Control plane security for wireless devices
By enabling Access Stratum security for signaling in control plane operation modes, the framework addresses security vulnerabilities in wireless communications systems, ensuring secure and reliable location information transmission.
Patent Information
- Application Number
- PCT/US2025/011123
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-02
- Filing Date
- 2025-01-10
- Publication Date
- 2025-08-07
AI Technical Summary
Wireless communications systems face security vulnerabilities in control plane operation modes due to unencrypted location information transmission, which lacks integrity protection, leading to potential security risks.
A framework is introduced to enable Access Stratum (AS) level security for signaling in control plane operation modes by allowing user equipment (UE) to indicate support for AS security protocols, enabling secure transmission of location information via designated Signaling Radio Bearers (SRBs).
This approach enhances security by ensuring encrypted and protected location information transmission, improving communication reliability and user experience while maintaining high data rates.
Smart Images

Figure US2025011123_07082025_PF_FP_ABST
Abstract
Description
CONTROL PLANE SECURITY FOR WIRELESS DEVICESCROSS REFERENCE
[0001] The present Application for Patent claims priority to Greek Patent Application No. 20240100070 by SHRESTHA et al., entitled ‘CONTROL PLANE SECURITY FOR WIRELESS DEVICES,” filed February 2, 2024, assigned to the assignee hereof and is expressly incorporated by reference herein.FIELD OF TECHNOLOGY
[0002] The following relates to wireless communication, including control plane security for wireless devices.BACKGROUND
[0003] Wireless communications systems are widely deployed to provide various types of communication content such as voice, video, packet data, messaging, broadcast, and so on. These systems may be capable of supporting communication with multiple users by sharing the available system resources (e.g.. time, frequency, and power). Examples of such multiple-access systems include fourth generation (4G) systems such as Long Term Evolution (LTE) systems, LTE-Advanced (LTE-A) systems, or LTE-A Pro systems, and fifth generation (5G) systems which may be referred to as New Radio (NR) systems. These systems may employ technologies such as code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), or discrete Fourier transform spread orthogonal frequency division multiplexing (DFT-S-OFDM). A wireless multiple-access communications system may include one or more base stations, each supporting wireless communication for communication devices, which may be known as user equipment (UE).SUMMARY
[0004] The described techniques relate to improved methods, systems, devices, and apparatuses that support control plane security for wireless devices. For example, the described techniques provide a framework for establishing access stratum (AS) security for a control plane operation mode in which a data radio bearer (DRB) is notestablished. In some examples, a user equipment (UE) may transmit, via a first signaling radio bearer (SRB), a request to establish a radio resource control (RRC) connection with a network entity for the UE to operate in accordance with the control plane operation mode. The UE may, in some cases, transmit a UE capability indication to the network entity to indicate a capability of the UE to support AS security for communications associated with the control plane operation mode. In response to the UE capability indication, the UE may receive an RRC message from the network entity indicating that one or more AS security protocols are enabled, configured, or available to be used for at least one SRB.
[0005] A method for wireless communications by a UE is described. The method may include transmitting, via a first SRB, a request to establish a RRC connection with a network entity for the UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB. transmitting an indication of a capability of the UE to support AS security for communications associated with the control plane operation mode, and receiving, from the network entity in accordance with the control plane operation mode, a RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security for communications associated with the control plane operation mode.
[0006] A UE for wireless communications is described. The UE may include one or more memories storing processor executable code, and one or more processors coupled with the one or more memories. The one or more processors may individually or collectively be operable to execute the code to cause the UE to transmit, via a first SRB, a request to establish a RRC connection with a netw ork entity for the UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB, transmit an indication of a capability of the UE to support AS security for communications associated with the control plane operation mode, and receive, from the network entity in accordance with the control plane operation mode, a RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security for communications associated with the control plane operation mode.
[0007] Another UE for wireless communications is described. The UE may include means for transmitting, via a first SRB, a request to establish a RRC connection with a network entity for the UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB, means for transmitting an indication of a capability of the UE to support AS security for communications associated with the control plane operation mode, and means for receiving, from the network entity7in accordance with the control plane operation mode, a RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security for communications associated with the control plane operation mode.
[0008] A non-transitory computer-readable medium storing code for wireless communications is described. The code may include instructions executable by one or more processors to transmit, via a first SRB. a request to establish a RRC connection with a network entity for the UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB, transmit an indication of a capability7of the UE to support AS security' for communications associated with the control plane operation mode, and receive, from the network entity in accordance with the control plane operation mode, a RRC message that indicates one or more AS security' protocols are configured for at least one SRB in response to the capability of the UE to support AS security for communications associated with the control plane operation mode.
[0009] In some examples of the method. UEs, and non-transitory computer-readable medium described herein, transmitting the indication of the capability may include operations, features, means, or instructions for transmitting, via the first SRB, a connection request message including the request to establish the RRC connection with the network entity' and including the indication of the capability.
[0010] In some examples of the method. UEs, and non-transitory computer-readable medium described herein, receiving the RRC message may include operations, features, means, or instructions for receiving, via a second SRB, a connection setup command and a security mode command, where the connection setup command indicates one or more parameters associated with a third SRB, and where the security mode commandindicates that the one or more AS security protocols may be configured for the third SRB.
[0011] In some examples of the method, UEs, and non-transitory computer-readable medium described herein, receiving the RRC message may include operations, features, means, or instructions for receiving, via a second SRB, a connection setup command that indicates one or more parameters associated with a third SRB and receiving, via the third SRB in, the RRC message after reception of the connection setup command, the RRC message including a security mode command that indicates that the one or more AS security’ protocols may be configured for the third SRB.
[0012] In some examples of the method. UEs. and non-transitory computer-readable medium described herein, transmitting the indication of the capability may include operations, features, means, or instructions for transmitting, via a second SRB, a connection complete message that indicates successful establishment of the RRC connection, where the connection complete message includes the indication of the capability'.
[0013] Some examples of the method, UEs, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for transmitting, to the network entity, a first message via the at least one SRB after reception of the RRC message, where the first message includes location information associated with the UE, and where the location information may be encry pted using the one or more AS security' protocols.
[0014] Some examples of the method, UEs, and non-transitory' computer-readable medium described herein may further include operations, features, means, or instructions for transmitting, to the network entity after transmission of the first message, a second message via a second SRB, where the at least one SRB includes a third SRB, and where the second message includes information encry pted using one or more non-AS security7protocols.
[0015] Some examples of the method, UEs, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for receiving, from the network entity after transmission of the first message, a security7release command that indicates the one or more AS securityprotocols may be disabled for the third SRB, where transmission of the second message via the third SRB may be in response to the security release command.
[0016] Some examples of the method, UEs, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for generating an encryption key for the one or more AS security protocols and encry pting the location information in accordance with the one or more AS security protocols using the encry ption key.
[0017] Some examples of the method, UEs, and non-transitory7computer-readable medium described herein may further include operations, features, means, or instructions for transmitting, to the network entity, a first message via a second SRB after reception of the RRC message, where the RRC message indicates that the one or more AS security' protocols may be configured for a third SRB, and where the first message includes a non-AS message or a second RRC message that indicates successful establishment of the RRC connection.
[0018] In some examples of the method. UEs. and non-transitory computer-readable medium described herein, the second SRB may be associated with NarrowBand-Intemet of Things (NB-IoT) devices and may be usable for communications via a dedicated control channel and the third SRB may be usable for communications via the dedicated control channel, and a priority level associated with the third SRB may be higher than one or more other priority levels associated with one or more other SRBs usable for communications via the dedicated control channel.
[0019] Some examples of the method, UEs, and non-transitory' computer-readable medium described herein may further include operations, features, means, or instructions for transmitting, to the network entity after reception of the RRC message, a connection complete message that indicates successful completion of the RRC connection, where transmission of the connection complete message may be in accordance with a mobility management entity -based reestablishment procedure or an AS-based reestablishment procedure.
[0020] Some examples of the method, UEs, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for receiving a control message that indicates, to the UE, to use the mobilitymanagement entity-based reestablishment procedure or the AS-based reestablishment procedure, where transmitting the connection complete message may be in accordance with the control message.
[0021] In some examples of the method. UEs, and non-transitory computer-readable medium described herein, transmitting the indication of the capability may include operations, features, means, or instructions for transmitting the indication of the capability in accordance with a tracking area update procedure or an initial attach procedure.
[0022] In some examples of the method. UEs, and non-transitory computer-readable medium described herein, transmitting the indication of the capability may include operations, features, means, or instructions for determining a change in a location of the UE and transmitting the indication of the capability based on the change in the location of the UE satisfying a threshold.
[0023] In some examples of the method. UEs, and non-transitory computer-readable medium described herein, transmitting the indication of the capability may include operations, features, means, or instructions for determining a location of the UE based on navigation data associated with a global navigation satellite system and transmitting the indication of the capability to report the location of the UE to the network entity.
[0024] In some examples of the method. UEs, and non-transitory computer-readable medium described herein, the RRC message indicates that the one or more AS security protocols may be only enabled for the at least one SRB.
[0025] A method for wireless communications by a network entity is described. The method may include obtaining, via a first SRB, a request to establish a RRC connection with a UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB. obtaining an indication of a capability of the UE to support AS security for communications associated with the control plane operation mode, and outputting a RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security for communications associated with the control plane operation mode.
[0026] A network entity for wireless communications is described. The network entity may include one or more memories storing processor executable code, and one or more processors coupled with the one or more memories. The one or more processors may individually or collectively be operable to execute the code to cause the network entity to obtain, via a first SRB, a request to establish a RRC connection with a UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB, obtain an indication of a capability of the UE to support AS security’ for communications associated with the control plane operation mode, and output a RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security for communications associated wi th the control plane operation mode.
[0027] Another network entity for wireless communications is described. The network entity may include means for obtaining, via a first SRB, a request to establish a RRC connection with a UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB, means for obtaining an indication of a capability' of the UE to support AS security for communications associated with the control plane operation mode, and means for outputting a RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security for communications associated with the control plane operation mode.
[0028] A non-transitory computer-readable medium storing code for wireless communications is described. The code may include instructions executable by one or more processors to obtain, via a first SRB. a request to establish a RRC connection with a UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB, obtain an indication of a capability of the UE to support AS security' for communications associated with the control plane operation mode, and output a RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security' for communications associated with the control plane operation mode.
[0029] In some examples of the method, network entities, and non-transitory computer-readable medium described herein, obtaining the indication of the capability may include operations, features, means, or instructions for obtaining, via the first SRB,a connection request message including the request to establish the RRC connection with the network entity and including the indication of the capability.
[0030] In some examples of the method, netw ork entities, and non-transitory computer-readable medium described herein, outputting the RRC message may include operations, features, means, or instructions for outputting, via a second SRB. a connection setup command and a security mode command, where the connection setup command indicates one or more parameters associated wi th a third SRB, and where the security mode command indicates that the one or more AS security protocols may be configured for the third SRB.
[0031] In some examples of the method, network entities, and non-transitory computer-readable medium described herein, outputting the RRC message may include operations, features, means, or instructions for outputting, via a second SRB, a connection setup command that indicates one or more parameters associated with a third SRB and outputting, via the third SRB, the RRC message after reception of the connection setup command, the RRC message including a security mode command that indicates that the one or more AS security protocols may be configured for the third SRB.
[0032] In some examples of the method, network entities, and non-transitory computer-readable medium described herein, obtaining the indication of the capability may include operations, features, means, or instructions for obtaining, via a second SRB, a connection complete message that indicates successful establishment of the RRC connection, where the connection complete message includes the indication of the capability.
[0033] Some examples of the method, network entities, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for obtaining a first message via the at least one SRB, where the first message includes location information associated with the UE, and where the location information may be encrypted using the one or more AS security protocols.
[0034] Some examples of the method, network entities, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for obtaining a second message via a second SRB, where the atleast one SRB includes a third SRB, and where the second message includes information encrypted using one or more non- AS security protocols.
[0035] Some examples of the method, network entities, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for outputting a security release command that indicates the one or more AS security protocols may be disabled for the third SRB, where the second message may be obtained via the third SRB in response to the security release command.
[0036] Some examples of the method, network entities, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for obtaining a first message via a second SRB, where the first message includes a non-AS message or a second RRC message that indicates successful establishment of the RRC connection.
[0037] Some examples of the method, network entities, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for obtaining a connection complete message that indicates successful completion of the RRC connection, where the connection complete message may be obtained in accordance with a mobility' management entity -based reestablishment procedure or an AS-based reestablishment procedure.
[0038] Some examples of the method, network entities, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for outputting a control message that indicates, to the UE, to use the mobility' management entity-based reestablishment procedure or the AS-based reestablishment procedure, where the connection complete message may be obtained in accordance with the control message.
[0039] In some examples of the method, network entities, and non-transitory computer-readable medium described herein, obtaining the indication of the capability may include operations, features, means, or instructions for obtaining the indication of the capability in accordance with a tracking area update procedure or an initial attach procedure.
[0040] In some examples of the method, network entities, and non-transitory computer-readable medium described herein, obtaining the indication of the capability may include operations, features, means, or instructions for obtaining the indication of the capability based on a change in a location of the UE satisfying a threshold.
[0041] In some examples of the method, network entities, and non-transitory computer-readable medium described herein, the RRC message indicates that the one or more AS security protocols may be only enabled for the at least one SRB.BRIEF DESCRIPTION OF THE DRAWINGS
[0042] FIG. 1 shows an example of a wireless communications system that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure.
[0043] FIG. 2 shows an example of a network architecture that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure.
[0044] FIG. 3 shows an example of a wireless communications system that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure.
[0045] FIGs. 4 and 5 show examples of a process flow that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure.
[0046] FIGs. 6 and 7 show block diagrams of devices that support control plane security for wireless devices in accordance with one or more aspects of the present disclosure.
[0047] FIG. 8 shows a block diagram of a communications manager that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure.
[0048] FIG. 9 shows a diagram of a system including a device that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure.
[0049] FIGs. 10 and 11 show block diagrams of devices that support control plane security for wireless devices in accordance with one or more aspects of the present disclosure.
[0050] FIG. 12 shows a block diagram of a communications manager that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure.
[0051] FIG. 13 shows a diagram of a system including a device that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure.
[0052] FIGs. 14 and 15 show flowcharts illustrating methods that support control plane security for wireless devices in accordance with one or more aspects of the present disclosure.DETAILED DESCRIPTION
[0053] Some wireless communications systems may support communications via one or more types of radio bearers, such as data radio bearers (DRBs) and signaling radio bearers (SRBs). As described herein, a radio bearer may refer to a channel (e.g., logical channel, a transport channel) used to carry data. For example, a communication device (e.g., a user equipment (UE), a network entity), may use a DRB to communicate user plane data and an SRB to communicate control plane data. In some cases, a wireless communications system may support a control plane operation mode (also referred to herein as a control plane cellular internet of things (CIoT) optimization mode) in which the UE may refrain from establishing a DRB for communication with the network entity. Accordingly, while the UE operates in accordance with the control plane operation mode, the UE and the network entity may communicate via one or more SRBs. In some cases, the UE and the network entity may use non-access stratum (NAS) security for data exchanged via the one or more SRBs and access stratum (AS) security for data exchanged via one or more DRBs. Accordingly, the UE may not support AS security for data exchange between the UE and the network entity while the UE operates in accordance with the control plane operation mode. That is, for data exchange between the UE and the network entity while the UE operates in accordancewith the control plane operation mode, encryption and integrity protection may be performed at the NAS layer.
[0054] The UE may determine to report location information to the netw ork while operating in the control plane operation mode. In some cases, the UE may report the location information by adding the location information to a message (e.g., a NAS message, an RRC message) to be transmitted to the network via an SRB. In such cases, however, the location information may be added at the AS layer (or RRC layer) and, as such, may be unencry pted and lack integrity protection. Transmitting unencrypted location information may lead to one or more security vulnerabilities for the UE.
[0055] Various aspects of the present disclosure relate to control plane security for wireless devices and, more specifically, to a framework for a UE to enable AS level security for signaling communicated in the control plane operation mode. For example, a UE may use an SRB (e.g., SRBO) to transmit an RRC request message to the network, such that the UE may establish an RRC connection and may use the established RRC connection to communicate with the network in the control plane operation mode. Additionally, while operating in the control plane operation mode, the UE may report, to the network, that the UE supports AS level security for signaling communicated in the control plane operation mode. For example, the UE may transmit, to the network, an AS security capability indication or a location updated request indication, which may indicate that the UE supports AS level security for signaling communicated in the control plane operation mode (e.g., for signaling communicated via one or more SRBs). The UE may include the AS security capability indication or the location updated request indication in the RRC connection request. Alternatively, the UE may transmit the AS security capability indication or the location updated request indication to the network entity after transmitting the RRC connection request message. For example, the UE may include the AS security capability indication or the location updated request indication in an RRC connection complete message, which may be transmitted via the UE after transmission of the RRC connection request message. In response to the UE reporting the capability of the UE to support AS level security for signaling communicated in the control plane operation mode, the network may enable one or more AS security protocols for another SRB (e.g.. SRB1). For example, in response to transmitting the AS security capability indication or the location updated requestindication, the UE may receive a security mode command from the network, which may indicate that the one or more AS securi ty protocols are enabled (e.g., configured) for SRB1. Accordingly, the UE may use the AS security protocols to report the location information to the network via SRB 1.
[0056] Particular aspects of the subject matter described herein may be implemented to realize one or more of the following potential advantages. For example, the techniques employed by the described communication devices (e.g., the UE, the network entity) may provide benefits and enhancements to wireless communication devices operating within the network, including enabling improved coordination between the wireless communication devices. In some examples, operations performed by the described communication devices may provide improvements to location reporting by the UE, which may increase the reliability of communications between the UE and the network entity. The operations performed by the described communication devices to improve location reporting by the UE may include indicating that the UE supports AS level security for signaling communicated in the control plane operation mode and indicating that one or more AS security protocols are enabled for an SRB. In some implementations, operations performed by the described wireless communication devices may also support improvements to user experience and higher data rates, among other benefits.
[0057] Aspects of the disclosure are described in the context of wireless communications systems. Aspects of the disclosure are also described in the context of a network architecture and process flows. Aspects of the disclosure are further illustrated by and described with reference to apparatus diagrams, system diagrams, and flowcharts that relate to control plane security for wireless devices.
[0058] FIG. 1 shows an example of a wireless communications system 100 that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure. The wireless communications system 100 may include one or more devices, such as one or more network devices (e.g., network entities 105), one or more UEs 1 15, and a core network 130. In some examples, the wireless communications system 100 may be a Long Term Evolution (LTE) network, an LTE- Advanced (LTE- A) network, an LTE-A Pro network, a New Radio (NR) network, or anetwork operating in accordance with other systems and radio technologies, including future systems and radio technologies not explicitly mentioned herein.
[0059] The network entities 105 may be dispersed throughout a geographic area to form the wireless communications system 100 and may include devices in different forms or having different capabilities. In various examples, a network entity 105 may be referred to as a network element, a mobility element, a radio access network (RAN) node, or network equipment, among other nomenclature. In some examples, network entities 105 and UEs 115 may wirelessly communicate via communication link(s) 125 (e.g., a radio frequency (RF) access link). For example, a network entity 105 may support a coverage area 110 (e.g., a geographic coverage area) over which the UEs 1 15 and the network entity 105 may establish the communication link(s) 125. The coverage area 110 may be an example of a geographic area over which a network entity 105 and a UE 115 may support the communication of signals according to one or more radio access technologies (RATs).
[0060] The UEs 115 may be dispersed throughout a coverage area 110 of the wireless communications system 100, and each UE 115 may be stationary, or mobile, or both at different times. The UEs 115 may be devices in different forms or having different capabilities. Some example UEs 115 are illustrated in FIG. 1. The UEs 115 described herein may be capable of supporting communications with various types of devices in the wireless communications system 100 (e.g., other wireless communication devices, including UEs 115 or network entities 105), as shown in FIG. 1.
[0061] As described herein, a node of the wireless communications system 100, which may be referred to as a network node, or a wireless node, may be a network entity 105 (e.g., any network entity described herein), a UE 115 (e.g.. any UE described herein), a network controller, an apparatus, a device, a computing system, one or more components, or another suitable processing entity configured to perform any of the techniques described herein. For example, a node may be a UE 115. As another example, a node may be a network entity 105. As another example, a first node may be configured to communicate with a second node or a third node. In one aspect of this example, the first node may be a UE 115, the second node may be a network entity 105, and the third node may be a UE 115. In another aspect of this example, the first node may be a UE 115, the second node may be a network entity 105, and the third node maybe a network entity 105. In yet other aspects of this example, the first, second, and third nodes may be different relative to these examples. Similarly, reference to a UE 115, network entity 105, apparatus, device, computing sy stem, or the like may include disclosure of the UE 115, network entity 105, apparatus, device, computing system, or the like being a node. For example, disclosure that a UE 1 15 is configured to receive information from a network entity 105 also discloses that a first node is configured to receive information from a second node.
[0062] In some examples, network entities 105 may communicate with a core network 130. or with one another, or both. For example, network entities 105 may communicate with the core network 130 via backhaul communication link(s) 120 (e.g., in accordance with an SI, N2, N3, or other interface protocol). In some examples, netw ork entities 105 may communicate with one another via backhaul communication link(s) 120 (e.g., in accordance with an X2, Xn, or other interface protocol) either directly (e.g.. directly between network entities 105) or indirectly (e.g.. via the core network 130). In some examples, network entities 105 may communicate with one another via a midhaul communication link 162 (e.g., in accordance with a midhaul interface protocol) or a fronthaul communication link 168 (e.g., in accordance with a fronthaul interface protocol), or any combination thereof. The backhaul communication link(s) 120, midhaul communication links 162, or fronthaul communication links 168 may be or include one or more wired links (e.g., an electrical link, an optical fiber link) or one or more wireless links (e.g.. a radio link, a wireless optical link), among other examples or various combinations thereof. A UE 115 may communicate with the core network 130 via a communication link 155.
[0063] One or more of the network entities 105 or network equipment described herein may include or may be referred to as a base station 140 (e.g., a base transceiver station, a radio base station, an NR base station, an access point, a radio transceiver, a NodeB, an eNodeB (eNB), a next-generation NodeB or giga-NodeB (either of which may be referred to as a gNB), a 5G NB, a next-generation eNB (ng-eNB), a Home NodeB, a Home eNodeB, or other suitable terminology). In some examples, a network entity7105 (e.g., a base station 140) may be implemented in an aggregated (e.g., monolithic, standalone) base station architecture, which may be configured to utilize aprotocol stack that is physically or logically integrated within one network entity (e.g., a network entity 105 or a single RAN node, such as a base station 140).
[0064] In some examples, a network entity 105 may be implemented in a disaggregated architecture (e.g., a disaggregated base station architecture, a disaggregated RAN architecture), which may be configured to utilize a protocol stack that is physically or logically distributed among multiple network entities (e.g., network entities 105), such as an integrated access and backhaul (TAB) network, an open RAN (O-RAN) (e.g., a network configuration sponsored by the O-RAN Alliance), or a virtualized RAN (vRAN) (e.g., a cloud RAN (C-RAN)). For example, a network entity- 105 may include one or more of a central unit (CU), such as a CU 160, a distributed unit (DU), such as a DU 165, a radio unit (RU), such as an RU 170, a RAN Intelligent Controller (RIC), such as an RIC 175 (e.g., a Near-Real Time RIC (Near-RT RIC), a Non-Real Time RIC (Non-RT RIC)), a Service Management and Orchestration (SMO) system, such as an SMO system 180, or any combination thereof. An RU 170 may also be referred to as a radio head, a smart radio head, a remote radio head (RRH), a remote radio unit (RRU), or a transmission reception point (TRP). One or more components of the network entities 105 in a disaggregated RAN architecture may be co-located, or one or more components of the network entities 105 may be located in distributed locations (e.g., separate physical locations). In some examples, one or more of the network entities 105 of a disaggregated RAN architecture may be implemented as virtual units (e.g., a virtual CU (VCU), a virtual DU (VDU), a virtual RU (VRU)).
[0065] The split of functionality between a CU 160. a DU 165, and an RU 170 is flexible and may support different functionalities depending on which functions (e.g., network layer functions, protocol layer functions, baseband functions, RF functions, or any combinations thereof) are performed at a CU 160, a DU 165, or an RU 170. For example, a functional split of a protocol stack may be employed between a CU 160 and a DU 165 such that the CU 160 may support one or more layers of the protocol stack and the DU 165 may support one or more different layers of the protocol stack. In some examples, the CU 160 may host upper protocol layer (e.g., layer 3 (L3), layer 2 (L2)) functionality and signaling (e.g., Radio Resource Control (RRC), sendee data adaption protocol (SDAP), Packet Data Convergence Protocol (PDCP)). The CU 160 (e.g., one or more CUs) may be connected to a DU 165 (e.g., one or more DUs) or an RU 170(e.g., one or more RUs), or some combination thereof, and the DUs 165, RUs 170, or both may host lower protocol layers, such as layer 1 (LI) (e.g., physical (PHY) layer) or L2 (e g., radio link control (RLC) layer, medium access control (MAC) layer) functionality and signaling, and may each be at least partially controlled by the CU 160. Additionally, or alternatively, a functional split of the protocol stack may be employed between a DU 165 and an RU 170 such that the DU 165 may support one or more layers of the protocol stack and the RU 170 may support one or more different layers of the protocol stack. The DU 165 may support one or multiple different cells (e.g., via one or multiple different RUs, such as an RU 170). In some cases, a functional split between a CU 160 and a DU 165 or between a DU 165 and an RU 170 may be within a protocol layer (e.g., some functions for a protocol layer may be performed by one of a CU 160, a DU 165, or an RU 170, while other functions of the protocol layer are performed by a different one of the CU 160, the DU 165, or the RU 170). A CU 160 may be functionally split further into CU control plane (CU-CP) and CU user plane (CU-UP) functions. A CU 160 may be connected to a DU 165 via a midhaul communication link 162 (e.g., Fl, Fl-c, Fl-u), and a DU 165 may be connected to an RU 170 via a fronthaul communication link 168 (e.g., open fronthaul (FH) interface). In some examples, a midhaul communication link 162 or a fronthaul communication link 168 may be implemented in accordance with an interface (e.g., a channel) between layers of a protocol stack supported by respective network entities (e.g., one or more of the network entities 105) that are in communication via such communication links.
[0066] In some wireless communications systems (e.g., the wireless communications system 100), infrastructure and spectral resources for radio access may support wireless backhaul link capabilities to supplement wired backhaul connections, providing an IAB network architecture (e.g., to a core network 130). In some cases, in an IAB network, one or more of the network entities 105 (e.g., network entities 105 or IAB node(s) 104) may be partially controlled by each other. The IAB node(s) 104 may be referred to as a donor entity or an TAB donor. A DU 165 or an RU 170 may be partially controlled by a CU 160 associated with a network entity 105 or base station 140 (such as a donor network entity or a donor base station). The one or more donor entities (e.g., IAB donors) may be in communication with one or more additional devices (e.g., IAB node(s) 104) via supported access and backhaul links (e.g., backhaulcommunication link(s) 120). TAB node(s) 104 may include an TAB mobile termination (IAB-MT) controlled (e.g., scheduled) by one or more DUs (e.g., DUs 165) of a coupled TAB donor. An IAB-MT may be equipped with an independent set of antennas for relay of communications with UEs 115 or may share the same antennas (e.g., of an RU 170) of TAB node(s) 104 used for access via the DU 165 of the TAB node(s) 104 (e.g., referred to as virtual IAB-MT (vIAB-MT)). In some examples, the IAB node(s) 104 may include one or more DUs (e.g., DUs 165) that support communication links with additional entities (e.g., IAB node(s) 104, UEs 115) within the relay chain or configuration of the access network (e.g., downstream). In such cases, one or more components of the disaggregated RAN architecture (e.g., the IAB node(s) 104 or components of the IAB node(s) 104) may be configured to operate according to the techniques described herein.
[0067] In the case of the techniques described herein applied in the context of a disaggregated RAN architecture, one or more components of the disaggregated RAN architecture may be configured to support test as described herein. For example, some operations described as being performed by a UE 115 or a network entity 105 (e.g., a base station 140) may additionally, or alternatively, be performed by one or more components of the disaggregated RAN architecture (e.g., components such as an IAB node, a DU 165, a CU 160, an RU 170, an RIC 175, an SMO system 180).
[0068] A UE 115 may include or may be referred to as a mobile device, a wireless device, a remote device, a handheld device, or a subscriber device, or some other suitable terminology, where the ‘‘device'’ may also be referred to as a unit, a station, a terminal, or a client, among other examples. A UE 115 may also include or may be referred to as a personal electronic device such as a cellular phone, a personal digital assistant (PDA), a tablet computer, a laptop computer, or a personal computer. In some examples, a UE 115 may include or be referred to as a wireless local loop (WLL) station, an Internet of Things (loT) device, an Internet of Everything (loE) device, or a machine type communications (MTC) device, among other examples, which may be implemented in various objects such as appliances, vehicles, or meters, among other examples.
[0069] The UEs 115 described herein may be able to communicate with various types of devices, such as UEs 115 that may sometimes operate as relays, as well as thenetwork entities 105 and the network equipment including macro eNBs or gNBs, small cell eNBs or gNBs, or relay base stations, among other examples, as shown in FIG. 1.
[0070] The UEs 115 and the network entities 105 may wirelessly communicate with one another via the communication link(s) 125 (e.g., one or more access links) using resources associated with one or more carriers. The term "‘carrier’7may refer to a set of RF spectrum resources having a defined PHY layer structure for supporting the communication link(s) 125. For example, a carrier used for the communication link(s) 125 may include a portion of an RF spectrum band (e.g., a bandwidth part (BWP)) that is operated according to one or more PHY layer channels for a given RAT (e.g., LTE, LTE-A, LTE-A Pro, NR). Each PHY layer channel may carry acquisition signaling (e.g., synchronization signals, system information), control signaling that coordinates operation for the carrier, user data, or other signaling. The wireless communications system 100 may support communication with a UE 115 using carrier aggregation or multi-carrier operation. A UE 115 may be configured with multiple downlink component carriers and one or more uplink component carriers according to a carrier aggregation configuration. Carrier aggregation may be used with both frequency division duplexing (FDD) and time division duplexing (TDD) component carriers. Communication between a network entity 105 and other devices may refer to communication betw een the devices and any portion (e.g., entity, sub-entity) of a network entity 105. For example, the terms “transmitting,” “receiving,” or “communicating,” when referring to a network entity 105, may refer to any portion of a network entity 105 (e.g., a base station 140, a CU 160, a DU 165. a RU 170) of a RAN communicating with another device (e.g., directly or via one or more other network entities, such as one or more of the netw ork entities 105).
[0071] Signal wave forms transmitted via a carrier may be made up of multiple subcarriers (e.g., using multi-carrier modulation (MCM) techniques such as orthogonal frequency division multiplexing (OFDM) or discrete Fourier transform spread OFDM (DFT-S-OFDM)). In a system employing MCM techniques, a resource element may refer to resources of one symbol period (e.g., a duration of one modulation symbol) and one subcarrier, in which case the symbol period and subcarrier spacing may be inversely related. The quantity of bits carried by each resource element may depend on the modulation scheme (e.g., the order of the modulation scheme, the coding rate of themodulation scheme, or both), such that a relatively higher quantity of resource elements (e.g., in a transmission duration) and a relatively higher order of a modulation scheme may correspond to a relatively higher rate of communication. A wireless communications resource may refer to a combination of an RF spectrum resource, a time resource, and a spatial resource (e.g., a spatial layer, a beam), and the use of multiple spatial resources may increase the data rate or data integrity for communications with a UE 115.
[0072] The time intervals for the network entities 105 or the UEs 115 may be expressed in multiples of a basic time unit which may, for example, refer to a sampling period of Tsseconds, for which fmaxmay represent a supported subcarrier spacing, and N may represent a supported discrete Fourier transform (DFT) size. Time intervals of a communications resource may be organized according to radio frames each having a specified duration (e.g., 10 milliseconds (ms)). Each radio frame may be identified by a system frame number (SFN) (e.g., ranging from 0 to 1023).
[0073] Each frame may include multiple consecutively-numbered subframes or slots, and each subframe or slot may have the same duration. In some examples, a frame may be divided (e.g., in the time domain) into subframes, and each subframe may be further divided into a quantity of slots. Alternatively, each frame may include a variable quantity7of slots, and the quantity7of slots may depend on subcarrier spacing. Each slot may include a quantity of symbol periods (e.g., depending on the length of the cyclic prefix prepended to each symbol period). In some wireless communications systems, such as the wireless communications system 100, a slot may further be divided into multiple mini-slots associated yvith one or more symbols. Excluding the cyclic prefix, each symbol period may be associated with one or more (e.g.. Ay) sampling periods. The duration of a symbol period may depend on the subcarrier spacing or frequency band of operation.
[0074] A subframe, a slot, a mini-slot, or a symbol may be the smallest scheduling unit (e.g.. in the time domain) of the wireless communications system 100 and may be referred to as a transmission time interval (TTI). In some examples, the TTI duration (e.g., a quantity7of symbol periods in a TTI) may be variable. Additionally, oralternatively, the smallest scheduling unit of the wireless communications system 100 may be dynamically selected (e.g., in bursts of shortened TTIs (sTTIs)).
[0075] Physical channels may be multiplexed for communication using a carrier according to various techniques. A physical control channel and a physical data channel may be multiplexed for signaling via a downlink carrier, for example, using one or more of time division multiplexing (TDM) techniques, frequency division multiplexing (FDM) techniques, or hybrid TDM-FDM techniques. A control region (e.g., a control resource set (CORESET)) for a physical control channel may be defined by a set of symbol periods and may extend across the system bandwidth or a subset of the system bandwidth of the carrier. One or more control regions (e.g., CORESETs) may be configured for a set of the UEs 115. For example, one or more of the UEs 115 may monitor or search control regions for control information according to one or more search space sets, and each search space set may include one or multiple control channel candidates in one or more aggregation levels arranged in a cascaded manner. An aggregation level for a control channel candidate may refer to an amount of control channel resources (e.g., control channel elements (CCEs)) associated with encoded information for a control information format having a given payload size. Search space sets may include common search space sets configured for sending control information to UEs 115 (e.g., one or more UEs) or may include UE-specific search space sets for sending control information to a UE 115 (e.g., a specific UE).
[0076] In some examples, a network entity 105 (e.g., a base station 140, an RU 170) may be movable and therefore provide communication coverage for a moving coverage area, such as the coverage area 110. In some examples, coverage areas 110 (e.g., different coverage areas) associated with different technologies may overlap, but the coverage areas 110 (e.g., different coverage areas) may be supported by the same network entity (e.g., a network entity 105). In some other examples, overlapping coverage areas, such as a coverage area 110, associated with different technologies may be supported by different network entities (e.g., the network entities 105). The wireless communications system 100 may include, for example, a heterogeneous network in which different types of the network entities 105 support communications for coverage areas 110 (e.g., different coverage areas) using the same or different RATs.
[0077] The wireless communications system 100 may be configured to support ultra-reliable communications or low-latency communications, or various combinations thereof. For example, the wireless communications system 100 may be configured to support ultra-reliable low-latency communications (URLLC). The UEs 115 may be designed to support ultra-reliable, low-latency, or critical functions. Ultra-reliable communications may include private communication or group communication and may be supported by one or more sendees such as push-to-talk, video, or data. Support for ultra-reliable, low-latency functions may include prioritization of services, and such services may be used for public safety or general commercial applications. The terms ultra-reliable, low-latency, and ultra-reliable low-latency may be used interchangeably herein.
[0078] In some examples, a UE 115 may be configured to support communicating directly with other UEs (e.g., one or more of the UEs 115) via a device-to-device (D2D) communication link, such as a D2D communication link 135 (e.g., in accordance with a peer-to-peer (P2P), D2D, or sidelink protocol). In some examples, one or more UEs 115 of a group that are performing D2D communications may be within the coverage area 110 of a netw ork entity 105 (e.g., a base station 140, an RU 170), which may support aspects of such D2D communications being configured by (e.g., scheduled by) the network entity 105. In some examples, one or more UEs 115 of such a group may be outside the coverage area 110 of a network entity 105 or may be otherwise unable to or not configured to receive transmissions from a network entity 105. In some examples, groups of the UEs 115 communicating via D2D communications may support a one-to- many (1:M) system in which each UE 115 transmits to one or more of the UEs 115 in the group. In some examples, a netw ork entity' 105 may facilitate the scheduling of resources for D2D communications. In some other examples, D2D communications may be carried out between the UEs 115 without an involvement of a network entity 105.
[0079] The core network 130 may provide user authentication, access authorization, tracking, Internet Protocol (IP) connectivity, and other access, routing, or mobility functions. The core network 130 may be an evolved packet core (EPC) or 5G core (5GC), which may include at least one control plane entity that manages access and mobility (e.g., a mobility management entity (MME), an access and mobilitymanagement function (AMF)) and at least one user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW), a Packet Data Network (PDN) gateway (P-GW), or a user plane function (UPF)). The control plane entity may manage NAS functions such as mobility, authentication, and bearer management for the UEs 1 15 served by the network entities 105 (e.g., base stations 140) associated with the core network 130. User IP packets may be transferred through the user plane entity7, which may provide IP address allocation as well as other functions. The user plane entity may be connected to IP services 150 for one or more network operators. The IP services 150 may include access to the Internet. Intranet(s). an IP Multimedia Subsystem (IMS), or a Packet-Switched Streaming Service.
[0080] The wireless communications system 100 may operate using one or more frequency bands, which may be in the range of 300 megahertz (MHz) to 300 gigahertz (GHz). Generally, the region from 300 MHz to 3 GHz is known as the ultra-high frequency (UHF) region or decimeter band because the wavelengths range from approximately one decimeter to one meter in length. UHF waves may be blocked or redirected by buildings and environmental features, which may be referred to as clusters, but the waves may penetrate structures sufficiently for a macro cell to provide service to the UEs 115 located indoors. Communications using UHF waves may be associated with smaller antennas and shorter ranges (e.g., less than one hundred kilometers) compared to communications using the smaller frequencies and longer waves of the high frequency (HF) or very high frequency (VHF) portion of the spectrum below 300 MHz.
[0081] The wireless communications system 100 may utilize both licensed and unlicensed RF spectrum bands. For example, the wireless communications system 100 may employ License Assisted Access (LAA), LTE-Unlicensed (LTE-U) RAT, or NR technology using an unlicensed band such as the 5 GHz industrial, scientific, and medical (ISM) band. While operating using unlicensed RF spectrum bands, devices such as the network entities 105 and the UEs 115 may employ carrier sensing for collision detection and avoidance. In some examples, operations using unlicensed bands may be based on a carrier aggregation configuration in conjunction with component carriers operating using a licensed band (e.g., LAA). Operations using unlicensedspectrum may include downlink transmissions, uplink transmissions, P2P transmissions, or D2D transmissions, among other examples.
[0082] A network entity 105 (e.g., a base station 140, an RU 170) or a UE 115 may be equipped with multiple antennas, which may be used to employ techniques such as transmit diversity, receive diversity, multiple-input multiple-output (MIMO) communications, or beamforming. The antennas of a network entity 105 or a UE 1 15 may be located within one or more antenna arrays or antenna panels, which may support MIMO operations or transmit or receive beamforming. For example, one or more base station antennas or antenna arrays may be co-located at an antenna assembly, such as an antenna tower. In some examples, antennas or antenna arrays associated with a network entity 105 may be located at diverse geographic locations. A network entity' 105 may include an antenna array with a set of rows and columns of antenna ports that the network entity 105 may use to support beamforming of communications with a UE 115. Likewise, a UE 115 may include one or more antenna arrays that may support various MIMO or beamforming operations. Additionally, or alternatively, an antenna panel may support RF beamforming for a signal transmitted via an antenna port.
[0083] Beamforming, which may also be referred to as spatial fdtering, directional transmission, or directional reception, is a signal processing technique that may be used at a transmitting device or a receiving device (e.g., a network entity 105, a UE 115) to shape or steer an antenna beam (e.g., a transmit beam, a receive beam) along a spatial path between the transmitting device and the receiving device. Beamforming may be achieved by combining the signals communicated via antenna elements of an antenna array such that some signals propagating along particular orientations with respect to an antenna array experience constructive interference while others experience destructive interference. The adjustment of signals communicated via the antenna elements may include a transmitting device or a receiving device applying amplitude offsets, phase offsets, or both to signals carried via the antenna elements associated with the device. The adjustments associated with each of the antenna elements may be defined by a beamforming weight set associated with a particular orientation (e.g., with respect to the antenna array of the transmitting device or receiving device, or with respect to some other orientation).
[0084] The wireless communications system 100 may be a packet-based network that operates according to a layered protocol stack. In the user plane, communications at the bearer or PDCP layer may be IP-based. An RLC layer may perform packet segmentation and reassembly to communicate via logical channels. A MAC layer may perform priority handling and multiplexing of logical channels into transport channels. The MAC layer also may implement error detection techniques, error correction techniques, or both to support retransmissions to improve link efficiency. In the control plane, an RRC layer may provide establishment, configuration, and maintenance of an RRC connection between a UE 115 and a network entity 105 or a core network 130 supporting radio bearers for user plane data. A PHY layer may map transport channels to physical channels.
[0085] The wireless communications system 100 may support a framework for establishing AS security for a control plane operation mode in which a DRB is not established. For example, in accordance with the framework, the UE 115 may transmit, via a first SRB, a request to establish an RRC connection with a network entity 105 for the UE 115 to operate in accordance w ith the control plane operation mode. The UE 115 may also transmit a UE capability indication to the netw ork entity 105. The UE capability indication may indicate a capability of the UE 115 to support AS security for communications associated with the control plane operation mode. In response to the UE capability indication, the UE 115 may receive an RRC message from the network entity 105. The RRC message may indicate that one or more AS security protocols are enabled (e.g.. configured) for at least one SRB. Accordingly, the UE 115 may apply the one or more AS security protocols for communications with the network entity 105 in accordance with the control plane operation mode. For example, the UE 115 may apply (e.g., may only apply) the one or more AS security protocols for communications with the network entity 105 via the at least one SRB. In some examples, the UE 115 may apply the one or more AS security protocols for transmission of UE location information to the network entity 105 via the at least one SRB.
[0086] FIG. 2 shows an example of a network architecture 200 (e.g., a disaggregated base station architecture, a disaggregated RAN architecture) that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure. The network architecture 200 may illustrate an example forimplementing one or more aspects of the wireless communications system 100. The network architecture 200 may include one or more CUs 160-a that may communicate directly with a core network 130-a via a backhaul communication link 120-a, or indirectly with the core network 130-a through one or more disaggregated network entities 105 (e.g., a Near-RT RIC 175-b via an E2 link, or aNon-RT RIC 175-a associated with an SMO 180-a (e.g., an SMO Framework), or both). A CU 160-a may communicate with one or more DUs 165-a via respective midhaul communication links 162-a (e.g.. an Fl interface). The DUs 165-a may communicate with one or more RUs 170-a via respective fronthaul communication links 168-a. The R s 170-a may be associated with respective coverage areas 110-a and may communicate with UEs 115 -a via one or more communication links 125-a. In some implementations, a UE 115-a may be simultaneously served by multiple RUs 170-a.
[0087] Each of the network entities 105 of the network architecture 200 (e.g., CUs 160-a, DUs 165-a, RUs 170-a. Non-RT RICs 175-a. Near-RT RICs 175-b, SMOs 180-a. Open Clouds (O-Clouds) 205, Open eNBs (O-eNBs) 210) may include one or more interfaces or may be coupled with one or more interfaces configured to receive or transmit signals (e.g., data, information) via a wired or wireless transmission medium. Each network entity 105, or an associated processor (e.g.. controller) providing instructions to an interface of the network entity 105, may be configured to communicate with one or more of the other network entities 105 via the transmission medium. For example, the network entities 105 may include a wired interface configured to receive or transmit signals over a wired transmission medium to one or more of the other network entities 105. Additionally, or alternatively, the network entities 105 may include a wireless interface, which may include a receiver, a transmitter, or transceiver (e.g., an RF transceiver) configured to receive or transmit signals, or both, over a wireless transmission medium to one or more of the other network entities 105.
[0088] In some examples, a CU 160-a may host one or more higher layer control functions. Such control functions may include RRC, PDCP, SDAP, or the like. Each control function may be implemented with an interface configured to communicate signals with other control functions hosted by the CU 160-a. A CU 160-a may be configured to handle user plane functionality (e.g., CU-UP), control plane functionality(e.g., CU-CP), or a combination thereof. Tn some examples, a CU 1 0-a may be logically split into one or more CU-UP units and one or more CU-CP units. A CU-UP unit may communicate bidirectionally with the CU-CP unit via an interface, such as an El interface when implemented in an O-RAN configuration. A CU 160-a may be implemented to communicate with a DU 165-a, as necessary, for network control and signaling.
[0089] A DU 165-a may correspond to a logical unit that includes one or more functions (e.g., base station functions, RAN functions) to control the operation of one or more RUs 170-a. In some examples, a DU 165-a may host, at least partially, one or more of an RLC layer, a MAC layer, and one or more aspects of a PHY layer (e.g., a high PHY layer, such as modules for FEC encoding and decoding, scrambling, modulation and demodulation, or the like) depending, at least in part, on a functional split, such as those defined by the 3rd Generation Partnership Project (3GPP). In some examples, a DU 165-a may further host one or more low PHY layers. Each layer may be implemented with an interface configured to communicate signals with other layers hosted by the DU 165-a, or with control functions hosted by a CU 160-a.
[0090] In some examples, lower-layer functionality7may be implemented by one or more RUs 170-a. For example, an RU 170-a, controlled by a DU 165-a, may correspond to a logical node that hosts RF processing functions, or low-PHY layer functions (e.g.. performing fast Fourier transform (FFT), inverse FFT (iFFT), digital beamforming, physical random access channel (PRACH) extraction and filtering, or the like), or both, based at least in part on the functional split, such as a lower-layer functional split. In such an architecture, an RU 170-a may be implemented to handle over the air (OTA) communication with one or more UEs 115-a. In some implementations, real-time and non-real-time aspects of control and user plane communication with the RU(s) 170-a may be controlled by the corresponding DU 165-a. In some examples, such a configuration may enable a DU 165-a and a CU 160-a to be implemented in a cloudbased RAN architecture, such as a vRAN architecture.
[0091] The SMO 180-a may be configured to support RAN deployment and provisioning of non-virtualized and virtualized network entities 105. For non-virtualized network entities 105, the SMO 180-a may be configured to support the deployment of dedicated physical resources for RAN coverage requirements which may be managedvia an operations and maintenance interface (e.g., an 01 interface). For virtualized network entities 105, the SMO 180-a may be configured to interact with a cloud computing platform (e.g., an O-Cloud 205) to perform network entity life cycle management (e.g., to instantiate virtualized network entities 105) via a cloud computing platform interface (e.g., an 02 interface). Such virtualized network entities 105 can include, but are not limited to, CUs 160-a, DUs 165-a, RUs 170-a, and Near-RT RICs 175-b. In some implementations, the SMO 180-a may communicate with components configured in accordance with a 4G RAN (e.g., via an 01 interface). Additionally, or alternatively, in some implementations, the SMO 180-a may communicate directly with one or more RUs 170-a via an 01 interface. The SMO 180-a also may include aNon- RT RIC 175-a configured to support functionality of the SMO 180-a.
[0092] The Non-RT RIC 175-a may be configured to include a logical function that enables non-real-time control and optimization of RAN elements and resources, Artificial Intelligence (Al) or Machine Learning (ML) workflows including model training and updates, or policy -based guidance of applications / features in the Near-RT RIC 175-b. The Non-RT RIC 175-a may be coupled to or communicate with (e.g., via an Al interface) the Near-RT RIC 175-b. The Near-RT RIC 175-b may be configured to include a logical function that enables near-real-time control and optimization of RAN elements and resources via data collection and actions over an interface (e.g., via an E2 interface) connecting one or more CUs 160-a, one or more DUs 165-a, or both, as well as an O-eNB 210, with the Near-RT RIC 175-b.
[0093] In some examples, to generate AI / ML models to be deployed in the Near-RT RIC 175-b. the Non-RT RIC 175-a may receive parameters or external enrichment information from external servers. Such information may be utilized by the Near-RT RIC 175-b and may be received at the SMO 180-a or the Non-RT RIC 175-a from nonnetwork data sources or from network functions. In some examples, the Non-RT RIC 175-a or the Near-RT RIC 175-b may be configured to tune RAN behavior or performance. For example, the Non-RT RIC 175-a may monitor long-term trends and patterns for performance and employ Al or ML models to perform corrective actions through the SMO 180-a (e.g., reconfiguration via 01) or via generation of RAN management policies (e.g.. Al policies).
[0094] The network architecture 200 may support control plane security for wireless devices. For example, a UE 115-a may use an SRB (e.g., SRBO) to transmit an RRC request message to anetwork entity (e.g., a CU 160-a, a DU 165-a, an RU 170-a) to establish an RRC connection for communications with the network in accordance with a control plane operation mode. Additionally, while operating in the control plane operation mode, the UE 115-a may report that the UE 1 15-a supports AS level security for signaling communicated in the control plane operation mode. For example, the UE 115-a may indicate, to the network, a capability of the UE to support AS level security for signaling communicated in the control plane operation mode (e.g., for signaling communicated via one or more SRBs). In response to the capability' of the UE to support AS level security for signaling communicated in the control plane operation mode, the network entity may transmit a security' mode command to the UE 115-a. The security mode command may indicate that the one or more AS security protocols are enabled for another SRB (e.g., SRB1). Accordingly, in response to the security mode command, the UE 115-a may use the one or more AS security' protocols to report location information to the network entity via SRB1. In some examples, enabling the UE 115-a to indicate that the UE supports AS level security for signaling communicated in the control plane operation mode may lead to improved security for location reporting by the UE 115-a, among other benefits.
[0095] FIG. 3 shows an example of a wireless communications system 300 that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure. In some examples, the wireless communications system 300 may implement aspects of the wireless communications system 100 and the network architecture 200. For example, the wireless communications system 300 may include anetwork entity 305 (e.g., e.g., a CU, a DU, an RU, a base station, an IAB node, or one or more other network nodes), and a UE 315, which may be examples of the corresponding devices illustrated by and described with reference to FIGs. 1 and 2. The network entity 305 and the UE 315 may communicate within a coverage area 310, which may be an example of a coverage area 110 illustrated by and described with reference to FIG. 1. Additionally, the network entity 305 and the UE 315 may communicate via a communication link 320, which may be an example of a communication link 125-a illustrated by and described with reference to FIG. 2.
[0096] The wireless communications system 300 may support communications via one or more types of radio bearers, such as DRBs and SRBs. The UE 315 may communicate user plane data via a DRB and control plane data via an SRB. That is, an SRB may be an example of a channel (e.g., a transport channel, a logical channel) for one or more upper layer messages (e.g., RRC messages, NAS messages). In some cases, the UE 315 may operate in accordance with a control plane operation mode (also referred to as a control plane CIoT optimization mode) in which the UE 315 may refrain from establishing a DRB and may communicate with the network via an SRB. That is, in the control plane operation mode, the exchange of data between the UE 315 and the network entity 305 may occur via one or more SRBs (e.g., at the NAS or RRC level). The UE 315 and the network entity 305 may use NAS security for data exchanged via one or more SRBs. Accordingly, for data exchanged between the UE 315 and the network entity 305 in accordance with the control plane operation mode (e.g., while the UE 315 operates in the control plane operation mode), encryption and integrity protection may be performed at the NAS layer. In other words, while operating in the control plane operation mode, the UE 315 may not support or operate with AS security establishment.
[0097] In some cases, the UE 315 may determine to report location information to the network while operating in the control plane operation mode. For example, the UE 315 may be an example of a NarrowBand-Intemet-of-Things (NB-IoT) device and the wireless communications system 300 may support the deployment of one or more NB- loT non-terrestrial networks (NTNs). In such an example, one or more satellite operators may necessitate (e.g., based on regulatory requirements) that the network obtain information regarding the location of the UE 315, such that the UE 315 may be connected to a core network of a country in which the UE 315 is located. In such cases, the location information may be reported without encryption or integrity protection. For example, the location information may be generated (and thus added to a data message) at the AS layer and, because the control plane operation mode uses NAS layer security, the location information may be communicated without encry ption or integrity protection. Communicating location information without encryption or integrity protection may lead to one or more security vulnerabilities for the UE 315. For example, because the location information is unencrypted, the location information may beexposed to unintended recipients. Additionally, or alternatively, the network may be unable to request location information from the UE 315, for example, when the network lacks consent from the user of the UE 315. In some cases, the UE 315 may support one or more location protocols (e.g., an LTE positioning protocol (LPP)) through which the UE 315 may report location information. However, such location protocols may be associated with a relatively large quantity of storage (e.g., may include the use of a relatively large quantity of storage), which may not be suitable for some types of UEs. For example, relatively large quantities of storage may not be supported by low-cost NB-loT UEs.
[0098] As illustrated in the example of FIG. 3, the UE 315 and the network entity 305 may support a framework for establishing AS security for the control plane operation mode. In accordance with the framework (e.g., a relatively quick RAN-based solution), the network entity 305 may use a security mode command for the purpose of reporting UE location (e.g., enabling the reporting of the UE location) via an RRC message or NAS message in an SRB (e.g., SRB1). Additionally, in accordance with the framework, AS security may be used to provide encry ption and integrity protection for the location information, for example, without a user plane bearer (e.g., a DRB) and while preserving the control plane operation mode. The network entity 305 may use the security mode command (or another ty pe of message) to enable the AS security' for the control plane operation mode when, for example, a previously reported (e.g., last reported) location of the UE is invalid. The network entity 305 may disable the AS security for the control plane operation mode, for example, when AS security and the associated signaling overhead (e.g., 4 bytes of message authentication code-integrity (MAC-I)) may not be used (e.g., may not be necessary). For example, the network entity 305 may disable the AS security when the UE 315 communicates a message with control plane data and without user plane data (e.g., when the UE 315 only communicates control plane data).
[0099] As illustrated in the example of FIG. 3, the UE 315 may transmit an RRC request message 325 to the network entity 305 via a first SRB (e.g., SRB0). The RRC request message 325 may include a request to establish an RRC connection with the network entity 305 for the UE 315 to operate in accordance with the control plane operation mode. In some examples, the RRC request message 325 may be an exampleof a message used to request the establishment of an RRC connection. For example, the RRC request message 325 may be an example of an RRCComectionRequest message (e.g., Msg3, a message transmitting during an RRC connection establishment procedure). Additionally, or alternatively, the RRC request message 325 may be an example of a message used to initiate a control plane early data transmission (CP EDT). For example, the RRC request message 325 may be an example of an RRCEarlyDataRequest message.
[0100] Additionally, the UE 315 may transmit a UE capability' indication 330 to the network entity 305. The UE capability indication 330 may indicate a capability of the UE 315 to support AS security for communications associated with the control plane operation mode. For example, the UE capability indication 330 may include a control plane AS security' capability7indication or a location update request indication. In some examples, the UE 315 may transmit the RRC request message 325 with the UE capability indication 330. For example, the UE 315 may include the UE capability indication 330 in the RRCConnectionRequest message or the RRCEarlyDataRequest message. In some other examples, the UE 315 may transmit the UE capability7indication 330 after transmission of the RRC request message 325. For example, the UE 315 may include the UE capability indication 330 in a message used to confirm the successful completion of an RRC connection (e.g., in an RRCConnectionSetupComplete message, in Msg5, during an initial attach procedure).
[0101] In response to the UE capability7indication 330, the UE 315 may receive an AS security7indication 335 from the network entity' 305. In other words, in response to the capability of the UE 315 to support AS security for communications associated with the control plane operation mode, the network entity7305 may transmit an RRC message to the UE 315, and the RRC message may include the AS security indication 335. The AS security7indication 335 may indicate that one or more AS security protocols are enabled (e.g.. configured) for one or more SRBs, such as SRB1. Accordingly, the UE 315 may use the one or more SRBs to transmit location information 340 to the network entity7305. For example, after reception of the AS security indication 335, the UE 315 may transmit the location information 340 to the network entity7via SRB 1. The use of AS security7for reporting transmitting the location information 340 may be relativelyless complex for some types of UEs, such as low-cost NB-IoT UEs, and may therefore lead to improved performance, among other benefits.
[0102] The location information 340 may indicate location information associated with the UE 315 (e.g., may indicate a location of the UE 315) and may be encry pted using the one or more AS security protocols. For example, the UE 315 may use the control plane operation mode, may indicate that the UE 315 supports the AS security (e.g., via the UE capability indication 330), and may receive a security mode command (e.g., the AS security indication 335). In such an example, the UE 315 may establish an SRB (e.g., SRBlbis) and may determine to derive one or more security keys. In some examples, the UE 315 may determine to derive one or more keys used for RRC traffic (e.g., one or more KRRC key). Additionally, the UE 315 may refrain from deriving one or more keys for user plane traffic (e.g., one or more UP keys). For example, the UE 315 may derive an integrity protection key (KRRCint), an encry ption key (KRRCenc), or both. The UE may use the encry ption key (KRRCenc) to encrypt the location information 340.
[0103] In some examples, integrity protection may be checked by the UE 315 based on the security' mode command. In such examples, the network entity 305 may refrain from (e.g., may not need to) check integrity protection for subsequent messages, such as the location information 340 (e.g.. a location report). Accordingly, in some examples, the UE 315 may refrain from using the integrity protection key (KRRCint) for the location information 340. In other yy ords, the encr ption key (KRRCenc) may be used to send the location information 340 over the SRB and integrity protection may not be used to send the location information 340 over the SRB. Integrity protection may add signaling overhead (e.g., 4 bytes of signaling overhead). As such, refraining from using the integrity protection key may lead to reduced signaling overhead, among other benefits. In some examples, the UE 315 may use an SRB control plane PDCP data PDU format (e.g., without MAC -I) for transmitting the location information 340.
[0104] The UE 315 may perform a re-establishment procedure 345 (e.g., a connection re-establishment procedure, an RRC connection re-establishment procedure) to re-establish the RRC connection. For example, the netyvork entity 305 may trigger the UE 315 (or the UE 315 may be otherwise triggered) to perform the re-establishment procedure 345. The re-establishment procedure 345 may include mobility managemententity-based (MME-based) re-establishment or AS-based re-establishment. For example, the network entity 305 may configure the UE 315 (e.g., transmit control signaling that indicates) to use an MME-based re-establishment procedure or an AS- based re-establishment procedure. In some examples, the UE 315 may receive a control message that indicates, to the UE 315, to use the MME-based re-establishment procedure or the AS-based re-establishment procedure. In such an example, the reestablishment procedure 345 may be based on the control message. That is, the reestablishment procedure 345 may be the MME-based re-establishment procedure or the AS-based re-establishment procedure.
[0105] In some examples, such as examples in which the UE 315 may experience radio link failure (RLF), the UE 315 may use the AS-based re-establishment procedure (e.g., due to AS security already being established via the security mode command). In such examples, the UE 315 may use SRB1 to send a message that confirms (e.g., indicates) the successful completion of the RRC connection re-establishment. For example, the UE 315 may use SRB1 to send an RRCComectionReestablishmentComplete message (e.g., Msg5). That is, the UE 315 may transmit, to the network entity 305 after reception of the AS security indication 335, an RRC connection complete message (or RRC connection re-establishment complete message) that indicates successful completion of the RRC connection, and transmission of the RRC connection complete message may be in accordance with the AS-based re-establishment procedure. In some examples, after the UE 315 transmits the location information 340 (e.g., in a location report) the SRB1 may be suspended until RLF is triggered. Accordingly, the AS-based re-establishment procedure may involve (e.g., may be used for) the resumption of the SRB1. After re-establishment, one or more keys (e.g., one or more new keys, such as new encryption key or a new integrity protection key) may be derived at the UE 315. Accordingly, in some examples, the AS- based re-establishment procedure may be used by the network entity 305 to refresh one or more keys (e.g., the encryption key, the integrity protection key).
[0106] In some other examples, the UE 315 may use the MME-based reestablishment procedure. In such examples, the UE 315 may refrain from using SRB1 (e.g., SRB1 may not be used). For example, the UE 315 may use the control plane operation mode and SRBlbis to send the message that confirms the successfulcompletion of the RRC connection re-establishment (e g., to send the RRCConnectionReestablishmentComplete message, to send Msg5). That is, the UE 315 may transmit, to the network entity 305 after reception of the AS security indication 335, an RRC connection complete message (or RRC connection re-establishment complete message) that indicates successful completion of the RRC connection, and transmission of the RRC connection complete message may be in accordance with the MME-based re-establishment procedure. In such examples, the MME may use NASbased MAC -I and COUNT to complete the re-establishment. In some examples, configuring the UE 315 to use an MME-based re-establishment procedure or an AS- based re-establishment procedure may lead to improved performance associated with RRC connection re-establishment, among other benefits.
[0107] FIG. 4 shows an example of a process flow 400 that supports control plane security’ for wireless devices in accordance with one or more aspects of the present disclosure. The process flow 400 may implement or may be implemented by aspects of the wireless communications system 100, the network architecture 200, and the wireless communications system 300. For example, the process flow 400 illustrates operations at a network entity 405, which may be an example of a network entity (e.g., a CU, a DU, an RU, a base station, an IAB node, or one or more other network nodes) illustrated by and described with reference to FIGs. 1 through 3. Additionally, the process flow’ 400 illustrates operations at a UE 415, which may be an example of a UE illustrated by and described w ith reference to FIGs. 1 through 3. The operations performed at the network entity 405 and the UE 415 may support improvements to communications between the network entity 405 and the UE 415, among other benefits. In the following description of the process flow’ 400, the operations performed at the netw ork entity 405 and the UE 415 may occur in a different order than the example order shown. Additionally, the operations performed at the netw ork entity' 405 and the UE 415 may be performed at different times. Some operations may be combined, and some operations may be omitted.
[0108] In some examples, the network entity 405 and the UE 415 may support a framework for establishing AS security' for a control plane operation mode in w hich the UE 415 may refrain from establishing a DRB and may communicate with the network via an SRB. For example, in accordance w ith the framework, the UE 415 may indicate acapability of the UE 415 to support AS security for an SRB (e.g., only for the SRB). For example, the UE 415 may determine to transmit a location update (e.g., to report location information) to the network entity 405. The UE 415 may determine to transmit the location update (e.g.. the UE capability indication) for a registration area update (e.g., a tracking area update (TAU)) or for initial attach. That is, the UE 415 may transmit the UE capability indication in accordance with a TAU procedure or an initial attach procedure. Additionally, or alternatively, the UE 415 may determine to transmit the location update (e.g., the UE capability indication) when a location of the UE changes by a threshold. For example, the UE 415 may determine a change in a location of the UE 415 and may transmit the UE capability’ indication based on the change in the location of the UE 415 satisfying a threshold. Additionally, or alternatively, the UE 415 may determine to transmit the location update after global navigation satellite system (GNSS) fix (e.g.. in connected mode) to update location. For example, the UE 415 may determine a location of the UE 415 based on navigation data associated with GNSS and may transmit the UE capability indication to report the location of the UE 415 to the network entity 405. As illustrated in the example of FIG. 4, the UE 415 may indicate the capability via an RRC request message (e.g., in an RRCConnectionRequest message or an RRCEarlyDataRequest message), which may be used to request the establishment of an RRC connection. The RRC request message may correspond to Msg3.
[0109] For example, at 420, the UE 415 may transmit a preamble to the network entity 405 to initiate a random access procedure with the network entity 405. The preamble, also referred to as a physical random access channel (PRACH), may correspond to Msgl. The UE 415 may initiate the random access procedure with the network entity 405 to establish an RRC connection with the network entity 405.
[0110] In some examples, at 425, the UE 415 may receive a random access response (RAR) from the network entity 405. That is, in response to receiving the preamble at 420, the network entity 405 may transmit a RAR to the UE 415. The RAR may correspond to Msg2.
[0111] At 430, the UE 415 may transmit the RRC request message to the network entity’ 405. The RRC request message may be an example of an RRC message illustrated by and described with reference to FIG. 3. For example, the RRC message may include a UE capability indication (e.g., an AS security capability indication, alocation update request indication). The UE capability indication (e.g., within the RRC request message) may be an example of a UE capability indication illustrated by and described with reference to FIG. 3. For example, the UE capability indication may indicate that the UE 415 supports AS security for one or more SRBs (e.g., only for the one or more SRBs). That is, the UE capability indication may indicate that the UE 415 supports AS security for communications associated with the control plane operation mode. The UE 415 may transmit the RRC request message with the capability indication via a first SRB (e.g., SRBO). In other words, the UE 415 may transmit, via the first SRB, a connection request message including a request to establish the RRC connection with the network entity and including the indication of the capability of the UE 415 to support AS security for the control plane operation mode. The RRC request message may correspond to Msg3.
[0112] In some examples, such as examples in which the RRC request messages (Msg3) lacks the capability indication, the network entity 405 may determine that a previously reported UE location (e.g., the UE’s last reported UE location) is valid. Accordingly, in such examples, the network entity’ 405 may refrain from enabling AS security (e.g., AS security may not need to be enabled). After the UE 415 transmits the RRC request message with the UE capability indication at 430, the UE 415 may establish one or more other SRBs. For example, the UE 415 may establish SRBlbis or SRB1, or both.
[0113] For example, at 435, the UE 415 may receive an RRC connection setup message (e.g., RRCConnectionSetup message) from the network entity 405. The RRC connection setup message may correspond to Msg4. The network entity 405 may transmit the RRC connection setup message via a second SRB (e.g., SRB Ibis), and may use the RRC connection setup message to establish a third SRB (e.g., SRB1). The RRC connection setup message may indicate one or more parameters associated with SRB1. As described herein, SRBlbis may correspond to an SRB that is associated with NB- loT devices and is usable for communications via a dedicated control channel. Additionally, as described herein, SRB1 may correspond to an SRB that is usable for communications via the dedicated control channel. In some examples, a priority level associated with SRB1 may be higher than one or more other priority levels associated with one or more other SRBs usable for communications via the dedicated controlchannel (e.g., may be higher than a respective priority level associated with SRB2 or SRB3). In some examples, the RRC connection setup message may correspond to a dedicated configuration (e.g., for SRB1). After reception of the RRC connection setup message, the UE 415 may perform contention resolution, apply the dedicated configuration, and wait for a security mode command.
[0114] For example, after the UE 415 transmits the RRC request message, the network entity 405 may retrieve the UE capability (e.g., from the UE capabilityindication). may establish SRBlbis or SRB1 (or both), and may generate a security mode command. That is. after the UE 415 transmits the RRC request message with the UE capability indication (e.g., after the network entity 405 receives the UE capability indication in Msg3), the network entity 405 may transmit a security- mode command to the UE 415. The security mode command may include an indication that one or more AS security protocols are enabled (e.g., configured) for one or more SRBs (e.g., SRB1). That is. the security mode command may include an AS security indication, which may indicate that one or more AS security protocols are enabled for SRB 1. The network entity 405 may transmit the security- mode command with Msg4 (e.g., with the RRC connection setup message) or after Msg4.
[0115] At 440, the UE 415 may receive the AS security indication. The AS securityindication may be an example of an AS security indication illustrated by and described with reference to FIG. 3. For example, the UE 415 may receive the AS securityindication via a security mode command. That is, the UE 415 may receive the security mode command, which may include the AS security indication. The AS security indication may indicate that one or more AS security protocols are enabled for SRB1. The UE 415 may receive the security mode command (e.g., an RRC message) in accordance with the control plane operation mode, and the security mod command may indicate that one or more AS security protocols are enabled for SRB1 based on (e.g., in response to) the capability indication indicating that the UE supports AS security for communications associated with the control plane operation mode. In some examples, the UE 415 may receive the AS security indication (e.g., the security mode command that includes the AS security indication) via SRB1. Although illustrated as occurring after reception of the RRC connection setup message (Msg4) at 435, the UE 415 may receive the AS security indication with (e.g., in) the RRC connection setup message.For example, at 435, the UE 415 may receive, via the second SRB (e.g., SRBl bis), the RRC connection setup command and a security mode command. In such an example, the RRC connection setup command may indicate one or more parameters associated with a third SRB (e.g., SRB1). and the security mode command may indicates that the one or more AS security protocols are enabled for the third SRB. Alternatively, the UE 415 may receive the AS security7indication after (e.g., in a different message from) the RRC connection setup message. For example, the UE 415 may receive, via the second SRB (e.g., SRBlbis), the RRC connection setup command that indicates one or more parameters associated with the third SRB (e.g., SRB1). After reception of the RRC connection setup command, the UE 415 may receive, via the third SRB and in response the RRC request message, the security mode command that indicates that the one or more AS security protocols are enabled for the third SRB (e.g., for SRB1).
[0116] In some examples, after reception of the security mode command, the UE 415 may derive one or more KRRC keys (e.g., an integrity protection key (KRRCint), an encryption key (KRRCenc), or both). Additionally, or alternatively, the UE 415 may perform an integrity check and may encrypt or cipher one or more subsequent RRC messages.
[0117] In some examples, at 445, the UE 415 may transmit an RRC connection complete message to the network entity 405. The RRC connection complete message (e.g., RRCConnectionSetupComplete message) may correspond to Msg5 and may confirm the successful completion of an RRC connection. In some examples, such as examples in which the security mode command indicates that AS security is enabled for SRB1, the UE 415 may determine that SRBlbis is no longer used (e.g.. may determine that only SRB1 is used). In such an example, the UE 415 may use SRB1 to send the RRC connection complete message (Msg5) to the network entity 405. In some other examples in which the security mode command indicates that AS security' is enabled for SRB1, the UE 415 may determine that SRBlbis may be used for NAS message delivery (e.g., all NAS message deliver). In such examples, the UE 415 may use SRBlbis to send the RRC connection complete message (Msg5). In some examples, it may be possible for the UE 415 to send the RRC connection complete message in SRB1 with integrity protection and ciphering. Additionally, for other RRC messages, such as UEinformation response messages and security mode complete messages, the UE 415 may use SRB1 with integrity protection and ciphering.
[0118] In some examples, at 450, the UE 415 may transmit location information to the network entity 405. That is, for examples in which AS security is enabled for SRB1, the UE 415 may use SRB1 (and the AS security) to send the location information (e.g., to only send location information). The location information may be an example of location information illustrated by and described with reference to FIG. 3. For example, the UE 415 may send the location information via SRB 1 in accordance with the one or more AS security’ protocols enabled for SRB1. That is, the UE 415 may transmit, to the network entity 405, a first message via the third SRB (e.g., SRB1) after reception of the AS security' indication, where the first message includes the location information associated with the UE 415, and where the location information is encrypted using the one or more AS security protocols. In some examples, the UE 415 may generate an encryption key for the one or more AS security protocols. In such examples, the UE 415 may encrypt the location information in accordance with the one or more AS security protocols using the generated encryption key.
[0119] The UE 415 may send the location information in a UE location report. After transmitting the UE location report, the UE 415 may use the control plane operation mode to transmit one or more other messages (e.g., without location information) via SRB Ibis (e.g., may bypass PDCP). In other words, after transmitting the UE location report (with the location information) the UE 415 may refrain from using SRB1. In some examples, the UE 415 may implicitly determine to refrain from using SRB1 after successful transmission of the location report. In some other examples, the UE 415 may receive a command from the network entity 405, which may indicate a release of SRB1, and hence AS security. In some examples, the UE 415 may release SRB1 to reduce signaling overhead (e.g., to save 4 bytes of signaling overhead of MAC -I for each SRB data transmission).
[0120] FIG. 5 shows an example of a process flow 500 that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure. The process flow 500 may implement or may be implemented by aspects of the wireless communications system 100, the network architecture 200, the wireless communications system 300, and the process flow 400. For example, the process flow500 illustrates operations at a network entity 505, which may be an example of a network entity (e.g., a CU, a DU, an RU, a base station, an IAB node, or one or more other network nodes) illustrated by and described with reference to FIGs. 1 through 4. Additionally, the process flow 500 illustrates operations at a UE 515, which may be an example of a UE illustrated by and described with reference to FIGs. 1 through 4. The operations performed at the network entity' 505 and the UE 515 may support improvements to communications between the network entity 505 and the UE 515, among other benefits. In the following description of the process flow 500, the operations performed at the network entity’ 505 and the UE 515 may occur in a different order than the example order shown. Additionally, the operations performed at the network entity 505 and the UE 515 may be performed at different times. Some operations may be combined, and some operations may be omitted.
[0121] In some examples, the network entity 505 and the UE 515 may support a framework for establishing AS security for a control plane operation mode in which the UE 515 may refrain from establishing a DRB and may communicate with the network via an SRB. In accordance with the framework, the UE 515 may indicate a capability- of the UE 515 to support AS security for an SRB (e.g., only for the SRB). For example, the UE 515 may determine to transmit a location update (e.g., to report location information) to the network entity 505. The UE 515 may determine to transmit the location update for a registration area update (e.g., a tracking area update (TAU)), for initial attach, or when a location of the UE changes by a threshold. Additionally, or alternatively, the UE 515 may determine to transmit the location update after GNSS fix (e.g., in an RRC connected mode) to update the location of the UE 515. As illustrated in the example of FIG. 5, the UE 515 may indicate the capability via an RRC connection complete message, which may be used to confirm the successful completion of an RRC connection. The RRC connection complete message may correspond to Msg5.
[0122] At 520, the UE 515 may transmit an RRC request message to the network entity 505. The RRC request message may be an example of an RRC request message illustrated by and described with reference to FIGs. 3 and 4. For example, the UE 515 may use the RRC request message (e.g., in an RRCConnectionRequest message or an RRCEarlyDcitaRequest message) to request the establishment of an RRC connection. That is. the RRC request message may include a request to establish an RRC with thenetwork entity 505 for the UE 515 to operate in accordance with the control plane operation mode for communications without establishment of a DRB. The RRC request message may correspond to Msg3. The UE 515 may transmit the RRC request message to the network entity 505 via a first SRB (e.g.. SRBO).
[0123] In some examples, at 525, the UE 515 may receive an RRC connection setup message (e g., RRCConnectionSetup message) from the network entity 505. The RRC connection setup message may be an example of an RRC connection setup message illustrated by and described with reference to FIG. 4. For example, the RRC connection setup message may correspond to Msg4. The network entity 505 may transmit the RRC connection setup message via a second SRB (e.g., SRB Ibis), and may use the RRC connection setup message to establish a third SRB (e.g., SRB1). In some examples, the RRC connection setup message may correspond to a dedicated configuration (e.g., for SRB1).
[0124] At 530, the UE 515 may transmit an RRC connection complete message to the network entity 505. The RRC connection complete message may be an example of an RRC connection complete message illustrated by and described with reference to FIG. 4. For example, the RRC connection complete message (e.g., RRCConnectionSetupComplete message) may correspond to Msg5 and may confirm the successful completion of an RRC connection. As illustrated in the example of FIG. 5, the RRC connection complete message may include the UE capability indication (e.g., an AS security capability indication, a location update needed indication). In other words, the RRC connection complete message may indicate (e.g.. via the UE capability indication) that the UE 515 supports AS security for one or more SRBs (e.g.. only for the one or more SRBs). That is, the UE capability indication included in the RRC connection complete message may indicate that the UE 515 supports AS security' for communications associated with the control plane operation mode. The UE 515 maytransmit the RRC connection complete message in SRBlbis. In other words, the UE 515 may transmit, via the second SRB (e.g., SRBbisl), an RRC connection complete message that indicates successful establishment of the RRC connection and includes the UE capability indication.
[0125] In some examples, the RRC connection complete message (Msg5) may lack the UE capability indication. In such an example, the network entity 505 may determinethat a previously reported UE location (e.g., a last reported UE location) is valid. Accordingly, in such examples, the network entity 505 may refrain from enabling AS security (e.g., AS security may not need to be enabled if Msg5 lacks the capability indication). In some other examples, after receiving Msg5, the network entity 505 may determine that location information for the UE 515 is to be obtained (e.g., may determine that location information for the UE 515 is needed).
[0126] At 535, the UE 515 may receive an AS security indication from the network entity 505. The AS security indication may be an example of an AS security' indication illustrated by and described with reference to FIG. 4. For example, the UE may receive the AS security indication via a security mode command. The UE 515 may receive the security mode command (e.g., and the AS security indication) via SRB1 after transmitting the UE capability' indication in Msg5. In other w ords, the security mode command may include an AS security indication, which may indicate that indicates one or more AS security protocols are enabled for SRB1. The UE 515 may receive the security mode command (e.g., an RRC message) in accordance with the control plane operation mode, and the security mode command may indicate that one or more AS security protocols are enabled for SRB1 based on (e.g., in response to) the capability indication indicating that the UE supports AS security for communications associated with the control plane operation mode. In some examples, the AS security indication may indicate that the one or more AS security protocols are only enabled for SRB.
[0127] In some examples, such as examples in which the security mode command indicates that AS security is enabled for SRB1, the UE 515 may determine that SRBlbis is no longer used (e.g.. may determine that only SRB1 is used). In such an example, the UE 515 may use SRB1 to send one or more subsequent RRC messages. Additionally, or alternatively, for examples in which the security mode command indicates that AS security is enabled for SRB1, the UE 515 may determine that SRBlbis may be used for NAS message delivery (e.g., all NAS message deliver). In such examples, for other RRC messages, such as for UE information response messages and security mode complete messages, the UE 515 may use SRB1 with integrity protection and ciphering.
[0128] For example, at 540, the UE 515 may transmit location information to the network entity 505. The location information may be an example of location information illustrated by and described with reference to FIGs. 3 and 4. For example,in response to AS security being enabled for SRB 1, the UE 515 may use SRB1 (and the enabled AS security) to send the location information (e.g., to only send location information) to the network entity 505. That is, the UE 515 may send the location information via SRB1 in accordance with the one or more AS security protocols enabled for SRB1. In some examples, the UE 515 may transmit the location information in response to a request from the network entity 505. For example, the UE 515 may receive a UE information request (e.g., UEInformationRequest-NB) from the network entity 505 via SRB1. In some examples, the UE information request may include a coarse location request. In such examples, the UE 515 may transmit the location information to the network entity 505 in a UE information response. That is, the UE 515 may transmit the UE information response (e.g., UEInformationResponse-NB) to the network entity 505 via SRB1. In some examples, the UE information response may include coarse location information. In some examples, the UE 515 may refrain from using (e.g., may release) SRB1 after sending the location information (e.g., a UE location report). The UE 515 refraining from using SRB1 may be implicit (e.g., after successful location report) or based on signaling from the network entity 505.
[0129] For example, at 545, the UE 515 may receive a release SRB1 command from the network entity. The release SRB1 command may indicate for the UE 515 to release SRB1 and, as such, may also indicate for the UE 515 to release AS security’. In other words, the UE 515 may receive, from the network entity 505 after transmission of the location information, the release SRB1 command (e.g., a connection release command, a security release command) that indicates the one or more AS security protocols are disabled for the third SRB (e.g., for SRB1). In some examples, releasing SRB1 may lead to reduced signaling overhead (e.g., may save 4 bytes of signaling overhead of MAC-I for each SRB data transmission). For example, in response to receiving the release SRB1 command, the UE 515 may transmit, to the network entity 505, an RRC message via the second SRB (e.g.. SRBlbis). In such an example, the RRC message may include information encrypted using one or more NAS security protocols.
[0130] In some examples, at 550, the UE 515 may receive a control plane operation mode indication from the network entity 505. The control plane operation mode indication may indicate for the UE 515 to continue to use the control plane operation mode for communication with the network entity 505. Accordingly, after transmittingthe location information, the UE 515 may use the control plane operation mode to transmit one or more other messages (e.g., without location information) via SRBlbis (e.g., may bypass PDCP). Accordingly, the UE 515 may refrain from using SRB1. In some examples, enabling AS security for communication associated with the control plane operation mode may lead to increased security and improved reliability of wireless communications between the UE 515 and the network entity, among other benefits.
[0131] FIG. 6 shows a block diagram 600 of a device 605 that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure. The device 605 may be an example of aspects of a UE 1 15 as described herein. The device 605 may include a receiver 610, a transmitter 615, and a communications manager 620. The device 605, or one or more components of the device 605 (e.g., the receiver 610, the transmitter 615. the communications manager 620). may include at least one processor, which may be coupled with at least one memory, to, individually or collectively, support or enable the described techniques. Each of these components may be in communication with one another (e.g., via one or more buses).
[0132] The receiver 610 may provide a means for receiving information such as packets, user data, control information, or any combination thereof associated with various information channels (e.g., control channels, data channels, information channels related to control plane security for wireless devices). Information may be passed on to other components of the device 605. The receiver 610 may utilize a single antenna or a set of multiple antennas.
[0133] The transmitter 615 may provide a means for transmitting signals generated by other components of the device 605. For example, the transmitter 615 may transmit information such as packets, user data, control information, or any combination thereof associated with various information channels (e.g., control channels, data channels, information channels related to control plane security for wireless devices). In some examples, the transmitter 615 may be co-located with a receiver 610 in a transceiver module. The transmitter 615 may utilize a single antenna or a set of multiple antennas.
[0134] The communications manager 620, the receiver 610, the transmitter 615, or various combinations or components thereof may be examples of means for performing various aspects of control plane security for wireless devices as described herein. For example, the communications manager 620. the receiver 610. the transmitter 615, or various combinations or components thereof may be capable of performing one or more of the functions described herein.
[0135] In some examples, the communications manager 620, the receiver 610, the transmitter 615, or various combinations or components thereof may be implemented in hardware (e.g., in communications management circuitry). The hardware may include at least one of a processor, a digital signal processor (DSP), a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a microcontroller, discrete gate or transistor logic, discrete hardware components, or any combination thereof configured as or otherwise supporting, individually or collectively, a means for performing the functions described in the present disclosure. In some examples, at least one processor and at least one memory coupled with the at least one processor may be configured to perform one or more of the functions described herein (e.g.. by one or more processors, individually or collectively, executing instructions stored in the at least one memory).
[0136] Additionally, or alternatively, the communications manager 620, the receiver 610, the transmitter 615, or various combinations or components thereof may be implemented in code (e.g., as communications management software or firmware) executed by at least one processor (e.g., referred to as a processor-executable code). If implemented in code executed by at least one processor, the functions of the communications manager 620, the receiver 610, the transmitter 615, or various combinations or components thereof may be performed by a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, a microcontroller, or any combination of these or other programmable logic devices (e.g., configured as or otherwise supporting, individually or collectively, a means for performing the functions described in the present disclosure).
[0137] In some examples, the communications manager 620 may be configured to perform various operations (e.g., receiving, obtaining, monitoring, outputting, transmitting) using or otherwise in cooperation with the receiver 610. the transmitter615, or both. For example, the communications manager 620 may receive information from the receiver 610, send information to the transmitter 615, or be integrated in combination with the receiver 610, the transmitter 615, or both to obtain information, output information, or perform various other operations as described herein.
[0138] The communications manager 620 may support wireless communications in accordance with examples as disclosed herein. For example, the communications manager 620 is capable of, configured to, or operable to support a means for transmitting, via a first SRB, a request to establish an RRC connection with a network entity for the UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB. The communications manager 620 is capable of, configured to, or operable to support a means for transmitting an indication of a capability of the UE to support AS security for communications associated with the control plane operation mode. The communications manager 620 is capable of. configured to, or operable to support a means for receiving, from the network entity in accordance with the control plane operation mode, an RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security for communications associated with the control plane operation mode.
[0139] By including or configuring the communications manager 620 in accordance with examples as described herein, the device 605 (e.g., at least one processor controlling or otherwise coupled with the receiver 610, the transmitter 615, the communications manager 620. or a combination thereof) may support techniques for more efficient utilization of communication resources.
[0140] FIG. 7 shows a block diagram 700 of a device 705 that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure. The device 705 may be an example of aspects of a device 605 or a UE 115 as described herein. The device 705 may include a receiver 710, a transmitter 715, and a communications manager 720. The device 705, or one or more components of the device 705 (e.g., the receiver 710, the transmitter 715, the communications manager 720), may include at least one processor, which may be coupled with at least one memory, to support the described techniques. Each of these components may be in communication with one another (e.g., via one or more buses).
[0141] The receiver 710 may provide a means for receiving information such as packets, user data, control information, or any combination thereof associated with various information channels (e.g., control channels, data channels, information channels related to control plane security for wireless devices). Information may be passed on to other components of the device 705. The receiver 710 may utilize a single antenna or a set of multiple antennas.
[0142] The transmitter 715 may provide a means for transmitting signals generated by other components of the device 705. For example, the transmitter 715 may transmit information such as packets, user data, control information, or any combination thereof associated with various information channels (e.g., control channels, data channels, information channels related to control plane security for wireless devices). In some examples, the transmitter 715 may be co-located with a receiver 710 in a transceiver module. The transmitter 715 may utilize a single antenna or a set of multiple antennas.
[0143] The device 705, or various components thereof, may be an example of means for performing various aspects of control plane security for wireless devices as described herein. For example, the communications manager 720 may include a request component 725, a capability7indication component 730, an RRC message component 735, or any combination thereof. The communications manager 720 may be an example of aspects of a communications manager 620 as described herein. In some examples, the communications manager 720, or various components thereof, may' be configured to perform various operations (e.g., receiving, obtaining, monitoring, outputting, transmitting) using or otherwise in cooperation with the receiver 710, the transmitter 715, or both. For example, the communications manager 720 may receive information from the receiver 710, send information to the transmitter 715, or be integrated in combination with the receiver 710, the transmitter 715, or both to obtain information, output information, or perform various other operations as described herein.
[0144] The communications manager 720 may support wireless communications in accordance with examples as disclosed herein. The request component 725 is capable of, configured to, or operable to support a means for transmitting, via a first SRB, a request to establish an RRC connection with a network entity' for the UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB. The capability indication component 730 is capable of,configured to, or operable to support a means for transmitting an indication of a capability of the UE to support AS security for communications associated with the control plane operation mode. The RRC message component 735 is capable of. configured to, or operable to support a means for receiving, from the network entity in accordance with the control plane operation mode, an RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security' for communications associated with the control plane operation mode.
[0145] FIG. 8 shows a block diagram 800 of a communications manager 820 that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure. The communications manager 820 may be an example of aspects of a communications manager 620, a communications manager 720, or both, as described herein. The communications manager 820, or various components thereof, may be an example of means for performing various aspects of control plane security’ for wireless devices as described herein. For example, the communications manager 820 may include a request component 825, a capability indication component 830, an RRC message component 835, a location information component 840, a connection establishment component 845. a NAS security component 850, an SRB component 855, a connection release component 860, an AS security’ component 865, or any combination thereof. Each of these components, or components or subcomponents thereof (e.g., one or more processors, one or more memories), may communicate, directly or indirectly, with one another (e.g.. via one or more buses).
[0146] The communications manager 820 may support wireless communications in accordance with examples as disclosed herein. The request component 825 is capable of, configured to, or operable to support a means for transmitting, via a first SRB, a request to establish an RRC connection with a network entity for the UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB. The capability indication component 830 is capable of, configured to, or operable to support a means for transmitting an indication of a capability of the UE to support AS security’ for communications associated with the control plane operation mode. The RRC message component 835 is capable of. configured to, or operable to support a means for receiving, from the network entity inaccordance with the control plane operation mode, an RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security' for communications associated with the control plane operation mode.
[0147] In some examples, to support transmitting the indication of the capability, the request component 825 is capable of, configured to, or operable to support a means for transmitting, via the first SRB, a connection request message including the request to establish the RRC connection with the network entity and including the indication of the capability.
[0148] In some examples, to support receiving the RRC message, the RRC message component 835 is capable of, configured to, or operable to support a means for receiving, via a second SRB, a connection setup command and a security mode command, where the connection setup command indicates one or more parameters associated with a third SRB, and where the security mode command indicates that the one or more AS security protocols are configured for the third SRB.
[0149] In some examples, to support receiving the RRC message, the RRC message component 835 is capable of, configured to, or operable to support a means for receiving, via a second SRB, a connection setup command that indicates one or more parameters associated with a third SRB. In some examples, to support receiving the RRC message, the RRC message component 835 is capable of, configured to, or operable to support a means for receiving, via the third SRB, the RRC message after reception of the connection setup command, the RRC message including a security mode command that indicates that the one or more AS security protocols are configured for the third SRB.
[0150] In some examples, to support transmitting the indication of the capability, the capability indication component 830 is capable of, configured to, or operable to support a means for transmitting, via a second SRB, a connection complete message that indicates successful establishment of the RRC connection, where the connection complete message includes the indication of the capability.
[0151] In some examples, the location information component 840 is capable of, configured to, or operable to support a means for transmitting, to the network entity, afirst message via the at least one SRB after reception of the RRC message, where the first message includes location information associated with the UE, and where the location information is encrypted using the one or more AS security protocols.
[0152] In some examples, the NAS security component 850 is capable of, configured to, or operable to support a means for transmitting, to the network entity after transmission of the first message, a second message via a second SRB, where the at least one SRB includes a third SRB, and where the second message includes information encrypted using one or more NAS security protocols.
[0153] In some examples, the connection release component 860 is capable of, configured to, or operable to support a means for receiving, from the network entity after transmission of the first message, a security release command that indicates the one or more AS security protocols are disabled for the third SRB, where transmission of the second message via the third SRB is in response to the security release command.
[0154] In some examples, the AS security component 865 is capable of, configured to, or operable to support a means for generating an encryption key for the one or more AS security' protocols. In some examples, the AS security component 865 is capable of, configured to, or operable to support a means for encrypting the location information in accordance with the one or more AS security' protocols using the encryption key.
[0155] In some examples, the connection establishment component 845 is capable of, configured to, or operable to support a means for transmitting, to the network entity, a first message via a second SRB after reception of the RRC message, where the RRC message indicates that the one or more AS security' protocols are configured for a third SRB, and where the first message includes a NAS message or a second RRC message that indicates successful establishment of the RRC connection.
[0156] In some examples, the second SRB is associated with NB-IoT devices and is usable for communications via a dedicated control channel. In some examples, the third SRB is usable for communications via the dedicated control channel, and a priority' level associated with the third SRB is higher than one or more other priority' levels associated with one or more other SRBs usable for communications via the dedicated control channel.
[0157] In some examples, the connection establishment component 845 is capable of, configured to, or operable to support a means for transmitting, to the network entity after reception of the RRC message, a connection complete message that indicates successful completion of the RRC connection, where transmission of the connection complete message is in accordance with an MME-based re-establishment procedure or an AS-based re-establishment procedure.
[0158] In some examples, the connection establishment component 845 is capable of, configured to, or operable to support a means for receiving a control message that indicates, to the UE, to use the MME-based re-establishment procedure or the AS-based re-establishment procedure, where transmitting the connection complete message is in accordance with the control message.
[0159] In some examples, to support transmitting the indication of the capability, the capability indication component 830 is capable of, configured to, or operable to support a means for transmitting the indication of the capability in accordance with a TAU procedure or an initial attach procedure.
[0160] In some examples, to support transmitting the indication of the capability, the capability' indication component 830 is capable of, configured to, or operable to support a means for determining a change in a location of the UE. In some examples, to support transmitting the indication of the capability, the capability indication component 830 is capable of, configured to, or operable to support a means for transmitting the indication of the capability' based on the change in the location of the UE satisfying a threshold.
[0161] In some examples, to support transmitting the indication of the capability, the capability indication component 830 is capable of, configured to, or operable to support a means for determining a location of the UE based on navigation data associated with a global navigation satellite system. In some examples, to support transmitting the indication of the capability', the capability indication component 830 is capable of, configured to, or operable to support a means for transmitting the indication of the capability to report the location of the UE to the network entity. In some examples, the RRC message indicates that the one or more AS security protocols are only enabled for the at least one SRB.
[0162] FIG. 9 shows a diagram of a system 900 including a device 905 that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure. The device 905 may be an example of or include components of a device 605. a device 705, or a UE 115 as described herein. The device 905 may communicate (e.g., wirelessly) with one or more other devices (e.g., network entities 105, UEs 115, or a combination thereof). The device 905 may include components for bi-directional voice and data communications including components for transmitting and receiving communications, such as a communications manager 920. an input / output (I / O) controller, such as an I / O controller 910, a transceiver 915. one or more antennas 925, at least one memory 930, code 935, and at least one processor 940. These components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more buses (e.g.. a bus 945).
[0163] The I / O controller 910 may manage input and output signals for the device 905. The I / O controller 910 may also manage peripherals not integrated into the device 905. In some cases, the I / O controller 910 may represent a physical connection or port to an external peripheral. In some cases, the I / O controller 910 may utilize an operating system such as iOS®, ANDROID®. MS-DOS®, MS-WINDOWS®, OS / 2®, UNIX®. LINUX®, or another known operating system. Additionally, or alternatively, the I / O controller 910 may represent or interact with a modem, a keyboard, a mouse, a touchscreen, or a similar device. In some cases, the I / O controller 910 may be implemented as part of one or more processors, such as the at least one processor 940. In some cases, a user may interact with the device 905 via the I / O controller 910 or via hardware components controlled by the I / O controller 910.
[0164] In some cases, the device 905 may include a single antenna. However, in some other cases, the device 905 may have more than one antenna, which may be capable of concurrently transmitting or receiving multiple wireless transmissions. The transceiver 915 may communicate bi-directionally via the one or more antennas 925 using wired or wireless links as described herein. For example, the transceiver 915 may represent a wireless transceiver and may communicate bi-directionally with another wireless transceiver. The transceiver 915 may also include a modem to modulate the packets, to provide the modulated packets to one or more antennas 925 for transmission.and to demodulate packets received from the one or more antennas 925. The transceiver 915, or the transceiver 915 and one or more antennas 925, may be an example of a transmitter 615, a transmitter 715, a receiver 610, a receiver 710, or any combination thereof or component thereof, as described herein.
[0165] The at least one memory 930 may include random access memory (RAM) and read-only memory (ROM). The at least one memory 930 may store computer- readable, computer-executable, or processor-executable code, such as the code 935. The code 935 may include instructions that, when executed by the at least one processor 940, cause the device 905 to perform various functions described herein. The code 935 may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. In some cases, the code 935 may not be directly executable by the at least one processor 940 but may cause a computer (e.g., when compiled and executed) to perform functions described herein. In some cases, the at least one memory 930 may include, among other things, a basic I / O system (BIOS) which may control basic hardware or software operation such as the interaction with peripheral components or devices.
[0166] The at least one processor 940 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, a microcontroller, an ASIC, an FPGA. a programmable logic device, a discrete gate or transistor logic component, a discrete hardware component, or any combination thereof). In some cases, the at least one processor 940 may be configured to operate a memory array using a memory' controller. In some other cases, a memory controller may be integrated into the at least one processor 940. The at least one processor 940 may be configured to execute computer-readable instructions stored in a memory (e.g., the at least one memory 930) to cause the device 905 to perform various functions (e.g., functions or tasks supporting control plane security' for wireless devices). For example, the device 905 or a component of the device 905 may include at least one processor 940 and at least one memory 930 coupled with or to the at least one processor 940, the at least one processor 940 and the at least one memory^ 930 configured to perform various functions described herein. In some examples, the at least one processor 940 may include multiple processors and the at least one memory' 930 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiplememories, which may, individually or collectively, be configured to perform various functions described herein. In some examples, the at least one processor 940 may be a component of a processing system, which may refer to a system (such as a series) of machines, circuitry (including, for example, one or both of processor circuitry (which may include the at least one processor 940) and memory circuitry (which may include the at least one memory 930)), or components, that receives or obtains inputs and processes the inputs to produce, generate, or obtain a set of outputs. The processing system may be configured to perform one or more of the functions described herein. For example, the at least one processor 940 or a processing system including the at least one processor 940 may be configured to, configurable to, or operable to cause the device 905 to perform one or more of the functions described herein. Further, as described herein, being “configured to,” being “configurable to,” and being “operable to” may be used interchangeably and may be associated with a capability, when executing code 935 (e.g., processor-executable code) stored in the at least one memory 930 or otherwise, to perform one or more of the functions described herein.
[0167] The communications manager 920 may support wireless communications in accordance with examples as disclosed herein. For example, the communications manager 920 is capable of. configured to, or operable to support a means for transmitting, via a first SRB, a request to establish an RRC connection with a network entity for the UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB. The communications manager 920 is capable of, configured to, or operable to support a means for transmitting an indication of a capability of the UE to support AS security for communications associated with the control plane operation mode. The communications manager 920 is capable of, configured to, or operable to support a means for receiving, from the netw ork entity in accordance with the control plane operation mode, an RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security for communications associated with the control plane operation mode.
[0168] By including or configuring the communications manager 920 in accordance with examples as described herein, the device 905 may support techniques for improvedcommunication reliability, more efficient utilization of communication resources, and improved coordination between devices.
[0169] In some examples, the communications manager 920 may be configured to perform various operations (e.g.. receiving, monitoring, transmitting) using or otherwise in cooperation with the transceiver 915, the one or more antennas 925, or any combination thereof. Although the communications manager 920 is illustrated as a separate component, in some examples, one or more functions described with reference to the communications manager 920 may be supported by or performed by the at least one processor 940, the at least one memory 930, the code 935, or any combination thereof. For example, the code 935 may include instructions executable by the at least one processor 940 to cause the device 905 to perform various aspects of control plane security for wireless devices as described herein, or the at least one processor 940 and the at least one memory 930 may be otherwise configured to, individually or collectively, perform or support such operations.
[0170] FIG. 10 shows a block diagram 1000 of a device 1005 that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure. The device 1005 may be an example of aspects of a network entity 105 as described herein. The device 1005 may include a receiver 1010, a transmitter 1015. and a communications manager 1020. The device 1005, or one or more components of the device 1005 (e.g., the receiver 1010, the transmitter 1015, the communications manager 1020), may include at least one processor, which may be coupled with at least one memory, to, individually or collectively, support or enable the described techniques. Each of these components may be in communication with one another (e.g., via one or more buses).
[0171] The receiver 1010 may provide a means for obtaining (e.g., receiving, determining, identifying) information such as user data, control information, or any combination thereof (e g., I / Q samples, symbols, packets, protocol data units, service data units) associated with various channels (e.g., control channels, data channels, information channels, channels associated with a protocol stack). Information may be passed on to other components of the device 1005. In some examples, the receiver 1010 may support obtaining information by receiving signals via one or more antennas. Additionally, or alternatively, the receiver 1010 may support obtaining information byreceiving signals via one or more wired (e.g., electrical, fiber optic) interfaces, wireless interfaces, or any combination thereof.
[0172] The transmitter 1015 may provide a means for outputting (e.g., transmitting, providing, conveying, sending) information generated by other components of the device 1005. For example, the transmitter 1015 may output information such as user data, control information, or any combination thereof (e.g., I / Q samples, symbols, packets, protocol data units, service data units) associated with various channels (e.g., control channels, data channels, information channels, channels associated with a protocol stack). In some examples, the transmitter 1015 may support outputting information by transmitting signals via one or more antennas. Additionally, or alternatively, the transmitter 1015 may support outputting information by transmitting signals via one or more wired (e.g., electrical, fiber optic) interfaces, wireless interfaces, or any combination thereof. In some examples, the transmitter 1015 and the receiver 1010 may be co-located in a transceiver, which may include or be coupled with a modem.
[0173] The communications manager 1020, the receiver 1010, the transmitter 1015, or various combinations or components thereof may be examples of means for performing various aspects of control plane security for wireless devices as described herein. For example, the communications manager 1020, the receiver 1010, the transmitter 1015, or various combinations or components thereof may be capable of performing one or more of the functions described herein.
[0174] In some examples, the communications manager 1020, the receiver 1010, the transmitter 1015, or various combinations or components thereof may be implemented in hardware (e.g., in communications management circuitry). The hardware may include at least one of a processor, a DSP, a CPU, an ASIC, an FPGA or other programmable logic device, a microcontroller, discrete gate or transistor logic, discrete hardware components, or any combination thereof configured as or otherwise supporting, individually or collectively, a means for performing the functions described in the present disclosure. In some examples, at least one processor and at least one memory coupled with the at least one processor may be configured to perform one or more of the functions described herein (e.g., by one or more processors, individually or collectively, executing instructions stored in the at least one memory).
[0175] Additionally, or alternatively, the communications manager 1020, the receiver 1010, the transmitter 1015, or various combinations or components thereof may be implemented in code (e.g., as communications management software or firmware) executed by at least one processor (e.g., referred to as a processor-executable code). If implemented in code executed by at least one processor, the functions of the communications manager 1020, the receiver 1010, the transmitter 1015, or various combinations or components thereof may be performed by a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, a microcontroller, or any combination of these or other programmable logic devices (e.g., configured as or otherwise supporting, individually or collectively, a means for performing the functions described in the present disclosure).
[0176] In some examples, the communications manager 1020 may be configured to perform various operations (e.g.. receiving, obtaining, monitoring, outputting, transmitting) using or otherwise in cooperation with the receiver 1010, the transmitter 1015, or both. For example, the communications manager 1020 may receive information from the receiver 1010, send information to the transmitter 1015, or be integrated in combination with the receiver 1010, the transmitter 1015, or both to obtain information, output information, or perform various other operations as described herein.
[0177] The communications manager 1020 may support wireless communications in accordance with examples as disclosed herein. For example, the communications manager 1020 is capable of, configured to, or operable to support a means for obtaining, via a first SRB, a request to establish an RRC connection with a UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB. The communications manager 1020 is capable of, configured to, or operable to support a means for obtaining an indication of a capability of the UE to support AS security for communications associated with the control plane operation mode. The communications manager 1020 is capable of, configured to, or operable to support a means for outputting an RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security for communications associated with the control plane operation mode.
[0178] By including or configuring the communications manager 1020 in accordance with examples as described herein, the device 1005 (e.g., at least one processor controlling or otherwise coupled with the receiver 1010, the transmitter 1015, the communications manager 1020, or a combination thereof) may support techniques for more efficient utilization of communication resources.
[0179] FIG. 11 shows a block diagram 1100 of a device 1105 that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure. The device 1105 may be an example of aspects of a device 1005 or a network entity 105 as described herein. The device 1105 may include a receiver 1110, a transmitter 1115, and a communications manager 1120. The device 1105, or one or more components of the device 1105 (e.g. , the receiver 1110, the transmitter 1115, the communications manager 1120), may include at least one processor, which may be coupled with at least one memory, to support the described techniques. Each of these components may be in communication with one another (e.g.. via one or more buses).
[0180] The receiver 11 10 may provide a means for obtaining (e.g., receiving, determining, identifying) information such as user data, control information, or any combination thereof (e.g., I / Q samples, symbols, packets, protocol data units, service data units) associated with various channels (e.g., control channels, data channels, information channels, channels associated with a protocol stack). Information may be passed on to other components of the device 1105. In some examples, the receiver 1110 may support obtaining information by receiving signals via one or more antennas. Additionally, or alternatively, the receiver 1110 may support obtaining information by receiving signals via one or more wired (e.g., electrical, fiber optic) interfaces, wireless interfaces, or any combination thereof.
[0181] The transmitter 1115 may provide a means for outputting (e.g., transmitting, providing, conveying, sending) information generated by other components of the device 1105. For example, the transmitter 1115 may output information such as user data, control information, or any combination thereof (e.g., I / Q samples, symbols, packets, protocol data units, service data units) associated with various channels (e.g., control channels, data channels, information channels, channels associated with a protocol stack). In some examples, the transmitter 1115 may support outputting information by transmitting signals via one or more antennas. Additionally, oralternatively, the transmitter 1 1 15 may support outputting information by transmitting signals via one or more wired (e.g., electrical, fiber optic) interfaces, wireless interfaces, or any combination thereof. In some examples, the transmitter 1115 and the receiver 1110 may be co-located in a transceiver, which may include or be coupled with a modem.
[0182] The device 1105, or various components thereof, may be an example of means for performing various aspects of control plane security for wireless devices as described herein. For example, the communications manager 1120 may include an RRC connection request component 1125, a UE capability indication component 1130, an AS security indication component 1135, or any combination thereof. The communications manager 1120 may be an example of aspects of a communications manager 1020 as described herein. In some examples, the communications manager 1120, or various components thereof, may be configured to perform various operations (e.g., receiving, obtaining, monitoring, outputting, transmitting) using or otherwise in cooperation with the receiver 11 10, the transmitter 11 15, or both. For example, the communications manager 1120 may receive information from the receiver 1110, send information to the transmitter 1115, or be integrated in combination with the receiver 1110, the transmitter 1115. or both to obtain information, output information, or perform various other operations as described herein.
[0183] The communications manager 1120 may support wireless communications in accordance with examples as disclosed herein. The RRC connection request component 1125 is capable of, configured to, or operable to support a means for obtaining, via a first SRB, a request to establish an RRC connection with a UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB. The UE capability indication component 1130 is capable of, configured to, or operable to support a means for obtaining an indication of a capability' of the UE to support AS security for communications associated with the control plane operation mode. The AS security' indication component 1135 is capable of, configured to, or operable to support a means for outputting an RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security for communications associated with the control plane operation mode.
[0184] FIG. 12 shows a block diagram 1200 of a communications manager 1220 that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure. The communications manager 1220 may be an example of aspects of a communications manager 1020, a communications manager 1120, or both, as described herein. The communications manager 1220, or various components thereof, may be an example of means for performing various aspects of control plane security for wireless devices as described herein. For example, the communications manager 1220 may include an RRC connection request component 1225. a UE capability indication component 1230, an AS security indication component 1235, a UE location indication component 1240, a connection complete indication component 1245, a connection setup indication component 1250, a security' mode indication component 1255, a connection release indication component 1260, or any combination thereof. Each of these components, or components or subcomponents thereof (e.g., one or more processors, one or more memories), may communicate, directly or indirectly, with one another (e.g., via one or more buses). The communications may include communications within a protocol layer of a protocol stack, communications associated with a logical channel of a protocol stack (e.g., between protocol layers of a protocol stack, within a device, component, or virtualized component associated with a network entity 105, between devices, components, or virtualized components associated with a network entity' 105), or any combination thereof.
[0185] The communications manager 1220 may support wireless communications in accordance with examples as disclosed herein. The RRC connection request component 1225 is capable of, configured to, or operable to support a means for obtaining, via a first SRB, a request to establish an RRC connection with a UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB. The UE capability indication component 1230 is capable of, configured to, or operable to support a means for obtaining an indication of a capability of the UE to support AS security' for communications associated with the control plane operation mode. The AS security indication component 1235 is capable of, configured to, or operable to support a means for outputting an RRC message that indicates one or more AS security' protocols are configured for at least one SRB in response to thecapability of the UE to support AS security for communications associated with the control plane operation mode.
[0186] In some examples, to support obtaining the indication of the capability, the UE capability indication component 1230 is capable of, configured to, or operable to support a means for obtaining, via the first SRB, a connection request message including the request to establish the RRC connection with the network entity and including the indication of the capability'.
[0187] In some examples, to support outputting the RRC message, the AS security' indication component 1235 is capable of, configured to. or operable to support a means for outputting, via a second SRB, a connection setup command and a security mode command, where the connection setup command indicates one or more parameters associated with a third SRB, and where the security mode command indicates that the one or more AS security protocols are configured for the third SRB.
[0188] In some examples, to support outputting the RRC message, the connection setup indication component 1250 is capable of, configured to. or operable to support a means for outputting, via a second SRB, a connection setup command that indicates one or more parameters associated with a third SRB. In some examples, to support outputting the RRC message, the security mode indication component 1255 is capable of, configured to, or operable to support a means for outputting, via the third SRB, the RRC message after reception of the connection setup command, the RRC message including a security mode command that indicates that the one or more AS securityprotocols are configured for the third SRB.
[0189] In some examples, to support obtaining the indication of the capability, the UE capability indication component 1230 is capable of, configured to, or operable to support a means for obtaining, via a second SRB, a connection complete message that indicates successful establishment of the RRC connection, where the connection complete message includes the indication of the capability.
[0190] In some examples, the UE location indication component 1240 is capable of, configured to, or operable to support a means for obtaining a first message via the at least one SRB, where the first message includes location information associated withthe UE, and where the location information is encrypted using the one or more AS security protocols.
[0191] In some examples, the UE location indication component 1240 is capable of, configured to, or operable to support a means for obtaining a second message via a second SRB. where the at least one SRB includes a third SRB, and where the second message includes information encrypted using one or more NAS security protocols.
[0192] In some examples, the connection release indication component 1260 is capable of, configured to, or operable to support a means for outputting a security release command that indicates the one or more AS security protocols are disabled for the third SRB, where the second message is obtained via the third SRB in response to the security’ release command.
[0193] In some examples, the connection complete indication component 1245 is capable of, configured to, or operable to support a means for obtaining a first message via a second SRB, where the first message includes a NAS message or a second RRC message that indicates successful establishment of the RRC connection.
[0194] In some examples, the connection complete indication component 1245 is capable of, configured to, or operable to support a means for obtaining a connection complete message that indicates successful completion of the RRC connection, where the connection complete message is obtained in accordance with an MME-based reestablishment procedure or an AS-based re-establishment procedure.
[0195] In some examples, the connection complete indication component 1245 is capable of, configured to, or operable to support a means for outputting a control message that indicates, to the UE, to use the MME-based re-establishment procedure or the AS-based re-establishment procedure, where the connection complete message is obtained in accordance with the control message.
[0196] In some examples, to support obtaining the indication of the capability, the UE capability indication component 1230 is capable of, configured to, or operable to support a means for obtaining the indication of the capability in accordance wi th a TAU procedure or an initial attach procedure.
[0197] In some examples, to support obtaining the indication of the capability, the UE capability indication component 1230 is capable of, configured to, or operable to support a means for obtaining the indication of the capability based on a change in a location of the UE satisfying a threshold. In some examples, the RRC message indicates that the one or more AS security protocols are only enabled for the at least one SRB.
[0198] FIG. 13 shows a diagram of a system 1300 including a device 1305 that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure. The device 1305 may be an example of or include components of a device 1005, a device 1105, or a network entity 105 as described herein. The device 1305 may communicate with other network devices or network equipment such as one or more of the network entities 105, UEs 115, or any combination thereof. The communications may include communications over one or more wired interfaces, over one or more wireless interfaces, or any combination thereof. The device 1305 may include components that support outputting and obtaining communications, such as a communications manager 1320, a transceiver 1310, one or more antennas 1315, at least one memory 1325, code 1330, and at least one processor 1335. These components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more buses (e.g., a bus 1340).
[0199] The transceiver 1310 may support bi-directional communications via wired links, wireless links, or both as described herein. In some examples, the transceiver 1310 may include a wired transceiver and may communicate bi-directionally with another wired transceiver. Additionally, or alternatively, in some examples, the transceiver 1310 may include a wireless transceiver and may communicate bidirectionally with another wireless transceiver. In some examples, the device 1305 may include one or more antennas 1315, which may be capable of transmitting or receiving wireless transmissions (e.g., concurrently). The transceiver 1310 may also include a modem to modulate signals, to provide the modulated signals for transmission (e.g., by one or more antennas 1315, by a wired transmitter), to receive modulated signals (e.g., from one or more antennas 1315, from a wired receiver), and to demodulate signals. In some implementations, the transceiver 1310 may include one or more interfaces, such as one or more interfaces coupled with the one or more antennas 1315 that are configuredto support various receiving or obtaining operations, or one or more interfaces coupled with the one or more antennas 1315 that are configured to support various transmitting or outputting operations, or a combination thereof. In some implementations, the transceiver 1310 may include or be configured for coupling with one or more processors or one or more memory components that are operable to perform or support operations based on received or obtained information or signals, or to generate information or other signals for transmission or other outputting, or any combination thereof. In some implementations, the transceiver 1310, or the transceiver 1310 and the one or more antennas 1315. or the transceiver 1310 and the one or more antennas 1315 and one or more processors or one or more memon components (e.g., the at least one processor 1335, the at least one memory 1325, or both), may be included in a chip or chip assembly that is installed in the device 1305. In some examples, the transceiver 1310 may be operable to support communications via one or more communications links (e.g., communication link(s) 125, backhaul communication link(s) 120, a midhaul communication link 162, a fronthaul communication link 168).
[0200] The at least one memory 1325 may include RAM, ROM, or any combination thereof. The at least one memory' 1325 may store computer-readable, computerexecutable. or processor-executable code, such as the code 1330. The code 1330 may include instructions that, when executed by one or more of the at least one processor 1335, cause the device 1305 to perform various functions described herein. The code 1330 may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. In some cases, the code 1330 may not be directly executable by a processor of the at least one processor 1335 but may cause a computer (e.g., when compiled and executed) to perform functions described herein. In some cases, the at least one memory' 1325 may include, among other things, a BIOS which may control basic hardware or software operation such as the interaction with peripheral components or devices. In some examples, the at least one processor 1335 may include multiple processors and the at least one memory' 1325 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories which may, individually or collectively, be configured to perform various functions herein (for example, as part of a processing system).
[0201] The at least one processor 1335 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, an ASIC, a CPU, an FPGA, a microcontroller, a programmable logic device, discrete gate or transistor logic, a discrete hardware component, or any combination thereof). In some cases, the at least one processor 1335 may be configured to operate a memory array using a memory controller. In some other cases, a memory controller may be integrated into one or more of the at least one processor 1335. The at least one processor 1335 may be configured to execute computer-readable instructions stored in a memory (e.g., one or more of the at least one memory 1325) to cause the device 1305 to perform various functions (e.g., functions or tasks supporting control plane security for wireless devices). For example, the device 1305 or a component of the device 1305 may include at least one processor 1335 and at least one memory 1325 coupled with one or more of the at least one processor 1335, the at least one processor 1335 and the at least one memory 1325 configured to perform various functions described herein. The at least one processor 1335 may be an example of a cloud-computing platform (e.g., one or more physical nodes and supporting software such as operating systems, virtual machines, or container instances) that may host the functions (e.g., by executing code 1330) to perform the functions of the device 1305. The at least one processor 1335 may be any one or more suitable processors capable of executing scripts or instructions of one or more software programs stored in the device 1305 (such as within one or more of the at least one memory 1325). In some examples, the at least one processor 1335 may include multiple processors and the at least one memory 1325 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein. In some examples, the at least one processor 1335 may be a component of a processing system, which may refer to a system (such as a series) of machines, circuitry (including, for example, one or both of processor circuitry (which may include the at least one processor 1335) and memory circuitry (which may include the at least one memory 1325)), or components, that receives or obtains inputs and processes the inputs to produce, generate, or obtain a set of outputs. The processing system may be configured to perform one or more of the functions described herein. For example, the at least one processor 1335 or a processing system including the at least one processor 1335 may be configured to, configurable to, or operable to cause thedevice 1305 to perform one or more of the functions described herein. Further, as described herein, being “configured to,” being “configurable to,” and being “operable to” may be used interchangeably and may be associated with a capability, when executing code stored in the at least one memory 1325 or otherwise, to perform one or more of the functions described herein.
[0202] In some examples, a bus 1340 may support communications of (e.g., within) a protocol layer of a protocol stack. In some examples, a bus 1340 may support communications associated with a logical channel of a protocol stack (e.g., between protocol layers of a protocol stack), which may include communications performed within a component of the device 1305, or between different components of the device 1305 that may be co-located or located in different locations (e.g., where the device 1305 may refer to a system in which one or more of the communications manager 1320, the transceiver 1310, the at least one memory 1325, the code 1330, and the at least one processor 1335 may be located in one of the different components or divided between different components).
[0203] In some examples, the communications manager 1320 may manage aspects of communications with a core network 130 (e.g., via one or more wired or wireless backhaul links). For example, the communications manager 1320 may manage the transfer of data communications for client devices, such as one or more UEs 115. In some examples, the communications manager 1320 may manage communications with one or more other network entities 105, and may include a controller or scheduler for controlling communications with UEs 115 (e.g.. in cooperation with the one or more other network devices). In some examples, the communications manager 1320 may support an X2 interface within an LTE / LTE-A wireless communications network technology to provide communication between network entities 105.
[0204] The communications manager 1320 may support wireless communications in accordance with examples as disclosed herein. For example, the communications manager 1320 is capable of, configured to, or operable to support a means for obtaining, via a first SRB, a request to establish an RRC connection with a UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB. The communications manager 1320 is capable of, configured to, or operable to support a means for obtaining an indication of a capability of the UEto support AS security for communications associated with the control plane operation mode. The communications manager 1320 is capable of, configured to, or operable to support a means for outputting an RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security for communications associated with the control plane operation mode.
[0205] By including or configuring the communications manager 1320 in accordance with examples as described herein, the device 1305 may support techniques for improved communication reliability, more efficient utilization of communication resources, and improved coordination between devices.
[0206] In some examples, the communications manager 1320 may be configured to perform various operations (e.g., receiving, obtaining, monitoring, outputting, transmitting) using or otherwise in cooperation with the transceiver 1310, the one or more antennas 1315 (e.g., where applicable), or any combination thereof. Although the communications manager 1320 is illustrated as a separate component, in some examples, one or more functions described with reference to the communications manager 1320 may be supported by or performed by the transceiver 1310, one or more of the at least one processor 1335, one or more of the at least one memory’ 1325, the code 1330. or any combination thereof (for example, by a processing system including at least a portion of the at least one processor 1335, the at least one memory 1325, the code 1330, or any combination thereof). For example, the code 1330 may include instructions executable by one or more of the at least one processor 1335 to cause the device 1305 to perform various aspects of control plane security for wireless devices as described herein, or the at least one processor 1335 and the at least one memory 1325 may be otherwise configured to, individually or collectively, perform or support such operations.
[0207] FIG. 14 shows a flowchart illustrating a method 1400 that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure. The operations of the method 1400 may be implemented by a UE or its components as described herein. For example, the operations of the method 1400 may be performed by a UE 115 as described with reference to FIGs. 1 through 9. In some examples, a UE may execute a set of instructions to control the functionalelements of the UE to perform the described functions. Additionally, or alternatively, the UE may perform aspects of the described functions using special-purpose hardware.
[0208] At 1405, the method may include transmitting, via a first SRB, a request to establish an RRC connection with a network entity for the UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB. The operations of 1405 may be performed in accordance with examples as disclosed herein. In some examples, aspects of the operations of 1405 may be performed by a request component 825 as described with reference to FIG. 8.
[0209] At 1410, the method may include transmitting an indication of a capability of the UE to support AS security for communications associated with the control plane operation mode. The operations of 1410 may be performed in accordance with examples as disclosed herein. In some examples, aspects of the operations of 1410 may be performed by a capability indication component 830 as described with reference to FIG. 8.
[0210] At 1415, the method may include receiving, from the network entity in accordance with the control plane operation mode, an RRC message that indicates one or more AS security protocols are configrued for at least one SRB in response to the capability of the UE to support AS security' for communications associated with the control plane operation mode. The operations of 1415 may be performed in accordance with examples as disclosed herein. In some examples, aspects of the operations of 1415 may be performed by an RRC message component 835 as described with reference to FIG. 8.
[0211] FIG. 15 shows a flowchart illustrating a method 1500 that supports control plane security for wireless devices in accordance with one or more aspects of the present disclosure. The operations of the method 1500 may be implemented by a network entity or its components as described herein. For example, the operations of the method 1500 may be performed by a network entity as described with reference to FIGs. 1 through 5 and 10 through 13. In some examples, a network entity may execute a set of instructions to control the functional elements of the network entity to perform the described functions. Additionally, or alternatively, the network entity may perform aspects of the described functions using special-purpose hardware.
[0212] At 1505, the method may include obtaining, via a first SRB, a request to establish an RRC connection with a UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB. The operations of 1505 may be performed in accordance with examples as disclosed herein. In some examples, aspects of the operations of 1505 may be performed by an RRC connection request component 1225 as described with reference to FIG. 12.
[0213] At 1510, the method may include obtaining an indication of a capability of the UE to support AS security for communications associated with the control plane operation mode. The operations of 1510 may be performed in accordance with examples as disclosed herein. In some examples, aspects of the operations of 1510 may be performed by a UE capability' indication component 1230 as described with reference to FIG. 12.
[0214] At 1515, the method may include outputting an RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security for communications associated with the control plane operation mode. The operations of 1515 may be performed in accordance with examples as disclosed herein. In some examples, aspects of the operations of 1515 may be performed by an AS security indication component 1235 as described with reference to FIG. 12.
[0215] The following provides an overview of aspects of the present disclosure:
[0216] Aspect 1 : A method for wireless communications by a UE, comprising: transmitting, via a first SRB, a request to establish a RRC connection with a network entity for the UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB; transmitting an indication of a capability of the UE to support AS security for communications associated with the control plane operation mode; and receiving, from the network entity in accordance with the control plane operation mode, a RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability of the UE to support AS security for communications associated with the control plane operation mode.
[0217] Aspect 2: The method of aspect 1 , wherein transmitting the indication of the capability comprises: transmitting, via the first SRB, a connection request message comprising the request to establish the RRC connection with the network entity and comprising the indication of the capability.
[0218] Aspect 3: The method of aspect 2, wherein receiving the RRC message comprises: receiving, via a second SRB, a connection setup command and a security mode command, wherein the connection setup command indicates one or more parameters associated with a third SRB, and wherein the security mode command indicates that the one or more AS security protocols are configured for the third SRB.
[0219] Aspect 4: The method of any of aspects 2 through 3. wherein receiving the RRC message comprises: receiving, via a second SRB, a connection setup command that indicates one or more parameters associated with a third SRB; and receiving, via the third SRB in, the RRC message after reception of the connection setup command, the RRC message comprising a security mode command that indicates that the one or more AS security' protocols are configured for the third SRB.
[0220] Aspect 5: The method of any of aspects 1 through 4, wherein transmitting the indication of the capability comprises: transmitting, via a second SRB, a connection complete message that indicates successful establishment of the RRC connection, wherein the connection complete message comprises the indication of the capability.
[0221] Aspect 6: The method of any of aspects 1 through 5. further comprising: transmitting, to the network entity, a first message via the at least one SRB after reception of the RRC message, wherein the first message comprises location information associated with the UE, and wherein the location information is encrypted using the one or more AS security protocols.
[0222] Aspect 7: The method of aspect 6, further comprising: transmitting, to the network entity after transmission of the first message, a second message via a second SRB, wherein the at least one SRB comprises a third SRB, and wherein the second message comprises information encrypted using one or more non-AS security protocols.
[0223] Aspect 8: The method of aspect 7, further comprising: receiving, from the network entity after transmission of the first message, a security’ release command thatindicates the one or more AS security protocols are disabled for the third SRB, wherein transmission of the second message via the third SRB is in response to the security7release command.
[0224] Aspect 9: The method of any of aspects 7 through 8. further comprising: generating an encryption key for the one or more AS security protocols; and encrypting the location information in accordance with the one or more AS security protocols using the encryption key.
[0225] Aspect 10: The method of any of aspects 1 through 9, further comprising: transmitting, to the network entity, a first message via a second SRB after reception of the RRC message, wherein the RRC message indicates that the one or more AS security protocols are configured for a third SRB, and wherein the first message comprises a non- AS message or a second RRC message that indicates successful establishment of the RRC connection.
[0226] Aspect 11 : The method of aspect 10, wherein the second SRB is associated with NB-IoT devices and is usable for communications via a dedicated control channel; and the third SRB is usable for communications via the dedicated control channel, and a priority level associated with the third SRB is higher than one or more other priority levels associated with one or more other SRBs usable for communications via the dedicated control channel.
[0227] Aspect 12: The method of any of aspects 1 through 11, further comprising: transmitting, to the network entity after reception of the RRC message, a connection complete message that indicates successful completion of the RRC connection, wherein transmission of the connection complete message is in accordance with a mobility management entity-based reestablishment procedure or an AS-based reestablishment procedure.
[0228] Aspect 13: The method of aspect 12, further comprising: receiving a control message that indicates, to the UE, to use the mobility management entity -based reestablishment procedure or the AS-based reestablishment procedure, wherein transmitting the connection complete message is in accordance with the control message.
[0229] Aspect 14: The method of any of aspects 1 through 13, wherein transmitting the indication of the capability comprises: transmitting the indication of the capability in accordance with a tracking area update procedure or an initial attach procedure.
[0230] Aspect 15: The method of any of aspects 1 through 14, wherein transmitting the indication of the capability comprises: determining a change in a location of the UE; and transmitting the indication of the capability based at least in part on the change in the location of the UE satisfying a threshold.
[0231] Aspect 16: The method of any of aspects 1 through 15, wherein transmitting the indication of the capability comprises: determining a location of the UE based at least in part on navigation data associated with a global navigation satellite system: and transmitting the indication of the capability to report the location of the UE to the network entity.
[0232] Aspect 17: The method of any of aspects 1 through 16, wherein the RRC message indicates that the one or more AS security protocols are only enabled for the at least one SRB.
[0233] Aspect 18: A method for wireless communications by a network entity, comprising: obtaining, via a first SRB, a request to establish a RRC connection with a UE to operate in accordance with a control plane operation mode for communications without establishment of a DRB; obtaining an indication of a capability of the UE to support AS security for communications associated with the control plane operation mode: and outputting a RRC message that indicates one or more AS security protocols are configured for at least one SRB in response to the capability’ of the UE to support AS security for communications associated with the control plane operation mode.
[0234] Aspect 19: The method of aspect 18, wherein obtaining the indication of the capability comprises: obtaining, via the first SRB. a connection request message comprising the request to establish the RRC connection with the network entity’ and comprising the indication of the capability.
[0235] Aspect 20: The method of aspect 19, wherein outputting the RRC message comprises: outputting, via a second SRB, a connection setup command and a security mode command, wherein the connection setup command indicates one or moreparameters associated with a third SRB, and wherein the security mode command indicates that the one or more AS security7protocols are configured for the third SRB.
[0236] Aspect 21 : The method of any of aspects 19 through 20, wherein outputting the RRC message comprises: outputting, via a second SRB, a connection setup command that indicates one or more parameters associated with a third SRB; and outputting, via the third SRB, the RRC message after reception of the connection setup command, the RRC message comprising a security7mode command that indicates that the one or more AS security protocols are configured for the third SRB.
[0237] Aspect 22: The method of any of aspects 18 through 21, wherein obtaining the indication of the capability comprises: obtaining, via a second SRB, a connection complete message that indicates successful establishment of the RRC connection, wherein the connection complete message comprises the indication of the capability7.
[0238] Aspect 23: The method of any of aspects 18 through 22, further comprising: obtaining a first message via the at least one SRB. wherein the first message comprises location information associated with the UE, and wherein the location information is encrypted using the one or more AS security7protocols.
[0239] Aspect 24: The method of aspect 23, further comprising: obtaining a second message via a second SRB, wherein the at least one SRB comprises a third SRB, and wherein the second message comprises information encrypted using one or more non- AS security7protocols.
[0240] Aspect 25: The method of aspect 24. further comprising: outputting a security7release command that indicates the one or more AS security protocols are disabled for the third SRB, wherein the second message is obtained via the third SRB in response to the security release command.
[0241] Aspect 26: The method of any of aspects 18 through 25, further comprising: obtaining a first message via a second SRB. wherein the first message comprises a non- AS message or a second RRC message that indicates successful establishment of the RRC connection.
[0242] Aspect 27: The method of any of aspects 18 through 26, further comprising: obtaining a connection complete message that indicates successful completion of theRRC connection, wherein the connection complete message is obtained in accordance with a mobility management entity-based reestablishment procedure or an AS-based reestablishment procedure.
[0243] Aspect 28: The method of aspect 27, further comprising: outputting a control message that indicates, to the UE, to use the mobility management entity-based reestablishment procedure or the AS-based reestablishment procedure, wherein the connection complete message is obtained in accordance with the control message.
[0244] Aspect 29: The method of any of aspects 18 through 28, wherein obtaining the indication of the capability comprises: obtaining the indication of the capability in accordance with a tracking area update procedure or an initial attach procedure.
[0245] Aspect 30: The method of any of aspects 18 through 29. wherein obtaining the indication of the capability comprises: obtaining the indication of the capability' based at least in part on a change in a location of the UE satisfying a threshold.
[0246] Aspect 31 : The method of any of aspects 18 through 30, wherein the RRC message indicates that the one or more AS security protocols are only enabled for the at least one SRB.
[0247] Aspect 32: A UE for wireless communications, comprising one or more memories storing processor-executable code, and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the UE to perform a method of any of aspects 1 through 17.
[0248] Aspect 33: A UE for wireless communications, comprising at least one means for performing a method of any of aspects 1 through 17.
[0249] Aspect 34: A non-transitory computer-readable medium storing code for wireless communications, the code comprising instructions executable by one or more processors to perform a method of any of aspects 1 through 17.
[0250] Aspect 35: A network entity for wireless communications, comprising one or more memories storing processor-executable code, and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the network entity to perform a method of any of aspects 18 through 31.
[0251] Aspect 36: A network entity for wireless communications, comprising at least one means for performing a method of any of aspects 18 through 31.
[0252] Aspect 37: A non-transitory computer-readable medium storing code for wireless communications, the code comprising instructions executable by one or more processors to perform a method of any of aspects 18 through 31.
[0253] It should be noted that the methods described herein describe possible implementations. The operations and the steps may be rearranged or otherwise modified and other implementations are possible. Further, aspects from two or more of the methods may be combined.
[0254] Although aspects of an LTE, LTE-A, LTE-A Pro, or NR system may be described for purposes of example, and LTE, LTE-A. LTE-A Pro, or NR terminology may be used in much of the description, the techniques described herein are applicable beyond LTE, LTE-A, LTE-A Pro, or NR networks. For example, the described techniques may be applicable to various other wireless communications systems such as Ultra Mobile Broadband (UMB), Institute of Electrical and Electronics Engineers (IEEE) 802.1 1 (Wi-Fi), IEEE 802. 16 (WiMAX), IEEE 802.20, Flash-OFDM, as well as other systems and radio technologies not explicitly mentioned herein.
[0255] Information and signals described herein may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
[0256] The various illustrative blocks and components described in connection with the disclosure herein may be implemented or performed using a general-purpose processor, a DSP, an ASIC, a CPU, an FPGA or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor but, in the alternative, the processor may be any processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices (e.g., a combination of a DSP and a microprocessor,multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration). Any functions or operations described herein as being capable of being performed by a processor may be performed by multiple processors that, individually or collectively, are capable of performing the described functions or operations.
[0257] The functions described herein may be implemented using hardware, software executed by a processor, firmware, or any combination thereof. If implemented using software executed by a processor, the functions may be stored as or transmitted using one or more instructions or code of a computer-readable medium. Other examples and implementations are within the scope of the disclosure and appended claims. For example, due to the nature of software, functions described herein may be implemented using software executed by a processor, hardware, firmware, hardwiring, or combinations of any of these. Features implementing functions may also be physically located at various positions, including being distributed such that portions of functions are implemented at different physical locations.
[0258] Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one location to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer. By way of example, and not limitation, non-transitory computer-readable media may include RAM, ROM, electrically erasable programmable ROM (EEPROM), flash memory, compact disk (CD) ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that may be used to carry or store desired program code means in the form of instructions or data structures and that may be accessed by a general-purpose or special-purpose computer or a general-purpose or special-purpose processor. Also, any connection is properly termed a computer-readable medium. For example, if the software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of computer-readable medium. Disk and disc, as used herein, include CD. laser disc,optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray disc. Disks may reproduce data magnetically, and discs may reproduce data optically using lasers. Combinations of the above are also included within the scope of computer-readable media. Any functions or operations described herein as being capable of being performed by a memory may be performed by multiple memories that, individually or collectively, are capable of performing the described functions or operations.
[0259] As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of or “one or more of’) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i. e. , A and B and C). Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on.”
[0260] As used herein, including in the claims, the article “a” before a noun is open- ended and understood to refer to “at least one” of those nouns or “one or more” of those nouns. Thus, the terms “a,” “at least one,” “one or more,” and “at least one of one or more” may be interchangeable. For example, if a claim recites “a component” that performs one or more functions, each of the individual functions may be performed by a single component or by any combination of multiple components. Thus, the term “a component” having characteristics or performing functions may refer to “at least one of one or more components” having a particular characteristic or performing a particular function. Subsequent reference to a component introduced with the article “a” using the terms “the” or “said” may refer to any or all of the one or more components. For example, a component introduced with the article “a” may be understood to mean “one or more components.” and referring to “the component” subsequently in the claims may be understood to be equivalent to referring to “at least one of the one or more components.” Similarly, subsequent reference to a component introduced as “one or more components” using the terms “the” or “said” may refer to any or all of the one or more components. For example, referring to “the one or more components”subsequently in the claims may be understood to be equivalent to referring to “at least one of the one or more components.”
[0261] The term “determine” or “determining” encompasses a variety of actions and, therefore, “determining” can include calculating, computing, processing, deriving, investigating, looking up (such as via looking up in a table, a database, or another data structure), ascertaining, and the like. Also, “determining” can include receiving (e g., receiving information), accessing (e.g., accessing data stored in memory), and the like. Also, “determining” can include resolving, obtaining, selecting, choosing, establishing, and other such similar actions.
[0262] In the appended figures, similar components or features may have the same reference label. Further, various components of the same type may be distinguished by following the reference label by a dash and a second label that distinguishes among the similar components. If just the first reference label is used in the specification, the description is applicable to any one of the similar components having the same first reference label irrespective of the second reference label or other subsequent reference label.
[0263] The description set forth herein, in connection with the appended drawings, describes example configurations and does not represent all the examples that may be implemented or that are within the scope of the claims. The term “example” used herein means “serving as an example, instance, or illustration” and not “preferred” or “advantageous over other examples.” The detailed description includes specific details for the purpose of providing an understanding of the described techniques. These techniques, however, may be practiced without these specific details. In some figures, known structures and devices are shown in block diagram form in order to avoid obscuring the concepts of the described examples.
[0264] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs describedherein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.
Claims
CLAIMSWhat is claimed is:1 . A user equipment (UE), comprising: one or more memories storing processor-executable code; and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the UE to: transmit, via a first signaling radio bearer, a request to establish a radio resource control connection with a network entity for the UE to operate in accordance with a control plane operation mode for communications without establishment of a data radio bearer; transmit an indication of a capability of the UE to support access stratum security for communications associated with the control plane operation mode; and receive, from the network entity' in accordance with the control plane operation mode, a radio resource control message that indicates one or more access stratum security protocols are configured for at least one signaling radio bearer in response to the capability of the UE to support access stratum security for communications associated with the control plane operation mode.
2. The UE of claim 1, wherein, to transmit the indication of the capability, the one or more processors are individually or collectively operable to execute the code to cause the UE to: transmit, via the first signaling radio bearer, a connection request message comprising the request to establish the radio resource control connection with the network entity and comprising the indication of the capability.
3. The UE of claim 2, wherein, to receive the radio resource control message, the one or more processors are individually or collectively operable to execute the code to cause the UE to: receive, via a second signaling radio bearer, a connection setup command and a security' mode command, wherein the connection setup command indicates one or more parameters associated with a third signaling radio bearer, and wherein the securitymode command indicates that the one or more access stratum security protocols are configured for the third signaling radio bearer.
4. The UE of claim 2, wherein, to receive the radio resource control message, the one or more processors are individually or collectively operable to execute the code to cause the UE to: receive, via a second signaling radio bearer, a connection setup command that indicates one or more parameters associated with a third signaling radio bearer; and receive, via the third signaling radio bearer, the radio resource control message after reception of the connection setup command, the radio resource control message comprising a security' mode command that indicates that the one or more access stratum security protocols are configured for the third signaling radio bearer.
5. The UE of claim 1, wherein, to transmit the indication of the capability', the one or more processors are individually or collectively operable to execute the code to cause the UE to: transmit, via a second signaling radio bearer, a connection complete message that indicates successful establishment of the radio resource control connection, wherein the connection complete message comprises the indication of the capability'.
6. The UE of claim 1, wherein the one or more processors are individually or collectively further operable to execute the code to cause the UE to: transmit, to the network entity', a first message via the at least one signaling radio bearer after reception of the radio resource control message, wherein the first message comprises location information associated with the UE, and wherein the location information is encry pted using the one or more access stratum security' protocols.
7. The UE of claim 6, wherein the one or more processors are individually or collectively further operable to execute the code to cause the UE to: transmit, to the network entity7after transmission of the first message, a second message via a second signaling radio bearer, wherein the at least one signaling radio bearer comprises a third signaling radio bearer, and wherein the second messagecomprises information encrypted using one or more non-access stratum security protocols.
8. The UE of claim 7, wherein the one or more processors are individually or collectively further operable to execute the code to cause the UE to: receive, from the network entity after transmission of the first message, a security release command that indicates the one or more access stratum security protocols are disabled for the third signaling radio bearer, wherein transmission of the second message via the third signaling radio bearer is in response to the security release command.
9. The UE of claim 7, wherein the one or more processors are individually or collectively further operable to execute the code to cause the UE to: generate an encryption key for the one or more access stratum security protocols; and encrypt the location information in accordance with the one or more access stratum security protocols using the encryption key.
10. The UE of claim 1, wherein the one or more processors are individually or collectively further operable to execute the code to cause the UE to: transmit, to the network entity, a first message via a second signaling radio bearer after reception of the radio resource control message, wherein the radio resource control message indicates that the one or more access stratum security protocols are configured for a third signaling radio bearer, and wherein the first message comprises a non-access stratum message or a second radio resource control message that indicates successful establishment of the radio resource control connection.
11. The UE of claim 10, wherein: the second signaling radio bearer is associated with NarrowBand-Intemet of Things (NB-IoT) devices and is usable for communications via a dedicated control channel; and the third signaling radio bearer is usable for communications via the dedicated control channel, and a priority level associated with the third signaling radiobearer is higher than one or more other priority levels associated with one or more other signaling radio bearers usable for communications via the dedicated control channel.
12. The UE of claim 1, wherein the one or more processors are individually or collectively further operable to execute the code to cause the UE to: transmit, to the network entity after reception of the radio resource control message, a connection complete message that indicates successful completion of the radio resource control connection, wherein transmission of the connection complete message is in accordance with a mobility management entity-based re-establishment procedure or an access stratum-based re-establishment procedure.
13. The UE of claim 12, wherein the one or more processors are individually or collectively further operable to execute the code to cause the UE to: receive a control message that indicates, to the UE, to use the mobility management entity -based re-establishment procedure or the access stratum-based reestablishment procedure, wherein transmitting the connection complete message is in accordance with the control message.
14. The UE of claim 1, wherein, to transmit the indication of the capability', the one or more processors are individually or collectively operable to execute the code to cause the UE to: transmit the indication of the capability' in accordance with a tracking area update procedure or an initial attach procedure.
15. The UE of claim 1, wherein, to transmit the indication of the capability', the one or more processors are individually or collectively operable to execute the code to cause the UE to: determine a change in a location of the UE; and transmit the indication of the capability’ based at least in part on the change in the location of the UE satisfying a threshold.
16. The UE of claim 1, wherein, to transmit the indication of the capability’, the one or more processors are individually or collectively operable to execute the code to cause the UE to:determine a location of the UE based at least in part on navigation data associated with a global navigation satellite system; and transmit the indication of the capability to report the location of the UE to the network entity.
17. The UE of claim 1, wherein the radio resource control message indicates that the one or more access stratum security protocols are only enabled for the at least one signaling radio bearer.
18. A network entity, comprising: one or more memories storing processor-executable code; and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the network entity to: obtain, via a first signaling radio bearer, a request to establish a radio resource control connection with a user equipment (UE) to operate in accordance with a control plane operation mode for communications without establishment of a data radio bearer; obtain an indication of a capability of the UE to support access stratum security for communications associated with the control plane operation mode; and output a radio resource control message that indicates one or more access stratum security protocols are configured for at least one signaling radio bearer in response to the capability’ of the UE to support access stratum security for communications associated with the control plane operation mode.
19. The network entity of claim 18, wherein, to obtain the indication of the capability, the one or more processors are individually or collectively operable to execute the code to cause the network entity to: obtain, via the first signaling radio bearer, a connection request message comprising the request to establish the radio resource control connection with the network entity and comprising the indication of the capability.
20. The network entity of claim 19, wherein, to output the radio resource control message, the one or more processors are individually or collectively operable to execute the code to cause the network entity to: output, via a second signaling radio bearer, a connection setup command and a security mode command, wherein the connection setup command indicates one or more parameters associated with a third signaling radio bearer, and wherein the security mode command indicates that the one or more access stratum security protocols are configured for the third signaling radio bearer.
21. The network entity of claim 19, wherein, to output the radio resource control message, the one or more processors are individually or collectively operable to execute the code to cause the network entity to: output, via a second signaling radio bearer, a connection setup command that indicates one or more parameters associated with a third signaling radio bearer; and output, via the third signaling radio bearer, the radio resource control message after reception of the connection setup command, the radio resource control message comprising a security mode command that indicates that the one or more access stratum security protocols are configrued for the third signaling radio bearer.
22. The network entity of claim 18, wherein, to obtain the indication of the capability, the one or more processors are individually or collectively operable to execute the code to cause the network entity to: obtain, via a second signaling radio bearer, a connection complete message that indicates successful establishment of the radio resource control connection, wherein the connection complete message comprises the indication of the capability.
23. The network entity of claim 18, wherein the one or more processors are individually or collectively further operable to execute the code to cause the network entity to: obtain a first message via the at least one signaling radio bearer, wherein the first message comprises location information associated with the UE, and wherein the location information is encrypted using the one or more access stratum security protocols.
24. The network entity of claim 23, wherein the one or more processors are individually or collectively further operable to execute the code to cause the network entity to: obtain a second message via a second signaling radio bearer, wherein the at least one signaling radio bearer comprises a third signaling radio bearer, and wherein the second message comprises information encrypted using one or more non-access stratum security protocols.
25. The network entity of claim 24, wherein the one or more processors are individually or collectively further operable to execute the code to cause the network entity to: output a security release command that indicates the one or more access stratum security protocols are disabled for the third signaling radio bearer, wherein the second message is obtained via the third signaling radio bearer in response to the security release command.
26. The network entity of claim 18, wherein the one or more processors are individually or collectively further operable to execute the code to cause the network entity to: obtain a first message via a second signaling radio bearer, wherein the first message comprises a non-access stratum message or a second radio resource control message that indicates successful establishment of the radio resource control connection.
27. The network entity of claim 18, wherein the one or more processors are individually or collectively further operable to execute the code to cause the network entity to: obtain a connection complete message that indicates successful completion of the radio resource control connection, wherein the connection complete message is obtained in accordance with a mobility management entity-based reestablishment procedure or an access stratum-based re-establishment procedure.
28. The network entity of claim 27, wherein the one or more processors are individually or collectively further operable to execute the code to cause the network entity to: output a control message that indicates, to the UE, to use the mobility management entity-based re-establishment procedure or the access stratum-based reestablishment procedure, wherein the connection complete message is obtained in accordance with the control message.
29. The network entity of claim 18, wherein, to obtain the indication of the capability, the one or more processors are individually or collectively operable to execute the code to cause the network entity to: obtain the indication of the capability in accordance with a tracking area update procedure or an initial attach procedure.
30. A method for wireless communications by a user equipment (UE). comprising: transmitting, via a first signaling radio bearer, a request to establish a radio resource control connection with a network entity for the UE to operate in accordance with a control plane operation mode for communications without establishment of a data radio bearer; transmitting an indication of a capability of the UE to support access stratum security for communications associated with the control plane operation mode; and receiving, from the network entity7in accordance with the control plane operation mode, a radio resource control message that indicates one or more access stratum security protocols are configured for at least one signaling radio bearer in response to the capability of the UE to support access stratum security for communications associated with the control plane operation mode.
Citation Information
Patent Citations
Radio access capabilities of a wireless device
US20210153022A1
Data transmission method and apparatus
US20220210859A1
Protecting Capability Information Transfer in a Wireless Communication Network
US20230188992A1