Devices, methods, apparatuses, and computer readable media for security
By employing key generation techniques for integrity and confidentiality protection, the secure tunnel between UE and HN is established, addressing security gaps in 5G and B5G systems and ensuring secure data transfer.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- ALCATEL LUCENT SHANGHAI BELL CO LTD
- Filing Date
- 2024-10-18
- Publication Date
- 2026-04-23
AI Technical Summary
Current mobile communication systems, particularly 5G and beyond (B5G), lack end-to-end secure tunnels between user equipment (UE) and home networks (HN), failing to provide sufficient security for sensitive information transfer and not protecting sensitive data from intermediate networks.
Implementing separate or combined key generation techniques for integrity and confidentiality protection between UE and HN, using algorithms like TUAK and MILENAGE, to establish a secure tunnel ensuring integrity and confidentiality of data packets.
Enhances security by establishing a secure tunnel between UE and HN, protecting sensitive information from intermediate networks, and ensuring the integrity and confidentiality of data transfer.
Smart Images

Figure CN2024125662_23042026_PF_FP_ABST
Abstract
Description
DEVICES, METHODS, APPARATUSES, AND COMPUTER READABLE MEDIA FOR SECURITYTECHNICAL FIELD
[0001] Various example embodiments relate to devices, methods, apparatuses, and computer readable media for security.BACKGROUND
[0002] In current fifth generation of mobile communication system (5G) , there is no end-to-end secure tunnel between a user equipment (UE) and a home network (HN) . If an HN sends data packet to a UE, the HN needs firstly to send the data packet to visited public land mobile network (VPLMN) / access and mobility management function (AMF) , and subsequently the VPLMN / AMF delivers the data packet to the UE via non-access stratum (NAS) . For procedures defined and used to transfer small data from an HN to a UE securely, such as steering of roaming (SoR) , UE parameter update (UPU) , etc. current mechanisms cannot provide sufficient security. In addition, in beyond 5G (B5G) , e.g. sixth generation of mobile communication system (6G) , sensitive information, e.g. enhanced / optimized re-authentication indication and random, re-authentication value list, and other polices, etc., sent from 6G HN to 6G UE should be visible to mobile equipment (ME) and should not be visible to VPLMN / AMF, but current mechanisms cannot effectively protect such sensitive information.SUMMARY
[0003] A brief summary of exemplary embodiments is provided below to provide basic understanding of some aspects of various embodiments. It should be noted that this summary is not intended to identify key features of essential elements or define scopes of the embodiments, and its sole purpose is to introduce some concepts in a simplified form as a preamble for a more detailed description provided below.
[0004] In a first aspect, disclosed is an apparatus for a terminal device. The apparatus may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, may cause the apparatus at least to:receive from a network device, packets being integrity protected and ciphered; generate at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; and transmit to the network device, an acknowledgement at least being integrity protected by the at least one first key and ciphered by the at least one second key in response to the packets, in case of successfully verifying the packets based at least on the at least one first key and the at least one second key.
[0005] In a second aspect, disclosed is an apparatus for a network device. The apparatus may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, may cause the apparatus at least to:generate at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; transmit to a terminal device, packets at least being integrity protected by the at least one first key and ciphered by the at least one second key; and receive from the terminal device, an acknowledgement being integrity protected and ciphered in response to the packets.
[0006] In a third aspect, disclosed is a method performed by an apparatus for a terminal device. The method may comprise: receiving from a network device, packets being integrity protected and ciphered; generating at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; and transmitting to the network device, an acknowledgement at least being integrity protected by the at least one first key and ciphered by the at least one second key in response to the packets, in case of successfully verifying the packets based at least on the at least one first key and the at least one second key.
[0007] In a fourth aspect, disclosed is a method performed by an apparatus for a network device. The method may comprise: generating at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; transmitting to a terminal device, packets at least being integrity protected by the at least one first key and ciphered by the at least one second key; and receiving from the terminal device, an acknowledgement being integrity protected and ciphered in response to the packets.
[0008] In a fifth aspect, disclosed is an apparatus for a terminal device. The apparatus may comprise: means for receiving from a network device, packets being integrity protected and ciphered; means for generating at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; and means for transmitting to the network device, an acknowledgement at least being integrity protected by the at least one first key and ciphered by the at least one second key in response to the packets, in case of successfully verifying the packets based at least on the at least one first key and the at least one second key.
[0009] In a sixth aspect, disclosed is an apparatus for a network device. The apparatus may comprise: means for generating at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; means for transmitting to a terminal device, packets at least being integrity protected by the at least one first key and ciphered by the at least one second key; and means for receiving from the terminal device, an acknowledgement being integrity protected and ciphered in response to the packets.
[0010] In a seventh aspect, a computer-readable medium is disclosed. The computer-readable medium may comprise program instructions that, when executed by an apparatus for a terminal device, may cause the apparatus at least to: receive from a network device, packets being integrity protected and ciphered; generate at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; and transmit to the network device, an acknowledgement at least being integrity protected by the at least one first key and ciphered by the at least one second key in response to the packets, in case of successfully verifying the packets based at least on the at least one first key and the at least one second key.
[0011] In an eighth aspect, a computer-readable medium is disclosed. The computer-readable medium may comprise program instructions that, when executed by an apparatus for a network device, may cause the apparatus at least to: generate at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; transmit to a terminal device, packets at least being integrity protected by the at least one first key and ciphered by the at least one second key; and receive from the terminal device, an acknowledgement being integrity protected and ciphered in response to the packets.
[0012] Other features and advantages of the example embodiments of the present disclosure will also be apparent from the following description of specific embodiments when read in conjunction with the accompanying drawings, which illustrate, by way of example, the principles of example embodiments of the present disclosure.BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Some example embodiments will now be described, by way of non-limiting examples, with reference to the accompanying drawings.
[0014] FIG. 1A shows an example diagram of separate key generation according to the example embodiments of the present disclosure.
[0015] FIG. 1B shows an example diagram of key generation for SoR according to the example embodiments of the present disclosure.
[0016] FIG. 1C shows an example diagram of key generation for UPU according to the example embodiments of the present disclosure.
[0017] FIG. 2A shows an example diagram of combined key generation according to the example embodiments of the present disclosure.
[0018] FIG. 2B shows an example diagram of key generation for both SoR and UPU according to the example embodiments of the present disclosure.
[0019] FIG. 3 shows an example sequence diagram according to the example embodiments of the present disclosure.
[0020] FIG. 4 shows an example sequence diagram according to the example embodiments of the present disclosure.
[0021] FIG. 5A shows an example sequence diagram according to the example embodiments of the present disclosure.
[0022] FIG. 5B shows an example diagram of authentication vector generation which can be applied in the example embodiments of the present disclosure.
[0023] FIG. 5C shows an example diagram of KSEAF generation which can be applied in the example embodiments of the present disclosure.
[0024] FIG. 5D shows an example diagram of network authentication which can be applied in the example embodiments of the present disclosure.
[0025] FIG. 5E shows an example diagram of KAMF generation which can be applied in the example embodiments of the present disclosure.
[0026] FIG. 6A shows an example sequence diagram according to the example embodiments of the present disclosure.
[0027] FIG. 6B shows an example diagram of authentication vector generation which can be applied in the example embodiments of the present disclosure.
[0028] FIG. 6C shows an example diagram of network authentication which can be applied in the example embodiments of the present disclosure.
[0029] FIG. 6D shows an example diagram of KAUSF and KSEAF generation which can be applied in the example embodiments of the present disclosure.
[0030] FIG. 6E shows an example diagram of KAMF generation which can be applied in the example embodiments of the present disclosure.
[0031] FIG. 6F shows an example diagram of KAUSF, KSEAF, and KAMF generation which can be applied in the example embodiments of the present disclosure.
[0032] FIG. 7 shows an example sequence diagram according to the example embodiments of the present disclosure.
[0033] FIG. 8 shows a flow chart illustrating an example method 800 for security according to the example embodiments of the present disclosure.
[0034] FIG. 9 shows a flow chart illustrating an example method 900 for security according to the example embodiments of the present disclosure.
[0035] FIG. 10 shows a block diagram illustrating an example device 1000 for security according to the example embodiments of the present disclosure.
[0036] FIG. 11 shows a block diagram illustrating an example device 1100 for security according to the example embodiments of the present disclosure.
[0037] FIG. 12 shows a block diagram illustrating an example apparatus 1200 for security according to the example embodiments of the present disclosure.
[0038] FIG. 13 shows a block diagram illustrating an example apparatus 1300 for security according to the example embodiments of the present disclosure.
[0039] Throughout the drawings, same or similar reference numbers indicate same or similar elements. A repetitive description on the same elements would be omitted.DETAILED DESCRIPTION
[0040] Herein below, some example embodiments are described in detail with reference to the accompanying drawings. The following description includes specific details for the purpose of providing a thorough understanding of various concepts. However, it will be apparent to those skilled in the art that these concepts may be practiced without these specific details. In some instances, well known circuits, techniques and components are shown in block diagram form to avoid obscuring the described concepts and features.
[0041] For HN packets towards a UE which should not be accessed by 6G serving network (SN) or 6G access network (AN) , both integrity protection and confidentiality protection should be enabled but are not supported in current UPU or SoR.
[0042] Example embodiments of the present disclosure can create a secure tunnel, which may provide integrity and confidentiality protection, between a UE and an HN, such that the UE and the HN can securely transfer data packets, such as parameters.
[0043] FIG. 1A shows an example diagram of separate key generation according to the example embodiments of the present disclosure. The procedure shown in FIG. 1A may be performed by a UE and / or a network device of an HN, and the network device may function as an authentication server function (AUSF) entity, a unified data management (UDM) entity, a network exposure function (NEF) entity, and / or a network function (NF) entity of the HN.
[0044] The example key generation shown in FIG. 1A may be performed separately for SoR and UPU. In other words, the example key generation shown in FIG. 1A may be performed for either SoR or UPU. Further, FIG. 1A shows the generation of cipher key (CK) and integrity key (IK) in comparison to authentication token (AUTN) generation during authentication and key agreement (AKA) procedure. The blocks with dashed lines represent the operations, the functions, and / or the values which can be omitted from the AUTN generation during the AKA procedure. In the present disclosure, CK may refer to a key for confidentiality protection, IK may refer to a key for integrity protection, and ciphering and encryption may be interchangeable. And in the present disclosure, f1, f2, f3, f4, and f5 refer to authentication and key generation functions of TUAK and / or MILENAGE algorithm set proposed by the 3rd Generation Partnership Project (3GPP) .
[0045] In an operation 110, the network device may generate a random number (RAND) 115 specific for SoR or UPU, and the UE may receive the RAND 115 from the network device. In some embodiments, the RAND 115 may be generated for the AKA procedure, which means the RAND used in the previous AKA can be used for the key generation shown in FIG. 1A. In some embodiments, the network device may newly generate the RAND 115 for deriving the CK 120 and the IK 125.
[0046] The RAND 115 and a key for the network device, e.g. an AUSF entity, denoted as KAUSF are input to f3 function and f4 function to generate a CK 120 and an IK 125, respectively. The CK 120 and the IK 125 may be used for SoR or UPU.
[0047] FIG. 1B shows an example diagram of key generation for SoR according to the example embodiments of the present disclosure. The example key generation for SoR shown in FIG. 1B is simplified from FIG. 1A, in case the example key generation shown in FIG. 1A is for SoR. In this case, the RAND 115 is specific for SoR, dented as RANDSoR. The RANDSoR and the KAUSF are input to f3 function and f4 function to generate a CK for SoR and an IK for SoR, respectively. In this case the CK 120 is the CK for SoR, denoted as CKSoR, and the IK 125 is the IK for SoR, denoted as IKSoR.
[0048] FIG. 1C shows an example diagram of key generation for UPU according to the example embodiments of the present disclosure. The example key generation for UPU shown in FIG. 1B is simplified from FIG. 1A, in case the example key generation shown in FIG. 1A is for UPU. In this case, the RAND 115 is specific for UPU, dented as RANDUPU. The RANDUPU and the KAUSF are input to f3 function and f4 function to generate a CK for UPU and an IK for UPU, respectively. In this case the CK 120 is the CK for UPU, denoted as CKUPU, and the IK 125 is the IK for UPU, denoted as IKUPU.
[0049] FIG. 1A to FIG. 1C show SoR and UPU as examples. The example embodiments of the present disclosure are not limited to SoR and UPU. Alternatively or additionally, in some embodiments, the UE and the network device may generate a CK and an IK for a data transfer HN procedure other than the SoR and UPU in the manner shown in FIG. 1A to FIG. 1C.
[0050] FIG. 2A shows an example diagram of combined key generation according to the example embodiments of the present disclosure. The procedure shown in FIG. 2A may be performed by the UE and / or the network device of the HN.
[0051] The example key generation shown in FIG. 2A may be performed commonly for SoR and UPU. In other words, the example key generation shown in FIG. 2A may be performed for both SoR and UPU and thus may be referred to as a combined key generation. Further, FIG. 2A shows the generation of CK and IK in comparison to the AUTN generation during the AKA procedure. The blocks with dashed lines represent the operations, the functions, and / or the values which can be omitted from the AUTN generation during the AKA procedure.
[0052] In an operation 210, the network device may generate a RAND 215 for both SoR and UPU, and the UE may receive the RAND 215 from the network device. In some embodiments, the RAND 215 may be generated for the AKA procedure, which means the RAND used in the previous AKA can be used for the key generation shown in FIG. 2A. In some embodiments, the network device may newly generate the RAND 215 for deriving the CK 220 and the IK 225.
[0053] The RAND 215 and the KAUSF are input to f3 function and f4 function to generate a CK 220 and an IK 225, respectively. The CK 220 and the IK 225 may be common to SoR and UPU. In some embodiments, The CK 220 may be an HN cipher key, and the IK 225 may be an HN integrity protection key.
[0054] FIG. 2B shows an example diagram of key generation for both SoR and UPU according to the example embodiments of the present disclosure. The example key generation shown in FIG. 2B is simplified from FIG. 2A. The RAND 215 is common to SoR and UPU. The RAND 215 and the KAUSF are input to f3 function and f4 function to generate a CK common to SoR and UPU and an IK common to SoR and UPU, respectively. The CK 220 is the CK common to SoR and UPU, denoted as CKSoR_UPU, and the IK 225 is the IK common to SoR and UPU, denoted as IKSoR_UPU.
[0055] Thus, according to the example embodiments of the present disclosure, SoR and UPU procedures can be enhanced by key generation techniques, and some mechanisms, e.g. f3 and f4 functions, from the AUTN generation of the AKA procedure can be reused and adapted.
[0056] FIG. 2A and FIG. 2B show SoR and UPU as examples. The example embodiments of the present disclosure are not limited to SoR and UPU. Alternatively or additionally, in some embodiments, the UE and the network device may generate a combined CK and a combined IK common to SoR, UPU, and a data transfer HN procedure other than the SoR and UPU in the manner shown in FIG. 2A and FIG. 2B.
[0057] In some embodiments, when the UE and / or the network device derive keys for SoR integrity protection and SoR ciphering from the KAUSF, or when the UE and / or the network device derive keys for UPU integrity protection and UPU ciphering from the KAUSF, or when the UE and / or the network device derive a CK and an IK for another data transfer HN procedure from the KAUSF, or when the UE and / or the network device derive a CK and an IK common to SoR, UPU and another data transfer HN procedure from the KAUSF, parameters used in generating the CK (s) and the IK (s) may comprise HN algorithm type distinguisher, length of the HN algorithm type distinguisher, HN algorithm identity, and length of the HN algorithm identity.
[0058] In some embodiments, the following parameters can be used to form the string S input to the key derivation function (KDF) .
[0059] - Function code (FC) = a value unused for any other key generation
[0060] - P0 = 6G HN algorithm type distinguisher
[0061] - L0 = length of 6G HN algorithm type distinguisher (e.g. 0x00, 0x01)
[0062] - P1 = 6G HN algorithm identity
[0063] - L1 = length of 6G HN algorithm identity (e.g. 0x00, 0x01)
[0064] The 6G HN algorithm type distinguisher may be 6G SoR encryption algorithm, denoted as 6G-SoR-enc-alg, for SoR encryption algorithms and 6G SoR integrity protection algorithm, denoted as 6G-SoR-int-alg, for SoR integrity protection algorithms. The 6G HN algorithm type distinguisher may be 6G UPU encryption algorithm, denoted as 6G-UPU-enc-alg, for UPU encryption algorithms and 6G UPU integrity protection algorithm, denoted as 6G-UPU-int-alg, for UPU integrity protection algorithms. The values 0x00 and 0x05 to 0xf0 may be reserved for future use of new HN encryption and integrity protection cases, for example, a data transfer HN procedure other than the SoR and UPU. The 6G HN algorithm type distinguisher may be 6G new HN feature encryption algorithm, denoted as 6G-New HN Feature-enc-alg, and 6G new HN feature integrity protection algorithm, denoted as 6G-New HN Feature-int-alg. The values 0xf1 to 0xff may be reserved for private use or stand-alone non-public network (SNPN) use cases. Table 1 shows an example 6G HN algorithm type distinguisher.
[0065] Table 1
[0066] FIG. 3 shows an example sequence diagram according to the example embodiments of the present disclosure. Referring to FIG. 3, a UE 310 may represent any terminal device. A SN 320 and a HN 330 are shown to represent network side serving the UE 310. In the SN 320, a radio access network (RAN) 322 and an AMF entity 324 are shown as example SN elements. In the HN 330, an AUSF entity 332 and a UDM entity 334 are shown as example HN elements. The UE 310 may be the UE described with respect to FIG. 1A to FIG. 1C and Fig. 2A to FIG. 2B, and the AUSF entity 332 may be an example of the network device described with respect to FIG. 1A to FIG. 1C and Fig. 2A to FIG. 2B. It may be assumed that the UE 310, the RAN 322, the AMF entity 324, the AUSF entity 332, and the UDM entity 334 can support 6G.
[0067] Referring to FIG. 3, the UE 310 may transmit to the AUSF entity 332, capabilities for security of the UE 310. For example, The UE 310 may transmit information 312 on UE security capabilities to the AUSF entity 332. In some embodiments, the UE 310 may transmit the information 312 to the AMF entity 324 via the RAN 322, and the AMF entity 324 may further forward the information 312 to the AUSF entity 332. In some embodiments, the information 312 may be transmitted from the UE 310 to the AMF entity 324 via a registration request and the AMF entity 324 to the AUSF entity 332 via an authentication request.
[0068] Receiving the security capabilities of the UE 310, the AUSF entity 332 may store the security capabilities of the UE 310. In an operation 338, the UE 310, the SN 320 and the HN 330 may complete an AKA procedure, which may be similar to the AKA procedure described in 3GPP technical specification (TS) 33.501.
[0069] In an operation 340, the AUSF entity 332 may select an integrity protection algorithm and a ciphering algorithm based on the capabilities for security of the UE 310. Then, in an operation 342, the AUSF entity 332 may generate at least one first key for integrity protection according to the integrity protection algorithm and at least one second key for ciphering according to the ciphering algorithm. In some embodiments, the first key may be the IK, and the second key may be the CK. In some embodiments, the AUSF entity 332 may generate separate IKs and separate CKs in the manner shown in FIG. 1A to FIG. 1C. In some embodiments, the AUSF entity 332 may generate a combined IK and a combined CK in the manner shown in FIG. 2A to FIG. 2B.
[0070] Then, in an operation 344, the AUSF entity 332 may perform a security mode command (SMC) procedure with the UE 310. From the perspective of UE, the UE 310 may perform the SMC procedure with the AUSF entity 332. In other words, in the operation 344, the SMC procedure can be run between the UE 310 and the AUSF entity 332, and thus the SMC procedure may be referred to as a 6G HN SMC procedure.
[0071] In the operation 344, the AUSF entity 332 may transmit to the UE 310, packets 346 being integrity protected by the IK (s) generated in the operation 342 and ciphered by the CK (s) generated in the operation 342. In some embodiments, the AUSF entity 332 may transmit one or more containers to the UE 310. In some embodiments, the packets 346 may be contained in the one or more containers. Alternatively or additionally, the one or more containers may comprise information on the algorithms selected in the operation 340 and the RAND (s) used in the operation 342 for generating the CK (s) and IK (s) .
[0072] In some embodiments, in case in the operation 342 the AUSF entity 332 generates separate IKs and separate CKs in the manner shown in FIG. 1A to FIG. 1C, the AUSF entity 332 may construct and transmit separate containers for the separate IKs and separate CKs, respectively. For example, a container may comprise the information on the algorithms and the RAND for generating the keys for SoR, a container may comprise the information on the algorithms and the RAND for generating the keys for UPU, and a container may comprise the information on the algorithms and the RAND for generating the keys for another data transfer HN procedure.
[0073] In some embodiments, in case in the operation 342 the AUSF entity 332 generates a combined IK and a combined CK in the manner shown in FIG. 2A to FIG. 2B, the AUSF entity 332 may construct and transmit one container for the combined IK and combined CK. For example, one container may comprise the information on the algorithms and the RAND for generating the combined keys common to SoR, UPU, and another data transfer HN procedure.
[0074] In an operation 314, the UE 310 may generate IK (s) according to an integrity protection algorithm and CK (s) according to a ciphering algorithm. With the one or more containers sent from the AUSF entity 332, the UE 310 may generate the IK (s) and CK (s) based on the same algorithms and inputs, e.g. the RAND (s) and KAUSF, as those used by the AUSF entity 332.
[0075] Thus, the UE 310 may decipher the packets 346 using the CK (s) generated in the operation 314 and verify the integrity of the packets 346 using the IK (s) generated in operation 314 to verify the received packets 346. In some embodiments, the packets 346 may comprise the capabilities for security of the UE 310 which were transmitted from the UE 310. By replaying the capabilities for security received from the AUSF entity 332, the UE 310 may be aware whether the packets 346 have been modified by the SN 320, e.g. the RAN 322 and / or the AMF entity 324.
[0076] In case of successfully verifying the packets 346 based on the IK (s) and the CK (s) generated in the operation 314, in response to the packets 346, the UE 310 may transmit to the AUSF entity 332, an acknowledgement (ACK) 316 being integrity protected by the IK (s) generated in the operation 314 and ciphered by the CK (s) generated in the operation 314.
[0077] Receiving the ACK 316, the AUSF entity 332 may decipher the ACK 316 using the CK (s) generated in the operation 342 and verify the integrity of the ACK 316 using the IK (s) generated in operation 342.
[0078] Thus, SoR, UPU, and / or another data transfer HN procedure can be enhanced with ciphering and integrity protection from the HN 330, and the HN SMC procedure can be performed, so the secure tunnel between the UE 310 and the HN 330 can be established.
[0079] Then, in an operation 326, the UE 310 and the SN 320 may execute an access stratum (AS) and NAS SMC procedure.
[0080] FIG. 4 shows an example sequence diagram according to the example embodiments of the present disclosure. The example sequence shown in FIG. 4 may also be performed by the UE 310, the RAN 322 and the AMF entity 324 of the SN 320, and the AUSF entity 332 and the UDM entity 334 of the HN 330.
[0081] Referring to FIG. 4, the UE 310 may transmit to the AMF entity 324, the capabilities for security of the UE 310. For example, The UE 310 may transmit the information 312 on UE security capabilities to the AMF entity 324 via the RAN 322. In some embodiments, the information 312 may be transmitted from the UE 310 to the AMF entity 324 via a registration request. Then, the AMF entity 324 may transmit to the AUSF entity 332, an authentication request 426 for the UE 310. In some embodiments, the authentication request 426 does not need to comprise the capabilities for security of the UE 310. And in the operation 338, the UE 310, the SN 320 and the HN 330 may complete the AKA procedure.
[0082] In some embodiment, the integrity protection algorithm and the ciphering algorithm may be preconfigured. For example, the operator of the network may preconfigure the algorithms in the AUSF entity 332 and the UE 310. The integrity protection algorithm and the ciphering algorithm may be unique in the HN procedures.
[0083] In an operation 442, the AUSF entity 332 may generate the IK (s) according to the integrity protection algorithm and the CK (s) according to the ciphering algorithm. In some embodiments, the AUSF entity 332 may generate separate IKs and separate CKs in the manner shown in FIG. 1A to FIG. 1C. In some embodiments, the AUSF entity 332 may generate a combined IK and a combined CK in the manner shown in FIG. 2A to FIG. 2B.
[0084] Then, in an operation 444, an authentication procedure may be performed between the HN 330 and the UE 310.
[0085] In the operation 444, the AUSF entity 332 may transmit to the UE 310, packets 446 being integrity protected by the IK (s) generated in the operation 442 and ciphered by the CK (s) generated in the operation 442. In some embodiments, the AUSF entity 332 may transmit one or more containers to the UE 310. In some embodiments, the packets 346 may be contained in the one or more containers. Alternatively or additionally, the one or more containers may comprise the RAND (s) used in the operation 442 for generating the CK (s) and IK (s) .
[0086] In some embodiments, in case in the operation 442 the AUSF entity 332 generates separate IKs and separate CKs in the manner shown in FIG. 1A to FIG. 1C, the AUSF entity 332 may construct and transmit separate containers for the separate IKs and separate CKs, respectively. For example, a container may comprise the information on the RAND for generating the keys for SoR, a container may comprise the information on the RAND for generating the keys for UPU, and a container may comprise the information on the RAND for generating the keys for another data transfer HN procedure.
[0087] In some embodiments, in case in the operation 442 the AUSF entity 332 generates a combined IK and a combined CK in the manner shown in FIG. 2A to FIG. 2B, the AUSF entity 332 may construct and transmit one container for the combined IK and combined CK. For example, one container may comprise the information on the RAND for generating the combined keys common to SoR, UPU, and another data transfer HN procedure.
[0088] In an operation 414, the UE 310 may generate the IK (s) according to the integrity protection algorithm and the CK (s) according to the ciphering algorithm. In some embodiments, the integrity protection algorithm and the ciphering algorithm may be provided by the operator of the network in the universal subscriber identity module (USIM) of the UE 310, and thus the ME of the UE 310 may fetch the algorithms from the USIM. Therefore, the UE 310 may generate the IK (s) and CK (s) based on the same algorithms and inputs, e.g. the RAND (s) and KAUSF, as those used by the AUSF entity 332.
[0089] Thus, the UE 310 may decipher the packets 446 using the CK (s) generated in the operation 414 and verify the integrity of the packets 446 using the IK (s) generated in operation 414 to verify the received packets 446. The UE 310 may be aware whether the packets 446 have been modified by the SN 320, e.g. the RAN 322 and / or the AMF entity 324.
[0090] In case of successfully verifying the packets 446 based on the IK (s) and the CK (s) generated in the operation 414, in response to the packets 446, the UE 310 may transmit to the AUSF entity 332, an ACK 416 being integrity protected by the IK (s) generated in the operation 414 and ciphered by the CK (s) generated in the operation 414.
[0091] Receiving the ACK 416, the AUSF entity 332 may decipher the ACK 416 using the CK (s) generated in the operation 442 and verify the integrity of the ACK 416 using the IK (s) generated in operation 442.
[0092] Thus, SoR, UPU, and / or another data transfer HN procedure can be enhanced with ciphering and integrity protection from the HN 330, and the secure tunnel between the UE 310 and the HN 330 can be established.
[0093] Then, in an operation 326, the UE 310 and the SN 320 may execute the AS and NAS SMC procedure.
[0094] FIG. 5A shows an example sequence diagram according to the example embodiments of the present disclosure. The example sequence diagram shown in FIG. 5A may be the implementation of the example sequence diagram shown in FIG. 4 on the basis of 6G AKA adaptation procedure.
[0095] Referring to FIG. 5A, compared to FIG. 4, in the SN 320, the RAN 322 is omitted, and a security anchor function (SEAF) entity 325 is further shown. It may be appreciated that the transmissions between the AMF entity 324 / SEAF entity 325 and the UE 110 may be via the RAN 322, and the operations related to the AMF entity 324 / SEAF entity 325 may be performed by the AMF entity 324 and / or the SEAF entity 325. In the HN 330, compared to FIG. 4, an authentication credential repository and processing function (ARPF) entity 335 and a subscription identifier de-concealing function (SIDF) entity 337 are further shown. The operations related to the UDM entity 334 / ARPF entity 335 / SIDF entity 337 may be performed by the UDM entity 334, the ARPF entity 335, and / or the SIDF entity 337.
[0096] In an operation 510, the UE 310 may perform a subscription permanent identifier (SUPI) to subscription concealed identifier (SUCI) concealment. Then, the UE 310 may transmit a registration request 512 to the AMF entity 324 / SEAF entity 325 via the RAN entity. The registration request 512 may comprise SUCI and / or 6G globally unique temporary UE identity (6G-GUTI) of the UE 310. In some embodiments, the registration request 512 may further comprise UE security capabilities of the UE 110.
[0097] Receiving the registration request 512, the AMF entity 324 / SEAF entity 325 may transmit an authentication request 520 to the AUSF entity 332. The authentication request 520 may comprise the SUCI and / or the 6G-GUTI of the UE 310, and may further comprise the name of the SN 320, denoted as SN-Name.
[0098] Receiving the authentication request 520, the AUSF entity 332 may transmit an authentication get request 530 to the UDM entity 334 / ARPF entity 335 / SIDF entity 337. The authentication get request 530 may comprise the SUCI and / or the 6G-GUTI of the UE 310, as well as the SN-Name of the SN 320.
[0099] Receiving the authentication get request 530, in an operation 532, the UDM entity 334 / ARPF entity 335 / SIDF entity 337 may perform an SUCI to SUPI de-concealment. In the operation 532, the UDM entity 334 / ARPF entity 335 / SIDF entity 337 may also select an authentication method. Then, in an operation 534, the UDM entity 334 / ARPF entity 335 / SIDF entity 337 may generate an authentication vector.
[0100] FIG. 5B shows an example diagram of authentication vector generation which can be applied in the example embodiments of the present disclosure. Referring to FIG. 5B, long term key K refers to an authentication key which is shared between and available to the USIM and the authentication center (AuC) in the home environment (HE) of 3G or home subscriber server (HSS) of 4G or UDM of 5G / 6G of the UE 310, and AMF refers to authentication management field. Those skilled in the art may understand that the AMF as input for generating keys is authentication management field, which is different from the AMF entity 324. In the example authentication vector generation shown in FIG. 5B, the generated authentication vector may be denoted as 6G HE AV.
[0101] Referring back to FIG. 5A, then, the UDM entity 334 / ARPF entity 335 / SIDF entity 337 may transmit an authentication get response 536 to the AUSF entity 332. The authentication get response 536 may comprise the generated 6G HE AV, the SUPI of the UE 310, and an indication of authentication and key management for applications (AKMA) .
[0102] Receiving the authentication get response 536, in an operation 538, the AUSF entity 332 may store the expected response (XRES) , denoted as XRES*, generated in FIG. 2B, and calculate a hash expected response (HXRES) , denoted as HXRES*.
[0103] Then, in an operation 540, the AUSF entity 332 may generate a key for the SEAF entity 325, denoted as KSEAF.
[0104] FIG. 5C shows an example diagram of KSEAF generation which can be applied in the example embodiments of the present disclosure. Referring to FIG. 5C, besides the KSEAF, the AUSF entity 332 may also generate a 6G serving environment (SE) AV.
[0105] Referring back to FIG. 5A, then, the AUSF entity 332 may transmit an authentication response 542 to the AMF entity 324 / SEAF entity 325. The authentication response 542 may comprise the 6G SE AV.
[0106] Receiving the authentication response 542, in an operation 522, the AMF entity 324 / SEAF entity 325 may store the HXRES*which is included in the 6G SE AV. Then, the AMF entity 324 / SEAF entity 325 may transmit an authentication request 524 to the UE 310. The authentication request 524 may comprise the RAND, the AUTN, a key set identifier for next generation radio access network (ngKSI) , and an anti-bidding down between architectures (ABBA) .
[0107] Receiving the authentication request 524, in an operation 514, the UE 310 may perform a network authentication.
[0108] FIG. 5D shows an example diagram of network authentication which can be applied in the example embodiments of the present disclosure. Referring to FIG. 5D, in the operation 514, the UE 310 may verity whether a message authentication code (MAC) == expected MAC (XMAC) &sequence number (SQN) is in a correct range.
[0109] Referring back to FIG. 5A, then, the UE 310 may transmit an authentication response 516 to the AMF entity 324 / SEAF entity 325. The authentication response 516 may comprise the response generated in the operation 514, denoted as RES*.
[0110] Receiving the authentication response 516, in an operation 526, the AMF entity 324 / SEAF entity 325 may calculate a hash response (HRES) , denoted as HRES*, and compare the HRES*to the stored HXRES*. In case the HRES*matches the HXRES*, the AMF entity 324 / SEAF entity 325 may transmit an authentication request 527 to the AUSF entity 332. The authentication request 527 may comprise the RES*.
[0111] Receiving the authentication request 527, in an operation 544, the AUSF entity 332 may verify the RES*with the stored XRES*. In case of successful verification in the operation 544, in an operation 546, the AUSF entity 332 may generate CK (s) and IK (s) .
[0112] In some embodiments, in the operation 546, the AUSF entity 332 may generate the CKs and the IKs separately for SoR, UPU, and / or another data transfer HN procedure, for example, in the manner shown in FIG. 1A, FIG. 1B, and FIG. 1C. In some embodiments, in the operation 546, the AUSF entity 332 may generate the combined CK and the combined IK common to SoR, UPU, and / or another data transfer HN procedure, for example, in the manner shown in FIG. 2A and FIG. 2B.
[0113] Then, the AUSF entity 332 may transmit an authentication response 548 to the AMF entity 324 / SEAF entity 325. The authentication response 548 may comprise an authentication result, the SUPI of the UE 310, the generated KSEAF, and HN packets being integrity protected by the IK (s) and ciphered by the CK (s) .
[0114] Further, the AUSF entity 332 may transmit an authentication result confirmation request 550 to the UDM entity 334 / ARPF entity 335 / SIDF entity 337. Receiving the authentication result confirmation request 550, in an operation 552, the UDM entity 334 may store authentication status of the UE 310. The UDM entity 334 / ARPF entity 335 / SIDF entity 337 may transmit an authentication result confirmation response 554 to the AUSF entity 332.
[0115] Receiving the authentication response 548, in an operation 528, the SEAF entity 325 may generate a key for the AMF entity 324, denoted as KAMF.
[0116] FIG. 5E shows an example diagram of KAMF generation which can be applied in the example embodiments of the present disclosure. After generating the KAMF, the SEAF entity 325 may transmit the KAMF and the ngKSI to the AMF entity 324.
[0117] Referring back to FIG. 5A, then, the AMF entity 324 / SEAF entity 325 may transmit an authentication result 529 to the UE 310. The authentication result 529 may comprise the HN packets being integrity protected by the IK (s) and ciphered by the CK (s) .
[0118] Receiving the authentication result 529, in an operation 518, the UE 310 may generate CK (s) and IK (s) . In some embodiments, in the operation 518, the UE 310 may generate the CKs and the IKs separately for SoR, UPU, and / or another data transfer HN procedure, for example, in the manner shown in FIG. 1A, FIG. 1B, and FIG. 1C. In some embodiments, in the operation 518, the UE 310 may generate the combined CK and the combined IK common to SoR, UPU, and / or another data transfer HN procedure, for example, in the manner shown in FIG. 2A and FIG. 2B.
[0119] In some embodiments, the UE 310 may decipher the HN packets using the generated CK (s) and verify the integrity of the HN packets using the generated IK (s) . In some embodiments, the UE 310 may transmit a response of an ACK 519 being integrity protected and ciphered by the generated CK (s) and IK (s) to the AUSF entity 332 via the AMF entity 324 / SEAF entity 325. Receiving the response of the ACK 519, the AUSF entity 332 may decipher the response of the ACK 519 using the CK (s) and verify the integrity of the response of the ACK 519 using the IK (s) .
[0120] FIG. 6A shows an example sequence diagram according to the example embodiments of the present disclosure. The example sequence diagram shown in FIG. 6A may be the implementation of the example sequence diagram shown in FIG. 4 on the basis of extensible authentication protocol (EAP) AKA prime adaptation procedure.
[0121] Referring to FIG. 6A, compared to FIG. 4, in the SN 320, the RAN 322 is omitted, and the SEAF entity 325 is further shown. It may be appreciated that the transmissions between the AMF entity 324 / SEAF entity 325 and the UE 110 may be via the RAN 322, and the operations related to the AMF entity 324 / SEAF entity 325 may be performed by the AMF entity 324 and / or the SEAF entity 325. In the HN 330, compared to FIG. 4, the ARPF entity 335 and the SIDF entity 337 are further shown. The operations related to the UDM entity 334 / ARPF entity 335 / SIDF entity 337 may be performed by the UDM entity 334, the ARPF entity 335, and / or the SIDF entity 337.
[0122] In an operation 610, the UE 310 may perform a SUPI to SUCI concealment. Then, the UE 310 may transmit a registration request 612 to the AMF entity 324 / SEAF entity 325. The registration request 612 may comprise SUCI and / or 6G-GUTI of the UE 310. In some embodiments, the registration request 612 may further comprise UE security capabilities of the UE 110.
[0123] Receiving the registration request 612, the AMF entity 324 / SEAF entity 325 may transmit an authentication request 620 to the AUSF entity 332. The authentication request 620 may comprise the SUCI and / or the 6G-GUTI of the UE 310, and may further comprise the SN-Name.
[0124] Receiving the authentication request 620, the AUSF entity 332 may transmit an authentication get request 630 to the UDM entity 334 / ARPF entity 335 / SIDF entity 337. The authentication get request 630 may comprise the SUCI and / or the 6G-GUTI of the UE 310, as well as the SN-Name of the SN 320.
[0125] Receiving the authentication get request 630, in an operation 632, the UDM entity 334 / ARPF entity 335 / SIDF entity 337 may perform an SUCI to SUPI de-concealment. In the operation 632, the UDM entity 334 / ARPF entity 335 / SIDF entity 337 may also select an authentication method. Then, in an operation 634, the UDM entity 334 / ARPF entity 335 / SIDF entity 337may generate an authentication vector.
[0126] FIG. 6B shows an example diagram of authentication vector generation which can be applied in the example embodiments of the present disclosure. In the example authentication vector generation shown in FIG. 6B, the generated authentication vector may be denoted as EAP-AKA’AV.
[0127] Referring back to FIG. 6A, then, the UDM entity 334 / ARPF entity 335 / SIDF entity 337 may transmit an authentication get response 636 to the AUSF entity 332. The authentication get response 636 may comprise the generated EAP-AKA’AV, the SUPI of the UE 310, and an AKMA indication.
[0128] Receiving the authentication get response 636, in an operation 638, the AUSF entity 332 may store the XRES. And the AUSF entity 332 may transmit an authentication response 640 to the AMF entity 324 / SEAF entity 325. The authentication response 640 may comprise an EAP request and / or an AKA’ challenge.
[0129] Receiving the authentication response 640, the AMF entity 324 / SEAF entity 325 may transmit an authentication request 622 to the UE 310. The authentication request 622 may comprise the EAP request and / or the AKA’ challenge, as well as an ngKSI and an ABBA.
[0130] Receiving the authentication request 622, in an operation 614, the UE 310 may perform a network authentication.
[0131] FIG. 6C shows an example diagram of network authentication which can be applied in the example embodiments of the present disclosure. Referring to FIG. 6C, in the operation 614, the UE 310 may verity whether a MAC == XMAC &SQN is in a correct range.
[0132] Referring back to FIG. 6A, then, the UE 310 may transmit an authentication response 616 to the AMF entity 324 / SEAF entity 325. The authentication response 616 may comprise an EAP response and / or an AKA’ challenge.
[0133] Receiving the authentication response 616, the AMF entity 324 / SEAF entity 325 may transmit an authentication request 624 to the AUSF entity 332. The authentication request 624 may comprise the EAP response and / or the AKA’ challenge.
[0134] Receiving the authentication request 624, in an operation 642, the AUSF entity 332 may verify the RES with the stored XRES. In case of successful verification in the operation 642, in an operation 644, the AUSF entity 332 may derive a key for the AUSF entity 332, denoted as KAUSF, and a KSEAF.
[0135] FIG. 6D shows an example diagram of KAUSF and KSEAF generation which can be applied in the example embodiments of the present disclosure. Then, referring back to FIG. 6A, in an operation 646, the AUSF entity 332 may generate CK (s) and IK (s) .
[0136] In some embodiments, in the operation 646, the AUSF entity 332 may generate the CKs and the IKs separately for SoR, UPU, and / or another data transfer HN procedure, for example, in the manner shown in FIG. 1A, FIG. 1B, and FIG. 1C. In some embodiments, in the operation 646, the AUSF entity 332 may generate the combined CK and the combined IK common to SoR, UPU, and / or another data transfer HN procedure, for example, in the manner shown in FIG. 2A and FIG. 2B.
[0137] Then, optionally, in an operation 648, the UE 310 and the AUSF entity 332 may perform exchange of further EAP message via the AMF entity 324 / SEAF entity 325.
[0138] Then, the AUSF entity 332 may transmit an authentication response 650 to the AMF entity 324 / SEAF entity 325. The authentication response 650 may comprise an indication indicating the EAP success, the SUPI of the UE 310, the generated KSEAF, and HN packets being integrity protected by the IK (s) and ciphered by the CK (s) .
[0139] Further, the AUSF entity 332 may transmit an authentication result confirmation request 652 to the UDM entity 334 / ARPF entity 335 / SIDF entity 337. Receiving the authentication result confirmation request 652, in an operation 654, the UDM entity 334 may store authentication status of the UE 310. The UDM entity 334 / ARPF entity 335 / SIDF entity 337 may transmit an authentication result confirmation response 656 to the AUSF entity 332.
[0140] Receiving the authentication response 650, in an operation 626, the SEAF entity 325 may generate a KAMF.
[0141] FIG. 6E shows an example diagram of KAMF generation which can be applied in the example embodiments of the present disclosure. After generating the KAMF, the SEAF entity 325 may transmit the KAMF and the ngKSI to the AMF entity 324.
[0142] Referring back to FIG. 6A, then, the AMF entity 324 / SEAF entity 325 may transmit an authentication result 628 or an NAS SMC 629 to the UE 310. The authentication result 628 or an NAS SMC 629 may comprise the indication indicating the EAP success, the ngKSI, and the ABBA, as well as the HN packets being integrity protected by the IK (s) and ciphered by the CK (s) .
[0143] Receiving the authentication result 628 or the NAS SMC 629, in an operation 617, the UE 310 may generate a KAUSF, a KSEAF, and a KAMF.
[0144] FIG. 6F shows an example diagram of KAUSF, KSEAF, and KAMF generation which can be applied in the example embodiments of the present disclosure. After generating the KAMF, referring back to FIG. 6A, in an operation 618, the UE 310 may generate CK (s) and IK (s) .
[0145] In some embodiments, in the operation 618, the UE 310 may generate the CKs and the IKs separately for SoR, UPU, and / or another data transfer HN procedure, for example, in the manner shown in FIG. 1A, FIG. 1B, and FIG. 1C. In some embodiments, in the operation 618, the UE 310 may generate the combined CK and the combined IK common to SoR, UPU, and / or another data transfer HN procedure, for example, in the manner shown in FIG. 2A and FIG. 2B.
[0146] In some embodiments, the UE 310 may decipher the HN packets using the generated CK (s) and verify the integrity of the HN packets using the generated IK (s) . In some embodiments, the UE 310 may transmit a response of an ACK 519 being integrity protected and ciphered by the generated CK (s) and IK (s) to the AUSF entity 332 via the AMF entity 324 / SEAF entity 325. Receiving the response of the ACK 519, the AUSF entity 332 may decipher the response of the ACK 519 using the CK (s) and verify the integrity of the response of the ACK 519 using the IK (s) .
[0147] FIG. 7 shows an example sequence diagram according to the example embodiments of the present disclosure. The example sequence shown in FIG. 7 may also be performed by the UE 310, the RAN 322 and the AMF entity 324 of the SN 320, and the AUSF entity 332 and the UDM entity 334 of the HN 330.
[0148] Referring to FIG. 7, the UE 310 may transmit to the AMF entity 324, the capabilities for security of the UE 310. For example, The UE 310 may transmit the information 312 on UE security capabilities to the AMF entity 324 via the RAN 322. In some embodiments, the information 312 may be transmitted from the UE 310 to the AMF entity 324 via a registration request. Then, the AMF entity 324 may transmit to the AUSF entity 332, the authentication request 426 for the UE 310. In some embodiments, the authentication request 426 does not need to comprise the capabilities for security of the UE 310. And in the operation 338, the UE 310, the SN 320 and the HN 330 may complete the AKA procedure.
[0149] In the operation 442, the AUSF entity 332 may generate the IK (s) according to the integrity protection algorithm and the CK (s) according to the ciphering algorithm. In some embodiments, the AUSF entity 332 may generate separate IKs and separate CKs in the manner shown in FIG. 1A to FIG. 1C. In some embodiments, the AUSF entity 332 may generate a combined IK and a combined CK in the manner shown in FIG. 2A to FIG. 2B.
[0150] In some embodiments, for the HN packets to be transmitted to the UE 310, after being integrity protected by the IK (s) generated in the operation 442 and ciphered by the CK (s) generated in the operation 442, in an operation 742, the AUSF entity 332 may perform integrity protection and ciphering on the HN packets using authentication and key generation functions f8 and f9, which are recommended by European Telecommunications Standards Institute (ETSI) Security Algorithms Group of Experts (SAGE) . For example, f8 may be used for ciphering, and f9 may be used for integrity protection.
[0151] Then, in an operation 444, an authentication procedure may be performed between the HN 330 and the UE 310.
[0152] In the operation 744, the AUSF entity 332 may transmit to the UE 310, packets 746, which are integrity protected and ciphered by the IK (s) and the CK (s) generated in the operation 442 and further ciphered and integrity protected by f8 and f9. In some embodiments, the AUSF entity 332 may transmit one or more containers to the UE 310. In some embodiments, the packets 746 may be contained in the one or more containers. Alternatively or additionally, the one or more containers may comprise the RAND (s) used in the operation 442 for generating the CK (s) and IK (s) .
[0153] In some embodiments, in case in the operation 442 the AUSF entity 332 generates separate IKs and separate CKs in the manner shown in FIG. 1A to FIG. 1C, the AUSF entity 332 may construct and transmit separate containers for the separate IKs and separate CKs, respectively. For example, a container may comprise the information on the RAND for generating the keys for SoR, a container may comprise the information on the RAND for generating the keys for UPU, and a container may comprise the information on the RAND for generating the keys for another data transfer HN procedure.
[0154] In some embodiments, in case in the operation 442 the AUSF entity 332 generates a combined IK and a combined CK in the manner shown in FIG. 2A to FIG. 2B, the AUSF entity 332 may construct and transmit one container for the combined IK and combined CK. For example, one container may comprise the information on the RAND for generating the combined keys common to SoR, UPU, and another data transfer HN procedure.
[0155] In the operation 414, the UE 310 may generate the IK (s) according to the integrity protection algorithm and the CK (s) according to the ciphering algorithm. Then, the UE 310 may decipher the packets 746 using the CK (s) generated in the operation 414 and f8 and verify the integrity of the packets 746 using the IK (s) generated in the operation 414 and f9 to verify the received packets 746.
[0156] In some embodiments, the information on the integrity protection algorithm and the ciphering algorithm as well as the information on f8 and f9 may be preconfigured in the UE 310 and the AUSF entity 332, e.g. in a manner similar to the embodiments of FIG. 4. In some embodiments, the information on the integrity protection algorithm and the ciphering algorithm as well as the information on f8 and f9 may be notified by the AUSF entity 332, e.g. in a manner similar to the embodiments of FIG. 3.
[0157] In case of successfully verifying the packets 746, in response to the packets 746, the UE 310 may perform ciphering on an ACK using the CK (s) generated in the operation 414 and perform integrity protection on the ACK using the IK (s) generated in the operation 414. In an operation 714, the UE 310 may perform integrity protection and ciphering on the acknowledgement using authentication and key generation functions f8 and f9. For example, f8 may be used for ciphering, and f9 may be used for integrity protection.
[0158] Then, the UE 310 may transmit to the AUSF entity 332, an ACK 716 being integrity protected by the IK (s) generated in the operation 414 and f9 and ciphered by the CK (s) generated in the operation 414 and f8.
[0159] Receiving the ACK 716, the AUSF entity 332 may decipher the ACK 716 using the CK (s) generated in the operation 442 and f8 and verify the integrity of the ACK 716 using the IK (s) generated in operation 442 and f9.
[0160] Thus, SoR, UPU, and / or another data transfer HN procedure can be enhanced with ciphering and integrity protection from the HN 330, and the secure tunnel between the UE 310 and the HN 330 can be established.
[0161] Then, in an operation 326, the UE 310 and the SN 320 may execute the AS and NAS SMC procedure.
[0162] The separate or combined keys can be refreshed by the UE 310 and the AUSF entity 332. For key refresh for the SoR, UPU, and another data transfer HN procedure, the AUSF entity 332 may newly generate separate RANDSoR, RANDUPU, and another RAND, or combined RAND, and thus newly generate corresponding CK (s) and IK (s) for SoR, UPU, and / or another data transfer HN procedure. Receiving the newly generated RAND (s) from the AUSF entity 332, the UE 310 may also newly generate corresponding CK (s) and IK (s) for SoR, UPU, and / or another data transfer HN procedure.
[0163] Establishing the secure tunnel between the UE 310 and the HN 330, a secure data transfer service, denoted as Nn_SecureDataTransfer, can be used to transfer the data securely between the UE 310 and the HN 330.
[0164] In some embodiments, the UE 310 can transmit to the network device, data being integrity protected by the IK (s) and ciphered by the CK (s) using the secure data transfer service. In some embodiments, the data may further be integrity protected ciphered by f8 and f9 using the secure data transfer service.
[0165] In some embodiments, the network device may transmit to the UE 310, data being integrity protected by the IK (s) and ciphered by the CK (s) using the secure data transfer service. In some embodiments, the data may further be integrity protected ciphered by f8 and f9 using the secure data transfer service.
[0166] In some embodiments, the Nn_SecureDataTransfer service may contain following APIs: request / response where the HN 330 can transfer the data to the UE 310 securely; and subscribe / notification where the UE 310 can be allowed to transfer the data to the HN 330 and the HN 330 can deliver the data to NF chaining.
[0167] In the above example embodiments, the AUSF entity 332 is taken as an example of the network device. The operations performed by the AUSF entity 332 in the above example embodiments may also be performed by the UDM entity 334, a NEF entity and / or another NF entity. For example, the secure data transfer service can be implemented by the AUSF entity 332, the UDM entity 334, the NEF entity and / or the another NF entity. In addition to or as an alternative to the AUSF entity 332, the network device according to the example embodiments may function as the UDM entity 334, the NEF entity and / or the another NF entity, which, as an entity of the HN 330, like the AUSF entity 332, can send secure packet to the UE 310.
[0168] Similar to the above example embodiments, in some embodiments, the UE 310 may also trigger or share uplink data or request according to configurations, and the uplink transmissions can be hidden from 6G SN and sent towards the 6G HN.
[0169] In the example embodiments of the present disclosure, the functionalities such as f3, f4, f8, and f9 recommended by ETSI SAGE can be reused, and the key generation mechanisms of radio resource control (RRC) for AN and NAS for SN can be adapted for HN key generation.
[0170] Further, according to the example embodiments of the present disclosure, the sensitive information can be protected and in addition to the USIM in secured packet case, the ME can also decipher and proceed the sensitive information on demand.
[0171] FIG. 8 shows a flow chart illustrating an example method 800 for security according to the example embodiments of the present disclosure. The example method 800 may be performed, for example, by an apparatus for a terminal device, such as the UE 310 above mentioned.
[0172] Referring to FIG. 8, the example method 800 may comprise: an operation 810 of receiving from a network device, packets being integrity protected and ciphered; an operation 820 of generating at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; and an operation 830 of transmitting to the network device, an acknowledgement at least being integrity protected by the at least one first key and ciphered by the at least one second key in response to the packets, in case of successfully verifying the packets based at least on the at least one first key and the at least one second key.
[0173] In some embodiments, the example method 800 may comprise: generating the at least one first key and the at least one second key based on a random number received from the network device and a key for the network device using authentication and key generation functions f3 and f4.
[0174] In some embodiments, parameters used in generating the at least one first key and the at least one second key may comprise home network algorithm type distinguisher, length of the home network algorithm type distinguisher, home network algorithm identity, and length of the home network algorithm identity.
[0175] In some embodiments, the example method 800 may comprise: transmitting to the network device, capabilities for security of the terminal device; and performing a SMC procedure with the network device, and wherein the packets may comprise the capabilities for security of the terminal device transmitted from the terminal device, and the integrity protection algorithm and the ciphering algorithm may be selected by the network device.
[0176] In some embodiments, the integrity protection algorithm and the ciphering algorithm may be preconfigured.
[0177] In some embodiments, the example method 800 may comprise: performing integrity protection and ciphering on the acknowledgement using authentication and key generation functions f8 and f9.
[0178] In some embodiments, the example method 800 may comprise: refreshing the at least one first key for integrity protection and the at least one second key for ciphering.
[0179] In some embodiments, the at least one first key may comprise at least one of the following: the first key for an SoR procedure, the first key for a UPU procedure, the first key for a data transfer HN procedure, or the first key common to the SoR procedure, the UPU procedure, and the data transfer HN procedure, and the at least one second key may comprise at least one of the following: the second key for the SoR procedure, the second key for the UPU procedure, the second key for the data transfer HN procedure, or the second key common to the SoR procedure, the UPU procedure, and the data transfer HN procedure.
[0180] In some embodiments, the example method 800 may comprise: transmitting to the network device, data at least being integrity protected by the at least one first key and ciphered by the at least one second key using a secure data transfer service.
[0181] FIG. 9 shows a flow chart illustrating an example method 900 for security according to the example embodiments of the present disclosure. The example method 900 may be performed, for example, by an apparatus for a network device, such as the network device in the above examples, which may be, for example, the AUSF entity 332, the UDM entity 334, the NEF entity, and / or another NF entity, above mentioned.
[0182] Referring to FIG. 9, the example method 900 may comprise: an operation 910 of generating at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; an operation 920 of transmitting to a terminal device, packets at least being integrity protected by the at least one first key and ciphered by the at least one second key; and an operation 930 of receiving from the terminal device, an acknowledgement being integrity protected and ciphered in response to the packets.
[0183] In some embodiments, the example method 900 may comprise: generating the at least one first key and the at least one second key based on a random number generated by the apparatus and a key for the network device using authentication and key generation functions f3 and f4.
[0184] In some embodiments, parameters used in generating the at least one first key and the at least one second key may comprise home network algorithm type distinguisher, length of the home network algorithm type distinguisher, home network algorithm identity, and length of the home network algorithm identity.
[0185] In some embodiments, the example method 900 may comprise: receiving from the terminal device, capabilities for security of the terminal device; selecting the integrity protection algorithm and the ciphering algorithm based on the capabilities for security of the terminal device; and performing a SMC procedure with the terminal device, and wherein the packets comprise the capabilities for security of the terminal device transmitted from the terminal device.
[0186] In some embodiments, the example method 900 may comprise: performing integrity protection and ciphering on the packets using authentication and key generation functions f8 and f9.
[0187] In some embodiments, the example method 900 may comprise: refreshing the at least one first key for integrity protection and the at least one second key for ciphering.
[0188] In some embodiments, the at least one first key may comprise at least one of the following: the first key for an SoR procedure, the first key for a UPU procedure, the first key for a data transfer HN procedure, or the first key common to the SoR procedure, the UPU procedure, and the data transfer HN procedure, and the at least one second key may comprise at least one of the following: the second key for the SoR procedure, the second key for the UPU procedure, the second key for the data transfer HN procedure, or the second key common to the SoR procedure, the UPU procedure, and the data transfer HN procedure.
[0189] In some embodiments, the example method 900 may comprise: transmitting to the terminal device, data at least being integrity protected by the at least one first key and ciphered by the at least one second key using a secure data transfer service.
[0190] In some embodiments, the apparatus may function as at least one of the following: an AUSF entity, a UDM entity, an NEF entity, or an NF entity.
[0191] FIG. 10 shows a block diagram illustrating an example device 1000 for security according to the example embodiments of the present disclosure. The device, for example, may be at least part of an apparatus for a terminal device, such as the UE 310 in the above examples.
[0192] As shown in FIG. 10, the example device 1000 may comprise at least one processor 1010 and at least one memory 1020 that may store instructions 1030. The instructions 1030, when executed by the at least one processor 1010, may cause the device 1000 at least to perform the example method 800 described above.
[0193] In various example embodiments, the at least one processor 1010 in the example device 1000 may comprise, but is not limited to, at least one hardware processor, including at least one microprocessor such as a central processing unit (CPU) , a portion of at least one hardware processor, and any other suitable dedicated processor such as those developed based on for example Field Programmable Gate Array (FPGA) and Application Specific Integrated Circuit (ASIC) . Further, the at least one processor 1010 may also include at least one other circuitry or element not shown in FIG. 10.
[0194] In various example embodiments, the at least one memory 1020 in the example device 1000 may comprise at least one storage medium in various forms, such as a transitory memory and / or a non-transitory memory. The transitory memory may include, but is not limited to, for example, a random-access memory (RAM) , a cache, and so on. The non-transitory memory may include, but is not limited to, for example, a read-only memory (ROM) , a hard disk, a flash memory, and so on. The term “non-transitory, ” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM) . Further, the at least memory 1020 may include, but is not limited to, an electric, a magnetic, an optical, an electromagnetic, an infrared, or a semiconductor system, apparatus, or device or any combination of the above.
[0195] Further, in various example embodiments, the example device 1000 may also include at least one other circuitry, element, and interface, for example at least one I / O interface, at least one antenna element, and the like.
[0196] In various example embodiments, the circuitries, parts, elements, and interfaces in the example device 1000, comprising the at least one processor 1010 and the at least one memory 1020, may be coupled together via any suitable connections including, but is not limited to, buses, crossbars, wiring and / or wireless lines, in any suitable ways, for example electrically, magnetically, optically, electromagnetically, and the like.
[0197] It is understood that the structure of the device on the side of the UE 310 is not limited to the above example device 1000.
[0198] FIG. 11 shows a block diagram illustrating an example device 1100 for security according to the example embodiments of the present disclosure. The device, for example, may be at least part of an apparatus for a network device, such as the network device, which may be, for example, the AUSF entity 332, the UDM entity 334, the NEF entity, and / or another NF entity, in the above examples.
[0199] As shown in FIG. 11, the example device 1100 may comprise at least one processor 1110 and at least one memory 1120 that may store instructions 1130. The instructions 1130, when executed by the at least one processor 1110, may cause the device 1100 at least to perform the example method 900 described above.
[0200] In various example embodiments, the at least one processor 1110 in the example device 1100 may comprise, but is not limited to, at least one hardware processor, including at least one microprocessor such as a central processing unit (CPU) , a portion of at least one hardware processor, and any other suitable dedicated processor such as those developed based on for example Field Programmable Gate Array (FPGA) and Application Specific Integrated Circuit (ASIC) . Further, the at least one processor 1110 may also include at least one other circuitry or element not shown in FIG. 11.
[0201] In various example embodiments, the at least one memory 1120 in the example device 1100 may comprise at least one storage medium in various forms, such as a transitory memory and / or a non-transitory memory. The transitory memory may include, but is not limited to, for example, a random-access memory (RAM) , a cache, and so on. The non-transitory memory may include, but is not limited to, for example, a read-only memory (ROM) , a hard disk, a flash memory, and so on. The term “non-transitory, ” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM) . Further, the at least memory 1120 may include, but is not limited to, an electric, a magnetic, an optical, an electromagnetic, an infrared, or a semiconductor system, apparatus, or device or any combination of the above.
[0202] Further, in various example embodiments, the example device 1100 may also include at least one other circuitry, element, and interface, for example at least one I / O interface, at least one antenna element, and the like.
[0203] In various example embodiments, the circuitries, parts, elements, and interfaces in the example device 1100, including the at least one processor 1110 and the at least one memory 1120, may be coupled together via any suitable connections including, but is not limited to, buses, crossbars, wiring and / or wireless lines, in any suitable ways, for example electrically, magnetically, optically, electromagnetically, and the like.
[0204] It is understood that the structure of the device on the side of the network device is not limited to the above example device 1100.
[0205] FIG. 12 shows a block diagram illustrating an example apparatus 1200 for security according to the example embodiments of the present disclosure. The apparatus, for example, may be at least part of a terminal device, such as the UE 310 in the above examples.
[0206] As shown in FIG. 12, the example apparatus 1200 may comprise: means 1210 for receiving from a network device, packets being integrity protected and ciphered; means 1220 for generating at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; and means 1230 for transmitting to the network device, an acknowledgement at least being integrity protected by the at least one first key and ciphered by the at least one second key in response to the packets, in case of successfully verifying the packets based at least on the at least one first key and the at least one second key.
[0207] In some embodiments, the apparatus 1200 may comprise: means for generating the at least one first key and the at least one second key based on a random number received from the network device and a key for the network device using authentication and key generation functions f3 and f4.
[0208] In some embodiments, parameters used in generating the at least one first key and the at least one second key may comprise home network algorithm type distinguisher, length of the home network algorithm type distinguisher, home network algorithm identity, and length of the home network algorithm identity.
[0209] In some embodiments, the apparatus 1200 may comprise: means for transmitting to the network device, capabilities for security of the terminal device; and means for performing a SMC procedure with the network device, and wherein the packets may comprise the capabilities for security of the terminal device transmitted from the terminal device, and the integrity protection algorithm and the ciphering algorithm may be selected by the network device.
[0210] In some embodiments, the integrity protection algorithm and the ciphering algorithm may be preconfigured.
[0211] In some embodiments, the apparatus 1200 may comprise: means for performing integrity protection and ciphering on the acknowledgement using authentication and key generation functions f8 and f9.
[0212] In some embodiments, the apparatus 1200 may comprise: means for refreshing the at least one first key for integrity protection and the at least one second key for ciphering.
[0213] In some embodiments, the at least one first key may comprise at least one of the following: the first key for an SoR procedure, the first key for a UPU procedure, the first key for a data transfer HN procedure, or the first key common to the SoR procedure, the UPU procedure, and the data transfer HN procedure, and the at least one second key may comprise at least one of the following: the second key for the SoR procedure, the second key for the UPU procedure, the second key for the data transfer HN procedure, or the second key common to the SoR procedure, the UPU procedure, and the data transfer HN procedure.
[0214] In some embodiments, the apparatus 1200 may comprise: means for transmitting to the network device, data at least being integrity protected by the at least one first key and ciphered by the at least one second key using a secure data transfer service.
[0215] In some example embodiments, examples of means in the example apparatus 1200 may include circuitries. For example, an example of means 1210 may include a circuitry configured to perform the operation 810 of the example method 800, an example of means 1220 may include a circuitry configured to perform the operation 820 of the example method 800, and an example of means 1230 may include a circuitry configured to perform the operation 830 of the example method 800.
[0216] The example apparatus 1200 may further include means comprising circuitry configured to perform the example method 800. In some example embodiments, examples of means may also include software modules and any other suitable function entities.
[0217] FIG. 13 shows a block diagram illustrating an example apparatus 1300 for security according to the example embodiments of the present disclosure. The apparatus, for example, may be at least part of a network device, such as the network device in the above examples, which may be, for example, the AUSF entity 332, the UDM entity 334, the NEF entity, and / or another NF entity, in the above examples.
[0218] As shown in FIG. 13, the example apparatus 1300 may comprise: means 1310 for generating at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; means 1320 for transmitting to a terminal device, packets at least being integrity protected by the at least one first key and ciphered by the at least one second key; and means 1330 for receiving from the terminal device, an acknowledgement being integrity protected and ciphered in response to the packets.
[0219] In some embodiments, the apparatus 1300 may comprise: means for generating the at least one first key and the at least one second key based on a random number generated by the apparatus and a key for the network device using authentication and key generation functions f3 and f4.
[0220] In some embodiments, parameters used in generating the at least one first key and the at least one second key may comprise home network algorithm type distinguisher, length of the home network algorithm type distinguisher, home network algorithm identity, and length of the home network algorithm identity.
[0221] In some embodiments, the apparatus 1300 may comprise: means for receiving from the terminal device, capabilities for security of the terminal device; means for selecting the integrity protection algorithm and the ciphering algorithm based on the capabilities for security of the terminal device; and means for performing a SMC procedure with the terminal device, and wherein the packets comprise the capabilities for security of the terminal device transmitted from the terminal device.
[0222] In some embodiments, the apparatus 1300 may comprise: means for performing integrity protection and ciphering on the packets using authentication and key generation functions f8 and f9.
[0223] In some embodiments, the apparatus 1300 may comprise: means for refreshing the at least one first key for integrity protection and the at least one second key for ciphering.
[0224] In some embodiments, the at least one first key may comprise at least one of the following: the first key for an SoR procedure, the first key for a UPU procedure, the first key for a data transfer HN procedure, or the first key common to the SoR procedure, the UPU procedure, and the data transfer HN procedure, and the at least one second key may comprise at least one of the following: the second key for the SoR procedure, the second key for the UPU procedure, the second key for the data transfer HN procedure, or the second key common to the SoR procedure, the UPU procedure, and the data transfer HN procedure.
[0225] In some embodiments, the apparatus 1300 may comprise: means for transmitting to the terminal device, data at least being integrity protected by the at least one first key and ciphered by the at least one second key using a secure data transfer service.
[0226] In some embodiments, the apparatus may function as at least one of the following: an AUSF entity, a UDM entity, an NEF entity, or an NF entity.
[0227] In some example embodiments, examples of means in the example apparatus 1300 may include circuitries. For example, an example of means 1310 may include a circuitry configured to perform the operation 910 of the example method 900, an example of means 1320 may include a circuitry configured to perform the operation 920 of the example method 900, and an example of means 1330 may include a circuitry configured to perform the operation 930 of the example method 900.
[0228] The example apparatus 1300 may further include means comprising circuitry configured to perform the example method 900. In some example embodiments, examples of means may also include software modules and any other suitable function entities.
[0229] The example embodiments of the present disclosure also provide a computer-readable medium comprising program instructions that, when executed by an apparatus for a terminal device, such as the UE 310 in the above examples, may cause the apparatus at least to: receive from a network device, packets being integrity protected and ciphered; generate at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; and transmit to the network device, an acknowledgement at least being integrity protected by the at least one first key and ciphered by the at least one second key in response to the packets, in case of successfully verifying the packets based at least on the at least one first key and the at least one second key.
[0230] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: generate the at least one first key and the at least one second key based on a random number received from the network device and a key for the network device using authentication and key generation functions f3 and f4.
[0231] In some embodiments, parameters used in generating the at least one first key and the at least one second key may comprise home network algorithm type distinguisher, length of the home network algorithm type distinguisher, home network algorithm identity, and length of the home network algorithm identity.
[0232] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: transmit to the network device, capabilities for security of the terminal device; and perform a SMC procedure with the network device, and wherein the packets may comprise the capabilities for security of the terminal device transmitted from the terminal device, and the integrity protection algorithm and the ciphering algorithm may be selected by the network device.
[0233] In some embodiments, the integrity protection algorithm and the ciphering algorithm may be preconfigured.
[0234] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: perform integrity protection and ciphering on the acknowledgement using authentication and key generation functions f8 and f9.
[0235] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: refresh the at least one first key for integrity protection and the at least one second key for ciphering.
[0236] In some embodiments, the at least one first key may comprise at least one of the following: the first key for an SoR procedure, the first key for a UPU procedure, the first key for a data transfer HN procedure, or the first key common to the SoR procedure, the UPU procedure, and the data transfer HN procedure, and the at least one second key may comprise at least one of the following: the second key for the SoR procedure, the second key for the UPU procedure, the second key for the data transfer HN procedure, or the second key common to the SoR procedure, the UPU procedure, and the data transfer HN procedure.
[0237] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: transmit to the network device, data at least being integrity protected by the at least one first key and ciphered by the at least one second key using a secure data transfer service.
[0238] The example embodiments of the present disclosure also provide a computer-readable medium comprising program instructions that, when executed by an apparatus for a network device, such as the network device in the above examples, which may be, for example, the AUSF entity 332, the UDM entity 334, the NEF entity, and / or another NF entity, may cause the apparatus at least to: generate at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; transmit to a terminal device, packets at least being integrity protected by the at least one first key and ciphered by the at least one second key; and receive from the terminal device, an acknowledgement being integrity protected and ciphered in response to the packets.
[0239] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: generate the at least one first key and the at least one second key based on a random number generated by the apparatus and a key for the network device using authentication and key generation functions f3 and f4.
[0240] In some embodiments, parameters used in generating the at least one first key and the at least one second key may comprise home network algorithm type distinguisher, length of the home network algorithm type distinguisher, home network algorithm identity, and length of the home network algorithm identity.
[0241] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: receive from the terminal device, capabilities for security of the terminal device; select the integrity protection algorithm and the ciphering algorithm based on the capabilities for security of the terminal device; and perform a SMC procedure with the terminal device, and wherein the packets comprise the capabilities for security of the terminal device transmitted from the terminal device.
[0242] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: perform integrity protection and ciphering on the packets using authentication and key generation functions f8 and f9.
[0243] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: refresh the at least one first key for integrity protection and the at least one second key for ciphering.
[0244] In some embodiments, the at least one first key may comprise at least one of the following: the first key for an SoR procedure, the first key for a UPU procedure, the first key for a data transfer HN procedure, or the first key common to the SoR procedure, the UPU procedure, and the data transfer HN procedure, and the at least one second key may comprise at least one of the following: the second key for the SoR procedure, the second key for the UPU procedure, the second key for the data transfer HN procedure, or the second key common to the SoR procedure, the UPU procedure, and the data transfer HN procedure.
[0245] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: transmit to the terminal device, data at least being integrity protected by the at least one first key and ciphered by the at least one second key using a secure data transfer service.
[0246] In some embodiments, the apparatus may function as at least one of the following: an AUSF entity, a UDM entity, an NEF entity, or an NF entity.
[0247] As used herein, “at least one of the following: <a list of two or more elements>” and “at least one of <a list of two or more elements>” and similar wording, where the list of two or more elements are joined by “and” or “or” , mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0248] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE) , a Subscriber Station (SS) , a Portable Subscriber Station, a Mobile Station (MS) , or an Access Terminal (AT) . The terminal device may include, but is not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA) , portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE) , laptop-mounted equipment (LME) , USB dongles, smart devices, wireless customer-premises equipment (CPE) , an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD) , a vehicle, a drone, a medical device and applications (e.g., remote surgery) , an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts) , a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an IAB node (e.g., a relay node) . In the above description, the terms “terminal device” , “communication device” , “terminal” , “user equipment” and “UE” may be used interchangeably.
[0249] The term “circuitry” throughout this disclosure may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) ; (b) combinations of hardware circuits and software, such as (as applicable) (i) a combination of analog and / or digital hardware circuit (s) with software / firmware and (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) ; and (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. This definition of circuitry applies to one or all uses of this term in this disclosure, including in any claims. As a further example, as used in this disclosure, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0250] Another example embodiment may relate to computer program codes or instructions which may cause an apparatus to perform at least the respective methods described above. Another example embodiment may be related to a computer-readable medium having such computer program codes or instructions stored thereon. In some embodiments, such a computer-readable medium may include at least one storage medium in various forms such as a volatile memory and / or a non-volatile memory. The volatile memory may include, but is not limited to, for example, a RAM, a cache, and so on. The non-volatile memory may include, but is not limited to, a ROM, a hard disk, a flash memory, and so on. The non-volatile memory may also include, but is not limited to, an electric, a magnetic, an optical, an electromagnetic, an infrared, or a semiconductor system, apparatus, or device or any combination of the above.
[0251] Unless the context clearly requires otherwise, throughout the description and the claims, the words “comprise, ” “comprising, ” and the like are to be construed in an inclusive sense, as opposed to an exclusive or exhaustive sense; that is to say, in the sense of “including, but is not limited to. ” The word “coupled” , as generally used herein, refers to two or more elements that may be either directly connected, or connected by way of one or more intermediate elements. Likewise, the word “connected” , as generally used herein, refers to two or more elements that may be either directly connected, or connected by way of one or more intermediate elements. Additionally, the words “herein, ” “above, ” “below, ” and words of similar import, when used in this application, shall refer to this application as a whole and not to any particular portions of this application. Where the context permits, words in the description using the singular or plural number may also include the plural or singular number respectively. The word “or” in reference to a list of two or more items, that word covers all of the following interpretations of the word: any of the items in the list, all of the items in the list, and any combination of the items in the list.
[0252] Moreover, conditional language used herein, such as, among others, “can, ” “could, ” “might, ” “may, ” “e.g., ” “for example, ” “such as” and the like, unless specifically stated otherwise, or otherwise understood within the context as used, is generally intended to convey that certain embodiments include, while other embodiments do not include, certain features, elements and / or states. Thus, such conditional language is not generally intended to imply that features, elements and / or states are in any way required for one or more embodiments or that one or more embodiments necessarily include logic for deciding, with or without author input or prompting, whether these features, elements and / or states are included or are to be performed in any particular embodiment.
[0253] As used herein, the term "determine / determining" (and grammatical variants thereof) can include, not least: calculating, computing, processing, deriving, measuring, investigating, looking up (for example, looking up in a table, a database or another data structure) , ascertaining and the like. Also, "determining" can include receiving (for example, receiving information) , accessing (for example, accessing data in a memory) , obtaining and the like. Also, "determine / determining" can include resolving, selecting, choosing, establishing, and the like.
[0254] While some embodiments have been described, these embodiments have been presented by way of example, and are not intended to limit the scope of the disclosure. Indeed, the apparatus, methods, and systems described herein may be embodied in a variety of other forms; furthermore, various omissions, substitutions, and changes in the form of the methods and systems described herein may be made without departing from the spirit of the disclosure. For example, while blocks are presented in a given arrangement, alternative embodiments may perform similar functionalities with different components and / or circuit topologies, and some blocks may be deleted, moved, added, subdivided, combined, and / or modified. At least one of these blocks may be implemented in a variety of different ways. The order of these blocks may also be changed. Any suitable combination of the elements and actions of the some embodiments described above can be combined to provide further embodiments. The accompanying claims and their equivalents are intended to cover such forms or modifications as would fall within the scope and spirit of the disclosure.
[0255] Abbreviations used in the description and / or in the figures are defined as follows:
[0256] 3GPP TS 3rd Generation Partnership Project Technical Specification
[0257] 3G third generation of mobile communication system
[0258] 4G fourth generation of mobile communication system
[0259] 5G fifth generation of mobile communication system
[0260] 6G sixth generation of mobile communication system
[0261] 6G-GUTI 6G globally unique temporary UE identity
[0262] ABBA anti-bidding down between architectures
[0263] ACK acknowledgement
[0264] AMF access and mobility management function
[0265] AMF authentication management field
[0266] AK anonymity key
[0267] AKA authentication and key agreement
[0268] AKMA authentication and key management for applications
[0269] AN access network
[0270] ARPF authentication credential repository and processing function
[0271] AS access stratum
[0272] AuC authentication center
[0273] AUSF authentication server function
[0274] AUTN authentication token
[0275] AV authentication vector
[0276] B5G beyond 5G
[0277] CK cipher key
[0278] EAP extensible authentication protocol
[0279] ETSI European Telecommunications Standards Institute
[0280] FC function code
[0281] HE home environment
[0282] HN home network
[0283] HRES hash response
[0284] HSS home subscriber server
[0285] HXRES hash expected response
[0286] IK integrity key
[0287] KDF key derivation function
[0288] MAC message authentication code
[0289] ME mobile equipment
[0290] NAS non-access stratum
[0291] NEF network exposure function
[0292] NF network function
[0293] ngKSI next generation radio access network
[0294] RAN radio access network
[0295] RAND random number
[0296] RES response
[0297] RFC request for comments
[0298] RRC radio resource control
[0299] SAGE Security Algorithms Group of Experts
[0300] SE serving environment
[0301] SEAF security anchor function
[0302] SIDF subscription identifier de-concealing function
[0303] SMC security mode command
[0304] SN serving network
[0305] SNPN stand-alone non-public network
[0306] SoR steering of roaming
[0307] SQN sequence number
[0308] SUCI subscription concealed identifier
[0309] SUPI subscription permanent identifier
[0310] UDM unified data management
[0311] UE user equipment
[0312] UPU UE parameter update
[0313] USIM universal subscriber identity module
[0314] VPLMN visited public land mobile network
[0315] XMAC expected MAC
[0316] XRES expected response
Claims
1.An apparatus for a terminal device, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:receive from a network device, packets being integrity protected and ciphered;generate at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; andtransmit to the network device, an acknowledgement at least being integrity protected by the at least one first key and ciphered by the at least one second key in response to the packets, in case of successfully verifying the packets based at least on the at least one first key and the at least one second key.2.The apparatus of claim 1, wherein the apparatus is configured to:generate the at least one first key and the at least one second key based on a random number received from the network device and a key for the network device using authentication and key generation functions f3 and f4.3.The apparatus of claim 1 or 2, wherein parameters used in generating the at least one first key and the at least one second key comprise home network algorithm type distinguisher, length of the home network algorithm type distinguisher, home network algorithm identity, and length of the home network algorithm identity.4.The apparatus of any of claims 1 to 3, wherein the apparatus is configured to:transmit to the network device, capabilities for security of the terminal device; andperform a security mode command procedure with the network device, and wherein the packets comprise the capabilities for security of the terminal device transmitted from the terminal device, and the integrity protection algorithm and the ciphering algorithm are selected by the network device.5.The apparatus of any of claims 1 to 3, wherein the integrity protection algorithm and the ciphering algorithm are preconfigured.6.The apparatus of any of claims 1 to 5, wherein the apparatus is configured to:perform integrity protection and ciphering on the acknowledgement using authentication and key generation functions f8 and f9.7.The apparatus of any of claims 1 to 6, wherein the apparatus is configured to:refresh the at least one first key for integrity protection and the at least one second key for ciphering.8.The apparatus of any of claims 1 to 7, wherein the at least one first key comprises at least one of the following: the first key for a steering of roaming, procedure, the first key for a user equipment parameter update procedure, the first key for a data transfer home network procedure, or the first key common to the steering of roaming procedure, the user equipment parameter update procedure, and the data transfer home network procedure, andthe at least one second key comprises at least one of the following: the second key for the steering of roaming procedure, the second key for the user equipment parameter update procedure, the second key for the data transfer home network procedure, or the second key common to the steering of roaming procedure, the user equipment parameter update procedure, and the data transfer home network procedure.9.The apparatus of any of claims 1 to 8, wherein the apparatus is configured to:transmit to the network device, data at least being integrity protected by the at least one first key and ciphered by the at least one second key using a secure data transfer service.10.An apparatus for a network device, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:generate at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm;transmit to a terminal device, packets at least being integrity protected by the at least one first key and ciphered by the at least one second key; andreceive from the terminal device, an acknowledgement being integrity protected and ciphered in response to the packets.11.The apparatus of claim 10, wherein the apparatus is configured to:generate the at least one first key and the at least one second key based on a random number generated by the apparatus and a key for the network device using authentication and key generation functions f3 and f4.12.The apparatus of claim 10 or 11, wherein parameters used in generating the at least one first key and the at least one second key comprise home network algorithm type distinguisher, length of the home network algorithm type distinguisher, home network algorithm identity, and length of the home network algorithm identity.13.The apparatus of any of claims 10 to 12, wherein the apparatus is configured to:receive from the terminal device, capabilities for security of the terminal device;select the integrity protection algorithm and the ciphering algorithm based on the capabilities for security of the terminal device; andperform a security mode command procedure with the terminal device, and wherein the packets comprise the capabilities for security of the terminal device transmitted from the terminal device.14.The apparatus of any of claims 10 to 13, wherein the apparatus is configured to:perform integrity protection and ciphering on the packets using authentication and key generation functions f8 and f9.15.The apparatus of any of claims 10 to 14, wherein the apparatus is configured to:refresh the at least one first key for integrity protection and the at least one second key for ciphering.16.The apparatus of any of claims 10 to 15, wherein the at least one first key comprises at least one of the following: the first key for a steering of roaming procedure, the first key for a user equipment parameter update procedure, the first key for a data transfer home network procedure, or the first key common to the steering of roaming procedure, the user equipment parameter update procedure, and the data transfer home network procedure, andthe at least one second key comprises at least one of the following: the second key for the steering of roaming procedure, the second key for the user equipment parameter update procedure, the second key for the data transfer home network procedure, or the second key common to the steering of roaming procedure, the user equipment parameter update procedure, and the data transfer home network procedure.17.The apparatus of any of claims 10 to 16, wherein the apparatus is configured to:transmit to the terminal device, data at least being integrity protected by the at least one first key and ciphered by the at least one second key using a secure data transfer service.18.The apparatus of any of claims 10 to 17, wherein the apparatus functions as at least one of the following: an authentication server function entity, a unified data management entity, a network exposure function entity, or a network function entity.19.A method performed by an apparatus for a terminal device, comprising:receiving from a network device, packets being integrity protected and ciphered;generating at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm; andtransmitting to the network device, an acknowledgement at least being integrity protected by the at least one first key and ciphered by the at least one second key in response to the packets, in case of successfully verifying the packets based at least on the at least one first key and the at least one second key.20.The method of claim 19, comprising:generating the at least one first key and the at least one second key based on a random number received from the network device and a key for the network device using authentication and key generation functions f3 and f4.21.The method of claim 19 or 20, wherein parameters used in generating the at least one first key and the at least one second key comprise home network algorithm type distinguisher, length of the home network algorithm type distinguisher, home network algorithm identity, and length of the home network algorithm identity.22.The method of any of claims 19 to 21, comprising:transmitting to the network device, capabilities for security of the terminal device; andperforming a security mode command procedure with the network device, and wherein the packets comprise the capabilities for security of the terminal device transmitted from the terminal device, and the integrity protection algorithm and the ciphering algorithm are selected by the network device.23.The method of any of claims 19 to 21, wherein the integrity protection algorithm and the ciphering algorithm are preconfigured.24.The method of any of claims 19 to 23, comprising:performing integrity protection and ciphering on the acknowledgement using authentication and key generation functions f8 and f9.25.The method of any of claims 19 to 24, comprising:refreshing the at least one first key for integrity protection and the at least one second key for ciphering.26.The method of any of claims 19 to 25, wherein the at least one first key comprises at least one of the following: the first key for a steering of roaming, procedure, the first key for a user equipment parameter update procedure, the first key for a data transfer home network procedure, or the first key common to the steering of roaming procedure, the user equipment parameter update procedure, and the data transfer home network procedure, andthe at least one second key comprises at least one of the following: the second key for the steering of roaming procedure, the second key for the user equipment parameter update procedure, the second key for the data transfer home network procedure, or the second key common to the steering of roaming procedure, the user equipment parameter update procedure, and the data transfer home network procedure.27.The method of any of claims 19 to 26, comprising:transmitting to the network device, data at least being integrity protected by the at least one first key and ciphered by the at least one second key using a secure data transfer service.28.A method performed by an apparatus for a network device, comprising:generating at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for ciphering according to a ciphering algorithm;transmitting to a terminal device, packets at least being integrity protected by the at least one first key and ciphered by the at least one second key; andreceiving from the terminal device, an acknowledgement being integrity protected and ciphered in response to the packets.29.The method of claim 28, comprising:generating the at least one first key and the at least one second key based on a random number generated by the apparatus and a key for the network device using authentication and key generation functions f3 and f4.30.The method of claim 28 or 29, wherein parameters used in generating the at least one first key and the at least one second key comprise home network algorithm type distinguisher, length of the home network algorithm type distinguisher, home network algorithm identity, and length of the home network algorithm identity.31.The method of any of claims 28 to 30, comprising:receiving from the terminal device, capabilities for security of the terminal device;selecting the integrity protection algorithm and the ciphering algorithm based on the capabilities for security of the terminal device; andperforming a security mode command procedure with the terminal device, and wherein the packets comprise the capabilities for security of the terminal device transmitted from the terminal device.32.The method of any of claims 28 to 31, comprising:performing integrity protection and ciphering on the packets using authentication and key generation functions f8 and f9.33.The method of any of claims 28 to 32, comprising:refreshing the at least one first key for integrity protection and the at least one second key for ciphering.34.The method of any of claims 28 to 33, wherein the at least one first key comprises at least one of the following: the first key for a steering of roaming procedure, the first key for a user equipment parameter update procedure, the first key for a data transfer home network procedure, or the first key common to the steering of roaming procedure, the user equipment parameter update procedure, and the data transfer home network procedure, andthe at least one second key comprises at least one of the following: the second key for the steering of roaming procedure, the second key for the user equipment parameter update procedure, the second key for the data transfer home network procedure, or the second key common to the steering of roaming procedure, the user equipment parameter update procedure, and the data transfer home network procedure.35.The method of any of claims 28 to 34, comprising:transmitting to the terminal device, data at least being integrity protected by the at least one first key and ciphered by the at least one second key using a secure data transfer service.36.The method of any of claims 28 to 35, wherein the apparatus functions as at least one of the following: an authentication server function entity, a unified data management entity, a network exposure function entity, or a network function entity.37.An apparatus for a terminal device, comprising means for performing the method of any of claims 19 to 27.38.An apparatus for a network device, comprising means for performing the method of any of claims 28 to 36.39.A computer-readable medium comprising program instructions that, when executed by an apparatus for a terminal device, cause the apparatus to at least perform the method of any of claims 19 to 27.40.A computer-readable medium comprising program instructions that, when executed by an apparatus for a network device, cause the apparatus to at least perform the method of any of claims 28 to 36.
Citation Information
Patent Citations
Data transmission method, user equipment and network side device
CN108293223A
Method for managing security key of mobile communication system, and apparatus therefor
US20210058790A1
Verification method, device and equipment and computer readable storage medium
WO2021088593A1
Terminal, base station, communication method, and wireless communication system
WO2024116337A1