Method and apparatus for network assisted security establishment supporting relay between user equipments

By receiving the direct communication security request message from the target UE in the wireless communication system, and sending a reject message to abort link establishment when the key request fails, the network assisted security establishment difficulty of inter-UE relay communication is solved and communication security is ensured.

CN120224490AActive Publication Date: 2025-06-27ASUS TECH LICENSING INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411857441.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-26
Filing Date
2024-12-17
Publication Date
2025-06-27
Estimated Expiration
2044-12-17

AI Technical Summary

Technical Problem

In wireless communication systems, there are difficulties in establishing network assisted security for inter-UE relay communication, especially when the key requesting program fails, the system is difficult to effectively handle, resulting in a threat to communication security.

Method used

By relaying the UE to receive the direct communication security request message from the target UE, if the key request program fails, a direct communication security rejection message will be sent, and the direct link establishment program will be aborted to ensure communication security.

Benefits of technology

It effectively solves the communication security problem caused by the failure of key request, and ensures the security and stability of inter-UE relay communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120224490A_ABST
    Figure CN120224490A_ABST
Patent Text Reader

Abstract

A method and apparatus for supporting network assisted security setup of relay between user equipments is disclosed. In one embodiment, a relay user equipment receives, from a source user equipment, a first direct communication request message to establish an inter-user equipment relay communication with a target user equipment. The relay user equipment also sends a second direct communication request message to the target-end user equipment in a direct link establishment procedure for establishing a direct link supporting relay communication between the user equipment. The relay user equipment also receives, from the target user equipment, a direct communication security request message that triggers the relay user equipment to perform a key request procedure with the network. In addition, if the key request procedure with the network fails, the relay user equipment sends a direct communication security rejection message to the target-end user equipment. Further, the relay user equipment aborts the direct link setup procedure after sending the direct communication security rejection message.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - Reference to Related Applications

[0002] This application claims the benefit of U.S. Provisional Patent Application No. 63 / 614,718, filed on December 26, 2023, the entire disclosure of which is incorporated herein by reference in its entirety. Technical Field

[0003] This disclosure generally relates to wireless communication networks, and more particularly, to methods and apparatuses for supporting network - assisted security establishment in UE - to - UE relay in a wireless communication system. Background Art

[0004] With the rapid growth in the demand for transmitting large amounts of data to and from mobile communication devices, traditional mobile voice communication networks have evolved into networks that communicate using Internet Protocol (IP) data packets. Such IP packet communication can provide IP - bearer voice, multimedia, multicast, and on - demand communication services to users of mobile communication devices.

[0005] An exemplary network structure is the Evolved Universal Terrestrial Radio Access Network (E - UTRAN). The E - UTRAN system can provide high data throughput to enable the above - mentioned IP - bearer voice and multimedia services. Currently, the 3GPP standards organization is discussing new next - generation (e.g., 5G) radio technologies. Thus, changes to the current body of the 3GPP standards are currently being submitted and considered to evolve and complete the 3GPP standards. Summary of the Invention

[0006] A method and apparatus for relaying a User Equipment (UE) are disclosed. In one embodiment, the relay UE receives a first direct communication request message from a source UE to establish UE - to - UE (U2U) relay communication with a target UE. The relay UE also sends a second direct communication request message to the target UE in a direct - link establishment procedure for establishing a direct link to support the U2U relay communication. The relay UE also receives a direct communication security request message from the target UE that triggers the relay UE to execute a key request procedure with the network. Additionally, if the key request procedure with the network fails, the relay UE sends a direct communication security rejection message to the target UE. Further, after sending the direct communication security rejection message, the relay UE aborts the direct - link establishment procedure. Brief Description of the Drawings

[0007] Figure 1 Drawing showing a wireless communication system according to an exemplary embodiment.

[0008] Figure 2 Block diagram of a transmitter system (also referred to as an access network) and a receiver system (also referred to as a user equipment or UE) according to an exemplary embodiment.

[0009] Figure 3 Functional block diagram of a communication system according to an exemplary embodiment.

[0010] Figure 4 According to an exemplary embodiment Figure 3 Functional block diagram of the program code of

[0011] Figure 5 Reproduction of 3GPP R2-2314074's Figure 16 .12.2.x-1, 3GPP TS23.304 V18.4.0's Figure 6 .4.3.1-1.

[0012] Figure 6 Reproduction of 3GPP R2-2314074's Figure 16 .12.2.x-2, 3GPP TS23.304 V18.4.0's Figure 6 .7.1.1-1.

[0013] Figure 7 Reproduction of 3GPP R2-2314074's Figure 16 .12.x-1, 3GPP TS24.554 V18.2.0's Figure 7 .2.2.2.1.

[0014] Figure 8 Reproduction of 3GPP R2-2314014's Figure 5 .8.9.1.1-1, 3GPP TS24.554 V18.2.0's Figure 7 .2.2.2.2.

[0015] Figure 9 Reproduction of 3GPP R2-2314014's Figure 5 .8.9.1.1-2, 3GPP TS24.554 V18.2.0's Figure 7 .2.10.2.1.

[0016] Figure 10 Reproduction of 3GPP R2-2314014's Figure 5 .8.9.8.1-1, 3GPP TS24.554 V18.2.0'sFigure 8 . Reproduction of 2.10.2.4.2.1

[0017] Figure 11 It is of 3GPP TS 33.503 V18.0.0 Figure 6 . Reproduction of 3.3.2.2 - 1

[0018] Figure 12 It is of 3GPP TS 33.503 V18.0.0 Figure 6 . Reproduction of 6.3.1 - 1

[0019] Figure 13 It is of 3GPP C1 - 238124 Figure 8 . Reproduction of a.2.x.2.1

[0020] Figure 14 Shows an example of the step - by - step process of network - unaided PC5 security establishment for U2U relay communication based on relevant standards according to an exemplary embodiment.

[0021] Figure 15A Shows an example of the step - by - step process of successfully network - aided PC5 security establishment for U2U relay communication based on relevant standards according to an exemplary embodiment.

[0022] Figure 15B Shows an example of the step - by - step process of unsuccessfully network - aided PC5 security establishment for U2U relay communication based on relevant standards according to an exemplary embodiment.

[0023] Figure 16 Shows an example of a potential way forward followed by subsequent actions of sending a direct communication security rejection.

[0024] Figure 17 Shows an example of potential problems according to an exemplary embodiment.

[0025] Figure 18 Shows, according to an exemplary embodiment, for solving Figure 17 Examples of possible solutions to the problems shown.

[0026] Figure 19 It is a flowchart according to an exemplary embodiment.

[0027] Figure 20 It is a flowchart according to an exemplary embodiment.

[0028] Figure 21 It is a flowchart according to an exemplary embodiment.

[0029] Figure 22It is a flowchart according to an exemplary embodiment. Detailed implementation

[0030] The exemplary wireless communication systems and devices described below employ a wireless communication system that supports broadcast services. Wireless communication systems are widely deployed to provide various types of communications, such as voice, data, and so on. These systems may be based on code division multiple access (CDMA), time division multiple access (TDMA), orthogonal frequency division multiple access (OFDMA), 3GPP Long Term Evolution (LTE) radio access, 3GPP Long Term Evolution Advanced (LTE-A or LTE-Advanced), 3GPP2 Ultra Mobile Broadband (UMB), WiMax, 3GPP New Radio (NR), or some other modulation techniques.

[0031] Specifically, the exemplary wireless communication systems and devices described below may be designed to support one or more standards, such as those provided by an association named "Third Generation Partnership Project" (referred to herein as 3GPP), including: TS23.304 V18.4.0, "Proximity based Service (ProSe) in 5G System (5GS) (Release 18)"; TS24.554 V18.2.0, "Proximity-service (ProSe) in 5G System (5GS) Protocol Aspects; Phase 3 (Release 18)"; TS 33.503 V18.0.0, "Security Aspects of Proximity based Service (ProSe) in 5G System (5GS) (Release 18)"; and C1-238124, "5G ProSe UE-to-UE Relay Direct Link Security Establishment Procedure", Xiaomi. The standards and documents listed above are hereby expressly incorporated herein by reference in their entirety.

[0032] Figure 1 A multi-access wireless communication system according to an embodiment of the present invention is shown. The access network 100 (access network, AN) includes multiple antenna groups, where one antenna group includes 104 and 106, another antenna group includes 108 and 110, and yet another antenna group includes 112 and 114. In Figure 1In this figure, only two antennas are shown for each antenna group. However, each antenna group can utilize more or fewer antennas. The access terminal 116 (AT) communicates with antennas 112 and 114, where antennas 112 and 114 transmit information to the access terminal 116 via the forward link 120 and receive information from the access terminal 116 via the reverse link 118. The access terminal (AT) 122 communicates with antennas 106 and 108, where antennas 106 and 108 transmit information to the access terminal (AT) 122 via the forward link 126 and receive information from the access terminal (AT) 122 via the reverse link 124. In an FDD system, the communication links 118, 120, 124, and 126 can communicate using different frequencies. For example, the forward link 120 can use a frequency different from the frequency used by the reverse link 118.

[0033] Each antenna group and / or the area in which the antenna group is designed to communicate is often referred to as a sector of the access network. In an embodiment, each antenna group is designed to communicate with access terminals in a sector of the area covered by the access network 100.

[0034] In the communication via the forward links 120 and 126, the transmitting antennas of the access network 100 can utilize beamforming to improve the signal-to-noise ratio of the forward links for different access terminals 116 and 122. In addition, compared to an access network that transmits to all its access terminals via a single antenna, an access network that uses beamforming to transmit to access terminals randomly dispersed in its coverage causes less interference to the access terminals in adjacent cells.

[0035] The access network (AN) can be a fixed station or a base station for communicating with terminals and can also be referred to as an access point, NodeB, base station, enhanced base station, evolved Node B (eNB), network node, network, or some other term. The access terminal (AT) can also be referred to as a user equipment (UE), wireless communication device, terminal, access terminal, or some other term.

[0036] Figure 2 is a simplified block diagram of an embodiment of a transmitter system 210 (also referred to as an access network) and a receiver system 250 (also referred to as an access terminal (AT) or user equipment (UE)) in a MIMO system 200. At the transmitter system 210, traffic data for multiple data streams is provided from a data source 212 to a transmit (TX) data processor 214.

[0037] In one embodiment, each data stream is transmitted via a respective transmit antenna. The TX data processor 214 formats, encodes, and interleaves the traffic data for the data stream based on a particular decoding scheme selected for each data stream to provide encoded data.

[0038] The encoded data for each data stream can be multiplexed with pilot data using OFDM techniques. Pilot data is typically a known data pattern that is processed in a known manner and can be used at the receiver system to estimate the channel response. Then, the multiplexed pilot data and the encoded data for the data stream can be modulated (i.e., symbol mapped) based on a particular modulation scheme selected for each data stream (e.g., BPSK, QPSK, M-PK, or M-QAM) to provide modulated symbols. The data rate, encoding, and modulation for each data stream can be determined by instructions executed by the processor 230.

[0039] Next, the modulated symbols for all data streams are provided to the TX MIMO processor 220, which can further process the modulated symbols (e.g., for OFDM). Then, the TX MIMO processor 220 provides N T streams of modulated symbols to N T transmitters (TMTR) 222a through 222t. In some embodiments, the TX MIMO processor 220 applies beamforming weights to the symbols of the data stream and the antennas from which the symbols are transmitted.

[0040] Each transmitter 222 receives and processes the respective symbol stream to provide one or more analog signals, and further conditions the analog signals (e.g., amplifies, filters, and upconverts) to provide a modulated signal suitable for transmission over the MIMO channel. Then, N T modulated signals from transmitters 222a through 222t are transmitted from N T antennas 224a through 224t.

[0041] At the receiver system 250, the transmitted modulated signals are received by N R antennas 252a through 252r, and the signals received from each antenna 252 are provided to a respective receiver (RCVR) 254a through 254r. Each receiver 254 conditions the respective received signal (e.g., filters, amplifies, and downconverts), digitizes the conditioned signal to provide samples, and further processes the samples to provide a corresponding "received" symbol stream.

[0042] Next, the RX data processor 260 receives from N RA receiver 254 receives N R symbol streams and processes the N R received symbol streams based on specific receiver processing techniques to provide N T "detected" symbol streams. Subsequently, the RX data processor 260 demodulates, deinterleaves, and decodes each detected symbol stream to recover the service data for the data stream. The processing performed by the RX data processor 260 is complementary to the processing performed by the TX MIMO processor 220 and the TX data processor 214 at the transmitter system 210.

[0043] The processor 270 periodically determines which precoding matrix (discussed below) to use. The processor 270 formulates a reverse link message that includes a matrix index portion and a rank value portion.

[0044] The reverse link message can include various types of information about the communication link and / or the received data streams. Subsequently, the reverse link message is processed by the TX data processor 238 (which also receives service data for several data streams from the data source 236), modulated by the modulator 280, conditioned by the transmitters 254a to 254r, and transmitted back to the transmitter system 210.

[0045] At the transmitter system 210, the modulated signal from the receiver system 250 is received by the antenna 224, conditioned by the receiver 222, demodulated by the demodulator 240, and processed by the RX data processor 242 to extract the reverse link message transmitted by the receiver system 250. Subsequently, the processor 230 determines which precoding matrix to use to determine the beamforming weights and then processes the extracted message.

[0046] Turning now to Figure 3 , this figure shows an alternative simplified functional block diagram of a communication device according to an embodiment of the present invention. As Figure 3 shown, the UE (or AT) 116 and 122 in Figure 1 or Figure 1a base station (or AN) 100 in, and the wireless communication system is preferably an NR system. The communication device 300 may include an input device 302, an output device 304, a control circuit 306, a central processing unit (CPU) 308, a memory 310, program code 312, and a transceiver 314. The control circuit 306 executes the program code 312 in the memory 310 through the CPU 308, thereby controlling the operation of the communication device 300. The communication device 300 may receive signals input by a user through the input device 302 (such as a keyboard or keypad), and may output images and sounds through the output device 304 (such as a monitor or speaker). The transceiver 314 is used to receive and transmit wireless signals, transfer the received signals to the control circuit 306, and wirelessly output the signals generated by the control circuit 306. The communication device 300 in the wireless communication system may also be used to implement Figure 1 the AN 100 in.

[0047] Figure 4 is according to an embodiment of the present invention Figure 3 a simplified block diagram of the program code 312 shown in. In this embodiment, the program code 312 includes an application layer 400, a layer 3 part 402, and a layer 2 part 404, and is coupled to a layer 1 part 406. The layer 3 part 402 generally performs radio resource control. The layer 2 part 404 generally performs link control. The layer 1 part 406 generally performs physical connection.

[0048] 3GPP 23.304 introduces some procedures related to unicast link communication as follows:

[0049] 6.4.3.1 Layer 2 link establishment through the PC5 reference point

[0050] To perform unicast mode ProSe direct communication through the PC5 reference point, the UE is configured with the relevant information as described in Section 5.1.3.

[0051] Figure 6 .4.3.1-1 shows the layer 2 link establishment procedure for unicast mode ProSe direct communication through the PC5 reference point.

[0052] [The name of 3GPP TS23.304 V18.4.0 is "Layer 2 Link Establishment Procedure" Figure 6 .4.3.1-1 is reproduced as Figure 5

[0053] 1. The UE determines the destination layer 2 ID for signaling reception for PC5 unicast link establishment, as specified in Section 5.8.2.4.

[0054] ​2. The ProSe application layer in UE-1 provides application information for PC5 unicast communication. The application information includes ProSe service information and the application layer ID of the UE. The application information may include the application layer ID of the target UE.

[0055] The ProSe application layer in UE-1 may provide ProSe application requirements for this unicast communication. UE-1 determines the PC5 QoS parameters and PFI as specified in Section 5.6.1.

[0056] If UE-1 decides to reuse an existing PC5 unicast link as specified in Section 5.3.4, UE triggers the layer 2 link modification procedure as specified in Section 6.4.3.4.

[0057] 3. UE-1 sends a direct communication request message to initiate the unicast layer 2 link establishment procedure. The direct communication request message includes:

[0058] - Source user information: The application layer ID of the initiating UE (i.e., the application layer ID of UE-1).

[0059] - If the ProSe application layer provides the application layer ID of the target UE in step 2, it includes the following information:

[0060] - Target user information: The application layer ID of the target UE (i.e., the application layer ID of UE-2).

[0061] - ProSe service information: Information about the ProSe identifier for which the layer 2 link establishment is requested.

[0062] - Security information: Information for establishing security.

[0063] Note 1: The security information and the necessary protection for the source user information and the target user information are defined in TS 33.503

[29] .

[0064] The source layer 2 ID and the destination layer 2 ID for sending the direct communication request message are determined as specified in Sections 5.8.2.1 and 5.8.2.4. The destination layer 2 ID can be a broadcast or unicast layer 2 ID. When using a unicast layer 2 ID, the target user information will be included in the direct communication request message.

[0065] UE-1 sends the direct communication request message via PC5 broadcast or unicast using the source layer 2 ID and the destination layer 2 ID.

[0066] The preconfigured PC5 DRX configuration can be used for transmitting and receiving this message (see TS 38.300

[12] ).

[0067] 4. Security with UE-1 is established as follows:

[0068] 4a. If the target user information is included in the direct communication request message, the target UE (i.e., UE-2) responds by establishing security with UE-1.

[0069] 4b. If the target user information is not included in the direct communication request message, the UE interested in using the notified ProSe service over the PC5 unicast link with UE-1 responds by establishing security with UE-1.

[0070] Note 2: Signaling for the security procedures is defined in TS 33.503

[29] .

[0071] When security protection is enabled, UE-1 sends the following information to the target UE:

[0072] - If using IP communication, then:

[0073] - IP address configuration: For IP communication, this link requires IP address configuration, and the IP address configuration indicates one of the following values:

[0074] - "DHCPv4 server", provided that only the IPv4 address allocation mechanism is supported by the initiating UE, i.e., acting as a DHCPv4 server; or

[0075] - "IPv6 router", provided that only the IPv6 address allocation mechanism is supported by the initiating UE, i.e., acting as an IPv6 router; or

[0076] - "DHCPv4 server and IPv6 router", provided that both IPv4 and IPv6 address allocation mechanisms are supported by the initiating UE; or

[0077] - "Address allocation not supported", provided that neither the IPv4 nor the IPv6 address allocation mechanism is supported by the initiating UE.

[0078] - Link-local IPv6 address: If UE-1 does not support the IPv6 IP address allocation mechanism, i.e., the IP address configuration indicates "address allocation not supported", a link-local IPv6 address is formed locally based on RFC 4862

[17] .

[0079] - QoS information: Information about the PC5 QoS flow. For each PC5 QoS flow, PFI and the corresponding PC5 QoS parameters (i.e., PQI and optionally other parameters such as MFBR / GFBR, etc.) and optionally the associated ProSe identifier.

[0080] - Optional PC5 QoS rules.

[0081] Determine the source Layer 2 ID for the security establishment procedure as specified in Sections 5.8.2.1 and 5.8.2.4. The destination Layer 2 ID is set to the source Layer 2 ID of the received direct communication request message.

[0082] After receiving the security establishment procedure message, UE-1 obtains the Layer 2 ID of the peer UE for signaling and data traffic for this unicast link for future communication.

[0083] 5. The target UE that has successfully established security with UE-1 sends a direct communication acceptance message to UE-1:

[0084] 5a. (UE-oriented Layer 2 link establishment) If the direct communication request message contains target user information, the target UE (i.e., UE-2) responds with a direct communication acceptance message when the application layer ID for UE-2 matches.

[0085] 5b. (ProSe service-oriented Layer 2 link establishment) If the direct communication request message does not contain target user information, the UE interested in using the notified ProSe service (UE-2 and UE-4 in Figure 6 .4.3.1-1) responds to the request by sending a direct communication acceptance message.

[0086] The direct communication acceptance message contains:

[0087] - Source user information: The application layer ID of the UE sending the direct communication acceptance message.

[0088] - QoS information: Information about the PC5 QoS flow. For each PC5 QoS flow, the PFI requested by UE-1 and the corresponding PC5 QoS parameters (i.e., PQI and optionally other parameters such as MFBR / GFBR etc.) and optionally the associated ProSe identifier.

[0089] - Optional PC5 QoS rules.

[0090] - If using IP communication, then:

[0091] - IP address configuration: For IP communication, this link requires IP address configuration, and the IP address configuration indicates one of the following values:

[0092] - "DHCPv4 server", provided that only the IPv4 address allocation mechanism is supported by the target UE, i.e., acting as a DHCPv4 server; or

[0093] - "IPv6 router", provided that only the IPv6 address allocation mechanism is supported by the target UE, i.e., acting as an IPv6 router; or

[0094] - "DHCPv4 Server and IPv6 Router", provided that both the IPv4 and IPv6 address allocation mechanisms are supported by the target UE; or

[0095] - "Address Allocation Not Supported", provided that neither the IPv4 nor the IPv6 address allocation mechanism is supported by the target UE.

[0096] - Link-Local IPv6 Address: If the target UE does not support the IPv6 IP address allocation mechanism, i.e., the IP address configuration indicates "Address Allocation Not Supported" and UE-1 contains the link-local IPv6 address established for security in step 4, then the link-local IPv6 address is formed locally based on RFC4862

[17] . The target UE will contain a non-conflicting link-local IPv6 address.

[0097] If two UEs (i.e., the initiating UE and the target UE) are selected to use the link-local IPv6 address, then these two UEs will deactivate the duplicate address detection defined in RFC 4862

[17] .

[0098] Note 3: When the initiating UE or the target UE indicates support for IPv6 routing, the corresponding address configuration procedure will be performed after the layer 2 link is established, and the link-local IPv6 address will be ignored.

[0099] The ProSe layer of the UE that establishes the PC5 unicast link will assign the PC5 link identifier for the unicast link and the PC5 unicast link-related information and pass them down to the AS layer. The PC5 unicast link-related information includes layer 2 ID information (i.e., the source layer 2 ID and the destination layer 2 ID). This enables the AS layer to maintain the PC5 link identifier and the PC5 unicast link-related information.

[0100] Two UEs can negotiate the PC5 DRX configuration in the AS layer, and the PC5 DRX parameter values can be configured for each pair of source and destination layer 2 IDs in the AS layer.

[0101] 6. Transmit ProSe data through the established unicast link as follows:

[0102] The PC5 link identifier and the PFI are provided to the AS layer together with the ProSe data.

[0103] In addition, optionally, the layer 2 ID information (i.e., the source layer 2 ID and the destination layer 2 ID) is provided to the AS layer.

[0104] Note 4: The UE implementation scheme provides the layer 2 ID information to the AS layer.

[0105] UE-1 sends ProSe data using the source layer 2 ID (i.e., the layer 2 ID of UE-1 for this unicast link) and the destination layer 2 ID (i.e., the layer 2 ID of the peer UE for this unicast link).

[0106] Note 5: The PC5 unicast link is bidirectional, so the peer UE of UE-1 can send ProSe data to UE-1 via the unicast link with UE-1.

[0107] […]

[0108] 6.7.1 5G ProSe Communication via 5G ProSe Layer 3 UE-to-UE Relay

[0109] 6.7.1.1 Layer 2 Link Establishment for PC5 Communication via 5G ProSe Layer 3 UE-to-UE Relay

[0110] Figure 6 .7.1.1-1 shows the procedure for layer 2 link establishment for 5G ProSe layer 3 UE-to-UE relay.

[0111] [The one named "Layer 2 Link Establishment for 5G ProSe Layer 3 UE-to-UE Relay" in 3GPP TS23.304 V18.4.0 Figure 6 .7.1.1-1 is reproduced as Figure 6

[0112] 1. Perform service authorization and provisioning for the source 5G ProSe layer 3 end UE, the target 5G ProSe layer 3 end UE, and the 5G ProSe layer 3 UE-to-UE relay, as described in Section 6.2.

[0113] 2. The source 5G ProSe layer 3 end UE performs discovery of the 5G ProSe layer 3 UE-to-UE relay, as described in Section 6.3.2.4.

[0114] 3. The source 5G ProSe layer 3 end UE sends a direct communication request message to initiate the unicast layer 2 link establishment procedure using the 5G ProSe layer 3 UE-to-UE relay. The parameters included in the direct communication request message are described in Section 6.4.3.7.

[0115] The source layer 2 ID of the direct communication request message is assigned by the source 5G ProSe layer 3 end UE itself, and the destination layer 2 ID is set to the source layer 2 ID of the discovery message of the 5G ProSe layer 3 UE-to-UE relay.

[0116] The source 5G ProSe layer 3 end UE obtains application information and optional ProSe application requirements from the ProSe application layer and determines the end-to-end QoS parameters, as described in Section 5.6.3.1. ​

[0117] 4. If the user information ID of the 5G ProSe layer 3 inter-UE relay in the direct communication request message matches the user information ID of the 5G ProSe inter-UE relay and the RSC in the direct communication request matches one of the (pre)-configured RSCs of the relay, as specified in Section 5.1.5.1, the 5G ProSe layer 3 inter-UE relay responds by establishing security with the source 5G ProSe layer 3 end UE. When security protection is enabled, the source 5G ProSe layer 3 end UE sends the parameters as described in Section 6.4.3.7 to the 5G ProSe layer 3 inter-UE relay.

[0118] If the Ethernet MAC address of the source 5G ProSe layer 3 end UE has been used by another 5G ProSe layer 3 end UE, the 5G ProSe layer 3 inter-UE relay rejects the direct link establishment, indicating that the MAC address is not unique.

[0119] The source layer 2 ID for the security establishment procedure is assigned by the 5G ProSe layer 3 inter-UE relay itself, and the destination layer 2 ID is set to the source layer 2 ID of the received direct communication request message.

[0120] The 5G ProSe layer 3 inter-UE relay selects different source layer 2 IDs for the PC5 links for different types of services (i.e., IP service, Ethernet service, and unstructured service).

[0121] If the PC5 link is used to carry unstructured service, the 5G ProSe layer 3 inter-UE relay selects different source layer 2 IDs for different pairs of source and target 5G ProSe layer 3 end UEs.

[0122] After receiving the security establishment procedure message, the source 5G ProSe layer 3 end UE obtains the layer 2 ID of the 5G ProSe layer 3 inter-UE relay for the signaling and data services for this unicast link for future communication.

[0123] 5. After the security establishment procedure in step 4 is completed, the 5G ProSe layer 3 inter-UE relay sends a direct communication request message to initiate the unicast layer 2 link establishment procedure with the target 5G ProSe layer 3 end UE. The parameters included in the direct communication request message are described in Section 6.4.3.7.

[0124] The source layer 2 ID of the direct communication request message is assigned by the 5G ProSe layer 3 inter-UE relay itself, and the destination layer 2 ID is the unicast layer 2 ID of the target 5G ProSe layer 3 end UE associated with the user information ID of the target 5G ProSe layer 3 end UE.

[0125] The 5G ProSe layer 3 inter-UE relay selects different source layer 2 IDs for the PC5 link for different types of services, namely, IP services, Ethernet services, and unstructured services.

[0126] If the PC5 link is used to carry unstructured services, the 5G ProSe layer 3 inter-UE relay selects different source layer 2 IDs for different pairs of source and destination 5G ProSe layer 3 end UEs.

[0127] 6. If the user information ID and RSC of the destination 5G ProSe layer 3 end UE included in the direct communication request match the user information ID and the (pre)-configured RSC of the destination UE as specified in Section 5.1.5.1, the destination 5G ProSe layer 3 end UE responds by establishing security with the 5G ProSe layer 3 inter-UE relay. When security protection is enabled, the 5G ProSe layer 3 inter-UE relay sends the parameters as described in Section 6.4.3.7 to the destination 5G ProSe layer 3 end UE.

[0128] The source layer 2 ID for the security establishment procedure is assigned by the destination 5G ProSe layer 3 end UE itself, and the destination layer 2 ID is set to the source layer 2 ID of the received direct communication request message.

[0129] After receiving the security establishment procedure message, the 5G ProSe layer 3 inter-UE relay obtains the layer 2 ID of the destination 5G ProSe layer 3 end UE for signaling and data services for this unicast link for future communication.

[0130] 7. The destination 5G ProSe layer 3 end UE sends a direct communication acceptance message to the 5G ProSe layer 3 inter-UE relay with which security has been successfully established. The parameters included in the direct communication acceptance message are described in Section 6.4.3.7.

[0131] Note: When receiving the direct communication acceptance message, the 5G ProSe layer 3 inter-UE relay can detect that the Ethernet MAC address of the destination 5G ProSe layer 3 end UE has been used by another 5G ProSe layer 3 end UE.

[0132] 8. For IP services, an IPv6 prefix or an IPv4 address is assigned to the destination 5G ProSe layer 3 end UE as defined in Section 5.5.1.4.

[0133] 9. After receiving the direct communication acceptance message from the target 5G ProSe layer 3 UE, the 5G ProSe layer 3 UE - to - UE relay sends the direct communication acceptance message to the source 5G ProSe layer 3 UE with which security has been successfully established. The parameters included in the direct communication acceptance message are described in Section 6.4.3.7.

[0134] 10. For IP services, an IPv6 prefix or an IPv4 address is allocated to the source 5G ProSe layer 3 UE, as defined in Section 5.5.1.4.

[0135] 11. For IP communication, the 5G ProSe layer 3 UE - to - UE relay may store the association of the user information ID with the IP address of the target 5G ProSe layer 3 UE in its DNS entry, and the 5G ProSe layer 3 UE - to - UE relay can act as a DNS server for other UEs. If the IP address of the target 5G ProSe layer 3 UE is not received in step 9, the source 5G ProSe layer 3 UE may send a DNS query to the 5G ProSe layer 3 UE - to - UE relay after step 10 to request the IP address of the target 5G ProSe layer 3 UE, and the 5G ProSe layer 3 UE - to - UE relay will transmit the IP address of the target 5G ProSe layer 3 UE back to the source 5G ProSe layer 3 UE.

[0136] For Ethernet communication, the 5G ProSe layer 3 UE - to - UE relay maintains the association between the PC5 link and the Ethernet MAC address received from the 5G ProSe layer 3 UE.

[0137] For unstructured service communication, for each pair of source and target 5G ProSe layer 3 UEs, the 5G ProSe layer 3 UE - to - UE relay maintains a one - to - one mapping between the PC5 link and the source 5G ProSe layer 3 UE and between the PC5 link and the target 5G ProSe layer 3 UE.

[0138] 12. The source 5G ProSe layer 3 UE communicates with the target 5G ProSe layer 3 UE via the 5G ProSe layer 3 UE - to - UE relay.

[0139] In the case where a source 5G ProSe layer 3 UE communicates with multiple target 5G ProSe layer 3 UEs, according to the RSC, the PC5 link between the source 5G ProSe layer 3 UE and the relay between 5G ProSe layer 3 UEs can be shared among the multiple target 5G ProSe layer 3 UEs. At the same time, according to the RSC, the PC5 link can be individually established between the relay between 5G ProSe layer 3 UEs and the target 5G ProSe layer 3 UE. For the shared PC5 link, the layer 2 link modification procedure shall be used. The parameters used in the layer 2 link modification procedure are described in Section 6.4.3.7.

[0140] In the case where multiple source 5G ProSe layer 3 UEs communicate with a target 5G ProSe layer 3 UE, according to the RSC, the PC5 link between the relay between 5G ProSe layer 3 UEs and the target 5G ProSe layer 3 UE can be shared. At the same time, according to the RSC, the PC5 link can be individually established between the source 5G ProSe layer 3 UE and the relay between 5G ProSe layer 3 UEs. For the shared PC5 link, the layer 2 link modification procedure shall be used. The parameters used in the layer 2 link modification procedure are described in Section 6.4.3.7.

[0141] 3GPP 24.554 introduces some procedures related to unicast link communication as follows:

[0142] 7.2.2 5G ProSe direct link establishment procedure

[0143] 7.2.2.1 Overview

[0144] Depending on the type of 5G ProSe direct link establishment procedure (i.e., UE-oriented layer 2 link establishment or ProSe service-oriented layer 2 link establishment in 3GPP TS 23.304 [2]), the 5G ProSe direct link establishment procedure is used to establish a 5G ProSe direct link between two UEs or multiple 5G ProSe direct links between a UE and multiple target UEs. The UE that sends the request message is called the "initiating UE" and the other UE is called the "target UE". If the request message does not indicate a specific target UE (i.e., the target user information is not included in the request message) and multiple target UEs are interested in the ProSe application indicated in the request message, the initiating UE will process the corresponding response messages received from those target UEs. The maximum number of 5G ProSe direct links established in a UE each time shall not exceed the maximum number specific to the implementation plan of the established 5G ProSe direct links.

[0145] Note 1: The recommended maximum number of established 5G ProSe direct links is 8.

[0146] When the 5G ProSe direct link establishment procedure for a 5G ProSe layer 3 remote UE is successfully completed and if there is a PDU session established for relaying services of the 5G ProSe remote UE, the 5G ProSe layer 3 UE-to-network relay UE shall perform the remote UE reporting procedure as specified in 3GPP TS 24.501

[11] .

[0147] Note 2: A single PC5 unicast link is established between the 5G ProSe layer 2 UE-to-network relay UE and the 5G ProSe layer 2 remote UE to support the PDU session of the 5G ProSe layer 2 remote UE, as specified in 3GPP TS 38.300

[21] .

[0148] 7.2.2.2 Initiated by the initiating UE for the 5G ProSe direct link establishment procedure

[0149] The initiating UE shall meet the following preconditions before initiating this procedure:

[0150] a) The UE receives a request from the upper layer to transmit data packets for ProSe applications via PC5, a request from the lower layer, or in the case of 5G ProSe UE-to-UE relay, a ProSe direct link establishment request message or a ProSe direct link modification request message to trigger the ProSe direct link establishment;

[0151] b) The communication mode is unicast mode (e.g., preconfigured as specified in Section 5.2.4 or indicated by the upper layer);

[0152] c) The link layer identifier for the initiating UE (i.e., the layer 2 ID for unicast communication) is available (e.g., preconfigured or self-assigned) and not used by other existing 5G ProSe direct links within the initiating UE;

[0153] d) The link layer identifier for the destination UE (i.e., the unicast layer 2 ID or the broadcast layer 2 ID of the target UE) is available to the initiating UE (e.g., preconfigured, obtained as specified in Section 5.2, known via previous ProSe direct communication, or indicated by the lower layer);

[0154] Note 1: In the case where different ProSe applications are mapped to different preconfigured destination layer 2 IDs, when the initiating UE wishes to establish a single unicast link that can be used for more than one ProSe identifier, the UE can select any one of the preconfigured destination layer 2 IDs for unicast initial signaling.

[0155] e) The originating UE is authorized to perform 5G ProSe direct communication via PC5 in NR-PC5 in the serving PLMN, has a valid authorization to perform 5G ProSe direct communication via PC5 in NR-PC5 when not served by the NG-RAN, is authorized to use a 5G ProSe UE-to-network relay UE, is authorized to use a 5G ProSe UE-to-UE relay UE or is authorized to act as a 5G ProSe UE-to-UE relay UE. The UE considers that it is not served by the NG-RAN if the following conditions are met:

[0156] 1) It is not served by the NG-RAN for ProSe direct communication via PC5;

[0157] 2) It is in a restricted service state as specified in 3GPP TS 23.122

[14] , provided that the reason for the UE being in the restricted service state is one of the following;

[0158] i) The UE cannot find a suitable cell in the selected PLMN as specified in 3GPP TS 38.304

[15] ;

[0159] ii) The UE receives a registration rejection message or a service rejection message with a 5GMM cause #11 "PLMN not allowed" as specified in 3GPP TS 24.501

[11] ; or

[0160] iii) The UE receives a registration rejection message or a service rejection message with a 5GMM cause #7 "5GS service not allowed" as specified in 3GPP TS 24.501

[11] ; or

[0161] 3) It is in a restricted service state as specified in 3GPP TS 23.122

[14] for reasons other than i), ii) or iii) above and is located in a geographical area where the UE has "non-operator managed" radio parameters as specified in Section 5.2;

[0162] Editor's Note: The behavior of UEs in a restricted service state in the case of direct communication between a 5G ProSe end UE and a 5G ProSe UE-to-UE relay UE using the 5G ProSe direct link establishment procedure needs to be re-discussed, which will be determined by SA2.

[0163] f) There is no existing 5G ProSe direct link for a pair of peer application layer IDs, or there is an existing 5G ProSe direct link for a pair of peer application layer IDs, and:

[0164] 1) The network layer protocol of the existing 5G ProSe direct link is not the same as the network layer protocol required by the upper layer in the originating UE for this ProSe application;

[0165] 2) The security policy (signaling security policy or user plane security policy) corresponding to the ProSe identifier is not compatible with the security policy of the existing 5G ProSe direct link; or

[0166] 3) In the case where the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe layer 3 remote UE and a 5G ProSe layer 3 UE-to-network relay UE, the existing 5G ProSe direct link for the peer UE is established using a different RSC, or is established but not used for direct communication between a 5G ProSe layer 3 remote UE and a 5G ProSe layer 3 UE-to-network relay UE;

[0167] 4) In the case where the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe layer 2 remote UE and a 5G ProSe layer 2 UE-to-network relay UE, the existing 5G ProSe direct link for the peer UE is established but not used for direct communication between a 5G ProSe layer 2 remote UE and a 5G ProSe layer 2 UE-to-network relay UE;

[0168] 5) In the case where the 5G ProSe direct link establishment procedure is used for direct communication between a source 5G ProSe layer 3 end UE and a 5G ProSe layer 3 UE-to-relay UE, the initiating UE acts as the source 5G ProSe end UE, the existing 5G ProSe direct link for the peer UE is established using a different RSC, or is established but not used for direct communication between a source 5G ProSe layer 3 end UE and a 5G ProSe layer 3 UE-to-relay UE;

[0169] 6) In the case where the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe UE-to-relay UE and a target 5G ProSe end UE without integration of discovery, the initiating UE acts as the 5G ProSe UE-to-relay UE, the 5G ProSe direct link security mode control procedure between the source 5G ProSe end UE and the initiating UE has been successfully completed, and no 5G ProSe direct link is established between the initiating UE and the target 5G ProSe end UE, where the RSC is received in the ProSe direct link establishment request message for 5G ProSe UE-to-relay;

[0170] 7) In the case where the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe layer 3 UE - to - UE relay UE and a target 5G ProSe layer 3 end UE, the initiating UE acting as the 5G ProSe layer 3 UE - to - UE relay UE receives a ProSe direct link establishment request message containing a relay indication, and no 5G ProSe direct link is established between the initiating UE and the target 5G ProSe end UE, where an RSC is received in the ProSe direct link establishment request message for 5G ProSe UE - to - UE relay; or

[0171] 8) In the case where the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe layer 3 UE - to - UE relay UE and a target 5G ProSe layer 3 end UE, the initiating UE acting as the 5G ProSe layer 3 UE - to - UE relay UE receives a ProSe direct link modification request message for establishing 5G ProSe UE - to - UE relay communication with an additional 5G ProSe layer 3 end UE as specified in Section 7.2.3.2, and no 5G ProSe direct link is established between the initiating UE and the additional target 5G ProSe end UE, where an RSC is received in the ProSe direct link modification request message for 5G ProSe UE - to - UE relay;

[0172] g) The number of established 5G ProSe direct links is less than the implementation - specific maximum number of established 5G ProSe direct links allowed per UE;

[0173] h) Timer T5088 is not associated with the link - layer identifier of the destination UE or the timer T5088 associated with the link - layer identifier of the destination UE has expired or stopped.

[0174] After receiving service data or a request from the upper layer, the initiating UE will derive PC5 QoS parameters and assign a PQFI for the PC5 QoS flow established as specified in Section 7.2.7.

[0175] If the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE - to - network relay UE, the UE will apply DUCK or DUSK for UE - to - network relay discovery together with a UTC - based counter to encryption:

[0176] a) Relay service code; and

[0177] b) UP - PRUK ID or CP - PRUK ID (if available),

[0178] As specified in section 6.3.5.2 of 3GPP TS 33.503

[34] , and the UE shall use a security - protected relay service code and a security - protected UP - PRUK ID or a security - protected CP - PRUK ID to create a ProSe direct link establishment request message.

[0179] Note 2: If the UE is not configured with either DUCK or DUSK, the relay service code and the UP - PRUK ID or CP - PRUK ID are not encrypted.

[0180] To initiate the 5G ProSe direct link establishment procedure, the initiating UE shall create a ProSe direct link establishment request message. The initiating UE:

[0181] a) Shall contain source user information, which is set to the application layer ID of the initiating UE received from the upper layer, or in the case of 5G ProSe direct communication between a 5G ProSe end - UE and a relay UE between 5G ProSe UEs in the 5G ProSe direct link establishment procedure, is set to the user information ID of the source 5G ProSe end - UE;

[0182] b) If the 5G ProSe direct link establishment procedure is not for 5G ProSe direct communication between a 5G ProSe remote UE and a 5G ProSe UE - to - network relay UE, shall contain the ProSe identifier received from the upper layer;

[0183] c) Shall contain destination user information, which is set to the application layer ID of the destination UE if received from the upper layer or if known based on the unicast layer 2 ID of the destination UE (i.e., the destination layer 2 ID) as described in section 5.8.2.4 of 3GPP TS 23.304 [3], is set to the user information ID of the 5G ProSe UE - to - network relay UE obtained during the 5G ProSe UE - to - network relay discovery procedure, or is set to the user information ID of the destination 5G ProSe end - UE in the following cases:

[0184] 1) The initiating UE acts as the source 5G ProSe end - UE and the user information ID of the destination 5G ProSe end - UE is obtained during the 5G ProSe UE - to - UE relay discovery procedure; or

[0185] 2) The initiating UE acts as a 5G ProSe UE - to - UE relay UE and the user information ID of the destination 5G ProSe end - UE is obtained from the ProSe direct link establishment request message or the ProSe direct link modification request message from the source 5G ProSe end - UE;

[0186] ca) It shall contain the UE - to - UE relay UE user information, which is set to the user information ID of the 5G ProSe UE - to - UE relay UE in the following cases:

[0187] 1) Obtained during the 5G ProSe UE - to - UE relay discovery procedure, and the 5G ProSe direct link establishment procedure is used for 5G ProSe direct communication between the source 5G ProSe - side UE and the 5G ProSe UE - to - UE relay UE; or

[0188] 2) The initiating UE acts as the 5G ProSe UE - to - UE relay UE, and the user information ID is configured under the configuration parameters for 5G ProSe UE - to - UE relay, as specified in Section 5.2.7.

[0189] cb) It shall contain the target - side UE layer 2 ID, which is set to the layer 2 ID of the target 5G ProSe - side UE when the initiating UE acts as the source 5G ProSe - side UE and the layer 2 ID of the target 5G ProSe - side UE is available in the source 5G ProSe - side UE via previous direct communication.

[0190] d) If the 5G ProSe direct link is not used for direct communication between the 5G ProSe remote UE and the 5G ProSe UE - to - network relay UE:

[0191] 1) If the UE PC5 unicast signaling integrity protection policy is set to "Require signaling integrity protection" or "Prefer signaling integrity protection", it shall contain the key establishment information container, and if the UE PC5 unicast signaling integrity protection policy is set to "Do not require signaling integrity protection", it may contain the key establishment information container;

[0192] Note 3: The key establishment information container is provided by the upper layer.

[0193] e) It shall contain:

[0194] 1) Nonce_1, provided that the direct communication is not between the 5G ProSe remote UE and the 5G ProSe UE - to - network relay UE, or provided that the direct communication is between the 5G ProSe remote UE and the 5G ProSe UE - to - network relay UE and the security procedures on the control plane are used as specified in 3GPP TS 33.503

[34] ; or

[0195] 2) K NRP Freshness parameter 1, provided that the direct communication is between the 5G ProSe remote UE and the 5G ProSe UE - to - network relay UE and the security procedures on the user plane are used as specified in 3GPP TS 33.503

[34] .

[0196] If the UE PC5 unicast signaling integrity protection policy is set to "Require signaling integrity protection" or "Preferred signaling integrity protection", a 128-bit random value generated by the initiating UE is set for the purpose of session key establishment on this 5G ProSe direct link;

[0197] Note 4: The Nonce_1 IE in the ProSe direct link establishment request message is used to hold the value of Nonce_1 or K NRP Freshness parameter 1.

[0198] f) It shall include its UE security capabilities, a list of algorithms indicating the security establishment support of the initiating UE for this 5G ProSe direct link;

[0199] g) If the UE PC5 unicast signaling integrity protection policy is set to "Require signaling integrity protection" or "Preferred signaling integrity protection", it shall include the MSB of K NRP-sess ID selected by the initiating UE as specified in 3GPP TS 33.503

[34] ;

[0200] Note 5: If the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, K NRP-sess ID holds the ID corresponding to K NRP-sess . If the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, K NRP-sess ID holds the ID corresponding to K NRP-sess (if the security procedure on the user plane is used) or K relay-sess (if the security procedure on the control plane is used).

[0201] h) If the initiating UE has an existing K NRP for the target UE and the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, it may include K NRP ID;

[0202] i) It will include its UE PC5 unicast signaling security policy. In the case where different ProSe applications are mapped to different PC5 unicast signaling security policies, when the initiating UE wishes to establish a single unicast link that can be used for more than one ProSe application, the signaling security policies of each of those ProSe applications should be compatible. For example, "no signaling integrity protection required" and "signaling integrity protection required" are not compatible. In the case where the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, the signaling integrity protection policy should be set to "signaling integrity protection required";

[0203] j) It will include a relay service code IE, which is set to the relay service code of the target relay UE in the case where the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, or is set to the relay service code indicating the connectivity service requested by the source 5G ProSe end UE in the case where the 5G ProSe direct link establishment procedure is used for direct communication between a (source or target) 5G ProSe end UE and a 5G ProSe UE-to-relay UE;

[0204] k) If the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, it will include the least significant four bits of a UTC-based counter set to the UTC-based counter;

[0205] l) It will include a UE identity IE, which is set to the SUCI of the initiating UE in the following cases:

[0206] 1) The 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE; and

[0207] 2) The security for the 5G ProSe UE-to-network relay uses the security procedure on the control plane and the initiating UE does not have a valid CP-PRUK, as specified in 3GPP TS 33.503

[34] , or the security for the 5G ProSe UE-to-network relay uses the security procedure on the user plane and the initiating UE does not have a valid UP-PRUK, as specified in 3GPP TS 33.503

[34] ;

[0208] m) It will include a user security key ID IE, which is set to:

[0209] 1) The UP-PRUK ID of the initiating UE, provided that:

[0210] i) The 5G ProSe direct link establishment procedure is for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE;

[0211] ii) The initiating UE has a valid UP-PRUK; and

[0212] iii) The security for 5G ProSe UE-to-network relay uses the security procedures on the user plane as specified in 3GPP TS 33.503

[34] ; or

[0213] 2) The CP-PRUK ID of the initiating UE associated with the relay service code of the target UE, provided that:

[0214] i) The 5G ProSe direct link establishment procedure is for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE;

[0215] ii) The initiating UE has a valid CP-PRUK associated with the relay service code of the target UE; and

[0216] iii) The security for 5G ProSe UE-to-network relay uses the security procedures on the control plane as specified in 3GPP TS 33.503

[34] ;

[0217] n) If the UP-PRUK ID of the initiating UE is included and it is not in NAI format (see 3GPP TS 33.503

[34] ), the HPLMN ID of the initiating UE will be included;

[0218] o) The MIC IE will be included, which is set to the calculated MIC value in the case where the 5G ProSe direct link establishment procedure is for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE and the UE has a DUIK, as specified in Section 6.3.5.3 of 3GPP TS 33.503

[34] ; and

[0219] p) If the 5G ProSe direct link establishment procedure is for direct communication between a source 5G ProSe end UE and a 5G ProSe UE-to-relay UE and has integrated discovery, a relay indication will be included, which indicates that the ProSe direct link establishment request message can be forwarded by the 5G ProSe UE-to-relay UE;

[0220] Editor's note: The security parameters for 5G ProSe UE-to-relay and the parameters for 5G ProSe layer 2 UE-to-relay need further study.

[0221] After generating the ProSe direct link establishment request message, the initiating UE shall pass this message, together with the source layer 2 ID and the destination layer 2 ID, to the lower layer for transmission as follows:

[0222] a) If 5G ProSe direct communication is due to 5G ProSe direct discovery as defined in Sections 6.2.14, 6.2.15, 8.2.1, and 8a.2.1:

[0223] Self-assign the source layer 2 ID, and

[0224] 1) Set the destination layer 2 ID to the destination layer 2 ID of the target UE layer 2 ID received in the ProSe direct link establishment request message or ProSe direct link modification request message from the source 5G ProSe UE when the initiating UE acts as a 5G ProSe inter-UE relay UE;

[0225] 2) Otherwise, set it to the destination layer 2 ID of the source layer 2 ID in the ProSe PC5 discovery message received for the discovery procedure;

[0226] b) If the initiating UE acts as a source 5G ProSe UE and the 5G ProSe direct link establishment procedure is for direct communication between the source 5G ProSe UE and a 5G ProSe inter-UE relay UE with integrated discovery:

[0227] Self-assign the source layer 2 ID and set the destination layer 2 ID to the broadcast destination layer 2 ID configured as specified in Section 5.2.4; or

[0228] c) If the initiating UE acts as a 5G ProSe inter-UE relay UE and the 5G ProSe direct link establishment procedure is for direct communication between the 5G ProSe inter-UE relay UE and a target 5G ProSe UE with integrated discovery:

[0229] Self-assign the source layer 2 ID and set the destination layer 2 ID to:

[0230] 1) The destination layer 2 ID of the target UE layer 2 ID, provided that it is received in the ProSe direct link establishment request message from the source 5G ProSe UE; otherwise

[0231] 2) The broadcast destination layer 2 ID configured as specified in Section 5.2.4; or

[0232] d) Otherwise:

[0233] Self-assign a source layer 2 ID and set a destination layer 2 ID as the destination layer 2 ID for unicast initial signaling as specified in Section 5.2.4.

[0234] Note 6: The UE implementation ensures that any value of the self-assigned source layer 2 ID in a) and b) is different from any other self-assigned source layer 2 ID used for 5G ProSe direct discovery as specified in Sections 6.2.14, 6.2.15, and 8.2.1, and different from any other pre-provisioned destination layer 2 ID as specified in Section 5.2.

[0235] Note 6A: If the 5G ProSe direct link establishment procedure is used for 5G ProSe direct communication between a 5G ProSe layer 3 UE-to-UE relay UE and a target 5G ProSe layer 3 end UE, the UE implementation ensures that any value of the self-assigned source layer 2 ID in a) and b) is different from any self-assigned source layer 2 ID used for 5G ProSe direct communication with a different data unit type from the data unit type of the established 5G ProSe direct link.

[0236] Note 6B: If the 5G ProSe direct link establishment procedure is used for 5G ProSe direct communication between a 5G ProSe layer 3 UE-to-UE relay UE and a target 5G ProSe layer 3 end UE and for unstructured services, the UE implementation ensures that any value of the self-assigned source layer 2 ID in a) and b) is different from any other self-assigned source layer 2 ID used for 5G ProSe direct communication for unstructured services and different from the user information IDs of different pairs of source 5G ProSe end UEs and target 5G ProSe end UEs.

[0237] Note 7: The initiating UE may reuse the layer 2 ID of the initiating UE used in a previous 5G ProSe direct link with the same peer UE, except when the 5G ProSe direct link establishment procedure is used for 5G ProSe direct communication between a 5G ProSe layer 3 UE-to-UE relay UE and a target 5G ProSe layer 3 end UE for unstructured services and different pairs of source 5G ProSe end UEs' user information IDs and target 5G ProSe end UEs' user information IDs, and except when the 5G ProSe direct link establishment procedure is used for 5G ProSe direct communication between a 5G ProSe layer 3 UE-to-UE relay UE and a target 5G ProSe layer 3 end UE with a data unit type different from the data unit type of the previous 5G ProSe direct link.

[0238] And start timer T5080.

[0239] Note 8: The pre-configured PC5 DRX configuration is used for transmitting the ProSe direct link establishment request message, as specified in 3GPP TS 38.300

[21] .

[0240] While the timer T5080 is running, the UE shall not send a new ProSe direct link establishment request message to the same target UE identified by the same application layer ID. If the target user information IE is not included in the ProSe direct link establishment request message (i.e., the 5G ProSe direct link establishment procedure for ProSe applications), the initiating UE shall process multiple ProSe direct link establishment acceptance messages (if any) received from different target UEs before the expiration of the timer T5080 for establishing multiple 5G ProSe direct links.

[0241] Note 9: To ensure successful 5G ProSe direct link establishment, T5080 shall be set to a value greater than the sum of T5089 and T5092.

[0242] [[3GPP TS24.554 V18.2.0, named "5G ProSe direct link establishment procedure for UE", Figure 7 .2.2.2.1 is reproduced as Figure 7

[0243] [[3GPP TS24.554 V18.2.0, named "5G ProSe direct link establishment procedure for ProSe services", Figure 7 .2.2.2.2 is reproduced as Figure 8

[0244] 7.2.2.3 5G ProSe direct link establishment procedure accepted by the target UE

[0245] After receiving the ProSe direct link establishment request message, if the target UE accepts this request, the target UE shall uniquely assign a PC5 link identifier and create a 5G ProSe direct link context.

[0246] Note 1: The pre-configured PC5 DRX configuration is used for receiving the ProSe direct link establishment request message, as specified in 3GPP TS 38.300

[21] .

[0247] If the ProSe direct link establishment request message is for 5G ProSe direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, the target UE shall verify the MIC field in the received ProSe direct link establishment request using DUIK (if available) and decrypt the encrypted one using DUCK or DUSK: ​​

[0248] a) Relay service code; and

[0249] b) UP-PRUK ID or CP-PRUK ID (if received),

[0250] The DUCK or DUSK is used for 5G ProSe UE-to-network relay discovery (see Section 6.3.5.2 of 3GPP TS 33.503

[34] ), and the target UE verifies whether the relay service code matches the code sent by the target UE during the 5G ProSe UE-to-network relay discovery procedure.

[0251] Note 2: If the UE is not configured with either DUCK or DUSK, the relay service code and the UP-PRUK ID or CP-PRUK ID are not encrypted.

[0252] If the target UE acts as the target 5G ProSe end UE, and the 5G ProSe direct link establishment procedure is used for direct communication and integrated discovery between the 5G ProSe UE-to-network relay UE and the target 5G ProSe end UE, after receiving a ProSe direct link establishment request message containing the same source user information, ProSe identifier, and relay service code as received from multiple 5G ProSe UE-to-network relay UEs, the target UE selects the 5G ProSe UE-to-network relay UE among the 5G ProSe UE-to-network relay UEs that is used to communicate with the source 5G ProSe end UE, as specified in Section 6.7.3.2 of TS23.304.

[0253] If the 5G ProSe direct link establishment procedure is not used for direct communication between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay UE, the target UE may initiate the 5G ProSe direct link authentication procedure as specified in Section 7.2.12 and will initiate the 5G ProSe direct link security mode control procedure as specified in Section 7.2.10.

[0254] If the 5G ProSe direct link establishment procedure is used for direct communication between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay UE, the target UE will continue with:

[0255] a) Authentication and key agreement procedures, as specified in Section 5.5.4 of 3GPP TS24.501

[11] , provided that the security procedures on the control plane specified in 3GPP TS 33.503

[34] are used; or

[0256] b) A key request procedure as specified in Section 8.2.10.2.4, provided that the security procedures on the user plane as specified in 3GPP TS 33.503

[34] are used;

[0257] And the 5G ProSe direct link security mode control procedure as specified in Section 7.2.10 will be initiated.

[0258] In the 5G ProSe direct link context, the target UE will set the source layer 2 ID and the destination layer 2 ID as specified in Sections 7.2.12 and 7.2.10, store the corresponding source layer 2 ID for unicast communication, and store the destination layer 2 ID for unicast communication.

[0259] If:

[0260] a) The target user information IE is included in the ProSe direct link establishment request message, and this IE contains the application layer ID of the target UE; or

[0261] b) The target user information IE is not included in the ProSe direct link establishment request message, and the target UE is interested in the ProSe application identified by the ProSe identifier IE in the ProSe direct link establishment request message;

[0262] Then the target UE will:

[0263] a) If the direct communication is not between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay UE:

[0264] 1) Based on the K NRP ID included in the ProSe direct link establishment request message to identify the existing K NRP ; or

[0265] 2) If the K NRP ID is not included in the ProSe direct link establishment request message, then the target UE does not have the existing K NRP for the K NRP ID included in the ProSe direct link establishment request message, or the target UE wishes to derive a new K NRP , then derive the new K NRP . This may require performing one or more 5G ProSe direct link authentication procedures as specified in Section 7.2.12;

[0266] b) If the direct communication is between the 5G ProSe Remote UE and the 5G ProSe UE-to-Network Relay UE and uses the security procedures on the control plane as specified in 3GPP TS 33.503

[34] , then a new K is requested according to the security procedures on the user plane as specified in 3GPP TS 33.503

[34] . NR_ProSe ; or

[0267] c) If the direct communication is between the 5G ProSe Remote UE and the 5G ProSe UE-to-Network Relay UE and uses the security procedures on the user plane as specified in 3GPP TS 33.503

[34] , then a new K is requested according to the security procedures on the user plane. NRP .

[0268] Note 3: How many times the 5G ProSe direct link authentication procedure needs to be executed to derive a new K NRP depends on the authentication method used.

[0269] After identifying the existing K NRP or deriving a new K NRP or after receiving a new K NRP or K NR_ProSe the target UE will initiate the 5G ProSe direct link security mode control procedure as specified in Section 7.2.10.

[0270] After the 5G ProSe direct link security mode control procedure is successfully completed, to determine whether the ProSe direct link establishment request message is acceptable, in the case of IP communication, the target UE checks whether there is at least one common IP address configuration option supported by both the initiating UE and the target UE.

[0271] Before sending a ProSe direct link establishment acceptance message to the 5G ProSe Remote UE, the target UE acting as the 5G ProSe layer 3 UE-to-Network Relay UE initiates the PDU session establishment procedure requested by the initiating UE as specified in 3GPP TS 24.501

[11] , provided that:

[0272] 1) The PDU session for relaying the service associated with the RSC has not been established; or

[0273] 2) The PDU session for relaying the service associated with the RSC has been established, but the PDU session type is unstructured.

[0274] If the target UE accepts the 5G ProSe direct link establishment procedure, the target UE will create a ProSe direct link establishment acceptance message. The target UE:

[0275] a) Include the source user information, which is set to the application layer ID of the target UE received from the upper layer, or set to the user information ID of the target 5G ProSe end UE in the case of 5G ProSe direct communication between the 5G ProSe end UE and the relay UE between 5G ProSe UEs in the 5G ProSe direct link establishment procedure;

[0276] aa) Include the relay UE user information between UEs, which is set to the user information ID of the relay UE between 5G ProSe UEs in the case of 5G ProSe direct communication between the source 5G ProSe end UE and the relay UE between 5G ProSe UEs in the 5G ProSe direct link establishment procedure;

[0277] b) Include the PQFI, the corresponding PC5 QoS parameter, and optionally the ProSe identifier accepted by the target UE, provided that the target UE does not act as a 5G ProSe layer 2 UE to network relay UE and the 5G ProSe direct link establishment procedure is not integrated with discovery;

[0278] c) May include the PC5 QoS rule, provided that the target UE does not act as a 5G ProSe layer 2 UE to network relay UE and the 5G ProSe direct link establishment procedure is not integrated with discovery;

[0279] d) If IP communication is used and the target UE does not act as a 5G ProSe layer 2 UE to network relay UE, then include the IP address configuration IE set to one of the following values:

[0280] 1) "DHCPv4 server", provided that only the IPv4 address allocation mechanism is supported by the target UE, i.e., acting as a DHCPv4 server;

[0281] 2) "IPv6 router", provided that only the IPv6 address allocation mechanism is supported by the target UE, i.e., acting as an IPv6 router;

[0282] 3) "DHCPv4 server and IPv6 router", provided that both the IPv4 and IPv6 address allocation mechanisms are supported by the target UE; or

[0283] 4) "Address allocation not supported", provided that neither the IPv4 nor the IPv6 address allocation mechanism is supported by the target UE and the target UE does not act as a 5G ProSe layer 3 UE to network relay UE;

[0284] Note 4: If the communication uses Ethernet or unstructured data unit type, the UE does not include the IP address configuration IE nor the link-local IPv6 address IE.

[0285] e) If the IP address configuration IE is set to "Address allocation not supported", the received ProSe direct link security mode complete message contains a link-local IPv6 address IE and the target UE neither acts as a 5G ProSe layer 2 UE-to-network relay UE nor acts as a 5G ProSe layer 3 relay UE, then it will contain a link-local IPv6 address IE formed locally based on IETF RFC 4862

[25] ;

[0286] f) It will contain the configuration of UE PC5 unicast user plane security protection based on the agreed user plane security policy, as specified in 3GPP TS 33.503

[34] .

[0287] Editor's note: The security parameters for 5G ProSe UE-to-UE relay and the parameters for 5G ProSe layer 2 UE-to-UE relay are subject to further study.

[0288] g) If the 5G ProSe direct link establishment procedure is used for 5G ProSe direct communication between a source or target 5G ProSe layer 3 end UE and a 5G ProSe layer 3 UE-to-UE relay UE and for Ethernet traffic, it will contain the MAC address of the target 5G ProSe layer 3 end UE; and

[0289] h) It may contain a target 5G ProSe layer 3 end UE IP address IE, set to the IP address of the target 5G ProSe layer 3 end UE, provided that the 5G ProSe direct link establishment procedure is used for 5G ProSe direct communication between a source 5G ProSe layer 3 end UE and a 5G ProSe layer 3 UE-to-UE relay UE and the data unit type of the communication is IP.

[0290] Editor's note: The security parameters for 5G ProSe UE-to-UE relay and the parameters for 5G ProSe layer 2 UE-to-UE relay are subject to further study.

[0291] After generating a ProSe direct link establishment accept message, in the following cases, the target UE will pass this message together with the layer 2 ID of the initiating UE for unicast communication and the layer 2 ID of the target UE for unicast communication to the lower layer for transmission, and will start timer T5090:

[0292] a) At least one ProSe identifier for the 5G ProSe direct link meets the privacy requirements as specified in Section 5.2.4; or

[0293] b) T5090 is configured as specified in Section 5.2.5.

[0294] Note 5: The PC5 DRX configuration in the AS layer is negotiated between two UEs, and the PC5 DRX parameter values are configured according to each pair of source and destination layer 2 IDs in the AS layer, as specified in 3GPP TS 38.300

[21] .

[0295] After sending the ProSe direct link establishment acceptance message, the target UE provides the following information to the lower layer together with the layer 2 ID, so that the lower layer can process the incoming PC5 signaling or traffic data:

[0296] a) The PC5 link identifier self-assigned for this 5G ProSe direct link;

[0297] b) The PQFI and its corresponding PC5 QoS parameters (if available); and

[0298] c) The activation indication for PC5 unicast user plane security protection for the 5G ProSe direct link (if applicable).

[0299] If the target UE accepts the 5G ProSe direct link establishment request and the 5G ProSe direct link is established but not used for 5G ProSe direct communication between the 5G ProSe remote UE and the 5G ProSe UE to network relay UE, and 5G ProSe direct communication between the 5G ProSe end UE and the 5G ProSe UE to relay UE, then the target UE can perform the PC5 QoS flow establishment on the 5G ProSe direct link, as specified in Section 7.2.7. If the 5G ProSe direct link is established for 5G ProSe direct communication between the 5G ProSe layer 3 remote UE and the 5G ProSe layer 3 UE to network relay UE, then the target UE can perform the PC5 QoS flow establishment on the 5G ProSe direct link, as specified in Section 8.2.6. If the 5G ProSe direct link is established for 5G ProSe direct communication between the 5G ProSe layer 3 end UE and the 5G ProSe layer 3 UE to relay UE, then the target UE can perform the PC5 QoS flow establishment on the 5G ProSe direct link, as specified in Section 8a.2.7.

[0300] 7.2.2.4 Completion of the 5G ProSe direct link establishment procedure by the initiating UE

[0301] If the target user information IE is included in the ProSe direct link establishment request message, the initiating UE shall stop timer T5080 after receiving the ProSe direct link establishment accept message. If the target user information IE is not included in the ProSe direct link establishment request message, the initiating UE may keep timer T5080 running and continue to process multiple response messages (i.e., ProSe direct link establishment accept messages) from multiple target UEs.

[0302] For each received ProSe direct link establishment accept message, the initiating UE shall uniquely assign a PC5 link identifier and create a 5G ProSe direct link context for each 5G ProSe direct link. Then, the initiating UE shall store the source layer 2 ID and the destination layer 2 ID used in the transmission of this message provided by the lower layer in the 5G ProSe direct link context to complete the establishment of the 5G ProSe direct link with the target UE. Thereafter, the initiating UE shall use the established link for ProSe direct communication via PC5 and additional PC5 signaling messages to the target UE.

[0303] If the initiating UE acts as a 5G ProSe UE - to - UE relay UE and the 5G ProSe direct link establishment procedure is used for direct communication and integrated discovery between the 5G ProSe UE - to - UE relay UE and the target 5G ProSe end UE, after receiving the ProSe direct link establishment accept message from the target 5G ProSe end UE, the initiating UE shall initiate the 5G ProSe direct link security mode control procedure with the source 5G ProSe end UE, and after successfully completing the 5G ProSe direct link security mode control procedure with the source 5G ProSe end UE, the initiating UE shall create a ProSe direct link establishment accept message as specified in Section 7.2.2.3 to send to the source 5G ProSe end UE.

[0304] After receiving the ProSe direct link establishment accept message, the initiating UE shall provide the following information together with the layer 2 ID to the lower layer so that the lower layer can process the incoming PC5 signaling or traffic data:

[0305] a) The PC5 link identifier self - assigned for this 5G ProSe direct link;

[0306] b) The PQFI and its corresponding PC5 QoS parameters (if available); and

[0307] c) The activation indication for PC5 unicast user plane security protection for the 5G ProSe direct link (if applicable).

[0308] The initiating UE shall start timer T5090 if:

[0309] a) at least one ProSe identifier for 5G ProSe direct link meets the privacy requirements specified in Section 5.2.4; or

[0310] b) T5090 is configured as specified in Section 5.2.5.

[0311] Additionally, the initiating UE may perform PC5 QoS flow establishment on the 5G ProSe direct link as specified in Section 7.2.7.

[0312] After timer T5080 expires, if the ProSe direct link establishment request message does not contain the target user information IE and the initiating UE receives at least one ProSe direct link establishment accept message, the UE implementation shall consider the 5G ProSe direct link establishment procedure as completed or restart timer T5080.

[0313] If the 5G ProSe direct link establishment procedure is triggered by a ProSe direct link modification request message from the source 5G ProSe layer 3 end UE as specified in Section 7.2.3.2, then in the case where the initiating UE acts as a 5G ProSe layer 3 UE - to - UE relay UE, after receiving the ProSe direct link establishment accept message, the initiating UE shall send a ProSe direct link modification accept message to the source 5G ProSe layer 3 end UE as specified in Section 7.2.3.3.

[0314] 7.2.2.5 5G ProSe direct link establishment procedure not accepted by the target UE

[0315] If the ProSe direct link establishment request message cannot be accepted, the target UE shall send a ProSe direct link establishment reject message. The ProSe direct link establishment reject message contains a PC5 signaling protocol cause IE set to one of the following cause values:

[0316] #1 Direct communication with the target UE is not allowed;

[0317] #3 Conflict of layer 2 ID detected for unicast communication;

[0318] #5 Lack of resources for 5G ProSe direct link;

[0319] #13 Congestion situation;

[0320] #15 5G ProSe UE - to - network relay security procedure failed;

[0321] #20 Failure from the UE at the 5G ProSe side

[0322] #yy The 5G ProSe direct link already exists; or

[0323] #111 Unspecified protocol error.

[0324] If the target UE is not allowed to accept a ProSe direct link establishment request message, e.g., based on operator policies or configuration parameters for ProSe direct communication over PC5 as specified in Section 5.2, or the target UE acts as a 5G ProSe layer 3 UE to network relay UE in a non - allowed area of its serving PLMN and the corresponding relay service code is not associated with high - priority access as defined in Section 5.3.5 of 3GPP TS 24.501

[11] , the target UE shall send a ProSe direct link establishment rejection message containing the PC5 signalling protocol cause value #1 "Direct communication with the target UE not allowed".

[0325] Note 1: When a target UE acting as a 5G ProSe layer 3 UE to network relay UE is involved in its own emergency service as specified in 3GPP TS 24.501

[11] or handling the emergency service of another 5G ProSe layer 3 remote UE, and receives a ProSe direct link establishment request message with an RSC specific to the emergency service, if the target UE decides to prioritize its own ongoing emergency service or the emergency service of other 5G ProSe layer 3 remote UE due to local regulations or implementation - specific requirements, the target UE is allowed to ignore the ProSe direct link establishment request message.

[0326] For a ProSe direct link establishment request message received from a layer 2 ID (for unicast communication), if the target UE already has an existing link to the UE established using this layer 2 ID or is currently processing a ProSe direct link establishment request message from the same layer 2 ID and one of the following parameters is different from the existing link or a link for which link establishment is in progress:

[0327] a) Source user information;

[0328] b) Data type (e.g., IP, Ethernet or unstructured); or

[0329] c) Security policy,

[0330] the target UE shall send a ProSe direct link establishment rejection message containing the PC5 signalling protocol cause value #3 "Conflict detected for layer 2 ID for unicast communication".

[0331] Note 2: If the UE is processing a ProSe direct discovery message with the same source layer 2 ID as the received ProSe direct link establishment request message, avoiding a conflict of the destination layer 2 ID depends on the UE implementation (e.g., sending a ProSe direct link establishment rejection message containing the PC5 signaling protocol cause value #3 "Conflict of layer 2 ID detected for unicast communication" or ignoring the ProSe direct discovery message).

[0332] Note 3: The data type (e.g., IP, Ethernet, or unstructured) is indicated by the optional IP address configuration IE contained in the corresponding direct link security mode complete message, i.e., if this IE is included, the data type of the requested link is of IP type, and if this IE is not included, the data type of the requested link is Ethernet or unstructured.

[0333] If the 5G ProSe direct link establishment fails due to reaching the implementation-specific maximum number of established 5G ProSe direct links or other temporary lower layer problems causing resource constraints, the target UE shall send a ProSe direct link establishment rejection message containing the PC5 signaling protocol cause value #"5 Lack of resources for 5G ProSe direct link".

[0334] If the 5G ProSe direct link establishment request is for 5G ProSe UE-to-network relay and:

[0335] a) NAS-level mobility management congestion control as specified in Section 5.3.9 of TS 24.501

[11] is activated at the target UE acting as a 5G ProSe UE-to-network relay UE; or

[0336] b) The target UE acting as a 5G ProSe UE-to-network relay UE is in a congested state;

[0337] then the target UE shall send a ProSe direct link establishment rejection message containing the PC5 signaling protocol cause value #13 "Congestion situation". The target UE may provide a fallback timer value to the initiating UE in the ProSe direct link establishment rejection message. If the fallback timer for NAS-level mobility management congestion control is running, the target UE shall not accept any 5G ProSe direct link establishment requests for relay.

[0338] If the 5G ProSe direct link establishment request is for a 5G ProSe UE-to-network relay, at the target UE acting as a 5G ProSe layer 3 UE-to-network relay UE, activate the NAS-level session management congestion specified in Sections 6.2.7 and 6.2.8 of TS 24.501

[11] , and the relay service code used in the 5G ProSe direct link establishment corresponds to the DNN and / or S-NSSAI for which the NAS-level session management congestion is activated, and the target UE needs to execute a PDU session establishment procedure for the DNN and / or S-NSSAI or a PDU session modification procedure for the DNN and / or S-NSSAI, then the target UE shall send a ProSe direct link establishment rejection message containing the PC5 signaling protocol cause value #13 "Congestion situation". The target UE may provide a fallback timer value to the initiating UE in the ProSe direct link establishment rejection message.

[0339] Note 4: How the target UE determines that it is in a congested state is implementation-specific (e.g., any relay-related operation overhead, etc.).

[0340] Note 5: In the case where the target UE is under NAS-level mobility management congestion control, it is an implementation option to set the fallback timer value provided to the initiating UE to the remaining time of the mobility management fallback timer T3346 or with an additional offset value.

[0341] If the 5G ProSe direct link establishment request is for a 5G ProSe layer 3 UE-to-network relay, the PDU session for relaying the service is a LADN PDU session, and the target UE acting as a 5G ProSe layer 3 UE-to-network relay UE is outside the LADN service area, then the target UE shall send a ProSe direct link establishment rejection message containing the PC5 signaling protocol cause value #111 "Unspecified protocol error".

[0342] If the 5G ProSe direct link establishment request is for 5G ProSe layer 3 UE-to-network relay, the request shall establish a PDU session as a 5G ProSe layer 3 UE-to-network relay UE of the target UE, and if the PDU session establishment is unsuccessful due to receiving 5GSM cause #8 "Maximum number of PDU sessions reached", #27 "DNN missing or unknown", #28 "PDU session type unknown", #29 "User authentication or authorization failed", #31 "Unspecified reject request", #32 "Service option not supported", #33 "Requested service option not subscribed", #46 "Outside the LADN service area" or #65 "Maximum number of PDU sessions reached" as specified in 3GPP TS 24.501

[11] , the target UE shall send a ProSe direct link establishment reject message containing the PC5 signaling protocol cause value #111 "Unspecified protocol error".

[0343] If the 5G ProSe direct link establishment request is for 5G ProSe UE-to-UE relay and:

[0344] a) The target UE acting as the target 5G ProSe end UE is in a congested state;

[0345] Then the target UE shall send a ProSe direct link establishment reject message containing the PC5 signaling protocol cause value #13 "Congestion situation". The target UE may provide a fallback timer value to the initiating UE in the ProSe direct link establishment reject message.

[0346] After receiving the ProSe direct link establishment reject message from the target 5G ProSe end UE, the initiating UE acts as a 5G ProSe UE-to-UE relay UE, and the 5G ProSe direct link establishment procedure is for direct communication between the source 5G ProSe end UE and the 5G ProSe UE-to-UE relay UE. The target 5G ProSe end UE has rejected the 5G ProSe direct link establishment procedure or the 5G ProSe direct link modification procedure. The reject message contains a fallback value and the initiating UE has not reached the maximum number of allowed retransmissions. Then the initiating UE shall notify (message TBD) the source 5G ProSe end UE that the target 5G ProSe end UE has rejected the link establishment or link modification request and shall provide the cause value from the target 5G ProSe end UE.

[0347] Editor's note: How the target 5G ProSe end UE notifies the 5G ProSe UE-to-UE relay UE of the rejected link establishment or link modification request remains to be further studied.

[0348] After receiving a ProSe direct link establishment rejection message from the target 5G ProSe end UE, the initiating UE acts as a 5G ProSe UE - to - UE relay UE. The 5G ProSe direct link establishment procedure is for direct communication between the source 5G ProSe end UE and the 5G ProSe UE - to - UE relay UE. If the target 5G ProSe end UE has rejected the 5G ProSe direct link establishment procedure or the 5G ProSe direct link modification procedure, the rejection message contains a fallback value, and the initiating UE has reached the maximum number of allowed retransmissions, then the initiating UE shall send a ProSe direct link establishment rejection message with an appropriate PC5 signaling protocol cause value to the source 5G ProSe end UE. The initiating UE shall include the PC5 protocol cause value #20 "Failure from 5G ProSe end UE" in the ProSe direct link establishment rejection message, and include the PC5 end UE failure cause IE set to #13 "Congestion situation" received from the target 5G ProSe end UE that rejected the 5G ProSe direct link establishment or 5G ProSe direct link modification procedure. The initiating UE may include the target end UE information IE set to the user information ID of the target 5G ProSe end UE in the ProSe direct link establishment rejection message.

[0349] If the 5G ProSe direct link establishment request is for 5G ProSe UE - to - UE relay and:

[0350] a) The target UE acting as a 5G ProSe UE - to - UE relay UE is in a congested state;

[0351] Then the target UE shall send a ProSe direct link establishment rejection message containing the PC5 signaling protocol cause value #13 "Congestion situation". The target UE may provide a fallback timer value to the initiating UE in the ProSe direct link establishment rejection message.

[0352] If the 5G ProSe direct link establishment procedure is for direct communication between a 5G ProSe remote UE and a 5G ProSe UE - to - network relay UE and it fails due to a failure of the security procedure on the control plane or the security procedure on the user plane as specified in 3GPP TS 33.503

[34] , then the target UE will send a ProSe direct link establishment rejection message containing the PC5 signaling protocol cause value #15 "Security procedure failure for 5G ProSe UE - to - network relay". If an EAP message is received from the network according to the security procedure on the control plane specified in 3GPP TS 33.503

[34] , then the target UE will provide the said EAP message.

[0353] If the 5G ProSe direct link establishment procedure is for direct communication between the relay UE among 5G ProSe UEs and the target 5G ProSe end UE, integrated with discovery, and a 5G ProSe direct link for a pair of originating UE user information IDs and target UE user information IDs already exists and the data type unit is IP or Ethernet, the target UE shall send a ProSe direct link establishment rejection message containing the PC5 signaling protocol cause value #yy "5G ProSe direct link already exists" to the relay UE among 5G ProSe UEs.

[0354] If the target UE acts as the target 5G ProSe end UE and the 5G ProSe direct link establishment procedure is between the relay UE among 5G ProSe UEs and the target 5G ProSe end UE, the target 5G ProSe end UE may include in the ProSe direct link establishment rejection message:

[0355] a) A source end UE information IE set to the user information ID of the source 5G ProSe end UE;

[0356] b) A target end UE information IE set to the user information ID of the target 5G ProSe end UE; and

[0357] c) A UE - to - UE relay UE information IE set to the user information ID of the relay UE among 5G ProSe UEs.

[0358] If the target UE acts as the relay UE among 5G ProSe UEs, the 5G ProSe direct link establishment procedure is between the source 5G ProSe end UE and the relay UE among 5G ProSe UEs, and the target 5G ProSe end UE has rejected the 5G ProSe direct link establishment procedure or the 5G ProSe direct link modification procedure, the relay UE among 5G ProSe UEs shall send a ProSe direct link establishment rejection message with the PC5 signaling protocol cause value #20 "Failure from 5G ProSe end UE" to the source 5G ProSe end UE. The relay UE among 5G ProSe UEs may include in the ProSe direct link establishment rejection message a PC5 end UE failure cause IE, which is set to the PC5 signaling protocol cause received from the target 5G ProSe end UE that has rejected the 5G ProSe direct link establishment procedure. The relay UE among 5G ProSe UEs may include in the ProSe direct link establishment rejection message:

[0359] a) A source end UE information IE set to the user information ID of the source 5G ProSe end UE;

[0360] b) A target UE information IE set as the user information ID of the target 5G ProSe end UE; and

[0361] c) A UE - to - UE relay UE information IE set as the user information ID of the 5G ProSe UE - to - UE relay UE.

[0362] Note 6: When CP - PRUK or UP - PRUK is not found in the network, the cause value #15 "Security procedure failure for 5G ProSe UE - to - network relay" is also used.

[0363] If the 5G ProSe direct link establishment fails for other reasons, the target UE will send a ProSe direct link establishment rejection message containing the PC5 signaling protocol cause value #111 "Unspecified protocol error".

[0364] After sending the ProSe direct link establishment rejection message, the target UE will provide the following information to the lower layer, as well as the layer 2 ID of the initiating UE for unicast communication and the layer 2 ID of the target UE for unicast communication:

[0365] a) An indication of the de - activation of PC5 unicast security protection and the deletion of the security context for the 5G ProSe direct link (if applicable).

[0366] After receiving a ProSe direct link establishment rejection message, the initiating UE shall stop timer T5080 and abort the 5G ProSe direct link establishment procedure. If the PC5 signaling protocol cause value in the ProSe direct link establishment rejection message is #1 "Direct communication with the target UE not allowed" or #5 "Lack of resources for 5G ProSe direct link", the initiating UE shall not attempt to initiate the 5G ProSe direct link establishment procedure with the same target UE for at least a time period T. If the PC5 signaling protocol cause value in the ProSe direct link establishment rejection message is #13 "Congestion situation", and a backoff timer value is provided in the ProSe direct link establishment rejection message, the initiating UE shall start timer T5088 associated with the layer 2 ID of the target UE and set its value to the provided timer value. If the PC5 signaling protocol cause value in the ProSe direct link establishment rejection message is #15 "Security procedure for 5G ProSe UE-to-network relay failed", and the initiating UE has included a UE identity IE set to SUCI in the ProSe direct link establishment request message, the initiating UE shall initiate the UE-to-network relay reselection procedure as specified in Section 8.2.3. If the PC5 signaling protocol cause value in the ProSe direct link establishment rejection message is #15 "Security procedure for 5G ProSe UE-to-network relay failed", and the initiating UE has included a user security key ID IE set to UP-PRUK ID or CP-PRUK ID in the ProSe direct link establishment request message, the initiating UE may initiate the UE-to-network relay reselection procedure as specified in Section 8.2.3, and the UE shall further:

[0367] a) If the same 5G ProSe UE-to-network relay UE is selected, discard the previously used CP-PRUK and the associated CP-PRUK ID, or UP-PRUK and the associated UP-PRUK ID (if any), and include a UE identity IE set to SUCI in the ProSe direct link establishment request when initiating a subsequent 5G ProSe direct link establishment procedure as specified in Section 7.2.2.2; or

[0368] b) If a different 5G ProSe UE-to-network relay UE is selected, include a user security key ID IE set to the previously used UP-PRUK ID or CP-PRUK ID in the ProSe direct link establishment request message.

[0369] NOTE 7: The length of the time period T is UE implementation specific and may be different for the cases when the UE receives PC5 signaling protocol cause value #1 "Direct communication with target UE not allowed" or when the UE receives PC5 signaling protocol cause value #5 "Lack of resources for 5G ProSe direct link".

[0370] Editor's note: Security related content is for further study and depends on SA3 requirements.

[0371] If the 5G ProSe direct link establishment procedure is for direct communication between a 5G ProSe inter-UE relay UE and a target 5G ProSe end UE and the PC5 signaling protocol cause value in the ProSe direct link establishment reject message is #yy "5G ProSe direct link already exists", the initiating UE acting as a 5G ProSe inter-UE relay UE may initiate a 5G ProSe direct link modification procedure with the target UE to associate the source 5G ProSe end UE user information ID and ProSe identifier as specified in the rejected ProSe direct link establishment request message with the existing 5G ProSe direct link.

[0372] After receiving the ProSe Direct Link Establishment Reject message, the initiating UE shall provide the following information to the lower layer along with the Layer 2 ID of the initiating UE for unicast communication and the Layer 2 ID of the target UE for unicast communication:

[0373] a) Indication of deactivation of PC5 unicast security protection and deletion of security context for 5G ProSe direct link (if applicable).

[0374] 7.2.2.6 Abnormal situations

[0375] 7.2.2.6.1 Abnormal situation at the initiating UE

[0376] If the timer T5080 expires and the target user information IE is included in the ProSe direct link establishment request message, the initiating UE will retransmit the ProSe direct link establishment request message and restart the timer T5080. After reaching the maximum number of allowed retransmissions, the initiating UE will abort the 5G ProSe direct link establishment procedure and may notify the upper layer that the target UE is unreachable.

[0377] After the expiration of timer T5080, if the ProSe direct link establishment request message does not contain the target user information IE and the initiating UE does not receive any ProSe direct link establishment acceptance message, the initiating UE may retransmit the ProSe direct link establishment request message and restart timer T5080. If the ProSe direct link establishment request message does not contain the target user information IE and the initiating UE does not receive any ProSe direct link establishment acceptance message, then after reaching the maximum number of allowed retransmissions, the initiating UE shall abort the 5G ProSe direct link establishment procedure and may notify the upper layer that no target UE is available.

[0378] Note: The maximum number of allowed retransmissions is specific to the UE implementation.

[0379] If the link establishment is no longer required before the completion of the procedure, the initiating UE shall abort the procedure.

[0380] When the initiating UE aborts the 5G ProSe direct link establishment procedure, the initiating UE shall provide the following information to the lower layer, together with the layer 2 ID of the initiating UE for unicast communication and the layer 2 ID of the target UE for unicast communication:

[0381] a) Indication of the deactivation of PC5 unicast security protection and the deletion of the security context for the 5G ProSe direct link (if applicable).

[0382] 7.2.2.6.2 Abnormal situations at the target UE

[0383] For a ProSe direct link establishment request message received from the source layer 2 ID (for unicast communication), if the target UE has an existing link established with a UE that is known to use the same source layer 2 ID, the same source user information, the same data type (IP, Ethernet, or unstructured), and the same security policy, the UE shall process the new request. However, the target UE shall delete the existing 5G ProSe direct link context only after the new link establishment procedure is successful.

[0384] Note: The data type (e.g., IP, Ethernet, or unstructured) is indicated by the optional IP address configuration IE contained in the corresponding ProSe direct link security mode complete message, i.e., if this IE is included, the data type of the requested link is of IP type, and if this IE is not included, the data type of the requested link is Ethernet or unstructured.

[0385] If the ProSe direct link establishment request message is for 5G ProSe direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, after the target UE decrypts the encrypted relay service code using DUSK or DUCK for 5G ProSe UE-to-network relay discovery, if the relay service code does not match the code sent by the target UE during the 5G ProSe UE-to-network relay discovery procedure, the target UE shall abort the 5G ProSe direct link establishment procedure.

[0386] If the ProSe direct link establishment request message is for 5G ProSe direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, the message integrity is protected and the integrity verification of the message fails at the target UE, then the target UE shall abort the 5G ProSe direct link establishment procedure.

[0387] […]

[0388] 7.2.10 5G ProSe Direct Link Security Mode Control Procedure

[0389] 7.2.10.1 Overview

[0390] The 5G ProSe direct link security mode control procedure is used to establish security between two UEs during the 5G ProSe direct link establishment procedure or the 5G ProSe direct link key update procedure. If UE PC5 signaling integrity protection is not activated, security is not established. After successful completion of the 5G ProSe direct link security mode control procedure, the selected security algorithm and its non-empty associated keys are used for integrity protection and encryption of all PC5 signaling messages exchanged over this 5G ProSe direct link between the UEs, and the security context can be used to protect all PC5 user plane data exchanged over this 5G ProSe direct link between the UEs. The UE that sends the ProSe direct link security mode command message is referred to as the "initiating UE", and the other UE is referred to as the "target UE".

[0391] 7.2.10.2 Initiating the 5G ProSe Direct Link Security Mode Control Procedure by the Initiating UE

[0392] The initiating UE shall meet the following preconditions before initiating the 5G ProSe direct link security mode control procedure:

[0393] a) The target UE has initiated the 5G ProSe direct link establishment procedure towards the initiating UE by sending a ProSe direct link establishment request message and the following:

[0394] 1) ProSe Direct Link Establishment Request Message:

[0395] i) It contains a Target User Information IE which contains the Application Layer ID of the initiating UE; or

[0396] ii) It does not contain a Target User Information IE and the initiating UE is interested in the ProSe service identified by the ProSe identifier in the ProSe Direct Link Establishment Request Message; and

[0397] 2) Initiating UE:

[0398] i) If the direct communication is not between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, based on the K NRP ID identifying the existing K NRP or deriving a new K NRP ;

[0399] ii) If the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE where security procedures on the user plane are used, receiving a new K according to the security procedures on the user plane as specified in 3GPP TS 33.503

[34] NRP ;

[0400] iii) If the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE where security procedures on the control plane are used, receiving a new K according to the security procedures on the control plane as specified in 3GPP TS 33.503

[34] NR_ProSe ; or

[0401] iv) It has decided not to activate security protection based on its UE 5G ProSe Direct Signaling Security Policy and the 5G ProSe Direct Signaling Security Policy of the target UE; or

[0402] b) The target UE has initiated a 5G ProSe direct link key update procedure towards the initiating UE by sending a ProSe Direct Link Key Update Request Message and the following:

[0403] 1) If the target UE has included a re-authentication indication in the ProSe Direct Link Key Update Request Message, the initiating UE has derived a new K NRP .

[0404] Whenever:

[0405] a) The direct communication is not between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, provided that a new K has been derived by the initiating UENRP ; or

[0406] b) Direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, provided that the Initiating UE has received a new K according to the security procedures on the user plane or the security procedures on the control plane as specified in 3GPP TS 33.503

[34] , respectively NRP or K NR_ProSe ;

[0407] The Initiating UE shall generate the 2 MSBs of K NRP ID to ensure that the resulting K NRP ID is unique in the Initiating UE

[0408] Note 1: If the direct communication is not between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, the K NRP ID stores the ID corresponding to K NRP . If the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, the K NRP ID stores the ID corresponding to K NRP (if the security procedures on the user plane are used) or K NR_ProSe (if the security procedures on the control plane are used).

[0409] The Initiating UE shall select a security algorithm according to its UE 5G ProSe direct signaling security policy and the 5G ProSe direct signaling security policy of the target UE. If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link establishment procedure, then if the 5G ProSe direct signaling integrity protection policy of the Initiating UE or the target UE is set to "require signaling integrity protection", the Initiating UE shall not select an empty integrity protection algorithm. If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link key update procedure, the Initiating UE:

[0410] a) If the integrity protection algorithm currently used for the 5G ProSe direct link is different from the empty integrity protection algorithm, it shall not select the empty integrity protection algorithm;

[0411] b) If the encryption protection algorithm currently used for the 5G ProSe direct link is different from the empty encryption protection algorithm, it shall not select the empty encryption protection algorithm;

[0412] c) If the integrity protection algorithm currently in use is the empty integrity protection algorithm, it shall select the empty integrity protection algorithm; and

[0413] d) If the encryption protection algorithm currently in use is the null encryption protection algorithm, the null encryption protection algorithm will be selected.

[0414] Next, the initiating UE will:

[0415] a) If direct communication is not between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay UE:

[0416] 1) Generate a 128-bit Nonce_2 value;

[0417] 2) Derive K NRP based on Nonce_1, K NRP-sess received in the ProSe direct link establishment request message and Nonce_2, as specified in 3GPP TS 33.536

[37] ; and

[0418] 3) Derive the NR PC5 encryption key NRPEK and the NR PC5 integrity key NRPIK based on K NRP-sess and the selected security algorithm, as specified in 3GPP TS 33.536

[37] ;

[0419] b) If direct communication is between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay UE and uses the security procedures on the control plane as specified in 3GPP TS 33.503

[34] :

[0420] 1) Derive K NR_ProSe based on K relay-sess received in the ProSe direct link establishment request message, Nonce_2, and Nonce_1, as specified in 3GPP TS 33.503

[34] ; and

[0421] 2) Derive the NR PC5 encryption key K relay-sess and the NR PC5 integrity key K relay-enc based on K relay-int and the selected security algorithm, as specified in 3GPP TS 33.503

[34] ; or

[0422] c) If direct communication is between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay UE and uses the security procedures on the user plane as specified in 3GPP TS 33.503

[34] , then:

[0423] 1) Based on K NRP received in the ProSe direct link establishment request message, K NRP freshness parameter 2, and KNRP Freshness parameter 1 derivation K NRP-sess , as specified in 3GPP TS 33.503

[34] ; and

[0424] 2) Derive the NR PC5 encryption key NRPEK and the NR PC5 integrity key NRPIK according to K NRP-sess and the selected security algorithm, as specified in 3GPP TS 33.503

[34] ; and

[0425] d) Create a ProSe direct link security mode command message. In this message, the initiating UE:

[0426] 1) Include a key establishment information container IE, provided that the 5G ProSe direct link is not used for direct communication between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay UE and the new K NRP has been derived at the initiating UE and the authentication method used to generate K NRP requires sending information to complete the 5G ProSe direct link authentication procedure;

[0427] Note 2: The key establishment information container is provided by the upper layer.

[0428] 2) Include the MSB of the K NRP ID IE, provided that the new K NRP has been derived or the new K NRP or K NR_ProSe has been received at the initiating UE;

[0429] 3) Include a Nonce_2IE, which is set to:

[0430] i) A 128-bit random value generated by the initiating UE when the direct communication is not between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay UE;

[0431] ii) The value of the K NRP freshness parameter 2 received by the initiating UE when the direct communication is between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay UE and the security procedure on the user plane as specified in 3GPP TS 33.503

[34] is used; or

[0432] iii) The Nonce_2 value received by the initiating UE when the direct communication is between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay UE and the security procedure on the control plane as specified in 3GPP TS 33.503

[34] is used;

[0433] For the purpose of establishing a session key on this 5G ProSe direct link in case the selected integrity protection algorithm is not an empty integrity protection algorithm;

[0434] 4) will include the selected security algorithm;

[0435] 5) will include the UE security capabilities received from the target UE in the ProSe direct link establishment request message or the ProSe direct link key update request message;

[0436] 6) will include the UE 5G ProSe direct signaling security policy received from the target UE in the ProSe direct link establishment request message;

[0437] 7) will include the LSB of the K NRP-sess ID selected by the initiating UE as specified in 3GPP TS 33.536

[37] , provided that the selected integrity protection algorithm is not an empty integrity protection algorithm;

[0438] Note 3: If the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, the K NRP-sess ID stores the ID corresponding to K NRP-sess If the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, the K NRP-sess ID stores the ID corresponding to K NRP-sess (if using the security procedure on the user plane) or K relay-sess (if using the security procedure on the control plane).

[0439] 8) When the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, if received from the 5G PKMF according to the security procedure on the user plane as specified in 3GPP TS 33.503

[34] , will include the GPI; and

[0440] 9) When the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, if received from the network according to the security procedure on the control plane as specified in 3GPP TS 33.503

[34] , will include the EAP message.

[0441] If the security protection of this 5G ProSe direct link is activated by using a non-empty integrity protection algorithm or a non-empty encryption protection algorithm, the initiating UE will use the K NRP-sessThe MSB of the ID and K included in the ProSe direct link security mode command message NRP-sess The LSB of the ID forms K NRP-sess The ID. The initiating UE will use K NRP-sess The ID to identify the new security context.

[0442] The initiating UE will set the source layer 2 ID and the destination layer 2 ID as follows:

[0443] 1) If the initiating UE acts as a 5G ProSe layer 3 UE to network relay UE and the authentication method based on EAP-AKA' is used as specified in Section 6.3.3.3 of 3GPP TS 33.503

[34] , then

[0444] Set the source layer 2 ID to the source layer 2 ID for the ProSe AA message transmission request message, and set the destination layer 2 ID to the destination layer 2 ID for the ProSe AA message transmission request message;

[0445] 2) If the initiating UE does not act as a 5G ProSe UE to network relay UE and has initiated a 5G ProSe direct link authentication procedure, then:

[0446] Set the source layer 2 ID to the source layer 2 ID for the ProSe direct link authentication request message, and set the destination layer 2 ID to the destination layer 2 ID for the ProSe direct link authentication request message;

[0447] 3) Otherwise, self-assign the source layer 2 ID and set the destination layer 2 ID to the source layer 2 ID in the ProSe direct link establishment request message.

[0448] Note 4: The UE implementation ensures that any value of the self-assigned source layer 2 ID is different from any other self-assigned source layer 2 ID used for 5G ProSe direct discovery as specified in Sections 6.2.14, 6.2.15, and 8.2.1, and different from any other pre-provisioned destination layer 2 ID as specified in Section 5.2.

[0449] Note 5: The target UE can reuse the layer 2 ID that the target UE used in the previous 5G ProSe direct link with the same peer UE.

[0450] After generating the ProSe direct link security mode command message, the initiating UE passes this message together with the following to the lower layer for transmission: the source layer 2 ID and the destination layer 2 ID, NRPIK (or K relay-int , if applicable), NRPEK (or K relay-enc , if applicable) (if applicable), KNRP-sess The ID, the selected security algorithm as specified in TS 33.536

[37] , the activation indication (if applicable) for 5G ProSe direct signaling security protection for the 5G ProSe direct link with the new security context, and start timer T5089. While timer T5089 is running, the initiating UE shall not send a new ProSe direct link security mode command message to the same target UE.

[0451] Note 6: The ProSe direct link security mode command message is integrity protected (and not encrypted) at the lower layer using the new security context.

[0452] If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link key update procedure, the initiating UE shall provide to the lower layer the activation indication (if applicable) for 5G ProSe direct user plane security protection for the 5G ProSe direct link with the new security context, together with the layer 2 ID of the initiating UE for 5G ProSe direct communication and the layer 2 ID of the target UE for 5G ProSe direct communication.

[0453] [The section titled "5G ProSe direct link security mode control procedure" in 3GPP TS 24.554 V18.2.0 Figure 7 .2.10.2.1 is reproduced as Figure 9

[0454] 7.2.10.3 5G ProSe direct link security mode control procedure accepted by the target UE

[0455] ​After receiving the ProSe direct link security mode command message, if it contains the layer 2 ID of the newly assigned initiating UE and if the 5G ProSe direct link authentication procedure has not been executed, the target UE will replace the layer 2 ID of the original initiating UE with the layer 2 ID of the newly assigned initiating UE for 5G ProSe direct communication. The target UE will check the selected security algorithm IE contained in the ProSe direct link security mode command message. If the "null integrity algorithm" is included in the selected security algorithm IE, integrity protection will not be provided for this 5G ProSe direct link, and signaling messages will be transmitted without protection. If the "null encryption algorithm" and an integrity algorithm other than the "null integrity algorithm" are included in the selected algorithm IE, encryption protection will not be provided for this 5G ProSe direct link, and signaling messages will be transmitted without protection. If the 5G ProSe direct signaling integrity protection policy of the target UE is set to "require signaling integrity protection", the target UE will check that the selected security algorithm IE in the ProSe direct link security mode command message does not contain a null integrity protection algorithm. If the selected integrity protection algorithm is not a null integrity protection algorithm, the target UE will:

[0456] a) If the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE:

[0457] 1) Derive K NRP based on K NRP-sess , Nonce_1, and Nonce_2 received in the ProSe direct link security mode command message, as specified in 3GPP TS 33.536

[37] ;

[0458] 2) Derive NRPIK based on K NRP-sess and the selected integrity algorithm, as specified in 3GPP TS 33.536

[37] ; and

[0459] 3) If K NRP-sess is derived and the selected encryption protection algorithm is not a null encryption protection algorithm, the target UE will derive NRPEK based on K NRP-sess and the selected encryption algorithm, as specified in 3GPP TS 33.536

[37] ; or

[0460] b) If the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE:

[0461] 1) If the security procedure on the control plane as specified in 3GPP TS 33.503

[34] is used, derive K relay-sess based on the security procedure on the control plane, and based on Krelay-sess and the selected integrity algorithm to derive K relay-int , as specified in 3GPP TS 33.503

[34] . If K is derived relay-sess and the selected cipher protection algorithm is not the null cipher protection algorithm, the target UE shall derive K relay-sess and the selected cipher algorithm, as specified in 3GPP TS 33.503

[34] ; or relay-enc

[0462] 2) If the security procedures on the user plane as specified in 3GPP TS 33.503

[34] are used, K is derived according to the security procedures on the user plane NRP-sess , and NRPIK is derived according to K NRP-sess and the selected integrity algorithm, as specified in 3GPP TS 33.503

[34] . If K is derived NRP-sess and the selected cipher protection algorithm is not the null cipher protection algorithm, the target UE shall derive NRPEK according to K NRP-sess and the selected cipher algorithm, as specified in 3GPP TS 33.503

[34] .

[0463] The target UE shall determine whether the ProSe direct link security mode command message can be accepted by the following operations:

[0464] a) If the 5G ProSe direct signaling integrity protection policy of the target UE is set to "require signaling integrity protection", check that the selected security algorithm IE in the ProSe direct link security mode command message does not contain the null integrity protection algorithm.

[0465] b) If the selected integrity protection algorithm is not the null integrity protection algorithm, require the lower layer to check the integrity of the ProSe direct link security mode command message using NRPIK (or K relay-int , if applicable) and the selected integrity protection algorithm;

[0466] c) Check that the received UE security capabilities have not changed compared to the values sent by the target UE to the initiating UE in the ProSe direct link establishment request message or ProSe direct link key update request message;

[0467] d) If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link establishment procedure,

[0468] 1) Check that the received UE 5G ProSe direct signaling security policy has not changed compared to the value sent by the target UE to the initiating UE in the ProSe direct link establishment request message; and​

[0469] 2) Check the K included in the ProSe direct link security mode command message NRP-sess The LSB of the ID is not set to the same value as those received from another UE in response to the ProSe direct link establishment request message for the target UE; and

[0470] e) If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link key update procedure and the integrity protection algorithm currently used for the 5G ProSe direct link is different from the null integrity protection algorithm, check that the selected security algorithm IE in the ProSe direct link security mode command message does not include the null integrity protection algorithm.

[0471] If the target UE does not include the KNRP ID in the ProSe direct link establishment request message, the target UE includes a re-authentication indication in the ProSe direct link key update request message, or the initiating UE has selected to derive:

[0472] a) A new K NRP if the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE; the target UE shall derive K NRP as specified in 3GPP TS 33.536

[37] ;

[0473] b) A new K NRP if the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE and uses the security procedure on the user plane as specified in 3GPP TS 33.503

[34] , the target UE shall derive K NRP as specified in 3GPP TS 33.536

[37] ; or

[0474] c) A new K NR_ProSe if the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE and uses the security procedure on the control plane as specified in 3GPP TS 33.503

[34] , the target UE shall derive K NR_ProSe as specified in 3GPP TS 33.536

[37] ; and

[0475] The target UE shall select the 2 LSBs of the K NRP ID to ensure that the resulting K NRP ID will be unique in the target UE. The target UE shall, based on the MSB of the received K NRP ID and its selected K NRPThe 2 LSBs of the ID form K NRP ID and shall be stored together with K NRP / K NR_ProSe to store the complete K NRP ID

[0476] Note 1: If the direct communication is not between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay UE, the K NRP ID saves the ID corresponding to K NRP If the direct communication is between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay UE, the K NRP ID saves the ID corresponding to K NRP (if the security procedure on the user plane is used) or K NR_ProSe (if the security procedure on the control plane is used).

[0477] If the GPI is included in the ProSe direct link security mode command message and the direct communication is between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay UE, then according to the security procedure on the user plane specified in 3GPP TS 33.503

[34] , the target UE will derive the UP-PRUK from the GPI, obtain the UP-PRUK ID, and use the UP-PRUK to derive K NRP .

[0478] If the target UE accepts the ProSe direct link security mode command message, the target UE shall create a ProSe direct link security mode completion message. In this message, the target UE:

[0479] a) If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link establishment procedure:

[0480] 1) If the 5G ProSe direct link is not used for 5G ProSe direct communication between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay UE, it shall contain the PQFI and the corresponding PC5 QoS parameters;

[0481] 2) If the 5G ProSe direct link is used for 5G ProSe direct communication between the 5G ProSe layer 3 remote UE and the 5G ProSe layer 3 UE-to-network relay UE, it may contain the PQFI and the corresponding PC5 QoS parameters;

[0482] Note 2: If the 5G ProSe direct link is used for 5G ProSe direct communication between a 5G ProSe layer 2 remote UE and a 5G ProSe layer 2 UE-to-network relay UE, the PQFI and the corresponding PC5 QoS parameters are not included.

[0483] b) If IP communication is used and the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link establishment procedure, an IP address configuration IE set to one of the following values will be included:

[0484] 1) "IPv6 Router", provided that only the IPv6 address allocation mechanism is supported by the target UE, i.e., acting as an IPv6 router;

[0485] 2) "DHCPv4 Server", provided that only the IPv4 address allocation mechanism is supported by the target UE, i.e., acting as a DHCPv4 server;

[0486] 3) "DHCPv4 Server and IPv6 Router", provided that both the IPv4 and IPv6 address allocation mechanisms are supported by the target UE; or

[0487] 4) "Address Allocation Not Supported", provided that neither the IPv4 nor the IPv6 address allocation mechanism is supported by the target UE;

[0488] Note 3: If the communication uses Ethernet or an unstructured data unit type, the UE does not include an IP address configuration IE nor a link-local IPv6 address IE.

[0489] c) If IP communication is used, the IP address configuration IE is set to "Address Allocation Not Supported" and the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link establishment procedure, a link-local IPv6 address IE formed locally based on IETF RFC4862

[25] will be included;

[0490] d) If a new K is derived NRP or a new K is received NRP or K NR_ProSe , then the 2 LSBs of the K NRP ID will be included; and

[0491] e) If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link establishment procedure, it shall include its UE 5G ProSe direct user plane security policy for this 5G ProSe direct link. In the case where different ProSe services are mapped to different 5G ProSe direct user plane security policies, when more than one ProSe identifier is included in the ProSe direct link establishment request message, the user plane security policies of those ProSe services shall be compatible. For example, "no need for user plane integrity protection" and "need for user plane integrity protection" are not compatible.

[0492] If the selected integrity protection algorithm is not the null integrity protection algorithm, the target UE shall generate K NRP-sess ID based on the MSB of the K NRP-sess ID that it has sent in the ProSe direct link establishment request message or ProSe direct link key update request message and the LSB of the K NRP-sess ID received in the ProSe direct link security mode command message. The target UE shall use the K NRP-sess ID to identify the new security context.

[0493] After generating the ProSe direct link security mode complete message, the target UE shall pass this message together with the following to the lower layer for transmission: the layer 2 ID of the target UE for 5G ProSe direct communication and the layer 2 ID of the initiating UE for 5G ProSe direct communication, the NRPIK (or K relay-int , if applicable), the NRPEK (or K relay-enc , if applicable) (if applicable), the K NRP-sess ID, the selected security algorithm as specified in 3GPP TS 33.536

[37] , and an indication of the activation of 5G ProSe direct signaling security protection for the 5G ProSe direct link with the new security context (if applicable).

[0494] Note 4: The ProSe direct link security mode complete message and other 5G ProSe direct signaling messages are integrity protected and encrypted (if applicable) at the lower layer using the new security context.

[0495] If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link key update procedure, the target UE shall provide to the lower layer an indication (if applicable) for activation of 5G ProSe direct user plane security protection for the 5G ProSe direct link with the new security context, together with the layer 2 ID of the initiating UE for 5G ProSe direct communication and the layer 2 ID of the target UE for 5G ProSe direct communication.

[0496] 7.2.10.4 Completion of the 5G ProSe direct link security mode control procedure by the initiating UE

[0497] Upon receipt of the ProSe direct link security mode completion message, the initiating UE shall stop timer T5089. If the selected integrity protection algorithm is not the null integrity protection algorithm, the UE shall check the integrity of the ProSe direct link security mode completion message. If the integrity check passes, the initiating UE shall then continue with the procedure to trigger the 5G ProSe direct link security mode control procedure. If the selected integrity protection algorithm is the null integrity protection algorithm, the UE shall continue with the procedure without checking integrity protection.

[0498] Upon receipt of the ProSe direct link security mode completion message, the initiating UE shall delete the old security context (if any) it has for the target UE.

[0499] 7.2.10.5 5G ProSe direct link security mode control procedure not accepted by the target UE

[0500] If the ProSe direct link security mode command message cannot be accepted, the target UE shall send a ProSe direct link security mode rejection message, and the target UE shall abort the ongoing procedure initiated to trigger the 5G ProSe direct link security mode control procedure, unless the ongoing procedure is the 5G ProSe direct link establishment procedure and the target user information is not included in the ProSe direct link establishment request message. The ProSe direct link security mode rejection message contains a PC5 signaling protocol cause IE indicating one of the following cause values:

[0501] #5: Lack of resources for the 5G ProSe direct link;

[0502] #7: Integrity failure;

[0503] #8: UE security capability mismatch;

[0504] #9: K NRP-sess LSB conflict of the ID;

[0505] #10: UE PC5 unicast signaling security policy mismatch;

[0506] #14: Authentication synchronization error; or

[0507] #111: Unsigned protocol error.

[0508] If this 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link establishment procedure and the implementation-specific maximum number of established NR 5G ProSe direct links has been reached, the target UE shall send a ProSe direct link security mode reject message containing the PC5 signaling protocol cause value #5 "Lack of resources for 5G ProSe direct link".

[0509] If the ProSe direct link security mode command message cannot be accepted because the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link establishment procedure, the selected security algorithm IE in the ProSe direct link security mode command message contains a null integrity protection algorithm, and the 5G ProSe direct signaling integrity protection policy of the target UE is set to "Require signaling integrity protection", the target UE shall include the PC5 signaling protocol cause #10 "UE PC5 unicast signaling security policy mismatch" in the ProSe direct link security mode reject message.

[0510] If the ProSe direct link security mode command message cannot be accepted because the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link key update procedure, the integrity protection algorithm currently used for the 5G ProSe direct link is different from the null integrity protection algorithm, and the selected security algorithm IE in the ProSe direct link security mode command message contains a null integrity protection algorithm, the target UE shall include the PC5 signaling protocol cause #10 "UE PC5 unicast signaling security policy mismatch" in the ProSe direct link security mode reject message.

[0511] If the target UE detects that the UE security capability IE received in the ProSe direct link security mode command message has changed compared to the most recent value sent by the target UE to the initiating UE in the ProSe direct link establishment request message or the ProSe direct link key update request message, the target UE shall include the PC5 signaling protocol cause #8 "UE security capability mismatch" in the ProSe direct link security mode reject message.

[0512] If the target UE detects the K included in the ProSe direct link security mode command message NRP-sessIf the LSB of the ID is set to the same values as those received from another UE in response to a ProSe direct link establishment request message for the target UE, the target UE shall include in the ProSe direct link security mode reject message the PC5 signalling protocol cause #9 "K NRP- sess LSB conflict of ID".

[0513] If the 5G ProSe direct link security mode control procedure is for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, and the ProSe direct link security mode command message cannot be accepted due to a synchronization error when processing the authentication vector (if any) contained in the GPI sent by the 5G ProSe UE-to-network relay UE to the 5G ProSe remote UE, the target UE shall include in the ProSe direct link security mode reject message the PC5 signalling protocol cause #14 "Authentication synchronization error", and shall include the RAND and AUTS parameters in the ProSe direct link security mode reject message.

[0514] After generating the ProSe direct link security mode reject message, the target UE shall pass this message, together with the layer 2 ID of the originating UE for 5G ProSe direct communication and the layer 2 ID of the target UE for 5G ProSe direct communication, to the lower layer for transmission.

[0515] After receiving the ProSe direct link security mode reject message, the originating UE shall stop timer T5089, provide an indication to the lower layer to deactivate 5G ProSe direct security protection and delete the security context for the 5G ProSe direct link (if applicable), and:

[0516] a) If the PC5 signalling protocol cause IE in the ProSe direct link security mode reject message is set to #9 "K NRP-sess LSB conflict of ID", retransmit the ProSe direct link security mode command message with different values of the LSB of K NRP-sess ID, and restart timer T5089;

[0517] b) If the PC5 signalling protocol cause IE in the ProSe direct link security mode reject message is set to #14 “Authentication synchronization error”, the message contains RAND and AUTS, and the 5G ProSe direct link security mode control procedure is for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, a fresh GPI may be extracted from the PKMF by sending a key request message containing RAND and AUTS, as specified in 3GPP TS 33.503

[34] ; or

[0518] c) If the PC5 signalling protocol cause IE is set to a value other than #9 “LSB conflict of K NRP-sess ID” and other than #14 “Authentication synchronization error”, abort the ongoing procedure that triggered the 5G ProSe direct link security mode control procedure.

[0519] […]

[0520] 8.2.10.2.3 5G ProSe Remote User Key Request Procedure

[0521] 8.2.10.2.3.1 General

[0522] The purpose of the 5G ProSe remote user key request procedure is for the UE authorized to act as a 5G ProSe remote UE to obtain the UP-PRUK and UP-PRUK ID.

[0523] […]

[0524] 8.2.10.2.4 Key Request Procedure

[0525] 8.2.10.2.4.1 General

[0526] The purpose of the key request procedure is for the UE acting as a 5G ProSe UE-to-network relay to obtain the security parameters required to establish a 5G ProSe direct link with a 5G ProSe remote UE.

[0527] 8.2.10.2.4.2 Initiation of Key Request Procedure

[0528] The UE shall initiate the key request procedure:

[0529] a) When the UE acting as a 5G ProSe UE-to-network relay for the relay service code receives a request to establish a 5G ProSe direct link from a 5G ProSe remote UE; and

[0530] b) When the 5G ProSe direct link security mode control procedure is rejected by the 5G ProSe remote UE due to an authentication synchronization error.

[0531] The UE will send with <key-request>The PROSE_KEY_REQUEST message of the element is used to initiate the key request procedure. In <key-request>Among the elements, UE:

[0532] a) will contain a new transaction ID;

[0533] b) will contain a relay service code in which the establishment of a 5G ProSe direct link is requested;

[0534] c) will contain the SUCI or UP-PRUK ID of the 5G ProSe remote UE received from the 5G ProSe remote UE;

[0535] d) will contain the K received from the 5G ProSe remote UE NRP freshness parameter 1;

[0536] e) will contain the PLMN identity of the HPLMN of the 5G ProSe remote UE if received from the 5G ProSe remote UE; and

[0537] f) will contain the AUTS and RAND received from the 5G ProSe remote UE if the key request procedure is initiated after the 5G ProSe direct link security mode control procedure is rejected by the 5G ProSe remote UE due to an authentication synchronization error.

[0538] Figure 8 .2.10.2.4.2.1 shows the interaction between the UE and the 5G PKMF in the key request procedure.

[0539] [[The one named "Key Request Procedure" in 3GPP TS24.554 V18.2.0 Figure 8 .2.10.2.4.2.1 is reproduced as Figure 10

[0540] 8.2.10.2.4.3 Key request procedure accepted by the 5G PKMF

[0541] Upon receiving one with <key-request>After the PROSE_KEY_REQUEST message of the element, if:

[0542] a) The PROSE_KEY_REQUEST message is received in the PROSE_KEY_REQUEST message through a TLS tunnel established by the UE authorized to act as a 5G ProSe UE-to-network relay for the relay service code; and

[0543] b) The 5G ProSe remote UE (if present) providing the SUCI, UP-PRUK ID or AUTS and the PLMN identity of the HPLMN of the 5G ProSe remote UE indicated in the PROSE_KEY_REQUEST message is authorized to act as the 5G ProSe remote UE for the relay service code indicated in the PROSE_KEY_REQUEST message;

[0544] The 5G PKMF will send a message containing <key-accept>PROSE_KEY_RESPONSE message for the element. In <key-accept>In the element, 5G PKMF:

[0545] a) will include a transaction ID having a value set to the transaction ID received in the PROSE_KEY_REQUEST message;

[0546] b) will include the UP-PRUK ID of the 5G ProSe remote UE;

[0547] c) will include K NRP ;

[0548] d) will include K NRP freshness parameter 2; and

[0549] e) will include GBA push information (GPI) if AUTS and RAND are included in the PROSE_KEY_REQUEST message or a new UP-PRUK is required.

[0550] If the 5G ProSe remote UE is served by another 5G PKMF, the 5G PKMF of the 5G ProSe UE-to-network relay requests the 5G PKMF of the 5G ProSe remote UE to check the SUCI, UP-PRUK ID or AUTS indicated in the PROSE_KEY_REQUEST message provided by the 5G ProSe remote UE and the PLMN identity of the HPLMN of the 5G ProSe remote UE (if present) to be authorized to act as the 5G ProSe remote UE for the relay service code indicated in the PROSE_KEY_REQUEST message and provide the UP-PRUK ID, K NRP 、K NRP freshness parameter 2 and optionally GBA push information (GPI) of the 5G ProSe remote UE.

[0551] 8.2.10.2.4.4 Completion of the key request procedure by the UE

[0552] After receiving a PROSE_KEY_RESPONSE message having a <key_accept> element, if the transaction ID included in the <key_accept> element matches the value sent by the UE in the PROSE_KEY_REQUEST message having a <KEY_REQUEST> element, the UE will use the UP-PRUK ID, K NRP 、K NRP freshness parameter 2 and GBA push information (GPI) (if received) of the 5G ProSe remote UE in the 5G ProSe direct link establishment.

[0553] 8.2.10.2.4.5 Key Request Procedures Not Accepted by 5G PKMF

[0554] If the 5G PKMF cannot accept a key with <key-request>For the PROSE_KEY_REQUEST message of the element, the 5GPKMF will send a message containing <key-reject>PROSE_KEY_RESPONSE message of the element. In <key-reject>In the element, the 5G PKMF will include a transaction ID set to the value of the transaction ID received in the PROSE_KEY_REQUEST message and will include an appropriate PC8 control protocol cause value.

[0555] Note: When, for example, the UP-PRUK is not found in the network, the 5G PKMF decides to reject the PROSE_KEY_REQUEST message.

[0556] After receiving a PROSE_KEY_RESPONSE message with a <key_reject> element, if the transaction ID included in the <key_reject> element matches the value sent by the UE in the PROSE_KEY_REQUEST message with a <KEY_REQUEST> element, the UE shall consider the key request procedure as rejected.

[0557] 8.2.10.2.4.6 Abnormal situations in the UE

[0558] The following abnormal situations can be identified:

[0559] a) The transport layer indicates the delivery failure of the PROSE_KEY_REQUEST message (e.g., after the TCP retransmission timeout)

[0560] The UE shall close the existing secure connection with the 5G PKMF, establish a new secure connection, and then restart the key request procedure.

[0561] b) After the PROSE_KEY_REQUEST message has been successfully delivered, the 5G PKMF does not respond (e.g., a TCP ACK for the PROSE_KEY_REQUEST message has been received)

[0562] The UE shall retransmit the PROSE_KEY_REQUEST message.

[0563] Note: The timer that triggers the retransmission and the maximum number of retransmissions allowed are specific to the UE implementation.

[0564] 8.2.10.2.4.7 Abnormal situations in the 5G PKMF

[0565] The following abnormal situations can be identified:

[0566] a) The lower layer indicates the delivery failure of the PROSE_KEY_RESPONSE message

[0567] After receiving an indication from the lower layer that the PROSE_KEY_RESPONSE message has not been successfully acknowledged (e.g., no TCP ACK has been received), the 5G PKMF will abort the procedure.

[0568] 3GPP TS 33.503 introduces the following concepts:

[0569] 6.3.3.2.2 PC5 security establishment for 5G ProSe UE-to-network relay communication on the user plane

[0570] [The procedure named "PC5 security establishment for 5G ProSe UE-to-network relay communication on the user plane" in 3GPP TS 33.503 V18.0.0 Figure 6 .3.3.2.2-1 is reproduced as Figure 11

[0571] […]

[0572] 4a. The 5G ProSe UE-to-network relay sends a key request message containing the UP-PRUK ID or SUCI, RSC, and K NRP freshness parameter 1 to its 5G PKMF. If the HPLMN ID of the 5G ProSe remote UE is included in the DCR, the key request message shall also include the said HPLMN ID.

[0573] […]

[0574] 4e. The 5G PKMF of the 5G ProSe UE-to-network relay sends a key response message to the 5G ProSe UE-to-network relay, the key response message containing the remote user ID, K NRP , K NRP freshness parameter 2, GPI (if used) to calculate the fresh UP-PRUK for the UE-to-network relay.

[0575] 5a. The 5G ProSe UE-to-network relay shall derive the session key (K NRP ) based on K NRP-SESS , and then derive the confidentiality key (NRPEK) (if applicable) and the integrity key (NRPIK) based on the PC5 security policy, as specified in TS 33.536 [6]. The 5G ProSe UE-to-network relay shall store the remote user ID received in step 4d. The establishment of the KNRP ID and KNRP-sess ID is as specified in TS 33.536 [6]. The 5G ProSe UE-to-network relay sends a direct security mode command message to the 5G ProSe remote UE. This message shall also include the K NRP freshness parameter 2 in addition to the parameters specified in TS 33.536 [6], and shall be protected as specified in TS 33.536 [6].

[0576] […]​

[0577] 5c. The 5G ProSe direct security mode complete message for the remote UE responds to the 5G ProSe UE-to-network relay, as specified in TS 33.536 [6].

[0578] […]

[0579] 6.6.3.1 Network-assisted security for 5G ProSe PC5 communication for 5G ProSe layer 3 UE-to-UE relay

[0580] The procedures based on the User Plane (UP) as specified in Section 6.3.3.2 and the procedures based on the Control Plane (CP) as specified in Section 6.3.3.3 are used to provide authentication, authorization, and security establishment between the 5G ProSe layer 3 UE-to-UE relay and the source UE, with the following modifications:

[0581] - The remote UE is replaced by the source UE.

[0582] - The UE-to-network relay is replaced by the UE-to-UE relay.

[0583] The procedures based on the User Plane (UP) as specified in Section 6.3.3.2 and the procedures based on the Control Plane (CP) as specified in Section 6.3.3.3 are used to provide authentication, authorization, and security establishment between the 5G ProSe layer 3 UE-to-UE relay and the destination UE, with the following modifications:

[0584] - The remote UE is replaced by the destination UE.

[0585] - The UE-to-network relay is replaced by the UE-to-UE relay.

[0586] - The procedures are initiated after the successful completion of security establishment between the 5G ProSe layer 3 UE-to-UE relay and the source UE, as specified in Section 6.7 of TS 23.304 [8].

[0587] - Steps 4 - 5d in Section 6.3.3.2.2 and steps 3 - 16 in Section 6.3.3.3.2 are not triggered by the Direct Communication Request (DCR) message sent by the inter-UE relay. After receiving the DCR message containing the RSC from the inter-UE relay and if the network-assisted security indicator associated with the RSC indicates that a network-assisted security procedure is required to trigger the establishment of the second-hop PC5 link security, the target UE will notify the inter-UE relay to initiate the above steps using messages for direct communication security request and direct communication security acceptance. The direct communication security request message will contain the SUCI or UP-PRUK / CP-PRUK ID of the target UE, the relay service code, and freshness_parameter_1. After receiving the direct communication security request message, the inter-UE relay needs to ensure that it is within the network coverage before initiating the security procedure.

[0588] - The direct communication request sent by the inter-UE relay to the target UE does not contain the PRUK-ID. Therefore, by modifying Appendix A.7 to generate a key stream of the RSC length, the security mechanism in Section 6.3.5 is modified to only protect the RSC.

[0589] - The direct communication security request message is protected by reusing the protection method defined in Section 6.3.5.

[0590] Figure 6 .6.3.1 - 1 shows the high-level process of the second-hop PC5 link security between the 5G ProSe layer 3 inter-UE relay and the target UE.

[0591] [[3GPP TS 33.503 V18.0.0, named "PC5 Security Establishment Procedure between 5G ProSe Inter-UE Relay and Target 5G ProSe End UE"]] Figure 6 .6.3.1 - 1 is reproduced as Figure 12

[0592] 3GPP C1-238124 introduced the following concepts:

[0593] 8a.2.x 5G ProSe Inter-UE Relay Direct Link Security Establishment Procedure

[0594] 8a.2.x.1 Overview

[0595] The purpose of the 5G ProSe inter-UE relay direct link security establishment procedure is to enable the target 5G ProSe end UE to establish security between the 5G ProSe UE inter-UE relay UE and the target 5G ProSe end UE. ​

[0596] When the target 5G ProSe end UE receives a ProSe direct link establishment request message from a 5G ProSe UE - to - UE relay UE and the network - assisted security indicator associated with the received relay service code indicates that a network - assisted security procedure is required, the procedure is triggered.

[0597] 8a.2.x.2 Initiate the 5G ProSe UE - to - UE relay direct link security establishment procedure by the initiating UE

[0598] The initiating UE shall meet the following prerequisites before initiating this procedure:

[0599] a) Receive a ProSe direct link establishment request message;

[0600] b) The initiating UE acting as the target 5G ProSe end UE is authorized to use the 5G ProSe UE - to - UE relay UE in the registered PLMN or the local PLMN;

[0601] c) The network - assisted security indicator associated with the received relay service code indicates that a network - assisted security procedure is required.

[0602] The UE shall initiate the 5G ProSe UE - to - UE relay direct link security establishment procedure by sending a ProSe direct link security establishment request message. The initiating UE:

[0603] a) Shall include:

[0604] 1) Nonce_1, provided that the security procedure on the control plane is used as specified in 3GPP TS 33.503

[34] ; or

[0605] 2) K NRP Freshness parameter 1, provided that the security procedure on the user plane is used as specified in 3GPP TS 33.503

[34] ;

[0606] If the UE PC5 unicast signaling integrity protection policy is set to "signaling integrity protection required" or "preferred signaling integrity protection", a 128 - bit random numerical value generated by the initiating UE is set for the purpose of session key establishment on this 5G ProSe direct link;

[0607] b) Shall include its UE security capabilities, indicating a list of algorithms supported by the initiating UE for the security establishment of this 5G ProSe direct link;

[0608] c) If the UE PC5 unicast signaling integrity protection policy is set to "Require signaling integrity protection" or "Preferred signaling integrity protection", then it shall include the MSB of the K NRP-sess ID selected by the originating UE as specified in 3GPP TS 33.503

[34] ;

[0609] d) It shall include its UE PC5 unicast signaling security policy. The signaling integrity protection policy shall be set to "Require signaling integrity protection";

[0610] e) It shall include a Relay Service Code IE set to indicate the relay service code of the connectivity service requested by the source 5G ProSe end UE;

[0611] f) It shall include the four least significant bits of a UTC-based counter set as the UTC-based counter LSB;

[0612] g) It shall include a UE Identity IE which is set to the SUCI of the originating UE in the following cases:

[0613] 1) The 5G ProSe direct link establishment procedure is for direct communication between the target 5G ProSe end UE and the relay UE among 5G ProSe UEs; and

[0614] 2) The security for 5G ProSe UE-to-UE relay uses the security procedure on the control plane and the originating UE does not have a valid CP-PRUK as specified in 3GPP TS 33.503

[34] , or the security for 5G ProSe UE-to-UE relay uses the security procedure on the user plane and the originating UE does not have a valid UP-PRUK as specified in 3GPP TS 33.503

[34] ;

[0615] h) It shall include a User Security Key ID IE which is set to:

[0616] 1) The UP-PRUK ID of the originating UE, provided that:

[0617] i) The 5G ProSe direct link establishment procedure is for direct communication between the target 5G ProSe end UE and the relay UE among 5G ProSe UEs;

[0618] ii) The originating UE has a valid UP-PRUK; and

[0619] iii) The security for 5G ProSe UE-to-UE relay uses the security procedure on the user plane as specified in 3GPP TS33.503

[34] ; or

[0620] 2) The CP-PRUK ID of the originating UE associated with the relay service code of the target UE, provided that:

[0621] i) The 5G ProSe direct link establishment procedure is used for direct communication between the target 5G ProSe end UE and the relay UE among 5G ProSe UEs;

[0622] ii) The originating UE has a valid CP-PRUK associated with the relay service code of the target UE; and

[0623] iii) The security for relay among 5G ProSe UEs uses the security procedures on the control plane as specified in 3GPP TS 33.503

[34] ;

[0624] i) If the UP-PRUK ID of the originating UE is included and it is not in NAI format (see 3GPP TS 33.503

[34] ), the HPLMN ID of the originating UE will be included;

[0625] j) If the relay UE among 5G ProSe UEs and the target 5G ProSe end UE have a DUIK, the MIC IE set to the calculated MIC value as specified in 3GPP TS 33.503

[34] will be included.

[0626] Editor's note: How to set the layer 2 ID of the ProSe direct link establishment request message remains to be further studied.

[0627] Editor's note: The retransmission timer of the ProSe direct link security establishment request message remains to be further studied.

[0628] [[3GPP C1-238124, named "5G ProSe Direct Link Security Establishment Procedure" Figure 8 a.2.x.2.1 is reproduced as Figure 13

[0629] 8a.2.x.3 5G ProSe UE-to-UE Relay Direct Link Security Establishment Procedure Accepted by the Target UE

[0630] After receiving the ProSe direct link security establishment request message, the target UE will verify the MIC field in the received ProSe direct link security establishment request with the DUIK (if available) and decrypt the encrypted:

[0631] a) Relay service code; and

[0632] b) UP-PRUK ID or CP-PRUK ID (if received), ​

[0633] The DUCK or DUSK has an associated encrypted bit mask for 5G ProSe UE - to - UE relay discovery (see section 6.6.3.1 of 3GPP TS 33.503

[34] ), and the target UE verifies whether the relay service code matches the code sent by the target UE in the ProSe direct link establishment request message.

[0634] Note 1: If the UE is neither configured to use DUCK nor configured to use DUSK, the relay service code and the UP - PRUK ID or CP - PRUK ID are not encrypted.

[0635] If the target UE is authorized to act as a 5G ProSe UE - to - UE relay UE and is within the NG - RAN coverage, the target UE will proceed as follows:

[0636] a) An authentication and key agreement procedure, as specified in section 5.5.4 of 3GPP TS24.501

[11] , provided that the security procedures on the control plane as specified in 3GPP TS 33.503

[34] are used; or

[0637] b) A key request procedure, as specified in section 8.2.10.2.4, provided that the security procedures on the user plane as specified in 3GPP TS 33.503

[34] are used;

[0638] And will initiate a 5G ProSe direct link security mode control procedure, as specified in section 7.2.10.

[0639] The target UE will:

[0640] a) If the security procedures on the control plane as specified in 3GPP TS 33.503

[34] are used, request a new K according to the security procedures on the user plane as specified in 3GPP TS 33.503

[34] NR_ProSe ; or

[0641] b) If the security procedures on the user plane as specified in 3GPP TS 33.503

[34] are used, request a new K according to the security procedures on the user plane. NRP .

[0642] Note 2: How many times the 5G ProSe direct link authentication procedure needs to be executed to derive a new K NRP depends on the authentication method used.

[0643] After deriving a new K NRP or after receiving a new K NRP or K NR_ProSe After that, the target UE shall initiate the 5G ProSe direct link security mode control procedure as specified in Section 7.2.10. The target UE determines whether the ProSe direct link security establishment request message can be accepted based on the result of the 5G ProSe direct link security mode control procedure.

[0644] If the target UE accepts the 5G ProSe direct link security establishment procedure, the target UE shall create a ProSe direct link security establishment acceptance message and pass the message, together with the layer 2 ID of the initiating UE for unicast communication and the layer 2 ID of the target UE for unicast communication, to the lower layer for transmission.

[0645] Editor's note: The content of the ProSe direct link security establishment acceptance message remains to be further studied.

[0646] 8a.2.x.4 Completion of the 5G ProSe UE-to-UE relay direct link security establishment procedure by the initiating UE

[0647] For each received ProSe direct link security establishment acceptance message, the initiating UE shall create a ProSe direct link establishment acceptance message as specified in Section 7.2.2.4.

[0648] 8a.2.x.5 5G ProSe UE-to-UE relay direct link security establishment procedure not accepted by the target UE

[0649] If the ProSe direct link security establishment request message cannot be accepted, the target UE shall send a ProSe direct link security establishment rejection message. The ProSe direct link security establishment rejection message contains a PC5 signaling protocol cause IE set to one of the following cause values:

[0650] #6 Authentication failure

[0651] #7 Integrity failure;

[0652] #13 Congestion situation;

[0653] #15 Security procedure failure for 5G ProSe UE-to-UE relay;

[0654] #111 Unspecified protocol error. If the target UE acting as a 5G ProSe UE-to-UE relay UE is in a congested state, the target UE shall send a ProSe direct link security establishment rejection message containing the PC5 signaling protocol cause value #13 "Congestion situation". The target UE may provide a fallback timer value to the initiating UE in the ProSe direct link security establishment rejection message.

[0655] If the 5G ProSe direct link security establishment procedure fails due to the failure of the security procedure on the control plane or the security procedure on the user plane as specified in 3GPP TS 33.503

[34] , the target UE shall send a ProSe direct link security establishment rejection message containing the PC5 signaling protocol cause value #15 "Security procedure failure for 5G ProSe inter-UE relay". If an EAP message is received from the network according to the security procedure on the control plane specified in 3GPP TS 33.503

[34] , the target UE shall provide the said EAP message.

[0656] If the 5G ProSe direct link security establishment procedure fails for other reasons, the target UE shall send a ProSe direct link security establishment rejection message containing the PC5 signaling protocol cause value #111 "Unspecified protocol error".

[0657] After sending the ProSe direct link security establishment rejection message, the target UE shall provide the following information to the lower layer, together with the layer 2 ID of the initiating UE for unicast communication and the layer 2 ID of the target UE for unicast communication:

[0658] a) Indication of deactivation of PC5 unicast security protection and deletion of the security context for the 5G ProSe direct link (if applicable).

[0659] After receiving the ProSe direct link security establishment rejection message, the initiating UE shall provide the following information to the lower layer, together with the layer 2 ID of the initiating UE for unicast communication and the layer 2 ID of the target UE for unicast communication:

[0660] a) Indication of deactivation of PC5 unicast security protection and deletion of the security context for the 5G ProSe direct link (if applicable).

[0661] […]

[0662] According to 3GPP TS23.304, the UE can execute the PC5 unicast link establishment procedure with the peer UE (e.g., layer 2 link establishment) to establish a layer 2 link or unicast link between the two UEs. Basically, the layer 2 identity / identifier (ID) of the peer UE identified by the application layer ID of the peer UE can be discovered via discovery messages during the establishment of the PC5 unicast link or via previous sidelink communication, such as an existing or previous unicast link to the same application layer ID is known to the UE, or obtained from an application layer service notification. The initial signaling for establishing the PC5 unicast link (i.e., direct communication request) can use the known layer 2 ID of the peer UE or a preset destination layer 2 ID associated with a proximity-based service (ProSe) service / application configured for PC5 unicast link establishment. During the PC5 unicast link establishment procedure, the layer 2 IDs of the two UEs are exchanged and used for future communication between the two UEs. Additionally, according to 3GPP TS24.554, the two UEs will exchange security information with each other during the PC5 unicast link establishment, so that the two UEs use the negotiated security context (including security algorithms and / or keys) to protect the content of the traffic sent on the PC5 unicast link (including, for example, PC5-S signaling, PC5-RRC signaling, and / or PC5 user plane data).

[0663] According to 3GPP TS23.304, UE-to-UE relay is supported in sidelink communication, which means that in the case where two UEs (e.g., source UE / UE1 and destination UE / UE2) cannot communicate directly with each other, a relay UE can be used to support data communication between the two UEs. UE-to-UE relay communication can include a first-hop direct link established between UE1 and the relay UE and a second-hop direct link established between the relay UE and UE2.

[0664] To support security in UE-to-UE (U2U) relay communication, network-assisted security for 5G ProSe PC5 communication for 5G ProSe layer 3 UE-to-UE relay is introduced in section 6.6.3.1 of 3GPP TS 33.503, and non-network-assisted security for 5G ProSe PC5 communication for 5G ProSe layer 3 UE-to-UE relay is introduced in section 6.6.3.2 of 3GPP TS 33.503. It should be noted that the service flow in the case of non-network assistance considers section 6.7.1.1 of 3GPP TS23.304 and sections 7.2.2 and 7.2.10 of 3GPP TS24.554, and can be shown in Figure 14 Specifically, Figure 14 Show an exemplary step - by - step process for network - unaided PC5 security establishment for U2U relay communication based on relevant standards.

[0665] Regarding the service flow in the case of network - assisted security in U2U relay communication, at least Sections 7.2.2, 7.2.10, 8.2.10.2.3, and 8.2.10.2.4 of TS 3GPP24.554 and Sections 6.6.3.1 and 6.3.3.2.2 of 3GPP TS 33.503 are considered, and can be shown as successfully completing network - assisted PC5 security establishment for U2U relay communication. Figure 15A in the service flow shown in

[0666] Figure 15A The details of each step in the service flow shown in are as follows:

[0667] 1. The source UE (i.e., UE1) can perform a discovery procedure and then find a relay UE that can support U2U relay communication.

[0668] 2. UE1 can send a message to the network requesting the root security key for U2U relay communication with the relay UE. This message can be a ProSe remote user key request message. If UE1 is within the network / cell coverage area, UE1 can send this message. If UE1 has a valid root security key (i.e., UP - PRUK), UE1 can include the identifier of the valid root security key (i.e., UP - PRUK ID) in this message.

[0669] UE1 can receive a response message from the network (if UE1 is within the network / cell coverage area). This message can be a ProSe remote user key response message. This response message can contain the requested root security key and the root security key ID (i.e., UP - PRUK ID).

[0670] These messages and the corresponding response messages can be sent using IP transport (i.e., by using IP packets).

[0671] 3. UE1 can send a PC5-S message to the relay UE to establish a first-hop direct link with the relay UE for U2U relay communication. This PC5-S message can be a direct communication request message. If UE1 has a valid root security key, the PC5-S message can include the root security key ID. On the contrary, if UE1 does not have a valid root security key, the PC5-S message can include the SUCI of UE1. Other parameters in the PC5-S message can refer to relevant standards. The PC5-S message can trigger the relay UE to execute a key request procedure with the network (if the relay service code included in the PC5-S message is associated with information indicating the need for network-assisted security establishment (e.g., network-assisted security indicator)).

[0672] This PC5-S message can be sent on the PC5 interface, that is, this PC5-S message can be sent by using the layer 2 ID of UE1 as the source layer 2 ID and using the layer 2 ID of the relay UE as the destination layer 2 ID. It should be noted that the layer 2 ID of the relay UE can be learned by receiving a discovery message from the relay UE during the discovery procedure.

[0673] 4. In the key request procedure, the relay UE can send a message to the network requesting an intermediate security key for U2U relay communication with UE1. This message can be a key request message. If the PC5-S message in step 3 includes the root security key ID, the root security key ID can be included in this message. If the PC5-S message in step 3 includes a Subscription Concealed Identifier (SUCI), the SUCI can be included in this message. Other parameters in this message can refer to relevant standards.

[0674] The relay UE can receive a response message from the network. This response message can include the intermediate security key (i.e., K NRP ) and other parameters specified in the relevant standards. If the message sent from the relay UE to the network includes the SUCI, this response message can also include information (e.g., GPI) for UE1 to derive / determine / calculate the intermediate security key. This information for UE1 to derive / determine / calculate the intermediate security key can be forwarded to UE1.

[0675] This message and the corresponding response message can be sent by using IP transmission.

[0676] 5. The relay UE may send a PC5-S message to UE1 to establish a security context on the first-hop direct link. This PC5-S message may be a security mode command message. This PC5-S message may contain information (e.g., GPI) for UE1 to derive / determine / calculate a security key (if the SUCI is included in the PC5-S message in step 3).

[0677] The relay UE may receive a response PC5-S message from UE1 to complete the establishment of the security context. This response PC5-S message may be a security mode complete message.

[0678] This PC5-S message and the corresponding response PC5-S message may be sent on the PC5 interface. This PC5-S message may be sent by using the layer 2 ID of UE1 as the destination layer 2 ID and the layer 2 ID of the relay UE as the source layer 2 ID. This response PC5-S message may be sent by using the layer 2 ID of UE1 as the source layer 2 ID and the layer 2 ID of the relay UE as the destination layer 2 ID.

[0679] 6. Then the relay UE may send a PC5-S message to UE2 to establish a second-hop direct link for U2U relay communication. This PC5-S message may be a direct communication request message. The relay service code may be included in this PC5-S message and may be associated with information indicating the need for network-assisted security establishment (e.g., network-assisted security indicator).

[0680] This PC5-S message may be sent on the PC5 interface. This PC5-S message may be sent by using the layer 2 ID of UE2 or the broadcast layer 2 ID as the destination layer 2 ID and the layer 2 ID of the relay UE as the source layer 2 ID.

[0681] 7. UE2 may send a message to the network to request the root security key for U2U relay communication with the relay UE. This message may be a ProSe remote user key request message. If UE2 is within the network / cell coverage, UE2 may send this message. If UE2 has a valid root security key (i.e., UP-PRUK), UE2 may include the identifier of the valid root security key (i.e., UP-PRUK ID) in this message.

[0682] UE2 may receive a response message from the network (if UE2 is within the network / cell coverage). This response message may contain the requested root security key and the root security key ID (i.e., UP-PRUK ID). It should be noted that the root security key of UE1 and the root security key of UE2 may be the same or different.

[0683] The message and the corresponding response message can be sent by using IP transmission (i.e., by using IP packets).

[0684] 8. UE2 can send a PC5-S message to the relay UE to trigger the relay UE to execute a key request procedure with the network. The PC5-S message can be a direct communication security request message. If UE2 has a valid root security key (i.e., UP-PRUK), UE2 can include the identifier of the valid root security key (i.e., UP-PRUK ID) in the message; otherwise, UE2 can include the SUCI of UE2 in the message.

[0685] The PC5-S message can be sent on the PC5 interface. The PC5-S message can be sent by using the layer 2 ID of UE2 as the source layer 2 ID and using the layer 2 ID of the relay UE as the destination layer 2 ID.

[0686] 9. In the key request procedure, the relay UE can send a message to the network to request an intermediate security key for U2U relay communication with UE2. The message can be a key request message. If the PC5-S message in step 8 contains the root security key ID (i.e., UP-PRUK ID), the root security key ID can be included in the message. If the PC5-S message in step 8 contains the SUCI, the SUCI can be included in the message. Other parameters in the message can refer to the relevant standards.

[0687] The relay UE can receive a response message from the network. The response message can contain the intermediate security key (i.e., K NRP ) used in the second-hop direct link and other parameters specified in the relevant standards. If the message sent from the relay UE to the network contains the SUCI, the response message can also contain information (e.g., GPI) for UE2 to derive / determine / calculate the intermediate security key. The information for UE2 to derive / determine / calculate the intermediate security key can be forwarded to UE2. It should be noted that the intermediate security key used in the first-hop direct link and the intermediate security key used in the second-hop direct link can be the same or different.

[0688] The message and the corresponding response message can be sent by using IP transmission.

[0689] 10. The relay UE can send a PC5-S message to UE2 to establish a security context on the second-hop direct link. The PC5-S message can be a security mode command message. The PC5-S message can contain information for UE2 to derive / determine / calculate the intermediate security key (if the SUCI is included in the PC5-S message in step 8).

[0690] The relay UE may receive a response PC5-S message from UE1 that completes the establishment of the security context. This response PC5-S message may be a security mode completion message.

[0691] This PC5-S message and the corresponding response PC5-S message may be sent on the PC5 interface. This PC5-S message may be sent by using the layer 2 ID of UE2 as the destination layer 2 ID and the layer 2 ID of the relay UE as the source layer 2 ID. This response PC5-S message may be sent by using the layer 2 ID of UE2 as the source layer 2 ID and the layer 2 ID of the relay UE as the destination layer 2 ID.

[0692] 11. The relay UE may send a response PC5-S message corresponding to the PC5-S message in step 8 to UE2. This response PC5-S message may be a direct communication security acceptance message.

[0693] This response PC5-S message may be sent on the PC5 interface. This response PC5-S message may be sent by using the layer 2 ID of UE2 as the destination layer 2 ID and the layer 2 ID of the relay UE as the source layer 2 ID.

[0694] 12. UE2 may send a PC5-S message to the relay UE that completes the establishment of the second-hop direct link. This PC5-S message may be a direct communication acceptance message.

[0695] This PC5-S message may be sent on the PC5 interface. This PC5-S message may be sent by using the layer 2 ID of UE2 as the source layer 2 ID and the layer 2 ID of the relay UE as the destination layer 2 ID.

[0696] 13. The relay UE may send a PC5-S message to UE1 that completes the establishment of the first-hop direct link. This PC5-S message may be a direct communication acceptance message.

[0697] This PC5-S message may be sent on the PC5 interface. This PC5-S message may be sent by using the layer 2 ID of UE1 as the destination layer 2 ID and the layer 2 ID of the relay UE as the source layer 2 ID.

[0698] During the key request procedure between the relay UE and the network for requesting the intermediate security key used in the second-hop direct link, the time to receive the key response message may exceed the period expected by the relay UE (due to, for example, poor network throughput). Therefore, the key request procedure may be considered a failure. In this case, the relay UE may send a PC5-S rejection message corresponding to the PC5-S message used to trigger the relay UE to execute the key request procedure. This PC5-S rejection message may be a direct communication security rejection message.

[0699] According to 3GPP TS 33.503, after sending a direct communication security rejection message, the relay UE only provides the lower layer with an indication of the deactivation of PC5 unicast security protection and the deletion of the security context for the 5G ProSe direct link. Similarly, after receiving a direct communication security rejection message, UE2 performs the same actions as the relay UE. The following actions on the relay UE and UE2 are not yet clear. This scenario can be shown in Figure 15B If the relay UE is implemented based on 3GPP TS 33.503, since the relay UE can start timer T5080 when sending a direct communication request message to UE2, timer T5080 may expire, and thus the relay UE may re - send the direct communication request message to UE2, which may be unnecessary.

[0700] To avoid the above uncertainties, it may be better for UE2 to respond to the relay UE with a response message in response to the receipt of the direct communication security rejection message, so that the relay UE can stop timer T5080 (to avoid further re - transmission of the direct communication request message). This response message can be a direct communication rejection message. This response message can correspond to the direct communication request message sent from the relay UE to UE2. In response to receiving the direct communication rejection message from UE2, it also seems feasible for the relay UE to send a direct communication rejection message (corresponding to the direct communication request message sent from UE1 to the relay UE) to UE1, because network - assisted security establishment cannot be satisfied. This concept can be shown as Figure 16 Option 1 in Figure 16 shows an example of the step - by - step process of network - assisted unsuccessful PC5 security establishment for U2U relay communication based on relevant standards.

[0701] Alternatively, in terms of reducing signaling overhead, it is also feasible for the relay UE and UE2 to locally abort the second - hop direct link establishment procedure, because the direct communication security rejection message implies that network - assisted security establishment cannot be satisfied, and thus U2U relay communication cannot be established. In this way, it may not be necessary for UE2 to send a direct communication rejection message to the relay UE. This concept can be shown as Figure 16 Option 2 in

[0702] If Option 2 is followed, it should be noted that in 3GPP TS24.554, it is specified that the relay UE takes no action towards UE1. If this is the case, since UE1 can start timer T5080 when sending a direct communication request message to the relay UE, timer T5080 may expire, and thus UE1 may re - send the direct communication request message to the relay UE, which may be unnecessary. This scenario (or problem) can be in Figure 17 shown in

[0703] Thus, it may be better for the relay UE to send a direct communication rejection message (corresponding to the direct communication request message sent from UE1 to the relay UE) to UE1 in response to aborting the second-hop direct link establishment procedure (due to, for example, unfulfilled network-assisted security establishment). This can be done in Figure 18 shown in Figure 18 which shows an Figure 17 exemplary solution to the situation (or problem) shown in

[0704] The direct communication rejection message (sent from UE2 to the relay UE and / or from the relay UE to UE1) may include a cause value or information indicating that network-assisted security establishment cannot be satisfied (for the relay service code indicated in the direct communication request message).

[0705] Since network-assisted security establishment cannot be satisfied, in response to receiving the direct communication rejection message from the relay UE, UE1 may perform U2U relay reselection to find another relay UE for establishing U2U relay communication with UE2. U2U relay reselection may be a discovery procedure for finding one or more U2U relay UEs. If a new relay UE is found, the service flow may be re-initiated as shown in Figure 15A and Figure 16 and Figure 18 shown in

[0706] Figure 19 is a flow chart 1900 for a relay user equipment (UE). In step 1905, the relay UE receives a first direct communication request message from a source UE to establish user equipment-to-user equipment (U2U) relay communication with a destination UE. In step 1910, the relay UE sends a second direct communication request message to the destination UE in a direct link establishment procedure for establishing a direct link for U2U relay communication. In step 1915, the relay UE receives a direct communication security request message from the destination UE triggering the relay UE to execute a key request procedure with the network. In step 1920, if the key request procedure with the network fails, the relay UE sends a direct communication security rejection message to the destination UE. In step 1925, in response to the failure of the key request procedure, the relay UE aborts the direct link establishment procedure.

[0707] Returning to reference Figure 3 and 4 , in an exemplary instance from the perspective of the relay UE. The relay UE 300 includes program code 312 stored in the memory 310. The CPU 308 can execute the program code 312 to enable the relay UE to: (i) receive a first direct communication request message for establishing U2U relay communication with the target UE from the source UE; (ii) send a second direct communication request message to the target UE in a direct link establishment procedure for establishing a direct link for U2U relay communication; (iii) receive a direct communication security request message from the target UE that triggers the relay UE to execute a key request procedure with the network; (iv) if the key request procedure with the network fails, send a direct communication security rejection message to the target UE; and (v) abort the direct link establishment procedure in response to the failure of the key request procedure. In addition, the CPU 308 can execute the program code 312 to perform all of the actions and steps described above or other actions and steps described herein.

[0708] Figure 20 FIG. 2000 is a flowchart for a relay user equipment (UE). In step 2005, the relay UE receives a first direct communication request message for establishing UE-to-UE (U2U) relay communication with the target UE from the source UE. In step 2010, the relay UE sends a second direct communication request message to the target UE in a direct link establishment procedure for establishing a direct link for U2U relay communication. In step 2015, the relay UE receives a direct communication security request message from the target UE that triggers the relay UE to execute a key request procedure with the network. In step 2020, if the key request procedure with the network fails, the relay UE sends a direct communication security rejection message to the target UE. In step 2025, in response to sending the direct communication security rejection message, the relay UE aborts the direct link establishment procedure.

[0709] Return reference Figure 3 and 4 , in an exemplary instance from the perspective of the relay UE. The relay UE 300 includes program code 312 stored in a memory 310. A CPU 308 may execute the program code 312 to enable the relay UE to: (i) receive, from a source UE, a first direct communication request message for establishing U2U relay communication with a destination UE; (ii) send, in a direct link establishment procedure for establishing a direct link for U2U relay communication, a second direct communication request message to the destination UE; (iii) receive, from the destination UE, a direct communication security request message that triggers the relay UE to execute a key request procedure with the network; (iv) if the key request procedure with the network fails, send a direct communication security rejection message to the destination UE; and (v) in response to sending the direct communication security rejection message, abort the direct link establishment procedure. Additionally, the CPU 308 may execute the program code 312 to perform all of the actions and steps described above or other actions and steps described herein.

[0710] Figure 21 is a flowchart 2100 for a target user equipment (UE). In step 2105, the destination UE receives a second direct communication request message from the relay UE, where the second direct communication request message is sent in a direct link establishment procedure for establishing a direct link for user equipment to user equipment (U2U) relay communication. In step 2110, the destination UE sends a direct communication security request message to the relay UE that triggers the relay UE to execute a key request procedure with the network. In step 2115, the destination UE receives a direct communication security rejection message from the relay UE. In step 2120, in response to receiving the direct communication security rejection message, the destination UE aborts the direct link establishment procedure.

[0711] Return reference Figure 3 and 4 , in an exemplary instance from the perspective of the target UE. The target UE 300 includes program code 312 stored in a memory 310. A CPU 308 may execute the program code 312 to enable the target UE to: (i) receive a second direct communication request message from the relay UE, where the second direct communication request message is sent in a direct link establishment procedure for establishing a direct link for U2U relay communication; (ii) send a direct communication security request message to the relay UE that triggers the relay UE to execute a key request procedure with the network; (iii) receive a direct communication security rejection message from the relay UE; and (iv) in response to receiving the direct communication security rejection message, abort the direct link establishment procedure. Additionally, the CPU 308 may execute the program code 312 to perform all of the actions and steps described above or other actions and steps described herein.

[0712] In Figure 19 , 20 In the context of the embodiments shown in FIGS. 1 and 21, in one embodiment, in response to aborting the direct link establishment procedure, the relay UE may send a first direct communication rejection message to the source UE. In response to the failure of the key request procedure, the relay UE may send a first direct communication rejection message to the source UE.

[0713] In one embodiment, the first / second direct communication request message may include at least one of user information of the source UE, user information of the relay UE, user information of the target UE, and a relay service code. The direct communication security request message may include at least one of SUCI, UP-PRUK ID, and K NRP freshness parameter 1. The direct communication security rejection message may include a cause value or information indicating the failure of the key request procedure. The first direct communication rejection message may include a cause value or information indicating that network-assisted security establishment cannot be satisfied. The user information may be an upper layer ID or an application layer ID.

[0714] More specifically, in one embodiment, the network may include one or more network nodes including one of the following:

[0715] - gNB or base station;

[0716] - AMF;

[0717] - PKMF of the source UE;

[0718] - PKMF of the target UE; and / or

[0719] - PKMF of the relay UE.

[0720] More specifically, in one embodiment, the PKMF of the source UE and the PKMF of the relay UE may be the same. The PKMF of the target UE and the PKMF of the relay UE may be the same. The PKMF of the source UE and the PKMF of the target UE may be the same.

[0721] More specifically, in one embodiment, the direct link may be a layer 2 link, a unicast link, a PC5 link, a PC5 connection, a PC5-S connection, or a PC5-RRC connection. The ProSe remote user key request message may be a PROSE_PRUK_REQUEST message. The ProSe remote user key response message may be a PROSE_PRUK_RESPONSE message. The key request message may be a PROSE_KEY_REQUEST message. The key response message may be a PROSE_KEY_RESPONSE message.

[0722] Figure 22 It is a flowchart 2200 for relaying a user equipment (UE). In step 2205, the relay UE receives a first direct communication request message for establishing UE-to-UE (U2U) relay communication with a target UE from a source UE. In step 2210, the relay UE sends a second direct communication request message to the target UE in a direct link establishment procedure for establishing a direct link supporting U2U relay communication. In step 2215, the relay UE receives a direct communication security request message from the target UE triggering the relay UE to execute a key request procedure with the network. In step 2220, if the key request procedure with the network fails, the relay UE sends a direct communication security rejection message to the target UE. In step 2225, after sending the direct communication security rejection message, the relay UE aborts the direct link establishment procedure.

[0723] In Figure 22 In the context of the embodiment shown in, in one embodiment, after aborting the direct link establishment procedure, the relay UE may send a first direct communication rejection message to the source UE.

[0724] In one embodiment, the first direct communication rejection message may correspond to the first direct communication request message.

[0725] In one embodiment, the second direct communication request message may at least include a relay service code associated with a network-assisted security indicator, and the network-assisted security indicator indicates a security procedure that requires network assistance.

[0726] In one embodiment, the first / second direct communication request message may be a ProSe direct link establishment request message, the direct communication security request message may be a ProSe direct link security establishment request message, and / or the direct communication security rejection message may be a ProSe direct link security establishment rejection message. The first direct communication rejection message may be a ProSe direct link establishment rejection message.

[0727] Return reference Figure 3 and 4 , in an exemplary instance from the perspective of the relay UE. The relay UE 300 includes program code 312 stored in the memory 310. The CPU 308 can execute the program code 312 to enable the relay UE to: (i) receive, from a source UE, a first direct communication request message for establishing U2U relay communication with a target UE; (ii) send, in a direct link establishment procedure for establishing a direct link supporting U2U relay communication, a second direct communication request message to the target UE; (iii) receive, from the target UE, a direct communication security request message triggering the relay UE to execute a key request procedure with the network; (iv) if the key request procedure with the network fails, send a direct communication security rejection message to the target UE; and (v) abort the direct link establishment procedure after sending the direct communication security rejection message. In addition, the CPU 308 can execute the program code 312 to perform all of the actions and steps described above or other actions and steps described herein.

[0728] Various aspects of the present disclosure have been described above. It should be understood that the teachings herein can be embodied in a wide variety of forms, and any specific structure, function, or both disclosed herein are merely representative. Based on the teachings herein, those skilled in the art should understand that the aspects disclosed herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, using any number of the aspects set forth herein, a device can be implemented or a method can be practiced. Additionally, this device can be implemented or this method can be practiced using other structures, functions, or a combination of structures and functions in addition to or different from one or more of the aspects set forth herein. As examples of some of the above concepts, in some aspects, parallel channels can be established based on the pulse repetition frequency. In some aspects, parallel channels can be established based on the pulse position or offset. In some aspects, parallel channels can be established based on the time-hopping sequence. In some aspects, parallel channels can be established based on the pulse repetition frequency, pulse position or offset, and time-hopping sequence.

[0729] Those skilled in the art will understand that a variety of different arts and techniques can be used to represent information and signals. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the above description can be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, optical fields or optical particles, or any combination thereof.

[0730] Those skilled in the art will further appreciate that the various illustrative logical blocks, modules, processors, components, circuits, and algorithm steps described in connection with the aspects disclosed herein can be implemented as electronic hardware (e.g., digital implementations, analog implementations, or combinations of both, which can be designed using source coding or some other technique), various forms of program or design code with instructions (for convenience, which may be referred to herein as "software" or "software modules"), or combinations of both. To clearly illustrate this interchangeability of hardware and software, the various illustrative components, blocks, modules, circuits, and steps have been generally described above in terms of their functionality. Whether this functionality is implemented as hardware or software depends on the particular application and the design constraints imposed on the overall system. Those skilled in the art can implement the described functionality in different ways for each particular application, but such implementation decisions should not be construed as departing from the scope of the present disclosure.

[0731] In addition, the various illustrative logical blocks, modules, and circuits described in connection with the aspects disclosed herein can be implemented within or performed by an integrated circuit ("IC"), access terminal, or access point. The IC can include a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic, discrete hardware components, electrical components, optical components, mechanical components, or any combination thereof designed to perform the functions described herein, and can execute code or instructions residing within the IC, outside the IC, or in both cases. The general-purpose processor can be a microprocessor, but in the alternative, the processor can be any conventional processor, controller, microcontroller, or state machine. The processor can also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.

[0732] It should be understood that any particular order or hierarchy of steps in any disclosed process is an example of a sample method. It should be understood that, based on design preferences, the particular order or hierarchy of steps in a process can be rearranged while remaining within the scope of the present disclosure. The appended method claims present the elements of the various steps in a sample order and are not intended to be limited to the particular order or hierarchy presented.

[0733] The steps of a method or algorithm described in connection with the various aspects disclosed herein can be implemented directly in hardware, in a software module executed by a processor, or in a combination of the two. Software modules (e.g., including executable instructions and related data) and other data can reside in a data memory, such as a RAM memory, a flash memory, a ROM memory, an EPROM memory, an EEPROM memory, a register, a hard disk, a removable disk, a CD-ROM, or any other form of computer-readable storage medium known in the art. The exemplary storage medium can be coupled to a machine such as, for convenience, the machine may be referred to herein as a "processor", such that the processor can read information (e.g., code) from the storage medium and write information to the storage medium. The exemplary storage medium can be integral with the processor. The processor and the storage medium can reside in an ASIC. The ASIC can reside in a user device. In an alternative, the processor and the storage medium can reside as discrete components in the user device. Additionally, in some aspects, any suitable computer program product can include a computer-readable medium that includes code related to one or more aspects of the present disclosure. In some aspects, the computer program product can include packaging material.

[0734] Although the invention has been described in connection with various aspects, it is to be understood that the invention is capable of further modification. This application is intended to cover any variations, uses, or adaptations of the invention that generally follow the principles of the invention and include such departures from the present disclosure as come within the known and customary practice in the art to which the invention pertains. ​

Claims

1. A method for relaying user equipment, characterized in that: include: The relay user equipment receives a first direct communication request message from the source user equipment to establish relay communication between user equipments with the target user equipment; The relay user equipment sends a second direct communication request message to the target user equipment in a direct link establishment procedure for establishing a direct link supporting relay communication between the user equipments; The relay user equipment receives a direct communication security request message from the target end user equipment, triggering the relay user equipment to perform a key request procedure with the network; If the key request procedure with the network fails, the relay user equipment sends a direct communication security rejection message to the target user equipment; as well as After sending the direct communication security rejection message, the relay user equipment aborts the direct link establishment procedure.

2. The method according to claim 1, characterized in that Also includes: After terminating the direct link establishment procedure, the relay user equipment sends a first direct communication rejection message to the source user equipment.

3. The method according to claim 2, characterized in that The first direct communication rejection message corresponds to the first direct communication request message.

4. The method according to claim 2, characterized in that: The first direct communication rejection message is a proximity-based service direct link establishment rejection message.

5. The method according to claim 1, characterized in that The second direct communication request message includes at least a relay service code associated with a network-assisted security indicator, the network-assisted security indicator indicating that a network-assisted security procedure is required.

6. The method according to claim 1, characterized in that The first / second direct communication request message is a proximity based service direct link establishment request message, the direct communication security request message is a proximity based service direct link security establishment request message, and / or the direct communication security rejection message is a proximity based service direct link security establishment rejection message.

7. A relay user equipment, characterized in that: include: Control circuit; a processor installed in the control circuit; as well as a memory installed in the control circuit and operably coupled to the processor; wherein the processor is configured to execute program code stored in the memory to: Receiving, from a source user equipment, a first direct communication request message for establishing relay communication between user equipments with a target user equipment; Sending a second direct communication request message to the target user equipment in a direct link establishment procedure for establishing a direct link supporting relay communication between the user equipments; receiving, from the target user equipment, a direct communication security request message that triggers the relay user equipment to perform a key request procedure with the network; If the key request procedure with the network fails, sending a direct communication security rejection message to the target end user equipment; as well as After sending the direct communication security rejection message, the direct link establishment procedure is aborted.

8. The relay user equipment according to claim 7, characterized in that: The processor is further configured to execute program code stored in the memory to: After terminating the direct link establishment procedure, a first direct communication rejection message is sent to the source user equipment.

9. The relay user equipment according to claim 8, characterized in that: The first direct communication rejection message corresponds to the first direct communication request message.

10. The relay user equipment according to claim 8, characterized in that: The first direct communication rejection message is a proximity-based service direct link establishment rejection message.

11. The relay user equipment according to claim 7, characterized in that: The second direct communication request message includes at least a relay service code associated with a network-assisted security indicator, the network-assisted security indicator indicating that a network-assisted security procedure is required.

12. The relay user equipment according to claim 7, characterized in that: The first / second direct communication request message is a proximity based service direct link establishment request message, the direct communication security request message is a proximity based service direct link security establishment request message, and / or the direct communication security rejection message is a proximity based service direct link security establishment rejection message.

Citation Information

Patent Citations

  • Relay side link communication for secure link setup

    CN115413413A

  • Method and apparatus for relay user equipment to support connection with another remote user equipment

    CN116437495A

  • Method and apparatus for authenticating network access request through terminal-to-terminal connection in mobile communication system

    CN117121525A

  • Method and device for establishing security association and performing handoff authentication in communication system

    JP2009171543A