Applying security protocols based on user equipment (UE) capabilities in wireless communications systems
By enabling UEs to indicate their security capabilities and the network to respond with appropriate security protocols, the system addresses the challenge of inconsistent security levels in wireless communications, thereby enhancing security and preventing establishment failures.
Patent Information
- Application Number
- PCT/IB2025/051190
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-09
- Filing Date
- 2025-02-04
- Publication Date
- 2025-06-26
AI Technical Summary
Existing wireless communications systems face challenges in consistently applying appropriate security protocols based on the capabilities of user equipment (UE), leading to variability in security levels between the AS and NAS layers, and potential security establishment failures.
The system facilitates communications between UEs and the network to determine and apply appropriate security levels, such as 256-bit security, by having UEs indicate their security capabilities and the network responding with instructions on the security protocols to apply during authentication procedures.
This approach mitigates security establishment failures and ensures consistent security levels across different UEs and network entities, enhancing the overall security of wireless communications systems.
Smart Images

Figure IB2025051190_26062025_PF_FP_ABST
Abstract
Description
APPLYING SECURITY PROTOCOLS BASED ON USER EQUIPMENT (UE) CAPABILITIES IN WIRELESS COMMUNICATIONS SYSTEMSTECHNICAL FIELD
[0001] This application claims priority to U.S. Provisional Patent Application No. 63 / 551,701, filed on February 9, 2024, entitled APPLYING SECURITY PROTOCOLS BASED ON USER EQUIPMENT (UE) CAPABILITIES IN WIRELESS COMMUNICATIONS SYSTEMS, which is incorporated by reference in its entirety.TECHNICAL FIELD
[0002] The present disclosure relates to wireless communications, and more specifically to applying security protocol based on user equipment (UE) capabilities.BACKGROUND
[0003] A wireless communications system may include one or multiple network communication devices, such as base stations, which may support wireless communications for one or multiple user communication devices, which may be otherwise known as user equipment (UE), or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like). Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G)).
[0004] Wireless communications systems apply a security context for communications between UEs and base stations or other network communications devices. For example, to activate security for a UE, a Non Access Stratum (NAS) security context may be established between the UE and an Access and Mobility Management Function (AMF) of anetwork. The security context, which can include authentication, integrity protection, and ciphering applied to communications, may be created during a primary authentication and / or key agreement procedure between the UE and the AMF (or other network function).SUMMARY
[0005] An article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” may be interchangeable. As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of’ or “one or more of’ or “one or both of’) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on. Further, as used herein, including in the claims, a “set” may include one or more elements.
[0006] The present disclosure relates to methods, apparatuses, and systems that facilitate communications (e.g., messaging) between UEs and the network to determine what levels of security (e.g., 256-bit security or 128-bit security) to apply when the UEs connect to the network.
[0007] Some implementations of the method and apparatuses described herein may further include a UE for wireless communication, comprising at least one memory and at least one processor coupled with the at least one memory and configured to cause the UE to transmit, to a network entity, an indication of a 256-bit security capability for the UE, and receive, from the network entity, a response that confirms the UE is to apply the 256-bit security capability when performing an authentication procedure with the network entity.
[0008] In some implementations of the method and apparatuses described herein, the indication of the 256-bit security capability for the UE includes an indication that the UE supports a 256-bit key size.
[0009] In some implementations of the method and apparatuses described herein, the response indicates use of 256-bit key size by the UE.
[0010] In some implementations of the method and apparatuses described herein, the indication of the 256-bit security capability for the UE includes an indication that the UE supports 256-bit cryptographic algorithms for integrity protection and ciphering.
[0011] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the UE to transmit the indication of the 256-bit security capability for the UE to an AMF via a NAS message.
[0012] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the UE to transmit the indication of the 256-bit security capability for the UE to an AMF via an N1 transport message.
[0013] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the UE to transmit the indication of the 256-bit security capability for the UE during a primary authentication procedure with the network entity.
[0014] In some implementations of the method and apparatuses described herein, the primary authentication procedure includes an Extensible Authentication Protocol Authentication and Key Agreement (EAP-AKA1) authentication procedure.
[0015] In some implementations of the method and apparatuses described herein, the primary authentication procedure includes an 5G Authentication and Key Agreement (5G- AKA) authentication procedure.
[0016] In some implementations of the method and apparatuses described herein, the at least one processor is further configured to cause the UE to generate a 256-bit security keys for ciphering and integrity protection upon receiving the response from the network entity and perform the ciphering and integrity protection using the generated 256-bit keys.
[0017] In some implementations of the method and apparatuses described herein, the generated and used 256-bit security key is a 256-bit NAS integrity key, a 256-bit NAS ciphering key, a 256-bit AS integrity key, a 256-bit AS ciphering key, a 256-bit user plane (UP) integrity key, or a 256-bit UP ciphering key.
[0018] Some implementations of the method and apparatuses described herein may further include a network entity for wireless communication, comprising at least one memory and at least one processor coupled with the at least one memory and configured to cause the network entity to receive, from a UE, an indication of a 256-bit security capability for the UE, determine whether the UE is to apply the 256-bit security capability based on one or more of the 256-bit security capability for the UE, subscription data associated with the UE, or capabilities of a communications network that includes the network entity, and transmit, to the UE, a response that confirms the UE is to apply the 256-bit security capability when performing an authentication procedure with the network entity.
[0019] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network entity to transmit the response that confirms the UE is to apply the 256-bit security capability when performing a NAS security procedure.
[0020] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network entity to transmit the response that confirms the UE is to apply the 256-bit security capability via an Anti-Bidding down Between Architectures (ABBA) parameter sent to the UE during the authentication procedure.
[0021] In some implementations of the method and apparatuses described herein, the response indicates use of a 256-bit key size.
[0022] In some implementations of the method and apparatuses described herein, the network entity is a United Data Management (UDM) function that manages the subscription data along with 256-bit security requirements associated with the UE.
[0023] In some implementations of the method and apparatuses described herein, the authentication procedure is an EAP-AKA’ authentication procedure, the processor is further configured to cause the network entity to instruct a security anchor function (SEAF) to utilize 256-bit security during the EAP-AKA' authentication procedure.
[0024] In some implementations of the method and apparatuses described herein, the authentication procedure is a 5G-AKA authentication procedure, the processor is further configured to cause the network entity to instruct a SEAF to utilize 256-bit security during the 5G-AKA authentication procedure.
[0025] Some implementations of the method and apparatuses described herein may further include a network entity for wireless communication, including at least one memory and at least one processor coupled with the at least one memory and configured to cause the network entity to receive, from a UE an indication of a 256-bit security capability for the UE, determine whether to apply a 256-bit cryptographic algorithm for ciphering and integrity protection based on the 256-bit security capability for the UE and an operator policy for an operator of the network entity that prioritizes the 256-bit cryptographic algorithm, and transmit, to the UE, a response that confirms the UE is to apply the 256-bit security capability when performing a security mode command procedure with the network entity.
[0026] In some implementations of the method and apparatuses described herein, the network entity receives the indication of the 256-bit security capability for the UE via a NAS message.
[0027] In some implementations of the method and apparatuses described herein, the network entity receives the indication of the 256-bit security capability for the UE via an N1 transport message.
[0028] In some implementations of the method and apparatuses described herein, the network entity receives the indication of the 256-bit security capability for the UE via a registration request sent to the network entity during a primary authentication procedure.
[0029] In some implementations of the method and apparatuses described herein, the response that confirms the UE is to apply the 256-bit security capability incudesinformation identifying 256-bit cryptographic algorithms for ciphering and integrity protection supported by the network entity.
[0030] In some implementations of the method and apparatuses described herein, the 256-bit cryptographic algorithm is associated with NAS integrity and ciphering protection.
[0031] In some implementations of the method and apparatuses described herein, the network entity is an AMF.
[0032] Some implementations of the method and apparatuses described herein may further include a network entity for wireless communication, including at least one memory and at least one processor coupled with the at least one memory and configured to cause the network entity to receive, from an AMF, an indication of a 256-bit security capability for a UE and determine a 256-bit cryptographic algorithm to apply for AS security based on one or more of: the 256-bit security capability for the UE, a use 256-bit algorithm from the AMF, and an operator policy of the network entity that prioritizes 256-bit cryptographic algorithms.
[0033] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network entity to determine the 256-bit cryptographic algorithm to apply to radio resource control (RRC) ciphering and integrity protection procedures.
[0034] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network entity to determine the 256-bit cryptographic algorithm to apply to UP ciphering and integrity protection procedures.
[0035] In some implementations of the method and apparatuses described herein, the network entity is an NR Node B (gNB) or a Next Generation Evolved Node-B (ng-eNB).BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.
[0037] Figure 2 illustrates a messaging flow of an authentication procedure for a UE in accordance with aspects of the present disclosure.
[0038] Figure 3 illustrates a messaging flow of an authentication procedure for EAP- AKA’ in accordance with aspects of the present disclosure.
[0039] Figure 4 illustrates a messaging flow of an authentication procedure for 5G- AKA’ in accordance with aspects of the present disclosure.
[0040] Figure 5 illustrates a messaging flow of a NAS security mode command procedure in accordance with aspects of the present disclosure.
[0041] Figure 6 illustrates a messaging flow of an AS security mode command procedure in accordance with aspects of the present disclosure.
[0042] Figure 7 illustrates an example of a UE in accordance with aspects of the present disclosure.
[0043] Figure 8 illustrates an example of a processor in accordance with aspects of the present disclosure.
[0044] Figure 9 illustrates an example of a network equipment (NE) in accordance with aspects of the present disclosure.
[0045] Figure 10 illustrates a flowchart of a method performed by a UE in accordance with aspects of the present disclosure.
[0046] Figure 11 illustrates a flowchart of a method performed by a NE in accordance with aspects of the present disclosure.
[0047] Figure 12 illustrates a flowchart of another method performed by a NE in accordance with aspects of the present disclosure.
[0048] Figure 13 illustrates a flowchart of another method performed by a NE in accordance with aspects of the present disclosure.DETAILED DESCRIPTION
[0049] Recently, 265-bit algorithms and other security mechanism have been introduced to wireless communications systems, such as to core networks and radio access networks (RANs). The introduction of 265-bit capabilities enables 256-bit capable UEs to connect to base stations (e.g., gNBs) that support the 256-bit algorithms and / or Access and Mobility Management Functions (AMFs) that support the 256-bit algorithms. However, such support for 256-bit capabilities is not ubiquitous across networks or UEs.
[0050] Thus, there may be scenarios where a UE supports 256-bit security, but a network entity or function does not support 256-bit security (e.g., a gNB or AMF only supports 128-bit security). Similarly, there may be scenarios where one or more network nodes support 256-bit security, but the UE, or another network node, does not support 256- bit security (e.g., the UE only supports 128-bit security).
[0051] In such cases, there can variability in supporting 256-bit security (e.g., cryptography, ciphering, integrity protection) between the AS layer and the NAS layer of the network. This variability can lead to problems associated with applying different security mechanism to communications between UEs and network entities, among other problems.
[0052] For example, there are active subscriptions having permanent security keys that do not have sufficient entropy to provide for effective 256-bit security (e.g., it is still possible to provision current Universal Subscriber Identity Modules, or USIMs, with 128- bit keys). However, legacy key derivation algorithms and permanent keys with 128 bits do not provide sufficient entropy to ensure 256-bit protection on a AS and NAS layer.
[0053] To improve security, wireless communications systems have introduced 256-bit algorithms in both the RAN and the core networks. For example, the introduction may lead to UEs having 256-bit key sizes (e.g., permanent keys) and / or 256-bit algorithms (e.g., ciphering, integrity protection, and so on) along with legacy UEs (e.g., UEs that support 128-bit key sizes or 128-bit algorithms. Thus, a network supporting 256-bit security (e.g., 256-bit cryptographic algorithm selection / negotiation and use) may realize security establishment failures with such UEs.
[0054] The technology described herein provides solutions to such issues, by facilitating communications (e.g., messaging) between UEs and the network to determine what levels of security (e.g., 256-bit security or 128-bit security) to apply when the UEs connect to the network. For example, a UE may send an indication of its security capabilities to the network, which may respond with an indication or instructions on what level of security to apply when establishing a secure connection to the network.
[0055] Thus, the systems and method described herein can mitigate security establishment failures and other drawbacks arising from the introduction or roll out of an enhanced level of security (e.g., 256-bit) to a network and / or various network entities, among other benefits.
[0056] Aspects of the present disclosure are described in the context of a wireless communications system.
[0057] Figure 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more NE 102, one or more UE 104, and a core network (CN) 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LIE- Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a NR network, such as a 5G network, a 5G- Advanced (5G-A) network, or a 5G ultrawideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA), etc.
[0058] The one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NE 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, a radio access network (RAN), a NodeB, an eNodeB (eNB), a next-generation NodeB (gNB), or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link, which may be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.
[0059] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For example, an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102.
[0060] The one or more UE 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Internet-of-Things (loT) device, an Internet-of-Everything (loE) device, or machine-type communication (MTC) device, among other examples.
[0061] A UE 104 may be able to support wireless communication directly with otherUEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, thecommunication link may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.
[0062] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., SI, N2, N2, or network interface). In some implementations, the NE 102 may communicate with each other directly. In some other implementations, the NE 102 may communicate with each other or indirectly (e.g., via the CN 106. In some implementations, one or more NE 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC). An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as a radio heads, smart radio heads, or transmission-reception points (TRPs).
[0063] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC), or a 5G core (5GC), which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME), an access and mobility management functions (AMF)) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW), a Packet Data Network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for the one or more UEs 104 served by the one or more NE 102 associated with the CN 106.
[0064] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g., via an SI, N2, N2, or another network interface). The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g., a protocol data unit (PDU) session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g., control information, data, and the like) between the UE 104 and the application server using the established session (e.g., the established PDU session). ThePDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g., one or more network functions of the CN 106).
[0065] In the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communications). In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104 may support various frame structures (i.e., multiple frame structures). The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.
[0066] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., / r=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., / r=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., / r=l) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., / r=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., / r=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., / r=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.
[0067] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames). Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations,each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.
[0068] Additionally or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e., / r=0, jU=l, / r=2, jU=3, / r=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing), a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., / r=0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.
[0069] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data).In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.
[0070] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies). For example, FR1 may be associated with a first numerology (e.g., / r=0), which includes 15 kHz subcarrier spacing; a second numerology (e.g., / r=l), which includes 30 kHz subcarrier spacing; and a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies). For example, FR2 may be associated with a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., / r=3), which includes 120 kHz subcarrier spacing.
[0071] As described herein, the systems and method determine security levels / capabilities / strengths supported by UEs and networks during authentication procedures (e.g., primary authentication procedures), in order to avoid failures when establishing security for communications, among other benefits.
[0072] In some embodiments, when the UE 104 can support 256-bit security, the UE 104 indicates to the network (e.g., the NE 102) the corresponding 256-bit security capabilities via messaging (e.g., a NAS message or N1 transport). For example, 256-bit security capabilities may include:
[0073] Support of a 256-bit key size (e.g., 256-bit permanent key, 256-bit key derivation function, such as HMAC-SHA-256), which may be provided via a “256-bit key size supported” indication; and / or
[0074] Support of 256-bit cryptographic algorithms (e.g., 256-bit SNOW 3G based algorithm, 256-bit AES based algorithm, 256-bit ZUC based algorithm, and so on), which may be provided via a “256-bit cryptographic algorithms supported” indication, along with algorithm identities / identifiers.
[0075] A Unified Data Management (UDM) function manages permanent key size information (e.g., 128-bits or 256-bits) as part of subscription data for the UE. The network (e.g., the UDM or the AMF) may determine whether to apply 256-bit security based on theUE capabilities, subscription data, and / or network security capabilities. The network (e.g., AMF) may transmit an indication to the UE to apply 256-bit security (e.g., to use an 256-bit key size) as part of a new (Anti-Bidding down Between Architectures) ABBA parameter for bidding down attack prevention and / or to not truncate NAS and / or AS keys.
[0076] The network (e.g., the AMF) may transmit an indication to the UE to apply 256- bit security (e.g., 256-bit key size and 256-bit algorithms) for NAS security and / or for AS security, along with the 256-bit security capabilities of the UE.
[0077] The network (e.g., the gNB) may transmit an indication to apply 256-bit security (e.g., 256-bit key size and 256-bit algorithms) to the UE for the AS security (e.g., radio resource control (RRC) and UP security). The UE, upon receiving the 256-bit key size indication, generates and uses 256-bit NAS keys (e.g., KNASintand KNASenc) and AS keys (RRC keys (e.g., KRRCintand KRRCenc)), UP Keys (e.g., KuPintand KuPenc). For example, the UE skips the truncation of the keys.
[0078] Figure 2 illustrates a messaging flow 200 of an authentication procedure for a UE in accordance with aspects of the present disclosure. The messaging flow 200, in some embodiments, depicts how the UE 104 can indicate its 256-bit capabilities to the network, which enables the network to determine and / or select the key size (e.g., 256-bit key size) to be applied by the UE 104 during an authentication procedure or security establishment.
[0079] In step 1, when capable of supporting 256-bit security, the UE 104 indicates the corresponding UE 256-bit security capabilities to the network in a NAS message / Nl transport (e.g., Registration Request / Mobility Registration update / Periodic Registration update / any initial NAS message / protocol data unit (PDU) session establishment / modification request message, and so on) along with a UE identifier (subscription concealed identifier (SUCI) or 5G globally unique temporary UE identity (5G-GUTI)).
[0080] As described herein, the UE 256-bit security capabilities may include (1) the UE 104 supporting a 256-bit key size (e.g., 256 bit permanent key, 256 bits key derivation function, such as HMAC-SHA-256), (2) the UE 104 supporting 256-bit cryptographicalgorithms (e.g., 256-bit SNOW 3G based algorithm, 256-bit AES based algorithm, 256-bit ZUC based algorithm, and so on).
[0081] For example, a UE supported ciphering algorithms list can be part of an Encryption Algorithms information element (IE) in a UE Security Capabilities IE and include: NEAO (Null ciphering algorithm), 128-NEA1 (128-bit SNOW 3G based algorithm), 128-NEA2 (128-bit AES based algorithm), 128-NEA3 (128-bit ZUC based algorithm), 256-NEA1 / 4 (256-bit SNOW 3G based algorithm), 256-NEA2 / 5 (256-bit AES based algorithm), 256-NEA3 / 6 (256-bit ZUC based algorithm), and so on.
[0082] As another example, a UE supported integrity protection algorithms list can be part of an Integrity Algorithms IE in a UE Security Capabilities IE and include: NIAO (Null integrity protection algorithm), 128-NIA1 (128-bit SNOW 3G based algorithm), 128-NIA2 (128-bit AES based algorithm), 128-NIA3 (128-bit ZUC based algorithm), 256-NIA1 / 4 (256-bit SNOW 3G based algorithm), 256-NIA2 / 5 (256-bit AES based algorithm), 256- NIA3 / 6 (256-bit ZUC based algorithm), and so on.
[0083] In step 2, a security anchor function (SEAF) 210 may initiate an authentication with the UE 104 during any procedure establishing a signaling connection with the UE 104, according to the SEAF's policy. The UE 104 may use SUCI or 5G-GUTI, as well as its UE 256-bit security capabilities, in the Registration Request.
[0084] The SEAF 210 may invoke a Nausf_UEAuthentication service by sending a Nausf UEAuthentication Authenticate Request message to an Authentication Server Function (AUSF) 220 whenever the SEAF 210 wishes to initiate an authentication. The Nausf UEAuthentication Authenticate Request message may contain the UE 256-bit security capabilities, the serving network name and either: SUCI, as defined in a current specification, or SUPI, as defined in TS 23.501. The SEAF 210 may include the SUPI in the Nausf UEAuthentication Authenticate Request message in case the SEAF 210 has a valid 5G-GUTI and re-authenticates the UE 104. Otherwise, the SUCI is included in the Nausf UEAuthentication Authenticate Request.
[0085] In some cases, a local policy for the selection of the authentication method may not be on a per-UE basis, and instead may apply for some or all UEs. Further, theNausf UEAuthentication Authenticate Request may contain a Disaster Roaming service indication, as specified in TS 23.502 clause 4.2.2.2.
[0086] In step 3, upon receiving the Nausf UEAuthentication Authenticate Request message, the AUSF 220 checks that the requesting SEAF 210 in the serving network identified by the 3gpp-Sbi-Originating-Network-Id header specified in TS 29.500 is entitled to use the serving network name in the Nausf UEAuthentication Authenticate Request. For the Disaster Roaming, the AUSF 220 may check the local configuration and, if allowed, the AUSF 220 sends Nudm_UEAuthentication_Get Request to a UDM 230 (or Authentication credential Repository and Processing Function (ARPF) or Subscription Identifier De-concealing Function (SIDF)).
[0087] The Nudm UEAuthentication Get Request sent from the AUSF 220 to the UDM 230 may include the following information (1) SUCI or SUPI; (2) the serving network name; (3) if received from the SEAF 210, (4) a Disaster Roaming service indication, and (5) the UE 256-bit security capabilities (when received in step 2).
[0088] In step 4a, upon reception of the Nudm UEAuthentication Get Request, the UDM 230 invokes SIDF when a SUCI is received. The SIDF may de-conceal SUCI to gain SUPI before the UDM 230 can process the request.
[0089] In step 4b, based on SUPI, the UDM 230 (or ARPF) chooses or selects the authentication method. The Nudm UEAuthentication Get Response, in reply to the Nudm UEAuthentication Get Request, and the Nausf UEAuthentication Authenticate Response message, in reply to the Nausf UEAuthentication Authenticate Request message, are described herein as part of the authentication procedures. For the Disaster Roaming, the UDM 230 may check the local configuration and, if allowed, the UDM 230 proceeds with the chosen authentication method.
[0090] The UDM 230 manages the UE’s permanent key ‘K’ size information (e.g., 128-bits or 256-bits) as part of the UE subscription data. Based on the received UE 256-bit security capabilities, the UDM 230 determines the type of key size to be used by considering the subscription data (e.g., operator configured key size security policy) associated with the UE 104, as well as the UE’s permanent key size. In some cases, thesubscription data may include a permanent Key ‘K’ / key size security policy set as ‘512’; ‘256 bit Key’ and / or ‘128 bit Key’ in a prioritized list.
[0091] The UDM 230 may determine the key sizes based on the following:
[0092] When the UE 104 supports 256-bit security capabilities and the subscription data (e.g., operator configured key size security policy as ‘256-bit key size required’ and the UE’s permanent key size is 256-bits) allows 256-bits key size, the UDM 230 determines to enforce a 256-bit key size;
[0093] When the UE 104 supports 256-bit security capabilities and the subscription data (e.g., operator configured key size security policy as ‘256-bit key size required’ and the UE’s permanent key size is 128-bits) allows 256-bits key size, the UDM determines to enforce a 256-bits key size;
[0094] When the UE 104 supports 256-bit security capabilities and the subscription data (e.g., operator configured key size security policy as ‘256-bit key size required’ and the UE’s permanent key size is 128-bits) allows only 128-bits key size, the UDM 230 determines not to enforce a 256-bits key size (e.g., the UDM 230 only allows a 128-bit key size); and / or
[0095] When the UE 256-bit security capabilities are not received in the UDM 230 (e.g., not provided by the UE 104) and the subscription data (e.g., the operator configured key size security policy as ‘256-bit key size required’ and the UE’s permanent key size is 128-bits) allows only 128-bits key size, the UDM 230 determines not to enforce a 256-bits key size (e.g., the UDM 230 only allows a 128-bit key size).
[0096] Following the determination of the key size by the UDM 230, the UDM 130 may indicate the selected key size to other network functions and / or the UE during a primary authentication procedure, as described herein.
[0097] Of course, while the embodiments described herein refer to 256-bit algorithms, such systems and methods may be extended to cover increased bit sizes, such as 512-bit, and so on.
[0098] Figure 3 illustrates a messaging flow 300 of an authentication procedure for EAP-AKA’ in accordance with aspects of the present disclosure. The messaging flow 300, in some embodiments, depicts how the UDM 230 enforces (e.g., indicates) to the network and the UE 104 to use the selected 256-bit security (e.g., 256-bit key size) during a primary authentication procedure, such as EAP-AKA’.
[0099] In step 1, the UDM 230 (e.g., ARPF) generates an authentication vector (AV) with an Authentication Management Field (AMF) separation bit = 1 as defined in TS 33.102. The UDM / ARPF computes CK' and IK' as per the normative Annex A and replaced CK and IK by CK' and IK'.
[0100] In step 2, the UDM 230 sends the transformed authentication vector AV (RAND, AUTN, XRES, CK', IK'), and a “Use 256-bit key size” indication to the AUSF 220 from which it received the Nudm UEAuthentication Get Request together with an indication that the AV is to be used for EAP-AKA' using a Nudm UEAuthentication Get Response message.
[0101] In some cases, the exchange of a Nudm UEAuthentication Get Request message and an Nudm_UEAuthentication_Get Response message between the AUSF 230 and the UDM 230 or ARPF may be the same as for trusted access using EAP-AKA' described in TS 33.402, sub-clause 6.2, step 10, except for the input parameter to the key derivation, which is the value of <network name>. The "network name" is a concept from RFC 5448 and is carried in the AT KDF INPUT attribute in EAP-AKA'. The value of <network name> parameter is not defined in RFC 5448, but rather in 3GPP specifications. For EPS, it is defined as "access network identity" in TS 24.302, and for 5G, it is defined as "serving network name" in TS 33.501.
[0102] In cases when the SUCI was included in the Nudm UEAuthentication Get Request, the UDM 230 may include the SUPI in the Nudm UEAuthentication Get Response. If a subscriber has an AKMA subscription, the UDM 230 may include the AKMA indication and Routing indicator in the Nudm UEAuthentication Get Response. Further, as described with respect to Figure 2, when the UDM 230 determines to enforce 256-bit security for the UE 104 (e.g., to apply 256-bit key size for the NAS and ASsecurity), the UDM 230 includes a “Use 256-bit key size” indication in the Nudm UEAuthentication Get Response.
[0103] In step 3, The AUSF 220 sends the EAP-Request / AKA'-Challenge message to the SEAF 210 in a Nausf UEAuthentication Authenticate Response message along with “Use 256-bit key size indication” (if received).
[0104] In step 4, the SEAF 210 transparently forwards the EAP-Request / AKA'- Challenge message to the UE 104 in a NAS message Authentication Request message. Mobile Equipment (ME) forwards the RAND and AUTN received in EAP-Request / AKA'- Challenge message to the USIM of the UE 104. The message may include the ngKSI and a new ABBA parameter containing a “Use 256-bit key size” indication and / or a “Use 256-bit security” indication. The SEAF 210 includes the ngKSI and new ABBA parameter indicating “Use 256-bit key size” indication and / or “Use 256-bit security indication” in all EAP- Authentication request messages. The ngKSI may be used by the UE 104 and AMF to identify the partial native security context that is created when the authentication is successful. The SEAF 210 shall set the ABBA parameter as defined in Table 1. During an EAP authentication, the value of the ngKSI and the ABBA parameter sent by the SEAF 210 to the UE 104 is not changed.
[0105] The ABBA parameter is provided to the UE 104 from the SEAF 210 and is used as an input parameter for KAMF derivation. To support a flexible set of security features, the ABBA parameter is defined when security features change. To ensure forward compatibility, the ABBA parameter is a variable length parameter. The SEAF 210 sets the ABBA parameter to 0x0000. The UE 104 uses the ABBA parameter provided by the SEAF 210 in the calculation of KAMF. The SEAF 210, based on operator policy or if the SEAF 210 receives the “Use 256-bit key size” indication from the AUSF 220 in the any of the authentication response messages described here (e.g., step 3), sets the ABBA parameter as “Use 256-bit key size” indication and / or “Use 256-bit security indication.”
[0106] The following values may be defined for ABBA parameter:Table 1
[0107] A new ABBA parameter indicating “Use 256-bit key size” indication and / or “Use 256-bit security” indication is provided to the UE 104 from SEAF 210 and is used as an input parameter for KAMF derivation. In some cases, the SEAF 210 may understand that the authentication method used is an EAP method by evaluating the type of authentication method based on the Nausf UEAuthentication Authenticate Response message. In other cases, the ME may send to the USIM the “Use 256-bit key size” indication to enable use of a 256-bit key derivation function (e.g., HMAC-SHA-256) for key generation.
[0108] In step 5a, after receiving the RAND and AUTN, the USIM verifies the freshness of the AV by checking whether the AUTN can be accepted as described in TS 33.102. If so, the USIM computes a response RES. The USIM returns RES, CK, IK to the ME. When the USIM computes a Kc (e.g., GPRS Kc) from CK and IK using conversion function c3 as described in TS 33.102, and sends it to the ME, the ME ignores such GPRS Kc and does not store the GPRS Kc on USIM or in ME. The ME derives CK' and IK' according to Annex A.3 TS 33.501. If the verification of the AUTN fails on the USIM, then the USIM and ME proceed as described in TS 33.501 sub-clause 6.1.3. 3.
[0109] In step 5b, the UE 104 stores the “Use 256-bit key size” indication, determines to not truncate any NAS and AS keys further, and determines to use the 256-bit keys for NAS Security (KNASint and KNASenc) and AS Security (RRC keys (KRRCintand KRRCenc), UP Keys (KuPint and KuPenc)), and thus skips truncation of the key. In some cases, when the ME sends to the USIM “Use 256-bit key size” indication, the USIM determines to use a 256-bit key derivation function (e.g., HMAC-SHA-256) for key generation, such as CK’, IK’ from CK, IK.
[0110] In step 6, the UE 104 sends the EAP-Response / AKA'-Challenge message to the SEAF 210 in a NAS message Auth-Resp message.
[0111] In step 7, the SEAF 210 transparently forwards the EAP-Response / AKA'- Challenge message to the AUSF 220 in a Nausf_UEAuthentication_Authenticate Request message.
[0112] In step 8, the AUSF 220 verifies the message by comparing the XRES and RES, and when the AUSF 220 has successfully verified the message, it continues, otherwise it returns an error to the SEAF 210. The AUSF 230 may inform the UDM 230 about the authentication result (for linking authentication confirmation).
[0113] In step 9, the AUSF 220 and the UE 104 may exchange EAP-Request / AKA- Notifi cation and EAP-Response / AKA' -Notification messages via the SEAF 210. The SEAF 210 transparently forward these messages. In some cases, EAP Notifications as described in RFC 3748 and EAP- AKA Notifications as described in RFC 4187 can be used at any time in the EAP- AKA exchange. These notifications can be used for protected result indications or when the EAP server detects an error in the received EAP- AKA response.
[0114] In step 10, the AUSF 220 derives EMSK from CK’ and IK’ as described in RFC 5448 and Annex F. The AUSF 220 uses the most significant 256 bits of EMSK as the KAUSF and then calculates KSEAF from KAUSF as described in TS 33.501 clause A.6. The AUSF 220 sends an EAP Success message to the SEAF 210 inside aNausf UEAuthentication Authenticate Response, which forwards it transparently to the UE 104. The Nausf_UEAuthentication_Authenticate Response message contains the KSEAF. When the AUSF220 received a SUCI from the SEAF 210 when the authentication was initiated, then the AUSF 220 includes the SUPI in the Nausf_UEAuthentication_Authenticate Response message. The AUSF 220 stores the KAUSF based on the home network operator's policy.
[0115] In some cases, for lawful interception, the AUSF 220 sending SUPI to the SEAF 210 may be necessary but not sufficient. By including the SUPI as an input parameter to the key derivation of KAMF from KSEAF, additional assurance on the correctness of SUPI is achieved by the serving network from both the home network side and the UE side.
[0116] In step 11, the SEAF 210 sends the EAP Success message to the UE 104 in the N1 message. This message may include the ngKSI and the ABBA parameter indicating the “Use 256-bit key size” indication and / or the Use 256-bit security” indication. The SEAF 210 sets the ABBA parameter as defined in step 4. For example, based on operator policy or upon receiving a “Use 256-bit key size” indication from the AUSF 220 in the any of the authentication response messages described herein (e.g., in step 3), the SEAF 210 sets the ABBA parameter as “Use 256-bit key size” indication and / or “Use 256-bit security” indication.
[0117] In some cases, the messaging of step 11 may be a NAS Security Mode Command or Authentication Result. Further, the ABBA parameter may be included to enable the bidding down protection of security features.
[0118] Further, in some cases, the key received in theNausf UEAuthentication Authenticate Response message may become the anchor key, KSEAF in the sense of the key hierarchy. The SEAF 210 may derive the KAMF from the KSEAF, the ABBA parameter indicating the “Use 256-bit key size” indication and / or “Use 256-bit security” indication and the SUPI and send it to the AMF. On receiving the EAP- Success message, the UE 104 derives EMSK from CK’ and IK’ as described in RFC 5448 (e.g., similar to the network). The ME uses the most significant 256 bits of the EMSK as the KAUSF and then calculates KSEAF in the same way as the AUSF 220. The UE 104 derives the KAMF from the KSEAF, the ABBA parameter indicating the “Use 256-bit key size” and / or “Use 256-bit security” indication and the SUPI,
[0119] In some cases, the UE 104 may create the temporary security context as described in step 11 after receiving the EAP message that allows EMSK to be calculated. The UE 104 turns this temporary security context into a partial security context when it receives the EAP Success. The UE 104 removes the temporary security context if the EAP authentication fails.
[0120] In some cases, the EAP-Response / AKA'-Challenge message is not successfully verified, the subsequent AUSF behavior is determined according to the home network's policy. Further, when the AUSF 220 and SEAF 210 determine that the authentication wassuccessful, the SEAF 210 may provide the ngKSI and the KAMF to the AMF. Also, the selection of key size may be applicable to any authentication procedure described herein (e.g., any EAP based authentication procedure).
[0121] Figure 4 illustrates a messaging flow 400 of an authentication procedure for 5G- AKA’ in accordance with aspects of the present disclosure. The messaging flow 400, in some embodiments, depicts how the UDM 230 enforces or indicates to the network and the UE 104 to use the selected 256-bit security (e.g., 256-bit key size) during the 5G AKA primary authentication procedure.
[0122] In step 1, for each Nudm Authenticate Get Request, the UDM 230 (ARPF) creates a 5G HE AV. The UDM / ARPF generates an AV with the Authentication Management Field (AMF) separation bit set to "1" as defined in TS 33.102. The UDM 230 derives KAUSF and calculate XRES* as in TS 33.501. Finally, the UDM 230 creates a 5G HE AV from RAND, AUTN, XRES*, and KAUSF.
[0123] In step 2, the UDM 230 returns the 5G HE AV to the AUSF 220 together with an indication that the 5G HE AV is to be used for 5G AKA and “Use 256-bit key size” indication in a Nudm UEAuthentication Get Response. When the SUCI was included in the Nudm UEAuthentication Get Request, the UDM 230 includes the SUPI in the Nudm UEAuthentication Get Response after deconcealment of SUCI by SIDF. When a subscriber has an AKMA subscription, the UDM 230 includes the AKMA indication and Routing indicator in the Nudm UEAuthentication Get Response. Further, as described herein, when the UDM 230 determines to enforce 256-bit security for the UE 104 (e.g., to apply 256-bit key size for the NAS and AS security), the UDM 230 includes the “Use 256- bit key size” indication in the Nudm UEAuthentication Get Response.
[0124] In step 3, the AUSF 220 stores the XRES* temporarily together with the received SUCI or SUPI.
[0125] In step 4, the AUSF 220 generates the 5G AV from the 5G HE AV received from the UDM 230 (ARPF) by computing the HXRES* from XRES* (according to Annex A.5 TS 33.501) and KSEAF from KAUSF (according to Annex A.6 TS 33.501), and replacing the XRES* with the HXRES* and KAUSF with KSEAF in the 5G HE AV.
[0126] In step 5, the AUSF 220 removes the KSEAF and return the 5G SE AV (RAND, AUTN, HXRES*) and the “Use 256-bit key size” indication to the SEAF 210 in a Nausf UEAuthentication UEAuthenti cation Response.
[0127] In step 6, the SEAF 210 sends RAND, AUTN to the UE 104 in a NAS message Authentication Request. The message may include the ngKSI used by the UE 104 and AMF to identify the KAMF and the partial native security context that is created if the authentication is successful. The message may also include the ABBA parameter containing the “Use 256-bit key size” and / or “Use 256-bit security” indication. The SEAF 210 sets the ABBA parameter as shown in Table 2. The ME forwards the RAND and AUTN received in the NAS message Authentication Request to the USIM.
[0128] The SEAF 210 provides the ABBA parameter to the UE 104 and is used as an input parameter for KAMF derivation. To support flexible set of security features ABBA parameter is defined when security features change. To ensure forward compatibility, the ABBA parameter is a variable length parameter. The SEAF 210 sets the ABBA parameter to 0x0000. The UE 104 uses the ABBA parameter provided by the SEAF 210 in the calculation of KAMF.
[0129] Based on operator policy or if the SEAF 210 receives a “Use 256-bit key size” indication from the AUSF 220 in the any of the authentication response message described here (e.g., in step 3), the SEAF 210 sets the ABBA parameter as “Use 256-bit key size” and / or “Use 256-bit security” indication.
[0130] The following values may be defined for ABBA parameter:Table 2
[0131] In some cases, the new ABBA parameter indicating “Use 256-bit key size” indication and / or “Use 256-bit security” indication is provided to the UE 104 from the SEAF 210 and is used as an input parameter for KAMF derivation. The ABBA parameter may be included to enable the bidding down protection of security features.
[0132] In step 7a, upon receipt of the RAND and AUTN, the USIM verifies the freshness of the received values by checking whether the AUTN can be accepted as described in TS 33.102. If so, the USIM computes a response RES. The USIM returns RES, CK, IK to the ME. When the USIM computes a Kc (e.g., GPRS Kc) from CK and IK using conversion function c3 as described in TS 33.102, and sends it to the ME, the ME ignores the GPRS Kc and does not store the GPRS Kc on USIM or in ME. The ME then computes RES* from RES according to Annex A.4 TS 33.501. The ME calculates KAUSF from CK||IK according to clause A.2 TS 33.501. The ME calculates KSEAF from KAUSF according to clause A.6 TS 33.501. An ME accessing 5G checks during authentication that the "separation bit" in the AMF field of AUTN is set to 1. The "separation bit" is bit 0 of the AMF field of AUTN.
[0133] In some cases, the separation bit in the AMF field of AUTN cannot be used anymore for operator specific purposes as described by TS 33.102, Annex F. Further, the UE 104 (via the USIM) may determine to use K with 256 bits for key generation (e.g., CK, IK and further keys K aus f).
[0134] In step 7b, the UE 104 stores the “Use 256-bit key size” indication. The UE 104 (ME) derives Kamf from Kseaf, the ABBA parameter containing the Use 256 bit key size indication, and SUPI. Further, the UE 104(ME) determines to not truncate any NAS and AS keys further and determines to use the 256-bit keys for NAS Security (KXA IIH and KNASenc) and AS Security (RRC keys (KRRCintand KRRCenc), and UP Keys (KuPimand KuPenc)), skipping truncation of the key.
[0135] In some cases, when the ME sends to the USIM the “Use 256-bit key size” indication, the USIM determines to use the 256-bit key derivation function (e.g., HMAC- SHA-256) for key generation, such as Kausf from CK, IK.
[0136] In step 8, the UE 104returns RES* to the SEAF 210 in a NAS message Authentication Response.
[0137] In step 9, the SEAF 210 computes HRES* from RES* according to Annex A.5 TS 33.501, and the SEAF 210 compares HRES* and HXRES*. If they coincide, the SEAF 210 considers the authentication successful from the serving network point of view. If not, the SEAF 210 proceeds as described in sub-clause 6.1.3.2.2 TS 33.501. If the UE 104 is not reached, and the RES* is never received by the SEAF 210, the SEAF 210 considers authentication as failed, and indicates a failure to the AUSF 220.
[0138] In step 10, the SEAF 210 sends RES*, as received from the UE 104, in a Nausf_UEAuthentication_Authenticate Request message to the AUSF 220.
[0139] In step 11, when the AUSF 220 receives as authentication confirmation the Nausf_UEAuthentication_Authenticate Request message including a RES*, the AUSF 220 may verify whether the 5G AV has expired. If the 5G AV has expired, the AUSF 220 may consider the authentication as unsuccessful from the home network point of view. Upon successful authentication, the AUSF 220 stores the KAUSF based on the home network operator's policy according to clause 6.1.1.1. The AUSF 220 compares the received RES* with the stored XRES*. If the RES* and XRES* are equal, the AUSF 220 considers the authentication as successful from the home network point of view. The AUSF 220 informs the UDM 230 about the authentication result (for linking with the authentication confirmation). In some cases, the AUSF 220 may temporarily store the KAUSF received in step 2 until the RES* verification is done successfully (e.g., in step 11).
[0140] In step 12, the AUSF 220 indicates to the SEAF 210 in theNausf UEAuthentication Authenticate Response whether the authentication was successful or not from the home network point of view. If the authentication was successful, the KSEAF is sent to the SEAF 210 in the Nausf_UEAuthentication_Authenticate Response. When the AUSF 220 received a SUCI from the SEAF 210 in the authentication request (see sub-clause 6.1.2 of the present document), and if the authentication was successful, then the AUSF 220 includes the SUPI in the Nausf UEAuthentication Authenticate Response message.
[0141] In step 13, when the authentication was successful, the key KSEAF received in the Nausf UEAuthentication Authenticate Response message becomes the anchor key within the key hierarchy. The SEAF 210 may derive the KAMF from the KSEAF, the ABBA parameter indicating the “Use 256-bit key size” indication and / or “Use 256-bit security” indication and the SUPI (see step 6). For example, when based on operator policy or upon receipt of the “Use 256-bit key size” indication from the AUSF 220 in an authentication response message described herein (e.g., in step 5), the SEAF 210 sets the ABBA parameter as “Use 256-bit key size” indication and / or “Use 256-bit security” indication.
[0142] In some cases, the SEAF 210 provides the ngKSI and the KAMF to the AMF. If the AUSF 220 indicates that the authentication was successful from the home network point of view, then the AMF shall initiate the NAS security mode command procedure, as described herein, with the UE, to take the newly generated partial native 5G NAS security context into use. Upon receiving the valid NAS Security Mode Command message from the AMF, the UE 104 considers the performed primary authentication as successful.
[0143] In some cases, if a SUCI was used for the authentication, the SEAF 210 may only provide ngKSI and KA F to the AMF after it has received theNausf UEAuthentication Authenticate Response message containing KSEAF and SUPI, and thus no communication services are provided to the UE 104 until the SUPI is known to the serving network.
[0144] Figure 5 illustrates a messaging flow 500 of a NAS security mode command procedure in accordance with aspects of the present disclosure. The messaging flow 500, in some embodiments, depicts how the AMF determines and applies 256-bit cryptographic algorithm for the NAS protection (e.g., for ciphering and integrity protection) with 256-bit keys (KNASintand KNASenc) based on the capability of the UE 104 to support 256-bit security capabilities.
[0145] For example, a NAS Security Mode Command (SMC), as depicted in Figure 4, can be used to establish a NAS Security context between the UE 104 and an AMF 510. The procedure includes roundtrip messages between the AMF 510 and the UE 104. The AMF 510 sends the NAS Security Mode Command message to the UE 104 and the UE 104replies with the NAS Security Mode Complete message. In some cases, the UE 104 in RRC Connected and a serving network (the AMF 510) may employ some agreed upon algorithms for 128-bit or 256-bit NAS ciphering and NAS integrity protection (to be used between the UE 104 and the AMF 510).
[0146] In some cases, the SMC procedure protects the Registration Request against a man-in-the-middle attack where the attacker modifies the IES containing the UE security capabilities provided by the UE 104 in the Registration Request. For example, when the method completes successfully, the UE 104 is attached to the network knowing that no bidding down attack has happened. In case a bidding down attack was attempted, the verification of the NAS SMC fails and the UE 104 replies with a reject message (e.g., the UE 104 does not attach to the network).
[0147] In step la, when the UE 104 is capable of supporting 256-bit security, the UE 104 indicates the corresponding UE 256-bit security capabilities to the network in any NAS message / Nl transport / initial NAS message (e.g., Registration Request / Mobility Registration update / Periodic Registration update / any initial NAS message / PDU session establishment / modification request message, and so on) along with a UE identifier (SUCI / 5G-GUH). The UE 104 256-bit security capabilities are described herein. Primary authentication may be performed between the UE 104 and the AMF 510 as depicted in Figure 2 or Figure 3. If the primary authentication is successful, the NAS security mode command procedure is initiated by the AMF 510 as follows.
[0148] In step lb, the AMF 510 determines to select and apply a 256-bit cryptographic algorithm (e.g., for NAS integrity and ciphering protection) when it receives UE security capabilities to support 256-bit algorithms and when an operator configuration policy includes 256-bit algorithms in a prioritized list. When the AMF 510 determines to apply 256-bit a cryptographic algorithm for NAS security, the AMF 510, following the NAS integrity and encryption key derivation (KNASintand KNASenc), retains the 256-bit keys of KNASintand KNASenc and skips the NAS key truncation. The AMF 510 activates the NAS integrity protection before sending the NAS Security Mode Command message.
[0149] In some cases, the AMF 510 determines to select and apply 256-bit cryptographic algorithm (e.g., for NAS integrity and ciphering protection) when the UE security capabilities to support 256 algorithms is received via the “Use 256-bit key size” indication from the SEAF 210 (e.g., during a primary authentication procedure, described herein) and if an operator configuration policy includes 256-bit algorithms in the prioritized list.
[0150] The following are example ciphering algorithm identifier values (e.g., for 5GNAS and New Radio):"00002" NEAO Null ciphering algorithm;"OOOh" 128-NEA1 128-bit SNOW 3G based algorithm;"OOIO2" 128-NEA2 128-bit AES based algorithm; and"00112" 128-NEA3 128-bit ZUC based algorithm."OIOO2" 256-NEA1 / 4 256-bit SNOW 3G based algorithm;"OIOI2" 256-NEA2 / 5 256-bit AES based algorithm; and"01 IO2" 256-NEA3 / 6 256-bit ZUC based algorithm.
[0151] The following are example integity algorithm identifier values (e.g., for 5GNAS and New Radio):"OOOO2" NEAO Null Integrity protection algorithm;"OOOh" 128-NIA1 128 -bit SNOW 3G based algorithm;"OOIO2" 128-NIA2 128 -bit AES based algorithm; and"00112" 128-NIA3 128 -bit ZUC based algorithm."OIOO2" 256-NIA1 / 4 256 -bit SNOW 3G based algorithm;"OIOI2" 256-NIA2 / 5 256 -bit AES based algorithm; and"OI IO2" 256-NIA3 / 6 256 -bit ZUC based algorithm.
[0152] In step 1c, the AMF 510 sends the NAS Security Mode Command message to the UE 104. The NAS Security Mode Command may contain: the replayed UE security capabilities with 256-bit cryptographic algorithms support indication / information, theselected NAS algorithms (e.g., 256-bit integrity and 256-bit ciphering algorithm), and the ngKSI for identifying the KAMF. The NAS Security Mode Command message may contain: K AMF change flag (carried in the additional 5G security parameters IE specified in TS 24.501) to indicate a new KAMF is calculated, a flag requesting the complete initial NAS message (see subclause 6.4.6), an ABBA parameter indicating “Use 256-bit key size” indication and / or “Use 256-bit security” indication. When there is horizontal derivation of KA F during a mobility registration update or during multiple registration in same PLMN, the K_AMF_change_flag may be included in the NAS Security Mode Command message as described in clause 6.9.3 TS 33.501.
[0153] In some cases, when the AMF 510 determines to apply a 256-bit cryptographic algorithm for NAS protection, the message may be integrity protected (but not ciphered) with 256-bit NAS integrity key (KNASint) based on the KAMF indicated by the ngKSI in the NAS Security Mode Command message. The “Use 256-bit key size” indication and / or “Use 256-bit security” indication may be sent to the UE 104 as part of the ABBA parameter or as individual IE.
[0154] In some cases, such as when the network supports interworking using the N26 interface between a Mobility Management Entity (MME), in 4G / LTE, and the AMF 510, the AMF 510 includes the selected EPS NAS algorithms (defined in Annex B of TS 33.401) to be used after mobility to EPS in the NAS Security Mode Command message. The UE 510 may store the algorithms for use after mobility to EPS using the N26 interface between the MME and the AMF 510. The AMF 510 stores the selected EPS NAS algorithms in the UE security context.
[0155] Further, when the AMF 510 change happens either due to N2-handover or idle mode mobility, the selected EPS NAS algorithms are included in the 5G UE security context and provided to a target AMF as part of the 5G UE security context.
[0156] In step Id, upon determining to apply a 256-bit cryptographic algorithm for NAS protection, the AMF 510 activates NAS uplink deciphering using the 256-bit KNASenc after sending the NAS Security Mode Command message.
[0157] In step 2a, the UE 104 determines to derive and retain 256-bit keys (for KNASint and KNASenc), and thus skips truncation of NAS security keys based on the received selected NAS algorithms (e.g., indicating 256-bit integrity and 256-bit ciphering algorithm) or based on the received “Use 256-bit key size” indication and / or “Use 256-bit security” indication from the AMF 510. The UE 104 verifies the NAS Security Mode Command message.
[0158] For example, the UE 104 checks that the UE security capabilities, having 256- bits cryptographic algorithms support indication / information (e.g., when sent in step 1 by the UE 104) sent by the AMF 510 match the capabilities stored in the UE 104 to ensure that they were not modified by an attacker. The UE 104 verifies the integrity protection using the indicated (e.g., 256-bit) NAS integrity algorithm and the NAS integrity key based on the KAMF indicated by the ngKSI.
[0159] When the NAS Security Mode Command message includes a K_AMF_change_flag, the UE 104 derives a new KAMF as described in Annex A.13 TS33.501 and sets the NAS COUNTS to zero. When the verification of the integrity of the NAS Security Mode Command message is successful, the UE 104 starts NAS integrity protection and ciphering / deciphering with the security context indicated by the ngKSI.
[0160] In step 2b, the UE 104 sends the NAS Security Mode Complete message to the AMF 510, which is now ciphered and integrity protected (e.g., with the 256-bit keys for KNASint and KNASenc if 256-bit NAS integrity and ciphering algorithms were selected and used). The NAS Security Mode Complete message may include PEI when the AMF 510 requested it in the NAS Security Mode Command message. The AMF 510 may set the NAS COUNTs to zero if horizontal derivation of KA F is performed. The UE 104 may include the complete initial NAS message.
[0161] When the verification of the NAS Security Mode Command message is not successful in the UE 104, the UE 104 replies with a NAS Security Mode Reject message (see TS 24.501). The NAS Security Mode Reject message and all subsequent NAS messages are protected with the previous, if any, 5GNAS security context (e.g., the 5G NAS security context used prior to the failed NAS Security Mode Command message). Ifno 5GNAS security context existed prior to the NAS Security Mode Command message, the NAS Security Mode Reject message may remain unprotected.
[0162] In some cases, the AMF 510 de-ciphers and checks the integrity protection on the NAS Security Mode Complete message using the key and algorithm (e.g., with the 256- bit keys for KNASintand KNASenc if 256-bit NAS integrity and ciphering algorithms were selected and used) indicated in the NAS Security Mode Command message. At the AMF 510, NAS downlink ciphering, with this security context, starts after receiving the NAS Security Mode Complete message.
[0163] In step le, the AMF 510 activates NAS downlink ciphering, such as by using the 256-bit KNASCIIC when 256-bit NAS ciphering algorithms was selected. In some cases, the uplink NAS COUNT may wrap around by sending the NAS Security Mode Reject message and the UE 104 releases the NAS connection instead of sending the NAS Security Mode Reject message.
[0164] Further, when the AMF 510 successfully validates the NAS SMC Complete message, the AMF 510 has successfully confirmed the SUPI received from the home network and the SUPI used by the UE match. However, an integrity check failure of the NAS SMC Complete message at the AMF 510 may be caused by other factors than a mismatch of the SUPIs or bidding down of 256-bit NAS ciphering / integrity algorithms to 128-bit NAS ciphering / integrity algorithms.
[0165] Figure 6 illustrates a messaging flow 600 of an AS security mode command procedure in accordance with aspects of the present disclosure. The messaging flow 600, in some embodiments, depicts how a gNB (or ng-eNB) 610 determines and applies 256 bit cryptographic algorithm for AS protection (e.g., for RRC and User Plane ciphering and integrity protection) with 256-bit keys (e.g., RRC security keys - KRRCintand KRRCenc and / or UP Security Keys - KuPmtand KuPenc) based on the capability of the UE 104 to support 256- bit security capabilities, as described herein.
[0166] The AS SMC procedure, depicted in Figure 6, is for RRC and UP security algorithms negotiation and RRC security activation for the gNB / ng-eNB 610 and the UE 104. The AS SMC procedure can be triggered to establish a secure RRC signaling-onlyconnection during UE registration or PDU session establishment as specified in TS 38.413 and TS 23.502. The activation of UP security is described in clause 6.6.2 TS 33.501. The AS SMC procedure may include roundtrip messages between the gNB / ng-eNB 610 and the UE 104. The gNB / ng-eNB 610 sends the AS security mode command to the UE 104 and the UE 104 replies with the AS security mode complete message.
[0167] In some cases, when the AMF 510 receives UE security capabilities that support 256 algorithms, and when the AMF 510 determines to select and apply 256-bit cryptographic algorithm (e.g., for NAS integrity and ciphering protection), following the successful reception of NAS security mode complete message, the AMF 510 initiates an NGAP procedure INITIAL CONTEXT SETUP, where the AMF 510 sends the initial context setup request message to the gNB 610 that includes the UE security capabilities with support of 256 algorithms (e.g., with the list of algorithm identities / identifiers specific to 256 bit cryptographic algorithms for ciphering and integrity protection, as described herein.
[0168] In step la, the gNB 610 determines to select and apply 256-bit cryptographic algorithms (e.g., for AS security, such as RRC integrity and ciphering protection and UP integrity and ciphering protection) upon receipt of UE security capabilities to support 256- bit algorithms from the AMF 510 (in the initial context setup request) and if an operator configuration policy includes 256-bit algorithms in a prioritized list. If the gNB 610 determines to apply a 256-bit cryptographic algorithm for AS (RRC and UP) security and following the RRC integrity and encryption key derivation (KRRCint and KRRCenc) and UP integrity and encryption key derivation (KuPint and KuPenc), the gNB 610 retains the 256-bit keys of KRRCint and KRRCenc and skips the RRC key truncation. Similarly, the gNB 610 retains the 256-bit keys of KuPint and KuPenc and skips the UP key truncation. The gNB 610 activates the RRC integrity protection before sending the AS Security Mode Command message.
[0169] The following are example ciphering algorithm identifier values (e.g., for 5G NAS and New Radio):"OOOO2" NEA0 Null ciphering algorithm;"00012" 128-NEA1 128 -bit SNOW 3G based algorithm;"OOIO2" 128-NEA2 128 -bit AES based algorithm; and"00112" 128-NEA3 128 -bit ZUC based algorithm."OIOO2" 256-NEA1 / 4 256 -bit SNOW 3G based algorithm;"OlOh" 256-NEA2 / 5 256 -bit AES based algorithm; and"OI IO2" 256-NEA3 / 6 256 -bit ZUC based algorithm.
[0170] The following are exai nple integity algorithm identifier values (e.g., for 5GNAS and New Radio):"OOOO2" NEA0 Null Integrity protection algorithm;"OOOI2" 128-NIA1 128 -bit SNOW 3G based algorithm;"OOIO2" 128-NIA2 128 -bit AES based algorithm; and"00112" 128-NIA3 128 -bit ZUC based algorithm."OIOO2" 256-NIA1 / 4 256 -bit SNOW 3G based algorithm;"OlOh" 256-NIA2 / 5 256 -bit AES based algorithm; and"OI IO2" 256-NIA3 / 6 256 -bit ZUC based algorithm.
[0171] In step lb, the AS security mode command message sent from the gNB / ng-eNB610 to the UE 104 may contain the selected 256-bit RRC and UP encryption and integrity algorithms and may contain the “Use 256-bit key size” indication and / or “Use 256-bit security” indication. This AS security mode command message may be integrity protected with a 256-bit RRC integrity key based on the current KgNB and use the selected 256-bit cryptographic algorithm for integrity protection (if the gNB 610 selects and uses the 256-bit integrity algorithm).
[0172] In step 2a, the UE 104 determines to derive and retain 256-bit keys (for AS keys, such as RRC keys: KRRCint , KRRCenc and UP Keys: KuPint and KuPenc) and skips the RRC and UP key truncation based on the received selected RRC and UP algorithms (e.g., indicating 256-bit integrity and 256-bit ciphering algorithms) or based on the received “Use 256-bit key size” indication and / or “Use 256-bit security” indication from the gNB 610. The UE 104 verifies the AS Security Mode Command message, such as by verifying theintegrity protection using the indicated (e.g., 256-bit) RRC integrity algorithm and the RRC integrity key.
[0173] In step 2b, the AS security mode complete message from the UE 104 to the gNB / ng-eNB 610 may be integrity protected with the selected (e.g., 256 bits) RRC algorithm indicated in the AS security mode command message and selected (e.g., 256 bits) RRC integrity key based on the current KgNB.
[0174] In step 1c, 256-bit RRC downlink ciphering (encryption) at the gNB / ng-eNB 610 starts by sending the AS security mode command message. 256-bit RRC uplink deciphering (decryption) at the gNB / ng-eNB 610 starts after receiving and successfully verifying the AS security mode complete message.
[0175] In step 2c, 256-bit RRC uplink ciphering (encryption) at the UE 104 starts after sending the AS security mode complete message. 256-bit RRC downlink deciphering (decryption) at the UE 104 starts after receiving and successfully verifying the AS security mode command message. If any control of the AS security mode command is not successful in the UE 104, the UE 104 may reply with an unprotected security mode failure message (see TS 38.331).
[0176] In some cases, ciphering and integrity protection of UP downlink and uplink (e.g., with 256 bits UP Keys: KuPintand KuPenc and selected 256 bits integrity and ciphering algorithms) at the UE 104 and the gNB / ng-eNB 610, starts as defined by clause 6.6.2 TS 33.501. Further, the AS SMC procedure is used only during an initial context setup between the UE 104 and the gNB / ng-eNB 610, such as when activating an initial KgNB at RRC IDLE to RRC CONNECTED state transition.
[0177] In some cases, the derivation of a KgNB at RRC IDLE to RRC CONNECTED state ensures that the AS SMC procedure establishes a fresh KgNB, and the PDCP COUNTs can be reset.
[0178] Figure 7 illustrates an example of a UE 700 in accordance with aspects of the present disclosure. The UE 700 may include a processor 702, a memory 704, a controller 706, and a transceiver 708. The processor 702, the memory 704, the controller 706, or the transceiver 708, or various combinations thereof or various components thereof may beexamples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0179] The processor 702, the memory 704, the controller 706, or the transceiver 708, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0180] The processor 702 may include an intelligent hardware device (e.g., a general- purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 702 may be configured to operate the memory 704. In some other implementations, the memory 704 may be integrated into the processor 702. The processor 702 may be configured to execute computer-readable instructions stored in the memory 704 to cause the UE 700 to perform various functions of the present disclosure.
[0181] The memory 704 may include volatile or non-volatile memory. The memory 704 may store computer-readable, computer-executable code including instructions when executed by the processor 702 cause the UE 700 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 704 or another type of memory. Computer-readable media includes both non- transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0182] In some implementations, the processor 702 and the memory 704 coupled with the processor 702 may be configured to cause the UE 700 to perform one or more of the functions described herein (e.g., executing, by the processor 702, instructions stored in the memory 704). For example, the processor 702 may support wireless communication at the UE 700 in accordance with examples as disclosed herein. The UE 700 may be configuredto support a means for transmitting, to a network entity, an indication of a 256-bit security capability for the UE, and receiving, from the network entity, a response that confirms the UE is to apply the 256-bit security capability when performing an authentication procedure with the network entity.
[0183] The controller 706 may manage input and output signals for the UE 700. The controller 706 may also manage peripherals not integrated into the UE 700. In some implementations, the controller 706 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 706 may be implemented as part of the processor 702.
[0184] In some implementations, the UE 700 may include at least one transceiver 708. In some other implementations, the UE 700 may have more than one transceiver 708. The transceiver 708 may represent a wireless transceiver. The transceiver 708 may include one or more receiver chains 710, one or more transmitter chains 712, or a combination thereof.
[0185] A receiver chain 710 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 710 may include one or more antennas for receive the signal over the air or wireless medium. The receiver chain 710 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 710 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 710 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.
[0186] A transmitter chain 712 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 712 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 712 may also include at least one poweramplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 712 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0187] Figure 8 illustrates an example of a processor 800 in accordance with aspects of the present disclosure. The processor 800 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 800 may include a controller 802 configured to perform various operations in accordance with examples as described herein. The processor 800 may optionally include at least one memory 804, which may be, for example, an L1 / L2 / L3 cache. Additionally, or alternatively, the processor 800 may optionally include one or more arithmetic-logic units (ALUs) 806. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).
[0188] The processor 800 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 800) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase change memory (PCM), and others).
[0189] The controller 802 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 800 to cause the processor 800 to support various operations in accordance with examples as described herein. For example, the controller 802 may operate as a control unit of the processor 800, generating control signals that manage the operation of various componentsof the processor 800. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.
[0190] The controller 802 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 804 and determine subsequent instruction(s) to be executed to cause the processor 800 to support various operations in accordance with examples as described herein. The controller 802 may be configured to track memory address of instructions associated with the memory 804. The controller 802 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 802 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 800 to cause the processor 800 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 802 may be configured to manage flow of data within the processor 800. The controller 802 may be configured to control transfer of data between registers, arithmetic logic units (ALUs), and other functional units of the processor 800.
[0191] The memory 804 may include one or more caches (e.g., memory local to or included in the processor 800 or other memory, such RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementations, the memory 804 may reside within or on a processor chipset (e.g., local to the processor 800). In some other implementations, the memory 804 may reside external to the processor chipset (e.g., remote to the processor 800).
[0192] The memory 804 may store computer-readable, computer-executable code including instructions that, when executed by the processor 800, cause the processor 800 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 802 and / or the processor 800 may be configured to execute computer-readable instructions stored in the memory 804 to cause the processor 800 to perform various functions. For example, the processor 800 and / or the controller 802 may be coupled with or to the memory 804, the processor 800, the controller 802, and the memory 804 may be configured to perform various functions described herein. In some examples, the processor800 may include multiple processors and the memory 804 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.
[0193] The one or more ALUs 806 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 806 may reside within or on a processor chipset (e.g., the processor 800). In some other implementations, the one or more ALUs 806 may reside external to the processor chipset (e.g., the processor 800). One or more ALUs 806 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 806 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 806 be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 806 may support logical operations such as AND, OR, exclusive-OR (XOR), not-OR (NOR), and not- AND (NAND), enabling the one or more ALUs 806 to handle conditional operations, comparisons, and bitwise operations.
[0194] The processor 800 may support wireless communication in accordance with examples as disclosed herein. The UE processor 800 may be configured to support a means for transmitting, to a network entity, an indication of a 256-bit security capability for the UE, and receiving, from the network entity, a response that confirms the UE is to apply the 256-bit security capability when performing an authentication procedure with the network entity.
[0195] Figure 9 illustrates an example of a NE 900 in accordance with aspects of the present disclosure. The NE 900 may include a processor 902, a memory 904, a controller 906, and a transceiver 908. The processor 902, the memory 904, the controller 906, or the transceiver 908, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0196] The processor 902, the memory 904, the controller 906, or the transceiver 908, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0197] The processor 902 may include an intelligent hardware device (e.g., a general- purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 902 may be configured to operate the memory 904. In some other implementations, the memory 904 may be integrated into the processor 902. The processor 902 may be configured to execute computer-readable instructions stored in the memory 904 to cause the NE 900 to perform various functions of the present disclosure.
[0198] The memory 904 may include volatile or non-volatile memory. The memory 904 may store computer-readable, computer-executable code including instructions when executed by the processor 902 cause the NE 900 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 904 or another type of memory. Computer-readable media includes both non- transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0199] In some implementations, the processor 902 and the memory 904 coupled with the processor 902 may be configured to cause the NE 900 to perform one or more of the functions described herein (e.g., executing, by the processor 902, instructions stored in the memory 904). For example, the processor 902 may support wireless communication at the NE 900 in accordance with examples as disclosed herein. The NE 900 may be configured to support a means for receiving, from a UE, an indication of a 256-bit security capability for the UE, determining whether the UE is to apply the 256-bit security capability based on one or more of the 256-bit security capability for the UE, subscription data associated with the UE, or capabilities of a communications network that includes the network entity, andtransmitting, to the UE, a response that confirms the UE is to apply the 256-bit security capability when performing an authentication procedure with the network entity.
[0200] As another example, the NE 900 may be configured to support a means for receiving, from a UE, an indication of a 256-bit security capability for the UE, determining whether to apply a 256-bit cryptographic algorithm for ciphering and integrity protection based on the 256-bit security capability for the UE and an operator policy for an operator of the network entity that prioritizes the 256-bit cryptographic algorithm, and transmitting, to the UE, a response that confirms the UE is to apply the 256-bit security capability when performing a security mode command procedure with the network entity.
[0201] As another example, the NE 900 may be configured to support a means for receiving, from an AMF, an indication of a 256-bit security capability for a UE and determining a 256-bit cryptographic algorithm to apply for AS security based on one or more of: the 256-bit security capability for the UE, a use 256-bit algorithm from the AMF, and an operator policy of the network entity that prioritizes 256-bit cryptographic algorithms.
[0202] The controller 906 may manage input and output signals for the NE 900. The controller 906 may also manage peripherals not integrated into the NE 900. In some implementations, the controller 906 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 906 may be implemented as part of the processor 902.
[0203] In some implementations, the NE 900 may include at least one transceiver 908. In some other implementations, the NE 900 may have more than one transceiver 908. The transceiver 908 may represent a wireless transceiver. The transceiver 908 may include one or more receiver chains 910, one or more transmitter chains 912, or a combination thereof.
[0204] A receiver chain 910 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 910 may include one or more antennas for receive the signal over the air or wireless medium. The receiver chain 910 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 910 may include atleast one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 910 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.
[0205] A transmitter chain 912 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 912 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 912 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 912 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0206] Figure 10 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a UE as described herein. In some implementations, the UE may execute a set of instructions to control the function elements of the UE to perform the described functions.
[0207] At 1002, the method may include transmitting, to a network entity, an indication of a 256-bit security capability for a UE. The operations of 1002 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1002 may be performed by a UE as described with reference to Figure 7.
[0208] At 1004, the method may include receiving, from the network entity, a response that confirms the UE is to apply the 256-bit security capability when performing an authentication procedure with the network entity. The operations of 1004 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1004 may be performed by a UE as described with reference to Figure 7.
[0209] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0210] Figure 11 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.
[0211] At 1102, the method may include receiving, from a UE, an indication of a 256- bit security capability for the UE. The operations of 1102 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1102 may be performed by a NE as described with reference to Figure 9.
[0212] At 1104, the method may include determining whether the UE is to apply the 256-bit security capability based on one or more of the 256-bit security capability for the UE, subscription data associated with the UE, or capabilities of a communications network that includes the network entity. The operations of 1104 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1104 may be performed by a NE as described with reference to Figure 9.
[0213] At 1106, the method may include transmitting, to the UE, a response that confirms the UE is to apply the 256-bit security capability when performing an authentication procedure with the network entity. The operations of 1106 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1106 may be performed by a NE as described with reference to Figure 9.
[0214] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0215] Figure 12 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as describedherein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.
[0216] At 1202, the method may include receiving, from a UE, an indication of a 256- bit security capability for the UE. The operations of 1202 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1202 may be performed by a NE as described with reference to Figure 9.
[0217] At 1204, the method may include determining whether to apply a 256-bit cryptographic algorithm for ciphering and integrity protection based on the 256-bit security capability for the UE and an operator policy for an operator of the network entity that prioritizes the 256-bit cryptographic algorithm. The operations of 1204 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1204 may be performed by a NE as described with reference to Figure 9.
[0218] At 1206, the method may include transmitting, to the UE, a response that confirms the UE is to apply the 256-bit security capability when performing a security mode command procedure with the network entity. The operations of 1206 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1206 may be performed by a NE as described with reference to Figure 9.
[0219] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0220] Figure 13 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.
[0221] At 1302, the method may include receiving, from an AMF, an indication of a 256-bit security capability for a UE. The operations of 1302 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1302 may be performed by a NE as described with reference to Figure 9.
[0222] At 1304, the method may include determining a 256-bit cryptographic algorithm to apply for AS security based on one or more of: the 256-bit security capability for the UE, a use 256-bit algorithm from the AMF, and an operator policy of the network entity that prioritizes 256-bit cryptographic algorithms.
[0223] The operations of 1304 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1304 may be performed by a NE as described with reference to Figure 9.
[0224] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0225] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.
Claims
CLAIMSWhat is claimed is:
1. A user equipment (UE) for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the UE to: transmit, to a network entity, an indication of a 256-bit security capability for the UE; and receive, from the network entity, a response that confirms the UE is to apply the 256-bit security capability when performing an authentication procedure with the network entity.
2. The UE of claim 1, wherein the indication of the 256-bit security capability for the UE includes an indication that the UE supports a 256-bit key size.
3. The UE of claim 1, wherein the response indicates use of 256-bit key size by the UE.
4. The UE of claim 1, wherein the indication of the 256-bit security capability for the UE includes an indication that the UE supports 256-bit cryptographic algorithms for integrity protection and ciphering.
5. The UE of claim 1, wherein the at least one processor is configured to cause the UE to transmit the indication of the 256-bit security capability for the UE to an Access and Mobility Management Function (AMF) via a Non Access Stratum (NAS) message.
6. The UE of claim 1, wherein the at least one processor is configured to cause the UE to transmit the indication of the 256-bit security capability for the UE to an Access and Mobility Management Function (AMF) via an N1 transport message.
7. The UE of claim 1, wherein the at least one processor is configured to cause the UE to transmit the indication of the 256-bit security capability for the UE during a primary authentication procedure with the network entity.
8. The UE of claim 7, wherein the primary authentication procedure includes an Extensible Authentication Protocol Authentication and Key Agreement (EAP- AKA') authentication procedure.
9. The UE of claim 7, wherein the primary authentication procedure includes an 5G Authentication and Key Agreement (5G-AKA) authentication procedure.
10. The UE of claim 1, wherein the at least one processor is further configured to cause the UE to: generate a 256-bit security keys for ciphering and integrity protection upon receiving the response from the network entity; and perform the ciphering and integrity protection using the generated 256-bit keys.
11. The UE of claim 10, wherein the generated and used 256-bit security key is a 256-bit Non Access Stratum (NAS) integrity key, a 256-bit Non Access Stratum (NAS) ciphering key, a 256-bit Access Stratum (AS) integrity key, a 256-bit Access Stratum (AS) ciphering key, a 256-bit user plane (UP) integrity key, or a 256-bit user plane (UP) ciphering key.
12. A network entity for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the network entity to: receive, from a user equipment (UE), an indication of a 256-bit security capability for the UE;determine whether the UE is to apply the 256-bit security capability based on one or more of the 256-bit security capability for the UE, subscription data associated with the UE, or capabilities of a communications network that includes the network entity; and transmit, to the UE, a response that confirms the UE is to apply the 256-bit security capability when performing an authentication procedure with the network entity.
13. The network entity of claim 12, wherein the at least one processor is configured to cause the network entity to transmit the response that confirms the UE is to apply the 256-bit security capability when performing a Non Access Stratum (NAS) security procedure.
14. The network entity of claim 12, wherein the at least one processor is configured to cause the network entity to transmit the response that confirms the UE is to apply the 256-bit security capability via an Anti-Bidding down Between Architectures (ABBA) parameter sent to the UE during the authentication procedure.
15. The network entity of claim 12, wherein the response indicates use of a 256-bit key size.
16. The network entity of claim 12, wherein the network entity is a United Data Management (UDM) function that manages the subscription data along with 256-bit security requirements associated with the UE.
17. The network entity of claim 12, when the authentication procedure is an Extensible Authentication Protocol Authentication and Key Agreement (EAP- AKA') authentication procedure, the processor is further configured to cause the network entity to: instruct a security anchor function (SEAF) to utilize 256-bit security during the EAP- AKA' authentication procedure.
18. The network entity of claim 12, when the authentication procedure is an 5G Authentication and Key Agreement (5G-AKA) authentication procedure, the processor is further configured to cause the network entity to: instruct a security anchor function (SEAF) to utilize 256-bit security during the 5G- AKA authentication procedure.
19. A network entity for wireless communication, including: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the network entity to: receive, from a user equipment (UE), an indication of a 256-bit security capability for the UE; determine whether to apply a 256-bit cryptographic algorithm for ciphering and integrity protection based on the 256-bit security capability for the UE and an operator policy for an operator of the network entity that prioritizes the 256-bit cryptographic algorithm; and transmit, to the UE, a response that confirms the UE is to apply the 256-bit security capability when performing a security mode command procedure with the network entity.
20. A network entity for wireless communication, including: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the network entity to: receive, from an Access and Mobility Management Function (AMF), an indication of a 256-bit security capability for a user equipment (UE); and determine a 256-bit cryptographic algorithm to apply for Access Stratum (AS) security based on one or more of: the 256-bit security capability for the UE, a use 256-bit algorithm from the AMF, and an operatorpolicy of the network entity that prioritizes 256-bit cryptographic algorithms.
Citation Information
Patent Citations
Security negotiation method, terminal equipment and network equipment
CN110366175A
Method for negotiating security capability of 5G mobile communication network
CN111787532A
US202463551701P