Protection of UDP options for media related information

By reusing the QUIC layer's security context for UDP-Connect packets to encrypt and decrypt MRI within UDP Options, the method ensures secure end-to-end protection for MRI, addressing vulnerabilities in existing solutions and enhancing security for individual flows.

WO2025218963A1PCT designated stage Publication Date: 2025-10-23LENOVO INT COÖPERATIEF U A
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/056229
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-02-07
Filing Date
2025-03-07
Publication Date
2025-10-23

AI Technical Summary

Technical Problem

Existing solutions fail to provide secure end-to-end protection for Media Related Information (MRI) exchanged between Application Server (AS) and User Plane Function (UPF) using Transport options for UDP, as security keys cannot be negotiated effectively, leaving individual flows vulnerable to side channel attacks.

Method used

Implementing a method where the AS and UPF reuse the same security context established for UDP-Connect packets, using the QUIC layer for encryption and decryption of MRI within UDP Options, ensuring the same cipher suite and derived keys are used for both types of packets.

Benefits of technology

Provides secure end-to-end protection for MRI by ensuring the same security keys are used for both UDP-Connect packets and UDP Options, thereby safeguarding against side channel attacks and enhancing the security of individual flows within TLS tunnels.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025056229_23102025_PF_FP_ABST
    Figure EP2025056229_23102025_PF_FP_ABST
Patent Text Reader

Abstract

Various aspects of the present disclosure relate to network equipment comprising a memory and a processor coupled with the memory and configured to cause the network equipment to receive a Connect-UDP Establishment Request Message over an established QUIC connection with TLS protocol, provide a UPD Options information element with a Media Related Information, MRI, to a QUIC Layer, for encryption with a Connect-UDP security context, and, at the QUIC layer, encrypt content of the UPD Options information element to obtain an UPD Options information element with encrypted content. The processor is further configured to append the UDP Options information element with encrypted content to an encrypted Connect-UDP packet, and send the encrypted Connect-UDP packet with the UDP Options information element with encrypted content.
Need to check novelty before this filing date? Find Prior Art

Description

PROTECTION OF UDP OPTIONS FOR MEDIA RELATED INFORMATIONTECHNICAL FIELD

[0001] The present disclosure relates to wireless communications and more specifically to the protection of User Datagram Protocol (UDP) options for media related information.BACKGROUND

[0002] A wireless communications system may include one or multiple network communication devices, such as base stations, which may support wireless communications for one or multiple user communication devices, which may be otherwise known as user equipment (UE), or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like). Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G)).SUMMARY

[0003] An article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” may be interchangeable. As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of’ or “one or more of’ or “one or both of’) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein,the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on. Further, as used herein, including in the claims, a “set” may include one or more elements.

[0004] Some implementations of the method and apparatuses described herein may further include network equipment comprising at least one memory and at least one processor coupled with the at least one memory and configured to cause the network equipment to receive a Connect-UDP Establishment Request Message over an established QUIC connection with Transport Layer Security, TLS, protocol, provide a UPD Options information element with a Media Related Information, MRI, to a QUIC Layer, for encryption with a Connect-UDP security context, and, at the QUIC layer, encrypt content of the UPD Options information element to obtain an UPD Options information element with encrypted content. The at least one processor is further configured to cause the network equipment to receive from the QUIC layer the UDP Options information element with encrypted content and an encrypted Connect-UDP packet, append the UDP Options information element with encrypted content to an encrypted Connect-UDP packet, and send the encrypted Connect-UDP packet with the UDP Options information element with encrypted content.

[0005] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network equipment to encrypt content of the UPD Options information element with a cipher suite that is the same as a cipher suite used to obtain the encrypted Connect-UDP packet.

[0006] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network equipment to send a UDP Echo Request message, wherein a token field of the UDP Echo Request message contains an Encryption Service Indication to indicate that subsequent downlink packets include a UPD Options information element with encrypted MRI content, and receive a UDP Echo Response message, wherein a token field of the UDP Echo Response message includes the Encryption Service Indication.

[0007] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network equipment to generate a nonce value and associate the nonce with the Connect-UDP Establishment Request Message, obtain asession key using the nonce and provide the session key to the QUIC layer, send a UDP Echo Request message, wherein a token field of the UDP Echo Request message contains the nonce, and receive a UDP Echo Response message, wherein a token field of the UDP Echo Response message includes the nonce.

[0008] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network to, at the QUIC layer, encrypt content of the UPD Options information element using the session key to obtain an encrypted UPD Options information element.

[0009] In some implementations of the method and apparatuses described herein, the nonce value is a pseudo-random number.

[0010] In some implementations of the method and apparatuses described herein, the nonce value has a length of 4 bytes.

[0011] In some implementations of the method and apparatuses described herein, the at least one processor is configured to operate the network equipment as an Application Server.

[0012] In some implementations of the method and apparatuses described herein, the Connect-UDP Establishment Request Message is associated with an Extended Reality and Media, XRM, service.

[0013] In some implementations of the method and apparatuses described herein, the Connect-UDP Establishment Request Message is received from a User Plane Function, and the encrypted Connect-UDP packet with the UDP Options information element with encrypted content is sent to that User Plane Function.

[0014] Some implementations of the method and apparatuses described herein may further include a network equipment comprising at least one memory and at least one processor coupled with the at least one memory and configured to cause the network equipment to send a Connect-UDP Establishment Request Message over an established QUIC connection with Transport Layer Security, TLS, protocol, receive an encrypted Connect-UDP packet with an appended UDP Options information element with encrypted content, the encrypted content of the UDP Options information element including encrypted Media Related Information, MRI, content, and provide the UPD Options information element with encrypted Media Related Information, MRI content, to a QUIC Layer, for decryption with a Connect-UDP security context. The at least one processor is further configured tocause the network equipment to, at the QUIC layer, decrypt the encrypted content of the UPD Options information element to obtain a decrypted content of the UPD Options information element, and receive from the QUIC layer the decrypted content of the UDP Options information element.

[0015] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network equipment to decrypt the encrypted content of the UDP Options information element with a cipher suite that is the same as a cipher suite used to obtain a decrypted Connect-UDP packet.

[0016] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network equipment to receive a UDP Echo Request message, wherein a token field of the UDP Echo Request message contains an Encryption Service Indication to indicate that subsequent downlink packets include a UPD Options information element with encrypted MRI content, and send a UDP Echo Response message, wherein a token field of the UDP Echo Response message includes the Encryption Service Indication.

[0017] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network equipment to receive a UDP Echo Request message, wherein a token field of the UDP Echo Request message contains a nonce value and associate the nonce with the Connect-UDP Establishment Request Message, obtain a session key using the nonce and provide the session key to the QUIC layer, and send a UDP Echo Response message, wherein a token field of the UDP Echo Response message includes the nonce.

[0018] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network to, at the QUIC layer, decrypt the encrypted content of the UPD Options information element using the session key to obtain an decrypted content of the UPD Options information element.

[0019] In some implementations of the method and apparatuses described herein, the nonce value is a pseudo-random number.

[0020] In some implementations of the method and apparatuses described herein, the at least one processor is configured to operate the network equipment as a User Plane Function.

[0021] In some implementations of the method and apparatuses described herein, the Connect-UDP Establishment Request Message is sent to an Application Server, and the encrypted Connect-UDP packet with the UDP Options information element with encrypted content is received from that Application Server.

[0022] Some implementations of the method and apparatuses described herein may further include a method performed by a network equipment and comprising receiving a Connect-UDP Establishment Request Message over an established QUIC connection with Transport Layer Security, TLS, protocol, providing a UPD Options information element with a Media Related Information, MRI, to a QUIC Layer, for encryption with a Connect-UDP security context, at the QUIC layer, encrypting the content of the UPD Options information element to obtain a UPD Options information element with encrypted content, and receiving from the QUIC layer the UDP Options information element with encrypted content and an encrypted Connect-UDP packet. The method further comprises appending the UDP Options information element with encrypted content to an encrypted Connect-UDP packet, and sending the encrypted Connect-UDP packet with the UDP Options information element with encrypted content.

[0023] Some implementations of the method and apparatuses described herein may further include a method performed by a network equipment and comprising sending a Connect-UDP Establishment Request Message over an established QUIC connection with Transport Layer Security, TLS, protocol, receiving an encrypted Connect-UDP packet with an appended UDP Options information element with encrypted content, the encrypted content of the UDP Options information element including an encrypted Media Related Information, MRI, content, providing the UPD Options information element with encrypted Media Related Information, MRI, content to a QUIC Layer, for decryption with a Connect- UDP security context and, at the QUIC layer, decrypting the content of the UPD Options information element to obtain a decrypted Media Related Information, MRI, content of the UPD Options information element. The method further comprises receiving from the QUIC layer the decrypted Media Related Information, MRI, content of the UDP Options information element.BRIEF DESCRIPTION OF THE DRAWINGS

[0024] Figure 1 illustrates the structure of a UDP datagram including payload, with attached UDP-Option header including Media Related Information (MRI);

[0025] Figure 2 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.

[0026] Figure 3 illustrates a process providing protection for MRI of the UDP datagram of Figure 1, according to a first embodiment;

[0027] Figure 4 illustrates a process providing protection for MRI of the UDP datagram of Figure 1, according to a second embodiment;

[0028] Figure 5 illustrates a process providing protection for MRI of the UDP datagram of Figure 1, according to a third embodiment;

[0029] Figure 6 illustrates an example of a network equipment (NE) 600 in accordance with aspects of the present disclosure;

[0030] Figure 7 illustrates a flowchart of a method performed by a NE in accordance with aspects of the present disclosure; and

[0031] Figure 8 illustrates a flowchart of a method performed by a NE in accordance with other aspects of the present disclosure.DETAILED DESCRIPTION

[0032] Extended reality is a term commonly used to refer to real and virtual combined environments generated by computer systems including wearables. The 3GPP SA2 working group has studied enhancements for the support of Extended Reality and Media service (XRM) in the Rel-19 study FS_XRM_Ph2. The study item results are documented in TS 23.501. The study identified Media Related Information (MRI), i.e., PDU Set and dynamic traffic characteristics information, for end-to-end encrypted XRM traffic and one or more encapsulation protocol options to support relaying MRI over N6 reference point (that is the demarcation point between mobile devices and the Internet) of the 3GPP architecture. The one or more encapsulation protocol options include1) Media over QUIC Transport (MoQT) [Media over QUIC (MoQ), IETF draft-ietf- moq-transport];2) Proxying-UDP-in-HTTP / 3 [Connect-UDP for Using Proxying-UDP-in-HTTP, IETF RFC 9298] and QUIC-Aware Proxying [QUIC-Aware Proxy, IETF draft-ietf- masque-quic-proxy]; and3) Transport options for UDP [IETF draft-ietf-tsvwg-udp-options: "Transport options for UDP"].

[0033] In the case of option 3), the inner UDP datagrams contain the unmodified pay load for both uplink, UL, and downlink, DL traffic and the MRI is included in the UDP option of the DL outer UDP datagram. The MRI in the outer UDP packet requires protection and the provision of matching security keys in the User Plane Function (UPF) and Application Server (AS) (proxy) for setting up the secure Transport Layer Security (TLS) connection. TS 23.501 (as incorporated herein) includes a (Editor) note stating that the security keys for UDP-Option can be negotiated using connect-udp upgrade token in tunneled mode between the UPF and AS proxy and that the implementation details are according to SA WG3 (3 GPP group).

[0034] A potential issue with this approach is that security keys cannot be negotiated using the token mechanism defined in the “Transport options for UDP” draft, as suggested in the Editor’s Note, since the request-response pair needs to have the same value of the token and the token size is 4 bytes long.

[0035] There is currently no solution to provision the same security keys in the UPF and the AS. The existing solutions considered in TS 33.501 [3GPP TS 33.501 V19.1.0 (2025- 01) “Security architecture and procedures for 5G system (Release 19)”] are related either to network domain security or Service Based Interfaces (SBI). Whilst TS 33.501 includes a clause “12.3 Protection of the NEF - AF interface” which could be reused for the UPF-AS reference point, i.e., network domain security based on TLS and pre-provisioned certificates, this would result in a single, large TLS tunnel to transport all XRM traffic and the individual flows which might not be secure against side channel attacks, since the MRI of the individual flows are still unprotected within the tunnel.

[0036] Figure 1 illustrates schematically the structure of a UDP datagram including payload, with attached UDP-Option header including Media Related Information (MRI), such as is exchanged between the AS and the UPF. As already noted there is currently nosolution to protect the MRI in the UDP-Options , end-to-end, and there is also no solution for setting-up the same security keys in the UPF and the AS for this purpose.

[0037] The solution discussed below provides a means to protect the MRI exchanged end-to-end between the AS and the UPF. In particular it provides a means to agree upon the use of shared security keys to encrypt the MRI. The solution is convenient and lightweight and reuses, as far as possible, already established mechanisms.

[0038] Aspects of the present disclosure are described in the context of a wireless communications system further described with reference to Figure 2.

[0039] Figure 2 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more NE 102, one or more UE 104, and a core network (CN) 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LIE- Advanced (LIE- A) network. In some other implementations, the wireless communications system 100 may be a NR network, such as a 5G network, a 5G- Advanced (5G-A) network, or a 5G ultrawideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA), etc.

[0040] The one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NE 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, a radio access network (RAN), a NodeB, an eNodeB (eNB), a next-generation NodeB (gNB), or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link, which may be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.

[0041] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For example, an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102.

[0042] The one or more UE 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Internet-of- Things (loT) device, an Internet-of-Everything (loE) device, or machine-type communication (MTC) device, among other examples.

[0043] A UE 104 may be able to support wireless communication directly with other UEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to- everything (V2X) deployments, or cellular-V2X deployments, the communication link may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.

[0044] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., SI, N2, N2, or network interface). In some implementations, the NE 102 may communicate with each other directly. In some other implementations, the NE 102 may communicate with each other or indirectly (e.g., via the CN 106. In some implementations, one or more NE 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC).An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as a radio heads, smart radio heads, or transmission-reception points (TRPs).

[0045] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC), or a 5G core (5GC), which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME), an access and mobility management functions (AMF)) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW), a Packet Data Network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for the one or more UEs 104 served by the one or more NE 102 associated with the CN 106.

[0046] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g., via an SI, N2, N2, or another network interface). The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g., a protocol data unit (PDU) session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g., control information, data, and the like) between the UE 104 and the application server using the established session (e.g., the established PDU session). The PDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g., one or more network functions of the CN 106).

[0047] In the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communications). In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104 may support various frame structures (i.e., multiple frame structures).The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.

[0048] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., / r=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., / r=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., / r=l) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., / r=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., / r=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., / r=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.

[0049] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames). Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.

[0050] Additionally, or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e., / r=0, jU=l, / r=2, jU=3, / r=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extendedcyclic prefix (e.g., applicable for 60 kHz subcarrier spacing), a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., / r =0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.

[0051] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data). In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.

[0052] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies). For example, FR1 may be associated with a first numerology (e.g., / r=0), which includes 15 kHz subcarrier spacing; a second numerology (e.g., / z=l), which includes 30 kHz subcarrier spacing; and a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies). For example, FR2 may be associated with a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., / r=3), which includes 120 kHz subcarrier spacing.

[0053] In the context of the following description of exemplary embodiments, QUIC encryption Service refers to the reuse of the API of the QUIC layer and indicates that the content (i.e., media related information) to be carried by means of UDP Options is provided to the QUIC Layer as input for encryption and decryption with the selected cipher suite, including the respective security keys, in the same way as for the Connect-UDP packets. Thecontent (i. e. , MRI) ciphertext is transported in the UDP option for MRI transported alongside the UDP datagram encapsulating the associated Connect-UDP packet.

[0054] Figure 3 illustrates schematically a solution for protecting MRI in accordance with aspects of the present disclosure. The Figure illustrates a UPF implemented in a network equipment 300 and an AS implemented in a network equipment 302. The solution relies upon UDP Options content encryption with reuse of QUIC layer without key separation. Specifically, the AS and the UPF reuse the same security context established for the UDP- Connect packets, for encrypting the MRI in the UDP Options. There is thus no separate key derivation for the protection of the content of the UDP Options (MRI). Figure 3 illustrates the following procedure to protect the content of the UDP Options:1. It is assumed that the UPF and the AS are pre-provisioned with a pre-shared certificate or a pre-shared key for the TUS connection in the QUIC layer. The AS establishes a Connect UDP session as per RFC 9298 with the UPF.2. The QUIC layer is used as encryption service for performing the UDP Options content encryption at the AS side and the decryption at the UPF side. The encryption service at the QUIC layer uses the same cipher suite as for the UDP-Connect packets with the same derived keys as for the UDP-Connect packets.3. The AS sends the protected QUIC packet in a UDP packet and “piggybacks” the encrypted content (with the MRI) in the UDP Options on the UDP packet.4. The UPF decrypts the QUIC packet and the UDP Options content separately using the encryption service at the QUIC layer.

[0055] Figure 4 illustrates schematically an alternative solution for protecting MRI in accordance with aspects of the present disclosure. The Figure illustrates a UPF implemented in a network equipment 400 and an AS implemented in a network equipment 402. The solution again relies upon using the cipher suite of the QUIC layer for the Connect-UDP also for the content of the UDP Options. Figure 4 illustrates the following procedure to protect the content of the UDP Options:1. It is assumed that the UPF and the AS are pre-provisioned with a pre-shared certificate or a pre-shared key for the TUS connection in the QUIC layer. The AS establishes a Connect UDP session as per RFC 9298 with the UPF.2. The QUIC layer is used as the encryption service for performing the UDP Options content encryption at the AS side and the decryption at the UPF side. The encryption service at the QUIC layer uses the same cipher suite as for the UDP-Connect packets with the same derived keys as for the UDP-Connect packets. The AS selects “Encryption Service Indication” for the token in the ECHO messages. The Encryption Service Indication may be coded in a predefined format in order to inform the UPF that the subsequent downlink packets will have piggybacked encrypted MRI in the UDP Options.3. The AS sends a UDP Echo Request in the UDP Options and includes the token: “Encryption Service Indication”.4. The UPF receives the token; “Encryption Service Indication”, and uses for the subsequently received UDP Options the QUIC Layer to decrypt the content of the UDP Options.5. The UPF replays the token; “Encryption Service Indication”, in a UDP Echo Response to the AS.6. The AS sends the protected QUIC packet in a UDP packet and piggybacks the encrypted content (with the MRI) in the UDP Options. The UPF decrypts the QUIC packet and the UDP Options content separately using the encryption service at the QUIC layer.

[0056] Figure 5 illustrates schematically a further alternative solution for protecting MRI in accordance with aspects of the present disclosure. The Figure illustrates a UPF implemented in a network equipment 500 and an AS implemented in a network equipment 502.

[0057] According to the illustrated solution, at the time of the UDP-Connect session establishment, the AS sends an Echo request message to the UPF according to IETF draft- ietf-tsvwg-udp-options. This Echo request REQ contains a 4 byte token which is used as a “Nonce”. The Nonce is used for freshness and to distinguish the security keys between the XRM connections. The Nonce may be a (pseudo) random number generated by the AS and which is likely to be unique among all simultaneously ongoing XRM connections of the AS and the particular UPF. The AS and the UPF use the Nonce to derive the security key for encrypting the UDP Options content with the MRI. The QUIC layer is used as an encryptionservice for performing the encryption at the AS side and the decryption at the UPF side. The encryption service at the QUIC layer may use the same cipher suite as for the UDP-Connect packets.

[0058] Figure 5 illustrates the following procedure to protect the UDP Options content:1. It is assumed that the UPF and the AS are pre-provisioned with a shared secret, i.e., a security root key. This root key is not directly used for protecting a specific connection, but rather is used as input to derive further session keys for each of the XRM connections. The AS establishes a Connect UDP session as per RFC 9298 with the UPF.2. The AS generates a Nonce, which may be a (pseudo) random number and unique within all the connections between the AS and a particular UPF. The Nonce may have the length of 4 bytes so that it fits into the token parameter of the UDP Echo messages. The AS generates a session key based on the pre-shared root key, e.g. session key = KDF(Root key, Nonce). The Key Derivation Function (KDF) may use additional inputs other than the Nonce, e.g. AS name, IP addresses of the AS and / or UPF etc.3. The AS sends a UDP Echo Request in the UDP Options and includes the Nonce in the token field.4. The UPF uses the Nonce in the token field and generates the session key based on the pre-shared root key and the Nonce in the similar way as the AS.5. The UPF sends a UDP Echo Response to the AS with the Nonce in the token field. The Nonce can be also used as a key identifier for the different XRM connections of different UEs as the same UPF and AS. The AS can interpret the reception of the replayed Nonce as an acknowledgment that the UPF derived the session security key in the same way as the AS.6. As part of the Connect UDP Session Establishment in step 1, the UPF and the AS setup a QUIC connection with TLS. The derived session key is provided to the QUIC layer for potentially further key derivations depending on the selected cipher suite for encrypting the UDP Options content with the MRI. The QUIC layer is used as encryption service for performing the encryption at the AS side and the decryption at the UPF side. The encryption service at the QUIC layer may use the same ciphersuite as for the UDP-Connect packets. The AS sends now the protected QUIC packet in an UDP packet and piggybacks the encrypted content (with the MRI) in the UDP Options. The UPF decrypts the QUIC packet and the UDP Options content separately.

[0059] Figure 6 illustrates an example of a Network Equipment [NE] 600 in accordance with aspects of the present disclosure. The NE 600 may include a processor 602, a memory 604, a controller 606, and a transceiver 608. The processor 602, the memory 604, the controller 606, or the transceiver 608, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0060] The processor 602, the memory 604, the controller 606, or the transceiver 608, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.

[0061] The processor 602 may include an intelligent hardware device (e.g., a general- purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 602 may be configured to operate the memory 604. In some other implementations, the memory 604 may be integrated into the processor 602. The processor 602 may be configured to execute computer-readable instructions stored in the memory 604 to cause the NE 600 to perform various functions of the present disclosure.

[0062] The memory 604 may include volatile or non-volatile memory. The memory 604 may store computer-readable, computer-executable code including instructions when executed by the processor 602 cause the NE 600 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 604 or another type of memory. Computer-readable media includes both non- transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storagemedium may be any available medium that may be accessed by a general-purpose or specialpurpose computer.

[0063] In some implementations, the processor 602 and the memory 604 coupled with the processor 602 may be configured to cause the NE 600 to perform one or more of the functions described herein (e.g., executing, by the processor 602, instructions stored in the memory 604). For example, the processor 602 may support wireless communication at the NE 600 in accordance with examples as disclosed herein. The NE 600 may be configured to support a means for receiving a Connect-UDP Establishment Request Message over an established QUIC connection with Transport Layer Security, TLS, protocol, providing a UPD Options information element with a Media Related Information, MRI, to a QUIC Layer, for encryption with a Connect-UDP security context, at the QUIC layer, encrypting the content of the UPD Options information element to obtain an UPD Options information element with encrypted content, receiving from the QUIC layer the UDP Options information element with encrypted content and an encrypted Connect-UDP packet, appending the UDP Options information element with encrypted content to an encrypted Connect-UDP packet, and sending the encrypted Connect-UDP packet with the UDP Options information element with encrypted content.

[0064] The NE 600 may be configured to support a means for causing the network equipment to encrypt content of the UPD Options information element with a cipher suite that is the same as a cipher suite used to obtain the encrypted Connect-UDP packet.

[0065] The NE 600 may be configured to support a means for causing the network equipment to send a UDP Echo Request message, wherein a token field of the UDP Echo Request message contains an Encryption Service Indication to indicate that subsequent downlink packets include an UPD Options information element with encrypted MRI content, and receive a UDP Echo Response message, wherein a token field of the UDP Echo Response message includes the Encryption Service Indication.

[0066] The NE 600 may be configured to support a means for causing the network equipment to generate a nonce value and associate the nonce with the Connect-UDP Establishment Request Message, obtain a session key using the nonce and provide the session key to the QUIC layer, send a UDP Echo Request message, wherein a token field of the UDPEcho Request message contains the nonce, and receive a UDP Echo Response message, wherein a token field of the UDP Echo Response message includes the nonce.

[0067] The NE 600 may be configured to support a means for causing the network to, at the QUIC layer, encrypt content of the UPD Options information element using the session key to obtain an encrypted UPD Options information element.

[0068] The NE 600 may be configured to support a means, wherein the nonce value is a pseudo-random number.

[0069] The NE 600 may be configured to support a means, wherein the nonce value has a length of 4 bytes.

[0070] The NE 600 may be configured to support a means for operating the network equipment as an Application Server.

[0071] The NE 600 may be configured to support a means, wherein the Connect-UDP Establishment Request Message is associated with an Extended Reality and Media, XRM, service.

[0072] The NE 600 may be configured to support a means, wherein the Connect-UDP Establishment Request Message is received from a User Plane Function, and the encrypted Connect-UDP packet with the UDP Options information element with encrypted content is sent to that User Plane Function.

[0073] The NE 600 may be configured to support a means for sending a Connect-UDP Establishment Request Message over an established QUIC connection with Transport Layer Security, TLS, protocol, receiving an encrypted Connect-UDP packet with an appended UDP Options information element with encrypted content, the encrypted content of the UDP Options information element including encrypted Media Related Information, MRI, content, providing the UPD Options information element with encrypted Media Related Information, MRI content, to a QUIC Layer, for decryption with a Connect-UDP security context, at the QUIC layer, decrypting the encrypted content of the UPD Options information element to obtain a decrypted content of the UPD Options information element, and receiving from the QUIC layer the decrypted content of the UDP Options information element.

[0074] The NE 600 may be configured to support a means for causing the network equipment to decrypt the encrypted content of the UDP Options information element with a cipher suite that is the same as a cipher suite used to obtain a decrypted Connect-UDP packet.

[0075] The NE 600 may be configured to support a means for receiving a UDP Echo Request message, wherein a token field of the UDP Echo Request message contains an Encryption Service Indication to indicate that subsequent downlink packets include a UPD Options information element with encrypted MRI content, and sending a UDP Echo Response message, wherein a token field of the UDP Echo Response message includes the Encryption Service Indication.

[0076] The NE 600 may be configured to support a means for causing the network equipment to receive a UDP Echo Request message, wherein a token field of the UDP Echo Request message contains a nonce value and associate the nonce with the Connect-UDP Establishment Request Message, obtain a session key using the nonce and provide the session key to the QUIC layer, and send a UDP Echo Response message, wherein a token field of the UDP Echo Response message includes the nonce.

[0077] The NE 600 may be configured to support a means for causing the network to, at the QUIC layer, decrypt the encrypted content of the UPD Options information element using the session key to obtain an decrypted content of the UPD Options information element.

[0078] The NE 600 may be configured to support a means, wherein the nonce value is a pseudo-random number.

[0079] The NE 600 may be configured to support a means for operating the network equipment as a User Plane Function.

[0080] The controller 606 may manage input and output signals for the NE 600. The controller 606 may also manage peripherals not integrated into the NE 600. In some implementations, the controller 606 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 606 may be implemented as part of the processor 602.

[0081] In some implementations, the NE 600 may include at least one transceiver 608. In some other implementations, the NE 600 may have more than one transceiver 608. The transceiver 608 may represent a wireless transceiver. The transceiver 608 may include one or more receiver chains 610, one or more transmitter chains 612, or a combination thereof.

[0082] A receiver chain 610 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 610 may include one or more antennas for receive the signal over the air or wireless medium.The receiver chain 610 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 610 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 610 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.

[0083] A transmitter chain 612 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 612 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 612 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 612 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0084] Figure 7 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.

[0085] At 702, the method may include receiving a Connect-UDP Establishment Request Message over an established QUIC connection with Transport Layer Security, TLS, protocol. The operations of 702 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 702 may be performed by a NE as described with reference to Figure 6.

[0086] At 704, the method may include providing a UPD Options information element with a Media Related Information, MRI, to a QUIC Layer, for encryption with a Connect- UDP security context. The operations of 704 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 704 may be performed by a NE as described with reference to Figure 6.

[0087] At 706, the method may include, at the QUIC layer, encrypting the content of the UPD Options information element to obtain a UPD Options information element with encrypted content. The operations of 706 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 706 may be performed a NE as described with reference to Figure 6.

[0088] At 708, the method may include receiving from the QUIC layer the UDP Options information element with encrypted content and an encrypted Connect-UDP packet. The operations of 708 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 708 may be performed a NE as described with reference to Figure 6.

[0089] At 710, the method may include appending the UDP Options information element with encrypted content to an encrypted Connect-UDP packet. The operations of 710 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 710 may be performed a NE as described with reference to F igure 6.

[0090] At 712, the method may include sending the encrypted Connect-UDP packet with the UDP Options information element with encrypted content. The operations of 712 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 712 may be performed a NE as described with reference to Figure 6.

[0091] Figure 8 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.

[0092] At 802, the method may include sending a Connect-UDP Establishment Request Message over an established QUIC connection with Transport Layer Security, TLS, protocol. The operations of 802 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 802 may be performed by a NE as described with reference to Figure 6.

[0093] At 804, the method may include receiving an encrypted Connect-UDP packet with an appended UDP Options information element with encrypted content, the encryptedcontent of the UDP Options information element including an encrypted Media Related Information, MRI, content. The operations of 804 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 804 may be performed by a NE as described with reference to Figure 6.

[0094] At 806, the method may include providing the UPD Options information element with encrypted Media Related Information, MRI, content to a QUIC Layer, for decryption with a Connect-UDP security context. The operations of 806 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 806 may be performed by a NE as described with reference to Figure 6.

[0095] At 808, the method may include, at the QUIC layer, decrypting the content of the UPD Options information element to obtain a decrypted Media Related Information, MRI, content of the UPD Options information element. The operations of 808 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 808 may be performed by a NE as described with reference to Figure 6.

[0096] At 810, the method may include receiving from the QUIC layer the decrypted Media Related Information, MRI, content of the UDP Options information element. The operations of 810 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 810 may be performed by a NE as described with reference to Figure 6.

[0097] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.

[0098] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.

Claims

What is claimed is:

1. A network equipment, comprising: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the network equipment to: receive a Connect-UDP Establishment Request Message over an established QUIC connection with Transport Layer Security, TLS, protocol; provide a UPD Options information element with a Media Related Information, MRI, to a QUIC Layer, for encryption with a Connect-UDP security context; at the QUIC layer, encrypt content of the UPD Options information element to obtain an UPD Options information element with encrypted content; receive from the QUIC layer the UDP Options information element with encrypted content and an encrypted Connect-UDP packet; append the UDP Options information element with encrypted content to an encrypted Connect-UDP packet; and send the encrypted Connect-UDP packet with the UDP Options information element with encrypted content.

2. The network equipment according to claim 1, wherein the at least one processor is configured to cause the network equipment to encrypt content of the UPD Options information element with a cipher suite that is the same as a cipher suite used to obtain the encrypted Connect-UDP packet.

3. The network equipment according to claim 1 or 2, wherein the at least one processor is configured to cause the network equipment to: send a UDP Echo Request message, wherein a token field of the UDP Echo Request message contains an Encryption Service Indication to indicate that subsequent downlink packets will include an UPD Options information element with encrypted MRI content; andreceive a UDP Echo Response message, wherein a token field of the UDP Echo Response message includes the Encryption Service Indication.

4. The network equipment according to claim 1, wherein the at least one processor is configured to cause the network equipment to: generate a nonce value and associate the nonce with the Connect-UDP Establishment Request Message; obtain a session key using the nonce and provide the session key to the QUIC layer; send a UDP Echo Request message, wherein a token field of the UDP Echo Request message contains the nonce; and receive a UDP Echo Response message, wherein a token field of the UDP Echo Response message includes the nonce.

5. The network equipment according to 4, wherein the at least one processor is configured to cause the network to: at the QUIC layer, encrypt content of the UPD Options information element using the session key to obtain an encrypted UPD Options information element.

6. The network equipment according to claim 4 or 5 , wherein the nonce value is a pseudorandom number.

7. The network Equipment according to any one of claims 4 to 6, wherein the nonce value has a length of 4 bytes.

8. The network equipment according to any one of the preceding claims, wherein the at least one processor is configured to operate the network equipment as an Application Server.

9. The network equipment according to any one of the preceding claims, wherein the Connect-UDP Establishment Request Message is associated with an Extended Reality and Media, XRM, service.

10. The network equipment according to any one of the preceding claims, wherein the Connect-UDP Establishment Request Message is received from a User Plane Function, and the encrypted Connect-UDP packet with the UDP Options information element with encrypted content is sent to that User Plane Function.

11. A network equipment, comprising: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the network equipment to: send a Connect-UDP Establishment Request Message over an established QUIC connection with Transport Layer Security, TLS, protocol; receive an encrypted Connect-UDP packet with an appended UDP Options information element with encrypted content, the encrypted content of the UDP Options information element including encrypted Media Related Information, MRI, content; provide the UPD Options information element with encrypted Media Related Information, MRI content, to a QUIC Layer, for decryption with a Connect-UDP security context; at the QUIC layer, decrypt the encrypted content of the UPD Options information element to obtain a decrypted content of the UPD Options information element; and receive from the QUIC layer the decrypted content of the UDP Options information element.

12. The network equipment according to claim 12, wherein the at least one processor is configured to cause the network equipment to decrypt the encrypted content of the UDP Options information element with a cipher suite that is the same as a cipher suite used to obtain a decrypted Connect-UDP packet.

13. The network equipment according to claim 11 or 12, wherein the at least one processor is configured to cause the network equipment to: receive a UDP Echo Request message, wherein a token field of the UDP Echo Request message contains an Encryption Service Indication to indicate that subsequentdownlink packets will include an UPD Options information element with encrypted MRI content; and send a UDP Echo Response message, wherein a token field of the UDP Echo Response message includes the Encryption Service Indication.

14. The network equipment according to claim 10, wherein the at least one processor is configured to cause the network equipment to: receive a UDP Echo Request message, wherein a token field of the UDP Echo Request message contains a nonce value and associate the nonce with the Connect-UDP Establishment Request Message; obtain a session key using the nonce and provide the session key to the QUIC layer; and send a UDP Echo Response message, wherein a token field of the UDP Echo Response message includes the nonce.

15. The network equipment according to 14, wherein the at least one processor is configured to cause the network to: at the QUIC layer, decrypt the encrypted content of the UPD Options information element using the session key to obtain an decrypted content of the UPD Options information element.

16. The network equipment according to claim 14 or 15, wherein the nonce value is a pseudo-random number.

17. The network equipment according to any one of claims 11 to 16, wherein the at least one processor is configured to operate the network equipment as a User Plane Function.

18. The network equipment according to any one of claims 11 to 17, wherein the Connect- UDP Establishment Request Message is sent to an Application Server, and the encrypted Connect-UDP packet with the UDP Options information element with encrypted content is received from that Application Server.

19. A method performed by a network equipment and comprising: receiving a Connect-UDP Establishment Request Message over an established QUIC connection with Transport Layer Security, TLS, protocol; providing a UPD Options information element with a Media Related Information, MRI, to a QUIC Layer, for encryption with a Connect-UDP security context; at the QUIC layer, encrypting the content of the UPD Options information element to obtain a UPD Options information element with encrypted content; receiving from the QUIC layer the UDP Options information element with encrypted content and an encrypted Connect-UDP packet; appending the UDP Options information element with encrypted content to an encrypted Connect-UDP packet; and sending the encrypted Connect-UDP packet with the UDP Options information element with encrypted content.

20. A method performed by a network equipment and comprising: sending a Connect-UDP Establishment Request Message over an established QUIC connection with Transport Layer Security, TLS, protocol; receiving an encrypted Connect-UDP packet with an appended UDP Options information element with encrypted content, the encrypted content of the UDP Options information element including an encrypted Media Related Information, MRI, content; providing the UPD Options information element with encrypted Media Related Information, MRI, content to a QUIC Layer, for decryption with a Connect-UDP security context; at the QUIC layer, decrypting the content of the UPD Options information element to obtain a decrypted Media Related Information, MRI, content of the UPD Options information element; and receiving from the QUIC layer the decrypted Media Related Information, MRI, content of the UDP Options information element.