Tclas element for filtering ipsec traffic

By extending the TCLAS element and adding classifier type 11 to identify and filter 5G QoS service flows carried by IPsec SA, the problem of QoS differentiation within Wi-Fi access is solved, end-to-end service quality is guaranteed, and the user experience of 5G services is improved.

CN115918142BActive Publication Date: 2026-06-02INTEL CORP

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INTEL CORP
Filing Date
2021-07-23
Publication Date
2026-06-02

Smart Images

  • Figure CN115918142B_ABST
    Figure CN115918142B_ABST
Patent Text Reader

Abstract

To carry 5G QoS traffic flows over an IPsec Security Association (SA) within a WLAN network, a STA is configured to encode a frame to include a Traffic Classification (TCLAS) element that includes a frame classifier field. The frame classifier field can include a classifier type subfield and a classifier parameter subfield. To identify and filter 5G QoS traffic flows carried over an IPsec SA, the STA can set the classifier type subfield to a predetermined value (e.g., 11) to indicate that an IPsec SA parameter is included in the classifier parameter subfield, and include a Security Parameter Index (SPI), a destination IP address, and an IPsec protocol within the classifier parameter subfield.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Priority requirements

[0002] This application claims priority to U.S. Provisional Patent Application Serial No. 63 / 057,088 [Reference No. AD1400-Z], filed July 27, 2020, which is incorporated herein by reference in its entirety. Technical Field

[0003] The embodiments relate to wireless communication. Some embodiments relate to wireless local area networks (WLANs) and WLAN access. Some embodiments relate to fifth-generation (5G) network services carried within a WLAN access via IPsec security association (SA). Background Technology

[0004] Internet Protocol Security (IPsec) is a suite of secure network protocols that authenticates and encrypts packets to provide secure, encrypted communication between devices over Internet Protocol (IP) networks. For example, IPsec is used in Virtual Private Networks (VPNs). One issue with transmitting data over Wi-Fi is the Quality of Service (QoS) differentiation of 5G services (e.g., 5G user streams and 5G signaling) carried via IPsec SAs within Wi-Fi access. Therefore, a method is needed to enable IPsec traffic filtering to ensure end-to-end QoS on Wi-Fi within 5G networks. Attached Figure Description

[0005] Figure 1 A WLAN reference architecture for device-centric QoS management for 5G streaming is shown according to some embodiments.

[0006] Figure 2 A WLAN reference architecture for network-centric QoS management for 5G streaming is shown according to some embodiments.

[0007] Figure 3A The format of the Business Classification (TCLAS) element is shown according to some embodiments.

[0008] Figure 3B A frame classifier field is shown according to some embodiments.

[0009] Figure 4 This is a table showing the classifier value types according to some embodiments.

[0010] Figure 5A The frame classifier field of classifier type 11 for services over IPv4 is shown according to some embodiments.

[0011] Figure 5B The frame classifier field of classifier type 11 for services over IPv6 is shown according to some embodiments.

[0012] Figure 6 This is a table illustrating IPsec SA direction values ​​according to some embodiments.

[0013] Figure 7 This is a functional block diagram of a wireless communication device according to some embodiments. Detailed Implementation

[0014] The following description and accompanying drawings fully illustrate specific embodiments to enable those skilled in the art to implement them. Other embodiments may be combined with structural changes, logical changes, electrical changes, process changes, and other modifications. Parts and features of some embodiments may be included or replaced with parts and features of other embodiments. The embodiments set forth in the claims cover all available equivalents of those claims.

[0015] Some embodiments disclosed herein relate to a station (STA) configured to operate in a wireless local area network (WLAN). In these embodiments, to carry 5G QoS service flows via IPsec Security Association (SA) within the WLAN network, the STA is configured to encode frames to include a Service Classification (TCLAS) element containing a Frame Classifier field. In these embodiments, the Frame Classifier field may include a Classifier Type subfield and a Classifier Parameter subfield. In these embodiments, to identify and filter 5G QoS service flows carried via IPsec SA, the STA may set the Classifier Type subfield to a predetermined value (e.g., 11) to indicate the inclusion of IPsec SA parameters in the Classifier Parameter subfield, and include a Security Parameter Index (SPI), destination IP address, and IPsec protocol within the Classifier Parameter subfield. In these embodiments, the STA may be configured to transmit frames via the WLAN as part of a 5G QoS service flow. These embodiments are described in more detail below.

[0016] In some embodiments, when an IPsec SA is established for a 5G QoS service flow over a WLAN, the STA can be configured to encode frames according to the Encapsulated Secure Payload (ESP) security protocol. In these embodiments, the ESP header can be encoded to include an SPI field that includes an SPI. In these embodiments, the destination IP address is derived from the external IP header and can refer to the destination address of the endpoint used for receiving and processing IPsec packets.

[0017] In some embodiments, the frame classifier field may further include a classifier mask subfield before the classifier parameter subfield. In these embodiments, the STA can be configured to encode the classifier mask subfield to indicate that the first four fields of the classifier parameter subfield will be matched in the frame for filtering traffic carried through the IPsec SA. In some embodiments, the first four fields of the classifier parameter subfield may include an IP protocol version field, a field indicating the IPsec protocol, a field indicating the destination IP address, and a field indicating the SPI associated with the IPsec SA. In these embodiments, the IP protocol version field may indicate whether the IP protocol version is IPv4 or IPv6.

[0018] In some embodiments, the field used to indicate the IPsec protocol is a value used for the IPsec protocol. In these embodiments, the STA can be configured to either set the field used to indicate the IPsec protocol to 50 for encapsulating the Security Payload (ESP), or set it to 51 for the Authentication Header (AH).

[0019] In some embodiments, the classifier parameter subfield may be encoded to include an IPsec SA direction field indicating the direction (e.g., uplink or downlink) of 5G QoS service flow carried over the IPsec SA. In some embodiments, the STA may be configured to set the classifier type subfield to a value of 11 to indicate that IPsec SA parameters are included in the classifier parameter subfield. In these embodiments, the STA may be configured to set the classifier type subfield to a value from 0 to 10 to indicate non-IPsec SA classifier parameters.

[0020] In some embodiments, the STA can be configured to set up 5G QoS service flows for an IPsec SA. In these embodiments, the STA can be part of a user equipment (UE) configured to operate in a 5G network. In these embodiments, the STA can include a 5G QoS entity. In some embodiments of these embodiments, the STA can include an NWu interface for connecting to a 5G core network with non-access stratum (NAS) functionality.

[0021] In some embodiments, an IPsec SA is established between the Non-3GPP Interoperability Function (N3IWF) or Trusted Non-3GPP Gateway Function (TNGF) and the UE. In these embodiments, the TCLAS element can be configured to provide service filtering information for 5G QoS service flows carried by the IPsec SA established between the N3IWF or TNGF and the UE. In these embodiments, the TCLAS element supports IPsec service filtering to ensure end-to-end quality of service over Wi-Fi in the 5G system. The TCLAS element can also support filtering IPsec services based on a combination of SPI (Security Parameter Index), the destination IP address (for IPsec processing endpoints), and the IPsec protocol. In some embodiments, the STA may include a baseband processor, and its memory may be configured to store the TCLAS element.

[0022] Some embodiments relate to a non-transitory computer-readable storage medium storing instructions for execution by processing circuitry of a STA configured to operate in a wireless local area network (WLAN). In these embodiments, to carry 5G QoS services via IPsec Security Association (SA) within a WLAN network, the STA may be configured to encode frames to include a Service Classification (TCLAS) element containing a Frame Classifier field. In these embodiments, the Frame Classifier field includes a Classifier Type subfield and a Classifier Parameter subfield. In these embodiments, to identify and filter 5G QoS service flows carried via IPsec SA, the STA may be configured to set the Classifier Type subfield to a predetermined value (e.g., 11) to indicate the inclusion of IPsec SA parameters in the Classifier Parameter subfield, and to include a Security Parameter Index (SPI), destination IP address, and IPsec protocol within the Classifier Parameter subfield. Some embodiments relate to methods performed by a STA configured to operate in a wireless local area network (WLAN). These embodiments are described in more detail below.

[0023] 3GPP Releases 15 and 16 define support for integrating untrusted and trusted Wi-Fi access networks with 5G systems via N3IWF (Non-3GPP Interoperability Function) and TNGF (Trusted Non-3GPP Gateway Function), as described in TS 23.501. A UE can establish a PDU session solely through Wi-Fi access, or it can establish a multi-access PDU session (MA PDU session), enabling the simultaneous carrying of user plane services via both 3GPP (NR, LTE) and Wi-Fi access. These PDU sessions carry user data services via 5G QoS flows. To carry 5G flows via Wi-Fi access, an IPsec Security Association (SA) is established between the gateway function N3IWF / TNGF and the UE. 5G user data flows are carried via the IPsec SA, while 5G NAS signaling is carried via the IPsec signaling SA established on the Wi-Fi access.

[0024] In 5G systems, the QoS requirements for 5G QoS flows also apply when these flows are carried via WLAN access. It is important to ensure that, taking into account 5G QoS characteristics and parameters, QoS differentiation within WLAN access can be provided for these 5G QoS flows to meet the end-to-end QoS requirements of applications / services, regardless of which radio access carries the service.

[0025] Within Wi-Fi access, service identification and filtering are provided by parameters in the TCLAS element, as defined in the IEEE 802.11 specification. To provide QoS differentiation for 5G services carried via IPsec SA within Wi-Fi access, the TCLAS element needs to be extended to filter IPsec SA services.

[0026] Some embodiments disclosed herein provide extensions to the 802.11TCLAS element to enable IPsec traffic filtering, thereby ensuring end-to-end quality of service over Wi-Fi in 5G systems.

[0027] In some embodiments, support for QoS differentiation of 5G services (5G user streams and 5G signaling) carried via IPsec SA within Wi-Fi access is provided by extending the TCLAS element to filter IPsec SA services based on a combination of SPI (Security Parameter Index), the destination IP address (for the IPsec processing endpoint), and the IPsec protocol (these three parameters uniquely identify the IPsec SA according to RFC 2401).

[0028] Several vendors and operators are planning to deploy 5G systems that may include Wi-Fi for data delivery in applications such as enterprise, home, industrial automation, and public hotspots. The embodiments disclosed herein implement QoS differentiation for 5G user data and signaling services carried over IPsec SA within Wi-Fi access. This ensures end-to-end quality of service for 5G services / applications carried over Wi-Fi access, enabling seamless use of 3GPP and Wi-Fi radios, thereby providing an improved user experience for 5G services.

[0029] Some embodiments disclosed herein provide TCLAS extensions for 5G services. To carry 5G user data and signaling services via untrusted and trusted WLAN access integrated with the 5G network, one or more IPsec security associations (SAs), such as 3GPP 'TS 24.502, are established between the N3IWF / TNGF and the UE, accessing the 3GPP 5G core network (5GCN) via a non-3GPP access network (N3AN); as described in Phase 3. 5G user data streams are carried via one or more IPsec SAs, while 5G NAS signaling is carried via IPsec signaling SAs established over Wi-Fi access.

[0030] Figure 1 A WLAN reference architecture model is shown for device-centric QoS management related to 5G user data streams and 5G signaling carried via IPsec SA. Figure 2 A WLAN reference architecture model is shown for network-centric QoS management related to 5G user data flows and 5G signaling carried over IPsec SAs. In both approaches, 5G QoS-related information is received from the 3GPP domain by a higher-layer 5G QoS entity within the WLAN domain. In both approaches, QoS service flows (TS) are established by the WLAN STA with the WLAN AP for filtering and prioritizing 5G services carried over IPsec SAs established via WLAN access.

[0031] The TCLAS element specifies service filtering parameters for filtering and prioritizing traffic to differentiate service flows within the WLAN. This element needs to be enhanced to specify filtering parameters for services carried via a specific IPsec SA, specifically for filtering 5G services carried via IPsec SAs and / or signaling IPsec SAs established between the N3IWF / TNGF and the UE. Enhanced TCLAS elements can typically be used to specify service filters for filtering traffic carried via IPsec SAs in the DL or UL.

[0032] The TCLAS element contains a set of parameters required to identify the various types of PDUs or incoming MSDUs belonging to a specific TS. Figure 3A The format of the Business Classification (TCLAS) element is shown according to some embodiments. Figure 3B The frame classifier field is shown according to some embodiments. Classifier type values ​​are defined in IEEE P802.11-REVmd / D3.1, February 2020.

[0033] Existing classifier type values ​​cannot be used to filter packets carried by a specific IPsec SA. Classifier type 10 allows filtering packets based on SPI, but it does not allow filtering packets based on the unique identifier of the IPsec SA using a combination of SPI, destination IP address, and protocol type.

[0034] The embodiments disclosed herein propose assigning a new classifier type 11 to extend the TCLAS element for providing IPsec SA parameters required for identifying and filtering IPsec SA services, such as... Figure 4 As shown. Figure 4 This is a table showing the classifier value types according to some embodiments.

[0035] IPsec SAs exist in pairs, one in each direction, used for inbound and outbound traffic exchange between IPsec endpoints according to RFC 2401. Each IPsec SA in each direction is identified by the SPI (Security Parameter Index), the destination IP address (for the IPsec processing endpoint), and the IPsec protocol used for the SA. In the case of establishing IPsec SAs over WLANs to carry 5G services, the ESP (Encapsulate Security Payload) security protocol is used, which is identified from the Protocol or Next Header field in the outer IP header of the IPsec packet. The destination IP address comes from the outer IP header and refers to the destination address of the endpoint that will receive and process the IPsec packet. The SPI field is included in the ESP header.

[0036] In addition, in order to filter and prioritize IPsec SA services, WLAN APs and WLAN STAs will need to know the direction (UL or DL) of the IPsec SA, so that they can establish a suitable set of filters (SPI, destination IP address, IPsec protocol) for QoS service flows in both uplink and downlink directions to filter IPsec SA services.

[0037] Figure 5A and Figure 5B The format for the frame classifier field for classifier type 11 is defined to provide filtering parameters for IPsecSA services. Figure 5AThe frame classifier field of classifier type 11 for services over IPv4 is shown according to some embodiments. Figure 5B The image illustrates a frame classifier field of classifier type 11 for services over IPv6, according to some embodiments. The classifier mask field can have its first four bits set to 1 to indicate that the first four fields should match in the MSDU for filtering services carried over IPsec SAs. In these embodiments, the classifier type field is set to 11, but this is not necessary, as another value can be specified to filter IPsec SA services.

[0038] In some embodiments, the classifier mask field has the first four LSB bits set to 1, indicating that the first four fields (version, IPsec protocol, destination IP address, and SPI) need to match in the MSDU for filtering traffic carried via the IPsecSA. The version field indicates the IP protocol version, set to 4 for IPv4 and 6 for IPv6.

[0039] The IPsec protocol field indicates the value used for the protocol in the external IP header or the next header parameter, thus indicating the IPsec protocol carried in the encapsulated packet. It is set to 50 for ESP (Encapsulated Security Payload, RFC 4303) and 51 for AH (Authentication Header, RFC 4302).

[0040] The Destination IP Address field is the destination address from the external IP header and refers to the endpoint that will receive and process IPsec packets. The SPI field indicates the index of security parameters associated with the IPsec security association.

[0041] The IPsec SA direction field indicates the uplink or downlink direction of the service carried over the IPsec security association and is used to establish appropriate filters for filtering uplink and downlink IPsec SA services. Each direction (UL or DL) IPsec SA is uniquely identified by a combination of parameters (SPI, destination IP address, and protocol). Figure 6 This is a table illustrating IPsec SA direction values ​​according to some embodiments.

[0042] Figure 7 This is a functional block diagram of a wireless communication device according to some embodiments. In one embodiment, Figure 7A functional block diagram is shown that can be used as a communication station (STA) according to some embodiments, suitable for use as an AP STA, non-AP STA, or other user equipment. Communication station 700 can also be used as a handheld device, mobile device, cellular phone, smartphone, tablet computer, netbook, wireless terminal, laptop computer, wearable computing device, femtocell, high data rate (HDR) user station, access point, access terminal, or other personal communication system (PCS) device.

[0043] Communication station 700 may include communication circuitry 702 and transceiver 710 for transmitting signals to and receiving signals from other communication stations using one or more antennas 701. Communication circuitry 702 may include circuitry operable for controlling access to a wireless medium via physical layer (PHY) communication and / or medium access control (MAC) communication, and / or any other communication layer for transmitting and receiving signals. Communication station 700 may also include processing circuitry 706 and memory 708, which are arranged to perform the operations described herein. In some embodiments, communication circuitry 702 and processing circuitry 706 may be configured to perform the operations detailed in the above figures, diagrams, and flowcharts.

[0044] According to some embodiments, communication circuitry 702 may be arranged to compete for a wireless medium and configure frames or packets for transmission over the wireless medium. Communication circuitry 702 may be arranged to transmit and receive signals. Communication circuitry 702 may also include circuitry for modulation / demodulation, up-conversion / down-conversion, filtering, amplification, etc. In some embodiments, processing circuitry 706 of communication station 700 may include one or more processors. In other embodiments, two or more antennas 701 may be coupled to communication circuitry 702 arranged for transmitting and receiving signals. Memory 708 may store information for configuring processing circuitry 706 to perform operations for configuring and transmitting message frames and performing the various operations described herein. Memory 708 may include any type of memory, including non-transitory memory, for storing information in a machine-readable (e.g., computer) form. For example, memory 708 may include computer-readable storage devices, read-only memory (ROM), random access memory (RAM), disk storage media, optical storage media, flash memory devices, and other storage devices and media.

[0045] In some embodiments, communication station 700 may be part of a portable wireless communication device, such as a personal digital assistant (PDA), a laptop or portable computer with wireless communication capabilities, a web tablet computer, a cordless phone, a smartphone, a wireless headset, a pager, an instant messaging device, a digital camera, an access point, a television set, a medical device (e.g., a heart rate monitor, a blood pressure monitor, etc.), a wearable computer device, or another device that can wirelessly receive and / or transmit information.

[0046] In some embodiments, communication station 700 may include one or more antennas 701. Antenna 701 may include one or more directional or omnidirectional antennas, including, for example, dipole antennas, monopole antennas, patch antennas, loop antennas, microstrip antennas, or other types of antennas suitable for transmitting RF signals. In some embodiments, instead of two or more antennas, a single antenna with multiple apertures may be used. In these embodiments, each aperture can be considered a separate antenna. In some multiple-input multiple-output (MIMO) embodiments, the antennas can be effectively separated for spatial diversity and the different channel characteristics that may result between each antenna and the antenna of the transmitting station.

[0047] In some embodiments, the communication station 700 may include one or more of a keyboard, a display, a non-volatile memory port, multiple antennas, a graphics processor, an application processor, a speaker, and other mobile device components. The display may be an LCD screen including a touchscreen.

[0048] Although the communication station 700 is shown as having several separate functional elements, two or more of these functional elements can be combined and implemented by a combination of software-configurable elements (e.g., processing elements including digital signal processors (DSPs)) and / or other hardware elements. For example, some elements may include one or more microprocessors, DSPs, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), radio frequency integrated circuits (RFICs), and combinations of various hardware and logic circuits to perform at least the functions described herein. In some embodiments, the functional elements of the communication station 700 may refer to one or more processes running on one or more processing elements.

[0049] Embodiments may be implemented as hardware, firmware, and software, or a combination thereof. Embodiments may also be implemented as instructions stored on a computer-readable storage device, which can be read and executed by at least one processor to perform the operations described herein. A computer-readable storage device may include any non-transitory mechanism for storing information in a machine-readable (e.g., computer) form. For example, a computer-readable storage device may include read-only memory (ROM), random access memory (RAM), disk storage media, optical storage media, flash memory devices, and other storage devices and media. Some embodiments may include one or more processors and may be configured with instructions stored on the computer-readable storage device.

[0050] In some embodiments, the physical layer protocol data unit may be a physical layer conformance process (PLCP) protocol data unit (PPDU). In some embodiments, the AP and STA may communicate according to one of the IEEE 802.11 standards. IEEE 802.11-2016 is incorporated herein by reference. IEEE P802.11-REVmd / D2.4, August 2019 and IEEE specification draft IEEE P802.11ax / D5.0, October 2019 are also incorporated herein by reference in their entirety.

[0051] Example:

[0052] Example 1 may include a WLAN system integrated with a 5G core via a TNGF or N3IWF gateway function, wherein the UE supports cellular and Wi-Fi capabilities. The Wi-Fi access network (with WLAN APs and a wireless LAN controller) and other necessary elements are as described in 3GPP TS 23.501 and IEEE 802.11-2016 specifications.

[0053] Example 2 may include the WLAN system of Example 1, wherein the UE may be a Wi-Fi-only device with 3GPP NAS functionality and NWu and / or NWt interface functionality for connecting to the 5G core via untrusted or trusted WLAN access, as defined in 3GPP specifications TS 23.501, TS 23.502 and TS 24.502.

[0054] Example 3 may include the WLAN system of Example 1 or 2, wherein a higher-level entity, referred to as the “5G QoS entity”, is located within the WLAN STA or WLAN AP, and this entity receives 5G QoS related information from the 3GPP domain for use with 5G user data streams and 5G signaling to be carried over Wi-Fi access via IPsec Security Association (SA).

[0055] Example 4 may include Example 3, wherein, after receiving a trigger from the 5G QoS entity for initiating QoS negotiation for an IPsec SA, the WLAN STA initiates a QoS Service Flow (TS) establishment with the WLAN AP for filtering and prioritizing 5G services (5G user data flows or 5G signaling) carried through one or more IPsec SAs.

[0056] Example 5 may include Example 1, in which the WLAN STA initiates a QoS service flow (TS) establishment with the WLAN AP for filtering and prioritizing any traffic carried through one or more IPsec SAs.

[0057] Example 6 may include Examples 4 and 5, wherein the TCLAS element is included by the WLAN STA to provide service filters and user priorities for services carried over a specific IPsec SA.

[0058] Example 7 may include Example 6, wherein the TCLAS element provides service filtering information for 5G services carried by the IPsec SA or signaling IPsec SA established between the N3IWF / TNGF and the UE.

[0059] Example 8 may include Examples 6 and 7, wherein the TCLAS element includes a classifier type field with a value of 11 to provide IPsec security association parameters.

[0060] Example 9 may include Examples 6 through 8, wherein the TCLAS element for classifier type 11 includes a classifier mask, version, IPsec protocol, destination IP address, security parameter index (SPI), and IPsec SA direction field.

[0061] Example 10 may include Example 9, wherein the classifier mask field has the first four LSB bits set to 1, thereby indicating that the first four fields (version, IPsec protocol, destination IP address, and SPI) need to be matched in the MSDU for filtering traffic carried through the IPsec SA.

[0062] Example 11 may include Examples 9 and 10, where the version field indicates the IP protocol version, set to 4 for IPv4 and 6 for IPv6.

[0063] Example 12 may include Examples 9 and 10, wherein the IPsec protocol field indicates the value of the protocol in the outer IP header or the next header parameter, thereby indicating that the IPsec protocol is carried in the encapsulated packet. The IPsec protocol field is set to 50 for ESP (Encapsulated Security Payload, RFC 4303) and to 51 for AH (Authentication Header, RFC 4302).

[0064] Example 13 may include Examples 9 and 10, wherein the destination IP address field is the destination address from the external IP header and refers to the endpoint that will receive and process IPsec packets.

[0065] Example 14 may include Examples 9 and 10, where the SPI field indicates an index of security parameters associated with the IPsec security association. The SPI field is included in the ESP or AH protocol header.

[0066] Example 15 may include Examples 9 and 10, wherein the IPsec SA direction field indicates the uplink or downlink direction of the service carried through the IPsec security association and is used to establish an appropriate filter for filtering uplink and downlink IPsec SA services.

[0067] Example 16 may include Example 15, wherein the IPsec SA direction field is set to a value of 0 to indicate that the uplink IPsec SA carries uplink traffic, and is set to a value of 1 to indicate that the downlink IPsec SA carries downlink traffic.

[0068] An abstract is provided to comply with Section 1.72(b) of 37 C.FR, which requires that an abstract be provided to allow the reader to determine the nature and essential points of the technical disclosure. It is understood at the time of filing that it will not be used to limit or interpret the scope or meaning of the claims. The following claims are hereby incorporated into the detailed description, each claim representing a separate embodiment.

Claims

1. An apparatus configured for operation of a station (STA) in a wireless local area network (WLAN), the apparatus comprising: Processing circuits and memory, In order to carry 5G QoS service flows via IPsec Security Association (SA) within the WLAN network, the processing circuit is configured as follows: The frame is encoded to include a Service Classification (TCLAS) element containing a Frame Classifier field, wherein the Frame Classifier field includes a Classifier Type subfield and a Classifier Parameter subfield. To identify and filter 5G QoS service flows carried through the IPsec SA, the processing circuitry is configured to: set the classifier type subfield to a predetermined value to indicate that the IPsec SA parameter is included in the classifier parameter subfield, and include a Security Parameter Index (SPI), a destination IP address, and the IPsec protocol within the classifier parameter subfield, wherein the classifier parameter subfield is further encoded to include an IPsec SA direction field indicating the direction of the 5G QoS service flow carried through the IPsec SA; and The STA is configured to send the frame via the WLAN as part of a 5G QoS service flow.

2. The apparatus according to claim 1, wherein, When establishing an IPsec SA for a 5G QoS service flow over a WLAN, the processing circuitry is configured to: encode the frame according to the Encapsulated Secure Payload (ESP) security protocol, wherein the ESP header is encoded to include an SPI field containing the SPI, and The destination IP address is derived from the external IP header and refers to the destination address of the endpoint used to receive and process IPsec packets.

3. The apparatus according to claim 2, wherein, The frame classifier field also includes a classifier mask subfield before the classifier parameter subfield, and The processing circuit is configured to encode the classifier mask subfield to indicate that the first four fields of the classifier parameter subfield will be matched in the frame for filtering services carried through the IPsec SA.

4. The apparatus according to claim 3, wherein, The first four fields of the classifier parameter subfield include an IP protocol version field, a field indicating the IPsec protocol, a field indicating the destination IP address, and a field indicating the SPI associated with the IPsec SA. The IP protocol version field indicates whether the IP protocol version is IPv4 or IPv6.

5. The apparatus according to claim 4, wherein, The field used to indicate the IPsec protocol is a value used for the IPsec protocol, and The processing circuit is configured to set the field used to indicate the IPsec protocol to 50 for the Encapsulated Security Payload (ESP), or to set it to 51 for the Authentication Header (AH).

6. The apparatus according to claim 1, wherein, The processing circuit is configured to set the classifier type subfield to the value 11 to indicate that the IPsec SA parameter is included in the classifier parameter subfield, and The processing circuit is configured to set the classifier type subfield to a value from 0 to 10 to indicate non-IPsec SA classifier parameters.

7. The apparatus according to claim 6, wherein, The processing circuit is configured to establish a 5G QoS service flow for the IPsec SA. The STA is configured as part of a user equipment (UE) configured to operate in a 5G network, and the STA includes a 5G QoS entity. The device also includes an NWu interface for connecting to a 5G core network with non-access stratum (NAS) functionality.

8. The apparatus according to claim 7, wherein, Establish the IPsec SA between the Non-3GPP Interoperability Function (N3IWF) or Trusted Non-3GPP Gateway Function (TNGF) and the UE, and The TCLAS element is configured to provide service filtering information for 5G QoS service flows carried by the IPsec SA established between the N3IWF or the TNGF and the UE.

9. The apparatus according to claim 1, wherein, The processing circuitry includes a baseband processor, and the memory is configured to store the TCLAS elements.

10. A non-transitory computer-readable storage medium storing instructions executed by processing circuitry of a station (STA) configured to operate in a wireless local area network (WLAN), wherein, In order to carry 5G QoS service flows via IPsec Security Association (SA) within the WLAN network, the processing circuitry is configured to: The frame is encoded to include a Service Classification (TCLAS) element containing a Frame Classifier field, wherein the Frame Classifier field includes a Classifier Type subfield and a Classifier Parameter subfield. To identify and filter 5G QoS service flows carried through the IPsec SA, the processing circuitry is configured to: set the classifier type subfield to a predetermined value to indicate that the IPsec SA parameter is included in the classifier parameter subfield, and include a Security Parameter Index (SPI), a destination IP address, and the IPsec protocol within the classifier parameter subfield, wherein the classifier parameter subfield is further encoded to include an IPsec SA direction field indicating the direction of the 5G QoS service flow carried through the IPsec SA; and The STA is configured to send the frame via the WLAN as part of a 5G QoS service flow.

11. The non-transitory computer-readable storage medium according to claim 10, wherein, When establishing the IPsec SA for a 5G QoS service flow over a WLAN, the processing circuitry is configured to: encode the frame according to the Encapsulated Secure Payload (ESP) security protocol, wherein the ESP header is encoded to include an SPI field containing the SPI, and The destination IP address is derived from the external IP header and refers to the destination address of the endpoint used to receive and process IPsec packets.

12. The non-transitory computer-readable storage medium according to claim 11, wherein, The frame classifier field also includes a classifier mask subfield before the classifier parameter subfield, and The processing circuit is configured to encode the classifier mask subfield to indicate that the first four fields of the classifier parameter subfield will be matched in the frame for filtering services carried through the IPsec SA.

13. The non-transitory computer-readable storage medium according to claim 12, wherein, The first four fields of the classifier parameter subfield include an IP protocol version field, a field indicating the IPsec protocol, a field indicating the destination IP address, and a field indicating the SPI associated with the IPsec SA. The IP protocol version field indicates whether the IP protocol version is IPv4 or IPv6.

14. The non-transitory computer-readable storage medium according to claim 13, wherein, The field used to indicate the IPsec protocol is a value used for the IPsec protocol, and The processing circuit is configured to set the field used to indicate the IPsec protocol to 50 for the Encapsulated Security Payload (ESP), or to set it to 51 for the Authentication Header (AH).

15. The non-transitory computer-readable storage medium according to claim 10, wherein, The processing circuit is configured to set the classifier type subfield to the value 11 to indicate that the IPsecSA parameter is included in the classifier parameter subfield, and The processing circuit is configured to set the classifier type subfield to a value from 0 to 10 to indicate non-IPsec SA classifier parameters.

16. The non-transitory computer-readable storage medium according to claim 15, wherein, The processing circuit is configured to establish a 5G QoS service flow for the IPsec SA. The STA is configured as part of a user equipment (UE) configured to operate in a 5G network, and the STA includes a 5G QoS entity. The instructions also configure an NWu interface for connecting to a 5G core network with non-access stratum (NAS) functionality.

17. A method performed by processing circuitry of a station (STA) configured to operate in a wireless local area network (WLAN), wherein, To carry 5G QoS service flows via IPsec Security Association (SA) within the WLAN network, the method includes: The frame is encoded to include a Service Classification (TCLAS) element containing a Frame Classifier field, wherein the Frame Classifier field includes a Classifier Type subfield and a Classifier Parameter subfield. To identify and filter 5G QoS service flows carried through the IPsec SA, the method includes: setting the classifier type subfield to a predetermined value to indicate that IPsec SA parameters are included in the classifier parameter subfield, and including a Security Parameter Index (SPI), a destination IP address, and an IPsec protocol within the classifier parameter subfield, wherein the classifier parameter subfield is further encoded to include an IPsec SA direction field indicating the direction of the 5G QoS service flow carried through the IPsec SA; and The STA is configured to send the frame via the WLAN as part of a 5G QoS service flow.

18. The method of claim 17, further comprising: Establish the IPsec SA for 5G QoS service flows over WLAN; as well as The frame is encoded according to the Encapsulated Secure Payload (ESP) security protocol, wherein the ESP header is encoded to include the SPI field containing the SPI.