Secure protection of user consent for edge computing

By transmitting the indication of user consent in the cellular network, the problem of the cellular network not obtaining user consent is solved, secure access to UE location information is achieved, and information security and user privacy protection are improved.

CN116235515BActive Publication Date: 2025-09-09APPLE INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202080105228.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-16
Publication Date
2025-09-09
Estimated Expiration
2040-09-16

AI Technical Summary

Technical Problem

In the existing technology, cellular networks fail to effectively obtain user consent before accessing user equipment (UE) location information, resulting in information security risks.

Method used

Secure connections are achieved by transmitting an indication of user consent from the user equipment (UE) to the network, ensuring authorization before accessing UE location information, and utilizing protected messages during initial registration, UE configuration update, and PDU session establishment.

Benefits of technology

Ensure the security of UE location information when accessing the network, prevent unauthorized entities from obtaining it, and improve information security and user privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116235515B_ABST
    Figure CN116235515B_ABST
Patent Text Reader

Abstract

Example embodiments relate to a user equipment (UE) that provides a network with an indication of user consent for access to UE information. The UE may perform operations including transmitting the indication of user consent to a first network. The user consent corresponds to a network function obtaining the UE information. The operations also include transmitting the UE information to the first network and establishing a connection with a second network. The network function performs operations related to establishing the connection between the UE and the second network using the UE information.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] User equipment (UE) can connect to an edge data network to access edge computing services. Edge computing refers to performing computation and data processing at the network where the data is generated. When connected, application data can flow between the UE and the edge application server (EAS) of the edge data network.

[0002] The cellular network may perform operations related to establishing a connection between the UE and the EAS of the edge data network. For example, the cellular network may access the UE location information and determine an appropriate packet data unit (PDU) session anchor (PSA) for the UE location. However, the network may obtain user consent to access the UE location information before accessing the UE location information. Summary of the Invention

[0003] Some example embodiments relate to a baseband processor configured to perform operations. The operations include transmitting an indication of user consent to a first network. The user consent corresponds to a network function obtaining UE information. The operations also include transmitting UE information to the first network and establishing a connection with a second network. The network function performs operations related to establishing a connection between the UE and the second network using the UE information.

[0004] Other exemplary embodiments relate to a user equipment (UE) comprising: a transceiver configured to communicate with multiple networks; and a processor communicatively coupled to the transceiver and configured to perform operations. The operations include transmitting an indication of user consent to a first network. The user consent corresponds to a network function obtaining UE information. The operations also include transmitting UE information to the first network and establishing a connection with a second network. The network function performs operations related to establishing a connection between the UE and the second network using the UE information.

[0005] Other exemplary embodiments relate to a method performed by a user equipment (UE). The method includes transmitting an indication of user consent to a first network. The user consent corresponds to a network function obtaining UE information. The operation also includes transmitting the UE information to the first network and establishing a connection with a second network. The network function performs operations related to establishing a connection between the UE and the second network using the UE information. BRIEF DESCRIPTION OF THE DRAWINGS

[0006] Figure 1 Exemplary network arrangements are shown according to various exemplary embodiments.

[0007] Figure 2 An exemplary user equipment (UE) is shown in accordance with various exemplary embodiments.

[0008] Figure 3An architecture for enabling edge applications according to various exemplary embodiments is shown.

[0009] Figure 4 Methods for establishing a connection between a UE and an edge data network using UE location information are shown according to various exemplary embodiments.

[0010] Figure 5a A signaling diagram is shown for a UE to provide an indication of user consent to the network during an initial registration procedure according to various exemplary embodiments.

[0011] Figure 5b A signaling diagram is shown for a UE to provide an indication of user consent to the network during an initial registration procedure according to various exemplary embodiments.

[0012] Figure 6 A signaling diagram is shown for UE 110 to provide an indication of user consent to the network during a UE configuration update procedure according to various exemplary embodiments.

[0013] Figure 7 A signaling diagram for a UE to provide an indication of user consent to the network during a packet data unit (PDU) session establishment is shown in accordance with various exemplary embodiments. DETAILED DESCRIPTION

[0014] The exemplary embodiments may be further understood with reference to the following description and associated drawings, wherein like elements have the same reference numerals.The exemplary embodiments relate to a user equipment (UE) that provides an indication of user consent to access UE information to a network.

[0015] The exemplary embodiments are described with respect to a UE. However, reference to a UE is provided for illustrative purposes only. The exemplary embodiments may be used with any electronic component that can establish a connection with a network and is configured with hardware, software, and / or firmware for exchanging information and data with the network. Therefore, as described herein, a UE is intended to represent any suitable electronic component.

[0016] Example embodiments are also described with reference to a 5G New Radio (NR) network. However, reference to a 5G NR network is provided for illustrative purposes only. Example embodiments may be used with any network that implements the functionality described herein for edge computing. Thus, a 5G NR network as described herein may represent any network that includes functionality associated with edge computing.

[0017] In addition, the exemplary embodiments are described with reference to edge computing (EC). The UE can access the edge data network via the 5G NR network. The edge data network can provide the UE with access to edge computing services. Edge computing generally refers to performing computing and data processing at the network where the data is generated. Compared to traditional methods that utilize a centralized architecture, edge computing is a distributed approach in which data processing is located towards the edge of the network, closer to the end user. This allows performance to be optimized and latency to be minimized.

[0018] The 5G NR network may collect UE location information to facilitate establishing a connection between the UE and an edge application server (EAS) of an edge data network. However, the 5G NR network may be configured to receive user consent before accessing the UE location information. An exemplary embodiment relates to the UE providing an indication of user consent to the 5G NR network that the network is authorized to access the UE location information. As will be described in more detail below, the exemplary embodiment includes various techniques for providing an indication of user consent to the 5G NR network in a protected message. These techniques ensure that the indication of user consent is not modified when it is sent to the network, and therefore the corresponding UE information is not disclosed to unauthorized entities.

[0019] Throughout this specification, the term "user consent" generally refers to an indication that a user of a UE has authorized the network to access one or more types of UE information and / or perform operations associated with the UE. This indication may be based on user input, pre-configured settings, an agreement between the user and the network operator, an agreement between the user and a third party, or any other appropriate factor. In some examples, user consent is described as corresponding to network access to UE location information. However, reference to UE location information is provided for illustrative purposes only, and the exemplary embodiments are applicable to user consent associated with any type of UE information, features, and / or operations.

[0020] Figure 1 An exemplary network arrangement 100 according to various exemplary embodiments is shown. The exemplary network arrangement 100 includes a UE 110. Those skilled in the art will appreciate that the UE 110 can be any type of electronic component configured to communicate via a network, such as a mobile phone, tablet computer, desktop computer, smartphone, phablet, embedded device, wearable device, Cat-M device, Cat-M1 device, MTC device, eMTC device, other types of Internet of Things (IoT) devices, etc. A practical network arrangement can include any number of UEs used by any number of users. Therefore, the example of a single UE 110 is provided for illustrative purposes only.

[0021] UE 110 can be configured to communicate with one or more networks. In the example of network configuration 100, the network with which UE 110 can wirelessly communicate is a 5G NR radio access network (RAN) 120. However, UE 110 can also communicate with other types of networks (e.g., 5G cloud RAN, LTE RAN, traditional cellular network, WLAN, etc.), and UE 110 can also communicate with the network via a wired connection. Regarding the exemplary embodiment, UE 110 can establish a connection with 5G NR RAN 120. Therefore, UE 110 can have a 5G NR chipset to communicate with NR RAN 120.

[0022] The 5G NR RAN 120 may be part of a cellular network that may be deployed by a network operator, such as Verizon, AT&T, Sprint, T-Mobile, etc. The 5G NR RAN 120 may include, for example, cells or base stations (Node B, eNodeB, HeNB, eNBS, gNB, gNodeB, macrocell base stations, microcell base stations, small cell base stations, femtocell base stations, etc.) configured to send and receive communication traffic from UEs equipped with appropriate cellular chipsets.

[0023] In network arrangement 100, 5G NR RAN 120 includes cell 120A, which represents a gNB. However, a practical network arrangement may include any number of different types of cells deployed by any number of RANs. Therefore, for illustrative purposes, an example with a single cell 120A is provided.

[0024] UE 110 may connect to 5G NR-RAN 120 via cell 120A. Those skilled in the art will appreciate that any relevant procedures may be performed for UE 110 to connect to 5G NR-RAN 120. For example, as described above, 5G NR-RAN 120 may be associated with a particular cellular provider, where UE 110 and / or its user has protocol and credential information (e.g., stored on a SIM card). Upon detecting the presence of 5G NR-RAN 120, UE 110 may transmit corresponding credential information to associate with 5G NR-RAN 120. More specifically, UE 110 may associate with a particular cell (e.g., cell 120A). However, as described above, reference to 5G NR-RAN 120 is for illustrative purposes only, and any suitable type of RAN may be used.

[0025] The network arrangement 100 also includes a cellular core network 130. The cellular core network 130 can be viewed as an interconnected collection of components that manage the operation and traffic of the cellular network. In this example, the components include an access and mobility management function (AMF) 131, a policy control function (PCF) 132, a session management function (SMF) 133, and a user plane function (UPF) 134. However, a practical cellular core network may include various other components that perform any of a variety of different functions.

[0026] The AMF 131 performs operations related to mobility management, such as, but not limited to, paging, non-access stratum (NAS) management, and registration procedure management between the UE 110 and the cellular core network 130. Reference to a single AMF 131 is for illustrative purposes only, and an actual network arrangement may include any appropriate number of AMFs.

[0027] PCF 132 performs control plane related operations such as, but not limited to, managing policy rules for control plane functions, including network slicing, roaming, and mobility management. Reference to a single PCF 132 is for illustrative purposes only, and an actual network deployment may include any appropriate number of PCFs.

[0028] SMF 133 performs operations related to session management, such as, but not limited to, session establishment, session release, IP address allocation, policy and quality of service (QoS) enforcement, etc. SMF 133 may be equipped with one or more communication interfaces to communicate with other network components (e.g., network functions, RAN, UE, etc.). The exemplary embodiments are not limited to SMFs performing the above-referenced operations. Those skilled in the art will appreciate the various different types of operations that can be performed by SMFs. Furthermore, reference to a single SMF 133 is for illustrative purposes only, and an actual network deployment may include any appropriate number of SMFs.

[0029] The UPF 134 performs operations related to packet data unit (PDU) session management. For example, the UPF 134 may facilitate a connection between the UE 110 and the edge data network 170. The UPF 134 may be equipped with one or more communication interfaces to communicate with other networks and / or network components (e.g., network functions, RAN, UE, etc.). The exemplary embodiments are not limited to UPFs performing the above-referenced operations. Those skilled in the art will appreciate the various different types of operations that the UPF may perform. Furthermore, reference to a single UPF 134 is for illustrative purposes only, and an actual network arrangement may include any appropriate number of UPFs.

[0030] The network arrangement 100 also includes the Internet 140, an IP Multimedia Subsystem (IMS) 150, and a network service backbone 160. The cellular core network 130 manages traffic flowing between the cellular network and the Internet 140. The IMS 150 can generally be described as an architecture for delivering multimedia services to the UE 110 using IP protocols. The IMS 150 can communicate with the cellular core network 130 and the Internet 140 to provide multimedia services to the UE 110. The network service backbone 160 communicates directly or indirectly with the Internet 140 and the cellular core network 130. The network service backbone 160 can generally be described as a set of components (e.g., servers, network storage arrangements, etc.) that implement a set of services that can be used to extend the functionality of the UE 110 to communicate with various networks.

[0031] Furthermore, the network arrangement 100 includes an edge data network 170 and an edge configuration server (ECS) 180. The exemplary embodiment is described with respect to implementing authentication and authorization procedures between the UE 110 and the ECS 180. Figure 3 Edge data network 170 and ECS 180 are described in more detail.

[0032] Figure 2 An exemplary UE 110 is shown according to various exemplary embodiments. Figure 1 100 is used to describe the UE 110. The UE 110 may include a processor 205, a memory arrangement 210, a display device 215, an input / output (I / O) device 220, a transceiver 225, and other components 230. The other components 230 may include, for example, an audio input device, an audio output device, a power source, a data acquisition device, a port for electrically connecting the UE 110 to other electronic devices, and the like.

[0033] The processor 205 may be configured to execute various types of software. For example, the processor may execute the user consent engine 235. The user consent engine 235 may perform various operations related to providing the network with an indication of user consent for network access to UE location information.

[0034] The aforementioned execution of the engine by processor 205 is merely exemplary. Functionality associated with software may also be represented as a separate, integrated component of UE 110, or may be a modular component coupled to UE 110, such as an integrated circuit with or without firmware. For example, an integrated circuit may include input circuitry for receiving signals and processing circuitry for processing signals and other information. The engine may also be embodied as a single application or as separate applications. Furthermore, in some UEs, the functionality described with respect to processor 205 is shared between two or more processors, such as a baseband processor and an application processor. The exemplary embodiments may be implemented in any of these or other configurations of a UE.

[0035] The memory arrangement 210 may be a hardware component configured to store data related to operations performed by the UE 110. The display device 215 may be a hardware component configured to display data to a user, and the I / O device 220 may be a hardware component that enables user input. The display device 215 and the I / O device 220 may be separate components or may be integrated together (such as a touch screen). The transceiver 225 may be a hardware component configured to establish a connection with the 5G NR-RAN 120, LTE-RAN (not shown in the figure), traditional RAN (not shown in the figure), WLAN (not shown in the figure), etc. Therefore, the transceiver 225 can operate on multiple different frequencies or channels (e.g., a set of continuous frequencies).

[0036] Figure 3 An architecture 300 for enabling edge applications according to various exemplary embodiments is shown. Figure 1 The architecture 300 is described with reference to the network arrangement 100 of FIG.

[0037] The architecture 300 provides a general example of the types of components that may interact with each other to facilitate exchanging application data traffic with the edge data network 170. The architecture 300 includes a UE 110, a core network 130, and an edge data network 170. The UE 110 may establish a connection to the edge data network 170 via the core network 130 and various other components (e.g., cell 120A, 5G NR RAN 120, network functions, etc.).

[0038] In architecture 300, various components are shown as connected via reference points labeled EDGE-X (e.g., EDGE-1, EDGE-2, EDGE-3, EDGE-4, EDGE-5, EDGE-6, EDGE-7, EDGE-8, etc.). Those skilled in the art will appreciate that each of these reference points (e.g., connections, interfaces) is defined in 3GPP specifications. Example architecture arrangement 300 utilizes these reference points in the manner defined in the 3GPP specifications. Furthermore, while these interfaces are referred to as reference points throughout this specification, it should be understood that these interfaces need not be direct wired or wireless connections; that is, they may communicate via intervening hardware and / or software components. To provide an example, UE 110 exchanges communications with gNB 120A. However, in architecture 300, UE 110 is shown as having a connection to ECS 180. However, this connection is not a direct communication link between UE 110 and ECS 180. Instead, it is a connection facilitated by intervening hardware and software components. Therefore, throughout the specification, the terms “connection,” “reference point,” and “interface” may be used interchangeably to describe the interfaces between various components in the architecture 300 and the network arrangement 100 .

[0039] During operation, application data traffic 305 may flow between an application client 310 executing on a UE 110 and an edge application server (EAS) 172 of an edge data network 170. The EAS 172 may be accessed through the core network 130 via an uplink classifier (CL) and a branching point (NP), or in any other suitable manner. Those skilled in the art will understand the various different types of operations and configurations associated with the application client and the EAS. The operations performed by these components are beyond the scope of the exemplary embodiments. Instead, these components are included in the description of the architecture 300 to show an example of how the flow of application data traffic 305 between the UE 110 and the edge data network 170 may be achieved after user consent is provided.

[0040] UE 110 may also include an edge enabler client (EEC) 315, which may be configured to provide support functionality to application client 310. For example, EEC 315 may perform concept-related operations such as, but not limited to, discovery of EASs (e.g., EAS 172) available in the edge data network, and retrieval and provisioning of configuration information that may enable the exchange of application data traffic 305 between application client 310 and EAS 172. To distinguish EEC 315 from other EECs, EEC 315 may be associated with a globally unique value (e.g., an EEC ID) that identifies EEC 315. Furthermore, reference to a single application client 310 and EEC 315 is provided for illustrative purposes only, and UE 110 may be configured with any suitable number of application clients and EECs.

[0041] The edge data network 170 may also include an edge enabler server (EES) 174. The EES 174 may be configured to provide support functions to the EAS 172 and the EEC 315 running on the UE 110. For example, the EES 174 may perform operations related to the concept, such as, but not limited to, configuring configurations to enable the exchange of application data traffic 305 between the UE 110 and the EAS 172, and providing information related to the EAS 172 to the EEC 315 running on the UE 110. Those skilled in the art will understand the various different types of operations and configurations associated with the EES. In addition, reference to an edge data network 170 including a single EAS 172 and a single EES 174 is provided for illustrative purposes only. In actual deployment scenarios, the edge data network may include any appropriate EAS and EES that interact with any number of UEs.

[0042] The ECS 180 may be configured to provide support functions for connecting the EEC 315 to the EES 174. For example, the ECS 180 may perform operations related to the concept, such as, but not limited to, provisioning edge configuration information to the EEC 315. The edge configuration information may include information for connecting the EEC 315 to the EES 174 (e.g., service area information, etc.) and information for establishing a connection with the EES 174 (e.g., a uniform resource identifier (URI)). Those skilled in the art will appreciate the various different types of operations and configurations associated with the ECS.

[0043] In network architectures 100 and 300, ECS 180 is shown as being outside edge data network 170 and core network 130. However, this is provided for illustrative purposes only. ECS 180 may be deployed in any suitable virtual and / or physical location (e.g., within a mobile network operator's domain or within a third-party domain) and implemented via any suitable combination of hardware, software, and / or firmware.

[0044] Figure 4 A method 400 for establishing a connection between a UE 110 and an edge data network 170 using UE location information is shown according to various exemplary embodiments. Figure 1 The network arrangement 100 and Figure 2 The method 400 is described with reference to the UE 110.

[0045] At 405, the network receives an indication of user consent for UE location data from UE 110. This indication may be received in any suitable message. As described above, user consent may indicate that the network is authorized to access UE location information. A specific example of how the network receives an indication of user consent will be provided in more detail below, following the description of method 400. Method 400 provides a general overview of how a 5G NR network may use UE location information to facilitate connectivity between UE 110 and edge data network 170. Thus, the operations described in method 400 may be performed before application data traffic 305 flows.

[0046] In 410, the network receives UE location information from UE 110. In some embodiments, SMF 133 or any other network function can be configured to ensure that user consent is obtained before the UE location information is accessed by the network. As will be described below, the UE location information can be used to establish a connection between UE 110 and edge data network 170.

[0047] In this example, a Domain Name System (DNS) application function (AF) operating on core network 130 may perform various operations related to establishing a connection between UE 110 and edge data network 170. These operations may include, but are not limited to, receiving a UE DNS request for a fully qualified domain name (FQDN) associated with EAS 172, authorizing UE 110 and services, receiving UE location information (e.g., 410), and determining at least one appropriate local PDU session anchor (PSA) point for the UE location and application.

[0048] There are several ways in which the AF may obtain UE location information. In one example, the AF may request the UE location from PCF 132, PCF 132 may forward the request to SMF 133, and then SMF 133 may subscribe to the Namf_EventExposure service. In another example, the AF may request the UE location information from PCF 132, PCF 132 may forward the request to SMF 133, and then AMF 131 may send the UE location information to SMF 133 in a Nsmf_PDUSession_updateSMContext message. In yet another example, the AF may subscribe to the UE location information from the core network 130. However, any reference to a network receiving UE location information in any particular manner is provided for illustrative purposes only. The exemplary techniques described herein for providing user consent to the network may be performed before collection of UE location information is performed in any particular manner.

[0049] In 415, a PDU session is established between UE 110 and EAS 172. Continuing with the example provided above, using the UE location information and the FQDN, the DNS AF can obtain a preferred location for N6 access to the edge data network 170 for the corresponding application (e.g., application client 310) and the corresponding subnet (or full Internet Protocol (IP) address) after NAT using the EC translation table based on the SLA. Thus, the components shown in the DNS AF and enabling architecture 300 can work together to establish a PDU session between UE 110 and EAS 172.

[0050] In a first aspect, exemplary embodiments relate to using initial registration to provide an indication of user consent to the network. In other words, exemplary embodiments utilize protected messages used during the initial registration process to provide security for the indication of user consent. As will be described below, the signaling that occurs during the registration process may depend on whether UE 110 and AMF 131 have the appropriate security context.

[0051] Figure 5a A signaling diagram 500 is shown for UE 110 to provide an indication of user consent to the network during an initial registration procedure, according to various exemplary embodiments.

[0052] As noted above, UE 110 may send an indication of user consent to authorize the AF to obtain UE location information during the initial registration process. Those skilled in the art will appreciate that the initial registration process may occur between UE 110 and AMF 131. Thus, signaling diagram 500 includes UE 110 and AMF 131.

[0053] In 505, UE 110 is camped on a cell and is in idle state. In 510, UE 110 is triggered to exit idle state.

[0054] In 515, UE 110 determines that a security context exists between UE 110 and AMF 131. According to the initial registration procedure, when UE 110 has a NAS security context, UE 110 sends a message having a complete initial NAS message encrypted in a NAS container and a plaintext information element (IE), and the entire message integrity is protected. Those skilled in the art will understand that the initial NAS message refers to the first NAS message (e.g., service request, mobility registration, etc.) sent after UE 110 transitions from an idle state.

[0055] At 520, UE 110 may transmit an initial NAS message to AMF 131. In this example, UE 110 includes an indication of user consent encrypted in a NAS container. Thus, UE 110 utilizes the initial registration procedure to provide an indication of user context to AMF 131. At 525, AMF 131 may transmit a response to the initial NAS message, indicating that AMF 131 has received the initial NAS message.

[0056] Figure 5b A signaling diagram 550 is shown for UE 110 to provide an indication of user consent to the network during an initial registration procedure according to various exemplary embodiments. Similar to signaling diagram 500, signaling diagram 550 includes UE 110 and AMF 131.

[0057] In 555, UE 110 is camped on the cell and is in idle state. In 560, UE 110 is triggered to exit idle state.

[0058] In 565, UE 110 determines that no security context exists between UE 110 and AMF 131. In 570, according to the initial registration procedure, UE 110 may send an initial NAS message including a plurality of plaintext IEs to AMF 131. These plaintext IEs may be used to establish a security context between UE 110 and AMF 131. However, since the plaintext IEs are not protected, an indication of user consent is not included in the plaintext IEs.

[0059] In 575, UE 110 and AMF 131 may perform an authentication procedure to establish a security context. In 580, AMF 131 may transmit a NAS security command to UE 110. In 585, UE 110 may transmit a NAS message to AMF 131 in response to the NAS security command. In this example, the NAS message includes an indication of user consent encrypted in a NAS container. Thus, UE 110 utilizes the initial registration procedure to provide AMF 131 with an indication of the user context. In 590, AMF 131 may transmit a response to the initial NAS message, indicating that AMF 131 has received the initial NAS message.

[0060] The exemplary embodiments are not limited to the Figure 5a to Figure 5b Those skilled in the art will appreciate that the exemplary concepts described herein are applicable to both the current implementation of the initial registration process and future implementations of the initial registration process.

[0061] In a second aspect, exemplary embodiments relate to using a UE configuration update procedure to provide an indication of user consent to a network. For example, exemplary embodiments utilize protected messages used in the UE configuration update procedure to provide security for the indication of user consent.

[0062] Figure 6 A signaling diagram 600 is shown for UE 110 to provide an indication of user consent to the network during a UE configuration update procedure, according to various exemplary embodiments.

[0063] Those skilled in the art will appreciate that the UE configuration update procedure may include a signaling exchange between UE 110 and AMF 131.

[0064] In 605, AMF 131 transmits a user consent query to UE 110. In this example, AMF 131 may include the user consent query for allowing AF to obtain UE location information in the UE Configuration Update Command. In other embodiments, instead of the UE Configuration Update Command, the user consent query may be included in any appropriate message for delivering UE policies.

[0065] In 610, UE 110 transmits an indication of user consent to AMF 131. In some embodiments, UE 110 may include the indication of user consent in a UE Configuration Update Complete message. In other embodiments, instead of a UE Configuration Update Complete message, the user consent may be included in any suitable message for providing the results of the delivery of the UE policy. Thus, UE 110 utilizes the UE Configuration Update procedure to provide an indication of the user context to AMF 131.

[0066] The exemplary embodiments are not limited to the Figure 6 Those skilled in the art will appreciate that the exemplary concepts described herein are applicable to current implementations of the UE configuration update procedure and future implementations of the UE configuration update procedure.

[0067] In a third aspect, exemplary embodiments relate to using PDU session establishment to provide an indication of user consent to a network. For example, exemplary embodiments utilize protected messages used in PDU session establishment to provide security for the indication of user consent.

[0068] Figure 7 A signaling diagram 700 is shown for UE 110 to provide an indication of user consent to the network during PDU session establishment, according to various exemplary embodiments.

[0069] During PDU session establishment, SMF 133 provides edge configuration server information (e.g., one or more FQDNs and / or IP addresses of edge configuration servers) to UE 110. UE 110 may provide an indication of requesting edge configuration server information in the PDU session establishment request. An exemplary embodiment relates to providing an indication of user consent to the network before the PDU session establishment is completed.

[0070] Signaling diagram 700 includes UE 110, RAN 120, AMF 131, SMF 133 and edge data network 172. Those skilled in the art will appreciate that the actual PDU session establishment process may include other network components and signaling not shown in signaling diagram 700. Therefore, the exemplary embodiments are not limited to the above referenced embodiments. Figure 7 Those skilled in the art will appreciate that the exemplary concepts described herein are applicable to PDU session establishment and future implementations of PDU session establishment.

[0071] In 705, UE 110 transmits a PDU Session Establishment Request to AMF 131. In some embodiments, UE 110 may include an indication of user consent in the PDU Session Establishment Request. Thus, UE 110 may provide an indication of user consent even without receiving a query from AMF 131.

[0072] In 710, SMF 133 transmits a user consent query to AMF 131. For example, SMF 133 may transmit a Namf_Communication_N1N2Message to AMF 131.

[0073] In 715, the AMF 131 may forward the user consent query to the RAN 120. For example, the AMF 131 may transmit an N2 PDU Session Request including the user consent query to the RAN.

[0074] At 720, RAN 120 transmits a user consent query to UE 110. For example, RAN 120 may incorporate the user consent query into a radio resource control (RRC) connection reconfiguration message. At 725, UE 110 transmits a user consent response (yes or no) to RAN 120. In this example, the user consent response indicates that the network is authorized to access the UE location data.

[0075] In 730, the RAN 120 transmits an indication of user consent to the AMF 131. For example, the RAN 120 may transmit an N2 PDU Session Response including the user consent to the AMF 131.

[0076] In 735, AMF 131 may forward the indication of user consent to SMF 133 using any appropriate message. At this point, in some embodiments, only SMF 133 may send user sensitive information to AF after it receives the indication of user consent. In 740, a PDU session is established between UE 110 and edge data network 172. As described above with reference to Figures 3 and 4 As described above, various components on the network side and the UE 110 side may work together to establish a PDU session between the UE 110 and the edge data network 172 .

[0077] Those skilled in the art will appreciate that the exemplary embodiments described above may be implemented with any suitable software configuration or hardware configuration or combination thereof. Exemplary hardware platforms for implementing the exemplary embodiments may include, for example, Intel x86-based platforms with compatible operating systems, Windows OS, Mac platforms and MAC OS, mobile devices with operating systems such as iOS, Android, etc. The exemplary embodiments of the above methods may be embodied as a program comprising lines of code stored on a non-transitory computer-readable storage medium, which, when compiled, may be executed on a processor or microprocessor.

[0078] Although this patent application describes various combinations of various embodiments, each with different features, those skilled in the art will understand that any feature of one embodiment may be combined with features of other embodiments in any manner not publicly denied, or with features that are not functionally or logically inconsistent with the operation or described function of the device of the embodiments disclosed herein.

[0079] It is understood that the use of personally identifiable information should be subject to privacy policies and practices that are generally recognized to meet or exceed industry or government requirements for maintaining user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of unintentional or unauthorized access or use, and the nature of authorized use should be clearly stated to users.

[0080] It will be apparent to those skilled in the art that various modifications may be made to the present disclosure without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure is intended to cover modifications and variations of the present disclosure provided that these modifications and variations are within the scope of the appended claims and their equivalents.

Claims

1. A baseband processor, the baseband processor being configured to perform operations comprising: During the initial registration procedure of a user equipment UE: Determining that there is no security context between the UE and the mobility management function AMF; In response to determining that there is no security context between the UE and the AMF, sending an initial non-access stratum (NAS) message to the AMF, the initial NAS message including a plaintext information element (IE) for establishing a security context between the UE and the AMF, wherein the plaintext IE does not include an indication of user consent for UE location information; performing an authentication procedure to establish a security context between the UE and the AMF; and In response to the NAS security command, sending a second NAS message to the AMF, The second NAS message includes an indication of user consent for UE location information, The user consents to a network function corresponding to obtaining UE location information; Transmitting the UE location information to the first network; as well as Establishing a connection with a second network, wherein the network function performs operations related to establishing the connection using the UE location information.

2. The baseband processor according to claim 1, wherein the first network is a 5G New Radio (NR) network, and the second network is an edge data network.

3. The baseband processor of claim 1 , wherein the indication of user consent is included in the second NAS message encrypted in a NAS container.

4. The baseband processor of claim 1, wherein the indication of the user's consent is not included in a plain text information element (IE).

5. The baseband processor according to any one of claims 1 to 4, wherein the operations further comprise: receiving a response to the initial NAS message from the AMF.

6. The baseband processor according to any one of claims 1 to 4, wherein the operations further comprise: In response to determining that a security context exists between the UE and the AMF, sending an initial NAS message including the indication of the user consent to the AMF.

7. The baseband processor according to any one of claims 1 to 4, wherein the initial NAS message comprises a first NAS message sent by the UE after the UE transitions from an idle state.

8. A user equipment (UE), comprising: a transceiver configured to communicate with a plurality of networks; as well as a processor communicatively coupled to the transceiver and configured to perform operations including: During the initial registration procedure of the UE: Determining that there is no security context between the UE and the mobility management function AMF; In response to determining that there is no security context between the UE and the AMF, sending an initial non-access stratum (NAS) message to the AMF, the initial NAS message including a plaintext information element (IE) for establishing a security context between the UE and the AMF, wherein the plaintext IE does not include an indication of user consent for UE location information; performing an authentication procedure to establish a security context between the UE and the AMF; and sending, in response to the NAS security command, a second NAS message to the AMF, the second NAS message including an indication of user consent for UE location information, the user consent corresponding to a network capability for obtaining UE location information; Transmitting the UE location information to the first network; as well as Establishing a connection with a second network, wherein the network function performs operations related to establishing the connection using the UE location information.

9. The UE according to claim 8, wherein the first network is a 5G New Radio (NR) network, and the second network is an edge data network.

10. The UE of claim 8, wherein the indication of user consent is included in the second NAS message encrypted in a NAS container.

11. The UE of claim 8, wherein the indication of the user consent is not included in a plain text information element (IE).

12. The UE according to any one of claims 8 to 11, wherein the operations further comprise: receiving a response to the initial NAS message from the AMF.

13. The UE according to any one of claims 8 to 11, wherein the operations further comprise: In response to determining that a security context exists between the UE and the AMF, sending an initial NAS message including the indication of the user consent to the AMF.

14. The UE according to any one of claims 8 to 11, wherein the initial NAS message comprises a first NAS message sent by the UE after transitioning from an idle state.

15. A method for wireless communication, comprising: At the user equipment UE: During the initial registration procedure of the UE: Determining that there is no security context between the UE and the mobility management function AMF; In response to determining that there is no security context between the UE and the AMF, sending an initial non-access stratum (NAS) message to the AMF, the initial NAS message including a plaintext information element (IE) for establishing a security context between the UE and the AMF, wherein the plaintext IE does not include an indication of user consent for UE location information; performing an authentication procedure to establish a security context between the UE and the AMF; and sending, in response to the NAS security command, a second NAS message to the AMF, the second NAS message including an indication of user consent for UE location information, the user consent corresponding to a network capability for obtaining UE location information; Transmitting the UE location information to the first network; as well as Establishing a connection with a second network, wherein the network function performs operations related to establishing the connection using the UE location information.

16. The method of claim 15, wherein the first network is a 5G New Radio (NR) network, and the second network is an edge data network.

17. The method of claim 15, wherein the indication of user consent is included in the second NAS message encrypted in a NAS container.

18. The method of claim 15, wherein the indication of the user's consent is not included in a plain text information element (IE).

19. The method according to any one of claims 15 to 18, further comprising: receiving a response to the initial NAS message from the AMF.

20. The method according to any one of claims 15 to 18, further comprising: In response to determining that a security context exists between the UE and the AMF, sending an initial NAS message including the indication of the user consent to the AMF.

21. The method according to any one of claims 15 to 18, wherein the initial NAS message comprises a first NAS message sent by the UE after transitioning from an idle state.

Citation Information

Patent Citations

  • Network data analytics function, access and mobility function, and control method for UE analytics assistance for network automation and optimisation

    WO2020066890A1