Method, user equipment, system or telecommunication network, program and computer program product for operating user equipment within or as part of a telecommunication network

By introducing application authorization functions in telecommunications networks, the application or application layer functionality of user equipment can control and supervise data transmission sessions with core networks and data networks on demand, solving the problem of lack of application granular access control in the prior art and achieving flexible and secure data transmission management.

CN117941394BActive Publication Date: 2025-06-10DEUTSCHE TELEKOM AG
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202280061201.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-09-10
Filing Date
2022-09-01
Publication Date
2025-06-10
Estimated Expiration
2042-09-01

AI Technical Summary

Technical Problem

There is a lack of access control and authentication methods in existing telecommunications networks on a per-application granularity, resulting in the application or application layer functionality that cannot control and supervise data transmission sessions with the core network and data network on demand.

Method used

Introducing application authorization function or functionality, the user equipment transmits application access request messages, including relevant credential information, to the application authorization function or functionality. If authorization passes, it will obtain permission to access the data transmission session.

Benefits of technology

It realizes application-specific control and supervision of data transmission sessions, allowing the application or application layer to functionally access and use data transmission sessions on demand, enhancing the flexibility and security of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117941394B_ABST
    Figure CN117941394B_ABST
Patent Text Reader

Abstract

The present invention relates to a method for operating user equipment within or as part of a telecommunications network, wherein the operation of the user equipment involves the operation of an application or application layer functionality of the user equipment, wherein the telecommunications network includes or is associated with or assigned to an access network and a core network, wherein the core network provides data connectivity towards a data network to the user equipment, wherein the operation of the application or application layer functionality of the user equipment requires the establishment of at least one data transfer session between the user equipment and the core network, wherein the user equipment includes or is assigned to or can access an application authorization function or functionality, wherein the application authorization function or functionality authorizes the application or application layer functionality to access the at least one data transfer session, and wherein, in order for the application or application layer functionality to use the at least one data transfer session to exchange payload data with and / or connect to the core network and / or the data network, the method comprises the following steps: -- in a first step, the application or application layer functionality transmits an application access request message to the application authorization function or functionality, the application access request message including at least one credential information related to the application or application layer functionality, -- in a second step, in the case where the application authorization function or functionality determines that the application access request message is valid, the application authorization function or functionality transmits an application access grant message to the application or application layer functionality.
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUND OF THE INVENTION

[0001] The present invention relates to a method for operating user equipment within or as part of a telecommunications network, wherein the operation of the user equipment involves the operation of an application or application layer functionality of the user equipment, and wherein the operation of the application or application layer functionality of the user equipment requires establishing at least one data transfer session between the user equipment and the core network for the application or application layer functionality to use the at least one data transfer session to exchange payload data with the core network and / or a data network or to connect to the core network and / or a data network.

[0002] Furthermore, the present invention relates to user equipment for operating within or as part of a telecommunications network, wherein the operation of the user equipment involves the operation of an application or application layer functionality of the user equipment, and wherein the operation of the application or application layer functionality of the user equipment requires establishing at least one data transfer session between the user equipment and the core network for the application or application layer functionality to use the at least one data transfer session to exchange payload data with the core network and / or a data network or to connect to the core network and / or a data network.

[0003] Additionally, the present invention relates to a system or telecommunications network for operating user equipment within or as part of a telecommunications network, wherein the operation of the user equipment involves the operation of an application or application layer functionality of the user equipment, and wherein the operation of the application or application layer functionality of the user equipment requires establishing at least one data transfer session between the user equipment and the core network for the application or application layer functionality to use the at least one data transfer session to exchange payload data with the core network and / or a data network or to connect to the core network and / or a data network.

[0004] Additionally, the present invention relates to an application authorization function or functionality of a system or telecommunications network according to the present invention.

[0005] Furthermore, the present invention relates to a program and a computer-readable medium for a method according to the present invention for operating user equipment within or as part of a telecommunications network.

[0006] In a conventionally known telecommunication network, there is usually a distinction between an access network (also denoted by AN in the context of the present invention) and a core network (also denoted by CN in the context of the present invention). A user equipment is part of or connected to such a telecommunication network. In particular, for a mobile communication network, the access network is a radio access network. In the case of a mobile communication network, the user equipment communicates with the radio access network via a radio interface for conveying both signaling information and (payload) data traffic. Even though there is a logical separation (e.g., in the case of a telecommunication network according to the 5G standard, in the form of logical channels such as N1 / N2 versus N3 interfaces), both types of data are ultimately transmitted on the same physical medium. A similar situation (conveying signaling information and (payload) data traffic on the same physical medium, e.g., digital subscriber line) also applies to the case of a fixed-line telecommunication network. However, in many cases, the aim is for the user equipment to be connected to a data network; this requires a data transmission session (e.g., in the case of a telecommunication network according to the 5G standard, in the form of a PDU session).

[0007] A data transmission session (or PDU session) is a logical data transmission channel that terminates at the core network and provides connectivity to a data network; a data transmission session (or PDU session) typically has a termination point (e.g., in the case of a telecommunication network according to the 5G standard, a user plane function (UPF)), which is also referred to as a data transmission session anchor (or PDU session anchor). When the user equipment moves (e.g., by means of a handover operation implemented within a mobile communication network, in particular a radio access network), the data transmission session anchor typically remains unchanged (hence the term "anchor").

[0008] Currently, different applications (or application layer functionalities) implemented in or by a user equipment can generally interact with a telecommunication network or its components or entities or components or entities connected thereto (such as typically a data network). However, the possibilities or capabilities of such applications (e.g., regarding which access is available for which service and under which conditions) conventionally depend on the subscription of the user equipment, and there are no access control (i.e., authorization) and authentication methods available on a per-application granularity basis. There are ways to authenticate (the user equipment) to the network, to a specific slice, and to a given PDU session, but not for registration within the PDU session. SUMMARY OF THE INVENTION

[0009] The object of the present invention is to provide a technically simple, efficient and cost-effective solution for operating user equipment within or as part of a telecommunication network, where the operation of the user equipment involves the operation of an application or application layer functionality of the user equipment, and where the access of the application or application layer functionality to a data transmission session (to at least one data transmission session) can be controlled and regulated in an application-dependent manner. A further object of the present invention is to provide a corresponding user equipment, system or mobile communication network, application authorization function or functionality, as well as a corresponding program and computer-readable medium.

[0010] The object of the present invention is achieved by a method for operating user equipment within or as part of a telecommunication network, where the operation of the user equipment involves the operation of an application or application layer functionality of the user equipment,

[0011] where the telecommunication network includes or is associated with or assigned to an access network and a core network, and where the core network provides data connectivity towards a data network to the user equipment,

[0012] where the operation of the application or application layer functionality of the user equipment requires the establishment of at least one data transmission session between the user equipment and the core network,

[0013] where the user equipment includes or is assigned to or can access an application authorization function or functionality, and where the application authorization function or functionality authorizes the application or application layer functionality to access the at least one data transmission session,

[0014] where, in order for the application or application layer functionality to use the at least one data transmission session to exchange payload data with the core network and / or the data network or to connect to the core network and / or the data network, the method comprises the following steps:

[0015] -- In a first step, the application or application layer functionality transmits an application access request message to the application authorization function or functionality, the application access request message including at least one credential information related to the application or application layer functionality,

[0016] -- In a second step, in the case where the application authorization function or functionality determines that the application access request message is valid, the application authorization function or functionality transmits an application access grant message to the application or application layer functionality.

[0017] Thus, according to the present invention, it is advantageously possible to request access to a data transmission session by means of an application or application layer functionality and for the application authorization function or functionality to provide access (i.e., the application or application layer functionality transmits an application access request message (including at least one piece of credential information related to the application or application layer functionality) to the application authorization function or functionality, and the application authorization function or functionality (in the case where the application access request message is determined to be valid by the application authorization function or functionality) transmits an application access grant message to the application or application layer functionality), and the application or application layer functionality can use the (at least one) data transmission session in an application-specific manner to exchange payload data with the core network and / or data network or connect to the core network and / or data network.

[0018] In this regard, it is advantageously possible to provide differentiated services related to how and where such services are deployed in a telecommunication network (e.g., edge services, low-latency services, specific features, etc.) and who can access which services (i.e., for a given subscription of a (user equipment) and / or under which conditions which services are allowed for which applications or application layer functionalities).

[0019] Conventionally, the scope of a mobile network (or more generally, a telecommunication network) includes, or consists of, user equipment, an access network, a core network, and one or more data networks. Conventionally, this implies that access, service, and subscription information is related to the user equipment subscription, and conventionally there is no way of using access control / authorization and authentication methods on a per-application granularity basis. There is typically authentication for establishing access to the network, to a specific slice, and to a given PDU session, but no way of registering within the PDU session.

[0020] According to the present invention, it is advantageously possible to, for example, restrict access to a specific network slice to a specific application, charge in an application-specific manner (in particular, application-specific traffic based on application flows), and more generally, be able to control access to data connectivity on a per-application basis (as an alternative or supplement to on a per-subscriber basis). Thus, according to the present invention, it is advantageously possible that a network operator may provide connectivity not only to a specific subscriber (e.g., a physical customer or user equipment), but also to an application (i.e., in an application-specific manner). This means that the services that a given user equipment can access are determined not only by the subscription data of the given user equipment (or the subscription data associated with the user equipment), but also by the "application subscription data" (i.e., by means of an application or application layer functionality requesting and an application authorization function or functionality providing access to a data transmission session).

[0021] To establish a data connection that enables a user equipment (or any user equipment) to communicate with a data network, a data transmission session (in particular, a PDU session) is required. A data transmission session (or PDU session) is a logical data transmission channel that typically terminates at the core network and provides connectivity to the data network. The termination point of a given data transmission session (or PDU session) - typically the user plane function in the context of a 5G telecommunications network - is referred to as the data transmission session anchor (or PDU session anchor (PSA), especially in 5G). When the user equipment moves (e.g., in the case of a handover), the data transmission session anchor generally remains rather constant. As follows, i.e., according to the following processing steps, a data transmission session (or PDU session) is established between the user equipment and the core network:

[0022] The user equipment sends a session establishment request (i.e., the corresponding message) to the core network; the data transmission session is established by the core network; the core network sends a data transmission session establishment acceptance (i.e., the corresponding message) to the user equipment; as a result of these processing steps, the user equipment, in particular an application or application layer functionality within or as part of the user equipment, can use the data transmission session or PDU session to send data traffic to and / or receive data traffic from the data network (accessible through or via the core network).

[0023] According to the present invention, the user equipment includes or is assigned to or can access an application authorization function or functionality, wherein the application authorization function or functionality authorizes the application or application layer functionality to access one or more of the considered data transmission sessions (i.e., at least one data transmission session). The exchange of payload data (or data traffic), or the connectivity between the application or application layer functionality and the core network and / or the data network, requires at least one data transmission session.

[0024] A telecommunications network generally includes an access network and a core network. However, the present invention also relates to the situation where, strictly speaking, the telecommunications network does not include both the access network and the core network, but the telecommunications network is only associated with or assigned to the access network (and particularly includes the core network), or the telecommunications network is only associated with or assigned to the core network (and particularly includes the access network), or the telecommunications network is only associated with or assigned to both the access network and the core network. According to the present invention, the core network particularly provides data connectivity towards the data network to the user equipment, and thus the core network at least partially implements 5G functionality.

[0025] According to the present invention, it is advantageously possible to implement a data transmission session that may require an application to request access or use (for which data traffic or payload data is to be transmitted to and from a data network), by transmitting an application access request message to an application authorization function or functionality. Only in the case where the request is granted (by transmitting an application access grant message to the application or application layer functionality (and received by it)), can the application or application layer functionality access the data transmission session, and of course, the grant can also be rejected by the application authorization function or functionality (in the case where the application access request message is determined to be invalid by the application authorization function or functionality).

[0026] According to the present invention, it is further advantageously possible and preferred that the operation of the user equipment further involves the operation of another application or another application layer functionality of the user equipment,

[0027] wherein the operation of the another application or another application layer functionality of the user equipment also uses at least one data transmission session established between the user equipment and the core network,

[0028] wherein, in order for the another application or another application layer functionality to use the at least one data transmission session to exchange payload data with the core network and / or data network or connect to the core network and / or data network: the another application or another application layer functionality transmits an another application access request message to the application authorization function or functionality, the another application access request message includes at least one another credential information related to the another application or another application layer functionality, and in the case where the application authorization function or functionality determines that the another application access request message is valid, the application authorization function or functionality transmits an another application access grant message to the another application or another application layer functionality.

[0029] Thus, according to the present invention, it is advantageously possible that access to a data transmission session (or to different data transmission sessions) is conditional on an application (and / or application layer functionality) and another application (and / or another application layer functionality) requesting such access by using its specific at least one credential information (i.e., at least one credential information in the case of an application or application layer functionality, and at least one another credential information in the case of another application or another application layer functionality) - thus, according to the present invention, the grant of such access to a data transmission session (or multiple data transmission sessions) is application-specific.

[0030] According to the present invention, it is further advantageously possible and preferred that the at least one credential information is or corresponds to or includes a certificate or certificate information and / or token information.

[0031] Thus, the concept of the present invention can be relatively easily implemented using voucher information or fragments of voucher information of a type known conventionally (such as certificates and / or tokens) and fragments of information derived therefrom.

[0032] Furthermore, it may be advantageous and preferred that the application access request message, at least one piece of voucher information, and the application access grant message are application-specific or application group-specific, respectively.

[0033] Thus, advantageously, the security level can be enhanced, for example, by using different application access request messages, different fragments of voucher information, and different application access grant messages specific to the respective application (or application layer functionality) or its group (between different applications or application layer functionalities, or between different application groups or different groups of application layer functionalities).

[0034] Furthermore, according to the present invention, it may be advantageous and preferred that the voucher information relates to two or more applications or application layer functionalities, in particular a group of applications or application layer functionalities.

[0035] Thus, it may be advantageous that - in a situation where access to a data transmission session has been requested and provided or granted to a first application or first application layer functionality (in the considered application group or group of application layer functionalities) - a second application or second application layer functionality (in the considered application group or group of application layer functionalities) can directly use the granted access to the corresponding data transmission session.

[0036] Furthermore, according to the present invention, it may be advantageous and preferred that at least one piece of voucher information is valid for two or more data transmission sessions.

[0037] Thus, it may be advantageous that an application or application layer functionality that has been granted access to a first data transmission session can also access a second data transmission session (without necessarily having to request access to the second data transmission session again).

[0038] Furthermore, according to the present invention, it may be advantageous and preferred that, in a third step after the second step, an application or application layer functionality of the user equipment uses at least one data transmission session to exchange payload data with the core network and / or data network, or to transmit payload data to and / or receive payload data from the core network and / or data network.

[0039] Furthermore, according to the present invention, it may be advantageous and preferred that at least one data transmission session is a PDU session, a protocol data unit session.

[0040] Furthermore, according to the present invention, it is advantageously possible and preferred that, in a fourth step after the first step and before the second step, an authorization function or functionality queries a core network, in particular its authorization server function, based on at least one credential information, in particular in order to determine whether an application access request message is valid.

[0041] Thereby, it is advantageously possible to centrally check or verify the validity of an application access request message (e.g., by the authorization server function of the core network).

[0042] According to a further preferred embodiment of the present invention, the fourth step involves the user equipment exchanging a PDU session modification message with the core network, in particular its authorization server function, after the PDU session has been established or generated.

[0043] Wherein, in particular, the establishment or generation or subsequent modification of the PDU session includes an indication of the capabilities related to the handling of the application access request message and the application access grant message and / or an indication of the necessity for using or handling the application access request message and the application access grant message.

[0044] By exchanging a PDU session modification message between the user equipment and the core network, in particular its authorization server function, it is advantageously possible to more easily realize the benefits of the present invention by using the established mechanism or means to modify the data transmission session or the PDU session.

[0045] By using an indication of the capabilities (related to the handling of the application access request message and the application access grant message) and / or an indication of the necessity (for using or handling the application access request message and the application access grant message), it is advantageously possible to modify the data transmission session or the PDU session, in particular during the fourth step or during a fifth step before the first step, such that the mechanism of the present invention is possible and / or even required, in particular for a certain application or application layer functionality or for a group of certain (specifically defined) applications or application layer functionalities or for a certain type of application or application layer functionality.

[0046] Furthermore, according to the present invention, it is advantageously possible and preferred that, during the fourth step, an authorization function or functionality queries or retrieves application flow information from the core network, in particular from its session management function, which is related to at least one credential information or is related to an application or application layer functionality or an application group or an application layer functionality group.

[0047] In particular, application flow information is used to indicate payload data related to application credentials (or application group credentials) within a data transmission session, while an application or application layer functionality of a user equipment uses at least one data transmission session to exchange payload data with a core network and / or a data network, or to transmit payload data to and / or receive payload data from the core network and / or the data network.

[0048] Thus, according to the present invention, it is advantageously possible to mark the payload data (or data traffic) of a corresponding application or application layer functionality (or a corresponding application group or application layer functionality group) within a data transmission session (i.e., typically within a PDU session).

[0049] Furthermore, the present invention relates to a user equipment for operating within a telecommunication network or as part of a telecommunication network, wherein the operation of the user equipment involves the operation of an application or application layer functionality of the user equipment.

[0050] The user equipment is configured to communicate with the telecommunication network or as part of the telecommunication network with its access network and core network, wherein the core network provides data connectivity towards a data network to the user equipment.

[0051] The operation of an application or application layer functionality of the user equipment requires establishing at least one data transmission session between the user equipment and the core network.

[0052] The user equipment includes or is assigned to or can access an application authorization function or functionality, wherein the application authorization function or functionality authorizes the application or application layer functionality to access the at least one data transmission session.

[0053] In order for an application or application layer functionality to use the at least one data transmission session to exchange payload data with the core network and / or the data network or to connect to the core network and / or the data network, the user equipment is configured such that:

[0054] - The application or application layer functionality transmits an application access request message to the application authorization function or functionality, the application access request message including at least one piece of credential information related to the application or application layer functionality.

[0055] - In a case where the application authorization function or functionality determines that the application access request message is valid, the application or application layer functionality receives an application access grant message from the application authorization function or functionality.

[0056] Furthermore, the present invention relates to a system or telecommunication network for operating a user equipment within a telecommunication network or as part of a telecommunication network, wherein the operation of the user equipment involves the operation of an application or application layer functionality of the user equipment.

[0057] wherein the telecommunications network comprises or is associated with or assigned to an access network and a core network, wherein the core network provides data connectivity towards a data network to the user equipment,

[0058] wherein the operation of an application or application layer functionality of the user equipment requires establishing at least one data transfer session between the user equipment and the core network,

[0059] wherein the user equipment comprises or is assigned to or is capable of accessing an application authorization function or functionality, wherein the application authorization function or functionality authorizes the application or application layer functionality to access the at least one data transfer session,

[0060] wherein, in order for an application or application layer functionality to use the at least one data transfer session to exchange payload data with and / or connect to the core network and / or the data network, the system or telecommunications network is configured such that:

[0061] -- the application authorization function or functionality receives an application access request message from the application or application layer functionality, the application access request message comprising at least one credential information related to the application or application layer functionality,

[0062] -- in a case where the application authorization function or functionality determines that the application access request message is valid, the application authorization function or functionality transmits an application access grant message to the application or application layer functionality.

[0063] Additionally, the present invention relates to an application authorization function or functionality of the system or telecommunications network of the present invention.

[0064] Additionally, the present invention also relates to a program comprising computer-readable program code and / or a computer-readable medium comprising instructions, which when executed on a computer and / or on the user equipment and / or on the application authorization function or functionality and / or on a network node of the telecommunications network, or partially on the user equipment and / or partially on the application authorization function or functionality and / or partially on a network node of the telecommunications network, cause the computer and / or the user equipment and / or the application authorization function or functionality and / or the network node of the telecommunications network to execute the method of the present invention.

[0065] These and other features, characteristics and advantages of the present invention will become apparent in the following detailed description in conjunction with the drawings, in which the principles of the present invention are shown by way of example. This specification is for illustrative purposes only and does not limit the scope of the present invention. Reference is made to the accompanying drawings by reference numerals cited below.

[0066] Brief Description of the Drawings

[0067] Figure 1A telecommunications network including an access network, a core network, and a user equipment is schematically shown, where a data network is part of the telecommunications network, or is connected to or accessible by the telecommunications network, and where the user equipment includes or provides an application authorization function or functionality for authorizing access by an application or application layer functionality of the user equipment to a data transmission session between the user equipment and the core network or towards the data network.

[0068] Figure 2 A user equipment, an application or application layer functionality of the user equipment, an access network, a core network, and a data network according to the present invention are schematically illustrated, where two possible implementations regarding the positioning or association of an application authorization function or functionality according to the present invention are shown.

[0069] Figures 3 to 5 A communication diagram between an application, a user equipment, a core network, and a data network according to the present invention is schematically illustrated.

[0070] Detailed Description

[0071] The present invention will be described with respect to specific embodiments and with reference to certain drawings, but the present invention is not limited thereto and is only defined by the claims. The described drawings are merely schematic and not restrictive. In the drawings, for illustrative purposes, the sizes of some of the elements may be enlarged and not drawn to scale.

[0072] The indefinite or definite article is used when referring to a singular noun, e.g., "a", "an", "the" includes the plural form of the noun unless otherwise specified.

[0073] Furthermore, the terms first, second, third, etc. in the description and claims are used to distinguish between similar elements and not necessarily to describe an order or temporal sequence. It should be understood that the terms so used are interchangeable under appropriate circumstances, and the embodiments of the present invention described herein are capable of operating in an order different from that described or illustrated herein.

[0074] In Figure 1 a telecommunications network 100 including an access network 110 and a core network 120 is schematically shown. The access network 110 includes a plurality of radio cells 11, 12. Furthermore, the core network 120 is connected to a data network 130. The core network 120 provides data connectivity to a user equipment 20 towards the data network 130. In Figure 1In the exemplary situation or scenario shown, the first base station entity 111 generates or is associated with or spans the first radio cell 11, and the second base station entity 112 generates or is associated with or spans the second radio cell 12. The user equipment 20 is part of the telecommunication network 100 or is connected to the telecommunication network 100 via an air interface (or radio interface) with one of the base station entities (in the example shown, the first base station entity 111 or the second base station entity 112). The user equipment 20 has or includes an application 21 or application layer functionality 21, for example, an installed application or other program or program module. Additionally, in Figure 1 the exemplary embodiment shown, the user equipment 20 includes an application authorization function or functionality 25 for authorizing the application 21 or application layer functionality 21 to access Figure 1 a data transmission session not explicitly shown therein.

[0075] The core network 120 includes an authorization server function 121, a session management function 122, and a user plane function 123. The user equipment 20 is generally but not necessarily mobile, i.e., capable of moving relative to the (generally but not necessarily static) radio cells 11, 12 of the access network 110 or the corresponding base station entities 111, 112.

[0076] Generally in the context of the present invention, the authorization server function 121 provides authorization functionality; in particular, in the context of a telecommunication network according to the 5G standard, such authorization functionality can be provided by an access and mobility management function and / or by an authentication server function and / or by a unified data management: the authentication server function (AUSF) generally provides authentication functionality, the unified data management (UDM) has authorization data, and the access and mobility management function (AMF) generally provides actual authorization depending on these data.

[0077] According to the present invention - as in a conventionally known telecommunication network - logically, a data transmission session (or PDU session) is established between the user equipment 20 and the core network 120 (of course, also involving the access network 110), and has an associated (or defined) quality of service level, i.e., a number of quality of service flows can be included within the data transmission session.

[0078] In Figure 2In the figure, two representations or implementations according to the present invention are shown. Both representations or implementations show an application 21 or application layer functionality 21 of a user equipment 20, the user equipment 20, the access network 110, the core network 120 and the data network 130. Between the user equipment 20 and the core network 120, a PDU session or data transmission session 210 is schematically shown. The PDU session or data transmission session 210 is terminated (or anchored) in the core network 120 by means of a session anchor 123 or a PDU session anchor 123, in particular the user plane function 123 of the core network (in particular in the case of a 5G telecommunication network 100). The two implementations according to the present invention mainly involve the positioning or association of an application authorization function or functionality 25 - wherein the application authorization function or functionality 25 is integrated in the user equipment 20 or co-located with the user equipment 20 (in the case of a 5G telecommunication network 100). Figure 2 ), or the application authorization function or functionality 25 is integrated in the core network 120 or co-located with the core network 120 (in Figure 2 In both representations or implementations, the application authorization function or functionality 25 is exemplarily shown together with the session access control function or functionality 26. The session access control function or functionality 26 is provided in particular for supervising the decisions of the application authorization function or functionality 25 and in particular for triggering downlink data packets and uplink data packets to be marked or tagged.

[0079] Even in Figure 2 In (and still Figures 3 to 5 ) represents an application 21 or application layer functionality 21 that is separate from the user equipment 20, but it will be understood that the application 21 or application layer functionality 21 is implemented or integrated in the user equipment 20.

[0080] In the case where two different applications 21 or application layer functionality 21 (typically as part of the user equipment 20, i.e. installed on the user equipment 20 (e.g. as an application) or a native part of the user equipment 20 (e.g. as part of its operating system)) both use a given PDU session or data transfer session 210, according to the invention it is advantageously possible to:

[0081] -- restricting access to such PDU sessions or data transfer sessions 210 on a per-application basis and / or

[0082] -- Downlink data packets and / or uplink data packets are also marked or tagged on a per-application basis.

[0083] Both of these are not possible in conventionally known telecommunication networks.

[0084] In conventionally known telecommunications networks, credentials are used or can be used for:

[0085] --The user equipment obtains or is provided with access to a network or a telecommunications network

[0086] --and / or access to a given network slice

[0087] --and / or the establishment of a data transmission session (or PDU session).

[0088] This means that, mainly using 5G nomenclature, regarding access to the network (especially in the case of a public land mobile network), the user equipment subscription data (which is usually stored in the subscriber identity module of the user equipment, especially the USIM) is used to register in the network via the access and mobility management function. Regarding access to a given (network) slice, the 5G network may require authentication and provide / deny authorization for access to a specific (network) slice (especially in addition to the credentials regarding access to the network). In particular, for access to a given network slice and the establishment of a data transmission session (or PDU session), it is foreseeable that an external credential server (especially outside the core network) can be used. Regarding access to the network, this is also possible (e.g., in the case of a 5G-based private network, i.e., SNPN), however it is not usually used for public mobile networks (public land mobile networks) as defined by the 3GPP standard, and the credentials for granting access to the public land mobile network are stored in the USIM (physical UICC or in electronic form (e.g., eSIM)) in the user equipment. Other types of credentials can be stored elsewhere, but are ultimately used in the communication between the user equipment and the core network to grant access to, for example, a given slice and / or as part of the data transmission session (or PDU session) establishment procedure.

[0089] Furthermore, regarding conventionally known telecommunications networks, a common use of such PDU session authentication is that the PDU session is used to connect to a private data network (including or having been assigned a data network name DNN) to provide VPN-like data services (e.g., access to a corporate network), where the credentials used for PDU session establishment are not operator credentials, but third-party credentials from, for example, a company. Thus, a specific PDU session can be exclusively used for a given data connection and authenticated via dedicated credentials.

[0090] The current typical usage of PDU sessions in a mobile communication network (usually a telecommunications network according to the 4G standard) is that there are two PDU sessions present almost all (or most) of the time: a PDU session for Internet access (especially used by applications such as browsers, video streaming, etc. to connect to the Internet) and a PDU session for IP Multimedia Subsystem (IMS) access (especially used by a phone dialer - usually bundled as part of the operating system of a user equipment). The corresponding PDU session anchor (PSA, which is mainly played by the user plane function in a 5G network) can be different for each PDU session, or alternatively shared by more than one PDU session. A typical scenario used by enterprises is that a company virtual private network (VPN) replaces the Internet DNN, so "Internet access" is provided by the VPN (i.e., the company network), which also results in two PDU sessions.

[0091] Additionally, in a conventionally known telecommunication network, an application can access a PDU session (e.g., for common Internet DNN access) and additional PDU sessions that support specific services (such as edge features) on different network slices, for example. Such additional PDU sessions are also potentially shared by several applications. Further, in a conventionally known telecommunication network, there can be several PDU sessions that provide connectivity to the same DNN (e.g., to provide "normal", high-bandwidth, best-effort via a PDU session and, for example, via a separate network slice, implement a separate PDU session that also provides ultra-reliable low-latency communication URLLC support and additional features but may have limited bandwidth). Additionally, in a conventionally known telecommunication network, PDU sessions convey metadata related to the traffic being transmitted (or payload data packets) by tagging the data packets being transmitted with an identifier. For example, 3GPP TS 38.401 includes the PDU session protocol stack, i.e., the protocol structure for data sent via a PDU session, and 3GPP TS 38.415 shows how user-plane packets (between the access network and the core network) are marked as belonging to a specific QoS flow (as part of a PDU session). Additionally, in a GTP-U tunnel, the TEID mapping (tunnel endpoint identifier) and the quality of service flow identifier are also used as metadata for payload data packets and contain the traffic to a specific PDU session. Additionally, 3GPP TS 38.301 includes the user-plane stack between the user equipment and the access network (for the case of a telecommunication network (5G-NR) according to the 5G standard) and shows how the user equipment maps differentiated quality of service flows into the protocol stack that provides communication between the user equipment and the access network. On the reverse side (i.e., between the access network and the user equipment), the reverse process is performed: at the access network - user equipment interface, the quality of service flows are separated; the quality of service flow handling steps defined in 3GPP TS 37.324 typically work by adding an end marker control PDU that contains a QFI, which indicates the ID of the quality of service flow (3GPP TS23.501) to which the SDAP PDU belongs. As defined in 3GPP TS 37.324, "The SDAP entity at the UE uses the end marker control PDU to indicate that it stops mapping the SDAP SDUs of the QoS flow indicated by the QFI / PQFI to the DRB / SL-DRB on which the end marker control PDU is transmitted."

[0092] According to the present invention, there is provided a method for operating user equipment 20 within or as part of a telecommunications network 100. Generally, the operation of user equipment 20 involves the operation of an application 21 or application layer functionality 21 of the user equipment 20. Such an application 21 or application layer functionality 21 may in particular be an app or application installed on the user equipment 20 or the operating system of the user equipment 20 (i.e., the native part of the user equipment 20). Generally, the telecommunications network 100 includes or is associated with or assigned to an access network 110 and a core network 120, where the core network 120 provides data connectivity towards a data network 130 to the user equipment 20.

[0093] The operation of the application 21 or application layer functionality 21 of the user equipment 20 requires the establishment of at least one data transfer session 210 between the user equipment 20 and the core network 120 (via the access network 110). Generally, in reality, multiple data transfer sessions are typically established between the user equipment 20 and the core network 120 via the access network 110. This is also known from conventional telecommunications networks. According to the present invention, access to the considered data transfer session 210 (for the application 21 or application layer functionality 21) can be granted or permitted on a per-application basis, which is not possible in conventionally known telecommunications networks.

[0094] Therefore, according to the present invention, the user equipment 20 includes or is assigned to or can access an application authorization function or functionality 25. This application authorization function or functionality 25 authorizes the application 21 or application layer functionality 21 to access at least one (considered) data transfer session 210. In order for the application 21 or application layer functionality 21 to use at least one data transfer session 210 to exchange payload data with the core network 120 and / or the data network 130 (i.e., to send payload data to and / or receive payload data from the core network 120 and / or the data network 130, thus connecting to the core network 120 and / or the data network 130), the method includes first and second steps, namely: in the first step, the application 21 or application layer functionality 21 transmits an application access request message 201 to the application authorization function or functionality 25, the application access request message 201 including at least one piece of credential information 250 related to the application 21 or application layer functionality 21, and in the second step, in the case where the application authorization function or functionality 25 determines that the application access request message 201 is valid, the application authorization function or functionality 25 transmits an application access grant message 202 to the application 21 or application layer functionality 21.

[0095] Thus, in the telecommunications network 100 of the present invention, at least the application authorization function or functionality 25 according to the present invention is provided or present in (or accessible to) the user equipment 20. The application authorization function or functionality implements the Application Authorization Function (AAF), which authorizes applications 21 (or application layer functionality 21) such that they can access a given PDU session 210, i.e., at least one data transfer session 210 under consideration. In particular, furthermore, in the telecommunications network 100 of the present invention, the session access control function or functionality 26 is also provided or present in (or accessible to) the user equipment 20. The session access control function or functionality 26 implements the PDU Session Access Control Function (PDU-ACF), which supervises the decisions of the AAF and, in particular, accordingly marks (or tags) the traffic, especially the payload traffic.

[0096] According to a specific embodiment of the present invention, in particular, two scenarios are considered, namely the location of the AAF (or application authorization function or functionality) 25 within the user equipment 20 (see the upper part of Figure 2 and the location of the AAF (or application authorization function or functionality) 25 within the core network 120 (see the lower part of Figure 2 ). In both scenarios, the PDU-ACF (or session access control function or functionality) 26 is preferably placed within the user equipment 20 (after all, it does supervise access to a given PDU session or data transfer session 210). However, according to the present invention, preferably, (since the PDU-ACF functionality (session access control function or functionality) 26 will generally be placed in the user equipment 20), it is less beneficial to locate the AAF (application authorization function or functionality) 25 in the core network 120 than to place it at the user equipment 20.

[0097] Thus, according to an embodiment of the present invention, preferably, both the application (or application layer functionality) 21 and another application (or another application layer functionality) are operated. According to this embodiment, both the application 21 and another application are able to use the at least one data transfer session 210 established between the user equipment 20 and the core network 120 by means of a request to access (to exchange payload data with the core network 120 and / or the data network 130 or connect to the core network 120 and / or the data network 130), and this access is requested by means of an individual (or application-specific) application access request message (to the application authorization function or functionality 25), where the application access request message respectively includes at least one credential information (related to the application or another application).

[0098] In Figure 3Therein, a communication diagram between an application 21, a user equipment 20, a core network 120, and a data network 130 according to the present invention is schematically shown. In Figure 3 Therein, it is assumed that an application authorization function or functionality 25 is part of the user equipment 20, and a session access control function or functionality 26 is also part of the user equipment 20. In addition, the core network 120 includes an authorization server function 121, a session management function 122, and a user plane function 123.

[0099] In a first processing step 301, an application 21 or application layer functionality 21 sends a request to an application authorization function or functionality 25 to access a data transfer session 210 (or PDU session 210); the request includes an application access request message 201 or is the same as the application access request message 201, which in turn includes at least one piece of credential information 250, namely an application credential (related to the application 21 or application layer functionality 21). In a second processing step 302, the application authorization function or functionality 25 evaluates the credential information. In a third processing step 303 and a fourth processing step 304, the application authorization function or functionality 25 queries an authorization server function 121 regarding the received credential information and receives a result back from the authorization server function 121 as a return. In a fifth processing step 305 and a sixth processing step 306, the application authorization function or functionality 25 queries and / or retrieves application flow information from a session management function 122 (related to at least one piece of credential information 250, or related to the application 21 or application layer functionality 21 or a group of applications 21 or a group of application layer functionalities 21), and receives a result back from the session management function 122 as a return. In a seventh processing step 307, the session management function 122 transmits the application flow information to a data transfer session anchor (or PDU session anchor, PSA or user plane function) 123. In an eighth processing step 308, the application authorization function or functionality 25 sends a message to a session access control function or functionality 26 to establish access for the corresponding (requesting) application 21 or application layer functionality 21 to the PDU session or data transfer session 210. In a ninth processing step 309, the application authorization function or functionality grants access (to the data transfer session or PDU session 210 under consideration) to the application 21 or application layer functionality 21. In a tenth processing step 310, the application 21 or application layer functionality 21 (operably) sends data (payload data packets) to the session access control function or functionality 26, and in an eleventh processing step 311, the session access control function or functionality 26 marks (or tags) the data packets received from the application 21 or application layer functionality 21 such that within the data transfer session or PDU session 210, different applications can be distinguished, that is, the payload data transmitted using the data transfer session or PDU session 210 consists of different application flows. In a twelfth processing step, the session access control function or functionality 26 transmits the payload data (received from the application 21 or application layer functionality 21 in the tenth processing step 310) to the core network 120, particularly the user plane function 123 (acting as a data transfer session anchor (or PDU session anchor)). In a thirteenth processing step 313, this data is forwarded by the core network 120, particularly the user plane function 123, to the data network 130.

[0100] Thus, according to an embodiment of the present invention, there is a PDU-ACF (or session access control function or functionality) 26, and the PDU-ACF (or session access control function or functionality) 26 is responsible for supervising access to the PDU session or data transmission session 210 (e.g., when requesting a socket from the operating system of the user equipment 20, the application 21 or application layer functionality 21 needs to include credentials (at least one piece of credential information 250), and a socket object can be successfully created only when the access is granted by the lower layer), and thus, supervising the access of the application 21 or application layer functionality 21 to the data transmission session or PDU session 210, and additionally, the data flow within the corresponding PDU session 210 can be marked based on the originating application 21 or application layer functionality 21; thus, within the PDU session or data transmission session 210, different application flows (of the payload data related to different applications 21 or application layer functionalities 21 accessing the considered PDU session or data transmission session 210) can be distinguished (or classification is performed on these different data flows within the corresponding PDU session 210); according to the present invention, additionally, quality of service flows can be considered within the corresponding PDU session 210. Thus, according to the present invention, application (or application-specific) based flow classification can be complementarily used for quality of service marking. Subsequently, the core network 120 can use this information to (among other things):

[0101] -- Apply different priority rankings / traffic policies to traffic from a given application 21 or application layer functionality 21,

[0102] -- Apply different charging rules to different applications 21 or application layer functionalities 21,

[0103] -- Perform the above functionality without performing traffic or application deep packet inspection (DPI).

[0104] In Figure 4 a communication diagram between the application 21, user equipment 20, access network 110, core network 120, and data network 130 according to a preferred embodiment of the present invention is schematically shown. In Figure 4 it is assumed that the application authorization function or functionality 25 is part of the user equipment 20. In particular, the session access control function or functionality 26 is also part of the user equipment 20. Additionally, the core network 120 particularly includes components or functions such as an authorization server function 121, a session management function 122, and a user plane function 123; however, these functions or components are not specifically shown in Figure 4 .

[0105] Primarily, Figure 4Embodiments are shown that enable application (or application - specific) access control for a data transmission session or PDU session 21. In a first processing step 401, an application 21 or application layer functionality 21 sends a request to access the considered (or at least one) data transmission session 210 (or PDU session 210) to a user equipment 20, in particular to its application authorization function or functionality 25; the request includes an application access request message 201 or is identical to the application access request message 201 (in accordance with the first step of the method according to the invention), and includes at least one piece of credential information 250, i.e., an application credential. This processing step of "requesting access to the PDU session 210 (or data transmission session 210)" is conceived in its simplest form as an extension of the OS API such that when a communication socket is initialized, the application credential (or similar / analogous information, such as an authorization token) is added to the socket creation call. Internally, this socket call is mapped to a PDU session, for example, to a "common Internet DNN PDU session", but in this case, it will only return when the user equipment stack successfully executes a PDU session modification procedure. In a second processing step 402, the credential information is evaluated by the user equipment 20, in particular by the application authorization function or functionality 25. In a third processing step 403 and a fourth processing step 404, the user equipment 20 (in particular the application authorization function or functionality 25) queries the core network 120 (in particular the authorization server function 121) and / or an entity outside or external to the core network 120 (or another authorization server function) regarding the received credential information and receives a result back from the authorization server function 121; in the latter case (i.e., in the case of an entity external to the core network 120), the communication flows via the core network 120 to the authorization server function 121. The third and fourth processing steps 403, 404 particularly correspond to or implement the fourth step of the method according to the invention (after the first step and before the second step), i.e., the application authorization function or functionality 25 or the user equipment 20 queries the core network 120 regarding at least one piece of credential information 250, in particular to determine whether the application access request message 201 is valid.

[0106] In a fifth processing step 405, the user equipment 20 sets up the requested access to the PDU session or data transmission session 210 by the application 21 or the application layer functionality 21, and in a sixth processing step 406, based on the second step of the method according to the invention, access is granted by transmitting an application access grant message 202 from the user equipment 20 to the application 21 or the application layer functionality 21 (in the case where the application access request message 201 is determined to be valid). Of course, in the case where the application access request message 201 is determined to be invalid (in particular due to the lack, invalidity or non - correspondence of at least one credential information 250 with the application access request message 201 or the requesting application 21 or the application layer functionality 21), access to the considered PDU session or data transmission session 210 is not granted. In a seventh processing step 407, payload data (i.e., data traffic) between the application 21 or the application layer functionality 21 and the data network 130 is exchanged (operably) via the data transmission session or PDU session 210 (corresponding to the third step of the inventive method according to the invention (after the second step)).

[0107] Furthermore, according to the present invention, preferably, the present invention is implemented by means of an extension to the PDU session modification to allow application - based authentication / authorization. This is schematically shown in Figure 5 which Figure 5 again shows the communication diagram between the application 21, the user equipment 20, the access network 110, the core network 120 and the data network 130. Again in Figure 5 it is assumed that the application authorization function or functionality 25 is part of the user equipment 20. In particular, the session access control function or functionality 26 is also part of the user equipment 20. Furthermore, the core network 120 particularly includes components or functions such as an authorization server function 121, a session management function 122 and a user plane function 123; however, these functions or components are not specifically shown in Figure 5 which Figure 5 shows an embodiment of the present invention in which application - based authentication / authorization or access control (for the data transmission session or PDU session 21) is implemented by means of an extension to the PDU session modification.

[0108] In a first processing step 501, the user equipment 20 sends or transmits a PDU session establishment request (message) to the core network 120. In a second processing step 502, the core network 120 establishes a PDU session 210 (or a data transmission session 210). In a third processing step 503, the core network 120 sends or transmits a PDU session establishment acceptance (message) to the user equipment 20.

[0109] In a fourth processing step 504, the application 21 or the application layer functionality 21 sends a request to the user equipment 20, in particular to its application authorization function or functionality 25, for access to the considered (or at least one) data transfer session 210 (or PDU session 210); the request includes an application access request message 201 or is identical to the application access request message 201 (in accordance with the first step of the method according to the invention), and includes at least one credential information 250, i.e., an application credential. Again, this processing step can be implemented by means of an extension of the OS API (in particular by adding an application credential (or similar / analogous information such as an authorization token, or information derived from an application credential) to a socket creation call). In a fifth processing step 505, the user equipment 20 transmits a PDU session modification request (message) to the core network 120 (in particular including authorization information, i.e., at least one credential information 250). In a sixth processing step 506, the core network 120 transmits a PDU session modification acceptance (message) (or "PDU session modification accepted") to the user equipment 20, in particular including application access grant information. In a seventh processing step 507, based on the second step of the method according to the invention, an access grant is communicated to the application 21 or the application layer functionality 21 by means of the user equipment 20 transmitting an application access grant message 202 to the application 21 or the application layer functionality 21 (in the case where the application access request message 201 is determined to be valid). In an eighth processing step 508, payload data (i.e., data traffic) between the application 21 or the application layer functionality 21 and the data network 130 is exchanged (operably) via the data transfer session or PDU session 210 (corresponding to the third step of the inventive method according to the invention (after the second step)).

[0110] According to a preferred embodiment of the invention, the application authorization function or functionality 25 queries or retrieves (in particular during the fourth step of the method according to the invention) application flow information from the core network 120, in particular from its session management function 122, which is related to at least one credential information 250, or to the application 21 or the application layer functionality 21 or a group of applications 21 or a group of application layer functionalities 21, whereby, in particular, the application flow information can be used to indicate payload data related to application or application group credentials within the data transfer session 210, while the application 21 or the application layer functionality 21 of the user equipment 20 uses the at least one data transfer session 210 to exchange payload data with the core network 120 and / or the data network 130, or to transmit payload data to the core network 120 and / or the data network 130 and / or receive payload data from the core network 120 and / or the data network 130. Thus, by means of the application flow information, different applications 21 or application layer functionalities 21 (or different application groups or different application layer functionality groups) can be distinguished.

[0111] According to the present invention, it is preferably possible to implement an indication of additional capabilities, i.e., an indication regarding PDU session support for application-based authentication and / or packet marking, and an indication as to whether it is mandatory. Similarly, these capabilities can be added to the PDU establishment request (e.g., the user equipment 20 requests the existence of such capabilities in the provided PDU session / data transfer session 210). Such an indication is preferably transmitted, sent, and / or received during the first and third processing steps 501, 503 according to Figure 5 That is, the PDU session establishment request (message) (the first processing step 501) includes an additional capability indication or a corresponding information segment indicating such additional capabilities, and the PDU session establishment acceptance (message) (the third processing step 503) includes an indication or a corresponding information segment indicating such additional capabilities.

[0112] Furthermore, according to the present invention, it is preferably possible to implement awareness of the access network 110. In a 5G network, the radio access network 110 is aware of the PDU session and its associated QoS flows. For example, the gNB (i.e., the base station entity) uses this information to direct scheduling. According to the present invention, by extending the PDU session framework to the application (or the application layer functionality of the user equipment), the radio access network 110 preferably becomes aware of the application flow information (especially in addition to being aware of the network slice used and / or the PDU session used and / or the quality of service level assigned to each data flow), and advantageously can use the application flow information to:

[0113] -- direct scheduling, and / or

[0114] -- direct the activation of specific radio access network features on a per-application basis (e.g., L4S marking, e.g., for latency-critical applications), and / or

[0115] -- based on the application flow, the core network 120 can instruct the access network 110 to apply certain policies / features / mobility restrictions / priorities, etc. to the traffic (payload data) regarding a certain application or a certain group of applications.

[0116] In certain embodiments of the present invention, further preferably, the credential information 250 relates to two or more applications 21 or application layer functionalities 21, in particular a group of applications 21 or application layer functionalities 21. This means that these two or more applications 21 or application layer functionalities 21 share or use the same credential information. Additionally or alternatively, in certain embodiments of the present invention, further preferably, at least one piece of credential information 250 is valid for two or more data transfer sessions 210 - that is, according to the present invention (according to one extreme case), an application 21 or an application layer functionality 21 may have or use specific credential information 250 (different from the credential information used by other applications or application layer functionalities) and / or an application 21 or an application layer functionality 21 may have or use different credential information 250 for different data transfer sessions or PDU sessions 210; and (according to another extreme case) multiple applications 21 or multiple application layer functionalities 21 (or a group of applications 21 or a group of application layer functionalities 21) have or use shared credential information 250 (but different from the credential information of other applications or application layer functionalities) and / or multiple applications 21 or multiple application layer functionalities 21 have or use shared credential information 250 for different data transfer sessions or PDU sessions 210.

Claims

1. A method for operating user equipment (20) within a telecommunication network (100) or as part of a telecommunication network (100), wherein the operation of the user equipment (20) includes the operation of an application or application layer function (21) of the user equipment (20), wherein the telecommunication network (100) includes or is associated with or assigned to an access network (110) and a core network (120), wherein the core network (120) provides data connectivity towards a data network (130) to the user equipment (20), wherein the operation of the application or application layer function (21) of the user equipment (20) requires the establishment of at least one data transfer session (210) between the user equipment (20) and the core network (120), wherein the at least one data transfer session (210) is a PDU session (210), i.e., a protocol data unit session, wherein the user equipment (20) or the core network (120) includes an application authorization function (25), wherein the application authorization function (25) authorizes the application or application layer function (21) to access the at least one data transfer session (210), wherein, in order for the application or application layer function (21) to use the at least one data transfer session (210) to exchange payload data with the core network (120) and / or the data network (130) or to connect to the core network (120) and / or the data network (130), the method comprises the following steps: -- In a first step, the application or application layer function (21) transmits an application access request message (201) to the application authorization function (25), the application access request message (201) including at least one credential information (250) related to the application or application layer function (21), -- In a second step, in the case where the application authorization function (25) determines that the application access request message (201) is valid, the application authorization function (25) transmits an application access grant message (202) to the application or application layer function (21), such that the access of the application or application layer function (21) to the at least one data transfer session (210) is only allowed in the case where the application access request message (201) is determined to be valid, and wherein the access is not allowed in the case where the application access request message (201) is determined to be invalid, wherein the user equipment (20) includes a session access control function (26), and the session access control function (26) supervises the access of the application or application layer function (21) to the at least one data transfer session (210) according to the decision of the application authorization function (25).

2. The method according to claim 1, wherein the operation of the user equipment (20) further includes the operation of additional applications or additional application layer functions of the user equipment (20), The operation of the additional application or the additional application layer function of the user equipment (20) also uses the at least one data transfer session (210) established between the user equipment (20) and the core network (120). Wherein, In order for the additional application or the additional application layer function to use the at least one data transfer session (210) to exchange payload data with the core network (120) and / or the data network (130) or connect to the core network (120) and / or the data network (130): the additional application or the additional application layer function transmits an additional application access request message to the application authorization function (25), the additional application access request message including at least one additional credential information related to the additional application or the additional application layer function, and in the case where the application authorization function (25) determines that the additional application access request message is valid, the application authorization function (25) transmits an additional application access grant message to the additional application or the additional application layer function.

3. The method according to claim 1, wherein the at least one credential information (250) includes a certificate or certificate information and / or token information, and / or wherein the application access request message (201), the at least one credential information (250), and the application access grant message (202) are application-specific or application-group-specific respectively.

4. The method according to claim 1, wherein the credential information relates to two or more applications or application layer functions (21).

5. The method according to claim 4, wherein the credential information relates to a group of applications or application layer functions (21).

6. The method according to claim 1, wherein the at least one credential information (250) is valid for two or more data transfer sessions (210).

7. The method according to claim 1, wherein in a third step after the second step, the application or application layer function (21) of the user equipment (20) uses the at least one data transfer session (210) to exchange payload data with the core network (120) and / or the data network (130), or transmits payload data to the core network (120) and / or the data network (130) and / or receives payload data from the core network (120) and / or the data network (130).

8. The method according to claim 1, wherein in a fourth step after the first step and before the second step, the application authorization function (25) queries the core network (120) regarding the at least one credential information (250) to determine whether the application access request message (201) is valid.

9. The method according to claim 8, wherein in the fourth step, the application authorization function (25) queries the authorization server function (121) of the core network (120) with respect to the at least one credential information (250) to determine whether the application access request message (201) is valid.

10. The method according to claim 8, wherein the fourth step involves, after the PDU session (210) has been established or generated, the user equipment (20) exchanging a PDU session modification message with the core network (120), wherein, the establishment or generation or subsequent modification of the PDU session (210) includes an indication of capabilities related to the handling of the application access request message and the application access grant message and / or the necessity to use or handle the application access request message and the application access grant message.

11. The method according to claim 9, wherein the fourth step involves, after the PDU session (210) has been established or generated, the user equipment (20) exchanging a PDU session modification message with the authorization server function (121) of the core network (120), wherein, the establishment or generation or subsequent modification of the PDU session (210) includes an indication of capabilities related to the handling of the application access request message and the application access grant message and / or the necessity to use or handle the application access request message and the application access grant message.

12. The method according to claim 8, wherein during the fourth step, the application authorization function (25) queries or retrieves from the core network (120) application flow information related to the at least one credential information (250) or related to the application or application layer function (21) or the group of applications or the group of application layer functions, wherein, the application flow information is used to indicate payload data related to the application or application group credentials within the data transmission session (210), while the application or application layer function (21) of the user equipment (20) uses the at least one data transmission session (210) to exchange payload data with the core network (120) and / or the data network (130), or to transmit payload data to and / or receive payload data from the core network (120) and / or the data network (130).

13. The method according to claim 12, wherein during the fourth step, the application authorization function (25) queries or retrieves from the session management function (122) of the core network (120) application flow information related to the at least one credential information (250) or related to the application or application layer function (21) or the group of applications or the group of application layer functions.

14. A user equipment (20) for operating within a telecommunications network (100) or as part of a telecommunications network (100), wherein the operation of the user equipment (20) includes the operation of an application or application layer function (21) of the user equipment (20). The user equipment (20) is configured to communicate with the telecommunications network (100) or, as part of the telecommunications network (100), with its access network (110) and core network (120), wherein the core network (120) provides data connectivity towards a data network (130) to the user equipment (20). The operation of the application or application layer function (21) of the user equipment (20) requires the establishment of at least one data transfer session (210) between the user equipment (20) and the core network (120), wherein the at least one data transfer session (210) is a PDU session (210), i.e., a protocol data unit session. The user equipment (20) includes an application authorization function (25), wherein the application authorization function (25) authorizes the application or application layer function (21) to access the at least one data transfer session (210). Wherein, In order for the application or application layer function (21) to use the at least one data transfer session (210) to exchange payload data with the core network (120) and / or the data network (130) or to connect to the core network (120) and / or the data network (130), the user equipment (20) is configured such that: -- The application or application layer function (21) transmits an application access request message (201) to the application authorization function (25), the application access request message (201) including at least one credential information (250) related to the application or application layer function (21). -- In the case where the application authorization function (25) determines that the application access request message (201) is valid, the application or application layer function (21) receives an application access grant message (202) from the application authorization function (25), such that the access of the application or application layer function (21) to the at least one data transfer session (210) is only permitted in the case where the application access request message (201) is determined to be valid, and wherein access is not permitted in the case where the application access request message (201) is determined to be invalid. The user equipment (20) includes a session access control function (26), the session access control function (26) being configured to monitor the access of the application or application layer function (21) to the at least one data transfer session (210) according to the decision of the application authorization function (25).

15. A telecommunications network (100) for operating a user equipment (20) within a telecommunications network (100) or as part of a telecommunications network (100), wherein the operation of the user equipment (20) includes the operation of an application or application layer function (21) of the user equipment (20). The telecommunications network (100) includes or is associated with or assigned to an access network (110), and the telecommunications network (100) includes a core network (120), where the core network (120) provides data connectivity to a data network (130) for the user equipment (20). The operation of the application or application layer function (21) of the user equipment (20) requires the establishment of at least one data transmission session (210) between the user equipment (20) and the core network (120), and the at least one data transmission session (210) is a PDU session (210), i.e., a protocol data unit session. The core network (120) includes an application authorization function (25), and the application authorization function (25) authorizes the application or application layer function (21) to access the at least one data transmission session (210). Wherein,[ In order for the application or application layer function (21) to use the at least one data transmission session (210) to exchange payload data with the core network (120) and / or the data network (130) or connect to the core network (120) and / or the data network (130), the telecommunications network (100) is configured such that: - The application authorization function (25) receives an application access request message (201) from the application or application layer function (21), and the application access request message (201) includes at least one piece of credential information (250) related to the application or application layer function (21). - In the case where the application authorization function (25) determines that the application access request message (201) is valid, the application authorization function (25) transmits an application access grant message (202) to the application or application layer function (21), such that the access of the application or application layer function (21) to the at least one data transmission session (210) is only allowed when the application access request message (201) is determined to be valid, and access is not allowed when the application access request message (201) is determined to be invalid. The user equipment (20) includes a session access control function (26), and the session access control function (26) is configured to supervise the access of the application or application layer function (21) to the at least one data transmission session (210) according to the decision of the application authorization function (25).

16. A program comprising computer-readable program code which, when executed on a computer, and / or on user equipment (20), and / or on an application authorization function (25), and / or on a network node of a telecommunication network (100), or partly on the user equipment (20), and / or partly on the application authorization function (25), and / or partly on a network node of the telecommunication network (100), causes the computer and / or the user equipment (20) and / or the application authorization function (25) and / or the network node of the telecommunication network (100) to perform the method according to any one of claims 1 to 13.

17. A computer-readable medium comprising instructions which, when executed on a computer, and / or on user equipment (20), and / or on an application authorization function (25), and / or on a network node of a telecommunication network (100), or partly on the user equipment (20), and / or partly on the application authorization function (25), and / or partly on a network node of the telecommunication network (100), causes the computer and / or the user equipment (20) and / or the application authorization function (25) and / or the network node of the telecommunication network (100) to perform the method according to any one of claims 1 to 13.

Citation Information

Patent Citations

  • Accessing a mobile communication network using a user identifier

    WO2021069067A1