Method, device and computer program product for wireless communication
Patent Information
- Application Number
- PCT/CN2024/111141
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-08-09
- Publication Date
- 2025-07-31
Smart Images

Figure CN2024111141_31072025_PF_FP_ABST
Abstract
Description
METHOD, DEVICE AND COMPUTER PROGRAM PRODUCT FOR WIRELESS COMMUNICATION
[0001] This document is directed generally to wireless communications, and in particular to 5th generation (5G) communications or 6th generation (6G) communications.
[0002] Integrity and encryption protections in telecom are essential for securing data transmission across networks. Integrity protections ensure that the data sent is received unaltered, protecting against tampering and ensuring authenticity. Encryption protections, on the other hand, protect the confidentiality of the data by converting it into a coded format that can only be deciphered by authorized parties. Together, these protections form a critical part of telecom security protocols, safeguarding sensitive information and maintaining the trustworthiness of communication systems.
[0003] This document relates to methods, systems, and computer program products for a wireless communication.
[0004] One aspect of the present disclosure relates to a wireless communication method. In an embodiment, the wireless communication method includes: transmitting, by a wireless communication terminal to a wireless communication node, a first message using an authenticated encryption with associated data, AEAD, mode according to an AEAD information carried by a second message from the wireless communication node.
[0005] Another aspect of the present disclosure relates to a wireless communication method. In an embodiment, the wireless communication method includes: receiving, by a wireless communication node from a wireless communication terminal, a first message using an authenticated encryption with associated data, AEAD, mode according to an AEAD information carried by a second message from the wireless communication node.
[0006] Another aspect of the present disclosure relates to a wireless communication terminal. In an embodiment, the wireless communication terminal includes a communication unit and a processor. The processor is configured to: transmit, to a wireless communication node via the communication unit, a first message using an authenticated encryption with associated data, AEAD, mode according to an AEAD information carried by a second message from the wireless communication node.
[0007] Another aspect of the present disclosure relates to a wireless communication node. In an embodiment, the wireless communication node includes a communication unit and a processor. The processor is configured to: receive, from a wireless communication terminal a communication unit, a first message using an authenticated encryption with associated data, AEAD, mode according to an AEAD information carried by a second message from the wireless communication node.
[0008] Various embodiments may preferably implement the following features:
[0009] Preferably, the AEAD information comprises at least one of:
[0010] an AEAD indicator;
[0011] an AEAD usage policy; or
[0012] an authenticated encryption algorithm.
[0013] Preferably, the first message is transmitted using the AEAD mode in response to at least one of:
[0014] the second message comprising an AEAD indicator with a first value indicating the AEAD mode being used;
[0015] the second message comprising an AEAD usage policy, and the AEAD usage policy indicating the AEAD mode being used or a first condition in the AEAD usage policy for using the AEAD mode being met; or
[0016] the second message comprising an authenticated encryption algorithm.
[0017] Preferably, the first message is transmitted without using the AEAD mode in response to:
[0018] the second message comprising an AEAD indicator with a second value indicating an AEAD mode not being used;
[0019] the second message comprising an AEAD usage policy, and the AEAD usage policy indicating the AEAD mode not being used or a second condition in the AEAD usage policy for not using the AEAD mode being met; or
[0020] the second message not comprising an authenticated encryption algorithm.
[0021] Preferably, an integrity protection and ciphering for the first message is based on an authenticated encryption algorithm in response to the AEAD mode being used.
[0022] Preferably, an integrity protection and ciphering for the second message is based on an authenticated encryption algorithm in response to the AEAD mode being used.
[0023] Preferably, the wireless communication terminal performs at least one of:
[0024] verifying an integrity protection of the second message by using an authenticated encryption algorithm in response to the AEAD mode being used; or
[0025] performing an integrity protection and ciphering for the first message by using an authenticated encryption algorithm in response to the AEAD mode being used.
[0026] Preferably, the AEAD information indicates:
[0027] the AEAD mode is used and an authenticated encryption algorithm is based on an algorithm of a selected ciphering algorithm and a selected integrity algorithm;
[0028] the AEAD mode is used and the select algorithm is based on an algorithm of a selected ciphering algorithm; or
[0029] the AEAD mode is used and the select algorithm is based on an algorithm of a selected integrity algorithm.
[0030] Preferably, the wireless communication terminal transmits, to the wireless communication node, a third message comprising an authenticated encryption algorithm supported by the wireless communication terminal.
[0031] Preferably, the first message comprises a Non-Access-stratum, NAS, Security Mode Complete message or an Access-stratum, AS, Security Mode Complete message;
[0032] wherein the second message comprises a NAS Security Mode Command message or an AS Security Mode Command message; and / or
[0033] wherein a third message comprising an authenticated encryption algorithm supported by the wireless communication terminal transmitted from the wireless communication terminal transmits to the wireless communication node is a registration request message.
[0034] Preferably, the wireless communication method further comprising at least one of:
[0035] receiving, by the wireless communication node from the wireless communication terminal, a third message comprising the authenticated encryption algorithm supported by the wireless communication terminal; or
[0036] transmitting, by the wireless communication node to the wireless communication terminal, a fourth message without using the AEAD mode in response to at least one of:
[0037] the wireless communication node being not supporting an authenticated encryption algorithm; or
[0038] a priority of an integrity algorithm or a ciphering algorithm is higher than a priority of an authenticated encryption algorithm.
[0039] The present disclosure relates to a computer program product comprising a computer-readable program medium code stored thereupon, the code, when executed by a processor, causing the processor to implement a wireless communication method recited in any one of foregoing methods.
[0040] The exemplary embodiments disclosed herein are directed to providing features that will become readily apparent by reference to the following description when taken in conjunction with the accompanying drawings. In accordance with various embodiments, exemplary systems, methods, devices and computer program products are disclosed herein. It is understood, however, that these embodiments are presented by way of example and not limitation, and it will be apparent to those of ordinary skill in the art who read the present disclosure that various modifications to the disclosed embodiments can be made while remaining within the scope of the present disclosure.
[0041] Thus, the present disclosure is not limited to the exemplary embodiments and applications described and illustrated herein. Additionally, the specific order and / or hierarchy of steps or operations in the methods disclosed herein are merely exemplary approaches. Based upon design preferences, the specific order or hierarchy of steps or operations of the disclosed methods or processes can be re-arranged while remaining within the scope of the present disclosure. Thus, those of ordinary skill in the art will understand that the methods and techniques disclosed herein present various steps or operations in a sample order, and the present disclosure is not limited to the specific order or hierarchy presented unless expressly stated otherwise.
[0042] The above and other aspects and their implementations are described in greater detail in the drawings, the descriptions, and the claims.
[0043] FIG. 1 shows a schematic diagram of a network according to an embodiment of the present disclosure.
[0044] FIG. 2 shows a schematic diagram of a procedure according to an embodiment of the present disclosure.
[0045] FIG. 3 shows a schematic diagram of a procedure according to an embodiment of the present disclosure.
[0046] FIG. 4 shows a schematic diagram of a procedure according to an embodiment of the present disclosure.
[0047] FIG. 5 shows a schematic diagram of a procedure according to an embodiment of the present disclosure.
[0048] FIG. 6 shows a schematic diagram of a procedure according to an embodiment of the present disclosure.
[0049] FIG. 7 shows an example of a schematic diagram of a wireless communication terminal according to an embodiment of the present disclosure.
[0050] FIG. 8 shows an example of a schematic diagram of a wireless communication node according to an embodiment of the present disclosure.
[0051] FIGs. 9 and 10 show flowcharts of wireless communication methods according to some embodiments of the present disclosure.
[0052] In some embodiments, the 256-bit cryptographic algorithms include 256-bit Integrity, Encryption, and Authenticated Encryption (AE) Algorithms for 5G Non-Access Stratum (NAS) and AS layers based on the Advanced Encryption Standard (AES) , the SNOW 5G, and the Zu Chongzhi (ZUC) . The AE is an encryption scheme combining the functionalities of encryption and authentication into a single, efficient operation, providing confidentiality, integrity, and authenticity protection together. Moreover, the AE scheme allows messages to contain associated data, which needs to be authenticated but does not need to be kept confidential. This mode is called Authenticated encryption with the associated data (AEAD) . The AEAD can provide the encryption and the integrity protection for messages and provide the integrity protection for associated data. If the message is NULL, the AEAD may only provide integrity protection for the associated data and can be regarded as an integrity protection algorithm.
[0053] In some embodiments, since the AEAD algorithms can be used in diverse scenarios including the integrity protection only and the encryption and integrity protection together, it can replace the integrity algorithms and encryption algorithms. In some embodiments, the AEAD mode shall not be used together with encryption and integrity algorithms. Some embodiments of the present disclosure provide methods to negotiate AEAD algorithms, e.g., in security mode command (SMC) procedures.
[0054] Some embodiments of the present disclosure propose a mechanism to perform algorithm negotiation (e.g., in SMC procedures) between the UE (user equipment) and the 5GS (5G system) . In some embodiments, the UE and / or the 5GS may support the AEAD mode.
[0055] In some embodiments, the authenticated encryption is a form of encryption that, in addition to providing confidentiality for the plaintext that is encrypted, provides a way to check its integrity and authenticity. The Authenticated Encryption with Associated Data, or the AEAD, adds the ability to check the integrity and authenticity of some Associated Data (AD) . In some embodiments, the AD is also called the “additional authenticated data” , that is not encrypted.
[0056] Some cryptographic applications require both confidentiality and message authentication. The confidentiality is a security service that ensures that data is available only to those authorized to obtain it; usually it is realized through encryption. The message authentication is the service that ensures that data has not been altered or forged by unauthorized entities; e.g., it can be achieved by using a Message Authentication Code (MAC) . This service is also called the data integrity. Some applications use an encryption method and a MAC together to provide both of those security services, with each algorithm using an independent key. In some embodiments, both security services using a single crypto algorithm is provided. For example, the cipher and MAC may be replaced by an Authenticated Encryption with Associated Data (AEAD) algorithm. In some embodiments, some crypto algorithms that implement AEAD algorithms are defined, including block cipher modes of operation and dedicated algorithms.
[0057] Authenticated Encryption
[0058] In some embodiments, the authenticated encryption operation has four inputs, each of which is an octet string:
[0059] A secret key K, which may be generated in a way that is uniformly random or pseudorandom;
[0060] A nonce N, each nonce provided to distinct invocations of the Authenticated Encryption operation may be distinct, for any particular value of the key, unless each and every nonce is zero-length. Applications that can generate distinct nonces may use a nonce formation method and may use any other method that meets the uniqueness requirement. Other applications may use zero-length nonces.
[0061] A plaintext P, which contains the data to be encrypted and authenticated.
[0062] The associated data A, which contains the data to be authenticated, but not encrypted.
[0063] There is a single output:
[0064] A ciphertext C, which is at least as long as the plaintext, or an indication that the requested encryption operation could not be performed.
[0065] C=AEAD (K, N, P, A) .
[0066] Authenticated Decryption
[0067] In some embodiments, the authenticated decryption operation has four inputs: K, N, A, and C, as described above. The authenticated decryption operation has only a single output, either a plaintext value P or a special symbol FAIL that indicates that the inputs are not authentic. A ciphertext C, a nonce N, and associated data A are authentic for key K, when the C is generated by the encrypt operation with inputs K, N, P, and A, for some values of N, P, and A. The authenticated decrypt operation may, with high probability, return FAIL whenever the inputs N, P, and A were crafted by a nonce-respecting adversary that does not know the secret key (assuming that the AEAD algorithm is secure) .
[0068] AEAD_AES_128_GCM
[0069] In some embodiments, the AEAD_AES_128_GCM authenticated encryption algorithm uses AES-128 as the block cipher, by providing the key, nonce, and plaintext, and associated data to that mode of operation. An authentication tag with a length of 16 octets (128 bits) is used. The AEAD_AES_128_GCM ciphertext is formed by appending the authentication tag provided as an output to the GCM (Galois Counter Mode) encryption operation to the ciphertext that is output by that operation. The input and output lengths are as follows:
[0070] K_LEN is 16 octets,
[0071] P_MAX is 2^36 -31 octets,
[0072] A_MAX is 2^61 -1 octets,
[0073] N_MIN and N_MAX are both 12 octets, and
[0074] C_MAX is 2^36 -15 octets.
[0075] An AEAD_AES_128_GCM ciphertext is 16 octets longer than its corresponding plaintext.
[0076] AEAD_AES_256_GCM.
[0077] This algorithm is identical to AEAD_AES_128_GCM, but with the following differences:
[0078] K_LEN is 32 octets, instead of 16 octets, and AES-256 GCM is used instead of AES-128 GCM.
[0079] NAS Security context between UE and AMF
[0080] FIG. 1 shows a schematic diagram of a procedure according to an embodiment of the present disclosure.
[0081] In some embodiments, the NAS SMC shown in FIG. 1 may be used to establish NAS Security context between the UE and the AMF (Access and Mobility Management Function) . This procedure comprises a roundtrip of messages between the AMF and the UE. The AMF sends the NAS Security Mode Command message to the UE and the UE replies with the NAS Security Mode Complete message.
[0082] In some embodiments, the NAS SMC procedure is designed such that it protects the Registration Request against a man-in-the-middle attack where the attacker modifies the IEs (information elements) containing the UE security capabilities provided by the UE in the Registration Request. If the method completes successfully, the UE is attached to the network knowing that no bidding down attack has happened. In case a bidding down attack was attempted, the verification of the NAS SMC may fail, and the UE replies with a reject message meaning that the UE may not attach to the network.
[0083] 1a. The AMF activates the NAS integrity protection before sending the NAS Security Mode Command message.
[0084] 1b. The AMF sends the NAS Security Mode Command message to the UE. The NAS Security Mode Command message may contain: the replayed UE security capabilities, the selected NAS algorithms, and the Key Set Identifier (ngKSI) for identifying the KAMF (e.g., a key of the AMF) . The NAS Security Mode Command message may contain: K_AMF_change_flag (carried in the additional 5G security parameters IE) to indicate a new KAMF is calculated, a flag requesting the complete initial NAS message, Anti-Bidding down Between Architectures (ABBA) parameter. In the case of horizontal derivation of KAMF during mobility registration update or during multiple registration in the same Public Land Mobile Network (PLMN) , K_AMF_change_flag may be included in the NAS Security Mode Command message.
[0085] This message may be integrity protected (but not ciphered) with the NAS integrity key based on the KAMF indicated by the ngKSI in the NAS Security Mode Command message (see FIG. 1) .
[0086] In case the network supports interworking using the N26 interface between the Mobility Management Entity (MME) and the AMF, the AMF may also include the selected Evolved Packet System (EPS) NAS algorithms to be used after mobility to the EPS in the NAS Security Mode Command message. The UE may store the algorithms for use after mobility to the EPS using the N26 interface between the MME and the AMF. The AMF may store the selected EPS NAS algorithms in the UE security context.
[0087] When the AMF change happens either due to N2-handover or idle mode mobility, the selected EPS NAS algorithms is included in the 5G UE security context and provided to the target AMF as part of the 5G UE security context.
[0088] 1c. The AMF activates the NAS uplink deciphering after sending the NAS Security Mode Command message.
[0089] 2a. The UE may verify the NAS Security Mode Command message. This includes checking that the UE security capabilities sent by the AMF match the ones stored in the UE to ensure that these were not modified by an attacker and verifying the integrity protection using the indicated NAS integrity algorithm and the NAS integrity key based on the KAMF indicated by the ngKSI.
[0090] In case the NAS Security Mode Command message includes a K_AMF_change_flag, the UE may derive a new KAMF and set the NAS COUNTs to zero.
[0091] If the verification of the integrity of the NAS Security Mode Command message is successful, the UE may start the NAS integrity protection and ciphering / deciphering with the security context indicated by the ngKSI.
[0092] 2b. The UE sends the NAS Security Mode Complete message to the AMF ciphered and integrity protected. The NAS Security Mode Complete message may include the Permanent Equipment Identifier (PEI) in case the AMF requested it in the NAS Security Mode Command message. The AMF may set the NAS COUNTs to zero if horizontal derivation of KAMF is performed. The UE may include the complete initial NAS message.
[0093] If the verification of the NAS Security Mode Command message is not successful in the UE, it may reply with a NAS Security Mode Reject message. The NAS Security Mode Reject message and all subsequent NAS messages may be protected with the previous, if any, 5G NAS security context, i.e., the 5G NAS security context used prior to the failed NAS Security Mode Command message. If no 5G NAS security context existed prior to the NAS Security Mode Command message, the NAS Security Mode Reject message may remain unprotected.
[0094] The AMF may de-cipher and check the integrity protection on the NAS Security Mode Complete message using the key and algorithm indicated in the NAS Security Mode Command message. NAS downlink ciphering at the AMF with this security context may start after receiving the NAS Security Mode Complete message.
[0095] 1d. The AMF activates NAS downlink ciphering.
[0096] If the uplink NAS COUNT may wrap around by sending the NAS Security Mode Reject message, the UE releases the NAS connection instead of sending the NAS Security Mode Reject message.
[0097] If the AMF successfully validated the NAS SMC Complete message, the AMF has successfully confirmed the Subscription Permanent Identifier (SUPI) received from the home network and the SUPI used by the UE match. However, the integrity check failure of the NAS SMC Complete message at the AMF could have other causes than a mismatch of the SUPIs.
[0098] AS security algorithms negotiation and consideration during UE initial AS security context establishment
[0099] Each gNB (next generation Node B) or ng-eNB (next generation -evolved Node B) may be configured via network management with lists of algorithms which are allowed for usage. There may be one list for integrity algorithms, and one for ciphering algorithms. These lists may be ordered according to a priority decided by the operator. When the AS security context is to be established in the gNB / ng-eNB, the AMF may send the UE 5G security capabilities to the gNB / ng-eNB. The gNB / ng-eNB may choose the ciphering algorithm which has the highest priority from its configured list and is also present in the UE 5G security capabilities.
[0100] AS SMC procedure
[0101] FIG. 2 shows a schematic diagram of a procedure according to an embodiment of the present disclosure.
[0102] The AS (Access-stratum) SMC procedure is for the RRC (Radio Resource Control) and UP (User Plane) security algorithms negotiation and RRC security activation for the gNB / ng-eNB. The AS SMC procedure can be triggered to establish a secure RRC signalling-only connection during UE registration or PDU session establishment. The activation of the UP security is as described. The AS SMC procedure consists of a roundtrip of messages between the gNB / ng-eNB and the UE. The gNB / ng-eNB sends the AS security mode command to the UE and the UE replies with the AS security mode complete message (see FIG. 2) .
[0103] In some embodiments, the AS security mode command message sent from the gNB / ng-eNB to the UE may contain the selected RRC and / or UP encryption and integrity algorithms. This AS security mode command message may be integrity protected with RRC integrity key based on the current KgNB. In some embodiments, KgNB is a key derived by the UE and AMF from KAMF. KgNB is further derived by the UE and source gNB when performing horizontal or vertical key derivation. The KgNB is used as KeNB between the UE and ng-eNB.
[0104] In some embodiments, the AS security mode complete message from UE to gNB / ng-eNB may be integrity protected with the selected RRC algorithm indicated in the AS security mode command message and RRC integrity key based on the current KgNB.
[0105] In some embodiments, RRC downlink ciphering (encryption) at the gNB / ng-eNB may start after sending the AS security mode command message. RRC uplink deciphering (decryption) at the gNB / ng-eNB may start after receiving and successful verification of the AS security mode complete message.
[0106] In some embodiments, RRC uplink ciphering (encryption) at the UE may start after sending the AS security mode complete message. RRC downlink deciphering (decryption) at the UE may start after receiving and successful verification of the AS security mode command message.
[0107] If any control of the AS security mode command is not successful in the UE, the UE may reply with an unprotected security mode failure message.
[0108] Ciphering and integrity protection of UP downlink and uplink, at the UE and the gNB / ng-eNB, may start as defined.
[0109] AS SMC may be used only during an initial context setup between the UE and the gNB / ng-eNB (i.e., to activate an initial KgNB at RRC_IDLE to RRC_CONNECTED state transition) .
[0110] Derivation of a KgNB at RRC_IDLE to RRC_CONNECTED state ensures that AS SMC establishes a fresh KgNB. Consequently, the PDCP (Packet Data Convergence Protocol) COUNTs can be reset.
[0111] In some embodiments, considering the gradual deployment, devices and network elements of mixed cryptographic capabilities may co-exist. For example, some devices and network elements may support AE algorithms, some may just support ciphering and integrity algorithms (e.g., not support AEAD) . In some embodiments, ciphering algorithms and integrity algorithms are assigned with different identifier values, e.g., 128-bit SNOW 3G based integrity algorithm 128-NIA1 and ciphering algorithm 128-NEA1 are set to "00012" , respectively. After introducing authenticated encryption algorithms, it is possible to assign identifier values to them, e.g., the 256-bit SNOW 5G based authenticated algorithm 256-NCA4 to be set to “0101” . By assigning identifier values, the algorithms can be indicated in the SMC message. In some embodiments, it is also possible that they are not assigned any values. In such cases, the selection of authenticated encryption algorithm cannot be indicated in the SMC message directly.
[0112] Some embodiments of the present disclosure provide methods for the first scenario that authenticated encryption algorithms are assigned values. Some embodiments of the present disclosure provide methods for the second scenario that authenticated encryption algorithms are not assigned any value.
[0113] In the paragraphs below, some aspects of the present disclosure are provided, but the present disclosure is not limited thereto. Besides, embodiments in different aspects described below can be combined unless expressly stated otherwise.
[0114] Aspect 1:
[0115] FIG. 3 shows a schematic diagram of a procedure (e.g., a registration procedure) according to an embodiment of the present disclosure. In some embodiments, the UE may include all algorithms it supports in the Registration Request message and send it to the AMF. In some embodiments, the procedure may include at least one of the following operations.
[0116] 1-3. The UE sends the registration request to the AMF forwarded by the gNB / ng-eNB, which performs an AMF selection to determine the AMF. In some embodiments, the message contains cleartext IEs and may contain non-cleartext IEs. In some embodiments, the UE may include the UE security capabilities as a cleartext IE, e.g., the UE security capabilities include the ciphering, integrity and / or authenticated encryption algorithms supported by the UE.
[0117] In some embodiments, if the UE has no NAS security context, the UE may include only cleartext IEs in the message sends the registration request without integrity protection.
[0118] In some embodiments, if the UE has the NAS security context, the UE uses the current 5G security context algorithms to protect the Registration Request message. In some embodiments, if the UE does not need to send non-cleartext IEs, the message may be only integrity protected. In some embodiments, if the UE needs to send non-cleartext IEs, both cleartext IEs and non-cleartext IEs may be in the NAS message container IE, and the UE may cipher the value part of the NAS message container IE. In some embodiments, the UE may then send a registration request message containing the cleartext IEs and the NAS message container IE.
[0119] In some embodiments, if the chosen algorithms in the NAS security context are ciphering algorithm and integrity algorithm, or the AEAD mode is not used, the message is protected as by using the ciphering algorithm and integrity algorithm. In some embodiments, if the chosen algorithm in the NAS security context in the authenticated encryption algorithm, or the AEAD mode is used, the message may be protected by the chosen authenticated encryption algorithm, where the input plaintext “P” is the value part of the NAS message container IE, and the input associated data “A” is the cleartext IEs. The output ciphertext “C” is both encrypted and integrity protected. In some embodiments, if the UE does not need to send non-cleartext IEs, there is no NAS message container, and the input plaintext “P” is set to NULL.
[0120] 4. The AMF requests the NAS security context from the last visited AMF. In some embodiments, the last visited AMF uses the selected algorithm in the NAS security context to verify the Registration Request message and provides the NAS security context to the AMF if the integrity check is successful.
[0121] 5. If the AMF supports the selected algorithm in the security context, the registration can be continued.
[0122] In some embodiments, if the AMF does not support the selected algorithm, e.g., the selected algorithm in the security context is authenticated encryption algorithm, but the AMF only supports ciphering and integrity protection algorithms, the initial NAS message cannot be deciphered. In this case, the AMF may select the algorithms with the highest priority in its locally configured list of algorithms that are also present in the received UE security capabilities. In some embodiments, the AMF may send a security message (e.g., a NAS Security Mode Command message, to facilitate the understanding, the NAS Security Mode Command message will be taken as an example in the present disclosure, but the present disclosure is not limited thereto) to the UE, including the selected algorithms, and a flag requesting the UE to send the complete initial NAS message in a response message (e.g., the NAS Security Mode Complete message, to facilitate the understanding, the NAS Security Mode Complete message will be taken as an example in the present disclosure, but the present disclosure is not limited thereto) due to the algorithm in the security context is not supported.
[0123] In some embodiments, if the AMF supports the selected algorithms but wants to change to other algorithms, e.g., another algorithm has the highest priority in the local configuration of the AMF, the AMF may select the algorithms with highest priority in its locally configured list of algorithms that are also present in the received UE security capabilities. The AMF may include the selected algorithms in the NAS Security Mode Command message to the UE.
[0124] In some embodiments, if the AMF supports authenticated encryption algorithms, the AMF and the UE may continue the SMC procedure based on authenticated encryption algorithms. In some alternative embodiments, even if the AMF supports authenticated encryption algorithms, the AMF and the UE may continue the SMC procedure without using authenticated encryption algorithms (e.g., using ciphering and integrity protection algorithms) . Details in this regard will be described in the embodiments (e.g., embodiments described in Aspects 2 to 10) below.
[0125] In some embodiments, the UE may send the NAS Security Mode Complete message to the network in response to a NAS Security Mode Command message. The NAS Security Mode Complete message may be ciphered and integrity protected by the selected algorithms sent from the AMF. Furthermore, the NAS Security Mode Complete message may include the complete initial NAS message in a NAS Container if either requested by the AMF or the UE sent the initial NAS message unprotected. In some embodiments, the AMF may use the complete initial NAS message that is in the NAS container as the message to respond to.
[0126] In some embodiments, the AMF may send its Registration Accept message to the UE. In some embodiments, this message may be ciphered and integrity protected.
[0127] In some embodiments, if the UE supports the authenticated encryption algorithm based on Snow 5G, the NCA4 may be included in the request message.
[0128] In some embodiments, if the NCA4 is the selected algorithm in the 5G NAS security context, as an authenticated encryption algorithm, the following parameters may be used as input for the NCE4.
[0129] The parameters include at least one of:
[0130] P: the data need to be ciphered and integrity protected;
[0131] K: key;
[0132] A: the data needs to be integrity protected but not need to be ciphered; and / or
[0133] N: a nonce as initialization vector.
[0134] In this case, P is the value part of the NAS message container IE, and A is the cleartext IEs.
[0135] Aspect 2:
[0136] In some embodiments, in the NAS SMC procedure, the AMF chooses ciphering algorithm, integrity algorithm, authentication algorithm, respectively. In some embodiments, the AMF uses an AEAD indicator to instruct the UE whether to use the AEAD mode.
[0137] FIG. 4 shows a schematic diagram of a NAS SMC procedure according to an embodiment of the present disclosure. In some embodiments, the procedure may include at least one of the following operations.
[0138] 1a. The AMF decides whether to use the AEAD mode for the NAS protection and activates the NAS integrity protection before sending a security message for the NAS security (e.g., the NAS Security Mode Command message) . For example, the AMF decides to use the AEAD mode for the NAS protection based on the local configuration that an authenticated encryption algorithm has the highest priority according to the configured lists.
[0139] 1b. The AMF sends a security message (e.g., the NAS Security Mode Command message) to the UE. In some embodiments, the security message may contain: the UE security capabilities (e.g., the replayed UE security capabilities sent by the UE to the AMF in previous procedures (e.g., sent via the registration request in the procedure described in embodiments in Aspect 1) ) , the selected NAS algorithms (e.g., including ciphering algorithm, integrity algorithm, and / or authenticated encryption algorithm) , and / or the ngKSI for identifying the KAMF. In some embodiments, an AEAD indicator is also included in the message to indicate the decision of AMF on whether to use AEAD mode for NAS protection. For example, the AEAD indicator is set to “1” when the AMF decides to use the AEAD mode, and the indicator is set to “0” when the AMF decides not to use the AEAD mode.
[0140] In some embodiments, the security message (e.g., the NAS Security Mode Command message) may contain: K_AMF_change_flag to indicate a new KAMF is calculated, a flag requesting the complete initial NAS message, the Anti-Bidding down Between Architectures (ABBA) parameter (s) . In the case of horizontal derivation of KAMF during mobility registration update or during multiple registration in same PLMN, K_AMF_change_flag may be included in this security message (e.g., the NAS Security Mode Command message) . In some embodiments, the security message (e.g., the NAS Security Mode Command message) may contain: the NAS MAC (Message Authentication Code) . In some embodiments, the NAS MAC is used to authenticate a message and ensure its integrity. The NAS MAC is the output of integrity protection algorithm (or authenticated encryption algorithm with plaintext setting to NULL) , while the input of the algorithm is the message and a key. In this scenario, the input message is the parameters in the security message described above, including the UE security capabilities, the selected NAS algorithms, etc.
[0141] In some embodiments, this security message (e.g., the NAS Security Mode Command message) may be integrity protected (but not ciphered) with the NAS integrity algorithm (e.g., with a NAS integrity key based on the KAMF indicated by the ngKSI in the security message (e.g., the NAS Security Mode Command message) ) or the NAS authenticated encryption algorithm (e.g., with a NAS authenticated encryption key based on the KAMF indicated by the ngKSI in the security message (e.g., the NAS Security Mode Command message) ) . In some embodiments, to use the NAS integrity algorithm or the NAS authenticated encryption algorithm for the integrity protection of the security message depends on whether to use the AEAD mode (e.g., whether the AEAD indicator indicate to use the AEAD) .
[0142] 1c. The AMF activates the NAS uplink deciphering after sending the security message (e.g., the NAS Security Mode Command message) .
[0143] 2a. The UE may verify the security message (e.g., the NAS Security Mode Command message) . In some embodiments, the verification includes checking that the UE security capabilities sent by the AMF match the ones stored in the UE to ensure that these UE security capabilities were not modified by an attacker and verifying the integrity protection. In some embodiments, if the received AEAD indicator indicates that the AEAD mode shall be used, the UE uses the indicated NAS authenticated encryption algorithm and the NAS authenticated encryption key to verify the integrity protection of the security message. In some embodiments, if the received AEAD indicator indicates that AEAD mode shall not be used, the UE uses the indicated NAS integrity algorithm and the NAS integrity key based on the KAMF indicated by the ngKSI to verify the integrity protection of the security message.
[0144] In some embodiments, if the verification of the integrity of the security message (e.g., NAS Security Mode Command message) is successful, the UE may start the NAS integrity protection and ciphering / deciphering (e.g., the UE may decipher the subsequent encrypted NAS message sent after SMC, such as the registration accept message) with the security context indicated by the ngKSI (e.g., performing the NAS integrity and ciphering on the security message (e.g., the NAS Security Mode Complete message) to be sent to the AMF) . In some embodiments, if the received AEAD indicator indicates that AEAD mode shall be used, the UE uses NAS authenticated encryption algorithm for the NAS integrity protection and ciphering / deciphering. In some embodiments, if the received AEAD indicator indicates that AEAD mode shall not be used, the UE uses NAS integrity algorithm and ciphering algorithm for the NAS integrity protection and ciphering / deciphering.
[0145] 2b. The UE sends a response message (e.g., the NAS Security Mode Complete message) to the AMF, in which the response message is ciphered and integrity protected. In some embodiments, if the AEAD mode is used, the UE uses authenticated encryption algorithm for ciphering and integrity protection. In some embodiments, if the AEAD mode is not used, the UE uses integrity algorithm for integrity protection and ciphering algorithm for ciphering. In some embodiments, the response message (e.g., the NAS Security Mode Complete message) may include the PEI in case the AMF requested the PEI in the security message (e.g., the NAS Security Mode Command message) . In some embodiments, the AMF may set the NAS COUNTs to zero if the horizontal derivation of KAMF is performed. In some embodiments, the UE may include the complete initial NAS message in the response message. In some embodiments, the UE may include the complete initial NAS message in the NAS container in the response message.
[0146] In some embodiments, if the verification of the security message (e.g., the NAS Security Mode Command message) is not successful by the UE, the UE may reply with a reject message (e.g., NAS Security Mode Reject message) . The reject message (e.g., NAS Security Mode Reject message) and all subsequent NAS messages may be protected with the previous, if any, 5G NAS security context, e.g., the 5G NAS security context used prior to the failed security message (e.g., the NAS Security Mode Command message) . In some embodiments, if no 5G NAS security context existed prior to the security message (e.g., the NAS Security Mode Command message) , the reject message (e.g., NAS Security Mode Reject message) may remain unprotected.
[0147] In some embodiments, the AMF may decipher and check the integrity protection on the response message (e.g., the NAS Security Mode Complete message) using the key and algorithm indicated in the security message. In some embodiments, the NAS downlink ciphering at the AMF with this security context may start after receiving the response message (e.g., the NAS Security Mode Complete message) .
[0148] In some embodiments, the response message (e.g., the NAS Security Mode Complete message) may contain: the NAS MAC. In some embodiments, the NAS MAC is used to authenticate a message and ensure its integrity. The NAS MAC is the output of integrity protection algorithm (or authenticated encryption algorithm with plaintext setting to NULL) , while the input of the algorithm is the message and a key. In this scenario, the input message may include the complete initial NAS message in NAS container.
[0149] 1d. The AMF activates NAS downlink ciphering.
[0150] An example is provided below.
[0151] In some embodiments, the UE supports ciphering algorithm NEA0, NEA1, NEA2 and NEA4, supports integrity algorithm NIA0, NIA1, NIA2 and NIA4 and supports authenticated algorithm NCA4 and NCA5.
[0152] In some embodiments, the AMF may select the algorithms with highest priority in its locally configured list of algorithms that are also present in the received UE security capabilities. For example, NEA1, NIA1 and NCA4.
[0153] In some embodiments, if AMF decides to use the AEAD mode, the Security Mode Command message may contain the identifiers of NEA1, NIA1 and NCA4, also the AEAD indicator “1” .
[0154] In some embodiments, if AMF decides not to use the AEAD mode, the Security Mode Command message may contain the identifiers of NEA1, NIA1 and NCA4, also the AEAD indicator “0” .
[0155] Aspect 3:
[0156] FIG. 5 shows a schematic diagram of an AS SMC procedure according to an embodiment of the present disclosure. In some embodiments, the procedure may include at least one of the following operations.
[0157] 1a. The gNB / ng-eNB decides whether to use AEAD mode for the AS protection and starts the RRC integrity protection based on the chosen mode. In some embodiments, if the gNB / ng-eNB decides to use the AEAD mode, the authentication encryption algorithm may be used for integrity. Otherwise, the integrity algorithm is used. For example, the gNB / ng-eNB decides to use the AEAD mode based on the local configuration that an authenticated encryption algorithm has the highest priority according to the configured lists.
[0158] 1b. The gNB / ng-eNB sends a security message (e.g., the AS Security Mode Command message) to UE. In some embodiments, the message may contain the selected RRC and / or the UP encryption algorithms, integrity algorithms, and authenticated encryption algorithms. In some embodiments, an AEAD indicator is also includes in the message to indicates the decision of gNB / ng-eNB on whether to use AEAD mode for the AS protection. For example, the AEAD indicator is set to “1” when gNB / ng-eNB decide to use AEAD mode, and the indicator is set to “0” when the gNB / ng-eNB decides not to use AEAD mode. In some embodiments, this security message may be integrity protected with RRC integrity algorithm (e.g., with a RRC integrity key based on the current KgNB) or RRC authenticated encryption algorithm (e.g., with a RRC authenticated encryption key based on the current KgNB) . In some embodiments, whether to use integrity algorithm or authenticated encryption algorithm for the integrity protection of the security message depends on whether to use AEAD mode (e.g., whether the AEAD indicator indicates to use the AEAD) . In some embodiments, the security message (e.g., the AS Security Mode Command message) may contain: the MAC-I (message authentication code for integrity) . In some embodiments, the MAC-I is used to authenticate a message and ensure its integrity. The MAC-I is the output of integrity protection algorithm (or authenticated encryption algorithm with plaintext setting to NULL) , while the input of the algorithm is the message and a key. In this scenario, the input message is the parameters in the security message described above, including the selected RRC and / or the UP encryption algorithms, integrity algorithms, and authenticated encryption algorithms, etc.
[0159] 1c. The gNB / ng-eNB starts RRC downlink ciphering (encryption) after sending the security message.
[0160] 2a. The UE may verify the security message (e.g., the AS Security Mode Command message) . In some embodiments, if the received AEAD indicator indicates that AEAD mode shall be used, the UE uses the indicated RRC authenticated encryption algorithm and the RRC authenticated encryption key to verify the integrity protection of the security message. In some embodiments, if the received AEAD indicator indicates that the AEAD mode shall not be used, the UE uses the indicated RRC integrity algorithm and the RRC integrity key based on the KgNB to verify the integrity protection of the security message. In some embodiments, if the verification of the integrity of the security message (e.g., the AS Security Mode Command message) is successful, the UE may start RRC integrity protection and RRC downlink deciphering. In some embodiments, if the received AEAD indicator indicates that AEAD mode shall be used, the UE uses RRC authenticated encryption algorithm for the RRC integrity protection and ciphering / deciphering (e.g., performing the RRC integrity and ciphering / deciphering on the response message (e.g., the AS Security Mode Complete message) to be sent to the gNB / ng-eNB) . In some embodiments, if the received AEAD indicator indicates that the AEAD mode shall not be used, the UE uses RRC integrity algorithm and ciphering algorithm for the RRC integrity protection and ciphering / deciphering.
[0161] 2b. The UE sends a response message (e.g., the AS Security Mode Complete message) to the gNB / ng-eNB. In some embodiments, the message may be integrity protected with the selected RRC algorithm indicated in the security message described in operation 1b. In some embodiments, if the AEAD mode is used, the UE uses RRC authenticated encryption algorithm for integrity protection. In some embodiments, if the AEAD mode is not used, the UE uses RRC integrity algorithm for integrity protection.
[0162] In some embodiments, the response message (e.g., the AS Security Mode Complete message) may contain: the MAC-I. In some embodiments, the MAC-I is used to authenticate a message and ensure its integrity. The MAC-I is the output of integrity protection algorithm (or authenticated encryption algorithm with plaintext setting to NULL) , while the input of the algorithm is the message and a key. In this scenario, the input message is the response message described above.
[0163] 2c. The UE starts the RRC uplink ciphering (encryption) .
[0164] 1d. The gNB / ng-eNB starts the RRC uplink deciphering (decryption) .
[0165] Aspect 4:
[0166] In some embodiments, another NAS SMC procedure is provided. This procedure has many aspects substantially identical to the NAS SMC procedure in Aspect 2. The difference is, in this NAS SMC procedure, the AMF sends the AEAD usage policy instead of an indicator to the UE in the security message (e.g., the NAS Security Mode Command message) . That is, the security message contains the UE security capabilities (e.g., the replayed UE security capabilities sent by the UE to the AMF in previous procedures (e.g., sent via the registration request in the procedure described in embodiments in Aspect 1) ) , the selected NAS ciphering algorithm, integrity algorithm, authenticated encryption algorithm, the ngKSI for identifying the KAMF, and / or an AEAD usage policy. The AEAD usage policy is to indicate the decision of the AMF on whether and / or how to use the AEAD mode for the NAS protection.
[0167] In some embodiments, the AMF decides whether to use the AEAD mode for the NAS protection and activates the NAS integrity protection before sending a security message for the NAS security (e.g., the NAS Security Mode Command message) . Details of this operation can be ascertained by referring to the operation 1a in Aspect 2, and will not be repeated herein.
[0168] In some embodiments, the AMF sends a security message (e.g., the NAS Security Mode Command message) to the UE. In some embodiments, the security message may contain: the UE security capabilities (e.g., the replayed UE security capabilities sent by the UE to the AMF in previous procedures (e.g., sent via the registration request in the procedure described in embodiments in Aspect 1) ) , the selected NAS algorithms (e.g., including ciphering algorithm, integrity algorithm, and / or authenticated encryption algorithm) , and / or the ngKSI for identifying the KAMF. In some embodiments, an AEAD usage policy is also included in the message to indicate the decision of the AMF on whether and / or how to use the AEAD mode for the NAS protection. Details of this operation can be ascertained by referring to the operation 1b in Aspect 2, and will not be repeated herein.
[0169] In some embodiments, for example, the AEAD usage policy can indicate the authenticated encryption algorithm is always used. In some embodiments, for example, the AEAD usage policy can indicate the authenticated encryption algorithm is used when the message requires both encryption and integrity protections, and the integrity algorithm is used when the message requires only integrity protection. In some embodiments, for example, the AEAD usage policy can indicate the authenticated encryption algorithm is not used.
[0170] In some embodiments, the AMF activates the NAS uplink deciphering after sending the security message.
[0171] In some embodiments, the UE may verify the security message. In some embodiments, the verification includes checking that the UE security capabilities sent by the AMF match the ones stored in the UE to ensure that these UE security capabilities were not modified by an attacker and verifying the integrity protection. In some embodiments, the UE verifies the security message based on the AEAD usage policy in the security message.
[0172] For example, if the AEAD usage policy indicates that the authenticated encryption algorithm is always used, when the UE receives the security message (e.g., the NAS Security Mode Command message) , the UE verifies the security message using the authenticated encryption algorithm. Similarly, the UE transmits the response message (e.g., the NAS Security Mode Complete message) ciphered and integrity protected by using the authenticated encryption algorithm.
[0173] As another example, the AEAD usage policy indicates that the authenticated encryption algorithm is used when the message requires both encryption and integrity protections and the integrity algorithm is used when the message requires only integrity protection. When the UE receives the security message (e.g., the NAS Security Mode Command message) , the UE verifies the security message using the integrity algorithm in response to that the security message has only integrity protection. However, the UE transmits the response message ciphered and integrity protected by using the authenticated encryption algorithm in response to that the response message requires both encryption and integrity protections.
[0174] Details of the verification can be ascertained by referring to the operation 2a in Aspect 2, and will not be repeated herein.
[0175] In some embodiments, if the verification of the integrity of the security message is successful, the UE may start the NAS integrity protection and ciphering / deciphering with the security context indicated by the ngKSI (e.g., performing the NAS integrity and ciphering on the security message (e.g., the NAS Security Mode Complete message) to be sent to the AMF) .
[0176] In some embodiments, based on the AEAD usage policy, if AEAD mode shall be used, the UE uses NAS authenticated encryption algorithm for the NAS integrity protection and ciphering / deciphering. In some embodiments, based on the AEAD usage policy, if AEAD mode shall not be used, the UE uses NAS integrity algorithm and ciphering algorithm for the NAS integrity protection and ciphering / deciphering.
[0177] In some embodiments, after the NAS integrity protection and ciphering / deciphering, the UE sends a response message (e.g., the NAS Security Mode Complete message) to the AMF, in which the response message is ciphered and integrity protected. In some embodiments, based on the AEAD usage policy, if the AEAD mode is used, the UE uses authenticated encryption algorithm for ciphering and integrity protection. In some embodiments, based on the AEAD usage policy, if the AEAD mode is not used, the UE uses integrity algorithm for integrity protection and ciphering algorithm for ciphering.
[0178] In some embodiments, if the verification of the security message (e.g., the NAS Security Mode Command message) is not successful by the UE, the UE may reply with a reject message (e.g., NAS Security Mode Reject message) .
[0179] In some embodiments, the AMF may decipher and check the integrity protection on the response message (e.g., the NAS Security Mode Complete message) .
[0180] Details of these operations can be ascertained by referring to the operation 2b in Aspect 2, and will not be repeated herein.
[0181] In some embodiments, after receiving the response message, the AMF activates NAS downlink ciphering.
[0182] Details of this NAS SMC procedure can be ascertained by referring to the embodiments in Aspect 2, and will not be repeated herein.
[0183] Aspect 5:
[0184] In some embodiments, another AS SMC procedure is provided. This procedure has many aspects substantially identical to the AS SMC procedure in Aspect 3. The difference is, in this AS SMC procedure, the gNB / ng-eNB sends the AEAD usage policy instead of an indicator to the UE in the security message (e.g., the AS Security Mode Command message) . That is, the security message sent from gNB / ng-eNB to UE may contain the selected RRC and / or UP encryption algorithm, integrity algorithms authenticated encryption algorithms, and / or an AEAD usage policy. The AEAD usage policy is to indicate the decision of the gNB / ng-eNB on whether and how to use AEAD mode for the RRC and / or the UP protection. The UE’s algorithm selection may follow the AEAD usage policy sent by gNB / ng-eNB.
[0185] In some embodiments, the gNB / ng-eNB decides whether to use AEAD mode for the AS protection and starts the RRC integrity protection based on the chosen mode. Details of this operation can be ascertained by referring to the operation 1a in Aspect 3, and will not be repeated herein.
[0186] In some embodiments, the gNB / ng-eNB sends a security message (e.g., the AS Security Mode Command message) to UE. In some embodiments, the message may contain the selected RRC and / or the UP encryption algorithms, integrity algorithms, and authenticated encryption algorithms. In some embodiments, an AEAD usage policy is also includes in the message to indicates the decision of gNB / ng-eNB on whether and / or how to use the AEAD mode for the AS protection. Details of this operation can be ascertained by referring to the operation 1b in Aspect 3, and will not be repeated herein.
[0187] In some embodiments, for example, the AEAD usage policy can indicate the authenticated encryption algorithm is always used. In some embodiments, for example, the AEAD usage policy can indicate the authenticated encryption algorithm is used when the message requires both encryption and integrity protections, and the integrity algorithm is used when the message requires only integrity protection. In some embodiments, for example, the AEAD usage policy can indicate the authenticated encryption algorithm is not used.
[0188] In some embodiments, the gNB / ng-eNB starts RRC downlink ciphering (encryption) after sending the security message.
[0189] In some embodiments, the UE may verify the security message (e.g., the AS Security Mode Command message) . In some embodiments, the UE verifies the security message based on the AEAD usage policy in the security message.
[0190] For example, if the AEAD usage policy indicates that the authenticated encryption algorithm is always used, when the UE receives the security message (e.g., the AS Security Mode Command message) , the UE verifies the security message using the authenticated encryption algorithm. Similarly, the UE transmits the response message ciphered and integrity protected by using the authenticated encryption algorithm.
[0191] As another example, if the AEAD usage policy indicates that the authenticated encryption algorithm is used when the message requires both encryption and integrity protections and the integrity algorithm is used when the message requires only integrity protection. When the UE receives the security message (e.g., the AS Security Mode Command message) , the UE verifies the security message using the integrity algorithm in response to that the security message has only integrity protection. However, the UE transmits the response message (e.g., the AS Security Mode Complete message) ciphered and integrity protected by using the authenticated encryption algorithm in response to that the response message requires both encryption and integrity protections.
[0192] Details of the verification can be ascertained by referring to the operation 2a in Aspect 3, and will not be repeated herein.
[0193] In some embodiments, based on the received AEAD usage policy, if AEAD mode shall be used, the UE uses the indicated RRC authenticated encryption algorithm and the RRC authenticated encryption key to verify the integrity protection of the security message. In some embodiments, based on the received AEAD usage policy, if the AEAD mode shall not be used, the UE uses the indicated RRC integrity algorithm and the RRC integrity key based on the KgNB to verify the integrity protection of the security message.
[0194] In some embodiments, if the verification of the integrity of the security message (e.g., the AS Security Mode Command message) is successful, the UE may start RRC integrity protection and RRC downlink deciphering. In some embodiments, based on the received AEAD usage policy, if AEAD mode shall be used, the UE uses RRC authenticated encryption algorithm for the RRC integrity protection and ciphering / deciphering (e.g., performing the RRC integrity and ciphering on the security message (e.g., the AS Security Mode Complete message) to be sent to the gNB / ng-eNB) . In some embodiments, based on the received AEAD usage policy, if AEAD mode shall not be used, the UE uses RRC integrity algorithm and ciphering algorithm for the RRC integrity protection and ciphering / deciphering.
[0195] After RRC integrity protection and RRC downlink deciphering, the UE sends a response message (e.g., the AS Security Mode Complete message) to the gNB / ng-eNB. In some embodiments, the message may be integrity protected with the selected RRC algorithm based on the received AEAD usage policy in the security message. In some embodiments, based on the received AEAD usage policy, if the AEAD mode is used, the UE uses RRC authenticated encryption algorithm for integrity protection. In some embodiments, based on the received AEAD usage policy, if the AEAD mode is not used, the UE uses RRC integrity algorithm for integrity protection. Details of these operations can be ascertained by referring to the operation 2b in Aspect 3, and will not be repeated herein.
[0196] After sending the response message, the UE starts the RRC uplink ciphering (encryption) .
[0197] After receiving the response message, the gNB / ng-eNB starts the RRC uplink deciphering (decryption) .
[0198] Details of this AS SMC procedure can be ascertained by referring to the embodiments in Aspect 3, and will not be repeated herein.
[0199] Aspect 6:
[0200] FIG. 6 shows a schematic diagram of a NAS SMC procedure according to an embodiment of the present disclosure.
[0201] In some embodiments, in the NAS SMC procedure, the AMF chooses ciphering algorithm and integrity algorithm, or authentication algorithm. In some embodiments, the UE decides whether to use the AEAD mode based on the receiving algorithms. In some embodiments, the procedure may include at least one of the following operations.
[0202] 1a. The AMF decides whether to use the AEAD mode for the NAS protection and activates the NAS integrity protection before sending a security message for the NAS security (e.g., the NAS Security Mode Command message) . For example, the AMF decides to use the AEAD mode for the NAS protection based on the local configuration that an authenticated encryption algorithm has the highest priority according to the configured lists.
[0203] 1b. The AMF sends a security message (e.g., the NAS Security Mode Command message) to the UE. The security message may contain: the UE security capabilities (e.g., the replayed UE security capabilities sent by the UE to the AMF in previous procedures (e.g., sent via the registration request in the procedure described in embodiments in Aspect 1) ) , the selected NAS algorithms (e.g., including either ciphering algorithm and integrity algorithm, or authenticated encryption algorithm) , and / or the ngKSI for identifying the KAMF. In some embodiments, if the AMF decides to use the AEAD mode, only authenticated encryption algorithm may be sent. If the AMF decides to refrain from using the AEAD mode, only ciphering algorithm and integrity algorithm may be sent. In some embodiments, the security message may contain: K_AMF_change_flag to indicate a new KAMF is calculated, a flag requesting the complete initial NAS message, Anti-Bidding down Between Architectures (ABBA) parameter. In the case of horizontal derivation of KAMF during mobility registration update or during multiple registration in same PLMN, K_AMF_change_flag may be included in the security message. In some embodiments, the security message (e.g., the NAS Security Mode Command message) may contain: the NAS MAC. Details of the NAS MAC can be ascertained by referring to the embodiments in Aspect 2 above and will not be repeated herein.
[0204] If the AMF decides to use the AEAD mode, the security message may be integrity protected with the authenticated encryption algorithm (e.g., with a NAS authenticated encryption key) . If not, this security message may be integrity protected with the NAS integrity key (e.g., with a NAS integrity key) .
[0205] 1c. The AMF activates NAS uplink deciphering after sending the security message.
[0206] 2a. The UE may verify the security message. This includes checking that the UE security capabilities sent by the AMF match the ones stored in the UE to ensure that these were not modified by an attacker and verifying the integrity protection. In some embodiments, if the authenticated encryption algorithm is received (e.g., it may indicate the AEAD mode is used) , the UE uses the indicated NAS authenticated encryption algorithm and the NAS authenticated encryption key to verify the integrity protection of the security message. In some embodiments, if the integrity algorithm is received (e.g., it may indicate the AEAD mode is not used) , the UE uses the indicated NAS integrity algorithm and the NAS integrity key based on the KAMF indicated by the ngKSI to verify the integrity protection of the security message.
[0207] In some embodiments, if the verification of the integrity of the NAS Security Mode Command message is successful, the UE may start the NAS integrity protection and ciphering / deciphering with the security context indicated by the ngKSI (e.g., performing the NAS integrity and ciphering on the security message (e.g., the NAS Security Mode Complete message) to be sent to the AMF) . In some embodiments, to use the authenticated encryption algorithm or the ciphering algorithm and integrity algorithm on the NAS integrity protection and ciphering / deciphering depends on the algorithm it received in the security message. For example, when the UE receives the authenticated encryption algorithm in the security message, the UE use the authenticated encryption algorithm on the NAS integrity protection and ciphering / deciphering. When the UE receives the ciphering algorithm and integrity algorithm in the security message, the UE use the ciphering algorithm and integrity algorithm on the NAS integrity protection and ciphering / deciphering.
[0208] 2b. The UE sends a response message (e.g., NAS Security Mode Complete message) to the AMF, in which the response message is ciphered and integrity protected. In some embodiments, if the AEAD mode is used, the UE uses the authenticated encryption algorithm for ciphering and integrity protection. In some embodiments, if the AEAD mode is not used, the UE uses the integrity algorithm for the integrity protection and the ciphering algorithm for ciphering. In some embodiments, the NAS Security Mode Complete message may include the PEI in case the AMF requested it in the NAS Security Mode Command message. In some embodiments, the AMF may set the NAS COUNTs to zero if the horizontal derivation of KAMF is performed. The UE may include the complete initial NAS message.
[0209] In some embodiments, if the verification of the security message is not successful in the UE, it may reply with a reject message (e.g., the NAS Security Mode Reject message) . In some embodiments, the reject message and all subsequent NAS messages may be protected with the previous, if any, 5G NAS security context, i.e., the 5G NAS security context used prior to the failed security message. In some embodiments, if no 5G NAS security context existed prior to the security message, the reject message may remain unprotected.
[0210] In some embodiments, the AMF may decipher and check the integrity protection on the response message using the key and algorithm indicated in the security message. In some embodiments, the NAS downlink ciphering at the AMF with this security context may start after receiving the response message. In some embodiments, the response message (e.g., the NAS Security Mode Complete message) may contain: the NAS MAC. Details of the NAS MAC can be ascertained by referring to the embodiments in Aspect 2 above and will not be repeated herein.
[0211] 1d. The AMF activates NAS downlink ciphering.
[0212] An example is provided below.
[0213] In some embodiments, the UE supports the ciphering algorithm NEA0, NEA1, NEA2 and NEA4, supports the integrity algorithm NIA0, NIA1, NIA2 and NIA4 and supports the authenticated algorithm NCA4 and NCA5.
[0214] In some embodiments, the AMF may select the algorithms with highest priority in its locally configured list of algorithms that are also present in the received UE security capabilities. For example, NEA1, NIA1 and NCA4.
[0215] In some embodiments, if the AMF decides to use the AEAD mode, the Security Mode Command message may contain the identifiers of NCA4.
[0216] In some embodiments, if the AMF decides not to use the AEAD mode, the Security Mode Command message may contain the identifiers of NEA1, NIA1.
[0217] Aspect 7:
[0218] In some embodiments, another AS SMC procedure is provided. This procedure has many aspects substantially identical to the AS SMC procedure in Aspect 3. The difference is, in this AS SMC procedure, instead of using the AEAD indicator, the gNB / ng-eNB sends the selected RRC and / or UP encryption and integrity algorithms or the gNB / ng-eNB sends the selected RRC and / or UP authenticated encryption algorithms to indicate whether to use AEAD mode.
[0219] That is, in some embodiments, the security message (e.g., the AS Security Mode Command message) sent from gNB / ng-eNB to UE contains the selected RRC and / or UP encryption and integrity algorithms or contains the selected RRC and / or UP authenticated encryption algorithms. In some embodiments, if the gNB / ng-eNB decides to use the AEAD mode for the RRC and / or the UP protection, the selected RRC and / or UP authenticated encryption algorithms may be included in the message. In some embodiments, if the gNB / ng-eNB decides to use the AEAD mode, only authenticated encryption algorithm may be sent. If the gNB / ng-eNB decides to refrain from using the AEAD mode, only ciphering algorithm and integrity algorithm may be sent.
[0220] In some embodiments, upon receiving the security message, the UE may check whether the RRC and / or UP authenticated encryption algorithm is included. If the RRC and / or UP authenticated encryption algorithm is included, the UE may use the authenticated encryption algorithm for RRC and / or UP protection. If the RRC and / or UP authenticated encryption algorithm is absent from the security message, the UE may use the selected RRC and / or UP encryption and integrity algorithms for ciphering / deciphering and integrity protection.
[0221] In some embodiments, the gNB / ng-eNB decides whether to use AEAD mode for the AS protection and starts the RRC integrity protection based on the chosen mode. Details of this operation can be ascertained by referring to the operation 1a in Aspect 3, and will not be repeated herein.
[0222] In some embodiments, the gNB / ng-eNB sends a security message (e.g., the AS Security Mode Command message) to UE. In some embodiments, security message contains the selected RRC and / or UP encryption and integrity algorithms or contains the selected RRC and / or UP authenticated encryption algorithms. In some embodiments, if the gNB / ng-eNB decides to use the AEAD mode, only RRC and / or UP authenticated encryption algorithms may be sent. If the gNB / ng-eNB decides to refrain from using the AEAD mode, only the selected RRC and / or UP encryption and integrity algorithms may be sent. Details of this operation can be ascertained by referring to the operation 1b in Aspect 3, and will not be repeated herein.
[0223] In some embodiments, the gNB / ng-eNB starts RRC downlink ciphering (encryption) after sending the security message.
[0224] In some embodiments, the UE may verify the security message (e.g., the AS Security Mode Command message) . In some embodiments, the UE verifies the security message based on the algorithm (s) in the security message. In some embodiments, the UE may check whether the RRC and / or UP authenticated encryption algorithm is included in the security message. If the RRC and / or UP authenticated encryption algorithm is included (it may indicate AEAD mode shall be used) , the UE uses the indicated RRC authenticated encryption algorithm and the RRC authenticated encryption key to verify the integrity protection of the security message. If the RRC and / or UP authenticated encryption algorithm is absent from the security message (it may indicate AEAD mode shall not be used) , the UE uses the indicated RRC integrity algorithm and the RRC integrity key based on the KgNB to verify the integrity protection of the security message.
[0225] In some embodiments, if the verification of the integrity of the security message (e.g., the AS Security Mode Command message) is successful, the UE may start RRC integrity protection and RRC downlink deciphering. In some embodiments, based on the algorithm (s) in the security message, if AEAD mode shall be used, the UE uses RRC authenticated encryption algorithm for the RRC integrity protection and ciphering / deciphering (e.g., performing the RRC integrity and ciphering on the security message (e.g., the AS Security Mode Complete message) to be sent to the gNB / ng-eNB) . In some embodiments, based on the algorithm (s) in the security message, if AEAD mode shall not be used, the UE uses RRC integrity algorithm and ciphering algorithm for the RRC integrity protection and ciphering / deciphering.
[0226] After RRC integrity protection and RRC downlink deciphering, the UE sends a response message (e.g., the AS Security Mode Complete message) to the gNB / ng-eNB. In some embodiments, the message may be integrity protected with the selected RRC algorithm based on the algorithm (s) in the security message. In some embodiments, based on the algorithm (s) in the security message, if the AEAD mode shall be used, the UE uses RRC authenticated encryption algorithm for integrity protection. In some embodiments, based on the algorithm (s) in the security message, if the AEAD mode shall not be used, the UE uses RRC integrity algorithm for integrity protection. Details of these operations can be ascertained by referring to the operation 2b in Aspect 3, and will not be repeated herein.
[0227] After sending the response message, the UE starts the RRC uplink ciphering (encryption) .
[0228] After receiving the response message, the gNB / ng-eNB starts the RRC uplink deciphering (decryption) .
[0229] Details of this AS SMC procedure can be ascertained by referring to the embodiments in Aspect 3, and will not be repeated herein.
[0230] Aspect 8:
[0231] In some embodiments, another NAS SMC procedure is provided. This procedure has many aspects substantially identical to the NAS SMC procedure in Aspect 6. The difference is, in this NAS SMC procedure, the ciphering and integrity algorithm may always be sent, while in embodiments in Aspect 6, the ciphering and integrity algorithm may be sent to UE only if it is decided to be used.
[0232] That is, in some embodiments, the AMF may send the security message to the UE containing: the UE security capabilities (e.g., the replayed UE security capabilities sent by the UE to the AMF in previous procedures (e.g., sent via the registration request in the procedure described in embodiments in Aspect 1) ) , the selected ciphering algorithm, integrity algorithm, and the ngKSI for identifying the KAMF. In some embodiments, the NAS Security Mode Command message may contain: K_AMF_change_flag to indicate a new KAMF is calculated, a flag requesting the complete initial NAS message, Anti-Bidding down Between Architectures (ABBA) parameter. In some embodiments, if the AMF decides to use the AEAD mode, the selected NAS authenticated encryption algorithm may also be included in the message.
[0233] In some embodiments, the UE may verify the security message. Upon receiving the security message, the UE may check whether the NAS authenticated encryption algorithm is included. If the NAS authenticated encryption algorithm is included (it may indicate the AEAD mode shall be used) , the UE may use the authenticated encryption algorithm for NAS protection. If the NAS authenticated encryption algorithm is absent from the security message (it may indicate the AEAD mode shall not be used) , the UE may use the selected ciphering algorithm and integrity algorithm.
[0234] In some embodiments, the AMF decides whether to use the AEAD mode for the NAS protection and activates the NAS integrity protection before sending a security message for the NAS security (e.g., the NAS Security Mode Command message) . Details of this operation can be ascertained by referring to the operation 1a in Aspect 6, and will not be repeated herein.
[0235] In some embodiments, the AMF sends a security message (e.g., the NAS Security Mode Command message) to the UE. In some embodiments, the security message may contain: the UE security capabilities (e.g., the replayed UE security capabilities sent by the UE to the AMF in previous procedures (e.g., sent via the registration request in the procedure described in embodiments in Aspect 1) ) , the selected NAS algorithms (e.g., including ciphering algorithm and integrity algorithm) , and / or the ngKSI for identifying the KAMF. In some embodiments, if the AMF decides to use the AEAD mode, the selected NAS authenticated encryption algorithm may also be included in the security message. If the AMF decides to refrain from using the AEAD mode, the selected NAS authenticated encryption algorithm may be absent from the security message. Details of this operation can be ascertained by referring to the operation 1b in Aspect 6, and will not be repeated herein.
[0236] In some embodiments, the AMF activates the NAS uplink deciphering after sending the security message.
[0237] In some embodiments, the UE may verify the security message. In some embodiments, the verification includes checking that the UE security capabilities sent by the AMF match the ones stored in the UE to ensure that these UE security capabilities were not modified by an attacker and verifying the integrity protection. In some embodiments, the UE verifies the security message based on the received algorithm (s) in the security message.
[0238] For example, if the selected NAS authenticated encryption algorithm is included in the security message, the UE verifies the security message using the authenticated encryption algorithm. If the selected NAS authenticated encryption algorithm is absent from the security message, the UE verifies the security message using the integrity algorithm. Details of the verification can be ascertained by referring to the operation 2a in Aspect 6, and will not be repeated herein.
[0239] In some embodiments, if the verification of the integrity of the security message is successful, the UE may start the NAS integrity protection and ciphering / deciphering with the security context indicated by the ngKSI (e.g., performing the NAS integrity and ciphering on the security message (e.g., the NAS Security Mode Complete message) to be sent to the AMF) .
[0240] In some embodiments, based on the received algorithm (s) in the security message, if AEAD mode shall be used, the UE uses NAS authenticated encryption algorithm for the NAS integrity protection and ciphering / deciphering. In some embodiments, based on the received algorithm (s) in the security message, if AEAD mode shall not be used, the UE uses NAS integrity algorithm and ciphering algorithm for the NAS integrity protection and ciphering / deciphering.
[0241] In some embodiments, after the NAS integrity protection and ciphering / deciphering, the UE sends a response message (e.g., the NAS Security Mode Complete message) to the AMF, in which the response message is ciphered and integrity protected. In some embodiments, based on the received algorithm (s) in the security message, if the AEAD mode is used, the UE uses authenticated encryption algorithm for ciphering and integrity protection. In some embodiments, based on the received algorithm (s) in the security message, if the AEAD mode is not used, the UE uses integrity algorithm for integrity protection and ciphering algorithm for ciphering.
[0242] In some embodiments, if the verification of the security message (e.g., the NAS Security Mode Command message) is not successful by the UE, the UE may reply with a reject message (e.g., NAS Security Mode Reject message) .
[0243] In some embodiments, the AMF may decipher and check the integrity protection on the response message (e.g., the NAS Security Mode Complete message) .
[0244] Details of these operations can be ascertained by referring to the operation 2b in Aspect 6, and will not be repeated herein.
[0245] In some embodiments, after receiving the response message, the AMF activates NAS downlink ciphering.
[0246] An example is provided below.
[0247] In some embodiments, the UE supports ciphering algorithm NEA0, NEA1, NEA2 and NEA4, supports integrity algorithm NIA0, NIA1, NIA2 and NIA4 and supports authenticated algorithm NCA4 and NCA5.
[0248] In some embodiments, the AMF may select the algorithms with highest priority in its locally configured list of algorithms that are also present in the received UE security capabilities. For example, NEA2, NIA1 and NCA4.
[0249] In some embodiments, if the AMF decides to use the AEAD mode, the Security Mode Command message may contain the identifiers of NEA1, NIA1, NCA4.
[0250] In some embodiments, if the AMF decides not to use the AEAD mode, the Security Mode Command message may contain the identifiers of NEA1, NIA1.
[0251] Details of this NAS SMC procedure can be ascertained by referring to the embodiments in Aspect 6, and will not be repeated herein.
[0252] Aspect 9:
[0253] In some embodiments, another AS SMC procedure is provided. This procedure has many aspects substantially identical to the AS SMC procedure in Aspect 7. The difference is, in this AS SMC procedure, the ciphering and integrity algorithm may always be sent, while in embodiments in Aspect 7, the ciphering and integrity algorithm may be sent to UE only if it is decided to be used.
[0254] That is, in some embodiments, the security message (e.g., the AS Security Mode Command message) sent from the gNB / ng-eNB to the UE may contain the selected RRC and / or UP encryption algorithm, integrity algorithms. In some embodiments, if the gNB / ng-eNB decides to use the AEAD mode for the RRC and / or the UP protection, the selected RRC and / or UP authenticated encryption algorithms may also be included in the security message. In some embodiments, if the gNB / ng-eNB decides to use the AEAD mode, all ciphering algorithm, integrity algorithm and authenticated encryption algorithm may be sent. If the gNB / ng-eNB decides to refrain from using the AEAD mode, only ciphering algorithm and integrity algorithm may be sent.
[0255] In some embodiments, upon receiving the security message, the UE may check whether the RRC and / or the UP authenticated encryption algorithm is included. In some embodiments, if the RRC and / or the UP authenticated encryption algorithm is included (it may indicate the AEAD mode shall be used) , the UE may use the authenticated encryption algorithm for RRC and / or UP protection. In some embodiments, if the RRC and / or the UP authenticated encryption algorithm is absent from the security message (it may indicate the AEAD mode shall not be used) , the UE may use the selected RRC and / or UP encryption and integrity algorithms.
[0256] In some embodiments, the gNB / ng-eNB decides whether to use AEAD mode for the AS protection and starts the RRC integrity protection based on the chosen mode. Details of this operation can be ascertained by referring to the operation 1a in Aspect 7, and will not be repeated herein.
[0257] In some embodiments, the gNB / ng-eNB sends a security message (e.g., the AS Security Mode Command message) to UE. In some embodiments, the security message contains the selected RRC and / or UP encryption and integrity algorithms. In some embodiments, the security message further contains the selected RRC and / or UP authenticated encryption algorithms. In some embodiments, if the gNB / ng-eNB decides to use the AEAD mode, the selected RRC and / or UP authenticated encryption algorithms are included in the security message. In some embodiments, if the gNB / ng-eNB decides to refrain from using the AEAD mode, the selected RRC and / or UP authenticated encryption algorithms are absent from the security message.
[0258] In some embodiments, the gNB / ng-eNB starts RRC downlink ciphering (encryption) after sending the security message.
[0259] In some embodiments, the UE may verify the security message (e.g., the AS Security Mode Command message) . In some embodiments, the UE verifies the security message based on the algorithm (s) in the security message. In some embodiments, the UE may check whether the RRC and / or UP authenticated encryption algorithm is included in the security message. If the RRC and / or UP authenticated encryption algorithm is included (it may indicate AEAD mode shall be used) , the UE uses the indicated RRC authenticated encryption algorithm and the RRC authenticated encryption key to verify the integrity protection of the security message. If the RRC and / or UP authenticated encryption algorithm is absent from the security message (it may indicate AEAD mode shall not be used) , the UE uses the indicated RRC integrity algorithm and the RRC integrity key based on the KgNB to verify the integrity protection of the security message.
[0260] In some embodiments, if the verification of the integrity of the security message (e.g., the AS Security Mode Command message) is successful, the UE may start RRC integrity protection and RRC downlink deciphering. In some embodiments, based on the algorithm (s) in the security message, if AEAD mode shall be used, the UE uses RRC authenticated encryption algorithm for the RRC integrity protection and ciphering / deciphering (e.g., performing the RRC integrity and ciphering on the security message (e.g., the AS Security Mode Complete message) to be sent to the gNB / ng-eNB) . In some embodiments, based on the algorithm (s) in the security message, if AEAD mode shall not be used, the UE uses RRC integrity algorithm and ciphering algorithm for the RRC integrity protection and ciphering / deciphering.
[0261] After RRC integrity protection and RRC downlink deciphering, the UE sends a response message (e.g., the AS Security Mode Complete message) to the gNB / ng-eNB. In some embodiments, the message may be integrity protected with the selected RRC algorithm based on the algorithm (s) in the security message. In some embodiments, based on the algorithm (s) in the security message, if the AEAD mode shall be used, the UE uses RRC authenticated encryption algorithm for integrity protection. In some embodiments, based on the algorithm (s) in the security message, if the AEAD mode shall not be used, the UE uses RRC integrity algorithm for integrity protection. Details of these operations can be ascertained by referring to the operation 2b in Aspect 7, and will not be repeated herein.
[0262] After sending the response message, the UE starts the RRC uplink ciphering (encryption) .
[0263] After receiving the response message, the gNB / ng-eNB starts the RRC uplink deciphering (decryption) .
[0264] Details of this AS SMC procedure can be ascertained by referring to the embodiments in Aspect 7, and will not be repeated herein.
[0265] Aspect 10:
[0266] This embodiment may be applied when there is no new identifier introduced for the Authenticated Algorithm. In such scenario, another indicator is introduced to the security message (e.g., the Security Mode Command message) indicate that whether AEAD mode (e.g., the authenticated encryption algorithm) is used.
[0267] In some embodiments, the AMF sends the security message to the UE. In some embodiments, the security message may contain: the UE security capabilities (e.g., the replayed UE security capabilities sent by the UE to the AMF in previous procedures (e.g., sent via the registration request in the procedure described in embodiments in Aspect 1) ) , the selected ciphering algorithm, integrity algorithm, and the ngKSI for identifying the KAMF. In some embodiments, the security message may contain: K_AMF_change_flag to indicate a new KAMF is calculated, a flag requesting the complete initial NAS message, Anti-Bidding down Between Architectures (ABBA) parameter. In some embodiments, an AEAD mode indicator may also be included in the message to indicate whether the AEAD mode is used, i.e., whether to use the authenticated encryption algorithm and which authenticated encryption algorithm is used to protect the NAS message.
[0268] In some embodiments, the AEAD indicator can indicate that the AEAD mode is used and the select algorithm is based on the same algorithm with the selected ciphering algorithm and the integrity algorithm.
[0269] For example, the selected ciphering algorithm and the integrity algorithm are NEA4 and NIA4, which are both 256-bit SNOW 5G based algorithms, and the AEAD indicator indicates that the AEAD mode is used. This means the selected algorithm to be used for NAS protection is 256-bit SNOW 5G based authenticated encryption algorithm, i.e., NCA4.
[0270] In some embodiments, the AEAD indicator can indicate that the AEAD mode is used and the select algorithm is based on the same algorithm with the selected ciphering algorithm.
[0271] For example, the selected ciphering algorithm and integrity algorithm are NEA4 and NIA5, where NEA4 is SNOW 5G based ciphering algorithm and NIA5 is AES based integrity algorithm, and the AEAD indicator indicates that the AEAD mode is used. This means the selected algorithm to be used for NAS protection is 256-bit SNOW 5G based authenticated encryption algorithm, i.e., NCA4.
[0272] In some embodiments, the AEAD indicator can indicate that the AEAD mode is used and the select algorithm is based on the same algorithm with the selected integrity algorithm.
[0273] For example, the selected ciphering algorithm and integrity algorithm are NEA4 and NIA5, where NEA4 is SNOW 5G based ciphering algorithm and NIA5 is AES based integrity algorithm, and the AEAD indicator indicates that the AEAD mode is used. This means the selected algorithm to be used for NAS protection is 256-bit AES based authenticated encryption algorithm, i.e., NCA5.
[0274] In some embodiments, the AEAD indicator described above can be applied to the embodiments in Aspect 2, 4, 6, or 8. For example, said AEAD indicator can replace the AEAD indicator in Aspect 2. As another example, said AEAD indicator may be included in the security message 4, 6, or 8. Details in this regard can be ascertained by referring to the embodiments above, and will not be repeated herein.
[0275] In some embodiments, the AEAD indicator described above can be applied to the embodiments in Aspect 3. That is, the security message described in Aspect 3 may contain an AEAD mode indicator indicating whether the AEAD mode is used and which authenticated encryption algorithm is used to protect the AS message. In some embodiments, the AEAD indicator described above can be applied to the embodiments in Aspect 3, 5, 7, or 9. For example, said AEAD indicator can replace the AEAD indicator in Aspect 3. As another example, said AEAD indicator may be included in the security message in Aspect 5, 7, or 9. Details in this regard can be ascertained by referring to the embodiments above, and will not be repeated herein.
[0276] Some embodiments of the present disclosure provide a mechanism for the UE and the 5GS supporting the AEAD mode to negotiate on the algorithm they used for the NAS and the AS protection.
[0277] Specifically, the UE may include the algorithms it supported in the registration request message sent to the AMF. In some embodiments, the AMF may select the algorithms to be used for the NAS protection, and the gNB / ng-eNB may select the algorithms to be used for the AS protection. Some possible ways are provided for the security mode command procedures.
[0278] In some embodiments, the AMF, gNB, or ng-eNB may always send the selected ciphering algorithm, integrity algorithm, and authenticated encryption algorithms to the UE. To inform the UE how to use these algorithms, the AMF, gNB, or ng-eNB can send at least one of:
[0279] an indicator indicating whether the authenticated encryption algorithm is used; and / or
[0280] an AEAD usage policy indicates when the authenticated encryption algorithm is used.
[0281] In some embodiments, the AMF, gNB, or ng-eNB may not always send the selected authenticated encryption algorithm.
[0282] In some embodiments, the AMF, gNB, or ng-eNB may send the selected ciphering algorithm and integrity algorithm or authenticated encryption algorithms to the UE. If the AEAD mode is decided to be used, the AMF, gNB, or ng-eNB may send the authenticated encryption algorithm and may not send the ciphering algorithm and integrity algorithm. If the AEAD mode is decided not to be used, the AMF, gNB, or ng-eNB may send the selected ciphering algorithm and integrity algorithm and may not send the authenticated encryption algorithm.
[0283] In some embodiments, if the AEAD mode is decided to be used, the AMF, gNB, or ng-eNB may send the authenticated encryption algorithm together with the ciphering algorithm and integrity algorithm. In some embodiments, if the authenticated encryption algorithm is received, the UE may use it to protect the message.
[0284] In some embodiments, if the authenticated algorithms are not assigned values, a new indicator is designed to indicate whether the AEAD mode is used. In some embodiments, if the AEAD mode is used, the select authenticated encryption algorithm is based on the same algorithm with the selected ciphering and / or integrity algorithm.
[0285] FIG. 7 relates to a diagram of a wireless communication terminal 30 according to an embodiment of the present disclosure. The wireless communication terminal 30 may be a tag, a mobile phone, a laptop, a tablet computer, an electronic book or a portable computer system and is not limited herein. The wireless communication terminal 30 may be used to implement the UE described in this disclosure. The wireless communication terminal 30 may include a processor 300 such as a microprocessor or Application Specific Integrated Circuit (ASIC) , a storage unit 310 and a communication unit 320. The storage unit 310 may be any data storage device that stores a program code 312, which is accessed and executed by the processor 300. Embodiments of the storage unit 310 include but are not limited to a subscriber identity module (SIM) , read-only memory (ROM) , flash memory, random-access memory (RAM) , hard-disk, and optical data storage device. The communication unit 320 may a transceiver and is used to transmit and receive signals (e.g., messages or packets) according to processing results of the processor 300. In an embodiment, the communication unit 320 transmits and receives the signals via at least one antenna 322 or via wiring.
[0286] In an embodiment, the storage unit 310 and the program code 312 may be omitted and the processor 300 may include a storage unit with stored program code.
[0287] The processor 300 may implement any one of the steps or operations in exemplified embodiments on the wireless communication terminal 30, e.g., by executing the program code 312.
[0288] The communication unit 320 may be a transceiver. The communication unit 320 may as an alternative or in addition be combining a transmitting unit and a receiving unit configured to transmit and to receive, respectively, signals to and from a wireless communication node.
[0289] In some embodiments, the wireless communication terminal 30 may be used to perform the operations of the UE described in this disclosure. In some embodiments, the processor 300 and the communication unit 320 collaboratively perform the operations described in this disclosure. For example, the processor 300 performs operations and transmit or receive signals, message, and / or information through the communication unit 320.
[0290] FIG. 8 relates to a diagram of a wireless communication node 40 according to an embodiment of the present disclosure. The wireless communication node 40 may be a satellite, a base station (BS) (e.g., a gNB or a ng-eNB) , a network entity, a Domain Name System (DNS) server, a Mobility Management Entity (MME) , Serving Gateway (S-GW) , Packet Data Network (PDN) Gateway (P-GW) , a radio access network (RAN) (e.g., a next generation RAN (NG-RAN) ) , a data network, a core network, a communication node in the core network, or a Radio Network Controller (RNC) , and is not limited herein. In addition, the wireless communication node 40 may include (perform) at least one network function such as an access and mobility management function (AMF) , a session management function (SMF) , a user place function (UPF) , a policy control function (PCF) , an application function (AF) , etc. The wireless communication node 40 may be used to implement the base station described in this disclosure. The wireless communication node 40 may include a processor 400 such as a microprocessor or ASIC, a storage unit 410 and a communication unit 420. The storage unit 410 may be any data storage device that stores a program code 412, which is accessed and executed by the processor 400. Examples of the storage unit 410 include but are not limited to a SIM, ROM, flash memory, RAM, hard-disk, and optical data storage device. The communication unit 420 may be a transceiver and is used to transmit and receive signals (e.g., messages or packets) according to processing results of the processor 400. In an embodiment, the communication unit 420 transmits and receives the signals via at least one antenna 422 or via wiring.
[0291] In an embodiment, the storage unit 410 and the program code 412 may be omitted. The processor 400 may include a storage unit with stored program code.
[0292] The processor 400 may implement any steps or operations described in exemplified embodiments on the wireless communication node 40, e.g., via executing the program code 412.
[0293] The communication unit 420 may be a transceiver. The communication unit 420 may as an alternative or in addition be combining a transmitting unit and a receiving unit configured to transmit and to receive, respectively, signals, messages, or information to and from a wireless communication node or a wireless communication terminal.
[0294] In some embodiments, the wireless communication node 40 may be used to perform the operations of the AMF, gNB, or ng-eNB described in this disclosure. In some embodiments, the processor 400 and the communication unit 420 collaboratively perform the operations described in this disclosure. For example, the processor 400 performs operations and transmit or receive signals through the communication unit 420.
[0295] A wireless communication method is also provided according to an embodiment of the present disclosure. In an embodiment, the wireless communication method may be performed by using a wireless communication terminal (e.g., a UE) . In an embodiment, the wireless communication terminal may be implemented by using the wireless communication terminal 30 described in this disclosure, but is not limited thereto.
[0296] Referring to FIG. 9, in an embodiment, the wireless communication method includes: transmitting, by a wireless communication terminal to a wireless communication node, a first message using an authenticated encryption with associated data, AEAD, mode according to an AEAD information carried by a second message from the wireless communication node.
[0297] Details in this regard can be ascertained with reference to the paragraphs above, and will not be repeated herein.
[0298] Another wireless communication method is also provided according to an embodiment of the present disclosure. In an embodiment, the wireless communication method may be performed by using a wireless communication node (e.g., AMF, gNB, or ng-eNB) . In an embodiment, the wireless communication node may be implemented by using the wireless communication node 40 described in this disclosure, but is not limited thereto.
[0299] Referring to FIG. 10, in an embodiment, the wireless communication method includes: receiving, by a wireless communication node from a wireless communication terminal, a first message using an authenticated encryption with associated data, AEAD, mode according to an AEAD information carried by a second message from the wireless communication node.
[0300] Details in this regard can be ascertained with reference to the paragraphs above, and will not be repeated herein.
[0301] In some embodiments, the AEAD information may include at least one of the AEAD indicator, the AEAD usage policy, and / or the authenticated encryption algorithm described above.
[0302] In some embodiments, the wireless communication terminal used in the present disclosure may indicate the UE described above.
[0303] In some embodiments, the wireless communication node used in the present disclosure may indicate the node, AMF, gNB, or ng-eNB described above.
[0304] While various embodiments of the present disclosure have been described above, it should be understood that they have been presented by way of example only, and not by way of limitation. Likewise, the various diagrams may depict an example architecture or configuration, which are provided to enable persons of ordinary skill in the art to understand exemplary features and functions of the present disclosure. Such persons would understand, however, that the present disclosure is not restricted to the illustrated example architectures or configurations, but can be implemented using a variety of alternative architectures and configurations. Additionally, as would be understood by persons of ordinary skill in the art, one or more features of one embodiment can be combined with one or more features of another embodiment described herein. Thus, the breadth and scope of the present disclosure should not be limited by any one of the above-described exemplary embodiments.
[0305] It is understood that, in the present disclosure, the term “and / or” or symbol “ / ” may include any and all combinations of one or more of the associated listed items. For example, A and / or B and / or C includes any and all combinations of one or more of A, B, and C, including A, B, C, A and B, A and C, B and C, and a combination of A and B and C. Likewise, A / B / C includes any and all combinations of one or more of A, B, and C, including A, B, C, A and B, A and C, B and C, and a combination of A and B and C.
[0306] It is also understood that any reference to an element herein using a designation such as "first, " "second, " and so forth does not generally limit the quantity or order of those elements. Rather, these designations can be used herein as a convenient means of distinguishing between two or more elements or instances of an element. Thus, a reference to first and second elements does not mean that only two elements can be employed, or that the first element must precede the second element in some manner.
[0307] Additionally, a person having ordinary skill in the art would understand that information and signals can be represented using any one of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits and symbols, for example, which may be referenced in the above description can be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
[0308] A skilled person would further appreciate that any one of the various illustrative logical blocks, units, processors, means, circuits, methods and functions described in connection with the aspects disclosed herein can be implemented by electronic hardware (e.g., a digital implementation, an analog implementation, or a combination of the two) , firmware, various forms of program or design code incorporating instructions (which can be referred to herein, for convenience, as "software" or a "software unit” ) , or any combination of these techniques.
[0309] To clearly illustrate this interchangeability of hardware, firmware and software, various illustrative components, blocks, units, circuits, operations, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware, firmware or software, or a combination of these techniques, depends upon the particular application and design constraints imposed on the overall system. Skilled artisans can implement the described functionality in various ways for each particular application, but such implementation decisions do not cause a departure from the scope of the present disclosure. In accordance with various embodiments, a processor, device, component, circuit, structure, machine, unit, etc. can be configured to perform one or more of the functions described herein. The term “configured to” or “configured for” as used herein with respect to a specified operation or function refers to a processor, device, component, circuit, structure, machine, unit, etc. that is physically constructed, programmed and / or arranged to perform the specified operation or function.
[0310] Furthermore, a skilled person would understand that various illustrative logical blocks, units, devices, components and circuits described herein can be implemented within or performed by an integrated circuit (IC) that can include a general-purpose processor, a digital signal processor (DSP) , an application specific integrated circuit (ASIC) , a field programmable gate array (FPGA) or other programmable logic device, or any combination thereof. The logical blocks, units, and circuits can further include antennas and / or transceivers to communicate with various components within the network or within the device. A general-purpose processor can be a microprocessor, but in the alternative, the processor can be any conventional processor, controller, or state machine. A processor can also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other suitable configuration to perform the functions described herein. If implemented in software, the functions can be stored as one or more instructions or code on a computer-readable medium. Thus, the steps or operations of a method or algorithm disclosed herein can be implemented as software stored on a computer-readable medium.
[0311] Computer-readable media includes both computer storage media and communication media including any medium that can be enabled to transfer a computer program or code from one place to another. A storage media can be any available media that can be accessed by a computer. By way of example, and not limitation, such computer-readable media can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store desired program code in the form of instructions or data structures and that can be accessed by a computer.
[0312] In this document, the term "unit" as used herein, refers to software, firmware, hardware, and any combination of these elements for performing the associated functions described herein. Additionally, for purpose of discussion, the various units are described as discrete units; however, as would be apparent to one of ordinary skill in the art, two or more units may be combined to form a single unit that performs the associated functions according to embodiments of the present disclosure.
[0313] Additionally, memory or other storage, as well as communication components, may be employed in embodiments of the present disclosure. It will be appreciated that, for clarity purposes, the above description has described embodiments of the present disclosure with reference to different functional units and processors. However, it will be apparent that any suitable distribution of functionality between different functional units, processing logic elements or domains may be used without detracting from the present disclosure. For example, functionality illustrated to be performed by separate processing logic elements, or controllers, may be performed by the same processing logic element, or controller. Hence, references to specific functional units are only references to a suitable means for providing the described functionality, rather than indicative of a strict logical or physical structure or organization.
[0314] Various modifications to the implementations described in this disclosure will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other implementations without departing from the scope of the claims. Thus, the disclosure is not intended to be limited to the implementations shown herein, but is to be accorded the widest scope consistent with the novel features and principles disclosed herein, as recited in the claims below.
Claims
1.A wireless communication method comprising:transmitting, by a wireless communication terminal to a wireless communication node, a first message using an authenticated encryption with associated data, AEAD, mode according to an AEAD information carried by a second message from the wireless communication node.2.The wireless communication method of claim 1, wherein the AEAD information comprises at least one of:an AEAD indicator;an AEAD usage policy; oran authenticated encryption algorithm.3.The wireless communication method of claim 1 or 2, wherein the first message is transmitted using the AEAD mode in response to at least one of:the second message comprising an AEAD indicator with a first value indicating the AEAD mode being used;the second message comprising an AEAD usage policy, and the AEAD usage policy indicating the AEAD mode being used or a first condition in the AEAD usage policy for using the AEAD mode being met; orthe second message comprising an authenticated encryption algorithm.4.The wireless communication method of any of claims 1 to 3, wherein the first message is transmitted without using the AEAD mode in response to:the second message comprising an AEAD indicator with a second value indicating an AEAD mode not being used;the second message comprising an AEAD usage policy, and the AEAD usage policy indicating the AEAD mode not being used or a second condition in the AEAD usage policy for not using the AEAD mode being met; orthe second message not comprising an authenticated encryption algorithm.5.The wireless communication method of any of claims 1 to 4, wherein an integrity protection and ciphering for the first message is based on an authenticated encryption algorithm in response to the AEAD mode being used.6.The wireless communication method of any of claims 1 to 5, wherein an integrity protection and ciphering for the second message is based on an authenticated encryption algorithm in response to the AEAD mode being used.7.The wireless communication method of any of claims 1 to 6, wherein the wireless communication terminal performs at least one of:verifying an integrity protection of the second message by using an authenticated encryption algorithm in response to the AEAD mode being used; orperforming an integrity protection and ciphering for the first message by using an authenticated encryption algorithm in response to the AEAD mode being used.8.The wireless communication method of any of claims 1 to 7, wherein the AEAD information indicates:the AEAD mode is used and an authenticated encryption algorithm is based on an algorithm of a selected ciphering algorithm and a selected integrity algorithm;the AEAD mode is used and the select algorithm is based on an algorithm of a selected ciphering algorithm; orthe AEAD mode is used and the select algorithm is based on an algorithm of a selected integrity algorithm.9.The wireless communication method of any of claims 1 to 8, wherein the wireless communication terminal transmits, to the wireless communication node, a third message comprising an authenticated encryption algorithm supported by the wireless communication terminal.10.The wireless communication method of any of claims 1 to 9, wherein the first message comprises a Non-Access-stratum, NAS, Security Mode Complete message or an Access-stratum, AS, Security Mode Complete message;wherein the second message comprises a NAS Security Mode Command message or an AS Security Mode Command message; and / orwherein a third message comprising an authenticated encryption algorithm supported by the wireless communication terminal transmitted from the wireless communication terminal transmits to the wireless communication node is a registration request message.11.A wireless communication method comprising:receiving, by a wireless communication node from a wireless communication terminal, a first message using an authenticated encryption with associated data, AEAD, mode according to an AEAD information carried by a second message from the wireless communication node.12.The wireless communication method of claim 11, wherein the AEAD information comprises at least one of:an AEAD indicator;an AEAD usage policy; oran authenticated encryption algorithm.13.The wireless communication method of claim 11 or 12, wherein the first message is received using the AEAD mode in response to at least one of:the second message comprising an AEAD indicator with a first value indicating the AEAD mode being used;the second message comprising an AEAD usage policy, and the AEAD usage policy indicating the AEAD mode being used or a first condition in the AEAD usage policy for using the AEAD mode being met; orthe second message comprising an authenticated encryption algorithm.14.The wireless communication method of any of claims 11 to 13, wherein the first message is received without using the AEAD mode in response to:the second message comprising an AEAD indicator with a second value indicating an AEAD mode not being used;the second message comprising an AEAD usage policy, and the AEAD usage policy indicating the AEAD mode not being used or a second condition in the AEAD usage policy for not using the AEAD mode being met; orthe second message not comprising an authenticated encryption algorithm.15.The wireless communication method of any of claims 11 to 14, wherein an integrity protection and ciphering for the first message is based on an authenticated encryption algorithm in response to the AEAD mode being used.16.The wireless communication method of any of claims 11 to 15, wherein an integrity protection and ciphering for the second message is based on an authenticated encryption algorithm in response to the AEAD mode being used.17.The wireless communication method of any of claims 11 to 16, wherein the wireless communication node decides to use the AEAD mode or an integrity algorithm for an integrity protection of the second message.18.The wireless communication method of any of claims 11 to 17, wherein the AEAD information indicates:the AEAD mode is used and an authenticated encryption algorithm is based on an algorithm of a selected ciphering algorithm and a selected integrity algorithm;the AEAD mode is used and the select algorithm is based on an algorithm of a selected ciphering algorithm; orthe AEAD mode is used and the select algorithm is based on an algorithm of a selected integrity algorithm.19.The wireless communication method of any of claims 11 to 18, further comprising at least one of:receiving, by the wireless communication node from the wireless communication terminal, a third message comprising the authenticated encryption algorithm supported by the wireless communication terminal; ortransmitting, by the wireless communication node to the wireless communication terminal, a fourth message without using the AEAD mode in response to at least one of:the wireless communication node being not supporting an authenticated encryption algorithm; ora priority of an integrity algorithm or a ciphering algorithm is higher than a priority of an authenticated encryption algorithm.20.The wireless communication method of any of claims 11 to 19, wherein the first message comprises a Non-Access-stratum, NAS, Security Mode Complete message or an Access-stratum, AS, Security Mode Complete message; and / orwherein the second message comprises a NAS Security Mode Command message or an AS Security Mode Command message.21.A wireless communication terminal, comprising:a communication unit; anda processor configured to:transmit, to a wireless communication node via the communication unit, a first message using an authenticated encryption with associated data, AEAD, mode according to an AEAD information carried by a second message from the wireless communication node.22.The wireless communication terminal of claim 21, wherein the processor is further configured to perform a wireless communication method of any of claims 2 to 10.23.A wireless communication node, comprising:a communication unit; anda processor configured to:receive, from a wireless communication terminal a communication unit, a first message using an authenticated encryption with associated data, AEAD, mode according to an AEAD information carried by a second message from the wireless communication node.24.The wireless communication node of claim 23, wherein the processor is further configured to perform a wireless communication method of any of claims 12 to 20.25.A computer program product comprising a computer-readable program medium code stored thereupon, the code, when executed by a processor, causing the processor to implement a wireless communication method recited in any of claims 1 to 20.
Citation Information
Patent Citations
Data communication method and device
CN110365482A
Firmware package manufacturing method and device, firmware package upgrading method and device and terminal
CN116700772A
Confidential communication management
WO2016131056A1
Method for encrypting plain text
WO2023066689A1