US2019208411A1PendingUtilityA1

Security framework for msg3 and msg4 in early data transmission

Assignee: INTEL CORPPriority: Mar 16, 2018Filed: Mar 6, 2019Published: Jul 4, 2019
Est. expiryMar 16, 2038(~11.6 yrs left)· nominal 20-yr term from priority
H04W 76/30H04L 9/3242H04L 2209/805H04L 9/0861H04L 2209/80H04W 84/042H04W 12/001H04W 12/0401H04W 74/0833H04W 12/041H04W 12/03
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods of a security framework for an RRC connection are described. The UE receives a release message that comprises a current Next Hop Chaining Counter (NCC). The UE derives a new KeNB* using the current NCC and transmits an EDT RA preamble to same or a different base station. After receiving an RAR with an uplink allocation, the UE transmits a RRCConnectionResumeRequest message. The UE transmits uplink data encrypted using KeNB* if the uplink allocation includes a data allocation sufficient for the data, fall backs to a legacy RRC connection procedure in which the stored KeNB* is discarded and then KeNB* is re-derived if the data allocation is insufficient for the data due to a CE level change, and fall backs to a legacy RRC connection procedure in which the stored KeNB* is used instead of discarding KeNB* if the uplink allocation excludes the data allocation.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An apparatus of a user equipment (UE), the UE configured as either a Bandwidth reduced Low complexity (BL) UE or a coverage enhancement (CE) UE or a Narrow Band Internet of Things (NB-IoT) UE, the apparatus comprising:
 a memory to store a current encryption key (K eNB ) and a current Next Hop Chaining Counter (NCC); and   processing circuitry arranged to:
 suspend a radio resource control (RRC) connection with a first base station; 
 after suspension of the RRC connection, select a random access (RA) preamble for transmission to a second base station, the RA preamble selected being:
 an early data transmission (EDT) RA preamble if:
 uplink user plane data that is less than a transport block size is buffered in the memory for transmission, and 
 an NCC received during suspension of the RRC connection is stored in the memory as the current NCC, and 
 
 otherwise a non-EDT RA preamble; 
 
 after transmission of the RA preamble, decode a random access response (RAR) from the second base station, the RAR comprising an uplink allocation for transmission of a RRCConnectionResumeRequest message; 
 in response to reception of the RAR, encode for transmission to the second base station:
 the RRCConnectionResumeRequest message, and 
 if the uplink allocation includes a data allocation in response to transmission of the EDT random access preamble, uplink data encrypted using a new encryption key (K eNB* ) derived using the current encryption key and the current NCC. 
 
   
     
     
         2 . The apparatus of  claim 1 , wherein:
 if the current NCC stored in the memory is not the NCC received from the first base station during suspension of the RRC connection, the RA preamble is the non-EDT RA preamble.   
     
     
         3 . The apparatus of  claim 1 , wherein:
 the current NCC stored in the memory is the NCC received from the first base station during suspension of the RRC connection,   the RA preamble is the EDT RA preamble, and   the processing circuitry is further arranged to derive the new encryption key using the current NCC prior to transmission of the RRCConnectionResumeRequest message.   
     
     
         4 . The apparatus of  claim 3 , wherein the processing circuitry is further arranged to:
 in response to the uplink allocation excluding the data allocation, fall back to a non-EDT RRC connection procedure in which the UE is configured to:
 enter an RRC_Connected state, and 
 avoid derivation of the new encryption key after reception, from the second base station, of a RRCConnectionResume message in response to transmission of the RRCConnectionResumeRequest. 
   
     
     
         5 . The apparatus of  claim 4 , wherein:
 the RRCConnectionResume message comprises an RRC NCC, and   the processing circuitry is further arranged to ignore the RRC NCC in encryption key derivation.   
     
     
         6 . The apparatus of  claim 3 , wherein:
 the memory is configured to store the current encryption key and the new encryption key derived prior to transmission of the RRCConnectionResumeRequest message,   the processing circuitry is further arranged to:
 increase a coverage enhancement (CE) level in response to failure to receive the RAR after transmission of the EDT RA preamble, the RAR received after the increase of the CE level, 
 determine whether the increase of the CE level results in the uplink allocation, which includes the data allocation, being insufficient to enable transmission of the RRCConnectionResumeRequest and uplink data, and 
 fall back to a non-EDT RRC connection procedure in response to a determination that the increase of the CE level results in the uplink allocation being insufficient to enable transmission of the RRCConnectionResumeRequest and uplink data. 
   
     
     
         7 . The apparatus of  claim 6 , wherein in the non-EDT RRC connection procedure, the processing circuitry is further arranged to:
 delete the new encryption key stored in the memory,   decode a RRCConnectionResume message, from the second base station, in response to transmission of the RRCConnectionResumeRequest message without transmission of the uplink data, the RRCConnectionResume message comprises an RCC NCC, and   derive another new encryption key using the RCC NCC and the current encryption key after reception of the RRCConnectionResume message, for transmission of the uplink data.   
     
     
         8 . The apparatus of  claim 3 , wherein:
 the memory is configured to store the current encryption key and the new encryption key derived prior to transmission of the RRCConnectionResumeRequest message, and   the processing circuitry is further arranged to:
 in response to transmission of the RRCConnectionResumeRequest message, decode, from the second base station, a RRCConnectionReject message with a suspend indication, and 
 in response to reception of the RRC Connection Reject message, enter an RRC_Idle state and delete the new encryption key from the memory. 
   
     
     
         9 . The apparatus of  claim 3 , wherein:
 the memory is configured to store the current encryption key and the new encryption key derived prior to transmission of the RRCConnectionResumeRequest message, and   the processing circuitry is further arranged to:
 in response to transmission of the RRCConnectionResumeRequest message, decode, from the second base station, a RRCConnectionRelease message with a suspend indication, and 
 in response to reception of the RRCConnectionRelease message, delete the current encryption key from the memory. 
   
     
     
         10 . The apparatus of  claim 3 , wherein:
 the memory is configured to store the current encryption key and the new encryption key derived prior to transmission of the RRCConnectionResumeRequest message, and   the processing circuitry is further arranged to, after storage of the new encryption in the memory, delete the new encryption key in response to one of:
 expiration of a timer T300 before reception of a RRC message in response to transmission of the RRCConnectionResumeRequest message, or 
 reselection of a cell during a RA procedure for EDT. 
   
     
     
         11 . The apparatus of  claim 1 , wherein:
 the new NCC was received from the first base station during suspension of the RRC connection, and   the current NCC is used to derive an encryption key for a non-EDT RRC Connection procedure and the new NCC is used to derive an encryption key for an EDT RRC Connection procedure.   
     
     
         12 . The apparatus of  claim 1 , wherein:
 the memory is configured to store the new NCC, and   the processing circuitry is further arranged to:
 if the UE initiates EDT compare the current and new NCC prior to transmission of the RA preamble to determine whether to use vertical or horizontal derivation to derive the new encryption key, and 
 if the UE initiates a non-EDT RRC connection, wait until a RRCConnectionResume message containing a newer NCC is received from the second base station and compare the newer NCC with the current NCC to determine whether to use vertical or horizontal derivation to derive the new encryption key. 
   
     
     
         13 . The apparatus of  claim 1 , wherein:
 the first base station is a legacy source evolved NodeB (eNB) that does not support EDT and the second base station is a target eNB that supports EDT, or the first base station is a Rel-15 eNB that has disabled EDT and the second base station is an eNB that has enabled EDT,   if the current NCC stored in the memory is not the NCC received from the first base station during suspension of the RRC connection, and   the RA preamble is the non-EDT RA preamble.   
     
     
         14 . The apparatus of  claim 1 , wherein the processing circuitry comprises:
 a baseband processor configured to encode transmissions to, and decode transmissions from, the first and second base stations.   
     
     
         15 . An apparatus of a base station, the apparatus comprising:
 a memory to store a current Next Hop Chaining Counter (NCC);   processing circuitry arranged to:
 decode, from a user equipment (UE), the UE configured as either a Bandwidth reduced Low complexity (BL) UE or a coverage enhancement (CE) UE or a Narrow Band Internet of Things (NB-IoT) UE, an early data transmission (EDT) random access (RA) preamble; 
 encode, for transmission to the UE, a random access response (RAR) in response to reception of the EDT RA preamble, the RAR comprising an uplink grant for transmission of a RRCConnectionResumeRequest message by the UE; 
 in response to reception of the RAR, decode a radio resource control (RRC)ConnectionResumeRequest message, and, if the uplink grant includes a data grant, uplink data encrypted using a new encryption key (K eNB* ) derived using the current NCC and an encryption key (K eNB ) stored in the UE, the new encryption key stored in the UE; and 
 in response to reception of the RRCConnectionResumeRequest message, encode for transmission to the UE one of:
 in response to reception of the uplink data, an RRCConnectionRelease containing downlink data and a suspend indication, or 
 if the data grant is not included in the uplink grant, an RRCConnectionResume message containing a RRC NCC to be ignored by the UE, or, if the uplink data is not present despite the data grant being included in the uplink grant, an RRCConnectionResume message containing the current NCC. 
 
   
     
     
         16 . The apparatus of  claim 15 , wherein the processing circuitry is further arranged to:
 ignore the RRC NCC in encryption key derivation, and   determine that the uplink data is not present despite the data grant being included in the uplink grant due to a change in coverage enhancement (CE) level of the UE.   
     
     
         17 . A non-transitory computer-readable storage medium that stores instructions for execution by one or more processors of a user equipment (UE), the one or more processors to configure the UE to, when the instructions are executed:
 receive a radio resource control (RRC) ConnectionRelease message that suspends communication with a first base station, the RRCConnectionRelease message comprising a current Next Hop Chaining Counter (NCC);   transmit an early data transmission (EDT) random access (RA) preamble to a second base station;   derive a new encryption key (K eNB* ) using the current NCC;   decode a random access response (RAR) from the second base station in response to transmitting the EDT RA preamble, the RAR comprising an uplink grant for transmission of a RRCConnectionResumeRequest message;   in response to reception of the RAR, transmit to the second base station:
 a RRCConnectionResumeRequest message, 
 if the uplink grant includes a data grant, uplink data encrypted using the new encryption key, and 
 if the uplink grant excludes the data grant, fall back to a first non-EDT RRC connection procedure in which, after reception of a RRCConnectionResume message containing an RRC NCC, the UE enters an RRC_Connected state and uses the new encryption key for data encryption instead of discarding the new encryption key stored in memory and then re-deriving the new encryption key using the RRC NCC. 
   
     
     
         18 . The medium of  claim 17 , wherein the instructions, when executed, further configure the UE to:
 increase a coverage enhancement (CE) level in response to failure to receive the RAR after transmission of the EDT RA preamble, the RAR received after the increase of the CE level,   determine whether the increase of the CE level results in the uplink grant, which includes the data grant, being insufficient to enable transmission of the RRCConnectionResumeRequest message and uplink data, and   fall back to a second non-EDT RRC connection procedure in response to a determination that the increase of the CE level results in the uplink grant being insufficient to enable transmission of the RRCConnectionResumeRequest message and uplink data.   
     
     
         19 . The medium of  claim 18 , wherein the instructions, when executed, further configure the UE to:
 delete the new encryption key stored in the memory,   receive a first RRCConnectionResume message, from the second base station, in response to transmission of the RRCConnectionResumeRequest message without transmission of the uplink data, the first RRCConnectionResume message comprising the current NCC, and   derive another new encryption key using the current NCC after reception of the first RRC Connection Resume message, for transmission of the uplink data.   
     
     
         20 . The medium of  claim 17 , wherein the instructions, when executed, further configure the UE to:
 in response to transmission of the RRCConnectionResumeRequest message one of:
 receive, from the second base station, a RRCConnectionReject message with a suspend indication, and in response to reception of the RRCConnectionReject message, enter an RRC_Idle mode and delete the new encryption key from the memory, 
 receive, from the second base station, a RRCConnectionRelease message with a suspend indication, and in response to reception of the RRCConnectionRelease message, delete a current encryption key stored in the memory, or 
 after storage of the new encryption key in the memory, delete the new encryption key in response to one of:
 expiration of a timer T300 before reception of the RRCConnectionRelease message, or 
 reselection of a cell during a RA procedure for EDT.

Join the waitlist — get patent alerts

Track US2019208411A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.