Methods and apparatuses for supporting system information (SI) security protection

WO2026174837A1PCT designated stage Publication Date: 2026-08-27LENOVO (BEIJING) LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/133050
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-11-06
Publication Date
2026-08-27

Smart Images

  • Figure CN2025133050_27082026_PF_FP_ABST
    Figure CN2025133050_27082026_PF_FP_ABST
Patent Text Reader

Abstract

Various aspects of the present application relate to methods and apparatuses for supporting system information (SI) security protection in a wireless communications system. According to an embodiment of the present application, a UE includes at least one memory and at least one processor coupled to the at least one memory and configured to cause the UE to: receive, from a radio access network (RAN) node, SI of a cell of the RAN node and a set of digital signatures, wherein the SI is carried in at least one of a master information block (MIB) or a set of system information blocks (SIBs), and wherein the set of digital signatures is generated by using a private key from a pair of {the private key, a public key} and the SI as inputs to a security algorithm; generate another SI by using the set of digital signatures and the public key as the inputs to the security algorithm; and determine that the cell is authentic if the another SI is identical with the SI, or consider that the cell is barred if the another SI is different from the SI.
Need to check novelty before this filing date? Find Prior Art

Description

METHODS AND APPARATUSES FOR SUPPORTING SYSTEM INFORMATION (SI) SECURITY PROTECTIONTECHNICAL FIELD

[0001] Embodiments of the present application generally relate to wireless communication technology, especially to methods and apparatuses for supporting system information (SI) security protection in a wireless communications system.BACKGROUND

[0002] A wireless communications system may include one or multiple network communication devices, such as base stations, which may support wireless communications for one or multiple user communication devices, which may be otherwise known as UE, or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g. time-domain resources (e.g. symbols, slots, subframes, frames, or the like) or frequency-domain resources (e.g. subcarriers, carriers, or the like) . Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g. sixth generation (6G) ) .SUMMARY

[0003] An article "a" before an element is unrestricted and understood to refer to "at least one" of those elements or "one or more" of those elements. The terms "a, " "at least one, " "one or more, " and "at least one of one or more" may be interchangeable. As used herein, including in the claims, "or" as used in a list of items (e.g. a list of items prefaced by a phrase such as "at least one of" or "one or more of" or "one or both of" ) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e. A and B and C) . Also, as used herein, the phrase "based on" shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as "based on condition A" may be based on both a condition A and a condition B without departing from the scope of the present application. In other words, as used herein, the phrase "based on" shall be construed in the same manner as the phrase "based at least in part on. Further, as used herein, including in the claims, a "set" may include one or more elements.

[0004] Some implementations of the present application provide a user equipment (UE) for wireless communication. The UE includes at least one memory; and at least one processor coupled to the at least one memory and configured to cause the UE to: receive, from a radio access network (RAN) node, first system information (SI) of a first cell of the RAN node and a set of first digital signatures, wherein the first SI is carried in at least one of a master information block (MIB) or a set of first system information blocks (SIBs) , and wherein the set of first digital signatures is generated by using a first private key from a pair of {the first private key, a first public key} and the first SI as inputs to a first security algorithm; generate second SI by using the set of first digital signatures and the first public key as the inputs to the first security algorithm; and determine that the first cell is authentic if the second SI is identical with the first SI, or consider that the first cell is barred if the second SI is different from the first SI.

[0005] In some implementations of the UE described herein, the set of first SIBs includes the set of first digital signatures.

[0006] In some implementations of the UE described herein, the first SI is carried in system information block1 (SIB1) , and the SIB1 includes at least one of the following: scheduling information regarding third SI, wherein the third SI includes the first public key; or a configuration used by the UE to request the third SI.

[0007] In some implementations of the UE described herein, the at least one processor is further configured to cause the UE to receive the third SI from the RAN node.

[0008] In some implementations of the UE described herein, before receiving the third SI, the at least one processor is further configured to cause the UE to transmit a request for the third SI to the RAN node based on the configuration.

[0009] In some implementations of the UE described herein, the third SI further includes at least one of the following: the first security algorithm; valid time duration of the first public key; or a first valid area of the first public key, wherein the first valid area covers all cells of the RAN node, one or more cells of the RAN node, or a protecting area related to the RAN node.

[0010] In some implementations of the UE described herein, the third SI is carried in a second SIB different from the SIB1 and the MIB, the second SIB includes a second digital signature, the second digital signature is generated by using the third SI and a second private key from a pair of {the second private key, a second public key} as inputs to a second security algorithm, and the second security algorithm is identical with or different from the first security algorithm.

[0011] In some implementations of the UE described herein, the at least one processor is further configured to cause the UE to: generate fourth SI by using the second digital signature and the second public key as the inputs to the second security algorithm, wherein the second public key is pre-configured in the UE or received by the UE from the RAN node; and determine that the first cell is authentic if the fourth SI is identical with the third SI, or consider that the first cell is barred if the fourth SI is different from the third SI.

[0012] In some implementations of the UE described herein, the SIB1 further includes the set of first digital signatures, and the first SI is: the SIB1 except the set of first digital signatures; or the MIB, and the SIB1 except the set of first digital signatures.

[0013] In some implementations of the UE described herein, after determining that the first cell is authentic, the at least one processor is further configured to cause the UE to: store system information included in the SIB1; or store the MIB and the system information included in the SIB1.

[0014] In some implementations of the UE described herein, after considering that the first cell is barred, the at least one processor is further configured to cause the UE to: discard the MIB and system information included in the SIB1, and perform a cell re-selection towards one or more cells of the RAN node other than the first cell; or consider that the RAN node to which the first cell belongs is barred.

[0015] In some implementations of the UE described herein, the at least one processor is further configured to cause the UE to: exclude the first cell as a candidate for a cell selection or a cell re-selection of the UE after considering that the first cell is barred; or exclude all cells of the RAN node as candidates for the cell selection or the cell re-selection of the UE after considering that the RAN node is barred.

[0016] In some implementations of the UE described herein, the at least one processor is further configured to cause the UE to initiate a radio resource control (RRC) connection reestablishment procedure or enter an RRC idle state if the UE is in an RRC connected state.

[0017] In some implementations of the UE described herein, the at least one processor is further configured to cause the UE to receive, from the RAN node, fifth SI different from the first SI and the third SI, and wherein the fifth SI includes the set of first digital signatures.

[0018] In some implementations of the UE described herein, the set of first digital signatures includes at least one of the following: a digital signature associated with one SIB within the set of first SIBs; or a digital signature associated with two or more SIBs within the set of first SIBs.

[0019] In some implementations of the UE described herein, the SIB1 further includes at least one of the following: scheduling information regarding the fifth SI; information indicating that the SIB1 is security protected; information indicating that the MIB is security protected; a set of third SIBs that is security protected; or a set of fourth SIBs that is not security protected.

[0020] In some implementations of the UE described herein, the SIB1 further includes a set of indicators associated with the set of third SIBs, and each indicator within the set of indicators indicates that one SIB within the set of third SIBs is security protected.

[0021] In some implementations of the UE described herein, after considering that one or more cells of the RAN node are barred, the at least one processor is further configured to cause the UE to transmit identifier information of the one or more cells to the RAN node.

[0022] In some implementations of the UE described herein, the at least one processor is further configured to cause the UE to transmit one of the following to the RAN node: a set of SI without successful security verification of each cell within the one or more cells; or information indicating that verification of the third SI is failed.

[0023] In some implementations of the UE described herein, to receive the first SI, the at least one processor is further configured to cause the UE to receive, from the RAN node, a system information message including the set of first SIBs carrying the first SI, and wherein: the system information message includes one or more indicators, and each indicator within the one or more indicators indicates that one SIB within the set of first SIBs is security protected; or the system information message includes one indicator indicating that the set of first SIBs is security protected.

[0024] Some implementations of the present application provide a processor for wireless communication, comprising at least one controller coupled with at least one memory and configured to cause the processor to: receive, from a radio access network (RAN) node, first system information (SI) of a first cell of the RAN node and a set of first digital signatures, wherein the first SI is carried in at least one of a master information block (MIB) or a set of first system information blocks (SIBs) , and wherein the set of first digital signatures is generated by using a first private key from a pair of {the first private key, a first public key} and the first SI as inputs to a first security algorithm; generate second SI by using the set of first digital signatures and the first public key as the inputs to the first security algorithm; and determine that the first cell is authentic if the second SI is identical with the first SI, or consider that the first cell is barred if the second SI is different from the first SI.

[0025] Some implementations of the present application provide a method performed by a user equipment (UE) for wireless communication. The method includes: receiving, from a radio access network (RAN) node, first system information (SI) of a first cell of the RAN node and a set of first digital signatures, wherein the first SI is carried in at least one of a master information block (MIB) or a set of first system information blocks (SIBs) , and wherein the set of first digital signatures is generated by using a first private key from a pair of {the first private key, a first public key} and the first SI as inputs to a first security algorithm; generating second SI by using the set of first digital signatures and the first public key as the inputs to the first security algorithm; and determining that the first cell is authentic if the second SI is identical with the first SI, or considering that the first cell is barred if the second SI is different from the first SI.

[0026] Some implementations of the present application provide a radio access network (RAN) node for wireless communication. The RAN node includes at least one memory; and at least one processor coupled to the at least one memory and configured to cause the RAN node to: generate a set of first digital signatures by using a first private key from a pair of {the first private key, a first public key} and first system information (SI) of a first cell of the RAN node as inputs to a first security algorithm; and transmit the first SI and the set of first digital signatures to a user equipment (UE) , wherein the first SI is carried in at least one of a master information block (MIB) or a set of first system information blocks (SIBs) .

[0027] In some implementations of the RAN node described herein, the set of first SIBs includes the set of first digital signatures.

[0028] In some implementations of the RAN node described herein, the first SI is carried in system information block1 (SIB1) , and the SIB1 includes at least one of the following: scheduling information regarding third SI, wherein the third SI includes the first public key; or a configuration used by the UE to request the third SI.

[0029] In some implementations of the RAN node described herein, the at least one processor is further configured to cause the RAN node to transmit the third SI to the UE.

[0030] In some implementations of the RAN node described herein, before transmitting the third SI, the at least one processor is further configured to cause the RAN node to receive a request for the third SI from the UE.

[0031] In some implementations of the RAN node described herein, the at least one processor is further configured to cause the RAN node to generate a second digital signature by using the third SI and a second private key from a pair of {the second private key, a second public key} as inputs to a second security algorithm, and wherein the second security algorithm is identical with or different from the first security algorithm.

[0032] In some implementations of the RAN node described herein, the at least one processor is further configured to cause the RAN node to transmit a second SIB to the UE, and wherein the second SIB includes the third SI and the second digital signature.

[0033] In some implementations of the RAN node described herein, the third SI further includes at least one of the following: the first security algorithm; valid time duration of the first public key; or a first valid area of the first public key, wherein the first valid area covers all cells of the RAN node, one or more cells of the RAN node, or a protecting area related to the RAN node.

[0034] In some implementations of the RAN node described herein, the SIB1 further includes the set of first digital signatures, and the first SI is: the SIB1 except the set of first digital signatures; or the MIB, and the SIB1 except the set of first digital signatures.

[0035] In some implementations of the RAN node described herein, the at least one processor is further configured to cause the RAN node to transmit fifth SI different from the first SI and the third SI to the UE, and wherein the fifth SI includes the set of first digital signatures.

[0036] In some implementations of the RAN node described herein, the set of first digital signatures includes at least one of the following: a digital signature associated with one SIB within the set of first SIBs; or a digital signature associated with two or more SIBs within the set of first SIBs.

[0037] In some implementations of the RAN node described herein, the SIB1 further includes at least one of the following: scheduling information regarding the fifth SI; information indicating that the SIB1 is security protected; information indicating that the MIB is security protected; a set of third SIBs that is security protected; or a set of fourth SIBs that is not security protected.

[0038] In some implementations of the RAN node described herein, the SIB1 further includes a set of indicators associated with the set of third SIBs, and each indicator within the set of indicators indicates that one SIB within the set of third SIBs is security protected.

[0039] In some implementations of the RAN node described herein, the at least one processor is further configured to cause the RAN node to receive identifier information of one or more cells of the RAN node from the UE if the one or more cells are considered as barred.

[0040] In some implementations of the RAN node described herein, the at least one processor is further configured to cause the RAN node to receive one of the following from the UE: a set of SI without successful security verification of each cell within the one or more cells; or information indicating that verification of the third SI is failed.

[0041] In some implementations of the RAN node described herein, to transmit the first SI, the at least one processor is further configured to cause the RAN node to transmit, to the UE, a system information message including the set of first SIBs carrying the first SI, and wherein: the system information message includes one or more indicators, and each indicator within the one or more indicators indicates that one SIB within the set of first SIBs is security protected; or the system information message includes one indicator indicating that the set of first SIBs is security protected.

[0042] In some implementations of the RAN node described herein, the at least one processor is further configured to cause the RAN node to receive security information used for SI security protection from a core network (CN) node.

[0043] In some implementations of the RAN node described herein, the RAN node includes a distributed unit (DU) and a central unit (CU) , and wherein the at least one processor is further configured to cause the CU to transmit security information used for SI security protection to the DU.

[0044] In some implementations of the RAN node described herein, the at least one processor is further configured to cause the DU to transmit security capability supported by the DU to the CU, and the security capability includes at least one of the following: information indicating whether the DU supports the SI security protection; or one or more security algorithms supported by the DU for the SI security protection.

[0045] In some implementations of the RAN node described herein, the RAN node includes a distributed unit (DU) and a central unit (CU) , and wherein the at least one processor is further configured to cause the DU to transmit security information used for SI security protection to the CU.

[0046] In some implementations of the RAN node described herein, the security information used for the SI security protection includes at least one of the following: the first security algorithm; the second security algorithm; one or more first private keys or one or more pairs of {the first private key, the first public key} ; valid time duration of each first private key within the one or more first private keys or each pair within the one or more pairs of {the first private key, the first public key} ; identifier information of each first private key within the one or more first private keys or each pair within the one or more pairs of {the first private key, the first public key} ; a first valid area of each first private key within the one or more first private keys or each pair within the one or more pairs of {the first private key, the first public key} ; one or more second private keys or one or more pairs of {asecond private key, a second public key} ; valid time duration of each second private key within the one or more second private keys or each pair within the one or more pairs of {the second private key, the second public key} ; identifier information of each second private key within the one or more second private keys or each pair within the one or more pairs of {the second private key, the second public key} ; or a second valid area of each second private key within the one or more second private keys or each pair within the one or more pairs of {the second private key, the second public key} , wherein at least one of the first valid area or the second valid area covers all cells of the RAN node, one or more cells of the RAN node, or a protecting area related to the RAN node.

[0047] Some implementations of the present application provide a processor for wireless communication, comprising at least one controller coupled with at least one memory and configured to cause the processor to: generate a set of first digital signatures by using a first private key from a pair of {the first private key, a first public key} and first system information (SI) of a first cell of a radio access network (RAN) node as inputs to a first security algorithm; and transmit the first SI and the set of first digital signatures to a user equipment (UE) , wherein the first SI is carried in at least one of a master information block (MIB) or a set of first system information blocks (SIBs) .

[0048] Some implementations of the present application provide a method performed by a radio access network (RAN) node for wireless communication. The method includes: generating a set of first digital signatures by using a first private key from a pair of {the first private key, a first public key} and first system information (SI) of a first cell of the RAN node as inputs to a first security algorithm; and transmitting the first SI and the set of first digital signatures to a user equipment (UE) , wherein the first SI is carried in at least one of a master information block (MIB) or a set of first system information blocks (SIBs) .BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1A illustrates an example of SI security protection using an asymmetric algorithm in accordance with aspects of the present application.

[0050] Figure 1 illustrates an example of a wireless communications system in accordance with aspects of the present application.

[0051] Figure 2 illustrates an example of a UE 200 in accordance with aspects of the present application.

[0052] Figure 3 illustrates an example of a processor 300 in accordance with aspects of the present application.

[0053] Figure 4 illustrates an example of a network equipment (NE) 400 in accordance with aspects of the present application.

[0054] Figure 5 illustrates a flowchart of a method performed by a UE in accordance with aspects of the present application.

[0055] Figure 6 illustrates a flowchart of a method performed by a RAN node in accordance with aspects of the present application.

[0056] Figures 7 and 8 illustrate exemplary signalling flows of performing SI security protection in accordance with aspects of the present application.

[0057] Figures 9 and 10 illustrate exemplary signalling flows of performing SI security protection in a split RAN architecture in accordance with aspects of the present application.DETAILED DESCRIPTION

[0058] In a wireless communications system, broadcasting system information (SI) is one of essential functions in a RAN node. The SI may include information like cell (re-) selection parameters, neighbouring cell information, frequency priority, blocklisted cell, common channel configuration information, non-access stratum (NAS) common information, and public warning system messages. The SI is intended for all UEs in RRC_IDLE, RRC_INACTIVE, and RRC_CONNECTED states which are camping on a cell of the RAN node. For example, in the RRC_IDLE state or RRC_INACTIVE state, a UE typically acquires the SI from the cell and performs initial access to transition to the RRC_CONNECTED state to obtain services.

[0059] In general, the SI consists of a MIB and a number of SIBs, which are divided into "Minimum SI" and "Other SI" as below. (1) "Minimum SI" comprises basic information required for initial access and information for acquiring any other SI. "Minimum SI" consists of: - MIB contains cell barred status information and essential physical layer information of the cell required to receive further system information, e.g. CORESET#0 configuration. MIB is periodically broadcast on a broadcast channel (PBCH) . - SIB1 defines the scheduling of other system information blocks and contains information required for initial access. SIB1 is also referred to as Remaining Minimum SI (RMSI) and is periodically broadcast on a downlink shared channel (DL-SCH) or sent in a dedicated manner on DL-SCH to UEs in RRC_CONNECTED. (2) "Other SI" encompasses all SIBs not broadcast in "Minimum SI" . Those SIBs can either be periodically broadcast on DL-SCH, broadcast on-demand on DL-SCH (i.e. upon request from UEs in RRC_IDLE, RRC_INACTIVE, or RRC_CONNECTED) , or sent in a dedicated manner on DL-SCH to UEs in RRC_CONNECTED (i.e. upon request, if configured by the network, from UEs in RRC_CONNECTED or when the UE has an active a bandwidth part (BWP) with no common search space configured or when the UE configured with inter cell beam management is receiving DL-SCH from a transmission reception point (TRP) with a physical cell identifier (PCI) different from serving cell's PCI) . -- "Other SI" consists of: - SIB2 contains cell re-selection information, mainly related to the serving cell; - SIB3 contains information about the serving frequency and intra-frequency neighbouring cells relevant for cell re-selection (including cell re-selection parameters common for a frequency as well as cell specific re-selection parameters) ; - SIB4 contains information about other new radio (NR) frequencies and inter-frequency neighbouring cells relevant for cell re-selection (including cell re-selection parameters common for a frequency as well as cell specific re-selection parameters) , which can also be used for NR idle / inactive measurements; - SIB5 contains information about evolved universal terrestrial radio access (E-UTRA) frequencies and E-UTRA neighbouring cells relevant for cell re-selection (including cell re-selection parameters common for a frequency as well as cell specific re-selection parameters) ; - SIB6 contains an earthquake and tsunami warning system (ETWS) primary notification; - SIB7 contains an ETWS secondary notification; - SIB8 contains a commercial mobile alert system (CMAS) warning notification; - SIB9 contains information related to global positioning system (GPS) time and coordinated universal time (UTC) ; - SIB10 contains the human-readable network names (HRNN) of the non-public networks (NPN) slisted in SIB1; - SIB11 contains information related to idle or inactive measurements; - SIB15 contains information related to disaster roaming; - SIB16 contains slice-based cell reselection information; - SIB17 and SIB17bis contain information related to tracking reference signal (TRS) configuration for UEs in RRC_IDLE or RRC_INACTIVE state; - SIBpos contains positioning assistance data as defined in 3GPP specifications TS 37.355

[0043] and TS 38.331

[0012] ; - SIB18 contains information related to group IDs for network selection (GINs) associated with standalone non-public networks (SNPNs) listed in SIB1. - SIB19 in a terrestrial network (TN) contains non terrestrial network (NTN) -specific parameters for NTN neighbour cells as defined in 3GPP specification TS 38.331

[0012] . -- For sidelink, "Other SI" also includes: - SIB12 contains information related to NR sidelink communication, ranging and sidelink positioning; - SIB13 contains information related to SystemInformationBlockType21 for vehicle to everything (V2X) sidelink communication as specified in 3GPP specification TS 36.331 clause 5.2.2.28

[0029] ; - SIB14 contains information related to SystemInformationBlockType26 for V2X sidelink communication as specified in 3GPP specification TS 36.331 clause 5.2.2.33

[0029] ; - SIB23 contains information related to ranging and sidelink positioning. -- For non-terrestrial network, "Other SI" also includes: - SIB19 contains NTN-specific parameters for serving cell and optionally NTN-specific parameters for neighbour cells as defined in 3GPP specification TS 38.331

[0012] . - SIB25 contains TN coverage information as defined in 3GPP specification TS 38.331

[0012] . -- For multicast broadcast service (MBS) broadcast, "Other SI" also includes: - SIB20 contains multicast control channel (MCCH) configuration; - SIB21 contains information related to service continuity for MBS broadcast reception. -- For MBS multicast reception in RRC_INACTIVE state, "Other SI" also includes: - SIB24 contains the information required to acquire the multicast MCCH / MTCH configuration as defined in 3GPP specification TS 38.331

[0012] . -- For an air to ground (ATG) network, "Other SI" also includes: - SIB22 contains ATG-specific parameters for serving cell and optionally ATG-specific parameters for neighbour cells as defined in 3GPP specification TS 38.331

[0012] .

[0060] In the legacy wireless communication system, the SI is without security protection, e.g. integrity protection or encryption. However, the broadcast SI which carries vital system parameters that govern the initial access and connectivity to the network is transmitted in plain text and could be easily tempered with by a fake (or false) RAN node (e.g. a false base station (BS) ) . The false BS is a device that impersonates as a cellular BS to intercept and manipulate communications towards one or more UEs. The false BS could trick the UEs in the vicinity into connecting to it by emitting a stronger signal as the cellular BS, or the false BS may completely block the connectivity for these UEs to the genuine BS. Specifically, various security threats include user tracking, data theft or fraud by intercepting unencrypted data or authentication codes, denial-of-service (DoS) attacks, downgrade attacks by forcing the UEs to connect to less secure network protocols and performance degradation (e.g. draining battery by repeated search for connection) .

[0061] The present application studies security aspects and proposes to enable security protection of SI and mitigate threats from false BSs. Currently, details related to a solution of asymmetric key based SI security protection have not been discussed. Since the legacy access stratum (AS) security protection mechanism is designed for two-party communication, i.e. per-UE based symmetric key derivation, it is not suitable for the SI security protection. For the SI, it is a n-party communication between multiple UEs and a BS, i.e. all UEs under a cell of the BS receive the SI broadcasted by the BS, wherein the number n is dynamic and large.

[0062] The present application discloses that a possible approach to provide SI security protection is using asymmetric key or public key based digital signatures, which allow messages to be broadcast from one party and verified by many parties without the need to share the signing key (private key) . Since one or more SI messages are periodically and frequently broadcasted, encryption imposes a significant burden and large delay on data encoding or decoding in both UE and network sides, but integrity protection ensures that the SI cannot be tampered with.

[0063] Figure 1A illustrates an example of SI security protection using an asymmetric algorithm in accordance with aspects of the present application. As shown in Figure 1A, a RAN node (e.g. a BS) uses a private key and SI of a cell of the RAN node as inputs to a security algorithm to generate a digital signature. The RAN node sends the SI and the digital signature to a UE. The UE uses a public key to verify the digital signature. Specifically, the UE uses the public key and the received digital signature as inputs to the security algorithm to generate verified SI, and then compares the verified SI with the received SI. If the verification is successful (i.e. the verified SI is identical with the received SI) , the received SI is authentic, and the UE considers the cell as authentic. If the verification is failed (i.e. the verified SI is different from the received SI) , the received SI is not authentic, and the UE considers the cell as barred.

[0064] Embodiments of the present application aim to support a mechanism for SI security protection via asymmetric encryption.

[0065] In particular, considering that the MIB size is 23 bits and the maximum size that a SIB can take is 2976 bits, while the digital signature size is 512 bits or more, some embodiments of the present application aim to solve an issue of how to provide a digital signature of SI. In particular, in some embodiments, the digital signature is carried within a SIB. In some other embodiments, the digital signature of one or more SIBs is carried within a new SIB (e.g. SIB-x) different from the legacy SIB or a separate SIB different from the SIB being protected.

[0066] For example, the SIB-x may include one or more digital signatures, where each digital signature is associated with a SIB or a set of SIBs. If each digital signature is associated with a set of SIBs, multiple SIBs within a SI message may be used together as an input to a security algorithm to generate a single digital signature.

[0067] In some embodiments, SIB1 defines scheduling information of the SIB-x. For a MIB, in some embodiments, the MIB is without security protection, i.e. no digital signature. In some other embodiments, the MIB and SIB1 may be used together as inputs to the security algorithm to generate a single digital signature.

[0068] Considering that the MIB size is 23 bits, the maximum size that a SIB can take is 2976 bits, and a public key is 1024 bits or more, while the public key should be updated to make the key cracking impossible in time, some embodiments of the present application aim to solve an issue of how to provide the public key used for SI verification. In particular, the public key may be carried within a new SIB (e.g. SIB-y) different from the legacy SIB or a separate SIB different from the SIB being protected.

[0069] In some embodiments, the SIB-y may include an algorithm identifier used to identify a security algorithm, the public key used for SI security protection, and valid time information during which the public key is valid (e.g. the time where the public key begins and the time where the public key ends) . For example, the public key may be provided per cell, per BS, or per protection area. If the public key is provided per BS or per protection area, the UE may obtain the public key only once within the same BS or the same protection area.

[0070] In some embodiments, the UE is pre-configured with the public key (e.g. a root key) to verify the SIB-y, where the SIB-y includes the digital signature using the private key corresponding to the root key. In some implementations, the UE may be pre-configured with a list of root keys. In this case, the SIB-y may include the root key or a key ID which identifies the root key.

[0071] In some embodiments, the BS obtains a pair of {public key, private key} from the core network (CN) , e.g. during a next generation (NG) interface setup procedure or an access and mobility management function (AMF) configuration update procedure. In some embodiments, the SIB1 defines the scheduling information of the SIB-y. The SIB-y may be the same with the SIB-x.

[0072] Some embodiments of the present application aim to solve an issue of what’s a UE's behavior on receipt of SI with security protection, e.g. integrity protection.

[0073] In some embodiments, upon receiving the MIB and the SIB1, the UE stores the MIB and the SIB1. - In an example, if the UE has a stored valid public key, the UE may use the public key to verify the digital signature. If the verification is successful, the UE considers the cell as authentic. If the verification is failed, the UE considers the cell of the BS as barred. In some cases, the UE may further consider the BS as barred, i.e. considering all the cells within the BS as barred. After considering the cell of the BS as barred, the UE may perform a cell re-selection to other cells within the BS, wherein the UE may exclude the barred cell as a candidate for cell selection or cell re-selection. - In another example, if the UE hasn’ t a stored a valid public key, it continues reception of SIB-y, and then uses the root key to verify the digital signature associated to the SIB-y. If the verification is successful, the UE stores the public key included in the SIB-y and uses the public key to verify the digital signature associated to the MIB or SIB1. If the verification is failed, the UE considers the cell as barred. In some cases, the UE may further consider the BS as barred, i.e. considering all the cells within the BS as barred. After considering the cell of the BS as barred, the UE may discard the current MIB or SIB1and performs cell re-selection to other cells within the BS, wherein the UE may exclude the barred cell as a candidate for cell selection or cell re-selection.

[0074] In some other embodiments, upon receiving the SIB other than the MIB and the SIB1, the UE uses the public key to verify the digital signature. If the verification is successful, the UE stores the received SIB. If the verification is failed, the UE considers the cell of the BS as barred. In some cases, the UE may further consider the BS as barred, i.e. considering all the cells within the BS as barred. After considering the cell of the BS as barred, the UE may discard the current MIB or SIB1 and performs cell re-selection to other cells within the BS, wherein the UE may exclude the barred cell as a candidate for cell selection or cell reselection.

[0075] In some additional embodiments, if the UE is in RRC_CONNECTED state and the verification of the SIB is failed, the UE may initiate the RRC connection re-establishment procedure or enter the RRC_IDLE state.

[0076] In yet some additional embodiments, after the successful connection to the network, the UE may report one or more cells that are considered as barred by the UE due to the failed verification of the SI, which can help in detecting the false BS. For each cell, the UE may further report the following to the network: - The SI without the successful security verification, e.g. the verification of the digital signature is failed. - The verification of the public key is failed, e.g. the verification of the digital signature of the SIB-y is failed.

[0077] Some embodiments of the present application aim to solve an issue of how to support coexistence of legacy SI without security protection and SI with security protection. In one solution, for the SI with security protection, the SI may include an indicator indicating that the SI is security protected. In one option, each SI includes such indicator. In another option, SIB1 includes a list of SIBs that is security protected, and / or a list of SIBs that is not security protected.

[0078] In a split RAN architecture (i.e. a CU-DU split RAN) , some SI are encoded by a DU of a RAN node, while other SI are encoded by a CU of the RAN node. Some embodiments of the present application aim to solve an issue of how to support the SI security protection. In one solution, to provide a unique SI security protection (e.g. same security algorithm and / or same public key for all SI within the cell of the RAN node) , the CU and the DU may negotiate the SI security protection related information.

[0079] In some embodiments, the CU sends the latest private key or the latest pair of {private key, public key} used for SI security protection to the DU. The CU may also send the security algorithm, and / or the root key used for SIB-y security protection to the DU.

[0080] In some other embodiments, the DU sends SI security capability to the CU. In an example, the CU determines whether SI security protection should be activated, determines a security algorithm used for the SI security protection, and sends the determination to the DU. In another example, the DU determines a security algorithm used for SI security protection, and sends the determination to the CU.

[0081] In the embodiments of the present application, since one or more SI messages are periodically and frequently broadcasted, encryption imposes a significant burden and large delay on data encoding or decoding in both UE and network sides, but integrity protection ensures that system information cannot be tampered with. Therefore, in some cases, the SI security protection can be interpreted as the SI integrity protection, and the SI security verification can be interpreted as the SI integrity verification.

[0082] In the embodiments of the present application, the SI refers to a MIB and / or a SIB without security protection, or a MIB and / or a SIB being security protected, e.g. the SI (aMIB and / or a number of SIBs) defined in TS 38.300. In some cases, the successful SI security verification can be interpreted as the SI authentic, the cell authentic, or the like. In some other cases, the failed SI security verification can be interpreted as the SI unauthentic, the cell unauthentic, the cell barred, or the like.

[0083] More details of the embodiments of the present application will be illustrated in the following text in combination with the appended drawings.

[0084] Figure 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present application. The wireless communications system 100 may include one or more NE 102, one or more UE 104, and a core network (CN) 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LTE-Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a NR network, such as a 5G network, a 5G-Advanced (5G-A) network, or a 5G ultrawideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi) , IEEE 802.16 (WiMAX) , IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA) , frequency division multiple access (FDMA) , or code division multiple access (CDMA) , etc.

[0085] The one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NE 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, a radio access network (RAN) , a NodeB, an eNodeB (eNB) , a next-generation NodeB (gNB) , a 6G NodeB, or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link, which may be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g. receive signaling, transmit signaling) over a Uu interface.

[0086] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For example, an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g. voice, video, packet data, messaging, broadcast, etc. ) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN) . In some implementations, different geographic coverage areas associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102.

[0087] In some implementations, each of the NE 102 may be implemented as a distributed unit (DU) . The DU may be a logical node hosting radio link control (RLC) layer functionality, medium access control (MAC) layer functionality, and the physical (PHY) layer functionality.

[0088] In some implementations, each of the NE 102 may be implemented as a central unit (CU) . The CU may be a logical node hosting RRC layer functionality, service data adaptation protocol (SDAP) functionality, and the packet data convergence protocol (PDCP) layer functionality that controls the operation of one or more DUs. The CU terminates the F1 interface connected with the DU.

[0089] The one or more UE 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Internet-of-Things (IoT) device, an Internet-of-Everything (IoE) device, or machine-type communication (MTC) device, among other examples.

[0090] A UE 104 may be able to support wireless communication directly with other UEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.

[0091] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g. S1, N2, or network interface) . In some implementations, the NE 102 may communicate with each other directly. In some other implementations, the NE 102 may communicate with each other or indirectly (e.g. via the CN 106. In some implementations, one or more NE 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC) . An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as a radio heads, smart radio heads, or transmission-reception points (TRPs) .

[0092] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC) , or a 5G core (5GC) , or a 6G core (6GC) , which may include a control plane entity that manages access and mobility (e.g. a mobility management entity (MME) , an access and mobility management functions (AMF) ) and a user plane entity that routes packets or interconnects to external networks (e.g. a serving gateway (S-GW) , a Packet Data Network (PDN) gateway (P-GW) , or a user plane function (UPF) ) . In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g. data bearers, signal bearers, etc. ) for the one or more UEs 104 served by the one or more NE 102 associated with the CN 106.

[0093] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g. via an S1, N2, or another network interface) . The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g. a protocol data unit (PDU) session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g. control information, data, and the like) between the UE 104 and the application server using the established session (e.g. the established PDU session) . The PDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g. one or more network functions of the CN 106) .

[0094] In the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g. time resources (e.g. symbols, slots, subframes, frames, or the like) or frequency resources (e.g. subcarriers, carriers) ) to perform various operations (e.g. wireless communications) . In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104 may support various frame structures (i.e. multiple frame structures) . The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.

[0095] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g. μ=0) may be associated with a first subcarrier spacing (e.g. 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g. μ=0) associated with the first subcarrier spacing (e.g. 15 kHz) may utilize one slot per subframe. A second numerology (e.g. μ=1) may be associated with a second subcarrier spacing (e.g. 30 kHz) and a normal cyclic prefix. A third numerology (e.g. μ=2) may be associated with a third subcarrier spacing (e.g. 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g. μ=3) may be associated with a fourth subcarrier spacing (e.g. 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g. μ=4) may be associated with a fifth subcarrier spacing (e.g. 240 kHz) and a normal cyclic prefix.

[0096] A time interval of a resource (e.g. a communication resource) may be organized according to frames (also referred to as radio frames) . Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.

[0097] Additionally or alternatively, a time interval of a resource (e.g. a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g. quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e. μ=0, μ=1, μ=2, μ=3, μ=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively. Each slot may include a number (e.g. quantity) of symbols (e.g. OFDM symbols) . In some implementations, the number (e.g. quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g. applicable for 60 kHz subcarrier spacing) , a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g. μ=0) associated with a first subcarrier spacing (e.g. 15 kHz) may be used interchangeably between subframes and slots.

[0098] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz –7.125 GHz) , FR2 (24.25 GHz –52.6 GHz) , FR3 (7.125 GHz –24.25 GHz) , FR4 (52.6 GHz –114.25 GHz) , FR4a or FR4-1 (52.6 GHz –71 GHz) , and FR5 (114.25 GHz –300 GHz) . In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g. control information, data) . In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.

[0099] FR1 may be associated with one or multiple numerologies (e.g. at least three numerologies) . For example, FR1 may be associated with a first numerology (e.g. μ=0) , which includes 15 kHz subcarrier spacing; a second numerology (e.g. μ=1) , which includes 30 kHz subcarrier spacing; and a third numerology (e.g. μ=2) , which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g. at least 2 numerologies) . For example, FR2 may be associated with a third numerology (e.g. μ=2) , which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g. μ=3) , which includes 120 kHz subcarrier spacing.

[0100] Figure 2 illustrates an example of a UE 200 in accordance with aspects of the present application. The UE 200 may include a processor 202, a memory 204, a controller 206, and a transceiver 208. The processor 202, the memory 204, the controller 206, or the transceiver 208, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present application as described herein. These components may be coupled (e.g. operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0101] The processor 202, the memory 204, the controller 206, or the transceiver 208, or various combinations or components thereof may be implemented in hardware (e.g. circuitry) . The hardware may include a processor, a digital signal processor (DSP) , an application-specific integrated circuit (ASIC) , or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present application.

[0102] The processor 202 may include an intelligent hardware device (e.g. a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof) . In some implementations, the processor 202 may be configured to operate the memory 204. In some other implementations, the memory 204 may be integrated into the processor 202. The processor 202 may be configured to execute computer-readable instructions stored in the memory 204 to cause the UE 200 to perform various functions of the present application.

[0103] The memory 204 may include volatile or non-volatile memory. The memory 204 may store computer-readable, computer-executable code including instructions when executed by the processor 202 cause the UE 200 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 204 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0104] In some implementations, the processor 202 and the memory 204 coupled with the processor 202 may be configured to cause the UE 200 to perform one or more of the functions described herein (e.g. executing, by the processor 202, instructions stored in the memory 204) . For example, the processor 202 may support wireless communication at the UE 200 in accordance with examples as disclosed with respect to Figure 6. The UE 200 may be configured to support: a means for receiving, from a RAN node, SI of a cell of the RAN node and a set of digital signatures, wherein the SI is carried in at least one of a MIB or a set of SIBs, and wherein the set of digital signatures is generated by using a private key from a pair of {the private key, a public key} and the SI as inputs to a security algorithm; a means for generating another SI by using the set of digital signatures and the public key as the inputs to the security algorithm; and a means for determining that the cell is authentic if the another SI is identical with the SI, or a means for considering that the cell is barred if the another SI is different from the SI.

[0105] The controller 206 may manage input and output signals for the UE 200. The controller 206 may also manage peripherals not integrated into the UE 200. In some implementations, the controller 206 may utilize an operating system such as   or other operating systems. In some implementations, the controller 206 may be implemented as part of the processor 202.

[0106] In some implementations, the UE 200 may include at least one transceiver 208. In some other implementations, the UE 200 may have more than one transceiver 208. The transceiver 208 may represent a wireless transceiver. The transceiver 208 may include one or more receiver chains 210, one or more transmitter chains 212, or a combination thereof. The means for receiving abovementioned in the processor 202 or the means for transmitting in the processor 202 may be implemented via at least one transceiver 208.

[0107] A receiver chain 210 may be configured to receive signals (e.g. control information, data, packets) over a wireless medium. For example, the receiver chain 210 may include one or more antennas for receive the signal over the air or wireless medium. The receiver chain 210 may include at least one amplifier (e.g. a low-noise amplifier (LNA) ) configured to amplify the received signal. The receiver chain 210 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 210 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.

[0108] A transmitter chain 212 may be configured to generate and transmit signals (e.g. control information, data, packets) . The transmitter chain 212 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM) , frequency modulation (FM) , or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM) . The transmitter chain 212 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 212 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0109] Figure 3 illustrates an example of a processor 300 in accordance with aspects of the present application. The processor 300 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 300 may include a controller 302 configured to perform various operations in accordance with examples as described herein. The processor 300 may optionally include at least one memory 304, which may be, for example, an L1 / L2 / L3 cache. Additionally, or alternatively, the processor 300 may optionally include one or more arithmetic-logic units (ALUs) 306. One or more of these components may be in electronic communication or otherwise coupled (e.g. operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g. buses) .

[0110] The processor 300 may be a processor chipset and include a protocol stack (e.g. a software stack) executed by the processor chipset to perform various operations (e.g. receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g. memory local to or included in the processor chipset (e.g. the processor 300) or other memory (e.g. random access memory (RAM) , read-only memory (ROM) , dynamic RAM (DRAM) , synchronous dynamic RAM (SDRAM) , static RAM (SRAM) , ferroelectric RAM (FeRAM) , magnetic RAM (MRAM) , resistive RAM (RRAM) , flash memory, phase change memory (PCM) , and others) .

[0111] The controller 302 may be configured to manage and coordinate various operations (e.g. signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 300 to cause the processor 300 to support various operations in accordance with examples as described herein. For example, the controller 302 may operate as a control unit of the processor 300, generating control signals that manage the operation of various components of the processor 300. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.

[0112] The controller 302 may be configured to fetch (e.g. obtain, retrieve, receive) instructions from the memory 304 and determine subsequent instruction (s) to be executed to cause the processor 300 to support various operations in accordance with examples as described herein. The controller 302 may be configured to track memory address of instructions associated with the memory 304. The controller 302 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 302 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 300 to cause the processor 300 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 302 may be configured to manage flow of data within the processor 300. The controller 302 may be configured to control transfer of data between registers, arithmetic logic units (ALUs) , and other functional units of the processor 300.

[0113] The memory 304 may include one or more caches (e.g. memory local to or included in the processor 300 or other memory, such RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementations, the memory 304 may reside within or on a processor chipset (e.g. local to the processor 300) . In some other implementations, the memory 304 may reside external to the processor chipset (e.g. remote to the processor 300) .

[0114] The memory 304 may store computer-readable, computer-executable code including instructions that, when executed by the processor 300, cause the processor 300 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 302 and / or the processor 300 may be configured to execute computer-readable instructions stored in the memory 304 to cause the processor 300 to perform various functions. For example, the processor 300 and / or the controller 302 may be coupled with or to the memory 304, the processor 300, the controller 302, and the memory 304 may be configured to perform various functions described herein. In some examples, the processor 300 may include multiple processors and the memory 304 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.

[0115] The one or more ALUs 306 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 306 may reside within or on a processor chipset (e.g. the processor 300) . In some other implementations, the one or more ALUs 306 may reside external to the processor chipset (e.g. the processor 300) . One or more ALUs 306 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 306 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 306 be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 306 may support logical operations such as AND, OR, exclusive-OR (XOR) , not-OR (NOR) , and not-AND (NAND) , enabling the one or more ALUs 306 to handle conditional operations, comparisons, and bitwise operations.

[0116] The processor 300 may support wireless communication in accordance with examples as disclosed herein. In some implementations, the processor 300 may be configured to support means for performing operations of a UE as described with respect to Figure 5. The processor 300 may be configured to support: a means for receiving, from a RAN node, SI of a cell of the RAN node and a set of digital signatures, wherein the SI is carried in at least one of a MIB or a set of SIBs, and wherein the set of digital signatures is generated by using a private key from a pair of {the private key, a public key} and the SI as inputs to a security algorithm; a means for generating another SI by using the set of digital signatures and the public key as the inputs to the security algorithm; and a means for determining that the cell is authentic if the another SI is identical with the SI, or a means for considering that the cell is barred if the another SI is different from the SI.

[0117] In some implementations, the processor 300 may be configured to support means for performing operations of a RAN node as described with respect to Figure 6. The processor 300 may be configured to or operable to support: a means for generating a set of digital signatures by using a private key from a pair of {the private key, a public key} and SI of a cell of the RAN node as inputs to a security algorithm; and a means for transmitting the SI and the set of digital signatures to a UE, wherein the SI is carried in at least one of a MIB or a set of SIBs.

[0118] It should be appreciated by persons skilled in the art that the components in exemplary processor 300 may be changed, for example, some of the components in exemplary processor 300 may be omitted or modified or new component (s) may be added to exemplary processor 300, without departing from the spirit and scope of the disclosure. For example, in some embodiments, the processor 300 may not include the ALUs 306.

[0119] Figure 4 illustrates an example of a NE 400 in accordance with aspects of the present application. The NE 400 may include a processor 402, a memory 404, a controller 406, and a transceiver 408. The processor 402, the memory 404, the controller 406, or the transceiver 408, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present application as described herein. These components may be coupled (e.g. operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0120] The processor 402, the memory 404, the controller 406, or the transceiver 408, or various combinations or components thereof may be implemented in hardware (e.g. circuitry) . The hardware may include a processor, a digital signal processor (DSP) , an application-specific integrated circuit (ASIC) , or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present application.

[0121] The processor 402 may include an intelligent hardware device (e.g. a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof) . In some implementations, the processor 402 may be configured to operate the memory 404. In some other implementations, the memory 404 may be integrated into the processor 402. The processor 402 may be configured to execute computer-readable instructions stored in the memory 404 to cause the NE 400 to perform various functions of the present application.

[0122] The memory 404 may include volatile or non-volatile memory. The memory 404 may store computer-readable, computer-executable code including instructions when executed by the processor 402 cause the NE 400 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 404 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0123] In some implementations, the processor 402 and the memory 404 coupled with the processor 402 may be configured to cause the NE 400 to perform one or more of the functions described herein (e.g. executing, by the processor 402, instructions stored in the memory 404) .

[0124] In some implementations, the NE 400 may be a RAN node as described with respect to Figure 6, which is configured to support: a means for generating a set of digital signatures by using a private key from a pair of {the private key, a public key} and SI of a cell of the RAN node as inputs to a security algorithm; and a means for transmitting the SI and the set of digital signatures to a UE, wherein the SI is carried in at least one of a MIB or a set of SIBs.

[0125] The controller 406 may manage input and output signals for the NE 400. The controller 406 may also manage peripherals not integrated into the NE 400. In some implementations, the controller 406 may utilize an operating system such as or other operating systems. In some implementations, the controller 406 may be implemented as part of the processor 402.

[0126] In some implementations, the NE 400 may include at least one transceiver 408. In some other implementations, the NE 400 may have more than one transceiver 408. The transceiver 408 may represent a wireless transceiver. The transceiver 408 may include one or more receiver chains 410, one or more transmitter chains 412, or a combination thereof. The means for receiving or the means for transmitting abovementioned in the processor 402 may be implemented via at least one transceiver 408.

[0127] A receiver chain 410 may be configured to receive signals (e.g. control information, data, packets) over a wireless medium. For example, the receiver chain 410 may include one or more antennas for receive the signal over the air or wireless medium. The receiver chain 410 may include at least one amplifier (e.g. a low-noise amplifier (LNA) ) configured to amplify the received signal. The receiver chain 410 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 410 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.

[0128] A transmitter chain 412 may be configured to generate and transmit signals (e.g. control information, data, packets) . The transmitter chain 412 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM) , frequency modulation (FM) , or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM) . The transmitter chain 412 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 412 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0129] It should be appreciated by persons skilled in the art that the components in exemplary NE 400 may be changed, for example, some of the components in exemplary NE 400 may be omitted or modified or new component (s) may be added to exemplary NE 400, without departing from the spirit and scope of the disclosure. For example, in some embodiments, the NE 400 may not include the controller 406.

[0130] Figure 5 illustrates a flowchart of a method performed by a UE in accordance with aspects of the present application. In some implementations, the UE may execute a set of instructions to control the function elements of the UE to perform the described functions. In some implementations, aspects of operations 502, 504 and 506 may be performed by UE 200 as described with reference to Figure 2. Specific examples are described in the embodiments of Figures 7-10 as follows.

[0131] At 502, the method may include receiving, by a UE from a RAN node, SI (denoted as first SI) of a cell (denoted as first cell) of the RAN node and a set of digital signatures (denoted as a set of first digital signatures) (e.g. step 702, step 707, step 802 or step 806 in Figure 7 or Figure 8) . The first SI may be carried in a MIB and / or a set of SIBs (denoted as a set of first SIBs) . The set of first digital signatures is generated by using a private key (denoted as a first private key, e.g. SK-1) from a pair of {the first private key, a public key} (e.g. {SK-1, PK-1} ) and the first SI as inputs to a security algorithm (denoted as a first security algorithm) . The public key is denoted as a first public key (e.g. PK-1) .

[0132] In some implementations, the set of first digital signatures includes: (1) a digital signature associated with one SIB within the set of first SIBs; and / or (2) a digital signature associated with two or more SIBs within the set of first SIBs.

[0133] At 504, the method may include generating, by the UE, another SI (denoted as second SI) by using the set of first digital signatures and the first public key as the inputs to the first security algorithm.

[0134] At 506, the method may include determining, by the UE, that the first cell is authentic if the second SI is identical with the first SI, or considering, by the UE, that the first cell is barred if the second SI is different from the first SI.

[0135] In some implementations (e.g. step 702 in Figure 7) , the set of first SIBs includes the set of first digital signatures.

[0136] In some implementations (e.g. step 702 or step 802 in Figure 7 or Figure 8) , the first SI is carried in SIB1. The SIB1 may include: (1) scheduling information (e.g., periodicity, SI-window size) regarding SI (denoted as third SI, e.g. SIB-y) ; and / or (2) a configuration used by the UE to request the third SI. The third SI may include the first public key (e.g. PK-1) .

[0137] In some implementations (e.g. step 704 or step 804 in Figure 7 or Figure 8) , the UE may receive the third SI from the RAN node. In an implementation (e.g. step 703 or step 803 in Figure 7 or Figure 8) , before receiving the third SI, the UE may transmit a request for the third SI (e.g. a request for SIB-y) to the RAN node based on the configuration that is included in the SIB1.

[0138] In some implementations, the third SI further includes at least one of the following: (1) the first security algorithm; (2) valid time duration of the first public key, e.g. validity of the first public key; or (3) a valid area (denoted as a first valid area) of the first public key. The first valid area may cover all cells of the RAN node, one or more cells of the RAN node, or a protecting area related to the RAN node. The protecting area may be a tracking area, a paging area, a RAN-based notification area, or others.

[0139] In some implementations, the third SI (e.g. SIB-y) is carried in a SIB (denoted as a second SIB) different from the SIB1 and the MIB. The second SIB includes a digital signature (denoted as a second digital signature) which is generated by using the third SI and another private key (denoted as a second private key, e.g. SK-2) from a pair of {the second private key, another public key} as inputs to another security algorithm (denoted as a second security algorithm) . Another public key is denoted as a second public key. The second private key is from a pair of {the second private key, the second public key} . The second security algorithm may be identical with or different from the first security algorithm.

[0140] In some implementations (e.g. step 705 in Figure 7) , the UE may generate SI (denoted as fourth SI, e.g. decrypted SIB-y) by using the second digital signature and the second public key (e.g. PK-2) as the inputs to the second security algorithm. For example, the second public key is pre-configured in the UE, or is received by the UE from the RAN node. If the fourth SI is identical with the third SI, the UE may determine that the first cell is authentic. If the fourth SI is different from the third SI, the UE may consider that the first cell is barred.

[0141] In some implementations (e.g. step 702 in Figure 7) , the SIB1 further includes the set of first digital signatures (e.g. DS-1) . In one case, the first SI may be the SIB1 except the set of first digital signatures. In another case, the first SI may be the MIB, and the SIB1 except the set of first digital signatures.

[0142] In some implementations (e.g. step 706 in Figure 7) , after determining that the first cell is authentic, the UE may store system information included in the SIB1, or store the MIB and the system information included in the SIB1.

[0143] In some implementations, after considering that the first cell is barred, the UE may discard the MIB and system information included in the SIB1, and perform a cell re-selection towards one or more cells of the RAN node other than the first cell. In some other implementations, after considering that the first cell is barred, the UE may consider that the RAN node to which the first cell belongs is barred.

[0144] In some embodiments (e.g. step 705 or step 805 in Figure 7 or Figure 8) , after considering that the first cell is barred, the UE may exclude the first cell (i.e. the barred cell) as a candidate for a cell selection or a cell re-selection of the UE. In some other embodiments, after considering that the RAN node is barred, the UE may exclude all cells of the RAN node as candidates for the cell selection or the cell re-selection of the UE.

[0145] In some implementations (e.g. step 706 or step 806 in Figure 7 or Figure 8) , the UE may initiate an RRC connection reestablishment procedure or enter an RRC idle state (i.e. RRC_IDLE) , if the UE is in an RRC connected state (i.e. RRC_CONNECTED) .

[0146] In some implementations (e.g. step 807 in Figure 8) , the UE may receive, from the RAN node, SI (denoted as fifth SI, e.g. SIB-x) different from the first SI (e.g. SIB1 received in step 802 in Figure 8) and the third SI (e.g. SIB-y) , which includes the set of first digital signatures (e.g. DS-1) .

[0147] In some implementations (e.g. step 802 in Figure 8) , the SIB1 further includes at least one of the following: (1) scheduling information regarding the fifth SI (e.g. SIB-x) ; (2) information (e.g. a first indicator) indicating that the SIB1 is security protected; (3) information (e.g. a second indicator) indicating that the MIB is security protected; (4) a set of third SIBs that is security protected; or (5) a set of fourth SIBs that is not security protected.

[0148] In some other implementations (e.g. step 802 in Figure 8) , the SIB1 further includes a set of indicators (e.g. a set of third indicators) associated with the set of third SIBs, wherein each indicator indicates that one SIB within the set of third SIBs is security protected.

[0149] In some implementations (e.g. step 708 or step 809 in Figure 7 or Figure 8) , after considering that one or more cells of the RAN node are barred, the UE may transmit identifier information of the one or more cells to the RAN node. In an embodiment, the UE may transmit one of the following to the RAN node: (1) a set of SI without successful security verification of each cell within the one or more cells; or (2) information indicating that verification of the third SI is failed.

[0150] In some implementations (e.g. step 806 in Figure 8) , the UE may receive, from the RAN node, a system information message (e.g. SystemInformation message) including the set of first SIBs carrying the first SI. In an example, the system information message includes one or more indicators (e.g. a set of fourth indicators) , wherein each indicator indicates that one SIB within the set of first SIBs is security protected. In another example, the system information message includes one indicator (e.g. a fifth indicator) indicating that the set of first SIBs is security protected.

[0151] It should be noted that the method described in Figure 5 describes possible implementations, and that the operations and the steps may be rearranged or otherwise eliminated or modified and that other implementations are possible, without departing from the spirit and scope of the disclosure.

[0152] Figure 6 illustrates a flowchart of a method performed by a RAN node in accordance with aspects of the present application. The RAN node (e.g. a BS) may execute a set of instructions to control the function elements of the RAN node to perform the described functions. In some implementations, aspects of operations 602 and 604 may be performed by NE 400 as described with reference to Figure 4. Specific examples are described in the embodiments of Figures 7-10 as follows.

[0153] At 602, the method may include generating, by a RAN node, a set of digital signatures (e.g. a set of first digital signatures as described in Figure 5) by using a private key from a pair of {the private key, a public key} and SI (e.g. first SI as described in Figure 5) of a cell of the RAN node as inputs to a security algorithm (e.g. by using a first private key from a pair of {the first private key, a first public key} (e.g. {SK-1, PK-1} ) and first SI of a first cell of the RAN node as inputs to a first security algorithm as described in Figure 5) .

[0154] The set of digital signatures transmitted at 604 may include the same or similar elements or partial elements as those in the set of digital signatures received at 502 as described in the embodiment of Figure 5.

[0155] At 604, the method may include transmitting the first SI and the set of first digital signatures by the RAN node to a UE (e.g. step 702, step 707, step 802 or step 806 in Figure 7 or Figure 8) . The first SI may be carried in a MIB and / or a set of SIBs (e.g. a set of first SIBs as described in Figure 5) . For example, the set of first SIBs includes the set of first digital signatures (e.g. step 702 in Figure 7) .

[0156] In an embodiment, the first SI may be carried in SIB1. The SIB1 may include the same or similar elements or partial elements as those in the SIB1 as described in the embodiment of Figure 5. For example, the SIB1 includes at least one of the following: (1) scheduling information (e.g. periodicity, SI-window size) regarding SI (e.g. third SI as described in Figure 5, e.g. SIB-y) including the first public key (e.g. PK-1) . The SI may include the same or similar elements or partial elements as those in the third SI as described in the embodiment of Figure 5. (2) a configuration used by the UE to request the third SI.

[0157] In some implementations (e.g. step 704 or step 804 in Figure 7 or Figure 8) , the RAN node may transmit the third SI to the UE. Before transmitting the third SI, the RAN node may receive a request for the third SI (e.g. a request for SIB-y) from the UE (e.g. step 703 or step 803 in Figure 7 or Figure 8) .

[0158] In some implementations, the RAN node may generate a digital signature (e.g. a second digital signature as described in Figure 5, e.g. DS-2) , e.g. by using the third SI and a second private key from a pair of {the second private key, a second public key} as inputs to a second security algorithm as described in the embodiment of Figure 5. The second security algorithm may be identical with or different from the first security algorithm.

[0159] In some implementations (e.g. step 704 or step 804 in Figure 7 or Figure 8) , the RAN node may transmit, to the UE, a SIB (e.g. a second SIB as described in Figure 5) which includes the third SI and the second digital signature.

[0160] In some implementations (e.g. step 807 in Figure 8) , the RAN node may transmit, to the UE, SI (e.g. fifth SI as described in Figure 5, e.g. SIB-x) which is different from the first SI (e.g. SIB1 received in step 802 in Figure 8) and the third SI (e.g. SIB-y) and includes the set of first digital signatures (e.g. DS-1) .

[0161] In some implementations (e.g. step 708 or step 809 in Figure 7 or Figure 8) , the RAN node may receive identifier information of one or more cells of the RAN node from the UE if the one or more cells are considered as barred.

[0162] In some implementations (e.g. step 708 or step 809 in Figure 7 or Figure 8) , the RAN node may receive one of the following from the UE: (1) a set of SI without successful security verification of each cell within the one or more cells; or (2) information indicating that verification of the third SI is failed.

[0163] In some implementations (e.g. step 806 in Figure 8) , the RAN node may transmit, to the UE, a system information message (e.g. SystemInformation message) including the set of first SIBs carrying the first SI. The system information message may include the same or similar elements or partial elements as those in the system information message as described in the embodiment of Figure 5.

[0164] In some implementations, the RAN node may receive security information used for SI security protection from a CN node.

[0165] In some implementations that the RAN node includes a DU and a CU, the CU may transmit the security information used for SI security protection to the DU (e.g. step 902 in Figure 9) . In an implementation (e.g. step 901 in Figure 9) , the DU may transmit, to the CU, security capability supported by the DU which includes: (1) information indicating whether the DU supports the SI security protection; and / or (2) one or more security algorithms (e.g. secure hash algorithm (SHA) -256, elliptic curve-based certificateless signatures for identity-based encryption (ECCSI) , or elliptic curve digital signature algorithm (ECDSA) ) supported by the DU for the SI security protection.

[0166] In some other implementations that the RAN node includes a DU and a CU, the DU may transmit the security information used for SI security protection to the CU (e.g. step 1001 in Figure 10) .

[0167] The security information used for SI security protection may include at least one of the following: (1) the first security algorithm; (2) the second security algorithm; (3) one or more first private keys (e.g. one or more SK-1) , or one or more pairs of {the first private key, the first public key} (e.g. one or more {SK-1, PK-1} pairs) ; (4) valid time duration of "each first private key within the one or more first private keys" or "each pair within the one or more pairs of {the first private key, the first public key} " ; (5) identifier information of "each first private key within the one or more first private keys " or "each pair within the one or more pairs of {the first private key, the first public key} " (e.g. a first identifier of each SK-1 or each {SK-1, PK-1} pair) ; (6) a valid area (denoted as a first valid area) of "each first private key within the one or more first private keys" or "each pair within the one or more pairs of {the first private key, the first public key} " ; (7) one or more second private keys (e.g. one or more SK-2) , or one or more pairs of {asecond private key, a second public key} (e.g. one or more {SK-2, PK-2} pairs) ; (8) valid time duration of "each second private key within the one or more second private keys" or "each pair within the one or more pairs of {the second private key, the second public key} " ; (9) identifier information of "each second private key within the one or more second private keys" or "each pair within the one or more pairs of {the second private key, the second public key} " (e.g. a second identifier of each SK-2 or each {SK-2, PK-2} pair) ; or (10) a valid area (denoted as a second valid area) of "each second private key within the one or more second private keys" or "each pair within the one or more pairs of {the second private key, the second public key} " . The first valid area and / or the second valid area may cover all cells of the RAN node, one or more cells of the RAN node, or a protecting area related to the RAN node.

[0168] It should be noted that the method described in Figure 6 describes possible implementations, and that the operations and the steps may be rearranged or otherwise eliminated or modified and that other implementations are possible, without departing from the spirit and scope of the disclosure.

[0169] Figure 7 illustrates an exemplary signalling flow of performing SI security protection in accordance with aspects of the present application. Details described in all other embodiments of the present application are applicable for the embodiments of Figure 7.

[0170] In the embodiments of Figure 7, a digital signature of SI is carried within a SIB. Following steps 701 to 708 may be performed, wherein steps 703, 704, 705 and 708 are optional and thus are marked as dotted lines.

[0171] In step 701, a UE receives a MIB, which is periodically broadcast by a RAN node (e.g. a BS) . The MIB contains essential physical layer information of a cell of the RAN node required to receive SIB1.

[0172] In step 702, the UE receives SIB1, which contains information required for initial access, from the RAN node. For example, the SIB1 includes a digital signature (e.g. DS-1) . DS-1 is generated by the RAN node using a private key (e.g. SK-1) as input to a first security algorithm. The first security algorithm is an asymmetric algorithm, such as SHA-256, ECCSI or ECDSA. - In some cases, besides SK-1, the RAN node also uses "the SIB1 except DS-1" as an input to the first security algorithm, to generate DS-1. - In some other cases, besides SK-1, the RAN node also uses the MIB and "the SIB1except DS-1" together as inputs to the first security algorithm, to generate DS-1.

[0173] For example, the SIB1 received at 702 includes information regarding scheduling (e.g. periodicity, SI-window size) of SIB-y. The SIB1 may further include a configuration needed by the UE to request the SIB-y or system information carried in the SIB-y. The SIB-y is different from the SIB1 and the MIB.

[0174] In an embodiment, the RAN node may receive a {SK-1, PK-1} pair from a CN node. The RAN node may further receive the information related to the {SK-1, PK-1} pair from the CN node, such as the first security algorithm, validity and the area (e.g. per cell, per RAN node, or per protection area) where the {SK-1, PK-1} pair applies to. The valid time duration (which may also be named as validity) and the valid area of the {SK-1, PK-1} pair are described in step 704.

[0175] In step 703, if the UE doesn’ t have a valid PK-1, the UE sends a request for SIB-y to the RAN node. The RAN node may respond with the SIB-y. This step 703 is optional in some implementations.

[0176] In step 704, the UE continues the reception of the SIB-y. The SIB-y includes the public key (e.g. PK-1) used for the SI (other than the SIB-y) security verification, wherein PK-1 corresponds to SK-1. - In some cases, PK-1 is provided per cell. That is, PK-1 is only valid within the cell. - In some cases, PK-1 is provided per RAN node. That is, PK-1 is valid across all cells within the same RAN node. - In some cases, PK-1 is provided per protection area. That is, PK-1 is valid across cells within the same protection area. The protection area can be a tracking area, a paging area, a RAN-based notification area, or others.

[0177] In some implementations, the SIB-y may further include at least one of the following: - The validity indicating the time information during which PK-1 is valid, e.g. the time where PK-1 begins and the time where PK-1 ends. - The first security algorithm where PK-1 belongs to. For example, the first security algorithm is identified by an algorithm identifier, and the SIB-y includes the identifier of the first security algorithm.

[0178] In some implementations, the SIB-y may include a digital signature (e.g. DS-2) , wherein DS-2 is generated by the RAN node using "the SIB-y except DS-2" and "aprivate key (e.g. SK-2) " as inputs to a second security algorithm. The second security algorithm may be the same as or different from the first security algorithm. In some cases, the RAN node receives SK-2 or a {SK-2, PK-2} pair from the CN node.

[0179] In step 705, the UE verifies the SIB-y. The UE uses "apublic key (e.g. PK-2) corresponding to SK-2" and "the received DS-2" as inputs to the second security algorithm, to generate a decrypted SIB-y (i.e., SIB-y without a digital signature) . - If the decrypted SIB-y is the same as the received SIB-y without DS-2 (i.e. the received SIB-y except DS-2) , the verification is successful, and the UE considers the SIB-y as authentic, e.g. the cell is authentic. - In some embodiments, the UE stores the security information included in the SIB-y, e.g. PK-1, the security algorithm, and the validity. - If the decrypted SIB-y is different from the received SIB-y without the DS-2, the verification is failed, and the UE considers the SIB-y as unauthentic. In this case, the UE considers the cell as barred. - In some embodiments, the UE discards the MIB and SIB1 received in step 701 and step 702, and then performs cell re-selection to other cells, where the UE may exclude the barred cell as a candidate for cell selection or cell re-selection. - In some other embodiments, the UE may consider the RAN node where the cell belongs to as barred, e.g. considering all the cells within the RAN node as barred. In this case, the UE may exclude all the cells within the RAN node as candidates for cell selection or cell re-selection.

[0180] In some cases, the UE is pre-configured with one or more PK-2, e.g. in a universal subscriber identity module (USIM) or mobile equipment (ME) . If the UE is pre-configured with multiple PK-2, the UE may receive "an identifier indicating PK-2 that is used for the SIB-y verification" from the RAN node in step 704.

[0181] In step 706, the UE verifies the SIB1. The UE may use PK-1 and the received DS-1 as inputs to the first security algorithm, to generate a decrypted SIB1. In some cases, if the MIB and "the SIB1 except DS-1" are used together to generate the DS-1 in step 702, the UE uses PK-1 and the received DS-1 as inputs to the first security algorithm to generate the decrypted {MIB, SIB1} . - If the decrypted SIB is the same as "the received SIB1 without DS-1" (i.e. the received SIB1 except DS-1) , or the decrypted {MIB, SIB1} is the same as "the received {MIB, SIB1} without DS-1 (i.e. the received {MIB, SIB1} except DS-1) " , the verification is successful, and the UE considers the SIB1 or the {MIB, SIB1} as authentic, e.g. the cell is authentic. In an embodiment, the UE stores the SIB1 or the {MIB, SIB1} . - If the decrypted SIB is different from the received SIB1 without DS-1, or the decrypted {MIB, SIB1} is different from the received {MIB, SIB1} without DS-1, the verification is failed, and the UE considers the SIB1 or the {MIB, SIB1} as unauthentic. In this case, the UE considers the cell as barred. - The UE discards the SIB1 or the {MIB, SIB1} received in step 701 and step 702, and then performs cell re-selection to other cells, where the UE may exclude the barred cell as a candidate for cell selection or cell re-selection. - The UE may consider the RAN node where the cell belongs to as barred, e.g. considering all cells within the RAN node as barred. In this case, the UE may exclude all the cells within the RAN node as candidates for cell selection or cell re-selection. - If the UE is in RRC_CONNECTED state, the UE may initiate the RRC connection re-establishment procedure or enter the RRC_IDLE state.

[0182] In some cases, if the UE has a valid PK-1, e.g. during previous RRC connection, step 704 and step 705 are not needed.

[0183] In step 707, the UE receives other SI including the digital signature based on SK-1, and verifies the other SI based on PK-1. - If the verification is successful, the UE may store the SIB1. - If the verification is failed, the UE may consider the cell as barred. - In some cases, the UE may discard the MIB and SIB1 received in step 701 and step 702, and then performs cell re-selection to other cells, where the UE may exclude the barred cell as a candidate for cell selection or cell re-selection. - In some cases, the UE may consider the RAN node where the cell belongs to as barred, e.g. considering all cells within the RAN node as barred. In this case, the UE may exclude all the cells within the RAN node as candidates for cell selection or cell re-selection.

[0184] In step 708, after the successful connection to the RAN node, the UE may report one or more cells that are considered as barred by the UE due to the failed verification of the SI, which can help in detecting the false RAN node. For example, the UE may further report: - One or more SI without the successful security verification for each barred cell, e.g. the verification of the digital signature is failed. - Information indicating that the verification of the public key is failed, e.g. the verification of the digital signature of the SIB-y is failed.

[0185] Figure 8 illustrates another exemplary signalling flow of performing SI security protection in accordance with aspects of the present application. Details described in all other embodiments of the present application are applicable for the embodiments of Figure 8.

[0186] In the embodiments of Figure 8, a digital signature of SI is carried within new SIB-x. Following steps 801 to 809 may be performed, wherein steps 803, 806 and 809 are optional and thus are marked as dotted lines.

[0187] In step 801, a UE receives a MIB, which is periodically broadcast by a RAN node (e.g. a BS) . The MIB contains essential physical layer information of the cell required to receive SIB1.

[0188] In step 802, the UE receives the SIB1, which contains information required for initial access. For example: - The SIB1 may include information regarding scheduling (e.g. periodicity, SI-window size) of SIB-y. The SIB1 may further include a configuration needed by the UE to perform the SIB-y request. - The SIB1 may include information regarding scheduling (e.g. periodicity, SI-window size) of SIB-x. - The SIB1 may include a first indicator indicating that the SIB1 is security protected. -The SIB1 may include a second indicator indicating that the MIB is security protected. - The SIB1 may include a list of SIBs, where each SIB is associated with a third indicator indicating that the SIB is security protected. - The SIB1 may include a list of SIBs that is security protected. - The SIB1 may include a list of SIBs that is not security protected.

[0189] Step 803 is the same as step 703 in the embodiments of Figure 7. Step 803 is optional in some implementations.

[0190] Step 804 is the same as step 704 in the embodiments of Figure 7.

[0191] Step 805 is the same as step 705 in the embodiments of Figure 7.

[0192] In step 806, the UE receives a SystemInformation message from the BS, where this message is used to convey one or more SIBs that are transmitted with the same periodicity. - In some cases, each SIB included in the message is associated with a fourth indicator, which indicates that this SIB is security protected. - In some cases, the message includes a fifth indicator, which indicates that all SIBs included in the message are security protected.

[0193] Step 806 is optional in some implementations.

[0194] In step 807, the UE continues the reception of the SIB-x. - The SIB-x may include one or more digital signatures (e.g. DS-1) , where each DS-1 is associated with an SI or a set of SI. If DS-1 is associated with a set of SI, it indicates the corresponding SI within the set of SI are used together as inputs to the first security algorithm, to generate DS-1. For example, if DS-1 is associated with the MIB and the SIB1, it indicates that the MIB and the SIB1 are used together as inputs to the first security algorithm, to generate DS-1. - The SIB-x is different from the legacy SI, e.g. it is a new SI different from the MIB, SIB1 or other SIBs (e.g. SIB2 to SIB25 defined in 3GPP specification TS 38.300 v19.0.0) being security protected.

[0195] In step 808, the UE verifies the SI. The UE uses PK-1 and the received DS-1 as inputs to the first security algorithm, to generate a decrypted SI or a decrypted set of SI. - If the decrypted SI is the same as the SI received in step 807, or the decrypted set of SI is the same as the set of SI received in step 807, the verification is successful, and the UE considers the SI or the set of SI as authentic, e.g. the cell is authentic. In some cases, the UE may store the SI or the set of SI. - If the decrypted SI is different from the SI received in step 807, or the decrypted set of SI is different from the set of SI received in step 807, the verification is failed, and the UE considers the SI or the set of SI as unauthentic. In this case, the UE considers the cell as barred. - In some embodiments, the UE discards the received SI or the set of SI, and then performs cell re-selection to other cells, where the UE may exclude the barred cell as a candidate for cell selection or cell re-selection. - In some other embodiments, the UE may consider the RAN node where the cell belongs to as barred, e.g. consider all cells within the RAN node as barred. In this case, the UE may exclude all the cells within the RAN node as candidates for cell selection or cell re-selection. - In some additional embodiments, if the UE is in RRC_CONNECTED state, the UE may initiate the RRC connection re-establishment procedure or enter the RRC_IDLE state.

[0196] Step 809 is the same as step 708 in the embodiments of Figure 7.

[0197] Figure 9 illustrates an exemplary signalling flow of performing SI security protection in a split RAN architecture in accordance with aspects of the present application. Details described in all other embodiments of the present application are applicable for the embodiments of Figure 9.

[0198] As shown in Figure 9, a RAN node (e.g. a BS) is in CU-DU architecture, and includes a CU and one or more DUs. In the embodiments of Figure 9, the CU determines the security information used for SI security protection. Following steps 901 to 904 may be performed, wherein steps 901 and 904 are optional and thus are marked as dotted lines.

[0199] In step 901, a DU of a RAN node may send security capability supported by the DU to a CU of the RAN node. For example, the security capability includes at least one of the following: - An indicator indicating whether the DU supports the SI security protection. - One or more security algorithms supported by the DU for the SI security protection, such as SHA-256, ECCSI and / or ECDSA.

[0200] Step 901 is optional in some implementations.

[0201] In step 902, the CU sends security information used for SI security protection to the DU. The security information may include at least one of the following: - The first security algorithm used for SI security protection except the SIB-y. - The second security algorithm used for SIB-y security protection. - One or more SK-1 or one or more {SK-1, PK-1} pairs used for SI security protection, except for the SIB-y. Each SK-1 or each {SK-1, PK-1} pair may be associated with a first identifier. In addition, the security information may further include information related to the SK-1 or the {SK-1, PK-1} pair, such as validity and a valid area (e.g. per cell, per RAN node, or per protection area) where the SK-1 or the {SK-1, PK-1} applies to. - One or more SK-2 or one or more {SK-2, PK-2} pairs used for SIB-y security protection. Each SK-2 or each {SK-2, PK-2} pair may be associated with a second identifier. In addition, the security information may further include the information related to the SK-2 or the {SK-2, PK-2} pair, such as validity and a valid area (e.g. per cell, per RAN node, or per protection area) where the {SK-2, PK-2} applies to.

[0202] In step 903, the UE and the DU or CU perform the SI security protection and verification, as described in the embodiments of Figure 7 (i.e. steps 701 to 708) or the embodiments of Figure 8 (i.e. steps 801 to 809) .

[0203] In step 904, the CU may update the security information used for SI security protection in the DU. For example, the updated security information may include at least one of the following: - The first security algorithm used for SI security protection except the SIB-y. - The second security algorithm used for SIB-y security protection. - One or more SK-1 or one or more {SK-1, PK-1} pairs used for SI security protection, except for the SIB-y. Each SK-1 or each {SK-1, PK-1} pair may be associated with a first identifier. - The information related to the SK-1 or the {SK-1, PK-1} pair, such as the validity and the valid area (e.g. per cell, per RAN node, or per protection area) where the {SK-1, PK-1} applies to. - One or more SK-2 or one or more {SK-2, PK-2} pairs used for SIB-y security protection. Each SK-2 or each {SK-2, PK-2} pair may be associated with a second identifier. - The information related to the SK-2 or the {SK-2, PK-2} pair, such as validity and the valid area (e.g. per cell, per RAN node, or per protection area) where the {SK-2, PK-2} applies to.

[0204] For example, the CU may receive the updated security information used for SI security protection from the CN node, and then sends it to the DU in step 904. Step 904 is optional in some implementations.

[0205] Figure 10 illustrates another exemplary signalling flow of performing SI security protection in a split RAN architecture in accordance with aspects of the present application. Details described in all other embodiments of the present application are applicable for the embodiments of Figure 10.

[0206] As shown in Figure 10, a RAN node (e.g. a BS) is in CU-DU architecture, and includes a CU and one or more DUs. In the embodiments of Figure 10, the DU determines security information used for SI security protection. Following steps 1001 to 1003 may be performed, wherein step 1003 is optional and thus is marked as a dotted line.

[0207] In step 1001, a DU of a RAN node sends the security information used for SI security protection to a CU of the RAN node. For example, the security information may include at least one of the following: - The first security algorithm used for SI security protection except the SIB-y. - The second security algorithm used for SIB-y security protection. - One or more SK-1 or one or more {SK-1, PK-1} pairs used for SI security protection, except for the SIB-y. Each SK-1 or each {SK-1, PK-1} pair may be associated with a first identifier. In addition, the security information may further include the information related to the SK-1 or the {SK-1, PK-1} pair, such as validity and a valid area (e.g. per cell, per RAN node, or per protection area) where the {SK-1, PK-1} applies to. - One or more SK-2 or one or more {SK-2, PK-2} pairs used for SIB-y security protection. Each SK-2 or each {SK-2, PK-2} pair may be associated with a second identifier. In addition, the security information may further include the information related to the SK-2 or the {SK-2, PK-2} pair, such as validity and a valid area (e.g. per cell, per RAN node, or per protection area) where the {SK-2, PK-2} applies to.

[0208] In step 1002, the UE and the DU or CU perform the SI security protection and verification, as described in the embodiments of Figure 7 (i.e. steps 701 to 708) or the embodiments of Figure 8 (i.e. steps 801 to 809) .

[0209] In step 1003, the CU may update the security information used for SI security protection in the DU. in some implementations, the CU receives the updated security information used for SI security protection from the CN node or from operation administration and maintenance (OAM) , and then sends it to the DU. For example, the updated security information may include at least one of the following: - The first security algorithm used for SI security protection except the SIB-y. - The second security algorithm used for SIB-y security protection. - One or more SK-1 or one or more {SK-1, PK-1} pairs used for SI security protection, except for the SIB-y. Each SK-1 or each {SK-1, PK-1} pair may be associated with a first identifier. - The information related to the SK-1 or the {SK-1, PK-1} pair, such as the validity and the valid area (e.g. per cell, per RAN node, or per protection area) where the {SK-1, PK-1} applies to. - One or more SK-2 or one or more {SK-2, PK-2} pairs used for SIB-y security protection. Each SK-2 or each {SK-2, PK-2} pair may be associated with a second identifier. - The information related to the SK-2 or the {SK-2, PK-2} pair, such as validity and the valid area (e.g. per cell, per RAN node, or per protection area) where the {SK-2, PK-2} applies to.

[0210] Step 1003 is optional in some implementations.

[0211] In some other embodiments of the present application, the DU may provide suggested security information used for SI security protection to the CU, while the CU may determine the final security information used for SI security protection and then send it to the DU.For example, the suggested security information may include at least one of the following: - One or more first security algorithms used for SI security protection except the SIB-y. - One or more second security algorithms used for SIB-y security protection. - One or more SK-1 or one or more {SK-1, PK-1} pairs used for SI security protection, except for the SIB-y. Each SK-1 or each {SK-1, PK-1} pair may be associated with a first identifier. - One or more SK-2 or one or more {SK-2, PK-2} pairs used for SIB-y security protection. Each SK-2 or each {SK-2, PK-2} pair may be associated with a second identifier.

[0212] The final security information may include at least one of the following: - The first security algorithm used for SI security protection except the SIB-y. - The second security algorithm used for SIB-y security protection. - The SK-1 or the {SK-1, PK-1} pairs used for SI security protection, except for the SIB-y. The SK-1 or each {SK-1, PK-1} pair may be associated with a first identifier. - The SK-2 or the {SK-2, PK-2} pairs used for SIB-y security protection. The SK-2 or each {SK-2, PK-2} pair may be associated with a second identifier.

[0213] The description herein is provided to enable a person having ordinary skill in the art to make or use the application. Various modifications to the application will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the application. Thus, the application is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.

Claims

1.A user equipment (UE) for wireless communication, comprising:at least one memory; andat least one processor coupled to the at least one memory and configured to cause the UE to:receive, from a radio access network (RAN) node, first system information (SI) of a first cell of the RAN node and a set of first digital signatures, wherein the first SI is carried in at least one of a master information block (MIB) or a set of first system information blocks (SIBs) , and wherein the set of first digital signatures is generated by using a first private key from a pair of {the first private key, a first public key} and the first SI as inputs to a first security algorithm;generate second SI by using the set of first digital signatures and the first public key as the inputs to the first security algorithm; anddetermine that the first cell is authentic if the second SI is identical with the first SI, or consider that the first cell is barred if the second SI is different from the first SI.2.The UE of claim 1, wherein the set of first SIBs includes the set of first digital signatures.3.The UE of claim 1, wherein the first SI is carried in system information block1 (SIB1) , and the SIB1 includes at least one of the following:scheduling information regarding third SI, wherein the third SI includes the first public key; ora configuration used by the UE to request the third SI.4.The UE of claim 3, wherein the third SI further includes at least one of the following:the first security algorithm;valid time duration of the first public key; ora first valid area of the first public key, wherein the first valid area covers all cells of the RAN node, one or more cells of the RAN node, or a protecting area related to the RAN node.5.The UE of claim 3, wherein the third SI is carried in a second SIB different from the SIB1 and the MIB, the second SIB includes a second digital signature, the second digital signature is generated by using the third SI and a second private key from a pair of {the second private key, a second public key} as inputs to a second security algorithm, and the second security algorithm is identical with or different from the first security algorithm.6.The UE of claim 5, wherein the at least one processor is further configured to cause the UE to:generate fourth SI by using the second digital signature and the second public key as the inputs to the second security algorithm, wherein the second public key is pre-configured in the UE or received by the UE from the RAN node; anddetermine that the first cell is authentic if the fourth SI is identical with the third SI, or consider that the first cell is barred if the fourth SI is different from the third SI.7.The UE of claim 3, wherein the SIB1 further includes the set of first digital signatures, and the first SI is:the SIB1 except the set of first digital signatures; orthe MIB, and the SIB1 except the set of first digital signatures.8.The UE of claim 7, wherein after determining that the first cell is authentic, the at least one processor is further configured to cause the UE to:store system information included in the SIB1; orstore the MIB and the system information included in the SIB1.9.The UE of claim 7, wherein after considering that the first cell is barred, the at least one processor is further configured to cause the UE to:discard the MIB and system information included in the SIB1, and perform a cell re-selection towards one or more cells of the RAN node other than the first cell; orconsider that the RAN node to which the first cell belongs is barred.10.The UE of claim 9, wherein the at least one processor is further configured to cause the UE to:exclude the first cell as a candidate for a cell selection or a cell re-selection of the UE after considering that the first cell is barred; orexclude all cells of the RAN node as candidates for the cell selection or the cell re-selection of the UE after considering that the RAN node is barred.11.The UE of claim 9, wherein the at least one processor is further configured to cause the UE to initiate a radio resource control (RRC) connection reestablishment procedure or enter an RRC idle state if the UE is in an RRC connected state.12.The UE of claim 3, wherein after considering that one or more cells of the RAN node are barred, the at least one processor is further configured to cause the UE to transmit identifier information of the one or more cells to the RAN node.13.The UE of claim 12, wherein the at least one processor is further configured to cause the UE to transmit one of the following to the RAN node:a set of SI without successful security verification of each cell within the one or more cells; orinformation indicating that verification of the third SI is failed.14.A radio access network (RAN) node for wireless communication, comprising:at least one memory; andat least one processor coupled to the at least one memory and configured to cause the RAN node to:generate a set of first digital signatures by using a first private key from a pair of {the first private key, a first public key} and first system information (SI) of a first cell of the RAN node as inputs to a first security algorithm; andtransmit the first SI and the set of first digital signatures to a user equipment (UE) , wherein the first SI is carried in at least one of a master information block (MIB) or a set of first system information blocks (SIBs) .15.The RAN node of claim 14, wherein the at least one processor is further configured to cause the RAN node to receive security information used for SI security protection from a core network (CN) node.16.The RAN node of claim 14, wherein the RAN node includes a distributed unit (DU) and a central unit (CU) , and wherein the at least one processor is further configured to cause the CU to transmit security information used for SI security protection to the DU.17.The RAN node of claim 14, wherein the RAN node includes a distributed unit (DU) and a central unit (CU) , and wherein the at least one processor is further configured to cause the DU to transmit security information used for SI security protection to the CU.18.The RAN node of any of claims 15, 16 and 17, wherein the security information used for the SI security protection includes at least one of the following:the first security algorithm;the second security algorithm;one or more first private keys or one or more pairs of {the first private key, the first public key} ;valid time duration of each first private key within the one or more first private keys or each pair within the one or more pairs of {the first private key, the first public key} ;identifier information of each first private key within the one or more first private keys or each pair within the one or more pairs of {the first private key, the first public key} ;a first valid area of each first private key within the one or more first private keys or each pair within the one or more pairs of {the first private key, the first public key} ;one or more second private keys or one or more pairs of {asecond private key, a second public key} ;valid time duration of each second private key within the one or more second private keys or each pair within the one or more pairs of {the second private key, the second public key} ;identifier information of each second private key within the one or more second private keys or each pair within the one or more pairs of {the second private key, the second public key} ; ora second valid area of each second private key within the one or more second private keys or each pair within the one or more pairs of {the second private key, the second public key} ,wherein at least one of the first valid area or the second valid area covers all cells of the RAN node, one or more cells of the RAN node, or a protecting area related to the RAN node.19.A processor for wireless communication, comprising:at least one controller coupled with at least one memory and configured to cause the processor to:receive, from a radio access network (RAN) node, first system information (SI) of a first cell of the RAN node and a set of first digital signatures, wherein the first SI is carried in at least one of a master information block (MIB) or a set of first system information blocks (SIBs) , and wherein the set of first digital signatures is generated by using a first private key from a pair of {the first private key, a first public key} and the first SI as inputs to a first security algorithm;generate second SI by using the set of first digital signatures and the first public key as the inputs to the first security algorithm; anddetermine that the first cell is authentic if the second SI is identical with the first SI, or consider that the first cell is barred if the second SI is different from the first SI.20.A method performed by a user equipment (UE) for wireless communication, comprising:receiving, from a radio access network (RAN) node, first system information (SI) of a first cell of the RAN node and a set of first digital signatures, wherein the first SI is carried in at least one of a master information block (MIB) or a first set of system information blocks (SIBs) , and wherein the set of first digital signatures is generated by using a first private key from a pair of {the first private key, a first public key} and the first SI as inputs to a first security algorithm;generating second SI by using the set of first digital signatures and the first public key as the inputs to the first security algorithm; anddetermining that the first cell is authentic if the second SI is identical with the first SI, or considering that the first cell is barred if the second SI is different from the first SI.