Secure communication of broadcast information related to cell access
Aspects of the disclosure relate to mechanisms for securely communicating broadcast information related to cell access within a secure cell. The broadcast information may be encrypted using a cell-specific broadcast key that may be derived from a broadcast root key that is refreshed periodically. A wireless communication device may obtain the broadcast root key via a secure connection with a provisioning server or core network node within a core network maintaining the broadcast root key or a long term key from which the broadcast root key may be derived. The cell-specific broadcast key may be derived using a key derivation function of the broadcast root key and at least cell identifying information associated with the secure cell.
1 . A method of wireless communication, comprising, at a wireless communication device:
obtaining a broadcast root key of a plurality of broadcast root keys, wherein each of the plurality of broadcast root keys is allocated to a different respective set of wireless communication devices;
receiving an acquisition signal from a radio access network (RAN) node serving a secure cell within a RAN of a wireless communication system;
receiving provisioning information comprising a system frame number (SFN) of the RAN and a hyper frame number (HFN) of the RAN;
obtaining cell identifying information based on at least the acquisition signal;
deriving a cell-specific broadcast key based on at least the broadcast root key and the cell identifying information, wherein the cell-specific broadcast key is unique to the secure cell and derivable by each of a plurality of wireless communication devices within the secure cell, wherein the cell-specific broadcast key is common to all of the plurality of wireless communication devices within the secure cell;
receiving encrypted broadcast information related to cell access broadcast to the plurality of wireless communication devices, including the wireless communication device, in the secure cell; and
decrypting the encrypted broadcast information based on the cell-specific broadcast key and a freshness parameter to produce decrypted broadcast information, wherein the freshness parameter comprises a concatenation of the HFN and the SFN.
2 . The method of claim 1 , wherein the obtaining the broadcast root key further comprises:
receiving provisioning information further comprising additional provisioning information that comprises at least one of the broadcast root key, a long term key, a current time, or a key identifier of the broadcast root key, or a system frame number (SFN) of the RAN.
3 . The method of claim 2 , wherein the obtaining the broadcast root key further comprises:
deriving the broadcast root key based on at least the long term key, a refresh parameter determined based on the current time, and one or more of a network identifier associated with the RAN, a tracking area code associated with a tracking area comprising the secure cell, an area identifier associated with the RAN node, or a registration area code associated with a registration area comprising the secure cell.
4 . The method of claim 3 , wherein the refresh parameter comprises a quotient of a current counter value of a counter set based on the current time and a key refresh interval.
5 . The method of claim 1 , wherein the obtaining the broadcast root key further comprises:
receiving additional provisioning information associated with the broadcast root key via an out-of-band delivery path external to the wireless communication system.
6 . The method of claim 1 , wherein the obtaining the broadcast root key further comprises:
receiving additional provisioning information associated with the broadcast root key from at least one of a provisioning server, a core network node, or the RAN node.
7 . The method of claim 1 , wherein the obtaining the broadcast root key further comprises:
accessing a pinhole access cell served by the RAN node based on unencrypted broadcast information related to cell access transmitted in the pinhole access cell; and
registering with a core network via the pinhole access cell to obtain the broadcast root key.
8 . The method of claim 7 , wherein the obtaining the broadcast root key further comprises:
establishing a protocol data unit (PDU) session via the pinhole access cell; establishing a connection with a provisioning server via the PDU session; and
receiving additional provisioning information associated with the broadcast root key on the wireless communication device from the provisioning server.
9 . The method of claim 8 , further comprising:
performing device authentication and device attestation with the provisioning server to establish a secure connection with the provisioning server, wherein the receiving the additional provisioning information further comprises:
receiving the additional provisioning information in response to successfully performing the device authentication and the device attestation.
10 . The method of claim 7 , wherein the registering with the core network further comprises:
transmitting a registration request message to a core network node within the core network via the pinhole access cell; and
receiving a registration accept message from the core network node via the pinhole access cell, wherein the registration accept message comprises the additional provisioning information associated with the broadcast root key.
11 . The method of claim 7 , further comprising:
receiving a radio resource control (RRC) connection release message from the pinhole access cell, wherein the RRC connection release message comprises redirection information for redirecting the wireless communication device to the secure cell; and
accessing the secure cell utilizing the decrypted broadcast information.
12 . The method of claim 7 , further comprising:
receiving a handover command from the pinhole access cell to handover the wireless communication device from the pinhole access cell to the secure cell; and
accessing the secure cell utilizing the decrypted broadcast information.
13 . The method of claim 1 , wherein:
the cell identifying information comprises a concatenation of a physical cell identity (PCI) and an absolute radio frequency channel number (ARFCN) of the secure cell, and
the acquisition signal comprises unencrypted broadcast information and at least a part of the encrypted broadcast information, wherein the unencrypted broadcast information comprises the PCI and the ARFCN.
14 . The method of claim 13 , wherein:
the acquisition signal comprises a synchronization signal block (SSB) comprising a primary synchronization signal, a secondary synchronization signal, and a physical broadcast control channel (PBCH),
the unencrypted broadcast information comprises the primary synchronization signal,
the secondary synchronization signal and a first portion of the PBCH,
the first portion of the PBCH comprises the SFN within a master information block (MIB), and
the encrypted broadcast information comprises a remaining portion of the PBCH, a system information block, and a physical downlink control channel (PDCCH) control resource set comprising scheduling information for the system information block.
15 . The method of claim 1 , wherein the acquisition signal comprises a first acquisition signal comprising the encrypted broadcast information and a second acquisition signal comprising at least one cell-specific security parameter.
16 . The method of claim 15 , wherein the at least one cell-specific security parameter comprises the cell identifying information, and wherein the deriving the cell-specific broadcast key further comprises:
deriving the cell-specific broadcast key based on the broadcast root key and the at least one cell-specific security parameter, wherein the at least one cell-specific security parameter further comprises at least one of a key identifier of the broadcast root key, an identifier of the RAN node, or the freshness parameter.
17 . The method of claim 15 , wherein the second acquisition signal comprises a message authentication code derived from the cell-specific broadcast key and the second acquisition signal, and further comprising:
verifying an integrity of the second acquisition signal using the message authentication code based on an integrity protection key derived from the cell-specific broadcast key.
18 . The method of claim 1 , wherein the deriving the cell-specific broadcast key further comprises:
deriving a broadcast RAN key based on the broadcast root key and an identifier of the RAN node; and
deriving the cell-specific broadcast key based on the broadcast RAN key and the cell identifying information.
19 . The method of claim 1 , further comprising:
registering with a core network upon accessing the secure cell;
establishing an access stratum security context with the RAN node, the access stratum security context comprising a RAN node key;
deriving a cell-specific unicast key based on the RAN node key and at least one parameter, wherein the at least one parameter comprises a concatenation of the cell identifying information and the freshness parameter;
receiving encrypted downlink control information comprising unicast information for the wireless communication device from the RAN node; and
decrypting the encrypted downlink control information using the cell-specific unicast key.
20 . A wireless communication device configured for wireless communication, comprising:
one or more memories; and
one or more processors coupled to the one or more memories, wherein the one or more processors are configured to:
obtain provisioning information comprising a broadcast root key of a plurality of broadcast root keys, wherein each of the plurality of broadcast root keys is allocated to a different respective set of wireless communication devices;
receive an acquisition signal from a radio access network (RAN) node serving a secure cell within a RAN of a wireless communication network;
receive provisioning information comprising a system frame number (SFN) of the RAN and a hyper frame number (HFN) of the RAN;
obtain cell identifying information based on at least the acquisition signal;
derive a cell-specific broadcast key based on at least the broadcast root key and the cell identifying information, wherein the cell-specific broadcast key is unique to the secure cell and derivable by each of a plurality of wireless communication devices within the secure cell, wherein the cell-specific broadcast key is common to all of the plurality of wireless communication devices within the secure cell;
receive encrypted broadcast information related to cell access, the encrypted broadcast information being broadcast to the plurality of wireless communication devices, including the wireless communication device, in the secure cell; and
decrypt the encrypted broadcast information based on the cell-specific broadcast key and a freshness parameter to produce decrypted broadcast information, wherein the freshness parameter comprises a concatenation of the HFN and the SFN to access the secure cell.
21 . A method of wireless communication in a wireless communication system, comprising, at a radio access network (RAN) node:
obtaining a cell-specific broadcast key for a secure cell served by the RAN node within a RAN, the cell-specific broadcast key being derived based on a broadcast root key of a plurality of broadcast root keys, each associated with a different respective set of wireless communication devices, wherein the cell-specific broadcast key is unique to the secure cell and derivable by each of a plurality of wireless communication devices within the secure cell, wherein the cell-specific broadcast key is common to all of the plurality of wireless communication devices within the secure cell;
transmitting provisioning information comprising a system frame number (SFN) of the RAN and a hyper frame number (HFN) of the RAN to a wireless communication device;
encrypting broadcast information related to cell access for broadcast to the plurality of wireless communication devices in the secure cell based on the cell-specific broadcast key and a freshness parameter to produce encrypted broadcast information, wherein the freshness parameter comprises a concatenation of the HFN and the SFN; and
providing the encrypted broadcast information in the secure cell.
22 . The method of claim 21 , wherein the obtaining the cell-specific broadcast key further comprises:
receiving the cell-specific broadcast key from a core network node within a core network, wherein the cell-specific broadcast key is derived from the broadcast root key provided to the core network node by a provisioning server.
23 . The method of claim 21 , wherein the obtaining the cell-specific broadcast key further comprises:
receiving a broadcast RAN key derived from the broadcast root key from a core network node in a core network; and
deriving the cell-specific broadcast key based on the broadcast RAN key and cell identifying information associated with the secure cell.
24 . The method of claim 21 , wherein at least a part of the encrypted broadcast information is transmitted within a first acquisition signal in the secure cell, and further comprising:
transmitting a second acquisition signal comprising at least one cell-specific security parameter, wherein the at least one cell-specific security parameter comprises cell identifying information and further comprises at least one of a key identifier of the broadcast root key from which the cell-specific broadcast key is derived, an identifier of the RAN node, or the freshness parameter.
25 . The method of claim 21 , further comprising:
transmitting provisioning information to a wireless communication device, wherein at least part of the provisioning information originating at a provisioning server, wherein the provisioning information further comprises additional provisioning information that enables provisioning of the broadcast root key from which the cell-specific broadcast key is derived on the wireless communication device, wherein the additional provisioning information further comprises at least one of the broadcast root key, a long term key, a current time, or a key identifier of the broadcast root key, or a system frame number (SFN).
26 . The method of claim 21 , further comprising:
transmitting unencrypted broadcast information related to cell access in a pinhole access cell served by the RAN node;
receiving a registration request from a wireless communication device via the pinhole access cell based on the unencrypted broadcast information to register the wireless communication device with a core network; and
transmitting a registration accept message from a core network node within the core network to the wireless communication device via the pinhole access cell.
27 . The method of claim 21 , further comprising:
establishing an access stratum security context with a wireless communication device upon the wireless communication device registering with a core network, the access stratum security context comprising a RAN node key;
deriving a cell-specific unicast key based on the RAN node key and at least one parameter;
encrypting downlink control information comprising unicast information for the wireless communication device using the cell-specific unicast key to produce encrypted downlink control information; and
transmitting the encrypted downlink control information to the wireless communication device.
28 . A radio access network (RAN) node, comprising:
one or more memories; and
one or more processors coupled to the one or more memories, wherein the one or more processors are configured to:
obtain a cell-specific broadcast key for a secure cell served by the RAN node within a RAN, the cell-specific broadcast key being derived based on a broadcast root key of a plurality of broadcast root keys, each associated with a different respective set of wireless communication devices, wherein the cell-specific broadcast key is unique to the secure cell and derivable by each of a plurality of wireless communication devices within the secure cell, wherein the cell-specific broadcast key is common to all of the plurality of wireless communication devices within the secure cell;
transmit provisioning information comprising a system frame number (SFN) of the RAN and a hyper frame number (HFN) of the RAN to a wireless communication device;
encrypt broadcast information related to cell access for broadcast to the plurality of wireless communication devices in the secure cell based on the cell-specific broadcast key and a freshness parameter to produce encrypted broadcast information, wherein the freshness parameter comprises a concatenation of the HFN and the SFN; and
provide the encrypted broadcast information in the secure cell.