Methods and devices enhancing security mode establishment for user equipment communications
The UE's indication of ciphering algorithm rejection with a new cause value in Security Mode Failure messages enables efficient reconfiguration or disconnection, addressing inefficiencies and ensuring secure communication in wireless systems.
Patent Information
- Application Number
- PCT/US2025/018984
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-06
- Filing Date
- 2025-03-07
- Publication Date
- 2026-02-12
AI Technical Summary
In wireless communication systems, the UE may reject a network-configured ciphering algorithm without indicating the cause, leading to energy and resource waste, and the behavior during Security Mode establishment is not well defined, especially during emergency calls.
The UE indicates the rejection of a particular ciphering algorithm through a Security Mode Failure message with a new cause value, and performs integrity checks, allowing the network to reconfigure a more robust ciphering algorithm or disconnect the connection.
This approach enhances security mode establishment by efficiently handling ciphering algorithm reconfigurations and ensures secure communication, even during emergency calls, by reducing energy waste and optimizing resource utilization.
Smart Images

Figure US2025018984_12022026_PF_FP_ABST
Abstract
Description
Patent ApplicationAttorney Docket Number 0683-098-WOMETHODS AND DEVICES ENHANCING SECURITY MODE ESTABLISHMENT FOR USER EQUIPMENT COMMUNICATIONSFIELD OF THE DISCLOSURE
[0001] This document generally describes methods and devices (e.g., user equipment (UE) and network entity (NE)) operating in wireless communication systems such as (but not limited to) the ones described in 3rd Generation Partnership Project (3GPP) technical specifications, such as the Fifth Generation (5G) or Long Term Evolution (LTE) communication systems. More particularly, the methods and devices employ techniques for establishing secure encryption algorithms for UEs, ensuring the confidentiality of user and signaling data.BACKGROUND
[0002] This background description is provided for the purpose of generally presenting the context of the embodiments described later in this document. Work of the presently named inventors, to the extent it is described in this background section, as well as aspects of the description that may not otherwise qualify as prior art at the time of filing, are neither expressly nor impliedly admitted as prior art against the embodiments.
[0003] In wireless communication systems, the Packet Data Convergence Protocol (PDCP) sublayer of the radio protocol stack provides services such as transfer of user-plane data, ciphering, integrity protection, etc. For example, the PDCP layer defined for the Evolved Universal Terrestrial Radio Access (EUTRA) radio interface (see 3GPP technical specification, TS, 36.323) and New Radio (NR) (see 3GPP TS 38.323) provides sequencing of protocol data units (PDUs) transmitted in the uplink direction (from a user device, also known as a UE, to a base station, which is an NE) as well as in the downlink direction (from the base station to the UE). Further, the PDCP sublayer provides signaling radio bearers (SRBs) and data radio bearers (DRBs) to the Radio Resource Control (RRC) sublayer. The UE and the base station (BS) use SRBsPatent ApplicationAttorney Docket Number 0683-098-WO to exchange RRC messages and non-access stratum (NAS) messages and use DRBs to transport data on a user plane.
[0004] When an NE (e.g., a BS or a core network device such as a Mobility Management Entity (MME) or an Access and Mobility Management Function (AMF)) communicates with a UE, the NE and the UE use a ciphering algorithm to encrypt and decrypt data communicated between the NE and UE. The ciphering algorithm may be a null ciphering algorithm known as (EEAO in LTE and NEAO in 5G), a 128-bit SNOW 3G based algorithm (known as 128-EEA1 in LTE and 128-NEA1 in 5G), a 128-bit AES based algorithm (known as 128-EEA2 in LTE and 128-NEA2 in 5G) and, optionally, a 128-bit ZUC based algorithm (known as 128-EEA3 in LTE and 128-NEA3 in 5G). The UE receives a Security Mode Command (SMCommand) as described in the 3GPP technical specifications, the SMCommand conveying selected algorithms for encrypting and for data integrity protection. However, the NE may select a ciphering algorithm that the UE does not allow, for example, the UE finds the network-configured algorithm to be an unsecure ciphering algorithm for the communications between the UE and the NE. For example, the NE configures the UE with the null ciphering algorithm for encrypting and decrypting data. In another example, the UE finds the 128-bit SNOW 3G ciphering algorithm not to be secure enough while the 128-bit AES based ciphering algorithm is allowed (i.e. , the UE only allows data communication with the 128-bit AES ciphering algorithm). Thus, a UE may be capable of handling a particular ciphering algorithm yet not allow that ciphering algorithm.
[0005] Conventionally, upon determining that the network-selected algorithm is not allowed, the UE rejects (e.g., sends a Security Mode Reject (SMR) or a Security Mode Failure (SMF)) without indicating the cause of rejection (beyond, for example, an SMR cause #23 indicating UE security capabilities mismatch, or an SMR cause #24 indicating security mode rejected, unspecified). This deficiency causes waste of energy and communication resources because the network does not know how to effectively overcome the rejection. Another conventional weakness in Security Mode establishment procedures is that some of the related messages (e.g., the SMCommand) are not subject to integrity check. Additionally, the UE’s behavior related to Security ModePatent ApplicationAttorney Docket Number 0683-098-WO establishment is not yet well defined in case of an ongoing emergency call when receiving an SMCommand.SUMMARY
[0006] During a Security Mode establishment, a UE according to various embodiments indicates that the UE does not allow a particular ciphering algorithm in response to network’s SMCommand specifying the ciphering algorithm. The UE’s response may be an SMF, an SMR, or a Security Mode Complete (SMComplete), as defined in the 3GPP technical specifications, enabled to indicate that the UE does not allow the NE-indicated ciphering algorithm. The SMCommand and the response include respective message authentication codes (MACs) enabling the recipient to perform an integrity check. The UE may refrain from performing the integrity protection check when the ciphering algorithm is not allowed. Upon receiving, from the UE, a response indicating that the ciphering algorithm is not allowed, the NE may transmit another message indicating another ciphering algorithm. Alternatively, the NE may interrupt the connection with the UE. In another approach, the UE may refrain from determining whether the ciphering algorithm is allowed and use the NE indicated ciphering algorithm when there is an ongoing emergency call (i.e. , the call has been initiated prior to receiving the SMCommand indicating the ciphering algorithm).Patent ApplicationAttorney Docket Number 0683-098-WOBRIEF DESCRIPTION OF THE DRAWINGS
[0007] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate one or more embodiments and, together with the description, explain these embodiments.
[0008] Fig. 1 schematically illustrates a wireless communication system in which techniques according to various embodiments are implemented.
[0009] Fig. 2 illustrates the communication protocol stack.
[0010] Figs. 3A and 3B illustrate the use of a ciphering algorithm and an integrity protection algorithm, respectively, usable for communications.
[0011] Figs. 4A-4D are signal diagrams illustrating enhanced security techniques employed between a UE and a base station (BS) according to various embodiments.
[0012] Figs. 5A-5D are signal diagrams illustrating enhanced security techniques employed between a UE and a core network device according to various embodiments.
[0013] Figs. 6A-6E are flow diagrams of UE methods with the UE indicating to the BS or the core network (CN) device that a 1stciphering algorithm is not allowed, according to various embodiments.
[0014] Figs. 7A and 7B are flow diagrams of UE methods related to a 2ndciphering algorithm provided by the NE after the 1stciphering algorithm is not allowed according to some embodiments.
[0015] Fig. 8A-8C are flow diagrams of NE methods according to various embodiments.
[0016] Figs. 9A and 9B are flow diagrams of UE methods including decision blocks related to emergency calls impacting the enhanced security mode establishment according to some embodiments.
[0017] Figs. 10A-10B are flow diagrams of NE methods illustrating various decision blocks according to some embodiments.DETAILED DESCRIPTION
[0018] Methods and devices described in this section embody techniques related to improving Security Mode establishment procedures, in particular, related to the UE indicating to the NE (a BS or a core network device) that the UE does not allow aPatent ApplicationAttorney Docket Number 0683-098-WO network-configured (via an SMCommand) ciphering algorithm, and UE’s behavior in case of an ongoing emergency call.
[0019] The embodiment descriptions in this section refer to the accompanying drawings. The same reference numbers in different drawings identify the same or similar elements. The detailed descriptions do not preclude other embodiments within the scope of the appended claims. The embodiments are not limited to the described configurations but may be extended to other arrangements.
[0020] Fig. 1 exemplarily illustrates a wireless communication system 100 that includes a UE 102, base stations (BSs) 104 and 106, and a core network (CN) 110. The BSs 104 and 106 operate in a radio access network (RAN) 105 connected to the CN 110. The CN 110 includes an evolved packet core (EPC) 111 and / or a 5G core (5GC) 160. The CN 110 may also be implemented as a sixth generation (6G) core or other wireless communication system’s core.
[0021] The BS 104 covers a cell 124, and the BS 106 covers a cell 126. If the BS 104 is a gNB, the cell 124 is an NR cell. If the BS 104 is an ng-eNB or eNB, the cell 124 is an evolved universal terrestrial radio access (E-UTRA) cell. Similarly, if the BS 106 is a gNB, the cell 126 is an NR cell, and if the BS 106 is an ng-eNB or eNB, the cell 126 is an E-UTRA cell. The cells 124 and 126 may be in the same Radio Access Network Notification Areas (RNA) or different RNAs. In general, the RAN 105 includes any number of terrestrial and non-terrestrial BSs, and each of the BSs covering one or more cells. The UE 102 supports at least a 5G NR (or simply, “NR”) or an E-UTRA air interface to communicate with the BSs 104 and 106. The cells 124 and 126 can partially overlap, so that the UE 102 can select, reselect, or hand over from one of the cells 124 and 126 to the other. To directly exchange messages or information, the BS 104 and BS 106 can support an X2 or Xn interface 108. Each of the BSs 104, 106 connects to the CN 110 via an interface 109 (e.g., an S1 or an NG interface, only one labeled). In general, the CN 110 can connect to any suitable number of terrestrial and / or non-terrestrial BSs supporting NR cells and / or EUTRA cells.
[0022] Among other components, the EPC 111 can include a Mobility Management Entity (MME) 112, a Serving Gateway (SGW) 114, and a Packet Data Network Gateway (PGW) 116. The MME 112 is configured to manage authentication, registration, paging,Patent ApplicationAttorney Docket Number 0683-098-WO and other related functions. The SGW 114 is configured to transfer user-plane packets related to audio calls, video calls, Internet traffic, etc. The PGW 116 provides connectivity from the UE to one or more external packet data networks (e.g., an Internet network and / or an Internet Protocol (IP) Multimedia Subsystem (IMS) network). The 5GC 160 may include among other components an Access and Mobility Management Function (AMF) 162, a Session Management Function (SMF) 164, and a User Plane Function (UPF) 166. The AMF 162 is configured to manage authentication, registration, paging, and other related functions. The SMF 164 is configured to manage PDU sessions. The UPF 162 is configured to transfer user-plane packets related to audio calls, video calls, Internet traffic, etc. These components are merely an illustration and not intended to be a limitation for the following embodiments.
[0023] The BS 104 is equipped with a transceiver and processing hardware 130 that can include one or more processors (e.g., general-purpose processor(s) and / or special-purpose processing unit(s)) and a non-transitory computer-readable memory storing instructions that the one or more processors execute. For example, the processing hardware 130 includes a processor 132 configured to process data that the BS 104 transmits in the downlink (DL) direction, and / or process data that the BS 104 receives in the uplink (UL) direction. The processing hardware 130 also includes a transmitter 134 configured to transmit data in the DL direction and a receiver 136 configured to receive data in the UL direction. The transmitter and the receiver may be combined into a single hardware component and are called in this document “transceiver.” The processing hardware 130 further includes an RRC controller 138 configured to implement procedures and messaging related to the RRC layer of the protocol communication stack and an NAS controller 139 configured to implement procedures and messaging related to the NAS layer of the protocol communication stack. The RRC controller and the NAS controller may not be a separate component but a combination of software and / or hardware. The BS 106 generally includes similar components.
[0024] The UE 102 is equipped processing hardware 150 that includes one or more processors (general-purpose processor(s) and / or special purpose unit(s)) and non- transitory computer-readable memory storing machine-readable instructions executable on the one or more processors. In the exemplary illustration in Fig. 1 , the processingPatent ApplicationAttorney Docket Number 0683-098-WO hardware 150 includes a processor 152 to process data that the UE 102 transmits in the UL direction and data the UE 102 receives in the DL direction. The processing hardware 150 also includes a transmitter 154 configured to transmit data in the DL direction and a receiver 156 configured to receive data in the DL direction. The processing hardware 150 further includes an RRC controller 158 that implements procedures and messaging at the RRC layer of the protocol communication stack and an NAS controller 159 configured to implement procedures and messaging related to the NAS layer of the protocol communication stack. The RRC controller and the NAS controller may not be a separate component but a combination of software and / or hardware.
[0025] The CN 110 may be hosted by one or more physical devices whose processing hardware 140 includes one or more processors such as processor 142, a transmitter 144 and a receiver 146 (e.g., a transceiver). Such physical devices are configured to wirelessly communicate with the BSs such as 104 and 106 and through the BSs with UEs.
[0026] Fig. 2 illustrates, in a simplified manner, a protocol stack 200 according to which the UE 102 can communicate with a BS 201 (e.g., one or more of the BSs 104, 106) and the CN 110. A physical (PHY) layer 202 of the protocol stack 200 provides transport channels to a medium access control (MAC) layer 204, which in turn provides logical channels to a radio link control (RLC) layer 206. The RLC layer 206 in turn provides RLC channels to a PDCP layer 208. The PDCP layer 208 in turn provides data transfer services to an RRC layer 210, an Internet Protocol (IP) layer and / or a Service Data Adaptation Protocol (SDAP) layer (not shown in Fig. 2). The PDCP layer 208 receives packets (e.g., from the RRC sublayer 2RN10, the SDAP layer, or the IP layer, layered directly or indirectly over the PDCP layer 208) that can be referred to as service data units (SDUs), and output packets (e.g., to the RLC layer 206) that can be referred to as protocol data units (PDUs). Except where the difference between SDUs and PDUs is relevant, this disclosure for simplicity refers to both SDUs and PDUs as “packets”. In some embodiments, the PHY layer 202, MAC layer 204, RLC layer 206, PDCP layer 208, RRC layer 210 are EUTRA layers or sublayers. In other embodiments, the PHY layer 202, MAC layer 204, RLC layer 206, PDCP layer 208, RRC layer 210 are NR layers or sublayers.Patent ApplicationAttorney Docket Number 0683-098-WO
[0027] The RRC layer 210 provides data transfer services to a Non-Access-Stratum (NAS) layer 212. The NAS layer 212 includes a mobility management (MM) sublayer and / or a session management (SM) sublayer. In some embodiments, the MM sublayer is an EPS MM (EMM) sublayer. In other embodiments, the MM sublayer is a 5G MM (5GMM) sublayer. In some embodiments, the SM sublayer is an EPS SM (ESM) sublayer. In other embodiments, the SM sublayer is a 5G SM (5GSM) sublayer. When the BS 201 (gNB or eNB 104 / 106) receives UL NAS PDlls from the UE 102, the BS forwards the UL NAS PDlls to the CN 110 without processing the UL NAS PDUs. When the BS 201 receives DL NAS PDUs from the CN 110, the BS forwards the DL NAS PDUs to the UE 102 without processing the DL NAS PDUs. That is, the NAS layer 212 is transparent to the BS. The NAS layer 212 might provide a ciphering function to perform data encryption and decryption. The NAS layer 212 may provide a protection function to perform data integrity protection and data integrity verification.
[0028] On a control plane, the PDCP sublayer 208 may provide signaling radio bearers (SRBs) to the RRC layer 210 to exchange RRC messages or NAS messages (e.g., MM messages and / or SM messages). On a user plane, the PDCP layer 208 may provide Data Radio Bearers (DRBs) to support user plane data exchange. User plane data exchanged on the PDCP layer 208 may be SDAP PDUs, Internet Protocol (IP) packets or Ethernet packets. The PDCP layer 208 might provide a ciphering function to perform data encryption and decryption.
[0029] Currently-used 128-bit ciphering algorithms operate as illustrated in Fig. 3A. Both a sender 301 and a receiver 311 (which each may be a UE or an NE, such as, a BS or an AMF) use a ciphering algorithm to generate an output KEYSTREAM block using a 128-bit cipher KEY, a 32-bit COUNT, a 5-bit BEARER identity, the 1 -bit DIRECTION of the transmission (which is 0 for uplink and 1 for downlink), and the LENGTH of the keystream as input parameters. The sender 301 then uses the KEYSTREAM block to encrypt the PLAINTEXT block thereby generating the output CIPHERTEXT block. The receiver 311 uses the KEYSTREAM block, which it generates in the same manner as the sender, to decrypt the CIPHERTEXT block thereby regenerating the output PLAINTEXT block. The sender 301 and the receiver 311 use the same ciphering algorithm that may be a null ciphering algorithm known as (EEA0 in LTE and NEA0 in 5G), a 128-bit SNOW 3G basedPatent ApplicationAttorney Docket Number 0683-098-WO algorithm (known as 128-EEA1 in LTE and 128-NEA1 in 5G), a 128-bit AES based algorithm (known as 128-EEA2 in LTE and 128-NEA2 in 5G) and, optionally, a 128-bit ZUC based algorithm (known as 128-EEA3 in LTE and 128-NEA3 in 5G). Other ciphering algorithms may be used in the future.
[0030] The PDCP layer 208 may provide a protection function to perform data integrity protection and data integrity verification. Currently-used 128-bit integrity protection algorithms operate as illustrated in Fig. 3B. The sender 301 and the receiver 311 use the same integrity protection algorithm to generate a 32 -bit message authentication code MAC-I / NAS-MAC and XMAC-I / XNAS-MAC (here X stands for “expected”), respectively, based on a 128-bit integrity KEY, a 32-bit COUNT, a 5-bit BEARER identity, and a 1 -bit DIRECTION of the transmission, and the MESSAGE itself. The integrity protection algorithm may be a null algorithm known as (EIA0 in LTE and NIA0 in 5G), a 128-bit SN0W3G based algorithm (known as 128-EIA1 in LTE and 128-NIA1 in 5G), a 128-bit AES based algorithm (known as 128-EIA2 in LTE and 128-NIA2 in 5G) and, optionally, a 128-bit ZUC based algorithm (known as 128-EIA3 in LTE and 128-NIA3 in 5G). The sender 301 appends the 32-bit message authentication code MAC-I / NAS-MAC to the message. The receiver 311 verifies integrity by comparing XMAC-I / XNAS-MAC with the MAC-I / NAS-MAC appended to the message. The sender 301 applies the data integrity protection before data ciphering, and the receiver 311 deciphers the received PDU and verifies received data integrity for a received message using the received MAC.
[0031] Figs. 4A-4D are signal diagrams illustrating enhanced security techniques employed between a UE (e.g. 102 in Fig. 1 ) and a BS (e.g., 104 in Fig. 1 ) according to various embodiments. In these scenarios, the messages may be RRC messages. Figs. 5A-5D are signal diagrams illustrating enhanced security techniques employed between a UE and a core network device according to various embodiments. In these scenarios, the messages may be NAS messages forwarded by a BS 104 and a RAN 105 as illustrated in Fig. 1 . Events in Figs. 4A-5D that are similar are labeled with similar reference numbers (e.g., event 402 of Figs. 4A-4D is similar to event 502 of Figs. 5A-5D, event 404 of Figs. 4A-4D is similar to event 504 of Figs. 5A-5D, etc.), with differences discussed below where appropriate. With the exception of the differences shown in the figures and discussed below, any of the alternative implementationsPatent ApplicationAttorney Docket Number 0683-098-WO discussed with respect to a particular event (e.g., for messaging and processing) may apply to events labeled with similar reference numbers in other figures.
[0032] Referring first to Fig. 4A, in a scenario 400A, the BS 104 operates a cell (e.g., cell 124) and communicates with the UE 102 via the cell. To simplify the following description, the events where PDUs and / or messages are exchanged between the BS 104 and the UE 102 occur via the cell. The UE 102 initially operates 402 in a connected state (e.g., RRC_CONNECTED state) and receives 404 a DL PDU from the BS 104, including a 1stSecurity Mode Command (SMCommand, i.e. , a message) and a 1stmessage authentication code (MACI ) for the 1stSMCommand. The 1stSMCommand configures an integrity protection algorithm and a 1stciphering algorithm. The BS 104 generates MAC1 using the integrity protection algorithm. For example, the BS 104 generates MAC1 using the integrity protection algorithm, the 1stSMCommand, and parameters as described for Fig. 3B.
[0033] The UE 102 then performs 406 an integrity protection check for the 1stSMCommand and determines that the 1stSMCommand passes the integrity protection check. For example, the UE 102 performs the integrity check for the 1stSMCommand using the integrity protection algorithm, MAC1 , and parameters as described for Fig. 3B. The UE 102 determines 408 that the 1stciphering algorithm indicated by the SMCommand is not allowed, for example, due to weak security protection or no security protection provided by the 1stciphering algorithm. The events 404, 406, and 408 are collectively referred to as an SMCommand reception procedure 490.
[0034] In response to determining that the 1stSMCommand passes the integrity protection check and that the 1stciphering algorithm is not allowed, the UE 102 generates 410 a Security Mode Failure (SMF, e.g., a message) and a 2nd MAC (MAC2) for the SMF. In some embodiments, the UE 102 generates MAC2 using the integrity protection algorithm, the SMF message, and parameters as described for Fig. 3B. In response to the 1stSMCommand, the UE 102 then transmits 412 a UL PDU to the BS 104. This UL PDU includes the SMF and MAC2. In this scenario, the UE 102 indicates in the SMF that the 1stciphering algorithm is not allowed. For example, the SMF is the Security Mode Failure message defined in 3GPP TS 38.331 or 36.331 modified to include a new cause value “ciphering algorithm not allowed.” This new cause value isPatent ApplicationAttorney Docket Number 0683-098-WO not yet defined or different from the currently defined causes in the Security Mode Failure message in 3GPP specification 38.331 or 36.331. The UE 102 includes the new cause value in the SMF to indicate that the NE-indicated 1stciphering algorithm is not allowed by the UE.
[0035] In some embodiments, the UE 102 applies encryption to the SMF and MAC2 using the 1stciphering algorithm and parameters as described in Fig. 3A. The UE 102 may do so although the 1stciphering algorithm is not allowed. Although the UE 102 does not allow using the 1stciphering algorithm for received messages, the UE 102 may still apply the 1stciphering algorithm for the transmitted UL PDU containing the SMF and MAC2. The UE 102 generates an encrypted SMF and an encrypted MAC2 by applying the NE-indicated 1stciphering algorithm to the SMF and to MAC2. The UE 102 then transmits 412, to the BS 104, a UL PDU including the encrypted SMF and the encrypted MAC2. Upon receiving 412 the UL PDU, the BS 104 applies decryption to the encrypted SMF and the encrypted MAC2 and obtains an unencrypted SMF and an unencrypted MAC2. The unencrypted SMF and the unencrypted MAC should be the same as the SMF and MAC2 generated by the UE 102 respectively (i.e., before the UE 102 has applied the encryption). The BS 104 then performs the integrity protection check 414 for the SMF using MAC2 and the integrity protection algorithm as described above.
[0036] In other embodiments, the UE 102 does not apply encryption to the SMF and MAC2. The UE 102 may do so because the BS 104 may not be able to determine whether a received SMF is encrypted or not. Thus, the BS 104 does not decrypt the received SMF and MAC2 and performs only an integrity protection check.
[0037] In some embodiments, when the UE 102 determines that the 1stSMCommand fails the integrity check at event 406, the UE 102 refrains from generating the MAC2 for the SMF and transmits, to the BS 104, a UL PDU including the SMF but not MAC2. The absence of a MAC prevents the BS 104 from performing the integrity protection check. In such cases, the UE 102 may refrain from applying encryption to the SMF.
[0038] As already mentioned above and assuming no ciphering has been applied to the SMF and MAC2, upon receiving the SMF and MAC2, the BS 104 performs 414Patent ApplicationAttorney Docket Number 0683-098-WO an integrity protection check for the SMF based on MAC2 (if present) and the integrity protection algorithm and determines that the SMF passes the integrity protection check. Based on the indication (e.g., the new cause value) in the SMF, the BS 104 determines that the UE 102 does not allow the 1stciphering algorithm. After determining that the SMF passes the integrity protection check and that the UE does not allow the 1stciphering algorithm, in this example the BS 104 determines to configure the UE 102 with a 2ndciphering algorithm. The 2ndciphering algorithm may be more robust than the 1stciphering algorithm. In order to configure the UE 102 with the 2ndciphering algorithm, the BS 104 generates a 2ndSMCommand specifying the 2ndciphering algorithm and uses integrity protection to generate a third MAC (MAC3) for the 2ndSMCommand. The BS 104 then transmits 416 a DL PDU to the UE 102. The DL PDU includes the 2ndSMCommand and MAC3 in a structure similar to the previously sent 404 1stSMCommand and MAC1. The BS 104 may generate MAC3 using the integrity protection algorithm, the 2ndSMCommand message, and parameters as described for Fig. 3B.
[0039] When receiving 416 the DL PDU, the UE 102 performs 418 an integrity protection check for the 2ndSMCommand based on MAC3 and the integrity protection algorithm. The UE 102 may perform 418 the integrity protection check for the 2ndSMCommand based on MAC3, the integrity protection algorithm, and parameters as described for Fig. 3B similar to block 406. Contrasting with block 408, the UE 102 then determines 420 the 2ndciphering algorithm is allowed by the UE.
[0040] When the UE 102 applies encryption to the SMF and MAC2 with the 1stciphering algorithm and parameters as described for Fig. 3A, the BS 104 also applies encryption to the 2ndSMCommand and MAC3 using the 1stciphering algorithm and parameters as described for Fig. 3A. The BS 104 thus obtains an encrypted SMCommand and an encrypted MAC. The BS 104 then transmits 416 a DL PDU to the UE 102, including the encrypted SMCommand and the encrypted MAC. Upon receiving 416 the DL PDU, the UE 102 applies decryption to the encrypted SMCommand and the encrypted MAC3 to obtain the unencrypted SMCommand and the unencrypted MAC. The unencrypted SMCommand and the unencrypted MAC should be the same as the 2ndSMCommand and MAC3 generated by the BS 104 respectively, before the BS 104Patent ApplicationAttorney Docket Number 0683-098-WO applies the encryption. The UE 102 then performs the integrity protection check for the 2ndSMC based on MAC3 using the integrity protection algorithm as described above.
[0041] When the UE 102 refrains from applying encryption to the SMF and MAC2, the BS 104 also refrains from encrypting to the 2ndSMCommand and MAC3.
[0042] In response to the 2ndSMCommand and determining 420 that the 2ndciphering algorithm is allowed, the UE 102 generates 422 a Security Mode Complete (SMComplete) and a fourth MAC (MAC4) for the SMComplete. The UE 102 then transmits 424 a UL PDU including the SMComplete and MAC4 to the BS 104. The UE 102 may generate MAC4 using the integrity protection algorithm, the SMComplete, and parameters as described for Fig. 3B. Upon receiving the UL PDU, the BS 104 performs 425 an integrity protection check of the received SMComplete using MAC4, the integrity protection algorithm, and parameters as described for Fig. 3B. The UE 102 then communicates 426 data (e.g., control-plane data and / or user-plane data) with the BS 104 using the 2ndciphering algorithm. In response to determining the SMComplete passes the integrity protection check, the BS 104 also communicates data (e.g., controlplane data and / or user-plane data) with the UE 102 using the 2ndciphering algorithm.
[0043] In some embodiments, the UE 102 applies encryption to the SMComplete and MAC4 using the 2ndciphering algorithm and parameters as described for Fig. 3A. The UE 102 thus obtains an encrypted SMComplete and an encrypted MAC. In this case, the UL PDU that the UE 102 transmits, to the BS 104, includes the encrypted SMComplete and the encrypted MAC. Upon receiving the UL PDU, the BS 104 applies decryption to the encrypted SMComplete and the encrypted MAC4 and obtains an unencrypted SMComplete and an unencrypted MAC4. The BS 104 decrypts the encrypted SMComplete and the encrypted MAC4 using the 2ndciphering algorithm and parameters as described for Fig. 3A. The unencrypted SMComplete and the unencrypted MAC should be the same as the SMComplete and MAC4 generated by the UE 102 respectively, before the UE 102 applies the encryption. The BS 104 then performs the integrity protection check for the unencrypted SMComplete based on the unencrypted MAC4 and the integrity protection algorithm as described above.
[0044] While the 1stciphering algorithm may be a null ciphering algorithm, the 2ndciphering algorithm may be one of a 128-bit SNOW 3G based algorithm (known as 128-Patent ApplicationAttorney Docket Number 0683-098-WOEEA1 in LTE and 128-NEA1 in 5G), a 128-bit AES based algorithm (known as 128- EEA2 in LTE and 128-NEA2 in 5G), and a 128-bit ZUC based algorithm (known as 128- EEA3 in LTE and 128-NEA3 in 5G). While the 1stciphering algorithm is a 128-bit SNOW 3G based algorithm, the 2ndciphering algorithm may be a 128-bit AES based algorithm or a 128-bit ZUC based algorithm. When the 1stciphering algorithm is one of a 128-bit SN0W 3G based algorithm, a 128-bit AES based algorithm, and a 128-bit ZUC based algorithm, the 2ndciphering algorithm is a 256-bit ciphering algorithm. The 256-bit ciphering algorithm may be 256-bit SNOW 3G based algorithm, a 256-bit AES based algorithm, or a 256-bit ZUC based algorithm.
[0045] The events 418, 420, 422, 424, 425, and 426 in Fig. 4A related to the 2ndciphering algorithm are collectively referred to as procedure 495. The procedure 495 encompasses (A) integrity protection check the UE performs when the BS sends 2ndSMCommand indicating 2ndciphering algorithm, (B) the UE indicating to the BS that the 2ndalgorithm is allowed and then (C) the UE and the BS communicating using the 2ndciphering algorithm.
[0046] The UL PDUs and DL PDUs in the events 404, 412, 416, and 424 may be PDCP PDUs. In an embodiment in which the UE 102 refrains from generating a MAC for the SMF, the UE 102 does not include a MAC2 in the UL PDU sent at the event 412 and the event 414 is omitted. Although not illustrated in Fig. 4A, if the 1stSMCommand does not pass the integrity protection check, the UE 102 does not include a MAC in the UL PDU of the event 412 and the event 414 is omitted.
[0047] In some embodiments, if the UE 102 does not receive a SMCommand indicating the 2ndciphering algorithm from the BS 104 like event 416 within a predetermined time period, the UE 102 might disconnect from the BS 104 and transition to the idle state. For example, the UE 102 might start a timer with the predetermined time period value after transmitting 412 the UL PDU. If the UE 102 receives 416 the DL PDU from the BS 104, the UE 102 stops the timer. Otherwise, if the timer expires because the UE 102 does not receive a SMCommand indicating the 2ndciphering algorithm from the BS 104 like event 416, the UE 102 disconnects from the BS 104 and transitions to the idle state. In other embodiments, if the UE 102 receives one or more other DL PUDs or messages instead of receiving 416 the DL PDU or 2ndSMCommandPatent ApplicationAttorney Docket Number 0683-098-WO after transmitting 412 the UL PDU or SMF, the UE 102 might disconnect from the BS 104 and transition to the idle state. With these embodiments, if the BS 104 (e.g., a fake BS) neither configures a ciphering algorithm allowed by the UE 102 nor transitions the UE 102 to the idle state, the UE 102 actively break away from the control of the BS 104.
[0048] Fig. 4B illustrates a scenario 400B similar to the scenario 400A, except that the scenario 400B includes events 428 and 430 instead of the events pertaining to the procedure 495 (416, 418, 420, 422, 424, 425, and 426). In scenario 400B, at 414, the BS 104 determines that the SMF passes the integrity protection check and detects (e.g., based on the new indication in SMF) that the UE 102 does not allow the 1stciphering algorithm. In response to the determination 414, the BS 104 then transmits 428 an RRC Release message directing the UE 102 to transition to an idle state (e.g., RRCJDLE). In response to the RRC Release message, the UE 102 transitions 430 to the idle state. The BS 104 may generate a MAC (MAC3) for the RRC Release message and transmits, to the UE 102, a DL PDU including the RRC Release message and optional MAC3 in the event 428. The DL PDU may be a PDCP PDU. When the UE 102 does not send a MAC2 for the SMF as described above, the BS 104 may also not generate a MAC3 for the RRC Release message and / or include the MAC3 in the DL PDU 428.
[0049] Fig. 4C illustrates a scenario 400C similar to the scenario 400A, except that the scenario 400C includes events 411 , 413, and 415 instead of events 410, 412, and 414. In scenario 400C, upon receiving the 1 st SMC, the UE 102 generates 411 a SMComplete (e.g., a message) indicating the UE does not allow the NE-indicated 1stciphering algorithm and a second MAC (MAC2) for the SMComplete. The SMComplete in scenario 400C replaces the SMF in scenario 400A. The UE 102 then transmits 413 a UL PDU including the SMComplete and MAC2 to the BS 104 (the event 413 being similar to the event 412). The BS 104 performs 415 an integrity protection check for the SMComplete and determines that the SMComplete passes the integrity protection check. The BS 104 may perform the integrity protection check for the SMComplete using MAC2, the integrity protection algorithm, and parameters as described for Fig. 3B. Descriptions related to the events 410, 412, and 414 generally apply to the events 411 , 413, and 415 respectively, except for replacing the “SMF” with the “SMComplete”.Patent ApplicationAttorney Docket Number 0683-098-WO
[0050] In some alternative embodiments, the BS 104 generates an RRC reconfiguration message configuring the 2ndciphering algorithm instead of the 2ndSMCommand shown as event 416. The BS 104 then generates a third MAC (MAC3) for the RRC reconfiguration message and transmits a DL MAC PDU including the RRC reconfiguration message and MAC3 to the UE 102 instead of the DL PDU 416 which is part of the procedure 495. The UE 102 performs actions of the events 418, 420, and 422. In response to the RRC reconfiguration message, the UE 102 then generates an RRC reconfiguration complete message and a fourth MAC (MAC4) for the RRC reconfiguration complete message. The UE 102 transmits a UL PDU including the RRC reconfiguration complete message and MAC4 instead of the UL PDU 424. Descriptions for the events 416 and 424 apply to the RRC reconfiguration message and the RRC reconfiguration complete message.
[0051] Fig. 4D illustrates a scenario 400D similar to the scenario 400C, except that the scenario 400D includes events 411 X, 413X, and 432 instead of events 411 and 413. The events 411X and 413X are similar to the events 411 and 413, except that the SMComplete in the events 411X and 413X does not indicate that the 1stciphering algorithm is not allowed. The UE 102 transmits 432 to the BS 104, a UL RRC message and a MAC (MAC3) for the UL RRC message. The UL RRC message indicates the UE does not allow the 1stciphering algorithm. The UE 102 generates MAC3 using the integrity protection algorithm, the UL RRC message, and parameters as described for Fig. 3B. The BS 104 then performs 433 an integrity protection check for the UL RRC message and determines that the UL RRC message passes the integrity protection check. The BS 104 may perform the integrity protection check for the UL RRC message based on MAC3, the integrity protection algorithm, and parameters, as described for Fig. 3B. Descriptions related to the events 410, 412, and 414 apply to the events 411 X, 414X, and 415 respectively, by replacing the “SMF” with the “SMComplete”.
[0052] Figs. 5A-5D are signal diagrams illustrating enhanced security techniques employed between a UE and a core network device. These signal diagrams are similar in some respects to the signal diagrams illustrated in Figs. 4A-4D. The CN 110 in these figures has a structure able to perform as 140 in Fig. 1 (i.e. , processing hardwarePatent ApplicationAttorney Docket Number 0683-098-WO including at least a processor 142, a transmitter 144, and a receiver 146). The BS 104 and the RAN 105 (e.g., as illustrated in Fig. 1 ) intermediate message exchanges between the UE 102 and the CN 110 in these scenarios.
[0053] In the scenario 500A illustrated in Fig. 5A, the UE 102 located within a cell (e.g., cell 124 in Fig. 1 ) operated by the BS 104 (via RAN 105) communicates with the CN 110. The UE 102, which initially operates 502 in a connected state (e.g., RRC_CONNECTED state), sends 534, to the CN 110, a UL NAS message triggering a Secure Mode establishment. The CN 110 may (i.e., optional) then send 536 to the UE 102 an Authentication Request causing the UE 102 to respond 538 with an Authentication Response. The Authentication Request and the Authentication Response are substantively (i.e., functionally) similar to the ones described in 3GPP technical specifications.
[0054] The CN 110 then sends 504 (which is similar to 404) a DL PDU including a 1stSMCommand and MAC1 for the 1stSMCommand. The 1stSMCommand configures an integrity protection algorithm and a 1stciphering algorithm. The CN 110 generates MAC1 using the integrity protection algorithm, the 1stSMCommand, and parameters as described for Fig. 3B. The UE 102 then performs 506 an integrity protection check for the 1stSMCommand and determines that the 1stSMCommand passes the integrity protection check. The UE 102 determines 508 that the 1stciphering algorithm is not allowed, for example, due to weak security protection or no security protection provided by the 1stciphering algorithm. The events 504, 506, and 508 are similar to the events 404, 406, and 408 respectively. The events 534, 536, 538, 504, 506, and 508 are collectively referred to as an SMCommand reception procedure 592 (which optionally includes an Authentication NAS procedure). Unlike SMCommand reception procedure 490, the SMCommand reception procedure 592 employs the UE 102 and the CN 110 (which communicate via the BS 104 and RAN 105).
[0055] In response to determining that the 1stSMCommand passes the integrity protection check and that the 1stciphering algorithm is not allowed, the UE 102 generates 510 a Security Mode Reject (SMR, e.g., a message) and a 2nd MAC (MAC2) for the SMR. In some embodiments, the UE 102 generates MAC2 using the integrity protection algorithm, the SMR, and parameters as described for Fig. 3B. In response toPatent ApplicationAttorney Docket Number 0683-098-WO the 1stSMCommand, the UE 102 then transmits 512 a UL PDU to the CN 110. This UL PDU includes the SMR and MAC2. In this scenario, the UE 102 indicates in the SMR that the 1stciphering algorithm is not allowed. For example, the SMR is the Security Mode Reject message defined in 3GPP specification 24.501 or 24.301 with a new cause value “ciphering algorithm not allowed.” This new cause value is not yet defined or different from the currently defined causes in the Security Mode Reject message in 3GPP specification 24.501 or 24.301. The UE 102 includes the new cause value in the SMR to indicate that the 1stciphering algorithm is not allowed.
[0056] In some embodiments, the UE 102 applies encryption to the SMR and MAC2 using the 1stciphering algorithm and parameters as described in Fig. 3A. Although the UE 102 does not allow using the 1stciphering algorithm for received messages, the UE 102 may still apply the 1stciphering algorithm for transmitted messages. The UE 102 obtains an encrypted SMR and an encrypted MAC2 by applying the previously-indicated 1stciphering algorithm to the SMR and to MAC2. The UE 102 then transmits 512, to the CN 110, a UL PDU including the encrypted SMR and the encrypted MAC2. Upon receiving 512 the UL PDU, the CN 110 applies decryption to the encrypted SMR and the encrypted MAC2 and obtains an unencrypted SMR and an unencrypted MAC2. The unencrypted SMR and the unencrypted MAC should be the same as the SMF and MAC2 generated by the UE 102 respectively (i.e., before the UE 102 has applied the encryption). The CN 110 then performs the integrity protection check for the SMR using MAC2 and the integrity protection algorithm as described above. Events 510, 512, and 514 are similar to events 410, 412, and 414 respectively, except that (A) in scenario 500A the UE communicates with the CN 110 via the BS 104 and RAN 105, while in scenario 400A the UE communicates with the BS 104, and (B) the UE generates an SMR in scenario 500A, while the UE generates an SMF in scenario 400A.
[0057] In other embodiments, the UE 102 does not apply encryption to the SMR and MAC2. The UE 102 may do so because the CN 110 may not be able to determine whether a received SMR is encrypted or not. Thus, the CN 110 does not decrypt the received SMR and MAC2.Patent ApplicationAttorney Docket Number 0683-098-WO
[0058] In some embodiments, when the UE 102 determines that the 1stSMCommand fails the integrity check, the UE 102 refrains from generating the MAC2 for the SMR and transmits to the CN 110 a UL PDU including the SMR but not MAC2. The absence of a MAC prevents the CN 110 from performing the integrity protection check. In such cases, the UE 102 may refrain from applying encryption to the SMR.
[0059] Further in scenario 500A, upon receiving the SMR and MAC2, the CN 110 performs 514 an integrity protection check for the SMR based on MAC2 and the integrity protection algorithm and determines that the SMR passes the integrity protection check. Based on the indication (e.g., the new cause value) in the SMR, the CN 110 determines that the UE 102 does not allow the 1stciphering algorithm. After determining that the SMR passes the integrity protection check and that the UE does not allow the 1stciphering algorithm, the CN 110 determines to configure the UE 102 with a 2ndciphering algorithm. The 2ndciphering algorithm may be more robust than the 1stciphering algorithm. In order to configure the UE 102 with the 2ndciphering algorithm, the CN 110 generates a 2ndSMCommand specifying the 2ndciphering algorithm and a third MAC (MAC3) for integrity protection of the 2ndSMCommand. The CN 110 then transmits 516 a DL PDU to the UE 102. This DL PDU includes the 2ndSMCommand and MAC3. The BS 104 may generate MAC using the integrity protection algorithm, the 2ndSMCommand, and parameters as described for Fig. 3B.
[0060] When receiving 516 the DL PDU, the UE 102 performs 518 an integrity protection check for the 2ndSMCommand based on MAC3 and the integrity protection algorithm (as in the examples discussed above). The UE 102 may perform the integrity protection check for the 2ndSMCommand based on MAC3, the integrity protection algorithm, and parameters as described for Fig. 3B. The UE 102 then determines 520 the 2ndciphering algorithm is allowed (as in 420).
[0061] When the UE 102 applies encryption to the SMR and MAC2 with the 1stciphering algorithm and parameters as described for Fig. 3A, the CN 110 also applies encryption to the 2ndSMCommand and MAC3 with the 1stciphering algorithm and parameters as described for Fig. 3A. The CN 110 thus obtains and transmits, to the UE, an encrypted SMCommand and an encrypted MAC within the DL PDU. Upon receiving 516 the DL PDU, the UE 102 then applies decryption to the encryptedPatent ApplicationAttorney Docket Number 0683-098-WOSMCommand and the encrypted MAC3 to obtain the unencrypted SMCommand and the unencrypted MAC. The unencrypted SMCommand and the unencrypted MAC should be the same as the 2ndSMCommand and MAC3 generated by the CN 110 respectively (before the CN 110 applies the encryption). The UE 102 then performs the integrity protection check for the 2ndSMC based on MAC3 using the integrity protection algorithm as described above.
[0062] When the UE 102 refrains from applying encryption to the SMR and MAC2, the CN 110 also refrains from encrypting to the 2ndSMCommand and MAC3.
[0063] In response to the 2ndSMCommand and determining that the 2ndciphering algorithm is allowed, the UE 102 generates 522 an SMComplete and a fourth MAC (MAC4) for the SMComplete. The UE 102 then transmits 524 a UL PDU including the SMComplete and MAC4 to the CN 110. The UE 102 may generate MAC4 using the integrity protection algorithm, the SMComplete, and parameters as described for Fig.3B. Upon receiving the UL PDU, the CN 110 performs 525 an integrity protection check of the received SMComplete using MAC4, the integrity protection algorithm, and parameters as described for Fig. 3B. The UE 102 then communicates 526 data (e.g., control-plane data and / or user-plane data) with the CN 110 using the 2ndciphering algorithm. In response to determining the SMComplete passes the integrity protection check, the CN 110 communicates 526 data (e.g., control-plane data and / or user-plane data) with the UE 102 using the 2ndciphering algorithm.
[0064] The CN 110 may send 527 a DL PDU including a DL NAS Accept (as defined in 3GPP technical specifications) and a MAC5 to the UE. Upon receiving this message, the UE performs 528 an integrity protection check of the DL NAS Accept using the integrity protection algorithm and MAC5.
[0065] In some embodiments, the UE 102 applies encryption to the SMComplete and MAC4 using the 2ndciphering algorithm and parameters as described for Fig. 3A. The UE 102 thus generates an encrypted SMComplete and an encrypted MAC. The UL PDU that the UE 102 transmits, to the CN 110, then includes the encrypted SMComplete and the encrypted MAC. Upon receiving this UL PDU, the CN 110 applies decryption to the encrypted SMComplete and the encrypted MAC and obtains an unencrypted SMComplete and an unencrypted MAC. The CN 110 decrypts thePatent ApplicationAttorney Docket Number 0683-098-WO encrypted SMComplete and the encrypted MAC using the 2ndciphering algorithm and parameters as described for Fig. 3A. The unencrypted SMComplete and the unencrypted MAC should be the same as the SMComplete and MAC4 generated by the UE 102 respectively (i.e. , before the UE 102 applies the encryption). The CN 110 then performs the integrity protection check for the unencrypted SMComplete based on the unencrypted MAC and the integrity protection algorithm as described above.
[0066] The events 518, 520, 522, 524, 525, 527, 528, and 526 in Fig. 5A related to the 2ndciphering algorithm are collectively referred to a procedure 595 (which is similar to yet different from the procedure 495 due to the additional events 527, 528 and the CN 110 instead of the BS 104).
[0067] The UL PDUs and DL PDUs in the events 504, 512, 516, 524, and 527 may be PDCP PDUs. In an embodiment in which the UE 102 refrains from generating a MAC for the SMR, the UE 102 does not include a MAC in the UL PDU sent at the event 512 and the event 514 is omitted. Although not illustrated in Fig. 5A, if the 1stSMCommand does not pass the integrity protection check, the UE 102 does not include a MAC in the UL PDU of the event 512 and the event 514 is omitted.
[0068] In some embodiments, if the UE 102 does not receive a SMCommand indicating the 2ndciphering algorithm from the CN 110 like event 516 within a predetermined time period, the UE 102 might disconnect from the BS 104 and transition to the idle state. For example, the UE 102 might start a timer with the predetermined time period value after transmitting 512 the UL PDU. If the UE 102 receives 516 the DL PDU from the CN 110, the UE 102 stops the timer. Otherwise, if the timer expires because the UE 102 does not receive a SMCommand indicating the 2ndciphering algorithm from the CN 110 like event 516, the UE 102 disconnects from the BS 104 and transitions to the idle state. In other embodiments, if the UE 102 receives one or more other DL PDUs or messages instead of receiving 516 the DL PDU or 2ndSMCommand after transmitting 512 the UL PDU or SMR, the UE 102 might disconnect from the BS 104 and transition to the idle state. With these embodiments, if the CN 110 (e.g., a fake CN) neither configures a ciphering algorithm allowed by the UE 102 nor the BS 104 does not transition the UE 102 to the idle state, the UE 102 actively break away from the control of the BS 104 and the CN 110.Patent ApplicationAttorney Docket Number 0683-098-WO
[0069] Fig. 5B illustrates a scenario 500B similar to the scenario 500A up to event 514 and similar to the scenario 400B after event 514. In scenario 500B, at 514, the CN 110 determines that the SMR passes the integrity protection check and detects (e.g., based on the new indication in SMR) that the UE 102 does not allow the 1stciphering algorithm. The CN 110 then transmits 527, to the UE 102, a DL PDU including a DL NAS Reject message (e.g., as defined in the 3GPP technical specifications) and a third MAC (MAC3) for the DL NAS Reject message. The UE 102 then performs 528 an integrity protection check of the received NAS Reject message using the MAC3. The CN 110 also sends 529 a UE Context Release message to the BS 104, which in turn sends 530 (similar to 428) an RRC Release message directing the UE 102 to transition to an idle state (e.g., RRCJDLE). In response to the RRC Release message, the UE 102 transitions 531 to the idle state.
[0070] Fig. 5C illustrates a scenario 500C similar to the scenario 500A, except that the scenario 500C includes events 511 , 513, and 515 instead of events 510, 512, and 514. In scenario 500C, the UE 102 generates 511 an SMComplete indicating the 1stciphering algorithm not allowed and a second MAC (MAC2) for the SMComplete. The SMComplete in scenario 500C replaces the SMR in scenario 500A. The UE 102 then transmits 513 a UL PDU including the SMComplete and MAC2 to the CN 110 (the event 513 being similar to the event 512). The CN 110 performs 515 an integrity protection check for the SMComplete and determines that the SMComplete passes the integrity protection check. The BS 104 may perform the integrity protection check for the SMComplete using MAC2, the integrity protection algorithm, and parameters as described for Fig. 3B. Descriptions related to the events 510, 512, and 514 generally apply to the events 511 , 513, and 515 respectively, except for replacing the “SMR” with the “SMComplete”.
[0071] Fig. 5D illustrates a scenario 500D similar to the scenario 500C, except that the scenario 500D includes events 511X, 513X, and 532 instead of events 511 and 513. The events 511X and 513X are similar to the events 411 and 413, except that the SMComplete in the events 511X and 513X does not indicate that the 1stciphering algorithm is not allowed. The UE 102 transmits 532 to the CN 110, a UL PDU including an UL NAS message and a MAC (MAC3) for the UL RRC message. The UL NASPatent ApplicationAttorney Docket Number 0683-098-WO message indicates the 1stciphering algorithm is not allowed. The UE 102 generates MAC3 using the integrity protection algorithm, the UL NAS message, and parameters as described for Fig. 3B. The CN 110 then performs 533 an integrity protection check for the UL NAS message (e.g., using MAC3, the integrity protection algorithm and parameters, as described for Fig. 3B) and determines that the UL NAS message passes the integrity protection check.
[0072] Figs. 6A-6E are flow diagrams of UE methods with the UE indicating to the BS or the CN device (i.e. , to a network entity (NE) engaged in a Security Mode establishment procedure) that a NE-indicated 1stciphering algorithm is not allowed, according to various embodiments.
[0073] Method 600A illustrated in Fig. 6A begins with the UE receiving 604, from an NE, a 1stSMCommand and a first MAC (MAC1 ) for the 1stSMCommand. The NE may be a base station (e.g., the BS 104 in Figs. 4A-4D) or a CN device (e.g., the CN 110 in Figs. 5A-5D). Step 604 corresponds, for example, to events 404 and 504 (when the NE is the BS or the CN device, respectively). The 1stSMCommand configures an integrity protection algorithm and a 1stciphering algorithm.
[0074] The method 600A then includes performing 606 an integrity protection check for the 1stSMCommand using the integrity protection algorithm and MAC1 to determine that the 1stSMCommand passes the integrity protection check. Step 604 corresponds, for example, to events 404 and 504 (when the NE is the BS or the CN device, respectively).
[0075] The method 600A continues with the UE determining 608 that the 1stciphering algorithm indicated in the 1stSMCommand is not allowed by the UE. Step 608 corresponds, for example, to events 408 and 508 (when the NE is the BS or the CN device, respectively). Note that the ciphering algorithm indicated in the 1stSMCommand not being allowed by the UE is different from the UE being unable to handle the ciphering algorithm (e.g., UE’s ability to handle a certain ciphering algorithm may be specified in UE capability information).
[0076] Further in method 600A, the UE generates 610 an SMF or an SMR and a second MAC (MAC2) for the SMF / SMR. That is, if the NE is a BS, the UE generates an SMF, and if the NE is a CN device, the UE generates an SMR. The SMF / SMR mayPatent ApplicationAttorney Docket Number 0683-098-WO indicate that 1stciphering algorithm not allowed. When the SMF / SMR indicates that 1stciphering algorithm not allowed, step 610 corresponds, for example, to events 410 and 510 for the NE being the BS or the CN device, respectively. When the SMF / SMR does not indicate that 1stciphering algorithm not allowed, the UE may send separately (like in 415 and 515) the indication that 1stciphering algorithm is not allowed.
[0077] The method 600A ends with transmitting 612 the SMF / SMR and MAC2 to the NE, in response to the 1stSMCommand. Step 612 corresponds, for example, to events 412 and 512 (when the NE is the BS or the CN device, respectively).
[0078] The method 600B illustrated in Fig. 6B is similar to method 600A starting with the same steps 604, 606, and 608. The method 600B then continues with generating 611 a 1stSMComplete and MAC2 for the 1stSMComplete. Here, the 1stSMComplete message indicates that 1stciphering algorithm is not allowed. The method 600B ends with transmitting 613 the 1stSMComplete and MAC2 to the network, in response to the 1stSMCommand. Thus steps 611 and 613 are similar to steps 610 and 612 except that the former (611 and 613) refer to the SMF / SMR and the latter (611 and 613) to the SMComplete.
[0079] The method 600C illustrated in Fig. 6C is similar to methods 600A and 600B starting with same steps 604, 606, and 608. In the method 600C, the generating 611X of a 1stSMComplete and MAC2 for the 1stSMComplete differs from 611 in Fig. 6B because in 611X the SMComplete message does not indicate that the 1stciphering algorithm is not allowed. Instead of including such an indication in the SMComplete message, after transmitting 613X the 1stSMComplete and MAC2 to the network, in response to the 1stSMCommand, the method 600C further includes transmitting 632 a UL PDU to the network, including information and MAC3, the information indicating the 1stciphering algorithm is not allowed (similar to 432 and 532).
[0080] The method 600D in Fig. 6D is also similar to the method 600A with the following differences. After step 604 (receiving the 1stSMCommand), the method 600D continues with step 608 (determining the 1stciphering algorithm not allowed), thus omitting step 606. The method 600D continues with refraining 609 from applying the integrity protection algorithm and the 1stciphering algorithm in response to thePatent ApplicationAttorney Docket Number 0683-098-WO determination 608. The method 600D ends with steps 610 and 612 as does the method 600A.
[0081] The method 600E in Fig. 6E provides for when the 1stciphering algorithm is allowed. After steps 604 and 606 described above, step 608 in the methods 600A, 600B, 600C and 600D is replaced by inquiry 632: “Is the 1stciphering algorithm allowed?” When the 1stciphering algorithm is not allowed (i.e. , NO branch of 632), the method 600E continues with steps following 608 in 600A, 600B, 600C, or 600D. However, when the 1stciphering algorithm is allowed (i.e., YES branch of 632), the method 600E continues with generating 622 a 1stSMComplete and MAC4 for the 1stSMComplete, transmitting 624 the 1stSMComplete and MAC4 to the NE, in response to the 1stSMCommand, and communicating 626 data with the NE using the 1stciphering algorithm. Steps 622, 624, and 626 are similar to events 422, 424, and 426 or 522, 524, 526 which similarly refer to a ciphering algorithm (2ndin the signal diagrams) determined to be allowed.
[0082] Figs. 7A and 7B are flow diagrams of UE methods related to a 2ndciphering algorithm provided by the NE after the 1stciphering algorithm is not allowed by the UE according to some embodiments. After the steps related to the 1stciphering algorithm which the UE does not allow (i.e., the steps of methods 600A, 600B, 600C, or 600D) collectively labeled 701 , the method 700A includes receiving 716, from the NE (i.e., a BS or a CN device), a 2ndSMCommand and MAC3 for the 2ndSMCommand. This 2ndSMCommand indicates a 2ndciphering algorithm. The method 700A then includes performing 718 an integrity protection check for the 2ndSMCommand using the integrity protection algorithm and MAC3 to determine the 2ndSMCommand passes the integrity protection check. After determining 720 that the 2ndciphering algorithm indicated in the 2ndSMCommand is allowed, the method 700A includes generating 722 a 2ndSMComplete and MAC4 for the 2ndSMComplete and transmitting 724 the 2ndSMComplete and MAC4 to the NE. The method finally includes communicating 726 with the NE using the 2ndciphering algorithm. The steps 716, 718, 720, 722, 724, and 726 correspond to events 416, 418, 420, 422, 424, and 426 respectively when the NE is a BS such as BS 104, and to events 516, 518, 520, 522, 524, and 526 respectively when the NE is a CN device such as CN 110 / 140.Patent ApplicationAttorney Docket Number 0683-098-WO
[0083] The method 700B in Fig. 7B is similar to method 700A but valid only when the NE is a BS such as BS 104. Instead of steps 716 and 718 of the method 700A, the method 700B includes steps 736 and 738. Thus, the method 700B includes receiving 736, from the NE, an RRC reconfiguration message and MAC3 for the RRC reconfiguration message. This RRC reconfiguration message indicates a 2ndciphering algorithm. The method 700B also includes performing 738 an integrity protection check for the RRC reconfiguration message using the integrity protection algorithm and MAC3 to determine the RRC reconfiguration message passes the integrity protection check.
[0084] Further, instead of steps 722 and 724 of the method 700A, the method 700B includes steps 740 and 742. Thus, the method 700B includes generating 740 an RRC reconfiguration complete message and MAC4 for the RRC reconfiguration complete message, and transmitting 742 the RRC reconfiguration complete message and MAC4 to the NE.
[0085] Fig. 8A-8C are flow diagrams of NE methods according to various embodiments. These methods illustrate the NE behavior related to enhancing security mode establishment as illustrated in Figs. 4A-D and 5A-D. Thus the NE may be a base station (e.g., 104) or a CN device (e.g., 110 / 140).
[0086] The method 800A illustrated in Fig. 8A starts with transmitting 804, to a UE, a 1stSMCommand and a first MAC (MAC1 ) for the 1stSMCommand. Here, the 1stSMCommand indicates an integrity protection algorithm and a 1stciphering algorithm. Step 804 corresponds to 404 and 504 in Figs. 4A-5D.
[0087] Further, the method 800A includes receiving 812, from the UE, an SMF / SMR and MAC2 for the SMF / SMR, in response to the 1stSMCommand. That is, if the NE is a BS, the NE receives an SMF, and if the NE is a CN device, the NE receives an SMR. The SMF / SMR indicates the 1stciphering algorithm is not allowed (e.g., using a new value for the cause of the failure / rejection). Step 812 corresponds to 412 or 512 in Figs. 4A-5D.
[0088] The method 800A may further include performing 814 an integrity protection check for the SMF / SMR using the integrity protection algorithm and MAC2 to determine the SMF / SMR passes the integrity protection check. Step 814 corresponds to 414 or 514 in Figs. 4A-5D. Further, the method 800A includes transmitting 816, toPatent ApplicationAttorney Docket Number 0683-098-WO the UE, a 2ndSMCommand and MAC3 for the 2ndSMCommand, the 2ndSMCommand configuring a 2ndciphering algorithm. Step 816 corresponds to 416 or 516 in Figs. 4A- 5D.
[0089] The method 800A continues with receiving 824 an SMComplete and MAC4 for the SMComplete from the UE, in response to the 2ndSMCommand, and then performing 825 an integrity protection check for the SMComplete using the integrity protection algorithm and MAC4 to determine the SMComplete passes the integrity protection check. Steps 824 and 825 correspond to events 424 and 425 or events 524 and 525 in Figs. 4A-5D. The method 800A concludes with communicating 826 with the UE using the 2ndciphering algorithm (which corresponds to events 426 or 526 in Figs. 4A-5D).
[0090] The method 800B in Fig. 8B is similar to the method 800A except that steps 812 and 814 are replaced by steps 813 and 815 because SMComplete replaces SMF / SMR as response to the 1stSMCommand. Thus, the method 800B includes receiving 813, from the UE, a 1stSMComplete and MAC2 for the 1stSMComplete, in response to the 1stSMCommand. Here, the 1stSMComplete indicates that the 1stciphering algorithm is not allowed. The method 800B further includes performing 815 an integrity protection check for the 1stSMComplete using the integrity protection algorithm and MAC2 to determine the 1stSMComplete passes the integrity protection check. Steps 813 and 815 correspond to events 413 and 415 or 513 and 515 respectively in Figs. 4A-5D.
[0091] The method 800C illustrated in Fig. 8C is similar to the method 800B except that steps 816, 824, and 825 of the method 800B are replaced by steps 817, 821 , and 823. After step 815, the method 800C continues with transmitting 817, to the UE, an RRC reconfiguration message and MAC3 for the RRC reconfiguration message. This RRC reconfiguration message indicates a 2ndciphering algorithm. The method 800C further includes receiving 821 an RRC reconfiguration complete message and MAC4 for the RRC reconfiguration message from the UE, in response to the RRC reconfiguration message. Furthermore, the method 800C includes performing 823 an integrity protection check for the RRC reconfiguration complete message using thePatent ApplicationAttorney Docket Number 0683-098-WO integrity protection algorithm and MAC4 to determine the RRC reconfiguration complete message passes the integrity protection check.
[0092] Figs. 9A and 9B are flow diagrams of UE methods with decision blocks related to emergency calls impacting the enhanced security mode establishment according to some embodiments. Steps 904, 906, and 908 of the method 900A are substantively similar to steps 604, 606, and 608 (i.e. , the corresponding steps do not differ in a significant manner). Then, the method 900A includes an inquiry 950 (i.e., a decision block) testing: “Has an emergency call been initiated?” If there is no ongoing emergency call (i.e., NO branch of 950), the method 900A continues with step 912 that is, transmitting an SMF / SMR / SMComplete to the network in response to the 1stSMCommand and then according to any of 600A-E. If there is an ongoing emergency call (i.e., YEs branch of 950), the method continues with steps 911X (generating a 1stSMComplete and MAC2 for the 1stSMComplete) and 913X (transmitting the 1stSMComplete and MAC2 to the NE, in response to the 1stSMCommand) before communicating 927 data with the NE using the 1stciphering algorithm. In other words, when there is an ongoing emergency call, the NE-indicated 1stciphering algorithm is used for communicating regardless of whether the 1stciphering algorithm is allowed at the UE.
[0093] The method 900B illustrated in Fig. 9B is similar to the method 900A except that the method 900B does not include step 908 but includes a second decision block 952 testing whether the 1stciphering algorithm is allowed when there is no ongoing emergency call (i.e., NO branch of 950). If the 1stciphering algorithm is not allowed (i.e., NO branch of 952), the method 900B continues with 912 described above. If the 1stciphering algorithm is allowed (i.e., Yes branch of 952), the method 900B continues with steps 911X, 913X, and 927 described above.
[0094] Figs. 10A-10C are flow diagrams of NE methods illustrating various other decision blocks according to some embodiments.
[0095] The method 1000A illustrated in Fig. 10 is similar to the method 800A steps 1004, 1012, 1014, 1016, 1024, 1025, and 1026 being substantively similar to steps 804, 812, 814, 816, 824, 825, and 826. The decision block 1054 follows step 1012 and tests whether a MAC for the SMF / SMR / / 1stSMComplete has been received. IfPatent ApplicationAttorney Docket Number 0683-098-WO the answer to this inquiry is YES, the method 1000A follows essentially the same steps as the method 800A. However, if the answer to this inquiry is NO, then the method 1000A includes transmitting 1028 an RRC release message to the UE.
[0096] The method 1000B illustrated in Fig. 10B is similar to the method 1000A except that decision block 1054 is replaced by decision block 1055 as to whether the SMF / SMR / 1stSMComplete indicates the 1stciphering algorithm is not allowed by the UE. If the answer to this inquiry is YES, the method 1000B follows essentially the same steps as the method 1000A. However, if the answer to this inquiry is NO, then the method 1000B includes transmitting 1028 an RRC release message to the UE.
[0097] According to one example, a wireless communication method (e.g., 600A) performed by a UE (e.g., 102) includes: receiving (e.g., 604), from an NE (e.g., 104, 110, 140) a first SMCommand and a first MAC, the first SMCommand indicating an integrity protection algorithm and a first ciphering algorithm. This method further includes transmitting (e.g., 612), to the NE, a response to the first SMCommand, the response indicating that the first ciphering algorithm is not allowed by the UE. The transmitting the response may include determining (e.g., 608) whether the first ciphering algorithm is allowed by the UE, and generating (e.g., 610) the response indicating that the first ciphering algorithm is not allowed based on the determining. The transmitting of the response may include transmitting a first message with a second MAC and transmitting a second message indicating that the first ciphering algorithm is not allowed by the UE (as for example in Figs. 4B, 5B). The receiving of the first SMCommand may include performing an integrity check of the first SMCommand using the integrity protection algorithm and the first MAC. The wireless communication method may further include encrypting the response using the first ciphering algorithm. When the first ciphering algorithm is not allowed, the UE may refrain from performing the integrity protection check of the first SMCommand (using the integrity protection algorithm and the first MAC) and from applying the first ciphering algorithm to the response (as in step 609 in Figure 6D). The response may be a Security Mode Complete message as defined in 3GPP technical specifications (e.g., as in step 611 in Fig. 6B, 6C, and Figs. 4C, 4D, 5C, 5D). Alternatively, when the response is a radio resource control, RRC, message for aPatent ApplicationAttorney Docket Number 0683-098-WO base station, the response may be a Security Mode Failure message as defined in 3GPP technical specifications (as illustrated, e.g., in Figs. 4A and 4B). In yet another alternative, when the response is a non-access stratum, NAS, message for a network core entity, the response may be a Security Mode Reject message as defined in 3GPP technical specifications (as illustrated, e.g., in Figs. 5A and 5B). The wireless communication method may further include receiving, from the NE, a second SMCommand that indicates a second ciphering algorithm, and communicating (e.g., 426, 526, 626) data with the NE using the second ciphering algorithm, when the second ciphering algorithm is allowed by the UE (e.g., as in 716, 718, 724 in Fig. 7A). The receiving of the second SMCommand may include: (i) receiving, from the NE, a first radio resource control, RRC, message and a third MAC, the first RRC message indicating the second ciphering algorithm; (ii) performing an integrity check of the first RRC message using the integrity protection algorithm and the third MAC; and (iii) upon determining that the second ciphering algorithm is allowed by the UE, transmitting, to the NE, a second RRC message and a fourth MAC (e.g., 736, 738,742 in Fig. 7B). Here, the first RRC message may be an RRC reconfiguration message and the second RRC message may be an RRC reconfiguration complete message. The wireless communication method may further include communicating data with the NE using the first ciphering algorithm regardless of whether the first ciphering algorithm is allowed by the UE when an ongoing emergency call has been initiated before the receiving the first SMCommand. The NE may be a base station or a core network device communicating to the UE via a base station.
[0098] According to another example, a wireless communication method (e.g., 800A) performed by a NE (e.g., 104, 110, 140) includes transmitting (e.g., 804), to a UE (e.g. 102), a first SMCommand and a first MAC, the first SMCommand indicating an integrity protection algorithm and a first ciphering algorithm. The method further includes receiving (e.g., 812, 813), from the UE, a response to the first SMCommand and a second MAC, the response indicating that the first ciphering algorithm is not allowed by the UE (as in Figs. 8A-C, 10A-10B). The response may be a Security Mode Complete message (e.g., 813 in Figs. 8B and 8D), a Security Mode Failure message as defined in 3GPP technical specifications (e.g., 812 in Figs. 8A and 8C), or a SecurityPatent ApplicationAttorney Docket Number 0683-098-WOMode Reject message (e.g.,812 in Fig. 8A and 8C) as defined in 3GPP technical specifications. The wireless communication method may further include transmitting, to the UE, a second SMCommand indicating a second ciphering algorithm (e.g., 816 in Figs. 8A-D). Alternatively or additionally, the wireless communication method may further include wirelessly disconnecting from the UE (as in Fig. 10B). The wireless communication method may further include transmitting an RRC release message when the response does not include a second MAC (as in Fig. 10A). The NE may be a base station or a core network device.
[0099] A wireless communication (e.g., 102, 104, 140) device having a transceiver (e.g., 154, 156, 134, 136, 144, 146) and a processor (e.g., 152, 132, 142) is configured to cooperate for performing any one of the example methods above.
[0100] Reference throughout this section to “one embodiment” or “an embodiment” means that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout the specification are not necessarily all referring to the same embodiment. Further, the particular features, structures or characteristics may be combined in any suitable manner in one or more embodiments.
[0101] Numerical adjectives “first”, “second”, and “third” do not imply any order (are not ordinals) but are markers to distinguish separate instances of similar elements. References to the singular (e.g., “a” or “an”, “the”) should include the plural unless clearly indicated otherwise.
[0102] As used herein, a phrase referring to “at least one of” or “one or more of” a list of items refers to any combination of those items, including single members. For example, “at least one of: a, b, or c” is intended to cover the possibilities of: a only, b only, c only, a combination of a and b, a combination of a and c, a combination of b and c, and a combination of a and b and c.
[0103] Although the features and elements of the present embodiments are described in the embodiments in particular combinations, each feature or element can be used alone without the other features and elements of the embodiments or in various combinations with or without other features and elements disclosed herein. ThePatent ApplicationAttorney Docket Number 0683-098-WO methods or flowcharts may be implemented in a computer program, software or firmware tangibly embodied in a computer-readable storage medium for execution by a specifically programmed computer or processor.
Claims
Patent ApplicationAttorney Docket Number 0683-098-WOWHAT IS CLAIMED IS:1 . A wireless communication method (600A) performed by user equipment (102), UE, the method comprising: receiving (604), from a network entity (104, 110, 140), NE, a first security mode command, SMCommand, and a first message authentication code, MAC, the first SMCommand indicating an integrity protection algorithm and a first ciphering algorithm; and transmitting (612), to the NE, a response to the first SMCommand, the response indicating that the first ciphering algorithm is not allowed by the UE.
2. The wireless communication method of claim 1 , wherein the transmitting the response comprises: transmitting a first message with a second MAC; and transmitting a second message indicating that the first ciphering algorithm is not allowed by the UE.
3. The wireless communication method of claim 1 or 2, further comprising: encrypting the response using the first ciphering algorithm.
4. The wireless communication method of any of claims 1 to 3, wherein the receiving comprises: performing an integrity check of the first SMCommand using the integrity protection algorithm and the first MAC.
5. The wireless communication method of claim 1 or 2, wherein the UE refrains from performing an integrity protection check of the first SMCommand using the integrity protection algorithm and the first MAC, and refrains from applying the first ciphering algorithm to the response when the first ciphering algorithm is not allowed.Patent ApplicationAttorney Docket Number 0683-098-WO6. The wireless communication method of any of claims 1 to 5, wherein the response is a Security Mode Complete message or a Security Mode Failure message as defined in 3GPP technical specifications when the response is a radio resource control, RRC, message for a base station.
7. The wireless communication method of any of claims 1 to 5, wherein the response is a Security Mode Reject message as defined in 3GPP technical specifications when the response is a non-access stratum, NAS, message for a network core entity.
8. The wireless communication method of any of claims 1 to 7, further comprising: receiving, from the NE, a second SMCommand that indicates a second ciphering algorithm; and communicating (426, 526, 626) data with the NE using the second ciphering algorithm, when the second ciphering algorithm is allowed by the UE,9. The wireless communication method of any of claims 1 to 8, further comprising: communicating data with the NE using the first ciphering algorithm regardless of whether the first ciphering algorithm is allowed by the UE when an ongoing emergency call has been initiated before the receiving the first SMCommand.
10. A wireless communication method (800A) performed by a network entity, NE, (104, 110, 140), the method comprising: transmitting (804), to a user equipment, UE, (102), a first security mode command, SMCommand, and a first message authentication code, MAC, the first SMCommand indicating an integrity protection algorithm and a first ciphering algorithm; andPatent ApplicationAttorney Docket Number 0683-098-WO receiving (812, 813), from the UE, a response to the first SMCommand and a second MAC, the response indicating that the first ciphering algorithm is not allowed by the UE.11 . The wireless communication method of claim 10, wherein the response is a Security Mode Complete message, a Security Mode Failure message or a Security Mode Reject as defined in 3GPP technical specifications.
12. The wireless communication method of claim 10 or 11 , further comprising: transmitting, to the UE, a second SMCommand indicating a second ciphering algorithm.
13. The wireless communication method of any of claims 10 to 12, further comprising: transmitting a radio resource control, RRC, release message when the response does not include a second MAC.
14. The wireless communication method of any of claims 10 to 13, wherein the NE is a base station a core network device.
15. A wireless communication (102, 104, 140) device comprising a transceiver (154, 156, 134, 136, 144, 146) and a processor (152, 132, 142) configured to cooperate for performing any one of methods recited in claims 1-14.
Citation Information
Patent Citations
Method and Device for Negotiating Security and Integrity Algorithms
US20220225100A1