Security keys for functional splits in wireless networking architecture
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- NOKIA TECHNOLOGIES OY
- Filing Date
- 2025-12-11
- Publication Date
- 2026-08-06
Smart Images

Figure IMGF000029_0001_TABLE 
Figure 00000040_0000 
Figure 00000041_0000
Abstract
Description
SECURITY KEYS FOR FUNCTIONAL SPLITS IN WIRELESS NETWORKING ARCHITECTURECROSS-REFERENCE TO RELATED APPLICATIONS
[0001] The following applications are related: U.S. Provisional Application having attorney docket no. 335550-US-PSP (44665-547); U.S. Provisional Application having attorney docket no. 335707-US-PSP (44665-545); U.S. Provisional Application having attorney docket no. 335708-US-PSP (44665-546); and U.S. Provisional Application having attorney docket no. 335909-US-PSP (44665-556).FIELD
[0002] Various example embodiments relate to security keys and, more particularly, to security keys for functional splits in wireless networking architecture.BACKGROUND
[0003] Wireless networking provides significant advantages for user mobility. A user’s ability to remain connected while on the move provides advantages not only for the user, but also provides greater efficiency and productivity for society as a whole. As expectations for connection reliability, data speed, and lower power consumption, become more demanding, technology for wireless networking must also keep pace with such expectations. For example, where certain functional splits in wireless networking architecture may be possible, impacts of such functional splits may be considered. Accordingly, there is continuing interest in improving wireless networking technology.SUMMARY
[0004] In aspects of the present disclosure, a method includes: accessing key derivation parameters; generating a first key (KDU) for a distributed unit of a radio access network (RAN) node, where the first key is generated based on a key derivation function and at least some of the key derivation parameters; and generating a second key (KCU-UP) for a user plane of a central unit of the RAN node, where the second key is generated based on the key derivation function and at least some of the key derivation parameters.
[0005] In an aspect, the key derivation parameters include: a key (K§NB) of the RAN node, and a fixed constant value (FC), where the first key (KDU) is generated based on K§NB and FC, and where the second key (KCU-UP) is generated based on KgNB and FC.
[0006] In an aspect, the key derivation parameters further include a string “DU”, and the first key (KDU) is generated further based on the string “DU”.
[0007] In an aspect, the key derivation parameters further include a string “CU-UP”, and the second key (KCU-UP) is generated further based on the string “CU-UP”.
[0008] In an aspect, the key derivation parameters further include an identifier, the first key (KDU) is generated further based on the identifier, and the second key (KCU-UP) is generated further based on the identifier.
[0009] In an aspect, the key derivation parameters further include an identifier of the distributed unit of the RAN node (DU-ID), and the first key (KDU) is generated further based on the DU-ID.
[0010] In an aspect, the key derivation parameters further include an identifier of the user plane of the central unit of the RAN node (CU-UP -ID), and the second key (KCU-UP) is generated further based on the CU-UP -ID.
[0011] In an aspect, the key derivation parameters further include a radio network temporary identifier (RNTI), and the first key (KDU) is generated further based on the RNTI.
[0012] In an aspect, the key derivation parameters further include a radio network temporary identifier (RNTI), and the second key (KCU-UP) is generated further based on the RNTI.
[0013] In an aspect, the key derivation parameters further include a radio resource control user equipment identifier (RRC-UE-ID), and the first key (KDU) is generated further based on the RRC-UE-ID.
[0014] In an aspect, the key derivation parameters further include a user plane user equipment identifier (UP-UE-ID), and the second key (KCU-UP) is generated further based on the UP-UE-ID.
[0015] In an aspect, the method further includes: generating a radio resource control (RRC) integrity key (KRRCint) based on the first key (KDU).
[0016] In an aspect, the method further includes: generating a radio resource control (RRC) encryption key (KRRCenc) based on the first key (KDU).
[0017] In an aspect, the method further includes: generating a user plane (UP) integrity key (Kupint) based on the second key (KCU-UP).
[0018] In an aspect, the method further includes: generating a user plane (UP) encryption key (Kupenc) based on the second key (KCU-UP).
[0019] In aspects of the present disclosure, a method includes: accessing key derivation parameters including: a key (K§NB) of a radio access network (RAN) node, a fixed constantvalue (FC), a first random number, and a second random number; generating a first key (KDU) for a distributed unit of the RAN node, where the first key is generated based on a key derivation function and at least some of the key derivation parameters; and generating a second key (KCU-UP) for a user plane of a central unit of the RAN node, where the second key is generated based on the key derivation function and at least some of the key derivation parameters.
[0020] In an aspect, the first key (KDU) is generated based on KgNB, FC, and the first random number.
[0021] In an aspect, the second key (KCU-UP) is generated based on KgNB, FC, and the second random number.
[0022] In an aspect, the method further includes: receiving the first random number and the second number from a network apparatus.
[0023] In an aspect, the method further includes: generating a third key (target KDU) for a target distributed unit of a handover, the third key generated based on the key derivation function, the first key (KDU), FC, and a third random number.
[0024] In an aspect, the method further includes: receiving the third random number from a network apparatus.
[0025] In an aspect, the method further includes: generating a radio resource control (RRC) integrity key (KRRCint) based on the first key (KDU).
[0026] In an aspect, the method further includes: generating a radio resource control (RRC) encryption key (KRRCenc) based on the first key (KDU).
[0027] In an aspect, the method further includes: generating a user plane (UP) integrity key (Kupint) based on the second key (KCU-UP).
[0028] In an aspect, the method further includes: generating a user plane (UP) encryption key (Kupenc) based on the second key (KCU-UP).
[0029] In aspects of the present disclosure, a method includes: accessing key derivation parameters including: a key (K§NB) of a radio access network (RAN) node, a fixed constant value (FC), a first random number, and a second random number; generating a first key (KDU) for a distributed unit of the RAN node, where the first key is generated based on a key derivation function and at least some of the key derivation parameters; and generating a second key (KCU-UP) for a user plane of a central unit of the RAN node, where the second key is generated based on the key derivation function and at least some of the key derivation parameters.
[0030] In an aspect, the first key (KDU) is generated based on K§NB, FC, and the first random number.
[0031] In an aspect, the second key (KCU-UP) is generated based on K§NB, FC, and the second random number.
[0032] In an aspect, the method further includes: receiving the first random number and the second number from a network apparatus.
[0033] In an aspect, the method further includes: generating a third key (target KDU) for a target distributed unit of a handover, where the third key is generated based on the key derivation function, the first key (KDU), FC, and a third random number.
[0034] In an aspect, the method further includes: receiving the third random number from a network apparatus.
[0035] In an aspect, the method further includes: generating a radio resource control (RRC) integrity key (KRRCint) based on the first key (KDU).
[0036] In an aspect, the method further includes: generating a radio resource control (RRC) encryption key (KRRCenc) based on the first key (KDU).
[0037] In an aspect, the method further includes: generating a user plane (UP) integrity key (Kupint) based on the second key (KCU-UP).
[0038] In an aspect, the method further includes: generating a user plane (UP) encryption key (Kupenc) based on the second key (KCU-UP).
[0039] In aspects of the present disclosure, a method includes: accessing key derivation parameters including: a key (source KDU) of a source distributed unit (DU) of a radio access network (RAN) node, and a fixed constant value (FC), where the source DU is a source of a handover to a target distributed unit (DU) of the RAN node; and generating a key (target KDU) for the target DU of the RAN node, the target KDU generated based on a key derivation function and at least the source KDU and the FC.
[0040] In an aspect, the key derivation parameters further include an identifier of the target DU of the RAN node, and the target KDU is generated further based on the identifier of the target DU of the RAN node.
[0041] In an aspect, the key derivation parameters further include: a string “DU”, and a radio resource control user equipment identifier (RRC-UE-ID), and the target KDU is generated based further on the string “DU” and the RRC-UE-ID.
[0042] In an aspect, the key derivation parameters further include a random number, and the target KDU is generated based further on the random number.
[0043] In an aspect, the method further includes: receiving the random number from a network apparatus.
[0044] In an aspect, the method further includes: incrementing a counter, by a predetermined amount, from a counter value to an incremented counter value. The key derivation parameters further include the incremented counter value, and the target KDU is generated based further on the incremented counter value.
[0045] In an aspect, the source KDU was derived based on the counter value.
[0046] In an aspect, the method further includes: transmitting the incremented counter value to the target DU.
[0047] In an aspect, the method further includes: generating a radio resource control (RRC) integrity key (KRRCint) based on the source KDU.
[0048] In an aspect, the method further includes: generating a radio resource control (RRC) encryption key (KRRCenc) based on the source KDU.
[0049] In an aspect, the method further includes: generating a radio resource control (RRC) integrity key (KRRCint) based on the target KDU.
[0050] In an aspect, the method further includes: generating a radio resource control (RRC) encryption key (KRRCenc) based on the target KDU.
[0051] In an aspect, any one of the preceding methods is performed by a UE.
[0052] In an aspect, any one of the preceding methods is performed by a RAN node.
[0053] In aspects of the present disclosure, an apparatus includes: at least one processor; and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus to perform a method as in any one of preceding methods.
[0054] In aspects of the present disclosure, a non-transitory processor-readable medium stores instructions which, when executed by at least one processor of an apparatus, cause the apparatus to perform a method as in any one of the preceding methods.
[0055] According to some aspects, there is provided the subject matter of the independent claims and of the Examples. Some further aspects are defined in the dependent claims and in the Examples.BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Some example embodiments will now be described with reference to the accompanying drawings.
[0057] FIG. 1 is a diagram of an example embodiment of wireless networking between a network system and a user equipment (UE), according to one illustrated aspect of the disclosure;
[0058] FIG. 2 is a diagram of example components of a network system, according to one illustrated aspect of the disclosure;
[0059] FIG. 3 is a diagram of an example embodiment of a functional split of a wireless network architecture, according to one illustrated aspect of the disclosure;
[0060] FIG. 4 is a diagram of an example embodiment of a key hierarchy of a wireless network, according to one illustrated aspect of the disclosure;
[0061] FIG. 5 is a diagram of example embodiments of input parameters for generating security keys, according to one illustrated aspect of the disclosure;
[0062] FIG. 6 is a diagram of further example embodiments of input parameters for generating security keys, according to one illustrated aspect of the disclosure;
[0063] FIG. 7 is a diagram of an example embodiment of vertical and horizontal key derivation for inter-RAN node handover, according to one illustrated aspect of the disclosure;
[0064] FIG. 8 is a diagram of an example embodiment of vertical and horizontal key derivation for intra-RAN node distributed unit handover, according to one illustrated aspect of the disclosure;
[0065] FIG. 9 is a diagram of example embodiments of input parameters for generating security keys for a target distributed unit, according to one illustrated aspect of the disclosure;
[0066] FIG. 10 is a diagram of an example embodiment of an operation for generating security keys, according to one illustrated aspect of the disclosure; and
[0067] FIG. 11 is a diagram of an example of components of a user equipment or of a network apparatus, according to one illustrated aspect of the present disclosure.DETAILED DESCRIPTION
[0068] The present disclosure relates to security keys for functional splits in wireless networking architecture, such as functional splits between central unit(s) (CU) and distributed unit(s) (DU) in a wireless network architecture. In aspects, a security key (KDU) is generated for a distributed unit (DU) of a radio access network (RAN) node. In aspects, a security key (KCU-UP) is generated for a central unit-user plane (CU-UP) of a RAN node. In aspects, a security key is generated for a target node of a handover. The security keys can be generated using a key derivation function (KDF) and using various input parameters, which will be described below herein.
[0069] In the following description, certain specific details are set forth in order to provide a thorough understanding of disclosed aspects. However, one skilled in the relevant art will recognize that aspects may be practiced without one or more of these specific details or with other methods, components, materials, etc. In other instances, well-known structures associated with transmitters, receivers, or transceivers have not been shown or described in detail to avoid unnecessarily obscuring descriptions of the aspects.
[0070] Reference throughout this specification to “one aspect” or “an aspect” means that a particular feature, structure, or characteristic described in connection with the aspect is included in at least one aspect. Thus, the appearances of the phrases “in one aspect” or “in an aspect” in various places throughout this specification are not necessarily all referring to the same aspect. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more aspects.
[0071] Embodiments described in the present disclosure may be implemented in wireless networking apparatuses, such as, without limitation, apparatuses utilizing Worldwide Interoperability for Microwave Access (WiMAX), Global System for Mobile communications (GSM, 2G), GSM EDGE radio access Network (GERAN), General Packet Radio Service (GRPS), Universal Mobile Telecommunication System (UMTS, 3G) based on basic wideband-code division multiple access (W-CDMA), high-speed packet access (HSPA), Long Term Evolution (LTE), LTE-Advanced, enhanced LTE (eLTE), 5G New Radio (5G NR), 5G Advance, 6G (and beyond) and 802.1 lax (Wi-Fi 6), among other wireless networking systems. The term ‘eLTE’ here denotes the LTE evolution that connects to a 5G core. LTE is also known as evolved UMTS terrestrial radio access (EUTRA) or as evolved UMTS terrestrial radio access network (EUTRAN).
[0072] The present disclosure may use the term “serving network device” to refer to a network node or network device (or a portion thereof) that services a UE. As used herein, the terms “transmit toward,” “transmit to,” “receive from,” and “cooperate with,” (and their variations) include communications that may or may not involve communications through one or more intermediate devices or nodes. The term “acquire” (and its variations) includes acquiring in the first instance or reacquiring after the first instance. The term “connection” may mean a physical connection or a logical connection.
[0073] The present disclosure uses 5G NR as an example of a wireless network and may use smartphones and / or extended reality headsets as an example of UEs. It is intended and shall be understood that such examples are merely illustrative, and the present disclosure is applicable to other wireless networks and user equipment.
[0074] FIG. l isa diagram depicting an example of wireless networking between a network system 100 and a user equipment (UE) 150. The network system 100 may include one or more network nodes 120, one or more servers 110, and / or one or more network equipment 130 (e.g., test equipment). The network nodes 120 will be described in more detail below. As used herein, the term “network apparatus” may refer to any component of the network system 100, such as the server 110, the network node 120, the network equipment 130, any component(s) of the foregoing, and / or any other component(s) of the network system 100. Examples of network apparatuses include, without limitation, apparatuses implementing aspects of 5G NR, among others. The present disclosure describes embodiments related to 5GNR and embodiments that involve aspects defined by 3rd Generation Partnership Project (3GPP). However, it is contemplated that embodiments relating to other wireless networking technologies are encompassed within the scope of the present disclosure.
[0075] The following description provides further details of examples of network nodes. In a 5G NR network, a gNodeB (also known as gNB) may include, e.g., a node that provides new radio (NR) user plane and control plane protocol terminations towards the UE and that is connected via a NG interface to the 5G core (5GC), e.g., according to 3GPP TS 38.300 V16.6.0 (2021-06) section 3.2, which is hereby incorporated by reference herein.
[0076] A gNB supports various protocol layers, e.g., Layer 1 (LI) - physical layer, Layer 2 (L2), and Layer 3 (L3).
[0077] The layer 2 (L2) of NR is split into the following sublayers: Medium Access Control (MAC), Radio Link Control (RLC), Packet Data Convergence Protocol (PDCP) and Service Data Adaptation Protocol (SDAP), where, e.g. :o The physical layer offers to the MAC sublayer transport channels; o The MAC sublayer offers to the RLC sublayer logical channels;o The RLC sublayer offers to the PDCP sublayer RLC channels;o The PDCP sublayer offers to the SDAP sublayer radio bearers;o The SDAP sublayer offers to 5GC quality of service (QoS) flows; o Control channels include broadcast control channel (BCCH) and physical control channel (PCCH).
[0078] Layer 3 (L3) includes, e.g., radio resource control (RRC), e.g., according to 3GPP TS 38.300 V16.6.0 (2021-06) section 6, which is hereby incorporated by reference herein.
[0079] A gNB central unit (gNB-CU) includes, e.g., a logical node hosting, e.g., service data adaptation protocol (SDAP), and packet data convergence protocol (PDCP) protocols of the gNB or PDCP protocols of the en-gNB, that controls the operation of one or more gNBdistributed units (gNB-DUs). The gNB-CU terminates the Fl interface connected with the gNB-DU. A gNB-CU may also be referred to herein as a CU, a central unit, a centralized unit, or a control unit.
[0080] A gNB Distributed Unit (gNB-DU) includes, e.g., a logical node hosting, e.g., radio link control (RLC), media access control (MAC), and physical (PHY) layers of the gNB or en-gNB, and its operation is partly controlled by the gNB-CU. One gNB-DU supports one or multiple cells. One cell is supported by only one gNB-DU. The gNB-DU terminates the Fl interface connected with the gNB-CU. A gNB-DU may also be referred to herein as DU or a distributed unit.
[0081] A gNB-CU-Control Plane (gNB-CU-CP) includes, e.g., a logical node. The gNB-CU-CP terminates the El interface connected with the gNB-CU-User Plane (gNB-CU-UP) and the Fl-C interface connected with the gNB-DU.
[0082] A gNB-CU-User Plane (gNB-CU-UP) includes, e.g., a logical node hosting, e.g., the user plane part of the PDCP protocol of the gNB-CU for an en-gNB, and the user plane part of the PDCP protocol and the SDAP protocol of the gNB-CU for a gNB. The gNB-CU-UP terminates the El interface connected with the gNB-CU-CP and the Fl-U interface connected with the gNB-DU, e.g., according to 3GPP TS 38.401 V16.6.0 (2021-07) section 3.1, which is hereby incorporated by reference herein.
[0083] As used herein, the term “network node” may refer to any of a gNB, a gNB-CU, a gNB-DU, a gNB-CU-CP, or a gNB-CU-UP, or any combination of them.
[0084] A RAN (radio access network) node or network node such as, e.g., a gNB, gNB-CU, or gNB-DU, or parts thereof, may be implemented using, e.g., an apparatus with at least one processor and / or at least one memory with processor-readable instructions (“program”) configured to support and / or provision and / or process CU and / or DU related functionality and / or features, and / or at least one protocol (sub-)layer of a RAN (radio access network), e.g., layer 2 and / or layer 3. An example of such an apparatus and components will be described in connection with FIG. 11 below. Different functional splits between the central and distributed unit are possible, and an example will be described below in connection with FIG. 3.
[0085] The gNB-CU and gNB-DU parts may, e.g., be co-located or physically separated. The gNB-DU may even be split further, e.g., into two parts, e.g., one including processing equipment and one including an antenna. A central unit (CU) may also be called baseband unit / radio equipment controller / cloud-RAN / virtual-RAN (BBU / REC / C-RAN / V-RAN), open-RAN (0-RAN), or part thereof. A distributed unit (DU) may also be called remote radio head / remote radio unit / radio equipment / radio unit (RRH / RRU / RE / RU), or part thereof.Hereinafter, in various example embodiments of the present disclosure, a network node, which supports at least one of central unit functionality or a layer 3 protocol of a radio access network, may be, e.g., a gNB-CU. Similarly, a network node, which supports at least one of distributed unit functionality or a layer 2 protocol of the radio access network, may be, e.g., a gNB-DU.
[0086] A gNB-CU may support one or multiple gNB-DUs. A gNB-DU may support one or multiple cells and, thus, could support a serving cell for a user equipment (UE) or support a candidate cell for handover, dual connectivity, and / or carrier aggregation, among other procedures.
[0087] The user equipment (UE) 150 may be or include a wireless or mobile device, an apparatus with a radio interface to interact with a RAN (radio access network), a smartphone, an in-vehicle apparatus, an loT device, or a M2M device, among other types of user equipment. Such UE 150 may include: at least one processor; and at least one memory including program code; where the at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus at least to perform certain operations, such as, e.g., RRC connection to the RAN. An example of components of a UE will be described in connection with FIG. 11. In embodiments, the UE 150 may be configured to generate a message (e.g., including a cell ID) to be transmitted via radio towards a RAN (e.g., to reach and communicate with a serving cell). In embodiments, the UE 150 may generate and transmit and receive RRC messages containing one or more RRC PDUs (packet data units). Persons skilled in the art will understand RRC protocol as well as other procedures a UE may perform.
[0088] With continuing reference to FIG. 1, in the example of a 5G NR network, the network system 100 provides one or more cells, which define a coverage area of the network system 100. As described above, the network system 100 may include a gNB of a 5G NR network or may include any other apparatus configured to control radio communication and manage radio resources within a cell. As used herein, the term “resource” may refer to radio resources, such as a resource block (RB), a physical resource block (PRB), a radio frame, a subframe, a time slot, a sub-band, a frequency region, a sub-carrier, a beam, etc. In embodiments, the network node 120 may be called a base station.
[0089] FIG. 1 provides an example and is merely illustrative of a network system 100 and a UE 150. Persons skilled in the art will understand that the network system 100 includes components not illustrated in FIG. 1 and will understand that other user equipment may be in communication with the network system 100.
[0090] FIG. 2 is a block diagram of example components of the network system 100 of FIG. 1. A 5GNR network may be described as an example of the network system 100, and itis intended that aspects of the following description shall be applicable to other types of network systems, as well. The network system may operate in accordance with the signals and connections shown in FIG. 1 such that the UE 150 is in communication with the network system 100 through the radio access network 225. Additionally, the network system may be divided into user plane components and functions and control plane components and functions, as shown and described herein. Unless indicated otherwise, the terms “component”, “function”, and “service” may be used interchangeably herein, and they may refer to and be implemented by instructions executed by one or more processors.
[0091] Example functions of the components are described below. The example functions are merely illustrative, and it shall be understood that additional operations and functions may be performed by the components described herein. Additionally, the connections between components may be virtual connections over service-based interfaces such that any component may communicate with any other component. In this manner, any component may act as a service “producer,” for any other component that is a service “consumer,” to provide services for network functions.
[0092] For example, a core network 210 is described in the control plane of the network system. The core network 210 may include an authentication server function (AUSF) 211, an access and mobility management function (AMF) 212, and a session management function (SMF) 213. The core network 210 may also include a network slice selection function (NSSF) 214, a network exposure function (NEF) 215, a network repository function (NRF) 216, and a unified data management function (UDM) 217, which may include a uniform data repository (UDR) 224.
[0093] Additional components and functions of the core network 210 may include an application function 218, policy control function (PCF) 219, network data analytics function (NWDAF) 220, analytics data repository function (ADRF) 221, management data analytics function (MDAF) 222, and operations and management function (0AM) 223.
[0094] The user plane includes the UE 150, a radio access network (RAN) 225, a user plane function (UPF) 226, and a data network (DN) 227. The RAN 225 may include one or more components described in connection with FIG. 1, such as one or more network nodes. However, the RAN 225 may not be limited to such components. The UPF 226 provides connection for data being transmitted over the RAN 225. The DN 226 identifies services from service providers, Internet access, and third party services, for example.
[0095] The AMF 212 processes connection and mobility tasks. The AUSF 211 receives authentication requests from the AMF 212 and interacts with UDM 217 to authenticate andvalidate network responses for determination of successful authentication. The SMF 213 conducts packet data unit (PDU) session management, as well as manages session context with the UPF 226.
[0096] The NSSF 214 may select a network slicing instance (NSI) and determine the allowed network slice selection assistance information (NSSAI). This selection and determination is utilized to set the AMF 212 to provide service to the UE 150. The NEF 215 secures access to network services for third parties to create specialized network services. The NRF 216 acts as a repository to store network functions to allow the functions to register with and discover each other.
[0097] The UDM 217 generates authentication vectors for use by the AUSF 211 and ADM 212 and provides user identification handling. The UDM 217 may be connected to the UDR 224 which stores data associated with authentication, applications, or the like. The AF 218 provides application services to a user (e.g., streaming services, etc.). The PCF 219 provides policy control functionality. For example, the PCF 219 may assist in network slicing and mobility management, as well as provide quality of service (QoS) and charging functionality.
[0098] The NWDAF 220 collects data (e.g., from the UE 150 and the network system) to perform network analytics and provide insight to functions that utilize the analytics in the providing of services. The ADRF 221 allows the storage, retrieval, and removal of data and analytics by consumers. The MDAF 222 provides additional data analytics services for network functions. The 0AM 223 provides provisioning and management processing functions to manage elements in or connected to the network (e.g., UE 150, network nodes, etc.).
[0099] FIG. 2 is merely an example of components of a network system, and variations are contemplated to be within the scope of the present disclosure. In embodiments, the network system may include other components not illustrated in FIG. 2. In embodiments, the network system may not include every component illustrated in FIG. 2. In embodiments, the components and connections may be implemented with different connections than those illustrated in FIG. 2. Such and other embodiments are contemplated to be within the scope of the present disclosure.
[0100] As mentioned above, in aspects, the present disclosure relates to security keys for functional splits in wireless networking architecture, such as functional splits between central unit(s) (CU) and distributed unit(s) (DU) in a wireless network architecture.
[0101] FIG. 3 shows an example of a functional split in which a DU includes, e.g., a logical node hosting radio resource control (RRC) and the control plane part of the PDCP (PDCP-c),in addition to hosting RLC and MAC. Various aspects of such a functional split and architecture will now be described.
[0102] The CU is the centralized part of the RAN node (e.g., gNB) and is further divided into two sub-units:Central Unit-Control Plane (CU-CP): Manages signaling and control function;Central Unit-User Plane (CU-UP): Handles user data processing and forwarding.
[0103] The illustrated architecture of FIG. 3 includes a core network 310 (e.g., control portion of core network) and a user plane function (UPF) 320. In FIG. 3, both the core network 310 and the UPF 320 are in communication with a plurality of radio access network (RAN) nodes, including a first RAN node 330 and a second RAN node 340. Each of the first RAN node 330 and the second RAN node 340 includes a CU-UP(Central). The first RAN node 330 includes a first DU 332, a second DU 334, and a radio unit (RU) for each DU. The second RAN node 340 includes a first DU 342, a second DU 344, and a RU for each DU. In the illustrated architecture, a common CU-CP is used for both the first RAN node 330 and the second RAN node 340. Each of these is further described below.
[0104] CU-CP is responsible for control plane tasks, primarily focusing on signaling and session management between the user equipment (UE) and the network. Operations of the CU-CP may include:Control Signaling Management:• Interfaces with the core network (e.g., AMF and SMF) over the N2 interface.• Coordinates mobility and paging functions.Policy and QoS Enforcement:• Ensures adherence to quality of service (QoS) policies as per the PCF and SMF. Load Balancing:• Optimizes resource allocation across multiple DUs and / or CU-UPs. Interface:• Communicates with the CU-UP using the El interface, a logical connection enabling separation of control and user plane functionalities.• Interacts with a DU (Distributed Unit) via the Fl -C interface.
[0105] CU-UP is focused on user plane tasks and deals with the transmission of user data. Operations of the CU-UP may include:Packet Data Convergence Protocol (PDCP):• Performs header compression, ciphering, and integrity protection.• Reordering and retransmission of user data packets.Data Routing and Forwarding:• Manages the transport of data packets to / from the core network through the user plane function (UPF).• Implements data buffering during handovers.QoS Handling:• Applies QoS rules for user plane traffic as defined by the SMF and PCF.Mobility Anchoring:• Ensures seamless data delivery during inter-cell or inter-gNB mobility.Interface:• Communicates with the CU-CP via the El interface.• Interacts with the DU using the F 1 -U interface for user data transmission.
[0106] Benefits of a CU-CP and CU-UP split may include:Scalability: Independent scaling of control and user plane functions depending on the demand (e.g., high signaling in dense areas or high data throughput in hotspots). Centralization: Facilitates central processing of control functions, which improves resource coordination and system efficiency.Flexibility: Enables deployment of CU-UP closer to the edge for latency-sensitive applications, while CU-CP can remain centralized.Network Slicing: Supports network slices with different QoS and latency requirements by dynamically assigning CU-CP and CU-UP resources.
[0107] A DU is an intermediate processing unit in the 5G RAN architecture. It is located closer to the cell site than the Central Unit (CU) but still away from the physical antennas. Operations of the DU may include:Real-time Processing:• Executes time-critical operations for the Medium Access Control (MAC) layer, Radio Link Control (RLC) layer, and parts of the Physical Layer (PHY).Radio Resource Management:• Allocates radio resources dynamically to ensure efficient spectrum usage. Error Correction:• Implements Hybrid Automatic Repeat Request (HARQ) for error recovery in the data link layer.Interfacing:Acts as a bridge between the Central Unit (CU) and Radio Unit (RU).• Coordinates with the CU over the Fl interface (Fl-C for control signaling, Fill for user data).• Interfaces with the RU via the lower-layer split (LLS) interface, e.g., using protocols such as Common Public Radio Interface (CPRI) or eCPRI.
[0108] A Radio Unit (RU) is a hardware component located at the cell site. It is responsible for transmitting and receiving radio frequency (RF) signals and converting them for transport to the DU. Operations of a RU may include:Radio Frequency (RF) Processing:• Handles RF transmission and reception through antennas.• Implements digital front-end functions such as digital beamforming (e.g., for use of massive multiple-input-multiple-output (MIMO) technology).Analog-Digital Conversion:• Converts RF signals to digital format for transport to the DU and vice versa. Synchronization:• Maintains precise timing synchronization, for advanced features such as coordinated multipoint (CoMP).Antenna Management:• Supports advanced antenna configurations, such as massive MIMO and millimeter-wave (mmWave) operations.
[0109] In the illustrated architecture, the RRC function is provided in each DU, while user plane (UP) related functions are centralized in the CU-UP. Operations of radio resource control (RRC) may include managing UE connection setup, release, and mobility (handover), and handling RRC signaling messages between UE and the RAN node, among others.
[0110] The functional split and architecture shown in FIG. 3 is merely an example, and variations are contemplated to be within the scope of the present disclosure.
[0111] Referring now to FIG. 4, there is shown security keys for a wireless architecture, such as the wireless architecture of FIG. 3. Aspects of security keys and security architecture are described in 3GPP TS 33.501, which is incorporated by reference herein in its entirety. As persons skilled in the art will understand, security keys may be used for, e.g., authentication, encryption, and decryption. As used herein, security keys will generally be denoted by the symbol K.
[0112] Aspects of the present disclosure address two security issues.
[0113] First, the present disclosure addresses initial security key generation / derivation for the functional split and architecture.
[0114] Second, the present disclosure addresses impacts to key generation / derivation during handover procedure, when forward secrecy principle is violated, since the source RAN node (e.g., gNB) in the handover procedure could use the UP keys to decrypt communications in the target RAN node (e.g., gNB).
[0115] In accordance with aspects of the present disclosure:• A DU specific key (KDU) 410 is derived from key KgNB.• KDU key 410 is used to derive RRC integrity and RRC encryption keys.• A CU-UP specific key (KCU-UP) 420 is derived from key KgNB.• KCU-UP key 420 is used to derive UP integrity and UP encryption keys.• During inter-RAN node (e.g., inter-gNB) handover, after target RAN node (e.g., gNB) keys generation from existing next hop (NH) parameter value or KgNB, DU and CU-UP keys will be generated by target RAN node (e.g., gNB), so forward secrecy issue is resolved.
[0116] The DU specific key (KDU) 410 and the CU-UP specific key (KCU-UP) 420 may be derived independently by a UE and by a network apparatus.
[0117] The illustration of FIG. 4 is merely an example, and variations are contemplated to be within the scope of the present disclosure.
[0118] FIG. 5 and FIG. 6 show six embodiments for computing initiate keys KDU and KCU-UP using a key derivation function (KDF) and various input parameters to the KDF. The initiate keys are generated in non-handover situations. Aspects of KDF are described in 3GPP TS 33.501. Other KDF are contemplated to be within the scope of the present disclosure. As mentioned above, the DU specific key (KDU) and the CU-UP specific key (KCU-UP) may be derived independently by a UE and by a network apparatus.
[0119] FIG. 5 shows embodiments A, B, C, and D, and FIG. 6 shows embodiments E and F. In each of the embodiments, when the DU specific key (KDU) and the CU-UP specific key (KCU-UP) are generated by the UE or by the network, it is assumed that the UE and the network already have the input parameters used to generate such keys. Signaling aspects of the various embodiments are described in Table 1 below.
[0120] In embodiment A, for generating the key KDU, the input parameters to the KDF include key KgNB, a fixed constant value (FC), and the string “DU”. For generating the key KCU-UP, the input parameters include key KgNB, a fixed constant value (FC), and the string “CU-UP”.
[0121] In embodiment B, for generating the key KDU, the input parameters to the KDF include key KgNB, a fixed constant value (FC), and a DU identifier (DU-ID). For generating the key KCU-UP, the input parameters include key KgNB, a fixed constant value (FC), and a CU-UP identifier (CU-UP -ID). Persons skilled in the art will understand the DU identifier (DU-ID) and the CU-UP identifier (CU-UP -ID). For example, the RAN node may define the DU-ID and CU-UP -ID and transmit the DU-ID and CU-UP -ID to the UE for the UE to use in generating the keys.
[0122] In embodiment C, for generating the key KDU, the input parameters to the KDF include key KgNB, a fixed constant value (FC), a radio network temporary identifier (RNTI), and the string “DU”. For generating the key KCU-UP, the input parameters include key KgNB, a fixed constant value (FC), a radio network temporary identifier (RNTI), and the string “CU-UP”. Persons skilled in the art will understand the radio network temporary identifier (RNTI).
[0123] In embodiment D, for generating the key KDU, the input parameters to the KDF include key KgNB, a fixed constant value (FC), a radio resource control -UE ID (RRC-UE-ID), and the string “DU”. For generating the key KCU-UP, the input parameters include key KgNB, a fixed constant value (FC), a user plane-UE ID (UP-UE-ID), and the string “CU-UP”. Persons skilled in the art will understand the RRC-UE-ID and the UP-UE-ID. For example, the RRC-UE-ID is associated to a certain DU within a RAN node (e.g., gNB), is not restricted to a hardware, and is available for use between the RAN and the UE for the RRC connection. The UP-UE-ID is associated to a certain CU-UP within the RAN node (e.g., gNB), is not restricted to a hardware, and is available for use between the RAN and the UE for the user plane connection.
[0124] In embodiment E, for generating the key KDU, the input parameters to the KDF include key KgNB, a fixed constant value (FC), and a random number (RANDDU) for generating the key KDU. For generating the key KCU-UP, the input parameters include key KgNB, a fixed constant value (FC), and a random number (RANDCU-UP) for generating the key KCU-UP. In embodiments, when the UE generates the keys, the random numbers RANDDU and RANDCU-UP may be transmitted from the network to the UE.
[0125] In embodiment F, for generating the key KDU, the input parameters to the KDF include key KgNB, a fixed constant value (FC), and a counter value (COUNTDU) for generating the key KDU. For generating the key KCU-UP, the input parameters include key KgNB, a fixed constant value (FC), and a counter value (COUNTCU-UP) for generating the key KCU-UP. In embodiments, when the UE generates the keys, the UE may maintain the counter values COUNTDU and COUNTCU-UP.
[0126] Impacts of the various embodiments shown in FIG. 5 and FIG. 6 are as follows, including impacts to security during handover (HO) and impacts to signaling.Table 1. Security and Signaling Impacts
[0127] The embodiments shown in FIG. 5 and FIG. 6 are merely examples, and variations are contemplated to be within the scope of the present disclosure.
[0128] FIG. 7 is a diagram of aspects of key generation for an inter-RAN node (e.g., inter-gNB) handover scenario, such as a handover from RAN node 330 to RAN node 340 in FIG. 3. During inter-RAN (e.g., inter-gNB) handover, the KAMF key is used to derive the KgNB key and the next hop (NH) value, e.g., as shown in FIG. 4. Persons skilled in the art will understand the NH value and will understand such procedure for deriving the KgNB key and the next hop (NH) value.
[0129] With continuing reference to FIG. 7, for an inter-RAN node handover to a target RAN node (e.g., gNB), a source RAN node (e.g., gNB) can use either vertical key derivation or horizontal key derivation to generate a target RAN node’s key (target K§NB). AS shown in FIG. 7, vertical key derivation uses NH values received from the AMF to generate the targetRAN node’s key (target K§NB), whereas horizontal key derivation uses physical cell identity (PCI) and downlink (DL) frequency to generate the target RAN node’s key (target K§NB). After handover is successful, the target RAN node’s key (target K§NB) is used to generate the DU key (KDU) and CU-UP key (KCU-UP), which are in turn used to generate both UP keys and RRC keys of the target RAN node, as shown in FIG. 4.
[0130] FIG. 7 is merely an example, and variations are contemplated to be within the scope of the present disclosure.
[0131] FIG. 8 is a diagram of aspects of key generation for an intra-RAN node (e.g., intra-gNB) DU handover scenario. As an example, intra-RAN node DU handover may involve (with respect to FIG. 3) handover from DU 332 to DU 334 in RAN node 330, or handover from DU 342 to DU 344 in RAN node 340. During an intra-RAN node (e.g., intra-gNB) DU handover, the KAMF key is used to derive the KgNB key and the next hop (NH) value, e.g., as shown in FIG. 4. Persons skilled in the art will understand the NH value and will understand such procedure for deriving the KgNB key and the next hop (NH) value.
[0132] With continuing reference to FIG. 8, for an intra-RAN node handover to a target DU, a source DU and / or a UE can use either vertical key derivation or horizontal key derivation to derive the target DU’s key (target KDU). AS shown in FIG. 8, vertical key derivation uses NH values received from the AMF to generate the target DU’s key (target KDU), whereas horizontal key derivation uses physical cell identity (PCI) and downlink (DL) frequency to generate the target DU’s key (target KDU). Because the handover is an intra-RAN node DU handover, no new UP keys will be generated, and only RRC integrity and RRC encryption keys of the target DU are generated.
[0133] In accordance with aspects of the present disclosure, rather than using PCI and DL frequency for horizontal key derivation, other parameters may be used by the UE and / or source DU to generate the target DU’s key. FIG. 9 shows four embodiments, which are described below.
[0134] In embodiment 1, for generating the target DU’s key (target KDU), the input parameters to the KDF include the source DU’s key (source KDU), a fixed constant value (FC), and a target DU identifier (DU-ID). Persons skilled in the art will understand the target DU identifier (DU-ID). For example, the RAN node may define the target DU identifier (DU-ID), and transmit it to the UE for use in generating the target DU’s key.
[0135] In embodiment 2, for generating the target DU’s key (target KDU), the input parameters to the KDF include the source DU’s key (source KDU), a fixed constant value (FC), a radio resource control-UE ID (RRC-UE-ID), and the string “DU”. Persons skilled in the artwill understand the RRC-UE-ID. For example, the RAN node may define the RRC-UE-ID and transmit it to the UE for use in generating the target DU’s key.
[0136] In embodiment 3, for generating the target DU’s key (target KDU), the input parameters to the KDF include the source DU’s key (source KDU), a fixed constant value (FC), and a random number (RANDDU) for generating the target DU’s key (target KDU). In embodiments, when the UE generates the key, the random number RANDDU may be transmitted from the network to the UE.
[0137] In embodiment 4, for generating the target DU’s key (target KDU), the input parameters to the KDF include the source DU’s key (source KDU), a fixed constant value (FC), and a counter value (COUNTDU) for generating the target DU’s key (target KDU). In embodiments, when the UE generates the key, the UE may maintain the counter value COUNTDU. For example, the value of COUNTDU may initially be 0 or some other initial value. For each handover to a target DU, the value of COUNTDU may be incremented by 1 or by some other predetermined increase, and the resulting COUNTDU may be provided to the target DU. For further handovers, the value of COUNTDU may be similarly incremented and provided to further target DUs.
[0138] The embodiments shown in FIG. 9 are merely illustrative, and variations are contemplated to be within the scope of the present disclosure.
[0139] Referring now to FIG. 10, there is shown a flow diagram of an example of an operation in a UE or in a network apparatus.
[0140] At block 1010, the operation involves accessing key derivation parameters. The key derivation parameters may include any of the parameters described in connection with FIG. 5, FIG. 6, and FIG. 9.
[0141] At block 1020, the operation involves generating a first key (KDU) for a distributed unit of a radio access network (RAN) node, where the first key is generated using a key derivation function and at least some of the key derivation parameters. Aspects of the key derivation function are described in 3GPP TS 33.501. Other key derivation functions are contemplated to be within the scope of the present disclosure. The first key (KDU) may be generated, for example, using any of the embodiments described in connection with FIG. 5, FIG. 6, or FIG. 9.
[0142] At block 1030, the operation involves generating a second key (KCU-UP) for a user plane of a central unit of the RAN node, where the second key is generated using the key derivation function and at least some of the key derivation parameters. The second key (Kcu-UP) may be generated, for example, using any of the embodiments described in connection with FIG. 5 or FIG. 6.
[0143] The operations of FIG. 10 are merely examples, and variations are contemplated to be within the scope of the present disclosure. In embodiments, the operations may include other blocks not illustrated in FIG. 10. In embodiments, the operations may not include every block illustrated in FIG. 10. Such and other embodiments are contemplated to be within the scope of the present disclosure.
[0144] Referring now to FIG. 11, there is shown a block diagram of example components of a UE or a network apparatus. The apparatus includes an electronic storage (e.g., non-transitory processor-readable medium) 1110, a processor 1120, a memory 1150, and a network interface 1140. The various components may be communicatively coupled with each other. The processor 1120 may be and may include any type of processor, such as a single-core central processing unit (CPU), a multi-core CPU, a microprocessor, a digital signal processor (DSP), a System-on-Chip (SoC), or any other type of processor. The memory 1150 may be a volatile type of memory, e.g., RAM, or a non-volatile type of memory, e.g., NAND flash memory. The memory 1150 includes processor-readable instructions that are executable by the processor 1120 to cause the apparatus to perform various operations, including those mentioned herein, such as the operations described in connection with FIGS. 3-10.
[0145] The electronic storage 1110 may be and include any type of electronic storage used for storing data, such as hard disk drive, solid state drive, and / or optical disc, among other types of electronic storage. The electronic storage 1110 stores processor-readable instructions for causing the apparatus to perform its operations and stores data associated with such operations, such as storing data relating to 5G NR standards, among other data. The network interface 1140 may implement wireless networking technologies such as 5G NR and / or other wireless networking technologies.
[0146] The components shown in FIG. 11 are merely examples, and persons skilled in the art will understand that an apparatus includes other components not illustrated and may include multiples of any of the illustrated components. Such and other embodiments are contemplated to be within the scope of the present disclosure.
[0147] Further embodiments of the present disclosure include the following examples. In the following, any “means” may be implemented by at least one processor and processorexecutable instructions, unless the context indicates otherwise. Any “means” for receiving or transmitting may be implemented by a transceiver. The notation Example n.x refers to any Example having a value for n and a value for x.
[0148] Example 1.1. A method comprising:accessing key derivation parameters;generating a first key (KDU) for a distributed unit of a radio access network (RAN) node, the first key generated based on a key derivation function and at least some of the key derivation parameters; andgenerating a second key (KCU-UP) for a user plane of a central unit of the RAN node, the second key generated based on the key derivation function and at least some of the key derivation parameters.
[0149] Example 1.2. The method of Example 1.1,wherein the key derivation parameters comprise:a key (K§NB) of the RAN node, anda fixed constant value (FC),wherein the first key (KDU) is generated based on KgNB and FC, andwherein the second key (KCU-UP) is generated based on KgNB and FC.
[0150] Example 1.3. The method of Example 1.2,wherein the key derivation parameters further comprise a string “DU”, and wherein the first key (KDU) is generated further based on the string “DU”.
[0151] Example 1.4. The method of Example 1.2 or Example 1.3,wherein the key derivation parameters further comprise a string “CU-UP”, and wherein the second key (KCU-UP) is generated further based on the string “CU-UP”.
[0152] Example 1.5. The method of any one of Example 1.2- Example 1.4, wherein the key derivation parameters further comprise an identifier,wherein the first key (KDU) is generated further based on the identifier, and wherein the second key (KCU-UP) is generated further based on the identifier.
[0153] Example 1.6. The method of Example 1.2,wherein the key derivation parameters further comprise an identifier of the distributed unit of the RAN node (DU-ID),wherein the first key (KDU) is generated further based on the DU-ID.
[0154] Example 1.7. The method of Example 1.2 or Example 1.6,wherein the key derivation parameters further comprise an identifier of the user plane of the central unit of the RAN node (CU-UP -ID),wherein the second key (KCU-UP) is generated further based on the CU-UP -ID.
[0155] Example 1.8. The method of any one of Example 1.3 or Example 1.4,wherein the key derivation parameters further comprise a radio network temporary identifier (RNTI),wherein the first key (KDU) is generated further based on the RNTI.
[0156] Example 1.9. The method of any one of Example 1.3, Example 1.4, or Example 1.8,wherein the key derivation parameters further comprise a radio network temporary identifier (RNTI),wherein the second key (KCU-UP) is generated further based on the RNTI.
[0157] Example 1.10. The method of any one of Example 1.3 or Example 1.4, wherein the key derivation parameters further comprise a radio resource control user equipment identifier (RRC-UE-ID),wherein the first key (KDU) is generated further based on the RRC-UE-ID.
[0158] Example 1.11. The method of any one of Example 1.3, Example 1.4, or Example 1.10,wherein the key derivation parameters further comprise a user plane user equipment identifier (UP-UE-ID),wherein the second key (KCU-UP) is generated further based on the UP-UE-ID.
[0159] Example 1.12. The method of any one of Example 1.1- Example 1.11, further comprising:generating a radio resource control (RRC) integrity key (KRRCint) based on the first key (KDU).
[0160] Example 1.13. The method of any one of Example 1.1- Example 1.12, further comprising:generating a radio resource control (RRC) encryption key (KRRCenc) based on the first key (KDU).
[0161] Example 1.14. The method of any one of Example 1.1- Example 1.13, further comprising:generating a user plane (UP) integrity key (Kupint) based on the second key (KCU-UP).
[0162] Example 1.15. The method of any one of Example 1.1- Example 1.14, further comprising:generating a user plane (UP) encryption key (Kupenc) based on the second key (KCU-UP).
[0163] Example 1.16. The method of any one of Example 1.1-Example 1.15, wherein the method is performed in a user equipment (UE).
[0164] Example 1.17. The method of any one of Example 1.1-Example 1.15, wherein the method is performed in the RAN node.
[0165] Example 1.18. An apparatus comprising:at least one processor; andat least one memory storing instructions which, when executed by the at least one processor, cause the apparatus to perform a method as in any one of Example 1.1- Example 1.17.
[0166] Example 1.19. A non-transitory processor-readable medium storing instructions which, when executed by at least one processor of an apparatus, cause the apparatus to perform a method as in any one of Example 1.1- Example 1.17.
[0167] Example 2.1. An apparatus comprising:means for accessing key derivation parameters;means for generating a first key (KDU) for a distributed unit of a radio access network (RAN) node, the first key generated based on a key derivation function and at least some of the key derivation parameters; andmeans for generating a second key (KCU-UP) for a user plane of a central unit of the RAN node, the second key generated based on the key derivation function and at least some of the key derivation parameters.
[0168] Example 2.2. The apparatus of Example 2.1,wherein the key derivation parameters comprise:a key (K§NB) of the RAN node, anda fixed constant value (FC),wherein the first key (KDU) is generated based on KgNB and FC, andwherein the second key (KCU-UP) is generated based on KgNB and FC.
[0169] Example 2.3. The apparatus of Example 2.2,wherein the key derivation parameters further comprise a string “DU”, and wherein the first key (KDU) is generated further based on the string “DU”.
[0170] Example 2.4. The apparatus of Example 2.2 or Example 2.3,wherein the key derivation parameters further comprise a string “CU-UP”, and wherein the second key (KCU-UP) is generated further based on the string “CU-UP”.
[0171] Example 2.5. The apparatus of any one of Example 2.2- Example 2.4, wherein the key derivation parameters further comprise an identifier,wherein the first key (KDU) is generated further based on the identifier, and wherein the second key (KCU-UP) is generated further based on the identifier.
[0172] Example 2.6. The apparatus of Example 2.2,wherein the key derivation parameters further comprise an identifier of the distributed unit of the RAN node (DU-ID),wherein the first key (KDU) is generated further based on the DU-ID.
[0173] Example 2.7. The apparatus of Example 2.2 or Example 2.6,wherein the key derivation parameters further comprise an identifier of the user plane of the central unit of the RAN node (CU-UP-ID),wherein the second key (KCU-UP) is generated further based on the CU-UP-ID.
[0174] Example 2.8. The apparatus of any one of Example 2.3 or Example 2.4, wherein the key derivation parameters further comprise a radio network temporary identifier (RNTI),wherein the first key (KDU) is generated further based on the RNTI.
[0175] Example 2.9. The apparatus of any one of Example 2.3, Example 2.4, or Example 2.8,wherein the key derivation parameters further comprise a radio network temporary identifier (RNTI),wherein the second key (KCU-UP) is generated further based on the RNTI.
[0176] Example 2.10. The apparatus of any one of Example 2.3 or Example 2.4, wherein the key derivation parameters further comprise a radio resource control user equipment identifier (RRC-UE-ID),wherein the first key (KDU) is generated further based on the RRC-UE-ID.
[0177] Example 2.11. The apparatus of any one of Example 2.3, Example 2.4, or Example 2.10,wherein the key derivation parameters further comprise a user plane user equipment identifier (UP-UE-ID),wherein the second key (KCU-UP) is generated further based on the UP-UE-ID.
[0178] Example 2.12. The apparatus of any one of Example 2.1- Example 2.11, further comprising:means for generating a radio resource control (RRC) integrity key (KRRCint) based on the first key (KDU).
[0179] Example 2.13. The apparatus of any one of Example 2.1- Example 2.12, further comprising:means for generating a radio resource control (RRC) encryption key (KRRCenc) based on the first key (KDU).
[0180] Example 2.14. The apparatus of any one of Example 2.1- Example 2.13, further comprising:means for generating a user plane (UP) integrity key (Kupint) based on the second key (KCU-UP).
[0181] Example 2.15. The apparatus of any one of Example 2.1- Example 2.14, further comprising:means for generating a user plane (UP) encryption key (Kupenc) based on the second key (KCU-UP).
[0182] Example 3.1. A method comprising:accessing key derivation parameters comprising:a key (K§NB) of a radio access network (RAN) node,a fixed constant value (FC),a first random number, anda second random number;generating a first key (KDU) for a distributed unit of the RAN node, the first key generated based on a key derivation function and at least some of the key derivation parameters; andgenerating a second key (KCU-UP) for a user plane of a central unit of the RAN node, the second key generated based on the key derivation function and at least some of the key derivation parameters.
[0183] Example 3.2. The method of Example 3.1, wherein the first key (KDU) is generated based on KgNB, FC, and the first random number.
[0184] Example 3.3. The method of Example 3.1 or Example 3.2, wherein the second key (KCU-UP) is generated based on KgNB, FC, and the second random number.
[0185] Example 3.4. The method of any one of Example 3.1- Example 3.3, further comprising:receiving the first random number and the second number from a network apparatus.
[0186] Example 3.5. The method of any one of Example 3.1- Example 3.4, further comprising:generating a third key (target KDU) for a target distributed unit of a handover, the third key generated based on the key derivation function, the first key (KDU), FC, and a third random number.
[0187] Example 3.6. The method of Example 3.5, further comprising:receiving the third random number from a network apparatus.
[0188] Example 3.7. The method of any one of Example 3.1- Example 3.6, further comprising:generating a radio resource control (RRC) integrity key (KRRCint) based on the first key (KDU).
[0189] Example 3.8. The method of any one of Example 3.1- Example 3.7, further comprising:generating a radio resource control (RRC) encryption key (KRRCenc) based on the first key (KDU).
[0190] Example 3.9. The method of any one of Example 3.1- Example 3.8, further comprising:generating a user plane (UP) integrity key (Kupint) based on the second key (KCU-UP).
[0191] Example 3.10. The method of any one of Example 3.1- Example 3.9, further comprising:generating a user plane (UP) encryption key (Kupenc) based on the second key (KCU-UP).
[0192] Example 3.11. The method of any one of Example 3.1-Example 3.10, wherein the method is performed in a user equipment (UE).
[0193] Example 3.12. The method of any one of Example 3.1-Example 3.10, wherein the method is performed in the RAN node.
[0194] Example 3.13. An apparatus comprising:at least one processor; andat least one memory storing instructions which, when executed by the at least one processor, cause the apparatus to perform a method as in any one of Example 3.1- Example 3.12.
[0195] Example 3.14. A non-transitory processor-readable medium storing instructions which, when executed by at least one processor of an apparatus, cause the apparatus to perform a method as in any one of Example 3.1- Example 3.12.
[0196] Example 4.1. An apparatus comprising:means for accessing key derivation parameters comprising:a key (K§NB) of a radio access network (RAN) node,a fixed constant value (FC),a first random number, anda second random number;means for generating a first key (KDU) for a distributed unit of the RAN node, the first key generated based on a key derivation function and at least some of the key derivation parameters; andmeans for generating a second key (KCU-UP) for a user plane of a central unit of the RAN node, the second key generated based on the key derivation function and at least some of the key derivation parameters.
[0197] Example 4.2. The apparatus of Example 4.1, wherein the first key (KDU) is generated based on K§NB, FC, and the first random number.
[0198] Example 4.3. The apparatus of Example 4.1 or Example 4.2, wherein the second key (KCU-UP) is generated based on KgNB, FC, and the second random number.
[0199] Example 4.4. The apparatus of any one of Example 4.1- Example 4.3, further comprising:means for receiving the first random number and the second number from a network apparatus.
[0200] Example 4.5. The apparatus of any one of Example 4.1- Example 4.4, further comprising:means for generating a third key (target KDU) for a target distributed unit of a handover, the third key generated based on the key derivation function, the first key (KDU), FC, and a third random number.
[0201] Example 4.6. The apparatus of Example 4.5, further comprising:means for receiving the third random number from a network apparatus.
[0202] Example 4.7. The apparatus of any one of Example 4.1- Example 4.6, further comprising:means for generating a radio resource control (RRC) integrity key (KRRCint) based on the first key (KDU).
[0203] Example 4.8. The apparatus of any one of Example 4.1- Example 4.7, further comprising:means for generating a radio resource control (RRC) encryption key (KRRCenc) based on the first key (KDU).
[0204] Example 4.9. The apparatus of any one of Example 4.1- Example 4.8, further comprising:means for generating a user plane (UP) integrity key (Kupint) based on the second key (KCU-UP).
[0205] Example 4.10. The apparatus of any one of Example 4.1- Example 4.9, further comprising:means for generating a user plane (UP) encryption key (Kupenc) based on the second key (KCU-UP).
[0206] Example 5.1. A method comprising:accessing key derivation parameters comprising:a key (K§NB) of a radio access network (RAN) node,a fixed constant value (FC),a first counter value provided by a first counter, anda second counter value provided by a second counter;generating a first key (KDU) for a distributed unit of the RAN node, the first key generated based on a key derivation function and at least some of the key derivation parameters; andgenerating a second key (KCU-UP) for a user plane of a central unit of the RAN node, the second key generated based on the key derivation function and at least some of the key derivation parameters.
[0207] Example 5.2. The method of Example 5.1, wherein the first key (KDU) is generated based on K§NB, FC, and the first counter value.
[0208] Example 5.3. The method of Example 5.1 or Example 5.2, wherein the second key (KCU-UP) is generated based on KgNB, FC, and the second counter value.
[0209] Example 5.4. The method of any one of Example 5.1- Example 5.3, further comprising:incrementing the first counter by a predetermined amount to provide a first incremented counter value; andgenerating a third key (target KDU) for secure communication with a target distributed unit (DU) of a handover, the third key generated based on the key derivation function, the first key (KDU), FC, and the first incremented counter value.
[0210] Example 5.5. The method of Example 5.4, further comprising:transmitting the first incremented counter value to the target DU.
[0211] Example 5.6. The method of any one of Example 5.1- Example 5.5, further comprising:generating a radio resource control (RRC) integrity key (KRRCint) based on the first key (KDU).
[0212] Example 5.7. The method of any one of Example 5.1- Example 5.6, further comprising:generating a radio resource control (RRC) encryption key (KRRCenc) based on the first key (KDU).
[0213] Example 5.8. The method of any one of Example 5.1- Example 5.7, further comprising:generating a user plane (UP) integrity key (Kupint) based on the second key (KCU-UP).
[0214] Example 5.9. The method of any one of Example 5.1- Example 5.8, further comprising:generating a user plane (UP) encryption key (Kupenc) based on the second key (KCU-UP).
[0215] Example 5.10. The method of any one of Example 5.1-Example 5.9, wherein the method is performed in a user equipment (UE).
[0216] Example 5.11. The method of any one of Example 5.1-Example 5.9, wherein the method is performed in the RAN node.
[0217] Example 5.12. An apparatus comprising:at least one processor; andat least one memory storing instructions which, when executed by the at least one processor, cause the apparatus to perform a method as in any one of Example 5.1- Example 5.11.
[0218] Example 5.13. A non-transitory processor-readable medium storing instructions which, when executed by at least one processor of an apparatus, cause the apparatus to perform a method as in any one of Example 5.1- Example 5.11.
[0219] Example 6.1. An apparatus comprising:means for accessing key derivation parameters comprising:a key (K§NB) of a radio access network (RAN) node,a fixed constant value (FC),a first counter value provided by a first counter, anda second counter value provided by a second counter;means for generating a first key (KDU) for a distributed unit of the RAN node, the first key generated based on a key derivation function and at least some of the key derivation parameters; andmeans for generating a second key (KCU-UP) for a user plane of a central unit of the RAN node, the second key generated based on the key derivation function and at least some of the key derivation parameters.
[0220] Example 6.2. The apparatus of Example 6.1, wherein the first key (KDU) is generated based on K§NB, FC, and the first counter value.
[0221] Example 6.3. The apparatus of Example 6.1 or Example 6.2, wherein the second key (KCU-UP) is generated based on K§NB, FC, and the second counter value.
[0222] Example 6.4. The apparatus of any one of Example 6.1- Example 6.3, further comprising:means for incrementing the first counter by a predetermined amount to provide a first incremented counter value; andmeans for generating a third key (target KDU) for secure communication with a target distributed unit (DU) of a handover, the third key generated based on the key derivation function, the first key (KDU), FC, and the first incremented counter value.
[0223] Example 6.5. The apparatus of Example 6.4, further comprising:means for transmitting the first incremented counter value to the target DU.
[0224] Example 6.6. The apparatus of any one of Example 6.1- Example 6.5, further comprising:means for generating a radio resource control (RRC) integrity key (KRRCint) based on the first key (KDU).
[0225] Example 6.7. The apparatus of any one of Example 6.1- Example 6.6, further comprising:means for generating a radio resource control (RRC) encryption key (KRRCenc) based on the first key (KDU).
[0226] Example 6.8. The apparatus of any one of Example 6.1- Example 6.7, further comprising:means for generating a user plane (UP) integrity key (Kupint) based on the second key (KCU-UP).
[0227] Example 6.9. The apparatus of any one of Example 6.1- Example 6.8, further comprising:means for generating a user plane (UP) encryption key (Kupenc) based on the second key (KCU-UP).
[0228] Example 7.1. A method comprising:accessing key derivation parameters comprising:a key (source KDU) of a source distributed unit (DU) of a radio access network (RAN) node, anda fixed constant value (FC),wherein the source DU is a source of a handover to a target distributed unit (DU) of the RAN node; andgenerating a key (target KDU) for the target DU of the RAN node, the target KDU generated based on a key derivation function and at least the source KDU and the FC.
[0229] Example 7.2. The method of Example 7.1,wherein the key derivation parameters further comprise an identifier of the target DU of the RAN node,wherein the target KDU is generated further based on the identifier of the target DU of the RAN node.
[0230] Example 7.3. The method of Example 7.1,wherein the key derivation parameters further comprise:a string “DU”, anda radio resource control user equipment identifier (RRC-UE-ID), wherein the target KDU is generated based further on the string “DU” and the RRC-UE-ID.
[0231] Example 7.4. The method of Example 7.1,wherein the key derivation parameters further comprise a random number, wherein the target KDU is generated based further on the random number.
[0232] Example 7.5. The method of Example 7.4, further comprising:receiving the random number from a network apparatus.
[0233] Example 7.6. The method of Example 7.1, further comprising:incrementing a counter, by a predetermined amount, from a counter value to an incremented counter value,wherein the key derivation parameters further comprise the incremented counter value, wherein the target KDU is generated based further on the incremented counter value.
[0234] Example 7.7. The method of Example 7.6, wherein the source KDU was derived based on the counter value.
[0235] Example 7.8. The method of Example 7.6 or Example 7.7, further comprising: transmitting the incremented counter value to the target DU.
[0236] Example 7.9. The method of any one of Example 7.1- Example 7.8, further comprising:generating a radio resource control (RRC) integrity key (KRRCint) based on the source KDU.
[0237] Example 7.10. The method of any one of Example 7.1- Example 7.9, further comprising:generating a radio resource control (RRC) encryption key (KRRCenc) based on the source KDU.
[0238] Example 7.11. The method of any one of Example 7.1- Example 7.10, further comprising:generating a radio resource control (RRC) integrity key (KRRCint) based on the target KDU.
[0239] Example 7.12. The method of any one of Example 7.1- Example 7.11, further comprising:generating a radio resource control (RRC) encryption key (KRRCenc) based on the target KDU.
[0240] Example 7.13. The method of any one of Example 7.1-Example 7.12, wherein the method is performed in a user equipment (UE).
[0241] Example 7.14. The method of any one of Example 7.1-Example 7.12, wherein the method is performed in the RAN node.
[0242] Example 7.15. An apparatus comprising:at least one processor; andat least one memory storing instructions which, when executed by the at least one processor, cause the apparatus to perform a method as in any one of Example 7.1- Example 7.14.
[0243] Example 7.16. A non-transitory processor-readable medium storing instructions which, when executed by at least one processor of an apparatus, cause the apparatus to perform a method as in any one of Example 7.1- Example 7.14.
[0244] Example 8.1. An apparatus comprising:means for accessing key derivation parameters comprising:a key (source KDU) of a source distributed unit (DU) of a radio access network (RAN) node, anda fixed constant value (FC),wherein the source DU is a source of a handover to a target distributed unit (DU) of the RAN node; andmeans for generating a key (target KDU) for the target DU of the RAN node, the target KDU generated based on a key derivation function and at least the source KDU and the FC.
[0245] Example 8.2. The apparatus of Example 8.1,wherein the key derivation parameters further comprise an identifier of the target DU of the RAN node,wherein the target KDU is generated further based on the identifier of the target DU of the RAN node.
[0246] Example 8.3. The apparatus of Example 8.1,wherein the key derivation parameters further comprise:a string “DU”, anda radio resource control user equipment identifier (RRC-UE-ID), wherein the target KDU is generated based further on the string “DU” and the RRC-UE-ID.
[0247] Example 8.4. The apparatus of Example 8.1,wherein the key derivation parameters further comprise a random number, wherein the target KDU is generated based further on the random number.
[0248] Example 8.5. The apparatus of Example 8.4, further comprising:means for receiving the random number from a network apparatus.
[0249] Example 8.6. The apparatus of Example 8.1, further comprising:means for incrementing a counter, by a predetermined amount, from a counter value to an incremented counter value,wherein the key derivation parameters further comprise the incremented counter value, wherein the target KDU is generated based further on the incremented counter value.
[0250] Example 8.7. The apparatus of Example 8.6, wherein the source KDU was derived based on the counter value.
[0251] Example 8.8. The apparatus of Example 8.6 or Example 8.7, further comprising:means for transmitting the incremented counter value to the target DU.
[0252] Example 8.9. The apparatus of any one of Example 8.1- Example 8.8, further comprising:means for generating a radio resource control (RRC) integrity key (KRRCint) based on the source KDU.
[0253] Example 8.10. The apparatus of any one of Example 8.1- Example 8.9, further comprising:means for generating a radio resource control (RRC) encryption key (KRRCenc) based on the source KDU.
[0254] Example 8.11. The apparatus of any one of Example 8.1- Example 8.10, further comprising:means for generating a radio resource control (RRC) integrity key (KRRCint) based on the target KDU.
[0255] Example 8.12. The apparatus of any one of Example 8.1- Example 8.11, further comprising:means for generating a radio resource control (RRC) encryption key (KRRCenc) based on the target KDU.
[0256] The embodiments and aspects disclosed herein are examples of the present disclosure and may be embodied in various forms. For instance, although certain embodiments herein are described as separate embodiments, each of the embodiments herein may be combined with one or more of the other embodiments herein. Specific structural and functional details disclosed herein are not to be interpreted as limiting, but as a basis for the claims and as a representative basis for teaching one skilled in the art to variously employ the present disclosure in virtually any appropriately detailed structure. Like reference numerals may refer to similar or identical elements throughout the description of the figures.
[0257] The phrases “in an aspect,” “in aspects,” “in various aspects,” “in some aspects,” or “in other aspects” may each refer to one or more of the same or different aspects in accordance with this present disclosure. The phrase “a plurality of’ may refer to two or more.
[0258] The phrases “in an embodiment,” “in embodiments,” “in various embodiments,” “in some embodiments,” or “in other embodiments” may each refer to one or more of the same or different embodiments in accordance with the present disclosure. A phrase in the form “A or B” means “(A), (B), or (A and B).” A phrase in the form “at least one of A, B, or C” means “(A); (B); (C); (A and B); (A and C); (B and C); or (A, B, and C) .”
[0259] Any of the herein described methods, programs, algorithms or codes may be converted to, or expressed in, a programming language or computer program. The terms “programming language” and “computer program,” as used herein, each include any language used to specify instructions to a computer, and include (but is not limited to) the following languages and their derivatives: Assembler, Basic, Batch files, BCPL, C, C+, C++, Delphi, Fortran, Java, JavaScript, machine code, operating system command languages, Pascal, Perl, PL1, Python, scripting languages, Visual Basic, metalanguages which themselves specify programs, and all first, second, third, fourth, fifth, or further generation computer languages. Also included are database and other data schemas, and any other meta-languages. No distinction is made between languages which are interpreted, compiled, or use both compiled and interpreted approaches. No distinction is made between compiled and source versions of a program. Thus, reference to a program, where the programming language could exist in morethan one state (such as source, compiled, object, or linked) is a reference to any and all such states. Reference to a program may encompass the actual instructions and / or the intent of those instructions.
[0260] While aspects of the present disclosure have been shown in the drawings, it is not intended that the present disclosure be limited thereto, as it is intended that the present disclosure be as broad in scope as the art will allow and that the specification be read likewise. Therefore, the above description should not be construed as limiting, but merely as exemplifications of particular aspects. Those skilled in the art will envision other modifications within the scope and spirit of the claims appended hereto.
Claims
WHAT IS CLAIMED IS:
1. A method comprising:accessing key derivation parameters;generating a first key (KDU) for a distributed unit of a radio access network (RAN) node, the first key generated based on a key derivation function and at least some of the key derivation parameters; andgenerating a second key (KCU-UP) for a user plane of a central unit of the RAN node, the second key generated based on the key derivation function and at least some of the key derivation parameters.
2. The method of claim 1,wherein the key derivation parameters comprise:a key (K§NB) of the RAN node, anda fixed constant value (FC),wherein the first key (KDU) is generated based on KgNB and FC, andwherein the second key (KCU-UP) is generated based on KgNB and FC.
3. The method of claim 2,wherein the key derivation parameters further comprise a string “DU”, and wherein the first key (KDU) is generated further based on the string “DU”.
4. The method of claim 2 or claim 3,wherein the key derivation parameters further comprise a string “CU-UP”, and wherein the second key (KCU-UP) is generated further based on the string “CU-UP”.
5. The method of any one of claims 2-4, wherein the key derivation parameters further comprise an identifier,wherein the first key (KDU) is generated further based on the identifier, and wherein the second key (KCU-UP) is generated further based on the identifier.
6. The method of claim 2,wherein the key derivation parameters further comprise an identifier of the distributed unit of the RAN node (DU-ID),37wherein the first key (KDU) is generated further based on the DU-ID.
7. The method of claim 2 or claim 6,wherein the key derivation parameters further comprise an identifier of the user plane of the central unit of the RAN node (CU-UP-ID),wherein the second key (KCU-UP) is generated further based on the CU-UP-ID.
8. The method of any one of claim 3 or claim 4,wherein the key derivation parameters further comprise a radio network temporary identifier (RNTI),wherein the first key (KDU) is generated further based on the RNTI.
9. The method of any one of claims 3, 4, or 8,wherein the key derivation parameters further comprise a radio network temporary identifier (RNTI),wherein the second key (KCU-UP) is generated further based on the RNTI.
10. The method of any one of claim 3 or claim 4,wherein the key derivation parameters further comprise a radio resource control user equipment identifier (RRC-UE-ID),wherein the first key (KDU) is generated further based on the RRC-UE-ID.
11. The method of any one of claims 3, 4, or 10,wherein the key derivation parameters further comprise a user plane user equipment identifier (UP-UE-ID),wherein the second key (KCU-UP) is generated further based on the UP-UE-ID.
12. The method of any one of claims 1-11, further comprising:generating a radio resource control (RRC) integrity key (KRRCint) based on the first key (KDU).
13. The method of any one of claims 1-12, further comprising:generating a radio resource control (RRC) encryption key (KRRCenc) based on the first key (KDU).3814. The method of any one of claims 1-13, further comprising:generating a user plane (UP) integrity key (Kupint) based on the second key (KCU-UP).
15. The method of any one of claims 1-14, further comprising:generating a user plane (UP) encryption key (Kupenc) based on the second key (KCU- UP).
16. The method of any one of claims 1-15, wherein the method is performed in a user equipment (UE).
17. The method of any one of claims 1-15, wherein the method is performed in the RAN node.
18. An apparatus comprising:at least one processor; andat least one memory storing instructions which, when executed by the at least one processor, cause the apparatus to perform a method as in any one of claims 1-17.
19. A non-transitory processor-readable medium storing instructions which, when executed by at least one processor of an apparatus, cause the apparatus to perform a method as in any one of claims 1-17.