Protection of BAP transmissions
A method performed by a first node includes obtaining a configuration for performing backhaul integrity protection and verification for backhaul adaptation protocol, BAP, data protocol data unit, PDU, packets transmitted and/or received over a backhaul link. The method includes computing a security token to be included in a BAP data PDU to be transmitted. The method includes adding the security token in the BAP data PDU. The method includes transmitting the BAP data PDU with the security token towards a second IAB node.
1 . A method performed by a first node comprising:
obtaining a configuration for performing backhaul integrity protection and verification for backhaul adaptation protocol (BAP) data protocol data unit (PDU) packets transmitted and/or received over a backhaul link;
computing a security token to be included in a BAP data PDU to be transmitted;
adding the security token in the BAP data PDU; and
transmitting the BAP data PDU with the security token towards a second IAB node, wherein obtaining the configuration comprises obtaining parameters for using in performing the backhaul integrity protection and verification, wherein adding the security token in the BAP data PDU comprises setting a field in a BAP header to indicate presence of the security token.
2 . The method of claim 1 , wherein obtaining the parameters comprises obtaining one or more of:
an identification (ID) of the backhaul (BH) radio link control (RLC) channel ID associated to the BAP PDU to be protected;
security keys comprising a root key and/or derived keys for integrity protection;
a D/C bit indicating if the PDU is a BAP Control PDU or a BAP Data PDU, one or more reserved bits (R) and a T bit to indicate presence/absence of a token field;
a refresh token for providing replay protection;
an IAB node destination identity of the BAP data PDU to be protected;
a path identity over which the BPA data PDU to be protected is transmitted; and
a security algorithm identity of a security algorithm to use for integrity protection, wherein computing a security token comprises computing the security token based on the security algorithm identity.
3 . The method of claim 1 , further comprising responsive to receiving a BAP data PDU having a security token to be forwarded to a next IAB node:
relaying the security token included in the BAP data PDU received to the next IAB node without modifying the security token, or
performing integrity protection verification on the BAP data PDU received.
4 . The method of claim 3 wherein the BAP data PDU has multiple security tokens and performing integrity protection verification comprises performing integrity protection verification on a security token of the multiple security tokens meant for the IAB node.
5 . The method of claim 3 , wherein performing integrity protection verification comprises generating a token based on parameters associated to the BAP data PDU.
6 . The method of claim 1 , further comprising:
responsive to receiving a BAP data PDU for the IAB node, performing integrity protection verification on the BAP data PDU received.
7 . The method of claim 3 , further comprising:
responsive to the integrity protection verification results in determining that the BAP data PDU is not valid, discarding the BAP data PDU.
8 . The method of claim 3 , further comprising:
responsive to the integrity protection verification results in determining that the BAP data PDU is not valid, transmitting an indication to a central unit IAB node that the BAP data PDU has been declared as not valid due to an unsuccessful security protection verification.
9 . The method of claim 3 , further comprising:
responsive to the integrity protection verification results in determining that the BAP data PDU is not valid, performing a Radio Resource Control (RRC) connection reestablishment, and wherein performing the RRC connection reestablishment comprises performing the RRC connection reestablishment to an IAB node different from the one from which the BAP data PDU received that was determined to not be valid.
10 . The method of claim 3 , further comprising:
responsive to the integrity protection verification results in determining that the BAP data PDU is not valid, keeping a log of BAP data PDUs that are not valid and informing higher layers of the BAP data PDU that has been declared as not valid due to an unsuccessful security protection verification.
11 . The method of claim 3 , further comprising:
responsive to the integrity protection verification results in determining that the BAP data PDU is valid, removing the header, including the security token and forwarding content of the BAP data PDU to higher layers and to a transmitting entity if the BAP data PDU has to be relayed to a next hop.
12 . A method performed by a central unit (CU) Integrated Access and Backhaul (IAB) node comprising:
receiving an indication from an IAB node;
responsive to the indication being of a received invalid BAP PDU caused by a second IAB node, performing at least one action to prevent the second IAB node from further attacks, wherein performing the at least one action comprises releasing a radio resource control (RRC) connection between the IAB node and the second IAB node, wherein performing the at least one CU IAB node action further comprises updating routing tables of IAB node such that the second IAB node is excluded from an IAB network topology, or releasing RRC connections and F1 connections of the second IAB node.
13 . The method of claim 12 , further comprising:
transmitting a configuration for performing backhaul integrity protection and verification for backhaul adaptation protocol (BAP) data protocol data unit (PDU) packets transmitted and/or received over a backhaul link to the IAB node.
14 . The method of claim 12 , wherein the second IAB node comprises an attacking IAB node.
15 . A first node comprising:
processing circuitry; and
memory coupled with the processing circuitry, wherein the memory includes instructions that when executed by the processing circuitry causes the first node to perform operations according to claim 1 .
16 . A Central Unit (CU) Integrated Access and Backhaul (IAB) node comprising:
processing circuitry; and
memory coupled with the processing circuitry, wherein the memory includes instructions that when executed by the processing circuitry causes the CU IAB node to perform operations according to claim 12 .