WO2025008947A1 - System and method of handling integrity failure for idle mode nas - Google Patents
System and method of handling integrity failure for idle mode nas Download PDFInfo
- Publication number
- WO2025008947A1 WO2025008947A1 PCT/IN2024/050928 IN2024050928W WO2025008947A1 WO 2025008947 A1 WO2025008947 A1 WO 2025008947A1 IN 2024050928 W IN2024050928 W IN 2024050928W WO 2025008947 A1 WO2025008947 A1 WO 2025008947A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- amf
- count
- uplink
- sqn
- stored
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W76/00—Connection management
- H04W76/20—Manipulation of established connections
- H04W76/27—Transitions between radio resource control [RRC] states
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/10—Integrity
- H04W12/106—Packet or message integrity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W60/00—Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
- H04W60/04—Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration using triggered events
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W88/00—Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
- H04W88/14—Backbone network devices
Definitions
- the present invention relates to communication technology and, more particularly, to handling integrity failure for idle mode NAS.
- Access & Mobility Management Function is responsible for managing the mobility and access of User Equipment (UEs).
- UEs User Equipment
- AMF Access & Mobility Management Function
- Re-authentication involves verifying the identity and security credentials of the UE, while re-registration involves updating the network with the UE's current location and status. These processes ensure the integrity and security of the communication between the UE and the network. By initiating re-authentication or reregistration, the AMF can mitigate potential security risks and maintain the integrity of the network connection.
- One or more embodiments of the present disclosure provide a system and a method of handling integrity failures in Non-Access Stratum (NAS) message for idle mode procedure in a communication network.
- NAS Non-Access Stratum
- a system for handling integrity failures in Non-Access Stratum (NAS) message for idle mode procedure in a communication network includes a User Equipment (UE) and an Access and Mobility Management Function (AMF).
- the UE is configured to send a request for an idle mode procedure to the AMF.
- the request for the idle mode procedure includes a Message Authentication Code (MAC) and a UE uplink Sequence Number (SQN).
- MAC Message Authentication Code
- SQL UE uplink Sequence Number
- the AMF is configured to: receive the request for the idle mode procedure from the UE; determine an integrity failure in relation to the idle mode procedure initiated by the UE when a MAC value calculated at the AMF using a NAS integrity algorithm is different from the MAC value received from the UE; calculate a gap count by comparing the UE uplink SQN received from the UE and an AMF uplink SQN stored at the AMF; update an overflow count stored at the AMF based on comparison of the gap count and a configured gap count pre-stored at the AMF to make the overflow count stored at the AMF equal to an overflow count stored at the UE; and perform integrity validation of the NAS message based on the updated overflow count and the UE uplink SQN received from the UE.
- the AMF recalculates a MAC value using the UE uplink sequence number received from the UE and the updated overflow count, and determines a successful match between the overflow count stored at the AMF and the overflow count stored at the UE.
- the request for the idle mode procedure is received as one of a Mobility Request (MR), Periodic Request (PR), and a Service Request (SR).
- the request includes one or more of a SQN and a NAS message.
- the gap count is determined by adding a predefined number to the received UE uplink SQN and subtracting the AMF uplink SQN from a sum.
- the gap count is determined by adding a predefined number to the AMF uplink SQN and subtracting the UE uplink SQN from a sum.
- the overflow count is incremented.
- the overflow count is decremented.
- a method of handling integrity failures in Non-Access Stratum (NAS) message for idle mode procedure in a communication network includes the step of receiving, by an Access and Mobility Management Function (AMF), a request for an idle mode procedure from a User Equipment (UE).
- the request for the idle mode procedure includes a Message Authentication Code (MAC) and a UE uplink Sequence Number (SQN).
- the method includes the step of determining, by the AMF, an integrity failure in relation to the idle mode procedure initiated by the UE when a MAC value calculated at the AMF is different from the MAC value received from the UE.
- AMF Access and Mobility Management Function
- UE User Equipment
- the request for the idle mode procedure includes a Message Authentication Code (MAC) and a UE uplink Sequence Number (SQN).
- the method includes the step of determining, by the AMF, an integrity failure in relation to the idle mode procedure initiated by the UE when a MAC value calculated at the AMF is different from the MAC value received from
- the method includes the step of calculating, by the AMF, a gap count by comparing the UE uplink SQN received from the UE and an AMF uplink SQN stored at the AMF.
- the method includes the step of updating, by the AMF, an overflow count stored at the AMF based on comparison of the gap count and a configured gap count pre-stored at the AMF to make the overflow count stored at the AMF equal to an overflow count stored at the UE.
- the method includes the step of performing, by the AMF, integrity validation of the NAS message based on the updated overflow count and the UE uplink SQN received from the UE.
- the AMF recalculates a MAC using the UE uplink SQN received from the UE and the updated overflow count, and determines a successful match between the overflow count stored at the AMF and the overflow count stored at the UE.
- the request for the idle mode procedure is received as one of a Mobility Request (MR), Periodic Request (PR), and a Service Request (SR).
- the request includes one or more of a SQN and a NAS message.
- the gap count is determined by adding a predefined number to the received UE uplink SQN and subtracting the AMF uplink SQN from a sum.
- the gap count is determined by adding a predefined number to the AMF uplink SQN and subtracting the UE uplink SQN from a sum.
- the overflow count is incremented.
- the overflow count is decremented.
- a non-transitory computer-readable medium having stored thereon computer-readable instructions Upon being executed by a processor, the computer-readable instructions cause the processor to receive a request for an idle mode procedure from a User Equipment (UE).
- the request for the idle mode procedure includes a Message Authentication Code (MAC) value and a UE uplink Sequence Number (SQN).
- the computer-readable instructions further cause the processor to determine an integrity failure in relation to the idle mode procedure initiated by the UE when a MAC value calculated at an Access and Mobility Management Function (AMF) is different from the MAC value received from the UE.
- AMF Access and Mobility Management Function
- the computer-readable instructions cause the processor to calculate a gap count by comparing the UE uplink SQN received from the UE and an AMF uplink SQN stored at the AMF.
- the computer-readable instructions cause the processor to update an overflow count stored at the AMF based on comparison of the gap count and a configured gap count pre-stored at the AMF to make the overflow count stored at the AMF equal to an overflow count stored at the UE.
- the computer-readable instructions cause the processor to perform integrity validation of the NAS message based on the updated overflow count and the UE uplink SQN received from the UE.
- FIG. 1 illustrates a system architecture for handling integrity failures in Non- Access Stratum (NAS) message for idle mode procedure in a communication network, according to one or more embodiments of the present subject matter;
- NAS Non- Access Stratum
- FIG. 2 illustrates a block diagram of a system for handling integrity failures in NAS message for idle mode procedure in a communication network, according to one or more embodiments of the present subject matter
- FIG. 4 illustrates a timing diagram of a method of connection establishment, release, and reporting integrity failure in a communication network, according to one or more embodiments of the present subject matter
- FIG. 6 illustrates a flow chart of a method of handling integrity failures in NAS message for idle mode procedure in a communication network, according to one or more embodiments of the present subject matter.
- Various embodiments of the present invention provide an Access and Mobility Management Function (AMF) for handling integrity failure in idle state NAS.
- AMF Access and Mobility Management Function
- the invention introduces a novel method executed by the Access and Mobility Management Function (AMF) within a communication network to effectively address integrity failures occurring in idle state responses received from User Equipment (UE).
- UE User Equipment
- FIG. 1 illustrates a system architecture for handling integrity failures in Non- Access Stratum (NAS) message for idle mode procedure in a communication network, in accordance with one implementation of the present embodiment.
- the system comprises several interconnected components that work together to handle the integrity failures.
- NAS Non- Access Stratum
- the system architecture shows a User Equipment (UE) 110.
- UE User Equipment
- the description will be explained with respect to one or more UEs 110, or to be more specific will be explained with respect to a first UE 110a, a second UE 110b, and a third UE 110c, and should nowhere be construed as limiting the scope of the present disclosure.
- each of the first UE 110a, the second UE 110b, and the third UE 110c is a mobile phone or a smartphone.
- Each of the first UE 110a, the second UE 110b, and the third UE 110c is configured to transmit a request for an idle mode procedure via a communication network 105 to a system 125.
- the communication network 105 includes, by way of example but not limitation, one or more of a wireless network, a wired network, an internet, an intranet, a public network, a private network, a packet- switched network, a circuit-switched network, an ad hoc network, an infrastructure network, a Public-Switched Telephone Network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or some combination thereof.
- PSTN Public-Switched Telephone Network
- the communication network 105 may include, but is not limited to, a Third Generation (3G), a Fourth Generation (4G), a Fifth Generation (5G), a Sixth Generation (6G), a New Radio (NR), a Narrow Band Internet of Things (NB-IoT), an Open Radio Access Network (O-RAN), and the like.
- 3G Third Generation
- 4G Fourth Generation
- 5G Fifth Generation
- 6G Sixth Generation
- NR New Radio
- NB-IoT Narrow Band Internet of Things
- OF-RAN Open Radio Access Network
- a server 115 is accessible via the communication network 105.
- the server 115 may include by way of example but not limitation, one or more of a standalone server, a server blade, a server rack, a bank of servers, a server farm, hardware supporting a part of a cloud service or system, a home server, hardware running a virtualized server, one or more processors executing code to function as a server, one or more machines performing server-side functionality as described herein, at least a portion of any of the above, some combination thereof.
- the entity may include, but is not limited to, a vendor, a network operator, a company, an organization, a university, a lab facility, a business enterprise, a defence facility, or any other facility that provides content.
- the system 125 is configured to operate as an Access and Mobility Management Function (AMF) and hence alternatively referred as AMF.
- AMF Access and Mobility Management Function
- the system 125 may be generic in nature and may be integrated with any application including a System Management Facility (SMF), a Business Telephony Application Server (BTAS), a Converged Telephony Application Server (CTAS), any SIP (Session Initiation Protocol) Application Server which interacts with core Internet Protocol Multimedia Subsystem (IMS) on Industrial Control System (ISC) interface as defined by Third Generation Partnership Project (3GPP) to host a wide array of cloud telephony enterprise services, a System Information Blocks (SIB)/ and a Mobility Management Entity (MME).
- SIMF System Information Blocks
- MME Mobility Management Entity
- FIG. 2 illustrates a block diagram of the system 125 for handling integrity failures in Non-Access Stratum (NAS) message for idle mode procedure in a communication network, according to one or more embodiments of the present invention.
- the system 125 is adapted to be embedded within the server 115 or is embedded as an individual entity. However, for the purpose of description, the system 125 is described as an integral part of the server 115, without deviating from the scope of the present disclosure.
- the system 125 includes one or more processors 205, a memory 210, and an input/output interface unit 215.
- the one or more processor 205 hereinafter referred to as the processor 205 may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, state machines, logic circuitries, single board computers, and/or any devices that manipulate signals based on operational instructions.
- the system 125 includes one or more processors 205.
- the system 125 may include multiple processors as per the requirement and without deviating from the scope of the present disclosure.
- the one or more processors 205 is configured to fetch and execute computer-readable instructions stored in the memory 210.
- the memory 210 may be configured to store one or more computer-readable instructions or routines in a non-transitory computer-readable storage medium, which may be fetched and executed to create or share data packets over a network service.
- the memory 210 may include any non-transitory storage device including, for example, volatile memory such as RAM, or non-volatile memory such as EPROM, flash memory, and the like.
- the input/output (RO) interface unit 215 includes a variety of interfaces, for example, interfaces for data input and output devices, referred to as Input/Output (RO) devices, storage devices, and the like.
- the I/O interface unit 215 facilitates communication of the system 125.
- the RO interface unit 215 provides a communication pathway for one or more components of the system 125. Examples of such components include, but are not limited to, the network devices 110, a backend database 220, and a distributed cache 225.
- the backend database 220 is one of, but is not limited to, a centralized database, a cloud-based database, a commercial database, an open-source database, a distributed database, an end-user database, a graphical database, a No-Structured Query Language (NoSQL) database, an object-oriented database, a personal database, an in-memory database, a document-based database, a time series database, a wide column database, a key value database, a search database, a cache database, and so forth.
- NoStructured Query Language (NoSQL) database No-Structured Query Language
- object-oriented database a personal database
- an in-memory database a document-based database
- a time series database a time series database
- a wide column database a key value database
- search database a cache database
- the distributed cache 225 is a pool of random-access memory (RAM) of multiple networked computers into a single in-memory data store for use as a data cache to provide fast access to data.
- the distributed cache 225 is essential for applications that need to scale across multiple servers or are distributed geographically.
- the distributed cache 225 ensures that data is available close to where it’s needed, even if the original data source is remote or under heavy load.
- the one or more processors 205 may be implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the one or more processors 205.
- programming for the one or more processors 205 may be processorexecutable instructions stored on a non -transitory machine-readable storage medium and the hardware for one or more processors 205 may comprise a processing resource (for example, one or more processors), to execute such instructions.
- the memory 210 may store instructions that, when executed by the processing resource, implement the one or more processors 205.
- system 125 may comprise the memory 210 storing the instructions and the processing resource to execute the instructions, or the memory 210 may be separate but accessible to the system 125 and the processing resource.
- the one or more processors 205 may be implemented by electronic circuitry.
- the processor 205 implements a request receiving module 228, an integrity failure determining module 230, a gap count calculation module 235, an overflow count updating module 240, and an integrity validation module 245 communicably coupled to each other.
- the request receiving module 228 is communicably connected to each of the first UE 110a, the second UE 110b, and the third UE 110c via the communication network 105. Accordingly, the request receiving module 228 is configured to receive a request for an idle mode procedure from a User Equipment (UE).
- the request for the idle mode procedure is received as a Mobility Request (MR), Periodic Request (PR), or a Service Request (SR).
- the request for the idle mode procedure includes a Message Authentication Code (MAC) and a UE uplink Sequence Number (SQN).
- the request may include a NAS message.
- MAC information element contains integrity protection information for a message.
- the MAC IE is included in the SECURITY PROTECTED 5GS NAS MESSAGE if a valid 5G NAS security context exists and security functions are started.
- the SQN consists of eight least significant bits of the NAS COUNT for a SECURITY PROTECTED 5GS NAS MESSAGE.
- a NAS COUNT is constructed as a NAS sequence number (8 least significant bits) concatenated with a NAS overflow counter (16 most significant bits).
- the NAS message may be a plain 5GS NAS message and would include extended protocol discriminator, security header type associated with a half spare octet or PDU session identity, procedure transaction identity, message type, and other information elements, as required.
- the NAS message may be a security protected 5GS NAS message and would include extended protocol discriminator, security header type associated with a half spare octet, message authentication code, sequence number, and plain 5GS NAS message.
- SECURITY PROTECTED 5GS NAS MESSAGE, integrity protection shall include octet 7 to n, i.e. the SQN IE and the NAS message IE.
- the one or more processors 205 further implements the integrity failure determining module 230 configured to determine an integrity failure in relation to the idle mode procedure initiated by the UE when a MAC value calculated at the AMF is different from the MAC value received from the UE.
- the one or more processors 205 further implements the gap count calculation module 235 configured to calculate a gap count by comparing the UE uplink SQN received from the UE and an AMF uplink SQN stored at the AMF. In one case, when the UE uplink SQN received from the UE crosses a predefined count and the AMF uplink SQN is less than or equal to the predefined count, the gap count is determined by adding a predefined number to the received UE uplink SQN and subtracting the AMF uplink SQN from a sum.
- the gap count is determined by adding a predefined number to the AMF uplink SQN and subtracting the UE uplink SQN from a sum.
- the one or more processors 205 further implements the overflow count updating module 240 configured to update an overflow count stored at the AMF based on comparison of the gap count and a configured gap count pre-stored at the AMF to make the overflow count stored at the AMF equal to an overflow count stored at the UE.
- the overflow count is incremented.
- the overflow count is decremented.
- the one or more processors 205 further implements the integrity validation module 245 configured to perform integrity validation of the NAS message based on the updated overflow count and the UE uplink SQN received from the UE.
- the AMF recalculates a MAC using the UE uplink SQN received from the UE and the updated overflow count. Thereafter, the AMF determines a successful match between the overflow count stored at the AMF and the overflow count stored at the UE.
- One or more parameters associated with operation of one or more of the above described modules are configurable and may be stored in one or more of the database 220 and the distributed cache 225.
- FIG. 3 illustrating a block diagram of the system 125 and the first UE 110a communicating with each other for handling integrity failures in NAS message for idle mode procedure in a communication network
- a preferred embodiment of the system 125 is described. It is to be noted that the embodiment with respect to FIG. 3 will be explained with respect to the first UE 110a for the purpose of description and illustration and should nowhere be construed as limited to the scope of the present disclosure.
- the first network device 110a includes one or more primary processors 305 communicably coupled to the one or more processors 205 of the system 125.
- the one or more primary processors 305 are coupled with a memory unit 310 storing instructions which are executed by the one or more primary processors 305. Execution of the stored instructions by the one or more primary processors 305 enables the first UE 110a to provide a request for an idle mode procedure.
- the first UE 110a further includes a kernel 315 which is a core component serving as the primary interface between hardware components of the first UE 110a and the plurality of services at the backend database 220.
- the kernel 315 is configured to provide the plurality of services on the first UE 110a to resources available in the communication network 105.
- the resources include one of a Central Processing Unit (CPU), memory components such as Random Access Memory (RAM) and Read Only Memory (ROM).
- CPU Central Processing Unit
- RAM Random Access Memory
- ROM Read Only Memory
- the request receiving module 228 of the one or more processors 205 is communicably connected to the kernel 315 of the first UE 110a.
- the request receiving module 228 is configured to receive a request for an idle mode procedure from a User Equipment (UE) over N1 interface.
- the request for the idle mode procedure includes a Message Authentication Code (MAC) and a UE uplink Sequence Number (SQN).
- the one or more processors 205 further include the integrity failure determining module 230 communicably connected to the request receiving module 228 to determine an integrity failure in relation to the idle mode procedure initiated by the UE when a MAC value calculated at the AMF is different from the MAC value received from the UE.
- the one or more processors 205 further include the gap count calculation module 235 communicably connected to the integrity failure determining module 230 to calculate a gap count by comparing the UE uplink SQN received from the UE and an AMF uplink SQN stored at the AMF.
- the one or more processors 205 further include the overflow count updating module 240 communicably connected to the gap count calculation module 235 to update an overflow count stored at the AMF based on comparison of the gap count and a configured gap count pre-stored at the AMF to make the overflow count stored at the AMF equal to an overflow count stored at the UE.
- the one or more processors 205 further include the integrity validation module 245 communicably connected to the overflow count updating module 240 to perform integrity validation of the NAS message based on the updated overflow count and the UE uplink SQN received from the UE.
- FIG. 4 illustrates a timing diagram of a method of connection establishment, release, and reporting integrity failure in a communication network, according to one or more embodiments of the present disclosure.
- the method is described with the embodiments as illustrated in FIGS. 1, 2, and 3 and should nowhere be construed as limiting the scope of the present disclosure.
- the first UE 110a sends a registration request to the system/ AMF 125 via a Radio Access Network (RAN) 105a, and the first UE 110a gets connected with the system/AMF 125. After connection establishment, the first UE 110a sends data to the system/AMF 125, and packet loss occurs during the communication.
- RAN Radio Access Network
- the RAN 105a sends a Radio Resource Control (RRC) release request to the first UE 110a. Further, at step 415, the RAN 105a sends the release request to the system/AMF 125. With this, the first UE 110a initiates procedure to enter in idle mode. [0052] At step 420, the system/ AMF 125 sends confirmation to the RAN 105a to release the connection. At step 425, the RAN 105a sends a release completion message to the system/ AMF 125, and the first UE 110a enter in the idle mode.
- RRC Radio Resource Control
- the first UE 110a indicates to the system/AMF 125 about integrity failure, when the first UE 110a is operating in an uplink or Mobile Originating (MO) mode.
- the system/AMF 125 sends a paging message to the first UE 110a, at step 435.
- the paging message indicates to the first UE 110a that the system/AMF 125 has a message to share and the system/AMF 125 must monitor the communication channel.
- FIG. 5 illustrates a timing diagram of a method of handling integrity failures in NAS message for idle mode procedure in a communication network, according to one or more embodiments of the present disclosure.
- the method is described with the embodiments as illustrated in FIGS. 1, 2, 3, and 4 and should nowhere be construed as limiting the scope of the present disclosure.
- the first UE 110a present in an idle state sends an idle state response i.e. a request for an idle mode procedure to a network, such as the system/AMF 125 via the RAN 105a.
- the RAN 105a may be a part of the communication network 105 and would be any of the following types: Distributed RAN (D-RAN), Centralized RAN (C-RAN), Virtualized RAN (vRAN), and OpenRAN (O-RAN).
- the first UE 110a sends the idle state response based on events like service requests or paging requests received from the system/AMF 125 via the RAN 105a.
- the idle state response may be an MR/PR/SR response.
- the first UE 110a also transmits a MAC and a UE uplink SQN to the system/AMF 125.
- the system/AMF 125 performs an integrity check on the idle state response received from the first UE 110a.
- the system/AMF 125 determines integrity failure at the system/AMF 125 when a MAC value calculated at the system/ AMF 125 differs from a MAC value received from the first UE 110a.
- the system/AMF 125 calculates a gap count by comparing the UE uplink SQN received from the first UE 110a with an AMF uplink SQN stored at the system/AMF 125.
- the AMF adds a predefined number, for example 255 to the UE uplink SQN and subtracts the AMF uplink SQN from the addition result to obtain the gap count.
- the AMF adds the predefined number to the AMF uplink SQN and subtracts the UE uplink SQN to obtain the gap count.
- the system/AMF 125 determines if the calculated gap count is less than or equal to a configured gap count pre-stored at the system/AMF 125.
- the system/AMF 125 compares the gap count to update an overflow count.
- the system/AMF 125 updates the overflow count stored at the AMF based on the comparison of the gap count. For example, the system/AMF 125 makes an overflow count stored at the system/AMF 125 equal to an overflow count stored at the first UE 110a based on the comparison of the gap count. In one implementation, when the calculated gap count is less than or equal to the configured gap count stored at the system/AMF 125 and the UE uplink SQN is greater than the AMF uplink SQN, the system/AMF 125 increments the overflow count by a predefined value, for example 1.
- the system/AMF 125 decrements the overflow count by the predefined value. In this manner, updating the overflow count ensures synchronization of the overflow count between the system/AMF 125 and the first UE 110a.
- the system/AMF 125 re -performs the integrity check using an updated overflow count and the UE uplink SQN. By recalculating the MAC value
- the system/ AMF 125 verifies the integrity of communication.
- a successful integrity check eliminates the need for resource-intensive reauthentication and re-registration procedures during the idle state of the first UE 110a. This approach optimizes network resource utilization, promotes cost-effective operations, and reduces signaling overhead.
- FIG. 6 illustrates a flow chart of a method 500 of handling integrity failures in NAS message for idle mode procedure in a communication network, according to one or more embodiments of the present disclosure.
- the method 600 is described with the embodiments as illustrated in FIGS. 1 and 5 and should nowhere be construed as limiting the scope of the present disclosure.
- a UE When a UE is present in an idle state, the UE sends a response to the network, which may be triggered by certain events like a service request or a paging request.
- the response may contain important information or instructions.
- a MAC value is also received from the UE, along with a UE uplink SQN.
- the UE uplink SQN may be understood as a value assigned to the transmission by the UE indicating an order of the transmission.
- a similar value, referred as an AMF uplink SQN is also stored at the AMF.
- the AMF On receiving the response from the UE, the AMF may be configured for ensuring the integrity and security of the communication between the UE and the network.
- the AMF detect integrity failure by analyzing an idle state response received from the UE.
- An integrity failure refers to a situation where the AMF detects that a MAC value at the AMF is different than the MAC value calculated at the UE.
- the method 600 includes the step of calculating a gap count based on an UE uplink SQN received from the UE and an AMF uplink SQN stored at the AMF, by the one or more processors 205.
- the AMF determines the difference or "gap" between the two numbers, to gain insight into transmission status.
- the gap count is calculated by adding 255 to the UE uplink SQN and subtracting the AMF uplink SQN from the result to obtain the gap count.
- the gap count is calculated by adding 255 to the AMF uplink SQN and subtracting the UE uplink SQN from the result to obtain the gap count.
- the method 600 includes the step of updating an overflow count stored at the AMF, by the one or more processors 205.
- the overflow count stored at the AMF is updated by the AMF based on the calculated gap count and a configured gap count pre-stored at the AMF. In an example, when the calculated gap count is less than or equal to the configured gap count that is pre-stored at the AMF and where the UE uplink sequence number received from the UE is greater than the AMF uplink sequence number, the overflow count stored at the AMF is incremented by 1.
- the overflow count stored at the AMF is decremented by 1. In this manner, a value of the overflow count stored at the AMF becomes equal to a value of the overflow count stored at the UE.
- the method 600 includes the step of re-performing an integrity check, by the one or more processors 205.
- the integrity check is re -performed by the AMF based on the updated overflow count and the UE uplink SQN.
- the AMF recalculates the MAC value using the UE uplink SQN and the updated overflow count. As the value of the overflow count stored at the AMF is made equal to the value of the overflow count stored at the UE, integrity check is performed successfully.
- the present invention further discloses a non-transitory computer-readable medium having stored thereon computer-readable instructions.
- the computer- readable instructions are executed by the processor 205.
- the processor 205 is configured to receive a request for an idle mode procedure from a User Equipment (UE).
- the request for the idle mode procedure includes a Message Authentication Code (MAC) and a UE uplink Sequence Number (SQN).
- MAC Message Authentication Code
- SQL UE uplink Sequence Number
- the processor 205 is further configured to determine an integrity failure in relation to the idle mode procedure initiated by the UE when a MAC value calculated at the AMF is different from the MAC value received from the UE.
- the processor 205 is further configured to calculate a gap count by comparing the UE uplink SQN received from the UE and an AMF uplink SQN stored at the AMF.
- the processor 205 is further configured to update an overflow count stored at the AMF based on comparison of the gap count and a configured gap count pre-stored at the AMF to make the overflow count stored at the AMF equal to an overflow count stored at the UE.
- the processor 205 is further configured to perform integrity validation of the NAS message based on the updated overflow count and the UE uplink SQN received from the UE.
- the above described techniques of the present disclosure provide multiple advantages, including averting the need of performing re-authentication or reregistration procedure when an integrity failure occurs during idle state of UE. Averting such procedures facilitate optimized usage of network resources and economical operations. Further, implementation of techniques of the present disclosure also results in reduction of signaling overheads. Present disclosure also offers the technical advantage of checking integrity of packets to ensure no attack occurs in case when someone tries to modify or corrupt data packets.
- the present invention offers multiple advantages over the prior art and the above listed are a few examples to emphasize on some of the advantageous features.
- the listed advantages are to be read in a non-limiting manner.
- a server may include or comprise, by way of example but not limitation, one or more of a standalone server, a server blade, a server rack, a bank of servers, a server farm, hardware supporting a part of a cloud service or system, a home server, hardware running a virtualized server, one or more processors executing code to function as a server, one or more machines performing server-side functionality as described herein, at least a portion of any of the above, some combination thereof.
- the entity may include, but is not limited to, a vendor, a network operator, a company, an organization, a university, a lab facility, a business enterprise, a defence facility, or any other facility that provides content.
- a network may include, by way of example but not limitation, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth.
- the network may also include, by way of example but not limitation, one or more of a wireless network, a wired network, an internet, an intranet, a public network, a private network, a packet-switched network, a circuit-switched network, an ad hoc network, an infrastructure network, a Public- Switched Telephone Network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or some combination thereof.
- PSTN Public- Switched Telephone Network
- a wireless device or a user equipment may include, but are not limited to, a handheld wireless communication device (e.g., a mobile phone, a smart phone, a phablet device, and so on), a wearable computer device (e.g., a head-mounted display computer device, a head-mounted camera device, a wristwatch computer device, and so on), a Global Positioning System (GPS) device, a laptop computer, a tablet computer, or another type of portable computer, a media playing device, a portable gaming system, and/or any other type of computer device with wireless communication capabilities, and the like.
- the UEs may communicate with the system via set of executable instructions residing on any operating system.
- the UEs may include, but are not limited to, any electrical, electronic, electro-mechanical or an equipment or a combination of one or more of the above devices such as virtual reality (VR) devices, augmented reality (AR) devices, laptop, a general-purpose computer, desktop, personal digital assistant, tablet computer, mainframe computer, or any other computing device, wherein the computing device may include one or more in-built or externally coupled accessories including, but not limited to, a visual aid device such as camera, audio aid, a microphone, a keyboard, input devices for receiving input from a user such as touch pad, touch enabled screen, electronic pen and the like. It may be appreciated that the UEs may not be restricted to the mentioned devices and various other devices may be used.
- VR virtual reality
- AR augmented reality
- laptop a general-purpose computer
- desktop personal digital assistant
- tablet computer tablet computer
- mainframe computer mainframe computer
- the computing device may include one or more in-built or externally coupled accessories including, but not limited to, a visual aid device such as camera, audio aid, a
- a system may include one or more processors coupled with a memory, wherein the memory may store instructions which when executed by the one or more processors may cause the system to perform offloading/onloading of broadcasting or multicasting content in networks.
- the system may include one or more processor(s).
- the one or more processor(s) may be implemented as one or more microprocessors, microcomputers, microcontrollers, edge or fog microcontrollers, digital signal processors, central processing units, logic circuitries, and/or any devices that process data based on operational instructions.
- the one or more processor(s) may be configured to fetch and execute computer-readable instructions stored in a memory of the system.
- the memory may be configured to store one or more computer-readable instructions or routines in a non- transitory computer readable storage medium, which may be fetched and executed to create or share data packets over a network service.
- the memory may comprise any non-transitory storage device including, for example, volatile memory such as Random-Access Memory (RAM), or non-volatile memory such as Electrically Erasable Programmable Read-only Memory (EPROM), flash memory, and the like.
- the system may include an interface(s).
- the interface(s) may comprise a variety of interfaces, for example, interfaces for data input and output devices, referred to as input/output (I/O) devices, storage devices, and the like.
- the interface(s) may facilitate communication for the system.
- the interface(s) may also provide a communication pathway for one or more components of the system. Examples of such components include, but are not limited to, processing unit/engine(s) and a database.
- the processing unit/engine(s) may be implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the processing engine(s). In examples described herein, such combinations of hardware and programming may be implemented in several different ways.
- the programming for the processing engine(s) may be processor executable instructions stored on a non-transitory machine-readable storage medium and the hardware for the processing engine(s) may comprise a processing resource (for example, one or more processors), to execute such instructions.
- the machine-readable storage medium may store instructions that, when executed by the processing resource, implement the processing engine(s).
- the system may include the machine -readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine- readable storage medium may be separate but accessible to the system and the processing resource.
- the processing engine(s) may be implemented by electronic circuitry.
- the database may comprise data that may be either stored or generated as a result of functionalities implemented by any of the components of the processor or the processing engines.
- a computer system may include an external storage device, a bus, a main memory, a read-only memory, a mass storage device, communication port(s), and a processor.
- the communication port(s) may be any of an RS-232 port for use with a modem-based dialup connection, a 10/100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports.
- the communication port(s) may be chosen depending on a network, such a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system connects.
- LAN Local Area Network
- WAN Wide Area Network
- the main memory may be random access memory (RAM), or any other dynamic storage device commonly known in the art.
- the read-only memory may be any static storage device(s) including, but not limited to, a Programmable Read Only Memory (PROM) chips for storing static information e.g., start-up or basic input/output system (BIOS) instructions for the processor.
- the mass storage device may be any current or future mass storage solution, which may be used to store information and/or instructions.
- the bus communicatively couples the processor with the other memory, storage, and communication blocks.
- the bus can be, e.g.
- PCI Peripheral Component Interconnect
- PCLX PCI Extended
- SCSI Small Computer System Interface
- USB universal serial bus
- operator and administrative interfaces e.g. a display, keyboard, and a cursor control device, may also be coupled to the bus to support direct operator interaction with the computer system.
- Other operator and administrative interfaces may be provided through network connections connected through the communication port(s).
- One or more processors -205 are included in the central processing unit - ;
- Request receiving module - 228
- Gap count calculation module - 235 [0089]
- Integrity validation module - 245 Integrity validation module - 245;
- Kernel - 315 [0095] Kernel - 315.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP24835668.5A EP4740692A1 (en) | 2023-07-03 | 2024-06-26 | System and method of handling integrity failure for idle mode nas |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| IN202321044337 | 2023-07-03 | ||
| IN202321044337 | 2023-07-03 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025008947A1 true WO2025008947A1 (en) | 2025-01-09 |
Family
ID=94171268
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/IN2024/050928 Ceased WO2025008947A1 (en) | 2023-07-03 | 2024-06-26 | System and method of handling integrity failure for idle mode nas |
Country Status (2)
| Country | Link |
|---|---|
| EP (1) | EP4740692A1 (en) |
| WO (1) | WO2025008947A1 (en) |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2020207401A1 (en) * | 2019-04-08 | 2020-10-15 | Mediatek Singapore Pte. Ltd. | 5g nas recovery from nasc failure |
| US20220007182A1 (en) * | 2018-11-02 | 2022-01-06 | Apple Inc. | Protection of Initial Non-Access Stratum Protocol Message in 5G Systems |
-
2024
- 2024-06-26 WO PCT/IN2024/050928 patent/WO2025008947A1/en not_active Ceased
- 2024-06-26 EP EP24835668.5A patent/EP4740692A1/en active Pending
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20220007182A1 (en) * | 2018-11-02 | 2022-01-06 | Apple Inc. | Protection of Initial Non-Access Stratum Protocol Message in 5G Systems |
| WO2020207401A1 (en) * | 2019-04-08 | 2020-10-15 | Mediatek Singapore Pte. Ltd. | 5g nas recovery from nasc failure |
Also Published As
| Publication number | Publication date |
|---|---|
| EP4740692A1 (en) | 2026-05-13 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US10326591B2 (en) | Efficient quantum key management | |
| CN107533543B (en) | Distributed memory caching system with local cache | |
| US9003519B2 (en) | Verifying transactions using out-of-band devices | |
| US10171463B1 (en) | Secure transport layer authentication of network traffic | |
| US11025425B2 (en) | User security token invalidation | |
| US9589122B2 (en) | Operation processing method and device | |
| CN112559994B (en) | Access control methods, devices, equipment and storage media | |
| US10783277B2 (en) | Blockchain-type data storage | |
| US10567492B1 (en) | Methods for load balancing in a federated identity environment and devices thereof | |
| CN113225348B (en) | Request anti-replay verification method and device | |
| US11252143B2 (en) | Authentication system, authentication server and authentication method | |
| CN112887284B (en) | Access authentication method and device, electronic equipment and readable medium | |
| US12225132B2 (en) | Cybersecurity guard for core network elements | |
| US8996607B1 (en) | Identity-based casting of network addresses | |
| WO2015074443A1 (en) | An operation processing method and device | |
| CN110674376A (en) | Interface parameter checking method, device, equipment and computer readable storage medium | |
| CN107135085B (en) | Statistical control method and system for directional flow | |
| US20170270561A1 (en) | Method, terminal and server for monitoring advertisement exhibition | |
| WO2018024176A1 (en) | Device and method preventing repeated logins of same user | |
| EP3193485A1 (en) | Device, server, system and method for data attestation | |
| CN115130116A (en) | Business resource access method, device, equipment, readable storage medium and system | |
| CN112966286B (en) | Method, system, device and computer readable medium for user login | |
| CN111586013B (en) | Network intrusion detection method, device, node terminal and storage medium | |
| EP4740692A1 (en) | System and method of handling integrity failure for idle mode nas | |
| CN110417615B (en) | Check switch control method, device and equipment and computer readable storage medium |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24835668 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2024835668 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2024835668 Country of ref document: EP Effective date: 20260203 |
|
| WWP | Wipo information: published in national office |
Ref document number: 2024835668 Country of ref document: EP |