Security for proximity based services multi-hop UE-to- network relay discovery

By verifying relay discovery security materials using a Home Public Land Mobile Network (HPLMN) ID in clear text, the method secures 5G ProSe multi-hop UE-to-network relay discovery, addressing vulnerabilities and ensuring secure communication paths.

WO2026077986A1PCT designated stage Publication Date: 2026-04-16TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/078821
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-10-07
Filing Date
2025-10-07
Publication Date
2026-04-16

AI Technical Summary

Technical Problem

Existing 5G ProSe multi-hop UE-to-network relay discovery systems lack effective security mechanisms to protect discovery messages, making them vulnerable to attacks such as discovery message manipulation and unauthorized access to private user information.

Method used

Implementing a method for UEs to verify relay discovery security materials using a Home Public Land Mobile Network (HPLMN) ID in clear text within discovery messages, enabling secure verification and processing of these messages.

Benefits of technology

Enhances security in multi-hop U2N relay arrangements by mitigating unauthorized access and ensuring end-to-end and hop-to-hop security between remote UEs and U2N relays.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025078821_16042026_PF_FP_ABST
    Figure EP2025078821_16042026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments include a method for a first user equipment (UE) arranged to discover intermediate UE-to-network (U2N) relays that facilitate access to a communication network via a U2N relay. Such method includes receiving, from a third UE configured to operate as an intermediate U2N relay between the first UE and a second UE configured to operate as the U2N relay, a message associated with multi-hop relay discovery. The message includes a first portion generated by the third UE, a second portion generated by the second UE and a home public land mobile network (HPLMN) ID in clear text. Such method further includes identifying, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message. The method also includes verifying at least the first portion of the message based on the identified relay discovery security materials. Such method further includes, based on successful verification of at least the first portion, processing the message.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SECURITY FOR PROXIMITY BASED SERVICES MULTI-HOP UE-TO-

[0002] NETWORK RELAY DISCOVERY

[0003] TECHNICAL FIELD

[0004] The present disclosure relates generally to wireless networks and devices, and more specifically to techniques that enable user equipment (UEs) to securely discover a multi-hop path of relay UEs that facilitate UE communication with a wireless network.

[0005] BACKGROUND

[0006] Currently the fifth generation (5G) of cellular systems, also referred to as New Radio (NR), is being standardized within the Third-Generation Partnership Project (3GPP). NR is developed for maximum flexibility to support multiple and substantially different use cases. These include enhanced mobile broadband (eMBB), machine type communications (MTC), ultra-reliable low latency communications (URLLC), Public Safety communications, Vehicle- to-Everything (V2X) communication, and several other use cases. NR was initially specified in 3GPP Release 15 (Rel-15) and continues to evolve through subsequent releases, such as Rel-16 and Rel-17.

[0007] PROximity -based SErvices (ProSe) in 3 GPP enables direct device-to-device (D2D) communication and is particularly important in scenarios where devices need to communicate directly without involving the core network, such as in mission-critical communications or in situations where the network is unavailable. In ProSe communication, a ProSe-enabled UE may have different roles.

[0008] As specified in 3GPP Rel-17, a 5G ProSe UE-to-Network (U2N) Relay is a 5G ProSe- enabled UE that provides indirect Layer-2 and Layer-3 single-hop communication between a 5G data network (DN) and a ProSe Remote UE, e.g. a 5G ProSe-enabled UE that is out of coverage of the network, by using direct communication.

[0009] In 3 GPP Rel-19, 5G ProSe U2N Relay enables indirect Layer-3 multi -hop communication between the 5G network and the ProSe Remote UE by means of a 5G ProSe U2N Relay and 5G ProSe Intermediate U2N Relay. In multi-hop communication, there may be one or multiple 5G ProSe Intermediate U2N Relays between the 5G ProSe Remote UE and the 5G ProSe U2N Relay.

[0010] Typically, 5G ProSe-enabled UEs initially discover each other via 5G ProSe Discovery procedure, then trigger ProSe Communication (aka PC5 link) establishment for each other. Each 5G ProSe discovery message includes a specific code such as a Relay Service Code (RSC) in the case of ProSe U2N relay. There is a one-to-one association between codes and security materials, e.g., each RSC is associated with a corresponding set of security materials including Code-Sending Security Parameters and Code-Receiving Security Parameters.

[0011] As specified in clause 6.3.2.3.2 of 3GPP Technical Specification (TS) 23.304 (vl9.1.0) and clause 6.1.3.2.2.1 of 3GPP TS 33.503 (vl8.4.0), an announcing 5G ProSe Layer-3 U2N Relay and a monitoring 5G ProSe Remote UE perform protected (restricted) relay discovery. The information included by the original announcing 5G ProSe U2N Relay is protected by the relay discovery security material as specified in clause 6.1.3.2.2.1 of 3GPP TS 33.503 (V18.4.0).

[0012] To support multi-hop U2N relaying, a ProSe Remote UE can discover a ProSe U2N Relay via one or more proximate ProSe Intermediate U2N Relays. These discovery messages used to discover either a proximate Intermediate U2N Relay or a target U2N Relay via a proximate Intermediate U2N Relay need to be security protected. Failure to protect the security of these discovery messages for multi-hop U2N relaying may lead to various attacks by unauthorized UEs, such as discovery message manipulation, replay, and / or capture of private or sensitive user information. As described in 3GPP Technical Report (TR) 33.743 (v0.3.0) different security mechanisms for discovery messages in multi-hop U2N relaying, including ProSe multi-hop U2N Relay (both Layer-2 and Layer-3 Relays) and ProSe multi-hop UE-to- UE Relay (Layer-3 Relay only), are being considered.

[0013] In particular, solutions for the following two models of relay discovery specified in 3GPP TR 33.743 (VO.3.0) are referred to herein:

[0014] Model A: announcement sent by announcing 5G ProSe U2N and received by monitoring 5G ProSe Remote UE; and

[0015] Model B: discovery solicitation sent by discoverer 5G ProSe Remote UE and received by Discoveree 5G ProSe U2N and discovery response sent by Discoveree 5G ProSe U2N and received by discoverer 5G ProSe Remote UE.

[0016] SUMMARY

[0017] An object of embodiments of the present disclosure is to provide, enable and facilitate solutions for a receiving UE (e.g. a 5G ProSe Intermediate U2N Relay or a ProSe Remote UE in Model A or a 5G ProSe Intermediate U2N relay, a 5G ProSe U2N relay or a Remote UE in Model B) to identify which discovery security materials have been used by an intermediate U2N relay for protection of additional information that the intermediate U2N relay added / updated in a message associated with multi -hop relay discovery. A further object is to provide, enable and facilitate solutions for the involved UE's to request these relay discovery security materials, e.g., from the 5G PKMF or 5G DDN MF.

[0018] More particularly, embodiments herein include a method performed by a first user equipment (UE) configured to discover intermediate UE-to-network (U2N) relays that facilitate access to a communication network via a U2N relay. The method comprises receiving, from a third UE configured to operate as an intermediate U2N relay between the first UE and a second UE configured to operate as the U2N relay, a message associated with multi -hop relay discovery. In some embodiments, the message includes a first portion generated by the third UE. The message also includes a second portion generated by the second

[0019] UE. The message also includes a home public land mobile network (HPLMN) ID in clear text. The method also comprises identifying, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message. The method also comprises verifying at least the first portion of the message based on the identified relay discovery security materials. The method also comprises, based on successful verification of at least the first portion, processing the message.

[0020] Other embodiments herein include a method for a second user equipment (UE) configured to provide a UE-to-network (U2N) relay between intermediate U2N relays and a communication network. The method comprises receiving, from a third UE configured to operate as an intermediate U2N relay between the second UE and a first UE, a message associated with multi-hop relay discovery. In some embodiments, the message includes a first portion generated by the third UE. The message also includes a second portion generated by the first UE. The message also includes a home public land mobile network (HPLMN) ID in clear text. The method also comprises identifying, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message. The method also comprises verifying at least the first portion of the message based on the identified relay discovery security materials. The method also comprises, based on successful verification of at least the first portion, processing the message.

[0021] Other embodiments herein include a method performed by a third user equipment (UE) configured to provide an intermediate UE-to-network (U2N) relay between a remote UE and a U2N relay for facilitating access to a communication network. The method comprises receiving a first message associated with multi-hop relay discovery. In some embodiments, the first message includes a second portion generated by a message source UE. The first message also includes a first portion generated by the message source UE or a fourth UE configured as an intermediate U2N relay between the message source UE and the third UE. The first message also includes a home public land mobile network (HPLMN) ID in clear text. The method also comprises identifying, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message. The method also comprises verifying at least the first portion of the message based on the identified relay discovery security materials. The method also comprises, based on successful verification of at least the first portion, processing the message.

[0022] Other embodiments herein include a method performed by a third user equipment (UE) configured to provide an intermediate UE-to-network (U2N) relay between a remote UE and a U2N relay for facilitating access to a communication network. The method comprises receiving a first message associated with multi-hop relay discovery. In some embodiments, the first message includes a second portion generated by a message source UE. The first message also includes a first portion generated by the message source UE or a fourth UE configured as an intermediate U2N relay between the message source UE and the third UE. The method also comprises updating the first portion of the message. The method also comprises securing at least the updated first portion using relay discovery security materials that are associated with a home public land mobile network (HPLMN) ID. The method also comprises sending, to a message target UE or a fifth UE configured as an intermediate U2N relay between the message target UE and the third UE, a second message that includes the secured updated first portion, includes the second portion, and includes the HPLMN ID in clear text.

[0023] Other embodiments herein include a first user equipment (UE) configured to discover intermediate UE-to-network (U2N) relays that facilitate access to a communication network via a U2N relay. The first UE is configured to receive, from a third UE configured to operate as an intermediate U2N relay between the first UE and a second UE configured to operate as the U2N relay, a message associated with multi-hop relay discovery. In some embodiments, the message includes a first portion generated by the third UE. The message also includes a second portion generated by the second UE. The message also includes a home public land mobile network (HPLMN) ID in clear text. The first UE is also configured to identify, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message. The first UE is also configured to verify at least the first portion of the message based on the identified relay discovery security materials. The first UE is also configured to, based on successful verification of at least the first portion, process the message.

[0024] Other embodiments herein include a second user equipment (UE) configured to provide a UE-to-network (U2N) relay between intermediate U2N relays and a communication network. The second UE is configured to receive, from a third UE configured to operate as an intermediate U2N relay between the second UE and a first UE, a message associated with multi-hop relay discovery. In some embodiments, the message includes a first portion generated by the third UE. The message also includes a second portion generated by the first UE. The message also includes a home public land mobile network (HPLMN) ID in clear text.

[0025] The second UE is also configured to identify, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message. The second UE is also configured to verify at least the first portion of the message based on the identified relay discovery security materials. The second UE is also configured to, based on successful verification of at least the first portion, process the message.

[0026] Other embodiments herein include a third user equipment (UE) configured to provide an intermediate UE-to-network (U2N) relay between a remote UE and a U2N relay for facilitating access to a communication network. The third UE is configured to receive a first message associated with multi-hop relay discovery. In some embodiments, the first message includes a second portion generated by a message source UE. The first message also includes a first portion generated by the message source UE or a fourth UE configured as an intermediate U2N relay between the message source UE and the third UE. The first message also includes a home public land mobile network (HPLMN) ID in clear text. The third UE is also configured to identify, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message. The third UE is also configured to verify at least the first portion of the message based on the identified relay discovery security materials. The third UE is also configured to, based on successful verification of at least the first portion, process the message.

[0027] Other embodiments herein include a third user equipment (UE) configured to provide an intermediate UE-to-network (U2N) relay between a remote UE and a U2N relay for facilitating access to a communication network. The third UE is configured to receive a first message associated with multi-hop relay discovery. In some embodiments, the first message includes a second portion generated by a message source UE. The first message also includes a first portion generated by the message source UE or a fourth UE configured as an intermediate U2N relay between the message source UE and the third UE. The third UE is also configured to update the first portion of the message. The third UE is also configured to secure at least the updated first portion using relay discovery security materials that are associated with a home public land mobile network (HPLMN) ID. The third UE is also configured to send, to a message target UE or a fifth UE configured as an intermediate U2N relay between the message target UE and the third UE, a second message that includes the secured updated first portion, includes the second portion, and includes the HPLMN ID in clear text.

[0028] Other embodiments herein include a first user equipment (UE) configured to discover intermediate UE-to-network (U2N) relays that facilitate access to a communication network via a U2N relay. The first UE comprises communication interface circuitry configured to communicate with other UEs configured as intermediate U2N relays. The first UE also comprises processing circuitry operatively coupled to the communication interface circuitry, whereby the processing circuitry and the communication interface circuitry are configured to receive, from a third UE configured to operate as an intermediate U2N relay between the first UE and a second UE configured to operate as the U2N relay, a message associated with multihop relay discovery. In some embodiments, the message includes a first portion generated by the third UE. The message also includes a second portion generated by the second UE. The message also includes a home public land mobile network (HPLMN) ID in clear text. The processing circuitry and the communication interface circuitry are also configured to identify, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message. The processing circuitry and the communication interface circuitry are also configured to verify at least the first portion of the message based on the identified relay discovery security materials. The processing circuitry and the communication interface circuitry are also configured to, based on successful verification of at least the first portion, process the message.

[0029] Other embodiments herein include a second user equipment (UE) configured to provide a UE-to-network (U2N) relay between intermediate U2N relays and a communication network. The second UE comprises communication interface circuitry configured to communicate with other UEs configured as intermediate U2N relays. The second UE also comprises processing circuitry operatively coupled to the communication interface circuitry, whereby the processing circuitry and the communication interface circuitry are configured to receive, from a third UE configured to operate as an intermediate U2N relay between the second UE and a first UE, a message associated with multi-hop relay discovery. In some embodiments, the message includes a first portion generated by the third UE. The message also includes a second portion generated by the first UE. The message also includes a home public land mobile network (HPLMN) ID in clear text. The processing circuitry and the communication interface circuitry are configured to identify, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message. The processing circuitry and the communication interface circuitry are configured to verify at least the first portion of the message based on the identified relay discovery security materials. The processing circuitry and the communication interface circuitry are configured to, based on successful verification of at least the first portion, process the message.

[0030] Other embodiments herein include a third user equipment (UE) configured to provide an intermediate UE-to-network (U2N) relay between a remote UE and a U2N relay for facilitating access to a communication network. The third UE comprises communication interface circuitry configured to communicate with other UEs configured as remote UEs, intermediate U2N relays, or U2N relays coupled to communication network. The third UE also comprises processing circuitry operatively coupled to the communication interface circuitry, whereby the processing circuitry and the communication interface circuitry are configured to receive a first message associated with multi-hop relay discovery. In some embodiments, the first message includes a second portion generated by a message source UE. The first message also includes a first portion generated by the message source UE or a fourth UE configured as an intermediate U2N relay between the message source UE and the third UE. The first message also includes a home public land mobile network (HPLMN) ID in clear text. The processing circuitry and the communication interface circuitry are also configured to identify, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message. The processing circuitry and the communication interface circuitry are also configured to verify at least the first portion of the message based on the identified relay discovery security materials. The processing circuitry and the communication interface circuitry are also configured to, based on successful verification of at least the first portion, process the message.

[0031] Other embodiments herein include a third user equipment (UE) configured to provide an intermediate UE-to-network (U2N) relay between a remote UE and a U2N relay for facilitating access to a communication network. The third UE comprises communication interface circuitry configured to communicate with other UEs configured as remote UEs, intermediate U2N relays, or U2N relays coupled to communication network. The third UE also comprises processing circuitry operatively coupled to the communication interface circuitry, whereby the processing circuitry and the communication interface circuitry are configured to receive a first message associated with multi-hop relay discovery. The first message includes a second portion generated by a message source UE. The first message also includes a first portion generated by the message source UE or a fourth UE configured as an intermediate U2N relay between the message source UE and the third UE. The processing circuitry and the communication interface circuitry are also configured to update the first portion of the message. The processing circuitry and the communication interface circuitry are also configured to secure at least the updated first portion using relay discovery security materials that are associated with a home public land mobile network (HPLMN) ID. The processing circuitry and the communication interface circuitry are also configured to send, to a message target UE or a fifth UE configured as an intermediate U2N relay between the message target UE and the third UE, a second message that includes the secured updated first portion, includes the second portion, and includes the HPLMN ID in clear text.

[0032] Other variations of these exemplary methods are disclosed herein.

[0033] Other embodiments include UEs (e.g., wireless devices) configured to perform operations corresponding to any of the exemplary methods described herein. Other embodiments include non-transitory, computer-readable media storing program instructions that, when executed by processing circuitry, configure such UEs to perform operations corresponding to any of the exemplary methods described herein.

[0034] Some embodiments described herein may facilitate secure discovery in multi-hop U2N arrangements where source intermediate U2N relays are using their own discovery security material which mitigates attacks by unauthorized intermediate U2N relays. At a high level, embodiments will facilitate end-to-end security between a remote UE and a U2N relay as well as hop-to-hop security between the remote UE, the intermediate U2N relay(s), and the U2N relay.

[0035] These and other objects, features, and advantages of embodiments of the present disclosure will become apparent upon reading the following Detailed Description in view of the Drawings briefly described below.

[0036] BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 shows exemplary NR user plane (UP) and control plane (CP) protocol stacks. Figure 2 illustrates a high-level view of an exemplary 5G / NR network architecture. Figure 3 shows three exemplary network coverage scenarios for two UEs and a gNB serving a cell.

[0038] Figure 4 shows a reference architecture for single-hop 5G ProSe U2N Relay.

[0039] Figure 5 shows an example scenario of multi-hop 5G ProSe U2N Relay.

[0040] Figure 6 shows signaling for an example of a conventional discovery procedure supporting multi-hop U2N Relay. Figure 7 shows signaling for a further example of a conventional discovery procedure supporting multi-hop U2N Relay.

[0041] Figure 8 shows signaling for a conventional security procedure for restricted 5G ProSe Direct Discovery Model A.

[0042] Figure 9 shows signaling for a conventional security procedure for restricted 5G ProSe Direct Discovery Model B.

[0043] Figure 10 shows signaling for an example of discovery procedure supporting multi -hop U2N Relay according to various embodiments of the present disclosure.

[0044] Figure 11 shows signaling for a further example of a discovery procedure supporting multi-hop U2N Relay, according to various embodiments of the present disclosure.

[0045] Figure I la, shows signaling for a further example of a discovery procedure supporting multi-hop U2N Relay, according to various embodiments of the present disclosure.

[0046] Figure 12 shows signaling for a security procedure for restricted 5G ProSe Direct Discovery Model A, according to various embodiments of the present disclosure.

[0047] Figure 13 shows signaling for a security procedure for restricted 5G ProSe Direct Discovery Model B, according to various embodiments of the present disclosure.

[0048] Figure 14A shows a flow diagram of an exemplary method for a first UE (e.g., wireless device), according to various embodiments of the present disclosure.

[0049] Figure 14B shows a flow diagram of an exemplary method for a first UE (e.g., wireless device), according to various embodiments of the present disclosure.

[0050] Figure 15A shows a flow diagram of an exemplary method for a second UE (e.g., wireless device), according to various embodiments of the present disclosure.

[0051] Figure 15B shows a flow diagram of an exemplary method for a second UE (e.g., wireless device), according to various embodiments of the present disclosure.

[0052] Figure 16A shows a flow diagram of an exemplary method for a third UE (e.g., wireless device), according to various embodiments of the present disclosure.

[0053] Figure 16B shows a flow diagram of an exemplary method for a third UE (e.g., wireless device), according to various embodiments of the present disclosure.

[0054] Figure 17 shows a communication system according to various embodiments of the present disclosure.

[0055] Figure 18 shows a UE according to various embodiments of the present disclosure. DETAILED DESCRIPTION

[0056] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Other embodiments, however, are contained within the scope of the subject matter disclosed herein, the disclosed subject matter should not be construed as limited to only the embodiments set forth herein; rather, these embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.

[0057] In general, all terms used herein are to be interpreted according to their ordinary meaning to a person of ordinary skill in the relevant technical field, unless a different meaning is expressly defined and / or implied from the context of use. All references to a / an / the element, apparatus, component, means, step, etc. are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise or clearly implied from the context of use. The operations of any methods and / or procedures disclosed herein do not have to be performed in the exact order disclosed, unless an operation is explicitly described as following or preceding another operation and / or where it is implicit that an operation must follow or precede another operation. Any feature of any embodiment disclosed herein can apply to any other disclosed embodiment, as appropriate. Likewise, any advantage of any embodiment described herein can apply to any other disclosed embodiment, as appropriate.

[0058] Furthermore, the following terms are used throughout the description given below:

[0059] Radio Access Node: As used herein, a “radio access node” (or equivalently “radio network node,” “radio access network node,” or “RAN node”) can be any node in a radio access network (RAN) that operates to wirelessly transmit and / or receive signals. Some examples of a radio access node include, but are not limited to, a base station (e.g., gNB in a 3GPP 5G / NR network or an enhanced or eNB in a 3GPP LTE network), base station distributed components (e.g., CU and DU), a high-power or macro base station, a low-power base station (e.g., micro, pico, femto, or home base station, or the like), an integrated access backhaul (IAB) node, a transmission point (TP), a transmission reception point (TRP), a remote radio unit (RRU or RRH), and a relay node.

[0060] Core Network Node: As used herein, a “core network node” is any type of node in a core network. Some examples of a core network node include, e.g., a Mobility Management Entity (MME), a serving gateway (SGW), a PDN Gateway (P-GW), a Policy and Charging Rules Function (PCRF), an access and mobility management function (AMF), a session management function (SMF), a user plane function (UPF), a Charging Function (CHF), a Policy Control Function (PCF), an Authentication Server Function (AUSF), a location management function (LMF), or the like.

[0061] Wireless Device: As used herein, a “wireless device” (or “WD” for short) is any type of device that is capable, configured, arranged and / or operable to communicate wirelessly with network nodes and / or other wireless devices. Communicating wirelessly can involve transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information through air. Unless otherwise noted, the term “wireless device” is used interchangeably herein with the term “user equipment” (or “UE” for short), with both of these terms having a different meaning than the term “network node”.

[0062] Radio Node: As used herein, a “radio node” can be either a “radio access node” (or equivalent term) or a “wireless device.”

[0063] Network Node: As used herein, a “network node” is any node that is either part of the radio access network (e.g., a radio access node or equivalent term) or of the core network (c.g, a core network node discussed above) of a cellular communications network. Functionally, a network node is equipment capable, configured, arranged, and / or operable to communicate directly or indirectly with a wireless device and / or with other network nodes or equipment in the cellular communications network, to enable and / or provide wireless access to the wireless device, and / or to perform other functions (e.g., administration) in the cellular communications network.

[0064] Node: As used herein, the term “node” (without prefix) can be any type of node that can in or with a wireless network (including RAN and / or core network), including a radio access node (or equivalent term), core network node, or wireless device. However, the term “node” may be limited to a particular type (e.g., radio access node, IAB node) based on its specific characteristics in any given context.

[0065] The above definitions are not meant to be exclusive. In other words, various ones of the above terms may be explained and / or described elsewhere in the present disclosure using the same or similar terminology. Nevertheless, to the extent that such other explanations and / or descriptions conflict with the above definitions, the above definitions should control.

[0066] Note that the description given herein focuses on a 3 GPP cellular communications system and, as such, 3GPP terminology or terminology similar to 3GPP terminology is generally used. However, the concepts disclosed herein are not limited to a 3 GPP system and can be applied in any system that can benefit from the concepts, principles, and / or embodiments described herein. Figure 1 shows an exemplary configuration of NR user plane (UP) and control plane (CP) protocol stacks between a UE (110), a gNodeB (gNB, e.g., base station, 120), and an access and mobility management function (AMF, 130) in a 5G core network (5GC). Physical (PHY), Medium Access Control (MAC), Radio Link Control (RLC), and Packet Data Convergence Protocol (PDCP) layers between the UE and the gNB are common to UP and CP. PDCP provides ciphering / deciphering, integrity protection, sequence numbering, reordering, and duplicate detection for both CP and UP, as well as header compression and retransmission for UP data.

[0067] On the UP side, Internet protocol (IP) packets arrive to PDCP as service data units (SDUs), and PDCP creates protocol data units (PDUs) to deliver to RLC. The Service Data Adaptation Protocol (SDAP) layer handles quality-of-service (QoS) including mapping between QoS flows and Data Radio Bearers (DRBs) and marking QoS flow identifiers (QFI) in UL and DL packets. RLC transfers PDCP PDUs to MAC through logical channels (LCH). RLC provides error detection / correction, concatenation, segmentation / reassembly, sequence numbering, reordering of data transferred to / from the upper layers. MAC provides mapping between LCHs and PHY transport channels, LCH prioritization, multiplexing into or demultiplexing from transport blocks (TBs), hybrid ARQ (HARQ) error correction, and dynamic scheduling (in gNB). PHY provides transport channel services to MAC and handles transfer over the NR radio interface, e.g., via modulation, coding, antenna mapping, and beam forming.

[0068] On the CP side, the non-access stratum (NAS) layer between UE and AMF handles UE / gNB authentication, mobility management, and security control. RRC sits below NAS in the UE but terminates in the gNB rather than the AMF. RRC controls communications between UE and gNB at the radio interface as well as the mobility of a UE between cells in the NG- RAN. RRC also broadcasts system information (SI) and performs establishment, configuration, maintenance, and release of DRBs and Signaling Radio Bearers (SRBs) and used by UEs. Additionally, RRC controls addition, modification, and release of carrier aggregation (CA) and dual -connectivity (DC) configurations for UEs and performs various security functions such as key management.

[0069] After a UE is powered ON it will be in the RRC IDLE state until an RRC connection is established with the network, at which time the UE will transition to RRC CONNECTED state e.g., where data transfer can occur). The UE returns to RRC IDLE after the connection with the network is released. In RRC IDLE state, the UE’s radio is active on a discontinuous reception (DRX) schedule configured by upper layers. During DRX active periods (also referred to as “DRX On durations”), an RRC IDLE UE receives SI broadcast in the cell where the UE is camping, performs measurements of neighbor cells to support cell reselection, and monitors a paging channel on physical DL control channel (PDCCH) for pages from 5GC via gNB. A UE in RRC IDLE state is not known to the gNB serving the cell where the UE is camping. However, NR RRC includes an RRC INACTIVE state in which a UE is known (e.g., via context) by the serving gNB.

[0070] Figure 2 shows a high-level view of an exemplary 5G network architecture, including a Next Generation Radio Access Network (NG-RAN, 299) and a 5GC (298). As shown in the figure, the NG-RAN can include gNBs (e.g., 210a,b) and ng-eNBs (e.g., 220a, b) that are connected via respective Xn interfaces. The gNBs and ng-eNBs are also connected to the 5GC via the NG interfaces, more specifically to access and mobility management function (AMFs, e.g., 230a,b) via respective NG-C interfaces and to user plane functions (UPFs, e.g., 240a, b) via respective NG-U interfaces. Moreover, the AMFs can communicate with one or more policy control functions (PCFs, e.g., 250a, b) and network exposure functions (NEFs, e.g., 260a, b).

[0071] Each of the gNBs can support the NR radio interface including frequency division duplexing (FDD), time division duplexing (TDD), or a combination thereof. In contrast, each of ng-eNBs can support the LTE radio interface but, unlike conventional LTE eNodeBs (eNBs), connect to the 5GC via the NG interface. Each of the gNBs and ng-eNBs can serve a geographic coverage area including one more cells (e.g., 211a-b, 221a-b). The gNBs and ng- eNBs can also use various directional beams to provide coverage in the respective cells. Depending on the cell in which it is located, a UE (205) can communicate with the gNB or ng- eNB serving that cell via the NR or LTE radio interface, respectively. Although Figure 2 shows gNBs and ng-eNBs separately, it is also possible that a single NG-RAN node provides both types of functionality.

[0072] Each gNB can include a central (or centralized) unit (CU or gNB-CU) and one or more distributed (or decentralized) units (DU or gNB-DU), which can be viewed as logical nodes. CUs host higher-layer protocols and perform various gNB functions such controlling the operation of DUs, which host lower-layer protocols and can include various subsets of the gNB functions. A CU connects to its associated DUs over respective Fl logical interfaces. Each of the CUs and DUs can include various circuitry needed to perform their respective functions, including processing circuitry, communication interface circuitry (e.g., for communication via Xn, NG, radio, etc. interfaces), and power supply circuitry. As briefly mentioned above, 3GPP Rel-17 specifies a 5G ProSe U2N Relay providing indirect Layer-2 and Layer-3 single-hop communication between a 5G destination network (DN) and a ProSe Remote UE, e.g. a 5G ProSe-enabled UE that is out of coverage of the network, by using direct communication. Moreover, in 3GPP Rel-19 5GProSe multi-hop U2N discovery has been studied and specified.

[0073] In general, a ProSe-enabled UE can support unicast communication via the uplink / downlink radio interface (also referred to as “Uu”) to a 3GPP RAN, such as the LTE Evolved-UTRAN (E-UTRAN) or the NG-RAN. A ProSe-enabled UE can also support unicast communication over sidelink (SL) i.e., PC5 interface. In addition to Uu and PC5 interfaces, the ProSe-enabled UEs can communicate with a ProSe network function (NF) via respective PC3 interfaces. Communication with the ProSe NF requires a UE to establish a connection with the RAN, either directly via the Uu interface or indirectly via PC5 and another UE’s Uu interface. The ProSe function provides the UE various information for network related actions, such as service authorization and provisioning of PLMN-specific information (e.g., security parameters, group IDs, group IP addresses, out-of-coverage radio resources, etc.).

[0074] In this specification, the following definitions of ProSe-enabled UEs are used: 5G ProSe U2N Relay: A 5G ProSe-enabled UE that provides functionality to support connectivity to the network for 5G ProSe Remote UE(s). In this specification 5G ProSe U2N Relay is also referred to as U2N Relay and ProSe U2N Relay and just U2N.

[0075] 5G ProSe Intermediate U2N Relay: A 5G ProSe-enabled UE that provides functionality to support connectivity to the network for 5G ProSe Remote UE(s) by using the PC5 reference point with other 5G ProSe-enabled UEs. The 5G ProSe Intermediate U2N Relay is located on the path between 5G ProSe Remote UE and 5G ProSe U2N Relay. In this specification 5G ProSe Intermediate U2N Relay is also referred to as ProSe Intermediate U2N Relay, Intermediate U2N Relay, multi-hop U2N relay and Intermediate.

[0076] 5G ProSe Remote UE: A 5G ProSe-enabled UE that communicates with a data network via zero or more 5G ProSe Intermediate U2N Relay(s) and a 5G ProSe U2N Relay. In this specification 5G ProSe Remote UE is also referred to as ProSe Remote UE and Remote UE.

[0077] Figure 3 shows three exemplary network coverage scenarios for two UEs (310, 320) and a gNB (330) serving a cell. In the full coverage scenario (left), both UEs are in the coverage of the cell, such that they both can communicate with the gNB via respective Uu interfaces and directly with each other via the PC5 interface. In the partial coverage scenario (center), only one of the UEs is in coverage of the cell, but the out-of-coverage UE can still communicate with the gNB indirectly via the PC5 interface with the in-coverage UE. In the out-of-coverage scenario, both UEs can only communicate with each other via the PC5 interface.

[0078] In general, the term “SL standalone” refers to direct communication between two SL- capable UEs (e.g., via PC5) in which source and destination are the UEs themselves. In contrast, the term “SL relay” refers to indirect communication between a network node and a remote UE via a first interface (e.g., Uu) between the network node an intermediate (or relay) UE and a second interface (e.g., PC5) between the relay UE and the remote UE. In this case the relay UE is neither the source nor the destination.

[0079] In general, an “out-of-coverage UE” is one that cannot establish a direct connection to the network and must communicate via either SL standalone or SL relay. UEs that are in coverage can be configured by the network (e.g., gNB) via RRC signaling and / or broadcast system information, either directly (via Uu interface) or indirectly (via PC5 interface and relay UE Uu interface). Out-of-coverage UEs rely on a (pre-)configuration available in their SIMs. These pre-configurations are generally static but can be updated by the network when a UE is in coverage. A “peer UE” refers to a UE that can communicate with the out-of-coverage UE via SL standalone or SL relay (in which case the peer UE is also a relay UE).

[0080] As previously mentioned 3 GPP Rel-17 includes coverage extension for SL-based communication, including U2N relay for cellular coverage extension. In U2N relay, a UE extends the network connectivity to another nearby UE by using direct communication. U2N relay functionality is fundamental for network coverage extension for public safety in remote areas, for wearable devices tethering in commercial use cases (e.g., sensors, virtual reality headsets), etc.

[0081] LTE U2N relay functionality uses a layer-3 (L3) architecture in which the relay of data packets via the PC5 interface is performed at the network layer, and UEs connected to a L3 U2N relay are transparent to the network. NR U2N relay uses two different architectures: a L3 architecture similar to LTE, and a newly defined architecture in which PC5 relaying occurs within layer 2 (L2), over the RLC sublayer.

[0082] 3GPP TR 23.752 (vl7.0.0) section 6.7 describes L2-based U2N relay functionality, which includes forwarding functionality that can relay any type of traffic over the PC5 interface between two UEs. A L2 U2N Relay UE supports connectivity to the 5GS (i.e., NG-RAN and 5GC) for other UEs that have successfully established a PC5 link to the L2 U2N Relay UE. A UE connected to a L2 U2N Relay will be seen by the network as a regular UE., as if it was directly connected to the network. This gives the network control of the connection and services but requires the definition of several new mechanisms not present or needed in the L3 architecture.

[0083] 3GPP TR 23.752 (vl7.0.0) section 6.6 describes L3 -based U2N relay functionality (also referred to as “ProSe 5G U2N Relay”) that can be used for both public safety and commercial services. A ProSe 5G U2N Relay UE supports connectivity to the 5GS (i.e., NG- RAN and 5GC) for other UEs that have successfully established a PC5 link to the ProSe 5G U2N Relay UE.

[0084] Figure 4 shows a reference architecture for 5G ProSe U2N Relay as specified in 3GPP Rel-17, enabling indirect Layer-2 and Layer-3 single-hop communication between the 5G network and Remote UEs (e.g. for UEs that are out of coverage of the network). This is called single-hop communication as the communication is direct between Remote UE and Layer-3 U2N Relay. In this architecture, a 5G ProSe Remote UE has a PC5 link to a 5G ProSe U2N Relay UE, which also has Uu connection to the NG-RAN. By this arrangement, the 5G ProSe Remote UE can communicate with the NG-RAN, the associated 5GC, and the data network.

[0085] Figure 5 shows an example scenario of multi-hop 5G ProSe U2N Relay as studied and specified in 3GPP Rel-19, enabling indirect Layer-3 multi-hop communication between the 5G network and a Remote UE (e.g. for UEs that are out of coverage of the network). As previously explained, in this architecture a new UE has been specified, which is named 5G ProSe Intermediate U2N Relay. In this example, the 5G ProSe Remote UE has a PC5 link to the 5G ProSe Intermediate U2N Relay, which also has a PC5 link to an 5G ProSe U2N Relay UE, which also has Uu connection to the NG-RAN. By this arrangement, the 5G ProSe Remote UE can communicate with the NG-RAN, the coupled 5GC, and the data network. There may be one or multiple 5G ProSe Intermediate U2N Relays between the 5G ProSe Remote UE and the 5G ProSe U2N Relay. In this figure, the 5G ProSe Layer-3 U2N Relay may be in the HPLMN or a Visiting Public Land Mobile Network (VPLMN).

[0086] Typically, 5G ProSe UEs initially discover each other via a 5G ProSe Discovery procedure, then trigger ProSe Communication (aka PC5 link) establishment for each other.

[0087] Each 5G ProSe discovery includes a specific code, a Relay Service Code (RSC) in the case of ProSe U2N relay. There is a one-to-one association between codes and security materials, e.g., each RSC is associated with a corresponding set of security materials including Code-Sending Security Parameters and Code-Receiving Security Parameters.

[0088] Support for single-hop relay discovery, selection, authorization, connection establishment and data transfer for ProSe U2U Relay were addressed in Rel-17 and / or Rel-18. As previously explained clause 6.3.2.3.2 of 3GPP Technical Specification (TS) 23.304 (V19.1.0) and clause 6.1.3.2.2.1 of 3GPP TS 33.503 (vl8.4.0) specify an announcing 5GProSe Layer-3 U2N Relay and a monitoring 5G ProSe Remote UE performing protected (restricted) relay discovery. The information included by the original announcing 5G ProSe U2N Relay, e.g., Relay Service Code (RSC), user info of the announcing 5G ProSe U2N

[0089] Relay, accumulated Quality of Service (QoS) is protected by the relay discovery security material as specified in clause 6.1.3.2.2.1 of 3GPP TS 33.503 (vl 8.4.0).

[0090] Security mechanisms in 5G ProSe multi-hop U2N relay discovery have been studied and specified in 3GPP Rel-19. 3GPP Technical Report (TR) 33.743 (VO.3.0) shows different security mechanisms for discovery messages in multi-hop U2N relaying, including ProSe multi-hop U2N relay (both Layer-2 and Layer-3 Relays).

[0091] As previously explained, solutions for the following two models of relay discovery specified in 3GPP TR 33.743 (VO.3.0) are referred to herein:

[0092] Model A: announcement sent by announcing 5G ProSe U2N and received by monitoring 5G ProSe Remote UE; and

[0093] Model B: discovery solicitation sent by Discoverer 5G ProSe Remote UE and received by Discoveree 5G ProSe U2N and discovery response sent by Discoveree 5G ProSe U2N and received by Discoverer 5G ProSe Remote UE.

[0094] Figure 6 shows signaling for a current relay discovery procedure, applicable in Model A, supporting multi-hop U2N relay as described in 3GPP TR 33.743 (V0.3.0), clause 6.2 (referred to as Solution #2). In other words, Figure 6 shows signaling for 5G ProSe intermediate U2N discovery for Model A also referred to as 5G ProSe multi-hop U2N relay discovery for Model A in 3GPP TS 23.304 (vl9.1.0). An announcing 5G ProSe U2N Relay and a monitoring 5G ProSe Remote UE perform protected relay discovery as specified in 3GPP 23.304 (V19.1.0) clause 6.3.2.3.2 and 3GPP TS 33.503 (vl 8.4.0) clause 6.1.3.2.2.1. The announcing

[0095] 5G ProSe U2N Relay sends an Announcement message and protects it with relay discovery security material as specified in these clauses. As previously explained the announcing 5G ProSe U2N Relay may also include in or with this message information such as Relay Service Code (RSC), user info of the announcing 5G ProSe U2N Relay, accumulated Quality of Service (QoS), "hop info", such as maximum hop limit, initial value of hop counter, visited route information (e.g., list of visited Relay IDs), etc. The announcing 5G ProSe U2N Relay can protect the information by relay discovery security material.

[0096] The Intermediate U2N Relay(s) can relay and forward the discovery Announcement message sent by the announcing 5G ProSe U2N Relay and can also insert and / or update information (e.g., hop count, route information, etc.) needed to support multi-hop U2N relay in the forwarded messages.

[0097] To protect the integrity and / or confidentiality of the information inserted and / or updated each Intermediate U2N Relay also needs to obtain a set of relay discovery security material from its own Home Public Land Mobile Network (HPLMN), referred to herein as “intermediate relay discovery security material”. As such, the forwarded relay discovery Announcement message contains both the original discovery Announcement message protected by the relay discovery security material associated with the announcing U2N relay and the inserted and / or updated information protected by the intermediate relay discovery security material associated with the Intermediate U2N Relay.

[0098] Figure 7 shows signaling for a current relay discovery procedure, applicable for Model B, supporting multi-hop U2N relay as described in 3GPP Technical Report (TR) 33.743 (VO.3.0), clause 6.3 (referred to as Solution #3). In other words, Figure 7 shows signaling for 5G ProSe intermediate U2N discovery for Model B also referred to as 5G ProSe multi-hop U2N relay discovery for Model B in 3GPP TS 23.304 (vl9.1.0) As shown in Figure 7, a Discoveree 5G ProSe U2N Relay and a Discoverer 5G ProSe Remote UE perform protected relay discovery as specified in 3GPP 23.304 (V19.1.0) clause 6.3.2.3.3 and 3GPP TS 33.503 (vl8.4.0) clause 6.1.3.2.2.2. With respect to the previous statement, clause 6.3.2.3.3 of TS 23.304 (V19.1.0) and clause 6.1.3.2.2.2 of TS 33.503 (vl8.4.0) uses the terms "Discoveree UE" and "Discoverer UE" and in the context of the Rel-19 study these roles are assumed to be taken by the 5G ProSe Layer-3 U2N Relay and the Remote UE respectively. The information included by the original sending UE (i.e., the Remote UE and the 5G ProSe U2N) is protected by the relay discovery security material. The Intermediate U2N Relay(s) can relay and forward the Discovery Solicitation / Response messages sent by the discoverer 5G ProSe Remote UE and the Discoveree 5G ProSe U2N Relay, respectively. The intermediate U2N can also insert other information (e.g., by including its own User Infor ID in the path) or update other information (such as hop info) needed to support multi-hop U2N relay in the forwarded messages.

[0099] Current procedure for relay discovery are specified in 3GPP TS 33.503 for Model A and Model B

[0100] Figure 8 shows signaling for current security procedure for restricted 5G ProSe Direct Discovery Model A as specified in clause 6.1.3.2.2.1 of TS 33.503 (vl 8.4.0).

[0101] *** Start text from clause 6.1.3.2.2.1 of 3GPP TS 33.503 (v!8.4.0) *** NOTE 1 : When the user-plane based security procedure for the UE-to-Network Relay is used, the 5G PKMF takes the role of the 5G DDNMF as described in clause 6.3.3.2 of the present document.

[0102] Steps 1-4 refer to an Announcing UE:

[0103] 1. Announcing UE sends a Discovery Request message containing the Restricted ProSe Application User ID (RPAUID) to the 5G DDNMF in its HPLMN in order to get the ProSe Code to announce and to get the associated security material. In addition, the Announcing UE shall include its PC5 UE security capability that contains the list of supported ciphering algorithms by the UE in the Discovery Request message.

[0104] For 5G ProSe UE-to-Network Relay discovery, the 5G ProSe UE-to-Network Relay plays the role of the Announcing UE and sends a Relay Discovery Key Request instead of a Discovery Request. The Relay Discovery Key Request message includes the Relay Service Code (RSC) and the 5G ProSe UE-to-Network Relay's PC5 security capability.

[0105] 2. The 5G DDNMF may check for the announce authorization with the ProSe Application Server.

[0106] For 5G ProSe UE-to-Network Relay discovery, the 5G DDNMF may check with the UDM whether the UE-to-Network relay is authorized to announce UE-to-Network relay discovery message.

[0107] 3. If the Announcing UE is roaming, the 5G DDNMF s in the HPLMN and VPLMN of the Announcing UE exchange Announce Auth.

[0108] For 5G ProSe UE-to-Network Relay discovery,

[0109] Npkmf Discovery AnnounceAuthorize service operation is used to obtain the authorization from the 5G PKMF for announcing in the PLMN.

[0110] 4. The 5G DDNMF in the HPLMN of the Announcing UE returns the ProSe Restricted Code and the corresponding Code-Sending Security Parameters, along with the CURRENT TIME and MAX OFFSET parameters. The Code-Sending Security Parameters provide the necessary information for the Announcing UE to protect the transmission of the ProSe Restricted Code and are stored with the ProSe Restricted Code. The Announcing UE takes the same actions with CURRENT TIME and MAX OFFSET as described for the Announcing UE in step 4 of clause 6.1.3.1 of the present document. The 5G DDNMF in the HPLMN of the Announcing UE shall include the chosen PC5 ciphering algorithm in the Discovery Response message. The 5G DDNMF determines the chosen PC5 ciphering algorithm based on the ProSe Restricted Code and the received PC5 UE security capability in step 1. The UE stores the chosen PC5 ciphering algorithm together with the ProSe Restricted Code.

[0111] In addition, the 5G DDNMF in the HPLMN of the Announcing UE may associate the ProSe Restricted Code with the PC5 security policies and include the PC5 security policies in the Discovery Response message.

[0112] For 5G ProSe UE-to-Network Relay discovery, a Relay Discovery Key Response is used instead of the Discovery Response, and the RSC is used instead of the ProSe Restricted Code.

[0113] NOTE 2: 5G DDNMF may get the PC5 security policies in different ways (e.g. from

[0114] PCF, from ProSe Application Server, or based on local configuration).

[0115] Steps 5-10 refer to a Monitoring UE:

[0116] 5. The Monitoring UE sends a Discovery Request message containing the RPAUID and its PC5 UE security capability to the 5G DDNMF in its HPLMN in order to be allowed to monitor for one or more Restricted ProSe Application User IDs.

[0117] For 5G ProSe UE-to-Network Relay discovery, the 5G ProSe Remote UE plays the role of the Monitoring UE and sends a Relay Discovery Key Request instead of the Discovery Request. The Relay Discovery Key Request message includes the RSC and the 5G ProSe Remote UE's PC5 security capability. The Remote UE may provide a list of PLMN IDs in which the UE is authorized to use a 5G ProSe UE-to-Network Relay, in the Relay Discovery Key Request.

[0118] 6. The 5G DDNMF in the HPLMN of the Monitoring UE sends an authorization request to the ProSe Application Server. If, based on the permission settings, the RPAUID is allowed to discover at least one of the Target RPAUIDs contained in the Application Level Container, the ProSe Application Server returns an authorization response.

[0119] For 5G ProSe UE-to-Network Relay discovery, the 5G DDNMF of the Remote UE may check with the UDM whether the Remote UE is authorized to monitor UE-to- Network relay discovery. 7. If the Discovery Request is authorized, the 5G DDNMF in the HPLMN of the Monitoring UE contacts the 5G DDNMF in the HPLMN of the Announcing UE by sending a Monitor Request message, as specified in clause 6.3 of TS 23.304 [2], including the PC5 UE security capability received in step 5.

[0120] For 5G ProSe UE-to-Network Relay Discovery, Relay Discovery Key Request and RSC are used instead of Discovery Request and RPAUID. The 5G DDNMF of the remote UE discovers 5G DDNMF(s) of the potential 5G ProSe UE-to-Network relay(s) supporting the RSC based on HPLMN IDs of the potential 5G ProSe UE-to- Network relay(s) mapping to the RSC. Npkmf_Discovery_MonitorKey service operation is used to obtain the discovery key from the 5G PKMF for monitoring in the PLMN.

[0121] NOTE 2a: 5G DDNMF may get the HPLMN IDs of the potential 5G ProSe UE-to- Network relays in different ways (e.g. from PCF, or based on local configuration).

[0122] 8. The 5G DDNMF in the HPLMN of the Announcing UE may exchange authorization messages with the ProSe Application Server.

[0123] For 5G ProSe UE-to-Network Relay discovery, this step is skipped.

[0124] 9. If the PC5 UE security capability in step 5 includes the chosen PC5 ciphering algorithm, the 5G DDNMF in the HPLMN of the Announcing UE responds to the 5G DDNMF in the HPLMN of the Monitoring UE with a Monitor Response message including the ProSe Restricted Code, the corresponding Code-Receiving Security Parameters, an optional Discovery User Integrity Key (DUIK), and the chosen PC5 ciphering algorithm (based on the information / keys stored in step 4). The Code- Receiving Security Parameters provide the information needed by the Monitoring UE to undo the protection applied by the Announcing UE. The DUIK shall be included as a separate parameter if the Code-Receiving Security Parameters indicate that the Monitoring UE use Match Reports for MIC checking. The 5G DDNMF in the HPLMN of the Monitoring UE stores the ProSe Restricted Code and the Discovery User Integrity Key (if it received one outside of the Code-Receiving Security Parameters). For 5G ProSe UE-to-Network Relay discovery, a Relay Discovery Key Response is used instead of the Monitor Response, and the RSC and the HPLMN ID of the 5G ProSe UE-to-Network Relay (i.e. the Announcing UE) are used instead of the ProSe Restricted Code. The HPLMN ID of the 5G ProSe UE-to-Network Relay is used to identify the discovery security materials. Npkmf_Discovery_MonitorKey service operation is used to obtain the discovery key from the 5G PKMF for monitoring in the PLMN.

[0125] The 5G DDNMF in the HPLMN of the Announcing UE may send the PC5 security policies associated with the ProSe Restricted Code to the 5G DDNMF in the HPLMN of the Monitoring UE.

[0126] NOTE 3 : For 5G ProSe Direct Discovery, there are two possible configurations for integrity checking, namely, MIC checked by the 5 G DDNMF of the Monitoring UE, and MIC checked at the Monitoring UE side. Which configuration to use is decided by the 5G DDNMF, which assigns the monitored ProSe Restricted Code and signals the Monitoring UE in the Code-Receiving Security Parameters.

[0127] For 5G ProSe UE-to-Network Relay discovery, MIC checking is performed only at the Remote UE and the 5G DDNMF of the Remote UE does not need to configure integrity checking for UE-to-Network Relay discovery.

[0128] NOTE 4: The chosen PC5 ciphering algorithm is associated with the ProSe Restricted

[0129] Code.

[0130] 10. The 5G DDNMF in the HPLMN of the Monitoring UE returns the Discovery Filter and the Code-Receiving Security Parameters, along with the CURRENT TIME and MAX OFFSET parameters and the chosen PC5 ciphering algorithm. The Monitoring UE takes the same actions with CURRENT TIME and MAX OFFSET as described for the Monitoring UE in step 9 of clause 6.1.3.1 of the present document. The UE stores the Discovery Filter, Code-Receiving Security Parameters, and the chosen PC5 ciphering algorithm together with the ProSe Restricted Code.

[0131] For 5G ProSe UE-to-Network Relay discovery, a Relay Discovery Key Response is returned instead of the Discovery Response, and the RSC is included instead of the ProSe Restricted Code. The response message contains the discovery security materials and the HPLMN ID as contained in step 9. The Relay Discovery Key Response includes multiple sets of discovery security materials and the associated HPLMN IDs of the potential relays if multiple 5GDDNMFs / PKMFs of the potential relays supporting the RSC are discovered in step 7.

[0132] If the 5G DDNMF in the HPLMN of the Monitoring UE receives the PC5 security policies associated with the ProSe Restricted Code in step 9, the Monitoring UE's 5G DDNMF forwards the PC5 security policies to the Monitoring UE.

[0133] Steps 11 and 12 occur over PC5:

[0134] 11. The UE starts announcing, if the UTC-based counter provided by the system associated with the discovery slot is within the MAX OFFSET of the Announcing UE's ProSe clock and if the Validity Timer has not expired. The UE forms the discovery message and protects it. The four least significant bits of UTC-based counter are transmitted along with the protected discovery message.

[0135] For 5G ProSe UE-to-Network Relay discovery, RSC is used instead of ProSe Response Code and the announcing message also includes the HPLMN ID in cleartext to identify the discovery security materials.

[0136] 12. The Monitoring UE listens for a discovery message that satisfies its Discovery Filter if the UTC-based counter associated with that discovery slot is within the

[0137] MAX OFFSET of the monitoring UE's ProSe clock. In order to find such a matching message, it processes the message. If the Monitoring UE was not asked to send Match Reports for MIC checking, it stops at this step from a security perspective. Otherwise, it proceeds to step 13.

[0138] For 5G ProSe UE-to-Network Relay discovery, the 5G ProSe remote UE decides the discovery security materials to process the discovery message based on the HPLMN ID in the discovery message.

[0139] NOTE 5: The UE checking the integrity of the discovery message on its own does not prevent the UE from sending a Match Report due to requirements in TS 23.304 [2], If such a Match Report is sent, then there is no security functionality involved.

[0140] Steps 13-16 refer to a Monitoring UE that has encountered a match:

[0141] NOTE 6: For 5G ProSe UE-to-Network Relay discovery, the steps 13-16 are skipped. 13. If the UE has either not had the 5G DDNMF check the MIC for the discovered ProSe Restricted Code previously or the 5G DDNMF has checked a MIC for the ProSe Restricted Code and the associated Match Report refresh timer (see step 15 for details of this timer) has expired, or as required based on the procedure specified in TS 23.304 [2], then the Monitoring UE sends a Match Report message to the 5G DDNMF in the HPLMN of the Monitoring UE. The Match Report contains the UTC- based counter value with four least significant bits equal to four least significant bits received along with discovery message and nearest to the Monitoring UE's UTC- based counter associated with the discovery slot where it heard the announcement, and other discovery message parameters including the ProSe Restricted Code and MIC. The 5G DDNMF checks the MIC.

[0142] 14. The 5G DDNMF in the HPLMN of the Monitoring UE may exchange an Auth Req / Auth Resp with the ProSe Application Server to ensure that Monitoring UE is authorized to discover the Announcing UE.

[0143] 15. The 5G DDNMF in the HPLMN of the Monitoring UE returns to the Monitoring UE an acknowledgement that the integrity check passed. It also provides the CURRENT TIME parameter, by which the UE (re)sets its ProSe clock. The 5G DDNMF in the HPLMN of the Monitoring UE included the Match Report refresh timer in the message to the Monitoring UE. The Match Report refresh timer indicates how long the UE will wait before sending a new Match Report for the ProSe Restricted Code.

[0144] 16. The 5G DDNMF in the HPLMN of the Monitoring UE may send a Match Report Info message to the 5G DDNMF in the HPLMN of the Announcing UE.

[0145] *** End text from clause 6.1.3.2.2.1 of 3GPP TS 33.503 (vl8.4.0) *** Figure 9 shows signaling for current security procedure for restricted 5G ProSe Direct

[0146] Discovery Model B as specified in clause 6.1.3.2.2.2 of TS 33.503 (vl8.4.0).

[0147] *** Start text from clause 6.1.3.2.2.2 of 3GPP TS 33.503 (vl8.4.0) ***

[0148] NOTE 1 : When the user-plane based security procedure for the UE-to-Network Relay is used, the 5G PKMF takes the role of the 5G DDNMF as described in clause 6.3.3.2 of the present document.

[0149] Steps 1-4 refer to a Discoveree UE: Discoveree UE sends a Discovery Request message containing the RPAUID to the 5G DDNMF in its HPLMN in order to get Discovery Query Filter(s) to monitor a query, the ProSe Response Code to announce and associated security materials. The command indicates that this is for ProSe Response (Model B) operation, i.e. for a Discoveree UE. In addition, the Discoveree UE shall include its PC5 UE security capability that contains the list of supported ciphering algorithms by the UE in the Discovery Request message.

[0150] For 5G ProSe UE-to-Network Relay discovery, the 5G ProSe UE-to-Network Relay plays the role of the Discoveree UE and sends a Relay Discovery Key Request instead of a Discovery Request. The Relay Discovery Key Request message includes the Relay Service Code (RSC) and the 5G ProSe UE-to-Network Relay's PC5 security capability. The 5G DDNMF may check for the announce authorization with the ProSe Application Server depending on 5G DDNMF configuration.

[0151] For 5G ProSe UE-to-Network Relay discovery, the 5G DDNMF may check with the UDM whether the UE-to-Network relay is authorized to announce UE-to-Network relay discovery. The 5G DDNMFs in the HPLMN and VPLMN of the Discoveree UE exchange Announce Auth. Messages. If the Discoveree UE is not roaming, these steps do not take place.

[0152] For 5G ProSe UE-to-Network Relay discovery,

[0153] Npkmf Discovery AnnounceAuthorize service operation is used to obtain the authorization from the 5G PKMF for announcing in the PLMN. The 5G DDNMF in the HPLMN of the Discoveree UE returns the ProSe Response Code and the Code-Sending Security Parameters, Discovery Query Filter(s), Code- Receiving Security Parameters corresponding to each discovery filter along with the CURRENT TIME and MAX OFFSET parameters and the chosen PC5 ciphering algorithm. The Code-Sending Security Parameters provide the necessary information for the Discoveree UE to protect the transmission of the ProSe Response Code and are stored with the ProSe Response Code. The Code-Receiving Security Parameters provide the information needed by the Discoveree UE to undo the protection applied to the ProSe Query Code by the Discoverer UE. The Code-Receiving Security Parameters indicate a Match Report will not be used for MIC checking. The UE stores each Discovery Filter with its associated Code-Receiving Security Parameters. The Discoveree UE takes the same actions with CURRENT TIME and MAX OFFSET as described for the Announcing UE in step 4 of clause 6.1.3.1 of the present document. The 5G DDNMF in the HPLMN of the Discoveree UE shall include the chosen PC5 ciphering algorithm in the Discovery Response message. The 5G DDNMF determines the chosen PC5 ciphering algorithm based on the ProSe Response Code and the received PC5 UE security capability in step 1. The UE stores the chosen PC5 ciphering algorithm together with the ProSe Response Code.

[0154] In addition, the 5G DDNMF in the HPLMN of the Discoveree UE may associate the ProSe Response Code with the PC5 security policies and include the PC5 security policies in the Discovery Response message.

[0155] For 5G ProSe UE-to-Network Relay discovery, a Relay Discovery Key Response is used instead of the Discovery Response, and the RSC is used instead of ProSe Query Code and ProSe Response Code.

[0156] NOTE 2: 5G DDNMF may get the PC5 security policies in different ways (e.g. from

[0157] PCF, from ProSe Application Server, or based on local configuration).

[0158] Steps 5-10 refer to a Discoverer UE:

[0159] 5. The Discoverer UE sends a Discovery Request message containing the RPAUID and its PC5 UE security capability to the 5G DDNMF in its HPLMN in order to be allowed to discover one or more Restricted ProSe Application User IDs.

[0160] For 5G ProSe UE-to-Network Relay discovery, the 5G ProSe Remote UE plays the role of the Discoverer UE and sends a Relay Discovery Key Request instead of the Discovery Request. The Relay Discovery Key Request message includes the RSC and the 5G ProSe Remote UE's PC5 security capabilities. The Remote UE may provide a list of PLMN IDs in which the UE is authorized to use a 5G ProSe UE-to-Network Relay, in the Relay Discovery Key Request.

[0161] 6. The 5G DDNMF in the HPLMN of the Discoverer UE sends an authorization request to the ProSe Application Server. If the RPAUID is allowed to discover at least one of the Target RPAUIDs contained in the Application Level Container, the ProSe Application Server returns an authorization response.

[0162] For 5G ProSe UE-to-Network Relay discovery, the 5G DDNMF of the Remote UE may check with the UDM whether the Remote LE is authorized to monitor LE-to- Network relay discovery.

[0163] 7. If the Discovery Request is authorized, the 5G DDNMF in the HPLMN of the Discoverer UE contacts the 5G DDNMF in the HPLMN of the Discoveree LE by sending a Discovery Request message, as specified in clause 6.3 of TS 23.304 [2], including the PC5 LE security capability in step 5.

[0164] For 5G ProSe UE-to-Network Relay Discovery, Relay Discovery Key Request and RSC are used instead of Discovery Request and RPAUID. The 5G DDNMF of the remote UE discovers 5G DDNMF(s) of the potential 5G ProSe UE-to-Network relay(s) supporting the RSC based on HPLMN IDs of the potential 5G ProSe UE-to- Network relay(s) mapping to the RSC. Npkmf_Discovery_DiscoveryKey service operation is used to obtain the discovery key from the 5G PKMF for a discoverer LE in the PLMN.

[0165] NOTE 2a: 5G DDNMF may get the HPLMN IDs of the potential 5G ProSe UE-to-

[0166] Network relays in different ways (e.g. from PCF, or based on local configuration).

[0167] 8. The 5G DDNMF in the HPLMN of the Discoveree LE may exchange authorization messages with the ProSe Application Server.

[0168] For 5G ProSe UE-to-Network Relay discovery, this step is skipped.

[0169] 9. If the PC5 LE security capability in step 5 includes the chosen PC5 ciphering algorithm, the 5G DDNMF in the HPLMN of the Discoveree LE responds to the 5G DDNMF in the HPLMN of the Discoverer LE with a Discovery Response message including the ProSe Query Code(s) and their associated Code-Sending Security Parameters, ProSe Response Code and its associated Code-Receiving Security Parameters, an optional Discovery User Integrity Key (DUIK) for the ProSe Response Code, and a chosen PC5 ciphering algorithm. The Code-Receiving Security Parameters provide the information needed by the Discoverer LE to undo the protection applied by the Discoveree LE. The DUIK shall be included as a separate parameter if the Code-Receiving Security Parameters indicate that the Discoverer UE use Match Reports for MIC checking. The 5G DDNMF in the HPLMN of the Discoverer UE stores the ProSe Response Code and the Discovery User Integrity Key (if it received one outside of the Code-Receiving Security Parameters). The Code- Sending Security Parameters provide the information needed by the Discoverer UE to protect the ProSe Query Code.

[0170] The 5G DDNMF in the HPLMN of the Discoveree UE may send the PC5 security policies associated with the ProSe Response Code to the 5G DDNMF in the HPLMN of the Discoverer UE.

[0171] For 5G ProSe UE-to-Network Relay discovery, a Relay Discovery Key Response is used instead of the Discovery Response, and the RSC and the HPLMN ID of the 5G ProSe UE-to-Network Relay (i.e. the Discoveree UE) are used instead of ProSe Query Code and ProSe Response Code. The HPLMN ID of the 5G ProSe UE-to- Network Relay is used to identify the discovery security materials.

[0172] Npkmf Discovery DiscoveryKey service operation is used to obtain the discovery key from the 5G PKMF for a discoverer UE in the PLMN.

[0173] NOTE 3: For 5G ProSe Direct Discovery, there are two possible configurations for integrity checking, namely, MIC checked by the 5G DDNMF of the Discoverer UE, and MIC checked at the Discoverer UE side; this is decided by the 5G DDNMF that assigns the ProSe Restricted Code, and signals the Discoverer UE in the Code-Receiving Security Parameters.

[0174] For 5G ProSe UE-to-Network Relay discovery, MIC checking is performed only at the Remote UE and the 5G DDNMF of the Remote UE does not need to configure integrity checking for UE-to-Network Relay discovery.

[0175] NOTE 4: The chosen PC5 ciphering algorithm is associated with the ProSe Response

[0176] Code.

[0177] 10. The 5G DDNMFs in the HPLMN and VPLMN of the Discoverer UE exchange Announce Auth. messages. If the Discoverer UE is not roaming, these steps do not take place. For 5G ProSe UE-to-Network Relay discovery,

[0178] Npkmf Discovery AnnounceAuthorize service operation is used to obtain the authorization from the 5G PKMF for discovering in the PLMN.

[0179] 11. The 5G DDNMF in the HPLMN of the Discoverer UE returns the Discovery Response Filter and the Code-Receiving Security Parameters, the ProSe Query Code, the Code-Sending Security Parameters along with the CURRENT TIME and MAX OFFSET parameters and the chosen PC5 ciphering algorithm. The Discoverer UE takes the same actions with CURRENT TIME and MAX OFFSET as described for the Monitoring UE in step 9 of clause 6.1.3.1 of the present document. The UE stores the Discovery Response Filter and its Code-Receiving Security Parameters and the ProSe Query Code and its Code-Sending Security Parameters, and the chosen PC5 ciphering algorithm together with the ProSe Response Code.

[0180] If the 5G DDNMF in the HPLMN of the Discoverer UE receives the PC 5 security policies associated with the ProSe Response Code in step 9, the Discoverer UE's 5G DDNMF forwards the PC5 security policies to the Discoverer UE.

[0181] For 5G ProSe UE-to-Network Relay discovery, a Relay Discovery Key Response is used instead of the Discovery Response, and the RSC is used instead of the ProSe Restricted Code. The response message contains the discovery security materials and the HPLMN ID as contained in step 9. The Relay Discovery Key Response includes multiple sets of discovery security materials and the associated HPLMN IDs of the potential relays if multiple 5G DDNMFs / PKMFs of the potential relays supporting the RSC are discovered in step 7.

[0182] Steps 12 to 15 occur over PC5:

[0183] 12. The Discoverer UE sends the ProSe Query Code and also listens for a response message if the UTC-based counter provided by the system associated with the discovery slot is within the MAX OFFSET of the Discoverer UE's ProSe clock and if the Validity Timer has not expired. The Discoverer UE forms the discovery message and protects it. The four least significant bits of UTC-based counter are transmitted along with the protected discovery message.

[0184] For 5G ProSe UE-to-Network Relay discovery, RSC is used instead of ProSe Query

[0185] Code. 13. The Discoveree UE listens for a discovery message that satisfies its Discovery Filter if the UTC-based counter associated with that discovery slot is within the

[0186] MAX OFFSET of the Discoveree UE's ProSe clock. In order to find such a matching message, it processes the message.

[0187] NOTE 5: Match Reports are not used for the MIC checking of ProSe Query Codes.

[0188] 14. The Discoveree UE sends the ProSe Response Code associated with the discovered ProSe Query Code. The Discoveree UE forms the discovery message and protects it. The four least significant bits of UTC-based counter are transmitted along with the protected discovery message.

[0189] For 5G ProSe UE-to-Network Relay discovery, RSC is used instead of ProSe Response Code and the discovery message also includes the HPLMN ID in cleartext to identify the discovery security materials.

[0190] 15. The Discoverer UE listens for a discovery message that satisfies its Discovery Filter. In order to find such a matching message, it processes the message. If the Discoverer UE was not asked to send Match Reports for MIC checking, it stops at this step from a security perspective. Otherwise, it proceeds to step 16.

[0191] For 5G ProSe UE-to-Network Relay discovery, the 5G ProSe remote UE decides the discovery security materials to process the discovery message based on the HPLMN ID in the discovery message.

[0192] NOTE 6: The UE checking the integrity of the discovery message on its own does not prevent the UE from sending a Match Report due to requirements in TS 23.304 [2], If such a Match Report is sent, then there is no security functionality involved.

[0193] NOTE 7: The security keys in the Code-Sending Security Parameters of Discoverer

[0194] UE and the security keys in the Code-Sending Security Parameters of Discoveree UE need to be generated independently and randomly.

[0195] Steps 16-19 refer to a Discoverer UE that has encountered a match:

[0196] NOTE 8: For 5G ProSe UE-to-Network Relay discovery, the steps 16-19 are skipped.

[0197] 16. If the Discoverer UE has either not had the 5G DDNMF check the MIC for the discovered ProSe Response Code previously or the 5G DDNMF has checked a MIC for the ProSe Response Code and the associated Match Report refresh timer (see step 18 for details of this timer) has expired, or as required based on the procedure specified in TS 23.304 [2], then the Discoverer UE sends a Match Report message to the 5G DDNMF in the HPLMN of the Discoverer UE. The Match Report contains the UTC-based counter value with four least significant bits equal to four least significant bits received along with discovery message and nearest to the Discoverer UE's UTC- based counter associated with the discovery slot where it heard the announcement, and other discovery message parameters including the ProSe Response Code and MIC. The 5G DDNMF checks the MIC.

[0198] 17. The 5G DDNMF in the HPLMN of the Discoverer UE may exchange an Auth Req / Auth Resp with the ProSe Application Server to ensure that Discoverer UE is authorized to discover the Discoveree UE.

[0199] 18. The 5G DDNMF in the HPLMN of the Discoverer UE returns to the Discoverer UE an acknowledgement that the integrity check passed. It also provides the CURRENT TIME parameter, by which the UE (re)sets its ProSe clock. The 5G DDNMF in the HPLMN of the Discoverer UE include the Match Report refresh timer in the message to the Discoverer UE. The Match Report refresh timer indicates how long the UE will wait before sending a new Match Report for the ProSe Response Code.

[0200] 19. The 5G DDNMF in the HPLMN of the Discoverer UE may send a Match Report Info message to the 5G DDNMF in the HPLMN of the Discoveree UE.

[0201] *** End text from clause 6.1.3.2.2.2 of 3GPP TS 33.503 (vl8.4.0) ***

[0202] To protect the integrity and / or confidentiality of the updated and / or inserted information, each Intermediate U2N Relay also needs to obtain a set of relay discovery security material from its own HPLMN, i.e., the “intermediate relay discovery security material” discussed above. As such, the forwarded Discovery Solicitation / Response messages contain both the original discovery message protected by the relay discovery security material associated with the message source and the inserted / updated information protected by the intermediate relay discovery security material associated with the Intermediate U2N Relay.

[0203] As previously explained, there currently exist certain challenges. The discovery messages, such as the discovery Announcement messages and / or the Discovery Solicitation / Response messages forwarded by a ProSe Intermediate U2N Relay may contain both an original relay discovery announcement message protected by the relay discovery security material as well as additional information inserted / updated by the ProSe Intermediate U2N Relay protected by the intermediate relay discovery security material associated with the ProSe Intermediate U2N Relay. The ProSe Intermediate U2N Relay may for example add its own User Info ID in the path, and / or update hop information, as needed to support multi-hop U2N relaying in the forwarded messages. The forwarded relay discovery message may thus contain both the original relay discovery announcement message protected by the relay discovery security material associated with a ProSe U2N Relay (e.g., an announcing U2N relay or Discoveree U2N relay depending on use case) as well as the additional information (e.g., identifiers, hop info) protected by the intermediate relay discovery security material associated with the ProSe Intermediate U2N Relay. It is to be understood that that the discovery security material of the ProSe Intermediate U2N Relay is different from the relay discovery security material associated with a U2N relay.

[0204] A ProSe Intermediate U2N Relay may belong to a HPLMN different than the HPLMN of the ProSe Remote UE, the ProSe U2N Relay or another 5G ProSe Intermediate U2N Relay, on the same path. In other words, each node in the path from the Remote UE to the U2N relay, including the Remote UE, the U2N relay and the set of intermediate U2N relays, may belong to a HPLMN which is in general different from other nodes.

[0205] ProSe Intermediate U2N Relays belonging to different HPLMNs will use different discovery security materials allocated by respective HPLMN.

[0206] Currently, it is not feasible for the receiving UE e.g. the 5G ProSe Intermediate U2N Relay or the ProSe Remote UE in Model A or the 5G ProSe Intermediate U2N relay, the 5G ProSe U2N relay or the Remote UE in Model B) to identify which discovery security materials that has been used by the source ProSe Intermediate U2N Relay for protection of the additional information.

[0207] In addition, it is currently not specified how the intermediate relay discovery security material associated with the ProSe Intermediate U2N Relay may be requested by the UE from the 5G PKMF or 5G DDNMF.

[0208] Embodiments of the present disclosure address these problems, issues, and / or difficulties by providing, enabling and facilitating solutions for the receiving UE (e.g. the 5G ProSe Intermediate U2N Relay or the ProSe Remote UE in Model A or the 5G ProSe Intermediate U2N relay, the 5G ProSe U2N relay or the Remote UE in Model B) to identify which discovery security materials have been used by the source 5G ProSe Intermediate U2N Relay for protection of the additional information and solutions for the involved UE's to request the intermediate relay discovery security material associated with the Intermediate U2N Relay from the 5G PKMF or 5G DDNMF.

[0209] Certain aspects of the disclosure and their embodiments may provide solutions to these or other challenges. In some embodiments, a 5G ProSe Intermediate U2N Relay may include the identification (ID) of its HPLMN, i.e., a HPLMN ID in clear text over PC5 together with the protected additional information protected by the intermediate relay discovery security material associated with the Intermediate U2N Relay. In this manner embodiments facilitate a receiving UE distinguishing the intermediate relay discovery security material associated with the Intermediate U2N Relay belonging to a HPLMN different from the HPLMN of the receiving UE.

[0210] Figure 10 shows signaling for a relay discovery procedure, applicable in Model A, supporting multi-hop U2N relay according to some embodiments of the present disclosure.

[0211] The procedure is between an Announcing U2N Relay (1010), a first Intermediate U2N Relay (1020), a second Intermediate U2N Relay (1030), and a Monitoring Remote UE (1040). Although the operations shown in Figure 10 are given numerical labels, this is intended to facilitate explanation rather than to require or imply any specific operational order, unless expressly stated otherwise.

[0212] In operation 0a, the announcing U2N is provisioned with the relay discovery security materials from its HPLMN as acting as Announcing UE specified in clause 3GPP TS 33.503 (vl 8.4.0) clause 6.1.3.2.2.1. Also, each of the intermediate 5G ProSe U2N(s) and the remote UE are provisioned with the relay discovery security materials (associated with announcing U2N) acting as Monitoring UE as specified in 3GPP TS 33.503 (vl 8.4.0) clause 6.1.3.2.2.1. For example, the intermediate U2N Relays need to be provisioned with Announcing U2N relay discovery security material to understand the RSC being announced by the Announcing U2N relay. Note that the intermediate U2N(s) and the Remote UE are provisioned with the U2N discovery security material to verify the integrity of the information originally announced by the 5G ProSe U2N, e.g. RSC, User info of the 5G ProSe U2N, Accumulated QoS if available etc.

[0213] In operation 0b, the Intermediate U2N Relays are also provisioned by their respective HPLMNs with intermediate relay discovery security material used for protection of the forwarded announcement message, for their roles as announcing UEs as specified in 3 GPP TS 33.503 (vl8.4.0) clause 6.1.3.2.2.1. The Intermediate U2N Relays, the Monitoring Remote UE, and / or the Announcing U2N Relay are also provisioned with intermediate relay discovery security materials associated with neighbouring Intermediate U2Ns, for their roles as Monitoring UE as specified in 3GPP TS 33.503 (vl 8.4.0) clause 6.1.3.2.2.1. To retrieve intermediate relay discovery security material, the solution reuses the procedure of clause 6.1.3.2.2.1 of 3GPP TS 33.503 (vl8.4.0) with some modifications. Each intermediate 5GProSe U2N acts as announcing UE, and the neighbours of this intermediate 5G ProSe U2N(other intermediate 5G ProSe U2N(s), the remote UE or the 5G ProSe U2N) act as Monitoring UE. It ensures the PC5 interface protection at each hop for the forwarded announcement message by the intermediate 5G ProSe U2N.

[0214] In operation 1, the Announcing U2N Relay reuses the 5G ProSe U2N relay Discovery Announcement message as specified in 3GPP TS 33.503 (vl 8.4.0) clause 6.1.3.2.2.1 with additional information (e.g. hop count=l, User info of the announcing 5G ProSe U2N, Accumulated QoS) required for multi-hop U2N relay and protects the message with relay discovery security material obtained in operation 0a.

[0215] In operation 2, the first Intermediate U2N Relay receives the protected announcement message, obtains the information originally announced by the 5G ProSe U2N Relay, e.g., the RSC and the User info of the 5G ProSe U2N Relay, and verifies the Announcement message based on the relay discovery security material associated with the announcing U2N, which it obtained in operation 0a. In this context, “Verify” includes decrypting the encryption applied to the message and its data elements by the sender and checking the integrity of the message and data elements according to the integrity protection applied by the sender.

[0216] If verification is successful, the first Intermediate U2N Relay updates the hop information (e.g. hop count) and forwards the original Announcement message with the additional information (e.g. updated hop count and its own User info ID as Announcer Info). The forwarded message is protected by the intermediate relay discovery security material that the first Intermediate U2N Relay obtained from its HPLMN in operation 0b.

[0217] In addition, the first Intermediate U2N Relay includes the ID of its HPLMN in clear text in the forwarded message.

[0218] In operation 3, the second Intermediate U2N Relay receives the protected message, obtains the information originally announced by the 5G ProSe U2N e.g., RSC and the User info of the 5G ProSe U2N Relay and verifies the original Announcement message based on the relay discovery security material associated with the announcing U2N, which it obtained in operation 0a. The second Intermediate U2N Relay also verifies the additional information based on intermediate relay discovery security material associated with the first Intermediate U2N Relay, which it obtained in operation 0b. The second Intermediate U2N Relay identifies the intermediate relay discovery security material associated with the first Intermediate U2N Relay based on the clear text HPLMN ID included by the first Intermediate U2N Relay in operation 2.

[0219] If the verification is successful, the second Intermediate U2N Relay stores the received information (e.g. a record of the RSC, the User info of the 5G ProSe U2N, Announcer Info and the associated Hop-Count value), updates the hop information (e.g. hop count) and forwards the original Announcement message with the additional information (e.g. updated hop count and its own User info ID as Announcer Info). The forwarded message is protected by the intermediate relay discovery security material that the second Intermediate U2N Relay obtained from its HPLMN in operation Ob.

[0220] In addition, the second Intermediate U2N Relay includes the ID of its HPLMN in clear text in the forwarded message.

[0221] In operation 4, upon receiving the Announcement message from the second Intermediate U2N Relay, the monitoring Remote UE obtains the information originally announced by the 5G ProSe U2N e.g. RSC and the User info of the 5G ProSe U2N and verifies the received Announcement message using the relay discovery security material associated with the announcing U2N, which it obtained in operation 0a. The monitoring Remote UE also obtains and verifies the additional information inserted by the sending second Intermediate U2N Relay (e.g. hop count, Announcer Info) based on the intermediate relay discovery security material associated with the second Intermediate U2N Relay, which it obtained in operation Ob. The 5G ProSe Remote UE identifies the intermediate relay discovery security material associated with the second Intermediate U2N Relay based on the clear text HPLMN ID included by the second Intermediate U2N Relay in operation 3.

[0222] If the verification is successful, the monitoring 5G ProSe Remote UE processes the relay announcement message as specified in 3GPP TS 33.503 (vl 8.4.0) clause 6.1.3.2.2.1. Figure

[0223] 11 shows signaling for a relay discovery procedure, applicable in Model B, supporting multi-hop U2N relay according to some embodiments of the present disclosure. The procedure is between a Discoverer Remote UE (1110), a first Intermediate U2N Relay (1120), a second Intermediate U2N Relay (1130), and a Discoveree U2N Relay (1140). Although the operations shown in Figure 11 are given numerical labels, this is intended to facilitate explanation rather than to require or imply any specific operational order, unless expressly stated otherwise.

[0224] In operation 0a, the Discoveree U2N Relay is provisioned with relay discovery security materials from its HPLMN as specified in 3GPP TS 33.503 (v!8.4.0) clause 6.1.3.2.2.2. The intermediate U2N Relays and the Discoverer Remote UE are provisioned with the relay discovery security materials associated with the Discoveree U2N for their roles as Discoverer UE as specified in 3GPP TS 33.503 (vl 8.4.0) clause 6.1.3.2.2.2.

[0225] In operation 0b, the Intermediate U2N Relays are also provisioned by their respective HPLMNs with intermediate relay discovery security material used for protection of forwarded discovery Solicitation / Response messages, for their roles as Discoveree UE as specified in 3GPP TS 33.503 (vl 8.4.0) clause 6.1.3.2.2.2. The 5G ProSe intermediate U2N, the Discoveree 5G ProSe U2N and the Discoverer remote UE are also provisioned with the intermediate relay discovery security materials associated with the neighbouring intermediate U2Ns, for their roles as Discoverer UE as specified in 3GPP TS 33.503 (vl 8.4.0) clause 6.1.3.2.2.2.

[0226] In operation 1, the Discoverer Remote UE reuses the 5G ProSe U2N Relay Discovery Solicitation message as specified in 3GPP TS 33.503 (vl8.4.0) clause 6.1.3.2.2.2 and protects the message with relay discovery security material obtained in operation 0a.

[0227] In operation 2, the first Intermediate U2N Relay receives the protected Relay Discovery Solicitation message, verifies the security (i.e., decryption, integrity check) based on the relay discovery security material associated with the Discoveree U2N obtained in operation 0a, and obtains the RSC. If verification is successful, the first Intermediate U2N Relay includes its own User Info ID in the path and forwards the original Relay Discovery Solicitation message with the additional information (e.g. updated path info). The forwarded message is now protected not only by the relay discovery security material associated with the Discoveree U2N (applied in operation 1) but also by the intermediate relay discovery security material that the first Intermediate U2N Relay obtained from its HPLMN in operation 0b.

[0228] In addition, the first Intermediate U2N Relay includes its HPLMN ID in clear text in the forwarded message.

[0229] In operation 3, the second Intermediate U2N Relay receives the protected Discovery Solicitation message, obtains the RSC, verifies the original Relay Discovery Solicitation message based on the relay discovery security material associated with the Discoveree U2N obtained in operation 0a, and verifies the updated information based on intermediate relay discovery security material associated with the first Intermediate U2N Relay obtained in operation 0b. The second Intermediate U2N Relay identifies the intermediate relay discovery security material associated with the first Intermediate U2N Relay based on the clear text HPLMN ID included by the first Intermediate U2N Relay in operation 2.

[0230] If verification is successful, the second Intermediate U2N Relay again includes its own User Info ID in the path and forwards the original Relay Discovery Solicitation message with the updated information (e.g. updated path info). The forwarded message is protected by the intermediate relay discovery security material that the second Intermediate U2N Relay obtained from its HPLMN in operation Ob. In addition, the second Intermediate U2N Relay includes its HPLMN ID in clear text in the forwarded message.

[0231] In operation 4, upon receiving the Discovery Solicitation message from the second Intermediate U2N Relay, the Discoveree 5G ProSe U2N verifies the received Relay Discovery Solicitation message using the relay discovery security material associated with the Discoveree U2N obtained in operation 0a and the updated information based on the intermediate relay discovery security material associated with the second Intermediate U2N Relay obtained in operation Ob. The Discoveree 5G ProSe U2N identifies the intermediate relay discovery security material associated with the second Intermediate U2N Relay based on the clear text HPLMN ID included by the intermediate second Intermediate U2N Relay in operation 3.

[0232] If verification is successful, the Discoveree U2N Relay processes the Relay Discovery Solicitation message as specified in 3GPP TS 33.503 (vl 8.4.0) clause 6.1.3.2.2.2.

[0233] In operation 5, the Discoveree U2N Relay sends a 5G ProSe UE-to-Network Relay Discovery Response message as specified in 3GPP TS 33.503 (vl 8.4.0) clause 6.1.3.2.2.2 with additional information e.g. RSC, User info of the 5G ProSe U2N, the selected path info (the list of User Info IDs of intermediate Relays in the path) required for multi -hop U2N relay. The Discoveree U2N Relay protects the message with relay discovery security material obtained in operation 0a.

[0234] In operation 6, the second Intermediate U2N Relay verifies the protected Discovery Response message received from Discoveree U2N Relay. The second Intermediate U2N Relay forwards the message with the updated additional information if available and protects the forwarded message with the intermediate relay discovery security material that the second Intermediate U2N Relay obtained from its HPLMN in operation 0b, same as in operation 3. In addition, the second Intermediate U2N Relay includes its HPLMN ID in clear text in the forwarded message.

[0235] In operation 7, the first Intermediate U2N Relay verifies the protected Relay Discovery Response message received from the second Intermediate U2N Relay. The first Intermediate U2N Relay identifies the intermediate relay discovery security material associated with the second Intermediate U2N Relay based on the clear text HPLMN ID included by the intermediate second Intermediate U2N Relay in operation 6.

[0236] The first Intermediate U2N Relay forwards the message with the updated additional information if available and protects the forwarded message with the intermediate relay discovery security material that the first Intermediate U2N Relay obtained from its HPLMN in operation Ob, same as in operation 2. In addition, the first Intermediate U2N Relay includes its HPLMN in clear text in the forwarded message.

[0237] In operation 8, upon receiving the Relay Discovery Response message from the first Intermediate U2N Relay, the Discoverer Remote UE verifies the received message using the relay discovery security material associated with the Discoveree U2N obtained in operation 0a and verifies the additional information based on the intermediate relay discovery security material associated with the first Intermediate U2N Relay, which it obtained in operation Ob. The Discoverer 5G ProSe Remote UE identifies the intermediate relay discovery security material associated with the first Intermediate U2N Relay based on the clear text HPLMN ID included by the intermediate first Intermediate U2N Relay in operation 7.

[0238] If the verification is successful, the Discoverer 5G ProSe Remote UE processes the Discovery Response message as specified in 3GPP TS 33.503 (vl 8.4.0) clause 6.1.3.2.2.2.

[0239] As previously explained, existing procedures for 5G ProSe intermediate U2N Relay discovery are specified in 3GPP TS 33.503 (vl8.4.0) and in 3GPP TS 23.304 (vl9.1.0), in 3GPP TS 23.304 (vl9.1.0) referred to as 5G ProSe multi-hop U2N relay discovery.

[0240] In some embodiments, the existing procedures for Relay Discovery Request / Response messages may be enhanced by the requesting UE indicating a new indication whether the UE requests the discovery security parameters for an 5G ProSe Intermediate U2N Relay, and if the requesting UE is acting as either source 5G ProSe Intermediate U2N Relay or as a target 5G ProSe Intermediate U2N Relay / target U2N Relay / target Remote UE or both. In this manner embodiments facilitate a UE involved in the multi-hop U2N relay discovery requesting the intermediate relay discovery security material associated with the intermediate U2N from the 5G PKMF or 5G DDNMF.

[0241] Figure 12 shows signaling for a restricted 5GProSe Direct Discovery according to some embodiments of the present disclosure. The described procedure is based on the restricted 5G ProSe Direct Discovery Model A described in clause 6.1.3.2.2.1 of 3GPP TS 33.503 (vl8.4.0) and enhanced according to some embodiments of the present disclosure. The procedure is between a Monitoring UE (1210), an Announcing UE (1220), a 5G DDNMF in the HPLMN of the Monitoring UE (1230), a 5G DDNMF in the VPLMN of the Announcing UE (1240), a 5G DDNMF in the HPLMN of the Announcing UE (1250), and a ProSe Application Server (1260). Although the operations shown in Figure 12 are given numerical labels, this is intended to facilitate explanation rather than to require or imply any specific operational order, unless expressly stated otherwise. As described in clause 6.3.3.2 of 3GPP TS 33.503 (vl8.4.0) when a user-plane based security procedure for the U2N Relay is used, the 5G PKMF takes the role of the 5G DDNMF.

[0242] Each sending intermediate 5G ProSe U2N acts as announcing UE of clause 6.1.3.2.2.1 in 3GPP TS 33.503 (vl8.4.0), and the neighbours of this intermediate 5G ProSe U2N (other intermediate 5G ProSe U2N(s), or the 5G ProSe Remote UE etc.) receiving forwarded message act as Monitoring UEs. They are called as sending UE and receiving UE accordingly.

[0243] Operations 1-4 refer to an Announcing UE (e.g., the first Intermediate U2N Relay).

[0244] In operation 1, the Announcing UE sends a Discovery Request message containing a Restricted ProSe Application User ID (RPAUID) to the 5G DDNMF in its HPLMN in order to get a ProSe Code to announce and to get the associated security material. In addition, the Announcing UE includes in the Discovery Request message its PC5 UE security capability that contains a list of ciphering algorithms supported by the UE.

[0245] For 5G ProSe Intermediate U2N Relay discovery, the 5G ProSe Intermediate U2N Relay plays the role of the Announcing UE and sends a Relay Discovery Key Request instead of a Discovery Request. The Relay Discovery Key Request message includes the Relay Service Code (RSC) for multi-path U2N relay and the 5G ProSe Intermediate U2N Relay's PC5 security capability. The requesting UE includes a new indication in the Relay Discovery Key Request command / message whether the requesting UE requests the discovery security parameters for an 5G ProSe intermediate U2N Relay, or if requesting UE is acting as either source 5G ProSe Intermediate U2N Relay, or as a target 5G ProSe Intermediate U2N relay / target U2N relay / target Remote UE or both.

[0246] Operation 2 corresponds to step 2 of clause 6.1.3.2.2.1 of TS 33.503 (vl8.4.0).

[0247] In some embodiments in operation 2, for 5G ProSe Intermediate U2N Relay discovery, the 5G DDNMF of the 5G ProSe Intermediate U2N Relay may check with the UDM whether the intermediate U2N relay is authorized to announce intermediate U2N relay discovery message.

[0248] Operation 3 corresponds to step 3 of clause 6.1.3.2.2.1 of TS 33.503 (vl8.4.0).

[0249] In some embodiments in operation 3, for 5G ProSe intermediate U2N Relay discovery, Npkmf Discovery AnnounceAuthorize service operation is used to obtain the authorization from the 5G PKMF for announcing in the PLMN.

[0250] Operation 4 corresponds to step 4 of clause 6.1.3.2.2.1 of TS 33.503 (vl8.4.0).

[0251] In some embodiments in operation 4, for 5G ProSe intermediate U2N Relay discovery, a Relay Discovery Key Response is used instead of the Discovery Response, and the RSC for multi-path U2N relay is used instead of ProSe Restricted Code. The Relay Discovery Key Response command indicates that this is a request for security material for a 5G ProSe intermediate U2N Relay (= Announcing UE) acting in 5G ProSe multi-hop U2N Relay discovery in Model A operation.

[0252] NOTE 2: 5G DDNMF may get the PC5 security policies in different ways (e.g. from PCF, from ProSe Application Server, or based on local configuration).

[0253] Operations 5-10 refer to a Monitoring UE (e.g., the second Intermediate U2N Relay).

[0254] In operation 5, the Monitoring UE sends a Discovery Request message containing the RPAUID and its PC5 UE security capability to the 5G DDNMF in its HPLMN in order to be allowed to monitor for one or more Restricted ProSe Application User IDs.

[0255] For 5G ProSe U2N Relay discovery, the 5G ProSe Remote UE plays the role of the Monitoring UE and sends a Relay Discovery Key Request instead of the Discovery Request. The Relay Discovery Key Request message includes the RSC and the 5G ProSe Remote UE's PC5 security capability. The Remote UE may provide a list of PLMN IDs in which the UE is authorized to use a 5G ProSe U2N Relay, in the Relay Discovery Key Request.

[0256] For 5G ProSe intermediate U2N Relay discovery, the 5G ProSe intermediate U2N Relay or the 5G ProSe Remote UE plays the role of the Monitoring UE and sends an Relay Discovery Key Request instead of the Discovery Request. The requesting UE includes a new indication in the Relay Discovery Key Request command / message whether the requesting UE requests the discovery security parameters for an 5G ProSe intermediate U2N relay, or if requesting UE is acting as either source 5G ProSe intermediate U2N relay; or as a target 5G ProSe intermediate U2N relay / target U2N relay / target Remote UE or both.

[0257] Operation 6 corresponds to step 6 of clause 6.1.3.2.2.1 of TS 33.503 (vl8.4.0).

[0258] In some embodiments in operation 6, for 5G ProSe intermediate U2N Relay discovery: If the 5G ProSe intermediate U2N Relay plays the role of the Monitoring UE, the 5G DDNMF of the intermediate U2N relay may check with the UDM whether the intermediate U2N relay is authorized to monitor intermediate U2N relay discovery. If the 5G ProSe Remote UE plays the role of the Monitoring UE, the 5G DDNMF of the Remote UE may check with the UDM whether the Remote UE is authorized to monitor intermediate U2N relay discovery.

[0259] Operation 7 corresponds to step 7 of clause 6.1.3.2.2.1 of TS 33.503 (vl8.4.0).

[0260] In some embodiments in operation 7 for 5G ProSe intermediate U2N Relay Discovery, Relay Discovery Key Request and RSC for multi-path U2N relay are used instead of Discovery Request and RPAUID. The 5G DDNMF of the remote UE or the 5G DDNMF of the 5G ProSe intermediate U2N relay discovers 5G DDNMF(s) of the potential 5G ProSe intermediate U2N relay(s) supporting the RSC for multi-path U2N relay based on HPLMN IDs of the potential 5G ProSe intermediate U2N relay(s) mapping to the RSC for multi-path U2N relay. Npkmf Discovery DiscoveryKey service operation is used to obtain the discovery key from the 5G PKMF for a Discoverer UE in the PLMN. In addition the 5G DDNMF of the remote UE or the 5G DDNMF of the 5G ProSe intermediate U2N relay sends the requesting UE indication included in the Relay Discovery Key Request command / message in Operation 5 whether the requesting UE requests the discovery security parameters for an 5G ProSe intermediate U2N relay, or if requesting UE is acting as either source 5G ProSe intermediate U2N relay, or as a target 5G ProSe intermediate U2N relay / target U2N relay / target Remote UE or both.

[0261] Operation 8 corresponds to step 8 of clause 6.1.3.2.2.1 of TS 33.503 (vl8.4.0). In some embodiment, for 5G ProSe U2N Relay discovery, operation 8 is skipped.

[0262] Operation 9 corresponds to step 9 of clause 6.1.3.2.2.1 of TS 33.503 (vl8.4.0).

[0263] In some embodiments in operation 9 for 5G ProSe intermediate U2N Relay discovery, a Relay Discovery Key Response is used instead of the Discovery Response, and the RSC for multi-path U2N relay and the HPLMN ID of the 5G ProSe intermediate U2N (i.e. the Announcing UE) are used instead of ProSe Restricted Code.

[0264] The HPLMN ID of the 5G ProSe intermediate U2N Relay is used to identify the discovery security materials. Npkmf_Discovery_DiscoveryKey service operation is used to obtain the discovery key from the 5G PKMF for a monitoring UE in the PLMN. Operation

[0265] 10 corresponds to step 10 of clause 6.1.3.2.2.1 of TS 33.503 (vl8.4.0).

[0266] In some embodiments in operation 10 for 5G ProSe intermediate U2N Relay discovery, a Relay Discovery Key Response is used instead of the Discovery Response, and the RSC for multi-path U2N relay is used instead of the ProSe Restricted Code. The response message contains the discovery security materials and the HPLMN ID as contained in operation 9. The Relay Discovery Key Response includes multiple sets of discovery security materials and the associated HPLMN IDs of the potential relays if multiple 5GDDNMFs / PKMFs of the potential relays supporting the RSC for multi-path U2N relay are discovered in operation 7. The Relay Discovery Key Response command indicates that this is a request for security material for a 5G ProSe intermediate U2N Relay acting in 5G ProSe multi-hop U2N Relay discovery in Model A operation.

[0267] If the 5G DDNMF in the HPLMN of the Monitoring UE receives the PC5 security policies associated with the ProSe Restricted Code in operation 9, the Monitoring UE's 5G DDNMF forwards the PC5 security policies to the Monitoring UE. In operations 11-12, the sending UE (e.g. the first intermediate U2N relay) sends the protected message protected by the intermediate discovery security material to the receiving UE (e.g. the second intermediate U2N relay), e.g. step 2 of clause 2.7.1.1.1 of of TS 33.503 (V18.4.0).

[0268] NOTE that the sending or receiving UE role for intermediate U2N (s) in multi -hop U2N discovery depends on which entity forwards a discovery message. E.g. the first intermediate U2N relay is the sending UE and the second intermediate U2N relay is the receiving UE when the first intermediate U2N relay forwards the discovery message to the second intermediate U2N relay.

[0269] Operation 11 corresponds to step 11 of clause 6.1.3.2.2.1 of TS 33.503 (vl8.4.0).

[0270] In some embodiments in operation 11 for 5G ProSe intermediate U2N Relay discovery, RSC for multi-path U2N relay is used instead of ProSe Restricted Code Code and the announcing message also includes the HPLMN ID in cleartext to identify the discovery security materials.

[0271] The 5G ProSe intermediate U2N Relay protects the Additional information included for 5G ProSe intermediate U2N Relay discovery in the Discovery message and includes also the HPLMN ID of the Announcing UE in the discovery message in clear text, sent over PC5 interface.

[0272] Operation 12 corresponds to step 12 of clause 6.1.3.2.2.1 of TS 33.503 (vl8.4.0).

[0273] For 5G ProSe intermediate U2N Relay discovery, the 5G ProSe intermediate U2N Relay or the 5G ProSe remote UE decides the discovery security materials to process the Additional information included in the discovery message based on the HPLMN ID of the Announcing UE (i.e. 5G ProSe intermediate U2N relay) in the discovery message.

[0274] Figure 13 shows signaling for a restricted 5G ProSe Direct Discovery according to some embodiments of the present disclosure. The described procedure is based on the restricted 5G ProSe Direct Discovery Model B described in clause 6.1.3.2.2.2 of 3GPP TS 33.503 (vl 8.4.0) and enhanced according to some embodiments of the present disclosure. The procedure is between a Discoverer UE (1310), a Discoveree UE (1320), a 5G DDNMF in the HPLMN of the Discoverer UE (1330), a 5G DDNMF in the VPLMN of the Discoverer / Discoveree UE (1340), a 5G DDNMF in the HPLMN of the Discoveree UE (1350), and a ProSe Application Server (1360). Although the operations shown in Figure 13 are given numerical labels, this is intended to facilitate explanation rather than to require or imply any specific operational order, unless expressly stated otherwise.

[0275] Operations 1-4 refer to a Discoveree UE (e.g. the second intermediate U2N relay). In operation 1, the Discoveree UE sends a Discovery Request message containing the RPAUID to the 5G DDNMF in its HPLMN in order to get Discovery Query Filter(s) to monitor a query, the ProSe Response Code to announce and associated security materials. The command indicates that this is for ProSe Response (Model B) operation, i.e. for a Discoveree UE. In addition, the Discoveree UE includes its PC5 UE security capability that contains the list of supported ciphering algorithms by the UE in the Discovery Request message.

[0276] For 5G ProSe U2N Relay discovery, the 5G ProSe U2N Relay plays the role of the Discoveree UE and sends a Relay Discovery Key Request instead of a Discovery Request. The Relay Discovery Key Request message includes the Relay Service Code (RSC) and the 5G ProSe U2N Relay's PC5 security capability.

[0277] For 5G ProSe intermediate U2N Relay discovery, the 5G ProSe intermediate U2N Relay plays the role of the Discoveree UE and sends a Relay Discovery Key Request instead of a Discovery Request. The requesting UE shall include a new indication in the Relay Discovery Key Request command / message whether the requesting UE requests the discovery security parameters for an 5G ProSe intermediate U2N relay, and if requesting UE is acting as either source 5G ProSe intermediate U2N relay; or as a target 5G ProSe intermediate U2N relay / target U2N relay / target Remote UE or both.

[0278] Operations 2-4 correspond to steps 2-4 described in clause 6.1.3.2.2.2 of 3GPP TS 33.503 (V18.4.0).

[0279] Operations 5-10 refer to a Discoverer UE (e.g. the first intermediate U2N relay).

[0280] Operation 5 corresponds to step 5 of clause 6.1.3.2.2.2 of TS 33.503 (vl 8.4.0).

[0281] In some embodiments in operation 5 for 5G ProSe intermediate U2N Relay discovery, the 5G ProSe intermediate U2N Relay or the 5G ProSe Remote UE plays the role of the Discoverer UE and sends a Relay Discovery Key Request instead of the Discovery Request. The requesting UE includes a new indication in the Relay Discovery Key Request command / message whether the requesting UE requests the discovery security parameters for an 5G ProSe intermediate U2N relay, and if requesting UE is acting as either source 5G ProSe intermediate U2N relay, or as a target 5G ProSe intermediate U2N relay / target U2N relay / target Remote UE or both.

[0282] Operation 6 corresponds to step 6 of clause 6.1.3.2.2.2 of TS 33.503 (vl8.4.0).

[0283] In some embodiments in operation 6, if the 5G ProSe intermediate U2N Relay plays the role of the Discoverer UE: For 5G ProSe intermediate U2N Relay discovery, the 5G DDNMF of the intermediate U2N relay may check with the UDM whether the intermediate U2N relay is authorized to monitor intermediate U2N relay discovery.

[0284] If the 5G ProSe Remote UE plays the role of the Discoverer UE:

[0285] For 5G ProSe intermediate U2N Relay discovery, the 5G DDNMF of the Remote UE may check with the UDM whether the Remote UE is authorized to monitor intermediate U2N relay discovery.

[0286] Operation 7 corresponds to step 7 of clause 6.1.3.2.2.2 of TS 33.503 (vl8.4.0).

[0287] In some embodiments in operation 7, for 5G ProSe intermediate U2N Relay Discovery, Relay Discovery Key Request and RSC for multi-path U2N relay are used instead of Discovery Request and RPAUID. The 5G DDNMF of the remote UE or the 5G DDNMF of the 5G ProSe intermediate U2N relay discovers 5G DDNMF(s) of the potential 5G ProSe intermediate U2N relay(s) supporting the RSC for multi-path U2N relay based on HPLMN IDs of the potential 5G ProSe intermediate U2N relay(s) mapping to the RSC for multi-path U2N relay .

[0288] Npkmf Discovery DiscoveryKey service operation is used to obtain the discovery key from the 5G PKMF for a Discoverer UE in the PLMN. In addition the 5G DDNMF of the remote UE or the 5G DDNMF of the 5G ProSe intermediate U2N relay sends the requesting UE indication included in the Relay Discovery Key Request command / message in Operation 5 whether the requesting UE requests the discovery security parameters for an 5G ProSe intermediate U2N relay, or if requesting UE is acting as either source 5G ProSe intermediate U2N relay, or as a target 5G ProSe intermediate U2N relay / target U2N relay / target Remote UE or both.

[0289] Operation 8 corresponds to step 8 of clause 6.1.3.2.2.2 of TS 33.503 (vl8.4.0).

[0290] In some embodiments in operation 8, for 5G ProSe intermediate U2N Relay Discovery, this step is skipped.

[0291] Operation 9 corresponds to step 9 of clause 6.1.3.2.2.2 of TS 33.503 (vl8.4.0).

[0292] In some embodiments in operation 9, for 5G ProSe intermediate U2N Relay discovery, a Relay Discovery Key Response is used instead of the Discovery Response, and the RSC for multi-path U2N relay and the HPLMN ID of the 5G ProSe intermediate U2N Relay (i.e. the Discoveree UE) are used instead of ProSe Query Code and ProSe Response Code. The HPLMN ID of the 5G ProSe intermediate U2N Relay is used to identify the discovery security materials. Npkmf Discovery DiscoveryKey service operation is used to obtain the discovery key from the 5G PKMF for a Discoverer UE in the PLMN. NOTE 3: For 5G ProSe Direct Discovery, there are two possible configurations for integrity checking, namely, MIC checked by the 5G DDNMF of the Discoverer UE, and MIC checked at the Discoverer UE side; this is decided by the 5G DDNMF that assigns the ProSe Restricted Code and signals the Discoverer UE in the Code-Receiving Security Parameters.

[0293] For 5G ProSe U2N Relay discovery, MIC checking is performed only at the Remote UE and the 5G DDNMF of the Remote UE does not need to configure integrity checking for U2N Relay discovery.

[0294] If the 5G ProSe intermediate U2N Relay plays the role of the Discoverer UE, for 5G ProSe intermediate U2N Relay discovery, MIC checking is performed only at the 5G ProSe intermediate U2N Relay and the 5G DDNMF of the 5G ProSe intermediate U2N Relay does not need to configure integrity checking for 5G ProSe intermediate U2N Relay discovery.

[0295] If the 5G ProSe Remote UE plays the role of the Discoverer UE, for 5G ProSe intermediate U2N Relay discovery, MIC checking is performed only at the Remote UE and the 5G DDNMF of the Remote UE does not need to configure integrity checking for 5G ProSe intermediate U2N Relay discovery.

[0296] Operation 10 corresponds to step 10 of clause 6.1.3.2.2.2 of TS 33.503 (vl8.4.0).

[0297] In some embodiments in operation 10, for 5G ProSe intermediate U2N Relay discovery, Npkmf Discovery AnnounceAuthorize service operation is used to obtain the authorization from the 5G PKMF for discovering in the PLMN.

[0298] Operation 11 corresponds to step 11 of clause 6.1.3.2.2.2 of TS 33.503 (vl8.4.0).

[0299] In some embodiments in operation 11, for 5GProSe intermediate U2N Relay discovery, an Relay Discovery Key Response is used instead of the Discovery Response, and the RSC for multi-path U2N relay is used instead of the ProSe Restricted Code. The response message contains the discovery security materials and the HPLMN ID as contained in step 9. The Relay Discovery Key Response includes multiple sets of discovery security materials and the associated HPLMN IDs of the potential relays if multiple 5G DDNMF s / PKMFs of the potential relays supporting the RSC for multi-path U2N relay are discovered in step 7. The Relay Discovery Key Response command indicates that this is a request for security material for a 5G ProSe intermediate U2N Relay (= Discoveree UE) acting in 5G ProSe multi-hop U2N Relay discovery in Model B operation in PLMN(s) (x,y,z).

[0300] In operations 12-14, the Discoverer UE (e.g. the first intermediate U2N relay) sends the message protected (discovery Solicitation) by the intermediate discovery material associated with the Discoveree UE to the Discoveree UE (e.g. the second intermediate U2N relay). The Discoveree UE (e.g. the second intermediate U2N relay) sends the protected message (discovery Response) by the intermediate discovery material associated with the Discoveree UE to the Discoverer UE (e.g. the first intermediate U2N relay).

[0301] The operations 12-14 differ from the principles of the current legacy discovery procedure for Model B in TS 33.503 (vl 8.4.0) in clause 2.7.1.1.2. If the principles of the current legacy discovery procedure for Model B in TS 33.503 (vl 8.4.0) (i.e. clause 2.7.1.1.2) would have been followed, then the following second variant would apply. In this variant the first intermediate U2N relay is using the discovery key of the second intermediate U2N relay in both step 2 and step 6. This follows the current Model B in Rel-18 TS 33.503 (vl8.4.0).

[0302] A simplified flow of a discovery procedure supporting multi-hop U2N Relay according to embodiments of the current specification is shown in Figure 1 la in operations 2 and 6. In this variant the first intermediate U2N relay is using the discovery key of the second intermediate U2N relay in both step 2 and step 6, according to the current Model B in Rel-18 TS 33.503 (V18.4.0).

[0303] Various features of the embodiments described above correspond to various operations illustrated in Figures 14A-16A, which show exemplary methods (e.g., procedures) for a first UE, a second UE, and a third UE, respectively. In other words, various features of the operations described below correspond to various embodiments described above, including the exemplary procedures shown in Figures 14A-16A. Furthermore, the exemplary methods shown in Figures 14A-16A can be used cooperatively to provide various benefits, advantages, and / or solutions to problems described herein. Although Figures 14A-16A show specific blocks in particular orders, the operations of the exemplary methods can be performed in different orders than shown and can be combined and / or divided into blocks having different functionality than shown. Optional blocks or operations are indicated by dashed lines.

[0304] In addition, Figure 14A shows an exemplary method (e.g., procedure) for a first UE configured to discover intermediate U2N relays that facilitate access to a communication network via a U2N relay, according to various embodiments of the present disclosure. The exemplary method can be performed by a remote UE (e.g., wireless device) such as described elsewhere herein.

[0305] The exemplary method includes the operations of block 1410A, where the first UE obtains the following security material from the first UE’s PLMN: relay discovery security materials associated with a second UE configured to operate as the U2N relay and intermediate relay discovery security materials associated with a third UE configured to operate as an intermediate U2N relay between the first UE and the second UE and an associated HPLMN ID of the third UE. The exemplary method also includes the operations of block 1420A, where the first UE receives from the third UE a message associated with multi-hop relay discovery. The message includes a first portion generated by the third UE, a second portion generated by the second UE and the HPLMN ID of the third UEs HPLMN in clear text. The exemplary method also includes the operations of block 1430A, where the first UE verifies the following: the first portion based on the intermediate relay discovery security materials associated with the third UE, and the second portion based on the relay discovery security materials associated with the second UE. The security materials associated with the third UE are identified by the first UE based on the HPLMN ID of the third UE. The exemplary method also includes the operations of block 1440 A, where based on successful verification of the first and second portions, the first UE processes the content of the message.

[0306] In some embodiments, obtaining the intermediate relay discovery security materials associated with the third UE and the associated HPLMN ID of the third UE in block 1410A include the following operations, labelled with corresponding block numbers:

[0307] • (1411 A) sending to the first UE’s HPLMN a request for the intermediate relay discovery security materials, wherein the request comprises an indication of: whether the first UE requests the intermediate relay discovery security materials for an intermediate U2N relay, and whether the first UE is acting as: a source intermediate U2N relay and / or one of: a target intermediate U2N relay, a target U2N relay, or a target Remote UE; and

[0308] • (1412A) in response to the request, obtaining from the first UE’s HPLMN the intermediate relay discovery security material associated with the third UE and the associated HPLMN ID of the third UE.

[0309] In some of these embodiments, the first UE is Monitoring Remote UE and the message is an Announcement. In other of these embodiments, the first UE is a Discoverer Remote UE and the message is a Discovery Response.

[0310] In addition, Figure 15A shows an exemplary method (e.g., procedure) for a second UE configured to provide a U2N relay between intermediate U2N relays and a communication network, according to various embodiments of the present disclosure. The exemplary method can be performed by a U2N relay UE (e.g., wireless device) such as described elsewhere herein.

[0311] The exemplary method includes the operations of block 1510A, where the second UE obtains the following security material from the second UE’ s HPLMN : relay discovery security materials associated with the second UE, and intermediate relay discovery security materials associated with a third UE configured to operate as an intermediate U2N relay and an associated HPLMN ID of the third UE. The exemplary method also includes the operations of block 1520A, where the second UE receives from the third UE a message associated with multi- hop relay discovery. The message includes a first portion generated by the third UE, a second portion generated by the first UE and the HPLMN ID of the third UEs HPLMN in clear text. The exemplary method also includes the operations of block 1530A, where the second UE verifies the following: the first portion based on the intermediate relay discovery security materials associated with the third UE, and the second portion based on the relay discovery security materials associated with the second UE. The security materials associated with the third UE are identified by the second UE based on the HPLMN ID of the third UE. The exemplary method also includes the operations of block 1540A, where the second UE based on successful verification of the first portion, and the second portion, processes the content of the message.

[0312] In some embodiments, obtaining the intermediate relay discovery security materials associated with the third UE and the associated HPLMN ID of the third UE in block 1510A includes the following operations, labelled with corresponding sub-block numbers:

[0313] • (1511 A) sending to the second UE’s HPLMN a request for the intermediate relay discovery security materials, wherein the request comprises an indication of: whether the second UE requests the intermediate relay discovery security materials for an intermediate U2N relay, and whether the second UE is acting as: a source intermediate U2N relay and / or one of: a target intermediate U2N relay, a target U2N relay, or a target Remote UE, and

[0314] • (1512A) in response to the request, obtaining from the second UE’s HPLMN the intermediate relay discovery security material associated with the third UE and the associated HPLMN ID of the third UE.

[0315] In some of these embodiments, the second UE is a Discoveree U2N Relay and the secure message is a Discovery Solicitation message.

[0316] In addition, Figure 16A shows an exemplary method (e.g., procedure) for a third UE configured to provide an intermediate U2N relay between remote UEs and a U2N relay coupled to communication network, according to various embodiments of the present disclosure. The exemplary method can be performed by an intermediate U2N relay UE (e.g., wireless device) such as described elsewhere herein.

[0317] The exemplary method includes the operations of block 1620 A, where the third UE receives a first message associated with multi-hop relay discovery. The first message includes a second portion generated by a message source UE and a first portion generated by one of the following: the message source UE, or a fourth UE arranged as an intermediate U2N relay between the message source UE and the third UE, and when the first portion is generated by the fourth UE a HPLMN IS of the fourth UE’s HPLMN in clear text.

[0318] The exemplary method also includes the operations of block 1630A, where the third UE verifies the first portion based on one of the following: relay discovery security materials associated with a second UE arranged to provide the U2N relay, or intermediate relay discovery security materials associated with the fourth UE. The intermediate relay discovery security materials associated with the fourth UE are identified by the third UE based on the HPLMN ID of the third UE.

[0319] The exemplary method also includes the operations of block 1640A, where the third UE verifies the second portion based on the relay discovery security materials associated with the message source UE. The exemplary method also includes the operations of block 1650A, where based on successful verification of the first and second portions, the third UE updates the first portion and secures the updated first portion using the intermediate relay discovery security materials associated with the third UE. The exemplary method also includes the operations of block 1660 A, where the third UE sends a second message including the second portion, the secured updated first portion and the HPLMN ID of the third UE’ s HPLMN to one of the following: a message target UE, or a fifth UE arranged as an intermediate U2N relay between the message target UE and the third UE.

[0320] In some embodiments, the first portion includes a hop count and the second portion includes a relay service code (RSC), and updating the first portion in block 1650A includes the operations of sub-block 1651 A, where the third UE increments the hop count. In some of these embodiments, the hop count was generated by the message source UE and updated by the fourth UE, i.e., prior to being received by the third UE.

[0321] In some embodiments, the exemplary method also includes the operations of block 1610A, where the third UE obtains the following from the third UE’s HPLMN: the relay discovery security materials associated with the second UE, the intermediate relay discovery security materials associated with the third UE, and the intermediate relay discovery security materials associated with the fourth UE and an associated HPLMN ID of the fourth UE.

[0322] In some embodiments, obtaining the intermediate relay discovery security materials associated with an intermediate U2N relay and an associated HPLMN ID of that UE in block 1610A includes the following operations, labelled with corresponding sub-block numbers: • (1611 A) sending to the third UE’s HPLMN a request for the intermediate relay discovery security materials, wherein the request comprises an indication of: whether the third UE requests the intermediate relay discovery security materials for an intermediate U2N relay, and whether the third UE is acting as: a source intermediate U2N relay and / or one of: a target intermediate U2N relay, a target U2N relay, or a target Remote UE, and

[0323] • (1612A) in response to the request, obtaining from the third UE’s HPLMN the intermediate relay discovery security material associated with the UE arranged as an intermediate U2N relay, and the associated HPLMN ID of the UE arranged as an intermediate U2N relay.

[0324] In some embodiments, the first and second messages are Announcement messages, and the message source UE is the second UE arranged as an Announcing U2N Relay. In other embodiments, the first and second messages are Discovery Response messages, and the message source UE is the second UE arranged as a Discoveree U2N Relay. In other embodiments, the first and second messages are Discovery Solicitation messages, and the message source UE is a first UE arranged as a Discoverer Remote UE.

[0325] In addition, Figure 14B shows an exemplary method (e.g., procedure) for a first UE configured to discover intermediate U2N relays that facilitate access to a communication network via a U2N relay, according to various embodiments of the present disclosure. The exemplary method can be performed by a remote UE (e.g., wireless device) such as described elsewhere herein.

[0326] The exemplary method includes the operations of block 1410B, where the first UE receives, from a third UE configured to operate as an intermediate U2N relay between the first UE and a second UE configured to operate as the U2N relay, a message associated with multihop relay discovery. The message includes a first portion generated by the third UE (block 141 IB), a second portion generated by the second UE (block 1412B), and the HPLMN ID in clear text (block 1413B).

[0327] The exemplary method also includes the operations of block 1420B, where the first UE identifies, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message. The exemplary method also includes the operations of block 1430B, where the first UE verifies at least the first portion of the message based on the identified relay discovery security materials. The exemplary method also includes the operations of block 1440B, where, based on successful verification of at least the first portions, the first UE processes the message.

[0328] In some of these embodiments, the first UE is Monitoring Remote UE and the message is an Announcement. In other of these embodiments, the first UE is a Discoverer Remote UE and the message is a Discovery Response.

[0329] In some embodiments, the method further comprises obtaining multiple sets of relay discovery security materials associated with respective HPLMN IDs, and said identifying comprises identifying the relay discovery security materials based on which to verify at least the first portion of the message as being the relay discovery security materials that are included in whichever one of the sets of relay discovery security materials that is associated with the HPLMN ID included in the message. In some embodiments, the multiple sets of relay discovery security materials are obtained from an HPLMN of the first UE.

[0330] In some embodiments, the identified relay discovery security materials include a decryption key associated with the HPLMN ID included in the message, and wherein said verifying comprises decrypting at least the first portion of the message using the decryption key. In other embodiments, alternatively or additionally, the identified relay discovery security materials include an integrity protection key associated with the HPLMN ID included in the message, and said verifying comprises checking an integrity of at least the first portion of the message using the integrity protection key.

[0331] In some embodiments, the first portion of the message includes hop information for the message associated with the multi-hop relay discovery and / or the second portion of the message includes a Relay Service Code, RSC.

[0332] In some embodiments, the first UE is a Monitoring Remote UE and the message is an Announcement. In other embodiments, the first UE is a Discoverer Remote UE and the message is a Discovery Response.

[0333] In addition, Figure 15B shows an exemplary method (e.g., procedure) for a second UE configured to provide a U2N relay between intermediate U2N relays and a communication network, according to various embodiments of the present disclosure. The exemplary method can be performed by a U2N relay UE (e.g., wireless device) such as described elsewhere herein.

[0334] The exemplary method includes the operations of block 1510B, where the second UE receives from a third UE configured to operate as an intermediate U2N relay between the second UE and a first UE, a message associated with multi-hop relay discovery. The message includes a first portion generated by the third UE (block 151 IB), a second portion generated by the first UE (block 1512B), and the HPLMN ID in clear text (block 1513B).

[0335] The exemplary method also includes the operations of block 1520B, where the second UE identifies, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message. The exemplary method also includes the operations of block 1530A, where the second UE verifies at least the first portion of the message based on the identified relay discovery security materials. The exemplary method also includes the operations of block 1540B, where, based on successful verification of at least the first portion, the second UE processes the message.

[0336] In some of these embodiments, the second UE is a Discoveree U2N Relay and the secure message is a Discovery Solicitation message.

[0337] In some embodiments, the method further comprises obtaining multiple sets of relay discovery security materials associated with respective HPLMN IDs, and said identifying comprises identifying the relay discovery security materials based on which to verify at least the first portion of the message as being the relay discovery security materials that are included in whichever one of the sets of relay discovery security materials that is associated with the HPLMN ID included in the message. In some embodiments, the multiple sets of relay discovery security materials are obtained from an HPLMN of the second UE.

[0338] In some embodiments, the identified relay discovery security materials include a decryption key associated with the HPLMN ID included in the message, and said verifying comprises decrypting at least the first portion of the message using the decryption key. In other embodiments, alternatively or additionally, the identified relay discovery security materials include an integrity protection key associated with the HPLMN ID included in the message, and wherein said verifying comprises checking an integrity of at least the first portion of the message using the integrity protection key.

[0339] In some embodiments, the first portion of the message includes hop information for the message associated with the multi-hop relay discovery and / or the second portion of the message includes a Relay Service Code, RSC.

[0340] In some embodiments, the second UE is a Discoveree U2N Relay and the message is a Discovery Solicitation message.

[0341] In addition, Figure 16B shows an exemplary method (e.g., procedure) for a third UE configured to provide an intermediate U2N relay between remote UEs and a U2N relay for facilitating access to a communication network, according to various embodiments of the present disclosure. The exemplary method can be performed by an intermediate U2N relay UE (e.g., wireless device) such as described elsewhere herein.

[0342] The exemplary method includes the operations of block 1610B, where third UE receives a first message associated with multi-hop relay discovery. The message includes a second portion generated by a message source UE (block 161 IB), a first portion generated by the message source UE or a fourth UE configured as an intermediate U2N relay between the message source UE and the third UE (block 1612B), and the HPLMN ID in clear text (block 1613B).

[0343] The exemplary method includes the operations of block 1620B, where the third UE identifies, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message. The exemplary method also includes the operations of block 163 OB, where the third UE verifies at least the first portion of the message based on the identified relay discovery security materials. The exemplary method also includes the operations of block 1640B, where, based on successful verification of at least the first portion, the third UE processes the message.

[0344] In some embodiments, processing the message comprises updating the first portion, and wherein the method further comprises sending a second message that includes the second portion, the updated first portion, and the HPLMN ID in clear text, wherein the message is sent to a message target UE or a fifth UE configured as an intermediate U2N relay between the message target UE and the third UE. In some embodiments, the first portion includes a hop count and wherein updating the first portion includes incrementing the hop count. In some embodiments, the hop count was generated by the message source UE and updated by the fourth UE.

[0345] In some embodiments, the method further comprises obtaining multiple sets of relay discovery security materials associated with respective HPLMN IDs, and said identifying comprises identifying the relay discovery security materials based on which to verify at least the first portion of the message as being the relay discovery security materials that are included in whichever one of the sets of relay discovery security materials that is associated with the HPLMN ID included in the message. In some embodiments, the multiple sets of relay discovery security materials are obtained from an HPLMN of the third UE.

[0346] In some embodiments, the identified relay discovery security materials include a decryption key associated with the HPLMN ID included in the message, and wherein said verifying comprises decrypting at least the first portion of the message using the decryption key. In other embodiments, alternatively or additionally, the identified relay discovery security materials include an integrity protection key associated with the HPLMN ID included in the message, and said verifying comprises checking an integrity of at least the first portion of the message using the integrity protection key.

[0347] In some embodiments, the first portion of the message includes hop information for the message associated with the multi-hop relay discovery and / or the second portion of the message includes a Relay Service Code, RSC.

[0348] In some embodiments, the first message is an Announcement message, and the message source UE is the second UE configured as an Announcing U2N Relay. In other embodiments, the first message is a Discovery Response message, and the message source UE is the second UE configured as a Discoveree U2N Relay. In yet other embodiments, the first message is a Discovery Solicitation message, and the message source UE is a first UE configured as a Discoverer Remote UE.

[0349] The exemplary method also includes the operations of block 1660B, where the third UE receives a first message associated with multi-hop relay discovery. The first message includes a second portion generated by a message source UE (block 166 IB), and a first portion generated by the message source UE or a fourth UE configured as an intermediate U2N relay between the message source UE and the third UE (block 1662B).

[0350] The exemplary method also includes the operations of block 1670A, where the third UE updates the first portion of the message. The exemplary method also includes the operations of block 1680 A, where the third UE secures at least the updated first portion using relay discovery security materials that are associated with a HPLMN ID. The exemplary method also includes the operations of block 1690 A, where the third UE sends, to a message target UE or a fifth UE configured as an intermediate U2N relay between the message target UE and the third UE, a second message that includes the secured updated first portion, includes the second portion, and includes the HPLMN ID in clear text.

[0351] In some embodiments, the first portion includes a hop count and updating the first portion includes incrementing the hop count. In some embodiments, the hop count was generated by the message source UE and updated by the fourth UE.

[0352] In some embodiments, the relay discovery security materials include a decryption key associated with the HPLMN ID. In other embodiments, the relay discovery security materials alternatively or additionally include an integrity protection key associated with the HPLMN ID.

[0353] In some embodiments, the first portion of the message includes hop information for the message associated with the multi-hop relay discovery and / or the second portion of the message includes a Relay Service Code, RSC.

[0354] In some embodiments, the first and second messages are Announcement messages, and the message source UE is the second UE configured as an Announcing U2N Relay. In other embodiments, the first and second messages are Discovery Response messages, and the message source UE is the second UE configured as a Discoveree U2N Relay. In yet other embodiments, the first and second messages are Discovery Solicitation messages, and the message source UE is a first UE configured as a Discoverer Remote UE.

[0355] Although various embodiments are described above in terms of methods, techniques, and / or procedures, the person of ordinary skill will readily comprehend that such methods, techniques, and / or procedures can be embodied by various combinations of hardware and software in various systems, communication devices, computing devices, control devices, apparatuses, non-transitory computer-readable media, computer program products, etc.

[0356] Figure 17 shows an example of a communication system 1700 in accordance with some embodiments. In this example, communication system 1700 includes a telecommunication network 1702 that includes an access network 1704 (e.g., RAN) and a core network 1706, which includes one or more core network nodes 1708. Access network 1704 includes one or more access network nodes, such as network nodes 1710a-b (one or more of which may be generally referred to as network nodes 1710), or any other similar 3 GPP access nodes or non- 3 GPP access points. Moreover, as will be appreciated by those of skill in the art, a network node is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that network nodes include disaggregated implementations or portions thereof. For example, in some embodiments, telecommunication network 1702 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a node in telecommunication network 1702 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement one or more functionalities of any node in telecommunication network 1702, including one or more network nodes 1710 and / or core network nodes 1708.

[0357] Examples of an ORAN network node include an open radio unit (O-RU), an open distributed unit (O-DU), an open central unit (O-CU), including an O-CU control plane (O- CU-CP) or an O-CU user plane (O-CU-UP), a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or any combination thereof (the adjective “open” designating support of an ORAN specification). The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an Al, Fl, Wl, El, E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN access node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an 0-2 interface defined by the 0-RAN Alliance or comparable technologies. Network nodes 1710 facilitate direct or indirect connection of UEs, such as by connecting UEs 1712a-d (one or more of which may be generally referred to as UEs 1712) to core network 1706 over one or more wireless connections.

[0358] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, communication system 1700 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. Communication system 1700 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.

[0359] UEs 1712 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with network nodes 1710 and other communication devices. Similarly, network nodes 1710 are arranged, capable, configured, and / or operable to communicate directly or indirectly with UEs 1712 and / or with other network nodes or equipment in telecommunication network 1702 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in telecommunication network 1702.

[0360] In the depicted example, core network 1706 connects network nodes 1710 to one or more hosts, such as host 1716. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. Core network 1706 includes one or more core network nodes (e.g., 1708) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of core network node 1708. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De- concealing function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF).

[0361] Host 1716 may be under the ownership or control of a service provider other than an operator or provider of access network 1704 and / or telecommunication network 1702, and may be operated by the service provider or on behalf of the service provider. Host 1716 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.

[0362] As a whole, communication system 1700 of Figure 17 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox.

[0363] In some examples, telecommunication network 1702 is a cellular network that implements 3GPP standardized features. Accordingly, telecommunication network 1702 may support network slicing to provide different logical networks to different devices that are connected to telecommunication network 1702. For example, telecommunication network 1702 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive loT services to yet further UEs.

[0364] In some examples, UEs 1712 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to access network 1704 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from access network 1704. Additionally, a UE may be configured for operating in single- or multi -RAT or multi-standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC).

[0365] In the example, hub 1714 communicates with access network 1704 to facilitate indirect communication between one or more UEs (e.g., UE 1712c and / or 1712d) and network nodes (e.g., network node 1710b). In some examples, hub 1714 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, hub 1714 may be a broadband router enabling access to core network 1706 for the UEs. As another example, hub 1714 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes 1710, or by executable code, script, process, or other instructions in hub 1714. As another example, hub 1714 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, hub 1714 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker or other media delivery device, hub 1714 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which hub 1714 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, hub 1714 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy loT devices.

[0366] Hub 1714 may have a constant / persistent or intermittent connection to network node 1710b. Hub 1714 may also allow for a different communication scheme and / or schedule between hub 1714 and UEs (e.g., UE 1712c and / or 1712d), and between hub 1714 and core network 1706. In other examples, hub 1714 is connected to core network 1706 and / or one or more UEs via a wired connection. Moreover, hub 1714 may be configured to connect to an M2M service provider over access network 1704 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with network nodes 1710 while still connected via hub 1714 via a wired or wireless connection. In some embodiments, hub 1714 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the UEs from / to network node 1710b. In other embodiments, hub 1714 may be a non-dedicated hub - that is, a device which is capable of operating to route communications between the UEs and network node 1710b, but which is additionally capable of operating as a communication start and / or end point for certain data channels. In some embodiments hub 1714 may be configured to operate as a U2N relay, including performing operations attributed to U2N relays in any of the exemplary methods or procedures described above.

[0367] Figure 18 shows a UE 1800 in accordance with some embodiments. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage device, playback appliance, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), smart device, wireless customer-premise equipment (CPE), vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by 3 GPP, including a narrow band internet of things (NB- loT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.

[0368] A UE may support device-to-device (D2D) communication, for example by implementing a 3 GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle- to-everything (V2X). In other examples, a UE may not necessarily have a user in the sense of a human user who owns and / or operates the relevant device. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but which may not, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter).

[0369] UE 1800 includes processing circuitry 1802 that is operatively coupled via a bus 1804 to an input / output interface 1806, a power source 1808, a memory 1810, a communication interface 1812, and / or any other component, or any combination thereof. Certain UEs may utilize all or a subset of the components shown in Figure 18. The level of integration between the components may vary from one UE to another UE. Further, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0370] Processing circuitry 1802 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in memory 1810. Processing circuitry 1802 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field-programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general-purpose processors, such as a microprocessor or digital signal processor (DSP), together with appropriate software; or any combination of the above. For example, processing circuitry 1802 may include multiple central processing units (CPUs).

[0371] In the example, input / output interface 1806 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into UE 1800. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.

[0372] In some embodiments, power source 1808 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used. Power source 1808 may further include power circuitry for delivering power from power source 1808 itself, and / or an external power source, to the various parts of UE 1800 via input circuitry or an interface such as an electrical power cable. Delivering power may be, for example, for charging power source 1808. Power circuitry may perform any formatting, converting, or other modification to the power from power source 1808 to make the power suitable for the respective components of UE 1800 to which power is supplied.

[0373] Memory 1810 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable readonly memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, memory 1810 includes one or more application programs 1814, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data 1816. Memory 1810 may store, for use by UE 1800, any of a variety of various operating systems or combinations of operating systems.

[0374] Memory 1810 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID), flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD-DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUICC), integrated UICC (iUICC) or a removable UICC commonly known as ‘ SIM card.’ Memory 1810 may allow UE 1800 to access instructions, application programs and the like, stored on transitory or non-transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing a communication system may be tangibly embodied as or in memory 1810, which may be or comprise a device-readable storage medium.

[0375] Processing circuitry 1802 may be configured to communicate with an access network or other network using communication interface 1812. Communication interface 1812 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 1822. Communication interface 1812 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or a network node in an access network). Each transceiver may include a transmitter 1818 and / or a receiver 1820 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, transmitter 1818 and receiver 1820 may be coupled to one or more antennas (e.g., antenna 1822) and may share circuit components, software or firmware, or alternatively be implemented separately.

[0376] In the illustrated embodiment, communication functions of communication interface 1812 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented in according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / internet protocol (TCP / IP), synchronous optical networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), and so forth.

[0377] Regardless of the type of sensor, a UE may provide an output of data captured by its sensors, through its communication interface 1812, via a wireless connection to a network node. Data captured by sensors of a UE can be communicated through a wireless connection to a network node via another UE. The output may be periodic (e.g., once every 15 minutes if it reports the sensed temperature), random (e.g., to even out the load from reporting from several sensors), in response to a triggering event (e.g., an alert is sent when moisture is detected), in response to a request (e.g., a user initiated request), or a continuous stream (e.g., a live video feed of a patient).

[0378] As another example, a UE comprises an actuator, a motor, or a switch, related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, the UE may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input.

[0379] A UE, when in the form of an Internet of Things (loT) device, may be a device for use in one or more application domains, these domains comprising, but not limited to, city wearable technology, extended industrial application and healthcare. Non-limiting examples of such an loT device are a device which is or which is embedded in: a connected refrigerator or freezer, a TV, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a head-mounted display for Augmented Reality (AR) or Virtual Reality (VR), a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal- or item-tracking device, a sensor for monitoring a plant or animal, an industrial robot, an Unmanned Aerial Vehicle (UAV), and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot. A UE in the form of an loT device comprises circuitry and / or software in dependence of the intended application of the loT device in addition to other components as described in relation to UE 1800 shown in Figure 18.

[0380] As yet another specific example, in an loT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another UE and / or a network node. The UE may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, the UE may implement the 3 GPP NB-IoT standard. In other scenarios, a UE may represent a vehicle, such as a car, a bus, a truck, a ship and an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.

[0381] In practice, any number of UEs may be used together with respect to a single use case. For example, a first UE might be or be integrated in a drone and provide the drone’s speed information (obtained through a speed sensor) to a second UE that is a remote controller operating the drone. When the user makes changes from the remote controller, the first UE may adjust the throttle on the drone (e.g. by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second UE can also include more than one of the functionalities described above. For example, a UE might comprise the sensor and the actuator, and handle communication of data for both the speed sensor and the actuators.

[0382] The foregoing merely illustrates the principles of the disclosure. Various modifications and alterations to the described embodiments will be apparent to those skilled in the art in view of the teachings herein. It will thus be appreciated that those skilled in the art will be able to devise numerous systems, arrangements, and procedures that, although not explicitly shown or described herein, embody the principles of the disclosure and can be thus within the spirit and scope of the disclosure. Various embodiments can be used together with one another, as well as interchangeably therewith, as should be understood by those having ordinary skill in the art.

[0383] The term unit, as used herein, can have conventional meaning in the field of electronics, electrical devices and / or electronic devices and can include, for example, electrical and / or electronic circuitry, devices, modules, processors, memories, logic solid state and / or discrete devices, computer programs or instructions for carrying out respective tasks, procedures, computations, outputs, and / or displaying functions, and so on, as such as those that are described herein.

[0384] Any appropriate steps, methods, features, functions, or benefits disclosed herein may be performed through one or more functional units or modules of one or more virtual apparatuses. Each virtual apparatus may comprise a number of these functional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processor (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as Read Only Memory (ROM), Random Access Memory (RAM), cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory includes program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein. In some implementations, the processing circuitry may be used to cause the respective functional unit to perform corresponding functions according to one or more embodiments of the present disclosure.

[0385] As described herein, device and / or apparatus can be represented by a semiconductor chip, a chipset, or a (hardware) module comprising such chip or chipset; this, however, does not exclude the possibility that a functionality of a device or apparatus, instead of being hardware implemented, be implemented as a software module such as a computer program or a computer program product comprising executable software code portions for execution or being run on a processor. Furthermore, functionality of a device or apparatus can be implemented by any combination of hardware and software. A device or apparatus can also be regarded as an assembly of multiple devices and / or apparatuses, whether functionally in cooperation with or independently of each other. Moreover, devices and apparatuses can be implemented in a distributed fashion throughout a system, so long as the functionality of the device or apparatus is preserved. Such and similar principles are considered as known to a skilled person.

[0386] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs. It will be further understood that terms used herein should be interpreted as having a meaning that is consistent with their meaning in the context of this specification and the relevant art and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein.

[0387] In addition, certain terms used in the present disclosure, including the specification and drawings, can be used synonymously in certain instances (e.g., “data” and “information”). It should be understood, that although these terms (and / or other terms that can be synonymous to one another) can be used synonymously herein, there can be instances when such words can be intended to not be used synonymously. *** Start text from Change Request (CR) Solution #3: Security of multi -hop UE-to-Network Relay discovery Model B***

[0388] 2 REFERENCES

[0389] [1] 3GPP TR 23.700-03 : " Study on system enhancement for Proximity based Services

[0390] (ProSe) in the 5G System (5GS); Phase 3".

[0391] 3 RATIONALE

[0392] Solution #3 includes the following Editor's Notes:

[0393] Editor’s Note: How to retrieve the corresponding relay discovery security material and the intermediate relay discovery security material is FFS.

[0394] To retrieve relay discovery security material, the solution reuses the procedure of clause 6.1.3.2.2.2 of TS 33.503[5],

[0395] To retrieve intermediate relay discovery security material, the solution uses the procedure of clause 6.1.3.2.2.2 of TS 33.503[5] for 5G ProSe UE-to-Network Relay as baseline with extension. A flow is added in the solution to show the extension compared to the existing relay discovery key request procedure.

[0396] It is also clarified that the intermediate relay discovery security material associated with the intermediate U2N #n is identified based on the HPLMN ID of the intermediate U2N #n.

[0397] Editor’s Note: How the solution protects the path information during the discovery of multi-hop U2N relay is FFS.

[0398] In this solution, the path (hop) information included by the original sending UE (i.e. the Remote UE or the 5G ProSe U2N) is protected by the relay discovery security material. The path (hop) information inserted by the forwarding intermediate 5G ProSe U2N is protected by the intermediate relay discovery security material. Thus it ensures the trustworthiness of path (hop) information during the discovery procedure.

[0399] This contribution proposes to resolve the above ENs about the solution. It also proposes to remove the following EN:

[0400] Editor's Note: Further evaluation is FFS

[0401] 4 DETAILED PROPOSAL

[0402] 4444START of CHANGE4444

[0403] 6.3 Solution #3: Security of multi-hop UE-to-Network Relay discovery Model B

[0404] 6.3.1 Introduction

[0405] This solution addresses key issue #1 : Security for multi-hop UE-to-Network Relay.

[0406] The Discoveree 5G ProSe U2N and the Discoverer 5G ProSe Remote UE performs protected relay discovery as specified in clause 6.3.2.3.3 of TS 23.304 (vl9.1.0) and clause 6.1.3.2.2.2 of TS 33.503 (vl 8.4.0). With respect to the previous statement, clause 6.3.2.3.2 of TS 23.304 (vl9.1.0) and clause 6.1.3.2.2.1 of TS 33.503 (vl8.4.0) uses the terms "Announcing UE" and "Monitoring UE" and in the context of the Rel-19 study these roles are assumed to be taken by the 5G ProSe Layer-3 U2N Relay and the Remote UE respectively. The information included by the original sending UE (i.e. The Remote UE and the 5G ProSe U2N) e.g. RSC, User info of the Remote UE, User info of the 5G ProSe U2N, the selected path info (the list of User Info IDs of intermediate Relays in the path) is protected by the relay discovery security material.

[0407] The intermediate U2N can relay and forward the discovery Solicitation / Response messages sent by the Discoveree 5G ProSe U2N and the Discoverer 5G ProSe Remote UE. The intermediate U2N can additionally insert necessary information (e.g. by including its own User Info ID in the path) required to support multi-hop U2N relay in the forwarded messages. To protect the integrity and / or confidentiality of the information inserted / updated by the intermediate U2N, the intermediate U2N needs to obtain also a set of relay discovery security material from its own HPLMN, called as intermediate relay discovery security material in this solution for brevity. So that the forwarded relay discovery messages contain both original relay discovery Solicitation / Response message protected by the relay discovery security material associated with the Discoveree U2N and also the additional information protected by the intermediate relay discovery security material associated with the intermediate U2N. The intermediate relay discovery security material associated with the intermediate U2N #n is identified based on the HPLMN ID of the intermediate U2N #n.

[0408] NOTE: The complete additional information (e.g. hop count) updated by the intermediate U2N that is required for multi-hop U2N relay is to be defined by SA2.

[0409] NOTE: There could be one or more intermediate U2Ns in the discovery message path. The maximum number of intermediate U2N(s) in the path is to be defined by SA2. This solution shows only two intermediate U2Ns as example.

[0410] There could be possibly additional input parameters or extensions to security material provisioning procedure of 6.1.3.2.2.1 of TS 33.503 needed to differentiate the intermediate relay discovery security material with the relay discovery security material.

[0411] 6,3,2 Solution details

[0412] The security procedure for multiple hop 5G ProSe UE-to-Network Relay Discovery with Model B is described as follows. Oa.The discoveree 5G ProSe U2N is provisioned with the relay discovery security materials from its HPLMN, acting as discoveree UE as specified in clause 6.1.3.2.2.2 of TS 33.503[5],

[0413] Each intermediate 5G ProSe U2N(s) and the remote UE are provisioned with the relay discovery security materials associated with discoveree U2N, acting as discoverer UE as specified in clause 6.1.3.2.2.2 of TS 33.503 [5].

[0414] NOTE 1 : The intermediate U2N (s) and the Remote UE are provisioned with the U2N discovery security material to verify the integrity of the information originally sent by the 5G ProSe U2N, e.g. RSC, User info of the 5G ProSe U2N, the selected path info (the list of User Info IDs of intermediate Relays in the path) etc..

[0415] Ob. Each 5G ProSe intermediate U2N UE (e.g. U2N #1, U2N #2) is also provisioned with the intermediate relay discovery security material used for protection of the forwarded discovery Solicitation / Response messages from its own HPLMN, acting as discoveree UE as specified in clause 6.1.3.2.2.2 of TS 33.503 [5].

[0416] The neighbors of this intermediate 5G ProSe U2N(other intermediate 5G ProSe U2N(s), the remote UE or the 5G ProSe U2N) The 5G ProSe intermediate U2N, the discoveree 5G ProSe U2N and the remote UE are also provisioned with the intermediate relay discovery security materials associated with the neighbouring intermediate U2Ns, acting as discoverer UE as specified in clause 6.1.3.2.2.2 of TS 33.503[5],

[0417] See clause 6.3.2.1 for provisioning of the intermediate relay discovery security material for Model B.

[0418] 1. The discoverer Remote UE reuses the 5G ProSe UE-to-Network Relay Discovery Solicitation message as specified in clause 6.1.3.2.2.2 of TS 33.503 [5] with the information e.g. RSC, User info of the sending Remote UE, optionally User info of the target 5G ProSe U2N required for multi -hop U2N relay and protects the message with relay discovery security material obtained from step 0a. The Discovery Solicitation message also includes the HPLMN ID of the discoveree U2N in cleartext to identify the relay discovery security materials.

[0419] 2. The intermediate U2N #1 receives the protected Relay Discovery Solicitation message, obtains the RSC and verifies the Relay Discovery Solicitation message based on the relay discovery security material associated with the discoveree U2N obtained from step 0a. If the verification is successful, the intermediate U2N #1 includes its own User Info ID in the path and forwards the original Relay Discovery Solicitation message with the additional information (e.g. updated path info). The forwarded message is protected by the intermediate relay discovery security material that the intermediate U2N #1 obtained from its HPLMN from step 0b. The intermediate U2N #1 also includes it's Home PLMN ID in clear text in the forwarded message to identify the intermediate discovery security material associated with the intermediate U2N #1.

[0420] 3. The intermediate U2N #2 received the protected message, obtains the RSC and verifies the original Relay Discovery Solicitation message based on the relay discovery security material associated with the discoveree U2N obtained from step 0a and the additional information based on intermediate relay discovery security material associated with the intermediate U2N #1 which was obtained from step Ob. The intermediate U2N #2 identifies the intermediate relay discovery security material associated with the intermediate U2N #1 based on the clear text HPLMN ID included by the intermediate U2N #1 in step 2. If the verification is successful, the intermediate U2N #2 updates includes its own User Info ID in the path and forwards the original Relay Discovery Solicitation message with the additional information (e.g. updated path info). The forwarded message is protected by the intermediate relay discovery security material that the intermediate U2N #2 obtained from its HPLMN from step Ob. The intermediate U2N #2 also includes it's Home PLMN ID in clear text in the forwarded message to identify the intermediate discovery security material associated with the intermediate U2N #2.

[0421] 4. On receiving the Relay Discovery Solicitation message from the intermediate U2N #2 , the discoveree 5G ProSe U2N verifies the received Relay Discovery Solicitation message using the relay discovery security material associated with the discoveree U2N obtained from step 0a and the additional information based on intermediate relay discovery security material associated with the intermediate U2N #2 which was obtained from step Ob. The discoveree 5G ProSe U2N identifies the intermediate relay discovery security material associated with the intermediate U2N #2 based on the clear text HPLMN ID included by the intermediate U2N #2 in step 3. If the verification is successful, the discoveree 5G ProSe U2N shall process the Relay Discovery Solicitation message as specified in clause 6.1.3.2.2.2 of TS 33.503 [5].

[0422] 5. The discoveree U2N reuses the 5G ProSe UE-to-Network Relay Discovery Response message as specified in clause 6.1.3.2.2.2 of TS 33.503 [5] with the information e.g. RSC, User info of the 5G ProSe U2N, the selected path info (the list of User Info IDs of intermediate Relays in the path) required for multi-hop U2N relay and protects the message with relay discovery security material obtained from step 0a.

[0423] 6. The intermediate U2N #2 verifies the protected Relay Discovery Response message and forward the message with the updated additional information if available and protect the forwarded message with the intermediate relay discovery security material that the intermediate U2N #2 obtained from its HPLMN from step 0b, same as step 3. In addition, the intermediate U2N #2 includes it's Home PLMN ID in clear text in the forwarded message to identify the intermediate discovery security material associated with the intermediate U2N #2.

[0424] 7. The intermediate U2N #1 verifies the protected Relay Discovery Response message. The intermediate U2N #1 identifies the intermediate relay discovery security material associated with the intermediate U2N #2 based on the clear text HPLMN ID included by the intermediate U2N #2 in step 6. The intermediate U2N #1 forwards the message with the updated additional information if available and protect the forwarded message with the intermediate relay discovery security material that the intermediate U2N #1 obtained from its HPLMN from step 0b, same as step 2. In addition, the intermediate U2N #1 includes it's Home PLMN in clear text in the forwarded message to identify the intermediate discovery security material associated with the intermediate U2N #1.

[0425] 8. On receiving the Relay Discovery Response message from the intermediate U2N #1 , the discoverer 5G ProSe Remote UE verifies the received Relay Discovery Response message using the relay discovery security material associated with the discoveree U2N obtained from step 0a and the additional information based on intermediate relay discovery security material associated with the intermediate U2N #1 which was obtained from step Ob. The discoverer 5G ProSe Remote UE identifies the intermediate relay discovery security material associated with the intermediate U2N #1 based on the clear text HPLMN ID included by the intermediate U2N #1 in step 7. If the verification is successful, the discoverer 5G ProSe Remote UE shall process the Relay Discovery Response message as specified in clause 6.1.3.2.2.2 of TS 33.503 [5].

[0426] The security procedure to retrieve intermediate relay discovery security material uses the procedure of clause 6.1.3.2.2.1 of TS 33.503 [5] for 5G ProSe UE-to-Network Relay as baseline with extension. Differences to clause 6.1.3.2.2.1 of TS 33.503 are mentioned below:

[0427] Each sending intermediate 5G ProSe U2N acts as announcing UE of clause 6.1.3.2.2.1 of TS

[0428] 33.503 [5], and the neighbours of this intermediate 5G ProSe U2N(other intermediate 5G

[0429] ProSe U2N(s), or the 5G ProSe Remote UE etc.) receiving forwarded message act as

[0430] Monitoring UEs. They are called as sending UE and receiving UE accordingly.

[0431] Steps 1-4 refer to a sending UE (e.g. intermediate U2N #1);

[0432] Stepl, the Relay Discovery Key request message also includes an indication that intermediate relay discovery security material is requested.

[0433] Step4, the Relay Discovery Key response message contains the intermediate relay discovery security materials associated with the HPLMN ID of the sending UE (intermediate U2N #1) Steps 5-10 refer to a receiving UE(e.g. intermediate U2N #2);

[0434] Step5,7, the Relay Discovery Key request message also includes an indication that intermediate relay discovery security material is requested.

[0435] Step9,10, the Relay Discovery Key response message contains the intermediate relay discovery security materials and the HPLMN ID of the sending UE (intermediate U2N #1).

[0436] NOTE 2: The sending or receiving UE role for intermediate U2N (s) in multi -hop U2N discovery Model B procedure depends on which entity forwards the discovery Solicitation and / or discovery Response message. E.g. the intermediate U2N #1 is the sending UE and the intermediate U2N #2 is the receiving UE when the intermediate U2N #1 forwards the discovery Solicitation message to the intermediate U2N #2. In the other direction, the intermediate U2N #1 is the receiving UE and the intermediate U2N #2 is the sending UE when the intermediate U2N #2 forwards the discovery Response message to the intermediate U2N #1.

[0437] 6,3,3 Evaluation

[0438] The solution addresses key issue #1 and provides methods for security protection (confidentiality protection, integrity protection and replay protection, and mitigating trackability and linkability attacks) of multi-hop UE-to-Network Relay discovery Model B.

[0439] The solution proposes to reuse the existing Restricted 5G ProSe UE-to-Network Discovery Model B security methods, with extensions to support two sets of discovery security material i.e. the relay discovery security material and the intermediate relay discovery security material.

[0440] *** End text from Change Request (CR) Solution #3: Security of multi -hop UE-to-Network Relay discovery Model B***

[0441] *** Start text from Change Request (CR) Solution #2: Security of multi -hop UE-to-Network Relay discovery Model A ***

[0442] 2 REFERENCES

[0443] [1] 3GPP TR 23.700-03 : " Study on system enhancement for Proximity based Services (ProSe) in the 5G System (5GS); Phase 3".

[0444] 3 RATIONALE

[0445] Solution #2 includes the following Editor Notes:

[0446] Editor’s Note: How to retrieve the corresponding relay discovery security material and the intermediate relay discovery security material is FFS.

[0447] To retrieve relay discovery security material, it reuses the procedure of clause 6.1.3.2.2.1 of TS 33.503[5],

[0448] To retrieve intermediate relay discovery security material, this solution uses the procedure of clause 6.1.3.2.2.1 of TS 33.503[5] for 5G ProSe UE-to-Network Relay as baseline with extension. A flow is added in the solution to show the extension compared to the existing relay discovery key request procedure.

[0449] It is also clarified that the intermediate relay discovery security material associated with the intermediate U2N #n is identified based on the HPLMN ID of the intermediate U2N #n.

[0450] Editor’s Note: How the solution protects the path information during the discovery of multi-hop U2N relay is FFS.

[0451] In this solution, the path (hop) information included by the original announcing 5G ProSe U2N is protected by the relay discovery security material. The path (hop) information inserted by the forwarding intermediate 5G ProSe U2N is protected by the intermediate relay discovery security material. Thus it ensures the trustworthiness of path (hop) information during the discovery procedure.

[0452] This contribution proposes to resolve the above ENs about the solution. It also proposes to remove the following EN: Editor's Note: Further evaluation is FFS

[0453] 4 DETAILED PROPOSAL

[0454] 4444START of CHANGE4444

[0455] 6.2 Solution #2: Security of multi-hop UE-to-Network Relay discovery Model A

[0456] 6,2, 1 Introduction

[0457] This solution addresses key issue #1 : Security for multi-hop UE-to-Network Relay.

[0458] The announcing 5G ProSe U2N and the monitoring 5G ProSe Remote UE performs protected relay discovery as specified in clause 6.3.2.3.2 of TS 23.304 [4] and clause 6.1.3.2.2.1 of TS 33.503 [5], The information included by the original announcing 5G ProSe U2N e.g. RSC, User info of the announcing 5G ProSe U2N, Accumulated QoS is protected by the relay discovery security material.

[0459] The intermediate U2N can relay and forward the discovery Announcement message sent by the announcing 5G ProSe U2N. The intermediate U2N can additionally insert necessary information (e.g. hop count, Announcer Info (User info of the intermediate U2N)) required to support multi-hop U2N relay in the forwarded messages.

[0460] To protect the integrity and / or confidentiality of the information inserted / updated by the intermediate U2N, the intermediate U2N needs to obtain also a set of relay discovery security material from its own HPLMN, called as intermediate relay discovery security material in this solution for brevity. So that the forwarded relay discovery message contains both original relay discovery announcement message protected by the relay discovery security material associated with the announcing U2N and also the additional information protected by the intermediate relay discovery security material associated with the intermediate U2N. The intermediate relay discovery security material associated with the intermediate U2N #n is identified based on the HPLMN ID of the intermediate U2N #n.

[0461] NOTE 1 : The complete additional information (e.g. hop count) updated by the intermediate U2N that is required for multi-hop U2N relay discovery is to be defined by SA2.

[0462] NOTE 2: There could be one or more intermediate U2Ns in the discovery message path. The maximum number of intermediate U2N(s) in the path is to be defined by SA2. This solution shows only two intermediate U2Ns as example.

[0463] There could be possibly additional input parameters or extensions to security material provisioning procedure of 6.1.3.2.2.1 of TS 33.503 needed to differentiate the intermediate relay discovery security material with the relay discovery security material. 6,2.2 Solution details

[0464] The security procedure for multiple hop 5G ProSe UE-to-Network Relay Discovery with Model A is described as follows.

[0465] Oa. The announcing 5G ProSe U2N is provisioned with the relay discovery security materials from its HPLMN as acting as Announcing UE specified in clause 6.1.3.2.2.1 of TS 33.503[5],

[0466] Each intermediate 5G ProSe U2N(s) and the remote UE are provisioned with the relay discovery security materials associated with announcing U2N acting as Monitoring UE as specified in clause 6.1.3.2.2.1 of TS 33.503[5],

[0467] NOTE 1 : The intermediate U2N(s) and the Remote UE are provisioned with the U2N discovery security material to verify the integrity of the information originally announced by the 5G ProSe U2N, e.g. RSC, User info of the 5G ProSe U2N, Accumulated QoS if available etc.

[0468] Ob. Each 5G ProSe intermediate U2N UE (e.g. U2N #1, U2N #2) is also provisioned with the intermediate relay discovery security material used for protection of the forwarded announcement message from its own HPLMN, acting as announcing UE as specified in clause 6.1.3.2.2.1 of TS 33.503 [5],

[0469] The neighbors of this intermediate 5G ProSe U2N(other intermediate 5G ProSe U2N(s), the remote UE or the 5G ProSe U2N) are also provisioned with the intermediate relay discovery security materials associated with this intermediate U2N, acting as Monitoring UE as specified in clause 6.1.3.2.2.1 of TS 33.503 [5],

[0470] See clause 6.2.2.1 for provisioning of the intermediate relay discovery security material for Model A.

[0471] 1. The announcing U2N reuses the 5G ProSe UE-to-Network Relay Discovery Announcement message as Discovery Solicitation specified in clause 6.1.3.2.2.1 of TS 33.503 [5] with the information e.g. hop count=l, RSC, User info of the announcing 5G ProSe U2N, Accumulated QoS required for multi-hop U2N relay and protects the message with relay discovery security material obtained from step 0a. The announcing message also includes the HPLMN ID of the announcing U2N in cleartext to identify the relay discovery security materials as specified in clause 6.1.3.2.2.1 of TS 33.503 [5].

[0472] 2. The intermediate U2N #1 receives the protected announcement message, obtains the information originally announced by the 5G ProSe U2N e.g. RSC and the User info of the 5G ProSe U2N and verifies the Announcement message based on the relay discovery security material associated with the announcing U2N obtained from step 0a. If the verification is successful, the intermediate U2N #1 updates the hop information (e.g. hop count) and forwards the original Announcement message with the additional information (e.g. updated hop count and its own User info ID as Announcer Info). The forwarded message is protected by the intermediate relay discovery security material that the intermediate U2N #1 obtained from its HPLMN from step Ob. The intermediate U2N #1 also includes it's Home PLMN ID in clear text in the forwarded message to identify the intermediate discovery security material. 3. The intermediate U2N #2 received the protected message, obtains the information originally announced by the 5G ProSe U2N e.g. RSC and the User info of the 5G ProSe U2N and verifies the original Announcement message based on the relay discovery security material associated with the announcing U2N obtained from step Oa and the additional information inserted by the sending intermediate U2N #1 (e.g. hop count, Announcer Info) based on intermediate relay discovery security material associated with the intermediate U2N #1 which was obtained from step Ob. The intermediate U2N #2 identifies the intermediate relay discovery security material associated with the intermediate U2N #1 based on the clear text HPLMN ID included by the intermediate U2N #1 in step 2. If the verification is successful, the intermediate U2N #2 stores the received information (e.g. a record of the RSC, the User info of the 5G ProSe U2N, Announcer Info and the associated Hop-Count value), updates the hop information (e.g. hop count) and forwards the original Announcement message with the additional information (e.g. updated hop count and its own User info ID as Announcer Info). The forwarded message is protected by the intermediate relay discovery security material that the intermediate U2N #2 obtained from its HPLMN from step Ob. The intermediate U2N #2 also includes it's Home PLMN ID in clear text in the forwarded message to identify the intermediate discovery security material.

[0473] 4. On receiving the Announcement message from the intermediate U2N #2 , the monitoring 5G ProSe Remote UE obtains the information originally announced by the 5G ProSe U2N e.g. RSC and the User info of the 5G ProSe U2N, identifies the relay discovery security materials to process the original discovery message based on the HPLMN ID of the announcing U2N included in the discovery message as in stepl and verifies the received Announcement message using the relay discovery security material associated with the announcing U2N obtained from step Oa. The monitoring 5G ProSe Remote UE also identifies the intermediate relay discovery security material associated with the intermediate U2N #2 based on the clear text HPLMN ID included by the intermediate U2N #2 in step 3, obtains and verifies the additional information inserted by the sending intermediate U2N #2 (e.g. hop count, Announcer Info) based on intermediate relay discovery security material associated with the intermediate U2N #2 which was obtained from step Ob. If the verification is successful, the monitoring 5G ProSe Remote UE shall process the relay announcement message as specified in clause 6.1.3.2.2.1 of TS 33.503[5],

[0474] The security procedure to retrieve intermediate relay discovery security material uses the procedure of clause 6.1.3.2.2.1 of TS 33.503 [5] for 5G ProSe UE-to-Network Relay as baseline with extension. Differences to clause 6.1.3.2.2.1 of TS 33.503 are mentioned below: Each sending intermediate 5G ProSe U2N acts as announcing UE of clause 6.1.3.2.2.1 of TS 33.503 [5], and the neighbours of this intermediate 5G ProSe U2N(other intermediate 5G ProSe U2N(s), or the 5G ProSe Remote UE etc.) receiving forwarded message act as Monitoring UEs. They are called as sending UE and receiving UE accordingly. Steps 1-4 refer to a sending UE (e.g. intermediate U2N #1);

[0475] Stepl, the Relay Discovery Key request message also includes an indication that intermediate relay discovery security material is requested.

[0476] Step4, the Relay Discovery Key response message contains the intermediate relay discovery security materials associated with the HPLMN ID of the sending UE (intermediate U2N #1) Steps 5-10 refer to a receiving UE(e.g. intermediate U2N #2);

[0477] Step5,7, the Relay Discovery Key request message also includes an indication that intermediate relay discovery security material is requested.

[0478] Step9,10, the Relay Discovery Key response message contains the intermediate relay discovery security materials and the HPLMN ID of the sending UE (intermediate U2N #1).

[0479] 6,2,3 Evaluation

[0480] The solution addresses key issue #1 and provides methods for security protection (confidentiality protection, integrity protection and replay protection, and mitigating trackability and linkability attacks) of multi-hop UE-to-Network Relay discovery Model A. The solution proposes to reuse the existing Restricted 5G ProSe UE-to-Network Discovery Model A security methods, with extensions to support two sets of discovery security material i.e. the relay discovery security material and the intermediate relay discovery security material.

[0481] *** End text from Change Request (CR) Solution #2: Security of multi -hop UE-to-Network Relay discovery Model A ***

[0482] EMBODIMENTS

[0483] Group A Embodiments

[0484] Al . A method performed by a first user equipment (UE) arranged to discover intermediate UE-to-network (U2N) relays that facilitate access to a communication network via a U2N relay, the method comprising: obtaining the following security material from the first UE’s home public land mobile network (HPLMN): relay discovery security materials associated with a second UE configured to operate as the U2N relay; and intermediate relay discovery security materials associated with a third UE configured to operate as an intermediate U2N relay between the first UE and the second UE and an associated HPLMN identification (ID) of the third UE; receiving from the third UE a message associated with multi-hop relay discovery, wherein the message includes a first portion generated by the third UE, a second portion generated by the second UE and the HPLMN ID of the third UEs HPLMN in clear text; verifying the following: the first portion based on the intermediate relay discovery security materials associated with the third UE, and the second portion based on the relay discovery security materials associated with the second UE, wherein the security materials associated with the third UE are identified by the first UE based on the HPLMN ID of the third UE; and based on successful verification of the first portion, and the second portion, processing the message.

[0485] A2. The method of embodiment Al, wherein obtaining the intermediate relay discovery security materials associated with the third UE and the associated HPLMN ID of the third UE comprises: sending to the first UE’s HPLMN a request for the intermediate relay discovery security materials, wherein the request comprises an indication of: whether the first UE requests the intermediate relay discovery security materials for an intermediate U2N relay, and whether the first UE is acting as: a source intermediate U2N relay and / or one of: a target intermediate U2N relay, a target U2N relay, or a target Remote UE, and in response to the request, obtaining from the first UE’s HPLMN the intermediate relay discovery security material associated with the third UE and the associated HPLMN ID of the third UE;

[0486] A3. The method of any of embodiments A1-A2, wherein the first UE is a Monitoring Remote UE and the message is an Announcement.

[0487] A4. The method of any of embodiments A1-A2, wherein the first UE is a Discoverer Remote UE and the message is a Discovery Response.

[0488] Group B Embodiments

[0489] Bl. A method for a second user equipment (UE) arranged to provide a UE-to-network (U2N) relay between intermediate U2N relays and a communication network, the method comprising: obtaining the following security material from the second UE’s home public land mobile network (HPLMN): relay discovery security materials associated with the second UE; and intermediate relay discovery security materials associated with a third UE configured to operate as an intermediate U2N relay and an associated HPLMN identification (ID) of the third UE; receiving from the third UE a message associated with multi-hop relay discovery, wherein the message includes a first portion generated by the third UE, a second portion generated by the first UE and the HPLMN ID of the third UEs HPLMN in clear text; verifying the following: the first portion based on the intermediate relay discovery security materials associated with the third UE, and the second portion based on the relay discovery security materials associated with the second UE, wherein the security materials associated with the third UE are identified by the second UE based on the HPLMN ID of the third UE; and based on successful verification of the first portion, and the second portion, processing the message.

[0490] B2. The method of embodiment Bl, wherein obtaining the intermediate relay discovery security materials associated with the third UE and the associated HPLMN ID of the third UE comprises: sending to the second UE’s HPLMN a request for the intermediate relay discovery security materials, wherein the request comprises an indication of: whether the second UE requests the intermediate relay discovery security materials for an intermediate U2N relay, and whether the second UE is acting as: a source intermediate U2N relay and / or one of: a target intermediate U2N relay, a target U2N relay, or a target Remote UE, and in response to the request, obtaining from the second UE’s HPLMN the intermediate relay discovery security material associated with the third UE and the associated HPLMN ID of the third UE.

[0491] B3. The method of any of embodiments Bl -B2, wherein the second UE is a Discoveree U2N Relay and the secure message is a Discovery Solicitation message.

[0492] C Embodiments

[0493] Cl . A method for a third user equipment (UE) arranged to provide an intermediate UE-to- network (U2N) relay between remote UEs and a U2N relay coupled to communication network, the method comprising: receiving a first message associated with multi-hop relay discovery, wherein the first message includes a second portion generated by a message source UE, a first portion generated by one of the following: the message source UE, or a fourth UE arranged as an intermediate U2N relay between the message source UE and the third UE, and when the first portion is generated by the fourth UE a home public land mobile network identification (HPLMN ID) of the fourth UE’s HPLMN in clear text, verifying the first portion based on one of the following: relay discovery security materials associated with a second UE arranged to provide the U2N relay; or intermediate relay discovery security materials associated with the fourth UE, wherein the intermediate relay discovery security materials associated with the fourth UE are identified by the third UE based on the HPLMN ID of the third UE; verifying the second portion based on the relay discovery security materials associated with the message source UE; based on successful verification of the first and second portions, updating the first portion and securing the updated first portion using the intermediate relay discovery security materials associated with the third UE; and sending a second message including the second portion, the secured updated first portion and the HPLMN ID of the third UE’s HPLMN to one of the following: a message target UE, or a fifth UE arranged as an intermediate U2N relay between the message target UE and the third UE.

[0494] C2. The method of embodiment Cl, wherein the first portion includes a hop count and the second portion includes a relay service code (RSC), and updating the first portion includes incrementing the hop count.

[0495] C3. The method of embodiment C2, wherein the hop count was generated by the message source UE and updated by the fourth UE.

[0496] C4. The method of any of the embodiments Cl - C3, further comprising: obtaining from the third UE’s HPLMN one or more of the relay discovery security materials associated with the second UE; the intermediate relay discovery security materials associated with the third UE; and the intermediate relay discovery security materials associated with the fourth UE.

[0497] C5. The method of embodiment C4, wherein obtaining the intermediate relay discovery security materials associated with an intermediate U2N relay comprises: sending to the third UE’s HPLMN a request for the intermediate relay discovery security materials, wherein the request comprises an indication of: whether the third UE requests the intermediate relay discovery security materials for an intermediate U2N relay, and whether the third UE is acting as: a source intermediate U2N relay and / or one of: a target intermediate U2N relay, a target U2N relay, or a target Remote UE, and in response to the request, obtaining from the third UE’s HPLMN the intermediate relay discovery security material associated with the UE arranged as an intermediate U2N relay, and the associated HPLMN ID of the UE arranged as an intermediate U2N relay.

[0498] C6. The method of any of embodiments C1-C5, wherein the first and second messages are Announcement messages, and the message source UE is the second UE arranged as an Announcing U2N Relay. C7. The method of any of embodiments C1-C6, wherein the first and second messages are Discovery Response messages, and the message source UE is the second UE arranged as a Discoveree U2N Relay.

[0499] C8. The method of any of embodiments C1-C7, wherein the first and second messages are Discovery Solicitation messages, and the message source UE is a first UE arranged as a Discoverer Remote UE.

[0500] DI . A first user equipment (UE) arranged to discover intermediate UE-to-network (U2N) relays that facilitate access to a communication network via a U2N relay, the first UE comprising: communication interface circuitry configured to communicate with other UEs configured as intermediate U2N relays; and processing circuitry operatively coupled to the communication interface circuitry, whereby the processing circuitry and the communication interface circuitry are configured to perform operations corresponding to any of the methods of embodiments A1-A4.

[0501] D2. A first user equipment (UE) arranged to discover intermediate UE-to-network (U2N) relays that facilitate access to a communication network via a U2N relay, the first UE being configured to perform operations corresponding to any of the methods of embodiments Al- A4.

[0502] D3. A non-transitory, computer-readable medium storing computer-executable instructions that, when executed by processing circuitry of a first user equipment (UE) arranged to discover intermediate UE-to-network (U2N) relays that facilitate access to a communication network via a U2N relay, configure the first UE to perform operations corresponding to any of the methods of embodiments A1-A4.

[0503] D4. A computer program product comprising computer-executable instructions that, when executed by processing circuitry of a first user equipment (UE) arranged to discover intermediate UE-to-network (U2N) relays that facilitate access to a communication network via a U2N relay, configure the first UE to perform operations corresponding to any of the methods of embodiments A1-A4.

[0504] El. A second user equipment (UE) arranged to provide a UE-to-network (U2N) relay between intermediate U2N relays and a communication network, the second UE comprising: communication interface circuitry configured to communicate with other UEs configured as intermediate U2N relays; and processing circuitry operatively coupled to the communication interface circuitry, whereby the processing circuitry and the communication interface circuitry are configured to perform operations corresponding to any of the methods of embodiments B 1 -B3.

[0505] E2. A second user equipment (UE) arranged to provide a UE-to-network (U2N) relay between intermediate U2N relays and a communication network, the second UE being configured to perform operations corresponding to any of the methods of embodiments BIBS.

[0506] E3. A non-transitory, computer-readable medium storing computer-executable instructions that, when executed by processing circuitry of a second user equipment (UE) arranged to provide a UE-to-network (U2N) relay between intermediate U2N relays and a communication network, configure the UE to perform operations corresponding to any of the methods of embodiments B1-B3.

[0507] E4. A computer program product comprising computer-executable instructions that, when executed by processing circuitry of a second user equipment (UE) arranged to provide a UE- to-network (U2N) relay between intermediate U2N relays and a communication network, configure the UE to perform operations corresponding to any of the methods of embodiments B1-B3.

[0508] Fl. A third user equipment (UE) arranged to provide an intermediate UE-to-network (U2N) relay between remote UEs and a U2N relay coupled to communication network, the third UE comprising: communication interface circuitry configured to communicate with other UEs configured as remote UEs, intermediate U2N relays, or U2N relays coupled to communication network; and processing circuitry operatively coupled to the communication interface circuitry, whereby the processing circuitry and the communication interface circuitry are configured to perform operations corresponding to any of the methods of embodiments C1-C8.

[0509] F2. A third user equipment (UE) arranged to provide an intermediate UE-to-network (U2N) relay between remote UEs and a U2N relay coupled to communication network, the third UE being configured to perform operations corresponding to any of the methods of embodiments C1-C8.

[0510] F3. A non-transitory, computer-readable medium storing computer-executable instructions that, when executed by processing circuitry of a third user equipment (UE) arranged to provide an intermediate UE-to-network (U2N) relay between remote UEs and a U2N relay coupled to communication network, configure the third UE to perform operations corresponding to any of the methods of embodiments C1-C8.

[0511] F4. A computer program product comprising computer-executable instructions that, when executed by processing circuitry of a third user equipment (UE) arranged to provide an intermediate UE-to-network (U2N) relay between remote UEs and a U2N relay coupled to communication network, configure the third UE to perform operations corresponding to any of the methods of embodiments C1-C8.

Claims

CLAIMS1. A method performed by a first user equipment (UE) configured to discover intermediate UE-to-network (U2N) relays that facilitate access to a communication network via a U2N relay, the method comprising: receiving (1410B), from a third UE configured to operate as an intermediate U2N relay between the first UE and a second UE configured to operate as the U2N relay, a message associated with multi-hop relay discovery, wherein the message includes: a first portion generated by the third UE; a second portion generated by the second UE; and a home public land mobile network (HPLMN) ID in clear text; identifying (1420B), based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message; verifying (143 OB) at least the first portion of the message based on the identified relay discovery security materials; and based on successful verification of at least the first portion, processing (1440B) the message.

2. The method of claim 1, further comprising obtaining multiple sets of relay discovery security materials associated with respective HPLMN IDs, and wherein said identifying comprises identifying the relay discovery security materials based on which to verify at least the first portion of the message as being the relay discovery security materials that are included in whichever one of the sets of relay discovery security materials that is associated with the HPLMN ID included in the message.

3. The method of claim 2, wherein the multiple sets of relay discovery security materials are obtained from an HPLMN of the first UE.

4. The method of any of claims 1-3, wherein: the identified relay discovery security materials include a decryption key associated with the HPLMN ID included in the message, and wherein said verifying comprises decrypting at least the first portion of the message using the82decryption key; and / or the identified relay discovery security materials include an integrity protection key associated with the HPLMN ID included in the message, and wherein said verifying comprises checking an integrity of at least the first portion of the message using the integrity protection key.

5. The method of any of claims 1-4, wherein the first portion of the message includes hop information for the message associated with the multi-hop relay discovery and / or the second portion of the message includes a Relay Service Code, RSC.

6. The method of any of claims 1-5, wherein: the first UE is a Monitoring Remote UE and the message is an Announcement; or the first UE is a Discoverer Remote UE and the message is a Discovery Response.

7. A method for a second user equipment (UE) configured to provide a UE-to-network (U2N) relay between intermediate U2N relays and a communication network, the method comprising: receiving (1510B), from a third UE configured to operate as an intermediate U2N relay between the second UE and a first UE, a message associated with multihop relay discovery, wherein the message includes: a first portion generated by the third UE; a second portion generated by the first UE; and a home public land mobile network (HPLMN) ID in clear text; identifying (1520B), based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message; verifying (1530B) at least the first portion of the message based on the identified relay discovery security materials; and based on successful verification of at least the first portion, processing (1540B) the message.

8. The method of claim 7, further comprising obtaining multiple sets of relay discovery security materials associated with respective HPLMN IDs, and wherein said identifying comprises identifying the relay discovery security materials based on which to verify at least83the first portion of the message as being the relay discovery security materials that are included in whichever one of the sets of relay discovery security materials that is associated with the HPLMN ID included in the message.

9. The method of claim 8, wherein the multiple sets of relay discovery security materials are obtained from an HPLMN of the second UE.

10. The method of any of claims 7-9, wherein: the identified relay discovery security materials include a decryption key associated with the HPLMN ID included in the message, and wherein said verifying comprises decrypting at least the first portion of the message using the decryption key; and / or the identified relay discovery security materials include an integrity protection key associated with the HPLMN ID included in the message, and wherein said verifying comprises checking an integrity of at least the first portion of the message using the integrity protection key.

11. The method of any of claims 7-10, wherein the first portion of the message includes hop information for the message associated with the multi-hop relay discovery and / or the second portion of the message includes a Relay Service Code, RSC.

12. The method of any of claims 7-11, wherein the second UE is a DiscovereeU2N Relay and the message is a Discovery Solicitation message.

13. A method performed by a third user equipment (UE) configured to provide an intermediate UE-to-network (U2N) relay between a remote UE and a U2N relay for facilitating access to a communication network, the method comprising: receiving (1610B) a first message associated with multi-hop relay discovery, wherein the first message includes: a second portion generated by a message source UE; a first portion generated by the message source UE or a fourth UE configured as an intermediate U2N relay between the message source UE and the third UE; and a home public land mobile network (HPLMN) ID in clear text;84identifying (1620B), based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message; verifying (163 OB) at least the first portion of the message based on the identified relay discovery security materials; and based on successful verification of at least the first portion, processing (1640B) the message.

14. The method of claim 13, wherein processing the message comprises updating the first portion, and wherein the method further comprises sending a second message that includes the second portion, the updated first portion, and the HPLMN ID in clear text, wherein the message is sent to a message target UE or a fifth UE configured as an intermediate U2N relay between the message target UE and the third UE.

15. The method of claim 14, wherein the first portion includes a hop count and wherein updating the first portion includes incrementing the hop count.

16. The method of claim 15, wherein the hop count was generated by the message source UE and updated by the fourth UE.

17. The method of any of claims 13-16, further comprising obtaining multiple sets of relay discovery security materials associated with respective HPLMN IDs, and wherein said identifying comprises identifying the relay discovery security materials based on which to verify at least the first portion of the message as being the relay discovery security materials that are included in whichever one of the sets of relay discovery security materials that is associated with the HPLMN ID included in the message.

18. The method of claim 17, wherein the multiple sets of relay discovery security materials are obtained from an HPLMN of the third UE.

19. The method of any of claims 13-18, wherein: the identified relay discovery security materials include a decryption key associated with the HPLMN ID included in the message, and wherein said verifying comprises decrypting at least the first portion of the message using the85decryption key; and / or the identified relay discovery security materials include an integrity protection key associated with the HPLMN ID included in the message, and wherein said verifying comprises checking an integrity of at least the first portion of the message using the integrity protection key.

20. The method of any of claims 13-19, wherein the first portion of the message includes hop information for the message associated with the multi-hop relay discovery and / or the second portion of the message includes a Relay Service Code, RSC.

21. The method of any of claims 13-20, wherein: the first message is an Announcement message, and the message source UE is the second UE configured as an Announcing U2N Relay; the first message is a Discovery Response message, and the message source UE is the second UE configured as a Discoveree U2N Relay; or the first message is a Discovery Solicitation message, and the message source UE is a first UE configured as a Discoverer Remote UE.

22. A method performed by a third user equipment (UE) configured to provide an intermediate UE-to-network (U2N) relay between a remote UE and a U2N relay for facilitating access to a communication network, the method comprising: receiving (1660B) a first message associated with multi-hop relay discovery, wherein the first message includes: a second portion generated by a message source UE; a first portion generated by the message source UE or a fourth UE configured as an intermediate U2N relay between the message source UE and the third UE; updating (1670B) the first portion of the message; securing (1680B) at least the updated first portion using relay discovery security materials that are associated with a home public land mobile network (HPLMN) ID; and sending (1690B), to a message target UE or a fifth UE configured as an intermediateU2N relay between the message target UE and the third UE, a second message that includes the secured updated first portion, includes the second portion,86and includes the HPLMN ID in clear text.

23. The method of claim 22, wherein the first portion includes a hop count and wherein updating the first portion includes incrementing the hop count.

24. The method of claim 23, wherein the hop count was generated by the message source UE and updated by the fourth UE.

25. The method of any of claims 22-24, wherein the relay discovery security materials include: a decryption key associated with the HPLMN ID; and / or an integrity protection key associated with the HPLMN ID.

26. The method of any of claims 22-25, wherein the first portion of the message includes hop information for the message associated with the multi-hop relay discovery and / or the second portion of the message includes a Relay Service Code, RSC.

27. The method of any of claims 22-25, wherein: the first and second messages are Announcement messages, and the message source UE is the second UE configured as an Announcing U2N Relay; the first and second messages are Discovery Response messages, and the message source UE is the second UE configured as a Discoveree U2N Relay; or the first and second messages are Discovery Solicitation messages, and the message source UE is a first UE configured as a Discoverer Remote UE.

28. A first user equipment (UE) configured to discover intermediate UE-to-network (U2N) relays that facilitate access to a communication network via a U2N relay, the first UE configured to: receive, from a third UE configured to operate as an intermediate U2N relay between the first UE and a second UE configured to operate as the U2N relay, a message associated with multi-hop relay discovery, wherein the message includes: a first portion generated by the third UE; a second portion generated by the second UE; and87a home public land mobile network (HPLMN) ID in clear text; identify, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message; verify at least the first portion of the message based on the identified relay discovery security materials; and based on successful verification of at least the first portion, process the message.

29. The first UE of claim 28, configured to perform the method of any of claims 2-6.

30. A second user equipment (UE) configured to provide a UE-to-network (U2N) relay between intermediate U2N relays and a communication network, the second UE configured to: receive, from a third UE configured to operate as an intermediate U2N relay between the second UE and a first UE, a message associated with multi-hop relay discovery, wherein the message includes: a first portion generated by the third UE; a second portion generated by the first UE; and a home public land mobile network (HPLMN) ID in clear text; identify, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message; verify at least the first portion of the message based on the identified relay discovery security materials; and based on successful verification of at least the first portion, process the message.

31. The second UE of claim 30, configured to perform the method of any of claims 8-12.

32. A third user equipment (UE) configured to provide an intermediate UE-to-network (U2N) relay between a remote UE and a U2N relay for facilitating access to a communication network, the third UE configured to: receive a first message associated with multi-hop relay discovery, wherein the first message includes: a second portion generated by a message source UE; a first portion generated by the message source UE or a fourth UE configured as an intermediate U2N relay between the message source UE and the88third UE; and a home public land mobile network (HPLMN) ID in clear text; identify, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message; verify at least the first portion of the message based on the identified relay discovery security materials; and based on successful verification of at least the first portion, process the message.

33. The third UE of claim 32, configured to perform the method of any of claims 14-21.

34. A third user equipment (UE) configured to provide an intermediate UE-to-network (U2N) relay between a remote UE and a U2N relay for facilitating access to a communication network, the third UE configured to: receive a first message associated with multi-hop relay discovery, wherein the first message includes: a second portion generated by a message source UE; a first portion generated by the message source UE or a fourth UE configured as an intermediate U2N relay between the message source UE and the third UE; update the first portion of the message; secure at least the updated first portion using relay discovery security materials that are associated with a home public land mobile network (HPLMN) ID; and send, to a message target UE or a fifth UE configured as an intermediate U2N relay between the message target UE and the third UE, a second message that includes the secured updated first portion, includes the second portion, and includes the HPLMN ID in clear text.

35. The third UE of claim 34, configured to perform the method of any of claims 23-27.

36. A computer program comprising instructions which, when executed by at least one processor of a first user equipment (UE), causes the first UE to perform the method of any of claims 1-6.

37. A computer program comprising instructions which, when executed by at least oneprocessor of a second user equipment (UE), causes the second UE to perform the method of any of claims 7-12.

38. A computer program comprising instructions which, when executed by at least one processor of a third user equipment (UE), causes the third UE to perform the method of any of claims 14-27.

39. A carrier containing the computer program of any of claims 36-38, wherein the carrier is one of an electronic signal, optical signal, radio signal, or computer readable storage medium.

40. A first user equipment (UE) configured to discover intermediate UE-to-network (U2N) relays that facilitate access to a communication network via a U2N relay, the first UE comprising: communication interface circuitry configured to communicate with other UEs configured as intermediate U2N relays; and processing circuitry operatively coupled to the communication interface circuitry, whereby the processing circuitry and the communication interface circuitry are configured to: receive, from a third UE configured to operate as an intermediate U2N relay between the first UE and a second UE configured to operate as the U2N relay, a message associated with multi-hop relay discovery, wherein the message includes: a first portion generated by the third UE; a second portion generated by the second UE; and a home public land mobile network (HPLMN) ID in clear text; identify, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message; verify at least the first portion of the message based on the identified relay discovery security materials; and based on successful verification of at least the first portion, process the message.

41. The first UE of claim 40, the processing circuitry and the communication interface circuitry configured to perform the method of any of claims 2-6.

42. A second user equipment (UE) configured to provide a UE-to-network (U2N) relay between intermediate U2N relays and a communication network, the second UE comprising: communication interface circuitry configured to communicate with other UEs configured as intermediate U2N relays; and processing circuitry operatively coupled to the communication interface circuitry, whereby the processing circuitry and the communication interface circuitry are configured to: receive, from a third UE configured to operate as an intermediate U2N relay between the second UE and a first UE, a message associated with multi-hop relay discovery, wherein the message includes: a first portion generated by the third UE; a second portion generated by the first UE; and a home public land mobile network (HPLMN) ID in clear text; identify, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message; verify at least the first portion of the message based on the identified relay discovery security materials; and based on successful verification of at least the first portion, process the message.

43. The second UE of claim 42, the processing circuitry and the communication interface circuitry configured to perform the method of any of claims 8-12.

44. A third user equipment (UE) configured to provide an intermediate UE-to-network (U2N) relay between a remote UE and a U2N relay for facilitating access to a communication network, the third UE comprising: communication interface circuitry configured to communicate with other UEs configured as remote UEs, intermediate U2N relays, or U2N relays coupled to communication network; and processing circuitry operatively coupled to the communication interface circuitry,whereby the processing circuitry and the communication interface circuitry are configured to: receive a first message associated with multi-hop relay discovery, wherein the first message includes: a second portion generated by a message source UE; a first portion generated by the message source UE or a fourth UE configured as an intermediate U2N relay between the message source UE and the third UE; and a home public land mobile network (HPLMN) ID in clear text; identify, based on the HPLMN ID included in the message, relay discovery security materials based on which to verify at least the first portion of the message; verify at least the first portion of the message based on the identified relay discovery security materials; and based on successful verification of at least the first portion, process the message.

45. The third UE of claim 44, the processing circuitry and the communication interface circuitry configured to perform the method of any of claims 14-21.

46. A third user equipment (UE) configured to provide an intermediate UE-to-network (U2N) relay between a remote UE and a U2N relay for facilitating access to a communication network, the third UE comprising: communication interface circuitry configured to communicate with other UEs configured as remote UEs, intermediate U2N relays, or U2N relays coupled to communication network; and processing circuitry operatively coupled to the communication interface circuitry, whereby the processing circuitry and the communication interface circuitry are configured to: receive a first message associated with multi-hop relay discovery, wherein the first message includes: a second portion generated by a message source UE; a first portion generated by the message source UE or a fourth UE configured as an intermediate U2N relay between the message92source UE and the third UE; update the first portion of the message; secure at least the updated first portion using relay discovery security materials that are associated with a home public land mobile network (HPLMN) ID; and send, to a message target UE or a fifth UE configured as an intermediate U2N relay between the message target UE and the third UE, a second message that includes the secured updated first portion, includes the second portion, and includes the HPLMN ID in clear text.

47. The third UE of claim 46, the processing circuitry and the communication interface circuitry configured to perform the method of any of claims 23-27.93

Citation Information

Patent Citations

  • Discovery key handling for UE-to-network repeater discovery

    CN116746184A

  • Communication method, device, system and storage medium

    CN118542005A

  • Communication method, relay device, remote terminal and communication system

    CN118592045A

  • Methods and systems for providing home network routing information of remote user equipment (UE) following authentication failure during establishment of UE-to-network (U2N) relay communication

    US20240048981A1