Technologies for physical layer security in a wireless cellular network
The implementation of a physical layer key (KPHY) in wireless cellular networks addresses key leakage issues by deriving encryption and integrity keys from channel measurements, enhancing network security and integrity.
Patent Information
- Application Number
- PCT/CN2024/111469
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-08-12
- Publication Date
- 2026-02-19
AI Technical Summary
Leakage of top layer keys K, CK, and/or IK in wireless cellular networks breaks the encryption and integrity checking system, compromising security.
Implementing physical layer security by generating a physical layer key (KPHY) using a hash function of channel measurements, and deriving encryption and integrity keys from this key to secure NAS and AS signaling.
Enhances network security by ensuring only authorized devices can replicate the physical layer key, thereby preventing unauthorized access and maintaining encryption and integrity.
Smart Images

Figure CN2024111469_19022026_PF_FP_ABST
Abstract
Description
TECHNOLOGIES FOR PHYSICAL LAYER SECURITY IN A WIRELESS CELLULAR NETWORKTECHNICAL FIELD
[0001] This application relates generally to communication networks and, in particular, to technologies for physical layer security in a wireless cellular network.BACKGROUND
[0002] Third Generation Partnership Project (3GPP) Technical Specifications (TSs) define standards for wireless networks. These TSs describe aspects related to signaling traffic through systems that incorporate wireless networks.BRIEF DESCRIPTION OF THE DRAWINGS
[0003] FIG. 1 illustrates a network environment in accordance with some embodiments.
[0004] FIG. 2 illustrates a hierarchy of key generation in a 5G system (5GS) .
[0005] FIG. 3 illustrates a registration procedure in accordance with various embodiments.
[0006] FIG. 4 illustrates a user equipment (UE) security capability information element in accordance with some embodiments.
[0007] FIG. 5 illustrates a non-access stratum (NAS) security mode command procedure in accordance with some embodiments.
[0008] FIG. 6 illustrates an access stratum (AS) security mode command procedure in accordance with some embodiments.
[0009] FIG. 7 illustrates an operational flow / algorithmic structure in accordance with some embodiments.
[0010] FIG. 8 illustrates another operational flow / algorithmic structure in accordance with some embodiments.
[0011] FIG. 9 illustrates another operational flow / algorithmic structure in accordance with some embodiments.
[0012] FIG. 10 illustrates a user equipment in accordance with some embodiments.
[0013] FIG. 11 illustrates a network device in accordance with some embodiments.DETAILED DESCRIPTION
[0014] The following detailed description refers to the accompanying drawings. The same reference numbers may be used in different drawings to identify the same or similar elements. In the following description, for purposes of explanation and not limitation, specific details are set forth such as particular structures, architectures, interfaces, techniques, etc. in order to provide a thorough understanding of the various aspects of various embodiments. However, it will be apparent to those skilled in the art having the benefit of the present disclosure that the various aspects of the various embodiments may be practiced in other examples that depart from these specific details. In certain instances, descriptions of well-known devices, circuits, and methods are omitted so as not to obscure the description of the various embodiments with unnecessary detail. For the purposes of the present document, the phrase “A or B” means (A) , (B) , or (A and B) ; and the phrase “based on A” means “based at least in part on A, ” for example, it could be “based solely on A” or it could be “based in part on A. ”
[0015] The following is a glossary of terms that may be used in this disclosure.
[0016] The term “circuitry” as used herein refers to, is part of, or includes hardware components such as an electronic circuit, a logic circuit, a processor (shared, dedicated, or group) or memory (shared, dedicated, or group) , an application specific integrated circuit (ASIC) , a field-programmable device (FPD) (e.g., a field-programmable gate array (FPGA) , a programmable logic device (PLD) , a complex PLD (CPLD) , a high-capacity PLD (HCPLD) , a structured ASIC, or a programmable system-on-a-chip (SoC) ) , digital signal processors (DSPs) , etc., that are configured to provide the described functionality. In some embodiments, the circuitry may execute one or more software or firmware programs to provide at least some of the described functionality. The term “circuitry” may also refer to a combination of one or more hardware elements (or a combination of circuits used in an electrical or electronic system) with the program code used to carry out the functionality of that program code. In these embodiments, the combination of hardware elements and program code may be referred to as a particular type of circuitry.
[0017] The term “processor circuitry” as used herein refers to, is part of, or includes circuitry capable of sequentially and automatically carrying out a sequence of arithmetic or logical operations, or recording, storing, or transferring digital data. The term “processor circuitry” may refer an application processor, baseband processor, a central processing unit (CPU) , a graphics processing unit, a single-core processor, a dual-core processor, a triple-core processor, a quad-core processor, or any other device capable of executing or otherwise operating computer-executable instructions, such as program code, software modules, or functional processes.
[0018] The term “interface circuitry” as used herein refers to, is part of, or includes circuitry that enables the exchange of information between two or more components or devices. The term “interface circuitry” may refer to one or more hardware interfaces, for example, buses, I / O interfaces, peripheral component interfaces, network interface cards, or the like.
[0019] The term “user equipment” or “UE” as used herein refers to a device with radio communication capabilities and may describe a remote user of network resources in a communications network. The term “user equipment” or “UE” may be considered synonymous to, and may be referred to as, client, mobile, mobile device, mobile terminal, user terminal, mobile unit, mobile station, mobile user, subscriber, user, remote station, access agent, user agent, receiver, radio equipment, reconfigurable radio equipment, reconfigurable mobile device, etc. Furthermore, the term “user equipment” or “UE” may include any type of wireless / wired device or any computing device including a wireless communications interface.
[0020] The term “computer system” as used herein refers to any type interconnected electronic devices, computer devices, or components thereof. Additionally, the term “computer system” or “system” may refer to various components of a computer that are communicatively coupled with one another. Furthermore, the term “computer system” or “system” may refer to multiple computer devices or multiple computing systems that are communicatively coupled with one another and configured to share computing or networking resources.
[0021] The term “resource” as used herein refers to a physical or virtual device, a physical or virtual component within a computing environment, or a physical or virtual component within a particular device, such as computer devices, mechanical devices, memory space, processor / CPU time, processor / CPU usage, processor and accelerator loads, hardware time or usage, electrical power, input / output operations, ports or network sockets, channel / link allocation, throughput, memory usage, storage, network, database and applications, workload units, or the like. A “hardware resource” may refer to compute, storage, or network resources provided by physical hardware element (s) . A “virtualized resource” may refer to compute, storage, or network resources provided by virtualization infrastructure to an application, device, system, etc. The term “network resource” or “communication resource” may refer to resources that are accessible by computer devices / systems via a communications network. The term “system resources” may refer to any kind of shared entities to provide services, and may include computing or network resources. System resources may be considered as a set of coherent functions, network data objects or services, accessible through a server where such system resources reside on a single host or multiple hosts and are clearly identifiable.
[0022] The term “channel” as used herein refers to any transmission medium, either tangible or intangible, which is used to communicate data or a data stream. The term “channel” may be synonymous with or equivalent to “communications channel, ” “data communications channel, ” “transmission channel, ” “data transmission channel, ” “access channel, ” “data access channel, ” “link, ” “data link, ” “carrier, ” “radio-frequency carrier, ” or any other like term denoting a pathway or medium through which data is communicated. Additionally, the term “link” as used herein refers to a connection between two devices for the purpose of transmitting and receiving information.
[0023] The terms “instantiate, ” “instantiation, ” and the like as used herein refers to the creation of an instance. An “instance” also refers to a concrete occurrence of an object, which may occur, for example, during execution of program code.
[0024] The term “connected” may mean that two or more elements, at a common communication protocol layer, have an established signaling relationship with one another over a communication channel, link, interface, or reference point.
[0025] The term “network element” as used herein refers to physical or virtualized equipment or infrastructure used to provide wired or wireless communication network services. The term “network element” may be considered synonymous to or referred to as a networked computer, networking hardware, network equipment, network node, virtualized network function, or the like.
[0026] The term “information element” refers to a structural element containing one or more fields. The term “field” refers to individual contents of an information element, or a data element that contains content. An information element may include one or more additional information elements.
[0027] The term “based on” as used herein may indicate that an item is based solely on another item and / or an item is based on another item and one or more additional items. For example, item 1 being determined based on item 2 may indicate that item 1 is determined based solely on item 2 and / or is determined based on item 2 and one or more other items in embodiments.
[0028] FIG. 1 illustrates a network environment 100 in accordance with some embodiments. The network environment 100 may include a user equipment (UE) 104 communicatively coupled with a base station 108 of a radio access network (RAN) 110. The UE 104 and the base station 108 may communicate over air interfaces compatible with 3GPP TSs such as those that define a Fifth Generation (5G) new radio (NR) system or a later system. The base station 108 may provide user plane and control plane protocol terminations toward the UE 104.
[0029] The network environment 100 may further include a core network 112. For example, the core network 112 may comprise a 5th Generation Core network (5GC) or later generation core network. The core network 112 may be coupled to the base station 108 via a fiber optic or wireless backhaul. The core network 112 may provide functions for the UE 104 via the base station 108. These functions may include managing subscriber profile information, subscriber location, authentication of services, or switching functions for voice and data sessions. For example, the core network 112 may include an access and mobility management function (AMF) 114.
[0030] In some embodiments, the network environment 100 may also include UE 106. The UE 106 may be coupled with the UE 104 via a sidelink interface. In some embodiments, the UE 106 may act as a relay node to communicatively couple the UE 104 to the RAN 110. In other embodiments, the UE 106 and the UE 104 may represent end nodes of a communication link. For example, the UEs 104 and 106 may exchange data with one another (e.g., using the physical layer security techniques described herein) .
[0031] In NR, a secret key hierarchy is used to generate encryption key (cipher key) and integrity key (for integrity checking) at different security layers. FIG. 2 illustrates an example of key hierarchy generation in 5GS. FIG. 2 may correspond to Figure 6.2.1-1 of 3GPP TS 33.501, V18.6.0. The keys include a top level key, K, and a cipher key (CK) and integrity key (IK) generated from the top level key, K. As shown, various other keys may be generated from one or more of the keys K, CK, and / or IK for use at different layers (e.g., functions) on the network side and UE side. In case of EAP-AKA’, keys CK’ and IK’ are derived from CK and IK, respectively.
[0032] The layers at the network side may include unified data management (UDM) / authentication credential repository and processing function (ARPF) , an authentication server function (AUSF) , in a home public land mobile network (HPMLN) , and security anchor function (SEAF) , access and mobility management function (AMF) , and non-3GPP inter-working function (N3IWF) , mobile equipment (ME) , and gNode B (gNB) . At the UE side, the layers may include a universal subscriber identity module (USIM) and a ME.
[0033] As shown in FIG. 2, the key hierarchy may include the following keys:
[0034] - KAUSF: Key for ASF in home network, derived from CK’ and IK’
[0035] - KSEAF: Anchor key in SEAF, derived from KAUSF;
[0036] - KAMF: Key for AMF in serving network, derived from KSEAF;
[0037] ○ KNASint, KNASenc: keys for non-access stratum (NAS) signaling, derived from KAMF
[0038] - KgNB: Key for NG-RAN, derived from KAMF
[0039] ○ KRRCint: integrity key for radio resource control (RRC) signaling
[0040] ○ KRRCenc: encryption key for RRC signaling
[0041] ○ KUPint: integrity key for user plane (UP) traffic
[0042] ○ KUPenc: encryption key for UP traffic.
[0043] A key derivation function is specified in 3GPP TS 33.220, V18.3.0, Annex B.2.0. An output key is derived from a hash function (e.g., hash-based message authentication code (HMAC) -secure hash algorithm (SHA) -256) of an input key (Key) and a string (S) , e.g., derived key = HMAC-SHA-256 (Key, S) . To derive the keys for the UP and RRC traffic, the input key is the 256-bit KgNB. The string S is generated from input parameters concatenated into a two-octet string.
[0044] In one example, the string S is constructed from n+1 input parameters as follows:
[0045] S = FC || P0 || L0 || P1 || L1 || P2 || L2 || P3 || L3 || ... || Pn || Ln
[0046] where:
[0047] - FC is used to distinguish between different instances of the algorithm and is either a single octet or consists of two octets of the form Fc1 || FC2 where FC1 =0xFF and FC2 is a single octet.
[0048] - P0 ... Pn are the n+1 input parameter encodings, express the number of octets in input parameter Pi as a number k in the range [0, 65535] .
[0049] - L0 ... Ln are the two-octet representations of the length of the corresponding input parameter encodings P0 ... Pn.
[0050] ○ Li is then a 16-bit long encoding of the number k.
[0051] - For RRC integrity, UP integrity, and RRC / UP encryption algorithms from KgNB:
[0052] ○ FC = 0x15; P0 = algorithm type distinguisher (see Table 1 below, corresponding to Table A. 7-1 of 3GPP TS 33.401) , P1 = algorithm identity.
[0053] Table 1
[0054] One issue with the techniques described above is that leakage of the top layer keys K, CK, and / or IK may break the whole encryption and integrity checking system.
[0055] Various embodiments herein provide techniques for physical layer security in a wireless cellular network. For example, embodiments may include techniques to use a secret key generated from the physical layer, referred to as a physical layer key (KPHY) . In some embodiments, the physical layer key may be used to generate one or more keys for NAS and / or AS signaling, e.g., including RRC signaling and / or UP traffic. The physical layer key may be used to generate one or more encryption keys and / or one or more integrity keys.
[0056] In some embodiments, the derived key may be derived from a hash function (e.g., HMAC-SHA, such as HMAC-SHA-256) of an input key (Kin) and a string (S) . In one example, the string S input to the hash function is based on the physical layer key KPHY. In another example, the input key Kin to the hash function is based on the physical layer key KPHY. In another example, the derived key may be derived based on the output of the hash function (e.g., output bits) and the physical layer key KPHY. In some embodiments, two or more of these techniques may be combined to derive an output key.
[0057] Various embodiments further provide signaling to support the techniques for physical layer security. For example, the UE may report its capability of generating the physical layer key, e.g., to the AMF in a registration procedure. The AMF may indicate UE’s capability of generating physical layer key to the RAN (e.g., base station) . The RAN may indicate its own capability of supporting physical layer key generation to the AMF.
[0058] Various embodiments further relate to determination and / or configuration of a physical layer security policy (e.g., based on the capability information. For example, the physical layer security policy may be indicated to the UE as part of a NAS security mode command procedure between the UE and the AMF. Additionally, or alternatively, the physical layer security policy may be indicated to the UE as part of an AS security mode command procedure between the UE and the RAN.
[0059] In embodiments, the UE 104 and / or RAN 110 (e.g., base station 108) may generate the physical layer key KPHY based on observations on a channel between the UE 104 and RAN 110. Since the UE 104 and RAN 110 can both observe the channel, their observations are correlated. A potential eavesdropper device that attempts to observe the channel and generate the physical layer key is likely to get different observation results and thus not be able to replicate the physical layer key.
[0060] For example, the RAN 110 may transmit a downlink reference signal (e.g., a channel state information –reference signal (CSI-RS) , synchronization signal block (SSB) , and / or another reference signal) in one or more resources, and the UE 104 may perform one or more measurements on the downlink reference signal. The UE 104 may transmit an uplink reference signal (e.g., a sounding reference signal (SRS) and / or another reference signal) in one or more resources, and the RAN 110 may perform one or more measurements on the uplink reference signal. The UE 104 and / or RAN 110 may each generate the physical layer key KPHY based on their respective measurements. In some embodiments, the generation of the physical layer key may further include a correction procedure, e.g., based on capability information of the UE 104 and / or RAN 110. Additionally, or alternatively, the UE 104 and / or RAN 110 may perform a confirmation procedure to confirm that the physical layer keys that they generated match.
[0061] In various embodiments, the UE 104 and / or RAN 110 may derive one or more security keys (also referred to as output keys) based on the physical layer key. For example, the one or more security keys may include one or more of NAS encryption key KNASenc, NAS integrity key KNASint, RRC encryption key KRRCenc, RRC integrity key KRRCint, UP encryption key KUPenc, and / or UP integrity key KUPint. In embodiments, KNASenc and / or KNASint may be generated based on KPHY and KAMF. KRRCenc, KRRCint, KUPenc, and / or KUPint may be generated based on KPHY and a base station key (KBS, which may be KgNB in embodiments in which the base station is a gNB) .
[0062] Various techniques may be used to derive the security key based on the physical layer key in accordance with embodiments herein. In one example, a string prime (S’) may be derived based on string S and the physical layer key KPHY. For example, S’ = f (S, KPHY) , where f is any suitable function. In one example, f is an XOR function, e.g., XOR (S, K’PHY) , where K’PHY is derived from KPHY and has a same number of bits as S (e.g., 16 bits) . The security key may be derived based on a hash function (e.g., HMAC-SHA-256) of S’ and an input key Kin, e.g., Kout = Hash (S’, Kin) . The input key Kin may be, for example, KAMF for a NAS security key, or KBS for an AS (e.g., RRC and / or UP) security key.
[0063] In another example, the input key to the hash function may be based on the KPHY. For example, an input key prime (K’in) may be generated based on KPHY and Kin (e.g., KAMF or KBS) , e.g., K’in = f (Kin, KPHY) . The function, f, may be any suitable function such as an XOR function, e.g., K’in = XOR (Kin, K’PHY) where K’PHY is derived from KPHY and has a same number of bits as Kin (e.g., 256 bits) .
[0064] In another example, the security key may be based on the output of the hash function (e.g., Hash (S, Kin) ) and KPHY, e.g., Kout = f (Hash (Kin, S) , KPHY) . The function, f, may be any suitable function such as an XOR function, e.g., Kout = XOR (Hash (Key, S) , K’PHY) where K’PHY is derived from KPHY and has a same number of bits as the output of the hash function (e.g., 128 or 256 bits) .
[0065] In some embodiments, two or more of the above techniques may be combined to generate the security key. For example, the KPHY may be used more than once in the generation of the security key, e.g., to determine the string input to the hash function, to determine the input key provided to the hash function, and / or combined with the hash output to determine the security key.
[0066] In various embodiments, the UE may use the one or more security keys for NAS communication with the AMF and / or for AS communication (e.g., RRC and / or UP) with the RAN (e.g., base station) .
[0067] Various embodiments further provide techniques for the UE and / or network to provide capability information related to using the physical layer security key for NAS and / or AS communications. FIG. 3 illustrates an example registration procedure 300 (hereinafter “procedure 300” ) in accordance with various embodiments. As shown, aspects of the procedure 300 may be performed by a UE (e.g., UE 104) , RAN (e.g., RAN 110, such as base station 108) , AMF (e.g., AMF 114) , SMF, and / or UDM.
[0068] At 304 of the procedure 300, the UE may send a registration request to the AMF (e.g., via the RAN) . The registration request may include UE capability information related to physical layer security (UE PHYSE capability report) . The UE capability information may indicate the UE’s capability to generate and / or use the physical layer key.
[0069] In some embodiments, the UE capability information related to physical layer key may be included in a UE security capability information element (IE) . An example UE security capability IE 400 is depicted in FIG. 4, which may correspond to Figure 9.11.3.54-1 of 3GPP TS 24.501, V18.7.0. The UE security capability IE 400 may indicate which security algorithms are supported by the UE for NAS security (e.g., in N1 mode) , and which security algorithms are supported for AS security. The UE security capability IE 400 may be a type 4 IE with a minimum length of 4 octets and a maximum length of 10 octets.
[0070] In one example, a single bit may be used to indicate that the UE is capable of generating the physical layer key from the physical layer procedure. In another example, the UE capability information may be indicated in combination with a supported algorithm, e.g., encryption algorithm and / or integrity algorithm. For example, 256-6G-EA0 may indicate that 256-bit key length is used for encryption, while 256-6G-EA0-PHY may indicate that the 256-bit key length is enhanced with the physical layer key for encryption.
[0071] In other embodiments, the UE capability information related to the physical layer key may be indicated separately from the UE security capability IE. For example, the UE capability information may be a single bit to indicate that the UE is capable of generating the physical layer key as discussed above. Alternatively, the UE capability information may include multiple bits to indicate one or more parameters of the physical layer key (e.g., generated key length) that are supported by the UE.
[0072] At 308 of the procedure 300, a security procedure (e.g., authentication) may be performed, e.g., to authenticate the UE. Aspects of the security procedure may be performed by the UE, RAN, AMF, SMF, and / or UDM.
[0073] At 312 of the procedure 300, the AMF may send an initial context setup request to the RAN. The initial context setup request may include a UE capability indication (UE PHYSE capability indication) to indicate to the RAN the UE’s capability regarding generation and / or use of the physical layer key. The UE capability indication may be similar to the UE capability information described above with reference to operation 304.
[0074] While the procedure 300 is shown and described with reference to a registration procedure, a similar procedure may be used to modify a registration. For example, the AMF may send a UE context modification request to the RAN with the UE capability indication.
[0075] At 316 of the procedure 300, the RAN may send an initial context setup response to the AMF. The initial context setup response may include a RAN capability indication (RAN PHYSE capability indication) to indicate the RAN’s capability regarding generation and / or use of the physical layer key. The RAN capability information may be similar to the UE capability information described above.
[0076] In some embodiments, the RAN may send a RAN configuration update message to the AMF to provide the RAN capability information instead of or in addition to the initial context setup response.
[0077] At 320, the procedure 300 may include a NAS security mode command (SMC) procedure. An example NAS security mode command procedure 500 is shown in FIG. 5 and described further below.
[0078] At 324, the procedure 300 may include an AS SMC procedure. An example AS security mode command procedure 600 is shown in FIG. 6 and described further below.
[0079] At 328 of the procedure 300, the AMF may send a registration accept message to the UE.
[0080] FIG. 5 illustrates an example NAS SMC procedure 500 (hereinafter “procedure 500” ) in accordance with various embodiments. Aspects of the procedure 500 may be performed by a UE (e.g., UE 104) and / or AMF (e.g., AMF 114) .
[0081] At 504 of the procedure 500, the AMF may start integrity protection (e.g., for NAS) .
[0082] At 508 of the procedure 500, the AMF may send a NAS security mode command to the UE. The NAS security mode command may indicate a physical layer security policy to be used by the UE and / or AMF for NAS security with a physical layer key. The physical layer security policy may be indicated in an information element.
[0083] The physical layer security policy may include one or more of: a selected physical layer security algorithm; a generated key length; a key refreshing interval; resources for uplink and downlink reference signal transmissions for the generation of the physical layer key; and / or a validity duration of using the physical layer security policy. In embodiments, the AMF may determine the physical layer security policy and / or one or more parameters thereof based on the UE capability information related to the physical layer key.
[0084] In some embodiments, the NAS security mode command may further include the UE security capabilities, and / or a NAS key set identifier (ngKSI) for use by the UE to identify the KAMF. The NAS security mode command message may include a K_AMF_change flag to indicate that a new KAMF is calculated, a flag requesting the complete initial NAS message, and / or an anti-bidding down between architectures (ABBA) parameter.
[0085] At 512 of the procedure 500, the AMF may start uplink deciphering (e.g., after sending the NAS security mode command message. At 516 of the procedure 500, the UE may verify NAS SMC integrity and, if successful, start uplink ciphering, downlink deciphering, and integrity protection. The integrity verification may include checking that the UE security capabilities sent by the AMF match the capabilities stored in the UE to ensure that the capabilities were not modified by an attached, and / or verifying the integrity protection using the indicated NAS integrity algorithm and the NAS integrity key based on the KAMF indicated by the ngKSI (and the KPHY as discussed herein, in some embodiments) . If the integrity is successfully verified, the UE may start NAS integrity protection, uplink ciphering, and / or downlink deciphering with the security context indicated by the ngKSI.
[0086] At 520 of the procedure 500, the UE may send the AMF a NAS security mode complete message. The NAS security mode complete message may include an acknowledgment (ACK) or negative acknowledgment (NACK) of the physical layer security policy (e.g., to confirm whether the physical layer security policy is accepted by the UE) . The NAS security mode complete message may be ciphered and integrity protected (e.g., using respective security keys generated based on the KPHY as discussed herein) .
[0087] At 524 of the procedure 500, the AMF may start downlink ciphering.
[0088] FIG. 6 illustrates an example AS SMC procedure 600 (hereinafter “procedure 600” ) in accordance with various embodiments. Aspects of the procedure 600 may be performed by a UE (e.g., UE 104) and / or base station (e.g., base station 108) .
[0089] At 604 of the procedure 600, the base station may start RRC integrity protection.
[0090] At 608 of the procedure 600, the base station may send an AS security mode command to the UE. The AS security mode command may indicate a physical layer security policy to be used by the UE and / or base station for AS security with a physical layer key.
[0091] The physical layer security policy may be indicated in an information element. The physical layer security policy may include one or more of: a selected physical layer security algorithm; a generated key length; a key refreshing interval; resources for uplink and downlink reference signal transmissions for the generation of the physical layer key; and / or a validity duration of using the physical layer security policy. In embodiments, the physical layer security policy and / or one or more parameters thereof may be determined based on the UE capability information related to the physical layer key. In some embodiments, different physical layer security policies may be indicated for RRC signaling and UP signaling, respectively. The AS security mode command may be integrity protected with the RRC integrity key based on the current KBS.
[0092] At 612 of the procedure 600, the base station may start RRC downlink ciphering. At 616 of the procedure 600, the UE may verify AS SMC integrity and, if successful, start RRC integrity protection and RRC downlink deciphering. For example, the integrity may be verified based on the KBS.
[0093] At 620 of the procedure 600, the UE may send the base station an AS security mode complete message. The AS security mode complete message may include an acknowledgment (ACK) or negative acknowledgment (NACK) of the physical layer security policy (e.g., to confirm whether the physical layer security policy is accepted by the UE) . The AS security mode complete message may be integrity protected with the selected RRC algorithm indicated in the AS security mode command message and the RRC integrity key based on the KBS (e.g., and the KPHY in some embodiments) .
[0094] At 624 of the procedure 600, the UE may start RRC uplink ciphering.
[0095] At 628 of the procedure 600, the base station may start RRC uplink deciphering.
[0096] Various embodiments herein further provide techniques to support provisioning of physical layer security policies in the AMF and / or RAN (e.g., base station) . In some embodiments, the AMF may be configured (e.g., via network management) with one or more lists of algorithms that are allowed for usage. For example, the AMF may be configured with a first list for NAS integrity algorithms and a second list for NAS ciphering algorithms. In embodiments, the algorithms in a respective list may be ordered by priority. The priority may be determined / configurable by the network operator in some embodiments.
[0097] In various embodiments, the configured list may include one or more algorithms that use the physical layer key. The AMF may select an algorithm for use based on UE capability (e.g., in addition to the relative priority of the algorithms) . For example, the AMF may select an algorithm that uses the physical layer key based on the UE supporting the physical layer key.
[0098] In various embodiments, the AMF may select the algorithm to use for NAS security and / or AS security, e.g., according to the NAS SMC procedure such as procedure 500. The AMF may notify the RAN of the selected algorithm. Additionally, or alternatively, the AMF may indicate to the RAN the physical layer security policy to be followed by the RAN. This information may be included in an AMF configuration update message from the AMF to the RAN.
[0099] In some embodiments, the RAN may generate the physical layer key (e.g., in accordance with the selected algorithm) and provide the physical layer key to the AMF (e.g., to enable the AMF to use the physical layer key for NAS communication with the UE) . The interface between the RAN and the AMF may be secure to enable the key to be provided over the interface.
[0100] In some embodiments, the RAN (e.g., base station) may be configured (e.g., via network management) with one or more lists of security algorithms that are allowed for usage. For example, the RAN may be configured with a first list for integrity algorithms and a second list for ciphering algorithms. In embodiments, the algorithms in a respective list may be ordered by priority. The priority may be determined / configurable by the network operator in some embodiments.
[0101] As discussed above, the RAN may receive the UE capability information associated with physical layer security, e.g., as part of establishing AS security context in the RAN. The RAN may select the algorithm to use for communication with the UE that has a highest priority from the configured list and is also supported by the UE. In various embodiments, one or more of the algorithms may use the physical layer key as discussed herein.
[0102] FIG. 7 is an operational flow / algorithmic structure 700 for physical layer security in accordance with some embodiments. The operational flow / algorithmic structure 700 may be implemented by a UE such as, for example, UE 104, UE 1000 (shown in FIG. 10 and discussed further below) , or components thereof; for example, a baseband processor 1004A.
[0103] The operational flow / algorithmic structure 700 may include, at 704, generating a physical layer key (KPHY) . For example, the KPHY may be generated based on one or more measurements on a channel. The one or more measurements may be performed on a reference signal transmitted by the network (e.g., base station) in respective reference signal resources. The UE may also transmit an uplink reference signal on respective uplink resources to enable the network to perform one or more measurements on the channel and generate a corresponding physical layer key based on the one or more measurements.
[0104] The operational flow / algorithmic structure 700 may further include, at 708, deriving a security key based on the KPHY. For example, as discussed herein, deriving the security key may include deriving a string prime (S’) based on a string (S) and the KPHY, and deriving the security key based on a hash function of the string prime and an input key (e.g., a base station key (KBS) or an AMF key (KAMF) ) . In another example, deriving the security key may include deriving a key prime (K’) based on the KPHY and the input key, and deriving the security key based on a hash function of the K’ and a string (S) . In another example, deriving the security key may include performing a hash function of a string (S) and the input key, and deriving the security key based on the KPHY and an output of the hash function.
[0105] The operational flow / algorithmic structure 700 may further include, at 712, communicating with a base station or an AMF using the security key. For example, the security key may be an encryption key or an integrity key. The communication may be, for example, receiving a downlink transmission from and / or transmitting an uplink transmission to an AMF via NAS signaling with the AMF, and / or receiving a downlink transmission from and / or transmitting an uplink transmission to a RAN via AS signaling (e.g., RRC and / or UP signaling) .
[0106] FIG. 8 is another operational flow / algorithmic structure 800 in accordance with some embodiments. The operational flow / algorithmic structure 800 may be performed by a base station such as base station 108, network device 1100 (discussed further below with reference to FIG. 11) , or components thereof, for example, processors 1104A.
[0107] The operational flow / algorithmic structure 800 may include, at 804, generating a physical layer key (KPHY) associated with a UE. For example, the KPHY may be generated based on one or more measurements on a channel. The one or more measurements may be performed on an uplink reference signal transmitted by the UE in respective uplink resources. The network may also transmit a downlink reference signal on respective downlink resources to enable the UE to perform one or more measurements on the channel and generate a corresponding physical layer key based on the one or more measurements.
[0108] The operational flow / algorithmic structure 800 may further include, at 808, deriving a security key based on the KPHY and a base station key (KBS) . The KBS may be KgNB in embodiments in which the base station is a gNB. For example, as discussed herein, deriving the security key may include deriving a string prime (S’) based on a string (S) and the KPHY, and deriving the security key based on a hash function of the string prime and the KBS. In another example, deriving the security key may include deriving a key prime (K’) based on the KPHY and the KBS, and deriving the security key based on a hash function of the K’ and a string (S) . In another example, deriving the security key may include performing a hash function of a string (S) and the KBS, and deriving the security key based on the KPHY and an output of the hash function.
[0109] The operational flow / algorithmic structure 800 may further include, at 812, communicating with the UE using the security key. For example, the communication may be via AS signaling to and / or from the UE, such as RRC signaling and / or UP signaling.
[0110] FIG. 9 is another operational flow / algorithmic structure 900 in accordance with some embodiments. The operational flow / algorithmic structure 900 may be performed by an AMF such as AMF 114, network device 1100 (discussed further below with reference to FIG. 11) , or components thereof, for example, processors 1104A.
[0111] The operational flow / algorithmic structure 900 may include, at 904, receiving a physical layer key (KPHY) associated with a UE. The KPHY may be received from a RAN, such as a base station of the RAN.
[0112] The operational flow / algorithmic structure 900 may further include, at 908, deriving a security key based on the KPHY and an AMF key (KAMF) . For example, as discussed herein, deriving the security key may include deriving a string prime (S’) based on a string (S) and the KPHY, and deriving the security key based on a hash function of the string prime and the KAMF. In another example, deriving the security key may include deriving a key prime (K’) based on the KPHY and the KAMF, and deriving the security key based on a hash function of the K’ and a string (S) . In another example, deriving the security key may include performing a hash function of a string (S) and the KAMF, and deriving the security key based on the KPHY and an output of the hash function.
[0113] The operational flow / algorithmic structure 900 may further include, at 912, communicating with the UE using the security key. The communication may include transmitting a downlink transmission and / or receiving an uplink transmission via NAS signaling.
[0114] FIG. 10 illustrates a UE 1000 in accordance with some embodiments. The UE 1000 may be similar to and substantially interchangeable with UE 104 and / or UE 106.
[0115] The UE 1000 may be any mobile or non-mobile computing device, such as, for example, mobile phones, computers, tablets, industrial wireless sensors (for example, microphones, carbon dioxide sensors, pressure sensors, humidity sensors, thermometers, motion sensors, accelerometers, laser scanners, fluid level sensors, inventory sensors, electric voltage / current meters, or actuators) , video surveillance / monitoring devices (for example, cameras or video cameras) , wearable devices (for example, a smart watch) , or Internet-of-things devices.
[0116] The UE 1000 may include processors 1004, RF interface circuitry 1008, memory / storage 1012, user interface 1016, sensors 1020, driver circuitry 1022, power management integrated circuit (PMIC) 1024, antenna 1026, and battery 1028. The components of the UE 1000 may be implemented as integrated circuits (ICs) , portions thereof, discrete electronic devices, or other modules, logic, hardware, software, firmware, or a combination thereof. The block diagram of FIG. 10 is intended to show a high-level view of some of the components of the UE 1000. However, some of the components shown may be omitted, additional components may be present, and different arrangement of the components shown may occur in other implementations.
[0117] The components of the UE 1000 may be coupled with various other components over one or more interconnects 1032, which may represent any type of interface, input / output, bus (local, system, or expansion) , transmission line, trace, or optical connection that allows various circuit components (on common or different chips or chipsets) to interact with one another.
[0118] The processors 1004 may include processor circuitry such as, for example, baseband processor circuitry (BB) 1004A, central processor unit circuitry (CPU) 1004B, and graphics processor unit circuitry (GPU) 1004C. The processors 1004 may include any type of circuitry or processor circuitry that executes or otherwise operates computer-executable instructions, such as program code, software modules, or functional processes from memory / storage 1012 to cause the UE 1000 to perform delay-adaptive operations as described herein. The processors 1004 may also include interface circuitry 1004D to communicatively couple the processor circuitry with one or more other components of the UE 1000.
[0119] In some embodiments, the baseband processor circuitry 1004A may access a communication protocol stack 1036 in the memory / storage 1012 to communicate over a 3GPP compatible network. In general, the baseband processor circuitry 1004A may access the communication protocol stack 1036 to: perform user plane functions at a PHY layer, MAC layer, RLC layer, PDCP layer, SDAP layer, and PDU layer; and perform control plane functions at a PHY layer, MAC layer, RLC layer, PDCP layer, RRC layer, and a NAS layer. In some embodiments, the PHY layer operations may additionally / alternatively be performed by the components of the RF interface circuitry 1008.
[0120] The baseband processor circuitry 1004A may generate or process baseband signals or waveforms that carry information in 3GPP-compatible networks. In some embodiments, the waveforms for NR may be based on cyclic prefix OFDM (CP-OFDM) in the uplink or downlink, and discrete Fourier transform spread OFDM (DFT-S-OFDM) in the uplink.
[0121] The memory / storage 1012 may include one or more non-transitory, computer-readable media that includes instructions (for example, communication protocol stack 1036) that may be executed by one or more of the processors 1004 to cause the UE 1000 to perform various operations described herein (e.g., associated with generation and / or use of a physical layer key, such as operations of FIG. 7) .
[0122] The memory / storage 1012 includes any type of volatile or non-volatile memory that may be distributed throughout the UE 1000. In some embodiments, some of the memory / storage 1012 may be located on the processors 1004 themselves (for example, memory / storage 1012 may be part of a chipset that corresponds to the baseband processor circuitry 1004A) , while other memory / storage 1012 is external to the processors 1004 but accessible thereto via a memory interface. The memory / storage 1012 may include any suitable volatile or non-volatile memory such as, but not limited to, dynamic random access memory (DRAM) , static random access memory (SRAM) , erasable programmable read only memory (EPROM) , electrically erasable programmable read only memory (EEPROM) , Flash memory, solid-state memory, or any other type of memory device technology.
[0123] The RF interface circuitry 1008 may include transceiver circuitry and a radio frequency front module (RFEM) that allows the UE 1000 to communicate with other devices over a radio access network. The RF interface circuitry 1008 may include various elements arranged in transmit or receive paths. These elements may include, for example, switches, mixers, amplifiers, filters, synthesizer circuitry, and control circuitry.
[0124] In the receive path, the RFEM may receive a radiated signal from an air interface via antenna 1026 and proceed to filter and amplify (with a low-noise amplifier) the signal. The signal may be provided to a receiver of the transceiver that down-converts the RF signal into a baseband signal that is provided to the baseband processor of the processors 1004.
[0125] In the transmit path, the transmitter of the transceiver up-converts the baseband signal received from the baseband processor and provides the RF signal to the RFEM. The RFEM may amplify the RF signal through a power amplifier prior to the signal being radiated across the air interface via the antenna 1026.
[0126] In various embodiments, the RF interface circuitry 1008 may be configured to transmit / receive signals in a manner compatible with NR access technologies.
[0127] The antenna 1026 may include antenna elements to convert electrical signals into radio waves to travel through the air and to convert received radio waves into electrical signals. The antenna elements may be arranged into one or more antenna panels. The antenna 1026 may have antenna panels that are omnidirectional, directional, or a combination thereof to enable beamforming and multiple input, multiple output communications. The antenna 1026 may include microstrip antennas, printed antennas fabricated on the surface of one or more printed circuit boards, patch antennas, or phased array antennas. The antenna 1026 may have one or more panels designed for specific frequency bands including bands in FR1 or FR2.
[0128] The user interface 1016 includes various input / output (I / O) devices designed to enable user interaction with the UE 1000. The user interface 1016 includes input device circuitry and output device circuitry. Input device circuitry includes any physical or virtual means for accepting an input including, inter alia, one or more physical or virtual buttons (for example, a reset button) , a physical keyboard, keypad, mouse, touchpad, touchscreen, microphones, scanner, headset, or the like. The output device circuitry includes any physical or virtual means for showing information or otherwise conveying information, such as sensor readings, actuator position (s) , or other like information. Output device circuitry may include any number or combinations of audio or visual display, including, inter alia, one or more simple visual outputs / indicators (for example, binary status indicators such as light emitting diodes (LEDs) and multi-character visual outputs, or more complex outputs such as display devices or touchscreens (for example, liquid crystal displays (LCDs) , LED displays, quantum dot displays, and projectors) , with the output of characters, graphics, multimedia objects, and the like being generated or produced from the operation of the UE 1000.
[0129] The sensors 1020 may include devices, modules, or subsystems whose purpose is to detect events or changes in their environment and send the information (sensor data) about the detected events to some other device, module, or subsystem. Examples of such sensors include inertia measurement units comprising accelerometers, gyroscopes, or magnetometers; microelectromechanical systems or nanoelectromechanical systems comprising 3-axis accelerometers, 3-axis gyroscopes, or magnetometers; level sensors; flow sensors; temperature sensors (for example, thermistors) ; pressure sensors; barometric pressure sensors; gravimeters; altimeters; image capture devices (for example, cameras or lensless apertures) ; light detection and ranging sensors; proximity sensors (for example, infrared radiation detector and the like) ; depth sensors; ambient light sensors; ultrasonic transceivers; and microphones or other like audio capture devices.
[0130] The driver circuitry 1022 may include software and hardware elements that operate to control particular devices that are embedded in the UE 1000, attached to the UE 1000, or otherwise communicatively coupled with the UE 1000. The driver circuitry 1022 may include individual drivers allowing other components to interact with or control various input / output (I / O) devices that may be present within, or connected to, the UE 1000. For example, driver circuitry 1022 may include a display driver to control and allow access to a display device, a touchscreen driver to control and allow access to a touchscreen interface, sensor drivers to obtain sensor readings of sensors 1020 and control and allow access to sensors 1020, drivers to obtain actuator positions of electro-mechanic components or control and allow access to the electro-mechanic components, a camera driver to control and allow access to an embedded image capture device, audio drivers to control and allow access to one or more audio devices.
[0131] The PMIC 1024 may manage power provided to various components of the UE 1000. In particular, with respect to the processors 1004, the PMIC 1024 may control power-source selection, voltage scaling, battery charging, or DC-to-DC conversion.
[0132] A battery 1028 may power the UE 1000, although in some examples the UE 1000 may be deployed in a fixed location and may have a power supply coupled to an electrical grid. The battery 1028 may be a lithium ion battery, a metal-air battery, such as a zinc-air battery, an aluminum-air battery, a lithium-air battery, and the like. In some implementations, such as in vehicle-based applications, the battery 1028 may be a typical lead-acid automotive battery.
[0133] FIG. 11 illustrates a network device 1100 in accordance with some embodiments. The network device 1100 may be similar to and substantially interchangeable with base station 108 or a device of the core network 112 (e.g., AMF 114) or external data network 120.
[0134] The network device 1100 may include processors 1104, RF interface circuitry 1108 (if implemented as a base station) , core network (CN) interface circuitry 1114, memory / storage circuitry 1112, and antenna structure 1126.
[0135] The components of the network device 1100 may be coupled with various other components over one or more interconnects 1128.
[0136] The processors 1104, RF interface circuitry 1108, memory / storage circuitry 1112 (including communication protocol stack 1110) , antenna structure 1126, and interconnects 1128 may be similar to like-named elements shown and described with respect to FIG. 10.
[0137] The processors 1104 may include processor circuitry such as, for example, baseband processor circuitry (BB) 1104A, central processor unit circuitry (CPU) 1104B, and graphics processor unit circuitry (GPU) 1104C. The processors 1104 may include any type of circuitry or processor circuitry that executes or otherwise operates computer-executable instructions, such as program code, software modules, or functional processes from memory / storage circuitry 1112 to cause the network device 1100 to perform operations described herein (e.g., operations associated with generation and / or use of a physical layer key, such as operations of FIG. 8 and / or FIG. 9) . The processors 1104 may also include interface circuitry 1104D to communicatively couple the processor circuitry with one or more other components of the network device 1100.
[0138] The CN interface circuitry 1114 may provide connectivity to a core network, for example, a 5th Generation Core network (5GC) using a 5GC-compatible network interface protocol such as carrier Ethernet protocols, or some other suitable protocol. Network connectivity may be provided to / from the network device 1100 via a fiber optic or wireless backhaul. The CN interface circuitry 1114 may include one or more dedicated processors or FPGAs to communicate using one or more of the aforementioned protocols. In some implementations, the CN interface circuitry 1114 may include multiple controllers to provide connectivity to other networks using the same or different protocols.
[0139] It is well understood that the use of personally identifiable information should follow privacy policies and practices that are generally recognized as meeting or exceeding industry or governmental requirements for maintaining the privacy of users. In particular, personally identifiable information data should be managed and handled so as to minimize risks of unintentional or unauthorized access or use, and the nature of authorized use should be clearly indicated to users.
[0140] For one or more embodiments, at least one of the components set forth in one or more of the preceding figures may be configured to perform one or more operations, techniques, processes, or methods as set forth in the example section below. For example, the baseband circuitry as described above in connection with one or more of the preceding figures may be configured to operate in accordance with one or more of the examples set forth below. For another example, circuitry associated with a UE, base station, network element, etc. as described above in connection with one or more of the preceding figures may be configured to operate in accordance with one or more of the examples set forth below in the example section.
[0141] In the following sections, further exemplary embodiments are provided.
[0142] Example 1 may include method comprising: generating a physical layer key (KPHY) based on one or more measurements on a channel; deriving a security key based on the KPHY; and communicating with a base station or an access and mobility management function (AMF) using the security key.
[0143] Example 2 may include the method of example 1 or some other example herein, wherein the security key is an encryption key or an integrity key.
[0144] Example 3 may include the method of example 1 or some other example herein, wherein the communicating is via non-access stratum (NAS) signaling, radio resource control (RRC) signaling, or user plane signaling.
[0145] Example 4 may include the method of example 1 or some other example herein, wherein deriving the security key includes: deriving a string prime (S’) based on a string (S) and the KPHY; and deriving the security key based on a hash function of the string prime and a base station key (KBS) or an AMF key (KAMF) .
[0146] Example 5 may include the method of example 1 or some other example herein, wherein deriving the security key includes: deriving a key prime (K’) based on the KPHY and a base station key (KBS) or an AMF key (KAMF) ; and deriving the security key based on a hash function of the K’ and a string (S) .
[0147] Example 6 may include the method of example 1 or some other example herein, wherein deriving the security key includes: performing a hash function of a string (S) and a base station key (KBS) or an AMF key (KAMF) ; and deriving the security key based on the KPHY and an output of the hash function.
[0148] Example 7 may include the method of example 1 or some other example herein, further comprising generating a registration request for transmission to the AMF, wherein the registration request indicates a user equipment (UE) capability to generate the KPHY.
[0149] Example 8 may include the method of example 7 or some other example herein, wherein the indication of the UE capability also indicates an encryption algorithm or an integrity algorithm that is supported.
[0150] Example 9 may include the method of example 7 or some other example herein, wherein the indication of the UE capability further indicates a key length that is supported.
[0151] Example 10 may include the method of example 1 or some other example herein, further comprising decoding a non-access stratum (NAS) security mode command from the AMF, wherein the NAS security mode command indicates a physical layer security policy, wherein the indicated physical layer security policy includes one or more of: a physical layer security algorithm; a key length of the KPHY; a key refreshing interval; resources for an uplink reference signal and a downlink reference signal for generation of the KPHY; or a validity duration of the physical layer security policy.
[0152] Example 11 may include the method of example 1 or some other example herein, further comprising decoding an access stratum (AS) security mode command from the base station, wherein the AS security mode command indicates a physical layer security policy, wherein the physical layer security policy includes one or more of: a physical layer security algorithm; a key length of the KPHY; a key refreshing interval; resources for an uplink reference signal and a downlink reference signal for generation of the KPHY; or a validity duration of the physical layer security policy.
[0153] Example 12 may include a method comprising: generating a physical layer key (KPHY) based on one or more measurements on an uplink reference signal transmitted by a user equipment (UE) ; deriving a security key based on the KPHY and a base station key (KBS) ; and communicating with the UE using the security key.
[0154] Example 13 may include the method of example 12 or some other example herein, wherein the security key is an encryption key or an integrity key.
[0155] Example 14 may include the method of example 12 or some other example herein, wherein the communicating is via radio resource control (RRC) signaling or user plane signaling.
[0156] Example 15 may include the method of example 12 or some other example herein, wherein deriving the security key includes: deriving a string prime (S’) based on a string (S) and the KPHY; and deriving the security key based on a hash function of the string prime and the KBS.
[0157] Example 16 may include the method of example 12 or some other example herein, wherein deriving the security key includes: deriving a key prime (K’) based on the KPHY and the KBS; and deriving the security key based on a hash function of the K’ and a string (S) .
[0158] Example 17 may include the method of example 12 or some other example herein, wherein deriving the security key includes: performing a hash function of a string (S) and the KBS; and deriving the security key based on the KPHY and an output of the hash function.
[0159] Example 18 may include the method of example 12 or some other example herein, further comprising: receiving, from an access and mobility management function (AMF) , an indication of a capability of the UE to generate the KPHY; and encoding, for transmission to the AMF, an indication of a capability of a network to generate the KPHY.
[0160] Example 19 may include the method of example 12 or some other example herein, further comprising providing the KPHY to an access and mobility management function (AMF) .
[0161] Example 20 may include the method of example 12 or some other example herein, further comprising encoding an access stratum (AS) security mode command for transmission to the UE, wherein the AS security mode command indicates a physical layer security policy, wherein the physical layer security policy includes one or more of: a physical layer security algorithm; a key length of the KPHY; a key refreshing interval; resources for an uplink reference signal and a downlink reference signal for generation of the KPHY; or a validity duration of the physical layer security policy.
[0162] Example 21 may include a method comprising: receiving, from a base station, a physical layer key (KPHY) associated with a user equipment (UE) ; deriving a security key based on the KPHY and an access and mobility management (AMF) key (KAMF) ; and communicating with the UE via non-access stratum (NAS) signaling using the security key.
[0163] Example 22 may include the method of example 21 or some other example herein, wherein deriving the security key includes: deriving a string prime (S’) based on a string (S) and the KPHY, and deriving the security key based on a hash function of the string prime and the KAMF; deriving a key prime (K’) based on the KPHY and the KAMF, and deriving the security key based on a hash function of the K’ and a string (S) ; or performing a hash function of a string (S) and the KAMF, and deriving the security key based on the KPHY and an output of the hash function.
[0164] Example 23 may include the method of example 21 or some other example herein, further comprising: receiving, from the UE, a registration request that indicates a capability of the UE to generate the KPHY; and encoding, for transmission to a radio access network (RAN) , an initial context setup request or a context modification request that indicates the capability of the UE to generate the KPHY.
[0165] Example 24 may include the method of example 23 or some other example herein, wherein the capability is a first capability, and wherein the method further comprises receiving, from the RAN, an initial context setup response message or a RAN configuration update message that indicates a second capability of the RAN to generate the KPHY.
[0166] Example 25 may include the method of example 24 or some other example herein, further comprising: determining a physical layer security policy based on the first and second capabilities; and informing the UE and the RAN of the determined physical layer security policy; wherein the physical layer security policy includes one or more of: a physical layer security algorithm; a key length of the KPHY; a key refreshing interval; resources for an uplink reference signal and a downlink reference signal for generation of the KPHY; or a validity duration of the physical layer security policy.
[0167] Another example may include an apparatus comprising means to perform one or more elements of a method described in or related to any of examples 1–25, or any other method or process described herein.
[0168] Another example may include one or more non-transitory computer-readable media comprising instructions to cause an electronic device, upon execution of the instructions by one or more processors of the electronic device, to perform one or more elements of a method described in or related to any of examples 1–25, or any other method or process described herein.
[0169] Another example may include an apparatus comprising logic, modules, or circuitry to perform one or more elements of a method described in or related to any of examples 1–25, or any other method or process described herein.
[0170] Another example may include a method, technique, or process as described in or related to any of examples 1–25, or portions or parts thereof.
[0171] Another example may include an apparatus comprising: one or more processors and one or more computer-readable media comprising instructions that, when executed by the one or more processors, cause the one or more processors to perform the method, techniques, or process as described in or related to any of examples 1–25, or portions thereof.
[0172] Another example may include a signal as described in or related to any of examples 1–25, or portions or parts thereof.
[0173] Another example may include a datagram, information element, packet, frame, segment, PDU, or message as described in or related to any of examples 1–25, or portions or parts thereof, or otherwise described in the present disclosure.
[0174] Another example may include a signal encoded with data as described in or related to any of examples 1–25, or portions or parts thereof, or otherwise described in the present disclosure.
[0175] Another example may include a signal encoded with a datagram, IE, packet, frame, segment, PDU, or message as described in or related to any of examples 1–25, or portions or parts thereof, or otherwise described in the present disclosure.
[0176] Another example may include an electromagnetic signal carrying computer-readable instructions, wherein execution of the computer-readable instructions by one or more processors is to cause the one or more processors to perform the method, techniques, or process as described in or related to any of examples 1–25, or portions thereof.
[0177] Another example may include a computer program comprising instructions, wherein execution of the program by a processing element is to cause the processing element to carry out the method, techniques, or process as described in or related to any of examples 1–25, or portions thereof.
[0178] Another example may include a signal in a wireless network as shown and described herein.
[0179] Another example may include a method of communicating in a wireless network as shown and described herein.
[0180] Another example may include a system for providing wireless communication as shown and described herein.
[0181] Another example may include a device for providing wireless communication as shown and described herein.
[0182] Any of the above-described examples may be combined with any other example (or combination of examples) , unless explicitly stated otherwise. The foregoing description of one or more implementations provides illustration and description, but is not intended to be exhaustive or to limit the scope of embodiments to the precise form disclosed. Modifications and variations are possible in light of the above teachings or may be acquired from practice of various embodiments.
[0183] Although the embodiments above have been described in considerable detail, numerous variations and modifications will become apparent to those skilled in the art once the above disclosure is fully appreciated. It is intended that the following claims be interpreted to embrace all such variations and modifications.
Claims
A method comprising:generating a physical layer key (KPHY) based on one or more measurements on a channel;deriving a security key based on the KPHY; andcommunicating with a base station or an access and mobility management function (AMF) using the security key.The method of claim 1, wherein the security key is an encryption key or an integrity key.The method of claim 1, wherein the communicating is via non-access stratum (NAS) signaling, radio resource control (RRC) signaling, or user plane signaling.The method of claim 1, wherein deriving the security key includes:deriving a string prime (S’) based on a string (S) and the KPHY; andderiving the security key based on a hash function of the string prime and a base station key (KBS) or an AMF key (KAMF) .The method of claim 1, wherein deriving the security key includes:deriving a key prime (K’) based on the KPHY and a base station key (KBS) or an AMF key (KAMF) ; andderiving the security key based on a hash function of the K’ and a string (S) .The method of claim 1, wherein deriving the security key includes:performing a hash function of a string (S) and a base station key (KBS) or an AMF key (KAMF) ; andderiving the security key based on the KPHY and an output of the hash function.The method of claim 1, further comprising generating a registration request for transmission to the AMF, wherein the registration request indicates a user equipment (UE) capability to generate the KPHY.The method of claim 7, wherein the indication of the UE capability also indicates an encryption algorithm or an integrity algorithm that is supported.The method of claim 7, wherein the indication of the UE capability further indicates a key length that is supported.The method of claim 1, further comprising decoding a non-access stratum (NAS) security mode command from the AMF, wherein the NAS security mode command indicates a physical layer security policy, wherein the indicated physical layer security policy includes one or more of:a physical layer security algorithm;a key length of the KPHY;a key refreshing interval;resources for an uplink reference signal and a downlink reference signal for generation of the KPHY; ora validity duration of the physical layer security policy.The method of claim 1, further comprising decoding an access stratum (AS) security mode command from the base station, wherein the AS security mode command indicates a physical layer security policy, wherein the physical layer security policy includes one or more of:a physical layer security algorithm;a key length of the KPHY;a key refreshing interval;resources for an uplink reference signal and a downlink reference signal for generation of the KPHY; ora validity duration of the physical layer security policy.A method comprising:generating a physical layer key (KPHY) based on one or more measurements on an uplink reference signal transmitted by a user equipment (UE) ;deriving a security key based on the KPHY and a base station key (KBS) ; andcommunicating with the UE using the security key.The method of claim 12, wherein the security key is an encryption key or an integrity key.The method of claim 12, wherein the communicating is via radio resource control (RRC) signaling or user plane signaling.The method of claim 12, wherein deriving the security key includes:deriving a string prime (S’) based on a string (S) and the KPHY; andderiving the security key based on a hash function of the string prime and the KBS.The method of claim 12, wherein deriving the security key includes:deriving a key prime (K’) based on the KPHY and the KBS; andderiving the security key based on a hash function of the K’ and a string (S) .The method of claim 12, wherein deriving the security key includes:performing a hash function of a string (S) and the KBS; andderiving the security key based on the KPHY and an output of the hash function.The method of claim 12, further comprising:receiving, from an access and mobility management function (AMF) , an indication of a capability of the UE to generate the KPHY; andencoding, for transmission to the AMF, an indication of a capability of a network to generate the KPHY.The method of claim 12, further comprising providing the KPHY to an access and mobility management function (AMF) .The method of claim 12, further comprising encoding an access stratum (AS) security mode command for transmission to the UE, wherein the AS security mode command indicates a physical layer security policy, wherein the physical layer security policy includes one or more of:a physical layer security algorithm;a key length of the KPHY;a key refreshing interval;resources for an uplink reference signal and a downlink reference signal for generation of the KPHY; ora validity duration of the physical layer security policy.A method comprising:receiving, from a base station, a physical layer key (KPHY) associated with a user equipment (UE) ;deriving a security key based on the KPHY and an access and mobility management (AMF) key (KAMF) ; andcommunicating with the UE via non-access stratum (NAS) signaling using the security key.The method of claim 21, wherein deriving the security key includes:deriving a string prime (S’) based on a string (S) and the KPHY, and deriving the security key based on a hash function of the string prime and the KAMF;deriving a key prime (K’) based on the KPHY and the KAMF, and deriving the security key based on a hash function of the K’ and a string (S) ; orperforming a hash function of a string (S) and the KAMF, and deriving the security key based on the KPHY and an output of the hash function.The method of claim 21, further comprising:receiving, from the UE, a registration request that indicates a capability of the UE to generate the KPHY; andencoding, for transmission to a radio access network (RAN) , an initial context setup request or a context modification request that indicates the capability of the UE to generate the KPHY.The method of claim 23, wherein the capability is a first capability, and wherein the method further comprises receiving, from the RAN, an initial context setup response message or a RAN configuration update message that indicates a second capability of the RAN to generate the KPHY.The method of claim 24, further comprising:determining a physical layer security policy based on the first and second capabilities; andinforming the UE and the RAN of the determined physical layer security policy;wherein the physical layer security policy includes one or more of:a physical layer security algorithm;a key length of the KPHY;a key refreshing interval;resources for an uplink reference signal and a downlink reference signal for generation of the KPHY; ora validity duration of the physical layer security policy.
Citation Information
Patent Citations
Encryption negotiation method and related equipment
CN116915389A
User equipment, electronic equipment, wireless communication method and storage medium
CN116980900A
Communication key security isolation method and system based on hidden physical layer signature
CN118264413A
Physical layer (PHY) security for passive internet of things (IOT) devices
WO2023225929A1
Secure communication method and apparatus, terminal device, and network device
WO2023283789A1