School of Specs 24.501v20.0.0

3GPP 24.501 v20.0.0 — the document's own text

4.4.3.4 Ciphering and deciphering

The sender shall use its locally stored NAS COUNT as input to the ciphering algorithm.

The receiver shall use the NAS sequence number included in the received message and an estimate for the NAS overflow counter as defined in clause 4.4.3.1 to form the NAS COUNT input to the deciphering algorithm.

The input parameters to the NAS ciphering algorithm are the BEARER ID, DIRECTION bit, NAS COUNT, NAS encryption key and the length of the key stream to be generated by the encryption algorithm.

When applying initial NAS message protection to the REGISTRATION REQUEST, DEREGISTRATION REQUEST or SERVICE REQUEST message as described in clause 4.4.6, the length of the key stream is set to the length of the entire plain NAS message that is included in the NAS message container IE, i.e. the value part of the NAS message container IE, that is to be ciphered.

When applying initial NAS message protection to the CONTROL PLANE SERVICE REQUEST message as described in clause 4.4.6, the length of the key stream is set to the length of:

  • the value part of the CIoT small data container IE that is to be ciphered; or
  • the value part of the NAS message container IE that is to be ciphered.

When any NAS message is not sent as initial NAS message and needs to be sent ciphered, the length of the key stream is set to the length of the Plain 5GS NAS message IE in the security protected 5GS NAS message (see figure 9.1.1.2) starting with octet 8 (inclusive) until the end of the message.