Quality of service (QoS) differentiation for internet protocol (IP) access in wireless communication system

By using a single IPsec tunnel in a non-3GPP access network and setting different DSCP values ​​for datagrams of different service quality, the resource waste problem caused by establishing separate tunnels for different service quality in the prior art is solved, and efficient service quality distinction and multi-service quality communication support are achieved.

CN120077609APending Publication Date: 2025-05-30GOOGLE LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380076454.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-11-11
Filing Date
2023-11-09
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The prior art establishes separate IPsec tunnels for datagrams of different quality of service in non-3GPP access networks, resulting in signaling overhead and resource waste.

Method used

By establishing a single IPsec tunnel on a non-3GPP access network, datagrams with different differential service code points (DSCP) values ​​are generated, and protocol data units (PDUs) with different service quality are passed respectively to achieve the distinction between service quality.

Benefits of technology

This approach avoids the inefficiency of establishing a separate IPsec tunnel for each quality of service, reduces signaling overhead and resource consumption, while supporting multiple quality of service communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120077609A_ABST
    Figure CN120077609A_ABST
Patent Text Reader

Abstract

The present disclosure provides systems, methods, and devices for quality of service (QoS) differentiation for Internet Protocol (IP) access in a wireless communication system. Datagrams with different quality of service may traverse the same Internet Protocol Security (IPsec) tunnel through a non-3rd Generation Partnership Project (non-3GPP) access network. A user equipment (UE) (101) or a network node (such as a non-3GPP interworking function (N3IWF) or a trusted non-3GPP gateway function (TNGF)) (115) generates a first data report to convey a first encrypted PDU. The first datagram includes a first external IP header having a first differential service code point (DSCP) value that matches a second DSCP value corresponding to the first encrypted PDU (419). The UE (101) or the N3IWF / TNGF (115) transmits a first datagram via an IPsec tunnel in a non-3GPP access network. The non-3GPP access network performs QoS differential handling of the first datagram based on the DSCP value of the external IP header (421).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to wireless communication and mechanisms for communicating with different quality of service between a user equipment and a 5G core via a non-3rd Generation Partnership Project (3GPP) access network. Description of Related Art

[0002] A user equipment (UE) may access a 3GPP network via a non-3rd Generation Partnership Project (3GPP) access network. The non-3GPP access may also be Internet Protocol (IP) access. The UE and a 5th Generation (5G) core (5GC) may establish a Protocol Data Unit (PDU) session via the non-3GPP network. As part of establishing the PDU session, the UE may use a non-3GPP access function (such as a non-3GPP Interworking Function (N3IWF)) to establish one or more Internet Protocol Security (IPsec) Security Associations (SAs) (also referred to as IPsec tunnels). When accessing the 5GC via a non-3GPP network (e.g., an IP access network), the UE may use such IPsec SAs (IPsec tunnels) to send datagrams. The UE or the N3IWF may use the IPsec tunnel to send PDUs of the PDU session. The PDU may be encapsulated in a Generic Routing Encapsulation (GRE) packet. The GRE packet may be included in the payload of the IPsec packet, which also has an outer IP header and an IPsec header. Thus, the datagram includes an outer IP header, an IPsec header, and a payload that includes the GRE packet encapsulating the PDU packet. The outer IP header includes a Differentiated Services Code Point (DSCP) value indicating the QoS of the datagram. In some instances, the PDU session supports two or more qualities of service. For example, the PDU may include video data with a first Quality of Service (QoS) and voice data with a second QoS. Conventionally, the UE and the N3IWF establish separate IPsec tunnels for different QoSs, which wastes resources due to signaling overhead. Summary of the Invention

[0003] The systems, methods, and apparatuses of the present disclosure each have several innovative aspects, none of which alone is responsible for the desired attributes disclosed herein.

[0004] One innovative aspect of the subject matter described in this disclosure can be implemented in a method for generating datagrams for a protocol data unit (PDU) session between a user equipment (UE) and a fifth generation core network (5GC). The method includes establishing an Internet Protocol Security (IPsec) tunnel over a non-Third Generation Partnership Project (non-3GPP) access network. The method includes generating a first datagram to convey a first encrypted PDU. The first datagram includes a first outer Internet Protocol (IP) header having a first Differentiated Services Code Point (DSCP) value that matches a second DSCP value corresponding to the first encrypted PDU. The method includes generating a second datagram to convey a second encrypted PDU. The second datagram includes a second outer IP header having a third DSCP value that matches a fourth DSCP value corresponding to the second encrypted PDU, the third DSCP value being different from the first DSCP value. The method includes sending the first datagram and the second datagram via the IPsec tunnel in the non-3GPP access network.

[0005] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus (or device) including a processor and a radio communication interface, the apparatus (or device) being configured to implement the method mentioned above.

[0006] Another innovative aspect of the subject matter described in this disclosure can be implemented in a network node including a processor and a modem, the network node being configured to implement the method mentioned above.

[0007] Details of one or more implementations of the subject matter described in this disclosure are set forth in the accompanying drawings and the following description. Other features, aspects, and advantages will become apparent from the specification, the drawings, and the claims. Note that the relative dimensions of the following drawings may not be drawn to scale. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] Figure 1 A schematic diagram illustrating possible connections of a UE to a 5GC via different types of access networks in a wireless communication system is shown.

[0009] Figure 2 A schematic diagram illustrating the datagram structure is shown.

[0010] Figure 3 A schematic diagram illustrating the transmission of datagrams with different Quality of Service (QoS) between a user equipment (UE) and a non-3GPP Interworking Function (N3IWF) via an Internet Protocol Security (IPsec) tunnel is shown.

[0011] Figure 4AIt is a signaling diagram illustrating the message passing and operations for establishing a single IPsec sub - security association (SA) between the N3IWF and the UE.

[0012] Figure 4B It is a signaling diagram illustrating the message passing and operations for establishing multiple IPsec sub - SAs between the N3IWF and the UE.

[0013] Figure 5 It is a flowchart illustrating the operations for the UE or the N3IWF to send datagrams using a single IPsec tunnel or multiple IPsec tunnels.

[0014] Figure 6 It is a schematic diagram illustrating the criteria based on which the UE or the N3IWF can decide whether to utilize a single IPsec tunnel or multiple IPsec tunnels.

[0015] Figure 7 It shows a flowchart of an example process for quality of service (QoS) differentiation for non - 3GPP access.

[0016] Figure 8 It is a flowchart illustrating the operations for a sender to send datagrams using a single IPsec tunnel or multiple IPsec tunnels.

[0017] Figure 9 It shows a block diagram of an example device supporting QoS differentiation for non - 3GPP access.

[0018] The same reference numerals and names in the respective figures indicate the same elements. Detailed implementation

[0019] For the purpose of describing the innovative aspects of the present disclosure, the following description relates to certain implementations. However, those of ordinary skill in the art will readily recognize that the teachings herein can be applied in many different ways. Some of the examples in the present disclosure are based on wireless communication according to third - generation partnership project (3GPP) wireless standards such as 4G LTE and 5G NR standards. However, the described implementations can be implemented in any device, system, or network capable of sending and receiving radio frequency signals or other known signals according to any wireless communication standard, including any of the Institute of Electrical and Electronics Engineers (IEEE) 802.11, 802.15, or 802.16 wireless standards, the other known signals being used for communication within a wireless, cellular, or Internet of Things (IoT) network (such as a system utilizing 3G, 4G, 5G, WiFi, or future radio technologies).

[0020] The present disclosure provides systems, methods, and devices for quality of service (QoS) differentiation and Internet Protocol (IP) access in a wireless communication system. A user equipment (UE) may access a 5G network via a 3GPP access network or a non-3GPP access network. The UE and the 5G Core (5GC) may establish a Protocol Data Unit (PDU) session. The UE and a network node may establish one or more Internet Protocol Security (IPsec) Security Associations (SAs) to transport datagrams of the PDU session via the non-3GPP access network. The IPsec SA may be an IPsec tunnel. For simplicity, this specification describes untrusted non-3GPP access, where the UE uses an N3IWF to establish the IPsec tunnel, and the N3IWF acts as a gateway between the untrusted non-3GPP access and the 5GC. The UE may also communicate with the 5GC via a trusted non-3GPP access network, where the UE establishes an IPsec tunnel to a Trusted Non-3GPP Gateway Function (TNGF), and the TNGF acts as a gateway between the trusted non-3GPP access and the 5GC.

[0021] For untrusted non-3GPP access, the N3IWF is an access network node that provides QoS signaling to support QoS differentiation and mapping of QoS flows to non-3GPP access resources. For untrusted non-3GPP access, unauthorized users may access the non-3GPP access point, and QoS is not guaranteed. For trusted non-3GPP access, the TNGF is an access network node that provides QoS signaling to support QoS differentiation and mapping of QoS flows to non-3GPP access resources. For a trusted non-3GPP access network, only authorized users may access the non-3GPP access point, and QoS may be guaranteed. The trusted non-3GPP access network is connected to the 5GC via a Trusted Non-3GPP Gateway Function (TNGF).

[0022] According to some embodiments, the UE and the network generate datagrams for communicating via a single IPsec tunnel through an untrusted non-3GPP network with different qualities of service. For example, the UE may send one datagram with a specific Quality of Service (QoS) through the IPsec tunnel and another datagram with a different QoS through the same IPsec tunnel. By using a single IPsec tunnel for multiple datagrams with multiple different QoSs, the UE avoids the inefficiencies associated with establishing a separate IPsec tunnel for each QoS.

[0023] In some implementations, the UE and / or the N3IWF specify a specific QoS for each datagram in the IPsec tunnel. To implement the specified QoS, the UE and / or the N3IWF insert a copy of the Differentiated Services Code Point (DSCP) value of the PDU into the outer IP header of the datagram. For example, the UE may send two PDUs with different QoS via the same IPsec tunnel. To represent different qualities of service in a PDU session, each PDU will have a different DSCP. The UE creates two datagrams, where each datagram includes a different DSCP in its outer IP header. The UE customizes the QoS of the first datagram by copying the DSCP of the first PDU into the outer IP header of the first datagram. The UE customizes the QoS of the second datagram by copying the DSCP of the second PDU into the outer IP header of the second datagram. The UE may send the datagrams to the non-3GPP access network via the IPsec tunnel. The untrusted non-3GPP access network may discover the different QoS of each datagram by evaluating the outer IP header of each datagram.

[0024] Specific implementations of the subject matter described in this disclosure may be implemented to realize one or more of the following potential advantages. The UE may more easily connect to multiple services of the 3GPP network via the non-3GPP access network. In some implementations, the UE and the non-3GPP access network establish a single IPsec tunnel to support multiple qualities of service. By leveraging a single IPsec tunnel to support multiple qualities of service, the 3GPP network can avoid the signaling and computational overhead associated with establishing multiple IPsec tunnels.

[0025] Figure 1UE 101 can be connected to 5GC 110 via the 3GPP access network 111. The 3GPP access network 111 includes a radio access network (RAN) 102. The RAN 102 provides access for the UE 101 to communicate with other nodes such as 5GC 110 in the wireless communication system. The RAN (sometimes also referred to as a radio network or access network) can include multiple base stations (BSs) that can support the communication of the UE 101 and multiple other UEs. Depending on the wireless communication standard supported by the base station, different types of base stations can be referred to as NodeB, LTE evolved NodeB (eNB), next-generation NodeB (gNB), access point (AP), radio headend, transmit-receive point (TRP), etc. One or more LTE base stations can constitute an LTE RAN. The LTE RAN (sometimes also referred to as an LTE network) provides access to the wireless communication system. Similarly, one or more 5G base stations can constitute a 5G New Radio (NR) RAN and can be referred to as a 5G NR network that provides access to the wireless communication system. The LTE network and the 5G NR network are two examples of radio access networks available for transmission to 5GC 110.

[0026] UE 101 can also be connected to 5GC 110 via a trusted non-3GPP access network 113. The trusted non-3GPP access network 113 includes a trusted non-3GPP access point (TNAP) (such as a private WiFi access point) and a trusted non-3GPP gateway function (TNGF) 109.

[0027] In addition, UE 101 can be connected to 5GC 110 via an untrusted non-3GPP access network 112. The untrusted non-3GPP access network 112 includes at least one untrusted non-3GPP access point 106 and a non-3GPP interworking function (N3IWF) 107. The untrusted non-3GPP access point 106 can include any suitable WiFi access point, such as a public WiFi access point. The N3IWF 107 connects the untrusted non-3GPP access point 106 to access the access and mobility management function (AMF) 103 and the user plane function (UPF) 105 of 5GC 110. When UE 101 is connected to 5GC 110 via the untrusted non-3GPP access network 112, 5GC 110 establishes an Internet Protocol Security (IPsec) tunnel 114 between the N3IWF 107 and the UE 101. The UE 101 and the N3IWF 107 can send datagrams via the IPsec tunnel 114. In some implementations, each datagram in the IPsec tunnel 114 can have Quality of Service (QoS). For example, a datagram including streaming video data has one QoS, while another datagram including instant messaging data has a different QoS.

[0028] Figure 2 It is a schematic diagram illustrating the structure of a datagram. In some implementations, the datagram 220 includes an outer IP header 202 indicating a source IP address (such as the IP address of the UE 101) and a destination IP address (such as the IP address of the N3IWF 107). The outer IP header 202 is not encrypted. The outer IP header 202 includes a first DSCP value 210. The datagram 220 also includes an IPsec header 203 encapsulating encrypted data 204 of an IPsec packet. The encrypted data 204 includes an inner IP header 205 (encrypted), a Generic Routing Encapsulation (GRE) header 206 (encrypted), and a PDU 207 (encrypted). The PDU 207 includes a PDU IP header 208, which includes a second DSCP value 209 (encrypted). The first DSCP value 209 indicates the QoS of the PDU 207. When creating the datagram 220, some implementations of the UE 101 or the N3IWF 107 copy an unencrypted version of the second DSCP value 209 into the outer IP header 202. Thus, the outer IP header 202 includes a first DSCP value 210 that matches the second DSCP value 209. As described above, the first DSCP value 210 in the outer IP header 202 is not encrypted. The untrusted non-3GPP access network 112 provides QoS for the datagram 220 based on the first DSCP value 210 in the outer IP header 202.

[0029] Figure 3 It is a schematic diagram illustrating the transmission of datagrams with different QoS between the UE and the N3IWF via an IPsec tunnel. In Figure 3 this, the N3IWF / TNGF 115 establishes an IPsec tunnel 114 with the UE 101. After establishing the IPsec tunnel 114, the UE 101 and the N3IWF / TNGF 115 can send and receive datagrams through the IPsec tunnel 114. In the IPsec tunnel 114, each datagram can indicate a different QoS.

[0030] In some implementations, the UE 101 sends multiple datagrams through the IPsec tunnel 114, where each datagram indicates a different QoS. For example, the UE 101 generates and sends a first datagram 220 to the N3IWF / TNGF 115. The first datagram 220 includes an outer IP header 302, which includes a first DSCP value 310 that matches a second DSCP value 309 encrypted in the first PDU 307 in the first datagram 220. Since the first DSCP value matches the second DSCP value, the QoS of the first datagram 220 matches the QoS of the first PDU 307.

[0031] Continuing with this example, the UE 101 also generates and sends a second datagram 221. The second datagram 221 includes an outer IP header 312, which includes a third DSCP value 320 that matches a fourth DSCP value 319 encrypted in the second PDU 317 in the second datagram 221. Since the third DSCP value matches the fourth DSCP value, the QoS of the second datagram 221 matches the QoS of the second PDU 317.

[0032] As another example, the N3IWF / TNGF 115 generates and sends the first datagram 220 and the second datagram 221, as similarly described for the UE 101 in the reference Figure 3 Thus, both the UE 101 and the N3IWF / TNGF 115 can send multiple datagrams through a single IPsec tunnel 114, where each datagram indicates a different QoS.

[0033] Figure 4A is a signaling diagram illustrating the message passing and operations for establishing a single IPsec sub-SA between the N3IWF / TNGF and the UE. In some implementations, the 5GC 110 establishes an IPsec sub-SA when registering the UE 101, as specified in sub-clause 4.12.2 of TS 23.502. The IPsec sub-SA establishes an IPsec tunnel by indicating shared security attributes between the UE 101 and the N3IWF / TNGF 115 - such as cryptographic algorithms and modes, encryption keys, and other network service parameters. At 403, the UE101 sends a PDU session establishment request to the 5GC 110 via the N3IWF 107. At 404, the 5GC 110 responds to the PDU session establishment request with a decision to establish an IPsec sub-SA with the UE 101. Additionally, the 5GC 110 sends a message that instructs the N3IWF / TNGF 115 to establish a GRE tunnel for each QoS flow in the PDU session and to establish an IPsec SA with the UE 101.

[0034] At 405, the N3IWF 107 sends a request to create a child IPsec SA to the UE 101. In some implementations, the request includes a PDU session identifier (PSI) of the IPsec SA, a DSCP, a QoS flow identifier (QFI) of the IPsec SA, a DSCP value of the IPsec SA, a default IPsec sub-SA indication, and additional QoS information.

[0035] At 407, the UE 101 responds by sending an IPsec SA response that establishes an IPsec tunnel between the UE 101 and the N3IWF / TNGF 115. After the IPsec tunnel has been established, the N3IWF 107 sends a PDU session acceptance message to the UE 101 (at 413). The PDU session establishment acceptance message may include the IP address of the N3IWF / TNGF 115, QOS rules, and / or QOS flows.

[0036] At 415, the 5GC 110 and the N3IWF 107 synchronize the PDU session state.

[0037] After establishing a single IPsec sub-SA, the UE 101 and the N3IWF 107 may send datagrams 220 via the single IPsec sub-SA. In some implementations, each datagram 220 includes an outer IP header 202 that includes a first DSCP value 210 that matches a second encrypted DSCP value 209 of the PDU 207, where the PDU 207 is included in the datagram 220. As described above, the DSCP value 210 in the outer IP header 202 indicates the QoS of the datagram 220.

[0038] At 421, the non-3GPP access points 106 / 108 provide QoS to each datagram 220 of the IPsec sub-SA based on the DSCP value 210 in the outer IP header 202. Thus, an untrusted non-3GPP access network can perform QoS differentiation based on different DSCP values of a single IPsec tunnel.

[0039] In some implementations, the 5GC 110 establishes two or more IPsec sub-SAs, where each IPsec sub-SA has a specific QoS. For example, to accommodate two qualities of service, the 5GC 110 may create a first IPsec sub-SA for a first QoS and a second IPsec sub-SA for a second QoS.

[0040] Figure 4B Is a signaling diagram illustrating the message passing and operations for establishing multiple IPsec sub-SAs between the N3IWF and the UE. Figure 4Bshows a scenario where a UE uses non-3GPP access in the absence of the features of the present disclosure. In Figure 4B Network components 101-110 are the same as those described in the reference Figure 4A In addition, the messaging and operations 401-407 are the same as those described in the reference Figure 4A At 405 and 407, the N3IWF / TNGF 115 and the UE 101 establish a first IPsec sub-SA. At 429 and 431, the N3IWF 107 and the UE 101 establish a second IPsec sub-SA. Although Figure 4B shows two IPsec sub-SAs, the N3IWF / TNGF 115 and the UE 101 may establish any suitable number of IPsec sub-SAs to accommodate any number of quality of service.

[0041] At 433, the N3IWF / TNGF 115 sends a PDU session acceptance message to the UE 101. At 435, the 5GC 110 and the N3IWF / TNGF 115 synchronize the PDU session state. At this time, the UE 101 and the N3IWF / TNGF 115 have established two IPsec tunnels.

[0042] At 437, the N3IWF / TNGF 115 and the UE 101 send a datagram 220 through the IPsec sub-SA. As described above, each IPsec sub-SA supports a specific QoS. Therefore, all datagrams of a specific IPsec sub-SA indicate the same QoS. To indicate QoS in the datagram 220, the sender (N3IWF / TNGF 115 or UE 101) determines the DSCP value included in the IPsec sub-SA request (see boxes 405 and 429). Next, the sender generates a datagram 220 with an outer IP header 202 that matches the DSCP value included in the IPsec sub-SA request (such as the request at 405). All datagrams of a specific IPsec sub-SA include the same DSCP value in the outer header and thus receive the same QoS.

[0043] At 439, the non-3GPP access points 106 / 108 provide QoS to each datagram 220 based on the DSCP value 210 in the outer IP header 202 within the IPsec SA. Therefore, the untrusted non-3GPP access network 112 can perform QoS differentiation between IPsec sub-SAs.

[0044] In some implementations, the 5GC 110 selects between a single IPsec tunnel and multiple IPsec tunnels. When using a single IPsec tunnel, the single IPsec tunnel supports multiple quality of service. When using multiple IPsec tunnels, each IPsec tunnel supports a different QoS.

[0045] Figure 5 It is a flowchart illustrating the operation for a UE or N3IWF to send datagrams using a single IPsec tunnel or multiple IPsec tunnels. At block 502, the sender (UE 101 or N3IWF / TNGF 115) selects to send user plane data or establish an IPsec tunnel. If the sender selects to establish an IPsec tunnel, the process continues at block 504. On the first pass through flowchart 500, the sender will select to establish an IPsec tunnel. If the sender selects to send user plane data (such as datagram 220), the process continues at block 506.

[0046] At block 504, the sender establishes an IPsec tunnel between the UE 101 and the N3IWF / TNGF 115. On the first pass through flowchart 500, there is only a single IPsec tunnel. That is, there is a single IPsec sub-SA for the PDU session. The process continues at block 502.

[0047] At block 506, the sender determines whether at least one criterion for a single IPsec tunnel with support for multiple quality of service has been met. When the sender is the N3IWF 107, the criteria for a single IPsec tunnel include: the untrusted non-3GPP access network has not provided any DSCP value for the IPsec sub-SA in the IPsec sub-SA request (see 405 or 429). When the sender is the N3IWF / TNGF 115, the criteria also include: the untrusted non-3GPP access network has provided a DSCP value equal to zero in the IPsec sub-SA request (see 405 or 429). When the sender is the UE 101, the criteria for a single IPsec tunnel include: there is only a single IPsec tunnel between the UE 101 and the N3IWF / TNGF 115, the UE configuration settings indicate that the IPsec differential service feature is enabled, and the user configuration settings indicate that the IPsec differential service feature is enabled.

[0048] If at least one criterion has been met, the process continues at block 508. Otherwise, the process continues at block 510.

[0049] At block 508, the sender sets the first DSCP value 210 in the outer IP header 202 of the datagram 222 to the second DSCP value 209 in the PDU 207. The process continues at block 512.

[0050] At block 510, the sender sets the DSCP value 210 in the outer IP header 202 of the datagram 220 to the DSCP value received in the IPsec tunnel request. The process continues at block 512.

[0051] At block 512, the sender sends the datagram 220 via the IPsec tunnel. The process may continue at block 502 or end after block 512.

[0052] Figure 6 It is a schematic diagram showing the criteria based on which the UE or the N3IWF can decide whether to use a single IPsec tunnel or multiple IPsec tunnels. The criteria can be stored in the criteria repository 602. The criteria repository 602 includes multiple criteria 604 - 610. Each criterion can be specifically related to a particular sender. For example, criterion 604 can be related to the UE 101, but not to the N3IWF / TNGF 115. However, the criteria can be related to both the user equipment and the UE 101 as well as the N3IWF / TNGF 115. When the sender is the N3IWF / TNGF 115, the criteria 604 - 610 for having a single IPsec tunnel can include: The untrusted non-3GPP access network has not provided any DSCP value for the IPsec sub-SA in the IPsec sub-SA request (see 405 or 429). When the sender is the N3IWF 107, the criteria 604 - 610 can also include: The untrusted non-3GPP access network has provided a DSCP value equal to zero in the IPsec sub-SA request (see 405 or 429). When the sender is the UE 101, the criteria 604 - 610 for having a single IPsec tunnel can include: There is only a single IPsec tunnel between the UE 101 and the N3IWF / TNGF 115, the UE configuration settings indicate that the IPsec differential QoS feature is enabled, and the user configuration settings indicate that the IPsec differential QoS feature is enabled.

[0053] Figure 7 The flowchart of an example process 700 for QoS differentiation of non-3GPP access is shown. In some implementations, Figure 7 one or more of the process blocks can be executed by a device such as a UE, an N3IWF, or a TNGF, such as any one of the UE 101, the N3IWF 107, or the TNGF 109 as referenced Figure 1 、 Figure 4A and Figure 4B described.

[0054] At block 710, the device establishes an Internet Protocol Security (IPsec) tunnel over an untrusted non-3rd Generation Partnership Project (non-3GPP) access network. At block 720, the device generates a first datagram to convey a first encrypted PDU. The first datagram includes a first outer Internet Protocol (IP) header having a first Differentiated Services Code Point (DSCP) value that matches a second DSCP value corresponding to the first encrypted PDU. At block 730, the device generates a second datagram to convey a second encrypted PDU. The second datagram includes a second outer IP header having a third DSCP value that matches a fourth DSCP value corresponding to the second encrypted PDU. The first DSCP value is different from the third DSCP value. At block 740, the device sends the first datagram and the second datagram via the IPsec tunnel in the untrusted non-3GPP access network.

[0055] Although the figures illustrate example blocks of a process, in some implementations, the process may include additional blocks, fewer blocks, different blocks, or blocks arranged differently than those depicted in the figures. Additionally or alternatively, two or more blocks of the process may be performed in parallel.

[0056] Figure 8 is a flowchart illustrating operations for a sender to send datagrams using a single IPsec tunnel or multiple IPsec tunnels. In some implementations, Figure 7 one or more process blocks of Figure 1 may be performed by a device such as a UE, N3IWF, or TNGF, such as any of the UE 101, N3IWF 107, or TNGF 109 described with reference to Figure 4A and Figure 4B . At block 802, the device (such as UE 101 or N3IWF / TNGF 115) determines that user plane data is available for transmission and / or the device will establish an IPsec tunnel SA. At block 806, the device considers one or more of the following criteria: there is only one IPsec tunnel for the PDU session, the network does not provide a DSCP value for the IPsec tunnel, the network indicates that the DSCP value of the IPsec tunnel is zero, the UE configuration indicates that the IPsec QoS differentiation feature is enabled (such as on a public land mobile network basis), the user configuration indicates that the IPsec QoS differentiation feature is enabled.

[0057] At block 807, the device determines whether one or more of the criteria are met. If one or more of the criteria are met, the process continues at block 808. Otherwise, the process continues at block 810.

[0058] At block 808, the device sets the DSCP value of the outer IP header of the datagram to the DSCP value of the PDU. In some implementations, at block 816, when one or more of the following example conditions are met, the device re-evaluates which DSCP value will be placed in the outer IP header of the datagram: a new IPsec SA is established, an existing IPsec SA is deleted, and a periodic time period has elapsed.

[0059] At block 810, the device sets the DSCP value of the outer IP header of the datagram to the DSCP value in the IPsec tunnel request 405, rather than the DSCP value of the PDU.

[0060] Figure 9 A block diagram of an example apparatus 900 that supports QoS differentiation for non-3GPP access is shown. In some implementations, apparatus 900 may be an example of an apparatus for use in a UE such as UE 101 described above with reference to Figures 1 to 8 The UE 101. Apparatus 900 is capable of transmitting (or outputting for transmission) and receiving wireless communications. In some implementations, apparatus 900 is an example of N3IWF 107 and TNGF 109.

[0061] Apparatus 900 may be or may include a chip, a system-on-chip (SoC), a chipset, a package, or a device. The term "system-on-chip" (SoC) is used herein to refer to a set of interconnected electronic circuits, typically but not exclusively including one or more processors, memories, and communication interfaces. The SoC may include various different types of processors and processor cores, such as general-purpose processors, central processing units (CPUs), digital signal processors (DSPs), graphics processing units (GPUs), accelerated processing units (APUs), subsystem processors, auxiliary processors, single-core processors, and multi-core processors. The SoC may also include other hardware and hardware combinations, such as field-programmable gate arrays (FPGAs), configuration and status registers (CSRs), application-specific integrated circuits (ASICs), other programmable logic devices, discrete gate logic, transistor logic, registers, performance monitoring hardware, watchdog hardware, counters, and time bases. The SoC may be an integrated circuit (IC) configured such that the components of the IC reside on the same substrate, such as a single piece of semiconductor material (such as silicon for example).

[0062] The term "system-in-package" (SIP) is used herein to refer to a single module or package that can include multiple resources, computing units, cores, or processors located on two or more IC chips, substrates, or SoCs. For example, an SIP can include a single substrate on which multiple IC chips or semiconductor dies are stacked in a vertical configuration. Similarly, an SIP can include one or more multi-chip modules (MCMs) on which multiple ICs or semiconductor dies are encapsulated into a unified substrate. An SIP can also include multiple independent SoCs that are coupled together via high-speed communication circuitry and are very closely packaged (such as packaged on a single motherboard or within a single mobile communication device). The proximity of the SoCs facilitates high-speed communication as well as the sharing of memory and resources.

[0063] The term "multi-core processor" is used herein to refer to a single IC chip or chip package that includes two or more independent processing cores (e.g., CPU cores, IP cores, GPU cores, etc.) that are configured to read and execute program instructions. An SoC can include multiple multi-core processors, and each processor in the SoC can be referred to as a core. The term "multi-processor" can be used herein to refer to a system or device that includes two or more processing units that are configured to read and execute program instructions.

[0064] Device 900 can include one or more modems 902. In some implementations, one or more modems 902 (collectively referred to as "modems 902") can include a WWAN modem (e.g., a 3GPP 4G LTE or 5G compatible modem). In some implementations, device 900 also includes one or more radios (collectively referred to as "radios 904"). In some implementations, device 900 also includes one or more processors, processing blocks, or processing elements (collectively referred to as "processing system 906") and one or more memory blocks or elements (collectively referred to as "memory 908"). In some implementations, processing system 906 can include memory 908.

[0065] The modem 902 may include intelligent hardware blocks or devices, such as, for example, an application specific integrated circuit (ASIC), etc. The modem 902 is generally configured to implement the PHY layer. For example, the modem 902 is configured to modulate packets and output the modulated packets to the radio 904 for transmission over the wireless medium. Similarly, the modem 902 is configured to obtain the modulated packets received by the radio 904 and demodulate these packets to provide demodulated packets. In addition to the modulator and demodulator, the modem 902 may also include digital signal processing (DSP) circuitry, automatic gain control (AGC), a coder, a decoder, a multiplexer, and a demultiplexer. For example, when in the transmit mode, the data obtained from the processing system 906 is provided to the coder, which encodes the data to provide encoded bits. The encoded bits (using the selected MCS) are mapped to points in the modulation constellation to provide modulated symbols. The modulated symbols may be mapped to NSS spatial streams or NSTS space-time streams. The modulated symbols in the respective spatial or space-time streams may be multiplexed, transformed via an inverse fast Fourier transform (IFFT) block, and then provided to the DSP circuitry for Tx windowing and filtering. The digital signal may be provided to a digital-to-analog converter (DAC). The resulting analog signal may be provided to an upconverter and ultimately to the radio 904. In implementations involving beamforming, the modulated symbols in the respective spatial streams are precoded via a steering matrix prior to their placement to the IFFT block.

[0066] When in the receive mode, the digital signal received from the radio 904 is provided to the DSP circuitry, which is configured to acquire the received signal, for example, by detecting the presence of the signal and estimating the initial timing and frequency offset. The DSP circuitry is also configured to digitally condition the digital signal, for example, using channel (narrowband) filtering, analog impairment conditioning (such as correcting I / Q imbalance), and applying digital gain to ultimately obtain a narrowband signal. The output of the DSP circuitry may be fed to the AGC, which is configured to determine an appropriate gain using, for example, the information extracted from the digital signal in one or more received training fields. The output of the DSP circuitry is also coupled to the demodulator, which is configured to extract the modulated symbols from the signal and, for example, compute the log-likelihood ratio (LLR) for each bit position of each subcarrier in each spatial stream. The demodulator is coupled to the decoder, which may be configured to process the LLRs to provide decoded bits. The decoded bits from all spatial streams in the spatial stream are fed to the demultiplexer for demultiplexing. The demultiplexed bits may be descrambled and provided to the MAC layer (processing system 906) for processing, evaluation, or interpretation.

[0067] Radio 904 typically includes at least one radio frequency (RF) transmitter (or “transmitter chain”) and at least one RF receiver (or “receiver chain”) that can be combined into one or more transceivers. For example, the RF transmitter and receiver can include various DSP circuitry that includes at least one power amplifier (PA) and at least one low noise amplifier (LNA), respectively. The RF transmitter and receiver can in turn be coupled to one or more antennas. For example, in some implementations, device 900 can include multiple transmit antennas (each having a corresponding transmit chain) and multiple receive antennas (each having a corresponding receive chain), or can be coupled to them. The symbols output from modem 902 are provided to radio 904, which transmits the symbols via the coupled antennas. Similarly, the symbols received via the antennas are obtained by radio 904, which provides the symbols to modem 902.

[0068] Processing system 906 can include intelligent hardware blocks or devices designed to perform the functions described herein, such as, for example, processing cores, processing blocks, central processing units (CPUs), microprocessors, microcontrollers, digital signal processors (DSPs), application specific integrated circuits (ASICs), programmable logic devices (PLDs) such as field programmable gate arrays (FPGAs), discrete gate or transistor logic, discrete hardware components, or any combination thereof. Processing system 906 processes the information received via radio 904 and modem 902, and processes the information to be output via modem 902 and radio 904 for transmission over the wireless medium. In some implementations, processing system 906 can generally control modem 902 to cause the modem to perform the various operations described herein. For example, processing system 906 in combination with modem 902 can implement any of the features described with reference to Figures 2 to 6 any of the features described.

[0069] Memory 908 can include tangible storage media such as random access memory (RAM) or read only memory (ROM), or a combination thereof. Memory 908 can also store non-transitory processor or computer executable software (SW) code that includes instructions that, when executed by processing system 906, cause the processor to perform the various operations for wireless communication described herein, including generation, transmission, reception, and interpretation of MPDUs, frames, or packets. For example, the various functions of the components disclosed herein, or the various blocks or steps of the methods, operations, processes, or algorithms disclosed herein, can be implemented as one or more modules of one or more computer programs.

[0070] Figures 1 to 9The operations described herein are examples intended to assist in understanding example implementations and should not be used to limit potential implementations or the scope of the claims. Some implementations may perform additional operations, fewer operations, operations in parallel or in a different order, and some operations may be performed differently.

[0071] The foregoing disclosure provides illustration and description, but is not intended to be exhaustive or to limit the aspects to the precise forms disclosed. Modifications and variations can be made in light of the above disclosure, or can be obtained from practice of these aspects. Although aspects of the present disclosure have been described with respect to various examples, any combination of aspects from any example is also within the scope of the present disclosure. The examples in the present disclosure are provided for illustrative purposes only. Alternatively, or in addition to the other examples described herein, the examples also include any combination of the following implementation options (enumerated as clauses for clarity).

[0072] Clause 1. A method for generating datagrams for a protocol data unit (PDU) session between a user equipment (UE) and a fifth generation core network (5GC), comprising: establishing an Internet Protocol Security (IPsec) tunnel over a non-Third Generation Partnership Project (non-3GPP) access network; generating a first datagram to convey a first encrypted PDU, the first datagram including a first outer Internet Protocol (IP) header having a first Differentiated Services Code Point (DSCP) value that matches a second DSCP value corresponding to the first encrypted PDU; generating a second datagram to convey a second encrypted PDU, the second datagram including a second outer IP header having a third DSCP value that matches a fourth DSCP value corresponding to the second encrypted PDU, the first DSCP value being different from the third DSCP value; and sending the first datagram and the second datagram via the IPsec tunnel in the non-3GPP access network.

[0073] Clause 2. The method according to Clause 1, wherein the first DSCP value indicates a first quality of service (QoS) of a first data stream, and the third DSCP value indicates a second QoS different from the first QoS of a second data stream.

[0074] Clause 3. The method according to Clause 1, wherein each of the first datagram and the second datagram has an encrypted portion and an unencrypted header, the encrypted portion includes the first encrypted PDU or the second encrypted PDU respectively, and the unencrypted headers include the first outer IP header and the second outer IP header respectively.

[0075] Clause 4. The method according to Clause 3, wherein the unencrypted header includes an IPsec header, and the encrypted part is the payload of the IPsec packet.

[0076] Clause 5. The method according to Clause 4, wherein the payload of the IPsec packet includes a Generic Routing Encapsulation (GRE) packet encapsulating the first encrypted PDU or the second encrypted PDU, respectively.

[0077] Clause 6. The method according to any one of Clauses 1 to 5, wherein the IPsec tunnel is identified by a sub-SA of the IPsec security association (SA) created for the PDU session.

[0078] Clause 7. The method according to any one of Clauses 1 to 6, wherein the first datagram and the second datagram are sent or received by a non-3GPP interworking function (N3IWF) of a non-3GPP access network or a trusted non-3GPP gateway function (TNGF) of a non-3GPP access network.

[0079] Clause 8. The method according to any one of Clauses 1 to 7, wherein the generation of the first datagram and the generation of the second datagram include verifying that at least one criterion is met.

[0080] Clause 9. The method according to Clause 8, wherein the at least one criterion includes at least one of the following: the IPsec tunnel is the only IPsec tunnel for the PDU session between the UE and the non-3GPP access network, the non-3GPP access network has not provided any DSCP value for the IPsec tunnel, or the non-3GPP access network has provided a fifth DSCP value equal to zero for the IPsec tunnel.

[0081] Clause 10. The method according to Clause 8, wherein the at least one criterion includes at least one of the following: the UE configuration settings indicate that the IPsec differential service feature is enabled for the PDU session of the Public Land Mobile Network (PLMN) for the 5GC, or the user configuration settings indicate the enabling of the IPsec differential service feature by the user of the UE.

[0082] Clause 11. The method according to any one of Clauses 1 to 10, wherein the UE performs establishing the IPsec tunnel, generating the first datagram, generating the second datagram, and sending the first datagram and the second datagram.

[0083] Clause 12. The method according to any one of Clauses 8 to 10, wherein a network node communicatively coupled to the non-3GPP network and the 5GC performs establishing the IPsec tunnel, generating the first datagram, generating the second datagram, and sending the first datagram and the second datagram.

[0084] Clause 13. The method according to Clause 1, wherein the first DSCP value is in the first network protocol layer of the first datagram, and the third DSCP value is in the second network protocol layer of the second datagram, wherein the encapsulation protocol layer separates the first network protocol layer from the second network protocol layer.

[0085] Clause 14. A method for optimizing the transmission of data with different Quality of Service (QoS) between a User Equipment (UE) and a Fifth Generation Core Network (5GC) via a non-Third Generation Partnership Project (non-3GPP) access network, the method comprising: transmitting data according to a first QoS via an IPsec tunnel associated with a PDU session between the UE and the 5GC via the non-3GPP access network; testing whether any one of a plurality of conditions is met when a request to transmit the data according to a second QoS different from the first QoS is received; in response to meeting at least one of the plurality of conditions, transmitting the data via the IPsec tunnel according to the first quality and according to the second quality by respectively inserting a first Differentiated Services Code Point (DSCP) value and a second DSCP value into an outer IP header; and in response to not meeting the conditions, establishing another IPsec tunnel for transmitting the data according to the second quality, wherein the plurality of conditions include: the non-3GPP access network enables only one IPsec tunnel for the PDU session; the non-3GPP access network does not provide a DSCP value associated with the IPsec tunnel; the non-3GPP access network associates a predetermined DSCP value with the IPsec tunnel, the predetermined value indicating the ability to use the IPsec tunnel for different QoS; the UE is configured to transmit the data with different QoS via a single IPsec tunnel; and the user profile enables the UE to transmit the data with different QoS via the IPsec tunnel.

[0086] Clause 15. The method according to Clause 14, further comprising: re-evaluating the plurality of conditions when another IPsec tunnel is established, when an existing IPsec tunnel is deleted, or at a predetermined time interval.

[0087] Clause 16. A wireless communication device comprising a processor and a radio communication interface, the wireless communication device being configured to implement the method according to any one of Clauses 1 to 10, 13, and 14.

[0088] Clause 17. A network node comprising a processor and a modem, the network node being configured to implement the method according to any one of Clauses 1 to 10, 14, and 15.

[0089] Another innovative aspect of the subject matter described in this disclosure can be implemented as a wireless communication device of a UE. The wireless communication device can include at least one interface and a processing system communicatively coupled to the at least one interface. The processing system can be configured to implement any one of the above clauses.

[0090] Another innovative aspect of the subject matter described in this disclosure can be implemented as a portable electronic device, which includes a wireless communication device, a plurality of antennas coupled to at least one transceiver to wirelessly transmit signals output from the at least one transceiver, and a housing surrounding at least a portion of the wireless communication device, the at least one transceiver, and the plurality of antennas. The wireless communication device can include at least one interface and a processing system communicatively coupled to the at least one interface. The processing system can be configured to implement any one of the above clauses.

[0091] Another innovative aspect of the subject matter described in this disclosure can be implemented as a machine-readable medium having processor-readable instructions stored therein, which, when executed by a processing system of a UE, cause the UE to implement any one of the above clauses.

[0092] Another innovative aspect of the subject matter described in this disclosure can be implemented as a device. The device can include components for implementing any one of the above clauses.

[0093] As used herein, the term "component" is intended to be broadly interpreted as hardware, firmware, or a combination of hardware and software. As used herein, a processor is implemented in hardware, firmware, or a combination of hardware and software. As used herein, the phrase "based on" is intended to be broadly interpreted to mean "at least partially based on".

[0094] Some aspects are described herein in connection with a threshold. As used herein, meeting a threshold can refer to a value being greater than the threshold, greater than or equal to the threshold, less than the threshold, less than or equal to the threshold, equal to the threshold, not equal to the threshold, etc.

[0095] As used herein, a phrase referring to "at least one of" or "one or more of" a list of items refers to any combination of those items, including a single member. For example, "at least one of the following: a, b, or c" is intended to cover the possibilities of only a, only b, only c, a combination of a and b, a combination of a and c, a combination of b and c, and a combination of a, b, and c.

[0096] In this disclosure, the term "can" indicates ability, or alternatively indicates possible implementation options. The term "may" indicates permission, or alternatively indicates possible implementation options. The term "might" indicates a possible utilization of implementation options.

[0097] The various illustrative components, logics, logic blocks, modules, circuits, operations, and algorithmic processes described in connection with the implementations disclosed herein can be implemented as electronic hardware, firmware, software, or any combination of hardware, firmware, or software, including the structures disclosed herein and their structural equivalents. The interchangeability of hardware, firmware, and software has been described generally in terms of functionality and illustrated in the various illustrative components, blocks, modules, circuits, and processes described above. Whether such functionality is implemented in hardware, firmware, or software depends upon the particular application and design constraints imposed on the overall system.

[0098] The hardware and data processing devices for implementing the various illustrative components, logics, logic blocks, modules, and circuits described in connection with the aspects disclosed herein can be realized or executed using a general-purpose single-chip or multi-chip processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic device (PLD), discrete gate or transistor logic, discrete hardware components, or any combination thereof, which are designed to perform the functions described herein. The general-purpose processor can be a microprocessor, or any conventional processor, controller, microcontroller, or state machine. The processor can also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. In some implementations, specific processes, operations, and methods can be performed by circuitry specific to a given function.

[0099] As described above, in some aspects, the implementations of the subject matter described in this specification can be implemented as software. For example, the various functions of the components disclosed herein, or the various boxes or steps of the methods, operations, processes, or algorithms disclosed herein, can be implemented as one or more modules of one or more computer programs. Such computer programs can include non-transitory processor-executable instructions or computer-executable instructions encoded on one or more tangible processor-readable storage media or computer-readable storage media for execution by, or to control the operation of, a data processing device including the components of the apparatus described herein. By way of example, and not limitation, such storage media can include RAM, ROM, EEPROM, CD-ROM, or other optical disk storage, magnetic disk storage, or other magnetic storage devices, or any other medium that can be used to store program code in the form of instructions or data structures. Combinations of the above should also be included within the scope of storage media.

[0100] As used herein, the terms "user equipment", "wireless communication device", "mobile communication device", "communication device", or "mobile device" refer to any one or all of a cellular phone, smartphone, portable computing device, personal or mobile multimedia player, laptop computer, tablet computer, smartbook, Internet of Things (IoT) device, palmtop computer, wireless email receiver, cellular phone supporting multimedia Internet, wireless game controller, display subsystem, driver assistance system, vehicle controller, vehicle system controller, vehicle communication system, infotainment system, vehicle telematics system or subsystem, vehicle display system or subsystem, vehicle data controller or router, and similar electronic devices including a programmable processor, memory, and circuitry configured to perform the operations described herein.

[0101] As used herein, the terms "SIM", "SIM card", and "subscriber identity module" are used interchangeably to refer to a memory that may be an integrated circuit or embedded in a removable card and stores an International Mobile Subscriber Identity (IMSI), associated keys, or other information for identifying or authenticating a mobile communication device on a network and enabling communication services with the network. Since the information stored in the SIM enables the mobile communication device to establish a communication link with a specific network for specific communication services, the term "subscription" is used herein as a shorthand reference to refer to the communication services associated with and enabled by the information stored in a specific SIM, as the SIM and the communication network and the services and subscriptions supported by the network are related to each other. The SIM used in various examples may contain user account information, an International Mobile Subscriber Identity (IMSI), a set of SIM Application Toolkit (SAT) commands, and storage space for phonebook contacts. The SIM card may also store home identifiers (such as a System Identification Number (SID) / Network Identification Number (NID) pair, a Home Public Land Mobile Number (HPLMN) code, etc.) to indicate the SIM card network operator provider. An Integrated Circuit Card Identification (ICCID) SIM serial number may be printed on the SIM card for identification. However, the SIM may be implemented within a portion of the memory of the mobile communication device and thus does not need to be a separate or removable circuit, chip, or card.

[0102] Various modifications to the implementations described in this disclosure may be apparent to those skilled in the art, and the general principles defined herein may be applied to other implementations without departing from the spirit or scope of the disclosure. Therefore, the claims are not intended to be limited to the implementations shown herein but are accorded the widest scope consistent with the disclosure, the principles disclosed herein, and the novel features.

[0103] In addition, various features described in the context of separate implementations in this specification can also be implemented in combination in a single implementation. Conversely, each feature described in the context of a single implementation can also be implemented separately or in any suitable sub-combination in multiple implementations. Thus, although the features may have been described above as acting in a particular combination and even initially claimed as such, in some cases one or more features from the claimed combination can be deleted from the combination, and the claimed combination can cover a sub-combination or a variant of a sub-combination.

[0104] Similarly, although operations are depicted in the figures in a particular order, this should not be construed as requiring that such operations be performed in the particular order shown or in a sequential order, or that all of the illustrated operations be performed to achieve the desired result. Additionally, the figures may schematically depict one or more example processes in the form of a flowchart or a flow diagram. However, other operations not depicted can be incorporated into the example processes schematically shown. For example, one or more additional operations can be performed before, after, concurrently with, or between any of the illustrated operations. In some cases, multitasking and parallel processing may be advantageous. Moreover, the separation of the various system components in the implementations described above should not be construed as requiring such separation in all implementations, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products. Additionally, other implementations are within the scope of the appended claims. In some cases, the acts recited in the claims can be performed in a different order and still achieve the desired result.

Claims

1. A method for generating a datagram of a protocol data unit (PDU) session between a user equipment (UE) and a fifth generation core network (5GC), the method comprises: establishing an Internet Protocol Security (IPsec) tunnel over a non-Third Generation Partnership Project (non-3GPP) access network; generating a first datagram to convey a first encrypted PDU, the first datagram including a first outer Internet Protocol (IP) header; setting a first Differentiated Services Code Point (DSCP) value of the first outer IP header to match a second DSCP value of the first encrypted PDU; and sending the first datagram via the IPsec tunnel in the non-3GPP access network.

2. The method according to claim 1, wherein setting the first DSCP value comprises: when the non-3GPP access network has not provided any DSCP value for the IPsec tunnel, assigning the first DSCP value to match the second DSCP value.

3. The method according to any one of claims 1 to 2, wherein the first DSCP value indicates a first Quality of Service (QoS) of a first data flow between the UE and the 5GC.

4. The method according to any one of claims 1 to 3, wherein the first datagram comprises: an encrypted portion, the encrypted portion including an IPsec packet having a Generic Routing Encapsulation (GRE) packet encapsulating the first encrypted PDU, and an unencrypted header, the unencrypted header including an IPsec header as the first outer IP header.

5. The method according to any one of claims 1 to 4, wherein the IPsec tunnel is identified by a sub-Security Association (SA) of an IPsec SA created for the PDU session.

6. The method according to any one of claims 1 to 5, wherein the first datagram is sent or received by a non-3GPP Interworking Function (N3IWF) of the non-3GPP access network or a Trusted non-3GPP Gateway Function (TNGF) of the non-3GPP access network.

7. The method according to any one of claims 1 to 6, wherein setting the first DSCP value includes verifying that at least one criterion is met, wherein the at least one criterion includes at least one of the following: the IPsec tunnel is the only IPsec tunnel between the UE and the non-3GPP access network for the PDU session, the non-3GPP access network has not provided any DSCP value for the IPsec tunnel, the non-3GPP access network has provided a DSCP value equal to zero for the IPsec tunnel, the UE is configured to send multiple encrypted PDUs with different QoS via the IPsec tunnel, or a user profile enables the UE to send the multiple encrypted PDUs with different QoS via the IPsec tunnel.

8. The method according to any one of claims 1 to 7, further comprises: Generate a second datagram to convey the second encrypted PDU, the second datagram including a second outer IP header having a third DSCP value that matches a fourth DSCP value corresponding to the second encrypted PDU, the first DSCP value being different from the third DSCP value; and Transmit the second datagram via the IPsec tunnel in the non-3GPP access network such that the same IPsec tunnel carries both the first datagram and the second datagram using QoS differentiation based on the first DSCP value and the third DSCP value.

9. A method for optimizing the transmission of data with different Quality of Service (QoS) between a User Equipment (UE) and a Fifth Generation Core Network (5GC) via a non-Third Generation Partnership Project (non-3GPP) access network, the method comprises: Transmit data between the UE and the 5GC via the non-3GPP access network according to a first QoS via an IPsec tunnel associated with a PDU session; and Upon receiving a request to transmit the data according to a second QoS different from the first QoS: Transmit the data according to the first QoS and according to the second QoS via the IPsec tunnel by respectively inserting a first Differentiated Services Code Point (DSCP) value and a second DSCP value into an outer IP header; or Establish another IPsec tunnel for transmitting the data according to the second QoS.

10. The method according to claim 9, further comprises: Determine to transmit the data via the IPsec tunnel rather than establish another IPsec tunnel based on one or more conditions, the one or more conditions including: The non-3GPP access network enables only one IPsec tunnel for the PDU session; The non-3GPP access network does not provide a DSCP value associated with the IPsec tunnel; The non-3GPP access network associates a predetermined DSCP value with the IPsec tunnel, the predetermined value indicating the ability to use the IPsec tunnel for different QoS; The UE is configured to transmit the data with different QoS via a single IPsec tunnel; or The user profile enables the UE to transmit the data with different QoS via the IPsec tunnel.

11. The method according to claim 10, further comprises: Re-evaluate the one or more conditions when another IPsec tunnel is established, when the existing IPsec tunnel is deleted, or at a predetermined time interval.

12. A device, comprises: A modem; and A processor configured to control the modem to implement the method according to any one of claims 1 to 11.