Method and apparatus for network assisted security establishment supporting inter-user equipment relay
By employing a network-assisted security establishment method, the security issues of relay communication between user equipment were resolved, ensuring the stability and security of the communication link and preventing link establishment failures.
Patent Information
- Application Number
- CN202411857441.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-26
- Filing Date
- 2024-12-17
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2044-12-17
AI Technical Summary
In wireless communication systems, existing technologies struggle to effectively address the security issues of relay communication between user equipment, especially in the absence of network assistance, leading to communication link establishment failures or insufficient security.
A network-assisted security establishment method is introduced, which ensures the security of the communication link by relaying the UE to receive and send direct communication request and security request messages, including sending a direct communication security rejection message and terminating link establishment when the key request procedure fails.
It improves the security and reliability of relay communication between user equipment, ensures the stability and security of communication links, and avoids link establishment failures caused by security issues.
Smart Images

Figure CN120224490B_ABST
Abstract
Description
[0001] Cross-references to related applications
[0002] This application claims the benefit of U.S. Provisional Patent Application No. 63 / 614,718, filed December 26, 2023, the entire disclosure of which is incorporated herein by reference in its entirety. Technical Field
[0003] This disclosure generally relates to wireless communication networks, and more specifically, to methods and apparatus for supporting network-assisted security establishment in inter-UE relay within wireless communication systems. Background Technology
[0004] With the rapid growth in demand for transmitting large amounts of data to and from mobile communication devices, traditional mobile voice communication networks have evolved into networks that communicate using Internet Protocol (IP) data packets. This IP data packet communication can provide users of mobile communication devices with IP-bearing voice, multimedia, multicast, and video-on-demand communication services.
[0005] An exemplary network architecture is the Evolved Universal Terrestrial Radio Access Network (E-UTRAN). E-UTRAN systems can provide high data throughput to enable the aforementioned IP-based voice and multimedia services. Currently, the 3GPP standards organization is discussing new next-generation (e.g., 5G) radio technologies. Therefore, changes to the current core of the 3GPP standards are currently being submitted and considered to facilitate their evolution and completion. Summary of the Invention
[0006] A method and apparatus for relaying user equipment (UE) are disclosed. In one embodiment, the relay UE receives a first direct communication request message from a source UE to establish UE-to-UE (U2U) relay communication with a target UE. The relay UE also sends a second direct communication request message to the target UE in a direct link establishment procedure for establishing a direct link supporting the U2U relay communication. The relay UE also receives a direct communication security request message from the target UE that triggers the relay UE to execute a key request procedure with the network. Furthermore, if the key request procedure with the network fails, the relay UE sends a direct communication security rejection message to the target UE. Additionally, after sending the direct communication security rejection message, the relay UE suspends the direct link establishment procedure. Attached Figure Description
[0007] Figure 1 The accompanying drawings illustrate a wireless communication system according to an exemplary embodiment.
[0008] Figure 2 This is a block diagram of a transmitter system (also referred to as an access network) and a receiver system (also referred to as a user equipment or UE) according to an exemplary embodiment.
[0009] Figure 3 This is a functional block diagram of a communication system according to an exemplary embodiment.
[0010] Figure 4 This is based on an exemplary embodiment. Figure 3 Functional block diagram of the program code.
[0011] Figure 5 It is 3GPP R2-2314074 Figure 16 .12.2.x-1, 3GPP TS23.304V18.4.0 Figure 6 Reproduction of .4.3.1-1.
[0012] Figure 6 It is 3GPP R2-2314074 Figure 16 .12.2.x-2, 3GPP TS23.304V18.4.0 Figure 6 Reproduction of .7.1.1-1.
[0013] Figure 7 It is 3GPP R2-2314074 Figure 16 .12.x-1, 3GPP TS24.554V18.2.0 Figure 7 Reproduction of .2.2.2.1.
[0014] Figure 8 It is 3GPP R2-2314014 Figure 5 8.9.1.1-1, 3GPP TS24.554V18.2.0 Figure 7 Reproduction of .2.2.2.2.
[0015] Figure 9 It is 3GPP R2-2314014 Figure 5 8.9.1.1-2, 3GPP TS24.554V18.2.0 Figure 7 Reproduction of .2.10.2.1.
[0016] Figure 10 It is 3GPP R2-2314014 Figure 5 8.9.8.1-1, 3GPP TS24.554V18.2.0Figure 8 .2.10.2.4.2.1.
[0017] Figure 11 is a reproduction of Figure 6 .3.3.2.2-1.
[0018] Figure 12 is a reproduction of Figure 6 .6.3.1-1.
[0019] Figure 13 is a reproduction of Figure 8 a.2.x.2.1.
[0020] Figure 14 shows an example of a step flow for network assisted successful PC5 security establishment for U2U relay communication based on the relevant standards according to one example embodiment.
[0021] Figure 15A shows an example of a step flow for network assisted unsuccessful PC5 security establishment for U2U relay communication based on the relevant standards according to one example embodiment.
[0022] Figure 15B shows an example of a step flow for network assisted unsuccessful PC5 security establishment for U2U relay communication based on the relevant standards according to one example embodiment.
[0023] Figure 16 shows an example of potential ways of proceeding following the subsequent actions of sending a direct communication security rejection according to one example embodiment.
[0024] Figure 17 shows an example of potential problems according to one example embodiment.
[0025] Figure 18 shows an example of possible solutions for resolving Figure 17 the problems shown according to one example embodiment.
[0026] Figure 19 is a flowchart according to one example embodiment.
[0027] Figure 20 is a flowchart according to one example embodiment.
[0028] Figure 21 is a flowchart according to one example embodiment.
[0029] Figure 22is a flow diagram in accordance with one example embodiment. DETAILED DESCRIPTION
[0030] The example wireless communication systems and devices described below employ a wireless communication system supporting broadcast services. Wireless communication systems are widely deployed to provide various types of communication such as voice, data, and so on. These systems can be based on code division multiple access (CDMA), time division multiple access (TDMA), orthogonal frequency division multiple access (OFDMA), 3GPP Long Term Evolution (LTE) wireless access, 3GPP High Speed Packet
[0031] In particular, the example wireless communication systems and devices described below can be designed to support one or more standards, such as the standard offered by an association named “3rd Generation Partnership Project” (3GPP herein) including: TS 23.304 V18.4.0, “Proximity based Services (ProSe) in 5G System (5GS); Release 18”; TS 24.554 V18.2.0, “Proximity-service (ProSe) in 5G System (5GS); Stage 3; Release 18”; TS 33.503 V18.0.0, “Security aspects of Proximity based Services (ProSe) in 5G System (5GS); Release 18”; and C1-238124, “5G ProSe Inter-UE Relay Direct Link Security Establishment Procedure”, Xiaomi. The above-listed standards and documents are expressly incorporated herein in their entirety by reference.
[0032] Figure 1 A multiple access wireless communication system according to one embodiment of the present application is illustrated. An access network 100 (AN) includes multiple antenna groups, one including 104 and 106, another including 108 and 110, and an additional group including 112 and 114. In Figure 1Each antenna group is designed to communicate with access terminals in a sector of the area covered by the access network 100. In an embodiment, the antenna groups are each designed to communicate with access terminals in a sector of the area covered by the access network 100.
[0033] Each antenna group and / or the antenna groups are often referred to as a sector of the access network in the area in which they communicate. In an embodiment, the antenna groups are each designed to communicate with access terminals in a sector of the area covered by the access network 100.
[0034] In communication through the forward links 120 and 126, the transmitting antennas of the access network 100 can utilize beamforming to improve the signal-to-noise ratio of the forward links for the different access terminals 116 and 122. Additionally, a base station using beamforming to transmit to access terminals scattered randomly through its coverage area will result in a lower overall interference level as compared to a base station transmitting to all its access terminals using a single antenna.
[0035] An access network (AN) can be a fixed station or base station used in communication with terminals and can also be referred to as an access point, a Node B, a base station, an enhanced base station, an evolved Node B (eNB), a network node, a network, or some other terminology. An access terminal (AT) can also be called a user equipment (UE), a wireless communication device, terminal, access terminal or some other terminology.
[0036] Figure 2 is a simplified block diagram of an embodiment of a transmitter system 210 (also referred to as an access network) and a receiver system 250 (also referred to as an access terminal (AT) or user equipment (UE)) in a MIMO system 200. At the transmitter system 210, traffic data for a number of data streams is provided from a data source 212 to a transmit (TX) data processor 214.
[0037] In one embodiment, each data stream is transmitted through a respective transmit antenna. TX data processor 214 formats, codes and interleaves traffic data for each data stream based on a particular coding scheme selected for that data stream to provide coded data.
[0038] The coded data for each data stream can be multiplexed with pilot data using OFDM techniques. The pilot data is typically a known data pattern that is processed in a known manner and can be used at the receiver system to estimate the channel response. The multiplexed pilot and coded data for each data stream is then modulated (i.e., symbol mapped) based on a particular modulation scheme (e.g., BPSK, QSPK, M-PSK, or M-QAM) selected for that data stream to provide modulation symbols. The data rate, coding, and modulation for each data stream can be determined by instructions executed by processor 230.
[0039] The modulation symbols for all data streams are then provided to a TX MIMO processor 220, which can further process the modulation symbols (e.g., for OFDM). TX MIMO processor 220 then provides N T modulation symbol streams to N T transmitters (TMTR) 222a through 222t. In certain embodiments, TX MIMO processor 220 applies beamforming weights to the symbols of the data streams and to the antenna from which the symbols are being transmitted.
[0040] Each transmitter 222 receives and processes a respective symbol stream to provide one or more analog signals, and further conditions (e.g., amplifies, filters, and upconverts) the analog signals to provide a modulated signal suitable for transmission over the MIMO channel. N T modulated signals from transmitters 222a through 222t are transmitted from N T antennas 224a through 224t, respectively.
[0041] At receiver system 250, the transmitted modulated signals are received by N R antennas 252a through 252r and the received signal from each antenna 252 is provided to a respective receiver (RCVR) 254a through 254r. Each receiver 254 conditions (e.g., filters, amplifies, and downconverts) a respective received signal, digitizes the conditioned signal to provide samples, and further processes the samples to provide a corresponding "received" symbol stream.
[0042] The received symbol streams are then processed by a RX data processor 260 to provide N REach receiver 254 receives N R N symbol streams and process them based on specific receiver processing techniques. R Each received symbol stream provides N T Each detected symbol stream is then demodulated, deinterleaved, and decoded by the RX data processor 260 to recover the service data used for the data stream. The processing performed by the RX data processor 260 is complementary to the processing performed by the TX MIMO processor 220 and TX data processor 214 at the transmitter system 210.
[0043] Processor 270 periodically determines which pre-decoding matrix to use (discussed below). Processor 270 formulates a reverse link message including the matrix index part and the rank part.
[0044] The reverse link message may include various types of information about the communication link and / or the received data stream. The reverse link message is then processed by the TX data processor 238 (which also receives service data for several data streams from the data source 236), modulated by the modulator 280, regulated by the transmitters 254a to 254r, and transmitted back to the transmitter system 210.
[0045] At transmitter system 210, the modulated signal from receiver system 250 is received by antenna 224, conditioned by receiver 222, demodulated by demodulator 240, and processed by RX data processor 242 to extract the reverse link message transmitted by receiver system 250. Next, processor 230 determines which pre-decoding matrix to use to determine beamforming weights and then processes the extracted message.
[0046] See also Figure 3 This figure illustrates an alternative simplified functional block diagram of a communication device according to an embodiment of the present invention. Figure 3 As shown, this can be achieved using the communication device 300 in a wireless communication system. Figure 1 UE (or AT) 116 and 122 or Figure 1The communication device 300 is a base station (or AN) 100, and the wireless communication system is preferably an NR system. The communication device 300 may include an input device 302, an output device 304, a control circuit 306, a central processing unit (CPU) 308, a memory 310, program code 312, and a transceiver 314. The control circuit 306 executes the program code 312 in the memory 310 via the CPU 308, thereby controlling the operation of the communication device 300. The communication device 300 can receive signals input by a user via the input device 302 (e.g., a keyboard or keypad) and can output images and sounds via the output device 304 (e.g., a monitor or speaker). The transceiver 314 is used to receive and transmit wireless signals, pass the received signals to the control circuit 306, and wirelessly output signals generated by the control circuit 306. The communication device 300 in a wireless communication system can also be used for this purpose. Figure 1 AN 100 in the middle.
[0047] Figure 4 This is according to an embodiment of the present invention. Figure 3 The diagram shows a simplified block diagram of program code 312. In this embodiment, program code 312 includes an application layer 400, a layer 3 portion 402, and a layer 2 portion 404, and is coupled to a layer 1 portion 406. Layer 3 portion 402 typically performs radio resource control. Layer 2 portion 404 typically performs link control. Layer 1 portion 406 typically performs physical connections.
[0048] 3GPP 23.304 describes some procedures related to unicast link communication, as follows:
[0049] 6.4.3.1 Establishing a Layer 2 Link via the PC5 Reference Point
[0050] In order to perform unicast mode ProSe direct communication via the PC5 reference point, the UE is configured with the relevant information as described in Section 5.1.3.
[0051] Figure 6 4.3.1-1 shows the Layer 2 link establishment procedure for direct ProSe communication in unicast mode via the PC5 reference point.
[0052] The 3GPP TS23.304V18.4.0 specification is titled "Layer 2 Link Establishment Procedure". Figure 6 4.3.1-1 reproduced as Figure 5 ]
[0053] 1. The UE determines the destination layer 2 ID for signaling reception used for PC5 unicast link establishment, as specified in Section 5.8.2.4.
[0054] 2. The ProSe application layer in UE-1 provides application information for PC5 unicast communication. This application information includes ProSe service information and the UE's application layer ID. The application information may also include the target UE's application layer ID.
[0055] The ProSe application layer in UE-1 provides the ProSe application requirements for this unicast communication. UE-1 determines the PC5 QoS parameters and PFI as specified in Section 5.6.1.
[0056] If UE-1 decides to reuse an existing PC5 unicast link as specified in Section 5.3.4, the UE triggers a Layer 2 link modification procedure as specified in Section 6.4.3.4.
[0057] 3. UE-1 sends a Direct Communication Request message to initiate a unicast Layer 2 link establishment procedure. The Direct Communication Request message includes:
[0058] - Source user information: Application layer ID of the initiating UE (i.e., application layer ID of UE-1).
[0059] - If the ProSe application layer provides the target UE's application layer ID in step 2, then the following information is included:
[0060] - Target user information: Application layer ID of the target UE (i.e., application layer ID of UE-2).
[0061] -ProSe service information: Information about the ProSe identifier used to establish the request layer 2 link.
[0062] - Security information: Information used to establish security.
[0063] Note 1: Security information and necessary protection of source user information and target user information are defined in TS 33.503
[29] .
[0064] Determine the source tier 2 ID and destination tier 2 ID used to send the direct communication request message, as specified in Sections 5.8.2.1 and 5.8.2.4. The destination tier 2 ID can be a broadcast or unicast tier 2 ID. When using a unicast tier 2 ID, the target user information will be included in the direct communication request message.
[0065] UE-1 uses the source layer 2 ID and destination layer 2 ID to send a direct communication request message via PC5 broadcast or unicast.
[0066] The default PC5 DRX configuration can be used to send and receive this message (see TS 38.300
[12] ).
[0067] 4. Establish security with UE-1 as follows:
[0068] 4a. If the target user information is included in the Direct Communication Request message, the target UE (i.e. UE-2) responds by establishing security with UE-1.
[0069] 4b. If the target user information is not included in the Direct Communication Request message, the interested UE using the notified ProSe service over the PC5 unicast link with UE-1 responds by establishing security with UE-1.
[0070] NOTE 2: The signaling for the security procedures is defined in TS 33.503
[29] .
[0071] When security protection is enabled, UE-1 sends the following information to the target UE:
[0072] - If IP communication is used:
[0073] - IP address configuration: For IP communication, this link requires IP address configuration and the IP address configuration indicates one of the following values:
[0074] - "DHCPv4 server", if only IPv4 address allocation mechanism is supported by the initiating UE, i.e. acting as a DHCPv4 server; or
[0075] - "IPv6 router", if only IPv6 address allocation mechanism is supported by the initiating UE, i.e. acting as an IPv6 router; or
[0076] - "DHCPv4 server and IPv6 router", if both IPv4 and IPv6 address allocation mechanisms are supported by the initiating UE; or
[0077] - "No address allocation supported", if neither IPv4 nor IPv6 address allocation mechanism is supported by the initiating UE.
[0078] - Link-local IPv6 address: If the UE-1 does not support IPv6 IP address allocation mechanism, i.e. the IP address configuration indicates "No address allocation supported", a link-local IPv6 address is formed locally based on RFC 4862
[17] .
[0079] - QoS information: Information about the PC5 QoS flows. For each PC5 QoS flow, the PFI and the corresponding PC5 QoS parameters (i.e. PQI and conditionally other parameters such as MFBR / GFBR) and optionally the associated ProSe identifier.
[0080] - Optional PC5 QoS rules.
[0081] The source Layer-2 ID for the security establishment procedure is determined as specified in sections 5.8.2.1 and 5.8.2.4. The destination Layer-2 ID is set to the source Layer-2 ID of the received Direct Communication Request message.
[0082] Upon reception of the security establishment procedure message, UE-1 obtains the peer's Layer-2 ID for signaling and data traffic for this unicast link for future communication.
[0083] 5. The target UE that has successfully established security with UE-1 sends a Direct Communication Accept message to UE-1:
[0084] 5a. (UE-oriented Layer-2 link establishment) If target user information is included in the Direct Communication Request message, the target UE (i.e., UE-2) responds with a Direct Communication Accept message in case the application layer ID for UE-2 matches.
[0085] 5b. (ProSe service-oriented Layer-2 link establishment) If target user information is not included in the Direct Communication Request message, the UE (UE-2 and UE-4 in 4.3.1-1) that is interested in using the notified ProSe service responds to the request by sending a Direct Communication Accept message. Figure 6
[0086] The Direct Communication Accept message contains:
[0087] - Source user information: the application layer ID of the UE sending the Direct Communication Accept message.
[0088] - QoS information: information about the PC5 QoS flows. For each PC5 QoS flow, the PFI and the corresponding PC5 QoS parameters (i.e., PQI and conditionally other parameters such as MFBR / GFBR) requested by UE-1 and optionally the associated ProSe identifier.
[0089] - Optional PC5 QoS rules.
[0090] - If IP communication is used:
[0091] - IP address configuration: for IP communication, this link requires IP address configuration, and the IP address configuration indicates one of the following values:
[0092] - "DHCPv4 server", if only IPv4 address allocation mechanism is supported by the target UE, i.e., acting as a DHCPv4 server; or
[0093] - "IPv6 router", if only IPv6 address allocation mechanism is supported by the target UE, i.e., acting as an IPv6 router; or
[0094] - "DHCPv4 server with IPv6 router", provided that both IPv4 and IPv6 address allocation mechanisms are supported by the target UE; or
[0095] - "No address allocation", provided that neither IPv4 nor IPv6 address allocation mechanisms are supported by the target UE.
[0096] - Link-local IPv6 address: If the target UE does not support IPv6 IP address allocation mechanism, i.e. IP address configuration indicates "No address allocation" and the UE-1 contains a link-local IPv6 address from the security establishment in step 4, the link-local IPv6 address is formed locally based on RFC 4862
[17] . The target UE will contain a non-conflicting link-local IPv6 address.
[0097] If both UEs (i.e. the initiating UE and the target UE) are selected to use a link-local IPv6 address, both UEs will disable the Duplicate Address Detection as defined in RFC 4862
[17] .
[0098] NOTE 3: When the initiating UE or the target UE indicates support for IPv6 routing, the corresponding address configuration procedure will be performed after the establishment of the layer 2 link and the link-local IPv6 address is ignored.
[0099] The ProSe layer of the UE establishing the PC5 unicast link will pass down the PC5 link identifier for the unicast link and the PC5 unicast link related information to the AS layer. The PC5 unicast link related information contains the layer 2 ID information (i.e. source layer 2 ID and destination layer 2 ID). This enables the AS layer to maintain the PC5 link identifier as well as the PC5 unicast link related information.
[0100] Both UEs can negotiate the PC5 DRX configuration in the AS layer and the PC5 DRX parameter values can be configured per pair of source and destination layer 2 IDs in the AS layer.
[0101] 6. The ProSe data is transferred over the established unicast link as follows:
[0102] The PC5 link identifier and the PFI are provided to the AS layer together with the ProSe data.
[0103] Additionally, the layer 2 ID information (i.e. source layer 2 ID and destination layer 2 ID) is optionally provided to the AS layer.
[0104] NOTE 4: The layer 2 ID information is provided to the AS layer by the UE implementation.
[0105] The UE-1 sends the ProSe data using the source Layer-2 ID (i.e., the Layer-2 ID of the UE-1 for this unicast link) and the destination Layer-2 ID (i.e., the Layer-2 ID of the peer UE for this unicast link).
[0106] NOTE 5: The PC5 unicast link is bidirectional, so the peer UE of the UE-1 can send ProSe data to the UE-1 through the unicast link with the UE-1.
[0107] […]
[0108] 6.7.1 5G ProSe Communication via 5G ProSe Layer-3 Inter-UE Relay
[0109] 6.7.1.1 Layer-2 Link Establishment for PC5 Communication via 5G ProSe Layer-3 Inter-UE Relay
[0110] Figure 6 .7.1.1-1 shows the procedure for Layer-2 link establishment via 5G ProSe Layer-3 Inter-UE Relay.
[0111] [3GPP TS 23.304 V18.4.0, Name: "Layer-2 Link Establishment via 5G ProSe Layer-3 Inter-UE Relay" Figure 6 .7.1.1-1 is reproduced as Figure 6 ]
[0112] 1. The source 5G ProSe Layer-3 end-UE, the target 5G ProSe Layer-3 end-UE and the 5G ProSe Layer-3 Inter-UE Relay perform service authorization and provisioning as described in clause 6.2.
[0113] 2. The source 5G ProSe Layer-3 end-UE performs discovery of 5G ProSe Layer-3 Inter-UE Relay as described in clause 6.3.2.4.
[0114] 3. The source 5G ProSe Layer-3 end-UE sends a Direct Communication Request message to initiate the unicast Layer-2 link establishment procedure with 5G ProSe Layer-3 Inter-UE Relay. The parameters contained in the Direct Communication Request message are described in clause 6.4.3.7.
[0115] The source Layer-2 ID of the Direct Communication Request message is assigned by the source 5G ProSe Layer-3 end-UE itself and the destination Layer-2 ID is set to the source Layer-2 ID of the discovery message of the 5G ProSe Layer-3 Inter-UE Relay.
[0116] The source 5G ProSe Layer-3 end-UE obtains the application information and optional ProSe application requirements from the ProSe application layer and determines the end-to-end QoS parameters as described in clause 5.6.3.1.
[0117] 4. If the 5G ProSe Layer-3 Inter-UE Relay's User Info ID in the Direct Communication Request message matches the 5G ProSe Inter-UE Relay's User Info ID and the RSC in the Direct Communication Request matches one of the RSCs (pre-)configured with the relay, as specified in clause 5.1.5.1, the 5G ProSe Layer-3 Inter-UE Relay responds by establishing security with the source 5G ProSe Layer-3 End-UE. When security protection is enabled, the source 5G ProSe Layer-3 End-UE sends the parameters as described in clause 6.4.3.7 to the 5G ProSe Layer-3 Inter-UE Relay.
[0118] If the source 5G ProSe Layer-3 End-UE's Ethernet MAC address has already been used by another 5G ProSe Layer-3 End-UE, the 5G ProSe Layer-3 Inter-UE Relay rejects the direct link establishment, indicating that the MAC address is not unique.
[0119] The source Layer-2 ID for the security establishment procedure is assigned by the 5G ProSe Layer-3 Inter-UE Relay itself and the destination Layer-2 ID is set to the source Layer-2 ID of the received Direct Communication Request message.
[0120] The 5G ProSe Layer-3 Inter-UE Relay selects different source Layer-2 IDs for different types of traffic (i.e., IP traffic, Ethernet traffic, and unstructured traffic) for a PC5 link.
[0121] If the PC5 link is used to deliver unstructured traffic, the 5G ProSe Layer-3 Inter-UE Relay selects different source Layer-2 IDs for different pairs of source and target 5G ProSe Layer-3 End-UEs.
[0122] Upon receiving the security establishment procedure message, the source 5G ProSe Layer-3 End-UE obtains the Layer-2 ID of the 5G ProSe Layer-3 Inter-UE Relay for signaling and data traffic for this unicast link for future communication.
[0123] 5. After the security establishment procedure in step 4 is completed, the 5G ProSe Layer-3 Inter-UE Relay sends a Direct Communication Request message to initiate a unicast Layer-2 link establishment procedure with the target 5G ProSe Layer-3 End-UE. The parameters included in the Direct Communication Request message are described in clause 6.4.3.7.
[0124] The source Layer-2 ID of the Direct Communication Request message is assigned by the 5G ProSe Layer-3 Inter-UE Relay itself and the destination Layer-2 ID is the unicast Layer-2 ID of the target 5G ProSe Layer-3 End-UE associated with the User Info ID of the target 5G ProSe Layer-3 End-UE.
[0125] 5G ProSe Layer-3 inter-UE relay will select different source Layer-2 IDs for different types of traffic (i.e., IP traffic, Ethernet traffic, and unstructured traffic) for the PC5 link.
[0126] If the PC5 link is used to deliver unstructured traffic, the 5G ProSe Layer-3 inter-UE relay will select different source Layer-2 IDs for different pairs of source and target 5G ProSe Layer-3 end-UEs.
[0127] 6. If the user information ID and RSC of the target 5G ProSe Layer-3 end-UE contained in the direct communication request message match the user information ID and (pre-)configured RSC of the target UE as specified in section 5.1.5.1, the target 5G ProSe Layer-3 end-UE responds by establishing security with the 5G ProSe Layer-3 inter-UE relay. When security protection is enabled, the 5G ProSe Layer-3 inter-UE relay sends the parameters as described in section 6.4.3.7 to the target 5G ProSe Layer-3 end-UE.
[0128] The source Layer-2 ID for the security establishment procedure is assigned by the target 5G ProSe Layer-3 end-UE itself, and the destination Layer-2 ID is set to the source Layer-2 ID of the received direct communication request message.
[0129] Upon reception of the security establishment procedure message, the 5G ProSe Layer-3 inter-UE relay obtains the Layer-2 ID of the target 5G ProSe Layer-3 end-UE for signaling and data traffic for this unicast link for future communication.
[0130] 7. The target 5G ProSe Layer-3 end-UE sends a direct communication accept message to the 5G ProSe Layer-3 inter-UE relay with which security has been successfully established. The parameters contained in the direct communication accept message are described in section 6.4.3.7.
[0131] NOTE: The 5G ProSe Layer-3 inter-UE relay, upon reception of the direct communication accept message, can detect that the Ethernet MAC address of the target 5G ProSe Layer-3 end-UE is already used by another 5G ProSe Layer-3 end-UE.
[0132] 8. For IP traffic, an IPv6 prefix or IPv4 address is allocated for the target 5G ProSe Layer-3 end-UE as defined in section 5.5.1.4.
[0133] 9. After receiving the Direct Communication Accept message from the target 5G ProSe Layer 3 end UE, the 5G ProSe Layer 3 inter-UE relay sends a Direct Communication Accept message to the source 5G ProSe Layer 3 end UE with which it has successfully established security. The parameters contained in the Direct Communication Accept message are described in section 6.4.3.7.
[0134] 10. For IP traffic, an IPv6 prefix or IPv4 address is allocated for the source 5G ProSe Layer 3 end UE as defined in section 5.5.1.4.
[0135] 11. For IP communication, the 5G ProSe Layer 3 inter-UE relay can store the association of the user information ID with the IP address of the target 5G ProSe Layer 3 end UE into its DNS entry, and the 5G ProSe Layer 3 inter-UE relay can act as a DNS server for other UEs. If the IP address of the target 5G ProSe Layer 3 end UE is not received in step 9, the source 5G ProSe Layer 3 end UE can send a DNS query to the 5G ProSe Layer 3 inter-UE relay after step 10 to request the IP address of the target 5G ProSe Layer 3 end UE, and the 5G ProSe Layer 3 inter-UE relay returns the IP address of the target 5G ProSe Layer 3 end UE to the source 5G ProSe Layer 3 end UE.
[0136] For Ethernet communication, the 5G ProSe Layer 3 inter-UE relay maintains the association between the PC5 link and the Ethernet MAC address received from the 5G ProSe Layer 3 end UE.
[0137] For unstructured traffic communication, for each pair of source and target 5G ProSe Layer 3 end UEs, the 5G ProSe Layer 3 inter-UE relay maintains a 1:1 mapping between the PC5 link and the source 5G ProSe Layer 3 end UE and the PC5 link and the target 5G ProSe Layer 3 end UE.
[0138] 12. The source 5G ProSe Layer 3 end UE communicates with the target 5G ProSe Layer 3 end UE via the 5G ProSe Layer 3 inter-UE relay.
[0139] In case of one source 5G ProSe Layer-3 endpoint UE communicating with multiple target 5G ProSe Layer-3 endpoint UEs, the PC5 link between the source 5G ProSe Layer-3 endpoint UE and the 5G ProSe Layer-3 inter-UE relay can be shared among the multiple target 5G ProSe Layer-3 endpoint UEs according to the RSC, while the PC5 link can be established individually between the 5G ProSe Layer-3 inter-UE relay and the target 5G ProSe Layer-3 endpoint UEs according to the RSC. For the shared PC5 link, the Layer-2 link modification procedure shall be used. The parameters used in the Layer-2 link modification procedure are described in section 6.4.3.7.
[0140] In case of one source 5G ProSe Layer-3 endpoint UE communicating with multiple target 5G ProSe Layer-3 endpoint UEs, the PC5 link between the source 5G ProSe Layer-3 endpoint UE and the 5G ProSe Layer-3 inter-UE relay can be shared among the multiple target 5G ProSe Layer-3 endpoint UEs according to the RSC, while the PC5 link can be established individually between the 5G ProSe Layer-3 inter-UE relay and the target 5G ProSe Layer-3 endpoint UEs according to the RSC. For the shared PC5 link, the Layer-2 link modification procedure shall be used. The parameters used in the Layer-2 link modification procedure are described in section 6.4.3.7.
[0141] 3GPP 24.554 introduces some procedures related to unicast link communication as follows:
[0142] 7.2.2 5G ProSe Direct Link Establishment Procedure
[0143] 7.2.2.1 Overview
[0144] Depending on the type of the 5G ProSe Direct Link Establishment procedure (i.e. UE-oriented Layer-2 link establishment or ProSe Service-oriented Layer-2 link establishment in 3GPP TS 23.304 [2]), the 5G ProSe Direct Link Establishment procedure is used to establish a 5G ProSe Direct Link between two UEs or multiple 5G ProSe Direct Links between a UE and multiple target UEs. The UE sending the request message is referred to as the "initiating UE" and the other UE is referred to as the "target UE". If the request message does not indicate a specific target UE (i.e. no target user information is included in the request message) and multiple target UEs are interested in the ProSe Application indicated in the request message, the initiating UE shall handle the corresponding response messages received from those target UEs. The maximum number of 5G ProSe Direct Links established in a UE at a time shall not exceed the implementation-specific maximum number of established 5G ProSe Direct Links.
[0145] NOTE 1: The recommended maximum number of established 5G ProSe Direct Links is 8.
[0146] When the 5G ProSe Direct Link Setup procedure for a 5G ProSe Layer 3 Remote UE is successfully completed, and if there is a PDU session established for relaying traffic of a 5G ProSe Layer 3 Remote UE, the 5G ProSe Layer 3 UE-to-Network Relay UE shall perform the Remote UE Reporting procedure as specified in 3GPP TS 24.501
[11] .
[0147] NOTE 2: A single PC5 unicast link is established between the 5G ProSe Layer 2 UE-to-Network Relay UE and the 5G ProSe Layer 2 Remote UE for supporting the PDU session of the 5G ProSe Layer 2 Remote UE as specified in 3GPP TS 38.300
[21] .
[0148] 7.2.2.2 Initiation of the 5G ProSe Direct Link Setup procedure by the Initiating UE
[0149] The following preconditions shall be met by the Initiating UE before initiating this procedure:
[0150] a) The UE receives a request from upper layers to transfer data packets for a ProSe application over PC5, receives a request from lower layers, or receives a ProSe Direct Link Setup Request message or a ProSe Direct Link Modification Request message in case of 5G ProSe Inter-UE Relay to trigger the ProSe Direct Link Setup;
[0151] b) The communication mode is unicast mode (e.g., pre-configured as specified in clause 5.2.4 or indicated by upper layers);
[0152] c) The link layer identifier for the Initiating UE (i.e., Layer 2 ID for unicast communication) is available (e.g., pre-configured or self-assigned) and not used by other existing 5G ProSe Direct Links within the Initiating UE;
[0153] d) The link layer identifier for the Destination UE (i.e., unicast Layer 2 ID of the Target UE or broadcast Layer 2 ID) is available to the Initiating UE (e.g., pre-configured, obtained as specified in clause 5.2, known via previous ProSe Direct Communication, or indicated by lower layers);
[0154] NOTE 1: In case different ProSe applications are mapped to distinct pre-configured Destination Layer 2 IDs, when the Initiating UE wishes to establish a single unicast link available for more than one ProSe identifier, the UE can select any one of the pre-configured Destination Layer 2 IDs for unicast initial signaling.
[0155] e) the UE is authorized for 5G ProSe Direct Communication over PC5 in NR-PC5 in the serving PLMN, has a valid authorization for 5G ProSe Direct Communication over PC5 in NR-PC5 when not served by NG-RAN, is authorized to use 5G ProSe UE-to-Network Relay UE, is authorized to use 5G ProSe Inter-UE Relay UE or is authorized to act as 5G ProSe Inter-UE Relay UE. The UE considers itself not served by NG-RAN if the following conditions are met:
[0156] 1) not served by NG-RAN for ProSe Direct Communication over PC5;
[0157] 2) in a restricted service state as specified in 3GPP TS 23.122
[14] , provided that the reason the UE is in a restricted service state is one of the following;
[0158] i) the UE cannot find a suitable cell in a selected PLMN as specified in 3GPP TS 38.304
[15] ;
[0159] ii) the UE receives a registration reject message or service reject message with 5GMM cause #11 "PLMN not allowed" as specified in 3GPP TS 24.501
[11] ; or
[0160] iii) the UE receives a registration reject message or service reject message with 5GMM cause #7 "5GS service not allowed" as specified in 3GPP TS 24.501
[11] ; or
[0161] 3) in a restricted service state as specified in 3GPP TS 23.122
[14] for reasons other than i), ii) or iii) above and located in a geographical area where the UE is provisioned with a "non-operator managed" radio parameter as specified in clause 5.2;
[0162] Editor's note: The UE behavior in a restricted service state for the case of a 5G ProSe Direct Link Setup procedure for direct communication between a 5G ProSe End UE and a 5G ProSe Inter-UE Relay UE needs to be re-discussed, which will be determined by SA2.
[0163] f) there is no existing 5G ProSe Direct Link for the pair of peer application layer IDs or there is an existing 5G ProSe Direct Link for the pair of peer application layer IDs and:
[0164] 1) the network layer protocol of the existing 5G ProSe Direct Link is not the same as the network layer protocol required by the upper layer in the initiating UE for this ProSe application;
[0165] 2) the security policy (signaling security policy or user plane security policy) corresponding to the ProSe identifier is not compatible with the security policy of the existing 5G ProSe direct link; or
[0166] 3) in case the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe layer 3 remote UE and a 5G ProSe layer 3 UE-to- network relay UE, the existing 5G ProSe direct link for the peer UE is established with a different RSC, or is established but not used for direct communication between a 5G ProSe layer 3 remote UE and a 5G ProSe layer 3 UE-to-network relay UE;
[0167] 4) in case the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe layer 2 remote UE and a 5G ProSe layer 2 UE-to- network relay UE, the existing 5G ProSe direct link for the peer UE is established but not used for direct communication between a 5G ProSe layer 2 remote UE and a 5G ProSe layer 2 UE-to-network relay UE;
[0168] 5) in case the 5G ProSe direct link establishment procedure is used for direct communication between a source 5G ProSe layer 3 end UE and a 5G ProSe layer 3 inter-UE relay UE, the initiating UE acts as the source 5G ProSe end UE, the existing 5G ProSe direct link for the peer UE is established with a different RSC, or is established but not used for direct communication between a source 5G ProSe layer 3 end UE and a 5G ProSe layer 3 inter-UE relay UE;
[0169] 6) in case the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe inter-UE relay UE and a target 5G ProSe end UE without integration of discovery, the initiating UE acts as the 5G ProSe inter-UE relay UE, the 5G ProSe direct link security mode control procedure between the source 5G ProSe end UE and the initiating UE has been successfully completed, and no 5G ProSe direct link is established between the initiating UE and the target 5G ProSe end UE, wherein the RSC is received in the ProSe direct link establishment request message for 5G ProSe inter-UE relay;
[0170] 7) In case the 5G ProSe Direct Link Setup procedure is used for direct communication between a 5G ProSe Layer-3 inter-UE relay UE and a target 5G ProSe Layer-3 end-UE, the initiating UE acting as a 5G ProSe Layer-3 inter-UE relay UE receives the ProSe Direct Link Setup Request message containing the relay indication and no 5G ProSe Direct Link is established between the initiating UE and the target 5G ProSe end-UE, where the RSC is received in the ProSe Direct Link Setup Request message for 5G ProSe inter-UE relay; or
[0171] 8) In case the 5G ProSe Direct Link Setup procedure is used for direct communication between a 5G ProSe Layer-3 inter-UE relay UE and a target 5G ProSe Layer-3 end-UE, the initiating UE acting as a 5G ProSe Layer-3 inter-UE relay UE receives the ProSe Direct Link Modification Request message establishing 5G ProSe inter-UE relay communication with an additional 5G ProSe Layer-3 end-UE as specified in section 7.2.3.2 and no 5G ProSe Direct Link is established between the initiating UE and the additional target 5G ProSe end-UE, where the RSC is received in the ProSe Direct Link Modification Request message for 5G ProSe inter-UE relay;
[0172] g) the number of established 5G ProSe Direct Links is less than the implementation- specific maximum number of established 5G ProSe Direct Links allowed at a time in the UE;
[0173] h) the timer T5088 is not associated with the link layer identifier of the destination UE or the timer T5088 associated with the link layer identifier of the destination UE has expired or stopped.
[0174] After receiving service data or a request from upper layers, the initiating UE shall derive the PC5 QoS parameters and assign a PQFI for the PC5 QoS flow established as specified in section 7.2.7.
[0175] If the 5G ProSe Direct Link Setup procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-Network relay UE, the UE applies the DUCK or DUSK for UE-to-Network relay discovery together with a UTC-based counter to the encryption:
[0176] a) the relay service code; and
[0177] b) the UP-PRUK ID or CP-PRUK ID if available,
[0178] As specified in section 6.3.5.2 of 3GPP TS 33.503
[34] and the UE shall use the security protected Relay Service Code and the security protected UP-PRUK ID or the security protected CP-PRUK ID to create the ProSe Direct Link Setup Request message.
[0179] NOTE 2: If the UE is neither configured with DUCK nor with DUSK, the Relay Service Code and the UP-PRUK ID or CP-PRUK ID are not encrypted.
[0180] To initiate the 5G ProSe Direct Link Setup procedure, the initiating UE shall create the ProSe Direct Link Setup Request message. The initiating UE:
[0181] a) shall include the Source User Information set to the Application Layer ID of the initiating UE received from upper layers or to the User Information ID of the source 5G ProSe End UE in case the 5G ProSe Direct Link Setup procedure is used for 5G ProSe direct communication between a 5G ProSe Remote UE and a 5G ProSe Inter-UE Relay UE;
[0182] b) shall include the ProSe Identifier received from upper layers if the 5G ProSe Direct Link Setup procedure is not used for 5G ProSe direct communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE;
[0183] c) shall include the Target User Information set to the Application Layer ID of the target UE in case received from upper layers or known based on the unicast Layer-2 ID (i.e. Destination Layer-2 ID) of the target UE as described in section 5.8.2.4 of 3GPP TS 23.304 [3], set to the User Information ID of the 5G ProSe UE-to-Network Relay UE obtained during the 5G ProSe UE-to-Network Relay discovery procedure, or set to the User Information ID of the target 5G ProSe End UE in case:
[0184] 1) the initiating UE acts as the source 5G ProSe End UE and the User Information ID of the target 5G ProSe End UE is obtained during the 5G ProSe Inter-UE Relay discovery procedure; or
[0185] 2) the initiating UE acts as the 5G ProSe Inter-UE Relay UE and the User Information ID of the target 5G ProSe End UE is obtained in the ProSe Direct Link Setup Request message or in the ProSe Direct Link Modification Request message from the source 5G ProSe End UE;
[0186] ca) include UE-to-UE Relay UE user information, which is set to the user information ID of the 5G ProSe UE-to-UE Relay UE in the following cases:
[0187] 1) obtained during the 5G ProSe UE-to-UE Relay discovery procedure and the 5G ProSe Direct Link Setup procedure is for 5G ProSe direct communication between the source 5G ProSe end UE and the 5G ProSe UE-to-UE Relay UE; or
[0188] 2) the initiating UE acts as the 5G ProSe UE-to-UE Relay UE and the user information ID is configured under the configuration parameters for 5G ProSe UE-to-UE Relay as specified in clause 5.2.7;
[0189] cb) include target end UE layer 2 ID, which is set to the layer 2 ID of the target 5G ProSe end UE if the initiating UE acts as the source 5G ProSe end UE and the layer 2 ID of the target 5G ProSe end UE is available in the source 5G ProSe end UE via previous direct communication;
[0190] d) if the 5G ProSe direct link is not used for direct communication between the 5G ProSe remote UE and the 5G ProSe UE-to-Network Relay UE:
[0191] 1) include the key establishment information container if the UE PC5 unicast signaling integrity protection policy is set to "signaling integrity protection required" or "signaling integrity protection preferred", and can include the key establishment information container if the UE PC5 unicast signaling integrity protection policy is set to "signaling integrity protection not required";
[0192] NOTE 3: The key establishment information container is provided by upper layers.
[0193] e) include:
[0194] 1) Nonce_1, conditional on the direct communication not being between the 5G ProSe remote UE and the 5G ProSe UE-to-Network Relay UE, or conditional on the direct communication being between the 5G ProSe remote UE and the 5G ProSe UE-to-Network Relay UE and the security procedures on the control plane being used as specified in 3GPP TS 33.503
[34] ; or
[0195] 2) K NRP freshness parameter 1, conditional on the direct communication being between the 5G ProSe remote UE and the 5G ProSe UE-to-Network Relay UE and the security procedures on the user plane being used as specified in 3GPP TS 33.503
[34] ;
[0196] If the UE PC5 unicast signaling integrity protection policy is set to "signaling integrity protection required" or "signaling integrity protection preferred", a 128-bit random number value generated by the initiating UE is set for the purpose of this 5G ProSe Direct Link session key establishment;
[0197] NOTE 4: The Nonce_1 IE in the ProSe Direct Link Setup Request message is used to hold Nonce_1 or K NRP Freshness parameter 1 value.
[0198] f) Include its UE security capabilities, a list of algorithms that the initiating UE supports for security establishment for this 5G ProSe Direct Link;
[0199] g) If the UE PC5 unicast signaling integrity protection policy is set to "signaling integrity protection required" or "signaling integrity protection preferred", include K NRP-sess ID selected by the initiating UE as specified in 3GPP TS 33.503
[34] ;
[0200] NOTE 5: If the direct communication is not between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, K NRP-sess ID holds the ID corresponding to K NRP-sess ID. If the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, K NRP-sess ID holds the ID corresponding to K NRP-sess ID. (If a security procedure on the user plane is used) or K relay-sess ID. (If a security procedure on the control plane is used).
[0201] h) If the initiating UE has an existing K NRP ID for the target UE, and the direct communication is not between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, K NRP ID can be included;
[0202] i) Include a UE PC5 unicast signaling security policy. In case different ProSe applications are mapped to different PC5 unicast signaling security policies, when the initiating UE wishes to establish a single unicast link that can be used for more than one ProSe application, each signaling security policy of those ProSe applications shall be compatible, e.g. "signaling integrity protection not required" and "signaling integrity protection required" are not compatible. In case the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-Network Relay UE, the signaling integrity protection policy shall be set to "signaling integrity protection required";
[0203] j) Include a Relay Service Code IE, which is set to the Relay Service Code of the target Relay UE in case the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-Network Relay UE, or is set to the Relay Service Code indicating the connectivity service requested by the source 5G ProSe end UE in case the 5G ProSe direct link establishment procedure is used for direct communication between a (source or target) 5G ProSe end UE and a 5G ProSe inter-UE Relay UE;
[0204] k) Include a UTC-based counter LSB, which is set to the four least significant bits of a UTC-based counter, if the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-Network Relay UE;
[0205] l) Include a UE Identity IE, which is set to the SUCI of the initiating UE in case:
[0206] 1) the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-Network Relay UE; and
[0207] 2) the security for 5G ProSe UE-to-Network Relay uses a security procedure on the control plane and the initiating UE does not have a valid CP-PRUK, as specified in 3GPP TS 33.503
[34] , or the security for 5G ProSe UE-to-Network Relay uses a security procedure on the user plane and the initiating UE does not have a valid UP-PRUK, as specified in 3GPP TS 33.503
[34] ;
[0208] m) Include a User Security Key ID IE, which is set to:
[0209] 1) the UP-PRUK ID of the initiating UE, provided that:
[0210] i) the 5G ProSe Direct Link Setup procedure is used for direct communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE;
[0211] ii) the initiating UE has a valid UP-PRUK; and
[0212] iii) the security for 5G ProSe UE-to-Network Relay uses the security procedures on the user plane as specified in 3GPP TS 33.503
[34] ; or
[0213] 2) the CP-PRUK ID of the initiating UE associated with the relay service code of the target UE, with the condition that:
[0214] i) the 5G ProSe Direct Link Setup procedure is used for direct communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE;
[0215] ii) the initiating UE has a valid CP-PRUK associated with the relay service code of the target UE; and
[0216] iii) the security for 5G ProSe UE-to-Network Relay uses the security procedures on the control plane as specified in 3GPP TS 33.503
[34] ;
[0217] n) the HPLMN ID of the initiating UE is included if the UP-PRUK ID of the initiating UE is included and it is not in NAI format (see 3GPP TS 33.503
[34] );
[0218] o) the MIC IE is included and set to the computed MIC value as specified in section 6.3.5.3 of 3GPP TS 33.503
[34] if the 5G ProSe Direct Link Setup procedure is used for direct communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE and the UE has a DUIK; and
[0219] p) the Relay Indication is included indicating that the ProSe Direct Link Setup Request message can be forwarded by a 5G ProSe Inter-UE Relay UE if the 5G ProSe Direct Link Setup procedure is used for direct communication between a source 5G ProSe End UE and a 5G ProSe Inter-UE Relay UE with integrated discovery;
[0220] Editor's Note: Security parameters for 5G ProSe Inter-UE Relay and parameters for 5G ProSe Layer 2 Inter-UE Relay are to be further studied.
[0221] After generating the ProSe Direct Link Setup Request message, the initiating UE shall pass this message to lower layers for transmission along with the source Layer-2 ID and the destination Layer-2 ID as follows:
[0222] a) If the 5G ProSe Direct Communication is due to 5G ProSe Direct Discovery as defined in clause 6.2.14, 6.2.15, 8.2.1 and 8a.2.1:
[0223] assign the source Layer-2 ID by itself, and
[0224] 1) set to the destination Layer-2 ID of the target end-UE Layer-2 ID received in the ProSe Direct Link Setup Request message or ProSe Direct Link Modification Request message from the source 5G ProSe end-UE in case the initiating UE acts as a 5G ProSe Inter-UE Relay UE;
[0225] 2) else, set to the destination Layer-2 ID of the source Layer-2 ID received in the ProSe PC5 Discovery message for discovery procedure;
[0226] b) If the initiating UE acts as a source 5G ProSe end-UE and the 5G ProSe Direct Link Setup procedure is for direct communication between the source 5G ProSe end-UE and a 5G ProSe Inter-UE Relay UE with integrated discovery:
[0227] assign the source Layer-2 ID by itself and set the destination Layer-2 ID to the broadcast destination Layer-2 ID configured as specified in clause 5.2.4; or
[0228] c) If the initiating UE acts as a 5G ProSe Inter-UE Relay UE and the 5G ProSe Direct Link Setup procedure is for direct communication between the 5G ProSe Inter-UE Relay UE and a target 5G ProSe end-UE with integrated discovery:
[0229] assign the source Layer-2 ID by itself and set the destination Layer-2 ID to:
[0230] 1) the target end-UE Layer-2 ID, if received in the ProSe Direct Link Setup Request message from the source 5G ProSe end-UE; else
[0231] 2) the broadcast destination Layer-2 ID configured as specified in clause 5.2.4; or
[0232] d) else:
[0233] a destination Layer 2 ID that is set for the destination Layer 2 ID for unicast initial signaling as specified in clause 5.2.4,
[0234] NOTE 6: The UE implementation ensures that any value of the self-assigned source Layer 2 ID in a) and b) is different from any other self-assigned source Layer 2 ID used for 5G ProSe Direct Discovery as specified in clauses 6.2.14, 6.2.15, and 8.2.1, and different from any other provisioned destination Layer 2 ID as specified in clause 5.2.
[0235] NOTE 6A: If the 5G ProSe Direct Link Establishment procedure is used for 5G ProSe direct communication between a 5G ProSe Layer-3 inter-UE relay and a target 5G ProSe Layer-3 endpoint UE, the UE implementation ensures that any value of the self-assigned source Layer 2 ID in a) and b) is different from any self-assigned source Layer 2 ID used for 5G ProSe direct communication with a different data unit type than the data unit type of the established 5G ProSe direct link.
[0236] NOTE 6B: If the 5G ProSe Direct Link Establishment procedure is used for 5G ProSe direct communication between a 5G ProSe Layer-3 inter-UE relay and a target 5G ProSe Layer-3 endpoint UE and for unstructured traffic, the UE implementation ensures that any value of the self-assigned source Layer 2 ID in a) and b) is different from any other self-assigned source Layer 2 ID used for 5G ProSe direct communication for unstructured traffic and different pair of user information ID of the source 5G ProSe endpoint UE and user information ID of the target 5G ProSe endpoint UE.
[0237] NOTE 7: The initiating UE has the possibility to reuse the Layer 2 ID of the initiating UE used in a previous 5G ProSe direct link with the same peer UE, except for the case where the 5G ProSe Direct Link Establishment procedure is used for 5G ProSe direct communication between a 5G ProSe Layer-3 inter-UE relay and a target 5G ProSe Layer-3 endpoint UE for unstructured traffic and for a different pair of user information ID of the source 5G ProSe endpoint UE and user information ID of the target 5G ProSe endpoint UE, and except for the case where the 5G ProSe Direct Link Establishment procedure is used for 5G ProSe direct communication between a 5G ProSe Layer-3 inter-UE relay and a target 5G ProSe Layer-3 endpoint UE with a different data unit type than the data unit type of the previous 5G ProSe direct link.
[0238] and start timer T5080.
[0239] NOTE 8: The pre-configured PC5 DRX configuration is used for transmitting the ProSe Direct Link Setup Request message as specified in 3GPP TS 38.300
[21] .
[0240] While timer T5080 is running, the UE shall not send a new ProSe Direct Link Setup Request message to the same target UE identified by the same application layer ID. If the target user information IE is not included in the ProSe Direct Link Setup Request message (i.e., ProSe Application oriented 5G ProSe Direct Link Setup procedure), the initiating UE shall handle multiple ProSe Direct Link Setup Accept messages (if any) received from different target UEs for establishing multiple 5G ProSe Direct Links before the expiry of timer T5080.
[0241] NOTE 9: To ensure successful 5G ProSe Direct Link Setup, T5080 shall be set to a value greater than the sum of T5089 and T5092.
[0242] [3GPP TS 24.554 V18.2.0, entitled "5G ProSe Direct Link Setup Procedure for UE orientation", clause 5.2.2.2.1, is reproduced as Figure 7 .2.2.2.1 reproduced as Figure 7 ]
[0243] [3GPP TS 24.554 V18.2.0, entitled "5G ProSe Direct Link Setup Procedure for ProSe Service orientation", clause 5.2.2.2.2, is reproduced as Figure 7 .2.2.2.2 reproduced as Figure 8 ]
[0244] 7.2.2.3 5G ProSe Direct Link Setup procedure accepted by the target UE
[0245] Upon receiving the ProSe Direct Link Setup Request message, if the target UE accepts this request, the target UE shall uniquely assign a PC5 link identifier, create a 5G ProSe Direct Link context.
[0246] NOTE 1: The pre-configured PC5 DRX configuration is used for receiving the ProSe Direct Link Setup Request message as specified in 3GPP TS 38.300
[21] .
[0247] If the ProSe Direct Link Setup Request message is for 5G ProSe Direct Communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, the target UE shall verify the MIC field in the received ProSe Direct Link Setup Request with the DUIK (if present) and decrypt the encrypted:
[0248] a) Relay Service Code; and
[0249] b) UP-PRUK ID or CP-PRUK ID (if received),
[0250] The DUCK or DUSK is used for 5G ProSe UE-to-Network Relay discovery (see section 6.3.5.2 of 3GPP TS 33.503
[34] ), and the target UE verifies that the Relay Service Code matches the code sent by the target UE during the 5G ProSe UE-to-Network Relay discovery procedure.
[0251] NOTE 2: If the UE is neither configured with a DUCK nor with a DUSK, the Relay Service Code and UP-PRUK ID or CP-PRUK ID are not encrypted.
[0252] If the target UE acts as a target 5G ProSe End-UE and the 5G ProSe Direct Link Setup procedure is used for direct communication between a 5G ProSe Inter-UE Relay UE and the target 5G ProSe End-UE, integrated with discovery, upon receiving a ProSe Direct Link Setup Request message containing the same Source User Info, ProSe Identifier and Relay Service Code as received from multiple 5G ProSe Inter-UE Relay UEs, the target UE selects the 5G ProSe Inter-UE Relay UE to use for communication with the Source 5G ProSe End-UE as specified in section 6.7.3.2 of TS 23.304.
[0253] If the 5G ProSe Direct Link Setup procedure is not used for direct communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, the target UE can initiate the 5G ProSe Direct Link Authentication procedure as specified in section 7.2.12 and shall initiate the 5G ProSe Direct Link Security Mode Control procedure as specified in section 7.2.10.
[0254] If the 5G ProSe Direct Link Setup procedure is used for direct communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, the target UE shall proceed with:
[0255] a) the Authentication and Key Agreement procedure as specified in section 5.5.4 of 3GPP TS 24.501
[11] with the condition that the security procedure on the control plane as specified in 3GPP TS 33.503
[34] is used; or
[0256] b) Key request procedure as specified in clause 8.2.10.2.4, with the condition that security procedures on the user plane as specified in 3GPP TS 33.503
[34] are used;
[0257] and initiate the 5G ProSe Direct Link Security Mode Control procedure as specified in clause 7.2.10.
[0258] In the 5G ProSe Direct Link context, the target UE shall set the source Layer-2 ID and the destination Layer-2 ID as specified in clause 7.2.12 and clause 7.2.10, and store the corresponding source Layer-2 ID for unicast communication and the destination Layer-2 ID for unicast communication.
[0259] If:
[0260] a) the target user information IE is included in the ProSe Direct Link Establishment Request message and this IE contains the application layer ID of the target UE; or
[0261] b) the target user information IE is not included in the ProSe Direct Link Establishment Request message and the target UE is interested in the ProSe application identified by the ProSe Identifier IE in the ProSe Direct Link Establishment Request message;
[0262] then the target UE shall:
[0263] a) if the direct communication is not between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE:
[0264] 1) identify the existing K NRP ID based on the K NRP ID included in the ProSe Direct Link Establishment Request message; or
[0265] 2) if the K NRP ID is not included in the ProSe Direct Link Establishment Request message, the target UE does not have an existing K NRP ID for the K NRP ID included in the ProSe Direct Link Establishment Request message, or the target UE wishes to derive a new K NRP , then derive a new K NRP . This can require performing one or more 5G ProSe Direct Link Authentication procedures as specified in clause 7.2.12;
[0266] b) If the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE and uses the security procedures on the control plane as specified in 3GPP TS 33.503
[34] , a new K is requested according to the security procedures on the user plane as specified in 3GPP TS 33.503
[34] NR_ProSe ; or
[0267] c) If the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE and uses the security procedures on the user plane as specified in 3GPP TS 33.503
[34] , a new K is requested according to the security procedures on the user plane NRP .
[0268] NOTE 3: How many times the 5G ProSe Direct Link Authentication procedure needs to be performed to derive a new K NRP depends on the authentication method used.
[0269] After the existing K NRP or a new K NRP is identified, or after receiving a new K NRP or K NR_ProSe , the target UE shall initiate the 5G ProSe Direct Link Security Mode Control procedure as specified in clause 7.2.10.
[0270] After the 5G ProSe Direct Link Security Mode Control procedure is successfully completed, in order to determine whether the ProSe Direct Link Establishment Request message can be accepted, the target UE checks whether there is at least one common IP address configuration option supported by both the initiating UE and the target UE in case of IP communication.
[0271] Before sending the ProSe Direct Link Establishment Accept message to the 5G ProSe Remote UE, the target UE acting as a 5G ProSe Layer-3 UE-to-Network Relay UE initiates the PDU Session Establishment procedure requested by the UE, as specified in 3GPP TS 24.501
[11] , provided that:
[0272] 1) the PDU Session for relaying the services associated with the RSC has not been established; or
[0273] 2) the PDU Session for relaying the services associated with the RSC has been established but the PDU Session Type is unstructured.
[0274] If the target UE accepts the 5G ProSe Direct Link Establishment procedure, the target UE shall create the ProSe Direct Link Establishment Accept message. The target UE:
[0275] a) Include source user information set to the application layer ID of the target UE received from upper layers, or to the user information ID of the target 5G ProSe end UE in case of 5G ProSe direct link establishment procedure for 5G ProSe direct communication between a 5G ProSe inter-UE relay and a 5G ProSe UE-to-UE relay;
[0276] aa) Include inter-UE relay user information set to the user information ID of the 5G ProSe inter-UE relay in case of 5G ProSe direct link establishment procedure for 5G ProSe direct communication between a source 5G ProSe end UE and a 5G ProSe inter-UE relay;
[0277] b) Include PQFI, corresponding PC5 QoS parameters and optionally ProSe identifier accepted by the target UE, with the condition that the target UE does not act as a 5G ProSe layer 2 UE-to-Network relay and the 5G ProSe direct link establishment procedure is not integrated with discovery;
[0278] c) Can include PC5 QoS rules, with the condition that the target UE does not act as a 5G ProSe layer 2 UE-to-Network relay and the 5G ProSe direct link establishment procedure is not integrated with discovery;
[0279] d) If IP communication is used and the target UE does not act as a 5G ProSe layer 2 UE-to-Network relay, include IP address configuration IE set to one of the following values:
[0280] 1) "DHCPv4 server" with the condition that only IPv4 address allocation mechanism is supported by the target UE, i.e. acts as a DHCPv4 server;
[0281] 2) "IPv6 router" with the condition that only IPv6 address allocation mechanism is supported by the target UE, i.e. acts as an IPv6 router;
[0282] 3) "DHCPv4 server and IPv6 router" with the condition that both IPv4 and IPv6 address allocation mechanisms are supported by the target UE; or
[0283] 4) "Address allocation not supported" with the condition that neither IPv4 nor IPv6 address allocation mechanisms are supported by the target UE and the target UE does not act as a 5G ProSe layer 3 UE-to-Network relay;
[0284] NOTE 4: If the communication uses Ethernet or unstructured data unit type, the UE does not include the IP address configuration IE nor the link-local IPv6 address IE.
[0285] e) If the IP address configuration IE is set to "Address allocation not supported", the received ProSe Direct Link Security Mode Complete message contains the Link-Local IPv6 Address IE and the target UE does not act as a 5G ProSe Layer 2 UE-to-Network Relay UE nor as a 5G ProSe Layer 3 Relay UE, then include the Link-Local IPv6 address IE formed locally based on IETF RFC 4862
[25] ;
[0286] f) Include the configuration of the UE PC5 unicast user plane security protection based on the agreed user plane security policy as specified in 3GPP TS 33.503
[34] .
[0287] Editor's note: Security parameters for 5G ProSe UE-to-UE Relay and parameters for 5G ProSe Layer 2 UE-to-UE Relay are to be further studied.
[0288] g) If the 5G ProSe Direct Link Setup procedure is used for 5G ProSe direct communication between the source or target 5G ProSe Layer 3 end UE and a 5G ProSe Layer 3 UE-to-UE Relay UE and for Ethernet traffic, include the MAC address of the target 5G ProSe Layer 3 end UE; and
[0289] h) The target 5G ProSe Layer 3 end UE IP address IE can be included, set to the IP address of the target 5G ProSe Layer 3 end UE, provided that the 5G ProSe Direct Link Setup procedure is used for 5G ProSe direct communication between the source 5G ProSe Layer 3 end UE and a 5G ProSe Layer 3 UE-to-UE Relay UE and the type of data unit of the communication is IP.
[0290] Editor's note: Security parameters for 5G ProSe UE-to-UE Relay and parameters for 5G ProSe Layer 2 UE-to-UE Relay are to be further studied.
[0291] After generating the ProSe Direct Link Setup Accept message, the target UE passes this message to lower layers for transmission along with the Layer 2 ID of the initiating UE for unicast communication and the Layer 2 ID of the target UE for unicast communication and starts timer T5090 in the following cases:
[0292] a) At least one ProSe Identifier for the 5G ProSe Direct Link satisfies the privacy requirements as specified in clause 5.2.4; or
[0293] b) T5090 is configured as specified in clause 5.2.5.
[0294] NOTE 5: The two UEs negotiate the PC5 DRX configuration in the AS layer and the PC5 DRX parameter values are configured per pair of source and destination Layer 2 IDs in the AS layer as specified in 3GPP TS 38.300
[21] .
[0295] After sending the ProSe Direct Link Setup Accept message, the target UE provides the following information to lower layers along with the Layer 2 ID, enabling the lower layers to handle the incoming PC5 signaling or traffic data:
[0296] a) the PC5 link identifier self-assigned for this 5G ProSe Direct Link;
[0297] b) the PQFI and its corresponding PC5 QoS parameters (if available); and
[0298] c) an indication of activation of PC5 unicast user plane security protection for the 5G ProSe Direct Link (if applicable).
[0299] If the target UE accepts the 5G ProSe Direct Link Setup Request and the 5G ProSe Direct Link is established but not used for 5G ProSe Direct Communication between a 5G ProSe Layer 3 Remote UE and a 5G ProSe Layer 3 UE-to-Network Relay UE and 5G ProSe Direct Communication between a 5G ProSe Layer 3 End UE and a 5G ProSe Layer 3 Inter-UE Relay UE, the target UE can perform PC5 QoS Flow Setup on the 5G ProSe Direct Link as specified in Section 7.2.7. If the 5G ProSe Direct Link is established for 5G ProSe Direct Communication between a 5G ProSe Layer 3 Remote UE and a 5G ProSe Layer 3 UE-to-Network Relay UE, the target UE can perform PC5 QoS Flow Setup on the 5G ProSe Direct Link as specified in Section 8.2.6. If the 5G ProSe Direct Link is established for 5G ProSe Direct Communication between a 5G ProSe Layer 3 End UE and a 5G ProSe Layer 3 Inter-UE Relay UE, the target UE can perform PC5 QoS Flow Setup on the 5G ProSe Direct Link as specified in Section 8a.2.7.
[0300] 7.2.2.4 Completion of the 5G ProSe Direct Link Setup procedure by the initiating UE
[0301] If the target user information IE is included in the ProSe Direct Link Setup Request message, upon receiving the ProSe Direct Link Setup Accept message, the initiating UE shall stop the timer T5080. If the target user information IE is not included in the ProSe Direct Link Setup Request message, the initiating UE can keep the timer T5080 running and continue to process multiple response messages (i.e., ProSe Direct Link Setup Accept messages) from multiple target UEs.
[0302] For each received ProSe Direct Link Setup Accept message, the initiating UE shall uniquely assign a PC5 link identifier and create a 5G ProSe Direct Link context for each. The initiating UE shall then store the source and destination Layer 2 IDs used in the transmission of this message provided by the lower layers in the 5G ProSe Direct Link context to complete the establishment of the 5G ProSe Direct Link with the target UE. From this point onwards, the initiating UE shall use the established link for ProSe Direct Communication over PC5 and additional PC5 signaling messages to the target UE.
[0303] If the initiating UE acts as a 5G ProSe Inter-UE Relay UE and the 5G ProSe Direct Link Setup procedure is used for direct communication between the 5G ProSe Inter-UE Relay UE and the target 5G ProSe End-UE, integrated with discovery, upon receiving the ProSe Direct Link Setup Accept message from the target 5G ProSe End-UE, the initiating UE shall initiate the 5G ProSe Direct Link Security Mode Control procedure with the source 5G ProSe End-UE and upon successful completion of the 5G ProSe Direct Link Security Mode Control procedure with the source 5G ProSe End-UE, the initiating UE shall create the ProSe Direct Link Setup Accept message as specified in section 7.2.2.3 to send to the source 5G ProSe End-UE.
[0304] Upon receiving the ProSe Direct Link Setup Accept message, the initiating UE shall provide the following information to the lower layers along with the Layer 2 ID, enabling the lower layers to process the incoming PC5 signaling or traffic data:
[0305] a) the PC5 link identifier self-assigned for this 5G ProSe Direct Link;
[0306] b) the PQFI and its corresponding PC5 QoS parameters (if available); and
[0307] c) an indication of activation of PC5 unicast user plane security protection for the 5G ProSe Direct Link (if applicable).
[0308] The initiating UE shall start timer T5090, provided that:
[0309] a) at least one ProSe identifier for the 5G ProSe direct link meets the privacy requirements as specified in clause 5.2.4; or
[0310] b) T5090 is configured as specified in clause 5.2.5.
[0311] In addition, the initiating UE can perform PC5 QoS flow establishment over the 5G ProSe direct link as specified in clause 7.2.7.
[0312] Upon expiry of timer T5080, if the ProSe Direct Link Establishment Request message does not contain the Target User Information IE and the initiating UE receives at least one ProSe Direct Link Establishment Accept message, the UE implementation shall consider the 5G ProSe Direct Link Establishment procedure as completed or restart timer T5080.
[0313] If the 5G ProSe Direct Link Establishment procedure is triggered by a ProSe Direct Link Modification Request message from a source 5G ProSe Layer-3 end UE as specified in clause 7.2.3.2, in case the initiating UE acts as a 5G ProSe Layer-3 inter-UE relay, upon receiving the ProSe Direct Link Establishment Accept message, the initiating UE shall send a ProSe Direct Link Modification Accept message to the source 5G ProSe Layer-3 end UE as specified in clause 7.2.3.3.
[0314] 7.2.2.5 5G ProSe Direct Link Establishment procedure not accepted by the target UE
[0315] If the ProSe Direct Link Establishment Request message cannot be accepted, the target UE shall send a ProSe Direct Link Establishment Reject message. The ProSe Direct Link Establishment Reject message contains the PC5 Signaling Protocol Cause IE set to one of the following cause values:
[0316] #1 Direct communication with the target UE is not allowed;
[0317] #3 Layer-2 ID collision for unicast communication is detected;
[0318] #5 Lack of resources for 5G ProSe direct link;
[0319] #13 Congestion situation;
[0320] #15 Security procedure of 5G ProSe UE-to-Network relay failed;
[0321] #20 Failure from 5G ProSe end UE;
[0322] #yy 5G ProSe direct link already exists; or
[0323] #111 Unspecified protocol error.
[0324] If the target UE is not allowed to accept the ProSe Direct Link Setup Request message, e.g. based on operator policy or configuration parameters for ProSe direct communication over PC5 as specified in clause 5.2, or the target UE acts as a 5G ProSe Layer 3 UE-to-Network Relay UE in a not allowed area of its serving PLMN and the corresponding relay service code is not associated with high priority access as defined in clause 5.3.5 of 3GPP TS 24.501
[11] , the target UE shall send a ProSe Direct Link Setup Reject message containing the PC5 Signaling Protocol cause value #1 "Direct communication with target UE not allowed".
[0325] NOTE 1: When a target UE acting as a 5G ProSe Layer 3 UE-to-Network Relay UE is involved in its own emergency service as specified in 3GPP TS 24.501
[11] or handling an emergency service of another 5G ProSe Layer 3 Remote UE and receives a ProSe Direct Link Setup Request message with an RSC specific to an emergency service, the target UE is allowed to ignore the ProSe Direct Link Setup Request message if the target UE decides to prioritize its own ongoing emergency service or to prioritize handling the emergency service of the other 5G ProSe Layer 3 Remote UE due to local regulations or implementation-specific requirements.
[0326] For a ProSe Direct Link Setup Request message (for unicast communication) received from a Layer 2 ID, if the target UE has already established an existing link to the UE using this Layer 2 ID or is currently handling a ProSe Direct Link Setup Request message from the same Layer 2 ID with one of the following parameters different from the existing link or the link whose link setup is ongoing:
[0327] a) source user information;
[0328] b) data type (e.g. IP, Ethernet or unstructured); or
[0329] c) security policy,
[0330] the target UE shall send a ProSe Direct Link Setup Reject message containing the PC5 Signaling Protocol cause value #3 "Conflict of Layer 2 ID for unicast communication detected".
[0331] NOTE 2: If the UE is processing a ProSe Direct Discovery message from the same source Layer-2 ID as the received ProSe Direct Link Setup Request message, avoiding a conflict of the Destination Layer-2 ID is up to UE implementation (e.g., sending a ProSe Direct Link Setup Reject message containing PC5 Signaling Protocol Cause Value #3 "Conflict of Layer-2 ID for unicast communication detected" or ignoring the ProSe Direct Discovery message).
[0332] NOTE 3: The data type (e.g., IP, Ethernet or unstructured) is indicated by the optional IP Address Configuration IE contained in the corresponding Direct Link Security Mode Complete message, i.e., if this IE is included, the data type of the requested link is IP type, and if this IE is not included, the data type of the requested link is Ethernet or unstructured.
[0333] If the 5G ProSe Direct Link Setup fails due to having reached the implementation-specific maximum number of established 5G ProSe Direct Links or other temporary lower layer problems causing resource constraints, the target UE shall send a ProSe Direct Link Setup Reject message containing PC5 Signaling Protocol Cause Value # "5G ProSe Direct Link resources are scarce".
[0334] If the 5G ProSe Direct Link Setup Request is for a 5G ProSe UE-to-Network Relay and:
[0335] a) NAS level mobility management congestion control as specified in section 5.3.9 of TS 24.501
[11] is activated at the target UE acting as a 5G ProSe UE-to-Network Relay UE; or
[0336] b) the target UE acting as a 5G ProSe UE-to-Network Relay UE is in a congestion state;
[0337] the target UE shall send a ProSe Direct Link Setup Reject message containing PC5 Signaling Protocol Cause Value #13 "Congestion situation". The target UE can provide a back-off timer value to the initiating UE in the ProSe Direct Link Setup Reject message. If the back-off timer for NAS level mobility management congestion control is running, the target UE shall not accept any 5G ProSe Direct Link Setup Request for relaying.
[0338] If the 5G ProSe Direct Link Setup Request is for 5G ProSe Layer 3 UE-to-Network Relay, NAS level session management congestion specified in sections 6.2.7 and 6.2.8 of TS 24.501
[11] is activated at the target UE acting as a 5G ProSe Layer 3 UE-to-Network Relay UE, and the Relay Service Code used in the 5G ProSe Direct Link Setup corresponds to a DNN and / or S-NSSAI for which NAS level session management congestion is activated, and the target UE needs to perform a PDU Session Establishment procedure for the DNN and / or S-NSSAI or a PDU Session Modification procedure for the DNN and / or S-NSSAI, the target UE shall send a ProSe Direct Link Setup Reject message containing the PC5 Signaling Protocol Cause value #13 "Congestion situation". The target UE can provide a fallback timer value to the Initiating UE in the ProSe Direct Link Setup Reject message.
[0339] NOTE 4: How the target UE determines that it is in a congestion state is implementation specific (e.g., any relay related operation overhead, etc.).
[0340] NOTE 5: In case the target UE is under NAS level mobility management congestion control, the fallback timer value provided to the initiating UE is set to the remaining time of the mobility management fallback timer T3346 or with an additional offset value is an implementation option.
[0341] If the 5G ProSe Direct Link Setup Request is for 5G ProSe Layer 3 UE-to-Network Relay, the PDU Session used to relay the service is a LADN PDU Session, and the target UE acting as a 5G ProSe Layer 3 UE-to-Network Relay UE is outside the LADN service area, the target UE shall send a ProSe Direct Link Setup Reject message containing the PC5 Signaling Protocol Cause value #111 "Unspecified protocol error".
[0342] If the 5G ProSe Direct Link Setup Request is for a 5G ProSe Layer 3 UE-to-Network Relay, the request needs to establish a PDU Session as a target UE's 5G ProSe Layer 3 UE-to-Network Relay UE and the PDU Session establishment is not successful due to receiving 5GSM cause #8 "Maximum number of PDU Sessions reached", #27 "DNN missing or unknown", #28 "PDU Session Type unknown", #29 "User authentication or authorization not passed", #31 "Unspecified rejection request", #32 "Service option not supported", #33 "Not subscribed to requested service option", #46 "Outside LADN service area" or #65 "Maximum number of PDU Sessions reached" as specified in 3GPP TS 24.501
[11] , the target UE shall send a ProSe Direct Link Setup Reject message containing PC5 Signaling Protocol cause value #111 "Unspecified protocol error".
[0343] If the 5G ProSe Direct Link Setup Request is for a 5G ProSe Inter-UE Relay and:
[0344] a) the target UE acting as a target 5G ProSe End UE is in a congestion state;
[0345] then the target UE shall send a ProSe Direct Link Setup Reject message containing PC5 Signaling Protocol cause value #13 "Congestion situation". The target UE can provide a back-off timer value to the initiating UE in the ProSe Direct Link Setup Reject message.
[0346] Upon receiving a ProSe Direct Link Setup Reject message from a target 5G ProSe End UE, the initiating UE acts as a 5G ProSe Inter-UE Relay UE and the 5G ProSe Direct Link Setup procedure is for direct communication between a source 5G ProSe End UE and the 5G ProSe Inter-UE Relay UE, the target 5G ProSe End UE has rejected the 5G ProSe Direct Link Setup procedure or the 5G ProSe Direct Link Modification procedure, the reject message contains a back-off value, and the initiating UE has not reached the maximum number of allowed retransmissions, the initiating UE shall inform (message TBD) the source 5G ProSe End UE that the target 5G ProSe End UE has rejected the link setup or link modification request and shall provide the cause value from the target 5G ProSe End UE.
[0347] Editor's note: How the target 5G ProSe End UE informs the 5G ProSe Inter-UE Relay UE that it has rejected the link setup or link modification request is to be further studied.
[0348] After receiving a ProSe Direct Link Setup Reject message from the target 5G ProSe End UE, the Initiating UE acts as a 5G ProSe Inter-UE Relay UE, the 5G ProSe Direct Link Setup procedure is for direct communication between a Source 5G ProSe End UE and a 5G ProSe Inter-UE Relay UE, the target 5G ProSe End UE has rejected the 5G ProSe Direct Link Setup procedure or the 5G ProSe Direct Link Modification procedure, the reject message contains a fallback value, and the Initiating UE has reached the maximum number of allowed retransmissions, the Initiating UE shall send a ProSe Direct Link Setup Reject message to the Source 5G ProSe End UE with the appropriate PC5 Signaling Protocol cause value. The Initiating UE shall include the PC5 Protocol Cause Value #20 "Failure from 5G ProSe End UE" in the ProSe Direct Link Setup Reject message and include the PC5 End UE Failure Cause IE set to #13 "Congestion Scenario" received from the target 5G ProSe End UE that rejected the 5G ProSe Direct Link Setup or 5G ProSe Direct Link Modification procedure. The Initiating UE can include the Target End UE Information IE set to the User Info ID of the target 5G ProSe End UE in the ProSe Direct Link Setup Reject message.
[0349] If the 5G ProSe Direct Link Setup Request is for a 5G ProSe Inter-UE Relay and:
[0350] a) the target UE acting as a 5G ProSe Inter-UE Relay UE is in a congestion state;
[0351] then the target UE shall send a ProSe Direct Link Setup Reject message containing the PC5 Signaling Protocol cause value #13 "Congestion Scenario". The target UE can provide a fallback timer value to the Initiating UE in the ProSe Direct Link Setup Reject message.
[0352] If the 5G ProSe Direct Link Setup procedure is for direct communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE and it fails due to a failure of a security procedure on the control plane or a security procedure on the user plane as specified in 3GPP TS 33.503
[34] , the target UE shall send a ProSe Direct Link Setup Reject message containing the PC5 Signaling Protocol cause value #15 "Security procedure failure of 5G ProSe UE-to-Network Relay". If an EAP message is received from the network according to the security procedure on the control plane as specified in 3GPP TS 33.503
[34] , the target UE shall provide the EAP message.
[0353] If the 5G ProSe Direct Link Setup procedure is for direct communication between a 5G ProSe Inter-UE Relay UE and a target 5G ProSe End-UE, integrated with discovery, and a 5G ProSe Direct Link for a pair of Initiating UE User Info ID and Target UE User Info ID already exists and the Data Type element is IP or Ethernet, the target UE will send a ProSe Direct Link Setup Reject message to the 5G ProSe Inter-UE Relay UE containing the PC5 Signaling Protocol Cause value #yy "5G ProSe Direct Link already exists".
[0354] If the target UE acts as a target 5G ProSe End-UE and the 5G ProSe Direct Link Setup procedure is between a 5G ProSe Inter-UE Relay UE and the target 5G ProSe End-UE, the target 5G ProSe End-UE can include in the ProSe Direct Link Setup Reject message:
[0355] a) a Source End-UE Information IE set to the User Info ID of the source 5G ProSe End-UE;
[0356] b) a Target End-UE Information IE set to the User Info ID of the target 5G ProSe End-UE; and
[0357] c) an Inter-UE Relay UE Information IE set to the User Info ID of the 5G ProSe Inter-UE Relay UE.
[0358] If the target UE acts as a 5G ProSe Inter-UE Relay UE, the 5G ProSe Direct Link Setup procedure is between a source 5G ProSe End-UE and the 5G ProSe Inter-UE Relay UE, and the target 5G ProSe End-UE has rejected the 5G ProSe Direct Link Setup procedure or the 5G ProSe Direct Link Modification procedure, the 5G ProSe Inter-UE Relay UE will send a ProSe Direct Link Setup Reject message to the source 5G ProSe End-UE with the PC5 Signaling Protocol Cause value #20 "Failure from 5G ProSe End-UE". The 5G ProSe Inter-UE Relay UE can include in the ProSe Direct Link Setup Reject message a PC5 End-UE Failure Cause IE set to the PC5 Signaling Protocol Cause received from the target 5G ProSe End-UE that has rejected the 5G ProSe Direct Link Setup procedure. The 5G ProSe Inter-UE Relay UE can include in the ProSe Direct Link Setup Reject message:
[0359] a) a Source End-UE Information IE set to the User Info ID of the source 5G ProSe End-UE;
[0360] b) Target UE information IE set to the user information ID of the target 5G ProSe peer UE;
[0361] c) Inter-UE Relay UE information IE set to the user information ID of the 5G ProSe Inter-UE Relay UE.
[0362] NOTE 6: The cause value #15 "Security procedure of 5G ProSe UE-to-Network Relay failed" is also used when no CP-PRUK or UP-PRUK is found in the network.
[0363] If the 5G ProSe Direct Link Setup fails for other reasons, the target UE will send a ProSe Direct Link Setup Reject message containing the PC5 Signaling Protocol cause value #111 "Unspecified protocol error".
[0364] After sending the ProSe Direct Link Setup Reject message, the target UE will provide the following information to the lower layers as well as the Layer 2 ID of the initiating UE for unicast communication and the Layer 2 ID of the target UE for unicast communication:
[0365] a) Deactivation of PC5 unicast security protection and indication of deletion of the security context for 5G ProSe Direct Link (if applicable).
[0366] Upon receiving the ProSe Direct Link Setup Reject message, the initiating UE shall stop timer T5080 and abort the 5G ProSe Direct Link Setup procedure. If the PC5 Signaling Protocol cause value in the ProSe Direct Link Setup Reject message is #1 "Direct Communication with target UE not allowed" or #5 "Lack of resources for 5G ProSe Direct Link", the initiating UE shall not attempt to initiate a 5G ProSe Direct Link Setup procedure with the same target UE for at least a time period T. If the PC5 Signaling Protocol cause value in the ProSe Direct Link Setup Reject message is #13 "Congestion situation" and a back-off timer value is provided in the ProSe Direct Link Setup Reject message, the initiating UE shall start a timer T5088 associated with the Layer 2 ID of the target UE and set its value to the provided timer value. If the PC5 Signaling Protocol cause value in the ProSe Direct Link Setup Reject message is #15 "Security procedure for 5G ProSe UE-to-Network Relay failed" and the initiating UE has included a UE Identity IE set to SUCI in the ProSe Direct Link Setup Request message, the initiating UE shall initiate a UE-to-Network Relay reselection procedure as specified in clause 8.2.3. If the PC5 Signaling Protocol cause value in the ProSe Direct Link Setup Reject message is #15 "Security procedure for 5G ProSe UE-to-Network Relay failed" and the initiating UE has included a User Security Key ID IE set to UP-PRUK ID or CP-PRUK ID in the ProSe Direct Link Setup Request message, the initiating UE can initiate a UE-to-Network Relay reselection procedure as specified in clause 8.2.3 and the UE shall further:
[0367] a) if the same 5G ProSe UE-to-Network Relay UE is selected, discard the previously used CP-PRUK and associated CP-PRUK ID, or UP-PRUK and associated UP-PRUK ID if present, and include a UE Identity IE set to SUCI in the ProSe Direct Link Setup Request when initiating a subsequent 5G ProSe Direct Link Setup procedure as specified in clause 7.2.2.2; or
[0368] b) if a different 5G ProSe UE-to-Network Relay UE is selected, include a User Security Key ID IE set to the previously used UP-PRUK ID or CP-PRUK ID in the ProSe Direct Link Setup Request message.
[0369] NOTE 7: The length of the time period T is UE implementation specific and can be different for the case when the UE receives PC5 Signaling Protocol cause value #1 "Direct communication with the target UE is not allowed" or when the UE receives PC5 Signaling Protocol cause value #5 "Lack of resources for 5G ProSe Direct Link".
[0370] Editor's note: Security related content is FFS and depends on SA3 requirements.
[0371] If the 5G ProSe Direct Link Setup procedure is for direct communication between a 5G ProSe Inter-UE Relay UE and a target 5G ProSe End-UE and the PC5 Signaling Protocol cause value in the ProSe Direct Link Setup Reject message is #yy "5G ProSe Direct Link already exists", the initiating UE acting as a 5G ProSe Inter-UE Relay UE can initiate a 5G ProSe Direct Link Modification procedure with the target UE to associate the source 5G ProSe End-UE user information ID and ProSe Identifier as specified in the rejected ProSe Direct Link Setup Request message with the existing 5G ProSe Direct Link.
[0372] Upon reception of the ProSe Direct Link Setup Reject message, the initiating UE shall provide the following information to lower layers along with the Layer-2 ID of the initiating UE for unicast communication and the Layer-2 ID of the target UE for unicast communication:
[0373] a) Deactivation of PC5 unicast security protection and indication of deletion of the security context for 5G ProSe Direct Link (if applicable).
[0374] 7.2.2.6 Abnormal cases
[0375] 7.2.2.6.1 Abnormal cases at the initiating UE
[0376] If the timer T5080 expires and the target user information IE is included in the ProSe Direct Link Setup Request message, the initiating UE shall retransmit the ProSe Direct Link Setup Request message and restart the timer T5080. Upon reaching the maximum number of allowed retransmissions, the initiating UE shall abort the 5G ProSe Direct Link Setup procedure and can inform the upper layers that the target UE is unreachable.
[0377] Upon expiry of timer T5080, if the ProSe Direct Link Setup Request message does not contain the Target User Info IE and the initiating UE does not receive any ProSe Direct Link Setup Accept message, the initiating UE can retransmit the ProSe Direct Link Setup Request message and restart timer T5080. If the ProSe Direct Link Setup Request message does not contain the Target User Info IE and the initiating UE does not receive any ProSe Direct Link Setup Accept message, upon reaching the maximum number of allowed retransmissions, the initiating UE will abort the 5G ProSe Direct Link Setup procedure and can inform upper layers that no target UE is available.
[0378] NOTE: The maximum number of allowed retransmissions is UE implementation specific.
[0379] If the link does not need to be established anymore before the procedure is completed, the initiating UE shall abort the procedure.
[0380] When the initiating UE aborts the 5G ProSe Direct Link Setup procedure, the initiating UE will provide the following information to lower layers, together with the Layer 2 ID of the initiating UE for unicast communication and the Layer 2 ID of the target UE for unicast communication:
[0381] a) Deactivation of PC5 unicast security protection and indication of deletion of the security context for 5G ProSe Direct Link (if applicable).
[0382] 7.2.2.6.2 Abnormal cases at the target UE
[0383] For a ProSe Direct Link Setup Request message received from a source Layer 2 ID (for unicast communication), if the target UE has already established an existing link with a UE known to use the same source Layer 2 ID, the same source user information, the same data type (IP, Ethernet or unstructured) and the same security policy, the UE shall process the new request. However, the target UE shall delete the existing 5G ProSe Direct Link context only after the new link setup procedure is successful.
[0384] NOTE: The data type (e.g. IP, Ethernet or unstructured) is indicated by the optional IP Address Configuration IE contained in the corresponding ProSe Direct Link Security Mode Complete message, i.e. if this IE is contained, the data type of the requested link is IP type, and if this IE is not contained, the data type of the requested link is Ethernet or unstructured.
[0385] If the ProSe Direct Link Setup Request message is for 5G ProSe Direct Communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, after the target UE decrypts the encrypted Relay Service Code using the DUSK or DUCK for 5G ProSe UE-to-Network Relay discovery, the target UE shall abort the 5G ProSe Direct Link Setup procedure if the Relay Service Code does not match the code sent by the target UE during the 5G ProSe UE-to-Network Relay discovery procedure.
[0386] If the ProSe Direct Link Setup Request message is for 5G ProSe Direct Communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, message integrity is protected and integrity verification of the message fails at the target UE, the target UE shall abort the 5G ProSe Direct Link Setup procedure.
[0387] […]
[0388] 7.2.10 5G ProSe Direct Link Security Mode Control procedure
[0389] 7.2.10.1 Overview
[0390] The 5G ProSe Direct Link Security Mode Control procedure is used to establish security between two UEs during the 5G ProSe Direct Link Setup procedure or the 5G ProSe Direct Link Key Update procedure. If UE PC5 signaling integrity protection is not activated, no security is established. After successful completion of the 5G ProSe Direct Link Security Mode Control procedure, the selected security algorithms and their non-empty related keys are used for integrity protection and encryption of all PC5 signaling messages exchanged over this 5G ProSe Direct Link between the UEs, and the security context can be used to protect all PC5 user plane data exchanged over this 5G ProSe Direct Link between the UEs. The UE sending the ProSe Direct Link Security Mode Command message is referred to as the "initiating UE" and the other UE is referred to as the "target UE".
[0391] 7.2.10.2 Initiating the 5G ProSe Direct Link Security Mode Control procedure by the initiating UE
[0392] The initiating UE shall meet the following preconditions before initiating the 5G ProSe Direct Link Security Mode Control procedure:
[0393] a) The target UE has initiated the 5G ProSe Direct Link Setup procedure by sending the ProSe Direct Link Setup Request message and the following towards the initiating UE:
[0394] 1) ProSe Direct Link Setup Request message:
[0395] i) contains a Target User Info IE containing the application layer ID of the initiating UE; or
[0396] ii) does not contain a Target User Info IE and the initiating UE is interested in the ProSe service identified by the ProSe Identifier in the ProSe Direct Link Setup Request message; and
[0397] 2) The initiating UE:
[0398] i) if the direct communication is not between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, derives a new K NRP ID based on the K NRP ID identified in the ProSe Direct Link Setup Request message; or NRP ;
[0399] ii) if the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, where a security procedure on the user plane is used, receives a new K NRP according to the security procedure on the user plane as specified in 3GPP TS 33.503
[34] ; or
[0400] iii) if the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, where a security procedure on the control plane is used, receives a new K NR_ProSe according to the security procedure on the control plane as specified in 3GPP TS 33.503
[34] ; or
[0401] iv) has decided not to activate security protection based on its UE 5G ProSe Direct Signaling Security Policy and the 5G ProSe Direct Signaling Security Policy of the target UE; or
[0402] b) the target UE has initiated a 5G ProSe Direct Link Key Update procedure towards the initiating UE by sending a ProSe Direct Link Key Update Request message and:
[0403] 1) if the target UE has included a re-authentication indication in the ProSe Direct Link Key Update Request message, the initiating UE has derived a new K NRP .
[0404] whenever:
[0405] a) the direct communication is not between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, provided that a new K NRP ID has been derived by the initiating UENRP ; or
[0406] b) Direct communication between the 5G ProSe Remote UE and the 5G ProSe UE-to-Network Relay UE, provided that a new K NRP or K NR_ProSe has been received by the initiating UE according to the security procedures on the user plane or the security procedures on the control plane, respectively, as specified in 3GPP TS 33.503
[34] .
[0407] The initiating UE shall generate K NRP ID with 2 MSBs to ensure that the resulting K NRP ID will be unique in the initiating UE.
[0408] NOTE 1: If direct communication is not between the 5G ProSe Remote UE and the 5G ProSe UE-to-Network Relay UE, K NRP ID holds the ID corresponding to K NRP . If direct communication is between the 5G ProSe Remote UE and the 5G ProSe UE-to-Network Relay UE, K NRP ID holds the ID corresponding to K NRP , if the security procedures on the user plane are used, or K NR_ProSe , if the security procedures on the control plane are used.
[0409] The initiating UE shall select the security algorithms according to its UE 5G ProSe Direct Signaling Security Policy and the 5G ProSe Direct Signaling Security Policy of the target UE. If the 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Establishment procedure, the initiating UE shall not select the null integrity protection algorithm if the 5G ProSe Direct Signaling Integrity Protection Policy of the initiating UE or the target UE is set to "signaling integrity protection required". If the 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Key Update procedure, the initiating UE:
[0410] a) shall not select the null integrity protection algorithm if the integrity protection algorithm currently used for the 5G ProSe Direct Link is different from the null integrity protection algorithm;
[0411] b) shall not select the null ciphering protection algorithm if the ciphering protection algorithm currently used for the 5G ProSe Direct Link is different from the null ciphering protection algorithm;
[0412] c) shall select the null integrity protection algorithm if the integrity protection algorithm currently in use is the null integrity protection algorithm; and
[0413] d) If the currently used encryption protection algorithm is the empty encryption protection algorithm, then the empty encryption protection algorithm will be selected.
[0414] Next, the UE will initiate:
[0415] a) If direct communication is not between the 5G ProSe remote UE and the 5G ProSe UE to the network relay UE:
[0416] 1) Generate a 128-bit Nonce_2 value;
[0417] 2) Based on the Nonce_1 and K received in the ProSe direct link establishment request message NRP Exporting K from Nonce_2 NRP-sess As specified in 3GPP TS 33.536
[37] ; and
[0418] 3) According to K NRP-sess The selected security algorithm is used to derive the NR PC5 encryption key NRPEK and the NR PC5 integrity key NRPIK, as specified in 3GPP TS 33.536
[37] ;
[0419] b) If direct communication is between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, and security procedures on the control plane as specified in 3GPP TS 33.503
[34] are used:
[0420] 1) Based on K received in the ProSe direct link establishment request message NR_ProSe Nonce_2 and Nonce_1 derive K relay-sess As specified in 3GPP TS 33.503
[34] ; and
[0421] 2) According to K relay-sess The selected security algorithm is used to derive the NR PC5 encryption key K. relay-enc and NR PC5 integrity key K relay-int As specified in 3GPP TS 33.503
[34] ; or
[0422] c) If direct communication occurs between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, and a user plane security procedure as specified in 3GPP TS 33.503
[34] is used, then:
[0423] 1) Based on K received in the ProSe direct link establishment request message NRP K NRP Freshness parameters 2 and KNRP Freshness parameter 1 derives K NRP-sess as specified in 3GPP TS 33.503
[34] ; and
[0424] 2) Derives NR PC5 encryption key NRPEK and NR PC5 integrity key NRPIK from K NRP-sess and the selected security algorithms as specified in 3GPP TS 33.503
[34] ; and
[0425] d) Creates a ProSe Direct Link Security Mode Command message. In this message, the initiating UE:
[0426] 1) Includes the Key Establishment Information Container IE, provided that the 5G ProSe Direct Link is not used for direct communication between the 5G ProSe Remote UE and the 5G ProSe UE-to-Network Relay UE and a new K NRP has been derived at the initiating UE and is used to produce K NRP The authentication method requires sending information to complete the 5G ProSe Direct Link authentication procedure;
[0427] NOTE 2: The Key Establishment Information Container is provided by upper layers.
[0428] 2) Includes the MSB of K NRP ID IE, provided that a new K NRP has been derived or has been received at the initiating UE; or NRP K NR_ProSe ;
[0429] 3) Includes the Nonce_2 IE, which is set to:
[0430] i) A 128-bit random number value generated by the initiating UE when the direct communication is not between the 5G ProSe Remote UE and the 5G ProSe UE-to-Network Relay UE;
[0431] ii) The K NRP freshness parameter 2 value received by the initiating UE when the direct communication is between the 5G ProSe Remote UE and the 5G ProSe UE-to-Network Relay UE, where the security procedures on the user plane as specified in 3GPP TS 33.503
[34] are used; or
[0432] iii) The Nonce_2 value received by the initiating UE when the direct communication is between the 5G ProSe Remote UE and the 5G ProSe UE-to-Network Relay UE, where the security procedures on the control plane as specified in 3GPP TS 33.503
[34] are used;
[0433] For the purpose of establishing a session key over this 5G ProSe direct link in case the selected integrity protection algorithm is not the null integrity protection algorithm;
[0434] 4) shall contain the selected security algorithm;
[0435] 5) shall contain the UE security capabilities received from the target UE in the ProSe Direct Link Setup Request message or the ProSe Direct Link Key Update Request message;
[0436] 6) shall contain the UE 5G ProSe direct signaling security policy received from the target UE in the ProSe Direct Link Setup Request message;
[0437] 7) shall contain the K NRP-sess ID selected by the initiating UE as specified in 3GPP TS 33.536
[37] , provided that the selected integrity protection algorithm is not the null integrity protection algorithm;
[0438] NOTE 3: If the direct communication is not between the 5G ProSe Remote UE and the 5G ProSe UE-to-Network Relay UE, the K NRP-sess ID holds the ID corresponding to the K NRP-sess ID holds the ID corresponding to the K NRP-sess ID holds the ID corresponding to the K NRP-sess ID holds the ID corresponding to the K relay-sess ID holds the ID corresponding to the K
[0439] 8) shall contain the GPI when the direct communication is between the 5G ProSe Remote UE and the 5G ProSe UE-to-Network Relay UE, if received from the 5G PKMF according to the security procedures over the user plane as specified in 3GPP TS 33.503
[34] ; and
[0440] 9) shall contain the EAP message when the direct communication is between the 5G ProSe Remote UE and the 5G ProSe UE-to-Network Relay UE, if received from the network according to the security procedures over the control plane as specified in 3GPP TS 33.503
[34] .
[0441] If the security protection of this 5G ProSe direct link is activated by using a non-null integrity protection algorithm or a non-null encryption protection algorithm, the initiating UE shall include the K NRP-sessThe MSB of the ID and the K contained in the ProSe direct link security mode command message. NRP-sess ID's LSB formation K NRP-sess ID. The initiating UE will use K. NRP-sess The ID is used to identify the new security context.
[0442] The initiating UE will set the source stratum 2ID and destination stratum 2ID as follows:
[0443] 1) If the initiating UE acts as a 5G ProSe layer 3 UE to a network relay UE, and the authentication method based on EAP-AKA' is used as specified in section 6.3.3.3 of 3GPP TS 33.503
[34] , then
[0444] Set the source layer 2 ID to the source layer 2 ID used for the ProSe AA message transmission request message, and set the destination layer 2 ID to the destination layer 2 ID used for the ProSe AA message transmission request message;
[0445] 2) If the initiating UE does not act as a 5G ProSe UE-to-network relay UE, and the 5G ProSe direct link authentication procedure has already been initiated, then:
[0446] Set the source layer 2 ID to the source layer 2 ID used for the ProSe direct link authentication request message, and set the destination layer 2 ID to the destination layer 2 ID used for the ProSe direct link authentication request message.
[0447] 3) Otherwise, assign a source layer 2 ID and set the destination layer 2 ID to the source layer 2 ID in the ProSe direct link establishment request message.
[0448] Note 4: The UE implementation ensures that any value of the self-assigned source layer 2 ID is different from any other self-assigned source layer 2 ID used for 5G ProSe direct discovery as specified in Sections 6.2.14, 6.2.15 and 8.2.1, and different from any other pre-configured destination layer 2 ID as specified in Section 5.2.
[0449] Note 5: The target UE can reuse the Layer 2 ID that the target UE previously used in a 5GProSe direct link with the same peer UE.
[0450] After generating the ProSe direct link security mode command message, the initiating UE passes this message along with the following to the lower layer for transmission: source layer 2 ID and destination layer 2 ID, NRPIK (or K relay-int (where applicable), NRPEK (or K) relay-enc (where applicable) KNRP-sess ID, selected security algorithms as specified in TS 33.536
[37] , an indication of activation of 5G ProSe Direct Signaling Security Protection for 5G ProSe Direct Link with new security context (if applicable), and start timer T5089. While timer T5089 is running, the initiating UE shall not send a new ProSe Direct Link Security Mode Command message to the same target UE.
[0451] NOTE 6: The ProSe Direct Link Security Mode Command message is integrity protected (and not encrypted) at lower layers using the new security context.
[0452] If the 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Key Update procedure, the initiating UE shall provide to lower layers an indication of activation of 5G ProSe Direct User Plane Security Protection for 5G ProSe Direct Link with new security context (if applicable), along with the initiating UE's Layer 2 ID for 5G ProSe Direct Communication and the target UE's Layer 2 ID for 5G ProSe Direct Communication.
[0453] [3GPP TS 24.554 V18.2.0, clause 5.2.2.2.2, titled "5G ProSe Direct Link Security Mode Control procedure" Figure 7 .2.10.2.1 Reproduced as Figure 9 ]
[0454] 7.2.10.3 5G ProSe Direct Link Security Mode Control procedure accepted by the target UE
[0455] Upon receiving the ProSe Direct Link Security Mode Command message, if the newly assigned Layer-2 ID of the Initiating UE is included and if the 5G ProSe Direct Link Authentication procedure has not been performed, the Target UE shall replace the original Layer-2 ID of the Initiating UE with the newly assigned Layer-2 ID of the Initiating UE for 5G ProSe Direct Communication. The Target UE shall check the selected security algorithms IE included in the ProSe Direct Link Security Mode Command message. If "null integrity algorithm" is included in the selected security algorithms IE, no integrity protection is provided for this 5G ProSe Direct Link and the signaling messages are transmitted unprotected. If "null encryption algorithm" and an integrity algorithm other than "null integrity algorithm" are included in the selected algorithms IE, no encryption protection is provided for this 5G ProSe Direct Link and the signaling messages are transmitted unprotected. If the 5G ProSe Direct Signaling Integrity Protection policy of the Target UE is set to "signaling integrity protection required", the Target UE shall check that the selected security algorithms IE in the ProSe Direct Link Security Mode Command message does not include a null integrity protection algorithm. If the selected integrity protection algorithm is not a null integrity protection algorithm, the Target UE shall:
[0456] a) If the direct communication is not between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE:
[0457] 1) Derive K NRP , Nonce_1 and Nonce_2 from K NRP-sess as specified in 3GPP TS 33.536
[37] ;
[0458] 2) Derive NRPIK from K NRP-sess and the selected integrity algorithm as specified in 3GPP TS 33.536
[37] ; and
[0459] 3) If K NRP-sess is derived and the selected encryption protection algorithm is not a null encryption protection algorithm, the Target UE shall derive NRPEK from K NRP-sess and the selected encryption algorithm as specified in 3GPP TS 33.536
[37] ; or
[0460] b) If the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE:
[0461] 1) If the security procedures on the control plane as specified in 3GPP TS 33.503
[34] are used, derive K relay-sess from the security procedures on the control plane and derive Krelay-sess and the selected integrity algorithm derives K relay-int as specified in 3GPP TS 33.503
[34] . If K relay-sess and the selected encryption protection algorithm is not the null encryption protection algorithm, the target UE shall check the integrity of the ProSe Direct Link Security Mode Command message using NRPIK (or K relay-sess and the selected encryption algorithm derives K relay-enc as specified in 3GPP TS 33.503
[34] ; or
[0462] 2) If the security procedures on the user plane are used as specified in 3GPP TS 33.503
[34] , K NRP-sess is derived according to the security procedures on the user plane, and K NRP-sess and the selected integrity algorithm derives NRPIK as specified in 3GPP TS 33.503
[34] . If K NRP-sess is derived, and the selected encryption protection algorithm is not the null encryption protection algorithm, the target UE shall check the integrity of the ProSe Direct Link Security Mode Command message using NRPIK (or K NRP-sess and the selected encryption algorithm derives NRPEK as specified in 3GPP TS 33.503
[34] .
[0463] The target UE shall determine whether it can accept the ProSe Direct Link Security Mode Command message by:
[0464] a) If the 5G ProSe Direct Signaling Integrity Protection policy of the target UE is set to "Integrity protection of signaling is required", check that the selected security algorithms IE in the ProSe Direct Link Security Mode Command message does not contain the null integrity protection algorithm.
[0465] b) If the selected integrity protection algorithm is not the null integrity protection algorithm, require the lower layers to check the integrity of the ProSe Direct Link Security Mode Command message using NRPIK (or K relay-int , if applicable) and the selected integrity protection algorithm;
[0466] c) Check that the received UE security capabilities have not changed compared to the values sent by the target UE to the initiating UE in the ProSe Direct Link Setup Request message or the ProSe Direct Link Key Update Request message;
[0467] d) If the 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Setup procedure,
[0468] 1) Check that the received UE 5G ProSe Direct Signaling Security policy has not changed compared to the values sent by the target UE to the initiating UE in the ProSe Direct Link Setup Request message; and
[0469] 2) check that the K NRP-sess ID contained in the ProSe Direct Link Security Mode Command message is not set to the same values as those received from another UE in response to the ProSe Direct Link Establishment Request message by the target UE; and
[0470] e) if the 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Key Update procedure and the integrity protection algorithm currently used for the 5G ProSe Direct Link is different from the null integrity protection algorithm, check that the selected security algorithm IE in the ProSe Direct Link Security Mode Command message does not contain the null integrity protection algorithm.
[0471] If the target UE does not include the KNRP ID in the ProSe Direct Link Establishment Request message, the target UE includes a re-authentication indication in the ProSe Direct Link Key Update Request message, or the initiating UE has selected to derive:
[0472] a) a new K NRP If the direct communication is not between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE; the target UE shall derive K NRP As specified in 3GPP TS 33.536
[37] ;
[0473] b) a new K NRP If the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE and uses the security procedures on the user plane as specified in 3GPP TS 33.503
[34] , the target UE shall derive K NRP As specified in 3GPP TS 33.536
[37] ; or
[0474] c) a new K NR_ProSe If the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE and uses the security procedures on the control plane as specified in 3GPP TS 33.503
[34] , the target UE shall derive K NR_ProSe As specified in 3GPP TS 33.536
[37] ; and
[0475] The target UE shall select the 2 LSBs of the K NRP ID to ensure that the resulting K NRP ID will be unique in the target UE. The target UE shall derive the K NRP ID from the MSB of the received K NRPThe 2 LSBs of ID form K NRP ID, and shall be stored together with K NRP / K NR_ProSe ID. The complete K NRP ID.
[0476] NOTE 1: If the direct communication is not between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, K NRP ID holds the ID corresponding to K NRP If the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, K NRP ID holds the ID corresponding to K NRP (if security procedures on the user plane are used) or K NR_ProSe (if security procedures on the control plane are used).
[0477] If the GPI is included in the ProSe Direct Link Security Mode Command message and the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, the target UE shall derive the UP-PRUK from the GPI and obtain the UP-PRUK ID and derive K NRP from the UP-PRUK according to the security procedures on the user plane specified in 3GPP TS 33.503
[34] .
[0478] If the target UE accepts the ProSe Direct Link Security Mode Command message, the target UE shall create a ProSe Direct Link Security Mode Complete message. In this message, the target UE:
[0479] a) If the 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Establishment procedure:
[0480] 1) If the 5G ProSe Direct Link is not used for 5G ProSe Direct Communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, PQFI and corresponding PC5 QoS parameters can be included;
[0481] 2) If the 5G ProSe Direct Link is used for 5G ProSe Direct Communication between a 5G ProSe Layer-3 Remote UE and a 5G ProSe Layer-3 UE-to-Network Relay UE, PQFI and corresponding PC5 QoS parameters can be included;
[0482] NOTE 2: If 5G ProSe Direct Link is used for 5G ProSe Layer 2 Remote UE to 5G ProSe Layer 2 UE-to-Network Relay UE 5G ProSe Direct Communication, PQFI and corresponding PC5 QoS parameters are not included.
[0483] b) If IP communication is used and the 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Setup procedure, the IP Address Configuration IE is included with the IP Address set to one of the following values:
[0484] 1) "IPv6 Router" with the condition that only IPv6 address allocation mechanisms are supported by the target UE, i.e. acting as an IPv6 Router;
[0485] 2) "DHCPv4 Server" with the condition that only IPv4 address allocation mechanisms are supported by the target UE, i.e. acting as a DHCPv4 Server;
[0486] 3) "DHCPv4 Server and IPv6 Router" with the condition that both IPv4 and IPv6 address allocation mechanisms are supported by the target UE; or
[0487] 4) "Address Allocation not supported" with the condition that neither IPv4 nor IPv6 address allocation mechanisms are supported by the target UE;
[0488] NOTE 3: If the communication uses Ethernet or Unstructured Data Unit Type, the UE does not include the IP Address Configuration IE nor the Link-Local IPv6 Address IE.
[0489] c) If IP communication is used, the IP Address Configuration IE is set to "Address Allocation not supported" and the 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Setup procedure, the Link-Local IPv6 Address IE is included with the link-local IPv6 address formed locally based on IETF RFC 4862
[25] ;
[0490] d) If a new K NRP is derived or a new K NRP is received or K NR_ProSe is refreshed, the 2 LSBs of K NRP ID are included; and
[0491] e) If the 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Setup procedure, the target UE includes its UE 5G ProSe Direct User Plane Security Policy for this 5G ProSe Direct Link. In case different ProSe Services are mapped to different 5G ProSe Direct User Plane Security Policies, when more than one ProSe Identifier is included in the ProSe Direct Link Setup Request message, each User Plane Security Policy of those ProSe Services will be compatible, e.g. "No User Plane Integrity Protection Required" and "User Plane Integrity Protection Required" are not compatible.
[0492] If the selected integrity protection algorithm is not the NULL integrity protection algorithm, the target UE shall derive K NRP-sess ID from the MSB of the target UE's ID and K NRP-sess ID received in the ProSe Direct Link Security Mode Command message. NRP-sess ID. The target UE shall use K NRP-sess ID to identify the new security context.
[0493] After generating the ProSe Direct Link Security Mode Complete message, the target UE passes this message to lower layers for transmission along with the following: the target UE's Layer 2 ID for 5G ProSe Direct Communication and the initiating UE's Layer 2 ID for 5G ProSe Direct Communication, NRPIK (or K relay-int , if applicable), NRPEK (or K relay-enc , if applicable) (if applicable), K NRP-sess ID, the selected security algorithms as specified in 3GPP TS 33.536
[37] , and an indication of the activation of 5G ProSe Direct Signaling Security Protection for the 5G ProSe Direct Link with the new security context (if applicable).
[0494] NOTE 4: The ProSe Direct Link Security Mode Complete message and other 5G ProSe Direct Signaling messages are integrity protected and encrypted (if applicable) at lower layers using the new security context.
[0495] If the 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Key Update procedure, the target UE shall provide the lower layers with an indication of activation of the 5G ProSe Direct User Plane Security Protection for the 5G ProSe Direct Link with the new security context (if applicable) along with the Layer-2 ID of the initiating UE for 5G ProSe Direct Communication and the Layer-2 ID of the target UE for 5G ProSe Direct Communication.
[0496] 7.2.10.4 Completion of the 5G ProSe Direct Link Security Mode Control procedure by the initiating UE
[0497] Upon receiving the ProSe Direct Link Security Mode Complete message, the initiating UE shall stop timer T5089. If the selected integrity protection algorithm is not the NULL integrity protection algorithm, the UE checks the integrity of the ProSe Direct Link Security Mode Complete message. If the integrity check passes, the initiating UE shall then proceed to trigger the procedures of the 5G ProSe Direct Link Security Mode Control procedure. If the selected integrity protection algorithm is the NULL integrity protection algorithm, the UE proceeds with the procedure without checking the integrity protection.
[0498] Upon receiving the ProSe Direct Link Security Mode Complete message, the initiating UE shall delete the old security context (if present) it has for the target UE.
[0499] 7.2.10.5 5G ProSe Direct Link Security Mode Control procedure not accepted by the target UE
[0500] If the ProSe Direct Link Security Mode Command message cannot be accepted, the target UE shall send the ProSe Direct Link Security Mode Reject message and the target UE shall abort the ongoing procedure of the initiation of the 5G ProSe Direct Link Security Mode Control procedure, unless the ongoing procedure is the 5G ProSe Direct Link Establishment procedure and the target user information is not included in the ProSe Direct Link Establishment Request message. The ProSe Direct Link Security Mode Reject message contains the PC5 Signaling Protocol Cause IE indicating one of the following cause values:
[0501] #5: Lack of resources for 5G ProSe Direct Link;
[0502] #7: Integrity failure;
[0503] #8: UE security capability mismatch;
[0504] #9: K NRP-sess ID LSB conflict;
[0505] #10: UE PC5 unicast signaling security policy mismatch;
[0506] #14: Authentication synchronization error; or
[0507] #111: Unspecified protocol error.
[0508] If this 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Setup procedure and the established implementation- specific maximum number of NR 5G ProSe Direct Links has been reached, the target UE shall send a ProSe Direct Link Security Mode Reject message containing the PC5 Signaling Protocol Cause value #5 "Lack of resources for 5G ProSe Direct Link".
[0509] If the ProSe Direct Link Security Mode Command message cannot be accepted because the 5G ProSe Direct Link Security Mode Control procedure was triggered during the 5G ProSe Direct Link Setup procedure, the selected security algorithms IE in the ProSe Direct Link Security Mode Command message contains the null integrity protection algorithm, and the 5G ProSe Direct Signaling Integrity Protection policy of the target UE is set to "Signaling integrity protection required", the target UE shall include the PC5 Signaling Protocol Cause #10 "UE PC5 unicast signaling security policy mismatch" in the ProSe Direct Link Security Mode Reject message.
[0510] If the ProSe Direct Link Security Mode Command message cannot be accepted because the 5G ProSe Direct Link Security Mode Control procedure was triggered during the 5G ProSe Direct Link Key Update procedure, the integrity protection algorithm currently used for the 5G ProSe Direct Link is different from the null integrity protection algorithm, and the selected security algorithms IE in the ProSe Direct Link Security Mode Command message contains the null integrity protection algorithm, the target UE shall include the PC5 Signaling Protocol Cause #10 "UE PC5 unicast signaling security policy mismatch" in the ProSe Direct Link Security Mode Reject message.
[0511] If the target UE detects that the UE security capabilities IE received in the ProSe Direct Link Security Mode Command message has changed compared to the most recent value sent by the target UE to the initiating UE in the ProSe Direct Link Setup Request message or the ProSe Direct Link Key Update Request message, the target UE shall include the PC5 Signaling Protocol Cause #8 "UE security capabilities mismatch" in the ProSe Direct Link Security Mode Reject message.
[0512] If the target UE detects that the K NRP-sessID's LSBs are set to the same values as those received from another UE in response to the target UE's ProSe Direct Link Setup Request message, the target UE will include PC5 Signaling Protocol Cause #9 "K NRP- sess ID's LSBs conflict".
[0513] If the 5G ProSe Direct Link Security Mode Control procedure is for direct communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, and the ProSe Direct Link Security Mode Command message cannot be accepted due to a synchronization error in processing the authentication vector (if present) contained in the GPI sent by the 5G ProSe UE-to-Network Relay UE to the 5G ProSe Remote UE, the target UE will include PC5 Signaling Protocol Cause #14 "Authentication Synchronization Error" in the ProSe Direct Link Security Mode Reject message, and will include the RAND and AUTS parameters in the ProSe Direct Link Security Mode Reject message.
[0514] After generating the ProSe Direct Link Security Mode Reject message, the target UE will pass this message to the lower layers for transmission along with the Layer-2 ID of the initiating UE for 5G ProSe Direct Communication and the Layer-2 ID of the target UE for 5G ProSe Direct Communication.
[0515] Upon receiving the ProSe Direct Link Security Mode Reject message, the initiating UE will stop timer T5089, provide an indication to the lower layers to deactivate the 5G ProSe Direct Security Protection and delete the security context for 5G ProSe Direct Link (if applicable), and:
[0516] a) if the PC5 Signaling Protocol Cause IE in the ProSe Direct Link Security Mode Reject message is set to #9 "K NRP-sess ID's LSBs conflict", retransmit the ProSe Direct Link Security Mode Command message with K NRP-sess ID's LSBs having different values, and restart timer T5089;
[0517] b) If the PC5 Signaling Protocol Cause IE in the ProSe Direct Link Security Mode Reject message is set to #14 "Authentication Synchronization Error", the message contains RAND and AUTS, and the 5G ProSe Direct Link Security Mode Control procedure is for direct communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-Network Relay UE, then a fresh GPI can be extracted from the PKMF by sending a Key Request message containing RAND and AUTS as specified in 3GPP TS 33.503
[34] ; or
[0518] c) If the PC5 Signaling Protocol Cause IE is set to a value other than #9 "K NRP-sess ID LSB collision" and other than #14 "Authentication Synchronization Error", then abort the ongoing procedure that triggered the initiation of the 5G ProSe Direct Link Security Mode Control procedure.
[0519] […]
[0520] 8.2.10.2.3 5G ProSe Remote User Key Request procedure
[0521] 8.2.10.2.3.1 Overview
[0522] The purpose of the 5G ProSe Remote User Key Request procedure is for a UE authorized to act as a 5G ProSe Remote UE to obtain a UP-PRUK and a UP-PRUK ID.
[0523] […]
[0524] 8.2.10.2.4 Key Request procedure
[0525] 8.2.10.2.4.1 Overview
[0526] The purpose of the Key Request procedure is for a UE acting as a 5G ProSe UE-to-Network Relay to obtain security parameters needed to establish a 5G ProSe Direct Link with a 5G ProSe Remote UE.
[0527] 8.2.10.2.4.2 Key Request procedure initiation
[0528] A UE shall initiate the Key Request procedure:
[0529] a) when the UE acting as a 5G ProSe UE-to-Network Relay for a relay service code receives a request from a 5G ProSe Remote UE to establish a 5G ProSe Direct Link; and
[0530] b) when the 5G ProSe Direct Link Security Mode Control procedure is rejected by a 5G ProSe Remote UE due to an authentication synchronization error.
[0531] The UE will send a message with <key-request>The PROSE_KEY_REQUEST message is sent by an element to initiate the key request procedure. In <key-request>Among the elements, UE:
[0532] a) shall contain the new transaction ID;
[0533] b) shall contain the Relay Service Code in which the establishment of the 5G ProSe Direct Link is requested;
[0534] c) shall contain the SUCI or UP-PRUK ID of the 5G ProSe Remote UE received from the 5G ProSe Remote UE;
[0535] d) shall contain the K NRP freshness parameter 1;
[0536] e) shall contain the PLMN identity of the HPLMN of the 5G ProSe Remote UE if received from the 5G ProSe Remote UE; and
[0537] f) shall contain the AUTS and RAND received from the 5G ProSe Remote UE if the Key Request procedure is initiated after the 5G ProSe Direct Link Security Mode Control procedure is rejected by the 5G ProSe Remote UE due to authentication synchronization error.
[0538] Figure 8 .2.10.2.4.2.1 Illustration of the interaction between the UE and the 5G PKMF in the Key Request procedure.
[0539] [3GPP TS 24.554 V18.2.0, Name of clause: "Key Request procedure"] Figure 8 .2.10.2.4.2.1 Reproduction of Figure 10 ]
[0540] 8.2.10.2.4.3 Key Request procedure accepted by the 5G PKMF
[0541] Upon receiving a Key Request message with <key-request>If the element receives a PROSE_KEY_REQUEST message:
[0542] a) over a TLS tunnel established by the UE authorized to act as a 5G ProSe UE-to-Network Relay for the relay service code in the PROSE_KEY_REQUEST message; and
[0543] b) the 5G ProSe Remote UE indicated in the PROSE_KEY_REQUEST message to provide a SUCI, UP-PRUK ID, or AUTS and the PLMN identity of the HPLMN of the 5G ProSe Remote UE (if present) is authorized to act as a 5G ProSe Remote UE for the relay service code indicated in the PROSE_KEY_REQUEST message;
[0544] The 5G PKMF will send a message containing <key-accept>The PROSE KEY RESPONSE message of an element. In <key-accept>In the element, 5G PKMF:
[0545] a) the transaction ID containing the value set to the transaction ID received in the PROSE KEY REQUEST message;
[0546] b) the UP-PRUK ID of the 5G ProSe Remote UE;
[0547] c) the K NRP ;
[0548] d) the K NRP freshness parameter 2; and
[0549] e) the GBA push information (GPI) if the AUTS and RAND are contained in the PROSE KEY REQUEST message or a new UP-PRUK is needed.
[0550] If the 5G ProSe Remote UE is served by another 5G PKMF, the 5G PKMF of the 5G ProSe UE-to-Network Relay requests the 5G PKMF of the 5G ProSe Remote UE to check that the SUCI, the UP-PRUK ID or the AUTS provided by the 5G ProSe Remote UE indicated in the PROSE KEY REQUEST message and the PLMN identity of the HPLMN of the 5G ProSe Remote UE (if present) are authorized to act as the 5G ProSe Remote UE for the relay service code indicated in the PROSE KEY REQUEST message and to provide the UP-PRUK ID of the 5G ProSe Remote UE, the K NRP , the K NRP freshness parameter 2 and optionally the GBA push information (GPI).
[0551] 8.2.10.2.4.4 Completion of the key request procedure by the UE
[0552] Upon reception of the PROSE KEY RESPONSE message with the <key accept> element, if the transaction ID contained in the <key accept> element matches the value sent by the UE in the PROSE KEY REQUEST message with the <KEY REQUEST> element, the UE will use the UP-PRUK ID of the 5G ProSe Remote UE, the K NRP , the K NRP freshness parameter 2 and the GBA push information (GPI) if received, in the 5G ProSe Direct Link establishment.
[0553] 8.2.10.2.4.5 Key request procedure not accepted by 5G PKMF
[0554] If the 5G PKMF cannot accept the key request with <key-request>If the element is a PROSE_KEY_REQUEST message, the 5GPKMF shall send a <key-reject>The PROSE KEY RESPONSE message of the element. In <key-reject>Among the elements, the 5G PKMF will include a transaction ID set to the value of the transaction ID received in the PROSE KEY REQUEST message and will include the appropriate PC8 control protocol cause value.
[0555] NOTE: When, for example, the UP-PRUK is not found in the network, the 5G PKMF decides to reject the PROSE KEY REQUEST message.
[0556] Upon receiving the PROSE KEY RESPONSE message with the <key_reject> element, if the transaction ID included in the <key_reject> element matches the value sent by the UE in the PROSE KEY REQUEST message with the <KEY REQUEST> element, the UE shall consider the key request procedure as rejected.
[0557] 8.2.10.2.4.6 Exceptional cases in the UE
[0558] The following exceptional cases can be identified:
[0559] a) The transport layer indicates that the delivery of the PROSE KEY REQUEST message failed (e.g. after TCP retransmission timeout)
[0560] The UE shall close the existing secure connection with the 5G PKMF, establish a new secure connection and then restart the key request procedure.
[0561] b) The 5G PKMF is unresponsive after the PROSE KEY REQUEST message has been successfully delivered (e.g. a TCP ACK has been received for the PROSE KEY REQUEST message)
[0562] The UE shall retransmit the PROSE KEY REQUEST message.
[0563] NOTE: The timer that triggers the retransmission and the maximum number of allowed retransmissions are UE implementation specific.
[0564] 8.2.10.2.4.7 Exceptional cases in the 5G PKMF
[0565] The following exceptional cases can be identified:
[0566] a) Indication from the lower layers that the delivery of the PROSE KEY RESPONSE message failed
[0567] Upon receiving an indication from the lower layers that the PROSE KEY RESPONSE message has not been successfully acknowledged (e.g. a TCP ACK has not been received), the 5G PKMF shall abort the procedure.
[0568] 3GPP TS 33.503 introduces the following concepts:
[0569] 6.3.3.2.2 PC5 security establishment for 5G ProSe UE-to-Network Relay communication over the user plane
[0570] [Name of 3GPP TS 33.503 V18.0.0 is "PC5 Security Establishment Procedure for 5G ProSe UE-to-Network Relay Communication over the User Plane"] Figure 6 .3.3.2.2-1 is reproduced as Figure 11 ]
[0571] […]
[0572] 4a. The 5G ProSe UE-to-Network Relay sends to its 5G PKMF a Key Request message containing the UP-PRUK ID or SUCI, RSC, and K NRP freshness parameter 1. If the HPLMN ID of the 5G ProSe Remote UE is included in the DCR, the Key Request message shall also contain said HPLMN ID.
[0573] […]
[0574] 4e. The 5G PKMF of the 5G ProSe UE-to-Network Relay sends to the 5G ProSe UE-to-Network Relay a Key Response message containing the Remote User ID, K NRP , K NRP freshness parameter 2, GPI (if used) to compute a fresh UP-PRUK for the UE-to-Network Relay.
[0575] 5a. The 5G ProSe UE-to-Network Relay shall derive the session key (K NRP ) from K NRP-SESS , then derive the confidentiality key (NRPEK) and the integrity key (NRPIK) based on the PC5 security policy, if applicable, as specified in TS 33.536 [6]. The 5G ProSe UE-to-Network Relay shall store the Remote User ID received in step 4d. The establishment of KNRP ID and KNRP-sess ID is as specified in TS 33.536 [6]. The 5G ProSe UE-to-Network Relay sends to the 5G ProSe Remote UE a Direct Security Mode Command message. This message shall also contain K NRP freshness parameter 2, and shall be protected as specified in TS 33.536 [6].
[0576] […]
[0577] 5c. The 5G ProSe Remote UE responds with a Direct Security Mode Complete message to the 5G ProSe UE-to-Network Relay as specified in TS 33.536 [6].
[0578] […]
[0579] 6.6.3.1 Network-Assisted Security for 5G ProSe PC5 Communication for 5G ProSe Layer-3 Inter-UE Relay
[0580] The User Plane (UP) based procedures as specified in section 6.3.3.2 and the Control Plane (CP) based procedures as specified in section 6.3.3.3 are used to provide authentication, authorization and security establishment between the 5G ProSe Layer-3 Inter-UE Relay and the Source UE with the following modifications:
[0581] - The Remote UE is replaced by the Source UE.
[0582] - The UE-to-Network Relay is replaced by the Inter-UE Relay.
[0583] The User Plane (UP) based procedures as specified in section 6.3.3.2 and the Control Plane (CP) based procedures as specified in section 6.3.3.3 are used to provide authentication, authorization and security establishment between the 5G ProSe Layer-3 Inter-UE Relay and the Target UE with the following modifications:
[0584] - The Remote UE is replaced by the Target UE.
[0585] - The UE-to-Network Relay is replaced by the Inter-UE Relay.
[0586] - The procedures are initiated after the successful completion of the security establishment between the 5G ProSe Layer-3 Inter-UE Relay and the Source UE as specified in section 6.7 of TS 23.304 [8].
[0587] - Steps 4-5d in section 6.3.3.2.2 and step 3-16 in section 6.3.3.3.2 are not triggered by a Direct Communication Request (DCR) message sent by the inter-UE relay. Upon receiving the DCR message from the inter-UE relay containing the RSC and if the network assisted security indicator associated with the RSC indicates that a network assisted security procedure is required to trigger the second hop PC5 link security establishment, the target end UE will inform the inter-UE relay to initiate the above steps with a Direct Communication Security Request and a Direct Communication Security Accept using messages. The Direct Communication Security Request message will contain the SUCI or UP-PRUK / CP-PRUK ID of the target end UE, the relay service code and the freshness_parameter_1. Upon receiving the Direct Communication Security Request message, the inter-UE relay needs to ensure that it is in network coverage before initiating the security procedure.
[0588] - The Direct Communication Request sent by the inter-UE relay to the target end UE does not contain the PRUK-ID, therefore, the security mechanism in section 6.3.5 is modified to protect only the RSC by modifying Annex A.7 to generate a key stream of the length of the RSC.
[0589] - The Direct Communication Security Request message is protected by reusing the protection method defined in section 6.3.5.
[0590] Figure 6 .6.3.1-1 shows the high level procedure for the second hop PC5 link security between a 5G ProSe layer 3 inter-UE relay and a target end UE.
[0591] [3GPP TS 33.503 V18.0.0, Name: "PC5 Security Establishment Procedures between a 5G ProSe Inter-UE Relay and a Target 5G ProSe End UE", clause 8a.2.x] Figure 6 .6.3.1-1 is reproduced as Figure 12 ]
[0592] 3GPP C1-238124 introduced the following concepts:
[0593] 8a.2.x 5G ProSe Inter-UE Relay Direct Link Security Establishment Procedure
[0594] 8a.2.x.1 Overview
[0595] The purpose of the 5G ProSe Inter-UE Relay Direct Link Security Establishment Procedure is to enable the target 5G ProSe end UE to establish security between the 5G ProSe Inter-UE Relay UE and the target 5G ProSe end UE.
[0596] When the target 5G ProSe end UE receives the ProSe Direct Link Setup Request message from the 5G ProSe Inter-UE Relay UE and the network assisted security indicator associated with the received Relay Service Code indicates that a network assisted security procedure is required, the procedure is triggered.
[0597] 8a.2.x.2. Initiation of the 5G ProSe Inter-UE Relay Direct Link Security Setup procedure by the initiating UE
[0598] The following preconditions shall be fulfilled by the initiating UE before initiating this procedure:
[0599] a) receives the ProSe Direct Link Setup Request message;
[0600] b) the initiating UE acting as a target 5G ProSe end UE is authorized to use a 5G ProSe Inter-UE Relay UE in the registered PLMN or local PLMN;
[0601] c) the network assisted security indicator associated with the received Relay Service Code indicates that a network assisted security procedure is required.
[0602] The UE shall initiate the 5G ProSe Inter-UE Relay Direct Link Security Setup procedure by sending the ProSe Direct Link Security Setup Request message. The initiating UE:
[0603] a) shall include:
[0604] 1) Nonce_1, if a security procedure on the control plane is used as specified in 3GPP TS 33.503
[34] ; or
[0605] 2) K NRP freshness parameter 1, if a security procedure on the user plane is used as specified in 3GPP TS 33.503
[34] ;
[0606] a 128-bit random number value generated by the initiating UE for the purpose of session key establishment on this 5G ProSe Direct Link, if the UE PC5 unicast signaling integrity protection policy is set to "signaling integrity protection required" or "signaling integrity protection preferred";
[0607] b) shall include its UE security capabilities indicating a list of algorithms supported by the initiating UE for security setup for this 5G ProSe Direct Link;
[0608] c) if the UE PC5 unicast signaling integrity protection policy is set to "signaling integrity protection required" or "signaling integrity protection preferred", include the K NRP-sess ID MSB;
[0609] d) include its UE PC5 unicast signaling security policy. The signaling integrity protection policy shall be set to "signaling integrity protection required";
[0610] e) include the Relay Service Code IE set to the Relay Service Code indicating the connectivity service requested by the source 5G ProSe End UE;
[0611] f) include the UTC-based counter LSB containing the four least significant bits of the UTC-based counter set to:
[0612] g) include the UE Identity IE set to the SUCI of the initiating UE in the following cases:
[0613] 1) the 5G ProSe Direct Link Setup procedure is for direct communication between the target 5G ProSe End UE and a 5G ProSe Inter-UE Relay UE; and
[0614] 2) the security for 5G ProSe Inter-UE Relay uses a security procedure on the control plane and the initiating UE does not have a valid CP-PRUK as specified in 3GPP TS 33.503
[34] , or the security for 5G ProSe Inter-UE Relay uses a security procedure on the user plane and the initiating UE does not have a valid UP-PRUK as specified in 3GPP TS 33.503
[34] ;
[0615] h) include the User Security Key ID IE set to:
[0616] 1) the UP-PRUK ID of the initiating UE, provided that:
[0617] i) the 5G ProSe Direct Link Setup procedure is for direct communication between the target 5G ProSe End UE and a 5G ProSe Inter-UE Relay UE;
[0618] ii) the initiating UE has a valid UP-PRUK; and
[0619] iii) the security for 5G ProSe Inter-UE Relay uses a security procedure on the user plane as specified in 3GPP TS 33.503
[34] ; or
[0620] 2) CP-PRUK ID of the Initiating UE associated with the Relay Service Code of the Target UE, conditional on:
[0621] i) the 5G ProSe Direct Link Setup procedure is used for direct communication between the Target 5G ProSe End UE and the 5G ProSe Inter-UE Relay UE;
[0622] ii) the Initiating UE has a valid CP-PRUK associated with the Relay Service Code of the Target UE; and
[0623] iii) the security for 5G ProSe Inter-UE Relay uses security procedures on the control plane as specified in 3GPP TS 33.503
[34] ;
[0624] i) the HPLMN ID of the Initiating UE is included if the UP-PRUK ID of the Initiating UE is included and it is not in NAI format (see 3GPP TS 33.503
[34] );
[0625] j) the MIC IE set to the computed MIC value as specified in 3GPP TS 33.503
[34] is included if the 5G ProSe Inter-UE Relay UE and the Target 5G ProSe End UE have a DUIK.
[0626] Editor’s Note: How to set the Layer 2 ID of the ProSe Direct Link Setup Request message is FFS.
[0627] Editor’s Note: The retransmission timer of the ProSe Direct Link Security Setup Request message is FFS.
[0628] [3GPP C1-238124, “5G ProSe Direct Link Security Setup Procedure” Figure 8 a.2.x.2.1 is reproduced as Figure 13 ]
[0629] 8a.2.x.3 5G ProSe Inter-UE Relay Direct Link Security Setup Procedure Accepted by the Target UE
[0630] Upon receiving the ProSe Direct Link Security Setup Request message, the Target UE shall verify the MIC field in the received ProSe Direct Link Security Setup Request with the DUIK (if present) and decrypt the encrypted:
[0631] a) Relay Service Code; and
[0632] b) UP-PRUK ID or CP-PRUK ID (if received),
[0633] The DUCK or DUSK has an associated encrypted bit-mask for 5G ProSe inter-UE relay discovery (see section 6.6.3.1 of 3GPP TS 33.503
[34] ) and the target UE verifies that the relay service code matches the code sent by the target UE in the ProSe Direct Link Setup Request message.
[0634] NOTE 1: If the UE is neither configured to use DUCK nor DUSK, the relay service code and UP-PRUK ID or CP-PRUK ID are not encrypted.
[0635] If the target UE is authorized to act as a 5G ProSe inter-UE relay UE and is within NG-RAN coverage, the target UE proceeds with:
[0636] a) an authentication and key agreement procedure as specified in section 5.5.4 of 3GPP TS 24.501
[11] with the condition that the security procedures on the control plane as specified in 3GPP TS 33.503
[34] are used; or
[0637] b) a key request procedure as specified in section 8.2.10.2.4 with the condition that the security procedures on the user plane as specified in 3GPP TS 33.503
[34] are used;
[0638] and initiates the 5G ProSe direct link security mode control procedure as specified in section 7.2.10.
[0639] The target UE shall:
[0640] a) request a new K NR_ProSe according to the security procedures on the user plane as specified in 3GPP TS 33.503
[34] if the security procedures on the control plane as specified in 3GPP TS 33.503
[34] are used; or
[0641] b) request a new K NRP according to the security procedures on the user plane if the security procedures on the user plane as specified in 3GPP TS 33.503
[34] are used.
[0642] NOTE 2: How many times the 5G ProSe direct link authentication procedure needs to be performed to derive a new K NRP depends on the authentication method used.
[0643] After deriving a new K NRP or upon reception of a new K NRP or K NR_ProSe After that, the target UE shall initiate the 5G ProSe Direct Link Security Mode Control procedure as specified in clause 7.2.10. The target UE determines whether the ProSe Direct Link Security Establishment Request message can be accepted based on the result of the 5G ProSe Direct Link Security Mode Control procedure.
[0644] If the target UE accepts the 5G ProSe Direct Link Security Establishment procedure, the target UE shall create a ProSe Direct Link Security Establishment Accept message and pass the message to lower layers for transmission along with the Layer 2 ID of the initiating UE for unicast communication and the Layer 2 ID of the target UE for unicast communication.
[0645] Editor's Note: The content of the ProSe Direct Link Security Establishment Accept message is subject to further study.
[0646] 8a.2.x.4 Completion of the 5G ProSe Inter-UE Relay Direct Link Security Establishment procedure by the initiating UE
[0647] For each received ProSe Direct Link Security Establishment Accept message, the initiating UE shall create a ProSe Direct Link Establishment Accept message as specified in clause 7.2.2.4.
[0648] 8a.2.x.5 5G ProSe Inter-UE Relay Direct Link Security Establishment procedure not accepted by the target UE
[0649] If the ProSe Direct Link Security Establishment Request message cannot be accepted, the target UE shall send a ProSe Direct Link Security Establishment Reject message. The ProSe Direct Link Security Establishment Reject message contains the PC5 Signaling Protocol Cause IE set to one of the following cause values:
[0650] #6 Authentication failure
[0651] #7 Integrity failure;
[0652] #13 Congestion situation;
[0653] #15 Security procedure of 5G ProSe Inter-UE Relay failed;
[0654] #111 Unspecified protocol error. If the target UE acting as a 5G ProSe Inter-UE Relay UE is in a congestion state, the target UE shall send a ProSe Direct Link Security Establishment Reject message containing the PC5 Signaling Protocol Cause value #13 "Congestion situation". The target UE can provide a fallback timer value to the initiating UE in the ProSe Direct Link Security Establishment Reject message.
[0655] If the 5G ProSe Direct Link Security Establishment procedure fails due to failure of the security procedure on the control plane or the security procedure on the user plane as specified in 3GPP TS 33.503
[34] , the target UE shall send a ProSe Direct Link Security Establishment Reject message containing the PC5 Signaling Protocol Cause value #15 "Security procedure failure for 5G ProSe Inter-UE Relay". If an EAP message is received from the network according to the security procedure on the control plane as specified in 3GPP TS 33.503
[34] , the target UE shall provide the EAP message.
[0656] If the 5G ProSe Direct Link Security Establishment procedure fails for other reasons, the target UE shall send a ProSe Direct Link Security Establishment Reject message containing the PC5 Signaling Protocol Cause value #111 "Unspecified protocol error".
[0657] After sending the ProSe Direct Link Security Establishment Reject message, the target UE shall provide the following information to lower layers as well as the Layer-2 ID of the initiating UE for unicast communication and the Layer-2 ID of the target UE for unicast communication:
[0658] a) Deactivation of PC5 unicast security protection and indication of deletion of the security context for 5G ProSe Direct Link (if applicable).
[0659] After receiving the ProSe Direct Link Security Establishment Reject message, the initiating UE shall provide the following information to lower layers as well as the Layer-2 ID of the initiating UE for unicast communication and the Layer-2 ID of the target UE for unicast communication:
[0660] a) Deactivation of PC5 unicast security protection and indication of deletion of the security context for 5G ProSe Direct Link (if applicable).
[0661] […]
[0662] According to 3GPP TS 23.304, a UE can perform a PC5 unicast link establishment procedure (e.g., layer 2 link establishment) with a peer UE for establishing a layer 2 link or unicast link between the two UEs. Basically, the layer 2 identity / identifier (ID) of the peer UE identified by the application layer ID of the peer UE can be discovered during the establishment of the PC5 unicast link via discovery message or known from a prior sidelink communication, e.g., an existing or prior unicast link to the same application layer ID, or obtained from an application layer service announcement. The initial signaling for establishing the PC5 unicast link (i.e., direct communication request) can use the known layer 2 ID of the peer UE or a pre-set destination layer 2 ID associated with a Proximity-based Service (ProSe) service / application configured for PC5 unicast link establishment. During the PC5 unicast link establishment procedure, the layer 2 IDs of the two UEs are exchanged and used for future communication between the two UEs. In addition, according to 3GPP TS 24.554, the two UEs will exchange security information with each other during the PC5 unicast link establishment, such that the two UEs use the negotiated security context (including security algorithms and / or keys) to protect the content of traffic (including, e.g., PC5-S signaling, PC5-RRC signaling, and / or PC5 user plane data) sent on the PC5 unicast link.
[0663] According to 3GPP TS 23.304, inter-UE relay is supported in sidelink communication, which means that in case two UEs (e.g., source UE / UE1 and target UE / UE2) cannot directly communicate with each other, a relay UE can be used to support data communication between the two UEs. The inter-UE relay communication can include a first hop direct link established between UE1 and the relay UE and a second hop direct link established between the relay UE and UE2.
[0664] To support security in inter-UE (U2U) relay communication, network-assisted security for 5G ProSe PC5 communication for 5G ProSe layer 3 inter-UE relay is introduced in Section 6.6.3.1 of 3GPP TS 33.503, and network-unassisted security for 5G ProSe PC5 communication for 5G ProSe layer 3 inter-UE relay is introduced in Section 6.6.3.2 of 3GPP TS 33.503. It should be noted that the service flow without network assistance considers Section 6.7.1.1 of 3GPP TS 23.304 and Sections 7.2.2 and 7.2.10 of 3GPP TS 24.554, and can be demonstrated in Figure 14 Specifically, Figure 14 Exemplary step flows for network-assisted PC5 security establishment for U2U relay communication based on relevant standards are shown.
[0665] For service flows in case of network-assisted security in U2U relay communication, at least sections 7.2.2, 7.2.10, 8.2.10.2.3, and 8.2.10.2.4 of TS 3GPP 24.554 and sections 6.6.3.1 and 6.3.3.2.2 of 3GPP TS 33.503 are considered, and can be shown in Figure 15A
[0666] Figure 15A Details of each step in the service flow shown in
[0667] 1. The source UE (i.e., UE1) can perform a discovery procedure, then find a relay UE that can support U2U relay communication.
[0668] 2. UE1 can send a message to the network requesting a root security key for U2U relay communication with the relay UE. The message can be a ProSe Remote User Key Request message. UE1 can send the message to the network if UE1 is in network / cell coverage. UE1 can include an identifier of the valid root security key (i.e., UP-PRUK ID) in the message if UE1 has a valid root security key (i.e., UP-PRUK).
[0669] UE1 can receive a response message from the network if UE1 is in network / cell coverage. The message can be a ProSe Remote User Key Response message. The response message can include the requested root security key and the root security key ID (i.e., UP-PRUK ID).
[0670] The message and the corresponding response message can be sent by using IP transport (i.e., sent by using IP packets).
[0671] 3. UE1 can send a PC5-S message to the relay UE to establish the 1st hop direct link with the relay UE for U2U relay communication. The PC5-S message can be a Direct Communication Request message. If UE1 has a valid root security key, the PC5-S message can contain the root security key ID. Conversely, if UE1 does not have a valid root security key, the PC5-S message can contain the SUCI of UE1. Other parameters in the PC5-S message can refer to the relevant standards. The PC5-S message can trigger the relay UE to perform a key request procedure with the network if the relay service code contained in the PC5-S message is associated with information indicating that network assistance is needed for security establishment (e.g., network assistance security indicator).
[0672] The PC5-S message can be sent over the PC5 interface, i.e., the PC5-S message can be sent by using the layer 2 ID of UE1 as the source layer 2 ID and using the layer 2 ID of the relay UE as the destination layer 2 ID. It should be noted that the layer 2 ID of the relay UE can be learned by receiving a discovery message from the relay UE during a discovery procedure.
[0673] 4. In the key request procedure, the relay UE can send a message to the network to request an intermediate security key for U2U relay communication with UE1. The message can be a Key Request message. If the PC5-S message in step 3 contains a root security key ID, the root security key ID can be contained in the message. If the PC5-S message in step 3 contains a Subscription Concealed Identifier (SUCI), the SUCI can be contained in the message. Other parameters in the message can refer to the relevant standards.
[0674] The relay UE can receive a response message from the network. The response message can contain the intermediate security key (i.e., K NRP ) and other parameters specified in the relevant standards. If the message sent from the relay UE to the network contains a SUCI, the response message can also contain information (e.g., GPI) for UE1 to derive / determine / compute the intermediate security key. The information for UE1 to derive / determine / compute the intermediate security key can be forwarded to UE1.
[0675] The message and the corresponding response message can be sent by using IP transport.
[0676] 5. The relay UE can send a PC5-S message to UE1 to establish a security context on the 1st hop direct link. The PC5-S message can be a Security Mode Command message. The PC5-S message can contain information (e.g., GPI) for UE1 to derive / determine / compute a security key (if SUCI is contained in the PC5-S message in step 3).
[0677] The relay UE can receive a response PC5-S message from UE1 to complete the establishment of the security context. The response PC5-S message can be a Security Mode Complete message.
[0678] The PC5-S message and the corresponding response PC5-S message can be sent over the PC5 interface. The PC5-S message can be sent by using the layer 2 ID of UE1 as the destination layer 2 ID and using the layer 2 ID of the relay UE as the source layer 2 ID. The response PC5-S message can be sent by using the layer 2 ID of UE1 as the source layer 2 ID and using the layer 2 ID of the relay UE as the destination layer 2 ID.
[0679] 6. The relay UE can then send a PC5-S message to UE2 to establish the 2nd hop direct link for U2U relay communication. The PC5-S message can be a Direct Communication Request message. The relay service code can be contained in the PC5-S message and can be associated with information (e.g., network assisted security indicator) indicating that network assistance is needed for security establishment.
[0680] The PC5-S message can be sent over the PC5 interface. The PC5-S message can be sent by using the layer 2 ID of UE2 or a broadcast layer 2 ID as the destination layer 2 ID and using the layer 2 ID of the relay UE as the source layer 2 ID.
[0681] 7. UE2 can send a message to the network to request a root security key for U2U relay communication with the relay UE. The message can be a ProSe Remote UE Key Request message. UE2 can send the message to the network if UE2 is in network / cell coverage. UE2 can include an identifier of the valid root security key (i.e., UP-PRUK ID) in this message if UE2 has a valid root security key (i.e., UP-PRUK).
[0682] UE2 can receive a response message from the network if UE2 is in network / cell coverage. The response message can contain the requested root security key and the root security key ID (i.e., UP-PRUK ID). It should be noted that the root security key of UE1 and the root security key of UE2 can be the same or different.
[0683] The message and the corresponding response message can be sent by using IP transport (i.e., sent by using IP packets).
[0684] 8. UE2 can send a PC5-S message to the relay UE triggering the relay UE to perform a key request procedure with the network. The PC5-S message can be a Direct Communication Security Request message. If UE2 has a valid root security key (i.e., UP-PRUK), UE2 can include an identifier of the valid root security key (i.e., UP-PRUK ID) in the message; otherwise, UE2 can include the SUCI of UE2 in the message.
[0685] The PC5-S message can be sent over the PC5 interface. The PC5-S message can be sent by using the layer 2 ID of UE2 as the source layer 2 ID and using the layer 2 ID of the relay UE as the destination layer 2 ID.
[0686] 9. In the key request procedure, the relay UE can send a message to the network requesting an intermediate security key for the U2U relay communication with UE2. The message can be a Key Request message. If the PC5-S message in step 8 contains a root security key ID (i.e., UP-PRUK ID), the root security key ID can be included in the message. If the PC5-S message in step 8 contains a SUCI, the SUCI can be included in the message. Other parameters in the message can refer to relevant standards.
[0687] The relay UE can receive a response message from the network. The response message can contain an intermediate security key (i.e., K NRP ) used in the 2-hop direct link and other parameters specified in relevant standards. If the message sent from the relay UE to the network contains a SUCI, the response message can also contain information (e.g., GPI) for UE2 to derive / determine / compute the intermediate security key. The information for UE2 to derive / determine / compute the intermediate security key can be forwarded to UE2. It should be noted that the intermediate security key used in the 1-hop direct link and the intermediate security key used in the 2-hop direct link can be the same or different.
[0688] The message and the corresponding response message can be sent by using IP transport.
[0689] 10. The relay UE can send a PC5-S message to UE2 to establish a security context over the 2-hop direct link. The PC5-S message can be a Security Mode Command message. The PC5-S message can contain information for UE2 to derive / determine / compute the intermediate security key if the SUCI is included in the PC5-S message in step 8.
[0690] The relay UE can receive a response PC5-S message from UE1 completing establishment of the security context. The response PC5-S message can be a security mode complete message.
[0691] The PC5-S message and the corresponding response PC5-S message can be sent over the PC5 interface. The PC5-S message can be sent by using the layer 2 ID of UE2 as the destination layer 2 ID and using the layer 2 ID of the relay UE as the source layer 2 ID. The response PC5-S message can be sent by using the layer 2 ID of UE2 as the source layer 2 ID and using the layer 2 ID of the relay UE as the destination layer 2 ID.
[0692] 11. The relay UE can send a response PC5-S message to UE2 corresponding to the PC5-S message in step 8. The response PC5-S message can be a direct communication security accept message.
[0693] The response PC5-S message can be sent over the PC5 interface. The response PC5-S message can be sent by using the layer 2 ID of UE2 as the destination layer 2 ID and using the layer 2 ID of the relay UE as the source layer 2 ID.
[0694] 12. UE2 can send a PC5-S message to the relay UE completing establishment of the 2-hop direct link. The PC5-S message can be a direct communication accept message.
[0695] The PC5-S message can be sent over the PC5 interface. The PC5-S message can be sent by using the layer 2 ID of UE2 as the source layer 2 ID and using the layer 2 ID of the relay UE as the destination layer 2 ID.
[0696] 13. The relay UE can send a PC5-S message to UE1 completing establishment of the 1-hop direct link. The PC5-S message can be a direct communication accept message.
[0697] The PC5-S message can be sent over the PC5 interface. The PC5-S message can be sent by using the layer 2 ID of UE1 as the destination layer 2 ID and using the layer 2 ID of the relay UE as the source layer 2 ID.
[0698] During a key request procedure between the relay UE and the network for requesting an intermediate security key used in the 2-hop direct link, the time of receiving the key response message can exceed a period expected by the relay UE (due to, for example, poor network throughput). Thus, the key request procedure can be considered as failed. In this case, the relay UE can send a PC5-S reject message corresponding to the PC5-S message used to trigger the relay UE to perform the key request procedure. The PC5-S reject message can be a direct communication security reject message.
[0699] According to 3GPP TS 33.503, after sending the Direct Communication Security Reject message, the Relay UE only provides the lower layers with an indication of the deactivation of the PC5 unicast security protection and the deletion of the security context for 5G ProSe Direct Link. Similarly, after receiving the Direct Communication Security Reject message, UE2 performs the same actions as the Relay UE. The following actions on the Relay UE and UE2 are not clear. This case can be shown in Figure 15B
[0700] To avoid the above uncertainty, it can be better that UE2 responds to the Relay UE with a response message in response to the reception of the Direct Communication Security Reject message, so that the Relay UE can stop timer T5080 (to avoid further retransmission of the Direct Communication Request message). The response message can be a Direct Communication Reject message. The response message can correspond to the Direct Communication Request message sent from the Relay UE to UE2. It seems also feasible that, in response to receiving the Direct Communication Reject message from UE2, the Relay UE sends a Direct Communication Reject message (corresponding to the Direct Communication Request message sent from UE1 to the Relay UE) to UE1, because the network- assisted security establishment cannot be fulfilled. This concept can be shown as Option 1 in Figure 16 Figure 16 An example of a step flow for network- assisted unsuccessful PC5 security establishment for U2U relay communication based on the related standards is shown.
[0701] Alternatively, it is also feasible that the Relay UE and UE2 locally abort the 2nd hop direct link establishment procedure in terms of signaling overhead reduction, because the Direct Communication Security Reject message implies that the network- assisted security establishment cannot be fulfilled, and thus the U2U relay communication cannot be established. In this way, it can not be necessary for UE2 to send a Direct Communication Reject message to the Relay UE. This concept can be shown as Option 2 in Figure 16
[0702] If Option 2 is followed, it should be noted that in 3GPP TS 24.554 it is specified that the Relay UE does not take any action towards UE1. If this is the case, because UE1 can start timer T5080 upon sending the Direct Communication Request message to the Relay UE, timer T5080 can expire, and thus UE1 can re-send the Direct Communication Request message to the Relay UE, which can be unnecessary. This case (or problem) can be shown in Figure 17 It is displayed in the middle.
[0703] Therefore, it might be better for the relay UE to send a direct communication rejection message (corresponding to the direct communication request message sent from UE1 to the relay UE) to UE1 in response to the abort of the second-hop direct link establishment procedure (due to, for example, unmet network-assisted security establishment). This can be done in... Figure 18 Shown in Figure 18 The solution is shown Figure 17 The example solutions to the situations (or problems) shown in the document.
[0704] Direct communication rejection messages (sent from UE2 to the relay UE and / or from the relay UE to UE1) may contain a cause value or information indicating that network-assisted security establishment cannot be satisfied (for the relay service code indicated in the direct communication request message).
[0705] Since network-assisted security establishment cannot be achieved, in response to receiving a direct communication rejection message from the relay UE, UE1 can perform U2U relay reselection to find another relay UE for establishing U2U relay communication with UE2. U2U relay reselection can be a discovery procedure used to find one or more U2U relay UEs. If a new relay UE is found, the service flow can be re-initiated, such as... Figure 15A , Figure 16 and Figure 18 As shown in the image.
[0706] Figure 19 This is flowchart 1900 for a relay user equipment (UE). In step 1905, the relay UE receives a first direct communication request message from the source UE to establish inter-UE (U2U) relay communication with the target UE. In step 1910, the relay UE sends a second direct communication request message to the target UE in a direct link establishment procedure for establishing a direct link for U2U relay communication. In step 1915, the relay UE receives a direct communication security request message from the target UE that triggers the relay UE to execute a key request procedure with the network. In step 1920, if the key request procedure with the network fails, the relay UE sends a direct communication security denial message to the target UE. In step 1925, in response to the failure of the key request procedure, the relay UE aborts the direct link establishment procedure.
[0707] Return to reference Figure 3 and 4 In one example instance from the perspective of the relay UE, the relay UE 300 includes program code 312 stored in memory 310. CPU 308 can execute program code 312 to enable the relay UE to: (i) receive, from a source UE, a first direct communication request message to establish a U2U relay communication with a target UE; (ii) send, to the target UE, a second direct communication request message in a direct link establishment procedure to establish a direct link for the U2U relay communication; (iii) receive, from the target UE, a direct communication security request message that triggers the relay UE to perform a key request procedure with a network; (iv) send, to the target UE, a direct communication security rejection message if the key request procedure with the network fails; and (v) abort the direct link establishment procedure in response to the failure of the key request procedure. In addition, CPU 308 can execute program code 312 to perform all of the actions and steps described above or other actions and steps described herein.
[0708] Figure 20 is a flowchart 2000 for a relay user equipment (UE). In step 2005, the relay UE receives, from a source UE, a first direct communication request message to establish an inter-UE (U2U) relay communication with a target UE. In step 2010, the relay UE sends, to the target UE, a second direct communication request message in a direct link establishment procedure to establish a direct link for the U2U relay communication. In step 2015, the relay UE receives, from the target UE, a direct communication security request message that triggers the relay UE to perform a key request procedure with a network. In step 2020, the relay UE sends, to the target UE, a direct communication security rejection message if the key request procedure with the network fails. In step 2025, the relay UE aborts the direct link establishment procedure in response to sending the direct communication security rejection message.
[0709] Referring back to Figure 3 and 4 In one example from the perspective of the relay UE, the relay UE 300 includes program code 312 stored in memory 310. The CPU 308 can execute the program code 312 to enable the relay UE to: (i) receive, from a source UE, a first direct communication request message to establish a U2U relay communication with a target UE; (ii) send, to the target UE, a second direct communication request message in a direct link establishment procedure to establish a direct link for the U2U relay communication; (iii) receive, from the target UE, a direct communication security request message that triggers the relay UE to perform a key request procedure with a network; (iv) send, to the target UE, a direct communication security rejection message if the key request procedure with the network fails; and (v) abort the direct link establishment procedure in response to sending the direct communication security rejection message. In addition, the CPU 308 can execute the program code 312 to perform all of the actions and steps described above or other actions and steps described herein.
[0710] Figure 21 is a flowchart 2100 for a target user equipment (UE). In step 2105, the target UE receives, from a relay UE, a second direct communication request message, where the second direct communication request message is sent in a direct link establishment procedure to establish a direct link for inter-UE (U2U) relay communication. In step 2110, the target UE sends, to the relay UE, a direct communication security request message that triggers the relay UE to perform a key request procedure with a network. In step 2115, the target UE receives, from the relay UE, a direct communication security rejection message. In step 2120, the target UE aborts the direct link establishment procedure in response to receiving the direct communication security rejection message.
[0711] Referring back to Figure 3 and 4 In one example from the perspective of the target UE, the target UE 300 includes program code 312 stored in memory 310. The CPU 308 can execute the program code 312 to enable the target UE to: (i) receive, from a relay UE, a second direct communication request message, where the second direct communication request message is sent in a direct link establishment procedure to establish a direct link for U2U relay communication; (ii) send, to the relay UE, a direct communication security request message that triggers the relay UE to perform a key request procedure with a network; (iii) receive, from the relay UE, a direct communication security rejection message; and (iv) abort the direct link establishment procedure in response to receiving the direct communication security rejection message. In addition, the CPU 308 can execute the program code 312 to perform all of the actions and steps described above or other actions and steps described herein.
[0712] In Figure 19 , 20 In the context of the embodiments shown in FIGS. 21, in one embodiment, the relay UE can send a first direct communication rejection message to the source UE in response to aborting the direct link setup procedure. The relay UE can send the first direct communication rejection message to the source UE in response to a failure of the key request procedure.
[0713] In one embodiment, the first / second direct communication request message can contain at least one of user information of the source UE, user information of the relay UE, user information of the target UE, and a relay service code. The direct communication security request message can contain a SUCI, a UP-PRUK ID, and a K NRP The direct communication security rejection message can contain a cause value or information indicating a failure of the key request procedure. The first direct communication rejection message can contain a cause value or information indicating that a network- assisted security setup cannot be fulfilled. The user information can be an upper layer ID or an application layer ID.
[0714] More specifically, in one embodiment, the network can include one or more network nodes containing one of:
[0715] - a gNB or a base station;
[0716] - an AMF;
[0717] - a PKMF of the source UE;
[0718] - a PKMF of the target UE; and / or
[0719] - a PKMF of the relay UE.
[0720] More specifically, in one embodiment, the PKMF of the source UE and the PKMF of the relay UE can be the same. The PKMF of the target UE and the PKMF of the relay UE can be the same. The PKMF of the source UE and the PKMF of the target UE can be the same.
[0721] More specifically, in one embodiment, the direct link can be a layer 2 link, a unicast link, a PC5 link, a PC5 connection, a PC5-S connection, or a PC5-RRC connection. The ProSe Remote User Key Request message can be a PROSE PRUK REQUEST message. The ProSe Remote User Key Response message can be a PROSE PRUK RESPONSE message. The key request message can be a PROSE KEY REQUEST message. The key response message can be a PROSE KEY RESPONSE message.
[0722] Figure 22 is a flowchart 2200 for a relay user equipment (UE). In step 2205, the relay UE receives, from a source UE, a first direct communication request message to establish an inter-UE (U2U) relay communication with a target UE. In step 2210, the relay UE sends, to the target UE, a second direct communication request message in a direct link establishment procedure to establish a direct link supporting the U2U relay communication. In step 2215, the relay UE receives, from the target UE, a direct communication security request message triggering the relay UE to perform a key request procedure with a network. In step 2220, the relay UE sends, to the target UE, a direct communication security rejection message if the key request procedure with the network fails. In step 2225, the relay UE aborts the direct link establishment procedure after sending the direct communication security rejection message.
[0723] In the context of the embodiments shown in Figure 22 In the context of the embodiments shown in
[0724] In one embodiment, the first direct communication rejection message can correspond to the first direct communication request message.
[0725] In one embodiment, the second direct communication request message can contain at least a relay service code associated with a network assisted security indicator indicating a security procedure with network assistance is needed.
[0726] In one embodiment, the first / second direct communication request message can be a ProSe direct link establishment request message, the direct communication security request message can be a ProSe direct link security establishment request message, and / or the direct communication security rejection message can be a ProSe direct link security establishment rejection message. The first direct communication rejection message can be a ProSe direct link establishment rejection message.
[0727] Referring back to Figure 3 and 4 In one example instance from the perspective of the relay UE, the relay UE 300 includes program code 312 stored in memory 310. The CPU 308 can execute the program code 312 to enable the relay UE to: (i) receive, from a source UE, a first direct communication request message to establish a U2U relay communication with a target UE; (ii) send, to the target UE, a second direct communication request message in a direct link establishment procedure to establish a direct link that supports the U2U relay communication; (iii) receive, from the target UE, a direct communication security request message that triggers the relay UE to perform a key request procedure with the network; (iv) send, to the target UE, a direct communication security rejection message if the key request procedure with the network fails; and (v) abort the direct link establishment procedure after sending the direct communication security rejection message. In addition, the CPU 308 can execute the program code 312 to perform all of the actions and steps described above or other actions and steps described herein.
[0728] Various aspects of the disclosure have been described. It should be apparent that the teachings herein can be embodied in a wide variety of forms and that any specific structure, function, or both being disclosed herein is merely representative. Based on the teachings herein one skilled in the art should appreciate that an aspect disclosed herein can be implemented independently of any other aspects and that two or more aspects can be combined in various ways. For example, an apparatus can be implemented or a method can be practiced using any number of the aspects set forth herein. In addition, such an apparatus can be implemented or such a method can be practiced using other structure, functionality, or structure and functionality in addition to or other than one or more of the aspects set forth herein. As an example of some of the concepts discussed herein, in some aspects, parallel channels can be established based on a pulse repetition frequency. In some aspects, parallel channels can be established based on a pulse position or offset. In some aspects, parallel channels can be established based on a time hopping sequence. In some aspects, parallel channels can be established based on a pulse repetition frequency, a pulse position or offset, and a time hopping sequence.
[0729] Those skilled in the art will appreciate that information and signals can be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that can be referenced throughout the above description can be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
[0730] Those of skill would further appreciate that the various illustrative logical blocks, modules, processors, means, circuits, and algorithm steps described in connection with the aspects disclosed herein can be implemented as electronic hardware (e.g., a digital implementation, an analog implementation, or a combination of the two, which can be designed using source coding or some other technique), various forms of program or design code incorporating instructions (which can be referred to herein, for convenience, as "software" or a "software module"), or combinations of both. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans can implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present disclosure.
[0731] In addition, various illustrative logical blocks, modules, and circuits described in connection with the aspects disclosed herein can be implemented within or performed by an integrated circuit ("IC"), an access terminal, or an access point. The IC can include a general purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, electrical components, optical components, mechanical components, or any combination thereof designed to perform the functions described herein, and can execute codes or instructions that reside within the IC, outside of the IC, or both. A general purpose processor can be a microprocessor, but in the alternative, the processor can be any conventional processor, controller, microcontroller, or state machine. A processor can also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.
[0732] It should be understood that any particular order or hierarchy of steps in any disclosed process is an example of sample approaches. It should also be understood that, depending on the implementation chosen, the particular order or hierarchy of steps in any disclosed process can be re-arranged while remaining within the scope of the present disclosure. The accompanying method claims present elements of the various steps in a sample order, and are not intended to be limited to the specific order or hierarchy presented.
[0733] The steps of a method or algorithm described in connection with the aspects disclosed herein can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module (e.g., including executable instructions and related data) and other data can reside in a data memory such as RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, a removable disk, a CD-ROM, or any other form of computer-readable storage medium known in the art. A sample computer-readable storage medium can be coupled to a machine such as a computer / processor (which can be referred to herein, for convenience, as a "processor") such that the processor can read information (e.g., code) from and write information to the storage medium. A sample storage medium can be integral to the processor. The processor and the storage medium can reside in an ASIC. The ASIC can reside in a user device. In the alternative, the processor and the storage medium can reside as discrete components in a user device. Moreover, in some aspects any appropriate computer-program product can comprise a computer-readable medium comprising code that, when executed by a computer, can implement any of the techniques described herein. In some aspects a computer program product can comprise packaging materials.
[0734] While this application has been described in connection with various aspects, it will be understood that it is capable of further modifications. This application is intended to cover any variations, uses or adaptations of the application other than those expressly indicated herein.
Claims
1. A method for relaying a user equipment, the method comprising: comprising: receiving, from a source user equipment, a first direct communication request message to establish an inter-user equipment relay communication with a target user equipment; sending, to the target user equipment, a second direct communication request message in a direct link establishment procedure to establish a direct link supporting the inter-user equipment relay communication; receiving, from the target user equipment, a direct communication security request message triggering the relay user equipment to perform a key request procedure with a network; sending, to the target user equipment, a direct communication security reject message if the key request procedure with the network fails; and aborting the direct link establishment procedure after sending the direct communication security reject message.
2. The method of claim 1, wherein, further comprising: sending, to the source user equipment, a first direct communication reject message after aborting the direct link establishment procedure.
3. The method of claim 2, wherein, The first direct communication reject message corresponds to the first direct communication request message.
4. The method of claim 2, wherein, The first direct communication reject message is a Proximity-based Services direct link establishment reject message.
5. The method of claim 1, wherein, The second direct communication request message includes at least a relay service code associated with a network assisted security indicator indicating that a network assisted security procedure is required.
6. The method of claim 1, wherein, The first / second direct communication request message is a Proximity-based Services direct link establishment request message, the direct communication security request message is a Proximity-based Services direct link security establishment request message, and / or the direct communication security reject message is a Proximity-based Services direct link security establishment reject message.
7. A relay user equipment, comprising: comprising: a control circuit; a processor installed in the control circuit; and a memory installed in the control circuit and operably coupled to the processor; wherein the processor is configured to execute program code stored in the memory to: receive, from a source user equipment, a first direct communication request message to establish an inter-user equipment relay communication with a target user equipment; send, to the target user equipment, a second direct communication request message in a direct link establishment procedure to establish a direct link supporting the inter-user equipment relay communication; receive, from the target user equipment, a direct communication security request message triggering the relay user equipment to perform a key request procedure with a network; send, to the target user equipment, a direct communication security reject message if the key request procedure with the network fails; and abort the direct link establishment procedure after sending the direct communication security reject message.
8. The relay user equipment according to claim 7, wherein, The processor is further configured to execute program code stored in the memory to: send, to the source user equipment, a first direct communication reject message after aborting the direct link establishment procedure.
9. The relay user equipment according to claim 8, wherein, The first direct communication reject message corresponds to the first direct communication request message.
10. The relay user equipment according to claim 8, wherein, The first direct communication reject message is a Proximity-based Services direct link establishment reject message.
11. The relay user equipment according to claim 7, wherein, The second direct communication request message includes at least a relay service code associated with a network assisted security indicator indicating that a network assisted security procedure is required.
12. The relay user equipment according to claim 7, wherein, The first / second direct communication request message is a ProSe Direct Link Setup Request message, the direct communication security request message is a ProSe Direct Link Security Setup Request message, and / or the direct communication security rejection message is a ProSe Direct Link Security Setup Rejection message.
Citation Information
Patent Citations
Relay side link communication for secure link setup
CN115413413A
Method and apparatus for authenticating network access request through terminal-to-terminal connection in mobile communication system
CN117121525A