WO2023043724A1 - Securing application communication - Google Patents
Securing application communication Download PDFInfo
- Publication number
- WO2023043724A1 WO2023043724A1 PCT/US2022/043320 US2022043320W WO2023043724A1 WO 2023043724 A1 WO2023043724 A1 WO 2023043724A1 US 2022043320 W US2022043320 W US 2022043320W WO 2023043724 A1 WO2023043724 A1 WO 2023043724A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- session key
- freshness parameter
- processor
- naf
- application
- Prior art date
Links
- 238000004891 communication Methods 0.000 title claims abstract description 128
- 238000000034 method Methods 0.000 claims abstract description 93
- 230000001360 synchronised effect Effects 0.000 abstract description 2
- 230000006870 function Effects 0.000 description 47
- 238000003860 storage Methods 0.000 description 31
- 238000010586 diagram Methods 0.000 description 23
- 230000005540 biological transmission Effects 0.000 description 15
- 238000005516 engineering process Methods 0.000 description 15
- 230000008569 process Effects 0.000 description 13
- 238000012545 processing Methods 0.000 description 13
- 238000007726 management method Methods 0.000 description 11
- 230000001413 cellular effect Effects 0.000 description 6
- GVVPGTZRZFNKDS-JXMROGBWSA-N geranyl diphosphate Chemical compound CC(C)=CCC\C(C)=C\CO[P@](O)(=O)OP(O)(O)=O GVVPGTZRZFNKDS-JXMROGBWSA-N 0.000 description 5
- 238000010295 mobile communication Methods 0.000 description 5
- 230000002093 peripheral effect Effects 0.000 description 5
- 239000000758 substrate Substances 0.000 description 4
- 238000004590 computer program Methods 0.000 description 3
- 230000007246 mechanism Effects 0.000 description 3
- 230000003287 optical effect Effects 0.000 description 3
- 230000004044 response Effects 0.000 description 3
- 230000011664 signaling Effects 0.000 description 3
- 230000008901 benefit Effects 0.000 description 2
- 125000004122 cyclic group Chemical group 0.000 description 2
- 230000005670 electromagnetic radiation Effects 0.000 description 2
- 230000002708 enhancing effect Effects 0.000 description 2
- 230000007774 longterm Effects 0.000 description 2
- 238000013507 mapping Methods 0.000 description 2
- 239000004065 semiconductor Substances 0.000 description 2
- 238000012546 transfer Methods 0.000 description 2
- LHMQDVIHBXWNII-UHFFFAOYSA-N 3-amino-4-methoxy-n-phenylbenzamide Chemical compound C1=C(N)C(OC)=CC=C1C(=O)NC1=CC=CC=C1 LHMQDVIHBXWNII-UHFFFAOYSA-N 0.000 description 1
- 230000006978 adaptation Effects 0.000 description 1
- 230000002776 aggregation Effects 0.000 description 1
- 238000004220 aggregation Methods 0.000 description 1
- 238000013459 approach Methods 0.000 description 1
- 230000003190 augmentative effect Effects 0.000 description 1
- 239000000969 carrier Substances 0.000 description 1
- 238000006243 chemical reaction Methods 0.000 description 1
- 230000006835 compression Effects 0.000 description 1
- 238000007906 compression Methods 0.000 description 1
- 230000008878 coupling Effects 0.000 description 1
- 238000010168 coupling process Methods 0.000 description 1
- 238000005859 coupling reaction Methods 0.000 description 1
- 238000013500 data storage Methods 0.000 description 1
- 230000006837 decompression Effects 0.000 description 1
- 230000001419 dependent effect Effects 0.000 description 1
- 238000013461 design Methods 0.000 description 1
- 238000001514 detection method Methods 0.000 description 1
- 239000000835 fiber Substances 0.000 description 1
- 238000001914 filtration Methods 0.000 description 1
- 230000010365 information processing Effects 0.000 description 1
- 238000004519 manufacturing process Methods 0.000 description 1
- 238000005259 measurement Methods 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000005192 partition Methods 0.000 description 1
- APTZNLHMIGJTEW-UHFFFAOYSA-N pyraflufen-ethyl Chemical compound C1=C(Cl)C(OCC(=O)OCC)=CC(C=2C(=C(OC(F)F)N(C)N=2)Cl)=C1F APTZNLHMIGJTEW-UHFFFAOYSA-N 0.000 description 1
- 238000009877 rendering Methods 0.000 description 1
- 238000013468 resource allocation Methods 0.000 description 1
- 230000011218 segmentation Effects 0.000 description 1
- 239000004984 smart glass Substances 0.000 description 1
- 238000001228 spectrum Methods 0.000 description 1
- 238000012384 transportation and delivery Methods 0.000 description 1
- 238000011144 upstream manufacturing Methods 0.000 description 1
- 238000010200 validation analysis Methods 0.000 description 1
- 210000000707 wrist Anatomy 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/043—Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
- H04W12/0431—Key distribution or pre-distribution; Key agreement
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0869—Generation of secret information including derivation or calculation of cryptographic keys or passwords involving random numbers or seeds
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/041—Key generation or derivation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2463/00—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
- H04L2463/061—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying further key derivation, e.g. deriving traffic keys from a pair-wise master key
Definitions
- 5G Fifth Generation
- NR New Radio
- other communication technologies enable ultra-reliable low latency communication with user equipment (UEs) such as wireless devices.
- UEs user equipment
- An Edge computing architecture may be used to deliver such services.
- An Edge computing architecture enables services to be provided from a network device or element (such as a server) that is located relatively closely to a UE, which may reduce end-to-end latency and decrease resource demand and consumption on a communication network.
- Some applications and services may employ or may require communication security to provide one or more functions.
- Various aspects include methods performed by a processor of a UE for securing communications. Some aspects may include generating a freshness parameter, generating a unique session key based on a first session key and the freshness parameter, sending the freshness parameter to a Network Application Function (NAF) in a configuration that will enable the NAF to generate the unique session key, and communicating with the NAF using the unique session key.
- NAF Network Application Function
- the freshness parameter may be generated by a security bootstrapping client of the UE, and an application client of the UE may communicate with the NAF using the unique session key.
- the security bootstrapping client of the UE may include one of a Generic Bootstrapping Architecture (GBA) client or an Authentication and Key Management for Applications (AKMA) client.
- the freshness parameter may be associated with a specific application of the UE.
- the unique session key may be associated with a specific application of the UE and the first session key may be associated with the UE.
- the specific application may include a specific instantiation of the application.
- Further aspects include a UE having a processor configured to perform one or more operations of any of the methods summarized above. Further aspects include processing devices for use in a UE configured with processor-executable instructions to perform operations of any of the methods summarized above. Further aspects include a non-transitory processor-readable storage medium having stored thereon processor-executable instructions configured to cause a processor of a UE to perform operations of any of the methods summarized above. Further aspects include a UE having means for performing functions of any of the methods summarized above. Further aspects include a system on chip for use in a UE and that includes a processor configured to perform one or more operations of any of the methods summarized above.
- Various aspects include methods performed by a processor of a network device for securing communications. Some aspects may include receiving by the NAF from a UE a freshness parameter, receiving from a Key Server Function (KSF) a first session key, generating based on the freshness parameter and the first session key a unique session key, and communicating with the UE using the unique session key.
- KSF Key Server Function
- the freshness parameter may be associated with a specific application of the UE.
- the freshness parameter may include a random value.
- the freshness parameter may include an incremented nonce value.
- the unique session key may be associated with a specific application of the UE, and the first session key may be associated with the UE.
- the specific application may include a specific instantiation of the application.
- Some aspects may include sending to the UE a request to start secure communication.
- receiving by the NAF from the UE the freshness parameter may include receiving the freshness parameter in a network service request message.
- Further aspects include a network device having a processor configured to perform one or more operations of any of the methods summarized above. Further aspects include processing devices for use in a network device configured with processor-executable instructions to perform operations of any of the methods summarized above. Further aspects include a non-transitory processor-readable storage medium having stored thereon processor-executable instructions configured to cause a processor of a network device to perform operations of any of the methods summarized above. Further aspects include a network device having means for performing functions of any of the methods summarized above. Further aspects include a system on chip for use in a network device and that includes a processor configured to perform one or more operations of any of the methods summarized above.
- FIG. 1A is a system block diagram illustrating an example communications system suitable for implementing any of the various embodiments.
- FIG. IB is a system block diagram illustrating an example Edge computing system suitable for use with various embodiments.
- FIG. 2 is a component block diagram illustrating an example computing and wireless modem system suitable for implementing any of the various embodiments.
- FIG. 3 is a component block diagram illustrating a software architecture including a radio protocol stack for the user and control planes in wireless communications suitable for implementing any of the various embodiments.
- FIGS. 4A and 4B are component block diagrams illustrating a system configured for enhancing coverage for initial access accordance with various embodiments.
- FIG. 5A is a block diagram illustrating an example system for bootstrapping application security suitable for use with various embodiments.
- FIG. 5B is a message flow diagram illustrating communications exchanged between a and a network device during a method 500b for securing communications according to various embodiments.
- FIG. 6 is a process flow diagram illustrating a method performed by a processor of a UE for securing communications according to various embodiments.
- FIG. 7 is a process flow diagram illustrating a method performed by a processor of a network device for securing communications according to various embodiments.
- FIG. 8 is a component block diagram of a network device suitable for use with various embodiments.
- FIG. 9 is a component block diagram of a UE suitable for use with various embodiments. DETAILED DESCRIPTION
- a key generating entity executing within a UE may be configured to generate a freshness parameter that the UE uses to generate a unique session key for use in a communication protocol, such as of a security bootstrapping operation.
- the UE sends the freshness parameter to the network device as part of the bootstrapping operations, and the network then uses the freshness parameter to generate the same unique session key for use in that communication protocol.
- the UE and the network device then use the generated unique session key to secure communications for a particular application or service.
- the UE and the network device may generate unique session keys for different applications or services.
- the UE e.g., Edge applications
- the network device e.g., an Edge server
- GBA Generic Bootstrapping Architecture
- AKMA Authentication and Key Management for Applications
- GBA Generic Bootstrapping Architecture
- AKMA Authentication and Key Management for Applications
- UE user equipment
- endpoint or user devices including wireless devices, wireless router devices, wireless appliances, cellular telephones, smartphones, portable computing devices, personal or mobile multi-media players, laptop computers, tablet computers, smartbooks, ultrabooks, palmtop computers, wireless electronic mail receivers, multimedia Internet-enabled cellular telephones, medical devices and equipment, biometric sensors/devices, wearable devices including smart watches, smart clothing, smart glasses, smart wrist bands, smart jewelry (for example, smart rings and smart bracelets), entertainment devices (for example, wireless gaming controllers, music and video players, satellite radios, etc.), wireless-network enabled Internet of Things (loT) devices including smart meters/sensors, industrial manufacturing equipment, large and small machinery and appliances for home or enterprise use, wireless communication elements within autonomous and semiautonomous vehicles, UEs affixed to or incorporated into various mobile platforms, global positioning system devices, and similar electronic devices that include a memory, wireless communication components and a programmable processor.
- endpoint or user devices including wireless devices, wireless router devices, wireless appliances, cellular telephones,
- SOC system on chip
- a single SOC may contain circuitry for digital, analog, mixed-signal, and radio-frequency functions.
- a single SOC also may include any number of general purpose or specialized processors (digital signal processors, modem processors, video processors, etc.), memory blocks (such as ROM, RAM, Flash, etc.), and resources (such as timers, voltage regulators, oscillators, etc.).
- SOCs also may include software for controlling the integrated resources and processors, as well as for controlling peripheral devices.
- SIP system in a package
- a SIP may include a single substrate on which multiple IC chips or semiconductor dies are stacked in a vertical configuration.
- the SIP may include one or more multichip modules (MCMs) on which multiple ICs or semiconductor dies are packaged into a unifying substrate.
- MCMs multichip modules
- a SIP also may include multiple independent SOCs coupled together via high speed communication circuitry and packaged in close proximity, such as on a single motherboard or in a single wireless device. The proximity of the SOCs facilitates high speed communications and the sharing of memory and resources.
- the terms “network,” “system,” “wireless network,” “cellular network,” and “wireless communication network” may interchangeably refer to a portion or all of a wireless network of a carrier associated with a wireless device and/or subscription on a wireless device.
- the techniques described herein may be used for various wireless communication networks, such as Code Division Multiple Access (CDMA), time division multiple access (TDMA), FDMA, orthogonal FDMA (OFDMA), single carrier FDMA (SC-FDMA) and other networks.
- CDMA Code Division Multiple Access
- TDMA time division multiple access
- FDMA frequency division multiple access
- OFDMA orthogonal FDMA
- SC-FDMA single carrier FDMA
- any number of wireless networks may be deployed in a given geographic area.
- Each wireless network may support at least one radio access technology, which may operate on one or more frequency or range of frequencies.
- a CDMA network may implement Universal Terrestrial Radio Access (UTRA) (including Wideband Code Division Multiple Access (WCDMA) standards), CDMA2000 (including IS- 2000, IS-95 and/or IS-856 standards), etc.
- UTRA Universal Terrestrial Radio Access
- WCDMA Wideband Code Division Multiple Access
- CDMA2000 including IS- 2000, IS-95 and/or IS-856 standards
- a TDMA network may implement GSM Enhanced Data rates for GSM Evolution (EDGE).
- an OFDMA network may implement Evolved UTRA (E-UTRA) (including LTE standards), Institute of Electrical and Electronics Engineers (IEEE) 802.11 (WiFi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash-OFDM®, etc.
- E-UTRA Evolved UTRA
- WiFi Institute of Electrical and Electronics Engineers
- WiMAX IEEE 802.16
- Flash-OFDM® Flash-OFDM®
- such services may be provided at least in part using an Edge computing architecture, which enables services to be provided from a network device or element (such as a server) that is located relatively closely to a UE.
- Providing services from an Edge device may reduce end-to-end latency and decrease resource demand and consumption on a communication network.
- GBA Generic Bootstrapping Architecture
- AKA 3 GPP Authentication and Key Agreement
- AKMA Authentication and Key Management for Applications
- AF Application Function
- Various embodiments include methods and computing devices configured to perform the methods for securing communications between a UE and a network device that provides individualized communication security for an application or service.
- the UE may generate a freshness parameter, such as by a security bootstrapping client of the UE (for example a GBA client).
- a first session key e.g., a root key that is shared with the network device
- the freshness parameter may be associated with a specific application executing on, or being provided to, the UE.
- a UE may have several different Edge applications executing on a processor of the UE that are communicating with the same Edge server.
- multiple simultaneous Edge applications might include a navigation application, a media (e.g., music) streaming application, and an augmented reality application, each of which should have a different unique key.
- each of these different applications may be assigned a unique freshness parameter that is combined with the first session key by both the UE and the Edge server, thereby providing a unique session key for each application without changing the first session key used for communications between the UE and the Edge server.
- the freshness parameter may include a random value.
- the freshness parameter may include an incremented value, such as a value of a counter that may be incremented each time a new unique session key is required (e.g., for a new application or new instantiation of an application).
- the incremented value may be used as a nonce value (e.g., an incremented nonce value).
- the UE may send the freshness parameter to a Network Application Function (NAF) of the network device (for example, a NAF in GBA, an Application Function in AKMA, or another suitable function) in a configuration that will enable the NAF to generate the unique session key.
- NAF Network Application Function
- the UE may send the freshness parameter as part of a network service request message (e.g., an Application Request message).
- the NAF may execute the same algorithm as used by the UE to generate the same unique session key using the freshness parameter received from the UE (i.e., a unique session key that is identical to the unique session key generated by the UE).
- the NAF may receive (or may request and receive in response to the request) the first session key (i.e., a session key that is identical to the first session key used by the UE) from a Key Server Function (KSF) executing on a network device (such as a Bootstrapping Server Function (BSF), an AKMA function, or another suitable function).
- KSF Key Server Function
- BSF Bootstrapping Server Function
- AKMA AKMA function
- the NAF may generate the unique session key.
- the UE and the NAF may then communicate using the unique session key without having exchanged the unique session key.
- the UE and the NAF may generate unique session keys for each application or service of the UE (or provided to the UE by the network device).
- the UE may receive from the NAF a request to start secure communication.
- the request to start secure communication may include a domain name of the NAF (e.g., a Fully Qualified Domain Name (FQDN)) and a security protocol identifier, such as for an interface between the NAF and the UE, such as a Ua interface.
- the UE may derive (generate, calculate) the first session key based on the domain name of the NAF and the security protocol identifier.
- the UE may generate the freshness parameter and send the freshness parameter to the network device (e.g., to the NAF) in response to the request to start secure communication received from the NAF.
- the network device e.g., to the NAF
- the UE may generate the freshness parameter and pass the freshness parameter to the NAF.
- the UE also may use the freshness parameter and the first session key to generate the unique session key.
- the first session key may be associated with the UE.
- the session key such as a Ks NAF, Ks int NAF, or Ks_ext_NAF, may be a session key used in GBA.
- the freshness parameter may be associated with a specific application (or service) of the UE.
- the freshness parameter may be associated with a specific instantiation of an application (or service) of the UE.
- the NAF may receive the freshness parameter from the UE and receive a version of the first session key from the KSF, and the NAF may generate its own version of the unique session key using the freshness parameter and the first session key.
- the UE may include the freshness parameter in an existing field of a message exchanged between the UE and the NAF.
- various embodiments may be implemented without changing a protocol or architecture of messages or message exchanges.
- the freshness parameter may be included in a “cnonce” field.
- the freshness parameter may be included in an existing field of a ClientHello message or another suitable message.
- a length of the freshness parameter may be configured to fit within the existing field and/or message.
- the UE may generate, and the UE and the network device may handle, the freshness parameter at a similar security level and/or in a similarly secured memory portion as other cryptographic or session keys.
- Various embodiments enable the UE and the network device to generate a unique key for each application or service for the UE without exchanging private or secure information, such as a private key. As a result, various embodiments improve the operation of the UE, the network device, and the communication system by improving the security of communications between the UE and the network device.
- FIG. 1A is a system block diagram illustrating an example communications system 100.
- the communications system 100 may be a 5G New Radio (NR) network, or any other suitable network such as a Long Term Evolution (LTE) network.
- NR 5G New Radio
- LTE Long Term Evolution
- FIG. 1A illustrates a 5G network
- later generation networks may include the same or similar elements. Therefore, the reference to a 5G network and 5G network elements in the following descriptions is for illustrative purposes and is not intended to be limiting.
- the communications system 100 may include a heterogeneous network architecture that includes a core network 140 and a variety of UEs (illustrated as UEs 120a- 120e in FIG. 1).
- the communications system 100 may include an Edge network 142 to provide network computing resources, applications, and/or services in proximity to the mobile devices via one or more network devices 142a.
- the communications system 100 also may include a number of base stations (illustrated as the BS 110a, the BS 110b, the BS 110c, and the BS 1 lOd) and other network entities.
- a base station is an entity that communicates with UEs, and also may be referred to as a Node B, an LTE Evolved nodeB (eNodeB or eNB), an access point (AP), a radio head, a transmit receive point (TRP), a New Radio base station (NR BS), a 5G NodeB (NB), a Next Generation NodeB (gNodeB or gNB), or the like.
- eNodeB or eNB LTE Evolved nodeB
- AP access point
- TRP transmit receive point
- NR BS New Radio base station
- NB 5G NodeB
- gNodeB or gNB Next Generation NodeB
- Each base station may provide communication coverage for a particular geographic area.
- the term “cell” can refer to a coverage area of a base station, a base station subsystem serving this coverage area, or a combination thereof, depending on the context in which the term is used.
- the core network 140 may be any type core network
- a base station 110a-l lOd may provide communication coverage for a macro cell, a pico cell, a femto cell, another type of cell, or a combination thereof.
- a macro cell may cover a relatively large geographic area (for example, several kilometers in radius) and may allow unrestricted access by UEs with a service subscription.
- a pico cell may cover a relatively small geographic area and may allow unrestricted access by UEs with service subscription.
- a femto cell may cover a relatively small geographic area (for example, a home) and may allow restricted access by UEs having association with the femto cell (for example, UEs in a closed subscriber group (CSG)).
- CSG closed subscriber group
- a base station for a macro cell may be referred to as a macro BS.
- a base station for a pico cell may be referred to as a pico BS.
- a base station for a femto cell may be referred to as a femto BS or a home BS.
- a base station 110a may be a macro BS for a macro cell 102a
- a base station 110b may be a pico BS for a pico cell 102b
- a base station 110c may be a femto BS for a femto cell 102c.
- a base station 110a-l lOd may support one or multiple (for example, three) cells.
- the terms “eNB”, “base station”, “NR BS”, “gNB”, “TRP”, “AP”, “node B”, “5G NB”, and “cell” may be used interchangeably herein.
- a cell may not be stationary, and the geographic area of the cell may move according to the location of a mobile base station.
- the base stations 110a-l lOd may be interconnected to one another as well as to one or more other base stations or network nodes (not illustrated) in the communications system 100 through various types of backhaul interfaces, such as a direct physical connection, a virtual network, or a combination thereof using any suitable transport network [0041]
- the base station 110a-l lOd may communicate with the core network 140 over a wired or wireless communication link 126.
- the UEs 120a- 120e may communicate with the base station 110a-l lOd over a wireless communication link 122.
- the wired communication link 126 may use a variety of wired networks (such as Ethernet, TV cable, telephony, fiber optic and other forms of physical network connections) that may use one or more wired communication protocols, such as Ethernet, Point-To-Point protocol, High-Level Data Link Control (HDLC), Advanced Data Communication Control Protocol (ADCCP), and Transmission Control Protocol/Intemet Protocol (TCP/IP).
- wired networks such as Ethernet, TV cable, telephony, fiber optic and other forms of physical network connections
- wired communication protocols such as Ethernet, Point-To-Point protocol, High-Level Data Link Control (HDLC), Advanced Data Communication Control Protocol (ADCCP), and Transmission Control Protocol/Intemet Protocol (TCP/IP).
- the communications system 100 also may include relay stations (such as relay BS 1 lOd).
- a relay station is an entity that can receive a transmission of data from an upstream station (for example, a base station or a UE) and send a transmission of the data to a downstream station (for example, a UE or a base station).
- a relay station also may be a wireless device (e.g., a UE) that can relay transmissions for other UEs.
- a relay station 1 lOd may communicate with macro the base station 110a and the UE 120d in order to facilitate communication between the base station 110a and the UE 120d.
- a relay station also may be referred to as a relay base station, a relay base station, a relay, etc.
- the communications system 100 may be a heterogeneous network that includes base stations of different types, for example, macro base stations, pico base stations, femto base stations, relay base stations, etc. These different types of base stations may have different transmit power levels, different coverage areas, and different impacts on interference in communications system 100. For example, macro base stations may have a high transmit power level (for example, 5 to 40 Watts) whereas pico base stations, femto base stations, and relay base stations may have lower transmit power levels (for example, 0.1 to 2 Watts).
- a network controller 130 may couple to a set of base stations and may provide coordination and control for these base stations.
- the network controller 130 may communicate with the base stations via a backhaul.
- the base stations also may communicate with one another, for example, directly or indirectly via a wireless or wireline backhaul.
- the UEs 120a, 120b, 120c may be dispersed throughout the communications system 100, and each UE may be stationary or mobile.
- a UE also may be referred to as an access terminal, a terminal, a mobile station, a subscriber unit, a station, wireless device, etc.
- a macro base station 110a may communicate with the communication network 140 over a wired or wireless communication link 126.
- the UEs 120a, 120b, 120c may communicate with a base station 110a-l lOd over a wireless communication link 122.
- the wireless communication links 122 and 124 may include a plurality of carrier signals, frequencies, or frequency bands, each of which may include a plurality of logical channels.
- the wireless communication links 122 and 124 may utilize one or more radio access technologies (RATs).
- RATs radio access technologies
- Examples of RATs that may be used in a wireless communication link include 3GPP LTE, 3G, 4G, 5G (such as NR), GSM, Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Worldwide Interoperability for Microwave Access (WiMAX), Time Division Multiple Access (TDMA), and other mobile telephony communication technologies cellular RATs.
- medium range protocols such as Wi-Fi, LTE-U, LTE-Direct, LAA, MuLTEfire
- relatively short range RATs such as ZigBee, Bluetooth, and Bluetooth Low Energy (LE).
- Certain wireless networks utilize orthogonal frequency division multiplexing (OFDM) on the downlink and single-carrier frequency division multiplexing (SC-FDM) on the uplink.
- OFDM and SC-FDM partition the system bandwidth into multiple (K) orthogonal subcarriers, which are also commonly referred to as tones, bins, etc.
- K orthogonal subcarriers
- Each subcarrier may be modulated with data.
- modulation symbols are sent in the frequency domain with OFDM and in the time domain with SC-FDM.
- the spacing between adjacent subcarriers may be fixed, and the total number of subcarriers (K) may be dependent on the system bandwidth.
- the spacing of the subcarriers may be 15 kHz and the minimum resource allocation (called a “resource block”) may be 12 subcarriers (or 180 kHz). Consequently, the nominal Fast File Transfer (FFT) size may be equal to 128, 256, 512, 1024 or 2048 for system bandwidth of 1.25, 2.5, 5, 10 or 20 megahertz (MHz), respectively.
- the system bandwidth also may be partitioned into subbands. For example, a subband may cover 1.08 MHz (i.e., 6 resource blocks), and there may be 1, 2, 4, 8 or 16 subbands for system bandwidth of 1.25, 2.5, 5, 10 or 20 MHz, respectively.
- NR new radio
- 5G 5G network
- NR may utilize OFDM with a cyclic prefix (CP) on the uplink (UL) and downlink (DL) and include support for half-duplex operation using time division duplex (TDD).
- CP cyclic prefix
- TDD time division duplex
- a single component carrier bandwidth of 100 MHz may be supported.
- NR resource blocks may span 12 sub-carriers with a sub-carrier bandwidth of 75 kHz over a 0.1 millisecond (ms) duration.
- Each radio frame may consist of 50 subframes with a length of 10 ms. Consequently, each subframe may have a length of 0.2 ms.
- Each subframe may indicate a link direction (i.e., DL or UL) for data transmission and the link direction for each subframe may be dynamically switched.
- Each subframe may include DL/UL data as well as DL/UL control data.
- Beamforming may be supported and beam direction may be dynamically configured.
- Multiple Input Multiple Output (MIMO) transmissions with precoding also may be supported.
- MIMO configurations in the DL may support up to eight transmit antennas with multi-layer DL transmissions up to eight streams and up to two streams per UE. Multi-layer transmissions with up to 2 streams per UE may be supported.
- Aggregation of multiple cells may be supported with up to eight serving cells.
- NR may support a different air interface, other than an OFDM-based air interface.
- Some UEs may be considered machine-type communication (MTC) or evolved or enhanced machine-type communication (eMTC) UEs.
- MTC and eMTC UEs include, for example, robots, drones, remote devices, sensors, meters, monitors, location tags, etc., that may communicate with a base station, another device (for example, remote device), or some other entity.
- a wireless computing platform may provide, for example, connectivity for or to a network (for example, a wide area network such as Internet or a cellular network) via a wired or wireless communication link.
- Some UEs may be considered Intemet-of- Things (IoT) devices or may be implemented as NB-IoT (narrowband internet of things) devices.
- the UE 120a- 120e may be included inside a housing that houses components of the UE 120a- 120e, such as processor components, memory components, similar components, or a combination thereof.
- any number of communications systems and any number of wireless networks may be deployed in a given geographic area.
- Each communications system and wireless network may support a particular radio access technology (RAT) and may operate on one or more frequencies.
- RAT also may be referred to as a radio technology, an air interface, etc.
- a frequency also may be referred to as a carrier, a frequency channel, etc.
- Each frequency may support a single RAT in a given geographic area in order to avoid interference between communications systems of different RATs.
- 4G/LTE and/or 5G/NR RAT networks may be deployed.
- a 5G non- standalone (NSA) network may utilize both 4G/LTE RAT in the 4G/LTE RAN side of the 5G NSA network and 5G/NR RAT in the 5G/NR RAN side of the 5G NSA network.
- the 4G/LTE RAN and the 5G/NR RAN may both connect to one another and a 4G/LTE core network (e.g., an evolved packet core (EPC) network) in a 5G NSA network.
- EPC evolved packet core
- Other example network configurations may include a 5G standalone (SA) network in which a 5G/NR RAN connects to a 5G core network.
- SA 5G standalone
- two or more UEs may communicate directly using one or more sidelink channels (for example, without using a base station 1 lOa-d as an intermediary to communicate with one another).
- the UEs 120a- 120e may communicate using peer-to-peer (P2P) communications, device-to-device (D2D) communications, a vehicle-to-everything (V2X) protocol (which may include a vehicle-to-vehicle (V2V) protocol, a vehicle-to-infrastructure (V2I) protocol, or similar protocol), a mesh network, or similar networks, or combinations thereof.
- V2X vehicle-to-everything
- the UE 120a- 120e may perform scheduling operations, resource selection operations, as well as other operations described elsewhere herein as being performed by the base station 110a- HOd.
- FIG. IB is a system block diagram illustrating an example Edge computing system 150 suitable for use with various embodiments.
- Edge computing system 150 may include the Edge network 142 and a UE 170 (e.g., the UE 120a-120e) configured to communicate via a 3GPP core network 160.
- the Edge data network 152 may include an Edge application server 154 and one or more Edge enabler server(s) 156, in communication with an Edge configuration server 158. Examples of the Edge application server 154, Edge enabler server(s) 156, and Edge configuration server 158 include the network device 142a.
- the UE 170 may include an application client(s) 172 in communication with one or more Edge enabler client(s) 174.
- Each of the elements of the Edge computing system 150 may communicate over an Edge interface (e.g., EDGE-1, EDGE-2, . . . EDGE-9).
- Edge interface e.g., EDGE-1, EDGE-2, . . . EDGE
- the Edge application server 154 and the application client(s) 172 each may be configured to process computing tasks, and may communicate application data traffic (i.e., data related to a computing task, an application, a service, etc.) via the 3GPP core network 160.
- the Edge enabler server(s) 156 may be configured to maintain and advertise (e.g., to devices such as the UE 170) applications provided by the Edge application server(s) 154.
- the Edge configuration server 158 may be configured to manage communication within and among one or more Edge data networks 152.
- the Edge application server(s) 154 may provide information about its applications and their capabilities to the Edge enabler server(s) 156 via the EDGE-3 interface.
- the Edge enabler server(s) 156 may provide information about the Edge data network 152 to the Edge configuration server 158 via the EDGE-6 interface.
- the Edge application server(s) 154 and the Edge enabler server(s) 156 may communicate with the 3 GPP core network 160 via the EDGE-7 interface and the EDGE-2 interface, respectively.
- the Edge enabler client(s) 174 may obtain information about the available Edge data networks 152 from the Edge enabler server(s) 156 via the EDGE-1 interface (and/or from the Edge configuration server 158 via the EDGE-4 interface). In some embodiments, the Edge enabler client(s) 174 may obtain information about Edge application server(s) 154 such as available applications and their capabilities via the EDGE-4 interface. In some embodiments, the Edge enabler client 174, the Edge enabler server(s) 156, and the Edge configuration server 158 may employ a discovery and provisioning procedure via their respective Edge interfaces.
- the application client 172 may communicate with the Edge enabler client(s) 174 via the EDGE-5 interface.
- the Edge enabler client(s) 174 may obtain information about available Edge data networks 152 from the Edge configuration server 158 via the EDGE-4 interface, and may coordinate the use of the Edge application server(s) 154 with the Edge enabler server(s) 156 via the EDGE-1 interface.
- the Edge enabler server(s) 156 may coordinate with one another via the EDGE-9 interface.
- FIG. 2 is a component block diagram illustrating an example computing and wireless modem system 200 suitable for implementing any of the various embodiments.
- Various embodiments may be implemented on a number of single processor and multiprocessor computer systems, including a system-on-chip (SOC) or system in a package (SIP).
- SOC system-on-chip
- SIP system in a package
- the illustrated example computing system 200 (which may be a SIP in some embodiments) includes a two SOCs 202, 204 coupled to a clock 206, a voltage regulator 208, and a wireless transceiver 266 configured to send and receive wireless communications via an antenna (not shown) to/from UEs, such as a base station 110a.
- the first SOC 202 may operate as central processing unit (CPU) of the UE that carries out the instructions of software application programs by performing the arithmetic, logical, control and input/output (I/O) operations specified by the instructions.
- the second SOC 204 may operate as a specialized processing unit.
- the second SOC 204 may operate as a specialized 5G processing unit responsible for managing high volume, high speed (such as 5 Gbps, etc.), or very high frequency short wave length (such as 28 GHz mmWave spectrum, etc.) communications.
- the first SOC 202 may include a digital signal processor (DSP) 210, a modem processor 212, a graphics processor 214, an application processor 216, one or more coprocessors 218 (such as vector co-processor) connected to one or more of the processors, memory 220, custom circuity 222, system components and resources 224, an interconnection/bus module 226, one or more temperature sensors 230, a thermal management unit 232, and a thermal power envelope (TPE) component 234.
- DSP digital signal processor
- modem processor 212 such as graphics processing circuitry
- application processor 216 such as vector co-processor
- coprocessors 218 such as vector co-processor
- the second SOC 204 may include a 5G modem processor 252, a power management unit 254, an interconnection/bus module 264, a plurality of mmWave transceivers 256, memory 258, and various additional processors 260, such as an applications processor, packet processor, etc.
- Each processor 210, 212, 214, 216, 218, 252, 260 may include one or more cores, and each processor/core may perform operations independent of the other processors/cores.
- the first SOC 202 may include a processor that executes a first type of operating system (such as FreeBSD, LINUX, OS X, etc.) and a processor that executes a second type of operating system (such as MICROSOFT WINDOWS 10).
- a processor cluster architecture such as a synchronous processor cluster architecture, an asynchronous or heterogeneous processor cluster architecture, etc.
- the first and second SOC 202, 204 may include various system components, resources and custom circuitry for managing sensor data, analog-to-digital conversions, wireless data transmissions, and for performing other specialized operations, such as decoding data packets and processing encoded audio and video signals for rendering in a web browser.
- the system components and resources 224 of the first SOC 202 may include power amplifiers, voltage regulators, oscillators, phase-locked loops, peripheral bridges, data controllers, memory controllers, system controllers, access ports, timers, and other similar components used to support the processors and software clients running on a UE.
- the system components and resources 224 or custom circuitry 222 also may include circuitry to interface with peripheral devices, such as cameras, electronic displays, wireless communication devices, external memory chips, etc.
- the first and second SOC 202, 204 may communicate via interconnection/bus module 250.
- the various processors 210, 212, 214, 216, 218, may be interconnected to one or more memory elements 220, system components and resources 224, and custom circuitry 222, and a thermal management unit 232 via an interconnection/bus module 226.
- the processor 252 may be interconnected to the power management unit 254, the mmWave transceivers 256, memory 258, and various additional processors 260 via the interconnection/bus module 264.
- the interconnection/bus module 226, 250, 264 may include an array of reconfigurable logic gates or implement a bus architecture (such as CoreConnect, AMBA, etc.). Communications may be provided by advanced interconnects, such as high- performance networks-on chip (NoCs).
- NoCs high- performance networks-on chip
- the first or second SOCs 202, 204 may further include an input/output module (not illustrated) for communicating with resources external to the SOC, such as a clock 206 and a voltage regulator 208.
- resources external to the SOC such as clock 206, voltage regulator 208 may be shared by two or more of the internal SOC processors/cores.
- FIG. 3 is a component block diagram illustrating a software architecture 300 including a radio protocol stack for the user and control planes in wireless communications suitable for implementing any of the various embodiments.
- the UE 320 may implement the software architecture 300 to facilitate communication between a UE 320 (e.g., the UE 120a- 120e, 200) and a network device 350 (e.g., network device 142a in the Edge network 142) of a communication system (e.g., 100).
- layers in software architecture 300 may form logical connections with corresponding layers in software of the network device 350.
- the software architecture 300 may be distributed among one or more processors (e.g., the processors 212, 214, 216, 218, 252, 260). While illustrated with respect to one radio protocol stack, in a multi-SIM (subscriber identity module) UE, the software architecture 300 may include multiple protocol stacks, each of which may be associated with a different SIM (e.g., two protocol stacks associated with two SIMs, respectively, in a dual-SIM wireless communication device). While described below with reference to LTE communication layers, the software architecture 300 may support any of variety of standards and protocols for wireless communications, and/or may include additional protocol stacks that support any of variety of standards and protocols wireless communications.
- processors e.g., the processors 212, 214, 216, 218, 252, 260.
- the software architecture 300 may include multiple protocol stacks, each of which may be associated with a different SIM (e.g., two protocol stacks associated with two SIMs, respectively, in a dual-SIM wireless communication device). While described below with reference to L
- the software architecture 300 may include a Non-Access Stratum (NAS) 302 and an Access Stratum (AS) 304.
- the NAS 302 may include functions and protocols to support packet filtering, security management, mobility control, session management, and traffic and signaling between a SIM(s) of the UE (such as SIM(s) 204) and its core network 140.
- the AS 304 may include functions and protocols that support communication between a SIM(s) (such as SIM(s) 204) and entities of supported access networks (such as a base station).
- the AS 304 may include at least three layers (Layer 1, Layer 2, and Layer 3), each of which may contain various sub-layers.
- Layer 1 (LI) of the AS 304 may be a physical layer (PHY) 306, which may oversee functions that enable transmission or reception over the air interface via a wireless transceiver (e.g., 266).
- PHY physical layer
- Examples of such physical layer 306 functions may include cyclic redundancy check (CRC) attachment, coding blocks, scrambling and descrambling, modulation and demodulation, signal measurements, MIMO, etc.
- the physical layer may include various logical channels, including the Physical Downlink Control Channel (PDCCH) and the Physical Downlink Shared Channel (PDSCH).
- PDCH Physical Downlink Control Channel
- PDSCH Physical Downlink Shared Channel
- Layer 2 (L2) of the AS 304 may be responsible for the link between the UE 320 and the network device 350 over the physical layer 306.
- Layer 2 may include a media access control (MAC) sublayer 308, a radio link control (RLC) sublayer 310, a packet data convergence protocol (PDCP) 312 sublayer, and a Service Data Adaptation Protocol (SDAP) 317 sublayer each of which form logical connections terminating at the network device 350.
- MAC media access control
- RLC radio link control
- PDCP packet data convergence protocol
- SDAP Service Data Adaptation Protocol
- Layer 3 (L3) of the AS 304 may include a radio resource control (RRC) sublayer 3.
- RRC radio resource control
- the software architecture 300 may include additional Layer 3 sublayers, as well as various upper layers above Layer 3.
- the RRC sublayer 313 may provide functions including broadcasting system information, paging, and establishing and releasing an RRC signaling connection between the UE 320 and the network device 350.
- the SDAP sublayer 317 may provide mapping between Quality of Service (QoS) flows and data radio bearers (DRBs).
- QoS Quality of Service
- DRBs data radio bearers
- the PDCP sublayer 312 may provide uplink functions including multiplexing between different radio bearers and logical channels, sequence number addition, handover data handling, integrity protection, ciphering, and header compression.
- the PDCP sublayer 312 may provide functions that include in-sequence delivery of data packets, duplicate data packet detection, integrity validation, deciphering, and header decompression.
- the RLC sublayer 310 may provide segmentation and concatenation of upper layer data packets, retransmission of lost data packets, and Automatic Repeat Request (ARQ).
- ARQ Automatic Repeat Request
- the RLC sublayer 310 functions may include reordering of data packets to compensate for out-of-order reception, reassembly of upper layer data packets, and ARQ.
- MAC sublayer 308 may provide functions including multiplexing between logical and transport channels, random access procedure, logical channel priority, and hybrid- ARQ (HARQ) operations.
- the MAC layer functions may include channel mapping within a cell, de-multiplexing, discontinuous reception (DRX), and HARQ operations.
- the software architecture 300 may provide functions to transmit data through physical media, the software architecture 300 may further include at least one host layer 314 to provide data transfer services to various applications in the UE 320.
- application-specific functions provided by the at least one host layer 314 may provide an interface between the software architecture and the general purpose processor 206.
- the software architecture 300 may include one or more higher logical layer (such as transport, session, presentation, application, etc.) that provide host layer functions.
- the software architecture 300 may include a network layer (such as Internet protocol (IP) layer) in which a logical connection terminates at a packet data network (PDN) gateway (PGW).
- the software architecture 300 may include an application layer in which a logical connection terminates at another device (such as end user device, server, etc.).
- the software architecture 300 may further include in the AS 304 a hardware interface 316 between the physical layer 306 and the communication hardware (such as one or more radio frequency (RF) transceivers).
- RF radio frequency
- FIGS. 4A and 4B are component block diagrams illustrating a system 400 configured for enhancing coverage for initial access accordance with various embodiments.
- the system 400 may include a UE 402 (e.g., 120a- 120e, 170, 320) and a network device 404 (e.g., 142a, 154, 156, 158, 350).
- the UE 402 and the network device 404 may exchange wireless communications in order to establish a wireless communication link (e.g., 122).
- the UE 402 and the network device 404 may include one or more processors 428, 432 coupled to electronic storage 426, 430 and a wireless transceiver (e.g., 266).
- the wireless transceiver 266 may be configured to receive messages sent in transmissions and pass such message to the processor(s) 428, 432 for processing.
- the processor 428, 432 may be configured to send messages for transmission to the wireless transceiver 266 for transmission.
- the processor(s) 432 may be configured by machine- readable instructions 434.
- Machine-readable instructions 406 may include one or more instruction modules.
- the instruction modules may include computer program modules.
- the instruction modules may include one or more of a freshness parameter module 436, a unique session key module 438, a TX/RX module 440, and/or other instruction modules.
- the freshness parameter module 436 may be configured to generate a freshness parameter.
- the freshness parameter module 436 may execute within a security bootstrapping client of the UE 402, such as a GBA client.
- the freshness parameter module 436 use a random number generator to generate a random number for use as the freshness parameter.
- the freshness parameter module 436 use a counter to generate nonce value for use as the freshness parameter.
- the unique session key module 438 may be configured to generate a unique session key based on a first session key and the freshness parameter.
- the freshness parameter may be associated with a specific application of the UE 402.
- the first session key may be associated with the UE 402.
- the unique session key may be associated with a specific application of the UE 402.
- the TX/RX module 440 may be configured to enable communications with the network device 404, e.g., via the wireless transceiver 266.
- the TX/RX module 440 may be configured to send the freshness parameter to a NAF of the network device 404 in a configuration that will enable the NAF to generate the unique session key (e.g., via the wireless transceiver 266).
- the TX/RX module 440 may be configured to communicate with the network device 404 using the unique session key.
- the TX/RX module 440 may be configured to receive from the NAF a request to start secure communications including a domain name of the NAF and a security protocol identifier.
- Machine-readable instructions 406 may include one or more instruction modules.
- the instruction modules may include computer program modules.
- the instruction modules may include one or more of a freshness parameter module 408, a unique session key module 410, a transmit/receive (TX/RX) module 412, and/or other instruction modules.
- the freshness parameter module 408 may be configured to receive from the UE 402 the freshness parameter.
- the unique session key module 410 may be configured to receive from a KSF of the network device 404 a first session key.
- the unique session key module 410 may be configured to generate based on the freshness parameter and the first session key a unique session key.
- the TX/RX module 412 may be configured to communicate with the UE 402 using the unique session key (e.g., via the wireless transceiver 266).
- the TX/RX module 412 may be configured to send to the UE 402 a request to start secure communication including a domain name of the NAF and a security protocol identifier.
- the UE 402 and the network device 404 may be operatively linked via one or more wireless communication links (e.g., wireless communication link 122). It will be appreciated that this is not intended to be limiting, and that the scope of this disclosure includes embodiments in which the UE 402 and the network device 404 may be operatively linked via some other communication medium.
- the electronic storage 426, 430 may include non-transitory storage media that electronically stores information.
- the electronic storage media of electronic storage 426, 430 may include one or both of system storage that is provided integrally (i.e., substantially non-removable) with the UE 402 and the network device 404 and/or removable storage that is removably connectable to the UE 402 and the network device 404 via, for example, a port (e.g., a universal serial bus (USB) port, a firewire port, etc.) or a drive (e.g., a disk drive, etc.).
- a port e.g., a universal serial bus (USB) port, a firewire port, etc.
- a drive e.g., a disk drive, etc.
- Electronic storage 426, 430 may include one or more of optically readable storage media (e.g., optical disks, etc.), magnetically readable storage media (e.g., magnetic tape, magnetic hard drive, floppy drive, etc.), electrical charge-based storage media (e.g., EEPROM, RAM, etc.), solid-state storage media (e.g., flash drive, etc.), and/or other electronically readable storage media.
- Electronic storage 426, 430 may include one or more virtual storage resources (e.g., cloud storage, a virtual private network, and/or other virtual storage resources).
- Electronic storage 426, 430 may store software algorithms, information determined by processor(s) 428, 432, information received from the UE 402 and the network device 404, or other information that enables the UE 402 and the network device 404 to function as described herein.
- Processor(s) 428, 432 may be configured to provide information processing capabilities in the UE 402 and the network device 404.
- the processor(s) 428, 432 may include one or more of a digital processor, an analog processor, a digital circuit designed to process information, an analog circuit designed to process information, a state machine, and/or other mechanisms for electronically processing information.
- the processor(s) 428, 432 are illustrated as single entities, this is for illustrative purposes only.
- the processor(s) 428, 432 may include a plurality of processing units and/or processor cores. The processing units may be physically located within the same device, or processor(s) 428, 432 may represent processing functionality of a plurality of devices operating in coordination.
- the processor(s) 428, 432 may be configured to execute modules 408-412 and modules 436-440 and/or other modules by software; hardware; firmware; some combination of software, hardware, and/or firmware; and/or other mechanisms for configuring processing capabilities on processor(s) 428, 432.
- the term “module” may refer to any component or set of components that perform the functionality attributed to the module. This may include one or more physical processors during execution of processor readable instructions, the processor readable instructions, circuitry, hardware, storage media, or any other components.
- modules 408-412 and modules 436-440 The description of the functionality provided by the different modules 408-412 and modules 436-440 described below is for illustrative purposes, and is not intended to be limiting, as any of modules 408-412 and modules 436-440 may provide more or less functionality than is described. For example, one or more of the modules 408- 412 and modules 436-440 may be eliminated, and some or all of its functionality may be provided by other modules 408-412 and modules 436-440. As another example, the processor(s) 428, 432 may be configured to execute one or more additional modules that may perform some or all of the functionality attributed below to one of the modules 408-412 and modules 436-440. [0093] FIG.
- the system 500a may include a UE 502, a NAF 504, a key server function (KSF) 506, a Home Subscriber Server (HSS) 508, and a Subscriber Locator Function (SLF) 510.
- KSF key server function
- HSS Home Subscriber Server
- SSF Subscriber Locator Function
- the UE 502 and the KSF 506 may perform authentication operations to authenticate the UE 202.
- a negotiation between the KSF 506 and the UE 502 may perform the authentication operations via a Ub interface, and may employ a protocol such as AKA.
- the UE 502 may communicate with the NAF 504 via a Ua interface.
- the UE 502 and the NAF 504 may have no prior security association.
- the UE 502 may generate a first session key, e.g., Ks NAF.
- the NAF 504 may receive a first session key (e.g., Ks NAF) from the KSF 506 via a Zn interface.
- the HSS 508 may serve as a database or other suitable data storage that may store user authentication credentials for the UE 502, such as User Security Settings (USS) (e.g., GBA User Security Settings (GUSS)).
- USS User Security Settings
- GUISS GBA User Security Settings
- the HSS 508 may map the user authentication credentials to a private identity, such as an IP Multimedia Private Identity (IMPI).
- IMPI IP Multimedia Private Identity
- the HSS 508 may communicate this and other information to the KSF 506 via a Zh interface.
- the SLF 510 may store and provide information to identify the HSS 508 that stores information about the UE 502 (i.e., about a specific UE).
- the KSF 506 and the SLF 510 may communicate over a Dz interface.
- FIG. 5B is a message flow diagram illustrating communications that may be exchanged between a UE and a network device during a method 500b for securing communications according to various embodiments.
- a UE 520 e.g., 120a-120e, 170, 320, 404, 502 and a network device 526 (e.g., 142a, 154, 156, 158, 350, 402) may communicate over a wireless communication network, aspects of which are described above with reference to FIGS. 1A and IB.
- the UE 520 may include a GBA client 522 and an application client 420.
- the network device 526 may include a NAF 528 and a KSF 530.
- the NAF 528 may optionally send a request message 532 to the GBA client 522.
- the message 532 may include a request to start secure communications including a domain name of the NAF (e.g., an FQDN) and a security protocol identifier (e.g., a Ua security protocol identifier).
- the security protocol identifier may enable different keys to be generated for different protocols.
- each key may be limited to one use.
- the domain name of the NAF may enable a key to be unique to the NAF 528.
- the GBA client 522 may generate a freshness parameter.
- the freshness parameter may be or include a random number or a pseudorandom number, such as generated using a random number generating algorithm.
- the freshness parameter may be or include an incremented value, such as a value of counter that is incremented each time a new unique session key is required (e.g., for a new application or new instantiation of an application).
- the incremented value may be used as a nonce value (e.g., an incremented nonce value).
- the GBA client 522 may generate a unique session key (which may be referred to as Ks NAF unique) based on the first session key (e.g., Ks NAF) and the freshness parameter.
- the GBA client 522 may send the freshness parameter to the application client 524 in a message 538.
- the application client 524 may send the freshness parameter to the NAF 528 in a message 540.
- the message 540 may include a network service request message (for example, an Application Request message).
- the network service request message may include a bootstrapping transaction identifier (B-TID).
- the B-TID may function as an identifier of the first session key (e.g., Ks NAF).
- the NAF 528 may send the B-TID to the KSF 530 in a message 542.
- the message 542 also may include a NAF identifier.
- the message 542 may include an Authentication Request message.
- the KSF 530 may send a version of the first session key (e.g., Ks NAF) to the NAF 528 in a message 544.
- the message 544 also may include an application specific identifier associated with the UE (e.g., from a user profile associated with the UE).
- the message 544 may include an Authentication Answer message.
- the UE 520 may include the freshness parameter in an existing field of a message between the UE 520 and the network device 526, to enable implementation of the various embodiments without changing a protocol or architecture of messages or message exchanges.
- the freshness parameter may be included in a “cnonce” field.
- the freshness parameter may be included in an existing field of a ClientHello message or another suitable message.
- a length of the freshness parameter may be configured to fit within an such an existing field and/or message.
- the GBA client 522 may generate the freshness parameter at a similar security level and/or in a similarly secured memory portion as other cryptographic or session keys.
- the GBA client 522 and the NAF 528 may handle, use, process, and/or store the freshness parameter and or the unique session key in a secure memory of the respective device.
- the NAF 528 may generate the unique session key based on the first session key received from the KSF 530 and the freshness parameter received from the UE 520.
- the NAF is able to determine and use the same unique session key as generated by the UE without the exchange of any private key or information that could be used to defeat the encryption security provided by the unique session key, because the freshness parameter is used only once to generate a unique session key that changes in each communication session.
- the NAF 528 may store the generated unique session key in a memory of the NAF 528 (or of the network device 526) for use during the communication session.
- the NAF 528 may send a response message 550 to the application client 524 (e.g., responsive to the message 540, e.g., an Application Request message).
- the message 550 may include an Application Answer message.
- the UE 520 e.g., the application client 524) and the network device 526 (e.g. the NAF 528) may perform secure communications 552 using the unique session key.
- the unique session key may be unique to one application or service of the UE 520.
- FIG. 6 is a process flow diagram illustrating a method 600 that may be performed by a processor of a UE for securing communications with a network element according to various embodiments.
- the operations of the method 600 may be performed by a processor (such as the processor 210, 212, 214, 216, 218, 252, 260, 432) of a UE (e.g., 120a-120e, 170, 320, 404, 502, 520).
- the processor may receive a request to start secure communications from a Network Application Function (NAF) of a network device.
- NAF Network Application Function
- the request may include a domain name of the NAF and a security protocol identifier.
- Means for performing the operations of optional block 602 may include the processor 210, 212, 214, 216, 218, 252, 260, 432, the wireless transceiver 266, the TX/RX module 440, and the GBA client 522.
- the processor may generate a freshness parameter.
- the freshness parameter may be generated by a security bootstrapping client executing in the processor or in another processor (e.g., in a secure processing domain) of the UE.
- the freshness parameter may be associated with a specific application or a specific instantiation of an application (for example, a first instantiation, a second instantiation, and so forth) executing in the UE.
- the freshness parameter may be or include a random value.
- the freshness parameter may include be or include an incremented nonce value.
- Means for performing the operations of block 604 may include the processor 210, 212, 214, 216, 218, 252, 260, 432, the freshness parameter module 436, and/or the GBA client 522.
- the processor may generate a unique session key based on a first session key and the freshness parameter. For example, the processor may apply the first session key (e.g., Ks NAF) and the freshness parameter to a key generating algorithm to generate the unique session key (e.g., Ks NAF unique).
- the unique session key may be associated with a specific application of the UE and the first session key may be associated with the UE.
- the specific application may be or may include a specific instantiation of the application (for example, a first instantiation, a second instantiation, and so forth).
- Means for performing the operations of block 606 may include the processor 210, 212, 214, 216, 218, 252, 260, 432, the unique session key module 438, and the GBA client 522.
- the processor may send the freshness parameter to a NAF (e.g., 504, 528) in a configuration that will enable the NAF to generate the unique session key.
- the processor may send the freshness parameter to the NAF in a network service request message (e.g., an Application Request message).
- Means for performing the operations of block 608 may include the processor 210, 212, 214, 216, 218, 252, 260, 432, the wireless transceiver 266, the TX/RX module 440, and the application client 524.
- the processor may communicate with the NAF using the unique session key (e.g., to encrypt messages sent to the NAF and decrypt messages received from the NAF).
- an application client executing in the processor may perform the communications with the NAF.
- Means for performing the operations of block 610 may include the processor 210, 212, 214, 216, 218, 252, 260, 432, the wireless transceiver 266, the TX/RX module 440, and the application client 524.
- FIG. 7 is a process flow diagram illustrating a method 700 that may be performed by a processor of a network device for securing communications with a UE according to various embodiments.
- the operations of the method 700 may be performed by a processor (such as the processor 210, 212, 214, 216, 218, 252, 260, 432) of a network device (e.g., 142a, 154, 156, 158, 350, 404, 526).
- a processor such as the processor 210, 212, 214, 216, 218, 252, 260, 432
- a network device e.g., 142a, 154, 156, 158, 350, 404, 526.
- the processor may send a request to start secure communications to the UE.
- the request may include a domain name of a NAF and a security protocol identifier.
- Means for performing the operations of optional block 702 may include the processor 210, 212, 214, 216, 218, 252, 260, 432, the wireless transceiver 266, the TX/RX module 440, and the NAF 528.
- the NAF may receive a freshness parameter from the UE.
- the freshness parameter may be associated with a specific application of the UE.
- the specific application may be or may include a specific instantiation of the application (for example, a first instantiation, a second instantiation, and so forth).
- the freshness parameter may be or include a random value.
- the freshness parameter may be or include an incremented nonce value.
- Means for performing the operations of block 704 may include the processor 210, 212, 214, 216, 218, 252, 260, 432, the wireless transceiver 266, the freshness parameter module 408, and the NAF 528.
- the processor may receive from a Key Server Function (KSF) a first session key.
- KSF Key Server Function
- the first session key may be associated with the UE, for example, a Ks NAF session key.
- Means for performing the operations of block 706 may include the processor 210, 212, 214, 216, 218, 252, 260, 432, the unique session key module 410, the NAF 528, and the KSF 506, 530.
- the processor may generate a unique session key based on the freshness parameter and the first session key.
- the processor may apply the freshness parameter and the first session key (e.g., Ks NAF) to the same key generating algorithm as used by the UE in block 606 of the method 600 to generate the unique session key (e.g., Ks NAF unique), and thus generate the same unique session key as generated by the UE.
- the unique session key may be associated with a specific application of the UE, and the first session key is associated with the UE.
- the specific application may be a specific instantiation of the application (e.g., a first instantiation, a second instantiation, and so forth).
- Means for performing the operations of block 706 may include the processor 210, 212, 214, 216, 218, 252, 260, 432, the unique session key module 410, the NAF 528.
- the processor may communicate with the UE using the unique session key to encrypt messages sent to the UE and decrypt messages received from the UE.
- Means for performing the operations of block 710 may include the processor 210, 212, 214, 216, 218, 252, 260, 432, the wireless transceiver 266, the TX/RX module 440, and the NAF 528.
- FIG. 8 is a component block diagram of a network device 800 suitable for use with various embodiments.
- Such network devices e.g., the network device 142a, 154, 156, 158, 350, 404, 526) may include at least the components illustrated in FIG. 8.
- the network device 800 may typically include a processor 801 coupled to volatile memory 802 and a large capacity nonvolatile memory, such as a disk drive 808.
- the network device 800 also may include a peripheral memory access device 806 such as a floppy disc drive, compact disc (CD) or digital video disc (DVD) drive coupled to the processor 801.
- a peripheral memory access device 806 such as a floppy disc drive, compact disc (CD) or digital video disc (DVD) drive coupled to the processor 801.
- the network device 800 also may include network access ports 804 (or interfaces) coupled to the processor 801 for establishing data connections with a network, such as the Internet or a local area network coupled to other system computers and servers.
- the network device 800 may include one or more antennas 807 for sending and receiving electromagnetic radiation that may be connected to a wireless communication link.
- the network device 800 may include additional access ports, such as USB, Firewire, Thunderbolt, and the like for coupling to peripherals, external memory, or other devices.
- FIG. 9 is a component block diagram of a UE 900 suitable for use with various embodiments.
- various embodiments may be implemented on a variety of UEs 900 (for example, the UEs 120a-120e, 170, 320, 402, 502, 520), an example of which is illustrated in FIG. 9 in the form of a smartphone.
- the UE 900 may include a first SOC 202 (for example, a SOC-CPU) coupled to a second SOC 204 (for example, a 5G capable SOC).
- the first and second SOCs 202, 204 may be coupled to internal memory 916, a display 912, and to a speaker 914.
- the UE 900 may include an antenna 904 for sending and receiving electromagnetic radiation that may be connected to a wireless transceiver 266 coupled to one or more processors in the first and/or second SOCs 202, 204.
- the UE 900 may include menu selection buttons or rocker switches 920 for receiving user inputs.
- the UE 900 may include a sound encoding/decoding (CODEC) circuit 910, which digitizes sound received from a microphone into data packets suitable for wireless transmission and decodes received sound data packets to generate analog signals that are provided to the speaker to generate sound.
- CODEC sound encoding/decoding
- One or more of the processors in the first and second SOCs 202, 204, wireless transceiver 266 and CODEC 910 may include a digital signal processor (DSP) circuit (not shown separately).
- DSP digital signal processor
- the processors of the network device 800 and the UE 900 may be any programmable microprocessor, microcomputer or multiple processor chip or chips that can be configured by software instructions (applications) to perform a variety of functions, including the functions of some implementations described below.
- multiple processors may be provided, such as one processor within an SOC 204 dedicated to wireless communication functions and one processor within an SOC 202 dedicated to running other applications.
- Software applications may be stored in the memory 802, 916 before they are accessed and loaded into the processor.
- the processors may include internal memory sufficient to store the application software instructions.
- a component may be, but is not limited to, a process running on a processor, a processor, an object, an executable, a thread of execution, a program, or a computer.
- a component may be, but is not limited to, a process running on a processor, a processor, an object, an executable, a thread of execution, a program, or a computer.
- an application running on a UE and the UE may be referred to as a component.
- One or more components may reside within a process or thread of execution and a component may be localized on one processor or core or distributed between two or more processors or cores.
- these components may execute from various non-transitory computer readable media having various instructions or data structures stored thereon.
- Components may communicate by way of local or remote processes, function or procedure calls, electronic signals, data packets, memory read/writes, and other known network, computer, processor, or process related communication methodologies.
- a number of different cellular and mobile communication services and standards are available or contemplated in the future, all of which may implement and benefit from the various embodiments.
- Such services and standards include, e.g., third generation partnership project (3 GPP), long term evolution (LTE) systems, third generation wireless mobile communication technology (3G), fourth generation wireless mobile communication technology (4G), fifth generation wireless mobile communication technology (5G) as well as later generation 3 GPP technology, global system for mobile communications (GSM), universal mobile telecommunications system (UMTS), 3GSM, general packet radio service (GPRS), code division multiple access (CDMA) systems (e.g., cdmaOne, CDMA1020TM), enhanced data rates for GSM evolution (EDGE), advanced mobile phone system (AMPS), digital AMPS (IS- 136/TDMA), evolution-data optimized (EV-DO), digital enhanced cordless telecommunications (DECT), Worldwide Interoperability for Microwave Access (WiMAX), wireless local area network (WLAN), Wi-Fi Protected Access I & II (WPA
- Implementation examples are described in the following paragraphs. While some of the following implementation examples are described in terms of example methods, further example implementations may include: the example methods discussed in the following paragraphs implemented by a UE or a network device including a processor configured with processor-executable instructions to perform operations of the methods of the following implementation examples; the example methods discussed in the following paragraphs implemented by a UE or a network device including means for performing functions of the methods of the following implementation examples; and the example methods discussed in the following paragraphs may be implemented as a non-transitory processor-readable storage medium having stored thereon processor-executable instructions configured to cause a processor of a UE or a network device to perform the operations of the methods of the following implementation examples.
- Example 1 A method of securing communications performed by a processor of a user equipment (UE), including generating a freshness parameter, generating a unique session key based on a first session key and the freshness parameter, sending the freshness parameter to a Network Application Function (NAF) in a configuration that will enable the NAF to generate the unique session key, and communicating with the NAF using the unique session key.
- UE user equipment
- NAF Network Application Function
- Example 2 The method of example 1, in which the freshness parameter is generated by a security bootstrapping client executing in the processor, and in which an application client executing in the processor communicates with the NAF using the unique session key includes communicating with the NAF using the unique session key.
- Example 3 The method of example 2, in which the security bootstrapping client of the UE comprises one of a Generic Bootstrapping Architecture (GBA) client or an Authentication and Key Management for Applications (AKMA) client.
- GBA Generic Bootstrapping Architecture
- AKMA Authentication and Key Management for Applications
- Example 4 The method of any of examples 1-3, in which the freshness parameter is associated with a specific application of the UE.
- Example 5 The method of any of examples 1-4, in which the unique session key is associated with a specific application of the UE and the first session key is associated with the UE.
- Example 6 The method of example 5, in which the specific application includes a specific instantiation of the application.
- Example 7 The method of any of examples 1-6, further including receiving from the NAF a request to start secure communication.
- Example 8 The method of any of examples 1-7, in which the freshness parameter includes a random value.
- Example 9 The method of any of examples 1-8, in which the freshness parameter includes an incremented nonce value.
- Example 10 The method of any of examples 1-9, in which sending the freshness parameter to the NAF in a configuration that will enable the NAF to generate the unique session key includes sending the freshness parameter to the NAF in a network service request message.
- Example 11 A method of securing communications performed by a processor of a device, including receiving by a Network Application Function (NAF) from a user equipment (UE) a freshness parameter, receiving from a Key Server Function (KSF) a first session key, generating based on the freshness parameter and the first session key a unique session key, and communicating with the UE using the unique session key.
- NAF Network Application Function
- KSF Key Server Function
- Example 12 The method of example 11, in which the freshness parameter is generated by a security bootstrapping client of the UE; and an application client of the UED communicates with the NAF using the unique session key.
- Example 13 The method of example 12, in which the security bootstrapping client of the UE comprises one of a Generic Bootstrapping Architecture (GBA) client or an Authentication and Key Management for Applications (AKMA) client.
- GBA Generic Bootstrapping Architecture
- AKMA Authentication and Key Management for Applications
- Example 14 The method of any of examples 11-13, in which the freshness parameter is associated with a specific application of the UE.
- Example 15 The method of any of examples 11-14, in which the unique session key is associated with a specific application of the UE and the first session key is associated with the UE.
- Example 16 The method of any of examples 11-15, wherein the specific application includes a specific instantiation of the application.
- Example 17 The method of any of examples 11-16, in which the freshness parameter includes a random value.
- Example 18 The method of any of examples 11-17, in which the freshness parameter includes an incremented nonce value.
- Example 19 The method of any of examples 11-18, further including sending to the UE a request to start secure communications.
- Example 20 The method of any of examples 11-19, in which receiving by the NAF from the UE the freshness parameter includes receiving the freshness parameter in a network service request message.
- DSP digital signal processor
- ASIC application specific integrated circuit
- FPGA field programmable gate array
- a general-purpose processor may be a microprocessor, but, in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine.
- a processor may also be implemented as a combination of receiver smart objects, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Alternatively, some operations or methods may be performed by circuitry that is specific to a given function.
- the functions described may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions may be stored as one or more instructions or code on a non- transitory computer-readable storage medium or non-transitory processor-readable storage medium.
- the operations of a method or algorithm disclosed herein may be embodied in a processor-executable software module or processor-executable instructions, which may reside on a non-transitory computer-readable or processor- readable storage medium.
- Non-transitory computer-readable or processor-readable storage media may be any storage media that may be accessed by a computer or a processor.
- non-transitory computer- readable or processor-readable storage media may include RAM, ROM, EEPROM, FLASH memory, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage smart objects, or any other medium that may be used to store desired program code in the form of instructions or data structures and that may be accessed by a computer.
- Disk and disc includes compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray disc where disks usually reproduce data magnetically, while discs reproduce data optically with lasers. Combinations of the above are also included within the scope of non- transitory computer-readable and processor-readable media.
- the operations of a method or algorithm may reside as one or any combination or set of codes and/or instructions on a non-transitory processor-readable storage medium and/or computer-readable storage medium, which may be incorporated into a computer program product.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
Claims
Priority Applications (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202280060898.4A CN117917107A (en) | 2021-09-17 | 2022-09-13 | Ensuring application communication security |
EP22786180.4A EP4402925A1 (en) | 2021-09-17 | 2022-09-13 | Securing application communication |
KR1020247008008A KR20240056515A (en) | 2021-09-17 | 2022-09-13 | Application communication security |
Applications Claiming Priority (4)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US202163245692P | 2021-09-17 | 2021-09-17 | |
US63/245,692 | 2021-09-17 | ||
US17/931,505 US20230093720A1 (en) | 2021-09-17 | 2022-09-12 | Securing Application Communication |
US17/931,505 | 2022-09-12 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2023043724A1 true WO2023043724A1 (en) | 2023-03-23 |
Family
ID=83598417
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/US2022/043320 WO2023043724A1 (en) | 2021-09-17 | 2022-09-13 | Securing application communication |
Country Status (4)
Country | Link |
---|---|
EP (1) | EP4402925A1 (en) |
KR (1) | KR20240056515A (en) |
TW (1) | TW202320557A (en) |
WO (1) | WO2023043724A1 (en) |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20060236106A1 (en) * | 2005-04-18 | 2006-10-19 | Sarvar Patel | Providing fresh session keys |
WO2007034322A1 (en) * | 2005-09-26 | 2007-03-29 | Nokia Corporation | Method and apparatus for refreshing keys within a bootstrapping architecture |
CN112399369A (en) * | 2019-07-31 | 2021-02-23 | 华为技术有限公司 | Secret key updating, obtaining and canceling method and communication device |
-
2022
- 2022-09-13 EP EP22786180.4A patent/EP4402925A1/en active Pending
- 2022-09-13 KR KR1020247008008A patent/KR20240056515A/en unknown
- 2022-09-13 WO PCT/US2022/043320 patent/WO2023043724A1/en active Application Filing
- 2022-09-14 TW TW111134693A patent/TW202320557A/en unknown
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20060236106A1 (en) * | 2005-04-18 | 2006-10-19 | Sarvar Patel | Providing fresh session keys |
WO2007034322A1 (en) * | 2005-09-26 | 2007-03-29 | Nokia Corporation | Method and apparatus for refreshing keys within a bootstrapping architecture |
CN112399369A (en) * | 2019-07-31 | 2021-02-23 | 华为技术有限公司 | Secret key updating, obtaining and canceling method and communication device |
Also Published As
Publication number | Publication date |
---|---|
TW202320557A (en) | 2023-05-16 |
EP4402925A1 (en) | 2024-07-24 |
KR20240056515A (en) | 2024-04-30 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
EP4052400A1 (en) | Bandwidth part (bwp) for unicast/multicast and resource allocation for multicast | |
US20230044847A1 (en) | 5G Non-Seamless Wireless Local Area Network Offload | |
WO2021216247A1 (en) | Physical uplink control channel with uplink message short data field | |
EP4140070A1 (en) | Physical uplink control channel with buffer status report | |
US11716716B2 (en) | Barrage signal for protecting wireless communications | |
US20220167159A1 (en) | Systems and methods for authenticating a wireless device | |
US11533613B2 (en) | Providing secure communications between computing devices | |
US20230093720A1 (en) | Securing Application Communication | |
WO2021242410A1 (en) | Processing data using remote network computing resources | |
WO2023043724A1 (en) | Securing application communication | |
US20230137082A1 (en) | Generic Bootstrapping Architecture (GBA) Signaling To Indicate Need For Key Renegotiation | |
CN117917107A (en) | Ensuring application communication security | |
WO2021174435A1 (en) | Managing a downlink bit rate | |
US12126994B2 (en) | User plane integrity protection (UP IP) capability signaling in 5G/4G systems | |
WO2022051985A1 (en) | Managing a communication link for transfer control protocol communications | |
WO2022165826A1 (en) | Frames-per-second thermal management | |
US20210105612A1 (en) | User plane integrity protection (up ip) capability signaling in 5g/4g systems | |
WO2021243547A1 (en) | Managing transmission control protocol communication with a communication network | |
WO2023018608A1 (en) | 5g non-seamless wireless local area network offload | |
EP4427484A1 (en) | Managing end-to-end quality of service (qos) in a multi-network communication path | |
WO2023158495A1 (en) | Securing media stream communications | |
CN118176770A (en) | Managing end-to-end quality of service (QoS) in a multi-network communication path |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22786180 Country of ref document: EP Kind code of ref document: A1 |
|
WWE | Wipo information: entry into national phase |
Ref document number: 202427003600 Country of ref document: IN |
|
ENP | Entry into the national phase |
Ref document number: 20247008008 Country of ref document: KR Kind code of ref document: A |
|
WWE | Wipo information: entry into national phase |
Ref document number: 202280060898.4 Country of ref document: CN |
|
WWE | Wipo information: entry into national phase |
Ref document number: 2022786180 Country of ref document: EP |
|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
ENP | Entry into the national phase |
Ref document number: 2022786180 Country of ref document: EP Effective date: 20240417 |