Method and device for configuring security of network slice in wireless communication system

A key hierarchy system is introduced to establish security contexts for each network slice, addressing unauthorized access and data exposure issues in 5G systems, ensuring secure access and data protection.

WO2025244260A1PCT designated stage Publication Date: 2025-11-27SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/003589
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-22
Filing Date
2025-03-19
Publication Date
2025-11-27

AI Technical Summary

Technical Problem

Current 5G mobile communication systems lack specific methods for providing security for individual network slices, leading to unauthorized access and data exposure within network slices, and insufficient access control between network slices.

Method used

Implement a method for establishing a security context for each network slice by generating a security context per network slice using a key hierarchy system, including keys such as K_AMF, K_gNB, K_UPint, K_UPenc, K_RRCint, and K_RRCenc, to ensure secure access and data protection.

Benefits of technology

The proposed method effectively provides slice-by-slice security and access control, preventing unauthorized access and data exposure within network slices, enhancing security and reliability in 5G and beyond.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025003589_27112025_PF_FP_ABST
    Figure KR2025003589_27112025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a device and a method for configuring security of a network slice, the method comprising the steps of: acquiring a first base station key (K_gNB) on the basis of an AMF key (K_AMF); generating a key associated with at least one access stratum (AS) on the basis of the first base station key and an identifier corresponding to a network slice; and establishing an AS security context for each network slice on the basis of the key associated with the AS, wherein the network slice corresponds to a control unit (CU)-user plane (UP) of a base station.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for establishing security of a network slice in a wireless communication system

[0001] The present disclosure relates to a device and method for establishing security in a network slice. More specifically, the present disclosure relates to a device and method for establishing a security context in a network slice to protect data transmitted through the network slice.

[0002] Looking back at the evolution of wireless communication over successive generations, technologies have primarily been developed for human-facing services such as voice, multimedia, and data. With the commercialization of the 5G (5th Generation) communication system, an explosive increase in connected devices is expected to be connected to communication networks. Examples of networked objects include vehicles, robots, drones, home appliances, displays, smart sensors installed in various infrastructures, construction equipment, and factory equipment. Mobile devices are also expected to evolve into diverse form factors, such as augmented reality glasses, virtual reality headsets, and holographic devices. In the 6G (6th Generation) era, efforts are being made to develop improved 6G communication systems to connect hundreds of billions of devices and objects and provide diverse services. For this reason, 6G communication systems are often referred to as "beyond 5G."

[0003] The 6G communication system, expected to be realized around 2030, will have a maximum transmission speed of terabytes (i.e., 1,000 gigabits) per second (bps) and a wireless latency of 100 microseconds (μsec). In other words, compared to 5G, the transmission speed in a 6G communication system will be 50 times faster and the wireless latency will be reduced to one-tenth.

[0004] To achieve these high data rates and ultra-low latency, 6G communication systems are being considered for implementation in the terahertz (THz) band (e.g., from 95 gigahertz (GHz) to 3 terahertz (THz)). Compared to the millimeter wave (mmWave) band introduced in 5G, the terahertz band is expected to have more severe path loss and atmospheric absorption, making it more important to develop technologies that can guarantee signal reach, or coverage. Key technologies to ensure coverage include Radio Frequency (RF) components, antennas, new waveforms that offer better coverage than Orthogonal Frequency Division Multiplexing (OFDM), beamforming, and multiple antenna transmission technologies such as massive Multiple-Input and Multiple-Output (MIMO), Full Dimensional MIMO (FD-MIMO), array antennas, and large-scale antennas. In addition, new technologies such as metamaterial-based lenses and antennas, high-dimensional spatial multiplexing using Orbital Angular Momentum (OAM), and Reconfigurable Intelligent Surface (RIS) are being discussed to improve the coverage of terahertz band signals.

[0005] In addition, in order to improve frequency efficiency and system network, 6G communication systems are developing full duplex technology that utilizes the same frequency resources at the same time for uplink and downlink; network technology that integrates satellites and HAPS (High-Altitude Platform Stations); network structure innovation technology that supports mobile base stations and enables optimization and automation of network operation; dynamic spectrum sharing technology through collision avoidance based on spectrum usage prediction; AI-based communication technology that utilizes AI (Artificial Intelligence) from the design stage and internalizes end-to-end AI support functions to realize system optimization; and next-generation distributed computing technology that realizes services with complexity that exceeds the limits of terminal computing capabilities by utilizing ultra-high-performance communication and computing resources (Mobile Edge Computing (MEC), cloud, etc.). In addition, efforts are being made to further strengthen connectivity between devices, further optimize networks, promote softwareization of network entities, and increase the openness of wireless communications through the design of new protocols to be used in 6G communication systems, the implementation of hardware-based security environments, the development of mechanisms for the safe use of data, and the development of technologies for maintaining privacy.

[0006] Research and development of these 6G communication systems are expected to enable a new level of hyper-connected experience through the hyper-connectivity of 6G communication systems, which encompass not only connections between things but also connections between people and things. Specifically, 6G communication systems are expected to enable services such as truly immersive eXtended Reality (XR), high-fidelity mobile holograms, and digital replicas. Furthermore, services such as remote surgery, industrial automation, and emergency response, which are provided through 6G communication systems through enhanced security and reliability, will be applied in diverse fields such as industry, medicine, automobiles, and home appliances.

[0007] In wireless communication systems, entities involved in user data exchange can independently transmit and receive data across network slices (NS) for each service. Therefore, procedures are required to create security contexts for each network slice to protect them and enforce access control. Meanwhile, the traffic throughput required in wireless communication systems increases annually, and with each generation of communication technology, security-related requirements are also growing.

[0008] As described above, as more terminals are able to efficiently receive diverse services, greater security is expected to be required. Therefore, the present disclosure can provide a method for managing access control and security on a slice-by-slice basis between terminals and base stations.

[0009] The technical problems to be achieved in this document are not limited to the technical problems mentioned above, and other technical problems not mentioned can be clearly understood by a person having ordinary skill in the technical field to which the present invention belongs from the description below.

[0010] According to various embodiments of the present disclosure, in a wireless communication system, a method performed by a base station may include: obtaining a first base station key (K_gNB) based on an access and mobility management function (AMF) key (K_AMF); generating a key associated with at least one access stratum (AS) based on the first base station key and an identifier corresponding to a network slice; and establishing a network slice-specific AS security context between the base station and a user equipment (UE) based on the key associated with the at least one AS, wherein the network slice may correspond to a control unit (CU)-user plane (UP) of the base station.

[0011] According to various embodiments of the present disclosure, in a wireless communication system, a method performed by a user equipment (UE) may include: obtaining a first base station key (K_gNB) based on an access and mobility management function (AMF) key (K_AMF); generating a key associated with at least one access stratum (AS) based on the first base station key and an identifier corresponding to a network slice; and establishing an AS security context per network slice between the UE and the base station based on the key associated with the at least one AS, wherein the network slice may correspond to a control unit (CU)-user plane (UP) of the base station.

[0012] The present disclosure provides an electronic device and method capable of effectively providing a service in a wireless communication system.

[0013] The effects that can be obtained from the present disclosure are not limited to the effects mentioned above, and other effects that are not mentioned can be clearly understood by a person having ordinary skill in the art to which the present disclosure belongs from the description below.

[0014] FIG. 1 illustrates a communication network including core network entities in a wireless communication system according to embodiments of the present disclosure.

[0015] FIG. 2 illustrates the configuration of a user equipment (UE) in embodiments of the present disclosure.

[0016] FIG. 3 illustrates the configuration of a base station according to embodiments of the present disclosure.

[0017] FIG. 4 illustrates an example of key hierarchy generation according to embodiments of the present disclosure.

[0018] FIG. 5A illustrates a communication network including entities per network slice according to embodiments of the present disclosure.

[0019] FIG. 5b illustrates a process of exchanging network slice identifiers according to embodiments of the present disclosure.

[0020] FIG. 6 illustrates an example of an interface within a base station according to the separation of DU (distributed unit)-CU (central unit) functions according to embodiments of the present disclosure.

[0021] FIG. 7 illustrates the flow of signals for setting security per network slice according to embodiments of the present disclosure.

[0022] FIG. 8A and FIG. 8B illustrate an example for establishing a user plane (UP) security context per network slice according to embodiments of the present disclosure.

[0023] FIG. 9A and FIG. 9B illustrate an example for establishing a security context per network slice according to embodiments of the present disclosure.

[0024] FIG. 10 illustrates an example for establishing a security context per base station according to embodiments of the present disclosure.

[0025] FIG. 11A and FIG. 11B illustrate an example for establishing a security context per base station according to embodiments of the present disclosure.

[0026] FIG. 12 illustrates a signal flow for exchanging a master session key (MSK) according to embodiments of the present disclosure.

[0027] FIG. 13 illustrates an example for establishing a user plane security context per network slice using MSK according to embodiments of the present disclosure.

[0028] FIG. 14 illustrates an example for establishing a security context per network slice using MSK according to embodiments of the present disclosure.

[0029] FIG. 15 illustrates an example for establishing a base station security context per network slice using MSK according to embodiments of the present disclosure.

[0030] FIG. 16 illustrates an example for establishing a security context per base station using MSK according to embodiments of the present disclosure.

[0031] FIG. 17 illustrates an operation flow of a terminal or base station for establishing a security context for each network slice according to embodiments of the present disclosure.

[0032] Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the attached drawings. It should be noted that, where possible, identical components are represented by identical reference numerals throughout the drawings. Furthermore, detailed descriptions of well-known functions and configurations that may obscure the gist of the present invention will be omitted.

[0033] In describing the embodiments herein, descriptions of technical details that are well-known in the technical field to which the present invention pertains and are not directly related to the present invention will be omitted. This is to avoid obscuring the gist of the present invention by omitting unnecessary explanations and to convey the gist more clearly.

[0034] For the same reason, some components in the attached drawings are exaggerated, omitted, or schematically depicted. Furthermore, the dimensions of each component do not entirely reflect its actual size. Identical or corresponding components in each drawing are assigned the same reference numbers.

[0035] The advantages and features of the present invention, and the methods for achieving them, will become clearer with reference to the embodiments described in detail below together with the accompanying drawings. However, the present invention is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided only to ensure that the disclosure of the present invention is complete and to fully inform those skilled in the art of the scope of the invention, and the present invention is defined only by the scope of the claims. Like reference numerals designate like elements throughout the specification.

[0036] At this time, it will be understood that each block of the processing flow diagrams and combinations of the flow diagrams can be performed by computer program instructions. These computer program instructions can be installed in a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, so that the instructions executed by the processor of the computer or other programmable data processing equipment create a means for performing the functions described in the flow diagram block(s). These computer program instructions can also be stored in a computer-available or computer-readable memory that can direct a computer or other programmable data processing equipment to implement the functions in a specific manner, so that the instructions stored in the computer-available or computer-readable memory can also produce a manufactured item that includes an instruction means for performing the functions described in the flow diagram block(s). Since the computer program instructions may be installed on a computer or other programmable data processing device, a series of operational steps may be performed on the computer or other programmable data processing device to create a computer-executable process, and the instructions that cause the computer or other programmable data processing device to perform the steps for performing the functions described in the flowchart block(s) may also provide steps for performing the functions described in the flowchart block(s).

[0037] Additionally, each block may represent a module, segment, or portion of code that contains one or more executable instructions for performing a specific logical function(s). It should also be noted that in some alternative implementation examples, the functions described in the blocks may occur out of order. For example, two blocks depicted in succession may actually be executed substantially concurrently, or the blocks may sometimes be executed in reverse order, depending on their respective functions.

[0038] Here, the term '~ part' used in this embodiment means software or hardware components such as FPGA (field programmable gate array) or ASIC (application specific integrated circuit), and the '~ part' performs certain roles. However, the '~ part' is not limited to software or hardware. The '~ part' may be configured to be on an addressable storage medium and may be configured to play one or more processors. Therefore, as an example, the '~ part' includes components such as software components, object-oriented software components, class components, and task components, processes, functions, properties, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and '~ parts' may be combined into a smaller number of components and '~ parts' or further separated into additional components and '~ parts'. Additionally, the components and '~parts' may be implemented to play one or more central processing units (CPUs) within the device or secure multimedia card.

[0039] The embodiments of the present disclosure described below may also be applied to other communication systems with similar technical backgrounds or channel types. Furthermore, the embodiments of the present disclosure may be applied to other communication systems with some modifications, as determined by a person skilled in the art, without significantly departing from the scope of the present disclosure.

[0040] In the following description, terms used to identify connection nodes, terms referring to network entities or network functions (NFs), terms referring to messages, terms referring to interfaces between network objects, terms referring to various identification information, etc. are examples provided for convenience of explanation. Therefore, the present invention is not limited to the terms described below, and other terms referring to objects having equivalent technical meanings may be used.

[0041] For convenience of explanation, some terms and names defined in the 3rd generation partnership project long-term evolution (3GPP) standards may be used. However, the present invention is not limited to the terms and names described herein, and can be equally applied to systems conforming to other standards. In particular, the present disclosure can be applied to the 3GPP 5th generation mobile communication standards (e.g., 5GS and NR).

[0042] FIG. 1 illustrates a communication network including core network entities in a wireless communication system according to embodiments of the present disclosure. A 5G mobile communication network may be configured to include a 5G user equipment (UE) (110), a 5G radio access network (RAN) (120), and a 5G core network.

[0043] The 5G core network may be configured to include network functions such as an access and mobility management function (AMF) (150) that provides a mobility management function of UE, a session management function (SMF) (160) that provides a session management function, a user plane function (UPF) (170) that performs a data transfer role, a policy control function (PCF) (180) that provides a policy control function, a unified data management (UDM) (153) that provides a data management function such as subscriber data and policy control data, or a unified data repository (UDR) that stores data of various network functions.

[0044] Referring to FIG. 1, a user equipment (UE) (110) may communicate via a wireless channel formed with a base station (e.g., an eNB or gNB), i.e., an access network. In some embodiments, the UE (110) may be a device used by a user and configured to provide a user interface (UI). As an example, the UE (110) may be a terminal mounted (equipment) on a vehicle for driving. In some other embodiments, the UE (110) may be a device that performs machine type communication (MTC) that operates without user intervention, or may be an autonomous vehicle. UE may be referred to as a 'terminal', 'vehicle terminal', 'user equipment (UE)', 'mobile station', 'subscriber station', 'remote terminal', 'wireless terminal', or 'user device' or other terms having equivalent technical meanings, other than electronic devices. As the terminal, in addition to the UE, a customer-premises equipment (CPE) or a dongle-type terminal may be used. The CPE, while connected to the NG-RAN node like the UE, may provide a network to other communication equipment (e.g., a laptop).

[0045] Referring to FIG. 1, a radio access network (RAN) (120) is a network that is directly connected to a user device, for example, a terminal (110), and is an infrastructure that provides wireless access to the terminal (110). The radio access network (120) may include a set of a plurality of base stations including a base station, and the plurality of base stations may communicate through interfaces formed between each other. At least some of the interfaces between the plurality of base stations may be wired or wireless. A base station (e.g., an eNB, a gNB) of the radio access network (120) may have a structure that is divided into a central unit (CU) and a distributed unit (DU). In this case, one CU may control a plurality of DUs. In addition, a CU included in a base station may include at least one user plane (CU-UP) that manages a user plane and at least one control plane (CU-CP) that manages a control plane. In addition to base station, the base station may be referred to as an 'access point (AP)', 'gNB (next generation node B)', '5G node (5th generation node)', 'wireless point', 'transmission / reception point (TRP)', or other terms having equivalent technical meanings.

[0046] Referring to FIG. 1, the AMF (150) provides a function for access and mobility management per terminal (110), and basically, one terminal (110) can be connected to one AMF (150). For example, the AMF (150) may be a network function that manages the mobility of the terminal. Specifically, the AMF (150) may perform at least one of signaling between core network nodes for mobility between 3GPP access networks, an interface (N2 interface) between wireless access networks (e.g., 5G RAN) (120), non-access stratum (NAS) signaling or access stratum (AS) signaling with the terminal (110), identification of the SMF (160), and provisioning of transmission of session management (SM) messages between the terminal (110) and the SMF (160). Some or all of the functions of AMF (150) may be supported within a single instance of AMF (150).

[0047] Referring to FIG. 1, the SMF (160) provides a session management function, and when a terminal (110) has multiple sessions, each session may be managed by a different SMF (160). For example, the SMF (160) may be a network function that manages a packet data network (PDN) connection provided to the terminal. The PDN connection may be referred to as a protocol data unit (PDU) session. Specifically, the SMF (160) may perform at least one of the following functions: session management (e.g., session establishment, modification, and teardown, including maintaining tunnels between the UPF (170) and access network nodes), selection and control of user plane (UP) functions, traffic steering setup to route traffic to appropriate destinations in the UPF (170), termination of the SM portion of NAS messages, downlink data notification (DDN), and initiation of AN-specific SM information (e.g., forwarding it to the access network via the N2 interface via the AMF (150)). Some or all of the functions of the SMF (160) may be supported within a single instance of one SMF (160).

[0048] Referring to FIG. 1, the PCF (180) may be a network function that applies a mobile communication service provider's service policy, charging policy, and PDU Session policy to a terminal. According to one embodiment, the UDM (153) may be a network function that stores information about a subscriber. According to one embodiment, the UPF (170) may be a function that acts as a gateway that transfers user data (e.g., PDU) to a DN (data network). According to one embodiment, the NRF (network repository function) (159) may perform a function of identifying an NF. The NRF (159) may store information about NFs installed in a mobile communication service provider network and perform a function of notifying the stored information. According to one embodiment, the NEF (network exposure function) (155) may serve to connect a third-party server and an NF within a 5G mobile communication system. For example, the NEF (155) may be a function that provides information about a terminal to a server outside the 5G network. According to one embodiment, the authentication server function (AUSF) (151) may perform terminal authentication in a 3GPP access network and a non-3GPP access network. According to one embodiment, the network slice selection function (NSSF) (190) may perform a function of selecting a network slice instance provided to the terminal. According to one embodiment, the DN (140) may be a data network through which the terminal transmits and receives data in order to use the network operator's service or a third-party service.

[0049] In the 3GPP system, conceptual links connecting NFs within a 5G system may be referred to as reference points. Reference points may also be referred to as interfaces. The following exemplifies reference points (hereinafter, interchangeably referred to as interfaces) included in the 5G system architecture represented across various embodiments of the present disclosure.

[0050] - N1: Reference point between UE (110) and AMF (150)

[0051] - N2: Reference point between (R)AN(120) and AMF(150)

[0052] - N3: Reference point between (R)AN(120) and UPF(170)

[0053] - N4: Reference point between SMF (160) and UPF (170)

[0054] - N6: Reference point between UPF (170) and DN (140)

[0055] - N9: Reference point between two core UPFs (170)

[0056] Furthermore, while the embodiments of the present disclosure are described below using a 5G system as an example, the embodiments of the present disclosure can also be applied to other communication systems with similar technical backgrounds. Furthermore, the embodiments of the present disclosure can be applied to other communication systems with some modifications, as determined by a person skilled in the art, without significantly departing from the scope of the present disclosure.

[0057] According to various embodiments of the present disclosure, 5GC may include NFs as illustrated in FIG. 1, but is not limited to the example of FIG. 1, and 5GC may include more or fewer NFs than the NFs illustrated in FIG. 1.

[0058] Figure 2 illustrates the configuration of a user equipment (UE) according to embodiments of the present disclosure. Terms such as "unit" and "device" used herein refer to a unit that processes at least one function or operation, which may be implemented using hardware, software, or a combination of hardware and software.

[0059] Referring to FIG. 2, the terminal includes a communication unit (210), a storage unit (230), and a control unit (220).

[0060] The communication unit (210) performs functions for transmitting and receiving signals via a wireless channel. For example, the communication unit (210) performs a conversion function between a baseband signal and a bit stream according to the physical layer specifications of the system. For example, when transmitting data, the communication unit (210) generates complex symbols by encoding and modulating a transmission bit stream. In addition, when receiving data, the communication unit (210) restores a reception bit stream by demodulating and decoding the baseband signal. The communication unit (210) upconverts a baseband signal into an RF (radio frequency) band signal and transmits it through an antenna, and downconverts an RF band signal received through the antenna into a baseband signal. For example, the communication unit (210) may include a transmission filter, a reception filter, an amplifier, a mixer, an oscillator, a DAC, an ADC, etc.

[0061] In addition, the communication unit (210) may include a plurality of transmission and reception paths. Furthermore, the communication unit (210) may include an antenna unit. The communication unit (210) may include at least one antenna array composed of a plurality of antenna elements. In terms of hardware, the communication unit (210) may be composed of digital circuits and analog circuits (e.g., radio frequency integrated circuits (RFIC)). Here, the digital circuits and analog circuits may be implemented in a single package. In addition, the communication unit (210) may include a plurality of RF chains. The communication unit (210) may perform beamforming. The communication unit (210) may apply beamforming weights to a signal to be transmitted and received in order to impart directionality according to the settings of the control unit (220).

[0062] Specifically, the communication unit (210) may include an RF processing unit and a baseband processing unit. The RF processing unit performs functions for transmitting and receiving signals through a wireless channel, such as signal band conversion and amplification. The RF processing unit upconverts a baseband signal provided from the baseband processing unit into an RF band signal and transmits the upconverted signal through an antenna, and downconverts an RF band signal received through the antenna into a baseband signal. For example, the RF processing unit may include a transmission filter, a reception filter, an amplifier, a mixer, an oscillator, a digital to analog convertor (DAC), an analog to digital convertor (ADC), etc. The terminal may include one or more antennas. The RF processing unit may include a plurality of RF chains. Furthermore, the RF processing unit may perform beamforming. For the beamforming, the RF processing unit may adjust the phase and magnitude of each of the signals transmitted and received through a plurality of antennas or antenna elements.

[0063] The communication unit (210) transmits and receives signals according to the operations described in FIGS. 1 to 17. Accordingly, all or part of the communication unit (210) may be referred to as a transmitter, a receiver, or a transceiver. Furthermore, the communication unit (210) may include a plurality of communication modules to support a plurality of different wireless access technologies. In addition, the communication unit (210) may include different communication modules to process signals of different frequency bands. For example, the different wireless access technologies may include wireless LAN (e.g., IEEE 802.1x), cellular networks (e.g., LTE, NR), etc. In addition, the different frequency bands may include a super high frequency (SHF) (e.g., 2.5 GHz, 5 GHz) band, a millimeter wave (mm wave) (e.g., 60 GHz) band. Additionally, the communication unit (210) may utilize the same type of wireless access technology on different frequency bands (e.g., unlicensed bands for LAA (licensed Assisted Access) or NR-U (unlicensed), CBRS (citizens broadband radio service) (e.g., 3.5 GHz)).

[0064] The storage unit (230) stores data such as basic programs, application programs, and setting information for the operation of the terminal. The storage unit (230) may be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. The storage unit (230) stores data such as basic programs, application programs, and setting information for the operation of the terminal.

[0065] The control unit (220) controls the overall operations of the terminal. For example, the control unit (220) transmits and receives signals through the communication unit (210). In addition, the control unit (220) records and reads data in the storage unit (230). In addition, the control unit (220) can perform the functions of the protocol stack required by the communication standard. To this end, the control unit (220) may include at least one processor (or controller). The control unit (220) may include at least one processor or microprocessor, or may be a part of a processor. The control unit (220) may include various modules for performing communication. According to various embodiments, the control unit (220) may control the terminal to perform operations according to various embodiments described below.

[0066] Figure 3 illustrates the configuration of a base station according to embodiments of the present disclosure. Terms such as "unit" and "unit" used hereinafter refer to a unit that processes at least one function or operation, which may be implemented using hardware, software, or a combination of hardware and software.

[0067] Referring to FIG. 3, the base station includes a communication unit (310), a backhaul communication unit (340), a storage unit (330), and a control unit (320).

[0068] The communication unit (310) performs functions for transmitting and receiving signals via a wireless channel. For example, the communication unit (310) performs a conversion function between a baseband signal and a bit stream according to the physical layer specifications of the system. For example, when transmitting data, the communication unit (310) generates complex symbols by encoding and modulating the transmission bit stream. In addition, when receiving data, the communication unit (310) restores the reception bit stream by demodulating and decoding the baseband signal. The communication unit (310) may be configured to perform at least one of the operations of the transmitter or the receiver described through FIGS. 1 to 17. Accordingly, all or part of the communication unit (310) may be referred to as a modem, a transmitter, a receiver, or a transceiver. Additionally, in the following description, transmission and reception performed through a wireless or wired channel are used to mean that processing as described above is performed by the communication unit (310).

[0069] The communication unit (310) up-converts a baseband signal into an RF (radio frequency) band signal and transmits it through an antenna, and down-converts an RF band signal received through the antenna into a baseband signal. To this end, the communication unit (310) may include a transmission filter, a reception filter, an amplifier, a mixer, an oscillator, a digital to analog convertor (DAC), an analog to digital convertor (ADC), etc. In addition, the communication unit (310) may include a plurality of transmission and reception paths. Furthermore, the communication unit (310) may include at least one antenna array composed of a plurality of antenna elements. In terms of hardware, the communication unit (310) may be composed of a digital unit and an analog unit, and the analog unit may be composed of a plurality of sub-units according to operating power, operating frequency, etc. According to one embodiment, the communication unit (310) may include a unit that forms a beam, i.e., a beamforming unit. For example, the communication unit (310) may include an MMU (massive MIMO unit) for beamforming.

[0070] The communication unit (310) can transmit and receive signals. For this purpose, the communication unit (310) can include at least one transceiver. For example, the communication unit (310) can transmit a synchronization signal, a reference signal, system information, a message, control information, or data. In addition, the communication unit (310) can perform beamforming. The communication unit (310) can apply beamforming weights to signals to be transmitted and received in order to impart directionality according to the settings of the control unit (320). According to one embodiment, the communication unit (310) can generate a baseband signal according to the scheduling result and the transmission power calculation result. In addition, the RF unit within the communication unit (310) can transmit the generated signal through an antenna.

[0071] The communication unit (310) transmits and receives signals as described above. Accordingly, all or part of the communication unit (310) may be referred to as a "transmitter," a "receiver," or a "transmitting and receiving unit." Furthermore, in the following description, transmission and reception performed via a wireless channel are used to mean the operations described in FIGS. 1 to 17 being performed by the communication unit (310).

[0072] The backhaul communication unit (340) provides an interface for performing communication with other nodes within the network. That is, the backhaul communication unit (340) converts a bit string transmitted from a base station to other nodes (e.g., other access nodes, other base stations, upper nodes, core networks, etc.) into a physical signal, and converts a physical signal received from other nodes into a bit string.

[0073] The storage unit (330) stores data such as basic programs, application programs, and setting information for the operation of the base station. The storage unit (330) may include memory. The storage unit (330) may be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. In addition, the storage unit (330) provides stored data upon request from the control unit (320).

[0074] The control unit (320) controls the overall operations of the base station. For example, the control unit (320) transmits and receives signals through the communication unit (310) or the backhaul communication unit (340). In addition, the control unit (320) records and reads data in the storage unit (330). In addition, the control unit (320) can perform the functions of the protocol stack required by the communication standard. To this end, the control unit (320) can include at least one processor (or controller). According to various embodiments, the control unit (320) can control the base station to perform operations according to various embodiments described below.

[0075] In recent 5G communication systems, network slicing, which divides a single physical core network (CN) into independent virtual networks to provide customized services, is being utilized as a key technology for optimization. In other words, network slicing is an essential 5G mobile communication technology that maximizes the benefits of ultra-high speed, ultra-low latency, and hyper-connectivity by slicing and configuring a physical mobile communication network into multiple virtual networks. In particular, the need for 5G network slicing is continuously increasing, as standardized service policies for physical networks cannot fully guarantee 5G services with diverse requirements.

[0076] For example, a communication system based on 5G network slicing technology can provide a virtual network that guarantees ultra-low latency of several milliseconds (ms) and reliability close to 100% for next-generation communication services such as autonomous driving, cloud gaming, and industrial Internet of Things, and independently, services such as augmented reality (AR) / virtual reality (VR) streaming or ultra-high-definition video streaming can provide a virtual network that guarantees communication speeds of hundreds of megabits (Mbps) to several gigabits (Gbps). As such, the requirement for providing an optimized network for each service is increasing as core services in the 5G era will greatly expand.

[0077] Accordingly, the demand for security services utilizing network slices (NS) in current communication systems is increasing, and this need is particularly growing in services requiring high-reliability communication services, such as those in government, corporate, financial, and defense sectors. However, current 5G mobile communication systems do not provide specific methods for providing security for individual network slicing. This disclosure describes specific solutions to address this issue.

[0078] Various embodiments of the present disclosure propose a method for protecting a network slice and providing access control by creating a security context for each network slice.

[0079] Specifically, according to various embodiments of the present disclosure, a method is described for introducing a security context into a network slice to protect it from unauthorized access to the NS and exposure of data within the network slice.

[0080] Additionally, according to one embodiment, a method is described for providing inter-slice access control through each slice's own security context by assigning a security context to each network slice.

[0081] In addition, in the CU-CP (control plane) / CU-UP (user plane) architecture, different UPs can use the same security context. Therefore, considering this architecture, a method is described to provide access control by having the CU-CP derive a network slice security context for a slice using network slice selection assistance information (NSSAI) and transfer the derived security context to the CU-UP.

[0082] FIG. 4 illustrates an example of key hierarchy generation according to embodiments of the present disclosure. More specifically, FIG. 4 may include a key hierarchy (or key system) (410, 420) for access stratum (AS) security.

[0083] In one embodiment, 5GC and NG-RAN related keys may have the following requirements:

[0084] 1) Core networks and wireless networks are permitted to use encryption and integrity protection algorithms for AS and NAS protection with keys of 128 bits in length.

[0085] 2) The keys used for the user plane (UP), NAS and AS protection depend on the algorithms used for the keys.

[0086] Referring to FIG. 4, the AS key hierarchy (or key system) (410, 420) may include keys such as K_AMF, K_gNB (401), NH (402), K_gNB*, K_UPint (411), K_UPenc (412), K_RRCint (413), and K_RRCenc (414). A base station (e.g., a gNB) and a mobile equipment (ME) (e.g., a terminal or an ME included in a terminal) may generate AS keys to secure CP signaling and UP traffic, respectively. They may derive new keys using a key derivation function (KDF) and disclose the keys of higher layers.

[0087] Specifically, the various keys included in the key system (410, 420) and the process for deriving them are described below.

[0088] In one embodiment, the keys for a base station (e.g., NG-RAN) are as follows:

[0089] - K_gNB (401) may be a key derived from K_AMF by ME and AMF. K_gNB may be additionally derived by ME and source gNB when performing horizontal or vertical key derivation. K_gNB (401) may also be used as K_eNB between ME and ng-eNB. In one embodiment, K_gNB (401) may be generated from K_AMF by AMF and transmitted to base station. Base station may receive K_gNB (401) and NH (next hop) (402) from AMF, and may generate all additional keys dedicated to protecting 5G NR from at least one of K_gNB (401) or NH (402).

[0090] In one embodiment, the keys for traffic in the user plane (UP) are as follows:

[0091] - K_UPint(411) is a key derived from K_gNB(401) by the ME and the base station, and is a key used only for protecting UP traffic between the ME and the base station (e.g., gNB) with a specific integrity algorithm.

[0092] - K_UPenc (412) is a key derived from K_gNB (401) by the ME and the base station, and is a key used only for protecting UP traffic with a specific encryption algorithm.

[0093] According to one embodiment, the keys for radio resource control (RRC) signaling are as follows:

[0094] - K_RRCint (413) is a key derived from K_gNB (401) by the ME and the base station, and is a key used only for protection of control signals or RRC signaling with a specific integrity algorithm.

[0095] - K_RRCenc (414) is a key derived from K_gNB (401) by the ME and the base station, and is a key used only for protecting control signals or RRC signaling with a specific encryption algorithm.

[0096] In one embodiment, the intermediate keys are:

[0097] - NH(402) is a key derived by ME and AMF to provide forward security.

[0098] - K_gNB* is a key derived by the ME and the base station (e.g., gNB or ng-eNB) when performing horizontal or vertical key derivation using KDF. More specifically, NH (402) may be bound to the physical cell identity (PCI) of the base station and the corresponding frequency absolute radio-frequency channel number (ARFCN)-DL before being used as K_gNB (401) in the base station.

[0099] - K_AMF is a key that can be derived by ME and AMF using KDF during inter-AMF movement when UE moves from one AMF to another.

[0100] According to various embodiments of the present disclosure, a communication system may be configured with a key system (410, 420) as illustrated in FIG. 4. Referring to the key system (410, 420), a sub-key may be generated from a super-key using a key derivation function (KDF). In the key system (410, 420), a super-key may refer to a key at a starting point based on an arrow, and a sub-key may refer to a key at a point where an arrow arrives based on the arrow.

[0101] Here, a key design factor (KDF) can refer to a function used to obtain a key of a desired format, such as by extending a key to a longer length or converting it to a symmetric key using a random function (e.g., a hash function). Key hierarchy generation using a KDF must be carefully designed to ensure the security of 5G or next-generation 6G communication architectures. For example, if an attacker gains unauthorized access to a single input, the security of the key system can be compromised.

[0102] FIG. 5A illustrates a communication network including entities for each network slice according to embodiments of the present disclosure. More specifically, the communication network may include a RAN (520) including a base station connected to a terminal (510), an AMF (530) managing mobility, and an SMF and UPF connecting these to a data network (540) for each slice.

[0103] In one embodiment, network slicing may refer to a network service technology that creates new services based on isolation methods through existing infrastructure and virtual resources. Network slicing was introduced to create new services or efficiently monetize existing infrastructure. Specifically, wireless communication systems can efficiently provide service scenarios such as 5G enterprise services, private 5G, MEC (multi-access edge computing), smart factories, 5G automobiles, MCPTX (mission critical push-to-anything), patient services, energy transmission control, government surveillance and emergency services, broadcasting and streaming, manufacturing, supply chain, gaming, railways, and automobiles, based on network slicing-based technology. In particular, service providers can use shared infrastructure based on network slicing technology to provide new 5G services and save on operating expenditure (OPEX) and capital expenditure (CAPEX).

[0104] In one embodiment, network slicing can monitor service level agreement (SLA) conditions and support SLA-based services to ensure compliance. Specifically, network slicing can support various SLA requirements for services such as eMBB, URLLC, and mMTC.

[0105] However, current communication systems, while providing network slices for the diverse and efficient services described above, have a problem: they fail to provide a specific security context for these network slices. For example, the current 5G mobile communication system does not specifically specify how to provide security for network slicing, allowing users other than network slice managers and users to access the network slices.

[0106] Furthermore, current communication systems suffer from a lack of access control between network slices (e.g., the absence of access control between inter-network slices). For example, a network slice control mechanism must authorize shared resources while providing appropriate slice management, access control configuration, and security isolation between various slices. Such network slicing needs to incorporate the concept of zero trust architecture (ZTA) by providing slice security isolation for each segment, and provide security between slices through end-to-end slice isolation.

[0107] Current network slices, as illustrated in Figure 5a, do not provide separate security contexts between network slices. The communication system only includes a user plane key context to protect the user plane (UP) within the access stratum (AS), and can only provide access control to user plane data using this key. However, since this user plane key is shared across all network slices, if a user gains access to a specific network slice, that user can also gain access to other network slices.

[0108] According to one embodiment, for example, referring to FIG. 5A, a user plane (a first CU-UP (not shown) of the RAN (520)) corresponding to a first network slice (505) may provide a slice servicing URLLC, and a user plane (a second CU-UP (not shown) of the RAN (520)) corresponding to a second network slice (515) may provide a slice servicing eMBB. The first CU-UP and the second CU-UP may protect slice data based on a security context in the AS to protect slice data in the user plane. However, in this case, since the first CU-UP and the second CU-UP share the same security context, the first CU-UP may also access an eMBB slice that it does not serve, and conversely, the second CU-UP may also access an URLLC slice that it does not serve.

[0109] According to various embodiments of the present disclosure, a method for establishing and configuring a security context that can maintain access control and security between each slice is described. In addition, a method for establishing and configuring a security context for each slice according to the structure of a base station including multiple CU-UPs is described.

[0110] FIG. 5b illustrates a process of exchanging network slice identifiers according to embodiments of the present disclosure.

[0111] According to one embodiment, S-NSSAI (single-NSSAI) is a parameter that divides and distinguishes network slices based on QoS, and may include a role such as a slice ID for identifying a network slice.

[0112] In one embodiment, S-NSSAI may consist of:

[0113] - Slice / Service type (SST): Can represent distinct, expected, and different network slice behaviors in terms of functionality and services.

[0114] - Slice Differentiator (SD): Optional information that complements the SST, which can allow differentiation in selecting a network slice instance from among potential multiple network slice instances that all comply with the indicated SST.

[0115] The table shown below is an example of a standardized SST value, and the more specific structures of NSSAI, S-NSSAI, and SST / SD may include the information below.

[0116]

[0117] * NSSAI: combination of SST and SD for various network slices

[0118] - SST (0-127: standard / 128-255: operator)

[0119] - SD (Null: Telco, Hexadecimal H'FFFFFF: B2B)

[0120] * Standard NSSAI

[0121] - SST = 1,2,3,4,5 & SD = Null (the rest are all non-standard NSSAI)

[0122] In one embodiment, an NSSAI may be a set of one or more S-NSSAIs. Each S-NSSAI may support a network by selecting a specific network slice instance. The core network (CN) portion of the network slice instance(s) serving the terminal may be selected by the core network.

[0123] In one embodiment, the RAN may use the NSSAI requested in AS signaling to process the control plane connection of the UE before notifying the RAN of the allowed NSSAIs for 5GC. Once the UE is successfully registered, the core network may provide the RAN with the entire allowed NSSAI for the control plane aspect. Once a PDU session for a specific slice instance is established, the core network may provide the RAN with the S-NSSAI corresponding to the slice instance to which the PDU session belongs, so that the RAN can perform access-specific functions.

[0124] To be more specific about the above, the step of selecting a network slice instance may include a step of selecting a network slice instance to be allocated to a terminal based on an NSSAI included in a pre-determined request.

[0125] For example, the terminal (510) can transmit a requested NSSAI (502) from among the configured NSSAIs (501) to the AMF (530), and the AMF (530) can transmit it to the UDM (550). The UDM (550) or the AMF (530) can transmit an allowed NSSAI (504) to the terminal based on information of the subscribed S-NSSAIs (503) of the terminal.

[0126] The present disclosure provides a method for providing security to a network slice by individually assigning a security context to each NSSAI star (or S-NSSAI star).

[0127] FIG. 6 illustrates an example of an interface within a base station according to the separation of DU (distributed unit)-CU (central unit) functions according to embodiments of the present disclosure.

[0128] According to various embodiments of the present disclosure, to implement the concept of a cloud RAN, a structure is introduced that separates the CU into a CU-CP (control plane) and a CU-UP (user plane). The two planes described above can be connected to the DU via the F1-U and F1-C interfaces, respectively.

[0129] More specifically, the NG-RAN may include a set of base stations (e.g., gNBs) connected to a 5GC. The base station may include a gNB central unit (gNB-CU) and one or more gNB distributed units (gNB-DUs). The gNB-CU and gNB-DU may be connected via an F1 logical interface. A gNB-DU may be connected to only one gNB-CU.

[0130] In one embodiment, a gNB-CU is a logical node that hosts the RRC, SDAP, and PDCP protocols and can control the operation of one or more gNB-DU(s). The gNB-CU can also terminate the F1 interface connected to the gNB-DU.

[0131] In one embodiment, the gNB-DU is a logical node that hosts the RLC, MAC, and PHY layers, the operations of which may be partially controlled by the gNB-CU. A gNB-DU may support one or more cells. A cell may be supported by only a single gNB-DU. The gNB-DU may terminate the F1 interface connected to the gNB-CU.

[0132] For NG-RAN, the NG and Xn-C interfaces for a base station including gNB-CU and gNB-DUs may be terminated within the gNB-CU. For EN-DC (E-UTRA-NR Dual Connectivity), the S1-U and X2-C interfaces for a base station including gNB-CU and gNB-DUs may be terminated within the gNB-CU.

[0133] Meanwhile, in 5G RAN, in addition to the separation option of gNB-CU (hereinafter, referred to as CU for convenience) and gNB-DU (hereinafter, referred to as DU for convenience) as described above, a method of dividing CU into control plane and user plane entities to improve deployment efficiency is being discussed. For example, a central unit-control plane (CU-CP) (610) may correspond to the control plane portion of a gNB-CU. The CU-CP (610) may host the control plane portion of the PDCP protocol and the RRC protocol. One or more central unit-user planes (CU-UPs) (620-1, 620-N) may correspond to the user plane portion of a gNB-CU. The CU-UPs (620-1, 620-N) may host the user plane portion of the PDCP protocol and the SDAP protocol.

[0134] Referring to FIG. 6, a gNB (600) may include a CU-CP (610), multiple CU-UPs (620-1, 620-N), and multiple DUs (601, 602). The CU-CP (610) may be connected to the DUs (601, 602) via an F1-C interface. The CU-UPs (620-1, 620-N) may be connected to the DUs (601, 602) via an F1-U interface. The CU-UPs (620-1, 620-N) may be connected to the CU-CP (610) via an E1 interface. According to one embodiment, one DU (601, 602) can be connected to only one CU-CP (610), and one CU-UP (620-1, 620-N) can be connected to only one CU-CP (610). In addition, one DU (601, 602) can be connected to multiple CU-UPs (620-1, 620-N) under the control of the same CU-CP (610), and one CU-UP (620-1, 620-N) can be connected to multiple DUs (601, 602) under the control of the same CU-CP (610).

[0135] According to various embodiments of the present disclosure, methods and procedures for creating a security context for each network slice are described. Specifically, various embodiments may include detailed procedures for creating a security context for a network slice, including a mobile communication network and a third party. Furthermore, some embodiments may include detailed procedures for creating a security context according to a usage scenario of the network slice. Furthermore, some embodiments may include procedures for providing security by having an existing service provider participate in the security context creation procedure, thereby enabling the service provider to use a more secure network slice.

[0136] FIG. 7 illustrates a signal flow for setting security for each network slice according to embodiments of the present disclosure. More specifically, FIG. 7 illustrates a signal flow including the relationship between primary authentication for a terminal and network slice-specific authorization. For example, for a terminal to access a network slice, a home / serving PLMN may be required, which may be identified by an S-NSSAI (e.g., an authorized S-NSSAI). An authorized NSSAI (e.g., an authorized NSSAI) is provided to a terminal that has successfully completed primary authentication, and after primary authentication, the terminal and the AMF may receive a list of authorized S-NSSAIs.

[0137] In step 1, the terminal may transmit a registration request along with an S-NSSAI list. Here, the S-NSSAI list transmitted by the terminal may include at least one S-NSSAI from the configured S-NSSAI list.

[0138] In step 2, the terminal may perform primary authentication with the network. In one embodiment, for an initial registration request, the AMF / SEAF (security anchor function) may invoke primary authentication. Alternatively, for subsequent registration requests, if the terminal has already been authenticated and a valid security context exists in the AMF, primary authentication may be omitted.

[0139] In step 3, the AMF may determine whether slice-specific authentication is required for each NSSAI. In one embodiment, the AMF may determine whether network slice-specific authentication and authorization (NSSAA) is required for each S-NSSAI based on information stored in the UDM. In one embodiment, if NSSAA is not required based on subscription information, NSSAA for the S-NSSAI may be omitted in at least one of the following cases: if the terminal has successfully performed NSSAA regardless of the previous connection type and the result is still valid, or if NSSAA for the terminal is in progress.

[0140] In step 4, AMF may send a registration acceptance message to the terminal.

[0141] In step 5, the terminal can send a registration completion message to AMF.

[0142] In step 6, an extensible authentication protocol (EAP)-based NSSAA procedure for each S-NSSAI may be performed based on what was determined in step 3. In one embodiment, a master session key (MSK) may optionally be transmitted to the AMF. For example, the MSK may be included in an EPA success related message and transmitted to the AMF. The procedure of step 6 associated with the service provider and the MSK is described in more detail in FIG. 12 below. In one embodiment, the procedure of step 6 may be conveniently referred to as secondary authentication. With reference to step 6, the authentication authorization accounting (AAA)-P (provider) and the AAA-S (server) may include a server or entity including an external third-party provider.

[0143] In step 7, the AMF may transmit a UE configuration update to the UE. More specifically, based on the results of step 6, the AMF may transmit a UE configuration update message to the UE to update the requested S-NSSAI status according to the NSSAA results.

[0144] In step 8, the AMF can determine whether the received MSK can be used for NSSAI-specific key derivation.

[0145] In step 9, the terminal, the base station, and the AMF may establish a NAS security context. In one embodiment, the terminal, the base station, and the AMF may optionally use a key derived using the MSK.

[0146] In step 10, the terminal and the base station may establish an AS security context. In one embodiment, the terminal and the base station may selectively use a key derived using the MSK. More specifically, each base station needs to have a list of algorithms allowed for use set by network management. The selected ciphering algorithm or the selected integrity algorithm must be indicated to the terminal and may be used in the user plane and the RRC plane (e.g., the control plane). In one embodiment, the negotiation / security activation between the terminal and the base station for the ciphering algorithm or the integrity algorithm may be specifically referenced through the exchange procedure of the AS Security Mode Command described in 3GPP TS33.501. In addition, in various embodiments, the terminal or base station may be instructed, in addition to information about the allowed algorithms, via separate information, of a method for deriving an encryption key or an integrity key. Here, the method for deriving an encryption key or an integrity key may include at least one of the methods corresponding to the various embodiments described below (e.g., FIGS. 8A to 16 ). For example, a terminal or base station may be instructed on at least one of the NSSAI value, the MSK value, or whether to use a CU-CP-ID or CU-UP-ID, and may determine a method for deriving an encryption key or an integrity key.

[0147] According to various embodiments of the present disclosure, FIG. 7 discloses procedures in which a terminal, a base station, or a network entity receives an instruction (e.g., an instruction based on at least one of an NSSAI value, an MSK value, or whether to use a CU-CP-ID or a CU-UP-ID, etc.) for performing slice-specific authentication, or a procedure for obtaining an S-NSSAI, or a method for deriving an encryption key or an integrity key, and operates accordingly; however, not all of the procedures or steps are essential components, and some of the steps may be omitted if necessary. That is, the signal flow of FIG. 7 is merely an example, and various embodiments may include at least one of all, some, or a combination of some of the steps disclosed in FIG. 7. For example, a terminal or base station according to one embodiment may include at least one of a step for obtaining an S-NSSAI for establishing an AS security context, a second authentication step for obtaining an MSK, a step for establishing an AS security context, or an additional step as part of the embodiments described below for establishing a security context using a specific encryption / integrity key.

[0148] Figures 8a and 8b illustrate an example of establishing a user plane (UP) security context for each network slice according to embodiments of the present disclosure. It should be noted that in the embodiments described below, the ME may include a mobile device included in the terminal or the terminal itself.

[0149] According to various embodiments of the present disclosure, the terminal and the base station may obtain and have in advance K_gNB (hereinafter, for convenience, used interchangeably with 'base station key') generated based on the AMF key (K_AMF). In addition, the terminal and the base station may exchange algorithms for deriving an integrity key or an encryption key through an AS security procedure. According to one embodiment, the terminal and the base station may obtain in advance at least one of slice identifier information (e.g., S-NSSAI) per specific slice or MSK associated with a service provider according to some of the procedures described in FIG. 7 (e.g., primary authentication or secondary authentication).

[0150] Referring to the base station structure (810) of FIG. 8A, the base station may include a CU-CP, multiple CU-UPs, and multiple DUs, as described in FIG. 6. Here, the multiple CU-UPs may be connected to a data network based on different network slices. For example, referring to the communication network environment (820) of FIG. 8A, CU-UP1 among the CU-UPs may exchange data with the data network through a slice for URLLC service, or CU-UP2 may exchange data with the data network through a slice for eMBB service.

[0151] However, as described above, current wireless communication networks only use a common security key regardless of each slice, and do not include a specific method for establishing a security context for each slice. According to embodiments of the present disclosure, terminals and base stations can establish and assign individual security contexts for each slice, and enable access control for each slice by enabling the use of individual keys.

[0152] Referring to FIG. 8b, the terminal and the base station can derive a security context for each network slice using information for distinguishing network slices. That is, the terminal and the base station can derive a security context for each network slice using the identifier (ID) of the S-NSSAI (or the number (S-NSSAI#) of the S-NSSAI).

[0153] Referring to the first key system (830) of FIG. 8b, the terminal and the base station can each use K_gNB to derive a key (K_RRCint) for integrity protection of control signaling and a key (K_RRCenc) for encryption. Here, the keys generated for control signaling can correspond to signaling via the base station's CU-CP.

[0154] According to one embodiment, the terminal and the base station may derive the following base station keys using K_gNB and NH, respectively. The terminal and the base station may derive a key (K_UPint) for integrity protection of user plane data using K_gNB, N-UP-int-alg, Alg_ID, and S-NSSAI# values, or may derive a key (K_UPenc) for encryption using K_gNB, N-UP-enc-alg, Alg_ID, and S-NSSAI# values. In this case, the terminal and the base station may derive keys for each CU-UP corresponding to a separate slice. For example, the terminal and the base station may derive an integrity protection key and an encryption protection key for CU-UP#1 corresponding to S-NSSAI#1 (e.g., a slice for URLLC service), and separately, an integrity protection key and an encryption protection key for CU-UP#N corresponding to S-NSSAI#N (e.g., a slice for eMBB service).

[0155] More specifically, referring to the second key scheme (840) of FIG. 8B, the terminal and the base station can derive K_gNB* and thus K_gNB using PCI and ARFCN-DL based on the K_gNB and NH key obtained from the AMF. According to one embodiment, the terminal and the base station can derive K_UPint and K_UPenc through KDF based on the ID of the integrity / encryption algorithm and the delimiter information for the algorithm for the K_gNB and the user plane. According to one embodiment, the terminal and the base station can further use a slice identifier (e.g., S-NSSAI) to derive the integrity key and the encryption key for the user plane. Accordingly, the integrity key or the encryption key derived by the terminal and the base station can be generated as a slice-independent key corresponding to information about a specific slice. Additionally, the derived 256-bit integrity key and encryption key can be truncated to generate 128-bit user plane-related keys.

[0156] According to various embodiments of the present disclosure, the terminal and base station derive an integrity key or encryption key using information about each specific network slice, thereby allocating and establishing a security context for each network slice. Accordingly, the terminal and base station can establish security and implement access control between distinct network slices, even in an environment connected to multiple slices.

[0157] Figures 9a and 9b illustrate an example of establishing a network slice-specific security context according to embodiments of the present disclosure. More specifically, Figures 9a and 9b describe a method for establishing a slice-specific security context, taking into account a structure in which multiple CU-UPs are connected to a single CU-CP. It should be noted that in the embodiments described below, the ME may include a mobile device included in the terminal or the terminal itself.

[0158] According to various embodiments of the present disclosure, the terminal and the base station may obtain and have in advance K_gNB (hereinafter, for convenience, used interchangeably with 'base station key') generated based on the AMF key (K_AMF). In addition, the terminal and the base station may exchange algorithms for deriving an integrity key or an encryption key through an AS security procedure. According to one embodiment, the terminal and the base station may obtain in advance at least one of slice identifier information (e.g., S-NSSAI) per specific slice or MSK associated with a service provider according to some of the procedures described in FIG. 7 (e.g., primary authentication or secondary authentication).

[0159] Referring to the base station structure (910) of FIG. 9A, the base station may include a CU-CP, a plurality of CU-UPs, and a plurality of DUs, as described in FIG. 6. Here, a specific CU-UP connected to one base station (e.g., a DU) and a specific CU-UP connected to another base station may be connected to a data network based on different network slices, respectively. For example, referring to the communication network environment (920) of FIG. 9A, one of the base stations may exchange data with the data network through a slice for a URLLC service, or another may exchange data with the data network through a slice for an eMBB service.

[0160] However, as described above, current wireless communication networks only use a common security key regardless of each slice, and do not include a specific method for establishing a security context for each slice. According to embodiments of the present disclosure, a terminal and a base station can establish and assign individual security contexts for each slice, and enable access control for each slice by enabling the use of individual keys. In particular, according to one embodiment, a specific example for establishing a security context for each slice between base stations including a gNB-CU-CP / UP structure that uses a common base station key is described.

[0161] Referring to FIG. 9b, the terminal and the base station can derive a security context for each network slice using information for distinguishing network slices. That is, the terminal and the base station can derive a security context for each network slice using the identifier (ID) of the S-NSSAI (or the number (S-NSSAI#) of the S-NSSAI). In addition, the terminal and the base station can also derive a security context for each slice corresponding to each base station using a user plane identifier (e.g., gNB-CU-UP-ID).

[0162] Referring to the first key scheme (930) of FIG. 9b, the terminal and each base station can derive a key (K_RRCint) for integrity protection of control signaling, a key (K_RRCenc) for encryption, and a key (K_UPint) for integrity protection of user plane data, and a key (K_UPenc) for encryption, using K_gNB. Here, the keys generated for control signaling can correspond to signaling via the CU-CP of the base station. At this time, the terminal and the base station can derive keys for each CU-UP corresponding to a separate slice and for the CU-CP corresponding to each base station. For example, the terminal and the base station can derive an integrity protection and encryption key for control signaling corresponding to a specific base station (e.g., the first DU), and together with this, an integrity protection key and an encryption protection key for CU-UP#1 corresponding to S-NSSAI#1 (e.g., a slice for URLLC service). Separately, the terminal and base station can derive integrity protection and encryption keys for control signaling corresponding to another base station (e.g., a second DU), and together with this, derive integrity protection keys and encryption protection keys for CU-UP#N corresponding to S-NSSAI#N (e.g., a slice for eMBB service).

[0163] More specifically, referring to the second key scheme (940) of FIG. 9b, the terminal and the base station can derive K_gNB* and K_gNB accordingly using PCI and ARFCN-DL based on the K_gNB and NH keys obtained from the AMF. According to one embodiment, the terminal and the base station can derive K_RRCint and K_RRCenc through KDF based on identifier information about the ID and algorithm of the integrity / encryption algorithm for the K_gNB and the control plane. In addition, the terminal and the base station can derive K_UPint and K_UPenc through KDF based on identifier information about the ID and algorithm of the integrity / encryption algorithm for the K_gNB and the user plane. According to one embodiment, the terminal and the base station may further use at least one of a slice identifier (e.g., S-NSSAI) or a gNB-CU-UP-ID (e.g., a CU-UP identifier or a user plane identifier) ​​to derive integrity keys and encryption keys for the control plane and the user plane, respectively. Accordingly, the integrity keys or encryption keys derived by the terminal and the base station may be generated as slice-independent keys corresponding to information about a specific slice, and furthermore, particularly in an environment where multiple CU-UPs and multiple base stations (e.g., gNBs or DUs) exist, a slice-specific security context for each distinct base station may be established using a shared common K_gNB. Additionally, the derived 256-bit integrity key and encryption key may be truncated to generate 128-bit user plane-related keys.

[0164] According to various embodiments of the present disclosure, a terminal and a base station derive an integrity key or an encryption key using information about each specific network slice and an identifier for each CU-UP, so that the terminal and the base station can allocate and establish a security context for each network slice without ambiguity for each CU-UP even in an environment where multiple base stations exist. Accordingly, the terminal and the base station can establish security and realize access control between each distinct network slice even in an environment where multiple base stations are connected to multiple slices.

[0165] Figure 10 illustrates an example of establishing a security context per base station according to embodiments of the present disclosure. More specifically, Figure 10 describes a method for establishing a security context per base station, considering a scenario in which multiple base stations are connected and share one or more K_gNBs. Here, a specific base station can manage one or more K_gNBs. It should be noted that in the embodiments described below, the ME may include a mobile device included in the terminal or the terminal itself.

[0166] According to various embodiments of the present disclosure, a terminal and a base station may obtain a K_gNB (hereinafter, for convenience, interchangeably used as a 'base station key') generated through a KDF based on an AMF key (K_AMF) and a control plane identifier (e.g., gNB-CU-CP-ID). In addition, the terminal and the base station may exchange an algorithm for deriving an integrity key or an encryption key through an AS security procedure. According to one embodiment, the terminal and the base station may obtain in advance at least one of slice identifier information (e.g., S-NSSAI) per specific slice or an MSK associated with a service provider according to some of the procedures described in FIG. 7 (e.g., primary authentication or secondary authentication).

[0167] In one embodiment, the current wireless communication network only uses a common security key regardless of each base station or slice, and does not include a method for establishing a specific base station or slice-specific security context. In accordance with embodiments of the present disclosure, a terminal and a base station can establish and assign individual security contexts for each base station, and enable slice-specific access control by enabling the use of individual keys. In particular, in one embodiment, a specific example for establishing a security context for each base station or slice in a structure in which there are base stations including a gNB-CU-CP / UP structure that uses a common base station key is described.

[0168] Referring to FIG. 10, the terminal and the base station can derive a security context for each base station using information for distinguishing each base station (e.g., CU-CP). That is, the terminal and the base station can derive a security context for each base station using the identifier (ID) of the S-NSSAI and CU-CP.

[0169] Referring to the first key scheme (1010) of FIG. 10, the terminal and each base station can derive a key (K_RRCint) for integrity protection of control signaling, a key (K_RRCenc) for encryption, and a key (K_UPint) for integrity protection of user plane data, and a key (K_UPenc) for encryption, using K_gNB. Here, the keys generated for the control signaling can correspond to signaling through the CU-CP of the base station. At this time, the terminal and the base station can derive keys for each CU-UP corresponding to a separate slice and for the CU-CP corresponding to each base station. For example, the terminal and the base station can derive an integrity protection and encryption key for the control signaling corresponding to a specific base station (e.g., the first CU-CP-ID), and together with this, an integrity protection key and an encryption protection key for the CU-UP#1 corresponding to S-NSSAI#1 (e.g., a slice for URLLC service). Separately, the terminal and the base station can derive integrity protection and encryption keys for control signaling corresponding to another base station (e.g., a second CU-CP-ID), and together with this, derive integrity protection keys and encryption protection keys for CU-UP#N corresponding to S-NSSAI#N (e.g., a slice for eMBB service).

[0170] More specifically, referring to the second key scheme (1020) of FIG. 10, the terminal and the base station can obtain K_gNB and NH keys from the AMF. Here, the obtained K_gNB may include a key generated through a KDF based on a slice identifier (e.g., S-NSSAI#) corresponding to a network slice and an identifier of a CP (e.g., gNB-CU-CP-ID) corresponding to a specific base station. Accordingly, the terminal and the base station can obtain K_gNBs that are distinct for each base station and each slice, so that in an environment where multiple base stations exist, a security context per base station and a security context per network slice can be established.

[0171] According to one embodiment, based on the above-described key, the terminal and the base station can derive K_gNB* and K_gNB accordingly using PCI, ARFCN-DL. According to one embodiment, the terminal and the base station can derive K_RRCint and K_RRCenc through KDF based on identifier information about the ID and algorithm of the integrity / encryption algorithm for the K_gNB and the control plane. In addition, the terminal and the base station can derive K_UPint and K_UPenc through KDF based on identifier information about the ID and algorithm of the integrity / encryption algorithm for the K_gNB and the user plane. According to one embodiment, even if the terminal and the base station do not have an additional slice identifier (e.g., S-NSSAI) or gNB-CU-UP-ID (e.g., CU-UP identifier or user plane identifier), since the acquired K_gNB itself was generated in the previous step to be able to correspond per slice or per base station, a security context capable of access control can be established. However, this is merely an example, and it is not excluded that various keys may be generated by adding slice identifiers or user plane identifiers, of course, for additional security enhancement, depending on various embodiments. Accordingly, the integrity key or encryption key derived by the terminal and base station may be generated as a slice-independent key and a base station-independent key corresponding to information about a specific slice. Additionally, the derived 256-bit integrity key and encryption key may be truncated to generate 128-bit user plane-related keys.

[0172] According to various embodiments of the present disclosure, a terminal and a base station derive an integrity key or an encryption key using information about each specific network slice and an identifier for each base station, so that the terminal and the base station can assign and establish a security context for each network slice without ambiguity for each base station even in an environment where multiple base stations exist. Accordingly, the terminal and the base station can establish distinct security between each base station and each network slice and realize access control even in an environment where multiple base stations are connected to multiple slices.

[0173] Figures 11a and 11b illustrate an example for establishing a security context per base station according to embodiments of the present disclosure. More specifically, Figures 11a and 11b describe a method for establishing a security context per base station and slice, taking into account a structure in which multiple CU-CPs and multiple CU-UPs are connected (e.g., a structure in which multiple base stations are connected, such as dual connectivity). It should be noted that in the embodiments described below, the ME may include a mobile device included in the terminal or the terminal itself.

[0174] Referring to the base station structure (1110) of FIG. 11A, the base station may include a plurality of CU-CPs, a plurality of CU-UPs, and a plurality of DUs. Here, specific CU-UPs connected to each of the multiple base stations (e.g., CU-CPs) may be connected to a data network based on different network slices. For example, referring to the communication network environment (1120) of FIG. 11A, a specific CU-UP of each base station may exchange data with the data network through a slice for URLLC services, and another CU-UP may exchange data with the data network through a slice for eMBB services. In one embodiment, this may mean an environment such as dual connectivity that includes secondary gNBs. Accordingly, since each slice may be transmitted by a different base station, each base station may include a different base station security context in the AS.

[0175] However, as described above, current wireless communication networks only use a common security key regardless of each slice, and do not include a specific method for establishing a security context for each base station or slice. According to embodiments of the present disclosure, terminals and base stations can establish and assign individual security contexts for each base station or slice, and enable access control for each base station or slice by enabling the use of individual keys.

[0176] Referring to FIG. 11b, the terminal and the base station can derive a security context for each network slice by using information for distinguishing each base station (e.g., CU-CP) and information for distinguishing network slices. That is, the terminal and the base station can derive a security context for each base station or network slice by using the identifier (ID) of the CU-CP and the identifier (ID) of the S-NSSAI (or the number (S-NSSAI#) of the S-NSSAI). In addition, the terminal and the base station can also derive a security context for each slice corresponding to each base station by further using a user plane identifier (e.g., gNB-CU-UP-ID).

[0177] Referring to the first key scheme (1130) of FIG. 11b, the terminal and each base station can derive a key (K_RRCint) for integrity protection of control signaling, a key (K_RRCenc) for encryption, and a key (K_UPint) for integrity protection of user plane data, and a key (K_UPenc) for encryption, using K_gNB. Here, the keys generated for the control signaling can correspond to signaling through the CU-CP of the base station. At this time, the terminal and the base station can derive keys for each CU-UP corresponding to a separate slice and for the CU-CP corresponding to each base station. For example, the terminal and the base station can derive an integrity protection and encryption key for the control signaling corresponding to a specific base station (e.g., the first CU-CP-ID), and together with this, an integrity protection key and an encryption protection key for the CU-UP#1 corresponding to S-NSSAI#1 (e.g., a slice for URLLC service). Separately, the terminal and the base station can derive integrity protection and encryption keys for control signaling corresponding to another base station (e.g., a second CU-CP-ID), and together with this, derive integrity protection keys and encryption protection keys for CU-UP#N corresponding to S-NSSAI#N (e.g., a slice for eMBB service).

[0178] More specifically, referring to the second key scheme (1140) of FIG. 11B, the terminal and the base station can obtain K_gNB and NH keys from the AMF. Here, the obtained K_gNB may include a key generated through KDF based on an identifier of a CP corresponding to a specific base station (e.g., gNB-CU-CP-ID). Accordingly, the terminal and the base station can obtain a K_gNB that is distinct for each base station, so that a security context for each base station can be established in an environment where multiple base stations exist.

[0179] According to one embodiment, based on the above-described keys, the terminal and the base station can derive K_gNB* and K_gNB accordingly using PCI and ARFCN-DL. According to one embodiment, the terminal and the base station can derive K_RRCint and K_RRCenc through KDF based on identifier information about the ID and algorithm of the integrity / encryption algorithm for K_gNB and the control plane. In addition, the terminal and the base station can derive K_UPint and K_UPenc through KDF based on identifier information about the ID and algorithm of the integrity / encryption algorithm for K_gNB and the user plane. According to one embodiment, the terminal and the base station can further use at least one of a slice identifier (e.g., S-NSSAI) or a gNB-CU-UP-ID (e.g., a CU-UP identifier or a user plane identifier) ​​to derive the integrity key and the encryption key for the control plane and the user plane. Accordingly, the integrity key or encryption key derived by the terminal and the base station can be generated as a slice-independent key corresponding to information about a specific slice, and furthermore, especially in an environment where multiple CU-UPs and multiple base stations (e.g., gNBs) exist, a slice-specific security context can be established for each distinct base station using a shared common K_gNB. Additionally, the derived 256-bit integrity key and encryption key can be truncated to generate 128-bit user plane-related keys.

[0180] According to various embodiments of the present disclosure, a terminal and a base station derive an integrity key or an encryption key using information about each specific network slice and an identifier for each base station, so that the terminal and the base station can assign and establish a security context for each base station or network slice without ambiguity for each base station or CU-UP even in an environment where multiple base stations exist. Accordingly, the terminal and the base station can establish security and realize access control between each base station or network slice that are distinct even in an environment where multiple base stations are connected to multiple slices.

[0181] According to various embodiments of the present disclosure, FIGS. 8A to 11B disclose various examples for a terminal or a base station to establish an AS security context. However, not all examples or procedures included in the examples are essential components, and some examples or procedures may be omitted as needed. Furthermore, it should be understood that other procedures of the present disclosure (e.g., some of the procedures of FIG. 7 or FIG. 12 ) may be included and performed together to perform the above-described examples.

[0182] FIG. 12 illustrates a signal flow for exchanging a master session key (MSK) according to embodiments of the present disclosure. More specifically, FIG. 12 relates to a slice-specific authentication procedure initiated by step 6 of FIG. 7, and illustrates a signal flow according to the NSSAA procedure (conveniently referred to as secondary authentication) between an external third-party AAA server (AAA-S) and a terminal.

[0183] In step 1, for S-NSSAIs that require NSSAA, based on a change in subscription information or a trigger of AAA-S, AMF may trigger the NSSAA procedure.

[0184] In step 2, the AMF may request a UE user ID (e.g., EAP ID) for EAP authentication for the S-NSSAI via a NAS MM transport message containing the S-NSSAI.

[0185] In step 3, the terminal may send a NAS MM transport message containing the EAP ID and S-NSSAI for the S-NSSAI to the AMF.

[0186] In step 4, the AMF may send an authentication request message containing the EAP ID to the network slice specific authentication and authorization function (NSSAAF) that provides an interface with AAA.

[0187] In step 5, if an AAA-P exists (e.g., if the AAA-S is owned by another carrier and the operator deploys a proxy to the other carrier), the NSSAAF can forward the EAP ID response message to the AAA-P, or if no AAA-P exists, it can forward it directly to the AAA-S.

[0188] In steps 6 through 11, EAP messages may be exchanged with the terminal, and these steps may be repeated more than once. For more detailed procedures, refer to section 16.3 of 3GPP TS33.501.

[0189] In step 12, EAP authentication may be completed. At this time, the MSK may be passed to the NSSAAF along with the EAP success / failure message, the generic public subscription identifier (GPSI), and the external network slice information (S-NSSAI / ENSI).

[0190] In step 13, NSSAAF may send MSK along with EAP success / failure message, S-NSSAI, and GPSI to AMF.

[0191] In step 14, AMF can send an EAP success / failure message to the terminal.

[0192] Through the above-described process, the AMF can obtain an MSK from an AAA server associated with an external operator. The MSK may include a type of temporary symmetric / master key, and typically, only the terminal and the authentication server may have the MSK after authentication. However, according to embodiments of the present disclosure, since the MSK is delivered to the AMF as a root of trust (RoT), the MSK can be used to generate a K_gNB as in the examples described below, thereby allowing the external operator to intervene in the terminal's network slice, thereby enabling more efficient allocation and establishment of a per-slice security context.

[0193] According to various embodiments of the present disclosure, FIG. 12 discloses procedures for a terminal, a core network entity, and an external service provider's server to perform slice-specific authentication or procedures for an AMF to obtain an MSK; however, not all procedures or steps are essential components, and some steps may be omitted as needed. That is, the signal flow of FIG. 12 is merely an example, and various embodiments may include at least one of all, some, or a combination of some of the steps disclosed in FIG. 12 . For example, an AMF according to one embodiment may already obtain an MSK based on the procedure disclosed in FIG. 12 , and may include at least one of additional steps as part of a procedure for generating a K_gNB according to the procedure, or establishing a security context using a specific encryption / integrity key according to the procedure, as part of the embodiments to be described below.

[0194] Figure 13 illustrates an example of establishing a user plane security context for each network slice using MSK according to embodiments of the present disclosure. It should be noted that in the embodiments described below, the ME may include a mobile device included in the terminal or the terminal itself.

[0195] According to various embodiments of the present disclosure, the terminal and the base station may obtain and have in advance K_gNB (hereinafter, for convenience, used interchangeably with 'base station key') generated based on the AMF key (K_AMF). In addition, the terminal and the base station may exchange an algorithm for deriving an integrity key or an encryption key through an AS security procedure. According to one embodiment, the terminal and the base station may obtain in advance slice identifier information (e.g., S-NSSAI) for each specific slice according to some of the procedures described in FIG. 7 (e.g., primary authentication or secondary authentication), or the base station may obtain in advance at least one of the MSKs associated with the service provider from the AMF.

[0196] Referring to FIG. 13, the terminal and the base station can derive a security context for each network slice using information for distinguishing network slices. That is, the terminal and the base station can derive a security context for each network slice using the identifier (ID) of the S-NSSAI (or the number (S-NSSAI#) of the S-NSSAI) and the MSK associated with an external operator. Here, the MSK can be used to create a new K_gNB to provide a trust chain.

[0197] Referring to the first key scheme (1310) of FIG. 13, the terminal and the base station can derive a key (K_RRCint) for integrity protection of control signaling and a key (K_RRCenc) for encryption using K_gNB, NH, and MSK, respectively. More specifically, NH or MSK can be used to derive the base station key (K_gNB), and the terminal and the base station can derive a key (K_RRCint) for integrity protection and a key (K_RRCenc) for encryption based on the ID of K_gNB and the integrity / encryption algorithm and the identifier information for the algorithm. Here, the keys generated for control signaling can correspond to signaling through the CU-CP of the base station.

[0198] According to one embodiment, the terminal and the base station can derive a key (K_UPint) for integrity protection of user plane data and a key (K_UPenc) for encryption using K_gNB based on NH and MSK, respectively. At this time, the terminal and the base station can derive keys for each CU-UP corresponding to a separate slice. For example, the terminal and the base station can derive an integrity protection key and an encryption protection key for CU-UP#1 corresponding to S-NSSAI#1 (e.g., a slice for URLLC service), and separately, derive an integrity protection key and an encryption protection key for CU-UP#N corresponding to S-NSSAI#N (e.g., a slice for eMBB service). The integrity protection key and the encryption protection key generated here can include a key derived by further reflecting information associated with an external operator based on the MSK.

[0199] More specifically, referring to the second key scheme (1320) of FIG. 13, the terminal and the base station can derive K_gNB* and K_gNB accordingly using PCI, ARFCN-DL, and MSK based on K_gNB, NH key, and MSK obtained from AMF. According to one embodiment, the terminal and the base station can derive K_UPint and K_UPenc through KDF based on the ID of the integrity / encryption algorithm and the identifier information for the algorithm for the K_gNB and the user plane. According to one embodiment, the terminal and the base station can further use a slice identifier (e.g., S-NSSAI) to derive the integrity key and the encryption key for the user plane. Accordingly, the integrity key or the encryption key derived by the terminal and the base station can be generated as a slice-independent key corresponding to information about a specific slice. Additionally, the derived 256-bit integrity key and encryption key can be truncated to generate 128-bit user plane related keys.

[0200] According to various embodiments of the present disclosure, terminals and base stations derive integrity keys or encryption keys using information about each specific network slice and an MSK associated with an external service provider. Thus, the terminals and base stations can allocate and establish security contexts for each network slice that reflect information from the external service provider. Accordingly, the terminals and base stations can establish distinct security and access control between each network slice, even in an environment connected to multiple slices.

[0201] Figure 14 illustrates an example of establishing a network slice-specific security context using an MSK according to embodiments of the present disclosure. More specifically, Figure 14 describes a method for establishing a slice-specific security context, taking into account a structure in which multiple CU-UPs are connected to a single CU-CP. It should be noted that in the embodiments described below, the ME may include a mobile device included in the terminal or the terminal itself.

[0202] According to various embodiments of the present disclosure, the terminal and the base station may obtain and have in advance K_gNB (hereinafter, for convenience, used interchangeably with 'base station key') generated based on the AMF key (K_AMF). In addition, the terminal and the base station may exchange an algorithm for deriving an integrity key or an encryption key through an AS security procedure. According to one embodiment, the terminal and the base station may obtain in advance slice identifier information (e.g., S-NSSAI) for each specific slice according to some of the procedures described in FIG. 7 (e.g., primary authentication or secondary authentication), or the base station may obtain in advance at least one of the MSKs associated with the service provider from the AMF.

[0203] Referring to FIG. 14, the terminal and the base station can derive a security context for each network slice using information for distinguishing network slices. That is, the terminal and the base station can derive a security context for each network slice using the identifier (ID) of the S-NSSAI (or the number (S-NSSAI#) of the S-NSSAI) and the MSK associated with an external operator. Here, the MSK can be used to generate a new K_gNB to provide a chain of trust. In addition, the terminal and the base station can further derive a security context for each slice corresponding to each base station using a user plane identifier (e.g., gNB-CU-UP-ID).

[0204] Referring to the first key scheme (1410) of FIG. 14, the terminal and each base station can derive a key (K_RRCint) for integrity protection of control signaling, a key (K_RRCenc) for encryption, and a key (K_UPint) for integrity protection of user plane data, and a key (K_UPenc) for encryption, using K_gNB. More specifically, NH or MSK can be used to derive the base station key (K_gNB), and the terminal and base station can derive a key (e.g., K_UPint or K_RRCint) for integrity protection and a key (e.g., K_UPenc or K_RRCenc) for encryption based on the ID of the K_gNB and the integrity / encryption algorithm and the identifier information for the algorithm. Here, the keys generated for control signaling can correspond to signaling via the CU-CP of the base station. At this time, the terminal and the base station can derive keys for each CU-UP corresponding to a separate slice and each CU-CP corresponding to each base station. For example, the terminal and the base station can derive an integrity protection and encryption key for control signaling corresponding to a specific base station (e.g., a first DU), and together with the integrity protection key and the encryption protection key for CU-UP#1 corresponding to S-NSSAI#1 (e.g., a slice for URLLC service). Separately, the terminal and the base station can derive an integrity protection and encryption key for control signaling corresponding to another base station (e.g., a second DU), and together with the integrity protection key and the encryption protection key for CU-UP#N corresponding to S-NSSAI#N (e.g., a slice for eMBB service).

[0205] More specifically, referring to the second key scheme (1420) of FIG. 14, the terminal and the base station can derive K_gNB* and K_gNB accordingly using PCI, ARFCN-DL, and MSK based on the K_gNB and NH key obtained from the AMF. According to one embodiment, the terminal and the base station can derive K_RRCint and K_RRCenc through the KDF based on the identifier information for the ID and algorithm of the integrity / encryption algorithm for the K_gNB and the control plane. In addition, the terminal and the base station can derive K_UPint and K_UPenc through the KDF based on the identifier information for the ID and algorithm of the integrity / encryption algorithm for the K_gNB and the user plane. According to one embodiment, the terminal and the base station may further use at least one of a slice identifier (e.g., S-NSSAI) or a gNB-CU-UP-ID (e.g., a CU-UP identifier or a user plane identifier) ​​to derive integrity keys and encryption keys for the control plane and the user plane, respectively. Accordingly, the integrity keys or encryption keys derived by the terminal and the base station may be generated as slice-independent keys corresponding to information about a specific slice, and furthermore, particularly in an environment where multiple CU-UPs and multiple base stations (e.g., gNBs or DUs) exist, a slice-specific security context for each distinct base station may be established using a shared common K_gNB. Additionally, the derived 256-bit integrity key and encryption key may be truncated to generate 128-bit user plane-related keys.

[0206] According to various embodiments of the present disclosure, a terminal and a base station derive an integrity key or an encryption key using information about each specific network slice, an MSK associated with an external operator, and an identifier for each CU-UP, so that the terminal and the base station can allocate and establish a security context for each network slice that reflects information of an external operator without ambiguity about each CU-UP even in an environment where multiple base stations exist. Accordingly, the terminal and the base station can establish security and realize access control between each network slice that are distinct even in an environment where multiple base stations are connected to multiple slices.

[0207] Figure 15 illustrates an example of establishing a base station security context for each network slice using MSK according to embodiments of the present disclosure. More specifically, Figure 15 describes a method for establishing a base station security context for each base station, considering a scenario in which multiple base stations are connected and share one or more K_gNBs. Here, a specific base station can manage one or more K_gNBs. In the embodiments described below, the ME may of course include a mobile device included in a terminal or the terminal itself.

[0208] According to various embodiments of the present disclosure, a terminal and a base station may obtain a K_gNB (hereinafter, for convenience, interchangeably used as a 'base station key') generated through a KDF based on an AMF key (K_AMF) and a control plane identifier (e.g., gNB-CU-CP-ID). In addition, the terminal and the base station may exchange an algorithm for deriving an integrity key or an encryption key through an AS security procedure. According to one embodiment, the terminal and the base station may obtain slice identifier information (e.g., S-NSSAI) for each specific slice in advance according to some of the procedures described in FIG. 7 (e.g., primary authentication or secondary authentication), or the base station may obtain at least one of the MSKs associated with a service provider in advance from the AMF.

[0209] In one embodiment, the current wireless communication network only uses a common security key regardless of each base station or slice, and does not include a method for establishing a specific base station or slice-specific security context. In accordance with embodiments of the present disclosure, a terminal and a base station can establish and assign individual security contexts for each base station, and enable slice-specific access control by enabling the use of individual keys. In particular, in one embodiment, a specific example for establishing a security context for each base station or slice in a structure in which there are base stations including a gNB-CU-CP / UP structure that uses a common base station key is described.

[0210] Referring to FIG. 15, the terminal and the base station can derive a security context for each base station using information for distinguishing each base station (e.g., CU-CP). That is, the terminal and the base station can derive a security context for each base station using the identifier (ID) of the MSK, S-NSSAI, and CU-CP.

[0211] Referring to the first key scheme (1510) of FIG. 15, the terminal and each base station can derive a key (K_RRCint) for integrity protection of control signaling, a key (K_RRCenc) for encryption, and a key (K_UPint) for integrity protection of user plane data, and a key (K_UPenc) for encryption, using K_gNB, NH, and MSK. More specifically, NH or MSK can be used to derive the base station key (K_gNB), and the terminal and base station can derive a key (e.g., K_UPint or K_RRCint) for integrity protection and a key (e.g., K_UPenc or K_RRCenc) for encryption based on the ID of K_gNB and the integrity / encryption algorithm and the identifier information for the algorithm. Here, the keys generated for control signaling can correspond to signaling through the CU-CP of the base station. At this time, the terminal and the base station can derive keys for each CU-UP corresponding to a separate slice and each CU-CP corresponding to each base station. For example, the terminal and the base station can derive an integrity protection and encryption key of control signaling corresponding to a specific base station (e.g., a first CU-CP-ID), and, using an MSK associated with an external operator, derive an integrity protection key and an encryption protection key for CU-UP#1 corresponding to S-NSSAI#1 (e.g., a slice for URLLC service). Separately, the terminal and the base station can derive an integrity protection and encryption key of control signaling corresponding to another base station (e.g., a second CU-CP-ID), and, using an MSK associated with an external operator, derive an integrity protection key and an encryption protection key for CU-UP#N corresponding to S-NSSAI#N (e.g., a slice for eMBB service).

[0212] More specifically, referring to the second key scheme (1520) of FIG. 15, the terminal and the base station can obtain the K_gNB and NH keys from the AMF. Here, the obtained K_gNB may include a key generated through a KDF based on a slice identifier (e.g., S-NSSAI#) corresponding to a network slice, an identifier of a CP corresponding to a specific base station (e.g., gNB-CU-CP-ID), and an MSK associated with an external operator. Accordingly, the terminal and the base station can obtain a K_gNB that is distinguished for each base station and each slice and in which information of an external operator is reflected, so that in an environment where multiple base stations exist, a security context for each base station and a security context for each network slice can be established.

[0213] According to one embodiment, based on the above-described key, the terminal and the base station can derive K_gNB* and K_gNB accordingly using PCI, ARFCN-DL. According to one embodiment, the terminal and the base station can derive K_RRCint and K_RRCenc through KDF based on identifier information about the ID and algorithm of the integrity / encryption algorithm for the K_gNB and the control plane. In addition, the terminal and the base station can derive K_UPint and K_UPenc through KDF based on identifier information about the ID and algorithm of the integrity / encryption algorithm for the K_gNB and the user plane. According to one embodiment, even if the terminal and the base station do not have an additional slice identifier (e.g., S-NSSAI) or gNB-CU-UP-ID (e.g., CU-UP identifier or user plane identifier), since the acquired K_gNB itself was generated in the previous step to be able to correspond per slice or per base station, a security context capable of access control can be established. However, this is merely an example, and it is not excluded that various keys may be generated by adding slice identifiers or user plane identifiers, of course, for additional security enhancement, depending on various embodiments. Accordingly, the integrity key or encryption key derived by the terminal and base station may be generated as a slice-independent key and a base station-independent key corresponding to information about a specific slice. Additionally, the derived 256-bit integrity key and encryption key may be truncated to generate 128-bit user plane-related keys.

[0214] According to various embodiments of the present disclosure, a terminal and a base station derive an integrity key or an encryption key using information about each specific network slice, an MSK associated with an external operator, and an identifier for each base station, so that the terminal and the base station can allocate and establish a security context for each network slice that reflects information of an external operator without ambiguity about each base station even in an environment where multiple base stations exist. Accordingly, the terminal and the base station can establish distinct security between each base station and security between each network slice and realize access control even in an environment where multiple base stations are connected to multiple slices.

[0215] FIG. 16 illustrates an example of establishing a security context per base station using MSK according to embodiments of the present disclosure. More specifically, FIG. 16 describes a method for establishing a security context per base station and slice, taking into account a structure in which multiple CU-CPs and multiple CU-UPs are connected (e.g., a structure in which multiple base stations are connected, such as dual connectivity). It should be noted that in the embodiments described below, the ME may include a mobile device included in the terminal or the terminal itself.

[0216] Referring to FIG. 16, the terminal and the base station can derive a security context for each network slice by using information for distinguishing each base station (e.g., CU-CP) and information for distinguishing network slices. That is, the terminal and the base station can derive a security context for each base station or network slice by using an identifier (ID) of the CU-CP, an identifier (ID) of the S-NSSAI (or a number (S-NSSAI#) of the S-NSSAI), and an MSK associated with an external operator. Here, the MSK can be used to generate a new K_gNB to provide a chain of trust. In addition, the terminal and the base station can further derive a security context for each slice corresponding to each base station by using a user plane identifier (e.g., gNB-CU-UP-ID).

[0217] Referring to the first key scheme (1610) of FIG. 16, the terminal and each base station can derive a key (K_RRCint) for integrity protection of control signaling, a key (K_RRCenc) for encryption, and a key (K_UPint) for integrity protection of user plane data, and a key (K_UPenc) for encryption, using K_gNB. More specifically, NH or MSK can be used to derive the base station key (K_gNB), and the terminal and base station can derive a key (e.g., K_UPint or K_RRCint) for integrity protection and a key (e.g., K_UPenc or K_RRCenc) for encryption based on the ID of the K_gNB and the integrity / encryption algorithm and the identifier information for the algorithm. Here, the keys generated for control signaling can correspond to signaling via the CU-CP of the base station. At this time, the terminal and the base station can derive keys for each CU-UP corresponding to a separate slice and each CU-CP corresponding to each base station. For example, the terminal and the base station can derive an integrity protection and encryption key of control signaling corresponding to a specific base station (e.g., a first CU-CP-ID), and together with the integrity protection key and the encryption protection key for CU-UP#1 corresponding to S-NSSAI#1 (e.g., a slice for URLLC service). Separately, the terminal and the base station can derive an integrity protection and encryption key of control signaling corresponding to another base station (e.g., a second CU-CP-ID), and together with the integrity protection key and the encryption protection key for CU-UP#N corresponding to S-NSSAI#N (e.g., a slice for eMBB service).

[0218] More specifically, referring to the second key system (1620) of FIG. 16, the terminal and the base station can obtain the K_gNB and NH keys from the AMF. Here, the obtained K_gNB can include a key generated through a KDF based on an identifier of a CP corresponding to a specific base station (e.g., gNB-CU-CP-ID) and an MSK associated with an external operator. Accordingly, the terminal and the base station can obtain a K_gNB that is distinguished for each base station and reflects information of an external operator, so that a security context for each base station can be established in an environment where multiple base stations exist.

[0219] According to one embodiment, based on the above-described keys, the terminal and the base station can derive K_gNB* and K_gNB accordingly using PCI and ARFCN-DL. According to one embodiment, the terminal and the base station can derive K_RRCint and K_RRCenc through KDF based on identifier information about the ID and algorithm of the integrity / encryption algorithm for K_gNB and the control plane. In addition, the terminal and the base station can derive K_UPint and K_UPenc through KDF based on identifier information about the ID and algorithm of the integrity / encryption algorithm for K_gNB and the user plane. According to one embodiment, the terminal and the base station can further use at least one of a slice identifier (e.g., S-NSSAI) or a gNB-CU-UP-ID (e.g., a CU-UP identifier or a user plane identifier) ​​to derive the integrity key and the encryption key for the control plane and the user plane. Accordingly, the integrity key or encryption key derived by the terminal and the base station can be generated as a slice-independent key corresponding to information about a specific slice, and furthermore, especially in an environment where multiple CU-UPs and multiple base stations (e.g., gNBs) exist, a slice-specific security context can be established for each distinct base station using a shared common K_gNB. Additionally, the derived 256-bit integrity key and encryption key can be truncated to generate 128-bit user plane-related keys.

[0220] According to various embodiments of the present disclosure, a terminal and a base station derive an integrity key or an encryption key using information about each specific network slice, an MSK associated with an external operator, and an identifier for each base station, so that the terminal and the base station can allocate and establish a security context for each base station or network slice that reflects information of an external operator without ambiguity about each base station or CU-UP even in an environment where multiple base stations exist. Accordingly, the terminal and the base station can establish security and realize access control between each base station or network slice that are distinct even in an environment where multiple base stations are connected to multiple slices.

[0221] According to various embodiments of the present disclosure, FIGS. 13 to 16 disclose various examples for a terminal or a base station to establish an AS security context. However, not all examples or procedures included in the examples are essential components, and some examples or procedures may be omitted as needed. Furthermore, it goes without saying that other procedures of the present disclosure (e.g., some of the procedures of FIG. 7 or FIG. 12) may be included and performed together to perform the above-described examples.

[0222] Figure 17 illustrates the operational flow of a terminal or base station for establishing a security context for each network slice according to embodiments of the present disclosure. More specifically, the terminal or base station may perform operations including some of the steps disclosed in Figure 17 or some of the procedures described above to derive an integrity key and an encryption key.

[0223] In step 1710, the terminal or base station may obtain K_gNB. In one embodiment, the terminal or base station may obtain at least one of K_gNB, NH, or MSK generated from the AMF. Here, the terminal may have the MSK in advance. In one embodiment, the terminal or base station may obtain S-NSSAI for each slice through some of the procedures disclosed in FIG. 7. The specific details of step 1710 may include some of the procedures related to obtaining information for deriving security-related keys among the contents disclosed in FIG. 7 to FIG. 16 described above.

[0224] In step 1720, the terminal or base station may generate a key associated with the AS based on K_gNB and S-NSSAI. More specifically, the key associated with the AS may include K_UPint and K_UPenc, or K_RRCint and K_RRCenc, or K_gNB. According to one embodiment, the terminal or base station may derive K_UPint and K_UPenc based on K_gNB and S-NSSAI. According to one embodiment, the terminal or base station may also derive K_RRCint and K_RRCenc based on K_gNB and S-NSSAI. According to one embodiment, the terminal or base station may derive a key for integrity protection and a key for encryption based on at least one of K_gNB, S-NSSAI, CU-UP identifier, CU-CP identifier, or MSK. According to one embodiment, the specific details of step 1720 may include some of the procedures associated with deriving a security-related key among those disclosed in FIGS. 7 to 16 described above.

[0225] In step 1730, the terminal or base station may establish an AS security context between the terminal and the base station based on a key associated with the AS. More specifically, the key associated with the AS may include K_UPint and K_UPenc, or K_RRCint and K_RRCenc, or K_gNB. According to one embodiment, the terminal or base station may derive an integrity key or an encryption key using at least one of information about each specific network slice, an identifier for each base station, or an MSK, so that the terminal and the base station may allocate and establish an AS security context for each network slice. According to one embodiment, the specific contents of step 1730 may include some procedures related to establishing a security context among the contents disclosed in FIGS. 7 to 16 described above.

[0226] According to various embodiments of the present disclosure, the above-described operational flow is merely exemplary and may not be limited thereto. For example, each step may not be individually considered an essential component, and, depending on one embodiment, the desired technical effect may be achieved by at least one of all, some, or a combination of the operations.

[0227] It should be noted that the aforementioned configuration diagrams, examples of control / data signal transmission methods, examples of operational procedures, and configuration diagrams are not intended to limit the scope of the present disclosure. That is, not all components, entities, or operational steps described in the embodiments of the present disclosure should be construed as essential components for implementing the disclosure, and implementations may be made without detracting from the essence of the disclosure even if only some components are included. Furthermore, each embodiment may be combined and operated as needed. For example, parts of the methods proposed in the present disclosure may be combined to operate network entities and terminals.

[0228] The operations of the base station or terminal described above can be realized by providing a memory device storing the corresponding program code in any component within the base station or terminal device. That is, the control unit of the base station or terminal device can execute the operations described above by reading and executing the program code stored in the memory device using a processor or CPU (Central Processing Unit).

[0229] The various components and modules of the entity, base station or terminal device described in this specification may be operated using hardware circuits, such as logic circuits based on complementary metal oxide semiconductors, firmware, software and / or hardware and firmware and / or software embedded in a machine-readable medium. For example, various electrical structures and methods may be implemented using electrical circuits such as transistors, logic gates and application-specific semiconductors.

[0230] When implemented in software, a computer-readable storage medium storing one or more programs (software modules) may be provided. The one or more programs stored in the computer-readable storage medium are configured for execution by one or more processors within an electronic device. The one or more programs include instructions that cause the electronic device to execute methods according to embodiments described in the claims or specification of the present disclosure.

[0231] These programs (software modules, software) may be stored in random access memory, non-volatile memory including flash memory, read only memory (ROM), electrically erasable programmable read only memory (EEPROM), magnetic disc storage device, compact disc ROM (CD-ROM), digital versatile discs (DVDs) or other forms of optical storage device, magnetic cassette. Or, they may be stored in a memory configured as a combination of some or all of these. In addition, each configuration memory may be included in multiple numbers.

[0232] Additionally, the program may be stored in an attachable storage device that is accessible via a communication network such as the Internet, an intranet, a local area network (LAN), a wide local area network (WLAN), a storage area network (SAN), or a combination thereof. Such a storage device may be connected to a device performing an embodiment of the present disclosure via an external port. Additionally, a separate storage device on the communication network may be connected to a device performing an embodiment of the present disclosure.

[0233] In the specific embodiments of the present disclosure described above, components included in the disclosure are expressed singularly or plurally, depending on the specific embodiment presented. However, the singular or plural expressions are selected to suit the presented situation for convenience of explanation, and the present disclosure is not limited to singular or plural components. Even components expressed in plural may be composed of singular elements, or even components expressed in singular may be composed of plural elements.

[0234] While the detailed description of the present disclosure has described specific embodiments, it should be understood that various modifications are possible without departing from the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be determined not only by the scope of the claims described below but also by equivalents thereof. In other words, it will be apparent to those skilled in the art that other modifications based on the technical idea of ​​the present disclosure are possible. In addition, the above-described embodiments can be combined and operated with each other as needed. For example, parts of the methods proposed in the present disclosure can be combined with each other to operate a base station and a terminal. In addition, although the above-described embodiments have been presented based on a 5G, NR system, other modifications based on the technical idea of ​​the above-described embodiments can be implemented with other systems such as LTE, LTE-A, and LTE-A-Pro systems.

[0235] While the detailed description of this disclosure has described specific embodiments, it should be understood that various modifications are possible without departing from the scope of this disclosure. Therefore, the scope of this disclosure should not be limited to the described embodiments, but should be defined not only by the scope of the claims described below, but also by equivalents thereof.

Claims

1. In a wireless communication system, a base station, transceiver; and Including a controller coupled to the above transmitter and receiver, The above controller, Based on the AMF (access and mobility management function) key (K_AMF), the first base station key (K_gNB) is obtained, Generating a key associated with at least one AS (access stratum) based on the first base station key and the identifier corresponding to the network slice, and Based on a key associated with at least one AS, a network slice-specific AS security context is established between the base station and a user equipment (UE), The above network slice is a base station corresponding to the CU (control unit)-UP (user plane) of the base station.

2. In claim 1, A base station wherein the key associated with at least one AS comprises at least one of a user plane integrity key (K_UPint), a user plane encryption key (K_UPenc), a radio resource control (RRC) integrity key (K_RRCint), an RRC encryption key (K_RRCenc), or a second base station key.

3. In claim 2, The above identifier is a base station including at least one of S-NSSAI (single-network slice selection assistance information) or CU-UP ID (identifier) ​​of the base station.

4. In claim 3, A base station in which the first base station key is obtained based on at least one of an identifier corresponding to the network slice or a CU-CP (control plane) ID of the base station.

5. In claim 1, the controller, Further configured to receive information including a master section key (MSK) from an AMF entity, A base station, wherein at least one of the first base station key or the key for establishing the AS security context for each network slice is obtained based on the MSK.

6. In a wireless communication system, a user equipment (UE) is transceiver; and Including a controller coupled to the above transmitter and receiver, The above controller, Based on the AMF (access and mobility management function) key (K_AMF), the first base station key (K_gNB) is obtained, Generating a key associated with at least one AS (access stratum) based on the first base station key and the identifier corresponding to the network slice, and configured to establish a network slice-specific AS security context between the terminal and the base station based on a key associated with at least one AS; The above network slice is a terminal corresponding to the CU (control unit)-UP (user plane) of the base station.

7. In claim 6, A terminal in which the key associated with at least one AS comprises at least one of a user plane integrity key (K_UPint), a user plane encryption key (K_UPenc), an RRC (radio resource control) integrity key (K_RRCint), an RRC encryption key (K_RRCenc), or a second base station key.

8. In claim 7, The above identifier is a terminal including at least one of S-NSSAI (single-network slice selection assistance information) or CU-UP ID (identifier) ​​of the base station.

9. In claim 8, The terminal is obtained based on at least one of the identifier corresponding to the network slice or the CU-CP (control plane) ID of the base station, wherein the first base station key is obtained based on at least one of the identifier corresponding to the network slice or the CU-CP (control plane) ID of the base station.

10. In claim 6, the controller, It is further configured to obtain information including MSK (master section key) through an authentication procedure between the terminal and the entity associated with the service. A terminal in which at least one of the first base station key or the key for establishing the AS security context for each network slice is obtained based on the MSK.

11. In a wireless communication system, a method performed by a base station, A step of obtaining a first base station key (K_gNB) based on an AMF (access and mobility management function) key (K_AMF); generating a key associated with at least one AS (access stratum) based on the first base station key and an identifier corresponding to the network slice; and A step of establishing a network slice-specific AS security context between the base station and a user equipment (UE) based on a key associated with at least one AS, The above network slice is a method corresponding to the CU (control unit)-UP (user plane) of the base station.

12. In claim 11, A method wherein the key associated with at least one AS comprises at least one of a user plane integrity key (K_UPint), a user plane encryption key (K_UPenc), a radio resource control (RRC) integrity key (K_RRCint), an RRC encryption key (K_RRCenc), or a second base station key.

13. In claim 12, A method in which the above identifier includes at least one of S-NSSAI (single-network slice selection assistance information) or CU-UP ID (identifier) ​​of the base station.

14. In claim 13, A method in which the first base station key is obtained based on at least one of an identifier corresponding to the network slice or a CU-CP (control plane) ID of the base station.

15. In claim 11, the method comprises: Further comprising the step of receiving information including a master section key (MSK) from an AMF entity, A method wherein at least one of the first base station key or the key for establishing the AS security context for each network slice is obtained based on the MSK.

Citation Information

Patent Citations

  • Manufacturing method of high ionic conducting solid electrolyte for all-solid battery

    KR1020250060473A

  • Methods and systems for deriving CU-up security keys for disaggregated gnb architecture

    US20220030425A1

  • Security context for target amf

    US20230262453A1

  • Slice-specific security requirement information

    US20230269589A1

  • Automatic selection of CU-up instances for 5g

    WO2019083522A1