Method and device for access section security policy based on encryption

The method addresses computational resource waste and bus bottlenecks in 6G communication systems by integrating integrity verification and encryption processes for control plane communication, enhancing security policy management and signal transmission efficiency.

WO2026095571A1PCT designated stage Publication Date: 2026-05-07SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
SAMSUNG ELECTRONICS CO LTD
Filing Date
2025-10-28
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Existing wireless communication systems face challenges in efficiently managing security policies, particularly in 6G communication systems, which require enhanced signal coverage and security measures due to terahertz band path loss and atmospheric absorption, leading to computational resource waste and bus bottlenecks in message encryption processing.

Method used

A method and apparatus for performing security procedures in wireless communication systems, including receiving terminal capability information and security policies to determine and activate integrated integrity verification and encryption processes for control plane communication, reducing computational resource waste and bus bottlenecks.

Benefits of technology

The solution effectively manages security policies, reducing computational resource waste and bus bottlenecks, enabling efficient signal transmission and reception in 6G communication systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025017319_07052026_PF_FP_ABST
    Figure KR2025017319_07052026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a 5G or 6G communication system for supporting a data transmission rate higher than that of a 4G communication system such as LTE. More specifically, a method performed by a base station in a wireless communication system comprises the steps of: receiving terminal capability information related to security performance of a terminal; receiving, from a core network, a security policy for communication related to a control plane (CP), the security policy indicating a first security procedure based on a first key used for integrity verification and a second key used for encryption and / or a second security procedure based on a security key used in the integrated performance of the integrity verification and the encryption; determining, on the basis of the terminal capability information and the security policy, the security procedure applied to the communication related to the CP; and activating the security procedure applied to the communication related to the determined CP.
Need to check novelty before this filing date? Find Prior Art

Description

Encryption-based access section security policy method and device

[0001] The present disclosure generally relates to wireless communication systems, and more specifically to methods and devices for managing security policies.

[0002] Looking back at the evolution of wireless communication through successive generations, technologies have been developed primarily for human-oriented services, such as voice, multimedia, and data. Following the commercialization of 5G (5th Generation) communication systems, connected devices, which have been increasing explosively, are expected to be connected to communication networks. Examples of networked objects include vehicles, robots, drones, home appliances, displays, smart sensors installed in various infrastructures, construction machinery, and factory equipment. Mobile devices are expected to evolve into various form factors, such as augmented reality glasses, virtual reality headsets, and holographic devices. In the 6G (6th Generation) era, efforts are underway to develop improved 6G communication systems to connect hundreds of billions of devices and objects to provide diverse services. For this reason, 6G communication systems are being referred to as "beyond 5G" systems.

[0003] In the 6G communication system predicted to be realized around 2030, the maximum transmission speed is tera (i.e., 1,000 gigabit) bps (bit per second), and the wireless latency is 100 microseconds (μsec). In other words, compared to the 5G communication system, the transmission speed in the 6G communication system is 50 times faster, and the wireless latency is reduced to one-tenth.

[0004] To achieve such high data transmission speeds and ultra-low latency, 6G communication systems are being considered for implementation in the terahertz (THz) band (e.g., the 95 gigahertz (GHz) to 3 terahertz (3THz) band). Due to more severe path loss and atmospheric absorption phenomena compared to the millimeter wave (mmWave) band introduced in 5G, the importance of technologies capable of guaranteeing signal reach, or coverage, is expected to increase in the terahertz band. As key technologies to ensure coverage, new waveforms, beamforming, and multi-antenna transmission technologies such as massive Multiple-Input and Multiple-Output (MIMO), Full Dimensional MIMO (FD-MIMO), array antennas, and large-scale antennas, which are superior in terms of coverage compared to RF (Radio Frequency) devices, antennas, and OFDM (Orthogonal Frequency Division Multiplexing), must be developed. In addition, new technologies such as metamaterial-based lenses and antennas, high-dimensional spatial multiplexing technology using Orbital Angular Momentum (OAM), and Reconfigurable Intelligent Surface (RIS) are being discussed to improve the coverage of terahertz band signals.

[0005] In addition, to improve frequency efficiency and system network, development is underway in 6G communication systems for full duplex technology, in which uplink and downlink simultaneously utilize the same frequency resources at the same time; network technology that integrates satellites and HAPS (High-Altitude Platform Stations); network structure innovation technology that supports mobile base stations and enables network operation optimization and automation; dynamic spectrum sharing technology through collision avoidance based on spectrum usage prediction; AI-based communication technology that utilizes AI (Artificial Intelligence) from the design stage and internalizes end-to-end AI support functions to realize system optimization; and next-generation distributed computing technology that realizes services of complexity exceeding the limits of terminal computing capabilities by utilizing ultra-high performance communication and computing resources (Mobile Edge Computing (MEC), cloud, etc.). In addition, attempts are continuing to further strengthen connectivity between devices, further optimize networks, promote the softwareization of network entities, and increase the openness of wireless communication through the design of new protocols to be used in 6G communication systems, the implementation of hardware-based security environments, the development of mechanisms for the safe utilization of data, and the development of technologies regarding privacy maintenance methods.

[0006] Due to the research and development of such 6G communication systems, it is expected that a new dimension of hyper-connected experience will become possible through the hyper-connectivity of 6G communication systems, which encompasses not only connections between objects but also connections between people and objects. Specifically, it is projected that 6G communication systems will enable the provision of services such as truly immersive eXtended Reality (XR), high-fidelity mobile holograms, and digital replicas. Furthermore, services such as remote surgery, industrial automation, and emergency response, which are provided through 6G communication systems with enhanced security and reliability, will be applied in various fields including industry, healthcare, automotive, and home appliances.

[0007] Based on the discussion above, the present disclosure aims to provide an apparatus and method capable of performing effective transmission and reception of signals in a wireless communication system.

[0008] More specifically, the present disclosure provides an apparatus and method for performing a security procedure for control plane and user plane communication based on encryption.

[0009] According to various embodiments of the present disclosure, a method performed by a base station in a wireless communication system may include: receiving terminal capability information related to the security performance of a terminal; receiving a security policy for communication related to a control plane (CP) from a core network, wherein the security policy indicates at least one of a first security procedure based on a first key used for integrity verification and a second key used for encryption, or a second security procedure based on a security key used in a method in which the integrity verification and the encryption are performed in an integrated manner; determining a security procedure applied to communication related to the CP based on the terminal capability information and the security policy; and activating the security procedure applied to communication related to the determined CP.

[0010] The present disclosure has the effect of providing a device and method capable of effectively providing services in a wireless communication system.

[0011] The present disclosure has the effect of reducing the waste of computational resources and bus bottlenecks for message encryption processing in wireless communication systems.

[0012] The effects obtainable in the present disclosure are not limited to those mentioned in the various embodiments, and other unmentioned effects will be clearly understood by those skilled in the art to which the present disclosure pertains from the description below.

[0013] FIG. 1 illustrates a wireless environment network in a wireless communication system according to various embodiments of the present disclosure.

[0014] FIG. 2 illustrates the functional configuration of a base station in a wireless communication system according to various embodiments of the present disclosure.

[0015] FIG. 3 illustrates the functional configuration of a terminal in a wireless communication system according to various embodiments of the present disclosure.

[0016] FIG. 4 illustrates an example of a wireless resource area in a wireless communication system according to embodiments of the present disclosure.

[0017] FIG. 5 is a figure illustrating an example of packet processing in the PDCP layer of a transmitting end and the PDCP layer of a receiving end according to an embodiment of the present disclosure. More specifically, FIG. 5 is a figure relating to packet processing in the PDCP layer in 5G NR.

[0018] FIG. 6 is a figure illustrating an example of packet processing at the PDCP layer of a transmitting end according to various embodiments of the present disclosure.

[0019] Figure 7 is a diagram illustrating the bus bottleneck phenomenon, which is a problem that can occur when both integrity protection and encryption are performed.

[0020] FIG. 8 is a figure illustrating an integrity protection and encryption method with reduced bus occupancy of data packets according to an embodiment of the present disclosure.

[0021] FIG. 9 is a figure showing an example of data packet exchange to which a method integrating integrity and encryption according to an embodiment of the present disclosure is applied.

[0022] FIGS. 10 and 11 illustrate an example of a method that can reduce the number of bus occupancy cycles for data packet processing without sequentially performing integrity protection and encryption when a security procedure based on integrity protection and encryption is performed.

[0023] FIG. 12 is a figure showing another example of a method to reduce the number of bus occupancy attempts based on security procedures based on integrity protection and encryption performed sequentially.

[0024] Figure 13 is a figure showing another example of a method to reduce the number of bus occupancy attempts based on a security procedure based on an integrated method of integrity and encryption.

[0025] FIG. 14 is a flowchart illustrating an example of a security policy application procedure in an access section according to an embodiment of the present disclosure.

[0026] FIG. 15 is a flowchart illustrating an example of a security activation procedure based on a method in which the integrity and encryption of a control plane are integrated according to an embodiment of the present disclosure.

[0027] FIG. 16 is a flowchart illustrating an example of a user plane security policy application procedure according to an embodiment of the present disclosure.

[0028] FIG. 17 is a flowchart illustrating an example of a security activation procedure in a user plane according to an embodiment of the present disclosure.

[0029] FIG. 18 is a figure showing an example of a key structure according to one embodiment of the present disclosure.

[0030] FIG. 19 is a figure showing an example of a key structure according to one embodiment of the present disclosure.

[0031] FIG. 20 is a figure illustrating an example of a key generation procedure according to one embodiment of the present disclosure.

[0032] FIG. 21 is a figure illustrating an example of a key generation procedure according to one embodiment of the present disclosure.

[0033] FIG. 22 is a diagram illustrating an algorithm used in a security procedure based on a method that integrates integrity and encryption according to one embodiment of the present disclosure.

[0034] FIG. 23 is a diagram illustrating a PDCP packet format that can be used when a security procedure based on an integrated integrity and encryption method according to one embodiment of the present disclosure is applied.

[0035] FIG. 24 is a figure showing an example of packet processing at the PDCP layer of the transmitting end and the PDCP layer of the receiving end, to which a security procedure based on a method integrating integrity and encryption according to an embodiment of the present disclosure is applied.

[0036] FIG. 25 is a flowchart illustrating an example of how a method of operation of a DU (distribution unit) according to various embodiments of the present disclosure is performed.

[0037] According to various embodiments of the present disclosure, a method performed by a base station in a wireless communication system may include: receiving terminal capability information related to the security performance of a terminal; receiving a security policy for communication related to a control plane (CP) from a core network, wherein the security policy indicates at least one of a first security procedure based on a first key used for integrity verification and a second key used for encryption, or a second security procedure based on a security key used in a method in which the integrity verification and the encryption are performed in an integrated manner; determining a security procedure applied to communication related to the CP based on the terminal capability information and the security policy; and activating the security procedure applied to communication related to the determined CP.

[0038] Additionally, according to various embodiments of the present disclosure, a method performed by a terminal in a wireless communication system comprises: a step of transmitting terminal capability information related to terminal security performance to a base station; and a step of activating a security procedure determined based on a security policy for communication related to the terminal capability information and a control plane (CP), wherein the security policy may indicate at least one of a first security procedure based on a first key used for integrity verification and a second key used for encryption, or a second security procedure based on a security key used in a method in which the integrity verification and the encryption are performed in an integrated manner.

[0039] Additionally, according to various embodiments of the present disclosure, a base station in a wireless communication system comprises: a transceiver; and a controller connected to the transceiver, wherein the controller receives terminal capability information related to the security performance of a terminal and receives a security policy for communication related to a control plane (CP) from a core network, wherein the security policy indicates at least one of a first security procedure based on a first key used for integrity verification and a second key used for encryption, or a second security procedure based on a security key used in a method in which the integrity verification and the encryption are performed in an integrated manner, determines a security procedure applied to communication related to the CP based on the terminal capability information and the security policy, and is configured to activate the determined security procedure applied to communication related to the CP.

[0040] Additionally, according to various embodiments of the present disclosure, a terminal in a wireless communication system comprises: a transceiver; and a controller connected to the transceiver, wherein the controller is configured to transmit terminal capability information related to terminal security performance to a base station and to activate a security procedure determined based on a security policy for communication related to the terminal capability information and a control plane (CP), wherein the security policy may indicate at least one of a first security procedure based on a first key used for integrity verification and a second key used for encryption, or a second security procedure based on a security key used in a method in which the integrity verification and the encryption are performed in an integrated manner.

[0041] The terms used in this disclosure are used merely to describe specific embodiments and are not intended to limit the scope of other embodiments. A singular expression may include a plural expression unless the context clearly indicates otherwise. Terms used, including technical or scientific terms, may have the same meaning as generally understood by those skilled in the art described in this disclosure. Terms used in this disclosure that are defined in a general dictionary may be interpreted as having the same or similar meaning as they have in the context of the relevant technology, and are not to be interpreted in an ideal or overly formal sense unless explicitly defined in this disclosure. In some cases, even terms defined in this disclosure are not to be interpreted to exclude the embodiments of this disclosure.

[0042] In the various embodiments of the present disclosure described below, a hardware-based approach is described as an example. However, since the various embodiments of the present disclosure include techniques using both hardware and software, the various embodiments of the present disclosure do not exclude a software-based approach. Furthermore, terms referring to network entities, terms referring to device components, etc., are illustrative for the convenience of explanation. Accordingly, the present disclosure is not limited to the terms described below, and other terms having equivalent technical meanings may be used.

[0043] Additionally, the present disclosure describes various embodiments using terms defined in some communication standards (e.g., 3GPP (3rd generation partnership project), ETSI (European Telecommunication Standards Institute)), but this is merely illustrative. Various embodiments of the present disclosure can be easily modified and applied to other communication systems.

[0044] Additionally, in this disclosure, expressions such as "greater than" or "less than" may be used to determine whether a specific condition is satisfied or fulfilled; however, this is merely for the purpose of expressing an example and does not exclude descriptions such as "greater than" or "less than." Conditions described as "greater than" may be replaced with "greater than," conditions described as "less than" may be replaced with "less than," and conditions described as "greater than and less than" may be replaced with "greater than and less than."

[0045] Terms referring to signals, channels, control information, network entities, and device components used in the following description are examples provided for the convenience of explanation. Accordingly, the present disclosure is not limited to the terms described below, and other terms having equivalent technical meanings may be used.

[0046] 5G systems must support services that simultaneously satisfy various requirements so as to freely reflect the diverse needs of users and service providers. Services considered for 5G systems include enhanced mobile broadband (eMBB), massive machine type communication (mMTC), or ultra-reliable and low-latency communication (URLC).

[0047] eMBB aims to provide data transmission speeds that are superior to those supported by existing LTE, LTE-A, or LTE-Pro. For example, in a 5G system, eMBB must be able to provide a peak data rate of 20 Gbps in the downlink and 10 Gbps in the uplink from the perspective of a single base station. Furthermore, while providing these peak data rates, the 5G system must also provide an increased user-perceived data rate. To satisfy these requirements, improvements in various transmission and reception technologies, including enhanced multi-input multi-output (MIMO) transmission technology, may be required. Additionally, while LTE systems transmit signals using a maximum transmission bandwidth of 20 MHz in the 2 GHz band, 5G systems can meet the data transmission speeds required by 5G communication systems by using a frequency bandwidth wider than 20 MHz in frequency bands of 3 to 6 GHz or above 6 GHz.

[0048] Simultaneously, mMTC is being considered to support application services such as the Internet of Things (IoT) in 5G systems. To efficiently provide IoT, mMTC requires support for a large number of terminal connections within a cell, improved terminal coverage, enhanced battery life, and reduced terminal costs. Since IoT provides communication functions attached to various sensors and devices, it must be possible to support a large number of terminals within a cell (e.g., 1,000,000 terminals / km²). Furthermore, due to the nature of the service, terminals supporting mMTC are likely to be located in dead zones not covered by cells, such as building basements, thus requiring wider coverage compared to other services provided by 5G communication systems. Terminals supporting mMTC must consist of low-cost devices, and because it is difficult to frequently replace terminal batteries, they require a very long battery life of 10 to 16 years.

[0049] Finally, URLLC is a mission-critical cellular-based wireless communication service. For example, consider services used for remote control of robots or machinery, industrial automation, unmanned aerial vehicles, remote health care, or emergency alerts. Therefore, the communication provided by URLLC must offer very low latency and very high reliability. For instance, services supporting URLLC must satisfy an air interface latency of less than 0.5 milliseconds and simultaneously meet the requirement of a packet error rate of 10⁻⁵ or less. Consequently, for services supporting URLLC, 5G systems must provide a transmit time interval (TTI) smaller than for other services and simultaneously allocate wide resources in the frequency band to ensure the reliability of the communication link.

[0050] In addition, in 5G systems and / or 6G systems, data traffic for the three aforementioned services, namely eMBB, URLLC, and mMTC services, can be multiplexed and transmitted within the communication system. Different transmission and reception techniques and parameters may be used between services to satisfy the different requirements of each service.

[0051] FIG. 1 illustrates a wireless environment network in a wireless communication system according to various embodiments of the present disclosure. FIG. 1 illustrates a base station (110), a first terminal (120), and a second terminal (130) as some of the nodes using a wireless channel in the wireless communication system. FIG. 1 illustrates only one base station, but other base stations identical or similar to the base station (110) may be additionally included.

[0052] A base station (110) is a network infrastructure that provides wireless access to terminals (120, 130). The base station (110) has coverage defined as a specific geographical area based on the distance at which it can transmit signals. In addition to the base station, the base station (110) includes an 'access point (AP)', an 'eNodeB (eNB)', and a '5G node (5 th It may be referred to as 'generation node', 'next generation nodeB (gNB)', 'wireless point', 'transmission / reception point (TRP)', or other terms having an equivalent technical meaning.

[0053] Each of the first terminal (120) and the second terminal (130) is a device used by a user and performs communication with the base station (110) via a wireless channel. In some cases, at least one of the first terminal (120) and the second terminal (130) may be operated without user involvement. That is, at least one of the first terminal (120) and the second terminal (130) is a device that performs machine type communication (MTC) and may not be carried by the user. Each of the first terminal (120) and the second terminal (130) may be referred to as 'user equipment (UE)', 'mobile station', 'subscriber station', 'remote terminal', 'wireless terminal', or 'user device', or other terms having an equivalent technical meaning, in addition to 'terminal'.

[0054] A base station (110), a first terminal (120), and a second terminal (130) can transmit and receive wireless signals in a millimeter wave (mmWave) band (e.g., 28 GHz, 30 GHz, 38 GHz, 60 GHz). At this time, to improve channel gain, the base station (110), the first terminal (120), and the second terminal (130) can perform beamforming. Here, beamforming may include transmission beamforming and reception beamforming. That is, the base station (110), the first terminal (120), and the second terminal (130) can impart directivity to the transmission signal or the reception signal. To this end, the base station (110) and the terminals (120, 130) can select serving beams through a beam search or beam management procedure. After serving beams are selected, subsequent communication can be performed through a resource that is in a quasi-co-located (QCL) relationship with the resource that transmitted the serving beams.

[0055] If large-scale characteristics of the channel transmitting the symbol on the first antenna port can be inferred from the channel transmitting the symbol on the second antenna port, the first antenna port and the second antenna port may be evaluated to have a QCL relationship. For example, the large-scale characteristics may include at least one of a delay spread, a Doppler spread, a Doppler shift, an average gain, an average delay, and a spatial receiver parameter.

[0056] FIG. 2 illustrates the functional configuration of a base station in a wireless communication system according to various embodiments of the present disclosure. The configuration exemplified in FIG. 2 can be understood as the configuration of a base station (110). Terms such as '... unit', '... unit' used below refer to a unit that processes at least one function or operation, and this may be implemented in hardware or software, or a combination of hardware and software.

[0057] Referring to FIG. 2, the base station includes a wireless communication unit (210), a backhaul communication unit (220), a storage unit (230), and a control unit (240).

[0058] The wireless communication unit (210) performs functions for transmitting and receiving signals through a wireless channel. For example, the wireless communication unit (210) performs a conversion function between a baseband signal and a bit sequence according to the physical layer specifications of the system. For example, when transmitting data, the wireless communication unit (210) generates complex symbols by encoding and modulating the transmitted bit sequence. Also, when receiving data, the wireless communication unit (210) restores the received bit sequence by demodulating and decoding the baseband signal.

[0059] Additionally, the wireless communication unit (210) upconverts a baseband signal into an RF (radio frequency) band signal and transmits it through an antenna, and downconverts the RF band signal received through the antenna into a baseband signal. To this end, the wireless communication unit (210) may include a transmission filter, a reception filter, an amplifier, a mixer, an oscillator, a DAC (digital to analog converter), an ADC (analog to digital converter), etc. Additionally, the wireless communication unit (210) may include a plurality of transmission and reception paths. Furthermore, the wireless communication unit (210) may include at least one antenna array composed of a plurality of antenna elements.

[0060] In terms of hardware, the wireless communication unit (210) may be composed of a digital unit and an analog unit, and the analog unit may be composed of a plurality of sub-units depending on operating power, operating frequency, etc. The digital unit may be implemented as at least one processor (e.g., a digital signal processor (DSP)).

[0061] The wireless communication unit (210) transmits and receives signals as described above. Accordingly, all or part of the wireless communication unit (210) may be referred to as a 'transmitter', a 'receiver', or a 'transceiver'. Furthermore, in the following description, transmission and reception performed through a wireless channel are used to mean that processing as described above is performed by the wireless communication unit (210).

[0062] The backhaul communication unit (220) provides an interface for communicating with other nodes within the network. That is, the backhaul communication unit (220) converts a bit sequence transmitted from a base station to another node, e.g., another connection node, another base station, an upper node, a core network, etc., into a physical signal, and converts a physical signal received from another node into a bit sequence.

[0063] The storage unit (230) stores data such as basic programs, application programs, and configuration information for the operation of the base station. The storage unit (230) may be composed of volatile memory, non-volatile memory, or a combination of volatile memory and non-volatile memory. Additionally, the storage unit (230) provides the stored data upon request from the control unit (240).

[0064] The control unit (240) (or controller) controls the overall operations of the base station. For example, the control unit (240) transmits and receives signals through the wireless communication unit (210) or through the backhaul communication unit (220). Additionally, the control unit (240) writes and reads data to and from the storage unit (230). Furthermore, the control unit (240) can perform the functions of a protocol stack required by the communication standard. According to other implementation examples, the protocol stack may be included in the wireless communication unit (210). To this end, the control unit (240) may include at least one processor.

[0065] According to various embodiments, the control unit (240) can control the base station to perform operations according to various embodiments described below.

[0066] FIG. 3 illustrates the functional configuration of a terminal in a wireless communication system according to various embodiments of the present disclosure. The configuration exemplified in FIG. 3 can be understood as the configuration of a terminal (120, 130). Terms such as '...part', '...unit', etc. used below refer to a unit that processes at least one function or operation, and this may be implemented in hardware or software, or a combination of hardware and software.

[0067] Referring to FIG. 3, the terminal includes a communication unit (310), a storage unit (320), and a control unit (330).

[0068] The communication unit (310) performs functions for transmitting and receiving signals through a wireless channel. For example, the communication unit (310) performs a conversion function between a baseband signal and a bit sequence according to the physical layer specifications of the system. For example, when transmitting data, the communication unit (310) generates complex symbols by encoding and modulating the transmitted bit sequence. Also, when receiving data, the communication unit (310) restores the received bit sequence by demodulating and decoding the baseband signal. Additionally, the communication unit (310) upconverts the baseband signal into an RF band signal and transmits it through an antenna, and downconverts the RF band signal received through the antenna into a baseband signal. For example, the communication unit (310) may include a transmission filter, a reception filter, an amplifier, a mixer, an oscillator, a DAC, an ADC, etc.

[0069] Additionally, the communication unit (310) may include a plurality of transmission and reception paths. Furthermore, the communication unit (310) may include at least one antenna array composed of a plurality of antenna elements. In terms of hardware, the communication unit (310) may be composed of a digital circuit and an analog circuit (e.g., a radio frequency integrated circuit (RFIC)). Here, the digital circuit and the analog circuit may be implemented as a single package. Additionally, the communication unit (310) may include a plurality of RF chains. Furthermore, the communication unit (310) may perform beamforming.

[0070] The communication unit (310) transmits and receives signals as described above. Accordingly, all or part of the communication unit (310) may be referred to as a 'transmitter', a 'receiver', or a 'transmitter / receiver'. Additionally, in the following description, transmission and reception performed via a wireless channel are used to mean that processing as described above is performed by the communication unit (310).

[0071] The storage unit (320) stores data such as basic programs, application programs, and setting information for the operation of the terminal. The storage unit (320) may be composed of volatile memory, non-volatile memory, or a combination of volatile memory and non-volatile memory. Additionally, the storage unit (320) provides the stored data upon the request of the control unit (330).

[0072] The control unit (330) (or controller) controls the overall operations of the terminal. For example, the control unit (330) transmits and receives signals through the communication unit (310). Additionally, the control unit (330) writes and reads data to and from the storage unit (320). Furthermore, the control unit (330) can perform the functions of the protocol stack required by the communication standard. To this end, the control unit (330) may include at least one processor or microprocessor, or be part of a processor. Additionally, part of the communication unit (310) and the control unit (330) may be referred to as a communication processor (CP).

[0073] According to various embodiments, the control unit (330) can control the terminal to perform operations according to various embodiments described below.

[0074] FIG. 4 illustrates an example of a radio resource domain in a wireless communication system according to embodiments of the present disclosure. In various embodiments of the present disclosure, the radio resource domain may include a structure in a time-frequency domain. According to one embodiment, the wireless communication system may include an NR communication system.

[0075] Referring to FIG. 4, in the wireless resource domain, the horizontal axis represents the time domain and the vertical axis represents the frequency domain. The length of the wireless frame (404) is 10 ms. The wireless frame (404) may be a time domain segment consisting of 10 subframes. The length of the subframe (403) is 1 ms. The constituent unit in the time domain may be an OFDM (orthogonal frequency division multiplexing) and / or DFT-s-OFDM (DFT (discrete Fourier transform)-spread-OFDM) symbol, and N symb A number of OFDM and / or DFT-s-OFDM symbols (401) may be combined to form a single slot (402). According to various embodiments of the present disclosure, OFDM symbols may include symbols for cases where signals are transmitted and received using OFDM multiplexing, and DFT-s-OFDM symbols may include symbols for cases where signals are transmitted and received using DFT-s-OFDM or SC-FDMA (single carrier frequency division multiple access) multiplexing. The minimum transmission unit in the frequency domain is a subcarrier, and the carrier bandwidth constituting the resource grid is a total of N scBW It may be composed of several subcarriers (405). Additionally, for convenience of explanation, an embodiment regarding downlink signal transmission and reception is described in this disclosure, but this is also applicable to an embodiment regarding uplink signal transmission and reception.

[0076] According to one embodiment, the number of slots (402) constituting a single subframe (403) and the length of the slots (402) may vary depending on the subcarrier spacing. This subcarrier spacing may be referred to as numerology (μ). For example, the subcarrier spacing, the number of slots included in the subframe, the length of the slots, and the length of the subframe may be configured variably. For example, in an NR communication system, when the subcarrier spacing (SCS) is 15 kHz, one slot (402) constitutes one subframe (403), and the lengths of the slot (402) and the subframe (403) may each be 1 ms. Additionally, for example, when the subcarrier spacing is 30 kHz, two slots may constitute one subframe (403). In this case, the length of the slot is 0.5 ms and the length of the subframe is 1 ms.

[0077] According to one embodiment, the subcarrier spacing, the number of slots included in a subframe, the length of the slots, and the length of the subframe may be applied variably depending on the communication system. For example, in the case of an LTE system, the subcarrier spacing is 15 kHz, and two slots constitute one subframe, at which time the length of the slots may be 0.5 ms and the length of the subframe may be 1 ms. As another example, in the case of an NR system, the subcarrier spacing (μ) may be one of 15 kHz, 30 kHz, 60 kHz, 120 kHz, 240 kHz, 480 kHz, or 960 kHz, and the number of slots included in one subframe according to the subcarrier spacing (μ) may be 1, 2, 4, 8, 16, 32, or 64.

[0078] In the time-frequency domain, the basic unit of a resource may be a resource element (RE) (406), and the resource element (406) may be represented by an OFDM symbol index and a subcarrier index. A resource block may include multiple resource elements. In an NR system, a resource block (RB) (or physical resource block (PRB)) (407) is N in the frequency domain SC RB It can be defined as n consecutive subcarriers. The number of subcarriers N SC RB = can be 12. The frequency domain may include common resource blocks (CRBs). Physical resource blocks (PRBs) may be defined in the bandwidth part (BWP) in the frequency domain. CRB and PRB numbers may be determined differently depending on the subcarrier interval. In LTE systems, RBs are N in the time domain. symb N consecutive OFDM symbols and N in the frequency domain SC RB It can be defined as a series of consecutive subcarriers.

[0079] In an NR and / or LTE system, scheduling information for downlink data or uplink data may be transmitted from a base station (110) to a terminal (120) via downlink control information (DCI). According to various embodiments of the present disclosure, DCI may be defined according to various formats, each format may indicate whether the DCI includes scheduling information for uplink data (e.g., UL grant), whether it includes scheduling information for downlink data (DL resource allocation), whether it is a compact DCI with a small size of control information, whether it is a fall-back DCI, whether spatial multiplexing using multiple antennas is applied, and / or whether it is a DCI for power control. For example, NR DCI format 1_0 or NR DCI format 1_1 may include scheduling for downlink data. Also, for example, NR DCI format 0_0 or NR DCI format 0_1 ​​may include scheduling for uplink data.

[0080] As described above, FIG. 4 illustrates an example of a downlink and uplink slot structure in a wireless communication system. In particular, FIG. 4 illustrates the structure of a resource grid in a 3GPP NR system. Referring to FIG. 4, a slot may include multiple orthogonal frequency division multiplexing (OFDM) symbols in the time domain and multiple resource blocks (RBs) in the frequency domain. A signal may consist of part or all of the resource grid. Additionally, the number of OFDM symbols generally included in a single slot may vary depending on the length of the cyclic prefix (CP). In FIG. 4, for convenience of explanation, a case in which a single slot consists of 14 OFDM symbols is illustrated, but the configuration of symbols is not specified for the signal referred to in this disclosure. In addition, the modulation method of the generated signal is not limited to a specific value of QAM (Quadrature Amplitude Modulation) and can follow modulation methods of various communication standards such as BPSK (Binary phase-shift keying) and QPSK (Quadrature Phase Shift Keying).

[0081] According to various embodiments of the present disclosure, operations for controlling uplink retransmission for efficient signal transmission are described based on an LTE communication system or an NR communication system, but the contents of the present disclosure are not limited thereto and may be applied to various wireless communication systems for transmitting downlink or uplink control information. Furthermore, it is understood that the contents of the present disclosure may be applied to unlicensed bands in addition to licensed bands as needed.

[0082] In the present disclosure, the higher layer signaling or higher signal may be a signal transmission method transmitted from a base station (110) to a terminal (120) using a physical layer downlink data channel, or from a terminal (120) to a base station (110) using a physical layer uplink data channel. According to one embodiment, the higher layer signaling may include at least one of radio resource control (RRC) signaling, signaling according to an F1 interface between a centralized unit (CU) and a distributed unit (DU), or a signal transmission method transmitted through a medium access control (MAC) control element (MAC CE). Additionally, according to one embodiment, the higher layer signaling or higher signal may include system information, such as a system information block (SIB), that is transmitted commonly to a plurality of terminals (120).

[0083] In a 5G wireless communication system, a synchronization signal block (SSB) (or referred to as an SS block, SS / PBCH block, etc.) may be transmitted for initial access, and the synchronization signal block may consist of a primary synchronization signal (PSS), a secondary synchronization signal (SSS), and a physical broadcast channel (PBCH). Additionally, the SSB may contain information regarding the beam used by the base station to transmit signals; thus, the SSB index or SSB described below may refer to at least one beam. In the initial access phase, when a terminal first accesses the system, the terminal may obtain downlink time and frequency domain synchronization from the synchronization signal and obtain a cell ID through a cell search procedure. The synchronization signal may include the PSS and the SSS. The terminal may receive a PBCH containing a master information block (MIB) from the base station to obtain system information related to transmission and reception, such as system bandwidth or related control information, as well as basic parameter values. Based on the received PBCH, the terminal can obtain a system information block (SIB) by performing decoding on the PDCCH (physical downlink control channel) and PDSCH (physical downlink shared channel). Subsequently, the terminal can exchange identity with the base station through a random access step and initially connect to the network after going through steps such as registration and authentication.

[0084] As described above, one slot may include 14 symbols, and according to various embodiments of the present disclosure, the uplink-downlink configuration of symbols and / or slots in a 5G communication system may be configured in three stages.

[0085] As a first method, the uplink-downlink of symbols and / or slots can be established semi-statically at the symbol level through cell-specific configuration information derived from system information. More specifically, the cell-specific uplink-downlink configuration information derived from system information may include uplink-downlink pattern information and reference subcarrier information. The uplink-downlink pattern information may indicate the pattern periodicity, the number of consecutive downlink slots and the number of symbols in the next slot from the start of each pattern, the number of consecutive uplink slots and the number of symbols in the next slot from the end of the pattern. Slots and symbols not designated as uplink or downlink may be determined as flexible slots / symbols.

[0086] In a second method, through user-specific configuration information via dedicated upper-level signaling, a flexible slot or a slot containing a flexible symbol can be indicated by the number of consecutive downlink symbols from the start symbol of the slot and the number of consecutive uplink symbols from the end of the slot, respectively, or can be indicated by the entire slot downlink or the entire slot uplink.

[0087] As a third method, to dynamically change the downlink signal transmission and uplink signal transmission intervals, symbols designated as flexible symbols in each slot (e.g., symbols not designated as downlink or uplink) can be indicated as downlink symbols, uplink symbols, or flexible symbols through a Slot Format Indicator (SFI) included in the downlink control channel. The Slot Format Indicator can select an index from a pre-set table of uplink-downlink configurations for 14 symbols within a single slot.

[0088] In the following, to facilitate understanding of the method described in this disclosure, packet processing at the PDCP (Packet Data Convergence Protocol) layer of the transmitting end and the PDCP layer of the receiving end will be explained first.

[0089] FIG. 5 is a figure illustrating an example of packet processing in the PDCP layer of a transmitting end and the PDCP layer of a receiving end according to an embodiment of the present disclosure. More specifically, FIG. 5 is a figure relating to packet processing in the PDCP layer in 5G NR.

[0090] Referring to FIG. 5, the transmitting PDCP entity (the PDCP layer of the transmitting end) performs encryption using a PDCP SN (sequence number), and the transmitting PDCP entity can perform sequence numbering on the data PDCP SDU (Service Data Unit) received by the PDCP entity (501). The SN (sequence number) may be a unique serial number assigned to the PDCP SDU. By adding a sequence number to each data block included in the PDCP SDU (Service Data Unit) through sequence numbering, the receiving end can determine the order of the data, whether there is duplication, and the method of combination.

[0091] Afterwards, the transmitting PDCP entity can perform header compression (503),

[0092] Through header compression, the header of a PDCP SDU entering a PDCP entity can be compressed. Robust Header Compression (ROHC) is primarily used for header compression, and transmission efficiency can be increased by reducing the header size.

[0093] Next, encryption can be performed on the PDCP SDU after header compression to protect integrity and the confidentiality of user data (505), and integrity protection and encryption can be performed only on packets associated with the PDCP SDU. Integrity protection ensures that the message was sent and received from the correct source, and encryption prevents eavesdropping on user data from a third party in the wireless section. Since the encryption operations in this operation consume a large amount of computational resources, a hardware accelerator may be used for encryption operations in the mobile communication system. This may also be the case at the receiving end.

[0094] Subsequently, the transmitting PDCP entity adds a PDCP header to the processed PDCP SDU (507), the PDCP header may include (1) information about the SN assigned to the PDCP SDU, (2) a D / C field in bits that distinguish whether the PDU is a Data PDU or a Control PDU in the case of a DRB (Data Radio Bearer) (the D / C field is not added in the case of an SRB (Signaling Radio Bearer) as only a Data PDU is generated), (3) a PDU Type field indicating what kind of Control PDU it is in the case of a PDCP Control PDU, (4) an indicator to distinguish between encrypted data and unencrypted data, (5) information related to encryption or integrity protection (e.g., COUNT value) that may be placed before the PDCP SN field, (6) information related to header compression (ROHC) in the case of user plane (U-plane) data, etc.

[0095] Next, the transmitting PDCP entity can perform routing / replication (509). Routing / replication (509) can improve the reliability and efficiency of data transmission.

[0096] Routing can have the following characteristics.

[0097] (1) Multipath transmission: The PDCP layer can transmit a single data packet over multiple paths. This can be utilized primarily in carrier aggregation (CA) or dual connectivity (DC) environments.

[0098] (2) Path selection: The optimal path can be dynamically selected based on network conditions. This can help reduce network congestion and increase transmission efficiency.

[0099] (3) Load balancing: Network load can be balanced by distributing traffic across multiple paths.

[0100] The replication function can have the following characteristics.

[0101] (1) Packet duplication: The same PDCP PDU can be duplicated and transmitted simultaneously over multiple paths. This can be used primarily in URLLC (Ultra-Reliable Low-Latency Communication) services.

[0102] (2) Improved reliability: Even if packet loss occurs in one path, a duplicate packet transmitted through another path can arrive, so the reliability of transmission can be greatly improved.

[0103] (3) Reduction in latency: By transmitting via multiple paths simultaneously, packets can arrive via the fastest path, which can reduce overall latency.

[0104] (4) Selective application: The replication function is not applied to all data, but can be selectively applied to data that is important or sensitive to delay.

[0105] Subsequently, it is transmitted to the PDCP PDU lower layer and can be delivered to the receiver via the wireless interface.

[0106] The receiving PDCP entity can receive a PDCP PDU that has undergone processing by the receiving lower layer, and first, the PDCP header of the PDCP PDU can be removed (511). At this time, header decompression (517) can be performed without additional processing for packets not associated with the PDCP SDU.

[0107] Additional processing may be performed on packets associated with PDCP SDUs. More specifically, the receiving PDCP entity may perform decryption, which is a process of removing encryption applied at the transmitting end, and integrity verification (513), which is a process of confirming that the data has not been tampered with during transmission.

[0108] Afterwards, the receiving PDCP entity performs reordering, which is a process of sorting packets that have been out of order due to network delays or path differences into the correct order, and duplication, which is a process of identifying and removing duplicate packets (515).

[0109] Afterwards, header decompression can be performed on packets associated with PDCP SDU that have undergone processing (517).

[0110] The PDCP SDU, after decompression, can be passed to the upper layer of the receiving PDCP entity for processing.

[0111] FIG. 6 is a figure illustrating an example of packet processing at the PDCP layer of a transmitting end according to various embodiments of the present disclosure. More specifically, FIG. 6 illustrates packet processing at the PDCP layer of LTE and packet processing at the PDCP layer of 5G NR.

[0112] First, regarding packet processing in the PDCP layer of LTE, the transmitting PDCP entity of LTE (the PDCP layer of the transmitting end) performs encryption using a PDCP SN (sequence number), and the transmitting PDCP entity can perform sequence numbering on the data PDCP SDU (Service Data Unit) that enters the PDCP entity (601). The SN (sequence number) may be a unique serial number assigned to the PDCP SDU. By adding a sequence number to each data block included in the PDCP SDU (Service Data Unit) through sequence numbering, the receiving end can determine the order of the data, whether there is duplication, and the method of combination.

[0113] Afterwards, the LTE transmitter PDCP entity can perform header compression (503),

[0114] Through header compression, the header of a PDCP SDU entering a PDCP entity can be compressed. In the case of LTE, header compression can be performed only on user plane data.

[0115] Next, integrity protection (605) and encryption to protect the confidentiality of user data may be performed on the PDCP SDU for which header compression has been performed (607), and integrity protection (605) and encryption (607) may be performed only on packets associated with the PDCP SDU. Integrity protection (605) ensures that the message was transmitted and received from the correct source, and encryption (607) prevents eavesdropping on user data from a third party in the wireless section. In the case of LTE, integrity protection may be performed only on control plane data. Since the encryption operations in this operation consume a large amount of computational resources, a hardware accelerator may be used for encryption operations in the mobile communication system. This may also be the case at the receiving end.

[0116] Afterwards, the LTE transmitting PDCP entity can add a PDCP header to the processed PDCP SDU (608).

[0117] After 4, the LTE transmitting PDCP entity can perform routing (609). In the case of LTE, routing (609) can be performed only on user plane data.

[0118] Next, regarding packet processing at the PDCP layer of NR, the transmitting PDCP entity of NR (the PDCP layer of the transmitting end) performs encryption using a PDCP SN (sequence number), and the transmitting PDCP entity can perform sequence numbering on the data PDCP SDU (Service Data Unit) that enters the PDCP entity (611). The SN (sequence number) may be a unique serial number assigned to the PDCP SDU. By adding a sequence number to each data block included in the PDCP SDU (Service Data Unit) through sequence numbering, the receiving end can determine the order of the data, whether there is duplication, and the method of combination.

[0119] Afterwards, the transmitting PDCP entity can perform header compression (613),

[0120] Through header compression, the header of a PDCP SDU entering a PDCP entity can be compressed. Robust Header Compression (ROHC) is primarily used for header compression, and transmission efficiency can be increased by reducing the header size.

[0121] Next, for the PDCP SDU that has undergone header compression, encryption can be performed to protect integrity and the confidentiality of user data (615), and integrity protection and encryption can be performed only on packets associated with the PDCP SDU. Integrity protection ensures that the message was sent and received from the correct source, and encryption prevents eavesdropping on user data from a third party in the wireless section. Since the encryption operations in this operation consume a lot of computational resources, a hardware accelerator may be used for encryption operations in mobile communication systems. This may also be the case at the receiving end. In the case of NR, the implementation of full rate user plane (UP) integrity protection (UPIP) is mandatory to protect mobile communication data more securely (the use of UPIP is optional), and most mobile operators generally use full rate UPIP to provide a higher level of security to users.

[0122] Afterwards, the transmitting PDCP entity of the NR can add a PDCP header to the processed PDCP SDU (617).

[0123] Next, regarding packet processing at the PDCP layer of the NR, the transmitting PDCP entity of the NR can perform routing / replication (619). Routing / replication (619) can improve the reliability and efficiency of data transmission.

[0124] The base station can activate security with the terminal under the direction of the session management function (SMF). If the SMF instructs the base station to use integrity protection and encryption as a security policy, the base station can activate access stratum security to avoid violating said policy. Since packet security at the access stratum is handled by the PDCP layer, as explained earlier, between the base station and the terminal, the transmitting PDCP layer sequentially performs integrity protection and encryption to transmit the encrypted packet to the receiving end. When the receiving end receives the encrypted packet, it performs decryption and integrity verification on the encrypted packet.

[0125] As mentioned above, applying full-rate user plane integrity protection (UPIP) to control plane (CP) related data and all user plane (UP) related data at the PDCP layer may lead to an increase in computational overhead. In other words, compared to cases where integrity protection is applied only to control plane related data, or to control plane related data and some user plane data, the computational overhead of the base station and the terminal may increase when full-rate user plane integrity protection (UPIP) is applied to all user plane (UP) related data. This increased computational load may significantly consume the computational resources of the base station / terminal, thereby reducing the overall packet processing capability of the base station / terminal.

[0126] In addition, a potential problem arising from performing both integrity protection and encryption is a bus bottleneck for packet transmission.

[0127] Referring to Fig. 7, a bus bottleneck, which is a problem that can occur when both integrity protection and encryption are performed, is explained.

[0128] Figure 7 is a diagram illustrating the bus bottleneck phenomenon, which is a problem that can occur when both integrity protection and encryption are performed.

[0129] Referring to FIG. 7, among the sequence numbering (701), header compression (703), integrity protection (705), encryption (706), PDCP header addition (707), and routing / replication (709) performed by the transmitting PDCP entity, packet bottlenecks due to integrity protection (705) and encryption (706) are illustrated. As shown in FIG. 7, data exchange between the transmitting memory (710), CPU (720), and HW accelerator (730) may be required to perform integrity protection (705) and encryption (706).

[0130] More specifically, during the integrity protection (705) process, the memory (710) transmits a data packet to the CPU (720) (711), and the CPU (720) can transmit the received data packet to the HW accelerator (730) (721). Subsequently, the HW accelerator (730) performs integrity protection (731) on the received data packet and can transmit the data packet with integrity protection (731) applied to it to the CPU (720) (723). The CPU (720) can transmit the received packet with integrity protection (731) applied to it to the memory (710) (713). When the memory (710) receives the packet with integrity protection (731) applied from the CPU (720), the procedure for applying integrity protection (731) to the data packet can be terminated. It can be seen that a total of four data exchanges are performed during the procedure for applying integrity protection (731) to the data packet.

[0131] Next, during the encryption (706) process, the memory (710) transmits the data packet to the CPU (720) (715), and the CPU (720) can transmit the received data packet to the HW accelerator (730) (725). Afterwards, the HW accelerator (730) performs encryption (723) on the received data packet and can transmit the data packet with encryption protection (733) applied to the CPU (720) (727). The CPU (720) can transmit the received packet with encryption (733) applied to the memory (710) (717). When the memory (710) receives the packet with encryption (733) applied from the CPU (720), the procedure for applying encryption (733) to the data packet can be terminated. It can be seen that a total of four data exchanges are performed during the procedure for applying encryption (733) to the data packet.

[0132] As a result, it can be seen that a total of 8 data exchanges are performed in order for both the integrity protection (705) process and the encryption (706) process to be performed. Such repeated bus occupation causes a bottleneck in the internal system bus section, and as a result, packet processing performance may be degraded.

[0133] The above-mentioned problems can occur in the same way during the process of verifying integrity and performing decoding at the receiving end.

[0134] This disclosure describes measures to resolve the previously described problem of increased computational overhead for processing per packet and the problem of bottlenecks occurring in bus segments. More specifically, this disclosure describes a method for enhancing packet processing performance at a base station by introducing a new type of security algorithm used at the base station access layer and defining a procedure that enables the use of the new security algorithm.

[0135] More specifically, as a method to resolve the problem of increased computational overhead for processing per packet, an integrated integrity and encryption approach is introduced to reduce the amount of computation required for processing per packet at the base station. In particular, the integrated integrity and encryption approach refers to a method in which the integrity protection procedure and the encryption procedure, which were previously performed sequentially as separate processes, are executed as a single integrated procedure. That is, when the integrated integrity and encryption approach is applied to a data packet, the data packet can be transformed into a form substantially identical to a data packet in which both integrity protection and encryption processing have been performed. When the relevant integrated integrity and encryption approach is used, since both integrity protection and encryption processing can be applied through a single procedure, the amount of computation can be reduced compared to a method in which the integrity protection procedure and the encryption procedure are performed as two separate procedures. A detailed explanation of the integrated integrity and encryption approach will be provided below.

[0136] Additionally, an example of a method integrating integrity and encryption may be authenticated encryption (AE). In this case, authenticated encryption (AE) may include authenticated encryption with associated data (AEAD), key-committing AEAD, etc. The inverse process of a method integrating integrity and encryption may be a method integrating integrity verification and decryption. An example of a method integrating integrity verification and decryption, which is the inverse process of a method integrating integrity and encryption, may be authenticated decryption (AD). In this case, authenticated decryption (AD) may include authenticated decryption with associated data (ADAD), key-committing ADAD, etc. In particular, detailed security algorithms that can be used in the AEAD method include AES-GCM (Advanced Encryption Standard - Galois / Counter Mode) and AES-CCM (Advanced Encryption Standard - Counter with CBC-MAC).

[0137] More specifically, AES-GCM can be used to simultaneously provide data confidentiality (encryption) and integrity (authentication), and by supporting additional authentication data (AAD), authentication of unencrypted data may also be possible. In the case of AES-GCM, encryption is performed using the AES block cipher in counter mode, and an authentication tag is generated using the Galois field GF(2^128) operation. It receives four inputs (AES key, initialization vector (IV), plaintext, and optional AAD) and can generate two outputs (ciphertext and authentication tag) based on the four inputs. Additionally, AES-CCM can provide both data confidentiality (encryption) and integrity (authentication) simultaneously, and can also enable authentication of unencrypted data by supporting additional authentication data (AAD). AES-CCM may be a method that combines Counter mode (CTR) and Cipher Block Chaining-Message Authentication Code (CBC-MAC), and can generate two outputs (ciphertext and Message Authentication Code (MAC)) by receiving four inputs (AES key, nonce, plaintext, and optional AAD).

[0138] As a method to resolve the problem of bottlenecks in bus sections caused by bus occupancy, the present disclosure describes a method for reducing the number of bus occupancy attempts required per packet for integrity protection and encryption.

[0139] FIG. 8 is a figure illustrating an integrity protection and encryption method with reduced bus occupancy of data packets according to an embodiment of the present disclosure.

[0140] Referring to FIG. 8, the memory (810) transmits a data packet to the CPU (820) (811), and the CPU (820) can transmit the received data packet to the HW accelerator (830) (821). Subsequently, the HW accelerator (830) can sequentially perform integrity protection (831) and encryption (833) on the received data packet (831). Here, the method of sequentially performing integrity protection (831) and encryption (833) on the received data packet may be referred to as sequential encryption operation.

[0141] Next, the HW accelerator (830) can transmit a data packet in which integrity protection (831) and encryption (833) are performed sequentially to the CPU (820) (823). The CPU (820) can transmit the received data packet in which integrity protection (831) and encryption (833) are performed sequentially to the memory (810) (813). By the memory (810) receiving the data packet in which integrity protection (831) and encryption (833) are performed sequentially from the CPU (820), the procedure for applying integrity protection and encryption to the data packet can be terminated. According to the method according to FIG. 8, it can be seen that a total of 4 data exchanges are performed during the procedure for applying integrity protection and encryption to the data packet, and the number of bus occupancy events is reduced by half compared to the method of FIG. 7, which required a total of 8 data exchanges, thereby resolving the problem of bottlenecking caused by bus occupancy.

[0142] In addition, as another method to resolve the bottleneck problem in the bus section caused by bus occupancy, an integrated integrity and encryption method may be used. That is, as the integrity protection procedure and the encryption procedure, which were previously performed sequentially as separate procedures, are performed as a single integrated procedure, the number of data packet exchanges between memory, CPU, and HW accelerator can be reduced.

[0143] FIG. 9 is a figure showing an example of data packet exchange to which a method integrating integrity and encryption according to an embodiment of the present disclosure is applied.

[0144] Referring to FIG. 9, the memory (910) transmits a data packet to the CPU (920) (911), and the CPU (920) can transmit the received data packet to the HW accelerator (930) (921). Subsequently, the HW accelerator (830) can perform an integrated integrity and encryption method on the received data packet (931). Here, the data packet can be converted into a data packet that is substantially the same form as a data packet in which both integrity protection processing and encryption processing have been performed.

[0145] Next, the HW accelerator (930) can transmit a data packet in which an integrity and encryption method is performed to the CPU (920) (923). The CPU (920) can transmit the received data packet in which an integrity and encryption method is performed to the memory (910) (913). When the memory (910) receives the data packet in which an integrity and encryption method is performed from the CPU (920), the procedure for integrity protection and encryption application to the data packet can be terminated. According to the method according to FIG. 9, it can be seen that a total of 4 data exchanges are performed during the security procedure based on an integrity and encryption method for the data packet, and the number of bus occupancy events is reduced by half compared to the method of FIG. 7, which required a total of 8 data exchanges, thereby resolving the bottleneck problem caused by bus occupancy.

[0146] Figures 8 and 9 describe cases where sequential integrity protection and encryption are performed in the HW accelerator, or where integrity and encryption are integrated in the HW accelerator, but the problem of bottlenecks caused by bus occupancy can also be resolved by various other variations.

[0147] First, FIGS. 10 and 11 illustrate an example of a method that can reduce the number of bus occupancy cycles for data packet processing without sequentially performing integrity protection and encryption when a security procedure based on integrity protection and encryption is performed.

[0148] Referring to FIG. 10, memory (1010) transmits a data packet to CPU (1020) (1011), CPU (1020) performs integrity protection (1021) on the received data packet, and can transmit the data packet with integrity protection (1021) applied to memory (1010) (1013). When memory (1010) receives the packet with integrity protection (1021) applied by CPU (1020) from CPU (1020), the procedure for applying integrity protection (1021) to the data packet can be terminated. By having the integrity protection (1021) applied by CPU (1020) rather than HW accelerator (1030), it can be seen that only a total of two data exchanges are performed during the procedure for applying integrity protection (1021) to the data packet.

[0149] Next, during the encryption process, the memory (1010) transmits a data packet to the CPU (1020) (1015), and the CPU (1020) can transmit the received data packet to the HW accelerator (1030) (1023). Subsequently, the HW accelerator (1030) performs encryption (1031) on the received data packet and can transmit the data packet with the encryption (1031) applied to it to the CPU (1020) (1025). The CPU (1020) can transmit the received packet with the encryption (1031) applied to it to the memory (1010) (1017). When the memory (1010) receives the packet with the encryption (1031) applied from the CPU (1020), the procedure for applying encryption (1031) to the data packet can be terminated. It can be seen that a total of 4 data exchanges are performed during the procedure for applying encryption (1031) to the data packet.

[0150] As a result, it can be seen that according to the method of Fig. 10, a total of 6 data exchanges are performed to execute both the integrity protection process and the encryption process. Compared to the method of Fig. 7, which required a total of 8 data exchanges, the number of bus occupancy attempts is reduced by 2, thereby resolving the bottleneck issue caused by bus occupancy.

[0151] Next, referring to FIG. 11, in the integrity protection process, the memory (1110) transmits a data packet to the CPU (1120) (1111), and the CPU (1120) can transmit the received data packet to the HW accelerator (1130) (1121). Afterwards, the HW accelerator (1130) performs integrity protection (1131) on the received data packet and can transmit the data packet with integrity protection (1131) applied to it to the CPU (1120) (1123). The CPU (1120) can transmit the received packet with integrity protection (1131) applied to it to the memory (11110) (1113). When the memory (1110) receives the packet with integrity protection (1131) applied from the CPU (1120), the procedure for applying integrity protection (1131) to the data packet can be terminated. It can be seen that a total of 4 data exchanges are performed during the procedure for applying integrity protection (1131) to the data packet.

[0152] Next, during the encryption process, the memory (1110) transmits a data packet to the CPU (1120) (1115), the CPU (1120) performs encryption (1125) on the received data packet, and can transmit the data packet with the encryption (1125) applied to the memory (1110) (1117). When the memory (1110) receives the packet with the encryption (1125) applied from the CPU (1120), the procedure for applying encryption (1125) to the data packet can be terminated. It can be seen that a total of two data exchanges are performed during the procedure for applying encryption (1125) to the data packet.

[0153] Consequently, it can be seen that according to the method of Fig. 11, a total of 6 data exchanges are performed to execute both the integrity protection process and the encryption process. Compared to the method of Fig. 7, which required a total of 8 data exchanges, the number of bus occupancy attempts is reduced by 2, thereby resolving the bottleneck issue caused by bus occupancy.

[0154] FIG. 12 is a figure showing another example of a method to reduce the number of bus occupancy attempts based on security procedures based on integrity protection and encryption performed sequentially.

[0155] Referring to FIG. 12, the memory (1210) transmits a data packet to the CPU (1220) (1211), and the CPU (1220) can sequentially perform integrity protection and encryption on the received data packet (1221). Here, the method of sequentially performing integrity protection and encryption on the received data packet may be referred to as sequential encryption operation.

[0156] Next, the CPU (1220) can transmit a data packet to the memory (1210) in which integrity protection and encryption have been sequentially performed (1221) (1213). When the memory (1210) receives the data packet in which integrity protection and encryption have been sequentially performed (1221) from the CPU (1220), the procedure for applying integrity protection and encryption to the data packet can be terminated. According to the method according to FIG. 12, it can be seen that a total of 2 data exchanges are performed during the procedure for applying integrity protection and encryption to the data packet, and the number of bus occupancy events is reduced to 1 / 4 compared to the method of FIG. 7, which required a total of 8 data exchanges, thereby resolving the bottleneck problem caused by bus occupancy.

[0157] Figure 13 is a figure showing another example of a method to reduce the number of bus occupancy attempts based on a security procedure based on an integrated method of integrity and encryption.

[0158] Referring to FIG. 13, the memory (1310) transmits a data packet to the CPU (1320) (1311), and the CPU (1320) can perform an integrated integrity and encryption method on the received data packet (1321).

[0159] Next, the CPU (1320) can transmit a data packet to the memory (1310) in which an integrity and encryption integrated method is performed (1321) (1313). When the memory (1310) receives the data packet in which integrity protection and encryption are performed sequentially (1321) from the CPU (1320), the security procedure based on the integrity and encryption integrated method can be terminated. According to the method according to FIG. 13, it can be seen that a total of 2 data exchanges are performed during the procedure for applying integrity protection and encryption to the data packet, and the number of bus occupancy events is reduced to 1 / 4 compared to the method of FIG. 7, which required a total of 8 data exchanges, thereby resolving the bottleneck problem caused by bus occupancy.

[0160] As described above, communication between a terminal and a base station may involve the application of either a security procedure based on integrity protection and encryption or a security procedure based on an integrated method of integrity and encryption; therefore, a security policy instruction procedure that considers compatibility based on the security capabilities of the base station and the terminal may be required. This disclosure describes a security policy instruction procedure that considers compatibility based on the security capabilities of the base station and the terminal. Basically, the security policy instruction procedure described in this disclosure may be performed in such a manner that the base station receives security policy rules from the SMF, and applies either a security procedure based on integrity protection and encryption or a security procedure based on an integrated method of integrity and encryption, provided that such application does not violate the security policy rules.

[0161] That is, according to an embodiment of the present disclosure, the application of security at the access layer may include a procedure in which a mobile communication system selects an appropriate security policy for each control plane (CP) (e.g., radio resource control, RRC layer) and user plane (UP) by considering the performance (UE security capability) of the terminal. At this time, the mobile communication system may instruct an appropriate algorithm type to be applied to a base station by considering the security capability of the terminal, within a range that does not violate the security policy instructed by the core network (CN). Subsequently, the base station and the terminal can activate security.

[0162] The security procedure according to the embodiment of the present disclosure includes a procedure for directing and determining security policies in CP and UP sections. Since a procedure for considering the security capability of a terminal is also necessary for directing and determining security policies in CP and UP sections, the procedure for considering the security capability of the terminal is also included. Furthermore, the security procedure according to the embodiment of the present disclosure includes a process for generating a key by considering an integrated method of integrity and encryption, a detailed method for encrypting data, and a method for setting parameters. Additionally, according to the embodiment of the present disclosure, various PDCP packet formats that can be used when an integrated method of integrity and encryption is applied may also be defined.

[0163] FIG. 14 is a flowchart illustrating an example of a security policy application procedure in an access section according to an embodiment of the present disclosure.

[0164] Referring to FIG. 14, a base station (1420) may receive terminal security capability information (1411, 1431). At this time, the terminal security capability information received by the base station (1420) may be information transmitted by the terminal (1410) to the base station (1420), or information transmitted by the core network (1430) to the base station (1420). Alternatively, both the terminal (1410) and the core network (1430) may transmit terminal security capability information to the base station (1420). The core network (1430) may be an access mobility function (AMF) in operations related to the control plane and a session management function (SMF) in operations related to the user plane. The AMF and SMF may also be referred to as network function (NF1) and network function (NF2), respectively.

[0165] Here, terminal security capability information may include information regarding the types of security procedures supported by the terminal. More specifically, terminal security capability information may indicate (1) that the terminal supports security procedures based on integrity protection and encryption, (2) that the terminal supports security procedures based on an integrated method of integrity and encryption, (3) that the terminal supports both security procedures based on integrity protection and encryption and security procedures based on an integrated method of integrity and encryption, or (4) that the terminal does not support any of security procedures based on integrity protection and encryption and security procedures based on an integrated method of integrity and encryption. Additionally, security procedures to which only integrity protection is applied and / or security procedures to which only encryption is applied may be defined, and terminal security capability information may indicate (5) that the terminal supports security procedures to which only integrity protection is applied, or (6) that the terminal supports security procedures to which only encryption is applied.

[0166] Additionally, if the base station does not receive terminal security capability information, the base station may expect that the terminal does not support either security procedures based on integrity protection and encryption or security procedures based on an integrated method of integrity and encryption.

[0167] Next, the base station (1420) can receive a security policy for the control plane / user plane for establishing a PDU (protocol data unit) session from the core network (1430) (1433). Since the core network (1430) can determine in advance which security procedures are supported at the terminal (1410), the core network (1430) can determine a security policy for the control plane / user plane based on the types of security procedures supported at the terminal (1410) and transmit it to the base station (1420). More specifically, a security policy that can be instructed to the base station (1420) by the core network (1430) according to the types of security procedures supported at the terminal (1410) can be configured as follows.

[0168] 1) Where terminal security capability information indicates that the terminal supports security procedures based on integrity protection and encryption: the security policy may direct at least one of (1) security procedures to which only integrity protection is applied, (2) security procedures to which only encryption is applied, or (3) security procedures based on integrity protection and encryption.

[0169] 2) Where terminal security capability information indicates that the terminal supports security procedures based on a method that integrates integrity and encryption: the security policy may (1) direct security procedures based on a method that integrates integrity and encryption.

[0170] 3) Where terminal security capability information indicates that the terminal supports both security procedures based on integrity protection and encryption and security procedures based on a method that integrates integrity and encryption: the security policy may indicate at least one of (1) a security procedure to which only integrity protection is applied, (2) a security procedure to which only encryption is applied, or (3) a security procedure based on integrity protection and encryption, or (4) a security procedure based on a method that integrates integrity and encryption.

[0171] 4) Where the terminal security capability information indicates that the terminal does not support security procedures based on integrity protection and encryption, or security procedures based on an integrated method of integrity and encryption: the security policy may not direct any security procedures. Or, to reduce signaling overhead, in this case, the procedure for the core network to transmit the security policy to the base station may be omitted.

[0172] Subsequently, the base station (1420) can determine the type of algorithm to be used in the security procedure based on the security policy of the control plane / user plane (1421). At this time, the terminal security capability may be considered when determining the type of algorithm to be used in the security procedure. More specifically, if the range of the security procedure instructed to the base station (1420) exceeds the range of the security procedure supported by the terminal (1410), the base station (1420) can determine the type of algorithm to be used in the security procedure within the range of the terminal (1410)'s security capability. For example, if the terminal (1410) transmits terminal security capability information to the base station (1420) indicating that the terminal supports a security procedure based on a method that integrates integrity and encryption, and if the security policy received by the base station (1420) from the core network (1430) directs both a security procedure based on integrity protection and encryption and a security procedure based on a method that integrates integrity and encryption, the base station (1420) can determine the algorithm used in the security procedure based on a method that integrates integrity and encryption as an algorithm type.

[0173] Next, the base station (1420) can perform a control plane / user plane security activation mechanism with the terminal (1410) (1413). Through this, access layer security can be activated. Here, the security procedure used for access layer security may be a security procedure based on integrity protection and encryption, or a security procedure based on an integrated method of integrity and encryption.

[0174] In FIG. 14, for convenience of explanation, the control plane security policy application / activation operation and the user plane security policy application / activation operation are shown as being performed in parallel, but the user plane security policy application / activation operation may be performed after the control plane security policy application / activation operation is completed.

[0175] Hereinafter, with reference to FIG. 15, a security activation procedure based on a method integrating control plane (RRC section) integrity and encryption is described.

[0176] FIG. 15 is a flowchart illustrating an example of a security activation procedure based on a control plane integrity and encryption method according to an embodiment of the present disclosure. The security activation procedure based on a method of integrity and encryption may be a procedure performed in advance to apply security processing based on a method of integrity and encryption to uplink / downlink messages related to the RRC layer.

[0177] Additionally, the operations illustrated in FIG. 15 may be operations that can be performed when the control plane security policy received by the base station (1420) from the core network (1430) in the operation 1433 of FIG. 14 directs a security procedure based on a method in which integrity and encryption are integrated.

[0178] First, the base station (1520) (gNB, ng-eNB) can initiate protection based on a method that integrates integrity and encryption in the RRC section.

[0179] Next, the base station (1520) may transmit an AS security mode command to the terminal (1510) (1511), the AS security mode command may include information about a security algorithm used in a security procedure based on a method that integrates integrity and encryption, and an authentication tag (Auth Tag) related to the data to be transmitted. The authentication tag may be used to ensure the integrity and authentication of the message in the PDCP security procedure. The authentication tag may perform the following functions.

[0180] (1) Message integrity verification: Through the authentication tag, the receiving end can verify that the message has not been tampered with during transmission.

[0181] (2) Sender authentication: A valid authentication tag can prove that the transmitted message actually came from the expected sender.

[0182] (3) Prevention of replay attacks: Replay attacks can be prevented by using a unique authentication tag for each message.

[0183] At the transmitting end, an authentication tag can be attached to the encrypted data, and at the receiving end, the integrity and authentication of the received message can be verified by comparing the received authentication tag with an authentication tag calculated by the receiving end itself.

[0184] Returning to Fig. 15, the base station (1520) can start downlink protection in the RRC section (1525).

[0185] The terminal (1510) can perform verification of the AS security mode command received from the base station (1520) (1513). More specifically, the terminal (1510) can verify the received data and the authentication tag. At this time, if the terminal (1510) succeeds in the verification, it can start protection in the RRC section.

[0186] Afterwards, the terminal (1510) can transmit AS security mode completion to the base station (1520) (1515), and the AS security mode completion may include an authentication tag for verification.

[0187] Next, the terminal (1510) can start uplink protection of the RRC section (1517).

[0188] Additionally, the base station (1520) can verify the authentication tag for the completion of the AS security mode received from the terminal, and if the verification is successful, it can start uplink protection in the RRC section.

[0189] In FIG. 15, the initiation of downlink protection and uplink protection in the RRC section based on an integrated integrity and encryption method may mean that a security procedure based on an integrated integrity and encryption method is activated / applied to the transmission and reception of downlink and uplink messages in the RRC section. When a security procedure based on an integrated integrity and encryption method is activated, security processing based on an integrated integrity and encryption method may be performed on uplink and downlink messages related to the RRC layer.

[0190] Below, the procedure for applying a user plane security policy is described with reference to FIG. 16.

[0191] FIG. 16 is a flowchart illustrating an example of a user plane security policy application procedure according to an embodiment of the present disclosure.

[0192] The base station (1620) can receive a security policy of the user plane for establishing a PDU (protocol data unit) session from the SMF (session management function) (1630) (1631).

[0193] Subsequently, the base station (1620) can determine the type of algorithm to be used in the security procedure based on the security policy of the instructed user plane (1621). At this time, the determination of the algorithm type can be selected within a range that does not violate the instructed security policy. For example, if the security policy instructs both a security procedure based on integrity protection and encryption and a security procedure based on an integrated method of integrity and encryption, the base station (1620) may choose integrity protection and encryption instead of the integrated method of integrity and encryption, and vice versa.

[0194] Next, the base station (1620) can perform a user plane security activation mechanism with the terminal (1610) (1611). Through this, user plane security can be activated. Here, the security procedure used for user plane security may be a security procedure based on integrity protection and encryption, or a security procedure based on an integrated method of integrity and encryption.

[0195] Hereinafter, the security activation procedure in the user plane will be described with reference to FIG. 17.

[0196] FIG. 17 is a flowchart illustrating an example of a security activation procedure in a user plane according to an embodiment of the present disclosure. The security activation procedure in a user plane may be a procedure performed in advance to apply security processing to uplink / downlink messages associated with the user plane.

[0197] FIG. 17 relates to an RRC connection reconfiguration procedure used to add a data radio bearer (DRB), and as a prerequisite, the condition that RRC security is enabled as part of an AS security mode command procedure may be satisfied. At this time, the enabled RRC security may be a security procedure based on integrity protection and encryption or a security procedure based on an integrated method of integrity and encryption (1721).

[0198] The base station (1720) may transmit an RRC connection reconfiguration message for UP security activation to the terminal (1710), including instructions for activating UP security protection (a security procedure based on a method that integrates integrity and encryption) for each DRB according to a security policy (1723).

[0199] Afterward, the base station (1720) can, for each DRB, initiate uplink UP security protection (security procedure based on a method integrating integrity and encryption) verification and downlink UP security protection (security procedure based on a method integrating integrity and encryption) protection when UP security protection (security procedure based on a method integrating integrity and encryption) is activated (1725). At this time, if the base station (1720) does not possess a security key (K_UP) for UP security protection (security procedure based on a method integrating integrity and encryption), the base station (1720) must generate a security key, and UP security protection for the DRB corresponding to the generated security key can be initiated by the base station.

[0200] Next, the terminal (1710) can verify the RRC connection reconfiguration message (1711). At this time, if the verification of the RRC connection reconfiguration message is successful, UP security protection (a security procedure based on a method integrating integrity and encryption) can be activated for each DRB as indicated in the RRC connection reconfiguration message. When UP security protection (a security procedure based on a method integrating integrity and encryption) is activated, uplink UP security protection and downlink UP security verification can be initiated. Here, if the terminal (1710) does not possess a security key (K_UP) for UP security protection, the terminal (1710) can generate a security key, and UP security protection for the DRB corresponding to the generated security key can be initiated by the terminal (1710).

[0201] Finally, the terminal (1710) can send an RRC connection reconfiguration completion message to the base station (1720).

[0202] Hereinafter, the key hierarchy of keys used in the security procedure described in the present disclosure is described.

[0203] The key hierarchy used in PDCP security procedures consists of multiple stages, and a key for a specific purpose can be generated at each stage. This key hierarchy can enhance security and enable efficient key management.

[0204] The key components in the key hierarchy may include the Root Key, Intermediate Keys, PDCP Encryption Key, and PDCP Integrity Protection Key. Here, the Root Key is the highest-level key that serves as the basis for generating all other keys and is typically a permanent key stored on the USIM card. Additionally, Intermediate Keys are keys derived from the Root Key and can be used for secure communication between various elements of the network. The PDCP Encryption Key and Integrity Protection Key are derived from the Base Station Key (KgNB) among the Intermediate Keys and can be used for data encryption at the PDCP layer; furthermore, a unique Encryption Key and Integrity Protection Key may be assigned to each Radio Bearer.

[0205] FIG. 18 is a figure illustrating an example of a key structure according to one embodiment of the present disclosure. More specifically, FIG. 18 is a figure illustrating a key structure that can be used when applying a security procedure based on integrity protection and encryption.

[0206] Referring to FIG. 18, the intermediate key K gNB and K, a key for integrity protection in the RRC layer (control plane) from the intermediate key NH (Next Hop) keyRRCint (1821), K, the key for encryption in the RRC layer (control plane) RRCenc (1823), K, a key for integrity protection in the user plane UPint (1831), K, a key for encryption in the user plane UPenc (1833) can be generated. That is, a total of 4 control plane / user plane keys can be generated.

[0207] FIG. 19 is a figure illustrating an example of a key structure according to one embodiment of the present disclosure. More specifically, FIG. 19 is a figure illustrating a key structure that can be used when applying a security procedure based on a method in which integrity and encryption are integrated.

[0208] Referring to FIG. 19, the intermediate key K gNB and K, a key (RRC security key) used for security procedures based on an integrated method of integrity and encryption at the RRC layer (control plane) from the intermediate key NH (Next Hop) key. RRC (1821), K, a key (UP security key) used for security procedures based on a method that integrates integrity and encryption in the user plane. UP (1831) can be generated. That is, a total of 2 control plane / user plane keys can be generated. Accordingly, the number of cryptographic function executions can be reduced from 2 to 1, and the number of key derivations can be reduced from 2 to 1.

[0209] According to an embodiment of the present disclosure, an RRC integrity key or an RRC encryption key can be used as an RRC security key in a security procedure based on a method that integrates integrity and encryption, and an UP integrity key or an UP encryption key can be used as an UP security key in a security procedure based on a method that integrates integrity and encryption.

[0210] FIG. 20 is a figure illustrating an example of a key generation procedure according to one embodiment of the present disclosure. More specifically, FIG. 20 is a figure illustrating a key generation procedure that can be used when applying a security procedure based on integrity protection and encryption.

[0211] Referring to FIG. 20, there are four Key Derivation Functions (KDFs) for key generation (2011), and from the four KDFs, a key for user plane integrity protection, a key for user plane encryption, a key for control plane integrity protection, and a key for control plane encryption can be generated, respectively (2013). As input values ​​for the four KDFs, the intermediate key K gNB The algorithm and algorithm ID corresponding to each KDF can be input. The keys generated in operation 2013 can be truncated to form a 128-bit long key.

[0212] FIG. 21 is a figure illustrating an example of a key generation procedure according to one embodiment of the present disclosure. More specifically, FIG. 21 is a figure illustrating a key generation procedure that can be used when applying a security procedure based on a method in which integrity and encryption are integrated.

[0213] Referring to FIG. 21, there are two Key Derivation Functions (KDFs) for key generation (2111), and a user plane security key and a control plane security key can be generated from the two KDFs, respectively (2113). As input values ​​for the two KDFs, an intermediate key K gNB The algorithm and algorithm ID corresponding to each KDF can be input. The keys generated in the 2113 operation can be truncated to form a 128-bit long key.

[0214] FIG. 22 is a diagram illustrating an algorithm used in a security procedure based on a method that integrates integrity and encryption according to one embodiment of the present disclosure.

[0215] Referring to FIG. 22, input parameters for the encryption algorithm may include the message itself (i.e., MESSAGE), a 128-bit key for a method of integrating integrity and encryption named KEY, a 32-bit COUNT, a 5-bit bearer identifier BEARER, a 1-bit direction of transmission (i.e., uplink / downlink DIRECTION), and the required key stream length (i.e., LENGTH).

[0216] FIG. 23 is a diagram illustrating a PDCP packet format that can be used when a security procedure based on an integrated integrity and encryption method according to one embodiment of the present disclosure is applied.

[0217] The PDCP PDU formats 2310 to 2326 illustrated in FIG. 23 are byte-aligned bit sequences and their lengths can be multiples of 8 bits. Additionally, the Auth Tag can be truncated based on the most significant bit. Generally, 4 octets are used for the PDCP Auth Tag, but the Auth Tag in the PDCP PDU format illustrated in FIG. 23 may use i+1 octets (N-(Ni)+1).

[0218] The PDCP PDU format described in 2310 may be for an SRB, the PDCP PDU format described in 2320 is a PDCP data PDU format containing a 12-bit PDCP SN (sequence number), the PDCP PDU format described in 2330 is a PDCP data PDU format for a DRB containing an 18-bit PDCP SN (sequence number), the PDCP PDU format described in 2340 is a PDCP data PDU format for sidelink SRB1, SRB2, and SRB3 for unicast, the PDCP PDU format described in 2350 is a PDCP data PDU format for sidelink DRBs for unicast containing a 12-bit PDCP SN, and the PDCP PDU format described in 2360 is a PDCP data PDU format for sidelink DRBs for unicast containing an 18-bit PDDCP SN.

[0219] FIG. 24 is a figure showing an example of packet processing at the PDCP layer of the transmitting end and the PDCP layer of the receiving end, to which a security procedure based on a method integrating integrity and encryption according to an embodiment of the present disclosure is applied.

[0220] Referring to FIG. 24, the transmitting PDCP entity (the PDCP layer of the transmitting end) performs encryption using a PDCP SN (sequence number), and the transmitting PDCP entity can perform sequence numbering on the data PDCP SDU (Service Data Unit) received by the PDCP entity (2411). The SN (sequence number) may be a unique serial number assigned to the PDCP SDU. By adding a sequence number to each data block included in the PDCP SDU (Service Data Unit) through sequence numbering, the receiving end can determine the order of the data, whether there is duplication, and the method of combination.

[0221] Afterwards, the transmitting PDCP entity can perform header compression (2413),

[0222] Through header compression, the header of a PDCP SDU entering a PDCP entity can be compressed. Robust Header Compression (ROHC) is primarily used for header compression, and transmission efficiency can be increased by reducing the header size.

[0223] Next, a security procedure (security processing) based on an integrated integrity and encryption method can be applied to a PDCP SDU in which header compression has been performed (2415), and the security procedure based on an integrated integrity and encryption method can be performed only on packets associated with the PDCP SDU. By applying the security procedure based on an integrated integrity and encryption method, it can be guaranteed that the message was sent and received from the correct source, and eavesdropping on user data from a third party in the wireless section can be prevented.

[0224] Subsequently, the transmitting PDCP entity adds a PDCP header to the processed PDCP SDU (2417), the PDCP header may include (1) information about the SN assigned to the PDCP SDU, (2) a D / C field in bits that distinguish whether the PDU is a Data PDU or a Control PDU in the case of a DRB (Data Radio Bearer) (the D / C field is not added in the case of an SRB (Signaling Radio Bearer) as only a Data PDU is generated), (3) a PDU Type field indicating what kind of Control PDU it is in the case of a PDCP Control PDU, (4) an indicator to distinguish between data to which a security procedure based on an integrity and encryption method is applied and data to which a security procedure based on an integrity and encryption method is not applied, (5) information related to this (e.g., COUNT value) may be placed before the PDCP SN field when a security procedure based on an integrity and encryption method is applied, (6) information related to header compression (ROHC) in the case of user plane (U-plane) data, etc.

[0225] Next, the transmitting PDCP entity can perform routing / replication (2419). Routing / replication (2419) can improve the reliability and efficiency of data transmission.

[0226] Subsequently, it is transmitted to the PDCP PDU lower layer and can be delivered to the receiver via the wireless interface.

[0227] The receiving PDCP entity can receive a PDCP PDU that has undergone processing by the receiving lower layer, and first, the PDCP header of the PDCP PDU can be removed (2421). At this time, header decompression (2427) can be performed without additional processing for packets not associated with the PDCP SDU.

[0228] Additional processing may be performed on packets associated with PDCP SDUs. More specifically, the receiving PDCP entity may perform a security decryption procedure based on an integrated integrity and encryption method, which is a process of decrypting the security procedure based on an integrated integrity and encryption method applied at the transmitting end.

[0229] Afterwards, the receiving PDCP entity performs reordering, which is a process of sorting packets that have been out of order due to network delays or path differences into the correct order, and duplication, which is a process of identifying and removing duplicate packets (2412).

[0230] Afterwards, header decompression can be performed on packets associated with PDCP SDU that have undergone processing (2417).

[0231] The PDCP SDU, after decompression, can be passed to the upper layer of the receiving PDCP entity for processing.

[0232] The present disclosure introduces a new type of security algorithm at the base station access layer and defines a procedure that enables it, and has the effect of enhancing packet processing performance at the base station.

[0233] More specifically, according to the methods described in this disclosure, there is an effect of reducing the amount of computation required for processing per packet. That is, by introducing a method that integrates integrity and encryption, the amount of computation required for processing per packet at a base station can be reduced.

[0234] In addition, according to the methods described in this disclosure, the number of bus occupancy attempts can be reduced. That is, by introducing a method that integrates integrity and encryption, the number of bus occupancy attempts required for processing per packet at a base station can be reduced.

[0235] In addition, according to the methods described in this disclosure, the number of bus occupancy attempts required for processing per packet can be reduced even when performing existing integrity protection and encryption.

[0236] Finally, according to the methods described in this disclosure, a security policy instruction procedure considering compatibility is designed based on the security capabilities of the base station and the terminal. Consequently, the base station can switch from a security procedure based on integrity protection and encryption to a security procedure based on an integrated integrity and encryption method, without violating the security policy rules instructed by the SMF, and apply it, or vice versa. In other words, there is an effect that an appropriate security procedure method can be flexibly selected depending on the communication situation.

[0237] FIG. 25 is a flowchart illustrating an example in which a method of operating a base station is performed in various embodiments of the present disclosure.

[0238] First, the base station can receive terminal capability information related to the security performance of the terminal (2510).

[0239] Next, the base station can receive a security policy for communication related to the control plane (CP) from the core network (2520).

[0240] Here, the security policy may indicate at least one of a first security procedure based on a first key used for integrity verification and a second key used for encryption, or a second security procedure based on a security key used in a procedure in which the integrity verification and encryption are performed in an integrated manner.

[0241] The base station can determine the security procedure to be applied to communication related to the CP based on the terminal capability information and the security policy (2530).

[0242] Next, the base station can activate a security procedure applied to communication related to the above-determined CP (2540).

[0243] FIG. 26 is a flowchart illustrating an example of how a method of operation of a terminal according to various embodiments of the present disclosure is performed.

[0244] The terminal can transmit terminal capability information related to terminal security performance to the base station (2610).

[0245] Next, the terminal can activate a security procedure determined based on a security policy for communication related to speech ability information and the control plane (CP) (260).

[0246] The above security policy may direct at least one of a first security procedure based on a first key used for integrity verification and a second key used for encryption, or a second security procedure based on a security key used in a procedure in which the integrity verification and encryption are performed in an integrated manner.

[0247] Methods according to the embodiments described in the claims or detailed description of the present disclosure may be implemented in the form of hardware, software, or a combination of hardware and software.

[0248] When implemented in software, a computer-readable storage medium may be provided for storing one or more programs (software modules). One or more programs stored in the computer-readable storage medium are configured for execution by one or more processors within an electronic device. One or more programs include instructions that cause the electronic device to execute methods according to the claims or embodiments described in the specification of this disclosure.

[0249] Such programs (software modules, software) may be stored in random access memory, non-volatile memory including flash memory, read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic disc storage devices, compact disc-ROM (CD-ROM), digital versatile discs (DVDs), or other forms of optical storage devices, magnetic cassettes. Alternatively, they may be stored in memory composed of some or all of these. Additionally, each constituent memory may include multiple units.

[0250] Additionally, the program may be stored on an attachable storage device that can be accessed via a communication network such as the Internet, Intranet, LAN (local area network), WAN (wide area network), or SAN (storage area network), or a combination thereof. Such a storage device may be connected to a device performing an embodiment of the present disclosure through an external port. Additionally, a separate storage device on a communication network may be connected to a device performing an embodiment of the present disclosure.

[0251] In the specific embodiments of the present disclosure described above, the components included in the disclosure are expressed in a singular or plural form according to the specific embodiments presented. However, the singular or plural expression is selected to suit the situation presented for convenience of explanation, and the present disclosure is not limited to singular or plural components; even if a component is expressed in the plural form, it may be composed of a singular form, and even if a component is expressed in the singular form, it may be composed of a plural form.

[0252] Meanwhile, although specific embodiments have been described in the detailed description of the present disclosure, it is understood that various modifications are possible within the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be defined by the claims set forth below as well as equivalents thereof.

Claims

1. A method performed by a base station in a wireless communication system, wherein the method comprises: A step of receiving terminal capability information related to the security performance of the terminal; A step of receiving a security policy for communication related to the control plane (CP) from the core network, The above security policy directs at least one of a first security procedure based on a first key used for integrity verification and a second key used for encryption, or a second security procedure based on a security key used in a method in which the integrity verification and encryption are performed in an integrated manner; A step of determining a security procedure applied to communication related to the CP based on the terminal capability information and the security policy; and A method comprising the step of activating a security procedure applied to communication related to the above-determined CP.

2. In Paragraph 1, If the security procedure applied to communication related to the above-determined CP is the above-determined second security procedure, the step of activating the security procedure applied to communication related to the above-determined CP is, A step of transmitting to the terminal a security command message including information on an algorithm integrating integrity and encryption for the application of the second security procedure and an authentication tag; and The method includes the step of receiving a security completion message including the authentication tag from the terminal, Based on the above security command message, downlink protection of communication related to the above CP is initiated, and A method in which uplink protection of communication related to the CP is initiated based on the above security completion message.

3. In paragraph 2, when the activation of the security procedure applied to the communication related to the determined CP is completed, the method, A step of receiving a security policy for communication related to a user plane (UP) from the above core network, The above security policy directs at least one of the above first security procedure or the above second security procedure; A step of determining a security procedure applied to communication related to the UP based on the terminal capability information and the security policy; and A method comprising the step of activating a security procedure applied to communication related to the above-determined UP.

4. In Paragraph 1, At least one of the integrity verification or the encryption in the first security procedure is performed by the CPU (central processing unit) of the base station, and A method in which the integrity and encryption in the above second security procedure are integrated is performed by the CPU or hardware accelerator of the base station.

5. A method performed by a terminal in a wireless communication system, wherein the method comprises: A step of transmitting terminal capability information related to terminal security performance to a base station; and The method includes the step of activating a security procedure determined based on the above terminal capability information and a security policy for communication related to the control plane (CP), wherein A method in which the above security policy directs at least one of a first security procedure based on a first key used for integrity verification and a second key used for encryption, or a second security procedure based on a security key used in a method in which the integrity verification and encryption are performed in an integrated manner.

6. In Paragraph 5, If the security procedure applied to communication related to the above CP is the above second security procedure, the step of activating the security procedure applied to communication related to the above CP is, A step of receiving a security command message from the base station, the message including information on an algorithm integrating integrity and encryption for the application of the second security procedure and an authentication tag; and The method includes the step of transmitting a security completion message including the authentication tag to the base station, Based on the above security command message, downlink protection of communication related to the above CP is initiated, and A method in which uplink protection of communication related to the CP is initiated based on the above security completion message.

7. In Paragraph 6, When the activation of the security procedure applied to the communication related to the above CP is completed, the above method, A step of determining a security procedure for communication related to the UP, determined based on the above terminal capability information and a security policy for communication related to the user plane (UP). The above security policy directs at least one of the above first security procedure or the above second security procedure; and A method comprising the step of activating a security procedure applied to communication related to the above UP.

8. In Paragraph 5, At least one of the integrity verification or the encryption in the first security procedure is performed by the CPU (central processing unit) of the base station, and A method in which the integrity and encryption in the above second security procedure are integrated is performed by the CPU or hardware accelerator of the base station.

9. In a base station of a wireless communication system, the base station, Transmitter / receiver; and It includes a controller connected to the above-mentioned transmitter and receiver, The above controller is, Receive terminal capability information related to the security performance of the terminal, and Receive a security policy for communication related to the control plane (CP) from the core network, and The above security policy directs at least one of a first security procedure based on a first key used for integrity verification and a second key used for encryption, or a second security procedure based on a security key used in a method in which the integrity verification and encryption are performed in an integrated manner. Based on the above terminal capability information and the above security policy, determine the security procedure applied to communication related to the above CP, and A base station configured to enable security procedures applied to communications related to the above-determined CP.

10. In Paragraph 9, If the security procedure applied to communication related to the above-determined CP is the above-determined second security procedure, in order to activate the security procedure applied to communication related to the above-determined CP, the controller, To the above terminal, a security command message including information on an algorithm integrating integrity and encryption for the application of the second security procedure and an authentication tag is transmitted, and The above terminal is configured to receive a security completion message including the authentication tag, Based on the above security command message, downlink protection of communication related to the above CP is initiated, and A base station in which uplink protection of communication related to the CP is initiated based on the above security completion message.

11. In Paragraph 10, When the activation of the security procedure applied to communication related to the above-determined CP is completed, the controller, Receive a security policy for communication related to the user plane (UP) from the above core network, and The above security policy directs at least one of the above first security procedure or the above second security procedure, and Based on the above terminal capability information and the above security policy, determine the security procedure applied to communication related to the above UP, and A base station further configured to enable security procedures applied to communications related to the above-determined UP.

12. In a wireless communication system, a terminal, the terminal, Transmitter / receiver; and It includes a controller connected to the above-mentioned transmitter and receiver, The above controller is, Transmit terminal capability information related to terminal security performance to the base station, and It is configured to activate a security procedure determined based on the above terminal capability information and a security policy for communication related to the control plane (CP), A terminal that directs at least one of a first security procedure based on a first key used for integrity verification and a second key used for encryption, or a second security procedure based on a security key used in a method in which the integrity verification and encryption are performed in an integrated manner.

13. In Paragraph 12, If the security procedure applied to the communication related to the above CP is the second security procedure, the controller, in order to activate the security procedure applied to the communication related to the above CP, Receive a security command message from the base station containing information on an algorithm integrating integrity and encryption for the application of the second security procedure and an authentication tag, and The above base station is configured to transmit a security completion message including the authentication tag, wherein Based on the above security command message, downlink protection of communication related to the above CP is initiated, and A terminal in which uplink protection of communication related to the CP is initiated based on the above security completion message.

14. In Paragraph 13, When the activation of the security procedure applied to the communication related to the above CP is completed, the controller, Determining a security procedure for communication related to the UP, determined based on the above terminal capability information and a security policy for communication related to the user plane (UP), and The above security policy directs at least one of the above first security procedure or the above second security procedure, and A method further configured to enable security procedures applied to communications related to the above UP.

15. In Paragraph 12, At least one of the integrity verification or the encryption in the first security procedure is performed by the CPU (central processing unit) of the base station, and A terminal in which the method of integrating the integrity and encryption in the second security procedure is performed by the CPU or hardware accelerator of the base station.

Citation Information

Patent Citations

  • Integrated disaster prevention system using digital twin model and fire simulation and operation method of the same

    KR1020230067950A

  • Comb style connector and connecting assembly with the same

    KR1020240002395A

  • Composition for diagosing nonalcoholic steatohepatitis using gut microbiome and uses thereof

    KR1020240151900A

  • Network security architecture

    US20170012956A1

  • KR20230125322A