Mobile communication system, terminal device, base station device, network device, mobile communication method, and computer program

WO2026168147A1PCT designated stage Publication Date: 2026-08-13KDDI CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-01-20
Publication Date
2026-08-13

Smart Images

  • Figure JP2026001673_13082026_PF_FP_ABST
    Figure JP2026001673_13082026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention comprises a network function unit that uses authenticated encryption to execute processing relating to an SMC message in a non-access stratum. The network function unit transmits, to a user terminal, an SMC message for which only calculation of a message authentication code has been performed using authenticated encryption. If verification of the message authentication code of the SMC message received from the network function unit has succeeded, the user terminal uses authenticated encryption to execute processing relating to encryption and authentication of the message.
Need to check novelty before this filing date? Find Prior Art

Description

Mobile communication systems, terminal equipment, base station equipment, network equipment, mobile communication methods, and computer programs

[0001] The present invention relates to a mobile communication system, terminal equipment, base station equipment, network equipment, mobile communication method, and computer program. This application claims priority to Japanese Patent Application No. 2025-019336, filed in Japan on February 7, 2025, the contents of which are incorporated herein by reference.

[0002] Conventionally, the fifth-generation mobile communication system (5G system) standardized by "3GPP (registered trademark) (3rd Generation Partnership Project)" is known (see, for example, Non-Patent Document 1). Figure 4 is a diagram showing the schematic architecture of a conventional 5G system. In Figure 4, the 5G system consists of UE (User Equipment), RAN (Radio Access Network), CN (Core Network) UPF (User Plane Function), and various NF (Network Function) of the CN's control plane (C-plane). Examples of NFs of the CN's C-plane include AMF (Access and Mobility Management Function), SMF (Session Management Function), PCF (Policy Control Function), UDM (Unified Data Management), and UDR (Unified Data Repository).

[0003] One of the standardizations by 3GPP is the specification for encryption and authentication of messages sent and received by UEs. In this 3GPP specification, message encryption algorithms and authentication algorithms are provided as separate algorithms, and in the process of selecting these algorithms, message authentication is applied first, followed by message encryption.

[0004] Figure 5 shows the procedure regarding "Protecting the initial NAS message" in the Non-Access Stratum (NAS) of a conventional 5G system. Figure 5 is described in "Figure 6.4.6-1" of Non-Patent Document 1. Regarding the protection of messages when the UE and the AMF establish a connection, the process shown in Figure 5 is executed. The detailed procedures of "NAS Security Mode Command Procedure: "NAS SMC procedure"" for step 3 "NAS Security Mode Command" and step 4 "NAS Security Mode Complete" in Figure 5 are shown in Figure 6. Figure 6 is described in "Figure 6.7.2-1" of Non-Patent Document 1. In step 1b of Figure 6, the message sent from the AMF to the UE is not encrypted, and only message authentication is applied.

[0005] Figure 7 shows the "AS Security Mode Command Procedure: "AS SMC procedure"" in the Access Stratum (AS) of a conventional 5G system. Figure 7 is described in "Figure 6.7.4-1" of Non-Patent Document 1. Similar to the NAS in the AS, in step 1b of Figure 7, the message sent from the base station (gNB) to the UE is not encrypted, and only message authentication is applied.

[0006] 3GPP, TS 33.501, V18.5.0, 2024-03

[0007] However, in the above-mentioned 3GPP specifications, since the message encryption algorithm and the authentication algorithm are provided as separate algorithms, there is a problem in improving the processing speed.

[0008] In contrast, by using Authenticated Encryption with Associated Data (AEAD), both message encryption and authentication can be achieved simultaneously, which is expected to contribute to improved processing speed. Furthermore, with Authenticated Encryption, it is also possible to provide only either message encryption or authentication. However, applying such Authenticated Encryption (AEAD) to the aforementioned "NAS SMC procedure" and "AS SMC procedure" has been a challenge.

[0009] This invention was made in consideration of these circumstances, and its purpose is to apply authenticated encryption (AEAD) to the "NAS Security Mode Command procedure" and the "AS Security Mode Command procedure".

[0010] One aspect of the present invention is a mobile communication system in which a user terminal and a base station communicate wirelessly, comprising a network function unit that performs processing related to SMC (Security Mode Command) messages in the non-access layer using authenticated encryption, wherein the network function unit transmits an SMC message to the user terminal in which only the message authentication code has been calculated using authenticated encryption, and the user terminal, upon successful verification of the message authentication code of the SMC message received from the network function unit, performs processing related to message encryption and authentication using authenticated encryption. Another aspect of the present invention is a mobile communication system in which the network function unit is an AMF (Access and Mobility Management Function).

[0011] One aspect of the present invention is a mobile communication system in which a user terminal and a base station communicate wirelessly, wherein the base station uses authenticated encryption to perform processing related to SMC (Security Mode Command) messages in the access layer, the base station transmits an SMC message to the user terminal in which only the message authentication code has been calculated using authenticated encryption, and the user terminal, upon successful verification of the message authentication code of the SMC message received from the base station, performs processing related to message encryption and authentication using authenticated encryption.

[0012] One aspect of the present invention is a terminal device for a mobile communication system, which receives an SMC message from a network function unit of the mobile communication system that performs processing related to SMC (Security Mode Command) messages in the non-access layer using authenticated encryption, and if the verification of the message authentication code of the SMC message received from the network function unit is successful, the terminal device performs processing related to message encryption and authentication using authenticated encryption. Another aspect of the present invention is a network device for a mobile communication system, which includes a network function unit that performs processing related to SMC (Security Mode Command) messages in the non-access layer using authenticated encryption, and the network function unit transmits an SMC message from which only the message authentication code has been calculated using authenticated encryption to a user terminal of the mobile communication system.

[0013] One aspect of the present invention is a terminal device for a mobile communication system that receives an SMC message from a base station of the mobile communication system, which performs processing related to SMC (Security Mode Command) messages at the access layer using authenticated encryption, and if the verification of the message authentication code of the SMC message received from the base station is successful, the terminal device performs processing related to message encryption and authentication using authenticated encryption. Another aspect of the present invention is a base station device for a mobile communication system that performs processing related to SMC (Security Mode Command) messages at the access layer using authenticated encryption and transmits an SMC message from which only the message authentication code has been calculated using authenticated encryption to a user terminal of the mobile communication system.

[0014] One aspect of the present invention is a mobile communication method comprising the steps of: a terminal device of a mobile communication system receiving an SMC message from a network function unit of the mobile communication system that performs processing on SMC (Security Mode Command) messages in the non-access layer using authenticated encryption, with only the calculation of a message authentication code performed using authenticated encryption; and, if the verification of the message authentication code of the SMC message received from the network function unit is successful, the terminal device performing processing related to message encryption and authentication using authenticated encryption.

[0015] One aspect of the present invention is a computer program that causes a computer in a terminal device of a mobile communication system to perform the following steps: receive an SMC message from a network function unit of the mobile communication system, which performs processing related to SMC (Security Mode Command) messages in the non-access layer using authenticated encryption, and which has only calculated a message authentication code using authenticated encryption; and, if the verification of the message authentication code of the SMC message received from the network function unit is successful, perform processing related to message encryption and authentication using authenticated encryption.

[0016] According to the present invention, the effect is obtained that authenticated encryption (AEAD) can be applied to the "NAS SMC procedure (NAS Security Mode Command procedure)" and the "AS SMC procedure (AS Security Mode Command Procedure)".

[0017] This figure shows a schematic configuration example of a mobile communication system according to one embodiment. This figure shows the "NAS SMC procedure" according to one embodiment. This figure shows the "AS SMC procedure" according to one embodiment. This figure shows the schematic architecture of a conventional 5G system. This figure shows the procedure for "Protecting the initial NAS message" in the non-access layer (NAS) of a conventional 5G system. This figure shows the "NAS SMC procedure" of a conventional 5G system. This figure shows the "AS SMC procedure" of a conventional 5G system.

[0018] Embodiments of the present invention will be described below with reference to the drawings.

[0019] Figure 1 is a diagram showing a schematic configuration example of a mobile communication system 1 according to one embodiment. The mobile communication system 1 may be, for example, a 5G system. The mobile communication system 1 comprises a user terminal (UE) 100, a base station (gNB) 200, and an AMF (Access and Mobility Management Function) 300 (network function unit). The AMF 300 is one of the NFs (network functions) of the control plane (C-plane) of the CN (core network) of the 5G system. The user terminal 100 and the base station 200 communicate wirelessly. The user terminal 100 corresponds to a terminal device. The base station 200 corresponds to a base station device. The AMF 300 corresponds to a network device.

[0020] In this embodiment, authenticated encryption (AEAD) is used to perform either message encryption only, message authentication only, or both message encryption and authentication.

[0021] The user terminal 100 comprises a terminal communication processing unit 110, a wireless unit 120, and a terminal control unit 130. The terminal communication processing unit 110 includes an authentication-encrypted unit 111. The authentication-encrypted unit 111 performs authentication-encrypted processing on messages. Authentication-encrypted processing refers to processing that performs either message encryption only, message authentication only, or both message encryption and authentication using authentication-encrypted encryption.

[0022] The wireless unit 120 transmits and receives data wirelessly to and from the base station 200. Messages that have undergone authentication and encryption processing are transmitted and received between the wireless unit 120 and the base station 200.

[0023] The terminal control unit 130 controls the user terminal 100.

[0024] The base station 200 comprises a base station communication processing unit 210, a radio unit 220, and a base station control unit 230. The base station communication processing unit 210 includes an authenticated encryption unit 211. The authenticated encryption unit 211 performs authenticated encryption processing on messages. Authenticated encryption processing refers to processing that performs either message encryption only, message authentication only, or both message encryption and authentication using authenticated encryption.

[0025] The wireless unit 220 transmits and receives data wirelessly to and from the user terminal 100. Messages that have undergone authentication and encryption processing are transmitted and received between the wireless unit 220 and the user terminal 100.

[0026] The base station control unit 230 controls the base station 200.

[0027] Next, the mobile communication method according to this embodiment will be described with reference to Figures 2 and 3.

[0028] [Non-Access Stratum (NAS)] Referring to Figure 2, the procedure for the Security Mode Command (SMC) of the non-access stratum (NAS) according to this embodiment ("NAS SMC procedure") will be described. Figure 2 is a diagram showing the "NAS SMC procedure" according to this embodiment. In Figure 2, the parts corresponding to each step of the "NAS SMC procedure" of the conventional 5G system in Figure 6 are denoted by the same reference numerals.

[0029] Authenticated encryption with AD (AEAD) allows message authentication to be applied without encrypting the message by processing the message as "Associated Data (AD)". Therefore, for the SMC message that the AMF 300 sends to the user terminal 100 in step 1b, the AMF 300 processes it as AD by only calculating the Message Authentication Code (MAC) using authenticated encryption with AD (step 1a). The AMF 300 sends the SMC message "Security Mode Command" and MAC to the user terminal 100 (step 1b). The AMF 300 starts decrypting the message received from the user terminal 100 and verifying the MAC (step 1c).

[0030] In step 2a, the user terminal 100 verifies the MAC address of the SMC message received from the AMF 300 in step 1b. If the user terminal 100 successfully verifies the MAC address, it applies both encryption and authentication to the messages sent and received in step 2b and beyond by performing authentication-encrypted processing on the messages as plaintext. The user terminal 100 then sends the SMC message "Security Mode Complete" and MAC address, to the AMF 300 (step 2b).

[0031] The AMF300 applies both encryption and authentication to the message it sends to the user terminal 100 by performing authentication-encrypted processing on the message as plaintext (step 1d).

[0032] [Access Layer (AS (Access Stratum))] Referring to Figure 3, the SMC procedure of the access layer (AS) according to this embodiment ("AS SMC procedure") will be described. Figure 3 is a diagram showing the "AS SMC procedure" according to this embodiment. In Figure 3, the parts corresponding to each step of the "AS SMC procedure" of the conventional 5G system in Figure 7 are denoted by the same reference numerals.

[0033] For the SMC message that base station 200 (gNB) sends to user terminal 100 in step 1b, base station 200 processes it as AD by only calculating the message authentication code (MAC) using authenticated encryption (step 1a). Base station 200 sends the SMC message "Security Mode Command" and MAC to user terminal 100 (step 1b). Base station 200 and AMF 300 apply both encryption and authentication to the message by performing authenticated encryption processing on the message sent to user terminal 100 as plaintext (step 1c).

[0034] In step 2a, the user terminal 100 verifies the MAC address of the SMC message received from the base station 200 in step 1b. If the verification of the MAC address is successful, the user terminal 100 starts calculating the MAC address of the message to be sent to the base station 200 and decrypting the message to be received from the base station 200. Furthermore, if the verification of the MAC address is successful, the user terminal 100 applies both encryption and authentication to the messages to be sent and received in step 2c and beyond by performing authenticated encryption processing on the messages as plaintext. The user terminal 100 sends the authenticated SMC message "Security Mode Complete" and MAC address to the base station 200 (step 2b).

[0035] The user terminal 100 sends a message to the base station 200 that has both message encryption and authentication applied (step 2c). The base station 200 begins decrypting the message it receives from the user terminal 100 (step 1d).

[0036] According to this embodiment, the effect is obtained that authenticated encryption (AEAD) can be applied to the "NAS SMC procedure" and the "AS SMC procedure".

[0037] Furthermore, this will enable improvements in overall service quality, such as in mobile communication systems, and will contribute to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs): "Build resilient infrastructure, promote sustainable industrialization and foster innovation."

[0038] Although embodiments of the present invention have been described in detail above with reference to the drawings, the specific configuration is not limited to these embodiments, and design modifications and the like are also included within the scope of the gist of the present invention.

[0039] Alternatively, computer programs for realizing the functions of each of the above-mentioned devices may be recorded on a computer-readable recording medium, and the programs recorded on this recording medium may be loaded into a computer system and executed. The term "computer system" here may include hardware such as an operating system and peripheral devices. Furthermore, "computer-readable recording medium" refers to writable non-volatile memory such as flexible disks, magneto-optical disks, ROMs, and flash memory, portable media such as DVDs (Digital Versatile Discs), and storage devices such as hard disks built into a computer system.

[0040] Furthermore, "computer-readable recording media" includes volatile memory (e.g., DRAM (Dynamic Random Access Memory)) within a computer system that acts as a server or client when a program is transmitted via a network such as the Internet or a communication line such as a telephone line, which retains the program for a certain period of time. In addition, the above program may be transmitted from the computer system that stores the program in a storage device, etc., to another computer system via a transmission medium or by transmission waves within the transmission medium. Here, the "transmission medium" for transmitting the program refers to a medium that has the function of transmitting information, such as a network such as the Internet or a communication line such as a telephone line. Furthermore, the above program may be for the purpose of realizing a part of the above-mentioned functions. In addition, it may be a so-called differential file (differential program) that can realize the above-mentioned functions in combination with a program already recorded in the computer system.

[0041] According to the present invention, authenticated encryption can be applied to the "NAS SMC procedure" and the "AS SMC procedure".

[0042] 1...Mobile communication system, 100...User terminal (UE), 110...Terminal communication processing unit, 120...Wireless unit, 130...Terminal control unit, 111, 211...Authentication-enabled encryption unit, 200...Base station (gNB), 210...Base station communication processing unit, 220...Wireless unit, 230...Base station control unit, 300...AMF

Claims

1. A mobile communication system in which a user terminal and a base station communicate wirelessly, comprising a network function unit that performs processing related to SMC (Security Mode Command) messages in the non-access layer using authenticated encryption, wherein the network function unit transmits an SMC message to the user terminal, having only calculated a message authentication code using authenticated encryption, and the user terminal, upon successful verification of the message authentication code of the SMC message received from the network function unit, performs processing related to message encryption and authentication using authenticated encryption.

2. The mobile communication system according to claim 1, wherein the network function unit is an AMF (Access and Mobility Management Function).

3. A mobile communication system in which a user terminal and a base station communicate wirelessly, wherein the base station uses authenticated encryption to perform processing related to SMC (Security Mode Command) messages in the access layer, the base station transmits an SMC message to the user terminal in which only the message authentication code has been calculated using authenticated encryption, and the user terminal, upon successful verification of the message authentication code of the SMC message received from the base station, performs processing related to message encryption and authentication using authenticated encryption.

4. A terminal device of a mobile communication system, which receives an SMC message from the network function unit of the mobile communication system, which performs processing related to SMC (Security Mode Command) messages in the non-access layer using authenticated encryption, and which performs processing related to message encryption and authentication using authenticated encryption when the verification of the message authentication code of the SMC message received from the network function unit is successful.

5. A network device for a mobile communication system, comprising a network function unit that performs processing related to SMC (Security Mode Command) messages in the non-access layer using authenticated encryption, wherein the network function unit transmits an SMC message, for which only the message authentication code has been calculated using authenticated encryption, to a user terminal of the mobile communication system.

6. A terminal device of a mobile communication system, which receives an SMC message from a base station of the mobile communication system that performs processing related to SMC (Security Mode Command) messages in the access layer using authenticated encryption, and which performs processing related to message encryption and authentication using authenticated encryption when the verification of the message authentication code of the SMC message received from the base station is successful.

7. A base station device of a mobile communication system that performs processing related to SMC (Security Mode Command) messages at the access layer using authenticated encryption, and transmits an SMC message, in which only the message authentication code has been calculated using authenticated encryption, to a user terminal of the mobile communication system.

8. A mobile communication method comprising: a step of a terminal device of a mobile communication system receiving an SMC message from a network function unit of the mobile communication system that performs processing on SMC (Security Mode Command) messages in the non-access layer using authenticated encryption, with only the calculation of a message authentication code performed using authenticated encryption; and a step of the terminal device performing processing on encryption and authentication of a message using authenticated encryption if the verification of the message authentication code of the SMC message received from the network function unit is successful.

9. A computer program for a computer in a terminal device of a mobile communication system to perform the following steps: receiving an SMC message from the network function unit of the mobile communication system, which performs processing related to SMC (Security Mode Command) messages in the non-access layer using authenticated encryption, and which has only calculated a message authentication code using authenticated encryption; and, if the verification of the message authentication code of the SMC message received from the network function unit is successful, performing processing related to message encryption and authentication using authenticated encryption.