Protecting radio resource control (RRC) communications
Dynamic temporary security keys for RRC connections in telecommunications systems address vulnerabilities in 5G initial access by securing MSG3 and MSG5, ensuring secure and efficient communication establishment.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- NOKIA SOLUTIONS (SHANGHAI) CO LTD
- Filing Date
- 2025-01-24
- Publication Date
- 2026-07-30
AI Technical Summary
Existing telecommunications systems, particularly in 5G, face vulnerabilities during the initial access phase due to the lack of established security contexts in IDLE and INACTIVE states, leading to risks such as eavesdropping, spoofing, and downgrade attacks on RRC messages, which are not adequately addressed by current security mechanisms.
Implementing a dynamic generation of temporary security keys (TEMP_KEY) for each RRC connection to protect critical messages like MSG3 and MSG5, using key exchanges between the UE and gNB, ensuring confidentiality and integrity until a more permanent security context is established during the AS Security Mode Command procedure.
This approach provides robust, efficient, and scalable protection for RRC messages, mitigating risks of key compromise and ensuring secure initial access by using fresh cryptographic keys for each connection, enhancing security and reducing attack vectors.
Smart Images

Figure CN2025074802_30072026_PF_FP_ABST
Abstract
Description
PROTECTING RADIO RESOURCE CONTROL (RRC) COMMUNICATIONSFIELD
[0001] Various example embodiments of the present disclosure generally relate to the field of telecommunication and in particular, to methods, devices, apparatuses and computer readable storage medium for protecting Radio Resource Control (RRC) communications.BACKGROUND
[0002] The Access Stratum (AS) procedures play a pivotal role in modern telecommunications systems, enabling communication and control between User Equipment (UE) and the network. These procedures are essential for tasks such as connection setup, reconfiguration, and state management. The behavior and security of AS procedures vary significantly depending on the RRC state of the UE, primarily categorized as IDLE, INACTIVE, or CONNECTED.
[0003] In 6G, the management of RRC states introduces significant advancements over 5G, particularly in the differentiation between IDLE and INACTIVE states. While both states aim to reduce energy consumption and improve efficiency during periods of inactivity, 6G addresses key limitations observed in 5G and optimizes these states for advanced network requirements. In 5G, the IDLE and INACTIVE states are conceptually similar, with the primary difference being that the INACTIVE state retains the AS security context, enabling faster reconnections. However, in 6G, the distinction is more pronounced. The IDLE state in 6G is designed to minimize network awareness of the UE, with no Non-Access Stratum (NAS) or AS security context maintained. This state represents the UE as essentially “non-existent” to the network, apart from its subscription information, enabling maximum power saving. In contrast, the INACTIVE state in 6G retains both NAS and AS contexts, allowing for quick transitions to the CONNECTED state with a focus on minimizing latency. Additionally, 6G avoids making the INACTIVE state optional, addressing the latency and power consumption issues of 5G, where network operators often kept UEs in the CONNECTED state for quicker responses at the cost of higher energy consumption. By default, 6G networks leverage the INACTIVE state for most scenarios requiring temporary disconnections, reserving the IDLE state for rare cases, such as deregistration or power-up. The 6G enhancements also introduce improved control plane latency metrics. The INACTIVE state in 6G achieves latency optimization with a target of less than 10 milliseconds for transitioning back to CONNECTED, compared to significantly higher delays when resuming from the IDLE state. This differentiation enables 6G networks to balance power efficiency and latency, addressing the limitations of 5G and paving the way for advanced use cases requiring ultra-low latency and efficient mobility management.SUMMARY
[0004] In a first aspect of the present disclosure, there is provided a first apparatus. The first apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus at least to: transmit, to a second apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information; receive, from the second apparatus, a response to the request comprising an indication of confirmed key exchange information; and generate, based on the confirmed key exchange information, a key for the AS security.
[0005] In a second aspect of the present disclosure, there is provided a second apparatus. The second apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second apparatus at least to: receive, from a first apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information; transmit, to the first apparatus, a response to the request comprising an indication of confirmed key exchange information; and generate, based on the confirmed key exchange information, a key for the AS security.
[0006] In a third aspect of the present disclosure, there is provided a method. The method comprises: transmitting, to a second apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information; receiving, from the second apparatus, a response to the request comprising an indication of confirmed key exchange information; and generating, based on the confirmed key exchange information, a key for the AS security.
[0007] In a fourth aspect of the present disclosure, there is provided a method. The method comprises: receiving, from a first apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information; transmitting, to the first apparatus, a response to the request comprising an indication of confirmed key exchange information; and generating, based on the confirmed key exchange information, a key for the AS security.
[0008] In a fifth aspect of the present disclosure, there is provided a first apparatus. The first apparatus comprises means for transmitting, to a second apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information; means for receiving, from the second apparatus, a response to the request comprising an indication of confirmed key exchange information; and means for generating, based on the confirmed key exchange information, a key for the AS security.
[0009] In a sixth aspect of the present disclosure, there is provided a second apparatus. The second apparatus comprises means for receiving, from a first apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information; means for transmitting, to the first apparatus, a response to the request comprising an indication of confirmed key exchange information; and means for generating, based on the confirmed key exchange information, a key for the AS security.
[0010] In a seventh aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the third aspect.
[0011] In an eighth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the fourth aspect.
[0012] It is to be understood that the Summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description.BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Some example embodiments will now be described with reference to the accompanying drawings, where:
[0014] FIG. 1 illustrates an example communication environment in which example embodiments of the present disclosure can be implemented;
[0015] FIG. 2A illustrates a scenario where a spoofed downlink (DL) Non-Access Stratum (NAS) message is used for downgrade attack;
[0016] FIG. 2B illustrates a scenario where a spoofed User Plane (UP) disrupting the modem;
[0017] FIG. 3 illustrates a scenario in accordance with some embodiments in the disclosure;
[0018] FIG. 4 illustrates an example signaling process 400 in accordance with some embodiments in the disclosure;
[0019] FIG. 5 illustrates another example signaling process 500 in accordance with some embodiments in the disclosure;
[0020] FIG. 6 illustrates yet another example signaling process 600 in accordance with some embodiments in the disclosure;
[0021] FIG. 7 illustrates a flowchart of a method implemented at a first apparatus in accordance with some example embodiments of the present disclosure;
[0022] FIG. 8 illustrates a flowchart of a method implemented at a second apparatus in accordance with some example embodiments of the present disclosure;
[0023] FIG. 9 illustrates a simplified block diagram of a device that is suitable for implementing example embodiments of the present disclosure; and
[0024] FIG. 10 illustrates a block diagram of an example computer readable medium in accordance with some example embodiments of the present disclosure.
[0025] Throughout the drawings, the same or similar reference numerals represent the same or similar element.DETAILED DESCRIPTION
[0026] Principle of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. Embodiments described herein can be implemented in various manners other than the ones described below.
[0027] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0028] References in the present disclosure to “one embodiment, ” “an embodiment, ” “an example embodiment, ” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
[0029] It shall be understood that although the terms “first, ” “second, ” …, etc. in front of noun (s) and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another and they do not limit the order of the noun (s) . For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.
[0030] As used herein, “at least one of the following: <a list of two or more elements>” and “at least one of <a list of two or more elements>” and similar wording, where the list of two or more elements are joined by “and” or “or” , mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0031] As used herein, unless stated explicitly, performing a step “in response to A” does not indicate that the step is performed immediately after “A” occurs and one or more intervening steps may be included.
[0032] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a” , “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” , “comprising” , “has” , “having” , “includes” and / or “including” , when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0033] As used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and (b) combinations of hardware circuits and software, such as (as applicable) : (i) a combination of analog and / or digital hardware circuit (s) with software / firmware and (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0034] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0035] As used herein, the term “communication network” refers to a network following any suitable communication standards, such as New Radio (NR) , Long Term Evolution (LTE) , LTE-Advanced (LTE-A) , Wideband Code Division Multiple Access (WCDMA) , High-Speed Packet Access (HSPA) , Narrow Band Internet of Things (NB-IoT) and so on. Furthermore, the communications between a terminal device and a network device in the communication network may be performed according to any suitable generation communication protocols, including, but not limited to, the first generation (1G) , the second generation (2G) , 2.5G, 2.75G, the third generation (3G) , the fourth generation (4G) , 4.5G, the fifth generation (5G) , 5.5G, the sixth generation (6G) communication protocols, and / or any other protocols either currently known or to be developed in the future. Embodiments of the present disclosure may be applied in various communication systems. Given the rapid development in communications, there will of course also be future type communication technologies and systems with which the present disclosure may be embodied. It should not be seen as limiting the scope of the present disclosure to only the aforementioned system.
[0036] As used herein, the term “network device” refers to a node in a communication network via which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP) , for example, a node B (NodeB or NB) , an evolved NodeB (eNodeB or eNB) , an NR NB (also referred to as a gNB) , a Remote Radio Unit (RRU) , a radio header (RH) , a remote radio head (RRH) , a relay, an Integrated Access and Backhaul (IAB) node, a low power node such as a femto, a pico, a non-terrestrial network (NTN) or non-ground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, an aircraft network device, and so forth, depending on the applied terminology and technology. In some example embodiments, radio access network (RAN) split architecture comprises a Centralized Unit (CU) and a Distributed Unit (DU) at an IAB donor node. An IAB node comprises a Mobile Terminal (IAB-MT) part that behaves like a UE toward the parent node, and a DU part of an IAB node behaves like a base station toward the next-hop IAB node.
[0037] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE) , a Subscriber Station (SS) , a Portable Subscriber Station, a Mobile Station (MS) , or an Access Terminal (AT) . The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA) , portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE) , laptop-mounted equipment (LME) , USB dongles, smart devices, wireless customer-premises equipment (CPE) , an Internet of Things (IoT) device, a watch or other wearable, a head-mounted display (HMD) , a vehicle, a drone, a medical device and applications (e.g., remote surgery) , an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts) , a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an IAB node (e.g., a relay node) . In the following description, the terms “terminal device” , “communication device” , “terminal” , “user equipment” and “UE” may be used interchangeably.
[0038] As used herein, the term “resource, ” “transmission resource, ” “resource block, ” “physical resource block” (PRB) , “uplink resource, ” or “downlink resource” may refer to any resource for performing a communication, for example, a communication between a terminal device and a network device, such as a resource in time domain, a resource in frequency domain, a resource in space domain, a resource in code domain, or any other combination of the time, frequency, space and / or code domain resource enabling a communication, and the like. In the following, unless explicitly stated, a resource in both frequency domain and time domain will be used as an example of a transmission resource for describing some example embodiments of the present disclosure. It is noted that example embodiments of the present disclosure are equally applicable to other resources in other domains.
[0039] As used herein, the term “Access Stratum (AS) ” refers to the set of protocols and mechanisms within a wireless network responsible for the control and management of the radio access interface between terminal devices and the network. This includes, but is not limited to, tasks related to resource allocation, mobility management, and signaling for establishing, maintaining, and releasing communication connections. These functionalities leverage resources across various domains, including time, frequency, space, and code domains, to enable the efficient and reliable transfer of data. For example, AS may utilize physical resource blocks (PRBs) in the time and frequency domains for scheduling and managing uplink and downlink transmissions. Unless explicitly stated otherwise, references to AS functionalities and mechanisms are equally applicable to operations involving any combination of these domains. The AS enables optimized coordination between terminal devices and network entities to achieve robust and seamless communication.
[0040] As used herein, the term “Non-Access Stratum (NAS) ” refers to the set of protocols and mechanisms operating above the Access Stratum (AS) in a wireless network, focusing on managing the connection between terminal devices and the network core. NAS handles signaling and control functionalities related to mobility management, session management, authentication, and security. These mechanisms are essential for enabling and maintaining the overall service continuity and quality of communication. For example, NAS may manage the establishment of a secure connection between a terminal device and the core network while coordinating session parameters across multiple access networks. Unless explicitly stated otherwise, references to NAS functionalities encompass operations enabling secure, reliable, and consistent communication between terminal devices and the network core, independent of the underlying access stratum.
[0041] As used herein, the term “Radio Resource Control (RRC) ” refers to the management and allocation of communication resources within a wireless network, including but not limited to resources utilized for establishing, maintaining, and releasing connections between terminal devices and network devices. These resources, herein referred to as “resources, ” “transmission resources, ” “resource blocks” (RBs) , “physical resource blocks” (PRBs) , “uplink resources, ” or “downlink resources, ” encompass any combination of resources across various domains, including time, frequency, space, and code domains, or any other suitable combination thereof. For example, a resource in the frequency and time domains may be utilized to facilitate communication between terminal devices and network devices. Unless explicitly stated otherwise, references to “resources” in this context are equally applicable to resources in other domains. RRC enables the efficient management of these resources to enable reliable and optimized communication in wireless networks.
[0042] FIG. 1 illustrates an example communication environment 100 in which example embodiments of the present disclosure can be implemented. In the communication environment 100, a plurality of communication devices, including a terminal device 110 and a network device 120, can communicate with each other. In the example of FIG. 1, the terminal device 110 may be a UE and the network device 120 may be a base station serving the UE. The serving area of the network device 120 may be called a cell.
[0043] It is to be understood that the number of devices and their connections shown in FIG. 1 are only for the purpose of illustration without suggesting any limitation. The communication environment 100 may include any suitable number of devices configured to implementing example embodiments of the present disclosure. Although not shown, it would be appreciated that one or more additional devices may be located in the cell, and one or more additional cells may be deployed in the communication environment 100. It is noted that although illustrated as a network device, the network device 120 may be another device than a network device. Although illustrated as a terminal device, the terminal device 110 may be another device than a terminal device.
[0044] In the following, for the purpose of illustration, some example embodiments are described with the terminal device 110 operating as a UE and the network device 120 operating as a base station. However, in some example embodiments, operations described in connection with a terminal device may be implemented at a network device or other device, and operations described in connection with a network device may be implemented at a terminal device or other device.
[0045] In some example embodiments, a transmission direction from the network device 120 to the terminal device 110 is referred to as a downlink (DL) , while a transmission direction from the terminal device 110 to the network device 120 is referred to as an uplink (UL) . In DL, the network device 120 is a transmitting (TX) device (or a transmitter) and the terminal device 110 is a receiving (RX) device (or a receiver) . In UL, the terminal device 110 is a TX device (or a transmitter) and the network device 120 is a RX device (or a receiver) .
[0046] Communications in the communication environment 100 may be implemented according to any proper communication protocol (s) , comprising, but not limited to, cellular communication protocols, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA) , Frequency Division Multiple Access (FDMA) , Time Division Multiple Access (TDMA) , Frequency Division Duplex (FDD) , Time Division Duplex (TDD) , Multiple-Input Multiple-Output (MIMO) , Orthogonal Frequency Division Multiple (OFDM) , Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.
[0047] Example embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0048] As discussed in the Background, the behavior and security of AS procedures vary significantly depending on the RRC state of the UE, primarily categorized as IDLE, INACTIVE, or CONNECTED. In the IDLE state, the UE or RAN does not maintain an established AS security context. Procedures such as RRC setup configure basic AS parameters but do not secure the transmission of sensitive information. For instance, slice information is transmitted in plaintext, making it susceptible to eavesdropping or spoofing attacks. This lack of security represents a critical vulnerability in the initial access phase.
[0049] In the random access procedure, the UE initiates communication with the network by transmitting a preamble and waiting for a response to synchronize and allocate resources. This phase is inherently vulnerable due to the open nature of transmissions. Jamming attacks can disrupt communication by overwhelming the network with interference signals. Sniffing, enabled by the unprotected transmission of random access messages, allows attackers to intercept and analyze data, gaining unauthorized insights into network or UE-specific details. Spoofing attacks exploit this lack of protection by crafting fake messages, impersonating legitimate UEs, and hijacking resources or disrupting service. Addressing these risks is challenging because security contexts are not yet established during random access.
[0050] In the IDLE state, the UE lacks an active AS security context, leaving critical messages unprotected. RRC MSG3 and MSG5, which are integral to establishing connections, are sent in plaintext. MSG3 (Message 3) is the RRC Setup Request message sent by the UE to initiate establishment of an RRC connection. MSG5 (Message 5) is the RRC Setup Complete message sent by the UE to confirm the successful setup of an RRC connection and to include NAS signaling (e.g., Attach Request, Registration Request) . These messages sent in plaintext expose sensitive information, such as NAS slice identifiers, to attackers who can intercept these messages through sniffing, compromising confidentiality. Spoofing attacks are also a significant risk, where attackers inject malicious messages to manipulate or disrupt communication. These vulnerabilities create a critical window of opportunity for exploitation before AS security activation.
[0051] NAS messages, transported via AS procedures, face additional threats. The lack of protection for these messages makes them susceptible to spoofing, where attackers can manipulate responses to execute downgrade attacks. Such attacks disrupt 5G services by barring access or forcing the UE to fallback to older, less secure technologies. A simple illustration of this kind of attack may be referred to FIG. 2A, which illustrates a scenario with a spoofed DL NAS message is used for downgrade attack.
[0052] As shown in FIG. 2A, a spoofed DL NAS message can be utilized to execute a downgrade attack by injecting a fake message into the communication process between the UE and the network. In such an attack, a fake NAS message (② Malformed RRC Connection Setup shown in FIG. 2A) can be sent to the UE, simulating an authentication failure. This message interrupts the NAS authentication procedure and effectively disables the UE’s access to 5G services. By doing so, the attacker forces the UE to fall back to a less secure network (e.g., 4G or 3G) , where the security protocols are weaker and more vulnerable to further exploitation. Details of FIG. 2A will not be further described as it is self-explanatory.
[0053] The user plane headers and Media Access Control (MAC) layer lack encryption or integrity protection, introducing risks of sniffing and spoofing as side-channel attacks. Sniffing allows attackers to extract sensitive metadata, while spoofing can inject false data, disrupting communication. Combined with other vulnerabilities, these risks facilitate chained attacks, such as a downgrade attack where an attacker sequentially exploits multiple weak points to disable security features or degrade service.
[0054] Modem bugs, often discovered through fuzzing techniques, exemplify how vulnerabilities in implementation can be exploited. For instance, fake Radio Link Control (RLC) status Protocol Date Units (PDUs) may trigger unintended modem behavior, such as state switching or even a reboot. While not universally exploitable, such vulnerabilities highlight the potential harm and the necessity for robust testing and security mechanisms. These examples demonstrate the wide range of potential security risks inherent in current systems and emphasize the importance of comprehensive solutions in future network designs. A simple illustration of this kind of attack may referred to FIG. 2B, which illustrates a scenario where a spoofed User Plane (UP) disrupting the modem.
[0055] As shown in FIG. 2B, a spoofed UP message can be crafted to disrupt the modem’s operation by exploiting vulnerabilities in the handling of protocol data. In this scenario, a fake RLC status PDU (③ Malformed RLC status PDU) , which is intended for UL MSG5, is manipulated and sent to the modem. This spoofed PDU is incorrectly interpreted by the modem as a Transmission Configuration Indicator (TCI) state switching MAC Control Element (CE) . Such misinterpretation triggers an unintended state-switching operation, causing the modem to reboot. Details of FIG. 2B will not be further described as it is self-explanatory.
[0056] While existing approach in prior art provides a basic mechanism to protect MSG5 using a static key, yet it leaves significant gaps unaddressed. It does not specify how to secure MSG3, which remains vulnerable during the RRC connection initialization. Additionally, the reliance on a static key for message protection introduces a critical security risk, as compromising the private key could lead to the decryption of all transmitted or previously collected messages. Furthermore, the existing approach does not address how to protect other NAS containers effectively, and relying on asymmetric encryption for larger messages is resource-intensive and inefficient. These issues highlight the limitations of the prior art in enabling comprehensive and efficient message security.
[0057] Embodiments in the disclosure target at least one of the above unaddressed gaps. The core concept underlying the embodiments in the disclosure is the dynamic generation and utilization of temporary security keys (referred to as TEMP_KEY) to protect previously unprotected RRC messages during the initial access phase of a connection. The core concept involves creating a unique TEMP_KEY for every new RRC connection, enabling confidentiality and integrity for critical messages such as MSG3, MSG5, and other RRC messages containing NAS containers. The TEMP_KEY may be derived through the exchange of key material between the UE and the gNB, leveraging fresh cryptographic operations for every connection. This temporary security mechanism remains in effect until the AS Security Mode Command (SMC) procedure establishes a more permanent security context. Once the SMC process is successfully completed, the temporary keys are deleted, enabling that the security context is refreshed and reducing risks of key reuse or compromise. The approach emphasizes robust, efficient, and scalable protection of RRC messages, tailored for various operational scenarios.
[0058] In some embodiments, the TEMP_KEY is dynamically generated each time a new RRC connection is established. The UE may create a fresh private-public key pair and share only the public key with the gNB. The gNB may use this public key and a pre-configured private key to generate the TEMP_KEY. This TEMP_KEY may then be used to secure all previously unprotected RRC messages, specifically from MSG3 to MSG5, as well as other RRC messages containing NAS containers, until the AS Security Mode Command (SMC) procedure is completed. The use of dynamically generated keys enables that each RRC connection has a unique security key, mitigating risks associated with key compromise. Once the AS SMC is successfully executed, the temporary security keys generated in idle mode are deleted, further enhancing security by reducing potential attack vectors. This approach provides robust security for initial access while maintaining efficiency in key management.
[0059] In some embodiments, the focus is specifically on protecting RRC MSG5. A newly generated secret may be created independently at both the UE and the gNB through the exchanges of MSG3 and MSG4. This simplifies the process by targeting the protection of MSG5 directly, which is an important message during the initial access phase. By leveraging only the initial exchanges of MSG3 and MSG4 to derive the secret, the computational complexity is reduced compared to other approaches while still enabling the confidentiality and integrity of MSG5. This streamlined process is particularly suitable for scenarios where protecting MSG5 is of primary concern without the need for broader protections applied to other RRC messages. MSG4 (Message 4) is the RRC Setup message sent by the gNB. It is transmitted as part of the contention-based Random Access procedure and contains the Contention Resolution Identity, allowing the UE to verify whether it has been successfully identified by the gNB.
[0060] In some embodiments, the TEMP_KEY is also dynamically generated for each new RRC connection but with a key distinction. Here, the private-public key pair may be generated by the gNB rather than the UE. The gNB may then share its freshly generated private key with the UE, allowing both entities to derive the same TEMP_KEY. This TEMP_KEY may be used to secure all RRC messages from MSG3 to MSG5, as well as any other RRC messages containing NAS containers, until the AS SMC procedure is completed. The involvement of the gNB in private key generation introduces an additional layer of control and enables that the gNB plays an active role in the key generation process. Similarly, the temporary security keys are deleted after the AS SMC is successfully executed, enabling that the security context is refreshed for subsequent connections. This approach offers a balance between centralized control by the gNB and robust protection for unprotected RRC messages during initial access.
[0061] Referring now to FIG 3, which illustrates the scenario in accordance with some embodiments in the disclosure. The scenario is referred to as AS+NAS IDLE, occurs when the UE 110 establishes an RRC connection for the very first time. In this case, there is no existing UE context (and no security context as well) in the Radio Access Network (RAN) 121 or the Access and Mobility Management Function (AMF) 122. The UE 110 and the network lack any pre-existing security context, meaning that no cryptographic keys or prior security associations are available. This scenario represents the most vulnerable phase, as both AS and NAS are unsecured. The initial access requires the establishment of a completely new security framework, which begins with the exchange of key materials between the UE 110 and network, enabling secure communication to be established from scratch.
[0062] Upon receiving an RRC security request message, the UE 110 may take specific actions to enable secure communication. The UE 110 may apply the necessary security measures based on the key pairs generated for the gNB 120 and UE 110. Using the derived security keys, the UE 110 may trigger the RRCSetupRequest procedure while incorporating the NAS establishment cause received from the upper layers. This may enable that the connection request is securely transmitted, preventing unauthorized access or tampering. Optionally, the UE 110 may start a timer to maintain the established security keys for a predefined duration. If the timer expires, the UE should restart the process, enabling that the security context remains fresh and resistant to potential vulnerabilities. These mechanisms collectively enhance the robustness of 6G networks, enabling secure and efficient connectivity across a variety of scenarios.
[0063] Referring now to FIG. 4, which illustrates an example signaling process 400 in accordance with some embodiments in the disclosure. Though in FIG. 3, it is illustrated that the terminal device 110 as 6G UE 110 and the network device 120 as 6G gNB 120, the terminal device 110 may also be any other propriate types of terminal devices and the network device 120 may also be any other propriate types of network devices, e.g., corresponding devices of future generations.
[0064] First, the 6G network may pre-provision the Access Network (AN) public keys and their corresponding key IDs in the UE 110. These public keys may allow the UE to initiate secure communication during the initial access phase. The corresponding private keys and the Key IDs are securely stored at the 6G gNB 120. To indicate its support for temporary AS security, the gNB 120 may broadcast a System Information Block Type 1 (SIB1) message. The UE 110 may receive this SIB1 message and then initiate the Random Access Channel (RACH) procedure. Following the RACH preamble, the gNB 120 may respond with a RACH response to confirm the initiation of communication.
[0065] The UE 110 may decide to activate 401 the temporary AS security mechanism for the initial access phase. This decision marks the beginning of the security process to enable that sensitive information is protected during connection establishment. The activation is a deliberate choice by the UE 110 to trigger the subsequent steps for securing the communication. The UE 110 then enters a temporary idle mode AS security activation process 402.
[0066] Over Signaling Radio Bearer 0 (SRB0) , the UE 110 may transmit 403 an RRC security request (referred to as MSG3A) , to the gNB 120 to activate the temporary AS security during RRC IDLE mode, e.g., in response to the indication of the support for the temporary AS security comprised in the SIB1. This request may contain key exchange information, in this case, the AN_TEMP_ID, which is a public key ID proposed by the UE 110, along with a request to establish a temporary security key. This step may establish the intent of the UE 110 to use the specified public key for the secure key generation process.
[0067] The gNB 120 may evaluate the AN_TEMP_ID transmitted by the UE 110. The gNB 120 may accept 404 the proposed AN_TEMP_ID or select 404 a different AN_TEMP_ID from its pre-configured list. This flexibility enables compatibility and alignment between the UE 110 and gNB 120 during the key negotiation process.
[0068] The gNB 120 may then confirm its decision by transmitting 405 an RRC security setup message (referred to as MSG4A) over SRB0 to the UE 110. This message may include the confirmed key exchange information, in this case, the confirmed AN_TEMP_ID (either the AN_TEMP_ID proposed by the UE 100, or a different one selected by the gNB 120) , enabling that both the UE 110 and gNB 120 are synchronized in their choice of public key for the subsequent key generation. The UE 110 may then generate a key (TEMP_KEY) for the AS security based on the confirmed key exchange information, which will be explained in the following.
[0069] The UE 110 may generate 406 a fresh private-public key pair, referred to as UE_TEMP_PRIV_KEY and UE_TEMP_PUB_KEY. This may enable that each session begins with unique cryptographic keys, enhancing the overall security by preventing key reuse. These keys are generated specifically for the ongoing session and are not retained after the session ends.
[0070] The UE 110 may then transmit 407 the information about the newly generated temporary key pair, in this case, the public key (UE_TEMP_PUB_KEY) to the gNB 120 within an RRC security request message (referred to as MSG3B) over SRB0. If the public key is too large to fit within a single message, this step may be repeated, or the public key may be split into concatenated blocks to enable its complete transmission. Alternatively, to reduce signaling overhead, the UE 110 may include the AN_TEMP_ID alongside the public key in a single message, bypassing earlier intermediate steps.
[0071] The gNB 120 may use the received UE_TEMP_PUB_KEY and its private key (AN_TEMP_PRIV_KEY_1) associated with the confirmed AN_TEMP_ID to generate 408 a symmetric key called TEMP_KEY. Parallelly, the UE 110 may generate 408 the same TEMP_KEY using its private key (UE_TEMP_PRIV_KEY) and the public key (AN_TEMP_PUB_KEY_1) associated with the AN_TEMP_ID. This symmetric key serves as the shared secret used to secure subsequent communication between the UE 110 and gNB 120.
[0072] The gNB 120 may transmit 409 an RRC security setup acknowledgment message (referred to as MSG4B) to the UE 110, encrypted using the TEMP_KEY generated in 408. The UE 110 may decrypt this acknowledgment using its corresponding TEMP_KEY, enabling mutual authentication and secure synchronization. Then the UE 110 and gNB 120 enter a temporary idle mode 410 with AS security activated.
[0073] Over SRB1, the UE 110 and gNB 120 may exchange RRC Setup messages 411a (referred to as MSG3C) , including the RRC Setup response 411b (referred to as MSG4C) and RRC Setup complete message 411c. These messages, protected by the TEMP_KEY, enable the confidentiality and integrity of the communication. The RRC Setup complete message may include a NAS container (MSG5) , which is also secured using the TEMP_KEY. This temporary security mechanism remains active until the AS Security Mode Command (SMC) procedure is completed. Once AS security is fully established during RRC CONNECTED state with the generation of permanent AS keys (RRC and UP keys) , the temporary keys are deleted from both the UE 110 and the gNB 120.
[0074] As a critical note, the temporary idle mode AS security keys are uniquely generated for each new RRC setup procedure in idle mode. Between two idle RRC states, when transitioning to a connected state, previously used temporary keys are discarded, and fresh keys are generated. This enables that no key material is reused, maintaining robust security and minimizing the risk of cryptographic compromise.
[0075] Referring now to FIG. 5, which illustrates another example signaling process 500 in accordance with some embodiments in the disclosure.
[0076] The process 500 begins with the provisioning of AN public keys and their associated key IDs in the UE 110. These public keys are important for initiating secure communication between the UE 110 and the 6G gNB 120. The corresponding private keys are securely stored in the gNB 120. To enable temporary AS security, the gNB 120 may broadcast a System Information Block Type 1 (SIB1) message, signaling its capability to support temporary AS security. Once the UE 110 receives this message, it may initiate a Random Access Channel (RACH) preamble, and the gNB 120 may respond with a RACH response, completing the initial phase of the communication.
[0077] The UE 110 may decide to activate 501 temporary AS security to protect communication during the initial access phase. This decision triggers the mechanism for securing early-stage communication, enabling that sensitive information exchanged during the connection setup is protected from potential threats. The UE 110 then enters a temporary idle mode AS security activation process 502.
[0078] The UE 110 may transmit 503 an RRC security request (referred to as MSG3A) over Signaling Radio Bearer 0 (SRB0) , including key exchange information, in this case, an AN_TEMP_ID, which is a public key ID proposed by the UE 110 to the gNB 120. The request may also include a directive to establish a temporary security key. The transmission of the request to activate the AS security may be, for example, in response to the indication of the support for the temporary AS security comprised in the SIB1. This marks the initiation of the key negotiation process between the UE 110 and the gNB 120.
[0079] The gNB 120 may evaluate the AN_TEMP_ID proposed by the UE 110. The gNB 120 may choose to accept 504 the proposed ID or select 504 an alternative AN_TEMP_ID from its pre-configured list. This flexibility enables compatibility and alignment in the key negotiation process.
[0080] The gNB 120 may then confirm its decision by transmitting 505 an RRC security setup message (referred to as MSG4A) over SRB0 to the UE 110. This message may contain the confirmed key exchange information, in this case, the confirmed AN_TEMP_ID (either the AN_TEMP_ID proposed by the UE 100, or a different one selected by the gNB 120) , enabling that both entities are synchronized for the subsequent key generation process.
[0081] The UE 110 may generate 506 a fresh Diffie-Hellman private-public key pair, referred to as UE_TEMP_PRIV_KEY and UE_TEMP_PUB_KEY. The UE 110 may use its private key (UE_TEMP_PRIV_KEY) , and the public key (AN_TEMP_PUB_KEY_1) associated with the confirmed AN_TEMP_ID to derive a symmetric key, known as TEMP_KEY. Optionally, the UE 110 may encrypt the RRC container, which contains the RRC Setup Request (referred to as MSG3C) , using the TEMP_KEY to enhance security.
[0082] The UE 110 may transmit 507 the information about the newly generated temporary key pair, in this case, the public key (UE_TEMP_PUB_KEY) to the gNB 120 in an RRC security setup complete message (referred to as MSG5A) over SRB1. This message may also include the optionally RRC container encrypted with the TEMP_KEY, enabling the confidentiality and integrity of the information being transmitted.
[0083] The gNB 120 may use the received UE_TEMP_PUB_KEY and its private key (AN_TEMP_PRIV_KEY_1) to derive 508 the same TEMP_KEY. Using this TEMP_KEY, the gNB 120 may decrypt the RRC container, if it was encrypted by the UE 110 in 507. This enables that the gNB 120 and UE 110 are synchronized in their temporary security context. The UE 110 and gNB 120 enter a temporary idle mode 509 with AS security activated.
[0084] The RRC Setup message 510 may be sent over SRB1 and is encrypted using the TEMP_KEY generated in 508. The response 511 from the gNB 120 to the RRC Setup message is also protected with the TEMP_KEY. Subsequently, the RRC Setup complete message 511b, which contains the NAS container (MSG5) , may be transmitted to the gNB 120, encrypted with the TEMP_KEY. 510 is optional, as the RRC container may already have been securely transmitted in 507. If the RRC container was not encrypted and sent earlier, 510 becomes mandatory to enable message protection.
[0085] This protection mechanism remains active until the AS Security Mode Command (SMC) procedure is executed and permanent AS keys (RRC and UP keys) are generated. Once the SMC process is completed, the temporary idle mode security keys are deleted from both the UE 110 and the gNB 120 to prevent their reuse.
[0086] For every new RRC setup procedure initiated in idle mode, a new set of temporary AS security keys is generated. Between two idle RRC states, as the UE 110 transitions to a connected state, previously used temporary keys are discarded, and fresh keys are created. This enables robust security by eliminating risks associated with key reuse and maintaining the integrity and confidentiality of the communication process.
[0087] Possible updates to the specifications may be in the following:
[0088] Referring now to FIG. 6, which illustrates yet another example signaling process 600 in accordance with some embodiments in the disclosure.
[0089] Similarly, the 6G network may prepare the foundation for secure communication by pre-provisioning AN public keys and their corresponding key IDs in both the UE 110 and the gNB 120. These keys may facilitate the initial security negotiation process. The gNB 120 may broadcast a System Information Block Type 1 (SIB1) message, signaling its support for temporary AS security. Upon receiving this message, the UE 110 may initiate the Random Access Channel (RACH) preamble. The gNB 120 may then respond with the RACH response, establishing the first layer of communication necessary for the subsequent steps.
[0090] The UE 110 may decide to activate 601 the temporary AS security mechanism for the initial access. This decision initiates the security setup process, enabling that sensitive information exchanged during the connection establishment phase is protected. The UE 110 then enters a temporary idle mode AS security activation process 602.
[0091] The UE 110 may transmit 603 an RRC security request (referred to as MSG3A) over Signaling Radio Bearer 0 (SRB0) , which may include key exchange information, in this case, the UE_TEMP_ID-apublic key ID proposed by the UE 110. Along with this, the request may specify the UE’s intention to establish a temporary security key. This step marks the initiation of key negotiation between the UE 110 and the gNB 120.
[0092] The gNB 120 may evaluate the UE_TEMP_ID sent by the UE 110. Upon accepting 604 the proposed ID, the gNB 120 may generate a new private key, referred to as gNB_TEMP_KEY. This newly created key enables that the subsequent security process is based on fresh cryptographic material, enhancing the overall security.
[0093] The gNB 120 may derive 605 a shared secret key, known as TEMP_KEY, using the UE_TEMP_ID (received from the UE) and the newly generated gNB_TEMP_KEY. This shared key serves as the temporary security context, enabling encryption and integrity protection for subsequent messages.
[0094] The gNB 120 may transmit 606 an RRC security setup message (referred to as MSG4A) over SRB0 to the UE 110. This message may include the confirmed key exchange information, in this case, the newly generated gNB_TEMP_KEY, allowing the UE 110 to synchronize its security context with the gNB 120.
[0095] The UE 110 may generate 607 its own temporary security keys (TEMP_KEY) using the received gNB_TEMP_KEY and its locally stored UE_TEMP_ID. This enables that both the UE 110 and the gNB 120 have matching TEMP_KEYs, which form the basis for securing their communication. Then the UE 110 and gNB 120 enter a temporary idle mode 608 with AS security activated.
[0096] The RRC Setup message 609 may be transmitted over SRB1 and encrypted using the TEMP_KEY generated in 607. The gNB’s response 610 to the RRC Setup message is also protected with the same TEMP_KEY, enabling the bidirectional integrity and confidentiality of the communication. Finally, the RRC Setup complete message 611, containing a NAS container (MSG5) , may be sent to the gNB 120. This message is also encrypted using the TEMP_KEY, providing comprehensive protection during the setup process.
[0097] This protection mechanism remains active until the AS Security Mode Command (SMC) procedure is executed, at which point permanent AS keys for RRC and User Plane (UP) communication are generated. Once the SMC process is successfully completed, the temporary idle mode security keys are deleted from both the UE 110 and the gNB 120 to eliminate the risk of key reuse or compromise.
[0098] For every new RRC setup procedure initiated in idle mode, a fresh set of temporary AS security keys is generated. Between two idle RRC states, when transitioning to a connected state, previously used temporary keys are discarded, and entirely new keys are created. This enables robust and dynamic security, maintaining the confidentiality and integrity of communication in 6G networks while addressing potential vulnerabilities associated with key reuse.
[0099] Possible updates to the specification may be in the following:
[0100] FIG. 7 shows a flowchart of an example method 700 implemented at a first apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 700 will be described from the perspective of the first apparatus 110 in FIG. 1.
[0101] At block 710, transmitting, to a second apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information.
[0102] At block 720, receiving, from the second apparatus, a response to the request comprising an indication of confirmed key exchange information.
[0103] At block 730, generating, based on the confirmed key exchange information, a key for the AS security.
[0104] In some example embodiments, the method 700 further comprises: generating, based on the confirmed key exchange information, a temporary key pair; and generating the key for the AS security based on a private key of the temporary key pair and a public key associated with the confirmed key exchange information.
[0105] In some example embodiments, the method 700 further comprises: transmitting, to the second apparatus, information about the temporary key pair in the request.
[0106] In some example embodiments, the method 700 further comprises: transmitting, to the second apparatus, the information about the temporary key pair in an RRC container encrypted with the key for the AS security.
[0107] In some example embodiments, the information about the temporary key pair comprises a public key of the temporary key pair.
[0108] In some example embodiments, in response to the information about the temporary key pair exceeds the length of the request, the information about the temporary key pair is transmitted with one of: repeated transmission, each of the repeated transmission encapsulated with part of the information about the temporary key pair, or the information about the temporary key pair spitted into concatenated blocks.
[0109] In some example embodiments, the method 700 further comprises: receiving, from the second apparatus, a response comprising an indication of an acknowledgement of the activation of the AS security.
[0110] In some example embodiments, the confirmed key exchange information comprises an identifier of a selected Access Network, AN, public key.
[0111] In some example embodiments, the method 700 further comprises: generating the key for the AS security based on the received secret.
[0112] In some example embodiments, the method 700 further comprises: exchanging, with the second apparatus, access request messages encrypted with the key for the AS security.
[0113] In some example embodiments, the method 700 further comprises: receiving, from the second apparatus, configuration information comprising an indication of supporting the AS security during RRC connection initialization, wherein the transmission of the request to activate the AS security is in response to receiving the configuration information.
[0114] In some example embodiments, the method 700 further comprises: deleting the temporary key pair or the secret in response to the generation of the key for the AS security.
[0115] FIG. 8 shows a flowchart of an example method 800 implemented at a second apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 800 will be described from the perspective of the second apparatus 120 in FIG. 1.
[0116] At block 810, receiving, from a first apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information.
[0117] At block 820, transmitting, to the first apparatus, a response to the request comprising an indication of confirmed key exchange information.
[0118] At block 830, generating, based on the confirmed key exchange information, a key for the AS security.
[0119] In some example embodiments, the method 800 further comprises: receiving, from the first apparatus, information about a temporary key pair in the request, the temporary key pair generated based on the confirmed key exchange information by the first apparatus.
[0120] In some example embodiments, the method 800 further comprises: receiving, from the first apparatus, information about a temporary key pair in an RRC container encrypted with the key for the AS security, the temporary key pair generated based on the confirmed key exchange information by the first apparatus.
[0121] In some example embodiments, the method 800 further comprises: generating the key for the AS security based on the public key of the temporary key pair and a private key associated with the confirmed key exchange information.
[0122] In some example embodiments, the method 800 further comprises: decrypting the RRC container with the key for AS security.
[0123] In some example embodiments, the confirmed key exchange information comprises an identifier of a selected Access Network, AN, public key.
[0124] In some example embodiments, the method 800 further comprises: generating, based on the key exchange information, a secret; and transmitting, to the first apparatus, the secret.
[0125] In some example embodiments, the method 800 further comprises: exchanging, with the first apparatus, access request messages encrypted with the key for the AS security.
[0126] In some example embodiments, the method 800 further comprises: transmitting, to the first apparatus, configuration information comprising an indication of supporting the AS security during RRC connection initialization, wherein the reception of the request to activate the AS security is in response to transmitting the configuration information.
[0127] In some example embodiments, the method 800 further comprises: deleting the information about the temporary key pair or the secret in response to the generation of the key for the AS security.
[0128] In some example embodiments, the first apparatus is or is comprised in a terminal device, and wherein the second apparatus is or is comprised in a network device.
[0129] In some example embodiments, a first apparatus capable of performing any of the method 700 (for example, the first apparatus 110 in FIG. 1) may comprise means for performing the respective operations of the method 700. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The first apparatus may be implemented as or included in the first apparatus 110 in FIG. 1.
[0130] In some example embodiments, the first apparatus comprises means for transmitting, to a second apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information; means for receiving, from the second apparatus, a response to the request comprising an indication of confirmed key exchange information; and means for generating, based on the confirmed key exchange information, a key for the AS security.
[0131] In some example embodiments, the first apparatus further comprises: means for generating, based on the confirmed key exchange information, a temporary key pair; and means for generating the key for the AS security based on a private key of the temporary key pair and a public key associated with the confirmed key exchange information.
[0132] In some example embodiments, the first apparatus further comprises: means for transmitting, to the second apparatus, information about the temporary key pair in the request.
[0133] In some example embodiments, the first apparatus further comprises: means for transmitting, to the second apparatus, the information about the temporary key pair in an RRC container encrypted with the key for the AS security.
[0134] In some example embodiments, the information about the temporary key pair comprises a public key of the temporary key pair.
[0135] In some example embodiments, in response to the information about the temporary key pair exceeds the length of the request, the information about the temporary key pair is transmitted with one of: repeated transmission, each of the repeated transmission encapsulated with part of the information about the temporary key pair, or the information about the temporary key pair spitted into concatenated blocks.
[0136] In some example embodiments, the first apparatus further comprises: means for receiving, from the second apparatus, a response comprising an indication of an acknowledgement of the activation of the AS security.
[0137] In some example embodiments, the confirmed key exchange information comprises an identifier of a selected Access Network, AN, public key.
[0138] In some example embodiments, the first apparatus further comprises: means for generating the key for the AS security based on the received secret.
[0139] In some example embodiments, the first apparatus further comprises: means for exchanging, with the second apparatus, access request messages encrypted with the key for the AS security.
[0140] In some example embodiments, the first apparatus further comprises: means for receiving, from the second apparatus, configuration information comprising an indication of supporting the AS security during RRC connection initialization, wherein the transmission of the request to activate the AS security is in response to receiving the configuration information.
[0141] In some example embodiments, the first apparatus further comprises: means for deleting the temporary key pair or the secret in response to the generation of the key for the AS security.
[0142] In some example embodiments, a second apparatus capable of performing any of the method 800 (for example, the second apparatus 120 in FIG. 1) may comprise means for performing the respective operations of the method 800. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The second apparatus may be implemented as or included in the second apparatus 120 in FIG. 1.
[0143] In some example embodiments, the second apparatus comprises means for receiving, from a first apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information; means for transmitting, to the first apparatus, a response to the request comprising an indication of confirmed key exchange information; and means for generating, based on the confirmed key exchange information, a key for the AS security.
[0144] In some example embodiments, the second apparatus further comprises: means for receiving, from the first apparatus, information about a temporary key pair in the request, the temporary key pair generated based on the confirmed key exchange information by the first apparatus.
[0145] In some example embodiments, the second apparatus further comprises: means for receiving, from the first apparatus, information about a temporary key pair in an RRC container encrypted with the key for the AS security, the temporary key pair generated based on the confirmed key exchange information by the first apparatus.
[0146] In some example embodiments, the second apparatus further comprises: means for generating the key for the AS security based on the public key of the temporary key pair and a private key associated with the confirmed key exchange information.
[0147] In some example embodiments, the second apparatus further comprises: means for decrypting the RRC container with the key for AS security.
[0148] In some example embodiments, the confirmed key exchange information comprises an identifier of a selected Access Network, AN, public key.
[0149] In some example embodiments, the second apparatus further comprises: means for generating, based on the key exchange information, a secret; and means for transmitting, to the first apparatus, the secret.
[0150] In some example embodiments, the second apparatus further comprises: means for exchanging, with the first apparatus, access request messages encrypted with the key for the AS security.
[0151] In some example embodiments, the second apparatus further comprises: means for transmitting, to the first apparatus, configuration information comprising an indication of supporting the AS security during RRC connection initialization, wherein the reception of the request to activate the AS security is in response to transmitting the configuration information.
[0152] In some example embodiments, the second apparatus further comprises: means for deleting the information about the temporary key pair or the secret in response to the generation of the key for the AS security.
[0153] In some example embodiments, the first apparatus is or is comprised in a terminal device, and wherein the second apparatus is or is comprised in a network device.
[0154] FIG. 9 is a simplified block diagram of a device 900 that is suitable for implementing example embodiments of the present disclosure. The device 900 may be provided to implement a communication device, for example, the terminal device 110 or the network device 120 as shown in FIG. 1, the 6G UE 110 or the 6G gNB 120 as shown in FIGs. 4-6. As shown, the device 900 includes one or more processors 910, one or more memories 920 coupled to the processor 910, and one or more communication modules 940 coupled to the processor 910.
[0155] The communication module 940 is for bidirectional communications. The communication module 940 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interfaces may represent any interface that is necessary for communication with other network elements. In some example embodiments, the communication module 940 may include at least one antenna.
[0156] The processor 910 may be of any type suitable to the local technical network and may include one or more of the following: general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 900 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.
[0157] The memory 920 may include one or more non-volatile memories and one or more volatile memories. Examples of the non-volatile memories include, but are not limited to, a Read Only Memory (ROM) 924, an electrically programmable read only memory (EPROM) , a flash memory, a hard disk, a compact disc (CD) , a digital video disk (DVD) , an optical disk, a laser disk, and other magnetic storage and / or optical storage. Examples of the volatile memories include, but are not limited to, a random-access memory (RAM) 922 and other volatile memories that will not last in the power-down duration.
[0158] A computer program 930 includes computer executable instructions that are executed by the associated processor 910. The instructions of the program 930 may include instructions for performing operations / acts of some example embodiments of the present disclosure. The program 930 may be stored in the memory, e.g., the ROM 924. The processor 910 may perform any suitable actions and processing by loading the program 930 into the RAM 922.
[0159] The example embodiments of the present disclosure may be implemented by means of the program 930 so that the device 900 may perform any process of the disclosure as discussed with reference to FIG. 4 to FIG. 8. The example embodiments of the present disclosure may also be implemented by hardware or by a combination of software and hardware.
[0160] In some example embodiments, the program 930 may be tangibly contained in a computer readable medium which may be included in the device 900 (such as in the memory 920) or other storage devices that are accessible by the device 900. The device 900 may load the program 930 from the computer readable medium to the RAM 922 for execution. In some example embodiments, the computer readable medium may include any types of non-transitory storage medium, such as ROM, EPROM, a flash memory, a hard disk, CD, DVD, and the like. The term “non-transitory, ” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM) .
[0161] FIG. 10 shows an example of the computer readable medium 1000 which may be in form of CD, DVD or other optical storage disk. The computer readable medium 1000 has the program 930 stored thereon.
[0162] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, and other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. Although various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representations, it is to be understood that the block, apparatus, system, technique or method described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[0163] Some example embodiments of the present disclosure also provide at least one computer program product tangibly stored on a computer readable medium, such as a non-transitory computer readable medium. The computer program product includes computer-executable instructions, such as those included in program modules, being executed in a device on a target physical or virtual processor, to carry out any of the methods as described above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.
[0164] Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general-purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program code, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0165] In the context of the present disclosure, the computer program code or related data may be carried by any suitable carrier to enable the device, apparatus or processor to perform various processes and operations as described above. Examples of the carrier include a signal, computer readable medium, and the like.
[0166] The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random-access memory (RAM) , a read-only memory (ROM) , an erasable programmable read-only memory (EPROM or Flash memory) , an optical fiber, a portable compact disc read-only memory (CD-ROM) , an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0167] Further, although operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, although several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Unless explicitly stated, certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated, various features that are described in the context of a single embodiment may also be implemented in a plurality of embodiments separately or in any suitable sub-combination.
[0168] Although the present disclosure has been described in languages specific to structural features and / or methodological acts, it is to be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.
Claims
1.A first apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus at least to:transmit, to a second apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information;receive, from the second apparatus, a response to the request comprising an indication of confirmed key exchange information; andgenerate, based on the confirmed key exchange information, a key for the AS security.2.The first apparatus of claim 1, wherein the first apparatus is caused to:generate, based on the confirmed key exchange information, a temporary key pair; andgenerate the key for the AS security based on a private key of the temporary key pair and a public key associated with the confirmed key exchange information.3.The first apparatus of any of claims 1 to 2, wherein the first apparatus is caused to:transmit, to the second apparatus, information about the temporary key pair in the request.4.The first apparatus of any of claims 1 to 2, wherein the first apparatus is caused to:transmit, to the second apparatus, the information about the temporary key pair in an RRC container encrypted with the key for the AS security.5.The first apparatus of any of claims 1 to 4, wherein the information about the temporary key pair comprises a public key of the temporary key pair.6.The first apparatus of any of claims 3 to 5, wherein in response to the information about the temporary key pair exceeds the length of the request, the information about the temporary key pair is transmitted with one of:repeated transmission, each of the repeated transmission encapsulated with part of the information about the temporary key pair, orthe information about the temporary key pair spitted into concatenated blocks.7.The first apparatus of any of claims 1 to 6, wherein the first apparatus is caused to:receive, from the second apparatus, a response comprising an indication of an acknowledgement of the activation of the AS security.8.The first apparatus of any of claims 1 to 7, wherein the confirmed key exchange information comprises an identifier of a selected Access Network, AN, public key.9.The first apparatus of claim 1, wherein the confirmed key exchange information comprises a secret generated by the second apparatus, the first apparatus is caused to:generate the key for the AS security based on the received secret.10.The first apparatus of any of claims 1 to 9, wherein the first apparatus is caused to:exchange, with the second apparatus, access request messages encrypted with the key for the AS security.11.The first apparatus of any of claims 1 to 10, wherein the first apparatus is caused to:receive, from the second apparatus, configuration information comprising an indication of supporting the AS security during RRC connection initialization,wherein the transmission of the request to activate the AS security is in response to receiving the configuration information.12.The first apparatus of any of claims 1 to 11, wherein the first apparatus is caused to:delete the temporary key pair or the secret in response to the generation of the key for the AS security.13.A second apparatus, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the second apparatus at least to:receive, from a first apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information;transmit, to the first apparatus, a response to the request comprising an indication of confirmed key exchange information; andgenerate, based on the confirmed key exchange information, a key for the AS security.14.The second apparatus of claim 13, wherein the second apparatus is caused to:receive, from the first apparatus, information about a temporary key pair in the request, the temporary key pair generated based on the confirmed key exchange information by the first apparatus.15.The second apparatus of claim 13, wherein the second apparatus is caused to:receive, from the first apparatus, information about a temporary key pair in an RRC container encrypted with the key for the AS security, the temporary key pair generated based on the confirmed key exchange information by the first apparatus.16.The second apparatus of any of claims 14 to 15, wherein the information about the temporary key pair comprises a public key of the temporary key pair, the second apparatus is caused to:generate the key for the AS security based on the public key of the temporary key pair and a private key associated with the confirmed key exchange information.17.The second apparatus of claim 16, wherein the second apparatus is caused to:decrypt the RRC container with the key for AS security.18.The second apparatus of any of claims 13 to 17, wherein the confirmed key exchange information comprises an identifier of a selected Access Network, AN, public key.19.The second apparatus of claim 13, wherein the second apparatus is caused to:generate, based on the key exchange information, a secret; andtransmit, to the first apparatus, the secret.20.The second apparatus of any of claims 13 to 18, wherein the second apparatus is caused to:exchange, with the first apparatus, access request messages encrypted with the key for the AS security.21.The second apparatus of any of claims 13 to 20, wherein the second apparatus is caused to:transmit, to the first apparatus, configuration information comprising an indication of supporting the AS security during RRC connection initialization,wherein the reception of the request to activate the AS security is in response to transmitting the configuration information.22.The second apparatus of any of claims 13 to 21, wherein the second apparatus is caused to:delete the information about the temporary key pair or the secret in response to the generation of the key for the AS security.23.The second apparatus of any of claims 1 to 22, wherein the first apparatus is or is comprised in a terminal device, and wherein the second apparatus is or is comprised in a network device.24.A method comprising:transmitting, to a second apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information;receiving, from the second apparatus, a response to the request comprising an indication of confirmed key exchange information; andgenerating, based on the confirmed key exchange information, a key for the AS security.25.A method comprising:receiving, from a first apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information;transmitting, to the first apparatus, a response to the request comprising an indication of confirmed key exchange information; andgenerating, based on the confirmed key exchange information, a key for the AS security.26.A first apparatus comprising:means for transmitting, to a second apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information;means for receiving, from the second apparatus, a response to the request comprising an indication of confirmed key exchange information; andmeans for generating, based on the confirmed key exchange information, a key for the AS security.27.A second apparatus comprising:means for receiving, from a first apparatus, a request to activate Access Stratum, AS, security during Radio Resource Control, RRC, connection initialization, the request comprising key exchange information;means for transmitting, to the first apparatus, a response to the request comprising an indication of confirmed key exchange information; andmeans for generating, based on the confirmed key exchange information, a key for the AS security.28.A computer readable medium comprising instructions stored thereon for causing an apparatus at least to perform the method of claim 24 or the method of claim 25.29.A computer program comprising instructions for causing an apparatus at least to perform the method of claim 24 or the method of claim 25.