Method and apparatus for dynamically changing security algorithm

The dynamic change of security algorithms based on conditions addresses the challenge of balancing security and efficiency in communication networks by allowing negotiation and adaptation, enhancing security and reducing energy consumption and latency.

WO2026114709A1PCT designated stage Publication Date: 2026-06-04NOKIA TECHNOLOGIES OY

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2025-11-19
Publication Date
2026-06-04

Smart Images

  • Figure EP2025083498_04062026_PF_FP_ABST
    Figure EP2025083498_04062026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a method and an apparatus for dynamically changing security algorithm. An apparatus operating as a terminal device comprises: at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus operating as the terminal device at least to perform: receiving, from a network entity, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of security algorithm; and transmitting, to the network entity, an accept message, when the apparatus operating as the terminal device supports the list of security algorithms and the change pattern of security algorithm. With the dynamical change, the number of permutations and combinations of algorithms and keys may be increased. The security level may be further improved.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD AND APPARATUS FOR DYNAMICALLY CHANGING SECURITYALGORITHMTECHNICAL FIELD

[0001] Various example embodiments of the present disclosure relate generally to the technology of communication, and in particular to a method and apparatus for dynamically changing security algorithm.BACKGROUND

[0002] In communication networks, the communication content needs to be encrypted to improve security. In accordance with the increasing security requirements, various security algorithms are developed.

[0003] Generally, each of them has its own pros and cons. For example, a security algorithm with higher security level may need a longer key length and / or more complicated computation, and thus may cause some delay during communication and / or more energy consumption, relatively. In contrast, a simpler security algorithm with shorter key length and / or easier computation might have lower security level.SUMMARY

[0004] This summary is provided to introduce some aspects in a simplified form that are further described below in the detailed description. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.

[0005] Certain aspects of the present disclosure and their embodiments may provide solutions to these or other challenges. There are, proposed herein, various embodiments which address one or more of the issues disclosed herein. Specific method and apparatus for dynamically changing security algorithm may be provided.

[0006] A first aspect of the present disclosure provides an apparatus operating as a terminal device, comprising: at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus operating as the terminal device at least to perform: receiving, from a network entity, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of security algorithm; and transmitting, to the networkentity, an accept message, when the apparatus operating as the terminal device supports the list of security algorithms and the change pattern of security algorithm.

[0007] In exemplary embodiments of the present disclosure, the indication indicates a condition to trigger a change of security algorithm, and a manner to select a security algorithm from the list of security algorithms to be used after the change of security algorithm is triggered.

[0008] In exemplary embodiments of the present disclosure, the condition to trigger the change comprises at least one of: a time based condition, or a payload based condition. The time based condition is met after a security algorithm has been used for a configured time period. The payload based condition is met after a security algorithm has been used for a configured amount of payload. An amount of pay load is indicated by at least one of: a length of plain text, or a quantity number of messages.

[0009] In exemplary embodiments of the present disclosure, the indication indicates that security algorithms in the list of security algorithms are to be used cyclically.

[0010] In exemplary embodiments of the present disclosure, the indication indicates that a sequence number of the security algorithm to be used is determined based on a set of bits from a key. The set of bits to determine the security algorithm to be used has a first position in the key, and a set of bits to determine a previously used security algorithm has a second position in the key. The first position has a shift from the second position.

[0011] In exemplary embodiments of the present disclosure, the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus operating as the terminal device at least to perform: transmitting a reject message to the network entity, when the apparatus operating as the terminal device does not support at least one of: the list of security algorithms, or the change pattern of security algorithm.

[0012] In exemplary embodiments of the present disclosure, the reject message includes at least one of: a list of supported security algorithms, or a supported change pattern of security algorithm of the apparatus operating as the terminal device.

[0013] In exemplary embodiments of the present disclosure, the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus operating as the terminal device at least to perform: receiving, from the network entity, a second message for configuring security mode, wherein the second message comprises at least one of: at least a part of the list of supported security algorithms, and / or an indication of the supported change pattern of security algorithm.

[0014] In exemplary embodiments of the present disclosure, the at least one memory and thecomputer program code are further configured to, with the at least one processor, cause the apparatus operating as the terminal device at least to perform: waiting for a period after receiving the first message, when the apparatus operating as the terminal device does not support at least one of: the list of security algorithms, or the change pattern of security algorithm.

[0015] In exemplary embodiments of the present disclosure, an item of a security algorithm in the list of security algorithms comprises a type of the security algorithm and / or a key length of the security algorithm. The list of security algorithms comprises a subset of encryption algorithms, and / or a subset of integrity protection algorithms. The list of security algorithms is used for a Non- Access-Stratum, NAS, communication, and / or a Radio Resource Control, RRC, communication. The network entity comprises: a Radio Access Network, RAN, node, or a core network node including at least one of: an Access and Mobility Management Function, AMF, a user plane function, UPF, or a network data analytics function, NWDAF. The terminal device comprises: a user equipment, UE.

[0016] A second aspect of the present disclosure provides an apparatus operating as a network entity, comprising: at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus operating as the network entity at least to perform: transmitting, to a terminal device, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of security algorithm; and receiving, from the terminal device, an accept message, when the terminal device supports the list of security algorithms and the change pattern of security algorithm.

[0017] In exemplary embodiments of the present disclosure, the indication indicates a condition to trigger a change of security algorithm, and a manner to select a security algorithm from the list of security algorithms to be used after the change of security algorithm is triggered.

[0018] In exemplary embodiments of the present disclosure, the condition to trigger the change comprises at least one of: a time based condition, or a payload based condition. The time based condition is met after a security algorithm has been used for a configured time period. The payload based condition is met after a security algorithm has been used for a configured amount of payload. An amount of payload is indicated by a length of plain text, or a quantity number of messages.

[0019] In exemplary embodiments of the present disclosure, the indication indicates that security algorithms in the list of security algorithms are to be used cyclically.

[0020] In exemplary embodiments of the present disclosure, the indication indicates that a sequence number of the security algorithm to be used is determined based on a set of bits from a key. The set of bits to determine the security algorithm to be used has a first position in the key, and a set of bits todetermine a previously used security algorithm has a second position in the key. The first position has a shift from the second position.

[0021] In exemplary embodiments of the present disclosure, the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus operating as the network entity at least to perform: receiving a reject message from the terminal device, when the terminal device does not support at least one of: the list of security algorithms, or the change pattern of security algorithm.

[0022] In exemplary embodiments of the present disclosure, the reject message includes at least one of: a list of supported security algorithms, or a supported change pattern of security algorithm of the terminal device.

[0023] In exemplary embodiments of the present disclosure, the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus operating as the network entity at least to perform: storing at least one of: the list of supported security algorithms, or the supported change pattern of security algorithm of the terminal device; and transmitting, to the terminal device, a second message for configuring security mode, wherein the second message comprises at least one of: at least a part of the list of supported security algorithms, and / or an indication of the supported change pattern of security algorithm.

[0024] In exemplary embodiments of the present disclosure, the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus operating as the network entity at least to perform: determining that the terminal device does not support at least one of: the list of security algorithms, or the change pattern of security algorithm, when not receiving a response for a period after transmitting the first message.

[0025] In exemplary embodiments of the present disclosure, the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus operating as the network entity at least to perform: transmitting, to an operation administration network entity, a report about a capacity of the terminal device. At least one of: the list of security algorithms, or the indication of a change pattern of security algorithm is received from the operation administration network entity, or determined by the network entity.

[0026] In exemplary embodiments of the present disclosure, an item of a security algorithm in the list of security algorithms comprises a type of the security algorithm and / or a key length of the security algorithm. The list of security algorithms comprises a subset of encryption algorithms, and / or a subset of integrity protection algorithms. The list of security algorithms is used for a Non- Access-Stratum, NAS, communication, and / or a Radio Resource Control, RRC, communication. The network entitycomprises: a Radio Access Network, RAN, node, or a core network node including at least one of: an Access and Mobility Management Function, AMF, a user plane function, UPF, or a network data analytics function, NWDAF. The terminal device comprises: a user equipment, UE.

[0027] A third aspect of the present disclosure provides a method performed by an apparatus operating as a terminal device, comprising: receiving, from a network entity, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of security algorithm; and transmitting, to the network entity, an accept message, when the apparatus operating as the terminal device supports the list of security algorithms and the change pattern of security algorithm.

[0028] In exemplary embodiments of the present disclosure, the method is performed by the apparatus according to any of embodiments of the first aspect.

[0029] A fourth aspect of the present disclosure provides a method performed by an apparatus operating as a network entity, comprising: transmitting, to a terminal device, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of security algorithm; and receiving, from the terminal device, an accept message, when the terminal device supports the list of security algorithms and the change pattern of security algorithm.

[0030] In exemplary embodiments of the present disclosure, the method is performed by the apparatus according to any of embodiments of the second aspect.

[0031] A fifteenth aspect of the present disclosure provides a computer-readable storage medium storing instructions, which when executed by at least one processor of an apparatus, cause the at least one processor of the apparatus to perform at least the method according to any of the embodiments above mentioned.

[0032] According to embodiments of the present disclosure, the exemplary embodiments of the present disclosure propose a mechanism that provides specifical apparatuses / procedures to dynamically change security algorithm.

[0033] With the dynamical change, the number of permutations and combinations of algorithms and keys may be increased. The security level may be further improved.

[0034] Further, better performance, reduced energy consumption, lower latency and decreased computational load may be also achieved, by switching to relatively lesser security algorithms and shorter keys during certain periods. An approach may be provided for balancing security and efficiency.BRIEF DESCRIPTION OF DRAWINGS

[0035] The above and other aspects, features, and benefits of various embodiments of the present disclosure will become more fully apparent, by way of example, from the following detailed description with reference to the accompanying drawings, in which like reference numerals or letters are used to designate like or equivalent elements. The drawings are illustrated for facilitating better understanding of the embodiments of the disclosure and not necessarily drawn to scale, in which:

[0036] FIG. 1 is a diagram showing an example 3GPP 5G initial attach call flow.

[0037] FIG. 2 is a block diagram showing an exemplary structure for an apparatus operating as a terminal device, according to exemplary embodiments of the present disclosure.

[0038] FIG. 3A is a flow chart showing a method performed by an apparatus operating as a terminal device.

[0039] FIG. 3B is a flow chart showing further steps of the method as shown in FIG. 3A, according to exemplary embodiments of the present disclosure.

[0040] FIG. 3C is a flow chart showing further steps of the method as shown in FIG. 3A, according to exemplary embodiments of the present disclosure.

[0041] FIG. 3D is a flow chart showing further steps of the method as shown in FIG. 3A, according to exemplary embodiments of the present disclosure.

[0042] FIG. 4 is a block diagram showing an exemplary structure for an apparatus operating as a network entity, according to exemplary embodiments of the present disclosure.

[0043] FIG. 5A is a flow chart showing a method performed by an apparatus operating as a network entity.

[0044] FIG. 5B is a flow chart showing further steps of the method as shown in FIG. 5A, according to exemplary embodiments of the present disclosure.

[0045] FIG. 5C is a flow chart showing further steps of the method as shown in FIG. 5A, according to exemplary embodiments of the present disclosure.

[0046] FIG. 5D is a flow chart showing further steps of the method as shown in FIG. 5A, according to exemplary embodiments of the present disclosure.

[0047] FIG. 5E is a flow chart showing further steps of the method as shown in FIG. 5A, according to exemplary embodiments of the present disclosure.

[0048] FIG. 6 is a block diagram showing an apparatus / computer readable storage medium, according to embodiments of the present disclosure.

[0049] FIG. 7 is a block diagram showing exemplary apparatus units for a terminal device, which is suitable for performing the method according to embodiments of the disclosure.

[0050] FIG. 8 is a block diagram showing exemplary apparatus units for a network entity, which is suitable for performing the method according to embodiments of the disclosure.

[0051] FIG. 9 is a diagram showing an exemplary end-to-end message sequence including backward compatibility, according to embodiments of the present disclosure.

[0052] FIG. 10 is a diagram showing a first exemplary change pattern, according to embodiments of the present disclosure.

[0053] FIG. 11 is a diagram showing a second exemplary change pattern, according to embodiments of the present disclosure.

[0054] FIG. 12 is a diagram showing an exemplary structure for an NAS security change pattern information element, according to embodiments of the present disclosure.DETAILED DESCRIPTION

[0055] The embodiments of the present disclosure are described in detail with reference to the accompanying drawings. It should be understood that these embodiments are discussed only for better understanding, rather than limitations on the scope of the present disclosure. The described features, advantages, and characteristics of the disclosure may be combined in any suitable manner in one or more embodiments.

[0056] Generally, all terms used herein are to be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or is implied from the context in which it is used. The steps of any methods disclosed herein do not have to be performed in the exact order disclosed, unless clearly given and / or implied from the context. Any feature of any of the embodiments disclosed herein may be applied to any other embodiment, wherever appropriate.

[0057] As used herein, the term “network” or “communication network” refers to a network following any suitable communication standards (such for an internet network, or any wireless network). For example, wireless communication standards may comprise WLAN (Wireless Local Area Network), new radio (NR), long term evolution (LTE), LTE-Advanced, 5G NR, 6G etc. In the following description, the terms “network” and “system” can be used interchangeably.

[0058] The term “entity / network entity” refers to a computing device or computing node or computing function or any other devices (physical or virtual) in a communication network. For example, the node in the network may include a base station (BS), an access point (AP), or any other suitable device in a wireless communication network. The BS may be, for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), a next generation NodeB (gNodeB or gNB), a remote radio unit (RRU), a radio header (RH), a remote radio head (RRH), a relay, a low power node such asa femto, a pico, and so forth. Further, the node may include other core network node, such as an Access and Mobility Management Function, AMF, a Session Management Function, SMF, a User Plane Function, UPF, a mobility management entity, MME, or a serving gateway, S-GW, etc.

[0059] The term “terminal device” refers to any end device that can access a communication network and receive services therefrom. By way of example and not limitation, the terminal device refers to a mobile terminal, user equipment (UE), a non- AP device (such as a non-AP Station (STA)), or other suitable devices. The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, a wearable device, a vehicle-mounted wireless terminal device, a vehicle, and the like.

[0060] As one example, a terminal device may represent a device configured for communication in accordance with one or more communication standards promulgated by any standard organization, such as 3rdgeneration partnership project, 3GPP.

[0061] As yet another example, in an Internet of Things (loT) scenario, a terminal device may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another terminal device and / or network equipment. Particular examples of such machines or devices are sensors, metering devices such as power meters, industrial machinery, or home or personal appliances, for example refrigerators, televisions, personal wearables such as watches etc. In other scenarios, a terminal device may represent a vehicle or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.

[0062] It shall be understood that although the terms “first” and “second” etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed terms.

[0063] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0064] With evolution of mobile communication networks from second generation (2G) to 5thgeneration (5G) and beyond, secure communications, such as from user devices to the network, are becoming increasingly important. Secure communication includes integrity protection and confidentiality of control and user data. Symmetric secure communication uses a secret key both at thesender and receiver. 3rdgeneration partnership project (3GPP) systems typically support symmetric key systems. 3GPP supports a number of security algorithms including Advanced Encryption System (AES), Zu Chongzhi algorithm (ZUC) and SNOW 5G.

[0065] 5G introduced ultra-low latency communication for latency-sensitive services. In addition, networks are increasingly designed for higher performance in general and better energy efficiency / saving and lower latency in particular.

[0066] 3GPP supports a number of security algorithms including AES, ZUC and SNOW 5G. Each of them has its own pros and cons. For example, each of these algorithms support different key lengths.

[0067] FIG. 1 is a diagram showing an example 3GPP 5G initial attach call flow.

[0068] As shown in FIG. 1, the flow includes following main steps.

[0069] 1 The user equipment (UE) receives Synchronization Signal Block / Physical Broadcast Channel (SSB / PBCH) from the Radio Access Network (RAN).

[0070] 2 The UE receives System Information Block (SIB) from the RAN.

[0071] 3 The UE and RAN perform Random Access Channel (RACH) Process.

[0072] 4 The UE and RAN perform the Radio Resource Control (RRC) Establishment.

[0073] 5 The UE transmits the Registration Request to the Access and Mobility Management Function (AMF) via the RAN.

[0074] 6 The UE and the AMF perform the Authentication Process.

[0075] 7 The UE receives the Security Mode Command from the AMF, via non access stratum (NAS) message.

[0076] 8 The UE transmits the Security Mode Command Complete to the AMF, via NAS message.

[0077] 9 The UE receives the Security Mode Command from the RAN, via RRC message.

[0078] 10 The UE transmits the Security Mode Command Complete to the RAN, via RRC message.

[0079] 11 The UE and AMF perform procedures about registration accept and complete.

[0080] 12 The UE and RAN perform procedures about RRCReconfiguration.

[0081] 13 The UE and the Session Management Function procedures about Protocol Data Unit (PDU) session.

[0082] FIG. 1 highlights sending of NAS: Security mode command from AMF to UE and RRC: Security mode command from RAN to UE in BOLD and underline. These messages specify Integrity protection and ciphering algorithms to use over NAS and RRC respectively between UE and the AMF / RAN, respectively.

[0083] 3GPP Technical Specification (TS) 24.501 V18.6.0 (2024-03) defines NAS: Security mode command message with Selected NAS Security algorithms information element (IE) specifyingIntegrity protection and ciphering algorithms. 3GPP TS 24.501 specification defines Selected NAS Security algorithms IE specifying Integrity protection and ciphering algorithms.

[0084] 3GPP TS 38.331 V18.0.0 (2023-12) defines RRC: SecurityModeCommand message with SecurityAlgorithmConfig IE specifying Integrity protection and ciphering algorithms. 3GPP TS 38.331 specification defines SecurityAlgorithmConfig IE specifying Integrity protection and ciphering algorithms.

[0085] In 6thgeneration (6G), overall performance needs to be enhanced while keeping security intact or even enhancing it. One of the most important performance aspects is energy efficiency. Having stronger security could lead to increased computation, and hence, negatively affect the energy consumption.

[0086] Better security is typically achieved either by employing a better but often, complex security algorithm or by increasing the key length however, both techniques require more computing power thus increasing cost and energy. This also mean that security operations take longer thus increasing processing latency. This may result in challenges in meeting UE latency and energy efficiency / saving needs as well as network latency and energy efficiency / saving needs.

[0087] As the traffic grows, security operations could take longer and spend more energy thus making security a bottleneck. Many times, current art trades off security for performance and vice versa.

[0088] In 3GPP Services & Systems Aspects (SA) 3#117, S3-243400 is proposed for a new working item description (WID). This proposal is for allowing the UE to reject a security mode command if UE considers the proposed algorithm to be weak. In a non-emergency UE registration (attach) procedure, the current security algorithm decision made as part of the Security Mode negotiation is one-sided. The current procedure prevents the UE from rejecting, for example, an insecure algorithm or an algorithm known to be compromised, which erodes user privacy. Though this proposal was not agreed for release (Rel)-19, this could trigger offline discussions on allowing a negotiation of security algorithms between UE and the network, or likely to further affect the Rel-20.

[0089] Also, 256-bit algorithms are getting discussed in 3GPP SA3. Moreover, with quantum-safe algorithms getting discussed to be included in 3GPP, it is likely that older UEs (devices) do not support newer quantum- safe algorithms. Inclusion of such algorithms in Rel-19 / Rel-20 and future releases in 3GPP can pose an important challenge of backward compatibility for older UEs. Due to lack of support for quantum-safe or 256-bit algorithms, such UEs might be rendered vulnerable to attacks.

[0090] Some embodiments of the present disclosure may focus on the problem of achieving better performance while ensuring strong security.

[0091] FIG. 2 is a block diagram showing an exemplary structure for an apparatus operating as a terminal device, according to exemplary embodiments of the present disclosure.

[0092] As shown in FIG. 2, the apparatus 20 for a terminal device comprises at least one processor 202, and at least one memory 204 including computer program code. The at least one memory 204 and the computer program code are configured to, with the at least one processor 202, cause the apparatus 20 operating as the terminal device at least to perform the method according to any of the following embodiments, such as shown in FIG. 3A-FIG. 3D, FIG. 9-12.

[0093] FIG. 3A is a flow chart showing a method performed by an apparatus operating as a terminal device.

[0094] As shown in FIG. 3A, the method 300 comprises: a step S302, receiving, from a network entity, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of security algorithm; and a step S304, transmitting, to the network entity, an accept message, when the apparatus operating as the terminal device supports the list of security algorithms and the change pattern of security algorithm.

[0095] According to embodiments of the present disclosure, the exemplary embodiments of the present disclosure propose a mechanism that provides specifical apparatuses / procedures to dynamically change security algorithm.

[0096] With the dynamical change, the number of permutations and combinations of algorithms and keys may be increased. The security level may be further improved.

[0097] Further, better performance, reduced energy consumption, lower latency and decreased computational load may be also achieved, by switching to relatively lesser security algorithms and shorter keys during certain periods. An approach may be provided for balancing security and efficiency.

[0098] In exemplary embodiments of the present disclosure, the indication indicates a condition to trigger a change of security algorithm, and a manner to select a security algorithm from the list of security algorithms to be used after the change of security algorithm is triggered.

[0099] According to exemplary embodiments of the present disclosure, indication about a condition to trigger and a manner to select the security algorithm to be used may be provided from the network entity to the terminal device, the terminal device will be certain about the change pattern of security algorithms based on such indication in the message.

[0100] In exemplary embodiments of the present disclosure, the condition to trigger the change comprises at least one of: a time based condition, or a payload based condition. The time based condition is met after a security algorithm has been used for a configured time period. The payloadbased condition is met after a security algorithm has been used for a configured amount of payload. An amount of pay load is indicated by at least one of: a length of plain text, or a quantity number of messages.

[0101] According to exemplary embodiments of the present disclosure, various conditions to trigger may be supported, such as those based on time or payload.

[0102] In exemplary embodiments of the present disclosure, the indication indicates that security algorithms in the list of security algorithms are to be used cyclically.

[0103] According to exemplary embodiments of the present disclosure, various manners to determine the algorithm to be used may be also supported. A relatively simpler manner may be cyclically. For example, the algorithm in the list to be used may be the next one in the list, or the previous one, or the second one thereafter, or the third one therebefore, etc.

[0104] In exemplary embodiments of the present disclosure, the indication indicates that a sequence number of the security algorithm to be used is determined based on a set of bits from a key. The set of bits to determine the security algorithm to be used has a first position in the key, and a set of bits to determine a previously used security algorithm has a second position in the key. The first position has a shift from the second position.

[0105] According to exemplary embodiments of the present disclosure, other manners may be also used. For example, the algorithm to be used may be also related to other parameters, such as a key. Such a key will further improve the security level.

[0106] FIG. 3B is a flow chart showing further steps of the method as shown in FIG. 3A, according to exemplary embodiments of the present disclosure.

[0107] As shown in FIG. 3B, the method 300 further comprises: a step S306, transmitting a reject message to the network entity, when the apparatus operating as the terminal device does not support at least one of: the list of security algorithms, or the change pattern of security algorithm.

[0108] According to exemplary embodiments of the present disclosure, the terminal device may reject the configuration from the network entity, and thus the embodiments provide a mechanism for the terminal device to feedback to the network entity.

[0109] In exemplary embodiments of the present disclosure, the reject message includes at least one of: a list of supported security algorithms, or a supported change pattern of security algorithm of the apparatus operating as the terminal device.

[0110] According to exemplary embodiments of the present disclosure, the terminal device may provide a desired configuration to the network entity, and thus the embodiments provide a mechanism for the terminal device to negotiate with the network entity.

[0111] FIG. 3C is a flow chart showing further steps of the method as shown in FIG. 3A, according to exemplary embodiments of the present disclosure.

[0112] As shown in FIG. 3C, the method 300 further comprises: a step S308, receiving, from the network entity, a second message for configuring security mode, wherein the second message comprises at least one of: at least a part of the list of supported security algorithms, and / or an indication of the supported change pattern of security algorithm.

[0113] According to exemplary embodiments of the present disclosure, the terminal device may receive a supported configuration from the network entity, and thus the embodiments provide a mechanism for the terminal device to negotiate with the network entity.

[0114] FIG. 3D is a flow chart showing further steps of the method as shown in FIG. 3A, according to exemplary embodiments of the present disclosure.

[0115] As shown in FIG. 3D, the method 300 further comprises: a step S310, waiting for a period after receiving the first message, when the apparatus operating as the terminal device does not support at least one of: the list of security algorithms, or the change pattern of security algorithm.

[0116] According to exemplary embodiments of the present disclosure, the alter terminal devices, which cannot understand and utilize the first message may be also compatible.

[0117] In exemplary embodiments of the present disclosure, an item of a security algorithm in the list of security algorithms comprises a type of the security algorithm and / or a key length of the security algorithm. The list of security algorithms comprises a subset of encryption algorithms, and / or a subset of integrity protection algorithms. The list of security algorithms is used for a Non- Access-Stratum, NAS, communication, and / or a Radio Resource Control, RRC, communication. The network entity comprises: a Radio Access Network, RAN, node, or a core network node including at least one of: an Access and Mobility Management Function, AMF, a user plane function, UPF, or a network data analytics function, NWDAF. The terminal device comprises: a user equipment, UE.

[0118] According to exemplary embodiments of the present disclosure, the provided mechanism may be used to change the type of the security algorithm and the length of the key. Further, the provided mechanism may be generally and widely applicable to different algorithms, different types of communication, and different apparatus / device.

[0119] FIG. 4 is a block diagram showing an exemplary structure for an apparatus operating as a network entity, according to exemplary embodiments of the present disclosure.

[0120] As shown in FIG. 4, the apparatus 40 operating as a network entity comprises: at least one processor 402; and at least one memory 404 including computer program code. The at least one memory 404 and the computer program code configured to, with the at least one processor 402, causethe apparatus 40 operating as the network entity at least to perform any of the following embodiments, such as shown in FIG. 5A-FIG. 5E, FIG. 9-12.

[0121] FIG. 5A is a flow chart showing a method performed by an apparatus operating as a network entity.

[0122] As shown in FIG. 5A, the method 500 comprises: a step S502, transmitting, to a terminal device, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of security algorithm; and a step S504, receiving, from the terminal device, an accept message, when the terminal device supports the list of security algorithms and the change pattern of security algorithm.

[0123] In exemplary embodiments of the present disclosure, the indication indicates a condition to trigger a change of security algorithm, and a manner to select a security algorithm from the list of security algorithms to be used after the change of security algorithm is triggered.

[0124] In exemplary embodiments of the present disclosure, the condition to trigger the change comprises at least one of: a time based condition, or a payload based condition. The time based condition is met after a security algorithm has been used for a configured time period. The payload based condition is met after a security algorithm has been used for a configured amount of payload. An amount of payload is indicated by a length of plain text, or a quantity number of messages.

[0125] In exemplary embodiments of the present disclosure, the indication indicates that security algorithms in the list of security algorithms are to be used cyclically.

[0126] In exemplary embodiments of the present disclosure, the indication indicates that a sequence number of the security algorithm to be used is determined based on a set of bits from a key. The set of bits to determine the security algorithm to be used has a first position in the key, and a set of bits to determine a previously used security algorithm has a second position in the key. The first position has a shift from the second position.

[0127] FIG. 5B is a flow chart showing further steps of the method as shown in FIG. 5A, according to exemplary embodiments of the present disclosure.

[0128] In exemplary embodiments of the present disclosure, the method 500 further comprises: a step S506, receiving a reject message from the terminal device, when the terminal device does not support at least one of: the list of security algorithms, or the change pattern of security algorithm.

[0129] In exemplary embodiments of the present disclosure, the reject message includes at least one of: a list of supported security algorithms, or a supported change pattern of security algorithm of the terminal device.

[0130] FIG. 5C is a flow chart showing further steps of the method as shown in FIG. 5A, accordingto exemplary embodiments of the present disclosure.

[0131] In exemplary embodiments of the present disclosure, the method 500 further comprises: a step S508, storing at least one of: the list of supported security algorithms, or the supported change pattern of security algorithm of the terminal device; and a step S510, transmitting, to the terminal device, a second message for configuring security mode, wherein the second message comprises at least one of: at least a part of the list of supported security algorithms, and / or an indication of the supported change pattern of security algorithm.

[0132] According to embodiments of the present disclosure, the network entity may store historical data about the terminal device’s capability.

[0133] FIG. 5D is a flow chart showing further steps of the method as shown in FIG. 5A, according to exemplary embodiments of the present disclosure.

[0134] In exemplary embodiments of the present disclosure, the method 500 further comprises: a step S512, determining that the terminal device does not support at least one of: the list of security algorithms, or the change pattern of security algorithm, when not receiving a response for a period after transmitting the first message.

[0135] FIG. 5E is a flow chart showing further steps of the method as shown in FIG. 5A, according to exemplary embodiments of the present disclosure.

[0136] In exemplary embodiments of the present disclosure, the method 500 further comprises: a step S514, transmitting, to an operation administration network entity, a report about a capacity of the terminal device. At least one of: the list of security algorithms, or the indication of a change pattern of security algorithm is received from the operation administration network entity, or determined by the network entity.

[0137] According to exemplary embodiments of the present disclosure, the historical data about terminal device’s capability may be also provided to an operation administration network entity of an operator and / or an operation administration network entity in the core communication network.

[0138] In exemplary embodiments of the present disclosure, an item of a security algorithm in the list of security algorithms comprises a type of the security algorithm and / or a key length of the security algorithm. The list of security algorithms comprises a subset of encryption algorithms, and / or a subset of integrity protection algorithms. The list of security algorithms is used for a Non- Access-Stratum, NAS, communication, and / or a Radio Resource Control, RRC, communication. The network entity comprises: a Radio Access Network, RAN, node, or a core network node including at least one of: an Access and Mobility Management Function, AMF, a user plane function, UPF, or a network data analytics function, NWDAF. The terminal device comprises: a user equipment, UE.

[0139] The processor 202, 402 may be any kind of processing component, such as one or more microprocessor or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), special-purpose digital logic, and the like. The memory 204, 404 may be any kind of storage component, such as read-only memory (ROM), random-access memory, cache memory, flash memory devices, optical storage devices, etc.

[0140] FIG. 6 is a block diagram showing an apparatus / computer readable storage medium, according to embodiments of the present disclosure.

[0141] As shown in FIG. 6, a computer-readable storage medium 60 storing instructions 61, which when executed by at least one processor of an apparatus operating as a network node or a terminal device, cause the at least one processor of the apparatus to perform the method according to any of the embodiments above mentioned, such as shown in FIG. 3A-FIG. 3D, FIG. 5A-FIG. 5E, FIG. 9-12.

[0142] In addition, the present disclosure may also provide a carrier containing the computer program / instructions as mentioned above. The carrier is one of an electronic signal, optical signal, radio signal, or the above computer readable storage medium. The computer readable storage medium can be, for example, an optical compact disk or an electronic memory device like a RAM (random access memory), a ROM (read only memory), Flash memory, magnetic tape, CD-ROM, DVD, Blueray disc and the like.

[0143] FIG. 7 is a block diagram showing exemplary apparatus units for a terminal device, which is suitable for performing the method according to embodiments of the disclosure.

[0144] As shown in FIG. 7, the terminal device 70 may include: a receiving unit 702, configured for receiving, from a network entity, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of security algorithm; and a transmitting unit 704, configured for transmitting, to the network entity, an accept message, when the apparatus operating as the terminal device supports the list of security algorithms and the change pattern of security algorithm.

[0145] In exemplary embodiments of the present disclosure, the terminal device 70 is further configured for performing the method according to any of the embodiments above mentioned, such as shown in FIG. 3A-FIG. 3D, 9-12.

[0146] FIG. 8 is a block diagram showing exemplary apparatus units for a network entity, which is suitable for performing the method according to embodiments of the disclosure.

[0147] As shown in FIG. 8, the network entity may include: a transmitting unit 802, configured for transmitting, to a terminal device, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of securityalgorithm; and a receiving unit 804, configured for receiving, from the terminal device, an accept message, when the terminal device supports the list of security algorithms and the change pattern of security algorithm.

[0148] In exemplary embodiments of the present disclosure, the network entity 80 is further configured for performing the method according to any of the embodiments above mentioned, such as shown in FIG. 5A-FIG. 5E, FIG. 9-12.

[0149] The term ‘unit’ may have conventional meaning in the field of electronics, electrical devices and / or electronic devices and may include, for example, electrical and / or electronic circuitry, devices, modules, processors, memories, logic solid state and / or discrete devices, computer programs or instructions for carrying out respective tasks, procedures, computations, outputs, and / or displaying functions, and so on, as such as those that are described herein.

[0150] As used in the present disclosure, the term “circuitry” may refer to one or more or all of the following:(a) hardware-only circuit implementations (such as implementations in only analogy and / or digital circuitry) and(b) combinations of hardware circuits and software, such as (as applicable):(i) a combination of analogy and / or digital hardware circuit(s) with software / firmware and(ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and(c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.”

[0151] This definition of circuitry applies to all uses of this term in the present disclosure, including in any claims. As a further example, as used in the present disclosure, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0152] With these units, the apparatus may not need a fixed processor or memory, any kind of computing resource and storage resource may be arranged from at least onenode / device / entity / apparatus relating to the communication system. The virtualization technology and network computing technology (e.g., cloud computing) may be further introduced, so as to improve the usage efficiency of the network resources and the flexibility of the network.

[0153] The techniques described herein may be implemented by various means so that an apparatus implementing one or more functions of a corresponding apparatus described with an embodiment comprises not only prior art means, but also means for implementing the one or more functions of the corresponding apparatus described with the embodiment and it may comprise separate means for each separate function, or means that may be configured to perform two or more functions. For example, these techniques may be implemented in hardware (one or more apparatuses), firmware (one or more apparatuses), software (one or more modules / units), or combinations thereof. For a firmware or software, implementation may be made through modules (e.g., procedures, functions, and so on) that perform the functions described herein.

[0154] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionalities may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.

[0155] The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).

[0156] According to above embodiments, some further detailed solutions may be provided as follows.

[0157] It could be assumed that, the system supports a set A of ‘N‘ number of security algorithms: A = {A , ..., A ,...,A }; N >= 1; 1 <= i <= N.

[0158] Security algorithms are arranged in increasing order of security, i.e. Security of A <= ... <= Security of A. <= ... <= Security of A .

[0159] It could be further assumed that, each security algorithm Ai supports a set KEYSi of ‘Ni’number of keys:KEYS = { K , K ,...,K }; N >= 1; 1 <=j <= N . i il ij iN. i i

[0160] Keys are arranged in increasing order of length of key, i.e. Length of K <= ... <= Length of K . <= ... <= Length of K.N-

[0161] It could be further assumed that, a security algorithm at index ‘x’ in set ‘A’ i.e. A is selectedX and key at index ‘y’ for algorithm A in set ‘KEYS ’, i.e. K is selected. x>=l and y>=l. x x xy

[0162] Some embodiments of the present disclosure propose that in a predetermined pattern as negotiated between source and destination, security algorithms are changed from A to A or some1 X subset of them.

[0163] Similarly, in a predetermined pattern as negotiated between source and destination, keys are also changed from:• K to K for security algorithm A or some subset of them;• K to K for security algorithm A or some subset of them;21 2N2j b2• K to K for security algorithm A or some subset of them. xl xy x

[0164] As it is evident, when "lesser security" algorithms and shorter keys are used, there will be better performance (less energy, low latency, reduced computing and so on). However, from an attacker’s perspective, this invention makes choice of security algorithm also a variable thus the attacker has to try all the algorithms up to A and number of keys to be scanned by the attacker increasesXLength of K xy from 2 (a quantity number of possibly used values of the Kxy, which may be the longest key in the most secure algorithm)(a quantity number of combination of all possibly used values of all possible key and all possible secure algorithms) increasing the security manyfold.

[0165] With this proposal, the increased number of permutations and combinations of security algorithms and keys required to be attempted by an attacker significantly strengthens the security, while still having high performance windows during the communication between two entities. This also enables enhanced security for UEs compatible with Rel-18 or older 3GPP releases, which are not capable of supporting newer algorithms (like quantum safe or 256-bits).

[0166] It is assumed that the existing implementation of security key generation independently by entities involved in secure communication, i.e. network (RAN, core network (CN)) and UE would continue. In addition, modification to messages as identified in below embodiments may be implemented.

[0167] According to embodiments of the present disclosure, network (such as RAN, CN) and UE may change security algorithm and key in a given pattern as specified in below embodiments thus achieving better performance and enhanced security.

[0168] The embodiments of the present disclosure apply to currently supported 3GPP security algorithms and key lengths. Other alternatives can also include options for any kind of security algorithms to be supported and / or implemented in future, such as 256-bit and quantum safe algorithms.

[0169] FIG. 9 is a diagram showing an exemplary end-to-end message sequence including backward compatibility, according to embodiments of the present disclosure.

[0170] FIG. 9 illustrates the end-to-end message sequence for an exemplary embodiment of the present disclosure. Messages and message contents underlined in FIG. 9 are proposed by the embodiment of the present disclosure.

[0171] The message sequence mainly includes the following steps.

[0172] Step 0: This is an optional step which allows operator or Operation Administration and Maintenance (0AM) to configure the security change pattern details in the core network.

[0173] Step 1: UE primary authentication is successfully completed.

[0174] Step 2: After successful completion of UE authentication in step 1, core network can decide / derive a security change pattern. This decision can be implemented using historical data of security algorithm compatibility saved in the core network from steps 5a, 6a, and 9a described below. This step can help to optimize the selection of security algorithms and its parameters for specific UEs if same UEs are connecting to same core networks.

[0175] Step 3 : Core network sends NAS security mode command along with security change pattern IE as described in following Table 9.11.3.x.1. This can strengthen the security of UEs which do not support newer algorithms (like 256-bit or quantum safe), by allowing dynamic runtime changes in algorithms and key selections which is known only to the end entities - UE and core network.

[0176] Step 4: UE checks the security algorithms and parameters and verifies feasibility of security change pattern.

[0177] Step 5: If UE is capable of supporting the security algorithms and parameters and finds that the security change pattern is feasible, it responds with NAS Security Mode Command (SMC) Accept message.

[0178] Step 5a: Core network updates the information of supported algorithms and parameters for this UE in an internal database (DB). This can enable core network to derive appropriate IE in Step 2 when next NAS SMC is sent to the same UE.

[0179] Step 6: If UE does not support all algorithms and parameters but partially supports some from the given list, it responds with NAS SMC Reject message including the list of supported algorithms and parameters. For example, UEs which do not support quantum- safe algorithms can provide a list of algorithms supported along with this reject message.

[0180] Step 6a: Core network updates the information of supported algorithms and parameters for this UE in an internal DB. This can enable core network to derive appropriate IE in Step 2 when next NAS SMC is sent to the same UE.

[0181] Step 7: In this step, core network can send NAS SMC message with an updated IE for security change pattern. This updated IE can exclude what is not supported by this UE.

[0182] Step 8 : For the updated list, UE can respond with NAS SMC accept message.

[0183] Step 8a: This is an optional step where core network can send the information about supported security algorithms and parameters to OAM / operator. This can be used for further analytics.

[0184] Step 9, Step 9a, Step 10 and Step 11: For legacy UEs (which have not implemented SMC Reject message), core network can implement a timer in step 9. When the timer expires, core network can update local history for this UE’s supported algorithms and decide that such UEs are not yet upgraded in step 9a, and hence fall back to older SMC procedures in steps 10 and 11.

[0185] Step I la: This is an optional step where core network can send the information about supported security algorithms and parameters to OAM / operator. This can be used for further analytics.

[0186] Even though the above call flow is a core network centric example, it is evident that similar call flow could also be implemented for other communication procedures, such as a RAN-UE communication. For example, in a RAN-UE communication, the RAN node will send RRC security mode command messages to the UE, and thus configure the UE with the change pattern for security algorithms.

[0187] Some examples about the list of security algorithms, a condition to trigger a change of security algorithm, and a manner to select a security algorithm from the list of security algorithms to be used will be further illustrated.

[0188] FIG. 10 is a diagram showing a first exemplary change pattern, according to embodiments of the present disclosure.

[0189] In example 1, the condition to trigger is time based condition (which is configurable from the time based condition and the pay load based condition). Specifically, the algorithm may be changedevery 10 seconds.

[0190] The manner to select a security algorithm is based on a key. Specifically, it is based on a set of bits from a key. The position of the set of bits shifts each time to determine the security algorithm to be used when the change is triggered.

[0191] For example, in a time point 0s, three least significant bits (LSB) in position A of the key (which may be configurable from a derived key a reused algorithm key) are used to determine a sequence number of algorithm. In this example, the three LSB is 110 and may present a decimal value of 6. Thus, the algorithm NEA-126 with a sequence number of 6 in the list of algorithms is selected, and then is used for time period 0s (or, Is)- 10s.

[0192] Then, in time point Ils, the changed of algorithm is triggered. The three bits in position B, with a one-bit shift to position A, are used to determine a sequence number of algorithm. In this example, the three LSB is Oil and may present a decimal value of 3. Thus, the algorithm NEA-256 with a sequence number of 3 in the list of algorithms is selected, and then is used for time period 11s- 20s.

[0193] Further, in time point 21s, the changed of algorithm is triggered. The three bits in position C will be used.

[0194] FIG. 11 is a diagram showing a second exemplary change pattern, according to embodiments of the present disclosure.

[0195] In example 2, the condition to trigger the change is a payload size-based condition. Specifically, an algorithm is used for every 10 Mb data. The algorithms in the list will be used cyclically (Round-robin), and thus no additional parameters (such as the key) are needed.

[0196] It should be noted that, various combinations of the condition and manner may be used. For example, the condition may be time based and the algorithms may be used cyclically.

[0197] The following table captures Ciphering Speed in Mbps for three exemplar representative Ciphering Algorithms, namely, AES- 128, AES- 192 and AES-256 and gains on changing from longer key algorithm to shorter key algorithm (e.g. AES- 192 to AES- 128) based on certain lab tests:

[0198] Thus, according to embodiments of the present disclosure, shorter key algorithms may be used for better communication speed, and longer key algorithm may be used for enhanced security.

[0199] Thus, the flexible change of security algorithm during communication will provide both enhanced security and better performance.

[0200] According to embodiments of the present disclosure, some exemplary proposal may be also made for TS 24.501 Non-Access-Stratum (NAS) protocol for 5G System (5GS). It may be proposed to modify Security mode command message as follows (proposal underlined).Table 8.2.25.1.1: SECURITY MODE COMMAND message content

[0201] It should be noted that the name, value and / or other attributes of the proposed parameters are only examples for illustrative, rather than limitation.

[0202] Further details for the proposed parameters may be illustrated by following examples.9.11.3.x NAS security change pattern(see FIG. 12)Figure 9.11.3.X.1: NAS security change pattern information elementTable 9.11.3.X.1: NAS security algorithms information element

[0203] Further, similar changes could also be made in clause 1.1.1.1, TS 38.331 NR; Radio Resource Control (RRC) protocol specification for RAN-UE communication.

[0204] In 3GPP SA3#117, S3-243400 is proposed for a new WID. This proposal is for allowing the UE to reject a security mode command if UE considers the proposed algorithm to be weak. In a non-emergency UE registration (attach) procedure, the current security algorithm decision made aspart of the Security Mode negotiation is one-sided. The current procedure prevents the UE from rejecting, for example, an insecure algorithm or an algorithm known to be compromised, which erodes user privacy. Though this proposal was not agreed for Rel-19, this has triggered offline discussions on allowing a negotiation of security algorithms between UE and the network. The embodiments of the present disclosure will provide more enhancements to the proposal in Rel-20. This is also more likely to happen because of quantum-safe and 256-bit algorithms support which will be required in 3GPP.

[0205] Further, other related standards, such as relevant Open (O)-RAN standards could also be updated.

[0206] The embodiments may be applied in various kind of entities, such as various kinds of UE, core network functions (such as AMF, user plane function (UPF), network data analytics function (NWDAF)), RAN products (such as base stations), and Operation and Maintenance (O&M) products (inside or outside of the core network), and so on.

[0207] According to above exemplary embodiments of the present disclosure, the proposed method, apparatus and so on may be used for enhanced security for UEs based on a change between different combinations of security algorithms and security keys.

[0208] Such embodiments propose method for enhanced security for UEs by the increased number of permutations and combinations of security algorithms and keys by using security change pattern. The security change pattern enables dynamic runtime changes of security algorithms and key selections.

[0209] The proposed solution in such embodiments allows at least one of: strengthening of security increasing the number of permutations and combinations of algorithms and keys an attacker must attempt; better performance, reduced energy consumption, lower latency and decreased computational load by switching to 'lesser security' algorithms and shorter keys during certain periods; balanced approach to security and efficiency; or enhanced security for UEs compatible with Rel-18 or older 3GPP releases.

[0210] It should be understood that the above embodiments are only for illustration but not limitation. The present disclosure may be carried out in other ways than those specifically set forth herein without departing from essential characteristics of the disclosure. All changes to these embodiments not departing from the meaning and equivalency of the appended claims are intended to be comprised herein.

[0211] The following documents may be incorporated in their entirety by reference.3GPP TS 24.501 V18.6.0 (2024-03); Non- Access-Stratum (NAS) protocol for 5G System (5GS); Stage 33GPP TS 38.331 V18.0.0 (2023-12); NR; Radio Resource Control (RRC) protocol specification (Release 18)S3-243400, New mini WID on rejecting insecure security algorithms in NAS SMC procedure, 3GPP TSG-SA3 Meeting #127, Maastricht, Netherlands, 19 August -23 August 2024

[0212] ABBREVIATION EXPLANATIONAES Advanced Encryption SystemAMF Access and Mobility Management FunctionCN Core NetworkNAS Non-Access StratumRAN Radio Access NetworkUE User equipmentNEA NR Encryption AlgorithmNIA NR Integrity Protection AlgorithmAF Application FunctionUDM Unified Data ManagementUDR Unified Data RepositoryNEF Network Exposure FunctionNF Network FunctionNR New Radio3 GPP 3rd Generation Partnership ProjectTR Technical ReportNW Network3GPP 3rd generation partnership project5GC 5th Generation Core Network5G fifth generation6G sixth generationRRC Radio Resource ControlRel ReleaseDL DownlinkUL Uplink

Claims

CLAIMS1. An apparatus (20) operating as a terminal device, comprising: at least one processor (202); and at least one memory (204) including computer program code; the at least one memory (204) and the computer program code configured to, with the at least one processor (202), cause the apparatus (20) operating as the terminal device at least to perform: receiving, from a network entity, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of security algorithm; and transmitting, to the network entity, an accept message, when the apparatus operating as the terminal device supports the list of security algorithms and the change pattern of security algorithm.

2. The apparatus (20) operating as the terminal device according to claim 1, wherein the indication indicates a condition to trigger a change of security algorithm, and a manner to select a security algorithm from the list of security algorithms to be used after the change of security algorithm is triggered.

3. The apparatus (20) operating as the terminal device according to claim 2, wherein the condition to trigger the change comprises at least one of: a time based condition, or a payload based condition; wherein the time based condition is met after a security algorithm has been used for a configured time period; wherein the payload based condition is met after a security algorithm has been used for a configured amount of payload; and wherein an amount of payload is indicated by at least one of: a length of plain text, or a quantity number of messages.

4. The apparatus (20) operating as the terminal device according to any of claims 2 to 3, wherein the indication indicates that security algorithms in the list of security algorithms are to be used cyclically.

5. The apparatus (20) operating as the terminal device according to any of claims 2 to 3,wherein the indication indicates that a sequence number of the security algorithm to be used is determined based on a set of bits from a key; wherein the set of bits to determine the security algorithm to be used has a first position in the key, and a set of bits to determine a previously used security algorithm has a second position in the key; and wherein the first position has a shift from the second position.

6. The apparatus (20) operating as the terminal device according to any of claims 1 to 5, wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus operating as the terminal device at least to perform: transmitting a reject message to the network entity, when the apparatus operating as the terminal device does not support at least one of: the list of security algorithms, or the change pattern of security algorithm.

7. The apparatus (20) operating as the terminal device according to claim 6, wherein the reject message includes at least one of: a list of supported security algorithms, or a supported change pattern of security algorithm of the apparatus operating as the terminal device.

8. The apparatus (20) operating as the terminal device according to claim 7, wherein the at least one memory (204) and the computer program code are further configured to, with the at least one processor (202), cause the apparatus (20) operating as the terminal device at least to perform: receiving, from the network entity, a second message for configuring security mode, wherein the second message comprises at least one of: at least a part of the list of supported security algorithms, and / or an indication of the supported change pattern of security algorithm.

9. The apparatus (20) operating as the terminal device according to any of claims 1 to 5, wherein the at least one memory (204) and the computer program code are further configured to, with the at least one processor (202), cause the apparatus (20) operating as the terminal device at least to perform: waiting for a period after receiving the first message, when the apparatus operating as the terminal device does not support at least one of: the list of security algorithms, or the change pattern of security algorithm.

10. The apparatus (20) operating as the terminal device according to any of claims 1 to 9, wherein an item of a security algorithm in the list of security algorithms comprises a type of the security algorithm and / or a key length of the security algorithm; wherein the list of security algorithms comprises a subset of encryption algorithms, and / or a subset of integrity protection algorithms; wherein the list of security algorithms is used for a Non- Access-Stratum, NAS, communication, and / or a Radio Resource Control, RRC, communication; wherein the network entity comprises: a Radio Access Network, RAN, node, or a core network node including at least one of: an Access and Mobility Management Function, AMF, a user plane function, UPF, or a network data analytics function, NWDAF; and / or wherein the terminal device comprises: a user equipment, UE.

11. An apparatus (40) operating as a network entity, comprising: at least one processor (402); and at least one memory (404) including computer program code; the at least one memory (404) and the computer program code configured to, with the at least one processor (402), cause the apparatus (40) operating as the network entity at least to perform: transmitting, to a terminal device, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of security algorithm; and receiving, from the terminal device, an accept message, when the terminal device supports the list of security algorithms and the change pattern of security algorithm.

12. The apparatus (40) operating as the network entity according to claim 11, wherein the indication indicates a condition to trigger a change of security algorithm, and a manner to select a security algorithm from the list of security algorithms to be used after the change of security algorithm is triggered.

13. The apparatus (40) operating as the network entity according to claim 12, wherein the condition to trigger the change comprises at least one of: a time based condition, or a payload based condition; wherein the time based condition is met after a security algorithm has been used for a configured time period;wherein the payload based condition is met after a security algorithm has been used for a configured amount of payload; and wherein an amount of payload is indicated by a length of plain text, or a quantity number of messages.

14. The apparatus (40) operating as the network entity according to any of claims 12 to 13, wherein the indication indicates that security algorithms in the list of security algorithms are to be used cyclically.

15. The apparatus (40) operating as the network entity according to any of claims 12 to 13, wherein the indication indicates that a sequence number of the security algorithm to be used is determined based on a set of bits from a key; wherein the set of bits to determine the security algorithm to be used has a first position in the key, and a set of bits to determine a previously used security algorithm has a second position in the key; and wherein the first position has a shift from the second position.

16. The apparatus (40) operating as the network entity according to any of claims 11 to 15, wherein the at least one memory (404) and the computer program code are further configured to, with the at least one processor (402), cause the apparatus (40) operating as the network entity at least to perform: receiving a reject message from the terminal device, when the terminal device does not support at least one of: the list of security algorithms, or the change pattern of security algorithm.

17. The apparatus (40) operating as the network entity according to claim 16, wherein the reject message includes at least one of: a list of supported security algorithms, or a supported change pattern of security algorithm of the terminal device.

18. The apparatus (40) operating as the network entity according to claim 17, wherein the at least one memory (404) and the computer program code are further configured to, with the at least one processor (402), cause the apparatus (40) operating as the network entity at least to perform: storing at least one of: the list of supported security algorithms, or the supported change pattern of security algorithm of the terminal device; andtransmitting, to the terminal device, a second message for configuring security mode, wherein the second message comprises at least one of: at least a part of the list of supported security algorithms, and / or an indication of the supported change pattern of security algorithm.

19. The apparatus (40) operating as the network entity according to any of claims 11 to 15, wherein the at least one memory (404) and the computer program code are further configured to, with the at least one processor (402), cause the apparatus (40) operating as the network entity at least to perform: determining that the terminal device does not support at least one of: the list of security algorithms, or the change pattern of security algorithm, when not receiving a response for a period after transmitting the first message.

20. The apparatus (40) operating as the network entity according to any of claims 11 to 15, wherein the at least one memory (404) and the computer program code are further configured to, with the at least one processor (402), cause the apparatus (40) operating as the network entity at least to perform: transmitting, to an operation administration network entity, a report about a capacity of the terminal device; wherein at least one of: the list of security algorithms, or the indication of a change pattern of security algorithm is received from the operation administration network entity, or determined by the network entity.

21. The apparatus (40) operating as the network entity according to any of claims 11 to 20, wherein an item of a security algorithm in the list of security algorithms comprises a type of the security algorithm and / or a key length of the security algorithm; wherein the list of security algorithms comprises a subset of encryption algorithms, and / or a subset of integrity protection algorithms; wherein the list of security algorithms is used for a Non- Access-Stratum, NAS, communication, and / or a Radio Resource Control, RRC, communication; wherein the network entity comprises: a Radio Access Network, RAN, node, a core network node including at least one of: an Access and Mobility Management Function, AMF, a user plane function, UPF, or a network data analytics function, NWDAF; and wherein the terminal device comprises: a user equipment, UE.

22. A method (300) performed by an apparatus operating as a terminal device, comprising: receiving (S302), from a network entity, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of security algorithm; and transmitting (S304), to the network entity, an accept message, when the apparatus operating as the terminal device supports the list of security algorithms and the change pattern of security algorithm.

23. The method (300) according to claim 22, wherein the method is performed by the apparatus according to any of claims 1 to 10.

24. A method (500) performed by an apparatus operating as a network entity, comprising: transmitting (S502), to a terminal device, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of security algorithm; and receiving (S504), from the terminal device, an accept message, when the terminal device supports the list of security algorithms and the change pattern of security algorithm.

25. The method (500) according to claim 24, wherein the method is performed by the apparatus according to any of claims 11 to 21.

26. A computer-readable storage medium (60) storing instructions (61), which when executed by at least one processor of an apparatus, cause the at least one processor of the apparatus to at least perform the method according to any of claims 22 to 25.