Security aspects of forwarded mode packets in a wireless communication system
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- LENOVO INT COÖPERATIEF U A
- Filing Date
- 2026-01-22
- Publication Date
- 2026-08-06
Smart Images

Figure EP2026051619_06082026_PF_FP_ABST
Abstract
Description
SECURITY ASPECTS OF FORWARDED MODE PACKETS IN A WIRELESS COMMUNICATION SYSTEMTECHNICAL FIELD
[0001] The present disclosure relates generally to wireless communication, including the security aspects of forwarded mode packets in a wireless communication system.BACKGROUND
[0002] A wireless communications system may include one or multiple network communication devices, which may be otherwise knowns as network equipment (NE) supporting wireless communications for one or multiple user communication devices, which may be otherwise known as user equipment (UE), or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like). Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G)).SUMMARY
[0003] An article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” may be interchangeable. As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of’ or “one or more of’ or “one or both of’) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a Docket No. SMM920250200-GR-NPcondition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on. Further, as used herein, including in the claims, a “set” may include one or more elements.
[0004] A first network entity for wireless communication is described. The first network entity may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the first network entity may comprise at least one memory, and at least one processor coupled with the at least one memory and configured to cause the first network entity to: transmit, to a second network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing media related information (MRI) wherein the one or more transforms of the QUIC short header packets are encrypted; and receive, from the second network entity, a response to the request to establish the communication mode and the one or more transforms of the QUIC short header packets. The term ‘QUIC’ may refer to the name of the QUIC transport protocol as defined by the Internet Engineering Task Force (IETF). For example, the IETF Standard RFC 9000 titled “QUIC: A UDP-Based Multiplexed and Secure Transport” defines QUIC as the name, not an acronym, of a transport protocol.
[0005] A second network entity for wireless communication is described. The second network entity may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the second network entity may comprise at least one memory, and at least one processor coupled with the at least one memory and configured to cause the second network entity to: receive, from a first network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing MRI, wherein the one or more transforms of QUIC short header packets are encrypted; and transmit, to the first network entity, a response to the request to establish the communication mode and the one or more transforms of QUIC short header packets.
[0006] A method performed or performable by a first network entity is provided. The method may comprise: transmitting, to a second network entity, a request to establish aDocket No. SMM920250200-GR-NPcommunication mode for transmitting one or more transforms of QUIC short header packets containing MRI, wherein the one or more transforms of the QUIC short header packets are encrypted; receiving, from the second network entity, a response to the request to establish the communication mode and the one or more transforms of the QUIC short header packets.
[0007] A method performed or performable by a second network entity is provided. The method may comprise receiving, from a first network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing MRI, wherein the one or more transforms of QUIC short header packets are encrypted; transmitting, to the first network entity, a response to the request to establish the communication mode and the one or more transforms of QUIC short header packets.BRIEF DESCRIPTION OF THE DRAWINGS
[0008] Figure 1 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.
[0009] Figure 2 illustrates an example of a transformed QUIC short header packet with MRI in accordance with aspects of the present disclosure.
[0010] Figure 3 illustrates an example of a nonce used for advanced encryption standard (AES) cipher block chain message authentication code (CCM) in accordance with aspects of the present disclosure.
[0011] Figure 4 illustrates an example of a transformed QUIC short header packet with MRI in accordance with aspects of the present disclosure.
[0012] Figure 5 illustrates a further example of a transformed QUIC short header packet with MRI in accordance with aspects of the present disclosure.
[0013] Figure 6 illustrates a further example of a transformed QUIC short header packet with MRI in accordance with aspects of the present disclosure.
[0014] Figure 7 illustrates a further example of a transformed QUIC short header packet with MRI in accordance with aspects of the present disclosure.Docket No. SMM920250200-GR-NP
[0015] Figure 8 illustrates an example of decryption of a protected transformed QUIC short header packet with MRI in accordance with aspects of the present disclosure.
[0016] Figure 9 illustrates an example of a process flow that establishes a forwarded mode between an AS and a user plane function (UPF) in accordance with aspects of the present disclosure.
[0017] Figure 10 illustrates an example of a UE in accordance with aspects of the present disclosure.
[0018] Figure 11 illustrates an example of a processor in accordance with aspects of the present disclosure.
[0019] Figure 12 illustrates an example of an NE in accordance with aspects of the present disclosure.
[0020] Figure 13 illustrates a flowchart of a method performed by a NE in accordance with aspects of the present disclosure.
[0021] Figure 14 illustrates a flowchart of a method performed by a NE in accordance with aspects of the present disclosure.DETAILED DESCRIPTION
[0022] A wireless communication system may include one or more UE and NE. The one or more UE and NE may exchange data with each other. The data may be exchanged in the form of data packets. An example of a data packet is a QUIC packet.
[0023] A data packet may contain a header and a payload. The payload may comprise media data. The media data itself may have been originally generated by an application. The header of the data packet may comprise MRI associated with the media data. The MRI may comprise a protocol data unit (PDU) set information, an end of data burst indication, an expedited transfer indication, a data burst size, and / or a time to next burst, for example.
[0024] The security of a data packet is important in a wireless communication system for a number of reasons. A data packet may contain confidential or otherwise sensitive information that unauthorized entities are not permitted to access. Such sensitiveDocket No. SMM920250200-GR-NPinformation may, for example, contain commercially valuable, financially valuable, or personally sensitive information. The integrity of a data packet is also important, to ensure that the data received in the data packet is the data that was originally transmitted.
[0025] A data packet may be routed through a tunnel so as to provide a protected path between NE. The data packet may be encapsulated within (i.e., is proxied by) a further data packet, preserving the security and integrity of the encapsulated data packet as it is transmitted between NE (i.e., between a first network entity and a second network entity). An example of tunnelling is proxying user datagram protocol (UDP) in hypertext transfer protocol (HTTP) / 3.
[0026] In the third-generation partnership project (3 GPP), a forwarded mode has been introduced that is an extension of proxying UDP in HTTP / 3. The forwarded mode allows for the forwarding of transforms of QUIC short header packets without any encapsulation. For 3 GPP the transforms of the QUIC short header packets tend to include MRI which may be further encrypted using a key. However, the key tends to be used with unencrypted information i.e., a nonce counter and a virtual connection ID (VCID) present in the transforms of the QUIC short header packets. Accordingly, the transforms of the QUIC short header packets tend to be vulnerable to active and / or passive attacks from malicious parties.
[0027] In a passive attack, an attacker may attempt to identify the sender, a recipient, or an end user (i.e., a client) of the data packet by correlating the traffic (i.e., a plurality of data packets) transmitted in a wireless communication system. In an active attack, the attacker may directly intercept data packets to eavesdrop on the data being communicated, to inject their own data packets into the communication, to disguise data packets or to repeat data packets for malicious purposes (such as to create network loops).
[0028] The encryption of the transforms of the QUIC short header packets may be a partial or a full encryption. By providing such an encryption of the transforms of the QUIC short header packets, the security and integrity of the transforms used to convey the MRI and its related information between a first network entity and a second network entity tends to be maintained. For an operator of a wireless communication system or network, this canDocket No. SMM920250200-GR-NPpreserve the confidentiality, integrity, and availability of the services delivered over the system / network.
[0029] Aspects of the present disclosure are described in the context of a wireless communications system.
[0030] Figure 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more NE 102, one or more UE 104, and a core network (CN) 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LTE-Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a NR network, such as a 5G network, a 5G-Advanced (5G-A) network, or a 5G ultrawideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA), etc.
[0031] The one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NE 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, a radio access network (RAN), a NodeB, an eNodeB (eNB), a next-generation NodeB (gNB), or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link, which may be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g., receive signalling, transmit signalling) over a Uu interface.
[0032] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For Docket No. SMM920250200-GR-NPexample, an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102.
[0033] The one or more UE 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Internet-of-Things (loT) device, an Internet-of-Everything (loE) device, or machine-type communication (MTC) device, among other examples.
[0034] A UE 104 may be able to support wireless communication directly with other UEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.
[0035] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., SI, N2, N2, or network interface). In some implementations, the NE 102 may communicate with each other directly. In some other implementations, the NE 102 may communicate with each other or indirectly (e.g., via the CN 106. In some implementations, one or more NE 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC). An ANC may communicate with the one or more UEs 104 through one or more otherDocket No. SMM920250200-GR-NPaccess network transmission entities, which may be referred to as a radio heads, smart radio heads, or transmission-reception points (TRPs).
[0036] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC), or a 5G core (5GC), which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME), an access and mobility management functions (AMF)) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW), a Packet Data Network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for the one or more UEs 104 served by the one or more NE 102 associated with the CN 106.
[0037] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g., via an SI, N2, N2, or another network interface). The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g., a PDU session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g., control information, data, and the like) between the UE 104 and the application server using the established session (e.g., the established PDU session). The PDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g., one or more network functions of the CN 106).
[0038] In the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communications). In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104 may support various frame structuresDocket No. SMM920250200-GR-NP(i.e., multiple frame structures). The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.
[0039] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., / t=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., / t=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., / / =1) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., g=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., / t=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., / t=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.
[0040] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames). Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.
[0041] Additionally, or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e., / t=0, / t=l, =2, jtz=3, =4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a Docket No. SMM920250200-GR-NPnumerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing), a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., / t=0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.
[0042] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data). In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.
[0043] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies). For example, FR1 may be associated with a first numerology (e.g., / t=0), which includes 15 kHz subcarrier spacing; a second numerology (e.g., / / =1), which includes 30 kHz subcarrier spacing; and a third numerology (e.g., / / =2), which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies). For example, FR2 may be associated with a third numerology (e.g., / z=2), which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., / t=3), which includes 120 kHz subcarrier spacing.
[0044] The 3GPP Technical Specification TS 33.501 titled “Security architecture and procedures for 5G system” introduces a new transform for the forwarded mode described in the IETF draft ‘draft-ietf-masque-quic-proxy’ titled “QUIC Aware Proxying Using HTTP”.Docket No. SMM920250200-GR-NPThe new transform may be applied to QUIC short header packets. The new transform tends to have, however, certain flaws which can result in both passive and active attacks on the content of the transformed packets.
[0045] The forwarded mode has been described in the IETF draft ‘draft-ietf-masque-quic-proxy,’ incorporated herein by reference, and can be considered as an extension on proxying UDP in HTTP / 3 as described in the IETF Standard RFC 9298 titled “Proxying UDP in HTTP”. The forwarded mode allows the proxy (e.g., the HTTP / 3 proxy) to reuse the UDP 4-tuples for multiple connections for forwarding transforms of the QUIC short header packets, defined in the IETF Standard RFC 9000 titled “A UDP -Based Multiplexed and Secure Transport”, without any encapsulation for the QUIC connection. There are two transforms defined in the IETF draft ‘draft-ietf-masque-quic-proxy’. The two transforms are referred to as the ‘identity transform’ and the ‘scramble transform.’ The identity transform does not modify the packet being transmitted and hence is not recommended to be used if the scramble transport is supported. The scramble transform relies on an encryption based on the AES-128 block cipher, which is represented by the syntax AES-electronic code book (ECB) as described in the IETF Standard RFC 9001 titled “Using TLS to Secure QUIC”. Although the scramble transform is more secure than the identity transform, it is still not considered as a secure mode of communicating QUIC short header packets.
[0046] For 3 GPP, the transform of the QUIC short header packets contains MRI information in the header of the transform and the encrypted MRI with the related information for such an encryption. The encryption of the MRI is described in the 3 GPP Technical Specification TS 33.501 titled “Security Architecture and procedures for 5G system”. The encryption of the MRI may be based on an AES-CCM mode operation, which provides both authentication and encryption. The remainder of the transform tends to be unencrypted, except the payload of the transformed packets, which may be (independently from any transport) end-to-end encrypted between an application server (AS) and a device such as a UE.
[0047] Figure 2 illustrates an example of a transformed QUIC short header packet 200 with MRI. The example represents the transform of the QUIC short header packet proposedDocket No. SMM920250200-GR-NPin the 3GPP Technical Specification TS 33.501 titled “Security architecture and procedures for 5G system”.
[0048] The transformed QUIC short header packet 200 includes additional header information compared to the header information available in the QUIC short header packet as will now be described.
[0049] A first information 210 may be included in the transformed QUIC short header packet 200. The first information 210 may comprise one or more of Header Form, Fixed Bit, Spin Bit, Reserved Bits, Key Phase, and Packet Number Length, which may be set according to section 17.3.1 of the IETF Standard RFC 9000 titled “A UDP -Based Multiplexed and Secure Transport”. The first information 210 may comprise a Packet Number which may be set to the number of the transformed QUIC short header packet. The first information 210 is unencrypted.
[0050] A second information 220 may be included in the transformed QUIC short header packet 200. The second information 220 may include a Destination Connection ID that is set to a mapping Virtual Connection ID (VCID). The VCID is additional header information compared to header information available in the QUIC short header packet. The second information 220 is unencrypted.
[0051] A third information 230 may be included in the transformed QUIC short header packet 200. The second information 230 may comprise a Nonce Counter set as defined in clause 18.2.3 of the 3GPP Technical Specification TS 33.501 titled “Security architecture and procedures for 5G system”. The third information 230 is additional header information compared to header information available in the QUIC short header packet. The third information 230 is unencrypted.
[0052] A fourth information 240 may be included in the transformed QUIC short header packet 200. The fourth information 240 may include a Length of MRI encoded in the number of bytes as defined in clause 18.2.3 of the 3GPP Technical Specification TS 33.501. The fourth information 240 is additional header information compared to header information available in the QUIC short header packet. The fourth information 240 is unencrypted.Docket No. SMM920250200-GR-NP
[0053] A fifth information 250 may be included in the transformed QUIC short header packet 200. The fifth information 250 may include Protected MRI which may be the output of a security algorithm defined in clause 18.2.4 of the 3GPP Technical Specification TS 33.501. The security algorithm may take as an input, the MRI container, as defined in clause 22.2 of the 3GPP Technical Specification TS 29.561 titled “5G System;Interworking between 5G Network and external Data Networks; Stage 3”. The fifth information 250 is additional header information compared to header information available in the QUIC short header packet. The fifth information 250 may be encrypted according to AES-CCM.
[0054] A sixth information 260 may be included in the transformed QUIC short header packet 200. The sixth information 260 may include a Packet Payload 260 set to the end-to-end protected data.
[0055] Figure 3 illustrates an example of a nonce 300 used for AES-CCM in accordance with aspects of the present disclosure. The nonce 300 may be used to encrypt the protected MRI of the fifth information 250 of Figure 2.
[0056] The nonce 300 may be a 96-bit nonce comprises the 32 least significant bits (LSB) 310 of a VCID. The VCID may be the VCID of the second information 220 of Figure 2. The nonce 300 further comprises a 64-bit counter 320 comprising a 16-bit nonce counter field 322. The 16-bit nonce counter field 322 may be the nonce counter of the third information 230 of Figure 2.
[0057] According to the clauses 18.2.4 and 18.2.6 of the 3GPP Technical Specification TS 33.501 titled “Security architecture and procedures for 5G system”, the 96 bit nonce 300 is created to invoke the encryption for the protected MRI of the fifth information 250 of Figure 2, by concatenating the least significant 32 bits of the VCID of the second information 220 of Figure 2 with the 64-bit counter 320, which itself is initiated by the 16 bits of the Nonce Counter of the third information 230 of Figure 2. The 64-bit counter 320 is incremented by one for the consecutive transformed QUIC short header packets 200 for each VCID of the second information 220.Docket No. SMM920250200-GR-NP
[0058] Since the key for the encryption of the protected MRI of the fifth information 250 in Figure 2 is used with the unprotected bits of the Nonce Counter of the third information 230 and the VCID of the second information 220, the configuration of the transformed QUIC short header packet 200 can result in a vulnerability to a number of active and passive attacks. Examples of active and passive attacks will now be described with reference to Figures 2 and 3. The examples of active and passive attacks are not intended to be limiting.
[0059] In a passive attack, an attacker attempts to identify a client by correlating the traffic of the transformed QUIC short header packets 200. Such a cross correlating tends to be trivial if the transformed QUIC short header packets 200 are partially exposed, which is the case for the transformed QUIC short header packets 200 shown in Figure 2. The transformed QUIC short header packets 200 shown in Figure 2 expose in addition, the targeted servers for the clients by mapping the incoming and outgoing transformed packets at the proxy.
[0060] Active attacks may comprise packet interception, packet injection, packet spoofing and packet repeating.
[0061] In packet interception the unprotected VCID of the second information 220 and Nonce Counter of the third information 230 allow an attacker to eavesdrop the transmitted transformed QUIC short header packets 200 by creating the 96 bits nonce 300 of Figure 3 and therefrom decrypt the forwarded transformed QUIC short header packets 200.
[0062] In packet injection, the Destination Connection ID in the transformed QUIC short header packet 200 shown in Figure 2, is set to the VCID of the second information 220 assigned by the proxy to be used on the client-to-proxy 4-tuple in forwarded mode. The unencrypted VCID of the second information 220 can result in an active attacker being able to inject transformed packets for certain VCIDs.
[0063] In packet spoofing the exposed VCIDs of the second information 220 can result in that an active attacker disguising transformed packets as being transmitted over the client-to-proxy 4-tuple in forwarded mode.Docket No. SMM920250200-GR-NP
[0064] Packet repeating, whilst often used legitimately to improve reliability, can be used maliciously to cause undesirable side effects such as network loops where the transformed QUIC short header packets 200 circulate endlessly.
[0065] Figure 4 illustrates an example of a transformed QUIC short header packet 400 with MRI in accordance with aspects of the present disclosure. In this example, to prevent some of the passive and active attacks described herein, the AES-CCM ciphering algorithm as described in the 3GPP Technical Specification TS 33.501 is used for the transformed QUIC short header packet 400.
[0066] The transformed QUIC short header packet 400 includes a first information 410, second information 420, third information 430, fourth information 440, fifth information 460 and sixth information 460 as will now be described.
[0067] The first information 410 may be included in the transformed QUIC short header packet 400. The first information 410 may comprise one or more of Header Form, Fixed Bit, Spin Bit, Reserved Bits, Key Phase, Packet Number Length and Packet Number. The first information 410 may be the same as the first information 210 of Figure 2.However, the first information 410 may be encrypted by using AES-CCM ciphering algorithm as per the 3GPP Technical Specification TS 33.501.
[0068] The second information 420 may be included in the transformed QUIC short header packet 400. The second information 420 may include a Destination Connection ID set to VCID as per the second information 220 of Figure 2. However, the VCID may be, with the exception of the least significant 32 bits, encrypted by using the AES-CCM ciphering algorithm as per the 3GPP Technical Specification TS 33.501.
[0069] As per clause 18.2.6 of the 3GPP Technical Specification TS 33.501, a 96-bit nonce is created to invoke the encryption by concatenating the least significant 32 bits of the VCID with the 64-bit counter which is calculated by the received unencrypted value from a Nonce Counter Field of the third information 430 of the transformed QUIC short header packet 400. Therefore, the least significant 32 bits of the VCID may be unencrypted.
[0070] The third information 430 may be included in the transformed QUIC short header packet 400. The third information 430 may include a Nonce Counter Field . The Docket No. SMM920250200-GR-NPthird information 430 may be the same as in the third information 230 of Figure 2. The third information 430 is unencrypted.
[0071] The fourth information 440 may be included in the transformed QUIC short header packet 400. The fourth information 440 may include a Length of MRI that is encoded in the number of bytes as defined in clause 18.2.3 of the 3GPP Technical Specification TS 33.501. The fourth information 440 may be the same as the fourth information 240 of Figure 2. The fourth information 440 is unencrypted.
[0072] The fifth information 450 may be included in the transformed QUIC short header packet 400. The fifth information 450 may include aProtected MRI that comprises the output of a security algorithm defined in clause 18.2.4 of the 3GPP Technical Specification TS 33.501. The security algorithm may take as an input the MRI container, defined in clause 22.2 of the 3GPP TS 29.561 titled “5G System; Interworking between 5G Network and external Data Networks; Stage 3”. The fifth information 450 may be the same as the fifth information 250 of Figure 2.
[0073] The sixth information 460 may be included in the transformed QUIC short header packet 400. The sixth information 460 may include a Packet Payload. The sixth information 460 may be the same as the sixth information 260 of Figure 2, but with the packet payload re-encrypted using the AES-CCM ciphering algorithm as described in the 3GPP Technical Specification TS 33.501 in addition to the end-to-end encryption.
[0074] Although the described transformed QUIC short header packet 400 in this example tends to prevent some of the attacks described herein, it may still be vulnerable to packet interception because an attacker can create the key for the encryption / decryption by accessing the unprotected 32 LSB of the VCID of the second information 420 and the Nonce Counter of the third information 430.
[0075] Figure 5 illustrates a further example of a transformed QUIC short header packet 500 with MRI in accordance with aspects of the present disclosure. In this example, to further mitigate some of the passive and active attacks described herein, the transformed QUIC short header packet 400 is a modification of the scramble transform defined in theDocket No. SMM920250200-GR-NPIETF draft document ‘draft-ietf-masque-quic-proxy’ titled “QUIC-Aware Proxying Using HTTP”.
[0076] The transformed QUIC short header packet 500 comprises a first information 510, second information 520, third information 530, fourth information 540, fifth information 550 and sixth information 560 as will now be described.
[0077] The first information 510 may be included in the transformed QUIC short header packet 500. The first information 510 may comprise one or more of Header Form, Fixed Bit, Spin Bit, Reserved Bits, Key Phase, Packet Number Length, and Packet Number. The first information 510 may be the same as the first information 210 of Figure 2, however the first information 510 are part of the scramble transform described in the IETF draft document ‘draft-ietf-masque-quic-proxy’ titled “QUIC-Aware Proxying Using HTTP”.
[0078] The second information 520 may be included in the transformed QUIC short header packet 500. The second information 520 may comprise Destination Connection ID set to a VCID. The second information 520 may be the same as the second information 220 of Figure 2, however the second information 520 is part of the scramble transform as described in the IETF draft document ‘draft-ietf-masque-quic-proxy’.
[0079] The third information 530 may be included in the transformed QUIC short header packet 500. The third information 530 may comprise a Nonce Counter. The third information 530 may be the same as the third information 230, however the third information 530 is encrypted by using an AES-ECB ciphering algorithm which is used for scramble transfer as per the IETF draft document ‘draft-ietf-masque-quic-proxy’.
[0080] The fourth information 540 may be included in the transformed QUIC short header packet 500. The fourth information 540 may comprise a Length of protected MRI. The fourth information 540 may be the same as the fourth information 240 of Figure 2, however the fourth information 540 is encrypted by using the AES-CCM ciphering algorithm.
[0081] The fifth information 550 may be included in the transformed QUIC short header packet 500. The fifth information 550 may comprise a Protected MRI that is the Docket No. SMM920250200-GR-NPoutput of the security algorithm defined in clause 18.2.4 of the 3GPP Technical Specification TS 33.501 titled “Security architecture and procedures for 5G system”. The security algorithm may take as an input the MRI container, as defined in clause 22.2 of the 3GPP Technical Specification TS 29.561 titled “5G System; Interworking between 5G Network and external Data Networks; Stage 3”. The security algorithm may be AES-CCM. The fifth information 550 may be the same as the fifth information 250 of Figure 2.
[0082] The sixth information 560 may be included in the transformed QUIC short header packet 500. The sixth information 560 may comprise a Packet Payload. The sixth information 560 may be the same as the sixth information 260 of Figure 2, however the sixth information 560 may be re-encrypted as being a part of the scramble transform as per the IETF draft document ‘draft-ietf-masque-quic-proxy’ in addition to the end-to-end encryption.
[0083] In the transformed QUIC short header packet, the same key for the ciphering algorithm AES-ECB which is used for the scramble transfer (as per the IETF draft document ‘draft-ietf-masque-quic-proxy’), may be used for all the VCIDs of the second information 520. This key, which may be shared at the time of establishment of the forwarded mode, is used to decrypt the Nonce Counter of the third information 530 and the VCID of the second information 520 in order to later create the nonce for the AES-CCM encryption algorithm.
[0084] Figure 6 illustrates a further example of a transformed QUIC short header packet 600 with MRI in accordance with aspects of the present disclosure.
[0085] The transformed QUIC short header packet 600 comprises a first information 610, second information 620, third information 630, fourth information 640, fifth information 650 and sixth information 660 as will now be described.
[0086] This transformed QUIC short header packet 600 is similar to the transformed QUIC short header packet 500 of Figure 5 but with the following differences. The first information 610 is encrypted but is not limited to the scramble transform. The second information 620 is encrypted but is not limited to the scramble transform. The third information 630 is encrypted but is not limited to being AES-ECB encrypted. The fourthDocket No. SMM920250200-GR-NPinformation 640 is encrypted but is not limited to the AES-CCM or AES-ECB encryption. The fifth information 650 is AES-CCM encrypted. The sixth information 660 is reencrypted but not limited to the scramble transform.
[0087] More generally, the ciphering algorithm is not limited to AES-ECB which is used for the scramble transfer (as per the IETF draft document ‘draft-ietf-masque-quic-proxy’). Accordingly, the key which is used for the ciphering algorithm (which is the same for all the VCIDs of the second information 620), may be shared at the time of establishment of the forwarded mode as per the IETF draft document ‘draft-ietf-masque-quic-proxy’.
[0088] Figure 7 illustrates a further example of a transformed QUIC short header packet 700 with MRI in accordance with aspects of the present disclosure. In this example to further mitigate some of the passive and active attacks described herein, the AES-CCM ciphering algorithm as per the 3GPP Technical Specification TS 33.501 titled “Security architecture and procedures for 5G system” is used for the transformed QUIC short header packet 700.
[0089] The transformed QUIC short header packet 700 comprises a first information 710, a second information 720, a third information 730, a fourth information 740, a fifth information 750 and a sixth information 760 as will now be described.
[0090] The first information 710 may be included in the transformed QUIC short header packet 700. The first information 710 may comprise one or more Header Form, Fixed Bit, Spin Bit, Reserved Bits, Key Phase, Packet Number Length, and Packet Number. The first information 710 may be the same as the first information 210 of Figure 2 but with the first information 710 being encrypted by using an AES-CCM ciphering algorithm as per the 3GPP Technical Specification TS 33.501.
[0091] The second information 720 may be included in the transformed QUIC short header packet 700. The second information 720 may comprise a Destination Connection ID set to a VCID. The second information 720 may be the same as the second information 220 of Figure 2 but with the second information 720 being encrypted by using the AES-CCM ciphering algorithm as per the 3GPP Technical Specification TS 33.501.Docket No. SMM920250200-GR-NP
[0092] The third information 730 may be included in the transformed QUIC short header packet 700. The third information 730 may comprise a Nonce Counter Field. The third information 730 may be the same as the third information 230 of Figure 2 but with the third information 730 being encrypted by using the AES-CCM ciphering algorithm as per the 3GPP Technical Specification TS 33.501.
[0093] The fourth information 740 may be included in the transformed QUIC short header packet 700. The fourth information 740 may comprise a Length of MRI. The fourth information 740 may be the same as the fourth information 240 of Figure 2 but with the fourth information 740 being encrypted by using the AES-CCM ciphering algorithm as per the 3GPP Technical Specification TS 33.501.
[0094] The fifth information 750 may be included in the transformed QUIC short header packet 700. The fifth information 750 may comprise a Protected MRI that is the output of a security algorithm defined in clause 18.2.4 of the 3GPP Technical Specification TS 33.501 which takes as an input the MRI container, defined in clause 22.2 of the 3GPP Technical Specification TS 29.561 titled “5G System; Interworking between 5G Network and external Data Networks; Stage 3”. The fifth information 750 may be the same as the fifth information 250 of Figure 2 but with the fifth information 750 being encrypted using the AES-CCM ciphering algorithm.
[0095] The sixth information 760 may be included in the transformed QUIC short header packet 700. The sixth information 760 may comprise a Packet Payload. The sixth information 760 may be the same as the sixth information 260 of Figure 2 but with the sixth information 760 being re-encrypted by using an AES-CCM ciphering algorithm as per the 3GPP Technical Specification TS 33.501 in addition to the end-to-end encryption.
[0096] Decryption of the received transformed QUIC short header packets 700 may not be possible with the configuration in Figure 7, if the Nonce Counter of the third information 730 and the 32 LSB of the VCID of the second information 720 are protected by the AES-CCM encryption algorithm. Therefore, if the Nonce Counter of the third information 730 and the 32 LSB of VCID of the second information 720 are protected in the transformed QUIC short header packets 700, the un-protected Nonce Counter and the 32 LSB of Virtual Connection ID can be transmitted reliably on the corresponding HTTP / 3 messages QUIC Docket No. SMM920250200-GR-NPstream when, for example, establishing the Forwarded Mode described in the IETF draft document ‘draft-ietf-masque-quic-proxy’ titled “QUIC-Aware Proxying Using HTTP”. The un-protected Nonce Counter and the 32 LSB of Virtual Connection ID may also be updated or retransmitted reliably on the corresponding HTTP / 3 messages. These corresponding HTTP / 3 messages may be the same as that used for synchronization of the counter as described in clause 18.2.6 of the 3GPP Technical Specification TS 33.501.
[0097] A UPF may receive unprotected Nonce Counters and 32 least significant bits of VCIDs for an amount of k different connections, {[NC_1, VCID_1(32)], [NC_2, VCID_2(32)], ..., [NC_k, VCID_k(32)]}. If the same Nonce Counter is used for the k different connections, the received set by the UPF is {NC, VCID_1(32), VCID_2(32), ..., VCID_k(32)}.
[0098] On the receiver side, the received forwarded transformed QUIC short header packets 700 are decrypted by the already available the Nonce Counter and the 32 LSB of VCID pairs.
[0099] Figure 8 illustrates an example 800 of decryption of a protected transformed QUIC short header packet with MRI in accordance with aspects of the present disclosure. The figure illustrates when the encrypted packets are decrypted with the Nonce Counter and the 32 LSB of VCID pairs.
[0100] The example 800 shows an input 810, a decryption process 820, and an output 830. The input 810 may be an input to the decryption process 820. The output 830 may be an output from the decryption process 820.
[0101] The input 810 may comprise a transformed QUIC short header packet with MRI. The transformed QUIC short header packet may be the transformed QUIC short header packet 700 as described herein, for example with respect to Figure 7. The transformed QUIC short header packet may be encrypted using a key.
[0102] The decryption process 820 shows a plurality of different keys 820a, 820b, 820c, 820d that may be applied to the input 810. The key 820a is shown as “Key(NC_l, VCID_1(32))”. The key 820b is shown as “Key(NC_2, VCID_2(32))”. The key 820c isDocket No. SMM920250200-GR-NPshown as “Key(NC_i, VCID_i(32))”. The key 820d is shown as “Key(NC_k, VCID_k(32))”.
[0103] The output 830 includes a plurality of outputs 830a, 830b, 830c, 830d corresponding to the different keys 820a, 820b, 820c, 820d. The outputs 830a, 830b and 830d are shown as “XXXXXXXXXX”. The output 830c is shown as “Transformed packet (..., NC_i, VCID_i(32), ..More specifically, only the output 830c of the plurality of outputs 830a, 830b, 830c, 830d is a decryption of the same Nonce Counter and 32 LSB of VCID pair that results into the same pair. Therefore, the transformed QUIC short header packet of the input 810 is for that particular Virtual Connection ID with the same 32 LSB as in the Nonce Counter and the 32 LSB of VCID pair. The receiver, i.e., UPF, in the same manner, can separate all the received protected transformed packets for all the VCIDs in the established Forwarded Mode.
[0104] The parameters NC_1, NC_2, ... NC_k may have the same values if the Nonce Counter is the same for all the k different Virtual Connection IDs.
[0105] Figure 9 illustrates an example of a process flow 900 that establishes a forwarded mode between an AS and a user plane function (UPF) in accordance with aspects of the present disclosure.
[0106] The process flow 900 may implement or be implemented by aspects of the wireless communication system 100. For example, the process flow 900 may include an UE 910, an UPF 920, a session management function (SMF) 930, a policy control function (PCF) 940, an application function (AF) 950, an AS 960, which may be one or more examples of devices described herein with reference to Figure 1.
[0107] The process flow 900 may be referred to as a procedure, including one or more operations performed by one or more of the UE 910, UPF 920, SMF 930, PCF 940, AF 950, AS 960. In the example of Figure 9, the process flow 900 may include establishing the forwarded mode according to the IETF draft document ‘draft-ietf-masque-quic-proxy’ titled “QUIC-Aware Proxying Using HTTP”.
[0108] In the following description of the process flow 900, the operations or signalling performed between one or more of the UE 910, UPF 920, SMF 930, PCF 940, AF 950, AS Docket No. SMM920250200-GR-NP960 may be performed or signalled (e.g., transmitted, received) in a different order than the example order shown, or the operations or signalling performed by one or more of the UE 910, UPF 920, SMF 930, PCF 940, AF 950, AS 960 may be performed or signalled (e.g., transmitted, received) in different orders or at different times. Some operations or signalling may also be omitted from the process flow 900. Additionally, although some operations or signalling may be shown to occur at different times, these operations or signalling may occur at the same time or in overlapping time periods.
[0109] In step 901, the AF950 transmits a request to the PCF 940. The request may be for the UPF 920 to establish a session with the AS 960. The session may be an AF session. When requesting the AF session towards the 3 GPP network (i.e., to the PCF 940 / NEF), the AF 950 may include in the request additional information indicating to the 3GPP network that the UPF 920 needs to establish a QUIC / connect-UDP session with an HTTP / 3 proxy. The request may also indicate that the UPF 920 can identify MRI within UDP options. The AF 950 may also include in the request the address of an HTTP / 3 proxy server and the initial keys for security (see, for example, the IETF Standard RFC 9001 titled “Using TLS to Secure QUIC”) that the UPF 920 will need to establish a QUIC session. The PCF 940 may receive the request from the AF 950.
[0110] In step 902, the PCF 940 in the 3GPP network transmits PCC rules to the SMF 930. The SMF 930 may receive the PCC rules from the PCF 940. The PCC rules may include the information provided by the AF 950 in step 901.[OHl] In step 903, the SMF 930 may construct N4 rules from / based on the PCC rules received from the PCF 940. The N4 rules may include uplink and downlink Packet Detection Rules (PDR). The packet detection rules may indicate to the UPF 920 that for uplink packets sent from a specific UE 910 (or any UE) to a specific AS 960, the UPF 920 would need to establish a QUIC / connect-UDP session and route the packet within an HTTP Datagram to the address of the AS 960. The packet detection rules may indicate configuration information to the UPF 920 for downlink packets received from the QUIC connection by the UPF 920 over N6. For example, the configuration information may indicate to the UPF 920 to: extract the one or more real time protocol (RTP) packets from the received HTTP Datagram with the Context ID set to zero as defined in the IETFDocket No. SMM920250200-GR-NPStandard RFC 9298 titled “Proxying UDP in HTTP”; extract the MRI from the UDP options; and / or route the extracted MRI and one or more RTP packets over a QoS flow with PSDB requirements and PSER requirements towards a RAN.
[0112] In step 904, the SMF 930 transmits / sends the N4 rules to the UPF 920 that supports an HTTP / 3 client to establish a QUIC connection to create a tunnel for UDP communications with an HTTP / 3 server when a data packet is received that matches the PDR provided by the SMF 930.
[0113] In steps 905-906, upon the receipt of the N4 rule, the UPF 920 acting as the client, may transmit a request to the AS 960 to establish a UDP tunnel and a Forwarded Mode as described in the IETF draft document ‘draft-ietf-masque-quic-proxy’ to receive transformed QUIC short header packets containing the MRI, if both the HTTP proxy and the UPF 920 support the requirements for the Forwarded Mode. The AS 960 may receive the request. The AS 960 may transmit a response to the UPF 920. The UPF 920 may receive the response.
[0114] The transforms of the QUIC short header data packets are described for Figures 4-7 described herein may be used in the process flow 900. Accordingly, at step 905-906 the key for encryption of Nonce Counter and Virtual Connection ID may be shared between the UPF 920 and the AS 960; or the Nonce Counter and the 32 LSB of the VCID pairs with any related configurations may be shared.
[0115] In steps 907-908, prior to forwarding the transformed QUIC short header data packets to the UPF 920, the AS 960 may initially transmit to then UPF 920 the transformed short header data packets by using the established UDP tunnelling as described in the IETF Standard RFC 9298. However, once the Forwarded Mode has been established the transformed QUIC short header data packets may be forwarded towards the UPF 920 using the forwarded mode. During the establishment of the forwarded mode, both the UPF 920 and the HTTP proxy (the AS 960) inform each other that they are capable to encode and decode the transformed QUIC short header packets as described herein.
[0116] In step 909, the encrypted QUIC short header packets and the MRI, obtained from the transformed QUIC short header packets, are transmitted by the UPF 920 via a QoSDocket No. SMM920250200-GR-NPflow to the UE 910. The QoS flow may have PSDB requirements and / or PSER requirements.
[0117] When the synchronization of the counter as described in clause 18.2.6 of the 3GPP Technical Specification TS 33.501 occurs, the un-protected Nonce Counter and the 32 LSB of Virtual Connection ID pairs may also be updated or retransmitted reliably on the corresponding HTTP / 3 messages.
[0118] Any one of, or all of, the examples described herein, may create a different transform than the one in the 3GPP Technical Specification TS 29.561 . Accordingly, a new Internet Assigned Numbers Authority (IANA) registration may be needed for any of the new transforms described herein.
[0119] Furthermore, the creation of the nonce is not limited to the 32 least significant bits of a VCID as per the 3GPP Technical Specification TS 33.501. Any other numbers of bits may be used.
[0120] Figure 10 illustrates an example of a UE 1000 in accordance with aspects of the present disclosure. The UE 1000 may include a processor 1002, a memory 1004, a controller 1006, and a transceiver 1008. The processor 1002, the memory 1004, the controller 1006, or the transceiver 1008, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0121] The processor 1002, the memory 1004, the controller 1006, or the transceiver 1008, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0122] The processor 1002 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In Docket No. SMM920250200-GR-NPsome implementations, the processor 1002 may be configured to operate the memory 1004. In some other implementations, the memory 1004 may be integrated into the processor 1002. The processor 1002 may be configured to execute computer-readable instructions stored in the memory 1004 to cause the UE 1000 to perform various functions of the present disclosure.
[0123] The memory 1004 may include volatile or non-volatile memory. The memory 1004 may store computer-readable, computer-executable code including instructions when executed by the processor 1002 cause the UE 1000 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 1004 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0124] In some implementations, the processor 1002 and the memory 1004 coupled with the processor 1002 may be configured to cause the UE 1000 to perform one or more of the functions described herein (e.g., executing, by the processor 1002, instructions stored in the memory 1004). For example, the processor 1002 may support wireless communication at the UE 1000 in accordance with examples as disclosed herein. The UE 1000 may be configured to support the arrangements described herein.
[0125] The controller 1006 may manage input and output signals for the UE 1000. The controller 1006 may also manage peripherals not integrated into the UE 1000. In some implementations, the controller 1006 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 1006 may be implemented as part of the processor 1002.
[0126] In some implementations, the UE 1000 may include at least one transceiver 1008. In some other implementations, the UE 1000 may have more than one transceiver 1008. The transceiver 1008 may represent a wireless transceiver. The transceiver 1008 may include one or more receiver chains 1010, one or more transmitter chains 1012, or a combination thereof.Docket No. SMM920250200-GR-NP
[0127] A receiver chain 1010 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 1010 may include one or more antennas for receive the signal over the air or wireless medium. The receiver chain 1010 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 1010 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 1010 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.
[0128] A transmitter chain 1012 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 1012 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 1012 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 1012 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0129] Figure 11 illustrates an example of a processor 1100 in accordance with aspects of the present disclosure. The processor 1100 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 1100 may include a controller 1102 configured to perform various operations in accordance with examples as described herein. The processor 1100 may optionally include at least one memory 1104, which may be, for example, an L1 / L2 / L3 cache. Additionally, or alternatively, the processor 1100 may optionally include one or more arithmetic-logic units (ALUs) 1106. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).Docket No. SMM920250200-GR-NP
[0130] The processor 1100 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 1100) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase change memory (PCM), and others).
[0131] The controller 1102 may be configured to manage and coordinate various operations (e.g., signalling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 1100 to cause the processor 1100 to support various operations in accordance with examples as described herein. For example, the controller 1102 may operate as a control unit of the processor 1100, generating control signals that manage the operation of various components of the processor 1100. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.
[0132] The controller 1102 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 1104 and determine subsequent instruction(s) to be executed to cause the processor 1100 to support various operations in accordance with examples as described herein. The controller 1102 may be configured to track memory address of instructions associated with the memory 1104. The controller 1102 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 1102 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 1100 to cause the processor 1100 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 1102 may be configured to manage flow of data within the processor 1100. The controller 1102 may be configured to controlDocket No. SMM920250200-GR-NPtransfer of data between registers, arithmetic logic units (ALUs), and other functional units of the processor 1100.
[0133] The memory 1104 may include one or more caches (e.g., memory local to or included in the processor 1100 or other memory, such RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementations, the memory 1104 may reside within or on a processor chipset (e.g., local to the processor 1100). In some other implementations, the memory 1104 may reside external to the processor chipset (e.g., remote to the processor 1100).
[0134] The memory 1104 may store computer-readable, computer-executable code including instructions that, when executed by the processor 1100, cause the processor 1100 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 1102 and / or the processor 1100 may be configured to execute computer-readable instructions stored in the memory 1104 to cause the processor 1100 to perform various functions. For example, the processor 1100 and / or the controller 1102 may be coupled with or to the memory 1104, the processor 1100, the controller 1102, and the memory 1104 may be configured to perform various functions described herein. In some examples, the processor 1100 may include multiple processors and the memory 1104 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.
[0135] The one or more ALUs 1106 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 1106 may reside within or on a processor chipset (e.g., the processor 1100). In some other implementations, the one or more ALUs 1106 may reside external to the processor chipset (e.g., the processor 1100). One or more ALUs 1106 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 1106 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 1106 be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logicDocket No. SMM920250200-GR-NPgates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 1106 may support logical operations such as AND, OR, exclusive-OR (XOR), not-OR (NOR), and not-AND (NAND), enabling the one or more ALUs 1106 to handle conditional operations, comparisons, and bitwise operations.
[0136] The processor 1100 may support wireless communication in accordance with examples as disclosed herein. The processor 1100 may be configured to support a means for a first network entity as described herein. The processor 1100 may be configured to cause the first network entity to: transmit, to a second network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing MRI, wherein the one or more transforms of the QUIC short header packets are encrypted; and receive, from the second network entity, a response to the request to establish the communication mode and the one or more transforms of the QUIC short header packets.
[0137] The processor 1100 may be configured to or operable to support a means for a second network entity as described herein. The processor 1100 may be configured to cause the second network entity to: receive, from a first network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing MRI, wherein the one or more transforms of QUIC short header packets are encrypted; and transmit, to the first network entity, a response to the request to establish the communication mode and the one or more transforms of QUIC short header packets.
[0138] Figure 12 illustrates an example of a NE 1200 in accordance with aspects of the present disclosure. The NE 1200 may include a processor 1202, a memory 1204, a controller 1206, and a transceiver 1208. The processor 1202, the memory 1204, the controller 1206, or the transceiver 1208, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0139] The processor 1202, the memory 1204, the controller 1206, or the transceiver 1208, or various combinations or components thereof may be implemented in hardware Docket No. SMM920250200-GR-NP(e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0140] The processor 1202 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 1202 may be configured to operate the memory 1204. In some other implementations, the memory 1204 may be integrated into the processor 1202. The processor 1202 may be configured to execute computer-readable instructions stored in the memory 1204 to cause the NE 1200 to perform various functions of the present disclosure.
[0141] The memory 1204 may include volatile or non-volatile memory. The memory 1204 may store computer-readable, computer-executable code including instructions when executed by the processor 1202 cause the NE 1200 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 1204 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0142] In some implementations, the processor 1202 and the memory 1204 coupled with the processor 1202 may be configured to cause the NE 1200 to perform one or more of the functions described herein (e.g., executing, by the processor 1202, instructions stored in the memory 1204). For example, the processor 1202 may support wireless communication at the NE 1200 in accordance with examples as disclosed herein. The NE 1200 may be configured to support a means for a first network entity as described herein. The NE 1200 may be configured to: transmit, to a second network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing MRI, wherein the one or more transforms of the QUIC short header packets are encrypted; and receive, from the second network entity, a response to theDocket No. SMM920250200-GR-NPrequest to establish the communication mode and the one or more transforms of the QUIC short header packets.
[0143] Alternatively, the NE 1200 may be configured to or operable to support a means for a second network entity. The NE 1200 may be configured to: receive, from a first network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing MRI, wherein the one or more transforms of QUIC short header packets are encrypted; and transmit, to the first network entity, a response to the request to establish the communication mode and the one or more transforms of QUIC short header packets.
[0144] The controller 1206 may manage input and output signals for the NE 1200. The controller 1206 may also manage peripherals not integrated into the NE 1200. In some implementations, the controller 1206 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 1206 may be implemented as part of the processor 1202.
[0145] In some implementations, the NE 1200 may include at least one transceiver 1208. In some other implementations, the NE 1200 may have more than one transceiver 1208. The transceiver 1208 may represent a wireless transceiver. The transceiver 1208 may include one or more receiver chains 1210, one or more transmitter chains 1212, or a combination thereof.
[0146] A receiver chain 1210 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 1210 may include one or more antennas for receive the signal over the air or wireless medium. The receiver chain 1210 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 1210 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 1210 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.Docket No. SMM920250200-GR-NP
[0147] A transmitter chain 1212 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 1212 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 1212 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 1212 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0148] Figure 13 illustrates a flowchart of a method 1300 in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.
[0149] At 1302, the method 1300 may include transmitting, to a second network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing MRI, wherein the one or more transforms of the QUIC short header packets are encrypted. The operations of 1302 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1302 may be performed by a NE as described with reference to Figure 12.
[0150] At 1304, the method 1300 may include receiving, from the second network entity, a response to the request to establish the communication mode and the one or more transforms of the QUIC short header packets. The operations of 1304 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1304 may be performed by a NE as described with reference to Figure 12.
[0151] It should be noted that the method 1300 described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.Docket No. SMM920250200-GR-NP
[0152] Figure 14 illustrates a flowchart of a method 1400 in accordance with aspects of the present disclosure. The operations of the method 1400 may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.
[0153] At 1402, the method 1400 may include receiving, from a first network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing MRI, wherein the one or more transforms of QUIC short header packets are encrypted. The operations of 1402 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1402 may be performed by a NE as described with reference to Figure 12.
[0154] At 1404, the method 1400 may include transmitting, to the first network entity, a response to the request to establish the communication mode and the one or more transforms of QUIC short header packets. The operations of 1404 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1404 may be performed by a NE as described with reference to Figure 12.
[0155] It should be noted that the method 1400 described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0156] A first network entity for wireless communication is described. The first network entity may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the first network entity may comprise at least one memory, and at least one processor coupled with the at least one memory and configured to cause the first network entity to: transmit, to a second network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing MRI wherein the one or more transforms of the QUIC short header packets are encrypted; and receive, from the second network entity, a response to the request to establish the communication mode and the one or more transforms of the QUIC short header packets.Docket No. SMM920250200-GR-NP
[0157] The communication mode may comprise a UDP tunnel and a forwarded mode. The at least one processor may be configured to cause the first network entity to: receive, from the second network entity, the response to the request to establish the communication mode; and receive, from the second network entity, using the forwarded mode, the one or more transforms of the QUIC short header packets.
[0158] The forwarded mode may be established using the HTTP Connect method initiated by the first network entity (i.e., a UPF acting as HTTP client) and the successful response by the second network entity (i.e., a AS acting as HTTP proxy). Once the forwarded mode is established, the transformed packets can be transmitted by the second network entity and received by the first network entity.
[0159] The one or more transforms of the QUIC short header packets may be entirely encrypted.
[0160] The QUIC short header packets may be partially or entirely encrypted. By entirely encrypting the transforms of the QUIC short header packets, passive, and active attacks on the transformed QUIC short header packets tend to be mitigated. This tends to further improve the security of the transformed QUIC short header packets transmitted in the forwarded mode.
[0161] The one or more transforms of the QUIC short header packets may be encrypted, at least in part, based on a ciphering algorithm.
[0162] The ciphering algorithm tends to enhance the confidentiality and robustness of data transmitted between the first and second network entities. The ciphering algorithm may transform the one or more transforms of the QUIC short header packets into an encoded representation such that the underlying MRI cannot be easily resolved by an unauthorized entity. The network entities, possessing the corresponding decryption information may be the only entities able to decrypt the transforms. The ciphering algorithm tends to mitigate active and passive attacks such as eavesdropping, data extraction, and unauthorized manipulation of the transforms during transmission.
[0163] The ciphering algorithm may encrypt the one or more transforms entirely, or may encrypt a part thereof, such as one or more headers, for example.Docket No. SMM920250200-GR-NP
[0164] The ciphering algorithm may be based at least in part on a nonce counter and a part of a VCID associated with the one or more transforms of the QUIC short header packets.
[0165] The ciphering algorithm may be based at least in part on a key. The response may comprise the key. The response may comprise an indication of the ciphering algorithm associated with the key.
[0166] At least one of the nonce counter, part of the VCID and payload of a respective transform may be encrypted based on the ciphering algorithm and key. The key tends to be shared by the second network entity at the time of establishing the forwarding mode, such that the transforms of the QUIC short header packets can be encrypted and decrypted. For example, proxy-quic-forwarding may be used for a proxy (i.e., the second network entity) to send the key to a client (i.e., the first network entity). The key may be shared by the second network entity whether the transforms of the QUIC short header packets are partially or entirely encrypted.
[0167] The supported transforms may be transmitted from the client towards the proxy in the proxy-quic-forwarding header. The proxy may then transmit, as a response, the supported transform, and the associated key. In 3GPP, if a transform with an associated ciphering is transmitted, the name of the transform may identify the associated ciphering key. For example, a proxy may indicate in the response the supported transform 3GPP XRM AESCCM 8, 3GPP XRM AESCCM 16, Keyl, Key2. The ‘KeyU is the ciphering key for AES CCM ciphering algorithm with 8-byte authentication tag. The ‘Key2’ is the ciphering key for AES CCM ciphering algorithm with 16-byte authentication tag. These examples are not intended to be limiting and can be expanded, for example, such that the transform name also identifies the application of the 3 GPP where the ciphering algorithm and key are used.
[0168] The response may comprise the nonce counter and the part of the VCID. The nonce counter and the part of the VCID may be included in the one or more transforms of the QUIC short header packets.Docket No. SMM920250200-GR-NP
[0169] The nonce counter and the part of the VCID may be included in an unprotected part of the one or more transforms. Alternatively, the nonce counter and the part of the VCID may be provided in the response to allow for decryption of the transforms.
[0170] The at least one of the MRI of a respective transform and a payload of the respective transform may be encrypted by the ciphering algorithm. The payload may comprise a media data associated with the MRI.
[0171] The media data may be encrypted by some other means.
[0172] The ciphering algorithm may comprise at least one of: an AES-CCM; and an AES-ECB.
[0173] The AES-CCM tends to provide combined confidentiality, integrity, and authentication for the transforms of the QUIC short header packets.
[0174] The AES ECB tends to provide a computationally efficient method for encryption.
[0175] The one or more transforms may comprise at least one of: an identity transform; a scramble transform; and another transform for partially or entirely encrypting a QUIC short header packet.
[0176] The identify transform of a QUIC short header packet may be a replica of the QUIC short header packet. For example, the header fields may stay the same. The scramble transform of a QUIC short header packet may be a rearranged, mixed, substituted or otherwise altered version of the QUIC header packet. For example, the scramble transform may change the QUIC header packet in some reversible way. Another transform may partially or entirely encrypt a QUIC short header packet. For example, another transform may encrypt a header of the QUIC short header packet, or the body of the QUIC short header packet, or a combination thereof.
[0177] The first network entity may be a UPF acting as an HTTP / 3 client. The second network entity may be an AS acting as an HTTP / 3 proxy.Docket No. SMM920250200-GR-NP
[0178] The at least one processor may be further configured to cause the first network entity to: decrypt the one or more QUIC short header packets to obtain the MRI; and transmit the MRI to a UE.
[0179] A second network entity for wireless communication is described. The second network entity may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the second network entity may comprise at least one memory, and at least one processor coupled with the at least one memory and configured to cause the second network entity to: receive, from a first network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing MRI, wherein the one or more transforms of QUIC short header packets are encrypted; and transmit, to the first network entity, a response to the request to establish the communication mode and the one or more transforms of QUIC short header packets.
[0180] The communication mode may comprise a UDP tunnel and a forwarded mode. The at least one processor may be configured to cause the second network entity to: transmit, to the first network entity, the response to the request to establish the communication mode; and transmit, to the first network entity, using the forwarded mode, the one or more transforms of the QUIC short header packets.
[0181] The one or more transforms of the QUIC short header packets may be entirely encrypted.
[0182] The one or more transforms of the QUIC short header packets may be encrypted based on a ciphering algorithm.
[0183] The ciphering algorithm may be based at least in part on a nonce counter and a part of a VCID associated with the one or more transforms of the QUIC short header packets.
[0184] The ciphering algorithm may be based at least in part on a key. The response may comprise the key. The response may comprise an indication of the ciphering algorithm associated with the key.Docket No. SMM920250200-GR-NP
[0185] The response may comprise the nonce counter and the part of the VCID. The nonce counter and the part of the VCID may be included in the one or more transforms of the QUIC short header packets.
[0186] At least one of the MRI of a respective transform and a payload of the respective transform may be encrypted by the ciphering algorithm. The payload may comprise a media data associated with the MRI.
[0187] The ciphering algorithm may comprise at least one of: an AES-CCM; and an AES-ECB.
[0188] The one or more transforms may comprise at least one of: an identity transform; a scramble transform; and another transform for partially or entirely encrypting a QUIC short header packet.
[0189] The first network entity may be a UPF acting as HTTP / 3 client. The second network entity may be an AS acting as HTTP / 3 proxy.
[0190] A method performed or performable by a first network entity is provided. The method may comprise: transmitting, to a second network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing MRI, wherein the one or more transforms of the QUIC short header packets are encrypted; receiving, from the second network entity, a response to the request to establish the communication mode and the one or more transforms of the QUIC short header packets.
[0191] The communication mode may comprise a UDP tunnel and a forwarded mode. The at least one processor may be configured to cause the first network entity to: receive, from the second network entity, the response to the request to establish the communication mode; and receive, from the second network entity, using the forwarded mode, the one or more transforms of the QUIC short header packets.
[0192] The one or more transforms of the QUIC short header packets may be entirely encrypted.Docket No. SMM920250200-GR-NP
[0193] The one or more transforms of the QUIC short header packets may be encrypted, at least in part, based on a ciphering algorithm.
[0194] The ciphering algorithm may be based at least in part on a nonce counter and a part of a VCID associated with the one or more transforms of the QUIC short header packets.
[0195] The ciphering algorithm may be based at least in part on a key, wherein the response comprises the key, wherein the response optionally comprises an indication of the ciphering algorithm associated with the key.
[0196] The response may comprise the nonce counter and the part of the VCID.
[0197] The nonce counter and the part of the VCID may be included in the one or more transforms of the QUIC short header packets.
[0198] At least one of the MRI of a respective transform and a payload of the respective transform may be encrypted by the ciphering algorithm, wherein the payload may comprise a media data associated with the MRI.
[0199] The ciphering algorithm may comprise at least one of: AES-CCM; and AES-ECB.
[0200] The one or more transforms may comprise at least one of: an identity transform; a scramble transform; and another transform for partially or entirely encrypting a QUIC short header packet.
[0201] The first network entity may be a UPF acting as an HTTP / 3 client.
[0202] The second network entity may be an AS acting as an HTTP / 3 proxy.
[0203] The method may comprise: decrypting the one or more QUIC short header packets to obtain the MRI; and transmitting the MRI to a UE.
[0204] A method performed or performable by a second network entity is provided. The method may comprise receiving, from a first network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing MRI, wherein the one or more transforms of QUIC short header packetsDocket No. SMM920250200-GR-NPare encrypted; transmitting, to the first network entity, a response to the request to establish the communication mode and the one or more transforms of QUIC short header packets.
[0205] The communication mode may comprise a UDP tunnel and a forwarded mode. The at least one processor may be configured to cause the second network entity to: transmit, to the first network entity, the response to the request to establish the communication mode; and transmit, to the first network entity, using the forwarded mode, the one or more transforms of the QUIC short header packets.
[0206] The one or more transforms of the QUIC short header packets may be entirely encrypted.
[0207] The one or more transforms of the QUIC short header packets may be encrypted based on a ciphering algorithm.
[0208] The ciphering algorithm may be based at least in part on a nonce counter and a part of a VCID associated with the one or more transforms of the QUIC short header packets.
[0209] The ciphering algorithm may be based at least in part on a key, wherein the response comprises the key, wherein the response optionally comprises an indication of the ciphering algorithm associated with the key.
[0210] The response may comprise the nonce counter and the part of the VCID.
[0211] The nonce counter and the part of the VCID may be included in the one or more transforms of the QUIC short header packets.
[0212] At least one of the MRI of a respective transform and a payload of the respective transform may be encrypted by the ciphering algorithm, wherein the payload may comprise a media data associated with the MRI.
[0213] The ciphering algorithm may comprise at least one of AES-CCM; and AES-ECB.Docket No. SMM920250200-GR-NP
[0214] The one or more transforms may comprise at least one of: an identity transform; a scramble transform; and another transform for partially or entirely encrypting a QUIC short header packet.
[0215] The first network entity may be a UPF acting as an HTTP / 3 client.
[0216] The second network entity may be an AS acting as an HTTP / 3 proxy.
[0217] The disclosure herein tends to provide security aspects for the transformed QUIC short header packets used to convey MRI and its related information from an AS towards a UPF.
[0218] The disclosure herein tends to provide the security aspects by providing a full encryption of the transformed QUIC short header packets.
[0219] Current solutions do not provide adequate security for the transformed QUIC short header packets.
[0220] The disclosure herein provides a number of examples including full encryptions. A key for the encryption may be shared at the time of establishing the Forwarded Mode session as per the IETF draft ‘draft-ietf-masque-quic-proxy’ titled “QUIC-Aware Proxying Using HTTP.”
[0221] There is provided a method comprising: transmitting by a first network entity to a second network entity, a request and receiving a response, wherein the request and the response establish a UDP tunnel mode and a forwarded mode for transmission of one or more entirely encrypted transformed QUIC short header packets containing MRI; and transmitting by the second entity to a device the MRI.
[0222] The one or more entirely encrypted transformed QUIC short header packets may be obtained by applying a first ciphering algorithm by using a nonce counter and a partial VCID to: the MRI; and a QUIC short header packet containing data, wherein the data is encrypted by other means.
[0223] The nonce counter and the partial VCID may be shared by the first entity with the second entity during establishment of the forwarded mode.Docket No. SMM920250200-GR-NP
[0224] The nonce counter and the partial VCID may be transmitted by the first entity to the second entity as an unprotected part of the transformation of the QUIC short header packet.
[0225] The QUIC short header packet / s of the one or more entirely encrypted transformed QUIC short header packets, the nonce counter, and the partial VCID, may be encrypted by a second ciphering algorithm; wherein the first entity shares a key for the second ciphering algorithm with the second entity during establishment of the forwarded mode.
[0226] The first entity may be a UPF and the second entity may be an HTTP / 3 proxy.
[0227] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0228] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.
[0229] The following abbreviations are relevant in the field addressed by this document: 5GCN, 5G Core Network; 5GS, 5G System; ADAE, Application Data Analytics Enablement; ADAEC, Application Data Analytics Enablement Client; AD AES, Application Data Analytics Enablement Server; AES, Advanced Encryption Standard; AF, Application Function; AIML, Artificial Intelligence Machine Learning; AIMLE, AIML Enablement; AMF, Access and Mobility Management Function; ANDSP, Access Network Discovery and Selection Policy; API, Application Programming Interface; APN, Access Point Name; ATSSS, Access Traffic Steering, Switching, Splitting; AS, Application Server; BRID, Broadcast Remote Identification; BVLOS, Beyond Visual Line of Sight; C2, Command and Control; CAA, Civil Aviation Administration; CAPIF, Common API Framework; DC-AF, Data Collection AF; DC-Client, Data Collection Client ; DCN,Docket No. SMM920250200-GR-NPDedicated Core Network; DN, Data Network; DNN, Data Network Name; DNS, Domain Name System; ePDG, evolved Packet Data Gateway; ePCO, Extended Protocol Configuration Options; EDN, Edge Data Network; EPS, Evolved Packet System; ER-NSSAI, Extended rejected NSSAI ; E-UTRA, Evolved Universal Terrestrial Radio Access; FL, Federated Learning; FQDN, Fully Qualified Domain Name; GPRS, General Packet Radio Service; GPT, GPRS Tunnelling Protocol; GUMMEI, Globally Unique Mobility Management Entity Identifier; GUTI, Globally Unique Temporary Identity; HFL, Horizontal Federated Learning; HPLMN, Home PLMN; HSS, Home Subscriber Server; IE, Information Element; IMSI, International Mobile Subscriber Identity; IP, Internet Protocol; JSON, JavaScript Object Notation; KPI, Key Performance Indicator; LADN, Local Area Data Network; LCS, LoCation Services ; MCC, Mobile Country Code; ML, Machine Learning; MME, Mobility Management Entity; MRI, Media Related Information; MNC, Mobile Network Code; N3 AN, Non-3GPP Access Network; N3IWF, Non-3GPP InterWorking Function; NEF, Network Exposure Function; NF, Network Function; NID, Network Identifier; NRF, Network Repository Function; NRID, Networked Remote Identification; NSAC, Network Slice Admission Control; NSCE, Network Slice Capability Exposure; NSSF, Network Slice Selection Function; OS, Operating System; OS Id, Operating System Identity; OS App Id, Operating System Application Identity; PCF, Policy Control Function; PCO, Protocol Configuration Options; PD, Protocol Discriminator; PDN, Packet Data Network; PDN GW, PDN Gateway; PDR, Packet Detection Rules; PDU, Protocol Data Unit; PGW, PDN GW; PLMN, Public Land Mobile Network; PLMN ID, Public Land Mobile Network identity; ProSe, Proximity Services; ProSeP, ProSe Policy; PSDB, PDU SET Delay Budget; PSER, PDU SET Error Rate; PSI, PDU SET Information; PTI, Procedure Transaction Identity; P-TMSI, Packet Temporary Mobile Subscriber Identity; RAI, Routing Area Identity; RAN, Radio Access Network; RID, Remote Identification; RPLMN, Registered PLMN; RRC, Radio Resource Control; SAP, Service Access Point; SCEF, Service Capability Exposure Function; SCS, Services Capability Server; SDF, Service Data Flow; SEAL, Service Enabler Architecture Layer; SGW, Serving Gateway; SLA, Service Level Agreement; SMF, Session and Mobility Management Function; SM-PCO , Session Management PCO; SNPN, Standalone NonPublic Network; SNSCE, SEAL Network Slice Capability Enablement ; SNSCE-C, SEALDocket No. SMM920250200-GR-NPNetwork Slice Capability Enablement Client; SNSCE-S, SEAL Network Slice Capability Enablement Server; S-NSSAI, Single Network Slice Selection Assistance Information; SSC, Session and Service Continuity; SSID, Service Set Identifier; SUCI, Subscription Concealed Identifier; SUPI, Subscription Permanent Identifier; TA, Tracking Area; TAI, Tracking Area Identity; TAU, Tracking Area Update; TEID, Tunnel Endpoint Identifier; TNAN, Trusted Non-3GPP -Access-Network; TNAP, Trusted Non-3GPP Access Network; TNGF, Trusted Non-3GPP Gateway Function; TPAE, Third Party Authorized Entity; TS, Transfer Learning; UAS, Uncrewed Aerial System; UAS NF, Uncrewed Aerial System Network Function; UAV, Uncrewed Aerial Vehicle; UAV-C, Uncrewed Aerial Vehicle Controller; UDM, Unified Data Management; UDR, Unified Data Repository; UE, User Equipment; UPDS, UE Policy Delivery Service; UPF, User Plane Function; UPSC, UE Policy Section Code; UPSI, UE Policy Section Identifier; URSP, UE Route Selection Policy; USIM, Universal Subscriber Identity Module; USS, UAS Service Supplier; UTM, Uncrewed Aerial System Traffic Management; UUAA, USS UAVAuthorization / Authentication; UUID, Universal Unique Identifier; V2X, Vehicle to Everything; V2XP, V2X Policy; VAL, Vertical Application Layer; and WLANSP, Wireless Location Area Network Selection Policy.Docket No. SMM920250200-GR-NP
Claims
CLAIMSWhat is claimed is:
1. A first network entity for wireless communication, comprising:at least one memory; andat least one processor coupled with the at least one memory and configured to cause the first network entity to:transmit, to a second network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing media related information, MRI, wherein the one or more transforms of the QUIC short header packets are encrypted; andreceive, from the second network entity, a response to the request to establish the communication mode and the one or more transforms of the QUIC short header packets.
2. The first network entity of claim 1, wherein the communication mode comprises a user datagram protocol, UDP, tunnel and a forwarded mode, wherein the at least one processor is configured to cause the first network entity to:receive, from the second network entity, the response to the request to establish the communication mode; andreceive, from the second network entity, using the forwarded mode, the one or more transforms of the QUIC short header packets.
3. The first network entity of any one of the preceding claims, wherein the one or more transforms of the QUIC short header packets are entirely encrypted.Docket No. SMM920250200-GR-NP4. The first network entity of any one of the preceding claims, wherein the one or more transforms of the QUIC short header packets are encrypted, at least in part, based on a ciphering algorithm.
5. The first network entity of claim 4, wherein:the ciphering algorithm is based at least in part on a nonce counter and a part of a virtual connection identifier, VCID, associated with the one or more transforms of the QUIC short header packets.
6. The first network entity of claim 4, wherein:the ciphering algorithm is based at least in part on a key, wherein the response comprises the key, wherein the response optionally comprises an indication of the ciphering algorithm associated with the key.
7. The first network entity of claim 5, wherein:the response comprises the nonce counter and the part of the VCID; orthe nonce counter and the part of the VCID are included in the one or more transforms of the QUIC short header packets.
8. The first network entity of any one of claims 4-7, wherein at least one of the MRI of a respective transform and a payload of the respective transform are encrypted by the ciphering algorithm, wherein the payload comprises a media data associated with the MRI.
9. The first network entity of any one of claims 4-8, wherein the ciphering algorithm comprises at least one of:Docket No. SMM920250200-GR-NPan advanced encryption standard cipher block chaining message authentication code, AES-CCM; andan advanced encryption standard electronic codebook mode encryption, AES-ECB.
10. The first network entity of any one of the preceding claims, wherein the one or more transforms comprise at least one ofan identity transform;a scramble transform; andanother transform for partially or entirely encrypting a QUIC short header packet.
11. The first network entity of any one of the preceding claims, wherein:the first network entity is a user plane function, UPF, acting as an HTTP / 3 client; and / orthe second network entity is an application server, AS, acting as an HTTP / 3 proxy.
12. A second network entity for wireless communication, comprising:at least one memory; andat least one processor coupled with the at least one memory and configured to cause the second network entity to:receive, from a first network entity, a request to establish a communication mode for transmitting one or more transforms of QUIC short header packets containing MRI, wherein the one or more transforms of QUIC short header packets are encrypted; and transmit, to the first network entity, a response to the request to establish the communication mode and the one or more transforms of QUIC short header packets.Docket No. SMM920250200-GR-NP13. The second network entity of claim 12, wherein the communication mode comprises a UDP tunnel and a forwarded mode, wherein the at least one processor is configured to cause the second network entity to:transmit, to the first network entity, the response to the request to establish the communication mode; andtransmit, to the first network entity, using the forwarded mode, the one or more transforms of the QUIC short header packets.
14. The second network entity of any one of claims 12-13, wherein the one or more transforms of the QUIC short header packets are entirely encrypted.
15. The second network entity of any one of claims 12-14, wherein the one or more transforms of the QUIC short header packets are encrypted based on a ciphering algorithm.
16. The second network entity of claim 15, wherein:the ciphering algorithm is based at least in part on a nonce counter and a part of a VCID associated with the one or more transforms of the QUIC short header packets.
17. The second network entity of claim 15, wherein:the ciphering algorithm is based at least in part on a key, wherein the response comprises the key, wherein the response optionally comprises an indication of the ciphering algorithm associated with the key.
18. The second network entity of claim 16, wherein:the response comprises the nonce counter and the part of the VCID; orDocket No. SMM920250200-GR-NPthe nonce counter and the part of the VCID are included in the one or more transforms of the QUIC short header packets.
19. The second network entity of any one of claims 15-18, wherein at least one of the MRI of a respective transform and a payload of the respective transform are encrypted by the ciphering algorithm, wherein the payload comprises a media data associated with the MRI.
20. The second network entity of any one of claims 15-19, wherein the ciphering algorithm comprises at least one of:an AES-CCM; andan AES-ECB.Docket No. SMM920250200-GR-NP