Medium access control layer security
By applying cryptographic protection specifically to the MAC layer through the use of protected and unprotected transport blocks, the vulnerability of MAC control elements in current mobile communication systems is addressed, enhancing security and preventing attacks.
Patent Information
- Application Number
- PCT/EP2024/079431
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-22
- Filing Date
- 2024-10-18
- Publication Date
- 2025-05-30
AI Technical Summary
Current mobile communication systems lack effective cryptographic protection for the medium access control (MAC) layer, making them vulnerable to attacks that exploit the lack of protection for MAC control elements (MAC CEs).
The implementation of a security solution that applies cryptographic protection on the MAC layer by distinguishing between two types of transport blocks (TBs): one that requires protection and another that does not. This approach ensures that sensitive information is protected while allowing unprotected traffic to be transmitted efficiently.
This solution effectively prevents attacks targeting unprotected MAC CEs, enhances security for RLC and PDCP control messages and headers, and secures the complete control plane protocol stack, thereby improving the overall security and trustworthiness of the communication system.
Smart Images

Figure EP2024079431_30052025_PF_FP_ABST
Abstract
Description
MEDIUM ACCESS CONTROL LAYER SECURITYFIELDS[1] Various example embodiments of the present disclosure generally relate to the field of telecommunication and in particular, to methods, devices, apparatuses and computer readable storage medium for medium access control (MAC) layer security.BACKGROUND[2] Mobile security is a protection of portable computing devices, and the networks they connect to, from threats and vulnerabilities associated with wireless computing. Cryptographic protection of traffic on the radio interface is one of the most important security requirements for mobile networks. Consequently, it has been specified since 2ndgeneration (2G) communication system, in different flavors. For example, in 2G communication systems, circuit switched on encryption on the physical layer and 2G packet switched which includes encryption on logical link control (LLC) layer between user equipment (UE) and serving general packet radio service (GPRS) support node (SGSN). In 3rdgeneration (3G) communication systems, it introduces integrity protection (IP) for radio resource control (RRC) messages which is done on the RRC layer, and encryption for RRC and user plane traffic which is done on the radio link control (RLC) layer for RLC acknowledged mode (AM) and unacknowledged (UM) and on the medium access control (MAC) layer for RLC transparent mode (TM). Moreover, the 4thgeneration (4G) communication system proposes encryption for control plane (CP) and user plane (UP) on packet data convergence protocol (PDCP) layer and IP for the CP on the PDCP layer. Additionally, in 5thgeneration (5G) communication systems, it introduces encryption and IP for CP and UP on the PDCP layer.SUMMARY[3] In a first aspect of the present disclosure, there is provided a first apparatus. The first apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus to: obtain protection information indicating which control information and data require a security protection on a first protocol layer; determine whether to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer based ion the obtained protection information; apply the security protection if it is determined to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer; generate, based on the protection information, a transport block that comprises at least one of the at least one first protocol data unit at the first protocol layer that requires protection, and at least one second protocol data unit at the second protocol layer that requires protection, wherein the first protocol layer is lower than the second protocol layer, wherein the transport block further comprises information indicating whether the security protection is applied to one or more protocol data units at the first protocol layer; and transmit the transport block to a second apparatus.[4] In a second aspect of the present disclosure, there is provided a second apparatus. The second apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second apparatus to: obtain protection information indicating which control information and data require a security protection on a first protocol layer; receive, from a first apparatus a transport block that comprises one or more protocol data units, wherein the transport block comprises information indicating whether the security protection is applied to the one or more protocol data units at the first protocol layer; determine whether a protocol data unit in the one or more protocol data units requires the security protection based on the protection information; determine whether the security protection is applied to the protocol data unit in the one or more protocol data units based on the information indicating to which one or more protocol data units the security protection is applied; and process the protocol data unit based on the determinations.[5] In a third aspect of the present disclosure, there is provided a method. The method comprises: obtaining protection information indicating which control information and data require a security protection on a first protocol layer; determining whether to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer based on the obtained protection information; applying the security protection if it is determined to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer; generating, based on the protection information, a transport block that comprises at least one of: the at least one first protocol data unit at the first protocollayer that requires protection, and at least one second protocol data unit at the second protocol layer that requires protection, wherein the first protocol layer is lower than the second protocol layer, wherein the transport block further comprises information indicating whether the security protection is applied to one or more protocol data units at the first protocol layer; and transmitting the transport block to a second apparatus.[6] In a fourth aspect of the present disclosure, there is provided a method. The method comprises: obtaining protection information indicating which control information and data require a security protection on a first protocol layer; receiving, from a first apparatus a transport block that comprises one or more protocol data units, wherein the transport block comprises information indicating whether the security protection is applied to the one or more protocol data units at the first protocol layer; determining whether a protocol data unit in the one or more protocol data units requires the security protection based on the protection information; determining whether the security protection is applied to the protocol data unit in the one or more protocol data units based on the information indicating to which one or more protocol data units the security protection is applied; and processing the protocol data unit based on the determinations.[7] In a fifth aspect of the present disclosure, there is provided a first apparatus. The first apparatus comprises means for obtaining protection information indicating which control information and data require a security protection on a first protocol layer; means for determining whether to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer based on the obtained protection information; means for applying the security protection if it is determined to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer; means for generating, based on the protection information, a transport block that comprises at least one of the at least one first protocol data unit at the first protocol layer that requires protection, and at least one second protocol data unit at the second protocol layer that requires protection, wherein the first protocol layer is lower than the second protocol layer, wherein the transport block further comprises information indicating whether the security protection is applied to one or more protocol data units at the first protocol layer; and means for transmitting the transport block to a second apparatus.[8] In a sixth aspect of the present disclosure, there is provided a second apparatus. Thesecond apparatus comprises means for obtaining protection information indicating which control information and data require a security protection on a first protocol layer; means for receiving, from a first apparatus a transport block that comprises one or more protocol data units, wherein the transport block comprises information indicating whether the security protection is applied to the one or more protocol data units at the first protocol layer; means for determining whether a protocol data unit in the one or more protocol data units requires the security protection based on the protection information; means for determining whether the security protection is applied to the protocol data unit in the one or more protocol data units based on the information indicating to which one or more protocol data units the security protection is applied; and means for processing the protocol data unit based on the determinations.[9] In a seventh aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the third aspect.
[0010] In an eighth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the fourth aspect.
[0011] It is to be understood that the Summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description.BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Some example embodiments will now be described with reference to the accompanying drawings, where:
[0013] FIG. 1 illustrates a schematic diagram of overall architecture for separation of gNB- Centralized Unit (CU) -control plane (CP) and gNB-CU-user plane (UP);
[0014] FIG. 2 illustrates an example communication environment in which example embodiments of the present disclosure can be implemented;
[0015] FIG. 3 illustrates a schematic diagram of radio interface protocol stack;
[0016] FIG. 4 illustrates a schematic diagram of MAC protocol data unit (PDU);
[0017] FIG. 5 A illustrates a signaling chart for MAC layer security according to some example embodiments of the present disclosure;
[0018] FIG. 5B illustrates a signaling chart for MAC layer security according to some example embodiments of the present disclosure;
[0019] FIG. 6A to FIG. 6E illustrate schematic diagrams of transport blocks (TBs) according to some example embodiments of the present disclosure, respectively;
[0020] FIG. 7 illustrates a flowchart of a method implemented at a first device according to some example embodiments of the present disclosure;
[0021] FIG. 8 illustrates a flowchart of a method implemented at a second device according to some example embodiments of the present disclosure;
[0022] FIG. 9 illustrates a simplified block diagram of a device that is suitable for implementing example embodiments of the present disclosure; and
[0023] FIG. 10 illustrates a block diagram of an example computer readable medium in accordance with some example embodiments of the present disclosure.
[0024] Throughout the drawings, the same or similar reference numerals represent the same or similar element.DETAILED DESCRIPTION
[0025] Principle of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. Embodiments described herein can be implemented in various manners other than the ones described below.
[0026] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0027] References in the present disclosure to “one embodiment,” “an embodiment,” “an example embodiment,” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, suchphrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
[0028] It shall be understood that although the terms “first,” “second,”..., etc. in front of noun(s) and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another and they do not limit the order of the noun(s). For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.
[0029] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0030] As used herein, unless stated explicitly, performing a step “in response to A” does not indicate that the step is performed immediately after “A” occurs and one or more intervening steps may be included.
[0031] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises”, “comprising”, “has”, “having”, “includes” and / or “including”, when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0032] As used in this application, the term “circuitry” may refer to one or more or all of the following:(a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and(b) combinations of hardware circuits and software, such as (as applicable):(i) a combination of analog and / or digital hardware circuit(s) with software / firmware and(ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and© hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0033] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0034] As used herein, the term “communication network” refers to a network following any suitable communication standards, such as New Radio (NR), Long Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), Narrow Band Internet of Things (NB-IoT) and so on. Furthermore, the communications between a terminal device and a network device in the communication network may be performed according to any suitable generation communication protocols, including, but not limited to, the first generation (1G), the second generation (2G), 2.5G, 2.75G, the third generation (3G), the fourth generation (4G), 4.5G, the fifth generation (5G), the sixth generation (6G) communication protocols, and / or any other protocols either currently known or to be developed in the future. Embodiments of the present disclosure may be applied in various communication systems. Given the rapid development in communications, there will of course also be future type communication technologies and systems with which the present disclosure may beembodied. It should not be seen as limiting the scope of the present disclosure to only the aforementioned system.
[0035] As used herein, the term “network device” refers to a node in a communication network via which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP), for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio header (RH), a remote radio head (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low power node such as a femto, a pico, a non-terrestrial network (NTN) or non-ground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, an aircraft network device, and so forth, depending on the applied terminology and technology. In some example embodiments, radio access network (RAN) split architecture comprises a Centralized Unit (CU) and a Distributed Unit (DU) at an IAB donor node. An IAB node comprises a Mobile Terminal (IAB-MT) part that behaves like a UE toward the parent node, and a DU part of an IAB node behaves like a base station toward the next-hop IAB node.
[0036] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), a Portable Subscriber Station, a Mobile Station (MS), or an Access Terminal (AT). The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, wireless customer-premises equipment (CPE), an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) partof an IAB node (e.g., a relay node). In the following description, the terms “terminal device”, “communication device”, “terminal”, “user equipment” and “UE” may be used interchangeably.
[0037] As used herein, the term “resource,” “transmission resource,” “resource block,” “physical resource block” (PRB), “uplink resource,” or “downlink resource” may refer to any resource for performing a communication, for example, a communication between a terminal device and a network device, such as a resource in time domain, a resource in frequency domain, a resource in space domain, a resource in code domain, or any other combination of the time, frequency, space and / or code domain resource enabling a communication, and the like. In the following, unless explicitly stated, a resource in both frequency domain and time domain will be used as an example of a transmission resource for describing some example embodiments of the present disclosure. It is noted that example embodiments of the present disclosure are equally applicable to other resources in other domains.
[0038] As used herein, the term “medium access control (MAC) layer” may refer to a sublayer of data link layer of open system interconnections (OSI) reference model for data transmission. The MAC layer provides two main services to the upper layers; data transfer and radio resource allocation. The radio link control (RLC) layer may expect the data transfer and notification of transmission opportunities from the lower layer, such as the MAC sublayer. The term “packet data convergence protocol (PDCP) layer” used herein may refer to a protocol layer, typically between the RLC and RRC (Radio Resource Control) layers in 5G networks for control plane and between the RLC and SDAP (Service Data Adaptation Protocol) layers for user plane. The PDCP layer is responsible for providing header compression, a technique used to reduce the size of protocol headers transmitted over the radio interface by removing redundant information, allowing more data to be transmitted within a given bandwidth. The term “physical layer” may refer to a bottom-most layer in the OSI. The term “access stratum (AS)” used herein may refer to a layer of the protocol stack that resides in the UE and is responsible for controlling the radio interface between the UE and the network. The AS provides functions such as radio resource control, radio bearer control, and security.
[0039] The term “transport block (TB)” used herein may refer to a packet of data which is passed between MAC and physical layers. In 5G a transport block comprises a MAC PDU, i.e., a MAC PDU is equivalent to a transport block. Therefore, in this application the terms‘transport block’ and ‘MAC PDU’ basically mean the same thing. The term “MAC control element (MAC CE)” used herein may refer to a MAC structure carrying control information. The term “protocol data unit (PDU)” used herein may refer to a basic unit of exchange between entities that communicate using a specified networking protocol.
[0040] As used herein, the term “ciphering” used herein may refer to a process that is used to protect the confidentiality of user data that is transmitted. It involves the encryption of data. The term “integrity protection (IP)” used herein may refer to a feature that ensures the authenticity and integrity of user data by preventing various attacks such as message replay, data tampering, etc.
[0041] As mentioned above, several cryptographic protection techniques are proposed. For example, in 2G circuit switched, all traffic is encrypted on the physical layer. No IP is done, which is no longer proper. This approach encrypts also the lower layers, but is not applicable to modern networks, considering the channel structure and the data rates. In 2G packet switched, encryption was done on the LLC layer between UE and SGSN, focusing on protecting UP data. This is not applicable in today’s network architecture and protocol stacks.
[0042] Further, 3G provides integrity protection for RRC messages, done on the RRC layer. Encryption for RRC and user plane traffic is done on the RLC layer for RLC AM and UM and on the MAC layer for RLC TM. IP for lower layers is not provided. The 3G RAN architecture includes a Radio Network Control that terminates security on the network side. This component has been removed from the architecture since 4G.
[0043] 4G and 5G have put encryption and integrity protection on the PDCP layer, leaving all lower layers vulnerable to attacks. In particular, it proposes “Rationale and track of security decisions in LTE / SAE”. It considers the threat of attacks against the lower layers. For example, the threat to falsify or forge a MAC layer Buffer Status Report (BSR) is recognized. It is suggested that this attack is difficult to mount, and only denial of service (DoS) can be achieved. In general, providing encryption for the MAC layer is considered, but it is concluded that this is not required. This decision may have been reasonable at the time the 4G security architecture was designed. Having sticked to this decision and design in 5G is however questionable, as in the meantime, more and more security research work has been published disclosing meaningful attacks against the lower layer control communication.
[0044] Moreover, none of solutions changing the protocol layer on which protection is done, and consequently, it stayed in the PDCP layer as in 4G. Further, according to an example solution, it applies a secret key in the physical layer, to transform the cyclic redundancy check (CRC) of the transport block (TB). The intention is to detect the presence of a relay fake base station. This is no strong integrity protection, because it allows modifications of a TB in a way that the CRC before transformation is not changed. The function to compute the CRC is not a cryptographic hash function, so it allows such modifications. In particular, the attacker has a lot of freedom to put content into the TB, including additional MAC CEs and padding. So it may not be difficult to change the message in the desired way but maintain the original CRC. To summarize, this solution does not provide cryptographic protection for lower layers.
[0045] According to an example solution, it proposes that the MAC cryptographically protects such “data plane signaling messages”. The algorithms specified in LTE for usage in PDCP can be used by the MAC. Keys to be used in the MAC can be derived from eNB. This solution uses frame numbers that are known to the MAC at both the sender and receiver sides as unique input for the crypto algorithms. This provides non-repeating input for 2.91 hours. The eNB refreshes the keys before this time elapses. However, crypto can only be applied when the exact (sub)frame is known where a message is sent. When a MAC CE or RLC PDU is a sub-PDU of a larger MAC PDU, the frame must be calculated accordingly. Real time requirements may not be met in this approach. A 4byte MAC-I (message authentication code for integrity) per message is needed - this is a big overhead for short MAC CEs. When a message is repeated, encryption and integrity protection must be computed again, for the new frame, and the real time requirements must be met again.
[0046] According to another example solution, it proposes to observe the MAC CE containing the activation bitmap indicating the cells to be used in a carrier aggregation configuration. Although the configuration itself is transmitted encrypted only and not known to the attackers, it is possible to identify walking paths taken by victim subscribers on a campus with a certain accuracy solely based on monitoring the cell activation MAC CEs.
[0047] A lot of the research on radio interface vulnerabilities makes use of readily available open source software tools and affordable radio frequency (RF) hardware. These tools have been advanced significantly and / or dropped in price considerably since the time the LTE security decisions were made. This trend makes it more and more easy for attackersto mount radio interface attacks. It is expected that this trend continues and even accelerates.
[0048] Towards 6G, it is envisioned to handle more control procedures solely on the MAC layer. At the same time, superior security and trustworthiness is among the key value indicators for future 6G networks. This makes it imperative that protection is available for MAC CEs. Note that it may not be required to protect each and every MAC CE. There may be types of MAC CEs that cannot significantly be abused by attackers, so they can be transmitted without protection. “Significant abuse” refers to attacks that achieve more than temporary local DoS (which is inherently possible for a local attacker, e.g. simply by generating noise to prevent successful radio transmission).
[0049] Further, it is not clear how to provide suitable cryptographic protection for all the information that requires it in an efficient way, keeping the impact on overall throughput and latency low enough to meet the respective requirements of a 6G radio interface when using adequate hardware resources for executing the protocol software. A further problem is created by the 3GPP 5G radio access network (RAN) architecture shown in FIG. 1. In particular, in the 5G RAN architecture, PDCP and RRC are gNB -CP-centralized unit (CU) tasks and RLC, MAC and physical (PHY) are distributed unit (DU) tasks. In many RRC content modifications the change is needed only for DU owned protocol data. In this case applying protection by the PDCP layer in the gNB-CU-CP adds extra latency to the procedure, because data has to be passed back from the DU to the CU, where protection is applied, before it can be sent to the UE. The problem to be solved in this setup is how to get rid of this extra latency and enable faster UE configuration changes directly from the gNB-DU without need to contact gNB-CU-CP.
[0050] According to example embodiments of the present disclosure, it proposes a solution on MAC layer security. In particular, two types of TBs are introduced, where a first type of TB includes information that requires protection on the lower layer and a second type of TB only includes information that does not require protection on the lower layer. For the first type of TB, cryptographic protection is applied on the lower layer where the TBs are composed (for example, the MAC layer). The first type of TB is used for certain higher and certain lower layer control messages that require protection. No protection is applied on the lower layer to the second type of TB. The second type of TB is used for traffic that does not require protection, such as certain lower layer control messages or user plane traffic, which may be protected on some higher protocol layer. In this way, it can preventattacks exploiting the lack of protection of MAC CEs. As discussed earlier, a TB can be understood as a MAC PDU, i.e., alternatively, two types of MAC PDUs are introduced above.
[0051] FIG. 2 illustrates an example communication environment 100 in which example embodiments of the present disclosure can be implemented. In the communication environment 100, a first apparatus 110 and a second apparatus 120 may communicate with each other.
[0052] The first apparatus 110 may be a terminal device, such as a UE. The second apparatus 120 may be a network device, such as gNB. The first apparatus 110 may be in a cell 102 which is one of the serving cells. Alternatively, the first apparatus 110 may be a network device, such as a gNB, and the second apparatus 120 may be a terminal device, such as a UE.
[0053] In the following, for the purpose of illustration, some example embodiments are described with the first apparatus 110 operating as a terminal device and the second apparatus 120 operating as a network device. However, in some example embodiments, operations described in connection with a terminal device may be implemented at a network device or other device, and operations described in connection with a network device may be implemented at a terminal device or other device.
[0054] In some example embodiments, if the first apparatus 110 is a terminal device and the second apparatus 120 is a network device, a link from the second apparatus 120 to the first apparatus 110 is referred to as a downlink (DL), and a link from the first apparatus 110 to the second apparatus 120 is referred to as an uplink (UL). In DL, the second apparatus 120 is a transmitting (TX) device (or a transmitter) and the first apparatus 110 is a receiving (RX) device (or a receiver). In UL, the first apparatus 110 is a TX device (or a transmitter) and the second apparatus 120 is a RX device (or a receiver).
[0055] Communications in the communication environment 100 may be implemented according to any proper communication protocol(s), comprising, but not limited to, cellular communication protocols of the first generation (1G), the second generation (2G), the third generation (3G), the fourth generation (4G), the fifth generation (5G), the sixth generation (6G), and the like, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, thecommunication may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.
[0056] FIG. 3 illustrates a radio interface control plane protocol stack which can be implemented in the communication environment 100 shown in FIG. 2. As shown in FIG. 3, the radio interface protocol stack in the first apparatus 110 may include: a non-access stratum (NAS) layer, an RRC layer, a PDCP layer, an RLC layer, a MAC layer, and a PHY layer. The radio interface control plane protocol stack in the second apparatus 120 may include: an RRC layer, a PDCP layer, an RLC layer, a MAC layer, and a PHY layer.
[0057] In some solutions, because of the decision to perform ciphering and IP on the PDCP layer, lower layer information may not be protected. This may include PHY layer information such as downlink control information (DCI) on physical downlink control channel (PDCCH), uplink control information (UCI) on physical uplink control channel (PUCCH), MAC CEs, RLC control PDUs and MAC and RLC protocol headers. Also PDCP control PDUs may not be protected. The headers of PDCP data PDUs may be integrity protected.
[0058] PDCP data PDUs may not contain a header field indicating the protection status, i.e. whether the message is encrypted and / or integrity protected. The receiving PDCP may always be configured correctly to handle received messages correctly. For example, if the PDCP is configured to decipher received messages, it may apply deciphering to all received messages, without any check whether a message is indeed ciphered.
[0059] In some solutions, protection may be applied in the granularity of bearers (for example, signaling radio bearers (SRBs) and data radio bearers (DRBs)). Most of these bearers may have a fixed protection policy, i.e. if encryption and / or IP applies, it is done starting with the first PDU transmitted in the bearer. The notable exception is the SRB1, used to transport RRC messages between UE and eNB / gNB. The SRB1 may start without protection, and later, security is activated via the RRC Security Mode Command (SMC) procedure.
[0060] FIG. 4 illustrates a schematic diagram of MAC PDU 400 in 5G standard. As shown in FIG. 4, the MAC PDU 400 may include several MAC subPDUs. A MAC subPDU may include a MAC CE or a MAC service data unit (SDU). A MAC SDU is an RLC PDU, which could be an RLC control PDU or an RLC data PDU. An RLC data PDU encapsulates a PDCP PDU which could be PDCP control PDU or a PDCP data PDU. A PDCP data PDU encapsulates either an RRC PDU containing an RRC message, or an SDAP PDU containing UP data. A single MAC PDU can include MAC CEs as well as RRC messages or UP data. MAC subPDUs include header fields, but otherwise there are no MAC PDU header fields. The MAC PDU 400 may be passed as a Transport Block (TB) between MAC layer and physical layer and over the air.
[0061] Example embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. Reference is made to FIG. 5A, which illustrates a signaling flow 500 in accordance with some embodiments of the present disclosure. The signaling flow 500 involves a first device 510 which acts as a sender / transmitter and a second device 520 which acts as a receiver. In an example embodiment, the first device 510 may be implemented at the first apparatus 110 or included in the first apparatus 110 (for example, a MAC layer of the first apparatus 110) in FIG. 2 and the second device 520 may be implemented at the second apparatus 120 in FIG. 2. Alternatively, the first device 510 may be implemented at the second apparatus 120 in FIG. 2 and the second device 520 may be implemented at the first apparatus 110 or included in the first apparatus 110 (for example, a MAC layer of the first apparatus 110).
[0062] The first device 510 obtains (5010) protection information that indicates which control information and data require a security protection on a first protocol layer. The second device 520 also obtains (5010’) the protection information. In an example embodiment, if the first device 510 is UE and the second device 520 is a gNB, the second device 520 may transmit the protection information to the first device 510. That is, the first device 510 may receive the protection information from the second device 520. Alternatively, if the first device 510 is gNB and the second device 520 is UE, the first device 510 may transmit the protection information to the second device 520. That is, the second device 520 may receive the protection information from the first device 510. In some other example embodiments, the protection information may be predefined.
[0063] The first device 510 determine (5012) whether to apply the security protection atthe first protocol layer to at least one first PDU at the first protocol layer or at least one second PDU at a second protocol layer based on the obtained protection information. The first protocol layer is lower than the second protocol layer, which means that the first protocol layer is below the second protocol layer in the radio interface protocol stack. For example, as shown in FIG. 3, the MAC layer is lower than the RCL layer.
[0064] The first device 510 applies (5014) the security protection based on the determining. For example, if the first device 510 determines that a PDU (such as, a first PDU or a second PDU) requires the security protection based on the protection information, the first device 510 may apply the security protection to the PDU. Alternatively, if the first device 510 determines that a PDU (such as, a first PDU or a second PDU) does not require the security protection based on the protection information, the first device 510 may not apply the security protection to the PDU.
[0065] The first device 510 generates (5015) a transport block (TB) based on the protection information. The TB includes at least one of the at least one first PDU at the first protocol layer that requires protection and at least one second PDU at the second protocol layer that require protection. For example, the first PDU may refer to a MAC CE. The second PDU may refer to a MAC SDU, i.e., an RLC PDU. Thus for example, a PDU may be a MAC subPDU which may contain a MAC CE, a MAC SDU (=RLC PDU) or padding. The TB also includes information that indicates to which one or more PDUs the security protection is applied. In this way, it can pave the way for implementing more sensitive procedures on the MAC layer, as envisioned for 6G. Further, it can also provide security for RLC and PDCP control messages and headers and for RRC messages, securing the complete CP protocol stack.
[0066] In some example embodiments, the first protocol layer may refer to a lower layer. For example, the first protocol layer may be a MAC layer. It is noted that the first protocol layer may refer to other lower layers. Alternatively, the second protocol layer may refer to a higher layer. For example, the second protocol layer may be a RRC layer or a RLC layer. It is noted that the second protocol layer may refer to other higher layers.
[0067] The generated (5015) TB includes information indicating whether the security protection is applied to one or more protocol data units at the first protocol layer. In an example embodiment, the generated (5015) TB may include a header that contains an indication whether this TB is the first type of TB or the second type of TB. By way ofexample, headers of the first type of TB may include a field containing the count value assigned to this TB and a field that holds a cryptographically computed message authentication code for integrity (MAC-I). In an example embodiment, the first device 510 may compute the MAC-I over the complete TB (excluding the MAC-I field). In another example embodiment, the first device 510 may subsequently encrypt the complete TB excluding the indication field and the count or sequence number field. In some example embodiments, crypto algorithms as specified for 5G may be used, for example, advanced encryption standard (AES) in counter mode for encryption (called NR encryption algorithm 2 (NEA2) in 3GPP 5G specifications) and AES cipher based message authentication code (CMAC) for integrity (called NR integrity algorithm 2 (NIA2) in 3GPP 5G specifications).
[0068] In some example embodiments, if the protection information indicates that the security protection is required on the first protocol layer, the first device 510 may generate the first type of TB. In an example embodiment, the information indicating whether the security protection is applied to one or more protocol data units is included in the TB and not within the one or more protocol data units. For example, if the information indicates that the security protection is applied to the one or more protocol data units, at least one of a count value or a sequence number for the transport block may be included in the transport block and outside the one or more protocol data units.
[0069] FIG. 6A illustrates a schematic diagram of the first type of TB 600. As shown in FIG. 6 A, the TB 600 may include an indication 611 that indicates the security protection is applied to the protocol data unit 612. The TB 600 may also include a field 613 for a count value or a sequence number for the TB 600. The sequence number may be a part of the count value. For example, the full count may be included in the first type of TB, but only a sequence number (SN) including some of least significant bits of the count value. By way of example, the count value may include a 32bit integer, but only its 10 least significant bits may be included as a sequence number in the TB 600. In this way, it can save some space in the TB, but still allows the receiver to reconstruct the count and use it as input to decipher and integrity verification. In some other example embodiments, the TB 600 may include a message authentication code for integrity (MAC-I) field 614. The TB 600 may include the protocol data unit 612. The protocol data unit 612 may carry MAC CEs as well as higher layer PDUs, which may be structured as shown in FIG. 4.
[0070] Alternatively, the information indicating whether the security protection is appliedto the one or more protocol data units may be included in each of the one or more protocol data. In an example embodiment, at least one of a count value or a sequence number for the protocol data unit may be included in each of the one or more protocol data units. For example, the indication, the field for count value or sequence number for the protocol data unit and the MAC-I field may be a part of the protocol data unit. For example, as shown in FIG. 6B, the TB 600’ may include the protocol data unit 612’ that contains the indication 611 that indicates the security protection is applied to the protocol data unit 612, the field 613 for count value or sequence number for the protocol data unit 612, and the MAC -I field 614.
[0071] In some example embodiments, if the protection information indicates that the security protection is not required on the first protocol layer, the first device 510 may generate the second type of TB. FIG. 6C illustrates a schematic diagram of the second type of TB 610. As shown in FIG. 6C, the TB 610 may include an indication 621 that indicates the security protection is not applied to the protocol data unit 622. The TB 610 may also include the protocol data unit 622 which may be structured as shown in FIG. 4. Alternatively, the indication may be outside the protocol data unit. For example, as shown in FIG. 6D, the TB 610’ may include the protocol data unit 622’ which contains the indication 621 that indicates the security protection is not applied to the protocol data unit 622.
[0072] In some example embodiments, all protected PDUs may be placed together, so they form a “protected zone” inside the TB. In this case, the indication may include only, for example, the offset in the TB where this protected zone begins and how long it is. FIG. 6E shows a schematic diagram of an example of TB. For example, as shown in FIG. 6E, the TB 630 may include the indication 631 that indicates whether security is applied to some MAC subPDUs or not, a counter field 633, a protected zone start 635 and a protected zone length 636, i.e., the offset in the TB where this protected zone begins and how long it is, unprotected MAC subPDU(s) 637, protected MAC subPDU(s) 638 and a MAC-I 634.
[0073] In some example embodiments, user plane (UP) traffic may be protected on a higher layer. For example, the UP may be protected on the PDCP layer. It is noted if a new network architecture is adopted where the UP security may no longer be terminated in the same entity as the AS CP security, a new protocol between the UE and some entity in the RAN or core network may provide the protection. The UP traffic may be transported in the second type of TB.
[0074] In an example embodiment, the first device 510 may set the information indicating whether the security protection is applied to the protocol data unit as the count value for the TB. Alternatively, the first device 510 may set this information as the sequence number of the TB. In other words, there may not be explicit field for the indication. For example, there may be no field 611 in TB 600 / 600’ and no field 621 in TB 610 / 610’ and no field 631 in TB 630. In this case, in some example embodiments, if the first device 510 determines not to apply the security protection to each protocol data unit in the one or more protocol data units based on the protection information, the first device 510 may set the count value or the sequence number (i.e., the count value is regarded as the information) included in the TB and not within in the one or more protocol data units to be equal to a first predefined value which indicates the security protection is not applied to each protocol data unit in the one or more protocol data units. Alternatively, if the first device 510 determines not to apply the security protection to a protocol data unit in the one or more protocol data units, the first device 510 may set the information that is included in the protocol data unit at the count value for the protocol data unit or the sequence number of the protocol data unit. In this case, the count value for the protocol data unit or the sequence number of the protocol data unit may be set to the first predefined value. For example, if the count value or the sequence number is set to “0”, it may explicitly indicate that the security protection is not applied to the protocol data unit. Further, if not the count value but only a sequence number is transmitted in the TB, the count values > 0 with sequence number = 0 needs to be skipped, to ensure that sequence number = 0 always means count=0, so the first device 510 knows that no security protection is applied. Alternatively, if the count value or the sequence number is set to a value larger than 0, it may explicitly indicate that some form of security protection is applied to the protocol data unit.
[0075] The first device 510 and the second device 520 may perform an AS security activation by exchanging (5020) signaling. In an example embodiment, if the first device 510 is UE and the second device 520 is gNB, the second device 520 may generate a first MAC CE including a security mode command and transmit a first MAC CE including the security mode command to the first device 510. The first device 510 may then generate a second MAC CE including an acknowledgement to the security mode command to the second device 520, after receiving the first MAC CE including the security mode command. The first device 510 may apply an integrity protection to the second MAC CEand set the count value to be a second predefined value. The first device 510 may transmit the second MAC CE to the second device 520. In this case, the second device 520 may determine whether an integrity protection is applied to the second MAC CE. If the integration protection is applied, the second device 520 may perform the AS security activation after the reception of the second MAC CE including the acknowledgement to the security mode command. The second device 520 may determine that an integrity protection is applied to the transport block and the count value is set to be a second predefined value.
[0076] Alternatively, if the first device 510 is gNB and the second device 520 is UE, the first device 510 may generate the first MAC CE including the security mode command. The first device 510 may apply the integrity protection to the first MAC CE and set the count value to be the second predefined value. The first device 510 may transmit the first MAC CE to the second device 520. After the reception of the first MAC CE, the second device 520 may determine whether the integrity protection is applied to the first MAC CE. In this case, if the integrity protection is applied to the first MAC CE, the second device 520 may generate and transmit the second MAC CE including the acknowledgement to the security mode command to the first device 510. The first device 510 may perform the AS security activation after the reception of the second MAC CE. Alternatively, the security mode command and the corresponding acknowledgement may be exchanged via RRC signaling.
[0077] The first device 510 may apply the integrity protection to the TB, after receiving or transmitting the security mode command. In this case, the first device 510 may set the count value to be a second predefined value, for example, “1”. In other words, the TB with count =1 may be integrity protected but not encrypted.
[0078] Alternatively, the first device 510 may apply the integrity protection and the ciphering to one of the TB, the at least one first protocol data unit at the first protocol layer that requires protection, or the at least one second protocol data unit at the second protocol layer, after the transmission of the first MAC CE or the transmission of second MAC CE. In this case, the first device 510 may set the count value to be larger than the second predefined value.
[0079] In some example embodiments, only the ciphering and deciphering may be done by the MAC, but not the integrity protection. In other words, the first device 510 may onlyapply the ciphering not the integrity protection to the TB. It may be favorable if it turns out that suitable hardware on which the MAC can be deployed would not be capable of performing both ciphering and IP under the real time processing requirements of the MAC.
[0080] In both directions (uplink and downlink) an own count may be used, maintained by the first device 510, which requires that in addition to the count, also a direction bit different for the two directions must be included in the initialization vector of the crypto algorithms. In some example embodiment, count values >0 may be used in an increasing way by the first device 510. TBs may not necessarily be reordered in the receiving MAC. The count value may be used as initialization vector for the crypto algorithm when protecting a TB. This way, stream ciphers allowing efficient encryption (such as AES in counter mode) can be applied, and it is ensured that each cipher stream is unique (which is an important cryptographic requirement). The count values can also be used to detect replay of a packet. In some example embodiments, due to potential disordering, the second device 520 may maintain a certain window of acceptable count values.
[0081] The first device 510 transmits (5025) the TB to the second device 520. In other words, the second device 520 receives (5025) the TB from the first device 510. In some example embodiments, the physical layer of the first device 510 may add other information when transmitting (5025) the TB to the second device 520. For example, CRC may be added. In an example embodiment, if the indication indicates that the security protection is not applied to the protocol data unit, the first device 510 may transmit the TB without the security protection regardless of an access stratum security activation.
[0082] In an example embodiment, traffic that does not require the security protection may be sent in the second type of TB. For example, the first device 510 may transmit another TB without the security protection before or after the AS security activation. As another example, the traffic that does not require the security protection may be sent in the first type of TB. For example, the first type of TB that needs to be transmitted may also accommodate for e.g. a MAC CE that does not require protection, so this MAC CE is included into it. Even user plane traffic, e.g. an IP packet containing only a TCP acknowledge message, may be included into the first type of TB.
[0083] The second device 520 determines (5026) whether a protocol data unit included in the TB requires the security protection based on the protection information. The second device 520 also determines (5028) whether the security protection is applied to theprotocol data unit included in the TB.
[0084] The second device 520 processes (5030) the TB based on the determinations. For example, if the protocol data unit that requires the security protection according to the protection information is received without the security protection, the second device 520 may discard the protocol data unit. Alternatively, if the protocol data unit that requires the security protection according to the protection information is received with the security protection, the second device 520 may further process (for example, decode or decipher) the protocol data unit.
[0085] For example, if the AS security is not activated and the indication indicates the security protection is applied on the protocol data unit, the second device 520 may discard the TB. Alternatively, the second device 520 may store the TB and process it after the security activation.
[0086] According to example embodiments described with reference to FIG. 5A, there may be two types of TBs: Msec-TBs (i.e., the first type of TB) containing information that requires protection on the lower layer and plain-TBs (i.e., the second type of TB) containing information that does not require protection on the lower layer. In particular, to the Msec-TBs, cryptographic protection is applied on the lower layer where the TBs are composed (the MAC layer in today’s networks). Msecs-TBs may be used for certain higher and certain lower layer control messages that require protection. A unique integer value “count” may be assigned to each TB by the sender that can be used as unique input to crypto algorithms as well as for replay protection. Further, no protection is applied on the lower layer to plain-TBs. They are used for traffic that does not require protection, such as certain lower layer control messages or user plane traffic, which may be protected on some higher protocol layer. Moreover, each TB has a header that contains an indication whether this is an Msec-TB or plain-TB. Headers of Msec-TBs may further include a field containing the count value assigned to this TB and a field that holds a cryptographically computed MAC-I. When the connection between the UE and the network is in the process of being established, security is not yet activated, so only plain-TBs are exchanged. Security is activated subsequently by a procedure involving a first downlink Msec-TB with count=l (and specific content) being sent by the network and subsequently the first uplink Msec-TB with count=l (and specific content) being sent by the UE as acknowledgment. Among the lower layer control messages, a policy is specified which message types can be used always without protection. Such messages may be transmittedin a plain-TBs at any time, before, during and after security activation. Control messages and data that require protection according to the specified policy, but are received without protection in plain-TBs, are discarded. The present disclosure allows UE configuration modifications with security via MAC. This enables fast configuration management and changes in the gNB-DU.
[0087] According to the example embodiments of the present disclosure, it can prevent attacks exploiting the lack of protection of MAC CEs. Further, it can pave the way for implementing more, and more sensitive, procedures on the MAC layer, as envisioned for 6G. Moreover, it may provide security also for RLC and PDCP control messages and headers and for RRC messages, securing the complete CP protocol stack. In addition, in a CU-DU split of the base station, CP security can be terminated by the MAC layer in the DU, so the DU can decipher and understand received RRC information without involvement of the CU, and can cipher and send RRC information without the involvement of the CU. At the same time, this does not expose the UP to attacks against the DU (which may be endangered by lack of physical protection), as it allows UP security to be terminated in the CU, or in another entity in the future 6G RAN or core network. MAC CEs that, according to a specified protection policy, do not need protection, can be transmitted without protection at any time, even during and after security activation.
[0088] Reference is made to FIG. 5B, which illustrates a signaling flow 501 in accordance with some embodiments of the present disclosure. For the purposes of discussion, the signaling flow 501 may be discussed with reference to FIG. 2, for example, by using the first apparatus 110 and the second apparatus 120.
[0089] The first apparatus 110 and the second apparatus may transmit (5105) the second type of TBs to each other.
[0090] In some example embodiments, AS security may build on the previous establishment of NAS security. For example, when no AS security contexts exists and the first apparatus 110 connects to the cell 102, unprotected MAC and RRC messages may be exchanged, until the second apparatus 120 has obtained (5110’) the key K§NB from the core network as the root key for AS security. Then, AS security may be activated by the RRC SMC procedure today. In this procedure both in the first apparatus 110 and the second apparatus 120, the RRC may configure the PDCP to apply security. This approach is applicable to embodiments described in FIG. 5B, with the RRC configuring the MACinstead of the PDCP to apply security. The two RRC commands of the procedure (security mode command (SMCommand) sent by the second apparatus 120 and security mode complete (SMComplete) sent by the first apparatus 110 as an acknowledgement) may be transmitted in the TBs with count=l in both directions and may be integrity protected but not ciphered.
[0091] Alternatively, if the SMC procedure is performed by the exchange of MAC CEs, i.e. a new MAC CE comprising the same or similar information as RRC SMCommand, and a MAC CE acting as an acknowledgment. In this case the first type of TBs with count=l may be used to transmit these new MAC CEs.
[0092] For example, the second apparatus 120 may transmit (5115) a TB with count=l which include SMCommand MAC CE to the first apparatus 110. This TB may be integrity protected but not ciphered. The first apparatus may transmit (5120) another TB with count=l which include SMComplete MAC CE to the second apparatus 120. The other TB may be integrity protected but not ciphered. The second type of TB may also be transmitted during the activation of the AS security.
[0093] After the AS security activated, the second apparatus 120 may transmit (5125) a TB with count>l to the first apparatus 110. This TB may be integrity protected and ciphered. The first apparatus 110 may transmit (5130) another TB with count >1 to the second apparatus 120. The other TB may be integrity protected and ciphered. The second type of TB may also be transmitted after the activation of the AS security.
[0094] FIG. 7 shows a flowchart of an example method 700 implemented at a first apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the first apparatus may be the first apparatus 110 in FIG. 2 or the second apparatus 120 in FIG. 2.
[0095] At block 710, the first apparatus obtains protection information indicating which control information and data require a security protection on a first protocol layer.
[0096] At block 720, the first apparatus determines whether to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer based on the obtained protection information.
[0097] At block 730, the first apparatus applies the security protection if it is determinedto apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer.
[0098] At block 740, the first apparatus generates, based on the protection information, a transport block that includes at least one of the at least one first protocol data unit at the first protocol layer that requires protection, and at least one second protocol data unit at the second protocol layer that requires protection. The first protocol layer is lower than the second protocol layer. The transport block further comprises information indicating whether the security protection is applied to one or more protocol data units at the first protocol layer.
[0099] At block 750, the first apparatus transmits the transport block to a second apparatus.
[0100] In some example embodiments, the information indicating whether the security protection is applied to the one or more protocol data units is comprised in each of the one or more protocol data units, or wherein the information indicating whether the security protection is applied to the one or more protocol data units is comprised in the transport block and not within the one or more protocol data units.
[0101] In some example embodiments, if the information indicates that the security protection is applied to the one or more protocol data units, at least one of a count value or a sequence number for the transport block is included in the transport block and outside the one or more protocol data units, or wherein if the information indicates that the security protection is applied to the one or more protocol data units, at least one of a count value or a sequence number for the protocol data unit is included in each of the one or more protocol data units, and wherein the sequence number is a part of the count value.
[0102] In some example embodiments, the method 700 further comprises: based on a determination of not to apply the security protection to each protocol data unit in the one or more protocol data units, set the information that is comprised in the transport block and outside the one or more protocol data unit as at least one of a count value for the transport block, or a sequence number of the transport block, and wherein the count value or the sequence number equal to a first predefined value indicates that the security protection is not applied to each protocol data unit in the one or more protocol data units.
[0103] In some example embodiments, the method 700 further comprises: based on adetermination of not to apply the security protection to a protocol data unit in the one or more protocol data units based on the protection information, set the information that is comprised in the protocol data unit as at least one of: a count value for the protocol data unit, or a sequence number of the protocol data unit, and wherein the count value or the sequence number equal to a first predefined value indicates that the security protection is not applied to the protocol data unit in the one or more protocol data units.
[0104] In some example embodiments, the method 700 further comprises: generating a first medium access control control element including a security mode command; applying an integrity protection to the first medium access control control element; set the count value to be a second predefined value; transmitting, to the second apparatus, the first medium access control control element; and performing an access stratum security activation, after a reception of a second medium access control control element including an acknowledgment to the security mode command from the second apparatus.
[0105] In some example embodiments, the method 700 further comprises: generating a second medium access control control element including an acknowledgment to a security mode command, after a reception of a first medium access control control element including the security mode command from the second apparatus; applying an integrity protection to the second medium access control control element; set the count value to be a second predefined value; and transmitting the second medium access control control element to the second apparatus.
[0106] In some example embodiments, the method 700 further comprises: applying an integrity protection and a ciphering to one of: the transport block or to the at least one first protocol data unit at the first protocol layer that requires protection, or to the at least one second protocol data unit at a second protocol layer that requires protection, after the transmission of the first medium access control control element including the security mode command or after the transmission of the second medium access control control element including the acknowledgment to the security mode command; and set the count value larger than a second predefined value.
[0107] In some example embodiments, the method 700 further comprises: transmitting, to the second apparatus, another transport block without security protection after the access stratum security activation.
[0108] In some example embodiments, the first apparatus is a terminal device, and thesecond apparatus is a network device, or wherein the first apparatus is a network device, and the second apparatus is a terminal device, and wherein the first protocol layer is a medium access control layer, the second protocol layer is a radio resource control layer or a radio link control layer.
[0109] FIG. 8 shows a flowchart of an example method 800 implemented at a second apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the second apparatus may be the first apparatus 110 in FIG. 2 or the second apparatus 120 in FIG. 2.
[0110] At block 810, the second apparatus obtains protection information indicating which control information and data require a security protection on a first protocol layer.
[0111] At block 820, the second apparatus receives, from a first apparatus a transport block that comprises one or more protocol data units. The transport block comprises information indicating whether the security protection is applied to one or more protocol data units at the first protocol layer.
[0112] At block 830, the second apparatus determines whether a protocol data unit in the one or more protocol data units requires the security protection based on the protection information.
[0113] At block 840, the second apparatus determines whether the security protection is applied to the protocol data unit in the one or more protocol data units based on the information indicating to which one or more protocol data units the security protection is applied.
[0114] At block 850, the second apparatus processes the protocol data unit based on the determinations.
[0115] In some example embodiments, the method 800 further comprises: based on a determination that the protocol data unit that require the security protection according to the protection information is received without the security protection, discarding the protocol data unit.
[0116] In some example embodiments, the method 800 further comprises: based on a determination that the protocol data unit that require the security protection according to the protection information is received with the security protection, decoding or deciphering the protocol data unit.
[0117] In some example embodiments, the method 800 further comprises: after a reception of a first medium access control control element including the security mode command from the first apparatus, determining whether integrity protection is applied to the first medium access control control element; and if the integrity protection is applied to the first medium access control control element, transmitting, to the first apparatus, a second medium access control control element including the acknowledgment to the security mode command.
[0118] In some example embodiments, the method 800 further comprises: generating a first medium access control control element including a security mode command; transmitting, to the first apparatus, the first medium access control control element; receiving, from the first apparatus, a second medium access control control element including an acknowledgement to the security mode command; determining whether an integrity protection is applied to the second medium access control control element; and if the integrity protection is applied to the second medium access control control element, performing an access stratum security activation..
[0119] In some example embodiments, a first apparatus capable of performing any of the method 700 (for example, the first apparatus 110 or the second apparatus 120 in FIG. 2) may comprise means for performing the respective operations of the method 700. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The first apparatus may be implemented as or included in the first apparatus 110 or the second apparatus 120 in FIG. 2.
[0120] In some example embodiments, the first apparatus comprises means for obtaining protection information indicating which control information and data require a security protection on a first protocol layer; means for determining whether to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer based on the obtained protection information; means for applying the security protection if it is determined to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer; means for generating, based on the protection information, a transport block that comprises at least one of: the at least one first protocol data unit at the first protocol layer that requires protection, and at least one second protocol data unit at the second protocol layer that requires protection, wherein the first protocol layer islower than the second protocol layer, wherein the transport block further comprises information indicating whether the security protection is applied to one or more protocol data units at the first protocol layer; and means for transmitting the transport block to a second apparatus.
[0121] In some example embodiments, the information indicating whether the security protection is applied to the one or more protocol data units is comprised in each of the one or more protocol data units, or wherein the information indicating whether the security protection is applied to the one or more protocol data units is comprised in the transport block and not within the one or more protocol data units.
[0122] In some example embodiments, if the information indicates that the security protection is applied to the one or more protocol data units, at least one of a count value or a sequence number for the transport block is included in the transport block and outside the one or more protocol data units, or wherein if the information indicates that the security protection is applied to the one or more protocol data units, at least one of a count value or a sequence number for the protocol data unit is included in each of the one or more protocol data units, and wherein the sequence number is a part of the count value.
[0123] In some example embodiments, the first apparatus further comprises: based on a determination of not to apply the security protection to each protocol data unit in the one or more protocol data units, set the information that is comprised in the transport block and outside the one or more protocol data unit as at least one of a count value for the transport block, or a sequence number of the transport block, and wherein the count value or the sequence number equal to a first predefined value indicates that the security protection is not applied to each protocol data unit in the one or more protocol data units.
[0124] In some example embodiments, the first apparatus further comprises: based on a determination of not to apply the security protection to a protocol data unit in the one or more protocol data units based on the protection information, set the information that is comprised in the protocol data unit as at least one of: a count value for the protocol data unit, or a sequence number of the protocol data unit, and wherein the count value or the sequence number equal to a first predefined value indicates that the security protection is not applied to the protocol data unit in the one or more protocol data units.
[0125] In some example embodiments, the first apparatus further comprises: means for generating a first medium access control control element including a security modecommand; means for applying an integrity protection to the first medium access control control element; set the count value to be a second predefined value; means for transmitting, to the second apparatus, the first medium access control control element; and means for performing an access stratum security activation, after a reception of a second medium access control control element including an acknowledgment to the security mode command from the second apparatus.
[0126] In some example embodiments, the first apparatus further comprises: means for generating a second medium access control control element including an acknowledgment to a security mode command, after a reception of a first medium access control control element including the security mode command from the second apparatus; means for applying an integrity protection to the second medium access control control element; set the count value to be a second predefined value; and means for transmitting the second medium access control control element to the second apparatus.
[0127] In some example embodiments, the first apparatus further comprises: means for applying an integrity protection and a ciphering to one of: the transport block or to the at least one first protocol data unit at the first protocol layer that requires protection, or to the at least one second protocol data unit at a second protocol layer that requires protection, after the transmission of the first medium access control control element including the security mode command or after the transmission of the second medium access control control element including the acknowledgment to the security mode command; and set the count value larger than a second predefined value.
[0128] In some example embodiments, the first apparatus further comprises: means for transmitting, to the second apparatus, another transport block without security protection after the access stratum security activation.
[0129] In some example embodiments, the first apparatus is a terminal device, and the second apparatus is a network device, or wherein the first apparatus is a network device, and the second apparatus is a terminal device, and wherein the first protocol layer is a medium access control layer, the second protocol layer is a radio resource control layer.
[0130] In some example embodiments, a second apparatus capable of performing any of the method 800 (for example, the first apparatus 110 or the second apparatus 120 in FIG. 2) may comprise means for performing the respective operations of the method 800. The means may be implemented in any suitable form. For example, the means may beimplemented in a circuitry or software module. The second apparatus may be implemented as or included in the first apparatus 110 or the second apparatus 120 in FIG.2.
[0131] In some example embodiments, the second apparatus comprises means for obtaining protection information indicating which control information and data require a security protection on a first protocol layer; means for receiving, from a first apparatus a transport block that comprises one or more protocol data units, wherein the transport block comprises information indicating whether the security protection is applied to one or more protocol data units at the first protocol layer; means for determining whether a protocol data unit in the one or more protocol data units requires the security protection based on the protection information; means for determining whether the security protection is applied to the protocol data unit in the one or more protocol data units based on the information indicating to which one or more protocol data units the security protection is applied; and means for processing the protocol data unit based on the determinations.
[0132] In some example embodiments, the second apparatus further comprises: means for based on a determination that the protocol data unit that require the security protection according to the protection information is received without the security protection, discarding the protocol data unit.
[0133] In some example embodiments, the second apparatus further comprises: means for after a reception of a first medium access control control element including the security mode command from the first apparatus, determining whether integrity protection is applied to the first medium access control control element; and if the integrity protection is applied to the first medium access control control element, means for transmitting, to the first apparatus, a second medium access control control element including the acknowledgment to the security mode command.
[0134] In some example embodiments, the second apparatus further comprises: means for generating a first medium access control control element including a security mode command; means for transmitting, to the first apparatus, the first medium access control control element; means for receiving, from the first apparatus, a second medium access control control element including an acknowledgement to the security mode command; means for determining whether an integrity protection is applied to the second medium access control control elemen; and means for if the integrity protection is applied tosecond medium access control control element, performing an access stratum security activation.
[0135] In some example embodiments, the second apparatus further comprises means for performing other operations in some example embodiments of the method 800 or the first apparatus 110 or the second apparatus 120. In some example embodiments, the means comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the performance of the second apparatus.
[0136] FIG. 9 is a simplified block diagram of a device 900 that is suitable for implementing example embodiments of the present disclosure. The device 900 may be provided to implement a communication device, for example, the first apparatus 110 or the second apparatus 120 as shown in FIG. 2. As shown, the device 900 includes one or more processors 910, one or more memories 920 coupled to the processor 910, and one or more communication modules 940 coupled to the processor 910.
[0137] The communication module 940 is for bidirectional communications. The communication module 940 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interfaces may represent any interface that is necessary for communication with other network elements. In some example embodiments, the communication module 940 may include at least one antenna.
[0138] The processor 910 may be of any type suitable to the local technical network and may include one or more of the following: general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 900 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.
[0139] The memory 920 may include one or more non-volatile memories and one or more volatile memories. Examples of the non-volatile memories include, but are not limited to, a Read Only Memory (ROM) 924, an electrically programmable read only memory (EPROM), a flash memory, a hard disk, a compact disc (CD), a digital video disk (DVD), an optical disk, a laser disk, and other magnetic storage and / or optical storage. Examples of the volatile memories include, but are not limited to, a random access memory (RAM) 922 and other volatile memories that will not last in the power-down duration.
[0140] A computer program 930 includes computer executable instructions that are executed by the associated processor 910. The instructions of the program 930 may include instructions for performing operations / acts of some example embodiments of the present disclosure. The program 930 may be stored in the memory, e.g., the ROM 924. The processor 910 may perform any suitable actions and processing by loading the program 930 into the RAM 922.
[0141] The example embodiments of the present disclosure may be implemented by means of the program 930 so that the device 900 may perform any process of the disclosure as discussed with reference to FIG. 2 to FIG. 8. The example embodiments of the present disclosure may also be implemented by hardware or by a combination of software and hardware.
[0142] In some example embodiments, the program 930 may be tangibly contained in a computer readable medium which may be included in the device 900 (such as in the memory 920) or other storage devices that are accessible by the device 900. The device 900 may load the program 930 from the computer readable medium to the RAM 922 for execution. In some example embodiments, the computer readable medium may include any types of non-transitory storage medium, such as ROM, EPROM, a flash memory, a hard disk, CD, DVD, and the like. The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).
[0143] FIG. 10 shows an example of the computer readable medium 1000 which may be in form of CD, DVD or other optical storage disk. The computer readable medium 1000 has the program 930 stored thereon.
[0144] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, and other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. Although various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representations, it is to be understood that the block, apparatus, system, technique or method described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware orcontroller or other computing devices, or some combination thereof.
[0145] Some example embodiments of the present disclosure also provide at least one computer program product tangibly stored on a computer readable medium, such as a non- transitory computer readable medium. The computer program product includes computerexecutable instructions, such as those included in program modules, being executed in a device on a target physical or virtual processor, to carry out any of the methods as described above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.
[0146] Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program code, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0147] In the context of the present disclosure, the computer program code or related data may be carried by any suitable carrier to enable the device, apparatus or processor to perform various processes and operations as described above. Examples of the carrier include a signal, computer readable medium, and the like.
[0148] The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-onlymemory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0149] Further, although operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, although several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Unless explicitly stated, certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated, various features that are described in the context of a single embodiment may also be implemented in a plurality of embodiments separately or in any suitable sub-combination.
[0150] Although the present disclosure has been described in languages specific to structural features and / or methodological acts, it is to be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.
Claims
I / We Claim:
1. A first apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus to: obtain protection information indicating which control information and data require a security protection on a first protocol layer; determine whether to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer based on the obtained protection information; apply the security protection if it is determined to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer; generate, based on the protection information, a transport block that comprises at least one of: the at least one first protocol data unit at the first protocol layer that requires protection, and at least one second protocol data unit at the second protocol layer that requires protection, wherein the first protocol layer is lower than the second protocol layer, wherein the transport block further comprises information indicating whether the security protection is applied to one or more protocol data units at the first protocol layer; and transmit the transport block to a second apparatus.
2. The first apparatus of claim 1, wherein the information indicating whether the security protection is applied to the one or more protocol data units is comprised in each of the one or more protocol data units, or wherein the information indicating whether the security protection is applied to the one or more protocol data units is comprised in the transport block and not within the one or more protocol data units.
3. The first apparatus of claim 1 or 2, wherein if the information indicates that the security protection is applied to the one or more protocol data units, at least one of a count value or a sequence number for the transport block is included in the transport block and outside the one or more protocol data units, orwherein if the information indicates that the security protection is applied to the one or more protocol data units, at least one of a count value or a sequence number for the protocol data unit is included in each of the one or more protocol data units, and wherein the sequence number is a part of the count value.
4. The first apparatus of any of claims 1-3, wherein the first apparatus is caused to: based on a determination of not to apply the security protection to each protocol data unit in the one or more protocol data units, set the information that is comprised in the transport block and not within the one or more protocol data unit as at least one of: a count value for the transport block, or a sequence number of the transport block, and wherein the count value or the sequence number equal to a first predefined value indicates that the security protection is not applied to each protocol data unit in the one or more protocol data units.
5. The first apparatus of any of claim 1-3, wherein the first apparatus is caused to: based on a determination of not to apply the security protection to a protocol data unit in the one or more protocol data units based on the protection information, set the information that is comprised in the protocol data unit as at least one of: a count value for the protocol data unit, or a sequence number of the protocol data unit, and wherein the count value or the sequence number equal to a first predefined value indicates that the security protection is not applied to the protocol data unit in the one or more protocol data units.
6. The first apparatus of any of claims 1-5, wherein the first apparatus is a network device and the second apparatus is a terminal device, the first apparatus is caused to: generate a first medium access control control element including a security mode command; apply an integrity protection to the first medium access control control element; set the count value to be a second predefined value; transmit, to the second apparatus, the first medium access control control element; and perform an access stratum security activation, after a reception of a second medium access control control element including an acknowledgment to the security mode command from the second apparatus.
7. The first apparatus of any of claims 1-5, wherein the first apparatus is a terminal device and the second apparatus is a network device, the first apparatus is caused to:generate a second medium access control control element including an acknowledgment to a security mode command, after a reception of a first medium access control control element including the security mode command from the second apparatus; apply an integrity protection to the second medium access control control element; set the count value to be a second predefined value; and transmit the second medium access control control element to the second apparatus.
8. The first apparatus of claim 6 or 7, wherein the first apparatus is caused to: apply an integrity protection and a ciphering to one of: the transport block or to the at least one first protocol data unit at the first protocol layer that requires protection, or to the at least one second protocol data unit at a second protocol layer that requires protection, after the transmission of the first medium access control control element including the security mode command or after the transmission of the second medium access control control element including the acknowledgment to the security mode command; and set the count value larger than a second predefined value.
9. The first apparatus of any of claims 6-8, wherein the first apparatus is caused to: transmit, to the second apparatus, another transport block without security protection after the access stratum security activation.
10. The first apparatus of any of claims 1-5, wherein the first apparatus is a terminal device, and the second apparatus is a network device, or wherein the first apparatus is a network device, and the second apparatus is a terminal device, and wherein the first protocol layer is a medium access control layer, the second protocol layer is a radio resource control layer.
11. A second apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second apparatus to: obtain protection information indicating which control information and data require a security protection on a first protocol layer;receive, from a first apparatus a transport block that comprises one or more protocol data units, wherein the transport block comprises information indicating whether the security protection is applied to the one or more protocol data units at the first protocol layer; determine whether a protocol data unit in the one or more protocol data units requires the security protection based on the protection information; determine whether the security protection is applied to the protocol data unit in the one or more protocol data units based on the information indicating to which one or more protocol data units the security protection is applied; and process the protocol data unit based on the determinations.
12. The second apparatus of claim 11, wherein the second apparatus is caused to: based on a determination that the protocol data unit that requires the security protection according to the protection information is received without the security protection, discard the protocol data unit.
13. The second apparatus of claim 11, wherein the second apparatus is caused to: based on a determination that the protocol data unit that requires the security protection according to the protection information is received with the security protection, decode the protocol data unit.
14. The second apparatus of any of claims 11-13, wherein the first apparatus is a network device and the second apparatus is a terminal device, the second apparatus is caused to: after a reception of a first medium access control control element including the security mode command from the first apparatus, determine whether integrity protection is applied to the first medium access control control element; and if the integrity protection is applied to the first medium access control control element, transmit, to the first apparatus, a second medium access control control element including the acknowledgment to the security mode command.
15. The second apparatus of any of claims 11-13, wherein the first apparatus is a terminal device and the second apparatus is a network device, the second apparatus is caused to:after a transmission of a first medium access control control element including a security mode command, receive, from the first apparatus, a second medium access control control element including an acknowledgement to the security mode command; determine whether an integrity protection is applied to the second medium access control control element; and if the integrity protection is applied to second medium access control control element, perform an access stratum security activation, after a reception of the second medium access control control element including an acknowledgment to the security mode command.
16. A method comprising: obtaining, at a first apparatus, protection information indicating which control information and data require a security protection on a first protocol layer; determining whether to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer based on the obtained protection information; applying the security protection if it is determined to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer; generating, based on the protection information, a transport block that comprises at least one of: the at least one first protocol data unit at the first protocol layer that requires protection, and at least one second protocol data unit at the second protocol layer that requires protection, wherein the first protocol layer is lower than the second protocol layer, wherein the transport block further comprises information indicating whether the security protection is applied to one or more protocol data units at the first protocol layer; and transmitting the transport block to a second apparatus.
17. A method comprising: obtaining, at a second apparatus, protection information indicating which control information and data require a security protection on a first protocol layer; receiving, from a first apparatus a transport block that comprises one or more protocol data units, wherein the transport block comprises information indicating whether the security protection is applied to the one or more protocol data units at the first protocol layer; determining whether a protocol data unit in the one or more protocol data units requires the security protection based on the protection information;determining whether the security protection is applied to the protocol data unit in the one or more protocol data units based on the information indicating to which one or more protocol data units the security protection is applied; and processing the protocol data unit based on the determinations.
18. A first apparatus comprising: means for obtaining protection information indicating which control information and data require a security protection on a first protocol layer; means for determining whether to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer based on the obtained protection information; means for applying the security protection if it is determined to apply the security protection at the first protocol layer to at least one first protocol data unit at the first protocol layer or at least one second protocol data unit at a second protocol layer; means for generating, based on the protection information, a transport block that comprises at least one of: the at least one first protocol data unit at the first protocol layer that requires protection, and at least one second protocol data unit at the second protocol layer that requires protection, wherein the first protocol layer is lower than the second protocol layer, wherein the transport block further comprises information indicating whether the security protection is applied to one or more protocol data units at the first protocol layer; and means for transmitting the transport block to a second apparatus.
19. A second apparatus comprising: means for obtaining protection information indicating which control information and data require a security protection on a first protocol layer; means for receiving, from a first apparatus a transport block that comprises one or more protocol data units, wherein the transport block comprises information indicating whether the security protection is applied to the one or more protocol data units at the first protocol layer; means for determining whether a protocol data unit in the one or more protocol data units requires the security protection based on the protection information; means for determining whether the security protection is applied to the protocol data unit in the one or more protocol data units based on the information indicating to which one or more protocol data units the security protection is applied; and means for processing the protocol data unit based on the determinations.
20. A computer readable medium comprising instruction stored thereon for causing an apparatus at least to perform the method of claim 16 or 17.
Citation Information
Patent Citations
Communication method and apparatus
EP4369762A1
Medium access control security
US20200236537A1
Method and apparatus for enhancing security of mac layer entity in next-generation mobile communication system
US20220240094A1
Methods, infrastructure equipment and communications devices
WO2022167161A1
Communication method and apparatus
WO2023005929A1