Trusted non-3GPP gateway function for the control plane and the user plane
By splitting the TNGF architecture, TNGF is divided into independent control plane, user plane and security gateway functions, solving the problems of high cost and poor flexibility of existing TNGF deployment, and achieving more flexible and efficient 5G network deployment.
Patent Information
- Application Number
- CN202080103716.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-09-02
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2040-09-02
AI Technical Summary
In the prior art, trusted non-3GPP gateway function (TNGF) is deployed as a monolithic function, resulting in high costs, difficulty in scaling and evolving the control plane and the user plane independently, and the deployment is not flexible enough.
Using the slicing TNGF architecture, TNGF is split into smaller, separate and independent functions, such as TNGF-control plane (TNGF-CP), TNGF-user plane (TNGF-UP), and TNGF-Security Gateway (TNGF-SG), to support 5G registration and PDU session establishment.
By segmenting the TNGF architecture, the TNAN deployment cost is reduced, the control plane and user plane are independently scaled and evolved, the deployment flexibility is improved, and the multi-tenant environment for various network slicing is supported.
Smart Images

Figure CN116171598B_ABST
Abstract
Description
Technical Field
[0001] The subject matter disclosed herein generally relates to the distributed functions of a Trusted Non-3GPP Gateway Function (“TNGF”). Background Art
[0002] The following abbreviations and acronyms are defined herein, at least some of which are referred to in the following description.
[0003] 3rd Generation Partnership Project (“3GPP”), 5th Generation Core Network (“5GC”), Access and Mobility Management Function (“AMF”), Access Stratum (“AS”), Application Programming Interface (“API”), Downlink (“DL”), Evolved Node-B (“eNB”), Evolved Packet Core (“EPC”), Next Generation (e.g., 5G) Node-B (“gNB”), General Packet Radio Service (“GPRS”), GPRS Tunneling Protocol (“GTP”), Home Subscriber Server (“HSS”), IP Multimedia Subsystem (“IMS”, also known as “IP Multimedia Core Network Subsystem”), Internet Protocol (“IP”), Long Term Evolution (“LTE”), LTE-Advanced (“LTE-A”), Media Access Control (“MAC”), Mobile Network Operator (“MNO”), Mobility Management Entity (“MME”), Non-Access Stratum (“NAS”), Narrow Band (“NB”), Network Function (“NF”), Network Access Identifier (“NAI”), Next Generation Application Protocol (“NGAP”), Next Generation Radio Access Network (“NG-RAN”), New Radio (“NR”), Policy Control Function (“PCF”), Packet Data Network (“PDN”), Packet Data Unit (“PDU”), PDN Gateway (“PGW”), Public Land Mobile Network (“PLMN”), Quality of Service (“QoS”), Radio Access Network (“RAN”), Radio Access Technology (“RAT”), Radio Resource Control (“RRC”), Receive (“Rx”), Security Mode Control (“SMC”), Single Network Slice Selection Assistance Information (“S-NSSAI”), Serving Gateway (“SGW”), Session Management Function (“SMF”), Transmission Control Protocol (“TCP”), Transmission (“Tx”), Trusted Non-3GPP Access Network (“TNAN”), Trusted Non-3GPP Access Point (“TNAP”), Trusted Non-3GPP Gateway Function (“TNGF”), TNGF-Control Plane (“TNGF-CP”), TNGF-Security Gateway (“TNGF-SG”), TNGF-User Plane (“TNGF-UP”), Unified Data Management (“UDM”), User Equipment / Device (Mobile Terminal) (“UE”), Uplink (“UL”), User Plane (“UP”), Universal Mobile Telecommunications System (“UMTS”), User Datagram Protocol (“UDP”), Wireless Local Area Network (“WLAN”) and Worldwide Interoperability for Microwave Access (“WiMAX”).
[0004] In some embodiments, a UE may access a 5G Core (“5GC”) network via a gateway function in a trusted non-3GPP access network (“TNAN”). The trusted non-3GPP gateway function (“TNGF”) enables a 5G device (i.e., a UE) to connect to a 5G Core (“5GC”) network via a trusted non-3GPP access network, such as a Wi-Fi access network deployed and managed by a 3GPP mobile operator. SUMMARY OF THE INVENTION
[0005] Programs for supporting a split TNGF architecture are disclosed. Such programs may be implemented by devices, systems, methods, and program products according to various embodiments.
[0006] One method for, e.g., registering a UE of the TNGF-control plane (“TNGF-CP”) function includes receiving a request from an AMF in a mobile communication network. Here, during registration of a remote unit (i.e., a UE) via the TNGF-CP in a mobile communication network, the request contains a first security key (e.g., a TNGF key) for the remote unit and one or more allowed network slices (e.g., an allowed NSSAI). The first method includes selecting a TNGF-SG and sending a first message to the selected TNGF-SG. Here, the first message contains the first security key, an identifier of the remote unit, and a destination address and port indicating where the remote unit should send signaling messages (e.g., NAS messages) for the mobile communication network. The first method includes receiving a second message containing the address of the TNGF-SG from the selected TNGF-SG, and establishing a first connection (i.e., an NWt-C connection) with the remote unit via the selected TNGF-SG. The first method includes completing the registration of the remote unit in the mobile communication network.
[0007] Another method of the TNGF-CP for establishing a PDU session, for example, includes receiving a request from the AMF, where the request is sent during the establishment of a PDU session for a remote unit (i.e., UE) via the TNGF-CP, and where the request contains a session identifier (e.g., PDU session ID), a slice identifier (e.g., S-NSSAI), and one or more QoS profiles. The second method includes selecting the TNGF-UP and sending a first message to the selected TNGF-UP, the first message containing UL transport information associated with a UPF in the mobile communication network. The second method includes: receiving a second message from the selected TNGF-UP, the second message containing DL transport information associated with the selected TNGF-UP; and sending a third message to the selected TNGF-SG, the third message requesting the establishment of one or more security associations with the remote unit. The second method includes: receiving a fourth message from the selected TNGF-SG, the fourth message indicating that one or more security associations with the remote unit have been established; and completing the establishment of the PDU session for the remote unit.
[0008] One method of the TNGF-User Plane (“TNGF-UP”) function for establishing a PDU session, for example, includes receiving a first message from the TNGF-CP, the first message containing UL transport information associated with a UPF in the mobile communication network. The method includes: sending a second message to the TNGF-CP, the second message containing DL transport information associated with the TNGF-UP; and establishing a connection with the TNGF-SG in the TNAN. Here, the TNGF-CP and the TNGF-SG establish a PDU session between the remote unit and the UPF. The method includes forwarding the UL data corresponding to the PDU session to the UPF and forwarding the DL data corresponding to the PDU session to the TNGF-SG. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] A more specific description of the embodiments briefly described above will be presented with reference to the specific embodiments illustrated in the accompanying drawings. It should be understood that these drawings only depict some embodiments and should not be considered as limiting the scope. The embodiments will be described and explained with additional specificity and detail by using the drawings, in which:
[0010] Figure 1 FIG. for showing an embodiment of a wireless communication system for supporting split TNGF;
[0011] Figure 2 FIG. for showing an embodiment of a TIRAP architecture using split TNGF;
[0012] Figure 3 FIG. for showing an embodiment of a deployment instance with separate TNGF functions (e.g., split TNGF);
[0013] Figure 4A A signal flow diagram showing an embodiment of a first solution for TNGF re - authentication;
[0014] Figure 4B is Figure 4A a continuation of the program depicted in;
[0015] Figure 4C is Figures 4A-4B a continuation of the program depicted in;
[0016] Figure 4D is Figures 4A-4C a continuation of the program depicted in;
[0017] Figure 5 A diagram showing an embodiment of a split TNAN architecture with established connections and IPsec security associations (SAs);
[0018] Figure 6 A block diagram showing an embodiment of a user equipment supporting split TNGF;
[0019] Figure 7 A block diagram showing an embodiment of a network device implementing split TNGF;
[0020] Figure 8 A flowchart showing an embodiment of a first method for supporting split TNGF;
[0021] Figure 9 A flowchart showing an embodiment of a second method for supporting split TNGF; and
[0022] Figure 10 A flowchart showing an embodiment of a third method for supporting split TNGF. Detailed Description
[0023] As those skilled in the art will appreciate, aspects of the embodiments can be embodied as a system, apparatus, method, or program product. Thus, the embodiments can take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, microcode, etc.), or an embodiment combining software and hardware aspects.
[0024] For example, the disclosed embodiments may be implemented as hardware circuits, which include custom very large scale integration ("VLSI") circuits or gate arrays, off-the-shelf semiconductors such as logic chips, transistors, or other discrete components. The disclosed embodiments may also be implemented in programmable hardware devices, such as field programmable gate arrays, programmable array logic, programmable logic devices, and the like. As another example, the disclosed embodiments may include one or more physical or logical blocks of executable code, which may be organized, for example, as objects, programs, or functions.
[0025] In addition, an embodiment may take the form of a program product embodied in one or more computer-readable storage devices, which store machine-readable code, computer-readable code, and / or program code, hereinafter referred to as code. The storage device may be tangible, non-transitory, and / or non-transmissive. The storage device may not embody a signal. In one embodiment, the storage device only employs a signal for accessing the code.
[0026] Any combination of one or more computer-readable media may be utilized. The computer-readable media may be a computer-readable storage media. The computer-readable storage media may be a storage device storing the code. The storage device may be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, holographic, micro-mechanical, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing.
[0027] More specific examples (a non-exhaustive list) of the storage device will include the following: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory ("RAM"), a read-only memory ("ROM"), an erasable programmable read-only memory ("EPROM") or flash memory, a portable compact disc read-only memory ("CD-ROM"), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of this document, a computer-readable storage media may be any tangible media that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device.
[0028] References throughout this specification to "one embodiment", "an embodiment", or similar language mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Thus, unless otherwise expressly stated, the appearances of the phrases "in one embodiment", "in an embodiment", and similar language throughout this specification may, but do not necessarily, all refer to the same embodiment, but rather mean "one or more, but not all embodiments". Unless otherwise expressly specified, the terms "comprising", "including", "having", and variations thereof mean "including but not limited to". Unless otherwise expressly specified, a listing of items does not imply that any or all of the items are mutually exclusive. Unless otherwise expressly stated, the terms "a / an" and "the" also refer to "one or more".
[0029] As used herein, a list with the conjunction "and / or" includes any single item in the list or a combination of items in the list. For example, the list of A, B, and / or C includes only A, only B, only C, the combination of A and B, the combination of B and C, the combination of A and C, or the combination of A, B, and C. As used herein, a list using the term "one or more of" includes any single item in the list or a combination of items in the list. For example, one or more of A, B, and C includes only A, only B, only C, the combination of A and B, the combination of B and C, the combination of A and C, or the combination of A, B, and C. As used herein, a list using the term "one of" includes one and only one of any single item in the list. For example, "one of A, B, and C" includes only A, only B, or only C and does not include the combination of A, B, and C. As used herein, "a member selected from the group consisting of A, B, and C" includes one and only one of A, B, or C and does not include the combination of A, B, and C. As used herein, "a member selected from the group consisting of A, B, and C and combinations thereof" includes only A, only B, only C, the combination of A and B, the combination of B and C, the combination of A and C, or the combination of A, B, and C.
[0030] Furthermore, the described features, structures, or characteristics of the embodiments may be combined in any suitable manner. In the following description, numerous specific details are provided, such as examples of programming, software modules, user selections, network transactions, database queries, database structures, hardware modules, hardware circuits, hardware chips, etc., to provide a thorough understanding of the embodiments. However, those skilled in the relevant art will recognize that the embodiments may be practiced without one or more of these specific details, or with other methods, components, materials, etc. In other instances, well-known structures, materials, or operations are not shown or described in detail to avoid obscuring aspects of the embodiments.
[0031] Aspects of the embodiments are described below with reference to schematic flowcharts and / or schematic block diagrams of methods, apparatuses, systems, and program products according to embodiments. It should be understood that each block of the schematic flowcharts and / or schematic block diagrams can be implemented by code, and combinations of blocks in the schematic flowcharts and / or schematic block diagrams. This code can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to generate a machine, such that instructions executed by the processor of the computer or other programmable data processing device produce means for implementing the functions / actions specified in the schematic flowcharts and / or schematic block diagrams.
[0032] The code can also be stored in a storage device that can direct a computer, other programmable data processing device, or other device to operate in a particular manner, such that the instructions stored in the storage device produce an article of manufacture that includes instructions for implementing the functions / actions specified in the schematic flowcharts and / or schematic block diagrams.
[0033] The code can also be loaded onto a computer, other programmable data processing device, or other device to cause a series of operational steps to be performed on the computer, other programmable device, or other device to generate a computer-implemented process, such that the code executed on the computer or other programmable device provides a process for implementing the functions / actions specified in the schematic flowcharts and / or schematic block diagrams.
[0034] The schematic flowcharts and / or schematic block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of apparatuses, systems, methods, and program products according to various embodiments. In this regard, each block in the schematic flowcharts and / or schematic block diagrams can represent a module, segment, or portion of code that contains one or more executable instructions for implementing the specified logical function.
[0035] It should also be noted that in some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, depending on the functionality involved, two blocks shown in succession may in fact be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order. Other steps and methods may be conceived that are equivalent in function, logic, or effect to one or more blocks or portions thereof of the illustrated figures.
[0036] The description of the elements in each figure may refer to the elements of the foregoing figures. In all the figures, the same numerals refer to the same elements, including alternative embodiments of the same elements.
[0037] Methods, apparatuses, and systems for supporting split TNGF are disclosed. In the 3GPP specification of the present invention, a trusted non-3GPP gateway function ("TNGF") is defined, which enables a 5G device ("UE") to connect to a 5G core ("5GC") network via a trusted non-3GPP access network, e.g., a Wi-Fi access network deployed and managed by a 3GPP mobile operator. In the 3GPP specification of the present invention, TNGF is defined as a monolithic function, i.e., a function containing both a control plane ("CP") and a user plane ("UP") function as well as a security gateway ("SG") function.
[0038] As pointed out above, defining TNGF as a monolithic function that combines many different functions can result in various drawbacks well known in the prior art. For example, TNAN deployment may be more costly because the entire TNGF must be deployed even when only a part of the TNGF function is needed. Also, there is no separation between the control plane and the user plane, so it may be difficult to scale and evolve the control plane and the user plane independently. In addition, the deployment may not be flexible enough, for example, it is not possible to deploy the user plane function near the UE and the control plane function in a centralized location.
[0039] Based on the above, TNGF can be deployed using a "split TNGF" architecture, where TNGF is split into smaller, separate, and independent functions, as described in further detail below. The purpose of this disclosure is to define the individual functions of TNGF and to define how 5G registration and PDU session establishment procedures are carried out when TNGF is split into individual functions.
[0040] Specifically, this disclosure defines three individual functions of TNGF: the TNGF-control plane (TNGF-CP) function; the TNGF-user plane (TNGF-UP) function; and the TNGF-security gateway (TNGF-SG) function. These functions of "split" TNGF are described in more detail below with reference to Figure 2 Describe these functions of "split" TNGF in more detail.
[0041] Figure 1 A wireless communication system 100 for supporting split TNGF according to an embodiment of the present disclosure is depicted. In one embodiment, the wireless communication system 100 includes at least one remote unit 105, at least one trusted non-3GPP access network ("TNAN") 120, and a mobile core network 140 in a PLMN. The TNAN 120 may consist of at least one base unit 121. Depending on the radio access technology deployed by the TNAN 120, the remote unit 105 may communicate with the TNAN 120 using a non-3GPP communication link 113. Although Figure 1A specific number of remote units 105, base units 121, TNAN 120, and mobile core network 140 are depicted, but those skilled in the art will recognize that any number of remote units 105, base units 121, TNAN 120, and mobile core network 140 may be included in the wireless communication system 100.
[0042] In one embodiment, the wireless communication system 100 conforms to a 5G system specified in 3GPP specifications. However, more generally, the wireless communication system 100 may implement some other open or proprietary communication network, such as LTE / EPC (referred to as '4G') or WiMAX, and other networks. The present disclosure is not limited to embodiments of any specific wireless communication system architecture or protocol.
[0043] In one embodiment, the remote unit 105 may include a computing device, such as a desktop computer, laptop computer, personal digital assistant ("PDA"), tablet computer, smart phone, smart television (e.g., a television connected to the Internet), smart appliance (e.g., an appliance connected to the Internet), set-top box, game console, security system (including security cameras), in-vehicle computer, network device (e.g., router, switch, modem), etc. In some embodiments, the remote unit 105 includes a wearable device, such as a smart watch, fitness bracelet, optical head-mounted display, etc. Additionally, the remote unit 105 may be referred to as a UE, subscriber unit, mobile device, mobile station, user, terminal, mobile terminal, fixed terminal, subscriber station, user terminal, wireless transmit / receive unit ("WTRU"), device, or other terms used in the art.
[0044] The remote unit 105 may communicate directly with one or more of the base units 121 in the TNAN 120 via uplink ("UL") and downlink ("DL") communication signals. Additionally, the UL and DL communication signals may be carried on the communication link 113. It should be noted that the TNAN 120 is an intermediate network that provides the remote unit 105 with access to the mobile core network 140.
[0045] The base unit 121 may serve several remote units 105 within a service area (e.g., a cell or cell sector) via the communication link 113. The base unit 121 may communicate directly with one or more of the remote units 105 via communication signals. Generally, the base unit 121 transmits DL communication signals in the time, frequency, and / or spatial domain to serve the remote unit 105. Additionally, the DL communication signals may be carried on the communication link 113. The communication link 113 may be any suitable carrier in licensed or unlicensed radio spectrum. The communication link 113 facilitates communication between one or more of the remote units 105 and / or one or more of the base units 121.
[0046] As noted above, the TNAN120 supports secure signaling interfaces and interoperability with the 5G core network. The TNAN120 includes at least one TNGF. Additionally, the TNGF125 can be split into individual functions ( Figure 1 not depicted in the figure). By splitting (i.e., distributing) the TNGF125, the NWt interface existing between the remote unit 105 and the TNGF125 can be split into a control plane component (i.e., NWt-C) and a user plane component (i.e., NWt-U). Additionally, the Ta interface between the base unit 121 (i.e., the TNAN access point) and the TNGF125 can also be split into control plane and user plane components. The signaling interfaces supported by the TNAN120 with split-TNGF are described in detail below with reference to Figure 2 figure.
[0047] The base unit 121 can be distributed over a geographical area. In some embodiments, the base unit 121 may also be referred to as a trusted non-3GPP access point (“TNAP”), access terminal, access point, base station, base transceiver station, relay node, device, or any other term used in the art. The base unit 121 is typically a radio access network (“RAN”), such as part of the TNAN120, which may include one or more controllers communicatively coupled to one or more corresponding base units 121. These and other elements of the radio access network are not illustrated, but are generally well known to those of ordinary skill in the art. The base unit 121 is connected to the mobile core network 140 via the TNAN120.
[0048] In some embodiments, the remote unit 105 communicates with an application server (or other communication peer) via a network connection to the mobile core network 140. For example, an application (e.g., a web browser, media client, phone / VoIP application) in the remote unit 105 may trigger the remote unit 105 to establish a PDU session (or other data connection) with the mobile core network 140 using the TIRAP120. The PDU session represents a logical connection between the remote unit 105 and the UPF141. To establish a PDU session, the remote unit 105 must register with the mobile core network.
[0049] In one embodiment, the mobile core network 140 is a 5G core (“5GC”) or an evolved packet core (“EPC”), which may be coupled to data networks such as the Internet and private data networks, as well as other data networks. The remote unit 105 may have a subscription or other account on the mobile core network 140. The present disclosure is not limited to any particular implementation of a wireless communication system architecture or protocol.
[0050] The mobile core network 140 includes several network functions (“NF”). As depicted, the mobile core network 140 includes at least one user plane function (“UPF”) 141. The mobile core network 140 also includes multiple control plane functions, including but not limited to an access and mobility management function (“AMF”) 143, a session management function (“SMF”) 145, and a policy control function (“PCF”) 147. In certain embodiments, the mobile core network 140 may also include a unified data management function (“UDM”) 149, an authentication server function (“AUSF”), a network repository function (“NRF”) (used by various NFs to discover and communicate with each other via APIs), or other NFs defined for the 5G core.
[0051] In various embodiments, the mobile core network 140 supports different types of mobile data connections and different types of network slices, where each mobile data connection utilizes a specific network slice. Herein, a “network slice” refers to a part of the mobile core network 140 optimized for a specific service type or communication service. Each network slice includes a set of CP and / or UP network functions. A network instance can be identified by an S-NSSAI, and the set of network slices that the remote unit 105 is authorized to use is identified by an NSSAI. In certain embodiments, various network slices may include separate instances of network functions, such as SMF 145 and UPF 141. In some embodiments, different network slices may share some common network functions, such as AMF 143. For ease of illustration, Figure 1 different network slices are not shown, but it is assumed that they are supported. Although Figure 1 a specific number and type of network functions are depicted, those skilled in the art will recognize that any number and type of network functions can be included in the mobile core network 140.
[0052] Figure 2 FIG. 200 depicts a reference architecture for slicing a TNGF according to an embodiment of the present disclosure. Architecture 200 involves a UE 205 (i.e., an embodiment of the remote unit 105), a trusted non-3GPP access network (“TNAN”) 210, and a 5G core network (“5GC”) 240. The TNAN 210 includes a trusted non-3GPP access point (“TNAP”) 215 and a sliced trusted non-3GPP gateway function (“TNGF”) 220. The 5GC 240 includes an AMF 245 (which interacts with the sliced TNGF 220 via an N2 interface) and a UPF 250 (which interacts with the sliced TNGF 220 via an N3 interface). As depicted, the TNGF 220 is sliced into three separate and independent functions: TNGF-SG 225, TNGF-CP 230, and TNGF 235.
[0053] TNGF-CP 230 is a control plane function. The functions of TNGF-CP 230 are: (1) communicating with UE 205 using (a) the EAP-5G protocol before the establishment of the NWt-C connection and using (b) the NWt-C connection after the establishment of this connection; (2) communicating with TNAP 215 via the AAA protocol or other similar protocols; (3) requesting to establish an IPsec security association (SA) with UE 205 from TNGF-SG 225; and (4) requesting to reserve user plane resources from TNGF-UP 235 for exchanging user plane PDUs with UE 205.
[0054] TNGF-UP 235 is a user plane function. TNGF-UP 235 supports IP communication with UE 205 for exchanging user plane PDUs. TNGF-UP 235 communicates with TNGF-CP 230 using a new signaling protocol on the T2 interface.
[0055] TNGF-SG 225 is a security gateway function. TNGF-SG 225 uses the IKEv2 protocol to establish an IPsec security association (SA) with UE 205. For each UE 205, there is a "signaling IPsec SA", and for each PDU session of UE 205, there is one or more "IPsec sub-SAs". TNGF-SG 225 communicates with TNGF-CP 230 using a new signaling protocol on the Tl-C interface. In some embodiments, TNGF-SG 225 may act as a virtual private network ("VPN") gateway.
[0056] Figure 2 The new interfaces shown are as follows:
[0057] Ta-C: Supports AAA signaling between TNAP 215 and TNGF-CP 230 used during the initial stage of the registration process.
[0058] Ta-U: Supports IP communication between TNAP 215 and TNGF-SG 225. There is no signaling protocol on this interface.
[0059] NWt-C: Supports transmitting NAS messages between UE 205 and TNGF-CP 230 via a dedicated TCP connection.
[0060] NWt-U: Supports IP communication between UE 205 and TNGF-UP 235. There is no signaling protocol on this interface.
[0061] Tl-C: Supports relaying of NAS messages and also supports a new signaling protocol that enables TNGF-CP230 to request an IP security association (SA) with UE 205 from TNGF-SG 225.
[0062] Tl-U: Supports IP communication between TNGF-SG 225 and TNGF-UP 235. There is no signaling protocol on this interface.
[0063] T2: Supports a new signaling protocol that enables TNGF-CP 230 to request reservation of user plane resources (e.g., UP_IP_ADDR) from TNGF-UP 235 for exchanging user plane PDUs with UE 205.
[0064] Figure 3 Depicts an example deployment 300 for 5G registration on a trusted non-3GPP access network according to an embodiment of the present disclosure. Deployment 300 involves UE 205 (e.g., an embodiment of remote unit 105), multiple instances of TNAP 215 (identified as "215A", "215B", and "215C"), multiple instances of TNGF-SG 225 (identified as "225A" and "225B"), an instance of TNGF-CP 230, and multiple instances of TNGF-UP 235 (identified as "235A", "235B", and "235C"). As depicted, TNAN 210 is divided into a centralized data center 305 that supports a data path 315 from TNGF-SG 225A to AMF 245, and a remote site 310 that supports a data path 320 from TNGF-SG 225A to UPF 250. In various embodiments, the remote site 325 supports access to an edge data network 325.
[0065] An example deployment scenario is shown in the figure, where the TNGF-CP function is located in a centralized location 305, while the TNGF-UP function 235 and the TNGF-SG function 225 are located in a remote site 310, such as a shopping mall, a stadium, or other areas near the end user. It should be noted that each TNGF-UP 235 can be associated with a different network slice (or S-NSSAI), and when UE 205 requests a PDU session with a specific S-NSSAI, a TNGF-UP 235 that supports this S-NSSAI can be selected. This is another advantage of the proposed TNGF split: TNGF can support various network slices by using different TNGF-UP instances 235 for each network slice and by using a single TNGF-CP 230 for all network slices.
[0066] Figures 4A-4DDepict program 400 for supporting split TNGF according to an embodiment of the present disclosure. Program 400 illustrates a first solution for 5G registration and PDU session establishment in the case of split TNGF, which involves UE 205, TNAN 210 (including TNAP 215, TNGF-SG 225, TNGF-CP 230, TNGF-UP 235) and 5GC 240 (including AMF 245 and UPF 250).
[0067] Program 400 illustrates the signaling procedure applied when UE 205 registers for 5G via TNAN 210 that supports split TNGF 220. This program 400 is referred to as "5G registration using split TNGF" and is a modification of the existing "Registration procedure for trusted non-3GPP access" specified in clause 4.12a.2.2 of TS 23.502, with some extensions and additions shown. It should be noted that split TNGF is transparent to UE 205, i.e., UE 205 does not know whether it is interacting with an integrated TNGF or a split TNGF. 5GC 240 is also not affected by split TNGF, i.e.,
[0068] At Figure 4A step 1, program 400 starts where UE 205 decides to connect to a specific 5G PLMN via an available non-3GPP access network (i.e., via TNAN 210). UE 205 discovers that the non-3GPP access network supports 5G connectivity (or "trusted" connectivity) to this 5G PLMN, so it selects this "trusted" non-3GPP access network and initiates the "Registration procedure for trusted non-3GPP access" specified in clause 4.12a.2.2 of TS 23.502. In most typical cases, the trusted non-3GPP access network is a WLAN access network compliant with IEEE 802.11 specifications. First, UE 205 establishes a layer 2 (L2) connection with TNAP 215 in TNAN 210 (see signaling 401). In the case of an IEEE 802.11 WLAN, this L2 connection corresponds to an 802.11 association.
[0069] At step 2, an EAP procedure is initiated. The EAP message is encapsulated into a layer 2 ("L2") packet between UE 205 and TNAN 210, for example, encapsulated into an IEEE 802.11 / 802.1x packet. At step 2a, TNAP 215 requests the identity of UE 205 (see signaling 403). At step 2b, UE 205 provides the NAI to TNAP 215 (see signaling 405). The NAI provided by UE 205 indicates that UE 205 requests "5G connectivity" from a specific PLMN. For example, NAI = "<any_usemame>@nai.5gc.mnc <mnc>.mcc <mcc>.3gppnetwork.org”.
[0070] At step 3a, this NAI triggers the TNAP 215 to select the TNGF-CP (here the TNGF-CP 230, see box 407). At step 3b, the TNAP 215 sends an AAA request to the selected TNGF-CP (see signaling 409). Between the TNAP 215 and the TNGF-CP 230, each EAP packet is encapsulated into an AAA message because the AAA protocol runs on the Ta-C interface.
[0071] At step 4, the TNGF-CP 230 responds with an AAA response message that contains an EAP-Request / 5G-Start packet indicating the start of the EAP-5G session to the UE 205 and the UE 205 can start sending NAS messages encapsulated within EAP-5G packets (see signaling 411).
[0072] At step 5, the UE 205 sends an EAP-Response / 5G-NAS packet containing access network parameters (AN-parameters) and a registration request message (or service request message) (see signaling 413). The AN-parameters contain a UE identifier (e.g., SUCI or 5G-GUTI), the selected PLMN identifier, and the cause of establishment. Optionally, if the UE 205 does not operate in the default NSSAI containment mode D (specified in TS 23.502), then the AN-parameters may also contain the requested NSSAI. The cause of establishment provides the reason for requesting a signaling connection with the 5GC 240. The TNAP 215 forwards the EAP-Response / 5G-NAS packet within the AAA request message to the TNGF-CP 230.
[0073] At step 6a, the TNGF-CP 230 selects the AMF 245 in the 5GC 240 of the selected PLMN (here, the AMF 245 is selected, see box 415). For example, based on the received AN-parameters and local policies, as specified in clause 6.3.5 of TS 23.501. At step 6b, the TNGF-CP 230 forwards the registration request (or service request) received from the UE 205 to the selected AMF 245 within an N2 initial UE message (shown as N2 msg) (see signaling 417). This message contains N2 parameters including the selected PLMN ID and the cause of establishment.
[0074] At step 8, a mutual authentication and key negotiation procedure (see message 419) is performed between the UE 205 and the AUSF in the 5GC 240 (the AUSF is not shown in the figure). For example, the mutual authentication and key negotiation procedure can be as specified in TS 33.501. This procedure can utilize another EAP procedure called internal EAP (e.g., EAPA - AKA′) to make it obvious that it is different from the EAP - 5G (external EAP) initiated at step 4.
[0075] At step 9, after successful mutual authentication and key negotiation, the AMF 245 sends an N2 message containing a Security Mode Command (SMC) request to the TNGF - CP 230. The N2 message contains an EAP - Success packet indicating that the internal EAP procedure has been successfully completed (see message 421).
[0076] At step 10, the TNGF - CP 230 forwards the SMC request and the contained EAP - Success packet to the TNAP 215, and the TNAP 215 forwards it to the UE 205 within an EAP - Request / 5G - NAS packet (see message 423).
[0077] At step 11, the UE 205 responds with an SMC complete message, which is forwarded to the TNGF - CP 230 (see message 425).
[0078] At step 12, the SMC complete message is forwarded to the AMF 245 inside the N2 message (see message 427).
[0079] At step 13, the AMF 245 sends an N2 message (Initial Context Setup Request) to the TNGF - CP 230 to request the establishment of a secure connection between the UE 205 and the TNGF - CP 230. This N2 message contains a TNGF key applied to establish a secure connection with the UE 205 and the allowed NSSAI. The allowed NSSAI indicates a list of one or more S - NSSAIs allowed for this UE 205. It should be noted that the TNGF key is derived in the UE 205 and in the AUSF at step 8 and is forwarded from the AUSF to the AMF 245.
[0080] Continue Figure 4B , at step 14a, TNGF-CP230 selects TNGF-SG225, i.e., the security gateway with which UE205 will establish secure communication (see box 431). This TNGF-SG225 can be selected based on the allowed NSSAI received from AMF245. Different TNGF-SGs can be deployed for different network slices (or S-NSSAIs), so the selected TNGF-SG should support all S-NSSAIs included in the allowed NSSAI.
[0081] At step 14b, TNGF-CP 230 sends a Tl-C message (Initial Context Setup Request) to the selected TNGF-SG 225 so that the TNGF-SG associated with UE 205 establishes a Tl-C connection and provides the necessary information for establishing secure communication with UE 205 (see messaging 433). This Tl-C message contains the UE identifier (e.g., SUCI), the TNGF key applied to the establishment of the secure connection between UE 205 and TNGF-SG 225, the NAS IP address and NAS port of TNGF-CP230 to which UE 205 should send NAS messages, and a connection identifier (i.e., "Conn-id-a").
[0082] At step 14c, after the TNGF-SG 225 stores the received information, it responds with another Tl-C message (Initial Context Setup Response), which contains the TNGF-SG address to which UE205 should initiate a secure connection and its own connection identifier (i.e., "Conn-id-a") (see messaging 435).
[0083] At step 15, TNGF-CP 230 sends the TNGF-SG address to UE 205 in an EAP-Request / 5G-Notification packet (see messaging 437), and UE 205 responds with an EAP-Response / 5G-Notification packet (see messaging 439). Finally, TNGF-CP230 sends an EAP-Success message indicating the successful completion of the external EAP procedure (EAP-5G) to UE205 (see messaging 441). During step 15, TNGF-CP 230 also derives the TNAP key (as specified in TS 33.501) and forwards this key to TNAP 215 (i.e., in the AAA Accept message containing the EAP-Success message). This TNAP key is required to establish secure communication between UE205 and TNAP215.
[0084] At step 16, UE 205 derives the TNAP key from the TNGF key and establishes a secure communication with TNAP 215 (see message 443). Subsequently, UE 205 receives IP configuration data, including the local IP address (see message 445).
[0085] At step 19a, UE 205 initiates the establishment of a secure connection with TNGF-SG 225, the address of which was received in step 15b (see message 447). This secure connection is established using the IKEv2 protocol as specified, for example, in TS 23.502, TS 33.501, and TS 24.502.
[0086] At step 19b, after the IKE_SA_INIT exchange, UE 205 sends an IKE_AUTH request message that contains its identity (e.g., SUCI) and an AUTH payload calculated using the TNGF key in UE 205 (see message 449). TNGF-SG 225 uses the UE 205 identity to locate the UE context created for this UE_205 in step 14, which contains the TNGF key to be applied to verify the AUTH payload.
[0087] At step 19c, if the verification is successful (i.e., TNGF-SG 225 confirms that UE 205 has the correct TNGF key), then TNGF-SG 225 responds with an IKE_AUTH response message that contains its own AUTH payload calculated using the TNGF key in TNGF-SG 225, as well as the internal IP address of UE 205 and the NAS IP address and NAS port of TNGF-CP 230 to which UE 205 should send NAS messages (see message 451). After UE 205 confirms the validity of the AUTH payload from TNGF-SG 225, an IPsec security association (referred to as the "signaling IPsec SA") is established between UE 205 and TNGF-SG 225. The signaling IPsec SA is then used to transfer NAS messages between UE 205 and TNGF-CP 230 via TNGF-SG 225.
[0088] Continue Figure 4C , at step 20, the UE 205 establishes a TCP connection towards the NAS IP address and NAS port of the TNGF-CP 230 via the signaling IPsec SA established in step 19 (see messaging 453). The establishment of the TCP connection between the UE 205 and the TNGF-CP 230 also signals the establishment of the NWt-C connection between the UE 205 and the TNGF-CP 230. All subsequent NAS messages between the UE 205 and the TNGF-CP 230 are exchanged via this TCP connection or equivalently via the NWt-C connection. It should be noted that the TNGF-SG 225 relays all data received from the UE 205 via the signaling IPsec SA to the TNGF-CP 230 via the Tl-C connection established for this UE 205 in step 14.
[0089] At step 21, due to the establishment of a secure signaling connection (NWt-C connection) between the UE 205 and the TNGF-CP 230, the TNGF-CP 230 responds to the AMF 245 with an initial context setup response message (see messaging 455).
[0090] At step 22, the AMF 245 completes the 5G registration procedure by sending a registration acceptance message to the UE 205 via the TNGF-CP 230 and the TNGF-SG 225 (see messaging 457). At this time, the UE 205 has successfully registered with the 5GC and has established a secure signaling connection (NWt-C connection) with the TNGF-CP 230, via which NAS messages can be exchanged.
[0091] At step 30, the UE 205 decides to establish a PDU session with the 5GC so that data communication with an external data network (DN) can be performed. For this purpose, the UE 205 sends a PDU session establishment request message to the TNGF-CP 230 via the established NWt-C connection (see messaging 459). The TNGF-CP 230 forwards the PDU session establishment request message to the AMF 245, and the normal PDU session procedure in the 5GC is initiated.
[0092] At step 31, as part of the PDU session establishment procedure, the AMF 245 sends an N2 message (PDU session resource setup request) to the TNGF-CP 230 to trigger the establishment of user plane resources for the requested PDU session in the trusted non-3GPP access network (see messaging 461). This message contains the PDU session identifier, S-NNSAI, information about the QoS flows of the PDU session, and the PDU session establishment acceptance message.
[0093] Continue Figure 4D , at step 32a, TNGF-CP_230 selects, for example based on the received S-NSSAI, the TNGF-UP for this PDU session (see box 463). Here, TNGF-UP 235 is selected. It is envisioned that different TNGF-UPs will be deployed for different S-NSSAIs, so the TNGF-UP that supports the S-NSSAI requested for the PDU session must be selected.
[0094] At step 32b, TNGF-CP 230 determines how many IPsec sub-SAs to establish (see box 465). In the depicted example, TNGF-CP 230 decides to establish one IP sub-SA between UE 205 and TNGF-SG 225 for this PDU session, which will carry all QoS flows of the PDU session. This decision is based on the implementation logic of TNGF-CP 230, and in other cases, TNGF-CP 230 may decide to establish multiple IP sub-SAs for the PDU session, for example, one IP sub-SA for each QoS flow.
[0095] When multiple IP sub-SAs are established between UE_205 and TNGF-SG_225 for a PDU session, then there may be two cases: 1) a single TNGF-UP is selected, in which case all IP sub-SAs are linked to the same TNGF-UP (in this scenario, there is one N3 interface for the PDU session); and 2) multiple TNGF-UPs are selected, each TNGF-UP being linked to one or more IP sub-SAs (in this scenario, there are multiple N3 interfaces for the PDU session, each TNGF-UP having one N3 interface).
[0096] Although scenario 2) is not explicitly discussed in this disclosure, it is considered a viable alternative scenario. When TNGF-CP230 decides to select multiple TNGF-UPs for a PDU session, the following steps 33-34 are repeated for each selected TNGF-UP.
[0097] At step 33a, TNGF-CP 230 sends a request message via the T2 interface to the selected TNGF-UP 235 to prepare TNGF-UP 235 for upcoming user plane communication (see messaging 467). This request message indicates to TNGF-UP 235 the IP address of UPF 250 and the GTP tunnel identifier (referred to as "UL transport information") that TNGF-UP 235 needs to send uplink data to UPF 250 for the PDU session.
[0098] At step 33b, in response, TNGF-UP 235 sends its own IP address and GTP tunnel identifier (referred to as "DL transmission information") to TNGF-CP 230. The UPF 250 needs the IP address and GTP tunnel identifier to send downlink data to TNGF-UP 235 for the PDU session (see signaling 469). At step 36, TNGF-CP 230 sends the IP address and GTP tunnel identifier of TNGF-UP 235 to 5GC 240. Additionally, TNGF-UP 235 sends the IP address (UP_IP_ADDR) to which the UE 205 should send the uplink data for the PDU session to TNGF-CP 230.
[0099] At step 34a, TNGF-CP 230 requests the setup of an IP sub-SA for the PDU session from TNGF-SG 225 by sending a Tl-C message (resource setup request) to TNGF-SG 225. This message contains all the necessary information for setting up the IP sub-SA, including the PDU session ID, QoS flow identifier (QFI), DSCP value, additional QoS information, UP_IP_ADDR assigned by TNGF-UP 235, etc. All these parameters are specified in detail in TS 23.502. It should be noted that TNGF-CP 230 instructs TNGF-SG225 to establish several IP sub-SAs determined in step 32.
[0100] At step 34b, TNGF-SG 225 establishes an IP sub-SA with the UE205, for example, by sending an IKE_Create_Child_SA request message, and at step 34c, the UE 205 sends a response message. At step 34d, after establishing the IP sub-SA with the UE 205, TNGF-SG 225 sends a Tl-C message (resource setup response) indicating that the requested resources have been set to TNGF-CP 230 (see signaling 471).
[0101] At step 35, TNGF-CP 230 sends the PDU session establishment acceptance message received from the AMF 245 at step 31a to the UE 205 (see signaling 473). This message is sent via the established NWt-C connection.
[0102] At step 36, TNGF-CP 230 responds to AMF 245 with a PDU session resource setup response message indicating that the access resources for the PDU session have been established (see signaling 475). This message contains the "DL transport information" received by TNGF-UP 235 in step 33b. After this step, the requested PDU session is established, and UE 205 can communicate with an external data network (DN) via the 5G system.
[0103] At step 37, UE 205 sends each uplink PDU to TNGF-SG 225 via the established IP sub-SA, and TNGF-SG forwards the PDU to the UP IP ADDR of TNGF-UP 235. Subsequently, TNGF-UP 235 forwards the PDU inside the N3 packet to UPF 250 (see signaling 477). A similar forwarding procedure is performed in reverse for each downlink PDU, i.e., UPF 250 forwards the PDU inside the N3 packet to TNGF-UP 235, which in turn sends the downlink PDU to TNGF-SG 225, and TNGF-SG 225 forwards the downlink PDU to UE 205 via the established IP sub-SA.
[0104] Figure 5 Illustrates a split TNGF architecture 500 with established connections and IPsec security associations (SAs) according to an embodiment of the present disclosure. The established connections include an NWt-C connection 505 and at least one NWt-U connection 515. As depicted, the NWt-C connection 505 includes a signaling IPsec SA 510 and supports the delivery of NAS signaling via TCP using TNGF-CP 230. Also as depicted, the NWt-U connection 515 is included within a PDU session 520. The NWt-U connection 515 also includes a sub-IPsec SA 525 and supports the delivery of PDU data via GRE using TNGF-UP 235. UE 205 can communicate with an external data network (DN) 530 via the 5G system 240.
[0105] Figure 5 Schematically shows the established connections and IPsec security associations (SAs) after program 400 (i.e., registration & PDU session establishment) is completed. Resuming the PDU session represents the logical connection between UE 205 and UPF 250. Figure 5 It also shows how the UE 205 exchanges NAS messages with the AMF 245 via the TNGF-CP 230 and the TNGF-SG 225, and how the UE 205 exchanges data PDUs with the UPF 250 via the TNGF-UP 235 and the TNGF-SG 225. The NWt-C connection 505 corresponds to the TCP connection 510 between the UE 205 and the TNGF-CP 230. However, the NWt-U connection 515 between the UE 205 and the TNGF-UP 235 does not correspond to the underlying connection. The NWt-U connection 515 supports only IP communication between the UE 205 and the TNGF-UP 235 by using specific IP addresses: the internal IP address at the UE 205 and the UP_IP_ADDR at the TNGF-UP 235. It should be noted that there may be different TNGF-UP 235s for each IP sub-SA 525 of the PDU session 520, and there is one NWt-U connection 515 for each TNGF-UP 235 involved in the PDU session 520.
[0106] Figure 6 Depicts an embodiment of a user equipment device 600 according to an embodiment of the present disclosure. The user equipment device 600 may be an embodiment of the remote unit 105 and / or the UE 205. In addition, the user equipment device 600 may include a processor 605, a memory 610, an input device 615, an output device 620, and a transceiver 625. In some embodiments, the user equipment device 600 does not include any input device 615 and / or output device 620.
[0107] As depicted, the transceiver 625 includes at least one transmitter 630 and at least one receiver 635. Here, the transceiver 625 communicates with a mobile core network (e.g., 6GC) via an access network. Additionally, the transceiver 625 may support at least one network interface 640. Here, the at least one network interface 640 facilitates communication with the TNGF (e.g., using the "NWt" interface). Additionally, the at least one network interface 640 may include interfaces for communicating with the AMF, SMF, and / or UPF.
[0108] In one embodiment, the processor 605 may include any known controller capable of executing computer-readable instructions and / or capable of performing logical operations. For example, the processor 605 may be a microcontroller, a microprocessor, a central processing unit ("CPU"), a graphics processing unit ("GPU"), an auxiliary processing unit, a field programmable gate array ("FPGA"), or a similar programmable controller. In some embodiments, the processor 605 executes instructions stored in the memory 610 to perform the methods and routines described herein. The processor 605 is communicatively coupled to the memory 610, the input device 615, the output device 620, and the transceiver 625. In various embodiments, the processor 605 controls the user equipment device 600 to perform the above-described UE behaviors.
[0109] In one embodiment, the memory 610 is a computer-readable storage medium. In some embodiments, the memory 610 includes volatile computer storage media. For example, the memory 610 may include RAM, including dynamic RAM ("DRAM"), synchronous dynamic RAM ("SDRAM"), and / or static RAM ("SRAM"). In some embodiments, the memory 610 includes non-volatile computer storage media. For example, the memory 610 may include a hard disk drive, a flash memory, or any other suitable non-volatile computer storage device. In some embodiments, the memory 610 includes both volatile and non-volatile computer storage media.
[0110] In some embodiments, the memory 610 stores data related to UE activities, such as stored identities, message parameters, IP addresses, etc. In certain embodiments, the memory 610 also stores program code and related data, such as an operating system ("OS") or other controller algorithms and one or more software applications operating on the user equipment device 600.
[0111] In one embodiment, the input device 615 may include any known computer input device, including a touch panel, buttons, a keyboard, a stylus, a microphone, etc. In some embodiments, the input device 615 may be integrated with the output device 620, such as a touch screen or a similar touch-sensitive display. In some embodiments, the input device 615 includes a touch screen such that text can be input using a virtual keyboard displayed on the touch screen and / or by handwriting on the touch screen. In some embodiments, the input device 615 includes two or more different devices, such as a keyboard and a touch panel.
[0112] In one embodiment, output device 620 may include any known electronically controllable display or display device. Output device 620 may be designed to output visual, auditory, and / or tactile signals. In some embodiments, output device 620 includes an electronic display capable of outputting visual data to a user. For example, output device 620 may include, but is not limited to, an LCD display, an LED display, an OLED display, a projector, or a similar display device capable of outputting images, text, etc. to a user. As another non-limiting example, output device 620 may include a wearable display, such as a smartwatch, smart glasses, a head-mounted display, etc. Additionally, output device 620 may be a component of a smartphone, a personal digital assistant, a television, a desktop computer, a notebook (laptop) computer, a personal computer, a vehicle dashboard, etc.
[0113] In certain embodiments, output device 620 includes one or more speakers for generating sound. For example, output device 620 may generate an auditory warning or notification (e.g., beeping or ringing). In some embodiments, output device 620 includes one or more haptic devices for generating vibration, movement, or other tactile feedback. In some embodiments, all or part of output device 620 may be integrated with input device 615. For example, input device 615 and output device 620 may form a touchscreen or a similar touch-sensitive display. In other embodiments, all or part of output device 620 may be located near input device 615.
[0114] As described above, transceiver 625 communicates with one or more network functions of a mobile communication network via one or more access networks. Transceiver 625 operates under the control of processor 605 to transmit messages, data, and other signals and also to receive messages, data, and other signals. For example, processor 605 may selectively activate transceiver (or a portion thereof) at a particular time to send and receive messages.
[0115] Transceiver 625 may include one or more transmitters 630 and one or more receivers 635. Although only one transmitter 630 and one receiver 635 are illustrated, user equipment device 600 may have any suitable number of transmitters 630 and receivers 635. Additionally, transmitters 630 and receivers 635 may be of any suitable type of transmitter and receiver. In one embodiment, transceiver 625 includes a first transmitter / receiver pair for communicating with a mobile communication network via a licensed radio spectrum and a second transmitter / receiver pair for communicating with a mobile communication network via an unlicensed radio spectrum.
[0116] In some embodiments, a first transmitter / receiver pair for communicating with a mobile communication network via a licensed radio spectrum and a second transmitter / receiver pair for communicating with the mobile communication network via an unlicensed radio spectrum can be combined into a single transceiver unit, such as a single chip for performing functions that use both the licensed and unlicensed radio spectrums. In some embodiments, the first transmitter / receiver pair and the second transmitter / receiver pair can share one or more hardware components. For example, certain transceivers 625, transmitters 630, and receivers 635 can be implemented as physically separate components that access shared hardware resources and / or software resources, such as a network interface 640.
[0117] In various embodiments, one or more transmitters 630 and / or one or more receivers 635 can be implemented and / or integrated into a single hardware component, such as a multi-transceiver chip, a system-on-chip, an ASIC, or other types of hardware components. In certain embodiments, one or more transmitters 630 and / or one or more receivers 635 can be implemented and / or integrated into a multi-chip module. In some embodiments, other components, such as a network interface 640 or other hardware components / circuits, can be integrated with any number of transmitters 630 and / or receivers 635 into a single chip. In such embodiments, the transmitters 630 and receivers 635 can be logically configured as transceivers 625 that use one or more common control signals, or as modular transmitters 630 and receivers 635 implemented in the same hardware chip or multi-chip module.
[0118] Figure 7 Depicts an embodiment of a network equipment device 700 according to an embodiment of the present disclosure. In some embodiments, the network equipment device 700 can be an embodiment of a TNGF-SG, a TNGF-CP, and / or a TNGF-UP. Additionally, the network equipment device 700 can include a processor 705, a memory 710, an input device 715, an output device 720, and a transceiver 725. In some embodiments, the input device 715 and the output device 720 are combined into a single device (such as a touch screen). In certain embodiments, the network equipment device 700 does not include any input device 715 and / or output device 720.
[0119] As depicted, the transceiver 725 includes at least one transmitter 730 and at least one receiver 735. Here, the transceiver 725 communicates with one or more remote units 105. Additionally, the transceiver 725 can support at least one network interface 740, such as Figure 1 The NWt, N2, and N3 interfaces depicted therein. In some embodiments, transceiver 725 supports a first interface for communicating with a RAN node, a second interface for communicating with one or more network functions in a mobile core network (e.g., 7GC), and a third interface for communicating with a remote unit (e.g., UE).
[0120] In one embodiment, processor 705 may include any known controller capable of executing computer-readable instructions and / or capable of performing logical operations. For example, processor 705 may be a microcontroller, a microprocessor, a central processing unit ("CPU"), a graphics processing unit ("GPU"), an auxiliary processing unit, a field-programmable gate array ("FPGA"), or a similar programmable controller. In some embodiments, processor 705 executes instructions stored in memory 710 to perform the methods and routines described herein. Processor 705 is communicatively coupled to memory 710, input device 715, output device 720, and first transceiver 725.
[0121] In various embodiments, processor 705 controls network equipment device 700 to implement the above-described split TNGF behavior. For example, when implementing the control plane portion of split TNGF, transceiver 725 may support a first interface for communicating with a UE via TNAP (e.g., Ta-C connection) and a second interface for communicating with an AMF in a mobile communication network (e.g., N2 interface).
[0122] Processor 705 receives a request from the AMF. Here, the request is sent during the registration of the UE in the mobile communication network via network equipment device 700, where the request contains a first security key for the UE (e.g., TNGF key) and one or more allowed network slices (e.g., allowed NSSAI). In some embodiments, the request from the AMF is an NGAP initial context setup request message. In some embodiments, the request is sent in response to the UE sending a registration request message to the mobile communication network via network equipment device 700.
[0123] Processor 705 selects a TNGF-SG. In some embodiments, the processor selects a TNGF-SG that supports one or more allowed network slices for the UE. Processor 705 sends a first message to the selected TNGF-SG, the first message containing the first security key, the identification of the UE, and a destination address and port indicating where the UE will send signaling messages (e.g., NAS messages) for the mobile communication network.
[0124] The processor 705 receives a second message from the selected TNGF-SG, and the second message contains the address of the TNGF-SG. In some embodiments, the processor 705 sends the address of the TNGF-SG to the UE. In some embodiments, the first message contains a first connection identifier (e.g., Conn-id-a), and the second message contains a second connection identifier (e.g., Conn-id-b).
[0125] The processor 705 establishes a first connection (i.e., NWt-C connection) with the UE via the selected TNGF-SG. In some embodiments, the establishment of the first connection (i.e., NWt-C connection) indicates that an IPsec SA has been established between the UE and the TNGF-SG, and the IPsec SA is established using a second security key (e.g., IPsec key) derived from a first security key (e.g., TNGF key). In some embodiments, the processor 705 communicates with the UE using the EAP-5G protocol before establishing the first connection.
[0126] In some embodiments, the first connection is established towards a destination address and port (e.g., NAS_IP_ADDR, NAS_PORT) indicating where the UE will send signaling messages for the mobile communication network. In some embodiments, the first message and the second message are used to establish a second connection (e.g., Tl-C connection) between the TNGF-CP and the TNGF-SG, where the second connection is specific to the UE and is used to exchange messages between the TNGF-CP and the TNGF-SG associated with the UE.
[0127] The processor 705 completes the registration of the UE in the mobile communication network. In such embodiments, the processor 705 responds to the NGAP initial context setup request by sending an NGAP initial context setup response message and forwarding the registration acceptance message received from the AMF to the UE to complete the registration of the UE.
[0128] In some embodiments, when implementing the split of the control plane part of the TNGF, the transceiver 725 may support a first interface for communicating with the UE via the selected TNGF-SG (i.e., supporting the NWt-C connection), and a second interface for communicating with the AMF in the mobile communication network (i.e., the N2 interface). The processor 705 receives a request from the AMF, where the request is sent during the establishment of a PDU session for the UE via the device, and the request contains a session identifier (e.g., PDU session ID), a slice identifier (e.g., S-NSSAI), and one or more QoS profiles. In some embodiments, the request from the AMF is an NGAP PDU session resource setup request message. In certain embodiments, the AMF sends the request in response to the UE sending a PDU session establishment request message.
[0129] The processor 705 selects the TNGF-UP. In some embodiments, selecting the TNGF-UP includes selecting a TNGF-UP that supports the slice identifier contained in the support request. In some embodiments, selecting the TNGF-UP includes selecting multiple TNGF-UPs for a PDU session. In some embodiments, the TNGF-SG is selected during the registration of the UE in the mobile communication network.
[0130] The processor 705 sends a first message to the selected TNGF-UP. Here, the first message contains UL transmission information associated with the UPF in the mobile communication network. In some embodiments, the UL transmission information includes the IP address of the UPF and the GTP tunnel identifier. The processor 705 receives a second message from the selected TNGF-UP, and the second message contains DL transmission information associated with the selected TNGF-UP. In some embodiments, the DL transmission information includes the IP address of the selected TNGF-UP (i.e., UP_IP_ADDR) and the GTP tunnel identifier.
[0131] The processor 705 sends a third message requesting to establish one or more security associations with the UE to the selected TNGF-SG. In some embodiments, the processor 705 determines how many security associations to establish based on the QoS profile included in the request from the AMF. In some embodiments, the third message is sent via the Tl-C connection established between the TNGF-CP and the TNGF-SG, where the Tl-C connection is associated with the UE.
[0132] The processor 705 receives a fourth message from the selected TNGF-SG, and the fourth message indicates that one or more security associations with the UE have been established. In some embodiments, the third message contains a first connection identifier received from the TNGF-UP, and the fourth message contains a second connection identifier of the TNGF-SG, where the first and second connection identifiers are used to establish a connection between the TNGF-UP and the TNGF-SG.
[0133] The processor 705 completes the PDU session establishment for the UE. In certain embodiments, the request from the AMF further contains a PDU session establishment acceptance message, where completing the PDU session establishment includes forwarding the PDU session establishment acceptance message to the UE via the first interface and responding to the request from the AMF by sending an NGAP PDU session resource setup response message.
[0134] When implementing the user plane part of the split TNGF, the processor 705 may receive a first message from the TNGF-CP, and the first message contains UL transmission information associated with the UPF in the mobile communication network. In some embodiments, the UL transmission information includes the IP address of the UPF and the GTP tunnel identifier. The processor 705 sends a second message to the TNGF-CP, and the second message contains DL transmission information associated with the TNGF-UP. In some embodiments, the DL transmission information includes the IP address of the network equipment device 700 and the GTP tunnel identifier.
[0135] The processor 705 establishes a connection with the TNGF-SG in the TNAN, where the TNGF-CP and the TNGF-SG establish a PDU session between the UE and the UPF. In some embodiments, the connection with the TNGF-SG corresponds to the N3 tunnel towards the UPF. The processor 705 forwards the UL data corresponding to the PDU session to the UPF, and forwards the DL data corresponding to the PDU session to the TNGF-SG. In some embodiments, forwarding the UL data corresponding to the PDU session includes forwarding the UL data packets received from the TNGF-SG to the N3 tunnel, and forwarding the DL data corresponding to the PDU session includes forwarding the DL data packets received from the N3 tunnel to the TNGF-SG.
[0136] In one embodiment, the memory 710 is a computer-readable storage medium. In some embodiments, the memory 710 includes a volatile computer storage medium. For example, the memory 710 may include RAM, including dynamic RAM ("DRAM"), synchronous dynamic RAM ("SDRAM"), and / or static RAM ("SRAM"). In some embodiments, the memory 710 includes a non-volatile computer storage medium. For example, the memory 710 may include a hard disk drive, flash memory, or any other suitable non-volatile computer storage device. In some embodiments, the memory 710 includes both volatile and non-volatile computer storage media.
[0137] In some embodiments, the memory 710 stores data related to supporting the split TNGF, such as storing security keys, IP addresses, UE contexts, etc. In certain embodiments, the memory 710 also stores program code and related data, such as an operating system ("OS") or other controller algorithms and one or more software applications operating on the network equipment device 700.
[0138] In one embodiment, input device 715 may include any known computer input device, including a touch panel, buttons, a keyboard, a stylus, a microphone, etc. In some embodiments, input device 715 may be integrated with output device 720, such as a touch screen or a similar touch-sensitive display. In some embodiments, input device 715 includes a touch screen such that text may be input using a virtual keyboard displayed on the touch screen and / or by handwriting on the touch screen. In some embodiments, input device 715 includes two or more different devices, such as a keyboard and a touch panel.
[0139] In one embodiment, output device 720 may include any known electronically controllable display or display device. Output device 720 may be designed to output visual, auditory, and / or tactile signals. In some embodiments, output device 720 includes an electronic display capable of outputting visual data to a user. For example, output device 720 may include, but is not limited to, an LCD display, an LED display, an OLED display, a projector, or a similar display device capable of outputting images, text, etc. to a user. As another non-limiting example, output device 720 may include a wearable display, such as a smartwatch, smart glasses, a head-mounted display, etc. Additionally, output device 720 may be a component of a smartphone, a personal digital assistant, a television, a desktop computer, a notebook (laptop) computer, a personal computer, a vehicle dashboard, etc.
[0140] In certain embodiments, output device 720 includes one or more speakers for generating sound. For example, output device 720 may generate an auditory warning or notification (e.g., beeping or ringing). In some embodiments, output device 720 includes one or more haptic devices for generating vibration, movement, or other haptic feedback. In some embodiments, all or part of output device 720 may be integrated with input device 715. For example, input device 715 and output device 720 may form a touch screen or a similar touch-sensitive display. In other embodiments, all or part of output device 720 may be located near input device 715.
[0141] As described above, transceiver 725 may communicate with one or more remote units and / or with one or more interworking functions providing access to one or more PLMNs. Transceiver 725 may also communicate with one or more network functions (e.g., in mobile core network 140). Transceiver 725 operates under the control of processor 705 to transmit messages, data, and other signals and also to receive messages, data, and other signals. For example, processor 705 may selectively activate transceiver (or a portion thereof) at a particular time to send and receive messages.
[0142] The transceiver 725 may include one or more transmitters 730 and one or more receivers 735. In some embodiments, one or more transmitters 730 and / or one or more receivers 735 may share transceiver hardware and / or circuitry. For example, one or more transmitters 730 and / or one or more receivers 735 may share an antenna, an antenna tuner, an amplifier, a filter, an oscillator, a mixer, a modulator / demodulator, a power supply, etc. In one embodiment, the transceiver 725 implements multiple logical transceivers using different communication protocols or protocol stacks while using common physical hardware.
[0143] Figure 8 Depicts an embodiment of a method 800 for supporting sliced TNGF according to an embodiment of the present disclosure. In various embodiments, the method 800 is performed by a sliced TNGF as described above, such as TNGF 125, sliced TNGF 220, TNGF-CP 230, and / or a control plane entity of the network equipment device 700. In some embodiments, the method 800 is performed by a processor, such as a microcontroller, a microprocessor, a CPU, a GPU, an auxiliary processing unit, an FPGA, etc.
[0144] The method 800 begins and receives 805 a request from an AMF in a mobile communication network. Here, the request is sent during the registration of the remote unit via the TNGF-CP in the mobile communication network, and the request contains a first security key for the remote unit and one or more allowed network slices. The method 800 includes selecting 810 a TNGF-SG. The method 800 includes sending 815 a first message to the selected TNGF-SG. Here, the first message contains the first security key, an identifier of the remote unit, and a destination address and port indicating where the remote unit should send signaling messages for the mobile communication network. The method 800 includes receiving 820 a second message from the selected TNGF-SG, the second message containing the address of the TNGF-SG. The method 800 includes establishing 825 a first connection with the remote unit via the selected TNGF-SG. The method 800 includes completing 830 the registration of the remote unit in the mobile communication network. The method 800 ends.
[0145] Figure 9 Depicts an embodiment of a method 900 for supporting sliced TNGF according to an embodiment of the present disclosure. In various embodiments, the method 900 is performed by a sliced TNGF as described above, such as TNGF 125, sliced TNGF 220, TNGF-CP 230, and / or a control plane entity of the network equipment device 700. In some embodiments, the method 900 is performed by a processor, such as a microcontroller, a microprocessor, a CPU, a GPU, an auxiliary processing unit, an FPGA, etc.
[0146] Method 900 starts and receives 905 a request from the AMF, where the request is sent during the establishment of a PDU session for a remote unit via the TNGF-CP, and where the request contains a session identifier (e.g., PDU session ID), a slice identifier (e.g., S-NSSAI), and one or more QoS profiles. Method 900 includes selecting 910 the TNGF-UP. Method 900 includes sending 915 a first message to the selected TNGF-UP, the first message containing UL transport information associated with a UPF in a mobile communication network. Method 900 includes receiving 920 a second message from the selected TNGF-UP, the second message containing DL transport information associated with the selected TNGF-UP. Method 900 includes sending 925 a third message to the selected TNGF-SG, the third message requesting the establishment of one or more security associations with the remote unit. Method 900 includes receiving 930 a fourth message from the selected TNGF-SG, the fourth message indicating that one or more security associations with the remote unit have been established. Method 900 includes completing 935 the PDU session establishment for the remote unit. Method 900 ends.
[0147] Figure 10 Depicts an embodiment of a method 1000 for supporting split TNGF according to an embodiment of the present disclosure. In various embodiments, method 1000 is performed by a user plane entity of a split TNGF as described above, such as TNGF 125, split TNGF 220, TNGF-UP 235, and / or network equipment device 700. In some embodiments, method 1000 is performed by a processor, such as a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, FPGA, etc.
[0148] Method 1000 starts and receives 1005 a first message from the TNGF-CP, the first message containing UL transport information associated with a UPF in a mobile communication network. Method 1000 includes sending a second message to the TNGF-CP, the second message containing DL transport information associated with the TNGF-UP. Method 1000 includes establishing a connection with the TNGF-SG in the TNAN. Here, the TNGF-CP and the TNGF-SG establish a PDU session between the remote unit and the UPF. Method 1000 includes forwarding UL data corresponding to the PDU session to the UPF. Method 1000 includes forwarding DL data corresponding to the PDU session to the TNGF-SG. Method 1000 ends.
[0149] According to an embodiment of the present disclosure, a first device for supporting sliced TNGF is disclosed herein. The first device may be implemented by a sliced TNGF, such as TNGF 125, sliced TNGF 220, TNGF-CP 230, and / or a control plane portion of a network equipment device 700. The first device includes a processor, a first interface (e.g., supporting a Ta-C connection) that communicates with a remote unit via a TNAP, and a second interface (e.g., an N2 interface) that communicates with an AMF in a mobile communication network. The processor receives a request from the AMF. Here, during the registration of the remote unit in the mobile communication network via the device, the request contains a first security key (e.g., a TNGF key) for the remote unit and one or more allowed network slices (e.g., an allowed NSSAI). The processor selects a (TNGF-SG) and sends a first message to the selected TNGF-SG, the first message containing the first security key, the identifier of the remote unit, and a destination address and port indicating where the remote unit should send signaling messages (e.g., NAS messages) for the mobile communication network. The processor receives a second message containing the address of the TNGF-SG from the selected TNGF-SG and establishes a first connection (i.e., an NWt-C connection) with the remote unit via the selected TNGF-SG. The processor completes the registration of the remote unit in the mobile communication network.
[0150] In some embodiments, the request from the AMF is an NGAP initial context setup request message. In such embodiments, the processor responds to the NGAP initial context setup request by sending an NGAP initial context setup response message and forwarding the registration acceptance message received from the AMF to the remote unit to complete the registration of the remote unit. In some embodiments, the request is sent in response to the remote unit sending a registration request message to the mobile communication network via the device.
[0151] In some embodiments, selecting a TNGF-SG includes selecting a TNGF-SG that supports one or more allowed network slices for the remote unit. In some embodiments, the processor sends the address of the TNGF-SG to the remote unit.
[0152] In some embodiments, the first message contains a first connection identifier (e.g., Conn-id-a), and the second message contains a second connection identifier (e.g., Conn-id-b). In some embodiments, the first message and the second message are used to establish a second connection (e.g., a Tl-C connection) between the TNGF-CP and the TNGF-SG, where the second connection is specific to the remote unit and is used to exchange messages between the TNGF-CP and the TNGF-SG associated with the remote unit.
[0153] In some embodiments, the establishment of the first connection (i.e., the NWt-C connection) indicates that an IPsec SA has been established between the remote unit and the TNGF-SG, where the IPsec SA is established using a second security key (e.g., the IPsec key) derived from a first security key (e.g., the TNGF key). In some embodiments, the first connection is established towards the destination address and port (e.g., NAS_IP_ADDR, NAS_PORT) indicating where the remote unit will send signaling messages for the mobile communication network. In some embodiments, the processor communicates with the remote unit using the EAP-5G protocol before establishing the first connection.
[0154] According to an embodiment of the present disclosure, a first method for supporting split TNGF is disclosed herein. The first method may be performed by a control plane portion of a split TNGF, such as TNGF 125, split TNGF 220, TNGF-CP 230, and / or network equipment device 700. The first method includes receiving a request from an AMF in a mobile communication network. Herein, the request is sent during the registration of the remote unit via the TNGF-CP in the mobile communication network, and the request contains a first security key (e.g., the TNGF key) for the remote unit and one or more allowed network slices (e.g., the allowed NSSAI). The first method includes selecting a TNGF-SG and sending a first message to the selected TNGF-SG. Herein, the first message contains the first security key, the identity of the remote unit, and a destination address and port indicating where the remote unit should send signaling messages (e.g., NAS messages) for the mobile communication network. The first method includes receiving a second message containing the address of the TNGF-SG from the selected TNGF-SG, and establishing a first connection (i.e., the NWt-C connection) with the remote unit via the selected TNGF-SG. The first method includes completing the registration of the remote unit in the mobile communication network.
[0155] In some embodiments, the request from the AMF is an NGAP initial context setup request message. In certain embodiments, completing the registration of the remote unit includes responding to the NGAP initial context setup request by sending an NGAP initial context setup response message and forwarding the registration acceptance message received from the AMF to the remote unit. In some embodiments, the request is sent in response to the remote unit sending a registration request message to the mobile communication network via the TNGF-CP.
[0156] In some embodiments, selecting the TNGF-SG includes selecting a TNGF-SG that supports one or more allowed network slices for the remote unit. In some embodiments, the first method includes sending the address of the TNGF-SG to the remote unit.
[0157] In some embodiments, the first message contains a first connection identifier (e.g., Conn-id-a), and wherein the second message contains a second connection identifier (e.g., Conn-id-b). In some embodiments, the first message and the second message are used to establish a second connection (e.g., Tl-C connection) between the TNGF-CP and the TNGF-SG, wherein the second connection is specific to the remote unit and is used to exchange messages between the TNGF-CP and the TNGF-SG associated with the remote unit.
[0158] In some embodiments, the establishment of the first connection (i.e., NWt-C connection) indicates that an IPsec SA has been established between the remote unit and the TNGF-SG, wherein the IPsec SA is established using a second security key (e.g., IPsec key) derived from a first security key (e.g., TNGF key). In some embodiments, the first connection is established towards a destination address and port (e.g., NAS_IP_ADDR, NAS_PORT) indicating where the remote unit will send signaling messages for the mobile communication network. In some embodiments, the TNGF-CP communicates with the remote unit using the EAP-5G protocol before establishing the first connection.
[0159] According to an embodiment of the present disclosure, a second device for supporting split TNGF is disclosed herein. The second device may be implemented by a control plane portion of a split TNGF, such as TNGF 125, split TNGF 220, TNGF-CP 230, and / or network equipment device 700. The second device includes a processor, a first interface (i.e., supporting NWt-C connection) for communicating with a remote unit via a selected TNGF-SG, and a second interface (i.e., N2 interface) for communicating with an AMF in the mobile communication network.
[0160] The processor receives a request from the AMF, wherein the request is sent during the establishment of a PDU session for the remote unit via the device, and wherein the request contains a session identifier (e.g., PDU session ID), a slice identifier (e.g., S-NSSAI), and one or more QoS profiles. The processor selects a TNGF-UP and sends a first message to the selected TNGF-UP. Here, the first message contains UL transport information associated with a UPF in the mobile communication network. The processor receives a second message from the selected TNGF-UP, the second message containing DL transport information associated with the selected TNGF-UP, and sends a third message requesting to establish one or more security associations with the remote unit to the selected TNGF-SG. The processor receives a fourth message from the selected TNGF-SG and completes the establishment of the PDU session for the remote unit, the fourth message indicating that one or more security associations with the remote unit have been established.
[0161] In some embodiments, the request from the AMF is an NGAP PDU session resource setup request message. In certain embodiments, the AMF sends the request in response to the remote unit sending a PDU session establishment request message. In certain embodiments, the request from the AMF further includes a PDU session establishment accept message, where completing the PDU session establishment includes forwarding the PDU session establishment accept message to the remote unit via a first interface and responding to the request from the AMF by sending an NGAP PDU session resource setup response message.
[0162] In some embodiments, selecting the TNGF-UP includes selecting a TNGF-UP that supports the slice identifier included in the request. In some embodiments, selecting the TNGF-UP includes selecting multiple TNGF-UPs for a PDU session. In such embodiments, each of the multiple TNGF-UPs is linked to one or more IPsec sub-security associations. In some embodiments, the third message is sent via a Tl-C connection established between the TNGF-CP and the TNGF-SG, where the Tl-C connection is associated with the remote unit.
[0163] In some embodiments, the TNGF-SG is selected during the registration of the remote unit in the mobile communication network. In some embodiments, the processor determines how many security associations to establish based on the QoS profile included in the request from the AMF.
[0164] In some embodiments, the UL transmission information includes the IP address of the UPF and the GTP tunnel identifier. In some embodiments, the DL transmission information includes the IP address of the selected TNGF-UP (i.e., UP_IP_ADDR) and the GTP tunnel identifier. In some embodiments, the third message contains a first connection identifier received from the TNGF-UP, and the fourth message contains a second connection identifier of the TNGF-SG, where the first and second connection identifiers are used to establish a connection between the TNGF-UP and the TNGF-SG.
[0165] According to an embodiment of the present disclosure, a second method for supporting sliced TNGF is disclosed herein. The second method may be performed by a control plane portion of a sliced TNGF ("TNGF-CP"), such as TNGF 125, sliced TNGF 220, TNGF-CP 230, and / or network equipment device 700. The second method includes receiving a request from an AMF, where the request is sent during establishment of a PDU session for a remote unit via the TNGF-CP, and where the request contains a session identifier (e.g., PDU session ID), a slice identifier (e.g., S-NSSAI), and one or more QoS profiles. The second method includes selecting a TNGF-UP and sending a first message to the selected TNGF-UP, the first message containing UL transport information associated with a UPF in a mobile communication network. The second method includes: receiving a second message from the selected TNGF-UP, the second message containing DL transport information associated with the selected TNGF-UP; and sending a third message to the selected TNGF-SG, the third message requesting establishment of one or more security associations with the remote unit. The second method includes: receiving a fourth message from the selected TNGF-SG, the fourth message indicating that one or more security associations with the remote unit have been established; and completing the PDU session establishment for the remote unit.
[0166] In some embodiments, the request from the AMF is an NGAP PDU session resource setup request message. In certain embodiments, the AMF sends the request in response to a PDU session establishment request message sent by the remote unit. In certain embodiments, the request from the AMF further contains a PDU session establishment accept message, where completing the PDU session establishment includes forwarding the PDU session establishment accept message to the remote unit via a first interface and responding to the request from the AMF by sending an NGAP PDU session resource setup response message.
[0167] In some embodiments, selecting a TNGF-UP includes selecting a TNGF-UP that supports the slice identifier contained in the request. In some embodiments, selecting a TNGF-UP includes selecting multiple TNGF-UPs for a PDU session. In such embodiments, each of the multiple TNGF-UPs is linked to one or more IPsec sub-security associations. In some embodiments, the third message is sent via a Tl-C connection established between the TNGF-CP and the TNGF-SG, where the Tl-C connection is associated with the remote unit.
[0168] In some embodiments, the TNGF-SG is selected during registration of the remote unit with the mobile communication network. In some embodiments, the second method includes determining how many security associations to establish based on a QoS profile included in a request from the AMF. In some embodiments, the UL transmission information includes the IP address of the UPF and a GTP tunnel identifier.
[0169] In some embodiments, the DL transmission information includes the IP address of the selected TNGF-UP and a GTP tunnel identifier. In some embodiments, the third message contains a first connection identifier received from the TNGF-UP, and the fourth message contains a second connection identifier of the TNGF-SG, where the first and second connection identifiers are used to establish a connection between the TNGF-UP and the TNGF-SG.
[0170] According to embodiments of the present disclosure, a third device using a split TNGF is disclosed herein. The third device may be implemented by a user plane portion of a split TNGF (i.e., "TNGF-UP"), such as TNGF 125, split TNGF 220, TNGF-UP 235, and / or network equipment device 700. The third device includes a processor and a network interface that receives a first message from the TNGF-CP, the first message containing UL transmission information associated with a UPF in the mobile communication network. The processor sends a second message containing DL transmission information associated with the TNGF-UP to the TNGF-CP, and establishes a connection with the TNGF-SG in the TNAN, where the TNGF-CP and the TNGF-SG establish a PDU session between the remote unit and the UPF. The processor forwards UL data corresponding to the PDU session to the UPF, and forwards DL data corresponding to the PDU session to the TNGF-SG.
[0171] In some embodiments, the UL transmission information includes the IP address of the UPF and a GTP tunnel identifier. In some embodiments, the DL transmission information includes the IP address of the TNGF-UP and a GTP tunnel identifier. In some embodiments, the connection with the TNGF-SG corresponds to an N3 tunnel towards the UPF. In such embodiments, forwarding UL data corresponding to the PDU session includes forwarding UL data packets received from the TNGF-SG to the N3 tunnel, and forwarding DL data corresponding to the PDU session includes forwarding DL data packets received from the N3 tunnel to the TNGF-SG.
[0172] According to an embodiment of the present disclosure, a third method of using sliced TNGF is disclosed herein. The third method may be performed by a sliced TNGF, such as TNGF 125, sliced TNGF_220, TNGF-UP 235, and / or a user plane portion of the network equipment device 700. The third method includes receiving a first message from the TNGF-CP, the first message containing UL transmission information associated with a UPF in a mobile communication network. The third method includes: sending a second message to the TNGF-CP, the second message containing DL transmission information associated with the TNGF-UP; and establishing a connection with the TNGF-SG in the TNAN. Here, the TNGF-CP and the TNGF-SG establish a PDU session between the remote unit and the UPF. The third method includes forwarding UL data corresponding to the PDU session to the UPF and forwarding DL data corresponding to the PDU session to the TNGF-SG.
[0173] In some embodiments, the UL transmission information includes the IP address of the UPF and the GTP tunnel identifier. In some embodiments, the DL transmission information includes the IP address of the TNGF-UP and the GTP tunnel identifier. In some embodiments, the connection with the TNGF-SG corresponds to an N3 tunnel towards the UPF. In such embodiments, forwarding UL data corresponding to the PDU session includes forwarding UL data packets received from the TNGF-SG to the N3 tunnel, and forwarding DL data corresponding to the PDU session includes forwarding DL data packets received from the N3 tunnel to the TNGF-SG.
[0174] Embodiments may be practiced in other specific forms. The described embodiments should be considered illustrative rather than restrictive in all respects. Accordingly, the scope of the present invention is indicated by the appended claims rather than by the foregoing description. All changes that fall within the equivalent meaning and scope of the claims should be included within their scope.< / mcc> < / mnc>
Claims
1. A device for a trusted non-3GPP gateway function control plane TNGF-CP in a trusted non-3GPP access network TNAN, which comprises: a processor; and a memory coupled to the processor, the memory including instructions that can be executed by the processor to cause the device to: receive a request from an access and mobility management function AMF, where the request is associated with a registration procedure of a user equipment UE via the device in the network, and where the request contains a first security key and indicates one or more allowed network slices for the UE; select a trusted non-3GPP gateway function security gateway TNGF-SG; send a first message to the selected TNGF-SG, the first message containing the first security key, an identifier of the UE, and a destination address and port indicating where the UE will send signaling messages for the mobile communication network, where the first security key is used to establish secure communication between the TNGF-SG and the UE; receive a second message from the selected TNGF-SG, the second message containing an address of the TNGF-SG; establish a first connection with the UE via the selected TNGF-SG; and complete the registration procedure.
2. The device according to claim 1, wherein the received request includes a next generation application protocol NGAP initial context setup request message, and wherein, to complete the registration procedure, the instructions can further be executed by the processor to cause the device to: respond to the NGAP initial context setup request by sending an NGAP initial context setup response message; and forward a registration acceptance message received from the AMF to the UE.
3. The device according to claim 1, wherein the instructions can further be executed by the processor to cause the device to forward a registration request message to the AMF, where the request is received in response to forwarding the registration request message to the AMF.
4. The device according to claim 1, wherein, to select the TNGF-SG, the instructions can further be executed by the processor to cause the device to: select a TNGF-SG that supports the one or more allowed network slices for the UE, and send the address of the TNGF-SG to the UE.
5. The device according to claim 1, wherein the instructions can further be executed by the processor to cause the device to establish a second connection between the device and the TNGF-SG using the first message and the second message, where the second connection is specific to the UE and is used to exchange messages between the device and the TNGF-SG associated with the UE.
6. The device according to claim 1, wherein the establishment of the first connection indicates that an Internet Protocol Security (IPsec) security association (SA) has been established between the UE and the TNGF-SG, and wherein the IPsec SA is established using a second security key derived from the first security key.
7. The device according to claim 1, wherein the first connection is established towards the destination address and port, which indicate where the UE will send signaling messages for the mobile communication network.
8. The device according to claim 1, wherein the instructions are further executable by the processor to cause the device to communicate with the UE using the EAP-5G protocol before establishing the first connection.
9. A device for a trusted non-3GPP gateway function control plane (TNGF-CP) in a trusted non-3GPP access network (TNAN), the device comprising: a processor; and a memory coupled to the processor, the memory including instructions executable by the processor to cause the device to: communicate with a user equipment (UE) via a selected trusted non-3GPP gateway function security gateway (TNGF-SG); receive a request from an access and mobility management function (AMF) in a mobile communication network, wherein the request is sent during establishment of a protocol data unit (PDU) session for the UE via the device, and wherein the request contains a session identifier, a slice identifier, and one or more quality of service (QoS) profiles, and wherein a first security key provided by the AMF is used to establish secure communication between the TNGF-SG and the UE; select a TNGF-user plane entity (TNGF-UP); send a first message to the selected TNGF-UP, the first message containing uplink (UL) transport information associated with a user plane function (UPF) in the mobile communication network; receive a second message from the selected TNGF-UP, the second message containing downlink (DL) transport information associated with the selected TNGF-UP; send a third message to the selected TNGF-SG, the third message requesting establishment of one or more security associations with the UE; receive a fourth message from the selected TNGF-SG, the fourth message indicating that the one or more security associations with the UE have been established; and complete PDU session establishment for the UE.
10. The device according to claim 9, wherein the request from the AMF is a next generation application protocol (NGAP) PDU session resource setup request message, and wherein the instructions are further executable by the processor to cause the device to forward a PDU session establishment request message to the AMF, and wherein the request is received in response to forwarding the PDU session establishment request message to the AMF.
11. The apparatus according to claim 10, wherein the request includes a PDU session establishment acceptance message, and for completing the PDU session establishment, the instructions are further executable by the processor to cause the apparatus to forward the PDU session establishment acceptance message to the UE and send an NGAP PDU session resource setup response message in response to the request from the AMF.
12. The apparatus according to claim 9, wherein the instructions are further executable by the processor to cause the apparatus to select the TNGF-SG during registration of the UE in the mobile communication network, and for selecting the TNGF-UP, the instructions are further executable by the processor to cause the apparatus to select a corresponding TNGF-UP that supports the slice identifier included in the request.
13. The apparatus according to claim 9, wherein for selecting the TNGF-UP, the instructions are further executable by the processor to cause the apparatus to select a plurality of TNGF-UPs for a PDU session, and each of the plurality of TNGF-UPs is linked to one or more Internet Protocol Security (IPsec) sub-security associations.
14. The apparatus according to claim 9, wherein the third message is sent via a Tl-C connection established between the apparatus and the TNGF-SG, and the Tl-C connection is associated with the UE.
15. The apparatus according to claim 9, wherein the instructions are further executable by the processor to cause the apparatus to determine how many security associations to establish based on the QoS profile included in the request from the AMF.
16. The apparatus according to claim 9, wherein the UL transport information includes the Internet Protocol (IP) address of the UPF and the General Packet Radio Service (GPRS) tunnel identifier of the UPF, and the DL transport information includes the IP address of the selected TNGF-UP and the GTP tunnel identifier of the selected TNGF-UP.
17. The apparatus according to claim 9, wherein the third message contains a first connection identifier received from the TNGF-UP, and the fourth message contains a second connection identifier of the TNGF-SG, and the instructions are further executable by the processor to cause the apparatus to establish a connection between the TNGF-UP and the TNGF-SG using the first and second connection identifiers.
18. An apparatus for a trusted non-3GPP gateway function user plane (TNGF-UP) in a trusted non-3GPP access network (TNAN), the apparatus comprises: a processor; and a memory coupled to the processor, the memory including instructions that are executable by the processor to cause the apparatus to: receive a first message from a trusted non-3GPP gateway function control plane entity (TNGF-CP), the first message containing uplink (UL) transport information associated with a user plane function (UPF) in a mobile communication network; and send a second message to the TNGF-CP, the second message containing downlink DL transmission information associated with the device; establish a connection with a TNGF-SG in the TNAN, wherein the TNGF-CP and the TNGF-SG establish a protocol data unit PDU session between a user equipment UE and the UPF, wherein a first security key provided by an access and mobility management function AMF is used to establish secure communication between the TNGF-SG and the UE; forward UL data corresponding to the PDU session to the UPF; and forward DL data corresponding to the PDU session to the TNGF-SG.
19. The apparatus according to claim 18, wherein the UL transmission information includes an Internet protocol IP address of the UPF and a general packet radio service tunneling protocol GTP tunnel identifier of the UPF, and wherein the DL transmission information includes an IP address of the device and a GTP tunnel identifier of the device.
20. The apparatus according to claim 18, wherein the connection with the TNGF-SG corresponds to an N3 tunnel towards the UPF, and wherein for forwarding UL data corresponding to the PDU session, the instruction is further executable by the processor to cause the device to forward UL data packets received from the TNGF-SG to the N3 tunnel, and wherein for forwarding DL data corresponding to the PDU session, the instruction is further executable by the processor to cause the device to forward DL data packets received from the N3 tunnel to the TNGF-SG.
21. A processor for a trusted non-3GPP gateway function control plane TNGF-CP in a trusted non-3GPP access network TNAN, the comprising: at least one controller coupled to at least one memory and configured to cause the processor to: receive a request from an access and mobility management function AMF, wherein the request is associated with a registration procedure of a user equipment UE via the processor in the network, and wherein the request contains a first security key and indicates one or more allowed network slices for the UE; select a trusted non-3GPP gateway function security gateway TNGF-SG; send a first message to the selected TNGF-SG, the first message containing the first security key, an identifier of the UE, and a destination address and port indicating where the UE will send signaling messages for the mobile communication network, wherein the first security key is used to establish secure communication between the TNGF-SG and the UE; receive a second message from the selected TNGF-SG, the second message containing an address of the TNGF-SG; establish a first connection with the UE via the selected TNGF-SG; and complete the registration procedure.
Citation Information
Patent Citations
Security gateway selection in hybrid 4g and 5g networks
WO2019097499A1