Non-3gpp handover preparation
By establishing a simulated non-3GPP access tunnel under the existing RAN connection and gradually switching to the N3IWF connection of the second PLMN, the problems of excessive time consumption and interruption during the handover process between the non-3GPP access network and the PLMN are solved, achieving efficient service continuity and network handover.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-05-03
- Publication Date
- 2026-03-31
AI Technical Summary
Existing technologies involve a large number of message exchanges during the handover process between non-3GPP access networks and PLMNs, resulting in excessive time consumption. Furthermore, the handover process is prone to causing large-scale interruptions in data flow, especially when the UE device can only connect to one RAN at a time, making it impossible to effectively guarantee service continuity.
By establishing a simulated non-3GPP access tunnel under the existing RAN connection and gradually switching to the N3IWF connection of the second PLMN without interrupting the data flow, including registering in the first PLMN, establishing a second set of PDU sessions and security associations, then releasing RAN resources and connecting to the second PLMN through the second RAN, and optimizing IP address updates to maintain tunnel continuity.
It significantly reduces service interruption time, ensures the continuity of data flow during the handover process, and improves the efficiency and reliability of network handover.
Smart Images

Figure CN116057982B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method for switching network connections between one access network and another. Background Technology
[0002] Current cellular mobile communication systems provide user equipment (UE) devices with connectivity to the Public Land Mobile Network (PLMN) through various access networks (ANs). The Radio Access Network (RAN) is typically part of the PLMN, deployed and maintained by the PLMN operator, and is therefore trusted. Examples of RAN access technologies include UMTS (3G), LTE (4G), and New Radio (NR, 5G). In addition, the PLMN also provides access through external networks that are not part of the PLMN and whose access technologies are not specified by 3GPP. Therefore, this type of access is called "non-3GPP access." In cases where there is typically no trust relationship between the PLMN and non-3GPP access networks, this access is also called "untrusted non-3GPP access." Typical examples of such non-3GPP access technologies are Wi-Fi (WLAN) or fixed broadband access. Summary of the Invention
[0003] 5G architectures that do not use 3GPP access, such as Figure 1 As shown. Figure 1 The diagram illustrates the PLMN and its most important core network entities, including Authentication and Security Functions (AUSF), Universal Data Management Functions (UDM) (including, for example, a user database), and Authentication and Mobility Functions (AMF). The primary function of these entities is to register UE devices within the core network, including authentication, authorization, and supporting the mobility of UE devices throughout the network. Additionally, the PLMN has User Plane Functions (UPF) for each connection between the UE device and the data network, and Session Management Functions (SMF) for managing user data connections (including data routing and Quality of Service (QoS)) through the core network; such data connections are referred to as PDU sessions in the 5G architecture defined by 3GPP. In the example, Figure 1 The diagram shows a single UE device (UE 1) connected to the PLMN via the RAN (RAN 1). The dashed lines represent a single user plane connection (i.e., PDU session) between the UE device and the data network (e.g., the Internet) via the UPF.
[0004] The untrusted non-3GPP access network connects to the PLMN via the non-3GPP interoperability function (N3IWF). Figure 1The document also describes the user data transmission path from the UE device (UE 2) connecting to a non-3GPP access network (e.g., a public WLAN hotspot) and then through that non-3GPP access network to the data network of the PLMN via the N3IWF and UPF. The UE device is controlled by the AMF in the PLMN, while the non-3GPP access network is not controlled by the PLMN. Figure 1 Simplifications have been made in various aspects. For example, the UPF, SMF, and AMF serving UE 1 and UE 2 may each be multiple different entities; only one entity is shown in the diagram. Since a PLMN provides connectivity to various data networks, PDU sessions may connect to different data networks. Furthermore, UE 1 and UE 2 are likely the same UE device, i.e., a single device with a cellular transceiver for connecting to the RAN and a non-cellular transceiver (e.g., a WLAN module) for accessing public hotspots. In this case, the UE device will be served by a single AMF, but different SMFs and UPFs can still manage and constitute user data connections. The aforementioned non-3GPP access architecture was originally designed to connect UE devices to the PLMN when a RAN connection to the same PLMN already exists, or when the RAN cannot access the PLMN, connecting the UE to the PLMN solely through a non-3GPP access method.
[0005] For a UE device with a single cellular transmitter or a single cellular transceiver that registers in parallel on two different networks, the aforementioned non-3GPP access architecture can be reused in an enhanced 5G network. The UE device then connects to the first network via the RAN of the first network, and simultaneously connects to the second network via the N3IWF of both the first and second networks. Figure 2 The architecture is described in an exemplary manner. The diagram illustrates a first network and a UE device, which connect to the first network via the RAN (RAN 1) using a first credential (Cred 1) stored in the UE device. There may be one or more connections to a first data network, i.e., PDU sessions, of the first network. The UE device also has one or more PDU sessions to a second data network. The connection to the second data network connects the UE device to the N3IWF of the second network to establish a similar connection using a second credential (Cred 2). Figure 1 The connection is established by UE2 in the first network. In this architecture, from the perspective of the second network, the first network is a non-3GPP access network that is not controlled by the second network. For the first network, the second network is simply the service provider for the UE device accessing the first network through the second data network of the first network.
[0006] Non-3GPP architectures that provide non-3GPP access using 3GPP-defined access networks can be reused in various example networks. Example one is using a multi-USIM device with multiple (e.g., two) USIMs to access two different PLMNs, but the transmit or receive capabilities of these two different PLMNs only allow access to one RAN at a time. In this case, the first and second credentials ( Figure 2 In this example, Cred 1 and Cred 2 are credentials stored on the first and second USIMs, respectively. Example 2 illustrates a UE device simultaneously accessing a PLMN and a non-public network (NPN) with the same limited transmit / receive capabilities. In this case, the first credential (Cred 1) can be stored on the USIM in the UE device for accessing the PLMN, and the second credential (Cred 2) can be a non-3GPP credential, such as a certificate, stored on the UE device for accessing the NPN.
[0007] In the following text, the term PLMN is generally used for 3GPP networks, which are cellular mobile communication networks with a core network and potentially one or more RANs. This term includes deployments such as those described above, where the 3GPP network is an NPN. Therefore, the PLMN in the following text can be public or non-public, unless otherwise specified.
[0008] The relevant architecture on which this invention is based is described in 3GPP TS 23.501 § 5.30.2.7 and 5.30.2.8, see, for example, version 16.4.0.
[0009] Non-3GPP access to the PLMN requires the following function to register the UE device in the PLMN, i.e., to access the core network from the UE device through an access network not controlled by the PLMN (N3-AN).
[0010] The UE obtains IP connectivity from the N3-AN, meaning it typically receives an IP address (hereinafter referred to as the external IP address) and accesses the non-3GPP access network that connects the UE to at least one N3IWF (e.g., via the Internet). The UE then selects an N3IWF based on a pre-configured selection policy.
[0011] The UE accesses the N3IWF through the non-3GPP access network and exchanges keys with the N3IWF in accordance with the descriptions in IETF RFC 7296, Internet Key Exchange V2 (IKEv2) and 3GPP TS 23.502, §4.12.2. These procedures are included in this description and need not be repeated.
[0012] The Security Association (SA) established between the UE device and the N3IWF is essentially an encrypted tunnel between the UE device (represented by its current IP address and potential port number) and the N3IWF (represented by its current IP address and possible port number). This includes NAT traversal methods, if applicable, so that the UE device can establish a tunnel through the NAT. These methods can also be configured if the UE device supports the methods for overcoming IP address changes described in IETF RFC 4555-IKEv2 Mobility and Multihoming Protocol (MOBIKE).
[0013] The establishment of a Security Association (SA) involves multiple message exchanges from the UE device to the N3IWF. These messages provide initial establishment of the encrypted tunnel, credential exchange, authentication of the UE device in the core network including the AMF, the AUSF, and the UDM, and finally, the establishment of an IPsec security association to further exchange NAS signaling messages through the IPsec tunnel between the UE device and the N3IWF, and further exchange them to the AMF through the core network of the PLMN.
[0014] To establish an IPsec tunnel, the N3IWF allocates a second IP address to the UE from its local address space (i.e., internal IP address). Furthermore, the UE obtains a destination IP address (so-called NAS_IP_ADDRESS) from an address space, and through this address space, the UE addresses and sends control messages to the CN (i.e., to its AMF). For NAS signaling over the IPsec tunnel, the N3IWF uses NAS_IP_ADDRESS as the origin and the UE's internal IP address as the destination.
[0015] Once the IPsec tunnel between the UE and the N3IWF is securely established, the UE has a route that constitutes its logical connection with the AMF. The UE device is now controlled by the selected AMF, and it can request to establish a connection to the data network via the User Plane Function (UPF) on the N3-AN. For this purpose, a PDU session is established through the selected N3IWF, and for each PDU session, a sub-security association can be established between the UE device and the N3IWF.
[0016] If the non-3GPP access network is another PLMN, such as an NPN, then the method of using this establishment procedure is similar or the same.
[0017] As can be clearly seen from the above description, considering the detailed reference descriptions of 3GPP and IETF communication standards, the process of registering a UE device through a non-3GPP access network and N3IWF requires a large number of message exchanges, thus consuming a significant amount of time. After registration, establishing a PDU session through N3IWF will require additional NAS signaling message exchanges through the established SA, thereby consuming even more time.
[0018] The subject of this invention is an enhanced handover method. 3GPP TS 23.502V16.4.0 §4.9.2.2 describes a handover process for an existing PDU session established between a UE device connecting to a first RAN and then to a first PLMN. This process is used to switch the PDU session to a connection to a non-3GPP access network via the N3IWF of the first PLMN. The process includes steps such as registration via an untrusted non-3GPP access, establishment of a PDU session via the untrusted non-3GPP access, and release of RAN resources. Therefore, this process assumes that registration and establishment of a PDU session can be performed on a non-3GPP access network while the RAN resources are still in use and data transmission can continue. RAN resources can only be released after a PDU session is established via a non-3GPP access network and the N3IWF.
[0019] This procedure applies to non-3GPP access networks that can be used simultaneously with existing links between the UE device and the first RAN, such as WLAN-based N3-AN. However, this procedure does not apply to non-3GPP access networks using a second RAN and a second PLMN where a UE device is limited to accessing only a single RAN at a time due to its transceiver or transmitter capabilities.
[0020] TS 23.502 does not recommend establishing a connection to the N3IWF via the same PLMN access network. In TS 23.502, the tunnel coexists with and is independent of the connection on the first access network on the N3-AN.
[0021] For a non-3GPP network using a second RAN within a second PLMN, a direct alternative process would involve first releasing the resources of the first RAN, followed by a handover. Prior to the aforementioned three steps (i.e., registering the UE device in the first PLMN via N3IWF, establishing a PDU session in the first PLMN via N3IWF, and finally performing the handover), the handover would include the UE device registering in the second PLMN via the second RAN, and establishing a connection between the second PLMN and the first PLMN's N3IWF.
[0022] This process will cause a large-scale disruption to the data stream of the PDU session to be switched, which is undesirable for connections that require at least some degree of service continuity.
[0023] Therefore, the present invention is an enhancement to a 3GPP system comprising one or more 3GPP PLMNs (i.e., 3GPP core networks) and 3GPP UE devices, wherein an enhanced handover process is described, i.e., an existing connection is transferred from access via a first RAN through a first PLMN to access via a second RAN through a second PLMN and an N3IWF through the first PLMN.
[0024] This invention provides a method for a user equipment (UE) to switch a connection to a first data network from a first access network of a first mobile communication network to a second access network of a second mobile communication network. The method includes establishing a non-3GPP interoperability function (N3IWF) connection with the first mobile communication network through the first access network; establishing a communication tunnel between the UE and the N3IWF through the connection to the N3IWF; establishing a connection from the UE to the first data network through the communication tunnel; establishing a connection to the second access network and establishing a connection through the second access network to a third data network providing access to the N3IWF; and notifying the N3IWF of a change in its connection identifier, thereby enabling the connection established through the first access network to continue through the second access network.
[0025] This invention is an enhancement to the handover process. Before the handover occurs, the UE device is connected to the first PLMN via the first RAN of the first PLMN and has established a first set of PDU conversations (i.e., one or more PDU sessions) to one or more data networks of the first PLMN for user data exchange. The UE device has the capability of a transmitter or transceiver that allows connection (i.e., transmission) to a single RAN at a time.
[0026] An event requires the UE device to connect to a second PLMN. This event may be a detection by the UE device of a second PLMN with a higher priority than the first PLMN. The event may be a mobile initiation or mobile termination service action required by the UE device in the second PLMN, such as terminating a voice call, receiving an SMS in the second PLMN, or sending data in the second PLMN.
[0027] The method of the present invention may include two main steps. The first step occurs when a UE device connects to the first PLMN via the first RAN. The UE device establishes a second set of PDU sessions (i.e., one or more additional PDU sessions) to a data network that allows the UE device to connect to the N3IWF of the first PLMN. During the PDU session establishment, the UE device receives a first IP address from the address space of the data network of the first PLMN. The UE then registers access to the N3IWF in the first PLMN, including establishing a security association (SA) between the UE device and the N3IWF, and registering the new access in the core network of the first PLMN (e.g., in its current AMF). For this registration, the UE device uses the newly received first IP address, and then the UE device requests to switch the first set of PDU sessions from the first RAN to the newly registered connection to the N3IWF of the first PLMN.
[0028] In other words, in the first step, the UE device uses the existing RAN connection of the first PLMN to establish a tunnel through the first PLMN to the N3IWF of the first PLMN, thereby simulating non-3GPP access using the established RAN resources when a first set of PDU sessions exists. Then, the UE device requests to switch the existing first set of PDU sessions to the simulated non-3GPP access. The RAN resources directly used for the first set of PDU sessions can then be released, while the RAN resources used to establish and maintain the tunnel to the N3IWF carry the switched first set of PDU sessions.
[0029] As a result of the first step, the UE device has moved the first group of PDU sessions to the tunnel via a simulated non-3GPP access network through the N3IWF of the first PLMN. The simulated non-3GPP access network is established on the second group of PDU sessions, i.e., on the connection between the first RAN and the first PLMN. The first step is preparation for switching the newly established tunnel to the second PLMN via the second RAN in the second step. The advantage of the first step is that the security association between the UE and the N3IWF, the registration of the UE device through the N3IWF of the first PLMN, and the logical handover from the RAN to the non-3GPP access PDU sessions have been performed without interrupting the data flow of the first group of PDU sessions.
[0030] In the second step, the UE device releases all connections to the first RAN and accesses the second PLMN via the second RAN. This step requests the establishment of a third set of PDU sessions from the second PLMN to its data network, which provides a connection to the N3IWF of the first PLMN. During the PDU session establishment, the UE device receives a second IP address from the address space of the data network of the second PLMN. The UE device then connects to the N3IWF of the first PLMN via the third set of PDU sessions and performs the steps described in IETF RFC 4555, IKEv2 Mobility and Multihoming Protocol, MOBIKE, to change the UE device's IP address within an existing security association. Therefore, the UE device changes its IP address associated with the IPSec tunnel in the N3IWF from the first IP address to the second IP address; that is, the UE changes the endpoint of the IPSec tunnel on its side. Essentially, according to MOBIKE, the steps are as follows:
[0031] Send an information request containing the UPDATE_SA_ADDRESSES notification to the N3IWF.
[0032] Receive a response from the N3IWF confirming the IP address update of the UE device.
[0033] Then, the IPSecSA associated with the non-3GPP access tunnel (i.e., associated with the IKEv2 SA and subSA) will continue to transmit the data of the first set of PDU sessions through the tunnel now being transmitted over the third set of PDU sessions in the second PLMN. This invention limits the service interruption time for these PDU sessions to the time required to register the UE device in the second PLMN and establish the appropriate third set of PDU sessions, thus significantly reducing service interruptions.
[0034] An additional step can be introduced between the first and second steps as an intermediate step to further reduce service interruption time. Before the UE device releases its resources in the RAN, the first PLMN may send information to the second PLMN to prepare for establishing a third set of PDU sessions later for connecting the UE device to the N3IWF of the first PLMN via the second PLMN. The first PLMN may, for example, send a message to the Network Open Function (NEF) of the second PLMN to request the establishment of a third set of PDU sessions from the UE device to the N3IWF of the first PLMN, wherein the N3IWF is identified by its IP address or Fully Qualified Domain Name (FQDN). The UE device may have already provided identification information to the first PLMN, with which the UE device is identified in the message sent to the second PLMN. The message may contain information from the second PLMN regarding the nature of the PDU session for connecting to the N3IWF, such as data rate, latency, QoS, etc.
[0035] The second PLMN can then use this information to identify the UE device and prepare to establish the requested PDU session. If the UE device is already registered, the second PLMN can page the UE device on the second RAN of the second PLMN (if not yet done) and set the paging reason to either mobile termination data suspension or a new reason indicating a suspended connection with another PLMN.
[0036] In very special circumstances, the UE device connects to the second PLMN via the N3IWF of both the first and second PLMNs. The UE device itself can notify the second PLMN of the required third PDU session. The UE device can request to establish the third PDU session on the N3IWF of the second PLMN, and after accessing the second PLMN on the second RAN, it can request to switch the third PDU session from non-3GPP access via the first PLMN to 3GPP access via the second RAN. This may further reduce the PDU session establishment time, thereby reducing the downtime of the first PDU session.
[0037] The following describes alternative methods related to the present invention, focusing on the differences between the methods described above and the alternative methods. These alternative methods utilize multiple access PDU sessions as described in the 5G systems of version 16.
[0038] A Multi-Access Packet Data Unit (MA-PDU) session is a PDU session in which a UE device and the data network simultaneously establish connections via one or more UPFs through both 3GPP and non-3GPP access points. Data transmitted over an MA-PDU session can be transmitted at the time of session establishment or at another point within the session's validity period through a pre-selected single access point (e.g., a 3GPP access). Based on policies received and measurements executed in the UE device (for uplink services) and the edge UPF (for downlink services), a handover decision can change the access method, for example, switching to a non-3GPP access point. In this case, the actual access point can be easily reselected without performing a handover process from a 3GPP access point to a non-3GPP access point, and vice versa. Alternatively, data can be transmitted through both access points, with each packet selecting its access point based on policies and measurements. In another alternative, packets are redundantly transmitted over both access points to increase the likelihood of reception.
[0039] The first group of PDU sessions can be established as an MA-PDU session comprising an active, used 3GPP access segment and an inactive, unestablished non-3GPP access segment. In the first step described above, as previously stated, the UE device establishes a second group of PDU sessions and registers a simulated non-3GPP access at the N3IWF of the first PLMN. In this alternative approach, the handover of the first group of PDU sessions is replaced by activating and selecting the non-3GPP access segment of the first group of PDU sessions, while the 3GPP access is deselected. Both accesses can be used simultaneously for a limited time, with packet-by-packet access selection, to overcome potential startup problems associated with simulating non-3GPP access. The 3GPP access of the first group of MA-PDU sessions can be deactivated or deselected before performing the second step and after releasing RAN resources. During the establishment of the first set of MA-PDU sessions, the UE device may receive a policy from the core network. This policy includes the following rules: use 3GPP access segments when they are available, and autonomously activate and use simulated non-3GPP access segments when 3GPP access segments are unavailable or about to become unavailable. Edge UPFs in the core network can also be configured similarly, for example, based on network policies, and can be notified of the availability of both 3GPP and non-3GPP access segments to apply appropriate routing according to the policy.
[0040] In this alternative approach, the second step remains unchanged: the established IPSec tunnel is switched from the simulated non-3GPP access via the first PLMN to the connection via the second PLMN. Therefore, the final data of the first set of PDU sessions will continue to be transmitted via the non-3GPP access segment of the MA-PDU session on the second PLMN.
[0041] Another alternative approach also uses MA-PDU sessions. When a UE device registers with the first PLMN in the first RAN, it is certain that, while the UE device has active service, it may later switch to the second PLMN, requiring a switch to the second PLMN with as little disruption as possible. The first PLMN may, for example, notify the UE device of the potential change during or after registration and require or allow the establishment of an IPsec tunnel as preparation for such a handover. Alternatively, the UE device may store such information as part of its pre-configuration.
[0042] The UE device can first request the establishment of a set of PDU sessions (i.e., the second set of PDU sessions discussed above) from the first PLMN to the data network (DN 2) providing the connection to the N3IWF of the first PLMN. In most cases, these sessions contain only a single PDU session. After the second set of PDU sessions is established, the N3IWF of the first PLMN is requested to establish an IPSec tunnel and register the UE device's analog non-3GPP access on the core network as previously described. Therefore, the UE device is simultaneously registered on the first RAN and on the analog non-3GPP access transmitted via the N3IWF through the first RAN.
[0043] If a UE device needs to establish a PDU session to receive services from the first PLMN, it will establish a set of PDU sessions (the first set of PDU conversations discussed above) as an MA-PDU session, including a 3GPP access segment on the first RAN and a non-3GPP access segment on the established tunnel. For efficiency reasons, the non-3GPP access segment may be disabled, so all data packets will be transmitted through the 3GPP access segment as long as it is available. This can be achieved by configuring the edge UPF from the core network to the UE device and to the PDU session, with a strategy that restricts the MA-PDU session to the 3GPP access segment as long as it remains available, and triggers a switchover to the non-3GPP access segment when the 3GPP access segment becomes unavailable.
[0044] A significant advantage of this approach is that no preparation is required in the first PLMN upon detecting a loss of coverage in the first RAN or a need to switch to another RAN. Resources associated with the first RAN can be released, and as described in the preceding inventive method, registration in the second PLMN, establishment of a third set of PDU sessions, and notification of the N3IWF in the first PLMN regarding IP address changes can be performed immediately, while simultaneously establishing the connection from the second RAN to the second PLMN. This approach is the preferred alternative to current ideas because PLMN handovers can occur at any time, and the ultimately established PDU sessions can continue between the UE device and the first PLMN with minimal interruption. Attached Figure Description
[0045] Preferred embodiments of the invention will now be described by way of example only, with reference to the accompanying drawings, in which:
[0046] Figure 1 A schematic diagram of the data flow between the PLMN and non-3GPP access networks is shown.
[0047] Figure 2 It shows that the UE connects to the second PLMN through the first PLMN and connects to the data network using the N3IWF of the second PLMN;
[0048] Figure 3 This is a message sequence diagram of the first embodiment of the present invention;
[0049] Figure 4 This is a message sequence diagram of the second embodiment of the present invention;
[0050] Figure 5 This is a message sequence diagram of the third embodiment of the present invention. Detailed Implementation
[0051] Figure 3The diagram illustrates the message sequence between the UE device, PLMN, and NPN, as well as the resulting PDU sessions and IPSec tunnels, according to a first embodiment. For example, the PLMN includes an exemplary first radio access network (RAN 1), a core network (CN), a non-3GPP interoperability function (N3IWF), and two distinct data networks (DN 1, DN 2). The data networks are essentially entry / exit points from the core network to specific external networks. DN 1 could be an example of an IP-based multimedia subnet (IMS) providing IP-based voice and video call services to users of the PLMN. The UE device can register in the PLMN via its USIM and can initiate voice and video calls via a first set of PDU sessions indicated by the double-lined arrows between the UE device and DN 1. This first set of PDU sessions may include three PDU sessions: one for IMS signaling, one for voice data, and another for video data. The dots on the double-lined arrows indicate that the first set of PDU sessions is established via RAN 1.
[0052] Assuming the UE device has only a single transmission capability, it can only connect to one radio access network at a time. If the UE device is roaming, it includes a single USIM executed on the inserted UICC for authentication with the PLMN or other PLMNs. Roaming incorporates this invention without any significant changes, therefore roaming scenarios are not explicitly shown. The UE device also has credentials in its memory, such as in a secure memory built into the device, for authentication with the NPN. These credentials may be received from the NPN network via application software stored and executed on the mobile phone. For example, the NPN could be the network of an industrial plant where the UE device's user works. If the UE device connects to the NPN via its radio access network, one or more applications on the UE device can provide special services. The NPN is a complete 3GPP network, including a radio access network (RAN 2) and a core network (CN) providing one or more data networks (DN3). The NPN is as follows: Figure 3 As shown in the lower part.
[0053] When a UE device is connected to the PLMN via RAN 1 and has ongoing voice and video calls, the UE can be moved to the NPN coverage area that overlaps with the PLMN coverage area. Background cell search detects RAN 2 of the NPN; since this network has a higher priority than the PLMN, the UE device initiates the process of leaving RAN 1 and connecting to the NPN via RAN 2.
[0054] According to the present invention, the UE device and the PLMN now perform a process to prevent or reduce interruptions in ongoing voice and video calls. The UE device requests a second set of PDU sessions from the PLMN via RAN 1, wherein the second set of sessions includes a destination data network that allows connection to the N3IWF of the same PLMN and a QoS that matches the QoS required by the first set of PDU sessions. The second set of PDU sessions may, for example, include four PDU sessions, where the first session is used for IPSec tunnel establishment and NAS signaling, and the other three sessions include QoS that matches the sessions in the first set of PDU sessions (i.e., IMS signaling, voice, and video data). Alternatively, the UE device requests a second set of PDU sessions that includes only one PDU session for IPSec tunnel establishment and NAS signaling. The second set of PDU sessions may later include more PDU sessions for data transmission. The second set of PDU sessions may also alternatively include a single PDU session with a QoS high enough to transmit NAS and IMS signaling, voice, and video data simultaneously. Once the second set of PDU sessions is established, the UE device will receive an IP address dedicated to the data network DN 2.
[0055] The UE device will now select an N3IWF and request the establishment of an IPSec tunnel from the N3IWF, as detailed in the IETF and 3GPP specifications cited above. The UE device first establishes an IKE Security Association (SA), including the negotiation of encryption algorithms, then registers its simulated non-3GPP access in the PLMN's core network (CN), exchanges and verifies its identity, and ultimately facilitates the establishment of the IPSec tunnel for exchanging NAS signaling messages between the UE device and the CN.
[0056] Then, the UE device requests a switch from RAN 1 to the newly established IPSec tunnel connecting the N3IWF to the first group of PDU sessions. This switch may create a sub-security association (sub-SA) for each PDU session in the first group of PDU sessions. Creating sub-SAs may further facilitate the establishment of other PDU sessions in the second group of PDU sessions, transmitting the IPSec tunnel according to the alternative method selected above for establishing the second group of PDU sessions. Finally, the first group of PDU sessions will be transmitted entirely over the established IPSec tunnel, which is transmitted in the second group of PDU sessions via RAN 1, DN 2, and the N3IWF of the PLMN, as described above. Figure 3 As shown.
[0057] DN 2 can be a dedicated data network established by the PLMN, its purpose being to connect from within the PLMN to the PLMN's N3IWF, as newly introduced in this invention. DN 2 can also be a general-purpose data network, and the connection to the N3IWF can utilize an external transport network to connect the exit point of DN 2 and the N3IWF. The PLMN can leverage the fact that the simulated non-3GPP access is actually under the complete control of the PLMN to implement specific methods to enhance the establishment functionality of the IKE SA. The establishment of the second set of PDU sessions can, for example, trigger the core network to provide authentication information to the N3IWF in advance to reduce the delay in IPSec tunnel establishment, thereby accelerating the registration of the UE device in the NPN after RAN 2 is detected.
[0058] The UE device can now request the PLMN to release its resources in RAN 1, including the second set of PDU sessions established through RAN 1. Even if the tunnel itself is transmitted through the second set of PDU sessions, the UE device will not request the release of the first set of PDU sessions transmitted to the N3IWF through the IPSec tunnel, and therefore will lose its underlying transport layer.
[0059] After releasing radio resources to RAN 1, the UE itself registers in the NPN through RAN 2 and requests the establishment of a third set of PDU sessions to the data network (DN 3), wherein the data network provides access to the N3IWF of the first PLMN (again identified by its IP address, FQDN, or URL).
[0060] The third set of PDU sessions can be requested as a single PDU session for all data transmitted through the IPSec tunnel, or as separate PDU sessions for different parts of the data stream. In this exemplary embodiment, we assume that a single PDU session is first requested from the NPN to exchange IKE AUTH messages, quickly notifying the N3IWF of IP address changes and related endpoint changes occurring in the IPsec tunnel. Shortly after this PDU session is established, the UE device requests another PDU session to DN3 to transmit IMS signaling and voice and video data. The UE device notifies the N3IWF of the IP address change according to the above MOBIKE description, and from then on, the first set of PDU sessions to the PLMN proceeds through the established IPSec tunnel on the third set of PDU sessions of the NPN. For the user, voice and video calls will continue with little or no interruption.
[0061] The second implementation example Figure 4As shown. This embodiment swaps the roles of the PLMN and the NPN, implementing the invention in a manner similar to that described in the first embodiment. In this example, the UE device can first register via RAN 1 to an NPN with a persistent service running in DN 1. For this service, the UE device has established a first set of PDU sessions with DN 1, and these PDU sessions are established as MA-PDU sessions. The reason for using the MA-PDU sessions may be that the NPN may anticipate scenarios where the UE device moves out of the coverage area but needs to maintain its current service operation, which is a common use case for this NPN. The MA-PDU sessions are established with the 3GPP access segment selected and activated, without activating non-3GPP access segments.
[0062] The UE device detects that it may soon lose its connection with RAN 1 because it is leaving its coverage area. This detection can be based on location information and knowledge of RAN 1's coverage area, or on fading radio signals or other detection methods.
[0063] Similar to the first embodiment, the UE device requests to establish a connection to the N3IWF of the NPN and establishes a second set of PDU sessions with an IPSec tunnel to the N3IWF. Now, the UE device or the CN requests to switch the access of the first set of MA-PDU sessions to the simulated non-3GPP access. After the handover, the first set of MA-PDU sessions is carried through the IPSec tunnel on RAN 1 and the N3IWF.
[0064] In this embodiment, as long as no actual loss of RAN 1 is detected, the transmission over the IPSec tunnel transmitted on the NPN itself can be preserved. It is possible that if it is detected that the UE device has not actually left the coverage area of RAN 1, then the first group of MA-PDU sessions will switch back to a direct connection via RAN 1.
[0065] According to the example described for the second embodiment, an actual loss of RAN 1 is detected, and the UE device registers with the PLMN via RAN 2. A third PDU session is established. The UE device receives an IP address, which, after the successful establishment of the third PDU session, is communicated to the N3IWF of the NPN to switch the IPSec tunnel endpoint to the new connection via RAN 2 and the PLMN. Therefore, the service received by the UE device via DN 1 is not interrupted, or is interrupted only to a minimal extent.
[0066] Figure 5A third embodiment is illustrated. The UE device registers with the NPN via the NPN's RAN (RAN 1). The NPN may notify the UE device during registration that preparation for network handover should be triggered by the UE device because the UE device has triggered the establishment of a non-3GPP access simulated on the N3IWF. The identifier of the N3IWF may be provided in this information.
[0067] Therefore, the UE requests to establish a second set of PDU sessions to the data network (DN 2), which provides a connection to the N3IWF identified by the first PLMN during registration. This second set of PDU sessions may at this time contain only one PDU session, whose requested QoS applies to IPSec tunnel establishment and NAS signaling. In this second set of PDU sessions, the UE requests the establishment of an IPSec tunnel from the N3IWF and registers the non-3GPP access for the UE in the core network.
[0068] Subsequently, the UE device may need to establish services in the NPN, for example, to connect to machines in an industrial plant for maintenance. This service may be critical to the operation of the industrial plant, so connection interruption must be prevented. The UE device requests to establish a first set of PDU sessions to the data network (DN 1) providing the connection to the machine. The UE device requests that the establishment be treated as an MA-PDU session, including an access segment on RAN1 and another access segment for the established IPSec tunnel transmitted on RAN1. For efficiency reasons, actual transmission on the IPSec tunnel may be deactivated as long as the connection through RAN1 is available. The IPSec tunnel can be extended with sub-security associations of the newly established PDU sessions to allow for simple QoS processing of the data transmitted in the IPSec tunnel. The UE device can configure one or more policies or rules that require the UE to send all packets of the first set of PDU sessions through the 3GPP access segment as long as the 3GPP access segment is available, and automatically switch to a non-3GPP access segment as long as the access segment is unavailable. Edge UPFs can be configured with similar policies.
[0069] Now suppose the UE device leaves the coverage area of RAN 1, while an overlapping PLMN provides connectivity to RAN 2 at the same location. As shown in the previous embodiment, the UE device releases all resources in RAN 1 and registers in the PLMN. A third PDU session is established on a data network providing connectivity to the N3IWF of the first PLMN, and requests a change of IP address from the N3IWF for the IPSec tunnel containing the IKE SA and all sub-SAs. The connection between the UE device and the machine is now re-established via the changed endpoint on the UE device side. Triggered by previously received policies and rules, the UE now uses the IPSec tunnel for all packets associated with the first PDU session. Similarly, the edge UPF or UPF of the first PDU session will apply the received policies, thereby routing the corresponding packets to the non-3GPP access segment.
[0070] In this embodiment, the NPN notifies the UE device that network handover preparation should be triggered by the UE device because the UE device triggers the establishment of simulated non-3GPP access via N3IWF. This information can also be stored on the UE device in a configuration file received from a previous connection with the NPN. The NPN can also provide policies and rules to the UE device, allowing the UE device to autonomously determine whether to establish an IPSec tunnel based on the identity of the access network, environmental information, time, location, or radio measurements.
[0071] The embodiments described herein depict a first set of PDU sessions established for receiving one or more services from a first network (e.g., a PLMN or NPN). This first switches to non-3GPP access in the first network and then switches to non-3GPP access (e.g., an NPN or PLMN) in a second network. According to the invention, it should be understood that another set of PDU sessions can be established in the first network without switching to non-3GPP access. The UE device or the core network can determine, based on policies and rules, and on the nature of the service (e.g., its required QoS and its importance or priority), whether the PDU session for each received service also needs to maintain service continuity in the second network. For example, the UE device can decide not to switch to a connection to a general data network, such as a connection to the Internet, because these services can be received directly from the second network after a network change. For other services, it can be determined that they will not be interfered with or interrupted, and according to the invention, only essential services that need to continue will be switched.
[0072] It should be clear that although this embodiment is an example of a UE device switching between an NPN and a PLMN, or vice versa, the present invention is also applicable to switching between NPNs or PLMNs. The second network can even be a non-3GPP network, such as a WLAN connection, which is not available or cannot be accessed by the UE device when the service in the first network is established.
Claims
1. A method for a user equipment (UE) to handover a connection to a first data network from a first access network (RAN1) of a first mobile communication network (first PLMN) to a second access network (RAN2) of a second mobile communication network (second PLMN), the method comprising: establishing a connection to a non-3GPP interworking function (N3IWF) of the first mobile communication network over the first access network after establishing the connection to the first data network using the first access network; establishing a communication tunnel between the UE device and the N3IWF over the connection to the N3IWF; establishing the connection of the UE device to the first data network through the communication tunnel, wherein the communication tunnel has a tunnel endpoint at the UE device that is identified by a first connection identity; establishing a connection of the UE device with the second access network and establishing a connection of the UE device to a third data network through the second access network, wherein the third data network provides access to the N3IWF; notifying the N3IWF of a change of connection identity from the first connection identity to a second connection identity that identifies the tunnel endpoint at the UE device through the second access network, the change of connection identity allowing the N3IWF to switch the connection established over the first access network to continue through the second access network, wherein the method further comprises: releasing all connections of the UE device over the first access network while maintaining the communication tunnel between the UE device and the N3IWF and the connection between the UE device and the first data network through the communication tunnel after establishing the connection between the UE device and the first data network through the communication tunnel.
2. The method of claim 1, wherein, establishing the connection to the N3IWF at the same time as establishing the connection to the first data network using the first access network.
3. The method of claim 1 or 2, wherein, connecting the UE device to the first data network through the communication tunnel over the first access network after establishing the communication tunnel.
4. The method of claim 1 or 2, wherein: a connection of the UE device to a second data network having a first connection identity over the first access network is established in the first mobile communication network, the second data network being connectable to the N3IWF; access to the N3IWF is registered using the first connection identity; the connection to the first data network is handed over to a connection to the first data network through the N3IWF; after connecting to the second access network, the N3IWF is informed of a change of connection identity from the first connection identity to a second connection identity associated with the connection to the third data network.
5. The method of claim 4, wherein, The first mobile communication network sends, to the second mobile communication network, information for preparing establishment of the connection to the third data network, in order to connect the UE device with the N3IWF of the first mobile communication network, before releasing resources in the first access network.
6. The method of claim 5, wherein, The first mobile communication network sends a message to a network exposure function (NEF) of the second mobile communication network, to request establishment of a packet data unit (PDU) session of the UE device to the N3IWF.
7. The method of claim 6, wherein, Identity information of the UE device is provided to the second mobile communication network, wherein the identity information is used by the second mobile communication network to prepare establishment of the packet data unit session.
8. The method of claim 4, wherein, The UE device is connected to the second mobile communication network through the N3IWF of the first mobile communication network and the second mobile communication network, and the UE device requests the second mobile communication network to establish a packet data unit (PDU) session on the N3IWF of the second mobile communication network, and after accessing the second access network, the UE device requests to switch the PDU session from non-3GPP access through the first mobile communication network to 3GPP access through the second access network.
9. The method of claim 1 or 2, wherein, The connection to the first data network is a multi-access packet data unit (MA-PDU) session.
10. The method of claim 1, wherein, Preparation of a change of mobile communication network is triggered by the UE device at or after registration of the UE device with the first mobile communication network, to establish a packet data unit (PDU) session to a second data network providing a connection with the N3IWF, the UE device requesting from the N3IWF establishment of the communication tunnel and registration of non-3GPP access for the UE device in a core network of the first mobile communication network.
11. The method of claim 10, wherein, The connection of the UE device to the first data network is established as a MA-PDU session, the MA-PDU session comprising a first communication route between the UE device and the first data network through the first access network and a second communication route between the UE device and the first data network through the communication tunnel, the second data network and the N3IWF.
12. The method of claim 11, wherein, The connection of the UE device to the first data network is switched from the first communication route to the second communication route for establishing the connection of the UE device with the first data network through the communication tunnel.
13. A method for a mobile communication network (first PLMN) to switch a connection between a user equipment (UE) and a first data network from a first access network (RAN1) controlled by the mobile communication network to a second access network (RAN2) controlled by another mobile communication network (second PLMN), the method characterized by comprising: The connection between the UE device and the first data network has been established on the first access network, and a connection to a non-3GPP interworking function (N3IWF) of the mobile communication network is established on the first access network; establishing a communication tunnel between the UE device and the N3IWF over the connection to the N3IWF; establishing a connection between the UE device and the first data network through the communication tunnel; receiving, in the N3IWF on the second access network, information identifying a change in connection identity of a tunnel endpoint of the communication tunnel at the UE device, wherein the connection identity is changed from a first connection identity identifying the tunnel endpoint of the communication tunnel between the UE device and the N3IWF at the UE device over the first access network to a second connection identity identifying the tunnel endpoint of the communication tunnel between the UE device and the N3IWF at the UE device over the second access network, thereby enabling the connection established over the first access network to continue over the second access network, wherein the method further comprises: after establishing the connection between the UE device and the first data network through the communication tunnel, releasing all connections of the UE device over the first access network while maintaining the communication tunnel between the UE device and the N3IWF and the connection between the UE device and the first data network through the communication tunnel.