Message protection in random access procedure
The implementation of temporary key-based security key generation and protection mechanisms addresses the security gaps in random access procedures, enhancing message integrity and confidentiality in communication networks.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- NOKIA SOLUTIONS (SHANGHAI) CO LTD
- Filing Date
- 2025-01-24
- Publication Date
- 2026-07-30
AI Technical Summary
Existing communication networks lack effective security measures for message protection during random access procedures, particularly in transitions from idle or inactive states, exposing messages to potential interception and tampering.
Implementing security key generation and protection mechanisms using temporary keys for message protection in random access procedures, involving apparatuses and devices that generate and transmit messages secured with secondary security keys based on temporary keys.
Enhances the security of messages exchanged during random access procedures, ensuring integrity and confidentiality, especially in radio resource control transitions, thereby preventing unauthorized access and data tampering.
Smart Images

Figure CN2025074808_30072026_PF_FP_ABST
Abstract
Description
MESSAGE PROTECTION IN RANDOM ACCESS PROCEDUREFIELD
[0001] Various example embodiments of the present disclosure generally relate to the field of telecommunication and in particular, to methods, devices, apparatuses and computer readable storage medium for message protection in random access procedure.BACKGROUND
[0002] A communication network may serve as a facility that enables communications between two or more communication devices or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network. A communication device may be provided with a service by an application server.
[0003] The communication network may operate in accordance with standards such as those provided by Third Generation Partnership Project (3GPP) or European Telecommunications Standards Institute (ETSI) . Examples of standards provided by 3GPP are the so-called 3GPP standards for cellular technology generations, such as 3GPP standards for 4G technology, 5G technology, 6G technology etc.SUMMARY
[0004] Some example embodiments of this disclosure will be described with respect to certain aspects. These aspects are not intended to indicate key or essential features of the various example embodiments of this disclosure. Nor are they intended to be used to limit the scope thereof. Other related features, aspects, and elements will be apparent to a person skilled in the art in view of this disclosure. For example, it should be appreciated that further aspects may be provided by the combination of any two or more of the various aspects described below.
[0005] In a first aspect of the present disclosure, there is provided an apparatus. The apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive, from a device, information indicative of a setup of a first security key for message protection in a random access procedure, wherein the first security key is at least generated based on a temporary key; generate, at least based on the temporary key, a second security key for message protection in the random access procedure; and transmit, to the device, at least one first message associated with the random access procedure and protected with the second security key.
[0006] In a second aspect of the present disclosure, there is provided a device. The device comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to: transmit, to an apparatus, information indicative of a setup of a first security key for message protection in a random access procedure, wherein the first security key is at least generated based on a temporary key; and receive, from the apparatus, at least one first message associated with the random access procedure, the at least one first message being protected with a second security key for the message protection in the random access procedure, the second security key being generated at least based on the temporary key.
[0007] In a third aspect of the present disclosure, there is provided a network entity. The network entity comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the network entity at least to: receive, from a device, a request for a security key for message protection in a random access procedure; generate the security key at least based on a temporary key; and transmit the security key to the device.
[0008] In a fourth aspect of the present disclosure, there is provided an apparatus. The apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive, from a device, information indicative of a parameter associated with a first security key for message protection in a random access procedure; generate, at least based on the information indicative of the parameter, a second security key for the message protection in the random access procedure; and transmit, to the device, at least one first message associated with the random access procedure, and protected with the second security key.
[0009] In a fifth aspect of the present disclosure, there is provided a device. The device comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to: transmit, to an apparatus, information indicative of a parameter associated with a first security key for message protection in a random access procedure; and receive, from the apparatus, at least one first message associated with the random access procedure, the at least one first message being protected with a second security key, and the second security key being generated at least based on the information indicative of the parameter.
[0010] In a sixth aspect of the present disclosure, there is provided a network entity. The network entity comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the network entity at least to: receive, from a device, a request for a first security key for message protection in a random access procedure; generate the first security key at least based on a parameter associated with the first security key for message protection in the random access procedure; and transmit, to the device, at least one of the first security key or the parameter.
[0011] In a seventh aspect of the present disclosure, there is provided an apparatus. The apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: transmit, to a device, a request for resuming a connection with the device with a cause of security, wherein the apparatus is in a radio resource control inactive state and a key for security was shared by the apparatus and the device; and receive, from the device, a response to the request for resuming the connection with the device, the response being protected with the key.
[0012] In an eighth aspect of the present disclosure, there is provided a device. The device comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to: receive, from an apparatus, a request for resuming a connection with the device with a cause of security, wherein the apparatus is in a radio resource control inactive state and a key for security was shared by the apparatus and the device; and transmit, to the apparatus, a response to the request for resuming the connection, the response being protected with the key.
[0013] In a ninth aspect of the present disclosure, there is provided a method. The method comprises: receiving, from a device, information indicative of a setup of a first security key for message protection in a random access procedure, wherein the first security key is at least generated based on a temporary key; generating, at least based on the temporary key, a second security key for message protection in the random access procedure; and transmitting, to the device, at least one first message associated with the random access procedure and protected with the second security key.
[0014] In a tenth aspect of the present disclosure, there is provided a method. The method comprises: transmitting, to an apparatus, information indicative of a setup of a first security key for message protection in a random access procedure, wherein the first security key is at least generated based on a temporary key; and receiving, from the apparatus, at least one first message associated with the random access procedure, the at least one first message being protected with a second security key for the message protection in the random access procedure, the second security key being generated at least based on the temporary key.
[0015] In an eleventh aspect of the present disclosure, there is provided a method. The method comprises: receiving, from a device, a request for a security key for message protection in a random access procedure; generating the security key at least based on a temporary key; and transmitting the security key to the device.
[0016] In a twelfth aspect of the present disclosure, there is provided a method. The method comprises: receiving, from a device, information indicative of a parameter associated with a first security key for message protection in a random access procedure; generating, at least based on the information indicative of the parameter, a second security key for the message protection in the random access procedure; and transmitting, to the device, at least one first message associated with the random access procedure, and protected with the second security key.
[0017] In a thirteenth aspect of the present disclosure, there is provided a method. The method comprises: transmitting, to an apparatus, information indicative of a parameter associated with a first security key for message protection in a random access procedure; and receiving, from the apparatus, at least one first message associated with the random access procedure, the at least one first message being protected with a second security key, and the second security key being generated at least based on the information indicative of the parameter.
[0018] In a fourteenth aspect of the present disclosure, there is provided a method. The method comprises: receiving, from a device, a request for a first security key for message protection in a random access procedure; generating the first security key at least based on a parameter associated with the first security key for message protection in the random access procedure; and transmitting, to the device, at least one of the first security key or the parameter.
[0019] In a fifteenth aspect of the present disclosure, there is provided a method. The method comprises: transmitting, to a device, a request for resuming a connection with the device with a cause of security, wherein the apparatus is in a radio resource control inactive state and a key for security was shared by the apparatus and the device; and receiving, from the device, a response to the request for resuming the connection with the device, the response being protected with the key.
[0020] In a sixteenth aspect of the present disclosure, there is provided a method. The method comprises: receiving, from an apparatus, a request for resuming a connection with the device with a cause of security, wherein the apparatus is in a radio resource control inactive state and a key for security was shared by the apparatus and the device; and transmitting, to the apparatus, a response to the request for resuming the connection, the response being protected with the key.
[0021] In a seventeenth aspect of the present disclosure, there is provided an apparatus. The apparatus comprises means for receiving, from a device, information indicative of a setup of a first security key for message protection in a random access procedure, wherein the first security key is at least generated based on a temporary key; means for generating, at least based on the temporary key, a second security key for message protection in the random access procedure; and means for transmitting, to the device, at least one first message associated with the random access procedure and protected with the second security key.
[0022] In an eighteenth aspect of the present disclosure, there is provided a device. The device comprises means for transmitting, to an apparatus, information indicative of a setup of a first security key for message protection in a random access procedure, wherein the first security key is at least generated based on a temporary key; and means for receiving, from the apparatus, at least one first message associated with the random access procedure, the at least one first message being protected with a second security key for the message protection in the random access procedure, the second security key being generated at least based on the temporary key.
[0023] In a nineteenth aspect of the present disclosure, there is provided a network entity. The network entity comprises means for receiving, from a device, a request for a security key for message protection in a random access procedure; means for generating the security key at least based on a temporary key; and means for transmitting the security key to the device.
[0024] In a twentieth aspect of the present disclosure, there is provided an apparatus. The apparatus comprises means for receiving, from a device, information indicative of a parameter associated with a first security key for message protection in a random access procedure; means for generating, at least based on the information indicative of the parameter, a second security key for the message protection in the random access procedure; and means for transmitting, to the device, at least one first message associated with the random access procedure, and protected with the second security key.
[0025] In a twenty-first aspect of the present disclosure, there is provided a device. The device comprises means for transmitting, to an apparatus, information indicative of a parameter associated with a first security key for message protection in a random access procedure; and means for receiving, from the apparatus, at least one first message associated with the random access procedure, the at least one first message being protected with a second security key, and the second security key being generated at least based on the information indicative of the parameter.
[0026] In a twenty-second aspect of the present disclosure, there is provided a network entity. The network entity comprises means for receiving, from a device, a request for a first security key for message protection in a random access procedure; means for generating the first security key at least based on a parameter associated with the first security key for message protection in the random access procedure; and means for transmitting, to the device, at least one of the first security key or the parameter.
[0027] In a twenty-third aspect of the present disclosure, there is provided an apparatus. The apparatus comprises means for transmitting, to a device, a request for resuming a connection with the device with a cause of security, wherein the apparatus is in a radio resource control inactive state and a key for security was shared by the apparatus and the device; and means for receiving, from the device, a response to the request for resuming the connection with the device, the response being protected with the key.
[0028] In a twenty-fourth aspect of the present disclosure, there is provided a device. The device comprises means for receiving, from an apparatus, a request for resuming a connection with the device with a cause of security, wherein the apparatus is in a radio resource control inactive state and a key for security was shared by the apparatus and the device; and means for transmitting, to the apparatus, a response to the request for resuming the connection, the response being protected with the key.
[0029] In a twenty-fifth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the ninth aspect.
[0030] In a twenty-sixth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the tenth aspect.
[0031] In a twenty-seventh aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the eleventh aspect.
[0032] In a twenty-eighth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the twelfth aspect.
[0033] In a twenty-ninth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the thirteenth aspect.
[0034] In a thirtieth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the fourteenth aspect.
[0035] In a thirty-first aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the fifteenth aspect.
[0036] In a thirty-second aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the sixteenth aspect.
[0037] In some or all examples of the first to the thirty-second aspects, the temporary key is determined based on a key for an access and mobility management function, and wherein the apparatus is caused to: generate the second security key based on a key identifier of the apparatus and the temporary key.
[0038] In some or all examples of the first to the thirty-second aspects, the apparatus is caused to: receive, from the device, an indication in which temporary access stratum security is allowed; and transmit, to the device, a trigger to obtain, from a network entity, the first security key associated with the temporary access stratum security, the trigger comprising a key identifier of the apparatus and a temporary identifier of the apparatus.
[0039] In some or all examples of the first to the thirty-second aspects, the network entity comprises a device implementing mobility management.
[0040] In some or all examples of the first to the thirty-second aspects, the apparatus is caused to: receive, from the device, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key.
[0041] In some or all examples of the first to the thirty-second aspects, the at least one first message comprises at least one of: a request for a radio resource control connection setup; or a message indicating a complete of the radio resource control connection setup.
[0042] In some or all examples of the first to the thirty-second aspects, the at least one second message comprises a response to the request for the radio resource control connection setup.
[0043] In some or all examples of the first to the thirty-second aspects, the apparatus is in a radio resource control idle state.
[0044] In some or all examples of the first to the thirty-second aspects, the apparatus comprises a terminal device, and the device comprises a network device.
[0045] In some or all examples of the first to the thirty-second aspects, the device is caused to: transmit, to the apparatus, an indication that temporary access stratum security is allowed; and receive, from the apparatus, a trigger to obtain, from a network entity, the first security key associated with the temporary access stratum security, the trigger comprising a key identifier of the apparatus and a temporary identifier of the apparatus.
[0046] In some or all examples of the first to the thirty-second aspects, the device is caused to: transmit, to the apparatus, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key.
[0047] In some or all examples of the first to the thirty-second aspects, the device is caused to: transmit, to a network entity, a request for the first security key, the request comprising at least one of a key identifier of the apparatus or a temporary identifier of the apparatus; and receive, from the network entity, the first security key.
[0048] In some or all examples of the first to the thirty-second aspects, the request comprises at least one of a key identifier of an apparatus or a temporary identifier of the apparatus.
[0049] In some or all examples of the first to the thirty-second aspects, the temporary key is determined based on a key for an access and mobility management function, and the network entity is caused to: generate the security key based on the temporary key and the key identifier of the apparatus.
[0050] In some or all examples of the first to the thirty-second aspects, the apparatus is caused to: transmit, to the device, a request for the information indicative of the parameter, the request comprising a temporary identifier of the apparatus and a cause of security.
[0051] In some or all examples of the first to the thirty-second aspects, the apparatus is caused to: generate the second security key based on the parameter and a key for an access and mobility management function.
[0052] In some or all examples of the first to the thirty-second aspects, the apparatus is caused to: receive, from the device, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key.
[0053] In some or all examples of the first to the thirty-second aspects, the parameter comprises a random value.
[0054] In some or all examples of the first to the thirty-second aspects, the parameter is generated at the device or a network entity.
[0055] In some or all examples of the first to the thirty-second aspects, the device is caused to: receive, from the apparatus, a request for the information indicative of the parameter, the request comprising a temporary identifier of the apparatus and a cause of security.
[0056] In some or all examples of the first to the thirty-second aspects, the device is caused to: transmit, to the apparatus, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key.
[0057] In some or all examples of the first to the thirty-second aspects, the device is caused to: transmit, to a network entity, a request for the first security key; and receive, from the network entity, at least one of the first security key or the parameter.
[0058] In some or all examples of the first to the thirty-second aspects, the parameter is generated at the network entity, or the parameter is generated at the device and is comprised in the request for the first security key.
[0059] In some or all examples of the first to the thirty-second aspects, the request comprises a temporary identifier of an apparatus.
[0060] In some or all examples of the first to the thirty-second aspects, the apparatus is caused to: transmit, to the device, a message indicating complete of resuming the connection with the device, the message being protected with the key.
[0061] In some or all examples of the first to the thirty-second aspects, the device is caused to: receive, from the apparatus, a message indicating complete of resuming the connection with the device, the message being protected with the key.
[0062] It is to be understood that the Summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description.BRIEF DESCRIPTION OF THE DRAWINGS
[0063] Some example embodiments will now be described with reference to the accompanying drawings, where:
[0064] FIG. 1 illustrates an example communication environment in which example embodiments of the present disclosure can be implemented;
[0065] FIG. 2 illustrates an example signaling flow for initial radio resource control (RRC) procedure;
[0066] FIG. 3A illustrates an example signaling flow for initial access from an idle state;
[0067] FIG. 3B illustrates an example signaling flow for resume from an inactive state;
[0068] FIG. 4 illustrates a schematic diagram of an example state handling;
[0069] FIG. 5A and FIG. 5B illustrate example signaling flows for connecting a UE to an access and mobility management function (AMF) , respectively;
[0070] FIG. 6A and FIG. 6B illustrate example schematic diagrams of example attack scenarios, respectively;
[0071] FIG. 7 illustrates a schematic diagram of example scenarios during RRC connection establishment;
[0072] FIG. 8 illustrates an example signaling flow for message protection in a random access procedure in accordance with some example embodiments of the present disclosure;
[0073] FIG. 9 illustrates a schematic diagram of a process for generating a temporary key in accordance with some example embodiments of the present disclosure;
[0074] FIG. 10 illustrates an example signaling flow for message protection in a random access procedure in accordance with some example embodiments of the present disclosure;
[0075] FIG. 11 illustrates an example signaling flow for message protection in a random access procedure in accordance with some example embodiments of the present disclosure;
[0076] FIG. 12 illustrates an example signaling flow for message protection in a random access procedure in accordance with some example embodiments of the present disclosure;
[0077] FIG. 13 illustrates an example signaling flow for message protection in a random access procedure in accordance with some example embodiments of the present disclosure;
[0078] FIG. 14 illustrates an example signaling flow for message protection in a random access procedure in accordance with some example embodiments of the present disclosure;
[0079] FIG. 15A illustrates a flowchart of a method implemented at an apparatus in accordance with some example embodiments of the present disclosure;
[0080] FIG. 15B illustrates a flowchart of a method implemented at a device in accordance with some example embodiments of the present disclosure;
[0081] FIG. 15C illustrates a flowchart of a method implemented at a network entity in accordance with some example embodiments of the present disclosure;
[0082] FIG. 16A illustrates a flowchart of a method implemented at an apparatus in accordance with some example embodiments of the present disclosure;
[0083] FIG. 16B illustrates a flowchart of a method implemented at a device in accordance with some example embodiments of the present disclosure;
[0084] FIG. 16C illustrates a flowchart of a method implemented at a network entity in accordance with some example embodiments of the present disclosure;
[0085] FIG. 17A illustrates a flowchart of a method implemented at an apparatus in accordance with some example embodiments of the present disclosure;
[0086] FIG. 17B illustrates a flowchart of a method implemented at a device in accordance with some example embodiments of the present disclosure;
[0087] FIG. 18 illustrates a simplified block diagram of a device that is suitable for implementing example embodiments of the present disclosure; and
[0088] FIG. 19 illustrates a block diagram of an example computer readable medium in accordance with some example embodiments of the present disclosure.
[0089] Throughout the drawings, the same or similar reference numerals represent the same or similar element.DETAILED DESCRIPTION
[0090] Principle of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. Embodiments described herein can be implemented in various manners other than the ones described below.
[0091] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0092] References in the present disclosure to “one embodiment, ” “an embodiment, ” “an example embodiment, ” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
[0093] It shall be understood that although the terms “first, ” “second, ” …, etc. in front of noun (s) and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another and they do not limit the order of the noun (s) . For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.
[0094] As used herein, “at least one of the following: <a list of two or more elements>” and “at least one of <a list of two or more elements>” and similar wording, where the list of two or more elements are joined by “and” or “or” , mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0095] As used herein, unless stated explicitly, performing a step “in response to A” does not indicate that the step is performed immediately after “A” occurs and one or more intervening steps may be included.
[0096] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a” , “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” , “comprising” , “has” , “having” , “includes” and / or “including” , when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0097] As used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and (b) combinations of hardware circuits and software, such as (as applicable) : (i) a combination of analog and / or digital hardware circuit (s) with software / firmware and (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0098] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0099] As used herein, the term “communication network” refers to a network following any suitable communication standards, such as New Radio (NR) , Long Term Evolution (LTE) , LTE-Advanced (LTE-A) , Wideband Code Division Multiple Access (WCDMA) , High-Speed Packet Access (HSPA) , Narrow Band Internet of Things (NB-IoT) and so on. Furthermore, the communications between a terminal device and a network device in the communication network may be performed according to any suitable generation communication protocols, including, but not limited to, the first generation (1G) , the second generation (2G) , 2.5G, 2.75G, the third generation (3G) , the fourth generation (4G) , 4.5G, the fifth generation (5G) , 5.5G, the sixth generation (6G) communication protocols, and / or any other protocols either currently known or to be developed in the future. Embodiments of the present disclosure may be applied in various communication systems. Given the rapid development in communications, there will of course also be future type communication technologies and systems with which the present disclosure may be embodied. It should not be seen as limiting the scope of the present disclosure to only the aforementioned system.
[0100] As used herein, the term “network device” refers to a node in a communication network via which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP) , for example, a node B (NodeB or NB) , an evolved NodeB (eNodeB or eNB) , an NR NB (also referred to as a gNB) , a Remote Radio Unit (RRU) , a radio header (RH) , a remote radio head (RRH) , a relay, an Integrated Access and Backhaul (IAB) node, a low power node such as a femto, a pico, a non-terrestrial network (NTN) or non-ground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, an aircraft network device, and so forth, depending on the applied terminology and technology. In some example embodiments, radio access network (RAN) split architecture comprises a Centralized Unit (CU) and a Distributed Unit (DU) at an IAB donor node. An IAB node comprises a Mobile Terminal (IAB-MT) part that behaves like a UE toward the parent node, and a DU part of an IAB node behaves like a base station toward the next-hop IAB node.
[0101] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE) , a Subscriber Station (SS) , a Portable Subscriber Station, a Mobile Station (MS) , or an Access Terminal (AT) . The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA) , portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE) , laptop-mounted equipment (LME) , USB dongles, smart devices, wireless customer-premises equipment (CPE) , an Internet of Things (IoT) device, a watch or other wearable, a head-mounted display (HMD) , a vehicle, a drone, a medical device and applications (e.g., remote surgery) , an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts) , a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an IAB node (e.g., a relay node) . In the following description, the terms “terminal device” , “communication device” , “terminal” , “user equipment” and “UE” may be used interchangeably.
[0102] As used herein, the term “resource, ” “transmission resource, ” “resource block, ” “physical resource block (PRB) , ” “uplink resource, ” or “downlink resource” may refer to any resource for performing a communication, for example, a communication between a terminal device and a network device, such as a resource in time domain, a resource in frequency domain, a resource in space domain, a resource in code domain, or any other combination of the time, frequency, space and / or code domain resource enabling a communication, and the like. In the following, unless explicitly stated, a resource in both frequency domain and time domain will be used as an example of a transmission resource for describing some example embodiments of the present disclosure. It is noted that example embodiments of the present disclosure are equally applicable to other resources in other domains.
[0103] A core network function as described herein may be implemented as a core network entity that includes a combination of hardware processing circuit and software and / or firmware comprising machine-readable instructions, or software comprising machine-readable instructions that are executable by at least one processor of hardware processing circuit of an apparatus. A hardware processing circuit includes at least one processor and at least one memory storing machine-readable instructions that are executable by the at least one processor of the hardware processing circuit. A processor includes any or some combination of an accelerator, a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, a digital signal processor, a central processing unit, a graphic processing unit, a tensor processing unit. Memory includes any or some combination of volatile or non-volatile memory (e.g., a flash memory, cache, a random-access memory (RAM) , and / or a read-only memory (ROM) ) . The memory stores the machine-readable instructions of the software and / or firmware for execution by the at least one processor of the hardware processing circuit. The machine-readable instructions are executable by the at least one processor of the hardware processing circuit cause the hardware processing circuit to perform the actions or operations of the methods described herein. For example, the session management function described herein may be implemented as a session management entity and the session management policy control function described herein may be implemented as a session management policy control entity, respectively.
[0104] FIG. 1 illustrates an example communication environment 100 in which example embodiments of the present disclosure can be implemented. The communication environment 100 involves a first apparatus 110, a second apparatus 120, and a third apparatus 130. The first apparatus 110 may communicate with the second apparatus 120 and the third apparatus 130 bidirectionally. In the example of FIG. 1, the first apparatus 110 may include a terminal device (e.g., a UE) . The second apparatus 120 may include a network device (e.g., a base station, a gNB, etc. ) . The third apparatus 130 may include a network entity, or a network function (e.g., an access and mobility management function (AMF) , a mobility management (MM) , etc. ) .
[0105] It is to be understood that the number of first apparatus 110, the second apparatus 120 and the third apparatus 130 and their connections shown in FIG. 1 are only for the purpose of illustration without suggesting any limitation. The communication environment 100 may include any suitable number of apparatus and / or devices configured to implement example embodiments of the present disclosure.
[0106] In the following, for the purpose of illustration, some example embodiments are described with the first apparatus 110 operating as a terminal device, the second apparatus 120 operating as a network device, and the third apparatus 130 operating as a network entity or a network function. However, in some example embodiments, operations described in connection with a terminal device may be implemented at a network device or other device, and operations described in connection with a network device may be implemented at a terminal device or other device.
[0107] In some example embodiments, if the first apparatus 110 is a terminal device or included in a terminal device and the second apparatus 120 is a network device or is included in a network device, a transmission direction from the second apparatus 120 to the first apparatus 110 is referred to as a downlink (DL) , and a transmission direction from the first apparatus 110 to the second apparatus 120 is referred to as an uplink (UL) . In DL, the second apparatus 120 is a transmitting (TX) device (or a transmitter) and the first apparatus 110 is a receiving (RX) device (or a receiver) . In UL, the first apparatus 110 is a TX device (or a transmitter) and the second apparatus 120 is a RX device (or a receiver) .
[0108] Communications in the communication environment 100 may be implemented according to any proper communication protocol (s) , comprising, but not limited to, cellular communication protocols of the first generation (1G) , the second generation (2G) , the third generation (3G) , the fourth generation (4G) , the fifth generation (5G) , the sixth generation (6G) , and the like, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA) , Frequency Division Multiple Access (FDMA) , Time Division Multiple Access (TDMA) , Frequency Division Duplex (FDD) , Time Division Duplex (TDD) , Multiple-Input Multiple-Output (MIMO) , Orthogonal Frequency Division Multiple (OFDM) , Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.
[0109] In the context of User Equipment (UE) in cellular networks, there are three primary states: a connected state, an idle state, and an inactive state. in the connected state, the UE is actively engaged in communication with the network, enabling real-time data transfer, voice calls, or other services. In the idle state, the UE is not actively engaged in any communication but remains registered with the network, allowing it to receive incoming calls or messages. The inactive state, introduced in some advanced cellular networks like 5G NR, represents an intermediate state between the connected state and the idle state. In the inactive state, the UE maintains some context information with the network, enabling a faster return to the connected state compared to transitioning directly from idle.
[0110] From the perspective of security, the processes involved in transitioning the UE from the idle state to the connected state may differ from those involved in transitioning from the inactive state to the connected state.
[0111] FIG. 2 illustrates an example signaling flow 200 for an initial RRC procedure. As illustrated in FIG. 2, the signaling flow 200 involves a UE 210, a gNB 220, and an AMF 230. Specifically, the RRC procedure may be carried out as below.
[0112] The gNB 220 may broadcast system information, including a master information block (MIB) and / or system information block type 1 (SIB1) for the UE 210 to receive and decode. The UE 210 may receive MIB and / or SIB1 from the gNB 220. Based on the information obtained from the MIB and / or SIB1, the UE 210 may initiate the random access channel (RACH) procedure by transmitting a message, typically referred to as Msg 1 (Msg 1) , which includes a RACH preamble to the gNB 220. The gNB 220 may respond with a random access response (RAR) , and transmit a message, e.g., a Msg 2 (Msg 2) to the UE 210.
[0113] Subsequently, the UE 210 may use the information provided in the RAR to transmit, to the gNB 220, a message, e.g., a Msg 3 (Msg 3) which includes a RRC setup request in signaling radio bearer 0 (SRB0) . The Msg 3 is in plaintext and is used to request the establishment of an RRC connection. Then, the UE 210 may receive a massage, e.g., a Msg 4 (Msg 4) which includes a RRC setup response in SRB0. The Msg 4 is in plaintext and does not include security algorithm configuration. After receiving the Msg 4, the UE 210 may configure itself according to the instructions provided, and transmit, to the gNB 220, a RRC connection setup complete message, e.g., a Msg 5 in SRB1, confirming the establishment of the RRC connection. The Msg 5 contains a non-access stratum (NAS) registration message for registering with the network.
[0114] After successful establishment of the RRC connection, a NAS security process may be involved. For example, the NAS security process between the gNB 220 and the AMF 230 may include interactions such as NAS identity, NAS authentication, NAS security mode command, context setup, UE capability information, protocol data unit (PDU) session establishment, etc.
[0115] In the signaling flow 200, the messages such as MIB, SIB1, Msg 1, Msg 2, Msg 3, Msg 4, Msg 5, NAS identity response, NAS authentication request, NAS Authentication Response, NAS security mode command, NAS security mode command complete, AS security mode command are neither ciphered nor integrity protected. The messages such as AS security mode complete are integrity protected but not ciphered. The messages such as UECapabilityEnquiry, UECapabilityInformation, RCConnection Reconfiguration, RRCConnectionReconfigurationComplete, RegisterComplete, PDUSessionEstablishmentRequest, PDUSessionEstablishmentAccept are both ciphered and integrity protected.
[0116] As described above, the UE may be in three states, i.e., the connected state, the idle state, and the inactive state. The idle state and the inactive state are similar, a difference lies in that the UE retains its access stratum (AS) security context in the inactive state. From security perspective, the initial access that the UE transitions from idle state to the connected state may be different from that of the UE transitions from inactive state to the connected state.
[0117] FIG. 3A illustrates an example signaling flow 300A for initial access from the idle state. As illustrated in FIG. 3A, the signaling flow 300A involves a UE 310, a gNB 320, and a network entity 330 implementing AMF, which is also referred to as an AMF 330.
[0118] While the UE 310 is in the idle state, the UE 310 may listen system information broadcasts from the gNB 320. For example, the UE 310 may receive (301-A) MIB from the gNB 320, or the UE 310 may receive (302-A) SIB1 from the gNB 320. Based on the received MIB and / or SIB1, the UE 310 may decide to initiate (303-A) the initial access procedure. The initial access procedure may involve a RACH process (304-A) . For example, the UE 310 may transmit a random access preamble to the gNB 320 to request uplink synchronization and acquire network resources. Upon receiving the preamble, the gNB 320 may transmit a RACH response to the UE 310, allocating temporary uplink resources to the UE 310.
[0119] Subsequently, with these temporary uplink resources, the UE 310 may transmit (305-A) a message (e.g., a Msg 3) which includes a RRC setup request to the gNB 320. After receiving the message, the gNB 320 may process it and allocate dedicated radio resources for the UE 310. Then, the gNB 320 may transmit (306-A) a massage (e.g., a Msg 4) which includes a RRC setup response to the UE 310. The UE 310 receives the Msg 4, and after the UE 310 completes the establishment of the RRC connection, the UE 310 may transmit (307-A) a message indicative of complete of RRC connection (e.g., a RRC setup complete message) to the gNB 320. The RRC setup complete message may include a non-access stratum (NAS) message for further network access authentication and registration procedures. The gNB 320 may receive RRC setup complete message, and forward (308-A) the NAS message to the AMF 330. The AMF 330 may receive the NAS message, and process it to determine the necessary context information for the UE 310. Then, the AMF 330 may transmit (308-A) a message (e.g., an initial context setup message) to the gNB 320. Upon receiving the initial context setup message, the gNB 320 may configure the necessary network resources and services for the UE 310 based on the provided context information. Then, the gNB 320 and the UE 310 may engage in an AS security activation procedure to ensure the security of the communication between them. As can be seen that before the AS security is activated, there is no AS security between the UE 310 and the gNB 320.
[0120] FIG. 3B illustrates an example signaling flow 300B for resume from the inactivate state. As illustrated in FIG. 3B, the signaling flow 300B involves the UE 310 and the gNB 320. In addition, the AMF 330 is also shown in FIG. 3B.
[0121] While the UE 310 is in the inactive state, it may be triggered to resume the connection due to some reasons. For example, the UE 310 may receive system information from the gNB 320. For example, the UE 310 may receive (301-B) MIB from the gNB 320, or the UE 310 may receive (302-B) SIB1 from the gNB 320. Based on the received MIB and / or SIB1, the UE 310 may determine that an initial access procedure is initiate (303-B) . The initial access procedure may involve a RACH process (304-B) . For example, the UE 310 may transmit a random access preamble to the gNB 320 to request uplink synchronization and acquire network resources. Upon receiving the preamble, the gNB 320 may transmit a RACH response to the UE 310, allocating temporary uplink resources to the UE 310.
[0122] Subsequently, the UE 310 may transmit (305-B) a message (e.g., a Msg 3) which includes a RRC resume request to the gNB 320. For example, this Msg 3 includes information about the intention of the UE 310 to resume its previously inactive RRC connection. The gNB 320 may receive the message, and validate the identity of the UE 310 and confirms its request. Then, the gNB 320 may activate (306-B) AS security based on the stored UE security context. The gNB 320 may allocate necessary radio resources to the UE 310 and transmit (307-B) a message (e.g., a Msg 4) which includes RRC resume response to the UE 310. After the UE 310 completes the resumption of the RRC connection, it may transmit (308-B) a message (e.g., a RRC resume complete message) indicative of RRC resume complete to the gNB 320. This message may contain a NAS message for further network layer interaction and configuration. Then, the AS security between the UE 310 and the gNB 320 is activated.
[0123] In the context of next-generation communication networks, such as 6G communication network, the idle state and the inactive state may be different from that of the 5G communication network. For example, in the 6G communication network, the idle state may rarely be entered, and no AS or NAS context may be established. For example, a UE may be not registered to core network (CN) , and a configuration or security context is merely stored. The idle state may be a state at power-up, or state when de-registered. The power saving may be fully UE controlled, which may be up to UE implementation. As for the control plane (CP) latency, it may be not guaranteed to be fast, and it may be greater than 100ms, e.g. due to NAS security setup and establishing CN registration. Furthermore, no delay optimizations may be defined in this case, and the UE may operate solely based on received system information.
[0124] In the 6G communication network, the inactive state may be a common state. In the inactive state, UE may have both NAS and AS context stored (including security context) . The state transition from connected state to the inactive state may be allowed. While the connected state to the idle state may only allowed at error cases. The power saving may be related to UE-based mobility, on-demand SI, or single paging. Based on delay optimization, the CP latency may be expected to be less than 10ms (from 1st RACH preamble to having RRC connection setup) .
[0125] FIG. 4 illustrates a schematic diagram 400 of an example RRC state handling, for example, in a 6G communication system. As illustrated in FIG. 4, when a UE powers on without any AS or NAS context and is not registered, it may initially reside in the idle state. When the UE attempts to access the network (e.g., transitioning from the idle state to the connected state) , a transition from the idle state to the connected state is involved. For this transition, processes such as network registration, and NAS and AS context setup may be involved. This process may further involve error diagnostics to ensure a smooth transition. The control plane (CP) latency for this transition is anticipated to be greater than 100 ms.
[0126] In the connected state, the AS and NAS context are stored in the UE, and operations such as mobility management, tracking area update (TAU) and routing area update (RAU) , and paging are configured. For the transition from the connected state to the inactive state, since the AS and NAS context are stored in the UE, and operations are configured, the CP latency for this transition is anticipated to be less than 10 ms. For the transition from the inactive state back to the connected state, the previously stored AS context may be utilized, and the CP latency for this process is expected to be less than 20 ms. If an error occurs in the inactive state or specific conditions are met, the UE may transition to the idle state. In this case, the AS and NAS context may be flushed. The error diagnostics may be stored to aid in subsequent analysis and network optimization. The control plane latency is anticipated to be less than 5 ms.
[0127] The RRC connection request complete (also referred to as RRC Msg 5) carrying NAS registration request (REG-REQ) is encrypted with network public key or certificate and will contain encrypted single network slice selection assistance information (S-NSSAI) in the RRC part of the message. The Base station will decrypt the encrypted RRC message and will route the NAS REG-REQ to the correct AMF according to the S-NSSAI. Since the UE gets routed to the correct AMF, the AMF may be fully isolated, and no context transfer or context sharing is required between any other AMF.
[0128] FIG. 5A illustrate an example signaling flow 500A for connecting a UE directly to a target AMF. As illustrated in FIG. 5A, the signaling flow 500A involves a UE 510, a gNB 520, an AMF 530, and a network entity implementing a unified data management (UDM) 540, which is also referred to as the UDM 540.
[0129] In the signaling flow 500A, the UE 510 initiates (501A) the initial attach and authentication. The UDM 540 triggers the AMF 530 to send the network public key to the UE 510 for isolated network slices. Subsequently, the AMF 530 transmits (502A) , to the UE 510, the network public key, for encryption of the RRC message (e.g., Msg 5) . During the process, the gNB 520 is involved in the overall communication process, facilitating the interaction between the UE and the core network elements such as the AMF 530 and UDM 540.
[0130] FIG. 5B illustrate an example signaling flow 500B for connecting a UE directly to a target AMF. As illustrated in FIG. 5B, the signaling flow 500B involves the UE 510, the gNB 520, the AMF 530, and the UDM 540.
[0131] The UE 510 uses the provided network public key to encrypt the RRC message and the S-NSSI is included in the RRC message. The UE 510 also includes an indication in the NAS message that it has the public key. Then, the UE transmits (501B) the encrypted RRC message (e.g., RRC Msg 5) to the gNB 520. The encrypted RRC message may include S-NSSAI and NAS REG-REQ. The gNB 520 may receive the RRC Msg 5 from the UE 510. The gNB 520 may decode the encrypted RRC Msg 5 and learn the S-NSSAI. After that, the gNB 520 may forward (503B) the REG-REQ to the AMF 530 serving the S-NSSAI through an N2 message. Then, the UE 510 and the AMF 530 establish (504B) the AMF context specific to the network slice. It is noted that although it is not directly illustrating that UDM 540 involves in the process, the UDM 540 plays a crucial role in the overall process by triggering the AMF 530 to transmit the network public key to the UE 510 in the earlier phase (as illustrated in signaling flow 500A) for isolated network slices.
[0132] The random access procedure, particularly during the initial access phase, may be jammed, sniffed, or spoofed, and critical messages such as Msg 3, Msg 5, and NAS messages are transmitted in plaintext, making them susceptible to attacks. Additionally, user plane headers and the MAC layer are unprotected, allowing for potential side-channel attacks.
[0133] FIG. 6A illustrates a schematic diagram of an example attack scenario 600A between a UE 610 and a gNB 620. The gNB 620 may be a malicious gNB. In the attack scenario 600A, the malicious gNB 620 attempts to disrupt the modem of the UE 610. The main attack occurs at step 3, the malformed radio link control (RLC) status PDU is misinterpreted as a transmission configuration indicator (TCI) state switching media access control (MAC) control element (CE) , which leads to the rebooting of the modem of the UE 610. FIG. 6B illustrates a schematic diagram of an example attack scenario 600B between the UE 610 and the gNB 620. The gNB 620 may be a malicious gNB. The main attack occurs at step 2, the malicious gNB 620 transmits a malformed RRC connection setup message to the UE 610. After the UE 610 transmits the RRC setup complete (in two fragments) , the integrity of the communication process may be disrupted. The fake DL NAS message may be part of a downgrade attack. It interrupts the NAS authentication process by injecting an authentication failure, which disables the 5G access of the UE 610.
[0134] Depending on the state of UE, the RRC connection may have different scenarios. FIG. 7 illustrates a schematic diagram 700 of example scenarios during RRC connection establishment. In the scenario 701, a UE 710 is in the idle state, and is establishing the RRC connection for the first time. There is no UE context in the UE 710, the RAN 720, and the AMF 730, and there is no security context in the UE 710 or the AMF 730. In the scenario 702, UE 710 is in the idle state, and is establishing the RRC connection. There is no UE RRC context in the UE 710 and the RAN 720, and there are UE NAS security context in the UE 710 and the AMF 730. In the scenario 703, the UE 710 is in the inactive state, and is resuming RRC connectivity. The UE context is available both in the RAN 720 and the AMF 730. Both AS and NAS security contexts exist in the UE 710 and the AMF 730.
[0135] In accordance with embodiments of the present disclosure, there is provided a solution for message protection in random access procedure, the solution may be appliable to the above scenario 702 and scenario 703, to protect messages in the random access procedure. In a solution, a security key (e.g., a first security key, a second security key) for message protection in a random access procedure is generated, and at least one message associated with the random access procedure is protected with the second security key. Thus, during the random access procedure, the messages (e.g., Msg 3 or Msg 5) associated with the random access procedure are temporarily protected. The Msg 3 or Msg 5 will not share any sensitive information till idle mode security mode command (SMC) is successful, and will share information only when secure keys are available. Furthermore, failure of Msg 3 or Msg 5 security maybe logged and detected as suspicious activity.
[0136] Example embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0137] FIG. 8 illustrates an example signaling flow 800 for message protection in a random access procedure in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the signaling flow 800 will be discussed with reference to FIG. 1. As shown in FIG. 8, the signaling flow 800 involves a first apparatus 110, a second apparatus 120, and a third apparatus 130. In some example embodiments, the first apparatus 110 may include a terminal device (e.g., a UE in FIG. 10) . The second apparatus 120 may include a network device (e.g., a gNB in FIG. 10) . The third apparatus 130 may include a network entity, or a network function (e.g., an AMF or MM in FIG. 10) .
[0138] In some example embodiments, due to some reasons such as power saving, the first apparatus 110 may be in a radio resource control idle state. To transmit or receive data, the first apparatus 110 may establish a new connection with network (e.g., the second apparatus 120) . The first apparatus 110 may listen system information broadcasts from the second apparatus 120.
[0139] In some example embodiments, the system information broadcasts may include an indication that temporary access stratum security is allowed. Based on the received indication, the first apparatus 110 may transmit (801) a trigger to the second apparatus 120, to trigger the second apparatus 120 to obtain a first security key associated with the temporary access stratum security. The trigger may include a key identifier of the first apparatus 110 and a temporary identifier of the first apparatus 110. The second apparatus 120 may receive (802) the trigger from the first apparatus 110.
[0140] Based on the received trigger, the second apparatus 120 may transmit (803) , to the third apparatus 130, a request for the first security key for message protection in the random access procedure. In some example embodiments, the request may include at least one of the key identifier of the first apparatus 110 or the temporary identifier of the first apparatus 110. The third apparatus 130 may receive (804) , from the second apparatus 120, the request for the first security key for message protection in the random access procedure. Then, based on key identifier of the first apparatus 110 and a temporary key, the third apparatus 130 generates (805) the first security key.
[0141] In some example embodiments, the temporary key (denoted as KgNN_TEMP_KEY) may be determined based on a key for an access and mobility management function (denoted as KAMF) . FIG. 9 illustrates a schematic diagram of a process 900 for generating a temporary key in accordance with some example embodiments of the present disclosure. The KgNB_TEMP_KEY is generated from KAMF using string “RRC IDLE MODE” . As illustrated in FIG. 9, KgNB_TEMP_KEY is generated with a key derivation function (KDF) based on two inputs KAMF and SUPI (subscription permanent identifier) . It is noted that during authentication and NAS security mode command procedure, the security anchor function (SEAF) may generate the KAMF, from SEAF key. KAMF may be stored in the third apparatus 130.
[0142] Then, the third apparatus 130 transmits (806) the generated first security key to the second apparatus 120. The second apparatus 120 receives (807) the first security key from the third apparatus 130. With the received first security key, the second apparatus 120 transmits (808) information indicative of a setup of the first security key to the first apparatus 110. The first apparatus 110 receives (809) the information indicative of the setup of the first security key from the second apparatus 120.
[0143] In some example embodiments, the first apparatus 110 generates (810) a second security key for message protection in the random access procedure. For example, the first apparatus 110 may generate the second security key based on its key identifier and KgNB_TEMP_KEY which is determined based on the local KAMF of the first apparatus 110.
[0144] Although it is illustrated in FIG. 8 that the first apparatus 110 generates the second security key after reception of the information indicative of the setup of the first security key, the first apparatus 110 may generate the second security key in any time, regardless of whether the information indicative of the setup of the first security key is received or not. For example, the first apparatus 110 may generate the second security key after reception of the indication in which temporary access stratum security is allowed. For example, in this case, the trigger transmitted to the second apparatus 120 may be protected, encrypted, or ciphered with the second security key.
[0145] In some example embodiments, the first security key and the second security key may have the same value, such that the information and / or message encrypted or ciphered by the one of them may be decrypted or deciphered by the other one of the them. For example, the information indicative of the setup of the first security key may be protected, encrypted, or ciphered by the second apparatus 120 with the first security key. In this case, after receiving the information indicative of the setup of the first security key, the first apparatus 110 may verify the integrity of the information indicative of the setup of the first security key, and decrypt or decipher the information indicative of the setup of the first security key with the second security key.
[0146] In some example embodiments, the first apparatus 110 then transmits (811) at least one first message associated with the random access procedure to the second apparatus 120. The at least one first message are protected with the second security key. The at least one first message may include a request for a radio resource control connection setup, e.g., a RRC setup request. Alternatively, or additionally, the at least one first message may further include a message indicating a complete of the radio resource control connection setup. The second apparatus 120 may receive (812) the at least one first message from the first apparatus 110.
[0147] With the received at least one first message, the second apparatus 120 may transmit at least one second message associated with the random access procedure to the first apparatus 110, as the response. The at least one second message may be protected with the first security key. For example, the at least one second message may include a response to the request for the radio resource control connection setup.
[0148] As an example, the first apparatus 110 may transmit a RRC setup request in SRB1 to the second apparatus 120. When the second apparatus 120 receives the RRC setup request, it may first perform admission control to determine whether to accept the request based on factors such as available resources and network load. Then, the second apparatus 120 may configure the necessary radio resources for the first apparatus 110, and transmit a RRC setup message as a response to the first apparatus 110. For example, the RRC Setup message may include configuration information such as the dedicated radio bearer setting, timing advance command, etc. Upon receiving the RRC Setup message, the first apparatus 110 may parse the configuration information, and update its internal configuration. Then, the first apparatus 110 may transmit a RRC setup complete message to the second apparatus 120. The RRC setup complete message serves as an acknowledgment to the second apparatus 120, indicating that the first apparatus 110 has successfully established the RRC connection and is ready for further communication.
[0149] In some example embodiments, after the AS security mode command procedure is executed, and AS keys (e.g., RRC key, or UP key) are generated, the first apparatus 110 may delete or discard the second security key, and the second apparatus 120 may delete or discard the first security key.
[0150] In some example embodiments, for different random access procedures, the security key used may be different. For example, when the first apparatus 110 transitions back to the idle state due to some reasons, it effectively disconnects from the second apparatus 120 and ceases active communication. Subsequently, when the first apparatus 110 needs to re-establish an RRC connection with the second apparatus 120 due to various reasons such as initiating a new data session, responding to network paging, or moving to a new cell, it may undergo a new random access procedure. For this new random access procedure, a new first security key and a new second security key are generated, to protect messages associated with the new random access procedure.
[0151] FIG. 10 illustrates an example signaling flow 1000 for random access procedure in accordance with some example embodiments of the present disclosure. As shown in FIG. 10, the signaling flow 1000 involves a UE 1010, a gNB 1020, and a MM 1030. In some example embodiments, the UE 1010 may be an example of the first apparatus 110, the gNB 1020 may be an example of the second apparatus 120, and the MM 1030 may be an example of the third apparatus 130. The example embodiments illustrated in FIG. 10 is an implementation of the signaling flow 800 illustrated in FIG. 8. It should be understood that the steps shown in FIG. 10 is merely illustrative and not restrictive.
[0152] At the beginning, the UE 1010 is registered (1001) to the MM 1030, and is in the connected state. In this case, a temporary key, e.g., KgNB_TEMP_KEY is provisioned (1002) in the UE 1010 and the MM 1030. When there is no ongoing data transmission or service request from the user for a certain period, the UE 1010 may transition to the idle state to conserve power. When the UE 1010 has data to transmit or receive, it may need to establish a new connection with the network, and the UE 1010 will start (1003) a connection setup process.
[0153] The UE 1010 may listen system information broadcasts from the gNB 1020. For example, the UE 1010 may receive (1004) MIB from the gNB 1020. The MIB may include basic system parameters such as system bandwidth and physical downlink control channel (PDCCH) configuration information, etc. The UE 1010 may further receive (1005) SIB1 from the gNB 1020. The SIB1 may include more critical information about network access, such as whether the gNB 1020 allows the UE 1010 access, the RACH configuration, etc. Based on the SIB1, the UE 1010 may transmit (1006) a message (Msg 1) which includes a RACH preamble to the gNB 1020. Based on the SIB1 and the timing information of the Msg 1, the gNB 1020 may transmit (1007) a message (Msg 2) which include a RACH response to the UE 1010.
[0154] In some example embodiments, the SIB1 may include an indication indicating that temporary AS security is allowed. Based on the indication, the UE 1010 may decide to trigger (1008) temporary AS security for initial access. Then, a temporary AS security activation may be started (1009) . During the temporary AS security activation, the UE 1010 may transmit (1011) , to the gNB 1020, a message (Msg 3a) which includes a RRC security setup request in SRB0, to trigger the gNB 1020 to obtain a first security key associated with the temporary AS security. In some example embodiments, the RRC security setup request may include a temporary identifier UE_TEMP_ID and a key identifier UE_KEY_ID of the UE 1010. Examples of the RRC security setup request may be as follows. RRCSecurityRequest The RRCSecurityRequest message is used to request the establishment of temporary security of RRC request. Signalling radio bearer: SRB0 RLC-SAP: TM Logical channel: CCCH Direction: UE to Network RRCSecurityRequest message RRCSecurity-6G The RRCSecurity-6G message is used to establish SRB1 with temporary AS security. Signalling radio bearer: SRB0 RLC-SAP: TM Logical channel: CCCH Direction: Network to UE RRCSetup message
[0155] The gNB 1020 may receive the RRC security setup request from UE 1010. Then, the gNB 1020 may transmit (1012) , to the MM 1030, a request for the first security key associated with the temporary AS security. The request includes the temporary identifier UE_TEMP_ID and the key identifier UE_KEY_ID of the UE 1010. The MM 1030 may receive the request for the first security key associated with the temporary AS security from the gNB 1020. The MM 1030 may generate (1013) the first security key based on key identifier UE_KEY_ID of the UE 1010 and KgNB_TEMP_KEY.
[0156] Subsequently, the MM 1030 transmits (1014) the first security key to gNB 1020. Upon receiving the first security key, the gNB 1020 transmits (1015) , to the UE 1010, a message (Msg 4a) which includes RRC security setup response in SRB1, indicating successful setup of the first security key. The UE 1010 generates (1016) a second security key based on the key identifier UE_KEY_ID and KgNB_TEMP_KEY. It is noted that the second security key is generated locally and is not transmitted over the air interface. The UE 1010 may further check (1017) integrity of the Msg 4a and decipher the Msg 4a.
[0157] Based on the generated second security key, the temporary AS security may be activated (1009) . For example, the UE 1010 may protect and / or cipher a message (Msg 3b) which include a RRC setup request. Then, the UE 1010 transmits (1019) the protected and / or ciphered Msg 3b to the gNB 1020. The gNB 1020 may then transmit (1021) , to the UE 1010, a message (Msg 4b) which include a RRC setup response and protected and / or ciphered with the first security key. Upon receiving the Msg 4, the UE 1010 may transmit (1022) , to the gNB 1020, a message (Msg 5) which indicates complete of the radio resource control connection setup and protected and / or ciphered with the second security key.
[0158] By protecting the corresponding massages (e.g., Msg 3b, Msg 4b, or Msg 5) , the messages protected by security keys are less likely to be tampered with during transmission, confidentiality and integrity of the exchanged messages may be ensured, ensuring that the information received by the gNB or UE is the same as what was transmitted, and preventing unauthorized entities from intercepting or tampering with sensitive data.
[0159] FIG. 11 illustrates an example signaling flow 1100 for message protection in a random access procedure in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the signaling flow 1100 will be discussed with reference to FIG. 1. As shown in FIG. 11, the signaling flow 1100 involves the first apparatus 110, the second apparatus 120, and the third apparatus 130. In some example embodiments, the first apparatus 110 may include a terminal device (e.g., a UE) . The second apparatus 120 may include a network device (e.g., a gNB) . The third apparatus 130 may include a network entity, or a network function (e.g., an AMF or MM) .
[0160] In some example embodiments, due to some reasons such as power saving, the first apparatus 110 may be in a radio resource control idle state. When there is a need to transmit or receive data, the first apparatus 110 may establish a new connection with the second apparatus 120.
[0161] The first apparatus 110 may transmit (1101) , to the second apparatus 120, a request for information indicative of a parameter associated with a first security key for message protection in a random access procedure. In some example embodiments, the parameter may include a random value. The request may include a temporary identifier of the first apparatus 110 and a cause of security. For example, the temporary identifier may include temporary mobile subscriber identity (TMSI) , or 6G specific temporary mobile subscriber identity (6G S-TMSI) of the first apparatus 110. It is noted that before the first apparatus 110 transitions to the idle state, the temporary identifier with AMF level identifier may be shared with the first apparatus 110 and the third apparatus 130.
[0162] In some example embodiments, the second apparatus 120 may receive (1102) the request for information indicative of the parameter from the first apparatus 110, and know that it needs to obtain the first security key for message protection in the random access procedure. Then, the second apparatus 120 may transmit (1103) a request for the first security key to the third apparatus 130. The request may include a temporary identifier (e.g., TMSI) of the first apparatus 110, to cause the third apparatus 130 to obtain the right context of the first apparatus 110 based on the temporary identifier. The third apparatus 130 may receive (1104) the request for the first security key from the second apparatus 120.
[0163] The third apparatus 130 may generate the parameter. Then, the third apparatus 130 and generates (1105) the first security key at least based on the generated parameter. In some example embodiments, for example, the third apparatus 130 may generate first security key based on the parameter and KAMF. Then, the third apparatus 130 transmits (1106) the generated parameter and the generated first security key to the second apparatus 120. The second apparatus 120 receives (1107) the parameter and the first security key from the third apparatus 130.
[0164] In some further example embodiments, the parameter may be generated by the second apparatus 120. In this case, the request for the first security key may include the parameter, such that the third apparatus 130 may receive the parameter from the second apparatus 120. Then, the third apparatus 130 may generate the first security key based on the received parameter and KAMF. In this case, the third apparatus 130 may merely transmit the generated first security key to the second apparatus 120. The second apparatus 120 may receive the first security key from the third apparatus 130.
[0165] Then, the second apparatus 120 transmits (1108) the information indicative of the parameter to the first apparatus 110. The first apparatus 110 receives (1109) the information indicative of the parameter from the second apparatus 120. The first apparatus 110 then generates (1110) a second security key for the message protection in the random access procedure at least based on the parameter. In some example embodiments, for example, the first apparatus 110 may generate second security key based on the parameter and KAMF.
[0166] In some example embodiments, the first security key and the second security key may have the same value, such that the information and / or message encrypted or ciphered by the one of them may be decrypted or deciphered by the other one of the them. The first apparatus 110 may protect, encrypt or cipher at least one first message associated with the random access procedure with the second security key. Then, the first apparatus 110 transmits (1111) the protected, encrypted or ciphered at least one first message to the second apparatus 120. In some example embodiments, for example, the at least one first message may include a request for a radio resource control connection setup, e.g., a RRC setup request. Alternatively, or additionally, the at least one first message may further include a message indicating a complete of the radio resource control connection setup.
[0167] The second apparatus 120 receives (1112) the at least one first message from the first apparatus 110. As an example, the second apparatus 120 may decrypt or decipher the at least one first message with the first security key. The second apparatus 120 may protect, encrypt or cipher at least one second message associated with the random access procedure with the first security key, and transmit the protected, encrypted or ciphered at least one second message to the first apparatus 110. For example, the at least one second message may include a response to the request for the radio resource control connection setup.
[0168] As an example, the first apparatus 110 may transmit a RRC setup request which is protected with the second security key to the second apparatus 120.
[0169] Then, the second apparatus 120 may transmit a RRC setup message which is protected with the first security key as a response to the first apparatus 110. The first apparatus 110 may transmit a RRC setup complete message which is protected with the second security key to the second apparatus 120.
[0170] In some example embodiments, after the AS security mode command procedure is executed, and AS keys (e.g., RRC key, or UP key) are generated, the first apparatus 110 may delete or discard the second security key, and the second apparatus 120 may delete or discard the first security key.
[0171] In some example embodiments, when the first apparatus 110 transitions back to the idle state due to some reasons, and needs to re-establish an RRC connection with the second apparatus 120. The first apparatus 110 may need to generate a new second security key, and the third apparatus 130 may need to generate a new first security key.
[0172] FIG. 12 illustrates an example signaling flow 1200 for random access procedure in accordance with some example embodiments of the present disclosure. As shown in FIG. 12, the signaling flow 1200 involves a UE 1210, a gNB 1220, and a mobility management network function (MM NF) 1230. In some example embodiments, the UE 1210 may be an example of the first apparatus 110, the gNB 1220 may be an example of the second apparatus 120, and the MM NF 1230 may be an example of the third apparatus 130. The example embodiments illustrated in FIG. 12 is an implementation of the signaling flow 1100 illustrated in FIG. 11. It should be understood that the steps shown in FIG. 12 is merely illustrative and not restrictive.
[0173] The UE 1210 may be registered to the MM NF 1230 as the primary authentication is completed. In this case, the NAS context is available (1201A) in the UE 1210, and the NAS context is available (1201B) in the MM NF 1230. It is noted that there is not RAN UE context available. A UE identifier with AMF level identifier may be shared (1202) with UE 1210 and MM NF 1230. When there is no ongoing data transmission or service request from the user for a certain period, the UE 1210 may transition (1203) to the idle state. When the UE 1210 has data to transmit or receive, it may need to establish a new connection with the network. It is noted that the UE 1210 may establish a new connection with the previous connected gNB 1220, or UE 1210 may establish a new connection with a further gNB, which is not limited in the present disclosure.
[0174] The UE 1210 may then initiate the random access by transmitting (1204) a message (Msg 1) on a physical random access channel (PRACH) . The gNB 1220 then transmits (1205) a message (Msg 2) which includes a RAR to UE 1210, as a response.
[0175] Subsequently, the UE 1210 may transmit (1206) a message (Msg 3a) to the gNB 1220. The Msg 3a may include a RRC setup request and a temporary identifier of UE 1210 (e.g., 6G S-TMSI) . The Msg 3a may further include a cause of security, indicating the gNB 1220 to obtain a first security key associated with the security. The gNB 1220 may then initiate a process to obtain (1207) the first security key associated with the security. For example, the gNB 1220 may transmit (1208A) a request for the first security key to the MM NF 1230.
[0176] Based on the received request from the gNB 1220, the MM NF 1230 generates (1208B) a random value (e.g., a RAND) for the UE 1210, and the first security key (e.g., KgNB-Idle) based on the RAND and KAMF. Then, the MM NF 1230 transmits (1208C) the generated random value and the first security key to the gNB 1220. The gNB 1220 may receive the random value and the first security key from the MM NF 1230, and store (1209) the first security key.
[0177] Subsequently, the gNB 1220 transmits (1210A) a RRC setup message (Msg 4a) protected with the first security key and the random value to the 1210. Upon receiving the RRC Setup message, the UE 1210 generates (1210B) a second security key based on the random value and KAMF.
[0178] Based on the first security key and the second security key, a temporary AS security activation may be triggered. Then, in SRB1, the UE 1210 transmits (1210C) a message (Msg 3b) protected and / or ciphered with the second security key to the gNB 1220. For example, the Msg 3b may include a RRC setup request. The gNB 1220 may transmit (1211) a message (Msg 4b) protected and / or ciphered with the first security key to the UE 1210. For example, the Msg 4b may include a RRC setup response, which includes corresponding configuration protected and / or ciphered with the first security key. The UE 1210 may then transmit (1212) , to the gNB 1220, a message (Msg 5) which indicates complete of the radio resource control connection setup. For example, the Msg 5 may include the NAS content protected and / or ciphered with the second security key. The gNB 1220 may receive the NAS content, and decipher (1213) it with the first security key. Then, the gNB 1220 may forward the deciphered NAS content to the MM NF 1230. Finally, the RRC connection between the UE 1210 and the gNB 1220 may be established (1214) .
[0179] By protecting the corresponding massages (e.g., Msg 3b, Msg 4b, or Msg 5) , confidentiality and integrity of the exchanged messages may be ensured, preventing unauthorized entities from intercepting or tampering with sensitive data.
[0180] FIG. 13 illustrates an example signaling flow 1300 for random access procedure in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the signaling flow 1300 will be discussed with reference to FIG. 1. As shown in FIG. 13, the signaling flow 1300 involves the first apparatus 110, and the second apparatus 120. In some example embodiments, the first apparatus 110 may include a terminal device (e.g., a UE) . The second apparatus 120 may include a network device (e.g., a gNB) .
[0181] The first apparatus 110 may be in the RRC inactive state, and due to some reasons such as transmitting a message, or making a call, the first apparatus 110 needs to transition to the connected state, i.e., resuming the connection with the second apparatus 120. The first apparatus 110 transmits (1301) , to the second apparatus 120, a request for resuming a connection with the device with a cause of security. In some example embodiments, a key for security may be shared by the first apparatus 110 and the second apparatus 120. For example, during previous connection with the second apparatus 120, both the first apparatus 110 and the second apparatus 120 may have the key in the context of the first apparatus 110.
[0182] The second apparatus 120 receives (1302) the request from the first apparatus 110. The second apparatus 120 transmits (1303) a response protected with key to the first apparatus 110. The first apparatus 110 receives (1304) the response from the second apparatus 120. For example, the first apparatus 110 may de decrypt or decipher the content included in the response, and transmit a message which indicates complete of resuming the connection with the second apparatus 120 and protected with the key to the second apparatus 120.
[0183] During the transition of RRC inactive state to the RRC connected state, by protecting the relevant interactive messages, confidentiality of the exchanged information may be ensured, preventing unauthorized entities from intercepting or understanding sensitive data.
[0184] FIG. 14 illustrates an example signaling flow 1400 for random access procedure in accordance with some example embodiments of the present disclosure. As shown in FIG. 14, the signaling flow 1400 involves a UE 1410 and a gNB 1420. In some example embodiments, the UE 1410 may be an example of the first apparatus 110, the gNB 1420 may be an example of the second apparatus 120. The example embodiments illustrated in FIG. 14 is an implementation of the signaling flow 1300 illustrated in FIG. 13. It should be understood that this is merely illustrative and not restrictive.
[0185] The UE 1410 is in the RRC inactive state (1401) , where it is not actively transmitting but retains the RRC and / or UE AS context and maintains control plane connection with the gNB 1420. Then, due to a UE-triggered event such as making a call, the UE 1410 transitions from RRC inactive state to RRC connected state.
[0186] For example, the UE 1410 transmits (1402) a message which includes a RRC resume request to the gNB 1420. In some example embodiments, the message may further include the identifier of the UE 1410, e.g., cell radio network temporary identifier (C-RNTI) , and a cause for resume (e.g., security) . The gNB 1420 may validate the resume request. Then, the gNB 1420 transmits (1403) a RRC resume response to the UE 1410. The RRC resume response may include RRC resume configuration which is protected with the key. Then, the UE 1410 may transmit (1404) a RRC resume complete message to the gNB 1420, as acknowledgment of complete of resuming the connection with the gNB 1420.
[0187] FIG. 15A shows a flowchart of an example method 1500A implemented at an apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1500A will be described from the perspective of the first apparatus 110 in FIG. 1.
[0188] At block 1510, the first apparatus 110 receives, from a device, information indicative of a setup of a first security key for message protection in a random access procedure, wherein the first security key is at least generated based on a temporary key.
[0189] At block 1520, the first apparatus 110 generates, at least based on the temporary key, a second security key for message protection in the random access procedure.
[0190] At block 1530, the first apparatus 110 transmits, to the device, at least one first message associated with the random access procedure and protected with the second security key.
[0191] By generating the corresponding security key and protecting the messages corresponding in the random access procedure, the messages protected by security keys may be less likely to be tampered with during transmission, confidentiality and integrity of the exchanged messages may be ensured.
[0192] In some example embodiments, the method 1500A may further include: generating the second security key based on a key identifier of the apparatus and the temporary key. In this case, the security key generated at both first and second apparatus sides may be consistent with each other.
[0193] In some example embodiments, the method 1500A may further include: receiving, from the device, an indication in which temporary access stratum security is allowed; and transmitting, to the device, a trigger to obtain, from a network entity, the first security key associated with the temporary access stratum security, the trigger comprising a key identifier of the apparatus and a temporary identifier of the apparatus. In this way, by allowing the temporary access stratum security, robustness of the security may be improved.
[0194] In some example embodiments, the network entity may include a device implementing mobility management.
[0195] In some example embodiments, the method 1500A may further include: receiving, from the device, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key. In this way, the message (s) from the second apparatus may further be protected, the security of the random access procedure may be further enhanced.
[0196] In some example embodiments, the at least one first message may include at least one of: a request for a radio resource control connection setup; or a message indicating a complete of the radio resource control connection setup.
[0197] In some example embodiments, the at least one second message may include a response to the request for the radio resource control connection setup.
[0198] In some example embodiments, the first apparatus 110 may be in a radio resource control idle state.
[0199] In some example embodiments, the first apparatus 110 may include a terminal device, and the device may include a network device.
[0200] FIG. 15B shows a flowchart of an example method 1500B implemented at a device in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1500B will be described from the perspective of the second apparatus 120 in FIG. 1.
[0201] At block 1540, the second apparatus 120 transmits, to an apparatus, information indicative of a setup of a first security key for message protection in a random access procedure, wherein the first security key is at least generated based on a temporary key.
[0202] At block 1550, the second apparatus 120 receives, from the apparatus, at least one first message associated with the random access procedure, the at least one first message being protected with a second security key for the message protection in the random access procedure, the second security key being generated at least based on the temporary key.
[0203] In some example embodiments, the method 1500B may further include: transmitting, to the apparatus, an indication that temporary access stratum security is allowed; and receiving, from the apparatus, a trigger to obtain, from a network entity, the first security key associated with the temporary access stratum security, the trigger comprising a key identifier of the apparatus and a temporary identifier of the apparatus.
[0204] In some example embodiments, the method 1500B may further include: transmitting, to the apparatus, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key.
[0205] In some example embodiments, the method 1500B may further include: transmitting, to a network entity, a request for the first security key, the request comprising at least one of a key identifier of the apparatus or a temporary identifier of the apparatus; and receiving, from the network entity, the first security key. In this way, by transmitting the request to the network entity to generate the security key, efficiency of generating the security key may be improved.
[0206] In some example embodiments, the network entity may include a device implementing mobility management.
[0207] In some example embodiments, the at least one first message may include at least one of: a request for a radio resource control connection setup; or a message indicating a complete of the radio resource control connection setup.
[0208] In some example embodiments, the at least one second message may include a response to the request for the radio resource control connection setup.
[0209] In some example embodiments, the apparatus may include a terminal device, and the second apparatus 120 may include a network device.
[0210] FIG. 15C shows a flowchart of an example method 1500C implemented at a network entity in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1500C will be described from the perspective of the third apparatus 130 in FIG. 1.
[0211] At block 1560, the third apparatus 130 receives, from a device, a request for a security key for message protection in a random access procedure.
[0212] At block 1570, the third apparatus 130 generates the security key at least based on a temporary key.
[0213] At block 1580, the third apparatus 130 transmits the security key to the device.
[0214] In some example embodiments, the request may include at least one of a key identifier of an apparatus or a temporary identifier of the apparatus.
[0215] In some example embodiments, the apparatus may include a terminal device.
[0216] In some example embodiments, the method 1500C may further include: generating the security key based on the temporary key and the key identifier of the apparatus.
[0217] In some example embodiments, the third apparatus 130 may include a device implementing mobility management, and the device may include a network device.
[0218] FIG. 16A shows a flowchart of an example method 1600A implemented at an apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1600A will be described from the perspective of the first apparatus 110 in FIG. 1.
[0219] At block 1610, the first apparatus 110 receives, from a device, information indicative of a parameter associated with a first security key for message protection in a random access procedure.
[0220] At block 1620, the first apparatus 110 generates, at least based on the information indicative of the parameter, a second security key for the message protection in the random access procedure.
[0221] At block 1630, the first apparatus 110 transmits, to the device, at least one first message associated with the random access procedure, and protected with the second security key.
[0222] By generating the corresponding security key and protecting the messages corresponding in the random access procedure, the messages protected by security keys may be less likely to be tampered with during transmission, confidentiality and integrity of the exchanged messages may be ensured.
[0223] In some example embodiments, the method 1600A may further include: transmitting, to the device, a request for the information indicative of the parameter, the request comprising a temporary identifier of the apparatus and a cause of security. In this way, by including a cause of security in the request, robustness of the security may be improved.
[0224] In some example embodiments, the method 1600A may further include: generating the second security key based on the parameter and a key for an access and mobility management function. In this case, the security key generated at both first and second apparatus sides may be consistent with each other.
[0225] In some example embodiments, the method 1600A may further include: receiving, from the device, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key. In this way, the message (s) from the device may further be protected, the security of the random access procedure may be further enhanced.
[0226] In some example embodiments, the parameter may include a random value.
[0227] In some example embodiments, the parameter may be generated at the device or a network entity.
[0228] In some example embodiments, the network entity may include a device implementing mobility management.
[0229] In some example embodiments, the at least one first message may include at least one of: a request for a radio resource control connection setup; or a message indicating a complete of the radio resource control connection setup.
[0230] In some example embodiments, the at least one second message may include a response to the request for the radio resource control connection setup.
[0231] In some example embodiments, the first apparatus 110 may be in a radio resource control idle state.
[0232] In some example embodiments, the first apparatus 110 may include a terminal device, and the device may include a network device.
[0233] FIG. 16B shows a flowchart of an example method 1600B implemented at a device in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1600B will be described from the perspective of the second apparatus 120 in FIG. 1.
[0234] At block 1640, the second apparatus 120 transmits, to an apparatus, information indicative of a parameter associated with a first security key for message protection in a random access procedure.
[0235] At block 1650, the second apparatus 120 receives, from the apparatus, at least one first message associated with the random access procedure, the at least one first message being protected with a second security key, and the second security key being generated at least based on the information indicative of the parameter.
[0236] In some example embodiments, the method 1600B may further include: receiving, from the apparatus, a request for the information indicative of the parameter, the request comprising a temporary identifier of the apparatus and a cause of security. In this way, efficiency of generating the security key may be improved.
[0237] In some example embodiments, the method 1600B may further include: transmitting, to the apparatus, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key. In this way, the message (s) from the device may further be protected, the security of the random access procedure may be further enhanced.
[0238] In some example embodiments, the method 1600B may further include: transmitting, to a network entity, a request for the first security key; and receiving, from the network entity, at least one of the first security key or the parameter.
[0239] In some example embodiments, the network entity may include a device implementing mobility management.
[0240] In some example embodiments, the at least one first message may include at least one of: a request for a radio resource control connection setup; or a message indicating a complete of the radio resource control connection setup.
[0241] In some example embodiments, the at least one second message may include a response to the request for the radio resource control connection setup.
[0242] In some example embodiments, the apparatus may include a terminal device, and the second apparatus 120 may include a network device.
[0243] FIG. 16C shows a flowchart of an example method 1600C implemented at a network entity in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1600C will be described from the perspective of the third apparatus 130 in FIG. 1.
[0244] At block 1660, the third apparatus 130 receives, from a device, a request for a first security key for message protection in a random access procedure.
[0245] At block 1670, the third apparatus 130 generates the first security key at least based on a parameter associated with the first security key for message protection in the random access procedure.
[0246] At block 1680, the third apparatus 130 transmits, to the device, at least one of the first security key or the parameter.
[0247] In some example embodiments, the parameter may include a random value.
[0248] In some example embodiments, the parameter is generated at the network entity, or wherein the parameter may be generated at the device, and may be comprised in the request for the first security key.
[0249] In some example embodiments, the request may include a temporary identifier of an apparatus.
[0250] In some example embodiments, the apparatus may include a terminal device.
[0251] In some example embodiments, the third apparatus 130 may include a device implementing mobility management, and the device may include a network device.
[0252] FIG. 17A shows a flowchart of an example method 1700A implemented at an apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1700A will be described from the perspective of the first apparatus 110 in FIG. 1.
[0253] At block 1710, the first apparatus 110 transmits, to a device, a request for resuming a connection with the device with a cause of security, wherein the apparatus is in a radio resource control inactive state and a key for security was shared by the apparatus and the device.
[0254] At block 1720, the first apparatus 110 receives, from the device, a response to the request for resuming the connection with the device, the response being protected with the key.
[0255] By protecting the corresponding messages with a key in the procedure of resuming the connection, the procedure may be less likely to be tampered with during transmission, confidentiality and integrity of the exchanged messages may be ensured.
[0256] In some example embodiments, the method 1700A may further include: transmitting, to the device, a message indicating complete of resuming the connection with the device, the message being protected with the key. In this way, the device may clearly know that the connection has been successfully completed, ensuring the consistency of connection status between the two.
[0257] In some example embodiments, the first apparatus 110 may include a terminal device, and the device may include a network device.
[0258] FIG. 17B shows a flowchart of an example method 1700B implemented at a device in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1700B will be described from the perspective of the second apparatus 120 in FIG. 1.
[0259] At block 1730, the second apparatus 120 receives, from an apparatus, a request for resuming a connection with the device with a cause of security, wherein the apparatus is in a radio resource control inactive state and a key for security was shared by the apparatus and the device.
[0260] At block 1740, the second apparatus 120 transmits, to the apparatus, a response to the request for resuming the connection, the response being protected with the key.
[0261] In some example embodiments, the method 1700B may further include: receiving, from the apparatus, a message indicating complete of resuming the connection with the device, the message being protected with the key.
[0262] In some example embodiments, the apparatus may include a terminal device, and the second apparatus 120 may include a network device.
[0263] In some example embodiments, an apparatus capable of performing any of the method 1500A (for example, the first apparatus 110 in FIG. 1) may comprise means for performing the respective operations of the method 1500A. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The apparatus may be implemented as or included in the first apparatus 110 in FIG. 1.
[0264] In some example embodiments, the apparatus includes means for receiving, from a device, information indicative of a setup of a first security key for message protection in a random access procedure, wherein the first security key is at least generated based on a temporary key; means for generating, at least based on the temporary key, a second security key for message protection in the random access procedure; and means for transmitting, to the device, at least one first message associated with the random access procedure and protected with the second security key.
[0265] In some example embodiments, the apparatus may further include: means for generating the second security key based on a key identifier of the apparatus and the temporary key.
[0266] In some example embodiments, the apparatus may further include: means for receiving, from the device, an indication in which temporary access stratum security is allowed; and means for transmitting, to the device, a trigger to obtain, from a network entity, the first security key associated with the temporary access stratum security, the trigger comprising a key identifier of the apparatus and a temporary identifier of the apparatus.
[0267] In some example embodiments, the network entity may include a device implementing mobility management.
[0268] In some example embodiments, the apparatus may further include: means for receiving, from the device, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key.
[0269] In some example embodiments, the at least one first message may include at least one of: a request for a radio resource control connection setup; or a message indicating a complete of the radio resource control connection setup.
[0270] In some example embodiments, the at least one second message may include a response to the request for the radio resource control connection setup.
[0271] In some example embodiments, the first apparatus 110 may be in a radio resource control idle state.
[0272] In some example embodiments, the first apparatus 110 may include a terminal device, and the device may include a network device.
[0273] In some example embodiments, a device capable of performing any of the method 1500B (for example, the second apparatus 120 in FIG. 1) may comprise means for performing the respective operations of the method 1500B. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The device may be implemented as or included in the second apparatus 120 in FIG. 1.
[0274] In some example embodiments, the device may include means for transmitting, to an apparatus, information indicative of a setup of a first security key for message protection in a random access procedure, wherein the first security key is at least generated based on a temporary key; and means for receiving, from the apparatus, at least one first message associated with the random access procedure, the at least one first message being protected with a second security key for the message protection in the random access procedure, the second security key being generated at least based on the temporary key.
[0275] In some example embodiments, the device may further include: means for transmitting, to the apparatus, an indication that temporary access stratum security is allowed; and means for receiving, from the apparatus, a trigger to obtain, from a network entity, the first security key associated with the temporary access stratum security, the trigger comprising a key identifier of the apparatus and a temporary identifier of the apparatus.
[0276] In some example embodiments, the device may further include: means for transmitting, to the apparatus, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key.
[0277] In some example embodiments, the device may further include: means for transmitting, to a network entity, a request for the first security key, the request comprising at least one of a key identifier of the apparatus or a temporary identifier of the apparatus; and means for receiving, from the network entity, the first security key.
[0278] In some example embodiments, the network entity may include a device implementing mobility management.
[0279] In some example embodiments, the at least one first message may include at least one of: a request for a radio resource control connection setup; or a message indicating a complete of the radio resource control connection setup.
[0280] In some example embodiments, the at least one second message may include a response to the request for the radio resource control connection setup.
[0281] In some example embodiments, the first apparatus 110 may include a terminal device, and the device may include a network device.
[0282] In some example embodiments, a network entity capable of performing any of the method 1500C (for example, the third apparatus 130 in FIG. 1) may comprise means for performing the respective operations of the method 1500C. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The network entity may be implemented as or included in the network entity 110 in FIG. 1.
[0283] In some example embodiments, the network entity may include means for receiving, from a device, a request for a security key for message protection in a random access procedure; means for generating the security key at least based on a temporary key; and means for transmitting the security key to the device.
[0284] In some example embodiments, the request may include at least one of a key identifier of an apparatus or a temporary identifier of the apparatus.
[0285] In some example embodiments, the first apparatus 110 may include a terminal device.
[0286] In some example embodiments, the network entity may further include: means for generating the security key based on the temporary key and the key identifier of the apparatus.
[0287] In some example embodiments, the network entity may include a device implementing mobility management, and the device may include a network device.
[0288] In some example embodiments, an apparatus capable of performing any of the method 1600A (for example, the first apparatus 110 in FIG. 1) may comprise means for performing the respective operations of the method 1600A. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The apparatus may be implemented as or included in the first apparatus 110 in FIG. 1.
[0289] In some example embodiments, the apparatus may include means for receiving, from a device, information indicative of a parameter associated with a first security key for message protection in a random access procedure; means for generating, at least based on the information indicative of the parameter, a second security key for the message protection in the random access procedure; and means for transmitting, to the device, at least one first message associated with the random access procedure, and protected with the second security key.
[0290] In some example embodiments, the apparatus may further include: means for transmitting, to the device, a request for the information indicative of the parameter, the request comprising a temporary identifier of the apparatus and a cause of security.
[0291] In some example embodiments, the apparatus may further include: means for generating the second security key based on the parameter and a key for an access and mobility management function.
[0292] In some example embodiments, the apparatus may further include: means for receiving, from the device, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key.
[0293] In some example embodiments, the parameter may include a random value.
[0294] In some example embodiments, the parameter may be generated at the device or a network entity.
[0295] In some example embodiments, the network entity may include a device implementing mobility management.
[0296] In some example embodiments, the at least one first message may include at least one of: a request for a radio resource control connection setup; or a message indicating a complete of the radio resource control connection setup.
[0297] In some example embodiments, the at least one second message may include a response to the request for the radio resource control connection setup.
[0298] In some example embodiments, the first apparatus 110 may be in a radio resource control idle state.
[0299] In some example embodiments, the apparatus comprises a terminal device, and the device comprises a network device.
[0300] In some example embodiments, a device capable of performing any of the method 1600B (for example, the second apparatus 120 in FIG. 1) may comprise means for performing the respective operations of the method 1600B. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The device may be implemented as or included in the second apparatus 120 in FIG. 1.
[0301] In some example embodiments, the device comprises means for transmitting, to an apparatus, information indicative of a parameter associated with a first security key for message protection in a random access procedure; and means for receiving, from the apparatus, at least one first message associated with the random access procedure, the at least one first message being protected with a second security key, and the second security key being generated at least based on the information indicative of the parameter.
[0302] In some example embodiments, the device may further include: means for receiving, from the apparatus, a request for the information indicative of the parameter, the request comprising a temporary identifier of the apparatus and a cause of security.
[0303] In some example embodiments, the device may further include: means for transmitting, to the apparatus, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key.
[0304] In some example embodiments, the device may further include: means for transmitting, to a network entity, a request for the first security key; and means for receiving, from the network entity, at least one of the first security key or the parameter.
[0305] In some example embodiments, the network entity may include a device implementing mobility management.
[0306] In some example embodiments, the at least one first message may include at least one of: a request for a radio resource control connection setup; or a message indicating a complete of the radio resource control connection setup.
[0307] In some example embodiments, the at least one second message may include a response to the request for the radio resource control connection setup.
[0308] In some example embodiments, the apparatus comprises a terminal device, and the device comprises a network device.
[0309] In some example embodiments, a network entity capable of performing any of the method 1600C (for example, the third apparatus 130 in FIG. 1) may comprise means for performing the respective operations of the method 1600C. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The network entity may be implemented as or included in the network entity 110 in FIG. 1.
[0310] In some example embodiments, the network entity comprises means for receiving, from a device, a request for a first security key for message protection in a random access procedure; means for generating the first security key at least based on a parameter associated with the first security key for message protection in the random access procedure; and means for transmitting, to the device, at least one of the first security key or the parameter.
[0311] In some example embodiments, the parameter may include a random value.
[0312] In some example embodiments, the parameter is generated at the network entity, or wherein the parameter may be generated at the device, and may be comprised in the request for the first security key.
[0313] In some example embodiments, the request may include a temporary identifier of an apparatus.
[0314] In some example embodiments, the apparatus comprises a terminal device.
[0315] In some example embodiments, the network entity may include a device implementing mobility management, and the device may include a network device.
[0316] In some example embodiments, an apparatus capable of performing any of the method 1700A (for example, the first apparatus 110 in FIG. 1) may comprise means for performing the respective operations of the method 1700A. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The apparatus may be implemented as or included in the first apparatus 110 in FIG. 1.
[0317] In some example embodiments, the apparatus comprises means for transmitting, to a device, a request for resuming a connection with the device with a cause of security, wherein the apparatus is in a radio resource control inactive state and a key for security was shared by the apparatus and the device; and means for receiving, from the device, a response to the request for resuming the connection with the device, the response being protected with the key.
[0318] In some example embodiments, the apparatus may further include: means for transmitting, to the device, a message indicating complete of resuming the connection with the device, the message being protected with the key.
[0319] In some example embodiments, the apparatus may include a terminal device, and the device may include a network device.
[0320] In some example embodiments, a device capable of performing any of the method 1700B (for example, the second apparatus 120 in FIG. 1) may comprise means for performing the respective operations of the method 1700B. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The device may be implemented as or included in the second apparatus 120 in FIG. 1.
[0321] In some example embodiments, the device comprises means for receiving, from an apparatus, a request for resuming a connection with the device with a cause of security, wherein the apparatus is in a radio resource control inactive state and a key for security was shared by the apparatus and the device; and means for transmitting, to the apparatus, a response to the request for resuming the connection, the response being protected with the key.
[0322] In some example embodiments, the device may further include: means for receiving, from the apparatus, a message indicating complete of resuming the connection with the device, the message being protected with the key.
[0323] In some example embodiments, the apparatus may include a terminal device, and the device may include a network device.
[0324] FIG. 18 is a simplified block diagram of a device 1800 that is suitable for implementing example embodiments of the present disclosure. The device 1800 may be provided to implement a communication device, for example, the terminal device 110 or the network device 120 as shown in FIG. 1. As shown, the device 1800 includes one or more processors 1810, one or more memories 1820 coupled to the processor 1810, and one or more communication modules 1840 coupled to the processor 1810.
[0325] The communication module 1840 is for bidirectional communications. The communication module 1840 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interfaces may represent any interface that is necessary for communication with other network elements. In some example embodiments, the communication module 1840 may include at least one antenna.
[0326] The processor 1810 may be of any type suitable to the local technical network and may include one or more of the following: general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 1800 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.
[0327] The memory 1820 may include one or more non-volatile memories and one or more volatile memories. Examples of the non-volatile memories include, but are not limited to, a Read Only Memory (ROM) 1824, an electrically programmable read only memory (EPROM) , a flash memory, a hard disk, a compact disc (CD) , a digital video disk (DVD) , an optical disk, a laser disk, and other magnetic storage and / or optical storage. Examples of the volatile memories include, but are not limited to, a random-access memory (RAM) 1822 and other volatile memories that will not last in the power-down duration.
[0328] A computer program 1830 includes computer executable instructions that are executed by the associated processor 1810. The instructions of the program 1830 may include instructions for performing operations / acts of some example embodiments of the present disclosure. The program 1830 may be stored in the memory, e.g., the ROM 1824. The processor 1810 may perform any suitable actions and processing by loading the program 1830 into the RAM 1822.
[0329] The example embodiments of the present disclosure may be implemented by means of the program 1830 so that the device 1800 may perform any process of the disclosure as discussed with reference to FIG. 8 to FIG. 17B. The example embodiments of the present disclosure may also be implemented by hardware or by a combination of software and hardware.
[0330] In some example embodiments, the program 1830 may be tangibly contained in a computer readable medium which may be included in the device 1800 (such as in the memory 1820) or other storage devices that are accessible by the device 1800. The device 1800 may load the program 1830 from the computer readable medium to the RAM 1822 for execution. In some example embodiments, the computer readable medium may include any types of non-transitory storage medium, such as ROM, EPROM, a flash memory, a hard disk, CD, DVD, and the like. The term “non-transitory, ” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM) .
[0331] FIG. 19 shows an example of the computer readable medium 1900 which may be in form of CD, DVD or other optical storage disk. The computer readable medium 1900 has the program 1830 stored thereon.
[0332] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, and other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. Although various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representations, it is to be understood that the block, apparatus, system, technique or method described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[0333] Some example embodiments of the present disclosure also provide at least one computer program product tangibly stored on a computer readable medium, such as a non-transitory computer readable medium. The computer program product includes computer-executable instructions, such as those included in program modules, being executed in a device on a target physical or virtual processor, to carry out any of the methods as described above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.
[0334] Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general-purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program code, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0335] In the context of the present disclosure, the computer program code or related data may be carried by any suitable carrier to enable the device, apparatus or processor to perform various processes and operations as described above. Examples of the carrier include a signal, computer readable medium, and the like.
[0336] The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random-access memory (RAM) , a read-only memory (ROM) , an erasable programmable read-only memory (EPROM or Flash memory) , an optical fiber, a portable compact disc read-only memory (CD-ROM) , an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0337] Further, although operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, although several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Unless explicitly stated, certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated, various features that are described in the context of a single embodiment may also be implemented in a plurality of embodiments separately or in any suitable sub-combination.
[0338] Although the present disclosure has been described in languages specific to structural features and / or methodological acts, it is to be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.
Claims
1.An apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:receive, from a device, information indicative of a setup of a first security key for message protection in a random access procedure, wherein the first security key is at least generated based on a temporary key;generate, at least based on the temporary key, a second security key for message protection in the random access procedure; andtransmit, to the device, at least one first message associated with the random access procedure and protected with the second security key.2.The apparatus of claim 1, wherein the temporary key is determined based on a key for an access and mobility management function, and wherein the apparatus is caused to:generate the second security key based on a key identifier of the apparatus and the temporary key.3.The apparatus of claim 1 or 2, wherein the apparatus is caused to:receive, from the device, an indication in which temporary access stratum security is allowed; andtransmit, to the device, a trigger to obtain, from a network entity, the first security key associated with the temporary access stratum security, the trigger comprising a key identifier of the apparatus and a temporary identifier of the apparatus.4.The apparatus of claim 3, wherein the network entity comprises a device implementing mobility management.5.The apparatus of any of claims 1 to 4, wherein the apparatus is caused to:receive, from the device, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key.6.The apparatus of any of claims 1 to 5, wherein the at least one first message comprises at least one of:a request for a radio resource control connection setup; ora message indicating a complete of the radio resource control connection setup.7.The apparatus of claim 6, wherein the at least one second message comprises a response to the request for the radio resource control connection setup.8.The apparatus of any of claims 1 to 7, wherein the apparatus is in a radio resource control idle state.9.The apparatus of any of claims 1 to 8, wherein the apparatus comprises a terminal device, and the device comprises a network device.10.A device comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the device at least to:transmit, to an apparatus, information indicative of a setup of a first security key for message protection in a random access procedure, wherein the first security key is at least generated based on a temporary key; andreceive, from the apparatus, at least one first message associated with the random access procedure, the at least one first message being protected with a second security key for the message protection in the random access procedure, the second security key being generated at least based on the temporary key.11.The device of claim 10, wherein the device is caused to:transmit, to the apparatus, an indication that temporary access stratum security is allowed; andreceive, from the apparatus, a trigger to obtain, from a network entity, the first security key associated with the temporary access stratum security, the trigger comprising a key identifier of the apparatus and a temporary identifier of the apparatus.12.The device of claim 10 or 11, wherein the device is caused to:transmit, to the apparatus, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key.13.The device of any of claims 10 to 12, wherein the device is caused to:transmit, to a network entity, a request for the first security key, the request comprising at least one of a key identifier of the apparatus or a temporary identifier of the apparatus; andreceive, from the network entity, the first security key.14.The device of claim 13, wherein the network entity comprises a device implementing mobility management.15.The device of any of claims 10 to 14, wherein the at least one first message comprises at least one of:a request for a radio resource control connection setup; ora message indicating a complete of the radio resource control connection setup.16.The device of claim 15, wherein the at least one second message comprises a response to the request for the radio resource control connection setup.17.The device of any of claims 10 to 16, wherein the apparatus comprises a terminal device, and the device comprises a network device.18.A network entity comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the network entity at least to:receive, from a device, a request for a security key for message protection in a random access procedure;generate the security key at least based on a temporary key; andtransmit the security key to the device.19.The network entity of claim 18, wherein the request comprises at least one of a key identifier of an apparatus or a temporary identifier of the apparatus.20.The network entity of claim 19, wherein the apparatus comprises a terminal device.21.The network entity of claim 19 or 20, wherein the temporary key is determined based on a key for an access and mobility management function, and wherein the network entity is caused to:generate the security key based on the temporary key and the key identifier of the apparatus.22.The network entity of any of claims 18 to 21, wherein the network entity comprises a device implementing mobility management, and the device comprises a network device.23.An apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:receive, from a device, information indicative of a parameter associated with a first security key for message protection in a random access procedure;generate, at least based on the information indicative of the parameter, a second security key for the message protection in the random access procedure; andtransmit, to the device, at least one first message associated with the random access procedure, and protected with the second security key.24.The apparatus of claim 23, wherein the apparatus is caused to:transmit, to the device, a request for the information indicative of the parameter, the request comprising a temporary identifier of the apparatus and a cause of security.25.The apparatus of claim 23 or 24, wherein the apparatus is caused to:generate the second security key based on the parameter and a key for an access and mobility management function.26.The apparatus of any of claims 23 to 25, wherein the apparatus is caused to:receive, from the device, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key.27.The apparatus of any of claims 23 to 26, wherein the parameter comprises a random value.28.The apparatus of any of claims 23 to 27, wherein the parameter is generated at the device or a network entity.29.The apparatus of claim 28, wherein the network entity comprises a device implementing mobility management.30.The apparatus of any of claims 23 to 29, wherein the at least one first message comprises at least one of:a request for a radio resource control connection setup; ora message indicating a complete of the radio resource control connection setup.31.The apparatus of claim 30, wherein the at least one second message comprises a response to the request for the radio resource control connection setup.32.The apparatus of any of claims 23 to 31, wherein the apparatus is in a radio resource control idle state.33.The apparatus of any of claims 23 to 32, wherein the apparatus comprises a terminal device, and the device comprises a network device.34.A device comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the device at least to:transmit, to an apparatus, information indicative of a parameter associated with a first security key for message protection in a random access procedure; andreceive, from the apparatus, at least one first message associated with the random access procedure, the at least one first message being protected with a second security key, and the second security key being generated at least based on the information indicative of the parameter.35.The device of claim 34, wherein the device is caused to:receive, from the apparatus, a request for the information indicative of the parameter, the request comprising a temporary identifier of the apparatus and a cause of security.36.The device of claim 34 or 35, wherein the device is caused to:transmit, to the apparatus, at least one second message associated with the random access procedure, the at least one second message being protected with the first security key.37.The device of any of claims 34 to 36, wherein the device is caused to:transmit, to a network entity, a request for the first security key; andreceive, from the network entity, at least one of the first security key or the parameter.38.The device of claim 37, wherein the network entity comprises a device implementing mobility management.39.The device of any of claims 34 to 38 wherein the at least one first message comprises at least one of:a request for a radio resource control connection setup; ora message indicating a complete of the radio resource control connection setup.40.The device of claim 39, wherein the at least one second message comprises a response to the request for the radio resource control connection setup.41.The device of any of claims 34 to 40, wherein the apparatus comprises a terminal device, and the device comprises a network device.42.A network entity comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the network entity at least to:receive, from a device, a request for a first security key for message protection in a random access procedure;generate the first security key at least based on a parameter associated with the first security key for message protection in the random access procedure; andtransmit, to the device, at least one of the first security key or the parameter.43.The network entity of claim 42, wherein the parameter comprises a random value.44.The network entity of claim 42 or 43, wherein the parameter is generated at the network entity, orwherein the parameter is generated at the device, and is comprised in the request for the first security key.45.The network entity of any of claims 42 to 44, wherein the request comprises a temporary identifier of an apparatus.46.The network entity of claim 45, wherein the apparatus comprises a terminal device.47.The network entity of any of claims 42 to 46, wherein the network entity comprises a device implementing mobility management, and the device comprises a network device.48.An apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:transmit, to a device, a request for resuming a connection with the device with a cause of security, wherein the apparatus is in a radio resource control inactive state and a key for security was shared by the apparatus and the device; andreceive, from the device, a response to the request for resuming the connection with the device, the response being protected with the key.49.The apparatus of claim 48, wherein the apparatus is caused to:transmit, to the device, a message indicating complete of resuming the connection with the device, the message being protected with the key.50.The apparatus claim 48 or 49, wherein the apparatus comprises a terminal device, and the device comprises a network device.51.A device comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the device at least to:receive, from an apparatus, a request for resuming a connection with the device with a cause of security, wherein the apparatus is in a radio resource control inactive state and a key for security was shared by the apparatus and the device; andtransmit, to the apparatus, a response to the request for resuming the connection, the response being protected with the key.52.The device of claim 48, wherein the device is caused to:receive, from the apparatus, a message indicating complete of resuming the connection with the device, the message being protected with the key.53.The device claim 48 or 49, wherein the apparatus comprises a terminal device, and the device comprises a network device.