Terminal, wireless communication system, and wireless communication method

By implementing encryption and integrity mechanisms at the MAC layer, the wireless communication system protects MAC layer information, addressing the lack of confidentiality protection and enhancing security.

WO2026069530A1PCT designated stage Publication Date: 2026-04-02NTT DOCOMO INC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-26
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing wireless communication systems lack mechanisms to protect the confidentiality of information handled at the Media Access Control (MAC) layer, which is lower than the Packet Data Convergence Protocol (PDCP) layer, where protection is assumed.

Method used

Implementing a mechanism to protect the confidentiality of information at the MAC layer by using encryption and integrity algorithms, including the generation of keystreams and MAC-Is, and specifying which parts of the MAC PDU are protected, with options for generating these using different parameters than those used at the PDCP layer.

Benefits of technology

Enhances the security of wireless communication by ensuring the confidentiality of MAC layer information, thereby preventing unauthorized access to critical messages.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024034444_02042026_PF_FP_ABST
    Figure JP2024034444_02042026_PF_FP_ABST
Patent Text Reader

Abstract

This terminal is provided with a communication unit for communicating with a base station, and a control unit configured on the assumption that confidentiality is to be protected for at least some information of a message handled in a second layer lower than a first layer for which protection is assumed in the communication.
Need to check novelty before this filing date? Find Prior Art

Description

Terminal, wireless communication system, and wireless communication method

[0001] The present disclosure relates to a terminal, a wireless communication system, and a wireless communication method that support lower-layer security.

[0002] The 3rd Generation Partnership Project (3GPP: registered trademark) is standardizing the 5th generation mobile communication system (also called 5G, New Radio (NR), or Next Generation (NG)). Furthermore, 3GPP is also promoting the standardization of the next generation, called Beyond 5G, 5G Evolution, or 6G.

[0003] In 3GPP, confidentiality protection (e.g., RRC (Radio Resource Control) confidentiality protection) is performed at the PDCP (Packet Data Convergence Protocol) layer (e.g., Non-Patent Document 1).

[0004] 3GPP TS33.501 V18.6.0, July 2024

[0005] On the other hand, in the MAC (Media Access Control) layer, which is lower than the PDCP layer, there may be cases where information to be protected is handled.

[0006] The inventors focused on the above cases and found a need to clarify a mechanism for protecting the confidentiality of information handled in the second layer (e.g., MAC layer), which is lower than the first layer (e.g., PDCP layer) for which protection is assumed.

[0007] Therefore, the present disclosure has been made to solve the above-described problems, and an object thereof is to provide a terminal, a wireless communication system, and a wireless communication method that can appropriately protect the confidentiality of information handled in the second layer (e.g., MAC layer), which is lower than the first layer (e.g., PDCP layer) for which protection is assumed.

[0008] The disclosed aspect is a terminal comprising a communication unit that performs communication with a base station, and a control unit that assumes the protection of the confidentiality of at least some of the information of a message handled at a second layer lower than the first layer which is assumed to be protected in the communication.

[0009] The disclosed aspect is a wireless communication system comprising a terminal and a base station, wherein the terminal comprises a communication unit that performs communication with the base station and a control unit that assumes the protection of the confidentiality of at least some of the information of a message handled at a second layer lower than the first layer which is assumed to be protected in the communication.

[0010] The disclosed aspect is a wireless communication method comprising the steps of: performing communication with a base station; and ensuring the confidentiality of at least some of the information of a message handled at a second layer lower than the first layer which is assumed to be protected in the communication.

[0011] Figure 1 is an overall schematic diagram of the wireless communication system 10. Figure 2 is a diagram showing the frequency range used in the wireless communication system 10. Figure 3 is a diagram showing an example configuration of wireless frames, subframes, and slots used in the wireless communication system 10. Figure 4 is a functional block configuration diagram of the UE200. Figure 5 is a functional block configuration diagram of the gNB100. Figure 6 is a diagram for explaining the background technology. Figure 7 is a diagram for explaining the background technology. Figure 8 is a diagram for explaining the background technology. Figure 9 is a diagram for explaining the background technology. Figure 10 is a diagram for explaining the background technology. Figure 11 is a diagram for explaining operation example 1. Figure 12 is a diagram for explaining operation example 2. Figure 13 is a diagram for explaining operation example 2. Figure 14 is a diagram for explaining operation example 2. Figure 15 is a diagram showing an example of the hardware configuration of the gNB100 and UE200. Figure 16 is a diagram showing an example configuration of the vehicle 2001.

[0012] The embodiments will be described below with reference to the drawings. Note that identical or similar reference numerals are used to denote the same functions and components, and their descriptions will be omitted as appropriate.

[0013] (1) Overall schematic diagram 1 of the wireless communication system is an overall schematic diagram of the wireless communication system 10 according to the embodiment. The wireless communication system 10 is a wireless communication system in accordance with 5G New Radio (NR) and includes a Next Generation-Radio Access Network 20 (hereinafter referred to as NG-RAN20) and a terminal 200 (hereinafter referred to as UE (User Equipment) 200).

[0014] The wireless communication system 10 may also be a wireless communication system that conforms to a method called Beyond 5G, 5G Evolution, or 6G.

[0015] NG-RAN20 includes base station 100 (hereinafter referred to as gNB100). The specific configuration of the wireless communication system 10, including the number of gNB100 and UE200, is not limited to the example shown in Figure 1.

[0016] NG-RAN20 actually includes multiple NG-RAN Nodes, specifically gNBs (or ng-eNBs), and is connected to a 5G-compliant core network (5GC, not shown). Note that NG-RAN20 and 5GC may also be simply referred to as the "network".

[0017] The gNB100 is a 5G-compliant radio base station that performs 5G-compliant wireless communication with the UE200. The gNB100 and UE200 can support Massive MIMO (Multiple-Input Multiple-Output), which generates a more directional beamband by controlling radio signals transmitted from multiple antenna elements; carrier aggregation (CA), which uses multiple component carriers (CCs) bundled together; and dual connectivity (DC), which enables simultaneous communication with two or more transport blocks between the UE and each of the two NG-RAN Nodes.

[0018] Furthermore, the wireless communication system 10 supports multiple frequency ranges (FR). Figure 2 shows the frequency ranges used in the wireless communication system 10.

[0019] Firstly, the wireless communication system 10 may support multiple frequency ranges (FRs) as shown in Figure 2. For example, the wireless communication system 10 may support FR1, FR2-1, and FR2-2. The frequency bands for each FR are as follows:

[0020] FR1: 410 MHz to 7.125 GHz FR2-1: 24.25 GHz to 52.6 GHz FR2-2: Over 52.6 GHz to 71 GHz In FR1, 15, 30, or 60 kHz Sub-Carrier Spacing (SCS) may be used, and a bandwidth (BW) of 5 to 100 MHz may be used. FR2 is a higher frequency than FR1, and 60 kHz or 120 kHz (240 kHz may be included) SCS may be used, and a bandwidth (BW) of 50 to 400 MHz may be used.

[0021] Note that SCS may also be interpreted as numerology. Numerology is defined in 3GPP TS38.300 and corresponds to a single subcarrier interval in the frequency domain.

[0022] Furthermore, the wireless communication system 10 may also support higher frequency bands than the FR2 frequency band. Specifically, the wireless communication system 10 may support frequency bands exceeding 52.6 GHz up to 71 GHz or 114.25 GHz.

[0023] Secondly, the wireless communication system 10 may correspond to the wireless frames, subframes, and slots shown in Figure 3.

[0024] As shown in Figure 3, one slot consists of 14 symbols, and the larger (wider) the SCS, the shorter the symbol duration (and slot duration). In addition to 15kHz, 30kHz, 60kHz, 120kHz, and 240kHz, 480kHz, 960kHz, etc., may also be used for the SCS.

[0025] Furthermore, the number of symbols constituting one slot does not necessarily have to be 14 (for example, 28 symbols, 56 symbols). In addition, the number of slots per subframe may differ depending on the SCS.

[0026] The time direction (t) shown in Figure 3 may also be called the time domain, symbol period, or symbol time. The frequency direction may also be called the frequency domain, resource block, subcarrier, or bandwidth part (BWP).

[0027] (2) Functional Block Configuration of the Wireless Communication System Next, the functional block configuration of the wireless communication system 10 will be described.

[0028] First, we will describe the functional block configuration of UE200.

[0029] Figure 4 is a functional block diagram of the UE200. As shown in Figure 4, the UE200 comprises a wireless signal transmission / reception unit 210, an amplifier unit 220, a modulation / demodulation unit 230, a control signal / reference signal processing unit 240, an encoding / decoding unit 250, a data transmission / reception unit 260, and a control unit 270.

[0030] The wireless signal transceiver unit 210 transmits and receives wireless signals in accordance with NR. The wireless signal transceiver unit 210 supports Massive MIMO, CA which uses multiple CCs bundled together, and DC which communicates simultaneously between the UE and each of the two NG-RAN Nodes.

[0031] In this embodiment, the wireless signal transmission / reception unit 210 may constitute a communication unit that communicates with the gNB100.

[0032] The amplifier section 220 consists of components such as a PA (Power Amplifier) ​​and an LNA (Low Noise Amplifier). The amplifier section 220 amplifies the signal output from the modulation / demodulation section 230 to a predetermined power level. The amplifier section 220 also amplifies the RF signal output from the wireless signal transmission / reception section 210.

[0033] The modulation / demodulation unit 230 performs data modulation / demodulation, transmit power setting, and resource block allocation for each predetermined communication destination (gNB100 or other gNB). The modulation / demodulation unit 230 may apply Cyclic Prefix-Orthogonal Frequency Division Multiplexing (CP-OFDM) / Discrete Fourier Transform - Spread (DFT-S-OFDM). Furthermore, DFT-S-OFDM may be used not only for the uplink (UL) but also for the downlink (DL).

[0034] The control signal / reference signal processing unit 240 performs processing related to various control signals transmitted and received by the UE200, and processing related to various reference signals transmitted and received by the UE200.

[0035] Specifically, the control signal / reference signal processing unit 240 receives various control signals transmitted from the gNB100 via a predetermined control channel, such as control signals for the radio resource control layer (RRC). The control signal / reference signal processing unit 240 also transmits various control signals to the gNB100 via a predetermined control channel.

[0036] The control signal / reference signal processing unit 240 performs processing using reference signals (RS) such as the Demodulation Reference Signal (DMRS) and the Phase Tracking Reference Signal (PTRS).

[0037] DMRS is a terminal-specific, known reference signal (pilot signal) between the base station and the terminal used to estimate the fading channel used for data demodulation. PTRS is a terminal-specific reference signal intended to estimate phase noise, which is a problem in the high-frequency band.

[0038] In addition to DMRS and PTRS, the reference signals may also include Channel State Information-Reference Signal (CSI-RS), Sounding Reference Signal (SRS), and Positioning Reference Signal (PRS) for location information.

[0039] Furthermore, channels include control channels and data channels. Control channels include PDCCH (Physical Downlink Control Channel), PUCCH (Physical Uplink Control Channel), RACH (Random Access Channel), Downlink Control Information (DCI) including Random Access Radio Network Temporary Identifier (RA-RNTI), and Physical Broadcast Channel (PBCH), among others.

[0040] Furthermore, data channels include PDSCH (Physical Downlink Shared Channel) and PUSCH (Physical Uplink Shared Channel), among others. "Data" refers to data transmitted through a data channel. A data channel may also be interpreted as a shared channel.

[0041] Here, the control signal / reference signal processing unit 240 may receive downlink control information (DCI). The DCI includes fields that store existing fields such as DCI Formats, Carrier indicator (CI), BWP indicator, FDRA (Frequency Domain Resource Assignment), TDRA (Time Domain Resource Assignment), MCS (Modulation and Coding Scheme), HPN (HARQ Process Number), NDI (New Data Indicator), and RV (Redundancy Version).

[0042] The value stored in the DCI Format field is an information element that specifies the DCI format. The value stored in the CI field is an information element that specifies the CC to which the DCI applies. The value stored in the BWP indicator field is an information element that specifies the BWP to which the DCI applies. The BWP that can be specified by the BWP indicator is set by an information element (BandwidthPart-Config) included in the RRC message. The value stored in the FDRA field is an information element that specifies the frequency domain resource to which the DCI applies. The frequency domain resource is identified by the value stored in the FDRA field and an information element (RA Type) included in the RRC message. The value stored in the TDRA field is an information element that specifies the time domain resource to which the DCI applies. The time domain resource is identified by the value stored in the TDRA field and an information element (pdsch-TimeDomainAllocationList, push-TimeDomainAllocationList) included in the RRC message. The time domain resource may also be identified by the value stored in the TDRA field and the default table. The value stored in the MCS field is an information element that specifies the MCS to which the DCI applies. The MCS is identified by the value stored in MCS and the MCS table. The MCS table may be specified by the RRC message or identified by RNTI scrambling. The value stored in the HPN field is an information element that specifies the HARQ Process to which DCI is applied. The value stored in NDI is an information element that determines whether the data to which DCI is applied is initial transmission data. The value stored in the RV field is an information element that specifies the redundancy of the data to which DCI is applied.

[0043] The encoding / decoding unit 250 performs data splitting / concatenation and channel coding / decoding for each predetermined communication destination (gNB100 or other gNB).

[0044] Specifically, the encoding / decoding unit 250 divides the data output from the data transmission / reception unit 260 into a predetermined size, and performs channel coding on the divided data. Further, the encoding / decoding unit 250 decodes the data output from the modulation / demodulation unit 230, and concatenates the decoded data.

[0045] The data transmission / reception unit 260 performs transmission and reception of Protocol Data Unit (PDU) and Service Data Unit (SDU). Specifically, the data transmission / reception unit 260 performs assembly / disassembly of PDU / SDU in a plurality of layers (such as a Media Access Control layer (MAC), a Radio Link Control layer (RLC), and a Packet Data Convergence Protocol layer (PDCP)). Further, the data transmission / reception unit 260 performs error correction and retransmission control of data based on Hybrid Automatic Repeat Request (HARQ).

[0046] The control unit 270 controls each functional block constituting the UE 200. In an embodiment, the control unit 270 may constitute a control unit that assumes confidentiality protection of at least part of the information of a message handled in a second layer lower than a first layer for which protection is assumed in communication with the gNB 100.

[0047] Here, the first layer may be a Packet Data Convergence Protocol (PDCP) layer. The second layer may be a Media Access Control (MAC) layer. Messages handled in the MAC layer for which confidentiality protection is assumed may include DL messages (for example, DL-SCH), and may also include UL messages (for example, UL-SCH).

[0048] Second, the functional block configuration of the gNB 100 will be described.

[0049] FIG. 5 is a functional block configuration diagram of the gNB 100. As shown in FIG. 5, the gNB 100 includes a reception unit 110, a transmission unit 120, and a control unit 130.

[0050] The receiver 110 receives various signals from the UE200. The receiver 110 may also receive the UL signal via PUCCH or PUSCH.

[0051] The transmitter 120 transmits various signals to the UE200. The transmitter 120 may also transmit DL signals via PDCCH or PDSCH.

[0052] In this embodiment, the receiving unit 110 and the transmitting unit 120 may constitute a communication unit that communicates with the UE200.

[0053] The control unit 130 controls the gNB100. In this embodiment, the control unit 130 may be configured to protect the confidentiality of at least some of the information in the message handled at a second layer lower than the first layer which is assumed to be protected in communication with the UE200.

[0054] (3) Background Technology Below, we will explain the confidentiality protection (RRC confidentiality protection) related to the background technology. RRC confidentiality protection is carried out at the PDCP layer.

[0055] Firstly, regarding the encryption algorithm, as shown in Figure 6, the sender generates ciphertext (CIPHERTEXT BLOCK) by adding the keystream (KEYSTREAM BLOCK) to the plaintext (PLAINTEXT BLOCK) (XOR operation). The receiver generates plaintext (PLAINTEXT BLOCK) by adding the ciphertext (CIPHERTEXT BLOCK) and the keystream (KEYSTREAM BLOCK) (XOR operation).

[0056] Here, the keystream is generated based on KEY, COUNT, BEARER, DIRECTION, and LENGTH. KEY is the encryption key (e.g., 128 bits), COUNT is a value described later (e.g., 32 bits), BEARER is a value that identifies the bearer (e.g., 5 bits), DIRECTION is a value that indicates the direction of transmission, such as UL / DL (e.g., 1 bit), and LENGTH is a value that indicates the length of the keystream.

[0057] While not particularly limited, the cryptographic algorithms used may be those described in 3GPP TS33.501 §D.2.1.1 “Inputs and outputs”.

[0058] Secondly, regarding the integrity algorithm, as shown in Figure 7, the sender generates a MAC-I (Integrity) or NAS (Non-Access-Stratum)-MAC and sends the MAC-I or NAS-MAC to the receiver. The receiver generates an XMAC-I or XNAS-MAC and compares the received MAC-I (or NAS-MAC) with the generated XMAC-I (or XNAS-MAC).

[0059] Here, the keystream is generated based on KEY, MESSAGE, COUNT, BEARER, and DIRECTION. KEY is the integrity key (e.g., 128 bits), MESSAGE is the message itself, COUNT is the value of a counter that counts the keystream (e.g., 32 bits), BEARER is a value that identifies the bearer (e.g., 5 bits), and DIRECTION is a value that indicates the direction of transmission, such as UL / DL (e.g., 1 bit).

[0060] While not particularly limited, the completeness algorithm may be one of those described in 3GPP TS33.501 §D.3.1.1 “Inputs and outputs”.

[0061] Thirdly, MAC-PDUs will be described. As shown in Figure 8, a DL MAC-PDU consists of one or more MAC subPDUs. A MAC subPDU may include a fixed-sized MAC CE, a variable-sized MAC CE, a MAC SDU (Service Data Unit), or padding. A UL MAC-PDU consists of one or more MAC subPDUs. A MAC subPDU may include a MAC SDU, a fixed-sized MAC CE, a variable-sized MAC CE, or padding. For the configuration of MAC-PDUs, the configurations described in 3GPP TS38.321 §6.1.2 “MAC PDU (DL-SCH and UL-SCH except transparent MAC and Random Access Response)” may be used.

[0062] Fourth, the PDCP Data PDU of the PDCP layer will be described. The PDCP Data PDU may include U (User)-Plane Data, C (Control)-Plane Data, and the MAC-I described above. For example, the PDCP Data PDU may have the configuration shown in Figure 9. Regarding the configuration of the PDCP Data PDU, the configuration described in 3GPP TS38.323 §6.2.2.1 "Data PDU for SRBs" may be used, the configuration described in 3GPP TS38.323 §6.2.2.2 "Data PDU for DRBs and MRBs with 12 bits PDCP SN" may be used, and the configuration described in 3GPP TS38.323 §6.2.2.3 "Data PDU for DRBs and MRBs with 18 bits PDCP SN" may be used.

[0063] Fifth, the value of COUNT mentioned above will be explained. As shown in Figure 10, the value of COUNT consists of HFN (Hyper Frame Number) and PDCP SN (Sequence Number). The value of COUNT may be the value specified in 3GPP TS38.323 §6.3.5 “COUNT”.

[0064] (4) Issues As mentioned above, RRC is performed at the PDCP layer. On the other hand, there are cases where confidential information is handled at the MAC layer, which is lower than the PDCP layer. For example, a DL MAC CE could be the LTM (Lower Layer Triggered Mobility) cell switch command MAC CE. However, since the LTM cell switch command is used for handover from the source cell to the target cell, it carries the risk of handing over the UE200 to a fake base station, so it is desirable to protect the confidentiality of the LTM cell switch command.

[0065] The inventors, focusing on the cases described above, recognized the need to clarify a mechanism for protecting confidential information handled at a second layer (e.g., the MAC layer) that is lower than the first layer (e.g., the PDCP layer) where protection is envisioned.

[0066] (5) Examples of Operation In order to solve the above-mentioned problems, the following examples of operation may be specified. Specifically, the UE200 or gNB100 is intended to protect the confidentiality of at least some of the information in messages handled at the MAC layer, which is lower than the PDCP layer that is intended to be protected in communication between the UE200 and gNB100. The following examples of operation are possible.

[0067] (5.1) Operation Example 1 Operation Example 1 describes a mechanism for clarifying which parts of a MAC PDU are protected from confidentiality and which parts are not. Specifically, messages (MAC PDUs) handled at the second layer include a field indicating whether or not the information handled at the MAC layer is protected from confidentiality. The following options are possible for Operation Example 1.

[0068] In Option 1-1, as shown in Figure 11, the fields may be included in the header of each MAC subPDU that constitutes a second layer data unit (MAC PDU).

[0069] In such cases, a protected MAC subPDU may be assigned a MAC-I. An unprotected MAC subPDU may not be assigned a MAC-I, or it may be assigned a MAC-I configured with padding.

[0070] For protected MAC subPDUs, the ciphertext (CIPHERTEXT BLOCK) is generated by adding the keystream (KEYSTREAM BLOCK) to the plaintext (PLAINTEXT BLOCK) using an XOR operation. The XOR operation can also be interpreted as bit-per-bit binary addition. For unprotected MAC subPDUs, the plaintext (PLAINTEXT BLOCK) may be transmitted as is.

[0071] In Option 1-1, it should be noted that MAC-I differs from the background technology in that it is included in MAC PDU rather than PDCP Data PDU.

[0072] In option 1-2, as shown in Figure 11, the fields may be included in the header of the subdata unit (MAC subPDU) for each control element (MAC CE) contained within the MAC subPDU.

[0073] In such cases, a MAC subPDU containing a protected MAC CE may be assigned a MAC-I. A MAC subPDU containing an unprotected MAC CE may not be assigned a MAC-I, or it may be assigned a MAC-I consisting of padding.

[0074] For MAC subPDUs containing protected MAC CEs, the ciphertext (CIPHERTEXT BLOCK) is generated by adding the keystream (KEYSTREAM BLOCK) to the plaintext (PLAINTEXT BLOCK) using an XOR operation. The XOR operation can also be interpreted as bit-per-bit binary addition. For MAC subPDUs containing unprotected MAC CEs, the plaintext (PLAINTEXT BLOCK) may be transmitted as is.

[0075] In Option 1-2, it should be noted that MAC-I differs from the background technology in that it is included in MAC PDU rather than PDCP Data PDU.

[0076] In options 1-3, as shown in Figure 11, the field may be included in the header of each group of MAC subPDUs in the group header of the MAC subPDUs. A group of MAC subPDUs consists of one or more MAC subPDUs. The field may be included in the header of the first MAC subPDU in the group of MAC subPDUs.

[0077] In such cases, a group of protected MAC subPDUs may be assigned a MAC-I as a single unit. Unprotected MAC subPDUs do not need to be assigned a MAC-I, or they may be assigned a MAC-I consisting of padding.

[0078] For protected MAC subPDU groups, ciphertext (CIPHERTEXT BLOCK) is generated by adding the keystream (KEYSTREAM BLOCK) to the plaintext (PLAINTEXT BLOCK) using an XOR operation. The XOR operation can also be interpreted as bit-per-bit binary addition. Unprotected MAC subPDUs may be transmitted in plaintext (PLAINTEXT BLOCK).

[0079] In options 1-3, it should be noted that MAC-I differs from the background technology in that it is included in MAC PDU rather than PDCP Data PDU.

[0080] (5.2) Operation Example 2 Operation Example 2 describes a method for protecting the confidentiality of at least a portion of the MAC PDU. Specifically, in the MAC layer, parameters such as COUNT and BEARER do not exist as parameters used in encryption as described in Figure 7. Similarly, in the MAC layer, parameters such as BEARER and COUNT do not exist as parameters used in integrity as described in Figure 8. Therefore, confidentiality cannot be protected in the MAC layer using the exact same methods as in the PDCP layer. Against this backdrop, the UE200 or gNB100 generates information (keystream and MAC-I) used to protect the confidentiality of at least a portion of the message information handled in the second layer (MAC layer) in a different way than the first layer (PDCP layer). The following options are possible for Operation Example 2.

[0081] In Option 2-1, the UE200 or gNB100 may reuse a mechanism similar to that of the PDCP layer. That is, alternative values ​​are used for BEARER and COUNT. The following options are possible for Option 2-1.

[0082] Option 2-1-1 describes the BEARER. The following assumes a case where there are Bearer #1 to Bearer #3 in the PDCP layer (Logical channel). The following options are possible for Option 2-1-1.

[0083] In option 2-1-1-1, as shown in Figure 12, the MAC layer may treat Bearer#1 to Bearer#3 as a single Bearer (Default bearer).

[0084] In option 2-1-1-2, as shown in Figure 12, the MAC layer may divide the MAC entry into subMAC entries corresponding to Bearer#1 to Bearer#3. In such a case, a different keystream may be generated for each subMAC entry. Similarly, a different MAC-I may be generated for each subMAC entry.

[0085] In option 2-1-1-3, as shown in Figure 12, the MAC layer may introduce a new concept of Bearer (Bearer#1 to Bearer#3) corresponding to each of Bearer#1 to Bearer#3. In such a case, a different keystream may be generated for each Bearer. Similarly, a different MAC-I may be generated for each Bearer.

[0086] Option 2-1-2 will explain COUNT. The following options are possible for Option 2-1-2.

[0087] In option 2-1-2-1, COUNT may be assigned to each MAC subPDU. COUNT may also be generated based on the Sequence Number (SN) assigned to each MAC subPDU.

[0088] In option 2-1-2-2, COUNT may be assigned per MAC PDU. COUNT may be generated based on the SN assigned per MAC PDU.

[0089] In option 2-1-2-3, a default value (e.g., 0 or 1) may be used for COUNT.

[0090] While not particularly limited, option 2-1-2-1 may be combined with option 2-1-1-2 or option 2-1-1-3 as described above, and option 2-1-2-2 may be combined with option 2-1-1-1 as described above. However, various combinations are possible between each option of option 2-1-1 and each option of option 2-1-2.

[0091] In Option 2-2, the UE200 or gNB100 may use a different mechanism than the PDCP layer. For example, BEARER and COUNT may not be used in the generation of the keystream and MAC-I. That is, the keystream may be generated based on KEY, DIRECTION, and LENGTH. The MAC-I may be generated based on KEY, MESSAGE, and DIRECTION.

[0092] In such cases, a security algorithm for the MAC layer may be configured in UE200. For example, the security algorithm for the MAC layer may be an algorithm that generates keystreams and MAC-I without using BEARER and COUNT. The security algorithm for the MAC layer may be interpreted as a new security algorithm in order to distinguish it from existing security algorithms (see Figures 6 and 7).

[0093] For example, as shown in Figure 13, in step S10, the gNB may send a SecurityModeCommand to the UE, and in step S11, the UE may send a SecurityModeComplete to the gNB. SecurityModeCommand is an example of a message that sets the security algorithm for the MAC layer. SecurityModeCommand may be interpreted as an RRC message or as a higher-layer parameter.

[0094] For example, as shown in Figure 14, in step S20, the gNB may send RRCReconfiguration to the UE, and in step S21, the UE may send RRCReconfigurationComplete to the gNB. RRCReconfiguration is an example of a message that configures the security algorithm for the MAC layer. RRCReconfiguration may be interpreted as an RRC message or as a higher-layer parameter.

[0095] (5.3) Other Operation Example 1 may be applied to UL MAC PDU or DL ​​MAC PDU. Operation Example 2 may be applied to UL MAC PDU or DL ​​MAC PDU.

[0096] (6) Operation and Effects In the embodiment, the UE200 (or gNB100) is intended to protect the confidentiality of at least some of the information in messages handled at the MAC layer, which is lower than the PDCP layer that is intended to be protected in communication between the UE200 and the gNB100. With this configuration, the security of communication can be enhanced by focusing on cases in which the confidentiality of messages handled at the MAC layer should be protected.

[0097] In some embodiments, the MAC PDU may include a field indicating whether or not to protect the confidentiality of the information handled at the MAC layer (Operation Example 1). With such a configuration, it is clarified which parts of the MAC PDU should be protected, and the confidentiality of messages handled at the MAC layer can be properly protected.

[0098] In this embodiment, the UE200 (or gNB100) may generate information (keystream and MAC-I) used to protect the confidentiality of at least some of the information in the messages handled by the MAC layer in a manner different from that of the PDCP layer (Operation Example 2). With such a configuration, the method of protecting confidentiality in the MAC layer is clarified, and the confidentiality of messages handled by the MAC layer can be appropriately protected.

[0099] (7) Other Embodiments Although the contents of the present invention have been described above in accordance with the embodiments, it will be obvious to those skilled in the art that the present invention is not limited to these descriptions and that various modifications and improvements are possible.

[0100] Although not specifically mentioned in the disclosure above, the choice of which of Operation Example 1 to Operation Example 2 to use (hereinafter, which mode to use) may be set by a higher-layer parameter. The choice of which of each option in Operation Example 1 to Operation Example 2 to use (hereinafter, which mode to use) may be set by a higher-layer parameter. Which mode to support may be reported by UE200 as UE capability(ies). Which mode to use may be predefined in the wireless communication system 20. Which mode to use may be set by a higher-layer parameter and reported by UE200 as UE capability(ies).

[0101] Although not specifically mentioned in the disclosure above, the following UE capability(ies) may be defined. UE capability(ies) may be defined for each UE200, for each FR, or for each FC. UE capability(ies) may be included in the signals reported from the UE200 to the gNB100, or in the signals (RRC configuration) set from the NB100 to the UE200.

[0102] Although not specifically mentioned in the disclosure above, UE capability(ies) may include information indicating whether or not it has the ability to protect confidentiality at the MAC layer.

[0103] Although not specifically mentioned in the disclosure above, UE capability(ies) may include information indicating whether or not it supports any of options 1-1 through 1-3.

[0104] Although not specifically mentioned in the disclosure above, UE capability(ies) may include information indicating whether or not it supports option 2-1 to option 2-2.

[0105] Although not specifically mentioned in the disclosure above, UE capability(ies) may include information indicating whether or not it supports any of options 2-1-1-1 through 2-1-1-3.

[0106] Although not specifically mentioned in the disclosure above, UE capability(ies) may include information indicating whether or not it supports any of options 2-1-2-1 through 2-1-2-3.

[0107] In the disclosures above, configure, activate, update, indicate, enable, specify, and select may be interpreted as interchangeable. Similarly, link, associate, correspond, and map may be interpreted as interchangeable, and allocate, assign, monitor, and map may also be interpreted as interchangeable.

[0108] Furthermore, "specific," "dedicated," "UE specific," and "UE individual" may be interpreted interchangeably. Similarly, "common," "shared," "group-common," "UE common," and "UE shared" may be interpreted interchangeably.

[0109] The block diagrams (Figures 4 and 5) used in the description of the embodiments above show functional units. These functional blocks (components) are realized by any combination of at least one of hardware and software. Furthermore, the method of realizing each functional block is not particularly limited. That is, each functional block may be realized using one device that is physically or logically coupled, or it may be realized using two or more physically or logically separated devices that are directly or indirectly connected (for example, using wired or wireless connections). A functional block may be realized by combining the above one device or the above multiple devices with software.

[0110] Functions include, but are not limited to, judgment, decision, determination, calculation, calculation, processing, derivation, investigation, exploration, confirmation, reception, transmission, output, access, resolution, selection, selection, establishment, comparison, assumption, expectation, assumption, broadcasting, notifying, communicating, forwarding, configuring, reconfiguring, allocating (mapping), and assigning. For example, a functional block (configuration part) that enables transmission is called a transmitting unit or transmitter. In any case, as mentioned above, the method of implementation is not particularly limited.

[0111] Furthermore, the gNB100 and UE200 (the device) described above may function as a computer that processes the wireless communication method of this disclosure. Figure 15 shows an example of the hardware configuration of the device. As shown in Figure 15, the device may be configured as a computer device including a processor 1001, memory 1002, storage 1003, communication device 1004, input device 1005, output device 1006, and bus 1007.

[0112] In the following explanation, the term "device" can be replaced with "circuit," "device," "unit," etc. The hardware configuration of the device may include one or more of the devices shown in the diagram, or it may be configured to omit some of the devices.

[0113] Each functional block of the device (see Figures 4 and 5) is implemented by any hardware element of the computer device, or a combination of such hardware elements.

[0114] Furthermore, each function in the device is realized by loading predetermined software (programs) onto hardware such as the processor 1001 and memory 1002, which allows the processor 1001 to perform calculations, control communication by the communication device 1004, and control at least one of the reading and writing of data in the memory 1002 and storage 1003.

[0115] The processor 1001 controls the entire computer, for example, by running an operating system. The processor 1001 may consist of a central processing unit (CPU) that includes interfaces with peripheral devices, control units, arithmetic units, registers, and so on.

[0116] Furthermore, the processor 1001 reads programs (program code), software modules, data, etc., from at least one of the storage 1003 and the communication device 1004 into the memory 1002 and executes various processes accordingly. The program used is one that causes the computer to execute at least a part of the operations described in the above embodiment. Moreover, the above-mentioned various processes may be executed by one processor 1001, or by two or more processors 1001 simultaneously or sequentially. The processor 1001 may be implemented by one or more chips. The program may also be transmitted from a network via a telecommunications line.

[0117] Memory 1002 is a computer-readable recording medium and may consist of at least one of the following: Read Only Memory (ROM), Erasable Programmable ROM (EPROM), Electrically Erasable Programmable ROM (EEPROM), Random Access Memory (RAM), etc. Memory 1002 may also be called a register, cache, main memory, etc. Memory 1002 can store a program (program code), software module, etc., that can execute a method according to one embodiment of this disclosure.

[0118] Storage 1003 is a computer-readable recording medium and may consist of at least one of the following: an optical disc such as a Compact Disc ROM (CD-ROM), a hard disk drive, a flexible disk, a magneto-optical disk (e.g., Compact Disc, Digital Multipurpose Disc, Blu-ray® Disc), a smart card, flash memory (e.g., a card, stick, key drive), a floppy® disk, a magnetic strip, etc. Storage 1003 may also be called an auxiliary storage device. The recording medium described above may also be, for example, a database, server, or other suitable medium including at least one of memory 1002 and storage 1003.

[0119] The communication device 1004 is hardware (transceiver / receiver device) for communicating between computers via at least one of a wired network and a wireless network, and is also referred to as a network device, network controller, network card, communication module, etc.

[0120] The communication device 1004 may be configured to include, for example, a high-frequency switch, a duplexer, a filter, a frequency synthesizer, etc., in order to implement at least one of frequency division duplex (FDD) and time division duplex (TDD).

[0121] The input device 1005 is an input device that accepts input from an external source (e.g., a keyboard, mouse, microphone, switch, button, sensor, etc.). The output device 1006 is an output device that outputs to an external source (e.g., a display, speaker, LED lamp, etc.). The input device 1005 and the output device 1006 may be configured as an integrated unit (e.g., a touch panel).

[0122] Furthermore, each device, such as the processor 1001 and the memory 1002, is connected by a bus 1007 for communicating information. The bus 1007 may be configured using a single bus, or different buses may be configured for each device.

[0123] Furthermore, the device may include hardware such as a microprocessor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a programmable logic device (PLD), and a field programmable gate array (FPGA), and some or all of the functional blocks may be implemented by such hardware. For example, processor 1001 may be implemented using at least one of these hardware components.

[0124] Furthermore, notification of information is not limited to the embodiments / models described herein and may be carried out by other means. For example, notification of information may be carried out by physical layer signaling (e.g., Downlink Control Information (DCI), Uplink Control Information (UCI)), upper layer signaling (e.g., RRC signaling, Medium Access Control (MAC) signaling, broadcast information (Master Information Block (MIB), System Information Block (SIB))), other signals, or combinations thereof. RRC signaling may also be called RRC messages, and may be, for example, RRC Connection Setup messages, RRC Connection Reconfiguration messages, etc.

[0125] Each aspect / embodiment described herein may be applied to at least one of the following: Long Term Evolution (LTE), LTE-Advanced (LTE-A), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 6th generation mobile communication system (6G), xth generation mobile communication system (xG) (where x is, for example, an integer or decimal), Future Radio Access (FRA), New Radio (NR), W-CDMA®, GSM®, CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi®), IEEE 802.16 (WiMAX®), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth®, and other appropriate systems, as well as next-generation systems extended based thereon. Furthermore, multiple systems may be applied in combination (for example, a combination of at least one of LTE and LTE-A with 5G).

[0126] The processing procedures, sequences, flowcharts, etc., of each aspect / embodiment described herein may be reordered, provided they are consistent with each other. For example, the methods described herein present various step elements in an exemplary order and are not limited to that specific order.

[0127] The specific operations described in this disclosure as being performed by a base station may, in some cases, be performed by its upper node. In a network consisting of one or more network nodes having a base station, it is clear that various operations performed for communication with a terminal can be performed by the base station and at least one other network node (for example, an MME or S-GW, but not limited to these). Although the above example illustrates a case where there is one other network node besides the base station, it may also be a combination of multiple other network nodes (for example, an MME and an S-GW).

[0128] Information and signals (such as data) can be output from a higher layer (or lower layer) to a lower layer (or higher layer). Input and output may occur via multiple network nodes.

[0129] The input and output information may be stored in a specific location (e.g., memory) or managed using a management table. The input and output information may be overwritten, updated, or appended to. Output information may be deleted. Input information may be transmitted to other devices.

[0130] The determination may be made by a value represented by one bit (0 or 1), by a boolean value (true or false), or by a numerical comparison (for example, a comparison with a predetermined value).

[0131] Each aspect / embodiment described herein may be used individually, in combination, or switched between as needed during implementation. Furthermore, notification of specific information (e.g., notification that "X is") is not limited to explicit notification, but may also be implicit (e.g., by not providing such notification).

[0132] Software should be broadly interpreted to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, execution threads, procedures, functions, and so on, whether they are called software, firmware, middleware, microcode, hardware description languages, or by any other name.

[0133] Furthermore, software, instructions, information, etc., may be transmitted and received via a transmission medium. For example, if software is transmitted from a website, server, or other remote source using at least one of wired technology (such as coaxial cable, fiber optic cable, twisted pair, or Digital Subscriber Line (DSL)) and wireless technology (such as infrared or microwave), then at least one of these wired and wireless technologies is included in the definition of a transmission medium.

[0134] The information, signals, etc. described in this disclosure may be represented using any of the various different technologies. For example, the data, instructions, commands, information, signals, bits, symbols, chips, etc. that may be referred to throughout the above description may be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, optical fields or photons, or any combination thereof.

[0135] In addition, terms used in this disclosure and terms necessary for understanding this disclosure may be replaced with terms having the same or similar meanings. For example, at least one of the channel and symbol may be a signal (signaling). Also, a signal may be a message. Furthermore, a component carrier (CC) may be called a carrier frequency, cell, frequency carrier, etc.

[0136] The terms “system” and “network” as used in this disclosure are interchangeable.

[0137] Furthermore, the information, parameters, etc., described in this disclosure may be expressed using absolute values, relative values ​​from a given value, or other corresponding information. For example, wireless resources may be indicated by an index.

[0138] The names used for the parameters described above are not restrictive in any way. Furthermore, the formulas and other expressions using these parameters may differ from those expressly disclosed in this disclosure. Since various channels (e.g., PUCCH, PDCCH, etc.) and information elements can be identified by any suitable name, the various names assigned to these various channels and information elements are not restrictive in any way.

[0139] In this disclosure, terms such as "Base Station (BS)," "wireless base station," "fixed station," "NodeB," "eNodeB (eNB)," "gNodeB (gNB)," "access point," "transmission point," "reception point," "transmission / reception point," "cell," "sector," "cell group," "carrier," and "component carrier" may be used interchangeably. Base stations may also be referred to by terms such as macrocell, small cell, femtocell, and picocell.

[0140] A base station can house one or more (e.g., three) cells (also called sectors). If a base station houses multiple cells, the entire coverage area of ​​the base station can be divided into multiple smaller areas, each of which can also be provided with communication services by a base station subsystem (e.g., a small indoor base station (Remote Radio Head: RRH)).

[0141] The terms "cell" or "sector" refer to a portion or all of the coverage area of ​​at least one of the base stations and base station subsystems that provide communication services in this coverage.

[0142] In this disclosure, the transmission of information by a base station to a terminal may be interpreted as the base station instructing the terminal to perform control or operation based on the information.

[0143] In this disclosure, terms such as "Mobile Station (MS)," "user terminal," "User Equipment (UE)," and "terminal" may be used interchangeably.

[0144] A mobile station may also be referred to by those skilled in the art as a subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or several other appropriate terms.

[0145] At least one of the base station and the mobile station may be called a transmitting device, a receiving device, a communication device, etc. At least one of the base station and the mobile station may be a device mounted on a mobile body, the mobile body itself, etc. The mobile body may be a vehicle (e.g., a car, an airplane, etc.), an unmanned mobile body (e.g., a drone, an autonomous vehicle, etc.), or a robot (manned or unmanned). At least one of the base station and the mobile station may be a device that does not necessarily move during communication operation. For example, at least one of the base station and the mobile station may be an Internet of Things (IoT) device such as a sensor.

[0146] Furthermore, the term "base station" in this disclosure may be interpreted as "mobile station" (user terminal, hereinafter the same). For example, each aspect / embodiment of this disclosure may be applied to a configuration in which communication between a base station and a mobile station is replaced with communication between multiple mobile stations (which may be called, for example, Device-to-Device (D2D), Vehicle-to-Everything (V2X), etc.). In this case, the mobile station may have the functions that a base station has. Also, terms such as "uplink" and "downlink" may be interpreted as terms corresponding to terminal-to-terminal communication (for example, "side"). For example, uplink channel, downlink channel, etc. may be interpreted as side channel.

[0147] Similarly, the term "mobile station" in this disclosure may be interpreted as "base station." In this case, the base station may be configured to have the functions that a mobile station has.

[0148] A wireless frame may consist of one or more frames in the time domain. Each of these frames in the time domain may be called a subframe.

[0149] A subframe may further consist of one or more slots in the time domain. A subframe may have a fixed time length (e.g., 1 ms) that is independent of numerology.

[0150] Numerology may be communication parameters applied to at least one of the transmission and reception of a signal or channel. Numerology may include, for example, at least one of the following: subcarrier spacing (SCS), bandwidth, symbol length, cyclic prefix length, transmission time interval (TTI), number of symbols per TTI, radio frame configuration, specific filtering processes performed by the transceiver in the frequency domain, and specific windowing processes performed by the transceiver in the time domain.

[0151] A slot may consist of one or more symbols in the time domain (such as Orthogonal Frequency Division Multiplexing (OFDM) symbols or Single Carrier Frequency Division Multiple Access (SC-FDMA) symbols). A slot may also be a time unit based on neurology.

[0152] A slot may include multiple mini-slots. Each mini-slot may consist of one or more symbols in the time domain. Mini-slots may also be called sub-slots. Mini-slots may consist of fewer symbols than a slot. A PDSCH (or PUSCH) transmitted in a time unit larger than a mini-slot may be called a PDSCH (or PUSCH) mapping type A. A PDSCH (or PUSCH) transmitted using a mini-slot may be called a PDSCH (or PUSCH) mapping type B.

[0153] Wireless frames, subframes, slots, minislots, and symbols all represent units of time when transmitting a signal. Different names may be used for each of these terms.

[0154] For example, one subframe may be called a transmission time interval (TTI), multiple consecutive subframes may be called a TTI, or one slot or one minislot may be called a TTI. In other words, at least one of a subframe and a TTI may be a subframe (1 ms) in existing LTE, a period shorter than 1 ms (e.g., 1-13 symbols), or a period longer than 1 ms. Note that the unit representing the TTI may be called a slot, minislot, etc., instead of a subframe.

[0155] Here, TTI refers to, for example, the smallest unit of time for scheduling in wireless communication. For example, in an LTE system, the base station schedules each user terminal to allocate wireless resources (such as the frequency bandwidth and transmission power available to each user terminal) in TTI units. However, the definition of TTI is not limited to this.

[0156] TTI may be a transmission time unit for channel-encoded data packets (transport blocks), code blocks, code words, etc., or it may be a processing unit for scheduling, link adaptation, etc. Note that when a TTI is given, the actual time interval (e.g., number of symbols) in which the transport block, code block, code word, etc. are mapped may be shorter than the given TTI.

[0157] Furthermore, if one slot or one mini-slot is referred to as TTI, then one or more TTIs (i.e., one or more slots or one or more mini-slots) may constitute the minimum time unit of scheduling. In addition, the number of slots (number of mini-slots) that constitute the minimum time unit of scheduling may be controlled.

[0158] A TTI with a time length of 1ms may also be called a normal TTI, long TTI, normal subframe, long subframe, slot, etc. A TTI shorter than a normal TTI may also be called a shortened TTI, short TTI, partial or fractional TTI, shortened subframe, short subframe, mini slot, sub slot, slot, etc.

[0159] Furthermore, long TTIs (e.g., normal TTIs, subframes, etc.) may be interpreted as TTIs with a time length exceeding 1 ms, and short TTIs (e.g., shortened TTIs, etc.) may be interpreted as TTIs with a TTI length less than that of a long TTI but 1 ms or more.

[0160] A resource block (RB) is a resource allocation unit in the time domain and frequency domain, and in the frequency domain, it may contain one or more consecutive subcarriers. The number of subcarriers in an RB may be the same regardless of the neurology, for example, 12. The number of subcarriers in an RB may be determined based on the neurology.

[0161] Furthermore, the time domain of RB may contain one or more symbols and may be the length of one slot, one minislot, one subframe, or one TTI. One TTI, one subframe, etc., may each consist of one or more resource blocks.

[0162] One or more RBs may also be called Physical RBs (PRBs), Sub-Carrier Groups (SCGs), Resource Element Groups (REGs), PRB pairs, RB pairs, etc.

[0163] Furthermore, a resource block may consist of one or more resource elements (REs). For example, one RE may be a radio resource area comprising one subcarrier and one symbol.

[0164] A Bandwidth Part (BWP), also known as a partial bandwidth, may represent a subset of consecutive common resource blocks (RBs) for a given neurology in a given carrier. Here, the common RBs may be identified by an index of the RBs relative to the carrier's common reference point. PRBs may be defined and numbered within a given BWP.

[0165] A BWP may include BWPs for UL (UL BWP) and BWPs for DL ​​(DL BWP). One or more BWPs may be configured within a single carrier for a UE.

[0166] At least one of the configured BWPs may be active, and the UE does not need to assume that it will send or receive a given signal / channel outside of the active BWP. In this disclosure, terms such as "cell" and "carrier" may be read as "BWP".

[0167] The structures described above, such as wireless frames, subframes, slots, minislots, and symbols, are merely illustrative. For example, the number of subframes included in a wireless frame, the number of slots per subframe or wireless frame, the number of minislots included in a slot, the number of symbols and RBs included in a slot or minislot, the number of subcarriers included in an RB, and the number of symbols, symbol length, and cyclic prefix (CP) length within a TTI can be varied in various ways.

[0168] The terms “connected,” “coupled,” or any variation thereof, mean any direct or indirect connection or coupling between two or more elements, and may include the presence of one or more intermediate elements between two elements that are “connected” or “coupled” with each other. The coupling or connection between elements may be physical, logical, or a combination thereof. For example, “connection” may be read as “access.” As used in this disclosure, two elements may be considered to be “connected” or “coupled” with each other using at least one of one or more wires, cables, and printed electrical connections, and, in some non-limiting and non-exclusive examples, electromagnetic energy having wavelengths in the radio frequency domain, microwave domain, and optical (both visible and invisible) domain.

[0169] The reference signal can also be abbreviated as Reference Signal (RS), and may be called a pilot depending on the applicable standard.

[0170] In this disclosure, the phrase "based on" does not mean "based solely on" unless otherwise specified. In other words, the phrase "based on" means both "based solely on" and "based at least on."

[0171] In the configuration of each of the above devices, "means" may be replaced with "part," "circuit," "device," etc.

[0172] Any reference to elements using designations such as “First,” “Second,” etc., as used in this disclosure does not generally limit the quantity or order of those elements. These designations may be used in this disclosure as a convenient way to distinguish between two or more elements. Accordingly, references to the First and Second elements do not imply that only two elements may be employed therein, or that the First element must precede the Second element in any way.

[0173] Where the terms “include,” “including,” and variations thereof are used in this disclosure, these terms are intended to be inclusive, as is the term “comprising.” Furthermore, the term “or” as used in this disclosure is not intended to mean exclusive OR.

[0174] In this disclosure, if articles are added through translation, such as a, an, and the in English, this disclosure may include the fact that the noun following these articles is plural.

[0175] As used in this disclosure, the terms “determining” and “determining” may encompass a wide variety of actions. “Determining” may include, for example, judging, calculating, computing, processing, deriving, investigating, looking up, searching, or inquiring (e.g., searching in a table, database, or other data structure), or ascertaining. “Determining” may also include receiving (e.g., receiving information), transmitting (e.g., sending information), inputting, outputting, or accessing (e.g., accessing data in memory). Furthermore, "judgment" and "decision" can include considering something as having been "judged" or "decided" after resolving, selecting, choosing, establishing, comparing, etc. In other words, "judgment" and "decision" can include considering something as having been "judged" or "decided" after some action. Also, "judgment (decision)" can be reinterpreted as "assuming," "expecting," or "considering."

[0176] In this disclosure, the term "A and B are different" may mean "A and B are different from each other." The term may also mean "A and B are each different from C." Terms such as "separate" and "combine" may be interpreted similarly to "different."

[0177] Figure 16 shows an example of the configuration of vehicle 2001. As shown in Figure 16, vehicle 2001 includes a drive unit 2002, a steering unit 2003, an accelerator pedal 2004, a brake pedal 2005, a shift lever 2006, left and right front wheels 2007, left and right rear wheels 2008, an axle 2009, an electronic control unit 2010, various sensors 2021 to 2029, an information service unit 2012, and a communication module 2013.

[0178] The drive unit 2002 is composed of, for example, an engine, a motor, or a hybrid of an engine and a motor.

[0179] The steering unit 2003 includes at least a steering wheel (also called a handle) and is configured to steer at least one of the front wheels and the rear wheels based on the operation of the steering wheel, which is operated by the user.

[0180] The electronic control unit 2010 consists of a microprocessor 2031, memory (ROM, RAM) 2032, and communication ports (IO ports) 2033. Signals from various sensors 2021 to 2027 installed in the vehicle are input to the electronic control unit 2010. The electronic control unit 2010 may also be called an ECU (Electronic Control Unit).

[0181] Signals from various sensors 2021 to 2028 include current signals from the current sensor 2021 that senses motor current, front and rear wheel rotation speed signals obtained by the rotation speed sensor 2022, front and rear wheel air pressure signals obtained by the air pressure sensor 2023, vehicle speed signals obtained by the vehicle speed sensor 2024, acceleration signals obtained by the acceleration sensor 2025, accelerator pedal depression signals obtained by the accelerator pedal sensor 2029, brake pedal depression signals obtained by the brake pedal sensor 2026, shift lever operation signals obtained by the shift lever sensor 2027, and detection signals obtained by the object detection sensor 2028 for detecting obstacles, vehicles, pedestrians, etc.

[0182] The Information Services Unit 2012 consists of various devices for providing various types of information, such as driving information, traffic information, and entertainment information, including a car navigation system, audio system, speakers, television, and radio, and one or more ECUs that control these devices. The Information Services Unit 2012 uses information acquired from external devices via a communication module 2013, etc., to provide various multimedia information and multimedia services to the occupants of Vehicle 1.

[0183] The driver assistance system unit 2030 consists of various devices that provide functions to prevent accidents or reduce the driver's workload, such as millimeter-wave radar, LiDAR (Light Detection and Ranging), cameras, positioning locators (e.g., GNSS), map information (e.g., high-definition (HD) maps, autonomous vehicle (AV) maps), gyro systems (e.g., IMU (Inertial Measurement Unit), INS (Inertial Navigation System)), AI (Artificial Intelligence) chips, and AI processors, as well as one or more ECUs that control these devices. The driver assistance system unit 2030 also sends and receives various information via the communication module 2013 to realize driver assistance functions or autonomous driving functions.

[0184] The communication module 2013 can communicate with the microprocessor 2031 and components of the vehicle 1 via its communication port. For example, the communication module 2013 sends and receives data via the communication port 2033 between the drive unit 2002, steering unit 2003, accelerator pedal 2004, brake pedal 2005, shift lever 2006, left and right front wheels 2007, left and right rear wheels 2008, axle 2009, the microprocessor 2031 and memory (ROM, RAM) 2032 in the electronic control unit 2010, and sensors 2021 to 2028 provided in the vehicle 2001.

[0185] The communication module 2013 is a communication device that can be controlled by the microprocessor 2031 of the electronic control unit 2010 and can communicate with external devices. For example, it can send and receive various types of information to and from external devices via wireless communication. The communication module 2013 may be located either inside or outside the electronic control unit 2010. The external device may be, for example, a base station or a mobile station.

[0186] The communication module 2013 transmits current signals from current sensors input to the electronic control unit 2010 to an external device via wireless communication. The communication module 2013 also transmits, via wireless communication, other signals input to the electronic control unit 2010, including front and rear wheel rotation speed signals obtained by the rotation speed sensor 2022, front and rear wheel air pressure signals obtained by the air pressure sensor 2023, vehicle speed signals obtained by the vehicle speed sensor 2024, acceleration signals obtained by the acceleration sensor 2025, accelerator pedal depression signals obtained by the accelerator pedal sensor 2029, brake pedal depression signals obtained by the brake pedal sensor 2026, shift lever operation signals obtained by the shift lever sensor 2027, and detection signals obtained by the object detection sensor 2028 for detecting obstacles, vehicles, pedestrians, etc.

[0187] The communication module 2013 receives various information (traffic information, signal information, distance information, etc.) transmitted from external devices and displays it on the information service unit 2012 installed in the vehicle. The communication module 2013 also stores the various information received from external devices in memory 2032, which is available to the microprocessor 2031. Based on the information stored in memory 2032, the microprocessor 2031 may control the drive unit 2002, steering unit 2003, accelerator pedal 2004, brake pedal 2005, shift lever 2006, left and right front wheels 2007, left and right rear wheels 2008, axles 2009, sensors 2021 to 2028, etc., installed in the vehicle 2001.

[0188] Although the present disclosure has been described in detail above, it will be clear to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented in modified and altered forms without departing from the intent and scope of the present disclosure as defined by the claims. Therefore, the descriptions in the present disclosure are illustrative and not intended to be restrictive in any way.

[0189] (Note) The disclosure described above may also be expressed as follows:

[0190] The first feature is a terminal comprising a communication unit that performs communication with a base station, and a control unit that assumes the protection of the confidentiality of at least some of the information in the message handled at a second layer lower than the first layer which is assumed to be protected in the communication.

[0191] The second feature is that, in the first feature, the message handled by the second layer is a terminal that includes a field indicating whether or not to protect the confidentiality of the information handled by the second layer.

[0192] The third feature is that, in the second feature, the field is a terminal that is included in the header of each subdata unit constituting the data unit of the second layer, in the header of each subdata unit for each control element included in the subdata unit, or in the header of each group of subdata units for each group of subdata units.

[0193] The fourth feature is that, in at least one of the first to third features, the control unit is a terminal that generates information used to protect the confidentiality of at least some of the information of the messages handled by the second layer, in a manner different from that of the first layer.

[0194] The fifth feature is a wireless communication system comprising a terminal and a base station, wherein the terminal comprises a communication unit that performs communication with the base station and a control unit that assumes the protection of confidentiality of at least some of the information of a message handled in a second layer lower than the first layer which is assumed to be protected in the communication, and the message handled in the second layer includes a field indicating whether or not to protect the confidentiality of the information handled in the second layer.

[0195] The sixth feature is a wireless communication method comprising the steps of performing communication with a base station and assuming the protection of confidentiality of at least some of the information in a message handled at a second layer lower than the first layer which is assumed to be protected in the communication, wherein the message handled at the second layer includes a field indicating whether or not to protect the confidentiality of the information handled at the second layer.

[0196] 10 Wireless Communication System 10A First Network 10B Second Network 20A, 20B Wireless Access Network 30A, 30B Core Network 50 Network Device 51 Receiving Unit 52 Transmitting Unit 53 Control Unit 100A, 100B Base Station 200 UE 210 Wireless Signal Transmitting / Receiving Unit 220 Amplifier Unit 230 Modulation / Demodulation Unit 240 Control Signal / Reference Signal Processing Unit 250 Encoding / Decoding Unit 260 Data Transmitting / Receiving Unit 270 Control Unit 1001 Processor 1002 Memory 1003 Storage 1004 Communication Device 1005 Input Device 1006 Output Device 1007 Bus 2001 Vehicle 2002 Drive Unit 2003 Steering Unit 2004 Accelerator Pedal 2005 Brake Pedal 2006 Shift Lever 2007 Front wheels (left and right) 2008 Rear wheels (left and right) 2009 Axle 2010 Electronic control unit 2012 Information service unit 2013 Communication module 2021 Current sensor 2022 Rotation speed sensor 2023 Air pressure sensor 2024 Vehicle speed sensor 2025 Acceleration sensor 2026 Brake pedal sensor 2027 Shift lever sensor 2028 Object detection sensor 2029 Accelerator pedal sensor 2030 Driving assistance system unit 2031 Microprocessor 2032 Memory (ROM, RAM) 2033 Communication port

Claims

1. A terminal comprising: a communication unit that performs communication with a base station; and a control unit that assumes the protection of the confidentiality of at least some of the information of a message handled at a second layer lower than the first layer which is assumed to be protected in the communication.

2. The terminal according to claim 1, wherein the message handled by the second layer includes a field indicating whether or not to protect the confidentiality of the information handled by the second layer.

3. The terminal according to claim 2, wherein the field is included in the header of each subdata unit constituting the data unit of the second layer, in the header of each subdata unit, in the header of each subdata unit, in the header of each subdata unit, in the header of each group of subdata units.

4. The terminal according to claim 1, wherein the control unit generates information used to protect the confidentiality of at least some of the information of the messages handled by the second layer in a manner different from that of the first layer.

5. A wireless communication system comprising a terminal and a base station, wherein the terminal comprises a communication unit that performs communication with the base station and a control unit that assumes the protection of the confidentiality of at least some of the information of a message handled at a second layer lower than the first layer which is assumed to be protected in the communication.

6. A wireless communication method comprising the steps of: performing communication with a base station; and assuming the protection of the confidentiality of at least some of the information of a message handled at a second layer lower than the first layer which is assumed to be protected in the communication.

Citation Information

Patent Citations

  • Layer 2 security enhancement

    US20240214799A1