Data protection at mac layer using scrambling
MAC layer scrambling in next generation networks addresses security and efficiency challenges by deriving a scrambling code for uplink and downlink MAC data, enhancing security and reducing processing delays in communication.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- NOKIA TECHNOLOGIES OY
- Filing Date
- 2025-11-11
- Publication Date
- 2026-05-28
AI Technical Summary
Existing security mechanisms in next generation networks, such as 5G and beyond, face challenges in ensuring efficient and secure communication over the air interface, particularly in terms of computation time and processing delay.
Implementing MAC layer scrambling by deriving a MAC scrambling code based on a configuration and applying it to uplink and downlink MAC data before transmission to enhance security and reduce processing delays.
Enhances communication security and efficiency by providing more secure and faster data transmission through MAC layer scrambling, reducing computation time and processing delays compared to traditional methods like ciphering and integrity protection.
Smart Images

Figure EP2025082600_28052026_PF_FP_ABST
Abstract
Description
[0001] DATA PROTECTION AT MAC LAYER USING SCRAMBLING
[0002] Technical Field
[0003] This disclosure is related to the field of communication systems and, in particular, to next generation networks.
[0004] Background
[0005] Next generation networks, such as Fifth Generation (5G) and beyond (e.g., Sixth Generation (6G)), denote the next major phase of mobile telecommunications standards beyond Fourth Generation (4G) standards. In comparison to 4G networks, next generation networks may be enhanced in terms of radio access and network architecture to deliver faster data rates and more reliability. With mobile networks widely used across the country and the world, communications may be intercepted or suffer from other kinds of attacks. To ensure security and privacy, the 3rd Generation Partnership Project (3GPP) and other organizations have set forth security mechanisms for mobile networks, and the security procedures performed within the mobile networks. Due to the importance of security in 5G systems and beyond, it is desirable to continue to develop improved security mechanisms.
[0006] Summary
[0007] Described herein are enhancements to security mechanisms. As an overview, enhanced security mechanisms are provided at the MAC (Medium Access Control) layer. MAC data is scrambled before being passed to the physical layer for transmission. One technical benefit is communications over the air interface may be more secure from the MAC-layer perspective. Another technical benefit is protection via scrambling is more efficient in terms of computation time, processing, and / or delay as compared to other protection mechanisms, such as ciphering and integrity protection.
[0008] In an embodiment (also referred to as an aspect), an apparatus comprises at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving a MAC scrambling configuration, deriving a MAC scrambling code based on the MAC scrambling configuration, scrambling uplink MAC data based on the MAC scrambling code to generate scrambled uplink MAC data, and passing the scrambled uplink MAC data to a physical layer for transmission to a radio access network node.
[0009] In an embodiment, a method comprises receiving a MAC scrambling configuration, deriving a MAC scrambling code based on the MAC scrambling configuration, scrambling uplink MAC data based on the MAC scrambling code to generate scrambled uplink MAC data, and passing the scrambled uplink MAC data to a physical layer for transmission to a radio access network node.
[0010] In an embodiment, an apparatus comprises means for receiving a MAC scrambling configuration, means for deriving a MAC scrambling code based on the MAC scrambling configuration, means for scrambling uplink MAC data based on the MAC scrambling code to generate scrambled uplink MAC data, and means for passing the scrambled uplink MAC data to a physical layer for transmission to a radio access network node.
[0011] In an embodiment, an apparatus comprises at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: generating a MAC scrambling configuration, deriving a MAC scrambling code based on the MAC scrambling configuration, scrambling downlink MAC data based on the MAC scrambling code to generate scrambled downlink MAC data, and passing the scrambled downlink MAC data to a physical layer for transmission to user equipment.
[0012] In an embodiment, a method comprises generating a MAC scrambling configuration, deriving a MAC scrambling code based on the MAC scrambling configuration, scrambling downlink MAC data based on the MAC scrambling code to generate scrambled downlink MAC data, and passing the scrambled downlink MAC data to a physical layer for transmission to user equipment.
[0013] In an embodiment, an apparatus comprises means for generating a MAC scrambling configuration, means for deriving a MAC scrambling code based on the MAC scrambling configuration, means for scrambling downlink MAC data based on the MAC scrambling code to generate scrambled downlink MAC data, and means for passing the scrambled downlink MAC data to a physical layer for transmission to user equipment
[0014] Other embodiments may include computer readable media, other systems or apparatus, or other methods or means as described below. Also, one or more embodiments as described above may be combinable as described herein.
[0015] The above summary provides a basic understanding of some aspects of the specification. This summary is not an extensive overview of the specification. It is intended to neither identify key or critical elements of the specification nor delineate any scope of the particular embodiments of the specification, or any scope of the claims. Its sole purpose is to present some concepts of the specification in a simplified form as a prelude to the more detailed description that is presented later.
[0016] Description of the Drawings
[0017] Some embodiments of the invention are now described, by way of example only, and with reference to the accompanying drawings. The same reference number represents the same element or the same type of element on all drawings.
[0018] FIG. 1 illustrates a high-level architecture of a 5G system.
[0019] FIG. 2 illustrates a non-roaming architecture of a 5G system.
[0020] FIG. 3 illustrates an NG-RAN architecture.
[0021] FIG. 4 illustrates security mechanisms within a 5G system.
[0022] FIGS. 5A-5B illustrate the primary authentication procedure that provides mutual authentication between user equipment and the network.
[0023] FIG. 6 illustrates non-access stratum (NAS) and access stratum (AS) security procedures.
[0024] FIG. 7 illustrates a key hierarchy of a 5G system.
[0025] FIG. 8 is a block diagram of network elements / functions for providing security management in an illustrative embodiment.
[0026] FIG. 9 is a block diagram of a UE in an illustrative embodiment.
[0027] FIG. 10 is a block diagram illustrating a 5G NR radio protocol stack.
[0028] FIG. 11 illustrates communication pathways between multiple layers in a radio protocol stack.
[0029] FIG. 12 is a block diagram illustrating a data frame configuration.
[0030] FIG. 13 is a block diagram of a MAC PDU.
[0031] FIGS. 14A-14B are examples of a DL MAC PDU data structure and a UL MAC PDU data structure, respectively.
[0032] FIGS. 15A-15B are block diagrams illustrating MAC subheaders.
[0033] FIG. 16 is a block diagram of a MAC layer handler in an illustrative embodiment.
[0034] FIG. 17 is a block diagram of a MAC scrambling configuration in an illustrative embodiment.
[0035] FIG. 18 illustrates different degrees of primitive polynomials. FIGS. 19A-19B are flow charts illustrating a method of protecting MAC data in an illustrative embodiment.
[0036] FIG. 20 illustrates a scrambling process in an illustrative embodiment.
[0037] FIG. 21 is a flow chart illustrating additional details of the method of FIG. 19 in an illustrative embodiment.
[0038] FIGS. 22A-22B illustrate MAC scrambling configuration generation in an illustrative embodiment.
[0039] FIG. 23 illustrates a MAC scrambling configuration in an illustrative embodiment.
[0040] FIG. 24 illustrates a descrambling process in an illustrative embodiment.
[0041] FIGS. 25A-25B are flow charts illustrating a method of protecting MAC data in an illustrative embodiment.
[0042] FIG. 26 illustrates MAC scrambling configuration generation in an illustrative embodiment.
[0043] FIGS. 27A-27B are flow charts illustrating a method of protecting MAC data in an illustrative embodiment.
[0044] FIGS. 28A-28D are signaling diagrams illustrating protection of MAC data in illustrative embodiments.
[0045] FIG. 29 illustrates further details of an NG-RAN architecture.
[0046] Description of Embodiments
[0047] The figures and the following description illustrate specific exemplary embodiments. It will thus be appreciated that those skilled in the art will be able to devise various arrangements that, although not explicitly described or shown herein, embody the principles of the embodiments and are included within the scope of the embodiments. Furthermore, any examples described herein are intended to aid in understanding the principles of the embodiments, and are to be construed as being without limitation to such specifically recited examples and conditions. As a result, the inventive concept(s) is not limited to the specific embodiments or examples described below, but by the claims and their equivalents.
[0048] FIG. 1 illustrates a high-level architecture of a 5G system 100. A 5G system (5GS) 100 is a communication system (e.g., a 3GPP system) comprising a 5G Access Network ((R)AN) 102 (also referred to generally herein as a RAN) and a 5G core network (5GC) 104 (also referred to generally as a core network) that communicate with 5G User Equipment (UE) 106. The RAN 102 and 5GC 104 together may be referred to as a 5G network 101, a 5G mobile network, a 5G communication network, a next generation network, etc. Although the term “5G” is used herein as an example, any next generation or future generation networks beyond 4G are considered, such as 6G. Thus, a “mobile network” and the concepts described herein apply to 5G and beyond.
[0049] RAN 102 provides radio or wireless connectivity to a UE 106, and connects the UE 106 to the 5GC 104. RAN 102 may comprise a Next Generation Radio Access Network (NG-RAN), an Evolved Universal Terrestrial Radio Access Network (E-UTRAN), a non-3GPP access network (N3AN), a non-terrestrial access network (NTN), and / or another type of RAN connecting to 5GC 104. RAN 102 may support access through at least one RAN node, e.g., a gNodeB (gNB), an ng-eNodeB (ng-eNB)), an eNodeB (eNB), and / or Wireless Local Area Network (WLAN) access point. RAN 102 may support satellite radio access, new Radio Access Technologies (RATs), etc. A 5G access network may also support fixed access. 5GC 104 interconnects RAN 102 with a data network (DN) 108. 5GC 104 is comprised of Network Functions (NF) 110, which may be implemented either as a network element on dedicated hardware, as a chip or chipset comprised in a network element, as a software instance running on dedicated hardware, as a virtualized network function (VNF) instantiated on a dedicated or generic virtualization platform (e.g., a cloud infrastructure), etc. Data network 108 may be an operator external public or private data network, or an intra-operator data network (e.g., for IP Multimedia Subsystem (IMS) services). A UE 106 (also referred to as a mobile terminal) includes a 5G capable device configured to register with 5GC 104 to access services. UE 106 may include an end user device, such as a mobile phone (e.g., smartphone), a tablet, a computer with a mobile broadband adapter, etc. UE 106 may be enabled for voice services, data services, Machine-to-Machine (M2M) or Machine Type Communications (MTC) services, and / or other services.
[0050] FIG. 2 illustrates a non-roaming architecture 200 of a 5G system 100. The architecture 200 in FIG. 2 is a service-based representation, as is further described in 3GPP TS 23.501 (Release 19), which is incorporated by reference as if fully included herein. Architecture 200 is comprised of Network Functions (NF) for a 5GC 104, and the NFs for the control plane (CP) are separated from the user plane (UP). The control plane of the 5GC 104 includes an Authentication Server Function (AUSF) 210, an Access and Mobility Management Function (AMF) 212, a Session Management Function (SMF) 214, a Policy Control Function (PCF) 216, a Unified Data Management (UDM) 218, a Network Slice Selection Function (NSSF) 220, and an Application Function (AF) 222. The control plane of the 5GC 104 further includes a Network Exposure Function (NEF) 224, a NF Repository Function (NRF) 226, a Service Communication Proxy (SCP) 228, a Network Slice Admission Control Function (NSACF) 230, a Network Slicespecific and SNPN Authentication and Authorization Function (NSSAAF) 232, and an Edge Application Server Discovery Function (EASDF) 234. The user plane of the 5GC 104 includes one or more User Plane Functions (UPF) 240 that communicate with data network 108. A UE 106 is able to access the control plane and the user plane of the 5GC 104 through RAN 102.
[0051] FIG. 3 illustrates an NG-RAN architecture 300. The NG-RAN architecture 300 is further described in 3GPP TS 38.300 (Release 18), which is incorporated by reference as if fully included herein. An NG-RAN 302 is an example of a RAN 102 as described above, and comprises a plurality of RAN nodes 304 (also referred to as NG-RAN nodes). A RAN node 304 may be a gNB 306 configured to provide new-radio user plane and control plane protocol terminations towards a UE 106, or an ng-eNB 308 configured to provide E-UTRA user plane and control plane protocol terminations towards a UE 106. The gNBs 306 and ng-eNB s 308 are interconnected with each other by means of the Xn interface. The gNBs 306 and ng-eNB s 308 are also connected by means of the NG interfaces to the 5GC 104, more specifically, to the AMF 212 by means of the NG-C interface and to the UPF 240 by means of the NG-U interface.
[0052] In general, a UE 106 of a 5G system has a home mobile network (e.g., home Public Land Mobile Network (HPLMN)), which is the PLMN in which the profile of a mobile subscriber is held. A UE 106 may have service availability when connected to the HPLMN through one or more access types, such as 3GPP access and non-3GPP access (trusted or untrusted). When a UE 106 roams onto another network (referred to as a serving or visited mobile network (VPLMN)) different than the HPLMN, the 5GC 104 of the HPLMN is able to interconnect or interwork with the visited mobile network so that the user can access services even when roaming outside of the HPLMN.
[0053] There are a large number of subscribers that are able to access services from a carrier or home / mobile network operator that implements a mobile network comprising a 5G system 100, such as in FIGS. 1-2. Communications between the users or subscribers (i.e., through a UE) and the mobile network are protected by security mechanisms, such as the ones standardized by the 3GPP. Subscribers and the carrier expect security guarantees from the security mechanisms.
[0054] FIG. 4 illustrates security mechanisms 400 within a 5G system 100. One of the security mechanisms 400 is primary authentication and key agreement between the network (e.g., AMF 212 / UDM 218) and the UE 106. Other security mechanisms 400 are used to protect signaling between the network and the UE 106. For example, a security mechanism 400 is used to protect Non-Access Stratum (NAS) signaling between the AMF 212 and the UE 106. Other security mechanisms 400 are used to protect Access Stratum (AS) communications between a RAN node 304 (e.g., gNB 306) and the UE 106, such as Radio Resource Control (RRC) signaling between a gNB 306 and the UE 106, and User Plane (UP) traffic (also referred to as UP data) between the gNB 306 and the UE 106. Within the network, a security mechanism 400 may be used to protect IP connectivity between the gNB 306 and the 5GC 104 (e.g., AMF 212 / UPF 240), such as Internet Protocol Security (IPSec). Another security mechanism 400 is used for roaming and interconnect security, such as to protect control plane signaling between a Security Edge Protection Proxy (SEPP) 410 and another network 401 (e.g., a visited 5G network), and / or to protect user plane data between the UPF 240 and the other network 401. There may be additional security mechanisms 400 defined or used, which are not discussed for the sake of brevity.
[0055] FIGS. 5A-5B illustrate the primary authentication procedure that provides mutual authentication between the UE 106 and the network (e.g., AMF 212 / UDM 218). The purpose of the primary authentication and key agreement procedures is to enable mutual authentication between UE 106 and the home network of the UE 106, and provide keying material that can be used between the UE 106 and the serving network in subsequent security procedures (e.g., NAS and AS security procedures). The home network (e.g., HPLMN) represents an operator network or carrier network through which a subscriber (e.g., UE 106) has a subscription for services. The serving network has radio access equipment able to communicate with the UE 106 via radio signals. The keying material generated by the primary authentication and key agreement procedure results in an anchor key (called the KSEAF key) provided by the AUSF 210 of the home network to the Security Anchor Function (SEAF) of the serving network. The SEAF provides authentication functionality via the AMF 212 in the serving network, and supports primary authentication using a Subscription Concealed Identifier (SUCI) that contains the concealed Subscription Permanent Identifier (SUPI). The SUPI is a globally unique 5G identifier allocated to each subscriber in the 5G system 100. The SUCI is composed of a SUPI type, a Home Network Identifier (HN-ID) identifying the home network of the subscriber, a Routing Indicator (RID) that is assigned to the subscriber by the home network operator and provisioned in the Universal Subscriber Identity Module (USIM) of the UE 106, a Protection Scheme Identifier, a Home Network Public Key Identifier, and a Scheme Output. The anchor key (KSEAF) is derived from an intermediate key called the KAUSF key. The KAUSF key is established between the UE 106 and the home network (AUSF 210) resulting from the primary authentication procedure.
[0056] FIG. 5A is a signaling diagram that illustrates initiation of primary authentication, such as described in 3GPP TS 33.501 (Release 19), which is incorporated by reference as if fully included herein. The UE 106 transmits an N1 message 511 (i.e., an initial NAS message) to the serving network 506 (e.g., the AMF 212 of the serving network 506), such as a Registration Request. The serving network 506 may also be referred to as a serving PEMN, a visited-PEMN (VPLMN), etc., in a roaming scenario. The UE 106 uses the SUCI or a 5G Global Unique Temporary Identifier (5G-GUTI) in the Registration Request. SEAF 502 of the AMF 212 may initiate an authentication with the UE 106 during any procedure establishing a signaling connection with the UE 106. SEAF 502 invokes the Nausf_UEAuthentication service toward the home network 504 (e.g., HPLMN) by sending a Nausf_UEAuthentication_Authenticate Request message 512 to AUSF 210 to initiate an authentication. The Nausf_UEAuthentication_Authenticate Request message 512 includes the SUCI or SUPI, and the serving network name (SN-Name). Upon receiving the Nausf_UEAuthentication_Authenticate Request message 512, AUSF 210 checks that the requesting SEAF 502 in the serving network 506 is entitled to use the serving network name (SNN) in the Nausf_UEAuthentication_Authenticate Request message 512 by comparing the serving network name with the expected serving network name. When the serving network 506 is authorized to use the serving network name, AUSF 210 sends a Nudm_UEAuthentication_Get Request message 513 to UDM 218 of the home network. The Nudm_UEAuthentication_Get Request message 513 includes the SUCI or SUPI, and the serving network name. Upon reception of the Nudm_UEAuthentication_Get Request message 513, UDM 218 identifies the SUPI (if received), or invokes a Subscription Identifier De-concealing Function (SIDF) that deconceals the SUPI from the SUCI (if received). UDM 218 (or an Authentication credential Repository and Processing Function (ARPF) of UDM 218) selects or chooses the authentication method for primary authentication based on the SUPI.
[0057] FIG. 5B is a signaling diagram that illustrates a primary authentication procedure, such as described in 3GPP TS 33.501. In this example, 5G Authentication and Key Agreement (AKA) is described, but similar concepts apply for Extensible Authentication Protocol AKA prime (EAP-AKA'). For a Nudm_UEAuthentication_Get Request 513, UDM 218 creates a 5G Home Environment Authentication Vector (5G HE AV) for the selected authentication method. UDM 218 derives the KAUSF key and calculates an expected response (XRES*) to a challenge. UDM 218 creates the 5G HE AV comprising an authentication token (AUTN), the expected response (XRES*), the KAUSF key, and a random challenge (RAND). UDM 218 then sends a Nudm_UEAuthentication_Get Response message 514 to AUSF 210 with the 5G HE AV to be used for authentication (e.g., 5G AKA in FIG. 5B). In case the SUCI was included in the Nudm_UEAuthentication_Get Request 513, UDM 218 includes the SUPI in the Nudm_UEAuthentication_Get Response message 514 after de-concealment of the SUPI from the SUCI. If a subscriber has an Authentication and Key Management for Application (AKMA) subscription, UDM 218 may include an AKMA indication and the RID in the Nudm_UEAuthentication_Get Response message 514.
[0058] In response to the Nudm_UEAuthentication_Get Response message 514, AUSF 210 stores the expected response (XRES*) temporarily with the received SUCI or SUPI. AUSF 210 then generates a 5G Authentication Vector (5G AV) from the 5G HE AV received from UDM 218, by computing a hash expected response (HXRES*) from the expected response (XRES*) and the KSEAF key from the KAUSF key, and replacing the XRES* with the HXRES* and the KAUSF key with the KSEAF key in the 5G HE AV. AUSF 210 removes the KSEAF key to generate a 5G Serving Environment Authentication Vector (5G SE AV) that includes the authentication token (AUTN), hash expected response (HXRES*), and the random challenge (RAND). AUSF 210 sends a Nausf_UEAuthentication_Authenticate Response message 515 to SEAF 502 that includes the 5G SE AV. In response, SEAF 502 sends the authentication token (AUTN) and the random challenge (RAND) to the UE 106 in a NAS message Authentication Request message 516.
[0059] Although not shown in FIG. 5B, the UE 106 includes Mobile Equipment (ME) and a USIM. The ME receives the authentication token (AUTN) and the random challenge (RAND) in the NAS message Authentication Request message 516, and forwards the authentication token (AUTN) and the random challenge (RAND) to the USIM. The USIM of the UE 106 verifies the freshness of the received values by checking whether the authentication token (AUTN) can be accepted. If so, the USIM computes a response (RES), a cipher key (CK), and an integrity key (IK) based on the random challenge (RAND), and returns the response (RES), the CK key, and the IK key to the ME. The ME of the UE 106 computes RES* from RES, and calculates the KAUSF key from CK||IK and the KSEAF key from the KAUSF key.
[0060] The UE 106 sends a NAS message Authentication Response message 517 to SEAF 502 that includes RES*. In response, SEAF 502 computes HRES* from RES*, and compares HRES* and HXRES*. If they coincide, SEAF 502 considers the authentication successful from the serving network point of view. SEAF 502 sends RES*, as received from the UE 106, in a Nausf_UEAuthentication_Authenticate Request message 518 to AUSF 210. When AUSF 210 receives the Nausf_UEAuthentication_Authenticate Request message 518 including a RES* as authentication confirmation, AUSF 210 stores the KAUSF key based on the home network operator’s policy, and compares the received RES* with the stored XRES*. If the RES* and XRES* are equal, then AUSF 210 considers the authentication successful from the home network point of view. AUSF 210 informs UDM 218 about the authentication result (not shown). AUSF 210 also sends a Nausf_UEAuthentication_Authenticate Response message 519 to SEAF 502 indicating whether or not the authentication was successful from the home network point of view. If the authentication was successful, the KSEAF key is sent to SEAF 502 in the Nausf_UEAuthentication_Authenticate Response message 519. In case AUSF 210 received the SUCI from SEAF 502 in the authentication request, AUSF 210 includes the SUPI in the Nausf_UEAuthentication_Authenticate Response message 519 if the authentication was successful.
[0061] As described above, 5G divides UE management into the Non-Access Stratum (NAS) and the Access Stratum (AS). The NAS layer protocol manages the connection between a UE 106 and 5GC 104 (i.e., AMF 212), and the AS layer protocol manages the radio layer between a UE 106 and the RAN 102 (e.g., gNB 306) using RRC protocol. NAS security ensures that NAS signaling between a UE 106 and AMF 212 is protected on the control plane, and AS security ensures that RRC messages on the control plane and user plane traffic (e.g., IP packets) on the user plane are protected.
[0062] FIG. 6 illustrates NAS and AS security procedures, such as described in 3GPP TS 33.501 (sections 6.4 and 6.7, respectively). For NAS security, a NAS security mode command procedure is performed to establish a NAS security context between the UE 106 and the AMF 212. Each AMF 212 is configured via network management with lists of algorithms that are allowed for usage. Presently, there is one list for NAS integrity algorithms and one for NAS ciphering algorithms that are ordered according to a priority decided by the operator. To establish the NAS security context, AMF 212 selects one NAS ciphering algorithm and one NAS integrity protection algorithm, and derives the NAS integrity key and the NAS encryption key (e.g., KNASint and KNASBIIC) for the selected algorithms. AMF 212 initiates the NAS security mode command procedure by sending a NAS Security Mode Command message 611 to the UE 106. AMF 212 activates NAS integrity protection before sending the NAS Security Mode Command message 611. The NAS Security Mode Command message 611 contains the previously received UE security capabilities, the selected NAS algorithms, a key set identifier (i.e., ngKSI (next generation key set identifier)), and a message authentication code (NAS-MAC) generated by the AMF 212 for integrity protection of the NAS Security Mode Command message 611. The NAS Security Mode Command message 611 is integrity protected (but not ciphered) with the NAS integrity key based on the KAMF key indicated by the ngKSI. AMF 212 activates NAS uplink deciphering after sending the NAS Security Mode Command message 611.
[0063] On receipt of the NAS Security Mode Command message 611, the UE 106 verifies the integrity of the NAS Security Mode Command using the indicated NAS integrity algorithm and the NAS integrity key based on the KAMF key indicated by the ngKSI. The UE 106, with the received algorithms, generates the NAS integrity key and the NAS encryption key in the same manner as AMF 212. If verification is successful, the UE 106 begins NAS integrity protection and ciphering / deciphering with the security context indicated by the ngKSI. The UE 106 sends a NAS Security Mode Complete message 612 to AMF 212 that is ciphered and integrity protected. If the verification of the NAS Security Mode Command message 611 is not successful, the UE 106 replies with a NAS Security Mode Reject message (not shown). AMF 212 de-ciphers and checks the integrity of the received NAS Security Mode Complete message 612 using the key and algorithm indicated in the NAS Security Mode Command message 611. AMF 212 activates NAS downlink ciphering after receiving the NAS Security Mode Complete message 612.
[0064] AS security includes RRC security and User Plane (UP) security. For RRC security, RRC integrity protection and RRC confidentiality protection are provided by the Packet Data Convergence Protocol (PDCP) layer between a UE 106 and a gNB 306. The 5GC 104 supports a PDU connectivity service that provides exchange of PDUs between UE 106 and a data network 108 (identified by a Data Network Name (DNN)) over the user plane. Security of user plane traffic in 5G networks is controlled by the UP security policy. The SMF 214 provides the UP security policy for a Packet Data Unit (PDU) session to the gNB 306 (or ng-eNB) during the PDU session establishment procedure. The UP security policy indicates whether UP confidentiality protection and / or UP integrity protection are activated for Data Radio Bearers (DRBs) belonging to that PDU session.
[0065] An AS security mode command procedure is performed to establish an AS security context between the UE 106 and the NG-RAN 302. When the AS security context is to be established in the gNB 306, AMF 212 sends the UE 5G security capabilities with ciphering and integrity protected algorithms and the KgNB key in an NG Application Protocol (NGAP) Initial Context Setup message 613 to the NG-RAN 302 (e.g., gNB 306). Presently, each gNB 306 is configured via network management with lists of algorithms that are allowed for usage. There is one list for integrity algorithms and one for ciphering algorithms that are ordered according to a priority decided by the operator. The gNB 306 selects the AS integrity algorithm and the AS ciphering algorithm which has the highest priority from its configured list and present in the UE 5G security capabilities received from AMF 212. The gNB 306 derives the RRC integrity key (KRRCint), the UP integrity key (Kupint), the RRC ciphering key (KRRCenc), and the UP ciphering key (Kupenc) for the selected AS algorithms. The gNB 306 starts integrity protection for RRC messages.
[0066] The gNB 306 sends an integrity protected AS Security Mode Command message 614 to the UE 106, which contains the selected AS integrity algorithm and AS ciphering algorithm, and the message authentication code (MAC-I) generated by the gNB 306 for integrity protection of the AS Security Mode Command message 614. RRC downlink ciphering at the gNB 306 starts after sending the AS Security Mode Command message 614.
[0067] On receipt of the AS Security Mode Command message 614, the UE 106 derives the RRC integrity key (KRRCint) and the RRC ciphering key (KRRCenc) similar to the gNB 306 based on the selected AS integrity algorithm and AS ciphering algorithm. UE 106 verifies the AS Security Mode Command integrity and, if successful, starts RRC integrity protection and RRC downlink de-ciphering. The UE 106 then sends an AS Security Mode Complete message 615 with integrity protection to the gNB 306. The AS Security Mode Complete message 615 contains the MAC-I generated by the UE 106 for integrity protection of the AS Security Mode Complete message 615. The RRC uplink ciphering at the UE 106 starts after sending the AS Security Mode Complete message 615. Integrity of the AS Security Mode Complete message 615 is verified at the gNB 306, and the gNB 306 starts RRC uplink deciphering.
[0068] FIG. 7 illustrates a key hierarchy 700 of a 5G system 100, such as in 3GPP TS 33.501. The keys related to authentication include the following keys: K 701, and CK / IK 702. The key hierarchy 700 includes the following keys: KAUSF 703, KSEAF 704, KAMF 705, KNASint 706, KxASenc 707, KN3IWF 708, KgNB 709, KRRCint 710, KRRCenc 711, KuPint 712, and Kupenc 713. The keys for AUSF 210 in the home network 504 include the KAUSF key 703 derived by the ME of a UE 106 and AUSF 210 from CK', IK' in case of EAP-AKA', or by the ME and the ARPF of UDM 218 from CK, IK 702 in case of 5G AKA. The KSEAF key 704 is the anchor key derived by the ME and AUSF 210 from the KAUSF key 703. The key for AMF 212 in the serving network 506 is the KAMF key 705 derived by the ME and the SEAF 502 from the KSEAF key 704. The keys for NAS signaling (i.e., of a NAS security context) include the KNASint key 706 derived by the ME and AMF 212 from the KAMF key 705, which is used for integrity protection of NAS signaling with a particular integrity algorithm. The keys for NAS signaling also include the KNASBIIC key 707 derived by the ME and AMF 212 from the KAMF key 705, which is used for encryption of NAS signaling with a particular encryption algorithm. The key for the NG-RAN is the KgNB key 709 derived by the ME and AMF 212 from the KAMF key 705. For an AS security context, the keys for RRC signaling include the KRRCint key 710 derived by the ME and the gNB 306 from the KgNB key 709, which is used for integrity protection of RRC signaling with a particular integrity algorithm. The keys for RRC signaling further include the KRRCenc key 711 derived by the ME and the gNB 306 from the KgNB key 709, which is used for encryption of RRC signaling with a particular encryption algorithm. The keys for UP traffic include the Kupint key 712 derived by the ME and the gNB 306 from the KgNB key 709, which is used for integrity protection of UP traffic between the ME and the gNB 306 with a particular integrity algorithm. The keys for UP traffic further include the Kupenc key 713 derived by the ME and the gNB 306 from the KgNB key 709, which is used for encryption of UP traffic with a particular encryption algorithm. Next Hop parameter (NH) is part of the 5G AS security context for 3GPP access. The NH key 714 is an intermediate key derived by the ME and AMF 212 to provide forward security. The KNG-RAN* key is a key derived by the ME and NG-RAN 302 (i.e., gNB or ng-eNB) when performing a horizontal or vertical key derivation. The KAMF1key is a key that can be derived by the ME and AMF 212 when the UE 106 moves from one AMF 212 to another during inter-AMF mobility. For non-3GPP access, the KNSIWF key 708 is derived by the ME and the AMF 212 from the KAMF key 705 for non-3GPP access. There are other keys as part of the key hierarchy 700 of a 5G system 100, which are not discussed for the sake of brevity.
[0069] FIG. 8 is a block diagram of network elements / functions for providing security management in an illustrative embodiment. More particularly, a communication system 800 of FIG. 8 comprises a UE 106, a RAN node 304, and a plurality of network elements / functions 810 (i.e., a first network element / function 810-1 and a second network element / function 810-N). It is to be appreciated that UE 106, RAN node 304, and the network elements / functions 810 are configured to interact to provide security management (also referred to as protection management). Examples of network elements / functions 810 may include, but are not limited to, an AMF 212, a UPF 240, etc. An RAN node 304 is an element / function of a RAN configured to provide a UE access to a 5GC 104 through 3GPP access over the air interface, such as a gNB 306. Network element / function 810-1 comprises a processor 822-1 coupled to a memory 826- 1 and interface circuitry 820-1. The processor 822-1 of network element / function 810-1 includes a security management processing module 824-1 that may be implemented at least in part in the form of software executed by the processor 822-1. The security management processing module 824-1 performs security management described in conjunction with subsequent figures and otherwise herein. The memory 826-1 includes a security management storage module 828-1 that stores data generated or otherwise used during security management operations.
[0070] Network element / function 810-N comprises a processor 822-N coupled to a memory 826-N and interface circuitry 820-N. The processor 822-N of network element / function 810-N includes a security management processing module 824-N that may be implemented at least in part in the form of software executed by the processor 822-N. The security management processing module 824-N performs security management described in conjunction with subsequent figures and otherwise herein. The memory 826-N includes a security management storage module 828-N that stores data generated or otherwise used during security management operations.
[0071] The processors 822-1 and 822-N of the respective network elements / functions 810-1 and 810-N may comprise, for example, microprocessors, application-specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), digital signal processors (DSPs) or other types of processing devices or integrated circuits, as well as portions or combinations of such elements. Such integrated circuit devices, as well as portions or combinations thereof, are examples of “circuitry” as that term is used herein. A wide variety of other arrangements of hardware and associated software or firmware may be used in implementing the illustrative embodiments.
[0072] The memories 826-1 and 826-N of the respective network elements / functions 810-1 and 810-N may be used to store one or more software programs or instructions that are executed by the respective processors 822-1 and 822-N to implement at least a portion of the functionality described herein. For example, security management operations and other functionality as described in conjunction with subsequent figures and otherwise herein may be implemented in a straightforward manner using software code executed by processors 822-1 and 822-N.
[0073] A given one of the memories 826-1 and 826-N may therefore be viewed as an example of what is more generally referred to herein as a computer program product or still more generally as a processor-readable storage medium that has executable program code embodied therein. Other examples of processor-readable storage media may include disks or other types of magnetic or optical media, in any combination. Illustrative embodiments can include articles of manufacture comprising such computer program products or other processor-readable storage media.
[0074] The memories 826-1 and 826-N may more particularly comprise, for example, an electronic random-access memory (RAM), such as static RAM (SRAM), dynamic RAM (DRAM), or other types of volatile or non-volatile electronic memory. The latter may include, for example, non-volatile memories such as flash memory, magnetic RAM (MRAM), phasechange RAM (PC-RAM) or ferroelectric RAM (FRAM). The term “memory” as used herein is intended to be broadly construed, and may additionally or alternatively encompass, for example, a read-only memory (ROM), a disk-based memory, or other type of storage device, as well as portions or combinations of such devices.
[0075] Interface circuitry 820-1 and 820-N of the respective network elements / functions 810-1 and 810-N illustratively comprise transceivers or other communication hardware or firmware, Application Programming Interfaces (APIs), etc., that allows the associated system elements to communicate with one another in the manner described herein.
[0076] Network element / function 810-1 is configured for communication with network element / function 810-N, and vice-versa, via their respective interface circuitry 820-1 and 820-N. This communication involves network element / function 810-1 sending data to the network element / function 810-N, and the network element / function 810-N sending data to the network element / function 810-1. However, in alternative embodiments, other network elements may be operatively coupled between the network elements / functions 810-1 and 810-N. The term “data” as used herein is intended to be construed broadly, so as to encompass any type of information that may be sent between network elements / functions (as well as between UE 106 and a core network 104) including, but not limited to, messages, identifiers, keys, indicators, user data, control data, etc.
[0077] RAN node 304 comprises a processor 832 coupled to a memory 836 and interface circuitry 830. The processor 832 of RAN node 304 includes a security management processing module 834 that may be implemented at least in part in the form of software executed by the processor 832. The security management processing module 834 performs security management described in conjunction with subsequent figures and otherwise herein. The memory 836 includes a security management storage module 838 that stores data generated or otherwise used during security management operations. RAN node 304 is configured for communication with UE 106 and one or more network element / functions 810-N via interface circuitry 830. For example, interface circuitry 830 may be configured for radio communication over an air interface to communicate with a UE 106, and may be configured for backhaul communication with one or more network element / functions 810-N of the core network 104.
[0078] It is to be appreciated that the particular arrangement of components shown in FIG. 8 is an example, and numerous alternative configurations may be used in other embodiments. For example, any given network element / function can be configured to incorporate additional or alternative components and to support other communication protocols.
[0079] Other system elements may each also be configured to include components such as a processor, memory, and network interface. These elements need not be implemented on separate stand-alone processing platforms, but could instead, for example, represent different functional portions of a single common processing platform.
[0080] FIG. 9 is a block diagram of a UE 106 in an illustrative embodiment. From a functional standpoint, the UE 106 is composed of at least two parts: Mobile Equipment (ME) 900 and a Universal Subscriber Identity Module (USIM) 960. ME 900 comprises a radio interface component 902, one or more processors 904, and a memory 906, and may also comprise a user interface component 908. The UE 106 may also comprise a battery 910. Radio interface component 902 is a hardware component or means that represents the local radio resources of the UE 106, such as a Radio Frequency (RF) unit 920 (e.g., one or more radio transceivers) and one or more antennas 922. Radio interface component 902 may be configured for 5G New Radio (NR), Long Term Evolution (LTE), WiFi, Bluetooth, etc. Processor 904 represents the internal circuitry, logic, hardware, means, etc., that provides the functions of the UE 106. Processor 904 may be configured to execute instructions 940 for software that are loaded into memory 906. Processor 904 may execute an Operating System (OS) 934 for the UE 106 that manages hardware and software resources, and one or more application clients 935 for an application. Processor 904 may also execute a security controller 936, which comprises a component or means for performing security mechanisms within the UE 106 (i.e., within the ME 900), such as integrity protection mechanisms and / or encryption mechanisms. User interface component 908 is a hardware component for interacting with an end user. For example, user interface component 908 may comprise a display 950, screen, touch screen, and / or the like (e.g., a Liquid Crystal Display (LCD), a Light Emitting Diode (LED) display, etc.). User interface component 908 may include a keyboard or keypad, a tracking device (e.g., a trackball or trackpad), a speaker, a microphone, etc. USIM 960 is an integrated circuit that provides security and integrity functions for the UE 106. USIM 960 includes or is provisioned with a subscription profile associated with a subscription of a subscriber. A subscription profile may include a variety of information, such as subscription credentials (e.g., Subscription Permanent Identifier (SUPI)) used to uniquely identify a subscription and to mutually authenticate the UE 106 and a network.
[0081] The UE 106 may comprise various other components not specifically illustrated in FIG. 9.
[0082] FIG. 10 is a block diagram illustrating a 5G NR radio protocol stack 1000. The RAN protocol architecture is further described in 3GPP TS 38.300. The radio protocol stack 1000 is divided into a protocol stack for the control plane 1001 and a protocol stack for the user plane 1002. The radio protocol stack 1000 is mainly divided into three layers: the physical (PHY) layer 1004 (LI), the data link layer 1006 (L2), and the network layer 1008 (L3). The data link layer 1006 comprises the following layers or sublayers: the Medium Access Control (MAC) layer 1010, the Radio Link Control (RLC) layer 1012, and the Packet Data Convergence Protocol (PDCP) layer 1014. In the protocol stack for the control plane 1001, the network layer 1008 (L3) comprises the Radio Resource Control (RRC) layer 1016 (or sublayer). The protocol stack for the control plane 1001 further comprises the Non-Access Stratum (NAS) layer 1018 (i.e., NAS control protocol), which is terminated in an AMF 212 on the network side. The RRC layer 1016, PDCP layer 1014, RLC layer 1012, and MAC layer 1010 are terminated in a gNB 306 on the network side. In the protocol stack for the user plane 1002, the network layer 1008 (L3) comprises the Service Data Adaption Protocol (SDAP) layer 1020 (or sublayer). The SDAP layer 1020, PDCP layer 1014, RLC layer 1012, and MAC layer 1010 are terminated in a gNB 306 on the network side.
[0083] FIG. 11 illustrates communication pathways between multiple layers in a radio protocol stack 1000. For example, radio transmission (between gNB 306 and UE 106) via the radio interface 1102 (RF) takes place over the physical layer 1004. The physical layer 1004 includes a plurality of physical channels 1110, such as the Physical Uplink Shared Channel (PUSCH) 1112, which is a data channel used for uplink data transmission, and a Physical Downlink Shared Channel (PDSCH) 1114, which is a data channel used for downlink data transmission. FIG. 11 illustrates a scenario for user plane or user data transmissions, and it is understood that additional physical channels 1110 may exist for user plane and / or control plane transmissions that are omitted for the sake of brevity. The MAC layer 1010 sits atop the physical layer 1004, and they are connected via transport channels 1120. The transport channels 1120 are the link between the MAC layer 1010 and the physical layer 1004 (i.e., physical layer 1004 is a lower layer to the MAC layer 1010 in the radio protocol stack 1000). The transport channels 1120 may include an Uplink Shared Channel (UL-SCH) 1122, which is the main transport channel 1120 used for transmission of UL data, and a Downlink Shared Channel (DL-SCH) 1124, which is the main transport channel 1120 used for transmission of DL data. Data on the transport channels 1120 are organized or packaged into Transport Blocks (TB) 1126 by the MAC layer 1010. Again, it is understood that additional transport channels 1120 may exist for user plane and / or control plane transmissions that are omitted for the sake of brevity.
[0084] The RCL layer 1012 and the MAC layer 1010 are connected via logical channels 1130. The logical channels 1130 are the link between the MAC layer 1010 and the RLC layer 1012 (i.e., RLC layer 1012 is a higher layer to the MAC layer 1010 in the radio protocol stack 1000). The logical channels 1130 may include a Dedicated Traffic Channel (DTCH) 1134, which is a logical channel 1130 used for transmission of unicast uplink and downlink user data. Again, it is understood that additional logical channels 1130 may exist for user plane and / or control plane transmissions that are omitted for the sake of brevity.
[0085] Within the radio protocol stack 1000, the MAC layer 1010 has various functionalities. Some of the MAC functions are mapping between logical channels 1130 and transport channels 1120, multiplexing of MAC Service Data Units (SDUs), demultiplexing of MAC SDUs, scheduling information reporting, error correction through Hybrid Automatic Repeat Request (HARQ), logical channel prioritization, etc.
[0086] FIG. 12 is a block diagram illustrating a data frame configuration 1200. The SDAP layer 1020 exchanges Internet Protocol (IP) packets 1202 with higher layers, such as for one or more data radio bearers (DRB). The IP packets 1202 may comprise DL data 1240 or UL data 1242. In the SDAP layer 1020, an IP packet 1202 is encapsulated in an SDAP Service Data Unit (SDU) 1206 of an SDAP Protocol Data Unit (PDU) 1208, which comprises an appended SDAP header (H). In the PDCP layer 1014, an SDAP PDU 1208 is encapsulated in an PDCP SDU 1210 of a PDCP PDU 1212, which comprises an appended PDCP header (H). In the RCL layer 1012, a PDCP PDU 1212 is encapsulated in an RLC SDU 1214 of an RLC PDU 1216, which comprises an appended RLC header (H). In the MAC layer 1010, an RLC PDU 1216 is encapsulated in a MAC SDU 1220. The MAC layer 1010 multiplexes MAC SDUs 1220 into a MAC PDU 1222, or demultiplexes MAC SDUs 1220 from a MAC PDU 1222. FIG. 13 is a block diagram of a MAC PDU 1222. A MAC PDU 1222 is a bit string that is byte aligned (i.e., multiple of 8 bits) in length. A MAC PDU 1222 comprises one or more MAC subPDUs 1302. A MAC subPDU 1302 starts with a MAC subheader 1304 (H). A MAC subheader 1304 is followed by subPDU payload 1306. The subPDU payload 1306 may comprise a MAC SDU 1220, a MAC Control Element (MAC CE) 1312, or padding 1314. A MAC SDU 1220 is a unit of data that is passed between layers of the radio protocol stack 1000 (i.e., the actual or raw data that an application layer wants to send or receive). A MAC CE 1312 is a specialized data structure within a MAC PDU 1222 used for conveying control information between a UE and a RAN (e.g., gNB 306). 5G NR has defined a list of MAC CEs in 3GPP TS 38.321 (Release 18), which is incorporated by reference as if fully included herein. MAC CEs facilitate faster signaling and consequently reduce latency in terms of switching of beams, Bandwidth Part (BWP) activation, Serving Cell (SCell) activation / deactivation, etc. Padding 1314 occurs at the end of a MAC PDU 1222. When a set of MAC subPDUs 1302 doesn’t exactly fill a Transport Block (TB) 1126, a MAC subPDU 1302 with padding 1314 is included. A MAC subPDU 1302 with only a MAC subheader 1304 implies zero-length padding. The MAC subheaders 1304, MAC SDUs 1220, and MAC CEs 1312 are bit strings that are byte aligned in length. The leftmost bit is the most significant bit.
[0087] The order of MAC subPDUs 1302 in a MAC PDU 1222 is defined. In sidelink (SL) and uplink (UL), the order of concatenation is MAC SDUs 1220, MAC CEs 1312, and then padding 1314. In downlink (DL), the order is MAC CEs 1312, MAC SDUs 1220, and then padding 1314. In each case, padding 1314 is the last MAC subPDU 1302. MAC SDUs 1220 are of variable size, except for an SDU carrying UL Common Control Channel (CCCH) data. Some MAC CEs 1312 are of fixed size, while others are of variable size. FIGS. 14A-14B are examples of a DL MAC PDU data structure 1400 and a UL MAC PDU data structure 1402, respectively.
[0088] FIGS. 15A-15B are block diagrams illustrating MAC subheaders 1304. FIG. 15A illustrates an R / F / LCID / (eLCID) / L MAC subheader 1502, and FIG. 15B illustrates an R / LCID / (eLCID) MAC subheader 1504. The reserved bit 1510 (R) is set to “0”. The format field 1512 (F) indicates the size of the length field 1518 (L). There is one format field 1512 per MAC subheader 1304 except for MAC subheaders 1304 corresponding to fixed- sized MAC CEs 1312 and padding 1314. The size of the format field 1512 is one bit where a “0” indicates 8-bits of the length field 1518, and a “1” indicates 16-bits of the length field 1518. The LCID field 1514 indicates a Logical Channel ID (LCID) 1515. There is one LCID field 1514 per MAC subheader 1304. The size of the LCID field 1514 is 6-bits. The eLCID field 1516 (optional) indicates an extended Logical Channel ID (eLCID) 1517. The size of the eLCID field 1516 is one byte if LCID=34 or two bytes if LCID=33. The length field 1518 (L) indicates the length of the corresponding MAC SDU 1220 or variable-sized MAC CE 1312 in bytes. There is one length field 1518 per MAC subheader 1304 except for MAC subheaders 1304 corresponding to fixedsized MAC CEs 1312 and padding 1314. The size of the length field 1518 is indicated by the format field 1512.
[0089] From a security perspective, one potential issue is that MAC data is unprotected and susceptible to security attacks. This vulnerability may lead to attacks which may hamper UE or network operations, impact UE data reception (e.g., Transmission Configuration Indicator (TCI) state), track UE location (e.g., Scell activation, selected beam, Timing Advance (TA) commands, etc.), Denial-of-Service (DoS) attack (e.g., by spoofing Beam Failure Recovery (BFR) indication from UE), etc. Data in higher layers of the radio protocol stack 1000 (i.e., higher than the MAC layer 1010) may be secured using integrity protection and / or encryption algorithms. In FIGS. 11-12, for example, IP packets 1202, SDAP data (e.g., SDAP SDU 1206) in the SDAP layer 1020, PDCP data (e.g., PDCP SDU 1210) in the PDCP layer 1014, and / or RLC data (e.g., RLC SDU 1214) in the RLC layer 1012 may be protected via integrity protection and / or encryption. In embodiments described herein, scrambling is used to protect MAC data at the MAC layer 1010 (control plane MAC data and / or user plane MAC data). Scrambling is a process to randomize the MAC data to be transmitted. Scrambling helps improve security by ensuring that unauthorized or malicious users are not able to decode the MAC data.
[0090] FIG. 16 is a block diagram of a MAC layer handler 1600 in an illustrative embodiment. A MAC layer handler 1600 is a data processing apparatus comprising circuitry, logic, hardware, an application, means, etc., configured to protect MAC data at the MAC layer 1010. A MAC layer handler 1600 may be implemented in a RAN node 304 (e.g., gNB 306) and a UE 106 to protect MAC data exchanged over the air interface. MAC layer handler 1600 comprises a MAC scrambler 1602 (also referred to as a randomizer) and a MAC descrambler 1604 (also referred to as a de-randomizer). MAC scrambler 1602 is configured to manipulate a data stream (i.e., MAC data 1610) before transmission (i.e., passed to the physical layer 1004). More particularly, MAC scrambler 1602 is configured to derive or generate one or more MAC scrambling codes 1608 based on a MAC scrambling configuration 1606. A MAC scrambling code 1608 is a random sequence or a pseudo-random sequence of bits that is applied to a data stream. MAC scrambler 1602 is further configured to scramble MAC data 1610 with a scrambling algorithm 1614 based on the MAC scrambling code 1608 to generate scrambled MAC data 1612. The scrambling algorithm 1614 may, for example, convert an input string (i.e., MAC data 1610) into a seemingly random output string of the same length by pseudo-randomly selecting bits to invert. However, any desired scrambling algorithm 1614 may be used.
[0091] MAC descrambler 1604 is configured to manipulate a scrambled data stream (i.e., scrambled MAC data 1612) that is received (i.e., passed from the physical layer 1004). More particularly, MAC descrambler 1604 is configured to reverse the process of the MAC scrambler 1602 to derive (descrambled) MAC data 1610 from scrambled MAC data 1612.
[0092] FIG. 17 is a block diagram of a MAC scrambling configuration 1606 in an illustrative embodiment. MAC scrambling configuration 1606 includes the following variables or parameters 1700: a degree of primitive polynomials parameter 1702, a pair of primitive polynomials parameter 1712, a DL scrambling code number parameter 1722, and a UL scrambling code number parameter 1732. A degree 1706 of a polynomial is the highest of the degrees of the polynomial’s monomials (individual terms) with non-zero coefficients. The degree of primitive polynomials parameter 1702 includes a degree value 1704 that indicates the degree 1706 of the primitive polynomials in the pair of primitive polynomials parameter 1712. A primitive polynomial is the minimal polynomial of a primitive element of the finite field GF(pm). The pair of primitive polynomials parameter 1712 includes a polynomial- 1 value 1714 indicating a first primitive polynomial 1716 (e.g., primitive polynomial-1) of the degree 1706. The pair of primitive polynomials parameter 1712 also includes a polynomial-2 value 1715 indicating a second primitive polynomial 1717 (e.g., primitive polynomial-2) of the degree 1706. FIG. 18 illustrates different degrees 1706 of primitive polynomials 1802. In this example, two different degrees 1706 of primitive polynomials 1802 are shown; one for degree=8, and one for degree=9. However, other degrees 1706 are considered herein.
[0093] In FIG. 17, the DL scrambling code number parameter 1722 includes a DL scrambling code number value 1724 that indicates the DL scrambling code number 1726 (also referred to as scrambling sequence index or scrambling sequence number). The DL scrambling code number 1726 is a unique code sequence number between 0 and (2Adegree-l). For a given degree and a given pair of primitive polynomials, a total of 2Adegree number of different complex scrambling code sequences can be generated, and the scrambling code number uniquely identifies each such code sequence. This number is similar to “scrambling code number n” in clause 5.2.2 from 3GPP TS 25.213 (Release 18), which is incorporated by reference as if fully included herein. Using a configuration described herein, equations similar to clause 5.2.2 from 3GPP TS 25.213 may be used to generate unique complex scrambling code sequences for DL. It is noted that in clause 5.2.2 from 3GPP TS 25.213, two fixed primitive polynomials of a fixed degree “18” are being used. However, varying degrees and various pairs of primitive polynomials may be used because of dynamic configurations being used.
[0094] The UL scrambling code number parameter 1732 includes a UL scrambling code number value 1734 that indicates the UL scrambling code number 1736. The UL scrambling code number 1736 is similar to the DL scrambling code number 1726, and uniquely identifies any particular complex scrambling code sequence which can be generated using any given pair of primitive polynomials of any given degree. There can be 2Adegree such unique numbers, and each number generates a unique complex scrambling code sequence. This number is similar to “scrambling sequence number n” in clause 4.3.2.2 from 3GPP TS 25.213. Using a configuration described here, equations similar to clause 4.3.2.2 from 3GPP TS 25.213 may be used to generate unique complex scrambling code sequences for UL. It is noted that in clause 4.3.2.2 from 3GPP TS 25.213, a fixed pair of primitive polynomials of a fixed degree “25” are being used. However, varying degrees and various pairs of primitive polynomials can be used because of dynamic configurations being used.
[0095] The MAC scrambling configuration 1606 may also include a validity duration 1742 indicating or specifying a duration where the MAC scrambling configuration 1606 is valid. The validity duration 1742 may be a time period, a number of packets or transport blocks 1126, etc. One technical benefit is a fresh MAC scrambling configuration 1606 may be generated at the expiration of the validity duration 1742, which further enhances security.
[0096] When MAC data 1610 is scrambled in transmissions between a RAN node 304 and a UE 106, both entities need to possess the same MAC scrambling configuration 1606. In an embodiment, both the RAN node 304 and a UE 106 derive the MAC scrambling configuration 1606. In another embodiment, the RAN node 304 derives the MAC scrambling configuration 1606, and provides the MAC scrambling configuration 1606 to the UE 106.
[0097] The following provides an embodiment where both the RAN node 304 and a UE 106 derive the MAC scrambling configuration 1606. FIGS. 19A-19B are flow charts illustrating a method 1900 of protecting MAC data 1610 in an illustrative embodiment. Method 1900 may be performed in a RAN node 304 (e.g., gNB 306) and a UE 106. The steps of the flow charts described herein are not all inclusive and may include other steps not shown, and the steps may be performed in an alternative order. FIG. 19A illustrates steps of method 1900 for a transmission operation from a device (e.g., transmitting MAC data 1610) over the air interface. In embodiments described herein, MAC data 1610 (or a portion thereof) scheduled for transmission is protected via scrambling before being passed to the physical layer 1004. The MAC layer handler 1600 generates or derives a MAC scrambling configuration 1606 (step 1902). In an embodiment described in further detail below, the MAC scrambling configuration 1606 may be a random configuration 1750 or a pseudo-random configuration 1752 (see FIG. 17). In other words, parameters 1700 of the MAC scrambling configuration 1606 may be defined by random numbers or pseudo-random numbers. One technical benefit is the MAC scrambling configuration 1606 is more difficult to reproduce by a malicious entity.
[0098] The MAC layer handler 1600 generates or derives a MAC scrambling code 1608 based on the MAC scrambling configuration 1606 (step 1904). The MAC scrambling code 1608 may then be used to protect MAC data 1610. Thus, the MAC layer handler 1600 identifies MAC data 1610 scheduled for transmission (step 1906). For example, MAC layer handler 1600 may receive data (e.g., RLC PDUs 1216) from a higher layer (e.g., RLC layer 1012) that is scheduled for transmission (step 1908). The MAC layer handler 1600, through MAC scrambler 1602, performs scrambling of the MAC data 1610 (i.e., at least a portion thereof) using or based on the MAC scrambling code 1608 (step 1910). The MAC layer handler 1600 may scramble a portion of the MAC data 1610, such as one or more MAC CEs 1312 (optional step 1912), one or more MAC SDUs 1220 (optional step 1914), etc. The MAC layer handler 1600 may scramble all of the MAC data 1610, such as a MAC PDU 1222 or transport block 1126 (optional step 1916). With the desired MAC data 1610 scrambled, the MAC layer handler 1600 passes or submits the scrambled MAC data 1612 to the physical layer 1004 (step 1918).
[0099] When a validity duration 1742 is defined for the MAC scrambling configuration 1606 and has not expired or ended, the MAC layer handler 1600 may continue to scramble MAC data 1610 using the MAC scrambling code 1608. In other words, the MAC layer handler 1600 derives a MAC scrambling code 1608 based on the derived MAC scrambling configuration 1606 (step 1906 of FIG. 19A), and scrambles MAC data 1610 based on the derived MAC scrambling code 1608 (step 1908 of FIG. 19 A) when the MAC scrambling configuration 1606 is valid based on the validity duration 1742. When the validity duration 1742 expires, MAC layer handler 1600 may generate a new or fresh MAC scrambling configuration 1606 (see step 1902).
[0100] FIG. 20 illustrates a scrambling process 2000 in an illustrative embodiment. The scrambling process 2000 (also referred to as a scrambling procedure or operation) may represent run-time processing in a transmitter device (e.g., gNB 306 or UE 106). MAC data 1610 may be scrambled after performing serial-to-parallel bit conversion 2010 to create I- and Q-branches, where I and Q denote real and imaginary parts, respectively. The even bits 2002 of the MAC data 1610 may be used for the I-branch, and the odd bits 2004 of the MAC data 1610 may be used as the Q-branch for a complex number representation of I+jQ. Another conversion may be performed where a bit value of “0” is represented as a “1” and a bit value of “1” is represented as “-1”. MAC scrambler 1602 scrambles the MAC data 1610 by multiplying the resultant signals on the I- and Q-branches by the MAC scrambling code 1608. After scrambling, parallel-to- serial bit conversion 2012 of the bit representations is performed to generate the scrambled MAC data 1612.
[0101] In generating the MAC scrambling configuration 1606 as described above (step 1902), the MAC layer handler 1600 may generate pseudo-random numbers for the parameters 1700 of the MAC scrambling configuration 1606. FIG. 21 is a flow chart illustrating additional details of method 1900 in an illustrative embodiment. FIGS. 22A-22B illustrate MAC scrambling configuration generation 2200 in an illustrative embodiment. In FIG. 22A, MAC layer handler 1600 may implement a pseudo-random number generator 2204. Pseudo-random number generator 2204 is a hardware or software device configured to generate a pseudo-random sequence of numbers or symbols. In this embodiment, pseudo-random number generator 2204 is configured to generate multiple pseudo-random numbers 2230 (e.g., five, six, etc.) for the parameters 1700 of the MAC scrambling configuration 1606. Thus, pseudo-random number generator 2204 may implement or use a single pseudo-random number function 2206 to generate the multiple pseudo-random numbers 2230, or may use multiple pseudo-random number functions 2206 to generate the multiple pseudo-random numbers 2230 (e.g., one pseudo-random number function 2206 per pseudo-random number generated). One technical benefit is a MAC scrambling configuration 1606 is more difficult to replicate by an attacker or the like when the configuration is pseudo-random.
[0102] In this embodiment, the pseudo-random numbers 2230 generated for the MAC scrambling configuration 1606 need to be reproducible at the gNB 306 and the UE 106. Thus, the pseudo-random number generator 2204 is seeded with one or more MAC scrambling keys 2208. A seed 2210 is a positive integer that initializes a pseudo-random number generator to create reproducible streams of random numbers. The scrambling key(s) 2208 is used as a seed 2210 to the pseudo-random number generator 2204. For example, when a single pseudo-random number function 2206 is used to generate the multiple pseudo-random numbers 2230, a single scrambling key 2208 may be used as the seed 2210. When multiple pseudo-random number functions 2206 are used to generate the multiple pseudo-random numbers 2230, multiple scrambling keys 2208 may be used as seeds 2210.
[0103] In FIG. 21, the MAC layer handler 1600 identifies one or more scrambling keys 2208 (step 2102). In an embodiment, the MAC layer handler 1600 may re-use one or more existing keys (optional step 2104), such as from the key hierarchy 700 illustrated in FIG. 7. In FIG. 22A, for example, the MAC layer handler 1600 may use one or more existing keys 2216 previously generated during primary authentication of a UE, such as for ciphering and / or integrity protection in the access-stratum (i.e., AS security context). The existing keys 2216 may comprise the KRRCint key 710, the KRRCenc key 711, the Kupint key 712, the Kupenc key 713, the NH key 714, etc. The gNB 306 and the UE 106 may be pre-configured with information indicating which existing keys 2216 to use. In an embodiment, the MAC layer handler 1600 may generate or derive one or more new keys (optional step 2106). In FIG. 22A, for example, the MAC layer handler 1600 may derive one or more new keys 2214 with a key generator 2212. The key generator 2212 may use a variety of key derivation processes as desired to derive the new key(s) 2214.
[0104] In FIG. 21, the pseudo-random number generator 2204 generates a pseudo-random number for each parameter 1700 of the MAC scrambling configuration 1606 using the scrambling key(s) 2208 as a seed 2210 (step 2108). The pseudo-random number generator 2204 may also generate a pseudo-random number for the validity duration 1742 using a scrambling key 2208 as a seed 2210 (optional step 2110 in FIG. 21). In FIG. 22B, for example, the pseudorandom number generator 2204 may generate a pseudo-random number 2230 of “9” for the degree value 1704, a pseudo-random number 2230 of “2” for the polynomial- 1 value 1714, a pseudo-random number 2230 of “7” for the polynomial-2 value 1715, a pseudo-random number 2230 of “13” for the DL scrambling code number value 1724, a pseudo-random number 2230 of “42” for the UL scrambling code number value 1734, and a pseudo-random number 2230 of “63” for the validity duration 1742. The pseudo-random number generator 2204 may include constraints 2220 for the pseudo-random numbers 2230 that are generated so that the pseudorandom numbers 2230 are within desired ranges or limits. For example, a constraint 2220 for the degree value 1704 may be a range of “8-9”, “8-10”, etc.
[0105] FIG. 23 illustrates a MAC scrambling configuration 1606 in an illustrative embodiment. Based on the pseudo-random numbers 2230 generated in FIG. 22B, the MAC scrambling configuration 1606 indicates a pair of primitive polynomials (i.e., polynomial- 1 = 2 and primitive polynomial-2 = 7) of degree “9”.
[0106] The MAC layer handler 1600 is configured to reverse the process of scrambling to derive (descrambled) MAC data 1610 from scrambled MAC data 1612. FIG. 19B illustrates steps of method 1900 for a receiving operation at a device (e.g., receiving MAC data 1610) over the air interface. The MAC layer handler 1600 receives scrambled MAC data 1612 passed from the physical layer 1004 (step 1922). The MAC layer handler 1600, through MAC descrambler 1604, performs descrambling of scrambled MAC data 1612 (i.e., at least a portion thereof) using or based on the derived MAC scrambling code 1608 (step 1924). The MAC layer handler 1600 may descramble a portion of the scrambled MAC data 1612, such as one or more MAC CEs 1312 (optional step 1926), one or more MAC SDUs 1220 (optional step 1928), etc. The MAC layer handler 1600 may descramble all of the scrambled MAC data 1612, such as a MAC PDU 1222 or transport block 1126 (optional step 1930). The MAC layer handler 1600 then passes or submits the descrambled MAC data 1610 to a higher layer (step 1932), such as the RLC layer 1012.
[0107] FIG. 24 illustrates a descrambling process 2400 in an illustrative embodiment. The descrambling process 2400 (also referred to as a descrambling procedure or operation) may represent run-time processing in a receiver device (e.g., gNB 306 or UE 106). For the descrambling process 2400, the MAC descrambler 1604 reverses the process of the MAC scrambler 1602 described above and shown in FIG. 20.
[0108] One technical benefit is MAC data 1610 is protected when sent over the air interface using a scrambling technique. Another technical benefit is the scrambling technique is not as computationally intensive when compared to other protection techniques (e.g., encryption / ciphering and integrity protection). Thus, there is minimal processing overhead as scrambling can be done using hardware-level or chip-level implementations.
[0109] The following provides an embodiment where the RAN node 304 derives the MAC scrambling configuration 1606. FIGS. 25A-25B are flow charts illustrating a method 2500 of protecting MAC data 1610 in an illustrative embodiment. Method 2500 may be performed in a RAN node 304 (e.g., gNB 306). FIG. 25 A illustrates steps of method 2500 for a transmission operation from a RAN node 304 to a UE 106 over the air interface. In embodiments described herein, MAC data 1610 (or a portion thereof) scheduled for transmission is protected via scrambling before being passed to the physical layer 1004. The MAC layer handler 1600 of the RAN node 304 generates or derives a MAC scrambling configuration 1606 (step 2502). In this embodiment, the MAC layer handler 1600 may generate a pseudo-random configuration 1752 as described above for the MAC scrambling configuration 1606. In another example, the MAC layer handler 1600 may generate a random configuration 1750. The RAN node 304 may generate a MAC scrambling configuration 1606 each time a new channel is established.
[0110] FIG. 26 illustrates MAC scrambling configuration generation 2600 in an illustrative embodiment. The MAC layer handler 1600 may implement a random number generator 2604. Random number generator 2604 is a hardware or software device configured to generate a random sequence of numbers or symbols. In this embodiment, random number generator 2604 is configured to generate multiple random numbers 2630 (e.g., five, six, etc.) for the parameters 1700 of the MAC scrambling configuration 1606. Thus, random number generator 2604 may implement or use a single random number function 2606 to generate the multiple random numbers 2630, or may use multiple random number functions 2606 to generate the multiple random numbers 2630 (e.g., one random number function 2606 per random number generated). One technical benefit is a MAC scrambling configuration 1606 is more difficult to replicate by an attacker or the like when the configuration is random.
[0111] In this embodiment, the UE 106 does not independently derive the MAC scrambling configuration 1606, so the RAN node 304 transmits or provides the MAC scrambling configuration 1606 to the UE 106 (step 2504). The MAC layer handler 1600 generates or derives a MAC scrambling code 1608 based on the MAC scrambling configuration 1606 (step 2506). The MAC scrambling code 1608 may then be used to protect MAC data 1610 sent to the UE 106. Thus, the MAC layer handler 1600 identifies MAC data 1610 scheduled for transmission to the UE 106 (step 2508). For example, MAC layer handler 1600 may receive data (e.g., RLC PDUs 1216) from a higher layer (e.g., RLC layer 1012) that is scheduled for transmission (step 2510). In a transmission from a RAN node 304 to a UE 106, the MAC data 1610 may be referred to as DL MAC data 1610. The MAC layer handler 1600, through MAC scrambler 1602, performs scrambling of the DL MAC data 1610 (i.e., at least a portion thereof) using or based on the MAC scrambling code 1608 (step 2512). The MAC layer handler 1600 may scramble a portion of the DL MAC data 1610, such as one or more MAC CEs 1312 (optional step 2514), one or more MAC SDUs 1220 (optional step 2516), etc. The MAC layer handler 1600 may scramble all of the DL MAC data 1610, such as a MAC PDU 1222 or transport block 1126 (optional step 2518). With the desired DL MAC data 1610 scrambled, the MAC layer handler 1600 passes or submits the scrambled DL MAC data 1612 to the physical layer 1004 (step 2520). When a validity duration 1742 is defined for the MAC scrambling configuration 1606 and has not expired or ended, the MAC layer handler 1600 may continue to scramble DL MAC data 1610 using the MAC scrambling code 1608. When the validity duration 1742 expires, MAC layer handler 1600 may generate a new MAC scrambling configuration 1606 (see step 2502).
[0112] The MAC layer handler 1600 of the RAN node 304 is configured to reverse the process of scrambling to derive (descrambled) MAC data 1610 from scrambled MAC data 1612. FIG. 25B illustrates steps of method 2500 for a receiving operation at RAN node 304. The MAC layer handler 1600 receives scrambled MAC data 1612 passed from the physical layer 1004 (step 2522). In a transmission from a UE 106 to a RAN node 304, the scrambled MAC data 1612 may be referred to as scrambled UL MAC data 1612. The MAC layer handler 1600, through MAC descrambler 1604, performs descrambling of the scrambled UL MAC data 1612 (i.e., at least a portion thereof) using or based on the MAC scrambling code 1608 (step 2524). The MAC layer handler 1600 may descramble a portion of the scrambled UL MAC data 1612, such as one or more MAC CEs 1312 (optional step 2526), one or more MAC SDUs 1220 (optional step 2528), etc. The MAC layer handler 1600 may descramble all of the scrambled UL MAC data 1612, such as a MAC PDU 1222 or transport block 1126 (optional step 2530). The MAC layer handler 1600 then passes or submits the descrambled UL MAC data 1610 to a higher layer (step 2532), such as the RLC layer 1012.
[0113] One technical benefit is MAC data 1610 is protected when sent over the air interface using a scrambling technique. Another technical benefit is the scrambling technique is not as computationally intensive when compared to other protection techniques (e.g., encryption / ciphering and integrity protection). Thus, there is minimal processing overhead in the RAN node 304 as scrambling can be done using hardware-level or chip-level implementations .
[0114] EIGS. 27A-27B are flow charts illustrating a method 2700 of protecting MAC data 1610 in an illustrative embodiment. Method 2700 may be performed in a UE 106. EIG. 27A illustrates steps of method 2700 for a transmission operation from a UE 106 to a RAN node 304 over the air interface. In embodiments described herein, MAC data 1610 (or a portion thereof) scheduled for transmission is protected via scrambling before being passed to the physical layer 1004. The UE 106 receives a MAC scrambling configuration 1606 (step 2702). As described above, the UE 106 does not independently derive the MAC scrambling configuration 1606, so the network has to provide the MAC scrambling configuration 1606 to the UE 106. When the RAN node 304 generates the MAC scrambling configuration 1606 as described above, the UE 106 may receive the MAC scrambling configuration 1606 from the RAN node 304. However, other network elements (e.g., AMF 212) may generate and provide the MAC scrambling configuration 1606 to the UE 106.
[0115] The MAC layer handler 1600 generates or derives a MAC scrambling code 1608 based on the MAC scrambling configuration 1606 (step 2704). The MAC scrambling code 1608 may then be used to protect MAC data 1610 sent to the RAN node 304. Thus, the MAC layer handler 1600 identifies MAC data 1610 scheduled for transmission to the RAN node 304 (step 2706). For example, MAC layer handler 1600 may receive data (e.g., RLC PDUs 1216) from a higher layer (e.g., RLC layer 1012) that is scheduled for transmission (step 2708). In a transmission from a UE 106 to a RAN node 304, the MAC data 1610 may be referred to as UL MAC data 1610. The MAC layer handler 1600, through MAC scrambler 1602, performs scrambling of the UL MAC data 1610 (i.e., at least a portion thereof) using or based on the MAC scrambling code 1608 (step 2710). The MAC layer handler 1600 may scramble a portion of the UL MAC data 1610, such as one or more MAC CEs 1312 (optional step 2712), one or more MAC SDUs 1220 (optional step 2714), etc. The MAC layer handler 1600 may scramble all of the UL MAC data 1610, such as a MAC PDU 1222 or transport block 1126 (optional step 2716). With the desired UL MAC data 1610 scrambled, the MAC layer handler 1600 passes or submits the scrambled UL MAC data 1612 to the physical layer 1004 (step 2718).
[0116] The MAC layer handler 1600 of the UE 106 is configured to reverse the process of scrambling to derive (descrambled) MAC data 1610 from scrambled MAC data 1612. FIG. 27B illustrates steps of method 2700 for a receiving operation at UE 106. The MAC layer handler 1600 receives scrambled MAC data 1612 passed from the physical layer 1004 (step 2722). In a transmission from a RAN node 304 to a UE 106, the scrambled MAC data 1612 may be referred to as scrambled DL MAC data 1612. The MAC layer handler 1600, through MAC descrambler 1604, performs descrambling of the scrambled DL MAC data 1612 (i.e., at least a portion thereof) using or based on the MAC scrambling code 1608 (step 2724). The MAC layer handler 1600 may descramble a portion of the scrambled DL MAC data 1612, such as one or more MAC CEs 1312 (optional step 2726), one or more MAC SDUs 1220 (optional step 2728), etc. The MAC layer handler 1600 may descramble all of the scrambled DL MAC data 1612, such as a MAC PDU 1222 or transport block 1126 (optional step 2730). The MAC layer handler 1600 then passes or submits the descrambled DL MAC data 1610 to a higher layer (step 2732), such as the RLC layer 1012. One technical benefit is MAC data 1610 is protected when sent over the air interface using a scrambling technique. Another technical benefit is the scrambling technique is not as computationally intensive when compared to other protection techniques (e.g., encryption / ciphering and integrity protection). Thus, there is minimal processing overhead in the UE 106 as scrambling can be done using hardware-level or chip-level implementations.
[0117] FIGS. 28A-28D are signaling diagrams illustrating protection of MAC data 1610 in illustrative embodiments. FIGS. 28A-28B illustrate scenarios where a gNB 306 has a split architecture, and FIGS. 28C-28D illustrate scenarios where a gNB 306 has a non-split or colocated architecture.
[0118] FIG. 29 illustrates further details of an NG-RAN architecture 300. An NG-RAN 300 as in FIG. 29 is further described in 3GPP TS 38.401 (Release 18), which is incorporated by reference as if fully included herein. NG-RAN 300 comprises a set of gNBs 306 connected to 5GC 104 through the NG interface. As described above, a gNB 306 (also referred to as gNodeB) is a RAN node 304 that provides New Radio (NR) user plane and control plane protocol terminations towards the UE 106. A gNB 306 may comprise a gNB Central Unit (gNB-CU) 2910, and one or more gNB Distributed Units (gNB-DU) 2912. A gNB-CU 2910 is a logical node hosting RRC, Service Data Adaption Protocol (SDAP), and PDCP of the gNB that control the operation of one or more gNB-DUs 2912. A gNB-DU(s) 2912 is a logical node hosting REC, MAC, and physical (PHY) layers of the gNB, and its operation is partly controlled by the gNB-CU 2910. One gNB-DU 2912 supports one or multiple cells, and one cell is supported by only one gNB-DU 2912. A gNB-CU 2910 and a gNB-DU 2912 are connected via the Fl interface. A gNB 306 having a gNB-CU 2910 and one or more gNB-DUs 2912 is referred to as a split architecture 2922 or a functional split of the gNB 306. Otherwise, a gNB 306 is referred to as a non-split or co-located architecture 2920.
[0119] In FIG. 28A, it is assumed that UE authentication, NAS security context establishment, and AS security context establishment is completed. The gNB 306 (e.g., DU 2912) generates or derives a random or pseudo-random MAC scrambling configuration 1606 for protecting MAC data 1610, and provides a message 2801 to the UE 106 with the MAC scrambling configuration 1606. UE 106 may respond with a MAC scrambling configuration acknowledgement 2802. The DU 2912 and the UE 106 then each derive a MAC scrambling code 1608 as per the MAC scrambling configuration 1606.
[0120] For uplink communications from the UE 106 to the gNB 306, the UE 106 performs scrambling of MAC data 1610 (i.e., at least a portion of the MAC PDU) using the derived MAC scrambling code 1608. The UE 106 then transmits a UL packet 2810 to the gNB 306 that contains the scrambled MAC data 1612. In response to receiving the UL packet 2810, the DU 2912 descrambles the scrambled MAC data 1612 using the derived MAC scrambling code 1608.
[0121] For downlink communications from the gNB 306 to the UE 106, the DU 2912 performs scrambling of MAC data 1610 using the derived MAC scrambling code 1608. The DU 2912 then transmits a DL packet 2812 to the UE 106 that contains the scrambled MAC data 1612. In response to receiving the DL packet 2812, the UE 106 descrambles the scrambled MAC data 1612 using the derived MAC scrambling code 1608.
[0122] In FIG. 28B, it is assumed that UE authentication, NAS security context establishment, and AS security context establishment is completed. The gNB 306 (e.g., DU 2912) generates or derives a MAC scrambling configuration 1606 for protecting MAC data 1610, and the UE 106 also generates or derives the MAC scrambling configuration 1606 (i.e., the same configuration). In a gNB split architecture, a DU 2912 may be deployed as an NF in less secure environments, and it may not be safe to transfer keys from the CU 2910 to the DU 2912. Thus, the DU 2912 generates a new scrambling key(s) 2208 for seeding the pseudo-random number generator 2204, as opposed to reusing an existing key(s) 2216. Similarly, the UE 106 generates the new scrambling key(s) 2208 (i.e., the same key(s)) for seeding the pseudo-random number generator 2204. The DU 2912 and the UE 106 then each derive a MAC scrambling code 1608 as per the MAC scrambling configuration 1606. MAC data 1610 may be protected in uplink and downlink communications based on the derived MAC scrambling code 1608 as described above.
[0123] In FIG. 28C, it is assumed that UE authentication, NAS security context establishment, and AS security context establishment is completed. The gNB 306 generates or derives a random or pseudo-random MAC scrambling configuration 1606 for protecting MAC data 1610, and provides a message 2801 to the UE 106 with the MAC scrambling configuration 1606. UE 106 may respond with a MAC scrambling configuration acknowledgement 2802. The gNB 306 and the UE 106 then each derive a MAC scrambling code 1608 as per the MAC scrambling configuration 1606. MAC data 1610 may be protected in uplink and downlink communications based on the derived MAC scrambling code 1608 as described above.
[0124] In FIG. 28D, it is assumed that UE authentication, NAS security context establishment, and AS security context establishment is completed. The gNB 306 generates or derives a random MAC scrambling configuration 1606 for protecting MAC data 1610. In a gNB colocated architecture, the gNB 306 may re-use an existing key(s) 2216 (as shown in FIG. 28D) or generate a new scrambling key(s) 2208 for seeding the pseudo-random number generator 2204. Similarly, the UE 106 re-uses an existing key(s) 2216 or generates a new scrambling key(s) 2208 (i.e., the same key(s)) for seeding the pseudo-random number generator 2204. The gNB 306 and the UE 106 then each derive a MAC scrambling code 1608 as per the MAC scrambling configuration 1606. MAC data 1610 may be protected in uplink and downlink communications based on the derived MAC scrambling code 1608 as described above.
[0125] Any of the various elements or modules shown in the figures or described herein may be implemented as hardware, software, firmware, or some combination of these. For example, an element may be implemented as dedicated hardware. Dedicated hardware elements may be referred to as “processors”, “controllers”, or some similar terminology. When provided by a processor, the functions may be provided by a single dedicated processor, by a single shared processor, or by a plurality of individual processors, some of which may be shared. Moreover, explicit use of the term “processor” or “controller” should not be construed to refer exclusively to hardware capable of executing software, and may implicitly include, without limitation, digital signal processor (DSP) hardware, a network processor, application specific integrated circuit (ASIC) or other circuitry, field programmable gate array (FPGA), read only memory (ROM) for storing software, random access memory (RAM), non-volatile storage, logic, or some other physical hardware component or module.
[0126] Also, an element may be implemented as instructions executable by a processor or a computer to perform the functions of the element. Some examples of instructions are software, program code, and firmware. The instructions are operational when executed by the processor to direct the processor to perform the functions of the element. The instructions may be stored on storage devices that are readable by the processor. Some examples of the storage devices are digital or solid-state memories, magnetic storage media such as a magnetic disks and magnetic tapes, hard drives, or optically readable digital data storage media.
[0127] As used in this application, the term “circuitry” may refer to one or more or all of the following:
[0128] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry);
[0129] (b) combinations of hardware circuits and software, such as (as applicable):
[0130] (i) a combination of analog and / or digital hardware circuit(s) with software / firmware; and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions); and
[0131] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0132] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0133] Although specific embodiments were described herein, the scope of the disclosure is not limited to those specific embodiments. The scope of the disclosure is defined by the following claims and any equivalents thereof.
Claims
34What is claimed is:
1. An apparatus comprising: at least one processor; and at least one memory storing instructions, that when executed by the at least one processor, cause the apparatus at least to perform: receiving a medium access control (MAC) scrambling configuration; deriving a MAC scrambling code based on the MAC scrambling configuration; scrambling uplink MAC data based on the MAC scrambling code to generate scrambled uplink MAC data; and passing the scrambled uplink MAC data to a physical layer for transmission to a radio access network node.
2. The apparatus of claim 1, wherein the receiving the MAC scrambling configuration comprises: receiving the MAC scrambling configuration from the radio access network node.
3. The apparatus of claim 1, wherein: the MAC scrambling configuration comprises parameters defined by random numbers.
4. The apparatus of claim 1, wherein: the MAC scrambling configuration comprises one or more parameter values selected from: a first value indicating a degree of primitive polynomials; a second value indicating a first primitive polynomial of the degree; a third value indicating a second primitive polynomial of the degree; a fourth value indicating a downlink scrambling code number; and a fifth value indicating an uplink scrambling code number.
5. The apparatus of claim 1, wherein the receiving the MAC scrambling configuration further comprises: receiving a validity duration of the MAC scrambling configuration.
356. The apparatus of claim 1, wherein the scrambling comprises: scrambling one or more MAC control elements of the uplink MAC data.
7. The apparatus of claim 1, wherein the scrambling comprises: scrambling one or more MAC service data units of the uplink MAC data.
8. The apparatus of claim 1, wherein the scrambling comprises: scrambling a MAC protocol data unit or transport block containing the uplink MAC data.
9. The apparatus of claim 1, wherein the instructions when executed by the at least one processor, cause the apparatus at least to perform: receiving scrambled downlink MAC data passed from the physical layer regarding a transmission from the radio access network node; and descrambling the scrambled downlink MAC data based on the MAC scrambling code.
10. A method comprising: receiving a medium access control (MAC) scrambling configuration; deriving a MAC scrambling code based on the MAC scrambling configuration; scrambling uplink MAC data based on the MAC scrambling code to generate scrambled uplink MAC data; and passing the scrambled uplink MAC data to a physical layer for transmission to a radio access network node.
11. The method of claim 10, wherein the receiving the MAC scrambling configuration comprises: receiving the MAC scrambling configuration from the radio access network node.
12. The method of claim 10, wherein: the MAC scrambling configuration comprises parameters defined by random numbers.
13. The method of claim 10, wherein: the MAC scrambling configuration comprises one or more parameter values selected from:a first value indicating a degree of primitive polynomials; a second value indicating a first primitive polynomial of the degree; a third value indicating a second primitive polynomial of the degree; a fourth value indicating a downlink scrambling code number; and a fifth value indicating an uplink scrambling code number.
14. The method of claim 10, wherein the receiving the MAC scrambling configuration further comprises: receiving a validity duration of the MAC scrambling configuration.
15. The method of claim 10, wherein the scrambling comprises: scrambling one or more MAC control elements of the uplink MAC data.
16. The method of claim 10, wherein the scrambling comprises: scrambling one or more MAC service data units of the uplink MAC data.
17. The method of claim 10, wherein the scrambling comprises: scrambling a MAC protocol data unit or transport block containing the uplink MAC data.
18. The method of claim 10, wherein the instructions when executed by the at least one processor, cause the apparatus at least to perform: receiving scrambled downlink MAC data passed from the physical layer regarding a transmission from the radio access network node; and descrambling the scrambled downlink MAC data based on the MAC scrambling code.
19. A non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receive a medium access control (MAC) scrambling configuration; derive a MAC scrambling code based on the MAC scrambling configuration; scramble uplink MAC data based on the MAC scrambling code to generate scrambled uplink MAC data; and pass the scrambled uplink MAC data to a physical layer for transmission to a radio access network node.
20. An apparatus comprising: at least one processor; and at least one memory storing instructions, that when executed by the at least one processor, cause the apparatus at least to perform: generating a medium access control (MAC) scrambling configuration; deriving a MAC scrambling code based on the MAC scrambling configuration; scrambling downlink MAC data based on the MAC scrambling code to generate scrambled downlink MAC data; and passing the scrambled downlink MAC data to a physical layer for transmission to user equipment.
21. The apparatus of claim 20, wherein the instructions when executed by the at least one processor, cause the apparatus at least to perform: transmitting the MAC scrambling configuration to the user equipment.
22. The apparatus of claim 20, wherein: the MAC scrambling configuration comprises parameters defined by random numbers.
23. The apparatus of claim 20, wherein: the MAC scrambling configuration comprises one or more parameter values selected from: a first value indicating a degree of primitive polynomials; a second value indicating a first primitive polynomial of the degree; a third value indicating a second primitive polynomial of the degree; a fourth value indicating a downlink scrambling code number; and a fifth value indicating an uplink scrambling code number.
24. The apparatus of claim 23, wherein the generating the MAC scrambling configuration comprises: identifying at least one MAC scrambling key; and generating a random number for each of the parameter values using the at least one MAC scrambling key as a seed.3825. The apparatus of claim 24, wherein the identifying the at least one MAC scrambling key comprises one of: re-using at least one existing key generated during primary authentication of the user equipment as the at least one MAC scrambling key; or deriving at least one new key as the at least one MAC scrambling key.
26. The apparatus of claim 20, wherein the instructions when executed by the at least one processor, cause the apparatus at least to perform: generating a validity duration of the MAC scrambling configuration.
27. The apparatus of claim 26, wherein the generating the validity duration comprises: generating a random number for the validity duration.
28. The apparatus of claim 20, wherein the scrambling comprises: scrambling one or more MAC control elements of the downlink MAC data.
29. The apparatus of claim 20, wherein the scrambling comprises: scrambling one or more MAC service data units of the MAC data.
30. The apparatus of claim 20, wherein the scrambling comprises: scrambling a MAC protocol data unit or transport block containing the MAC data.
31. The apparatus of claim 20, wherein the instructions when executed by the at least one processor, cause the apparatus at least to perform: receiving scrambled uplink MAC data passed from the physical layer regarding a transmission from the user equipment; and descrambling the scrambled uplink MAC data based on the MAC scrambling code.3932. A method comprising: generating a medium access control (MAC) scrambling configuration; deriving a MAC scrambling code based on the MAC scrambling configuration; scrambling downlink MAC data based on the MAC scrambling code to generate scrambled downlink MAC data; and passing the scrambled downlink MAC data to a physical layer for transmission to user equipment.
33. The method of claim 32, further comprising: transmitting the MAC scrambling configuration to the user equipment.
34. The method of claim 32, wherein: the MAC scrambling configuration comprises parameters defined by random numbers.
35. The method of claim 32, wherein: the MAC scrambling configuration comprises one or more parameter values selected from: a first value indicating a degree of primitive polynomials; a second value indicating a first primitive polynomial of the degree; a third value indicating a second primitive polynomial of the degree; a fourth value indicating a downlink scrambling code number; and a fifth value indicating an uplink scrambling code number.
36. The method of claim 35, wherein the generating the MAC scrambling configuration comprises: identifying at least one MAC scrambling key; and generating a random number for each of the parameter values using the at least one MAC scrambling key as a seed.
37. The method of claim 36, wherein the identifying the at least one MAC scrambling key comprises one of: re-using at least one existing key generated during primary authentication of the user equipment as the at least one MAC scrambling key; or40 deriving at least one new key as the at least one MAC scrambling key.
38. The method of claim 32, further comprising: generating a validity duration of the MAC scrambling configuration.
39. The method of claim 38, wherein the generating the validity duration comprises: generating a random number for the validity duration.
40. The method of claim 32, wherein the scrambling comprises: scrambling one or more MAC control elements of the downlink MAC data.
41. The method of claim 32, wherein the scrambling comprises: scrambling one or more MAC service data units of the MAC data.
42. The method of claim 32, wherein the scrambling comprises: scrambling a MAC protocol data unit or transport block containing the MAC data.
43. The method of claim 32, further comprising: receiving scrambled uplink MAC data passed from the physical layer regarding a transmission from the user equipment; and descrambling the scrambled uplink MAC data based on the MAC scrambling code.
44. A non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: generate a medium access control (MAC) scrambling configuration; derive a MAC scrambling code based on the MAC scrambling configuration; scramble downlink MAC data based on the MAC scrambling code to generate scrambled downlink MAC data; and pass the scrambled downlink MAC data to a physical layer for transmission to user equipment.
Citation Information
Patent Citations
Method and device for distributing scrambling codes
CN101692732A
Method and apparatus for enhancing security of mac layer entity in next-generation mobile communication system
US20220240094A1
Layer 2 security enhancement
US20240214799A1