Key and counter management in wireless systems
Disclosed are wireless communications systems and techniques. For example, a wireless communication device (e.g., a user equipment (UE)) compares a first key identifier (generated from a key stored in a first storage unit, such as a universal subscriber identity module) to a second key identifier (stored in a second storage unit, such as non-volatile memory) to identify a mismatch between the key identifiers. Based on the mismatch, the device replaces, in the second storage unit, the second key identifier. In some examples, the device verifies integrity of a message using the key, replaces the second key identifier with the first key identifier, and updates a counter based on the message. In a second illustrative example, the device replaces the key with a replacement key, replaces the second key identifier with the third key identifier based on the replacement key, and resets a counter.
1 . An apparatus for wireless communications, comprising:
at least one memory comprising instructions; and
at least one processor coupled to the at least one memory and configured to:
identify a change associated with a removable storage unit;
set, in response to the change, a Key Set Identifier (KSI) to a predetermined value; and
invalidate, in response to the change, a security context, wherein the security context is not the KSI.
2 . The apparatus of claim 1 , wherein the at least one processor is configured to:
delete, in response to the change, a key.
3 . The apparatus of claim 2 , wherein the key is an Authentication Server Function (AUSF) key K AUSF .
4 . The apparatus of claim 2 , wherein the at least one processor is configured to:
initiate an authentication procedure to cause a new instance of the key to be generated to replace the key.
5 . The apparatus of claim 1 , wherein the removable storage unit is a universal subscriber identity module (USIM) that corresponds to the security context, and wherein the change associated with the removable storage unit includes a removal of the USIM from the apparatus.
6 . The apparatus of claim 5 , wherein the at least one processor is configured to:
delete, in response to the change, a key that corresponds to the USIM.
7 . The apparatus of claim 1 , wherein the removable storage unit is a first universal subscriber identity module (USIM) that corresponds to the security context, and wherein the change associated with the removable storage unit includes a change from the first USIM to a second USIM.
8 . The apparatus of claim 7 , wherein the at least one processor is configured to:
delete, in response to the change, a key that corresponds to the first USIM.
9 . The apparatus of claim 1 , wherein the removable storage unit is a universal subscriber identity module (USIM) that corresponds to the security context, and wherein the change associated with the removable storage unit includes a key being stored on the USIM and a counter being not present on the USIM, wherein the counter is associated with at least one of Steering of Roaming (SoR) or User equipment Parameters Update (UPU).
10 . The apparatus of claim 9 , wherein the at least one processor is configured to:
delete, in response to the change, a key that corresponds to the USIM.
11 . The apparatus of claim 1 , wherein the removable storage unit is a universal subscriber identity module (USIM) that corresponds to the security context and that stores a first instance of a key, and wherein the change associated with the removable storage unit includes the USIM storing a second instance of the key that is different from the first instance of the key.
12 . The apparatus of claim 11 , wherein the at least one processor is configured to:
delete, in response to the change, the second instance of the key from the USIM.
13 . The apparatus of claim 11 , wherein the at least one processor is configured to:
delete, in response to the change, the first instance of the key from a second storage unit.
14 . The apparatus of claim 1 , wherein the predetermined value is 111.
15 . The apparatus of claim 1 , wherein the predetermined value indicates that a key is invalid.
16 . The apparatus of claim 1 , wherein the at least one processor is configured to:
initiate an authentication procedure to cause a new security context to be generated to replace the security context.
17 . The apparatus of claim 1 , wherein the at least one processor is configured to:
initiate an authentication procedure based on the KSI being set to the predetermined value.
18 . The apparatus of claim 1 , wherein the KSI is a next-generation KSI (ngKSI) associated with a fifth-generation (5G) cellular network.
19 . The apparatus of claim 1 , wherein the security context includes at least one of Steering of Roaming (SoR) context or User equipment Parameters Update (UPU) context.
20 . The apparatus of claim 1 , wherein, to invalidate the security context, the at least one processor is configured to delete the security context.
21 . A method of wireless communications, the method comprising:
identifying a change associated with a removable storage unit;
setting, in response to the change, a Key Set Identifier (KSI) to a predetermined value; and
invalidating, in response to the change, a security context, wherein the security context is not the KSI.