Security solutions mitigating bidding-down attacks when decommissioning 2g / 3g networks
By providing UEs with lists of decommissioned 2G/3G networks and trusted cells through 5G signaling methods, the vulnerability to bidding-down attacks is mitigated, ensuring secure network selection.
Patent Information
- Application Number
- PCT/CN2024/086260
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-05
- Publication Date
- 2025-10-09
AI Technical Summary
Mobile network operators decommissioning 2G/3G networks leave user equipment (UEs) vulnerable to bidding-down attacks, as current 5G systems lack mechanisms to prevent UEs from selecting fake 2G/3G networks, which exploit weaker security protections.
Implementing mechanisms in 5G systems to provide UEs with lists of decommissioned 2G/3G networks and trusted or non-trusted cells, using various signaling methods such as NAS messages, SIBs, and USIM configurations to avoid selection of fake 2G/3G networks.
Prevents UEs from connecting to decommissioned 2G/3G networks, thereby mitigating bidding-down attacks and ensuring secure network selection.
Smart Images

Figure CN2024086260_09102025_PF_FP_ABST
Abstract
Description
Security Solutions Mitigating Bidding-Down Attacks When Decommissioning 2G / 3G NetworksBackground
[0001] Mobile network operators (MNOs) supporting 4G and 5G New Radio (NR) networks may decommission their 2G or 3G networks. For a user equipment (UE) with a subscription to a MNO that has no 2G / 3G service in a given tracking area, it is not appropriate for the UE to continue selecting such networks. Additionally, due to weaker protections in these previous generations, UEs may be tricked into selecting such networks. When this occurs, the UEs will be vulnerable to many known attacks pertaining to 2G and 3G. In one example, a fake base station (FBS) may transmit a tracking area code of a fake 2G / 3G cell to attempt to trick the UE into registering with the fake network in a bidding-down attack. There is no solution in the current 5G system to prevent UEs from selecting a 2G / 3G FBS when 5G / 4G is blocked by an attacker.Summary
[0002] Some example embodiments are related to an apparatus having processing circuitry configured to process, based on signals received from an access and mobility function (AMF) , a registration accept comprising at least one of a list of identifiers corresponding to decommissioned public land mobile network (PLMN) corresponding to a 2G or 3G network and a trusted list of cells corresponding to the 2G or 3G network and, when signals from a first 2G or 3G network are detected that either correspond to an entry in the list of identifiers of the decommissioned PLMNs corresponding to the 2G or 3G network or are not included on the trusted list of cells corresponding to the 2G or 3G network, avoid selection to the first 2G or 3G network.
[0003] Other example embodiments are related to an apparatus having processing circuitry configured to process, based on signals received from a base station, a system information block (SIB) of a 5G system (5GS) comprising at least one of a list of identifiers corresponding to decommissioned public land mobile networks (PLMN) corresponding to a 2G or 3G network and a trusted list of cells corresponding to the 2G or 3G network, and, when signals from a first 2G or 3G network are detected that either correspond to an entry in the list of identifiers of the decommissioned PLMNs corresponding to the 2G or 3G network or are not included on the trusted list of cells corresponding to the 2G or 3G network, avoid selection to the first 2G or 3G network.
[0004] Still further example embodiments are related to an apparatus having processing circuitry configured to register with an access and mobility function (AMF) of a 5G system (5GS) , process, based on signals received from the AMF, a non-access stratum (NAS) message comprising at least one of a list of identifiers corresponding to decommissioned public land mobile networks (PLMN) corresponding to a 2G or 3G network and a trusted list of cells corresponding to the 2G or 3G network and, when signals from a first 2G or 3G network are detected that either correspond to an entry in the list of identifiers of decommissioned PLMNs corresponding to the 2G or 3G network or are not included on the trusted list of cells corresponding to the 2G or 3G network, avoid selection to the first 2G or 3G network.
[0005] Additional example embodiments are related to an apparatus having processing circuitry configured to attempt to access a 5G system (5GS) and, when signals from a first 2G or 3G network are detected that either correspond to an entry in a pre-configured list of identifiers corresponding to decommissioned public land mobile networks (PLMN) corresponding to the 2G or 3G network or are not included on a pre-configured trusted list of cells corresponding to the 2G or 3G network, avoid selection to the first 2G or 3G network.
[0006] More example embodiments are related to an apparatus having processing circuitry configured to activate a universal subscriber identity module (USIM) for accessing a 5G system (5GS) , read an elementary file for forbidden Public Land Mobile Networks (EFFPLMN) as part of USIM initialization, the EFFPLMN including a list of identifiers corresponding to forbidden public land mobile networks (FPLMN) and, when signals from a 2G or 3G network are detected that correspond to an entry in the list of identifiers of the FPLMNs, avoid selection to the detected 2G or 3G network.
[0007] Further example embodiments are related to an apparatus having processing circuitry configured to process, based on signals received from a base station of a 5G system (5GS) , an access stratum (AS) security command comprising at least one of a list of identifiers corresponding to decommissioned public land mobile networks (PLMN) corresponding to a 2G or 3G network and a trusted list of cells corresponding to the 2G or 3G network, and, when signals from a 2G or 3G network are detected that either correspond to an entry in the list of identifiers of decommissioned PLMNs or are not included on the trusted list of cells, avoid selection to the detected 2G or 3G network.Brief Description of the Drawings
[0008] Fig. 1a shows a signaling diagram for indicating a list of PLMNs in which 2G or 3G has been decommissioned in a registration accept according to various example embodiments.
[0009] Fig. 1b shows a table for information elements (IEs) included in a Registration Accept message sent by the AMF to a UE according to various example embodiments.
[0010] Fig. 2 shows an example information element (IE) included in a SIB message according to various example embodiments.
[0011] Fig. 3a shows a signaling diagram for indicating a list of PLMNs in which 2G or 3G has been decommissioned and / or a list of trusted / not trusted 2G / 3G cells in a UE configuration update according to various example embodiments.
[0012] Fig. 3b shows a signaling diagram for indicating a list of PLMNs in which 2G or 3G has been decommissioned and / or a list of trusted / not trusted 2G / 3G cells in a tracking area update (TAU) accept message according to various example embodiments.
[0013] Fig. 4 shows a EFFPLMN including a list of FPLMNs according to various example embodiments.
[0014] Fig. 5 shows a signaling diagram for indicating a list of PLMNs in which 2G or 3G has been decommissioned and / or a list of trusted / not trusted 2G / 3G cells in a NAS security mode command according to various example embodiments.
[0015] Fig. 6 shows a signaling diagram for indicating a list of PLMNs in which 2G or 3G has been decommissioned and / or a list of trusted / not trusted 2G / 3G cells in an access stratum (AS) security mode command according to various example embodiments.
[0016] Fig. 7 shows an example network arrangement according to various example embodiments.
[0017] Fig. 8 shows an example user equipment (UE) according to various example embodiments.
[0018] Fig. 9 shows an example base station according to various example embodiments.Detailed Description
[0019] The example embodiments may be further understood with reference to the following description and the related appended drawings, wherein like elements are provided with the same reference numerals. The example embodiments relate to security-related operations for mitigating bidding down attacks in which an attacker attempts to induce a user equipment (UE) to select a fake base station (FBS) . In particular, the example embodiments describe operations for providing information to a UE regarding 2G and / or 3G public land mobile networks (PLMN) and / or cells that may or may not be accessed by the UE. If there are no valid 2G / 3G networks in a given tracking area, e.g., because the previous 2G / 3G networks of a mobile network operator (MNO) were decommissioned by the MNO, the UE will avoid selecting any 2G / 3G cells detected by the UE.
[0020] According to some aspects of these example embodiments, the 2G / 3G PLMN / cell information may be provided in a non-access stratum (NAS) message from the access and mobility function (AMF) of the 5G system (5GS) . In some example embodiments, the NAS message may comprise a registration accept, a UE configuration update, a TAU message, or a NAS security command. According to other aspects of these example embodiments, the 2G / 3G PLMN / cell information may be provided by a base station in a system information block (SIB) or an access stratum (AS) security command. According to still other aspects of these example embodiments, the 2G / 3G PLMN / cell information may be provided in a pre-configuration or in an update to a USIM profile.
[0021] The example embodiments are described with regard to a user equipment (UE) . However, reference to a UE is merely provided for illustrative purposes. The example embodiments may be utilized with any electronic component that may establish a connection to a network and is configured with the hardware, software, and / or firmware to exchange signaling and / or data with the network. Therefore, the UE as described herein is used to represent any electronic component.
[0022] The example embodiments are also described with reference to a 5G New Radio (NR) network and core network (5GC) of a 5G System (5GS) . However, reference to the 5GS is merely provided for illustrative purposes. The example embodiments may be utilized with any network implementing functionalities similar to those described herein. Therefore, the 5G NR network as described herein may represent any type of network implementing functionalities similar to the 5G NR network, e.g., 5G-Advanced networks, 6G networks, etc.
[0023] A base station of a network may provide the UE access to a public land mobile network (PLMN) , e.g., a PLMN operating a 5G New Radio (NR) radio access network (RAN) . A PLMN refers to the wireless services offered by a network operator to a subscriber in a particular geographical area. In some scenarios, multiple PLMNs may operate within a same network arrangement and share components, e.g., base stations. One PLMN may connect to other PLMNs for providing services including roaming, messaging, data, etc. These other PLMNs may belong to the same operator or a different operator.
[0024] The example embodiments are also described with reference to a 2G system, a 3G system, and a 4G system. The 2G system is implemented according to Global System for Mobile Communications (GSM) standards and deploys a GSM EDGE radio access network (RAN) (GERAN) ; the 3G system is implemented according to Universal Mobile Telecommunications System (UMTS) standards and deploys a UMTS Terrestrial radio access network (UTRAN) ; the 4G system is implemented according to long term evolution (LTE) standards and deploys a LTE-RAN.
[0025] Throughout the history of mobile network deployments, as mobile network systems are continuously evolving and improving, mobile network operators (MNO) periodically shift focus and investment to the newest generation network while the older networks are decommissioned. Currently, many operators supporting 4G and 5G networks are decommissioning their 2G and / or 3G networks. In such circumstances, it is no longer appropriate to allow a UE supporting 2G or 3G networks to continue selecting such networks. Additionally, due to weaker protections in these previous generations, UEs may be tricked into selecting such networks. When this occurs, the UEs will be vulnerable to many known attacks pertaining to 2G and 3G. Even when there is no 2G / 3G network in specific areas, a false base station (FBS) may claim to be a 2G / 3G node if the UE is still supporting 2G / 3G connection technology. The FBS may transmit a tracking area code of a fake 2G / 3G cell to attempt to trick the UE into registering with the fake network in a bidding-down attack. There is no solution in the current 5G system to prevent UEs from selecting 2G / 3G FBS when 5G / 4G is blocked by an attacker.
[0026] Accordingly, the UE and the 5GS should support mechanisms to mitigate bidding down attacks from LTE / NR to decommissioned GERAN / UTRAN by an attacker over the air interface.
[0027] The example embodiments are further described with regard to initial access operations including registration with the 5GS. Registering with the 5GS, in particular, with the access and mobility function (AMF) of the 5G core network (5GC) , includes authentication and security operations according to the Authentication and Key Agreement (AKA) protocol. The AKA mechanisms authenticate mobile devices and establish secure communication links between the device and the network. These operations involve 5GC entities including the AMF, a unified data management (UDM) , and an authentication server function (AUSF) . The AMF generally performs operations related to mobility management such as, but not limited to, paging, non-access stratum (NAS) management and registration procedure management between the UE and the 5GC. The AMF additionally manages the security key and associated security-related parameters, e.g., for establishing secure communication channels between the UE and the 5G RAN. The UDM generally performs operations related to authentication and data management (e.g., computing keys) . The AUSF performs the authentication with support from the UDM for computing authentication data and keys.
[0028] A subscriber identification module (SIM) or universal SIM (USIM) contains information that is used by the UE to establish a network connection. For example, the SIM may include an international mobile subscriber identifier (IMSI) that may be used for authentication with a cellular service provider, e.g., MNO. A USIM may enable a subscription with the MNO. The network to which the UE may connect using the first SIM may be the 5G NR cellular network, e.g., a PLMN deployed by a mobile network operator (MNO) . In some cases, a SIM or USIM may contain information for establishing a network connection with a PLMN deploying a 2G, 3G or 4G network. For example, a PLMN may deploy networks for multiple radio technologies including 4G / 5G and 2G / 3G or may deploy only a 2G / 3G network. The USIM may contain elementary files (EF) defining access conditions, data items and coding. In one example, the EF for forbidden PLMs (FPLMN) (EFFPLMN) contains the coding for n FPLMNs. It is read by the UE as part of the USIM initialization procedure and indicates PLMNs which the UE shall not automatically attempt to access. A PLMN is written to the EF if a network rejects a Location Update with the cause "PLMN not allowed" . The list of FPLMNs in the EF may be updated through an over the air (OTA) update by MNOs.
[0029] In a bidding down attack, the attacker may pose as a PLMN supporting 2G / 3G, e.g., as a fake base station (FBS) . Accordingly, it would be useful to the UE to have information regarding whether PLMNs / cells in the area should be avoided or may be trusted.
[0030] According to various example embodiments, solutions are provided for mitigating bidding down attacks on a UE when a 2G / 3G network of a PLMN is decommissioned. In the following example embodiments, the UE may be a 5G UE. The example embodiments are described with regard to scenarios in which a UE may be in an area where there is no legal 2G / 3G network. Therefore, any 2G / 3G networks are fake and the UE should be prevented from connecting to those networks. In various example embodiments, a UE is made aware of the information that there is no 2G / 3G network in this area. The example embodiments described herein include mechanisms for delivering this information to UE.
[0031] According to various example embodiments, a UE may receive information regarding the trustworthiness of PLMNs and / or cells of a 2G / 3G network and / or former 2G / 3G networks that have been decommissioned by a PLMN. In some aspects, the information may comprise a list of PLMNs that the UE should avoid, e.g., a decommissioned PLMN list. In other aspects, the information may comprise a list of cells that are either trusted or not trusted. The information for PLMNs and / or cells may be associated with a radio access technology, e.g., 2G or 3G, informing the UE that a 2G or 3G network is restricted for this PLMN. In cases where the PLMN deploys multiple networks, the UE may attempt to access those networks (e.g., 4G / 5G) that are not restricted.
[0032] Due to the sensitivity of this information, the information may be provided to the UE in a protected manner such that an attacker cannot read and / or modify the information. Additionally, the information and / or updates to the information may be provided as soon as possible, e.g., by signaling. In other cases, the information may be provided offline, e.g., in cases where a MNO has already decommissioned its entire 2G / 3G systems and the decommissioned PLMN and / or trusted / non-trusted cell information is not subject to frequent updates. Accordingly, the example embodiments describe various options for providing this information to a UE that considers urgency while maintaining protection of the information from third parties.
[0033] In some example embodiments, the UE may receive the information in NAS signaling, e.g., from the AMF, and updates may be provided to the UE if the AMF has reason to adjust the information. In other example embodiments, the UE may receive this information in a SIB, e.g., a protected SIB. In further example embodiments, the UE may receive this information in a UE configuration update or a TAU message from the AMF.
[0034] In still other example embodiments, the UE is pre-configured with the information, e.g., in a OS update procedure or during manufacture of the UE. In still further example embodiments, the UE may receive this information as part of the USIM initialization procedure that may occur when the EF is updated OTA.
[0035] In still other example embodiments, the UE may receive this information in a NAS security command. In still more example embodiments, the UE may receive this information in an AS security command.
[0036] In various example embodiments, the information may comprise a list of decommissioned PLMNs for the 2G / 3G network or a list of trusted / not trusted cells for the 2G / 3G network. Based on the information, if signals from a 2G or 3G network are detected that correspond to an entry in the list of decommissioned PLMNs for the 2G / 3G network; or are not included on the trusted list of cells for the 2G / 3G network, the UE may avoid selecting to the 2G or 3G network.
[0037] In a first aspect of these example embodiments, the UE may receive the indication of decommissioning the 2G / 3G from the network in a registration accept message from the AMF. In some example embodiments, a new IE may be added in the Registration Accept message comprising a “Decommissioned PLMN list” that includes a list of PLMNs decommissioned for 2G / 3G operations by a MNO. In other example embodiments, a new IE may be added in the Registration Accept message comprising a “Trusted 2G cell information” that includes a list of trusted 2G Cell IDs. In other example embodiments, a new IE may be added in the Registration Accept message comprising a “Not trusted 2G / 3G cell information” that includes a list of not trusted 2G or 3G Cell IDs. In still further example embodiments, multiple or all of these new IEs may be included in the Registration Accept.
[0038] Fig. 1a shows a signaling diagram 100 for indicating a list of PLMNs in which 2G or 3G has been decommissioned in a registration accept according to one example of these example embodiments. The signaling diagram 100 includes a UE 101, a RAN 102 (e.g., the 5G RAN) , the AMF 103, the UDM 104 and the AUSF 105.
[0039] In 110, the UE attempts to register with the AMF 103. In 115, the AMF 103 initiates authentication and security processes, e.g., the 5G AKA procedure.
[0040] In 120, the UE receives a registration accept from the AMF. The registration accept includes IEs comprising various information including, e.g., a 5G Globally Unique Temporary Identifier (GUTI) and network slice selection assistance information (NSSAI) . In this example, the registration accept further includes a new IE comprising a list of decommissioned PLMNs for the 2G / 3G network.
[0041] Fig. 1b shows a table 150 for information elements (IEs) included in a Registration Accept message sent by the AMF to a UE according to one example of these example embodiments. The table 150 includes a new IE 152 for “Decommissioned PLMN List” comprising a list of PLMNs decommissioned by the MNO. The IEs included in the Registration Accept message may also comprise an IE for a list of 2G trusted / not trusted cell IDs. The PLMNs / cells may further be associated with a RAT, e.g., 2G or 3G.
[0042] The first aspect described above may comprise a solution with regard to balancing security considerations with urgency considerations. The Registration Accept is the first message received by the UE after the 5G AKA is performed, and is thus fully protected by security keys, integrity protection, etc. Accordingly, it may be assumed that this message has not been tampered with by an attacker.
[0043] In a second aspect of the example embodiments, the UE receives the information / indication of decommissioning the 2G / 3G from the network in a SIB message. The current SIBs are defined as SIB1-4; SIB5 (if the UE supports E-UTRA) ; SIB6-10; SIB11 (if the UE is configured for idle / inactive measurements) ; SIB12 (if UE is capable of NR sidelink communication / discovery and is configured by upper layers to receive or transmit NR sidelink communication / discovery) ; SIB13, SIB14 (if UE is capable of V2X sidelink communication and is configured by upper layers to receive or transmit V2X sidelink communication) ; SIB15 (if UE is configured by upper layers to report disaster roaming related information) ; SIB16 (if the UE is capable of slice-based cell reselection and the UE receives NSAG information for cell reselection from upper layer) ; SIB17 (if the UE is using TRS resources for power saving in RRC_IDLE and RRC_INACTIVE) , SIB19 (if UE is accessing NR via NTN access) ; and SIB22 (for ATG access) .
[0044] In some examples, the decommissioned PLMN or trusted cell information may be provided by SIB 1, SIB3, SIB4, one of the reserved SIBs (e.g. SIB 23, 24, 25) , and / or a new SIB. Different SIBs may be broadcast periodically (e.g., at different intervals) or be on-demand. Thus, in some cases, the UE may be informed of this information and any changes to this information very quickly, e.g., if the information is included in SIBs 1, 3, or 4.
[0045] If the SIB is not protected, the security requirements may not be met according to current standards. However, some protections for SIB may be in current development or developed in the future. In one example, a signature may be added to the SIB to add protection, e.g., allow the UE to verify that the message is genuine.
[0046] Fig. 2 shows an example information element (IE) 200 included in a SIB message according to one example of these example embodiments. The IE 200 includes a DecommissionedPLMN-List-re16 comprising one or more DecommissionedPLMN.
[0047] After the UE is already registered to a PLMN, the serving network may have updated information, e.g., for 2G / 3G networks that have recently been decommissioned. The serving network may also stop using one of their networks temporarily. Thus, the UE may be notified to stop connecting to these networks. With regard to the first aspect described above, the AMF could deregister the UE so that the UE has to re-register and the updated information may be provided. With regard to the second aspect, a serving cell of the UE may be informed of the updated information such that the updated information may be provided in a subsequent SIB message.
[0048] In a third aspect of these example embodiments, the UE may receive the information in a NAS message. The information may be indicated by the network (e.g., AMF) in a NAS message sent in a UE configuration update or a TAU procedure.
[0049] In one aspect, the information may be indicated by the network (e.g., AMF) in a NAS message comprising a UE configuration update. In the UE configuration update command, the network may include the decommissioned PLMN list or trusted / not trusted 2G / 3G cell information.
[0050] Fig. 3a shows a signaling diagram 300 for indicating a list of PLMNs in which 2G or 3G has been decommissioned and / or a list of trusted / not trusted 2G / 3G cells in a UE configuration update according to one example of these example embodiments. The signaling diagram 300 includes a UE 301, a RAN 302 (e.g., the 5G RAN) , the AMF 303, the UDM 304 and the AUSF 305.
[0051] In 310, the UE 301 attempts to register with the AMF 303, similar to 110 of Fig. 1a. In 315, the AMF 303 initiates authentication and security processes, e.g., the 5G AKA procedure, similar to 110 of Fig. 1a.
[0052] In 320, the UE 301 receives a registration accept from the AMF 303. The registration accept includes IEs comprising various information including, e.g., a 5G Globally Unique Temporary Identifier (GUTI) and network slice selection assistance information (NSSAI) .
[0053] In 325, the UE 301 receives a UE configuration update from the AMF 303. The UE configuration update command may include IEs comprising updates to information provided earlier, e.g., in the registration accept, or may contain different IEs. In this example, the UE configuration update further includes a new IE comprising a list of PLMNs for which the 2G / 3G network has been decommissioned and / or a new IE comprising a list of trusted / not trusted 2G / 3G cells.
[0054] In 330, the UE 301 transmits a registration accept.
[0055] In another aspect, the information may be indicated by the network (e.g., AMF) in a NAS message comprising a TAU accept. In some example embodiments, the TAU message may include a TAI list that indicates which tracking areas are valid for 2G / 3G cells. In other example embodiments, if the 2G / 3G decommissioning are not per TAI, then one more IEs (Decommissioned PLMN list / trusted 2G / 3G cell list) may be added to the TAU accept message.
[0056] Fig. 3b shows a signaling diagram 350 for indicating a list of PLMNs in which 2G or 3G has been decommissioned and / or a list of trusted / not trusted 2G / 3G cells in a tracking area update (TAU) accept message according to one example of these example embodiments. The signaling diagram 350 includes a UE 351, a RAN 352 (e.g., the 5G RAN) , the AMF 353, the UDM 354 and the AUSF 355. Steps 360-370 of the signaling diagram 350 may be similar to the steps 310-320 of the signaling diagram 300 of Fig. 1a.
[0057] In 375, the UE 351 transmits a TAU request to the AMF 353. In 380, the UE 351 receives a TAU accept from the AMF 353. The TAU accept may include IEs comprising updates to tracking area information provided earlier or new information. In this example embodiment, the TAU accept further includes a new IE comprising a list of decommissioned PLMNs for the 2G / 3G network or a list of trusted 2G / 3G cells.
[0058] In a fourth aspect of the example embodiments, the UE receives the indication of decommissioning the 2G / 3G from the 5GS in a pre-configuration phase, e.g., offline. Thus, there is no impact on signaling. The network may notify UE vendors of the 2G / 3G information and the network vendor may implement this information into their devices.
[0059] This method is not as timely as the above example embodiments because the UE is not able to fetch the latest decommission information, which relies on the OS update procedure. Additionally, older devices may not be updated timely on the network deployment information relative to newer devices. Thus, this aspect may be used if, e.g., a MNO has decommissioned its entire 2G / 3G network, such that the information is not subject to frequent change.
[0060] In a fifth aspect of these example embodiments, a USIM profile of the UE is configured with the “forbidden PLMN list” . In one embodiment, the EFFPLMN contains the coding for n Forbidden PLMNs (FPLMN) to indicate PLMNs which the UE shall not automatically attempt to access. The EFFPLMN is read by the UE as part of the USIM initialization procedure. The EF may be updated through OTA by operators, so it may not be timely, but closely related with operators’ OTA plan. Fig. 4 shows a EFFPLMN 400 including a list of FPLMNs according to one example of these example embodiments.
[0061] In a sixth aspect of the example embodiments, the UE receives the indication of decommissioning the 2G / 3G in the NAS Security Mode Command.
[0062] A NAS Security command includes the replayed UE security capabilities, the selected NAS algorithms, and the ngKSI for identifying the KAM. A NAS security command may include K_AMF_change_flag (carried in the additional 5G security parameters IE specified in TS 24.501
[0035] ) to indicate a new KAMF is calculated, a flag requesting the complete initial NAS message (see subclause 6.4.6) , Anti-Bidding down Between Architectures (ABBA) parameter. In the case of horizontal derivation of KAMF during mobility registration update or during multiple registration in same PLMN, K_AMF_change_flag shall be included in the NAS Security Mode Command message as described in clause 6.9.3.
[0063] In these example embodiments, the NAS Security Mode command message may further include an indication of the decommissioned PLMN and / or trustworthy cell information for 2G / 3G networks. Accordingly, the information is included in a message that is integrity protected (but not ciphered) with NAS integrity key based on the KAMF indicated by the ngKSI in the NAS Security Mode Command message.
[0064] Fig. 5 shows a signaling diagram 500 for indicating a list of PLMNs in which 2G or 3G has been decommissioned and / or a list of trusted / not trusted 2G / 3G cells in a NAS security mode command according to one example of these example embodiments. The signaling diagram 500 includes a UE 501 and the AMF 502.
[0065] In 505, the AMF 502 starts integrity protection. In 510, the UE 501 receives a NAS security mode command from the AMF 502. The command may include various security related parameters. In this example, the command additionally includes an indication of decommissioned PLMNs for 2G / 3G.
[0066] In 515, the AMF 502 starts uplink deciphering. In 520, the UE 501 verifies NAS SMC integrity and starts uplink ciphering, downlink deciphering and integrity protection.
[0067] In 525, the UE 501 transmits a NAS security mode complete message. In 530, the AMF 502 starts downlink ciphering.
[0068] In a seventh aspect of the example embodiments, the UE receives the indication of decommissioning the 2G / 3G in the AS Security Mode Command. The AS security mode command message sent from the gNB / ng-eNB to the UE contains the selected RRC and UP encryption and integrity algorithms. In this example, the message further includes an indication of a decommission list: PLMN-2G / 3G. Accordingly, the information is included in a AS security mode command message that is integrity protected with RRC integrity key based on the current KgNB.
[0069] Fig. 6 shows a signaling diagram 600 for indicating a list of PLMNs in which 2G or 3G has been decommissioned and / or a list of trusted / not trusted 2G / 3G cells in an access stratum (AS) security mode command according to one example of these example embodiments. The signaling diagram 600 includes a UE 601 and a gNB 602. The gNB 602 may also be a ng-eNB.
[0070] In 605, the gNB 602 starts RRC integrity protection. In 610, the UE 601 receives an AS security mode command from the gNB 602. The command may include various security related parameters. In this example, the command additionally includes an indication of decommissioned PLMNs for 2G / 3G.
[0071] In 615, the gNB 602 starts RRC downlink ciphering. In 620, the UE 601 verifies AS SMC integrity and starts RRC integrity protection and RRC downlink deciphering.
[0072] In 625, the UE 601 transmits an AS security mode complete message. The message may include, e.g., MAC-1. In 630, the gNB 602 starts RRC uplink deciphering. In 635, the UE 601 starts RRC uplink ciphering.
[0073] Fig. 7 shows an example network arrangement 700 according to various example embodiments. The example network arrangement 700 includes a UE 710. The UE 710 may be any type of electronic component that is configured to communicate via a network, e.g., mobile phones, tablet computers, desktop computers, smartphones, embedded devices, wearables, Internet of Things (IoT) devices, etc. An actual network arrangement may include any number of UEs being used by any number of users. Thus, the example of one UE 710 is merely provided for illustrative purposes.
[0074] The UE 710 may be configured to communicate with one or more networks. In the example of the network arrangement 700, the network with which the UE 710 may wirelessly communicate is a 5G NR radio access network (RAN) 720. However, the UE 710 may also communicate with other types of networks (e.g., 5G cloud RAN, a next generation RAN (NG-RAN) , a legacy cellular network, etc. ) and the UE 710 may also communicate with networks over a wired connection. With regard to the example embodiments, the UE 710 may establish a connection with the 5G NR RAN 720. Therefore, the UE 710 may have a 5G NR chipset to communicate with the NR RAN 720.
[0075] The 5G NR RAN 720 may be portions of a cellular network that may be deployed by a network carrier (e.g., Verizon, AT&T, T-Mobile, etc. ) . The RAN 720 may include cells or base stations that are configured to send and receive traffic from UEs that are equipped with the appropriate cellular chip set. In this example, the 5G NR RAN 720 includes the gNB 720A and the gNB 720B. However, reference to a gNB is merely provided for illustrative purposes, any appropriate base station or cell may be deployed (e.g., Node Bs, eNodeBs, HeNBs, eNBs, gNBs, gNodeBs, macrocells, microcells, small cells, femtocells, etc. ) .
[0076] Any association procedure may be performed for the UE 710 to connect to the 5G NR RAN 720. For example, as discussed above, the 5G NR RAN 720 may be associated with a particular network carrier where the UE 710 and / or the user thereof has a contract and credential information (e.g., stored on a SIM card) . Upon detecting the presence of the 5G NR RAN 720, the UE 710 may transmit the corresponding credential information to associate with the 5G NR RAN 720. More specifically, the UE 710 may associate with a specific cell (e.g., gNB 720A) .
[0077] The network arrangement 700 also includes a cellular core network 730, the Internet 740, an IP Multimedia Subsystem (IMS) 750, and a network services backbone 760. The cellular core network 730 manages the traffic that flows between the cellular network and the Internet 740. The IMS 750 may be generally described as an architecture for delivering multimedia services to the UE 710 using the IP protocol. The IMS 750 may communicate with the cellular core network 730 and the Internet 740 to provide the multimedia services to the UE 710. The network services backbone 760 is in communication either directly or indirectly with the Internet 740 and the cellular core network 730. The network services backbone 760 may be generally described as a set of components (e.g., servers, network storage arrangements, etc. ) that implement a suite of services that may be used to extend the functionalities of the UE 710 in communication with the various networks.
[0078] Fig. 8 shows an example UE 710 according to various example embodiments. The UE 710 will be described with regard to the network arrangement 700 of Fig. 7. The UE 710 may represent any electronic device and may include a processor 805, a memory arrangement 810, a display device 815, an input / output (I / O) device 820, a transceiver 825, and other components 830. The other components 830 may include, for example, an audio input device, an audio output device, a battery that provides a limited power supply, a data acquisition device, ports to electrically connect the UE 710 to other electronic devices, sensors to detect conditions of the UE 710, etc.
[0079] The processor 805 may be configured to execute a plurality of engines for the UE 710. For example, the engines may include a security engine 835 for performing operations related to avoiding FBS attacks, as described in detail above.
[0080] The above referenced engine being an application (e.g., a program) executed by the processor 805 is only an example. The functionality associated with the engines may also be represented as a separate incorporated component of the UE 710 or may be a modular component coupled to the UE 710, e.g., an integrated circuit with or without firmware. For example, the integrated circuit may include input circuitry to receive signals and processing circuitry to process the signals and other information. The engines may also be embodied as one application or separate applications. In addition, in some UEs, the functionality described for the processor 805 is split among two or more processors such as a baseband processor and an applications processor. The example embodiments may be implemented in any of these or other configurations of a UE.
[0081] The memory arrangement 810 may be a hardware component configured to store data related to operations performed by the UE 710. The display device 815 may be a hardware component configured to show data to a user while the I / O device 820 may be a hardware component that enables the user to enter inputs. The display device 815 and the I / O device 820 may be separate components or integrated together such as a touchscreen.
[0082] The transceiver 825 may be a hardware component configured to establish a connection with the 5G NR-RAN 720, an LTE-RAN (not pictured) , a legacy RAN (not pictured) , a WLAN (not pictured) , etc. Accordingly, the transceiver 825 may operate on a variety of different frequencies or channels (e.g., set of consecutive frequencies) . The transceiver 825 includes circuitry configured to transmit and / or receive signals (e.g., control signals, data signals) . Such signals may be encoded with information implementing any one of the methods described herein. The processor 805 may be operably coupled to the transceiver 825 and configured to receive from and / or transmit signals to the transceiver 825. The processor 805 may be configured to encode and / or decode signals (e.g., signaling from a base station of a network) for implementing any one of the methods described herein.
[0083] Fig. 9 shows an example base station 900 according to various example embodiments. The base station 900 may represent the gNB 720A, the gNB 720B or any other access node through which the UE 710 may establish a connection and manage network operations. The base station 900 may operate as the MN or the SN as described in the examples above.
[0084] The base station 900 may include a processor 905, a memory arrangement 910, an input / output (I / O) device 915, a transceiver 920, and other components 925. The other components 925 may include, for example, an audio input device, an audio output device, a battery, a data acquisition device, ports to electrically connect the base station 500 to other electronic devices and / or power sources, etc.
[0085] The processor 905 may be configured to execute a plurality of engines for the UE 710. For example, the engines may include a security engine 930 for performing operations related to avoiding FBS attacks, as described in detail above.
[0086] The memory arrangement 910 may be a hardware component configured to store data related to operations performed by the base station 900. The I / O device 915 may be a hardware component or ports that enable a user to interact with the base station 900.
[0087] The transceiver 920 may be a hardware component configured to exchange data with the UE 710 and any other UE in the network arrangement 700. The transceiver 920 may operate on a variety of different frequencies or channels (e.g., set of consecutive frequencies) . The transceiver 920 includes circuitry configured to transmit and / or receive signals (e.g., control signals, data signals) . Such signals may be encoded with information implementing any one of the methods described herein. The processor 905 may be operably coupled to the transceiver 920 and configured to receive from and / or transmit signals to the transceiver 920. The processor 905 may be configured to encode and / or decode signals (e.g., signaling from a UE) for implementing any one of the methods described herein.
[0088] Examples
[0089] In a first example, a method, comprising processing, based on signals received from an access and mobility function (AMF) , a registration accept comprising at least one of a list of identifiers corresponding to decommissioned public land mobile network (PLMN) corresponding to a 2G or 3G network and a trusted list of cells corresponding to the 2G or 3G network and, when signals from a first 2G or 3G network are detected that either correspond to an entry in the list of identifiers of the decommissioned PLMNs corresponding to the 2G or 3G network or are not included on the trusted list of cells corresponding to the 2G or 3G network, avoid selection to the first 2G or 3G network.
[0090] In a second example, the method of the first example, wherein at least one of the list of identifiers of decommissioned PLMNs corresponding to the 2G or 3G network or the trusted list of cells corresponding to the 2G or 3G network is included in a new information element (IE) in the registration accept.
[0091] In a third example, a processor configured to perform any of the first or second examples.
[0092] In a fourth example, a user equipment (UE) comprising a transceiver configure to communicate with a network and a processor communicatively coupled to the transceiver and configured to perform any of the first or second examples.
[0093] In a fifth example, a method, comprising processing, based on signals received from a base station, a system information block (SIB) of a 5G system (5GS) comprising at least one of a list of identifiers corresponding to decommissioned public land mobile networks (PLMN) corresponding to a 2G or 3G network and a trusted list of cells corresponding to the 2G or 3G network, and, when signals from a first 2G or 3G network are detected that either correspond to an entry in the list of identifiers of the decommissioned PLMNs corresponding to the 2G or 3G network or are not included on the trusted list of cells corresponding to the 2G or 3G network, avoid selection to the first 2G or 3G network.
[0094] In a sixth example, the method of the fifth example, wherein the SIB comprises SIB1, SIB3, SIB4 or an other existing SIB.
[0095] In a seventh example, the method of the fifth example, wherein the SIB comprises reserved SIB 23, reserved SIB 24 or reserved SIB 25, or a new SIB.
[0096] In an eighth example, the method of the fifth example, wherein the SIB is protected by a signature.
[0097] In a ninth example, a processor configured to perform any of the fifth through eighth examples.
[0098] In a tenth example, a user equipment (UE) comprising a transceiver configure to communicate with a network and a processor communicatively coupled to the transceiver and configured to perform any of the fifth through eighth examples.
[0099] In an eleventh example, a method, comprising registering with an access and mobility function (AMF) of a 5G system (5GS) , processing, based on signals received from the AMF, a non-access stratum (NAS) message comprising at least one of a list of identifiers corresponding to decommissioned public land mobile networks (PLMN) corresponding to a 2G or 3G network and a trusted list of cells corresponding to the 2G or 3G network, and, when signals from a first 2G or 3G network are detected that either correspond to an entry in the list of identifiers of decommissioned PLMNs corresponding to the 2G or 3G network or are not included on the trusted list of cells corresponding to the 2G or 3G network, avoid selection to the first 2G or 3G network.
[0100] In a twelfth example, the method of the eleventh example, wherein the NAS message comprises a UE configuration update.
[0101] In a thirteenth example, the method of the twelfth example, wherein at least one of the list identifiers of decommissioned PLMNs corresponding to the 2G or 3G network or the trusted list of cells corresponding to the 2G or 3G network is included in a new information element (IE) in the UE configuration update.
[0102] In a fourteenth example, the method of the eleventh example, wherein the NAS message comprises a tracking area update accept (TAU) accept.
[0103] In a fifteenth example, the method of the fourteenth example, wherein at least one of the list of identifiers of decommissioned PLMNs corresponding to the 2G or 3G network or the trusted list of cells corresponding to the 2G or 3G network is included in a new information element (IE) in the TAU.
[0104] In a sixteenth example, the method of the eleventh example, wherein the NAS message comprises a non-access stratum (NAS) security command.
[0105] In a seventeenth example, a processor configured to perform any of the eleventh through sixteenth examples.
[0106] In an eighteenth example, a user equipment (UE) comprising a transceiver configure to communicate with a network and a processor communicatively coupled to the transceiver and configured to perform any of the eleventh through sixteenth examples.
[0107] In a nineteenth example, a method, comprising attempting to access a 5G system (5GS) , and, when signals from a first 2G or 3G network are detected that either correspond to an entry in a pre-configured list of identifiers corresponding to decommissioned public land mobile networks (PLMN) corresponding to the 2G or 3G network or are not included on a pre-configured trusted list of cells corresponding to the 2G or 3G network, avoid selection to the first 2G or 3G network.
[0108] In a twentieth example, a processor configured to perform the nineteenth example.
[0109] In a twenty first example, a user equipment (UE) comprising a transceiver configure to communicate with a network and a processor communicatively coupled to the transceiver and configured to perform the nineteenth example.
[0110] In a twenty second example, a method, comprising activating a universal subscriber identity module (USIM) for accessing a 5G system (5GS) , reading an elementary file for forbidden Public Land Mobile Networks (EFFPLMN) as part of USIM initialization, the EFFPLMN including a list of identifiers corresponding to forbidden public land mobile networks (FPLMN) and, when signals from a 2G or 3G network are detected that correspond to an entry in the list of identifiers of the FPLMNs, avoid selection to the detected 2G or 3G network.
[0111] In a twenty third example, the method of the twenty second example, further comprising processing, based on signals received in an over the air (OTA) update, updated EF information including an updated list of PLMNs.
[0112] In a twenty fourth example, a processor configured to perform any of the twenty second or twenty third examples.
[0113] In a twenty fifth example, a user equipment (UE) comprising a transceiver configure to communicate with a network and a processor communicatively coupled to the transceiver and configured to perform any of the twenty second or twenty third examples.
[0114] In a twenty sixth example, a method, comprising processing, based on signals received from a base station of a 5G system (5GS) , an access stratum (AS) security command comprising at least one of a list of identifiers corresponding to decommissioned public land mobile networks (PLMN) corresponding to a 2G or 3G network and a trusted list of cells corresponding to the 2G or 3G network, and, when signals from a 2G or 3G network are detected that either correspond to an entry in the list of identifiers of decommissioned PLMNs or are not included on the trusted list of cells, avoid selection to the detected 2G or 3G network.
[0115] In a twenty seventh example, a processor configured to perform the twenty sixth example.
[0116] In a twenty eighth example, a user equipment (UE) comprising a transceiver configure to communicate with a network and a processor communicatively coupled to the transceiver and configured to perform the twenty sixth example.
[0117] Those skilled in the art will understand that the above-described example embodiments may be implemented in any suitable software or hardware configuration or combination thereof. An example hardware platform for implementing the example embodiments may include, for example, an Intel x86 based platform with compatible operating system, a Windows OS, a Mac platform and MAC OS, a mobile device having an operating system such as iOS, Android, etc. The example embodiments of the above described method may be embodied as a program containing lines of code stored on a non-transitory computer readable storage medium that, when compiled, may be executed on a processor or microprocessor.
[0118] Although this application described various embodiments each having different features in various combinations, those skilled in the art will understand that any of the features of one embodiment may be combined with the features of the other embodiments in any manner not specifically disclaimed or which is not functionally or logically inconsistent with the operation of the device or the stated functions of the disclosed embodiments.
[0119] It is well understood that the use of personally identifiable information should follow privacy policies and practices that are generally recognized as meeting or exceeding industry or governmental requirements for maintaining the privacy of users. In particular, personally identifiable information data should be managed and handled so as to minimize risks of unintentional or unauthorized access or use, and the nature of authorized use should be clearly indicated to users.
[0120] It will be apparent to those skilled in the art that various modifications may be made in the present disclosure, without departing from the spirit or the scope of the disclosure. Thus, it is intended that the present disclosure cover modifications and variations of this disclosure provided they come within the scope of the appended claims and their equivalent.
Claims
1.An apparatus comprising processing circuitry configured to:process, based on signals received from an access and mobility function (AMF) , a registration accept comprising at least one of a list of identifiers corresponding to decommissioned public land mobile network (PLMN) corresponding to a 2G or 3G network and a trusted list of cells corresponding to the 2G or 3G network; andwhen signals from a first 2G or 3G network are detected that either correspond to an entry in the list of identifiers of the decommissioned PLMNs corresponding to the 2G or 3G network or are not included on the trusted list of cells corresponding to the 2G or 3G network, avoid selection to the first 2G or 3G network.2.The apparatus of claim 1, wherein at least one of the list of identifiers of decommissioned PLMNs corresponding to the 2G or 3G network or the trusted list of cells corresponding to the 2G or 3G network is included in a new information element (IE) in the registration accept.3.An apparatus comprising processing circuitry configured to:process, based on signals received from a base station, a system information block (SIB) of a 5G system (5GS) comprising at least one of a list of identifiers corresponding to decommissioned public land mobile networks (PLMN) corresponding to a 2G or 3G network and a trusted list of cells corresponding to the 2G or 3G network; andwhen signals from a first 2G or 3G network are detected that either correspond to an entry in the list of identifiers of the decommissioned PLMNs corresponding to the 2G or 3G network or are not included on the trusted list of cells corresponding to the 2G or 3G network, avoid selection to the first 2G or 3G network.4.The apparatus of claim 3, wherein the SIB comprises SIB1, SIB3, SIB4 or an other existing SIB.5.The apparatus of claim 3, wherein the SIB comprises reserved SIB 23, reserved SIB 24 or reserved SIB 25, or a new SIB.6.The apparatus of claim 3, wherein the SIB is protected by a signature.7.An apparatus comprising processing circuitry configured to:register with an access and mobility function (AMF) of a 5G system (5GS) ;process, based on signals received from the AMF, a non-access stratum (NAS) message comprising at least one of a list of identifiers corresponding to decommissioned public land mobile networks (PLMN) corresponding to a 2G or 3G network and a trusted list of cells corresponding to the 2G or 3G network; andwhen signals from a first 2G or 3G network are detected that either correspond to an entry in the list of identifiers of decommissioned PLMNs corresponding to the 2G or 3G network or are not included on the trusted list of cells corresponding to the 2G or 3G network, avoid selection to the first 2G or 3G network.8.The apparatus of claim 7, wherein the NAS message comprises a UE configuration update.9.The apparatus of claim 8, wherein at least one of the list identifiers of decommissioned PLMNs corresponding to the 2G or 3G network or the trusted list of cells corresponding to the 2G or 3G network is included in a new information element (IE) in the UE configuration update.10.The apparatus of claim 7, wherein the NAS message comprises a tracking area update accept (TAU) accept.11.The apparatus of claim 10, wherein at least one of the list of identifiers of decommissioned PLMNs corresponding to the 2G or 3G network or the trusted list of cells corresponding to the 2G or 3G network is included in a new information element (IE) in the TAU.12.The apparatus of claim 7, wherein the NAS message comprises a non-access stratum (NAS) security command.
Citation Information
Patent Citations
Method for selecting public land mobile network (PLMN), and apparatus and device thereof
CN105393603A
Reminding method and device for network security
CN106714173A
Network authorization assistance
CN109314916A
Autonomous learning and geographic-based energy efficient network communication
US20200037237A1