Method and device for enhancing private 5g network security in wireless communication system

WO2026168762A1PCT designated stage Publication Date: 2026-08-13SAMSUNG ELECTRONICS CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-04
Publication Date
2026-08-13

Smart Images

  • Figure KR2025099245_13082026_PF_FP_ABST
    Figure KR2025099245_13082026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are a method and device for enhancing private 5G network security in a wireless communication system. The method according to an embodiment of the present disclosure may comprise the steps of: transmitting, to an access and mobility management function (AMF), a registration request message including information indicating whether a security enhancement technology is applied; receiving, from the AMF, a first message requesting a UE security configuration capability; transmitting, to the AMF, a second message including the UE security configuration capability; receiving, from the AMF, a message including a UE security configuration; and activating the UE security configuration, wherein the UE security configuration may be determined by a network entity on the basis of a UE security capability.
Need to check novelty before this filing date? Find Prior Art

Description

Method and apparatus for enhancing 5G specialized network security in a wireless communication system

[0001] The present disclosure relates to a mobile communication terminal and a network change in a wireless communication system, wherein the mobile communication terminal enhances security by performing a predefined security enhancing behavior (SEB). More specifically, the terminal activates the SEB according to a list of SEBs stored by itself, and updates the said list of SEBs by receiving it from the network.

[0002] 5G mobile communication technology defines a wide frequency band to enable fast transmission speeds and new services, and can be implemented not only in frequency bands below 6 GHz ('Sub 6 GHz'), such as 3.5 gigahertz (3.5 GHz), but also in ultra-high frequency bands called millimeter waves (mmWave), such as 28 GHz and 39 GHz ('Above 6 GHz'). In addition, for 6G mobile communication technology, which is referred to as a system beyond 5G, implementation in the terahertz band (e.g., the 3 terahertz (3 THz) band at 95 GHz) is being considered to achieve transmission speeds 50 times faster and ultra-low latency reduced to one-tenth compared to 5G mobile communication technology.

[0003] In the early stages of 5G mobile communication technology, aiming to satisfy service support and performance requirements for enhanced Mobile BroadBand (eMBB), Ultra-Reliable Low-Latency Communications (URLLC), and massive Machine-Type Communications (mMTC), technologies such as beamforming and Massive MIMO to mitigate path loss and increase transmission distance in ultra-high frequency bands, support for various numerologies (such as the operation of multiple subcarrier spacings) and dynamic operation of slot formats for the efficient utilization of ultra-high frequency resources, initial access techniques to support multi-beam transmission and broadband, definition and operation of Band-Width Parts (BWP), Low Density Parity Check (LDPC) codes for high-volume data transmission, new channel coding methods such as Polar Codes for the reliable transmission of control information, and L2 pre-processing (L2 Standardization has been carried out for pre-processing, network slicing which provides a dedicated network specialized for specific services, and other methods.

[0004] Currently, discussions are underway to improve and enhance the performance of the initial 5G mobile communication technology, taking into account the services that the 5G mobile communication technology was intended to support. Additionally, standardization of the physical layer is in progress for technologies such as V2X (Vehicle-to-Everything), which helps autonomous vehicles make driving decisions and enhance user convenience based on their own location and status information transmitted by the vehicle; NR-U (New Radio Unlicensed), which aims for system operation in unlicensed bands to comply with various regulatory requirements; NR terminal low power consumption technology (UE Power Saving); Non-Terrestrial Network (NTN), which is direct terminal-satellite communication for securing coverage in areas where communication with the terrestrial network is impossible; and positioning.

[0005] In addition, standardization is underway in the field of wireless interface architecture / protocols for technologies such as the Industrial Internet of Things (IIoT) for supporting new services through linkage and convergence with other industries, Integrated Access and Backhaul (IAB) which provides nodes for expanding network service areas by integrating wireless backhaul links and access links, Mobility Enhancement including Conditional Handover and Dual Active Protocol Stack (DAPS) Handover, and 2-step Random Access for NR which simplifies random access procedures. Standardization is also underway in the field of system architecture / services for 5G baseline architectures (e.g., Service based Architecture, Service based Interface) for incorporating Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC), which provides services based on the location of the terminal.

[0006] When such 5G mobile communication systems are commercialized, connected devices, which are increasing explosively, will be connected to communication networks. Accordingly, it is expected that there will be a need to enhance the functionality and performance of 5G mobile communication systems and to integrate the operation of connected devices. To this end, new research is planned to be conducted on 5G performance improvement and complexity reduction, support for AI services, support for metaverse services, and drone communication using eXtended Reality (XR), Artificial Intelligence (AI), and Machine Learning (ML) to efficiently support Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR).

[0007] Furthermore, the advancement of these 5G mobile communication systems encompasses multi-antenna transmission technologies such as new waveforms, Full Dimensional MIMO (FD-MIMO), array antennas, and large-scale antennas to guarantee coverage in the terahertz band of 6G mobile communication technology; metamaterial-based lenses and antennas; high-dimensional spatial multiplexing technology using Orbital Angular Momentum (OAM); and Reconfigurable Intelligent Surface (RIS) technology to improve terahertz band signal coverage; as well as full-duplex technology for enhancing frequency efficiency and system networks in 6G mobile communication technology; AI-based communication technologies that realize system optimization by utilizing satellites and Artificial Intelligence (AI) from the design stage and internalizing end-to-end AI support functions; and the realization of services of complexity exceeding the limits of terminal computing capabilities by utilizing ultra-high-performance communication and computing resources. It could serve as a foundation for the development of next-generation distributed computing technologies.

[0008] A 5G specialized network, also known as a non-public network (NPN), is a 5G network configured to consider only specific institutions and enterprises as users, unlike a carrier's public land mobile network (PLMN) which targets general users. It is designed to be accessible only to designated users, aiming to provide security through network separation and specialized services. Such 5G specialized networks are used by Korea Electric Power Corporation (KEPCO) in South Korea for substation operations, and by Hanshin Electric Railway in Japan to prevent safety accidents.

[0009] From a technical perspective, there may be differences in the technologies employed by NPN and PLMN. In PLMN, in addition to technologies for basic communication, there are various techniques designed to account for specific situations, and multiple control plane messages are used for this purpose. For instance, in the event of a disaster, user data usage surges, potentially overloading the base station. In such cases, the base station may prohibit access from general users to ensure connectivity for high-priority users; access barring technology is employed for this purpose. On the other hand, in NPN, the number of users utilizing each base station remains relatively constant, and the traffic volume from IoT devices, which account for the majority of traffic, does not fluctuate. Therefore, it is highly likely that technologies such as access barring are not used in NPN, and the control plane messages used for access barring may not exist in NPN.

[0010] One of the purposes of using NPN is to maintain high security. However, since NPN and PLMN are nearly identical for most essential control plane protocols, it is highly likely that many known standard vulnerabilities of various control planes remain intact. Consequently, attackers aware of these vulnerabilities can exploit them to launch attacks on NPN terminals. For example, utilizing currently known standard vulnerabilities allows attackers to disable 5G functions on nearby terminals using FBS (fake base station), which can lead to a Denial of Service (DoS) attack on 5G NPN terminals. Considering that attacks exploiting various other standard vulnerabilities are also possible, it is highly probable that maintaining the high security of NPN will be difficult.

[0011] Under current mobile communication technology standards, there is no way for terminals to block attacks that exploit these standard vulnerabilities. This is because mobile terminals and networks are built based on mobile communication standards, meaning that even the vulnerabilities present in those standards are implemented within the terminals and networks. Furthermore, these standard vulnerabilities are difficult to patch. In some cases, patching is virtually impossible because it requires modifying the entire design of the mobile communication technology, while in others, although solutions exist, modification is difficult due to performance or operational issues. Consequently, attacks exploiting existing standard vulnerabilities are available to most terminals, and there is a high probability that they will not be patched in the future.

[0012] The present invention, for solving the above-mentioned problems, comprises a method performed by a user device (User equipment, UE) in a wireless communication system, the method including: transmitting a registration request message containing information indicating whether a security enhancement technology has been applied to an Access and Mobility Management Function (AMF); receiving a first message from the AMF requesting a UE security setting capability; transmitting a second message containing the UE security setting capability to the AMF; receiving a message containing a UE security setting from the AMF; and activating the UE security setting, wherein the UE security setting is determined by a network entity based on the UE security capability.

[0013] In one embodiment, the UE security setting is characterized by including whether it supports a response to an access barring attack included in the Master Information Block (MIB).

[0014] In one embodiment, the UE security setting is characterized by including whether it supports a response to a Registration reject attack.

[0015] In one embodiment, the information indicating whether the security enhancement technology has been applied is characterized as being bit information.

[0016] In addition, in another embodiment of the present invention, a method performed by a wireless communication system network entity comprises: receiving a message including a UE security setting capability from a UE (User equipment) via an Access and Mobility Management Function (AMF); determining a UE security setting to be activated based on the UE security setting capability; and transmitting the determined UE security setting to the UE via the AMF, wherein the UE security setting is activated based on the determined UE security setting.

[0017] In addition, in another embodiment of the present invention, a user device (User equipment, UE) in a wireless communication system comprises: a transceiver capable of transmitting and receiving at least one signal; and a control unit coupled to the transceiver. The control unit is configured to: transmit a registration request message containing information indicating whether a security enhancement technology has been applied to an Access and Mobility Management Function (AMF); receive a first message requesting a UE security setting capability from the AMF; transmit a second message containing the UE security setting capability to the AMF; receive a message containing a UE security setting from the AMF; and activate the UE security setting. The UE security setting is determined by a network entity based on the UE security setting capability.

[0018] In addition, in another embodiment of the present invention, a network entity in a wireless communication system comprises: a transceiver capable of transmitting and receiving at least one signal; and a control unit coupled to the transceiver. The control unit is configured to receive a message from a User Equipment (UE) through an Access and Mobility Management Function (AMF) that includes a UE security setting capability, determine a UE security setting to be activated based on the UE security setting capability, and transmit the determined UE security setting to the UE through the AMF, and the UE security setting is activated based on the determined UE security setting.

[0019] According to one embodiment of the present invention, a terminal used in a 5G specialized network can be defended against various known attacks. More precisely, a terminal having a predefined defense technique implemented to respond to previously known attacks can receive a list of defense techniques to use among them through communication with an NPN, and can enhance the security of the terminal by using the selected techniques. Through this, the terminal can defend against known attacks, including attacks that exploit standard vulnerabilities, depending on the defense technique activated.

[0020] Furthermore, in the case of a mobile communication terminal and network to which the present invention is applied, the terminal is in a state where appropriate SEBs are activated, and the mobile communication terminal is in a state where it can defend against attacks corresponding to said SEBs. Depending on the policy of the mobile communication network, the terminal may also activate all SEBs, in which case it becomes a state where it can defend against many attacks.

[0021] FIG. 1 is a drawing illustrating the structure of a 5G system according to various embodiments of the present disclosure.

[0022] FIG. 2 is a diagram showing a conventional operation prior to the present invention.

[0023] FIG. 3 is a diagram showing the overall operation according to one embodiment of the present invention.

[0024] FIG. 4 is a drawing showing a detailed operation according to one embodiment of the present invention.

[0025] FIG. 5 is a diagram showing a detailed operation according to an embodiment of the present invention.

[0026] FIG. 6 is a drawing showing a detailed operation according to one embodiment of the present invention.

[0027] FIG. 7 is a diagram showing a conventional operation of a first embodiment of the present invention.

[0028] FIG. 8 is a diagram showing a proposed operation according to a first embodiment of the present invention.

[0029] FIG. 9 is a drawing showing a flowchart according to a first embodiment of the present invention.

[0030] FIG. 10 is a diagram showing a prior operation of the 2-1 embodiment of the present invention.

[0031] FIG. 11 is a diagram showing a conventional operation for the second-2 embodiment of the present invention.

[0032] FIG. 12 is a diagram showing a proposed operation according to a second embodiment of the present invention.

[0033] FIG. 13 is a diagram showing a proposed operation according to a second embodiment of the present invention.

[0034] FIG. 14 is a diagram showing a flowchart according to a second embodiment of the present invention.

[0035] FIG. 15 is a diagram illustrating the structure of a terminal according to one embodiment of the present invention.

[0036] FIG. 16 is a diagram illustrating the structure of a network entity according to one embodiment of the present invention.

[0037] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings. Furthermore, in describing the present invention, detailed descriptions of related known functions or configurations are omitted if it is determined that such detailed descriptions would unnecessarily obscure the essence of the invention. Additionally, the terms described below are defined considering their functions in the present invention, and these may vary depending on the intentions or conventions of the user or operator. Therefore, their definitions should be based on the content throughout this specification.

[0038] The advantages and features of the present invention and the methods for achieving them will become clear by referring to the embodiments described below in detail together with the accompanying drawings. However, the present invention is not limited to the embodiments disclosed below but can be implemented in various different forms. These embodiments are provided merely to ensure that the disclosure of the present invention is complete and to fully inform those skilled in the art of the scope of the invention, and the present invention is defined only by the scope of the claims. Throughout the specification, the same reference numerals refer to the same components.

[0039] FIG. 1 is a drawing illustrating the structure of a 5G system according to various embodiments of the present disclosure.

[0040] A 5G mobile communication network consists of 5G UE (user equipment, terminal, 100), 5G RAN (radio access network, base station), gNB (5G nodeB), eNB (evolved nodeB, etc., 110), and a 5G core network. The 5G core network may be composed of NFs such as AMF (access and mobility management function, 120), which provides UE mobility management functions; SMF (session management function, 135), which provides session management functions; UPF (user plane function, 130), which performs data delivery; PCF (policy control function, 140), which provides policy control functions; UDM (unified data management, 145), which provides data management functions such as subscriber data and policy control data; and UDR (unified data repository), which stores data from various network functions (NFs) including UDM. The 5G core network consists of NSSF (network slice selection function, 160), NWDAF (network data analytic function, 151), and AF. It can be configured to include additional NFs such as (application function, 170), DN (data network, 175), and NSACF (network slice admission control function, 180).

[0041] In 3GPP systems, a conceptual link connecting NFs within a 5G system is defined as a reference point. The following is an example of a reference point included in the 5G system architecture depicted in Figure 1.

[0042] - N1: Reference point between UE and AMF

[0043] - N2: Reference point between (R)AN and AMF

[0044] - N3: Reference point between (R)AN and UPF

[0045] - N4: Reference point between SMF and UPF

[0046] - N5: Reference point between PCF and AF

[0047] - N6: Reference point between UPF and DN

[0048] - N7: Reference point between SMF and PCF

[0049] - N8: Reference point between UDM and AMF

[0050] - N9: Reference point between 2 core UPFs

[0051] - N10: Reference point between UDM and SMF

[0052] - N11: Reference point between AMF and SMF

[0053] - N12: Reference point between AMF and AUSF

[0054] - N13: Reference point between UDM and the authentication server function (AUSF)

[0055] - N14: Reference point between 2 AMFs

[0056] - N15: Reference point between PCF and AMF in non-roaming scenarios, reference point between PCF and AMF within the visited network in roaming scenarios

[0057] FIG. 2 is a diagram illustrating a conventional operation prior to the present invention. Referring to FIG. 2, the UE (260) and the AMF (240) perform a registration procedure. More specifically, the UE (260) transmits a registration request to the AMF (240) containing information necessary for the registration procedure (step 201), and the UDM (220), AMF (240), and UDM (260) can perform the registration procedure (step 202).

[0058]

[0059] FIG. 3 is a diagram illustrating the overall operation according to an embodiment of the present invention. Referring to FIG. 3, when a UE (380) connects to an AMF (360), it may notify the AMF (360) that it is a terminal to which the present technology is applied (step 302). After the UE (380) connects, the AMF (360) may request a SEB capability, which is a list of SEBs supported by the UE (380) (step 304), and the UE (380) may transmit this to the AMF (360) (step 305). The UE (380) may transmit the UE's SEB capability to the AMF (360) via a network function called a DSM (Device Security Management Function, 340) (step 306). The DSM (340) may determine the list of SEBs to be activated by the terminal based on the network operation policy and the received SEB capability (step 307). The DSM can transmit this to the terminal (step 308), and the terminal stores and activates the SEB accordingly (steps 309 to 310). Afterwards, the UE (380) can transmit a completion message to the DSM (340) via the AMF (360) (step 311).

[0060]

[0061] FIG. 4 is a diagram illustrating detailed operations according to the embodiment illustrated in FIG. 3 of the present invention. Referring to FIG. 4, the UE (380) to which the present technology is applied may have an SEB to be activated by default (step 301). The UE (380) may also store the SEB to be activated by default according to the manufacturer's policy. In this way, the UE (380) can activate the SEB even before connecting to a network to defend against some attacks. For example, the UE (380) may activate all SEBs it supports. Examples of SEBs are described in the first and second embodiments below.

[0062] The UE (380) can attempt to register with the network by sending a registration request message (step 302). At this time, the UE (380) can send the registration request message with the UE type notification set to 1, that is, the terminal is set to have the ability to perform SEB using the SEB parameters it possesses. Upon receiving this, the AMF (360) can confirm that the proposed technology has been applied to the terminal.

[0063] Afterward, the AMF (360) and the network can proceed with the registration procedure as per the existing procedure (step 303). Cases where registration fails follow the standard and are not covered here.

[0064]

[0065] FIG. 5 is a diagram showing detailed operation according to the embodiment illustrated in FIG. 3 of the present invention.

[0066] After the registration procedure is completed, the AMF (360) can confirm that the UE has sent a UE type notification IE as 1. The AMF (360) can send a UE SEB Capability Request message to the UE (380) (step 304). The message requesting the terminal's SEB capability may be a Non-access Stratum (NAS) message. Since the message is sent after registration, it may be sent with integrity protection and encryption applied. The present invention proposes that all NAS messages described below be transmitted and received only in a state of integrity protection and encryption.

[0067] A UE (380) that receives a UE SEB Capability Request message can respond to the AMF (360) with a UE SEB Capability Response message (step 305). The message may include SEB capability IE, which is a list of SEBs supported by the UE.

[0068] To explain the method of expressing SEB capability and the IE structure used in the present invention, the SEB capability IE may include a SEB capability IE and a selected SEB capability IE. Before considering this, the method of expressing various SEBs is described first. Specific examples of SEBs are explained in the following first and second embodiments.

[0069] In addition to the examples described in the first and second embodiments below, there are various attacks that attack a terminal using standard vulnerabilities. In the present invention, a list of such attacks is first defined. As an example, the list of attacks may be defined by assigning an index. An index 1 may be assigned to an attack using access barring introduced in the first embodiment, and an index 2 may be assigned to an attack using registration reject #27 introduced in the second embodiment. In this way, the list of attacks can be defined by assigning indices 0, 1, 2, ..., to the attacks. However, the present invention does not address specifically which attacks should or can be included in the list, but only describes the method of defining the list of attacks.

[0070] Subsequently, an SEB (security-enhanced operation) corresponding to each attack in the defined attack list is defined. As with the examples described in the first and second embodiments, an SEB that the terminal can respond to for each attack is defined, and a list of SEBs is defined. For example, an index value such as the index assigned to each attack can be assigned to the SEB.

[0071] Finally, for the SEBs defined in this way, the terminal can assign a value of 1 (supported) to SEBs it supports and a value of 0 (not supported) to SEBs it does not support. In the previous example, if an index is assigned to each SEB, these values ​​can be arranged in order to represent the list of supported SEBs in the form of a bitmap. SEB capability IE can be represented in this manner, which is similar to the method used to represent UE network capability in the current NAS standard. Specifically, examples of using UE network capability and SEB capability IE in NAS messages are presented in order. In this case, SEB capability IE can be represented as 11001.

[0072]

[0073]

[0074] Selected SEB capability IE can also be defined in a similar way to the above SEB capability IE. It can be expressed in the same way by assigning a value of 1 (enable) to each SEB to be enabled and a value of 0 (disable) to each SEB not to be enabled. The following shows an example of selected SEB capability IE, which corresponds to 01001.

[0075]

[0076] Upon receiving the UE SEB Capability Response message, the AMF (360) sends a UE SEB Capability Notification message to the DSM (340) (step 306), and the message may include the same UE SEB Capability IE as that included in the UE SEB Capability Response message.

[0077] DSM (340) can select the capability that the terminal will activate based on the received UE SEB Capability and the network policy (step 307). Specifically, as a method for determining the SEB that DSM (340) will activate, DSM (340) can receive the SEB capability IE transmitted by the terminal, select the SEB to activate among them, and configure the selected SEB capability.

[0078] At this time, the process of configuring the selected SEB capability IE can be composed of the following steps. First, the DSM (340) can check the list of SEBs supported by the terminal by referring to the SEB capability IE. Since SEBs not supported by the terminal cannot be activated, they can all be set to disabled in the selected SEB capability. For example, if the SEB capability is reported as 11001, SEBs 3 and 4 can be disabled. Next, the DSM (340) can determine which SEBs to disable according to the network policy. Looking at the background of using SEBs in the present invention, SEBs can be activated on the premise that specific messages are not used in the specialized network. For example, the SEB in the first embodiment assumed that the network does not use a Master Information Block (MIB) with the cellBarred value set to barred, and in the second embodiment, it assumed that the network does not use a registration reject message with the reject cause set to #27. However, this may be used in some specialized networks. Therefore, considering this, the DSM may not activate the corresponding SEB if the message that can be considered as an attack vector is used. For example, in a mobile network using a MIB where the cellBarred value is set to barred, the DSM may be configured so that the terminal always disables SEB 1. Therefore, as shown in the example figure above, SEB 1 is disabled. The DSM (340) can determine the list of SEBs to be activated by the terminal through the above steps and notify the terminal of the list by transmitting the selected SEB capability IE (step 308).

[0079]

[0080] FIG. 6 is a diagram showing detailed operation according to the embodiment illustrated in FIG. 3 of the present invention.

[0081] Subsequently, the DSM (340) may transmit a UE SEB Configuration Setup message to the AMF (360) (step 308), and the message may include a Selected SEB capability, which is a list of SEBs to be activated by the UE. Upon receiving this, the AMF (360) may transmit the message to the UE (380) (step 308). The UE (380) may store the received SEB parameter (step 309). The UE (380) may activate the SEB according to the SEB parameter value it has stored (step 310).

[0082] In the present invention, the terminal can activate the use of each SEB using SEB parameters it stores. This is updated by the selected SEB capability value, which is a parameter transmitted from the terminal by the network; this means that the SEB activated by the terminal is determined according to the selected SEB capability value transmitted by the network to the terminal. Additionally, these SEB parameters can be stored in advance by the terminal manufacturer within the terminal or by the network operator provisioning them on the SIM card. Through this, the terminal can activate the SEB even before connecting to the network. By applying this, the proposed terminal can activate the SEB even without changes to the mobile communication network (i.e., even in existing networks where a DSM does not exist). In this case, although there is a risk of reduced compatibility with the network, the security of the terminal can be enhanced.

[0083] In addition, as illustrated in the first and second embodiments described below, the existing operation of the SEB and the terminal may not be a simple single operation, but may be a change in the operation flow of the terminal. Specifically, it can be interpreted as a change in the state of the terminal and the conditions for state change. To implement this, the terminal can be implemented by using the value for each SEB of the selected SEB capability as a kind of flag, so that it can move to a newly implemented state only when the flag value is 1.

[0084] Finally, since the operations including the SEB covered in this invention are performed in the control plane, these implementations must be performed in the baseband of the mobile communication terminal. The figure below shows the changes in the terminal's operation depending on whether the SEB is used.

[0085] Afterwards, the UE (380) can determine whether activation was successful or failed by comparing the list of SEBs that were successfully activated with the list of SEBs that it has stored. Afterwards, the information can be included in the UE SEB Configuration Complete message and transmitted to the DSM (340) via the AMF (360) (step 311).

[0086]

[0087] The following describes the first and second embodiments regarding security enhancing behavior (SEB). Specifically, SEB refers to the operation of a terminal to defend against attacks utilizing known mobile communication standard vulnerabilities. As introduced in the background of the invention, all currently used mobile communication terminals are unable to respond to attacks utilizing standard vulnerabilities. Taking into account that some of the messages used in such attacks may not be used in specialized networks, the present invention proposes that when such messages are detected in a specialized network terminal, the terminal considers them as an attack and performs a defensive operation. Examples of attacks utilizing standard vulnerabilities and corresponding SEBs are presented below.

[0088]

[0089] <1st Embodiment: Exploiting access barring>

[0090] One example of SEB is a response to attacks that exploit access barring in broadcast messages. Access barring is a technology in 5G that prevents terminals from connecting to specific cells and base stations. This is intended to prepare for surges in network traffic during emergencies, such as war or natural disasters, and prevents high-priority users from being unable to use services.

[0091]

[0092] The figure above illustrates the structure of a 5G MIB. Each base station periodically broadcasts MIB (Master Information Block) messages, and the cellBarred IE in the MIB indicates whether access barring has been applied to the corresponding cell. If the cellBarred IE is barred, it is a cell with access barring applied, and terminals do not attempt to connect to that cell. Generally, most cells are in a notBarred state, so terminals can attempt to connect to them.

[0093] Meanwhile, MIB messages are not protected under mobile communication standards. MIB messages are PHY layer messages, and messages at this layer are not protected in any mobile communication technology. Therefore, an attacker can overshadow the cell-barred IE of MIB messages by executing a SigOver (Signal Overshadowing) attack, which is well-known in academia. As a result of this attack, the terminal does not attempt to connect to the corresponding cell. A SigOver attack is an attack that overwrites a signal; for example, in the case of Downlink SigOver, it refers to an attack where the attacker sends a stronger signal they have generated at the timing when the normal downlink signal arrives at the terminal. In this case, because the attacker's signal strength is stronger, the terminal cannot decipher the normal signal and perceives the attacker's signal as the normal signal, processing it accordingly. As another example, it is known that SigOver attacks are possible with Broadcast messages, as the timing for reception by the terminal is determined based on the reference signal.

[0094] This study demonstrated that an attack is possible by actually overshadowing the IE present in the LTE SIB. Although the aforementioned attack was not directly introduced in the paper, the SigOver attacker described in the paper is capable of executing it.

[0095]

[0096] FIG. 7 is a diagram showing a conventional operation of a first embodiment of the present invention.

[0097] In a normal MIB transmitted by an NPN base station, cellBarred is set to notBarred; however, a SigOver attacker can overshadow cellBarred to barred by overwriting a subframe. As a result, the UE perceives the cellBarred value of the corresponding cell MIB as being set to barred and does not connect to that cell.

[0098] In particular, this attack can have a significant impact on specialized networks. In the case of specialized networks, network operators can identify terminals connected to the network, such as sensors, allowing for more efficient cell planning compared to public networks. In other words, compared to public networks, each terminal is more likely to fall within the range of a single cell, and in such cases, the impact of this attack can be greater.

[0099] On the other hand, in NPN, there are virtually no cases where cellBarred is used as barred. As mentioned above, access barring is a technique intended to block terminal connections in emergency situations; however, considering the use cases of specialized networks, specialized network terminals should actually be guaranteed connectivity in emergency situations. Furthermore, since users are less fluid compared to public networks, the probability of being overloaded by traffic is also low. In conclusion, unlike public networks, it is highly likely that access barring is not used in NPN; therefore, NPN terminals can assume that an MIB with the cellBarred value set to barred is an attack vector.

[0100] To counter the above attack, the terminal can act as follows. First, the terminal can always treat the cellBarred IE in the MIB as not barred. That is, the terminal can attempt to connect to the cell even if the cellBarred IE value is barred. In this case, the terminal can connect to that cell as well and escape the impact of the attack. Additionally, SigOver can generally only attack terminals connected to a single cell, because the timing of each cell's reference signal transmission varies. Therefore, if the terminal determines that it has been attacked, it can connect to another cell to escape the attack.

[0101]

[0102] FIG. 8 is a diagram illustrating the proposed operation according to the first embodiment of the present invention. In FIG. 7, the terminal does not attempt to connect to a cell where the cellBarred value is set to barred. In this case, it searches for other cells, and if there are no connectable cells, it cannot receive service. On the other hand, in the operation of FIG. 8, the terminal can always attempt registration with the corresponding cell regardless of the cellBarred value of the received MIB. At this time, if an Authentication request message is received, the terminal completes the connection procedure. If the response timer expires or another message is received, the terminal searches for other cells excluding that cell. The figure below shows the control plane flow when an attack occurs on a terminal to which the corresponding SEB is applied.

[0103]

[0104] FIG. 9 is a diagram showing a flowchart according to a first embodiment of the present invention. FIG. 9 is a flowchart for explaining a comparison between a conventional operation and a proposed operation. Specifically, in the conventional operation, when a terminal receives a cellBarred among the IEs included in the MIB in a barred state during the process of cell search, the cell that broadcasted cellBarred as barred is excluded, and other cells are searched. Subsequently, if there is a connectable cell, a connection is attempted, and if there is no connectable cell, the service cannot be provided. Accordingly, there is a problem in that if an attacker attacks cellBarred included in the received MIB as barred, the service of that cell can be disrupted.

[0105] Therefore, in the proposed operation, even if the cellBarred field among the IEs included in the MIB is received as barred during the terminal's cell search process, the cell connection procedure is carried out regardless of the cellBarred field. A Registration Request is sent to the AMF, and a connection is established upon receiving an authentication-related message from the AMF. If an authentication-related message is not received from the AMF or the timer expires, that cell is excluded, and another cell is searched. Subsequently, if a connectable cell is found, a connection is attempted; if no connectable cell is found, the service is not provided. Thus, by proceeding with the cell connection procedure regardless of the cellBarred field even when the cellBarred field among the IEs included in the MIB is received as barred, it is possible to defend against attacks where an attacker attempts to set the cellBarred field to barred.

[0106]

[0107] <2nd Embodiment: Bidding Down Using Registration Reject>

[0108] Another example of enhanced security behavior is a bidding down attack using a Registration reject message. A bidding down attack is an attack aimed at lowering the security level by replacing the technology used by a terminal with a lower-tier one. The bidding down described in this attack refers to downgrading the RAT used by the terminal from 5G to LTE, 3G, etc.

[0109] First, this attack exploits a standard vulnerability in the registration reject message. According to the standard, when a terminal receives a registration reject message with the reject cause set to #27 (N1 mode not allowed), the terminal disables 5G functions. It should be noted that the terminal performs the same action for messages that are not integrity protected. Therefore, an attacker can attack the terminal by sending the message through an FBS attack (Embodiment 2-1) and a SigOver attack (Embodiment 2-2).

[0110]

[0111] FIG. 10 is a diagram illustrating a prior operation for the 2-1 embodiment of the present invention. FIG. 10 illustrates the attack flow of an attacker using an FBS. It is assumed that the terminal is connected to a specialized network. The attacker operates the FBS with high intensity to induce the terminal to connect to the FBS. When the induced terminal transmits a registration request, the FBS transmits a registration reject (cause #27) message. At this time, the FBS transmits the message without integrity protection. As a result, the terminal disables its 5G function. Since the specialized network used by the terminal operates only 5G, the terminal is now unable to connect to the specialized network and falls into a DoS state. For reference, since integrity protection is not required for the message, the attacker can also generate the message.

[0112]

[0113] FIG. 11 is a diagram illustrating a conventional operation for the 2-2 embodiment of the present invention. FIG. 11 illustrates an attack scenario assuming a SigOver attacker. It is assumed that the terminal is connected to a specialized network. To connect to the network, the terminal sends a registration request message, and the attacker first sends a registration reject (cause #27) message before the network responds to this message with an authentication request. This is an attack possible because, in the case of a downlink message, the SigOver attacker can directly generate a DCI message and send it to the UE. Since the UE receives the attacker's message, it does not process the authentication request sent by the network and disables the 5G function. Since the specialized network used by the terminal operates only 5G, the terminal is now unable to connect to the specialized network and falls into a DoS state.

[0114] Meanwhile, unlike the public network, it can be expected that the specialized network will not use the registration reject (cause 27) message for two reasons. First, a terminal receiving registration reject (cause 27) disables its 5G function, making it impossible for that terminal to connect to the specialized network normally. Therefore, it can be expected that the specialized network will not transmit the message, taking this into consideration. Second, this message is sent to terminals that are not allowed 5G, but since the specialized network uses only 5G, there is no possibility for a legitimate NPN terminal to receive this message. Therefore, a terminal receiving the registration reject (cause 27) message can determine that it has been attacked. In this case, the terminal can escape the attack by considering both of the above attacker models and following the following flow of action.

[0115]

[0116] FIGS. 12 and 13 are diagrams illustrating the proposed operation according to a second embodiment of the present invention. In FIGS. 10 and 11, the terminal is placed in a state of waiting for a response after transmitting a registration request message. Subsequent operations may vary depending on the response from the network; if an authentication request message is received as a response, the remaining registration procedure is executed, and if a registration reject #27 message is received as a response, the terminal disables its 5G function. When no response is received and the response waiting timer expires, the terminal retryes registration. This can be repeated as many times as the registration attempt counter internally managed by the terminal, and this value is generally set to 5. After attempting the counter times, the terminal searches for another cell.

[0117] Therefore, the operation proposed through the present invention suggests that when registration reject #27 is received in a response waiting state, instead of disabling the 5G function, the message is not processed and awaiting an additional response is waited for. If an authentication request message is subsequently received, it is assumed that a SigOver attack occurred, and the subsequent registration procedure is completed. If no additional response is received or no response is received, the registration attempt counter is retried as before. This is because the state of continuously receiving registration reject #27 messages can be considered as a state connected to the FBS, and consequently, the terminal can search for another cell.

[0118] That is, FIGS. 12 and FIGS. 13 respectively show the behavior of a terminal with the proposed behavior implemented when a SigOver attacker executes an attack and the behavior of a terminal with the proposed behavior implemented when an attacker operating an FBS executes an attack. As can be seen in FIGS. 12 and FIGS. 13, a terminal with the proposed behavior implemented can escape from the aforementioned attack.

[0119]

[0120] FIG. 14 is a diagram showing a flowchart according to a second embodiment of the present invention. FIG. 14 is a flowchart for explaining a comparison between a conventional operation and a proposed operation. Specifically, in the case of attempting 5G registration in the conventional operation, the terminal transmits a registration request to a base station, waits for a response, and proceeds with the remaining registration procedure upon receiving an Authentication request message from the base station. However, if a registration reject is received, the 5G function is disabled, and if no message is received, the terminal waits for a response and attempts 5G registration again for the number of attempts countered, and if the attempt counter is 0, it searches for another cell. In this case, there is a problem in that the 5G function is immediately disabled when a registration reject is received due to an FBS attack (Embodiment 2-1) or a Sigover attack (Embodiment 2-2).

[0121] Therefore, in the proposed operation, when a terminal attempts 5G registration and receives a registration reject from the base station, it is unclear whether this is a BS attack (Embodiment 2-1) or a Sigover attack (Embodiment 2-2). Thus, a method is proposed to suspend the processing of the response to the message and wait for an additional response without disabling the 5G function. Subsequently, if an Authentication request message is received, it is assumed that an attack occurred, and the subsequent registration procedure is completed. If no additional response is received or no response is received, the registration attempt counter is retried as before. Subsequently, if the attempt counter is 0, another cell is searched.

[0122]

[0123] FIG. 15 is a diagram illustrating the structure of a terminal according to one embodiment of the present invention.

[0124] Referring to FIG. 15, the terminal may include a transceiver (1510), a control unit (1520), and a storage unit (1530). In the present invention, the control unit may be defined as a circuit or an application-specific integrated circuit or at least one processor.

[0125] The transmitting and receiving unit (1510) can transmit and receive signals with other network entities.

[0126] The control unit (1520) can control the overall operation of the terminal according to the embodiment proposed in the present invention. For example, the control unit (1520) can control the signal flow between each block to perform operations according to the flowchart described above.

[0127] The storage unit (1530) can store at least one of the information transmitted and received through the transmission and reception unit (1510) and the information generated through the control unit (1520).

[0128]

[0129] FIG. 16 is a diagram illustrating the structure of a network entity according to one embodiment of the present invention.

[0130] Referring to FIG. 16, the network entity may include a transceiver (1610), a control unit (1620), and a storage unit (1630). In the present invention, the control unit may be defined as a circuit or an application-specific integrated circuit or at least one processor.

[0131] The transmitting and receiving unit (1610) can transmit and receive signals with other network entities.

[0132] The control unit (1620) can control the overall operation of the terminal according to the embodiment proposed in the present invention. For example, the control unit (1620) can control the signal flow between each block to perform operations according to the flowchart described above. The storage unit (1630) can store at least one of the information transmitted and received through the transmission and reception unit (1610) and the information generated through the control unit (1620).

[0133]

[0134] The operations of the embodiments described above can be realized by providing a memory device storing the corresponding program code in any component within the device. That is, the control unit within the device can execute the operations described above by reading the program code stored in the memory device by a processor or a CPU (Central Processing Unit) and executing it.

[0135] The entities or various components of terminal devices and modules described in this disclosure may be operated using hardware circuits, such as, for example, complementary metal oxide semiconductor-based logic circuits, firmware, software, and / or a combination of hardware and firmware and / or software embedded in a machine-readable medium. For example, various electrical structures and methods may be implemented using electrical circuits such as transistors, logic gates, and application-specific semiconductors.

[0136] Methods according to the claims or embodiments described in the specification of the present disclosure may be implemented in the form of hardware, software, or a combination of hardware and software.

[0137] When implemented in software, a computer-readable storage medium may be provided for storing one or more programs (software modules). One or more programs stored in the computer-readable storage medium are configured for execution by one or more processors within an electronic device. One or more programs include instructions that cause the electronic device to execute methods according to the claims or embodiments described in the specification of this disclosure.

[0138] These programs (software modules, software) may be stored in random access memory, non-volatile memory including flash memory, read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic disc storage device, compact disc-ROM (CD-ROM), digital versatile discs (DVDs), or other forms of optical storage devices, magnetic cassettes. Alternatively, they may be stored in a memory composed of some or all of these. Additionally, each constituent memory may include multiple units.

[0139] Additionally, the program may be stored on an attachable storage device that can be accessed via a communication network such as the Internet, Intranet, LAN (local area network), WAN (wide area network), or SAN (storage area network), or a combination thereof. Such a storage device may be connected to a device performing an embodiment of the present disclosure through an external port. Additionally, a separate storage device on a communication network may be connected to a device performing an embodiment of the present disclosure.

[0140] In the specific embodiments of the present disclosure described above, the components included in the disclosure are expressed in a singular or plural form according to the specific embodiments presented. However, the singular or plural expression is selected to suit the situation presented for convenience of explanation, and the present disclosure is not limited to singular or plural components; even if a component is expressed in the plural form, it may be composed of a singular form, and even if a component is expressed in the singular form, it may be composed of a plural form.

[0141] Meanwhile, although specific embodiments have been described in the detailed description of the present disclosure, it is understood that various modifications are possible within the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be defined by the claims set forth below as well as equivalents thereof.

Claims

1. A method performed by a user device (User equipment, UE) in a wireless communication system, A step of transmitting a registration request message containing information indicating whether security enhancement technology has been applied to an AMF (Access and Mobility Management Function); A step of receiving a first message from the above AMF requesting UE security configuration capability; A step of transmitting a second message including the UE security setting capability to the above AMF; A step of receiving a message including UE security settings from the above AMF; and The above includes the step of enabling the UE security settings, A method characterized in that the above UE security settings are determined by a network entity based on the above UE security capabilities.

2. In Paragraph 1, A method characterized by including whether the above-mentioned UE security setting supports a response to an access barring attack included in the Master Information Block (MIB).

3. In Paragraph 1, A method characterized by including whether the above-mentioned UE security setting supports a response to a Registration reject attack.

4. In Paragraph 1, A method characterized in that the information indicating whether the above-mentioned security enhancement technology has been applied is bit information.

5. A method performed by a wireless communication system network entity, A step of receiving a message from a UE (User equipment) including UE security configuration capabilities through an AMF (Access and Mobility management Function); A step of determining the UE security settings to be activated based on the above-mentioned UE security setting capability; and The method includes the step of transmitting the determined UE security settings to the above UE via the above AMF, and A method characterized by enabling UE security settings based on the above-determined UE security settings.

6. In Paragraph 5, A method characterized by including whether the above-mentioned UE security setting supports a response to an access barring attack included in the Master Information Block (MIB).

7. In Paragraph 5, A method characterized by including whether the above-mentioned UE security setting supports a response to a Registration reject attack.

8. In Paragraph 5, A method characterized in that the information indicating whether the above-mentioned security enhancement technology has been applied is bit information.

9. In a user device (User equipment, UE) in a wireless communication system, A transceiver capable of transmitting and receiving at least one signal; and It includes a control unit coupled with the above-mentioned transmitting and receiving unit, and The above control unit is: Send a registration request message containing information indicating whether security enhancement technology has been applied to the AMF (Access and Mobility Management Function), and Receive a first message from the above AMF requesting UE security configuration capability, and Transmit a second message including the UE security configuration capability to the above AMF, and From the above AMF, receive a message including UE security settings, and Configured to enable the above UE security settings, A user device characterized in that the above UE security setting is determined by a network entity based on the above UE security setting capability.

10. In Paragraph 9, A user device characterized by the above UE security settings including whether they support a response to an access barring attack included in the Master Information Block (MIB).

11. In Paragraph 9, A user device characterized by the above UE security settings including whether they support a response to a Registration reject attack.

12. In Paragraph 9, A user device characterized in that information indicating whether the above-mentioned security enhancement technology has been applied is bit information.

13. In network entities in wireless communication systems, A transceiver capable of transmitting and receiving at least one signal; and It includes a control unit coupled with the above-mentioned transmitting and receiving unit, and The above control unit is: A message including UE security configuration capabilities is received from UE (User equipment) via AMF (Access and Mobility management Function), and Determine the UE security settings to be activated based on the above UE security setting capability, and It is configured to transmit the determined UE security settings to the above UE via the above AMF, and A network entity characterized by enabling UE security settings based on the above-determined UE security settings.

14. In Paragraph 13, The above UE security settings include whether they support a response to access barring attacks included in the Master Information Block (MIB), and A network entity characterized by the above UE security settings including whether they support a response to a Registration reject attack.

15. In Paragraph 13, A network entity characterized by the fact that information indicating whether the above-mentioned security enhancement technology has been applied is bit information.