Authentication and authorization for user equipment (UE) relays to the network
By using relay UEs to provide access services to remote UEs in 5G systems, the authentication and authorization issues of remote UEs outside the radio coverage area are resolved, enabling secure network access for devices with limited coverage.
Patent Information
- Application Number
- CN202080102796.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-05-13
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2040-05-13
AI Technical Summary
In 5G wireless telecommunications systems, remote user equipment (remote UE) cannot directly access the network when it is outside the radio coverage area, resulting in problems with authentication and authorization.
By relaying UEs to provide access services to remote UEs within radio coverage, the relay network entity performs authentication and authorization, including receiving the remote UE's identifier, relay signaling, and authentication process, to ensure the secure transmission of information by the remote UE.
It enables network access authentication and authorization for remote UEs outside of radio coverage, ensuring network security and reliability, and is suitable for communication needs of devices with limited coverage, such as public security forces.
Smart Images

Figure CN116034595B_ABST
Abstract
Description
Technical Field
[0001] Some example embodiments may generally relate to mobile or wireless telecommunication systems, such as Long Term Evolution (LTE) or 5G radio access technologies or New Radio (NR) access technologies, or may relate to other communication systems. For example, some embodiments may relate to systems and / or methods for authentication and authorization of user equipment (UE) relays to a network. Background Technology
[0002] Examples of mobile or wireless telecommunications systems can include Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (UTRAN), Evolved UTRAN (E-UTRAN) for Long Term Evolution (LTE), LTE-A Advanced, MulteFire, LTE-A Pro, and / or 5G or New Radio (NR) access technologies. 5G wireless systems refer to next-generation (NG) radio systems and network architectures. 5G is primarily built on New Radio (NR), but 5G (or NG) networks can also be built on E-UTRA radio. NR is estimated to provide bit rates of 10-20 Gbit / s or higher and can at least support enhanced mobile broadband (eMBB), ultra-reliable low-latency communication (URLLC), and massive machine-type communication (mMTC). NR promises to provide ultra-wideband and ultra-robust low-latency connectivity and massive networks to support the Internet of Things (IoT). As IoT and machine-to-machine (M2M) communication become increasingly prevalent, the need for networks capable of meeting the requirements of low power consumption, low data rates, and long battery life will continue to grow. Note that in 5G, a node that can provide radio access to user equipment (i.e., similar to a NodeB in UTRAN or an eNB in LTE) can be named gNB when it is established on an NR radio, and NG-eNB when it is established on an E-UTRA radio. Summary of the Invention
[0003] According to a first embodiment, a method may include receiving an identifier of a remote UE by a relay UE. The relay UE may be within the radio coverage area of a network and may provide network access to a remote UE outside the radio coverage area. The method may include providing a first request to a relay network entity for authorization and authentication of the relay remote UE. The first request may include the identifier of the remote UE. The relay network entity may be associated with a serving network of the relay UE. The method may include relaying signaling between the remote UE and the serving network of the relay UE when signaling is associated with authenticating the remote UE. The method may include receiving a response associated with the first request. The response may include information identifying the result of the first request or security information to be used in association with the relay remote UE.
[0004] In one variant, the identifier of the remote UE may include a Subscription Hidden Identifier (SUCI). In one variant, the relay network entity may include an Access and Mobility Management Function (AMF). In one variant, the Non-Access Stratum (NAS) message may include a first request for authorization and authentication or a response associated with the first request. In one variant, the result of the first request may indicate that the first request has been accepted. In one variant, the method may further include relaying data received via the connection to the relay network entity based on the acceptance of the first request.
[0005] According to a second embodiment, a method may include receiving, by a first relay network entity, a first request for authorization to relay a remote UE for a relay UE. The first request may include an identifier of the remote UE. The relay UE may be within the radio coverage area of the network and may provide network access to a remote UE outside the radio coverage area. The method may include providing the first request for authorization to a second relay network entity. The first request may include an identifier of the remote UE and an identifier of the relay UE. The second relay network entity may be associated with the home network of the relay UE. The method may include relaying a second request for authentication of the remote UE between the relay UE and the second relay network entity. The method may include receiving a response associated with the first request for authorization or the second request for authentication. The response may include information identifying the result of the first request or the second request, or security information associated with the relaying of the remote UE. The method may include providing the response to the relay UE.
[0006] In one variant, the identifier of the remote UE may include a SUCI. In one variant, the identifier of the relay UE may include at least one of a Subscription Permanent Identifier (SUPI) or a General Public Subscription Identifier (GPSI). In one variant, the first relay network entity may include an AMF. In one variant, the second relay network entity may include an Authentication Server Function (AUSF). In one variant, the result of the first request may indicate that the first request has been rejected. In one variant, the result of the first request may indicate that the first request has been accepted.
[0007] According to a third embodiment, a method may include receiving, by a first relay network entity, a first request for authorization and authentication for relay UE to relay a remote UE. The first request may include an identifier of the remote UE and an identifier of the relay UE. The method may include ensuring that the remote UE is authenticated and authorized to be relayed by the relay UE. The method may include providing a response to a second relay network entity based on a configuration indicating whether the relay UE is permitted to relay the remote UE, the second relay network entity having issued the first request for authorization and authentication for relay UE to relay the remote UE.
[0008] In one variation, determining that the remote UE is authenticated and authorized may include providing a second request to the remote network entity authorizing the remote UE to be relayed by the relay UE when the remote UE and the relay UE have different home networks or when the remote UE cannot be served by the first relay network entity. In one variation, the remote network entity may be associated with the home network associated with the remote UE. In one variation, determining that the remote UE is authenticated and authorized may include relaying a third request associated with authenticating the remote UE between the first relay network entity and the remote network entity when the remote UE and the relay UE have different home networks or when the remote UE cannot be served by the first relay network entity. In one variation, determining that the remote UE is authenticated and authorized may include receiving a response associated with the second or third request when the remote UE and the relay UE have different home networks or when the remote UE cannot be served by the first relay network entity. In one variation, the response may include information identifying the result of the second or third request, the identity of the remote UE, or security information associated with the relaying of the remote UE.
[0009] In one variant, the identifier of the remote UE may include SUCI. In one variant, the identifier of the relay UE may include at least one of SUPI or GPSI. In one variant, the first relay network entity may include AUSF. In one variant, the second relay network entity may include AMF. In one variant, the first request may be received from the second network entity. In one variant, the remote network entity may include AUSF.
[0010] In one variant, the result of the first request may indicate that the first request has been rejected. In another variant, the result of the first request may indicate that the first request has been accepted. In one variant, the method may include determining whether the configuration indicates that the relay UE is allowed to relay remote UEs based on information from a unified data management (UDM) function or from an authentication, authorization, and accounting (AAA) server.
[0011] In one variant, when the remote UE and the relay UE have the same home network, determining that the remote UE is authenticated and authorized may include authenticating the remote UE via the relay serving network entity. In another variant, when the remote UE and the relay UE have the same home network, determining that the remote UE is authenticated and authorized may include determining whether the configuration indicates that the remote UE is allowed to be relayed by the relay UE. In yet another variant, when the remote UE and the relay UE have the same home network, determining that the remote UE is authenticated and authorized may include exchanging signaling with the remote UE to perform authentication and authorization of the remote UE via the relay UE's serving network and the relay UE. In one variant, the serving network of the relay UE and the indication used by the relay UE may be associated with the relaying of signaling.
[0012] According to a fourth embodiment, a method may include receiving a request for authorization and authentication of a remote UE relayed by a relay UE. The request may include an identifier of the remote UE and an identifier of the relay UE. The relay UE may be within the radio coverage area of the network and may provide network access to a remote UE outside the radio coverage area. The method may include authenticating the remote UE via a relay home network entity. The method may include receiving information from another remote network entity identifying whether the remote UE is permitted to be relayed by the relay UE. The method may include providing a response associated with the authorization request to the relay network entity. The response may include information identifying the result of the request, the identity of the remote UE, or security information associated with the relaying of the remote UE.
[0013] In one variant, the identifier of the remote UE may include SUCI. In one variant, the identifier of the relay UE may include at least one of SUPI or GPSI. In one variant, the remote network entity may include AUSF. In one variant, the relay network entity may include AUSF.
[0014] In one variant, the result of the request may indicate that the request has been rejected. In another variant, the result of the request may indicate that the request has been accepted. In yet another variant, the method may further include determining whether the remote UE is permitted to be relayed by the relay UE.
[0015] In one variant, the method may include providing a response based on determining that the remote UE is permitted to be relayed by the relay UE. In one variant, the method may include determining whether the remote UE is permitted to be relayed by the relay UE based on information from a UDM function or an AAA server. In one variant, the method may include authenticating the remote UE. In one variant, the method may include generating security material based on the result of authenticating the remote UE.
[0016] The fifth embodiment may relate to an apparatus including at least one processor and at least one memory containing computer program code. The at least one memory and the computer program code may be configured, together with the at least one processor, to cause the apparatus to perform at least the method according to the first embodiment, the second embodiment, the third embodiment, or the fourth embodiment, or any variation thereof.
[0017] The sixth embodiment may relate to an apparatus that may include a circuit system configured to perform the method according to the first, second, third, or fourth embodiment, or any of the variations thereof.
[0018] The seventh embodiment may relate to an apparatus that may include components for performing the method according to the first embodiment, the second embodiment, the third embodiment, or the fourth embodiment, or any variation thereof.
[0019] The eighth embodiment may relate to a computer-readable medium including program instructions stored thereon for performing at least the method according to the first, second, third, or fourth embodiment, or any variation thereof.
[0020] The ninth embodiment may relate to a computer program product with coded instructions for performing at least the method according to the first embodiment, the second embodiment, the third embodiment, or the fourth embodiment, or any variation thereof. Attached Figure Description
[0021] To correctly understand the exemplary embodiments, reference should be made to the accompanying drawings, in which:
[0022] Figure 1 An example architecture model of a proximity-based service (ProSe) 5G UE to network layer 3 (L3) solution is shown according to some embodiments;
[0023] Figure 2 An example architecture model is shown that uses a ProSe 5G UE to network L3 relay solution according to some embodiments and uses non-3GPP interoperability function (N3IWF);
[0024] Figure 3 An example protocol stack for a ProSe 5G UE-to-network L3 relay solution according to some embodiments is shown;
[0025] Figure 4 Examples of ProSe functional interfaces to other network elements and Public Land Mobile Networks (PLMNs) according to some embodiments are shown;
[0026] Figure 5Example signal diagrams illustrating authentication and authorization for UE-to-network relay according to some embodiments are shown;
[0027] Figure 6 An example flowchart of a method according to some embodiments is shown;
[0028] Figure 7 An example flowchart of a method according to some embodiments is shown;
[0029] Figure 8 An example flowchart of a method according to some embodiments is shown;
[0030] Figure 9 An example flowchart of a method according to some embodiments is shown;
[0031] Figure 10a An example block diagram of a device according to one embodiment is shown; and
[0032] Figure 10b An example block diagram of a device according to another embodiment is shown. Detailed Implementation
[0033] It will be readily understood that components of certain example embodiments, as generally described and illustrated in the accompanying drawings, can be arranged and designed in a variety of different configurations. Therefore, the following detailed description of some example embodiments of systems, methods, apparatuses, and computer program products for authentication and authorization of UE-to-network relays is not intended to limit the scope of any particular embodiment, but rather represents selected example embodiments.
[0034] Features, structures, or characteristics of the exemplary embodiments described throughout this specification may be combined in any suitable manner in one or more exemplary embodiments. For example, the use of the phrases “some embodiments,” “a few embodiments,” or other similar language throughout this specification means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment. Therefore, the appearance of the phrases “some embodiments,” “in some embodiments,” “in other embodiments,” or other similar language throughout this specification does not necessarily refer to the same set of embodiments, and the described features, structures, or characteristics may be combined in any suitable manner in one or more exemplary embodiments. Furthermore, the phrase “a set of…” refers to a set that includes one or more members of the referenced set. Therefore, the phrases “a set of…,” “one or more of…,” and “at least one of…” or equivalent phrases may be used interchangeably. In addition, unless expressly stated otherwise, “or” is intended to mean “and / or.”
[0035] Additionally, if necessary, the different functions or operations discussed below may be performed in different orders and / or simultaneously with each other. Furthermore, if necessary, one or more of the described functions or operations may be optional or may be combined. Therefore, the following description should be regarded only as illustrating the principles and teachings of certain example embodiments, and not as limiting it.
[0036] ProSe UE-to-Network Relay can include a relay mechanism in which a UE provides functionality to support connectivity to the network for (multiple) remote UEs (e.g., (multiple) UEs are outside radio coverage and cannot directly access the 3GPP radio network and therefore may require the service of at least one other UE within radio coverage (referred to as "UE-to-Network Relay" or "Relay UE") to reach the 3GPP radio network). The relay UE (ProSe UE-to-Network Relay) can have connectivity to a 5G system (5GS) and can relay control plane (CP) signaling and user plane (UP) traffic for (multiple) remote UEs that cannot obtain direct connectivity to the 5GS. This feature can be useful for members of public safety forces (e.g., firefighters / police). It can also be used for other commercial applications (e.g., wearable devices with limited battery life and / or coverage). ProSe UE-to-Network Relay can have various sets of solutions. One set can include Layer 2 (L2) solutions where the 5G Radio Access Network (RAN) and the relay UE can be modified so that the 5G RAN directly handles remote UEs for both CP and UP. In this scenario, the remote UE can be directly authenticated by 5GS as if it had a direct radio interface. Another approach could be a Layer 3 (L3) solution, where the 5G RAN may be unaware of the remote UE. In this case, the remote UE might not be directly authenticated by 5GS as if it had a direct radio interface. The relay UE may not know whether it is relaying UP or CP data for the remote UE.
[0037] Figure 1 An example architecture model using a proximity-based service (ProSe) 5G UE to network layer 3 (L3) solution according to some embodiments is shown. For example, some embodiments described herein can be applied to... Figure 1The architecture 100 shown herein may include a remote UE, a PC5 interface (e.g., a direct radio interface between two 3GPP UEs), a ProSe UE-to-network relay (relay UE), a Uu interface (e.g., a 3GPP radio interface between a 3GPP UE and an NG RAN), a next-generation RAN (NG-RAN), a 5G core (5GC), an N6 interface (e.g., a user plane interface between the 3GPP-defined 5G core (5GC) and the data network), and an application server (AS). Some embodiments described herein can solve... Figure 1 The architecture shown offers security but can be applied to any L3 solution that supports UE-to-network relay (including baseline L3 UE-to-network relay solutions described in certain technical specifications). For example, some embodiments described herein can resolve remote UE authentication before establishing a PC5 connection between the remote UE and the relay UE, can check whether the remote UE accepts relaying by the relay UE, can check whether the relay UE accepts relaying the remote UE, can facilitate the potential creation of private security keys via PC5, and so on.
[0038] As mentioned above, Figure 1 Provided as an example. Other examples are possible based on some embodiments.
[0039] Figure 2 An example architecture model using ProSe 5G UE to network L3 relay solution and N3IWF is shown according to some embodiments. For example, Figure 2 An architecture 200 in which some of the embodiments described herein may be implemented is shown. As shown, architecture 200 may include a remote UE, a PC5 interface, a trunk UE, a Uu interface, an NG-RAN, a trunk 5GC, a UPF (associated with the trunk UE), an N6 interface, a remote 5GC, an N3IWF, an NG-RAN, and a UPF (associated with the remote UE). Figure 3 An example protocol stack for a ProSe 5G UE-to-network L3 relay solution according to some embodiments is shown. For example, Figure 3 Protocol stack 300 is shown.
[0040] about Figure 2 and Figure 3 The 5GC serving a relay UE and the 5GC serving a remote UE can correspond to the same 5GC network; however, some embodiments described herein can also be applied to architectures in which they are associated with different networks or different slices of the same network. For example, as Figure 2 As shown, the 5GC (Serving and Home) of a remote UE can be a network other than the 5GC (Serving and Home) of a relay UE. Figure 2 and Figure 3In this context, the HPLMN (Home Network) and Serving PLMN (Visited Network) of remote UEs and relay UEs are not separated, and certain embodiments can be applied to contexts where such separation exists. While some embodiments described herein can address... Figure 2 and Figure 3 While ensuring the security of the architecture, certain embodiments can be applied to any L3 solution that supports UE-to-network relay (including baseline L3 UE-to-network relay solutions already described in some technical specifications). A User Plane Function (UPF) (for a relay UE) can represent the Protocol Data Unit (PDU) Session Anchor (PSA) of the relay UE, and a UPF (for a remote UE) can represent the PSA of the remote UE.
[0041] about Figure 3 Specifically, in the case of Internet Protocol version 4 (IPv4), the relay UE can assign an IPv4 address to a remote UE, and the relay UE can perform Network Address and Port Translation (NAPT) between IP-based service TCP or UDP / IP on the PC5 and Uu interfaces. For downlink (DL) services, the relay UE can use the IP port to determine the IP addressing information and PC5 link used to reach the remote UE. The relay UE may not know whether it is relaying a UP or CP for a remote UE. Still, regarding Figure 3 In the case of IPv6, a relay UE can request a prefix shorter than 64 bits and can allocate a 64-bit IPv6 prefix to a remote UE from the prefix range received from the network.
[0042] As mentioned above, Figure 2 and Figure 3 Provided as an example. Other examples are possible based on some embodiments.
[0043] Figure 4 Examples of ProSe functional interfaces to other network elements and Public Land Mobile Networks (PLMNs) according to some embodiments are shown. For example, Figure 4 Architecture 400 is shown, including various interfaces (e.g., PC2, PC4a, PC4b, PC6, and PC7 interfaces). The ProSe architecture 400 may have been specified for 4G / LTE in some technical specifications, and the security procedures may have been specified in other technical specifications. This architecture can define L3 relays and ProSe functions within the network. ProSe-enabled UEs and ProSe functions can authenticate each other. Authentication of remote UEs and key booting for ProSe functions can be performed using Generic Boot Architecture (GBA) elements specified in some technical specifications. Booting can be performed using a Boot Server (BSF) within the GBA framework.
[0044] The ProSe functionality can include three main sub-functions, which play different roles depending on the ProSe characteristics. For example, a sub-function might include a Direct Provisioning Function (DPF), which can be used to provide the UE with the necessary parameters for ProSe Direct Discovery and ProSe Direct Communication. As another example, a sub-function might include a Direct Discovery Name Management Function, which can be used to enable ProSe Direct Discovery by allocating and processing the mapping between ProSe Application Identifiers (IDs) and ProSe Application Codes used in ProSe Direct Discovery. Evolved Packet Core (EPC) level ProSe discovery functions can have reference points pointing to the AS (PC2 interface), other ProSe functions (PC6 interface), the Home Subscriber Server (HSS) (PC4a interface), and the UE (PC3 interface). In previous solutions, UE authentication was performed via the PC4a interface.
[0045] As mentioned above, Figure 4 Provided as an example. Other examples are possible based on some embodiments.
[0046] Some embodiments described herein can provide the creation of PC5 connections between remote UEs and relay UEs (examples of PC5 interfaces are provided in...). Figure 1 and Figure 2 (As shown in the diagram). A remote UE can provide a relay UE with a request for relaying and its own identifier (e.g., a Subscription Hidden Identifier (SUCI)), and the relay UE can forward this identifier to the network, enabling the network to authenticate the remote UE. The network can check the authorization for using the relay UE and / or the authorization for relaying the remote UE (e.g., it can check whether both the remote UE and the relay UE have a configuration that allows relaying). For authentication and authorization, the Access and Mobility Management Function (AMF) associated with the relay UE can forward this message between the remote UE and the Authentication Server Function (AUSF) of the remote UE. In this way, some embodiments described herein can address certain security issues related to the relaying of remote UEs.
[0047] Figure 5 Example signal diagrams illustrating authentication and authorization for UE-to-network relay according to some embodiments are shown. For example, Figure 5The diagram illustrates a remote UE, a relay UE, an NG-RAN, a relay AMF (e.g., an AMF serving a relay UE), a relay ASF (e.g., an ASF that can serve a relay UE), a relay unified data management (UDM) (e.g., a UDM that accesses subscription information for a relay UE) / authentication, authorization, and accounting server (AAA) (e.g., an AAA that controls services for a relay UE), a remote ASF (e.g., an ASF that can serve a remote UE), and a remote UDM / AAA. A relay AMF, ASF, and UDM / AAA can be associated with a relay UE (e.g., associated with the same serving network as the relay UE), and a remote ASF and UDM / AAA can be associated with a remote UE (e.g., associated with the same network as the remote UE). A remote UE can be associated with a different serving network (e.g., a different serving PLMN) than a relay UE. For example, a remote UE can be associated with a first visited PLMN (VPLMN), and a relay UE can be associated with a second VPLMN.
[0048] As shown in 500, a relay UE can perform a registration procedure for itself. In this operation, one or more AMFs may have already been assigned to the relay UE in its serving network. Similarly, one or more ASFs may have already been identified in the relay UE's home network. As shown in 502, a remote UE and a relay UE can perform procedures for PC5 establishment. For example, the remote UE may provide a request to the relay UE to relay the remote UE. The remote UE may provide the relay UE with its identifier (e.g., SUCI). The procedure at 502 can be associated with establishing a PC5 connection to the relay UE.
[0049] As shown in 504, a relay UE can provide a request to the relay AMF to authorize the relay of the remote UE. This request may include a Non-Access Stratum (NAS) message. The request may include the identifier of the remote UE (e.g., SUCI).
[0050] In this way, the relay UE can contact its AMF and request authorization for the relay remote UE by providing the SUCI of the remote UE, and some embodiments may include NAS signaling (e.g., based on the PUCI of the remote UE) that defines the request to authorize the relay remote UE. In some embodiments, NAS messages may be exchanged between the relay UE and its serving network.
[0051] As shown in 506, the AMF relay can provide a request to the relay AFS for authorization to relay the remote UE. This request may include the identifier of the remote UE (e.g., SUCI) and / or the identifier of the relay UE (e.g., Subscription Persistent Identifier (SUPI) or General Public Subscription Identifier (GPSI)). In this way, the AMF can send a request for authorization to relay the remote UE to the AFS in the relay UE's HPLMN by providing the relay UE's SUPI and GPSI, as well as the remote UE's SUCI. This may include defining new NAUSF services related to providing authorization for relaying the remote UE (e.g., utilizing the remote UE's SUCI and / or the relay UE's SUPI and GPSI).
[0052] As shown in 508, the relay AUSF can provide a request for authorization of a remote UE to be relayed by the relay UE. This request may include the identifier of the remote UE (e.g., SUCI) and / or the identifier of the relay UE (e.g., GPSI). In this way, the relay UE's AUSF can forward the request to the AUSF of the remote UE's HPLMN (determined based on the home network identifier and / or routing identifier of the remote UE's SUCI). This may include defining a new NAUSF service where authorization for relaying the remote UE is provided (e.g., based on the remote UE's SUCI and / or the relay UE's GPSI). The operation shown in 508 can be applied when the relay UE's AUSF cannot handle the authentication and authorization of the remote UE (e.g., when the relay UE and the remote UE have different home PLMNs). The relay AUSF can use the Mobile Country Code (MCC) / Mobile Network Code (MNC) of the remote UE's SUCI and the MCC / MNC of the relay UE's SUPI to determine whether the relay UE and the remote UE both originate from the same home network (HPLMN). When the AUSF of the relay UE can handle the authentication and authorization of the remote UE, the AUSF of the relay UE can support its interaction in 510 and 512.
[0053] As shown in 510, a remote AUSF can perform authentication of a remote UE. This can include multiple exchanges between the remote UE's AUSF and the remote UE. For example, exchanges related to this authentication process can be relayed by the relay UE's AUSF and AMF, and through the relay UE. These exchanges can be identified in a way that makes the relay UE aware that the authentication process is not aimed at itself, i.e., the relay UE, but at the remote UE. Since the relay UE's AMF can reject requests from the remote UE's AUSF (e.g., in the absence of a service protocol between the relay UE's serving network and the remote UE's home network), the authentication flow may have to pass through the relay UE's AUSF. In this way, the remote UE's AUSF can authenticate the remote UE. Authentication can be performed transparently by the relay UE's AUSF and AMF, and through the relay UE: the relay UE's AUSF and AMF, and the relay UE, transparently relay authentication-related signaling without understanding (e.g., processing, evaluating, etc.) the relayed authentication-related messages. Some or portions of these messages may be encrypted (or partially encrypted) and can only be decrypted by the remote UE and the remote AUSF. This may include new NAS signaling between the relay UE and its AMF. At the end of the authentication process, the AUSF may have already determined the remote UE's SUPI and GPSI. Both the remote UE and its AUSF can determine security (e.g., encryption) materials based on the remote UE's authentication. Security materials (e.g., encryption) may be used for PC5 security.
[0054] As shown in 512, the remote AUSF and the remote UDM / AAA can communicate to check whether relaying is authorized or permitted by the configuration associated with the remote UE. For example, this check can be performed using the GPSI of the relay UE and / or the GPSI of the remote UE, or using one or more other identifiers associated with the relay UE and / or the remote UE. As an example alternative, the AUSF can request the UDM to check the subscription data of the remote UE to determine whether the remote UE (identified by its SUPI) accepts relaying from the relay UE (identified by its GPSI). As another example alternative, the HPLMN can have a policy from a third-party AAA server (identified by the domain portion of the remote UE's GPSI) to check whether the remote UE (identified by its GPSI) accepts relaying from the relay UE (identified by its GPSI).
[0055] As shown in 514, the remote AUSF can provide the relay AUSF with a response authorizing the relayed remote UE. This response can identify the result of the request (e.g., whether the request was accepted or rejected), the identity of the remote user equipment (UE), and the security materials to be used in conjunction with the relay (e.g., passwords, public-private key pairs, hashes, etc.). This response can be included in the NAUSF message. In this way, assuming the check at 512 is positive, the remote UE's AUSF can respond to the request to provide authorization for the relayed remote UE from the relay UE's HPLMN's AUSF. The remote AUSF can provide the result and can provide the security materials derived from the remote UE's authentication as described above.
[0056] As shown in 516, the relay AUSF and the relay UDM / AAA can communicate to check whether the relay is authorized or permitted by a configuration associated with the remote UE. For example, this check can be performed using the GPSI of the relay UE and / or the GPSI of the remote UE, or using one or more other identifiers associated with the relay UE and / or the remote UE. In this way, the relay UE's AUSF can check whether the relay is authorized from the relay UE side. This may require one or more different alternatives. One alternative may include the AUSF requesting the UDM to check the relay UE's subscription data to determine whether the relay UE (identified by its SUPI) accepts the remote UE (identified by its GPSI). As another alternative, the HPLMN may have a policy for checking from a third-party AAA server (identified by the domain portion of the relay UE's GPSI) whether the relay UE (identified by its GPSI) accepts the relay of the remote UE identified by its GPSI. As mentioned above, this check can be performed in conjunction with a request from the relay AUSF to the remote AUSF.
[0057] As shown in 518, the relay AUSF can provide a response to the relay AMF regarding the authorization of the relayed remote UE. This response can identify the result of the request, the identity of the remote user equipment (UE), security materials to be used in conjunction with the relay, etc. This response can be included in the NAUSF service operation. Assuming the checks in the previous operation were positive, the relay UE's AUSF can respond to the request to provide authorization for the remote UE to be relayed from the relay UE's AMF. The relay AUSF can provide the result and the security materials received above.
[0058] As shown in 520, the relay AMF can provide the relay UE with a response authorizing the relay remote UE. This response can identify the outcome of the request (e.g., whether the request was accepted or rejected), security materials to be used in conjunction with the relay, etc. This response can be included in a NAS message. In this way, the (relay UE's) AMF can send a NAS response authorizing the relay remote UE (e.g., which includes the outcome of the request and / or security materials).
[0059] Assuming the request result indicates that relaying by the relay UE is permitted, the relay UE can perform relaying for the remote UE after receiving the response. For example, the remote UE can provide data and the relay UE can receive data, and the relay UE can provide data to the relay AMF and / or relay AFS. If the answer is negative, the relay UE can either trigger the release of the PC5 connection or maintain the PC5 connection but not activate its UE-to-network relay function.
[0060] The above embodiments can be understood through various example use cases. Although some embodiments are described herein in the context of the relay UE and the remote UE coming from different home networks, one example scenario involves the relay UE and the remote UE having subscriptions to the same HPLMN. In this case, the relay UE can register with the 5GS and obtain services for itself. The remote UE can attempt to establish a PC5 connection to the relay UE. During PC5 establishment, when the remote UE requests relaying from the relay UE to the network in a PC5 message, the remote UE can provide its SUCI to the relay UE. The relay UE can contact its AMF and can request (via a NAS message) authorization for the relay remote UE by providing the remote UE's SUCI. The NAS message can include a registration request, wherein a new registration type is used to reflect that the request is for authentication of the relay remote UE. Alternatively or additionally, the NAS message can include an uplink NAS transport message, wherein a new request type is used to reflect that the request is for authentication of the relay remote UE. Alternatively or additionally, the NAS message can include a new NAS message that can use a request type to reflect that the request is for authentication of the relay remote UE.
[0061] The AMF can identify the AUSSF because it was selected during the initial registration of the relay UE. The AMF can send an authorization request to the AUSSF for the remote UE to act as a relay between the remote UE and the AUSSF. This request can provide the relay UE's SUPI (and / or GPSI or other identifier) and the remote UE's SUCI. The AUSF can use the MCC / MNC of the remote UE's SUCI and the MCC / MCC of the relay UE's SUPI to determine whether the relay UE and the remote UE originate from the same home network (e.g., HPLMN).
[0062] The remote AUSF can authenticate the remote UE via the relay AMF and the relay UE. The AUSF can use the remote UE's SUCI to obtain a certificate for authentication. The relay AUSF can check whether the relay UE is allowed to perform relaying for the remote UE. For this purpose, it can use a UDM and / or an external AAA server. For example, relaying can be allowed when both the remote UE and the relay UE are members of the same International Mobile Subscriber Identity (IMSI) group. The AUSF can provide the authentication and authorization results to the relay AMF. If the answer (e.g., the result of the request) is negative, the relay UE can either trigger the release of the PC5 connection or maintain the PC5 connection but not activate its UE-to-network relay function.
[0063] Some embodiments can support various deployment scenarios. Remote UEs and relay UEs can correspond to different HPLMNs. The relay 5GC (the 5GC of the relay UE) and the remote 5GC (the 5GC of the remote UE) can be the same or different 5GC networks. Certain network entities can check whether to accept a remote UE being relayed by a relay UE. This can be done using the remote UE's UDM subscription data, which may contain information about which relay UEs (e.g., any UE, UEs based on IMSI group members, and / or UEs based on SUPI or GPSI lists) the remote UE accepts as relay UEs. In some embodiments, relaying can be allowed when both the remote UE and the relay UE are members of the same IMSI group. Alternatively or additionally, other embodiments can use HPLMN policies obtainable from a third-party server, where the policy indicates whether a remote UE accepts relaying by a relay UE identified by its Common Public Subscription Identifier (GPSI). During this step, the HPLMN can control whether relaying via the serving PLMN of the relay UE is allowed.
[0064] Some embodiments may check whether a relay UE is accepted as a relay for a remote UE. This can be done using UDM subscription data for the relay UE, which may include information about which remote UEs (e.g., any UE, UEs based on IMSI group members, and / or UEs based on SUPI or GPSI lists) the relay UE accepts for relaying. Alternatively or additionally, this can be done using an HPLMN policy obtainable from a third-party server, where the policy indicates whether the relay UE accepts relaying of remote UEs identified by its GPSI. The relay UE may be served by a VPLMN.
[0065] Some embodiments may include a remote AUSF using remote UE authentication to establish PC5 security material. As part of the remote UE HPLMN's authentication of the remote UE, both the remote AUSF and the remote UE may derive PC5-related security material. This derived security material may be provided back to the relay UE (via the relay UE's AMF) from the remote UE's AUSF, along with authorization for relaying.
[0066] As mentioned above, Figure 5 Provided as an example. Other examples are possible based on some embodiments.
[0067] Some embodiments may not extend the role of ProSe functionality (in EPC) to AMF and AUSF. Instead, AMF can act as a relay, similar to its role in Network Slice-Specific Authentication and Authorization (NSSAA). AUSF can be an entity capable of contacting UDM and / or a third-party AAA server to verify the relay-specific authentication and authorization of the UE to the network (e.g., it contacts a third-party AAA server as part of NSAA). In this way, some embodiments can be extensions of AMF / AUSF functionality. Furthermore, utilizing AMF / NAS and AMF can eliminate the need to define secure communication channels to reach the relay-specific authentication and authorization entity delivering the UE to the network, such as when GBA is not defined for 5GS.
[0068] Figure 6 Example flowcharts of methods according to some embodiments are shown. For example, Figure 6 An example operation of a relay UE (e.g., device 20) is shown. Figure 6 Some of the operations shown can be combined with Figures 1-5 The operation shown is similar.
[0069] In one embodiment, the method may include: at 600, receiving an identifier of a remote UE. The relay UE may be within the radio coverage area of the network and may provide network access to remote UEs outside the radio coverage area. In one embodiment, the method may include: at 602, providing a first request to a relay network entity for authorization and authentication of the relay remote UE. The first request may include the identifier of the remote UE. The relay network entity may be associated with a serving network of the relay UE. In one embodiment, the method may include: at 604, relaying the signaling between the remote UE and the serving network of the relay UE when the signaling is associated with authenticating the remote UE. In one embodiment, the method may include: at 606, receiving a response associated with the first request. The response may include information identifying the result of the first request or security information to be used in association with the relay remote UE.
[0070] In some embodiments, the identifier of the remote UE may include a SUCI. In some embodiments, the relay network entity may include an AMF. In some embodiments, the NAS message may include a first request for authorization and authentication or a response associated with the first request. In some embodiments, the result of the first request may indicate that the first request has been accepted. In some embodiments, the method may further include relaying data received via the connection to the relay network entity based on the acceptance of the first request.
[0071] As mentioned above, Figure 6 Provided as an example. Other examples are possible based on some embodiments.
[0072] Figure 7 Example flowcharts of methods according to some embodiments are shown. For example, Figure 7 An example operation of a relay AMF (first relay network entity) (e.g., a network node hosting the relay AMF (e.g., device 10)) is shown. Figure 7 Some of the operations shown can be combined with Figures 1-5 The operation shown is similar.
[0073] In one embodiment, the method may include: at 700, receiving a first request for authorization to relay a remote UE for a relay UE. The first request may include an identifier of the remote UE. The relay UE may be within the radio coverage area of the network and may provide network access to a remote UE outside the radio coverage area. In one embodiment, the method may include: at 702, providing the first request for authorization to a second relay network entity. The first request may include an identifier of the remote UE and an identifier of the relay UE. The second relay network entity may be associated with the home network of the relay UE. In one embodiment, the method may include: at 704, relaying a second request for authentication of the remote UE between the relay UE and the second relay network entity. In one embodiment, the method may include: at 706, receiving a response associated with the first request for authorization or the second request for authentication. The response may include information identifying the result of the first request or the second request, or security information associated with the relaying of the remote UE. In one embodiment, the method may include: at 708, providing the response to the relay UE.
[0074] In some embodiments, the identifier of the remote UE may include SUCI. In some embodiments, the identifier of the relay UE may include at least one of SUPI or GPSI. In some embodiments, the first relay network entity may include AMF. In some embodiments, the second relay network entity may include AUSF. In some embodiments, the result of the first request may indicate that the first request has been rejected. In some embodiments, the result of the first request may indicate that the first request has been accepted.
[0075] As mentioned above, Figure 7 Provided as an example. Other examples are possible based on some embodiments.
[0076] Figure 8 Example flowcharts of methods according to some embodiments are shown. For example, Figure 8 An example operation of a relay AUSF (first relay network entity) (e.g., a network entity hosting the relay AUSF (e.g., device 10)) is shown. Figure 8 Some of the operations shown can be combined with Figures 1-5 The operation shown is similar.
[0077] In one embodiment, the method may include: at 800, receiving a first request for authorization and authentication for relay UE to relay a remote UE. The first request may include an identifier of the remote UE and an identifier of the relay UE. In one embodiment, the method may include: at 802, ensuring that the remote UE is authenticated and authorized to be relayed by the relay UE (e.g., by performing authentication itself or requesting authentication from another network entity). In one embodiment, the method may include: at 804, providing a response to a second relay network entity based on a configuration indicating whether the relay UE is permitted to relay a remote UE, the second relay network entity having issued the first request for authorization and authentication for relay UE to relay a remote UE.
[0078] In some embodiments, when the remote UE and the relay UE have different home networks or when the remote UE cannot be served by the first relay network entity (e.g., even if the relay UE and the remote UE have the same HPLMN, another AUSF may have to be used), determining that the remote UE is authenticated and authorized may include providing a second request to the remote network entity to authorize the remote UE to be relayed by the relay UE. In some embodiments, the remote network entity may be associated with the home network associated with the remote UE. In some embodiments, when the remote UE and the relay UE have different home networks or when the remote UE cannot be served by the first relay network entity, determining that the remote UE is authenticated and authorized may include relaying a third request associated with authenticating the remote UE between the first relay network and the remote network entity. In some embodiments, when the remote UE and the relay UE have different home networks or when the remote UE cannot be served by the first relay network entity, determining that the remote UE is authenticated and authorized may include receiving a response associated with the second or third request. In some embodiments, the response may include information identifying the result of the second or third request, the identity of the remote UE, or security information associated with the relaying of the remote UE.
[0079] In some embodiments, the identifier of the remote UE may include SUCI. In some embodiments, the identifier of the relay UE may include at least one of SUPI or GPSI. In some embodiments, the first relay network entity may include AUSF. In some embodiments, the second relay network entity may include AMF. In some embodiments, the first request may be received from the second network entity. In some embodiments, the remote network entity may include AUSF.
[0080] In some embodiments, the result of the first request may indicate that the first request has been rejected. In some embodiments, the result of the first request may indicate that the first request has been accepted. In some embodiments, the method may include determining, based on information from the UDM function or from the AAA server, whether the configuration indicates that the relay UE is allowed to relay remote UEs.
[0081] In some embodiments, when the remote UE and the relay UE have the same home network, determining that the remote UE is authenticated and authorized may include authenticating the remote UE via the relay serving network entity. In some embodiments, determining that the remote UE is authenticated and authorized may include determining whether the configuration indicates that the remote UE is allowed to be relayed by the relay UE. In some embodiments, determining that the remote UE is authenticated and authorized may include exchanging signaling with the remote UE to perform authentication and authorization of the remote UE via the relay UE's serving network and the relay UE. In some embodiments, the service network of the relay UE and the indication used by the relay UE may be associated with the relaying of signaling.
[0082] As mentioned above, Figure 8 Provided as an example. Other examples are possible based on some embodiments.
[0083] Figure 9 Example flowcharts of methods according to some embodiments are shown. For example, Figure 9 An example operation of a remote AUSF (remote network entity) (e.g., a network node hosting a remote AUSF (e.g., device 10)) is shown. Figure 9 Some of the operations shown can be combined with Figures 1-5 Some of the operations shown are similar.
[0084] In one embodiment, the method may include: at 900, receiving an authorization and authentication request for a remote UE relayed by a relay UE. The request may include an identifier of the remote UE and an identifier of the relay UE. The relay UE may be within the radio coverage area of the network and may provide network access to a remote UE outside the radio coverage area. In one embodiment, the method may include: at 902, authenticating the remote UE via a relay home network entity (e.g., the remote UE's AFS may authenticate a remote UE that exchanges signaling via the relay UE's AFS (which itself uses the relay UE's AMF and then uses the relay UE to reach the remote UE)). In one embodiment, the method may include: at 904, receiving information identifying whether the remote UE is permitted to be relayed by the relay UE (e.g., received from another remote network entity). In one embodiment, the method may include: at 906, providing a response associated with the authorization request to the relay network entity. The response may include information identifying the result of the request, the identity of the remote UE, or security information associated with the relaying of the remote UE.
[0085] In some embodiments, the identifier of a remote UE may include SUCI. In some embodiments, the identifier of a relay UE may include at least one of SUPI or GPSI. In some embodiments, a remote network entity may include AUSF. In some embodiments, a relay network entity may include AUSF.
[0086] In some embodiments, the result of the request may indicate that the request has been rejected. In some embodiments, the result of the request may indicate that the request has been accepted. In some embodiments, the method may further include determining whether the remote UE is permitted to be relayed by the relay UE.
[0087] In some embodiments, the method may include providing a response based on determining that the remote UE is permitted to be relayed by the relay UE. In some embodiments, the method may include determining whether the remote UE is permitted to be relayed by the relay UE based on information from a UDM function or an AAA server. In some embodiments, the method may include authenticating the remote UE. In some embodiments, the method may include generating security material based on the result of authenticating the remote UE.
[0088] As mentioned above, Figure 9 Provided as an example. Other examples are possible based on some embodiments.
[0089] Figure 10aAn example of apparatus 10 according to one embodiment is shown. In one embodiment, apparatus 10 may be a node, host, or server in or serving a communications network. For example, apparatus 10 may be a network node, satellite, base station, Node B, evolved Node B (eNB), 5G Node B or access point, next-generation Node B (NG-NB or gNB), and / or WLAN access point associated with a radio access network such as an LTE network, 5G, or NR. In the example embodiment, apparatus 10 may be an eNB in LTE or a gNB in 5G. In some embodiments, the network node may host network entities such as AMF, AUSF, AAA, UDM, etc., as described elsewhere herein.
[0090] It should be understood that in some example embodiments, device 10 may include an edge cloud server as a distributed computing system, wherein the server and radio nodes may be separate devices communicating with each other via a radio path or via a wired connection, or they may reside in the same entity communicating via a wired connection. For example, in some example embodiments where device 10 represents a gNB, it may be configured in a central unit (CU) and distributed unit (DU) architecture that divides gNB functions. In such an architecture, the CU may be a logical node that includes gNB functions such as user data transmission, mobility control, radio access network sharing, location and / or session management, etc. The CU may control the operation of the DU(s) through a fronthaul interface. The DU may be a logical node that includes a subset of gNB functions, depending on the function splitting options. It should be noted that those skilled in the art will understand that device 10 may include Figure 10a Components or features not shown in the diagram.
[0091] like Figure 10a As shown in the example, device 10 may include a processor 12 for processing information and executing instructions or operations. Processor 12 may be any type of general-purpose or special-purpose processor. In fact, for example, processor 12 may include one or more of the following: general-purpose computer, special-purpose computer, microprocessor, digital signal processor (DSP), field-programmable gate array (FPGA), application-specific integrated circuit (ASIC), and processor based on a multi-core processor architecture. Although Figure 10a A single processor 12 is shown, but multiple processors may be used according to other embodiments. For example, it should be understood that in some embodiments, device 10 may include two or more processors that can form a multiprocessor system capable of supporting multiple processing (e.g., in this case, processor 12 may represent multiple processors). In some embodiments, the multiprocessor system may be tightly coupled or loosely coupled (e.g., to form a computer cluster).
[0092] The processor 12 can perform functions associated with the operation of the device 10, which may include, for example, precoding of antenna gain / phase parameters, encoding and decoding of individual bits forming communication messages, formatting of information, and overall control of the device 10, including processes related to the management of communication resources.
[0093] Device 10 may also include or be coupled to memory 14 (internal or external), which may be coupled to processor 12, for storing information and instructions executable by processor 12. Memory 14 may be one or more memories and may be of any type suitable for the local application environment, and may be implemented using any suitable volatile or non-volatile data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and / or removable memory. For example, memory 14 may include random access memory (RAM), read-only memory (ROM), static storage devices such as disks or optical discs, hard disk drives (HDDs), or any other type of non-transitory memory or computer-readable medium. Instructions stored in memory 14 may include program instructions or computer program code that, when executed by processor 12, enable device 10 to perform the tasks described herein.
[0094] In one embodiment, device 10 may further include or be coupled to an (internal or external) drive or port configured to accept and read external computer-readable storage media, such as an optical disc, USB drive, flash drive, or any other storage media. For example, the external computer-readable storage media may store computer programs or software that are executed by processor 12 and / or device 10.
[0095] In some embodiments, device 10 may further include or be coupled to one or more antennas 15 for transmitting and / or transmitting signals and / or data to and from device 10. Device 10 may also include or be coupled to a transceiver 18 configured to transmit and receive information. Transceiver 18 may include, for example, multiple radio interfaces that may be coupled to antenna(s) 15. The radio interfaces may correspond to a variety of radio access technologies, including one or more of the following: GSM, NB-IoT, LTE, 5G, WLAN, Bluetooth, BT-LE, NFC, RFID, UWB, MulteFire, etc. The radio interfaces may include components such as filters, converters (e.g., digital-to-analog converters), mappers, Fast Fourier Transform (FFT) modules, etc., to generate symbols for transmission via one or more downlinks and to receive symbols (e.g., via an uplink).
[0096] Therefore, transceiver 18 can be configured to modulate information onto a carrier waveform for transmission by antenna(s)15 and demodulate information received via antenna(s)15 for further processing by other elements of device 10. In other embodiments, transceiver 18 may be able to directly transmit and receive signals or data. Additionally or alternatively, in some embodiments, device 10 may include input and / or output devices (I / O devices).
[0097] In one embodiment, memory 14 may store software modules that provide functionality when executed by processor 12. These modules may include, for example, an operating system that provides operating system functionality to device 10. The memory may also store one or more functional modules, such as applications or programs, to provide additional functionality to device 10. Components of device 10 may be implemented in hardware or as any suitable combination of hardware and software.
[0098] According to some embodiments, the processor 12 and memory 14 may be included in or form part of a processing circuitry or control circuitry. Furthermore, in some embodiments, the transceiver 18 may be included in or form part of a transceiver circuitry.
[0099] As used herein, the term "circuit system" can refer to a hardware circuit implementation only (e.g., analog and / or digital circuit systems), a combination of hardware circuits and software, a combination of analog and / or digital hardware circuits with software / firmware, any part of a hardware processor(s) (including digital signal processors) having software working together to cause a device (e.g., device 10) to perform various functions, and / or a hardware circuit and / or processor(s) or a portion thereof that operates using software but may be absent when operation is not required. As another example, as used herein, the term "circuit system" can also encompass a hardware circuit or processor (or multiple processors) only, or a portion of a hardware circuit or processor, and its accompanying software and / or firmware implementation. The term "circuit system" can also encompass baseband integrated circuits, for example, in servers, cellular network nodes or devices, or other computing or networking devices.
[0100] As described above, in some embodiments, device 10 may be a network node or RAN node, such as a base station, access point, node B, eNB, gNB, WLAN access point, etc.
[0101] According to some embodiments, device 10 may be controlled by memory 14 and processor 12 to perform functions associated with any of the embodiments described herein, such as Figures 1-9 The flowchart or signaling diagram shown contains some operations.
[0102] For example, in one embodiment, device 10 may be controlled by memory 14 and processor 12 to receive a first request for authorization to relay a remote UE for a relay UE. The first request may include an identifier of the remote UE. The relay UE may be within the radio coverage area of the network and may provide network access to remote UEs outside the radio coverage area. In one embodiment, device 10 may be controlled by memory 14 and processor 12 to provide the first request for authorization to a second relay network entity. The first request may include an identifier of the remote UE and an identifier of the relay UE. The second relay network entity may be associated with the home network of the relay UE. In one embodiment, device 10 may be controlled by memory 14 and processor 12 to relay a second request for authentication of a remote UE between the relay UE and the second relay network entity. In one embodiment, device 10 may be controlled by memory 14 and processor 12 to receive a response associated with the first request for authorization or the second request for authentication. The response may include information identifying the result of the first request or the second request, or security information associated with the relay of the remote UE. In one embodiment, device 10 may be controlled by memory 14 and processor 12 to provide the response to the relay UE.
[0103] In one embodiment, the device 10 may be controlled by the memory 14 and the processor 12 to receive a first request for authorization and authentication for relaying a remote UE by a relay UE. The first request may include an identifier of the remote UE and an identifier of the relay UE. In one embodiment, the device 10 may be controlled by the memory 14 and the processor 12 to ensure that the remote UE is authenticated and authorized for relaying by the relay UE. In one embodiment, the device 10 may be controlled by the memory 14 and the processor 12 to provide a response to a second relay network entity based on a configuration indicating whether the relay UE is permitted to relay a remote UE, the second relay network entity having issued the first request for authorization and authentication for relaying a remote UE by a relay UE.
[0104] In one embodiment, device 10 may be controlled by memory 14 and processor 12 to receive a request for authorization and authentication of a remote UE to be relayed by a relay UE. The request may include an identifier of the remote UE and an identifier of the relay UE. The relay UE may be within the radio coverage area of the network and may provide network access to remote UEs outside the radio coverage area. In one embodiment, device 10 may be controlled by memory 14 and processor 12 to authenticate the remote UE via a relay home network entity. In one embodiment, device 10 may be controlled by memory 14 and processor 12 to receive information from another remote network entity identifying whether the remote UE is permitted to be relayed by the relay UE. In one embodiment, device 10 may be controlled by memory 14 and processor 12 to provide a response associated with the authorization request to the relay network entity. The response may include information identifying the result of the request, the identity of the remote UE, or security information associated with the relaying of the remote UE.
[0105] Figure 10b An example of a device 20 according to another embodiment is shown. In one embodiment, device 20 may be a node or element in or associated with a communication network, such as a UE, mobile equipment (ME), mobile station, mobile device, fixed device, IoT device, or other device. As described herein, a UE may alternatively be referred to as, for example, a mobile station, mobile equipment, mobile unit, mobile device, user equipment, subscriber station, wireless terminal, tablet computer, smartphone, IoT device, sensor, or NB-IoT device, etc. As an example, device 20 may be implemented in, for example, a wireless handheld device, a wireless plug-in accessory, etc.
[0106] In some example embodiments, device 20 may include one or more processors, one or more computer-readable storage media (e.g., memory, storage device, etc.), one or more radio access components (e.g., modem, transceiver, etc.), and / or a user interface. In some embodiments, device 20 may be configured to operate using one or more radio access technologies, such as GSM, LTE, LTE-A, NR, 5G, WLAN, WiFi, NB-IoT, Bluetooth, NFC, MulteFire, and / or any other radio access technology. It should be noted that those skilled in the art will understand that device 20 may include... Figure 10b Components or features not shown in the diagram.
[0107] like Figure 10bAs shown in the example, device 20 may include or be coupled to a processor 22 for processing information and executing instructions or operations. Processor 22 may be any type of general-purpose or special-purpose processor. In practice, processor 22 may include one or more of the following: general-purpose computer, special-purpose computer, microprocessor, digital signal processor (DSP), field-programmable gate array (FPGA), application-specific integrated circuit (ASIC), and processor based on a multi-core processor architecture. Although Figure 10b A single processor 22 is shown, but multiple processors may be used according to other embodiments. For example, it should be understood that in some embodiments, device 20 may include two or more processors that can form a multiprocessor system capable of supporting multiple processing (e.g., in this case, processor 22 may represent multiple processors). In some embodiments, the multiprocessor system may be tightly coupled or loosely coupled (e.g., to form a computer cluster).
[0108] The processor 22 can perform functions associated with the operation of the device 20, including, for example, precoding of antenna gain / phase parameters, encoding and decoding of individual bits forming communication messages, formatting of information, and overall control of the device 20, including processes related to the management of communication resources.
[0109] Device 20 may also include or be coupled to memory 24 (internal or external), which may be coupled to processor 22 for storing information and instructions executable by processor 22. Memory 24 may be one or more memories and may be of any type suitable for the local application environment, and may be implemented using any suitable volatile or non-volatile data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and / or removable memory. For example, memory 24 may include random access memory (RAM), read-only memory (ROM), static storage devices such as disks or optical discs, hard disk drives (HDDs), or any other type of non-transitory memory or computer-readable medium. Instructions stored in memory 24 may include program instructions or computer program code that, when executed by processor 22, enable device 20 to perform the tasks described herein.
[0110] In one embodiment, device 20 may further include or be coupled to an (internal or external) drive or port configured to accept and read external computer-readable storage media, such as an optical disc, USB drive, flash drive, or any other storage media. For example, the external computer-readable storage media may store computer programs or software that are executed by processor 22 and / or device 20.
[0111] In some embodiments, device 20 may further include or be coupled to one or more antennas 25 for receiving downlink signals and for transmitting from device 20 via an uplink. Device 20 may also include a transceiver 28 configured to transmit and receive information. Transceiver 28 may also include a radio interface (e.g., a modem) coupled to antenna 25. The radio interface may correspond to various radio access technologies, including GSM, LTE, LTE-A, 5G, NR, WLAN, NB-IoT, Bluetooth, BT-LE, NFC, RFID, UWB, etc. The radio interface may include other components such as filters, converters (e.g., digital-to-analog converters), symbol demappers, signal shaping components, inverse fast Fourier transform (IFFT) modules, etc., to process symbols carried by the downlink or uplink, such as OFDMA symbols.
[0112] For example, transceiver 28 may be configured to modulate information onto a carrier waveform for transmission by antenna(s)25 and demodulate information received via antenna(s)25 for further processing by other elements of device 20. In other embodiments, transceiver 28 may be able to directly transmit and receive signals or data. Additionally or alternatively, in some embodiments, device 20 may include input and / or output devices (I / O devices). In some embodiments, device 20 may also include a user interface, such as a graphical user interface or a touchscreen.
[0113] In one embodiment, memory 24 stores software modules that provide functionality when executed by processor 22. These modules may include, for example, an operating system that provides operating system functionality to device 20. The memory may also store one or more functional modules, such as applications or programs, to provide additional functionality to device 20. Components of device 20 may be implemented in hardware or as any suitable combination of hardware and software. According to an example embodiment, device 20 may optionally be configured to communicate with device 10 via wireless or wired communication link 70 according to any radio access technology such as NR.
[0114] According to some embodiments, the processor 22 and the memory 24 may be included in or form part of a processing circuitry or control circuitry. Furthermore, in some embodiments, the transceiver 28 may be included in or form part of a transceiver circuitry.
[0115] As described above, according to some embodiments, device 20 may be, for example, a UE, a mobile device, a mobile station, a ME, an IoT device, and / or an NB-IoT device. According to some embodiments, device 20 may be controlled by memory 24 and processor 22 to perform functions associated with the example embodiments described herein. For example, in some embodiments, device 20 may be configured to perform one or more processes depicted in any flowchart or signaling diagram described herein, such as... Figures 1-5 Those shown.
[0116] For example, in one embodiment, device 20 may be controlled by memory 24 and processor 22 to receive an identifier of a remote UE. The relay UE may be within the radio coverage area of the network and may provide network access to remote UEs outside the radio coverage area. In one embodiment, device 20 may be controlled by memory 24 and processor 22 to provide a first request to a relay network entity for authorization and authentication of the relay remote UE. The first request may include the identifier of the remote UE. The relay network entity may be associated with a serving network of the relay UE. In one embodiment, when signaling is associated with authenticating a remote UE, device 20 may be controlled by memory 24 and processor 22 to relay the signaling between the remote UE and the serving network of the relay UE. In one embodiment, device 20 may be controlled by memory 24 and processor 22 to receive a response associated with the first request. The response may include information identifying the result of the first request or security information to be used in association with the relay remote UE.
[0117] Therefore, some example embodiments offer several technical improvements, enhancements, and / or advantages compared to existing technologies. For example, one advantage of some example embodiments is enhanced security regarding the relay of remote UEs. Thus, the use of some example embodiments results in improved functionality of the communication network and its nodes, and therefore constitutes an improvement at least in the technical field of remote UE relay.
[0118] In some example embodiments, the functionality of any methods, processes, signaling diagrams, algorithms, or flowcharts described herein may be implemented by software and / or computer program code or code portions stored in memory or other computer-readable or tangible media and executed by a processor.
[0119] In some example embodiments, an apparatus may be included in or associated with at least one software application, module, unit, or entity configured to perform arithmetic operations, or configured to be a program or a portion thereof (including added or updated software routines) executed by at least one operating processor. The program (also referred to as a program product or computer program, including software routines, applets, and macros) may be stored in any device-readable data storage medium and may include program instructions for performing a specific task.
[0120] A computer program product may include one or more computer-executable components that, when the program runs, are configured to perform some example embodiments. The one or more computer-executable components may be at least one piece of software code or code. Modifications and configurations for implementing the functionality of the example embodiments may be executed as routines(s), which may be implemented as added or updated software routines(s). In one example, the software routines(s) may be downloaded to the device.
[0121] As an example, software or computer program code or code portions may be in the form of source code, object code, or some intermediate form, and may be stored on some carrier, distribution medium, or computer-readable medium, which may be any entity or device capable of carrying the program. For example, such a carrier may include recording media, computer memory, read-only memory, optoelectronic and / or electrical carrier signals, telecommunication signals, and / or software distribution packages. Depending on the required processing power, the computer program may execute in a single electronic digital computer or be distributed across multiple computers. The computer-readable medium or computer-readable storage medium may be a non-transitory medium.
[0122] In other example embodiments, the function may be performed by hardware or circuitry systems included in the device (e.g., device 10 or device 20), for example, by using an application-specific integrated circuit (ASIC), a programmable gate array (PGA), a field-programmable gate array (FPGA), or any other combination of hardware and software. In yet another example embodiment, the function may be implemented as a signal, such as an intangible component that can be carried by an electromagnetic signal downloaded from the Internet or another network.
[0123] According to the example embodiments, devices such as nodes, equipment or corresponding components can be configured as circuit systems, computers or microprocessors, such as monolithic computer elements, or configured as chipsets, which may include at least a memory for providing storage capacity for arithmetic operations(s) and / or an arithmetic processor for performing arithmetic operations(s).
[0124] The exemplary embodiments described herein are equally applicable to both singular and plural implementations, whether the singular or plural language is used in conjunction with the description of a particular embodiment. For example, an embodiment describing the operation of a single UE is equally applicable to embodiments involving multiple instances of UEs, and vice versa.
[0125] It will be readily understood by those skilled in the art that the exemplary embodiments discussed above can be practiced with different sequences of operation and / or with different configurations of hardware elements compared to those disclosed. Therefore, although some embodiments have been described based on these exemplary preferred embodiments, it will be apparent to those skilled in the art that certain modifications, variations, and alternative constructions will be readily apparent while remaining within the spirit and scope of the exemplary embodiments.
[0126] Partial vocabulary list
[0127] 5GC: 5G Core Network
[0128] 5GS: 5G system
[0129] 5G-AN: 5G Access Network
[0130] 5G-GUTI: 5G Globally Unique Temporary Identifier
[0131] 5G-S-TMSI: 5G S Temporary Mobile Subscription Identifier
[0132] AMF: Access and Mobility Management Functions
[0133] AUSF: Authentication Server Function
[0134] CHF: Billing Function
[0135] CP: Control Plane
[0136] DL: Downlink
[0137] DN: Data Network
[0138] DNN: Data Network Name
[0139] GPSI: General Public Subscription Identifier
[0140] HR: Home Route (Roaming)
[0141] IMEI / TAC: IMEI type assignment code
[0142] LBO: Local Interruption (Roaming)
[0143] N3IWF: Non-3GPP Interoperability Function
[0144] NEF: Network Exposure Function
[0145] NF: Network Functions
[0146] NR: New Radio
[0147] PEI: Permanent Device Identifier
[0148] (R)AN / RAN: (Radio) Access Network / Radio Access Network
[0149] SEAF: Safety Anchor Function
[0150] SMF: Session Management Function
[0151] UDM: Unified Data Management
[0152] UDR: Unified Data Repository
[0153] UL: Uplink
[0154] UPF: User Plane Functionality
Claims
1. A method at a relay user equipment, the method comprising: Receive (600) the identifier of the remote user equipment via a direct communication connection between the relay user equipment and the remote user equipment, wherein the remote user equipment is outside the radio coverage of the radio network that provides access to the service network of the remote user equipment; (602) Provide a first request for authorization for the relay user equipment as a relay for the remote user equipment to a relay network entity serving the network of the relay user equipment, wherein the first request includes the identifier of the remote user equipment. Signaling received from the remote user equipment and associated with authorization of the remote user equipment is relayed to the serving network of the relay user equipment, and signaling received from the serving network of the relay user equipment and associated with authorization of the remote user equipment is relayed to the remote user equipment, wherein the signaling received from the remote user equipment and associated with authorization of the remote user equipment is destined for the network entity of the serving network of the remote user equipment, and the signaling received from the serving network of the relay user equipment and associated with authorization of the remote user equipment originates from the network entity of the serving network of the remote user equipment and is destined for the remote user equipment; as well as Receive (606) a response to the first request from the relay network entity, wherein the response includes: Security information used in association with the following: The relay user equipment relays the control plane signaling and user plane services of the remote user equipment received via the direct communication connection to the service network of the remote user equipment via the service network of the relay user equipment. and / or The relay user equipment receives control plane signaling and user plane services for the remote user equipment from the service network of the remote user equipment via the service network of the relay user equipment, and relays them to the remote user equipment via the direct communication connection.
2. The method of claim 1, wherein the identifier of the remote user equipment includes a subscription hidden identifier.
3. The method according to claim 1, wherein the relay network entity includes access and mobility management functions.
4. The method of claim 1, wherein the first request for authorization is provided in a non-access stratum message, or the response associated with the first request is received in a non-access stratum message.
5. The method according to any one of claims 1 to 4, wherein the response further includes information indicating that the first request has been accepted, and The method further includes: Based on the information indicating that the first request has been accepted, control plane signaling and user plane services received from the remote user equipment via the direct communication connection are relayed to the serving network of the relay user equipment, and control plane signaling and user plane services received from the serving network of the remote user equipment via the serving network of the relay user equipment are also relayed to the remote user equipment.
6. A relay user equipment, comprising: A component for receiving the identifier of a remote user equipment via a direct communication connection between the relay user equipment and the remote user equipment, wherein the remote user equipment is outside the radio coverage of a radio network that provides access to a service network for the remote user equipment. A component for providing a relay network entity serving the relay user equipment with a first request to authorize the relay user equipment as a relay for the remote user equipment, wherein the first request includes the identifier of the remote user equipment. Components for: relaying signaling received from the remote user equipment and associated with authorization of the remote user equipment to the serving network of the relay user equipment, and relaying signaling received from the serving network of the relay user equipment and associated with authorization of the remote user equipment to the remote user equipment, wherein the signaling received from the remote user equipment and associated with authorization of the remote user equipment is destined for the network entity of the serving network of the remote user equipment, and the signaling received from the serving network of the relay user equipment and associated with authorization of the remote user equipment originates from the network entity of the serving network of the remote user equipment and is destined for the remote user equipment; as well as A component for receiving a response to the first request from the relay network entity, wherein the response includes: Security information used in association with the following: The relay user equipment relays the control plane signaling and user plane services of the remote user equipment received via the direct communication connection to the service network of the remote user equipment via the service network of the relay user equipment. and / or The relay user equipment receives control plane signaling and user plane services for the remote user equipment from the service network of the remote user equipment via the service network of the relay user equipment, and relays them to the remote user equipment via the direct communication connection.
7. The relay user equipment of claim 6, wherein the identifier of the remote user equipment includes a subscription hidden identifier.
8. The relay user equipment according to claim 6, wherein the relay network entity includes access and mobility management functions.
9. The relay user equipment of claim 6, wherein the first request for authorization is provided in a non-access stratum message, or the response associated with the first request is received in a non-access stratum message.
10. The relay user equipment according to any one of claims 6 to 9, wherein the response further includes information indicating that the first request has been accepted, and The relay user equipment further includes: Components for: relaying control plane signaling and user plane services received from the remote user equipment via the direct communication connection to the serving network of the relay user equipment based on the information indicating that the first request has been accepted, and relaying control plane signaling and user plane services received from the serving network of the remote user equipment via the serving network of the relay user equipment to the remote user equipment.
11. A computer-readable medium comprising instructions that, when executed by a relay device, cause the relay device to perform the method according to any one of claims 1 to 5.
12. A computer program product comprising instructions that, when executed by a relay device, cause the relay device to perform the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Method for transmitting and receiving data through relay in wireless communication system and apparatus therefor
US20190394816A1