Method and apparatus for key control message transfer across networks

By transmitting a private network information container with integrity and/or cryptographic protection between the UE and the home network, the security problem of information transmission in a private network without 3GPP credentials is solved, and secure communication is achieved when the UE is located outside the coverage area of ​​the home network.

CN116349266BActive Publication Date: 2025-11-07HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180065023.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-09-29
Filing Date
2021-09-28
Publication Date
2025-11-07
Estimated Expiration
2041-09-28

AI Technical Summary

Technical Problem

Existing technologies cannot effectively protect critical information transmitted between a UE and its home network outside the coverage area of ​​the home network, especially in private networks that do not use 3GPP credentials and protection mechanisms, where there is a risk of information being tampered with and the visited network blocking communication.

Method used

By generating and transmitting a private network information container containing integrity and/or cryptographic protection, and using 3GPP or non-3GPP credentials for verification and protection, secure transmission of information between the UE and the home network is ensured.

Benefits of technology

It improves the security of communication between a UE and its home network when the UE is outside the coverage area of ​​the home network. It is applicable to both public and private networks and prevents information tampering and network access blocking communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116349266B_ABST
    Figure CN116349266B_ABST
Patent Text Reader

Abstract

A network device in a network (514) can generate a network information container (532) including information to be sent to a communication device (512). The network (514) is a home network of the communication device (512) served by a visited network (516). The network information container (532) can be integrity protected and / or cipher protected. The network device can send a message to the communication device (512) through the visited network (516), the message including the network information container (532) and a credential indicator indicating a type of credential used to protect the network information container (532). The type of credential can be a 3GPP credential or a non-3GPP credential. Based on the type of credential, the communication device (512) can verify the network information container (532) by one or more security parameters and obtain the information in the network information container (532) upon successful verification or discard the network information container (532) upon failed verification.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to U.S. Provisional Application No. 63 / 084,793, filed September 29, 2020, entitled “Method and Apparatus for Critical Control Message Transfer in Private Networks,” the entire contents of which are incorporated herein by reference as if reproduced in its entirety. TECHNICAL FIELD

[0002] The present disclosure generally relates to wireless communications, and in particular embodiments, to techniques and mechanisms for critical control message transfer across networks. BACKGROUND

[0003] When a UE is out of coverage of a home network of the UE, the UE can communicate through a visited network. The visited network can have a business relationship (e.g., a roaming agreement) with the home network and can provide local connectivity for the UE. The visited network can be a public network or a private network. The home network can be a public network or a private network.

[0004] When the UE is out of coverage of the home network, the home network can direct the UE to select a visited network. For example, the home network can provide a preconfigured list of preferred networks for the UE, such as a list of preferred roaming public networks or a list of preferred private networks. The UE can first select a visited network preferred by the home network (e.g., select a visited network with higher reputation or cheaper roaming fee) from the list of preferred networks before the UE registers or connects to the selected visited network.

[0005] As another example, the home network can provide steering instructions to direct the UE to a more preferred network when the UE is registering or has connected to a visited network.

[0006] In either example, when critical information needs to be transferred between the home network and the UE out of coverage of the home network, the transfer of the critical information needs to be protected. In addition, because the visited network can be a network that the home network of the UE requests the UE to avoid, the critical information also needs to be hidden from the visited network and the visited network needs to be prevented from blocking the communication between the UE and its home network. SUMMARY

[0007] Embodiments of the present disclosure describe methods and apparatus for critical control message transfer across networks, which generally achieve technical advantages.

[0008] According to an aspect of the present disclosure, a method is provided, which comprises: receiving, by a communication device, a message from a first home network of the communication device through a first visited network of the communication device, the message comprising a first network information container and a credential indicator, the first network information container comprising information that is integrity protected and / or cipher protected, the credential indicator indicating a type of credential used to protect the first network information container; verifying, by the communication device, the first network information container based on the type of credential through one or more security parameters; and obtaining, by the communication device, the information comprised in the first network information container when the first network information container is verified successfully.

[0009] Optionally, in any of the above aspects, the message further comprises information indicating a type of protection mechanism used to protect the first network information container.

[0010] Optionally, in any of the above aspects, the type of protection mechanism comprises integrity protection only, cipher protection only, or integrity and cipher protection.

[0011] Optionally, in any of the above aspects, verifying the first network information container comprises: verifying, by the communication device, integrity of the first network information container through the one or more security parameters; and / or decrypting, by the communication device, the first network information container through the one or more security parameters.

[0012] Optionally, in any of the above aspects, the one or more security parameters comprise one or more of: a security parameter used to verify the first network information container or an access network, the security parameter comprising a certificate, a public key, or a private key; a key identifier; a synchronization or a freshness quantity; a random number; or a network security preference.

[0013] Optionally, in any of the above aspects, the method further comprises: executing, by the communication device, an instruction comprised in the first network information container when the first network information container is verified successfully.

[0014] Optionally, in any of the above aspects, the instruction: instructs the communication device to connect to a second visited network; or instructs the communication device to perform network selection based on a candidate network list provided by the first home network to select a new visited network.

[0015] Optionally, in any of the above aspects, the method further comprises: accessing, by the communication device, the second visited network or the new visited network using the type of credential indicated by the credential indicator and / or information in the first network information container.

[0016] Optionally, in any of the preceding aspects, the second visited network is a preferred network configured by the first home network for the communication device.

[0017] Optionally, in any of the preceding aspects, the method further includes sending, by the communication device, a second network information container to the first home network through the first visited network, the second network information container including information that is integrity protected and / or cipher protected.

[0018] Optionally, in any of the preceding aspects, the method further includes discarding, by the communication device, the first network information container when the first network information container is not successfully verified.

[0019] Optionally, in any of the preceding aspects, the type of the credential includes a 3GPP credential or a non-3GPP credential.

[0020] Optionally, in any of the preceding aspects, the first network information container includes at least one of: network steering instructions, network steering policies, a list of preferred visited networks for the communication device, quality of service (QoS) requirements for a service or a visited network, configuration and / or capability information for the communication device, or security parameters.

[0021] Optionally, in any of the preceding aspects, the message further includes the one or more security parameters.

[0022] Optionally, in any of the preceding aspects, the message further includes operator information of the first home network.

[0023] Optionally, in any of the preceding aspects, the message is a non-access stratum (NAS) message.

[0024] Optionally, in any of the preceding aspects, the communication device has or does not have a universal integrated circuit card (UICC).

[0025] Optionally, in any of the preceding aspects, the method further includes receiving, by the communication device, a third network information container corresponding to a second home network of the communication device and the first network information container corresponding to the first home network of the communication device.

[0026] Optionally, in any of the preceding aspects, one of the first home network and the second home network is a private network.

[0027] Optionally, in any of the preceding aspects, the first network information container includes information for accessing a public network and information for accessing a private network.

[0028] Optionally, in any of the preceding aspects, the first home network is a public network or a private network.

[0029] Optionally, in any of the preceding aspects, the first visited network is a public network or a private network.

[0030] Optionally, in any of the preceding aspects, the message further comprises information of usage restriction according to which the first network information container is used.

[0031] Optionally, in any of the preceding aspects, the method further comprises that the communication device, before receiving the message, performs authentication and authorization with the first home network through the first visited network.

[0032] According to another aspect of the present disclosure, a method is provided, comprising: determining, by a network device of a first network, to send first information to a communication device, the first network being a home network of the communication device, the communication device being served by a first visited network; generating, by the network device, a network information container comprising the first information, the network information container being integrity protected and / or cipher protected; determining, by the network device, a type of credential used to protect the network information container; and sending, by the network device, a message to the communication device through the first visited network, the message comprising the network information container and a credential indicator indicating the type of credential.

[0033] Optionally, in any of the preceding aspects, the network information container comprises at least one of: network steering instructions, network steering policies, a list of preferred visited networks of the communication device, quality of service (QoS) requirements of a service or a visited network, configuration and / or capability information of the communication device, or security parameters.

[0034] Optionally, in any of the preceding aspects, the network steering instructions: instruct the communication device to connect to a second visited network; or instruct the communication device to perform network selection based on a candidate network list provided by the home network to select a new visited network.

[0035] Optionally, in any of the preceding aspects, the message further comprises one or more security parameters used to verify the network information container.

[0036] Optionally, in any of the preceding aspects, the one or more security parameters include one or more of: security parameters for verifying the network information container or an access network, the security parameters including a certificate, a public key, or a private key; a key identifier; a synchronization or freshness; a random number; or a network security preference.

[0037] Optionally, in any of the preceding aspects, the message further includes operator information of the home network.

[0038] Optionally, in any of the preceding aspects, the message is a non-access stratum (NAS) message.

[0039] Optionally, in any of the preceding aspects, the communication device has or does not have a universal integrated circuit card (UICC).

[0040] Optionally, in any of the preceding aspects, the network information container includes information for accessing a public network and information for accessing a private network.

[0041] Optionally, in any of the preceding aspects, the home network is a public network or a private network.

[0042] Optionally, in any of the preceding aspects, the first visited network is a public network or a private network.

[0043] Optionally, in any of the preceding aspects, the message further includes usage restriction information according to which the network information container is used.

[0044] Optionally, in any of the preceding aspects, the method further includes receiving, by the network device from the communication device over the first visited network, an information container including information that is integrity protected and / or cipher protected.

[0045] Optionally, in any of the preceding aspects, the message further includes information indicating a type of protection mechanism used to protect the network information container.

[0046] Optionally, in any of the preceding aspects, the type of protection mechanism includes integrity protection only, cipher protection only, or integrity and cipher protection.

[0047] Optionally, in any of the preceding aspects, the type of credential includes a 3GPP credential or a non-3GPP credential.

[0048] According to another aspect of the present disclosure, there is provided an apparatus comprising: a non-transitory memory storage comprising instructions; one or more processors in communication with the memory storage, wherein the instructions, when executed by the one or more processors, cause the apparatus to perform any of the above aspects.

[0049] According to another aspect of the present disclosure, there is provided a non-transitory computer-readable medium storing computer instructions that, when executed by one or more processors of an apparatus of a first network, cause the apparatus to perform any of the above aspects.

[0050] According to another aspect of the present disclosure, there is provided a system comprising a network device of a first network and a communication device, the first network being a home network of the communication device, the communication device being served by a visited network. The network device is configured to perform: determining to send first information to the communication device; generating a network information container comprising the first information, the network information container being integrity protected and / or cipher protected; determining a type of credential used to protect the network information container; sending, to the communication device via the visited network, a message comprising the network information container and a credential indicator indicating the type of credential. The communication device is configured to perform: receiving, from the network device of the home network of the communication device via the visited network, a message; verifying the network information container via one or more security parameters based on the type of credential; obtaining the first information comprised in the network information container when the network information container is verified successfully.

[0051] The above aspects of the present disclosure improve the security of the communication of information between a UE and its home network when the UE is outside the coverage of the home network, so that the UE knows which type of credential to use to protect the communicated information. Based on this, the UE is able to verify the communicated information. BRIEF DESCRIPTION OF DRAWINGS

[0052] For a more complete understanding of the present disclosure and its advantages, reference is now made to the following description taken in conjunction with the accompanying drawings in which:

[0053] Figure 1 A schematic diagram illustrating an exemplary scenario where a UE is outside its home network is shown;

[0054] FIG. 2 shows a schematic diagram of a communication network highlighting the transmission of a SoR container and 3GPP credentials according to prior art;

[0055] Figure 3 Table 8.2.8.1.1 in 3GPP TS 24.501 is shown;

[0056] Figure 4A diagram showing an embodiment NAS message highlighting communication of a private network information container;

[0057] Figure 5 A diagram for an embodiment operation between a UE, two home networks of the UE, and a visited network of the UE;

[0058] Figure 6 A diagram for an embodiment operation between a UE, two home networks of the UE, and a visited network of the UE;

[0059] Figure 7 A diagram for an embodiment method of private network information container key and policy provisioning;

[0060] Figure 8 A flow diagram for an embodiment method of wireless communication;

[0061] Figure 9 A flow diagram for another embodiment method of wireless communication;

[0062] Figure 10 A flow diagram for another embodiment method of wireless communication;

[0063] Figure 11 A diagram for an embodiment communication system;

[0064] Figure 12A An example end device (ED) is shown;

[0065] Figure 12B An example base station is shown; and

[0066] Figure 13 A block diagram of an embodiment computing system that can be used for implementing the devices and methods disclosed herein.

[0067] Corresponding numerals and symbols in different figures generally refer to corresponding parts unless context dictates otherwise. The drawings are drawn to illustrate aspects of the embodiments and are not necessarily to scale. DETAILED DESCRIPTION

[0068] Embodiments of the present disclosure are discussed in detail below. It should be apparent that the disclosure can be embodied in a variety of specific contexts, and that the specific embodiments discussed herein are merely illustrative and not restrictive of the scope of the claims. Furthermore, it should be understood that various changes, substitutions and alterations can be made herein without departing from the spirit and scope of the disclosure as defined by the appended claims.

[0069] For ease of description, some abbreviations used in this disclosure are listed as follows:

[0070] • N3IWF: Non-3GPP interworking Function

[0071] • SNPN: Stand-alone Non-Public-Network

[0072] • UPF: User Plane Function

[0073] • DN: Data Network

[0074] • PLMN: Public-Line-Mobile Network

[0075] • SP: Service Provider

[0076] • UDM: Unified Data Management

[0077] • NWDAF: NetWork Data Analytic Function

[0078] • UICC: Universal Integrated Circuit Card. UICC is a new generation of subscriber identification module (SIM) included in mobile phones or laptops used in some high-speed wireless 3G networks.

[0079] • SLA: Service License Agreement

[0080] NAS: Non-Access Stratum

[0081] A user equipment (UE) that is out of coverage of a home network can communicate with the home network through a visited network of the UE. Traditionally, when information is to be communicated between the home network (the home network is a public network) and the UE through the visited network, the information can be protected using third generation partnership project (3GPP) credentials and protection mechanisms and transmitted. However, this solution is not applicable to home networks that do not use or support 3GPP credentials and protection mechanisms. Examples of home networks that do not use or support 3GPP credentials can include private 3GPP networks built for private, non-public use or for specific users.

[0082] Embodiments of the present disclosure provide methods of communication between a UE and its home network when the UE is out of coverage of the home network. These embodiments support the communication of integrity protected and / or cipher protected information between the home network and the UE through a visited network and allow the UE to know whether to use 3GPP credentials and / or protection mechanisms or non-3GPP credentials and / or protection mechanisms so that the UE can select the corresponding protection mechanisms and keys to securely communicate information between the UE and the home network and access the visited network. These embodiments improve the security of communication when the UE is out of coverage of the home network and are applicable to both public networks and private networks.

[0083] In some embodiments, a network device in a network can generate a network information container including information to be sent to a communication device that is out of coverage of the network. The network is a home network of the communication device that is served by a visited network. The network information container can be integrity protected and / or cipher protected. The network device can send a message including the network information container and a credential indicator to the communication device through the visited network, the credential indicator indicating a type of credentials used to protect the network information container. The type of credentials can be 3GPP credentials or non-3GPP credentials. According to the type of credentials, the communication device can verify the network information container through one or more security parameters and obtain the information in the network information container when the verification is successful or discard the network information container when the verification fails. More details are provided below.

[0084] A UE can use a visited network for communication when the UE is out of coverage of a home network of the UE. The home network of the UE can be a network to which the UE has subscribed, e.g., a network to which a user subscribes a communication service. The visited network can have a business relationship (e.g., a roaming agreement) with the home network and provide a local connection for the UE. The visited network can be a public network or a private network. The home network can be a public network or a private network. (Note: Roaming is a specific term for public networks, where there are regulatory requirements involved. The term “roaming” is now generally not used for private networks.)

[0085] Figure 1 A diagram illustrating an example scenario 100 in which a UE is out of coverage of its home network is shown. As shown, a UE 105 is out of coverage of its home network 110 but in coverage of visited networks 120, 130. In Figure 1 In the example scenario 100, each ellipse represents coverage of a respective network. The UE can select a visited network 120 or 130 for the UE to communicate wirelessly. The home network 110 can direct the UE 105 to select a visited network when the UE is out of coverage of the home network 110.

[0086] The home network 110 generally has two ways to direct the selection of the UE 105. In one way, the home network 110 can provide a preconfigured list of preferred networks for the UE, such as a list of preferred roaming networks for public networks or a list of preferred networks for private networks. The UE 105 can select a visited network preferred by the home network 110 (e.g., select a visited network with higher reputation or cheaper roaming charges) first through the list of preferred networks, and then the UE registers or connects to the selected visited network. For example, when the UE 105 is out of coverage of the home network 110, the UE 105 can select the visited network 130 according to the list of preferred networks provided by the home network 110.

[0087] In another way, the home network 110 can provide a direction instruction to direct the UE to a more preferred network when the UE 105 is registering or has connected to a visited network. For example, when the UE 105 is out of coverage of the home network 110, the UE connects to the visited network 120. The UE 105 can receive a direction instruction from the home network 110 indicating the visited network 130 to which the UE 105 can connect to the home network can be preferred.

[0088] Using a preferred network is beneficial to both the UE and the home network of the UE (e.g., lower roaming charges). Solutions have been proposed to enable a UE service provider to which a UE has subscribed to direct the UE to a more preferred network when the UE has registered or connected to a less preferred network.

[0089] 3GPP introduced a mechanism for a public home network using 3GPP defined credentials and security mechanisms to steer its UEs to preferred public visited networks, called “steering of roaming” (SoR), where the public home network uses the control plane of the public visited network to send steering instructions to the UE in a SoR container. The SoR mechanism can not be suitable for private home networks when the private home network does not use 3GPP credentials and security mechanisms. A private network can be a network built for private users or non-public users or for specific users. For example, a corporate network is a private network that only corporate users can access, not the general public. A private network built using 5G specifications can use the same protocols, same procedures, and same message mechanisms defined in 3GPP specifications, but such private networks can use non-3GPP credentials (e.g., certificates, public / private keys, etc.) for authentication. 3GPP is studying solutions to allow service providers of private home networks to steer their UEs to another visited network when the UE registers or connects to a visited network. In 3GPP SA2 (Architecture Working Group) and 3GPP SA3 (Security Working Group), a new 3GPP R17 study item on network enhancements for private networks (FS_NPN). U.S. Provisional Application No. 63 / 021460, entitled “Method and Apparatus for Network Initiated Continuity of SNPN Deployments,” filed May 7, 2020, introduces a private network steering mechanism where the private network sends special steering instructions to the UE, which is incorporated herein by reference in its entirety.

[0090] A home network of a UE can provide the UE with a list of preferred networks and one or more steering instructions in order to guide / steer the UE to a visited network that the home network prefers more. These two pieces of information, the list of preferred networks and the one or more steering instructions, can be used by the UE at different connection stages. For example, the list of preferred networks can be used for the network selection stage of the UE, and the one or more steering instructions can be used when the UE is in a connected state. Thus, there are different security issues for the delivery of information, as described below.

[0091] In any case, for example, when the network cannot predict the location where the UE will access, the network can not be able to provide the UE with a list of preferred networks.

[0092] When a UE is outside the coverage of the home network, the UE needs to connect to a visited network. The basic assumption is that the visited network performs well (e.g., carries signaling traffic all the way to the UE's home network without modifying its content; does not intentionally drop signaling traffic even if the purpose of the signaling is to redirect the UE to another network, etc.) even if the visited network is not the home network operator's preferred network due to high roaming charges, etc. Under this assumption, the home network should not worry that the visited network to which the UE is currently connected will modify the information sent from the home network to the UE, such as the list of preferred networks, before forwarding the list of preferred networks to the UE. However, a more cautious action that the home network can take when the list of preferred networks is sent to the UE through the visited network to which the UE is currently connected can be to provide security protection for the list of preferred networks. This will help protect the delivery of the list of preferred networks, especially when the UE is accessing a visited network that is not in the list of preferred networks or the visited network is not performing well.

[0093] As mentioned above, the home network can not be able to provide the UE with an appropriate list of preferred networks in all cases when the UE accesses the home network. Therefore, there is a need to provide such a list of network preferences in real time when the UE accesses a visited network, for example, for the first time. The home network can need to send the list to the UE through the visited network.

[0094] If the UE is already connected to a visited network and the list of preferred networks from the home network does not trigger the UE to leave the currently connected visited network to another network, the home network does not need to worry that the currently connected visited network will modify the list of preferred networks before forwarding the list of preferred networks to the UE.

[0095] Steering information (steering instructions) is used to steer the UE from the currently connected visited network to a new visited network. Steering information is one example of a control message. However, even if the currently connected visited network is performing well, there can still be a risk that the currently connected visited network will modify the steering instructions to keep the UE in its network. Therefore, steering instructions from the home network and any other information that the home network attempts to send to the UE need to have security protection (e.g., integrity protection and / or ciphering protection) to avoid the control message and other information being modified.

[0096] In view of the above various situations and concerns, there is a need for key control information, such as steering information determined by a UE’s home network or a preferred list of the visiting network, to be sent from the UE’s home network and forwarded to the UE by the visiting network (e.g., a private network) to be protected end-to-end (E2E). Similarly, there is also a need for key control information sent by the UE to the home network through the visiting network to be E2E protected. There is no guarantee that the visiting network (e.g., a network with poor performance or other users can have previously provided negative reviews or ratings) will deliver the control information without possible misuse or manipulation.

[0097] Current 3GPP standards define a dedicated container (e.g., SoR container) to carry the integrity protected public network SoR instructions, such as public network SoR instructions with keys derived (also referred to as derived) from 3GPP credentials. The 3GPP credentials can include long-term keys and subscription identifiers that are used to uniquely identify a UE subscription, which can be used for mutual authentication of the UE and the 3GPP core network. The 3GPP credentials can also be used to derive other security parameters. These 3GPP credentials can be shared between the UE (e.g., stored in the UE’s UICC, such as a SIM card, if available) and the UE’s home network (e.g., stored in the UDM). Thus, the SoR container is tightly coupled with the 3GPP credentials and the UICC in the UE.

[0098] Currently, the SoR container is integrity protected. The integrity protection and related algorithms are specified in 3GPP TS 33.501, V15.4.0, R15 (2019-05), which is incorporated by reference herein. As an example, a key (e.g., K ausf ) can be generated based on a primary authentication procedure between the UE and the home network. The home network then integrity protects the SoR container using the key, such as by computing a message authentication code (first code) for the SoR container using an integrity algorithm. The message authentication code can be appended to the SoR container and sent. The UE can use the same key to verify whether the SoR container was modified during transmission. For example, the UE can compute a message authentication code (second code) based on the received SoR container and verify the integrity of the SoR container by comparing the second code with the received first code. Since the SoR container is only integrity protected, a person who can receive the SoR container can still see the SoR container. However, any modification to the SoR container is detectable. The integrity code (or message authentication code) computed when the SoR container is modified will be different from the code of the SoR container sender.

[0099] Figure 2 shows a schematic diagram 200 of a communication network highlighting the transmission of SoR containers and 3GPP credentials according to the prior art. The network 200 comprises a public home network 202 of a UE 222. The UE 222 comprises a UICC 224. The public home network 202 comprises a UDM 204 storing 3GPP credentials. The public home network 202 can transmit, through a network function (NF) 206, to the UE 222 a SoR container containing SoR instructions, and 3GPP credentials stored in the UDM 204. The UE 222 can store the received 3GPP credentials in the UICC 224. The UE can derive a key based on the saved 3GPP credentials and verify the received SoR container. Figure 3 Table 8.2.8.1.1 in 3GPP TS 24.501, V16.5.1, R16 (2020-08), “5G; Non-Access-Stratum (NAS) protocol for 5G System (5GS); Stage 3” is shown, which is incorporated herein by reference. Figure 3 The SoR transparent container in Table 8.2.8.1.1 is shown.

[0100] However, for some standalone private networks, non-3GPP credentials are used for authentication and access to the standalone private network. These private networks can use non-3GPP credentials and protection mechanisms, which are different from 3GPP credentials and protection mechanisms. For example, a private network can use a public / private key scheme to protect the transmitted information (container). The UE can protect the container using the public key of the home network, only the home network with the private key can recover or verify the container. The non-3GPP credentials can take several forms, for example, a key is derived based on the non-3GPP credentials and the key is used to protect the container integrity / privacy; directly use the private key (of the non-3GPP credentials) to protect the container integrity / privacy through the network, while the UE uses the public key of the network to confirm the container, etc. Therefore, the current SoR mechanism is not suitable for private networks that do not use or support 3GPP credentials for container authentication and subsequent protection. In addition, the UE can not have a UICC that stores 3GPP credentials or non-3GPP credentials. Therefore, the above-mentioned prior art in Figure 2 may not be suitable for use, for example. In addition, when a UE subscribes to both a public network and a private network (i.e., the UE has two home networks), the two networks can use different security or key mechanisms. Coordination between the UE and the home network is needed to select the correct mechanism and the correct key to securely communicate bootstrapping instructions and other information between the UE and the home network.

[0101] Accordingly, service providers of home networks need methods and apparatuses to provide control information, such as steering instructions, to their UEs through a visited network using non-3GPP credentials. Embodiments of the present disclosure provide a mechanism to communicate information between a UE and its home network through a visited network of the UE. These embodiments improve the security of the communication, allow hiding the information from the visited network, and avoid the visited network blocking the communication between the UE and its home network (as the visited network can be a network that the UE’s home network requests the UE to avoid). These embodiments are applicable to public networks and private networks.

[0102] In some embodiments, a new private network information container (or referred to as network information container) can be established to communicate information that needs security protection, such as mobility instructions, between a UE’s home network and the UE through a visited network of the UE (i.e., the UE is located in the coverage of the home network). The term “private network information container” used in the present disclosure is merely used to distinguish from the traditional SoR container and should not be limited to only the case involving a private network. The private network information container is a dedicated private network information container used to exchange critical information between a UE and its private home network, both of which can not implement the 3GPP defined credential and security mechanism. The private network information container can be transported in a NAS message or any other applicable message. The content of the private network information container can be protected with security parameters derived from non-3GPP credentials (e.g., certificates, public keys, or private keys, etc.) according to the protection mechanism. The security parameters can be established, determined, or derived through a one-time authentication procedure (each UE accessing a public network or a private network needs to go through a one-time authentication procedure according to the specification of 3GPP TS 33.501, V15.4.0, R15 (2019-05)) or a dedicated key creation procedure after the authentication procedure. For example, the dedicated key creation procedure can be performed when the previously used key has expired. In this case, the key can be refreshed without running another one-time authentication procedure. For example, the authentication procedure can be a one-time authentication or a two-time authentication after the one-time authentication according to 3GPP TS 33.501. Embodiment mechanisms can be established to allow the UE and the home network to exchange indications to indicate which security mechanism and container (a container that has been traditionally defined to deliver a list of preferred public networks) to use for the home network to communicate mobility instructions when the UE is capable of supporting multiple security mechanisms or has different subscriptions. These embodiments have no impact on UEs that do not support the embodiment mechanisms. In the following description, the terms “private network information container” and “container” are used interchangeably.

[0103] Figure 4An embodiment of a NAS message 400 according to embodiments of the disclosure is shown, highlighting the communication of the private network information container. The NAS message 400 can be communicated between a UE and a home network of the UE by a visited network of the UE that is located outside of a home network coverage. The NAS message 400 can be sent by the UE or by the home network. The NAS message 400 can be any existing or future NAS message used to carry a network information container. The NAS message 400, for example, can be an update or attach message, an authentication message, a service request, etc. As shown, the NAS message 400 includes a credential indication 402, security parameters 404 (including one or more parameters), a private network information container 406, and home operator information 408.

[0104] The credential indication 402 indicates the type of credential used with the private network information container 406, e.g., 3GPP credential or non-3GPP credential. For example, the credential indication 402 can indicate whether the key used to integrity protect the private network information container 406 is based on a 3GPP credential or a non-3GPP credential. The key can be acquired through an authentication procedure between the UE and its home network or derived from the home network’s credential. Thus, the credential indication 402 indicates the type of credential used to protect the container. As another example, the credential indication 402 can indicate which type of credential (e.g., 3GPP or non-3GPP) the UE will use to access (e.g., authenticate to) a visited network. The credential indication 402 can also indicate the type of protection (e.g., security mechanism) applied to the private network information container 406. For example, the type of protection can be 3GPP or non-3GPP integrity only, 3GPP or non-3GPP cipher only, or 3GPP or non-3GPP integrity and cipher. Cipher protection here is also referred to as privacy protection, where a sender encrypts information based on an encryption algorithm agreed upon by both the sender and the receiver using one or more security parameters such as a cipher key, and the receiver of the information can decrypt the cipher protected information using one or more security parameters such as a cipher key. The cipher key can be a public key or a private key. Typically, the security parameters used to cipher / encrypt information / messages can include a key and a degree of synchronization, but can also include other parameters such as a cell ID, a frequency being used by the cell, and / or a direction of transmission of the message (i.e., uplink or downlink). The type of protection can be indicated with the credential indication 402 or separately from the credential indication 402. As an example, the credential indication 402 can be a flag (or indicator) that indicates which type of credential and / or security mechanism will be used. For example, if the flag is set (or indicates) 3GPP (e.g., using one bit “0”), it means that a 3GPP credential and a security mechanism (e.g., integrity protection) are used for the private network information container 406. If the flag is set to non-3GPP (e.g., using one bit “1”), it means that a non-3GPP credential and a security mechanism (e.g., integrity and cipher protection) are used for the private network information container 406. As another example, the credential indication 402 can be one bit that indicates whether a 3GPP or non-3GPP credential is used, and the NAS message 400 includes a protection indicator, which can be two bits, to indicate the type of protection applied to the container. Those of skill in the art or ordinary skill will recognize many variations, modifications, and embodiments for indicating the type of credential and the type of protection.

[0105] The security parameters 404 can be used to verify the private network information container 406. The private network information container 406 can be integrity protected and / or cipher protected. A UE receiving the private network information container 406 can use the security parameters 404 (which can also be based on the indicated protection type) to verify (confirm or authenticate) the integrity and privacy of the private network information container 406. The security parameters 404 can include one or more of the following information:

[0106] One or more parameters, such as a certificate, a public key, and / or a private key, etc., can be used to verify the private network information container 406, or to access / connect to a visited network (e.g., to authenticate to the visited network);

[0107] A key identifier. For example, the key identifier can identify a key or a key pair (e.g., a public / private key pair) to be used, e.g., to verify the container 406 (e.g., to compute a message) or to access / connect to a visited network;

[0108] A synchronization or freshness (e.g., a monotonically increasing counter or sequence number, a counter for cipher synchronization). The synchronization or freshness helps to ensure that the protection of the container cannot be replayed in the future;

[0109] An indicator indicating which protection algorithm (which integrity protection algorithm or which cipher protection algorithm) is to be used;

[0110] A random number. The random number is similar to the synchronization or freshness, but can be randomly generated. The purpose of providing the random number is to avoid replay of the protected information; or

[0111] A network security preference (e.g., network security policy related information). For example, the security preference / policy of a network to be accessed can be included.

[0112] The credential indication 402 and the security parameters 404 can be provided by a sender of the private network information container 406, such as a UE or a home network of the UE.

[0113] The private network information container 406 in these embodiments can be used to convey information between a UE and a home network of the UE, which requires E2E integrity and / or privacy protection. The information contained in the private network information container 406 can be used by the UE to select, connect and / or access a visited network, or can be used by the home network of the UE to configure one or more visited networks, such as an optimal visited network, for the UE. The private network information container 406 can include one or more of the following information:

[0114] Network steering instructions. This can be transmitted from the home network to the UE.

[0115] Network steering policy. This can be transmitted from the home network to the UE. Examples of network steering policy can include a preference order of multiple visited networks that the UE can steer to, network geo-location restrictions, etc. The preference can be determined based on security protection requirements. For example, a first preference can be that ciphering and integrity protection are required, a second preference can be that ciphering is required, and a third preference can be that integrity protection is required. For example, if a visited network requires ciphering protection and the UE does not support it, the UE can not select the visited network.

[0116] List of preferred visited networks for the UE. This can be transmitted from the home network to the UE. The home network of the UE can determine / configure the list of preferred visited networks for the UE to select a network to steer to.

[0117] Quality of service (QoS) requirements for the UE’s service (e.g., current service) or the UE’s visited network (target visited network). This can be transmitted from the UE to the home network of the UE. The QoS can be a requirement required for the service provided to the UE or a requirement that must be met by the visited network. For example, when the UE determines that the current visited network does not meet the QoS, the UE can determine to connect to another visited network even though the current visited network can have met other network steering policies. Which visited network the UE selects and connects to can be a decision made based on one or more factors, such as: steering policy (e.g., network steering policy), security policy (e.g., security protection types required by the home network or supported by the UE), QoS requirements (e.g., of the UE and / or service), UE capability (e.g., whether the UE supports a certain type of protection, or RF capability), etc. Based on these requirements, the UE can be used to select the network that is most suitable for the home network’s preference. None of the available visited networks can meet all the requirements of the UE and the home network.

[0118] Configuration and capability information of the UE. The configuration information of the UE can include radio frequency (RF) related parameters, such as frequency bands supported by the network or the UE. The configuration information of the UE should not be visible or modified by any other entity except its home network. The capability information of the UE can include UE security capabilities, such as the ability to support protection types or protection algorithms. The UE capability can sometimes be retransmitted by the home network back to the UE to inform the UE that the UE capability information has been received by the home network and has not been modified by anyone trying to listen to the communication between the UE and the home network.

[0119] Security parameters for integrity protection and / or ciphering protection of the private network information container 406. This can include the security parameters 404, or a message authentication code (or confirmation code, calculated based on the content of the container, synchronization, and / or other information).

[0120] The private network information container 406 can be used to convey information, e.g., mobility information or non-mobility information, between a home network of the UE and the UE, where the information needs E2E integrity and / or privacy protection. Depending on the protection mechanism used, the UE can use a key sent by the home network or derived by the UE based on the credential type indicated by the credential indication 402 (e.g., a key generated in a one-time authentication procedure with the home network), and can use information carried in the security parameters 404 or other information, to verify the private network information container 406.

[0121] An advantage of using a NAS message to carry the private network information container 406 is that the UE does not incur any roaming charges before a user plane session is established. The UE is typically charged for the amount of user plane data transferred over a user plane protocol data unit (PDU) session, but does not incur any charges for control plane data or signaling.

[0122] The home operator information 408 can include information about the operator (or service provider) of the home network of the UE, e.g., an identifier of the operator. The UE determines the correspondence between the private network information container 406 and the home network of the UE based on the home operator information 408.

[0123] In one embodiment, the private network information container can include a protected portion and an unprotected portion. The protected portion can include the information described above, and the unprotected portion can include the security parameters, e.g., the security parameters 404. Thus, in this embodiment, the private network information container can also include the security parameters. When the entire container is only integrity protected, all content within the container is in plain text. An advantage of placing the security parameters within the container is that the security parameters are additionally integrity protected compared to placing the security parameters outside of the container.

[0124] The private network information container can be transferred in the control plane between the UE and the home network, and can also be transferred in the control plane between the home network and a visited network. For example, after the home network provides the private network information container to the visited network over a control plane interface between the home network and the visited network, the private network information container can be carried in a NAS message between the UE and the visited network.

[0125] In some embodiments, after the UE is authenticated and authorized by its home network, the private network information container can be protected based on non-3GPP credentials (may be integrity and / or privacy protected. That is, the home network supports non-3GPP credentials. Traditional mechanisms for public home networks assume that the UE's current visited network is trusted, and the network information container is only integrity protected by the home network. The current visited network can be able to detect or even modify the content of the container, e.g., steering instructions instructing the UE to go to another network, and the current visited network still delivers the container to the UE. The UE can determine that the content of the container is detected or modified by the current visited network, and can discard the container.

[0126] In some cases, the information in the container needs additional protection (i.e., privacy protection) so that the current visited network cannot access the container. According to embodiments of the present disclosure, the container can be integrity protected and cipher protected. Protecting the container based on non-3GPP credentials can take several forms, e.g., a key for integrity or privacy protection of the container can be derived; or the private key is used directly to protect the container integrity or privacy by the network, and the UE uses the public key of the network to confirm / verify the container, etc.

[0127] When the UE or the UE's home network sends the private network information container, the UE or the UE's home network can protect the private network information container using the credentials used during the one-time authentication of the UE with the home network. For example, the public key of the public-private key pair credential can be used directly to protect the container, or a key can be derived / generated from the credential to protect the container. A set of security parameters can be sent with the private network information container so that the recipient of the private network information container (e.g., the UE or the home network) can determine the protection scheme used to protect the private network information container, and derive the necessary information (e.g., a key derived based on the one-time authentication, such as K ausf ), if the private network information container is additionally encrypted, perform integrity detection and / or decryption of the private network information container.

[0128] In the case where the UE is connected to both the public network and the private network through the same visited network (the UE has two home networks, one is the public network and the other is the private network), the NAS message, such as the NAS message 400, can include two (2) network information containers (e.g., one for the public home network and one for the private home network). The NAS message can also include home operator information to distinguish the containers for different home networks. For example, the NAS message can include information of Operator 1 corresponding to the UE’s public home network and information of Operator 2 corresponding to the UE’s private home network. Each of the public home network and the private home network corresponds to one of the two network information containers in the NAS message. This information about the operators can be conveyed inside or outside the private network information container in the NAS message.

[0129] In the case where the UE is capable of supporting 3GPP-based credentials (which can mean that the UE is equipped with a UICC) and non-3GPP credentials, one embodiment can also include an indication, such as an indication about Figure 4 The indication 402 described, which is sent in the same control plane message with the network information container, to indicate whether the network information container is protected by a 3GPP key or a non-3GPP key. The indication can indicate the type of credentials, which can include 3GPP credentials or non-3GPP credentials. The indication can also be used in the case where there is a pre-defined container (e.g., the SoR container defined in TS 24.501) that can be configured to include information of both public and private networks. For example, the container can include a list of preferred public networks and a list of preferred private networks that the UE can access when not in the coverage of its home network. In this case, the indication can also indicate the security mechanism used to protect the container.

[0130] The private network information container and related network functions that use the private network information container can require additional security considerations. In some embodiments, an authorization policy or indication about one or more usage restrictions for the private network information container and those network functions that use the private network information container can be provided. These usage restrictions can include the location of the UE or the visited network that can use the container, allowed visited network operators and visited networks that can use the container or related functions, a valid time period for using the container, etc. For example, the authorization policy and indication can be provided to the UE during the home network authentication and authorization procedure of the UE or the policy update procedure of the UE.

[0131] These embodiments are agnostic to the access technology and can be applied to new radio (NR) and long term evolution (LTE) networks, or any other access technology under consideration in 3GPP, such as WiFi. Note: the current logic in 3GPP standards is that a private network using 3GPP defined standards will adhere to 3GPP conventions, i.e. proper use of AS and / or NAS messages.

[0132] The private network information container can be extended to a common key information container to support private and public networks. In this case, there can be no separate private and public network containers, but rather a single common container is used. For example, the existing SoR container can be used to convey information for both private and public networks. The indications discussed herein can be used for this common container to facilitate different needs from private and public networks. For example, a UE has a private home network and a public home network, each of which can generate a common network information container for sending information to the UE. In this case, the public home network does not need to separately generate a public network information container to send information, and similarly, the private home network does not need to separately generate a private network information container to send information. Thus, the public home network and the private home network can use the same common network information container (e.g., same structure, same fields, etc.) to securely communicate information.

[0133] Exemplary embodiments of the present disclosure can support different UE and network deployment scenarios as shown in Table 1 and Table 2 below. The home network of a UE can be a public network or a private network. The visited network can also be a public network or a private network. Table 1 shows the case where the UE has a UICC, and the present embodiments can be supported and applied to the scenario where the home network is a private network and the visited network is a private or public network. Table 2 shows the case where the UE does not have a UICC, and the present embodiments can be supported and applied to the scenario where the home network is a public network or a private network and the visited network is a private network or a public network.

[0134] Table 1

[0135] Public visited network Private visited network Public home network This is prior art Embodiment supports Private home network Embodiment supports Embodiment supports

[0136] Table 2

[0137] Public visited network Private visited network Public home network Embodiment supports Embodiment supports Private home network Embodiment supports Embodiment supports

[0138] Figure 5An illustration of embodiment operations 500 between a UE, the UE's home network, and the UE's visited network highlighting the communication of a protected private network information container. As shown, the UE 512 can not be within the coverage of its home network 514 and can enter the coverage of network 516. The UE 512 can select network 516 as its visited network and connect to network 516. The UE 512 can perform a one-time authentication and authorization with its home network 514 through network 516 (step 522). The home network 514 can be a private network that does not support 3GPP credentials. The network 516 can be a private network or a public network. During the one-time authentication and authorization, the home network 514 can generate one or more parameters, such as a key, based on the non-3GPP credentials and send the one or more parameters to the UE 512 through the visited network 516. The one or more parameters can be used to protect information communicated between the UE 512 and the home network 514. For example, when the home network 514 has information to send to the UE 512, the home network 514 can generate a private network information container that includes the information and protect the private network information using the key (and other parameters) and a security mechanism, such as applying integrity protection and / or cipher protection to the private network information container. The home network 514 can then transmit the protected private network information container 532 to the UE 512 through the UE's visited network 516 (e.g., through a network function 518 of the visited network 516) (steps 524, 526). The home network 514 can transmit a NAS message, such as the one shown, to carry the protected private network information container 532. Figure 4

[0139] As an example, the protected private network information container 532 can include a bootstrapping instruction that instructs the UE 512 to connect to a new visited network or perform network reselection. The protected private network information container 532 can also include credentials for the UE 512 to use to access the new visited network (e.g., to authenticate with the new visited network). When the UE 512 successfully verifies the protected private network information container 532, the UE 512 can execute the bootstrapping instruction to connect to the new visited network and perform authentication with the new visited network (e.g., using the credentials). When the authentication with the new visited network is successful, the UE 512 can then perform wireless communications through the new visited network, in which case communications between the UE 512 and the home network 514 will be through the new visited network. Embodiment network information containers protected by integrity / cipher protection can be used to communicate critical information between the UE 512 and the home network 514 through the new visited network. The same parameters generated during the one-time authentication and authorization in step 522 can be used to protect the network information containers.

[0140] ​Similarly, when the UE 512 has information to send to the home network 514, the UE 512 can generate a protected network information container 532 including the information and send the protected private network information container to the home network 514, e.g., through the visiting network 516, through a NAS message. The NAS message can also include security parameters of the UE, e.g., UE security capabilities. The information sent by the UE 512 to the home network 514 can include a request by the UE 512 to be steered to another visiting network. This can be the case when the UE's visiting network does not meet the UE's security requirements / QoS requirements, and the UE needs to connect to another visiting network. For example, if the security settings of the visiting network are such that cipher protection and / or integrity protection cannot be achieved for all subsequent communications in the visiting network, the UE can request another preferred visiting network from the home network. The information sent by the UE 512 to the home network 514 can also include requirements for the target visiting network and / or QoS requirements for the UE's service. The UE can also send other information using the protected network information container, e.g., a report about the visiting network. For example, when the visiting network performance is poor (e.g., the UE is requested to re-authenticate with the visiting network repeatedly), the UE needs to report this back to the home network. In this case, the protected container can hide such information from the visiting network.

[0141] Figure 6For an example operation 600 of a UE, two home networks of the UE, and a visited network of the UE, the communication of the respective protected private network information containers corresponding to the two home networks is highlighted. In this example, the UE 612 has a subscription (dual subscription) of two networks 614 and 616, that is, the UE 612 has two home networks. In the example, the home network 614 can be a private network that does not support 3GPP credentials, and the home network 616 can be a public network that supports 3GPP credentials. The UE 612 can not be within the coverage of its home networks 614 and 616, and is connected to the network 618 as its visited network. This can be a case where both home networks 614 and 616 instruct the UE 612 to connect to the same visited network 618, or a case where the UE 612 selects the same visited network 618 based on the requirements (e.g., steering policies, security policies, QoS requirements, etc.) of both home networks 614 and 616. The UE 612 can perform authentication and authorization with the home network 614 through the network 618 (step 622, step 624). For example, after the authentication and authorization with the home network 614, the UE 612 can also perform authentication with the network 618 based on the credentials of the home network 614, e.g., using a key derived from a non-3GPP credential (step 624). The UE 612 can perform authentication and authorization with the home network 616 through the network 618 (step 626, step 624). For example, after the authentication and authorization with the home network 616, the UE 612 can also perform authentication with the network 618 based on the credentials of the home network 616, e.g., using a key derived from a 3GPP credential (step 624). In a case where the UE 612 connects to two respective visited networks, e.g., based on the requirements / steering policies of its two respective home networks (e.g., the UE 612 selects a first visited network based on the requirements of the home network 614, and selects a second visited network based on the requirements of the home network 616), the UE 612 can perform authentication and authorization with its respective home networks through the respective visited networks, and can perform authentication with its respective visited networks using the credentials of the respective home networks.

[0142] After the UE 612 connects to the network 618, the UE 612 and the home network 614 can exchange a private network information container 642 over the visited network 618 (step 628, step 630). The private network information container 642 corresponds to the home network 614. The UE 612 and the home network 616 can also exchange a public network information container 644 over the visited network 618 (step 630, step 632). The public network information container 644 can be protected and corresponds to the home network 616. The private network information container 642 and the public network information container 644 can be integrity and / or cipher protected and can be sent in NAS messages as discussed with respect to Figure 4 The home network 614 can transmit a non-3GPP flag to the UE 612 to indicate that the UE is to use non-3GPP credentials. For example, a key used to verify the protected private network information container 642 or to authenticate / authorize the visited network for the UE 612 can be derived based on non-3GPP credentials. The home network 616 can transmit a 3GPP flag to the UE 612 to indicate that the UE is to use 3GPP credentials. For example, a key used to verify the protected public network information container 644 or to authenticate / authorize the visited network for the UE 612 is derived based on 3GPP credentials.

[0143] Figure 7An example method 700 for provisioning private network information container keys and policies. As shown, a UE 702 that is not within the coverage of its private home network 3 selects a private visited network 1 (may also be referred to as network 1, or visited network 1 in the following description) and successfully performs an initial authentication and authorization with its private home network 3 via the private visited network 1 (step 1 732). This can be performed through interactions between the private visited network 1 (e.g., through a (radio) access network ((R)AN) 704 of network 1, an access and mobility management function (AMF) 706 of network 1, a UDM 708 of network 1, and / or an authentication server function (AUSF) 710 of network 1) and the home network 3 (e.g., through an AUSF 712 of home network 3). The initial authentication and authorization is performed between the UE 702 and its home network 3. During the initial authentication and authorization, the home network 3 can generate security parameters that can be used to protect information communicated between the home network 3 and the UE 702, and / or can be used for authentication between the UE 702 and the visited network 1. When the UE 702 is successfully authenticated and authorized, the home network 3 can inform the visited network 1 that the UE 702 is successfully authenticated and authorized. The visited network 1 can then determine whether to allow the UE 702 to continue to access the visited network 1, or the visited network 1 can request the UE 702 to perform a secondary authentication with the visited network 1. In this example, the visited network 1 does not request the UE 702 to perform a secondary authentication. Figure 7

[0144] ​The home network 3 can provide the UE 702 with a key (for protecting the container) based on the non-3GPP credential creation, new security parameters for the private network information container, and a policy (limitation policy) for using the private network information container, e.g., specifying whether the UE 702 is allowed to use the private network information container when the UE 702 connects to the private visited network 2, e.g., through the AUSF 710 of the network 1 and the AUSF 712 of the home network 3 (step 2 734). The above information provided by the home network 3 can be generated by the home network 3 during an initial authentication and authorization with the UE 702, for example. It can not be necessary to provide the UE 702 with new security parameters and policies for each authentication and authorization procedure, as the information can be stored in the memory of the UE 702 for long-term use. Step 2 734 can occur in an authorization phase, a policy update procedure, or other procedures that allow the home network 3 to update the configuration and policies of the UE 702. The UE 702 can store the key, security parameters, and policy for future use of the private network information container (step 3 736). The key can be used for sending or receiving the private network information container. For example, the key and security parameters can be used to verify the private network information container sent by the home network 3 to the UE 702 through the visited network 1. In the example where the home network 3 protects the container using a public-private key mechanism, the key can be the public key sent by the home network 3. The public key can then be used to verify the private network information container, e.g., as shown in step 5 740 of Figure 7 In an embodiment, the home network 3 can not send the key to the UE in step 2 734. In this case, the UE 702 can derive the key based on the credential indicated in step 4 738 of Figure 7 and use the derived key to verify the private network information container.

[0145] When the home network 3 needs to send information (e.g., an instruction) to the UE 702 that requires privacy / integrity protection, the home network 3 can send a protected private network information container containing the instruction, a security key, and an indication that the security key is based on a non-3GPP credential to the UE 702 through the visited network 1 (step 4 738). The instruction in this example can direct the UE 702 to another visited network different from the visited network 1. The UE 702 can use the security key to access the other visited network. The information in step 4 738 can be sent from the UDM 714 of the home network 3 to the UDM 708 of the network 1, the AMF 706 of the network 1, the RAN 704 of the network 1, and the UE 702. The information can be sent in a NAS message, e.g., as shown in Figure 4The NAS message 400 shown, in this case, the security keys can be sent as part of the security parameters 404. The UE 702 can use the stored keys (and can also use one or more of the new security parameters sent in step 2 734, and / or one or more security parameters carried in the NAS message) to detect the authenticity of the message (verify / authenticate the protected private network information container), and if passed, the UE 702 executes the instructions (step 5 740). The UE 702 can use the security parameters (e.g., those described above) to verify the protected private network information container. The UE 702 can verify the integrity and privacy of the protected private network information container. As an example, to verify the protected private network information container, the UE 702 can compute a message authentication code (MAC) using the keys stored by the UE 702 in step 736, the synchronization degree (which can be sent to the UE 702 by the home network 1 in step 2 734 or step 4 738), and the container (and possibly other information), and verify that the computed MAC is the same as the MAC attached to the message carrying the container. The UE 702 can also perform decryption of the message (if encrypted), for example, based on the security parameters sent by the home network 1. Figure 4 The UE 702 can verify the integrity and privacy of the protected private network information container. As an example, to verify the protected private network information container, the UE 702 can compute a message authentication code (MAC) using the keys stored by the UE 702 in step 736, the synchronization degree (which can be sent to the UE 702 by the home network 1 in step 2 734 or step 4 738), and the container (and possibly other information), and verify that the computed MAC is the same as the MAC attached to the message carrying the container. The UE 702 can also perform decryption of the message (if encrypted), for example, based on the security parameters sent by the home network 1.

[0146] Figure 7 The private home network is shown to pass the private network information container to the UE only by way of example. The UE can also pass the private network information container to its private home network by Figure 7 a similar procedure shown. In this case, steps similar to steps 1-3 of Figure 7 may be performed. However, in step 4 738, the UE sends the container to the private home network using an uplink control message, and does not need to perform step 5 740.

[0147] Figure 8A flowchart of an embodiment method 800 for wireless communication. The method 800 can indicate operations of a UE. As shown, at step 802, the UE interacts with its home network for one-time authentication and authorization (A&A). This can be performed when the UE connects / accesses the home network. The home network in this example is a private network. At step 804, if the A&A is successful, the UE receives and stores one or more new security parameters (e.g., public key) for future communication with the home network. At step 806, the UE can receive a private network information container from the home network through a visited network, along with an indication of which type of credential to use. This can occur when the UE is outside the coverage of the home network and connects to a visited network. At step 808, the UE can use the security parameters to detect the security of the private network information container, e.g., by detecting the integrity and / or privacy (by decrypting the container) of the container. The security parameters can be sent by the home network with the private network information container, within the private network information container, or before the private network information container is transmitted. At step 810, the UE determines whether the security detection is successful. At step 812, if the detection is not successful, the UE can discard the private network information container and send an error message to the home network indicating that the private network information container was not successfully received. At step 814, if the detection is successful, the UE can obtain information contained in the private network information container, e.g., one or more instructions, and execute the instructions. For example, the private network information container can include a steering instruction indicating that the UE connect to another visited network that can be more preferred by the home network. To execute the instruction, e.g., connect to another visited network, at step 816, the UE can detect whether to use 3GPP credentials, e.g., to authenticate with the other visited network. This can be performed based on the indication received at step 806. When the indication is to use 3GPP credentials, at step 818, the UE uses 3GPP credentials stored in the UICC. When the indication is to use non-3GPP credentials, at step 820, the UE uses non-3GPP credentials obtained during the one-time authentication at step 802.

[0148] Figure 9A flowchart of another embodiment method 900 for wireless communication. The method 900 can indicate operations performed by a communication device, such as a UE. The communication device is out of coverage of its home network and communicates with the home network through a visited network. As shown, the communication device receives a message from the home network through the visited network, where the message includes a network information container and a credential indicator (step 902). The network information container includes information that is integrity protected and / or cipher protected. The credential indicator indicates a type of credential used to protect the network information container. The communication device can validate the network information container based on the credential indication through one or more security parameters (step 904). When the network information container is validated successfully, the communication device can obtain information included in the network information container (step 906). The communication device can then perform further operations based on the information in the network information container. For example, the information can include a steering instruction that indicates the communication device to connect to another visited network, in which case the communication device can perform the instruction to connect and access the other visited network, e.g., based on the indicated credential type (e.g., using a key derived based on the credential type). As another example, the information can include an instruction that indicates the communication device to perform cell selection to select a new visited network from a list of preferred networks provided by the home network, in which case the communication device can select a network from the list of preferred networks as the new visited network and connect to the selected network, e.g., based on the indicated credential type. If the network information container is not validated successfully, the communication device can discard the network information container. In this case, the communication device can send a message to the home network indicating that the network information container is not received successfully.

[0149] Figure 10 A flowchart of another embodiment method 1000 for wireless communication. The method 1000 can indicate operations performed by a network device of a network. In this example, the network is a home network of a communication device. The communication device is out of coverage of the home network and communicates with the home network through a visited network. As shown, the network device determines to send information to the communication device (step 1002), and generates a network information container that includes the information, where the network information container is integrity protected and / or cipher protected (step 1004). The network device determines a type of credential used to protect the network information container (step 1006). The network device then sends the network information container and a credential indicator that indicates the type of credential to the communication device through the visited network (step 1008).

[0150] Figure 11An exemplary communication system 1100 to which embodiments of the application can be applied is shown. Generally, a number of wireless or wireline users are able to transmit and receive data and other content via system 1100. System 1100 can implement one or more channel access methods, such as code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), single-carrier FDMA (SC-FDMA), or non-orthogonal multiple access (NOMA).

[0151] In this example, communication system 1100 includes electronic devices (EDs) 1110a- 1110c, radio access networks (RANs) 1120a and 1120b, a core network 1130, a public switched telephone network (PSTN) 1140, the Internet 1150, and other networks 1160. While the Figure 11 A certain number of these components or elements are shown in system 1100, but any number of these components or elements can be included in system 1100.

[0152] EDs 1110a-1110c are used for operation or communication in system 1100. For example, EDs 1110a-1110c are used for transmission or reception by wireless or wired communication channels. EDs 1110a-1110c all represent any suitable end-user device, and can include (or can be referred to as) a user equipment (UE), a wireless transmit or receive unit (WTRU), a mobile station, a fixed or mobile subscriber unit, a cellular telephone, a personal digital assistant (PDA), a smartphone, a laptop, a computer, a tablet, a wireless sensor, or a consumer electronics device.

[0153] The RANs 1120a and 1120b herein each include a base station 1170a and 1170b. Each of the base stations 1170a and 1170b functions to wirelessly communicate with one or more of the EDs 1110a-c to enable access to the core network 1130, the PSTN 1140, the Internet 1150, or other networks 1160. The base stations 1170a and 1170b can comprise (or be) one or more of a number of well-known devices, such as a base transceiver station (BTS), a Node-B, an evolved NodeB (eNodeB), a next generation (NG) NodeB (gNB), a Home NodeB, a Home eNodeB, a site controller, an access point (AP), or a wireless router, for example. The EDs 1110a-c are configured to connect and communicate with the Internet 1150, and can access the core network 1130, the PSTN 1140, or other networks 1160.

[0154] In Figure 11 In the illustrated embodiment, the base station 1170a forms part of the RAN 1120a, which can include other base stations, elements, or devices. Further, the base station 1170b forms part of the RAN 1120b, which can include other base stations, elements, and / or devices. Each of the base stations 1170a and 1170b functions to transmit or receive wireless signals within a particular geographic area, sometimes referred to as a “cell.” In some embodiments, multiple-input multiple-output (MIMO) technology can be used, with multiple transceivers for each cell.

[0155] The base stations 1170a and 1170b communicate with one or more of the EDs 1110a-c using wireless communication links over one or more air interfaces 11110. The air interfaces 11110 can use any suitable wireless access technology.

[0156] It is contemplated that the system 1100 can use multi-channel access functionality, including schemes as described above. In particular embodiments, the base stations and EDs implement 5G New Radio (NR), LTE, LTE-A, or LTE-B. Of course, other multiple access schemes and wireless protocols can be utilized.

[0157] The RANs 1120a and 1120b communicate with the core network 1130 to provide the EDs 1110a- 1110c with access to voice, data, applications, voice over internet protocol (VoIP), or other services. It will be appreciated that the RANs 1120a and 1120b or the core network 1130 can be in direct or indirect communication with one or more other RANs (not shown) that employ the same RAT as the RANs 1120a and 1120b or a different RAT. Additionally, the core network 1130 can serve as a gateway for the EDs 1110a- 1110c to access other networks (e.g., the PSTN 1140, the Internet 1150, and the other networks 1160). Moreover, one or more of the EDs 1110a- 1110c can communicate with one or more network-attached storage devices (NAS) (not shown).

[0158] Although Figure 11 various changes can be made to the communication system Figure 11 illustrated. For example, the communication system 1100 could include any number of EDs, base stations, networks, or other components in any suitable configuration.

[0159] Figure 12A and Figure 12B Exemplary devices that can implement the various methods and teachings disclosed herein are shown. In particular, Figure 12A An exemplary ED 1210 (e.g., UE) is shown, Figure 12B An exemplary base station 1270 is shown. These components can be used in the system 1100 or any other suitable system.

[0160] As Figure 12A shown, the ED 1210 includes at least one processing unit 1200. The processing unit 1200 implements various processing operations of the ED 1210. For example, the processing unit 1200 could execute a signal coding

[0161] The ED 1210 also includes at least one transceiver 1202. The transceiver 1202 is used to modulate data or other content for transmission by at least one antenna or network interface controller (NIC) 1204. The transceiver 1202 is also used to demodulate data or other content received by the at least one antenna 1204. Each transceiver 1202 includes any suitable structure for generating a signal for wireless or wired transmission or processing a signal received via wireless or wired transmission. Each antenna 1204 includes any suitable structure for transmitting or receiving a wireless signal or wired signal. One or multiple transceivers 1202 can be used in the ED 1210, and one or multiple antennas 1204 can be used in the ED 1210. Although the transceiver 1202 is shown as a single functional unit, it can also be implemented using at least one transmitter and at least one separate receiver.

[0162] The ED 1210 also includes one or more input / output devices 1206 or interfaces (e.g., wired interfaces to the Internet 1150). The input / output devices 1206 facilitate interaction with a user or other devices (network communications) within the network. Each input / output device 1206 includes any suitable structure for providing information to or receiving information from a user, such as a speaker, microphone, keypad, keyboard, display, or touch screen, including network interface communications.

[0163] Further, the ED 1210 includes at least one memory 1208. The memory 1208 stores instructions and data used, generated, or collected by the ED 1210. For example, the memory 1208 could store software or firmware instructions executed by the processing unit(s) 1200 and data used in reducing or eliminating interference in incoming signals. Each memory 1208 includes any suitable one or both of volatile or non-volatile memory. Any suitable type of memory can be used, such as random access memory (RAM), read only memory (ROM), hard disk, optical disk, subscriber identity module (SIM) card, memory stick, secure digital (SD) card, and the like.

[0164] As Figure 12BAs shown, base station 1270 includes at least one processing unit 1250, at least one transceiver 1252 (including transmitter and receiver functionality), one or more antennas 1256, at least one memory 1258, and one or more input / output devices or interfaces 1266. A scheduler, as will be appreciated by those skilled in the art, is coupled to processing unit 1250. The scheduler can be included within base station 1270 or can operate separately from base station 1270. Processing unit 1250 implements various processing operations of base station 1270, such as signal coding, data processing, power control, input / output processing, or any other functionality. Processing unit 1250 can also support the methods and teachings detailed above. Each processing unit 1250 includes any suitable processing or computing device configured to perform one or more operations. Each processing unit 1250 maybe, for example, a microprocessor, microcontroller, digital signal processor, field programmable gate array, or application specific integrated circuit.

[0165] Each transceiver 1252 includes any suitable structure for generating signals for wireless or wired transmission to one or more EDs or other devices. Each transceiver 1252 also includes any suitable structure for processing signals received via wireless or wired transmission from one or more EDs or other devices. Although shown as combined into a single transceiver 1252, a transmitter and a receiver can be separate components. Each antenna 1256 includes any suitable structure for transmitting or receiving wireless or wired signals. Although shown as a single antenna 1256 coupled to transceiver 1252, one or more antennas 1256 can be coupled to one or more transceivers 1252, such that separate antennas 1256 are coupled to transmitters and receivers if configured as separate components. Each memory 1258 includes any suitable volatile or non-volatile storage and retrieval devices. Each input / output device 1266 facilitates interaction with a user or other devices (such as communication via a network). Each input / output device 1266 includes any suitable structure for providing information to or from a user, including network interface communications.

[0166] Figure 13is a block diagram of a computing system 1300 that can be used to implement the devices and methods disclosed herein. For example, the computing system can be any of a UE, an access network (AN), a mobility management (MM), a session management (SM), a user plane gateway (UPGW), or an access stratum (AS) entity. Particular devices can utilize all of the components shown or only a subset of the components, and levels of integration can vary from device to device. Furthermore, a device can be composed of multiple physical components, each comprising some or all of the components shown, or the device can be composed of a single physical component comprising all of the components shown. Finally, the computing system 1300 can be composed of one or more physical devices, each comprising some or all of the components shown. The computing system 1300 includes a processing unit 1302. The processing unit includes a central processing unit (CPU) 1314, a memory 1308, and can also include a mass storage device 1304, a video adapter 1310, and an I / O interface 1312 connected to a bus 1320.

[0167] The bus 1320 can be one or more of several types of bus structures including a memory bus or memory controller, a peripheral bus or external bus, and a video bus. The CPU 1314 can comprise any type of electronic data processor. The memory 1308 can comprise any type of non-transitory system memory such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), read-only memory (ROM), or a combination thereof. In an embodiment, the memory 1308 can include a ROM for use by a bootloader program during startup and a DRAM for use during program execution.

[0168] The mass storage device 1304 can comprise any type of non-transitory storage device for storing data, programs and other information and for making such data, programs and other information accessible via the bus 1320. The mass storage device 1304 can comprise one or more of a solid state hard drive, a hard disk drive, a disk drive, or an optical disk drive.

[0169] The video adapter 1310 and the I / O interface 1312 provide interfaces to couple external input and output devices to the processing unit 1302. As illustrated, examples of input and output devices include a display 1318 coupled to the video adapter 1310 and a mouse, keyboard, or printer 1316 coupled to the I / O interface 1312. Other devices can be coupled to the processing unit 1302 and additional or fewer interface cards can be utilized. For example, a serial interface in the form of a universal serial bus (USB) interface 1320 can be used to provide an interface for an external device.

[0170] The processing unit 1302 also includes one or more network interfaces 1306, which can comprise wired links, such as an Ethernet cable or wireless links to an access node or different networks. The network interface 1306 can allow the processing unit 1302 to communicate with remote units via the networks to which the network interface 1306 is connected. The network interface 1306 can provide wireless communication via one or more transmitters / transmission antennas and one or more receivers / reception antennas. In embodiments, the processing unit 1302 is coupled to a local-area network 1322 or a wide-area network for data processing and communications with remote devices, such as other processing units, the Internet, or remote storage facilities.

[0171] It is to be understood that one or more steps in the example methods provided herein can be performed by a corresponding unit or module. For example, a signal can be transmitted by a transmission unit or module. A signal can be received by a reception unit or module. A signal can be processed by a processing unit or module. Other steps can be performed by a verification unit / module, an integrity detection unit / module, an obtaining unit / module, an encryption / decryption unit / module, an indication unit / module, an accessing unit / module, a discarding unit / module, an execution unit / module, an authentication and authorization unit / module, a determination unit / module, a generation unit / module, and / or an integrity protection unit / module. The corresponding units / modules can be hardware, software, or a combination thereof. For example, one or more of the units / modules can be an integrated circuit, such as a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC).

[0172] While the application has been described in detail, it should be understood that various changes, substitutions and alterations can be made hereto without departing from the spirit and scope of the application as defined by the appended claims. Moreover, the scope of the application is not intended to be limited to the particular embodiments described in the specification, as the application is capable of being practiced with a variety of process, machines, manufacture, compositions of matter, means, methods, or steps in accordance with the disclosure, as presently existing or later developed. Accordingly, the appended claims are intended to embrace any and all embodiments within the scope of the claims.

Claims

1. A communication method characterized by comprising: The method comprises: receiving, by a communication device, a message from a first home network of the communication device via a first visited network of the communication device, the message comprising a first network information container and a credential indicator, the first network information container comprising information that is integrity protected and / or cipher protected, the credential indicator indicating a type of credential used to protect the first network information container; wherein the type of credential comprises a 3GPP credential or a non-3GPP credential, and the credential indicator is a flag bit, the flag bit being of a first value to indicate that the credential is a 3GPP credential, and the flag bit being of a second value to indicate that the credential is a non-3GPP credential; verifying, by the communication device, the first network information container based on the type of credential via one or more security parameters; and when the first network information container is verified successfully, obtaining, by the communication device, the information comprised in the first network information container.

2. The method of claim 1, wherein, The message further comprises information indicating a type of protection mechanism used to protect the first network information container.

3. The method of claim 2, wherein, The type of protection mechanism comprises integrity protection only, cipher protection only, or integrity and cipher protection.

4. The method of claim 1, wherein, Verifying the first network information container comprises: verifying, by the communication device, integrity of the first network information container via the one or more security parameters; and / or decrypting, by the communication device, the first network information container via the one or more security parameters.

5. The method of claim 1, wherein, The one or more security parameters comprise one or more of: a security parameter used to verify the first network information container or an access network, the security parameter comprising a certificate, a public key, or a private key; a key identifier; synchronization or freshness; a random number; or a network security preference.

6. The method of claim 1, wherein, The method further comprises: when the first network information container is verified successfully, executing, by the communication device, an instruction comprised in the first network information container.

7. The method of claim 6, wherein, The instruction: indicates the communication device to connect to a second visited network; or indicates the communication device to perform network selection based on a candidate network list provided by the first home network to select a new visited network.

8. The method of claim 7, wherein, The method further comprises: accessing, by the communication device, the second visited network or the new visited network using the type of credential indicated by the credential indicator and / or information in the first network information container.

9. The method of claim 7, wherein, The second visited network is a preferred network configured by the first home network for the communication device.

10. The method according to any one of claims 1 to 9, characterized in that, The method further comprises: sending, by the communication device, a second network information container to the first home network via the first visited network, the second network information container comprising information that is integrity protected and / or cipher protected.

11. The method according to any one of claims 1 to 5, characterized in that, The method further comprises: when the first network information container is not verified successfully, discarding, by the communication device, the first network information container.

12. The method according to any one of claims 1 to 9, characterized in that, The first network information container comprises at least one of: a network bootstrapping instruction; a network bootstrapping policy; a list of preferred visited networks of the communication device; a quality of service (QoS) requirement of a service or a visited network; configuration and / or capability information of the communication device; or a security parameter.

13. The method according to any one of claims 1 to 9, characterized in that, The message further comprises the one or more security parameters.

14. The method according to any one of claims 1 to 9, characterized in that, The message further includes operator information of the first home network.

15. The method according to any one of claims 1 to 9, characterized in that, The message is a non-access stratum (NAS) message.

16. The method according to any one of claims 1 to 9, characterized in that, The communication device has or does not have a universal integrated circuit card (UICC).

17. The method of any one of claims 1 to 9, wherein, The method further includes: The communication device receives a third network information container corresponding to a second home network of the communication device and the first network information container corresponding to the first home network of the communication device.

18. The method of claim 17, wherein, One of the first home network and the second home network is a private network.

19. The method according to any one of claims 1 to 9, characterized in that, The first network information container includes information for accessing a public network and information for accessing a private network.

20. The method of any one of claims 1 to 9, wherein, The first home network is a public network or a private network.

21. The method of any one of claims 1 to 9, wherein, The first visited network is a public network or a private network.

22. The method of any one of claims 1 to 9, wherein, The message further includes usage restriction information according to which the first network information container is used.

23. The method of any one of claims 1 to 9, wherein, The method further includes: The communication device authenticates and authorizes with the first home network through the first visited network before receiving the message.

24. A method of communication, comprising: The method includes: A network device of a first network determines to send first information to a communication device, the first network being a home network of the communication device, the communication device being served by a first visited network; The network device generates a network information container including the first information, the network information container being integrity protected and / or cipher protected; The network device determines a type of credential used to protect the network information container; and The network device sends a message to the communication device through the first visited network, the message including the network information container and a credential indicator indicating the type of credential; wherein the type of credential includes a 3GPP credential or a non-3GPP credential, and the credential indicator is a flag bit, the flag bit being of a first value to indicate that the credential is a 3GPP credential, and the flag bit being of a second value to indicate that the credential is a non-3GPP credential.

25. The method of claim 24, wherein, The network information container includes at least one of: a network steering instruction; a network steering policy; a preferred visited network list of the communication device; a quality of service (QoS) requirement of a serving or visited network; configuration and / or capability information of the communication device; or a security parameter.

26. The method of claim 25, wherein, The network steering instruction: indicates the communication device to connect to a second visited network; or indicates the communication device to perform network selection based on a candidate network list provided by the home network to select a new visited network.

27. The method of claim 24, wherein, The message further includes one or more security parameters used to verify the network information container.

28. The method of claim 27, wherein, The one or more security parameters include one or more of: a security parameter used to verify the network information container or an access network, the security parameter including a certificate, a public key, or a private key; a key identifier; synchronization or freshness; a random number; or a network security preference.

29. The method according to any one of claims 24 to 28, characterized in that, The message further includes operator information of the home network.

30. The method of any one of claims 24-28, wherein, The message is a non-access stratum (NAS) message.

31. The method of any one of claims 24-28, wherein, The communication device has or does not have a universal integrated circuit card (UICC).

32. The method of any one of claims 24-28, wherein, The network information container includes information for accessing a public network and information for accessing a private network.

33. The method of any one of claims 24-28, wherein, The home network is a public network or a private network.

34. The method of any one of claims 24-28, wherein, The first visited network is a public network or a private network.

35. The method of any one of claims 24-28, wherein, The message further includes usage restriction information according to which the network information container is used.

36. The method of any one of claims 24-28, wherein, The method further includes: The network device receives, from the communication device via the first visited network, an information container including information that is integrity-protected and / or cipher-protected.

37. The method of any one of claims 24-28, wherein, The message further includes information indicating a protection mechanism type used to protect the network information container.

38. The method of claim 37, wherein, The protection mechanism type includes integrity protection only, cipher protection only, or integrity and cipher protection.

39. A communications device, characterized by The apparatus includes: a non-transitory memory storage storing instructions; and one or more processors in communication with the memory storage, wherein the instructions, when executed by the one or more processors, cause the apparatus to perform: receiving, via a first visited network of the apparatus, a message from a first home network of the apparatus, the message including a first network information container and a credential indicator, the first network information container including information that is integrity-protected and / or cipher-protected, the credential indicator indicating a type of credential used to protect the first network information container; wherein the type of credential includes a 3GPP credential or a non-3GPP credential, the credential indicator being a flag bit, the flag bit being of a first value to indicate the credential is a 3GPP credential, the flag bit being of a second value to indicate the credential is a non-3GPP credential; verifying the first network information container based on the type of credential via one or more security parameters; and when the first network information container is verified successfully, obtaining the information included in the first network information container.

40. A non-transitory computer-readable medium storing computer instructions, wherein the computer instructions, when executed by a processor, cause the processor to perform operations comprising: The computer instructions, when executed by one or more processors of an apparatus, cause the apparatus to perform: receiving, via a first visited network of the apparatus, a message from a first home network of the apparatus, the message including a first network information container and a credential indicator, the first network information container including information that is integrity-protected and / or cipher-protected, the credential indicator indicating a type of credential used to protect the first network information container; wherein the type of credential includes a 3GPP credential or a non-3GPP credential, the credential indicator being a flag bit, the flag bit being of a first value to indicate the credential is a 3GPP credential, the flag bit being of a second value to indicate the credential is a non-3GPP credential; verifying the first network information container based on the type of credential via one or more security parameters; and when the first network information container is verified successfully, obtaining the information included in the first network information container.

41. A communications device of a first network, the device comprising: The communication apparatus includes: a non-transitory memory storage storing instructions; and one or more processors in communication with the memory storage, wherein the instructions, when executed by the one or more processors, cause the apparatus to perform: determining to send first information to a communication device, the first network being a home network of the communication device, the communication device being served by a first visited network; generating a network information container including the first information, the network information container being integrity-protected and / or cipher-protected; determining a type of credential used to protect the network information container; and sending, by the first visited network, a message to the communication device, the message including the network information container and a credential indicator indicating the type of credential; wherein the type of credential includes a 3GPP credential or a non-3GPP credential, and the credential indicator is a flag bit, the flag bit being of a first value to indicate the credential is a 3GPP credential, and the flag bit being of a second value to indicate the credential is a non-3GPP credential.

42. A non-transitory computer readable medium storing computer instructions, wherein, when executed by one or more processors of an apparatus of a first network, the computer instructions cause the apparatus to perform: determining to send first information to a communication device, the first network being a home network of the communication device, the communication device being served by a first visited network; generating a network information container including the first information, the network information container being integrity protected and / or cipher protected; determining a type of credential used to protect the network information container; and sending, by the first visited network, a message to the communication device, the message including the network information container and a credential indicator indicating the type of credential; wherein the type of credential includes a 3GPP credential or a non-3GPP credential, and the credential indicator is a flag bit, the flag bit being of a first value to indicate the credential is a 3GPP credential, and the flag bit being of a second value to indicate the credential is a non-3GPP credential.

43. A communication system, the system including a network device of a first network and a communication device, the first network being a home network of the communication device, the communication device being served by a visited network, characterized in that the network device is configured to perform: determining to send first information to the communication device; generating a network information container including the first information, the network information container being integrity protected and / or cipher protected; determining a type of credential used to protect the network information container; and sending, by the visited network, a message to the communication device, the message including the network information container and a credential indicator indicating the type of credential; wherein the type of credential includes a 3GPP credential or a non-3GPP credential, and the credential indicator is a flag bit, the flag bit being of a first value to indicate the credential is a 3GPP credential, and the flag bit being of a second value to indicate the credential is a non-3GPP credential; and the communication device is configured to perform: receiving, by the visited network, the message from the home network of the communication device; verifying the network information container by one or more security parameters based on the type of credential; and when the network information container is verified successfully, obtaining the first information included in the network information container.

Citation Information

Patent Citations

  • Method and system to detect Anti-steering of roaming activity in wireless communication network

    WO2019017689A1