Method, apparatus, and system for user plane security in communication system
Disclosed is a 6G communication system for achieving a high data transmission rate and a super-low latency time after 4G and 5G communication systems. According to various embodiments of the present disclosure, a method of selectively performing integrity protection or ciphering for data (for example, UP data, user data, or application data), an apparatus for performing the method, and a system for implementing embodiments are provided. According to an embodiment, a UP security procedure based on whether data is ciphered is provided. According to an embodiment, when confidentiality and integrity are provided for data, a packet structure for improving calculation efficiency is provided. Accordingly, an effect of reducing calculation resources and calculation time spent for enhancing security of data can be obtained by preventing already ciphered data from being overlappingly ciphered, and thus a more efficient communication system can be implemented.
1 . A method of a base station in a communication system, the method comprising:
receiving, from a server or a user equipment (UE), a request to configure user plane (UP) security for at least one header of a packet except for ciphered payload, wherein the packet includes payload and the at least one header, the payload corresponding to data, and the at least one header being associated with the data;
determining whether the payload is ciphered at an upper layer and the at least one header is not ciphered at the upper layer, based on the request;
in case that the payload is ciphered and the at least one header is not ciphered, transmitting, to the, a control message including an indicator instructing the UE to configure the UP security for the at least one header, except for the payload;
configuring the UP security for the at least one header, except for the payload; and
transmitting, to the UE, a downlink signal secured based on the UP security, and receiving, from the UE, an uplink signal secured based on the UP security,
wherein configuring the UP security for the at least one header includes ciphering the at least one header.
2 . The method of claim 1 , further comprising:
performing an inspection of the packet based on at least one ciphering protocol,
wherein the payload is determined to be ciphered based on the inspection.
3 . The method of claim 1 ,
wherein the payload is determined to be ciphered based on a reception of the request.
4 . The method of claim 1 ,
wherein configuring the UP security for the at least one header further includes:
performing integrity protection procedure for the at least one header; and
generating information for integrity protection, based on the integrity protection procedure,
wherein the information for the integrity protection is ciphered with the at least one header,
wherein the information for the integrity protection includes a message authentication code-integrity (MAC-I),
wherein a location of the information for the integrity protection corresponding to the payload is determined based on a location of the payload, and
wherein the information for the integrity protection is located in front of the payload in the packet.
5 . A method of a user equipment (UE) in a communication system, the method comprising:
transmitting, to a base station, a request to configure user plane (UP) security for at least one header of a packet except for ciphered payload, wherein the packet includes payload and the at least one header, the payload corresponding to data, and the at least one header being associated with the data;
as a response to the request, in case that the payload is ciphered at an upper layer and the at least one header is not ciphered at the upper layer, receiving, from the base station, a control message including an indicator instructing the UE to configure the UP security for the at least one header, except for the payload;
configuring the UP security for the at least one header, except for the payload; and
receiving, from the base station, a downlink signal secured based on the UP security, and transmitting, to the base station, an uplink signal secured based on the UP security,
wherein configuring the UP security for the at least one header includes ciphering the at least one header.
6 . The method of claim 5 ,
wherein configuring the UP security for the at least one header further includes:
performing integrity protection procedure for the at least one header; and
generating information for integrity protection based on the integrity protection procedure,
wherein the information for the integrity protection is ciphered with the at least one header,
wherein the information for the integrity protection includes a message authentication code-integrity (MAC-I),
wherein a location of the information for the integrity protection corresponding to the payload is determined based on a location of the payload, and
wherein the information for the integrity protection is located in front of the payload in the packet.
7 . A method of a server in a communication system, the method comprising:
generating a request to configure user plane (UP) security for at least one header of a packet except for ciphered payload, wherein the packet includes payload and the at least one header, the payload corresponding to data, and the at least one header being associated with the data; and
transmitting, to a base station, the request;
wherein, in case that the payload is ciphered at an upper layer and the at least one header is not ciphered at the upper layer, a downlink signal and an uplink signal are secured based on the UP security for the at least one header except for the payload, and
wherein the UP security for the at least one header includes ciphering for the at least one header.
8 . A base station in a communication system, the base station comprising:
a transceiver; and
a controller operably connected to the transceiver, the controller configured to:
receive, from a server or a user equipment (UE), a request to configure user plane (UP) security for at least one header of a packet except for ciphered payload, wherein the packet includes payload and the at least one header, the payload corresponding to data, and the at least one header being associated with the data,
determine whether the payload is ciphered at an upper layer and the at least one header is not ciphered at the upper layer, based on the request,
in case that the payload is ciphered and the at least one header is not ciphered, transmit, to the UE, a control message including an indicator instructing the UE to configure the UP security for the at least one header, except for the payload,
configure the UP security for the at least one header, except for the payload, and
transmit, to the UE, a downlink signal secured based on the UP security, and receive, from the UE, an uplink signal secured based on the UP security,
wherein a configuration of the UP security for the at least one header includes ciphering the at least one header.
9 . The base station of claim 8 ,
wherein the controller is further configured to perform an inspection of the packet based on at least one ciphering protocol, and
wherein the payload is determined to be ciphered based on the inspection.
10 . The base station of claim 8 ,
wherein the payload is determined to be ciphered based on a reception of the request.
11 . The base station of claim 8 ,
wherein the configuration of the UP security for the at least one header further includes:
performing integrity protection procedure for the at least one header; and
generating information for integrity protection, based on the integrity protection procedure,
wherein the information for the integrity protection is ciphered with the at least one header,
wherein the information for the integrity protection includes a message authentication code-integrity (MAC-I),
wherein a location of the information for the integrity protection corresponding to the payload is determined based on a location of the payload, and
wherein the information for the integrity protection is located in front of the payload in the packet.
12 . A user equipment (UE) in a communication system, the UE comprising:
a transceiver; and
a controller operably connected to the transceiver, the controller configured to:
transmit, to a base station, a request to configure user plane (UP) security for at least one header of a packet except for ciphered payload, wherein the packet includes payload and the at least one header, the payload corresponding to data, and the at least one header being associated with the data;
as a response to the request, in case that the payload is ciphered at an upper layer and the at least one header is not ciphered at the upper layer, receive, from the base station, a control message including an indicator instructing the UE to configure the UP security for the at least one header, except for the payload,
configure the UP security for the at least one header, except for the payload, and
receive, from the base station, a downlink signal secured based on the UP security, and transmit, to the base station, an uplink signal secured based on the UP security,
wherein a configuration of the UP security for the at least one header includes ciphering the at least one header.
13 . The UE of claim 12 ,
wherein the configuration of the UP security for the at least one header further includes:
performing integrity protection procedure for the at least one header; and
generating information for integrity protection based on the integrity protection procedure,
wherein the information for the integrity protection is ciphered with the at least one header,
wherein the information for the integrity protection includes a message authentication code-integrity (MAC-I),
wherein a location of the information for the integrity protection corresponding to the payload is determined based on a location of the payload, and
wherein the information for the integrity protection is located in front of the payload in the packet.
14 . A server in a communication system, the server comprising:
a transceiver; and
a controller operably connected to the transceiver, the controller configured to:
generate a request to configure user plane (UP) security for at least one header of a packet except for ciphered payload, wherein the packet includes payload and the at least one header, the payload corresponding to data, and the at least one header being associated with the data, and
transmit, to a base station, the request,
wherein, in case that the payload is ciphered at an upper layer and the at least one header is not ciphered at the upper layer, a downlink signal and an uplink signal are secured based on the UP security for the at least one header except for the payload, and
wherein the UP security for the at least one header includes ciphering for the at least one header.