Method for integrity protection of user plane data

By having the UE indicate the integrity protection mode during registration and adjust the policy according to network instructions, the problem of unprotected user plane data in 4G networks is solved, and flexible and secure integrity protection of user plane data in next-generation networks is achieved.

CN115278659BActive Publication Date: 2026-01-09TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210843592.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2017-01-30
Filing Date
2018-01-30
Publication Date
2026-01-09
Estimated Expiration
2038-01-30

AI Technical Summary

Technical Problem

In 3GPP Release 13, integrity protection of user plane data between the UE and the core network was not considered in Long Term Evolution (LTE) networks, resulting in the inability to implement integrity protection in 4G networks. However, in next-generation networks, integrity protection of user plane data is a necessary feature.

Method used

A method is provided that allows a user device (UE) to indicate its supported integrity protection modes to a communication network during registration, and to adjust the protection policy for user plane data according to the instructions of the communication network, including integrity protection, no integrity protection, or simultaneous integrity and confidentiality protection, and can indicate the maximum data rate.

Benefits of technology

It enables flexible and controllable integrity protection of user plane data in next-generation networks, ensuring the security and consistency of data transmission and adapting to the needs of different network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115278659B_ABST
    Figure CN115278659B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a method for integrity protection of user plane data, in particular a method for operating a radio access node of a communication network, the radio access node comprising a source radio access node, the method comprising: in a handover of a user equipment, UE, from the source radio access node to a target radio access node, sending an indication of an IPUP mode to be used by the communication network for the UE, wherein the IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE; not using integrity protection for user plane data exchanged with the UE; or using integrity protection for user plane data and not using confidentiality protection for user plane data.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of patent application No. 201880017371.7, filed in the National Phase of the PCT International Application PCT / EP2018 / 052285 on January 30, 2018, with the title "Method for integrity protection of user plane data". TECHNICAL FIELD

[0002] The present disclosure relates to methods for operating a user equipment (UE), a radio access node and a core network node in a communication network. The present disclosure also relates to apparatuses and computer programs configured to perform the methods for operating the UE, the radio access node and the core network node. BACKGROUND

[0003] Integrity protection of user plane (UP) data between the UE and the core network was introduced in 3GPP Release 13 for enhanced GPRS for Internet of Things (IoT) devices. With the negotiation of the implementation of integrity protection of UP data occurring at the NAS layer (mobility management layer) and the integrity protection supported on the LLC layer in the core network, the support of integrity protection of UP data in the UE and in the network is optional.

[0004] The negotiation of integrity protection of UP data is not considered in the standards for Long Term Evolution (4G) networks, so integrity protection of UP data is not possible in these networks. However, integrity protection of UP data between the UE and the base station can be a desirable feature of next generation (5G) networks.

[0005] In next generation networks, the Radio Access Network (RAN) can adopt the RAN architecture and interfaces as specified in TR 33.801 vl.0.0 [x]. Figure 1 A possible new RAN architecture for next generation networks is illustrated. Referring to Figure 1 , it is expected that gNBs 102 and eLTE eNBs 104 can be connected to the same Next Generation Core (NGC) 106. A gNB 102 will be able to connect to other gNBs 102 or (e)LTE eNBs 104 through a new RAN interface, named Xn interface 108. SUMMARY

[0006] Examples of the present disclosure provide methods that solve the operation of a UE, a radio access node and a core network node in a communication network. These methods involve the use of integrity protection of user plane data exchanged between the UE and the communication network.

[0007] According to an aspect of the present disclosure, a method for operating a user equipment, UE, is provided, wherein the UE is configured to connect to a communication network. The method comprises indicating, to the communication network, an integrity protection for user plane, IPUP, mode supported by the UE upon requesting to register with the communication network. The IPUP mode comprises one of using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0008] The method can further comprise indicating, to the communication network, a UE preference regarding the IPUP mode to be used by the communication network for the UE. The indicated UE preference can apply to at least one of all data exchanged with the communication network, or data exchanged with one specific slice or multiple slices of the communication network.

[0009] The method can further comprise receiving, from the communication network, an indication of the IPUP mode to be used by the communication network for the UE. The indication can apply to at least one of all data exchanged with the communication network, or data exchanged with one specific slice or multiple slices of the communication network.

[0010] Indicating, to the communication network, the IPUP mode of using integrity protection for user plane data exchanged with the UE or using integrity protection for user plane data and not using confidentiality protection for user plane data can comprise indicating, to the communication network, a maximum data rate of user plane data for which integrity protection can be applied. The data rate can be a maximum total data rate.

[0011] The method can further comprise informing a user of the UE about the IPUP mode to be used by the communication network for the UE.

[0012] The method can further comprise, if the IPUP mode indicated by the communication network does not match a UE preference regarding which IPUP mode should be used by the communication network for the UE, performing at least one of the following: refusing to connect to the network; disconnecting from the network; informing a user of the UE that the IPUP mode indicated by the communication network does not match the UE preference regarding which IPUP mode should be used by the communication network for the UE.

[0013] The method can further comprise, if the UE performs at least one of refusing to connect to the network or disconnecting from the network, performing at least one of the following: requesting to register with a different radio access node of the communication network, or requesting to register with a different communication network.

[0014] The method can further comprise querying a list comprising at least one of: a radio access node or a communication network supporting integrity protection for user plane data, and selecting from the list at least one of: the radio access node of the communication network or a different communication network for requesting registration. The list can be configured in a memory of the UE. The list can be received over a radio link.

[0015] The method can further comprise receiving a message from a target radio access node of the communication network during a procedure to handover the UE from a source radio access node to the target radio access node, the message comprising an indication that the target radio access node will use a different IPUP mode for the UE than a IPUP mode used by the source radio access node.

[0016] The method can further comprise if the indication from the target radio access node is that the IPUP mode to be used by the communication network via the target radio access node does not match a UE preference regarding which IPUP mode should be used for the UE by the communication network, performing at least one of: disconnecting from the network; accepting the handover and informing a user of the UE of the IPUP mode to be used for the UE by the communication network via the target radio access node; or seeking a handover to a different radio access node of the communication network.

[0017] The method can further comprise during a procedure for secondary radio access node addition, secondary radio access node modification requiring a key update, or data radio bearer offloading, receiving an indication from a radio access node of the communication network of an IPUP mode to be used for the UE by the communication network; and if the indicated IPUP mode involves use of integrity protection for user plane data, deriving and using a key for integrity protection of user plane data.

[0018] The indication of the IPUP mode to be used for the UE by the communication network can be received with a RRC reconfiguration request.

[0019] According to another aspect of the disclosure, there is provided a method for operating a radio access node of a communication network. The method comprises receiving an indication of an integrity protection for user plane, IPUP, mode supported by a user equipment, UE, from the UE requesting registration with the communication network. The IPUP mode comprises one of: use of integrity protection for user plane data exchanged with the UE, no use of integrity protection for user plane data exchanged with the UE, or use of integrity protection for user plane data and no use of confidentiality protection for user plane data. The indication is received from the UE via the communication network.

[0020] The method can further comprise receiving, from the UE, an indication of an IPUP mode to be used by the communication network for the UE. The indicated UE preference can apply to at least one of: all data exchanged with the communication network, or data exchanged with one particular slice or multiple slices of the communication network.

[0021] Receiving, from the UE, the indicated IPUP mode of using integrity protection for user plane data exchanged with the UE or using integrity protection for user plane data and not using confidentiality protection for user plane data can comprise receiving, from the UE, a maximum data rate of user plane data for which integrity protection can be applied. The data rate can be a maximum total data rate.

[0022] The method can further comprise receiving, from a core node of the communication network, an indication of an IPUP mode to be used by the communication network for the UE.

[0023] The method can further comprise, if the indicated IPUP mode is supported by the radio access node, sending, to the core node, an indication that the IPUP mode to be used by the communication network for the UE will be enabled by the radio access node.

[0024] The method can further comprise, if the indicated IPUP mode received from the core node of the communication network is not supported by the radio access node, performing at least one of: rejecting a registration request received from the UE; or omitting to send, to the core node, an indication that the IPUP mode to be used by the communication network for the UE will be enabled by the radio access node.

[0025] The method can further comprise sending, to the UE, an indication of an IPUP mode to be used by the communication network for the UE.

[0026] If the IPUP mode to be used by the communication network for the UE involves using integrity protection for user plane data, the indication of the IPUP mode to be used by the communication network for the UE can comprise an identifier of an algorithm for integrity protection of UP data.

[0027] The IPUP mode indicated to the UE by the radio access node can be an IPUP mode received from a core node of the communication network.

[0028] The IPUP mode indicated to the UE can be selected by the radio access node according to a policy hosted on the radio access node.

[0029] According to another aspect of the disclosure, there is provided a method for operating a radio access node of a communication network, the radio access node comprising a target radio access node. The method comprises, during a procedure of handing over a user equipment, UE, from a source radio access node to the target radio access node, receiving an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0030] The method can further comprise checking whether an indication is received from the target radio access node that the target radio access node will enable the IPUP mode to be used by the communication network for the UE.

[0031] The method can further comprise assuming that the target radio access node will not enable the IPUP mode to be used by the communication network for the UE, if no indication is received that the target radio access node will enable the IPUP mode to be used by the communication network for the UE.

[0032] According to another aspect of the disclosure, there is provided a method for operating a radio access node of a communication network, the radio access node comprising a target radio access node. The method comprises, during a procedure of handing over a user equipment, UE, from a source radio access node to the target radio access node, receiving an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0033] The indication of the IPUP mode to be used by the communication network for the UE can be received from at least one of the source radio access node or a core node of the communication network.

[0034] The method can further comprise deciding whether to use the indicated IPUP mode, and if it is decided not to use the indicated IPUP mode, sending an indication to the UE that the target radio access node will use a different IPUP mode for the UE than the IPUP mode used by the source radio access node.

[0035] The indication of the IPUP mode to be used by the communication network for the UE can be received from the source radio access node, and the method can further comprise sending the indication of the IPUP mode received from the source radio access node to a core node of the communication network.

[0036] The method can further comprise, if the target radio access node supports the indicated IPUP mode, sending, to at least one of the source radio access node or a core node of the communication network, an indication that the target radio access node will enable the IPUP mode to be used by the communication network for the UE.

[0037] The method can further comprise, if the target radio access node does not support the received indicated IPUP mode, performing at least one of: rejecting the handover of the UE, or accepting the handover of the UE and omitting to send an indication that the target radio access node will enable the IPUP mode to be used by the communication network for the UE.

[0038] According to another aspect of the disclosure, there is provided a method for operating a radio access node of a communication network, the radio access node comprising a primary radio access node. The method comprises sending, to a secondary radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a UE. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data. The indication is sent to the secondary radio access node during a procedure for at least one of the secondary radio access node addition, the secondary radio access node modification requiring a key update, or data radio bearer, DRB, deactivation.

[0039] If the IPUP mode indicated to the secondary radio access node involves using integrity protection for user plane data, the indication of the IPUP mode to be used by the communication network for the UE can comprise a list of supported algorithms for integrity protection of UP data.

[0040] The method can further comprise checking whether an indication is received from the secondary radio access node that the secondary radio access node will enable the IPUP mode to be used by the communication network for the UE.

[0041] The method can further comprise, if no indication is received that the secondary radio access node will enable the IPUP mode to be used by the communication network for the UE, assuming that the secondary radio access node will not enable the IPUP mode to be used by the communication network for the UE.

[0042] The method can further comprise, if the indication of the IPUP mode to be used by the communication network for the UE is sent to the secondary radio access node during a DRB deactivation procedure, sending, to the UE, an RRC reconfiguration request comprising the indication of the IPUP mode to be used by the communication network for the UE.

[0043] The RRC reconfiguration request can include an identity of a selected integrity algorithm to be used for UP integrity protection.

[0044] According to another aspect of the disclosure, there is provided a method for operating a radio access node of a communication network, the radio access node comprising a secondary radio access node. The method comprises receiving, from a primary radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a UE. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data. The indication is received from the primary radio access node during a procedure for at least one of: secondary radio access node addition, secondary radio access node modification requiring a key update, data radio bearer, DRB, deactivation.

[0045] If the IPUP mode indicated by the primary radio access node involves using integrity protection for user plane data, the indication of the IPUP mode to be used by the communication network for the UE can comprise an identifier of an integrity algorithm to be used for UP integrity protection.

[0046] The method can further comprise sending, to the primary radio access node, an indication that the secondary radio access node will enable the IPUP mode to be used by the communication network for the UE, if the secondary radio access node supports the indicated IPUP mode.

[0047] The method can further comprise performing at least one of: rejecting the requested procedure from the primary radio access node, or accepting the requested procedure from the primary radio access node and omitting to send, to the primary radio access node, an indication that the secondary radio access node will enable the IPUP mode to be used by the communication network for the UE, if the target radio access node does not support the received indicated IPUP mode.

[0048] The method can further comprise deriving and using a key for integrity protection of user plane data exchanged with the UE, if the indication of the IPUP mode to be used by the communication network for the UE is received from the primary radio access node during a procedure for secondary radio access node addition or secondary radio access node modification requiring a key update, and if the IPUP mode indicated by the primary radio access node involves using integrity protection for user plane data.

[0049] According to another aspect of the disclosure, a method for operating a core node in a communication network is provided. The method comprises sending, to a radio access node of the communication network, an indication for a user plane integrity protection, IPUP, mode to be used by the communication network for a user equipment, UE, requesting to register with the communication network. The IPUP mode comprises one of using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0050] The method can further comprise checking whether an indication is received from the radio access node of the communication network that the radio access node of the communication network will enable the IPUP mode indicated to the radio access node of the communication network.

[0051] The method can further comprise assuming that the radio access node will not enable the IPUP mode to be used by the communication network for the UE if no indication is received that the radio access node will enable the IPUP mode indicated to the radio access node.

[0052] The core network node can be a new core network node for the UE, and the method can further comprise sending a request for information related to the UE to an old core network node for the UE, and receiving from the old core network node an indication of the IPUP mode to be used by the communication network for the UE.

[0053] The method can further comprise receiving, during an update location procedure, an indication of the IPUP mode to be used by the communication network for the UE from a subscription management node corresponding to the UE.

[0054] The method can further comprise deciding the IPUP mode to be used by the communication network for the UE.

[0055] The method can further comprise if the IPUP mode decided by the core network node does not match a preference communicated by the UE for the IPUP mode to be used by the communication network for the UE, performing one of rejecting a request from the UE to register with the communication network, or accepting a request from the UE to register with the communication network and informing the UE of the IPUP decided by the core network node.

[0056] The decided IPUP mode applies to at least one of all data exchanged between the UE and the communication network, or data exchanged between the UE and one specific slice or multiple slices of the communication network.

[0057] The method can further comprise indicating to the UE the decided IPUP mode to be used by the communication network for the UE.

[0058] According to another aspect of the disclosure, there is provided a method for operating a core node in a communication network, the core network node comprising an old core network node for a user equipment, UE, requesting registration with the communication network. The method comprises receiving, from a new core network node for the UE, an information request related to the UE, and sending, to the new core network node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0059] The indicated IPUP mode can be applied to at least one of: all data exchanged between the UE and the communication network, or data exchanged between the UE and one specific slice or slices of the communication network.

[0060] According to another aspect of the disclosure, there is provided a method for operating a core node in a communication network. The method comprises receiving, from a target radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a user equipment, UE, to be handed over to the target radio access node, verifying whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode stored by the core network node for the UE, and if there is a mismatch between the indicated IPUP mode and the stored IPUP mode, performing at least one of: logging the mismatch as an event or triggering an alarm. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0061] According to another aspect of the disclosure, there is provided a method for operating a core node in a communication network. The method comprises sending, to a target radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a UE to be handed over to the target radio access node. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0062] The method can further comprise checking whether an indication is received from the target radio access node that the target radio access node will enable the IPUP mode to be used by the communication network for the UE.

[0063] According to another aspect of the disclosure, there is provided a computer program comprising instructions which, when executed on at least one processor, cause the at least one processor to carry out the method according to any of the preceding aspects of the disclosure.

[0064] According to another aspect of the disclosure, there is provided a carrier containing the computer program according to the preceding aspect of the disclosure, wherein the carrier comprises one of an electrical signal, an optical signal, a radio signal, or a computer readable storage medium.

[0065] According to another aspect of the disclosure, there is provided a computer program product comprising a non-transitory computer readable medium having stored thereon the computer program according to the preceding aspect of the disclosure.

[0066] According to another aspect of the disclosure, there is provided an apparatus for operating a user equipment, UE, configured to connect to a communication network, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor, causing the apparatus to be operable to indicate, to the communication network, an integrity protection for user plane, IPUP, mode supported by the UE upon requesting registration with the communication network. The IPUP mode comprises one of using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0067] According to another aspect of the disclosure, there is provided an apparatus for operating a radio access node of a communication network, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor, causing the apparatus to be operable to receive, from a user equipment, UE, requesting registration with the communication network, an indication of an integrity protection for user plane, IPUP, mode supported by the UE. The IPUP mode comprises one of using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data. The indication is received from the UE via the communication network.

[0068] According to another aspect of the disclosure, there is provided an apparatus for operating a radio access node of a communication network, the radio access node comprising a source radio access node, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to be operable to transmit, during a procedure to handover a user equipment, UE, from the source radio access node to a target radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0069] According to another aspect of the disclosure, there is provided an apparatus for operating a radio access node of a communication network, the radio access node comprising a target radio access node, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to be operable to receive, during a procedure to handover a user equipment, UE, from a source radio access node to the target radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0070] According to another aspect of the disclosure, there is provided an apparatus for operating a radio access node of a communication network, the radio access node comprising a master radio access node, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to be operable to transmit, to a secondary radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a UE. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data. The indication is transmitted to the secondary radio access node during a procedure for at least one of: secondary radio access node addition, secondary radio access node modification requiring a key update, or data radio bearer, DRB, offloading.

[0071] According to another aspect of the disclosure, there is provided an apparatus for operating a radio access node of a communication network, the radio access node comprising a secondary radio access node, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to be operable to receive, from a primary radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a user equipment, UE. The IPUP mode comprises one of: integrity protection to be used for user plane data exchanged with the UE, no integrity protection to be used for user plane data exchanged with the UE, or integrity protection to be used for user plane data and no confidentiality protection to be used for user plane data. The indication is received from the primary radio access node during a procedure for at least one of the secondary radio access node addition, secondary radio access node modification requiring a key update, data radio bearer, DRB, deactivation.

[0072] According to another aspect of the disclosure, there is provided an apparatus for operating a core node in a communication network, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to be operable to send, to a radio access node of the communication network, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a user equipment, UE, requesting registration with the communication network. The IPUP mode comprises one of: integrity protection to be used for user plane data exchanged with the UE, no integrity protection to be used for user plane data exchanged with the UE, or integrity protection to be used for user plane data and no confidentiality protection to be used for user plane data.

[0073] According to another aspect of the disclosure, there is provided an apparatus for operating a core node in a communication network, the core network node comprising an old core network node for a user equipment, UE, requesting registration with the communication network, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to be operable to receive, from a new core network node for the UE, a request for information related to the UE, and to send, to the new core network node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE. The IPUP mode comprises one of: integrity protection to be used for user plane data exchanged with the UE, no integrity protection to be used for user plane data exchanged with the UE, or integrity protection to be used for user plane data and no confidentiality protection to be used for user plane data.

[0074] According to another aspect of the disclosure, there is provided an apparatus for operating a core node in a communication network, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to be operable to receive, from a target radio access node, an indication of an integrity protection for user plane, IPUP, mode used by the communication network for a user equipment, UE, to be handed over to the target radio access node, verify whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode stored by the core network node for the UE, and if there is a mismatch between the indicated IPUP mode and the stored IPUP mode, perform at least one of the following: record the mismatch as an event or trigger an alarm. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0075] According to another aspect of the disclosure, there is provided an apparatus for operating a core node in a communication network, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to be operable to receive, from a target radio access node, an indication of an integrity protection for user plane, IPUP, mode used by the communication network for a user equipment, UE, to be handed over to the target radio access node, verify whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode stored by the core network node for the UE, and if there is a mismatch between the indicated IPUP mode and the stored IPUP mode, perform at least one of the following: record the mismatch as an event or trigger an alarm. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0076] According to another aspect of the disclosure, there is provided an apparatus for operating a user equipment, UE, configured to be connected to a communication network, the apparatus configured to indicate, to the communication network, an integrity protection for user plane, IPUP, mode supported by the UE when requesting to register with the communication network. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0077] According to another aspect of this disclosure, an apparatus is provided for operating a radio access node in a communication network, the apparatus being configured to receive from a user equipment (UE) requesting registration with the communication network an indication of an IPUP mode for user plane integrity protection supported by the UE. The IPUP mode includes one of the following: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data, the indication being received from the UE via the communication network.

[0078] According to another aspect of this disclosure, an apparatus is provided for operating a radio access node of a communication network, the radio access node including a source radio access node, the apparatus being configured to: during a handover of a user equipment (UE) from the source radio access node to a target radio access node, transmit an indication by the communication network of a user plane integrity protection IPUP mode to be used by the UE. The IPUP mode includes one of the following: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0079] According to another aspect of this disclosure, an apparatus is provided for operating a radio access node of a communication network, the radio access node including a target radio access node, the apparatus being configured to: during a handover of a user equipment (UE) from a source radio access node to the target radio access node, receive an indication from the communication network of an IPUP mode for user plane integrity protection to be used by the UE. The IPUP mode includes one of the following: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for the user plane data.

[0080] According to another aspect of this disclosure, an apparatus is provided for operating a radio access node of a communication network, the radio access node including a primary radio access node, the apparatus being configured to send an indication to a secondary radio access node of a user plane integrity protection IPUP mode to be used by the communication network for a UE. The IPUP mode includes one of the following: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data. The indication is sent to the secondary radio access node during at least one of the following processes: adding a secondary radio access node, modifying a secondary radio access node requiring a key update, or offloading a data radio bearer (DRB).

[0081] According to another aspect of the disclosure, there is provided an apparatus for operating a radio access node of a communication network, the radio access node comprising a secondary radio access node, the apparatus being configured to receive, from a primary radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a user equipment, UE. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data. The indication is received from the primary radio access node during a procedure for at least one of the secondary radio access node addition, the secondary radio access node modification requiring a key update, data radio bearer, DRB, deactivation.

[0082] According to another aspect of the disclosure, there is provided an apparatus for operating a core node in a communication network, the apparatus being configured to send, to a radio access node of the communication network, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a user equipment, UE, requesting registration with the communication network. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0083] According to another aspect of the disclosure, there is provided an apparatus for operating a core node in a communication network, the core network node comprising an old core network node for a user equipment, UE, requesting registration with the communication network, the apparatus being configured to: receive, from a new core network node for the UE, a request for information related to the UE, and send, to the new core network node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE, the IPUP mode comprising one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0084] According to another aspect of the disclosure, there is provided an apparatus for operating a core node in a communication network, the apparatus configured to receive, from a target radio access node, an indication of an integrity protection for user plane, IPUP, mode used by the communication network for a user equipment, UE, to be handed over to the target radio access node, verify whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode stored by the core network node for the UE, and if there is a mismatch between the indicated IPUP mode and the stored IPUP mode, perform at least one of the following: log the mismatch as an event or trigger an alarm. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0085] According to another aspect of the disclosure, there is provided an apparatus for operating a core node in a communication network, the apparatus configured to receive, from a target radio access node, an indication of an integrity protection for user plane, IPUP, mode used by the communication network for a user equipment, UE, to be handed over to the target radio access node, verify whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode stored by the core network node for the UE, and if there is a mismatch between the indicated IPUP mode and the stored IPUP mode, perform at least one of the following: log the mismatch as an event or trigger an alarm. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0086] According to another aspect of the disclosure, there is provided an apparatus for operating a core node in a communication network, the apparatus configured to receive, from a target radio access node, an indication of an integrity protection for user plane, IPUP, mode used by the communication network for a user equipment, UE, to be handed over to the target radio access node, verify whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode stored by the core network node for the UE, and if there is a mismatch between the indicated IPUP mode and the stored IPUP mode, perform at least one of the following: log the mismatch as an event or trigger an alarm. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0087] According to another aspect of the disclosure, there is provided an apparatus for operating a core node in a communication network, the apparatus configured to receive, from a target radio access node, an indication of an integrity protection for user plane, IPUP, mode used by the communication network for a user equipment, UE, to be handed over to the target radio access node, verify whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode stored by the core network node for the UE, and if there is a mismatch between the indicated IPUP mode and the stored IPUP mode, perform at least one of the following: log the mismatch as an event or trigger an alarm. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0088] According to another aspect of the disclosure, there is provided an apparatus for operating a radio access node of a communication network, the radio access node comprising a target radio access node, the apparatus comprising a receiving module for receiving, during a procedure of handover of a user equipment, UE, from a source radio access node to the target radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0089] According to another aspect of the disclosure, there is provided an apparatus for operating a radio access node of a communication network, the radio access node comprising a target radio access node, the apparatus comprising a receiving module for receiving, during a procedure of handover of a user equipment, UE, from a source radio access node to the target radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0090] According to another aspect of the disclosure, there is provided an apparatus for operating a radio access node of a communication network, the radio access node comprising a target radio access node, the apparatus comprising a receiving module for receiving, during a procedure of handover of a user equipment, UE, from a source radio access node to the target radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0091] According to another aspect of the disclosure, there is provided an apparatus for operating a radio access node of a communication network, the radio access node comprising a secondary radio access node, the apparatus comprising a receiving module for receiving, from a primary radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a user equipment, UE. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data. The indication is received from the primary radio access node during a procedure for at least one of the secondary radio access node addition, the secondary radio access node modification requiring a key update, data radio bearer, DRB, deactivation.

[0092] According to another aspect of the disclosure, there is provided an apparatus for operating a core node in a communication network, the apparatus comprising a sending module for sending, to a radio access node of the communication network, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a user equipment, UE, requesting registration with the communication network. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0093] According to another aspect of the disclosure, there is provided an apparatus for operating a core node in a communication network, the core network node comprising an old core network node for a user equipment, UE, requesting registration with the communication network, the apparatus comprising: a receiving module for receiving, from a new core network node for the UE, a request for information related to the UE; and a sending module for sending, to the new core network node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0094] According to another aspect of the disclosure, there is provided an apparatus for operating a core node in a communication network, the apparatus comprising: a receiving module for receiving, from a target radio access node, an indication by the communication network of an integrity protection for user plane, IPUP, mode to be used by a user equipment, UE, being handed over to the target radio access node; and a processing module for verifying whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode stored by the core network node for the UE, and if there is a mismatch between the indicated IPUP mode and the stored IPUP mode, performing at least one of the following: logging the mismatch as an event or triggering an alarm. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0095] According to another aspect of the disclosure, there is provided an apparatus for operating a core node in a communication network, the apparatus comprising a sending module for sending, to a target radio access node, an indication by the communication network of an integrity protection for user plane, IPUP, mode to be used by a user equipment, UE, being handed over to the target radio access node. The IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data. BRIEF DESCRIPTION OF DRAWINGS

[0096] For a better understanding of the present disclosure, and to show how it can be implemented, reference will now be made, by way of example, to the accompanying drawings in which:

[0097] Figure 1 is a representation of a possible RAN architecture for next generation networks;

[0098] Figures 2a to 2c shows a flow chart of processing steps in a method for operating a user equipment (UE);

[0099] Figure 3 is a flow chart showing processing steps in a method for operating a radio access node in a communication network;

[0100] Figure 4 is a flow chart showing processing steps in another example of a method for operating a radio access node;

[0101] Figure 5 is a flow chart showing processing steps in another example of a method for operating a radio access node;

[0102] Figure 6 is a flowchart illustrating processing steps in another example of a method for operating a radio access node;

[0103] Figure 7 is a flowchart illustrating processing steps in another example of a method for operating a radio access node;

[0104] Figures 8a to 8b is a flowchart illustrating processing steps in a method for operating a core node in a communication network;

[0105] Figure 9 is a flowchart illustrating processing steps in another example of a method for operating a core node;

[0106] Figure 10 is a flowchart illustrating processing steps in another example of a method for operating a core node;

[0107] Figure 11 is a flowchart illustrating processing steps in another example of a method for operating a core node;

[0108] Figure 12 is a block diagram illustrating functional units in an apparatus for operating a UE;

[0109] Figure 13 is a block diagram illustrating functional units in an apparatus for operating a radio access node;

[0110] Figure 14 is a block diagram illustrating functional units in an apparatus for operating a core node;

[0111] Figure 15 is a block diagram illustrating functional units in another example of an apparatus for operating a UE;

[0112] Figure 16 is a block diagram illustrating functional units in another example of an apparatus for operating a radio access node;

[0113] Figure 17 is a block diagram illustrating functional units in another example of an apparatus for operating a radio access node;

[0114] Figure 18 is a block diagram illustrating functional units in another example of an apparatus for operating a core node;

[0115] Figure 19 is a block diagram illustrating functional units in another example of an apparatus for operating a core node;

[0116] Figure 20is a block diagram illustrating functional units in another example of an apparatus for operating a core node;

[0117] Figure 21 is a signaling diagram illustrating a registration procedure for a UE;

[0118] Figure 22 is a signaling diagram illustrating details of a registration procedure for a UE;

[0119] Figure 23 is a signaling diagram illustrating another detail of a registration procedure for a UE; and

[0120] Figure 24 is a signaling diagram illustrating secondary eNB ciphering / deciphering initiation. DETAILED DESCRIPTION

[0121] Aspects and examples of the present disclosure implement integrity protection for user plane data exchanged between a UE and a communication network. For example, the communication network can be a 4G LTE network or a 5G next generation network, although it should be understood that aspects and examples of the present disclosure can also be applied to other networks. The methods of operation of the UE, radio access node, and core network node according to examples of the present disclosure can collectively implement functionality for negotiation and application of integrity protection for the user plane during initial UE registration, handover, dual connectivity, etc.

[0122] According to examples of the present disclosure, a UE can indicate to the network that it supports UP integrity. The UE can indicate a maximum data rate for integrity protection of UP data as a kind of capability. For example, if the UE indicates 64 kbps as its maximum data rate, the network can assume that UP integrity protection is turned on only for data rates equal to or lower than 64 kbps. Higher data rates will not use UP integrity. This indication of capability can be used as the UE indicating to the network that it supports UP integrity. The UE can indicate its UE preference on whether UP integrity protection will be used or not. The subscriber preference for using UP integrity protection can be stored in the subscriber data management (SDM) / home subscriber service (HSS) and in the UE. The home network can thereby indicate to the serving network whether UP integrity "should" or "shall" be turned on.

[0123] Based on the indication received from the home network and the policy configured for the visited network (access management function (AMF) / mobility management entity (MME)), the visited network can make a policy decision on whether the UE needs UP integrity. Based on the policy decision, the core network can indicate to the UE in the NAS layer whether UP integrity will be used or not.

[0124] The core network can inform the base station or RAN (gNB or eNB) whether to use integrity protection for UP data. The indication or reference can be sent on the NG2 interface or S1 interface between the core network and the base station (RAN).

[0125] In other examples, the RAN can decide whether to use UP integrity protection without being told by the core network whether to use UP integrity protection. Other options can include the gNB / eNB deciding whether to use UP integrity protection based on UE preference received from the core network and possibly other information. The gNB or eNB can have a local policy on whether a UE that supports UP integrity starts UP integrity (based on UE 5GS security capabilities).

[0126] If the UE does not get the expected UP integrity protection, the UE can take responsive action. The action can be to connect to another gNB / eNB, or the UE can refrain from using a certain application.

[0127] The user of the UE can dynamically configure and change the UE preference on whether to use UP integrity via the UE GUI (user interface). The preference of the UE can be configured for all UP data, or according to network slice type (e.g., network slice selection assistance information, NSSAI) or according to network slice identifier (e.g., data network name, DNN). The UE can indicate to the user whether the network has enabled or disabled UP integrity when the procedure of registering with the communication network is completed. The indication can be for all data, according to the type or identifier of the slice.

[0128] The UE can be able to detect a network with sub-par security and apply a user-configured policy on how to react (e.g., only connect to a network that provides integrity protection for UP). This is advantageous for security of IoT devices for subscribers that trust the operator, but need stronger security than what is offered by today's network providers. In case the preferred PLMN does not use UP integrity protection, other PLMNs to pick can be configured by the user.

[0129] Another option can be to set up a new list on the USIM or in the ME that can contain PLMNs that support UP integrity protection. The list can be provided and configured to the UE by the home PLMN's operator through over-the-air. The home PLMN knows which operators it has roaming agreements with and which operators support UP integrity protection.

[0130] In X2 handover or Xn handover between two base stations, the source base station can inform the target base station whether integrity protection of UP data is enabled. The indication or reference can be sent from the source node to the target node over the Xn interface or the X2 interface.

[0131] The user can configure in the UE GUI whether to automatically accept non-integrity protected UP traffic (e.g. at handover) without asking the user’s policy.

[0132] The user can also be informed after handover to a new gNB or eNB that the new gNB or eNB does not support integrity protection and can be asked whether to continue the connection with the network.

[0133] The UE can be configured to, in case the gNB or eNB does not start integrity protection, try to reconnect to a different gNB or eNB of the same PLMN, hoping that the other gNB or eNB is updated with UP integrity algorithm and supports UP integrity protection.

[0134] In dual connectivity between two base stations, the master base station can inform the secondary base station whether integrity protection of UP data is enabled. The indication or reference can be sent from the master base station to the secondary base station over the Xn interface or the X2 interface.

[0135] The above discussed and additional functionalities can be implemented via methods executed on each entity involved in the relevant procedures. Reference is made to Figures 2a to 11 Examples of these methods are discussed in the following. Examples are described with reference to 4G networks and 5G networks, but it should be appreciated that this is for illustrative purposes only.

[0136] Figures 2a to 2c An example method 200 for operating a user equipment (UE) according to the present disclosure is shown. The UE is configured to connect to a communication network, e.g. which can comprise a fourth generation communication network or a fifth generation communication network. The method can be performed by an apparatus for operating the UE, which can be incorporated in the UE itself. Reference is made to Figure 2a In a first step 202, the method comprises indicating, to the communication network, an integrity protection for user plane (IPUP) mode supported by the UE when requesting to register to the communication network. The IPUP mode comprises one of: “use integrity protection for user plane data exchanged with the UE” 202a, “do not use integrity protection for user plane data exchanged with the UE” 202b, or “use integrity protection for user plane data and do not use confidentiality protection for user plane data” 202c.

[0137] According to examples of the present disclosure, the fourth generation communication network and the fifth generation communication network refer to respective generations of networks according to the 3GPP specifications. According to examples of the present disclosure, the "request for registration" can comprise sending an attach request or a tracking area update request in a 4G network. The message name for requesting registration in a 5G network has not been defined yet.

[0138] According to examples of the present disclosure, when the IPUP mode supported by the UE is "no integrity protection for user plane data", the indication can be a lack of indication of support for the IPUP modes "integrity protection for user plane data" or "integrity protection for user plane data and no confidentiality protection for user plane data".

[0139] According to examples of the present disclosure, the IPUP mode "integrity protection for user plane data and no confidentiality protection for user plane data" can enable the UE to specify that confidentiality protection for UP data can be turned off if integrity protection for UP data is turned on. Some very small UEs (e.g. including those related to devices in Internet of Things deployments) can have very limited power access and in order to prolong the life of the battery, it can be useful for the UE to be able to turn off encryption related to confidentiality protection if it knows that encryption related to integrity protection will be applied on a higher protocol layer.

[0140] According to examples of the present disclosure, the step of indicating to the communication network an IPUP mode of "integrity protection for user plane data" or "integrity protection for user plane data and no confidentiality protection for user plane data" for user plane data exchanged with the UE can comprise indicating to the communication network a maximum data rate of user plane data for which integrity protection can be applied. In these examples, the UE indicates its support for UP integrity by indicating a maximum data rate for which UP integrity should be used. It is assumed that the network turns on UP integrity protection for data rates up to the indicated maximum and will not use UP integrity protection for higher data rates. This can for example allow the case where integrity protection for UP data is expected for certain applications (e.g. Internet of Things applications) but not for others (e.g. including mobile broadband).

[0141] Referring again to Figure 2a The method can then comprise, in a step 204, indicating to the communication network a UE preference regarding an IPUP mode to be used by the communication network for the UE. The indicated UE preference can apply to at least one of: all data exchanged with the communication network 204a, or data exchanged with one specific slice or slices of the communication network. The one or more network slices can be identified by a slice type and / or by a slice identity. "Network slice" refers to the concept defined in the literature related to next generation networks.

[0142] The method 200 can then comprise, in step 206, receiving from the communication network an indication of an IP UP mode to be used by the communication network for the UE. The indication can apply to at least one of: all data exchanged with the communication network 206a, or data exchanged with one specific slice or slices of the communication network 206b. The indication can be received in the AS security mode command (e.g. by listing the supported algorithms for UP data), or as a general indication that UP integrity is supported (assuming the same algorithm used for control plane integrity protection is used for user plane integrity protection). Alternatively, the indication can be received in a RRC connection reconfiguration message.

[0143] In step 208, the method can further comprise informing a user of the UE of the IP UP mode to be used by the communication network for the UE. The informing step can be performed during registration with the communication network, or can be performed after registration with the communication network is complete, and can cause the user to take appropriate action if the IP UP mode to be used is not suitable for the user’s desired communication with the network.

[0144] In step 210, the method 200 can comprise checking whether the IP UP mode indicated by the communication network matches a UE preference regarding which IP UP mode should be used by the communication network for the UE. If the indicated mode does not match the UE preference regarding which IP UP mode should be used by the communication network for the UE, the method 200 can comprise performing at least one of: rejecting connection to the network in step 212, disconnecting from the network in step 214, or informing a user of the UE that the IP UP mode indicated by the communication network does not match the UE preference regarding which IP UP mode should be used by the communication network for the UE in step 216.

[0145] If the UE performs at least one of the rejecting connection to the network of step 212 or the disconnecting from the network of step 216, the method can further comprise performing at least one of: requesting registration with the communication network via a different radio access node of the communication network in step 222, or requesting registration with a different communication network in step 224. Prior to performing step 222 or step 224, the method can comprise querying a list comprising at least one of a radio access node or a communication network that supports integrity protection for user plane data in step 218, and selecting at least one of a radio access node of the communication network or a different communication network for which to request registration from the list in step 220. The list can be configured in a memory of the UE or can be received over a radio link. For example, the list can be received from a home communication network (e.g. home PLMN) of the UE.

[0146] After steps 222, 224, or if the check in step 210 shows that the indicated IPUP mode matches the UE preference, the method 200 can further comprise receiving, at some later point in time, a message from the target radio access node of the communications network during a procedure to handover the UE from the source radio access node to the target radio access node, the message comprising an indication that the target radio access node will use a different IPUP mode for the UE than the IPUP mode used by the source radio access node. The indication can be received in an AS security mode command. Alternatively, the indication can be received in an RRC connection reconfiguration message.

[0147] In step 228, the method 200 can further comprise checking whether the indication from the target radio access node is that the IPUP mode to be used by the communications network via the target radio access node does not match the UE preference regarding which IPUP mode should be used for the UE by the communications network. If the check indicates that the IPUP mode to be used does not match the UE preference, the method 200 can further comprise performing at least one of: disconnecting from the network in step 230, accepting the handover and informing a user of the UE about the IPUP mode to be used by the communications network via the target radio access node in step 232, or seeking handover to a different radio access node of the communications network in step 234.

[0148] Referring now to Figure 2c The method 200 can further comprise receiving, in step 236, an indication of an IPUP mode to be used for the UE by the communications network from a radio access node of the communications network. The radio access node can be an eNB or a gNB. The radio access node can be the radio access node via which the registration request is transmitted by the UE to the communications network, or can be a different radio access node. The indication can be received during a procedure for secondary radio access node addition, secondary radio access node modification requiring a key update, or data radio bearer (DRB) offloading. The indication can be received with an RRC reconfiguration request as shown in step 238. If the indicated IPUP mode involves use of integrity protection for user plane data as determined by the check in step 240, the method can further comprise deriving and using a key for integrity protection of user plane data in step 242.

[0149] It will be appreciated that certain steps outlined above can be performed in a different order than shown in the figures. Figures 2a to 2c In the foregoing description, certain steps can be performed in a different order than shown in the figures.

[0150] According to another aspect of the disclosure, there is provided another method for operating a user equipment (UE). The UE is configured to connect to a communication network, e.g. which can comprise a fourth generation communication network or a fifth generation communication network. The method can be performed by an apparatus for operating the UE, which can be incorporated in the UE itself. The method comprises receiving, from a target radio access node of the communication network, a message during a procedure of handing over the UE from a source radio access node to the target radio access node, the message comprising an indication that the target radio access node will use, for the UE, a different IPUP mode than used by the source radio access node. The method can further comprise, if the indication from the target radio access node is that the IPUP mode to be used by the communication network via the target radio access node does not match a UE preference regarding which IPUP mode should be used for the UE by the communication network, performing at least one of the following: disconnecting from the network, accepting the handover and informing a user of the UE about the IPUP mode to be used by the communication network via the target radio access node, or seeking a handover to a different radio access node of the communication network.

[0151] Figure 3 An example method 300 for operating a radio access node of a communication network according to the disclosure is shown. The communication network can comprise a fourth generation communication network or a fifth generation communication network, for example. The method can be performed by an apparatus for operating the radio access node, which can be incorporated in the radio access node itself and / or can have appropriate functionality for operating the radio access node, which can be a virtual network function. The radio access node can be an eNodeB or a gNodeB.

[0152] Reference is made to Figure 3 In a first step 302, the method comprises receiving, from a UE requesting to register with the communication network, an indication of an IPUP mode supported by the UE. The IPUP mode comprises one of: "use integrity protection for user plane data exchanged with the UE" 302a, "do not use integrity protection for user plane data exchanged with the UE" 302b, or "use integrity protection for user plane data and do not use confidentiality protection for user plane data". The indication is received from the UE via the communication network. For example, the message can be sent to a core network of the communication network in a manner transparent to the radio access node, and can be subsequently forwarded from the core network to the radio access node.

[0153] According to examples of the present disclosure, the step 302 of receiving, from a UE requesting registration with a communication network, an indication of an IPUP mode to be used with the UE, either with integrity protection of user plane data exchanged with the UE or with integrity protection of user plane data and without confidentiality protection of user plane data, can comprise receiving, from the UE, a maximum data rate of user plane data for which integrity protection can be applied. In these examples, the UE indicates its support of UP integrity by indicating a maximum data rate for which UP integrity should be used. It is assumed that the network turns UP integrity protection on for data rates up to the indicated maximum, while for higher data rates UP integrity protection will not be used. This can allow, for example, for the case that integrity protection of UP data is expected for certain applications (e.g. Internet of Things applications) but not for others (e.g. including mobile broadband).

[0154] The method 300 can further comprise receiving, from the UE, a UE preference for an IPUP mode to be used with the UE by the communication network, in step 304. The indicated UE preference can apply to at least one of: all data exchanged with the communication network, as shown in step 304a, or data exchanged with one specific slice or multiple slices of the communication network, as shown in step 304b. The one or more network slices can be identified by a slice type and / or by a slice identity.

[0155] The method 300 can further comprise receiving, from a core node of the communication network, an indication of an IPUP mode to be used with the UE by the communication network, in step 306. The indication can comprise security capabilities and supported integrity algorithms for integrity protection of UP data. The core node can be, for example, a Mobility Management Entity (MME) in a LTE network or an Access Management Function (AMF) in a next generation network.

[0156] The method 300 can further comprise checking, in step 308, whether the indicated IPUP mode is supported by the radio access node. If the indicated IPUP mode is supported by the radio access node, the method can further comprise sending, to the core node, an indication that the radio access node will enable the IPUP mode to be used with the UE by the communication network, in step 310.

[0157] If the indicated IPUP mode received from the core node of the communication network is not supported by the radio access node, the method can further comprise performing at least one of: rejecting, in step 312, the registration request received from the UE, or omitting, in step 314, sending to the core node an indication that the radio access node will enable the IPUP mode to be used with the UE by the communication network.

[0158] In step 316, the method 300 can further comprise sending, to the UE, an indication of an IPUP mode to be used by the communication network for the UE. If the IPUP mode to be used by the communication network for the UE involves the use of integrity protection for user plane data, the indication of the IPUP mode to be used by the communication network for the UE can indicate an integrity algorithm selected by the radio access node to be used for the integrity protection of the UP data, as illustrated in step 316a. The identifier can be included only if the algorithm is different from the algorithm to be used for the protection of the control plane data.

[0159] The indication sent to the UE in step 316 can apply to at least one of: all data exchanged with the communication network, or data exchanged with one specific slice or slices of the communication network. In some examples, the indication can be sent in an AS security mode command. Alternatively, the indication can be sent in an RRC connection reconfiguration message.

[0160] The IPUP mode indicated to the UE by the radio access node can be an IPUP mode received from a core node of the communication network, as illustrated in step 316b, or can be selected by the radio access node according to a policy hosted on the radio access node. The policy can take into account both preferences received from the UE and the IPUP mode received from the core network node.

[0161] It should be appreciated that reference is made to Figure 3 It should be appreciated that certain steps outlined above can be performed in a different order than illustrated in the figures.

[0162] Figure 4 Another example method 400 for operating a radio access node of a communication network according to the present disclosure is illustrated. The communication network can comprise a fourth generation communication network or a fifth generation communication network, for example. The method can be performed by an apparatus for operating a radio access node, which can be incorporated in the radio access node itself and / or can have appropriate functionality for operating a radio access node, which can be a virtual network function. The radio access node can be an eNodeB or a gNodeB.

[0163] Reference is made to Figure 4The radio access node comprises a target radio access node, and the method comprises, in a first step 402, during a handover of the UE from a source radio access node to the target radio access node, sending an indication of an IPUP mode to be used by the communication network for the UE. The IPUP mode comprises one of: "use of integrity protection for user plane data exchanged with the UE" 402a, "no use of integrity protection for user plane data exchanged with the UE" 402b, or "use of integrity protection for user plane data and no use of confidentiality protection for user plane data" 402c. In some examples, the indication of the IPUP mode can be sent to the target radio access node with a handover request message. According to examples of the disclosure, the step of sending the indication of the IPUP mode can comprise sending a maximum data rate of user plane data for which integrity protection can be applied.

[0164] The method can further comprise, in a step 404, checking whether an indication is received from the target radio access node that the target radio access node will enable the IPUP mode to be used by the communication network for the UE. In a step 406, if it is determined that no indication is received that the target radio access node will enable the IPUP mode to be used by the communication network for the UE, the method can further comprise assuming that the target radio access node will not enable the IPUP mode to be used by the communication network for the UE. In some examples, a failure to receive an indication of the enablement from the target node can be due to a legacy target node, or a target node that does not understand the indication from the source target node for any other reason. In such a case, the method can further comprise, in a step 410, proceeding with the handover procedure or terminating the handover procedure. The decision to proceed with the handover procedure or to terminate the handover procedure can be based on a policy hosted on the source radio access node, which can take into account received UE preferences and / or subscription information for the UE received from a core network node such as a MME or AMF.

[0165] Figure 5 Another example method 500 for operating a radio access node of a communication network according to the disclosure is shown. The communication network can comprise a fourth generation communication network or a fifth generation communication network, for example. The method can be performed by an apparatus for operating a radio access node, which can be incorporated in the radio access node itself and / or can have appropriate functionality for operating a radio access node, which can be a virtual network function. The radio access node can be an eNodeB or a gNodeB.

[0166] Reference Figure 5The radio access node comprises a target radio access node, and the method comprises: in a first step 502, receiving, during a handover of the UE from a source radio access node to the target radio access node, an indication by the communication network of an IPUP mode to be used for the UE. The IPUP mode comprises one of: "use integrity protection for user plane data exchanged with the UE" 502a, "do not use integrity protection for user plane data exchanged with the UE" 502b, or "use integrity protection for user plane data and do not use confidentiality protection for user plane data" 502c. According to examples of the present disclosure, the step of receiving the IPUP mode can comprise receiving a maximum data rate of user plane data for which integrity protection can be applied.

[0167] The indication by the communication network of the IPUP mode to be used for the UE can be received from at least one of the source radio access node or a core node of the communication network. For example, the core node can be an MME in a 4G network or an AMF in a 5G network.

[0168] In a step 504, if the indication by the communication network of the IPUP mode to be used for the UE is received from the source radio access node, the method can further comprise sending, to a core node of the communication network, the indication of the IPUP mode received from the source radio access node. For example, the core node can be an MME or an AMF.

[0169] In a step 506, the method can comprise checking whether the target radio access node supports the indicated IPUP mode, and, if the target radio access node does not support the received indicated IPUP mode, the method can comprise performing one of: rejecting the handover of the UE in a step 508, or accepting the handover of the UE and omitting to send an indication that the target radio access node will enable the IPUP mode to be used for the UE by the communication network.

[0170] In a step 512, the method can comprise deciding whether to use the indicated IPUP mode, and, if it is decided not to use the indicated IPUP mode 514, sending an indication to the UE in a step 518 that the target radio access node will use a different IPUP mode for the UE than the IPUP mode used by the source radio access node. The indication can be sent in an AS security mode command. Alternatively, the indication can be sent in an RRC connection reconfiguration message.

[0171] If the target radio access node supports the indicated IPUP mode, the method can further comprise, in a step 516, sending, to at least one of the source radio access node or a core node of the communication network, an indication that the target radio access node will enable the IPUP mode to be used for the UE by the communication network. As Figure 5As illustrated in the figure, the sending can rely on the target radio access node deciding to use the indicated IPUP mode at step 512. The indication of the enabling of the indicated IPUP mode can be sent to the entity from which the indication of the IPUP mode was received, i.e. to the source radio access node or to the core radio access node.

[0172] It should be appreciated that reference is made to Figure 5 It should be appreciated that certain steps outlined above can be performed in a different order than illustrated in the figure.

[0173] Figure 6 Another example method 600 for operating a radio access node of a communication network according to the disclosure is illustrated. The communication network can comprise a fourth generation communication network or a fifth generation communication network, for example. The method can be performed by an apparatus for operating a radio access node, which can be incorporated in the radio access node itself and / or can have appropriate functionality for operating a radio access node, which can be a virtual network function. The radio access node can be an eNodeB or a gNodeB.

[0174] Reference is made to Figure 6 The radio access node comprises a primary radio access node, and the method comprises, in a first step 602, sending, to a secondary radio access node, an indication of an IPUP mode to be used by the communication network for a UE. The IPUP mode comprises one of: "use integrity protection for user plane data exchanged with the UE" 602a, "do not use integrity protection for user plane data exchanged with the UE" 602b, or "use integrity protection for user plane data and do not use confidentiality protection for user plane data" 602c. The indication is sent to the secondary radio access node during a procedure for at least one of: the secondary radio access node addition 602i, the secondary radio access node modification that requires a key update 602ii, or data radio bearer (DRB) offloading 602iii, all within the context of dual connectivity. According to examples of the disclosure, the step of sending the IPUP mode can comprise sending a maximum data rate for user plane data for which integrity protection can be applied.

[0175] If the IPUP mode indicated to the secondary radio access node involves the use of integrity protection for user plane data (i.e. mode "integrity protection for user plane data exchanged with the UE" or mode "integrity protection for user plane data and no confidentiality protection for user plane data"), the indication by the communication network of the IPUP mode to be used for the UE can comprise a list of supported algorithms for integrity protection of UP data. In some examples, the list of supported algorithms for IPUP can be the same as the list for integrity protection of control plane data and not indicated separately. In further examples, the list can comprise a single identified integrity algorithm.

[0176] In step 604, the method can further comprise checking whether an indication is received from the secondary radio access node that the secondary radio access node will enable the IPUP mode to be used for the UE by the communication network. If no indication is received that the secondary radio access node will enable the IPUP mode to be used for the UE by the communication network (step 606), the method can further comprise assuming in step 608 that the secondary radio access node will not enable the IPUP mode to be used for the UE by the communication network. Failure to receive an indication of enablement from the secondary node can be due to a legacy secondary node, or a secondary node that does not understand the indication from the source target node for any other reason. In this case, the method can further comprise proceeding with the procedure or terminating the procedure in step 610. The decision to proceed with the procedure or terminate the procedure can be based on a policy hosted on the radio access node, which can take into account the received UE preferences and / or subscription information for the UE received from a core network node such as a MME or AMF.

[0177] If an indication is received that the secondary radio access node will enable the IPUP mode to be used for the UE by the communication network, the method can further comprise sending an RRC reconfiguration request to the UE in step 614 if the indication of the IPUP mode to be used for the UE by the communication network is sent to the secondary radio access node during the DRB offload procedure (step 612). The RRC reconfiguration request can comprise an algorithm identifier for the selected algorithm for integrity protection for UP. The identifier can only be included if the selected algorithm is different from the algorithm that will be used to protect the control plane. If the indication of the IPUP mode in the RRC reconfiguration request indicates that the IPUP mode will be enabled and used, the UE will compute a new key for integrity protection of user plane data, which is associated with the DRB that will be offloaded.

[0178] It will be appreciated that reference to Figure 6Certain steps outlined in the foregoing overview can be performed in a different order than illustrated.

[0179] Figure 7 Another example method 700 for operating a radio access node of a communication network according to the present disclosure is shown. The communication network can comprise a fourth generation communication network or a fifth generation communication network, for example. The method can be performed by an apparatus for operating a radio access node, which can be incorporated in the radio access node itself and / or can have appropriate functionality for operating a radio access node, which can be a virtual network function. The radio access node can be an eNodeB or a gNodeB.

[0180] Reference is made to Figure 7 The radio access node comprises a secondary radio access node and the method comprises, in a first step 702, receiving from a primary radio access node an indication of an IPUP mode to be used by the communication network for a UE. The IPUP mode comprises one of: "use integrity protection for user plane data exchanged with the UE" 702a, "do not use integrity protection for user plane data exchanged with the UE" 702b, or "use integrity protection for user plane data and do not use confidentiality protection for user plane data" 702c. The indication is received from the primary radio access node during a procedure for at least one of: secondary radio access node addition 702i, secondary radio access node modification requiring a key update 702ii, or data radio bearer (DRB) offloading 702iii, all in the context of dual connectivity. According to examples of the present disclosure, the step of receiving the IPUP mode can comprise receiving a maximum data rate of user plane data for which integrity protection can be applied.

[0181] If the IPUP mode indicated by the primary radio access node involves use of integrity protection for user plane data (i.e. mode "use integrity protection for user plane data exchanged with the UE" or mode "use integrity protection for user plane data and do not use confidentiality protection for user plane data"), the indication of the IPUP mode to be used by the communication network for the UE can comprise an identifier of an integrity algorithm to be used for UP integrity protection. The identifier can only be included if the algorithm is different from the one to be used for protecting the control plane. In a further example, the secondary radio access node can assume that the integrity protection algorithm of the control plane data is also supported for the user plane.

[0182] If the secondary radio access node supports the indicated IPUP mode (step 704), the method can further comprise, in a step 706, sending to the primary radio access node an indication that the secondary radio access node will enable the IPUP mode to be used by the communication network for the UE.

[0183] If the secondary radio access node does not support the received indicated IPUP mode (step 704), the method may further include performing at least one of the following: rejecting the requested procedure from the primary radio access node in step 708; or accepting the requested procedure from the primary radio access node in step 710, omitting sending an instruction to the primary radio access node that the secondary radio access node will enable the IPUP mode to be used by the communication network for the UE.

[0184] The method may further include: if the indication of the IPUP mode used by the UE by the communication network is received from the primary radio access node during the process of adding a secondary radio access node or modifying a secondary radio access node that requires a key update, and if the IPUP mode indicated by the primary radio access node involves the use of integrity protection for user plane data (step 712), then in step 714, a key for integrity protection of user plane data exchanged with the UE is derived and used.

[0185] It should be understood that, for reference Figure 7 Some of the steps outlined above can be performed in a different order than that shown in the diagram.

[0186] Figure 8a and Figure 8b An example method 800 for operating a core node of a communication network according to this disclosure is shown. For example, the communication network may include a fourth-generation or fifth-generation communication network. The method can be performed by means for operating the core node, which may be incorporated into the core node itself and / or may have appropriate functions for operating the core node, such as virtual network functions. The core node may be an MME or an AMF.

[0187] refer to Figure 8a The method may first include, in step 802, receiving a registration request for the UE. The method may further include, in step 804, checking whether the core node is a new core node for the UE. If so, the method may further include, in step 806, sending a request for information related to the UE to the UE's old core network, and in step 808, receiving an indication from the old core network node of the IPUP mode to be used by the communication network for the UE. According to an example of this disclosure, step 808 of receiving the IPUP mode may include: receiving the maximum data rate of user plane data to which integrity protection can be applied.

[0188] In step 810, the method can further comprise receiving, from a subscription management node corresponding to the UE, an indication of an IPUP mode to be used by the communication network for the UE during the update location procedure. According to examples of the disclosure, the step 810 of receiving the IPUP mode can comprise receiving a maximum data rate of user plane data for which integrity protection can be applied.

[0189] The method can further comprise deciding, in step 812, an IPUP mode to be used by the communication network for the UE. The decision can be based on policies hosted by the core network node and can take into account the indications received from the old core network node and / or the subscription management node. The decided IPUP mode can be applied to at least one of: all data exchanged between the UE and the communication network 812a, or data exchanged between the UE and one specific slice or multiple slices of the communication network 812b. The one or more network slices can be identified by a slice type or a slice identity.

[0190] The method can further comprise checking, in step 814, whether the IPUP mode decided by the core network node matches the preference communicated by the UE for the IPUP mode to be used by the communication network for the UE. With reference to Figure 8b If the IPUP mode decided by the core network node does not match the preference communicated by the UE for the IPUP mode to be used by the communication network for the UE, the method can further comprise performing one of: rejecting, in step 816, the request from the UE for registration to the communication network; or accepting, in step 818, the request from the UE for registration to the communication network and informing the UE of the IPUP decided by the core network node.

[0191] The method comprises, in step 820, sending, to a radio access node of the communication network, an indication of an IPUP mode to be used by the communication network for the UE requesting registration to the communication network. The IPUP mode comprises one of: “use integrity protection for user plane data exchanged with the UE” 820a, “do not use integrity protection for user plane data exchanged with the UE” 820b, or “use integrity protection for user plane data and do not use confidentiality protection for user plane data”. The indication can comprise security capabilities and integrity algorithms supported for integrity protection of UP data. The indicated IPUP mode can be the mode decided by the core network node in step 812. According to examples of the disclosure, the step 820 of sending the IPUP mode can comprise sending a maximum data rate of user plane data for which integrity protection can be applied.

[0192] The method can further comprise, at step 822, checking whether an indication is received from the radio access node of the communication network that the radio access node of the communication network is to enable the IPUP mode indicated to the radio access node of the communication network.

[0193] The method can further comprise, at step 826, indicating to the UE the decided IPUP mode to be used by the communication network for the UE. The sending of the indication can be conditional on the reception of the indication that the radio access node of the communication network is to enable the IPUP mode indicated to the radio access node.

[0194] If no indication is received that the radio access node is to enable the IPUP mode indicated to the radio access node (step 824), the method can further comprise assuming that the radio access node is not to enable the IPUP mode to be used by the communication network for the UE. The failure to receive the indication of the enabling from the radio access node can be due to a legacy radio access node, or a radio access node that does not understand the indication from the core node for any other reason. In this case, the method can further comprise, at step 830, accepting or rejecting the registration request. The decision can be based on policies hosted on the core node, which can take into account the received UE preferences and / or subscription information for the UE.

[0195] It should be appreciated that reference is made to Figure 8a and Figure 8b It should be appreciated that certain steps outlined above can be performed in a different order than shown in the figures.

[0196] Figure 9 Another example method 900 for operating a core node of a communication network according to the present disclosure is shown. The communication network can comprise a fourth generation communication network or a fifth generation communication network, for example. The method can be performed by an apparatus for operating a core node, which can be incorporated in the core node itself and / or can have appropriate functionality for operating a core node, which can be a virtual network function. The core node can be a MME or an AMF.

[0197] Reference is made to Figure 9The core network node comprises an old core network node for which the UE requested registration to the communication network, and the method comprises: receiving, at step 902, a request for information related to the UE from a new core network node for the UE, and sending, at step 904, to the new core network node, an indication of an IPUP mode to be used by the communication network for the UE. The IPUP mode comprises one of: "use integrity protection for user plane data exchanged with the UE" 904a, "do not use integrity protection for user plane data exchanged with the UE" 904b, or "use integrity protection for user plane data and do not use confidentiality protection for user plane data" 904c. The indicated IPUP mode can be applied to at least one of: all data exchanged between the UE and the communication network 904i, or data exchanged between the UE and one specific slice or slices of the communication network 904ii. According to examples of the disclosure, the step 904 of sending the IPUP mode can comprise sending a maximum data rate of user plane data for which integrity protection can be applied.

[0198] Figure 10 Another example method 1000 for operating a core node of a communication network according to the disclosure is shown. The communication network can comprise a fourth generation communication network or a fifth generation communication network, for example. The method can be performed by an apparatus for operating a core node, which can be incorporated in the core node itself and / or can have appropriate functionality for operating the core node, which can be a virtual network function. The core node can be a MME or an AMF.

[0199] Reference is made to Figure 10 The method comprises, in a first step 1002, receiving, from a target radio access node, an indication of an IPUP mode to be used by the communication network for a UE to be handed over to the target radio access node. The IPUP mode comprises one of: "use integrity protection for user plane data exchanged with the UE" 1002a, "do not use integrity protection for user plane data exchanged with the UE" 1002b, or "use integrity protection for user plane data and do not use confidentiality protection for user plane data" 1002c. According to examples of the disclosure, the step 1002 of receiving the IPUP mode can comprise receiving a maximum data rate of user plane data for which integrity protection can be applied.

[0200] The method further comprises, in a step 1004, verifying whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode stored by the core network node for the UE. If there is no match between the indicated IPUP mode and the stored IPUP mode (step 1006), the method further comprises performing at least one of: logging the mismatch as an event in a step 1008 or triggering an alarm in a step 1010.

[0201] Figure 11 Another example method 1100 for operating a core node of a communication network according to the present disclosure is shown. The communication network can comprise a fourth generation communication network or a fifth generation communication network, for example. The method can be performed by an apparatus for operating a core node, which can be incorporated in the core node itself and / or can have appropriate functionality for operating the core node, which can be a virtual network function. The core node can be a MME or an AMF.

[0202] Reference is made to Figure 11 The method comprises, in a first step 1102, sending, to a target radio access node, an indication of an IPUP mode to be used by the communication network for a UE to be handed over to the target radio access node. The IPUP mode comprises one of: "use integrity protection for user plane data exchanged with the UE" 1102a, "do not use integrity protection for user plane data exchanged with the UE" 1102b, or "use integrity protection for user plane data and do not use confidentiality protection for user plane data" 1102c. In some examples, the indication can be sent in a handover request message. According to examples of the present disclosure, the step 1102 of sending the IPUP mode can comprise sending a maximum data rate of user plane data for which integrity protection can be applied.

[0203] The method can further comprise, in a step 1104, checking whether an indication is received from the target radio access node that the target radio access node will enable the IPUP mode to be used by the communication network for the UE. If no indication is received from the target radio access node that it will enable the IPUP mode indicated to the radio access node (step 1106), the method can further comprise assuming that the target radio access node will not enable the IPUP mode to be used by the communication network for the UE. Reasons for failure to receive the indication of enablement from the target node can be a legacy target node, or a target node that does not understand the indication from the core node for any other reason. In such a case, the method can further comprise continuing with the handover procedure or terminating the handover procedure in a step 1110. The decision to continue with the handover procedure or to terminate the handover procedure can be based on policies hosted on the core network node, which can take into account received UE preferences and / or subscription information for the UE.

[0204] According to aspects of the present disclosure, there is provided a computer program comprising instructions which, when executed on at least one processor, cause the at least one processor to carry out the method of any of the preceding examples discussed with reference to Figures 2 to Figure 11 According to aspects of the present disclosure, there is provided a computer program comprising instructions which, when executed on at least one processor, cause the at least one processor to carry out the method of any of the preceding examples discussed with reference to Figures 2 to

[0205] According to an aspect of the disclosure, there is provided a carrier containing the computer program as discussed above, wherein the carrier comprises one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium.

[0206] According to an aspect of the disclosure, there is provided a computer program product comprising a non-transitory computer readable medium storing a computer program as discussed above.

[0207] Figure 12 A first example of an apparatus 1200 that can perform the methods for operating a UE as discussed above and as illustrated in Figures 2a to 2c Fig. 1 1 is shown. The apparatus can perform these methods e.g. when it receives suitable instructions from a computer program. With reference to Figure 12 the apparatus comprises a processor 1202, a memory 1204 and an interface 1206. The memory 1204 contains instructions executable by the processor 1202, which makes the apparatus 1200 operable to perform some or all of the steps of the methods for operating a UE described above and in the numbered claims below.

[0208] Figure 13 A first example of an apparatus 1300 that can perform the methods for operating a radio access node as discussed above and as illustrated in Figures 3 to 7 Fig. 12 is shown. The apparatus can perform these methods e.g. when it receives suitable instructions from a computer program. With reference to Figure 13 the apparatus comprises a processor 1302, a memory 1304 and an interface 1306. The memory 1304 contains instructions executable by the processor 1302, which makes the apparatus 1300 operable to perform some or all of the steps of the methods for operating a radio access node described above and in the numbered claims below.

[0209] Figure 14 A first example of an apparatus 1400 that can perform the methods for operating a core node as discussed above and as illustrated in Figures 8a to 11 Fig. 13 is shown. The apparatus can perform these methods e.g. when it receives suitable instructions from a computer program. With reference to Figure 14 the apparatus comprises a processor 1402, a memory 1404 and an interface 1406. The memory 1404 contains instructions executable by the processor 1402, which makes the apparatus 1400 operable to perform some or all of the steps of the methods for operating a core node described above and in the numbered claims below.

[0210] Figure 15An alternative example apparatus 1500 is shown, which, for example, can implement the method for operating the UE as discussed above and described in the claims numbered below, upon receiving appropriate instructions from a computer program. It should be understood that... Figure 15 The modules shown can be implemented in any suitable combination of hardware and / or software. For example, a module may include one or more processors, and one or more memories containing instructions executable by the one or more processors. Modules can be integrated to any extent.

[0211] refer to Figure 15 The apparatus 1500 includes a transmitting module 1502 for indicating to the communication network an IPUP mode supported by the UE when requesting registration with the communication network, wherein the IPUP mode includes one of the following: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data. The apparatus also includes an interface 1504.

[0212] Figure 16 and Figure 17 Alternative examples of the apparatus 1600 and 1700 are shown. For example, alternative examples 1600 and 1700 can implement, upon receiving appropriate instructions from a computer program, the methods for operating a radio access node as discussed above and described in the claims numbered below. It should be understood that... Figure 16 and Figure 17 The modules shown can be implemented in any suitable combination of hardware and / or software. For example, a module may include one or more processors, and one or more memories containing instructions executable by the one or more processors. Modules can be integrated to any extent.

[0213] refer to Figure 16The apparatus 1600 includes a transmitting module 1602 and an interface 1604. The radio access node can be a source radio access node, and the transmitting module 1602 can be used to transmit, during a procedure to handover a UE from the source radio access node to a target radio access node, an indication of an IPUP mode to be used by the communication network for the UE, wherein the IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data. In further examples, the radio access node can be a master radio access node, and the transmitting module 1602 can be used to transmit, to a secondary radio access node, an indication of an IPUP mode to be used by the communication network for the UE, wherein the IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data. The indication can be transmitted to the secondary radio access node during a procedure for at least one of: secondary radio access node addition, secondary radio access node modification requiring a key update, or data radio bearer (DRB) offload.

[0214] With reference to Figure 17 The apparatus 1700 includes a receiving module 1702 and an interface 1704. The receiving module can be used to receive, from a UE requesting to register with a communication network, an indication of an IPUP mode supported by the UE, wherein the IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data, and wherein the indication is received from the UE via the communication network.

[0215] In other examples, the radio access node can comprise a target radio access node, and the receiving module 1702 can be used to receive, during a procedure to handover a UE from a source radio access node to the target radio access node, an indication of an IPUP mode to be used by the communication network for the UE, wherein the IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE, not using integrity protection for user plane data exchanged with the UE, or using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0216] In other examples, the radio access node can comprise a secondary radio access node and the receiving module 1702 can be used to receive, from a primary radio access node, an indication of an IPUP mode to be used by the communication network for a UE, wherein the IPUP mode comprises one of: integrity protection to be used for user plane data exchanged with the UE, no integrity protection to be used for user plane data exchanged with the UE, or integrity protection to be used for user plane data and no confidentiality protection to be used for user plane data. The indication can be received from the primary radio access node during a procedure for at least one of: secondary radio access node addition, secondary radio access node modification requiring a key update, or DRB offload.

[0217] Figures 18 to 20 Alternative examples 1800, 1900, 2000 of apparatus are shown, e.g. the alternative examples 1800, 1900, 2000 of apparatus can implement a method for operating a core node as discussed above and as specified in the claims numbered below when receiving suitable instructions from a computer program. It will be appreciated that, Figures 18 to 20 The modules shown in FIGS. 1800, 1900, 2000 can be implemented in any suitable combination of hardware and / or software. For example, the modules can comprise one or more processors, and one or more memories containing instructions executable by the one or more processors. The modules can be integrated to any degree.

[0218] With reference to Figure 18 The apparatus 1800 comprises a sending module 1802 and an interface 1804. The sending module can be used to send, to a radio access node of a communication network, an indication of an IPUP mode to be used by the communication network for a UE requesting to register with the communication network, wherein the IPUP mode comprises one of: integrity protection to be used for user plane data exchanged with the UE, no integrity protection to be used for user plane data exchanged with the UE, or integrity protection to be used for user plane data and no confidentiality protection to be used for user plane data.

[0219] In other examples, the sending module can be used to send, to a target radio access node, an indication of an IPUP mode to be used by the communication network for a UE to be handed over to the target radio access node, wherein the IPUP mode comprises one of: integrity protection to be used for user plane data exchanged with the UE, no integrity protection to be used for user plane data exchanged with the UE, or integrity protection to be used for user plane data and no confidentiality protection to be used for user plane data.

[0220] With reference to Figure 19The apparatus 1900 comprises a receiving module 1902, a sending module 1904 and an interface 1906. The core network node comprises an old core network node for a UE requesting registration with a communication network. The receiving module 1902 is configured to receive, from a new core network node for the UE, a request for information related to the UE. The sending module 1904 is configured to send, to the new core network node, an indication of an IPUP mode to be used by the communication network for the UE, wherein the IPUP mode comprises one of: integrity protection for user plane data exchanged with the UE, no integrity protection for user plane data exchanged with the UE, or integrity protection for user plane data and no confidentiality protection for user plane data.

[0221] Reference is made to Figure 20 The apparatus 2000 comprises a receiving module 2002, a processing module 2004 and an interface 2006. The receiving module 2002 is configured to receive, from a target radio access node, an indication by the communication network of an IPUP mode to be used for a UE being handed over to the target radio access node. The processing module is configured to verify whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode stored by a core network node for the UE, and, if there is a mismatch between the indicated IPUP mode and the stored IPUP mode, to perform at least one of: logging the mismatch as an event or triggering an alarm. The IPUP mode comprises one of: integrity protection for user plane data exchanged with the UE, no integrity protection for user plane data exchanged with the UE, or integrity protection for user plane data and no confidentiality protection for user plane data.

[0222] Example applications of the methods according to the present disclosure are illustrated in the context of communication network procedures including UE registration, handover, dual connectivity management, etc. below. The example applications illustrate how different examples of the methods illustrated above can collectively enable the functionality of enabling integrity protection for user plane data. It should be appreciated that the examples below are for illustrative purposes only and are not intended to limit the scope of the present disclosure in any way. The examples below are presented in the context of LTE and 5G / Next Generation networks.

[0223] Negotiation of use of integrity protection for user plane in a UE registration procedure

[0224] The UE negotiates with the communication network whether integrity protection for UP data transmitted between the UE and the base station will be enabled or disabled. The UE indicates its support for UP integrity protection or otherwise. The UE can indicate its capability as the maximum data rate for UP data integrity protection. For example, if the UE indicates 64kbps as its maximum data rate, it can be assumed that the network only enables UP integrity protection for data rates equal to or lower than 64kbps. Higher data rates will not use UP integrity. This capability indication can be used as an indication from the UE to the network that it supports UP integrity. The UE can indicate its preference regarding whether UP integrity protection should be used. This preference can apply to all data exchanged with the network, and can apply to specific slice types (e.g., Network Slice Selection Auxiliary Information, NSSAI) or slice identifiers (e.g., Data Network Name, DNN).

[0225] The examples below apply to both 5G and 4G (EPC / LTE). In 4G (EPC / LTE), the registration process described below will be replaced by an attach process or a tracking area update process. The new improvements described in the steps below apply to EPC because a very similar process is used in 4G (EPC).

[0226] register

[0227] SA2 is developed for 5G and Figure 21 The following registration process shown in the figure is improved by using UP's integrity protection negotiation, and the new improvement in the figure is to The text is shown.

[0228]

[0229] refer to Figure 21 Steps 1 to 23 in the process:

[0230] 1. UE to RAN: Registration Request (Registration Type, Permanent ID or Temporary ID, Security Parameters, NSSAI)

[0231] Registration type indicator: Whether the UE wants to perform "initial registration" (i.e., the UE is in an unregistered state) or "normal registration" (i.e., the UE is in a registered state). If a temporary ID is included, the temporary ID indicates the last serving AMF. Security parameters are used for authentication and integrity protection. NSSAI indicates network slice selection auxiliary information (as defined in TS 23.501, TS23.502, and TR 23.799).

[0232]

[0233] 2. If the permanent ID is included, or the temporary ID does not indicate a valid AMF, the RAN selects an AMF based on RAT and NSSAI (if available).

[0234] The RAN selects an AMF as described in TS 23.501, TS 23.502 and TR 23.799.

[0235] 3. RAN to AMF: Registration Request (registration type, permanent ID or temporary ID, security parameters, NSSAI) and location information, cell identity, RAT type.

[0236] Location information, cell identity and RAT type related to the cell in which the UE is camped.

[0237] 4. [Conditional] New AMF to old AMF: Information Request (complete registration request)

[0238] If the UE's temporary ID is included in the registration request and the serving AMF has changed since the last registration, the new AMF can send an Information Request to the old AMF including the Complete Registration Request IE to request the UE's permanent ID and MM context.

[0239] 5. [Conditional] Old AMF to new AMF: Information Response (permanent ID, MM context)

[0240] The old AMF responds to the new AMF with an Information Response including the UE's permanent ID and MM context.

[0241]

[0242] 6. [Conditional] AMF to UE: Identity Request

[0243] If the permanent ID is neither provided by the UE nor retrieved from the old AMF, the AMF sends an Identity Request message to the UE to initiate the identity request procedure.

[0244] 7. [Conditional] UE to AMF: Identity Response

[0245] The UE responds with an Identity Response message including the permanent ID.

[0246] 8. If the registration request is not sent, the integrity or integrity protection is indicated as failed (Information Response of step 5), the AMF selects an AUSF based on the permanent ID.

[0247] The AMF selects an AUSF as described in clause X of TS 23.ABC[xx].

[0248] 9. If the registration request was not sent, the integrity protected or integrity protection was indicated as failed in step 5 (Information Response), the AUSF can initiate authentication of the UE and NAS security functions. If security is established, the AMF can retrieve the IMEI from the UE.

[0249] Authentication and security are performed as described in TS 23.502 and SA3 TR 33.799.

[0250] 10. [Conditional] AMF to UE: Identity Request

[0251] If the ME identity is neither provided by the UE nor retrieved from the old AMF, the AMF sends an Identity Request message to the UE to initiate the Identity Request procedure to retrieve the ME identity.

[0252] 11. Optionally, the AMF initiates the ME identity check.

[0253] The ME identity check is performed as described in TS 23.502.

[0254] 12. If step 13 will be performed, the AMF selects the SDM based on the permanent ID.

[0255] The AMF selects the SDM as described in TS 23.502.

[0256] 13. If the AMF has changed since the last registration, or if there is no valid subscription context for the UE in the AMF, or if the UE provided a permanent ID that does not refer to a valid context in the AMF, the AMF initiates the Update Location procedure. This will include the SDM initiating the location cancellation (if present) to the old AMF. The old AMF deletes the MM context and informs all possibly associated SMFs.

[0257] The Update Location procedure is performed as described in TS 23.502.

[0258]

[0259] 14. Optionally, the AMF selects the PCF based on the permanent ID.

[0260] The AMF selects the PCF as described in TS 23.502.

[0261] 15. [Optional] AMF to PCF: UE Context Setup Request

[0262] The AMF requests the PCF to apply operator policies for the UE.

[0263] 16. PCF to AMF: UE Context Setup Ack

[0264] The PCF acknowledges the UE context setup request message.

[0265] 17、

[0266] The AMF sends a registration accept message to the UE indicating that the "initial registration" has been accepted. If the AMF allocated a new temporary ID, the temporary ID is included.

[0267]

[0268]

[0269] 21. [Conditional] UE to AMF: Registration complete

[0270] The UE sends a registration complete message to the AMF to acknowledge whether a new temporary ID was allocated.

[0271]

[0272] The core network indicates to the RAN whether UP integrity protection should be used or not

[0273] It should be appreciated that the new improvements described in the steps below are illustrated in Figure 22 and denoted by the text are applicable to both 5G and 4G (EPC / LTE). The core network indicates to the RAN whether UP integrity protection should be used or not.

[0274] With the support of the indication whether UP integrity protection should be used or not, the following registration procedures developed for 5G in SA2 are improved.

[0275] Reference is made to steps 4 to 8 in Figure 22

[0276] The RAN indicates to the UE whether it supports or not UP integrity protection

[0277] It should be appreciated that the new improvements described in the steps below are illustrated in

[0278] and denoted by the Figure 23 text are applicable to both 5G and 4G (EPC / LTE). Reference is made to steps 4 to 8 in

[0279] Figure 23

[0280]

[0281] ​​

[0282] Initial AS security context establishment

[0283] The new improvements described in the following steps are made by using Textual representation.

[0284] 4G (EPC / LTE)

[0285] Each eNB shall be configured via network management with a list of algorithms allowed to be used. There shall be one list for integrity algorithms and one list for encryption algorithms. These lists shall be ordered according to a priority decided by the operator. When an AS security context is established in the eNB, the MME shall send the UE EPS security capabilities to the eNB, The eNB shall pick the encryption algorithm that has the highest priority in the list configured in the eNB and that is present in the UE EPS security capabilities at the same time. The eNB shall pick the integrity algorithm that has the highest priority in the list configured in the eNB and that is present in the UE EPS security capabilities at the same time.

[0286] It shall be indicated to the UE in the AS SMC. The encryption algorithm is used for encryption of user plane and RRC traffic. The integrity algorithm is used for integrity protection of RRC traffic and, if applicable, for integrity protection of user plane traffic between RN and DeNB.

[0287]

[0288] 5G

[0289] Each gNB shall be configured via network management with a list of algorithms allowed to be used. There shall be one list for integrity algorithms and one list for encryption algorithms. These lists shall be ordered according to a priority decided by the operator. When an AS security context is established in the gNB, the AMF shall send the UE 5GS security capabilities to the eNB, The eNB shall pick the encryption algorithm that has the highest priority in the list configured in the eNB and that is present in the UE 5GS security capabilities at the same time. The gNB shall pick the integrity algorithm that has the highest priority in the list configured in the eNB and that is present in the UE 5GS security capabilities at the same time.

[0290] Should be indicated to the UE in the AS SMC. The ciphering algorithm is used for ciphering of user plane and RRC traffic. The integrity algorithm is used for integrity protection of RRC traffic and, if applicable, for integrity protection of user plane traffic between RN and DgNB.

[0291]

[0292] Handover

[0293] The new improvements described in the steps below by using Textual representation.

[0294] X2 handover

[0295] 4G (EPC / LTE)

[0296] At handover over X2 from source eNB to target eNB, the source eNB shall include the UE EPS security capabilities in the Handover Request message, as well as an indication whether UP integrity should be turned on or not, the ciphering algorithm and the integrity algorithm used in the source cell. The target eNB shall select from the UE EPS security capabilities the algorithm with the highest priority according to a prioritized list of locally configured algorithms (this applies to both the integrity algorithm and the ciphering algorithm). If the target eNB selects a different algorithm compared to the source eNB, the selected algorithm, as well as an indication whether UP integrity should also be turned on, shall be indicated to the UE in the Handover Command (i.e. in the RRCConnectionReconfiguration procedure in TS 36.331). If the UE does not receive any selection of integrity algorithm and ciphering algorithm, the UE continues to use the ones before the handover. (see TS 36.331

[21] ). In the path-switch message, the target eNB shall send to the MME the UE EPS security capabilities received from the source eNB, The MME shall verify that the UE EPS security capabilities received from the eNB, are the same as the UE EPS security capabilities the MME has stored, If there is a mismatch, the MME can log the event and can take additional measures (e.g. initiate an alarm).

[0297] The encryption algorithm and integrity algorithm used in the source cell are transferred to the target eNB in the handover request message in order for the target eNB to decrypt and integrity verify the RRC Reestablishment Complete message on SRB1 during possible RRC Connection Re-establishment procedure. This information is also used by the target eNB to decide whether to include the new selection of security algorithms in the handover command A new selection of security algorithms in the handover command

[0298] Xn handover

[0299] 5G

[0300] When handing over over Xn from a source gNB to a target gNB, the source gNB shall include the UE 5GS security capabilities, and the encryption algorithm and integrity algorithm used in the source cell in the handover request message. The target gNB shall select the algorithm with the highest priority from the UE 5GS security capabilities according to a prioritized list of locally configured algorithms (this applies to both integrity algorithm and encryption algorithm). If the target gNB selects a different algorithm compared to the source gNB, the selected algorithm, shall be indicated to the UE in the (handover command). If the UE does not receive any selection of integrity algorithm and encryption algorithm, the UE continues to use the same algorithms as before the handover (see TS 36.331

[21] ). In the path switch message, the target gNB shall send the UE 5GS security capabilities received from the source gNB, and to the AMF. The AMF shall verify that the UE 5GS security capabilities received from the gNB, are the same as the UE 5GS security capabilities already stored by the AMF, If there is a mismatch, the AMF can log the event and can take additional measures (e.g. initiate an alarm).

[0301] The encryption and integrity algorithms used in the source cell are transferred to the target gNB in the Handover Request message in order for the target gNB to decrypt and integrity verify the RRCConnectionReestablishmentComplete message on SRB1 during the possible RRC Connection Re-establishment procedure. This information is also used by the target gNB to decide whether a new selection of security algorithms needs to be included in the Handover Command (RRCConnectionReconfiguration message).

[0302]

[0303]

[0304]

[0305]

[0306] S1 handover

[0307]

[0308] When handing over over S1 from a source eNB to a target eNB (possibly including MME change, and thus UE security capabilities transfer from source MME to target MME, The target MME shall send the UE EPS security capabilities, The target eNB shall select the algorithm with the highest priority from the UE EPS security capabilities according to the prioritized list of locally configured algorithms (this applies to both integrity and encryption algorithms). If the target eNB selects a different algorithm compared to the source eNB, the selected algorithm, and Should be indicated to the UE in the RRCConnectionReconfiguration message (i.e. the Handover Command). If the UE does not receive any selection of integrity and encryption algorithms, it continues to use the same algorithms as before the handover and (see TS 36.331

[21] ).

[0309] NG2 handover

[0310] 5G

[0311] At handover from source gNB to target gNB over NG2 (possibly including AMF change, and consequent transfer of UE security capabilities from source AMF to target AMF, The target AMF shall send the UE 5GS security capabilities to the target gNB in the NG2 AP HANDOVER REQUEST message, The target gNB shall select the algorithm with the highest priority from the UE 5GS security capabilities according to the prioritized list of locally configured algorithms (this applies to both integrity algorithms and encryption algorithms). If the target gNB selects a different algorithm compared to the source gNB, the selected algorithm, and shall be indicated to the UE in the RRCConnectionReconfiguration message (i.e. the handover command). If the UE does not receive any selection of integrity algorithm and encryption algorithm in the RRCConnectionReconfiguration message, it continues to use the same algorithms as before the handover and (see TS 36.331

[21] ).

[0312]

[0313] Table 2: Architecture options for similar to NG2 handover

[0314]

[0315] Intra-eNB handover

[0316]

[0317] No need to change AS security algorithms in RRCConnectionReconfiguration message during intra-eNB handover If the UE does not receive any selection of new AS security algorithms in the RRCConnectionReconfiguration message during intra-eNB handover, the UE continues to use the same algorithms as before the handover (see TS 36.331

[21] ).

[0318] Intra-gNB and intra-eNB handover

[0319] 5G

[0320] No need to change AS security algorithms in RRCConnectionReconfiguration message during intra-gNB handover If the UE does not receive any selection of new AS security algorithms in the RRCConnectionReconfiguration message during an intra-gNB handover, the UE continues to use the same algorithms as before the handover

[0321] No change of AS security algorithms during intra-eNB handover If the UE does not receive any selection of new AS security algorithms in the RRCConnectionReconfiguration message during an intra-eNB handover, the UE continues to use the same algorithms as before the handover

[0322] Dual connectivity

[0323] It should be understood that the new improvements described in the steps below and indicated by using italics apply to both 4G and 5G.

[0324] Addition and modification of data radio bearers (DRBs) in a secondary eNB (SeNB)

[0325] When performing a SeNB addition procedure (i.e. initial offloading of one or more radio bearers towards the SeNB) or a SeNB modification procedure that requires an update of S-K eNB , the master eNB (MeNB) shall derive S-K eNB as defined in clause E.2.4 of TS 33.401 eNB A new S-K eNB is generated. During the SeNB addition procedure or the SeNB modification procedure that requires a key update, the MeNB shall provide the generated S-K eNB to the SeNB. SeNB.

[0326] TS 36.300 defines the SeNB addition procedure and the SeNB modification procedure.

[0327]

[0328] The SeNB shall derive the key K UPenc from the received S-K eNB as defined in clause E.2.4 of the current specification and use K UPenc for all radio bearers that are added.

[0329] At any instant, the same K UPencIt was used to encrypt all radio bearers between the SeNB and the UE. Once from SK eNB Exported K UPenc SeNB and UE can delete SK eNB .

[0330]

[0331] During the SeNB addition process for adding one or more radio bearers to the UE, the MeNB should provide the UE with exported SK. eNB The value of the SCG counter used. The UE should derive the SK value as described in section E.2.4 of TS 33.401. eNB and K UPenc .

[0332] When performing the procedure to add subsequent radio bearers to the same SeNB, the MeNB should allocate radio bearers for each new radio bearer since the last SK. eNB The radio bearer identifier that was not used before the change.

[0333] If the MeNB is unable to allocate unused radio bearer identifiers to new radio bearers in the SeNB due to exhaustion of radio bearer identifier space, the MeNB should increment the SCG counter and calculate the new SK. eNB And then the SeNB modification process should be performed to update SK. eNB Even when it becomes possible to assign a new radio bearer identifier, the MeNB can choose to update the SK. eNB Instead of assigning new radio bearer identifiers.

[0334] If the SeNB receives a new SK from the MeNB during the SeNB modification process... eNB Then SeNB should use the new SK eNB Exported K UPenc It serves as the encryption key for all radio bearers.

[0335] If the UE receives a new SCG counter during the SeNB addition / modification process, the UE should use the new SK counter. eNB Exported K UPenc This serves as the encryption key for all radio bearers already established with SeNB.

[0336] When the last radio bearer on the SeNB is released, the SeNB release procedure is performed; the SeNB and UE should delete the K UPenc If SK was not deleted before...eNB Then SeNB and UE shall also delete S-K eNB .

[0337] Start of encryption / decryption

[0338] The DRB offload procedure with start of encryption / decryption follows the steps outlined below and shown in Figure 24 .

[0339] 1. The UE and the MeNB establish an RRC connection.

[0340] 2. The MeNB decides to offload DRBs towards the SeNB. The MeNB sends a request message for SCG addition to the SeNB over X2-C (Xn-C in 5G) to negotiate the available resources on the SeNB, configure, The MeNB computes and transfers S-K eNB to the SeNB as needed. The UE EPS security capabilities and the encryption algorithm used on the signaling radio bearer should also be sent to the SeNB.

[0341]

[0342] 3. The SeNB allocates the required resources and picks the encryption algorithm that has the highest priority in its configured list and that is also present in the UE EPS security capabilities.

[0343] 4. The SeNB sends a message for SCG addition grant to the MeNB to indicate the availability of the requested resources and the identifier for the selected algorithm (if it is different from the one selected by the MeNB in 2) to serve the requested DRBs for the UE.

[0344]

[0345]

[0346] 5. The MeNB sends an RRC connection reconfiguration request to the UE indicating that it configures a new DRB towards the SeNB. The MeNB shall include the SCG counter parameter to indicate that the UE shall compute S-K eNB and K UPenc for the SeNB, and The MeNB forwards the UE configuration parameters to the UE (which can include the algorithm identifiers received from the SeNB in step 4). (See TS 33.401 section E.2.4.3 for additional details).

[0347] Because the message is sent between the MeNB and the UE over the RRC connection, the K RRCint is used by the MeNB. The message is integrity protected. Thus the SCC cannot be tampered with and the UE can assume that the SCC is new.

[0348] 6、The UE accepts the RRC connection reconfiguration command and shall compute the S-K eNB for the SeNB. The UE shall also compute the K UPenc The UE sends the RRC reconfiguration complete to the MeNB. Once the S-K eNB and K UPenc are derived, the UE starts encryption / decryption.

[0349] 7、The MeNB sends a complete message for SCG addition to the SeNB over X2-C (Xn-C in 5G) in 4G to inform the SeNB of the configuration result. When receiving this message, the SeNB can activate encryption / decryption of the UP data with the UE If the SeNB does not activate encryption / decryption with the UE at this stage The SeNB shall activate encryption / decryption after receiving the random access request from the UE

[0350] Negotiation of security algorithms

[0351] As shown in Figure 24 When one or more DRBs for the UE are established at the SeNB, the MeNB shall forward the UE EPS security capabilities / UE 5GS security capabilities associated with the UE, the identifiers of the AS encryption algorithms selected by the MeNB for SRBs for the UE to the SeNB in the X2 (4G) (Xn (5G)) request message for SCG SeNB addition / modification.

[0352] Upon reception of this message, the SeNB shall identify the AS encryption algorithm having the highest priority in the locally configured priority list of AS encryption algorithms also present in the received UE EPS security capabilities. If the so identified AS encryption algorithm is different from the one indicated in the received X2 request message for SCG addition / modification, the SeNB shall include in the X2 response message for SCG addition / modification an indicator for the locally identified AS encryption algorithm.

[0353]

[0354] The MeNB shall forward this indication to the UE during the RRC Connection Reconfiguration (RRCConnectionReconfiguration) procedure which establishes the SCG DRBs in the UE. If the UE does not receive any AS encryption algorithm indication in this RRCConnectionReconfiguration procedure, the UE shall use the same AS encryption algorithm it uses for SRBs for the SCG DRBs. Otherwise, the UE shall use the indicated encryption algorithm for the SCG DRBs.

[0355] The UE uses one encryption algorithm for the encryption of SRBs and any possible DRBs established with the MeNB, and the same or a different encryption algorithm for the encryption of DRBs established with the SeNB. Encryption algorithm.

[0356]

[0357]

[0358] S-K eNB Update

[0359] S-K eNB Update trigger

[0360] The system supports update of S-K eNB . The MeNB can update S-K eNB at any time by using the S-K eNB update procedure defined in clause E.2.5.2 of TS 33.401 for any reason. eNB

[0361] If the MeNB has a currently valid K eNB ​If a key update is performed, the MeNB should update any SKs associated with that AS security context. eNB This preserves the two-hop safety property for X2 switching.

[0362]

[0363] If MeNB receives a request for SK from SeNB eNB The update request or the decision to execute SK. eNB If updated (see TS 33.401, section E.2.5.1), then MeNB should calculate the new SK according to the definition in TS 33.401, section E.2.4. eNB And increment the SCG counter. The MeNB should then execute the SeNB modification procedure to send the new SK to the SeNB. eNB The MeNB should provide the UE with the information regarding the export of the SK during the integrity-protected RRC process. eNB The value of the SCG counter used. The UE should derive the SK value as described in Section E.2.4 of TS33.401. eNB and K UPenc .

[0364] When UE or SeNB starts using the new SK eNB At that time, they should be based on the new SK eNB Recalculate K UPenc .

[0365] RAN decides whether to use UP integrity.

[0366] It should be understood that the new improvements outlined below and indicated in italics apply to both 5G and 4G (EPC / LTE).

[0367]

[0368] Visibility and configurability in UE

[0369]

[0370]

[0371] As discussed above, the aspects and examples of the present disclosure outlined above are applicable to 5G (next generation system), EPC / LTE, and other networks. The aspects and examples of the present disclosure outlined above are applicable to all types of UEs including smart phones, IoT devices, wearable devices, etc. A summary of different aspects of the functionality that can be provided by the methods and procedures discussed above is explained below:

[0372] How the policy of application of integrity protection is handled in the network, e.g. how the home network influences the policy, how the AMF / MME or gNB / eNB decides whether to apply integrity:

[0373] The UE indicates to the core network AMF / MME support or otherwise of UP integrity. The UE can also indicate to the core network AMF / MME its preference to use or not use UP integrity. The home network (SDM / HSS) can indicate to the serving network that UP integrity "should" or "shall" be turned on. Based on the indication received from the home network and the policy configured for the visited network (AMF / MME), the visited network makes a policy decision on whether UP integrity will be applied to the UE. Based on the policy decision, the core network indicates to the UE in the NAS layer whether UP integrity will be used. The core network (AMF / MME) informs the base station or RAN whether integrity protection for UP data will be used.

[0374] Any of the above mentioned policies and preferences can be per UE (i.e. for all user plane data) or per slice type or per slice identity (for the UE). For example, the UE can indicate a preference to use UP integrity for all data, or per slice type or slice identity. The home network can indicate a preference to use UP integrity for all data, or per slice type or slice identity, and the AMF / MME can make a policy decision per UE (for all UP data) or per slice type or slice identity.

[0375] How the UE reacts if it does not get the level of protection it wants (including the preferences stored in HSS or negotiated):

[0376] Initial or default preferences of a subscriber for using integrity protection on UP can be stored in the SDM / HSS and in the UE. The AMF / MME in the serving network can obtain the preferences from the SDM / HSS. The AMF / MME can inform the gNB / eNB of the preferences of the UE. The gNB / eNB can then decide whether to use UP integrity protection based on the preferences of the UE and possibly other information.

[0377] If the UE wants to change the initial or default preference mentioned above, the UE can send its current preference to the network (e.g. gNB / eNB or AMF / MME). The network can decide whether to replace the initial or default preference with the UE’s current preference.

[0378] In either of the cases mentioned above (i.e. initial or default preference, or current preference), if the UE does not get the desired UP integrity protection, the UE can take a response action. The response action can be: continue without UP integrity protection, or connect to another gNB / eNB / cell, or avoid using a certain application, or inform a certain function / application in the operator’s / third party’s network.

[0379] Policy on how to handle application of integrity protected UP in a base station at X2 and Xn handover:

[0380] At X2 or Xn handover between two base stations, the source base station can need to inform the target base station whether integrity protection of UP data is enabled. The indication or reference can be sent from the source node to the target node over the Xn or X2 interface.

[0381] If the indication received from the source base station is an indication that UP integrity protection will be enabled, the target base station can respond to the source base station with the indication. If the target base station does not support integrity protection of UP data and the indication from the source base station indicates that UP integrity should be used, the target base station can reject the handover by responding with an error code, or accept the handover but not send its indication that it will enable UP integrity protection (e.g. in the case of a legacy base station). The policy configured for the target node can determine the appropriate action. If the target base station accepts the request but does not send its indication that it will enable UP integrity protection (e.g. in the case of a legacy base station), the policy configured in the source base station can determine whether the source base station should continue the procedure or terminate the connection with the target base station.

[0382] Policy on how to handle application of integrity protected UP in a base station at dual connectivity:

[0383] In dual connectivity between two base stations, the primary base station can inform the secondary base station whether to enable integrity protection for UP data. The indication or preference can be sent from the primary base station to the secondary base station over the Xn interface or the X2 interface. If the indication received from the primary base station is an indication that UP integrity protection will be enabled, the secondary base station can respond to the primary base station with that indication. If the secondary base station does not support integrity protection for UP data and the indication from the primary base station indicates that UP integrity should be used, the secondary base station can either reject the request from the primary base station to setup the bearer by responding with an error code, or accept the request but not send an indication that it will enable UP integrity protection (e.g., in the case of a legacy base station). The policy configured for the secondary base station can determine the appropriate action. If the secondary base station accepts the request but does not send an indication that it will enable UP integrity protection, the policy configured in the primary base station can determine whether the primary base station should continue the procedure or terminate the connection with the secondary base station.

[0384] How the UE preference to use or not use UP integrity protection is determined in the UE, and how the user is made aware whether UP integrity protection has been enabled or disabled in the network:

[0385] The user of the UE can dynamically configure and change the UE's preference whether to use UP integrity in the UE GUI (user interface). It can be possible to configure the UE's preference whether to use UP integrity according to slice type, according to specific slice, according to cell, according to area, etc. When the registration procedure is completed, the UE can indicate to the user whether UP integrity has been enabled or disabled by the network. The indication can be according to type of slice, according to specific slice, according to cell, according to area, etc.

[0386] For IoT devices that do not have a GUI (user interface), the UE's preference can be pre-configured on the USIM or in the ME.

[0387] In case integrity protection is disabled in the device (e.g., IoT device), a notification can be sent to another device by the UE or by the network. For example, via SMS, instant messaging, email.

[0388] The device configuration can not need to be performed by the device itself. The device configuration can be performed remotely (e.g., by the operator or service provider initiated using OMA DM, for example, using SMS or email).

[0389] How the UE discovers a PLMN that supports UP integrity protection:

[0390] The UE can be able to detect a network that is not secure enough and can apply a user-configured policy of how to react (e.g., only connect to a network that provides integrity protection for UP). This is beneficial for security for IoT devices that are used by subscribers that trust the operator, but requires stronger security than what is offered by today's network providers. In case the preferred PLMN does not use UP integrity protection, other PLMNs can be configured by the user or the UE to pick.

[0391] Another option can be to set a new list on the USIM or in the ME that can contain PLMNs that support UP integrity protection. This list can be provided and configured to the UE by the home PLMN's operator over-the-air. The home PLMN knows which operators it has roaming agreements with and knows which operators support UP integrity protection.

[0392] In a further option, the base station can broadcast whether it supports UP integrity protection as part of the system information within its respective cell.

[0393] If the UE experiences a handover to a gNB or eNB that does not support UP integrity, how does the UE act:

[0394] The user can configure in the UE GUI whether to automatically accept non-integrity protected UP traffic (e.g., at handover) without asking the user's policy. The user can also be informed after a handover to a new gNB or eNB that the new gNB or eNB does not support integrity protection and can be asked whether to continue the connection with the network. The UE can be configured to try to connect to a different gNB or eNB of the same PLMN in case the gNB or eNB does not start integrity protection, in the hope that the other gNB or eNB is updated with UP integrity algorithms and supports UP integrity protection.

[0395] In case integrity protection is disabled in a device (e.g., an IoT device), a notification can be sent to another device by the UE or by the network. For example, via SMS, instant messaging, email, etc.

[0396] How does the gNB / eNB decide whether to apply and use UP integrity:

[0397] The core network (AMF / MME) can inform the base station or RAN whether to use integrity protection for UP data. The indication or reference can be sent on the NG2 interface in 5G and S1 interface in 4G between the core network and the base station (RAN). The UE 5GS security capabilities can be sent on the NG2 interface together with the indication or reference. The gNB or eNB has the local policy (based on the UE 5GS security capabilities) whether to activate UP integrity for UEs supporting UP integrity or not, if possible.

[0398] Aspects and examples of the present disclosure can thus enable the UE, the home network, and the visited network to indicate and negotiate the use of UP integrity in a secure manner.

[0399] The core network can inform the base station whether the base station should enable integrity protection for UP data. Another option can be that the RAN can decide to use UP integrity or not without being told by the core NW whether to use UP integrity or not.

[0400] In Xn handover or X2 handover between two base stations, the source base station can inform the target base station whether to enable integrity protection for UP data. The target base station can implement UP integrity for the UE being handed over.

[0401] In dual connectivity between two base stations, the master base station can inform the secondary base station whether to enable integrity protection for UP data. The indication or reference can be sent from the master base station to the secondary base station on the Xn interface or X2 interface. The secondary base station can implement UP integrity for bearers offloaded from the master base station.

[0402] Advantageously, the user of the UE can dynamically configure and change the UE's preference in the UE GUI (user interface) regarding whether to use UP integrity or not. The UE's preference whether to use UP integrity or not can be configured for all data, or according to slice type or according to slice identifier.

[0403] When the registration procedure is completed, the UE can indicate to the user whether UP integrity has been enabled or disabled by the network. The indication can be made for all data, or according to type of slice or slice identifier.

[0404] The UE can be able to detect a network with inferior security and apply a user-configured policy of how to react (e.g., only connect to networks providing integrity protection for UP). This is advantageous for security for IoT devices for which the subscriber trusts the operator, but requires stronger security than today's network providers.

[0405] The user can configure in the phone GUI whether to automatically accept non-integrity protected UP traffic (e.g., at handover) without asking the user's policy.

[0406] In case the preferred PLMN does not use UP integrity protection, the user can configure other PLMNs to be picked.

[0407] In case the preferred PLMN does not use UP integrity protection, the home operator can configure other PLMNs to be picked. The list can be provided and configured to the UE by the operator of the home PLMN over the air.

[0408] The user can also be informed after handover to a new gNB or eNB that the new gNB or eNB does not support integrity protection and can be asked if he wants to continue the connection to the network.

[0409] The UE can be configured to try to connect to a different gNB or eNB of the same PLMN in case the gNB or eNB does not start integrity protection in the hope that the other gNB or eNB is updated with UP integrity algorithms and supports UP integrity protection.

[0410] The gNB or eNB can have a local policy (based on the UE 5GS security capabilities) whether to start UP integrity for UEs that support UP integrity.

[0411] The methods of the present disclosure can be implemented in hardware, or as software modules running on one or more processors. The methods can also be performed according to instructions in a computer program and the present disclosure also provides a computer readable medium having stored thereon a program for performing any of the methods described herein. A computer program product embodying the present disclosure can be stored on a computer readable medium, or it can be in the form of a signal such as a downloadable data signal.

[0412] It should be noted that the above-mentioned examples illustrate rather than limit the disclosure, and that those skilled in the art will be able to design many alternative embodiments without departing from the scope of the appended claims. The word "comprising" does not exclude the presence of elements or steps other than those listed in a claim "a" or "an" shall not exclude the presence of a plurality of that element, and a single processor or other unit can fulfill the functions of several units recited in the claims. Any reference signs in the claims should not be construed as limiting the scope of the claims.

[0413] The following are certain illustrative embodiments further showing various aspects of the disclosed subject matter.

[0414] 1. A method for operating a user equipment, UE, configured to connect to a communication network, the method comprising:

[0415] when requesting to register with the communication network, indicating to the communication network an IPUP mode supported by the UE for a user plane;

[0416] wherein the IPUP mode comprises one of:

[0417] using integrity protection for user plane data exchanged with the UE;

[0418] not using integrity protection for user plane data exchanged with the UE; or

[0419] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0420] 2. The method of item 1, further comprising:

[0421] indicating to the communication network a UE preference regarding an IPUP mode to be used by the communication network for the UE.

[0422] 3. The method of item 2, wherein the indicated UE preference applies to at least one of:

[0423] all data exchanged with the communication network; or

[0424] data exchanged with one specific slice or multiple slices of the communication network.

[0425] 4. The method of any of the preceding items, further comprising:

[0426] receiving from the communication network an indication of an IPUP mode to be used by the communication network for the UE.

[0427] 5. The method of item 4, wherein the indication applies to at least one of:

[0428] all data exchanged with the communication network; or

[0429] data exchanged with one specific slice or multiple slices of the communication network.

[0430] 6. The method of item 4 or item 5, further comprising:

[0431] informing a user of the UE of the IPUP mode to be used by the communication network for the UE.

[0432] 7. The method of any of items 4 to 6, further comprising:

[0433] if the IPUP mode indicated by the communication network does not match the UE preference on which IPUP mode the UE should use with respect to the communication network, performing at least one of:

[0434] rejecting to connect to the network;

[0435] disconnecting from the network;

[0436] informing a user of the UE that the IPUP mode indicated by the communication network does not match the UE preference on which IPUP mode the UE should use with respect to the communication network.

[0437] 8. The method according to item 7, further comprising:

[0438] if the UE performs at least one of rejecting to connect to the network or disconnecting from the network, performing at least one of:

[0439] requesting to register with the communication network via a different radio access node of the communication network; or

[0440] requesting to register with a different communication network.

[0441] 9. The method according to item 8, further comprising:

[0442] querying a list comprising at least one of a radio access node or a communication network supporting integrity protection for user plane data; and

[0443] selecting at least one of a radio access node of the communication network or a different communication network for requesting registration from the list.

[0444] 10. The method according to item 9, wherein the list is configured in a memory of the UE.

[0445] 11. The method according to item 9, wherein the list is received over a radio link.

[0446] 12. The method according to any of the preceding items, further comprising:

[0447] receiving a message from the target radio access node of the communication network during a procedure of handing over the UE from a source radio access node to the target radio access node, the message comprising an indication that the target radio access node will use a different IPUP mode for the UE than the IPUP mode used by the source radio access node.

[0448] 13. The method according to item 12, further comprising:

[0449] If the indication from the target radio access node is that the IPUP mode to be used by the communication network via the target radio access node does not match the UE preference on which IPUP mode the UE should use with the communication network, then at least one of the following is performed:

[0450] Disconnecting from the network;

[0451] Accepting the handover and informing a user of the UE about the IPUP mode to be used by the communication network via the target radio access node; or

[0452] Seeking handover to a different radio access node of the communication network.

[0453] 14. The method according to any of the preceding items, further comprising,

[0454] receiving, from a radio access node of the communication network, an indication of an IPUP mode to be used by the communication network for the UE during a procedure for secondary radio access node addition, secondary radio access node modification requiring key update, or data radio bearer offloading; and

[0455] If the indicated IPUP mode involves use of integrity protection for user plane data, deriving and using a key for integrity protection of user plane data.

[0456] 15. The method according to item 14, wherein the indication of the IPUP mode to be used by the communication network for the UE is received with a RRC reconfiguration request.

[0457] 16. A method for operating a radio access node of a communication network, the method comprising:

[0458] receiving, from a user equipment, UE, requesting registration with the communication network, an indication of an integrity protection, IPUP, mode for a user plane that the UE supports;

[0459] wherein the IPUP mode comprises one of:

[0460] use of integrity protection for user plane data exchanged with the UE;

[0461] no use of integrity protection for user plane data exchanged with the UE; or

[0462] use of integrity protection for user plane data and no use of confidentiality protection for user plane data;

[0463] and wherein the indication is received from the UE via the communication network.

[0464] 17. The method of item 16, further comprising:

[0465] receiving, from the UE, a UE preference for an IPUP mode to be used by the communication network for the UE.

[0466] 18. The method of item 17, wherein the indicated UE preference applies to at least one of:

[0467] all data exchanged with the communication network; or

[0468] data exchanged with one particular slice or multiple slices of the communication network.

[0469] 19. The method of any of items 16 to 18, further comprising:

[0470] receiving, from a core node of the communication network, an indication of an IPUP mode to be used by the communication network for the UE.

[0471] 20. The method of item 19, further comprising:

[0472] if the indicated IPUP mode is supported by the radio access node, sending an indication to the core node that the radio access node will enable the IPUP mode to be used by the communication network for the UE.

[0473] 21. The method of item 19 or item 20, further comprising:

[0474] if the indicated IPUP mode received from the core node of the communication network is not supported by the radio access node, performing at least one of:

[0475] rejecting a request received from the UE for registration; or

[0476] omitting sending an indication to the core node that the radio access node will enable the IPUP mode to be used by the communication network for the UE.

[0477] 22. The method of any of items 16 to 21, further comprising:

[0478] sending, to the UE, an indication of an IPUP mode to be used by the communication network for the UE.

[0479] 23. The method of item 22, wherein if the IPUP mode to be used by the communication network for the UE involves using integrity protection for user plane data, the indication of the IPUP mode to be used by the communication network for the UE includes an identifier of an algorithm for integrity protection of UP data.

[0480] 24. The method according to item 22 or item 23 when dependent on item 19, wherein the IPUP mode indicated to the UE by the radio access node is an IPUP mode received from a core node of the communication network.

[0481] 25. The method according to item 22 or item 23, wherein the IPUP mode indicated to the UE is selected by the radio access node in accordance with a policy hosted on the radio access node.

[0482] 26. A method for operating a radio access node of a communication network, the radio access node comprising a source radio access node, the method comprising:

[0483] during a handover of a user equipment, UE, from a source radio access node to a target radio access node, sending an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE;

[0484] wherein the IPUP mode comprises one of:

[0485] using integrity protection for user plane data exchanged with the UE;

[0486] not using integrity protection for user plane data exchanged with the UE; or

[0487] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0488] 27. The method according to item 26, further comprising:

[0489] checking whether an indication is received from the target radio access node that the target radio access node will enable the IPUP mode to be used by the communication network for the UE.

[0490] 28. The method according to item 27, further comprising:

[0491] if no indication is received that the target radio access node will enable the IPUP mode to be used by the communication network for the UE, assuming that the target radio access node will not enable the IPUP mode to be used by the communication network for the UE.

[0492] 29. A method for operating a radio access node of a communication network, the radio access node comprising a target radio access node, the method comprising:

[0493] receiving, during a procedure of handing over a user equipment, UE, from a source radio access node to a target radio access node, an indication by a communication network of an integrity protection for user plane, IPUP, mode to be used for the UE;

[0494] wherein the IPUP mode comprises one of:

[0495] using integrity protection for user plane data exchanged with the UE;

[0496] not using integrity protection for user plane data exchanged with the UE; or

[0497] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0498] 30. The method according to item 29, wherein the indication by the communication network of the IPUP mode to be used for the UE is received from at least one of:

[0499] the source radio access node; or

[0500] a core node of the communication network.

[0501] 31. The method according to item 29 or item 30, further comprising:

[0502] deciding whether to use the indicated IPUP mode; and

[0503] if it is decided not to use the indicated IPUP mode, sending an indication to the UE that the target radio access node will use a different IPUP mode for the UE than the IPUP mode used by the source radio access node.

[0504] 32. The method according to any of items 29 to 31, wherein the indication by the communication network of the IPUP mode to be used for the UE is received from the source radio access node, the method further comprising:

[0505] sending the indication of the IPUP mode received from the source radio access node to a core node of the communication network.

[0506] 33. The method according to any of items 29 to 32, further comprising:

[0507] if the target radio access node supports the indicated IPUP mode, sending an indication to at least one of the source radio access node or a core node of the communication network that the target radio access node will enable the IPUP mode to be used for the UE by the communication network.

[0508] 34. The method of any of clauses 29-33, further comprising:

[0509] if the target radio access node does not support the received indicated IPUP mode, performing one of:

[0510] rejecting the handover of the UE; or

[0511] accepting the handover of the UE and omitting sending an indication that the target radio access node will enable the IPUP mode to be used by the communication network for the UE.

[0512] 35. A method for operating a radio access node of a communication network, the radio access node comprising a primary radio access node, the method comprising:

[0513] sending, to a secondary radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a UE;

[0514] wherein the IPUP mode comprises one of:

[0515] using integrity protection for user plane data exchanged with the UE;

[0516] not using integrity protection for user plane data exchanged with the UE; or

[0517] using integrity protection for user plane data and not using confidentiality protection for user plane data,

[0518] and wherein the indication is sent to the secondary radio access node during a procedure for at least one of:

[0519] secondary radio access node addition;

[0520] secondary radio access node modification requiring a key update;

[0521] data radio bearer, DRB, offloading.

[0522] 36. The method of clause 35, wherein if the IPUP mode indicated to the secondary radio access node involves using integrity protection for user plane data, the indication of the IPUP mode to be used by the communication network for the UE comprises a list of supported algorithms for integrity protection of UP data.

[0523] 37. The method of clause 35 or clause 36, further comprising:

[0524] checking if an indication is received from the secondary radio access node that the secondary radio access node will enable the IPUP mode to be used by the communication network for the UE.

[0525] 38. The method of item 37, further comprising:

[0526] assuming that the secondary radio access node will not enable an IPUP mode to be used by the communication network for the UE if no indication is received that the secondary radio access node will enable an IPUP mode to be used by the communication network for the UE.

[0527] 39. The method of any of items 35 to 38, further comprising, if an indication of an IPUP mode to be used by the communication network for the UE is sent to the secondary radio access node during a DRB offload procedure:

[0528] sending an RRC reconfiguration request to the UE, the request including the indication of the IPUP mode to be used by the communication network for the UE.

[0529] 40. The method of item 39, wherein the RRC reconfiguration request includes a selected integrity algorithm identifier to be used for UP integrity protection.

[0530] 41. A method for operating a radio access node of a communication network, the radio access node comprising a secondary radio access node, the method comprising:

[0531] receiving, from a primary radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a UE;

[0532] wherein the IPUP mode comprises one of:

[0533] using integrity protection for user plane data exchanged with the UE;

[0534] not using integrity protection for user plane data exchanged with the UE; or

[0535] using integrity protection for user plane data and not using confidentiality protection for user plane data,

[0536] and wherein the indication is received from the primary radio access node during a procedure for at least one of:

[0537] secondary radio access node addition;

[0538] secondary radio access node modification requiring a key update;

[0539] data radio bearer, DRB, offload.

[0540] 42. The method of item 41, wherein, if the IPUP mode indicated by the master radio access node involves the use of integrity protection for user plane data, the indication by the communication network of the IPUP mode to be used for the UE comprises an identifier of an integrity algorithm to be used for UP integrity protection.

[0541] 43. The method of item 41 or item 42, further comprising:

[0542] if the secondary radio access node supports the indicated IPUP mode, sending an indication to the master radio access node that the secondary radio access node will enable the IPUP mode to be used for the UE by the communication network.

[0543] 44. The method of any of items 41 to 43, further comprising:

[0544] if the secondary radio access node does not support the received indicated IPUP mode, performing at least one of:

[0545] rejecting the requested procedure from the master radio access node; or

[0546] accepting the requested procedure from the master radio access node and omitting to send an indication to the master radio access node that the secondary radio access node will enable the IPUP mode to be used for the UE by the communication network.

[0547] 45. The method of any of items 41 to 44, further comprising:

[0548] if the indication of the IPUP mode to be used for the UE by the communication network is received from the master radio access node during a procedure for secondary radio access node addition, or secondary radio access node modification requiring a key update, and if the IPUP mode indicated by the master radio access node involves the use of integrity protection for user plane data, deriving and using a key for integrity protection of user plane data exchanged with the UE.

[0549] 46. A method for operating a core node in a communication network, the method comprising:

[0550] sending, to a radio access node of the communication network, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a user equipment, UE, requesting registration with the communication network;

[0551] wherein the IPUP mode comprises one of:

[0552] the use of integrity protection for user plane data exchanged with the UE;

[0553] no integrity protection is used for user plane data exchanged with the UE; or

[0554] integrity protection is used for user plane data and no confidentiality protection is used for user plane data.

[0555] 47. The method of item 46, further comprising:

[0556] checking whether an indication is received from the radio access node of the communication network that the radio access node of the communication network is to enable the IPUP mode indicated to the radio access node of the communication network.

[0557] 48. The method of item 47, further comprising:

[0558] if the indication is not received that the radio access node is to enable the IPUP mode indicated to the radio access node, assuming that the radio access node is not to enable the IPUP mode to be used by the communication network for the UE.

[0559] 49. The method of any of items 46 to 48, wherein the core network node is a new core network node for the UE, the method further comprising:

[0560] sending a request for information related to the UE to an old core network of the UE; and receiving from the old core network node an indication of the IPUP mode to be used by the communication network for the UE.

[0561] 50. The method of item 49, further comprising:

[0562] receiving, during an update location procedure, from a subscription management node corresponding to the UE, an indication of the IPUP mode to be used by the communication network for the UE.

[0563] 51. The method of item 49 or item 50, further comprising:

[0564] deciding the IPUP mode to be used by the communication network for the UE.

[0565] 52. The method of item 51, further comprising:

[0566] if the IPUP mode decided by the core network node does not match a preference communicated by the UE for the IPUP mode to be used by the communication network for the UE, performing one of:

[0567] rejecting a request from the UE to register with the communication network; or

[0568] receiving a request from the UE to register with the communication network, and informing the UE of an IPUP decided by the core network node.

[0569] 53. The method of item 51 or 52, wherein the decided IPUP mode applies to at least one of:

[0570] all data exchanged between the UE and the communication network; or

[0571] data exchanged between the UE and one specific slice or multiple slices of the communication network.

[0572] 54. The method of any of items 51 to 53, further comprising:

[0573] indicating to the UE the decided IPUP mode to be used by the communication network for the UE.

[0574] 55. A method for operating a core node in a communication network, the core network node comprising an old core network node for a user equipment, UE, requesting to register with the communication network, the method comprising:

[0575] receiving from a new core network node for the UE a request for information related to the UE; and

[0576] sending to the new core network node an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE, wherein the IPUP mode comprises one of:

[0577] using integrity protection for user plane data exchanged with the UE;

[0578] not using integrity protection for user plane data exchanged with the UE; or

[0579] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0580] 56. The method of item 55, wherein the indicated IPUP mode applies to at least one of:

[0581] all data exchanged between the UE and the communication network; or

[0582] data exchanged between the UE and one specific slice or multiple slices of the communication network.

[0583] 57. A method for operating a core node in a communication network, the method comprising:

[0584] receiving, from the target radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a user equipment, UE, to be handed over to the target radio access node;

[0585] verifying whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode stored by the core network node for the UE; and

[0586] if there is a mismatch between the indicated IPUP mode and the stored IPUP mode, performing at least one of:

[0587] logging the mismatch as an event; or

[0588] triggering an alarm;

[0589] wherein the IPUP mode comprises one of:

[0590] using integrity protection for user plane data exchanged with the UE;

[0591] not using integrity protection for user plane data exchanged with the UE; or

[0592] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0593] 58. A method for operating a core node in a communication network, the method comprising:

[0594] sending, to a target radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a user equipment, UE, to be handed over to the target radio access node;

[0595] wherein the IPUP mode comprises one of:

[0596] using integrity protection for user plane data exchanged with the UE;

[0597] not using integrity protection for user plane data exchanged with the UE; or

[0598] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0599] 59. The method according to item 56, further comprising:

[0600] checking whether an indication is received from the target radio access node that the target radio access node will enable the IPUP mode to be used by the communication network for the UE.

[0601] 60. A computer program comprising instructions which, when executed on at least one processor, cause the at least one processor to carry out the method according to any one of the preceding claims.

[0602] 61. A carrier containing the computer program of claim 60, wherein the carrier is one of an electronic signal, optical signal, radio frequency signal or computer readable storage medium.

[0603] 62. A computer program product comprising a non-transitory computer- readable medium having stored thereon a computer program according to claim 60.

[0604] 63. An apparatus for operating a user equipment, UE, configured to connect to a communication network, the apparatus comprising a processor and a memory, said memory containing instructions executable by said processor, whereby said apparatus is operable to:

[0605] indicate to the communication network an integrity protection for user plane, IPUP, mode supported by the UE when requesting to register with the communication network;

[0606] wherein the IPUP mode comprises one of:

[0607] use integrity protection for user plane data exchanged with the UE;

[0608] not use integrity protection for user plane data exchanged with the UE; or

[0609] use integrity protection for user plane data and not use confidentiality protection for user plane data.

[0610] 64. An apparatus for operating a radio access node of a communication network, the apparatus comprising a processor and a memory, said memory containing instructions executable by said processor, whereby said apparatus is operable to:

[0611] receive, from a user equipment, UE, requesting to register with the communication network, an indication of an integrity protection for user plane, IPUP, mode supported by the UE;

[0612] wherein the IPUP mode comprises one of:

[0613] use integrity protection for user plane data exchanged with the UE;

[0614] not use integrity protection for user plane data exchanged with the UE; or

[0615] using integrity protection for user plane data and not using confidentiality protection for user plane data;

[0616] and wherein the indication is received from the UE via the communications network.

[0617] 65. An apparatus for operating a radio access node of a communications network, the radio access node comprising a source radio access node, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to be operable to:

[0618] during a procedure to handover a user equipment, UE, from a source radio access node to a target radio access node, transmit an indication of an integrity protection for user plane, IPUP, mode to be used by the communications network for the UE;

[0619] wherein the IPUP mode comprises one of:

[0620] using integrity protection for user plane data exchanged with the UE;

[0621] not using integrity protection for user plane data exchanged with the UE; or

[0622] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0623] 66. An apparatus for operating a radio access node of a communications network, the radio access node comprising a target radio access node, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to be operable to:

[0624] during a procedure to handover a user equipment, UE, from a source radio access node to a target radio access node, receive an indication of an integrity protection for user plane, IPUP, mode to be used by the communications network for the UE;

[0625] wherein the IPUP mode comprises one of:

[0626] using integrity protection for user plane data exchanged with the UE;

[0627] not using integrity protection for user plane data exchanged with the UE; or

[0628] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0629] 67. An apparatus for operating a radio access node of a communications network, the radio access node comprising a primary radio access node, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor whereby the apparatus is operable to:

[0630] send, to a secondary radio access node, an indication of an integrity protection for user plane (IPUP) mode to be used by the communications network for the UE;

[0631] wherein the IPUP mode comprises one of:

[0632] integrity protection is used for user plane data exchanged with the UE;

[0633] integrity protection is not used for user plane data exchanged with the UE; or

[0634] integrity protection is used for user plane data and confidentiality protection is not used for user plane data,

[0635] and wherein the indication is sent to the secondary radio access node during a procedure for at least one of:

[0636] secondary radio access node addition;

[0637] secondary radio access node modification requiring a key update;

[0638] data radio bearer (DRB) offload.

[0639] 68. An apparatus for operating a radio access node of a communications network, the radio access node comprising a secondary radio access node, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor whereby the apparatus is operable to:

[0640] receive, from a primary radio access node, an indication of an integrity protection for user plane (IPUP) mode to be used by the communications network for the UE;

[0641] wherein the IPUP mode comprises one of:

[0642] integrity protection is used for user plane data exchanged with the UE;

[0643] integrity protection is not used for user plane data exchanged with the UE; or

[0644] integrity protection is used for user plane data and confidentiality protection is not used for user plane data,

[0645] and wherein the indication is received from the master radio access node during a procedure for at least one of:

[0646] a secondary radio access node addition;

[0647] a secondary radio access node modification requiring a key update;

[0648] a data radio bearer, DRB, offload.

[0649] 69. An apparatus for operating a core node in a communication network, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to be operable to:

[0650] send, to a radio access node of the communication network, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a user equipment, UE, requesting registration with the communication network;

[0651] wherein the IPUP mode comprises one of:

[0652] use of integrity protection for user plane data exchanged with the UE;

[0653] no use of integrity protection for user plane data exchanged with the UE; or

[0654] use of integrity protection for user plane data and no use of confidentiality protection for user plane data.

[0655] 70. An apparatus for operating a core node in a communication network, the core network node comprising an old core network node for a user equipment, UE, requesting registration with the communication network, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to be operable to:

[0656] receive, from a new core network for the UE, a request for information related to the UE; and

[0657] send, to the new core network node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE, wherein the IPUP mode comprises one of:

[0658] use of integrity protection for user plane data exchanged with the UE;

[0659] no use of integrity protection for user plane data exchanged with the UE; or

[0660] use of integrity protection for user plane data and no use of confidentiality protection for user plane data.

[0661] 71. An apparatus for operating a core node in a communication network, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor, whereby the apparatus is operable to:

[0662] receive, from a target radio access node, an indication of an integrity protection for user plane, IPUP, mode used by the communication network for a user equipment, UE, to be handed over to the target radio access node;

[0663] verify whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode stored by the core network node for the UE; and

[0664] if there is a mismatch between the indicated IPUP mode and the stored IPUP mode, perform at least one of:

[0665] log the mismatch as an event; or

[0666] trigger an alarm;

[0667] wherein the IPUP mode comprises one of:

[0668] integrity protection is used for user plane data exchanged with the UE;

[0669] integrity protection is not used for user plane data exchanged with the UE; or

[0670] integrity protection is used for user plane data and confidentiality protection is not used for user plane data.

[0671] 72. An apparatus for operating a core node in a communication network, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor, whereby the apparatus is operable to:

[0672] send, to a target radio access node, an indication of an integrity protection for user plane, IPUP, mode used by the communication network for a user equipment, UE, to be handed over to the target radio access node;

[0673] wherein the IPUP mode comprises one of:

[0674] integrity protection is used for user plane data exchanged with the UE;

[0675] integrity protection is not used for user plane data exchanged with the UE; or

[0676] integrity protection is used for user plane data and confidentiality protection is not used for user plane data.

[0677] 73. An apparatus for operating a user equipment, UE, configured to connect to a communication network, the apparatus configured to:

[0678] indicate to the communication network an integrity protection for user plane, IPUP, mode supported by the UE when requesting to register with the communication network;

[0679] wherein the IPUP mode comprises one of:

[0680] integrity protection is used for user plane data exchanged with the UE;

[0681] integrity protection is not used for user plane data exchanged with the UE; or

[0682] integrity protection is used for user plane data and confidentiality protection is not used for user plane data.

[0683] 74. An apparatus for operating a radio access node of a communication network, the apparatus configured to:

[0684] receive, from a user equipment, UE, requesting to register with the communication network, an indication of an integrity protection for user plane, IPUP, mode supported by the UE;

[0685] wherein the IPUP mode comprises one of:

[0686] integrity protection is used for user plane data exchanged with the UE;

[0687] integrity protection is not used for user plane data exchanged with the UE; or

[0688] integrity protection is used for user plane data and confidentiality protection is not used for user plane data.

[0689] and wherein the indication is received from the UE via the communication network.

[0690] 75. An apparatus for operating a radio access node of a communication network, the radio access node comprising a source radio access node, the apparatus configured to:

[0691] send, during a procedure to handover a user equipment, UE, from a source radio access node to a target radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE;

[0692] wherein the IPUP mode comprises one of:

[0693] using integrity protection for user plane data exchanged with the UE;

[0694] not using integrity protection for user plane data exchanged with the UE; or

[0695] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0696] 76. An apparatus for operating a radio access node of a communications network, the radio access node comprising a target radio access node, the apparatus configured to:

[0697] receive, during a procedure to handover a user equipment, UE, from a source radio access node to the target radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communications network for the UE;

[0698] wherein the IPUP mode comprises one of:

[0699] using integrity protection for user plane data exchanged with the UE;

[0700] not using integrity protection for user plane data exchanged with the UE; or

[0701] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0702] 77. An apparatus for operating a radio access node of a communications network, the radio access node comprising a primary radio access node, the apparatus configured to:

[0703] send, to a secondary radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communications network for a UE;

[0704] wherein the IPUP mode comprises one of:

[0705] using integrity protection for user plane data exchanged with the UE;

[0706] not using integrity protection for user plane data exchanged with the UE; or

[0707] using integrity protection for user plane data and not using confidentiality protection for user plane data,

[0708] and wherein the indication is sent to the secondary radio access node during a procedure for at least one of:

[0709] secondary radio access node addition;

[0710] Secondary radio access node modification requiring key update;

[0711] Data radio bearer, DRB, offload.

[0712] 78. An apparatus for operating a radio access node of a communication network, the radio access node comprising a secondary radio access node, the apparatus configured to:

[0713] receive, from a primary radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a user equipment, UE;

[0714] wherein the IPUP mode comprises one of:

[0715] use integrity protection for user plane data exchanged with the UE;

[0716] not use integrity protection for user plane data exchanged with the UE; or

[0717] use integrity protection for user plane data and not use confidentiality protection for user plane data,

[0718] and wherein the indication is received from the primary radio access node during a procedure for at least one of:

[0719] secondary radio access node addition;

[0720] secondary radio access node modification requiring key update;

[0721] data radio bearer, DRB, offload.

[0722] 79. An apparatus for operating a core node in a communication network, the apparatus configured to:

[0723] send, to a radio access node of the communication network, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a user equipment, UE, requesting registration with the communication network;

[0724] wherein the IPUP mode comprises one of:

[0725] use integrity protection for user plane data exchanged with the UE;

[0726] not use integrity protection for user plane data exchanged with the UE; or

[0727] use integrity protection for user plane data and not use confidentiality protection for user plane data.

[0728] 80. An apparatus for operating a core node in a communication network, the core network node comprising an old core network node for a user equipment, UE, requesting registration with the communication network, the apparatus being configured to:

[0729] receive, from a new core network for the UE, a request for information related to the UE; and

[0730] send, to the new core network node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE, wherein the IPUP mode comprises one of:

[0731] using integrity protection for user plane data exchanged with the UE;

[0732] not using integrity protection for user plane data exchanged with the UE; or

[0733] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0734] 81. An apparatus for operating a core node in a communication network, the apparatus being configured to:

[0735] receive, from a target radio access node, an indication by the communication network of an integrity protection for user plane, IPUP, mode to be used by a user equipment, UE, being handed over to the target radio access node;

[0736] verify whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode stored by the core network node for the UE; and

[0737] if there is a mismatch between the indicated IPUP mode and the stored IPUP mode, then performing at least one of:

[0738] logging the mismatch as an event; or

[0739] triggering an alarm;

[0740] wherein the IPUP mode comprises one of:

[0741] using integrity protection for user plane data exchanged with the UE;

[0742] not using integrity protection for user plane data exchanged with the UE; or

[0743] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0744] 82. An apparatus for operating a core node in a communication network, the apparatus configured to:

[0745] transmit, to a target radio access node, an indication of an integrity protection for user plane, IPUP, mode used by the communication network for a user equipment, UE, to be handed over to the target radio access node;

[0746] wherein the IPUP mode comprises one of:

[0747] use of integrity protection for user plane data exchanged with the UE;

[0748] no use of integrity protection for user plane data exchanged with the UE; or

[0749] use of integrity protection for user plane data and no use of confidentiality protection for user plane data.

[0750] 83. An apparatus for operating a user equipment, UE, configured to connect to a communication network, the apparatus comprising:

[0751] a transmitting module to indicate, to the communication network, an integrity protection for user plane, IPUP, mode supported by the UE when requesting registration with the communication network;

[0752] wherein the IPUP mode comprises one of:

[0753] use of integrity protection for user plane data exchanged with the UE;

[0754] no use of integrity protection for user plane data exchanged with the UE; or

[0755] use of integrity protection for user plane data and no use of confidentiality protection for user plane data.

[0756] 84. An apparatus for operating a radio access node of a communication network, the apparatus comprising:

[0757] a receiving module to receive, from a user equipment, UE, requesting registration with the communication network, an indication of an integrity protection for user plane, IPUP, mode supported by the UE;

[0758] wherein the IPUP mode comprises one of:

[0759] use of integrity protection for user plane data exchanged with the UE;

[0760] no use of integrity protection for user plane data exchanged with the UE; or

[0761] using integrity protection for user plane data and not using confidentiality protection for user plane data;

[0762] and wherein the indication is received from the UE via the communications network.

[0763] 85. An apparatus for operating a radio access node of a communications network, the radio access node comprising a source radio access node, the apparatus comprising:

[0764] a sending module for sending, during a handover of a user equipment, UE, from a source radio access node to a target radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communications network for the UE;

[0765] wherein the IPUP mode comprises one of:

[0766] using integrity protection for user plane data exchanged with the UE;

[0767] not using integrity protection for user plane data exchanged with the UE; or

[0768] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0769] 86. An apparatus for operating a radio access node of a communications network, the radio access node comprising a target radio access node, the apparatus comprising:

[0770] a receiving module for receiving, during a handover of a user equipment, UE, from a source radio access node to a target radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communications network for the UE;

[0771] wherein the IPUP mode comprises one of:

[0772] using integrity protection for user plane data exchanged with the UE;

[0773] not using integrity protection for user plane data exchanged with the UE; or

[0774] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0775] 87. An apparatus for operating a radio access node of a communications network, the radio access node comprising a master radio access node, the apparatus comprising:

[0776] a sending module configured to send, to a secondary radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE;

[0777] wherein the IPUP mode comprises one of:

[0778] using integrity protection for user plane data exchanged with the UE;

[0779] not using integrity protection for user plane data exchanged with the UE; or

[0780] using integrity protection for user plane data and not using confidentiality protection for user plane data,

[0781] and wherein the indication is sent to the secondary radio access node during a procedure for at least one of:

[0782] secondary radio access node addition;

[0783] secondary radio access node modification requiring a key update;

[0784] data radio bearer, DRB, offloading.

[0785] 88. An apparatus for operating a radio access node of a communication network, the radio access node comprising a secondary radio access node, the apparatus comprising:

[0786] a receiving module configured to receive, from a primary radio access node, an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for the UE;

[0787] wherein the IPUP mode comprises one of:

[0788] using integrity protection for user plane data exchanged with the UE;

[0789] not using integrity protection for user plane data exchanged with the UE; or

[0790] using integrity protection for user plane data and not using confidentiality protection for user plane data,

[0791] and wherein the indication is received from the primary radio access node during a procedure for at least one of:

[0792] secondary radio access node addition;

[0793] secondary radio access node modification requiring a key update;

[0794] data radio bearer, DRB, offloading.

[0795] 89. An apparatus for operating a core node in a communication network, the apparatus comprising:

[0796] a sending module for sending, to a radio access node of the communication network, an indication of an integrity protection for user plane (IPUP) mode to be used by the communication network for a user equipment (UE) requesting to register with the communication network;

[0797] wherein the IPUP mode comprises one of:

[0798] using integrity protection for user plane data exchanged with the UE;

[0799] not using integrity protection for user plane data exchanged with the UE; or

[0800] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0801] 90. An apparatus for operating a core node in a communication network, the core network node comprising an old core network node for a user equipment (UE) requesting to register with the communication network, the apparatus comprising:

[0802] a receiving module for receiving, from a new core network for the UE, a request for information related to the UE; and

[0803] a sending module for sending, to the new core network node, an indication of an integrity protection for user plane (IPUP) mode to be used by the communication network for the UE, wherein the IPUP mode comprises one of:

[0804] using integrity protection for user plane data exchanged with the UE;

[0805] not using integrity protection for user plane data exchanged with the UE; or

[0806] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0807] 91. An apparatus for operating a core node in a communication network, the apparatus comprising:

[0808] a receiving module for receiving, from a target radio access node, an indication of an integrity protection for user plane (IPUP) mode to be used by the communication network for a user equipment (UE) being handed over to the target radio access node; and

[0809] a processing module for verifying whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode for the UE stored by the core network node; and

[0810] if there is no match between the indicated IPUP mode and the stored IPUP mode, then performing at least one of:

[0811] recording the mismatch as an event; or

[0812] triggering an alarm;

[0813] wherein the IPUP mode comprises one of:

[0814] using integrity protection for user plane data exchanged with the UE;

[0815] not using integrity protection for user plane data exchanged with the UE; or

[0816] using integrity protection for user plane data and not using confidentiality protection for user plane data.

[0817] 92. An apparatus for operating a core node in a communication network, the apparatus comprising:

[0818] a sending module for sending, to a target radio access node, an indication by the communication network of an integrity protection for user plane, IPUP, mode used by a user equipment, UE, to be handed over to the target radio access node;

[0819] wherein the IPUP mode comprises one of:

[0820] using integrity protection for user plane data exchanged with the UE;

[0821] not using integrity protection for user plane data exchanged with the UE; or

[0822] using integrity protection for user plane data and not using confidentiality protection for user plane data.

Claims

1. A method for operating a radio access node of a communications network, the radio access node comprising a source radio access node, the method comprising: sending, in a handover of a user equipment, UE, from a source radio access node to a target radio access node, an indication of a user plane integrity protection, IPUP, mode that the communications network will use for the UE, the indication being based on one of a network slice type, a network slice identifier, a maximum data rate capability provided by the UE; wherein the IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE; not using integrity protection for user plane data exchanged with the UE; or using integrity protection for user plane data and not using confidentiality protection for user plane data.

2. The method of claim 1, further comprising: checking whether an indication is received from the target radio access node that the target radio access node will enable the IPUP mode that the communications network will use for the UE.

3. The method of claim 2, further comprising: assuming that the target radio access node will not enable the IPUP mode that the communications network will use for the UE, if the indication is not received that the target radio access node will enable the IPUP mode that the communications network will use for the UE.

4. A method for operating a radio access node of a communications network, the radio access node comprising a target radio access node, the method comprising: receiving, in a handover of a user equipment, UE, from a source radio access node to a target radio access node, an indication of a user plane integrity protection, IPUP, mode that the communications network will use for the UE, the indication being based on one of a network slice type, a network slice identifier, a maximum data rate capability provided by the UE; wherein the IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE; not using integrity protection for user plane data exchanged with the UE; or using integrity protection for user plane data and not using confidentiality protection for user plane data.

5. The method of claim 4, wherein the indication of the IPUP mode that the communications network will use for the UE is received from at least one of: the source radio access node; or a core node of the communications network.

6. The method of claim 4 or 5, further comprising: deciding whether to use the indicated IPUP mode; and if it is decided not to use the indicated IPUP mode, sending an indication to the UE that the target radio access node will use a different IPUP mode for the UE than an IPUP mode used by the source radio access node. the indication of the IPUP mode that the communications network will use for the UE being received from the source radio access node, the method further comprising:

7. The method of claim 4 or 5, wherein, sending the indication of the IPUP mode received from the source radio access node to a core node of the communications network.

8. The method of claim 4 or 5, further comprising: ​ if the target radio access node supports the indicated IPUP mode, sending to at least one of the source radio access node or a core node of the communication network an indication that the target radio access node will enable the IPUP mode to be used by the communication network for the UE.

9. The method of claim 4 or 5, further comprising: if the target radio access node does not support the received indicated IPUP mode, performing one of: rejecting the handover of the UE; or accepting the handover of the UE and omitting to send an indication that the target radio access node will enable the IPUP mode to be used by the communication network for the UE.

10. A method for operating a radio access node of a communication network, the radio access node comprising a primary radio access node, the method comprising: sending to a secondary radio access node an indication of an integrity protection for user plane, IPUP, mode to be used by the communication network for a UE, the indication being based on one of a network slice type, a network slice identifier, a maximum data rate capability provided by the UE; wherein the IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE; not using integrity protection for user plane data exchanged with the UE; or using integrity protection for user plane data and not using confidentiality protection for user plane data, and wherein the indication is sent to the secondary radio access node during a procedure for at least one of: secondary radio access node addition; secondary radio access node modification requiring a key update; data radio bearer, DRB, offload.

11. The method of claim 10, wherein, if the IPUP mode indicated to the secondary radio access node involves using integrity protection for user plane data, the indication of the IPUP mode to be used by the communication network for the UE comprises a list of supported algorithms for integrity protection of UP data.

12. The method of claim 10 or 11, further comprising: checking if an indication is received from the secondary radio access node that the secondary radio access node will enable the IPUP mode to be used by the communication network for the UE.

13. The method of claim 12, further comprising: if no indication is received from the secondary radio access node that the secondary radio access node will enable the IPUP mode to be used by the communication network for the UE, assuming that the secondary radio access node will not enable the IPUP mode to be used by the communication network for the UE.

14. The method of claim 10 or 11, further comprising, if the indication of the IPUP mode to be used by the communication network for the UE is sent to the secondary radio access node during a DRB offload procedure: sending to the UE an RRC reconfiguration request comprising the indication of the IPUP mode to be used by the communication network for the UE.

15. The method of claim 14, wherein, the RRC reconfiguration request comprising a selected integrity algorithm identifier to be used for UP integrity protection.

16. A method for operating a radio access node of a communication network, the radio access node comprising a secondary radio access node, the method comprising: receiving, from a master radio access node, an indication of an integrity protection for user plane, IPUP, mode that the communication network will use for the UE, the indication being based on one of a network slice type, a network slice identifier, a maximum data rate capability provided by the UE; wherein the IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE; not using integrity protection for user plane data exchanged with the UE; or using integrity protection for user plane data and not using confidentiality protection for user plane data, and wherein the indication is received from the master radio access node during a procedure for at least one of: secondary radio access node addition; secondary radio access node modification requiring a key update; data radio bearer, DRB, offloading.

17. The method of claim 16, wherein, If the IPUP mode indicated by the master radio access node involves using integrity protection for user plane data, the indication of the IPUP mode that the communication network will use for the UE comprises an identifier of an integrity algorithm to be used for UP integrity protection.

18. The method of claim 16 or 17, further comprising: if the secondary radio access node supports the indicated IPUP mode, sending an indication to the master radio access node that the secondary radio access node will enable the IPUP mode that the communication network will use for the UE.

19. The method of claim 16 or 17, further comprising: if the secondary radio access node does not support the received indicated IPUP mode, performing at least one of: rejecting the requested procedure from the master radio access node; or accepting the requested procedure from the master radio access node and omitting sending an indication to the master radio access node that the secondary radio access node will enable the IPUP mode that the communication network will use for the UE.

20. The method of claim 16 or 17, further comprising: if the indication of the IPUP mode that the communication network will use for the UE is received from the master radio access node during a procedure for secondary radio access node addition, or secondary radio access node modification requiring a key update, and if the IPUP mode indicated by the master radio access node involves using integrity protection for user plane data, deriving and using a key for integrity protection of user plane data exchanged with the UE.

21. A method for operating a core node in a communication network, the method comprising: receiving, from a target radio access node, an indication of an integrity protection for user plane, IPUP, mode that the communication network will use for a user equipment, UE, to be handed over to the target radio access node, the indication being based on one of a network slice type, a network slice identifier, a maximum data rate capability provided by the UE; verifying whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode stored by the core node for the UE; and if there is a mismatch between the indicated IPUP mode and the stored IPUP mode, performing at least one of: logging the mismatch as an event; or sending an indication to the target radio access node that the IPUP mode that the communication network will use for the UE is different from the IPUP mode stored by the core node for the UE. triggering an alarm; wherein the IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE; not using integrity protection for user plane data exchanged with the UE; or using integrity protection for user plane data and not using confidentiality protection for user plane data.

22. A method for operating a core node in a communication network, the method comprising: sending, to a target radio access node, an indication of an integrity protection for user plane, IPUP, mode that the communication network will use for a user equipment, UE, to be handed over to the target radio access node, the indication being based on one of a network slice type, a network slice identifier, a maximum data rate capability provided by the UE; wherein the IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE; not using integrity protection for user plane data exchanged with the UE; or using integrity protection for user plane data and not using confidentiality protection for user plane data.

23. The method of claim 22, further comprising: checking whether an indication is received from the target radio access node that the target radio access node will enable the IPUP mode that the communication network will use for the UE.

24. An apparatus for operating a radio access node of a communication network, the radio access node comprising a source radio access node, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor such that the apparatus is operative to: in a process of handover of a user equipment, UE, from a source radio access node to a target radio access node, send an indication of an integrity protection for user plane, IPUP, mode that the communication network will use for the UE, the indication being based on one of a network slice type, a network slice identifier, a maximum data rate capability provided by the UE; wherein the IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE; not using integrity protection for user plane data exchanged with the UE; or using integrity protection for user plane data and not using confidentiality protection for user plane data.

25. An apparatus for operating a radio access node of a communication network, the radio access node comprising a target radio access node, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor such that the apparatus is operative to: in a process of handover of a user equipment, UE, from a source radio access node to a target radio access node, receive an indication of an integrity protection for user plane, IPUP, mode that the communication network will use for the UE, the indication being based on one of a network slice type, a network slice identifier, a maximum data rate capability provided by the UE; wherein the IPUP mode comprising one of: using integrity protection for user plane data exchanged with the UE; not using integrity protection for user plane data exchanged with the UE; or using integrity protection for user plane data and not using confidentiality protection for user plane data. using integrity protection for user plane data and not using confidentiality protection for user plane data.

26. An apparatus for operating a radio access node of a communication network, the radio access node comprising a primary radio access node, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to operate to: send, to a secondary radio access node, an indication of an integrity protection for user plane (IPUP) mode to be used by the communication network for a UE, the indication based on one of a network slice type, a network slice identifier, a maximum data rate capability provided by the UE; wherein, the IPUP mode comprising one of: using integrity protection for user plane data exchanged with the UE; not using integrity protection for user plane data exchanged with the UE; or using integrity protection for user plane data and not using confidentiality protection for user plane data, and wherein the indication is sent to the secondary radio access node during a procedure for at least one of: secondary radio access node addition; secondary radio access node modification requiring a key update; data radio bearer (DRB) offload.

27. An apparatus for operating a radio access node of a communication network, the radio access node comprising a secondary radio access node, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to operate to: receive, from a primary radio access node, an indication of an integrity protection for user plane (IPUP) mode to be used by the communication network for a UE, the indication based on one of a network slice type, a network slice identifier, a maximum data rate capability provided by the UE; wherein, the IPUP mode comprising one of: using integrity protection for user plane data exchanged with the UE; not using integrity protection for user plane data exchanged with the UE; or using integrity protection for user plane data and not using confidentiality protection for user plane data, and wherein the indication is received from the primary radio access node during a procedure for at least one of: secondary radio access node addition; secondary radio access node modification requiring a key update; data radio bearer (DRB) offload.

28. An apparatus for operating a core node in a communication network, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor to cause the apparatus to operate to: receive, from a target radio access node, an indication of an integrity protection for user plane (IPUP) mode to be used by the communication network for a user equipment (UE) to be handed over to the target radio access node, the indication based on one of a network slice type, a network slice identifier, a maximum data rate capability provided by the UE; verify whether the IPUP mode indicated by the target radio access node is the same as an IPUP mode for the UE stored by the core node; and if there is no match between the indicated IPUP mode and the stored IPUP mode, then performing at least one of: recording the mismatch as an event; or triggering an alarm; wherein the IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE; not using integrity protection for user plane data exchanged with the UE; or using integrity protection for user plane data and not using confidentiality protection for user plane data.

29. An apparatus for operating a core node in a communication network, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor, causing the apparatus to operate for: sending, to a target radio access node, an indication of an integrity protection for user plane, IPUP, mode that the communication network is to use for a user equipment, UE, to be handed over to the target radio access node, the indication being based on one of a network slice type, a network slice identifier, a maximum data rate capability provided by the UE; wherein the IPUP mode comprises one of: using integrity protection for user plane data exchanged with the UE; not using integrity protection for user plane data exchanged with the UE; or using integrity protection for user plane data and not using confidentiality protection for user plane data.

Citation Information

Patent Citations

  • Method and device for protecting data on Un interface

    CN102448058A

  • Methods and Apparatus for Differencitating Security Configurations in a Radio Local Area Network

    US20150319652A1