IP Library Granted Patent US 12,739,639
Granted Patent B2
US 12,739,639 · App. 18/578,796 · Granted Sep 15, 2026

Protection of BAP transmissions

Inventors: Mattias Bergström (Sollentuna, SE); Marco Belleschi (Solna, SE); Prajwol Kumar Nakarmi (Solna, SE); Monica Wifvesson (Lund, SE)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04W12/106
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,639
App. No.
18/578,796
Granted
Sep 15, 2026
Kind
B2
Abstract

A method performed by a first node includes obtaining a configuration for performing backhaul integrity protection and verification for backhaul adaptation protocol, BAP, data protocol data unit, PDU, packets transmitted and/or received over a backhaul link. The method includes computing a security token to be included in a BAP data PDU to be transmitted. The method includes adding the security token in the BAP data PDU. The method includes transmitting the BAP data PDU with the security token towards a second IAB node.

Claims (42)

1 . A method performed by a first node comprising:

obtaining a configuration for performing backhaul integrity protection and verification for backhaul adaptation protocol (BAP) data protocol data unit (PDU) packets transmitted and/or received over a backhaul link;

computing a security token to be included in a BAP data PDU to be transmitted;

adding the security token in the BAP data PDU; and

transmitting the BAP data PDU with the security token towards a second IAB node, wherein obtaining the configuration comprises obtaining parameters for using in performing the backhaul integrity protection and verification, wherein adding the security token in the BAP data PDU comprises setting a field in a BAP header to indicate presence of the security token.

2 . The method of claim 1 , wherein obtaining the parameters comprises obtaining one or more of:

an identification (ID) of the backhaul (BH) radio link control (RLC) channel ID associated to the BAP PDU to be protected;

security keys comprising a root key and/or derived keys for integrity protection;

a D/C bit indicating if the PDU is a BAP Control PDU or a BAP Data PDU, one or more reserved bits (R) and a T bit to indicate presence/absence of a token field;

a refresh token for providing replay protection;

an IAB node destination identity of the BAP data PDU to be protected;

a path identity over which the BPA data PDU to be protected is transmitted; and

a security algorithm identity of a security algorithm to use for integrity protection, wherein computing a security token comprises computing the security token based on the security algorithm identity.

3 . The method of claim 1 , further comprising responsive to receiving a BAP data PDU having a security token to be forwarded to a next IAB node:

relaying the security token included in the BAP data PDU received to the next IAB node without modifying the security token, or

performing integrity protection verification on the BAP data PDU received.

4 . The method of claim 3 wherein the BAP data PDU has multiple security tokens and performing integrity protection verification comprises performing integrity protection verification on a security token of the multiple security tokens meant for the IAB node.

5 . The method of claim 3 , wherein performing integrity protection verification comprises generating a token based on parameters associated to the BAP data PDU.

6 . The method of claim 1 , further comprising:

responsive to receiving a BAP data PDU for the IAB node, performing integrity protection verification on the BAP data PDU received.

7 . The method of claim 3 , further comprising:

responsive to the integrity protection verification results in determining that the BAP data PDU is not valid, discarding the BAP data PDU.

8 . The method of claim 3 , further comprising:

responsive to the integrity protection verification results in determining that the BAP data PDU is not valid, transmitting an indication to a central unit IAB node that the BAP data PDU has been declared as not valid due to an unsuccessful security protection verification.

9 . The method of claim 3 , further comprising:

responsive to the integrity protection verification results in determining that the BAP data PDU is not valid, performing a Radio Resource Control (RRC) connection reestablishment, and wherein performing the RRC connection reestablishment comprises performing the RRC connection reestablishment to an IAB node different from the one from which the BAP data PDU received that was determined to not be valid.

10 . The method of claim 3 , further comprising:

responsive to the integrity protection verification results in determining that the BAP data PDU is not valid, keeping a log of BAP data PDUs that are not valid and informing higher layers of the BAP data PDU that has been declared as not valid due to an unsuccessful security protection verification.

11 . The method of claim 3 , further comprising:

responsive to the integrity protection verification results in determining that the BAP data PDU is valid, removing the header, including the security token and forwarding content of the BAP data PDU to higher layers and to a transmitting entity if the BAP data PDU has to be relayed to a next hop.

12 . A method performed by a central unit (CU) Integrated Access and Backhaul (IAB) node comprising:

receiving an indication from an IAB node;

responsive to the indication being of a received invalid BAP PDU caused by a second IAB node, performing at least one action to prevent the second IAB node from further attacks, wherein performing the at least one action comprises releasing a radio resource control (RRC) connection between the IAB node and the second IAB node, wherein performing the at least one CU IAB node action further comprises updating routing tables of IAB node such that the second IAB node is excluded from an IAB network topology, or releasing RRC connections and F1 connections of the second IAB node.

13 . The method of claim 12 , further comprising:

transmitting a configuration for performing backhaul integrity protection and verification for backhaul adaptation protocol (BAP) data protocol data unit (PDU) packets transmitted and/or received over a backhaul link to the IAB node.

14 . The method of claim 12 , wherein the second IAB node comprises an attacking IAB node.

15 . A first node comprising:

processing circuitry; and

memory coupled with the processing circuitry, wherein the memory includes instructions that when executed by the processing circuitry causes the first node to perform operations according to claim 1 .

16 . A Central Unit (CU) Integrated Access and Backhaul (IAB) node comprising:

processing circuitry; and

memory coupled with the processing circuitry, wherein the memory includes instructions that when executed by the processing circuitry causes the CU IAB node to perform operations according to claim 12 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: BERGSTRÖM, MATTIAS; BELLESCHI, MARCO; NAKARMI, PRAJWOL KUMAR; WIFVESSON, MONICA
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 066108/0831 →
Continuity (2)
Provisional Application 63232984 · Aug 13, 2021
Related Publication 20240323689A1 · Sep 26, 2024
References Cited (13)
US 11350305B2 · Kim · 2022 [cited by examiner]
US 11856401B2 · Jactat · 2023 [cited by examiner]
US 20200221329A1 · Kim · 2020 [cited by examiner]
US 20210112415A1 · Lee · 2021 [cited by examiner]
WO 2020174291A1 · 2020 [cited by applicant]
Suomalainen et al., “Securing Public Safety Communications on Commercial and Tactical 5G Networks: A Survey and Future Research Directions”, n IEEE Open Journal of the Communications Society, vol. 2, pp. 1590-1615, (Yea… [cited by examiner]
Gonzalez-Diaz et al., “Integrating Fronthaul and Backhaul Networks: Transport Challenges and Feasibility Results,” in IEEE Transactions on Mobile Computing, vol. 20, No. 2, pp. 533-549, Feb. 1, 2021. [cited by examiner]
International Search Report and Written Opinion of the International Searching Authority, PCT/EP2022/068166, mailed Oct. 6, 2022, 17 pages. [cited by applicant]
Samsung, “BAP header protection for IAB,” 3GPP TSG-RAN2#106, R2-1906735 (Revision of R2-1904680), Reno, USA, May 13-17, 2019, 2 pages. [cited by applicant]
Ericsson, “IAB: Discussion on security of BH link,” 3GPP TSG-SA3 Meeting #104e-Adhoc, S3-213464, e-meeting, Sep. 27-30, 2021, 4 pages. [cited by applicant]
3GPP TS 38.473 V16.0.0 (Dec. 2019); 3rd Generation Partnership Project; Technical Specification Group Radio Access Network; NG-RAN; F1 application protocol (F1AP) (Release 16), 239 pages. [cited by applicant]
3GPP TS 38.331 V16.5.0 (Jun. 2021); 3rd Generation Partnership Project; Technical Specification Group Radio Access Network; NR; Radio Resource Control (RRC) protocol specification (Release 16), 959 pages. [cited by applicant]
3GPP TS 33.501 V16.7.1 (Jun. 2021); 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16), 255 pages. [cited by applicant]