Secrecy of Network Slices with Attribution Control

By encrypting the network slice identifiers by encrypting the encryption key material shared between the wireless device and the home network, the problem of identifier information leakage in the 5G network is solved, and higher security and control are achieved, avoiding additional signaling overhead.

CN114026900BActive Publication Date: 2025-07-08TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080044441.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-06-17
Filing Date
2020-06-16
Publication Date
2025-07-08
Estimated Expiration
2040-06-16

AI Technical Summary

Technical Problem

In the prior art, network slice identifiers lack effective confidentiality protection in 5G networks, resulting in an increased risk of sensitive information leakage, especially when wireless devices and service networks differ from home networks.

Method used

The network slice identifier is encrypted by using encryption key material shared between the wireless device and the home network and refreshing the key material during the authentication process to ensure confidentiality and control of the information belong to the network.

Benefits of technology

Improves the security of network slice identifiers, reduces the risk of sensitive information leakage, and does not require additional signaling overhead or complex mapping maintenance mechanisms, providing full control over the home network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114026900B_ABST
    Figure CN114026900B_ABST
Patent Text Reader

Abstract

A wireless device (12) performs authentication (14) with a home network (10H) of the wireless device (12). The wireless device (12) uses encryption key material (22) to encrypt a network slice identifier (24), where the encryption key material (22) is obtainable from the authentication (14) with the home network (10H) and is shared between the wireless device (12) and the home network (10H). The wireless device (12) sends a message (20) including the encrypted network slice identifier (26). In some embodiments, a network node in a serving network (10S) of the wireless device (12) receives the message (20) and uses the encryption key material (22) to decrypt or request decryption of the encrypted network slice identifier (26), where the encryption key material (22) is obtainable by the wireless device (22) from the authentication (14) of the wireless device (12) with the home network (10H) and is shared between the wireless device (12) and the home network (10H).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application generally relates to wireless communication networks having one or more network slices, and more particularly to network slice secrecy in such networks. Background Art

[0002] A network slice is a logical network that provides specific network capabilities and network characteristics. An operator may deploy multiple network slices to provide different logical networks for providing corresponding different network capabilities and network characteristics. For example, different network slices may be dedicated to different corresponding services, such as Internet of Things (IoT) services, mission-critical services, mobile broadband services, etc. A single wireless device may be served by one or more network slices via an access network. In this regard, for example, when a wireless device requests registration or requests a service from the network, it may identify the network slice to utilize for providing the service. The serving network may then select which network slice to serve the wireless device based on that identification. Summary of the Invention

[0003] Some embodiments herein encrypt network slice identifiers sent by a wireless device to protect the confidentiality of the network slice identifiers. Some embodiments specifically use encryption key material shared between the wireless device and the device's home network and obtainable from the authentication of the device with the home network to do so. Thus, some embodiments advantageously use encryption key material bound to device authentication to protect network slice identifiers. These embodiments can limit the impact of the leaked encryption key material, i.e., the key material will be refreshed after each authentication run. In addition, compared to the case of sharing key material between the device and the device's serving network (which may be different from the home network), the key material shared between the device and the device's home network can advantageously maintain a higher level of security. Alternatively or additionally, the home network can advantageously maintain control of the key material and / or the secrecy of the network slice identifiers.

[0004] More specifically, embodiments herein include a method performed by a wireless device. The method includes performing an authentication of the wireless device with the wireless device's home network. The method also includes encrypting a network slice identifier using encryption key material obtainable from the authentication with the home network and shared between the wireless device and the home network. The method also includes sending a message including the encrypted network slice identifier.

[0005] In some embodiments, the method further includes directly deriving the encryption key material from a key obtainable from the authentication with the home network.

[0006] In some embodiments, the encryption key material includes a key dedicated to encrypting the network slice identifier.

[0007] In some embodiments, the home network is a 5G network, and the encryption key material includes one or more of the following or is directly derived from one or more of the following: a key K that can be obtained from the authentication of the wireless device with the authentication server function AUSF of the home network AUSF ; a cipher key CK; an integrity key IK; or an extended master session key EMSK.

[0008] In some embodiments, the encrypted network slice identifier is included in the access stratum AS part of the message. In other embodiments, the encrypted network slice identifier is included in the non-access stratum NAS part of the message.

[0009] In some embodiments, the network slice identifier includes a single network slice selection assistance information S-NSSAI.

[0010] Embodiments herein also include a method performed by a network node in the serving network of a wireless device. The method includes receiving a message including an encrypted network slice identifier. The method also includes using the encryption key material to decrypt or request the decryption of the encrypted network slice identifier, where the encryption key material can be obtained by the wireless device from the authentication of the wireless device with the home network and is shared between the wireless device and the home network.

[0011] In some embodiments, the serving network is the visited network of the wireless device. In this case, the decrypting or requesting includes requesting the decryption of the encrypted network slice identifier by sending a request including the encrypted network slice identifier to the home network. The method may also include receiving a response to the request from the home network, where the response includes the decrypted network slice identifier.

[0012] In some embodiments, the serving network is the home network (10H), and the decrypting or requesting includes decrypting the encrypted network slice identifier.

[0013] In some embodiments, the method further includes selecting a network slice or an access and mobility management function AMF for serving the wireless device based on the decrypted network slice identifier.

[0014] In some embodiments, the encryption key material is directly derived from a key that can be obtained from the authentication of the wireless device with the home network.

[0015] In some embodiments, the encryption key material includes a key dedicated to encrypting the network slice identifier.

[0016] In some embodiments, the home network is a 5G network, and the encryption key material includes one or more of the following or is directly derived from one or more of the following: a key K that can be obtained from the authentication of the wireless device with the authentication server function AUSF of the home network AUSF ; a cipher key CK; an integrity key IK; or an extended master session key EMSK.

[0017] In some embodiments, the encrypted network slice identifier is included in the access stratum AS part of the message. In other embodiments, the encrypted network slice identifier is included in the non-access stratum NAS part of the message.

[0018] In some embodiments, the network slice identifier includes a single network slice selection assistance information S-NSSAI.

[0019] Embodiments herein also include a method performed by a network node in the home network of a wireless device. The method includes receiving a request to decrypt an encrypted network slice identifier from the serving network of the wireless device. The method also includes decrypting the encrypted network slice identifier using the encryption key material that can be obtained by the wireless device from the authentication of the wireless device with the home network and is shared between the wireless device and the home network. The method further includes: sending a response to the request, the response including the decrypted network slice identifier obtained from the decryption.

[0020] In some embodiments, the method further includes directly deriving the encryption key material from a key that can be obtained from the authentication of the wireless device with the home network.

[0021] In some embodiments, the encryption key material includes a key dedicated to encrypting the network slice identifier.

[0022] In some embodiments, the home network is a 5G network, and the encryption key material includes one or more of the following or is directly derived from one or more of the following: a key K that can be obtained from the authentication of the wireless device with the authentication server function AUSF of the home network AUSF ; a cipher key CK; an integrity key IK; or an extended master session key EMSK.

[0023] Embodiments of the present disclosure also include corresponding apparatuses, computer programs, and carriers of these computer programs. For example, embodiments of the present disclosure include a wireless device, which includes, for example, a communication circuit and a processing circuit. The wireless device is configured to perform authentication of the wireless device with its home network. The wireless device is further configured to encrypt a network slice identifier using encryption key material, which can be obtained from the authentication with the home network and shared between the wireless device and the home network. The wireless device is further configured to send a message including the encrypted network slice identifier.

[0024] Embodiments of the present disclosure also include a network node in a serving network of a wireless device. The network node is configured to receive a message including an encrypted network slice identifier. The network node is further configured to use the encryption key material to decrypt or request decryption of the encrypted network slice identifier, where the encryption key material can be obtained by the wireless device from the authentication of the wireless device with the home network and shared between the wireless device and the home network.

[0025] Embodiments of the present disclosure also include a network node in a home network of a wireless device. The network node is configured to receive a request for decrypting the encrypted network slice identifier from the serving network of the wireless device. The network node is further configured to decrypt the encrypted network slice identifier using the encryption key material, where the encryption key material can be obtained by the wireless device from the authentication of the wireless device with the home network and shared between the wireless device and the home network. The network node is further configured to send a response to the request, where the response includes the decrypted network slice identifier obtained from the decryption. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 is a block diagram of a serving network and a home network of a wireless device according to some embodiments.

[0027] Figure 2 is a block diagram of key hierarchy generation in a 5G system according to some embodiments.

[0028] Figure 3 is a block diagram of a 5G network according to some embodiments.

[0029] Figure 4 is a call flow diagram for protecting a network slice identifier in a 5G network according to some embodiments.

[0030] Figure 5 is a block diagram of an encryption algorithm for encrypting a network slice identifier according to some embodiments.

[0031] Figure 6 is a logical flowchart of a method performed by a wireless device according to some embodiments.

[0032] Figure 7 is a logical flow diagram of a method performed by a network node in a serving network of a wireless device according to some embodiments.

[0033] Figure 8 is a logical flow diagram of a method performed by a network node in a home network of a wireless device according to some embodiments.

[0034] Figure 9 is a block diagram of a wireless device according to some embodiments.

[0035] Figure 10 is a block diagram of a network node according to some embodiments.

[0036] Figure 11 is a block diagram of a wireless communication network according to some embodiments.

[0037] Figure 12 is a block diagram of a user equipment according to some embodiments.

[0038] Figure 13 is a block diagram of a virtualized environment according to some embodiments.

[0039] Figure 14 is a block diagram of a communication network with a host computer according to some embodiments.

[0040] Figure 15 is a block diagram of a host computer according to some embodiments.

[0041] Figure 16 is a flowchart showing a method implemented in a communication system according to one embodiment.

[0042] Figure 17 is a flowchart showing a method implemented in a communication system according to one embodiment.

[0043] Figure 18 is a flowchart showing a method implemented in a communication system according to one embodiment.

[0044] Figure 19 is a flowchart showing a method implemented in a communication system according to one embodiment. Detailed Description

[0045] Figure 1FIG. 10 shows a wireless communication system 10 according to some embodiments. The system 10 provides wireless communication services to a wireless device 12 (e.g., a user equipment). In this regard, the wireless device 12 is associated with a subscription to a home network 10H, for example, via an integrated circuit card included or embedded in the wireless device 12. Then, in order to receive services, the wireless device 12 performs an authentication 14 with the home network 10H. Such authentication 14 may involve, for example, the wireless device 12 sending credentials to the home network 10H and the home network 10H determining whether those credentials are valid for receiving the requested services. In some embodiments, this authentication is referred to as a primary authentication to distinguish it from any secondary authentication that the wireless device 12 performs with a data network outside the wireless communication network domain. The authentication 14 may be performed, for example, by a network node 16H in the home network 10H, as Figure 1 shown. The network node 16H may implement, for example, an authentication server function (AUSF) and / or a unified data management (UDM) function, where the home network 10H is a 5G network.

[0046] After authenticating 14 with the home network 10H, the wireless device 12 may be served by a serving network 10S. In some embodiments, the serving network 10S is the same as the home network 10H. However, in other embodiments, the serving network 10S is a visited network that is different from the home network 10H. In either case, the serving network 10S may include N network slices 10S-1…10S-N. Each network slice 10S-1…10S-N is a logical network that provides specific network capabilities and network characteristics. For example, as Figure 1 shown, the network slices may have their respective slice-specific nodes or functions dedicated to serving these slices. In some embodiments, each network slice may include a slice-specific access and mobility management function (AMF), a session management function (SMF), and a user plane function (UPF).

[0047] In order to serve the wireless device 12 with appropriate (e.g., suitable for the type of service requested by the wireless device 12) network capabilities and characteristics, the serving network 10S may select a network slice from the network slices 10S-1…10S-N to serve the wireless device 12. This may involve, for example, selecting network nodes / functions 16-1…16-N to serve the wireless device 12. In any case, according to some embodiments, the wireless device 12 assists the serving network 10S in network slice selection by identifying the network slice that is or will be serving the wireless device 12. Then, in these and other cases, the wireless device 12 may send a message to the serving network 10S that includes a network slice identifier. The network slice identifier may be, for example, a single network slice selection assistance information (S-NSSAI) in a 5G network.

[0048] The wireless device 12 according to an embodiment of the present disclosure encrypts the network slice identifier sent by the wireless device 12 in a message to protect the confidentiality of the network slice identifier. In this regard, for this purpose, Figure 1 FIG. shows that the wireless device 12 utilizes encryption key material 22. The encryption key material 22 can be obtained, in particular, from the authentication 14 of the wireless device 12 with the home network 10H and is shared between the wireless device 12 and the home network 10H. The wireless device 12 encrypts the network slice identifier 24 (e.g., S-NSSAI) using the encryption key material 22 to obtain the encrypted network slice identifier 26. Then, the wireless device 12 sends a message 20 (e.g., a registration request message or a service request message) including the encrypted network slice identifier 26.

[0049] If the serving network 10S is the same as the home network 10H (i.e., the wireless device 12 is being served by its home network 10H), the serving network 10S can decrypt the encrypted network slice identifier 26 using the encryption key material 22. However, if the serving network 10S is different from the home network 10H such that the serving network 10S is a visited network, the serving network 10S according to some embodiments requests the home network 10H to decrypt the encrypted network slice identifier 26. That is, in some embodiments, the serving network 10S sends a request including the encrypted network slice identifier 26 to the home network 10H and receives a response to the request from the home network 10H, the response including the decrypted network slice identifier.

[0050] In some embodiments, for example, when the message 20 is a registration request, the encrypted network slice identifier 26 is included in the access stratum (AS) part of the message 20. In these and other cases, the radio network node in the serving network 10S can select a network slice (e.g., AMF) for forwarding the non-access stratum (NAS) part of the message based on the decrypted network slice identifier.

[0051] In other embodiments, the encrypted network slice identifier 26 can be included in the NAS part of the message 20. In this case, the message can be received by a core network node, and then the core network node can select a network slice (e.g., AMF) to which the message 20 is to be forwarded based on the decrypted network slice identifier.

[0052] Figure 2 FIG. shows a key hierarchy established according to the authentication 14 according to some 5G embodiments. In some embodiments, the encryption key material 22 is any key shared between the home network 10H (as shown by the HLPMN in Figure 2 or directly obtained from the home network 10H (as shown by the HLPMN in Figure 2derived from any key shared between the HLPMN shown in ). This includes, for example, keys CK, IK, K in the key hierarchy AUSF , CK′ or IK′. In other embodiments not shown, the encryption key material 22 is an Extended Master Session Key (EMSK) or is derived directly from the Extended Master Session Key (EMSK).

[0053] In some embodiments, the encryption key material 22 includes a key dedicated to encrypting network slice identifiers (e.g., K NSSAI ).

[0054] Some embodiments herein can be applied to the serving network 10S as a 5G network. The 5G system includes many new features that require the introduction of new security mechanisms. See, for example, 3GPP TS 33.501 v15.4.0. For example, the 5G system integrates non-3GPP access (e.g., Wireless Local Area Network, WLAN) with 3GPP access (New Radio, NR and Long Term Evolution, LTE) in a seamless manner. More precisely, in 5G, a User Equipment (UE), as an example of the wireless device 12 in Figure 1 can run common service access procedures independently of the underlying access.

[0055] More specifically, the 5G system includes an Access Network (AN) and a Core Network (CN). The AN in the 5G system is the network that allows the UE to obtain a connection to the CN (e.g., a base station, which can be a gNB or ng-eNB in 5G). The CN in 5G is referred to as the 5G Core (5GC). The 5GC contains all the Network Functions (NFs) to ensure a wide range of different functions, such as session management, connection management, charging, authentication, etc. Figure 3 A high-level overview of the 5G architecture for the non-roaming scenario is given.

[0056] The communication links between the UE and the network (AN and CN) can be grouped into two different layers. The UE communicates with the CN through the Non-Access Stratum (NAS) and with the AN through the Access Stratum (AS). All NAS communications are carried out between the UE and the Access and Connection Management Function (AMF) in the CN through the NAS protocol ( Figure 3 the N1 interface in ). The protection of the communications through these layers is provided by the NAS protocol (for NAS) and the Packet Data Convergence Protocol (PDCP) protocol (for AS).

[0057] Generally, the security mechanisms for these protocols rely on multiple different security keys. In the 5G security specifications, these keys are in Figure 2organized in the hierarchical structure shown. The long-term key part of the authentication credential is stored in the subscriber identity module (SIM) card on the UE side and in the unified data management (UDM) / authentication credential repository and processing function (ARPF) on the home public land mobile network (PLMN) side at the top layer.

[0058] Successful operation of the primary authentication between the UE and the authentication server function (AUSF) in the home public land mobile network (PLMN) results in the establishment of the K AUSF key, which is the second-level key in the hierarchical structure. This key is not intended to leave the home PLMN but is used for new functions introduced in the 5G system, such as providing parameters from the home PLMN to the UE. More precisely, the K AUSF key is used for integrity protection of the messages passed from the home PLMN to the UE. As described in 3GPP technical specification (TS) 33.501 v15.4.0, such new functions include steering of roaming (SoR) and the UDM parameter transfer process.

[0059] K AUSF is used to derive another key that is sent to the serving PLMN (K SEAF ). Then the serving PLMN key is used to derive subsequent NAS and AS protection keys. These lower-level keys, together with other security parameters (such as encryption algorithms, UE security capabilities, values of counters for replay protection in different protocols, etc.), constitute the definition of the 5G security context in, for example, TS 33.501 v15.4.0. It should be noted that K AUSF is not part of the 5G security context because the 5G security context resides in the serving network.

[0060] One of the new features introduced in the 5G system is network slicing. This function allows operators to better manage their networks and adjust their resources according to service types. Roughly speaking, in the context of 5G, a network slice is a set of network functions (usually AMF, SMF, and UPF) in (for example, the core network) dedicated to a specific service (such as the Internet of Things, mission-critical, mobile broadband (MBB), etc.).

[0061] The network slice in 5G is identified by a single network slice selection assistance information (S-NSSAI) as an example of the network slice identifier 24 in Figure 1 . In some embodiments, the S-NSSAI includes: (i) the slice / service type (SST), which refers to the expected network slice behavior in terms of features and services; (ii) the slice differentiator (SD), which is optional information that supplements the slice / service type to distinguish multiple network slices with the same slice / service type. During the registration process, the UE (as Figure 1The example of the wireless device 12 in ) can provide a set of S-NSSAIs called NSSAI, enabling the network to select an appropriate slice to serve the UE.

[0062] In particular, based on the requested NSSAI (if any) and subscription information, the 5GC is responsible for selecting network slice instances to serve the UE, including the 5GC control plane and user plane network functions corresponding to the network slice instances. Before the 5GC notifies the (R)AN of the allowed NSSAI, the (R)AN can use the requested NSSAI in the access layer signaling to handle the UE control plane connection. The requested NSSAI is used by the RAN for AMF selection. When the UE successfully registers through an access type, the CN notifies the (R)AN by providing the allowed NSSAI for the corresponding access type. For more detailed information on the network slice concept, see clause 5.18 of TS 23.501 v15.5.0.

[0063] NSSAI is sensitive because it can disclose information about the type or use of the UE (e.g., a police UE). Therefore, confidentiality protection should be provided for NSSAI.

[0064] Currently, during the registration process, NSSAI is usually included in the registration request message from the UE. Additionally, NSSAI can be included in the NAS layer (NAS protocol message) or the AS layer (RRC message). For the case of including NSSAI in the NAS layer, the initial NAS protection feature must be used. This feature described in TS 33.501 v15.5.0 requires any sensitive information to be included in an encrypted container within the initial NAS message. If NAS security has not been established, then any sensitive information must be sent after NAS security is established.

[0065] So far, for the case of sending NSSAI in the AS layer, the default behavior of the UE is that NSSAI is never included in the AS layer unless the home network configures the UE to do so. Therefore, for sensitive slices, the home network does nothing at all, while for non-sensitive slices, the network can use the procedures specified in TS 23.502 v5.5.1 to configure the UE to include NSSAI in the AS layer. The problem here is that including NSSAI in the AS layer only when it is not sensitive does not really provide confidentiality protection for this information, but only allows the information to be disclosed when the information is not sensitive. This itself can be regarded as a kind of information disclosure.

[0066] A new mechanism for protecting NSSAI at the AS should be introduced for the next version of TS 33.501 (version 16).

[0067] One solution for protecting the NSSAI would be to use the same key that is used to protect the SUPI in the initial registration request message when the operator deploys a subscription permanent identifier (SUPI) secrecy mechanism to protect the NSSAI. This key is a preconfigured home network key. In this case, the serving network would forward the protected NSSAI to the home network, which could decrypt it and provide the plaintext NSSAI back to the serving network. However, one problem with this solution is that it would use a preconfigured home network key instead of using encryption key material obtained from an earlier authentication run or existing NAS or AS security context. See, e.g., TR 33.813 v0.4.0.

[0068] Another solution is to use pseudonyms. Generally, a mapping between (the actual S-NSSAI) and a pseudonymous (or temporary) S-NSSAI would be maintained in the network and the UE. When the UE decides to include the NSSAI in the AS layer before security is established, it would use the temporary S-NSSAI instead of the real S-NSSAI to form the NSSAI. Now, depending on where the mapping is maintained, the home network or the serving network would use the received NSSAI to determine the real NSSAI and act accordingly. However, this solution does not really provide the same level of security as encryption and requires special considerations to avoid linkability, such as by changing the pseudonyms frequently. Therefore, this may require additional signaling overhead to synchronize the mapping between the UE and the network. Additionally, in the case of mapping desynchronization, this solution would require a recovery mechanism.

[0069] Certain aspects of the present disclosure and its embodiments can provide solutions to these or other challenges, for example, in a manner that avoids or mitigates the disadvantages of the alternative solutions described above for 5G. For example, some embodiments use a key that can be obtained from an earlier authentication run and is shared between the UE and the home network (not the serving network) to encrypt the NSSAI.

[0070] Certain embodiments can provide one or more of the following technical advantages. Compared to pseudonym-based solutions, some embodiments provide means for encrypting the NSSAI and thus provide a better level of protection. Some embodiments do not require additional signaling overhead or any failure to maintain the mapping between the real S-NSSAI and the pseudonymous S-NSSAI. Some embodiments reuse security material that can be obtained from and / or bound to an authentication run. Some embodiments give the home network full control over the secrecy of the NSSAI.

[0071] More specifically, some embodiments are based on encrypting the NSSAI information using a key generated by the authentication process and shared between the UE and the home network.Figure 4 Shows steps to be taken by a UE and a network according to some embodiments. In Figure 4 , the UE is Figure 1 an example of the wireless device 12 in NSSAI is an example of the encryption key material 22, and the encrypted K NSSAI is an example of the encrypted network slice ID 26.

[0072] In step 0a, the UE registers and authenticates with the network as described in TS 33.501 v15.4.0. The authentication process is typically performed during the initial registration when the UE is powered on or a new SIM card is inserted. Upon successful authentication, the UE and the network each generate and store additional keys (referred to here as K NSSAI ) in steps 0b and 0c for use only in NSSAI encryption.

[0073] In one embodiment, K NSSAI is derived from the K SEAF key in a manner similar to the derivation of K AUSF using a new FC value and possibly other parameters as described in Appendix A.6 of TS 33.501 v15.4.0. In this regard, K NSSAI can be derived from the K AUSF key through a key derivation function (KDF), where K NSSAI = KDF(Key, S), where Key is the K AUSF key.

[0074] More specifically, in some embodiments, the input parameters and their lengths should be concatenated into a string S as follows. The length of each input parameter measured in octets should be encoded as a two-octet long string: (a) representing the number of octets in the input parameter Pi as a number k in the range [0, 65535]; and (b) Li is the 16-bit long encoding of the number k. In some embodiments, the string S should be constructed from n + 1 input parameters as follows:

[0075] S = FC || P0 || L0 || P1 || L1 || P2 || L2 || P3 || L3 ||... || Pn || Ln

[0076] where

[0077] FC is used to distinguish different instances of the algorithm, and FC is a single octet, or consists of two octets in the form FC1 || FC2, where FC1 = 0xFF and FC2 is a single octet,

[0078] P0...Pn are n+1 input parameter encodings, and

[0079] L0...Ln are two octet representations of the lengths of the corresponding input parameter encodings P0...Pn.

[0080] In some embodiments, the following restriction applies to P0: P0 is a static ASCII-encoded string.

[0081] The final output (i.e., the derived key K NSSAI ) is equal to the KDF (denoted as Key) computed using the key on the string S. In some embodiments, the following KDF can be used:

[0082] Derived key = HMAC-SHA-256(Key, S)

[0083] where K NSSAI is the derived key, and K AUSF is Key.

[0084] In another embodiment, K AUSF can act as K NSSAI .

[0085] In any case, the UE stores the key KNSSAI until the next authentication run or the security context is deleted. On the network side, K NSSAI can be generated by the AUSF or UDM or otherwise derived, where Figure 4 shows the former case. In the case where K NSSAI is derived from K AUSF and the authentication process performed is 5G-AKA, then K NSSAI can be derived by the UDM because in this case, it is already the UDM that derives K AUSF . In the case where the authentication process performed is EAP-AKA′, then K AUSF is computed by the AUSF, so only the AUSF can compute the key derived from K AUSF . K NSSAI can be stored in the AUSF or UDM together with any other parameters related to the authenticated UE.

[0086] In step 1a, the UE decides at some point that it wants to access a network slice and determines that it needs to signal the NSSAI to the network. The UE then uses the K NSSAIThe key is used to encrypt the NSSAI, and the encrypted NSSAI is included in the message to be sent. In steps 1b and 1c, the encrypted payload is forwarded by the SEAF / AMF of the visited / serving PLMN to the home network together with any other information allowing the identification of the UE or the corresponding key used. Such information may be the Subscription Permanent Identifier (SUPI).

[0087] In step 2a, the home network retrieves K NSSAI , for example, based on the provided identification information (e.g., SUPI), and uses it to decrypt the encrypted message, i.e., the encrypted N SSAI . The AUSF or UDM may perform the decryption according to the location where K NSSAI is stored, where Figure 4 shows the former case. In step 2b, the home network then replies to the visited network, and the reply includes the plaintext N SSAI , so as to return the decrypted NSSAI to the visited network.

[0088] In step 3, the visited network can then select a suitable network slice for serving the UE's request based on the received NSSAI.

[0089] For the encryption of the NSSAI, one of the mandatory supported encryption algorithms described in Appendix D.2 of TS 33.501 v15.4.0 can be used. Using such algorithms will simplify the deployment of some embodiments, because any 5G-capable UE already supports these algorithms. Specifically, some embodiments use a 128-bit encryption algorithm as follows. The input parameters of the encryption algorithm are a 128-bit encryption key named KEY, a 32-bit COUNT, a 5-bit bearer identifier BEARER, a 1-bit transmission direction (i.e., DIRECTION), and the required key stream length (i.e., LENGTH). The DIRECTION bit should be 0 for the uplink and 1 for the downlink.

[0090] Figure 5 shows the encryption of the plaintext by applying bit-by-bit binary addition of the plaintext and the key stream using the encryption algorithm NEA (the encryption algorithm of 5G). The plaintext can be restored by generating the same key stream using the same input parameters as the ciphertext and applying bit-by-bit binary addition.

[0091] Based on the input parameters, the algorithm generates an output key stream block KEYSTREAM, which is used to encrypt the input plaintext block PLAINTEXT to produce an output ciphertext block CIPHERTEXT.

[0092] The input parameter LENGTH should only affect the length of the KEYSTREAM block, and not the actual bits therein.

[0093] Note that 128-NEA1 is the same as 128-EEA1 specified in Appendix B of TS 33.401 v15.8.0. 128-NEA2 is the same as 128-EEA2 specified in Appendix B of TS 33.401 v15.8.0. Additionally, 128-NEA3 is the same as 128-EEA3 specified in Appendix B of TS 33.401 v15.8.0.

[0094] In view of the above modifications and changes, Figure 6 depicts a method performed by a wireless device 12 according to a particular embodiment. The method includes performing an authentication 14 of the wireless device 12 with the home network 10H of the wireless device 12 (block 600). The authentication 14 can be, for example, a primary authentication. The method can also include encrypting a network slice identifier 24 (e.g., NSSAI) using encryption key material 22 that can be obtained from the authentication 14 with the home network 10H and is shared between the wireless device 12 and the home network 10H (block 620). In some embodiments, the method further includes sending a message 20 including the encrypted network slice identifier 26 (block 630).

[0095] In some embodiments, the method further includes deriving the encryption key material 22 (block 620). For example, this may require directly deriving the encryption key material 22 from a key K AUSF that can be obtained from the authentication with the home network 10H.

[0096] Figure 7 depicts a method performed by a network node 18S in the serving network 10S of the wireless device 12 according to other particular embodiments. The method includes receiving a message 20 including the encrypted network slice identifier 26 (block 700). The method also includes using the encryption key material 22 to decrypt or request the decryption of the encrypted network slice identifier 26, where the encryption key material 22 can be obtained by the wireless device 12 from the authentication 14 of the wireless device 12 with the home network 10H and is shared between the wireless device 12 and the home network 10H (block 710).

[0097] For example, in the case where the serving network 10S is a visited network of the wireless device, the decrypting or requesting can include requesting the decryption of the encrypted network slice identifier 26 by sending a request including the encrypted network slice identifier 26 to the home network 10H. In this case, the method can also include receiving a response to the request from the home network 10H, where the response includes the decrypted network slice identifier.

[0098] In other embodiments where the serving network 10S is the home network 10H, the decrypting or requesting may include decrypting the encrypted network slice identifier 26.

[0099] In some embodiments, the method may further include selecting network slices 10S-1…10S-N based on the decrypted network slice identifier to serve the wireless device 12 (block 720).

[0100] Figure 8 A method performed by a network node 18H in a home network 10H of a wireless device 12 according to other specific embodiments is depicted. The method includes receiving a request to decrypt an encrypted network slice identifier 26 from a serving network 10S of the wireless device 12 (block 800). The method may further include decrypting the encrypted network slice identifier using encryption key material 22, which may be obtained by the wireless device 12 from an authentication 14 of the wireless device with the home network 10H and is shared between the wireless device 12 and the home network 10H (block 810). The method in some embodiments further includes sending a response to the request, the response including the decrypted network slice identifier obtained according to the decryption (block 820).

[0101] In some embodiments, the method may further include deriving the encryption key material 22. For example, this may require directly deriving the encryption key material from a key K that can be obtained from an authentication with the home network. AUSF from which the encryption key material is directly derived.

[0102] Embodiments herein also include corresponding apparatuses. For example, embodiments herein include a wireless device configured to perform any of the steps of any of the embodiments described above for the wireless device.

[0103] Embodiments also include a wireless device 12, which includes a processing circuit and a power supply circuit. The processing circuit is configured to perform any of the steps of any of the embodiments described above for the wireless device 12. The power supply circuit is configured to supply power to the wireless device 12.

[0104] Embodiments also include a wireless device 12, which includes a processing circuit. The processing circuit is configured to perform any of the steps of any of the embodiments described above for the wireless device 12. In some embodiments, the wireless device 12 further includes a communication circuit.

[0105] Embodiments also include a wireless device 12, which includes a processing circuit and a memory. The memory contains instructions executable by the processing circuit, whereby the wireless device 12 is configured to perform any of the steps of any of the embodiments described above for the wireless device.

[0106] In addition, embodiments include a user equipment (UE). The UE includes an antenna configured to transmit and receive wireless signals. The UE also includes radio front-end circuitry connected to the antenna and a processing circuit and configured to condition signals communicated between the antenna and the processing circuit. The processing circuit is configured to perform any of the steps of any of the embodiments described above for the wireless device 12. In some embodiments, the UE further includes an input interface connected to the processing circuit and configured to allow information to be input into the UE for processing by the processing circuit. The UE may include an output interface connected to the processing circuit and configured to output information that has been processed by the processing circuit from the UE. The UE may also include a battery connected to the processing circuit and configured to power the UE.

[0107] Embodiments herein also include a network node 18S configured to perform any of the steps of any of the embodiments described above for the network node 18S.

[0108] Embodiments also include a network node 18S that includes a processing circuit and a power supply circuit. The processing circuit is configured to perform any of the steps of any of the embodiments described above for the network node 18S. The power supply circuit is configured to power the network node 18S.

[0109] Embodiments also include a network node 18S that includes a processing circuit. The processing circuit is configured to perform any of the steps of any of the embodiments described above for the network node 18S. In some embodiments, the network node 18S further includes communication circuitry.

[0110] Embodiments also include a network node 18S that includes a processing circuit and a memory. The memory contains instructions executable by the processing circuit, whereby the network node 18S is configured to perform any of the steps of any of the embodiments described above for the network node 18S.

[0111] Embodiments herein also include a network node 18H configured to perform any of the steps of any of the embodiments described above for the network node.

[0112] Embodiments also include a network node 18H that includes a processing circuit and a power supply circuit. The processing circuit is configured to perform any of the steps of any of the embodiments described above for the network node 18H. The power supply circuit is configured to power the network node 18H.

[0113] Embodiments also include a network node 18H that includes a processing circuit. The processing circuit is configured to perform any of the steps of any of the embodiments described above for the network node 18H. In some embodiments, the network node 18H further includes communication circuitry.

[0114] The embodiment also includes a network node 18H, which includes a processing circuit and a memory. The memory contains instructions executable by the processing circuit, whereby the network node 18H is configured to perform any of the steps of any of the embodiments described above for the network node 18H.

[0115] More specifically, the above-described apparatus may perform the methods and any other processing herein by implementing any functional device, module, unit, or circuit. In one embodiment, for example, the apparatus includes a corresponding circuit or circuitry configured to perform the steps shown in the method drawings. In this regard, the circuit or circuitry may include circuitry dedicated to performing certain functional processing and / or one or more microprocessors in combination with a memory. For example, the circuit may include one or more microprocessors or microcontrollers and other digital hardware, and the other digital hardware may include a digital signal processor (DSP), dedicated digital logic, etc. The processing circuit may be configured to execute program code stored in the memory, and the memory may include one or several types of memories, such as read-only memory (ROM), random access memory, cache memory, flash memory devices, optical storage devices, etc. In several embodiments, the program code stored in the memory may include program instructions for performing one or more telecommunication and / or data communication protocols, as well as instructions for performing one or more techniques described herein. In embodiments employing a memory, the memory stores program code that, when executed by one or more processors, performs the techniques described herein.

[0116] For example, Figure 9 A wireless device 900 (e.g., wireless device 12) implemented according to one or more embodiments is shown. As shown, the wireless device 900 includes a processing circuit 910 and a communication circuit 920. The communication circuit 920 (e.g., radio circuitry) is configured to send information to and / or receive information from one or more other nodes via any communication technology, for example. Such communication may occur via one or more antennas, which may be located inside or outside the wireless device 900. The processing circuit 910 is configured to perform the processing described above, for example, by executing instructions stored in a memory 930, as described, for example, in Figure 6 In this regard, the processing circuit 910 may implement certain functional devices, units, or modules.

[0117] Figure 10Shows a network node 1000 (e.g., network node 18S or network node 18H) implemented according to one or more embodiments. As shown, network node 1000 includes a processing circuit 1010 and a communication circuit 1020. The communication circuit 1020 is configured to send information to and / or receive information from one or more other nodes via any communication technology, for example. The processing circuit 1010 is configured to perform the processing described above, for example, by executing instructions stored in a memory 1030, in, for example Figure 7 and / or Figure 8 as described. In this regard, the processing circuit 1010 may implement certain functional means, units or modules.

[0118] Those skilled in the art will also understand that the embodiments herein also include corresponding computer programs.

[0119] The computer program includes instructions that, when executed on at least one processor of a device, cause the device to perform any of the corresponding processing described above. In this regard, the computer program may include one or more code modules corresponding to the above-described device or unit.

[0120] The embodiments also include a carrier containing such a computer program. The carrier may include one of an electrical signal, an optical signal, a radio signal, or a computer-readable storage medium.

[0121] In this regard, the embodiments herein also include a computer program product stored on a non-transitory computer-readable (storage or recording) medium, and the computer program product includes instructions that, when executed by a processor of a device, cause the device to perform as described above.

[0122] The embodiments also include a computer program product that includes a program code portion for performing the steps of any of the embodiments herein when the computer program product is executed by a computing device. The computer program product may be stored on a computer-readable recording medium.

[0123] Additional embodiments will now be described. For illustrative purposes, at least some of these embodiments may be described as applicable to certain contexts and / or wireless network types, but these embodiments are equally applicable to other contexts and / or wireless network types not explicitly described.

[0124] Although the subject matter described herein may be implemented using any suitable components in any suitable type of system, the embodiments disclosed herein are described with respect to a wireless network (e.g., Figure 11 the example wireless network shown in). For simplicity, Figure 11The wireless network only depicts network 1106, network nodes 1160 and 1160b, and WDs 1110, 1110b, and 1110c. In reality, the wireless network can also include any additional elements suitable for supporting communication between wireless devices or between a wireless device and another communication device (e.g., a landline phone, a service provider, or any other network node or terminal device). Among the depicted components, network node 1160 and wireless device (WD) 1110 are depicted in additional detail. The wireless network can provide communication and other types of services to one or more wireless devices to facilitate the access and / or use of services provided by or via the wireless network.

[0125] The wireless network can include any type of communication, telecommunication, data, cellular, and / or radio network or other similar type of system, and / or interface with any type of communication, telecommunication, data, cellular, and / or radio network or other similar type of system. In some embodiments, the wireless network can be configured to operate according to a specific standard or other type of predefined rules or procedures. Thus, a particular embodiment of a wireless communication network can implement communication standards such as Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), Long-Term Evolution (LTE), Narrowband Internet of Things (NB-IoT), and / or other suitable 2G, 3G, 4G, or 5G standards; wireless local area network (WLAN) standards such as IEEE 802.11 standards; and / or any other suitable wireless communication standards such as Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, and / or ZigBee standards.

[0126] Network 1106 can include one or more backhaul networks, core networks, IP networks, Public Switched Telephone Networks (PSTN), packet data networks, optical networks, wide area networks (WAN), local area networks (LAN), wireless local area networks (WLAN), wired networks, wireless networks, metropolitan area networks, and other networks to enable communication between devices.

[0127] Network node 1160 and WD 1110 include various components described in more detail below. These components work together to provide network node and / or wireless device functionality, such as providing a wireless connection in a wireless network. In different embodiments, the wireless network can include any number of wired or wireless networks, network nodes, base stations, controllers, wireless devices, relay stations, and / or any other components or systems that can facilitate or participate in the communication of data and / or signals, whether via a wired connection or a wireless connection.

[0128] As used herein, a network node refers to a device that is capable of, configured to, arranged to, and / or operable to communicate directly or indirectly with a wireless device and / or with other network nodes or devices in a wireless network to enable and / or provide wireless access to the wireless device and / or to perform other functions in the wireless network (e.g., management). Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs), and NR Node Bs (gNBs)). Base stations can be classified based on the amount of coverage they provide (or in other words, based on their transmit power levels), and thus they can also be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station can be a relay node or a relay host node that controls a relay. A network node can also include one or more (or all) parts of a distributed radio base station, such as a centralized digital unit and / or a remote radio unit (RRU) (sometimes referred to as a remote radio head (RRH)). Such a remote radio unit may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station can also be referred to as nodes in a distributed antenna system (DAS). Further examples of network nodes include multi-standard radio (MSR) devices (such as MSR BSs), network controllers (such as radio network controllers (RNCs) or base station controllers (BSCs)), base transceiver stations (BTSs), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), core network nodes (e.g., MSCs, MMEs), O&M nodes, OSS nodes, SON nodes, positioning nodes (e.g., E-SMLC), and / or MDTs. As another example, a network node can be a virtual network node, as described in more detail below. However, more generally, a network node can represent any suitable device (or group of devices) that is capable of, configured to, arranged to, and / or operable to enable and / or provide access to a wireless network to a wireless device, or to provide some service to a wireless device that is already connected to the wireless network.

[0129] In Figure 11 network node 1160 includes processing circuitry 1170, a device-readable medium 1180, an interface 1190, auxiliary device 1184, a power supply 1186, a power supply circuit 1187, and an antenna 1162. Although Figure 11The network node 1160 shown in the example wireless network can represent a device that includes a combination of the shown hardware components, but other embodiments can include network nodes with different combinations of components. It should be understood that a network node includes any suitable combination of hardware and / or software required to perform the tasks, features, functions, and methods disclosed herein. Additionally, although the components of network node 1160 are depicted as a single box located within a larger box or nested within multiple boxes, in reality, a network node can include multiple different physical components that make up a single illustrated component (e.g., the device-readable medium 1180 can include multiple individual hard disk drives as well as multiple RAM modules).

[0130] Similarly, network node 1160 can be composed of multiple physically separated components (e.g., NodeB components and RNC components, or BTS components and BSC components, etc.), and each of these components can have its respective corresponding components. In certain scenarios where network node 1160 includes multiple separated components (e.g., BTS and BSC components), one or more of these separated components can be shared among several network nodes. For example, a single RNC can control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair can be considered a single separate network node in some instances. In some embodiments, network node 1160 can be configured to support multiple radio access technologies (RATs). In such embodiments, some components can be replicated (e.g., separate device-readable media 1180 for different RATs), and some components can be reused (e.g., the same antenna 1162 can be shared by the RATs). Network node 1160 can also include multiple sets of various illustrated components for different wireless technologies (e.g., GSM, WCDMA, LTE, NR, WiFi, or Bluetooth wireless technologies) that are integrated into network node 1160. These wireless technologies can be integrated into the same or different chips or chip sets and other components within network node 1160.

[0131] The processing circuit 1170 is configured to perform any determination, calculation, or similar operation (e.g., certain obtaining operations) described herein as being provided by the network node. These operations performed by the processing circuit 1170 can include processing the information obtained by the processing circuit 1170 by, for example, converting the obtained information into other information, comparing the obtained information or the converted information with the information stored in the network node, and / or performing one or more operations based on the obtained information or the converted information, and making a determination based on the result of the processing.

[0132] The processing circuitry 1170 may include a combination of one or more of the following: a microprocessor, a controller, a microcontroller, a central processing unit, a digital signal processor, an application specific integrated circuit, a field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software, and / or encoded logic, operable to provide the network node 1160 functionality either alone or in combination with other network node 1160 components (e.g., the device-readable medium 1180). For example, the processing circuitry 1170 may execute instructions stored in the device-readable medium 1180 or in a memory within the processing circuitry 1170. Such functionality may include providing any one of the various wireless features, functions, or benefits discussed herein. In some embodiments, the processing circuitry 1170 may include a system on a chip (SOC).

[0133] In some embodiments, the processing circuitry 1170 may include one or more of radio frequency (RF) transceiver circuitry 1172 and baseband processing circuitry 1174. In some embodiments, the radio frequency (RF) transceiver circuitry 1172 and the baseband processing circuitry 1174 may be located on separate chips (or chip sets), boards, or units (e.g., a radio unit and a digital unit). In alternative embodiments, some or all of the RF transceiver circuitry 1172 and the baseband processing circuitry 1174 may be on the same chip or chip set, board, or unit.

[0134] In certain embodiments, some or all of the functionality described herein as being provided by a network node, base station, eNB, or other such network device may be performed by the processing circuitry 1170, which executes instructions stored on the device-readable medium 1180 or in a memory within the processing circuitry 1170. In alternative embodiments, some or all of the functionality may be provided, for example, in a hardwired manner by the processing circuitry 1170 without the execution of instructions stored on a separate or discrete device-readable medium. In any of these embodiments, whether or not instructions stored on a device-readable storage medium are executed, the processing circuitry 1170 may be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry 1170 or to other components of the network node 1160, but are enjoyed by the network node 1160 as a whole and / or by the end user and the wireless network generally.

[0135] The device-readable medium 1180 may include any form of volatile or non-volatile computer-readable memory, including but not limited to permanent storage devices, solid-state memories, remotely installed memories, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (e.g., hard disks), removable storage media (e.g., flash drives, compact discs (CDs) or digital video discs (DVDs)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory device that stores information, data, and / or instructions that can be used by the processing circuitry 1170. The device-readable medium 1180 may store any suitable instructions, data, or information, including computer programs, software, applications including one or more of logic, rules, code, tables, etc., and / or other instructions that can be executed by the processing circuitry 1170 and used by the network node 1160. The device-readable medium 1180 may be used to store any calculations made by the processing circuitry 1170 and / or any data received via the interface 1190. In some embodiments, the processing circuitry 1170 and the device-readable medium 1180 may be considered integrated.

[0136] The interface 1190 is used for wired or wireless communication of signaling and / or data between the network node 1160, the network 1106, and / or the WD 1110. As shown, the interface 1190 includes ports / terminals 1194 for sending data to and receiving data from the network 1106, for example, via a wired connection. The interface 1190 also includes a radio front-end circuit 1192, which may be coupled to the antenna 1162 or, in certain embodiments, is part of the antenna 1162. The radio front-end circuit 1192 includes a filter 1198 and an amplifier 1196. The radio front-end circuit 1192 may be connected to the antenna 1162 and the processing circuitry 1170. The radio front-end circuit may be configured to condition the signals communicating between the antenna 1162 and the processing circuitry 1170. The radio front-end circuit 1192 may receive digital data that will be transmitted outward via a wireless connection to other network nodes or WDs. The radio front-end circuit 1192 may use a combination of the filter 1198 and / or the amplifier 1196 to convert the digital data into a radio signal having suitable channel and bandwidth parameters. The radio signal may then be transmitted via the antenna 1162. Similarly, when receiving data, the antenna 1162 may collect the radio signal, which may then be converted into digital data by the radio front-end circuit 1192. The digital data may be passed to the processing circuitry 1170. In other embodiments, the interface may include different components and / or different combinations of components.

[0137] In some alternative embodiments, network node 1160 may not include a separate radio front-end circuit 1192. Instead, processing circuit 1170 may include a radio front-end circuit and may be connected to antenna 1162 without a separate radio front-end circuit 1192. Similarly, in some embodiments, all or some of RF transceiver circuit 1172 may be considered part of interface 1190. In other embodiments, interface 1190 may include one or more ports or terminals 1194, radio front-end circuit 1192, and RF transceiver circuit 1172 (as part of a radio unit (not shown)), and interface 1190 may communicate with baseband processing circuit 1174 (which is part of a digital unit (not shown)).

[0138] Antenna 1162 may include one or more antennas or antenna arrays configured to transmit and / or receive wireless signals. Antenna 1162 may be coupled to radio front-end circuit 1190 and may be any type of antenna capable of wirelessly transmitting and receiving data and / or signals. In some embodiments, antenna 1162 may include one or more omnidirectional, sector, or planar antennas operable to transmit / receive radio signals in, for example, a range between 2 GHz and 66 GHz. Omnidirectional antennas may be used to transmit / receive radio signals in any direction, sector antennas may be used to transmit / receive radio signals to / from devices within a specific area, and planar antennas may be line-of-sight antennas used to transmit / receive radio signals in a relatively straight line. In some cases, using more than one antenna may be referred to as MIMO. In certain embodiments, antenna 1162 may be separate from network node 1160 and may be connected to network node 1160 via an interface or port.

[0139] Antenna 1162, interface 1190, and / or processing circuit 1170 may be configured to perform any of the receiving operations and / or certain obtaining operations described herein as being performed by a network node. Any information, data, and / or signals may be received from a wireless device, another network node, and / or any other network device. Similarly, antenna 1162, interface 1190, and / or processing circuit 1170 may be configured to perform any of the sending operations described herein as being performed by a network node. Any information, data, and / or signals may be sent to a wireless device, another network node, and / or any other network device.

[0140] The power supply circuit 1187 may include or be coupled to a power management circuit and is configured to supply power to the components of the network node 1160 to perform the functions described herein. The power supply circuit 1187 may receive power from a power source 1186. The power source 1186 and / or the power supply circuit 1187 may be configured to supply power to the various components of the network node 1160 in a form suitable for each component (e.g., at the voltage and current levels required by each respective component). The power source 1186 may be included within the power supply circuit 1187 and / or the network node 1160 or external to the power supply circuit 1187 and / or the network node 1160. For example, the network node 1160 may be connected to an external power source (e.g., a power outlet) via an input circuit or an interface such as a cable, and the external power source may supply power to the power supply circuit 1187. As another example, the power source 1186 may include a power source in the form of a battery or a battery pack that is connected to or integrated within the power supply circuit 1187. The battery may provide backup power in the event of a failure of the external power source. Other types of power sources, such as photovoltaic devices, may also be used.

[0141] Alternative embodiments of the network node 1160 may include additional components beyond those shown Figure 11 in, which may be responsible for providing certain aspects of the functions of the network node (including any of the functions described herein and / or any functions required to support the subject matter described herein). For example, the network node 1160 may include a user interface device to allow information to be input into the network node 1160 and to allow information to be output from the network node 1160. This may allow a user to perform diagnostic, maintenance, repair, and other management functions on the network node 1160.

[0142] As used herein, a wireless device (WD) refers to a device that is capable of, configured to, arranged to, and / or operable to communicate wirelessly with a network node and / or another wireless device. Unless otherwise stated, the term WD may be used interchangeably with user equipment (UE) herein. Wireless transmission may include sending and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for transmitting information through the air. In some embodiments, a WD may be configured to send and / or receive information without direct human interaction. For example, a WD may be designed to send information to a network at a predetermined schedule when triggered by an internal or external event or in response to a request from the network. Examples of WDs include, but are not limited to, smart phones, mobile phones, cellular phones, IP voice (VoIP) phones, wireless local loop phones, desktop computers, personal digital assistants (PDAs), wireless cameras, gaming consoles or devices, music storage devices, playback devices, wearable terminal devices, wireless endpoints, mobile stations, tablet computers, portable computers, portable embedded devices (LEEs), portable mounted devices (LMEs), smart devices, wireless customer premise equipment (CPEs), in-vehicle wireless terminal devices, etc. A WD may support device-to-device (D2D) communication, vehicle-to-vehicle (V2V) communication, vehicle-to-infrastructure (V2I) communication, vehicle-to-everything (V2X) communication, for example, by implementing 3GPP standards for sidelink communication, and in this case may be referred to as a D2D communication device. As yet another specific example, in an Internet of Things (IoT) scenario, a WD may represent a machine or other device that performs monitoring and / or measurement and sends the results of such monitoring and / or measurement to another WD and / or network node. In this case, the WD may be a machine-to-machine (M2M) device, which may be referred to as an MTC device in the 3GPP context. As a specific example, a WD may be a UE that implements the 3GPP narrowband Internet of Things (NB-IoT) standard. Specific examples of such machines or devices are sensors, metering devices (e.g., electricity meters), industrial machines, or home or personal devices (e.g., refrigerators, TVs, etc.), personal wearable devices (e.g., watches, fitness trackers, etc.). In other scenarios, a WD may represent a vehicle or other device that is capable of monitoring and / or reporting its operating status or other functions associated with its operation. A WD as described above may represent a wirelessly connected endpoint, in which case the device may be referred to as a wireless terminal. Additionally, a WD as described above may be mobile, in which case it may also be referred to as a mobile device or mobile terminal.

[0143] As shown in the figure, the wireless device 1110 includes an antenna 1111, an interface 1114, a processing circuit 1120, a device-readable medium 1130, a user interface device 1132, an auxiliary device 1134, a power source 1136, and a power circuit 1137. The WD 1110 may include multiple sets of one or more of the illustrated components for different wireless technologies supported by the WD 1110 (e.g., GSM, WCDMA, LTE, NR, WiFi, WiMAX, NB-IoT, or Bluetooth wireless technologies, to name a few). These wireless technologies may be integrated into the same or different chips or chip sets as other components within the WD 1110.

[0144] The antenna 1111 may include one or more antennas or antenna arrays configured to transmit and / or receive wireless signals and is connected to the interface 1114. In some alternative embodiments, the antenna 1111 may be separate from the WD 1110 and may be connected to the WD 1110 through an interface or port. The antenna 1111, the interface 1114, and / or the processing circuit 1120 may be configured to perform any of the receiving or transmitting operations described herein as being performed by the WD. Any information, data, and / or signals may be received from network nodes and / or another WD. In some embodiments, the radio front-end circuit and / or the antenna 1111 may be considered an interface.

[0145] As shown in the figure, the interface 1114 includes a radio front-end circuit 1112 and the antenna 1111. The radio front-end circuit 1112 includes one or more filters 1118 and amplifiers 1116. The radio front-end circuit 1114 is connected to the antenna 1111 and the processing circuit 1120 and is configured to condition the signals transmitted between the antenna 1111 and the processing circuit 1120. The radio front-end circuit 1112 may be coupled to the antenna 1111 or be part of the antenna 1111. In some alternative embodiments, the WD 1110 may not include a separate radio front-end circuit 1112; rather, the processing circuit 1120 may include the radio front-end circuit and may be connected to the antenna 1111. Similarly, in some embodiments, some or all of the RF transceiver circuit 1122 may be considered part of the interface 1114. The radio front-end circuit 1112 may receive digital data that is to be transmitted outward over a wireless connection to other network nodes or WDs. The radio front-end circuit 1112 may use a combination of the filters 1118 and / or the amplifiers 1116 to convert the digital data into a radio signal having suitable channel and bandwidth parameters. The radio signal may then be transmitted through the antenna 1111. Similarly, when receiving data, the antenna 1111 may collect the radio signal, which may then be converted into digital data by the radio front-end circuit 1112. The digital data may be passed to the processing circuit 1120. In other embodiments, the interface may include different components and / or different combinations of components.

[0146] The processing circuitry 1120 may include one or more combinations of the following: a microprocessor, a controller, a microcontroller, a central processing unit, a digital signal processor, an application specific integrated circuit, a field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software, and / or coded logic that is operable to provide the WD 1110 functionality, either alone or in combination with other WD 1110 components (e.g., the device readable medium 1130). Such functionality may include providing any one of the various wireless features or benefits discussed herein. For example, the processing circuitry 1120 may execute instructions stored in the device readable medium 1130 or in a memory within the processing circuitry 1120 to provide the functionality disclosed herein.

[0147] As shown, the processing circuitry 1120 includes one or more of RF transceiver circuitry 1122, baseband processing circuitry 1124, and application processing circuitry 1126. In other embodiments, the processing circuitry may include different components and / or different combinations of components. In certain embodiments, the processing circuitry 1120 of the WD 1110 may include a SOC. In some embodiments, the RF transceiver circuitry 1122, baseband processing circuitry 1124, and application processing circuitry 1126 may be on separate chips or chip sets. In alternative embodiments, some or all of the baseband processing circuitry 1124 and the application processing circuitry 1126 may be combined into one chip or chip set, and the RF transceiver circuitry 1122 may be on a separate chip or chip set. In additional alternative embodiments, some or all of the RF transceiver circuitry 1122 and the baseband processing circuitry 1124 may be on the same chip or chip set, and the application processing circuitry 1126 may be on a separate chip or chip set. In other alternative embodiments, some or all of the RF transceiver circuitry 1122, baseband processing circuitry 1124, and application processing circuitry 1126 may be combined in the same chip or chip set. In some embodiments, the RF transceiver circuitry 1122 may be part of the interface 1114. The RF transceiver circuitry 1122 may condition RF signals for the processing circuitry 1120.

[0148] In some embodiments, some or all of the functions described herein as being performed by the WD may be provided by processing circuitry 1120 that executes instructions stored on a device-readable medium 1130, which in some embodiments may be a computer-readable storage medium. In alternative embodiments, some or all of the functions may be provided, for example, in a hard-wired manner by the processing circuitry 1120 without the execution of instructions stored on a separate or discrete device-readable storage medium. In any of these particular embodiments, whether or not instructions stored on a device-readable storage medium are executed, the processing circuitry 1120 may be configured to perform the described functions. The benefits provided by such functions are not limited to the processing circuitry 1120 or to other components of the WD 1110, but are enjoyed by the WD 1110 as a whole and / or generally by the end user and the wireless network.

[0149] The processing circuitry 1120 may be configured to perform any determination, calculation, or similar operation described herein as being performed by the WD (e.g., certain acquisition operations). These operations performed by the processing circuitry 1120 may include processing information obtained by the processing circuitry 1120 by, for example, converting the obtained information into other information, comparing the obtained information or the converted information with information stored by the WD 1110, and / or performing one or more operations based on the obtained information or the converted information and making a determination based on the result of such processing.

[0150] The device-readable medium 1130 is operable to store computer programs, software, applications including one or more of logic, rules, code, tables, etc., and / or other instructions executable by the processing circuitry 1120. The device-readable medium 1130 may include computer memory (e.g., random access memory (RAM) or read-only memory (ROM)), mass storage media (e.g., hard disk), removable storage media (e.g., compact disc (CD) or digital video disc (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory device that stores information, data, and / or instructions usable by the processing circuitry 1120. In some embodiments, the processing circuitry 1120 and the device-readable medium 1130 may be considered integrated.

[0151] The user interface device 1132 can provide components that allow a human user to interact with the WD 1110. Such interaction can take various forms, such as visual, auditory, tactile, etc. The user interface device 1132 is operable to generate output to the user and allow the user to provide input to the WD 1110. The type of interaction can vary according to the type of user interface device 1132 installed in the WD 1110. For example, if the WD 1110 is a smart phone, the interaction can be via a touch screen; if the WD 1110 is a smart meter, the interaction can be through a screen that provides usage (e.g., the number of gallons used) or a speaker that provides an audible alarm (e.g., if smoke is detected). The user interface device 1132 can include an input interface, devices, and circuits, as well as an output interface, devices, and circuits. The user interface device 1132 is configured to allow information to be input into the WD 1110 and is connected to the processing circuit 1120 to allow the processing circuit 1120 to process the input information. The user interface device 1132 can include, for example, a microphone, proximity or other sensors, keys / buttons, a touch display, one or more cameras, a USB port, or other input circuits. The user interface device 1132 is also configured to allow information to be output from the WD 1110 and allow the processing circuit 1120 to output information from the WD 1110. The user interface device 1132 can include, for example, a speaker, a display, a vibration circuit, a USB port, a headphone jack, or other output circuits. By using one or more input and output interfaces, devices, and circuits of the user interface device 1132, the WD 1110 can communicate with an end user and / or a wireless network and allow them to benefit from the functions described herein.

[0152] The auxiliary device 1134 is operable to provide more specific functions that may not typically be performed by the WD. This can include specialized sensors for making measurements for various purposes, interfaces for other types of communication such as wired communication, etc. The inclusion and type of components of the auxiliary device 1134 can vary according to the embodiment and / or scenario.

[0153] In some embodiments, power supply 1136 may be in the form of a battery or battery pack. Other types of power supplies may also be used, such as an external power supply (e.g., a power outlet), a photovoltaic device, or a fuel cell. WD 1110 may also include a power supply circuit 1137 for delivering power from power supply 1136 to various parts of WD 1110, and various parts of WD 1110 require power from power supply 1136 to perform any of the functions described or indicated herein. In certain embodiments, power supply circuit 1137 may include a power management circuit. Power supply circuit 1137 may additionally or alternatively be operable to receive power from an external power supply; in such a case, WD 1110 may be connected to an external power supply (e.g., a power outlet) via an input circuit or an interface such as a power cable. In certain embodiments, power supply circuit 1137 is also operable to deliver power from the external power supply to power supply 1136. For example, this may be used for charging power supply 1136. Power supply circuit 1137 may perform any formatting, conversion, or other modification of the power from power supply 1136 to make the power suitable for the various components of WD 1110 being powered.

[0154] Figure 12 An embodiment of a UE in accordance with various aspects described herein is shown. As used herein, a "user equipment" or "UE" may not necessarily have a "user" in the sense of a human user who owns and / or operates the associated equipment. Instead, a UE may represent a device that is intended to be sold to or operated by a human user but may not or initially may not be associated with a particular human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended to be sold to or operated by an end user but may be associated with or operate in the interest of a user (e.g., a smart meter). UE 12200 may be any UE identified by the 3rd Generation Partnership Project (3GPP), including an NB-IoT UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE. As Figure 12 shown, UE 1200 is an example of a WD configured for communication in accordance with one or more communication standards (e.g., GSM, UMTS, LTE, and / or 5G standards of 3GPP) released by the 3rd Generation Partnership Project (3GPP). As previously mentioned, the terms WD and UE may be used interchangeably. Thus, although Figure 12 it is a UE, the components discussed herein are equally applicable to a WD, and vice versa.

[0155] In Figure 12In [description], the UE 1200 includes processing circuitry 1201 operatively coupled to an input / output interface 1205, a radio frequency (RF) interface 1209, a network connection interface 1211, a memory 1215 including a random access memory (RAM) 1217, a read-only memory (ROM) 1219, and a storage medium 1221, etc., a communication subsystem 1231, a power supply 1233, and / or any other components, or any combination thereof. The storage medium 1221 includes an operating system 1223, application programs 1225, and data 1227. In other embodiments, the storage medium 1221 may include other similar types of information. Certain UEs may use Figure 12 all of the components shown in [description], or only a subset of these components. The level of integration between components may vary from one UE to another. Additionally, certain UEs may include multiple instances of components, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0156] In Figure 12 [description], the processing circuitry 1201 may be configured to process computer instructions and data. The processing circuitry 1201 may be configured to implement any sequential state machine operable to execute machine instructions of a machine-readable computer program stored as a memory, such as: one or more hardware-implemented state machines (e.g., implemented in discrete logic, FPGA, ASIC, etc.); programmable logic together with appropriate firmware; one or more stored programs, a general-purpose processor (e.g., a microprocessor or a digital signal processor (DSP)) together with suitable software; or any combination of the above. For example, the processing circuitry 1201 may include two central processing units (CPUs). Data may be information in a form suitable for use by a computer.

[0157] In the depicted embodiment, the input / output interface 1205 may be configured to provide a communication interface to an input device, an output device, or an input and output device. The UE 1200 may be configured to use an output device via the input / output interface 1205. The output device may use the same type of interface port as the input device. For example, a USB port may be used to provide both input to and output from the UE 1200. The output device may be a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, a transmitter, a smart card, another output device, or any combination thereof. The UE 1200 may be configured to use an input device via the input / output interface 1205 to allow a user to capture information into the UE 1200. The input device may include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a touchpad, a scroll wheel, a smart card, etc. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. The sensor may be, for example, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, another similar sensor, or any combination thereof. For example, the input device may be an accelerometer, a magnetometer, a digital camera, a microphone, and an optical sensor.

[0158] In Figure 12 it, the RF interface 1209 may be configured to provide a communication interface to RF components such as a transmitter, a receiver, and an antenna. The network connection interface 1211 may be configured to provide a communication interface to the network 1243a. The network 1243a may include a wired and / or wireless network, such as a local area network (LAN), a wide area network (WAN), a computer network, a wireless network, a telecommunications network, another similar network, or any combination thereof. For example, the network 1243a may include a Wi-Fi network. The network connection interface 1211 may be configured to include a receiver and a transmitter interface for communicating with one or more other devices via a communication network according to one or more communication protocols (e.g., Ethernet, TCP / IP, SONET, ATM, etc.). The network connection interface 1211 may implement receiver and transmitter functions suitable for a communication network link (e.g., optical, electrical, etc.). The receiver and transmitter functions may share circuit components, software, or firmware, or alternatively may be implemented separately.

[0159] The RAM 1217 can be configured to interface with the processing circuitry 1201 via the bus 1202 to provide storage or caching of data or computer instructions during the execution of software programs such as an operating system, applications, and device drivers. The ROM 1219 can be configured to provide computer instructions or data to the processing circuitry 1201. For example, the ROM 1219 can be configured to store invariant low-level system code or data for basic system functions stored in non-volatile memory, such as basic input and output (I / O), startup, or reception of keystrokes from a keyboard. The storage medium 1221 can be configured to include memory such as RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, floppy disks, hard disks, removable cartridge tapes, or flash drives. In one example, the storage medium 1221 can be configured to include an operating system 1223, an application 1225 such as a web browser application, a widget or gadget engine, or another application, and data files 1227. The storage medium 1221 can store any one or combination of various operating systems for use by the UE 1200.

[0160] The storage medium 1221 can be configured to include multiple physical drive units such as redundant arrays of independent disks (RAID), floppy disk drives, flash memory, USB flash drives, external hard disk drives, thumb drives, pen drives, key drives, high-definition digital versatile disc (HD-DVD) optical disc drives, internal hard disk drives, Blu-ray disc drives, holographic digital data storage (HDDS) optical disc drives, external mini dual in-line memory modules (DIMMs), synchronous dynamic random access memory (SDRAM), external micro DIMM SDRAM, smart card memory such as a subscriber identity module or removable subscriber identity (SIM / RUIM) module, other memory, or any combination thereof. The storage medium 1221 can allow the UE 1200 to access computer-executable instructions, applications, etc. stored on a transient or non-transient memory medium to offload or upload data. An article of manufacture such as an article using a communication system can be tangibly embodied in the storage medium 1221, and the storage medium 1221 can include a device-readable medium.

[0161] In Figure 12In [the figure], the processing circuit 1201 can be configured to communicate with the network 1243b using the communication subsystem 1231. The network 1243a and the network 1243b can be one or more identical networks or one or more different networks. The communication subsystem 1231 can be configured to include one or more transceivers for communicating with the network 1243b. For example, the communication subsystem 1231 can be configured to include one or more transceivers for communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another WD, UE) or a base station of a radio access network (RAN) according to one or more communication protocols (e.g., IEEE 802.12, CDMA, WCDMA, GSM, LTE, UTRAN, WiMax, etc.). Each transceiver can include a transmitter 1233 and / or a receiver 1235 to respectively implement the transmitter or receiver functions suitable for the RAN link (e.g., frequency allocation, etc.). In addition, the transmitter 1233 and the receiver 1235 of each transceiver can share circuit components, software, or firmware, or alternatively can be implemented separately.

[0162] In the illustrated embodiment, the communication functions of the communication subsystem 1231 can include data communication, voice communication, multimedia communication, short-range communication such as Bluetooth, near-field communication, location-based communication (such as the use of the Global Positioning System (GPS) for determining location), another similar communication function, or any combination thereof. For example, the communication subsystem 1231 can include cellular communication, Wi-Fi communication, Bluetooth communication, and GPS communication. The network 1243b can include wired and / or wireless networks, such as a local area network (LAN), a wide area network (WAN), a computer network, a wireless network, a telecommunications network, another similar network, or any combination thereof. For example, the network 1243b can be a cellular network, a Wi-Fi network, and / or a near-field network. The power supply 1213 can be configured to provide alternating current (AC) or direct current (DC) power to the components of the UE 1200.

[0163] The features, benefits, and / or functions described herein may be implemented in one of the components of UE 1200 or divided among multiple components of UE 1200. Additionally, the features, benefits, and / or functions described herein may be implemented in any combination of hardware, software, or firmware. In one example, the communication subsystem 1231 may be configured to include any of the components described herein. Additionally, the processing circuitry 1201 may be configured to communicate with any such component via the bus 1202. In another example, any such component may be represented by program instructions stored in the memory, which, when executed by the processing circuitry 1201, perform the corresponding functions described herein. In another example, the functions of any such component may be divided between the processing circuitry 1201 and the communication subsystem 1231. In another example, the non-computation-intensive functions of any such component may be implemented in software or firmware, and the computation-intensive functions may be implemented in hardware.

[0164] Figure 13 is a schematic block diagram illustrating a virtualized environment 1300 in which functions implemented by some embodiments may be virtualized. In this context, virtualization means creating a virtual version of a device or equipment, which may include virtualizing hardware platforms, storage devices, and network resources. As used herein, virtualization may be applied to nodes (e.g., virtualized base stations or virtualized radio access nodes) or devices (e.g., UEs, wireless devices, or any other type of communication device) or their components, and involves an implementation in which at least a portion of the functions are implemented as one or more virtual components (e.g., by one or more applications, components, functions, virtual machines, or containers executed on one or more physical processing nodes in one or more networks).

[0165] In some embodiments, some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines implemented in one or more virtual environments 1300 hosted by one or more hardware nodes 1330. Additionally, in embodiments where the virtual node is not a radio access node or does not require a radio connection (e.g., a core network node), the network node may be fully virtualized at this time.

[0166] These functions can be implemented by one or more applications 1320 (which may alternatively be referred to as software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.), and the one or more applications 1320 are operable to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein. The application 1320 runs in a virtualized environment 1300 that provides hardware 1330 including processing circuitry 1360 and memory 1390. The memory 1390 contains instructions 1395 executable by the processing circuitry 1360, whereby the application 1320 is operable to provide one or more of the features, benefits, and / or functions disclosed herein.

[0167] The virtualized environment 1300 includes general-purpose or special-purpose network hardware devices 1330, which include a set of one or more processors or processing circuitry 1360, which may be commercial off-the-shelf (COTS) processors, application-specific integrated circuits (ASICs), or any other type of processing circuitry including digital or analog hardware components or dedicated processors. Each hardware device may include a memory 1390-1, which may be non-permanent memory for temporarily storing instructions 1395 or software executed by the processing circuitry 1360. Each hardware device may include one or more network interface controllers (NICs) 1370, also known as network interface cards, which include a physical network interface 1380. Each hardware device may also include a non-transitory, permanent machine-readable storage medium 1390-2 in which software 1395 and / or instructions executable by the processing circuitry 1360 are stored. The software 1395 may include any type of software, including software for instantiating one or more virtualization layers 1350 (also known as hypervisors), software for executing virtual machines 1340, and software that allows it to perform the functions, features, and / or benefits described in connection with some of the embodiments described herein.

[0168] The virtual machine 1340 includes virtual processing, virtual memory, virtual networking or interfaces, and virtual storage, and can be run by a corresponding virtualization layer 1350 or hypervisor. Different embodiments of instances of the virtual device 1320 can be implemented on one or more of the virtual machines 1340, and the implementation can be made in different ways.

[0169] During operation, the processing circuitry 1360 executes software 1395 to instantiate a hypervisor or virtualization layer 1350, which is sometimes referred to as a virtual machine monitor (VMM). The virtualization layer 1350 can present a virtual operating platform that appears to the virtual machines 1340 as networked hardware.

[0170] As Figure 13As shown, the hardware 1330 can be an independent network node with general or specific components. The hardware 1330 can include an antenna 13225 and can implement some functions through virtualization. Alternatively, the hardware 1330 can be part of a larger hardware cluster (e.g., in a data center or customer premise equipment (CPE)), where many hardware nodes work together and are managed by a management and orchestration (MANO) 13100, which supervises the lifecycle management of applications 1320 and so on.

[0171] In some contexts, the virtualization of hardware is referred to as network function virtualization (NFV). NFV can be used to unify numerous network device types onto industrial standard high-volume server hardware, physical switches, and physical storage that can be located in data centers and customer premise equipment.

[0172] In the context of NFV, a virtual machine 1340 can be a software implementation of a physical machine that runs programs as if they were executed on a physical non-virtualized machine. Each virtual machine 1340 and the part of the hardware 1330 that executes the virtual machine (which can be hardware dedicated to the virtual machine and / or hardware shared by the virtual machine with other virtual machines in the virtual machine 1340) form a separate virtual network element (VNE).

[0173] Still in the context of NFV, a virtual network function (VNF) is responsible for handling specific network functions running in one or more virtual machines 1340 over the hardware network infrastructure 1330 and corresponds to Figure 13 the application 1320 in

[0174] In some embodiments, one or more radio units 13200, each including one or more transmitters 13220 and one or more receivers 13210, can be coupled to one or more antennas 13225. The radio units 13200 can communicate directly with the hardware node 1330 via one or more suitable network interfaces and can be used in combination with virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station.

[0175] In some embodiments, a control system 13230 can be used to implement some signaling and can alternatively be used for communication between the hardware node 1330 and the radio units 13200.

[0176] Figure 14 A telecommunications network connected to a host computer via an intermediate network is shown according to some embodiments. Specifically, referring to Figure 14, according to an embodiment, a communication system includes a telecommunication network 1410 (e.g., a 3GPP - type cellular network), and the telecommunication network 1410 includes an access network 1411 (e.g., a radio access network) and a core network 1414. The access network 1411 includes a plurality of base stations 1412a, 1412b, 1412c (e.g., NB, eNB, gNB, or other types of wireless access points), and each base station defines a corresponding coverage area 1413a, 1413b, 1413c. Each of the base stations 1412a, 1412b, 1412c can be connected to the core network 1414 via a wired or wireless connection 1415. A first UE 1491 located in the coverage area 1413c is configured to be wirelessly connected to the corresponding base station 1412c or paged by the corresponding base station 1412c. A second UE 1492 in the coverage area 1413a can be wirelessly connected to the corresponding base station 1412a. Although a plurality of UEs 1491, 1492 are shown in this example, the disclosed embodiments equally apply to the case where a single UE is in the coverage area or a single UE is connected to the corresponding base station 1412.

[0177] The telecommunication network 1410 is itself connected to a host computer 1430, and the host computer 1430 can be implemented as the hardware and / or software of an independent server, a cloud - implemented server, a distributed server, or as processing resources in a server cluster. The host computer 1430 can be owned or controlled by a service provider, or can be operated by or on behalf of a service provider. The connections 1421 and 1422 between the telecommunication network 1410 and the host computer 1430 can extend directly from the core network 1414 to the host computer 1430, or can be via an optional intermediate network 1420. The intermediate network 1420 can be one or a combination of more than one of a public, private, or bearer network; the intermediate network 1420 (if it exists) can be a backbone network or the Internet; specifically, the intermediate network 1420 can include two or more sub - networks (not shown).

[0178] Figure 14The communication system as a whole enables a connection between the connected UEs 1491, 1492 and the host computer 1430. This connection can be described as an over-the-top (OTT) connection 1450. The host computer 1430 and the connected UEs 1491, 1492 are configured to use the access network 1411, the core network 1414, any intermediate network 1420, and possibly other infrastructure (not shown) as intermediaries to transmit data and / or signaling via the OTT connection 1450. The OTT connection 1450 can be transparent in the sense that the participating communication devices through which the OTT connection 1450 passes are not aware of the significance of the routing of the uplink and downlink communications. For example, the past routing of an incoming downlink communication with data to be forwarded (e.g., handed over) from the host computer 1430 to the connected UE 1491 may not be notified to the base station 1412 or may not need to be notified to the base station 412. Similarly, the base station 1412 does not need to be aware of the future routing of an outgoing uplink communication from the UE 1491 to the host computer 1430.

[0179] Reference will now be made to Figure 15 describe an example implementation of the UE, base station, and host computer discussed in the preceding paragraphs according to an embodiment. Figure 15 A host computer communicating with a user equipment via a base station over a partial wireless connection according to some embodiments is shown. In the communication system 1500, the host computer 1510 includes hardware 1515, and the hardware 1515 includes a communication interface 1516 configured to establish and maintain a wired or wireless connection to an interface of different communication devices of the communication system 1500. The host computer 1510 further includes a processing circuit 1518, which may have storage and / or processing capabilities. Specifically, the processing circuit 1518 may include one or more programmable processors suitable for executing instructions, application-specific integrated circuits, field-programmable gate arrays, or combinations thereof (not shown). The host computer 1510 further includes software 1511, which is stored in or accessible by the host computer 1510 and executable by the processing circuit 1518. The software 1511 includes a host application 1512. The host application 1512 is operable to provide services to a remote user (e.g., UE 1530), and the UE 1530 is connected via an OTT connection 1550 terminated at the UE 1530 and the host computer 1510. When providing services to the remote user, the host application 1512 may provide user data to be sent using the OTT connection 1550.

[0180] The communication system 1500 also includes a base station 1520 provided in a telecommunications system. The base station 1520 includes hardware 1525 that enables it to communicate with the host computer 1510 and with the UE 1530. The hardware 1525 may include: a communication interface 1526 for establishing and maintaining a wired or wireless connection to an interface of different communication devices of the communication system 1500; and a radio interface 1527 for at least establishing and maintaining a wireless connection 1570 with the UE 1530 located in the coverage area ( Figure 15 not shown) served by the base station 1520. The communication interface 1526 may be configured to facilitate the connection 1560 to the host computer 1510. The connection 1560 may be direct, or it may pass through the core network of the telecommunications system ( Figure 15 not shown) and / or through one or more intermediate networks external to the telecommunications system. In the illustrated embodiment, the hardware 2325 of the base station 1520 further includes a processing circuit 1528, which may include one or more programmable processors suitable for executing instructions, application specific integrated circuits, field programmable gate arrays, or combinations thereof (not shown). The base station 1520 also has software 1521 stored internally or accessible via an external connection. The communication system 1500 also includes the aforementioned UE 1530. The hardware 1535 of the UE 1530 may include a radio interface 1537 configured to establish and maintain a wireless connection 1570 with a base station serving the coverage area where the UE 1530 is currently located. The hardware 1535 of the UE 1530 further includes a processing circuit 1538, which may include one or more programmable processors suitable for executing instructions, application specific integrated circuits, field programmable gate arrays, or combinations thereof (not shown). The UE 1530 also includes software 1531, which is stored in or accessible by the UE 1530 and executable by the processing circuit 1538. The software 1531 includes a client application 1532. The client application 1532 is operable to provide services to a human or non-human user with the support of the host computer 1510 via the UE 1530. In the host computer 1510, the executed host application 1512 may communicate with the executed client application 1532 via an OTT connection 1550 terminated at the UE 1530 and the host computer 1510. When providing services to a user, the client application 1532 may receive request data from the host application 1512 and provide user data in response to the request data. The OTT connection 1550 may transmit both the request data and the user data. The client application 1532 may interact with the user to generate the user data it provides.

[0181] Note that Figure 15 the illustrated host computer 1510, base station 1520, and UE 1530 may be respectively associated withFigure 14 is similar or identical to one of the host computers 1430, base stations 1412a, 1412b, 1412c, and one of the UEs 1491, 1492. That is, the internal workings of these entities can be as Figure 15 shown, and independently, the surrounding network topology can be Figure 14 the network topology of.

[0182] In Figure 15 , the OTT connection 1550 has been abstractly drawn to illustrate the communication between the host computer 1510 and the UE 1530 via the base station 1520, without explicitly mentioning any intermediate devices and the exact routing of messages via these devices. The network infrastructure can determine this routing, which can be configured to hide it from the UE 1530 or from the service provider operating the host computer 1510 or from both. When the OTT connection 1550 is active, the network infrastructure can also (e.g., based on load balancing considerations or reconfiguration of the network) make a decision to dynamically change the routing.

[0183] The wireless connection 1570 between the UE 1530 and the base station 1520 is in accordance with the teachings of the embodiments described throughout this disclosure. One or more of the various embodiments improve the performance of the OTT service provided to the UE 1530 using the OTT connection 1550, where the wireless connection 1570 forms the last leg in the OTT connection 1550.

[0184] For the purpose of monitoring data rate, latency, and other factors for the improvement of one or more embodiments, a measurement process may be provided. There may also be an optional network function for reconfiguring the OTT connection 1550 between the host computer 1510 and the UE 1530 in response to changes in the measurement results. The measurement process and / or the network function for reconfiguring the OTT connection 1550 may be implemented in the software 1511 and hardware 1515 of the host computer 1510 or in the software 1531 and hardware 1535 of the UE 1530 or in both. In an embodiment, sensors (not shown) may be deployed in the communication devices through which the OTT connection 1550 passes or may be deployed in association with the communication devices through which the OTT connection 1550 passes; the sensors may participate in the measurement process by providing values of the monitored quantities exemplified above or by providing values of other physical quantities that the software 1511, 1531 may use to calculate or estimate the monitored quantities. The reconfiguration of the OTT connection 1550 may include message format, retransmission settings, preferred routing, etc.; the reconfiguration need not affect the base station 1520 and may be unknown or imperceptible to the base station 1520. Such processes and functions may be known and practiced in the art. In a particular embodiment, the measurement may involve proprietary UE signaling that facilitates the measurement by the host computer 1510 of throughput, propagation time, latency, etc. The measurement may be implemented as follows: the software 1511 and 1531 enable the use of the OTT connection 1550 to send messages (specifically, empty messages or "dummy" messages) while they monitor propagation time, errors, etc.

[0185] Figure 16 is a flowchart showing a method implemented in a communication system according to one embodiment. The communication system includes a host computer, a base station, and a UE, which may be the host computer, the base station, and the UE described with reference to Figure 14 and Figure 15 For the sake of brevity of the present disclosure, only the figure references to Figure 16 will be included in this section. In step 1610, the host computer provides user data. In sub-step 1611 (which may be optional) of step 1610, the host computer provides user data by executing a host application. In step 1620, the host computer initiates a transmission carrying the user data to the UE. In step 1630 (which may be optional), according to the teachings of the embodiments described throughout the present disclosure, the base station sends the user data carried in the transmission initiated by the host computer to the UE. In step 1640 (which may also be optional), the UE executes a client application associated with the host application executed by the host computer.

[0186] Figure 17is a flowchart showing a method implemented in a communication system according to an embodiment. The communication system includes a host computer, a base station, and a UE, which may be the host computer, base station, and UE described with reference to Figure 14 and Figure 15 For the sake of brevity of the present disclosure, only references to the figures of Figure 17 will be included in this section. In step 1710 of the method, the host computer provides user data. In an optional sub-step (not shown), the host computer provides user data by executing a host application. In step 1720, the host computer initiates a transmission carrying the user data to the UE. According to the teachings of the embodiments described throughout the present disclosure, this transmission may be via the base station. In step 1730 (which may be optional), the UE receives the user data carried in the transmission.

[0187] Figure 18 is a flowchart showing a method implemented in a communication system according to an embodiment. The communication system includes a host computer, a base station, and a UE, which may be the host computer, base station, and UE described with reference to Figure 14 and Figure 15 For the sake of brevity of the present disclosure, only references to the figures of Figure 18 will be included in this section. In step 1810 (which may be optional), the UE receives input data provided by the host computer. Additionally or alternatively, in step 1820, the UE provides user data. In sub-step 1821 of step 1820 (which may be optional), the UE provides user data by executing a client application. In sub-step 1811 of step 1810 (which may be optional), the UE executes a client application that provides user data in response to the received input data provided by the host computer. When providing user data, the executed client application may also consider user input received from the user. Regardless of the specific manner of providing user data, the UE initiates a transmission of the user data to the host computer in sub-step 1830 (which may be optional). In step 1840 of the method, according to the teachings of the embodiments described throughout the present disclosure, the host computer receives the user data sent from the UE.

[0188] Figure 19 is a flowchart showing a method implemented in a communication system according to an embodiment. The communication system includes a host computer, a base station, and a UE, which may be the host computer, base station, and UE described with reference to Figure 14 and Figure 15 For the sake of brevity of the present disclosure, only references to the figures of Figure 19Figure reference. In step 1910 (which may be optional), the base station receives user data from the UE according to the teachings of the embodiments described throughout this disclosure. In step 1920 (which may be optional), the base station initiates the transmission of the received user data to the host computer. In step 1930 (which may be optional), the host computer receives the user data carried in the transmission initiated by the base station.

[0189] Any suitable steps, methods, features, functions, or benefits disclosed herein may be performed by one or more functional units or modules of one or more virtual devices. Each virtual device may include a plurality of such functional units. These functional units may be implemented by processing circuitry, which may include one or more microprocessors or microcontrollers and other digital hardware, which may include a digital signal processor (DSP), dedicated digital logic, etc. The processing circuitry may be configured to execute program code stored in a memory, which may include one or several types of memories, such as read-only memory (ROM), random access memory (RAM), cache memory, flash memory devices, optical storage devices, etc. The program code stored in the memory includes program instructions for executing one or more telecommunication and / or data communication protocols, and instructions for executing one or more of the techniques described herein. In some embodiments, the processing circuitry may be used to cause the corresponding functional unit to perform the corresponding function according to one or more embodiments of the present disclosure.

[0190] Accordingly, in view of the above, embodiments herein generally include a communication system that includes a host computer. The host computer may include processing circuitry configured to provide user data. The host computer may also include a communication interface configured to forward the user data to a cellular network for transmission to a user equipment (UE). The cellular network includes a base station having a radio interface and processing circuitry, and the processing circuitry of the base station is configured to perform any of the steps of any of the embodiments described above for the base station.

[0191] In some embodiments, the communication system further includes a base station.

[0192] In some embodiments, the communication system further includes a UE, wherein the UE is configured to communicate with the base station.

[0193] In some embodiments, the processing circuitry of the host computer is configured to execute a host application to provide user data; in such a case, the UE includes processing circuitry configured to execute a client application associated with the host application.

[0194] Embodiments of the present disclosure also include a method implemented in a communication system including a host computer, a base station, and a user equipment (UE). The method includes: providing user data at the host computer. The method may further include: at the host computer, initiating a transmission carrying the user data to the UE via a cellular network including the base station. The base station performs any step of any of the embodiments described above for the base station.

[0195] In some embodiments, the method further includes: transmitting the user data at the base station.

[0196] In some embodiments, the user data is provided at the host computer by executing a host application. In this case, the method further includes: at the UE, executing a client application associated with the host application.

[0197] Embodiments of the present disclosure also include a user equipment (UE) configured to communicate with a base station. The UE includes a radio interface and a processing circuit configured to perform any of the embodiments described above for the UE.

[0198] Embodiments of the present disclosure also include a communication system including a host computer. The host computer includes: a processing circuit configured to provide user data; and a communication interface configured to forward the user data to a cellular network for transmission to a user equipment (UE). The UE includes a radio interface and a processing circuit. The components of the UE are configured to perform any step of any of the embodiments described above for the UE.

[0199] In some embodiments, the cellular network further includes a base station configured to communicate with the UE.

[0200] In some embodiments, the processing circuit of the host computer is configured to execute a host application to provide user data; the processing circuit of the UE is configured to execute a client application associated with the host application.

[0201] Embodiments also include a method implemented in a communication system including a host computer, a base station, and a user equipment (UE). The method includes: providing user data at the host computer; and initiating a transmission carrying the user data to the UE via a cellular network including the base station. The UE performs any step of any of the embodiments described above for the UE.

[0202] In some embodiments, the method further includes: at the UE, receiving the user data from the base station.

[0203] Embodiments of the present disclosure also include a communication system including a host computer. The host computer includes a communication interface configured to receive user data sourced from a transmission from a user equipment (UE) to a base station. The UE includes a radio interface and a processing circuit. The processing circuit of the UE is configured to perform any of the steps of any of the embodiments described above for the UE.

[0204] In some embodiments, the communication system further includes a UE.

[0205] In some embodiments, the communication system further includes a base station. In such a case, the base station includes: a radio interface configured to communicate with the UE; and a communication interface configured to forward the user data carried in the transmission from the UE to the base station to the host computer.

[0206] In some embodiments, the processing circuit of the host computer is configured to execute a host application. And the processing circuit of the UE is configured to execute a client application associated with the host application, thereby providing user data.

[0207] In some embodiments, the processing circuit of the host computer is configured to execute a host application to provide request data. And the processing circuit of the UE is configured to execute a client application associated with the host application to provide user data in response to the request data.

[0208] Embodiments of the present disclosure also include a method implemented in a communication system including a host computer, a base station, and a user equipment (UE). The method includes: at the host computer, receiving user data sent from the UE to the base station. The UE performs any of the steps of any of the embodiments described above for the UE.

[0209] In some embodiments, the method further includes: at the UE, providing user data to the base station.

[0210] In some embodiments, the method further includes: at the UE, executing a client application to provide user data to be sent. The method may further include: at the host computer, executing a host application associated with the client application.

[0211] In some embodiments, the method further includes: at the UE, executing a client application; and at the UE, receiving input data for the client application. The input data is provided at the host computer by executing a host application associated with the client application. The user data to be sent is provided by the client application in response to the input data.

[0212] The embodiment also includes a communication system including a host computer. The host computer includes a communication interface configured to receive user data sourced from a transmission from a user equipment (UE) to a base station. The base station includes a radio interface and a processing circuit. The processing circuit of the base station is configured to perform any of the steps of any of the embodiments described above for the base station.

[0213] In some embodiments, the communication system further includes a base station.

[0214] In some embodiments, the communication system further includes a UE. The UE is configured to communicate with the base station.

[0215] In some embodiments, the processing circuit of the host computer is configured to execute a host application. And the UE is configured to execute a client application associated with the host application, so as to provide user data to be received by the host computer.

[0216] Furthermore, the embodiment includes a method implemented in a communication system including a host computer, a base station, and a user equipment (UE). The method includes: at the host computer, receiving user data from the base station, the user data being sourced from a transmission that the base station has received from the UE. The UE performs any of the steps of any of the embodiments described above for the UE.

[0217] In some embodiments, the method further includes: at the base station, receiving user data from the UE.

[0218] In some embodiments, the method further includes: at the base station, initiating transmission of the received user data to the host computer.

[0219] Generally, unless explicitly given and / or implied from the context of use a different meaning, all terms used herein will be interpreted according to their ordinary meaning in the relevant technical field. All references to "an / a / the element, device, component, apparatus, step", etc. shall be construed openly as referring to at least one instance of the element, device, component, apparatus, step, etc., unless otherwise explicitly stated. The steps of any method disclosed herein need not be performed in the exact order disclosed, unless a step must explicitly be described as after or before another step and / or implicitly a step must be after or before another step. In appropriate cases, any feature of any embodiment disclosed herein can be applied to any other embodiment. Similarly, any advantage of any embodiment can be applied to any other embodiment, and vice versa. Other objectives, features, and advantages of the appended embodiments will be apparent by description.

[0220] The term "unit" may have its conventional meaning in the field of electronic products, electrical devices, and / or electronic devices, and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logic solid-state and / or discrete devices, computer programs, or instructions for performing various tasks, processes, calculations, outputs, and / or display functions, etc. (such as those functions described herein).

[0221] Some embodiments contemplated herein are described more fully with reference to the accompanying drawings. However, other embodiments are within the scope of the subject matter disclosed herein. The subject matter of this disclosure should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.

Claims

1. A method performed by a wireless device (12), the method comprising: Performing (600) authentication (14) of the wireless device (12) with a home network (10H) of the wireless device (12) by performing an authentication process run with the home network (10H); Encrypting (620) a network slice identifier (24) using encryption key material (22), the encryption key material (22) being obtainable from the authentication (14) with the home network (10H), shared between the wireless device (12) and the home network (10H), not shared with an access network (10S) of the wireless device (12), and bound to the run of the authentication process with the home network (10H), wherein the access network (10S) is different from the home network (10H); and Sending (630) a message (20) including the encrypted network slice identifier (26) to the access network (10S) of the wireless device (12), The network slice identifier (24) includes single network slice selection assistance information S-NSSAI, and the encryption key material (22) includes a key K dedicated to encrypting the network slice identifier (24). NSSAI , and wherein the method further comprises: by K NSSAI = KDF(Key, S), the key K obtained from the authentication (14) with the home network (10H) AUSF Directly derive the encryption key material (22), where KDF is a key derivation function, where Key is the key K AUSF , and wherein S is a string including one or more input parameters and a concatenation of one or more corresponding lengths of the one or more input parameters.

2. The method according to claim 1, wherein The home network (10H) is a 5G network.

3. The method according to claim 1, wherein The encrypted network slice identifier (26) is included in an access stratum AS part of the message (20).

4. The method according to claim 1, wherein The encrypted network slice identifier (26) is included in a non-access stratum NAS part of the message (20).

5. A method performed by a network node (18S) in an access network (10S) of a wireless device (12), wherein the access network (10S) is different from a home network (10H) of the wireless device (12), the method comprising: Receiving (700) by the network node (18S) in the access network (10S) a message (20) including an encrypted network slice identifier (26); Sending a request to decrypt the encrypted network slice identifier (26) using encryption key material (22) to a network node (16H) in the home network (10H), the encryption key material (22) being obtainable by the wireless device (22) from the authentication (14) of the wireless device (12) with the home network (10H), shared between the wireless device (12) and the home network (10H), not shared with the access network (10S) of the wireless device (12), and bound to the run of the authentication process with the home network (10H); and Receiving from the home network (10H) a response to the request, the response including the decrypted network slice identifier, Wherein, the network slice identifier (24) includes a single network slice selection assistance information S-NSSAI, and wherein, the encryption key material (22) includes a key K dedicated to encrypting the network slice identifier (24). NSSAI , and wherein, the encryption key material (22) is generated by K NSSAI = KDF(Key, S) from the key K that can be obtained from the authentication (14) performed between the wireless device (12) and the home network (10H). AUSF directly derived, where KDF is a key derivation function, where Key is the key K AUSF , and wherein, S is a string including one or more input parameters and the concatenation of the one or more corresponding lengths of the one or more input parameters.

6. The method according to claim 5 further comprises: Selecting (720) a network slice or an access and mobility management function AMF for serving the wireless device (12) based on the decrypted network slice identifier.

7. The method according to any one of claims 5-6, wherein, The home network (10H) is a 5G network.

8. The method according to any one of claims 5-6, wherein The encrypted network slice identifier (26) is included in an access stratum AS part of the message (20).

9. The method according to any one of claims 5-6, wherein The encrypted network slice identifier (26) is included in a non-access stratum NAS part of the message (20).

10. A method performed by a network node (16H) in a home network (10H) of a wireless device (12), the method comprising: Receiving (800) a request to decrypt an encrypted network slice identifier (26) from a visited network (10S) of the wireless device (12), the visited network (10S) being different from the home network (10H); Decrypting (810) the encrypted network slice identifier (26) using encryption key material (22), the encryption key material (22) being obtainable by the wireless device (12) from an authentication (14) of the wireless device (12) with the home network (10H), shared between the wireless device (12) and the home network (10H), not shared with a visited network (10S) of the wireless device (12), and bound to the running of an authentication process between the wireless device (12) and the home network (10H); And Sending (820) a response to the request, the response including the decrypted network slice identifier obtained from the decryption, Wherein, the network slice identifier (24) includes a single network slice selection assistance information S-NSSAI, and wherein, the encryption key material (22) includes a key K dedicated to encrypting the network slice identifier (24). NSSAI , and wherein, the method further includes: through K NSSAI = KDF(Key, S), directly derive the encryption key material (22) from the key K that can be obtained from the authentication (14) performed between the wireless device (12) and the home network (10H), where KDF is a key derivation function, where Key is the key K AUSF , and wherein, S is a string including one or more input parameters and the concatenation of the one or more corresponding lengths of the one or more input parameters. AUSF ​ 11. The method according to claim 10, wherein, The home network (10H) is a 5G network.

12. A wireless device (12), comprising: A communication circuit (920); And A processing circuit (910) configured to: Perform an authentication (14) of the wireless device (12) with the home network (10H) by executing the running of an authentication process with the home network (10H) of the wireless device (12); Encrypt a network slice identifier (24) using encryption key material (22), the encryption key material (22) being obtainable from the authentication (14) with the home network (10H), shared between the wireless device (12) and the home network (10H), not shared with a visited network (10S) of the wireless device (12), and bound to the running of an authentication process with the home network (10H), wherein the visited network (10S) is different from the home network (10H); and Send (630) a message (20) including the encrypted network slice identifier (26) to a visited network (10S) of the wireless device (12), Wherein, the network slice identifier (24) includes a single network slice selection assistance information S-NSSAI, wherein the encryption key material (22) includes a key K dedicated to encrypting the network slice identifier (24) NSSAI and wherein the processing circuit (910) is further configured to: by K NSSAI = KDF(Key, S), directly derive the encryption key material (22) from the key K that can be obtained from the authentication (14) with the home network (10H), where KDF is a key derivation function, where Key is the key K AUSF and wherein S is a string including one or more input parameters and the concatenation of the one or more corresponding lengths of the one or more input parameters. AUSF ​ 13. The wireless device according to claim 12, wherein, The processing circuit (910) is configured to perform the method according to any one of claims 2-4.

14. A network node (18S, 900) in a visited network (10S) of a wireless device (12), wherein the visited network (10S) is different from a home network (10H) of the wireless device (12), the network node (18S, 900) comprising: A communication circuit (1020); And A processing circuit (1010) configured to: Receive, by a network node (18S) in the visited network (10S), a message (20) including an encrypted network slice identifier (26); Send a request to a network node (16H) in the home network (10H) to decrypt the encrypted network slice identifier (26) using encryption key material (22), the encryption key material (22) being obtainable by the wireless device (22) from an authentication (14) of the wireless device (12) with the home network (10H), shared between the wireless device (12) and the home network (10H), not shared with the visited network (10S) of the wireless device (12), and bound to the running of the authentication process with the home network (10H); and Receive a response to the request from the home network (10H), the response including the decrypted network slice identifier, Wherein, the network slice identifier (24) includes a single network slice selection assistance information S-NSSAI, and wherein, the encryption key material (22) includes a key K dedicated to encrypting the network slice identifier (24). NSSAI , and wherein, the encryption key material (22) is NSSAI directly derived from a key K obtained from the authentication (14) that can be performed between the wireless device (12) and the home network (10H) by K AUSF = KDF(Key, S), where KDF is a key derivation function, where Key is the key K AUSF , and wherein, S is a string including one or more input parameters and a concatenation of one or more corresponding lengths of the one or more input parameters.

15. The network node according to claim 14, wherein, The processing circuit (1010) is configured to perform the method according to any one of claims 6-9.

16. A network node (16H, 900) in a home network (10H) of a wireless device (12), the network node (16H, 900) comprising: A communication circuit (1020); And A processing circuit (1010), configured to: Receive a request to decrypt an encrypted network slice identifier (26) from a visited network (10S) of the wireless device (12), wherein the visited network (10S) is different from the home network (10H); Decrypt the encrypted network slice identifier (26) using encryption key material (22), the encryption key material (22) being obtainable by the wireless device (12) from an authentication (14) of the wireless device (12) with the home network (10H), shared between the wireless device (12) and the home network (10H), not shared with the visited network (10S) of the wireless device (12), and bound to the running of the authentication process between the wireless device (12) and the home network (10H); and Send a response to the request, the response including the decrypted network slice identifier obtained from the decryption, Wherein, the network slice identifier (24) includes a single network slice selection assistance information S-NSSAI, and wherein, the encryption key material (22) includes a key K dedicated to encrypting the network slice identifier (24). NSSAI And wherein, the processing circuit (1010) is further configured to: directly derive the encryption key material (22) from a key K obtained from the authentication (14) that can be performed between the wireless device (12) and the home network (10H) through K NSSAI = KDF(Key, S), where KDF is a key derivation function, where Key is the key K AUSF , and wherein, S is a string including one or more input parameters and the concatenation of the one or more corresponding lengths of the one or more input parameters. AUSF ​ 17. The network node according to claim 16, wherein, The processing circuit (1010) is configured to perform the method according to claim 11.

18. A computer program product comprising instructions which, when executed by at least one processor of a wireless device (12), cause the wireless device (12) to perform the method according to any one of claims 1-4.

19. A computer program product comprising instructions which, when executed by at least one processor of a network node (18S), cause the network node (18S) to perform the method according to any one of claims 5-9.

20. A computer program product comprising instructions which, when executed by at least one processor of a network node (16H), cause the network node (16H) to perform the method according to any one of claims 10-11.

21. A computer-readable storage medium comprising instructions which, when executed by at least one processor of a wireless device (12), cause the wireless device (12) to perform the method according to any one of claims 1-4.

22. A computer-readable storage medium comprising instructions which, when executed by at least one processor of a network node (18S), cause the network node (18S) to perform the method according to any one of claims 5-9.

23. A computer-readable storage medium comprising instructions which, when executed by at least one processor of a network node (16H), cause the network node (16H) to perform the method according to any one of claims 10-11.

Citation Information

Patent Citations

  • Circuit arrangement and a method for roaming between a visited network and a mobile station

    US20140003605A1

  • Methods and systems for privacy protection of 5g slice identifier

    WO2018236819A1