can generate an electronic signature for message M. There may be various ways in which UE 1 (301) generates an electronic signature. For example, UE 1 (301) can select an arbitrary value r. UE 1 (301) can generate a new s value using at least one of the selected r value, message M, UE_1.ID (e.g., ID of UE_1), KPAK, UE_1.PVT, or UE_1.SSK. According to one embodiment of the present disclosure, UE_1 (301) can generate an electronic signature by adding other values in addition to the r value, message M, UE_1.ID (e.g., ID of UE_1), KPAK, UE_1.PVT, or UE_1.SSK.
[0073] According to one embodiment of the present disclosure, a combination of the generated r and s values may be defined as an "electronic signature" value generated by UE_1 (301) for a message M. The generated "electronic signature" value (e.g., a combination of r and s values) and a bundle of UE1.PVT (e.g., a combination of r, s, UE1.PVT) includes a combination of the electronic signature value generated by UE_1 (301) and a value capable of verifying the electronic signature value, and may mean Sig. According to one embodiment of the present disclosure, if UE1.PVT is already known to a counterparty to receive the electronic signature, UE1.PVT may be omitted from the configuration of Sig, in which case Sig may be identical to the "electronic signature" value defined above.
[0074] In step (320), UE 1 (301) may transmit at least one of UE1.ID, message M, or UE1.Sig to UE 2 (302). According to one embodiment of the present disclosure, if the ID (UE1.ID.) of UE 1 (301) is already known to UE 2 (302), the ID of UE 1 (301) may be omitted in step (320).
[0075] In step (330), UE 2 (302) can verify the authenticity of the received electronic signature r, s values. According to one embodiment of the present disclosure, UE 2 (302) can verify whether the received electronic signature r, s values are correctly created electronic signature r, s values for the received message M using at least one of UE1.ID, UE1.PVT, KPAK, or message M. As an example, the verification method can be performed through the following process.
[0076] 1) UE 2 (302) verifies whether the received PVT is a valid point on the given elliptic curve.
[0077] 2) The elliptic curve generator, KPAK, ID of UE 1 (301), and PVT are sequentially concatenated and then a hash function is applied to derive HS.
[0078] 3) After concatenating HS, r, and M, apply the hash function to derive the HE value.
[0079] 4) After performing scalar multiplication on the elliptic curve using the HS value and PVT, the Y value is derived by adding KPAK on the elliptic curve.
[0080] 5) Perform scalar multiplication on the HE value and the generator on the elliptic curve. Perform scalar multiplication on Y and r on the elliptic curve. Perform addition on the two values of the performed result on the elliptic curve. Derive the J value through scalar multiplication on the elliptic curve for the value of the performed result and the s value.
[0081] 6) Assuming the J value as a point in the affine coordinate system, derive the x-coordinate and y-coordinate, and then apply the modulo operation to the x-coordinate to check if it is the same as the r value.
[0082] According to one embodiment of the present disclosure, UE 2 (302) can use other values in addition to UE1.ID, UE1.PVT, KPAK or message M for electronic signature verification.
[0083] FIG. 4 illustrates a signal flow for a terminal to receive information necessary for establishing security, according to various embodiments of the present disclosure. The UE (400), AUSF (401), and UDM (402) illustrated in FIG. 4 may include some or all of the configurations of the terminal (111), AUSF (170), and UDM (150) illustrated in FIG. 1.
[0084] Referring to FIG. 4, in step (405), the UE (400) may transmit a message requesting 'information required for establishing security during terminal-to-terminal relay' to the AUSF (401). According to one embodiment of the present disclosure, even if the UE (400) does not make a request, if the 'information required for establishing security during terminal-to-terminal relay' is provided to the UE (400), step (405) may be omitted.
[0085] In step (410), the AUSF (401) may transmit a message to the UDM (402) managing the subscription information of the UE (400) requesting confirmation as to whether the UE (400) is authorized to use or provide the terminal-to-terminal relay service. In one embodiment, if the UDM (402) provides the AUSF (401) with information as to whether the UE (400) is authorized to use or provide the terminal-to-terminal relay service even if the AUSF (401) does not specifically request it, step (410) may be omitted.
[0086] In step (415), in response to the request message received from the AUSF (401), the UDM (402) may transmit a response message to the AUSF (401) including information on whether the UE (400) is authorized to use or provide the terminal-to-terminal relay service. According to various embodiments of the present disclosure, the information on whether the UE (400) is authorized to use or provide the terminal-to-terminal relay service may be transmitted in various formats. For example, the above-described information may be transmitted using a parameter value or a flag value indicating the above-described information. According to one embodiment of the present disclosure, the above-described information may be referred to as a UE-to-UE indication.
[0087] In step (420), AUSF (401) may transmit a message to UE (400) requesting information necessary to generate 'information necessary for establishing security during terminal-to-terminal relay'. According to one embodiment, the message transmitted by AUSF (401) may include the UE-to-UE indication received by AUSF (401) from UDM (402) in step (415).
[0088] The UE (400) can determine whether to transmit information necessary to create ‘information necessary for establishing security when relaying between terminals’ to the AUSF (401) based on the information included in the received request message.
[0089] In step (425), if it is determined that the UE (400) needs to transmit information necessary for generating 'information necessary for establishing security during terminal-to-terminal relay' to the AUSF (401), the UE (400) may transmit information necessary for generating 'information necessary for establishing security during terminal-to-terminal relay' to the AUSF (401). According to an embodiment of the present disclosure, the information necessary for generating 'information necessary for establishing security during terminal-to-terminal relay' may be referred to as UE-to-UE Auth Info. According to an embodiment of the present disclosure, the 'UE-to-UE Auth Info' may be configured in various ways. According to an embodiment of the present disclosure, the UE (400) may configure the UE-to-UE Auth Info according to the terminal-to-terminal security establishment method(s) that the UE (400) can use. If there are multiple terminal-to-terminal security establishment methods available to the UE (400), the UE (400) can configure 'UE-to-UE Auth Info' to include information required for all terminal-to-terminal security establishment methods available to the UE (400). For example, the terminal-to-terminal security establishment methods can include the following two methods.
[0090] Method 1: Certificate-based approach
[0091] 1) According to one embodiment of the present disclosure, when using a Certificate-based approach, UE-to-UE Auth Info may include at least one of the following values.
[0092] (a) UE.ID (e.g., UE's ID)
[0093] (b) If there is a UE.Cert (e.g., a certificate of UE) issued by AUSF (401), UE.Cert (e.g., the certificate of UE includes the public key of UE (UE.PK))
[0094] (c) If there is no UE.Cert (e.g., UE's certificate) issued by AUSF (401), UE.PK
[0095] 2) According to one embodiment of the present disclosure, the UE.Cert may include at least one of the following pieces of information. For example, at least one of the following pieces of information may be included as part of the UE.Cert, or values corresponding to the following pieces of information may be included as part of the UE.Cert.
[0096] (a) The validity period of UE.Cert. For example, it may include information indicating the expiration date of UE.Cert. According to one embodiment of the present disclosure, information related to the validity period of UE.Cert may be provided in various ways. Some possible examples in this regard are as follows. However, according to one embodiment, the method of expressing the validity period is not limited to the methods described below, and may include any method capable of specifying the validity period of UE.Cert.
[0097] a) Last time UE.Cert was valid
[0098] b) The start time when UE.Cert is valid and the duration of validity.
[0099] c) The start and end times when UE.Cert is valid.
[0100] Method 2: Identity-based approach
[0101] 1) According to one embodiment of the present disclosure, when using an identity-based approach, UE-to-UE Auth Info may include UE.ID (e.g., ID of the UE).
[0102] 2) According to one embodiment of the present disclosure, UE.ID may include at least one of the following pieces of information. For example, at least one of the following pieces of information may be included as part of UE.ID, or values corresponding to the following pieces of information may be included as part of UE.ID.
[0103] (a) Validity period of UE.SSK and UE.PVT. For example, information indicating until when UE.SSK and UE.PVT are valid. According to one embodiment of the present disclosure, information related to the validity period of UE.SSK and UE.PVT may be provided in various ways. Some possible examples are as follows. However, according to one embodiment, the method of expressing the validity period is not limited to the method below, and may include any method capable of specifying the validity period of UE.SSK and UE.PVT.
[0104] a) Last time UE.SSK and UE.PVT were valid
[0105] b) The start time and duration of validity of UE.SSK and UE.PVT.
[0106] c) The start and end times when UE.SSK and UE.PVT are valid.
[0107] (b) When a UE (400) establishes a relay connection between terminals, the ID of the UE used to determine whether to establish discovery and / or connection (e.g., when one or more UEs use each other's layer-2 IDs to determine whether to discover and / or establish connection with the other UE, the layer-2 ID of the UE)
[0108] AUSF (401) can determine whether to transmit ‘information required for establishing security during terminal-to-terminal relay’ to UE (400) based on the information included in the response message received in steps (415) and (425).
[0109] In step (430), if AUSF (401) determines that it is necessary to transmit 'information required for establishing security during terminal-to-terminal relay' to UE (400), AUSF (401) may generate 'information required for establishing security during terminal-to-terminal relay'. According to one embodiment of the present disclosure, the 'information required for establishing security during terminal-to-terminal relay' generated to be transmitted from AUSF (401) to UE (400) may include UE-to-UE Security Materials. According to one embodiment of the present disclosure, UE-to-UE Security Materials may be configured in various ways. As an example, the following two examples may exist.
[0110] Method 1: Certificate-based approach
[0111] 1) When using a certificate-based approach, UE-to-UE Security Materials may include at least one of the following values:
[0112] (a) UE.Cert (e.g., UE's certificate)
[0113] (b) Information that can verify UE.Cert (e.g., the root CA (certificate authority) public key and / or root CA certificate and / or sub-CA(s) certificate(s) existing on the certificate chain).
[0114] 2) According to one embodiment of the present disclosure, UE.Cert may include at least one of the following pieces of information. For example, at least one of the following pieces of information may be included as part of UE.Cert, or values corresponding to the following pieces of information may be included as part of UE.Cert.
[0115] (a) The validity period of UE.Cert. For example, information indicating the expiration date of UE.Cert. According to one embodiment of the present disclosure, information related to the validity period of UE.Cert may be provided in various ways. In this regard, some possible examples are as follows. However, according to one embodiment, the method of expressing the validity period is not limited to the methods described below, and may include any method capable of specifying the validity period of UE.Cert.
[0116] a) Last time UE.Cert was valid
[0117] b) The start time when UE.Cert is valid and the duration of validity.
[0118] c) The start and end times when UE.Cert is valid.
[0119] Method 2: Identity-based approach
[0120] 1) Content related to identity-based digital signature may include methods similar or identical to those described in FIGS. 2 and 3 of the present disclosure.
[0121] 2) According to one embodiment of the present disclosure, when using an identity-based approach, UE-to-UE Security Materials may include at least one of the following values.
[0122] (a) UE.ID (e.g., UE's ID)
[0123] (b) UE.SSK
[0124] (c) UE.PVT
[0125] (d) KPAK(s)
[0126] 3) According to one embodiment of the present disclosure, the UE.ID may include at least one of the following pieces of information. For example, at least one of the following pieces of information may be included as part of the UE.ID, or values corresponding to the following pieces of information may be included as part of the UE.ID.
[0127] (a) Validity period of UE.SSK and UE.PVT. For example, UE.SSK may include information indicating how long UE.PVT is valid. According to one embodiment of the present disclosure, information related to the validity period of UE.SSK and UE.PVT may be provided in various ways. In this regard, some possible examples are as follows. However, according to one embodiment, the method of expressing the validity period is not limited to the method below, and may include any method that can specify the validity period of UE.SSK and UE.PVT.
[0128] a) Last time UE.SSK and UE.PVT were valid
[0129] b) The start time and duration of validity of UE.SSK and UE.PVT.
[0130] c) The start and end times when UE.SSK and UE.PVT are valid.
[0131] (b) When a UE (400) establishes a relay connection between terminals, the ID of the UE used for discovery and / or 'determining whether to establish a connection' (for example, when one or more UEs use each other's layer-2 ID to discover the other UE and / or determine whether to establish a connection, the layer-2 ID of the UE)
[0132] In step (435), AUSF (401) can transmit the UE-to-UE Security Materials generated in step (430) to UE (400).
[0133] According to one embodiment of the present disclosure, the 'process by which the UE acquires information necessary for establishing security during terminal-to-terminal relay' illustrated in FIG. 4 may be performed independently, but is not limited thereto, and may of course be performed as part of another process performed by the UE. For example, the 'process by which the UE acquires information necessary for establishing security during terminal-to-terminal relay' may be performed as part of a primary authentication process (e.g., EAP-AKA (Extensible Authentication Protocol-Authentication and Key Agreement) or 5G-AKA (5G-Authentication and Key Agreement)) in which the UE (400) connects to a network and performs authentication. The above process is described in detail in FIG. 5.
[0134] FIG. 5 illustrates another signal flow for a terminal to receive information necessary for establishing security, according to various embodiments of the present disclosure. Referring to FIG. 5, according to one embodiment, the 'process of the UE acquiring information necessary for establishing security when relaying between terminals' may be included as a part of the primary authentication process in which the UE is authenticated for network access. Referring to FIG. 5, the UE (500), AUSF (502), and UDM (503) illustrated in FIG. 5 may include part or all of the configurations of the terminal (111), AUSF (170), and UDM (150) illustrated in FIG. 1. In addition, the SEAF (Security Anchor Function) (501) illustrated in FIG. 5 is a logical function related to network authentication of the UE (500), and may be implemented as a function of one of the NFs illustrated in FIG. 1. For example, the SEAF (501) illustrated in FIG. 5 may be implemented as one of the functions of the AMF (180) illustrated in FIG. 1.
[0135] Referring to FIG. 5, in step (505), the UE (500) may transmit a message requesting authentication for network access to the SEAF (501).
[0136] In step (510), SEAF (501), which has received an authentication request message from UE (500), can transmit a message requesting AUSF (502) to proceed with a procedure related to authentication.
[0137] At step (515), AUSF (502) may transmit a message requesting authentication-related data to UDM (503).
[0138] In step (520), the UDM (503) that has received a message requesting authentication-related data from the AUSF (502) may perform at least one of the following processes.
[0139] Step 1: According to one embodiment of the present disclosure, the UDM (503) can identify the UE (500) and then check the subscription information of the UE (500). According to one embodiment of the present disclosure, the subscription information of the UE (500) can include at least one of the following:
[0140] (a) Information on whether UE (500) is a customer of the business operator;
[0141] (b) Information on the type of service subscribed to by the UE (500). In particular, in relation to various embodiments of the present disclosure, this may include subscription information of the UE (500) related to terminal-to-terminal relay. According to one embodiment of the present disclosure, the subscription information of the UE (500) related to terminal-to-terminal relay may include information on whether the UE (500) is authorized to use or provide terminal-to-terminal relay services.
[0142] Step 2: According to one embodiment of the present disclosure, the UE (500) may generate information (e.g., authentication vector (AV)) required for authentication.
[0143] In step (525), the UDM (503) may transmit a response message to the AUSF (502) in response to the request message received from the AUSF (502), including information including at least one of the AV generated in step (520) and UE-to-UE indication information according to the subscription information of the UE (500) confirmed in step (520). According to one embodiment of the present disclosure, the UE-to-UE indication information may include the UE-to-UE indication information described in FIG. 4.
[0144] In step (530), AUSF (502) may transmit a response message including the UE-to-UE indication received from UDM (503) to SEAF (501).
[0145] In step (535), SEAF (501) can transmit a response message including the UE-to-UE indication received from AUSF (502) to UE (500).
[0146] In step (540), the UE (500) that has received a message requesting data related to the authentication from SEAF (501) may perform at least one of the following processes.
[0147] Step 1: According to one embodiment of the present disclosure, the UE (500) may generate an authentication response to authenticate itself based on a request message received from SEAF (501).
[0148] Step 2: According to one embodiment of the present disclosure, based on the UE-to-UE indication information received from the SEAF (501), the UE (500) may include UE-to-UE Auth Info in the authentication response to be transmitted to the AUSF (502). The description of the UE-to-UE Auth Info may be similar or identical to the description of the UE-to-UE Auth Info in FIG. 4.
[0149] In step (545), the UE (500) may transmit an authentication response including UE-to-UE Auth Info to the SEAF (501).
[0150] In step (550), SEAF (501) can transmit an authentication response including UE-to-UE Auth Info received from UE (500) to AUSF (502).
[0151] In step (555), AUSF (502) can verify the authentication response received from SEAF (501). According to one embodiment of the present disclosure, through the above-described verification process, the network can authenticate that UE (500) is a legitimate user.
[0152] In step (560), based on the UE-to-UE indication received from the UDM (503) and the UE-to-UE Auth Info received from the SEAF (501), the AUSF (502) may determine whether to generate UE-to-UE Security Materials to be transmitted to the UE (500). The AUSF (502) may generate UE-to-UE Security Materials to be transmitted to the UE (500) based on the determination result. The description of the UE-to-UE Security Materials may be similar or identical to the description of the UE-to-UE Security Materials in FIG. 4.
[0153] In step (565), if the AUSF (502) generated UE-to-UE Security Materials in step (560), it may transmit a response message including the UE-to-UE Security Materials generated by the AUSF (502) to the SEAF (501).
[0154] In step (570), at least one of a key formation operation for secure communication between the UE (500) and the SEAF (501) (e.g., SMC (Security Mode Command) for convenience) or transmission of UE-to-UE Security Materials from the SEAF (501) to the UE (500) may be performed between the UE (500) and the SEAF (501).
[0155] However, according to various embodiments of the present disclosure, FIG. 5 is merely an example and is not limited thereto, and it is of course possible to combine it with any other embodiments that operate to establish security between terminals. For example, all or part of the processes of FIG. 5 may be performed in combination with all or part of the processes of FIGS. 4 to 8 as part of an operation to establish security between terminals.
[0156] FIG. 6 illustrates a signal flow for a terminal to set a security policy according to various embodiments of the present disclosure. Specifically, FIG. 6 illustrates a process for a terminal to set a security policy regarding whether to establish hop-by-hop protection and end-to-end protection (E2E protection). Referring to FIG. 6, the UE (600), AMF (601), and PCF (602) illustrated in FIG. 6 may include some or all of the configurations of the terminal (111), AMF (180), and PCF (140) illustrated in FIG. 1.
[0157] Referring to FIG. 6, at step (605), the PCF (602) may decide to transmit a security policy and parameters related to relay connection to a UE (600) authorized to use or provide a terminal-to-terminal relay service. According to one embodiment of the present disclosure, the above-described security policy may be referred to as a UE-to-UE security policy.
[0158] In step (610), the PCF (602) may transmit a message including a UE-to-UE security policy of the UE (600) to the AMF (601). The UE-to-UE security policy may include a Relay Service Code (RSC) indicating a relay service that the UE (600) can use and a relay connection security policy associated with the RSC. More specifically, according to one embodiment, the relay connection security policy associated with the RSC may include a security policy indicating whether hop-by-hop security is established and whether end-to-end security is established for the corresponding relay connection. According to one embodiment of the present disclosure, the security policy indicating whether hop-by-hop security is established may be referred to as a Hop-by-Hop Security Indicator. According to one embodiment of the present disclosure, the security policy indicating whether end-to-end security is established may be referred to as an End-to-End Security Indicator.
[0159] In step (615), AMF (601) may transmit a message including at least one of RSC, Hop-by-Hop Security Indicator, or End-to-End Security Indicator to UE (600) based on the message received in step (610).
[0160] In step (620), the UE (600) may perform a UE-to-UE security policy update based on the message received in step (615). According to one embodiment of the present disclosure, when a relay connection between terminals corresponding to a specific RSC is made thereafter, if a Hop-by-Hop Security Indicator associated with the RSC indicates that hop-by-hop security establishment is necessary, the UE (600) may establish hop-by-hop security. According to one embodiment of the present disclosure, when a relay connection between terminals corresponding to a specific RSC is made thereafter, if a Hop-by-Hop Security Indicator associated with the RSC indicates that hop-by-hop security establishment is not necessary, the UE (600) may not establish hop-by-hop security. According to one embodiment of the present disclosure, when a relay connection between terminals corresponding to a specific RSC is made thereafter, if an End-to-End Security Indicator associated with the RSC indicates that end-to-end security establishment is necessary, the UE (600) may establish end-to-end security. According to one embodiment of the present disclosure, when a relay connection between terminals corresponding to a specific RSC is made, the UE (600) may not establish end-to-end security if the End-to-End Security Indicator associated with the RSC indicates that end-to-end security establishment is not necessary.
[0161] In step (625), the UE (600) may transmit a message including the result of the UE-to-UE security policy update to the AMF (601).
[0162] In step (630), AMF (601) may transmit a message including the result of UE-to-UE security policy update of UE (600) to PCF (602) based on the message received in step (625).
[0163] However, according to various embodiments of the present disclosure, FIG. 6 is merely an example and is not limited thereto, and it is of course possible to combine it with any other embodiments that operate to establish security between terminals. For example, all or part of the processes of FIG. 6 may be performed in combination with all or part of the processes of FIGS. 4 to 8 as part of an operation to establish security between terminals.
[0164] FIG. 7 illustrates signal flow for establishing hop-by-hop security in terminal-to-terminal relay according to various embodiments of the present disclosure. Referring to FIG. 7, UE 1 (701) and UE 2 (703) illustrated in FIG. 7 may include all or part of the configuration of UE (111) illustrated in FIG. 1. Additionally, Relay UE (702) illustrated in FIG. 7 may include one of UE (111) illustrated in FIG. 1 and / or NF illustrated in FIG. 1.
[0165] Referring to FIG. 7, UE 1 (701) and Relay UE (702) may generate and share a hop-by-hop protection key to establish hop-by-hop security if they determine that hop-by-hop security establishment is necessary. In addition, Relay UE (702) and UE 2 (703) may generate and share a hop-by-hop protection key to establish hop-by-hop security if they determine that hop-by-hop security establishment is necessary.
[0166] In steps (705-a, 705-b, 705-c), UE 1 (701), UE 2 (703), and Relay UE (702) may perform a 'process of acquiring information necessary for establishing security when UE performs terminal-to-terminal relay' through a process similar to or identical to the process specifically described in FIGS. 4 and 5, respectively. According to one embodiment, UE 1 (701) and UE 2 (703) may be verified by the network in steps (705-a, 705-c) as to whether they have the authority to use the terminal-to-terminal relay service. According to one embodiment, Relay UE (702) may be verified by the network in step (705-c) as to whether they have the authority to provide the terminal-to-terminal relay service. According to one embodiment of the present disclosure, in steps (705-a, 705-b, 705-c), UE 1 (701), UE 2 (703), and Relay UE (702) may each obtain UE-to-UE Security Materials, and generate an electronic signature for message M based on the obtained UE-to-UE Security Materials. UE 1 (701), UE 2 (703), and Relay UE (702) may each generate UE1.Sig, UE2.Sig, and RelayUE.Sig, including the generated electronic signature and information capable of verifying the electronic signature. According to one embodiment of the present disclosure, the process of generating UE1.Sig, UE2.Sig, and RelayUE.Sig may be implemented through a Certificate-based approach or an identity-based approach. According to various embodiments of the present disclosure, the Certificate-based approach and the identity-approach described above may be performed through a process similar to or identical to the process described in detail in FIG. 4.
[0167] According to one embodiment, in steps (705-a, 705-b, 705-c), UE 1 (701), UE 2 (703), and Relay UE (702) may obtain a Relay Service Code (RSC) indicating a corresponding relay service when relaying between terminals and a Hop-by-Hop Security Indicator indicating whether hop-by-hop security is established in association with the RSC, and may agree on whether hop-by-hop security is established based on the obtained RSC and Hop-by-Hop Security Indicator. UE 1 (701), UE 2 (703), and Relay UE (702) may or may not establish hop-by-hop security depending on whether it is indicated by the Hop-by-Hop Security Indicator when establishing a connection.
[0168] In step (710), UE 1 (701) can discover and select Relay UE (702), which mediates terminal-to-terminal relay communication, and UE 2 (703) to communicate with via Relay UE (702), through a series of broadcast message exchange procedures. According to one embodiment of the present disclosure, if UE 1 (701) can establish a connection with UE 2 (703) via Relay UE (702) without the discovery and selection procedures described above, step (710) can be omitted.
[0169] In step (715), UE 1 (701) may generate a public key UE1.ePK and a private key UE1.eSK. UE 1 (701) may include information for establishing security with Relay UE (702) in UE1.Auth_Key_Info, which is a Generic Container of UE 1 (701). According to one embodiment of the present disclosure, UE 1 (701) may generate an electronic signature based on UE1.ePK and may generate UE1.Sig including the generated electronic signature. According to one embodiment of the present disclosure, UE1.ePK and UE1.eSK may include a pair of public and private keys used in any public key cryptosystem. According to one embodiment of the present disclosure, UE 1 (701) may include at least one of UE1.ID, UE1.ePK, or UE1.Sig in UE1.Auth_Key_Info. According to one embodiment of the present disclosure, when UE 1 (701) generates UE1.Sig based on a certificate-based approach, UE1.Auth_Key_Info may not include UE1.ID.
[0170] In step (720), UE 1 (701) may transmit a message including RSC and UE1.Auth_Key_Info to Relay UE (802).
[0171] In step (725), the Relay UE (702) may perform at least one of the following processes based on the message received in step (720).
[0172] Step 1: Relay UE (702) can verify the validity of the electronic signature sent by UE 1 (701) using the UE-to-UE Security Materials obtained in step (705-b) and UE1.Sig included in UE1.Auth_Key_Info received in step (720).
[0173] Step 2: Relay UE (702) can generate a public key RelayUE.ePK and a private key RelayUE.eSK. According to one embodiment of the present disclosure, the generated RelayUE.ePK and RelayUE.eSK can include a pair of public and private keys used in any public key cryptosystem.
[0174] Step 3: Relay UE (702) can generate an electronic signature targeting RelayUE.ePK.
[0175] Step 4: Relay UE (702) can generate RelayUE.Sig including an electronic signature.
[0176] Step 5: Relay UE (702) may include information for establishing security with UE 1 (701) in RelayUE.Auth_Key_Info, which is a Generic Container of Relay UE (702). According to one embodiment of the present disclosure, Relay UE (702) may include at least one of RelayUE.ID, RelayUE.ePK, or RelayUE.Sig in RelayUE.Auth_Key_Info. According to one embodiment of the present disclosure, when Relay UE (702) generates RelayUE.Sig based on a certificate-based approach, RelayUE.Auth_Key_Info may not include RelayUE.ID.
[0177] Step 6: Relay UE (702) can generate a protection key (e.g., hop-by-hop protection key) to be used for hop-by-hop security using UE1.ePK and RelayUE.eSK.
[0178] At step (730), Relay UE (702) may transmit a message including RSC and RelayUE.Auth_Key_Info to UE 1 (701).
[0179] In step (735), UE 1 (701) may perform at least one of the following processes.
[0180] Step 1: UE 1 (701) can verify the validity of the electronic signature sent by Relay UE (702) using the UE-to-UE Security Materials obtained in step (705-a) and RelayUE.Sig included in RelayUE.Auth_Key_Info received in step (730).
[0181] Step 2: UE 1 (701) can generate a protection key (e.g., hop-by-hop protection key) to be used for hop-by-hop security using RelayUE.ePK and UE1.eSK included in RelayUE.Auth_Key_Info received in step (730).
[0182] In step (740), UE 1 (701) may transmit a message to Relay UE (702) notifying that hop-to-hop security establishment has been completed.
[0183] According to one embodiment of the present disclosure, through steps (715) to (740), UE 1 (701) and UE 2 (702) can generate and share a security key to be used for hop-to-hop security. According to one embodiment of the present disclosure, UE 1 (701) and UE 2 (702) can perform hop-to-hop secure communication using the generated security key. According to one embodiment of the present disclosure, the secure communication performed by the above-described steps may include at least one of the following secure communications.
[0184] (1) Integrity protection communication of messages transmitted from UEx to UEy. For example, message integrity protection communication may include communication through generation of a MAC (Message Authentication Code).
[0185] (2) Confidentiality communication of messages transmitted from UEx to UEy. For example, confidentiality communication of messages may include communication through a message encryption / decryption process.
[0186] According to one embodiment of the present disclosure, in step (745), if hop-to-hop security establishment is required between Relay UE (702) and UE 2 (703), hop-to-hop security can be established by similarly applying steps (715) to (740) between Relay UE (702) and UE 2 (703).
[0187] However, according to various embodiments of the present disclosure, FIG. 7 is merely an example and is not limited thereto, and it is of course possible to combine it with any other embodiments that operate to establish security between terminals. For example, all or part of the processes of FIG. 7 may be performed in combination with all or part of the processes of FIGS. 4 to 8 as part of an operation to establish security between terminals.
[0188] FIG. 8 illustrates signal flows for establishing end-to-end security during terminal-to-terminal relay, according to various embodiments of the present disclosure. UE 1 (801) and UE 2 (803) illustrated in FIG. 8 may include all or part of the configuration of terminal (111) illustrated in FIG. 1. Additionally, relay UE (802) illustrated in FIG. 8 may include one of terminals (111) illustrated in FIG. 1 and / or NF illustrated in FIG. 1.
[0189] Referring to FIG. 8, UE 1 (801) and UE 2 (803) can communicate via Relay UE (802), and if UE 1 (801) and UE 2 (803) determine that end-to-end security establishment is necessary, they can generate and share an end-to-end protection key to establish end-to-end security.
[0190] In steps (805-a, 805-b, 805-c), UE 1 (801) and UE 2 (803) may perform a 'process of acquiring information necessary for establishing security when relaying between terminals' through a process similar to or identical to the content specifically described in FIGS. 4 and 5, respectively. According to one embodiment, UE 1 (801) and UE 2 (803) may be verified by the network in steps (805-a, 805-c) as to whether they have the authority to use the terminal-to-terminal relay service. According to one embodiment, Relay UE (802) may be verified by the network in step (805-c) as to whether they have the authority to provide the terminal-to-terminal relay service. According to one embodiment of the present disclosure, in steps (805-a, 805-b, 805-c), UE 1 (801) and UE 2 (803) can each obtain UE-to-UE Security Materials and generate an electronic signature for message M based on the obtained UE-to-UE Security Materials. UE 1 (801), UE 2 (803), and Relay UE (802) can generate UE1.Sig and UE2.Sig, respectively, including the generated electronic signature and information capable of verifying the electronic signature. According to one embodiment of the present disclosure, the process of generating UE1.Sig and UE2.Sig can be implemented through a Certificate-based approach or an identity-based approach. According to various embodiments of the present disclosure, the Certificate-based approach and the identity-approach described above can be performed through a process similar to or identical to the process described in detail in FIG. 4.
[0191] According to one embodiment, in steps (805-a, 805-b, 805-c), UE 1 (801), UE 2 (803), and Relay UE (802) may each obtain a Relay Service Code (RSC) indicating a corresponding relay service when relaying between terminals, and an End-to-End Security Indicator indicating whether end-to-end security is established in association with the RSC, and may agree on whether end-to-end security is established based on the obtained RSC and End-to-End Security Indicator. UE 1 (801) and UE 2 (803) may or may not establish end-to-end security depending on whether it is indicated by the End-to-End Security Indicator when establishing a connection.
[0192] In step (810), UE 1 (801) can discover and select Relay UE (802), which mediates terminal-to-terminal relay communication, and UE 2 (803) to communicate with via Relay UE (802), through a series of broadcast message exchange procedures. According to one embodiment of the present disclosure, if UE 1 (801) can establish a connection with UE 2 (803) via Relay UE (802) without the discovery and selection procedures described above, step (810) can be omitted.
[0193] In step (815), UE 1 (801) may generate a public key UE1.ePK and a private key UE1.eSK. UE 1 (801) may include information for establishing security with UE 2 (803) in UE1.Auth_Key_Info, which is a Generic Container of UE 1 (801). According to one embodiment of the present disclosure, UE 1 (801) may generate an electronic signature based on UE1.ePK and may generate UE1.Sig including the generated electronic signature. According to one embodiment of the present disclosure, UE1.ePK and UE1.eSK may include a pair of public and private keys used in any public key cryptosystem. According to one embodiment of the present disclosure, UE 1 (801) may include at least one of UE1.ID, UE1.ePK, or UE1.Sig in UE1.Auth_Key_Info. According to one embodiment of the present disclosure, when UE 1 (801) generates UE1.Sig based on a certificate-based approach, UE1.Auth_Key_Info may not include UE1.ID.
[0194] In step (820), UE 1 (801) may transmit a message including RSC and UE1.Auth_Key_Info to Relay UE (802).
[0195] In step (825), Relay UE (802) may transmit a message including RSC and UE1.Auth_Key_Info to UE 2 (803) based on the message received in step (820).
[0196] At step (830), UE 2 (803) may perform at least one of the following processes based on the message received at step (825).
[0197] Step 1: UE 2 (803) can verify the validity of the electronic signature sent by UE 1 (801) using the UE-to-UE Security Materials obtained in step (805-c) and the UE1.Sig included in the UE1.Auth_Key_Info received in step (825).
[0198] Step 2: UE 2 (803) can generate a public key UE2.ePK and a private key UE2.eSK. According to one embodiment of the present disclosure, the generated UE2.ePK and UE2.eSK can include a pair of public and private keys used in any public key cryptosystem.
[0199] Step 3: UE 2 (803) can generate an electronic signature targeting UE2.ePK.
[0200] Step 4: UE 2 (803) can generate UE2.Sig including an electronic signature.
[0201] Step 5: UE 2 (803) may include information for establishing security with UE 1 (801) in UE2.Auth_Key_Info, which is a Generic Container of UE 2 (803). According to one embodiment of the present disclosure, UE 2 (803) may include at least one of UE2.ID, UE2.ePK, or UE2.Sig in UE2.Auth_Key_Info. According to one embodiment of the present disclosure, if UE 2 (803) generates UE2.Sig based on a certificate-based approach, UE2.Auth_Key_Info may not include UE2.ID.
[0202] Step 6: UE 2 (803) can generate a protection key (e.g., E2E protection key) to be used for end-to-end security using UE1.ePK and UE2.eSK.
[0203] In step (835), according to one embodiment of the present disclosure, Relay UE (802) and UE 2 (803) can establish hop-by-hop security between Relay UE (802) and UE 2 (803). As hop-by-hop security is established, communication between Relay UE (802) and UE 2 (803) can be protected. Whether to establish hop-by-hop security between Relay UE (802) and UE 2 (803) can be determined based on RSC and Hop-by-Hop Security Indicator associated with RSC. The description of Hop-by-Hop Security Indicator may be similar or identical to the description of Hop-by-Hop Security Indicator in FIGS. 6 and 7. In addition, the method of establishing hop-by-hop security may be similar or identical to the process described in detail in FIG. 7.
[0204] At step (840), UE 2 (803) may transmit a message including RSC and UE2.Auth_Key_Info to Relay UE (802).
[0205] In step (845), according to one embodiment of the present disclosure, Relay UE (802) and UE 1 (801) can establish hop-by-hop security between Relay UE (802) and UE 1 (801). As hop-by-hop security is established, communication between Relay UE (802) and UE 1 (801) can be protected. Whether to establish hop-by-hop security between Relay UE (802) and UE 1 (801) can be determined based on RSC and Hop-by-Hop Security Indicator associated with RSC. The description of Hop-by-Hop Security Indicator may be similar or identical to the description of Hop-by-Hop Security Indicator in FIGS. 6 and 7. In addition, the method of establishing hop-by-hop security may be similar or identical to the process described in detail in FIG. 7.
[0206] At step (850), Relay UE (802) may transmit a message including RSC and UE2.Auth_Key_Info to UE 1 (801).
[0207] At step (855), UE 1 (801) may perform at least one of the following processes.
[0208] Step 1: UE 1 (801) can verify the validity of the electronic signature sent by UE 2 (803) using the UE-to-UE Security Materials provided in step (805-a) and the UE2.Sig included in the UE2.Auth_Key_Info received in step (850).
[0209] Step 2: UE 1 (801) can generate a protection key (e.g., E2E protection key) to be used for end-to-end security using UE2.ePK and UE1.eSK included in UE2.Auth_Key_Info received in step (850).
[0210] According to one embodiment of the present disclosure, through steps (815) to (855), UE 1 (801) and UE 2 (803) can generate and share a security key to be used for end-to-end security. According to one embodiment of the present disclosure, UE 1 (801) and UE 2 (803) can perform end-to-end secure communication using the generated security key. According to one embodiment of the present disclosure, the secure communication performed by the above-described steps may include at least one of the following secure communications.
[0211] (1) Integrity protection communication of messages transmitted from UEx to UEy. For example, message integrity protection communication may include communication through generation of a MAC (Message Authentication Code).
[0212] (2) Confidentiality communication of messages transmitted from UEx to UEy. For example, confidentiality communication of messages may include communication through a message encryption / decryption process.
[0213] However, according to various embodiments of the present disclosure, FIG. 8 is merely an example and is not limited thereto, and it is of course possible to combine it with any other embodiments that operate to establish security between terminals. For example, all or part of the processes of FIG. 8 may be performed in combination with all or part of the processes of FIGS. 4 to 7 as part of an operation to establish security between terminals.
[0214] Below, FIGS. 9 through 12 illustrate procedures for establishing security by allowing each terminal to negotiate hop-by-hop security and end-to-end security methods during terminal-to-terminal relay. However, for the same purpose of ensuring security during relay communication, according to various embodiments of the present disclosure, these steps may be combined with or independently configured with the steps illustrated in FIGS. 2 through 8 described above.
[0215] Additionally, according to various embodiments of the present disclosure, some of the steps described in FIGS. 2 through 12 may be omitted or combined. For example, according to various embodiments, if a service verification or discovery procedure has already been performed, only the steps for authentication and the steps for establishing security may be performed, excluding the steps already performed.
[0216] FIG. 9 illustrates the flow of signals for terminals to negotiate and establish hop-by-hop security and end-to-end security methods during terminal-to-terminal relay according to various embodiments of the present disclosure.
[0217] Referring to FIG. 9, UE 1 (901) and UE 2 (903) disclosed in FIG. 9 may include part or all of the configuration of the terminal (111) illustrated in FIG. 1. In addition, Relay UE (902) illustrated in FIG. 9 may include one of the terminals (111) illustrated in FIG. 1 and / or the NF illustrated in FIG. 1.
[0218] In steps (905-a, 905-b, 905-c), UE 1 (901), UE 2 (903), and Relay UE (902) can be verified by the network whether they each have terminal-to-terminal relay service authority. In addition, each terminal can obtain 'information necessary for establishing security during terminal-to-terminal relay communication'. According to various embodiments, 'information necessary for establishing security during terminal-to-terminal relay communication' may be provided to the terminal by the PCF according to the judgment of the PCF, provided to the terminal from the PCF at the request of the terminal, provided to the terminal from the PCF at the request of the AF, or preset and provided to the terminal according to the judgment of the operator. According to various embodiments, 'information necessary for establishing security during terminal-to-terminal relay communication' is not limited to the above-described entities (e.g., PCF, AF), and may be provided to the terminal from various components or entities.
[0219] When a terminal receives 'information required for establishing security during terminal-to-terminal relay communication' from multiple entities at once, the 'information required for establishing security during terminal-to-terminal relay communication' received from an entity with a higher priority set in the terminal may be preferentially utilized. According to one embodiment, the 'information required for establishing security during terminal-to-terminal relay communication' may include 'terminal-to-terminal relay security policy and parameters'. More specifically, the 'terminal-to-terminal relay security policy and parameters' may include at least one of a list of Relay Service Codes (RSCs) indicating terminal-to-terminal relay services that the terminal can use, 'hop-to-hop security settings' and 'end-to-end security settings' of a connection associated with the corresponding RSC(s), or security capabilities information of the terminal.
[0220] In one embodiment, the 'Hop-by-Hop Security Setting' may be referred to as a Hop-by-Hop Security Indicator. The 'Hop-by-Hop Security Setting' may include at least one of a control plane integrity setting in hop-by-hop security, a control plane confidentiality setting in hop-by-hop security, a user plane integrity setting in hop-by-hop security, or a user plane confidentiality setting in hop-by-hop security.
[0221] In one embodiment, the 'end-to-end security setting' may be referred to as an End-to-End Security Indicator and may include at least one of a control plane integrity setting in end-to-end security, a control plane confidentiality setting in end-to-end security, a user plane integrity setting in end-to-end security, or a user plane confidentiality setting in end-to-end security.
[0222] According to one embodiment, the settings of the Hop-by-Hop Security Indicator and the End-to-End Security Indicator can be one of three values: Required, Preferred, or Not Needed, or one of two values: Required or Not Needed.
[0223] According to one embodiment, the components included in the Hop-by-Hop Security Indicator or the End-to-End Security Indicator may be provided to the terminal by being set to appropriate values based on the terminal-to-terminal relay service unit (e.g., RSC), the terminal's capacity (e.g., power and computational resources), the terminal's version, or a combination thereof.
[0224] In one embodiment, the Hop-by-Hop Security Indicator or End-to-End Security Indicator may be used as a policy and parameter that serves as a basis for discovering and selecting neighboring terminals in a terminal-to-terminal relay discovery procedure. In one embodiment, the Hop-by-Hop Security Indicator or End-to-End Security Indicator may be used as a policy and parameter that serves as a basis for negotiating a security method in a terminal-to-terminal relay connection establishment procedure.
[0225] According to one embodiment, the security capabilities information of the terminal may mean a list of protection algorithms that the terminal can apply for security, and may include at least one of a list of control plane integrity protection algorithms in hop-by-hop security, a list of control plane confidentiality protection algorithms in hop-by-hop security, a list of user plane integrity protection algorithms in hop-by-hop security, a list of user plane confidentiality protection algorithms in hop-by-hop security, a list of control plane integrity protection algorithms in end-to-end security, a list of control plane confidentiality protection algorithms in end-to-end security, a list of user plane integrity protection algorithms in end-to-end security, or a list of user plane confidentiality protection algorithms in end-to-end security, in various combinations or forms.
[0226] At step (910), the Relay UE (902) can discover neighboring UE(s) supporting a terminal-to-terminal relay service identified by a specific RSC through a series of broadcast message exchange procedures. UE 1 (901) and UE 2 (903) discovered by the Relay UE (902) can establish a terminal-to-terminal relay connection to the specific RSC via the Relay UE (902).
[0227] At step (915), UE 1 (901) may transmit a Direct Communication Request message to Relay UE (902) to establish a terminal-to-terminal relay connection for a specific RSC with UE 2 (903). According to one embodiment, the message transmitted by UE 1 (901) may include at least one of an RSC identifying a specific terminal-to-terminal relay service, a Hop-by-Hop Security Indicator of UE 1 (901) associated with the RSC, an End-to-End Security Indicator of UE 1 (901) associated with the RSC, or security capabilities information of UE 1 (901).
[0228] In step (920), UE 1 (901) and Relay UE (902) may perform authentication and key formation procedures to establish hop-by-hop security during terminal-to-terminal relay. According to one embodiment, Relay UE (902) may reject the Direct Communication Request of UE 1 (901) if the Hop-by-Hop Security Indicator of Relay UE (902) is Not Needed and the Hop-by-Hop Security Indicator of UE 1 (901) received in step (915) is Required, or if the Hop-by-Hop Security Indicator of Relay UE (902) is Required and the Hop-by-Hop Security Indicator of UE 1 (901) received in step (915) is Not Needed, and may omit step (920) and / or subsequent procedures.
[0229] In steps (925) to (930), UE 1 (901) and Relay UE (902) can establish hop-by-hop security. The hop-by-hop security method of UE 1 (901) and Relay UE (902) can be negotiated based on the Hop-by-Hop Security Indicator and security capabilities information acquired by each terminal in steps (905-a, 905-b, 905-c).
[0230] In step (925), the Relay UE (902) may transmit a Direct Security Mode Command message including information necessary for establishing hop-by-hop security with UE 1 (901). According to one embodiment, the message transmitted by the Relay UE (902) may include at least one of a Hop-by-Hop Security Indicator of UE 1 (901), security capabilities information of UE 1 (901), or protection algorithm(s) selected by the Relay UE (902) to apply to hop-by-hop security based on the security capabilities information of UE 1 (901).
[0231] According to one embodiment, the Relay UE (902) may select a NULL protection algorithm and apply it to hop-by-hop security when the Hop-by-Hop Security Indicator of the Relay UE (902) is Not Needed or Preferred. If the selected protection algorithm is a NULL protection algorithm, the Relay UE (902) may transmit a Direct Security Mode Command message without applying protection to UE 1 (201). According to one embodiment, the Relay UE (902) may select a Non-NULL protection algorithm and apply it to hop-by-hop security when the Hop-by-Hop Security Indicator of the Relay UE (902) is Required or Preferred. If the selected protection algorithm is a Non-NULL protection algorithm, the Relay UE (902) may transmit a Direct Security Mode Command message with applying integrity protection to UE 1 (201). When applying the Non-Null protection algorithm to hop-by-hop security, the Relay UE (902) can protect the message between UE 1 (901) and the Relay UE (902) based on the key formed in step (920).
[0232] In step (930), UE 1 (901) can determine whether the hop-by-hop security setting of Relay UE (902) is valid based on the message received in step (925), and can transmit a Direct Security Mode Complete message to Relay UE (902). According to one embodiment, UE 1 (901) can check whether the Hop-by-Hop Security Indicator and security capabilities information of UE 1 (901) match the Hop-by-Hop Security Indicator and security capabilities information of UE 1 (901) included in the received message. By checking the match of the information, UE 1 (901) can prevent a bidding-down attack.
[0233] According to one embodiment, UE 1 (901) may transmit a Direct Security Mode Complete message with no protection applied to the Relay UE (902) when the Hop-by-Hop Security Indicator of UE 1 (901) is Not Needed or Preferred and the protection algorithm selected by the Relay UE (902) included in the received message is a NULL protection algorithm. According to one embodiment, UE 1 (901) may transmit a Direct Security Mode Complete message with integrity and / or confidentiality protection applied to the Relay UE (902) when the Hop-by-Hop Security Indicator of UE 1 (901) is Required or Preferred and the protection algorithm selected by the Relay UE (902) included in the received message is a Non-NULL protection algorithm. When applying the Non-NULL protection algorithm to hop-by-hop security, UE 1 (901) can protect messages between UE 1 (901) and Relay UE (902) based on the key formed in step (920).
[0234] In step (935), the Relay UE (902) may transmit a Direct Communication Request message to the UE 2 (903) to mediate a relay connection between UE 1 (901) and UE 2 (903) identified by a specific RSC. According to one embodiment, the message transmitted by the Relay UE (902) may include at least one of an RSC identifying a specific terminal-to-terminal relay service, a Hop-by-Hop Security Indicator of the Relay UE (902) associated with the RSC, security capabilities information of the Relay UE (902), an End-to-End Security Indicator of the UE 1 (901) associated with the RSC, or security capabilities information of the UE 1 (901).
[0235] In step (940), Relay UE (902) and UE 2 (903) may perform authentication and key formation procedures to establish hop-by-hop security during terminal-to-terminal relay. According to one embodiment, if the Hop-by-Hop Security Indicator of UE 2 (903) is Not Needed and the Hop-by-Hop Security Indicator of Relay UE (902) received in step (935) is Required, or if the Hop-by-Hop Security Indicator of UE 2 (903) is Required and the Hop-by-Hop Security Indicator of Relay UE (902) received in step (935) is Not Needed, UE 2 (903) may reject the Direct Communication Request of Relay UE (902) and skip step (940) and / or subsequent procedures.
[0236] In steps (945) to (950), Relay UE (902) and UE 2 (903) can establish hop-by-hop security. The hop-by-hop security method of Relay UE (902) and UE 2 (903) can be negotiated based on the Hop-by-Hop Security Indicator and security capabilities information acquired by each terminal in steps (905-a, 905-b, 905-c).
[0237] At step (945), UE 2 (903) may transmit a Direct Security Mode Command message including information necessary for establishing hop-by-hop security with Relay UE (902). According to one embodiment, the message transmitted by UE 2 (902) may include at least one of a Hop-by-Hop Security Indicator of Relay UE (902), security capabilities information of Relay UE (902), and protection algorithm(s) selected by UE 2 (903) to apply to hop-by-hop security based on the security capabilities information of Relay UE (902).
[0238] According to one embodiment, when the Hop-by-Hop Security Indicator of UE 2 (903) is Not Needed or Preferred, UE 2 (903) may select a NULL protection algorithm and apply it to hop-by-hop security. When the selected protection algorithm is a NULL protection algorithm, UE 2 (903) may transmit a Direct Security Mode Command message without applying protection to the Relay UE (902). According to one embodiment, when the Hop-by-Hop Security Indicator of UE 2 (903) is Required or Preferred, UE 2 (903) may select a Non-NULL protection algorithm and apply it to hop-by-hop security. When the selected protection algorithm is a Non-NULL protection algorithm, UE 2 (903) may transmit a Direct Security Mode Command message with applying integrity protection to the Relay UE (902). When applying the Non-NULL protection algorithm to hop-by-hop security, UE 2 (903) can protect messages between Relay UE (902) and UE 2 (903) based on the key formed in step (940).
[0239] In step (950), the Relay UE (902) can determine whether the hop-by-hop security setting of UE 2 (903) is valid based on the message received in step (945), and can transmit a Direct Security Mode Complete message to UE 2 (903). According to one embodiment, the Relay UE (902) can confirm whether the Hop-by-Hop Security Indicator and security capabilities information of the Relay UE (902) match the Hop-by-Hop Security Indicator and security capabilities information of the Relay UE (902) included in the received message. The Relay UE (902) can prevent a bidding-down attack according to the information verification procedure.
[0240] According to one embodiment, the Relay UE (902) may transmit a Direct Security Mode Complete message without applying protection to UE 2 (903) when the Hop-by-Hop Security Indicator of the Relay UE (902) is Not Needed or Preferred and the protection algorithm selected by UE 2 (903) included in the received message is a NULL protection algorithm. According to one embodiment, the Relay UE (902) may transmit a Direct Security Mode Complete message with applying integrity and / or confidentiality protection to UE 2 (903) when the Hop-by-Hop Security Indicator of the Relay UE (902) is Required or Preferred and the protection algorithm selected by UE 2 (903) included in the received message is a Non-NULL protection algorithm. When applying the Non-NULL protection algorithm to hop-by-hop security, the Relay UE (902) can protect the message between the Relay UE (902) and UE 2 (903) based on the key formed in step (945).
[0241] In step (955), UE 2 (903) can confirm that a hop-to-hop security method has been negotiated with Relay UE (902) based on the message received in step (950), and can transmit a Direct Communication Accept message to Relay UE (902). According to one embodiment, UE 2 (903) can verify the integrity of the received message to confirm that a hop-to-hop security method has been negotiated. According to one embodiment, if the protection algorithm selected by UE 2 (903) in step (945) is a Non-NULL protection algorithm, UE 2 (903) can transmit a Direct Communication Accept message with integrity and / or confidentiality protection applied to Relay UE (902). When applying the Non-NULL protection algorithm to hop-to-hop security, UE 2 (903) can protect the message between Relay UE (902) and UE 2 (903) based on the key formed in step (940).
[0242] In step (960), the Relay UE (902) can confirm that a hop-to-hop security method has been negotiated with UE 1 (901) based on the message received in step (930), and can transmit a Direct Communication Accept message to UE 1 (901). According to one embodiment, the Relay UE (902) can verify the integrity of the received message to confirm that a hop-to-hop security method has been negotiated. According to one embodiment, if the protection algorithm selected by the Relay UE (902) in step (925) is a Non-NULL protection algorithm, the Relay UE (902) can transmit a Direct Communication Accept message with integrity and / or confidentiality protection applied to UE 1 (901). When applying the Non-NULL protection algorithm to hop-to-hop security, the Relay UE (902) can protect the message between UE 1 (901) and the Relay UE (902) based on the key formed in step (920).
[0243] In step (965), UE 1 (901) and UE 2 (903) may perform authentication and key formation procedures to establish end-to-end security during terminal-to-terminal relay. According to one embodiment, if the End-to-End Security Indicator of UE 2 (903) is Not Needed and the End-to-End Security Indicator of UE 1 (901) received in step (935) is Required, or if the End-to-End Security Indicator of UE 2 (903) is Required and the End-to-End Security Indicator of UE 1 (901) received in step (935) is Not Needed, UE 2 (903) may reject the Direct Communication Request of UE 1 (901) and skip step (965) and / or subsequent procedures.
[0244] In steps (970) to (975), UE 1 (901) and UE 2 (903) can establish end-to-end security. The end-to-end security method of UE 1 (901) and UE 2 (903) can be negotiated based on the End-to-End Security Indicator and security capabilities information acquired by each terminal in steps (905-a, 905-b, 905-c).
[0245] At step (970), UE 2 (903) may transmit a Direct Security Mode Command message including information necessary for establishing end-to-end security with UE 1 (901) to UE 1 (901) via Relay UE (902). According to one embodiment, the message transmitted by UE 2 (902) may include at least one of the protection algorithm(s) selected by UE 2 (903) to be applied to end-to-end security based on at least one of the End-to-End Security Indicator of UE 1 (901), security capabilities information of UE 1 (901), or security capabilities information of UE 1 (901).
[0246] According to one embodiment, when the End-to-End Security Indicator of UE 2 (903) is Not Needed or Preferred, UE 2 (903) may select a NULL protection algorithm and apply it to end-to-end security. If the selected protection algorithm is a NULL protection algorithm, UE 2 (903) may transmit a Direct Security Mode Command message without applying protection to UE 1 (901). According to one embodiment, when the End-to-End Security Indicator of UE 2 (903) is Required or Preferred, UE 2 (903) may select a Non-NULL protection algorithm and apply it to end-to-end security. If the selected protection algorithm is a Non-NULL protection algorithm, UE 2 (903) may transmit a Direct Security Mode Command message with applying integrity protection to UE 1 (901). When applying the Non-NULL protection algorithm to end-to-end security, UE 2 (903) can protect the message between UE 1 (901) and UE 2 (903) based on the key formed in step (965).
[0247] In step (975), UE 1 (901) can determine whether the end-to-end security setting of UE 2 (903) is valid based on the message received in step (970), and can transmit a Direct Security Mode Complete message to UE 2 (903) via Relay UE (902). According to one embodiment, UE 1 (901) can check whether the End-to-End Security Indicator and security capabilities information of UE 1 (901) match the End-to-End Security Indicator and security capabilities information of UE 1 (901) included in the received message. UE 1 (901) can prevent a bidding-down attack through the information matching confirmation procedure.
[0248] According to one embodiment, UE 1 (901) may transmit a Direct Security Mode Complete message without applying protection to UE 2 (903) when the End-to-End Security Indicator of UE 1 (901) is Not Needed or Preferred and the protection algorithm selected by UE 2 (903) included in the received message is a NULL protection algorithm. According to one embodiment, UE 1 (901) may transmit a Direct Security Mode Complete message with applying integrity and / or confidentiality protection to UE 2 (903) when the End-to-End Security Indicator of UE 1 (901) is Required or Preferred and the protection algorithm selected by UE 2 (903) included in the received message is a Non-NULL protection algorithm. When applying the Non-NULL protection algorithm to end-to-end security, UE 1 (901) can protect the message between UE 1 (901) and UE 2 (903) based on the key formed in step (965).
[0249] In step (980), UE 2 (903) can confirm that the end-to-end security method has been negotiated with UE 1 (901) based on the message received in step (2150), and can transmit a Direct Communication Accept message to UE 1 (901) via Relay UE (902). According to one embodiment, UE 2 (903) can verify the integrity of the received message to confirm that the end-to-end security method has been negotiated. According to one embodiment, if the protection algorithm selected by UE 2 (903) in step (970) is a Non-NULL protection algorithm, UE 2 (903) can transmit a Direct Communication Accept message with integrity and / or confidentiality protection applied to UE 1 (201). When applying the Non-NULL protection algorithm to end-to-end security, UE 2 (903) can protect the message between UE 1 (901) and UE 2 (903) based on the key formed in step (965).
[0250] According to one embodiment, the signal flow for the end-to-end security method negotiation and the end-to-end security establishment method of steps (965) to (980) may be performed at a different layer than the hop-to-hop security method negotiation and the hop-to-hop security establishment method of steps (915) to (960). According to various embodiments of the present disclosure, the definition of the signal for the end-to-end security method negotiation and the end-to-hop security establishment method of steps (965) to (980) is not limited to the above-described definitions and may include various definitions different from the definitions of the signal for the hop-to-hop security method negotiation and the hop-to-hop security establishment method of steps (915) to (960) (e.g., Direct Security Mode Command, Direct Security Mode Complete, and Direct Communication Accept).
[0251] FIG. 10 illustrates the signal flow for terminals to discover terminals with which they can negotiate hop-by-hop security methods during a terminal-to-terminal relay discovery procedure, according to various embodiments of the present disclosure. More specifically, FIG. 10 illustrates the steps for a discovery procedure between a relay terminal and another terminal, applicable to various embodiments of the present disclosure.
[0252] Referring to FIG. 10, UE 1 (1001) and UE 2 (1003) disclosed in FIG. 10 may include part or all of the configuration of the terminal (111) illustrated in FIG. 1. In addition, Relay UE (1002) illustrated in FIG. 3 may include one of the terminals (111) illustrated in FIG. 1 and / or the NF illustrated in FIG. 1.
[0253] Steps (1005-a, 1005-b, 1005-c) may include the same operations as steps (905-a, 905-b, 905-c) of FIG. 2.
[0254] In step (1010), the Relay UE (1002) can discover neighboring UE(s) that support a terminal-to-terminal relay service identified by a specific RSC through a series of broadcast message exchange procedures. In the process of discovering neighboring UE(s), the Relay UE (1002) can obtain the User Info ID of each UE(s).
[0255] In step (1015), the Relay UE (1002) may transmit a UE-to-UE Relay Discovery Announcement message to adjacent terminal(s). According to one embodiment, the message transmitted by the Relay UE (1002) may include at least one of a User Info ID of the Relay UE (1002), a list of RSCs identifying terminal-to-terminal relay services that the Relay UE (1002) can mediate, a Hop-by-Hop Security Indicator of the Relay UE (1002) associated with the corresponding RSC(s), or a User Info ID of terminals associated with the corresponding RSC(s) obtained in step (1010).
[0256] According to one embodiment, if UE 1 (1001) or UE 2 (1003) receives a message from Relay UE (1002) and is authorized by the network in steps (1005-a, 1005-b, 1005-c) for a terminal-to-terminal relay service identifiable by the RSC included in the received message, UE 1 (1001) or UE 2 (1003) can check whether terminal-to-terminal relay connection establishment via Relay UE (1002) is possible. If the Hop-by-Hop Security Indicator of UE 1 (1001) or UE 2 (1003) is Required or Preferred and the Hop-by-Hop Security Indicator of Relay UE (1002) included in the received message is Required or Preferred, or if the Hop-by-Hop Security Indicator of UE 1 (1001) and UE 2 (1003) is Not Needed or Preferred and the Hop-by-Hop Security Indicator of Relay UE (1002) included in the received message is Not Needed or Preferred, UE 1 (1001) and UE 2 (1003) may be able to establish a terminal-to-terminal relay connection through Relay UE (1002).
[0257] Step (1020) may include at least one of all, part, or a combination of parts of steps (915) to (980) of FIG. 9.
[0258] FIG. 11 illustrates the signal flow for terminals to discover terminals capable of negotiating hop-by-hop security and end-to-end security methods during a discovery procedure during terminal-to-terminal relay, according to various embodiments of the present disclosure. More specifically, FIG. 11 illustrates the steps for a discovery procedure between a relay terminal and another terminal, applicable to various embodiments of the present disclosure.
[0259] Referring to FIG. 11, UE 1 (1101) and UE 2 (1103) disclosed in FIG. 11 may include part or all of the configuration of the terminal (111) illustrated in FIG. 1. In addition, Relay UE (1102) illustrated in FIG. 11 may include one of the terminals (111) illustrated in FIG. 1 and / or the NF illustrated in FIG. 1.
[0260] Steps (1105-a, 1105-b, 1105-c) may include the same operations as steps (905-a, 905-b, 905-c) of FIG. 2.
[0261] In step (1110), UE 1 (1101) may transmit a UE-to-UE Relay Discovery Solicitation message to discover a terminal with which to establish a terminal-to-terminal relay connection. According to one embodiment, the message transmitted by UE 1 (1101) may include at least one of a User Info ID of UE 1 (1101), an RSC identifying a terminal-to-terminal relay service, a Hop-by-Hop Security Indicator of UE 1 (1101) associated with the corresponding RSC, an End-to-End Security Indicator of UE 1 (1101) associated with the corresponding RSC, or a User Info ID of UE 2 (1103).
[0262] In step (1115), if Relay UE (1102) determines that it can mediate terminal relay service between UE 1 (1101) and UE 2 (1103) based on the received message, it can transmit a Relay Discovery Solicitation message to UE 2 (1103).
[0263] According to one embodiment, when the Relay UE (1102) is authorized by the network for a terminal-to-terminal relay service identifiable by the RSC included in the received message in steps (1105-a, 1105-b, 1105-c), if the Hop-by-Hop Security Indicator of the Relay UE (1102) is Required or Preferred and the Hop-by-Hop Security Indicator of UE 1 (1101) included in the received message is Required or Preferred, or if the Hop-by-Hop Security Indicator of the Relay UE (1102) is Not Needed or Preferred and the Hop-by-Hop Security Indicator of UE 1 (1101) included in the received message is Not Needed or Preferred, the Relay UE (1102) may mediate a terminal-to-terminal relay connection between UE 1 (1101) and UE 2 (1103). According to one embodiment, the message transmitted by the Relay UE (1102) may include at least one of the User Info ID of UE 1 (1101), the User Info ID of the Relay UE (1102), the RSC identifying the terminal-to-terminal relay service, the Hop-by-Hop Security Indicator of the Relay UE (1102) associated with the corresponding RSC, the End-to-End Security Indicator of the UE 1 (1101) associated with the corresponding RSC, or the User Info ID of the UE 2 (1103).
[0264] In step (1120), UE 2 (1103) can determine whether a terminal-to-terminal relay connection can be established based on the received message and transmit a UE-to-UE Relay Discovery Response message to Relay UE (1102).
[0265] According to one embodiment, when the Hop-by-Hop Security Indicator of UE 2 (1103) is Required or Preferred and the Hop-by-Hop Security Indicator of Relay UE (1102) included in the received message is Required or Preferred, or when the Hop-by-Hop Security Indicator of UE 2 (1103) is Not Needed or Preferred and the Hop-by-Hop Security Indicator of Relay UE (1102) included in the received message is Not Needed or Preferred, Relay UE (1102) and UE 2 (1103) can establish a hop-by-hop connection of a terminal-to-terminal relay.
[0266] According to one embodiment, when the End-to-End Security Indicator of UE 2 (1103) is Required or Preferred and the End-to-End Security Indicator of UE 1 (1101) included in the received message is Required or Preferred, or when the End-to-End Security Indicator of UE 2 (1103) is Not Needed or Preferred and the End-to-End Security Indicator of UE 1 (1101) included in the received message is Not Needed or Preferred, UE 1 (1101) and UE 2 (1103) can establish an end-to-end connection of a terminal-to-terminal relay.
[0267] According to one embodiment, the message transmitted by UE 2 (1103) may include at least one of an RSC identifying a terminal-to-terminal relay service, a User Info ID of UE 1 (1101), or a User Info ID of UE 2 (1103). According to one embodiment, even when UE 2 (1103) receives a UE-to-UE Relay Discovery Solicitation message from multiple Relay UEs (1102), it may determine whether to send a response message thereto.
[0268] In step (1125), Relay UE (1102) may transmit a UE-to-UE Relay Discovery Response message to UE 1 (1101) based on the received message. According to one embodiment, the message transmitted by Relay UE (1102) may include at least one of User Info ID of Relay UE (1102) or User Info ID of UE 2 (1103).
[0269] Step (1130) may include at least one of all, part, or a combination of parts of steps (915) to (980) of FIG. 9.
[0270] FIG. 12 illustrates another signal flow for terminals to negotiate and establish hop-to-hop security and end-to-end security methods during terminal-to-terminal relay, according to various embodiments of the present disclosure. More specifically, according to various embodiments of the present disclosure, the operations disclosed in FIG. 12 may be performed independently or in place of or in combination with the operations disclosed in FIG. 9.
[0271] Referring to FIG. 12, UE 1 (1201) and UE 2 (503) disclosed in FIG. 12 may include part or all of the configuration of the terminal (111) illustrated in FIG. 1. In addition, Relay UE (1202) illustrated in FIG. 5 may include one of the terminals (111) illustrated in FIG. 1 and / or the NF illustrated in FIG. 1.
[0272] Steps (1205-a, 1205-b, 1205-c) may include the operations of steps (905-a, 905-b, 905-c) of FIG. 9.
[0273] In step (1210), UE 1 (1201) may transmit a Direct Communication Request message to Relay UE (1202). According to an embodiment, UE 1 (1201) may transmit the Direct Communication Request message to Relay UE (1202) to establish a terminal-to-terminal relay connection for a specific RSC with UE 2 (1203). According to an embodiment, the message transmitted by UE 1 (1201) may include at least one of a relay_indication field indicating that the discovery procedure and the connection establishment procedure are integrated, an RSC identifying a specific terminal-to-terminal relay service, a Hop-by-Hop Security Indicator of UE 1 (1201) associated with the RSC, an End-to-End Security Indicator of UE 1 (1201) associated with the RSC, or security capabilities information of UE 1 (1201).
[0274] At step (1215), Relay UE (1202) may transmit a Direct Communication Request message to UE 2 (1203). According to one embodiment, Relay UE (1202) may transmit the Direct Communication Request message to UE 2 (1203) to mediate a relay connection between UE 1 (1201) and UE 2 (1203) identified by a specific RSC. According to one embodiment, a message transmitted by a Relay UE (1202) may include at least one of a relay_indication field indicating that a discovery procedure and a connection establishment procedure are integrated, an RSC identifying a specific terminal-to-terminal relay service, a Hop-by-Hop Security Indicator of a Relay UE (1202) associated with the RSC, security capabilities information of the Relay UE (1202), an End-to-End Security Indicator of a UE 1 (1201) associated with the RSC, or security capabilities information of the UE 1 (1201).
[0275] Steps (1220) to (1235) may include at least one of all, part, or a combination of parts of steps (940) to (955) of FIG. 9.
[0276] Steps (1240) to (1250) may include at least one of all, part, or a combination of parts of steps (920) to (930) of FIG. 9.
[0277] Step (1255) may include step (960) of FIG. 2.
[0278] Steps (1260) to (1275) may include at least one of all, part, or a combination of parts of steps (965) to (980) of FIG. 2.
[0279] FIG. 13 illustrates the functional configuration of a terminal according to various embodiments of the present disclosure. The configuration illustrated in FIG. 13 may be understood as the configuration of a terminal (111). Terms such as "... unit" and "... unit" used hereinafter refer to a unit that processes at least one function or operation, which may be implemented using hardware, software, or a combination of hardware and software.
[0280] Referring to FIG. 13, the terminal includes a communication unit (1310), a storage unit (1320), and a control unit (1330).
[0281] The communication unit (1310) performs functions for transmitting and receiving signals via a wireless channel. For example, the communication unit (1310) performs a conversion function between a baseband signal and a bit stream according to the physical layer specifications of the system. For example, when transmitting data, the communication unit (1310) generates complex symbols by encoding and modulating a transmission bit stream. In addition, when receiving data, the communication unit (1310) restores a reception bit stream by demodulating and decoding the baseband signal. In addition, the communication unit (1310) upconverts a baseband signal to an RF band signal and transmits it through an antenna, and downconverts an RF band signal received through the antenna to a baseband signal. For example, the communication unit (1310) may include a transmission filter, a reception filter, an amplifier, a mixer, an oscillator, a DAC, an ADC, etc.
[0282] In addition, the communication unit (1310) may include a plurality of transmission and reception paths. Furthermore, the communication unit (1310) may include at least one antenna array composed of a plurality of antenna elements. In terms of hardware, the communication unit (1310) may be composed of digital circuits and analog circuits (e.g., radio frequency integrated circuits (RFIC)). Here, the digital circuits and analog circuits may be implemented in a single package. In addition, the communication unit (1310) may include a plurality of RF chains. Furthermore, the communication unit (1310) may perform beamforming.
[0283] The communication unit (1310) transmits and receives signals as described above. Accordingly, all or part of the communication unit (1310) may be referred to as a "transmitter," a "receiver," or a "transmitting and receiving unit." Furthermore, in the following description, transmission and reception performed via a wireless channel are used to mean processing performed by the communication unit (1310) as described above.
[0284] The storage unit (1320) stores data such as basic programs, application programs, and setting information for the operation of the terminal. The storage unit (1320) may be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. In addition, the storage unit (1320) provides the stored data upon request from the control unit (1330).
[0285] The control unit (1330) controls the overall operations of the terminal. For example, the control unit (1330) transmits and receives signals through the communication unit (1310). In addition, the control unit (1330) records and reads data in the storage unit (1320). In addition, the control unit (1330) can perform the functions of the protocol stack required by the communication standard. To this end, the control unit (1330) may include at least one processor or microprocessor, or may be a part of a processor. In addition, a part of the communication unit (1310) and the control unit (1330) may be referred to as a CP (communication processor). According to various embodiments, the control unit (1330) may control the terminal to perform synchronization using a wireless communication network. For example, the control unit (1330) may control the terminal to perform operations according to the various embodiments described above.
[0286] Although FIG. 13 illustrates an example of a terminal, various modifications may be made to FIG. 13 . For example, various components in FIG. 13 may be combined, further divided, or omitted, and other components may be added according to special needs. Furthermore, as a specific example, the control unit (1330) may be divided into multiple processors, such as one or more central processing units (CPUs) and one or more graphics processing units (GPUs). Furthermore, although FIG. 13 illustrates a terminal configured as a mobile phone or a smart phone, the terminal may be configured to operate as other types of mobile or stationary devices.
[0287] FIG. 14 illustrates a functional configuration of a network entity according to various embodiments of the present disclosure. FIG. 14 illustrates a configuration of a core network object in a wireless communication system according to various embodiments of the present disclosure. The configuration illustrated in FIG. 14 may be understood as a configuration of a device having the function of at least one of the network entities including the AMF (180) or the AUSF (170) of FIG. 1. Terms such as “… unit” and “… device” used hereinafter mean a unit that processes at least one function or operation, and this may be implemented by hardware, software, or a combination of hardware and software.
[0288] Referring to the above drawing 14, the core network object is configured to include a communication unit (1410), a storage unit (1420), and a control unit (1430).
[0289] The communication unit (1410) provides an interface for communicating with other devices within the network. That is, the communication unit (1410) converts a bit string transmitted from a core network object to another device into a physical signal, and converts a physical signal received from another device into a bit string. That is, the communication unit (1410) can transmit and receive signals. Accordingly, the communication unit (1410) may be referred to as a modem, a transmitter, a receiver, or a transceiver. In this case, the communication unit (1410) enables the core network object to communicate with other devices or systems via a backhaul connection (e.g., a wired backhaul or a wireless backhaul) or via a network.
[0290] The storage unit (1420) stores data such as basic programs, application programs, and configuration information for the operation of the core network object. The storage unit (1420) may be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. In addition, the storage unit (1420) provides the stored data upon request from the control unit (1430).
[0291] The control unit (1430) controls the overall operations of the core network object. For example, the control unit (1430) transmits and receives signals through the communication unit (1410). Additionally, the control unit (1430) records and reads data from the storage unit (1420). For this purpose, the control unit (1430) may include at least one processor. According to various embodiments of the present disclosure, the control unit (1430) may control synchronization using a wireless communication network. For example, the control unit (1430) may control the core network object to perform operations according to the various embodiments described above.
[0292] In Fig. 14, the transceiver (1410) and the control unit (1430) are implemented as separate units, but the transceiver (1410) and the control unit (1430) may also be implemented as at least one processor. In addition, the network entity may be any one of a base station (RAN), AMF, SMF, UPF, PCF, NF, NEF, NRF, NSSF, UDM, UDR, AF, DN, AUSF, SCP, UDSF, context storage, OAM, EMS, AAA-P, and AAA-H.
[0293] The present disclosure provides a method and device for allowing terminals to negotiate hop-by-hop security and end-to-end security methods to safely protect data transmitted during relay between terminals, and thereby establish hop-by-hop security and end-to-end security.
[0294] In a wireless communication system according to one embodiment of the present disclosure, a method of a first terminal comprises the steps of: receiving hop-to-hop security and end-to-end security policies and parameters during terminal-to-terminal relay; discovering adjacent terminal(s) to establish a terminal-to-terminal relay connection; transmitting a first request message to a relay terminal, the first terminal including information necessary for establishing hop-to-hop security with the relay terminal and information necessary for establishing end-to-end security with a second terminal; performing mutual authentication and key formation with the relay terminal; receiving a first response message from the relay terminal including a hop-to-hop security method selected by the relay terminal based on the first request message; transmitting a second request message to the relay terminal to negotiate a hop-to-hop security method with the relay terminal; establishing hop-to-hop security with the relay terminal by receiving a second response message from the relay terminal; performing mutual authentication and key formation with the second terminal; receiving a third response message from the relay terminal including an end-to-end security method selected by the second terminal based on the first request message; and transmitting a third response message to the relay terminal. It may include a process of negotiating a terminal security method with the second terminal by transmitting a request message, and a process of establishing terminal security with the second terminal by receiving a fourth response message from the relay terminal.
[0295] In a wireless communication system according to one embodiment of the present disclosure, a method of a relay terminal comprises the steps of: receiving hop-by-hop security and end-to-end security policies and parameters when relaying between terminals; discovering adjacent terminal(s) to establish a terminal-to-terminal relay connection; receiving a first request message from a first terminal, the first terminal and the relay terminal including information necessary for establishing hop-by-hop security and information necessary for establishing end-to-end security between the first terminal and the second terminal; performing mutual authentication and key formation with the first terminal; transmitting a first response message including a hop-by-hop security method selected based on the first request message to the first terminal; receiving a second request message from the first terminal and negotiating a hop-by-hop security method with the first terminal; transmitting a third request message including information necessary for establishing hop-by-hop security between the relay terminal and the second terminal and information necessary for establishing end-to-end security between the first terminal and the second terminal to the second terminal; performing mutual authentication and key formation with the second terminal; and transmitting a second response message including a hop-by-hop security method selected based on the first request message to the first terminal. A process for receiving a second response message including a hop-by-hop security method selected based on a third request message, a process for transmitting a fourth request message to the second terminal to negotiate a hop-by-hop security method with the second terminal, a process for receiving a third response message from the second terminal to establish hop-by-hop security with the second terminal, a process for transmitting a fourth response message to the first terminal to establish hop-by-hop security with the first terminal, a process for receiving a fifth response message including an end-to-end security method selected by the second terminal based on the third request message from the second terminal, a process for transmitting the fifth response message to the first terminal, a process for receiving a fifth request message from the first terminal for negotiating an end-to-end security method with the second terminal, and a process for transmitting the fifth request message to the second terminal.It may include a process of receiving a sixth response message for establishing end-to-end security between the first terminal and the second terminal from the second terminal, and a process of transmitting the sixth response message to the first terminal.
[0296] In a wireless communication system according to one embodiment of the present disclosure, a method of a second terminal comprises the steps of: receiving hop-to-hop security and end-to-end security policies and parameters during terminal-to-terminal relay; discovering adjacent terminal(s) to establish a terminal-to-terminal relay connection; receiving a first request message from a relay terminal, the first request message including information necessary for establishing hop-to-hop security between the relay terminal and the second terminal and information necessary for establishing end-to-end security between the first terminal and the second terminal; performing mutual authentication and key formation with the relay terminal; transmitting a first response message including a hop-to-hop security method selected based on the first request message to the relay terminal; receiving a second request message from the relay terminal to negotiate a hop-to-hop security method with the relay terminal; transmitting a second response message to the relay terminal to establish hop-to-hop security with the relay terminal; performing mutual authentication and key formation with the first terminal; transmitting a third response message including an end-to-end security method selected by the second terminal based on the first request message to the relay terminal; receiving a third request message from the relay terminal It may include a process of negotiating a terminal security method with the first terminal, and a process of establishing terminal security with the first terminal by transmitting a fourth response message to the relay terminal.
[0297] In a wireless communication system according to one embodiment of the present disclosure, a method of a first terminal may include a process of receiving hop-by-hop security and end-to-end security policies and parameters during terminal-to-terminal relay, a process of receiving information necessary for establishing hop-by-hop security between the relay terminal and the first terminal from the relay terminal, and a process of performing a terminal-to-terminal relay connection procedure when hop-by-hop security can be established with the relay terminal.
[0298] In a wireless communication system according to one embodiment of the present disclosure, a method of a relay terminal may include a process of receiving hop-by-hop security and end-to-end security policies and parameters during terminal-to-terminal relay, a process of discovering adjacent terminal(s) with which to establish a terminal-to-terminal relay connection, a process of transmitting information necessary for establishing hop-by-hop security with the relay terminal to a first terminal and a second terminal, and a process of performing a terminal-to-terminal relay connection procedure when the first terminal, the second terminal, and the relay terminal are capable of establishing hop-by-hop security.
[0299] In a wireless communication system according to one embodiment of the present disclosure, a method of a second terminal may include a process of receiving hop-by-hop security and end-to-end security policies and parameters during terminal-to-terminal relay, a process of receiving information necessary for establishing hop-by-hop security between the relay terminal and the second terminal from the relay terminal, and a process of performing a terminal-to-terminal relay connection procedure when hop-by-hop security can be established with the relay terminal.
[0300] In a wireless communication system according to one embodiment of the present disclosure, a method of a first terminal may include a process of receiving a hop-by-hop security and end-to-end security policy and parameters during a terminal-to-terminal relay, a process of transmitting a first request message to a relay terminal, the first terminal including information necessary for establishing hop-by-hop security with a relay terminal and information necessary for establishing end-to-end security with a second terminal, a process of receiving a first response message from the relay terminal including information of the relay terminal with which the first terminal can establish hop-by-hop security and information of the second terminal with which the first terminal can establish end-to-end security, and a process of performing a terminal-to-terminal relay connection procedure when hop-by-hop security can be established with the relay terminal and end-to-end security can be established with the second terminal.
[0301] In a wireless communication system according to one embodiment of the present disclosure, a method of a relay terminal comprises the steps of: receiving a hop-by-hop security and end-to-end security policy and parameters when relaying between terminals; receiving a first request message from a first terminal, the first terminal and the relay terminal including information necessary for establishing hop-by-hop security and information necessary for establishing end-to-end security between the first terminal and the second terminal; transmitting a second request message to a second terminal, the second request message including information necessary for establishing hop-by-hop security between the relay terminal and the second terminal and information necessary for establishing end-to-end security between the first terminal and the second terminal; receiving a first response message from the second terminal, the first response message including information of the second terminal with which the relay terminal can establish hop-by-hop security and information of the second terminal with which the first terminal can establish end-to-end security; transmitting a second response message to the first terminal, the second response message including information of the relay terminal with which the first terminal can establish hop-by-hop security and information of the second terminal with which the first terminal can establish end-to-end security; If establishment is possible and hop-to-hop security can be established with the second terminal, a process for performing a terminal-to-terminal relay connection procedure may be included.
[0302] In a wireless communication system according to one embodiment of the present disclosure, a method of a second terminal may include a process of receiving a hop-to-hop security and end-to-end security policy and parameters during a terminal-to-terminal relay, a process of receiving a first request message including information necessary for establishing hop-to-hop security with the relay terminal and information necessary for establishing end-to-end security with the first terminal from the relay terminal, a process of transmitting a first response message including information of the second terminal capable of establishing hop-to-hop security with the relay terminal and information of the second terminal capable of establishing end-to-end security with the first terminal to the relay terminal, and a process of performing a terminal-to-terminal relay connection procedure when hop-to-hop security can be established with the relay terminal and end-to-end security can be established with the first terminal.
[0303] It should be noted that the aforementioned configuration diagrams, examples of control / data signal transmission methods, examples of operational procedures, and configuration diagrams are not intended to limit the scope of the present disclosure. That is, not all components, entities, or operational steps described in the embodiments of the present disclosure should be construed as essential components for implementing the disclosure, and implementations may be made without detracting from the essence of the disclosure even if only some components are included. Furthermore, each embodiment may be combined and operated as needed. For example, parts of the methods proposed in the present disclosure may be combined to operate network entities and terminals.
[0304] The operations of the base station or terminal described above can be realized by providing a memory device storing the corresponding program code in any component within the base station or terminal device. That is, the control unit of the base station or terminal device can execute the operations described above by reading and executing the program code stored in the memory device using a processor or CPU (Central Processing Unit).
[0305] The various components and modules of the entity, base station or terminal device described in this specification may be operated using hardware circuits, such as logic circuits based on complementary metal oxide semiconductors, firmware, software and / or hardware and firmware and / or software embedded in a machine-readable medium. For example, various electrical structures and methods may be implemented using electrical circuits such as transistors, logic gates and application-specific semiconductors.
[0306] When implemented in software, a computer-readable storage medium storing one or more programs (software modules) may be provided. The one or more programs stored in the computer-readable storage medium are configured for execution by one or more processors within an electronic device. The one or more programs include instructions that cause the electronic device to execute methods according to embodiments described in the claims or specification of the present disclosure.
[0307] These programs (software modules, software) may be stored in random access memory, non-volatile memory including flash memory, read only memory (ROM), electrically erasable programmable read only memory (EEPROM), magnetic disc storage device, compact disc ROM (CD-ROM), digital versatile discs (DVDs) or other forms of optical storage device, magnetic cassette. Or, they may be stored in a memory configured as a combination of some or all of these. In addition, each configuration memory may be included in multiple numbers.
[0308] Additionally, the program may be stored in an attachable storage device that is accessible via a communication network such as the Internet, an intranet, a local area network (LAN), a wide local area network (WLAN), a storage area network (SAN), or a combination thereof. Such a storage device may be connected to a device performing an embodiment of the present disclosure via an external port. Additionally, a separate storage device on the communication network may be connected to a device performing an embodiment of the present disclosure.
[0309] In the specific embodiments of the present disclosure described above, components included in the disclosure are expressed singularly or plurally, depending on the specific embodiment presented. However, the singular or plural expressions are selected to suit the presented situation for convenience of explanation, and the present disclosure is not limited to singular or plural components. Even components expressed in plural may be composed of singular elements, or even components expressed in singular may be composed of plural elements.
[0310] While the detailed description of the present disclosure has described specific embodiments, it should be understood that various modifications are possible without departing from the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be determined not only by the scope of the claims described below but also by equivalents thereof. In other words, it will be apparent to those skilled in the art that other modifications based on the technical idea of the present disclosure are possible. In addition, the above-described embodiments can be combined and operated with each other as needed. For example, parts of the methods proposed in the present disclosure can be combined with each other to operate a base station and a terminal. In addition, although the above-described embodiments have been presented based on a 5G, NR system, other modifications based on the technical idea of the above-described embodiments can be implemented with other systems such as LTE, LTE-A, and LTE-A-Pro systems.
[0311] While the detailed description of this disclosure has described specific embodiments, it should be understood that various modifications are possible without departing from the scope of this disclosure. Therefore, the scope of this disclosure should not be limited to the described embodiments, but should be defined not only by the scope of the claims described below, but also by equivalents thereof.
Claims
1. In a wireless communication system, a first terminal (user equipment, UE) transceiver; and Including a controller coupled to the above transmitter and receiver, The above controller, Obtain information related to the security of the first terminal and information about RSC (relay service code), Receive a first security policy parameter associated with the first terminal from a PCF (policy control function) entity, Transmitting a direct communication request message including information related to the security of the first terminal and the first security policy parameter to a relay UE, If hop-by-hop security establishment between the first terminal and the relay terminal is determined based on the first security policy parameter, information related to the security of the relay terminal is received from the relay terminal, and A first terminal configured to perform hop-to-hop security establishment by verifying information related to the security of the relay terminal.
2. In claim 1, if the establishment of end-to-end security between the first terminal and the second terminal is determined based on the first security policy parameter, the controller, Receive information related to the security of the second terminal from the relay terminal, and A first terminal configured to establish end-to-end security by verifying information related to the security of the second terminal.
3. In claim 1, the controller, Receive a discovery announcement message from the relay terminal, the discovery announcement message including a second security policy parameter associated with the relay terminal, and A first terminal further configured to determine the hop-by-hop security establishment between the first terminal and the relay terminal based on the first security policy parameter and the second security policy parameter.
4. In claim 1, the controller, Further configured to transmit a discovery solicitation message including the first security policy parameter to the relay terminal, The end-to-end security establishment between the first terminal and the second terminal is determined based on the first security policy parameter and the third security policy parameter associated with the second terminal.
5. In claim 3, A first terminal, wherein the first security policy parameter or the second security policy parameter includes at least one of a per-RSC hop-to-hop security indicator or an per-RSC end-to-end security indicator.
6. In a wireless communication system, a relay terminal (user equipment, UE) is transceiver; and Including a controller coupled to the above transmitter and receiver, The above controller, Obtain information related to the security of the above relay terminal, information about RSC (relay service code), Receive a first security policy parameter associated with the relay terminal from a PCF (policy control function) entity, Receive a direct communication request message from a first terminal, the direct communication request message including information related to the security of the first terminal and a second security policy parameter associated with the first terminal; When hop-by-hop security establishment between the first terminal and the relay terminal is determined based on the first security policy parameter and the second security policy parameter, information related to the security of the relay terminal is transmitted to the first terminal, and A relay terminal configured to perform hop-to-hop security establishment by verifying information related to the security of the first terminal.
7. In claim 6, if end-to-end security establishment between the first terminal and the second terminal is determined based on the first security policy parameter, the controller, Transmit the direct communication request message to the second terminal, Receive information related to the security of the second terminal from the second terminal, and A relay terminal configured to transmit information related to the security of the second terminal to the first terminal.
8. In claim 6, the controller, Performing a discovery procedure of the second terminal associated with the RSC, and Further configured to transmit a discovery announcement message including a first security policy parameter associated with the relay terminal to the first terminal, A relay terminal in which the hop-by-hop security establishment between the first terminal and the relay terminal is determined based on the first security policy parameter and the second security policy parameter.
9. In claim 6, the controller, Receive a discovery solicitation message including the first security policy parameter from the first terminal, and Further configured to transmit the discovery request message to the second terminal, A relay terminal in which end-to-end security establishment between the first terminal and the second terminal is determined based on the second security policy parameter and the third security policy parameter associated with the second terminal.
10. In claim 8, A relay terminal, wherein the first security policy parameter or the second security policy parameter includes at least one of a hop-by-hop security indicator per RSC or an end-to-end security indicator per RSC.
11. In a wireless communication system, a method performed by a first terminal (user equipment, UE) comprises: A step of obtaining information related to the security of the first terminal and information about RSC (relay service code); A step of receiving a first security policy parameter associated with the first terminal from a PCF (policy control function) entity; A step of transmitting a direct communication request message including information related to the security of the first terminal and the first security policy parameter to a relay UE; A step of receiving information related to the security of the relay terminal from the relay terminal when hop-by-hop security establishment between the first terminal and the relay terminal is determined based on the first security policy parameter; and A method comprising a step of performing hop-to-hop security establishment by verifying information related to the security of the relay terminal.
12. In claim 11, if end-to-end security establishment between the first terminal and the second terminal is determined based on the first security policy parameter, the method comprises: A step of receiving information related to the security of the second terminal from the relay terminal; and A method comprising a step of establishing end-to-end security by verifying information related to the security of the second terminal.
13. In claim 11, the method comprises: A step of receiving a discovery announcement message including a second security policy parameter associated with the relay terminal from the relay terminal; and A method further comprising a step of determining the establishment of hop-by-hop security between the first terminal and the relay terminal based on the first security policy parameter and the second security policy parameter.
14. In claim 11, the method comprises: Further comprising a step of transmitting a discovery solicitation message including the first security policy parameter to the relay terminal, A method in which end-to-end security establishment between the first terminal and the second terminal is determined based on the first security policy parameter and the third security policy parameter associated with the second terminal.
15. In claim 13, A method wherein the first security policy parameter or the second security policy parameter includes at least one of a per-RSC hop-by-hop security indicator or an per-RSC end-to-end security indicator.
Citation Information
Patent Citations
Method and apparatus for providing secure communication with a relay in a network
US6643701B1