Apparatuses and methods for supporting security in user equipment
By generating 256-bit security keys without truncation in 5G user equipment and using a key usage indicator, the limitations of current 5G networks are addressed, enhancing security and ensuring backward compatibility and interoperability.
Patent Information
- Application Number
- PCT/US2024/055935
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-04
- Filing Date
- 2024-11-14
- Publication Date
- 2025-06-12
AI Technical Summary
Current 5G networks only support 128-bit cipher algorithms, lacking backward compatibility and interoperability with non-5G networks that support both 128-bit and 256-bit algorithms.
Generating 256-bit security keys in user equipment (UE) for 5G networks without truncation functions, allowing for secure communication between UE and network equipment, and using a key usage indicator to adjust key usage based on network capabilities.
This solution enhances security by enabling 256-bit ciphering and integrity protection, while maintaining backward compatibility and interoperability, facilitating a smooth transition from 128-bit to 256-bit security algorithms.
Smart Images

Figure US2024055935_12062025_PF_FP_ABST
Abstract
Description
APPARATUSES AND METHODS FOR SUPPORTING SECURITY IN USER EQUIPMENTCROSS REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority to U.S. Provisional Application No. 63 / 605,986, entitled “METHOD FOR KEY GENERATION AND KEY USAGE INDICATION IN 5G,” filed on December 4, 2023, which is hereby incorporated in its entirety by this reference.TECHNICAL FIELD
[0002] The present disclosure relates to the field of communication systems, and more particularly, to apparatuses and methods for supporting security in a user equipment (UE).BACKGROUND
[0003] Currently, 5G networks only support 128-bit cipher algorithms, while some non-5G networks support both 128-bit and 256-bit algorithms. In 5G, keys used for cipher and integrity algorithms are 128-bit, as there is no prior support for 256-bit algorithms. In other networks, an application layer typically pre-configures security algorithms and generates corresponding keys (either 128-bit or 256-bit). These networks often use more capable equipment, prioritizing functionality over efficiency. Non-5G communications are typically end-to-end, with intermediate nodes unaware of the encryption, and do not support mobility or soft hand-offs. Therefore, current solutions lack backward compatibility and interoperability, which are unique challenges in mobile networks.
[0004] Therefore, there is a need for apparatuses and methods for supporting security in a user equipment (UE).SUMMARY
[0005] An object of the present disclosure is to propose apparatuses and methods for supporting security in a user equipment (UE), which can preserve backward compatibility and interoperability and / or enhance security.
[0006] In a first aspect of the present disclosure, a method for supporting security in a user equipment (UE) includes generating, by the UE, at least one 256-bit security key in the UE for a 5G network without truncation functions or by removing the truncation functions, to support a 256-bit ciphering and integrity protection; and using, by the UE, the at least one 256-bit security key to establish a secure communication between the UE and a network equipment.
[0007] In a second aspect of the present disclosure, a communication system includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The processor is configured to perform: generating at least one 256-bit security key in the UE for a 5G network without truncation functions or by removing the truncation functions, to support a 256-bit ciphering and integrity protection, and using the at least one 256-bit security key to establish a secure communication between the UE and a network equipment.
[0008] In a third aspect of the present disclosure, a non-transitory machine-readable storage medium has stored thereon instructions that, when executed by a computer, cause the computer to perform the above method.
[0009] In a fourth aspect of the present disclosure, a chip includes a processor, configured to call and run a computer program stored in a memory, to cause a device in which the chip is installed to execute the above method.
[0010] In a fifth aspect of the present disclosure, a computer readable storage medium, in which a computer program is stored, causes a computer to execute the above method.
[0011] In a sixth aspect of the present disclosure, a computer readable storage medium, in which a computer program is stored, causes a computer to execute the above method.
[0012] In a seventh aspect of the present disclosure, a computer program product includes a computer program, and the computer program causes a computer to execute the above method.
[0013] In an eighth aspect of the present disclosure, a computer program causes a computer to execute the above method.BRIEF DESCRIPTION OF DRAWINGS
[0014] In order to illustrate the embodiments of the present disclosure or related art more clearly, the following figures will be described in the embodiments are briefly introduced. It is obvious that the drawings are merely some embodiments of the present disclosure, a person having ordinary skill in this field can obtain other figures according to these figures without paying the premise.
[0015] FIG. 1 is a block diagram of a communication system according to an embodiment of the present disclosure.
[0016] FIG. 2 is a flowchart illustrating a method for supporting security in a user equipment (UE) according to an embodiment of the present disclosure.
[0017] FIG. 3 is a schematic diagram illustrating an example of a current key hierarchy and key generation in 5G.
[0018] FIG. 4 is a schematic diagram illustrating an example of a proposed enhanced 256-bit key generation in 5G according to an embodiment of the present disclosure.
[0019] FIG. 5 is a schematic diagram illustrating an example of using one-bit flag for each key according to an embodiment of the present disclosure.
[0020] FIG. 6 is a block diagram of an example of a computing device according to an embodiment of the present disclosure.
[0021] FIG. 7 is a block diagram of a communication system according to an embodiment of the present disclosure.DETAILED DESCRIPTION OF EMBODIMENTS
[0022] Embodiments of the present disclosure are described in detail with the technical matters, structural features, achieved objects, and effects with reference to the accompanying drawings as follows. Specifically, the terminologies in the embodiments of the present disclosure are merely for describing the purpose of the certain embodiment, but not to limit the disclosure.
[0023] The technical solutions of the embodiments of the present disclosure can be applied to various communication systems, such as a global system of mobile communication (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) system, a general packet radio service (GPRS), a long term evolution (LTE) system, a LTE frequency division duplex (FDD) system, a LTE time division duplex (TDD) system, an advanced long term evolution (LTE-A) system, a future 5th generation (5G) system (may also be called a new radio (NR) system), an evolution system of a NR system, aLTE-based access to unlicensed spectrum (LTE-U) system, a NR-based access to unlicensed spectrum (NR-U) system, an universal mobile telecommunication system (UMTS), a global interoperability for microwave access (WiMAX) communication system, wireless local area networks (WLAN), wireless fidelity (Wi-Fi), or other communication systems, etc.
[0024] A user equipment (UE) may refer to an access terminal, a subscriber unit, a subscriber station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device. The access terminal may be a cellular radio telephone, a cordless telephone, a session initiation protocol (SIP) telephone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication functions, a computing device, other processing devices coupled with a wireless modem, an in-vehicle device, a wearable device, a terminal device in a future 5G network, a terminal device in a future evolved public land mobile network (PLMN), etc.
[0025] Optionally, the communication system in the embodiment of the present application may be applied to an unlicensed spectrum, where the unlicensed spectrum may also be considered as a shared spectrum, or the communication system in the embodiment of the present application may also be applied to a licensed spectrum, where the licensed spectrum can also be considered an unshared spectrum.
[0026] Currently, 5G networks only support 128-bit cipher algorithms, while some other communication networks (e.g., non-5G) support both 128-bit and 256-bit cipher algorithms. In 5G, keys used for cipher and integrity algorithms are 128 bits, as there is no prior support for 256-bit algorithms.
[0027] In networks where applications support both 128-bit and 256-bit algorithms, an application layer typically pre-configures the security algorithm and generates appropriately sized keys (either 128 bits or 256 bits) for use in the cipher algorithm. Since an equipment in non-5G communication networks, such as PCs and network servers, is generally more capable, the applications tend to be less efficient compared to those in 5G networks. Efficiency is not a primary concern in non-5G communications, and after authentication, both 128-bit and 256-bit cipher keys are generated if supported.
[0028] Because communications in non-5G networks are end-to-end, there is no need to support intermediate communication nodes in the transport network. For instance, a communication session using 256-bit security between a client and server may pass through various nodes (e.g., routers, switches, hubs), but these nodes are unaware of the security algorithm being used in the end-to-end communication.
[0029] Additionally, non-5G communications are generally non-mobile and do not support mobility or soft hand-offs (e.g., make-before-break hand-offs). When a communication session moves between different networks, there is no need to consider the capabilities of each network, such as one network supporting 128-bit security and another supporting 256-bit security, because the network equipment is unaware of the security being used at the application layer.
[0030] As a result, current solutions or prior technologies do not support backward compatibility or interoperability, as these issues are specific to mobile network environments.
[0031] Some embodiments of the present disclosure provide a mechanism for key generation and key usage indication in 5 G to reduce the complexity of supporting 256-bit security by eliminating the truncation functionsin the current key generation procedure. This allows the user equipment and network equipment to operate at the highest level of security that both support (e.g., 256-bit security).
[0032] Additionally, some embodiments of the present disclosure provide a mechanism to maintain backward compatibility and interoperability during the transition from 128-bit to 256-bit security algorithms in 5G when both 128-bit and 256-bit algorithms are supported.
[0033] The 128-bit and 256-bit algorithms (commonly referred to as 128-bit or 256-bit security) are cipher algorithms using key lengths of either 128 bits or 256 bits to protect information, such as in the Advanced Encryption Standard (AES). With the design lifespan of the 128-bit cipher algorithm, like AES, nearing 20 years (e.g., AES was officially released in 2002), the industry is transitioning to increase key sizes from 128 bits to 256 bits. Increasing key size does not imply that the 128-bit algorithm is broken or obsolete. Both 128-bit and 256-bit algorithms will coexist well into the next generation of mobile communication systems, potentially until 2030, 2040, or beyond.
[0034] The transition from 128-bit to 256-bit security will be gradual and will only complete when all network equipment (e.g., Radio Access Network and Core Network equipment) and user equipment (e.g., handsets) are fully upgraded. Until this transition is complete, backward compatibility and interoperability between network and user equipment with varying security capabilities can be maintained to ensure users can continue to seamlessly enjoy 5G services across different networks.
[0035] Some embodiments of the present disclosure offer a mechanism to enable a user equipment and a network equipment to operate at the level of security supported by both (e.g., 256-bit security).
[0036] Some embodiments of the present disclosure provide a mechanism to reduce the complexity of key generation for supporting 256-bit security by removing truncation functions from the current key generation procedure in 5G. This enables security operations between user equipment and network equipment to function at the highest level of security that both support (e.g., 256-bit security).
[0037] Additionally, these embodiments offer a mechanism to indicate to the user equipment (UE) the size of the key (e.g., 128-bit) to be used during secure operations in a network that does not fully support 256-bit security. This mechanism can also be utilized to indicate to the UE the key size (e.g., 128-bit) when the network's security policy is set to use 128-bit security operations.
[0038] FIG. 1 illustrates a communication system 200 according to an embodiment of the present disclosure. The communication system 200 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the communication system using any suitably configured hardware and / or software. The communication system 200 may include a memory 201, a transceiver 202, and a processor 203 coupled to the memory 201 and the transceiver 202. The processor 203 may be configured to implement proposed functions, procedures and / or methods described in this description. Layers of radio interface protocol may be implemented in the processor 203. The memory 201 is operatively coupled with the processor 203 and stores a variety of information to operate the processor 203. The transceiver 202 is operatively coupled with the processor 203, and the transceiver 202 transmits and / or receives a radio signal. The processor 203 may include application-specific integrated circuit (ASIC), other chipset, logic circuit and / or data processing device. The memory 201 may include read-only memory (ROM), random access memory (RAM),flash memory, memory card, storage medium and / or other storage device. The transceiver 202 may include baseband circuitry to process radio frequency signals. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. The modules can be stored in the memory 201 and executed by the processor 203. The memory 201 can be implemented within the processor 203 or external to the processor 203 in which case those can be communicatively coupled to the processor 203 via various means as is known in the art.
[0039] In some embodiments, the processor 203 is configured to perform: generating at least one 256-bit security key in the UE for a 5G network without truncation functions or by removing the truncation functions, to support a 256-bit ciphering and integrity protection, and using the at least one 256-bit security key to establish a secure communication between the UE and a network equipment. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can preserve backward compatibility and interoperability and / or enhance security.
[0040] FIG. 2 illustrates a method 300 for supporting security in a user equipment (UE) according to an embodiment of the present disclosure. The method 300 for supporting security in the UE is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the method 300 for supporting security in the UE using any suitably configured hardware and / or software. In some embodiments, the method 300 for supporting security in the UE includes: an operation 302, generating, by the UE, at least one 256-bit security key in the UE for a 5 G network without truncation functions or by removing the truncation functions, to support a 256-bit ciphering and integrity protection, and an operation 304, using, by the UE, the at least one 256-bit security key to establish a secure communication between the UE and a network equipment. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can preserve backward compatibility and interoperability and / or enhance security.
[0041] Some embodiments of the present disclosure provide a mechanism to reduce the complexity of key generation for 256-bit security by removing truncation functions in the current 5G key generation process, allowing security operations between user equipment (UE) and network equipment to operate at the highest level of security both can support, such as 256-bit security. Additionally, these embodiments offer a mechanism to indicate the key size (e.g., 128-bit) to the UE for secure operations in networks that do not fully support 256-bit security, and can also signal the key size when the network’s security policy requires 128-bit security operations.
[0042] In some embodiments, the method further includes: when the 5G network does not support 256-bit security operations, generating, by the UE, at least one 128-bit security key from least significant 128 bits of the at least one 256-bit security key. In some embodiments, the method further includes indicating a size of at least one security key to be used during secure operations via a key usage indicator or a key flag. In some embodiments, the at least one security key is the at least one 256-bit security key or the at least one 128-bit security key. In some embodiments, the key usage indicator or the key flag indicates whether to use full 256 bits of the at least one 256-bit security key or least significant 128 bits of the at least one 256-bit security key. In some embodiments, the key usage indicator or the key flag is set for each security key generated in the UE, and a granularity of the key usage indicator or the key flag is adjustable, allowing the key usage indicator or the key flag to be set per security key or per group of security keys.
[0043] In some embodiments, the method further includes: generating, by the the UE, at least one intermediate 256-bit security key from at least one long-term security key in both the UE and the 5G network, wherein the at least one intermediate 256-bit security key is used to derive at least one final 128-bit security key or at least one final 256-bit security key for secure operations. In some embodiments, the method further includes storing, by a memory, the at least one intermediate 256-bit security key in a universal subscriber identity module (USIM) or a non-volatile memory of the UE if the USIM does not support a 5 G parameter storage. In some embodiments, the method further includes storing, by the memory, a latest intermediate 256-bit security key in the USIM or the non-volatile memory of the UE after successful completion of primary authentication. In some embodiments, the method further includes replacing, by the UE, an old intermediate 256-bit security key with the latest intermediate 256-bit security key.
[0044] In some embodiments, the method further includes performing, by the UE, secure operations using at least one 128-bit security key for at least one communication layer and using at least one 256-bit security key for at least another communication layer based on an operator security policy and / or the key usage indicator or the key flag. In some embodiments, during authentication and key agreement procedures, generating, by the UE, a security key material from the long-term security key stored in the USIM and forwarding, by the transceiver, the security key material to a mobile equipment (ME) of the UE for further key derivation and storage. In some embodiments, the at least one 256-bit security key is truncated to 128-bit for backward compatibility during transition from 128-bit to 256-bit secure operations. In some embodiments, the key flag is a one-byte flag, and the one-byte flag is used to represent a usage of at least one security key, and at least one bit of the one-byte flag is reserved for future expansion to accommodate at least one additional security key.
[0045] When a UE capable of supporting 128-bit security algorithms (e.g., cipher and integrity algorithms) is authenticated, the keys used for ciphering and integrity protection are generated as 128-bit keys. Currently, the key hierarchy supports 256-bit keys, starting from the root key (e.g., long-term key) to intermediate keys such as KAUSF, KSEAF, KgNB, and KAMF. These intermediate keys are generated as 256-bit keys in both the UE and the 5 G network, as shown in FIG. 3. However, these intermediate keys are not directly used for ciphering or integrity protection. Instead, the keys used for these security operations are generated as 128-bit keys. The lower part of FIG. 3 illustrates the 128-bit keys in the current 5G key generation process, as specified in Technical Specification 33.501.
[0046] To support full 256-bit keys for ciphering and integrity protection, the keys generated in current 5G systems (i.e., 128-bit KNASint, KNASBRC, Kupmt, Kupenc, KRRCint, and KRRCenc, as illustrated in FIG. 3) are extended to fully 256 bits. However, since 128-bit keys are still required for backward compatibility and interoperability during the transition period from 128-bit to 256-bit security (as not all equipment within the network and in roaming networks may support full 256-bit security operations), and considering that security is not end-to-end (e.g., ciphering from one UE to another UE), executing the key generation functions twice — once for generating 128-bit keys and once for 256-bit keys — would be inefficient. Therefore, in some embodiments of the present disclosure, key generation is executed only once, as illustrated in FIG. 4. In this process, KNASint, KNASenc, Kupmt, Kupenc, KRRCint, and KRRCenc are generated as 256-bit keys. This approach ensures that both 128-bit and 256-bit keys can coexist, providing backward compatibility while enabling a smoother transition to full 256-bit security in the future.
[0047] In some embodiments of the present disclosure, key generation is performed only once, as depicted in FIG. 4. During this process, KNAsmt, KNAsenc, Kupmt, Kupenc, KRRCint, and KRRCenc are generated as 256-bit keys. This method allows both 128-bit and 256-bit keys to coexist, ensuring backward compatibility while facilitating a smoother transition to full 256-bit security. The single execution of key generation reduces system complexity and processing overhead, allowing for seamless operation in networks that support both 128-bit and 256-bit security algorithms. As such, the system is capable of maintaining interoperability across devices and network nodes that are not fully upgraded to 256-bit security, thereby providing a flexible solution for networks during the transition period.
[0048] In details, in some embodiments of the present disclosure, key generation is performed only once, as illustrated in FIG. 4. During this process, security keys such as KNASint, KNASenc, KUPint, KUPenc, KRRCint, and KRRCenc are generated as 256-bit keys. This approach enables both 128-bit and 256-bit security keys to coexist within the system, ensuring backward compatibility and providing a seamless transition path towards full 256-bit security without introducing unnecessary complexity. The single execution of key generation significantly reduces system complexity by eliminating the need to generate separate 128-bit and 256-bit keys independently. In a traditional scenario, generating both sets of keys would require multiple key derivation processes, each consuming additional computational resources and adding to the overall processing overhead. By generating only 256-bit keys and utilizing flexible mechanisms (such as a key usage indicator) to determine whether the full 256 bits or the least significant 128 bits are to be used, the system ensures that all security requirements are met while optimizing the efficiency of key generation.
[0049] This method of key generation is particularly beneficial in environments where both legacy and upgraded network infrastructures coexist. As many networks and devices are still transitioning from 128-bit security to 256-bit security, there is often a mix of equipment that can only handle 128-bit encryption alongside newer systems capable of supporting 256-bit security algorithms. By generating 256-bit keys upfront, the system can dynamically adapt to the capabilities of the underlying network, allowing for secure communications regardless of the security protocols in use. Furthermore, this approach enhances the flexibility of the security architecture by allowing seamless operation in mixed-security environments. For example, if a device (UE) or network node connects to a legacy 5G network that supports only 128-bit security, the system can automatically utilize the least significant 128 bits of the generated 256-bit key without having to rerun the key generation process. This ensures that no additional processing burden is imposed on the device or network, while still maintaining the required level of security for the connection.
[0050] In addition to simplifying the key generation process, this approach also reduces the storage requirements for security keys. Since only 256-bit keys are stored, there is no need to maintain separate key sets for 128-bit and 256-bit operations. This consolidation minimizes the memory footprint of the security architecture, allowing more efficient use of available resources, particularly in resource-constrained devices such as mobile handsets. The ability to generate 256-bit keys in a single operation and selectively use either 128-bit or 256-bit segments based on network requirements also facilitates future scalability. As 5G networks evolve and begin to fully embrace 256-bit encryption, this system can easily transition to using the full 256-bit keys without requiring any changes to the key generation process itself. This future-proof design ensures that the network security architecture is flexible enough to support both current and future security needs.
[0051] Ultimately, this key generation method supports both backward compatibility and forward-looking security enhancements. It allows network operators and device manufacturers to continue supporting legacy 128- bit encryption during the transition to 256-bit security while reducing the complexity of managing multiple key sets. This streamlined approach ensures that security protocols can be implemented efficiently and consistently across various network environments, providing a robust and scalable solution for both present and future communication systems.
[0052] FIG. 4 illustrates that, in some embodiments, for every key in a network entity, there is a corresponding key in the UE. The USIM can store the same long-term key K that is stored in the ARPF. During an authentication and key agreement procedure, the USIM can generate key material from K and forward it to the ME. If provisioned by the home operator, the USIM can store the Home Network Public Key used for concealing the SUPI. The ME can generate the KAUSF from the CK and IK received from the USIM. The generation of this key material is specific to the authentication method. When 5G AKA is used, the ME can generate the RES* from RES. The UE can store the latest KAUSF or replace the old KAUSF with the latest one after the successful completion of the most recent primary authentication. If the USIM supports 5G parameter storage, the KAUSF can be stored in the USIM. Otherwise, the KAUSF can be stored in the non-volatile memory of the ME. In the case that 5G AKA is used as an authentication method, upon receiving a valid NAS Security Mode Command message from the AMF (to use the corresponding partial context derived from the newly generated KAUSF), the UE can consider the primary authentication successful and store the newly generated KAUSF or replace the old one with the latest KAUSF. In the case of any key-generating EAP method being used for the primary (re)authentication, upon receiving the EAP-Success message, the primary authentication can be considered successful, and the UE can store the newly generated KAUSF or replace the old KAUSF with the latest one.
[0053] FIG. 4 illustrates that, in some embodiments, the ME can perform the generation of KSEAF from the KAUSF. If the USIM supports 5G parameter storage, KSEAF can be stored in the USIM. Otherwise, KSEAF can be stored in the non-volatile memory of the ME. The ME can also perform the generation of KAMF. If the USIM supports 5G parameter storage, KAMF can be stored in the USIM; otherwise, KA F can be stored in the nonvolatile memory of the ME. The ME is also responsible for generating all other subsequent keys derived from KAMF. Any 5G security context, KAUSF, and KSEAF stored in the ME can be deleted from the ME if: a) the USIM is removed from the ME while the ME is powered on, b) the ME is powered on and detects that the USIM is different from the one used to create the 5G security context, and / or c) the ME is powered on and detects that no USIM is present.
[0054] In some embodiments of the present disclosure, FIG. 4 illustrates the end results of eliminating the truncation operation during the key generation process to improve efficiency while still generating 256-bit keys. By removing the truncation step, the key generation process is simplified, reducing computational complexity and processing time. This approach enables the generation of 256-bit keys directly without the need for additional truncation functions, thereby optimizing the overall security operation in 5G systems. The method ensures that 256-bit keys are consistently produced while maintaining compatibility with existing systems that rely on 128-bit keys during the transition phase to full 256-bit security.
[0055] In some embodiments of the present disclosure, to maintain backward compatibility and interoperability, a key usage indicator (or flag) is added to the 256-bit keys to signal whether the full 256 bits of each key can be used or if only the least significant 128 bits are to be utilized. For instance, when 128-bit keys are required — such as when a UE roams into an older 5G network (VPLMN or visited network) that does not support full 256-bit security operations or only supports partial 256-bit security — the key usage indicator or flag is activated. If the indicator is a single bit, a value of "1" indicates the use of the least significant 128 bits, while a "0" signifies the use of the full 256-bit key. When the indicator signals 128-bit operations, the UE may extract the least significant 128 bits from the 256-bit keys (KNASint,Kupmt, Kupenc, KRRCint, and KRRCenc) and use them as the corresponding 128-bit keys (KNASint, KNASenc, Kupmt, Kupenc, KRRCint, and KRRCenc). This mechanism ensures seamless transition and compatibility with networks that do not fully support 256-bit security operations.
[0056] In details, in some embodiments of the present disclosure, to maintain backward compatibility and interoperability, a key usage indicator (or flag) is introduced in conjunction with 256-bit keys to specify whether the entire 256 bits of each key are to be used, or if only the least significant 128 bits are needed. This mechanism is particularly beneficial in scenarios where the UE (User Equipment) roams into an older or less capable 5G network, such as a VPLMN (Visited Public Land Mobile Network), that does not fully support 256-bit security operations or only partially supports them. In such cases, the key usage indicator is activated to signal the appropriate level of security required by the network. The key usage indicator may be implemented as a single bit within the security framework, where a value of "1" indicates that only the least significant 128 bits of the key should be used for secure operations, and a value of "0" indicates that the full 256-bit key should be used. For instance, when 128-bit keys are required due to network limitations or interoperability constraints, the UE can automatically extract the least significant 128 bits from the existing 256-bit keys. These 256-bit keys include KNASint, KNASenc, Kupint, Kupenc, KRRCint, and KRRCenc, and the extracted 128-bit segments of these keys are used for corresponding security operations (i.e., KNASmt for NAS integrity, KNASenc for NAS encryption, Kupmt for user plane integrity, Kupenc for user plane encryption, KRRCint for RRC integrity, and KRRCenc for RRC encryption).
[0057] This key usage mechanism ensures a seamless transition between security levels without requiring the generation of separate 128-bit keys, which would otherwise add complexity to the key management process. By enabling the UE and network to adjust key usage dynamically based on network conditions, the solution ensures compatibility across various network infrastructures, especially during periods of migration where some networks support only 128-bit security while others implement 256-bit security. Furthermore, this approach significantly optimizes performance in mixed-security environments, such as during roaming between different network regions, where it is not practical or efficient to rely solely on 256-bit security. For instance, an older network may not be equipped to handle the computational demands of 256-bit security, but with this flag mechanism, the UE can gracefully fall back to 128-bit security, ensuring secure communications without overburdening network resources. This also simplifies the operational requirements on network providers by reducing the need for maintaining multiple sets of keys or protocols, streamlining both the UE and network infrastructure.
[0058] Additionally, this key flag mechanism provides a robust solution for networks gradually transitioning from 128-bit to 256-bit security. As operators upgrade their systems to support higher security standards, the same UE can continue to operate efficiently in both older and newer networks without requiring major overhaulsin key generation or management processes. This backward compatibility is critical in maintaining service continuity for users while allowing operators to enhance their network's security at their own pace. This solution is also scalable, meaning that as 5G and beyond-5G standards evolve, the key usage indicator can be adapted to accommodate more sophisticated security mechanisms. The flag itself can be extended to signal more granular security operations, allowing future implementations to selectively enable or disable certain levels of encryption or integrity protection, depending on the capabilities of both the UE and the network. This flexibility provides a future-proof mechanism for managing security operations as communication standards advance. The introduction of a key usage indicator or flag within the 256-bit key framework enhances the flexibility and interoperability of security operations across diverse network environments. It enables a smooth and efficient transition between 128-bit and 256-bit security, minimizes operational complexity, and ensures long-term scalability, all while maintaining a high level of security for user communications.
[0059] In some embodiments of the present disclosure, for additional flexibility, the granularity of the key usage indicator or key flag can be set either per key (e.g., one flag for KNASIHI and one for KNASenc) or per group of keys (e.g., a single flag for both KNASint and KNASenc). FIG. 5 illustrates an example of using a flag for each key currently defined in 5G. In this example, one byte is used to represent flags for the six keys (KNASint, KNASenc, Kupint, Kupenc, KRReint, and KRRCenc), leaving two bits available for future expansion. This approach not only provides flexibility in managing the use of 128-bit or 256-bit keys on a per-key or per-group basis but also allows for scalability as new keys may be added in future systems.
[0060] In details, in some embodiments of the present disclosure, to provide additional flexibility and control over security operations, the granularity of the key usage indicator or key flag can be configured either per individual key or per group of keys. For example, a separate flag can be assigned for each key, such as one for KNASint and one for KNASenc, enabling fine-grained control over the security level applied to each key. Alternatively, a single flag can be used for a group of related keys, such as KNASint and KNASenc, allowing for a more streamlined configuration where both keys share the same security settings.
[0061] FIG. 5 illustrates an embodiment where a key usage indicator is assigned to each key currently defined in 5 G. In this example, a single byte is used to represent flags for six different keys: KNASint, KNASenc, Kupmt, Kupenc, KRReint, and KRRCenc. This implementation leaves two additional bits within the byte for future expansion, enabling the system to accommodate more keys or additional functionalities as required by future 5G or beyond- 5G standards. By implementing this flexible flag system, network operators and equipment manufacturers can dynamically adjust the security level applied to each key based on the capabilities of the network and the UE. For instance, in networks that fully support 256-bit security, the flag can indicate the use of the full 256-bit key for both ciphering and integrity protection. In contrast, for backward-compatible operations in networks that only support 128-bit security, the flag can signal the use of only the least significant 128 bits of the key, thus ensuring seamless interoperability.
[0062] This approach also provides scalability. As 5G networks evolve and new key types are introduced (such as keys related to new security features or new communication protocols), the two remaining bits in the byte can be used to represent additional flags, eliminating the need for redesigning the flagging system. Moreover, the system can be extended to use more than one byte if additional keys or more granular control over key usage are needed in future implementations. The use of a flexible key flag system also optimizes memory andprocessing resources. Instead of maintaining separate processes for 128-bit and 256-bit key operations, the system can use a single unified process with key flags dynamically determining the applicable key length and operation. This reduces the overall complexity and processing load on both the UE and network equipment, enhancing performance without compromising security. Overall, this flexible and scalable approach to key usage indicators provides a robust mechanism for maintaining backward compatibility while preparing for future security upgrades, ensuring that both current and future 5G security needs are met efficiently.
[0063] This granularity allows for the flexibility of applying different security levels to various layers of communication within the network, depending on the operator’s security policy. For instance, an operator may choose to enforce 128-bit secure operations for NAS layer communications while utilizing 256-bit secure operations for UP and RRC layer communications. This enables a more tailored approach to security, optimizing performance where higher levels of protection are needed, such as in user plane (UP) and radio resource control (RRC) communications, without unnecessarily burdening other layers where 128-bit security may be sufficient.
[0064] By allowing different security configurations for each communication layer, the system can dynamically adapt to varying levels of threat or operational requirements. For example, UP layer communications, which handle user data, often require higher security due to the sensitive nature of the data being transmitted. In contrast, NAS layer communications, which handle signaling and mobility management, might not always require the same level of encryption, thus reducing overhead and improving system efficiency.
[0065] Furthermore, this flexibility supports network operators in balancing security and performance based on the specific use case or network conditions. In some scenarios, where resources are constrained or where interoperability with older systems is a priority, 128-bit security may be preferred across all layers. However, in higher security environments, operators can selectively apply 256-bit security to critical layers without disrupting the overall network performance. This ability to fine-tune security levels ensures that the network can maintain strong protection against potential threats while remaining adaptable to evolving standards and varying equipment capabilities. The operator can adjust security policies as needed, leveraging the granularity of the key usage indicators to meet both current and future security requirements efficiently.
[0066] Some embodiments of the present disclosure provide significant benefits to operators, UE vendors, and network equipment vendors by simplifying the existing key generation procedures in 5G. The streamlined key generation process reduces complexity, making it easier to implement and manage security operations. This simplification is particularly advantageous during the migration from 128-bit secure operations to 256-bit secure operations, as it allows for a smoother transition while supporting higher levels of security.
[0067] By eliminating unnecessary steps, such as truncation functions, and introducing flexible key usage indicators, some embodiments reduce the operational burden on both network operators and vendors. This results in more efficient key management, less processing overhead, and improved system performance, without compromising security. Additionally, this simplified approach ensures backward compatibility, making it easier for operators to maintain interoperability with legacy equipment and networks that still rely on 128-bit security.
[0068] Furthermore, some embodiments benefit the industry as a whole by facilitating a gradual and seamless transition to higher levels of security. As 5G networks evolve and demand for stronger security increases, the ability to smoothly transition from 128-bit to 256-bit security becomes crucial. These embodiments enableindustry stakeholders to adopt more advanced security measures without causing significant disruption to existing network operations or requiring costly upgrades.
[0069] Overall, some embodiments support the industry's long-term goal of enhancing security in 5G and future mobile communication systems. They provide a practical and efficient solution for scaling security operations, ensuring that networks can meet increasing security demands while maintaining flexibility and compatibility across different generations of network infrastructure.
[0070] Alternatives to the proposed solutions in some embodiments of the present disclosure include approaches that may address key generation but lack the flexibility and efficiency offered by the disclosed embodiments.
[0071] One alternative is for the UE and network to generate both 128-bit and 256-bit keys during the security key generation procedures. While this ensures that both key lengths are available for use, it is wasteful in terms of storage and processing resources. At any given time, either the 128-bit or the 256-bit keys are used, but not both simultaneously. Therefore, generating both sets of keys results in unnecessary overhead, reducing overall system efficiency.
[0072] Another alternative is to preconfigure the use of either 128-bit or 256-bit keys during the authentication and key agreement process. While this method reduces the complexity of generating both key lengths, it lacks the flexibility of adjusting security levels across different layers. For example, it would not allow for separate security operations, such as using 128-bit secure operations on the UP and RRC layers while simultaneously using 256-bit secure operations on the NAS layer. This alternative restricts the system's ability to dynamically adjust security based on the operator's policy or network conditions, limiting its adaptability to varying security requirements.
[0073] These alternatives, while feasible, do not offer the same level of flexibility, efficiency, or granularity as the solutions presented in some embodiments of the present disclosure. By contrast, the disclosed embodiments provide a more balanced and adaptable approach to key generation and security operations, optimizing both performance and resource usage while supporting future scalability.
[0074] Commercial interests for some embodiments are as follows. 1. Solve issues in the prior art. 2. Solve other issues. 3. Preserve backward compatibility and interoperability. 4. Enhance security. 5. Provide a good communication performance. 6. Provide high reliability. 7. Some embodiments of the present disclosure are used by chipset vendors, video system development vendors, automakers including cars, trains, trucks, buses, bicycles, moto-bikes, helmets, and etc., drones (unmanned aerial vehicles), smartphone makers, communication devices for public safety use, AR / VR / MR device maker for example gaming, conference / seminar, education purposes. Some embodiments of the present disclosure are a combination of “techniques / processes” that can be adopted in video standards to create an end product. Some embodiments of the present disclosure propose technical mechanisms. The at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure may be used for current and / or new / future standards regarding communication systems such as an AIoT device, a node (UE / BS), and / or a communication system. Compatible products follow at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure. The proposed solution, method, system, and apparatus are widely used in an AIoT device, a node (UE / BS), and / or acommunication system. With the implementation of the at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure, at least one modification to communication methods and apparatus are considered for standardizing.
[0075] FIG. 6 is an example of a computing device 1200 according to an embodiment of the present disclosure. Any suitable computing device can be used for performing the operations described herein. For example, FIG. 6 illustrates an example of the computing device 1200 that can implement apparatuses and methods of the above embodiments, using any suitably configured hardware and / or software. In some embodiments, the computing device 1200 can include a processor 1412 that is communicatively coupled to a memory 1414 and that executes computer-executable program code and / or accesses information stored in the memory 1414. The processor 1412 may include a microprocessor, an application-specific integrated circuit (“ASIC”), a state machine, or other processing device. The processor 1412 can include any of a number of processing devices, including one. Such a processor can include or may be in communication with a computer-readable medium storing instructions that, when executed by the processor 1412, cause the processor to perform the operations described herein.
[0076] The memory 1414 can include any suitable non-transitory computer-readable medium. The computer- readable medium can include any electronic, optical, magnetic, or other storage device capable of providing a processor with computer-readable instructions or other program code. Non-limiting examples of a computer- readable medium include a magnetic disk, a memory chip, a read-only memory (ROM), a random access memory (RAM), an application specific integrated circuit (ASIC), a configured processor, optical storage, magnetic tape or other magnetic storage, or any other medium from which a computer processor can read instructions. The instructions may include processor-specific instructions generated by a compiler and / or an interpreter from code written in any suitable computer-programming language, including, for example, C, C++, C#, visual basic, java, python, perl, javascript, and actionscript.
[0077] The computing device 1200 can also include a bus 1416. The bus 1416 can communicatively couple one or more components of the computing device 1200. The computing device 1200 can also include a number of external or internal devices such as input or output devices. For example, the computing device 1200 is illustrated with an input / output (“I / O”) interface 1418 that can receive input from one or more input devices 1420 or provide output to one or more output devices 1422. The one or more input devices 1420 and one or more output devices 1422 can be communicatively coupled to the I / O interface 1418. The communicative coupling can be implemented via any suitable manner (e.g., a connection via a printed circuit board, connection via a cable, communication via wireless transmissions, etc.). Non-limiting examples of input devices 1420 include a touch screen (e g., one or more cameras for imaging a touch area or pressure sensors for detecting pressure changes caused by a touch), a mouse, a keyboard, or any other device that can be used to generate input events in response to physical actions by a user of a computing device. Non-limiting examples of output devices 1422 include a liquid crystal display (LCD) screen, an external monitor, a speaker, or any other device that can be used to display or otherwise present outputs generated by a computing device.
[0078] The computing device 1200 can execute program code that configures the processor 1412 to perform one or more of the operations described above with respect to methods of the above embodiments. The programcode may be resident in the memory 1414 or any suitable computer-readable medium and may be executed by the processor 1412 or any other suitable processor.
[0079] The computing device 1200 can also include at least one network interface device 1424. The network interface device 1424 can include any device or group of devices suitable for establishing a wired or wireless data connection to one or more data networks 1428. Non limiting examples of the network interface device 1424 include an Ethernet network adapter, a modem, and / or the like. The computing device 1200 can transmit messages as electronic or optical signals via the network interface device 1424.
[0080] FIG. 7 is a block diagram of an example of a communication system 1500 according to an embodiment of the present disclosure. Embodiments described herein may be implemented into the communication system 1500 using any suitably configured hardware and / or software. FIG. 7 illustrates the communication system 1500 including a radio frequency (RF) circuitry 1510, a baseband circuitry 1520, an application circuitry 1530, a memory / storage 1540, a display 1550, a camera 1560, a sensor 1570, and an input / output (VO) interface 1580, coupled with each other at least as illustrated.
[0081] The application circuitry 1530 may include a circuitry such as, but not limited to, one or more singlecore or multi-core processors. The processors may include any combination of general-purpose processors and dedicated processors, such as graphics processors, application processors. The processors may be coupled with the memory / storage and configured to execute instructions stored in the memory / storage to enable various applications and / or operating systems running on the system. The communication system 1500 can execute program code that configures the application circuitry 1530 to perform one or more of the operations described above with respect to methods of the above embodiments. The program code may be resident in the application circuitry 1530 or any suitable computer-readable medium and may be executed by the application circuitry 1530 or any other suitable processor.
[0082] The baseband circuitry 1520 may include circuitry such as, but not limited to, one or more single-core or multi-core processors. The processors may include a baseband processor. The baseband circuitry may handle various radio control functions that may enable communication with one or more radio networks via the RF circuitry. The radio control functions may include, but are not limited to, signal modulation, encoding, decoding, radio frequency shifting, etc. In some embodiments, the baseband circuitry may provide for communication compatible with one or more radio technologies. For example, in some embodiments, the baseband circuitry may support communication with an evolved universal terrestrial radio access network (EUTRAN) and / or other wireless metropolitan area networks (WMAN), a wireless local area network (WLAN), a wireless personal area network (WPAN). Embodiments in which the baseband circuitry is configured to support radio communications of more than one wireless protocol may be referred to as multi-mode baseband circuitry.
[0083] In various embodiments, the baseband circuitry 1520 may include circuitry to operate with signals that are not strictly considered as being in a baseband frequency. For example, in some embodiments, baseband circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency. The RF circuitry 1510 may enable communication with wireless networks using modulated electromagnetic radiation through a non-solid medium. In various embodiments, theRF circuitry may include switches, filters, amplifiers, etc. to facilitate the communication with the wireless network. In various embodiments, the RF circuitry 1510 may include circuitry to operate with signals that are not strictly considered as being in a radio frequency. For example, in some embodiments, RF circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency.
[0084] In various embodiments, the transmitter circuitry, control circuitry, or receiver circuitry discussed above with respect to apparatuses and methods of the above embodiments may be embodied in whole or in part in one or more of the RF circuitry, the baseband circuitry, and / or the application circuitry. As used herein, “circuitry” may refer to, be part of, or include an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or group), and / or a memory (shared, dedicated, or group) that execute one or more software or firmware programs, a combinational logic circuit, and / or other suitable hardware components that provide the described functionality. In some embodiments, the electronic device circuitry may be implemented in, or functions associated with the circuitry may be implemented by, one or more software or firmware modules. In some embodiments, some or all of the constituent components of the baseband circuitry, the application circuitry, and / or the memory / storage may be implemented together on a system on a chip (SOC). The memory / storage 1540 may be used to load and store data and / or instructions, for example, for system. The memory / storage for one embodiment may include any combination of suitable volatile memory, such as dynamic random access memory (DRAM)), and / or non-volatile memory, such as flash memory.
[0085] In various embodiments, the VO interface 1580 may include one or more user interfaces designed to enable user interaction with the system and / or peripheral component interfaces designed to enable peripheral component interaction with the system. User interfaces may include, but are not limited to a physical keyboard or keypad, a touchpad, a speaker, a microphone, etc. Peripheral component interfaces may include, but are not limited to, a non-volatile memory port, a universal serial bus (USB) port, an audio jack, and a power supply interface. In various embodiments, the sensor 1570 may include one or more sensing devices to determine environmental conditions and / or location information related to the system. In some embodiments, the sensors may include, but are not limited to, a gyro sensor, an accelerometer, a proximity sensor, an ambient light sensor, and a positioning unit. The positioning unit may also be part of, or interact with, the baseband circuitry and / or RF circuitry to communicate with components of a positioning network, e.g., a global positioning system (GPS) satellite.
[0086] In various embodiments, the display 1550 may include a display, such as a liquid crystal display and a touch screen display. In various embodiments, the communication system 1500 may be a mobile computing device such as, but not limited to, a laptop computing device, a tablet computing device, a netbook, an ultrabook, a smartphone, an AR / VR glasses, etc. In various embodiments, system may have more or less components, and / or different architectures. Where appropriate, methods described herein may be implemented as a computer program. The computer program may be stored on a storage medium, such as a non-transitory storage medium.
[0087] A person having ordinary skill in the art understands that each of the units, algorithm, and steps described and disclosed in the embodiments of the present disclosure are realized using electronic hardware orcombinations of software for computers and electronic hardware. Whether the functions run in hardware or software depends on the condition of application and design requirement for a technical plan. A person having ordinary skill in the art can use different ways to realize the function for each specific application while such realizations should not go beyond the scope of the present disclosure. It is understood by a person having ordinary skill in the art that he / she can refer to the working processes of the system, device, and unit in the above-mentioned embodiment since the working processes of the above-mentioned system, device, and unit are basically the same. For easy description and simplicity, these working processes will not be detailed.
[0088] It is understood that the disclosed system, device, and method in the embodiments of the present disclosure can be realized with other ways. The above-mentioned embodiments are exemplary only. The division of the units is merely based on logical functions while other divisions exist in realization. It is possible that a plurality of units or components are combined or integrated in another system. It is also possible that some characteristics are omitted or skipped. On the other hand, the displayed or discussed mutual coupling, direct coupling, or communicative coupling operate through some ports, devices, or units whether indirectly or communicatively by ways of electrical, mechanical, or other kinds of forms.
[0089] The units as separating components for explanation are or are not physically separated. The units for display are or are not physical units, that is, located in one place or distributed on a plurality of network units. Some or all of the units are used according to the purposes of the embodiments. Moreover, each of the functional units in each of the embodiments can be integrated in one processing unit, physically independent, or integrated in one processing unit with two or more than two units.
[0090] If the software function unit is realized and used and sold as a product, it can be stored in a readable storage medium in a computer. Based on this understanding, the technical plan proposed by the present disclosure can be essentially or partially realized as the form of a software product. Or, one part of the technical plan beneficial to the conventional technology can be realized as the form of a software product. The software product in the computer is stored in a storage medium, including a plurality of commands for a computational device (such as a personal computer, a server, or a network device) to run all or some of the steps disclosed by the embodiments of the present disclosure. The storage medium includes a USB disk, a mobile hard disk, a readonly memory (ROM), a random access memory (RAM), a floppy disk, or other kinds of media capable of storing program codes.
[0091] While the present disclosure has been described in connection with what is considered the most practical and preferred embodiments, it is understood that the present disclosure is not limited to the disclosed embodiments but is intended to cover various arrangements made without departing from the scope of the broadest interpretation of the appended claims.
Claims
What is claimed is:
1. A method for supporting security in a user equipment (UE), comprising: generating, by the UE, at least one 256-bit security key in the UE for a 5G network without truncation functions or by removing the truncation functions, to support a 256-bit ciphering and integrity protection; and using, by the UE, the at least one 256-bit security key to establish a secure communication between the UE and a network equipment.
2. The method of claim 1, further comprising: when the 5G network does not support 256-bit security operations, generating, by the UE, at least one 128-bit security key from least significant 128 bits of the at least one 256-bit security key.
3. The method of claim 1 or 2, further comprising: indicating a size of at least one security key to be used during secure operations via a key usage indicator or a key flag.
4. The method of claim 3, wherein the at least one security key is the at least one 256-bit security key or the at least one 128-bit security key.
5. The method of claim 4, wherein the key usage indicator or the key flag indicates whether to use full 256 bits of the at least one 256-bit security key or least significant 128 bits of the at least one 256-bit security key.
6. The method of any one of claims 3 to 5, wherein the key usage indicator or the key flag is set for each security key generated in the UE, and a granularity of the key usage indicator or the key flag is adjustable, allowing the key usage indicator or the key flag to be set per security key or per group of security keys.
7. The method of any one of claims 1 to 6, further comprising: generating, by the UE, at least one intermediate 256-bit security key from at least one long-term security key in both the UE and the 5G network, wherein the at least one intermediate 256-bit security key is used to derive at least one final 128-bit security key or at least one final 256-bit security key for secure operations.
8. The method of claim 7, further comprising: storing, by a memory, the at least one intermediate 256-bit security key in a universal subscriber identity module (USIM) or a non-volatile memory of the UE if the USIM does not support a 5G parameter storage.
9. The method of claim 7 or 8, further comprising: storing, by the memory, a latest intermediate 256-bit security key in the USIM or the non-volatile memory of the UE after successful completion of primary authentication.
10. The method of claim 9, further comprising: replacing, by the UE, an old intermediate 256-bit security key with the latest intermediate 256-bit security key.
11. The method of any one of claims 1 to 10, further comprising: performing, by the UE, secure operations using at least one 128-bit security key for at least one communication layer and using at least one 256-bit security key for at least another communication layer based on an operator security policy and / or the key usage indicator or the key flag.
12. The method of any one of claims 7 to 11, wherein during authentication and key agreement procedures, generating, by the UE, a security key material from the long-term security key stored in the USIM and forwarding, by the transceiver, the security key material to a mobile equipment (ME) of the UE for further key derivationand storage.
13. The method of any one of claims 1 to 12, wherein the at least one 256-bit security key is truncated to 128- bit for backward compatibility during transition from 128-bit to 256-bit secure operations.
14. The method of any one of claims 3 to 13, wherein the key flag is a one-byte flag, and the one-byte flag is used to represent a usage of at least one security key, and at least one bit of the one-byte flag is reserved for future expansion to accommodate at least one additional security key.
15. A communication system, comprising: a memory; a transceiver; and a processor coupled to the memory and the transceiver; wherein the processor is configured to perform: generating at least one 256-bit security key in the UE for a 5G network without truncation functions or by removing the truncation functions, to support a 256-bit ciphering and integrity protection; and using the at least one 256-bit security key to establish a secure communication between the UE and a network equipment.
16. The communication system of claim 15, wherein when the 5G network does not support 256-bit security operations, the processor is configured to generate at least one 128-bit security key from least significant 128 bits of the at least one 256-bit security key.
17. The communication system of claim 15 or 16, wherein the processor is configured to indicate a size of at least one security key to be used during secure operations via a key usage indicator or a key flag.
18. The communication system of claim 17, wherein the at least one security key is the at least one 256-bit security key or the at least one 128-bit security key.
19. The communication system of claim 18, wherein the key usage indicator or the key flag indicates whether to use full 256 bits of the at least one 256-bit security key or least significant 128 bits of the at least one 256-bit security key.
20. The communication system of any one of claims 17 to 19, wherein the key usage indicator or the key flag is set for each security key generated in the UE, and a granularity of the key usage indicator or the key flag is adjustable, allowing the key usage indicator or the key flag to be set per security key or per group of security keys.
21. The communication system of any one of claims 15 to 20, wherein the processor is configured to generate at least one intermediate 256-bit security key from at least one long-term security key in both the UE and the 5G network, wherein the at least one intermediate 256-bit security key is used to derive at least one final 128-bit security key or at least one final 256-bit security key for secure operations.
22. The communication system of claim 21, wherein the memory is configured to store the at least one intermediate 256-bit security key in a universal subscriber identity module (USIM) or a non-volatile memory of the UE if the USIM does not support a 5G parameter storage.
23. The communication system of claim 21 or 22, wherein the memory is configured to store a latest intermediate 256-bit security key in the USIM or the non-volatile memory of the UE after successful completion of primary authentication.
24. The communication system of claim 23, wherein the processor is configured to replace an old intermediate 256-bit security key with the latest intermediate 256-bit security key.
25. The communication system of any one of claims 15 to 24, wherein the processor is configured to perform secure operations using at least one 128-bit security key for at least one communication layer and using at least one 256-bit security key for at least another communication layer based on an operator security policy and / or the key usage indicator or the key flag.
26. The communication system of any one of claims 21 to 25, wherein during authentication and key agreement procedures, the processor is configured to generate a security key material from the long-term security key stored in the USIM and the transceiver is configured to forward the security key material to a mobile equipment (ME) of the UE for further key derivation and storage.
27. The communication system of any one of claims 15 to 26, wherein the at least one 256-bit security key is truncated to 128-bit for backward compatibility during transition from 128-bit to 256-bit secure operations.
28. The communication system of any one of claims 17 to 27, wherein the key flag is a one-byte flag, and the one-byte flag is used to represent a usage of at least one security key, and at least one bit of the one-byte flag is reserved for future expansion to accommodate at least one additional security key.
29. A non-transitory machine-readable storage medium having stored thereon instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1 to 14.
30. A chip, comprising: a processor, configured to call and run a computer program stored in a memory, to cause a device in which the chip is installed to execute the method of any one of claims 1 to 14.
31. A computer readable storage medium, in which a computer program is stored, wherein the computer program causes a computer to execute the method of any one of claims 1 to 14.
32. A computer program product, comprising a computer program, wherein the computer program causes a computer to execute the method of any one of claims 1 to 14.
33. A computer program, wherein the computer program causes a computer to execute the method of any one of claims 1 to 14.
Citation Information
Patent Citations
Method and system for generating a pair of public key and secret key
US20090046853A1
Architecture and instruction set for implementing advanced encryption standard (AES)
US20200396057A1
Method, device, and system for authentication and authorization with edge data network
US20230336535A1