Method and system for secured communication of control information in a wireless network environment
Abstract
The present invention provides a method and system for safely securing control information in a wireless communication network environment. When the transmitting station needs to transmit control information to the receiving station, the transmitting station determines whether the control information belongs to the first type or the second type. If the control information is the second type of control information, the transmitting station secures the second type of control information by using the calculated counter value, the CMAC value, and the security key to protect the second type of control information. When the control information is secured, the transmitting station transmits the secured control information to the receiving station.

Term
6.3 yearsto projected expiry
Projected expiry 24 December 2032, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
16 claims: 2 independent, 14 dependent
- 1무선통신 환경에서 제어정보를 보안처리하는 방법에 있어서, 송신국에서, 제1 유형의 제어정보를 보안처리하기 위하여 하나 또는 다수의 보안키들 및 제2 유형의 제어정보를 보안처리하기 위하여 하나 또는 다수의 보안키들을 생성하는 과정;상기 제1 유형의 제어정보에 대하여 제1 유형의 카운터를 계산하고 상기 제2 유형의 제어정보에 대하여 제2 유형의 카운터를 계산하는 과정;상기 제1 유형의 제어정보에 대하여 제1 유형의 암호화 메시지 인증 코드(CMAC) 및 상기 제2 유형의 제어정보에 대하여 제2 유형의 암호화 메시지 인증 코드(CMAC)를 계산하는 과정;상기 제1 유형의 CMAC, 상기 제1 유형의 카운터, 및 상기 제1 유형의 제어정보에 대하여 유도되는 상기 하나 또는 다수의 보안키들을 이용하여 상기 제1 유형의 제어정보를 보안처리하는 과정;및 상기 제2 유형의 CMAC, 상기 제2 유형의 카운터, 및 상기 제2 유형의 제어정보에 대하여 유도되는 상기 하나 또는 다수의 보안키들을 이용하여 상기 제2 유형의 제어정보를 보안처리하는 과정을 포함하는 제어정보 보안 방법.
- 2제1항에 있어서, 상기 제1 유형의 제어정보는 설정된 시그널링 접속/흐름 상에서 수신국과 통신하는 제어 메시지를 포함하는 제어정보 보안 방법.
- 3제1항에 있어서, 상기 제2 유형의 제어정보는 매체접속제어(MAC) 시그널링 헤더들을 포함하는 제어정보 보안 방법.
- 4제1항에 있어서, 상기 제1 유형의 제어정보는 소정의 임계치보다 크거나 같은 크기를 갖는 제어정보 보안 방법.
- 5제1항에 있어서, 상기 제2 유형의 제어정보는 소정의 임계치보다 작은 크기를 갖는 제어정보 보안 방법.
- 6제1항에 있어서, 상기 제1 유형의 제어정보를 보안처리하기 위하여 상기 하나 또는 다수의 보안키들 및 상기 제2 유형의 제어정보를 보안처리하기 위하여 상기 하나 또는 다수의 보안키들을 생성하는 과정은, 인증키 전후관계(authentication key context)로부터 프리-키(pre-key)를 생성하는 과정;및 상기 프리-키를 이용하여, 상기 제1 유형의 제어정보를 보안처리하기 위하여 하나 또는 다수의 보안키들, 및 상기 제2 유형의 제어정보를 보안처리하기 위하여 하나 또는 다수의 보안키들을 유도하는 과정을 포함하는 제어정보 보안 방법.
- 7제1항에 있어서, 상기 제2 유형의 제어정보에 대하여 상기 제2 유형의 카운터를 계산하는 과정은, 상기 제2 유형의 제어정보가 상기 수신국에 안전하게 전송될 프레임의 프레임 넘버를 결정하는 과정;상기 프레임에 대한 롤 오버 카운터를 결정하는 과정;상기 제2 유형의 제어정보에 대한 제어정보 인덱스를 결정하는 과정;및 상기 프레임에 대한 롤 오버 카운터와 상기 제어정보 인덱스를 이용하여 상기 제2 유형의 제어정보에 대한 상기 제2 유형의 카운터를 계산하는 과정을 포함하는 제어정보 보안 방법.
- 8제1항에 있어서, 상기 제2 유형의 제어정보에 대하여 상기 제2 유형의 카운터를 계산하는 과정은, 상기 제2 유형의 제어정보가 상기 수신국에 안전하게 전송될 프레임의 프레임 넘버를 결정하는 과정;상기 프레임에 대한 롤 오버 카운터를 결정하는 과정;및 상기 프레임에 대한 롤 오버 카운터를 이용하여 상기 제2 유형의 제어정보에 대한 상기 제2 유형의 카운터를 계산하는 과정을 포함하는 제어정보 보안 방법.
- 9제1항에 있어서, 상기 제2 유형의 제어정보에 대하여 상기 제2 유형의 카운터를 계산하는 과정은, 상기 제2 유형의 제어정보에 대한 제어정보 인덱스를 결정하는 과정;및 상기 제어정보 인덱스를 이용하여 상기 제2 유형의 제어정보에 대한 상기 제2 유형의 카운터를 계산하는 과정을 포함하는 제어정보 보안 방법.
- 10제1항에 있어서, 상기 제1 유형의 제어정보에 대하여 상기 제1 유형의 카운터를 계산하는 과정은, 상기 제1 유형의 제어정보에 대한 패킷 넘버를 결정하는 과정;및 상기 패킷 넘버를 이용하여 상기 제1 유형의 제어정보에 대한 상기 제1 유형의 카운터를 계산하는 과정을 포함하는 제어정보 보안 방법.
- 11제1항에 있어서, 상기 제2 유형의 제어정보에 대하여 상기 제2 유형의 암호화 메시지 인증 코드(CMAC)를 계산하는 과정은, 인증키 식별자, 상기 제2 유형의 제어정보가 안전하게 전송될 프레임의 프레임 넘버, 이동국 논리 어드레스, 흐름 식별자, 상기 제2 유형의 카운터, 및 상기 제어정보의 내용을 이용하여 상기 제2 유형의 제어정보에 대한 상기 제2 유형의 CMAC를 계산하는 과정을 포함하는 제어정보 보안 방법.
- 12제1항에 있어서, 상기 제2 유형의 제어정보에 대한 상기 제2 유형의 CMAC는 상기 제1 유형의 제어정보에 대한 상기 제1 유형의 CMAC보다 짧은 것인 제어정보 보안 방법.
- 13무선통신 환경에서 제어정보를 보안처리하기 위한 송신국으로서, 상기 송신국은 제1항 내지 제12항 중의 어느 한 항에 기술된 방법에 의해 구현되는 것인 송신국.
- 14송신국으로부터 수신된 시그널링 헤더를 처리하는 방법에 있어서, 상기 송신국으로부터 수신된 시그널링 헤더가 보호되는지 여부를 결정하는 과정;상기 시그널링 헤더에 있는 카운터 값의 유효성(validating)을 확인하는 과정;상기 카운터 값이 유효하다면 상기 시그널링 헤더가 상기 송신국으로부터 수신되는 프레임의 프레임 넘버를 결정하는 과정;상기 카운터 값, 프레임 넘버, 인증키 식별자, 이동국 논리 어드레스, 흐름 식별자, 및 상기 시그널링 헤더의 내용에 기초하여 암호화 메시지 인증 코드(CMAC)를 계산하는 과정;상기 계산된 CMAC 값이 상기 시그널링 헤더에서의 상기 CMAC 값과 일치하는지 여부를 결정하는 과정;및 상기 계산된 CMAC 값이 상기 시그널링 헤더에서의 상기 CMAC 값과 일치한다면, 상기 시그널링 헤더의 내용을 처리하는 과정을 포함하는 시그널링 헤더를 처리하는 방법.
- 15제14항에 있어서, 상기 시그널링 헤더에 있는 카운터 값의 유효성을 확인하는 과정은, 동일한 카운터 값을 갖는 임의의 시그널링 헤더가 이전에 송신국으로부터 수신되어 있는지 여부를 결정하는 과정을 포함하는 시그널링 헤더를 처리하는 방법.
- 16송신국으로부터 수신된 시그널링 헤더를 처리하기 위한 수신국으로서, 상기 수신국은 제14항 내지 제15항 중의 어느 한 항에 기술된 방법에 의해 구현되는 것인 수신국.
Independent claims16
76 paragraphs, as filed
METHOD AND SYSTEM FOR SECURED COMMUNICATION OF CONTROL INFORMATION IN A WIRELESS NETWORK ENVIRONMENT}
The present invention relates generally to the field of wireless communication technology, and more particularly, to secure communication of control information in a wireless network environment.
Broadband wireless networks based on various communication standards (eg, the Institute for Electronic and Electrical Engineers (IEEE) 802.16e standard based on the WiMAX (Worldwide Interoperability for Microwave Access) standard and its evolution to IEEE 802.16m) are It provides various kinds of services such as voice, packet data, etc. Recently, IEEE 802.16m and IEEE 802.16e-based standards have been introduced to enable machine-to-machine (M2M) communication for applications such as smart grid, vehicle tracking, and healthcare. is being considered for Security is one of the important requirements for such standards as it will be used for many important applications such as healthcare and smart grid.
Various types of control information are exchanged for communication between a mobile station or an M2M device and a base station. Typically, control information is exchanged in the form of a control message transmitted during a signaling connection or flow formed between the M2M device and the base station. Currently, control messages are protected using a Cipher based Message Authentication Code (CMAC) algorithm, which is defined in the National Institute of Standards and Technology (NIST) special publication 800-38B. An 8-byte CMAC is generated using the CMAC structure as Optionally, the content of the control message may also be encrypted. A 3-byte counter or packet number (PN) is also used to provide protection against relay attacks. The counter is incremented after each transmission of a control message. The tuple <control security key, PN> is never repeated. The sequence number of the security key used to generate the CMAC is also sent with the control message. The method of protecting control messages adds a 12-byte overhead to each control message. Typically, a control message protected using a CMAC value is accompanied by a medium access control (MAC) protocol data unit (PDU). The MAC PDU accompanying the protected control message includes a MAC header and a payload. The payload includes a control message followed by security information consisting of a security key sequence number, reserved bits, the number of packets, and a CMAC value.
Control information is also exchanged in the form of MAC signaling headers, which are specific types of MAC headers. The MAC signaling headers are sent to the receiving station in MAC PDUs. It can be understood that a MAC PDU carrying a MAC signaling header does not contain any payload other than that MAC signaling header. MAC signaling headers are very short in size (on the order of a few bytes), but contain important information. Typically, MAC signaling headers are 6 to 7 bytes in size. The MAC signaling header may include a flow identifier field, a type field, a length field, and a content (content) field. The flow identifier field indicates a flow identifier associated with the MAC signaling header. The type field indicates the type of the MAC signaling header. The length field indicates the length of the MAC signaling header. The content field holds the actual content of the MAC signaling header. Currently, MAC signaling headers are exchanged between the base station and the mobile station or M2M device in a non-secure manner.
<p>The current control message protection technique cannot be applied to MAC signaling headers because a lot of overhead may be added to the size of the MAC signaling header compared to the control information itself.</p>
<p>According to one aspect of the present disclosure, there is provided a method of security processing (security) of control information in a wireless communication environment, wherein the method includes one or more control information in a transmitting station for security processing of the first type of control information. generating one or more security keys to secure the security keys and the second type of control information; calculating a counter of a first type with respect to the first type of control information and calculating a counter of a second type with respect to the second type of control information; calculating a first type of encrypted message authentication code (CMAC) for the first type of control information and a second type of encrypted message authentication code (CMAC) for the second type of control information; security processing of the first type of control information using the first type of CMAC, the first type of counter, and the one or more security keys derived for the first type of control information; and security processing of the second type of control information using the second type of CMAC, the second type of counter, and the one or more security keys derived for the second type of control information. include </p><p>According to another aspect of the present disclosure, there is provided a transmitting station comprising a processor and a memory communicatively connected to the processor, wherein the memory includes one or more security for securing a first type of control information. generate one or more security keys to secure the keys and the second type of control information; calculating a counter of a first type with respect to the first type of control information and calculating a counter of a second type with respect to the second type of control information; calculate a first type of encrypted message authentication code (CMAC) for the first type of control information and a second type of CMAC for the second type of control information; secure the first type of control information using the first type of CMAC, the first type of counter, and the one or more security keys derived for the first type of control information; and a control configured to secure the second type of control information using the second type of CMAC, the second type of counter, and the one or more security keys derived for the second type of control information. Includes information protection module.</p><p>According to another aspect of the present disclosure, there is provided a method for securely communicating signaling headers in a wireless communication environment, the method comprising: calculating, by a transmitting station, a counter value for a signaling header to be securely transmitted to a receiving station; calculate an encrypted message authentication code (CMAC) value for the signaling header; secure the signaling header using the CMAC value, the counter value, and one or more security keys derived for the signaling header; and transmitting the obtained signaling header to the receiving station.</p><p>According to another aspect of the present disclosure, there is provided a transmitting station comprising a processor and a memory communicatively coupled to the processor, the memory configured to: calculate a counter value for a signaling header to be securely transmitted to a receiving station; calculate an encrypted message authentication code (CMAC) value for the signaling header; secure the signaling header using the CMAC value, the counter value, and one or more security keys derived for the signaling header; and a control information protection module configured to transmit the obtained signaling header to a receiving station.</p><p>According to another aspect of the present disclosure, there is provided a method of processing a signaling header received from a transmitting station, the method comprising: determining whether a signaling header received from the transmitting station is protected; checking the validity of a counter value in the signaling header; determining a frame number of a frame in which the signaling header is received from the transmitting station if the counter value is valid; calculating a CMAC value based on the counter value, frame number, authentication key identifier, mobile station logical address, flow identifier, and contents of the signaling header; determining whether the calculated CMAC value matches the CMAC value in the signaling header; and if the calculated CMAC value matches the CMAC value in the signaling header, processing the content of the signaling header.</p><p>According to another aspect of the present disclosure, there is provided a receiving station comprising a processor and a memory communicatively coupled to the processor, wherein the memory determines whether a signaling header received from the transmitting station is protected; ; check the validity of a counter value in the signaling header; determine a frame number of a frame in which the signaling header is received from the transmitting station if the counter value is valid; calculate a CMAC value based on the counter value, the frame number, the authentication key identifier, the mobile station logical address, the flow identifier, and the content of the signaling header; determine whether the calculated CMAC value matches the CMAC value in the signaling header; and a control information processing module, configured to process the content of the signaling header if the calculated CMAC value matches the CMAC value in the signaling header.</p><p>According to another aspect of the present disclosure, there is provided a method for securely transmitting a signaling header in a wireless network environment, the method comprising: generating security key information to secure a signaling header to be transmitted to a receiving station; adding the security key information together with the content of the signaling header; generating a cyclic redundancy check (CRC) value for the security key information to which the content of the signaling header is added; adding the CRC value together with the content of the signaling header; and transmitting the signaling header together with the CRC value added to the content of the signaling header to the receiving station.</p><p>According to another aspect of the present disclosure, there is provided a transmitting station including a processor and a memory communicatively connected to the processor, wherein the memory includes a security key to secure a signaling header to be transmitted to a receiving station. generate information; adding the security key information together with the content of the signaling header; generating a cyclic redundancy check (CRC) value for the security key information to which the content of the signaling header is added; adding the CRC value together with the content of the signaling header; and a control information protection module configured to transmit the signaling header to the receiving station together with the CRC value added to the content of the signaling header.</p><p>According to another aspect of the present disclosure, there is provided a method of processing a protected signaling header in a wireless network environment, wherein the method generates security key information when receiving a protected signaling header having a CRC value from a transmitting station do; adding the security key information together with the content of the signaling header; generating a CRC value based on the security key information to which the content of the signaling header is added; determine whether the generated CRC value matches (harmonizes) a CRC value in the signaling header; and processing the content of the signaling header if the generated CRC value matches the CRC value in the signaling header.</p><p>According to another aspect of the present disclosure, there is provided a method of processing a protected signaling header in a wireless network environment, wherein the method generates security key information when receiving a protected signaling header having a CRC value from a transmitting station do; adding the security key information together with the content of the signaling header; generating a CRC value based on the security key information to which the content of the signaling header is added; determine whether the generated CRC value matches (harmonizes) a CRC value in the signaling header; and processing the content of the signaling header if the generated CRC value matches the CRC value in the signaling header.</p>
1 illustrates a block diagram of a wireless network system for securely communicating control information between a transmitting station and a receiving station, according to one embodiment. 2 is a process flow diagram illustrating a method of secure processing control information to be transmitted to a receiving station, according to an embodiment. 3 is a process flow diagram of a detailed method for securing a signaling header, according to an embodiment. 4A illustrates an exemplary format of a Protected Media Access Control (MAC) signaling header, according to one embodiment. 4B illustrates an exemplary format of a Protected Media Access Control (MAC) signaling header, according to another embodiment. 5A shows an exemplary format of a protected abnormal power down signaling header, according to another embodiment. 5B shows an exemplary format of a protected abnormal power-down signaling header, according to another embodiment. 5C shows another exemplary format of a protected abnormal power-down signaling header according to another embodiment. 5D shows another exemplary format of a protected abnormal power-down signaling header according to another embodiment. 5E shows another exemplary format of a protected abnormal power-down signaling header according to another embodiment. 6 is a flow diagram of a process illustrating an exemplary method of processing a signaling header received from a transmitting station, according to an embodiment. 7A is a process flow diagram illustrating an exemplary method for refreshing security keys associated with a first type of control information and a second type of control information, according to an embodiment. 7B is a process flow diagram illustrating an exemplary method for refreshing security keys associated with a first type of control information and a second type of control information, according to another embodiment. 7C is a process flow diagram illustrating an exemplary method of refreshing security keys associated with a first type of control information and a second type of control information, according to another embodiment. 8 is a process flow diagram of a detailed method of securing a signaling header according to an optional embodiment. 9 is a process flow diagram of a detailed method for processing a protected signaling header received from a transmitting station according to an alternative embodiment. 10 is a block diagram of a transmitting station showing various components for implementing embodiments of the present invention. 11 is a block diagram of a receiving station showing various components for implementing embodiments of the present invention. The drawings described above are for illustrative purposes only and are not intended to limit the scope of the present disclosure in any way.
The present invention provides a method and system for securely communicating control information in a wireless network environment. In the following description of embodiments of the present invention, reference is made to the accompanying drawings, which form a part hereof, in which specific embodiments in which the present invention may be realized are shown by way of example only. has been These embodiments are described in sufficient detail to enable those skilled in the art to practice the invention. And, it should be understood that other embodiments may also be utilized and changes may be made without departing from the scope of the present invention. Accordingly, the following detailed description is not made in a limiting sense, and the scope of the present invention will be defined only by the appended claims.
Throughout this specification, the expressions "secured, secure, or secured" and "protected" have substantially the same meaning and may be used interchangeably.
1 illustrates a block diagram of a wireless network system 100 for securely communicating control information between a transmitting station and a receiving station, according to one embodiment. In FIG. 1 , a system 100 includes a transmitting station 102 , a receiving station 104 , and a wireless interface 106 . The transmitting station 102 includes a control information protection module 106 and the receiving station 104 includes a control information processing module 108 . The transmitting station 102 may be a mobile station or a base station. The receiving station 104 may be a base station or a mobile station.
When the transmitting station 102 needs to transmit control information to the receiving station 104, the control information protection module 106 determines whether the control information should be protected. If the control information is to be protected, the control information protection module 106 determines whether the control information belongs to the first type or the second type. For example, the first type of control information includes control messages to be transmitted on a preset signaling connection/flow (eg, management messages in an IEEE 802.16.1 system, radio resource access control in a Long Term Evolution (LTE) system). message, etc.). The second type of control information may include signaling headers (eg, standalone signaling headers in an IEEE 802.16.1 system, medium access control (MAC) signaling headers in an LTE system, etc.). The second type of control information can reach up to 7 bytes in size. If the control information is the first type of control information, the control information protection module 106 provides a first type of counter, a first type of Cipher based Message Authentication Code (CMAC) value, and a first type of control. The first type of control information is secured using the calculated security keys to protect the information. If the control information is the second type of control information, the control information protection module 106 is configured to protect the second type of counter, the second type of encrypted message authentication code (CMAC) value, and the second type of control information. The second type of control information is secured using the calculated security keys. When the control information is secured, the transmitting station 102 transmits the secured control information to the receiving station 104 on the wireless interface 110 .
Upon receiving the secured control information, the control information processing module 108 determines the type of control information received from the transmitting station 102 . Accordingly, the control information processing module 108 decodes the received control information based on the type of the control information. The process of securing the control information and processing the secured control information is described in more detail in the following description.
2 is a process flow diagram illustrating a method of securing control information to be transmitted to a receiving station, according to an embodiment. In general, the transmitting station 102 transmits two types of control information to the receiving station 104 . Since these two types of control information accompany important information, the control information needs to be safely transmitted to the receiving station 104 . The process flow diagram 200 provides methodological procedures for secure processing of the first and second types of control information prior to transmitting it to the receiving station 104 .
In step 202, a pre-key is generated from an authentication key (AK). Typically, the authentication key is derived from each other at the transmitting station 102 (eg, a base station) and the receiving station 104 (eg, a mobile station) during the authentication process. The length of the authentication key is 160 bits. The pre-key may be used to create separate uplink and downlink security keys for securing the first type of control information and the second type of control information, respectively. In step 204, the uplink and/or downlink security keys for the first type of control information and the uplink and/or downlink security keys for the second type of control information are derived from the pre-key. For example, the uplink security key may be used to authenticate control information transmitted upstream, while the downlink security key may be used to authenticate control information transmitted downlink. In one exemplary implementation, the length of the uplink and downlink security keys for the first and second types of control information is 128 bits. In another exemplary implementation, the lengths of the uplink and downlink security keys for the first and second types of control information may be different sizes. It should be noted that the process of deriving security keys from the pre-key is well known to those skilled in the art, and a description thereof is omitted herein. New security keys are periodically generated according to the methods illustrated in FIGS. 7A and 7C .
In step 206, a first type of counter for the first type of control information is calculated. For example, the first type of counter may be a packet number (PN) of a MAC PDU to which the first type of control information is to be transmitted. In some embodiments, a packet number for the first type of control information is determined. In these embodiments, the first type of counter is calculated based on the first type of control information. In step 208, a first type of CMAC for the first type of control information is calculated. The first type of CMAC described above is calculated based on the CMAC configuration as specified in the National Institute of Standards and Technology (NIST) Special Publication 800-38B. For example, the first type of CMAC is truncate (Security key for control information of the first type, authentication key identifier | PN | Logical address of mobile station | flow identifier | Zero Padding | First type of control information, 64). In step 210, the first type of control information is secured using the first type of CMAC, the first type counter, and security keys derived for the first type of control information. A method of calculating the first type of counter and the first type of CMAC in order to secure the first type of control information is well known to those skilled in the art, so a description thereof will be omitted here.
Steps 212 to 216 exemplify a process for securing the second type of control information such as a signaling header according to the present invention. In step 212, a second type of counter for the second type of control information is calculated. In step 208, a second type of CMAC for the second type of control information is calculated. The second type of CMAC is calculated based on the CMAC configuration as specified in the National Institute of Standards and Technology (NIST) Special Publication 800-38B. For example, the CMAC of the second type is truncate (Security key for control information of the second type, authentication key identifier | frame number | mobile station logical address | flow identifier | counter value of the second type | zero padding | second type of control information, 16). In step 210, the second type of control information is secured using the CMAC of the second type, the second type counter, and security keys derived for the second type of control information. In step 212 , the second type of information to which the second type of CMAC and the second type of counter are added is transmitted to the receiving station 104 . It should be noted that the above-described second type counter and second type CMAC are separate from the first type counter and first type CMAC and are suitable for secure processing of the second type of control information. For example, the CMAC of the second type may be of a shorter length compared to the CMAC of the first type and is calculated using different methods than the method used to calculate the CMAC of the first type. In some embodiments, the second type of counter and the second type of CMAC include a total size of a packet including the secured second type of control information, the second type of CMAC and the second type of counter. It is calculated not to exceed the allowable threshold of the second type of control information. A detailed process for securing the second type of control information such as signaling headers is described in more detail with reference to FIG. 3 .
3 is a process flow diagram of a detailed method for securing a signaling header, according to an embodiment. Assume that the transmitting station 102 has a signaling header to be transmitted to the receiving station 104 . In step 302, it is determined whether the signaling header will be transmitted securely (in a secure manner) to the receiving station 104 . If the signaling header is to be transmitted in an unprotected manner, the unsecured signaling header is transmitted to the receiving station 104 in step 304 . If the signaling header is to be transmitted in a secure type, in step 306, it is determined whether security keys for securing the signaling header are available. If the security keys are not available, step 304 is performed.
If security keys are available, then at step 308, the frame number of the frame associated with the available resource is determined. Optionally, if security keys are available, it may be determined whether sufficient resources are available to transmit the signaling header in a secure type. For example, the base station communicates the resources allocated to the mobile station for every transmission by the mobile station. Based on the allocated resources, the mobile station may determine whether sufficient resources are available for secure transmission of the signaling header. If there are no resources available, step 304 is performed and the signaling header is transmitted without protection. If sufficient resources are available, step 308 is performed.
In step 310, a roll-over counter associated with the frame is determined. For example, the rollover counter is incremented after every frame rollover. In step 312, a signaling header index (also referred to as a control information index) related to the signaling header is determined. For every frame, a unique signaling header index is assigned to each signaling header to be transmitted in each frame. That is, the signaling header index is unique across signaling headers to be transmitted in one frame. In step 314, a counter value for the signaling header (previously referred to as a 'second type of counter') is calculated based on the signaling header index and the rollover counter of the frame. The counter value is used to provide protection against replay attacks. A retransmission attack is a form of network attack in which the transmission of valid data is intentionally or deceptively repeated or delayed.
In one embodiment, the counter value constitutes 'n1' most significant bits (MSB) corresponding to the rollover counter and 'n-n1' least significant bits (LSB) corresponding to the signaling header index. do. The 'n1' most significant bits corresponding to the rollover counter are 1 mod 2 (<sup>n1</sup>) is incremented by the same value as For example, if the frame number consists of 24 bits and 'n1' is 5 bits, when the frame number reaches 0x000000 from 0xFFFFFF, the most significant bit of 'n1' of the counter value is incremented by 1 mod 32. The least significant bit 'n-n1' corresponding to the signaling header index is allocated to the signaling headers in such a way that no two signaling headers in the same frame using the same security key have the same counter value. This allows the transmitting station 102 to use the same security key 2(2) per frame.<sup>n-</sup><sup>n1</sup>) makes it possible to secure the signaling headers. Accordingly, the transmitting station 102 will transmit every 2(<sup>n1</sup><sup>+</sup><sup>n2</sup>) will generate a new security key per frame. Here, 'n2' is the number of bits representing the frame number.
In another embodiment, the counter value constitutes the 'n1' least significant bit (LSB) corresponding to the rollover counter and the 'n-n1' most significant bit (MSB) corresponding to the signaling header index. The 'n1' most significant bits corresponding to the rollover counter are 1 mod 2 (<sup>n1</sup>) is incremented by the same value as For example, if the frame number consists of 24 bits and 'n1' is 5 bits, when the frame number reaches 0x000000 from 0xFFFFFF, the least significant bit of the counter value 'n1' is incremented by 1 mod 32. The most significant bit of 'n-n1' corresponding to the signaling header index is allocated to the signaling headers in such a way that no two signaling headers in the same frame using the same security key have the same counter value. Accordingly, the transmitting station 102 will transmit every 2(<sup>n1</sup><sup>+</sup><sup>n2</sup>) will generate a new security key per frame, where 'n2' is the number of bits representing the frame number.
In another embodiment, the counter value constitutes a rollover counter of the frame. The rollover counter is 1 mod 2() when a frame rollover occurs.<sup>n</sup>) is incremented by a value equal to For example, if the frame number consists of 24 bits and 'n' is 5 bits, the counter value is incremented by 1 mod 32 when the frame number reaches 0x000000 from 0xFFFFFF. This will allow the transmitting station 102 to secure only one signaling header per frame using the same security key. Accordingly, the transmitting station 102 will transmit every 2(<sup>n+</sup><sup>n2</sup>) will generate a new security key per frame. Here, 'n2' is the number of bits representing the frame number.
In another embodiment, the counter value constitutes a signaling header index related to the signaling header. The size of the signaling header is calculated based on the number of signaling headers to be transmitted in a secure type per frame using a security key. For example, if the size of the signaling header index is 'n' bits, the transmitting station 102 may secure 2n signaling headers per frame using the same security key. Accordingly, the transmitting station 102 will generate a new security key every 2n2 frames. Here, 'n2' is the number of bits representing the frame number.
In step 316, an indication is made in the signaling header to indicate that the signaling header is protected. In one embodiment, a flow identifier for indicating whether the signaling header is protected or not is set in the flow identifier field of the signaling header. For example, when the signaling header is protected, the flow identifier is set to the value '0b0100' in the flow identifier field. In another embodiment, an EC value is set in the EC field of the signaling header to indicate whether the signaling header is protected or not. For example, if the signaling header is protected, the EC field is set to a value of '1'. Optionally, the length of the signaling header is set in the length field of the signaling header in step 316 . In step 318, a CMAC value (also referred to as a 'second type of CMAC') for the signaling header is calculated. CMAC values are generated using the CMAC generation function. The following parameters are provided as inputs to the CMAC generation function for generating one CMAC value: a security key for the second type of control information, an authentication key identifier and a subsequent frame number followed by a signaling header index followed by The flow identifier followed by the counter value and the content of the subsequent signaling header. For example, the CMAC value is equal to truncate (Security Key for Second Type of Control Information | Authentication Key Identifier | Frame Number | Mobile Station Logical Address | Flow Identifier | Counter Value | Contents of the Signaling Header, 16). In one exemplary implementation, the 16 least significant bits of the value calculated above are used as the CMAC value. In another exemplary implementation, another 16-bit calculated value is used as the CMAC value.
In step 320, the secured signaling header is generated by adding a CMAC value and a counter value to the content of the signaling header. In one embodiment, the secured signaling header is generated by adding a CMAC value and at least 'n-n1' least significant bits of a counter value to the content of the signaling header, where the counter value is the 'n1' most significant bit of the rollover counter. bits and 'n-n1' least significant bits of the signaling header index. In another embodiment, the secured signaling header is generated by adding at least 'n1-n1' most significant bits of a CMAC value and a counter value, wherein the counter value includes 'n1' least significant bits of a rollover counter and signaling The 'n-n1' most significant bits of the header index are configured. In another embodiment, the secured signaling header is generated by adding a CMAC value and a rollover counter, where the counter value is equal to the rollover counter. In another embodiment, the secured signaling header is generated by adding the CMAC value and 'n1' least significant bit of the rollover counter of the frame, where the counter value is equal to the rollover counter of the frame. In another embodiment, the secured signaling header is generated by adding a CMAC value and/or a signaling header index, where the counter value is equal to the signaling header index. For example, the secured signaling header is generated by adding a CMAC value if the number of signaling headers allowed to be transmitted per frame is 'one'. It should be noted that the CMAC value and the counter value are added to the content of the signaling header so that the total size of the signaling header does not exceed the allowable total size (eg, 7 bytes). In step 322, the secured signaling header is transmitted to the receiving station 104.
The following description describes an exemplary process for protecting a signaling header in an IEEE 802.16.1b system. It is assumed that the mobile station in the IEEE 802.16.1b system needs to transmit the signaling header to the base station in a secure type. Also, assume that the security keys CMAC_SIG_KEY_U and CMAC_SIG_KEY_D for authenticating the signaling header in the uplink and downlink are derived as follows:
CMAC_SIG_KEY_U | CMAC_SIG_KEY_D = Dot16KDF (CMAC-TEK prekey, "CMACSIG", 256).
Upon obtaining the security keys, the mobile station resets the counter value to zero. The counter value is 8 bits in size. The first 5 bits of the counter value indicate the rollover counter for the frame in which the signaling header is to be transmitted. The next 3 least significant bits of the counter value indicate the signaling header index assigned to the signaling header. It should be noted that the signaling header index is assigned to the signaling header in such a way that no two signaling headers in the same frame obtained using the same security key have the same counter value. This enables the mobile station to protect 8 signaling headers per frame for 5 milliseconds (msec) using the same security key. Since the frame number is 24 bits in size and the rollover counter is 5 bits in size, the mobile station increments the counter value by the value of '1 mod 32' when the frame number reaches 0x000000 from 0xFFFFFF. Moreover, new security keys are updated every 2<sup>24 </sup>* 2<sup>5</sup> = 2<sup>29 </sup>It needs to be derived after frames.
Next, the mobile station uses the authentication key identifier (AKID), 24-bit frame number, 12-bit station identifier (STID) and 4-bit flow identifier (FID) in the signaling header, 8-bit counter value, 16-bit zero padding, and the content of the signaling header. Calculate the CMAC value for the subsequently made fields. The frame number is calculated based on the 22-bit super frame and the 2-bit frame index. For example, the CMAC value for the signaling header is calculated as follows:
CMAC Value = Truncate(CMAC(CMAC_SIG_KEY, AKID | 22-bit Super Frame Number | 2-bit Frame Index | STID | FID | Counter Value | 16-bit Zero Padding | Signaling Header Content), 16).
It is understood that CMAC values are constructed as specified in NIST Special Publication 800-38B. The mobile station generates a security-processed signaling header using 16 bits of LSB of an AES-CMAC calculation result such as a CMAC value and 3 bits of LSB of a counter value.
An exemplary procedure for protecting an abnormal power-down signaling header in an IEEE 802.16.1b system is described in the following description. In IEEE 802.16.1b, it is assumed that the M2M device needs to securely transmit an abnormal power-down signaling header in the uplink direction. In addition, it is assumed that the security key CMAC_SIG_KEY_U for authenticating the abnormal power-down signaling header transmitted in the uplink direction by the M2M device is derived as follows:
CMAC_SIG_KEY_U = Dot16KDF (CMAC-TEK prekey, "CMACSIG", 128).
Upon obtaining the security keys, the mobile station resets the counter value to zero. The counter value is equal to the rollover counter for one frame and has a size of 8 bits. The M2M device increments the counter value by the value '1 mod 8' when the frame number reaches 0x000000 from 0xFFFFFF. Accordingly, the M2M device can safely transmit one abnormal power-down signaling header per frame using the same uplink security key. Moreover, new security keys are updated every 2<sup>24</sup> * 2<sup>8</sup>= 2<sup>32</sup>It needs to be derived after frames.
Then, the mobile station performs the authentication key identifier (AKID), 24-bit frame number, 12-bit station identifier (STID) and 4-bit flow identifier (FID) in the signaling header, 8-bit counter value, 16-bit zero padding, abnormal power-down signaling Calculates the CMAC value for fields that are sequentially composed of header contents. The frame number is calculated based on the 22 bit super frame and the 2 bit frame index. For example, the CMAC value for the abnormal power-down signaling header is calculated as follows:
CMAC Value = Truncate(CMAC(CMAC_SIG_KEY_U, AKID | 22-bit Super Frame Number | 2-bit Frame Index | STID |FID | Counter Value | 16-bit Zero Padding | Signaling Header Content), 16). It is understood that CMAC values are constructed as specified in NIST Special Publication 800-38B. The mobile station generates one secured abnormal power-down signaling header by using the LSB 16 bits of the AES-CMAC calculation result such as the CMAC value and the LSB 3 bits of the counter value.
4A shows an exemplary format of a protected MAC signaling header 400 according to an embodiment. The MAC signaling header 400 includes a FID field 402 , a type field 404 , a length field 406 , a content field 408 , a counter field 410 and a CMAC value field 412 .
The FID field 402 contains a flow identifier associated with the MAC signaling header 400 indicating whether the MAC signaling header is protected. For example, if the MAC signaling header is protected, the FID field 401 has the value '0b100'. If the MAC signaling header 400 is not protected, the FID field 401 has the value '0b0010'. Accordingly, based on the value set in the FID field 402, the receiving station 104 determines whether the MAC signaling header 400 is protected or unprotected. The FID field 402 is 4 bits in size. The type field 404 indicates the type of the MAC signaling header 400 and is 5 bits in size. The length field 406 indicates the length of the FID field 402 , the type field 404 and the content field 406 . The content field 406 is 4 bits in size. For example, if the size of the MAC signaling header is 2 bytes, the length field 406 is set to the value '0b010'.
The content (content) field 408 holds the content of the MAC signaling header 400 and is 36 bits in size. The counter field 410 includes a counter value calculated for the MAC signaling header 400 and has a size of 8 bits. The CMAC field 412 contains the CMAC value calculated for the MAC signaling header 400 and has a size of 16 bits. The MAC signaling header 400 described above includes a counter field 410 and a CMAC field 412 if the FID field 402 is set to the value '0b0010' (that is, when the MAC signaling header is unprotected). It will be understood that this may not be the case.
4B illustrates an exemplary format of a Protected Media Access Control (MAC) signaling header, according to another embodiment. It will be appreciated that the MAC signaling header 450 of FIG. 4B is similar to the MAC signaling header 400 of FIG. 4C except for the information accompanying the length field 406 . In the MAC signaling header 450 , the length field 406 represents the sum of the lengths of the FID field 402 , the type field 404 , the content field 408 , the counter field 410 and the CMAC field 412 . .
5A shows an exemplary format for a protected abnormal power down signaling header 500 according to another embodiment. The abnormal power-down signaling header 500 includes an FID field 502 , a type field 504 , a length field 506 , an STD field 508 , an STID valid offset 510 , an emergency type field 512 , and an EC field 514 , counter field 516 , and CMAC field 518 .
The FID field 502 contains a flow identifier that distinguishes the MAC signaling header from other MAC PDUs and the FID field 502 is 4 bits in size. The type field 504 indicates the type of the abnormal power-down signaling header 500 and is 5 bits in size. The length field 506 indicates the total length of the abnormal power-down signaling header 500 . The length field 506 is 4 bits in size. The STID field 508 contains the STID associated with the mobile station transmitting the abnormal power down signaling header 500 . The STID field 510 indicates a valid STID offset assigned to a mobile station when the same STID is assigned to more than one mobile station. If the STID is uniquely assigned to one mobile station, that mobile station sets the STID valid offset field 510 to a value of '0'. The size of the STID valid offset field 510 is 3 bits.
The emergency type field 512 indicates the type of emergency transmitted together with the abnormal power-down signaling header. The size of the emergency field 512 is 1 bit. For example, the emergency type field 512 is set to the value '0b0' if the emergency type is a power outage. The EC field 514 indicates whether the abnormal power-down signaling header 500 is protected and has a size of 1 bit. For example, if the abnormal power-down signaling header 500 is protected, the EC field 514 contains the value '1'. If the abnormal power-down signaling header 500 is not protected, the EC field 514 includes the value '0'. Accordingly, based on the value set in the EC field 9514, the receiving station 104 determines whether the abnormal power-down signaling header 500 is protected or unprotected.
The counter field 516 includes a counter value calculated for the abnormal power-down signaling header 500 . The size of the counter field 516 is 3 bits. The CMAC field 518 contains the CMAC value calculated for the abnormal power-down signaling header 500 and has a size of 16 bits. The abnormal power-down signaling header 500 may not include the counter field 516 and the CMAC field 518 and it includes a reserved field of 19 bits or 3 bits when the abnormal power-down signaling header is not protected. it will be understood
5B shows another exemplary format of a protected abnormal power-down signaling header 550 according to another embodiment. It will be understood that the abnormal power-down signaling header 550 of FIG. 5B is the same as the abnormal power-down signaling header 500 of FIG. 5A except that the abnormal power-down signaling header 550 does not include the EC field 514 . will be able In the abnormal power-down signaling header 550, the length field 506 is set to indicate whether the abnormal power-down signaling header 550 is protected or not. For example, if the abnormal power-down signaling header 550 is protected, the FID field is set to a value of '0b0100'.
5C illustrates another exemplary format of a protected abnormal power-down signaling header 560, according to another embodiment. In particular, FIG. 5C illustrates an abnormal power-down signaling header 560 according to the IEEE 802.16p system. Abnormal power-down signaling header 560 is HT field 561, EC field 562, type field 563, extended type field 564, CID field 565, emergency type field 566, CMAC indicator field 567 , CMAC value field 568 , counter field 569 , reservation field 570 , and header check sequence field 571 .
The CMAC indicator field 567 indicates whether the abnormal power-down signaling header 560 is protected. For example, if the abnormal power-down signaling header is protected, the CMAC indicator field 567 is set to the value '1'. Optionally, if the abnormal power-down signaling header 560 is not protected, the CMAC indicator field is set to the value '0'. The CMAC field 568 contains the CMAC value calculated for the abnormal power-down signaling header 560 and has a size of 16 bits. The counter field 569 includes a counter value calculated for the abnormal power-down signaling header 560 . The size of the counter field 569 is 2 bits. It will be appreciated that the abnormal power-down signaling header 560 does not include the counter field 569 and the CMAC field 568 when the CMAC indicator field 567 is set to a value of '0'. Also, when the CMAC indicator field 567 is set to a value of '0', an 18-bit reserved field 571 is included in the abnormal power-down signaling header 560 . Since the other fields 561 to 566 and 571 are well known to those skilled in the art, descriptions thereof are omitted here.
5D illustrates another exemplary format of a protected abnormal power-down signaling header 575 according to another embodiment. The abnormal power-down signaling header 575 of FIG. 5B is the same as the abnormal power-down signaling header 560 of FIG. 5C except that the abnormal power-down signaling header 575 does not include the extended type field 564. that can be understood In the abnormal power-down signaling header 575 , the type field 563 is used to indicate the same type as the M2M abnormal power-down signaling header 575 . Removal of the extended type field 564 means that the transmitting station 102 contains the 3 least significant bits of the counter value in the abnormal power-down signaling header 575 as opposed to the 2 least significant bits in the abnormal power-down signaling header 560. It would be understandable to make it possible.
5E shows another exemplary format of a protected abnormal power-down signaling header 585, according to another embodiment. The abnormal power-down signaling header 585 of FIG. 5E is the same as the abnormal power-down signaling header 560 of FIG. 5C except that the abnormal power-down signaling header 585 does not include the extended counter field 569. that can be understood
It may be understood from FIGS. 5A to 5E that fields are added to the abnormal power-down signaling header in such a way that the total size of the abnormal power-down signaling header does not exceed 6 bytes. This facilitates the sending station 102 (eg, M2M device) to securely transmit the abnormal signaling header instead of the bandwidth request signaling header in the allocated resource (of about 6 bytes) based on the bandwidth request procedure. does it
6 is a flow diagram 600 of a process illustrating an exemplary method of processing a signaling header received from a transmitting station 102, according to one embodiment. In step 602 , a signaling header is received from the transmitting station 102 . In step 604, whether or not the signaling header is protected is determined based on an indicator set in the signaling header. For example, if the flow identifier field of the signaling header is used to indicate that the signaling header is protected, it is determined whether the signaling header is protected or not based on the value set in the flow identifier field. Optionally, if the EC field of the signaling header is used to indicate that the signaling header is protected, it is determined whether the signaling header is protected or not based on a value set in the EC field. If the indicator indicates that the signaling header is not protected, the signaling header is directly processed in step 606 .
If the indicator indicates that the signaling header is protected, information in the length field of the signaling header is read in step 608 . If the signaling header is a signaling header of variable length, the receiving station 104 reads the length field. In step 610, the counter value in the counter field of the signaling header is read. In step 612, it is determined whether the signaling header is valid based on the counter value. In other words, in step 612 , it is determined whether any signaling header having the same counter value has been previously received. If the signaling header is not valid, the signaling header is discarded in step 614 .
In step 616, a frame number of a frame in which a signaling header is received is determined. Each frame is assigned a frame number. When one MAC PDU containing the signaling header is received from the transmitting station 102, the receiving station 104 determines the frame in which the signaling header is transmitted and then determines the frame number associated with the frame. In step 618, a CMAC value for the CMAC value for the signaling header is generated based on the frame number and the counter value. In step 620, it is determined whether the generated CMAC value matches the CMAC value in the CMAC field of the received signaling header. If the determination result is true, the signaling header is processed in step 622 . Otherwise, in step 624, the signaling header is discarded.
7A is a process flow diagram illustrating an exemplary method for refreshing security keys associated with a first type of control information and a second type of control information, according to an embodiment. In step 702, it is determined whether a predetermined condition for refreshing the security keys derived for the first type of information and the second type of information is satisfied. In one embodiment, the predetermined condition is considered satisfied when the 'n1' bits of the counter value corresponding to the rollover counter of the frame concatenated with the frame number reach the threshold. In this embodiment, the threshold may be equal to 2 (n1 + n2) frames, where 'n2' is the number of bits representing the frame number. In another embodiment, the predetermined condition described above is considered satisfied when the rollover counter of the frame associated with the frame number reaches a threshold. In this embodiment, the threshold may be equal to 2 (n+n2) frames, where 'n' represents the rollover counter of the frame and 'n2' is the number of bits representing the frame number. In another embodiment, the predetermined condition described above is considered to be satisfied when the frame number reaches a threshold. In this embodiment, the threshold is equal to 2n2 frames, where 'n2' is the number of bits representing the frame number.
If it is determined that the above predetermined condition is satisfied, in step 704, a new authentication key relationship is established between the transmitting station 102 and the receiving station 104. In step 706, a new pre-key is generated based on a new authentication key context. In step 708, one or more new security keys are derived to secure the first and second types of control information using the pre-key. In step 710, the counter value is set to a value of '0' when deriving new security keys, and increases by a value of '1' after each frame rollover.
7B is a process flow diagram illustrating an exemplary method for refreshing security keys associated with a first type of control information and a second type of control information, according to another embodiment. In step 752, it is determined whether the predetermined condition for refreshing the security keys derived for the first type of control information and the second type of control information is satisfied. If it is determined that the above predetermined condition is satisfied, in step 754, the authentication key counter value related to the authentication key context is increased by the value '1'. The transmitting station keeps an authentication key counter to track whether or not the above predetermined condition is satisfied. This eliminates the need to perform step 702 of FIG. 7A. In step 756, when the authentication key counter associated with the authentication key is incremented, a new pre-key is generated from the new authentication key context. In step 758, one or more security keys are derived to secure the first type and the second type of control information using the new pre-key. In step 760, the counter value is set to a value of '0' when deriving new security keys, and is increased by a value of '1' after each frame rollover.
7C is a process flow diagram 770 illustrating an exemplary method for refreshing security keys associated with a first type of control information and a second type of control information, according to another embodiment. In step 772, it is determined whether the above-described predetermined condition for refreshing the derived security keys for the second type of information (eg, signaling headers) is satisfied. If it is determined that the predetermined condition is satisfied, in step 774, the security key counter related to the security keys derived for the second type of control information is incremented by a value of '1'. The transmitting station 102 maintains a security key counter to track whether the above-described predetermined condition is satisfied. This eliminates the need to perform step 702 of FIG. 7A. In step 776, when the value of the security tee counter associated with the one or more security keys is increased by the value '1', the one or more new security keys use the existing pre-key to secure the second type of control information. induced for Accordingly, the transmitting station 102 does not need to derive new security keys for both types of control information when the security key counter for the second type of control information is incremented by the value '1'. For those skilled in the art, the transmitting station 102 maintains a separate security key counter for the first type of control information and, when the security key counter is incremented, from the pre-key to obtain the first type of control information. It is conceivable that new security keys can be derived. In step 778, the counter value is set to a value of '0' when deriving new security keys, and is incremented by a value of '1' after each frame rollover.
8 is a process flow diagram 800 of a detailed method for securing a signaling header according to an optional embodiment. In step 802, security information for securing a signaling header to be transmitted to the receiving station 102 is generated. Security information is generated as follows;
Security Information = Security Key ID = Dot16KDF (Security Key, Security Key Count | Mobile Station Identifier | Base Station Identifier | Frame Number | Zero Padding (Optional) | Security Key ID, n).
In one embodiment, the value of 'n' is 64 bits. The security key count is updated every frame rollover, and the security key is refreshed before the security key reaches its maximum.
In step 804, security information is added to the content of the signaling header. In step 806, a cyclic redundancy check (CRC) value is generated based on the content of the signaling header and security information. Since the process of generating the CRC value is well known to those skilled in the art, a description thereof is omitted herein. In step 808, CRC information is added to the original content of the signaling header. The EC field or the FID field of the signaling header may be used to indicate whether the signaling header is protected. In step 810 , a signaling header having CRD information is transmitted to the receiving station 104 .
9 is a process flow diagram 900 of a detailed method for processing a protected signaling header received from a transmitting station, according to an alternative embodiment. In step 902, a signaling header is received from the transmitting station 102. In step 904, it is determined whether the signaling header is protected or not based on the flow identifier/EC field in the signaling header. If the flow identifier/EC field indicates that the signaling header is not protected, in step 906, the signaling header is directly processed.
If the flow identifier indicates that the signaling header is protected, at step 908 , security information is generated. In step 910, security information is added to the content of the signaling header. In step 912, a CRC value is generated using security information to which the content of the signaling header is added. In step 914, it is determined whether the generated CRC matches a CRC value in the protected signaling header. As a result, if they match, in step 916, the content of the protected signaling header is processed. However, if they do not match, the signaling header is discarded in step 918 .
10 is a block diagram of a transmitting station 102 illustrating various components for implementing embodiments of the present invention. In FIG. 10 , the transmitting station 102 includes a processor 1002 , a memory 1004 , a read-only memory (ROM) 1006 , a transmitter 1008 , a bus 1010 , a display device 1012 , and an input device ( 1014 ), and a cursor control unit 1016 .
Processor 1002 as used herein is a microprocessor, microcontroller, complex instruction set computing microprocessor, reduced instruction set computing microprocessor, very long instruction word (VLIW) type microprocessor, It is intended to encompass any type of arithmetic circuitry, such as, but not limited to, an explicitly parallel instruction computing (EPIC) type microprocessor, a graphics processor, a digital signal processor (DSP), or any kind of processing circuitry. It is intended The processor 1002 may also include embedded controllers, such as general purpose or programmable logic devices or arrays, application specific circuits (ASICs), single-chip computers, smart cards, and the like.
Memory 1004 may be both volatile and non-volatile memory. The memory 1004 may include a control information protection module 106 for securing the first type and the second type of control information according to any one or more of the above-described embodiments. Various forms of computer-readable storage media may be stored on and accessed from memory elements. Memory elements include read-only memory (ROM), random access memory (RAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), hard drives, and compact disks. may include any form of suitable memory device(s) for storing data and machine readable instructions, such as a removable media drive, digital video disk, diskette, magnetic tape cartridge, memory card, memory stick, etc. have.
Various embodiments of the present invention may be implemented in conjunction with modules comprising functions, procedures, data structures, and application programs for task execution, definition of abstract data types, or low-level hardware environments. The control information protection module 106 may be stored in the form of machine-readable instructions in any of the above-described storage media and may be executable by the processor 1002 . For example, a computer program may include machine readable instructions capable of obtaining first and second types of control information in accordance with the disclosed embodiments of the present invention and its teachings. In one embodiment, the program may be included on a CD-ROM and loaded from the CD-ROM to a hard drive in non-volatile memory.
The transceiver 1008 may be capable of securely transmitting first and second types of control information to the receiving station 104 . The bus 1010 serves as an interconnection between the various components of the transmitting station 102 . Components such as the display device 1012 , the input device 1014 , and the cursor control device 1016 are well known to those skilled in the art, and thus descriptions thereof will be omitted herein.
11 is a block diagram of a receiving station 104 showing various components for implementing embodiments of the present invention. In FIG. 11 , a receiving station 104 includes a processor 1102 , a memory 1104 , a read-only memory (ROM) 1106 , a receiver 1108 , a bus 1110 , a display device 1112 , and an input device ( 1114 ), and a cursor control device 1116 .
As used herein, processor 1102 is a microprocessor, microcontroller, integrated instruction set computing microprocessor, reduced instruction set computing microprocessor, VLIW-type microprocessor, EPIC-type microprocessor, graphics processor, digital signal processor (DSP). , or any type of arithmetic circuit, such as, but not limited to, processing circuitry of any kind. The processor 1002 may also include embedded controllers such as general purpose or programmable logic devices or arrays, application specific circuits (ASICs), single-chip computers, smart cards, and the like.
Memory 1104 and read-only memory (ROM) 1106 may be volatile and non-volatile memory. The memory 1104 may include a control information protection module 108 for securing the first type and the second type of control information according to any one or more of the above-described embodiments. Various forms of computer-readable storage media may be stored on and accessed from memory elements. Memory elements include read-only memory (ROM), random access memory (RAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), hard drives, and compact disks. may include any form of suitable memory device(s) for storing data and machine readable instructions, such as a removable media drive, digital video disk, diskette, magnetic tape cartridge, memory card, memory stick, etc. have.
Various embodiments of the present invention may be implemented in conjunction with modules comprising functions, procedures, data structures, and application programs for task execution, definition of abstract data types, or low-level hardware environments. The control information protection module 106 may be stored in the form of machine-readable instructions in any of the above-described storage media and may be executable by the processor 1102 . For example, a computer program may include machine readable instructions capable of obtaining first and second types of control information in accordance with the disclosed embodiments of the present invention and its teachings. In one embodiment, the program may be included on a CD-ROM and loaded from the CD-ROM to a hard drive in non-volatile memory.
The receiver 1108 may be capable of transmitting the first and second types of control information to the receiving station 104 in a secure manner. The bus 1110 serves as an interconnection between the various components of the transmitting station 102 . Components such as the display device 1112 , the input device 1114 , and the cursor control device 1116 are well known to those skilled in the art, and thus descriptions thereof will be omitted herein.
Although the above-described embodiments have been described with reference to the IEEE 802.16 system and in particular the IEEE 802.16.1 system, for those skilled in the art, the reference to the IEEE 802.16.1 systems is for illustrative purposes only, and various embodiments disclosed herein may not be used for versatility. It will be appreciated that it is applicable to other cellular communications without loss.
Although the present invention has been described above with reference to specific exemplary embodiments, it will be appreciated that various modifications and changes may be made to these embodiments without departing from the broader spirit and scope of the various embodiments. It will be obvious to an expert. In addition, the various devices, modules, etc. described herein may include a hardware circuit, for example, a logic circuit made of a complementary metal oxide (CMOS) type semiconductor, firmware, software and/or hardware, a combination of firmware, and/or It may be implemented and operated using software embodied in a machine-readable medium. For example, various electrical configurations and methods may be implemented using transistors, logic gates, and electrical circuits such as application specific integrated circuits (ASICs).
20 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2016153123A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| KR20070103707A | Cites | Republic of Korea | Search report |
| Yi-Ting Lin, etc., “Abnormal Power Down Indication Through Quick Access Procedure”, IEEE C80216p-11/0236(2011.09.09.) 1부.* | Non-patent | – | Search report |
9 members in 5 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 4551CHE2011 | India | – | |
| 4551CH2011 | India | A | |
| 2012011349 | Republic of Korea | W |
Members9
| Document | Office | Kind | |
|---|---|---|---|
| WO2013095074A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN104012134A | China | A | |
| KR20140116144AThis record | Republic of Korea | A | |
| US2014372758A1 | United States of America | A1 | |
| JP2015503307A | Japan | A | |
| US9992197B2 | United States of America | B2 | |
| CN104012134B | China | B | |
| KR102059079B1 | Republic of Korea | B1 | |
| JP6656617B2 | Japan | B2 |
7 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Changes to party contact information recordedST27 STATUS EVENT CODE: A-5-5-R10-R18-OTH-X000 (AS PROVIDED BY THE NATIONAL OFFICE)R18 | R18 | |
| Changes to party contact information recordedST27 STATUS EVENT CODE: A-5-5-R10-R18-OTH-X000 (AS PROVIDED BY THE NATIONAL OFFICE)R18 | R18 | |
| Changes to party contact information recordedST27 STATUS EVENT CODE: A-5-5-R10-R18-OTH-X000 (AS PROVIDED BY THE NATIONAL OFFICE)R18 | R18 | |
| Written decision to grantGRNT | GRNT | |
| Decision to grant or registration of patent rightE701 | E701 | |
| Notification of reason for refusalE902 | E902 | |
| Request for examinationA201 | A201 |
Numbers
- Publication
- 10-2014-0116144
- Application
- 1020147020661
Titles4
- Korean
- 무선 네트워크 환경에서 제어정보의 보안통신을 위한 방법 및 시스템
- English
- METHOD AND SYSTEM FOR SECURED COMMUNICATION OF CONTROL INFORMATION IN A WIRELESS NETWORK ENVIRONMENT
- Unlabeled
- 무선 네트워크 환경에서 제어정보의 보안통신을 위한 방법 및 시스템 {METHOD AND SYSTEM FOR SECURED COMMUNICATION OF CONTROL INFORMATION IN A WIRELESS NETWORK ENVIRONMENT}
- Unlabeled
- METHOD AND SYSTEM FOR SECURED COMMUNICATION OF CONTROL INFORMATION IN A WIRELESS NETWORK ENVIRONMENT}
Classification
- CPC, 4
- H04W12/037
- H04L63/0876
- H04W12/04
- H04W12/02
- IPC, 2
- H04W12 08
- H04W28 06