Relocating access gateway
By relocating the access gateway during UE registration, the problem that access gateways cannot support different network slices in the prior art is solved, and the dynamic adjustment of access gateways and the flexibility of the registration process are realized.
Patent Information
- Application Number
- CN202080099379.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-04-03
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2040-04-03
AI Technical Summary
During the UE registration process, existing technologies cannot effectively relocate the access gateway to support the needs of different network slices, which may result in the selected interoperability function failing to meet the UE's service requirements.
The method of initiating a relocation access gateway during UE registration includes receiving a relocation command from the mobile communication network, determining whether connection is supported, selecting a suitable access gateway, and establishing a connection through a security key to complete the registration process.
This technology enables dynamic adjustment of the access gateway during UE registration, ensuring that the access gateway can support the UE's network slicing requirements and improving the flexibility and success rate of the registration process.
Smart Images

Figure CN115380622B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The subject matter disclosed herein relates generally to relocating an access gateway, e.g., while UE registration is ongoing. BACKGROUND
[0002] The following abbreviations and acronyms are defined herein, at least some of which are referred to herein:
[0003] Third Generation Partnership Project (“3GPP”), Fifth Generation Core (“5GC”), Access and Mobility Management Function (“AMF”), Access Point Name (“APN”), Access Stratum (“AS”), Access Network Information (“ANI”), Application Programming Interface (“API”), Data Network Name (“DNN”), Downlink (“DL”), Enhanced Mobile Broadband (“eMBB”), Evolved Node B (“eNB”), Evolved Packet Core (“EPC”), Evolved UMTS Terrestrial Radio Access Network (“E-UTRAN”), Home Subscriber Server (“HSS”), IP Multimedia Subsystem (“IMS,” also referred to as “IP Multimedia Core Network Subsystem”), Internet Protocol (“IP”), Long Term Evolution (“LTE”), LTE- Advanced (“LTE-A”), Medium Access Control (“MAC”), Mobile Network Operator (“MNO”), Mobility Management Entity (“MME”), Non-Access Stratum (“NAS”), Narrow Band (“NB”), Network Function (“NF”), Network Access Identifier (“NAI”), Next Generation (e.g., 5G) Node B (“gNB”), Next Generation Radio Access Network (“NG-RAN”), New Radio (“NR”), Policy Control Function (“PCF”), Packet Data Network (“PDN”), Packet Data Unit (“PDU”), PDN Gateway (“PGW”), Public Land Mobile Network (“PLMN”), Quality of Service (“QoS”), Radio Access Network (“RAN”), Radio Access Technology (“RAT”), Radio Resource Control (“RRC”), Receive (“Rx”), Single-Network Slice Selection Assistance Information (“S-NSSAI”), Serving Gateway (“SGW”), Session Management Function (“SMF”), Transmission Control Protocol (“TCP”), Transmit (“Tx”), Unified Data Management (“UDM”), User Entity / Equipment (Mobile Terminal) (“UE”), Uplink (“UL”), User Plane (“UP”), Universal Mobile
[0004] In certain embodiments, a UE can connect to a 5G core in a PLMN via several types of non-3GPP access networks, all of which provide IP connectivity between the UE and the 5G core ("5GC") via an access gateway. SUMMARY
[0005] Methods for relocating an access gateway during UE registration are disclosed. Apparatuses and systems also perform the functions of these methods.
[0006] A method of a TNGF, e.g., for relocating an access gateway during UE registration, includes initiating registration of a remote unit with a mobile communication network and receiving a relocation command from an AMF in the mobile communication network while the registration is ongoing. Here, the relocation command contains an address of a first TNGF in the mobile communication network and a first security key. The method includes determining whether a connection with the first TNGF is supported. If the connection with the first TNGF is supported, the method includes sending a first request to the first TNGF, the first request containing a remote unit identity and an AMF identity. However, if the connection with the first TNGF is not supported, the method includes sending a relocation reject message to the AMF.
[0007] Another method of a TNGF, e.g., for relocating an access gateway during UE registration, includes receiving a first request from a first TNGF, the first request containing a remote unit identity and an AMF identity. Here, the first TNGF initiates registration of the remote unit with a mobile communication network. The method includes selecting an AMF in the mobile communication network using the AMF identity and sending a relocation notification message to the AMF, the relocation notification message containing the remote unit identity. Here, the relocation notification message indicates that the registration of the remote unit with the mobile communication network is to be resumed via the sending TNGF. The method includes receiving a second request containing a security key from the AMF in response to sending the relocation notification message, sending a first response to the first TNGF, and establishing a secure connection (e.g., an IPsec SA) with the remote unit by applying the security key.
[0008] A method of an AMF, e.g., for relocating an access gateway during UE registration, includes receiving a first request from a first access gateway, the first request including a first NAS message from a remote unit, the first NAS message initiating registration of the remote unit with a mobile communication network via the first access gateway. The method includes determining to relocate the registration of the remote unit to a second access gateway. Here, the second access gateway is to resume the registration of the remote unit. The method includes sending a relocation command to the first access gateway, the relocation command including an address of the second access gateway, and relocating the registration of the remote unit to the second access gateway in response to sending the relocation command.
[0009] A method for a UE, for example, for relocating an access gateway during UE registration, includes selecting a first N3IWF for registration with a mobile communication network via the first N3IWF and sending a first message to the first N3IWF, the first message containing a NAS message initiating a first registration process with the mobile communication network. The method includes receiving a first response from the first N3IWF and sending a second message to the first N3IWF indicating that the first registration process via the first N3IWF should be stopped. Here, the first response contains the address of a second N3IWF in the mobile communication network and the identity of an AMF. The method includes sending a third message to the second N3IWF and completing the first registration process via the second N3IWF. Here, the third message indicates that the first registration should be relocated to the second N3IWF. Attached Figure Description
[0010] A more specific description of the embodiments briefly described above will be presented with reference to specific embodiments illustrated in the accompanying drawings. It should be understood that these drawings depict only a few embodiments and are therefore not intended to be limiting of the scope. The embodiments will be described and explained using additional specificity and detail through the use of the drawings, in which:
[0011] Figure 1 This is a block diagram illustrating one embodiment of a wireless communication system for relocating an access gateway during UE registration;
[0012] Figure 2A This is a signal flow diagram illustrating one embodiment of the N3IWF relocation process during UE registration;
[0013] Figure 2B yes Figure 2A The continuation of the process described in the text;
[0014] Figure 2C yes Figure 2B The continuation of the process described in the text;
[0015] Figure 3A This is a signal flow diagram illustrating one embodiment of the process used for TNGF relocation during UE relocation;
[0016] Figure 3B yes Figure 3A The continuation of the process described in the text;
[0017] Figure 3C yes Figure 3B The continuation of the process described in the text;
[0018] Figure 4A This is a signal flow diagram illustrating another embodiment of the process used for TNGF relocation during UE relocation, and is... Figure 3A The continuation of the process described in the text;
[0019] Figure 4B is Figure 4A the continuation of the process depicted in
[0020] Figure 5 is a block diagram illustrating one embodiment of a user equipment device for relocating an access gateway during UE registration;
[0021] Figure 6 is a block diagram illustrating one embodiment of a network equipment device for relocating an access gateway during UE registration;
[0022] Figure 7 is a flow diagram illustrating one embodiment of a first method for relocating an access gateway during UE registration;
[0023] Figure 8 is a flow diagram illustrating one embodiment of a second method for relocating an access gateway during UE registration;
[0024] Figure 9 is a flow diagram illustrating one embodiment of a third method for relocating an access gateway during UE registration; and
[0025] Figure 10 is a flow diagram illustrating one embodiment of a fourth method for relocating an access gateway during UE registration. DETAILED DESCRIPTION
[0026] As those skilled in the art will appreciate, the various aspects of the embodiments can be embodied as a system, device, method or program product. Accordingly, the embodiments can take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects that can all generally be referred to herein as a "circuit," "module" or "system."
[0027] For example, disclosed embodiments can be implemented as a hardware circuit comprising custom very large scale integration ("VLSI") circuits or gate arrays, off-the-shelf semiconductors such as logic chips, transistors, or other discrete components. Disclosed embodiments can also be implemented in programmable hardware devices such as field programmable gate arrays, programmable array logic, programmable logic devices or the like. As another example, disclosed embodiments can include one or more physical or logical blocks of executable code, which may, for example, be organized as an object, procedure, or function.
[0028] Furthermore, embodiments can take the form of a program product embodied in one or more computer readable storage devices having stored thereon machine readable code, computer readable code, and / or program code, that when executed by a machine, are capable of causing the machine to carry out levels of the aspects of the embodiments. The machine can be a specially constructed machine, a programmable computer or multiple computers, or a combination of specially constructed and programmed computer hardware and computer software. The storage devices can be tangible, non-transitory and / or non-transmission. The storage devices can not embody signals. In some embodiments, the storage devices only take the form of signals used to access the code.
[0029] Any combination of one or more computer readable medium can be utilized. The computer readable medium can be a computer readable storage medium. The computer readable storage medium can be a storage device storing the code. The storage device can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, holographic, micromechanical, or
[0030] More specific examples (a non-exhaustive list) of the storage device would include the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory ("RAM"), a read-only memory ("ROM"), an erasable programmable read-only memory ("EPROM" or Flash memory), a portable compact disc read-only memory ("CD-ROM"), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of this document, a computer readable storage medium can be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device.
[0031] Reference throughout this specification to "one embodiment", "an embodiment", or similar language means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Thus, appearances of the phrases "in one embodiment", "in an embodiment", and similar language throughout this specification may, but do not necessarily, all refer to the same embodiment, but mean "one or more but not all embodiments". Unless otherwise noted, the terms "including", "comprising", "having" and variations thereof are meant to be broad and encompass the terms "consisting of" and "consisting essentially of". Unless otherwise noted, the list of items does not imply that any or all of the items are mutually exclusive. Unless otherwise noted, the terms "a" and "an" and "the" and similar referents are also meant to be broad and encompass the terms "one or more".
[0032] As used herein, a list with “and / or” includes any single item in the list or a combination of items in the list. For example, a list of A, B and / or C includes only A, only B, only C, a combination of A and B, a combination of B and C, a combination of A and C, or a combination of A, B, and C. As used herein, a list using the terminology “one or more of’ includes any single item in the list or a combination of items in the list. For example, one or more of A, B and C includes only A, only B, only C, a combination of A and B, a combination of B and C, a combination of A and C, or a combination of A, B, and C. As used herein, a list using the terminology “one of’ includes one and only one of any single item in the list. For example, “one of A, B, and C” includes only A, only B, or only C and excludes combinations of A, B, and C. As used herein, “a member selected from the group consisting of A, B, and C” includes one and only one of A, B, or C and excludes combinations of A, B, and C. As used herein, “a member selected from the group consisting of A, B, and C and combinations thereof’ includes only A, only B, only C, a combination of A and B, a combination of B and C, a combination of A and C, or a combination of A, B, and C.
[0033] Furthermore, features, structures or characteristics of the described embodiments can be combined in any suitable manner. In the following description, numerous specific details are provided, such as examples of programming, software modules, user selections, network transactions, database queries, database structures, hardware modules, hardware circuits, hardware chips, etc., to provide a thorough understanding of the embodiments. One skilled in the relevant art will recognize, however, that the embodiments can be practiced without one or more of the specific details, or with other methods, components, materials, and so forth. In other instances, well-known structures, materials, or operations are not shown or described in detail in order to avoid obscuring aspects of the embodiments.
[0034] Aspects of the embodiments are described below with reference to schematic flowcharts and / or schematic block diagrams of methods, apparatuses, systems, and program products according to the embodiments. It will be understood that each block of the schematic flowcharts and / or schematic block diagrams, and combinations of blocks in the schematic flowcharts and / or schematic block diagrams, can be implemented by code. The code can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the
[0035] The code can also be stored in a storage device that can direct a computer, other programmable data processing apparatus, or other devices to function in a particular manner, such that the instructions stored in the storage device produce an article of manufacture including instructions which implement the function / act specified in the schematic flowchart diagrams and / or schematic block diagrams.
[0036] The code can also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other devices to produce a computer implemented process such that the code which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the schematic flowchart diagrams and / or schematic block diagrams.
[0037] The schematic flowcharts and / or schematic block diagrams in the drawings show the architectural, functional, and operational aspects of possible implementations of apparatuses, systems, methods and program products according to various embodiments. In this regard, each block in the schematic flowcharts and / or schematic block diagrams can represent a module, segment, or portion of code, which comprises one or more executable instructions for implementing the specified logical functions.
[0038] It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks can sometimes be executed in the reverse order, depending upon the functionality involved. Other steps and methods can be conceived that are equivalent in function, logic, or effect to those illustrated, with the respect to accomplishing the functionality in a different manner.
[0039] The description of elements in each figure can refer to elements in previous figures. Like reference numbers in all figures indicate like elements, including like reference numbers for alternative embodiments of like elements.
[0040] Methods, apparatuses, and systems for relocating an access gateway during UE registration are disclosed. As specified in current 5G specifications (see, e.g., 3GPP TS 23.501 v16.3.0 and 3GPP TS 23.502 v16.3.0), a UE can connect to a 5G core network in a PLMN through several types of so-called untrusted non-3GPP access networks, which provide connectivity between the UE and the 5G system via a non-3GPP interworking function (“N3IWF”). The N3IWF can be deployed as part of the 5G core. Alternatively, the N3IWF can be deployed as part of the access network. From the 5G core network perspective, these access networks are considered untrusted because they do not support any secure signaling interface or any interworking with the 5G core network. In addition, they are considered non-3GPP access networks because they are based on technologies not specified by 3GPP, such as Wi-Fi access networks and wired access networks, etc.
[0041] In addition, a UE can connect to a 5G core in a PLMN via several types of so-called trusted non-3GPP access networks, all of which provide connectivity between the UE and the 5G system via a trusted non-3GPP gateway function (“TNGF”). The TNGF can be deployed as part of the access network, forming a trusted non-3GPP access network (“TNAN”). From the 5G core network perspective, these access networks are considered trusted because they support a secure signaling interface and interworking with the 5G core network. Such networks are considered non-3GPP access networks because they are based on technologies not specified by 3GPP, such as Wi-Fi access networks and wired line access networks, etc.
[0042] Currently, when a UE registers with a 5G core network in a PLMN via a non-3GPP access network, a single interworking function (e.g., N3IWF or TNGF, also referred to as an “access gateway”) must be selected for this UE (in many deployments already in place) that enables connectivity between the UE and the 5G core network via the non-3GPP access. Because all interworking functions currently provide the same capabilities (e.g., all support connectivity to the same 5G network slices), then the selection of the interworking function is a simple process. Any interworking function can be selected as long as it has sufficient resources to support the UE.
[0043] However, not all interworking functions can provide the same capabilities. For example, different interworking functions can be deployed to provide access to different network slices, each identified by a single network slice selection assistance information (S-NSSAI). Thus, when the 5G core network determines that the initially selected interworking function cannot support the slices allowed for the UE, it can be necessary to relocate the registration of the UE from the initially selected interworking function to a different interworking function.
[0044] Disclosed herein are procedures that enable a UE to register with a 5G core network initially using a first interworking function that is subsequently replaced (i.e., relocated to) a second interworking function, where the registration function is completed via the second interworking, and where the first interworking function is determined to be unsuitable for the UE (e.g., unable to support the allowed slices for the UE). The above-mentioned interworking function can be a N3IWF when the non-3GPP access network is considered “untrusted” by the 5G core network, or a TNGF when the non-3GPP access network is considered “trusted” by the 5G core network.
[0045] Figure 1 A wireless communication system 100 for relocating an access gateway during UE registration in accordance with embodiments of the disclosure is depicted. In one embodiment, the wireless communication system 100 includes at least one remote unit 105, at least one trusted non-3GPP access network (“TNAN”) 120, at least one untrusted non-3GPP access network (“untrusted AN”) 130, and a mobile core network 140 in a PLMN. The TNAN 120 can be composed of at least one base unit 121. The untrusted AN 130 can be composed of at least one base unit 131. The remote unit 105 can communicate with the TNAN 120 using a non-3GPP communication link in accordance with a radio access technology deployed by the TNAN 120. Similarly, the remote unit 105 can communicate with the untrusted AN 130 using a non-3GPP communication link 113 in accordance with a radio access technology deployed by the untrusted AN 130. Although Figure 1 A particular number of remote units 105, base units 110, TNANs 120, untrusted ANs 130, and mobile core networks 140 are depicted in FIG. 1. However, those skilled in the art will recognize that any number of remote units 105, base units 110, TNANs 120, untrusted ANs 130, and mobile core networks 140 can be included in the wireless communication system 100.
[0046] In one implementation, the wireless communication system 100 is compliant with the 5G system specified in the 3GPP specifications. More generally, however, the wireless communication system 100 can implement some other open or proprietary communication network, for example, LTE / EPC (known as 4G) or WiMAX, among other networks. The present disclosure is not intended to be limited to the implementation of any particular wireless communication system architecture or protocol.
[0047] In one embodiment, the remote units 105 can include computing devices, such as desktop computers, laptop computers, personal digital assistants (“PDAs”), tablet computers, smart phones, smart televisions (e.g., televisions connected to the Internet), smart appliances (e.g., appliances connected to the Internet), set-top boxes, game consoles, security systems (including security cameras), vehicle on-board computers, network equipment (e.g., routers, switches, modems), and the like. In some embodiments, the remote units 105 include wearable devices, such as smart watches, fitness bands, optical head-mounted displays, and the like. Moreover, the remote units 105 can be referred to as UEs, subscriber units, mobiles, mobile stations, users, terminals, mobile terminals, fixed terminals, subscriber stations, user terminals, wireless transmit / receive units (“WTRUs”), devices, or by other terminology used in the art.
[0048] The remote units 105 can communicate directly with one or more of the base units 121 in the TNAN 120 via uplink (“UL”) and downlink (“DL”) communication signals. The UL and DL communication signals can also be carried by the communication links 113. Here, the TNAN 120 is an intermediate network that provides the remote units 105 with access to the mobile core network 140, for example, via an IP network 150. Similarly, the remote units 105 can communicate directly with one or more of the base units 131 in the untrusted AN 130 via UL and DL communication signals. The UL and DL communication signals can also be carried by the communication links 113. Here, the untrusted AN 130 is an intermediate network that provides the remote units 105 with access to the mobile core network 140 via an N3IWF and, for example, via an IP network 150.
[0049] The base units 121 and 131 can serve a number of remote units 105 within a serving area, for example, a cell or a cell sector via communication link 113. The base units 121 and 131 can communicate directly with one or more remote units 105 via communication signals. Generally, the base units 121 and 131 transmit DL communication signals to serve the remote units 105 in the time, frequency, and / or spatial domain. Additionally, the DL communication signals can be carried by the communication links 113. The communication links 113 can be any suitable carrier in a licensed or unlicensed radio frequency spectrum band. The communication links 113 facilitate communication between one or more remote units 105 and / or one or more base units 121, 131.
[0050] As described above, the TNAN 120 supports a secure signaling interface and interworking with a 5G core network. The TNAN includes at least one TNGF; in the depicted embodiment, the TNAN 120 includes a first TNGF 125 and a second TNGF 127. In certain embodiments, the TNAN 120 supports a Tn interface between TGNFs in the TNAN 120. Details are described below with reference to Figures 3A-3C Details are described below with reference to Figures 4A-4B Details are described below with reference to
[0051] When a remote unit 105 registers with the mobile communication network 140 via the TNAN 120, the remote unit 105 establishes a “NWt” connection with a serving TNGF (e.g., the TNGF 125 as depicted) and an “N1” connection with the AMF 143 via the TNGF. The serving TNGF establishes an “N2” connection with the AMF 143 and an “N3” connection with the UPF 141. Although Figure 1 The interfaces established via the TNGF 125 are shown, but in other embodiments, these interfaces can be established via the TNGF 127.
[0052] The base units 121 can be distributed over a geographic region. In certain embodiments, the base units 121 can also be referred to as trusted non-3GPP access points (“TNAP”), access terminals, access points, bases, base stations, relay nodes, devices, or by any other terminology used in the art. The base units 121 are generally part of a radio access network (“RAN”), such as the TNAN 120, which can include one or more controllers communicably coupled to one or more corresponding base units 121. These and other elements of radio access network are not illustrated but are commonly known by those skilled in the art. The base units 121 connect to the mobile core network 140 via the TNAN 120.
[0053] Untrusted AN 130 does not support a secure signaling interface or interworking with a 5G core network. Thus, use of N3IWF facilitates access to mobile core network 140 via untrusted AN 130. In the depicted embodiment, system 100 includes a first N3IWF 135 and a second N3IWF 137. Here, N3IWFs 135, 137 can be located in core network 140. In certain embodiments, N3IWFs 135, 137 support connectivity to one or more 5GC networks for UEs that do support NAS protocols and applicable NAS procedures over non-3GPP access. Reference is made below to Figures 2A-2C Details of N3IWF relocation are described.
[0054] When remote unit 105 registers with mobile communication network 140 via untrusted AN 130, remote unit 105 establishes a “NWu” connection with a serving N3IWF (e.g., N3IWF 137, as depicted) and an “N1” connection with AMF 143 via the N3IWF. The serving N3IWF establishes an “N2” connection with AMF 143 and an “N3” connection with UPF 141. While Figure 1 Interfaces shown established via N3IWF 137, in other embodiments these interfaces can be established via N3IWF 135.
[0055] Base units 131 can be distributed over a geographic region. In certain embodiments, base units 131 can also be referred to as access terminals, access points, bases, base stations, relay nodes, devices, or by any other terminology used in the art. Base units 131 are generally part of a radio access network (“RAN”), such as untrusted AN 130, which can include one or more controllers
[0056] In some embodiments, the remote units 105 communicate with application servers (or other communication peers) via network connections with the mobile core network 140. For example, an application (e.g., web browser, media client, telephone / VoIP application) in a remote unit 105 can trigger the remote unit 105 to establish a PDU session (or other data connection) with the mobile core network 140 using the TNAN 120 and / or untrusted AN 130. The mobile core network 140 then relays traffic between the remote unit 105 and an application server in, for example, the IP network 150 using the PDU session. Note that a remote unit 105 can establish one or more PDU sessions (or other data connections) with the mobile core network 140. Thus, a remote unit 105 can have at least one PDU session for communicating with the IP network 150. The remote unit 105 can establish additional PDU sessions for communicating with other data networks and / or other communication peers.
[0057] In one embodiment, the mobile core network 140 is a 5G core (“5GC”) or an evolved packet core (“EPC”), which can be coupled to data networks (e.g., the IP network 150, such as the Internet and private data networks, among other data networks). A remote unit 105 can have a subscription or other account with the mobile core network 140. The present disclosure is not intended to be limited to the implementation of any particular wireless communication system architecture or protocol.
[0058] The mobile core network 140 includes several network functions (“NFs”). As depicted, the mobile core network 140 includes at least one user plane function (“UPF”) 141. The mobile core network 140 also includes multiple control plane functions, including but not limited to an access and mobility management function (“AMF”) 143, a session management function (“SMF”) 145, and a unified data management function (“UDM”) 149. In certain embodiments, the mobile core network 140 can also include a policy control function (“PCF”), an authentication server function (“AUSF”), a network repository function (“NRF”) (used by the various NFs to discover and communicate with each other by APIs), or other NFs defined for a 5G core network.
[0059] In various embodiments, the mobile core network 140 supports different types of mobile data connections and different types of network slices, where each mobile data connection utilizes a particular network slice. Each network slice includes a set of CP and UP network functions, where each network slice is optimized for a certain type of service or traffic class. For ease of illustration, in Figure 1Different network slices are not shown, but their support is assumed. In one example, each network slice includes an SMF and a UPF, but the various network slices share an AMF 143, a PCF, and a UDM 149. In another example, each network slice includes an AMF, an SMF, and a UPF. Although in Figure 1 A specific number and type of network functions are depicted in the mobile core network 140, but one of skill in the art will recognize that any number and type of network functions can be included in the mobile core network 140.
[0060] When a remote unit 105 registers with the mobile core network 140 via a non-3GPP access, a first interworking function (N3IWF 135-137 or TNGF 125-127) is selected. According to previous 3GPP standards, the selected interworking function would be used for the entire duration of the registration procedure. However, to enable replacement (i.e., relocation) of the first interworking function with a second interworking function and resumption of the registration procedure via the second interworking function in the middle of the registration procedure, the AMF 143 can send a relocation command to the first interworking function (i.e., the initially selected interworking function) so that the first interworking function does not complete the registration procedure, but the second interworking function resumes and completes the registration procedure.
[0061] Figures 2A-2C A procedure 200 for relocating an access gateway during UE registration according to embodiments of the disclosure is depicted. The procedure 200 involves a UE 205 (e.g., one embodiment of a remote unit 105), a first N3IWF (“N3IWF-1”) 211, a second N3IWF (“N3IWF-2”) 213, and an AMF 215 in a 5G core network 217. The procedure 300 details the signaling flow for a scenario in which the UE 205 attempts to register with the 5G core network 217 via an untrusted non-3GPP access network 210. Similar steps occur in other scenarios, e.g., when the UE 205 attempts to perform a service request, rather than a registration request. In some embodiments, the N3IWFs 211-213 are part of the 5G core network 217. In some embodiments, the N3IWFs 211-213 are part of the untrusted access network.
[0062] Figure 2A A first network deployment is depicted in which a non-3GPP access network is an untrusted non-3GPP access network 210 and a UE 205 initiates registration with a 5G core network 217 using a first N3IWF (“N3IWF-1”) 211. During registration, the AMF 230 determines that the N3IWF 211 is not suitable and relocates the registration to a second N3IWF (“N3IWF-2”) 213.
[0063] Reference is made to Figure 2A, process 200 begins at step 1 because the UE 205 decides to connect to a particular 5G PLMN via an available non-3GPP access network. The UE 205 is unable to discover a non-3GPP access network that supports 5G connectivity (or “trusted” connectivity) to this 5G PLMN, so it connects to an “untrusted” non-3GPP access network 210 and obtains an IP address (see block 221). At step lb, the UE 205 selects an N3IWF in the 5G PLMN (e.g., N3IWF-1 211) and discovers its IP address (see block 223).
[0064] Subsequently, the UE 205 initiates a registration procedure for untrusted non-3GPP access by starting an Internet Key Exchange (“IKE”) procedure, e.g., as specified in 3GPP TS 23.502 clause 4.12.2.2 (see block 225). Here, the N3IWF is discovered in step lb without taking into account any NSSAI information, so the discovered N3IWF-1 211 can not support the allowed NSSAI for this UE 205 (i.e., the UE 205’s subscription allowed NSSAI) and a different N3IWF can need to be used instead. In other words, the discovered N3IWF-1 211 can need to be relocated. Subsequent steps in this procedure specify how this relocation can be performed. NSSAI is a list of one or more S-NSSAIs. In the depicted embodiment, N3IWF-1 211 supports S-NSSAI-a and S-NSSAI-b, but not S-NSSAI-c. However, N3IWF-2 213 does support S-NSSAI-c.
[0065] At step 2, the UE 205 continues to establish an IPsec Security Association (“IPsec SA”) with the selected N3IWF-1 211 by initiating an IKE initial exchange according to RFC 7296 (see messaging 227).
[0066] At step 3, the UE 205 initiates an IKE AUTH exchange by sending an IKE AUTH request message (see messaging 229). No AUTH payload is included in this IKE AUTH request message, which indicates that the IKE AUTH exchange will use EAP signaling.
[0067] At step 4, the N3IWF-1 211 responds with an IKE AUTH response message that includes an EAP-Request / 5G-Start packet that indicates to the UE 205 that an EAP-5G session is starting and that the UE 205 can start sending NAS messages encapsulated within EAP-5G packets (see messaging 231).
[0068] At step 5, the UE 205 sends an IKE AUTH request to the N3IWF-1 211 (see messaging 233) that includes an EAP-Response / 5G-NAS packet containing access network parameters (AN-Params) and a registration request message (or service request message). The AN-Params contain the UE identity (e.g., SUCI or 5G-GUTI), the selected PLMN identity, the establishment cause, and (optionally) the requested NSSAI. The establishment cause provides the reason for requesting a signaling connection with the 5G core network 217.
[0069] At step 6, the N3IWF-1 211 selects an AMF 215 in the 5G core network 217 of the selected PLMN based on the received AN-Params and local policies, e.g., as specified in 3GPP TS 23.501 clause 6.3.5 (see block 235). In turn, the N3IWF-1 211 forwards the registration request (or service request) received from the UE 205 to the selected AMF 215 within an N2 Initial UE 205 message (see messaging 237). This message contains N2 parameters that include the selected PLMN ID and the establishment cause.
[0070] At step 7, a mutual authentication and key agreement procedure occurs, e.g., as specified in 3GPP TS 33.501 (see messaging 239). At step 8a, the AMF 215 determines the allowed NSSAI for this UE 205 (see block 241), e.g., determines that the UE 205 is allowed to use S-NSSAI-c. This can be determined by using the UE 205 subscription data received from the UDM.
[0071] Continuing Figure 2B At step 8b, the AMF 215 also determines that the N3IWF-1 211 does not support S-NSSAI-c, which is allowed for the UE 205, but there is another N3IWF (N3IWF-2 213) connected to the same AMF 215 that supports S-NSSAI-c (see block 243). Note that, as specified in 3GPP TS 38.413, when an N3IWF sets up an N2 connection with an AMF 215, the N3IWF indicates the list of supported S-NSSAIs. In this way, the AMF 215 knows the list of S-NSSAIs supported by each N3IWF connected to the AMF 215.
[0072] In the depicted procedure, it is assumed that the selected AMF 215 supports the allowed S-NSSAI-c for the UE 205, so no AMF 215 relocation is needed. However, if AMF 215 relocation is needed, AMF 215 relocation is performed before N3IWF relocation performed below (based on procedures specified in 3GPP TS 23.502).
[0073] At step 9, the AMF 215 sends an N3IWF relocation command to N3IWF-1 211 (see messaging 245). In this message, the AMF 215 includes the address of N3IWF-2 213 (which should be used for this UE 205 instead of N3IWF-1 211) and the AMF 215 identity, e.g., a globally unique AMF 215 identifier (GUAMI) or an IP address of the AMF 215. In some embodiments, the N3IWF relocation command also contains a security mode control (SMC) request message (i.e., a security mode command message) in order to establish a NAS security context for this UE 205 and further protect NAS messages. N3IWF-1 211 forwards the received SMC request message within an EAP 5G-NAS packet, the N3IWF-2 213 address, and the AMF 215 identity to the UE 205 (see messaging 247). Note that in alternative embodiments, e.g., when no SMC procedure is performed, the N3IWF relocation command does not contain an SMC request or any other NAS message.
[0074] At step 10, because the UE 205 receives the N3IWF address in step 9b, the UE 205 determines that another N3IWF should be selected. Thus, the UE 205 sends an EAP 5G-Stop packet (see messaging 249), which (as specified in 3GPP TS 24.502) triggers N3IWF-1 211 to terminate the ongoing IKE procedure by sending an IKE_INFORMATIONAL request message containing an EAP-Failure and an appropriate error cause (see messaging 251).
[0075] After this step, N3IWF-1 211 can release the N2 connection with the AMF 215. However, because the release of the N2 connection can impact the ongoing UE registration procedure, N3IWF-1 211 can delay the release of the N2 connection with the AMF 215, or can wait until another N2 connection has been established by N3IWF-2 213 with the AMF 215 and the N2 connection can be released from the AMF 215 and the UE registration procedure can be resumed.
[0076] At step 11-12, the UE 205 starts to establish a NWu connection with the N3IWF address received in step 9b. First, the UE 205 initiates a new IKE procedure towards N3IWF-2 213 (see block 253), thus repeating steps 2, 3, 4 (here labelled steps 11, 12a, 12b), but now between the UE 205 and N3IWF-2 213 (see messaging 255, 257, and 259).
[0077] At step 13, the UE 205 sends an IKE_AUTH request to N3IWF-2 213 (see messaging 261) including an EAP-Response / 5G-NAS packet containing the AN-Params and the SMC Complete message (i.e., Security Mode Complete), which is a response to the SMC Request message received in step 9b. In alternative embodiments, e.g., when the SMC procedure is not performed, the EAP packet sent by the UE 205 does not contain the SMC response or any other NAS message.
[0078] The AN-Params contain the UE identity (e.g., SUCI or 5G-GUTI), the establishment cause, (optionally) the requested NSSAI, and the AMF 215 identity received in step 9b. The presence of the AMF 215 identity in this message indicates to the N3IWF-2 213 that this message is sent to trigger a relocation to N3IWF-2 213. Alternatively, the establishment cause can contain a value that indicates to the N3IWF-2 213 that this message is sent to trigger a relocation to N3IWF-2 213.
[0079] Although the UE 205 reconnects to the new N3IWF, the NAS registration procedure between the UE 205 and the AMF 215 is resumed via the new N3IWF (i.e., N3IWF-2 213). Importantly, the registration procedure is not restarted due to the N3IWF relocation.
[0080] Continuing Figure 2C At step 14, the N3IWF-2 213 selects the same AMF 215 based on the received AMF 215 identity (see block 263) and sends an N3IWF relocation notification message to the AMF 215 (see messaging 265). In some embodiments, the N3IWF-2 213 forwards the SMC Complete message within the N3IWF relocation notification message to the AMF 215. In alternative embodiments, e.g., when the SMC procedure is not performed, the N3IWF relocation notification does not contain the SMC Complete or any other NAS message.
[0081] The N3IWF relocation notification message contains the UE identity, enabling the AMF 215 to identify the appropriate UE context (e.g., to associate the received SMC complete message with the UE 205) and resume the ongoing registration procedure for this UE 205. The N3IWF relocation notification message creates a new N2 connection associated with the UE 205. Here, the N3IWF-2 213 decides to send the N3IWF relocation notification message to the AMF 215 (instead of the initial UE 205 message) because it determines that the message in step 13 was sent to trigger a relocation to the N3IWF-2 213.
[0082] After the AMF 215 receives the N3IWF relocation notification from the N3IWF-2 213, the AMF 215 can have two different N2 connections associated with the same UE 205: one with the N3IWF-1 211 set up in step 6b, and another with the N3IWF-2 213 set up in step 14b. Therefore, the AMF 215 expects to release the N2 connection with the N3IWF-1 211, which is no longer needed. The messages exchanged for releasing this N2 connection are not shown in Figure 2C
[0083] Here, the AMF 215 ignores the N3IWF relocation notification if it has not previously sent the N3IWF relocation command for this UE 205.
[0084] At step 15, the AMF 215 sends an initial context setup request to the N3IWF-2 213 in order to set up a secure connection with the UE 205 (see messaging 267). This message includes the N3IWF key to be applied for authenticating the UE 205. In response, the N3IWF-2 213 sends an EAP-Success packet to the UE 205 within an IKE AUTH response, which ends the EAP-5G session initiated in step 12b (see messaging 269).
[0085] At step 18, IKE AUTH request / response messages are exchanged, but this time with an AUTH payload that is derived based on the common N3IWF key created in the UE 205 and 5GC network (see messaging 271 and 273). Here, the UE identity (e.g., SUCI or 5G-GUTI) received by N3IWF-2 213 in step 18a indicates to N3IWF-2 213 which N3IWF key should be used (i.e., the one received in step 15a) to authenticate the UE 205. After successful authentication in step 18, a secure IPsec SA is created between the UE 205 and N3IWF-2 213. At step 19, the UE 205 establishes a TCP connection with N3IWF-2 213 (e.g., as specified in 3GPP TS 23.502), which completes the establishment of the NWu connection between the UE 205 and N3IWF-2 213 (see messaging 275).
[0086] At step 20, after the NWu connection is established between the UE 205 and N3IWF-2 213, N3IWF-2 213 responds to the AMF 215 with an Initial Context Setup Response message, which indicates that a secure connection with the UE 205 has been established (see messaging 277). At step 21, the AMF 215 sends a DL NAS transport containing a Registration Accept message for the UE 205 to N3IWF-2 213 (see messaging 279). At step 22, the Registration Accept message is forwarded to the UE 205 within the established NWu connection (see messaging 281).
[0087] After the above signaling flow, the registration of the UE with the 5G core network 217 is complete and the initially selected N3IWF-1 211 is relocated to N3IWF-2 213, which supports the allowed NSSAI for the UE 205.
[0088] Figures 3A-3CA procedure 300 for relocating an access gateway during UE registration is depicted in accordance with embodiments of the present disclosure. The procedure 300 involves a UE 205 (e.g., one embodiment of the remote unit 105), a first TNGF (“TNGF-1”) 311, a second TNGF (“TNGF-2”) 313, and an AMF 215 in a 5G core network 217. The procedure 300 details a signaling flow for a modified registration procedure for a scenario in which the UE 205 attempts to register with the 5G core network 217 via a trusted non-3GPP access network. Here, the trusted non-3GPP access network supports connectivity (e.g., a “Tn” interface) between the TNGF-1 311 and the TNGF-2 313. Similar steps occur in other scenarios, e.g., when the UE 205 attempts to perform a service request, rather than a registration request.
[0089] Figure 3A A second network deployment is depicted in which the non-3GPP access network is a trusted non-3GPP access point 210 and the UE 205 initiates registration with the 5G core network 217 using a first TNGF (“TNGF-1”) 217. During registration, the AMF 230 determines that the TNGF-1 217 is not suitable and relocates the registration to a second TNGF (“TNGF-2”) 219. Details of TNGF relocation are described below with respect to Figure 4A -4C.
[0090] Referring to Figure 3A , the procedure 300 begins with the UE 205 deciding to connect to a particular 5G PLMN via an available non-3GPP access network. The UE 205 discovers a non-3GPP access network that supports 5G connectivity (or “trusted” connectivity) to this 5G PLMN, so it selects this “trusted” non-3GPP access network and initiates a trusted non-3GPP access registration procedure, e.g., as specified in 3GPP TS 23.502 clause 4.12a.2.2. In the most typical case, the trusted non-3GPP access network is a WLAN access network that complies with the IEEE 802.11 specification.
[0091] At step 1, the UE 205 establishes a layer-2 (L2) connection with a trusted non-3GPP access point (TNAP) 310 in the trusted non-3GPP access network (see messaging 321). In the case of an IEEE 802.11 WLAN, this L2 connection corresponds to an 802.11 association.
[0092] At step 2-3, the EAP procedure is initiated. EAP messages are encapsulated into layer 2 packets, e.g., IEEE 802.11 / 802. lx packets. The TNAP 310 requests a UE identity and the UE 205 sends a Network Access Identifier (“NAI”) as a response (see messaging 323, 325). The NAI provided by the UE 205 indicates that the UE 205 requests a “5G connection” to a specific PLMN, e.g., NAI = “<any_username>@nai.5gc.mnc <mnc>.mcc <mcc>.3gppnetwork.org”. This NAI triggers the TNAP 310 to select a TNGF (here, TNGF-1 311, see block 327) and send an AAA request to the selected TNGF (see messaging 329). Between the TNAP 310 and the TNGF-1 311, each EAP packet is encapsulated into an AAA message.
[0093] Here, the TNGF-1 311 is selected in step 3b without taking into account any NSSAI information, and thus, the selected TNGF-1 311 can not support the allowed NSSAI for this UE 205 (i.e., the NSSAI allowed by the subscription of the UE 205) and can instead need to use a different TNGF. In other words, the selected TNGF-1 311 can need to be relocated. Subsequent steps in this procedure specify how this relocation can be performed. In the depicted embodiment, the TNGF-1 311 supports S-NSSAI-a and S-NSSAI-b, but not S-NSSAI-c. However, the TNGF-2 313 does support S-NSSAI-c.
[0094] At step 4, the TNGF-1 311 responds with an AAA response message (see messaging 331) that includes an EAP-Request / 5G-Start packet indicating to the UE 205 that the EAP-5G session starts and that the UE 205 can start sending NAS messages encapsulated within EAP-5G packets.
[0095] At step 5, the UE 205 sends an EAP-Response / 5G-NAS packet containing access network parameters (AN-Params) and a registration request message (or service request message, see messaging 333). The AN-Params contain the UE identity (e.g., SUCI or 5G-GUTI), the selected PLMN identity, and the establishment cause. Optionally, if the UE 205 is not operating in default NSSAI inclusion mode D (specified in 3GPP TS 23.502), the requested NSSAI can also be included. The establishment cause provides the reason for requesting a signaling connection with the 5G core network 217. The TNAP 310 forwards the EAP-Response / 5G-NAS packet within an AAA request message to the TNGF-1 311.
[0096] At step 6, TNGF-1 311 selects an AMF 215 in the 5G core network 217 of the selected PLMN based on the received AN-Params and local policies, e.g., as specified in 3GPP TS 23.501 clause 6.3.5 (see block 335). In turn, TNGF-1 311 forwards the registration request (or service request) received from UE 205 to the selected AMF 215 within an N2 Initial UE 205 message (see messaging 337). This message contains N2 parameters, which include the selected PLMN ID and establishment cause.
[0097] At step 7, a mutual authentication and key agreement procedure occurs, e.g., as specified in 3GPP TS 33.501 (see messaging 339). At step 8a, the AMF 215 determines the allowed NSSAI for this UE 205 (see block 341), e.g., determines that the UE 205 is allowed to use S-NSSAI-c. This can be determined by using the UE 205 subscription data received from the UDM.
[0098] Continuing Figure 3B At step 8b, the AMF 215 also determines that TNGF-1 311 does not support S-NSSAI-c, which is allowed for the UE 205, but there is another TNGF (TNGF-2 313) connected to the same AMF 215 that supports S-NSSAI-c (see block 343). Note that when a TNGF sets up an N2 connection with an AMF 215, the TNGF indicates a list of supported S-NSSAIs, as specified in 3GPP TS 38.413. In this way, the AMF 215 knows the list of supported S-NSSAIs for each TNGF connected to the AMF 215.
[0099] Here, it is assumed that the selected AMF 215 supports the allowed S-NSSAI-c for the UE 205, so no AMF 215 relocation is needed. However, if AMF 215 relocation is needed, then AMF 215 relocation is performed prior to the TNGF relocation performed below (based on procedures specified in 3GPP TS 23.502).
[0100] At step 9, the AMF 215 sends a TNGF relocation command to TNGF-1 311 (see messaging 345). In this message, the AMF 215 includes the TNGF key and the address of TNGF-2 313, which should be used for this UE 205 instead of TNGF-1 311. In some embodiments, the TNGF relocation command also contains a Security Mode Control (SMC) request message (i.e., a Security Mode Command message) in order to establish a NAS security context for this UE 205 and protect further NAS messages.
[0101] At step 10, TNGF-1 311 forwards the received SMC request message and the TNGF-2 313 address within the EAP 5G-NAS packet to the UE 205 (see messaging 347). Note that in alternative embodiments, e.g., when no SMC procedure is performed, the TNGF relocation command does not contain an SMC request or any other NAS message. The TNGF-2 313 address indicates to the UE 205 the address at which the NWt connection should be established. The TNAP key is derived by TNGF-1 311 using the TNGF key in step 15a.
[0102] At step 11, the UE 205 sends an EAP-Response / 5G-NAS packet containing an SMC complete message (i.e., Security Mode Complete), which is a response to the received SMC request message (see messaging 349). This packet is forwarded to TNGF-1 311.
[0103] At step 12, because TNGF-1 311 received the TNGF relocation command in step 9a, TNGF-1 311 determines that the UE 205 should be relocated to TNGF-2 313. Therefore, TNGF-1 311 forwards the received SMC response message to TNGF-2 313 by sending a Tn request message to TNGF-2 313 (see messaging 351). In alternative embodiments, e.g., when no SMC procedure is performed, the Tn request message does not contain an SMC request or any other NAS message.
[0104] The Tn request message contains the UE identity (SUCI or 5G-GUTI) received in step 5b and the AMF 215 identity, e.g., a Global Unique AMF 215 Identifier (GUAMI) or an IP address of the AMF 215. If the AMF 215 identity is a GUAMI, then it is provided to TNGF-1 311, e.g., with the TNGF relocation command in step 9a.
[0105] At step 13, TNGF-2 313 selects the same AMF 215 based on the received AMF 215 identity (see block 353) and forwards the SMC complete message to the AMF 215 within a TNGF relocation notification message (see messaging 355). In alternative embodiments, e.g., when no SMC procedure is performed, the TNGF relocation notification does not contain a SMC complete or any other NAS message.
[0106] The TNGF relocation notification message contains the UE identity, enabling the AMF 215 to associate it with the appropriate UE 205 context and resume the ongoing registration procedure for this UE 205. The TNGF relocation notification message creates a new N2 connection associated with this UE 205.
[0107] After the AMF 215 receives the TNGF relocation notification message from TNGF-2 313, the AMF 215 has two different N2 connections associated with the same UE 205: one with TNGF-1 311 set up in step 6b and the other with TNGF-2 313 set up in step 13b. Therefore, the AMF 215 is expected to release the N2 connection with TNGF-1 311, which is no longer needed. The messages exchanged for releasing this N2 connection are not shown in Figure 3B Here, if the AMF 215 has not previously sent a TNGF relocation command for this UE 205, it ignores the TNGF relocation notification.
[0108] At step 14, the AMF 215 sends an initial context setup request to TNGF-2 313 in order to (a) enable the EAP-5G session to complete and (b) enable the NWt connection to be established between the UE 205 and TNGF-2 313 (see messaging 357). This message includes the TNGF keys that TNGF-2 313 also needs. In response, TNGF-2 313 sends a Tn response to TNGF-1 311 (see messaging 359).
[0109] At Figure 3C Continuing, TNGF-2 313 waits for UE 205 to start establishing the NWt connection (see block 361). At step 15, TNGF-1 311 derives the TNAP key from the TNGF key (see block 363) and sends an EAP-Success packet to UE 205 within the AAA accept, which ends the EAP-5G session initiated in step 4 (see messaging 365). The AAA accept also includes the TNAP key, which should be used to establish air interface security with UE 205. Here, TNGF-1 311 can not perform steps 15a and 15b after receiving the Tn Response (as shown in the figure) but after receiving this message in step lib.
[0110] At step 16, using the TNAP key (which is also derived by UE 205 from the TNGF key), UE 205 and TNAP establish air interface security (see messaging 367). In the case of an IEEE 802.11 WLAN, this corresponds to the 4-way handshake exchange. Subsequently, UE 205 obtains IP configuration information, including an IP address.
[0111] At step 18, UE 205 starts establishing the NWt connection with the received TNGF-2 313 address (see block 371). First, UE 205 initiates the IKE procedure towards TNGF-2 313 by starting the IKE initial exchange according to RFC 7296 (see messaging 373). Then, the IKE_AUTH request / response messages are exchanged using the AUTH payload, which is derived based on the common TNGF key created in UE 205 and the 5GC network (see messaging 375 and 377). Here, the UE identity (e.g., SUCI or 5G-GUTI) received by TNGF-2 313 in step 18b indicates to TNGF-2 313 which TNGF key should be used to authenticate UE 205 (i.e., the one received in step 15a). After successful authentication in step 18, a secure IPsec SA is created between UE 205 and TNGF-2 313.
[0112] At step 19, UE 205 establishes a TCP connection with TNGF-2 313 (as specified in 3GPP TS 23.502), which completes the establishment of the NWt connection between UE 205 and TNGF-2 313 (see messaging 379).
[0113] At step 20, after the NWt connection between the UE 205 and the TNGF-2 313 is established, the TNGF-2 313 responds to the AMF 215 with an Initial Context Setup Response message indicating that a secure connection with the UE 205 has been established (see messaging 381).
[0114] At step 21, the AMF 215 sends a DL NAS Transport containing a Registration Accept message for the UE 205 to the TNGF-2 313 (see messaging 383). At step 22, the Registration Accept message is forwarded to the UE 205 within the established NWt connection (see messaging 385).
[0115] After the above signaling flow, the registration of the UE with the 5G core network 217 is completed and the initially selected TNGF-1 311 is relocated to the TNGF-2 313 that supports the allowed NSSAI for the UE 205.
[0116] Figures 4A-4B A procedure 400 for relocating an access gateway during UE registration is depicted in accordance with embodiments of the present disclosure. The procedure 400 involves a UE 205 (e.g., one embodiment of the remote unit 105), a TNGF-1 311, a TNGF-2 313, and an AMF 215 in a 5G core network 217. The procedure 400 details a scenario for a UE 205 attempting to register with the 5G core network 217 via a trusted non-3GPP access network. However, the TNAN 215 does not support a connection between the TNGF-1 311 and the TNGF-2 313 (e.g., does not support a "Tn" interface). Similar steps occur in other scenarios, e.g., when the UE 205 attempts to perform a service request instead of a registration request. Note, Figure 4A is Figure 3A a continuation of
[0117] Referring to Figure 4A , the procedure 400 begins after the UE 205 and the TNGF-1 311 initiate a registration in the 5G core network 217 and the AMF 215 has determined an allowed NSSAI (see, e.g., step 8a of Figure 3A .
[0118] At step 8b, the AMF 215 determines that TNGF-1 311 does not support S-NSSAI-c, which is not allowed for the UE 205, but there is another TNGF (TNGF-2 313) connected to the same AMF 215 that supports S-NSSAI-c (see block 401). Note that, as specified in 3GPP TS 38.413, when a TNGF sets up an N2 connection with the AMF 215, the TNGF indicates the list of supported S-NSSAIs. In this way, the AMF 215 knows the list of supported S-NSSAIs for each TNGF connected to the AMF 215.
[0119] In the depicted embodiment, it is assumed that the selected AMF 215 supports the allowed S-NSSAI-c for the UE 205, so no AMF 215 relocation is needed. However, if AMF 215 relocation is needed, the AMF 215 relocation is performed before the TNGF relocation performed below (based on the procedures specified in 3GPP TS 23.502).
[0120] At step 9, the AMF 215 sends a TNGF relocation command to TNGF-1 311 (see messaging 403). In this message, the AMF 215 includes the TNGF key and the address of TNGF-2 313, which should be used for this UE 205 instead of TNGF-1 311. In some embodiments, the TNGF relocation command also contains a Security Mode Control (SMC) Request message (i.e., a Security Mode Command message) in order to establish the NAS security context for this UE 205 and protect further NAS messages.
[0121] At step 10, TNGF-1 311 forwards the received SMC Request message and the TNGF-2 313 address to the UE 205 within an EAP 5G-NAS packet (see messaging 405). Note that, in alternative embodiments, the TNGF relocation command does not contain an SMC Request or any other NAS message, e.g., when no SMC procedure is performed. The TNGF-2 313 address indicates to the UE 205 the address at which the NWt connection should be established. The TNAP key is derived by TNGF-1 311 using the TNGF key in step 15a.
[0122] At step 11, the UE 205 sends an EAP-Response / 5G-NAS packet containing an SMC Complete message (i.e., Security Mode Complete), which is a response to the received SMC Request message (see messaging 407). This packet is forwarded to TNGF-1 311.
[0123] At step 12, because TNGF-1 311 does not support the Tn interface with TNGF-2 313, TNGF-1 311 forwards the SMC Response message to the AMF 215 within a TNGF relocation reject message (see messaging 409). In alternative embodiments, e.g., when the SMC procedure is not performed, the TNGF relocation reject does not contain the SMC Complete or any other NAS message. Upon receiving the TNGF relocation reject message from TNGF-1 311, the AMF 215 determines that the Tn interface is not supported. This triggers the AMF 215 to perform the following step 17.
[0124] At step 15, TNGF-1 311 derives the TNAP key from the TNGF key (see block 411) and sends an EAP-Success packet to the UE 205 within a AAA Accept, which ends the EAP-5G session initiated in step 4 (see messaging 413). The AAA Accept also includes the TNAP key, which should be used to establish the air interface security with the UE 205.
[0125] At step 16, using the TNAP key (which is also derived by the UE 205 from the TNGF key), the UE 205 and the TNAP establish the air interface security (see messaging 415). In the case of an IEEE 802.11 WLAN, this corresponds to the 4-way handshake exchange. Subsequently, the UE 205 obtains IP configuration information, including an IP address (see messaging 417).
[0126] Continuing at Figure 4B step 17, because the AMF 215 determined (in step 12) that the Tn interface is not supported, the AMF 215 sends an Initial Context Setup Request to TNGF-2 313 in order to be able to establish the NWt connection between the UE 205 and TNGF-2 313 (see messaging 419). This message includes the TNGF key that should be used to authenticate the UE 205 and the UE identity (e.g., SUCI or 5G-GUTI). In response, TNGF-2 313 waits for the UE 205 to start establishing the NWt connection (see block 421).
[0127] After the AMF 215 sends the Initial Context Setup Request to TNGF-2 313, the AMF 215 has two different N2 connections associated with the same UE 205: one with TNGF-1 311 set up in step 6b, and the other with TNGF-2 313 set up in step 17. Therefore, the AMF 215 is expected to release the N2 connection with TNGF-1 311, which is no longer needed. The messages exchanged to release this N2 connection are not shown in Figure 4B FIG. 4.
[0128] At step 18, the UE 205 starts establishing a NWt connection with the TNGF-2 313 address received in step 9c (see messaging 423, 425, and 427). At step 19, the UE 205 establishes a TCP connection with the TNGF-2 313 (as specified in 3GPP TS 23.502), which completes the establishment of the NWt connection between the UE 205 and the TNGF-2 313 (see messaging 429). Details of establishing the NWt connection are discussed above with reference to Figure 3C FIG. 3.
[0129] At step 20, after the NWt connection between the UE 205 and the TNGF-2 313 is established, the TNGF-2 313 responds to the AMF 215 with an Initial Context Setup Response message indicating that a secure connection with the UE 205 has been established (see messaging 431). At step 21, the AMF 215 sends a DL NAS transport containing a Registration Accept message for the UE 205 to the TNGF-2 313 (see messaging 433). At step 22, the Registration Accept message is forwarded to the UE 205 within the established NWt connection (see messaging 435).
[0130] After the signaling flow described above, the registration of the UE with the 5G core network 217 is completed and the initially selected TNGF-1 311 is relocated to the TNGF-2 313 that supports the allowed NSSAI for the UE 205.
[0131] Figure 5 One embodiment of a user equipment apparatus 500 that can be used to relocate an access gateway during UE registration in accordance with embodiments of the present disclosure is depicted. The user equipment apparatus 500 can be one embodiment of the remote unit 105 and / or the UE 205. Furthermore, the user equipment apparatus 500 can include a processor 505, a memory 510, an input device 515, an output device 520, and a transceiver 525. In some embodiments, the input device 515 and the output device 520 are combined into a single device, such as a touch screen. In certain embodiments, the user equipment apparatus 500 can not include any input device 515 and / or output device 520.
[0132] As depicted, the transceiver 525 includes at least one transmitter 530 and at least one receiver 535. Here, the transceiver 525 communicates with a mobile core network (e.g., 5GC) via an access network. Further, the transceiver 525 can support at least one network interface 540. Here, the at least one network interface 540 facilitates communications with a non-3GPP access point (e.g., using a "NWu" or "NWt" interface). Additionally, the at least one network interface 540 can include interfaces for communicating with an AMF, SMF, and / or UPF.
[0133] In one embodiment, the processor 505 can include any known controller capable of executing computer-readable instructions and / or capable of performing logical operations. For example, the processor 505 can be a microcontroller, a microprocessor, a central processing unit ("CPU"), a graphics processing unit ("GPU"), an auxiliary processing unit, a field programmable gate array ("FPGA"), or similar programmable controller. In some embodiments, the processor 505 executes instructions stored in the memory 510 to perform methods and routines described herein. The processor 505 is communicatively coupled to the memory 510, the input device 515, the output device 520, and the transceiver 525.
[0134] In various embodiments, the processor 505 controls the user equipment 500 to implement the UE behaviors described above. In some embodiments, the processor 505 selects a first N3IWF for registration with a mobile communication network via the first N3IWF. The above discussion with reference to Figure 2A selects a first N3IWF (see step lb). The processor 505 sends, to the first N3IWF, a first message that initiates a first registration procedure with the mobile communication network. Here, the first message can contain a NAS message, such as a registration request message, as discussed above with reference to Figure 2A
[0135] The processor 505 receives, via the transceiver 525, a first response from the first N3IWF. Here, the first response contains an address of a second N3IWF and an identity of an AMF (AMF-Id) in the mobile communication network, as discussed above with reference to Figure 2A selects a first N3IWF (see step lb). The processor 505 sends, to the first N3IWF, a first message that initiates a first registration procedure with the mobile communication network. Here, the first message can contain a NAS message, such as a registration request message, as discussed above with reference to Figure 2A
[0136] The processor 505 sends a third message to the second N3IWF. Here, the third message indicates that the first registration is to be relocated to the second N3IWF. In certain embodiments, the indication in the third message is a combination of the AMF-Id and / or a specific establishment cause (i.e., “relocation”). The processor 505 completes the first registration procedure via the second N3IWF, as discussed above with reference to Figure 2A (see steps 15-21).
[0137] In some embodiments, the first message includes an identity of the mobile communication network (i.e., a selected PLMN ID) and an establishment cause, as discussed above with reference to Figure 2A (see step 5). In certain embodiments, the establishment cause indicates that the first registration is to be relocated to the second N3IWF. In some embodiments, the first response is received after mutual authentication and key agreement, as discussed above with reference to Figure 2A (see step 7). In some embodiments, the third message includes a second NAS message that resumes the first registration procedure via the second N3IWF. In various embodiments, the first NAS message includes a registration request, where the second NAS message includes an SMC complete message.
[0138] In some embodiments, the third message contains an identity of the AMF, where the identity of the AMF indicates that the first registration is to be relocated to the second N3IWF, and where the identity of the AMF is used by the second N3IWF to select the same AMF selected by the first N3IWF. In some embodiments, completing the registration with the mobile communication network via the second N3IWF includes establishing a NWu connection with the second N3IWF and receiving a registration accept via the established NWu connection.
[0139] In one embodiment, the memory 510 is a computer readable storage medium. In some embodiments, the memory 510 includes both volatile and nonvolatile computer storage media. In some embodiments, the memory 510 stores data relating to relocating an access gateway during UE registration, for example storing security keys, IP addresses, etc. In certain embodiments, the memory 510 also stores program code and related data, such as an operating system (“OS”) or other controller algorithms and one or more software applications that run on the user equipment device 500.
[0140] In one embodiment, input device 515 can include any known computer input device, including a touch panel, buttons, a keyboard, a stylus, a microphone, or the like. In some embodiments, input device 515 can be integrated with output device 520, e.g., as a touch screen or similar touch-sensitive display. In some embodiments, input device 515 includes a touch screen such that text can be input using a virtual keyboard displayed on the touch screen and / or by handwriting on the touch screen. In some embodiments, input device 515 includes two or more different devices, such as a keyboard and a touch panel.
[0141] In one embodiment, output device 520 can include any known electronically controllable display or display device. Output device 520 is designed to output visual, audible, and / or tactile signals. In some embodiments, output device 520 includes an electronic display capable of outputting visual data to a user. For example, output device 520 can include, but is not limited to, an LCD display, an LED display, an OLED display, a projector, or similar display device capable of outputting images, text, etc., to a user. As another, non-limiting, example, output device 520 can include a wearable display such as a smart watch, smart glasses, a heads-up display, or the like. Further, output device 520 can be a component of a smart phone, a personal digital assistant, a television, a table computer, a notebook (laptop) computer, a personal computer, a vehicle dashboard, or the like.
[0142] In certain embodiments, output device 520 includes one or more speakers for producing sound. For example, output device 520 can produce an audible alert or notification (e.g., a beep or chime). In some embodiments, output device 520 includes one or more haptic devices for producing vibrations, motion, or other haptic feedback. In some embodiments, all or portions of output device 520 can be integrated with input device 515. For example, input device 515 and output device 520 can form a touch screen or similar touch-sensitive display. In other embodiments, all or portions of output device 520 can be located near input device 515.
[0143] As discussed above, transceiver 525 communicates with one or more network functions of a mobile communication network via one or more access networks. Transceiver 525 operates under the control of processor 505 to transmit and to receive messages, data, and other signals. For example, processor 505 can selectively activate the transceiver (or portions thereof) at particular times in order to send and to receive messages.
[0144] The transceiver 525 can include one or more transmitters 530 and one or more receivers 535. Although only one transmitter 530 and one receiver 535 are illustrated, the user equipment apparatus 500 can have any suitable number of transmitters 530 and receivers 535. Further, the transmitter(s) 530 and the receiver(s) 535 can be any suitable type of transmitters and receivers. In one embodiment, the transceiver 525 includes a first transmitter / receiver pair for communicating with a mobile communication network over licensed radio spectrum and a second transmitter / receiver pair for communicating with a mobile communication network over unlicensed radio spectrum.
[0145] In certain embodiments, the first transmitter / receiver pair for communicating with a mobile communication network over licensed radio spectrum and the second transmitter / receiver pair for communicating with a mobile communication network over unlicensed radio spectrum can be combined into a single transceiver unit, such as a single chip that performs functions for both licensed and unlicensed radio spectrum. In some embodiments, the first transmitter / receiver pair and the second transmitter / receiver pair can share one or more hardware components. For example, certain transceivers 525, transmitters 530, and receivers 535 can be implemented as physically separate components that access shared hardware resources and / or software resources, such as the network interface 540.
[0146] In various embodiments, one or more transmitters 530 and / or one or more receivers 535 can be implemented and / or integrated into a single hardware component, such as a multi-transceiver chip, a system-on-a-chip, an ASIC, or other type of hardware component. In certain embodiments, one or more transmitters 530 and / or one or more receivers 535 can be implemented and / or integrated into a multi-chip module. In some embodiments, other components, such as the network interface 540, or other hardware components / circuits, can be integrated with any number of transmitters 530 and / or receivers 535 into a single chip. In such embodiments, the transmitters 530 and receivers 535 can be logically configured as a transceiver 525 that uses one common control signal or modular transmitters 530 and receivers 535 that are implemented in the same hardware chip or multi-chip module.
[0147] Figure 6 One embodiment of a network equipment apparatus 600 that can be used to relocate an access gateway during UE registration in accordance with embodiments of the disclosure is depicted. In some embodiments, the network equipment apparatus 600 can be one embodiment of a TNGF. In other embodiments, the network equipment apparatus 600 can be one embodiment of an AMF. Further, the network equipment apparatus 600 can include a processor 605, a memory 610, an input device 615, an output device 620, a transceiver 625. In some embodiments, the input device 615 and the output device 620 are combined into a single device, such as a touch screen. In certain embodiments, the network equipment apparatus 600 can not include any input device 615 and / or output device 620.
[0148] As depicted, the transceiver 625 includes at least one transmitter 630 and at least one receiver 635. Here, the transceiver 625 communicates with one or more remote units 105. Additionally, the transceiver 625 can support at least one network interface 640, such as the NWu interface depicted in Figure 1 In some embodiments, the transceiver 625 supports a first interface for communications with a RAN node, a second interface for communications with one or more network functions in a mobile core network (e.g., 6GC), and a third interface for communications with a remote unit (e.g., a UE).
[0149] In one embodiment, the processor 605 can include any known controller or processor capable of executing computer program instructions and / or capable of performing logical operations. For example, the processor 605 can be a microcontroller, a microprocessor, a central processing unit ("CPU"), a graphics processing unit ("GPU"), an auxiliary processing unit, a field programmable gate array ("FPGA"), or similar programmable controller. In some embodiments, the processor 605 executes instructions stored in the memory 610 to perform the methods and routines described herein. The processor 605 is communicatively coupled to the memory 610, the input device 615, the output device 620, and the first transceiver 625.
[0150] In various embodiments, the processor 605 controls the network equipment apparatus 600 to implement the TNGF-1 behavior described above. In some embodiments, the processor 605 initiates registration of a UE with a mobile communication network and receives a relocation command from an AMF while the registration is ongoing. Here, the relocation command contains an address of a first TNGF (i.e., TNGF-2) and a first security key.
[0151] The processor 605 determines whether a connection with the first TNGF is supported. If the connection with the first TNGF is supported, the processor 605 sends a first request to the first TNGF, the first request containing a UE identity and an AMF identity, as described above with reference to Figure 3B discussed (see step 12). However, if the connection with the first TNGF is not supported, the processor 605 sends a relocation reject message to the AMF, as discussed above with reference to Figure 4A discussed (see step 12).
[0152] In some embodiments, the processor 605 initiates registration of the UE with the mobile communication network by sending an Extensible Authentication Protocol 5G ("EAP-5G") packet containing a start indication to the UE, as discussed above with reference to Figure 3A discussed (see step 4). In such embodiments, the processor 605 further relays at least one NAS message between the UE and the AMF. In some embodiments, the processor 605 forwards the address of the first TNGF to the UE prior to sending the first request to the first TNGF or the relocation reject message to the AMF.
[0153] In some embodiments, the relocation command includes an SMC request, wherein the processor 605 forwards the SMC request and the address of the first TNGF to the UE prior to sending the first request to the first TNGF or the relocation reject message to the UE. AMF, and wherein the processor 605 receives a message from the UE in response to forwarding the SMC request, the message from the UE containing an SMC response.
[0154] In certain embodiments, the first request includes an SMC response, wherein the processor 605 receives a first response from the first TNGF, wherein the processor 605 generates a second security key using the first security key and forwards the second security key to an access point serving the UE in the non-3GPP access network. In other embodiments, the relocation reject message includes an SMC response. In various embodiments, the SMC request is a Security Mode Command message and the SMC response is a Security Mode Complete message.
[0155] In some embodiments, the relocation command containing the address of the first TNGF indicates that the first TNGF is selected to resume registration of the UE with the mobile communication network. In certain embodiments, the first TNGF is selected to resume registration of the UE with the mobile communication network in response to a determination at the AMF that the network equipment apparatus 600 does not support a set of allowed network slices (e.g., allowed NSSAI) for the UE, wherein the first TNGF supports the set of allowed network slices (allowed NSSAI).
[0156] In some embodiments, the relocation command contains an AMF identity. In one embodiment, the AMF identity is a GUAMI. In another embodiment, the AMF identity is an IP address of the AMF. Note that if the AMF identity in the first request is a GUAMI (not an IP address), the GUAMI must be provided by the AMF.
[0157] In various embodiments, the processor 605 controls the network equipment apparatus 600 to implement the above-described TNGF-2 behavior. Here, the processor 605 receives a first request from a first TNGF (i.e., TNGF-1), the first request including a UE identity and an AMF identity. Here, the first TNGF initiates registration of the UE with a mobile communication network, as discussed above with reference to Figure 3B (see step 12).
[0158] The processor 605 selects an AMF in the mobile communication network using the AMF identity, as discussed above with reference to Figure 3B (see step 13a), and sends a relocation notification message to the AMF, the relocation notification message including the UE identity. Here, the relocation notification message indicates that the registration of the UE with the mobile communication network is to be resumed via the network equipment apparatus 600. The processor 605 receives a second request from the AMF including a security key (i.e., TNGF key) in response to sending the relocation notification message, as discussed above with reference to Figure 3B (see step 14a), sends a first response to the first TNGF, as discussed above with reference to Figure 3C (see step 14d), and establishes a secure connection (e.g., IPsec SA) with the UE by applying the security key, as discussed above with reference to Figure 3C (see steps 18, 19).
[0159] In some embodiments, the first request includes an SMC request message, where the relocation notification message sent to the AMF includes the SMC request message. In various embodiments, the SMC request is a security mode command message. In some embodiments, the processor 605 sends a second response to the AMF in response to establishing the secure connection with the UE, as discussed above with reference to Figure 3C (see step 20).
[0160] In some embodiments, the processor 605 further completes the registration of the UE with the mobile communication network in response to establishing the secure connection with the UE. In some embodiments, the first TNGF does not support a set of allowed network slices (e.g., allowed NSSAI) for the UE, where the network equipment apparatus 600 supports the set of allowed network slices (allowed NSSAI).
[0161] In various embodiments, the processor 605 controls the network equipment apparatus 600 to implement the above-described AMF behavior. In some embodiments, the processor 605 receives a first request from a first access gateway (e.g., TNGF-1 or N3IWF-1), the first request including a first NAS message (e.g., registration request) from a UE, the first NAS message initiating registration of the UE with a mobile communication network via the first access gateway, as discussed above with reference to Figure 3A discussed above with reference to step 6b. The processor 605 determines to relocate the registration of the UE to a second access gateway (e.g., TNGF-2 or N3IWF-2). Here, the second access gateway is to resume the registration of the UE as discussed above with reference to Figure 3B and 4A discussed above with reference to step 8. The processor 605 sends a relocation command to the first access gateway, the relocation command including an address of the second access gateway, as discussed above with reference to Figure 3B and 4A discussed above with reference to step 9a, and relocates the registration of the UE to the second access gateway in response to sending the relocation command.
[0162] In some embodiments, the relocation command includes an SMC request message for the UE, where the processor 605 receives a relocation notification message from the second access gateway, the relocation notification message containing an SMC response message from the UE. In various embodiments, the SMC request is a security mode command message and the SMC response is a security mode complete message.
[0163] In some embodiments, the first access gateway is a first TNGF in a non-3GPP access network, where the second access gateway is a second TNGF in the non-3GPP access network, and where relocating the registration of the UE uses a procedure selected based on whether a connection between the first TNGF and the second TNGF is supported. In such embodiments, the processor 605 relocates the registration of the UE to the second TNGF by determining that the connection between the first TNGF and the second TNGF is not supported, where the processor 605 determines that the connection between the first TNGF and the second TNGF is not supported in response to receiving a relocation reject message from the first TNGF in response to sending the relocation command message.
[0164] In some embodiments, relocating the registration of the UE to the second TNGF includes sending an initial context setup request message to the second TNGF containing an identity of the UE and a security key in response to determining that the connection between the first TNGF and the second TNGF is not supported, as discussed above with reference to Figure 4A step 17). In certain embodiments, the processor 605 releases the connection with the first TNGF after sending the initial context setup request message to the second TNGF.
[0165] In some embodiments, relocating the registration of the UE to the second TNGF further includes receiving a notification message (e.g., TNGF relocation notification) from the second TNGF, where the notification message indicates that the connection between the first TNGF and the second TNGF is supported, as discussed above with reference to Figure 3B The first TNGF discussed (see step 14b) and, in response to receiving the notification message, sends an initial context setup request to the second TNGF containing the security keys. In certain embodiments, the processor 605 releases the connection with the first TNGF after receiving the notification message from the second TNGF.
[0166] In some embodiments, the first access gateway is a first N3IWF in a non-3GPP access network, wherein the second access gateway is a second N3IWF in the non-3GPP access network, and wherein the relocation command includes an AMF identity of the network equipment device 600. In certain embodiments, the second N3IWF uses the identity of the AMF to select the same AMF selected by the first N3IWF.
[0167] In some embodiments, the processor 605 repositions the registration of the UE to the second N3IWF by receiving a notification message (e.g., N3IWF relocation notification) from the second N3IWF, as discussed above with reference to Figure 3B The first TNGF discussed (see step 14b) and, in response to receiving the notification message, sends an initial context setup request to the second TNGF containing the security keys. In certain embodiments, the processor 605 releases the connection with the first TNGF after receiving the notification message from the second TNGF. Figure 3C and 4B The first TNGF discussed (see step 14b) and, in response to receiving the notification message, sends an initial context setup request to the second TNGF containing the security keys. In certain embodiments, the processor 605 releases the connection with the first TNGF after receiving the notification message from the second TNGF.
[0168] In one embodiment, the memory 610 is a computer readable storage medium. In some embodiments, the memory 610 includes both volatile and nonvolatile computer storage media. In some embodiments, the memory 610 stores data relating to repositioning access gateways during UE registration, for example storing security keys, IP addresses, UE contexts, etc. In certain embodiments, the memory 610 also stores program code and related data, such as an operating system ("OS") or other controller algorithms and one or more software applications running on the network equipment device 600.
[0169] In one embodiment, input device 615 can include any known computer input device including a touch panel, buttons, a keyboard, a pen, a microphone, etc. In some embodiments, input device 615 can be integrated with output device 620, for example, as a touch screen or similar touch-sensitive display. In some embodiments, input device 615 includes a touch screen such that text can be input using a virtual keyboard displayed on the touch screen and / or by handwriting on the touch screen. In some embodiments, input device 615 includes two or more different devices, such as a keyboard and a touch panel.
[0170] In one embodiment, output device 620 can include any known electronically controllable display or display device. Output device 620 can be designed to output visual, audible, and / or tactile signals. In some embodiments, output device 620 includes an electronic display or display device capable of outputting visual data to a user. For example, output device 620 can include, but is not limited to, an LCD display, an LED display, an OLED display, a projector, or similar display device capable of outputting images, text, etc., to a user. As another non-limiting example, output device 620 can include a wearable display such as a smart watch, smart glasses, a heads-up display, or the like. Further, output device 620 can be a component of a smart phone, a personal digital assistant, a television, a table computer, a notebook (laptop) computer, a personal computer, a vehicle dashboard, or the like.
[0171] In certain embodiments, output device 620 includes one or more speakers for producing sound. For example, output device 620 can produce an audible alert or notification (e.g., a beep or chime). In some embodiments, output device 620 includes one or more haptic devices for producing vibrations, motion, or other tactile feedback. In some embodiments, all or portions of output device 620 can be integrated with input device 615. For example, input device 615 and output device 620 can form a touch screen or similar touch-sensitive display. In other embodiments, all or portions of output device 620 can be located near input device 615.
[0172] As discussed above, transceiver 625 can communicate with one or more remote units and / or with one or more interworking functions that provide access to one or more PLMNs. Transceiver 625 can also communicate with one or more network functions (e.g., in mobile core network 140). Transceiver 625 operates under the control of processor 605 to transmit and to receive messages, data, and other signals. For example, processor 605 can selectively activate the transceiver (or portions thereof) at particular times in order to send and to receive messages.
[0173] The transceiver 625 can include one or more transmitters 630 and one or more receivers 635. In certain embodiments, the one or more transmitters 630 and / or the one or more receivers 635 can share transceiver hardware and / or circuitry. For example, the one or more transmitters 630 and / or the one or more receivers 635 can share antenna(s), antenna tuner(s), amplifier(s), filter(s), oscillator(s), mixer(s), modulator / demodulator(s), power supply, etc. In one embodiment, the transceiver 625 implements multiple logical transceivers using different communication protocols or protocol stacks while using common physical hardware.
[0174] Figure 7 One embodiment of a method 700 for relocating an access gateway during UE registration, in accordance with embodiments of the disclosure, is depicted. In various embodiments, the method 700 is performed by a TNGF, such as the TNGF 125, the TNGF 127, the TNGF-1 211, and / or the network equipment apparatus 600. In some embodiments, the method 700 is performed by a processor, such as a microcontroller, a microprocessor, a CPU, a GPU, an auxiliary processing unit, a FPGA, or the like.
[0175] The method 700 begins and initiates 705 registration of a remote unit with a mobile communication network. The method 700 includes receiving 710 a relocation command from an AMF in the mobile communication network while the registration is ongoing. Here, the relocation command contains an address of a first TNGF in the mobile communication network and a first security key.
[0176] The method 700 includes determining 715 whether a connection with the first TNGF is supported. If a connection with the first TNGF is supported, the method 700 includes sending 720 a first request to the first TNGF, the first request containing a remote unit identity and an AMF identity. However, if a connection with the first TNGF is not supported, the method 700 includes sending 725 a relocation reject message to the AMF. The method 700 ends.
[0177] Figure 8 One embodiment of a method 800 for relocating an access gateway during UE registration, in accordance with embodiments of the disclosure, is depicted. In various embodiments, the method 800 is performed by a TNGF, such as the TNGF 125, the TNGF 127, the TNGF-2 213, and / or the network equipment apparatus 600. In some embodiments, the method 800 is performed by a processor, such as a microcontroller, a microprocessor, a CPU, a GPU, an auxiliary processing unit, a FPGA, or the like.
[0178] The method 800 begins and receives 805 a first request from a first TNGF, the first request including a remote unit identity and an AMF identity. Here, the first TNGF initiates registration of the remote unit with the mobile communication network. The method 800 includes selecting 810 an AMF in the mobile communication network using the AMF identity.
[0179] The method 800 includes sending 815 a relocation notification message to the AMF, the relocation notification message including the remote unit identity. Here, the relocation notification message indicates that the registration of the remote unit with the mobile communication network is to be resumed via the sending TNGF. The method 800 includes receiving 820 a second request from the AMF including a security key (i.e., a TNGF key) in response to sending the relocation notification message.
[0180] The method 800 includes sending 825 a first response to the first TNGF. The method 800 includes establishing 830 a secure connection (e.g., an IPsec SA) with the remote unit by applying the security key. The method 800 ends.
[0181] Figure 9 One embodiment of a method 900 for relocating an access gateway during UE registration in accordance with embodiments of the present disclosure is depicted. In various embodiments, the method 900 is performed by an AMF, such as the AMF 143, the AMF 215, and / or the network equipment apparatus 600. In some embodiments, the method 900 is performed by a processor, such as a microcontroller, a microprocessor, a CPU, a GPU, an auxiliary processing unit, a FPGA, or the like.
[0182] The method 900 begins and receives 905 a first request from a first access gateway, the first request including a first NAS message (i.e., a registration request) from a remote unit that initiates registration of the remote unit with the mobile communication network via the first access gateway. The method 900 includes determining 910 to relocate the registration of the remote unit to a second access gateway. Here, the second access gateway is to resume the registration of the remote unit.
[0183] The method 900 includes sending 915 a relocation command to the first access gateway, the relocation command including an address of the second access gateway. The method 900 includes relocating 920 the registration of the remote unit to the second access gateway in response to sending the relocation command. The method 900 ends.
[0184] Figure 10 One embodiment of a method 1000 for relocating an access gateway during UE registration in accordance with embodiments of the present disclosure is depicted. In various embodiments, the method 1000 is performed by a UE, such as the remote unit 105, the UE 205, and / or the user equipment apparatus 500, as described above. In some embodiments, the method 1000 is performed by a processor, such as a microcontroller, a microprocessor, a CPU, a GPU, an auxiliary processing unit, a FPGA, or the like.
[0185] The method 1000 begins and selects 1005 a first N3IWF for registration with a mobile communication network via the first N3IWF. The method 1000 includes sending 1010 a first message to the first N3IWF, the first message containing a NAS message that initiates a first registration procedure with the mobile communication network.
[0186] The method 1000 includes receiving 1015 a first response from the first N3IWF. Here, the first response contains an address of a second N3IWF and an identity of an AMF in the mobile communication network. The method 1000 includes sending 1020 a second message to the first N3IWF, the second message indicating that the first registration procedure via the first N3IWF is to be stopped.
[0187] The method 1000 includes sending 1025 a third message to the second N3IWF and completing the first registration procedure via the second N3IWF. Here, the third message indicates that the first registration is to be relocated to the second N3IWF. The method 1000 ends.
[0188] Disclosed herein is a first apparatus for relocating an access gateway during UE registration in accordance with embodiments of the present disclosure. The first apparatus can be implemented by a TNGF, such as the TNGF 125, the TNGF 127, the TNGF-1 211, and / or the network equipment apparatus 600. The first apparatus includes an interface that communicates with a remote unit via a non-3GPP access network and with a plurality of network functions in a mobile communication network, including an AMF and a first TNGF. The first apparatus includes a processor that initiates a registration of the remote unit with the mobile communication network and receives a relocation command from the AMF while the registration is in progress. Here, the relocation command contains an address of the first TNGF and a first security key.
[0189] The processor determines whether a connection with the first TNGF is supported. If the connection with the first TNGF is supported, the processor sends a first request to the first TNGF, the first request containing the remote unit identity and the AMF identity. However, if the connection with the first TNGF is not supported, the processor sends a relocation reject message to the AMF.
[0190] In some embodiments, the processor initiates registration of the remote unit with the mobile communication network by sending an Extensible Authentication Protocol 5G ("EAP-5G") packet containing a start indication to the remote unit. In such embodiments, the processor further relays at least one NAS message between the remote unit and the AMF. In some embodiments, the processor forwards the address of the first TNGF to the remote unit prior to sending the first request to the first TNGF or sending the relocation reject message to the AMF.
[0191] In some embodiments, the relocation command includes an SMC request, wherein the processor forwards the SMC request and the address of the first TNGF to the remote unit prior to sending the first request to the first TNGF or sending the relocation reject message to the AMF, and wherein the processor receives a message from the remote unit in response to forwarding the SMC request, the message from the remote unit containing an SMC response.
[0192] In certain embodiments, the first request includes an SMC response, wherein the processor receives a first response from the first TNGF, wherein the processor generates a second security key using the first security key and forwards the second security key to an access point in the non-3GPP access network that is serving the remote unit. In other embodiments, the relocation reject message includes an SMC response. In various embodiments, the SMC request is a Security Mode Command message and the SMC response is a Security Mode Complete message.
[0193] In some embodiments, the relocation command containing the address of the first TNGF indicates that the first TNGF is selected to resume registration of the remote unit with the mobile communication network. In certain embodiments, the first TNGF is selected to resume registration of the remote unit with the mobile communication network in response to determining at the AMF that the apparatus does not support a set of allowed network slices (e.g., allowed NSSAI) for the remote unit, wherein the first TNGF supports the set of allowed network slices (allowed NSSAI).
[0194] In some embodiments, the relocation command contains an AMF identity. In one embodiment, the AMF identity is a GUAMI. In another embodiment, the AMF identity is an IP address of the AMF. Note that if the AMF identity in the first request is a GUAMI (not an IP address), the GUAMI must be provided by the AMF.
[0195] Disclosed herein is a first method for relocating an access gateway during UE registration according to embodiments of the present disclosure. The first method can be performed by a TNGF, such as the TNGF 125, the TNGF 127, the TNGF-1 211, and / or the network equipment apparatus 600. The first method includes initiating registration of a remote unit with a mobile communication network and receiving a relocation command from an AMF in the mobile communication network while the registration is ongoing. Here, the relocation command contains an address of a first TNGF in the mobile communication network and a first security key.
[0196] The first method includes determining whether a connection with the first TNGF is supported. If the connection with the first TNGF is supported, the first method includes sending a first request to the first TNGF, the first request containing a remote unit identity and an AMF identity. If, however, the connection with the first TNGF is not supported, the first method includes sending a relocation reject message to the AMF.
[0197] In some embodiments, initiating registration of a remote unit with a mobile communication network includes sending an Extensible Authentication Protocol 5G (“EAP-5G”) packet containing a start indication to the remote unit. In such embodiments, the first method further includes relaying at least one NAS message between the remote unit and the AMF. In some embodiments, the first method includes forwarding the address of the first TNGF to the remote unit prior to sending the first request to the first TNGF or sending the relocation reject message to the AMF.
[0198] In some embodiments, the relocation command includes an SMC request. In such embodiments, the first method includes forwarding the SMC request and the address of the first TNGF to the remote unit prior to sending the first request to the first TNGF or sending the relocation reject message to the AMF, and receiving a message from the remote unit in response to forwarding the SMC request, the message from the remote unit containing an SMC response.
[0199] In certain embodiments, the first request includes the SMC response. In such embodiments, the first method includes receiving a first response from the first TNGF, generating a second security key using the first security key, and forwarding the second security key to an access point in the non-3GPP access network that is serving the remote unit. In other embodiments, the relocation reject message includes the SMC response. In various embodiments, the SMC request is a security mode command message and the SMC response is a security mode complete message.
[0200] In some embodiments, the relocation command including the address of the first TNGF indicates that the first TNGF is selected to resume registration of the remote unit to the mobile communication network. In certain embodiments, the first TNGF is selected to resume registration of the remote unit to the mobile communication network in response to determining at the AMF that the apparatus does not support a set of allowed network slices (e.g., allowed NSSAI) for the remote unit, where the first TNGF supports the set of allowed network slices (allowed NSSAI).
[0201] In some embodiments, the relocation command includes an AMF identity. In one embodiment, the AMF identity is a GUAMI. In another embodiment, the AMF identity is an IP address of the AMF. Note that if the AMF identity in the first request is a GUAMI (not an IP address), the GUAMI must be provided by the AMF.
[0202] Disclosed herein is a second apparatus for relocating an access gateway during UE registration according to embodiments of the disclosure. The second apparatus can be implemented by a TNGF such as the TNGF 125, the TNGF 127, the TNGF-2 213, and / or the network equipment apparatus 600. The second apparatus includes an interface to communicate with a plurality of network functions in a mobile communication, including an AMF and a first TNGF. The second apparatus includes a processor that receives a first request from the first TNGF, the first request including a remote unit identity and an AMF identity. Here, the first TNGF initiates registration of the remote unit to the mobile communication network.
[0203] The processor selects an AMF in the mobile communication using the AMF identity and sends a relocation notification message to the AMF, the relocation notification message including the remote unit identity. Here, the relocation notification message indicates that registration of the remote unit to the mobile communication network is to be resumed via the apparatus. The processor receives a second request from the AMF including a security key in response to sending the relocation notification message, sends a first response to the first TNGF, and establishes a secure connection (e.g., IPsec SA) with the remote unit by applying the security key.
[0204] In some embodiments, the first request includes an SMC request message, where the relocation notification message sent to the AMF includes the SMC request message. In various embodiments, the SMC request is a security mode command message. In some embodiments, the processor sends a second response to the AMF in response to establishing the secure connection with the remote unit.
[0205] In some embodiments, in response to establishing the secure connection with the remote unit, the processor further completes registration of the remote unit with the mobile communication network. In some embodiments, the first TNGF does not support a set of allowed network slices (e.g., allowed NSSAI) for the remote unit, where the apparatus supports the set of allowed network slices (allowed NSSAI).
[0206] Disclosed herein is a second method for relocating an access gateway during UE registration according to embodiments of the disclosure. The second method can be performed by a TNGF, such as the TNGF 125, the TNGF 127, the TNGF-2 213, and / or the network equipment apparatus 600. The second method includes receiving a first request from a first TNGF, the first request containing a remote unit identity and an AMF identity. Here, the first TNGF initiates registration of a remote unit with a mobile communication network. The second method includes selecting an AMF in the mobile communication network using the AMF identity and sending a relocation notification message to the AMF, the relocation notification message containing the remote unit identity. Here, the relocation notification message indicates that the registration of the remote unit with the mobile communication network is to be resumed via the sending TNGF. The second method includes receiving a second request containing a security key from the AMF in response to sending the relocation notification message, sending a first response to the first TNGF, and establishing a secure connection (e.g., IPsec SA) with the remote unit by applying the security key.
[0207] In some embodiments, the first request contains an SMC request message, where the relocation notification message sent to the AMF contains the SMC request message. In various embodiments, the SMC request is a security mode command message. In some embodiments, the second method further includes sending a second response to the AMF in response to establishing the secure connection with the remote unit.
[0208] In some embodiments, the second method further includes completing registration of the remote unit with the mobile communication network in response to establishing the secure connection with the remote unit. In some embodiments, the first TNGF does not support a set of allowed network slices (e.g., allowed NSSAI) for the remote unit, where the apparatus supports the set of allowed network slices (allowed NSSAI).
[0209] Disclosed herein is a third apparatus for relocating an access gateway during UE registration according to embodiments of the present disclosure. The third apparatus can be implemented by an AMF such as the AMF 143, the AMF 215, and / or the network equipment apparatus 600. The third apparatus includes an interface that communicates with a plurality of access gateways that support connections to a mobile communication network via non-3GPP access networks. The third apparatus includes a processor that receives, from a first access gateway, a first request that includes a first NAS message from a remote unit that initiates registration of the remote unit with the mobile communication network via the first access gateway. The processor determines to relocate the registration of the remote unit to a second access gateway. Here, the second access gateway is to resume the registration of the remote unit. The processor sends, to the first access gateway, a relocation command that includes an address of the second access gateway and relocates the registration of the remote unit to the second access gateway in response to sending the relocation command.
[0210] In some embodiments, the relocation command includes an SMC request message for the remote unit, where the processor receives a relocation notification message from the second access gateway that contains an SMC response message from the remote unit. In various embodiments, the SMC request is a security mode command message and the SMC response is a security mode complete message.
[0211] In some embodiments, the first access gateway is a first TNGF in a non-3GPP access network, where the second access gateway is a second TNGF in the non-3GPP access network, and where relocating the registration of the remote unit uses a procedure selected based on whether connections between the first TNGF and the second TNGF are supported. In such embodiments, the processor relocates the registration of the remote unit to the second TNGF by determining that connections between the first TNGF and the second TNGF are not supported, where the processor receives a relocation reject message from the first TNGF in response to sending the relocation command message determines that connections between the first TNGF and the second TNGF are not supported.
[0212] In some embodiments, relocating the registration of the remote unit to the second TNGF includes sending, to the second TNGF, an initial context setup request message that contains an identity of the remote unit and a security key in response to determining that the first TNGF and the second TNGF are not supported. In certain embodiments, the processor releases the connection with the first TNGF after sending the initial context setup request message to the second TNGF.
[0213] In some embodiments, the relocating the registration of the remote unit to the second TNGF further comprises receiving a notification message from the second TNGF, wherein the notification message indicates support for a connection between the first TNGF and the second TNGF, and sending an initial context setup request containing a security key to the second TNGF in response to receiving the notification message. In certain embodiments, the processor releases the connection with the first TNGF after receiving the notification message from the second TNGF.
[0214] In some embodiments, the first access gateway is a first N3IWF in a non-3GPP access network, wherein the second access gateway is a second N3IWF in the non-3GPP access network, and wherein the relocation command includes an identity of an AMF of the apparatus. In certain embodiments, the second N3IWF uses the identity of the AMF to select the same AMF selected by the first N3IWF.
[0215] In some embodiments, the processor relocates the registration of the remote unit to the second N3IWF by receiving a notification message from the second N3IWF, wherein the notification message indicates that the remote unit is to resume registration via the second N3IWF, sending an initial context setup request containing a security key to be used to establish a secure connection with the remote unit to the second N3IWF in response to receiving the notification message, and receiving a response from the second N3IWF confirming establishment of the secure connection with the remote unit.
[0216] A third method for relocating an access gateway during UE registration according to embodiments of the disclosure is disclosed herein. The third method can be implemented by an AMF, such as the AMF 143, the AMF 215, and / or the network equipment apparatus 600. The third method includes receiving a first request from a first access gateway, the first request including a first NAS message from a remote unit that initiates registration of the remote unit with a mobile communication network via the first access gateway. The third method includes determining to relocate the registration of the remote unit to a second access gateway. Here, the second access gateway is to resume the registration of the remote unit. The third method includes sending a relocation command to the first access gateway and relocating the registration of the remote unit to the second access gateway in response to sending the relocation command, wherein the relocation command includes an address of the second access gateway.
[0217] In some embodiments, the relocation command includes an SMC request message for the remote unit, wherein the third method includes receiving a relocation notification message from the second access gateway containing an SMC response message from the remote unit. In various embodiments, the SMC request is a security mode command message and the SMC response is a security mode complete message.
[0218] In some embodiments, the first access gateway is a first TNGF in a non-3GPP access network, the second access gateway is a second TNGF in the non-3GPP access network, and the redirecting the registration of the remote unit uses a procedure selected based on whether a connection between the first TNGF and the second TNGF is supported. In such embodiments, the third method includes redirecting the registration of the remote unit to the second TNGF by determining that the connection between the first TNGF and the second TNGF is not supported, where the third method includes determining that the connection between the first TNGF and the second TNGF is not supported in response to receiving a relocation reject message from the first TNGF in response to sending the relocation command message.
[0219] In some embodiments, the redirecting the registration of the remote unit to the second TNGF includes sending an initial context setup request message containing a remote unit identity and a security key to the second TNGF in response to determining that the connection between the first TNGF and the second TNGF is not supported. In certain embodiments, the third method includes releasing the connection with the first TNGF after sending the initial context setup request message to the second TNGF.
[0220] In some embodiments, the redirecting the registration of the remote unit to the second TNGF further includes receiving a notification message from the second TNGF, where the notification message indicates that the connection between the first TNGF and the second TNGF is supported, and sending an initial context setup request containing a security key to the second TNGF in response to receiving the notification message. In certain embodiments, the third method includes releasing the connection with the first TNGF after receiving the notification message from the second TNGF.
[0221] In some embodiments, the first access gateway is a first N3IWF in a non-3GPP access network, the second access gateway is a second N3IWF in the non-3GPP access network, and the relocation command includes an AMF identity of the apparatus. In certain embodiments, the second N3IWF uses the identity of the AMF to select the same AMF selected by the first N3IWF.
[0222] In some embodiments, the third method includes redirecting the registration of the remote unit to the second N3IWF by receiving a notification message from the second N3IWF, where the notification message indicates that the remote unit resume registration via the second N3IWF, sending an initial context setup request containing a security key to be used to establish a secure connection with the remote unit to the second N3IWF in response to receiving the notification message, and receiving a response from the second N3IWF confirming that the secure connection with the remote unit is established.
[0223] Disclosed herein is a fourth apparatus for relocating an access gateway during UE registration according to embodiments of the disclosure. The fourth apparatus can be implemented by a UE such as the remote unit 105, the UE 205, and / or the user equipment apparatus 500. The fourth apparatus includes a transceiver that communicates with a non-3GPP access network; and a processor that selects a first N3IWF for registration with a mobile communication network via the first N3IWF. The processor sends a first message to the first N3IWF, the first message containing a NAS message that initiates a first registration procedure with the mobile communication network, and receives a first response from the first N3IWF. Here, the first response contains an address of a second N3IWF and an identity of an AMF in the mobile communication network. The processor sends a second message to the first N3IWF, the second message indicating that the first registration procedure via the first N3IWF is to be stopped, and sends a third message to the second N3IWF, the third message indicating that the first registration is to be relocated to the second N3IWF. The processor completes the first registration procedure via the second N3IWF.
[0224] In some embodiments, the first message includes an identity of the mobile communication network and an establishment cause. In certain embodiments, the establishment cause indicates that the first registration is to be relocated to the second N3IWF. In some embodiments, the first response is received after mutual authentication and key agreement. In some embodiments, the third message includes a second NAS message that resumes the first registration procedure via the second N3IWF. In various embodiments, the first NAS message includes a registration request, and the second NAS message includes an SMC complete message.
[0225] In some embodiments, the third message contains an identity of the AMF, wherein the identity of the AMF indicates that the first registration is to be relocated to the second N3IWF, and wherein the identity of the AMF is used by the second N3IWF to select the same AMF selected by the first N3IWF. In some embodiments, completing registration with the mobile communication network via the second N3IWF includes establishing a NWu connection with the second N3IWF and receiving a registration accept via the established NWu connection.
[0226] Disclosed herein is a fourth method for relocating an access gateway during UE registration according to embodiments of the disclosure. The fourth method can be implemented by a UE such as the remote unit 105, the UE 205, and / or the user equipment apparatus 500. The fourth method includes selecting a first N3IWF for registering with a mobile communication network via the first N3IWF, and sending a first message to the first N3IWF, the first message containing a NAS message that initiates a first registration procedure with the mobile communication network. The fourth method includes receiving a first response from the first N3IWF and sending a second message to the first N3IWF. Here, the first response contains an address of a second N3IWF and an identity of an AMF in the mobile communication network, and the second message indicates that the first registration procedure via the first N3IWF is to be stopped. The fourth method includes sending a third message to the second N3IWF, and completing the first registration procedure via the second N3IWF. Here, the third message indicates that the first registration is to be relocated to the second N3IWF.
[0227] In some embodiments, the first message includes an identity of the mobile communication network and an establishment cause. In certain embodiments, the establishment cause indicates that the first registration is to be relocated to the second N3IWF. In some embodiments, the first response is received after mutual authentication and key agreement. In some embodiments, the third message includes a second NAS message that resumes the first registration procedure via the second N3IWF. In various embodiments, the first NAS message includes a registration request, wherein the second NAS message includes an SMC complete message.
[0228] In some embodiments, the third message contains an identity of the AMF, wherein the identity of the AMF indicates that the first registration is to be relocated to the second N3IWF, and wherein the identity of the AMF is used by the second N3IWF to select the same AMF selected by the first N3IWF. In some embodiments, completing registration with the mobile communication network via the second N3IWF includes establishing a NWu connection with the second N3IWF and receiving a registration accept via the established NWu connection.
[0229] Embodiments can be practiced in other specific forms. The described embodiments are to be considered in all respects only as illustrative and not restrictive. The scope of the application is, therefore, indicated by the appended claims rather than by the foregoing description. All changes that come within the meaning and range of equivalency of the claims are to be embraced within their scope.< / mcc> < / mnc>
Claims
1. A Trusted Non-3GPP Gateway Function (“TNGF”) apparatus comprising: an interface to communicate with a remote unit via a Trusted Non-3GPP access network and to communicate with a plurality of network functions in a mobile communication network; and a processor to: initiate registration of the remote unit with the mobile communication network; receive a relocation command from an Access and Mobility Management Function (“AMF”) in the mobile communication network while the registration is in progress, the relocation command containing an address of a first TNGF and a first security key, wherein the first TNGF is different from the TNGF apparatus; determine whether connection with the first TNGF is supported; in response to connection with the first TNGF being supported, send a first request to the first TNGF containing a remote unit identity and an AMF identity; and in response to connection with the first TNGF not being supported, send a relocation reject message to the AMF.
2. The TNGF device of claim 1, wherein, the processor initiates registration of the remote unit with the mobile communication network by sending an Extensible Authentication Protocol 5G (“EAP-5G”) packet containing a start indication to the remote unit, and wherein the processor further relays at least one Non-Access Stratum (“NAS”) message between the remote unit and the AMF. 3.The TNGF device of claim 1, wherein, the processor forwards the address of the first TNGF to the remote unit prior to sending the first request to the first TNGF or sending the relocation reject message to the AMF.
4. The TNGF device of claim 3, wherein, the relocation command includes a Security Mode Control (“SMC”) request, wherein the processor forwards the SMC request and the address of the first TNGF to the remote unit prior to sending the first request to the first TNGF or sending the relocation reject message to the AMF, and wherein the processor receives a message from the remote unit in response to forwarding the SMC request, the message from the remote unit containing a SMC response.
5. The TNGF device of claim 4, wherein, the first request includes the SMC response, wherein the processor receives a first response from the first TNGF, wherein the processor generates a second security key using the first security key and forwards the second security key to an access point in the Trusted Non-3GPP access network that serves the remote unit.
6. The TNGF device of claim 4, wherein, the relocation reject message includes a SMC response.
7. The TNGF device of claim 1, wherein, the relocation command containing the address of the first TNGF indicates that the first TNGF is selected to resume the registration of the remote unit with the mobile communication network.
8. The TNGF device according to claim 7, wherein, the first TNGF is selected to resume the registration of the remote unit with the mobile communication network in response to a determination at the AMF that the apparatus does not support a set of allowed network slices for the remote unit, wherein the first TNGF supports the set of allowed network slices.
9. The TNGF device of claim 1, wherein, the relocation command contains the AMF identity and wherein the AMF identity is a Globally Unique AMF Identity (“GUAMI”).
10. A method performed by a trusted non-3GPP gateway function ("TNGF") comprising: initiating registration of a remote unit with a mobile communication network; receiving a relocation command from an access and mobility management function ("AMF") in the mobile communication network while the registration is in progress, the relocation command containing an address of a first TNGF and a first security key, wherein the first TNGF is different from the TNGF; determining whether connection with the first TNGF is supported; in response to connection with the first TNGF being supported, sending a first request to the first TNGF containing a remote unit identity and an AMF identity; and in response to connection with the first TNGF not being supported, sending a relocation reject message to the AMF.
Citation Information
Patent Citations
Methods for support of user plane separation and user plane local offloading for 5g non-3GPP access
WO2019186504A1