Modifying a first data connection to support data traffic on a second data connection
By modifying a first data connection to support a second data connection with adjusted QoS parameters, the UE ensures appropriate QoS treatment for data traffic between different core networks, addressing the unawareness of QoS requirements in existing systems.
Patent Information
- Application Number
- JP2023560683
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-03-31
- Publication Date
- 2025-11-06
- Estimated Expiration
- 2041-03-31
AI Technical Summary
In wireless communication systems, a user equipment device (UE) connecting to a fifth-generation (5G) core network via a non-public network (NPN) is unaware of the quality of service (QoS) requirements of a connection to a public land mobile network (PLMN), leading to inadequate QoS handling for data traffic routed through the NPN.
The UE modifies a first data connection with a first mobile network to support a second data connection with a second mobile network by adjusting QoS parameters, ensuring that data traffic for the second connection receives appropriate QoS treatment by creating new QoS flows or mapping existing flows to meet the requirements of the second connection.
This approach enables seamless and QoS-aware data transfer between different core networks, ensuring that data traffic meets the necessary quality of service requirements during the establishment of a second data connection, even if the first connection is unaware of these requirements.
Smart Images

Figure 0007765492000001 
Figure 0007765492000002 
Figure 0007765492000003
Abstract
Description
[Technical Field]
[0001] The subject matter disclosed herein relates generally to wireless communications, and more particularly to modifying a first data connection to support data traffic on a second data connection. [Background technology]
[0002] In certain wireless communication systems, a user equipment device (“UE”) can connect to a fifth-generation (“5G”) core network (i.e., “5GC”) of a public land mobile network (“PLMN”) or to a 5GC of a non-public network (“NPN”). Furthermore, the UE may be enabled to connect to a 5GC of a PLMN (a second core network) via a 5GC of an NPN (a first core network) and vice versa. However, the connection to the second core network via the first core network may be transparent to the first network. Thus, the first core network is unaware of the quality of service (“QoS”) requirements of the connection to the second core network via the first core network. [Prior art documents] [Non-patent literature]
[0003] [Non-Patent Document 1] 3GPP(registered trademark) TS 23.502 Summary of the Invention [Means for solving the problem]
[0004] Disclosed are procedures for modifying a first data connection during establishment of a second data connection, which may be implemented by an apparatus, a system, a method, and / or a computer program product.
[0005] One method for a user equipment device ("UE") includes receiving a first request over a first data connection with a first mobile communications network, the first data connection supporting multiple QoS flows, where the first request includes a first set of parameters for establishing a second data connection with an interworking function in a second mobile communications network, where data traffic for the second data connection is to be transferred over the first data connection. The first method includes, in response to receiving the first request, sending a second request to modify the first data connection, where the second request includes a second set of parameters derived from the first set of parameters, where the second set of parameters modifies the first data connection to support data traffic for the second data connection. The first method includes transmitting the data traffic for the second data connection over the modified first data connection.
[0006] A more particular description of the embodiments briefly described above will be made by reference to specific embodiments that are illustrated in the accompanying drawings, in which the embodiments will be described and explained with more specificity and detail using the accompanying drawings, with the understanding that these drawings illustrate only some embodiments and, therefore, should not be considered limiting in scope. [Brief explanation of the drawings]
[0007] [Figure 1] 1 is a schematic block diagram illustrating an embodiment of a wireless communication system for modifying a first data connection during establishment of a second data connection. [Figure 2] FIG. 1 illustrates one embodiment of a network deployment to support access to public land mobile network ("PLMN") services over a non-public network ("NPN"). [Figure 3] FIG. 1 illustrates an embodiment of a scenario for modifying a first data connection during the establishment of a second data connection. [Figure 4] FIG. 2 illustrates one embodiment of a first data connection. [Figure 5A] FIG. 10 is a signal flow diagram illustrating one embodiment of a procedure for modifying a first data connection during the establishment of a second data connection. [Figure 5B] FIG. 5B is a continuation of the procedure shown in FIG. 5A. [Figure 5C] FIG. 5B is a continuation of the procedure shown in FIGS. 5A and 5B. [Figure 6] FIG. 1 illustrates a first data connection modified to support a second data connection. [Figure 7] FIG. 2 is a block diagram illustrating an embodiment of a user equipment device that may be used to modify a first data connection during the establishment of a second data connection. [Figure 8] 1 is a block diagram illustrating an embodiment of a network device that may be used to modify a first data connection during the establishment of a second data connection. [Figure 9] 1 is a flow diagram illustrating one embodiment of a method for modifying a first data connection during the establishment of a second data connection. DETAILED DESCRIPTION OF THE INVENTION
[0008] As will be appreciated by one skilled in the art, aspects of the embodiments may be embodied as a system, apparatus, method or program product. Accordingly, the embodiments may take the form of an all-hardware embodiment, an all-software embodiment (including firmware, resident software, microcode, etc.) or an embodiment combining software and hardware aspects.
[0009] For example, the disclosed embodiments may be implemented as a hardware circuit comprising custom very large scale integrated ("VLSI") circuits or gate arrays, off-the-shelf semiconductors such as logic chips, transistors, or other discrete components. The disclosed embodiments may also be implemented in programmable hardware devices such as field programmable gate arrays, programmable array logic, programmable logic devices, etc. As another example, the disclosed embodiments may include one or more physical or logical blocks of executable code that may be organized as, for example, objects, procedures, or functions.
[0010] Furthermore, embodiments may take the form of a program product embodied in one or more computer-readable storage devices storing machine-readable code, computer-readable code, and / or program code, hereinafter referred to as code. The storage devices may be tangible, non-transitory, and / or non-transmittable. The storage devices may not embody signals. In certain embodiments, the storage devices use only signals to access the code.
[0011] Any combination of one or more computer readable mediums may be utilized. The computer readable medium may be a computer readable storage medium. The computer readable storage medium may be a storage device that stores code. The storage device may be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, holographic, micro-mechanical, or semiconductor system, apparatus, or device, or any suitable combination thereof.
[0012] More specific examples (non-exhaustive list) of storage devices include the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory ("RAM"), a read-only memory ("ROM"), an erasable programmable read-only memory ("EPROM" or flash memory), a portable compact disc read-only memory ("CD-ROM"), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the context of this specification, a computer-readable storage medium may be any tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device.
[0013] The code for carrying out the operations of the embodiments may be any number of lines and may be written in any combination of one or more programming languages, including object-oriented programming languages such as Python, Ruby, Java, Smalltalk, C++, etc.; conventional procedural programming languages such as the “C” programming language; and / or machine language such as assembly language. The code may run entirely on the user's computer, partially on the user's computer as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the last scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (“LAN”), wireless LAN (“WLAN”), or wide area network (“WAN”), or a connection to an external computer may be made (e.g., via the Internet using an Internet Service Provider (“ISP”)).
[0014] Furthermore, the described features, structures, or characteristics of the embodiments may be combined in any suitable manner. In the following description, numerous specific details are provided, such as examples of programming, software modules, user selections, network transactions, database queries, database structures, hardware modules, hardware circuits, hardware chips, etc., to provide a thorough understanding of the embodiments. However, those skilled in the art will recognize that the embodiments may be practiced without one or more of the specific details, or with other methods, components, materials, etc. In other cases, well-known structures, materials, or operations are not shown or described in detail to avoid obscuring aspects of the embodiments.
[0015] Reference throughout this specification to "one embodiment," "an embodiment," or similar language means that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment. Thus, throughout this specification, appearances of the phrases "in one embodiment," "in an embodiment," and similar language may, but do not necessarily, all refer to the same embodiment and may mean "one or more, but not all, embodiments" unless otherwise specified. The terms "including," "comprising," "having," and variations thereof mean "including, but not limited to," unless otherwise specified. An enumerated list of items does not imply that any or all of the items are mutually exclusive unless otherwise specified. Additionally, the terms "a," "an," and "the" refer to "one or more" unless otherwise specified.
[0016] As used herein, a list using the conjunction "and / or" includes any single item in the list or combination of items in the list. For example, a list of A, B, and / or C includes A only, B only, C only, a combination of A and B, a combination of B and C, a combination of A and C, or a combination of A, B, and C. As used herein, a list using the term "one or more of" includes any single item in the list or combination of items in the list. For example, one or more of A, B, and C includes A only, B only, C only, a combination of A and B, a combination of B and C, a combination of A and C, or a combination of A, B, and C. As used herein, a list using the term "one of" includes only one of any single item in the list. For example, "one of A, B, and C" includes only A, only B, or only C, and excludes the combination of A, B, and C. As used herein, "an element selected from the group consisting of A, B, and C" includes only one of A, B, or C, and excludes the combination of A, B, and C. As used herein, "an element selected from the group consisting of A, B, and C, and combinations thereof" includes only A, only B, only C, the combination of A and B, the combination of B and C, the combination of A and C, or the combination of A, B, and C.
[0017] Aspects of the embodiments are described below with reference to schematic flowcharts and / or schematic block diagrams of methods, apparatus, systems, and program products according to the embodiments. It will be understood that each block of the schematic flowcharts and / or schematic block diagrams, and combinations of blocks in the schematic flowcharts and / or schematic block diagrams, may be implemented by code. This code may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to create a machine, such that the instructions, executed by the processor of the computer or other programmable data processing apparatus, produce means for performing the functions / acts specified in the flowcharts and / or block diagrams.
[0018] The code may be stored on a computer-readable medium that can instruct a computer, other programmable data processing apparatus, or other device to function in a particular manner, such that the instructions stored on the storage device produce an article of manufacture that includes instructions that perform the functions / acts specified in the flowcharts and / or block diagrams.
[0019] The code may be loaded into a computer, other programmable data processing apparatus, or other device to cause the computer, other programmable apparatus, or other device to perform a series of operational steps to produce a computer-implemented process such that the code executing on the computer or other programmable apparatus provides a process for performing the functions / acts specified in the flow charts and / or block diagrams.
[0020] The flowcharts and / or block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of apparatus, systems, methods, and program products according to various embodiments. In this regard, each block in the flowcharts and / or block diagrams may represent a module, segment, or portion of code, which comprises one or more executable instructions of code for implementing the specified logical function(s).
[0021] It should also be noted that in some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending on the functionality involved. Other steps and methods may be conceived that are equivalent in function, logic, or effect to one or more blocks, or portions thereof, of the illustrated figures.
[0022] While various arrow types and line types may be used in the flowcharts and / or block diagrams, they are understood not to limit the scope of the corresponding embodiments. Indeed, some arrows or other connectors may be used to indicate only the logical flow of the depicted embodiments. For example, arrows may indicate wait or monitoring periods of indefinite duration between recited steps of the depicted embodiments. It is also noted that each block of the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flow diagrams, may be implemented by dedicated hardware-based systems that perform the specified functions or acts, or by a combination of dedicated hardware and code.
[0023] The description of elements in each figure may refer to elements in the procedure figures. Like numbers refer to like elements in all figures, including alternative embodiments of like elements.
[0024] Generally, the present disclosure describes systems, methods, and apparatuses for modifying a first data connection during the establishment of a second data connection. In certain embodiments, the methods may be implemented using computer code embodied in a computer-readable medium. In certain embodiments, the apparatus or system may include a computer-readable medium including computer-readable code that, when executed by a processor, causes the apparatus or system to perform at least a portion of the solutions described below.
[0025] This disclosure describes how a second PDU session can support data communication of a particular QoS, assuming that all data traffic goes through a first PDU session that is unaware of the QoS requirements of the second PDU session.
[0026] Disclosed herein is a solution that enables a UE to modify a first PDU session with a first 5G core network (e.g., an NPN) so that when the UE attempts to establish a second PDU session with the second 5G core network (e.g., a PLMN), the first PDU session can transfer one or more Internet Protocol Security ("IPsec") child security associations ("SAs") of the second PDU session by providing the necessary QoS processing.
[0027] 1 illustrates a wireless communication system 100 for modifying a first data connection during establishment of a second data connection according to an embodiment of the present disclosure. In one embodiment, the wireless communication system 100 includes at least one remote unit 105, a radio access network (“RAN”) 120, a first mobile core network 130, e.g., a non-public network (i.e., private network), and a second mobile core network 140, e.g., a public network. The RAN 120 and the mobile core network 130 form a mobile communication network. The RAN 120 may be comprised of a base unit 121 with which the remote unit 105 communicates using a wireless communication link 123. While the RAN 120 is shown as connecting only to the non-public network mobile core network 130, in other embodiments, the RAN 120 may connect only to the public network mobile core network 140.
[0028] Although a particular number of remote units 105, base units 121, wireless communication links 123, RANs 120, and mobile core networks 130, 140 are shown in FIG. 1 , those skilled in the art will recognize that any number of remote units 105, base units 121, wireless communication links 123, RANs 120, and mobile core networks 130, 140 may be included in the wireless communication system 100.
[0029] In one implementation, the RAN 120 conforms to a 5G system defined in 3rd Generation Partnership Project (“3GPP®”) specifications. For example, the RAN 120 may be an NG-RAN implementing an NR RAT and / or an LTE RAT. In another example, the RAN 120 may include a non-3GPP® RAT (e.g., Wi-Fi® or a WLAN conforming to the Institute of Electrical and Electronics Engineers (“IEEE”) 802.11 family). In another implementation, the RAN 120 conforms to an LTE system defined in 3GPP® specifications. However, more broadly, the wireless communications system 100 may implement any other open or proprietary communications network, e.g., the Worldwide Interoperability for Microwave Access (“WiMAX”) or the IEEE 802.16 family of standards, among other networks. This disclosure is not intended to be limited to any particular wireless communications system architecture or protocol implementation.
[0030] In one embodiment, the remote unit 105 may include a computing device such as a desktop computer, a laptop computer, a personal digital assistant ("PDA"), a tablet computer, a smartphone, a smart television (e.g., a television connected to the Internet), a smart appliance (e.g., an appliance connected to the Internet), a set-top box, a game console, a security system (including security cameras), an in-vehicle computer, a network device (e.g., a router, a switch, a modem), etc. In some embodiments, the remote unit 105 includes a wearable device such as a smart watch, a fitness band, an optical head-mounted display, etc. Additionally, the remote unit 105 may be referred to as a UE, a subscriber unit, a mobile phone, a mobile station, a user, a terminal, a mobile terminal, a fixed terminal, a subscriber station, a user terminal, a wireless transmit / receive unit ("WTRU"), a device, or other terminology used in the art. In various embodiments, the remote unit 105 includes a subscriber identity and / or identification module ("SIM") and a mobile equipment ("ME") that provides mobile termination functions (e.g., radio transmission, handover, voice coding and decoding, error detection and correction, signaling, and access to the SIM). In particular embodiments, the remote unit 105 may include terminal equipment ("TE") and / or may be incorporated into a consumer electronics appliance or device (e.g., a computing device as described above).
[0031] The remote units 105 may communicate directly with one or more of the base units 121 in the RAN 120 via uplink (“UL”) and downlink (“DL”) communication signals. Additionally, the UL and DL communication signals may be carried over a wireless communication link 123, where the RAN 120 is an intermediate network that provides the remote units 105 with access to the mobile core network 140.
[0032] In some embodiments, the remote unit 105 communicates with the application server 151 via a network connection with the mobile core network 130. For example, an application 107 (e.g., a web browser, a media client, a telephone and / or a voice over Internet protocol ("VoIP") application) in the remote unit 105 may trigger the remote unit 105 to establish a protocol data unit ("PDU") session (or other data connection) with the mobile core network 130 via the RAN 120. The mobile core network 130 then uses the PDU session to relay traffic between the remote unit 105 and the application server 151 in the packet data network 150. The PDU session represents a logical connection between the remote unit 105 and the user plane function ("UPF") 131.
[0033] To establish a PDU session (or PDN connection), the remote unit 105 must register with the mobile core network 130 (also referred to as "attached to the mobile core network" in the context of fourth generation ("4G") systems). Note that the remote unit 105 may establish one or more PDU sessions (or other data connections) with the mobile core network 130. Thus, the remote unit 105 may have at least one PDU session for communicating with the packet data network 150. The remote unit 105 may establish additional PDU sessions for communicating with other data networks and / or other communication peers.
[0034] In the context of 5G systems ("5GS"), the term "PDU session" refers to a data connection that provides end-to-end ("E2E") user plane ("UP") connectivity between a remote unit 105 and a particular data network ("DN") via the UPF 131. A PDU session supports one or more quality of service ("QoS") flows. In particular embodiments, there may be a one-to-one mapping between QoS flows and QoS profiles, such that all packets belonging to a particular QoS flow have the same 5G QoS identifier ("5QI").
[0035] In the context of a 4G / LTE system, such as the Evolved Packet System ("EPS"), a packet data network ("PDN") connection (also called an EPS session) provides end-to-end uptime connectivity between a remote unit and the PDN. The PDN connection procedure establishes an EPS bearer, i.e., a tunnel between the remote unit 105 and a packet gateway ("PGW," not shown) in the mobile core network 130. In certain embodiments, there is a one-to-one mapping between EPS bearers and QoS profiles, such that all packets belonging to a particular EPS bearer have the same QoS class identifier ("QCI").
[0036] As described in further detail below, the remote unit 105 may use the first data connection (e.g., PDU session) established with the first mobile core network 130 to establish a second data connection (e.g., part of the second PDU session) with the second mobile core network 140. When establishing the data connection (e.g., PDU session) with the second mobile core network 140, the remote unit 105 registers with the second mobile core network 140 using the first data connection.
[0037] The base units 121 may be distributed over a geographic region. In particular embodiments, the base units 121 may be referred to as access terminals, access points, bases, base stations, Node Bs (“NBs”), evolved Node Bs (abbreviated as eNodeBs or “eNBs” and also known as Evolved Universal Terrestrial Radio Access Network (“E-UTRAN”) Node Bs), 5G / NR Node Bs (“gNBs”), Home Node Bs, relay nodes, RAN nodes, or any other terminology used in the art. The base units 121 are generally part of a RAN, such as the RAN 120, which may include one or more controllers communicatively coupled to one or more corresponding base units 121. These and other elements of a radio access network are not shown but are generally familiar to those skilled in the art. The base units 121 connect to the mobile core network 140 via the RAN 120.
[0038] The base unit 121 may serve multiple remote units 105 within a serving area, e.g., a cell or a sector of a cell, via wireless communication link 123. The base unit 121 may communicate directly with one or more of the remote units 105 via communication signals. Generally, the base unit 121 transmits DL communication signals to serve the remote units 105 in the time, frequency, and / or space domains. Furthermore, the DL communication signals may be carried over the wireless communication link 123. The wireless communication link 123 may be any suitable carrier in a licensed or unlicensed radio spectrum. The wireless communication link 123 facilitates communication between one or more of the remote units 105 and / or one or more of the base units 121. During NR-U operation, the base unit 121 and the remote units 105 communicate over an unlicensed radio spectrum.
[0039] In one embodiment, the mobile core networks 130 and 140 are 5GC or evolved packet core ("EPC") networks that may be coupled to a packet data network 150, such as the Internet and a private data network, among other data networks. The remote units 105 may have a subscription or other account with the non-public mobile core network 130. Additionally, the remote units 105 may have a subscription or other account with the public mobile core network 140. In various embodiments, each mobile core network 130, 140 belongs to a single mobile network operator ("MNO"). This disclosure is not intended to be limited to any particular wireless communications system architecture or protocol implementation.
[0040] The mobile core network 130 includes several network functions (“NFs”). As shown, the mobile core network 130 includes at least one UPF 131. The mobile core network 130 also includes multiple control plane (“CP”) functions, including but not limited to an Access and Mobility Management Function (“AMF”) 133, a Session Management Function (“SMF”) 135, a Policy Control Function (“PCF”) 137, a Unified Data Management function (“UDM”), and a User Data Repository (“UDR”), that serve the RAN 120.
[0041] In the 5G architecture, the UPF 131 is responsible for packet routing and forwarding, packet inspection, QoS processing, and external PDU sessions for interconnecting data networks (DNs). The AMF 133 is responsible for NAS signaling termination, NAS encryption and integrity protection, registration management, connection management, mobility management, access authentication and authorization, and security context management. The SMF 135 is responsible for session management (i.e., session establishment, modification, and release), remote unit (i.e., UE) IP address allocation and management, DL data notification, and traffic steering configuration of the UPF for appropriate traffic routing.
[0042] The PCF 137 is responsible for the unified policy framework, providing policy rules to the CP function, and access subscription information for policy decisions in the UDR. The UDM is responsible for generating Authentication and Key Agreement (AKA) credentials, handling user identification, access authorization, and subscription management. The UDR is a repository of subscriber information and can be used to provide services to many network functions. For example, the UDR may store subscription data, policy-related data, subscriber-related data that is allowed to be exposed to third-party applications, etc. In some embodiments, the UDM is co-located with the UDR and is shown as a combined entity "UDM / UDR" 139.
[0043] In various embodiments, the mobile core network 130 may also include an Authentication Server Function ("AUSF") (acting as an authentication server), a Network Repository Function ("NRF") (providing registration and discovery of NF services, allowing NFs to identify each other's appropriate services and communicate with each other via application programming interfaces ("APIs")), a Network Exposure Function ("NEF") (responsible for making network data and resources easily accessible to customers and network partners), or other NFs defined for 5GC. In particular embodiments, the mobile core network 130 may include an Authentication, Authorization, and Accounting ("AAA") server.
[0044] The public mobile core network 140 includes several network functions (“NFs”). As shown, the mobile core network 140 includes at least one UPF 141. The mobile core network 140 also includes multiple control plane (“CP”) functions, including but not limited to an Access and Mobility Management Function (“AMF”) 143, a Session Management Function (“SMF”) 145, a Policy Control Function (“PCF”) 147, and a Unified Data Management Function (“UDM”), which serve the RAN 120. In some embodiments, the UDM is co-located with a User Data Repository (“UDR”) and shown as a combined entity “UDM / UDR” 149. The roles of UPF 141, AMF 143, SMF 145, PCF 147, and UDM / UDR 149 are the same as those described above with respect to UPF 131, AMF 133, SMF 135, PCF 137, and UDM / UDR 139. In various embodiments, mobile core network 140 may also include an Authentication Server Function ("AUSF"), a Network Repository Function ("NRF"), or other NF defined for 5GC. In particular embodiments, mobile core network 140 may include an Authentication, Authorization, and Accounting ("AAA") server.
[0045] In various embodiments, each of the mobile core networks 130 and 140 supports different types of mobile data connections and different types of network slices, with each mobile data connection utilizing a particular network slice. Here, a “network slice” refers to a portion of the core network optimized for a particular traffic type or communication service. A network instance is identified by a single-network slice selection assistance information (“S-NSSAI”), while a set of network slices that the remote unit 105 is authorized to use is identified by a network slice selection assistance information (“NSSAI”). Here, “NSSAI” refers to a vector value that includes one or more S-NSSAI values. In certain embodiments, various network slices may include separate instances of network functions, such as the SMF 135 / 145 and the UPF 131 / 141. In some embodiments, different network slices may share some common network functions, such as the AMF 133 / 143. For simplicity of illustration, different network slices are not shown in Figure 1, but their support is assumed.
[0046] 1, a particular number and type of network functions are shown, but those skilled in the art will recognize that any number and type of network functions may be included in the mobile core networks 130 and 140. Although shown as a non-public network mobile core, in other embodiments, the mobile core 130 may be a mobile core of a PLMN separate from the mobile core network 140. In such embodiments, the remote unit 105 may establish a data connection with the mobile core network 130 to register with the mobile core network 140 via a Non-3GPP Interworking Function ("N3IWF") 142.
[0047] The N3IWF 142 is a network function that supports access to 5GC via non-3GPP access networks. Generally, the N3IWF 142 supports connection to one or more 5GC networks for UEs that support NAS protocols and applicable NAS procedures over non-3GPP access. Here, the N3IWF 142 is also used to support access of the remote unit 105 to the mobile core network 140 via another mobile network, here the non-public mobile core network 130.
[0048] Although FIG. 1 shows components of a 5G RAN and a 5G core network, the described embodiments for modifying a first data connection during establishment of a second data connection apply to other types of communication networks and RATs, including variants of IEEE 802.11, Global System for Mobile Communications (“GSM” i.e., 2G digital cellular networks), General Packet Radio Service (“GPRS”), Universal Mobile Telecommunications System (“UMTS”), variants of LTE, CDMA 2000, Bluetooth, ZigBee, Sigfox, etc.
[0049] Furthermore, in variants of LTE where mobile core network 130 and / or mobile core network 140 are the EPC, the depicted network functions may be replaced by appropriate EPC entities such as a Mobility Management Entity ("MME"), a Serving Gateway ("SGW"), a PGW, a Home Subscriber Server ("HSS"), etc. For example, the AMF may be mapped to the MME, the SMF may be mapped to the control plane portion of the PGW and / or the MME, the UPF may be mapped to the SGW and user plane portion of the PGW, the UDM / UDR may be mapped to the HSS, etc.
[0050] In the following description, the term "RAN node" is used for a base station, but it can be replaced by any other radio access node, e.g., gNB, eNB, base station ("BS"), access point ("AP"), etc. Furthermore, the operations are primarily described in the context of 5G NR. However, the proposed solutions / methods are equally applicable to other mobile communication systems that modify a first data connection during the establishment of a second data connection.
[0051] To solve the above-mentioned problem of appropriate QoS handling for a second PDU session whose traffic is routed through a first PDU session, the present disclosure proposes a solution that enables a UE (e.g., a remote unit 105) that has established a first data connection with a first mobile network (i.e., a mobile core 130 of an NPN), the first data connection having a first set of QoS characteristics, to establish a second data connection with a second mobile network (i.e., a mobile core 140 of a PLMN), the second data connection having a second set of QoS characteristics, wherein traffic of the second data connection is forwarded over the first data connection, and the second data connection is established after modifying the first data connection to support the second QoS characteristics.
[0052] FIG. 2 illustrates a network deployment 200 including a UE 205 registering with a non-public network (“NPN”) 215. In one embodiment, the NPN 215 may be a standalone NP (“SNPN”), i.e., it has its own network functionality and does not rely on network functionality provided by a PLMN. In another embodiment, the NPN 215 may be a public network integrated NPN (“PNI-NPN”), i.e., a non-public network deployed with the support of a PLMN. The NPN 215 includes at least an AMF (“AMF-0”) 216, an SMF (“SMF-0”) 217, and a UPF (“UPF-0”) 218. In various embodiments, the NPN 215 includes additional NFs, as described above with reference to FIG. 1. Note that the UE 205 connects to the NPN 215 via an access network 210.
[0053] As shown, the UE 205 is simultaneously connected to two 5G core networks: a first 5GC of the NPN 215 and a second 5GC of the PLMN 220. After the UE 205 registers with the first 5GC of the NPN 215, it can access the second 5GC of the PLMN 220 as follows.
[0054] First, the UE 205 establishes an IP-type PDU session 235 with the first 5GC of the NPN according to existing procedures, thus obtaining an IP connection. This is the UE's 205's first PDU session, which (like any other PDU session) consists of one or more QoS flows, each carrying the data traffic of the PDU session with specific QoS requirements. Through the first PDU session, the UE 205 obtains a connection to data network 0 (DN-0) 225. As shown, the NPN 215 and the PLMN 220 are connected via data network ("DN-0") 225.
[0055] When the UE 205 decides to attach to a PLMN 220, the UE 205 discovers the IP address of the N3IWF 221 in this PLMN 220 (e.g., by performing a DNS procedure over the first PDU session) and establishes a signaling IPsec SA 240 with the N3IWF 221. The UE 205 then registers with this PLMN 220 by performing 5G registration via the N3IWF 221, or equivalently, existing procedures for 5G registration over untrusted non-3GPP access. This registration procedure is performed by exchanging NAS messages between the UE 205 and the AMF-1 222 via the N3IWF 221 and the first PDU session 235 of the UE 205 (i.e., via the UPF-0 218 in the NPN 215 and via the access network 210). As shown, PLMN 220 includes at least N3IWF 221, AMF (“AMF-1”) 222, SMF (“SMF-1”) 223, and UPF (“UPF-1”) 224. In various embodiments, PLMN 220 includes additional NFs, as described above with reference to FIG.
[0056] After registering with the PLMN 220 via the N3IWF 221 and via the first PDU session 235, the UE 205 requests to establish a (second) PDU session with the PLMN 220, which provides connectivity to the data network 1 (DN-1) 230. This is the UE 205's second PDU session, and all data traffic for this second PDU session is transported over the first PDU session 235. It is important to note that the second PDU session with the PLMN 220 is established completely transparently to the NPN 215. In other words, the NPN 215 cannot determine whether and when the UE 205 establishes the second PDU session, because all NAS messages exchanged between the UE 205 and the AMF-1 222 to establish this PDU session are sent as encrypted data packets over the first PDU session.
[0057] Furthermore, after registering with the PLMN 220, the UE 205 has an N1 connection with the AMF-0 216 for the NPN and also has an N1 connection with the AMF-1 222 for the PLMN. After establishing a second PDU session with the PLMN CN 220, the UE 205 may access another data network (“DN-1”) 230 via the UPF-1 224.
[0058] In one example, the second PDU session may be set up by the UE 205 to access real-time voice services in the PLMN 220. Thus, the voice traffic on the second PDU session is to be transmitted with appropriate QoS treatment so that the delay and loss rate do not exceed certain limits. As mentioned above, the second PDU session is established transparently to the NPN, and therefore, the QoS flow supported by the first PDU session 235 does not take into account the QoS requirements of the second PDU session. Therefore, the solution disclosed herein enables the UE 205 to modify the PDU session 235 to provide appropriate QoS treatment to the voice traffic of the second PDU session, for example, to support the QoS of the real-time voice traffic.
[0059] 3 illustrates a network architecture 300 showing user plane traffic according to an embodiment of the present disclosure. The network architecture 300 includes a UE 205 registered with a first mobile communication network 305. In various embodiments, the first mobile communication network 305 is a non-public network such as a mobile core network 130 and / or an NPN 215.
[0060] 3, the UE 205 has established a first PDU session 315 (i.e., PDU session 1) with a first mobile communication network 305 that has two QoS flows for communicating with a data network 0 225, e.g., the Internet. All data packets within the first PDU session 315 are transmitted over one of these two QoS flows (QoS flow 1 320 and QoS flow 2 325), with each QoS flow providing different QoS characteristics.
[0061] The UE 205 may be configured with QoS rules that map the UE's 205 uplink data traffic to one of these QoS flows. Similarly, the UPF-0 218 may be configured with N4 rules that map the UE's 205 downlink data traffic to one of these QoS flows. The first PDU session 315 is anchored at the UPF-0 218. As shown in Figure 2, data between the UPF-0 and the DN-0 225 passes through the N6 interface.
[0062] 3 , the UE 205 registers with the 5GC of the second mobile communications network 310 via the first PDU session 315 and establishes a second PDU session (“PDU session 2”) 335 for communication with the data network 1 230, e.g., an enterprise network. Here, the second PDU session 335 is anchored at the UPF-1 224. Note that traffic for the second PDU session 335 passes through a gateway or interworking function, shown here as the N3IWF 221, in the second mobile communications network 310. Note that the second mobile communications network 310 may be a public network, such as the mobile core network 140 and / or the PLMN 220.
[0063] After the establishment of the second PDU session (PDU session 2) 335 with the second mobile communications network 310 (e.g., PLMN), an IPsec child SA 340 is established between the UE 205 and the N3IWF 221, and all data traffic for the second PDU session 335 is forwarded through this child SA, the establishment of which is described in more detail with reference to FIGS. 5A-5C. In one embodiment, traffic for the IPsec child SA is forwarded through one of the existing QoS flows of the first PDU session. However, as mentioned above, it is possible that the first PDU session does not have a QoS flow suitable for providing the QoS required by the IPsec child SA of the second PDU session.
[0064] If the established QoS flow supports the appropriate QoS for the second PDU session 335, the UE 205 modifies the first PDU session 315 by indicating the existing QoS flow suitable for carrying the data traffic of the second PDU session 335 and provides a packet filter that identifies the data traffic of the second PDU session 335. Examples of such a packet filter include the IP address of the N3IWF 221 and a security parameter index (“SPI”) assigned by the N3IWF 221.
[0065] If the established QoS flow for the first PDU session 315 does not support the appropriate QoS for the second PDU session 335, the UE 205 modifies the first PDU session 315 by creating a new QoS flow 255 carrying the IPsec traffic of the second PDU session 335 and maps the IPsec traffic of the second PDU session 335 to this new QoS flow 255. In this way, the IPsec traffic of the second PDU session 335 receives the appropriate QoS treatment when passing through the first PDU session 315. In the illustrated example, it is assumed that a new QoS flow 330 is created to support the QoS requirements of the second PDU session 335.
[0066] 3, the first data connection corresponds to the first PDU session 315, and the second data connection corresponds to the IPsec child SA 340 between the UE and the N3IWF (and not the second PDU session). While the illustrated embodiment shows only one IPsec child SA 340, in other embodiments, the second PDU session 335 may have multiple IPsec child SAs, each dedicated to carrying traffic with similar QoS requirements.
[0067] In the typical case where the second PDU session 335 is comprised of multiple IPsec SAs, the UE 205 may establish new QoS flows for every IPsec SA. Alternatively, the UE 205 may establish new QoS flows for some IPsec SAs and map other IPsec SAs to existing QoS flows. For ease of illustration, only a single IPsec SA 340 is shown in FIG. 3.
[0068] 4 illustrates a scenario 400 in which a UE 205 establishes a first data connection 405 (i.e., PDU Session 1) with a first mobile communications network 305. In the illustrated example, the first data connection includes two QoS flows: a first QoS flow (“QoS Flow 1”) 410 and a second QoS flow (“QoS Flow 2”) 415; however, in other embodiments, the first data connection may be established with more or fewer QoS flows. The first QoS flow 410 may be used to transport data having first QoS requirements, while the second QoS flow 415 may be used to transport data traffic 420 having different QoS requirements. Among other things, the second QoS flow 415 is used to establish a signaling Internet Protocol Security (“IPsec”) security association (“SA”) 425 with the N3IWF 221 via DN-0 225. The signaling IPsec SA 425 established here may be an implementation of the signaling IPsec SA 240 described above. In a particular embodiment, the second QoS flow 415 may carry other data traffic 430 to the DN-0 225, i.e., having the same QoS requirements, and the signaling IPsec SA 425. It should be noted that the N3 IWF 221 in the second mobile communication network 310 terminates the signaling IPsec SA 425 and carries signaling traffic from the UE 205 to the AMF-1 222 using the N2 connection established with the AMF-1 222.
[0069] 5A-5C illustrate a procedure 500 for registering to a mobile network through another mobile network according to an embodiment of the present disclosure. The procedure 500 includes a UE 205, a Next Generation RAN ("NG-RAN") 405, an AMF, an SMF, a UPF, and a PCF (i.e., AMF-0 216, SMF-0 217, UPF-0 218, and "PCF-0" 503) in a first mobile communications network 305, and an N3IWF, an AMF, an SMF, a UPF, a PCF, and a UDM (i.e., N3IWF 221, AMF-1 222, SMF-1 223, UPF-1 224, "PCF-1" 501, and "UDM-1" 502, respectively) in a second mobile communications network 310.
[0070] Procedure 500 enables UE 205 to modify a first PDU session with a first mobile communication network 305 (e.g., an NPN) so that when UE 205 attempts to establish a second PDU session with a second mobile communication network 310 (e.g., a PLMN), the first PDU session can transfer one or more IPsec child SAs of the second PDU session by providing the necessary QoS processing. Procedure 500 assumes that the first mobile communication network 305 is an NPN and the second mobile communication network 310 is a PLMN, although in alternative embodiments, the roles of the NPN and PLMN may be swapped. In other words, the principles and procedures described below may also be applied in a scenario in which UE 205 is connected to a PLMN (consisting of an NG-RAN access and a 5GC core network) and connects to an NPN consisting of at least a 5G core network by using an N3IWF in the NPN using a PDU session via the PLMN. This scenario is beneficial when the coverage of the NPN is limited, and the UE 205 can use the PLMN to access NPN services when outside the coverage of the NPN.
[0071] 5A, procedure 500 begins with step 0 (see block 505) where, as a prerequisite, UE 205 has registered with the 5GC of the first mobile communication network 305 (e.g., NPN) and established a first PDU session 405 consisting of two QoS flows. UE 205 has also registered with the 5GC of the second mobile communication network 310, e.g., via N3IWF 221, and has therefore established a so-called "signaling IPsec SA" with N3IWF 221, through which all Non-Access Stratum ("NAS") messages between UE 205 and AMF-1 222 are exchanged. Note that all these NAS messages are encrypted and cannot be inspected by UPF-0 218 or another network function in the first mobile communication network 305.
[0072] In step 1a, the UE 205 sends a NAS message (e.g., a PDU session establishment request) to establish a second PDU session with the second mobile communications network 310. This NAS message is forwarded to the N3IWF 221 via the signaling IPsec SA 425 and then to the AMF-1 222 (see messaging 507). The PDU session establishment request includes a PDU session identity ("ID") that identifies the second PDU session, denoted here as "PDU session ID-2."
[0073] In step 1b, the AMF-1 222 sends a Create Session Management ("SM") Context Request message to the SMF-1 223 (see messaging 509), and in step 1c, a normal PDU session establishment procedure starts in the 5GC of the second mobile communications network 310 (see block 511), for example as specified in 3GPP TS 23.502. In step 1d, the SMF-1 223 sends an N1N2 Message Transfer to the AMF-1 222 (see messaging 513).
[0074] In step 2, as part of the second PDU session establishment procedure, N3IWF 221 receives a PDU session resource setup request message from AMF-1 222 (see messaging 515) requesting N3IWF 221 to reserve access resources to support (for example) two QoS flows: one Guaranteed Bit Rate ("GBR") QoS flow identified by QFI-1 and one non-GBR QoS flow identified by QFI-2. Each of the two QoS flows is associated with a set of QoS parameters, e.g., a packet delay budget ("PDB") and a packet error rate ("PER"), that specify the QoS requirements of the QoS flow. For the GBR QoS flow, the QoS parameters also include GBR QoS flow information, which includes the required maximum flow bit rate and guaranteed flow bit rate.
[0075] The 5GC of the second mobile communication network 310 (e.g., PLMN) determines the number of QoS flows on the second PDU session and the QoS parameters of each QoS flow based on the subscription information of the UE 205, pre-configured policies of the second mobile communication network 310, etc.
[0076] In step 3, to reserve appropriate access resources, N3IWF 221 decides to establish two IPsec child SAs with UE 205 (see block 517), where a first IPsec child SA will carry traffic for the GBR flow and a second IPsec child SA will carry traffic for the non-GBR flow.
[0077] 5B, in step 4, N3IWF 221 sends an IKEv2 Create Child SA Request to UE 205 to establish a first IPsec child SA for the GBR flow (see messaging 519). As specified in 3GPP TS 23.502, the IKEv2 Create Child SA Request includes several parameters related to the requested IPsec child SA, such as the SPI allocated by N3IWF 221 for the first IPsec child SA (denoted here as “SPI-i-1”), the PDU Session ID of the second PDU session (PDU Session ID-2), the Differentiated Services Code Point (“DSCP”), the QoS Flow ID (“QFI”) of the GBR flow, additional QoS information, etc. The additional QoS information includes parameters that define the QoS requirements of the first IPsec child SA, including a packet delay budget, a packet error rate, a maximum flow rate, and a guaranteed flow rate.
[0078] In one example, the additional QoS information includes: ●QoS characteristics: Resource type = GBR 〇Priority = 8 Packet Delay Budget = 20ms Packet error rate = 10^-3 Averaging Window = 1000ms GBR QoS flow information: Maximum Flow Bit Rate Downlink (MFBR Downlink) = 4Mbps Maximum Flow Bit Rate Uplink (MFBR Uplink) = 512Kbps Guaranteed Bandwidth Flow Bit Rate Downlink (GFBR Downlink) = 1Mbps Guaranteed Flow Bit Rate Uplink (GFBR Uplink) = 256Kbps
[0079] In step 5, the UE 205 determines that none of the existing QoS flows on the first PDU session 405 are suitable to meet the QoS requirements of the first IPsec child SA expressed by the additional QoS information, and therefore decides to request a new QoS flow on the first PDU session to forward traffic for the first IPsec child SA (see block 521).
[0080] In step 6, the UE 205 initiates a UE-initiated PDU session modification procedure 523 with the first mobile communication network 305 to establish a new QoS flow on the first PDU session. The UE 205 provides the AMF-0 216 (and SMF-0 217) with a PDU session ID (herein denoted "PDU session ID-1") identifying the first PDU session and a Requested QoS rules element describing the data traffic to be carried on the first IPsec child SA (see messaging 525). Furthermore, the UE 205 provides the AMF-0 216 (and SMF-0 217) with a Requested QoS flow descriptions element describing the QoS requirements of the traffic to be carried on the first IPsec child SA.
[0081] In one example, the UE 205 provides the following requested QoS rule elements and requested QoS flow description elements to the first mobile communications network 305: Required QoS rules 〇QoS rule 1 ■QoS rule identifier = No identifier assigned ■ Action = Create a new QoS rule ■ Packet filter 1 Direction: Uplink only Component 1 Component Type = SPI Component value = 0x01AB33F4 (i.e., SPI-r) Component 2 Component Type = IPv4 Remote Address Component value = 10.11.12.13 (i.e., N3IWF address) ■ Packet filter 2 Direction: Downlink only Component 1 Component Type = SPI Component value = 0x618AD2E7 (i.e., SPI-i) Component 2 Component Type = IPv4 Local Address Component value = 10.11.12.13 (i.e., N3IWF address) ■ Required segregation ■ QFI = No QFI assigned Required QoS flow description ○QoS flow description 1 ■ QFI = No QFI assigned ■ Action = Create a new QoS flow description ■ Parameter list ●Parameter 1:GFBR UL = 256Kbps ● Parameter 2: GFBR DL = 1Mbps ● Parameter 3: MFBR UL = 512Kbps ● Parameter 4: MFBR DL = 4Mbps Parameter 5: Averaging window = 1000ms
[0082] Note that the UE 205 derives elements to be included in the PDU session modification request sent to the first mobile communications network 305 by using the parameters received in step 4 from the N3IWF 221, e.g., SPI-i-1 and Additional QoS Information 1. Additionally, the UE 205 provides an SPI-r-1 that is allocated by the UE 205 to the first IPsec child SA. As used herein, the label "SPI-i" is used to indicate a network-allocated SPI (e.g., allocated by the N3IWF 221), and the label "SPI-r" is used to indicate a UE-allocated SPI.
[0083] If the first mobile communications network 305 (e.g., NPN) accepts the PDU session modification requested by the UE 205, the UPF-0 218, the AMF-0 216, the SMF-0 217, and the PCF-0 503 modify the first PDU session 405 and reserve resources to support the QoS requirements of the second IPsec child SA (see block 527). Via the AMF-0 216, the SMF-0 217 responds to the UE 205 with a PDU session modification command containing Authorized QoS rules and Authorized QoS flow descriptions elements, which are essentially identical to the requested QoS rules and requested QoS flow descriptions, respectively, provided by the UE 205, except that the authorized QoS rules and authorized QoS flow description elements contain the specific QFI values allocated by the first mobile communications network 305 for the newly created QoS flow (referred to as QoS Flow 3) (see messaging 529). The UE 205 acknowledges the PDU session modification command by sending a PDU session modification complete message (see messaging 531).
[0084] In step 7, after successfully reserving resources on the first PDU session in the first mobile communication network 305 to support the QoS requirements of the first IPsec child SA of the second PDU session, the UE 205 sends an IKEv2 Create Child SA Response to the N3IWF 221 including its SPI for the first IPsec child SA (here denoted as "SPI-r-1"), which completes the establishment of the first IPsec child SA (see messaging 533).
[0085] 5C, in step 3, since N3IWF 221 has determined to establish two IPsec child SAs for the second PDU session, steps similar to steps 4-7 are again performed to establish the second IPsec child SA and associated resources on the first PDU session. As a result, another new QoS flow is created on the first PDU session to support the QoS requirements of the second IPsec child SA (referred to as QoS Flow 4).
[0086] In step 8, N3IWF 221 sends an IKEv2 Create Child SA Request to UE 205 to establish a second IPsec child SA for the non-GBR flow (see messaging 535). Again, the IKEv2 Create Child SA Request includes several parameters related to the requested IPsec child SA, such as the SPI allocated by N3IWF 221 for the second IPsec child SA (denoted here as “SPI-i-2”), the PDU Session ID of the second PDU session (i.e., PDU Session ID-2), the DSCP, the QFI of the non-GBR flow, and additional QoS information. The additional QoS information includes parameters defining the QoS requirements of the second IPsec child SA (non-GBR), including the packet delay budget (“PDB”), packet error rate (“PER”), and the like. Note, however, that because the second IPsec child SA carries traffic for the non-GBR flow, the additional QoS information includes only a QoS characteristic component and does not include a GBR QoS flow information component.
[0087] In step 9, the UE 205 determines that none of the existing QoS flows on the first PDU session 405 are suitable to meet the QoS requirements of the second IPsec child SA expressed by the additional QoS information, and therefore decides to request a new QoS flow on the second PDU session to forward traffic for the second IPsec child SA (see block 537).
[0088] In step 10, the UE 205 initiates a UE-initiated PDU session modification procedure 539 with the first mobile communications network 305 (e.g., NPN) to establish a new QoS flow on the first PDU session. The UE 205 provides the AMF-0 216 (and SMF-0 217) with a PDU session ID (i.e., PDU session ID-1) identifying the first PDU session and a requested QoS rule element describing the data traffic to be carried on the second IPsec child SA (see messaging 541). Additionally, the UE 205 provides the AMF-0 216 (and SMF-0 217) with a requested QoS flow description element describing the QoS requirements of the traffic to be carried on the second IPsec child SA.
[0089] If the first mobile communications network 305 accepts the PDU session modification requested by the UE 205, the UPF-0 218, the AMF-0 216, the SMF-0 217, and the PCF-0 503 modify the first PDU session 405 and reserve resources to support the QoS requirements of the second IPsec child SA (see block 543). The SMF-0 217 sends a PDU session modification command to the UE 205 via the AMF-0 216 (see signaling 545), including the PDU session ID, the authorized QoS rules, and the authorized QoS flow description. The UE 205 acknowledges the PDU session modification command by sending a PDU session modification complete message (see messaging 547).
[0090] Note that steps 6 and 10 (UE-initiated PDU session modification) are required even if UE 205 determines that traffic for the requested IPsec child SA can be mapped to an existing QoS flow, i.e., when no new QoS flow needs to be established to support the first IPsec child SA and / or the second IPsec child SA. In this case, UE 205 sends a PDU session modification request that includes a requested QoS rule information element (“IE”) indicating “modify existing QoS rule and add packet filter” and will include a packet filter that identifies traffic for the first IPsec child SA and / or the second IPsec child SA.
[0091] In step 11, after successfully reserving resources on the first PDU session in the first mobile communications network 305 to support the QoS requirements of the second IPsec child SA of the second PDU session (i.e., of the non-GBR flow), the UE 205 sends an IKEv2 Child SA Creation Response to the N3IWF 221 including its own SPI for the second IPsec child SA (here denoted as "SPI-r-2"), which completes the establishment of the second IPsec child SA (see messaging 549).
[0092] In step 12, the N3IWF 221 responds to the AMF-1 222 with a PDU session resource setup response indicating that access resources for the second PDU session have been reserved (see messaging 551). At this point, the data traffic of the second PDU session can be carried between the UE 205 and the UPF-1 224 via the first PDU session. Note that the data traffic of the second PDU session consists of the data traffic of the first IPsec child SA and the data traffic of the second IPsec child SA. The traffic of the first IPsec child SA is forwarded on QoS flow 3 (created in step 6) of the first PDU session, and the data traffic of the second IPsec child SA is forwarded on QoS flow 4 (created in step 10) of the first PDU session.
[0093] By using procedure 500, the UE 205 ensures that traffic of the two IPsec child SAs (the second data connection and the third data connection) of the second PDU session is forwarded over the first PDU session (the first data connection) with appropriate QoS treatment. This enables the UE 205 to establish a PDU session with the second mobile communication network 310 (e.g., a PLMN) via the first mobile communication network 305 (e.g., an NPN), and the PDU session can receive the expected QoS treatment.
[0094] 6 illustrates a scenario 600 in which a first data connection has been modified to support the establishment of a second data connection, for example, according to the procedures described above with reference to FIGS. 5A-5C. Here, it is assumed that the modified first data connection 605 (i.e., the modified first PDU session) originally included a first QoS flow 410 and a second QoS flow 415, but that the UE 205 has determined that a new QoS flow is required to support an IPsec child SA for a second PDU session 635 established with a second mobile communications network 310 via the first PDU session.
[0095] In the illustrated example, the UE 205 created two new QoS flows to support the second PDU session 635: specifically, a third QoS flow (“QoS Flow 3”) 610 and a fourth QoS flow (“QoS Flow 4”) 615. The third QoS flow 610 will be used to forward data traffic for the first IPsec child SA 620 (e.g., a GBR flow), while the fourth QoS flow 615 will be used to forward data traffic for the second IPsec child SA 625 (e.g., a non-GBR flow). Note that the second QoS flow 415 supports a signaling Internet Protocol Security (“IPsec”) security association (“SA”) 425 with the N3IWF 221 via DN-0 225. Furthermore, it should be noted that the N3IWF 221 terminates the first and second IPsec child SAs 620, 625 and uses the N3 tunnel established with the UPF-1 224 in the second mobile communication network 310 to carry data traffic of the second PDU session 635, which includes both data traffic of the first IPsec child SA 620 and data traffic of the second IPsec child SA 625.
[0096] In FIG. 6, the first data connection corresponds to the first PDU session 605, the second data connection corresponds to the first IPsec child SA 620 between the UE and the N3IWF (not corresponding to the second PDU session), and the third data connection corresponds to the second IPsec child SA 625 between the UE and the N3IWF (not corresponding to the second PDU session).
[0097] 7 illustrates a user equipment device 700 that may be used to modify a first data connection during establishment of a second data connection, according to an embodiment of the present disclosure. In various embodiments, the user equipment device 700 is used to implement one or more of the solutions described above. The user equipment device 700 may be an embodiment of the remote unit 105 and / or the UE 205 described above. Additionally, the user equipment device 700 may include a processor 705, a memory 710, an input device 715, an output device 720, and a transceiver 725.
[0098] In some embodiments, input device(s) 715 and output device(s) 720 are combined into a single device, such as a touchscreen. In particular embodiments, user equipment device 700 may not include any input device(s) 715 and / or output device(s) 720. In various embodiments, user equipment device 700 may include one or more of processor 705, memory 710, and transceiver 725, and may not include input device(s) 715 and / or output device(s) 720.
[0099] As shown, the transceiver 725 includes at least one transmitter 730 and at least one receiver 735. In some embodiments, the transceiver 725 communicates with one or more cells (or wireless coverage areas) supported by one or more base units 121. In various embodiments, the transceiver 725 is capable of operating in an unlicensed spectrum. Further, the transceiver 725 may include multiple UE panels supporting one or more beams. Additionally, the transceiver 725 may support at least one network interface 740 and / or application interface 745. The application interface 745 may support one or more APIs. The network interface 740 may support 3GPP reference points such as Uu, N1, PC5, etc. As will be appreciated by those skilled in the art, other network interfaces 740 may be supported.
[0100] The processor 705, in one embodiment, may include any known controller capable of executing computer-readable instructions and / or performing logical operations. For example, the processor 705 may be a microcontroller, microprocessor, central processing unit ("CPU"), graphics processing unit ("GPU"), auxiliary processing unit, field programmable gate array ("FPGA"), or similar programmable controller. In some embodiments, the processor 705 executes instructions stored in memory 710 to perform the methods and routines described herein. The processor 705 is communicatively coupled to the memory 710, input devices 715, output devices 720, and a transceiver 725. In particular embodiments, the processor 705 may include an application processor (also referred to as a "main processor") that manages application domain and operating system ("OS") functions, and a baseband processor (also referred to as a "baseband radio processor") that manages radio functions.
[0101] In various embodiments, the processor 705 controls the user equipment device 700 to implement the above-described UE behaviors. For example, the processor 705 may receive a first request (e.g., an IKE Create Child SA request) over a first data connection (e.g., PDU Session 1) with a first mobile communications network via a first access network, the first data connection supporting multiple Quality of Service (“QoS”) flows. The first request includes a first set of parameters (e.g., SPI, additional QoS information) for establishing a second data connection (e.g., an IPsec child SA) with an interworking function (e.g., N3IWF) in a second mobile communications network, where data traffic of the second data connection is to be transferred over the first data connection (e.g., the IPsec child SA is transferred within PDU Session 1).
[0102] In some embodiments, the first mobile communications network comprises a non-public network ("NPN") and the second mobile communications network comprises a public land mobile network ("PLMN"). In other embodiments, the first mobile communications network comprises a PLMN and the second mobile communications network comprises an NPN.
[0103] In response to receiving the first request, via the transceiver 725, the processor 705 transmits a second request (e.g., a PDU session modification request) to modify the first data connection, the second request including a second set of parameters (e.g., a requested QoS rule, a requested QoS flow description) derived from the first set of parameters (e.g., an SPI, additional QoS information), the second set of parameters modifying the first data connection to support data traffic of the second data connection. Via the transceiver 725, the processor 705 transmits the data traffic of the second data connection through the modified first data connection.
[0104] As used herein, modifying a first data connection means either (a) adding a new QoS flow to the first data connection that is suitable for carrying data traffic of the second data connection, or (b) indicating an existing QoS flow of the first data connection that is suitable for carrying data traffic of the second data connection. User equipment device 700 determines option (a) when it determines that none of the existing QoS flows can support the required QoS of the second data connection, as indicated by the “additional QoS information” of the first request.
[0105] In some embodiments, the second set of parameters indicates establishing a new QoS flow on the first data connection, where the new QoS flow will carry data traffic for the second data connection. In such embodiments, the second set of parameters indicates establishing a new QoS flow on the first data connection in response to determining that none of the existing QoS flows on the first data connection are suitable for carrying data traffic for the second data connection. Note that a QoS flow is not suitable for carrying data traffic for the second data connection when the QoS provided by the QoS flow cannot provide the QoS required by the additional QoS information. In certain embodiments, the second set of parameters includes a packet filter (e.g., an IP address and SPI of the N3IWF) that identifies data traffic for the second data connection.
[0106] In some embodiments, the second set of parameters indicates an existing QoS flow for the first data connection, where the existing QoS flow will carry data traffic for the second data connection. In particular embodiments, the second set of parameters includes a packet filter (e.g., an IP address and SPI of the N3IWF) that identifies the data traffic for the second data connection.
[0107] In some embodiments, the second data connection includes an Internet Protocol Security ("IPsec") child security association ("SA"), and the first set of parameters includes a security parameter index ("SPI") and additional QoS information for the IPsec child SA. In particular embodiments, the second set of parameters includes requested QoS rules and requested QoS flow descriptions for modifying the first data connection to support data traffic of the IPsec child SA. Note that the requested QoS flow descriptions are only required when the IPsec child SA carries guaranteed bit rate ("GBR") traffic.
[0108] In some embodiments, the first request is an Internet Key Exchange ("IKE") Create Child SA request received from a non-3GPP interworking function ("N3IWF"). In such embodiments, the processor 705 further transmits an IKE Create Child SA response message to the N3IWF in response to the successful modification of the first data connection before transmitting data traffic of the second data connection through the modified first data connection. In some embodiments, the first request (e.g., an IKE Create Child SA request) is received in response to transmitting, over the first data connection, a PDU session establishment request requesting establishment of a PDU session in the second mobile communications network via an interworking function in the second mobile communications network. It should be noted that the PDU session in the second mobile communications network may be composed of one or more child IPsec SAs, e.g., a second data connection, a third data connection, etc.
[0109] In some further embodiments, the processor 705 receives a third request (e.g., a second IKE Child SA Creation Request) over the first data connection, where the third request includes a third set of parameters (e.g., SPI-2, Additional QoS Information 2) for establishing a third data connection (e.g., IPsec Child SA-2) with the interworking function, where data traffic of the third data connection is to be transferred over the first data connection (e.g., IPsec Child SA-2 is also transferred within PDU Session 1), and the second data connection and the third data connection form a PDU session with the second mobile communications network.
[0110] In one embodiment, in response to receiving the third request, the processor 705 transmits a fourth request (e.g., a PDU session modification request) to establish a new QoS flow on the first data connection. In another embodiment, in response to receiving the third request, the processor 705 transmits a fourth request (e.g., a PDU session modification request) to indicate an existing QoS flow of the first data connection that should carry data traffic for the third data connection. In either embodiment, the fourth request includes a fourth set of parameters (e.g., a requested QoS rule, a requested QoS flow description) derived from the third set of parameters. Via the transceiver 725, the processor 705 transmits the data traffic for the third data connection through either the new QoS flow of the first data connection or the indicated existing QoS flow of the first data connection.
[0111] Memory 710, in one embodiment, is a computer-readable storage medium. In some embodiments, memory 710 includes a volatile computer storage medium. For example, memory 710 may include RAM, including dynamic RAM (“DRAM”), synchronous dynamic RAM (“SDRAM”), and / or static RAM (“SRAM”). In some embodiments, memory 710 includes a non-volatile computer storage medium. For example, memory 710 may include a hard disk drive, flash memory, or any other suitable non-volatile computer storage device. In some embodiments, memory 710 includes both volatile and non-volatile computer storage media.
[0112] In some embodiments, memory 710 stores data related to modifying the first data connection during establishment of the second data connection. For example, memory 710 may store the various parameters, panel / beam configurations, resource allocations, policies, etc. described above. In particular embodiments, memory 710 also stores program code and associated data, such as operating systems or other controller algorithms running on device 700.
[0113] Input device(s) 715, in one embodiment, may include any known computer input device, including a touch panel, buttons, keyboard, stylus, microphone, etc. In some embodiments, input device(s) 715 may be integrated with output device(s) 720, for example, as a touch screen or similar touch-sensitive display. In some embodiments, input device(s) 715 includes a touch screen so that text may be entered using a virtual keyboard displayed on the touch screen and / or by handwriting on the touch screen. In some embodiments, input device(s) 715 includes two or more different devices, such as a keyboard and a touch panel.
[0114] Output device 720, in one embodiment, is designed to output visual, auditory, and / or tactile signals. In some embodiments, output device 720 includes an electronically controllable display or display device capable of outputting visual data to a user. For example, output device 720 may include, but is not limited to, an LCD display, an LED display, an OLED display, a projector, or similar display device capable of outputting images, text, etc. to a user. As another non-limiting example, output device 720 may include a wearable display that is separate from but communicatively coupled to other portions of user equipment device 700, such as a smartwatch, smart glasses, or a head-up display. Furthermore, output device 720 may be a component of a smartphone, a personal digital assistant, a television, a table computer, a notebook (laptop) computer, a personal computer, a vehicle dashboard, etc.
[0115] In particular embodiments, output device(s) 720 include one or more speakers for generating sound. For example, output device(s) 720 may generate audible alerts or notifications (e.g., beeps or chimes). In some embodiments, output device(s) 720 include one or more haptic devices for generating vibrations, movements, or other haptic feedback. In some embodiments, all or a portion of output device(s) 720 may be integrated with input device(s) 715. For example, input device(s) 715 and output device(s) 720 may form a touchscreen or similar touch-sensitive display. In other embodiments, output device(s) 720 may be located near input device(s) 715.
[0116] The transceiver 725 communicates with one or more network functions of a mobile communications network via one or more access networks. The transceiver 725 operates under the control of the processor 705 to transmit and receive messages, data, and other signals. For example, the processor 705 may selectively activate the transceiver 725 (or portions thereof) at particular times to transmit and receive messages.
[0117] The transceiver 725 includes at least one transmitter 730 and at least one receiver 735. The one or more transmitters 730 may be used to provide UL communication signals, such as the UL transmissions described herein, to the base unit 121. Similarly, the one or more receivers 735 may be used to receive DL communication signals from the base unit 121, as described herein. Although only one transmitter 730 and one receiver 735 are shown, the user equipment device 700 may have any suitable number of transmitters 730 and receivers 735. Furthermore, the transmitters 730 and receivers 735 may be any suitable types of transmitters and receivers. In one embodiment, the transceiver 725 includes a first transmitter / receiver pair used to communicate with a mobile communication network over a licensed radio spectrum and a second transmitter / receiver pair used to communicate with a mobile communication network over an unlicensed radio spectrum.
[0118] In particular embodiments, a first transmitter / receiver pair used to communicate with a mobile communications network over a licensed radio spectrum and a second transmitter / receiver pair used to communicate with a mobile communications network over an unlicensed radio spectrum may be combined into a single transceiver unit, e.g., a single chip that performs functions for use in both the licensed and unlicensed radio spectrum. In some embodiments, the first transmitter / receiver pair and the second transmitter / receiver pair may share one or more hardware components. For example, particular transceivers 725, transmitters 730, and receivers 735 may be implemented as physically separate components that access shared hardware and / or software resources, such as, for example, a network interface 740.
[0119] In various embodiments, one or more transmitters 730 and / or one or more receivers 735 may be implemented and / or integrated in a single hardware component, such as a multi-transceiver chip, a system-on-chip, an ASIC, or other type of hardware component. In particular embodiments, one or more transmitters 730 and / or one or more receivers 735 may be implemented and / or integrated in a multi-chip module. In some embodiments, other components, such as a network interface 740 or other hardware components / circuits, may be integrated on a single chip with any number of transmitters 730 and / or receivers 735. In such embodiments, the transmitters 730 and receivers 735 may be logically configured as a transceiver 725 using one or more common control signals, or as modular transmitters 730 and receivers 735 implemented within the same hardware chip or multi-chip module.
[0120] 8 illustrates a network device 800 that may be used to modify a first data connection during establishment of a second data connection, according to an embodiment of the present disclosure. In one embodiment, the network device 800 may be an implementation of a RAN node, such as the base unit 121, the RAN node 210, or a gNB, described above. Additionally, the base network device 800 may include a processor 805, a memory 810, an input device 815, an output device 820, and a transceiver 825.
[0121] In some embodiments, the input device(s) 815 and the output device(s) 820 are combined into a single device, such as a touchscreen. In particular embodiments, the network device 800 may not include any input device(s) 815 and / or output device(s) 820. In various embodiments, the network device 800 may include one or more of the processor 805, the memory 810, and the transceiver 825, and may not include the input device(s) 815 and / or the output device(s) 820.
[0122] As shown, the transceiver 825 includes at least one transmitter 830 and at least one receiver 835, where the transceiver 825 communicates with one or more remote units 105. Additionally, the transceiver 825 may support at least one network interface 840 and / or application interface 845. The application interface 845 may support one or more APIs. The network interface 840 may support 3GPP reference points such as Uu, N1, N2, and N3. As will be appreciated by those skilled in the art, other network interfaces 840 may be supported.
[0123] The processor 805, in one embodiment, may include any known controller capable of executing computer-readable instructions and / or performing logical operations. For example, the processor 805 may be a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, FPGA, or similar programmable controller. In some embodiments, the processor 805 executes instructions stored in memory 810 to perform the methods and routines described herein. The processor 805 is communicatively coupled to the memory 810, input devices 815, output devices 820, and a transceiver 825.
[0124] In various embodiments, the network device 800 is a RAN node (e.g., a gNB) that transmits UE configurations and receives measurement reports as described herein. In such embodiments, the processor 805 controls the network device 800 to perform the behavior described above. When operating as a RAN node, the processor 805 may include an application processor (also referred to as a “main processor”) that manages application domain and operating system (“OS”) functions, and a baseband processor (also referred to as a “baseband radio processor”) that manages radio functions.
[0125] In various embodiments, the network device 800 is a gateway function and / or an interworking function, such as the N3IWF 142 and / or N3IWF 221 described above. In such embodiments, the processor 805 may control the network interface 840 to send and receive messages between the UE and a core NF in the second mobile communications network 310 (i.e., via a PDU session or other data connection with the first mobile communications network 305). Furthermore, the processor 805 may process PDU session establishment messages exchanged between the UE and a core NF in the second mobile communications network 310, as described above, and determine several IPsec child SAs to establish for the PDU session established with the second mobile communications network 310.
[0126] Memory 810, in one embodiment, is a computer-readable storage medium. In some embodiments, memory 810 includes a volatile computer storage medium. For example, memory 810 may include RAM, including dynamic RAM (“DRAM”), synchronous dynamic RAM (“SDRAM”), and / or static RAM (“SRAM”). In some embodiments, memory 810 includes a non-volatile computer storage medium. For example, memory 810 may include a hard disk drive, flash memory, or any other suitable non-volatile computer storage device. In some embodiments, memory 810 includes both volatile and non-volatile computer storage media.
[0127] In some embodiments, memory 810 stores data related to modifying the first data connection during the establishment of the second data connection. For example, memory 810 may store the above-mentioned parameters, configurations, resource allocations, policies, etc. In particular embodiments, memory 810 also stores program code and associated data, such as operating systems or other controller algorithms running on device 800.
[0128] The input device 815, in one embodiment, may include any known computer input device, including a touch panel, buttons, a keyboard, a stylus, a microphone, etc. In some embodiments, the input device 815 may be integrated with the output device 820, for example, as a touch screen or similar touch-sensitive display. In some embodiments, the input device 815 includes a touch screen so that text may be entered using a virtual keyboard displayed on the touch screen and / or by handwriting on the touch screen. In some embodiments, the input device 815 includes two or more different devices, such as a keyboard and a touch panel.
[0129] In one embodiment, output device 820 is designed to output visual, auditory, and / or tactile signals. In some embodiments, output device 820 includes an electronically controllable display or display device capable of outputting visual data to a user. For example, output device 820 may include, but is not limited to, an LCD display, an LED display, an OLED display, a projector, or similar display device capable of outputting images, text, etc. to a user. As another non-limiting example, output device 820 may include a wearable display that is separate from but communicatively coupled to other portions of network device 800, such as a smartwatch, smart glasses, or a head-up display. Furthermore, output device 820 may be a component of a smartphone, a personal digital assistant, a television, a table computer, a notebook (laptop) computer, a personal computer, a vehicle dashboard, etc.
[0130] In particular embodiments, output device 820 includes one or more speakers for generating sound. For example, output device 820 may generate an audible alert or notification (e.g., a beep or chime). In some embodiments, output device 820 includes one or more haptic devices for generating vibration, movement, or other haptic feedback. In some embodiments, all or a portion of output device 820 may be integrated with input device 815. For example, input device 815 and output device 820 may form a touchscreen or similar touch-sensitive display. In other embodiments, output device 820 may be located near input device 815.
[0131] The transceiver 825 includes at least one transmitter 830 and at least one receiver 835. The one or more transmitters 830 may be used to communicate with a UE, as described herein. Similarly, the one or more receivers 835 may be used to communicate with a network function of an NPN, PLMN, and / or RAN, as described herein. Although only one transmitter 830 and one receiver 835 are shown, the network device 800 may have any suitable number of transmitters 830 and receivers 835. Furthermore, the transmitters 830 and receivers 835 may be any suitable types of transmitters and receivers.
[0132] 9 illustrates one embodiment of a method 900 for modifying a first data connection during establishment of a second data connection, according to embodiments of the present disclosure. In various embodiments, method 900 is performed by a user equipment device in a mobile communications network, such as the remote unit 105, UE 205, and / or user equipment device 700 described above. In some embodiments, method 900 is performed by a processor, such as a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, FPGA, or the like.
[0133] The method 900 starts by receiving (905) a first request (i.e., an IKE Child SA Creation Request) over a first data connection (i.e., over PDU Session 1) with a first mobile communications network (i.e., the mobile core network 130, the NPN 215, and / or the first network 305), the first data connection supporting multiple QoS flows, where the first request includes a first set of parameters (i.e., SPI, additional QoS information) for establishing a second data connection (i.e., an IPsec Child SA) with an interworking function (i.e., the N3IWF 142 and / or the N3IWF 221) in a second mobile communications network (i.e., the mobile core network 140, the PLMN 220, and / or the second network 310), where data traffic of the second data connection is to be transported over the first data connection (i.e., the IPsec Child SA is transported within PDU Session 1).
[0134] Method 900 includes transmitting 910 a second request (i.e., a PDU session modification request) to modify the first data connection in response to receiving the first request, where the second request includes a second set of parameters (i.e., requested QoS rules, requested QoS flow description) derived from the first set of parameters (i.e., SPI, additional QoS information), and the second set of parameters modify the first data connection to support data traffic for the second data connection. Method 900 includes transmitting 915 the data traffic for the second data connection over the modified first data connection. Method 900 then ends.
[0135] Disclosed herein is a first apparatus for modifying a first data connection during establishment of a second data connection according to an embodiment of the present disclosure. The first apparatus may be implemented by a user equipment device in a mobile communication network, such as the above-described remote unit 105, UE 205, and / or user equipment device 700. The first apparatus includes a processor and a transceiver supporting a first data connection (e.g., a first PDU session) with a first mobile communication network via a first access network, the first data connection supporting multiple Quality of Service ("QoS") flows. The processor receives a first request (e.g., an IKE child SA creation request) over the first data connection, the first request including a first set of parameters (e.g., SPI, additional QoS information) for establishing a second data connection (e.g., IPsec child SA) with an interworking function (e.g., N3IWF) in the second mobile communication network. Here, data traffic of the second data connection is to be transferred through the first data connection (e.g., an IPsec child SA is transferred within the first PDU session). Via the transceiver, the processor, in response to receiving the first request, transmits a second request (e.g., a PDU session modification request) to modify the first data connection, the second request including a second set of parameters (e.g., a requested QoS rule, a requested QoS flow description) derived from the first set of parameters (e.g., an SPI, additional QoS information), the second set of parameters modifying the first data connection to support the data traffic of the second data connection, and the processor transmits the data traffic of the second data connection through the modified first data connection.
[0136] In some embodiments, the second set of parameters indicates establishing a new QoS flow on the first data connection, where the new QoS flow will carry data traffic for the second data connection. In such embodiments, the second set of parameters indicates establishing a new QoS flow on the first data connection in response to determining that none of the existing QoS flows on the first data connection are suitable for carrying data traffic for the second data connection. In particular embodiments, the second set of parameters includes a packet filter (e.g., an IP address and SPI of the N3IWF) that identifies data traffic for the second data connection.
[0137] In some embodiments, the second set of parameters indicates an existing QoS flow for the first data connection, where the existing QoS flow will carry data traffic for the second data connection. In particular embodiments, the second set of parameters includes a packet filter (e.g., an IP address and SPI of the N3IWF) that identifies the data traffic for the second data connection.
[0138] In some embodiments, the second data connection includes an Internet Protocol Security ("IPsec") child security association ("SA"), and the first set of parameters includes a security parameter index ("SPI") and additional QoS information for the IPsec child SA. In particular embodiments, the second set of parameters includes requested QoS rules and requested QoS flow descriptions for modifying the first data connection to support data traffic of the IPsec child SA. In some embodiments, the first mobile communications network includes a non-public network ("NPN"), and the second mobile communications network includes a public land mobile network ("PLMN"). In other embodiments, the first mobile communications network includes a PLMN, and the second mobile communications network includes an NPN.
[0139] In some embodiments, the first request is an Internet Key Exchange ("IKE") Child SA Create Request received from a non-3GPP (registered trademark) Interworking Function ("N3IWF"). In such embodiments, the processor further transmits an IKE Child SA Create Response message to the N3IWF in response to successfully modifying the first data connection before transmitting data traffic of the second data connection through the modified first data connection. In some embodiments, the first request (e.g., an IKE Child SA Create Request) is received in response to transmitting, over the first data connection, a PDU session establishment request requesting establishment of a PDU session in the second mobile communications network via an interworking function in the second mobile communications network.
[0140] In some further embodiments, the processor receives a third request (e.g., a second IKE child SA creation request) over the first data connection, the third request including a third set of parameters (e.g., SPI-2, additional QoS information 2) for establishing a third data connection (e.g., IPsec child SA-2) with the interworking function, where data traffic of the third data connection is to be transported over the first data connection (e.g., IPsec child SA-2 is also transported within PDU session 1), and the second data connection and the third data connection form a PDU session with the second mobile communications network. In such embodiments, in response to receiving the third request, the processor transmits a fourth request (e.g., a PDU session modification request) to establish a new QoS flow on the first data connection and transmits the data traffic of the third data connection through the new QoS flow of the first data connection, the fourth request including a fourth set of parameters (e.g., a requested QoS rule, a requested QoS flow description) derived from the third set of parameters.
[0141] In some further embodiments, the processor receives a third request (e.g., an IKE Child SA Creation Request) over the first data connection, the third request including a third set of parameters for establishing a third data connection (e.g., IPsec Child SA-2) with the interworking function, where data traffic of the third data connection is to be transported over the first data connection (e.g., IPsec Child SA-2 is also transported within PDU Session 1), and the second data connection and the third data connection form a PDU session with the second mobile communications network. In such embodiments, in response to receiving the third request, the processor transmits a fourth request (e.g., a PDU Session Modification Request) to indicate an existing QoS flow of the first data connection that should carry the data traffic of the third data connection, and transmits the data traffic of the third data connection through the indicated existing QoS flow of the first data connection, the fourth request including a fourth set of parameters (e.g., a requested QoS rule, a requested QoS flow description) derived from the third set of parameters.
[0142] Disclosed herein is a first method for modifying a first data connection during establishment of a second data connection according to an embodiment of the present disclosure. The first method may be performed by a user equipment device in a mobile communication network, such as a remote unit 105, a UE 205, and / or a user equipment device 700. The first method includes receiving a first request (e.g., an IKE Child SA Creation Request) over a first data connection (e.g., over PDU Session 1) with a first mobile communication network via a first access network, where the first data connection supports multiple QoS flows. Here, the first request includes a first set of parameters (e.g., SPI, additional QoS information) for establishing a second data connection (e.g., IPsec Child SA) with an interworking function (e.g., N3IWF 142) in the second mobile communication network, where data traffic of the second data connection is to be transferred over the first data connection (e.g., the IPsec Child SA is transferred within PDU Session 1). The first method includes transmitting, in response to receiving the first request, a second request (e.g., a PDU session modification request) to modify the first data connection, where the second request includes a second set of parameters (e.g., a requested QoS rule, a requested QoS flow description) derived from the first set of parameters (e.g., an SPI, additional QoS information), and the second set of parameters modify the first data connection to support data traffic of the second data connection. The first method includes transmitting the data traffic of the second data connection through the modified first data connection.
[0143] In some embodiments, the second set of parameters indicates establishing a new QoS flow on the first data connection, the new QoS flow to carry data traffic for the second data connection. In such embodiments, the second set of parameters indicates establishing a new QoS flow on the first data connection in response to determining that none of the existing QoS flows on the first data connection are suitable for carrying data traffic for the second data connection. In particular embodiments, the second set of parameters includes a packet filter (e.g., an IP address and SPI of the N3IWF) that identifies data traffic for the second data connection.
[0144] In some embodiments, the second set of parameters indicates an existing QoS flow for the first data connection, which existing QoS flow will carry data traffic for the second data connection. In particular embodiments, the second set of parameters includes a packet filter (e.g., an IP address and SPI of the N3IWF) that identifies the data traffic for the second data connection.
[0145] In some embodiments, the second data connection includes an IPsec child SA, and the first set of parameters includes an SPI and additional QoS information for the IPsec child SA. In particular embodiments, the second set of parameters includes requested QoS rules and requested QoS flow descriptions for modifying the first data connection to support data traffic for the IPsec child SA. In some embodiments, the first mobile communications network includes an NPN, and the second mobile communications network includes a PLMN. In other embodiments, the first mobile communications network includes a PLMN, and the second mobile communications network includes an NPN.
[0146] In some embodiments, the first request is an IKE Child SA Create Request received from the N3IWF. In such embodiments, the first method may include, in response to successfully modifying the first data connection, sending an IKE Child SA Create Response message to the N3IWF before transmitting data traffic of the second data connection through the modified first data connection.
[0147] In some embodiments, the first request is received in response to transmission over the first data connection of a PDU session establishment request requesting the establishment of a PDU session in the second mobile communications network via an interworking function within the second mobile communications network.
[0148] In some embodiments, the first method further includes receiving a third request (e.g., a second IKE Child SA Creation Request) over the first data connection, the third request including a third set of parameters (e.g., SPI-2, Additional QoS Information 2) for establishing a third data connection (e.g., IPsec Child SA-2) with the interworking function, where data traffic of the third data connection is to be transported over the first data connection (e.g., IPsec Child SA-2 is also transported within PDU Session 1), and the second data connection and the third data connection form a PDU session with the second mobile communications network. In such embodiments, the first method further includes, in response to receiving the third request, sending a fourth request (e.g., a PDU Session Modification Request) to establish a new QoS flow on the first data connection and sending the data traffic of the third data connection through the new QoS flow of the first data connection, the fourth request including a fourth set of parameters (e.g., a requested QoS rule, a requested QoS flow description) derived from the third set of parameters.
[0149] In some embodiments, the first method further includes receiving a third request (e.g., an IKE Child SA Creation Request) over the first data connection, where the third request includes a third set of parameters (e.g., SPI-2, Additional QoS Information 2) for establishing a third data connection (e.g., IPsec Child SA-2) with the interworking function, where data traffic of the third data connection is to be transferred over the first data connection (e.g., IPsec Child SA-2 is also transferred within PDU Session 1), and the second data connection and the third data connection form a PDU session with the second mobile communications network. In such an embodiment, the first method further includes, in response to receiving the third request, sending a fourth request (e.g., a PDU session modification request) to indicate an existing QoS flow of the first data connection that should carry the data traffic of the third data connection, and sending the data traffic of the third data connection through the indicated existing QoS flow of the first data connection, wherein the fourth request includes a fourth set of parameters (e.g., a requested QoS rule, a requested QoS flow description) derived from the third set of parameters.
[0150] The embodiments may be embodied in other specific forms. The described embodiments are to be considered in all respects only as illustrative and not restrictive. The scope of the invention is, therefore, indicated by the appended claims rather than by the foregoing description. All changes that come within the meaning and range of equivalency of the claims are to be embraced within their scope. [Explanation of symbols]
[0151] 100 Wireless Communication System 105 Remote Unit 107 Applications 120 RAN 121 Base Unit 123 Wireless Communication Links 130 First Mobile Core Network 131 UPF 133 AMF 135 SMF 137 PCF 139 UDM / UDR 140 Second Mobile Core Network 141 UPF 142 N3IWF 143 AMF 145 SMF 147 PCF 149 UDM / UDR 150 Packet Data Network 151 Application Server 200 Network Deployment 205 UE 210 Access Network 215 NPN 216 AMF ("AMF-0") 217 SMF (SMF-0) 218 UPF ("UPF-0") 220 LMN 221 N3IWF 222 AMF ("AMF-1") 223 SMF ("SMF-1") 224 UPF ("UPF-1") 225 Data Network 0 (DN-0) 230 Data Network 1 (DN-1) 235 PDU sessions 240 Signaling IPsec SA 255 new QoS flows 300 Network Architecture 305 First Mobile Communication Network 310 Second Mobile Communication Network 315 1st PDU Session 320 QoS Flow 1 325 QoS Flow 2 330 New QoS Flows 335 Second PDU Session (“PDU Session 2”) 340 IPsec Child SA 400 Scenarios 405 First Data Connection, NG-RAN, First PDU Session 410 First QoS Flow ("QoS Flow 1") 415 Second QoS Flow ("QoS Flow 2") 420 data traffic 425 IPsec SA 430 data traffic 500 steps 501 PCF-1 502 UDM-1 503 PCF-0 523 UE-initiated PDU Session Modification Procedure 539 UE-initiated PDU Session Modification Procedure 600 scenarios 605 Modified 1st Data Connection, 1st PDU Session 610 Third QoS Flow ("QoS Flow 3") 615 Fourth QoS Flow ("QoS Flow 4") 620 First IPsec Child SA 625 Second IPsec Child SA 635 Second PDU Session 700 User Equipment Device 705 processor 710 memory 715 Input Devices 720 output device 725 Transceiver 730 Transmitter 735 receiver 740 network interface 745 Application Interface 800 Network Equipment 805 processor 810 memory 815 Input Devices 820 output device 825 Transceiver 830 Transmitter 835 receiver 840 network interface 845 Application Interface 900 ways
Claims
Claim 1: A user equipment ("UE") for wireless communications, comprising: at least one memory; coupled to the at least one memory, to the UE; in response to receiving a first request over a first data connection with a first mobile communications network, the first data connection supporting multiple Quality of Service ("QoS") flows, the first request including a first set of parameters for establishing a second data connection with an interworking function in a second mobile communications network, the first request being received from the interworking function and data traffic of the second data connection to be forwarded over the first data connection; and in response to determining that none of the existing QoS flows of the first data connection are suitable to meet the QoS requirements of the second data connection; initiating a modification procedure with the first mobile communications network by sending a second request to modify the first data connection, the second request including a second set of parameters derived from the first set of parameters, the second set of parameters indicating establishment of a new QoS flow on the first data connection, the new QoS flow to carry the data traffic of the second data connection, and the second set of parameters modifying the first data connection to support the data traffic of the second data connection; transmitting the data traffic of the second data connection over the modified first data connection; at least one processor configured to cause User Equipment ("UE"), including:
2. The UE of claim 1 , wherein the second set of parameters includes a packet filter that identifies the data traffic of the second data connection.
3. the second data connection includes an Internet Protocol Security (“IPsec”) child security association (“SA”); 10. The UE of claim 1, wherein a first set of parameters includes a security parameter index ("SPI") and additional QoS information for the IPsec child SA.
4. 4. The UE of claim 3, wherein the second set of parameters includes a requested QoS rule and a requested QoS flow description for modifying the first data connection to support data traffic of the IPsec child SA.
5. the first mobile communications network comprises a non-public network; The UE of claim 1 , wherein the second mobile communications network comprises a public land mobile network.
6. the first request is an Internet Key Exchange ("IKE") Child SA creation request received from a non-3GPP Interworking Function ("N3IWF"); 2. The UE of claim 1, wherein the processor is configured to send an IKE Child SA Creation Response message to the N3IWF in response to successful modification of the first data connection before transmitting the data traffic of the second data connection through the modified first data connection.
7. 2. The UE of claim 1, wherein the first request is received in response to transmission, via the first data connection, of a PDU session establishment request requesting establishment of a PDU session in the second mobile communications network via the interworking function in the second mobile communications network.
8. 1. A method performed by a user equipment, comprising: receiving a first request over a first data connection with a first mobile communications network, the first data connection supporting multiple Quality of Service ("QoS") flows, the first request including a first set of parameters for establishing a second data connection with an interworking function in a second mobile communications network, the first request being received from the interworking function, and data traffic of the second data connection to be forwarded over the first data connection; initiating a modification procedure with the first mobile communications network by sending a second request to modify the first data connection in response to receiving the first request and determining that none of the existing QoS flows of the first data connection are suitable to meet the QoS requirements of the second data connection, the second request including a second set of parameters derived from the first set of parameters, the second set of parameters indicating the establishment of a new QoS flow on the first data connection, the new QoS flow to carry the data traffic of the second data connection, and the second set of parameters modifying the first data connection to support the data traffic of the second data connection; transmitting the data traffic of the second data connection over the modified first data connection; A method comprising:
9. 9. The method of claim 8, wherein the second set of parameters includes a packet filter that identifies the data traffic of the second data connection.
10. the second data connection includes an Internet Protocol Security (“IPsec”) child security association (“SA”); 9. The method of claim 8, wherein a first set of parameters includes a Security Parameter Index ("SPI") and additional QoS information for the IPsec child SA.
11. 11. The method of claim 10, wherein the second set of parameters includes a requested QoS rule and a requested QoS flow description for modifying the first data connection to support data traffic of the IPsec child SA.
12. the first mobile communications network comprises a non-public network; The method of claim 8 , wherein the second mobile communications network comprises a public land mobile network.
13. the first request is an Internet Key Exchange ("IKE") Child SA creation request received from a non-3GPP Interworking Function ("N3IWF"), and the method comprises:
9. The method of claim 8, further comprising: in response to successful modification of the first data connection, sending an IKE Child SA Creation Response message to the N3IWF before sending the data traffic of the second data connection through the modified first data connection.
14. 9. The method of claim 8, wherein the first request is received in response to transmission, via the first data connection, of a PDU session establishment request requesting establishment of a PDU session in the second mobile communications network via the interworking function in the second mobile communications network.
Citation Information
Patent Citations
Establishing a new QOS flow for a data connection
WO2021052573A1