Stateless access stratum security for cellular internet of things
Abstract
Aspects of security schemes (eg, integrity protection, encryption, or both) are described. The measurement of access layer security can be realized without the overhead associated with establishing and/or maintaining a cellular-device-per-cellular access layer security context at a cellular Internet of Things (CIoT) base station (C-BS). A gateway (eg, CIoT Serving Gateway Node (C-SGN)) may derive the first key. The first key may be known only to the C-SGN. The C-SGN may derive the second key from the first key and parameters unique to the C-BS. The C-SGN may also derive the third key from the second key and the identity of the cellular device. The C-SGN may send the second and third keys to the C-BS and the cellular device, respectively. Small data messages encrypted and/or integrity protected by the cellular device may be decrypted and/or verified by the C-BS.

Term
10.2 yearsto projected expiry
Projected expiry 14 December 2036, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
30 claims: 4 independent, 26 dependent
- 1통신의 방법으로서, 게이트웨이에서, 상기 게이트웨이에만 알려져 있는 제 1 키를 획득하는 단계;상기 게이트웨이에서, 상기 제 1 키 및 무선 액세스 네트워크 (RAN) 노드에 고유한 파라미터에 기초하는 제 2 키를 획득하는 단계;상기 게이트웨이에 의해, 상기 제 2 키를 상기 RAN 노드에 프로비져닝하는 단계;상기 게이트웨이에서, 상기 제 2 키 및 셀룰러 디바이스에 고유한 파라미터에 기초하여 제 3 키를 획득하는 단계;및 상기 게이트웨이에 의해, 상기 제 3 키를 상기 셀룰러 디바이스에 프로비져닝하는 단계를 포함하는, 통신의 방법.
- 2제 1 항에 있어서, 상기 게이트웨이는 셀룰러 사물 인터넷 서빙 게이트웨이 노드 (C-SGN) 인, 통신의 방법.
- 3제 1 항에 있어서, 상기 제 1 키는 어떤 다른 키로부터 획득되지 않고 및/또는 상기 게이트웨이에서 랜덤으로 생성되는, 통신의 방법.
- 4제 1 항에 있어서, 상기 RAN 노드는 셀룰러 사물 인터넷 (CIoT) 기지국 (C-BS) 또는 진화된 노드 B (eNodeB) 이고, 그리고 상기 RAN 노드에 고유한 상기 파라미터는 C-BS 아이덴티티 또는 eNodeB 아이덴티티인, 통신의 방법.
- 5제 1 항에 있어서, 상기 제 2 키는 비-액세스 계층 (NAS) 메시지에서 상기 RAN 노드에 프로비져닝되는, 통신의 방법.
- 6제 1 항에 있어서, 상기 제 3 키는 비-액세스 계층 (NAS) 메시지에서 상기 셀룰러 디바이스에 프로비져닝되는, 통신의 방법.
- 7제 6 항에 있어서, 상기 NAS 메시지는 보안 NAS 메시지인, 통신의 방법.
- 8제 1 항에 있어서, 상기 제 3 키는 상기 셀룰러 디바이스에 암호화된 정보 엘리먼트 (IE) 로서 프로비져닝되는, 통신의 방법.
- 9제 8 항에 있어서, 상기 IE 는 상기 IE 를 암호화는데 이용되는 알고리즘을 식별하는 알고리즘 식별자를 포함하는, 통신의 방법.
- 10통신 장치로서, 통신 네트워크의 노드들과 통신하기 위한 통신 인터페이스;상기 통신 인터페이스에 커플링된 프로세싱 회로를 포함하고, 상기 프로세싱 회로는, 상기 통신 장치에만 알려져 있는 제 1 키를 획득하고;상기 제 1 키 및 무선 액세스 네트워크 (RAN) 노드에 고유한 파라미터에 기초하는 제 2 키를 획득하고;상기 제 2 키를 상기 RAN 노드에 프로비져닝하고;상기 제 2 키 및 셀룰러 디바이스에 고유한 파라미터에 기초하여 제 3 키를 획득하고;그리고 상기 제 3 키를 상기 셀룰러 디바이스에 프로비져닝하도록 적응된, 통신 장치.
- 11제 10 항에 있어서, 상기 프로세싱 회로는, 상기 제 1 키를 어떤 다른 키로부터 획득할 수 없을 시에 상기 제 1 키를 획득하고;및/또는 상기 통신 장치에서 상기 제 1 키를 랜덤으로 생성하는 것에 의해 상기 제 1 키를 획득하도록 추가로 적응되는, 통신 장치.
- 12제 10 항에 있어서, 상기 프로세싱 회로는, 비-액세스 계층 (NAS) 메시지에서 상기 제 2 키를 상기 RAN 노드에 프로비져닝하도록 추가로 적응되는, 통신 장치.
- 13제 10 항에 있어서, 상기 프로세싱 회로는, 비-액세스 계층 (NAS) 메시지에서 상기 제 3 키를 상기 셀룰러 디바이스에 프로비져닝하도록 추가로 적응되는, 통신 장치.
- 14제 10 항에 있어서, 상기 프로세싱 회로는, 암호화된 정보 엘리먼트 (IE) 에서 상기 제 3 키를 상기 셀룰러 디바이스에 프로비져닝하도록 추가로 적응되는, 통신 장치.
- 15장치로서, 통신 네트워크의 노드들과 통신하기 위한 통신 인터페이스;상기 통신 인터페이스에 커플링된 프로세싱 회로를 포함하고, 상기 프로세싱 회로는, 제 1 키 및 상기 장치에 고유한 파라미터에 기초하는 제 2 키를 획득하고;디바이스 아이덴티티 및 제 1 무결성 보호 값을 포함하는 스몰 (small) 데이터 메시지를 획득하고;상기 제 2 키 및 상기 디바이스 아이덴티티에 기초하는 제 3 키를 획득하고;상기 제 3 키에 기초하는 제 2 무결성 보호 값을 획득하고;상기 제 1 무결성 보호 값과 상기 제 2 무결성 보호 값을 비교하고;상기 제 1 무결성 보호 값이 상기 제 2 무결성 보호 값과 동일하지 않다는 것을 비교 결과가 표시하면 상기 스몰 데이터 메시지를 폐기하고;그리고 상기 제 1 무결성 보호 값이 상기 제 2 무결성 보호 값과 동일하다는 것을 상기 비교 결과가 표시하면 상기 스몰 데이터 메시지를 게이트웨이로 전송하도록 적응된, 장치.
- 16제 15 항에 있어서, 상기 제 1 무결성 보호 값 및 상기 제 2 무결성 보호 값은 적어도 하나의 논스 (nonce) 및/또는 타임 스탬프를 이용하여 획득되고, 그리고 상기 스몰 데이터 메시지를 획득하기 이전에, 상기 프로세싱 회로는, 상기 디바이스 아이덴티티에 의해 식별된 디바이스에 제 1 논스 및/또는 상기 타임 스탬프를 프로비져닝하고;및/또는 상기 디바이스로부터 제 2 논스를 획득하도록 추가로 적응되는, 장치.
- 17제 16 항에 있어서, 상기 프로세싱 회로는, 랜덤 액세스 프로시저 동안에 상기 제 1 논스 및/또는 상기 타임 스탬프를 프로비져닝하고 그리고 상기 제 2 논스를 획득하도록 추가로 적응되는, 장치.
- 18제 15 항에 있어서, 상기 스몰 데이터 메시지는 상기 제 3 키로 암호화되고, 그리고 상기 프로세싱 회로는, 상기 제 3 키를 이용하여 상기 스몰 데이터 메시지를 해독하도록 추가로 적응되는, 장치.
- 19제 15 항에 있어서, 상기 스몰 데이터 메시지를 획득하기 이전에, 상기 프로세싱 회로는, 트래픽 부하 값을 모니터링하고;상기 트래픽 부하 값이 미리결정된 임계값을 초과한다는 것을 검출하고;그리고 상기 트래픽 부하 값이 상기 미리결정된 임계값을 초과한다는 것을 검출하는 것에 응답하여, 상기 디바이스 아이덴티티에 의해 식별되는 디바이스로, 상기 장치로 전송된 다음의 하나 이상의 메시지들에 상기 제 1 무결성 보호 값을 포함시킬 것을 상기 디바이스에 요청하는 메시지를 전송하도록 추가로 적응되는, 장치.
- 20제 19 항에 있어서, 네트워크가 상기 미리결정된 임계값을 구성하는, 장치.
- 21제 15 항에 있어서, 상기 프로세싱 회로는, 게이트웨이로부터 상기 제 2 키를 획득하도록 추가로 적응되는, 장치.
- 22제 21 항에 있어서, 상기 게이트웨이는 셀룰러 사물 인터넷 서빙 게이트웨이 노드 (C-SGN) 인, 장치.
- 23제 15 항에 있어서, 상기 장치는 셀룰러 사물 인터넷 (CIoT) 기지국 (C-BS) 또는 진화된 노드 B (eNodeB) 이고, 그리고 장치에 고유한 상기 파라미터는 C-BS 아이덴티티 또는 eNodeB 아이덴티티인, 장치.
- 24제 15 항에 있어서, 상기 프로세싱 회로는, 적어도 하나의 논스 및/또는 타임 스탬프를 이용하여 상기 제 1 무결성 보호 값 및 상기 제 2 무결성 보호 값을 획득하도록 추가로 적응되는, 장치.
- 25제 15 항에 있어서, 상기 프로세싱 회로는, 디바이스와 초기 어태치 프로시저 동안에 액세스 계층 보안 구성을 협상하도록 추가로 적응되고, 상기 액세스 계층 보안 구성은, 보안 없이, 무결성 보호로, 암호화로, 무결성 보호 및 암호화로, 및/또는 온디맨드 무결성 보호로 스몰 데이터 메시지들이 상기 디바이스로부터 전송되는지 여부를 특정하고, 무결성 보호 및 암호화는 상기 제 3 키를 이용하여 수행되는, 장치.
- 26장치로서, 통신 네트워크의 노드들과 통신하기 위한 통신 인터페이스;상기 통신 인터페이스에 커플링된 프로세싱 회로를 포함하고, 상기 프로세싱 회로는, 제 2 키 및 상기 장치에 고유한 파라미터에 기초하는 제 3 키를 획득하고;액세스 계층 보안 구성을 협상하고;상기 제 3 키를 이용하여 상기 액세스 계층 보안 구성에 기초한 스몰 데이터 메시지를 보호하고;그리고 상기 제 3 키를 이용하여 보호된 상기 스몰 데이터 메시지를 전송하도록 적응된, 장치.
- 27제 26 항에 있어서, 상기 프로세싱 회로는, RAN 노드와 상기 액세스 계층 보안 구성을 협상하고;그리고 상기 제 3 키를 이용하여 보호된 상기 스몰 데이터 메시지를 상기 RAN 노드로 전송하도록 추가로 적응되는, 장치.
- 28제 26 항에 있어서, 상기 프로세싱 회로는, 게이트웨이로부터 상기 제 3 키를 획득하도록 추가로 적응되고, 상기 제 2 키는 제 1 키 및 RAN 노드에 고유한 파라미터에 기초하고, 그리고 상기 제 1 키는 상기 게이트웨이에만 알려져 있는, 장치.
- 29제 26 항에 있어서, 상기 프로세싱 회로는, 초기 어태치 프로시저 동안에 상기 액세스 계층 보안 구성을 협상하도록 추가로 적응되는, 장치.
- 30제 26 항에 있어서, 상기 프로세싱 회로는, 디바이스와 초기 어태치 프로시저 동안에 액세스 계층 보안 구성을 협상하도록 추가로 적응되고, 상기 액세스 계층 보안 구성은, 보안 없이, 무결성 보호로, 암호화로, 무결성 보호 및 암호화로, 및/또는 온디맨드 무결성 보호로 스몰 데이터 메시지들이 상기 디바이스로부터 전송되는지 여부를 특정하고, 무결성 보호 및 암호화는 상기 제 3 키를 이용하여 수행되는, 장치.
Independent claims30
219 paragraphs, as filed
Stateless Access Layer Security for Cellular Internet of Things
<b>CROSS-REFERENCE TO RELATED APPLICATIONS</b>
This application claims priority to Provisional Application No. 62/387,499, filed with the U.S. Patent and Trademark Office on December 23, 2015, and Regular Application No. 15/199,924, filed with the U.S. Patent and Trademark Office on June 30, 2016. Claiming the benefit, the entire contents of which are incorporated herein by reference for all applicable purposes and as if fully set forth hereinbelow.
Aspects of this disclosure relate generally to wireless communication, and more particularly, but not exclusively, to techniques for achieving access layer security in a stateless manner for cellular Internet of Things (CIoT) messages. .
The International Telecommunications Union (ITU) is an infrastructure that connects physical things and virtual things based on interoperability information and communication technologies, and the Internet of Things (IoT) explain As used herein, and in the context of IoT, a "thing" is a physical world (eg, a physical thing) or information world (eg, a virtual thing) capable of being identified and integrated into communication networks. ) is an object in Recommendation ITU-T Y.2060. Wireless communication networks, such as wireless wide area networks (WWAN) and/or wireless local-area networks (wireless LAN), are one of the information and communication technologies that are interoperable with IoT devices.
According to the Long Term Evolution (LTE) paradigm, two modes are defined for wireless access: connected mode; and idle mode. In connected mode, the cellular device is transmitting and receiving data. A user equipment (UE) context ("UE context") or "radio resource control (RRC) connection" is established in the connected mode. For a UE context, a radio bearer is established to relay data between the cellular device and the core network (eg, evolved packet core (EPC)). A radio bearer, referred to as an evolved radio access bearer (eRAB), includes a radio bearer portion and an S1 bearer portion. A radio bearer is established between the cellular device and the evolved Node B (eNodeB) over the LTE-Uu reference point. The S1 bearer is established between the eNodeB and the Serving Gateway (S-GW) on the S1 reference point. A security context is established to secure the communications.
In idle mode, the eRAB bearer (radio bearer and S1 bearer) is released and the security context is dropped. In this way, unnecessary radio resources are released. Radio bearers and security contexts are established and maintained only when there is data to be transmitted/received (ie in connected mode). When the cellular device wakes up (eg, from idle mode), the eNodeB establishes a new UE context and security context via a service request to the Mobility Management Entity (MME) and enters the connected mode. When the cellular device enters the idle state, the eNodeB removes the UE context (eg, eRAB bearer) and security context and enters the idle mode.
LTE mobility management and session management procedures support cellular Internet of Things (CIoT) devices and their CIoT devices, for example in terms of energy consumption, because the signaling delay to establish the UE context will extend the CIoT device wakeup period. It may incur significant overhead for the network. The overhead is associated with added latency, which is also undesirable.
To reduce overhead and latency, different requirements for mobility management and security functions of the CIoT have been proposed compared to the requirements for other communications through the cellular device. These different requirements may reduce overhead related to mobility management and security functions of IoT devices operating in a cellular network. However, different requirements leave radio access network (RAN) nodes and core network nodes open to undesirable vulnerabilities such as, for example, denial of service (DoS) and/or packet flooding attacks. may be Accordingly, it would be desirable to find ways to overcome or avoid these undesirable vulnerabilities without increasing overhead and latency.
<p>The following presents a simplified overview of some aspects of the disclosure in order to provide a basic understanding of such aspects. This summary is not an extensive overview of all contemplated features of the disclosure, and is intended to neither identify key or critical elements of all aspects of the disclosure nor delineate the scope of any or all aspects of the disclosure. does not Its sole purpose is to present various concepts of some aspects of the disclosure in a simplified form as a prelude to the more detailed description that is presented later.</p><p>In some implementations, the method of communication may include deriving, at the gateway, a first key that may be known only to the gateway. The gateway may also derive a second key, which may be based on a first key and a parameter that may be unique to a node of a radio access network (RAN). The gateway may send the second key to the node of the RAN. The gateway may also derive a third key. The third key may be based on the second key and a parameter that may be unique to the cellular device. The gateway may then send the third key to the cellular device.</p><p>In some implementations, a communications apparatus may include a communications interface that may communicate with nodes of a communications network and processing circuitry that may be coupled to the communications interface. The processing circuitry may be constructed, adapted, and/or configured to derive a first key that may be known only to the communication device. The processing circuitry may also derive a second key, which may be based on the first key and a parameter that may be unique to a node of a radio access network (RAN). The processing circuitry may cause the communication apparatus to transmit the second key to a node of the RAN. The processing circuitry may also derive a third key, which may be based on the second key and a parameter unique to the cellular device. The processing circuitry may cause the communication apparatus to transmit the third key to the cellular device.</p><p>In some implementations, the method of integrity protected communication may include receiving, at a radio access network (RAN) node, a second key. The second key may be based on the first key and a parameter unique to the RAN node. The method may also include receiving, at the RAN node, a small data message comprising a device identity and a first integrity protection value (eg, a value given in a message authentication code (MAC) or token). may be The RAN node may derive a third key, which may be based on the second key and the device identity. The RAN node may then derive the second integrity protection value using the third key. A comparison of the first integrity protection value and the second integrity protection value may be performed. If the result of the comparison indicates that the first and second integrity protection values are not equal, the RAN node may discard the small data message. However, if the result of the comparison indicates that the first and second integrity protection values are equal, the RAN node may send a small data message to the gateway.</p><p>In some implementations, a method of stateless access layer protection may be practiced. The method may include receiving a second key at a radio access network (RAN) node. The second key may be based on the first key and a parameter unique to the RAN node. The RAN node may receive an encrypted small data message containing the device identity. The small data message may be encrypted with a third key. The RAN node may derive a third key, which may be based on the second key and the device identity. The RAN node may then decrypt the small data message using the third key.</p><p>In some implementations, another method of stateless access layer security may be practiced. The method may include receiving a second key at a radio access network (RAN) node. The second key may be based on the first key and a parameter unique to the RAN node. The RAN node may receive a small data message containing the device identity. The small data message may be encrypted using a third key and the small data message may include an integrity protection value, where integrity protection is implemented using the third key. The RAN node may derive a third key, which may be based on the second key and the device identity. The small data message may be decrypted at the RAN node using the third key. Additionally, the integrity protection value may be verified at the RAN node using a third key.</p><p>In some implementations, a method of on-demand integrity protection may be provided. The method may include monitoring, by a radio access network (RAN) node, a traffic load value. The RAN node may detect that the traffic load value exceeds a predetermined threshold. The RAN node may, in response to detecting that the traffic load value exceeds a predetermined threshold, send a message to the cellular device. The message may request the cellular device to include the token in one or more messages sent to the RAN node.</p><p>In some implementations, an apparatus, such as a communications apparatus, may include a communications interface for communicating with nodes of a communications network and processing circuitry coupled to the communications interface. The device may be used for integrity protected communications. In some implementations, the processing circuit may be devised, adapted, and/or configured to receive the second key. The second key may be based on the first key and device-specific parameters. The processing circuitry may also receive the small data message including the device identity and the first integrity protection value. The processing circuit may derive a third key, which may be based on the second key and the device identity. The processing circuit may then derive a second integrity protection value using the third key. The comparison of the first integrity protection value and the second integrity protection value may be performed in the processing circuit. If the result of the comparison indicates that the first and second integrity protection values are not equal, the processing circuitry may cause the apparatus to discard the small data message. However, if the result of the comparison indicates that the first and second integrity protection values are equal, the processing circuitry may cause the apparatus to send a small data message to the gateway.</p><p>In some implementations, an apparatus, such as a communications apparatus, may include a communications interface for communicating with nodes of a communications network and processing circuitry coupled to the communications interface. The device may be used to enforce stateless access layer security. In some implementations, the processing circuit may be devised, adapted, and/or configured to receive the second key. The second key may be based on the first key and device-specific parameters. The processing circuitry may also receive the encrypted small data message including the device identity. In some implementations, the small data message may be encrypted with a third key. The processing circuit may derive the third key. The third key may be based on the second key and the device identity. The processing circuit may then decrypt the small data message using the third key.</p><p>In some implementations, an apparatus, such as a communications apparatus, may include a communications interface for communicating with nodes of a communications network and processing circuitry coupled to the communications interface. The device may also be used to enforce stateless access layer security. In some implementations, the processing circuit may be devised, adapted, and/or configured to receive the second key. The second key may be based on the first key and device-specific parameters. The processing circuitry may also receive the small data message including the device identity. The small data message may be encrypted with the third key and the small data message may include an integrity protection value derived using the third key. The processing circuit may derive a third key, which may be based on the second key and the device identity. The processing circuit may decrypt the small data message using the third key. The processing circuit may also verify the integrity protection value using the third key.</p><p>In some implementations, an apparatus, such as a communications apparatus, may include a communications interface for communicating with nodes of a communications network and processing circuitry coupled to the communications interface. The device may be used for on-demand integrity protected communications. In some implementations, the processing circuit may be designed, adapted, and/or configured to monitor a traffic load value. The processing circuit may detect that the traffic load value exceeds a predetermined threshold. The processing circuitry then causes the apparatus to, in response to detecting that the traffic load value exceeds a predetermined threshold, a message requesting the cellular device to include the token in the next one or more messages sent to the apparatus. It can also be sent to a cellular device.</p><p>In some implementations, the method of communication may include receiving, at the cellular device, a third key. The third key may be based on the second key and the identity of the cellular device, and the second key may be based on the first key and the radio access network (RAN) node identity. The method may further include configuring and/or negotiating a security protocol during the initial attach procedure. The security protocol may determine whether a cellular device may send small data messages without security, with integrity protection, with encryption, with integrity protection and encryption, and/or with integrity protection on demand. In some implementations, integrity protection and encryption may be based on a third key.</p><p>In some implementations, an apparatus, such as a communications apparatus, may include a communications interface for communicating with nodes of a communications network and processing circuitry coupled to the communications interface. In some implementations, the processing circuit may be devised, adapted, and/or configured to receive a third key. The third key may be based on the second key and the identity of the device. The second key may be based on the first key and a radio access network (RAN) node identity. The processing circuitry may be further designed, adapted, and/or configured to configure and/or negotiate a security protocol during the initial attach procedure. In some implementations, the security protocol may determine whether a device sends small data messages without security, with integrity protection, with encryption, with integrity protection and encryption, and/or with integrity protection on demand. In some implementations, integrity protection and encryption may be based on a third key.</p><p>In some implementations, an apparatus, such as a communications apparatus, may include a communications interface for communicating with nodes of a communications network and processing circuitry coupled to the communications interface. The device may also be used to enforce stateless access layer security. In some implementations, the processing circuitry obtains a third key based on a second key and a parameter unique to the device, negotiates an access layer security configuration, and uses the third key to generate a small data message based on the access layer security configuration. and may be devised, adapted, and/or configured to transmit the protected small data message using the third key. In some implementations, the processing circuit may be further adapted to negotiate an access layer security configuration with the RAN node, and send the protected small data message to the RAN node using the third key. In some implementations, the processing circuitry may be further adapted to obtain a third key from the gateway, wherein the second key is based on the first key and a parameter unique to the RAN node, the first key being known only to the gateway . In some aspects, the processing circuitry may be further adapted to negotiate an access layer security configuration during an initial attach processor. In some aspects, the processing circuitry may be further adapted to negotiate an access layer security configuration during an initial attach procedure with a device, wherein the access layer security configuration is without security, with integrity protection, with encryption, integrity protection and encryption. Specifies whether small data messages are sent from the device raw and/or with integrity protection on demand, where integrity protection and encryption are performed using a third key.</p>
Various features, nature, and advantages may become apparent from the detailed description set forth below when taken in conjunction with the drawings in which like reference numerals correspondingly identify throughout. 1 is a diagram illustrating an example of a communication network in which aspects of the present disclosure may find application. 2 is a diagram illustrating another example of a communication network in which aspects of the present disclosure may find application. 3 is a diagram illustrating another example of a communication network in which aspects of the present disclosure may find application. 4 is a flow diagram illustrating an example of an access layer security key derivation and provisioning process in accordance with some aspects of the present disclosure. 5 is a call flow diagram illustrating an example of an associated attach procedure under a cellular Internet of Things (CIoT) in accordance with some aspects of the present disclosure. 6 is a block diagram illustrating an example of a hardware implementation of an apparatus that may support one or more of obtaining, provisioning, and using stateless access layer security and security keys in accordance with some aspects of the present disclosure. 7 is a flow diagram illustrating an example of a stateless access layer security process in accordance with some aspects of the present disclosure. 8 is a block diagram illustrating another example of a hardware implementation of an apparatus that may support one or more of obtaining, provisioning, and using stateless access layer security and security keys in accordance with one or more aspects of the present disclosure. 9 is a flow diagram illustrating another example of a stateless access layer security process in accordance with some aspects of the present disclosure. 10 is a flow diagram illustrating another example of a stateless access layer security process in accordance with some aspects of the present disclosure. 11 is a flow diagram illustrating another example of a stateless access layer security process in accordance with some aspects of the present disclosure. 12 is a flow diagram illustrating another example of a stateless access layer security process in accordance with some aspects of the present disclosure. 13 is a block diagram illustrating another example of a hardware implementation of an apparatus that may support one or more of obtaining, provisioning, and using stateless access layer security and security keys in accordance with one or more aspects of the present disclosure. 14 is a flow diagram illustrating another example of a stateless access layer security process in accordance with some aspects of the present disclosure. 15 is a schematic illustration of a wireless communication network including multiple communication entities as may appear in some aspects of the present disclosure.
IoT devices may include, but are not limited to, any piece of equipment having the capabilities of communication and optional capabilities of sensing, actuation, data capture, data storage, and/or data processing. A cellular device (eg, chip component, wireless device, mobile device, user equipment (UE), terminal) may interface with an IoT device. The interface may be achieved either directly (eg, the IoT device may be integral with the cellular device) or indirectly (eg, the IoT device may interface to the cellular device via a local area network such as Bluetooth). have. For ease of reference, references to a cellular device made herein will be understood to be references to a cellular device interfaced to an IoT device (ie, a CIoT device), unless otherwise specified.
As used herein, the word "obtain" may mean to derive, generate, compute, retrieve, receive, request, etc., obtain locally and/or It may also encompass remote acquisition. As used herein, the word "acquire" may encompass partially acquiring and/or completely acquiring.
As used herein, the phrase "on-the-fly" may describe an action that may occur dynamically, or as needed.
<b>survey</b>
When a UE transitions from an idle mode to a connected mode, the UE and the network supporting the UE traditionally have a UE security context (eg, per-cellular-device) access stratum. ; AS) establish the security context) and eRAB bearer. However, for cellular Internet of Things (CIoT) devices (eg, UEs interfaced with IoT devices), to reduce overhead, parties remove the establishment of an access layer (AS) security context. and the removal of mobility management. Removal of mobility management (eg, removing MME) requires a change in network architecture. Accordingly, the CIoT architecture introduces a new node referred to as a CIoT Serving Gateway Node (C-SGN). The C-SGN combines any necessary functionality remaining from the MME with the functionality of the Serving-Gateway (S-GW).
However, removing access layer (AS) security and mobility management for CIoT devices is not an option for radio access network (RAN) nodes (eg, eNBs) and core network nodes such as denial of service (DoS) and/or packet It may leave it open to undesirable vulnerabilities such as packet flooding attacks.
The present disclosure may, in some aspects, be accomplished without establishing and/or maintaining a cellular-device-per-access layer (AS) security context in a RAN node, such as in a cellular Internet of Things (CIoT) base station (C-BS). security schemes (eg, integrity protection, encryption, or both). At least some measures of access layer security may be realized without the overhead associated with establishing and/or maintaining a per-cellular-device access layer security context.
A gateway, eg, C-SGN, may obtain three keys. The first key may not be derived from any other key and the first key may be known only to the C-SGN. The first key may be randomly generated, for example, by C-SGN. The second key is generated using them (eg to be derived using them) based on the first key and parameters unique to the radio access network (RAN) node (eg the identity of the eNB of the C-BS) could be). The third key may be based on the second key and the identity of the cellular device. The identity may be, for example, SAE-Temporary Mobile Subscriber Identity (S-TMSI).
The C-SGN may provision (eg, provide, transmit, forward) the second key to the RAN node and the third key to the cellular device. The third key may be provisioned to the cellular device, for example, via a secure NAS message.
When a cellular device sends a CIoT message (referred to as a "small data message"), the cellular device may add integrity protection and/or encryption to the CIoT message. Integrity protection and/or encryption may be performed using a third key. As noted, the third key may be based on (eg, to be derived using, generated using) the second key and the identity of the device. The cellular device sends an integrity protected and/or encrypted CIoT message (eg, a small data message) to the RAN node.
In some implementations, a RAN node may not establish and/or maintain an access layer (AS) security context with a device (eg, UE security context). Establishing and/or maintaining an access layer security context requires the use of state tables and processing of data associated with the state tables; This overhead is undesirable. In some implementations, the RAN node may configure the device to enable/disable an access layer security configuration (eg, ciphering or integrity protection) for a CIoT message using RRC signaling. The access layer security configuration may also be referred to as an access layer security protection configuration. Access layer security configuration may be triggered by a C-SGN or by a RAN node upon a triggering event. A triggering event may include, for example, detection of an attack such as a denial of service attack or detection of a spoof (eg, fake, not genuine) packet injection.
When access layer security is triggered or used, as described in the examples presented herein, the RAN node acquires (e.g., derives, to generate) the second key (provisioned to the RAN node by the C-SGN) and the identity of the cellular device. The identity of the cellular device is included with every small data message obtained at the RAN node and the second key is independent of the identity of the cellular device; Accordingly, the security scheme is stateless in the sense that a state table is not required. Using the third key, the RAN node can verify, decrypt, or both small data based on the configuration. In one aspect, the RAN node may receive a small data message (integrity protected and/or encrypted) protected by a third key and thereafter (ie, the small data message obtains the third key from the C-SGN). It may also decrypt the small data message and/or verify the integrity protection of the small data message (to verify that it was sent from the acquiring device).
<b>Exemplary operating environment</b>
1 is a diagram illustrating an example of a communication network 100 in which aspects of the present disclosure may find application. A radio access network (RAN) may include one or more network access nodes (eg, a cellular Internet of Things (CIoT) base station (C-BS), eNodeB) (referred to as a RAN node 102 ). The techniques presented herein may be used to provision keys to a RAN node 102 (eg, C-BS, eNodeB), a cellular device 116 , 122 , and/or a CIoT device 136 , 142 . . Keys (eg, cryptographic keys, mathematically derived keys) may be used to integrity protect and/or encrypt small data messages. Integrity protection and/or encryption of small data messages advantageously adds access layer security and protection to the communication network 100 .
In the example of FIG. 1 , the RAN node 102 may include multiple antenna groups, one group including antennas 104 and 106 , another group including antennas 108 and 110 and , and an additional group includes antennas 112 and 114 . 1 , two antennas are shown for each antenna group; However, more or fewer antennas may be utilized for each antenna group. Cellular device 116 may be in communication with antennas 112 and 114 , where antennas 112 and 114 connect to cellular device 116 via forward link 120 (eg, downlink). Transmits information and receives information from cellular device 116 via reverse link 118 (eg, uplink). Cellular device 112 may be in communication with antennas 104 and 106 , where antennas 104 and 106 transmit information to cellular device 122 over forward link 126 and reverse link 124 . ) receives information from the cellular device 122 via The RAN node 102 may also be in communication with other cellular devices, which may interface with, for example, Internet of Things (IoT) devices. For example, IoT device 150 may be communicating with cellular device 116 , where information may be transmitted to IoT device 150 over forward link 121 and information over reverse link 119 . from the IoT device 150 to the cellular device 116 via A cellular device that is interfaced (eg, directly or indirectly) to an IoT device (collectively referred to as a cellular Internet of Things (CIoT) device 136 or CIoT device 136 ) is one or more other antennas of the RAN node 102 . , where the antennas transmit information to the CIoT device 136 over the forward link 140 and receive information from the CIoT device 136 over the reverse link 138 . The CIoT device 142 may be communicating with one or more other antennas of the RAN node 102 , where the antennas transmit information to the CIoT device 142 over the forward link 146 and connect the reverse link 144 to the CIoT device 142 . Receive information from the CIoT device 142 through. The RAN node 102 may be coupled to the core network 130 by one or more communication links and/or reference points 128 .
The various concepts presented throughout this disclosure may be implemented across various telecommunication systems, network architectures, and communication standards. For example, the Third Generation Partnership Project (3GPP) is a standard body defining several wireless communication standards for networks involving the Evolved Packet System (EPS), frequently referred to as Long-Term Evolution (LTE) networks. am. Evolved versions of an LTE network, such as a 5th generation (5G) network, can be used for web browsing, video streaming, VoIP, mission-critical applications, multi-hop networks, remote operations with real-time feedback (eg, telesurgery). ) may be provided for many different types of services or applications, including, but not limited to, the like. The evolution of LTE networks is an ongoing process. The evolution includes changes/modifications/alternatives made for improved interoperability with all cellular devices, including cellular devices interfaced to IoT devices. Accordingly, examples of changes/modifications/alternatives to devices 116 , 122 , 150 , 136 , 142 , RAN node 102 and nodes within core network 130 are described herein.
Wireless cellular communication networks deal with security at two levels. These levels are referred to as the access stratum (AS) and the non-access stratum (NAS). Using Long Term Evolution (LTE) as an example, the access layer may be described as a functional layer in wireless telecommunication protocol stacks between the RAN and a cellular device. The access layer protocol layer may be responsible for transmitting data over the radio connection between the RAN and the cellular device and managing radio resources. The non-access layer may be a functional layer in wireless telecommunication protocol stacks between the core network and the cellular device. The non-access layer protocol layer may be used to manage the establishment of communication sessions and maintain continuous communication with the cellular device as it moves. The non-access layer protocol layer may also be used for passage of messages between a cellular device and a node of a core network (eg, MME or C-SGN), where the messages are passed transparently through the RAN . Examples of NAS messages include Update messages, Attach Request messages, Attach Accept messages, Authentication messages, and Service Requests.
In order to reduce overhead and latency, the 3GPP standard setting body has proposed different requirements for CIoT, compared to the requirements for other communications through a cellular device. However, these requirements may leave the RAN node and core network open to undesirable vulnerabilities.
Among the different requirements is the removal of access layer security. Access layer security relates to security at the air interface between a cellular device and an eNodeB. CIoT messages are proposed to be transmitted from the cellular device to the core network in the control plane, at the NAS layer. CIoT messages, referred to herein as small data messages, are thus protected by existing NAS security. However, as described below, removing AS security may leave the RAN node and core network open to undesirable vulnerabilities.
Also among the different requirements is the removal of mobility support for CIoT. IoT devices may operate by sending periodic reports throughout the day; They do not remain connected to the core network for long periods of time. Many IoT devices are stationary, they do not move through cells, rather they remain in a fixed location within the boundaries of one cell. Other IoT devices, such as those coupled to cars, humans, parcels, etc., travel through cells, ie they roam. As IoT devices roam through the network, when the time comes for them to send a report, they wake up in the cell and send their report from within that cell; Cell-to-cell connected mode mobility may not be required.
Therefore, connected mode mobility may not be supported in the CIoT architecture. Elimination of mobility management provides a reduction in overhead for both the eNodeB in the RAN and the MME in the core network. Accordingly, the CIoT architecture introduces a new node referred to as a CIoT Serving Gateway Node (C-SGN). The C-SGN combines any necessary functionality remaining from the MME with the functionality of the Serving-Gateway (S-GW). A C-SGN may be equivalent to a Serving General Packet Radio Service (GPRS) Support Node (SGSN) in 3G.
2 is a diagram illustrating another example of a communication network 200 in which aspects of the present disclosure may find application. For example, the techniques presented herein provide keys to a first RAN node 204 (eg, C-BS) and a CIoT device 206 by a gateway 202 (eg, C-SGN). may be used to provision The illustrative example of FIG. 2 shows a CIoT architecture for a non-roaming scenario involving a CIoT device 206 . In the aspect of FIG. 2 , the functions of a packet data network gateway (P-GW) may be integrated with that of the gateway 202 (eg, C-SGN). Additionally or alternatively, as an implementation option 240 , the functions of the P-GW may be separated from the gateway 202 in the P-GW 237 . According to implementation option 240 , the S5 reference point 239 may be used between the gateway 202 (eg, C-SGN) and the P-GW 237 . The S5 reference point may provide user plane tunneling and tunnel management between the gateway 202 (eg, C-SGN) and the P-GW 237 . The S5 reference point may be used, for example, if the gateway 202 (eg, C-SGN) connects to a non-collocated P-GW 237 for packet data network connectivity. Thus, even in the example non-roaming scenario of FIG. 2 , gateway 202 (eg, C-SGN) and P-GW 237 may optionally be separate entities (eg, they may not be juxtaposed).
In the illustrative example of FIG. 2 , keys provisioned by gateway 202 may be used to integrity protect and/or encrypt small data messages, thereby providing access layer protection to communication network 200 .
In the example of FIG. 2 , the CIoT device 206 may be represented as an IoT device 208 interfaced to a cellular device 210 . The interface may be direct (eg, IoT device 208 may be hardwired to cellular device 210 ) or indirect (eg, IoT device 208 may be connected via an intermediate communication network such as a Bluetooth wireless network). may be coupled to the cellular device 210 ). The CIoT device 206 will wirelessly communicate with the first RAN node 204 (eg, C-BS) over the C-Uu reference point 212 (reference points may also be referred to as network interfaces). may be The first RAN node 204 (eg, C-BS) may communicate with the gateway 202 (eg, C-SGN) over a reference point, S1, or equivalent. In some aspects, as illustrated in FIG. 2 , the first RAN node 204 may communicate with the gateway 202 over an S1-lite 214 reference point. S1-Lite is a "light-weight" version of S1 that is optimized for small data messages. For example, only S1 Application Protocol (S1AP) messages and information elements (IEs) necessary to support CIoT procedures may be included in S1-lite. In general, the reference point (eg, network interface) may be S1 , S1-lite 214 , or equivalent.
Also depicted in FIG. 2 is a Long Term Evolution (LTE) or Machine Type Communication (MTC) cellular device 216 . The LTE or MTC cellular device 216 may communicate wirelessly with a second RAN node 220 (eg, eNodeB) over an LTE Uu (eMTC) reference point 218 .
The second RAN node 220 may communicate with the gateway 202 over the S1 reference point. In some aspects, as illustrated in FIG. 2 , the second RAN node 220 may communicate with the gateway 202 over the S1-lite 222 reference point.
The gateway 202 may communicate with a home subscriber server 224 (HSS). HSS 224 may store and update a database containing user subscription information and generate security information from user identity keys. The HSS 224 may communicate with the gateway 202 over the S6a 226 reference point. The S6a 226 reference point enables the transmission of subscription and authentication data to authenticate/authorize user access to the communication network 200 . The gateway 202 is a short message service (SMS) gateway mobile switching center (SMS-GMSC)/interworking mobile switching center (IWMSC)/SMS router (ie, SMS-GMSC/IWMSC/SMS router 228) ) can also communicate with In general, the SMS-GMSC/IWMSC/SMS router 228 is a contact point for short message service with other networks. The SMS-GMSC/IWMSC/SMS router 228 may communicate with the gateway 202 over a Gd/Gdd 230 reference point. The gateway 202 may communicate with an application server 232 .
In general, application server 232 may host applications of service providers. The application server 232 may be located in a packet data network (eg, the Internet). The application server 232 may communicate with the gateway 202 over the SGi 234 reference point. The SGi 234 is a reference point between the gateway 202 (eg, C-SGN) and the packet data network.
3 is a diagram illustrating another example of a communication network 300 in which aspects of the present disclosure may find application. For example, the techniques presented herein provide keys to a first RAN node 304 (eg, C-BS) and a CIoT device 306 by a gateway 302 (eg, C-SGN). may be used to provision The illustrative example of FIG. 3 shows a CIoT architecture for a roaming scenario involving a CIoT device 306 .
In the illustrative example of FIG. 3 , keys provisioned by gateway 302 may be used to integrity protect and/or encrypt small data messages, thereby providing access layer protection to communication network 300 .
The nodes of FIG. 3 are external to the gateway 302 (eg, C-SGN) and/or not collocated with the gateway 302. Addition of a packet data network (PDN) gateway (P-GW) 336 node Except for , the same as or similar to the nodes of FIG. 2 . The description of FIG. 3 follows for completeness.
In the example of FIG. 3 , the CIoT device 306 may be represented as an IoT device 308 interfaced to a cellular device 310 . The interface may be direct (eg, IoT device 308 may be hardwired to cellular device 310 ) or indirect (eg, IoT device 308 may be connected via an intermediate communication network such as a Bluetooth wireless network). may be coupled to the cellular device 310 ). The CIoT device 306 is to communicate wirelessly with the first RAN node 304 (eg, C-BS) over the C-Uu reference point 312 (reference points may also be referred to as network interfaces). may be The first RAN node 304 (eg, C-BS) may communicate with the gateway 302 (eg, C-SGN) over an S1 reference point. In some aspects, as illustrated in FIG. 3 , the first RAN node 304 may communicate with the gateway 302 over the S1-lite 314 reference point. S1-Lite is a version of S1 that is optimized for small data messages. For example, only S1 Application Protocol (S1AP) messages and information elements (IEs) necessary to support CIoT procedures may be included in S1-lite. In general, the reference point (eg, network interface) may be S1 , S1-lite 314 , or equivalent.
Also depicted in FIG. 3 is a Long Term Evolution (LTE) or Machine Type Communication (MTC) cellular device 316 . The LTE or MTC cellular device 316 may communicate wirelessly with a second RAN node 320 (eg, eNodeB) over an LTE Uu (eMTC) reference point 318 .
The second RAN node 320 may communicate with the gateway 302 over the S1 reference point. In some aspects, as illustrated in FIG. 3 , the second RAN node 320 may communicate with the gateway 302 over the S1-lite 322 reference point.
The gateway 302 may communicate with a home subscriber server 324 (HSS). HSS 324 may store and update a database containing user subscription information and generate security information from user identity keys. The HSS 324 may communicate with the gateway 302 over the S6a 326 reference point. The S6a 326 reference point enables the transmission of subscription and authentication data for authenticating/authorizing user access to the communication network 300 . Gateway 302 communicates with Short Message Service (SMS) Gateway Mobile Switching Center (SMS-GMSC)/Interworking Mobile Switching Center (IWMSC)/SMS Router (ie, SMS-GMSC/IWMSC/SMS Router 328). may be In general, the SMS-GMSC/IWMSC/SMS router 328 is a contact point for short message service with other networks. The SMS-GMSC/IWMSC/SMS router 328 may communicate with the gateway 302 over a Gd/Gdd 330 reference point. The gateway 302 may communicate with the application server 332 .
In general, the application server 332 may host applications of service providers. The application server 332 may be located in a packet data network (eg, the Internet). The application server 332 may communicate with the P-GW 336 over the SGi 334 reference point. The SGi 334 is a reference point between the P-GW 336 and the application server 332 in the packet data network. The P-GW 336 may communicate with the gateway 302 (eg, C-SGN) over the S8 338 reference point. The S8 338 reference point is generally in the Serving GW (or C-SGN in the case of FIG. 3 ) in the Visitor Public Land Mobile Network (VPLMN) and in the Home Public Land Mobile Network (HPLMN). The Inter-Public Land Mobile Network (Inter-PLMN) is a reference point, providing a user and control plane interface between the P-GWs.
In the aspect of FIG. 3 , P-GW functions may be separated from gateway 302 in P-GW 336 , or as implementation option 340 in P-GW 337 . In the case of implementation option 340 , the S5 reference point 339 may be used between the gateway 302 (eg, C-SGN) and the P-GW 337 . The S5 reference point may provide user plane tunneling and tunnel management between the gateway 302 (eg, C-SGN) and the P-GW 337 . The S5 reference point may be used, for example, if the gateway 302 (eg, C-SGN) connects to a non-collocated P-GW 237 for packet data network connectivity.
In example aspects described herein, a cellular device may be interfaced to an Internet of Things (IoT) device. Example aspects are described with respect to data messages (eg, small data messages) transmitted between an IoT device and a core network via a cellular device; However, aspects described herein are not limited to small data messages and have applicability to other types of data messages.
<b>Exemplary Stateless Access Layer Security Processes</b>
4 is a flow diagram illustrating an example of an access layer security key derivation and provisioning process 400 in accordance with some aspects of the present disclosure. The gateway may first obtain 402 (eg, derive, generate, compute, retrieve, receive, request, etc.) the first key. The gateway may be a CIoT Serving Gateway Node (C-SGN). A C-SGN may be a gateway that may be implemented to support functionality for CIoT use cases. C-SGN may incorporate those aspects of LTE Mobility Management Entity (MME), LTE Serving Gateway (S-GW), and LTE Packet Data Network Gateway (P-GW) useful for CIoT use cases. Reference to C-SGN in this specification is for convenience. Aspects described herein are not limited to implementations using C-SGN as gateway. In some aspects, the terms C-SGN and gateway may be used interchangeably herein.
The first key may be referred to as a Master Access Stratum security Key (MASK). In some aspects, the first key is not obtained from any other key. For example, the first key is not derived from another key material. In some aspects, the first key may be obtained randomly in the C-SGN. For example, in some aspects, the first key may be randomly generated in the C-SGN. The first key may be known only to the C-SGN.
The C-SGN may then obtain 404 the second key. The second key may be referred to as a base station access layer security key (BASK). The second key may be obtained from a parameter unique to the first key (eg, MASK) and a radio access network (RAN) node (eg, eNodeB, C-BS). A parameter unique to a RAN node may be the identity of the RAN node. In one aspect, the identity of the RAN node may be a CIoT base station identity (C-BS ID). The C-BS ID may be equivalent to an eNodeB ID in LTE, for example. The second key may be obtained using a key derivation function (KDF). For example, the second key may be given as:
2nd key = KDF (MASK, C-BS ID),
where KDF is the key derivation function, MASK is the first key, and C-BS ID is the CIoT base station identity.
The second key may be provisioned 406 to the RAN node (eg, C-BS) by the gateway. Because at least the second key is based on the first key and a parameter unique to the radio access network (RAN) node, the second key may be provisioned to the RAN node before, during, or after the initial attachment of the cellular device to the cellular network. have.
The C-SGN may still further obtain a third key. The third key may be referred to as a Device Access Stratum security Key (DASK). The third key may be obtained from a second key (eg, BASK) and a parameter unique to the cellular device. A parameter unique to a cellular device may be the identity of the cellular device. The identity of the cellular device may be, for example, SAE-Temporary Mobile Subscriber Identity (S-TMSI).
The third key may be obtained using a key derivation function (KDF). For example, the third key may be given as:
3rd key = KDF (BASK, cellular device ID),
where KDF is the key derivation function, BASK is the second key, and cellular device ID is the identity of the cellular device.
In some aspects, the gateway (eg, C-GSN) may provision 410 a third key (eg, DASK) to the cellular device.
In some aspects, the cellular device may add integrity protection to the small data message, where the integrity protection may be based, for example, on a third key (eg, DASK) and the identity of the device. The cellular device may additionally or alternatively encrypt the small data message, where encryption may be performed using a third key (eg, DASK). The integrity protected and/or encrypted small data message may be transmitted from the cellular device to the RAN node.
The third key may be provisioned (eg, sent) to the cellular device via a secure non-access layer (NAS) message (ie, the NAS secure mode command is complete). One example of a secure NAS message may be an attach accept message, sent to the cellular device upon successful completion of the initial attach procedure. Alternatively, the third key may be sent to the cellular device as an encrypted information element (IE). In this alternative, the IE may include an algorithm identifier that identifies the algorithm used to encrypt the IE.
In some aspects, the RAN node does not establish and/or maintain an access layer security context with the device. Establishing and/or maintaining an access layer security context may require the use of state tables and processing of data associated with the state tables. The state table and associated processing may represent, for example, consumption of overhead, which is undesirable in CIoT. Indeed, aspects of a stateless security scheme are disclosed herein. For example, the RAN node processes a second key (eg, BASK) that was provisioned to the RAN node by the gateway (eg, C-SGN). In one example, the RAN node has a second key (eg, BASK) and a third key (eg, as needed) on-the-fly (eg, dynamically, as needed) from the identity of the cellular device. DASK) can also be obtained. The identity of the cellular device is included with every small data message obtained at the RAN node and the second key is independent of the identity of the cellular device; Accordingly, the security scheme is stateless, at least in the sense that a state table is not required.
The RAN node then obtains (eg, derives, generates) a third key on-the-fly to verify the integrity of the small data messages obtained from the device and/or to decrypt the small data messages ( For example, DASK) may be used. Using the example key generation and provisioning schemes described herein, a measure of AS security may be implemented with the aid of existing messages. The overhead is not increased. The RAN node may protect itself and the core network from vulnerabilities such as denial of service and/or flooding attacks.
5 is a call flow diagram 500 illustrating an example of an attach procedure under a cellular Internet of Things (CIoT) in accordance with some aspects of the present disclosure. In the aspect of FIG. 5 , a cellular device 502 (eg, CIoT device), a RAN node 504 (eg, C-BS), a core network gateway (eg, a CIoT serving gateway node (C-) SGN) 506), a Home Subscriber Server (HSS) 508, and a P-GW 510 are included. The P-GW 510 is depicted for scenarios in which the cellular device 502 is roaming.
The example call flow of FIG. 5 may begin when the RRC connection establishment procedure is performed 520 . During performance of the RRC connection establishment procedure, the cellular device 502 and the RAN node 504 set one or more nonce values (eg, nonce-device, nonce-RAN) as described later herein. and/or provide one or more timestamp values to each other. The cellular device 502 may perform the indicated attach procedure by sending an attach request 522 . During the attach procedure, the cellular device 502 may indicate that the attachment is for a CIoT small data message (eg, "CIoT Attach" may be included as a parameter of the attach request 522 ). have). The RAN node 504 (eg, C-BS) may select the optimized C-SGN 506 for CIoT based on a cellular device indication or based on pre-configuration. The cellular device 502 may also indicate a particular data type (eg, IP and/or non-IP and/or SMS). An access point name (APN) may be indicated. The APN may identify the P-GW 510 and/or C-SGN 506 for which the cellular device 502 requests connectivity, and the public land mobile network in which the C-SGN 506 is located ( PLMN) and/or P-GW 510 may include an APN operator identifier that identifies the PLMN in which it is located.
As indicated above, the C-SGN 506 may obtain a second key (eg, BASK) for the RAN node 504 (eg, C-BS). The C-SGN 506 may provision the second key to the RAN node 504 (eg, C-BS) in the NAS message 524 .
The C-SGN 506 may perform any necessary authentication/security procedures 526 .
The C-SGN 506 may perform a location update with a home subscriber server 508 (HSS) and retrieve subscription information 528 .
The C-SGN 506 may process the attach request 522 and may determine, based on the parameters provided with the attach request 522 , whether there is a need to establish an IP bearer service. If the data type parameter is identified as "IP", the PDN type indicates the type of IP address to be assigned (ie, IPv4, IPv6). The C-SGN 506 may assign an IP address based on the PDN type in the attach request 522 . NAS session management signaling may not be required. In a roaming scenario, the C-SGN 506 may send a Create Session Request (or a new control message) to the P-GW indicating that this is a CIoT attach request and indicating the data type 530 . The P-GW may assign an IP address based on the PDN type in the attach request.
In the roaming scenario alone, depending on the data type, the P-GW may send a Create Session response (or a new control message) to the C-SGN 532 . For the IP data case (eg, data type = IP), the session creation response may include the assigned IP address.
The C-SGN may respond by sending an Attach Accept message 534 to the cellular device 502 without any session management message. For data type = IP, the assigned IP address may be sent to the cellular device 502 . The attach accept message may include a Globally Unique Temporary Identifier (GUTI). The GUTI may be assigned by the C-SGN (or the MME function of the C-SGN) during the initial attach procedure of the cellular device 502 .
As indicated above, during an attach procedure (eg, initial attach), the C-SGN 506 may obtain a third key (eg, DASK) for the cellular device 502 . . According to some aspects, the C-SGN 506 may provision a third key to the cellular device in a NAS message (eg, in an Attach Accept message 534 ).
The cellular device 502 may respond with an attach complete message 536 .
The RRC connection may be released 538 .
6 is a diagram that may support one or more of obtaining (eg, derivation, generating, computing, retrieving, receiving, requesting, etc.), provisioning, and using stateless access layer security and security keys in accordance with aspects of the present disclosure. It is a block diagram illustrating an example of a hardware implementation of an apparatus 600 (eg, an electronic device). The apparatus 600 is a gateway (eg, C-SGN), a RAN node (eg, base station, eNB, C-BS), a cellular device (eg, CIoT device), or a mobile phone, a smart phone, It may be implemented in some other type of device that supports wireless communication, such as a tablet, portable computer, server, personal computer, sensor, entertainment device, medical device, or any other electronic device having wireless communication circuitry.
Apparatus 600 (eg, a communication apparatus) includes a communication interface 602 (eg, at least one transceiver), a storage medium 604 , a user interface 606 , a memory device 608 (eg, , storing one or more security keys 618 ), and processing circuitry 610 . In various implementations, user interface 606 may include one or more of a keypad, display, speaker, microphone, touchscreen display, or some other circuitry for receiving input from or sending output to the user. .
These components may be placed in electrical communication with and/or coupled to each other via a signaling bus 640 or other suitable component, represented generally by the connection lines in FIG. 6 . The signaling bus 640 may include any number of interconnecting buses and bridges depending on the particular application of the processing circuit 610 and the overall design constraints. The signaling bus 640 is coupled to and/or each of the communication interface 602 , the storage medium 604 , the user interface 606 , and the memory device 608 to the processing circuit 610 and/or the processing circuit 610 . ) and links the various circuits together so that they are in electrical communication with the Signaling bus 640 may also link various other circuits (not shown), such as timing sources, peripherals, voltage regulators, and power management circuits, which will not be described further, as they are well known in the art. may be
The communication interface 602 may be adapted to facilitate wireless communication of the apparatus 600 . For example, communication interface 602 may include circuitry and/or programming adapted to facilitate communication of information in both directions for one or more communication devices in a network. In some implementations, the communication interface 602 may be designed, adapted, and/or configured for wire-based communication. In some implementations, the communication interface 602 may be coupled to one or more antennas 612 for wireless communication within a wireless communication system. Communication interface 602 may be designed, adapted, and/or configured with one or more standalone receivers and/or transmitters, as well as one or more transceivers. In the illustrated example, the communication interface 602 includes a transmitter 614 and a receiver 616 .
Memory device 608 may represent one or more memory devices. As indicated, memory device 608 may maintain security keys 618 along with other information used by apparatus 600 . In some implementations, memory device 608 and storage medium 604 are implemented as a common memory component. The memory device 608 may also be used to store data that is manipulated by the processing circuit 610 or some other component of the apparatus 600 .
The storage medium 604 may be one or more non-transitory computer-readable, machine-readable, for storing programming, such as processor-executable code or instructions (eg, software, firmware), electronic data, databases, or other digital information. capable, and/or may represent processor-readable devices. Storage medium 604 may also be used to store data that is manipulated by processing circuitry 610 when performing programming. Storage medium 604 may be any type that can be accessed by a general purpose or special purpose processor, including portable or fixed storage devices, optical storage devices, and various other media capable of storing, containing, or carrying programming. media may be available.
By way of example and not limitation, the storage medium 604 may be a magnetic storage device (eg, a hard disk, a floppy disk, a magnetic strip), an optical disk (eg, a compact disk (CD) or a digital versatile disk (DVD)). , smart card, flash memory device (eg, card, stick, or key drive), random access memory (RAM), read only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrical may include physically erasable PROM (EEPROM), registers, removable disks, and any other suitable medium for storing software and/or instructions that may be accessed and read by a computer. The storage medium 604 may be implemented in an article of manufacture (eg, a computer program product). As one example, a computer program product may include a computer-readable medium in packaging materials. In view of the above, in some implementations, storage medium 604 may be a non-transitory (eg, tangible) storage medium.
The storage medium 604 may be coupled to the processing circuitry 610 such that the processing circuitry 610 can read information from, and write information to, the storage medium 604 . That is, the storage medium 604 may be in examples where the at least one storage medium is integral with the processing circuitry 610 and/or the at least one storage medium is separate from the processing circuitry 610 (eg, the apparatus 600 ). storage medium 604 is at least accessible by processing circuitry 610 , including examples that reside external to apparatus 600 , distributed across multiple entities, etc.) can be coupled.
The programming stored by the storage medium 604, when executed by the processing circuitry 610, causes the processing circuitry 610 to perform one or more of the various functions and/or process operations described herein. . For example, the storage medium 604 may be used for regulating operations in one or more hardware blocks of the processing circuit 610 , as well as, for example, wirelessly utilizing their respective communication protocols, or in some implementations. may include operations configured to utilize the communication interface 602 for wired communication.
Processing circuitry 610 is generally adapted for processing, including execution of such programming stored on storage medium 604 . As used herein, the terms "code" or "programming" refer to instructions, instruction sets, data, code, code, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise. segments, program code, programs, programming, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executables, threads of execution, procedure It should be construed broadly to include, without limitation, functions, functions, and the like.
The processing circuit 610 may be arranged to obtain, process and/or transfer data, control data access and storage, issue commands, and control other desired operations. The processing circuit 610 may include circuitry devised, adapted, and/or configured to implement the desired programming provided by suitable media in at least one example. For example, processing circuitry 610 may be implemented as one or more processors, one or more controllers, and/or other structure devised, adapted, and/or configured to execute executable programming. Examples of processing circuitry 610 include general purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic components, discrete gate or transistor logic, discrete hardware components. , or any combination thereof designed to perform the functions described herein. A general purpose processor may include a microprocessor, as well as any conventional processor, controller, microcontroller, or state machine. The processing circuit 610 may also be a combination of computing components, such as a combination of a DSP and a microprocessor, multiple microprocessors, a DSP core, an ASIC and one or more microprocessors in combination with a microprocessor, or any other number of various configurations. It may be implemented as a combination. These examples of processing circuit 610 are for illustrative purposes and other suitable configurations within the scope of this disclosure are contemplated.
In accordance with one or more aspects of the present disclosure, processing circuitry 610 may be configured for any of the features, processes, functions, operations and/or routines for any or all of the apparatuses described herein. It may be adapted to perform all or all. For example, the processing circuit 610 may be configured to perform and/or perform any one of the operations described in the blocks identified with respect to FIGS. 4, 5, 7, 9-12, and 14 . may be adapted. As used herein, the term "adapted" with respect to processing circuitry 610 means that processing circuitry 610 performs a particular process, function, operation, and/or routine in accordance with the various features described herein. may refer to performing one or more of devising, configuring, employing, implementing, and/or programmed.
The processing circuit 610 may be configured with means for performing and/or performing any one of the operations described in the blocks identified with respect to FIGS. 4 , 5 , 7 , 9-12 , and 14 ; For example, it may be a specialized processor such as an application specific integrated circuit (ASIC) that serves as an architecture for The processing circuit 610 may serve as one example of means for transmitting and/or means for receiving.
According to at least one example of the apparatus 600 , the processing circuit 610 includes a circuit/module 620 for communicating, a circuit/module 622 for determining, a circuit/module 624 for provisioning, and a sending It may include one or more of a circuit/module 626 for waiting, a circuit/module 628 for waiting, or a circuit/module 629 for acquiring.
As noted above, programming stored by storage medium 604, when executed by processing circuitry 610, causes processing circuitry 610 to perform one of the various functions and/or process operations described herein. to do more than one. For example, the storage medium 604 may include code 630 for communicating, code for determining 632 , code for provisioning 634 , code for transmitting 636 , code for waiting 638 , or code for obtaining 639 .
7 is a flow diagram illustrating an example of a stateless access layer security process 700 in accordance with some aspects of the present disclosure. The stateless access layer security process 700 may be located within a processing circuit (eg, processing circuit 610 of FIG. 6 ), which may be located at a gateway (eg, C-SGN) or some other suitable device. it might happen Accordingly, stateless access layer security process 700 may be operable at a gateway (eg, C-SGN) or some other suitable device. In various aspects within the scope of the present disclosure, stateless access layer security process 700 implements stateless access layer security including one or more of obtaining, provisioning, and using security keys in accordance with one or more aspects of the present disclosure. It may be implemented by any suitable device capable of supporting it.
According to some aspects, the stateless access layer security process 700 may include, at a device (eg, gateway, C-SGN), obtaining 702 a first key known only to the device. It can also be described as a method of In the apparatus, obtaining (704) a first key and a second key (eg, derived using, generated using them) based on parameters unique to a radio access network (RAN) node. provision 706, by the apparatus, a second key to the RAN node. In the apparatus, obtaining (708) a third key based on a second key and a parameter unique to the cellular device. and provisioning (710), by the apparatus, a third key to the cellular device.
According to some aspects, a device (eg, gateway, C-SGN, communication device) may obtain 702 a first key (eg, master access layer security key - MASK) known only to the device . In some aspects, the first key may not be obtained from any other key. In other words, the device may obtain the first key when it cannot obtain the first key from any other key. In some aspects, the device may randomly generate the first key. In other words, the device may obtain the first key by randomly generating the first key in the device. In some aspects, the apparatus may be a Cellular Internet of Things Serving Gateway Node (C-SGN). In some aspects only the device (eg, gateway, C-SGN) knows the first key (eg, MASK). In other words, in some aspects, the first key is known only to the device.
The apparatus may obtain 704 a second key (eg, a master access layer security keyMASK) that may be based on a first key and a parameter unique to a radio access network (RAN) node. In some aspects, a parameter unique to a RAN node may be the identity of the RAN node. In some aspects, the RAN node may be a CIoT base station (C-BS) or an evolved Node B (eNodeB), and the parameter unique to the RAN node may be a C-BS identity or an eNodeB identity. In some aspects, a key derivation function may be used to obtain (eg, derive, generate) a second key.
The apparatus may provision 706 a second key to the RAN node. In some aspects, the apparatus may provision the second key to the RAN node in a non-access layer (NAS) message. In some aspects, the non-access layer message may be a secure NAS message.
The apparatus may obtain 708 a third key (eg, a device access layer security keyDASK) that may be based on a second key and a parameter unique to the cellular device. In some aspects, a parameter unique to a cellular device may be a cellular device identity. In some aspects, a parameter unique to a cellular device may be a System Architecture Evolution (SAE) Temporary Mobile Subscriber Identity (S-TMSI). S-TMSI may be used to locally identify a cellular device within an MME group. S-TMSI may be used in paging a cellular device. An S-TMSI may consist of an MME code and an MME Mobile Subscriber Identity (M-TMSI). In some aspects, a key derivation function may be used to obtain (eg, derive, generate) a third key.
The apparatus may provision 710 a third key to the cellular device. In some aspects, the apparatus may provision a third key to the cellular device in a non-access layer (NAS) message. In some aspects, the non-access layer message may be a secure NAS message. In some aspects, the non-access layer message may be an attach accept message. In some aspects, the apparatus may provision a third key as an encrypted information element (IE) to the cellular device. The IE may include an algorithm identifier that identifies the algorithm used to encrypt the IE.
8 is a hardware implementation of an apparatus 800 (eg, electronic device, communication apparatus) that may support one or more of obtaining, provisioning, and using stateless access layer security and security keys in accordance with aspects of the present disclosure. It is a block diagram illustrating another example of The apparatus 800 is a gateway (eg, C-SGN), a RAN node (eg, eNB, C-BS), a cellular device (eg, CIoT device), or a mobile phone, smart phone, tablet, It may be implemented in some other type of device that supports wireless communication, such as a portable computer, server, personal computer, sensor, entertainment device, medical device, or any other electronic device having wireless communication circuitry.
The apparatus 800 includes a communication interface (eg, at least one transceiver) 802 , a storage medium 804 , a user interface 806 , a memory device 808 (eg, one or more security keys 818 ). ), and processing circuitry 810 . In various implementations, user interface 806 may include one or more of a keypad, display, speaker, microphone, touchscreen display, or some other circuitry for receiving input from or sending output to the user. . In general, the components of FIG. 8 may be similar to corresponding components of the apparatus 600 of FIG. 6 .
In accordance with one or more aspects of the present disclosure, processing circuitry 810 may be configured with any of the features, processes, functions, operations, and/or routines for any or all of the apparatuses described herein. may be adapted to perform any or all of For example, the processing circuit 810 may be adapted to perform any of the blocks described with respect to FIGS. 4 , 5 , 7 , 9-12 , and 14 . As used herein, the term "adapted" with respect to processing circuitry 810 means that processing circuitry 810 performs a particular process, function, operation, and/or routine in accordance with the various features described herein. may refer to performing one or more of devising, configuring, employing, implementing, and/or programmed.
The processing circuit 810 is configured to serve as means (eg, structure for) for performing any one of the operations described in conjunction with FIGS. 4 , 5 , 7 , 9-12 , and 14 . It may be a specialized processor, such as an application specific integrated circuit (ASIC). The processing circuit 810 may serve as one example of means for transmitting and/or means for receiving.
According to at least one example of the apparatus 800 , the processing circuit 810 includes a circuit/module 820 for communicating, a circuit/module 822 for receiving, a circuit/module for comparing 824 , and discarding. circuit/module 826 for, circuit/module for transmitting 828, circuit/module for obtaining 830, circuit/module for decoding 832, circuit/module for verifying 834, detecting circuits/modules 836 for monitoring, or circuits/modules 838 for monitoring.
As noted above, programming stored by storage medium 804, when executed by processing circuitry 810 , causes processing circuitry 810 to perform one of the various functions and/or process operations described herein. You can also make it do more than one thing. For example, storage medium 804 includes code 840 for communicating, code for receiving 842 , code for comparing 844 , code for discarding 846 , code for sending 848 , code for obtaining 850 , code for decrypting 852 , code for verifying 854 , code for detecting 856 , or code for monitoring 858 .
9 is a flow diagram illustrating an example of a method 900 of stateless access layer security protected communication in accordance with some aspects of the present disclosure. The method 900 of stateless access layer security protected communication includes processing circuitry (eg, may occur within the processing circuit 810 of FIG. 8 . Accordingly, the method 900 of stateless access layer security protected communication may be operable at a RAN node or some other suitable apparatus. In various aspects within the scope of the present disclosure, a method 900 of stateless access layer security protected communication includes one or more of obtaining, provisioning, and using security keys in accordance with one or more aspects of the present disclosure. may be implemented by any suitable device capable of supporting stateless access layer security, including
In the aspect of FIG. 9 , when the cellular device sends a small data message to a RAN node (eg, eNB, C-BS), the cellular device connects to the gateway (eg, C-SGN) during the initial attach procedure. The small data message may be protected (eg, integrity protected and/or encrypted) using a third key (eg, DASK) provisioned to the cellular device by the cellular device. A small data message that is protected (eg, integrity protected and/or encrypted) with a third key may be referred to herein as a "protected message". The third key may be based on the second key (eg, BASK) and the identity of the cellular device. The second key may be provisioned to the RAN node by the gateway before, during, or after the device sends the protected message to the RAN node. The second key may be stored at the RAN node, for example, in a long-term memory device (eg, memory device 808 of FIG. 8 ), temporary memory, or a cache.
When a RAN node receives a protected message from a cellular device, the RAN node may determine that the message includes an integrity protection value (eg, a message authentication code (MAC), token). The RAN node obtains (eg, derives, creates) on-the-fly, eg, from items (eg, second key, device ID) that the RAN node is known or available to the RAN node. It is also possible to verify the integrity protection value using a third key that can be used. For example, as described, the third key may be based on (e.g., use of) the second key (e.g., BASK) and the identity of the cellular device (e.g., device ID, S-TMSI). may be derived from, or generated using them). The second key may be provisioned from the gateway to the RAN node, while the identity of the cellular device (eg, S-TMSI) may be included in the small data message received by the RAN node.
According to exemplary aspects described herein, the second key (eg, BASK) may not be cellular-device-specific (eg, the second key is given may not be unique to the cellular device). Although the third key may be cellular-device-specific, the RAN node (eg, base station, eNB, C-BS) may use a security context (UE state, cellular device state) for the cellular device to implement access layer security. ) is not compelled to maintain Instead, to verify and/or decrypt the protected message from the cellular device, the RAN node uses the second key (eg BASK) and the device ID to obtain a third key on-the-fly and , the third key may be used to verify and/or decrypt the protected message from the cellular device. The second key may be provided to the RAN node by each gateway (eg, C-SGN) with which the RAN node is associated. The device ID may be included with the small data message to be verified and/or decrypted. The RAN node may obtain (eg, derive, generate, compute, retrieve, receive, request, etc.) the cellular device's third key on-the-fly when the RAN node receives the protected message from the cellular device. have. Accordingly, the exemplary access layer security scheme related to obtaining a third key (eg, DASK) is stateless.
In some implementations, the second key may be RAN-node-specific. In other implementations, the second key may be RAN-node-group-specific (eg, a plurality of RAN nodes may have a common group identifier). In implementations where the second key is RAN-node-group-specific, the second key may be shared among multiple RAN nodes in a given group. When the second key is shared between a plurality of RAN nodes, even if the cellular device connects to different RAN nodes in a given group, the cellular device has a gateway (e.g., There may be no need to obtain a new third key (eg, DASK) from C-SGN). Thus, instead of obtaining (eg, deriving, generating) the second key (eg, BASK) based on the first key (eg, MASK) and the RAN node identity (eg, eNB ID) For example, the gateway (eg, C-SGN) may obtain a first key (eg, MASK) and a second key (eg, BASK) from the RAN node group identity. In other words, within the coverage of a given RAN node group (ie, a given RAN node group), the RAN nodes of the given group share the same second key (eg, BASK). Accordingly, the cellular device (eg, CIoT device, UE) is configured to protect small data messages transmitted within the coverage of a given RAN node group (and/or verify and/or verify small data messages received within the coverage thereof). or to decrypt) may use a third key (eg, DASK) common to a plurality of RAN nodes in a given RAN node group. In some implementations, the network may configure the RAN node group and announce the availability of the RAN node group as part of the system information (SI).
In accordance with some aspects, a method 900 of stateless access layer security protected communication may be described as a method of secure protected communication. Stateless access layer security protected communications may secure communications with, for example, integrity protection and/or ciphering (generally referred to herein as encryption or decryption). The method, at the device (eg RAN node, C-BS, eNB), is based on a first key and device-specific parameters (eg derived using them, generated using them) obtaining ( 902 ) a second key. In the apparatus, obtaining (904) a small data message including a device identity and a first integrity protection value. In the apparatus, obtaining (906) a third key based on the second key and the device identity. At the device, obtaining (908) a second integrity protection value obtained (eg, derived, generated) using the third key. Integrity protection processes may be performed using a third key (to yield integrity protection values), and may further be performed using, for example, a protected device identity, one or more nonces, and a small data message. have. Comparing (910), at the device, the first integrity protection value and the second integrity protection value. Obtaining the comparison result/determining whether the first integrity protection value is equal to the second integrity protection value (912). Discard 914 the small data message from the device if the comparison result indicates that the first integrity protection value is not equal to the second integrity protection value. Alternatively, sending 916, from the device, a small data message to the gateway if the comparison result indicates that the first integrity protection value is equal to the second integrity protection value.
According to some aspects, an apparatus (eg, RAN node, C-BS, eNB) may obtain a second key (eg, BASK), wherein the second key is unique to the first key and the apparatus based on one parameter (902). In some aspects, the second key is obtained from a gateway. In some aspects, the first key is known only to the gateway. In some aspects, the gateway is a C-SGN. In some aspects, a parameter unique to a RAN node is the identity of the RAN node. For example, the RAN node may be a CIoT base station (C-BS) or an evolved Node B (eNodeB), and a parameter unique to the RAN node may be a C-BS identity or an eNodeB identity.
The apparatus (referred to as "apparatus" for convenience or alternatively referred to as "RAN node" in connection with the description of FIG. 9 that follows) sends a small data message comprising a device identity and a first integrity protection value. receive 904 .
The apparatus may obtain 906 a third key (eg, DASK) based on the second key and the device identity.
The device may obtain 908 a second integrity protection value using the third key.
In one aspect, the first and second integrity protection values may be values given to (eg, attributed to, calculated from) the token. In one aspect, the first and second integrity protection values may be values given in a message authentication code (MAC). As used herein, a token and/or MAC may be referred to as an integrity protection parameter. For example, in scenarios in which aspects of AS security protection described herein are used for uplink traffic (eg, from a device to a RAN node), the RAN node may use the device for use in AS security protection. It may be necessary to provide a nonce (eg, nonce-RAN) to . In such a scenario, a MAC as shown below may be used:
MAC = F (DASK, S-TMSI | Nonce-RAN | Message).
According to one alternative, another way to obtain the MAC may use the following equations:
K<sub>MAC</sub> = KDF (DASK, nonce-RAN), where K<sub>MAC</sub> is a one-time MAC generation key obtained based on DASK and nonce-RAN; KDF is a key derivation function.
MAC = F (K<sub>MAC</sub>, message).
According to another alternative, in order to take into account the case where multiple messages are sent for a single connection (eg RRC connection), a counter is set to the MAC of each message, ie,
MAC = F (K<sub>MAC</sub>, counter | message)
may be integrated to generate a new key (i.e., K<sub>MAC</sub>) is initialized (eg, to 0) when derived and is incremented by a predetermined value (eg, 1) for every single message for a connection.
In yet another alternative, aspects of AS security protection described herein may reduce uplink traffic (eg, from a device to a RAN node) and/or downlink traffic (eg, from a RAN node to a device). In the scenarios used for , the device may need to provide a nonce (eg, nonce-device) to the RAN node for use in AS security protection. In such a scenario, a MAC as shown below may be used:
MAC = F (DASK, S-TMSI | Nonce-Device | Nonce-RAN | Message),
For all the equations shown above here, F is a MAC generation function (eg, CMAC, HMAC) ("F" may alternatively be referred to herein as an integrity protection algorithm), and DASK is the second key is an example of, S-TMSI is an example of the identity of a cellular device, the nonce-device may be used only once and the first arbitrary number provided by the device, and the nonce-RAN may be used only once A second arbitrary number provided by the RAN node, and the message is a message to be transmitted (eg, a small data message).
According to another alternative, another way to obtain the MAC may use the following equations:
K<sub>MAC</sub> = KDF (DASK, S-TMSI | Nonce-Device | Nonce-RAN), where K<sub>MAC</sub> is a one-time MAC generation key obtained based on DASK, nonce-device and nonce-RAN; And KDF is a key derivation function.
MAC = F (K<sub>MAC</sub>, message)
According to another alternative, in order to account for the case where multiple messages are sent for a single connection (eg RRC connection), a counter is set to the MAC of each message, i.e.
MAC = F (K<sub>MAC</sub>, counter | message)
may be integrated to generate a new key (i.e., K<sub>MAC</sub>) is initialized (eg, to 0) when derived and is incremented by a predetermined value (eg, 1) for every single message for a connection.
An integrity protection parameter (eg, MAC, token) may incorporate one or more nonces (eg, nonce-device and/or nonce-RAN) to prevent reply attacks. In other words, one or more nonces may be used for retransmission protection. A nonce-device and/or a nonce-RAN may be exchanged between a device and a RAN node during a random access procedure. For example, the device may send a nonce-device to the RAN node in message 3 (RRC Connection Request) of the random access procedure and the RAN node may send a nonce-RAN to the device in message 4 (RRC Connection Setup) of the random access procedure. can also be sent. If more than one message is being sent, the nonce (eg, nonce-device and/or nonce-RAN) may be incremented by a predetermined fixed amount (eg, 1) for each message.
As an alternative to nonce (eg, nonce-device and/or nonce-RAN), any random number that may be exchanged (eg, to prevent retransmission attacks) is tolerated. In some aspects, a nonce may be replaced (eg, replaced) with a timestamp. The timestamp may be used when the cellular device and apparatus (eg, RAN node, C-BS) has a timer. Accordingly, in some aspects, and as an example, one or more of the nonces (eg, nonce-device and/or nonce-RAN) in the example MACs provided above are with a randomly selected number and/or timestamp. It may be replaced (eg, replaced).
As yet another alternative, in some aspects, one or more of the nonces (eg, nonce-device and/or nonce-RAN) in the example MACs provided above are with a cell-radio network temporary identity (C-RNTI). It may be replaced (eg, replaced). The C-RNTI may be a unique identification (ID) used to identify an RRC connection and for scheduling that is dedicated (eg, device-unique) to a particular cellular device. In such a scenario, for example, the first and second integrity protection parameters may be a message authentication code (MAC) obtained using parameter C-RNTI instead of nonce-device and nonce-RAN. E.g,
MAC = F (DASK, S-TMSI | C-RNTI | Message),
where F is a MAC generation function (eg, CMAC, HMAC), DASK is an example of a second key, S-TMSI is an example of an identity of a cellular device, and C-RNTI is an example of an identity of a cellular device The assigned identity, and the message is the message being sent (eg, a small data message). The use of this alternative may be affected by the strength of the privacy policies used by the network in assigning S-TMSI and C-RNTI identifiers. For example, this alternative may be used under the assumption that the network has good privacy policies for assigning its identifiers.
K<sub>MAC</sub> = KDF (DASK, S-TMSI | C-RNTI),
where K<sub>MAC</sub> is a one-time MAC generation key obtained based on DASK, S-TMSI and C-RNTI; And KDF is a key derivation function.
MAC = F (K<sub>MAC</sub>, message)
To account for the case where multiple messages are sent for a single connection (eg, RRC connection), the counter is the MAC of each message, i.e.,
MAC = F (K<sub>MAC</sub>, counter | message)
may be integrated to create
where the counter is the new key (i.e. K<sub>MAC</sub>) is initialized (eg, to 0) when derived and is incremented by a predetermined value (eg, 1) for every single message for a connection.
In the example alternatives described above, the integrity protection algorithm (eg, function F) used to obtain (eg, derive, generate) an integrity protection parameter (eg, MAC, token) is configured by the network may be determined and announced to the device. This also applies to ciphering algorithms, as described below.
Accordingly, in some aspects, the first integrity protection parameter and the second integrity protection parameter incorporate one or more nonces, random numbers, time stamps, and/or network assigned unique (eg, C-RNTI) parameters. You may. A method operable at a RAN node is to set, by the RAN node, a nonce (eg, nonce-RAN), a random number, a time stamp, and/or a network-assigned unique (eg, C-RNTI) parameter to the cellular device. It may include the step of provisioning to . The method operable at the RAN node is, by the RAN node, a nonce (eg, nonce-RAN), random number, timestamp, and/or network-assigned unique (eg, C-RNTI) during the random access procedure. ) provisioning the parameter to the cellular device. A method operable at a device may include provisioning, by the device, a nonce (eg, nonce-device), a random number, a time stamp, and/or a network assigned unique parameter to the RAN node. A method operable in a device may include provisioning, by the device, a nonce (eg, nonce-RAN), a random number, a time stamp, and/or a network assigned unique parameter to the RAN node during a random access procedure. may be
The device may compare 910 the first integrity protection value and the second integrity protection value.
The device may discard 914 the small data message if the comparison result indicates that the first integrity protection value is not equal to the second integrity protection value.
The device may send the small data message to the gateway (eg, next hop) if the comparison result indicates that the first integrity protection value is equal to the second integrity protection value.
As indicated above, in some aspects the first integrity protection parameter and the second integrity protection parameter may incorporate a random number and/or time stamp to prevent retransmission attacks. In some aspects, the RAN node may receive a small data message from a device identified by a device identity, and the RAN node provisions a random number to the device. For example, the small data message may be obtained from a device identified by a device identity and the random number may be a nonce provisioned to the device by the RAN node during a random access procedure. The nonce may be incremented by a fixed, predetermined amount for each message sent from the RAN node to the device.
The following process may also be used to implement a method of secure protected communication. The method comprises, at a radio access network (RAN) node, obtaining a first key and a second key based on a parameter unique to the RAN node, at the RAN node small data comprising a device identity and a first integrity protection value obtaining the message, at the RAN node obtaining a second key and a third key based on the device identity, at the RAN node obtaining a second integrity protection value based on the third key, at the RAN node , comparing the first integrity protection value with the second integrity protection value; discarding the small data message if the comparison result indicates, from the RAN node, that the first integrity protection value is not equal to the second integrity protection value; and sending, from the RAN node, a small data message to the gateway if the comparison result indicates that the first integrity protection value is equal to the second integrity protection value. According to some aspects, the second key is obtained from a gateway. According to some aspects, the gateway is a Cellular Internet of Things Serving Gateway Node (C-SGN). According to some aspects, the RAN node is a Cellular Internet of Things (CIoT) base station (C-BS) or an evolved Node B (eNodeB), and the parameter unique to the RAN node is a C-BS identity or an eNodeB identity. According to some aspects, the first integrity protection value and the second integrity protection value are obtained using at least one nonce and/or time stamp. According to some aspects, the device identity identifies a device, the method further comprising provisioning a first nonce and/or a time stamp to the device and/or obtaining a second nonce from the device. According to some aspects, provisioning a first nonce and/or a time stamp and obtaining a second nonce occur during a random access procedure. According to some aspects, the small data message is encrypted with the third key, and the method further comprises, at the RAN node, decrypting the small data message using the third key. According to some aspects, prior to obtaining the small data message, a method includes, by a RAN node, monitoring, by a RAN node, a traffic load value; detecting, by the RAN node, that the traffic load value exceeds a predetermined threshold; and in response to detecting that the traffic load value exceeds the predetermined threshold, include the first integrity protection value in the next one or more messages sent to the RAN node to the device identified by the device identity. It further comprises the step of sending a request message to. According to some aspects, the network configures a predetermined threshold. According to some aspects, prior to obtaining the small data message, the method further comprises configuring and/or negotiating an access layer security configuration during an initial attach procedure with a device identified by the device identity, wherein The access layer security configuration specifies whether small data messages are sent from the device without security, with integrity protection, with encryption, with integrity protection and encryption, and/or with integrity protection on demand, where integrity protection and encryption are the third This is done using the key.
10 is a flow diagram illustrating another example of a stateless access layer security process 1000 in accordance with some aspects of the present disclosure. The stateless access layer security process 1000 is a processing circuit (eg, the processing circuit of FIG. 8 ) that may be located in a radio access network (RAN) node (eg, C-BS) or some other suitable apparatus. 810))). Accordingly, the stateless access layer security process 1000 may be operable at a RAN node (eg, C-BS) or some other suitable apparatus. Of course, in various aspects within the scope of the present disclosure, the stateless access layer security process 1000 includes one or more of obtaining, provisioning, and using security keys in accordance with one or more aspects of the present disclosure. Thus, it may be implemented by any suitable device capable of supporting stateless access layer security.
In the aspect of FIG. 10 , when a cellular device sends a small data message to a RAN node (eg, C-BS), the cellular device is cellular by a gateway (eg, C-SGN) during an initial attach procedure. The small data message may be encrypted using a third key (eg, DASK) provisioned to the device. When a RAN node (eg, C-BS) receives a small data message from a cellular device, the RAN node sends a second key (eg, BASK) that may be provisioned to the RAN node by a gateway to the RAN node. The third key (eg, DASK) may be obtained on-the-fly using the identity of the cellular device, which may be carried along with the encrypted small data message obtained by For example, the encrypted small data message may be carried along with the cellular device's S-TMSI.
Encryption may use a nonce provided to the cellular device by a RAN node (eg, C-BS) during a random access procedure. In one aspect, the nonce may be provided as an initialization vector (IV) . E.g:
Ciphertext = Enc (DASK, IV, message),
where Enc is an encryption function (eg, AES-CTR, ...), DASK is an example of a second key, and IV is a nonce provided as an initialization vector.
An alternative method of encryption using a one-time key is as before:
K<sub>Enc</sub> = KDF (DASK, nonce),
where K<sub>Enc</sub> is a one-time encryption key obtained based on DASK and S-TMSI, C-RNTI, nonce-device, nonce-RAN or a combination thereof; And KDF is a key derivation function.
ciphertext = Enc(K<sub>Enc</sub>, IV, message),
Here, IV is initialized to a predetermined value (eg, 0, or a value obtained based on S-TMSI, C-RNTI, nonce-RAN, nonce-device, or a combination thereof).
To account for the case where multiple messages are sent for a single connection (eg, an RRC connection), a counter is counted in the ciphertext of each message, i.e.,
ciphertext = Enc(K<sub>Enc</sub>, IV, message)
may be combined to generate a , where IV is a new key (i.e., K<sub>Enc</sub>) is initialized when ) is derived (eg, 0, or a value obtained based on S-TMSI, C-RNTI, nonce-RAN, nonce-device, or a combination thereof), and for every single message for access It is incremented by a predetermined value (eg, 1).
As before, the RAN node may obtain a third key (eg, DASK) based on the second key (eg, BASK) and the identity of the cellular device.
In some aspects, inclusion of the IV in the message is used by the RAN node (eg, C-BS) as a nonce (eg, IV) for a short amount of time (eg, for the duration of the RRC connection). It is optional because it can store the nonce set to /IV ).
In some aspects, a nonce is a randomly selected number provided to a cellular device by an apparatus (eg, RAN node, C-BS) during a random access procedure. If more than one message is being sent, the nonce may be incremented by a predetermined fixed amount (eg, one) for each message. Alternatively, any random number provided to the cellular device by the apparatus (eg, RAN node, C-BS) and may be varied (eg, to prevent retransmission attacks) is tolerated. In some aspects, the nonce may be replaced with a C-RNTI. In some aspects, a nonce may be replaced with a timestamp. The timestamp may be used when the cellular device and apparatus (eg, RAN node, C-BS) has a timer.
Turning now to FIG. 10 , a device (eg, a RAN node, C-BS) may receive a second key (eg, BASK), wherein the second key includes a first key and a device (eg, For example, based on parameters specific to the RAN node, C-BS (1002). In some aspects, the RAN node receives the second key from the gateway, and the first key is known only to the gateway. In some aspects, the gateway is a C-SGN. In some aspects, a parameter unique to a RAN node is the identity of the RAN node. For example, the RAN node may be a CIoT base station (C-BS) or an evolved Node B (eNodeB), and a parameter unique to the RAN node may be a C-BS identity or an eNodeB identity.
The apparatus may receive an encrypted small data message including the device identity. In some aspects the small data message is encrypted 1004 with a third key (eg, DASK).
The apparatus may obtain 1006 a third key (eg, DASK) based on the second key and the device identity.
The device may decrypt 1008 the small data message using the third key.
In some aspects, encryption and decryption may incorporate a random number and/or timestamp to prevent retransmission attacks. In some aspects, the small data message may be obtained from a device identified by a device identity and the RAN node provisions a random number to the device. For example, the small data message may be obtained from a device identified by a device identity and the random number may be a nonce provisioned to the device by the RAN node during a random access procedure. The nonce may be incremented by a fixed, predetermined amount for each message sent from the RAN node to the device.
11 is a flow diagram illustrating another example of a stateless access layer security process 1100 in accordance with some aspects of the present disclosure. The stateless access layer security process 1100 is a processing circuit (eg, the processing circuit of FIG. 8 ) that may be located in a radio access network (RAN) node (eg, C-BS) or some other suitable apparatus. 810))). Accordingly, the stateless access layer security process 1100 may be operable at a RAN node (eg, C-BS) or some other suitable apparatus. Of course, in various aspects within the scope of the present disclosure, the stateless access layer security process 1100 includes one or more of obtaining, provisioning, and using security keys in accordance with one or more aspects of the present disclosure. Thus, it may be implemented by any suitable device capable of supporting stateless access layer security.
In the aspect of FIG. 11 , both encryption and integrity protection may be enabled. When both encryption and integrity protection are configured for use, an Authenticated Encryption With Associated Data (AEAD) cipher may be used. Access layer security may be configured and/or negotiated during the initial attach procedure.
Turning now to FIG. 11 , an apparatus (eg, a radio access network (RAN) node, C-BS) may receive a second key (eg, BASK), wherein the second key is the first key and parameters unique to the apparatus (eg, RAN node, C-BS) ( 1102 ). In some aspects, the RAN node receives the second key from the gateway, and the first key is known only to the gateway. In some aspects, the gateway is a C-SGN. In some aspects, a parameter unique to a RAN node is the identity of the RAN node. For example, the RAN node may be a CIoT base station (C-BS) or an evolved Node B (eNodeB), and a parameter unique to the RAN node may be a C-BS identity or an eNodeB identity.
The apparatus may receive a small data message including the device identity. In some aspects, the small data message may be encrypted with a third key (eg, DASK) and the small data message may include an integrity protection value derived or generated using the third key ( 1104 ).
The apparatus may obtain 1106 a third key (eg, DASK) based on the second key and the device identity.
The device may decrypt 1108 the small data message using the third key.
The device may verify 1110 the integrity protection value using the third key.
12 is a flow diagram illustrating another example of a stateless access layer security process 1200 in accordance with some aspects of the present disclosure. The stateless access layer security process 1200 is a processing circuit (eg, the processing circuit of FIG. 8 ) that may be located in a radio access network (RAN) node (eg, C-BS) or some other suitable apparatus. 810))). Accordingly, the stateless access layer security process 1200 may be operable at a RAN node (eg, C-BS) or some other suitable apparatus. Of course, in various aspects within the scope of the present disclosure, the stateless access layer security process 1200 includes one or more of obtaining, provisioning, and using security keys in accordance with one or more aspects of the present disclosure. Thus, it may be implemented by any suitable device capable of supporting stateless access layer security.
In the aspect of FIG. 12 , an exemplary on-demand integrity protection process employing tokens is depicted. According to one aspect, in the normal or first mode of operation, no access layer security is configured; In a second mode of operation, access layer security is configured. For example, when congestion and/or overhead is detected in a RAN node (eg, C-BS) or some other network node, the RAN node (eg, C-BS) is directed to a cellular device. A message (eg, indication, request, command, command) may be sent. The message may cause (or trigger) the cellular device to include the token along with one or more messages (eg, small data messages) sent to the RAN node (eg, C-BS). . In one example, congestion and/or overload may be detected based on large amount of small data message transmissions. In one example, when the traffic load exceeds a given threshold, congestion and/or overload may be detected, and transmission of an indication/request/command/command may be triggered. In some aspects, the threshold may be predefined. In some aspects, the network may configure a threshold.
According to some aspects, a token may be generated in the same way as a MAC for integrity; However, unlike MAC for integrity, tokens according to this aspect are provided on-demand from a RAN node (eg, provided in response to a demand from a RAN node).
For example, during a random access procedure, a RAN node (eg, C-BS) and a device may exchange a respective nonce (eg, nonce-RAN, nonce-device) as previously described. . Additionally, the RAN node may provide an indication/request/command/command to the cellular device to transmit the token along with one or more small data messages sent next. Tokens may be created as
token = F (DASK, S-TMSI | nonce-device | nonce-RAN | message),
where F is the token generation function (eg, CMAC, HMAC), DASK is the third key, S-TMSI is the identity of the cellular device (other parameters identifying the cellular device may be used), and nonce- A device, and a nonce-RAN, are described above, and a message is a transmitted message. If more than 1 message is being sent, the nonce may be incremented by a fixed amount (eg, 1) for each message.
When a RAN node (eg, C-BS) receives a message carrying a token from a cellular device, the RAN node may obtain a third key (eg, DASK) on-the-fly, wherein the third key may be based on the second key (eg, BASK) and the identity of the cellular device. The RAN node may then verify the token, eg, by obtaining (eg, deriving, generating) the second token according to the equation provided above and comparing the received token with the second token.
In some aspects, the nonce may be carried in a cellular device message or stored temporarily in a RAN node (eg, C-BS).
In various implementations, since this On-Demand Integrity Protection process employing a token is triggered during congestion/overload, the On-Demand Integrity Protection process can be performed if access layer security (e.g., LTE access layer security) is always active, Minimizes computational overhead that would otherwise be incurred on the cellular device and the RAN node (eg, C-BS).
Turning now to FIG. 12 , an apparatus (eg, a radio access network (RAN) node) may monitor 1202 a traffic load value.
The apparatus may detect 1204 that the traffic load value exceeds a predetermined threshold. In one example, a network (eg, a core network) may configure a predetermined threshold.
A message requesting the cellular device to include the token in the next one or more messages sent to the apparatus (RAN node, C-BS) in response to the apparatus detecting that the traffic load value exceeds a predetermined threshold (eg, indication, request, command, command) to a cellular device (eg, CIoT device).
13 is an apparatus 1300 (eg, a cellular device) that may support one or more of obtaining, provisioning, and using stateless access layer security and security keys in accordance with one or more aspects of the present disclosure. , CIoT device, electronic device, communication device) is a block diagram illustrating another example of a hardware implementation. Apparatus 1300 is a gateway (eg, C-SGN), RAN node (eg, base station, eNB, C-BS), cellular device, CIoT device, or mobile phone, smart phone, tablet, portable computer, It may be implemented in some other type of device that supports wireless communication, such as a server, personal computer, sensor, entertainment device, medical device, or any other electronic device having wireless communication circuitry.
The apparatus 1300 includes a communication interface (eg, at least one transceiver) 1302 , a storage medium 1304 , a user interface 1306 , a memory device 1308 (eg, one or more security keys 1318 ). ), and processing circuitry 1310 . In various implementations, user interface 1306 may include one or more of a keypad, display, speaker, microphone, touchscreen display, or some other circuitry for receiving input from or sending output to the user. In general, the components of FIG. 13 may be similar to corresponding components of the apparatus 600 of FIG. 6 .
In accordance with one or more aspects of the present disclosure, the processing circuit 1310 may be configured for any of the features, processes, functions, operations, and/or routines for any or all of the apparatuses described herein. may be adapted to perform any or all of For example, the processing circuit 1310 may implement any of the blocks, steps, functions, and/or processes described with respect to FIGS. 4, 5, 7, 9-12, and 14 . may be adapted to perform. As used herein, the term "adapted" with respect to the processing circuit 1310 is such that the processing circuit 1310 performs a particular process, function, operation, and/or routine in accordance with the various features described herein. may refer to performing one or more of devising, configuring, employing, implementing, and/or programmed.
The processing circuit 1310 is configured to serve as means (eg, structure for) for performing any one of the operations described in conjunction with FIGS. 4 , 5 , 7 , 9-12 , and 14 . It may be a specialized processor, such as an application specific integrated circuit (ASIC). The processing circuit 1310 may serve as one example of means for transmitting and/or means for receiving.
According to at least one example of the apparatus 1300 , the processing circuit 1310 includes a circuit/module 1320 for communicating, a circuit/module 1322 for receiving, a circuit/module 1324 for configuring, and a negotiation for. It may include one or more of a circuit/module 1326 for transmitting, a circuit/module 1328 for transmitting, a circuit/module 1330 for obtaining an integrity parameter, or a circuit/module 1332 for encrypting.
As noted above, programming stored by storage medium 1304, when executed by processing circuitry 1310 , causes processing circuitry 1310 to perform one of the various functions and/or process operations described herein. to do more than one. For example, the storage medium 1304 includes code 1340 for communicating, code for receiving 1342 , code for configuring 1344 , code for negotiating 1346 , code for transmitting 1348 , code 1350 for obtaining the integrity parameter, or code 1352 for encrypting.
14 is a flow diagram illustrating another example of a stateless access layer security process 1400 in accordance with aspects of the present disclosure. The stateless access layer security process 1400 takes place within a processing circuit (eg, processing circuit 1310 of FIG. 13 ), which may be located in a cellular device (eg, a CIoT device) or some other suitable apparatus. may be Accordingly, the stateless access layer security process 1400 may be operable in a cellular device or some other suitable apparatus. Of course, in various aspects within the scope of the present disclosure, the stateless access layer security process 1400 includes one or more of obtaining, provisioning, and using security keys in accordance with one or more aspects of the present disclosure. Thus, it may be implemented by any suitable device capable of supporting stateless access layer security.
Returning now to FIG. 14 , the apparatus (eg, cellular device, CIoT device) generates a second key (eg, BASK) and a third key (eg, DASK) based on parameters unique to the device. may be obtained (1402). In some aspects, a parameter unique to an apparatus may be an identity of the apparatus (eg, identity of a cellular device, cellular device ID, CIoT device ID). In some aspects, the second key may be based on the first key and the RAN node identity or RAN node group identity. The device may not know the second key and the first key. In some aspects, for example, the second key may be based on the first key and a parameter unique to the RAN node, and the first key may be known only to the gateway.
The device may configure and/or negotiate 1404 an access layer security configuration. In some aspects, the apparatus may negotiate an access layer security configuration with a RAN node. In some aspects, the device may negotiate an access layer security configuration during the initial attach procedure. In some aspects, the apparatus may negotiate an access layer security configuration with the RAN node during the initial attach procedure. According to some aspects, the access layer security configuration may specify whether small data messages are sent from a cellular device without security, with integrity protection, with encryption, with integrity protection and encryption, and/or with integrity protection on demand, and , where integrity protection and encryption may be performed using a third key.
The device may use the third key to secure 1406 the small data message based on the access layer security configuration. The device may use a third key to protect the small data message with integrity protection and/or encryption. The device may send 1408 the protected small data message using the third key. In some aspects, the apparatus may send a protected small data message to the RAN node using the third key.
For all aspects and implementations described herein, the gateway (eg, C-SGN) may periodically change the first key (eg, MASK). According to some aspects, the first key may be associated with a first index (eg, MASK index). For example, the first key may be determined by the first index. In one aspect, every time the first key changes (per period), the first index may change.
According to some aspects, a second key (eg, BASK) may be associated with a second index (eg, BASK index). The second index may be determined by the first index (eg, MASK index). For example, a RAN node (eg, C-BS) may be provisioned with a second key having a second index corresponding to a first index that is currently valid (eg, not expired, active). .
According to some aspects, a third key (eg, DASK) may be associated with a third index (eg, DASK index). The third index may be determined by the second index (eg, BASK index). For example, a cellular device (eg, a CIoT device) may be provisioned with a third key having a third index corresponding to a second index that is currently valid (eg, not expired, active).
A third key index (eg, DASK index) is an entity obtaining a small data message (eg, RAN node, C-BS) in accordance with aspects described herein for access layer security verification and/or It may be included in the small data message to obtain (eg, derive, generate) a third key (eg, DASK) that should be used for decryption.
A change in any key (eg, first, second, and/or third key) may, for example, cause time out, security, maintenance, detection of a key compromise, or the detection of a malicious device(s). It may be due to detection.
According to one aspect, when the key is invalid (eg, due to time expiration, security, maintenance, detection of key compromise, detection of malicious device(s)), an error message is sent to the cellular device and/or may be sent to a gateway (eg, C-SGN).
At the cellular device, upon obtaining the error message, the cellular device may send a request for a third key (eg, DASK) to the gateway (eg, C-SGN). The request for the third key may be referred to as a key request message (and alternatively may be referred to as a DASK update message). The key request message may not be protected by access layer security as discussed in the aspects described herein.
The key request message and/or error message triggers the gateway to send (eg, push) a new third key (eg, new DASK) to the cellular device using, for example, a secure NAS control message. For this purpose, it may be transmitted to a gateway. In one aspect, when a gateway changes a key for a given cellular device (eg, sending a new third key), the gateway sends a second key to other cellular devices (eg, a compromised second key of the third keys). may simultaneously provision separate new keys to devices that may be based on However, according to other aspects, when the gateway changes a key for a given cellular device (eg, sends a new third key), the gateway may not simultaneously provision separate new keys to other cellular devices. have.
Alternatively, a key request message (eg, DASK update) may be triggered by the device by sending an old key protected message to a gateway (eg, C-SGN).
A gateway (eg, C-SGN) may concurrently use multiple different first keys (eg, MASKs) and corresponding different second keys (eg, BASKs). Simultaneous use of different first keys and corresponding different second keys may, for example, reduce the impact of key changes and/or improve security in general.
According to some aspects, an access layer security protected message may obtain a greater priority than a message that does not utilize access layer security protection at the RAN node (eg, C-BS) (eg, to may be prioritized). According to some aspects, an access layer security protected message gets a greater priority than a message that does not utilize access layer security protection at the RAN node when the RAN node (eg, C-BS) is congested or overloaded. may (eg, be prioritized relative to).
According to some aspects, CIoT may not support connected mode mobility (ie, handover procedure). Accordingly, access layer security in accordance with some aspects described herein may also not support connected mode mobility.
According to some aspects described herein, when a cellular device (eg, CIoT device) attaches to a new RAN node (eg, C-BS), the cellular device sends a key request message as described above. can also be sent. For example, the cellular device may send a key request message to the new RAN node. According to some aspects, once the cellular device is attached to a previously attached RAN node (eg, C-BS), the cellular device (if the third key is not removed and/or any associated key index changes) otherwise) the third key (eg DASK) associated with the previously attached RAN node may be used.
15 is a schematic illustration of a portion of a wireless communication network 1500 that includes a RAN 1502 and multiple communication entities as may appear in some aspects of the present disclosure. As described herein, a cellular device, a CIoT device, an LTE wireless cellular device, and/or a machine-type communication wireless cellular device can be, for example, an IoT device 1504 , a smart alarm 1506 , a remote sensor 1508 . , smart phone 1510, mobile phone 1512, smart meter 1514, personal digital assistant (PDA) 1516, personal computer 1518, mesh node 1520, and/or tablet computer 1522 may reside in, or may be part of. Of course, the illustrated devices or components are examples, and any suitable node or device may appear within a wireless communication network within the scope of the present disclosure. These examples are provided to illustrate certain concepts of this disclosure. Those skilled in the art will recognize that these are exemplary in nature and that other examples may be included within the scope of this disclosure and the appended claims.
Those skilled in the art will readily appreciate that the various aspects described throughout this disclosure may be extended to any suitable telecommunication system, network architecture, and communication standard. As an example, the various aspects may be applied to UMTS systems such as W-CDMA, TD-SCDMA, and TD-CDMA. Various aspects may also include Long Term Evolution (LTE) (in FDD, TDD, or both modes), LTE-Advanced (LTE-A) (in FDD, TDD, or both modes), CDMA 2000, EV- Systems employing Evolution-Data Optimized (DO), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Ultra-Wideband (UWB), Bluetooth, and/or not yet It may apply to other suitable systems, including those described by undefined wide area network standards. The actual telecommunication standard, network architecture, and/or communication standard employed will depend on the particular application and overall design constraints imposed on the system.
Within this disclosure, the word "exemplary" is used to mean "serving as an example, instance, or illustration." Any implementation or aspect described herein as "exemplary" is not necessarily to be construed as advantageous or preferred over other aspects of the disclosure. Likewise, the term "aspects" does not require that all aspects of the present disclosure include the discussed feature, advantage, or mode of operation. The term "coupled" is used herein to refer to a direct or indirect mechanical and/or electrical coupling between two objects. For example, if object A physically touches and/or electrically communicates with object B, and object B physically touches and/or electrically communicates with object C, then objects A and C are - they directly physically communicate with each other Even if they are not in touch and/or in electrical communication - they may still be considered coupled to each other. For example, a first die may be coupled to a second die in the package even if the first die is never in direct physical contact with the second die. The terms "circuit" and "circuitry" are used broadly, and when connected and configured, a hardware implementation of electrical devices and conductors that, when connected and configured, enables performance of the functions described in this disclosure, without limitation as to the type of electronic circuits. are intended to include both software implementations of instructions and information that, when executed by a processor, enable performance of the functions described in this disclosure.
One or more of the components, blocks, features, and/or functions illustrated above may be rearranged and/or combined into a single component, block, feature, or function, or multiple components, blocks, features, and / or may be implemented with functions. Additional components, blocks, features, and/or functions may also be added without departing from the novel features disclosed herein. The apparatus, devices, and/or components illustrated above are adapted (eg, devised, constructed, employed, implemented, and/or programmed). The algorithms described herein may also be efficiently implemented in software and/or embedded in hardware.
It should be understood that the specific order or hierarchy of blocks in the disclosed methods is illustrative of exemplary processes. It is understood that the specific order or hierarchy of blocks in the methods may be rearranged. The accompanying method claims present elements of the various blocks in a sample order, and are not intended to be limited to the specific order or hierarchy presented unless specifically recited herein.
The previous description is provided to enable any person skilled in the art to practice the various aspects described herein. Various modifications to these aspects will be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to other aspects. Accordingly, the claims are not intended to be limited to the aspects shown herein, but are to be accorded the widest scope consistent with the language of the claims, wherein reference to an element in the singular unless specifically stated otherwise. It is not intended to mean "one and only one", but rather "one or more". Unless specifically stated otherwise, the term "some" refers to one or more. A phrase referring to "at least one of" a list of items refers to any combination of those items, including single members. As an example, "at least one of a, b, or c" means a; b; c; a and b; a and c; b and c; and a, b, and c. All structural and functional equivalents to the elements of the various aspects described throughout this disclosure, known or later come to be known to those skilled in the art, are expressly incorporated herein by reference and are intended to be encompassed by the claims. Moreover, nothing disclosed herein is intended to be dedicated to the public regardless of whether such disclosure is explicitly recited in the claims. 35 USC §112(f) unless any claim element is expressly recited using the phrase "means for" or, in the case of a method claim, the element is recited using the phrase "step for." should not be construed under the provisions of
16 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US11659396B2 | Cited by | United States of America | Applicant |
| US11206542B2 | Cited by | United States of America | Applicant |
| US11444980B2 | Cited by | United States of America | Applicant |
| US11057774B1 | Cited by | United States of America | Applicant |
| US11558747B2 | Cited by | United States of America | Applicant |
| US11115824B1 | Cited by | United States of America | Applicant |
| US12537828B2 | Cited by | United States of America | Applicant |
| US11533624B2 | Cited by | United States of America | Applicant |
| US11824881B2 | Cited by | United States of America | Applicant |
| US11799878B2 | Cited by | United States of America | Applicant |
| US11070982B1 | Cited by | United States of America | Applicant |
| KR20100028598A | Cites | Republic of Korea | Search report |
| US2010316223A1 | Cites | United States of America | Search report |
| KR20110111256A | Cites | Republic of Korea | Search report |
| US2015319172A1 | Cites | United States of America | Search report |
| EP3395038B1 | Cites | European Patent Office (EPO) | Search report |
| S3-130853, Security aspects of connectionless Data Transmission, 3GPP TSG SA WG3 (Security) Meeting #72, 2013.07.08.* | Non-patent | – | Search report |
14 members in 7 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 62387499 | United States of America | – | |
| 201562387499 | United States of America | P | |
| 15199924 | United States of America | – | |
| 201615199924 | United States of America | A | |
| 2016066702 | United States of America | W |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| US2017187691A1 | United States of America | A1 | |
| WO2017112491A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2017112491A3 | World Intellectual Property Organization (WIPO) | A3 | |
| CN108432206A | China | A | |
| KR20180098251AThis record | Republic of Korea | A | |
| EP3395038A2 | European Patent Office (EPO) | A2 | |
| BR112018012596A2 | Brazil | A2 | |
| JP2019506779A | Japan | A | |
| US10298549B2 | United States of America | B2 | |
| US2019260717A1 | United States of America | A1 | |
| US10637835B2 | United States of America | B2 | |
| CN108432206B | China | B | |
| EP3395038B1 | European Patent Office (EPO) | B1 | |
| KR102710873B1 | Republic of Korea | B1 |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Written decision to grantGRNT | GRNT | |
| Decision to grant or registration of patent rightE701 | E701 | |
| Notification of reason for final refusalE90F | E90F | |
| Notification of reason for refusalE902 | E902 | |
| Request for examinationA201 | A201 |
Numbers
- Publication
- 10-2018-0098251
- Application
- 1020187016964
Titles4
- Korean
- 셀룰러 사물 인터넷에 대한 무상태 액세스 계층 보안
- English
- Stateless Access Layer Security for Cellular Internet of Things
- Unlabeled
- 셀룰러 사물 인터넷에 대한 무상태 액세스 계층 보안
- Unlabeled
- Stateless Access Layer Security for Cellular Internet of Things
Classification
- CPC, 19
- H04L63/123
- H04L63/0428
- H04L63/062
- H04L63/205
- Y04S40/18
- H04L63/16
- H04L67/12
- H04L63/1458
- H04W4/70
- H04L9/0822
- H04W12/041
- H04L9/14
- H04W12/0433
- H04W12/04
- H04W12/106
- H04W12/10
- H04W88/16
- H04L41/08
- G06F2221/2151
- IPC, 7
- H04L29 06
- H04L29 08
- H04L9 08
- H04L9 14
- H04W12 04
- H04W12 10
- H04W4 70