Ambient-IOT DOS and DDOS attack remediation
Cryptographic puzzles are used to authenticate service requests and verify evidence, addressing AloT DDOS attacks by enhancing network security and preventing spoofing and replay attacks in mobile communication systems.
Patent Information
- Application Number
- PCT/US2025/016544
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-23
- Filing Date
- 2025-02-20
- Publication Date
- 2025-08-28
AI Technical Summary
Existing mobile communication systems are vulnerable to ambient-internet-of-things (AloT) distributed denial of service (DDOS) attacks, which can compromise network security and integrity.
Implementing cryptographic puzzles, such as reverse encryption puzzles or one-way cryptographic hash function puzzles, to authenticate service requests and verify evidence, thereby preventing spoofing and replay attacks, and modulating the effort required to generate evidence through a puzzle strength parameter.
Enhances network security by effectively mitigating DDOS attacks, ensuring authentic service requests and preventing identity spoofing and evidence replay, while maintaining efficient network operations.
Smart Images

Figure US2025016544_28082025_PF_FP_ABST
Abstract
Description
AMBIENT-IOT DOS AND DDOS ATTACK REMEDIATIONCROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims the benefit of U.S. Provisional Patent Application No. 63 / 557,053, filed February 23, 2024, the contents of which are hereby incorporated by reference herein.BACKGROUND
[0002] Mobile communications using wireless communication continue to evolve. A fifth generation may be referred to as 5G. A previous (legacy) generation of mobile communication may be, for example, fourth generation (4G) long term evolution (LTE).SUMMARY
[0003] Systems, methods, and instrumentalities are described herein related to ambient-internet-of- things (AloT) distributed denial of service (DDOS) attack remediation. A network node may include a processor. The network node may be configured to receive a request for service message from a wireless transmit / receive unit (WTRU). The network node may generate a puzzle based on the request for service message. The network node may send a service message response to the WTRU. The service message response may include an indication of the puzzle. The network node may receive an evidence request message including an indication of evidence. The evidence may be associated with a solution to the puzzle. The network node may verify the solution to the puzzle based on the indication of the evidence. The network node may, based on the verification, process the request for service message.
[0004] One or more features may be disclosed herein. For example, the service message response may include an indication of a freshness parameter configured to prevent spoofing of a WTRU identity or to prevent a replay of the evidence by a second WTRU. The puzzle may be an expiring puzzle based on the freshness parameter. The network node may send the service message response based on a determination that a number of failed authentication attempts satisfies a threshold.
[0005] The network node may send the service message response based on a determination to remediate a DDOS attack. The puzzle may be at least one of a reverse encryption puzzle or a one-way cryptographic hash function puzzle. The indication of the evidence may include a solution to an encryptionreversing puzzle or a solution to a hash function puzzle. The puzzle may be a reverse encryption puzzle. The indication of the evidence may include plaintext associated with an encryption key. The solution may be verified based on a determination that a portion of the plaintext associated with the encryption key and a portion of the solution are the same. The puzzle may be a cryptographic hash function puzzle. The indication of the evidence may include a hash function input text associated with a hash function argument. The solution may be verified based on a determination that a portion of the hash function input text associated with the hash function argument and a portion of the solution are the same. The processor may select a puzzle strength parameter. The puzzle strength parameter may be configured to modulate a level of effort to be spent by the WTRU to generate the evidence. The puzzle may be generated based on the puzzle strength parameter. The puzzle strength parameter may be associated with an encryption key length or a portion of a cryptographic hash function argument.
[0006] A WTRU may include a processor. The WTRU may be configured to send a request for service message to a network node. The WTRU may receive a service message response from the network node. The service message response may include an indication of a puzzle. The WTRU may generate evidence based on the puzzle. The evidence may be associated with a solution to the puzzle. The WTRU may send an evidence request message to the network node. The evidence request message may include an indication of the evidence and / or include a request that the indication of the evidence is verified by the network node based on the solution to the puzzle. The WTRU may receive an authentication response including an indication that the request for service message is being processed.
[0007] One or more features may be described herein. The service message response may include an indication of a freshness parameter configured to prevent spoofing of a WTRU identity or to prevent a replay of the evidence by a second WTRU. The puzzle may be an expiring puzzle based on the freshness parameter. The puzzle may be at least one of a reverse encryption puzzle or a one-way cryptographic hash function puzzle. The indication of the evidence may include a solution to an encryption reversing puzzle or a solution to a hash function puzzle. The puzzle may be a reverse encryption puzzle. The indication of the evidence may include a portion of plaintext associated with an encryption key. A portion of the solution to the puzzle and / or the portion of the plaintext associated with the encryption key may be the same. The indication of the puzzle may be associated with an encryption key length or a portion of a cryptographic hash function argument.
[0008] Systems, methods, and instrumentalities are described herein related to AloT (D)DOS attack remediation, for example, through the implementation of a cryptographic puzzle when processing a service provision request.
[0009] A device (e.g., an AloT device) may (e.g., be configured to) perform one or more actions. The device may send a request for service. The device may receive a cryptographic puzzle based on the request for service. The device may generate evidence based on a solution to the cryptographic puzzle. The device may send the evidence.
[0010] An intermediate node (e.g., WTRU) may (e.g., be configured to) perform one or more actions. The intermediate node may receive a request for service. The intermediate node may generate a cryptographic puzzle based on the request for service. The intermediate node may send the puzzle (e.g., to the requesting entity). The intermediate node may receive evidence indicating a solution to the puzzle. The intermediate node may determine whether the evidence is verified. The intermediate node may, based on the determination of whether the evidence is verified, permit further processing of the request for service.
[0011] The puzzle may be one or more of an individual one-time puzzle or an expiring puzzle. The puzzle may comprise a freshness parameter configured to prevent spoofing of a device identity.BRIEF DESCRIPTION OF THE DRAWINGS
[0012] FIG. 1 A is a system diagram illustrating an example communications system in which one or more disclosed embodiments may be implemented.
[0013] FIG. 1 B is a system diagram illustrating an example wireless transmit / receive unit (WTRU) that may be used within the communications system illustrated in FIG. 1A according to an embodiment.
[0014] FIG. 1 C is a system diagram illustrating an example radio access network (RAN) and an example core network (ON) that may be used within the communications system illustrated in FIG. 1 A according to an embodiment.
[0015] FIG. 1 D is a system diagram illustrating a further example RAN and a further example ON that may be used within the communications system illustrated in FIG. 1A according to an embodiment.
[0016] FIG. 2 depicts an example active / sleep cycle of a WTRU.
[0017] FIG. 3 depicts a call flow and components for an example attack remediation.
[0018] FIG. 4 depicts an example configuration and assembly of a puzzle based on reversing encryption.
[0019] FIG. 5 depicts an example configuration and assembly of a cryptographic puzzle based on reversing a cryptographic hash function.
[0020] FIG. 6 depicts example operations for solving an encryption reversing puzzle.
[0021] FIG. 7 depicts example operations for solving a hash function reversing puzzle.
[0022] FIG. 8 depicts example operations for processing evidence received from a unauthenticated entity (UnEn).
[0023] FIG. 9 depicts an example of AloT (D)DOS remediation in the context of EAP bootstrapping through the control plane of a (e.g., cellular) network.
[0024] FIG. 10 depicts an example 5G AKA (D)DOS remediation operation.
[0025] FIGS. 11 A-11 B depicts an example 5G AKA (D)DOS remediation operation.
[0026] FIGS. 12A-B depicts an example (D)DOS remediation operation for the EAP-AKA authentication procedure.
[0027] FIGS. 13A-13E depict an example (D)DOS remediation for PC5 security establishment procedure for 5G ProSe WTRU-to-network relay communication over a control plane.
[0028] FIG. 14 depicts an example edge service provisioning request and response.DETAILED DESCRIPTION
[0029] FIG. 1 A is a diagram illustrating an example communications system 100 in which one or more disclosed embodiments may be implemented. The communications system 100 may be a multiple access system that provides content, such as voice, data, video, messaging, broadcast, etc., to multiple wireless users. The communications system 100 may enable multiple wireless users to access such content through the sharing of system resources, including wireless bandwidth. For example, the communications systems 100 may employ one or more channel access methods, such as code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), single-carrier FDMA (SC-FDMA), zero-tail unique-word DFT-Spread OFDM (ZT UW DTS-s OFDM), unique word OFDM (UW-OFDM), resource block-filtered OFDM, filter bank multicarrier (FBMC), and the like.
[0030] As shown in FIG. 1A, the communications system 100 may include wireless transmit / receive units (WTRUs) 102a, 102b, 102c, 102d, a RAN 104 / 113, a ON 106 / 115, a public switched telephone network (PSTN) 108, the Internet 110, and other networks 112, though it will be appreciated that the disclosed embodiments contemplate any number of WTRUs, base stations, networks, and / or network elements. Each of the WTRUs 102a, 102b, 102c, 102d may be any type of device configured to operate and / or communicate in a wireless environment. By way of example, the WTRUs 102a, 102b, 102c, 102d, any of which may be referred to as a “station” and / or a “STA”, may be configured to transmit and / or receive wireless signals and may include a user equipment (UE), a mobile station, a fixed or mobile subscriber unit, a subscription-based unit, a pager, a cellular telephone, a personal digital assistant (PDA), a smartphone, a laptop, a netbook, a personal computer, a wireless sensor, a hotspot or Mi-Fi device, an Internet of Things(loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. Any of the WTRUs 102a, 102b, 102c and 102d may be interchangeably referred to as a UE.
[0031] The communications systems 100 may also include a base station 114a and / or a base station 114b. Each of the base stations 114a, 114b may be any type of device configured to wirelessly interface with at least one of the WTRUs 102a, 102b, 102c, 102d to facilitate access to one or more communication networks, such as the CN 106 / 115, the I nternet 110, and / or the other networks 112. By way of example, the base stations 114a, 114b may be a base transceiver station (BTS), a Node-B, an eNode B, a Home Node B, a Home eNode B, a gNB, a NR NodeB, a site controller, an access point (AP), a wireless router, and the like. While the base stations 114a, 114b are each depicted as a single element, it will be appreciated that the base stations 114a, 114b may include any number of interconnected base stations and / or network elements.
[0032] The base station 114a may be part of the RAN 104 / 113, which may also include other base stations and / or network elements (not shown), such as a base station controller (BSC), a radio network controller (RNC), relay nodes, etc. The base station 114a and / or the base station 114b may be configured to transmit and / or receive wireless signals on one or more carrier frequencies, which may be referred to as a cell (not shown). These frequencies may be in licensed spectrum, unlicensed spectrum, or a combination of licensed and unlicensed spectrum. A cell may provide coverage for a wireless service to a specific geographical area that may be relatively fixed or that may change over time. The cell may further be divided into cell sectors. For example, the cell associated with the base station 114a may be divided into three sectors. Thus, in one embodiment, the base station 114a may include three transceivers, i.e. , one for each sector of the cell. In an embodiment, the base station 114a may employ multiple-input multiple output (MIMO) technology and may utilize multiple transceivers for each sector of the cell. For example, beamforming may be used to transmit and / or receive signals in desired spatial directions.
[0033] The base stations 114a, 114b may communicate with one or more of the WTRUs 102a, 102b, 102c, 102d over an air interface 116, which may be any suitable wireless communication link (e.g., radio frequency (RF), microwave, centimeter wave, micrometer wave, infrared (IR), ultraviolet (UV), visible light, etc.). The air interface 116 may be established using any suitable radio access technology (RAT).
[0034] More specifically, as noted above, the communications system 100 may be a multiple access system and may employ one or more channel access schemes, such as CDMA, TDMA, FDMA, OFDMA, SC-FDMA, and the like. For example, the base station 114a in the RAN 104 / 113 and the WTRUs 102a,102b, 102c may implement a radio technology such as Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (UTRA), which may establish the air interface 115 / 116 / 117 using wideband CDMA (WCDMA). WCDMA may include communication protocols such as High-Speed Packet Access (HSPA) and / or Evolved HSPA (HSPA+). HSPA may include High-Speed Downlink (DL) Packet Access (HSDPA) and / or High-Speed UL Packet Access (HSUPA).
[0035] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as Evolved UMTS Terrestrial Radio Access (E-UTRA), which may establish the air interface 116 using Long Term Evolution (LTE) and / or LTE-Advanced (LTE-A) and / or LTE-Advanced Pro (LTE-A Pro).
[0036] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as NR Radio Access , which may establish the air interface 116 using New Radio (NR).
[0037] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement multiple radio access technologies. For example, the base station 114a and the WTRUs 102a, 102b, 102c may implement LTE radio access and NR radio access together, for instance using dual connectivity (DC) principles. Thus, the air interface utilized by WTRUs 102a, 102b, 102c may be characterized by multiple types of radio access technologies and / or transmissions sent to / from multiple types of base stations (e.g., a eNB and a gNB).
[0038] In other embodiments, the base station 114a and the WTRUs 102a, 102b, 102c may implement radio technologies such as IEEE 802.11 (i.e., Wireless Fidelity (WiFi), IEEE 802.16 (i.e., Worldwide Interoperability for Microwave Access (WiMAX)), CDMA2000, CDMA2000 1X, CDMA2000 EV-DO, Interim Standard 2000 (IS-2000), Interim Standard 95 (IS-95), Interim Standard 856 (IS-856), Global System for Mobile communications (GSM), Enhanced Data rates for GSM Evolution (EDGE), GSM EDGE (GERAN), and the like.
[0039] The base station 114b in FIG. 1 A may be a wireless router, Home Node B, Home eNode B, or access point, for example, and may utilize any suitable RAT for facilitating wireless connectivity in a localized area, such as a place of business, a home, a vehicle, a campus, an industrial facility, an air corridor (e.g., for use by drones), a roadway, and the like. In one embodiment, the base station 114b and the WTRUs 102c, 102d may implement a radio technology such as IEEE 802.11 to establish a wireless local area network (WLAN). In an embodiment, the base station 114b and the WTRUs 102c, 102d may implement a radio technology such as IEEE 802.15 to establish a wireless personal area network (WPAN). In yet another embodiment, the base station 114b and the WTRUs 102c, 102d may utilize a cellular-based RAT (e.g., WCDMA, CDMA2000, GSM, LTE, LTE-A, LTE-A Pro, NR etc.) to establish a picocell orfemtocell. As shown in FIG. 1 A, the base station 114b may have a direct connection to the Internet 110. Thus, the base station 114b may not be required to access the Internet 110 via the CN 106 / 115.
[0040] The RAN 104 / 113 may be in communication with the CN 106 / 115, which may be any type of network configured to provide voice, data, applications, and / or voice over internet protocol (VoIP) services to one or more of the WTRUs 102a, 102b, 102c, 102d. The data may have varying quality of service (QoS) requirements, such as differing throughput requirements, latency requirements, error tolerance requirements, reliability requirements, data throughput requirements, mobility requirements, and the like. The CN 106 / 115 may provide call control, billing services, mobile location-based services, pre-paid calling, Internet connectivity, video distribution, etc., and / or perform high-level security functions, such as user authentication. Although not shown in FIG. 1A, it will be appreciated that the RAN 104 / 113 and / or the CN 106 / 115 may be in direct or indirect communication with other RANs that employ the same RAT as the RAN 104 / 113 or a different RAT. For example, in addition to being connected to the RAN 104 / 113, which may be utilizing a NR radio technology, the CN 106 / 115 may also be in communication with another RAN (not shown) employing a GSM, UMTS, CDMA 2000, WiMAX, E-UTRA, or WiFi radio technology.
[0041] The CN 106 / 115 may also serve as a gateway for the WTRUs 102a, 102b, 102c, 102d to access the PSTN 108, the Internet 110, and / or the other networks 112. The PSTN 108 may include circuit- switched telephone networks that provide plain old telephone service (POTS). The Internet 110 may include a global system of interconnected computer networks and devices that use common communication protocols, such as the transmission control protocol (TCP), user datagram protocol (UDP) and / or the internet protocol (IP) in the TCP / IP internet protocol suite. The networks 112 may include wired and / or wireless communications networks owned and / or operated by other service providers. For example, the networks 112 may include another CN connected to one or more RANs, which may employ the same RAT as the RAN 104 / 113 or a different RAT.
[0042] Some or all of the WTRUs 102a, 102b, 102c, 102d in the communications system 100 may include multi-mode capabilities (e.g., the WTRUs 102a, 102b, 102c, 102d may include multiple transceivers for communicating with different wireless networks over different wireless links). For example, the WTRU 102c shown in FIG. 1A may be configured to communicate with the base station 114a, which may employ a cellular-based radio technology, and with the base station 114b, which may employ an IEEE 802 radio technology.
[0043] FIG. 1 B is a system diagram illustrating an example WTRU 102. As shown in FIG. 1 B, the WTRU 102 may include a processor 118, a transceiver 120, a transmit / receive element 122, a speaker / microphone 124, a keypad 126, a display / touchpad 128, non-removable memory 130, removable memory 132, a power source 134, a global positioning system (GPS) chipset 136, and / or other peripherals138, among others. It will be appreciated that the WTRU 102 may include any sub-combination of the foregoing elements while remaining consistent with an embodiment.
[0044] The processor 118 may be a general purpose processor, a special purpose processor, a conventional processor, a digital signal processor (DSP), a plurality of microprocessors, one or more microprocessors in association with a DSP core, a controller, a microcontroller, Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs) circuits, any other type of integrated circuit (IC), a state machine, and the like. The processor 118 may perform signal coding, data processing, power control, input / output processing, and / or any other functionality that enables the WTRU 102 to operate in a wireless environment. The processor 118 may be coupled to the transceiver 120, which may be coupled to the transmit / receive element 122. While FIG. 1 B depicts the processor 118 and the transceiver 120 as separate components, it will be appreciated that the processor 118 and the transceiver 120 may be integrated together in an electronic package or chip.
[0045] The transmit / receive element 122 may be configured to transmit signals to, or receive signals from, a base station (e.g., the base station 114a) over the air interface 116. For example, in one embodiment, the transmit / receive element 122 may be an antenna configured to transmit and / or receive RF signals. In an embodiment, the transmit / receive element 122 may be an emitter / detector configured to transmit and / or receive IR, UV, or visible light signals, for example. In yet another embodiment, the transmit / receive element 122 may be configured to transmit and / or receive both RF and light signals. It will be appreciated that the transmit / receive element 122 may be configured to transmit and / or receive any combination of wireless signals.
[0046] Although the transmit / receive element 122 is depicted in FIG. 1 B as a single element, the WTRU 102 may include any number of transmit / receive elements 122. More specifically, the WTRU 102 may employ MIMO technology. Thus, in one embodiment, the WTRU 102 may include two or more transmit / receive elements 122 (e.g., multiple antennas) for transmitting and receiving wireless signals over the air interface 116.
[0047] The transceiver 120 may be configured to modulate the signals that are to be transmitted by the transmit / receive element 122 and to demodulate the signals that are received by the transmit / receive element 122. As noted above, the WTRU 102 may have multi-mode capabilities. Thus, the transceiver 120 may include multiple transceivers for enabling the WTRU 102 to communicate via multiple RATs, such as NR and I EEE 802.11 , for example.
[0048] The processor 118 of the WTRU 102 may be coupled to, and may receive user input data from, the speaker / microphone 124, the keypad 126, and / or the display / touchpad 128 (e.g., a liquid crystal display (LCD) display unit or organic light-emitting diode (OLED) display unit). The processor 118 may also outputuser data to the speaker / microphone 124, the keypad 126, and / or the display / touchpad 128. In addition, the processor 118 may access information from, and store data in, any type of suitable memory, such as the non-removable memory 130 and / or the removable memory 132. The non-removable memory 130 may include random-access memory (RAM), read-only memory (ROM), a hard disk, or any other type of memory storage device. The removable memory 132 may include a subscriber identity module (SIM) card, a memory stick, a secure digital (SD) memory card, and the like. In other embodiments, the processor 118 may access information from, and store data in, memory that is not physically located on the WTRU 102, such as on a server or a home computer (not shown).
[0049] The processor 118 may receive power from the power source 134, and may be configured to distribute and / or control the power to the other components in the WTRU 102. The power source 134 may be any suitable device for powering the WTRU 102. For example, the power source 134 may include one or more dry cell batteries (e.g., nickel-cadmium (NiCd), nickel-zinc (NiZn), nickel metal hydride (NiMH), lithium-ion (Li-ion), etc.), solar cells, fuel cells, and the like.
[0050] The processor 118 may also be coupled to the GPS chipset 136, which may be configured to provide location information (e.g., longitude and latitude) regarding the current location of the WTRU 102. In addition to, or in lieu of, the information from the GPS chipset 136, the WTRU 102 may receive location information over the air interface 116 from a base station (e.g., base stations 114a, 114b) and / or determine its location based on the timing of the signals being received from two or more nearby base stations. It will be appreciated that the WTRU 102 may acquire location information by way of any suitable locationdetermination method while remaining consistent with an embodiment.
[0051] The processor 118 may further be coupled to other peripherals 138, which may include one or more software and / or hardware modules that provide additional features, functionality and / or wired or wireless connectivity. For example, the peripherals 138 may include an accelerometer, an e-compass, a satellite transceiver, a digital camera (for photographs and / or video), a universal serial bus (USB) port, a vibration device, a television transceiver, a hands free headset, a Bluetooth® module, a frequency modulated (FM) radio unit, a digital music player, a media player, a video game player module, an Internet browser, a Virtual Reality and / or Augmented Reality (VR / AR) device, an activity tracker, and the like. The peripherals 138 may include one or more sensors, the sensors may be one or more of a gyroscope, an accelerometer, a hall effect sensor, a magnetometer, an orientation sensor, a proximity sensor, a temperature sensor, a time sensor; a geolocation sensor; an altimeter, a light sensor, a touch sensor, a magnetometer, a barometer, a gesture sensor, a biometric sensor, and / or a humidity sensor.
[0052] The WTRU 102 may include a full duplex radio for which transmission and reception of some or all of the signals (e.g., associated with particular subframes for both the UL (e.g., for transmission) anddownlink (e.g., for reception) may be concurrent and / or simultaneous. The full duplex radio may include an interference management unit to reduce and or substantially eliminate self-interference via either hardware (e.g., a choke) or signal processing via a processor (e.g., a separate processor (not shown) or via processor 118). In an embodiment, the WRTU 102 may include a half-duplex radio for which transmission and reception of some or all of the signals (e.g., associated with particular subframes for either the UL (e.g., for transmission) or the downlink (e.g., for reception)).
[0053] FIG. 1 C is a system diagram illustrating the RAN 104 and the CN 106 according to an embodiment. As noted above, the RAN 104 may employ an E-UTRA radio technology to communicate with the WTRUs 102a, 102b, 102c over the air interface 116. The RAN 104 may also be in communication with the CN 106.
[0054] The RAN 104 may include eNode-Bs 160a, 160b, 160c, though it will be appreciated that the RAN 104 may include any number of eNode-Bs while remaining consistent with an embodiment. The eNode-Bs 160a, 160b, 160c may each include one or more transceivers for communicating with the WTRUs 102a, 102b, 102c over the air interface 116. In one embodiment, the eNode-Bs 160a, 160b, 160c may implement MIMO technology. Thus, the eNode-B 160a, for example, may use multiple antennas to transmit wireless signals to, and / or receive wireless signals from, the WTRU 102a.
[0055] Each of the eNode-Bs 160a, 160b, 160c may be associated with a particular cell (not shown) and may be configured to handle radio resource management decisions, handover decisions, scheduling of users in the UL and / or DL, and the like. As shown in FIG. 1 C, the eNode-Bs 160a, 160b, 160c may communicate with one another over an X2 interface.
[0056] The CN 106 shown in FIG. 1 C may include a mobility management entity (MME) 162, a serving gateway (SGW) 164, and a packet data network (PDN) gateway (or PGW) 166. While each of the foregoing elements are depicted as part of the CN 106, it will be appreciated that any of these elements may be owned and / or operated by an entity other than the CN operator.
[0057] The MME 162 may be connected to each of the eNode-Bs 160a, 160b, 160c in the RAN 104 via an S1 interface and may serve as a control node. For example, the MME 162 may be responsible for authenticating users of the WTRUs 102a, 102b, 102c, bearer activation / deactivation, selecting a particular serving gateway during an initial attach of the WTRUs 102a, 102b, 102c, and the like. The MME 162 may provide a control plane function for switching between the RAN 104 and other RANs (not shown) that employ other radio technologies, such as GSM and / or WCDMA.
[0058] The SGW 164 may be connected to each of the eNode Bs 160a, 160b, 160c in the RAN 104 via the S1 interface. The SGW 164 may generally route and forward user data packets to / from the WTRUs 102a, 102b, 102c. The SGW 164 may perform other functions, such as anchoring user planes during inter-eNode B handovers, triggering paging when DL data is available for the WTRUs 102a, 102b, 102c, managing and storing contexts of the WTRUs 102a, 102b, 102c, and the like.
[0059] The SGW 164 may be connected to the PGW 166, which may provide the WTRUs 102a, 102b, 102c with access to packet-switched networks, such as the Internet 110, to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices.
[0060] The CN 106 may facilitate communications with other networks. For example, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to circuit-switched networks, such as the PSTN 108, to facilitate communications between the WTRUs 102a, 102b, 102c and traditional land-line communications devices. For example, the CN 106 may include, or may communicate with, an IP gateway (e.g., an IP multimedia subsystem (IMS) server) that serves as an interface between the CN 106 and the PSTN 108. In addition, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to the other networks 112, which may include other wired and / or wireless networks that are owned and / or operated by other service providers.
[0061] Although the WTRU is described in FIGS. 1 A-1 D as a wireless terminal, it is contemplated that in certain representative embodiments that such a terminal may use (e.g., temporarily or permanently) wired communication interfaces with the communication network.
[0062] In representative embodiments, the other network 112 may be a WLAN.
[0063] A WLAN in Infrastructure Basic Service Set (BSS) mode may have an Access Point (AP) for the BSS and one or more stations (STAs) associated with the AP. The AP may have an access or an interface to a Distribution System (DS) or another type of wired / wireless network that carries traffic in to and / or out of the BSS. Traffic to STAs that originates from outside the BSS may arrive through the AP and may be delivered to the STAs. Traffic originating from STAs to destinations outside the BSS may be sent to the AP to be delivered to respective destinations. Traffic between STAs within the BSS may be sent through the AP, for example, where the source STA may send traffic to the AP and the AP may deliver the traffic to the destination STA. The traffic between STAs within a BSS may be considered and / or referred to as peer-to- peer traffic. The peer-to-peer traffic may be sent between (e.g., directly between) the source and destination STAs with a direct link setup (DLS). In certain representative embodiments, the DLS may use an 802.11e DLS or an 802.11 z tunneled DLS (TDLS). A WLAN using an Independent BSS (I BSS) mode may not have an AP, and the STAs (e.g., all of the STAs) within or using the IBSS may communicate directly with each other. The IBSS mode of communication may sometimes be referred to herein as an “ad- hoc” mode of communication.
[0064] When using the 802.11 ac infrastructure mode of operation or a similar mode of operations, theAP may transmit a beacon on a fixed channel, such as a primary channel. The primary channel may be afixed width (e.g., 20 MHz wide bandwidth) or a dynamically set width via signaling. The primary channel may be the operating channel of the BSS and may be used by the STAs to establish a connection with the AP. In certain representative embodiments, Carrier Sense Multiple Access with Collision Avoidance (CSMA / CA) may be implemented, for example in in 802.11 systems. For CSMA / CA, the STAs (e.g., every STA), including the AP, may sense the primary channel. If the primary channel is sensed / detected and / or determined to be busy by a particular STA, the particular STA may back off. One STA (e.g., only one station) may transmit at any given time in a given BSS.
[0065] High Throughput (HT) STAs may use a 40 MHz wide channel for communication, for example, via a combination of the primary 20 MHz channel with an adjacent or nonadjacent 20 MHz channel to form a 40 MHz wide channel.
[0066] Very High Throughput (VHT) STAs may support 20MHz, 40 MHz, 80 MHz, and / or 160 MHz wide channels. The 40 MHz, and / or 80 MHz, channels may be formed by combining contiguous 20 MHz channels. A 160 MHz channel may be formed by combining 8 contiguous 20 MHz channels, or by combining two non-contiguous 80 MHz channels, which may be referred to as an 80+80 configuration. For the 80+80 configuration, the data, after channel encoding, may be passed through a segment parser that may divide the data into two streams. Inverse Fast Fourier Transform (IFFT) processing, and time domain processing, may be done on each stream separately. The streams may be mapped on to the two 80 MHz channels, and the data may be transmitted by a transmitting STA. At the receiver of the receiving STA, the above described operation for the 80+80 configuration may be reversed, and the combined data may be sent to the Medium Access Control (MAC).
[0067] Sub 1 GHz modes of operation are supported by 802.11af and 802.11 ah. The channel operating bandwidths, and carriers, are reduced in 802.11 af and 802.11 ah relative to those used in 802.11 n, and 802.11 ac. 802.11 af supports 5 MHz, 10 MHz and 20 MHz bandwidths in the TV White Space (TVWS) spectrum, and 802.11 ah supports 1 MHz, 2 MHz, 4 MHz, 8 MHz, and 16 MHz bandwidths using non- TVWS spectrum. According to a representative embodiment, 802.11 ah may support Meter Type Control / Machine-Type Communications, such as MTC devices in a macro coverage area. MTC devices may have certain capabilities, for example, limited capabilities including support for (e.g., only support for) certain and / or limited bandwidths. The MTC devices may include a battery with a battery life above a threshold (e.g., to maintain a very long battery life).
[0068] WLAN systems, which may support multiple channels, and channel bandwidths, such as 802.11 n, 802.11 ac, 802.11 af, and 802.11 ah, include a channel which may be designated as the primary channel. The primary channel may have a bandwidth equal to the largest common operating bandwidth supported by all STAs in the BSS. The bandwidth of the primary channel may be set and / or limited by aSTA, from among all STAs in operating in a BSS, which supports the smallest bandwidth operating mode. In the example of 802.11 ah, the primary channel may be 1 MHz wide for STAs (e.g., MTC type devices) that support (e.g., only support) a 1 MHz mode, even if the AP, and other STAs in the BSS support 2 MHz, 4 MHz, 8 MHz, 16 MHz, and / or other channel bandwidth operating modes. Carrier sensing and / or Network Allocation Vector (NAV) settings may depend on the status of the primary channel. If the primary channel is busy, for example, due to a STA (which supports only a 1 MHz operating mode), transmitting to the AP, the entire available frequency bands may be considered busy even though a majority of the frequency bands remains idle and may be available.
[0069] In the United States, the available frequency bands, which may be used by 802.11 ah, are from 902 MHz to 928 MHz. In Korea, the available frequency bands are from 917.5 MHz to 923.5 MHz. In Japan, the available frequency bands are from 916.5 MHz to 927.5 MHz. The total bandwidth available for 802.11 ah is 6 MHz to 26 MHz depending on the country code.
[0070] FIG. 1 D is a system diagram illustrating the RAN 113 and the CN 115 according to an embodiment. As noted above, the RAN 113 may employ an NR radio technology to communicate with the WTRUs 102a, 102b, 102c over the air interface 116. The RAN 113 may also be in communication with the CN 115.
[0071] The RAN 113 may include gNBs 180a, 180b, 180c, though it will be appreciated that the RAN 113 may include any number of gNBs while remaining consistent with an embodiment. The gNBs 180a, 180b, 180c may each include one or more transceivers for communicating with the WTRUs 102a, 102b, 102c over the air interface 116. In one embodiment, the gNBs 180a, 180b, 180c may implement MIMO technology. For example, gNBs 180a, 108b may utilize beamforming to transmit signals to and / or receive signals from the gNBs 180a, 180b, 180c. Thus, the gNB 180a, for example, may use multiple antennas to transmit wireless signals to, and / or receive wireless signals from, the WTRU 102a. In an embodiment, the gNBs 180a, 180b, 180c may implement carrier aggregation technology. For example, the gNB 180a may transmit multiple component carriers to the WTRU 102a (not shown). A subset of these component carriers may be on unlicensed spectrum while the remaining component carriers may be on licensed spectrum. In an embodiment, the gNBs 180a, 180b, 180c may implement Coordinated Multi-Point (CoMP) technology. For example, WTRU 102a may receive coordinated transmissions from gNB 180a and gNB 180b (and / or gNB 180c).
[0072] The WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c using transmissions associated with a scalable numerology. For example, the OFDM symbol spacing and / or OFDM subcarrier spacing may vary for different transmissions, different cells, and / or different portions of the wireless transmission spectrum. The WTRUs 102a, 102b, 102c may communicate with gNBs 180a,180b, 180c using subframe or transmission time intervals (TTIs) of various or scalable lengths (e.g., containing varying number of OFDM symbols and / or lasting varying lengths of absolute time).
[0073] The gNBs 180a, 180b, 180c may be configured to communicate with the WTRUs 102a, 102b, 102c in a standalone configuration and / or a non-standalone configuration. In the standalone configuration, WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c without also accessing other RANs (e.g., such as eNode-Bs 160a, 160b, 160c). In the standalone configuration, WTRUs 102a, 102b, 102c may utilize one or more of gNBs 180a, 180b, 180c as a mobility anchor point. In the standalone configuration, WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c using signals in an unlicensed band. In a non-standalone configuration WTRUs 102a, 102b, 102c may communicate with / connect to gNBs 180a, 180b, 180c while also communicating with / connecting to another RAN such as eNode-Bs 160a, 160b, 160c. For example, WTRUs 102a, 102b, 102c may implement DC principles to communicate with one or more gNBs 180a, 180b, 180c and one or more eNode-Bs 160a, 160b, 160c substantially simultaneously. In the non-standalone configuration, eNode-Bs 160a, 160b, 160c may serve as a mobility anchor for WTRUs 102a, 102b, 102c and gNBs 180a, 180b, 180c may provide additional coverage and / or throughput for servicing WTRUs 102a, 102b, 102c.
[0074] Each of the gNBs 180a, 180b, 180c may be associated with a particular cell (not shown) and may be configured to handle radio resource management decisions, handover decisions, scheduling of users in the UL and / or DL, support of network slicing, dual connectivity, interworking between NR and E- UTRA, routing of user plane data towards User Plane Function (UPF) 184a, 184b, routing of control plane information towards Access and Mobility Management Function (AMF) 182a, 182b and the like. As shown in FIG. 1 D, the gNBs 180a, 180b, 180c may communicate with one another over an Xn interface.
[0075] The CN 115 shown in FIG. 1 D may include at least one AMF 182a, 182b, at least one UPF 184a, 184b, at least one Session Management Function (SMF) 183a, 183b, and possibly a Data Network (DN) 185a, 185b. While each of the foregoing elements are depicted as part of the CN 115, it will be appreciated that any of these elements may be owned and / or operated by an entity other than the CN operator.
[0076] The AMF 182a, 182b may be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 113 via an N2 interface and may serve as a control node. For example, the AMF 182a, 182b may be responsible for authenticating users of the WTRUs 102a, 102b, 102c, support for network slicing (e.g., handling of different PDU sessions with different requirements), selecting a particular SMF 183a, 183b, management of the registration area, termination of NAS signaling, mobility management, and the like. Network slicing may be used by the AMF 182a, 182b in order to customize CN support for WTRUs 102a, 102b, 102c based on the types of services being utilized WTRUs 102a, 102b, 102c. For example, differentnetwork slices may be established for different use cases such as services relying on ultra-reliable low latency (URLLC) access, services relying on enhanced massive mobile broadband (eMBB) access, services for machine type communication (MTC) access, and / or the like. The AMF 162 may provide a control plane function for switching between the RAN 113 and other RANs (not shown) that employ other radio technologies, such as LTE, LTE-A, LTE-A Pro, and / or non-3GPP access technologies such as WiFi.
[0077] The SMF 183a, 183b may be connected to an AMF 182a, 182b in the CN 115 via an N11 interface. The SMF 183a, 183b may also be connected to a UPF 184a, 184b in the CN 115 via an N4 interface. The SMF 183a, 183b may select and control the UPF 184a, 184b and configure the routing of traffic through the UPF 184a, 184b. The SMF 183a, 183b may perform other functions, such as managing and allocating UE IP address, managing PDU sessions, controlling policy enforcement and QoS, providing downlink data notifications, and the like. A PDU session type may be IP-based, non-IP based, Ethernetbased, and the like.
[0078] The UPF 184a, 184b may be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 113 via an N3 interface, which may provide the WTRUs 102a, 102b, 102c with access to packet- switched networks, such as the Internet 110, to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices. The UPF 184, 184b may perform other functions, such as routing and forwarding packets, enforcing user plane policies, supporting multi-homed PDU sessions, handling user plane QoS, buffering downlink packets, providing mobility anchoring, and the like.
[0079] The CN 115 may facilitate communications with other networks. For example, the CN 115 may include, or may communicate with, an IP gateway (e.g., an IP multimedia subsystem (IMS) server) that serves as an interface between the CN 115 and the PSTN 108. In addition, the CN 115 may provide the WTRUs 102a, 102b, 102c with access to the other networks 112, which may include other wired and / or wireless networks that are owned and / or operated by other service providers. In one embodiment, the WTRUs 102a, 102b, 102c may be connected to a local Data Network (DN) 185a, 185b through the UPF 184a, 184b via the N3 interface to the UPF 184a, 184b and an N6 interface between the UPF 184a, 184b and the DN 185a, 185b.
[0080] In view of Figures 1 A-1 D, and the corresponding description of Figures 1 A-1 D, one or more, or all, of the functions described herein with regard to one or more of: WTRU 102a-d, Base Station 114a-b, eNode-B 160a-c, MME 162, SGW 164, PGW 166, gNB 180a-c, AMF 182a-b, UPF 184a-b, SMF 183a-b, DN 185a-b, and / or any other device(s) described herein, may be performed by one or more emulation devices (not shown). The emulation devices may be one or more devices configured to emulate one or more, or all, of the functions described herein. For example, the emulation devices may be used to test other devices and / or to simulate network and / or WTRU functions.
[0081] The emulation devices may be designed to implement one or more tests of other devices in a lab environment and / or in an operator network environment. For example, the one or more emulation devices may perform the one or more, or all, functions while being fully or partially implemented and / or deployed as part of a wired and / or wireless communication network in order to test other devices within the communication network. The one or more emulation devices may perform the one or more, or all, functions while being temporarily implemented / deployed as part of a wired and / or wireless communication network. The emulation device may be directly coupled to another device for purposes of testing and / or may performing testing using over-the-air wireless communications.
[0082] The one or more emulation devices may perform the one or more, including all, functions while not being implemented / deployed as part of a wired and / or wireless communication network. For example, the emulation devices may be utilized in a testing scenario in a testing laboratory and / or a non-deployed (e.g., testing) wired and / or wireless communication network in order to implement testing of one or more components. The one or more emulation devices may be test equipment. Direct RF coupling and / or wireless communications via RF circuitry (e.g., which may include one or more antennas) may be used by the emulation devices to transmit and / or receive data.
[0083] Ambient Internet of Things (AloT) may refer to one or more of the following device types: devices (e.g., device type A) that may have no energy storage, and transmission may be performed by a WTRU using backscattering alone; devices (e.g., device type B) that use backscattering (similar to device type A), but the device may perform power boosting by using some stored energy at the device (e.g., derived from some energy harvesting); or devices (e.g., device type C) that may perform autonomous transmission (e.g., without the need for backscattering) at periods of time when it may have stored sufficient energy from energy harvesting.
[0084] FIG. 2 depicts an example active / sleep cycle of a device (e.g., a WTRU). In examples incorporating device types B and / or C, the WTRU may operate in short active periods, for example, while performing energy harvesting during a sleep period, as shown in FIG. 2.
[0085] Service parameters (e.g., requirement) for ambient power-enabled loT may include (e.g., contain) one or more of the following security parameters (e.g., requirement): the system (e.g., a 5G system) may enable security protection suitable for AloT, without compromising overall security protection; the system (e.g., 5G system) may be able to provide a mechanism to protect the privacy of information (e.g., location and identity) exchanged during communication between an AloT device and the 5G network or an AloT capable WTRU; or based on subscription and operator policies, the 5G system may authorize an AloT capable WTRU to communicate with a specific AloT device or with a group of AloT devices.
[0086] Performance service parameters (e.g., requirements) may include communication service availability. For example, communication service availability may be 99% for some services. For example, communication service availability may reach 99.9% for some services.
[0087] Confidentiality, integrity, and / or availability may be a guiding model in information security. A comprehensive information security strategy may include policies and / or security controls that minimize threats to these three crucial components. Confidentiality may refer to protecting information from unauthorized access. Integrity may refer to data that may be trustworthy, complete, and / or may not have been altered or modified (e.g., accidentally altered or modified) by an unauthorized user. Availability may refer to data that is accessible (e.g., as / when needed). Availability (e.g., in the context of AloT) may be a part of AloT security.
[0088] Architecture, such as security architecture, may affect availability. Access control may protect system availability (e.g., in the case where the authentication and authorization of walk-ins may be done by a receptionist at the office gates) and / or may be a vector for potential attacks on availability, such as DOS and DDOS attacks (e.g., in the case where the authentication and authorization are performed or aided by workers in the office behind the receptionist). An oversized level of security may request (e.g., require) considerable resources and / or may decrease availability (e.g., making a system more difficult to use).
[0089] An unauthenticated entity (UnEn) may be, for example, a WTRU or an AloT device. A UnEn may be interchangeably referred to herein as a WTRU, an AloT, a device, an entity, and / or the like.
[0090] An edge network node (ENN) may be, for example, a base station or an access point. An ENN may be interchangeably referred to herein as a network node and / or the like.
[0091] Remediation and / or throttling of DOS / DDOS attacks may request (e.g., require) the attacking entities to be authenticated and / or throttled (e.g., based on their authorization status). This remediation (e.g., requiring authentication) may not be possible if / when attacking entities are engaged in attacks on network entities and / or links engaged in authentication and / or authorization. For example, because authentication processes may be used to mount DOS / DDOS attacks, throttling a (e.g., only) authenticated entity(ies) may not be a useful remediation for such DOS / DDOS attacks. For example, if a (e.g., only) ENN(s) is engaged in authentication and / or authorization, that node(s) may be a potential DOS / DDOS victim. If core network nodes are engaged in authentication and / or authorization, the attack may affect core network functionality and / or interfaces (e.g., UDM / UDR in 5GS) and may not be limited to the edge node(s).
[0092] Malicious AloT devices and / or other entities that spoof AloT devices may be perpetrators of attacks on AloT system availability. A lack of availability of the AloT authentication and authorization subsystem at the time of the AloT device readiness to communicate (e.g., enough energy reclaimed / saved,policy-driven scheduling) may exacerbate a DOS attack, for example, by further delaying the AloT device communication session. Remediation of such attacks on availability may be achieved by, for example, selecting system architecture where the ENN is (e.g., fully) responsible for authentication and authorization of entities, and / or implementing a throttling mechanism that may allow mitigation of availability attacks (e.g., DOS) while affecting the malicious / attacking entities (e.g., in more disproportional ways than legitimate entities).
[0093] Systems, methods, and instrumentalities are described herein related to ambient-internet-of- things (AloT) distributed denial of service (DDOS) attack remediation. A network node may include a processor. The network node may be configured to receive a request for service message from a wireless transmit / receive unit (WTRU). The network node may generate a puzzle based on the request for service message. The network node may send a service message response to the WTRU. The service message response may include an indication of the puzzle. The network node may receive an evidence request message including an indication of evidence. The evidence may be associated with a solution to the puzzle. The network node may verify the solution to the puzzle based on the indication of the evidence. The network node may, based on the verification, process the request for service message.
[0094] One or more features may be disclosed herein. For example, the service message response may include an indication of a freshness parameter configured to prevent spoofing of a WTRU identity or to prevent a replay of the evidence by a second WTRU. The puzzle may be an expiring puzzle based on the freshness parameter. The network node may send the service message response based on a determination that a number of failed authentication attempts satisfies a threshold.
[0095] The network node may send the service message response based on a determination to remediate a DDOS attack. The puzzle may be at least one of a reverse encryption puzzle or a one-way cryptographic hash function puzzle. The indication of the evidence may include a solution to an encryption reversing puzzle or a solution to a hash function puzzle. The puzzle may be a reverse encryption puzzle. The indication of the evidence may include plaintext associated with an encryption key. The solution may be verified based on a determination that a portion of the plaintext associated with the encryption key and a portion of the solution are the same. The puzzle may be a cryptographic hash function puzzle. The indication of the evidence may include a hash function input text associated with a hash function argument. The solution may be verified based on a determination that a portion of the hash function input text associated with the hash function argument and a portion of the solution are the same. The processor may select a puzzle strength parameter. The puzzle strength parameter may be configured to modulate a level of effort to be spent by the WTRU to generate the evidence. The puzzle may be generated based on thepuzzle strength parameter. The puzzle strength parameter may be associated with an encryption key length or a portion of a cryptographic hash function argument.
[0096] A WTRU may include a processor. The WTRU may be configured to send a request for service message to a network node. The WTRU may receive a service message response from the network node. The service message response may include an indication of a puzzle. The WTRU may generate evidence based on the puzzle. The evidence may be associated with a solution to the puzzle. The WTRU may send an evidence request message to the network node. The evidence request message may include an indication of the evidence and / or include a request that the indication of the evidence is verified by the network node based on the solution to the puzzle. The WTRU may receive an authentication response including an indication that the request for service message is being processed.
[0097] One or more features may be described herein. The service message response may include an indication of a freshness parameter configured to prevent spoofing of a WTRU identity or to prevent a replay of the evidence by a second WTRU. The puzzle may be an expiring puzzle based on the freshness parameter. The puzzle may be at least one of a reverse encryption puzzle or a one-way cryptographic hash function puzzle. The indication of the evidence may include a solution to an encryption reversing puzzle or a solution to a hash function puzzle. The puzzle may be a reverse encryption puzzle. The indication of the evidence may include a portion of plaintext associated with an encryption key. A portion of the solution to the puzzle and / or the portion of the plaintext associated with the encryption key may be the same. The indication of the puzzle may be associated with an encryption key length or a portion of a cryptographic hash function argument.
[0098] Feature(s) associated with remediation of UnEn DOS and / or DDOS and increasing availability of AloT and (e.g., other 5G) systems are provided herein.
[0099] AloT (D)DOS remediation (e.g., in the context of EAP bootstrapping through a control plane of a network (e.g., a cellular network)) may be achieved by performing one or more of the following.
[0100] An AloT device may send a request for service message to an intermediate node (e.g., a network node and / or the like). In examples, the intermediate node may be a node associated with, among other things, a satellite, a base station, a server, and / or the like. The request for service message may be used with EAP bootstrapping through the control plane of the (e.g., cellular) network.
[0101] The intermediate node may generate and / or obtain (e.g., compose) a puzzle (e.g., with freshness parameters). For example, the intermediate node may generate and / or obtain (e.g., compose) a puzzle with parameters that may prevent spoofing the AloT device identity and / or replay of evidence by other entities. This may be achieved by, for example, making an individual one-time puzzle and / or expiringpuzzles (e.g., by implementing a short time-to-live parameter). The intermediate node may send a (e.g., composed / selected) puzzle to the AloT device.
[0102] The AloT device may solve the puzzle. The AloT device may produce evidence (e.g., the evidence corresponding to the solved puzzle). The AloT device may send (e.g., forward) the evidence corresponding to the solved puzzle to the intermediate node.
[0103] The intermediate node may analyze and / or verify the evidence corresponding to the solved puzzle. The intermediate node may (e.g., upon successful verification) allow further processing of an authentication and / or authorization request. For example, processing of the authentication and / or authorization request may be conditioned upon successful verification by an intermediate node. For example, proactive screening of authentication / authorization request(s) may be performed by an ENN.
[0104] Feature(s) associated with authentication and / or key management (AKA), for example, for (D)DOS remediation, are provided herein. For example, (e.g., 5G) AKA (D)DOS remediation may include performing one or more of the following.
[0105] A security anchor function (SEAF) may (e.g., after receiving a registration request) determine to offer a puzzle, for example, to throttle a (D)DOS attack. The SEAF may generate and / or obtain (e.g., compose) a cryptographic puzzle. The SEAF may bind the cryptographic puzzle to the WTRU identity (e.g., SUCI or 5G-GUTI) and / or add a (e.g., optional) freshness parameter, for example, to prevent puzzle replay attacks. The SEAF may send a message (e.g., a NAS message) with an encapsulated puzzle.
[0106] The WTRU (e.g., a WTRU that sent a registration request) may solve the puzzle. The WTRU may produce evidence of the solved puzzle. The WTRU may send (e.g., forward) the evidence of the solved puzzle, for example, to the SEAF.
[0107] The SEAF may verify the puzzle solution evidence (e.g., verify the evidence of the solved puzzle) and / or its binding to the WTRU identity (e.g., SUPI or 5G-GUTI). The SEAF may (e.g., after a successful verification) issue an authentication service (e.g., a Nausf_UEAuthentication service), for example, by sending a message (e.g., a Nausf_UEAuthentication_Authenticate request) to an authentication server function (AUSF).
[0108] In examples, AKA (D)DOS remediation (e.g., 5G AKA (D)DOS remediation) may include performing one or more of the following.
[0109] A SEAF may (e.g., after receiving an authentication response message from an AUSF) generate and / or obtain (e.g., compose) a cryptographic puzzle. The SEAF may, for example, bind the cryptographic puzzle to a WTRU identity (e.g., SUCI or 5G-GUTI) and / or add a (e.g., optional) freshness parameter, for example, to prevent puzzle replay attacks. The SEAF may send a message (e.g., a NAS message) with an encapsulated puzzle.
[0110] The WTRU (e.g., a WTRU that sent a registration request) may solve the puzzle. The WTRU may produce evidence of the solved puzzle. The WTRU may forward the evidence of the solved puzzle to the SEAF.
[0111] The SEAF may verify the puzzle solution evidence (e.g., verify the evidence of the solved puzzle) and / or its binding to the WTRU identity (e.g., SUPI or 5G-GUTI). The SEAF may (e.g., after a successful verification) follow up with an authentication request message.
[0112] In examples, (D)DOS remediation for the EAP-AKA' authentication procedure may include one or more of the following.
[0113] A SEAF may (e.g., after receipt of an EAP-Request / AKA'-Challenge message from an AUSF) determine to offer a puzzle, for example, to throttle a (D)DOS attack. The SEAF may generate and / or obtain (e.g., compose) a cryptographic puzzle. The SEAF may, for example, bind the puzzle to the WTRU identity (e.g., SUCI or 5G-GUTI) and / or add a freshness parameter, for example, to prevent puzzle replay attacks.
[0114] The SEAF may transparently forward the EAP-Request / AKA'-Challenge message and generated and / or obtained (e.g., composed / selected) cryptographical puzzle to a WTRU (e.g., a WTRU that sent a registration request) in a message (e.g., NAS message, authentication request message). A management entity (ME) may forward the random challenge (RAND) and authentication token (AUTN) received in the EAP-Request / AKA'-Challenge message to a universal subscriber identity module (USIM).
[0115] The WTRU (e.g., a WTRU that sent a registration request) may solve the offered cryptographic puzzle (e.g., spending some of its computational resources). The WTRU may send the EAP- Response / AKA'-Challenge message, for example, including the evidence of the cryptographic puzzle solution, to the SEAF.
[0116] A subscriber identity de-concealing function (SIDF) may verify the evidence of the solved puzzle. The SIDF may verify the solved puzzle’s freshness and / or binding to the WTRU identity (e.g., SUCI or 5G- GUTI).
[0117] The SEAF may send (e.g., transparently forward) the EAP-Response / AKA'-Challenge message to the AUSF (e.g., in Nausf_UEAuthentication_Authenticate request message).
[0118] Feature(s) associated with (D)DOS remediation for a PC5 security establishment procedure for 5G ProSe WTRU-to-network relay communication over the control plane are provided herein. For example, (D)DOS remediation for a PC5 security establishment procedure may include one or more of the following.
[0119] A SEAF may (e.g., after the discovery of a 5G ProSe WTRU-to-network relay) determine to offer a puzzle, for example, to throttle a (D)DOS attack.
[0120] The SEAF may generate and / or obtain (e.g., compose) a cryptographic puzzle. The SEAF may bind the cryptographic puzzle to a WTRU identity (e.g., SUCI or 5G-GUTI) and / or add a freshness parameter, for example, to prevent puzzle replay attacks. The SEAF may send a message (e.g., NAS message) with the encapsulated puzzle.
[0121] A WTRU (e.g., a WTRU that sent a registration request) may solve the puzzle. The WTRU may produce evidence of the solved puzzle. The WTRU may send (e.g., forward) the evidence of the solved puzzle to the SEAF.
[0122] The SEAF may verify the puzzle solution evidence (e.g., verify the evidence of the solved puzzle) and / or its binding to the WTRU identity (e.g., SUPI or 5G-GUTI). The SEAF may send the relay key request to an AMF, for example, of the 5G ProSe WTRU-to-network relay.
[0123] Edge (D)DOS remediation may be performed. For example, edge (D)DOS remediation may include one or more of the following.
[0124] An edge configuration server (ECS)Zedge enabler server (EES) may (e.g., after receiving the service provisioning request) decide to offer a puzzle, for example, to throttle a (D)DOS attack.
[0125] The ECS / EES may generate and / or obtain (e.g., compose) a cryptographic puzzle. The ECS / EES may (e.g., optionally) bind the cryptographic puzzle to an edge enabler client (EEC) identity (e.g., ECSP ID or GPSI) and / or add a (e.g., optional) freshness parameter, for example, to prevent puzzle replay attacks. The ECS / EES may send a message with the encapsulated puzzle to an application client (AC) / EEC (e.g., the AC / EEC that sent the service provisioning request).
[0126] The AC / EEC may solve the puzzle. The AC / EEC may produce evidence of the solved puzzle and / or send (e.g., forward) the evidence of the solved puzzle to the ECS / EES.
[0127] The ECS / EES may verify the puzzle solution evidence (e.g., verify the evidence of the solved puzzle) and / or its binding to the EEC identity (e.g., ECSP ID or GPSI). The ECS may (e.g., upon successful verification) perform an authorization check to verify whether the EEC may have authorization to perform the operation.
[0128] Attach remediation (e.g., of a DOS and / or (D)DOS attack) may include one or more of the following. An UnEn (e.g., an unauthenticated WTRU and / or an unauthenticated device) may send an authentication request to an ENN. The ENN may determine an appropriate task (e.g., a puzzle). The ENN may generate and / or obtain (e.g., compose / generate) an assigned task and may (e.g., optionally) bind the assigned task to an identity freshness parameter. The ENN may forward the assigned task to the UnEn. The UnEn may complete the assigned task (e.g., puzzle) and may forward evidence associated with completing the assigned task (e.g., the result) to the ENN. The ENN may compare the received result with the expected result. The ENN may (e.g., if the comparison is successful, such as if a portion of the receivedresult matches a portion of the expected result) forward the authentication request from the UnEn to the authentication function.
[0129] FIG. 3 depicts a call flow and components of an example attack remediation. As shown in FIG. 3 at 1, an UnEn (e.g., a device, a WTRU, and / or the like) may issue an authentication request to an ENN (e.g., a network node).
[0130] At 2, the ENN may determine to use a puzzle to remedy a potential (D)DOS attack. The determination to remedy a potential DDOS attack may be based on a request from a core network node (e.g., a network node). For example, a core network node may indicate to the ENN that a potential DDOS attack may be underway. The core network node may make this determination after observing a relatively high number of failed authentication attempts (e.g., a network node may determine that a DDOS attack is occurring based on a number of failed authentication attempts satisfying a threshold).
[0131] At 3, the ENN may generate and / or obtain (e.g., compose) a puzzle and / or (e.g., optionally) bind the puzzle to an identity, for example, the UnEn identity.
[0132] At 4, the ENN may reply to the UnEn with the puzzle (e.g., from 3).
[0133] At 5, the UnEn may solve the puzzle (e.g., received at 4). The UnEn may obtain the evidence(e.g., optionally) bound to the UnEn identity.
[0134] At 6, the UnEn may issue an authentication request to the ENN, for example, including (e.g., containing) the evidence of the solved puzzle (e.g., which may optionally be bound to, for example, the UnEn identity).
[0135] At 7, the ENN may verify that the received evidence corresponds to the puzzle (e.g., from 4, that may be bound to the UnEn identity).
[0136] At 8, the ENN may, for example, upon the successful verification at 7, send (e.g., forward) the authentication request to the authentication function.
[0137] A parameter may (e.g., additionally) be introduced. For example, the UnEn (e.g., WTRU, a device, and / or the like) and the serving network (e.g., ENN) may share a common value as a preprovisioned parameter or a parameter known during subscription, and / or the like.
[0138] The additional parameter may vary, for example, per SUPI or group. The parameter may be used to generate and / or obtain (e.g., compose) the puzzle and / or solve the puzzle. The edge node may (e.g., by incorporating an additional parameter) develop (e.g., more) variability in puzzles. For example, the incorporation of an additional parameter may make it more difficult to solve the puzzle by a UnEn (e.g., a malicious entity such as a WTRU).
[0139] Feature(s) associated with puzzle(s) (e.g., cryptographic puzzles), corresponding elements or parameters of puzzle(s), different exemplary types of puzzles, and / or exemplary operations of puzzle composition(s) are provided herein.
[0140] A puzzle may be a (e.g., any) cryptographic primitive (e.g., encryption, hash function, and / or the like) that may request (e.g., require) an (e.g., brute-force) attack to reverse. Puzzles may include one or more of: reversing of encryption or reversing of a one-way cryptographic hash function.
[0141] Reversing of encryption may be augmented (e.g., increased or decreased difficulty) by one or more of the following: finding plaintext or partial plaintext (e.g., a portion of plaintext) with no encryption key knowledge, partial key knowledge, and / or a reduced key size. In examples, increasing or decreasing the key size and / or other parameters may modulate the strength of the puzzle and / or the amount of work / effort that an entity (e.g., a WTRU) may have to spend to solve the puzzle (e.g., via a selected puzzle strength parameter).
[0142] Processor productivity may have an outsized effect on the time needed to reverse encryption. Puzzle parameters may include a key length (e.g., 128 for AES-128). In examples, a puzzle parameter may include a known key length (e.g., 120), leaving a portion of the key length (e.g., 8 bits) for brute-force attack. In examples, a puzzle parameter may include ciphertext. Cleartext corresponding to the ciphertext may be the puzzle evidence obtained as a result of a brute-force attack.
[0143] FIG. 4 depicts an example of the configuration and assembly of a cryptographic puzzle based on reversing encryption. The example procedure of FIG. 4 may represent generating and / or obtaining (e.g., composing) a puzzle (e.g., at 3 of FIG. 3).
[0144] FIG. 4 illustrates an example procedure for a configuration and / or assembly of a cryptographic puzzle (e.g., that may be triggered by the ENN). The procedure may be triggered if / when the ENN receives an authentication request. The ENN may determine that it may use a puzzle to remedy a (e.g., potential) DDOS attack. The ENN may trigger this procedure (e.g., determining to use a puzzle to remedy a potential DDOS attack) so that it may obtain a puzzle to send to the UnEn.
[0145] As shown in FIG. 4 at 1, a UnEn identity may be (e.g., randomly) selected, pre-provisioned, and / or received in an authentication request.
[0146] At 2, an anti-replay parameter (e.g., a time-stamp or a sequence number) may be selected.
[0147] At 3, a constant value character string may be selected, for example, to aid in the selection of the correct key during the brute-force reversing of encryption.
[0148] At 4, an encryption key of the strength (e.g., full strength) corresponding to the encryption function may be selected (e.g., randomly or pre-provisioned).
[0149] At 5, a hash function may be generated and / or obtained (e.g., implemented). The hash function may bind the UnEn identity, anti-replay parameter, and / or constant value character string, for example, by encrypting one or more together. For example, an output from 5 may be HASH(UnEn ID || Anti Replay par || Constant string). If a hash function is not generated and / or obtained (e.g., implemented), the output of 5 may be represented by one or more (e.g., a concatenation of inputs from) of 1-4, for example, as in UnEn ID || Anti Replay par || Constant string.
[0150] At 6, a cryptographic encryption function may produce a puzzle for 9. The cryptographic encryption function may be (e.g., optionally) used to protect privacy, confidentiality, and / or replay of the evidence for verification. It may protect the arguments obtained at 1-4 from disclosure to an untrusted UnEn.
[0151] At 7, the result of 5 may be retained (e.g., stored) for verification of the evidence.
[0152] At 8, an incomplete encryption key, for example, based on the value obtained from 4, may be selected. For example, if the full-strength key from 4 is 128 bits long, the key selected at 8 may be of length / strength that is less than 128 bits long. The resulting length of 1-127 bits may allow for modulation of the puzzle strength and / or efforts needed to reverse the encryption. In examples, a portion of the key may be sent to the UnEn based on a selected puzzle strength and / or determined effort to generate the evidence (e.g., via a puzzle strength parameter).
[0153] At 9, the puzzle may be assembled. For example, the puzzle may be assembled by concatenating the encrypted text, the incomplete encryption key from 8, and / or the optional constant from 3.
[0154] At 10, the assembled puzzle may be ready for solving by the UnEn. The assembled puzzle may comprise (e.g., include) the encrypted text, the incomplete encryption key from 8, a character string (e.g., known crypto text - optional element) from 3, and / or (e.g., optionally) a UnEn identity from 1 .
[0155] Reversing of a one-way cryptographic hash function may be augmented (e.g., increased or decreased difficulty). Finding an input argument with a partial input hash function argument knowledge may be described herein. In examples, increasing and / or decreasing the proportion between known and unknown portions of the hash function input may modulate the strength of the puzzle and / or the amount of work / effort that an entity (e.g., a WTRU) may have to spend to solve it (e.g., via a puzzle strength parameter).
[0156] RAM productivity may have an outsized effect on the time needed to reverse the hash function.
[0157] A partially known argument to the cryptographic hash function may be an input parameter. For example, when using a SHA-256 cryptographic hash, the input string to the hash may have a total length of N and a known input length of N-m. The hash output may be provided as an input parameter (e.g., one ofthe input parameters, such as a stated length of 256 for SHA-256). The puzzle may include (e.g., be comprised of) the m-bits of the input to the hash function that are not known. The effort may be needed (e.g., a level of effort may be determined by the network node) to use a brute-force attack and / or discover the unknown m-bits of input so that output = HASH-256 (e.g., a known input || unknown input). The unknown input (e.g., of the full length of the input) may be the evidence.
[0158] FIG. 5 depicts an example of the configuration and / or assembly of a cryptographic puzzle based on reversing a cryptographic hash function. The example operations of FIG. 5 may represent generating and / or obtaining (e.g., composing) a puzzle (e.g., FIG. 5 may include one or more examples associated with FIG. 3 at 3).
[0159] As shown in FIG. 5 at 1, a UnEn identity may be randomly selected or pre-provisioned.
[0160] At 2, an anti-replay parameter (e.g., a time-stamp or sequence number) may be selected (e.g., the network may select an anti-replay parameter).
[0161] At 3, a hash function may be implemented. The hash function may bind the UnEn identity and anti-replay parameter by hashing them together. For example, the output from 3 may be HASH(UnEn ID || Anti Replay par).
[0162] At 4, a cryptographic hash function (e.g., another cryptographic hash function) may be (e.g., optionally) used to protect privacy, confidentiality, and / or replay of the evidence for verification. The cryptographic hash function may protect the arguments obtained in 1 and / or 2 from disclosure, for example, to an untrusted UnEn.
[0163] At 5, the expected evidence value may be saved (e.g., stored). If 4 is not implemented, the output of 3 may be used as expected evidence (e.g., a portion of the output of 3 may be used as expected evidence).
[0164] At 6, a n-bit value and / or replacement character S may be selected.
[0165] At 7, n (e.g., leading, trailing, or random) bits of the output with the selected character S (e.g., from 6) may be replaced.
[0166] At 8, the puzzle may be assembled to be solved by the UnEn. The puzzle output may include (e.g., comprise) the output of 7, (e.g., optionally) the selected S character, and / or the UnEn identity from 1 .
[0167] One or more operations used for puzzle solving and associated processes, including (e.g., anticipated) methods, operations, inputs, and / or outputs, may be described herein.
[0168] A brute-force attack may be used to solve a puzzle(s).
[0169] An encryption reversing puzzle may be solved, for example, by performing one or more of the following (e.g., a device may solve an encryption reversing puzzle).
[0170] Solving an encryption reversal puzzle may be based on the brute-force operation and / or may include (e.g., comprise) finding plaintext and / or partial plaintext with no encryption key knowledge, partial key knowledge, and / or reduced key size.
[0171] Processor productivity (e.g., a device’s processing capacity) may have an effect (e.g., an outsized effect) on the time / effort needed to reverse encryption.
[0172] The procedure of solving an encryption reversal puzzle(s) may be built around going through one or more existing permutations of the encryption key (e.g., the whole encryption key), for example, while knowing the partial encryption key.
[0173] FIG. 6 depicts an example operation for solving an encryption reversing puzzle.
[0174] As shown in FIG. 6 at 1, the operation may be started (e.g., a device may begin to solve an encryption reversing puzzle).
[0175] At 2, the UnEn may receive the puzzle and / or corresponding parameters, for example from the ENN. For example, the puzzle and / or the parameters may correspond to what was generated in FIG. 4 at 10 (e.g., the puzzle and / or the parameters may be the puzzle output as described with reference to FIG. 10 at 4). The UnEn receiving the puzzle may correspond to Figure 3 at 4 (e.g., a device may receive a puzzle as described with reference to FIG 3 at 4).
[0176] At 3, the UnEn may select an initial value (e.g., the starting value of the unknown part of the encryption key). The UnEn may use the initial value, for example, together with the known part of the key.
[0177] At 4, the UnEn may execute the encryption function.
[0178] At 5, the UnEn may check if the encryption may be brute-forced (e.g., if the brute-forced cleartext includes (e.g., contains) the optional known cleartext corresponding to the input in FIG. 4 at 3).
[0179] At 6, if the encryption is not brute-forced, the UnEn may increment the unknown part of the key and / or may use that part together with the known part to try to brute-force the encryption again at 4.
[0180] At 7, if the encryption is be brute-forced, the evidence may include (e.g., be comprised of) the solved (i.e., brute-forced) encrypted text. The UnEn may send the evidence to the ENN. Sending the evidence may correspond to FIG. 3 at 6.
[0181] At 8, the operations may end.
[0182] Solving a one-way cryptographic hash function (e.g., SHA-256) reversing puzzle may be based on the brute-force operation and / or may include (e.g., comprise) finding the complete hash function input text with a (e.g., only) partial input hash function argument knowledge. In examples, solving the one-way cryptographic hash function reversing puzzle may include finding a portion of the hash function input text based on a partial input hash function argument knowledge. Increasing / decreasing the proportion betweenknown and unknown portions of the hash function input may modulate the strength of the puzzle and the amount of work / effort that an entity (e.g., a WTRU) may have to spend to solve it (e.g., via a puzzle strength parameter).
[0183] RAM productivity may have an effect (e.g., an outsized effect) on the time needed to reverse the hash function (e.g., to solve the one-way cryptographic hash function).
[0184] The partially known argument to the cryptographic hash function may be the input parameter. For example, when using SHA-256 cryptographic hash, the input string to the hash may include (e.g., have) a total length of N and a known input length of N-m. The hash output may be provided as an input parameter (e.g., one of the input parameters, such as a stated length of 256 for SHA-256). The puzzle may include (e.g., comprise) the m-bits of the input to the hash function that is not known. A brute-force attack may be requested to solve for (e.g., need to discover) the unknown m-bits of input, so that output = HASH-256 (known input || unknown input). Evidence produced in the process of solving the puzzle may include (e.g., comprise) the full length of the hash input.
[0185] FIG. 7 depicts example operations for solving a hash function reversing puzzle.
[0186] As shown in FIG. 6 at 1, the method may be started.
[0187] At 2, the UnEn may receive the puzzle and / or corresponding parameters, for example, from the ENN. For example, the puzzle and / or the parameters may correspond to what was generated in FIG. 5 at 8 (e.g., the puzzle and / or the parameters may be described with reference to FIG. 5 at 8). The UnEn receiving the puzzle may correspond to Figure 3 at 4.
[0188] At 3, the UnEn may select the initial value (e.g., the starting value of the unknown part of the hash input). The UnEn may use the initial value together with the known part of the hash input.
[0189] At 4, the UnEn may execute the hash function.
[0190] At 5, the UnEn may check if the hash may be brute-forced (e.g., if the hash output corresponds to the whole hash input and / or to the portion of the hash input to be solved).
[0191] At 6, if the hash is not brute-forced, the UnEn may increment the unknown part of the hash input and / or may use that part together with the known part to try to brute-force the hash again at 4.
[0192] At 7, if the hash is brute-forced, the evidence may include (e.g., comprise) the solved (e.g., brute- forced) complete hash input text (e.g., or the portion of the solved input text). The UnEn may send the evidence to the ENN. Sending the evidence may correspond to FIG. 3 at 6.
[0193] At 8, the operations may end.
[0194] An ENN may process evidence received from a UnEn. A UnEn may solve the puzzle and / or recover the evidence (e.g., as shown in FIGS. 6 and 7). If the evidence (e.g., recovered cleartext) wasbound with the UnEn identity and / or the replay prevention parameter (e.g., see FIGS. 4 and 5), it may (e.g., still) be bound to the UnEn identity and may be replay-resistant (e.g., another entity may not present the evidence and / or the evidence may not be replayed by the same UnEn or a different UnEn).
[0195] FIG. 8 depicts example operations for processing evidence received from a UnEn (e.g., by an ENN). An ENN may process the evidence parameter received from the UnEn (e.g., corresponding to FIG. 3 at 7).
[0196] As shown in FIG. 8, at 1 the operations may be started.
[0197] At 2, the ENN may receive evidence from UnEn (e.g., FIG. 3, at 6).
[0198] At 3, the ENN may recall saved expected evidence (e.g., FIG. 4 at 7 or FIG. 5 at 5).
[0199] At 4, the ENN may compare the received evidence with the expected evidence. If the comparison is successful (e.g., a portion of the received evidence matches a portion of the expected evidence), theENN may proceed to 5. The violation of the UnEn binding and / or replay protection may lead to the evidence submitted by the UnEn being not equal to the expected evidence (e.g., and / or the UnEn being denied further processing of the UnEn authentication request).
[0200] At 5, the ENN may allow further processing of the UnEn authentication request.
[0201] At 6, exception processing may be performed, for example, if the evidence is not equal to the expected evidence. Exception processing may include sending an additional message to the UnEn or a silent drop of the authentication request (e.g., ending FIG. 3 at 6).
[0202] At 7, the operations may end.
[0203] An ENN (e.g., a network node) may perform one or more of the following actions.
[0204] The ENN may receive an authentication request from a UnEn (e.g., as described with reference to FIG. 3 at 1). The request may include the identity of the UnEn.
[0205] The ENN may determine to perform a procedure to throttle and / or mitigate, a (D)DOS attack (e.g., as described with reference to FIG. 3 at 2). The determination may be based on a request from a core network node.
[0206] The ENN may determine a puzzle (e.g., as described with reference to FIG. 3 at 2, FIG. 4, or FIG. 5). The puzzle may include encrypted text, an incomplete encryption key, and / or a character string.
[0207] The ENN may send the puzzle to a UnEn (e.g., as described with reference to FIG. 3 at 4).
[0208] The ENN may receive a second authentication request from the UnEn (e.g., as described with reference to FIG. 3 at 6). The second authentication request may include the evidence.
[0209] The ENN may, based on the evidence of solving the puzzle correctly, determine to send the second authentication request to an authentication function (e.g., as described with reference to FIG. 3 at 7, 8).
[0210] A UnEn may perform one or more of the following actions.
[0211] The UnEn may send an authentication request to a network (e.g., as described with reference to FIG. 3 at 1). The request may include the identity of the UnEn.
[0212] The UnEn may receive a puzzle from the network (e.g., as described with reference to FIG. 3 at 4). The puzzle may include encrypted text, an incomplete encryption key, and / or a character string.
[0213] The UnEn may obtain evidence of solving the puzzle (e.g., as described with reference to FIG. 3 at 5 and / or FIG. 5).
[0214] The UnEn may send a second authentication request to a network (e.g., as described with reference to FIG. 3 at 6). The second authentication request may include the evidence.
[0215] AloT (D)DOS remediation in the context of EAP bootstrapping through the control plane of a (e.g., cellular) network may be described herein. For example, (D)DOS remediation in the context of EAP bootstrapping may be performed through an intermediate node.
[0216] (D)DOS protection may be applied to an AloT device interacting with an intermediate node (for example, a WTRU or RAN). FIG. 9 depicts an example of AloT (D)DOS remediation in the context of EAP bootstrapping through the control plane of a (e.g., cellular) network.
[0217] As shown in FIG. 9 at 1, an AloT device may send a request for service message to the intermediate node (e.g., in the context of EAP bootstrapping through the control plane of the cellular network).
[0218] At 2, the intermediate node may determine to offer a puzzle (e.g., to the AloT device) to remediate a DOS / DDOS attack.
[0219] At 3, the intermediate node may generate and / or obtain (e.g., compose) a puzzle (e.g., with a freshness parameter that may prevent spoofing the AloT device identity and / or replay of evidence by other entities). This may be achieved by (e.g., spoofing may be prevented and / or replaying evidence may be prevented), for example, by making an individual one-time puzzle and / or an expiring puzzle(s) (e.g., by a short time-to-live parameter). In examples, a network node may generate a puzzle based on the WTRU identity and / or based on an expiring time period.
[0220] At 4, the intermediate node may send the selected puzzle to the AloT device.
[0221] At 5, the AloT device may solve the puzzle and produce the evidence.
[0222] At 6, the AloT device may send (e.g., forward) the evidence corresponding to the solved puzzle to the intermediate node.
[0223] At 7, the intermediate node may analyze and verify the evidence corresponding to the solved puzzle. The intermediate node may (e.g., upon successful verification) allow proceeding to 8.
[0224] At 8-13, which may correspond to FIG. 4 at 1-6, including the EAP bootstrapping through the control plane of the (e.g., cellular) network.
[0225] 5G AKA (D)DOS remediation may be performed (e.g., based on the use of cryptographic puzzles for the initiation of an authentication procedure and / or selection of the authentication method).
[0226] FIG. 10 depicts an example of 5G AKA (D)DOS remediation operations.
[0227] As shown in FIG. 10 at 1 , a WTRU (e.g., a UnEn) may initiate a registration request (e.g., to a SEAF), for example, using SUCI or 5G-GUTI in the registration request.
[0228] At 2, the SEAF may determine to offer (e.g., send) a puzzle (e.g., to the WTRU) to throttle a (D)DOS attack.
[0229] At 3, the SEAF may generate and / or obtain (e.g., compose) a cryptographic puzzle. The SEAF may, for example, bind the cryptographic puzzle to the WTRU identity (e.g., via SUCI or 5G-GUTI) and / or add a freshness parameter to prevent puzzle replay attacks.
[0230] At 4, the SEAF may send a NAS message with an encapsulated puzzle.
[0231] At 5, the WTRU may solve the puzzle and / or produce evidence of the solved puzzle.
[0232] At 6, the WTRU may send (e.g., forward) the evidence of the solved puzzle to the SEAF.
[0233] At 7, the SEAF may verify the puzzle solution evidence (e.g., verify the evidence of the solved puzzle) and / or its binding to the WTRU identity (e.g., SUPI or 5G-GUTI).
[0234] At 8, after a successful verification in 7, the SEAF may (e.g., when the SEAF wishes to initiate an authentication) issue an authentication service (e.g., the NausfJJEAuthentication service) by sending an authentication request (e.g., Nausf_UEAuthentication_Authenticate request message) to the AUSF. SUCI may be included if the SEAF is not be aware of SUPI.
[0235] At 9, a Nudm_UEAuthentication_Get request may be sent from the AUSF to a UDM.
[0236] At 10, the UDM (e.g., upon reception of the Nudm_UEAuthentication_Get Request) may invoke SIDF if a n is received. SIDF may de-conceal SUCI to gain SUPI before the UDM may process the request. The UDM and / or ARPF may choose the authentication method, for example, based on SUPI.
[0237] 5G AKA (D)DOS remediation may include one or more of the following.
[0238] FIG. 11 A-11 B depict an example of 5G AKA (D)DOS remediation operations.
[0239] As shown in FIG. 11A at 1-5, an authentication procedure (e.g., for 5G AKA) may be performed.
[0240] At 6, the SEAF may determine to offer a puzzle to throttle a (D)DOS attack.
[0241] At 7, the SEAF may generate and / or obtain (e.g., compose) a cryptographic puzzle. The SEAF may bind the cryptographic puzzle to a WTRU identity (e.g., SUCI or 5G-GUTI) and / or add a freshness parameter, for example, to prevent puzzle replay attacks.
[0242] At 8, the SEAF may send a message (e.g., a NAS message) with a puzzle (e.g., an encapsulated puzzle) to the WTRU.
[0243] At 9, the WTRU may solve the puzzle and produce evidence of the solved puzzle.
[0244] At 10, the WTRU may send (e.g., forward) the evidence of the solved puzzle to the SEAF.
[0245] At 11 , the SEAF may verify the puzzle solution evidence (e.g., verify the evidence of the solved puzzle) and / or its binding to the WTRU identity (e.g., SUPI or 5G-GUTI). The operation(s) may, upon successful verification at 11, continue to 12.
[0246] At 12-18, an authentication procedure for 5G AKA may be performed.
[0247] In examples, 8-10 and / or 12-14 may be combined / overlayed (e.g., for simplicity).
[0248] (D)DOS remediation for the EAP-AKA’ authentication procedure may be performed, for example, based on the use of a cryptographic puzzle(s) in the authentication procedure for EAP-AKA’.
[0249] FIGS. 12A-12B depict example (D)DOS remediation operations for the EAP-AKA’ authentication procedure.
[0250] As shown in FIG. 12A at 1, the UDM / ARPF may generate an authentication vector (e.g., with an authentication management field separation bit = 1). The UDM / ARPF may (e.g., then) compute OK’ and IK’ (e.g., as per the normative Annex A) and / or replace CK and IK with OK’ and IK’.
[0251] At 2, the UDM may (e.g., subsequently) send the transformed authentication vector AV (e.g., RAND, AUTN, XRES, CK', IK') and / or an indication that the AV may be used for EAP-AKA', for example using a Nudm_UEAuthentication_Get response message, to an AUSF (e.g., the AUSF from which it received the Nudm_UEAuthentication_Get request).
[0252] The exchange of a Nudm_UEAuthentication_Get request message and an Nudm_UEAuthentication_Get response message between the AUSF and the UDM / ARPF may be similar (e.g., the same) as for a trusted access using EAP-AKA' (e.g., except for the input parameter to the key derivation, which may be the value of the network name (e.g., <network name>)). The network name may be carried in the AT_KDF_INPUT attribute in EAP-AKA'. The value of the network name (e.g., <network name>) parameter may be defined in 3GPP specifications. For example, for EPS, the network name maybe defined as an access network identity. For example, for 5G, the network name may include (e.g., be defined as) a serving network name.
[0253] If SUCI was included in the Nudm_UEAuthentication_Get request, the UDM may include the SUPI in the Nudm_UEAuthentication_Get response.
[0254] If a subscriber has an AKMA subscription, the UDM may include the AKMA indication and / or routing indicator in the Nudm_UEAuthentication_Get response.
[0255] At 3, the AUSF may send the EAP-Request / AKA'-Challenge message to the SEAF in a Nausf_UEAuthentication_Authenticate response message.
[0256] At 4, the SEAF may determine to offer a puzzle to throttle a (D)DOS attack.
[0257] At 5, the SEAF may generate and / or obtain (e.g., composes) a cryptographic puzzle. The SEAF may bind the cryptographic puzzle to the WTRU identity (e.g., SUCI or 5G-GUTI) and / or add a freshness parameter (e.g., to prevent puzzle replay attacks).
[0258] At 6, the SEAF may send (e.g., transparently forward) the EAP-Request / AKA'-Challenge message to the WTRU in a NAS message authentication request message with the selected cryptographical puzzle. The ME may forward the RAND and AUTN received in the EAP-Request / AKA'- Challenge message to the USIM. This message may include the ngKSI and / or ABBA parameter. The SEAF may include the ngKSI and / or ABBA parameter in a (e.g., only) EAP-Authentication request message(s). The ngKSI may be used by the WTRU and / or the AMF to identify the partial native security context that is created if the authentication is successful. The SEAF may set the ABBA parameter. During an EAP authentication, the value of the ngKSI and / or the ABBA parameter sent by the SEAF to the WTRU may not be changed.
[0259] The SEAF may (e.g., need to) understand that the authentication operation used is an EAP operation, for example, by evaluating the type of authentication operation based on the Nausf_UEAuthentication_Authenticate response message.
[0260] At 7, the USIM may (e.g., at receipt of the RAND and AUTN) verify the freshness of the AV by checking whether AUTN may be accepted.
[0261] The USIM may (e.g., if the AUTN may be accepted) compute a response RES. The USIM may return RES, CK, IK to the ME. If the USIM computes a Kc (e.g., GPRS Kc) from CK and IK (e.g., using conversion function c3) and / or sends it to the ME, the ME may (e.g., then) ignore such GPRS Kc and not store the GPRS Kc on the USIM or in the ME. The ME may derive CK' and IK'.
[0262] The USIM and the ME may (e.g., if the verification of the AUTN fails on the USIM) proceed.
[0263] At 8, the WTRU may solve the offered cryptographic puzzle (e.g., spending some of its computational resources).
[0264] At 9, the WTRU may send an EAP-Response / AKA'-Challenge message, including the evidence of the cryptographic puzzle solution, to the SEAF in a NAS message Auth-Resp message.
[0265] At 10, the SIDF verifies the evidence of the solved puzzle (e.g., optionally), its freshness, and / or binding to a WTRU ID (e.g., SUCI or 5G-GUTI).
[0266] At 11 , the SEAF may send (e.g., transparently forward) the EAP-Response / AKA'-Challenge message to the AUSF in Nausf_UEAuthentication_Authenticate request message.
[0267] At 12, the AUSF may verify the message by comparing the XRES and RES. If the AUSF has successfully verified this message, it may continue to 13. Otherwise, the AUSF may return an error to the SEAF. The AUSF may inform the UDM about the authentication result.
[0268] At 13, the AUSF and the WTRU may exchange EAP-Req uest / AK A'-Notification and EAP- Response / AKA'-Notification messages (e.g., via the SEAF). The SEAF may send (e.g., transparently forward) these messages.
[0269] EAP notifications and / or EAP-AKA notifications may be used at any time in the EAP-AKA exchange. These notifications may be used, for example, for protected result indications and / or when the EAP server detects an error in the received EAP-AKA response.
[0270] At 14, the AUSF may derive EMSK from CK’ and IK’. The AUSF may use the most significant 256 bits of EMSK as the KAUSF and / or may calculate KSEAF from KAUSF. The AUSF may send an EAP success message to the SEAF inside a Nausf_UEAuthentication_Authenticate response, which may forward it transparently to the WTRU. The Nausf_UEAuthentication_Authenticate response message may include the KSEAF. If the AUSF received a SUCI from the SEAF when the authentication was initiated, the AUSF may include the SUPI in the Nausf_UEAuthentication_Authenticate response message. The AUSF may store the KAUSF based on the home network operator's policy.
[0271] The AUSF sending a SUPI to a SEAF may occur (e.g., may be necessary for lawful interception) but may not be sufficient. By including the SUPI as an input parameter to the key derivation of KAMF from KSEAF, additional assurance on the correctness of SUPI may be achieved by the serving network from the home network and / or WTRU side.
[0272] At 15, the SEAF may send the EAP success message to the WTRU in the N1 message. This message may also include the ngKSI and / or the ABBA parameter. The SEAF may set the ABBA parameter.
[0273] (D)DOS remediation for PC5 security establishment procedure for 5G ProSe WTRU-to-network relay communication over the control plane may be performed.
[0274] Message 2 from a remote WTRU to a relay WTRU may be DDOS(ed). The techniques to slow down and / or mitigate DDOS may be used after Message 2 (e.g., a puzzle offer in 2a, WTRU solving the puzzle in 2b, and / or the remote WTRU allowing Message 3 a (e.g., only) if the puzzle is solved).
[0275] FIGS. 13A-13E depict an example (D)DOS remediation for PC5 security establishment procedure for 5G ProSe WTRU-to-network relay communication over the control plane.
[0276] As shown in FIG. 13A at 0, a 5G ProSe remote WTRU and / or the 5G ProSe WTRU-to-network relay may be registered with the network. The 5G ProSe WTRU-to-network relay may be authenticated and / or authorized by the network to provide WTRU-to-network relay service. The 5G ProSe remote WTRU may be authenticated and / or authorized by the network to receive a WTRU-to-network relay service. PC5 security policies may be provisioned (e.g., provided) to the 5G ProSe remote WTRU and / or the 5G ProSe WTRU-to-network relay, respectively, during this authorization and information provisioning procedure.
[0277] At 1 , the 5G ProSe remote WTRU or relay WTRU may initiate a discovery procedure using an operation (e.g., any method such as Model A or Model B operations). If the remote WTRU receives NCGI from the relay WTRU, it may store (e.g., temporarily store) the NCGI.
[0278] At 2, after the discovery of the 5G ProSe WTRU-to-network relay, the 5G ProSe remote WTRU may send a direct communication request to the 5G ProSe WTRU-to-network relay (e.g., for establishing a secure PC5 unicast link). The 5G ProSe remote WTRU may include a security capability (e.g., its security capabilities) and / or PC5 signaling security policy in the DCR message. The message may (e.g., also) include a relay service code, Nonce_1 .
[0279] If the 5G ProSe remote WTRU does not have a valid 5G ProSe remote user key (CP-PRUK), the 5G ProSe remote WTRU may include SUCI in the DCR to trigger 5G ProSe remote WTRU specific authentication and / or establish a CP-PRUK.
[0280] If the 5G ProSe remote WTRU (e.g., already) has a valid CP-PRUK for relay service code, the 5G ProSe remote WTRU may include the associated CP-PRUK ID in the DCR to indicate that the 5G ProSe remote WTRU wants to get (e.g., requests to obtain) relay connectivity using the CP-PRUK. The privacy and / or integrity protection of DCR may be used.
[0281] At 3, the SEAF may determine to offer a puzzle to throttle a (D)DOS attack.
[0282] At 4, the SEAF generate and / or obtain (e.g., composes) a cryptographic puzzle, (e.g., optionally) bind it (e.g., the puzzle) to the WTRU identity (SUCI or 5G-GUTI), and / or add an optional freshness parameter to prevent puzzle replay attacks.
[0283] At 5, the SEAF may send a NAS message with an encapsulated puzzle.
[0284] At 6, the WTRU may solve the puzzle and produce evidence of the solved puzzle.
[0285] At 7, the WTRU may send (e.g., forward) the evidence of the solved puzzle to the SEAF.
[0286] At 8, the SEAF may verify the puzzle solution evidence (e.g., verify the evidence of the solved puzzle) and / or its binding to the WTRU identity (SUPI or 5G-GUTI).
[0287] As shown in FIG. 13B, at 9, upon receiving the DCR message, the 5G ProSe WTRU-to-network relay may send the relay key request to the AMF of the 5G ProSe WTRU-to-network relay, including SUCI or CP-PRUK ID, RSC, and Nonce_1 received in the DCR message. The 5G ProSe WTRU-to-network relay may also include a transaction identifier (e.g., that identifies the 5G ProSe remote WTRU for the subsequent messages over 5G ProSe WTRU to network relay’s NAS messages) in the message.
[0288] At 10, the AMF of the 5G ProSe WTRU-to-network relay may verify with the UDM whether the 5G ProSe WTRU-to-network relay may be authorized to provide the WTRU-to-network relay service.
[0289] At 11 , the AMF of the 5G ProSe WTRU-to-network relay may select an AUSF based on SUCI or CP-PRUK ID and forward the parameters received in a Relay Key Request to the AUSF in a Nausf_UEAuthentication_ProseAuthenticate request message. The Nausf_UEAuthentication_ProseAuthenticate request message may include (e.g., contain) the 5G ProSe remote WTRU's SUCI or CP-PRUK ID, a relay service code, Nonce_1 , and / or a serving network name of the 5G ProSe WTRU-to-network relay. If CP-PRUK ID is received from an AMF of the 5G ProSe WTRU-to- network relay, the AUSF of the 5G ProSe remote WTRU may (e.g., temporarily) store Nonce_1 and may skip 6-9. If the 5G ProSe remote WTRU's SUCI is received from the AMF of the 5G ProSe WTRU-to- network relay, the AUSF of the 5G ProSe remote WTRU may (e.g., temporarily) store Nonce_1 and relay service code, and may skip 10.
[0290] The AUSF may get (e.g., receive and / or obtain) the 5G ProSe remote WTRU's routing indicator from the 5G ProSe remote WTRU's SUCI or CP-PRUK ID and may (e.g., temporarily) store the routing indicator.
[0291] At 12, the AUSF of the 5G ProSe remote WTRU may initiate a 5G ProSe remote WTRU (e.g., specific) authentication using the ProSe (e.g., specific) parameters received (e.g., RSC, and / or the like). The serving network name may be handled, for example, as described herein.
[0292] The AUSF of the 5G ProSe remote WTRU may retrieve the AVs from the UDM via a Nudm_UEAuthentication_GetProseAv request message. The AUSF may include the serving network name of the 5G ProSe WTRU-to-network relay in the Nudm_UEAuthentication_GetProseAV request message. Upon reception of the Nudm_UEAuthentication_GetProSeAv request, the UDM may invoke SIDF de-conceal SUCI to gain SUPI (e.g., before the UDM may process the request). The UDM may check whether the WTRU is authorized to use a ProSe WTRU-to-network relay service based on authorization information in the WTRU's subscription data. If the WTRU is authorized, the UDM may choose the EAP-AKA' authentication operation based on the received Nudm_UEAuthentication_GetProseAv request. The UDM may (e.g., then) generate an EAP-AKA’ Authentication vector for ProSe and / or may send a Nudm_UEAuthentication_GetProseAv response with the AV and SUPI to the AUSF.
[0293] At 13a, the AUSF of the 5G ProSe remote WTRU may (e.g., temporarily) store XRES and SUPI. The AUSF of the 5G ProSe remote WTRU may trigger authentication of the 5G ProSe remote WTRU based on EAP-AKA'. The AUSF of the 5G ProSe remote WTRU may generate the EAP-Request / AKA'- Challenge message and / or send an EAP-Request / AKA'-Challenge message to the AMF of the 5G ProSe WTRU-to-network relay in a Nausf_UEAuthentication_ProSeAuthenticate response message.
[0294] At 13b, the AMF of the 5G ProSe WTRU-to-network relay may forward the relay authentication request (e.g., including the EAP-Request / AKA'-Challenge) to the 5G ProSe WTRU-to-network relay over a NAS message, for example, including the transaction identifier of the 5G ProSe remote WTRU in the message. The NAS message may be protected using the NAS security context created for the 5G ProSe WTRU-to-network relay.
[0295] At 13c, based on the transaction identifier, the 5G ProSe WTRU-to-network relay may send (e.g., forward) the EAP-Request / AKA'-Challenge to the 5G ProSe remote WTRU over PC5 messages.
[0296] The USIM in the 5G ProSe remote WTRU may verify the freshness of the received values by checking whether AUTN may be accepted.
[0297] For EAP-AKA', the USIM may compute a response RES. The USIM may return RES, CK, and IK to the ME. The ME may derive CK' and IK'.
[0298] If the remote WTRU requests (e.g., requires) a network name verification (e.g., discrepancy comparison) and / or receives NCGI from the relay WTRU at 1 , the remote WTRU may verify using the SNN information received in the EAP-Request / AKA'-Challenge and / or the SN ID information in the NCGI. The remote WTRU may abort the authentication if verification fails. The remote WTRU may skip the network name verification if the remote WTRU does not receive NCGI from the relay.
[0299] At 13d, the 5G ProSe remote WTRU may return EAP-Response / AKA'-Challenge to the 5G ProSe WTRU-to-network relay over PC5 messages.
[0300] At 13e, the 5G ProSe WTRU-to-network relay may send (e.g., forward) the EAP-Response / AKA'- Challenge together with the transaction identifier of the 5G ProSe Remote WTRU to the AMF of the 5G ProSe WTRU-to-network relay in a NAS message relay authentication response.
[0301] At 13f, the AMF of the 5G ProSe WTRU-to-network relay may send (e.g., forward) EAP- Response / AKA'-Challenge to the AUSF of the 5G ProSe remote WTRU via Nausf_UEAuthentication_ProSeAuthenticate request.
[0302] The AUSF of the 5G ProSe remote WTRU may perform the WTRU authentication by verifying the received information.
[0303] For EAP-AKA', the AUSF of the 5G ProSe remote WTRU and the 5G ProSe remote WTRU may exchange EAP-Request / AKA'-Notification and EAP-Response / AKA'-Notification messages via the AMF of the 5G ProSe WTRU-to-network relay and the 5G ProSe WTRU-to-network relay. After the exchanges, the AUSF of the 5G ProSe remote WTRU and / or the 5G ProSe remote WTRU may use the most significant 256 bits of EMSK as the KAUSF_P in a similar way (e.g., the same way) as KAUSF is obtained for EAP- AKA’.
[0304] At 14, upon successful authentication, the AUSF of the 5G ProSe remote WTRU and / or the 5G ProSe remote WTRU may generate CP-PRUK as specified in CP-PRUK ID.
[0305] The CP-PRUK ID may be in NAI format (e.g., username@realm). The username part may include the routing indicator from 5 and the CP-PRUK ID*. The realm part may include a home network identifier. The CP-PRUK ID* may be specified.
[0306] At 15a, the AUSF of the 5G ProSe remote WTRU may select the PAnF (ProSe anchor function) based on CP-PRUK ID and send the SUPI, RSC, CP-PRUK, and / or CP-PRUK ID in Npanf_ProseKey_Register request message to the PAnF. The PAnF may be selected based on the routing indicator in the CP-PRUK ID.
[0307] At 15b, the PAnF may store the ProSe context info (e.g., SUPI, RSC, CP-PRUK, CP-PRUK ID) for the 5G ProSe remote WTRU and / or send a Npanf_ProseKey_Register response message to the AUSF.
[0308] At 16a, the AUSF of the 5G ProSe remote WTRU may select the PAnF based on CP-PRUK ID and / or send the received CP-PRUK ID and RSC in a Npanf_ProseKey_get request message. The PAnF may be selected based on the routing indicator in the CP-PRUK ID.
[0309] At 16b, the PAnF may retrieve CP-PRUK based on the CP-PRUK ID and may check whether the 5G ProSe remote WTRU is authorized to use the WTRU-to-network relay service based on received RSC (e.g., the PAnF may use the Nudm_SDM operation to check with the UDM whether the remote WTRU is authorized to use ProSe WTRU-to-network or WTRU-to-network relay service by using the SUPI). If the ProSe remote WTRU (e.g., 5G ProSe remote WTRU) is authorized and / or the retrieved CP-PRUK is valid, the PAnF may send Npanf_ProseKey_get response message with CP-PRUK to the AUSF.
[0310] If the CP-PRUK is stale, the PAnF may treat it as invalid based on a (e.g., local) policy. When receiving a Npanf_ProseKey_get request, the PAnF may respond with CP-PRUK not found.
[0311] As shown in FIG. 13D, at 17, the AUSF of the ProSe remote WTRU may generate Nonce_2 and derive the KNR_ProSe key using CP-PRUK, Nonce_1 , and Nonce_2.
[0312] At 18, the AUSF of the ProSe remote WTRU may send the KNR_ProSe, Nonce_2 in Nausf_UEAuthentication_ProseAuthenticate response message to the ProSe WTRU-to-network relay via the AMF of the ProSe WTRU-to-network relay. An EAP success message may be included if 7 (e.g., puzzle solving) is performed successfully. The AUSF of the ProSe remote WTRU may also include the CP- PRUK ID in the message.
[0313] At 19, when receiving a KNR_ProSe from the AUSF of the 5G ProSe remote WTRU via the AMF of the ProSe WTRU-to-network relay, the ProSe WTRU-to-network relay may derive PC5 session key Krelay-sess, confidentiality key Krelay-enc (e.g., if applicable), and / or the integrity key Krelay-int from KNR_ProSe. KNR_ProSe ID and / or Krelay-sess ID may be established similarly to (e.g., in the same way as) KNRP ID and KNRP-sess ID. The CP-PRUK ID may be sent from the AMF of the ProSe WTRU-to- network relay to the WTRU-to-network relay. The EAP success message may (e.g., also) be sent from the AMF of the ProSe WTRU-to-network relay to the WTRU-to-network (e.g., UE-to-network) relay if received from an AUSF.
[0314] At 20, the ProSe WTRU-to-network relay may send the received Nonce_2 and 5G ProSe remote WTRU's PC5 signaling security policy to the ProSe remote WTRU in a direct security mode command message (e.g., which may be integrity protected using Krelay-int). An EAP success message may be included if received from the AMF of the ProSe WTRU-to-network relay.
[0315] At 21 , a 5G ProSe remote WTRU may generate the KNR_ProSe key to be used for remote access via the ProSe WTRU-to-network relay (e.g., as defined in 11). The ProSe remote WTRU may derive PC5 session key Krelay-sess and / or confidentiality and integrity keys from KNR_ProSe (e.g., as defined in 13).
[0316] The ProSe remote WTRU may verify the direct security mode command message. Successful verification of the direct security mode command message may assure the ProSe remote WTRU that the ProSe WTRU-to-network relay may be authorized to provide the relay service.
[0317] At 22, the ProSe remote WTRU may send the direct security mode complete message, including (e.g., containing) its PC5 user plane security policies to the ProSe WTRU-to-network relay, which may be protected by Krelay-int or / and Krelay-enc derived from Krelay-sess according to the negotiated PC5 signaling policies between the ProSe remote WTRU and the ProSe WTRU-to-network relay.
[0318] At 23, based on receiving the direct security mode complete message, the ProSe WTRU-to- network relay may verify the direct security mode complete message. Successful verification of the direct security mode complete message may assure the 5G ProSe WTRU-to-network relay that the ProSe remote WTRU is authorized to get (e.g., retrieve and / or obtain) the relay service.
[0319] After the successful verification of the direct security mode complete message, the ProSe WTRU- to-network relay may respond with a direct communication accept message to the ProSe remote WTRU to finish the PC5 connection establishment procedures and store the CP-PRUK ID in the security context associated with the PC5 link with the ProSe remote WTRU.
[0320] At 24, when the condition(s) to send a remote WTRU report are reached, the ProSe Layer-3 WTRU-to-network relay may send a remote WTRU report (e.g., remote user ID, remote WTRU info, and / or the like) message to the SMF of the ProSe WTRU-to-network relay. The ProSe Layer-3 WTRU-to-network relay may include remote user ID (e.g., the CP-PRUK ID received in 13) in the message.
[0321] At 25, if the mapping of the remote user ID and the ProSe remote WTRU's SUPI is not available in the SMF of the ProSe WTRU-to-network relay, the SMF of the ProSe WTRU-to-network relay may discover the PAnF of the ProSe remote WTRU based on the remote user ID (e.g., the CP-PRUK ID) and may send a resolve remote user ID request towards the PAnF in a Npanf_ResolveRemoteUserld_Get request message, including the remote user ID of the 5G ProSe remote WTRU in the message.
[0322] The PAnF of the ProSe remote WTRU may send a resolve remote user ID response to the SMF of the ProSe WTRU-to-network relay in a Npanf_ResolveRemoteUserld_Get response message, including the SUPI of the ProSe remote WTRU in the message.
[0323] The SMF of the ProSe WTRU-to-network relay may store the remote user ID, the SUPI of the ProSe remote WTRU, and the remote WTRU info in the ProSe Layer-3 WTRU-to-network relay's SM context for this PDU Session associated with the relay. The SMF may send a remote WTRU report acknowledgment message to the ProSe Layer-3 WTRU-to-network relay.
[0324] In examples, communication between the ProSe remote WTRU and the network may take place securely via the ProSe WTRU-to-network relay.
[0325] If the ProSe remote WTRU receives from the ProSe WTRU-to-network relay a direct connection reject due to CP-PRUK ID not found in the network, the ProSe remote WTRU may not attempt to reconnect with the ProSe WTRU-to-network relay using the CP-PRUK ID. The ProSe remote WTRU may attempt to connect with the ProSe WTRU-to-network relay using its SUCI.
[0326] The CP-PRUK ID not being found condition may be detected by the PAnF if it does not find a ProSe context info for the ProSe remote WTRU that corresponds to the received CP-PRUK ID. The ProSeWTRU-to-network relay may be informed of this condition via the AUSF of the 5G ProSe remote WTRU and the AMF of the ProSe WTRU-to-network relay.
[0327] Edge (D)DOS remediation may be performed (e.g., based on the use of cryptographic puzzles for the initiation of edge access).
[0328] FIG. 14 depicts an example edge service provisioning request and response.
[0329] As shown in FIG. 14 at 1 , an EEC may send a service provisioning request to an ECS / EES. The service provisioning request may include the security credentials of the EEC received during the EEC authorization procedure and may include the WTRU identifier, such as GPSI, connectivity information, WTRU location, EEC service continuity support, and AC profile(s) information. The EEC may provide its requested ECSP identifier(s) in the service provisioning request based on the EEC preference.
[0330] At 2, the ECS / EES may determine to offer a puzzle to throttle a (D)DOS attack.
[0331] At 3, the ECS / EES generates and / or obtains (e.g., composes) a cryptographic puzzle. TheECS / EES may bind the cryptographic puzzle to the EEC identity (e.g., ECSP ID or GPSI) and / or add a freshness parameter to prevent puzzle replay attacks.
[0332] At 4, the ECS / EES may send a message with a puzzle (e.g., an encapsulated puzzle).
[0333] At 5, the AC / EEC may solve the puzzle and produce evidence of the solved puzzle.
[0334] At 6, the AC / EEC may send (e.g., forward) the evidence of a solved puzzle to the ECS / EES.
[0335] At 7, the SEAF may verify the puzzle solution evidence (e.g., verify the evidence of the solved puzzle) and / or its binding to the WTRU identity (e.g., ECSP ID or GPSI).
[0336] At 8, upon finishing the check (e.g., verifying the evidence of the solved puzzle is similar to the solution), the ECS may perform an authorization check to verify whether the EEC may have authorization to perform the operation.
[0337] At 9, if the processing of the request was successful, the ECS / EES may respond to the EEC's request with a service provisioning response. If the ECS has identified the relevant EES(s) information, the service provisioning response may include a list of EDN configuration information (e.g., identification of the EDN, EDN service area, and the requested (e.g., required) information (e.g., URI, IP address)) for establishing a connection to the NF that the AC / EEC may access.
[0338] Although features and elements described above are described in particular combinations, each feature or element may be used alone without the other features and elements of the preferred embodiments, or in various combinations with or without other features and elements.
[0339] Although the implementations described herein may consider 3GPP specific protocols, it is understood that the implementations described herein are not restricted to this scenario and may beapplicable to other wireless systems. For example, although the solutions described herein consider LTE, LTE-A, New Radio (NR) or 5G specific protocols, it is understood that the solutions described herein are not restricted to this scenario and are applicable to other wireless systems as well.
[0340] The processes described above may be implemented in a computer program, software, and / or firmware incorporated in a computer-readable medium for execution by a computer and / or processor. Examples of computer-readable media include, but are not limited to, electronic signals (transmitted over wired and / or wireless connections) and / or computer-readable storage media. Examples of computer- readable storage media include, but are not limited to, a read only memory (ROM), a random access memory (RAM), a register, cache memory, semiconductor memory devices, magnetic media such as, but not limited to, internal hard disks and removable disks, magneto-optical media, and / or optical media such as compact disc (CD)-ROM disks, and / or digital versatile disks (DVDs). A processor in association with software may be used to implement a radio frequency transceiver for use in a WTRU, terminal, base station, RNC, and / or any host computer.
Claims
CLAIMSWhat is claimed:1 . A network node comprising: a processor configured to: receive a request for service message from a wireless transmit / receive unit (WTRU); generate a puzzle based on the request for service message; send a service message response to the WTRU, wherein the service message response comprises an indication of the puzzle; receive an evidence request message comprising an indication of evidence, wherein the evidence is associated with a solution to the puzzle; verify the solution to the puzzle based on the indication of the evidence; and based on the verification, process the request for service message.
2. The network node of claim 1 , wherein the service message response comprises an indication of a freshness parameter configured to prevent spoofing of a WTRU identity or to prevent a replay of the evidence by a second WTRU.
3. The network node of claim 2, wherein the puzzle is an expiring puzzle based on the freshness parameter.
4. The network node of any one of claims 1-3, wherein the network node sends the service message response based on a determination that a number of failed authentication attempts satisfies a threshold.
5. The network node of any one of claims 1-4, wherein the network node sends the service message response based on a determination to remediate an distributed denial of service (DDOS) attack.
6. The network node of any one of claims 1-5, wherein the processor is further configured to: select a puzzle strength parameter configured to modulate a level of effort to be spent by the WTRU to generate the evidence, wherein the puzzle is generated based on the puzzle strength parameter, and wherein the puzzle strength parameter is associated with an encryption key length or a portion of a cryptographic hash function argument.
7. The network node of any one of claims 1-6, wherein the indication of the evidence comprises a solution to an encryption reversing puzzle or a solution to a hash function puzzle.
8. The network node of any one of claims 1-7, wherein the puzzle is a reverse encryption puzzle, wherein the indication of the evidence comprises plaintext associated with an encryption key, and wherein the solution is verified based on a determination that a portion of the plaintext associated with the encryption key and a portion of the solution are the same.
9. The network node of any one of claims 1-7, wherein the puzzle is a cryptographic hash function puzzle, wherein the indication of the evidence comprises a hash function input text associated with a hash function argument, and wherein the solution is verified based on a determination that a portion of the hash function input text associated with the hash function argument and a portion of the solution are the same.
10. A wireless transmit / receive unit (WTRU) comprising: a processor configured to: send a request for service message to a network node; receive a service message response from the network node, wherein the service message response comprises an indication of a puzzle; generate evidence based on the puzzle, wherein the evidence is associated with a solution to the puzzle; send an evidence request message to the network node, wherein the evidence request message comprises an indication of the evidence and comprises a request that the indication of the evidence is verified by the network node based on the solution to the puzzle; and receive an authentication response comprising an indication that the request for service message is being processed.11 . The WTRU of claim 10, wherein the service message response comprises an indication of a freshness parameter configured to prevent spoofing of a WTRU identity or to prevent a replay of the evidence by a second WTRU.
12. The WTRU of claim 11 , wherein the puzzle is an expiring puzzle based on the freshness parameter.
13. The WTRU of any one of claims 10-12, wherein the puzzle is at least one of a reverse encryption puzzle or a one-way cryptographic hash function puzzle.
14. The WTRU of any one of claims 10-13, wherein the indication of the evidence comprises a solution to an encryption reversing puzzle or a solution to a hash function puzzle.
15. The WTRU of any one of claims 10-14, wherein the indication of the puzzle is associated with an encryption key length or a portion of a cryptographic hash function argument.
16. A method comprising: receiving a request for service message from a wireless transmit / receive unit (WTRU); generating a puzzle based on the request for service message; sending a service message response to the WTRU, wherein the service message response comprises an indication of the puzzle; receiving an evidence request message comprising an indication of evidence, wherein the evidence is associated with a solution to the puzzle; verifying the solution to the puzzle based on the indication of the evidence; and based on the verification, processing the request for service message.
17. The method of claim 16, wherein the service message response comprises an indication of a freshness parameter configured to prevent spoofing of a WTRU identity or to prevent a replay of the evidence by a second WTRU.
18. The method of claim 17, wherein the puzzle is an expiring puzzle based on the freshness parameter.
19. The method of any one of claims 16-18, wherein the method further comprises sending the service message response based on a determination that a number of failed authentication attempts satisfies a threshold or based on a determination to remediate a distributed denial of service (DDOS) attack.
20. The method of any one of claims 16-19, wherein the method comprises selecting a puzzle strength parameter configured to modulate a level of effort to be spent by the WTRU to generate the evidence, wherein the puzzle is generated based on the puzzle strength parameter, and wherein the puzzle strength parameter is associated with an encryption key length or a portion of a cryptographic hash function argument.
Citation Information
Patent Citations
Methods providing authentication using a request commit message and related user equipment and network nodes
US20220286846A1