Configuration information security

The method securely stores and verifies configuration information using cryptographic encoding, addressing integrity and authenticity issues in wireless networks, ensuring seamless service continuity across radio states.

WO2025172900A1PCT designated stage Publication Date: 2025-08-21NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/051570
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-15
Filing Date
2025-02-13
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Existing wireless networks face challenges in securing configuration information, particularly during radio disconnected states, where the integrity and authenticity of configuration data are at risk, leading to potential tampering and service disruptions.

Method used

A method and apparatus that securely store configuration information with cryptographic encoding in a secure storage environment, enabling verification upon reconnection, using cryptographic algorithms and unique identifiers to ensure data integrity and authenticity.

Benefits of technology

Ensures the integrity and authenticity of configuration information across radio connection states, preventing tampering and ensuring seamless service continuity by verifying the data upon reconnection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025051570_21082025_PF_FP_ABST
    Figure IB2025051570_21082025_PF_FP_ABST
Patent Text Reader

Abstract

An apparatus comprising means for: receiving, from a first access node, configuration information and a cryptographic encoding of at least the configuration information; storing the received configuration information in a received configuration information data structure in at least one secure storage environment and the cryptographic encoding of at least the configuration information in at least one secure storage environment; and causing transmission, based at least in part on a transition from a radio disconnected mode to a radio connected mode, of content of the received configuration information data structure and the stored cryptographic encoding of at least the configuration information towards a second access node to enable a verification of the stored configuration information.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] TITLE

[0002] CONFIGURATION INFORMATION SECURITY

[0003] TECHNOLOGICAL FIELD

[0004] Examples of the disclosure relate to configuration information security. Some relate to configuration information security in a wireless network.

[0005] BACKGROUND

[0006] A wireless network comprises a plurality of network nodes including terminal nodes and access nodes. Communication between the terminal nodes and access nodes is wireless.

[0007] Configuration information can be used to configure behavior of one or more nodes in a network. In some circumstances it may be desirable to improve or enhance security of using configuration information in a wireless network.

[0008] BRIEF SUMMARY

[0009] According to various, but not necessarily all, embodiments there is provided an apparatus comprising means for: receiving, from a first access node, configuration information and a cryptographic encoding of at least the configuration information; storing the received configuration information in a received configuration information data structure in at least one secure storage environment and the cryptographic encoding of at least the configuration information in at least one secure storage environment; and causing transmission, based at least in part on a transition from a radio disconnected mode to a radio connected mode, of content of the received configuration information data structure and the stored cryptographic encoding of at least the configuration information towards a second access node to enable a verification of the stored configuration information.

[0010] In some examples, the cryptographic encoding of at least the configuration information is generated based, at least in part, on the configuration information, and at least one identifier configured to uniquely identify the first access node. In some examples, the cryptographic encoding of at least the configuration information is generated using the configuration information and the at least one identifier configured to uniquely identify the first access node as inputs into at least one cryptographic algorithm.

[0011] In some examples, the cryptographic encoding of at least the configuration information is generated based, at least in part, on the configuration information, and at least one random number value.

[0012] In some examples, the configuration information and the cryptographic encoding of at least the configuration information is receiving during a radio connected mode.

[0013] In some examples, the configuration information comprises quality of experience measurement collection configuration information.

[0014] According to various, but not necessarily all, embodiments there is provided a method comprising: receiving, from a first access node, configuration information and a cryptographic encoding of at least the configuration information; storing the received configuration information in a received configuration information data structure in at least one secure storage environment and the cryptographic encoding of at least the configuration information in at least one secure storage environment; and causing transmission, based at least in part on a transition from a radio disconnected mode to a radio connected mode, of content of the received configuration information data structure and the stored cryptographic encoding of at least the configuration information towards a second access node to enable a verification of the stored configuration information.

[0015] In some examples, the cryptographic encoding of at least the configuration information is generated based, at least in part, on the configuration information, and at least one identifier configured to uniquely identify the first access node.

[0016] According to various, but not necessarily all, embodiments there is provided a computer program comprising instructions which, when executed by an apparatus, cause the apparatus at least to perform: receiving, from a first access node, configuration information and a cryptographic encoding of at least the configuration information; storing the received configuration information in a received configuration information data structure in at least one secure storage environment and the cryptographic encoding of at least the configuration information in at least one secure storage environment; and causing transmission, based at least in part on a transition from a radio disconnected mode to a radio connected mode, of content of the received configuration information data structure and the stored cryptographic encoding of at least the configuration information towards a second access node to enable a verification of the stored configuration information.

[0017] According to various, but not necessarily all, embodiments there is provided an apparatus comprising means for: receiving configuration information from at least one core node; generating a cryptographic encoding of at least the configuration information; causing transmission of at least the configuration information and the cryptographic encoding of at least the configuration information towards a terminal node; receiving verification configuration information and a cryptographic encoding of at least configuration information from a terminal node; and verifying the received verification configuration information based, at least in part, on the received cryptographic encoding of at least configuration information.

[0018] In some examples, generating the cryptographic encoding of at least the configuration information comprises generating the cryptographic encoding based, at least in part, on the received configuration information, and at least one identifier configured to uniquely identify an access node.

[0019] In some examples, generating the cryptographic encoding of at least the configuration information comprises using the received configuration information and the at least one identifier configured to uniquely identify the access node as inputs into at least one cryptographic algorithm.

[0020] In some examples, the configuration information comprises quality of experience measurement collection configuration information. In some examples, the means are configured to cause transmission, towards at least one core node, of at least one of the following: the cryptographic encoding of at least the configuration information; or at least one identifier configured to uniquely identify an access node used in generating the cryptographic encoding of at least the configuration information.

[0021] In some examples, verifying the received verification configuration information comprises generating a cryptographic encoding of at least the verification configuration information and comparing the cryptographic encoding of at least the verification configuration information and the received cryptographic encoding of at least configuration information.

[0022] In some examples, the means are configured to receive at least one identifier configured to uniquely identify an access node for use in generating the cryptographic encoding of at least the verification configuration information.

[0023] In some examples, verifying the received verification configuration information comprises receiving an expected cryptographic encoding of at least configuration information and comparing the received cryptographic encoding of at least configuration information and the received expected cryptographic encoding of at least configuration information.

[0024] In some examples, verifying the received verification configuration information comprises causing transmission of the received verification configuration information and the received cryptographic encoding of at least configuration information for verification.

[0025] According to various, but not necessarily all, embodiments there is provided a computer program comprising instructions which, when executed by an apparatus, cause the apparatus at least to perform: receiving configuration information from at least one core node; generating a cryptographic encoding of at least the configuration information; causing transmission of at least the configuration information and the cryptographic encoding of at least the configuration information towards a terminal node; receiving verification configuration information and a cryptographic encoding of at least configuration information from a terminal node; and verifying the received verification configuration information based, at least in part, on the received cryptographic encoding of at least configuration information.

[0026] According to various, but not necessarily all, embodiments there is provided an apparatus comprising means for: causing transmission of configuration information towards at least one access node; receiving, from a requesting access node, a request for assistance in verification of verification configuration information; and causing transmission of information towards the requesting access node to enable verification of the verification configuration information.

[0027] In some examples, the configuration information comprises quality of experience measurement collection configuration information.

[0028] In some examples, causing transmission of information comprises causing transmission of at least one of the following: an expected cryptographic encoding of at least configuration information; or at least one identifier configured to uniquely identify an access node.

[0029] In some examples, the means are configured to receive at least one of the following: a cryptographic encoding of at least configuration information; or at least one identifier configured to uniquely identify an access node used in generating a cryptographic encoding of at least configuration information.

[0030] According to various, but not necessarily all, embodiments there is provided a method comprising: causing transmission of configuration information towards at least one access node; receiving, from a requesting access node, a request for assistance in verification of verification configuration information; and causing transmission of information towards the requesting access node to enable verification of the verification configuration information. According to various, but not necessarily all, embodiments there is provided a computer program comprising instructions which, when executed by an apparatus, cause the apparatus at least to perform: causing transmission of configuration information towards at least one access node; receiving, from a requesting access node, a request for assistance in verification of verification configuration information; and causing transmission of information towards the requesting access node to enable verification of the verification configuration information.

[0031] According to various, but not necessarily all, embodiments there is provided an apparatus comprising at least one processor; and at least one memory including computer program code; the at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to perform at least a part of one or more methods described herein.

[0032] According to various, but not necessarily all, embodiments there is provided an apparatus comprising means for performing at least part of one or more methods described herein.

[0033] The description of a function and / or action should additionally be considered to also disclose any means suitable for performing that function and / or action. Functions and / or actions described herein can be performed in any suitable way using any suitable method.

[0034] According to various, but not necessarily all, embodiments there is provided examples as claimed in the appended claims.

[0035] While the above examples of the disclosure and optional features are described separately, it is to be understood that their provision in all possible combinations and permutations is contained within the disclosure. It is to be understood that various examples of the disclosure can comprise any or all the features described in respect of other examples of the disclosure, and vice versa. Also, it is to be appreciated that any one or more or all the features, in any combination, may be implemented by / comprised in / performable by an apparatus, a method, and / or computer program instructions as desired, and as appropriate. The description of a function should additionally be considered to also disclose any means suitable for performing that function

[0036] BRIEF DESCRIPTION

[0037] Some examples will now be described with reference to the accompanying drawings in which: FIG. 1 shows an example of the subject matter described herein;

[0038] FIG. 2 shows another example of the subject matter described herein;

[0039] FIG. 3 shows another example of the subject matter described herein;

[0040] FIG. 4 shows another example of the subject matter described herein;

[0041] FIG. 5 shows another example of the subject matter described herein;

[0042] FIG. 6 shows another example of the subject matter described herein;

[0043] FIG. 7 shows another example of the subject matter described herein;

[0044] FIG. 8 shows another example of the subject matter described herein;

[0045] FIG. 9 shows another example of the subject matter described herein;

[0046] FIG. 10 shows another example of the subject matter described herein;

[0047] FIG. 11 shows another example of the subject matter described herein;

[0048] FIG. 12 shows another example of the subject matter described herein;

[0049] FIG. 13 shows another example of the subject matter described herein;

[0050] FIG. 14 shows another example of the subject matter described herein;

[0051] FIG. 15A shoes another example of the subject matter described herein;

[0052] FIG. 15B shows another example of the subject matter described herein;

[0053] The figures are not necessarily to scale. Certain features and views of the figures can be shown schematically or exaggerated in scale in the interest of clarity and conciseness. For example, the dimensions of some elements in the figures can be exaggerated relative to other elements to aid explication. Similar reference numerals are used in the figures to designate similar features. For clarity, all reference numerals are not necessarily displayed in all figures.

[0054] DETAILED DESCRIPTION FIG 1 illustrates an example of a network 100 comprising a plurality of network nodes including terminal nodes 110, access nodes 120 and one or more core nodes 129. The terminal nodes 110 and access nodes 120 communicate with each other. The one or more core nodes 129 communicate with the access nodes 120.

[0055] The network 100 is in this example a radio telecommunications network, in which at least some of the terminal nodes 110 and access nodes 120 communicate with each other using transmission / reception of radio waves / signals.

[0056] The one or more core nodes 129 may, in some examples, communicate with each other. The one or more access nodes 120 may, in some examples, communicate with each other.

[0057] The network 100 may be a cellular network comprising a plurality of cells 122 each served by an access node 120. In this example, the interface between the terminal nodes 110 and an access node 120 defining a cell 122 is a wireless interface 124.

[0058] The access node 120 is a cellular radio transceiver. The terminal nodes 110 are cellular radio transceivers.

[0059] In the example illustrated the cellular network 100 is a third generation Partnership Project (3GPP) network in which the terminal nodes 110 are user equipment (UE), see, for example, FIG. 2, and the access nodes 120 are base stations.

[0060] In examples the network 100 is an Evolved Universal Terrestrial Radio Access network (E- UTRAN). The E-UTRAN consists of E-UTRAN NodeBs (eNBs) 120, providing the E- UTRA user plane and control plane (RRC) protocol terminations towards the UE. The eNBs 120 are interconnected with each other by means of an X2 interface 126. The eNBs are also connected by means of the SI interface 128 to the Mobility Management Entity (MME) 129.

[0061] In other examples the network 100 is a Next Generation (or New Radio, NR) Radio Access network (NG-RAN). The NG-RAN consists of gNodeBs (gNBs) 120, providing the user plane and control plane (RRC) protocol terminations towards the UE 110. The gNBs 120 are interconnected with each other by means of an Xn interface 126. The gNBs are also connected by means of the N2 interface 128 to the Access and Mobility management Function (AMF).

[0062] In some examples, the access nodes 120 can comprise at least one wireless edge computing server.

[0063] A user equipment 130 (UE) can comprise a mobile equipment. Where reference is made to user equipment that reference includes and encompasses, wherever possible, a reference to mobile equipment.

[0064] In examples, the network 100 can comprise a combination of E-UTRAN and NG-RAN.

[0065] In examples, the network 100 can comprise a 6GRAN network.

[0066] Configuration information can be used in the network to control, for example, functionality of at least one terminal node 110, or access node 120 and so on.

[0067] In examples, configuration information can be securely stored, in a terminal node for example, to enable a serving access node 120 of the terminal node 110 to have access to the configuration information when the terminal node 110 is returning to a radio connected state.

[0068] In examples, it can be verified that the configuration information is as expected and has not been tampered with during storage, to ensure that the configuration is valid.

[0069] Examples of the disclosure relate to at least one of the following: apparatuses, methods, or computer programs for or involved in securely storing configuration information while a terminal node 110 is in a radio disconnected state.

[0070] Additionally, or alternatively, examples of the disclosure relate to at least one of the following: apparatuses, methods, or computer programs for or involved in verifying stored configuration information. FIG. 2 illustrates an example of signaling between entities. FIG. 2 also illustrates an example of a method 200.

[0071] FIG. 2 illustrates methods performed by a system comprising interaction between different system entities. FIG. 2 also illustrates a collection of separate methods performed separately by the different system entities.

[0072] One or more of the features discussed in relation to FIG. 2 can be found in one or more of the other FIGs.

[0073] In the example of FIG. 2, a plurality of apparatuses transmit and / or receive one or more signals and / or messages across and / or via and / or using a network. In examples, any suitable form of communication in any suitable network can be used. For example, at least a portion of the network 100 of FIG. 1 can be used.

[0074] In the example of FIG. 2, a terminal node 110, an access node 120A or access nodes 120A and 120B, and a core node 129 transmit and / or receive one or more signals and / or one or more messages.

[0075] In the example of FIG. 2, the terminal node 110 is a UE 170, the access nodes 120A, 120B are gNBs 173A, 173B and the core node 129 is an access management function (AMF) 175.

[0076] In examples, transmissions between entities illustrated in FIG. 2 can proceed via any number of intervening entities, including no intervening entities.

[0077] Although a single terminal node 110 is illustrated in the example of FIG. 2, in examples any suitable number of terminal nodes 110 can be included. Similarly, any suitable number of access nodes 120 can be used and any suitable number of core nodes 129 can be used.

[0078] As used herein, a description of a function / action should also be considered to disclose at least one of the following: enabling, causing, or controlling that function / action. For example, description of transmitting information should also be considered to disclose at least one of the following: enabling transmission of information, causing transmission of information, or controlling transmission of information.

[0079] For example, a description of an apparatus, such as a UE 170, transmitting information should also be considered to disclose at least one controller of the apparatus performing at least one of the following: enabling the apparatus to transmit the information, causing the apparatus to transmit the information, or controlling the apparatus to transmit the information.

[0080] In examples, at least part of method 200 can be considered a method of securely storing configuration information.

[0081] In examples, at least part of method 200 can be considered a method of securely storing configuration information while a terminal node is in a radio disconnected mode.

[0082] In examples, at least part of method 200 can be considered a method of verifying configuration information.

[0083] In the illustrated examples, the location of the blocks indicates the entity or entities performing the function(s) / action(s). For example, block 202 is performed by the core node 129 (transmitting) and the access node 120A (receiving). For example, block 204 is performed by the access node 120A.

[0084] As used herein, the term ‘block’ is intended to refer to an action or actions indicated in a FIG. For example, the term ‘block’ can refer to the action of transmitting / receiving indicated by reference numeral 202 in FIG. 2, and can also refer to the action of generating indicated by reference numeral 204 and so on.

[0085] At block 202, method 200 comprises transmitting configuration information 172 towards at least one access node 120A.

[0086] As FIG. 2 illustrates one or more functions / actions of transmitting, FIG. 2 also illustrates the corresponding receiving and causing / enabling / controlling receiving function(s) / action(s). For example, from the point of view of the access node 120A, at block 202, method 200 comprises receiving configuration 172 from at least one core node 129.

[0087] The configuration information 172 can comprises any suitable configuration information 172. For example, the configuration information 172 can comprise any suitable configuration information for use in a wireless network, such as the wireless network 100 in the example of FIG. 1.

[0088] In some examples, the configuration information 172 comprises configuration information 172 that is to be stored so that the configuration information 172 can be made available to a serving access node 120 of a terminal node 110 when the terminal node 110 transitions from a radio disconnected mode 180 to a radio connected mode 182.

[0089] In some examples, the configuration information 172 comprises radio configuration information.

[0090] In some examples, the configuration information 172 comprises measurement configuration information.

[0091] In some examples, the configuration information 172 comprises private or sensitive or confidential information relating to, for example, user privacy. For example, the configuration information 172 can comprise at least one of the following: IP address, slice details, or application layer details and so on.

[0092] In some examples, the configuration information 172 comprises configuration information to be stored to ensure continuity for at least one service provided to a terminal node 110 across radio connection states, such as radio resource control (RRC) states.

[0093] In some examples, the configuration information 172 comprises quality of experience measurement collection (QMC) configuration information 172. For example, the configuration information 172 can comprise multicast / broadcast service MBS QMC configuration information 172. In some examples, method 200 comprises determining, by the core node 129, the configuration information 172. For example, the configuration information 172 can be received or generated by the core node 129.

[0094] In examples, block 202 comprises transmitting an initial context setup request / UE context modification request.

[0095] At block 204, method 200 comprises generating a cryptographic encoding 174 of at least the configuration information 172.

[0096] In examples, the cryptographic encoding 174 is an encrypted or encoded or hashed version of at least the configuration information 172. Accordingly, in some examples, generating a cryptographic encoding 174 of at least the configuration information 172 comprises at least one of encrypting, encoding, or hashing the configuration information.

[0097] In some examples, the cryptographic encoding 174 is the result of applying at least one cryptographic algorithm 188 to the configuration information 172. The at least one cryptographic algorithm can comprise at least one of the following: at least one encryption algorithm, at least one encoding algorithm, or at least one hash algorithm and so on. For example, 128 bit algo or 256 bit algo or AEAD combined algorithm can be used.

[0098] A cryptographic algorithm 188 can, in examples, be considered a cryptographic function.

[0099] In some examples, generating the cryptographic encoding 174 of at least the configuration information 172 comprises generating the cryptographic encoding 174 based, at least in part, on the received configuration information 172, and at least one identifier 186 configured to uniquely identify an access node 120, for example the access node 120A that is generating the cryptographic encoding 174 of at least the configuration information 172, which can be considered a first access node 120A.

[0100] Accordingly, in examples, the cryptographic encoding 174 of at least the configuration information 172 is generated based, at least in part, on the configuration information 172, and at least one identifier 186 configured to uniquely identify the first access node 120A. The at least one identifier 186 can be any suitable identifier that is configured to uniquely identify an access node 120, such as the access node 120A. That is, in examples, the identifier 186 is an identifier associated with a single access node 120, such as the access node 120A.

[0101] For example, the at least one identifier 186 can comprise at least one of the following: physical cell identity (PCI) and E-UTRA absolute radio frequency channel number (EARFCN).

[0102] In some examples generating the cryptographic encoding 174 of at least the configuration information 172 comprises using the received configuration information 172 and the at least one identifier 186 configured to uniquely identify the access node 120 as inputs into at least one cryptographic algorithm 188.

[0103] Any suitable cryptographic algorithm 188 can be used. For example, any suitable encryption, encoding, or hash algorithm can be used. For example, any suitable hash function can be used.

[0104] In some examples, generating the cryptographic encoding 174 of at least the configuration information 172 comprises generating the cryptographic encoding 174 based, at least in part, on the received configuration information 172, and at least one random number value 190.

[0105] For example, generating the cryptographic encoding 174 of at least the configuration information 172 can comprise using the received configuration information 172 and the at least one random number value 190 as inputs into at least one cryptographic algorithm 188.

[0106] At block 206, method 200 comprises transmitting the configuration information 172 and the cryptographic encoding 174 of at least the configuration information 172 towards a terminal node 110. From the point of view of the terminal node 110, block 206 comprises receiving, from a first access node 120A, configuration information 172 and a cryptographic encoding 174 of at least the configuration information 172.

[0107] In some examples, block 206 comprises transmitting an RRCReconfiguration message.

[0108] At block 208, method 200 comprises storing the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment and the cryptographic encoding 174 of at least the configuration information 172 in at least one secure storage environment.

[0109] The received configuration information 172 and the cryptographic encoding 174 of at least the configuration information 172 can be stored in the same or different secure storage environments. For example, the received configuration information 172 and the cryptographic encoding 174 of at least the configuration information 172 can be stored in separately addressable data structures.

[0110] Any suitable secure storage environment or environments can be used. In examples, a secure storage environment can be considered a tamper proof memory.

[0111] In examples, a secure storage environment can comprise a trusted execution environment (TEE) or a universal integrated circuit card (UICC).

[0112] In examples, a received configuration information data structure 177 can comprise any suitable data structure configured to store the information of the received configuration information 172. For example, the received configuration information data structure 177 can be any suitable data structure into which the configuration information 172 can be stored for later retrieval.

[0113] At block 210, method 200 comprises transmitting, by the access node 120A towards at least one core node 129, at least one of the following: the cryptographic encoding 174 of at least the configuration information 172, or at least one identifier 186 configured to uniquely identify an access node 120A used in generating the cryptographic encoding 174 of at least the configuration information 172.

[0114] Accordingly, at block 210, the access node 120A can transmit at least one of the following: the cryptographic encoding 174 of at least the configuration information 172, or at least one identifier 186 configured to uniquely identify an access node 120A used in generating the cryptographic encoding 174 of at least the configuration information 172 towards the at least one core node 129 for storage to enable later retrieval from the core node 129 as needed. See, for example, block 218B of FIG. 2.

[0115] From the point of view of the core node 129, block 210 comprises receiving at least one of the following: a cryptographic encoding 174 of at least configuration information 172, or at least one identifier 186 configured to uniquely identify an access node 120A used in generating a cryptographic encoding of at least configuration information 172.

[0116] In examples, at block 206 the terminal node 110 is in a radio connected mode 182. Accordingly, in examples, at block 206 the configuration information 172 and the cryptographic encoding 174 of at least the configuration information 172 is received during a radio connected mode 182.

[0117] In examples, a mode can be considered a state and therefore the configuration information 172 and the cryptographic encoding 174 of at least the configuration information 172 can be received during a radio connected state.

[0118] In examples, a radio connected mode 182 is a state in which the terminal node 110 is actively connected to an access node 120 and the terminal node 110 is known to the access node 120.

[0119] In examples, a terminal node 110 maintains synchronization with the network in a radio connected mode.

[0120] A radio connected mode 182 can comprise RRC CONNECTED mode. At block 212, method 200 comprises transitioning from a radio connected mode 182 to a radio disconnected mode 180.

[0121] In examples, a radio disconnected mode 180 is a state in which the terminal node 110 is not actively connected to an access node 120 and the terminal node 100 is not known to an access node 120.

[0122] In examples, a terminal node 110 does not maintain synchronization with the network in a radio disconnected mode.

[0123] A radio disconnected 180 can comprise RRC IDLE or RRC INACTIVE mode.

[0124] Accordingly, in some examples, at block 212 the terminal node 110 transitions from RRC CONNECTED to RRC IDLE or RRC INACTIVE mode.

[0125] Block 212 can comprise one or more actions by at least one of the access node 120A or the core node 129.

[0126] At block 214, method 200 comprises transitioning from a radio disconnected mode 180 to a radio connected mode 182. For example, block 214 can comprise transitioning from RRC IDLE or RRC INACTIVE to RRC CONNECTED.

[0127] Block 214 can occur at some time after block 212 as indicated by the ‘.. .’ in the example of FIG. 2. For example, the terminal node 110 can remain in a radio disconnected mode 180 for some time before transitioning to a radio connected mode 182.

[0128] At block 214, the terminal node 110 can transition to a radio connected mode 182 with the first access node 120A or a different access node 120B. Therefore, in the example of FIG. 2, the vertical, solid, central line in the lower portion of FIG. 2 can represent actions at the first access node 120A or a different access node 120B. A vertical, dashed line in the lower portion of FIG. 2 is also shown, to represent action(s) at the first access node 120A in examples where the terminal node 110 has transitioned to a radio connected mode 182 with a different access node 120B.

[0129] Accordingly, at blocks 218A, 218A1, 218A2, 218B, 218B1, 218B2 FIG. 2 shows a plurality of options that can be performed in the method 200 of FIG. 2.

[0130] Block 214 can comprise one or more actions by at least one of the access node 120A, the access node 120B or the core node 129.

[0131] At block 216, method 200 comprises transmitting, based at least in part, on a transition from a radio disconnected mode 180 to a radio connected mode 182, of content 184 of the received configuration information data structure 177 and the stored cryptographic encoding 174 of the configuration information 172 towards a second access node 120A, 120B to enable a verification of the stored configuration information.

[0132] Consequently, FIG. 2 illustrates a method 200 comprising: receiving, from a first access node 120A, configuration information 172 and a cryptographic encoding 174 of at least the configuration information 172; storing the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment and the cryptographic encoding 174 of the configuration information 172 in at least one secure storage environment; and causing transmission, based at least in part on a transition from a radio disconnected mode 180 to a radio connected mode 182, of content 184 of the received configuration information data structure 177 and the stored cryptographic encoding 174 of the configuration information 172 towards a second access node 120A, 120B to enable a verification of the stored configuration information.

[0133] The first access node 120A and the second access node 120A, 120B can be the same, or different access nodes.

[0134] That is, in examples, the second access node can be referred to by reference 120A when the second access node is the same access node as the first access node 120A, or the second access node can be referred to by reference 120B when the second access node is a different access node than the first access node 120A.

[0135] In examples, the content 184 of the received configuration information data structure 177 is the stored configuration information when block 216 is performed.

[0136] Accordingly, in examples, if the content of the received configuration information data structure 177 is changed between block 208 and block 216, the stored configuration information transmitted at block 216 is different to the received configuration information 172.

[0137] For example, if the stored configuration information 172 at the terminal node 110 is tampered with, the content of the received configuration information data structure 177 changes between block 208 and block 216, and the stored configuration information that is transmitted at block 216 is different to the configuration information 172 received at block 206.

[0138] However, in some examples, the content 184 of the received configuration information data structure 177 does not change between block 208 and block 216 and therefore the stored configuration information that is transmitted at block 216 is, in some examples, the same as the received configuration information 172 at block 206.

[0139] As used herein, description of receiving configuration information and transmitting the configuration information is intended to include both the case where the configuration information that is transmitted is unchanged compared to the received configuration information and the case where the configuration information that is transmitted is changed compared to the received configuration information.

[0140] In examples, the content 184 of the received configuration information data structure 177 / the stored configuration information when block 216 is performed can be considered verification configuration information 192. From the point of view of the access node 120A, 120B method 200 comprises receiving verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 172 from a terminal node 110.

[0141] In some examples, block 216 comprises transmitting an RRCSetupComplete message.

[0142] At block 218, method 200 comprises verifying the received verification configuration information 192 based, at least in part, on the received cryptographic encoding of at least configuration information 174.

[0143] Consequently, FIG. 2 illustrates a method 200 comprising: receiving configuration information 172 from at least one core node 129; generating a cryptographic encoding 174 of at least the configuration information 172; causing transmission of the configuration information 172 and the cryptographic encoding 174 of at least the configuration information 172 towards a terminal node 110; receiving verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 172 from a terminal node 120; and verifying the received verification configuration information 192 based, at least in part, on the received cryptographic encoding 174 of at least configuration information 172.

[0144] In examples, verifying the received verification configuration information 192 comprises determining whether the configuration information 172 has changed while it was stored at the terminal node 110.

[0145] In some examples, verifying the received verification configuration information 192 comprises performing a comparison using the received cryptographic encoding 174 of at least configuration information 172.

[0146] In some examples, verifying the received verification configuration information 192 comprises generating a cryptographic encoding 194 of at least the verification configuration information 192. In some examples, verifying the received verification configuration information 192 comprises transmitting and receiving information.

[0147] For example, in examples where the second access node 120A is the same node as the first access node 120A, verifying the received configuration information 192 can comprise transmitting information towards the core node 129 and receiving information from the core node 129. This is illustrated as block 218B in the example of FIG. 2.

[0148] For example, in examples where the second access node 120B is a different node than the first access node 120A, verifying the received configuration information 192 can comprise transmitting information towards the core node 129 and receiving information from the core node 129. This is illustrated as block 218B in the example of FIG. 2.

[0149] Additionally, or alternatively, in examples where the second access node 120B is a different node than the first access node 120A, verifying the received configuration information 192 can comprise transmitting information towards the first access node 120A and receiving information from the first access node 120A. This is illustrated as block 218A in the example of FIG. 2.

[0150] In some examples, verifying the received verification configuration information 192 comprises generating a cryptographic encoding 194 of at least the verification configuration information 192 and comparing the cryptographic encoding 194 of at least the verification configuration information 192 and the received cryptographic encoding 174 of at least configuration information 172.

[0151] Generating the cryptographic encoding 194 of at least the verification configuration information 192 can be performed as described at block 204 in relation to the configuration information 172.

[0152] Accordingly, in examples, a cryptographic encoding 174 of the original configuration information 172 generated at block 204 can be compared with a cryptographic encoding 194 of the verification configuration information 192 received from the terminal node at block 216 to verify whether the configuration information 172 has changed while it has been stored at the terminal node 110.

[0153] This is because, in examples, the cryptographic encodings 174, 194 are generated in the same way and therefore if the input configuration information is unchanged the cryptographic encodings 174, 194 will also match.

[0154] In examples, information of the at least one cryptographic algorithm 188 used to generate the cryptographic encoding 174 can be transmitted with or separate to the configuration information 172.

[0155] For example, information of the at least one cryptographic algorithm 188 used to generate the cryptographic encoding 174 can be transmitted / received at block 206, stored at one or more of blocks 208 and block 210, and transmitted / received at block 218 to enable the cryptographic encoding 194 of the verification configuration information 192 to be generated.

[0156] In some examples, information of the at least one cryptographic algorithm 18 used to generate the cryptographic encoding 174 is preconfigured at the access nodes 120.

[0157] In some examples, the cryptographic encoding 174 of at least the configuration information 172 is generated based, at least in part, on the configuration information 172, and at least one identifier 186 configured to uniquely identify the first access node 120A.

[0158] In examples where the first access node 120A and the second access node 120A are the same nodes, the second access node 120A has access to the at least one identifier 186 that was used.

[0159] However, in examples where the first access node 120A and the second access node 120B are different access nodes, this may not be the case.

[0160] In some examples, method 200 comprises receiving at least one identifier 186 configured to uniquely identify an access node 120A for use in generating the cryptographic encoding 194 of at least the verification configuration information 192. The at least one identifier 186 can be received from the first access node 120A (block 218A) or the core node 129 (block 218B) or both.

[0161] In some examples, the second access node 120B requests the at least one identifier 186 from the first access node 120A, or the core node 129, or both.

[0162] In some examples, verifying the received verification configuration information 192 comprises receiving an expected cryptographic encoding 196 of at least configuration information and comparing the received cryptographic encoding 174 of at least configuration information 172 and the received expected cryptographic encoding 196 of at least configuration information.

[0163] In some examples, the expected cryptographic encoding 196 of at least configuration information can be received from the first access node 120A, which can still have the cryptographic encoding generated at block 204 available for use as the expected cryptographic encoding 196 (block 218A).

[0164] In some examples, the expected cryptographic encoding 196 of at least configuration information can be received from the core node 129 (block 218B), which, in examples, received the cryptographic encoding 174 of at least the configuration information 172 at block 210. The cryptographic encoding 174 of at least the configuration information 172 received at block 210 can be used as the expected cryptographic encoding 196 of at least configuration information.

[0165] The second access node 120B can request the expected cryptographic encoding 196 from the first access node 120A, or the core node 129, or both.

[0166] In some examples, verifying the received verification configuration information 192 comprises causing transmission of the received verification configuration information 192 and the received cryptographic encoding 174 of at least configuration information for verification. The received verification configuration information 192 and the received cryptographic encoding 174 of at least configuration information can be transmitted towards the first access node 120A (block 218A), the core node (block 218B), or both for verification.

[0167] In some examples, at block 218A1, the first access node 120A generates a cryptographic encoding 194 of at least the verification configuration information 192 and compares the cryptographic encoding 194 of at least the verification configuration information 192 and the received cryptographic encoding 174 of at least configuration information 172 to verify the verification configuration information 192.

[0168] At block 218A2, the first access node transmits a verification result 197 to the second access node 120B.

[0169] In examples, the verification result 197 is positive and indicates that the received verification configuration information 192 is valid if the cryptographic encodings 174, 194 match.

[0170] In examples, the verification result 197 is negative and indicates that the received verification configuration information 192 is invalid if the cryptographic encodings 174, 194 do not match.

[0171] In some examples, at block 218B1, the core node 129 generates a cryptographic encoding 194 of at least the verification configuration information 192 and compares the cryptographic encoding 194 of at least the verification configuration information 192 and the received cryptographic encoding 174 of at least configuration information 172 to verify the verification configuration information 192.

[0172] At block 218B2, the core node 129 transmits a verification result 197 to the second access node 120B.

[0173] In examples, the verification result 197 is positive and indicates that the received verification configuration information 192 is valid if the cryptographic encodings 174, 194 match. In examples, the verification result 197 is negative and indicates that the received verification configuration information 192 is invalid if the cryptographic encodings 174, 194 do not match.

[0174] In examples, from the point of view of the core node 129, method 200 comprises receiving, from a requesting access node, a request for assistance 199 in verification of verification configuration information 192.

[0175] The requesting access node can be the first access node 120A, or the second access node 120B.

[0176] In examples, the request for assistance 199 can comprise at least one of the following: a request for an expected cryptographic encoding 196 of at least configuration information, or a request for at least one identifier 186 configured to uniquely identify an access node 120.

[0177] In examples, from the point of view of the core node 129, method 200 comprises transmitting information 198 towards the requesting access node to enable a verification of the verification configuration information 192.

[0178] Consequently, FIG. 2 illustrates a method 200 comprising: causing transmission of configuration information 172 towards at least one access node 120; receiving, from a requesting access node, a request for assistance 199 in verification of verification configuration information 192; and causing transmission of information 198 towards the requesting access node to enable verification of the verification configuration information 192.

[0179] In some examples, transmitting information 198 comprises transmitting at least one of the following: an expected cryptographic encoding 196 of at least configuration information, or at least one identifier configured to uniquely identify an access node 120.

[0180] Examples of the disclosure are advantageous and / or provide technical benefits. For example, examples of the disclosure provide for securing storage of configuration information at a terminal node while the terminal node is in a radio disconnected state.

[0181] For example, examples of the disclosure provide for configuration information to be reused when a terminal node transitions from a radio disconnected state to a radio connected state.

[0182] For example, examples of the disclosure provide for verification of configuration information to ensure that the configuration information has not been tampered with while the configuration information is, for example, stored at a terminal node or during transit.

[0183] For example, examples of the disclosure provide for configuration information to be stored to ensure continuity for at least one service provided to a terminal node across radio connection states, such as radio resource control (RRC) states.

[0184] FIG. 3 illustrates an example of signaling between entities. FIG. 3 also illustrates an example of a method 300.

[0185] FIG. 3 illustrates methods performed by a system comprising interaction between different system entities. FIG. 3 also illustrates a collection of separate methods performed separately by the different system entities.

[0186] One or more of the features discussed in relation to FIG. 3 can be found in one or more of the other FIGs.

[0187] In the example of FIG. 3, a plurality of apparatuses transmit and / or receive one or more signals and / or messages across and / or via and / or using a network. In examples, any suitable form of communication in any suitable network can be used. For example, at least a portion of the network 100 of FIG. 1 can be used.

[0188] In the example of FIG. 3, a terminal node 110, an access node 120A or access nodes 120A and 120B, and a core node 129 transmit and / or receive one or more signals and / or one or more messages. In the example of FIG. 3, the terminal node 110 is a UE 170, the access nodes 120A, 120B are gNBs 173A, 173B and the core node 129 is an access management function (AMF) 175.

[0189] In examples, transmissions between entities illustrated in FIG. 3 can proceed via any number of intervening entities, including no intervening entities.

[0190] Although a single terminal node 110 is illustrated in the example of FIG. 3, in examples any suitable number of terminal nodes 110 can be included. Similarly, any suitable number of access nodes 120 can be used and any suitable number of core nodes 129 can be used.

[0191] In examples, at least part of method 300 can be considered a method of securely storing configuration information.

[0192] In examples, at least part of method 300 can be considered a method of securely storing configuration information while a terminal node is in a radio disconnected mode.

[0193] In examples, at least part of method 300 can be considered a method of verifying configuration information.

[0194] At block 302, method 300 comprises generating a cryptographic encoding 174 of at least configuration information 172 based, at least in part, on configuration information 172 and at least one random number value 190.

[0195] The configuration information 172 can comprises any suitable configuration information 172. For example, the configuration information 172 can comprise any suitable configuration information for use in a wireless network, such as the wireless network 100 in the example of FIG. 1.

[0196] In some examples, the configuration information 172 comprises configuration information 172 that is to be stored so that the configuration information 172 can be made available to a serving access node 120 of a terminal node 110 when the terminal node 110 transitions from a radio disconnected mode 180 to a radio connected mode 182. In some examples, the configuration information 172 comprises radio configuration information.

[0197] In some examples, the configuration information 172 comprises measurement configuration information.

[0198] In some examples, the configuration information 172 comprises private or sensitive or confidential information relating to, for example, user privacy. For example, the configuration information 172 can comprise at least one of the following: IP address, slice details, or application layer details and so on.

[0199] In some examples, the configuration information 172 comprises configuration information to be stored to ensure continuity for at least one service provided to a terminal node 110 across radio connection states, such as radio resource control (RRC) states.

[0200] In some examples, the configuration information 172 comprises quality of experience measurement collection (QMC) configuration information 172. For example, the configuration information 172 can comprise multicast / broadcast service MBS QMC configuration information 172.

[0201] In some examples, method 200 comprises determining, by the core node 129, the configuration information 172. For example, the configuration information 172 can be received or generated by the core node 129.

[0202] In examples, the cryptographic encoding 174 is an encrypted or encoded or hashed version of at least the configuration information 172. Accordingly, in some examples, generating a cryptographic encoding 174 of at least the configuration information 172 comprises at least one of encrypting, encoding, or hashing the configuration information.

[0203] In some examples, the cryptographic encoding 174 is the result of applying at least one cryptographic algorithm 188 to the configuration information 172. The at least one cryptographic algorithm can comprise at least one of the following: at least one encryption algorithm, at least one encoding algorithm, or at least one hash algorithm and so on. For example, 128 bit algo or 256 bit algo or AEAD combined algorithm can be used.

[0204] In some examples, generating the cryptographic encoding 174 of at least the configuration information 172 comprises using the configuration information 172 and the at least one random number value 190 as inputs into at least one cryptographic algorithm 188.

[0205] A cryptographic algorithm 188 can, in examples, be considered a cryptographic function.

[0206] Any suitable cryptographic algorithm 188 can be used. For example, any suitable encryption, encoding, or hash algorithm can be used. For example, any suitable hash function can be used.

[0207] The generated cryptographic encoding 174 of at least the configuration information 172 can be stored at the core node 129.

[0208] At block 304, method 300 comprises transmitting the configuration information 172 and the at least one random number value 190 towards at least one access node 120A. The access node 120A can be considered a first access node 120A.

[0209] As FIG. 3 illustrates one or more functions / actions of transmitting, FIG. 3 also illustrates the corresponding receiving and causing / enabling / controlling receiving function(s) / action(s). For example, from the point of view of the access node 120A, at block 304, method 300 comprises receiving configuration 172 and at least one random number value 190 from at least one core node 129.

[0210] In some examples, block 304 comprises transmitting an initial context setup request / UE context modification request.

[0211] At block 306, method 300 comprises transmitting the configuration information 172 and the at least one random number value 190 towards a terminal node 110. From the point of view of the terminal node 110, block 306 comprises receiving, from a first access node 120A, configuration information 172 and at least one random number value 190.

[0212] In some examples, block 306 comprises transmitting an RRCReconfiguration message.

[0213] At block 308, method 300 comprises storing the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment.

[0214] Any suitable secure storage environment or environments can be used. In examples, a secure storage environment can be considered a tamper proof memory.

[0215] In examples, a secure storage environment can comprise a trusted execution environment (TEE) or a universal integrated circuit card (UICC).

[0216] In examples, a received configuration information data structure 177 can comprise any suitable data structure configured to store the information of the received configuration information 172. For example, the received configuration information data structure 177 can be any suitable data structure into which the configuration information 172 can be stored for later retrieval.

[0217] At block 310, method 300 comprises generating a cryptographic encoding 174 of at least the configuration information 172 based, at least in part, on the received configuration information 172 and the received at least one random number value 190.

[0218] Generating the cryptographic encoding 174 of at least the configuration information 172 can be performed as described at block 304. Accordingly, in examples, when the configuration information 172 and the at least one random number value have not changed between block 302 and block 310, the cryptographic encoding 174 at the core node 192 will match the cryptographic encoding 174 at the terminal node.

[0219] In examples, generating the cryptographic encoding 174 of at least the configuration information 172 comprises generating the cryptographic encoding 174 based, at least in part, on the received configuration information 172, and the received at least one random number value 190.

[0220] In some examples, generating the cryptographic encoding 174 of at least the configuration information comprises using the configuration information 172 and the at least one random number value 190 as inputs into at least one cryptographic algorithm 188.

[0221] Information of the at least one cryptographic algorithm 188 used to generate the cryptographic encodings 174 can be transmitted with or separate to the configuration information 172.

[0222] For example, information of the at least one cryptographic algorithm 188 used to generate the cryptographic encoding 174 can be transmitted / received at block 304, and block 306, and stored at block 308.

[0223] In some examples, information of the at least one cryptographic algorithm 18 used to generate the cryptographic encoding 174 is preconfigured at the terminal node 110.

[0224] In examples, at block 306 the terminal node 110 is in a radio connected mode 182. Accordingly, in examples, at block 306 the configuration information 172 and the at least one random number value 190 are received during a radio connected mode 182.

[0225] At block 312, method 300 comprises transitioning from a radio connected mode 182 to a radio disconnected mode 180. In some examples, at block 312 the terminal node 110 transitions from RRC CONNECTED to RRC IDLE or RRC INACTIVE mode.

[0226] Block 312 can comprise one or more actions by at least one of the access node 120A or the core node 129.

[0227] At block 314, method 300 comprises transitioning from a radio disconnected mode 180 to a radio connected mode 182. For example, block 314 can comprise transitioning from RRC IDLE or RRC INACTIVE to RRC CONNECTED. Block 314 can occur at some time after block 312 as indicated by the ‘ in the example of FIG. 3. For example, the terminal node 110 can remain in a radio disconnected mode 180 for some time before transitioning to a radio connected mode 182.

[0228] At block 314, the terminal node 110 can transition to a radio connected mode 182 with the first access node 120A or a different access node 120B. Therefore, in the example of FIG. 2, the vertical, solid, central line in the lower portion of FIG. 2 can represent actions at the first access node 120A or a different access node 120B.

[0229] Block 314 can comprise one or more actions by at least one of the access node 120A, the access node 120B or the core node 129.

[0230] At block 316, method 300 comprises transmitting, based at least in part on a transition from a radio disconnected mode 180 to a radio connected mode 182, of content 184 of the received configuration information data structure 177 and the cryptographic encoding 174 of the configuration information 172 towards a second access node 120A, 120B to enable a verification of the stored configuration information.

[0231] Consequently, FIG. 3 illustrates a method 300 comprising: receiving, from a first access node 120A, configuration information 172 and at least one random number value 190; storing the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment; generating a cryptographic encoding 174 of at least the configuration information 172 based, at least in part, on the received configuration information 172 and the received at least one random number value 190; and causing transmission, based at least in part on a transition from a radio disconnected mode 180 to a radio connected mode 182, of content 184 of the received configuration information data structure 177 and the cryptographic encoding 174 of the configuration information 172 towards a second access node 120A, 120B to enable a verification of the stored configuration information. The first access node 120A and the second access node 120A, 120B can be the same, or different access nodes.

[0232] That is, in examples, the second access node can be referred to by reference 120A when the second access node is the same access node as the first access node 120A, or the second access node can be referred to by reference 120B when the second access node is a different access node than the first access node 120A.

[0233] In examples, the content 184 of the received configuration information data structure 177 is the stored configuration information when block 216 is performed.

[0234] Accordingly, in examples, if the content of the received configuration information data structure 177 is changed between block 308 and block 316, the stored configuration information transmitted at block 216 is different to the received configuration information 172.

[0235] For example, if the stored configuration information 172 at the terminal node 110 is tampered with, the content of the received configuration information data structure 177 changes between block 308 and block 316, and the stored configuration information that is transmitted at block 316 is different to the configuration information 172 received at block 306.

[0236] However, in some examples, the content 184 of the received configuration information data structure 177 does not change between block 308 and block 316 and therefore the stored configuration information that is transmitted at block 316 is, in some examples, the same as the received configuration information 172 at block 306.

[0237] In examples, the content 184 of the received configuration information data structure 177 / the stored configuration information when block 216 is performed can be considered verification configuration information 192.

[0238] From the point of view of the access node 120A, 120B method 300 comprises receiving verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 172 from a terminal node 110. In some examples, block 316 comprises transmitting an RRCSetupComplete message.

[0239] At block 318, method 300 comprises transmitting the received verification configuration information 192 and the received cryptographic encoding 174 of at least configuration information 172 towards a core node 129 to enable verification of the received verification configuration information 192.

[0240] Consequently, FIG. 3 illustrates a method 300 comprising: receiving configuration information 172 and at least one random number value 190 from at least one core node 129; causing transmission of the configuration information 172 and the at least one random number 190 value towards a terminal node 110; receiving verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 172 from a terminal node 110; and causing transmission of the received verification configuration information 192 and the received cryptographic encoding 174 of at least configuration information 172 towards a core node 129 to enable verification of the received verification configuration information 192.

[0241] In some examples, block 318 comprises transmitting a send UE information message.

[0242] From the point of view of the core node 129, method 300 comprises receiving verification configuration information 192 and a cryptographic encoding of at least configuration information 172 from and access node 120A, 120B.

[0243] At block 320, method 300 comprises generating a cryptographic encoding 194 of at least the verification configuration information 192 based, at least in part, on the verification configuration information 192 and the at least one random number value 190.

[0244] Generating the cryptographic encoding 194 of at least the verification configuration information 192 can be performed as described at block 204 in relation to the configuration information 172. Accordingly, in some examples, generating the cryptographic encoding 194 of at least the verification configuration information 192 comprises using the verification configuration information 192 and the at least one random number value 190 as inputs into at least one cryptographic algorithm.

[0245] At block 322, method 300 comprises comparing the cryptographic encoding 194 of at least the verification configuration information 192 with the generated cryptographic encoding 174 of at least configuration information 172 and the received cryptographic encoding 174 of at least configuration information 172 to verify the received verification information 192.

[0246] Consequently, FIG. 3 illustrates a method 300 comprising: generating a cryptographic encoding 174 of at least configuration information 172 based, at least in part, on configuration information 172 and at least one random number value 190; causing transmission of the configuration information 172 and the at least one random number value 190 towards at least one access node 120A; receiving verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 174 from an access node 120A, 120B; and generating a cryptographic encoding 194 of at least the verification configuration information 192 based, at least in part, on the verification configuration information 192 and the at least one random number value 190; comparing the cryptographic encoding 194 of at least the verification configuration information 192 with the generated cryptographic encoding 174 of at least configuration information 172 and the received cryptographic encoding 174 of at least configuration information 172 to verify the received verification configuration information 192.

[0247] In examples, the generated cryptographic encoding of at least configuration information can be referenced 172 A and the received cryptographic encoding of at least configuration information can be referenced 172B.

[0248] Accordingly, in examples, the cryptographic encoding 194 of at least the verification configuration information 192 is compared with the generated cryptographic encoding 174 of at least configuration information 172 from block 302 and the received cryptographic encoding 174 of at least configuration information 172 at block 318 to verify whether the configuration information 172 has changed after it was transmitted from the core node 129. For example, while it was in transit or while it was stored at the terminal node 110.

[0249] This is because, in examples, the cryptographic encodings 174, 194 are generated in the same way and therefore if the input configuration information is unchanged the cryptographic encodings 174, 194 will also match.

[0250] At block 324, method 300 comprises transmitting a verification result 197 towards the access node 120A, 120B (that was involved in block 318) based, at least in part, on the comparing.

[0251] In examples, method 300 comprises transmitting a positive verification result in response to determining that the cryptographic encoding 194 of at least the verification configuration information 192 matches the generated cryptographic encoding 174 of at least configuration information 172 and the received cryptographic encoding 174 of at least configuration information 172. Otherwise, in examples, the verification result is negative.

[0252] In examples, a positive verification result indicates that the received verification configuration information 192 is valid.

[0253] In examples, a negative verification result indicates that the received verification configuration information 192 is invalid.

[0254] Examples of the disclosure are advantageous and / or provide technical benefits.

[0255] For example, examples of the disclosure provide for securing storage of configuration information at a terminal node while the terminal node is in a radio disconnected state.

[0256] For example, examples of the disclosure provide for configuration information to be reused when a terminal node transitions from a radio disconnected state to a radio connected state.

[0257] For example, examples of the disclosure provide for verification of configuration information to ensure that the configuration information has not been tampered with while the configuration information is, for example, stored at a terminal node or during transit. For example, examples of the disclosure provide for configuration information to be stored to ensure continuity for at least one service provided to a terminal node across radio connection states, such as radio resource control (RRC) states.

[0258] FIG. 4 illustrates an example of a method 400.

[0259] Method 400 can be performed by any suitable apparatus comprising any suitable means for performing method 400, for example an apparatus as described in relation to FIG. 15A and / or FIG. 15B.

[0260] In examples, method 400 can be performed by a terminal node 110, such as a UE 170, or by at least one control device configured to control the functioning thereof.

[0261] At block 402, method 400 comprises receiving, from a first access node 120A, configuration information 172 and at least one random number value 190.

[0262] At block 404, method 400 comprises storing the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment.

[0263] At block 406, method 400 comprises generating a cryptographic encoding 174 of at least the configuration information 172 based, at least in part, on the received configuration information 172 and the received at least one random number value 190.

[0264] At block 408. Method 400 comprises causing transmission, based at least in part on a transition from a radio disconnected mode 180 to a radio connected mode 182, of content 184 of the received configuration information data structure 177 and the cryptographic encoding 174 of the configuration information 172 towards a second access node 120A, 120B to enable a verification of the stored configuration information.

[0265] Consequently, FIG 4 illustrates a method 400 comprising: receiving, from a first access node 120A, configuration information 172 and at least one random number value 190; storing the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment; generating a cryptographic encoding 174 of at least the configuration information 172 based, at least in part, on the received configuration information 172 and the received at least one random number value 190; and causing transmission, based at least in part on a transition from a radio disconnected mode 180 to a radio connected mode 182, of content 184 of the received configuration information data structure 177 and the cryptographic encoding 174 of the configuration information 172 towards a second access node 120A, 120B to enable a verification of the stored configuration information.

[0266] FIG. 5 illustrates an example of a method 500.

[0267] Method 500 can be performed by any suitable apparatus comprising any suitable means for performing method 500, for example an apparatus as described in relation to FIG. 15A and / or FIG. 15B.

[0268] In examples, method 500 can be performed by at least one access node 120, such as a gNB 173, or by at least one control device configured to control the functioning thereof.

[0269] At block 502, method 500 comprises receiving configuration information 172 and at least one random number value 190 from at least one core node 129.

[0270] At block 504, method 500 comprises causing transmission of the configuration information 172 and the at least one random number 190 value towards a terminal node 110.

[0271] At block 506, method 500 comprises receiving verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 172 from a terminal node 110. At block 508, method 500 comprises causing transmission of the received verification configuration information 192 and the received cryptographic encoding 174 of at least configuration information 172 towards a core node 129 to enable verification of the received verification configuration information 192.

[0272] Consequently, FIG. 5 illustrates a method 500 comprising: receiving configuration information 172 and at least one random number value 190 from at least one core node 129; causing transmission of the configuration information 172 and the at least one random number 190 value towards a terminal node 110; receiving verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 172 from a terminal node 110; and causing transmission of the received verification configuration information 192 and the received cryptographic encoding 174 of at least configuration information 172 towards a core node 129 to enable verification of the received verification configuration information 192.

[0273] FIG. 6 illustrates an example of a method 600.

[0274] Method 600 can be performed by any suitable apparatus comprising any suitable means for performing method 600, for example an apparatus as described in relation to FIG. 15A and / or FIG. 15B.

[0275] In examples, method 600 can be performed by a core node 129, such as an AMF 175, or by at least one control device configured to control the functioning thereof.

[0276] At block 602, method 600 comprises generating a cryptographic encoding 174 of at least configuration information 172 based, at least in part, on configuration information 172 and at least one random number value 190.

[0277] At block 604, method 600 comprises causing transmission of the configuration information 172 and the at least one random number value 190 towards at least one access node 120A. At block 606, method 600 comprises receiving verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 174 from an access node 120A, 120B.

[0278] At block 608, method 600 comprises generating a cryptographic encoding 194 of at least the verification configuration information 192 based, at least in part, on the verification configuration information 192 and the at least one random number value 190.

[0279] At block 610, method 600 comprises comparing the cryptographic encoding 194 of at least the verification configuration information 192 with the generated cryptographic encoding 174 of at least configuration information 172 and the received cryptographic encoding 174 of at least configuration information 172 to verify the received verification configuration information 192.

[0280] Consequently, FIG. 6 illustrates a method 600 comprising: generating a cryptographic encoding 174 of at least configuration information 172 based, at least in part, on configuration information 172 and at least one random number value 190; causing transmission of the configuration information 172 and the at least one random number value 190 towards at least one access node 120A; receiving verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 174 from an access node 120A, 120B; and generating a cryptographic encoding 194 of at least the verification configuration information 192 based, at least in part, on the verification configuration information 192 and the at least one random number value 190; comparing the cryptographic encoding 194 of at least the verification configuration information 192 with the generated cryptographic encoding 174 of at least configuration information 172 and the received cryptographic encoding 174 of at least configuration information 172 to verify the received verification configuration information 192.

[0281] FIG. 7 illustrates an example of a method 700. Method 700 can be performed by any suitable apparatus comprising any suitable means for performing method 400, for example an apparatus as described in relation to FIG. 15A and / or FIG. 15B.

[0282] In examples, method 700 can be performed by a terminal node 110, such as a UE 170, or by at least one control device configured to control the functioning thereof.

[0283] At block 702, method 700 comprises receiving, from a first access node 120A, configuration information 172 and a cryptographic encoding 174 of at least the configuration information 172.

[0284] At block 704, method 700 comprises storing the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment and the cryptographic encoding 174 of the configuration information 172 in at least one secure storage environment.

[0285] At block 706, method 700 comprises causing transmission, based at least in part on a transition from a radio disconnected mode 180 to a radio connected mode 182, of content 184 of the received configuration information data structure 177 and the stored cryptographic encoding 174 of the configuration information 172 towards a second access node 120A, 120B to enable a verification of the stored configuration information.

[0286] Consequently, FIG. 7 illustrates a method 700 comprising: receiving, from a first access node 120A, configuration information 172 and a cryptographic encoding 174 of at least the configuration information 172; storing the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment and the cryptographic encoding 174 of the configuration information 172 in at least one secure storage environment; and causing transmission, based at least in part on a transition from a radio disconnected mode 180 to a radio connected mode 182, of content 184 of the received configuration information data structure 177 and the stored cryptographic encoding 174 of the configuration information 172 towards a second access node 120A, 120B to enable a verification of the stored configuration information. FIG. 8 illustrates an example of a method 800.

[0287] Method 800 can be performed by any suitable apparatus comprising any suitable means for performing method 800, for example an apparatus as described in relation to FIG. 15A and / or FIG. 15B.

[0288] In examples, method 800 can be performed by at least one access node 120, such as a gNB 173, or by at least one control device configured to control the functioning thereof.

[0289] At block 802, method 800 comprises receiving configuration information 172 from at least one core node 129.

[0290] At block 804, method 800 comprises generating a cryptographic encoding 174 of at least the configuration information 172.

[0291] At block 806, method 800 comprises causing transmission of the configuration information 172 and the cryptographic encoding 174 of at least the configuration information 172 towards a terminal node 110.

[0292] At block 808, method 800 comprises receiving verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 172 from a terminal node 120.

[0293] At block 810, method 800 comprises verifying the received verification configuration information 192 based, at least in part, on the received cryptographic encoding 174 of at least configuration information 172.

[0294] Consequently, FIG. 8 illustrates a method 800 comprising: receiving configuration information 172 from at least one core node 129; generating a cryptographic encoding 174 of at least the configuration information 172; causing transmission of the configuration information 172 and the cryptographic encoding 174 of at least the configuration information 172 towards a terminal node 110; receiving verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 172 from a terminal node 120; and verifying the received verification configuration information 192 based, at least in part, on the received cryptographic encoding 174 of at least configuration information 172.

[0295] FIG. 9 illustrates an example of a method 900.

[0296] Method 900 can be performed by any suitable apparatus comprising any suitable means for performing method 900, for example an apparatus as described in relation to FIG. 15A and / or FIG. 15B.

[0297] In examples, method 900 can be performed by a core node 129, such as an AMF 175, or by at least one control device configured to control the functioning thereof.

[0298] At block 902, method 900 comprises causing transmission of configuration information 172 towards at least one access node 120.

[0299] At block 904, method 900 comprises receiving, from a requesting access node, a request for assistance 199 in verification of verification configuration information 192.

[0300] At block 906, method 900 comprises causing transmission of information 198 towards the requesting access node to enable verification of the verification configuration information 192.

[0301] Consequently, FIG. 9 illustrates a method 900 comprising: causing transmission of configuration information 172 towards at least one access node 120; receiving, from a requesting access node, a request for assistance 199 in verification of verification configuration information 192; and causing transmission of information 198 towards the requesting access node to enable verification of the verification configuration information 192.

[0302] In examples, to ensure signaling-based and management-based QoE measurement continuity for MBS across RRC states, the QoE measurement configuration information should be made available to the gNB serving the UE when the UE transits from the RRC_IDLE to RRC_CONNECTED state.

[0303] In examples, the QoE measurement configuration information should be stored at the UE or at the AMF while the UE is in RRC_IDLE state. After the UE transits from the RRC_IDLE to RRC_CONNECTED state, this information should be provided to the serving gNB.

[0304] In examples, the QoE measurement configuration information, when stored in UE when it is in RRC_IDLE state, should be stored in a manner to ensure that the privacy of the user is preserved.

[0305] Some examples of the disclosure focus on Security and Privacy aspects of QoE measurement configurations when stored in UE. In examples, parts of the configuration like IP address, Slice details, and application layer details can be sensitive information and may leak user privacy as well as confidential information about the network and network slices. If such information is stored in the UE, it should be stored in a secure memory location, and, ensured that it is not tampered with.

[0306] Examples of the disclosure provide methods and apparatus for the following:

[0307] Secure storage of QMC at the UE in tamper-proof memory. Storage in TEE kind of environments to ensure that even the access to this information is controlled and available only for UE’s services which need it, and not to any applications.

[0308] When stored in TEE, examples of the disclosure also proposes a light-weight application which is also stored in TEE to provide access to the stored QMC information.

[0309] Examples of the disclosure ensure Integrity of QMC is verified when sent from UE to RAN.

[0310] In examples, if QMC is stored in UE when it is in IDLE or INACTIVE mode, when it gets moves to CONNECTED mode, UE can send the stored QMC to RAN. This can be ensured in multiple ways as described herein. Examples described herein consider that UE may move from one cell to another in IDLE or INACTIVE mode. In examples, if QMC was stored when UE was connected to one cell, and UE moves to connected mode with another cell, the new serving cell should be able to verify the integrity of the QMC.

[0311] In all the options presented below, RAN can be considered as one or more access nodes, where an access node can be a gNodeB and / or a wireless edge computing server. Also, storage in UE should to be in a secure location, which could be, for example, in a TEE or in the UICC. Tampering of the QMC related data stored in the UE can be at the UE itself or by a man-in- the-middle (like a false BTS), and various options are considered to detect any tampering as well as the probable point of such tampering (at UE or outside the UE).

[0312] The algorithm used for hashing or encryption can be pre-configured in UE using state-of-the- art procedures like SoR or UPU or OTA configuration updates.

[0313] FIGs 10, 11, 12 and 13 illustrate examples of signaling between entities. FIGs 10, 11, 12, and 13 also illustrate examples of methods 1000, 1100, 1200, 1300.

[0314] FIGs 10, 11, 12, and 13 illustrate methods performed by a system comprising interaction between different system entities. FIGs 10, 11, 12, and 13 also illustrate a collection of separate methods performed separately by the different system entities.

[0315] With regard to FIG. 10, with this variant, AMF will generate the hashed MBS QMC configuration using a RAND value and the QMC information. The hashed value of MBS QMC configuration and the algorithm used to generate the hash value are sent to UE over secure NAS connection, and stored in UE’s TEE / secure memory location with access restrictions enforced, when UE is in connected mode.

[0316] Next time when UE moves once again from Idle to connected mode, then hashed value HMBS_QMC and MBS QMC configuration is sent from UE to RAN. RAN can verify the integrity of MBS QMC with help of AMF. In some examples, the hash value calculation can be obtained by applying MD5SUM or SHA256 kind of hashing algorithms on the QMC information only. However, usage of RAND can further ensure that the authentication of the UE providing the QMC information can also be verified.

[0317] At block 1 of FIG. 10, the AMF stores the MBS QMC configuration. The AMF will generate the RAND and using the cryptographic hash function to generate and store the hash value HMBS_QMC.

[0318] At block 2 of FIG. 10, the AMF will send the initial context setup request or UE context modification request with MBS QMC configuration and hash value HMBS_QMC to RAN.

[0319] At block 3 of FIG. 10, the RAN will send RRCReconfiguration with MBS QMC reconfiguration and hash value HMBS_QMC to UE. UE will store the hash value for future usage.

[0320] At block 4 of FIG. 10, UE is in RRC connected mode and after the MBS session is terminated. UE moves to RRC Idle mode. RAN will delete the MBS QMC configuration.

[0321] At block 5 of FIG. 10, when the UE moves to RRC connected state, then UE will send in the RRC setup complete message the MBS QMC configuration and hash value HMBS_QMC (which was stored in block 3) to RAN. RAN will fetch the RAND from AMF, so that RAN will generate expected HMBS_QMC using received MBS_QMC, and compare the generated hash with received HMBS_QMC to verify the integrity. If the verification is successful, then MBS QMC configuration is used by RAN.

[0322] In some examples, RAN can send the received MBS_QMC and HMBS_QMC to AMF and request for verification. Upon successful verification, AMF can respond with a positive ACK and enable usage of MBS_QMC.

[0323] With regard to FIG. 11, with this variant, AMF sends the MBS QMC configuration to RAN. RAN will use the PCI and EARFCN to generate the Hash value of HMBS_QMC. The generated HMBS_QMC will be sent to UE. When the UE moved from idle to connected mode, the HMBS_AMC and MBS QMC configuration is sent to RAN. RAN will generate the expected HMBS_QMC and verifies with HMBS_QMC.

[0324] At block 1 of FIG. 11, the AMF stores the MBS QMC configuration.

[0325] At block 2 of FIG. 11, the AMF sends the MBS QMC configuration in the initial context setup request or the UE context modification request message to the RAN. RAN will store the MBS QMC configuration and will generate the hash value HMBS_QMC with MBS_QMC, PCI value and EARFCN-DL as inputs to cryptographic hash function.

[0326] At block 3 of FIG. 11, the RAN will send the RRC reconfiguration message with MBS QMC configuration and hash value HMBS_QMC to the UE. UW will store QMC configuration and hash value. Also, in this block at 3c, the values required for verification of hash at a later point are stored in AMF.

[0327] At block 4 of FIG. 11 , the UE is in RRC connected mode and it moves to IDLE mode. MBS session is also terminated. RAN will delete the MBS QMC configuration.

[0328] At block 5 of FIG. 11 , when the UE moves to RRC connected mode, the RRC setup complete is sent with MBS QMC configuration and hash value HMBS_QMC to RAN. RAN will generate the expected HMBS_QMC and verifies it against the received HMBS_QMC. If verification is successful, then the RAN considers the configuration.

[0329] In some examples, the expected HMBS_QMC can be obtained from AMF and compared with the value obtained from the UE to ensure that the QMC and / or hash value is not tampered with in the UE.

[0330] In some examples, the serving RAN can obtain the PCI and EARFCN_DL from AMF which was stored in block 3c, compute the expected HMBS_QMC and then compare for verification of integrity of the QMC.

[0331] In some examples, this can also be done by communication between serving RAN and last serving RAN. This communication can be, for example: New RAN sends the HMBS_QMC and MBS_QMC received from UE to old RAN and requests for verification.

[0332] Alternatively, New RAN obtains PCI and EARFCN_DL from the old RAN and computes the hash value by itself for verification.

[0333] With regard to FIG. 12, with this variant, Hash value is generated and only RAND and algorithm information is sent to the UE, so UE also generates hash value independently. Later when UE moves form idle to connected state, then RAN will forward it to AMF, so the actual configuration can be verified by RAN with help from AMF. Instead of a RAND value, QMC_ID may also be used in this option (FIG. 13).

[0334] In the example of FIG. 13, the main difference with the example of FIG. 10 is that the hash value is never sent to UE or over the air(OTA). Instead, it is computed at both ends. Only the RAND value used for hash value generation is sent to UE, so the UE can also generate the hash value. Later when UE moves from idle mode to connected mode, the hash value HMBS_QMC is sent from UE to RAN and RAN can fetch the MBS QMC configuration from AMF after AMF performs hash verification using the previously stored hash value (from block 1) In block 5, when UE sends QMC as well as the hash value, AMF re-computes the hash using received QMC configuration, and compares it with both: Hash received from UE as well as the hash stored in AMF. If any of these fails, the verification fails. If both succeed, the QMC received from UE is fine and can be used.

[0335] With regard to FIG. 14, with this variant, the QMC ID is used as reference to QMC value configuration. Only the QMCID is shared to UE and later when configuration needs to be fetched, then the QMC ID is provided and MBS QMC configuration is fetched from the AMF using the associated QMC_ID.

[0336] With regard to FIG. 14, with this variant, AMF generates AN_PUB and AN_PRIV key. AMF will use the AN_PRIV key to encrypt the MBS_QMC. The encrypted MBS_QMC can be sent to the UE. When UE moves from idle mode to connected mode, UE sends the encrypted MBS_QMC to RAN and RAN either decrypts itself if it has received the AN_PUB key from AMF, or requests AMF to decrypt it to subsequently receive the un-encrypted MBS_QMC. At block 1 of FIG. 14, the AMF will store the MBS QMC configuration. AMF will generate a AN_PUB and AN_PRIV , which is private and public key pairs. These pairs are same to all RANs under this particular AMF. The AMF will use AN_PRIV to encrypt the MBS_QMC.

[0337] At block 2 of FIG. 14, the AMF sends the encrypted MBS_QMC value and optionally includes AN_PUB key to RAN in initial context setup request message or the UE context modification request to RAN. The RAN will store the MBS QMC configuration and AN_PUB key.

[0338] At block 3 of FIG. 14, RAN sends the RRC reconfiguration message to UE with encrypted MBS QMC, which is stored securely in the UE.

[0339] At block 4 of FIG. 14, the UE moves from connected state to idle state, as the MBS session is terminated. So the MBS QMC configuration is also deleted in RAN.

[0340] At block 5 of FIG. 14, the UE is moved to RRC connected state. The UE will send the RRC setup complete message with the encrypted MBS QMC which was securely stored in the UE, to the RAN.

[0341] In some examples, if all RANs are provisioned with AN_PUB key during block 2, the encrypted MBS_QMC is decrypted at the access node and MBS_QMC is retrieved.

[0342] In some examples, if the RAN nodes are not provisioned with AN_PUB key, the encrypted MBC_QMC received from the UE can be sent to the AMF for decryption.

[0343] Fig 15 A illustrates an example of a block diagram of an apparatus 130. The apparatus 130 may be a controller of an apparatus or device such as a terminal node 110, for example a UE 46, or an access node 120, or a core node 129. The apparatus 130 may be considered a controller or controller device. Implementation of a controller 130 may be as controller circuitry. The controller 130 may be implemented in hardware alone, have certain aspects in software including firmware alone or can be a combination of hardware and software (including firmware).

[0344] As illustrated in Fig 15A the controller 130 may be implemented using instructions that enable hardware functionality, for example, by using executable instructions 136 in a general- purpose or special-purpose processor 132 that may be stored on a machine readable storage medium (disk, memory etc.) to be executed by such a processor 132.

[0345] The processor 132 is configured to read from and write to the memory 134. The processor 132 may also comprise an output interface via which data and / or commands are output by the processor 132 and an input interface via which data and / or commands are input to the processor 132.

[0346] The memory 134 stores instructions, program, or code 136 that controls the operation of the apparatus 130 when loaded into the processor 132. The computer program instructions, program or code 136, provide the logic and routines that enables the apparatus 130 to perform the methods illustrated in the accompanying FIGs. The processor 132 by reading the memory 134 is configured to load and execute the instructions, program, or code 136.

[0347] The apparatus 130 comprises: at least one processor 132; and at least one memory 134 storing instructions that, when executed by the at least one processor 132, cause the apparatus at least to: receive, from a first access node 120A, configuration information 172 and at least one random number value 190; store the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment; generate a cryptographic encoding 174 of at least the configuration information 172 based, at least in part, on the received configuration information 172 and the received at least one random number value 190; and cause transmission, based at least in part on a transition from a radio disconnected mode 180 to a radio connected mode 182, of content 184 of the received configuration information data structure 177 and the cryptographic encoding 174 of the configuration information 172 towards a second access node 120A, 120B to enable a verification of the stored configuration information.

[0348] The apparatus 130 comprises: at least one processor 132; and at least one memory 134 storing instructions that, when executed by the at least one processor 132, cause the apparatus at least to: receive configuration information 172 and at least one random number value 190 from at least one core node 129; cause transmission of the configuration information 172 and the at least one random number 190 value towards a terminal node 110; receive verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 172 from a terminal node 110; and cause transmission of the received verification configuration information 192 and the received cryptographic encoding 174 of at least configuration information 172 towards a core node 129 to enable verification of the received verification configuration information 192.

[0349] The apparatus 130 comprises: at least one processor 132; and at least one memory 134 storing instructions that, when executed by the at least one processor 132, cause the apparatus at least to: generate a cryptographic encoding 174 of at least configuration information 172 based, at least in part, on configuration information 172 and at least one random number value 190; cause transmission of the configuration information 172 and the at least one random number value 190 towards at least one access node 120A; receive verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 174 from an access node 120A, 120B; and generate a cryptographic encoding 194 of at least the verification configuration information 192 based, at least in part, on the verification configuration information 192 and the at least one random number value 190; compare the cryptographic encoding 194 of at least the verification configuration information 192 with the generated cryptographic encoding 174 of at least configuration information 172 and the received cryptographic encoding 174 of at least configuration information 172 to verify the received verification configuration information 192.

[0350] The apparatus 130 comprises: at least one processor 132; and at least one memory 134 storing instructions that, when executed by the at least one processor 132, cause the apparatus at least to: receive, from a first access node 120A, configuration information 172 and a cryptographic encoding 174 of at least the configuration information 172; store the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment and the cryptographic encoding 174 of the configuration information 172 in at least one secure storage environment; and cause transmission, based at least in part on a transition from a radio disconnected mode 180 to a radio connected mode 182, of content 184 of the received configuration information data structure 177 and the stored cryptographic encoding 174 of the configuration information 172 towards a second access node 120A, 120B to enable a verification of the stored configuration information.

[0351] The apparatus 130 comprises: at least one processor 132; and at least one memory 134 storing instructions that, when executed by the at least one processor 132, cause the apparatus at least to: receive configuration information 172 from at least one core node 129; generate a cryptographic encoding 174 of at least the configuration information 172; cause transmission of the configuration information 172 and the cryptographic encoding 174 of at least the configuration information 172 towards a terminal node 110; receive verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 172 from a terminal node 120; and verify the received verification configuration information 192 based, at least in part, on the received cryptographic encoding 174 of at least configuration information 172.

[0352] The apparatus 130 comprises: at least one processor 132; and at least one memory 134 storing instructions that, when executed by the at least one processor 132, cause the apparatus at least to: cause transmission of configuration information 172 towards at least one access node 120; receive, from a requesting access node, a request for assistance 199 in verification of verification configuration information 192; and cause transmission of information 198 towards the requesting access node to enable verification of the verification configuration information 192.

[0353] As illustrated in Fig 15A, the instructions, program, or code 136 may arrive at the apparatus 130 via any suitable delivery mechanism 162. The delivery mechanism 162 may be, for example, a machine readable medium, a computer-readable medium, a non-transitory computer-readable storage medium, a computer program product, a memory device, a record medium such as a Compact Disc Read-Only Memory (CD-ROM) or a Digital Versatile Disc (DVD) or a solid-state memory, an article of manufacture that comprises or tangibly embodies the computer program 136. The delivery mechanism may be a signal configured to reliably transfer the computer program 136. The apparatus 130 may propagate or transmit the computer program 136 as a computer data signal.

[0354] The term “non-transitory” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal ) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).

[0355] Computer program instructions for causing an apparatus to perform at least the following or for performing at least the following: receiving, from a first access node 120A, configuration information 172 and at least one random number value 190; storing the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment; generating a cryptographic encoding 174 of at least the configuration information 172 based, at least in part, on the received configuration information 172 and the received at least one random number value 190; and causing transmission, based at least in part on a transition from a radio disconnected mode 180 to a radio connected mode 182, of content 184 of the received configuration information data structure 177 and the cryptographic encoding 174 of the configuration information 172 towards a second access node 120A, 120B to enable a verification of the stored configuration information.

[0356] Computer program instructions for causing an apparatus to perform at least the following or for performing at least the following: receiving configuration information 172 and at least one random number value 190 from at least one core node 129; causing transmission of the configuration information 172 and the at least one random number 190 value towards a terminal node 110; receiving verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 172 from a terminal node 110; and causing transmission of the received verification configuration information 192 and the received cryptographic encoding 174 of at least configuration information 172 towards a core node 129 to enable verification of the received verification configuration information 192.

[0357] Computer program instructions for causing an apparatus to perform at least the following or for performing at least the following: generating a cryptographic encoding 174 of at least configuration information 172 based, at least in part, on configuration information 172 and at least one random number value 190; causing transmission of the configuration information 172 and the at least one random number value 190 towards at least one access node 120A; receiving verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 174 from an access node 120A, 120B; generating a cryptographic encoding 194 of at least the verification configuration information 192 based, at least in part, on the verification configuration information 192 and the at least one random number value 190; and comparing the cryptographic encoding 194 of at least the verification configuration information 192 with the generated cryptographic encoding 174 of at least configuration information 172 and the received cryptographic encoding 174 of at least configuration information 172 to verify the received verification configuration information 192.

[0358] Computer program instructions for causing an apparatus to perform at least the following or for performing at least the following: receiving, from a first access node 120A, configuration information 172 and a cryptographic encoding 174 of at least the configuration information 172; storing the received configuration information 172 in a received configuration information data structure 177 in at least one secure storage environment and the cryptographic encoding 174 of the configuration information 172 in at least one secure storage environment; and causing transmission, based at least in part on a transition from a radio disconnected mode 180 to a radio connected mode 182, of content 184 of the received configuration information data structure 177 and the stored cryptographic encoding 174 of the configuration information 172 towards a second access node 120A, 120B to enable a verification of the stored configuration information.

[0359] Computer program instructions for causing an apparatus to perform at least the following or for performing at least the following: receiving configuration information 172 from at least one core node 129; generating a cryptographic encoding 174 of at least the configuration information 172; causing transmission of the configuration information 172 and the cryptographic encoding 174 of at least the configuration information 172 towards a terminal node 110; receiving verification configuration information 192 and a cryptographic encoding 174 of at least configuration information 172 from a terminal node 120; and verifying the received verification configuration information 192 based, at least in part, on the received cryptographic encoding 174 of at least configuration information 172.

[0360] Computer program instructions for causing an apparatus to perform at least the following or for performing at least the following: causing transmission of configuration information 172 towards at least one access node 120; receiving, from a requesting access node, a request for assistance 199 in verification of verification configuration information 192; and causing transmission of information 198 towards the requesting access node to enable verification of the verification configuration information 192.

[0361] The computer program instructions may be comprised in a computer program, a non-transitory computer readable medium, a computer program product, a machine readable medium. In some but not necessarily all examples, the computer program instructions may be distributed over more than one computer program.

[0362] Although the memory 134 is illustrated as a single component / circuitry it may be implemented as one or more separate components / circuitry some or all of which may be integrated / removable and / or may provide permanent / semi-permanent / dynamic / cached storage.

[0363] In examples the memory 134 comprises a random-access memory 158 and a read only memory 160. In examples the computer program 136 can be stored in the read only memory 158. See, for example, Fig. 15B.

[0364] Although the processor 132 is illustrated as a single component / circuitry it may be implemented as one or more separate components / circuitry some or all of which may be integrated / removable. The processor 132 may be a single core or multi-core processor.

[0365] References to ‘computer-readable storage medium’, ‘computer program product’, ‘tangibly embodied computer program’ etc. or a ‘controller’, ‘computer’, ‘processor’ etc. should be understood to encompass not only computers having different architectures such as single / multi- processor architectures and sequential (Von Neumann) / parallel architectures but also specialized circuits such as field-programmable gate arrays (FPGA), application specific circuits (ASIC), signal processing devices and other processing circuitry. References to computer program, instructions, code etc. should be understood to encompass software for a programmable processor or firmware such as, for example, the programmable content of a hardware device whether instructions for a processor, or configuration settings for a fixed- function device, gate array or programmable logic device etc.

[0366] As used in this application, the term ‘circuitry’ may refer to one or more or all the following:

[0367] (a) hardware-only circuitry implementations (such as implementations in only analog and / or digital circuitry) and

[0368] (b) combinations of hardware circuits and software, such as (as applicable): i. a combination of analog and / or digital hardware circuit(s) with software / firmware and ii. any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory or memories that work together to cause an apparatus, such as a mobile phone or server, to perform various functions and

[0369] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (for example, firmware) for operation, but the software may not be present when it is not needed for operation.

[0370] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the claim element, a baseband integrated circuit for a mobile device or a similar integrated circuit in a server, a cellular network device, or other computing or network device.

[0371] The blocks illustrated in the accompanying Figs may represent steps in a method and / or sections of code in the computer program 136. The illustration of a particular order to the blocks does not necessarily imply that there is a required or preferred order for the blocks and the order and arrangement of the block may be varied. Furthermore, it may be possible for some blocks to be omitted.

[0372] Where a structural feature has been described, it may be replaced by means for performing one or more of the functions of the structural feature whether that function or those functions are explicitly or implicitly described.

[0373] Where a structural feature has been described, it may be replaced by means for performing one or more of the functions of the structural feature whether that function or those functions are explicitly or implicitly described.

[0374] In examples, an apparatus 130 can comprise means for performing one or more methods, or at least part of one or more methods, as disclosed herein.

[0375] In examples, an apparatus 130 can be configured to perform one or more methods, or at least a part of one or more methods, as disclosed herein. The above-described examples find application as enabling components of: automotive systems; telecommunication systems; electonic systems including consumer electronic products; distributed computing systems; media systems for generating or rendering media content including audio, visual and audio visual content and mixed, mediated, virtual and / or augmented reality; personal systems including personal health systems or personal fitness systems; navigation systems; user interfaces also known as human machine interfaces; networks including cellular, non-cellular, and optical networks; ad-hoc networks; the internet; the internet of things; virtualized networks; and related software and services.

[0376] The apparatus can be provided in an electronic device, for example, a mobile terminal, according to an example of the present disclosure. It should be understood, however, that a mobile terminal is merely illustrative of an electronic device that would benefit from examples of implementations of the present disclosure and, therefore, should not be taken to limit the scope of the present disclosure to the same. While in certain implementation examples, the apparatus can be provided in a mobile terminal, other types of electronic devices, such as, but not limited to: mobile communication devices, hand portable electronic devices, wearable computing devices, portable digital assistants (PDAs), pagers, mobile computers, desktop computers, televisions, gaming devices, laptop computers, cameras, video recorders, GPS devices and other types of electronic systems, can readily employ examples of the present disclosure. Furthermore, devices can readily employ examples of the present disclosure regardless of their intent to provide mobility.

[0377] The term ‘comprise’ is used in this document with an inclusive not an exclusive meaning. That is any reference to X comprising Y indicates that X may comprise only one Y or may comprise more than one Y. If it is intended to use ‘comprise’ with an exclusive meaning then it will be made clear in the context by referring to ‘comprising only one...’ or by using ‘consisting.’

[0378] In this description, the wording ‘connect’, ‘couple’ and ‘communication’ and their derivatives mean operationally connected / coupled / in communication. It should be appreciated that any number or combination of intervening components can exist (including no intervening components), i.e., to provide direct or indirect connection / coupling / communication. Any such intervening components can include hardware and / or software components.

[0379] As used herein, the term "determine / determining" (and grammatical variants thereof) can include, not least: calculating, computing, processing, deriving, measuring, investigating, identifying, looking up (for example, looking up in a table, a database, or another data structure), ascertaining and the like. Also, "determining" can include receiving (for example, receiving information), accessing (for example, accessing data in a memory), obtaining and the like. Also, " determine / determining" can include resolving, selecting, choosing, establishing, and the like.

[0380] In this description, reference has been made to various examples. The description of features or functions in relation to an example indicates that those features or functions are present in that example. The use of the term ‘example’ or ‘for example’ or ‘can’ or ‘may’ in the text denotes, whether explicitly stated or not, that such features or functions are present in at least the described example, whether described as an example or not, and that they can be, but are not necessarily, present in some of or all other examples. Thus ‘example’, ‘for example’, ‘can’, or ‘may’ refers to a particular instance in a class of examples. A property of the instance can be a property of only that instance or a property of the class or a property of a sub-class of the class that includes some but not all the instances in the class. It is therefore implicitly disclosed that a feature described with reference to one example but not with reference to another example, can where possible be used in that other example as part of a working combination but does not necessarily have to be used in that other example.

[0381] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or” mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0382] Although examples have been described in the preceding paragraphs with reference to various examples, it should be appreciated that modifications to the examples given can be made without departing from the scope of the claims. Features described in the preceding description may be used in combinations other than the combinations explicitly described above.

[0383] Although functions have been described with reference to certain features, those functions may be performable by other features whether described or not.

[0384] The description of a feature, such as an apparatus or a component of an apparatus, configured to perform a function, or for performing a function, should additionally be considered to also disclose a method of performing that function. For example, description of an apparatus configured to perform one or more actions, or for performing one or more actions, should additionally be considered to disclose a method of performing those one or more actions with or without the apparatus.

[0385] Although features have been described with reference to certain examples, those features may also be present in other examples whether described or not.

[0386] The term ‘a’, ‘an’ or ‘the’ is used in this document with an inclusive not an exclusive meaning. That is any reference to X comprising a / an / the Y indicates that X may comprise only one Y or may comprise more than one Y unless the context clearly indicates the contrary. If it is intended to use ‘a’, ‘an’ or ‘the’ with an exclusive meaning then it will be made clear in the context. In some circumstances the use of ‘at least one’ or ‘one or more’ may be used to emphasis an inclusive meaning but the absence of these terms should not be taken to infer any exclusive meaning.

[0387] The presence of a feature (or combination of features) in a claim is a reference to that feature or (combination of features) itself and to features that achieve substantially the same technical effect (equivalent features). The equivalent features include, for example, features that are variants and achieve substantially the same result in substantially the same way. The equivalent features include, for example, features that perform substantially the same function, in substantially the same way to achieve substantially the same result.

[0388] In this description, reference has been made to various examples using adjectives or adjectival phrases to describe characteristics of the examples. Such a description of a characteristic in relation to an example indicates that the characteristic is present in some examples exactly as described and is present in other examples substantially as described.

[0389] The above description describes some examples of the present disclosure however those of ordinary skill in the art will be aware of possible alternative structures and method features which offer equivalent functionality to the specific examples of such structures and features described herein above and which for the sake of brevity and clarity have been omitted from the above description. Nonetheless, the above description should be read as implicitly including reference to such alternative structures and method features which provide equivalent functionality unless such alternative structures or method features are explicitly excluded in the above description of the examples of the present disclosure.

[0390] Whilst endeavoring in the foregoing specification to draw attention to those features believed to be of importance the Applicant may seek protection via the claims in respect of any patentable feature or combination of features hereinbefore referred to and / or shown in the drawings whether or not emphasis has been placed thereon.

Claims

CLAIMS1. An apparatus comprising means for: receiving, from a first access node, configuration information and a cryptographic encoding of at least the configuration information; storing the received configuration information in a received configuration information data structure in at least one secure storage environment and the cryptographic encoding of at least the configuration information in at least one secure storage environment; and causing transmission, based at least in part on a transition from a radio disconnected mode to a radio connected mode, of content of the received configuration information data structure and the stored cryptographic encoding of at least the configuration information towards a second access node to enable a verification of the stored configuration information.

2. An apparatus as claimed in claim 1, wherein the cryptographic encoding of at least the configuration information is generated based, at least in part, on the configuration information, and at least one identifier configured to uniquely identify the first access node.

3. An apparatus as claimed in claim 2, wherein the cryptographic encoding of at least the configuration information is generated using the configuration information and the at least one identifier configured to uniquely identify the first access node as inputs into at least one cryptographic algorithm.

4. An apparatus as claimed in claim 1 , wherein the cryptographic encoding of at least the configuration information is generated based, at least in part, on the configuration information, and at least one random number value.

5. An apparatus as claimed in any preceding claim, wherein the configuration information and the cryptographic encoding of at least the configuration information is receiving during a radio connected mode.

6. An apparatus as claimed in any preceding claim, wherein the configuration information comprises quality of experience measurement collection configuration information.

7. A method comprising: receiving, from a first access node, configuration information and a cryptographic encoding of at least the configuration information; storing the received configuration information in a received configuration information data structure in at least one secure storage environment and the cryptographic encoding of at least the configuration information in at least one secure storage environment; and causing transmission, based at least in part on a transition from a radio disconnected mode to a radio connected mode, of content of the received configuration information data structure and the stored cryptographic encoding of at least the configuration information towards a second access node to enable a verification of the stored configuration information.

8. A method as claimed in claim 7, wherein the cryptographic encoding of at least the configuration information is generated based, at least in part, on the configuration information, and at least one identifier configured to uniquely identify the first access node.

9. A computer program comprising instructions which, when executed by an apparatus, cause the apparatus at least to perform: receiving, from a first access node, configuration information and a cryptographic encoding of at least the configuration information; storing the received configuration information in a received configuration information data structure in at least one secure storage environment and the cryptographic encoding of at least the configuration information in at least one secure storage environment; and causing transmission, based at least in part on a transition from a radio disconnected mode to a radio connected mode, of content of the received configuration information data structure and the stored cryptographic encoding of at least the configuration information towards a second access node to enable a verification of the stored configuration information.

10. An apparatus comprising means for: receiving configuration information from at least one core node; generating a cryptographic encoding of at least the configuration information; causing transmission of at least the configuration information and the cryptographic encoding of at least the configuration information towards a terminal node;receiving verification configuration information and a cryptographic encoding of at least configuration information from a terminal node; and verifying the received verification configuration information based, at least in part, on the received cryptographic encoding of at least configuration information.

11. An apparatus as claimed in claim 10, wherein generating the cryptographic encoding of at least the configuration information comprises generating the cryptographic encoding based, at least in part, on the received configuration information, and at least one identifier configured to uniquely identify an access node.

12. An apparatus as claimed in claim 11, wherein generating the cryptographic encoding of at least the configuration information comprises using the received configuration information and the at least one identifier configured to uniquely identify the access node as inputs into at least one cryptographic algorithm.

13. An apparatus as claimed in any preceding claim, wherein the configuration information comprises quality of experience measurement collection configuration information.

14. An apparatus as claimed in any preceding claim, wherein the means are configured to cause transmission, towards at least one core node, of at least one of the following: the cryptographic encoding of at least the configuration information; or at least one identifier configured to uniquely identify an access node used in generating the cryptographic encoding of at least the configuration information.

15. An apparatus as claimed in any preceding claim, wherein verifying the received verification configuration information comprises generating a cryptographic encoding of at least the verification configuration information and comparing the cryptographic encoding of at least the verification configuration information and the received cryptographic encoding of at least configuration information.

16. An apparatus as claimed in claim 15, wherein the means are configured to receive at least one identifier configured to uniquely identify an access node for use in generating the cryptographic encoding of at least the verification configuration information.

17. An apparatus as claimed in any preceding claim, wherein verifying the received verification configuration information comprises receiving an expected cryptographic encoding of at least configuration information and comparing the received cryptographic encoding of at least configuration information and the received expected cryptographic encoding of at least configuration information.

18. An apparatus as claimed in any preceding claim, wherein verifying the received verification configuration information comprises causing transmission of the received verification configuration information and the received cryptographic encoding of at least configuration information for verification.

19. A computer program comprising instructions which, when executed by an apparatus, cause the apparatus at least to perform: receiving configuration information from at least one core node; generating a cryptographic encoding of at least the configuration information; causing transmission of at least the configuration information and the cryptographic encoding of at least the configuration information towards a terminal node; receiving verification configuration information and a cryptographic encoding of at least configuration information from a terminal node; and verifying the received verification configuration information based, at least in part, on the received cryptographic encoding of at least configuration information.

20. An apparatus comprising means for: causing transmission of configuration information towards at least one access node; receiving, from a requesting access node, a request for assistance in verification of verification configuration information; and causing transmission of information towards the requesting access node to enable verification of the verification configuration information.

21. An apparatus as claimed in claim 20, wherein the configuration information comprises quality of experience measurement collection configuration information.

22. An apparatus as claimed in claim 20 or 21, wherein causing transmission of information comprises causing transmission of at least one of the following: an expected cryptographic encoding of at least configuration information; or at least one identifier configured to uniquely identify an access node.

23. An apparatus as claimed in any of claims 20 to 22, wherein the means are configured to receive at least one of the following: a cryptographic encoding of at least configuration information; or at least one identifier configured to uniquely identify an access node used in generating a cryptographic encoding of at least configuration information.

24. A method comprising: causing transmission of configuration information towards at least one access node; receiving, from a requesting access node, a request for assistance in verification of verification configuration information; and causing transmission of information towards the requesting access node to enable verification of the verification configuration information.

25. A computer program comprising instructions which, when executed by an apparatus, cause the apparatus at least to perform: causing transmission of configuration information towards at least one access node; receiving, from a requesting access node, a request for assistance in verification of verification configuration information; and causing transmission of information towards the requesting access node to enable verification of the verification configuration information.