Method for secure configuration and provisioning of user equipment policies
By using the policy message authentication code and policy protection counter during the UE configuration update process, the risk of URSP rules being tampered with when UE policy provision is provided in roaming scenarios is solved, the integrity and security verification of policy information is achieved, and the reliability of policy control in 5GS is enhanced.
Patent Information
- Application Number
- CN202380069224.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-09-27
- Filing Date
- 2023-09-14
- Publication Date
- 2025-05-06
AI Technical Summary
The prior art has the potential risk that URSP rules are unintentionally or maliciously modified by VPLMN when UE policies are provided in roaming scenarios, and there is a lack of verification mechanism to ensure that the URSP rules associated with HPLMN have not been tampered with.
A security mechanism is introduced to transparently deliver UE policy information during the UE configuration update process, verify the integrity of the policy information by using the policy message authentication code (P-MAC-N) and the policy protection counter (PPC), and ensure the security of the UE policy information during the transmission process.
It effectively prevents URSP rules from being unintentionally or maliciously modified in the roaming environment, ensures the integrity and security of policy information received by the UE, and enhances the reliability of HPLMN-based policy control in 5GS.
Smart Images

Figure CN119948807A_ABST
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims the benefit of U.S. Provisional Patent Application No. 63 / 410,539, filed on September 27, 2022, the entire contents of which are incorporated herein by reference. BRIEF DESCRIPTION OF THE DRAWINGS
[0003] A more detailed understanding can be obtained from the detailed description given below in conjunction with the accompanying drawings by way of example. Similar to the detailed description, the figures in these drawings are examples. Therefore, the drawings (FIG.) and detailed description should not be considered limiting, and other equally effective examples are possible and likely. In addition, the same reference numerals ("ref.") in the figures represent the same elements, and among them:
[0004] Figure 1A is a system diagram illustrating an example communication system;
[0005] Figure 1B It shows that it can be Figure 1A A system diagram of an example wireless transmit / receive unit (WTRU) for use within the communication system is shown;
[0006] Figure 1C It shows that it can be Figure 1A A system diagram of an example radio access network (RAN) and an example core network (CN) used within a communication system shown in FIG.
[0007] Figure 1D It shows that it can be Figure 1A A system diagram of another example RAN and another example CN used within the illustrated communication system;
[0008] Figure 2 is a signal diagram depicting an example method according to aspects of the present disclosure;
[0009] Figure 3 An example method performed by a wireless transmit / receive unit (WTRU) according to aspects of the present disclosure is depicted; and
[0010] Figure 4 An example method performed by a network node according to aspects of the present disclosure is depicted. DETAILED DESCRIPTION
[0011] In the following detailed description, many specific details are set forth to provide a thorough understanding of the embodiments and / or examples disclosed herein. However, it should be understood that such embodiments and examples can be practiced without some or all of the specific details set forth herein. In other cases, well-known methods, processes, components and circuits are not described in detail to avoid blurring the following description. In addition, the embodiments and examples not specifically described herein can be practiced in place of or in conjunction with the embodiments and other examples explicitly, implicitly and / or inherently (collectively referred to as "provided") described, disclosed or otherwise provided herein. Although various embodiments are described and / or claimed herein, wherein devices, systems, equipment, etc. and / or any of their elements perform operations, processes, algorithms, functions, etc. and / or any part thereof, it should be understood that any embodiments described and / or claimed herein assume that any device, system, equipment, etc. and / or any of its elements are configured to perform any operations, processes, algorithms, functions, etc. and / or any part thereof.
[0012] Example Communication System
[0013] The methods, devices, and systems provided herein are well suited for communications involving wired and wireless networks. Figures 1A to 1D An overview of various types of wireless devices and infrastructure is provided in which various elements of the network can utilize, perform, be arranged according to, and / or be adapted and / or configured for the methods, apparatus, and systems provided herein.
[0014] Figure 1A 1 is a system diagram illustrating an example communication system 100 in which one or more disclosed embodiments may be implemented. The communication system 100 may be a multiple access system that provides content such as voice, data, video, messaging, broadcast, etc. to multiple wireless users. The communication system 100 may enable multiple wireless users to access such content by sharing system resources (including wireless bandwidth). For example, the communication system 100 may employ one or more channel access methods, such as code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), single carrier FDMA (SC-FDMA), zero tail (ZT) unique word (UW) discrete Fourier transform (DFT) spread OFDM (ZT UW DTS-s OFDM), unique word OFDM (UW-OFDM), resource block filtered OFDM, filter bank multi-carrier (FBMC), etc.
[0015] like Figure 1AAs shown, the communication system 100 may include wireless transmit / receive units (WTRUs) 102a, 102b, 102c, 102d, a radio access network (RAN) 104 / 113, a core network (CN) 106 / 115, a public switched telephone network (PSTN) 108, the Internet 110, and other networks 112, but it should be appreciated that the disclosed embodiments contemplate any number of WTRUs, base stations, networks, and / or network elements. Each of the WTRUs 102a, 102b, 102c, 102d may be any type of device configured to operate and / or communicate in a wireless environment. By way of example, the WTRUs 102a, 102b, 102c, 102d (any of which may be referred to as a "station" and / or "STA") may be configured to transmit and / or receive wireless signals, and may include (or be) a user equipment (UE), a mobile station, a fixed or mobile subscriber unit, a subscription-based unit, a pager, a cellular phone, a personal digital assistant (PDA), a smart phone, a laptop, a netbook, a personal computer, a wireless sensor, a hotspot or Mi-Fi device, an Internet of Things (IoT) device, a watch or other wearable device, a head-mounted display (HMD), a vehicle, a drone, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in an industrial and / or automated process chain environment), a consumer electronic device, a device operating on a commercial and / or industrial wireless network, etc. Any of the WTRUs 102a, 102b, 102c, and 102d may be interchangeably referred to as a UE.
[0016] The communication system 100 may also include a base station 114a and / or a base station 114b. Each of the base stations 114a, 114b may be any type of device configured to wirelessly interface with at least one of the WTRUs 102a, 102b, 102c, 102d, for example, to facilitate access to one or more communication networks, such as the CN 106 / 115, the Internet 110, and / or the network 112. By way of example, the base stations 114a, 114b may be any one of a base transceiver station (BTS), a Node B (NB), an eNode-B (eNB), a Home Node-B (HNB), a Home eNode-B (HeNB), a gNode-B (gNB), an NR Node-B (NR NB), a site controller, an access point (AP), a wireless router, and the like. Although each of the base stations 114a, 114b is depicted as a single element, it should be appreciated that the base stations 114a, 114b may include any number of interconnected base stations and / or network elements.
[0017] The base station 114a may be part of the RAN 104 / 113, which may also include other base stations and / or network elements (not shown), such as a base station controller (BSC), a radio network controller (RNC), a relay node, etc. The base station 114a and / or the base station 114b may be configured to transmit and / or receive wireless signals on one or more carrier frequencies, which may be referred to as a cell (not shown). These frequencies may be in a licensed spectrum, an unlicensed spectrum, or a combination of a licensed spectrum and an unlicensed spectrum. A cell may provide coverage for wireless services to a specific geographic area, which may be relatively fixed or may change over time. The cell may be further divided into cell sectors. For example, a cell associated with the base station 114a may be divided into three sectors. Thus, in an embodiment, the base station 114a may include three transceivers, that is, each transceiver corresponds to a sector of the cell. In an embodiment, the base station 114a may use multiple-input multiple-output (MIMO) technology, and may use multiple transceivers for each sector or any sector of the cell. For example, beamforming may be used to transmit and / or receive signals in a desired spatial direction.
[0018] The base stations 114a, 114b may communicate with one or more of the WTRUs 102a, 102b, 102c, 102d over an air interface 116, which may be any suitable wireless communication link (e.g., radio frequency (RF), microwave, centimeter wave, micrometer wave, infrared (IR), ultraviolet (UV), visible light, etc.). The air interface 116 may be established using any suitable radio access technology (RAT).
[0019] More specifically, as described above, the communication system 100 may be a multiple access system and may employ one or more channel access schemes such as CDMA, TDMA, FDMA, OFDMA, SC-FDMA, etc. For example, the base station 114a in the RAN 104 / 113 and the WTRUs 102a, 102b, 102c may implement a radio technology such as Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (UTRA), which may use Wideband CDMA (WCDMA) to establish the air interface 116. WCDMA may include communication protocols such as High Speed Packet Access (HSPA) and / or Evolved HSPA (HSPA+). HSPA may include High Speed Downlink Packet Access (HSDPA) and / or High Speed Uplink Packet Access (HSUPA).
[0020] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as Evolved UMTS Terrestrial Radio Access (E-UTRA), which may establish the air interface 116 using Long Term Evolution (LTE) and / or LTE-Advanced (LTE-A) and / or LTE-Advanced Pro (LTE-A Pro).
[0021] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as NR radio access, which may establish the air interface 116 using New Radio (NR).
[0022] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement multiple radio access technologies. For example, the base station 114a and the WTRUs 102a, 102b, 102c may together implement LTE radio access and NR radio access, for example using dual connectivity (DC) principles. Thus, the air interface used by the WTRUs 102a, 102b, 102c may be characterized by multiple types of radio access technologies and / or transmissions sent to / from multiple types of base stations (e.g., eNBs and gNBs).
[0023] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as IEEE 802.11 (i.e., Wireless Fidelity (Wi-Fi)), IEEE 802.16 (i.e., Worldwide Interoperability for Microwave Access (WiMAX)), CDMA2000, CDMA 2000 1X, CDMA 2000 EV-DO, Interim Standard 2000 (IS-2000), Interim Standard 95 (IS-95), Interim Standard 856 (IS-856), Global System for Mobile Communications (GSM), GSM Enhanced Data Rates for Evolution (EDGE), GSM EDGE (GERAN), and the like.
[0024] As an example, Figure 1AThe base station 114b in the example may be a wireless router, a home Node-B, a home eNode-B, or an access point, and may use any appropriate RAT to facilitate wireless connectivity in a local area, such as a business location, a residence, a vehicle, a campus, an industrial facility, an air corridor (e.g., for use by drones), a road, and the like. In an embodiment, the base station 114b and the WTRUs 102c, 102d may establish a wireless local area network (WLAN) by implementing a radio technology such as IEEE 802.11. In an embodiment, the base station 114b and the WTRUs 102c, 102d may establish a wireless personal area network (WPAN) by implementing a radio technology such as IEEE 802.15. In an embodiment, the base station 114b and the WTRUs 102c, 102d may establish any of a small cell, a pico cell, or a femto cell by using a cellular-based RAT (e.g., WCDMA, CDMA2000, GSM, LTE, LTE-A, LTE-A Pro, NR, and the like). As Figure 1A As shown, the base station 114b may have a direct connection to the Internet 110. Thus, the base station 114b may not need to access the Internet 110 via the CN 106 / 115.
[0025] The RAN 104 / 113 may be in communication with the CN 106 / 115, which may be any type of network configured to provide voice, data, applications, and / or Voice over Internet Protocol (VoIP) services to one or more of the WTRUs 102a, 102b, 102c, 102d. Data may have varying quality of service (QoS) requirements, such as different throughput requirements, latency requirements, fault tolerance requirements, reliability requirements, data throughput requirements, mobility requirements, etc. The CN 106 / 115 may provide call control, billing services, mobile location-based services, pre-paid calls, Internet connectivity, video distribution, etc., and / or perform advanced security functions, such as user authentication. Although in Figure 1A Although not shown, it will be appreciated that the RAN 104 / 113 and / or the CN 106 / 115 may be in direct or indirect communication with other RANs that employ the same RAT or a different RAT as the RAN 104 / 113. For example, in addition to being connected to the RAN 104 / 113, which may employ NR radio technology, the CN 106 / 115 may also be in communication with another RAN (not shown) employing any of GSM, UMTS, CDMA 2000, WiMAX, E-UTRA, or Wi-Fi radio technologies.
[0026] The CN 106 / 115 may also serve as a gateway for the WTRUs 102a, 102b, 102c, 102d to access the PSTN 108, the Internet 110, and / or other networks 112. The PSTN 108 may include a circuit-switched telephone network that provides plain old telephone service (POTS). The Internet 110 may include a global system of interconnected computer networks and devices that use common communication protocols, such as the Transmission Control Protocol (TCP), the User Datagram Protocol (UDP), and / or the Internet Protocol (IP) in the TCP / IP Internet protocol suite. The networks 112 may include wired and / or wireless communication networks owned and / or operated by other service providers. For example, the networks 112 may include another CN connected to one or more RANs, which may employ the same RAT as the RAN 104 / 114 or a different RAT.
[0027] Some or all of the WTRUs 102a, 102b, 102c, 102d in the communication system 100 may include multi-mode capabilities (e.g., the WTRUs 102a, 102b, 102c, 102d may include multiple transceivers for communicating with different wireless networks via different wireless links). Figure 1A The illustrated WTRU 102c may be configured to communicate with the base station 114a utilizing a cellular-based radio technology, and with the base station 114b utilizing an IEEE 802 radio technology.
[0028] Figure 1B is a system diagram showing an example WTRU 102. Figure 1B As shown, the WTRU 102 may include, among other things, a processor 118, a transceiver 120, a transmit / receive element 122, a speaker / microphone 124, a keyboard 126, a display / touchpad 128, non-removable memory 130, removable memory 132, a power source 134, a global positioning system (GPS) chipset 136, and / or other components / peripherals 138. It will be appreciated that the WTRU 102 may include any sub-combination of the foregoing elements while remaining consistent with an embodiment.
[0029] The processor 118 may be a general purpose processor, a special purpose processor, a conventional processor, a digital signal processor (DSP), a plurality of microprocessors, one or more microprocessors associated with a DSP core, a controller, a microcontroller, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), any other type of integrated circuit (IC), a state machine, etc. The processor 118 may perform signal coding, data processing, power control, input / output processing, and / or any other functionality that enables the WTRU 102 to operate in a wireless environment. The processor 118 may be coupled to the transceiver 120, which may be coupled to the transmit / receive element 122. Although Figure 1B The processor 118 and the transceiver 120 are depicted as separate components, but it will be appreciated that the processor 118 and the transceiver 120 may be integrated together, such as in an electronic package or chip.
[0030] The transmit / receive element 122 may be configured to transmit or receive signals to or from a base station (e.g., base station 114a) via the air interface 116. For example, in an embodiment, the transmit / receive element 122 may be an antenna configured to transmit and / or receive RF signals. In an embodiment, the transmit / receive element 122 may be an emitter / detector configured to transmit and / or receive IR. UV or visible light signals. In an embodiment, the transmit / receive element 122 may be configured to transmit and / or receive both RF and light signals. It should be understood that the transmit / receive element 122 may be configured to transmit and / or receive any combination of wireless signals.
[0031] Although the transmit / receive element 122 is Figure 1B Although depicted as a single element in the figure, the WTRU 102 may include any number of transmit / receive elements 122. For example, the WTRU 102 may employ MIMO technology. Thus, in an embodiment, the WTRU 102 may include two or more transmit / receive elements 122 (e.g., multiple antennas) for transmitting and receiving wireless signals over the air interface 116.
[0032] The transceiver 120 may be configured to modulate signals to be transmitted by the transmit / receive element 122 and to demodulate signals received by the transmit / receive element 122. As described above, the WTRU 102 may have multi-mode capabilities. Thus, the transceiver 120 may include multiple transceivers to enable the WTRU 102 to communicate via multiple RATs (e.g., NR and IEEE 802.11).
[0033] The processor 118 of the WTRU 102 may be coupled to a speaker / microphone 124, a keyboard 126, and / or a display / touchpad 128 (e.g., a liquid crystal display (LCD) display unit or an organic light emitting diode (OLED) display unit), and may receive user input data from these components. The processor 118 may also output user data to the speaker / microphone 124, the keyboard 126, and / or the display / touchpad 128. In addition, the processor 118 may access information from and store data in any type of suitable memory, such as a non-removable memory 130 and / or a removable memory 132. The non-removable memory 130 may include a random access memory (RAM), a read-only memory (ROM), a hard disk, or any other type of memory storage device. The removable memory 132 may include a subscriber identity module (SIM) card, a memory stick, a secure digital (SD) memory card, and the like. In other embodiments, the processor 118 may access information from and store data in memories that are not physically located on the WTRU 102, such as on a server or a home computer (not shown).
[0034] The processor 118 may receive power from the power source 134 and may be configured to distribute the power to and / or control other components in the WTRU 102. The power source 134 may be any suitable device for powering the WTRU 102. For example, the power source 134 may include one or more dry cell batteries (e.g., nickel-cadmium (NiCd), nickel-zinc (NiZn), nickel-metal hydride (NiMH), lithium-ion (Li-ion), etc.), solar cells, fuel cells, etc.
[0035] The processor 118 may also be coupled to the GPS chipset 136, which may be configured to provide location information (e.g., longitude and latitude) regarding the current location of the WTRU 102. In addition to or in lieu of the information from the GPS chipset 136, the WTRU 102 may receive location information from a base station (e.g., base stations 114a, 114b) over the air interface 116 and / or determine its location based on the timing of signals received from two or more nearby base stations. It should be appreciated that the WTRU 102 may acquire location information via any suitable location-determination method while remaining consistent with an embodiment.
[0036] The processor 118 may also be coupled to other components / peripherals 138, which may include one or more software and / or hardware modules / units that provide additional features, functionality, and / or wired or wireless connectivity. For example, the components / peripherals 138 may include an accelerometer, an electronic compass, a satellite transceiver, a digital camera (e.g., for photos and / or videos), a universal serial bus (USB) port, a vibration device, a television transceiver, a hands-free headset, a Bluetooth® module, a frequency modulation (FM) radio unit, a digital music player, a media player, a video game console module, an Internet browser, a virtual reality and / or augmented reality (VR / AR) device, an activity tracker, etc. The components / peripherals 138 may include one or more sensors, which may be one or more of a gyroscope, an accelerometer, a Hall effect sensor, a magnetometer, an orientation sensor, a proximity sensor, a temperature sensor, a time sensor; a geolocation sensor; an altimeter, a light sensor, a touch sensor, a magnetometer, a barometer, a gesture sensor, a biometric sensor, and / or a humidity sensor.
[0037] The WTRU 102 may include a full-duplex radio for which some or all signals (e.g., associated with specific subframes for both uplink (e.g., for transmission) and downlink (e.g., for reception)) may be concurrent and / or simultaneous. The full-duplex radio may include an interference management unit to reduce and / or substantially eliminate self-interference via hardware (e.g., choke) or via signal processing by a processor (e.g., a separate processor (not shown) or via the processor 118). In one embodiment, the WTRU 102 may include a half-duplex radio for which transmission and reception of some or all signals (e.g., associated with specific subframes for both uplink (e.g., for transmission) or downlink (e.g., for reception)) may be concurrent and / or simultaneous.
[0038] Figure 1C 1 is a system diagram showing the RAN 104 and the CN 106 according to an embodiment. As described above, the RAN 104 may employ an E-UTRA radio technology to communicate with the WTRUs 102a, 102b, and 102c over the air interface 116. The RAN 104 may also be in communication with the CN 106.
[0039] The RAN 104 may include eNode-Bs 160a, 160b, 160c, though it will be appreciated that the RAN 104 may include any number of eNode-Bs while remaining consistent with an embodiment. The eNode-Bs 160a, 160b, 160c may each include one or more transceivers for communicating with the WTRUs 102a, 102b, 102c over the air interface 116. In an embodiment, the eNode-Bs 160a, 160b, 160c may implement MIMO technology. Thus, for example, the eNode-B 160a may use multiple antennas to transmit wireless signals to, and receive wireless signals from, the WTRU 102a.
[0040] Each of the eNode-Bs 160a, 160b, and 160c may be associated with a particular cell (not shown) and may be configured to handle radio resource management decisions, handover decisions, user scheduling in uplink (UL) and / or downlink (DL), etc. Figure 1C As shown, eNode-Bs 160a, 160b, 160c may communicate with each other via an X2 interface.
[0041] Figure 1C The illustrated CN 106 may include a mobility management entity (MME) 162, a serving gateway (SGW) 164, and a packet data network (PDN) gateway (PGW) 166. While each of the foregoing elements is depicted as part of the CN 106, it should be appreciated that any of these elements may be owned and / or operated by an entity other than the CN operator.
[0042] The MME 162 may be connected to each of the eNode-Bs 160a, 160b, and 160c in the RAN 104 via an S1 interface and may serve as a control node. For example, the MME 162 may be responsible for authenticating users of the WTRUs 102a, 102b, 102c, bearer activation / deactivation, selecting a particular serving gateway during an initial attach of the WTRUs 102a, 102b, 102c, and the like. The MME 162 may provide a control plane function for switching between the RAN 104 and other RANs (not shown) that employ other radio technologies, such as GSM and / or WCDMA.
[0043] The SGW 164 may be connected to each of the eNode-Bs 160a, 160b, 160c in the RAN 104 via an S1 interface. The SGW 164 may generally route and forward user data packets to / from the WTRUs 102a, 102b, 102c. The SGW 164 may perform other functions, such as anchoring the user plane during inter-eNode-B handovers, triggering paging when DL data is available for the WTRUs 102a, 102b, 102c, managing and storing the contexts of the WTRUs 102a, 102b, 102c, and the like.
[0044] The SGW 164 may be connected to the PGW 166, which may provide the WTRUs 102a, 102b, 102c with access to the packet-switched network of the Internet 110 to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices.
[0045] The CN 106 may facilitate communications with other networks. For example, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to the circuit-switched network of the PSTN 108 to facilitate communications between the WTRUs 102a, 102b, 102c and traditional land-line communications devices. For example, the CN 106 may include or communicate with an IP gateway (e.g., an IP Multimedia Subsystem (IMS) server) that serves as an interface between the CN 106 and the PSTN 108. In addition, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to other networks 112, which may include other wired and / or wireless networks owned and / or operated by other service providers.
[0046] Although the WTRU Figures 1A to 1D Although described as a wireless terminal, it is contemplated that in certain representative embodiments, such a terminal may use (eg, temporarily or permanently) a wired communication interface with a communication network.
[0047] In a representative embodiment, other network 112 may be a WLAN.
[0048] A WLAN in infrastructure basic service set (BSS) mode may have an access point (AP) for a BSS and one or more stations (STAs) associated with the AP. The AP may have access or an interface to a distribution system (DS) or another type of wired / wireless network that carries traffic into and / or out of the BSS. Traffic originating from outside the BSS to a STA may arrive through the AP and may be delivered to the STA. Traffic originating from a STA to a destination outside the BSS may be sent to the AP to be delivered to the corresponding destination. Traffic between STAs within a BSS may be sent through the AP, for example, where a source STA may send traffic to the AP, and the AP may deliver the traffic to the destination STA. Traffic between STAs within a BSS may be considered and / or referred to as peer-to-peer traffic. Peer-to-peer traffic may be sent between a source STA and a destination STA (e.g., directly between a source STA and a destination STA) using direct link establishment (DLS). In certain representative embodiments, the DLS may use 802.11 e DLS or 802.11 z tunnel DLS (TDLS). A WLAN using an independent BSS (IBSS) mode may not have an AP, and STAs (eg, all STAs) within or using the IBSS may communicate directly with each other. The IBSS communication mode may sometimes be referred to herein as an "ad-hoc" communication mode.
[0049] When using the 802.11 ac infrastructure mode of operation or a similar mode of operation, the AP can send beacons on a fixed channel (such as a primary channel). The primary channel can be a fixed width (e.g., a 20MHz wide bandwidth) or a width dynamically set via signaling. The primary channel can be an operating channel of the BSS and can be used by the STA to establish a connection with the AP. In certain representative embodiments. For example, in an 802.11 system, carrier sense multiple access with collision avoidance (CSMA / CA) can be implemented. For CSMA / CA, a STA (e.g., each STA) (including the AP) can sense the primary channel. If the primary channel is sensed / detected and / or determined to be busy by a specific STA, the specific STA can back off. One STA (e.g., only one station) can transmit at any given time in a given BSS.
[0050] A high throughput (HT) STA may communicate using a 40 MHz wide channel, for example, formed via a combination of a primary 20 MHz channel and an adjacent or non-adjacent 20 MHz channel.
[0051] Very High Throughput (VHT) STA can support 20MHz, 40MHz, 80MHz and / or 160MHz wide channels. 40MHz and / or 80MHz channels can be formed by combining consecutive 20MHz channels. A 160MHz channel can be formed by combining 8 consecutive 20MHz channels or by combining two non-contiguous 80MHz channels, which can be referred to as an 80+80 configuration. For the 80+80 configuration, the data after channel coding can pass through a segment parser, which can divide the data into two streams. Inverse Fast Fourier Transform (IFFT) processing and time domain processing can be performed on each stream separately. The stream can be mapped onto two 80MHz channels, and the data can be sent by the transmitting STA. At the receiver of the receiving STA, the above operations for the 80+80 configuration can be reversed, and the combined data can be sent to a medium access control (MAC) layer, entity, etc.
[0052] 802.11af and 802.11ah support operating modes below 1 GHz. . The channel operating bandwidths and carriers in 802.11af and 802.11ah are reduced relative to the channel operating bandwidths and carriers used in 802.11n and 802.11ac. 802.11af supports 5 MHz, 10 MHz, and 20 MHz bandwidths in the TV White Space (TVWS) spectrum, and 802.11ah supports 1 MHz, 2 MHz, 4 MHz, 8 MHz, and 16 MHz bandwidths using non-TVWS spectrum. According to a representative embodiment, 802.11ah may support meter type control / machine type communication (MTC), such as MTC devices in macro coverage areas. MTC devices may have certain capabilities, such as limited capabilities including support for (e.g., only support for) certain and / or limited bandwidths. MTC devices may include a battery with a battery life above a threshold (e.g., to maintain a very long battery life).
[0053] WLAN systems that can support multiple channels and channel bandwidths, such as 802.11n, 802.11ac, 802.11af, and 802.11ah, include channels that can be designated as primary channels. The primary channel may have a bandwidth equal to the maximum common operating bandwidth supported by all STAs in the BSS. The bandwidth of the primary channel may be set and / or limited by a STA from all STAs operating in the BSS, which supports the minimum bandwidth operation mode. In the example of 802.11ah, for STAs (e.g., MTC-type devices) that support (e.g., only support) 1MHz mode, the primary channel may be 1MHz wide, even if the AP and other STAs in the BSS support 2MHz, 4MHz, 8MHz, 16MHz, and / or other channel bandwidth operation modes. Carrier sensing and / or network allocation vector (NAV) settings may depend on the state of the primary channel. If the primary channel is busy, for example, because a STA (which only supports 1MHz operation mode) is transmitting to the AP, the entire available band may be considered busy even if most of the band remains idle and may be available.
[0054] In the United States, the available frequency band that 802.11 ah can use is from 902MHz to 928MHz. In South Korea, the available frequency band is from 917.5 MHz to 923.5 MHz. In Japan, the available frequency band is from 916.5 MHz to 927.5 MHz. Depending on the country code, the total bandwidth available for 802.11 ah is 6MHz to 26MHz.
[0055] Figure 1D 1 is a system diagram showing the RAN 113 and the CN 115 according to an embodiment. As described above, the RAN 113 may communicate with the WTRUs 102a, 102b, 102c over the air interface 116 using NR radio technology. The RAN 113 may also communicate with the CN 115.
[0056] The RAN 113 may include gNBs 180a, 180b, 180c, though it will be appreciated that the RAN 113 may include any number of gNBs while remaining consistent with an embodiment. The gNBs 180a, 180b, 180c may each include one or more transceivers for communicating with the WTRUs 102a, 102b, 102c over the air interface 116. In an embodiment, the gNBs 180a, 180b, 180c may implement MIMO technology. For example, the gNBs 180a, 180b may utilize beamforming to transmit signals to and / or receive signals from the WTRUs 102a, 102b, 102c. Thus, for example, the gNB 180a may use multiple antennas to transmit wireless signals to and / or receive wireless signals from the WTRU 102a. In an embodiment, the gNBs 180a, 180b, 180c may implement carrier aggregation techniques. For example, the gNB 180a may send multiple component carriers (not shown) to the WTRU 102a. A subset of these component carriers may be on unlicensed spectrum, while the remaining component carriers may be on licensed spectrum. In an embodiment, the gNBs 180a, 180b, 180c may implement coordinated multi-point (CoMP) techniques. For example, the WTRU 102a may receive coordinated transmissions from the gNB 180a and gNB 180b (and / or gNB 180c).
[0057] The WTRUs 102a, 102b, 102c may communicate with the gNBs 180a, 180b, 180c using transmissions associated with a scalable digital configuration. For example, the OFDM symbol spacing and / or the OFDM subcarrier spacing may vary for different transmissions, different cells, and / or different portions of the wireless transmission spectrum. The WTRUs 102a, 102b, 102c may communicate with the gNBs 180a, 180b, 180c using subframes or transmission time intervals (TTIs) of varying or scalable lengths (e.g., including varying numbers of OFDM symbols and / or continuously varying absolute time lengths).
[0058] The gNBs 180a, 180b, 180c may be configured to communicate with the WTRUs 102a, 102b, 102c in a standalone configuration and / or a non-standalone configuration. In a standalone configuration, the WTRUs 102a, 102b, 102c may communicate with the gNBs 180a, 180b, 180c without accessing other RANs (e.g., such as the eNode-Bs 160a, 160b, 160c). In a standalone configuration, the WTRUs 102a, 102b, 102c may use one or more of the gNBs 180a, 180b, 180c as mobility anchors. In a standalone configuration, the WTRUs 102a, 102b, 102c may communicate with the gNBs 180a, 180b, 180c using signals in an unlicensed band. In a non-standalone configuration, the WTRUs 102a, 102b, 102c may communicate / connect with the gNBs 180a, 180b, 180c while also communicating / connecting with another RAN, such as the eNode-B 160a, 160b, 160c. For example, the WTRUs 102a, 102b, 102c may implement the DC principle to communicate with one or more gNBs 180a, 180b, 180c and one or more eNode-Bs 160a, 160b, 160c substantially simultaneously. In a non-standalone configuration, the eNode-B 160a, 160b, 160c may serve as a mobility anchor for the WTRUs 102a, 102b, 102c, and the gNBs 180a, 180b, 180c may provide additional coverage and / or throughput for serving the WTRUs 102a, 102b, 102c.
[0059] Each of the gNBs 180a, 180b, 180c may be associated with a particular cell (not shown) and may be configured to handle radio resource management decisions, handover decisions, scheduling of users in UL and / or DL, support network slicing, dual connectivity, interworking between NR and E-UTRA, routing of user plane data towards a user plane function (UPF) 184a, 184b, routing of control plane information towards an access and mobility management function (AMF) 182a, 182b, and the like. Figure 1D As shown, gNB180a, 180b, and 180c can communicate with each other through the Xn interface.
[0060] Figure 1DThe illustrated CN 115 may include at least one AMF 182a, 182b, at least one UPF 184a, 184b, at least one session management function (SMF) 183a, 183b, and at least one data network (DN) 185a, 185b. Although each of the foregoing elements is depicted as part of the CN 115, it should be understood that any of these elements may be owned and / or operated by an entity other than the CN operator.
[0061] The AMF 182a, 182b may be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 113 via an N2 interface and may serve as a control node. For example, the AMF 182a, 182b may be responsible for authenticating users of the WTRU 102a, 102b, 102c, supporting network slicing (e.g., handling different protocol data unit (PDU) sessions with different requirements), selecting a specific SMF 183a, 183b, managing registration areas, termination of NAS signaling, mobility management, etc. The AMF 182a, 182b may use network slicing, for example, to customize CN support for the WTRU 102a, 102b, 102c based on the type of service the WTRU 102a, 102b, 102c is using. For example, different network slices may be established for different use cases, such as services that rely on ultra-reliable low latency (URLLC) access, services that rely on enhanced massive mobile broadband (eMBB) access, services for MTC access, etc. The AMF 162 may provide a control plane function for switching between the RAN 113 and other RANs (not shown) that employ other radio technologies, such as LTE, LTE-A, LTE-A Pro, and / or non-3GPP access technologies such as WiFi.
[0062] The SMF 183a, 183b may be connected to the AMF 182a, 182b in the CN 115 via the N11 interface. The SMF 183a, 183b may also be connected to the UPF 184a, 184b in the CN 115 via the N4 interface. The SMF 183a, 183b may select and control the UPF 184a, 184b, and configure the routing of services through the UPF 184a, 184b. The SMF 183a, 183b may perform other functions, such as managing and allocating user equipment (UE) IP addresses, managing PDU sessions, controlling policy enforcement and QoS, providing downlink data notification, etc. The PDU session type may be IP-based, non-IP-based, Ethernet-based, etc.
[0063] The UPF 184a, 184b may be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 113 via an N3 interface, which may provide the WTRUs 102a, 102b, 102c with access to packet-switched networks, such as the Internet 110, for example, to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices. The UPF 184, 184b may perform other functions, such as routing and forwarding packets, enforcing user plane policies, supporting multi-homed PDU sessions, handling user plane QoS, buffering downlink packets, providing mobility anchoring, etc.
[0064] The CN 115 may facilitate communications with other networks. For example, the CN 115 may include or may communicate with an IP gateway (e.g., an IP Multimedia Subsystem (IMS) server) that serves as an interface between the CN 115 and the PSTN 108. In addition, the CN 115 may provide the WTRUs 102a, 102b, 102c with access to other networks 112, which may include other wired and / or wireless networks owned and / or operated by other service providers. In an embodiment, the WTRUs 102a, 102b, 102c may be connected to a local data network (DN) 185a, 185b through the UPF 184a, 184b via an N3 interface to the UPF 184a, 184b and an N6 interface between the UPF 184a, 184b and the DN 185a, 185b.
[0065] Given that Figures 1A to 1D ,as well as Figures 1A to 1D , one or more or all of the functions described herein with respect to any of the following: WTRU 102a-d, base station 11, eNode-B 160a-c, MME 162, SGW 164, PGW 166, gNB 180a-c, AMF 182a-b, UPF 184a-b, SMF 183a-b, DN 185a-b and / or any other (one or more) elements / devices described herein may be performed by one or more simulation elements / devices (not shown). A simulation device may be one or more devices configured to simulate one or more or all of the functions described herein. For example, a simulation device may be used to test other devices and / or simulate network and / or WTRU functions.
[0066] The simulation device may be designed to implement one or more tests of other devices in a laboratory environment and / or an operator network environment. For example, one or more simulation devices may perform one or more or all functions while being fully or partially implemented and / or deployed as part of a wired and / or wireless communication network in order to test other devices within the communication network. One or more simulation devices may perform one or more or all functions while being temporarily implemented / deployed as part of a wired and / or wireless communication network. For testing purposes, the simulation device may be directly coupled to another device, and / or may use over-the-air wireless communications to perform testing.
[0067] One or more emulated devices may perform one or more functions, including all functions, without being implemented / deployed as part of a wired and / or wireless communication network. For example, the emulated devices may be used in a test lab and / or in a test scenario in a non-deployed (e.g., testing) wired and / or wireless communication network to implement testing of one or more components. The one or more emulated devices may be test devices. The emulated devices may send and / or receive data using direct RF coupling and / or wireless communication via RF circuitry (e.g., which may include one or more antennas).
[0068] The examples provided herein do not limit the applicability of the subject matter to other wireless technologies, eg, using the same or different principles may be applicable.
[0069] As explained herein, a wireless transmit / receive unit (WTRU) may be an example of a user equipment (UE). Therefore, the terms UE and WTRU may be used herein in the same context.
[0070] background
[0071] UE Routing Selection Policy (URSP) provisioning until 3GPP Release 17 (Rel-17)
[0072] At the time of this disclosure, the following is the current view of the Rel-17 framework for URSP. The current policy control framework is described in 3GPP TS 23.503 V17.5.0, in particular including the UE Routing Selection Policy (URSP) provisioning. URSP is a policy used by the UE to determine how to route outgoing traffic. For example, traffic can be routed to an established PDU session, or the establishment of a new PDU session can be triggered. According to the existing UE Routing Selection Policy (URSP) configuration and provisioning procedures, the UE only accepts URSP rules from the Home Public Land Mobile Network (HPLMN). This can be done by pre-configuration (e.g., by an operator) or transmitted via signaling from the Policy Control Function (PCF) of the HPLMN, as defined in 3GPP TS 23.503 v17.5.0. The URSP rules transmitted via signaling take precedence over the pre-configured URSP rules if both exist. In the case of a roaming UE, the Home PCF (H-PCF) transmits the URSP rules to the UE via the Visited PCF (V-PCF). URSP, along with other types of policies (e.g., Vehicle-to-Everything Policy (V2XP), Access Network Discovery Selection Policy (ANDSP) including WLAN Selection Policy (WLANSP) rules, Proximity Service Policy (ProseP)) are part of the UE policy information. The UE policy information may be partitioned by the PCF into different policy parts with self-contained content (e.g., URSP rules are not split across policy parts) to allow correct delivery to the UE. The PCF decides to split the UE policy information into multiple policy parts based on the above self-containment requirement and size constraints known to the PCF (e.g., to allow "delivery" over non-access stratum (NAS) transport). Each policy part is identified by a policy part identifier (PSI).
[0073] WLAN Selection Policy (WLANSP) configuration until Rel-17
[0074] The UE may receive an Access Network Discovery and Selection Policy (ANDSP). The ANDSP may contain one or more WLAN Selection Policy (WLANSP) rules defined in clause 4.8.2.1.6 of TS 23.402 3GPP TS 23.402 v17.0.0.
[0075] WLANSP is a set of rules used by the UE to select and reselect a WLAN access network to connect to. The rules are provided to the UE with priority information, where each rule is assigned its priority. The UE evaluates the rules in priority order and selects the WLAN access network that matches / satisfies the requirements of the highest priority rule.
[0076] Rules can also contain information about when they should be considered valid (e.g., time and location validity conditions).
[0077] The ANDSP policy is received by the UE via NAS messaging. For example, the ANDSP policy is received in a policy part received in a UE configuration update procedure. The UE configuration update procedure is defined in 3GPP TS 23.502 v17.5.0.
[0078] WLANSP rules can come from the HPLMN and / or the visited PLMN (VPLMN). The rule ID informs the UE whether the WLANSP rule is from the HPLMN or the VPLMN. The UE determines which rules take precedence based on whether the UE is roaming. When the UE is roaming, the UE will give priority to the WLANSP rules of the visited network. In other words, when the UE is roaming, the UE will make a decision based on the WLANSP rules of the home network only if no network is found based on the WLANSP rules of the visited network. This prioritization process is described in Section 6.6.1.3 of 3GPP TS23.503 V17.5.0.
[0079] UE policy enhancements in Rel-18
[0080] System Aspect Working Group 2 (SA2) is studying potential enhancements to the URSP rules provisioning and update procedures in roaming scenarios (see 3GPP TR 23.700-85 v 1.0.0), while maintaining backward compatibility with existing HPLMN-based policy control as described above.
[0081] At this time of the disclosure, the following principles for enhancement are agreed. Support for PLMN-specific URSP rules is added, where an HPLM ID or VPLMN ID is provided along with the URSP to identify the PLMN to which the URSP is applicable. The H-PCF generates and provides the VPLMN-specific URSP rules to the UE.
[0082] Security parameter settings
[0083] 3GPP has defined a secure mechanism for transferring parameters from the home network, such as VPLMN List Information or UE Parameters Update (UPU) for Directed Roaming (SoR) (see 3GPP TS 33.501 vl 7.6.0).
[0084] For SoR and UPU procedures, the Unified Data Management (UDM) invokes security protection services from the Authentication Server Function (AUSF) to provide end-to-end integrity protection of the information sent to the UE. In both cases, the protection information is sent by the UDM to be relayed to the UE by the serving AMF in the VPLMN. In the case of SoR, the security mechanism can be triggered when the UE registers with the VPLMN or thereafter. In the case of UPU, the security mechanism can be triggered at any time after the UE has successfully registered in the 5GS.
[0085] Questions about UE policy provisioning
[0086] Until Rel-17, URSP rules were generated by the H-PCF via the V-PCF and delivered to the roaming UE based on the trust relationship between the HPLMN and the VPLMN. With this approach, there is a potential risk that the URSP rules are modified by the VPLMN (V-PCF) unintentionally or maliciously. For example, there is currently no mechanism for the UE to verify whether the URSP rules associated with the HPLMN (e.g., with the HPLMN ID) have been tampered with by the VPLMN.
[0087] A similar problem exists when the WLANSP rules are transferred from the H-PCF to the V-PCF. There is a potential risk that the WLANSP rules are modified by the VPLMN (V-PCF) unintentionally or maliciously. For example, the V-PCF may modify the WLANSP rules generated by the home network. Later, when the UE is served by the home network, the UE may apply the WLANSP rules modified by the visited network that previously served the UE.
[0088] One question is how to enable 5GS to implement the principles of HPLMN-based policy control, especially when considering enhancements to UE policy provisioning in roaming scenarios (e.g., supporting PLMN-specific URSP rules).
[0089] Proposed solution
[0090] UE policy information provides security mechanism
[0091] This solution describes how to support the H-PCF to provide secure UE policy information to the UE (e.g., when roaming) during the UE configuration update procedure for transparent policy delivery. The UE policy information may include a URSP that includes various PLMN-specific USRP rules. For example, one set of USRP rules may be associated with the HPLMN ID, while another set of rules may be associated with the VPLMN ID.
[0092] The procedures described in this document show how UE policy information that may contain URSP rules can be securely sent from the Home Network Function to the UE. These procedures can also be used to securely send UE policy information containing other types of policies (e.g., V2XP, ANDSP, (WLANSP), ProseP) to the UE.
[0093] Behavior on UE (e.g. roaming UE):
[0094] The behavior of the UE in a roaming environment, for example, may be as follows:
[0095] 1. The UE receives a NAS command message (e.g., using NAS transport) that includes UE policy information, a network-generated policy message authentication code (P-MAC-N), and a policy protection counter (PPC). The NAS message may include a request to send a secure confirmation (ack) of successful receipt of the UE policy information. The MAC is calculated by the network (AUSF) using a key shared with the UE (e.g., key AUSF (KAUSF)), the UE policy information, and the PPC, and the PPC enables the UE and the network function of the home network to verify that the UE policy information has not been tampered with. The P-MAC-N, PPC, and an indication that a secure ack is requested may be encoded in an information element along with the policy information. They may be encoded in such a way and may be separate from the policy information itself so that these information elements may be received and ignored by legacy UEs that do not understand the information. Encoding the P-MAC-N, PPC, and an indication that a secure ack is requested in such a way also allows the H-PCF to request the UE to send a UE-generated policy message authentication code (P-MAC-UE) to confirm the policy information sent to the UE in an earlier UE configuration update procedure. The UE may receive a UE policy that is split across multiple messages and transmitted as several UE policy information parts (eg, including one or more policy parts each). The UE reassembles the UE policy information using all received UE policy information parts before verifying the security of the UE policy, as described in the next step.
[0096] 2. The UE calculates a MAC in the same manner as the network using a key shared with the network (e.g., KAUSF), UE policy information, and PPC. The UE verifies that the calculated MAC matches the received P-MAC-N. If the verification is successful, the UE updates its policy with the received policy information. If the network requests a security ack, the UE calculates a MAC (P-MAC-UE) using the shared key, an indication of the policy update (e.g., success / failure), and the PPC. If the MAC verification fails, the UE discards the message. In an embodiment, in the event of an unsuccessful verification, the UE may not send an ack. In the event of an unsuccessful verification, attempt to tamper with a new policy or resend / replay the new policy to the UE. In either case, the UE should ignore the newly received policy. In an embodiment, if the H-PCF actually does send a new (updated) policy, the H-PCF will eventually detect the problem (e.g., using an existing timeout mechanism).
[0097] 3. The UE sends a NAS response message including the result of the UE policy processing (e.g., success / failure) together with the P-MAC-UE.
[0098] The UE may implement policy protection verification based on the UE (pre) configuration provided by the operator (e.g. stored on the ME or USIM). For example, such a configuration may indicate the type of policy for which security policy provision verification is implemented (e.g. URSP, WLANSP). The UE verifies the type of policy received and whether security protection is expected for it based on the configuration. The configuration may indicate that security policy provision verification is implemented on a per-VPLMN basis. For example, the HPLMN may decide to implement security policy provision with some roaming partners but not with other roaming partners based on the roaming agreement. The UE verifies the serving VPLMN ID and decides whether security protection is required based on the configuration.
[0099] Behavior of H-PCF:
[0100] H-PCF behaviors can include the following:
[0101] 1. The H-PCF decides to update the UE policy (e.g., during initial registration, UE location change, slice subscription change, etc.).
[0102] 2. The H-PCF obtains parameters from the V-PCF (or based on V-AF information) and builds and stores UE policy information, for example, including HPLMN and VPLMN-specific URSP rules.
[0103] 3. The H-PCF sends a request for policy information protection to the UDM, including the UE policy information and an indication of the requested UE ack.
[0104] 4. The H-PCF receives a response including P-MAC-N, PPC, and the intended UE generated MAC (XP-MAC-UE) from the UDM. The H-PCF stores the XP-MAC-UE with the policy information. The H-PCF may receive a pair of XP-MAC-UEs from the UDM, each with an indication of a successful and unsuccessful policy update indication, respectively.
[0105] 5. The H-PCF sends a request message to the AMF via the V-PCF to transmit the UE policy information along with the P-MAC-N, counters, and a request for a security ack from the UE.
[0106] 6. The H-PCF receives a response message from the AMF via the V-PCF, which includes the UE policy update result and the P-MAC-UE initiated at the UE.
[0107] 7. H-PCF compares the received P-MAC-UE with the stored XP-MAC-UE. If the P-MAC-UE verification succeeds, H-PCF further processes the UE policy update result, otherwise it considers the update failed.
[0108] In the above, the V-PCF may decide to segment the policy information into smaller UE policy information parts (e.g., UE policy information fragments) based on the self-contained content and size limit requirements according to the above sections entitled URSP provisioning up to Rel-17. In one example, the UE policy information fragment may include one or more policy parts. The following actions may be performed: The H-PCF requests the UDM / AUSF to protect the complete UE policy information regardless of the size of the resulting UE policy information, and sends the UE policy information, P-MAC-N, PPC, and ACK request to the V-PCF. The V-PCF continues to segment the UE policy information into fragments that are sent separately to the UE via the AMF. The V-PCF may provide information to the UE to assist in the reorganization of the complete UE policy (e.g., including the total number of expected UE policy fragments, and for each sent fragment, its index / position in the fragment list). The UE reconstructs the complete UE policy information based on the received fragments and the associated reorganization assistance information. The UE performs a security check on the resulting reorganized UE policy information as described above.
[0109] In another example, the H-PCF may perform UE policy information segmentation / splitting. The H-PCF may obtain a transmission size limit from the V-PCF to split the policy information according to that specific size requirement, i.e., so that any policy information fragment sent to the UE may fit into a single Namf_Communication_NlN2MessageTransfer call to the AMF. Additionally or alternatively, the H-PCF may request protection of the UE policy information for certain types of policies (e.g., URSP, WLANSP) without requesting protection of the UE policy information for other types of policies (e.g., V2XP, ProseP). The H-PCF may accordingly divide the UE policy information into fragments / parts that require protection and parts that do not require protection. The UE may perform an integrity check on the received UE policy information based on the applicable type of policy (e.g., based on the UE configuration, as described above). In such a scenario, the H-PCF proceeds similarly to the above, securely supplying UE policy for each individual UE policy information fragment each time. In this case, the H-PCF processes each UE policy information fragment, each UE policy information fragment having its own P-MAC-N, PPC, P-MAC-UE, to be sent to the UE individually.
[0110] Existing UEs do not support the above procedure, so the H-PCF cannot expect to receive a response including a P-MAC-UE from such a UE. In order to allow the H-PCF to detect the situation where the AMF or V-PCF has not provided the P-MAC-UE from the UE in the NAMF_Communication_nlMessageNotiy message, the UDM can indicate to the H-PCF that a response with a P-MAC-UE should be expected from the UE. The UDM can determine to send the indication to the PCF based on a pre-configuration (e.g., see the example of such pre-configuration above) and / or based on a support indication received from the UE in the 5GS Mobility Management (5GMM) capability information element during the UE registration process. Typically, the UDM can determine whether the UE supports the security policy provisioning procedure and notify the H-PCF of it.
[0111] Alternatively, for the above, the H-PCF may request protection policy information directly from the AUSF. In this scenario, the H-PCF requests the address of the AUSF that holds the last KAUSF and whether the UE supports the security policy provisioning procedure from the UDM. The H-PCF requests protection policy information directly from the AUSF (i.e., similar to the steps performed by the UDM below).
[0112] Behavior on UDM / AUSF:
[0113] The actions on UDM / AUSF can include the following:
[0114] 1. UDM receives a request for policy information protection from H-PCF, including UE policy information and a request for UE security ack.
[0115] 2. The UDM determines that the UE supports security policy provisioning (e.g., sends back a security ack) and locates the AUSF holding the last KAUSF.
[0116] 3. UDM sends a request message for policy information protection to AUSF, which includes UE policy information and an indication of requesting UE security ack. AUSF uses the current KAUSF and the PPC stored in AUSF to calculate the P-MAC-N of the received policy information. AUSF uses the PPC and the indication of the policy update (e.g., success, failure, respectively) to calculate XP-MAC-UE (e.g., its pair).
[0117] 3. UDM receives a response including P-MAC-N, PPC and xp-MAC-UE from AUSF.
[0118] 4. UDM sends a response including P-MAC-N, PPC and XP-MAC-UE to H-PCF.
[0119] Detailed process of secure UE policy information provisioning
[0120] Exemplary Figure 2 The signal diagram process for secure provisioning of UE policies is shown. The process can be triggered during the UE policy association establishment or modification process. It can be described as follows Figure 2 Event and message indication for signal diagrams.
[0121] Figure 2 Event 0: H-PCF decides to update UE policy. This may be triggered upon receiving a Policy Association Request message from V-PCF or any trigger for UE policy delivery.
[0122] Figure 2 Message 1: H-PCF sends a request for policy information protection to UDM, which includes Subscription Permanent Identifier (SUPI), UE policy information and an indication of the requested UE ack. UDM locates the UE information and determines that the UE supports security policy provisioning (e.g., based on configuration, registered capabilities) and locates the AUSF holding the last KAUSF.
[0123] Figure 2Message 2: UDM sends a request message for policy information protection to AUSF, which includes SUPI, UE policy information and an indication of requesting UE security ack. AUSF calculates P-MAC-N using the received policy information, the current KAUSF and the PPC (counter) stored in the AUSF. Whenever a new KAUSF is established between the AUSF and the UE, the PPC may be stored at both the UE and the AUSF and initialized to a predetermined initial value. The PPC is incremented by the AUSF / UE each time a new UE policy information protection related operation (e.g., generation or success check of P-MAC-n) is performed. If the PPC is about to wrap around, the AUSF suspends the policy protection service and resumes only when a new KAUSF is generated. The H-PCF is notified by the UDM / AUSF that the policy protection service is suspended and may be notified when the AUSF / UDM resumes.
[0124] Figure 2 Message 3: UDM receives a response including P-MAC-N, PPC and XP-MAC-UE from AUSF.
[0125] Figure 2 Message 4: UDM forwards the parameters from AUSF to H-PCF. H-PCF stores XP-MAC-UE and UE policy information.
[0126] Figure 2 Message 5: H-PCF sends a message to V-PCF including UE policy information, P-MAC-N, PPC and an indication requesting UE security ack. If V-PCF decides to divide the UE policy information into multiple smaller parts / fragments. V-PCF sends each segment separately to AMF. In this case, steps 6 to 10 can be repeated as many times as needed to transmit the complete UE policy information.
[0127] Figure 2 Message 6: V-PCF sends a message to the UE via AMF, the message including UE policy information (e.g., one of multiple UE policy fragments), P-MAC-N, PPC, and an indication of the requested UE security ack. In the case where the UE policy information is divided into multiple smaller fragments / parts, V-PCF includes these parameters along the fragment (e.g., along the initial or last fragment). In addition, to help the UE reconstruct the final UE policy information, V-PCF can indicate the number of fragments expected along the fragment (e.g., along the initial fragment).
[0128] Figure 2 Message 7: AMF forwards the security UE policy provisioning parameters from the V-PCF to the UE.
[0129] Figure 2Event 8: The UE determines that secure UE policy provisioning is required based on the UE configuration, the presence of security parameters (e.g., P-MAC-N, PPC). The UE checks whether the received PPC is greater than the stored PPC. The UE stores the security parameters and policy information (e.g., temporarily). The UE may receive several fragments separately. In that case, when all necessary UE policy fragments have been received, the UE combines / reassembles these fragments into complete UE policy information before performing security verification and update of its UE policy. When the UE has complete UE policy information (e.g., all UE policy fragments / parts are reassembled together), the UE calculates the MAC using the complete UE policy information, the current KAUSF, and the received PPC. The UE verifies that the calculated MAC matches the received P-MAC-N. If a secure ack is requested, the UE calculates a secure ack using the received indication, the current KAUSF, and the PPC. If the verification is successful, the UE updates its current UE policy with the newly received / reconstructed UE policy information and updates the PPC with the received PPC value.
[0130] Figure 2 Message 9: If the complete UE policy is processed, the UE sends a response message to the AMF, which includes the UE policy update result and P-MAC-UE. If other fragments are expected, the UE sends an indication that more UE policy information parts are expected.
[0131] Figure 2 Message 10: AMF forwards the result from the UE to the V-PCF. If there are other UE policy fragments to be sent, the V-PCF proceeds with the next UE policy fragment as described in message 6.
[0132] Figure 2 Message 11: V-PCF receives the message including the final result (including P-MAC-UE) and forwards it to H-PCF. H-PCF compares the received P-MAC-UE with the stored XP-MAC-UE. If the P-MAC-UE verification succeeds, H-PCF further processes the UE policy update result, otherwise it considers the UE policy update failed.
[0133] Figure 3 is an example method 300 of a process performed by a WTRU / UE to perform security provisioning for WTRU / UE policies. Figure 2 As shown, this process can be triggered during the WTRU / UE policy association establishment or modification process. Figure 3In the embodiment of the present invention, at 305, the WTRU receives a network message including new policy information, a first policy message authentication code (MAC) generated by the network (P-MAC-N), and a policy protection counter (PPC). At 310, the WTRU generates a second policy MAC using a security key shared with the network, the new policy information, and the PPC. At 315, the WTRU verifies the integrity of the network message by determining that the P-MAC-N matches the second policy MAC. At 320, the WTRU updates the WTRU's previous policy information with the new policy information based on the match between the P-MAC-N and the second policy MAC. The update occurs after the integrity verification indicates that a valid network message containing the new policy information has been received.
[0134] Involving Figure 3 In one example case of a WTRU method of implementing a network message, new policy information may be transmitted to the WTRU in multiple parts. In this example, integrity verification of the network message occurs after reassembling the new policy information using the multiple received parts. In the example case, verification of the network message also includes checking that the PPC is greater than the PPC previously stored by the WTRU.
[0135] Involving Figure 3 In one example of a WTRU method of receiving a network message, receiving the network message also includes receiving a request for confirmation of receipt of the new policy information. In one example of WTRU operation, Figure 3 The method may also include the WTRU sending a confirmation message to the network based on the successful verification of the network message. In this example, the WTRU confirmation message may include a third policy MAC (P-MAC-UE) generated by the WTRU to send to the network. In that case, the P-MAC-UE is generated by the WTRU using the indication of successful receipt of the new policy information, a security key shared with the network, and the PPC. In one aspect, the PPC limits the number of attempts to introduce new policy information in the WTRU.
[0136] Figure 4 An example method 400 is performed by a network node in a 5G core network to perform secure provisioning of policies for a WTRU operating in the network. In one example, the network node may be a Home Policy Control Function (H-PCF).
[0137] exist Figure 4 In the example embodiment, at 405, the network node generates new policy information for the WTRU using parameters from the access policy control function (V-PCF) of the 5G core network. At 410, the network node sends a request for policy information protection to the unified data management (UDM) function.
[0138] At 415, the network node receives a response to the request for policy information protection from the UDM function. The response includes one or more of a network generated policy message authentication code (P-MAC-N), a policy protection counter (PPC), and an expected policy MAC (XP-MAC-UE) to be generated by the WTRU. At 420, the network node sends a request to transmit new policy information to the V-PCF. The request to transmit new policy information includes one or more of the P-MAC-N and the PPC counter.
[0139] At 425, the network node receives a response to the request to transmit new policy information, the response to the transmission including the WTRU generated MAC (P-MAC-UE). At 430, the network node verifies the match of P-MAC-UE with XP-MAC-UE. Once a successful match is made, the network node can implement the new policy information sent to the WTRU based on the match of P-MAC-UE with XP-MAC-UE.
[0140] In one example, the network node generates a request for policy information protection at 410. The request at 410 may include one or more of new policy information and an indication that the WTRU acknowledges the request. In one example, at 420, the network node may request transmission of the new policy information, wherein the request for transmission includes an indication that the WTRU acknowledges the request.
[0141] in conclusion
[0142] Although features and elements are provided above in specific combinations, it will be understood by those of ordinary skill in the art that each feature or element can be used alone or in any combination with other features and elements. The present disclosure is not limited to the specific embodiments described in this application, which are intended to be illustrations of various aspects. Without departing from the spirit and scope of the present invention, many modifications and changes can be made, which will be apparent to those skilled in the art. The elements, actions or instructions used in the description of this application should not be interpreted as being critical or necessary to the present invention unless explicitly provided as such. According to the foregoing description, in addition to those listed herein, functionally equivalent methods and devices within the scope of the present disclosure will be apparent to those skilled in the art. Such modifications and changes are intended to fall within the scope of the appended claims. The present disclosure is limited only by the terms of the appended claims and the full scope of equivalents given by these claims. It should be understood that the present disclosure is not limited to a specific method or system.
[0143] For simplicity, the previous embodiments are discussed with respect to the terminology and structure of devices with infrared capabilities (i.e., infrared transmitters and receivers). However, the embodiments discussed are not limited to these systems, but can be applied to other systems using other forms of electromagnetic waves or non-electromagnetic waves (such as sound waves).
[0144] It should also be understood that the terminology used herein is for the purpose of describing specific embodiments only and is not intended to be limiting. As used herein, the term "video" or the term "image" may mean any of a snapshot, a single image, and / or a plurality of images displayed on a time basis. As another example, when referred to herein, the term "user equipment" and its abbreviation "UE", the term "remote" and / or the term "head mounted display" or its abbreviation "HMD" may mean or include (i) a wireless transmit and / or receive unit (WTRU); (ii) any of a number of embodiments of a WTRU; (iii) a device with wireless capabilities and / or with wired capabilities (e.g., connectable) that is configured with some or all of the structures and functions of a WTRU; (iii) a device with wireless capabilities and / or wired capabilities that is configured with less than all of the structures and functions of a WTRU; or (iv) the like. References herein to Figures 1A to 1D Details of an example WTRU are provided, which may represent any WTRU described herein. As another example, various disclosed embodiments herein above and below are described as utilizing a head mounted display. Those skilled in the art will recognize that devices other than head mounted displays may be utilized, and some or all of the present disclosure and various disclosed embodiments may be modified accordingly without undue experimentation. Examples of such other devices may include drones or other devices configured to stream information for providing an adapted reality experience.
[0145] In addition, the methods provided herein may be implemented in a computer program, software, or firmware incorporated into a computer-readable medium for execution by a computer or processor. Examples of computer-readable media include electronic signals (transmitted via a wired or wireless connection) and computer-readable storage media. Examples of computer-readable storage media include, but are not limited to, read-only memory (ROM), random access memory (RAM), registers, cache memory, semiconductor memory devices, magnetic media (e.g., internal hard disks and removable disks), magneto-optical media, and optical media (e.g., CD-ROM disks and digital versatile disks (DVDs)). A processor associated with the software may be used to implement a radio frequency transceiver used in a WTRU, UE, terminal, base station, RNC, or any host computer.
[0146] Variations of the methods, devices, and systems provided above are possible without departing from the scope of the present invention. In view of the wide variety of embodiments that may be applied, it should be understood that the embodiments shown are merely examples and should not be considered to limit the scope of the appended claims. For example, embodiments provided herein include handheld devices that may include or be used with any suitable voltage source (such as a battery, etc.) that provides any suitable voltage.
[0147] In addition, in the embodiments provided above, reference is made to processing platforms, computing systems, controllers, and other devices including processors. These devices may include at least one central processing unit ("CPU") and memory. According to the practice of those skilled in the art of computer programming, references to actions and symbolic representations of operations or instructions may be performed by various CPUs and memories. Such actions and operations or instructions may be referred to as being "executed," "computer executed," or "CPU executed."
[0148] Those of ordinary skill in the art will appreciate that the actions and symbolically represented operations or instructions include the manipulation of electrical signals by the CPU. The electrical system represents data bits, which may cause the resulting transformation or reduction of electrical signals and the maintenance of data bits at memory locations in the memory system, thereby reconfiguring or otherwise changing the operation of the CPU, as well as other processing of signals. The memory location where the data bits are stored is a physical location with specific electrical, magnetic, optical or organic properties corresponding to or representing the data bits. It should be understood that the embodiments are not limited to the above-mentioned platforms or CPUs, and other platforms and CPUs may support the provided methods.
[0149] The data bits may also be maintained on a computer-readable medium, including a magnetic disk, an optical disk, and any other volatile (e.g., random access memory (RAM)) or non-volatile (e.g., read-only memory (ROM)) mass storage system that can be read by the CPU. The computer-readable medium may include cooperating or interconnected computer-readable media that reside exclusively on a processing system or distributed among multiple interconnected processing systems that may be local or remote to the processing system. It should be understood that the embodiments are not limited to the above-mentioned memories, and other platforms and memories may support the provided methods.
[0150] In an illustrative embodiment, any of the operations, processes, etc. described herein may be implemented as computer-readable instructions stored on a computer-readable medium. The computer-readable instructions may be executed by a processor of a mobile unit, a network element, and / or any other computing device.
[0151] There is little distinction between hardware and software implementations of various aspects of the system. The use of hardware or software is usually (but not always, because in certain contexts, the choice between hardware and software may become important) a design choice that represents a cost-efficiency trade-off. There may be various carriers (e.g., hardware, software, and / or firmware) that can implement the processes and / or systems and / or other technologies described herein, and the preferred carrier may vary with the context of the deployment process and / or system and / or other technologies. For example, if the implementer determines that speed and accuracy are the most important, the implementer may select a primary hardware and / or firmware carrier. If flexibility is the most important, the implementer may select a primary software implementation. Alternatively, the implementer may select a combination of hardware, software, and / or firmware.
[0152] The foregoing detailed description has described various embodiments of the device and / or process by using block diagrams, flow charts and / or examples. Where such block diagrams, flow charts and / or examples include one or more functions and / or operations, it will be understood by those skilled in the art that each function and / or operation within such block diagrams, flow charts or examples may be implemented individually and / or collectively by various hardware, software, firmware or almost any combination thereof. In an embodiment, several parts of the subject matter described herein may be implemented via an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a digital signal processor (DSP) and / or other integrated formats. However, it will be recognized by those skilled in the art that some aspects of the embodiments disclosed herein may be implemented in whole or in part equivalently in an integrated circuit, as one or more computer programs running on one or more computers (e.g., as one or more programs running on one or more computer systems), as one or more programs running on one or more processors (e.g., as one or more programs running on one or more microprocessors), as firmware, or as almost any combination thereof, and that designing circuits and / or writing codes for software and / or firmware will be entirely within the skill of those skilled in the art in accordance with the present disclosure. Furthermore, those skilled in the art will appreciate that the mechanisms of the subject matter described herein may be distributed as a program product in various forms, and that the illustrative embodiments of the subject matter described herein apply regardless of the particular type of signal bearing medium used to actually carry out the distribution. Examples of signal bearing media include, but are not limited to, the following: recordable type media such as floppy disks, hard drives, CDs, DVDs. Digital tapes, computer memory, etc., and transmission type media such as digital and / or analog communication media (e.g., fiber optic cables, waveguides, wired communication links, wireless communication links, etc.).
[0153] Those skilled in the art will recognize that it is common in the art to describe devices and / or processes in the manner described herein, and thereafter use engineering practices to integrate such described devices and / or processes into a data processing system. That is, at least a portion of the devices and / or processes described herein can be integrated into a data processing system via a reasonable amount of experimentation. Those skilled in the art will recognize that a typical data processing system can typically include a system unit housing, a video display device, a memory such as volatile and non-volatile memory, a processor such as a microprocessor and a digital signal processor, a computing entity such as an operating system, a driver, a graphical user interface and an application, one or more interactive devices such as a touch pad or a screen, and / or a control system including a feedback loop and a control motor (e.g., feedback for sensing position and / or velocity, a control motor for moving and / or adjusting components and / or quantities). A typical data processing system can be implemented using any suitable commercially available components, such as components typically found in data computing / communication and / or network computing / communication systems.
[0154] The subject matter described herein sometimes shows different components included in or connected to different other components. It should be understood that the architecture depicted in this way is only an example, and many other architectures that can actually achieve the same function can be implemented. In a conceptual sense, any arrangement of components that achieve the same functionality is effectively "associated" so that the desired functionality can be achieved. Therefore, any two components combined to achieve a specific function herein can be regarded as "associated" with each other so that the desired function is achieved, regardless of the architecture or intermediate medium. Components. Similarly, any two components so associated can also be regarded as "operably connected" or "operably coupled" to each other to achieve the desired function 7, and any two components that can be so associated can also be regarded as "operably coupled" to each other to achieve the desired function. Specific examples of operably coupled include, but are not limited to, physically pairable and / or physically interactive components and / or wirelessly interactive and / or wirelessly interactive components and / or logically interactive and / or logically interactive components.
[0155] With respect to the use of substantially any plural and / or singular terms herein, those skilled in the art may translate from the plural to the singular and / or from the singular to the plural as appropriate, depending on the context and / or application. For clarity, various singular / plural permutations may be expressly set forth herein.
[0156] Those skilled in the art will understand that, in general, the terms used herein, particularly in the appended claims (e.g., the bodies of the appended claims), are generally intended to be "open" terms (e.g., the term "including" should be interpreted as "including but not limited to," the term "having" should be interpreted as "having at least," the term "comprising" should be interpreted as "including but not limited to," etc.). Those skilled in the art will further understand that if a "specific number of items introduced" into a claim is intended, such intent will be explicitly stated in the claim, and in the absence of such a statement, no such intent is present. For example, where only one item is intended, the term "single" or similar language may be used. To aid understanding, the following appended claims and / or the description herein may include the use of the introductory phrases "at least one" and "one or more" to introduce claim recitations. However, the use of these phrases should not be interpreted as implying that the introduction of a claim recitation by the indefinite article "a" or "an" limits any particular claim that includes such introduced claim recitation to embodiments that include only one such recitation, even when the same claim includes the introductory phrases "one or more" or "at least one" and an indefinite article such as "a" or "an" (e.g., "a" and / or "an" should be interpreted as meaning "at least one" or "one or more"). The same is true for the use of definite articles to introduce claim recitations. In addition, even if a specific number of introduced claim recitations is explicitly recited, one skilled in the art will recognize that such recitation should be interpreted to mean at least the recited number (e.g., the bare recitation of "two recitations" without other modifiers means at least two recitations, or two or more recitations). Furthermore, in those cases where a convention similar to "at least one of A, B, and C, etc." is used, generally such construction is intended that a person skilled in the art will understand the meaning of the convention (e.g., "a system having at least one of A, B, and C" will include but is not limited to systems having only A, only B, only C, A and B together, A and C together, B and C together, and / or A, B, and C together, etc.). In those cases where a convention similar to "at least one of A, B, or C, etc." is used, generally such construction is intended that a person skilled in the art will understand the meaning of the convention (e.g., "a system having at least one of A, B, or C" will include but is not limited to systems having only A, only B, only C, A and B together, A and C together, B and C together, and / or A, B, and C together, etc.). A person skilled in the art will further understand that any disjunctive words and / or phrases that actually present two or more alternative terms, whether in the specification, claims, or drawings, should be understood to contemplate the possibility of including one of the terms, either of the terms, or both of the terms. For example, the phrase "A or B" will be understood to include the possibility of "A" or "B" or "A and B".Furthermore, as used herein, the term "any" followed by a plurality of items and / or a listing of multiple categories of items is intended to include "any." Furthermore, as used herein, the term "set" is intended to include any number of items, including zero. Additionally, as used herein, the term "number" is intended to include any number, including zero. And as used herein, the term "plurality" is intended to be synonymous with "multiple."
[0157] In addition, where features or aspects of the disclosure are described in terms of Markush groups, those skilled in the art will recognize that the disclosure is also thereby described in terms of any individual member or subgroup of members of the Markush group.
[0158] As will be understood by those skilled in the art, for any and all purposes, for example, in terms of providing a written description, all ranges disclosed herein also encompass any and all possible sub-ranges and combinations of sub-ranges thereof. Any listed range can be easily considered to fully describe and make the same range be decomposed into at least equal half, one-third, one-quarter, one-fifth, one-tenth, etc. As a non-limiting example, each range discussed herein can be easily decomposed into a lower third, a middle third, and an upper third, etc. As will be understood by those skilled in the art, all languages such as "at most", "at least", "greater than", "less than", etc. include the listed numbers, and refer to the ranges that can be subsequently decomposed into sub-ranges as discussed above. Finally, as will be understood by those skilled in the art, the range includes each individual member. Therefore, for example, a group with 1-3 units refers to a group with 1, 2 or 3 units. Similarly, a group with 1-5 units refers to a group with 1, 2, 3, 4 or 5 units, etc.
[0159] Furthermore, the claims should not be read as limited to the order or elements provided unless otherwise stated. Furthermore, use of the term "means for..." in any claim is intended to invoke 35 U.S.C. § 112, paragraph 6 or means-plus-function claim format, and any claim without the term "means for..." is not so intended.
Claims
1. A wireless transmit / receive unit (WTRU), comprising circuitry, the WTRU being configured to: receiving a network message, the network message including new policy information, a first policy message authentication code (MAC) (P-MAC-N) generated by the network, and a policy protection counter (PPC); generating a second policy MAC using a security key shared with the network, the new policy information, and the PPC; verifying the integrity of the network message by determining that the P-MAC-N matches the second policy MAC; as well as The WTRU's previous policy information is updated with the new policy information based on a match between the P-MAC-N and the second policy MAC.
2. The WTRU of claim 1 , wherein: The WTRU verifies the integrity of the network message after reassembling the new policy information in instances when the new policy information is received in multiple parts.
3. The WTRU of claim 1 , wherein: The WTRU is also configured to: The integrity of the new policy information is verified by checking that the PPC is greater than the PPC previously stored by the WTRU.
4. The WTRU of claim 1 , wherein: The network message includes a request for confirmation of receipt of the new policy information.
5. The WTRU of claim 1 , wherein: The WTRU sends an acknowledgement message to the network based on successful verification of the network message including the new policy information.
6. The WTRU of claim 5, wherein: The acknowledgement message includes a third policy MAC (P-MAC-UE) generated by the WTRU to send to the network.
7. The WTRU of claim 6, wherein: The P-MAC-UE is generated by the WTRU using the indication of successful receipt of the new policy information, the security key shared with the network, and the PPC.
8. A method performed by a wireless transmit / receive unit (WTRU), the method comprising: receiving a network message, the network message including new policy information, a first policy message authentication code (MAC) (P-MAC-N) generated by the network, and a policy protection counter (PPC); generating a second policy MAC using a security key shared with the network, the new policy information, and the PPC; verifying the integrity of the network message by determining that the P-MAC-N matches the second policy MAC; as well as The WTRU's previous policy information is updated with the new policy information based on a match between the P-MAC-N and the second policy MAC.
9. The method according to claim 8, wherein: In instances when the new policy information is received in multiple parts, verifying the integrity of the network message occurs after reassembling the new policy information.
10. The method according to claim 8, wherein: Verifying the integrity of the network message further includes checking whether the PPC is greater than a PPC previously stored by the WTRU.
11. The method according to claim 8, wherein: Receiving the network message also includes receiving a request for confirmation of receipt of the new policy information.
12. The method according to claim 8, wherein: The method further includes sending a confirmation message to the network based on successful verification of the network message.
13. The method according to claim 12, wherein: The acknowledgement message includes a third policy MAC (P-MAC-UE) generated by the WTRU to send to the network.
14. The method according to claim 13, wherein: The P-MAC-UE is generated by the WTRU using the indication of successful receipt of the new policy information, the security key shared with the network, and the PPC.
15. The method according to claim 14, wherein: The PPC limits the number of attempts to introduce the new policy information in the WTRU.
16. A network node comprising a circuit, the network node being configured to: Generate new policy information for the wireless transmit / receive unit (WTRU) using parameters from the access policy control function (V-PCF) of the 5G core network; Sending a request for policy information protection to the unified data management (UDM) function; receiving a response to the request for policy information protection from the UDM function, the response comprising one or more of a network generated Policy Message Authentication Code (P-MAC-N), a Policy Protection Counter (PPC), and an Expected Policy MAC (XP-MAC-UE) to be generated by the WTRU; sending a request to transmit the new policy information, the request including one or more of the P-MAC-N and the PPC counter; receiving a response to the request to transmit the new policy information, the response to the transmission comprising a WTRU-generated MAC (P-MAC-UE); Verifying the matching of the P-MAC-UE and the XP-MAC-UE; as well as The new policy information sent to the WTRU is implemented based on a match between the P-MAC-UE and the XP-MAC-UE.
17. The network node according to claim 16, wherein: The request for policy information protection includes one or more of the new policy information and an indication that the WTRU acknowledges the request.
18. The network node according to claim 17, wherein: The request to transmit the new policy information includes the indication that the WTRU acknowledges the request.
19. The network node according to claim 1, wherein: The network node comprises a Home Policy Control Function (H-PCF).